sssd-kcm-2.5.2-2.el8 >  A aLU]KL}:3c⾢ǹaLPL>]8_51}* _li )p]aݪ M rAçB:ԫ5rۀ r}u.nN[RFڧ)F@#it{݃<-BXqP`.<ǔXB*m^U:F8G2lzZ(Α ,s5`R n7J t@vz̫Yr8afym#a35ˤǺՔ 8 ~GPXv{; >eɞ%,փqrV`f>4!tq _e `wawAo{\_Z*'q7'a'&<-Ot+aw}^a/5Y"G.]Zs 8Z''uGhu@% y= T>UiՋKhK7a^eR^3㵉\F0Skj枕iCY&>&כ箦j3Ȟ]q.o1͇=* qҺ%Vox Ȫ+ Z~9ɧ V8^@+J6-z ^P-4-F߲ߡKf@}B~;6W)9"0 h] oQ7 ;4?f&7OɎG[H"x+X%o蘨-K(r}ٓ+$n'-m2m$YT{^x1k'[ #@ @_꫋'Z{VK4]{ƃ569֯$W W4\Soiٕ)zLeB0Gmi?Xred"2z۟>pBq?qd   B 'DJRgx   , { cL; 8;;(48<9:df>g?g@gGgHh$Ih`XhtYh\h]h^i bjdlel fllltl,ulhvlwoxoDyoMpppqCsssd-kcm2.5.22.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.a6aarch64-02.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%,p5HyځAAA큤A큤aa#a#a#a#a#aaaaaaaaaacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8b4e29a574d0d8fb18abdee833929707d2486eab2d2c21cf074496be2e7bf9daf376befc2002de00e2de75ae3af497dfa9bed8c8bfbf7a7861745c671089373d36667e48d1236f2fe1e5ffb7a81acb6e205d44c7d2624daf00859ec815ffedbbbfd341da60a225b72a27d5279b3993295f3293905102420d77da9cf2b7fecb50e5508180b953426cd1a8f5d61bb945247ca605fa5fc4d8edb1fbe8f3aea00824e08a5e693f6e2dfb646038c431085f7a6ddc89427cedec6898ab8366e5b2057a5acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcm../../../../usr/lib64/sssd/libsss_secrets.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.2-2.el8.src.rpmconfig(sssd-kcm)libsss_secrets.so()(64bit)sssd-kcmsssd-kcm(aarch-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_secrets.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.5.2-2.el83.0.4-14.6.0-14.0-15.2-12.5.2-2.el84.14.3a@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh svuk2.5.2-2.el82.5.2-2.el82.5.2-2.el8 kcm_default_ccache.build-id96a6d499b5f4c4efb588dd83463996b55e2984fbf240a988b11bdf0d1c85f869bb67fb0b8c45312bsssd-kcm.servicesssd-kcm.socketlibsss_secrets.sosssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/96//usr/lib/.build-id/f2//usr/lib/systemd/system//usr/lib64/sssd//usr/libexec/sssd//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f240a988b11bdf0d1c85f869bb67fb0b8c45312b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=96a6d499b5f4c4efb588dd83463996b55e2984fb, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)/PRRRR+R'RRRR RR,RRRRRR R R"R R!R.R*RR#R(RRR5R-R)R1RRRRRRR+R RR/RRRR RR0R'R"R#R!R$R%R&RRRR RR,RRRRRR R R R.R*RR(RRR5utf-831a5e4401911cac411839ce16a5126ee5dd0769fd54136d6c064c00b9beabcbb?7zXZ !#,h] b2u Q{LSG)?>;/qa-oct!+Td U,zVrDxArWz!F 9lfyyGcuS[܎Oؐ2Ya~#/b|{Ƕ'iܸN byۄ5zTx`=6oe9idQE'hC\UR~XG*R2tLҺnf8(b~LaW>1ؓ#w_Y<0Oȑ_|%4=8QĶˣT<9ʹEK1M硨@|d <3b~r޸ܫu^'`΢B]/r2հ>?ѵG# IA殡6 *Nkd>Z6̑瑉q IV>UY0[Ϫ5.ا>U'cn BC.e#*c~Fj膙rL_gxYM>v4t~ȹ0Ou9֛;&β;v.5-+b4'*!X nfUydʭ&] OĀlx϶)'zwX:&kYi 2!HH7E@Hd\G+5;_%lVϠ8v`n*E}lSCr2ř~!\wF8J(;vQ2( v*]/͏ٌlwe(|,2y0 9SѫRZ W@|?k3Lj}5UԸr) y\d5Z} #9FLWa$&)+\>Qsb TԐ{PԯBP%w`q:!Z/ %ǎBafykPT.S- &gb^>,Z!DU蘏э)9xgR.)͐ S7qC.LΈIVXMH/YEjAP3P̰=)`7@C` v1&󕦱Xrdgq\ſ,*v(s&)' c¨]Æ3pfPM dK-8ΆrXn 7ăU$tث`j4!,Q&:yӋE9 0J@L-ܵ3+BwJyQE?5\N[FںP0+~u]n.o:r% 7F)xtJ17/E}U*V/Ƨy7j#CCRG8Cr3g@VoK ^OFmS1d-Swg>R tg̠jb~c#.݋Ke m|3YoZ B:d@?.r g^O}<5?jk|G`$2 v4btYN+'46oPӘ-XA-*A<(rI'>慈f EE=N*ࢉ؉JAV2e6Pg@Vc{"{ ;5%琸{naX da'IK=Zq e!ݛV폰ⲱ ).iU9#yT^x)o 1ljYl5u'JR>gǭqxa*;je{ݟ&yoKf9<|sug2Qt{+m!`!/DG i4IH2A.%/o!bdߌ3*Snyt^ӦkU/DNK#rFK ]p'q$Ϯd#k(HlF:V z0ɘ$QpX.[:?f[vbj5MI&' voЙssMrI !TSV31mҬ'vFkzMS1]O{|\.3q}m -,@cq5itUeh [R% bf籫Ad:(&CIJىKGFQnvB_8AoXt  vFVO4ͺӝɁį?8 S-_lVU%]?@sͲC1d"2R?pa'xꖍv\A%Jj-$~2t L4"W_0X# Ptݷb㷗^6l5Fٌ-nłzv0j0#9,L_.zY'3zzq? Tڠ"Q ?Y u+l:KIZJ( "zH1ӆ*OUIY\J7m~q"ҕMzikAE'VrD YxԞG*RIUjXJZ` XOcak@ձ7)ϽJ(y#/k~џLWL̛HF0B{p؅{^͵.K%.I/#)M@r_KU6N]>DzEތ{oYs )vƳ{մe8_v~kݴ´tq,8<56hZ`-L4e*`|k9LJܸbeY?]'~Q@!n^RAyr  )VEgFj}YeuR78DZOW@*U;4q!c!L)>%~qgS.0)]o,^5 y%[26<$!L3A6먖74geb! {EL  H(?ײtz{\Le&tG³앧&tzF>rt^we'9T`p}>A=dwt~٤άLU-Ц'iPj"T~fi.)6{Y2#=&h> PXl[g[A}ܧDb#g٭;!pJJY"Y"Ҧm "Ñ8Ey샥?`$,N6FkGa{ \b9̖ _ De#)&yǑ4Uևr=ꕃvo]MjU_>> 2Z$e6>Gxl!tj63-=pߋURlɿ U1™B yr~Q}'qgI&%ք~ Җ#RtFI|H3[yXORj}{j.he6$pCvAA'k))wHUEs)x=;OBa ^g>T%vc͒1GJMuЊT9Tbv壳e5LDPӎ۬64߱h0H0gbA~E䘾i ;_qU ޤwь=y!:&5>:z٬VTDjgk1= {ww{c7LI>cVCD= Y`bÿ=j Y"c[*[{xvmyf;CvFu1&BeI:H4'3r;T66X.:+c\A68.X"Z㎮ata?QS1/ۄ[F~Å.>kΥ,q!4ÉAqڏ)ʡܷOH>&r~GSA 6,BG89;[k&tCAV}|HeRIGhz|QY=C~(.=0αKj-oPS~XQe>1$O^fKƪ3j!8;iI: ָH*xʚ*Dtj3e" l$E= by`_0/BBP@1#BK>UO*!VG0bSQ)sd8%5^Eo]!?f"L:INǛDa*11=1n A(.9zrM3opØJepu/v8Ҧ?11Vz1bgt G) . 餿 @ c3VpK&pM.JYġzgk1{HlNN"]CF\4 d}b<9ɶP! B( 1J/KPpjACO0> )#(yw q+<*sz/D3oL7HN,яZ[舨`LRAўթ>LT9ًRl{}⤈Ϊ,p߱SN^5!K;޾xAW3I4I Y(ߪ0<Ȱ(-@GcWF8;b`g,1s_M$*Wcm;p{LDz:~ .5L߱77 66˧k§|,V6YX/k(mb]$spqEѹD ?tt8ʼnHV"^Ȕi)e/d3U9<ôRs`?' od&M<&t-4pDWz04J vCVY" 3 N% ,N{5p/AKʏE4Qe$3uTHyi x,*9pӜ Ɩ(GeRs%"skSCoYػz$oNL}T)H۾'hdIvVFm=qXlF޽*0Dmi_ X.!wUQ]$q^rOƝD8Mp!le~ Ш7qEȶ.:B98;W`NO/R'av0d8+{3:A2k6񩹚,"FPs9*VifEDq--I$۲n+'' [/ tAԊ7ׯ g+E]٘pE?kj<@%DSJ/_~Mpj?S0$R`U4>XRtOуj9؂ ?6?@E4.VE]n667Y<_hxalhF%uӆWQx2\$w4M<xlRBsG'J _ڀnH&h-gE\3_^x)yNiڬiuI-!\,8̺ `2U(LYs3,},{R0aK3dnAwRt ഺs2~[6rW;:=Ϗ1&ܧjI}fK/1C&j%`y?p 7mҙ)Pt ':H>tѦVet^7 _h-LٍBt8R*- M> J,dcʐ-YV(-9s!i`R6Y,H6a1#m+-˳#S>)p j%:BѲz\Ϭd ] !@Y޴|OL;N< ߡA?v>vK5oO=!9c5D/MCV5}HTJwݘ)E!ُ3|5-fhӏ gIr[eB/cfw[mvƹ﫳5|=tAGRN t"KCmwx!v(PJnq.X j/Vzdf<.Cf}e-1FEp~C N EY7<^3h|,$Lm&#tOD^JХ [7p[Y[:$F$+ fRS&-翌l1 ѫq%y>QXo>`Ah8W[&GsQ -dzUv)>9]l=WN5}7Jnk  t@~ OHNzR{Weʻ=XK/8`x(ɇw"@q pَ.`A7)n]!aC^z9˚BCVݓfͨNfsU>%R(rJlx$sp| /S\U̧ҍ~;$.EJln)sfhv7!Q,=It|ֱݩD%弇}XsEUv45Lc07^-hCMq.H]v'_ޢOى[v;&ݮ,qM j12Ix[„T^U#HV <`*-eƫ 4T#ǧ鸒H"`. ʻٶ=P]നhZ9۸QM0_*)#=SI< 47'#nAց +۟هAf*hQ7cw۠#+S_7&f}8Eƀec"~Oe^F߮oiR,63oNM9&sHvem9Lޡ2F #PloqM]sɬ3Jʳ#¢#"o} xKYT5ʝdzj85ucZiGmJΘi3V-DmyЩuV۷[৽}aWex\%3[q% y_fv(66~7snl팢K/:r5b-nyQ}f NTʔQg7[$,Q9 ZÑ.Gs`UMKܙPs Kyb rQs8YQweDYVʟ)K[]Bs"%9Q1oI7wN9acb|_ y ̔J4U>LL+ :CbN;$|, F,Eg3 xF ].vVʿW ,-&,d~|;W]SuN "ކ{9*TW8rl&!v%K\U~u-=aNPNuLBʓҋ* ⍘3ŪF<|U ,h~q-$\L4DǤT:gZ;Rl +}qI]bO BCANWРſmb~{_RM_>Ԓzԗ q,HrY[,*RSQ~~!ֳ`fj’u IY҃9:HNӁXMf;l %[{v=b?1UKTU}oQ@N8B~tj&]nqu!6JС(.K/c]m _2M%ًq;$&^qfdոɅO0[klOx/L"&5kZF3mؗ\/qxD Cj6uyVA8'*qt] hwg5~AYQt`xto2ab{L4py[Av櫹ȀCJ|ֿ.6OrF1#.op6U1,\^6y`]?UXK$Sm3p6Sn<)ʂbY;̊Zm\[a.ӛð+)MYj;b'w;4WK% Y9KD#H/rmw:~nyoI sy7Ξ!q5UQcx~ va *m2D'̧kÎ9K홪A}vpk[#Ffxg ;P]AM.!oδX<ƌiJ쒅x,cpkD&WwyIQ`&9YЪCXR 7Y Ʊ;*7_sc\qh.!8ܬ'iӜR"dE6b 24 2Ӹ&3`9ANH̃'\jY3 wL]tG atxT.~%?*cRuږͺ rA­g~ޝ|r:VKir.#9ogmLs/u?\St[Tn1vmMS@P7t 'qfch6~Fg65ϩ'vA?~qŚsë\޹DEkF?tnAơt/::g`BuH1x|Bc.i!$b0Ј'6m~t#T%G PV]w Y%wjhq>t ^ em@/ld (pjLe02 \\׽ܾ ݅5MTKib”Qko6Fn J_`S]Ȩ2!/C/͕ O me&&l3 Lᒣ+c(+sk3B1b,Mha0H)8"|6eFQ2toeJU;%ivae%/"1S*{Sg˿1aQQzvF98[WI}L*ڥ7ӽf?NfO1޶ⱞy'Od$Pf eݬ#ya&r%Ab*]%=߷34qp:(U;ՐS< BڸLrYi!nf/VP?51 }P1} u F{ bNO䶥\ykşttXTZa,oVpYхí&I86kGW/mþ@$AE7jnDCy"XHflp +e H$Z_OYd ,:Km2 7Z5ut / gؾʊSL̆xW Eròד6n6<.i?jMI'aC-Bfa-@onKYiv:r:5^V$ṳ_9I|l5Wn=5 }MIrery@ )Mrte../[fU}mǛ;XAǸA-մx<%&L}ߜl_7)>]>u|Dio/T°;#S_sA @TsT`lܸp$/k'%&mt:MKV("@eu6ys\Iz,T%O#jF4h [py{z m0Ori{$p0otG)6x:2_ȤE:v^yYg-hzF!0T_nj&D~htnECDRE sf3/0&Mīfcii bN0"hV=l؅v*6I*F|Sڄڿ3 Bog/o ~jNW R4P1ZHzKwum~=F\+|MzcU-?%p`IиwO7tTMFAT#+=SÙa8mϵ"o *?E$OmYԟhn=MkW}) ~("|m A@nv^ ʸs(Ai%A=s5w*+&c F# yk6yZ[k8J[NI)'ZƬ ѠiA2l f@NN嘹unKNߨ`68 Mʚ`_L2~:rLH`@DCaSJ[ӓR͔9oE6Nu F?8|<1ut {LhuG}}(hF)hE0 &Isn;\q#(3D  ojNe`. 0zZ2.,s]ZI 9^1ØL~=',ГxwsDտW aC/چK+e`yXKV;.U|}7P\C2ܘ@!GkSCI`%oiFdwP+; }"9L|i#-M^PE& I:I Yd3+]"b7]YR;) ^X{,בV`D b yPlSD¬T Ǐte˳lKٗySC;Et'8בrձR3Џ1ԼI?J<\m%`6׀x5{Ӊ,1FEm@[ܰշ=Oe-(g'ѩ3 Xe&>ȗ=c0W=[`1֌5y bk3ҽx#`wW#;ctMf @2$I?W m(RܝݹsSq`jJM"ʠ8O 7]]a&T~:lזZ3h'1vJs0e21M, -jۧp6\ 8d ]0$&i1EnoFzOH ֛T]a1œ}q3]္Z-{j|P8b}Exc-Й{u);YQ@a?-U.H M) !t:t>xXG,[+iUffSl#GBEnw6$߂Sٍ/]s3WviK!0wBN=x6SYp3=s* "iwEð|c5F8Av'+I]0[vc[.8[ĵ`¸Y.m"$y<"u}qIJI/4?f,S!\ܪf!]5GX nUBrPl EoC ht qc+V!*Ǹ#i[([m(-N|4pwiw nS.$ (_6=RN!lrmc[e2#!Ui3le~_ݲ]uK3{wڳ-qf,-teHZ =uшiKi)R57U`.jeei]؁QI˃xG!. $xk%8Y$##R@VghN*eTZm $t(yӏ%_NDK S?=U8r]yHoC]y]bJq.=$d/Ms.vIpe"2##o_h*C.脼X#ei##< 2^l“FӱÜtZ1,TnRȻ) ]Ët)HL% pΫ ]X7(CElPAXycR |Qij<_Xb"(BLҼ<_Kv2vEQCk\@H8~Io͠mOlYW7`4{M{n~U o);@}9K_V0!ѵ~4g,GMc~R)\6y 9 $/|`Q~~HI2g#Wv&nGY!_G ҌcffkO$XM*jZo} "9f1h%Mj6˄3mڤ5 ~lDL@S7I$/:gDr!7xnz|ܠ$~̍gs?8'/ @ǀ>!^-eӇ6f`^ͨo 5 5 ?R_⃣mdɸ ʝb׼@Pb'nUZu;3Ğdy{kӓ?٘-͍j8 y.UZ)R ž 9Ixe|KiB[F@w)`猾6UUVDN͋up_EqD>Q>ɌK3. }_JBg7:G,zQzE&Z(;8ؤx*bʽ8 ڭm.2X %036Bl:>bc{:d]loT<)HH*_D?eDF29ރP{s;b*"8ryس:Y{ șމ\sV)2havm5n۶>kBB `\X i1phu*Z$nav3=(󸠜Sх 3,}'NdmVEHzQp]0*EFUx]>[ A|.I,C0ٹ`kCS{s R~g,&R-&7<?Q3%t?s撢c[̼vwrh>t EU[S]iTC}RH0;Y15IՐX-9 @#X 7#DPrG>jd&C92 ,71n&qp { 7TgXmC|D-iK XRMGgtf jBV8XiNp M וfrݸlym/?J"|S}do˲I 8,糎3 Kh *?UzTnG VBozԛ _z<,zҹF wpgV~I@ptb4VaI;̔djkp_ucW\DRכ{@{ "*ࢄa#"\TpZݻNLK0xA1]7Z= 2Ya~yXW%($8r'zJF8">֊O:rRl/VW9*#9}k?vh ꛚqi? +T)^{m8濪>tJ, ّ]oJʓ SG3#a<p FYemkF\Bud!"܈K! bh ?&';g98q-#>d {u0U~qyDy ߤfe2n4##9 KP^!}4(YaDqZnP~fpiBE _摫\ܣMWb`R&l7/J 14v7ƾzssCQj4jZ DzB & J`wUs [Nx6UMttD"`/łj;7_!{XSMM t>= Bȫ$>U 7Jq?Co~Q/m~k$wt׮|ձzʼ'`Ird4=)IL/E^:pxa2]7LM@etMm;,@V TD(\TgeByr|y#aIݗR*4q>H~)L "E,0Z_Im@ݜ,6@ F?@\BVGeV^1tͻ2:V ý*ԽE_ě56 CY=GmћBϡVrpxeohF@uA4}ϥ ~5yøPsDg;7mH35u7 tMtiO a4z/PD;)H[2DGC3mQO%J6x?:oL^A;i(iҷ~[F5y2zTukT_%+0v SWeؓr6Zҥ7#ءGt)I.>/:> JF_!yS-vN?V)1@v?Qdm4m¨-N|4hʉ0])zD# $P`ԉCHQ22չlUrBb'/ݎ8h~#VR[S6vbtx]DF ѩ'ك^X.1F=7TJO#g=#1t%gd;GKȘ2Īk.k>BYDJ{sLk ~<٣!SK[wpɖzCʧe;$fpػ%Uyt&pZr~1Vbύ.#ݼPL VT6^nPhٲ,i%/PH$f}O=`MujQpec7[- M>R+V?#ҀCNKf ^ejFs0qƜBsMlaKkNWBNZ 049KO.ǽ2qb8E\HI+\7YĈ+}T1=F%_@$%BVuXV\`L-[Iaq/1Vr¹fx'֪hYPeg[=<:UF?>XQ< h(z" u0P{JO:g1UƗ4MGvi͸FrW8Uf%R1rfz/)Gz?_43V+:eFP? <sqF̗@8Oi؛ǃvRPpa6Waxh>^a? GE]gȇ M}GQNn9xZwο=7qc%+}}%`ZeFT$ɍpW~f~فkDLX3: SeDFյbFC5HfsGZͳWE1E+Ym)?_JQKB|#a+V?i*pdEŠ p}^7@M#CV2<1U'oi@V^Ć|%]sDg " ]9(3etfڭ+ ;?i۝Ȏ R4Ok8K|Nh[Еb]>W1=RBo1=b\iUJLM$Ocsפ/08OaZI=n@O$b$2'|#0 HC %G7N:ngX(OWY~hX2 O, ex(y(1D ;;2O"1~DƩ)*h>+mQLP|W5S7Pvk鄿4 &}K8W@0/V`d[l3Q+ 4ٯET. F8ï!WéIT¬eT0K⨔O{|(OVle/b&`IR|Pu? i`H|7V{/pm eޜ6i2~UΒ6ƁgHQti0ߨC*guTu7RȨ7 "Ie)}&`tEhf1PW0k4˘J^ʦ _84BmnJ\Î2UÀQhtVo*aP/xN' Wm>ksv3(WO¿I]xr+.Cdm_WtM฀L^i!12繱m=,p/t.r]El1 )Qo9'CeFC^kțeP#0H B݀7e 0 Or2s%NnU\aqa%,cBnFLKex<{<rͶ])i 9l%amKr@^9j=ArBF!p?+B Qa/q _w~(00}͵ -{V؉'?y퉧F/OgÍk#W1B3u% jI'kyU4l-G=E[ܦ/qZ p.f=bK2b>+Ca/b+cuGڷJk/r^4^= آ&'7yBI<Y~"$7);b. ĥp{\E8Q`dhfXᝆ8Zs 9U]iA+9$ q^'&tfq ~]jӫԮ,_ WEOXlj9ɱ.i֗lF*2_ a;s%콟$X:=U> _iᑤ)Blg' 5?ofvJ%&&acZ -@M7> -nԵsC|LJjt٧Q!}h#)6I rot|q wONyY(UWǼ}NF/O%,.[>E/RyEG4T)=bFq1!W(^ugۯ68ûK+P\:}P` DK$RhЗJ'6:@0S"yѤrvԱ;۫Ļ-o1I?bXw ְ|pȾO)k`{`sGn/ml𤋮|KqEnmnsу/ [r#hȑ|OeFeԮH?)8SYb)iqձIW}LVnB@,|BY|gi)](rVME9,0E̻~y urz&eǿc~#><F OL/Mfs1- N3iʞ)qJx%%>KCy4jG1 Μh?&-n<`'#:[MZ!&`/>ANLDL\,%^ԓEh+&[!4qpWfnckMs}hm{ݽ+)t2.1co=ޫ':>;]%@Gb&{jhݯ!5_-jJri6َϑdX+DhRT] FdP39bIx +37BoE_avc(+֕W'D<UUۏ "'Z%[m :ς˖nKlMxGcs}3wA:N>,ԠyEuF@.!G-pltMEc g_X `g`0䶐_:{bLZ.t~ x-cEKB/=q+  YD_U9nF x61IQ&{m"~F.)d9 ]3U2+".*ah~\cާQ.\LXW=5I~ =ۭĄa@$SX옰{x+OQ2S3d&BVn wlEOO02MEeDy.b.1>nEt'L&`f7p~AjhPyY=ƨݡb4r)\L3CYLxzz?>4qӿZ᷄A:HvSA9t(< x~)YU^l}QEf&-FW Ŧ]\_7G/Q 1u2 qξq2&1>o􋑂L3_o "6¾n%E<<^(I 8ݼNuٲ>' S"<g%ptE&z0O:N &' FE*-]ꊦ _ O:`L'5Fz>f-8h*b\ &th2R(9wQd_64x_IKqaR 6t9"Y%4)܄p`'zXbD=|XF|^NLVF-zmŗKY4'rSZafHl=j `:gJ)Ԧl#Zn26(z0 >ʂ'@53?dFxw0i_1aqEc8zP 8tK ;IL"a:*'|2 锧3D?agϡ27ԕf8uo+PpoHņ_d՛B+/ !W5[ wleHsE7Neu `]5~Prbw𱛷WDNg_uF>4;/$[P-sΎ>.XH]ؔt7ytp>;PF*s1K\6pvFIApLpy)t*K`Ŗi^h$DkʫLVh,ۥ/7W!Hl͌=jRR>F.{ʝ"bPPUc0׋ԍ) .60[fTP՛뇆[|X!ѓX^nj#9fbҩTnYn1dr%}=:zpwwh_ HƏ z-  EyX.:Z\=y Ò˳JfI iYʊ7;3tՀ؍n`r*| G0VO6aL:jIv9VMN%f GfK-oGZѕ&;:՗V9y\Z+H[{5 xbYvQK *sss%S8wCy2!CF?7;h!|ŧ],v-|pWSs Y }ʺ'e փ!m+ Ҝ%#TޒvoʷmM:TEVm`M+ cM%]Rlc\ay* փ|~s s7rk ZrfsQ~*n䝊}$~صY |m%K#m,.,A^b@#r:p(hCz.fKlq\|;IBH};X#md O/CBKKW&SVp{ASy(}FP55ZNT%7{ I&XYK:0ޱZ m r1i e\7E3Je-Bm籪i5^CΫ)_n̏b\́Wa"nZ4>nєtIH3$BTu}x5{mŖ,l3Ą/q׎ҠG[}ʳEoW<8t.95CyHouu]c}΂kp!fHCJT=h<^_񶷻&D`N[Z]RT5"2IEwYxs(d/L2t*88=>mL}:GV#3;*ղȤMݍ%3.!Wc3.;ӹvj -O!1y YAJ @ϩ~b tIDy<8J72h OBDJ;CNr$bq)a /7h=XJ lxeFV*s$-Y[ 9#yq=W/m~6-Jf4:7Ky$ ƀ7a\U$EG.D`>ص4TLh3n:N$EGQ E$Kӯ #JCnFXI~a'PZFYy[nǬǼ(~ZA|v8ZÓy ;gDœtm>VNUy@M(/)wuP-48JĚm9wD  s⚶PZj@i7b'.Б|R7Y%!y{vl"G^/N!Ӆi>&8\\vS;!a??P4ut&t˅=&YY Bh'>:-&o-cdZPbsGBۤix8 +}$=]6 XUOZvD1I{g -z"l)UI.mg! QHQqWTf/ :*hĶ5@>*Nc/4{˲_JFy#7sNeN%U h̽0Zžס 6]UH L[_)N(]M#젌(ꏾ NΆՆ5~ܜV/O6M',[V`iۋ}1b6?yvЄy7f-圗r (ad51F ٟ*#@~-cŧtz,nlN+ޒ S{/f<}~i]J5(,ve #2䕥b'#o%mvaơpҒOx s[]"trO)LXScney.<'އV98T/ȅiQS>8jRR3~A VhLtI\sF;Y=0B['6pJf \N:Ur?h^x()_Zl;;sP&eɉpl}+ OkPCxyr-0e;3I$Fp;II7?PnEb QYeE!FCi&l:JbGP!5&8KB#yubGg`(X~9Q+kV7V58}rv[XD5Z&26ףeEk;"ذdtJzJ=ePՏ밷Mh^ĝr`I7:5'U~gwr4vTHHi$Q2uxvA93x`Á?+|a>bp/)qib͔Z̕ڗy=ՈE1!pK׫]yiv>'h{D9:r29փw&#O0 (j rksbíݪQQ2|3%$E.BC8.u,~1ᒉ}|ʫXvh@Ƿ5˲ޥ0v<Sz4Tτ0 )hb(LŹlA6#K5\[ * ?1F!TPM6d=}^4GhuB/M'F&\!jyᜯQ?isk4re՗=*RBo·"X"I("VW<%|Wj5E `N:Y!};u'pHKA1( tPOLK^D)4Ú[\7Fgֳ˽0{V&_M}x͔%=0k/FhjF&cjH//r3}վ4zR֎0_|/i己A=V^S_%.\rAFʖx*2r DU{[BS">` " ÄfܶjXhͤkw/hp=xAGӽR)? [X%nzî_FDDuVl|A4̶u-nOpb  g}$J<;) 4uJ]Cp'(G|s 9yHqf9p\1|(Y>%YǺSR.cI&H[HaNe(՛pZ}"uVAFugJ9C0< ܩ< yw7 ]3Y|Q_{oDb2c`z絀.!d$:Ɠk5*Fd EW-XhLӭzMf(yю|?9ZF+gF6tn6N$ʶ(5OۨF aL!C'84Dk4 lީHNBEmW&xẇeqH4B2,fOIBÅlz,'A MXp%+Wc1IxvxzP~'Ny(8ܙ -pЈ՘T=T$F>m̊3YGy.' ^ :ca'JUf{FhgvK]=Ah^K?H|y xGJ߃<86[QpuI^J,N6"k ۾N^,&`*#jp=%l:Ԕ4UՀEb(sh2n}KAkQ)̧5 !kHPǕ` j4P< 7#LP((y3{1f%|3bcG%Awfg1K{jWZI], C~УH~Ù"KsPw$}UINPF+jQ8EblIpF|Ϝ]y41bFbH@2G?r  ֋KLd$cHnBY!h ]o2Hr2}MF<2kWmdOHs.*Xl?ylK$:>=$By'ѐb 7pU i_[4k+,B+_"|r=cNe7ҧ@blx! p!O`?J! TI||\jTѲOz>¾$^Z|2QThc%ߌ"Ť~tWm[U"GAbl/G.F8D\pԈL84KF< Qd ev#MpĠK{Sq>SH-^.S+ VmFB},-ebU9+E |qK.<ޞV#CpUh ĤsLPp`YG-Mnuܯz,tuN9W E):恧 {6NKE6w v3O6pc-WB˭5N[ªS6!y,W4 ?LuD byŐў:qqma曇Ӫ*q_wbx`azt~wMtbUR #قevHˠDpPۓwDJt_T }[,h1}؟S88TlukuI莾+,vН}$*)%wYBaVq\QҗR"?4Wd$DxKyLV鑻ܞ"XOI{-l5% ^_UP_\p~Y@ rVZ%.dsVC^;!0@~,˰W)k7k &==g*lJA~,|A@}ϊ˘`_KRFl'V8h9ӽ51[fqHcrc9}62X⶷u,k޹>PޞsPZyJeY2Bj i3p 2o榟5il%>"`<3m)V6<0w::+~ևTM/vز7cς;%k!g@>J=t[s*HTchA-% Iˆ5]Pp!2,Pe@$Je=E@0/ouyޢ)#3 `^B^l<vy5\['9X-/{"soH>1S*:rbD a:Z'|b2OkEx]zB/H:b'%jpe<'Zv٩y6,> p@QA_M^3G^RݪtBۑup\:JW CȭDO!/b7l5tHuY )D{t~,TylE^-VwˡEBcRt~MrXYUؗw% oC rYggkUӜe,5;U8is5ۉ~5/"vD;Tw`ňa|;3궂<i'{Rԥ2|Vh@ q ~(@"+Jr0 5֜!-Ӡ0$Zcc{<QS7:ko|)%g bfgYsC}d7ܸ'ftI>6;Оn\iY=8lOɂͤ"SŰ0߬=>xʾ|ۭ'W?<8Q3dk "~"Dh#(Mq֋wZ1)Jwgsz:[Jsa`NOMtxhV줩CZhe4wշuxLkVU_F_˽%o']p+ez9?cö;o-j5%&IIa(;*9f/:O9zIvi &ȡF/"Hv5,N7Аmsk'}]!ldIT^1d⚘)  2."(3b6N9"O&R^nGۋ7H\P»ݦ{D۶^K]ݷݚV+k0:&k!j gEpubU&n"ڨ0;]ϯWY\#H,!{.r^ uXOLZر+૾2Tibn[0"'K.kMPlQJ['|s\P|u[0ZA&0%! Ȟ|5_ | %+r4a !p~ߡRp7:t" 9ڣ.g^;?20M%hRPWQUps侑 ςQל.#͋ClB(i)6x;8ʩlGHb(}Jl'Aԓ=Z`+3sY h͚0zdmOMB5W±bVyM %.@&)Jlc/ю=t\A+PfztEP= 0K4M*$ /g] \!;ҥsV-utSg=hI'P,G' "EXX6jbueհnR>yDg 5 ϕ>mzb*ZYIJ*u[aD{nr$wAv:?4N88؜~x(6S)\Qm`蒂R!gl&vbPˈ??-ur76$9y(#+ʪpptN.61=2}>K*@)T)";l2 E\-_#{܏s <CxX}ENVѣ_S.Cy$<[>+`'\->|; ͨyP :c1H 1Aا>q}8 lc=0}f4. ߖ#6c[$c+pphW$10n~mGߠ '?2b j=r>'!sf)%c,j"uԣ;:5ڢjnLR!ķD;Gt]`-hv&UX`v®SL=?XձsTx1իwR>[|~'KM]TH!S,iUyKbm )tOr0U""}lTBHXbJ@l>uo+֟zpŴٓ 139:6oҮ_s]:m7?ɝ+`2 \޻BybRr}SK&Kcxh=[:ԄW75`HɡI ⁐g_%- *q?Zvǵ/S7+]Ã7f|f$".NORޭ_Ts'1-'KSQC-QdJܓoMfÒA3% 2[jM/׭EF8M% q*w3Wg͊狩i_`I4O/ :czOi(q[ K#zXnRM!7OTyda85|hHhUNXȌ@ͶA;rB\ffζH&@DT H)4 y z9Uj7 *f ^Ϟ6[.6MArX I*8Pf|$K&E6?&A]}Pf.Q-}2hj!:IܴF+vOE,% k*4WFA[ M㦋؛K/,@o ceIڥ^Hg[pp .~  Css0'O KY T ՠC!sJ+x+{9[Oϭ!ۗB]-fN=\ա/5%>Eߠp,_Ý"$"ʐvrH֬xx-G&)TMQe@D㫶$eG7VD2pcqh iTN_fv055O3W,ĵ`h[v_`ș2uӫ29d}ӷT-s}>@*Sjva+` k?4zTǘ*EZ82hKlD }-w6,m*ͪM a-kkip)d h<F N?;Şyۄb&79#K1Vtj;ɥyh|y2_ϳKA5֝lf1 +epo ~`4p+zc% M 39x#BIxM#[ akV>y2k(uhj_L F0;Z©sT+a x/ثRX]  M}<^*|=$=!'=n5b#yapU1Lc;HffrY`ZqT~3 f}x[BumHQQLiۜ\WW^ p)Pfz R,VRP?w^Mu§#Eq'k&:hSgJ%]\l %m[.٪L8+i%ȏ-d*v5w!KW<6+|:aI^}) }/ 36oB(`Cn4ԑiMAink˗%3LۄhNvN{Pݴ֌hge/~` #7N%Ipr9K"*ў''lRG4+DjvMjIvٻN]yL*OoN!qЁ jgU*'3z8|qK)DPۂ.7!VrݖR&Gjn!ȵlkbqrH_ W/Z})Ϸ_P6 sΙyQmķPqSpV6i -;Q#6j! ^ۨՑ5Y!Lj~W[Ǽ};ztyPo:bl$> !/ 7:$Jz>Vֳ^a9LiCHSJ0\C.awQ_Ne>?sLe*O"lnxfY/a<;q{\~^ 6d$Ťd]\7kJz#ƶy+ x!Q `r^fWy.[mnU٫rd ER2D[L'\ԣ+4fǴ#pZr h LMqx\68YSD :Ii_owmV6@YWvgg],APoKPpw;*>qjonm\ LeَѠ.6C$nZA 6=1l9E1xUBbt`ZatDmAX}bPo ;ÉcHR%EtA_l9 'M+}+驔{!Yojmz>ɥ-^A%=cL* ;(d2nD)IJЦ 9_+KRI,H OpCAyڇڋdׂH4&Ҏ (`itd0%G4)G{g7no'K9dεlhܧ$&@% gUT9!1[1lB==zRZqqINXr*HCmDw81!ޔEo|X4ml /ĮB_oɻK YtPM!d.”nA> ]43;'݄sk&~Վ[h7v,Ԓ*MYGyyuhN`0V}o*'BdTg@z@qƻsVrΕp'2TOx47 ,(>spLzSw޼4l@;uLAr^Uyb4bE%Cp7-c3~RV9'a!IR{9,@',bڶ]|2x2ڐZ 5 p9.|Hq7BR.Jȫ)i̋K6cM$3v9(Jlz'A V.3,CՀW;5}w-'$%LoyEabtd9L t0ⲱx|{rVLgZ碄 (Q.׶3XR4V;w)^Y1GY._LOa:|XzV9XT)t٥Z2N~k6T 0W1cK8ح :h9xT[NAN4SJTAy!~_qa}5ŊeaV$b%v>f4p.PyN}W@Y ٹfc7&iמ40Kڝޫ'S`l}!wG/!6(REn9Ȇ7W ~$Eª~If{3!yξsxwRDh+m/ @fSlOL543ZiE[bS:(m=YúCR}wm4dK)vg~8 o%G1¶L ?U{SIe_sdﮉYbrCN'5 \rFqMj;z*e*_"(NeG>O;*[QG?/>efLLif%Wq=Af6v}Y] ӀܩV2^&O,{,ftW@cf˹dj)teA8Y㚯J :D?VPo}K~5Oۼ#Rгf.rLE;3ȬS.@F}\g2tQm}ȋD1Qz?$pMތy{33sf;Nz$5JQf<-`USʼ4!*EuF )lw{M ](D]Q C8^< tղ j2V8j~@'[C-uW@^ǿKPz~4B ĽK<Z7@rt_}^'ʜ28G-{'-(іXYbWоւl#Cu]|/^uv yrp(ډFdm%NmhHK>I6f"{1N-:%k.N_S.3Ssj[z푡ڢ2z İL ("vfP_@XD,-D?t*Y L?ӟڱTܦ6ETG ?Vhp2{S/$0b5p8٫y% 7`Qae.BA8m}/qɋ(R{xӄ8)Q`.}L8J<^7X֦bR@f^6V$,AtxwdBgWg9Q>}ܤÆAHUT{+5H,YBh_\`3l )4b"[1Jۗrڝ݀biw B%)R?nIj_`c&k+VfX~ Da_#3|7ד]lin?;?hl룴e1:{pnwXLyțysd)UHUS]5 DI%86V}KM db&oa ˝AF\rI`TTgYyĞ@zknӐIέ@_tUtCS;U_=)'?&h p&dR},.^,XW>8z(?_Kgv\tu7-9_+v$&*c RE09[U(|UJ I;g'A֟.DQ! `HMȶP1C.7Ɨ !ap=t5(o]Zܼu|qS*Eh@sm.qW=5mٿA/}V`sFӃTrc$ eWbx+bڮEV F3m*5 jaV(X1;-RShIO僎1ejc58#X0S{>Gkwsri觙bވ5@H|w>|s)tCQ@>9){]Pqmt`̹؆ rkP iʘ?5ڱ;T}k].!m3;,#OƷ/ͻJ (;zLk֤Ǒ! B<3N =ե6믺p`֋d=-VDjp2{w5?EЛy5T5 ܑzGRhs=jwOب:8U[ KzLOQl/0; ?HƓcnW{s2Ug?gs ͅbhl,h^9en\.?O%n?`eQocz[gS?\Eٽ0<Mz,Dgxk9`F~SpӽeCl+9纆O)œcڪ&MRA_$HOFdv5!} jXkAb{y&p'IrY<*C葀'ecRz*rjP1LW a `zlS涏v <%Q LD]Jh'z=Ffrl LJlrlusDVW*ZL:uFFmW^BG "#J#xk!cF_NR۴FU6Hܚ G` =1RZeAC Ӡy"-Pz*+$y^sM.0{!ut|a?TA9(st]:'ȕmRr^}1ddi`TN]@Q*n4 I-S٤Ro'GOoƔ &kf3~w=PY؋Ƅ ƫV*:تl <ݢK2չ3_% Ct}B{ s4M2hoΝf>_4ʗ aD:hbyQ\0p 걡r*QUitDļ` lkH~n g7A6Ļ|@U4iKEl̷NWjICE #ct{$hkrݑb/,,.5s/?@iz#\p<jrӜ@u~LnfYqakA W5md e&*AtÝ1usq't$eL%W*DC`;ŔPyH$"<ҙ$#,E)jes7D=`l&feZ %k W:ΐdJ8R A43݋)ɠU>Z;Rm#a.5Bt' cȗR2|N񬡩F @K@ @R;}‚#׻;=ۭXo 'n^_>ٽ Cp <ΆL@ FǬˆRZG`HOk C\U3+ų%bXPu ,ݗS#Z.oge(P|e3uVvqIo7 &P u!^\3\0;=B.lJ5 %+̑ (n` ){%jquskZ NZ+qJ–X,eLzme2X( kNC-`P9276cРC]ͅ4])Q~U.BC Qj1MZ>j负Hm[1}_j7&YPtfЏ+棁ou}2=O/MFtfmKɢ3^lIV̆VcnVFL5d[A =>[S;%*Dǵ^%$_Rj<7?6=Z3~nH%mNCOqt6oGjKa=Ƙ՚=>|ɺU u+nUk!\K*߆7F]E㸩8?Ш)JxXMhf蜹E7ߦ#&@F'>9˹ D(#(Erkth?@~8_Dc|aHgztbژkbŲLTW{zi5d6rj?tuKNQ.Cn䈛c j}zN7fdrD; o2+U&ΥƬ H wJ^( Cq2HK)OP:y\#%yNW Iy/ܘ%6whF҆q )ᴙQ+{A:8}^%Czzv9&ʉ%Ff*ϋp8C٫& -H3hy7`4%趦Vh<&p߯ ~-2wmpZu ؖĴQΞ YgVjϏ2_T65J&ȣf ;%^xO!ΐH/0LHb2.5WbکYFr+ןqGDycuؙ~9cAKq~'?>~$G&hs?2`nyQP cYLB78\}ӗI5t4 hkT2bMQqq<{B`f]JX.q;9Eݦr /,Vu84E|tHMWّq$wM ~zb\d8)8AFﺫ:>IY}-&~] m$C `+4ȜTx$dF)hxbTV^ Nd%2{ 3͛,^f z[0%| ,NCZ.s)]#E%9|1 K @KUn.T^ӠDd>i3qSUE]hWqᯘR])&<gțˁ59?` 4a9)wX!F Ubx2uV w,^l뿊IlB U]:Mu(u} !5y keC>.{6ْ*g*dXjئ~u\\@xr:B@1i[zqX,%@8?sxcJ+['])kdBǤR!_>O&y3kl `I+Dr&1`\|ڊSM$]u(]# [Ϫ+j~$ %<ԫL0)Ѫ-g !BX۩cGR’S¿0ѶnH dtR }|Y48r=T-Ify)qm'"}r4q: )M#Q*Պ<(TQ ,]v#@~ͦtE%"^]ْA0Dܚ:l87:5m7/oL.F)/ܬ@q좞*E%b@:.~v_V (5tg+hn #>fQ1_<<B{.V .R悝%!-;ipeEOXGC]x$Z6)Ijv^5vZ , d zaӛ'7m(C_Z8m@*m)'ȚaVϟJ> LJeĴ"9 &'^f`:4mL@w('!~q>42&F<1 ?FȅtDu"^4'#뽳j6jnR $nl6ȈZ;Y>tNja N eւq7) DGi>r;.7Jt:گ@#3W:؏EKa:T((cI0: UhV)򊱫@[旯 D䥁pߋ3ϏWc˃2 P|U*Y¤/Z@Y!HDK h<0zz?e*v޿^jwRhPV8[Qku4èFBGߟֲN>g[ E T%ms,xb=:w|qŗm!+,}+u{.Դ{ȟԹIb 8%=6e=Ѻ(JM3ՑS%ji&%d2P&eHl&Z0Eu` 0F$P m;ޟ))*BS\u>yJp(s ;}%Lz؝KpW-QߗkGZSV SEp7V.w ׆XPxkkW8#m>oX0MSosIdtu4TLN$Kzl ?ʒ^te7n]úPL0* 9+|e }9ipeoI) \Q!H%dn{+Oڔ};L9zCx`BU8fy3o@ַd6Á? miMaaڋf*J֪-Ewzo1~V‹#( rL&~1 oR48MtSi\}qz^u;BW/n.& Haߗk f:Q.QS95L?2Cy֮Xkڶ+˸:r@Ps]yxN'n ؐ+@5c|F+s--QQ9;58دyYJԆۂp& @\ߨ<<4`ɼ;"aFλRok8Ͷg[JuǶK9j2{x~uS *_W]=Gwʎe1Ughm9VxtmaB 1n˪6^$cq)~}nXQ_ {~SI܂ՃIeti]$[,k\tFv#lyQ!jSwwIZb1r$+4*T3a7JjtLE*`| w~WL}ӿ̘FKNH 5mi'ѷ4FkgF^ZPzJ:gIYEW…hD=Uܖlt7}qBv+AV-!^Id <[k |H6:;$2O <{#khAZx-s1?z d#);x-o@9]za;qglYά 宵-jưn|7"ELԝ9gaa E xrtxG q ׸X' <[ `GwFHڦZzEl՝|Z)AdRRD'KbۗaJ \RC %N{Yo%&x5Z"s'}E813R[猌x_+ ƩϖfL;b5`/41+;nrS5V6${' ;;w@ H6D<{գonB፯WmQ@gFo *$ˋ⵳rѪgT2ejBbEPbgiX]{˅Tn|)tpy z.s"%f98mԻd<&p VY5wa)D?oDOn1~GBhlf8E1qaqŦPMѴ۬(zrAc{ ,tW=0MrtѾ9/OZdl\ 7/kR"# oʾ3L=g!Xk`<V\@Rxbf6T0)}fDԍfӠԤ֝ZdMjb/=Y_C:ם꒍"]ձ.f:x2iU/>v\Dp7ߐ|c\xc jFŬH` y7U<6 *Wǝ\Bl;ȊX&OiBv+'b ~pVY%Y9GNp{^&,׀$غ(olIo ,@I :=2]{ dnzB&`I}t 0?VD¾Î`eRRBP .eWZ*|҂N@ֲv~,Eo&aP*r &؆(yN*eL{̙ S # 2?xtCMz$8=ЮL,dvzxG'/Zܙ~|As3[oՀ蓲YRpѱ^̥#΍Px?ȏ5\`cڒP8߀^P}&\Զ+fquU:8Iq-ai+G9ǰ%ЧU_4bl MYRN 5ĸFxzl:JvZjo^@@6ŒESU!3N0|2 ݱژz҉ /@W|R{^{ #N󌩞 ]O kN=u<Ĩm̰^+E|1,\#GoLnz89Z?[t*(|_}68JRuصTؙ&+¥#˂&Hl 67՛-  x. uK#NS>'LF YdV'c"p{m7@z*mS@foh^eyJƸTlj{(xCj}g2 "=3 Ԯ}!9ޯ9s.z:% " _m9cn!K4 5N o F MdQiYY j'[(BU^όy ~$]>T4r'y82Ag,! J3`*FcC,>+Oݛ`oB_1 j&WyYV5DyMh'Y ΌҔ yF#8* c?_ܓ6"ʟ>oC/_[c Em q >;lo?Α;M&SZ(s*֊@w:u~Z5 wDwSOv'17߳lNqZItٖRTP5$ ѹq`2F_0c[ODkRǻkn!B"B2J|*.Ӻ]Kh+G;G鸿8@<֝wO$|xzy$)w.LaXc\TKmMgdඹГQe%n?4VҢz_>%&&{M8gj\QzsSszo*ft)=MN:7^$cPx>klH:8;Kp^7951IZޢ՟E+kުcq,Dˌk+1W!<(HF+&av'F2T2 ɦƌ--?4;U)D^4`j  3[s]`pU(EJ6H$Je??Cs8`]B ZEyu!7=gt,Z/XsEq947=qYiY~?t61[oщ!quBqY3e۱c~5#`$:6)aC dn'~˯@ewkޑmfc(0Ւg2= v &r]9C3<^mrnT&nj<␾%p1DlʶǔB&bӱ71֑f قK󬘩ԓ,zb}v;ZQђUuOObULE*Qk:✷g,;p>/Dٗ꺁LAjSMXQ/AyiEhQ71!Ԏ}s`2-ҫ>~J_GL"6PL6'k0iZS%]RՊ><]x҈20E&ϐ& TCeN0 x2ڂ˖A?"6.;ZA07`n=J/S0)גa/bSb5baQ蜌Z;F/<}ABK\ѵMU<01:$T56ߕ Tկ v5Ё)Sv봽˙E |OۄB%*sn@rX%3?0c3^]Ow:!@ `oxR~jTQCaVg:̑2:-F1h;R4v%+Pr٫ٴz^g a~6n[>ism:@hR&#XؿJ(-._2ڳXäjݑ7\saUJQ2-2dy~Rg$"tRza\û=eV bǤpb_7ិ }Wް3' 2odU0͕$|>){UMD  uٲF)m A1cOAFjfg^?(ufjA-ĺ9Gp:-Sk"q e'6Egqu 5rx9X8n!55PܳhV¯@ch>?wxo ˤN$+!{Wm[zGQ=$5Rej+"qZI VLŅYRtwAt&:O eH0/ZUQgȗ]sle# ؙkhԭKv*ePD#`ݗ/ n!%0q#4ٴɔfjA· GըK~ zx䔰>*^#k|zt"03y )ZU 7@v-0eF $WkPe IYt|i+ˌ.i@+dugD + h#cyfG>|c^SzgleDa?5!'O+tpCLV14|88Ayde3 * 3ky~i=e9QTBѸ{ k@f=K64-)ِtX T-(@DOKhFř ޳E ~ޏo}AS't@^o) 8~FoL;ZUn:&x Aih(~64&@2<E̲`务6"C"kSQ2˓ZU۠@璭׌-&9޴DEc q}Ei0 Lb^ʡӰzGv=Fmp-".΍藯ّ]Ȕe9rk?Ͱu1($B]3Sפ X 63"ϙaO_ )EQq9%aM8/,4yoMXDi!o%]2#89R%f1m "gBs-ΆV0oONg"=@HG_D\ɨ8;E>(FpofڰRv=,ӳ gTXTKjvR>D"0^1Z H̢\LtH1p/+oSS(1G'A7zC!Ay ;z!O&v;'}-~CoēZĂnP0&2cD~`@Kߴ-.9y!!ފGIDM7pEXв%pX;Fsh],I37"Hj/U*r }挃OJȍMv*<\ M a@:BQC&8sC&QS~S,2?%i8SO im2^~eSjqyF$Tf5}o1X_q.H_Lr%̮%UB=FW`K3*lYp=;K]X=[M1-HU@-7SWay_D'bO dPPqMNMnUv9zqo~t3Q5gZPi# ڣy;)qq(chM*KmZ(0{g* Og;bN4+* G@OrCr#)ćtcOJ8|j%sϥ>D/|l3$@#KMATd<Ǚ,/`.8Ȋ9 e/?+c QJSDQB0=w'E~z<􊿀V_>JBxil|M53~3>1]=1E0]h:qM\s6ZXj%Y. KHvԬx"x^}"9o wN `B+yL|2-D+`*zV| 4|&COuٹQhYͼ`7^d%n*"ʹM,R>@̰sOWLVT(bԮg7ƕ$`wj& 7dYò>X-&1=(]o6JrtD*k;T+ou c~< N.dT*:6E$opKcbs1~u`{^w*f.Iؿo;w)!ӲmI Q(!mC,UY4C!$hQP'M!N66vaI_QTffP|@G __3CṱwH׾U.RriqZ;R?H13>&5Mm{IzO\MCDQLϐV- ꚽB6:1ʙ90tQPX`֌iѥh\rPI&,?B?2~JY" u*r78ڷ-Z T mzgJk\DڵUn0&(L06I0DH_qă?r+> 4w)}n~(8JS?+ӊ6XaArlI;`J OJ[K& Q{,V?hI6pGf^CC &Q]Sobo,~@j=OUXH0p{vU֕&Yb!Vm&#z s(1 !=G7^?\WrW8'vLPs (J*rVw,6,-Y'jl(ާBcݛ/~%0᧠9@/+};VمB)m.b_ cN3] Fl*RzbLB1p.g9J4)~;r@V˸ fmsvB/V|-i!5dceE̕ѭsS#?3!QL[(R:Y"O1q Dbܔ7&:-Oj{3 A;y1x,%?U LF;P#gn\|^:;rۤ?O{$;Njfa/ [:f[12˱ĭ_\+!xܫ.̒#(-C ^1[l:%wCUmI oTA~Md*!{;0iI>PJNHTER/UT9 =i_3Le1lߍZ-y$2^Sa䞉Ͳ'?'|N.ٯh%!rkX'zR4$(iTrQm/Ƅ~{X\AU&C؃Qf.W&?6Ft^|yJ״A\âמ}7,: hHqb=[թ#CoX.} (K};i .Nc.{N7~qꋄ ڠ2~ qoLBƾsC bר8fqk?/mI=޵Kt GDTd5cNsOew/sqE 焇歵wh[ic>#9`xАAA` gn7jQ5?ZfǎYk) {q./`CN:e@=RAUDF^p~gvj¸|IyUnP^а}Cx$ _o~`X.KX9E)>8FJUF#faLvF5JptG2FAG:u~j-2-te95Xב汾E]P%M,lNL~wDrr\*Fz[8ou#LP}#d菼*qoYa!$RHe,eٻ: @&JP; ծr~pP a6XSnT+޷z˾ s$46MfIh-sb&kc"ao~f/ܪq$,WIl̹JlsmӉ+ᆲK Cͫ5|-qo]lmU*0urG!BnL^EP5G:*uǃba0l.cR+V `Xqx>Fq`>?zsTٙWrl$PUMyPm~PRuR~{n?{ Q 6‰t-\ψ9V _jNIyRm൲&"@hQaS t=_?*K K֠2qESZl8*̕WOȇݠg '>q,yj|B0 'o rS"s.@NKġнRݨSXqh]?yTgLao.-rsD  &_C t$uLMdElZ7m|ZXkt=[<+ǺtMK@P`/fF7%F=y*7cw[^ϽCeW<\@Gcc\[/R^ JUʨA$& 9R"gP$`{ױ}y[,?DZ`@V(x}Fbά?AO)aܕ*لS6:lZ4ebR vw\Dj0m_oteO;XVCj6K_!ퟩEr&ǷѮ0IT]U'^G"%G<>7J4ʿ;' ݭ0/~}/AZdCk ᦧppb_-qo2M|] xX^3l|`/Ҡ#AehSuம'cDqs* Xzs0 )}J-I6璵 yL;@6J7y'l|-8xTޞZ\kكed6'j$i ` B,g5ZFHE~(@!yiZ0)J"q.<嬕!Ⱡn&/E1ϻW#q+ X9pTTgo78јQG.(4* W @w${z>EF~GT*%[%Uh(:>ZLPp=i;2֐\ŋ5}JgR0) V@Y^R‘EcWh‰,`)QPѩ<9Kv>]ꘛy˱n'WH 6I'f1:q]2YEQd)b_~ xfXdD3A,᝝r1s$#5@rxQ__18GE% ;ɔ=;-dO'r"ۮ؀&M0ۍ Ѕ(iѶpߔQoelf XLz 3s@n ~N29'8)^&<#B̕n{wVڼJ>fSÃ%¤yb cEd",(:>hbřzw`Z}|&Lt 95bS68>vz=&&ZԭDG)'pf3Y 5{xϹTBbۃ8 ߯PfZ)ڛfa3"hg 0Wl;QooZ>Gn sU2yڧ21l2?psN±L9 RYpkRZ2ySw7GUD}M8_G9e;yy&1LmdSa3w9 %htpg=fv b@G㙘;!Y%g^m[:rZ/쬦o>n Je=3F߷bL("K-1fW{ŀU9~ێзHUZ/yBl;t"GjS?c7Jr'p84g)34`d2aNN AZ@sV=[~8ۤLSfm{K L8jO!PR]!\Bt=o uD(Ѡm7[4 k2yW 3PlE(Xk=rZtd[lx0B{Q ~r)yJ#ŭZc~ǭ.٨~[_G%_.QkhX/#_;40.2`vl!ԬLf1نI1;v|n0M;,*`_JA9BDniXƔSadq}bHLE $FJ9q6UXt|f(uh$򩠪!v+>39N֕f6Kb^17F =(2U|NIsm*vp6!q]Ee \,{UeSt'{C& @xՒ2KÌ,wH۱<53dpm؀+ ٍL;{'ªXYHcKFKM7RqG HʸSBɗ& OPCI=UeIJخ:d&Lsɺl+_mhVuԴ̎ɨ+D8׮־.[՚ݑAdhi|qӚfZFG=uGOG_M| XPU;t!;\/~3t;Dґg~Q?\g!CQ@\O.a3 r'Ir-{7G9lW¹m @h 0и*Jw,ug5`w eJP@n&hgYUR2l2'*.6(·~i7`98i~1(J@̥L@ODh39O) t+w!HgODba}U4#= T|Kx;ΉV5a¤ 7@ަ1b6P(4x-?<`,W[ QZא6g޲+ IZ>·LiBժo([eʢЭ?չZͿ`dZV2}2+t +7RͲns5 kx7LΦBUNZ&wpmAkBNSխi%#/G rK[GK!so.؃c H16=%Nӈqֻ(@' ʦ!:Q mHVm(UXJ;Ri~(g`F%홚sw~ΔR~6? GG.K,12§Ь}(&>ѦҟTQ(sE جbG x1#gPQ|z2OtD,48;ItepkԢB,^A]8- sOar:vvL2%?wv$gµTWV(rX+xμ48,鵿-ɤMLl t(e#SFgV&鯺@n7#zG#{~ }8vupork%JTDͨx[T#ƻz?Ӝx 8-J6.t¤x0ܒQLh跤ESc< ^9К\V^[ygj]CB Y\KQli$wNen}2ި (h{\?+HdbHqEL㘒&-i]CLǢ|W~F@6?GާhRMK$㖹wkoN?jtY%iuMVlO$,h)cqtNXpjvc'e8o86vjзpaj)zRy_x'th SN^a2򤜛GkYBҶt3)%HmVӐtԪ U>g[(g֥xwt1n}ʗ"r!RoͭUZ:\hҦ '2ǴOV0%D(&e8܍omU Z'Ouٌ/Tx3b\ K +so\@WH*E^0@mXrPg 0aK%%nC%g6Ƈ1Iz5Q] Z]X;h!T#wE[˜7R1n!wRj]h7d ,~: 8iܣ0^:=%k _y?DgݲzЎ Ò.1VٱG3}TOCui3(ާ:h" JMؼMvis_ g_,7yy_.mYxj݃B>M;z&y*<G_}g[g:,A cZŏp \Ek˻`(m囸*!óg 4AƮ]#Z;LGr{5WXj aա{ӨbV)lKaU\@X1>Ɉ>ZG+k甯+1 ]"8qϝ)s~gs8 vApZ瀲Ӌl%8 b5yXYYprAXDXP|EB'NPp;B@% o{IdeE8~K0WBRu").6rFX(+KTf)v"LUN`A KZ6&l>J1@LDR*E+]ADn]yd&4H_M=!9M $# n_LHl ")Fgmi832?s"x~Ԏʒp=%յzYWEtzyC82Gtb#)ni!Tl|tYGqI< ~#t:$reMƮus ,[)̻>i6#3)k;QhΌW`/ Ð'fᘿ9Y=ϵGjŘb-oAe9HO:~>,wzb||-X'3fM+JXZlBU '8:+f^I<˧~߱UE(3BOE7K Id`V>9rLw) )(ax2^Sjk&07u UlKOi0;^_[ҏN\t@ o`%Z5ou~&Y<ގ _uw7p` h '){(gF2‘zXSylPt``Z#Č>fu#(J,7#%`;!!W?g`7N_O^VeEqt:Ӫ)U&z9AԿt~VI^k)"b*\(dYȋqDC tRHK$dKB۷Qq'a4,>5dۯx`vfJkEO'YtRF԰}yIT ' "OVeswP h:ES飫h5ך\v%_yFaQZOSŘjV=qjx*H\ZA`@'5EvD;/$4H;}fp=!-h.3ۡZ0.-&}8X΀e0xp `rTtvĪh֬s@xqo|,3"ǰGxIza1 ٫,ͤ^1f5&:OѸ,w勺t "NV8ˣqAG0P?8VFF&@o\".3>ƻ@h3ey&#^Uε:7yex0_cX*1;V2 +pQ)~tBue6]p̓&]xKi4 >^? V&o$Vxhb8O/lG_szP0َk`,YEc]3ruvE`nuꕜ?-D8sZVz(9I@LY*QFxL"(ZPҘ{'<7 ~%<"\bm4'^9T ͒ (iGiEj\4~;q.>'=h@τq-C!|K",Z {=?P  'RQE_[LY{%1V$|hS]ɵjQFYo=2\ڜᬎB}8=fR>)fq3S˰+#hv]JhmɢEX%tYUE%""Gƀ0;^+(2UաPg9v*d ! ĪG!b^>1EtX[3 2L<4A%PKng<Px?r/}0Z"vN&Y{, n /gtJdV2R˜I~ ewe4|?P&='KpBül#x. Q+N^=Jkj//1R y50n^`Iؽ$sDVkI1?cVT '?? On\0QKͬ'u|QM%9M/*1m&^tle0e(M%ǝUԔT9[[0_'NlڽȮ\?,jX/ =*շʣyk.8؊l$|"Ca,`/>- B-Y-ڑ@ygZ'El_(K1Ho/0i?ñu |s.-r ʸ;z>LxjMW3 E;טڭ1h!Gg Cz#?l֒rjCdLfFwMONF!g`_bX?}f|6?zgUSBYi0'_3VX ggKח9L 9fMڕ6j>KOA]ίXUrΆ0 `b.z3=4 qvz - 31 AA$GRbpm;k\s8x`2E*IQ\{!@qRf0PP]-jЧW(%;Yb$+~+~|-߫զD*=Vv_ dUũ=bю&@7gxʏ+cum{ȳD.¡)|Q㾯[AB;Z^gW5NW1-1zT w!qSX|LaV ƁY>h)UL^6 qHZjn!&pS98\G w'{BQ>@#b4V_-\Ttp& _gegZ~ɗkXH@3A>q5\G5qd_ eݸk ?0cfhاo sd?{9&}bzxnq'Ϭ-Yf<:jPW޷$5;;6oIV8{OcU 5$bd@\ڏF@Ln#s)Jϕ=Rܘ^|c_ǰ-gNS0dF?Oy`FJYUHnifm%e,yT- Sǂ}9f* &` 'dNB} 9a[9{_XɻZwpBҥsiٝ9۽PyaG$ }fuA&Yu⊓9eL 0^LBLy y^Q9ˬ5OU"=jiҨ+,=jeZaw{^`g_]. [:D)LFrLq,ܸ~50[S./"\# /Fi9gW#ԡ 8mhY&W3>T..@bϐfEiEɣKyVQ3(W̅7+ο;^g}ځA3u͒tnt1\`, _4}i*\k }FL82h~sN+#prt~)ޡ S 94͕,d{v,A}r-KQmG돣c !RX/m? gswB򺑦gMf@Ԅ7:!,Zp3S]ZO6Ɗ nQm1Jw8,Bk٢_ia$[I.ܯ9?`m0hӺC{4 X΀D.$dAZ^,mr+-g#YAYxbJc0UJZ"XXi7^t=ec UtPƲu :(]kCav 6:gςD] VBuiu6fQ{0Mh5U"桸GLSS[ELW$Q5z/esfT] )[eۤQS#W'HPiڅaMG4j->jW$o<^N`ܑ!1rY7j6yJ;,`ܯ Xvr3jk>%oz[2M>}L"w=&BWF ueK^Gt_Qbe+vOwV7%ik 3ӓf (: ʭ7lEj [F Z~7<.Hf~BS8UAsJfqhͩc5$Y>B{Pf+}ΓǷ t2t}r>6'1,]v rT rFNW^*R`!|t .AKB2Kɘ<흞v@^3w$d:(V OtIHUKJ=!8~gB-&T3'ƪi;w^J0{FO|ZK9srB^JXJ;t?OtgT ~?z75i2bd>?$mIc+HR^ͧb/0K'xK &7HO5b*Uxw.N=UŇ7<<(F=o?tx"D3ik V'Km* }1U!7+۲smӱs's_8*nHȪ-0c\[,`YX$U0]Hf|[\ r3kՏԢUeyx1E8G,w4~qA#Χ"6aK۾t"Rφ>'?0|JaYJ˔"&մ$B+1]c9hOY};mw)N\܃:qcƂVM"@W.]3w_ZLƥVԦ,VT2U_Zy)^ccD~2cw0?$妻+s*G`+Π=z?ؔH:XZRu|w&Taig9wn:n.Ȉ>ԾMF];S1yg2`2֦MX_N]7ũLSh{5;|u57%fʘ״[t}ar{>Eb% |ۜ@ֶmZcVà3-aQv9 H="6/WAAFxLvPc8Uj$ww:fR(-K|R La aXҍ{ bt|GœUϭ`q=)jca .?Rkɮi&F@#{heM:9vkp,@?s^tH 5n̫8q=- ZǯxR">^n$HLSq4o7yn IǦx*׀dMS w,hI#x>o'Qo(NdQOϠH +g'4{KD2kPٱܵ 6nKgT10,U{{ޓa᪠BlR3c.QVm;ppPhcg;-̀ /_WPmr'' ['jsYRzs -Fu9CӴ]IvKP&CxH9ּEufx+' ).u :& KƔ&ùxwA_ޱZ=f$e2& =)fYnW'0M2>{D?&GDte;W@DK$`MTڮ#s2"v7aԗhgH /47ۚbu3|aJ]>|ZԿ)_P&[Pݺ1wLCYX&j`V'%ǝm91 w荕#Ay^ ?~.XlR [@QO| *Zs>vBLW]:M֓O `!FM!ׄv絁V߄iCߝPpghWS>` ب+]6p~g*kdܡ<|K;K(Mƙj=Џ#k@&  +gʏTX?痰wX&HD+D z4|o3h[6zsP Xfpn̟pdsM M`rTk1Ci% tHi{(<oho07Vg5MG#Xe7;]P2RO V#R(C=!ro&Fj8ɈyeL~q堠!wU.Oˀ.Sϰ~vM$c:xbQy a٪]U,44Tbr7-襧_[JcuّI=V6 Y} ԂV1Kn<p{?xM MVmQB L5puioFK䍋h}Q\߄bBvRchM6: H[޵(UTQlچ#đ?#o֯(!Br}h'cO=Z,?<N>fB6ZX p4aJ~VFIKܒ_sh1@RB-NۜG {>J1T#=oW=٭G"BZb,SfhR eA*0teѢ_5]K\vd\X\Rd;T7Gp&sUU~O ?7/VPbV~bTЂ&AnMa: *X]sޢ!hfX\ڒ&%GsɄ&>w&,;E /I('<|-"LLF^ ?Q/ v9lbp+:KXCn궨v֘{SF0ĉ*Nx??=Ʀ` Ik]D+REZL~QfWKNi Ov tP>_.J'҉wy^VG۶3_ d˩.ޤME\B֤-ˋK TH_@(F_s{C-,vip?tzHALpG.?le=CTbLvV^:5$u!kEX˾<'ehB)B`{e3h$Y=ڧ>VMEPb{iο}f}}1 J= a{̙ Uy^ T"k='[ Btc]1ԘiSȩӢO{f3,L̓j}PxOBaZ&y*̭Qfyp!_]DȮ kUKx,; r6-O,|g|Sdi+ٟ曱]8Y,qOνB @[@'qN-&>ސ\Me[ :I+ϊu8fx0G{¿ę࿶4,:G֮!=`%˶e  YV_M0`3CzTR5T^CVEo?W؁qIL y]o[~E ר"#?i*NnfK`U`/ e)ME6KђMǘxdFqнhP0_/+62QUM2˸?sp&۷MpPven='Lhs_X@[byqy{AC LU6vvTF])Zq˃PXA](r GPB||#26:tYIMBئ 7W~0xv6 -ي[s.`m0A@  I2Ya -jJ8bFbW.3Cp>Sܛ)Q{B,Ǣw.x;hg h IO+2’{EaTd b'( |\JQ>G0o!HOm~ | O{]  f!DVm P#5l`)wMK=e1[5 W`[|kLT[0`H(q')DQ(Hk#Dt?Y,`XW.ݹH7u0Sv-n ðH6I-^@m׀Zc‰~ pERb6e+1{+,t { 8s,"Eo~DҢ/]x,}yu$)ܯbcV_9;Oq(aU؉T\aᾦ&GXJGN>o"k3ݍi:O:A J0e OTVpB~*+b< | ^勴!_8r݊b6Y_7Uq:2#7ͩq "8 f3#* aHA^F*+^ zkWRsʀ4fPo(Br#|jH#A*,(fu\ vjUBMi߱x荠QcRWMM4aB+~1q ^@Q"[jOwjq(w]nDR;+LE#[>E0X(^gZm<#ʘ26,K[x؂u> )oF6fY0MhΥ̧ بR AG ,{y'Ϥ앱6G%rtx xXAnCgz״f/ !tfPUXlA 1BcerhJJǫN\&J}Ek22u%ϓ҇?+NYVI6!~]ݤ& y9 z]Q_9DfI 4cި"Cm<>6f9zG&J:jD3aa6sR+,0nƉ flG%1Н=;(/dIDOL$eK!FAd8&,Y\p^>ؾOL]e$&NUؒr~PLkh@xd2bkC <`dZ\ 1]lqHS|A^$hY6s-Q& .iY;n^.*7)>ӹJ.քx{/=+DTOY1_Z=O m\VaDcr#q;,:YQ2ʨƠ bH X_gsvO[};,QK;MLEyl[}C4·hN󇭭m6p/F$2?6 +)Rar&s}<2޹?z\j*{̭IJ,kEG[#h0 5nҜ=uy)VMF@u՟22O4}LǣUň*6bP|;< V_n80 >ٮg!dWGW=湻pll#9N@]$v3N岓BvFL5q*C٤n̿bvݳċ /5B`: V*GQr6G kTLHz΂(}[Nn.~csFuEN巩NWbRl7FOJ.+ cGp$d:5+tZVgnTZ| 4`QbؠW2%gɘA ?jNuWai puB p>MIY:nk,:<+S6Bޕ&ݶqGůrvz6frj='G:gGCČ=4UyM* Zk}opdCNj>Y=3fR%25K9~x%;}zhEg{{Ӿ7𼢲~'s*֩$N>>;wk-&Fp2AuMd% OEP va|Q^vh +LRIi-cwfOgp%*]ohhDĄЅ w;Tћ9ep"axnOꗟ=D/CoMu]o+`3n9Gt1VXrX#"c_N:9=Y#wi{ Pbwr4ԘY(jaY0NWt^fri!4QDB T)Pr!adǺ穴+Z`0e^ 2RZI"DsbԦƞAf*:_~Qb!R| yF$8'pj•ȃDgO$zpH& =`,W]?R}4|^ 9˘ʉ5Odcjp:g񜰙FrƜ-">f6MRL=IGY6*sĊ"[Ñ# JcJʠ JAؖ.eR͢'\aK"[_$ Z !.&jmC;[WATلUTyϧ>A|ꞕ66NE֦mqLhIp3>|MiT)q#d+2IȱT ?٥MT8L̿V 3K\$ ~^ZoK?'<]n 07L[$96ɾ(vzk 1]!z#+\pmۑlԩw3= =QoFZx"Ǽv574#0vY,_Ϸ0Ћ3NM_mRz7ps[L5pw~`|D@K3/__.^ l*bQFiR1S_VII/!H^lqa5aXM#OCh>^B^b' ,. uŦNU6yU&PR l|2!x%)yCuN52e}Y9NNk~o,nZ7KY6N'|enҮo0˜)gFLZ#3thf(ME\% s0lzm/!ys[H'+ObhxXn v49"1! r9>)MfVy.&s1KY3xWy]Y! jvttua.~<_&1$PbIEkW9w. fpR<) E%bdo⑶  ٢ V0f_HӁY#bݽ̀qa0:D, FuL%$ ?i6RIٓr,vd\z ,`4] |5k#ȏϐmѻ%PMf I ƒ?42h{]Q}OswgR}*q U^Oj0{T=Ut 3T<oTgye3; !"D]JgVgcwJI^=9Q{GKgFZ(@IX'8Mgj'P8(>/i6syfi3,i|Ә }>L٨86+'LaˍMnx##cR ܱ}߆@!onlj""*X8^@Hm]L{mPks.cxV;|eEYsrb2 k0]RƜ~)!C߯~rЋ -dU6ﱶh4-#nlJOq<9עA(8r-Ŝ%HӚ2[6y;4G,9Pj52һa_16޴|*zlpp~;iQE.y]I~*PݭJYcorC,+7L@_lż~Hm}  Bc>{YMYE&WL$]7@gc !3iѝ"v*d,]'s (aa_`?Ga+Iwicƴ4AWybn_J,w0ry}Ls6D So$m^dn}k0ޭ(`1'g3؏3?ZzSV̛>+D|0wQ)yCyJ%Ks5 (ަ27#,9 r#M?ڰ3 /iqp5 =/JW(D.fΙ5GWnQI&49 PҁBLa\|&|s GP@Ѳ3XJi 뾙X|Ѭ H.# Qڒ`f%2(y:Y7~T,&ފ}Fk4c;xnj@MoзgRGxG&q5eG-a^'H%'6iK"Rx ]q)%>5g)'nM`=~9N2&vݡ1X: z7ue*xc |j-U. J˗j6Wy{K? I[~&WV%N`9uLMEI~i9dE27 2YpzT3N#J5`\_ FAUj6QF ~LF1D>^H̙8).]Ws4Pf_\U|#k~d*g43JB6`\or UQ4pvWg  DEJ7Á ˢ W1H󉨄>Y^pc>mumlLB9ʡ} W`ޚ֭rP?yXbn&K"y<7_ѨJ]A@1Yytx'oi5iG9c\=lHg]ʡ=j bF t V߲k5om{S45ۈZWR}&/Pmɥ].{r=Ik/_ȮY$Wm cyPYr"oɿq Hn[:RYx,ZRRbĺRbd+ Aw6:#^gNMErhK6̚^3։tS/9 PP hj?&"/H95Ҝ,տ;e|S$ Jk͌F#/,?uM;O<rG9 nU@M1q4}QG3 E_D/ 73?ָ/촲RɫJ"bL9U12E\ YԃuڄTfL%>r0ԭ.)KEAZՓ>ifKXLoMSʟEk_0,DVjq&Q y\&ˆQWҨÿ*ԝKH+g͕CM7 0#vu\]2 -QȹO/ dI!_4~0;$'xUl5a~cbЏ  hh7iZ.EځF|VA&8䵰 tLv(p`LhFcA`{=zMN§I2Ee^dMvϸP+:=rI72)jB׫ٿ>?8(X꫷oe&{U늳8`B r #V\7DX: 9^X+~ 4|=zl<n7'V\=<.UxF]=1c˄مE sZ+P3 #iO%MKWu9N@,+oYNx(t`hlϗI},3vbQGˠi"<_81uF2EE^DR,(i:}z0pt7/Ok6ceɖY}-0we#\X6TaTlz4o WJE'\Os5tRI>][t^01(xB-1JFOލ&3Dۄn̾hX y՚d>M zp>U T}9Ix7d *Ȗ)֘vKh~*5hՆ41nEu_pY(Û[GceVx|֩j //parXh *|/Ҵz̫1 \ /uK+Ǚ/2 0^g8c[Y[bpd=ǙgUC|2ӻTѧ;zm5-ANgc,2$Fv7Wۡ7Ōrru+NE6SVb;V&;(@\k9FAoNU9ۑ^6b1Π̲E"i?,.Ұc[]{6m(^qecݔ@5[f-g`IYcxBNo֠3w=`վ -Zima`ǕZ%Ϋ'9%\ھX%Y_3[ܑC0""du7zy*Q|Gr{)%ޟhLU[G{Oo)Zjg 2ުɃz߅R n5}E&eU]h)du1a i,晅&Sv^~$֗1۵!vSW^*n &PQ+p/5 wļNv+x^fftSTL(*&#nqM4J(BeZ4wp{*{70z;QmRdvGKFY1kS,Mwp1Y& P>l~-,\b}Fo\ {0/4řͺV Rta+MD!&c oe6-̴UcspR(~pIrH~4 B2)@LGOx _߻ e&jܓ|KHa4WadfCi<8k˩fx"J+[ Bm=fOl0"$P<O"k62ˀKZ;Sqxyt0 U( VZIrw#n83+%.qQj16Q|AŢΟl Imlٯ2A^3ڽ'R>I2 qr;~P2E&zLÐpݪa 1Em#`f^D7YcJ8|^,ń+YbBg)?e{/:Y%ӣb1l VPd@:8x)G5s>]ZfI%Q+;P'P塴&Gw#FC*nrGgi>^nkdtFOZ,b^O+ibJ} &5BجI_2{Đ2tR={|HȲoZبpޠVe)E=Q50 @T 7)GuGDF.q&LLᚠ73HmXXYX\ Vy9k)mk'^]W[4nsXT ~ H8#0=ncV^e 9%δ/EHD:\n,$ L --o]l&2聍lȵTgYSWsnj"fpuNP4;mG\,-D; * cux$vH)62I{2dFҡ_1 ].wzR(>qx>kk,4 N#J95f}T;ZG2U@6#fIeӑ>dPdQϝ7(Ň3y-&Kr\uq=񎅺m9*Y,'ެ|+A9c]ʾ մ ,-[8iv+精]p/[-|Do~v%'qz& &5cׄiڍ-B>d)kbXk*JV{k,јs?I̫Y)(1G PֆCo0.̘<0)t_>IꂈbΛU2}j'wXMjG%8 );5떿?5'4x;EyrObբwz*kX  ffjkmE0/rb2ʌL%ɫD@!ʐ.go*+-=ȃq+]f5JENj|F1 ?ud/B4~yO>ZCJ;P,V\pÂ^`5}й}\M/VbAӱVWr)܍k9F${qL"|r|]=Eϴs.O0j :U7]'Qx*ЮgňgFZm)sb-rA0EwVWB_s3w/ ]1m`Hm2 #ϙkoq-ܔi'zZ`X!A^U6[η'-$o}Frcֵ542⁲#n̪[OXE/.d0J9N :{p$>3byqAowh$oj5`鼩 NtyHM: Qrd.,}pLkOP uXQ#*&k*H|7 *_ϟ^$> |]4lX^ XקNV RGʏƛY(qbHn.k4&> -̑ۇܤVB<\UZ6xO 6wipwnTg?)ŖpB+t boa^M•e~8}FEYsM;T Һ(#bk~;}'?Hlk}[[ S(c_<ߌ?\OSν+$WgtT({n+BqX,Ht,|lnry!A,AA_/`t]ԥ0 <1 x@P.}Uz=OawѺ1X;bs?S=*~3c.FF#N̐2GJ_HUL2ũi]dz{Rx{iNWT((քEmz;q?W'Ov$[Pz0QNˡ[g<t$ŠNwEM\}`bF4 BAM?]0jb"Ҵ b$:NSwY0`HӞxaGZ=rko'!ǜE{|@:d6kjМ29@Zۼu}7(::xRxM:>R[ 7_+fL@e4z!$R)5>@G@GU|EF[ 7 Րg_+}9$jD LH+`O\'[L 0SS7]oչaڴ4!sVhz<x(!Fs+ff+}U< TWǴ':]Mݬ G&m<%5GRm}M<0*;oWJpm;:TUU4XB}UH7Eq@Gdc FVMqnD#?AcaŖD^*Vi (BTT:8UHYl_fD/ )uژZ+l-hux qh)NsWI>5n:-=E.-ɯRz}gksC'H >ٸQ{NF8z- !_^1}:HYqRi+_KXk3"g~Ǝboܰ}oa InM:o% M>$ r@i2ρ _קV6R0 ; {eOE h2\-OH*(EP\|.98r;μh*WwR:n4k:~CXLZ*`ZФ$pv=b#ݵID )U{0m týS:;N\d5;(y?`nA^.FSy؝Z`݆hpa2]d)x}/_ n齊VGcI^mΙm,\x AATIX=hGWw23PWGy g慮YUgj&/Uٸτ/aƲj{ ԹrlO8?m5Q`|.rivc۪ƓyGJbq4ň33srj`(^&,}71 S"d,`!^Ѿ!k&Kjzc_nkO*Ǣsv{guren|MlFgu4݄ő3> ѦSmw'jAn4=ϑEzyAu43$yjՐђ| l UkJ,k]ŲpS@ Sbu{#ۨ udƝU=-˹''[MWW;L\_߂Ւ>]WK?' +~L( AQѠpČ9FeBPe(!WAzpx V84Cdv `G;j)btCԔn_kZ%r.kQ., Ehdܐ.|LuۂtW$ V .0e`J0N$Dd#SXocGxǃX4D5ܾ_s!Ow6Ck# U/ߍ1Tٲ VzUū*=cp#i}nO 6 [k<t`I!%ȕ8Bw,E&w-jjw4^~SB7ڟaXi%1$,;! p8VrC h.NC%#O=0Io1X۰V1ou\60yFgÅo)bh{c&e,ruRtд^|][,oFzw[m1"v2G JZo@_$y*7E{3G;sNjYj'%RaրL+P [t boVs‰iC~ZKwDU}v C"N4hrwGXщr2dn -5~'"F^ 1Ԧ]\=& K4e83v\io n,ܕ}Zo]{`~C!(ICIvԴj2h&o;MڴJgAukqō`1Q{z'bJewpJn6i'ku1(!P4ĸE^Dę9}brEc20zMlQ;u1, 3ߠ0Џ7w  4QjLuN nޭvP4QςE4s Dcrsq~朼uɛGy(5%Ӳ[8; ,TY4u`Jܖ ȃmAѪ Iwj[ԫcYח UЕjP*s,;,ki-`u.q3 0ӫcC(C͢+EbDAt_\3FEvA퓁cU/j3|>MtLL=l#eLJ#m3#Ӏ 6PKJ+Ud*'K%q-նuЯ8@ÅﲭYI\̥8[bɅc~}ppy5 |Hh-upWBˡ91 kK[q'T_$|W!ćWW+R~/}7p6<$sgs=75e\=zU5i4FPbF_ H:@H{7? Eh&Je?JmDtH[,ʪ)$|T*ntqRY'EO_]ƱJhb7E] D0e51ܿ+!MUa@~, ' R%a9oc&cb9p3Nb2I2~qH.Ȯ؏~ ?\tGN\.B>Euy&04E2rN@$Rp66ը(A\1P3Ϻo6_lg"NaΫQWWDո"%0"glsH JeŸGm[f*{ ~ YH[,] ; ߣ>+Z!϶(8"5 5bu˚Ke"M>djT忿ib)j0;Ő!yStZVjJNVK i D3 B9<+YE}n v~ V0  "_(X3:z̵wϨ`xm AS>؊yۑf阡doGnLxh+ Bi.yOuxXy^EX 7kx/]nFb:F Uˈ0Gt:r~ڣض$3)u߷a.d=p$pu7Sgy7^?ӛ`׃VӞOɴp}{jkBjBk]i/z=ߖ! ('E9j E+|7mR`!!:feXEj>)C73۠@WJNE-՝(m+ C <-5" =1rzj_Z4<\|u**rdh{.675E _^Mg>[wslc_BR&1b'A#Gl!8縨5@3zRq̦MŅ2y$1KB_s W wNeGk,6;\VXw':芔GNbG 0TxGMԥ$ ]7H*)ϿJ 3sؘTV_zPy/3j_V!Qq⅒kIZsJ"M)<ܲShs$V39'/r#1ʟNMUHNyB$ϰU]+wR]-'9EG|afZpE]֘VXD 3<{~G8/ k V|VxA4@},kWc?k+B6e xF@AMPP6<~A&yg Oʜ3X^.u;ѧ94T}ݾ 1A:$܌Z@m׻0ZI@Z$D8sWY:g:!: gcQpS;!T 5є_&<6π=)A0J^7i0ţ(^*[H^û`df%bcC=y/{,'BD*m9/D[|*މ29;9OtMR)Ad^|Q bB߶F>\!1҄e3SY'MOuQSu=V e^MC9PZFcO@h ?2/ D {w+G as| f_` ceߟWYgee8߉.XDèrziyZ4R96r 3onSybe BiZo0O5KZ{Whje캪k5lnj>` Qˣ8&eTOw L3>jJiTs+}2v7Iu;XnB!#haQjVo5~ .֝\3pumaƆ͖=OHEM AIӰ= Mp3*Tv=.YV{f6Pm(GQiҠa">yS8gny("R|k yw$ t> [PVУ ~ߜA"M Sc.͌ wtbclnuߐF0䘟ϊZxNg(ǐ2nhk"O W 6~>\ okB I k'q!4c'Nlp &x$`Fgj']*~JMआ,}ta|/T𑻯y~7B6Z@i07?>5{Q`$p8ֶ5ֶNukr QuF9.ڛ4Z*4%!dDjzR^ɗ\Ms9g(aH1HB[K}#ҊvCtCk $*تեlƖv-jA/*t/j2(s+V]zN fIŨBn C]2٥KE"PV қi)3L'4jH$h3N-)Jf\u4oY)߬hԖP)~U=^3F>_v96hGroHmT2 5QQb~&!F_!M> [XjCYVq#q\_Yo]sᐓU j(eIEsx7 ӝdgP9cL[py.2YbWSܫwVUwjSR fw?%Z:wd3͘8R(k; b.#刍@wFIf))֌-f9v}4ڣʪwжQ :F`z#BK : ބŇWi.= m"xq; 0mþ6"UJ}2IqM2y!]u# eg2ɠ6ؖdFm?P2.8)iɨ1ƟW]''jB%~G(N={a^Y>MVu5yLvb[J~߮6(O:EHE? ɕ܀^4R=cN`]k%*eYɭd/*9yLN,SQr⧁0F$ aND;q8A1w=S"tpr2TVju0fG@41,w-XI?Q 0B1-J;6 >&Yac/c;-$̮SzG~ a(ۂř:ED9w~hUn( Y˻ʔ&ؖH!c\֧=Bh^tU \] G|yBT ƆcncUsSHS *R >5c',nx.Dɸ&ZQItUt)xGk~Y4='m"'; n3 )K+ok⇢]+Vp@.s/僆V}U9=}I4)$}!?RPy;tX5]DZTs]B\WEfqgBPuKxRHS 6Vu ¶[n 9a-U1]%/ꪗJNם _ZVGEGc~Kp3G(܊385p*LNx|]r9 ;1;ɠ@cB dԄDhRxfZ~<Ξ$kWmg/埢ƾ2OBp+"Ζo϶1.G byfyYƶyfXl 6Ȣ{С!zÁ;J<_9.F<OdvЦbiDs-T?S q7 RܠED'<_k E'rMx-KOr䛥k;~ r]Ѹ]jG'>8|SW̊'rQʇ6\+@JP/yO\R|ؤKbu[5_c7,@)M;Ś$;(y `p^8mucQXkD /Zaϐ[ $?sJN~QJ2$^"Yݻd0`l/=LymQ9"#(XWZcKO8tStӫD]JGn0A1b2wlkˤE ˂S2et;ܮ+Q#4|$N:Y}.$6~7)CqMX\e{tby`B3xC]Ek޾™vfi1z;ϛVpT* ᝊjW!m*y*/XY71A"$uO{J'# ^yM`f(`Cz cg$k9MD㜵` 1FGN= fG79=3ғ%^yoU2wKPI2z9J|S+/Bm)F%␽gYp\apiBcIn#ծ=EoBQ|_Jݜk mv1{mˆPQK%OI9FB@H.L!_Fk\:8Óq[-ZLlOk_smN)hdiffԘ*>ɤฮP<+bEͮ2xo\'>s0x]P3nsp?7j۝}4SaSה06q/$) ;lma[c*K n1lro/%bDg|~p`<_h Enp101V%GY8[XD'c)zd*]}4s a~뎊HօD]W2`G§IRvU~Ncۋ8/*:@ k>fO!dwph @3Oko;lp22{y 4` q.U.Nha27[!-dlBǭmHGq: I1(pI]SϰA(U)4BL" <j<2!rkP/Ռ/}O Njg"?5["5TV#-; {o/CsxMf͗h}ӿL>VuMByJa1r*wxH[Tc 1u+^B tdwA CO(=ۢH1H۴ѝS3({vW3ljyohO2g-۪U-x{a,^"©iFCbUp@Jxzwe˛ev2]6juY(~  jSb/(d"}]ǜCLx}i6FE$V"2p " L>7M* TOqŌoil||) CWARU¹%S 9B"&;^Z}Hg"11-gg؏8PU-џLiS1ƍm,D'=C+jƮ_!] [>mY!K5>Kif @!nlasj\" ]_IaeE|yO7փ<y>ϨsFk E!`~ha1%f$ lBgrH2d]##XxDWˀ$zJk@dFj0r7hMfC$T|R!nR;Pp6c$]^ ٪/=]Nt 1~@7Slp8qRH7aeYzo~UGϛJpS4I8Ays(Qa˶>Wzr b}|:# m+9C3ՒR{$a" h+1ϏP=yGS r Q=x z?k@VS*-5w:apbH/+bfA|t۔?v$]DqR+82촡6C.K'R尭#HɱtI Ր>3ݲ5U%+vQh?g?6<'tp2iXoB4Ra"ub|"o7z$VڨHvoC {PDQWBHeG?gqˍ{=ap(1?EQyPM] 瞉Jb ETN$=akǚe\Ӕb.yc|ľ-}XOq3a=&w~^*Wo I9IGã %ԾH0N!4hDGb,ˏZa64R \*gаX9E0flʁ%y-csjP=u[يG1hN/cu.8q/XŜBgEӗM95 0NgY!n:Lv?*$=Xي)_ 5W5e20'xc zn`v=8|&ХXε<'+w(#v+ɪ+@k6_Hx~)_B".V&ﰘbG3sTeC({uiybePա6ҒÌf(o΍@ڂo.iHmT4t}E9.D{*GS^\/C bJ ?{+TʑNՙ?W,MVx˖f$Ӗ^ΠlȪ,|Ec*^'m8Ijl{5d~;Xƾ6CUqGFT(5e@jSpVp/?np! /Vd\$h8iuorI108y;ΜT5h]E2n#w`baF%YD^OeY|>_ >=\aF1D¥ &w Lf ΃See  +VTBS'̡C` s7E sY**guU yGM.\o^dsofBK y홣,%-i̋t9c*=j_EO-N%fMV2KOc._c,Tg"BV 4۾ [ v LցOl+1M"b+^baض>ںPXjo-hysbj)J ҥ,7o2=;9fѵi Y۝MYQ$L9m`t dO3` 'l$v"mؿOo-{5 ԼXJ.~(-$a0GWr#(r2_k?J@-pi&|ShJUH>SAc3pT@B!2/idcOJ v98u~%dѺ[ pJY TqGlmcV(EdUr,>%W^pl+.YBM3hOi MtԺ$`SL8$͵\ܩ==bq`qlk倜4$i aANxoi rcZ9_^y'>+,FT0Z55iXƥ q[׬|7{]#Y=(J=Y٥e]e~cuwe?lh?:T<ٗ6D ^[\ |A >VQE30?#;ޤHvuM|rNZC|V%Ď= 5?[4,OE<E^רbh>q1_JPLÔ_dqD]O.&j:_oG&ҡ >ת@u ֟xɲir7Y踤ě$|ԓf eT=iӇ&D+ל[]jK/%V](WvbruߗxdR#XNgWWD~2kvMPL:e `RlE~+W,V#5SkL%ЅyԈxͰ53٪x/''s@ P[4gɓp/Mx q)8zO}Z뾵Fӗ zX̡ .60nefmN$ t-8xՄ%7S˱+56J^RwplR˥Q:Yx%H6"ro퀇LJe/ȸ$q6:K3R^z(Q8EuMȨyWPoQ_g1bQ|jk}HJ#KV}(;ŢAu/#emO\ƾ]I(B,>v_(:;4y*T,֥gPng_׸&+U_޽'Y X3b$xl{RK*Ϻ"(;ȸ\ဃmpғϱvťd&0P53-.[\/?NTE/g@pɡ4N Iz *TX U(L 4-j <\ʹ}aD1t1r !'ukymUbJg򈐃Y$'*T-z%: ;F(BAF][A Egzx"7uæa 5ޱ"pT7zdS!&L V's6N,nA׸~c+d`MWk:LdZn/LJ=-[@B=`*|q E?k߳AE ;<*pdiT㛫Oī[khu)Q-+/6 z΀ri1By|S1C+|' r1'1ɢjDAY3˼MO8 2;&h8TO[QVnD~%'g5S>vنdž8heH~UvIw%IPO+-Z*.mc` hor0;j5yY8xMLWBus.*er^8']:[8rƞR;gWq!:'~wkſ[xL|'%SL uoy3uTWr!zJCFNMXh!Ծi;+BX y{# W{1]ɤf>3N?F1ɁmBB_HpG W`)Wi(_*B;6ႉ'dUϖ?vC,z */o/5@iB8>dPgCGzvUNEƋl/6)5pK/wpbE:lؙ+y)Zo|Oqh980,0v̖;R>8(UَS)e ?N~S6p!_.Ɔ$oMҁ13h\lW2AY,sVWlhǑR)!B# MݸT"9X;9j 7XEBlx4 ٤MjͩP'1g%BBr:g!nڠ&7A9}' 802ASܻC AĂ9菹xbr&D&8eF8rޤ}R^?H+y ^h`hwڋ*<75UjIaV5>t 9 ! |z1;],(4+v٦ƘCߪӅ% Kл~`LAH$#$nsRfkԛut5eVS"=f*׬:.C^x9sΗjkok |iDw栰?!&*;)sB+/1:`-0ZչexW XfM>1ndfk_}4s1Kg$&<$_7 9ż] 뷴]~$IG$ ,M:6HFa{uOÝǝ qRpQNh^^3]a!+TNPܫ.p =mOGBM";b6l*W]ׂ5W- |RgIhK|4YqDI {M8Uvo2;Xe4Ӂzyej00㒘kgBn䖒D#B®&KI7(&.C o œϴujGT?Z'u,<4_ J33mXZalΔm /wn[9ɷ]gU*͎P6P7ʏZg5/шmJHs.P* d^5\9&.J ?Xz#T %RѨYsG5"F#+O:E$+lBv!$yS`ƭ۸f =!:^ EOKppFيkFk}pӁ}%\Y 18p^!y2ca&ɔGuFM)UJ56u@(>T(p()^F{h0>oh̙XFqUd÷UrN׎^Քȁa$tg*C{BFPh`#Np=zm5 FݬN+h5̄x=雹L::i#4h r֬qO?=[GE@& }cEN0{4>Ňՠ@X3"o͟C݂r:)`ZYjvZ0 rn 1/KoB ˾] ?s+EMI(>ṃ5 \iTl[_ų!A>c4$$W+ k_@Y9‘5 >i~yIU ,[PSj]^.~1K4fFt! oj'[h X][#AOH*E|.u)o%HSjL[(ZgV,橒啽3Y|~!NGelԤ"R* \0k:gm]fvDlAМWC}#e;Z~];wۑ2?ꚸfi=7lDZ__'xdևΑն1Kɢ nǤ`W'DiSaD_x2׷pI!Do(X t/Eq8rkS*0y/{{yxL^5*'G*L gxw{+ʼnnABc -aߍeNpPQ3h^I\  R>3n~N2`_d?byړ-C2U ]0rZKU3cOl3wXHhQOr󑫹qK%˸V=/:bLjJ>RjVȧ3/Y@=6gclK6!m&eY@a棹5u^M_uwrspsBSS{xw|,tlA'\VC"DI|\ .{7XT$J3MȬe3mv+dQ%PSfH:i+هn/y:@AA$Zcӫ =݉D29 <'I Uwd!Z-CxH+*'n~sz_:6Ce֎Y^`3+N. b[\30h,,C?IB#rzx`X. O]xV,J$ b)̦ak9 6mff|,h;I3hjҰv4SɨG {̕v{A`a>i)b;c?SNW20h"!b]zDF#anRlVg|R?ί v<(Z?!)i0[_}WOQrf-bҲoz*Q^F 'ڸKob~dq)ue VxֽJE!.fF}=?TNxhvǟ,P;*Z!FK~B4A~ v/( _o`cԟ=_4l<2 y`c YjlN{<~WVQE6s+^t :$H ֩ 12 0xO.>as r~a".&h}v_(kGSwo3Q,S7)knTrGT$wc<"͛bLIk|.O}{hu\(]wTwu)ǡGUF1 Wqń%Wap}Y,jvMW3b|PGà Ǽ岒*~'{QrQL]&U(vQa R-YDpE1T~H4t wR]BMs؀)1޺/[jh?Pmkf!xi "} %0NJQg'E#lY)?07NS|M&F'g>qr`ˊ5zd#尩*=Ұqfn1 F-Cŀpģ:W2O`V 3~GRkapS%$^](H{~^OIh:3p9߻[/Wm]B]CenN| `oCt?s6I;Ŕm}^ s享< d`XZ3!꧆ܵ{~Tτ_=Dc^Vи0wpa:h}]qD_ͼ1ROZUY$8;'x%Zs ~Q ̚GPs]4$jx(5L {P!`0V8ԁy; H|JiFO^%ΰۓP+CsD6 KsWcSq6.>`"چCtgkkzEw#9*\K#)8i WØ-H{].ٯڙ6kA߹vߓiG׺[Nݛ>>KQE(e`Lc8`U$HX ;BvrI0x@uX<]d}vˮHA2O{a)֙jYsBT3%VBrR B:PUIːf/<ۉ$Ks40QP-ɌئF| f'R 9۟O%f>9~QJ)4|fDv۔SVo0ۯ6 J 9k[nA~2m7ސ|YR,,>- ߺ(Z !ALyj1]HqgXswfb&䉕-2kQ<,CJ_zy[i̗ŔwֵP>kБH7_H¬gitƣDa%z:m֫B 'Gǒ!rytE>ԓ+⌐.z~ϜwC͚VcʃFv ѫko&9)@'tCn;bbEV|%SDBNaސ71'Լ "aL 4l}W' Xl7Ж611q΄5@PbF Vtfym}sMX<[??Oz5:GQH>3_dQK.?B{ƊgOs_ N󆤊ǰsC71& %6 [mאU"y@%i(KYODh+Y΢1r7ɋ1vf{-͇Ir pIѷr #Ttp@87ût&k4_2HׄM( wQ'H#vd]NAg-HNwFoH: Tu%z OpMaeӒʣ&G VTaԹ:NV4I%j@ժϵfɼ;nQJ9X8 jZ?r^f׾;LvkIEex*2IsI q}q(ҭ$ :dI4~z> ,q)YArUZ!n ^g2K(JnG9Viup'r` I/;x]DH^6eC@6=y2eq#,ʩͧύF%eMϳɌj|lo` !keU3&GH4 9 Yͣȵmx)mZO{Mn+kTcgp#)vGKO'&e,̔bP]t.++2=]-$Fbt_G^zRwx1[>\^(C 1U95)@Ćŗyfw[6{-EId<|1ey#ZM5Gp-k >x Ax(3Na$[Jwlf X&NPnlE8K>[5ƽK=}\^լ /k2,Z{ gvg$baODN&SDhb"Czp|us5i!t2 [ցjmpE"5/y .0AbM 7_UM6%ua$_k _q2c jC' wYƩLU9uYPi_5#&d:$롯ʤ&·%DL B e6{sNR}_&ľ39;MonP͚*%P'lWm^Шrţ7+'& ?GGx+j.ߘ$nn|B9oyDwOy+dV4TζiFCkZwT'^j^<0mvoru50C:e&s?A"$,':Un7.&ZYI, j]$p lsLr&/C>KKv.t&@e<3û))[9GCmn5|Kq–بD9ճjՠn} cON9x|, w* '~rt7P`j;Ҳ)$9hH Cι4iu41ۼ ia@$י/%ro :>JB3Y{f{I@e )s 2MS]狅hF/<\(O~΅t$#PDU W3DgG1,xgy3 Ž۰X<@0qk#AR$'cx߼$ƀhRj 6x1 HҌCL2HT',` 8С[pR1;e} BDZx:9 4vn´v>qAoLZgl<ގr?>\-fӥK~ծ+\RJ?(}#DP w^e; rW4 dUL!nz\iʋg\almv}5.vR V+~:,b 5")d*#VIQ6'rCy1|Xcb&gE`s] ,%x=%@uqJ}x L@h4!fvVu;}Gd HOb )pdm;O'jl]0VK_>;Wԡ]Q{KYը8=:/XCk\X5],= QŚU;e'OV^ׇ>èztO Tvڃ!]cTX齃=ۦ0־5q| R*8C>fP2)-pUϭ E3G;CGXK#:BU{m> ?>2/t> r(k' 6-:ޑ6Hܯ:CҜD?Xׂre~w硘dv*UOISM5XpLﱟ= ?%\AȄ6M+=~++dV[ӈ/ lF`]lYRJv2lia\IY\B9r9.ػbvR}"۴]ZPψNYM9:^ln|Jn&}wU:ny])pOc% 4fjn0@uq'*H屼vf[QbW?78J~_Tpyk`(CBéd.5Xr+f1# ea2d=_$X_ l(X/6^60Bb 'ZՓj}[fۆ_yRu5H%XUMv<O$l)SPc\J 2o @pO?V"ctR+"wzTKA=f4e#Tu 9:p 9z%>ޑ[nU5t#M㪃,NZRX2 !$4xH[ r]UO~/# BP17z):@Ӧ"|98F\ܑa~ ,Ƹҍi"䩱LzyHǖYc+}>iSx[|^A$GQJ&+N{#* ?LF_@wθoS_N7DX szK TJuaU){=gQkB|ִS59DU$I./h?Q1"{ť.'e0mx{2և j@aHu;>_e!G!ԒF"%$T{QuXDʧ'y5/%9׻/|+Ώprߴ:]5l ީٿ+G \P1m5^~ NЬ7{vEuAZu90f"''5ҡϥs mfN{Da[Ͳx|| Q攤NDM.&\&C1`4v-Ysw 1gՕZh 'kNL4H?06%#Z:8f'%Mnnp)a& qnEPt25a~vy\ҥR,QBQ<^Gn梄W]yD ̣dJ1bkIڋ/q *ífbX?y!'Ce pA `Ӡt'-&%705`P%[@BSx"&D y"Z#O3p 4qbJ(A;]Z١ f\bJw%!@ Ɉ;$vDKZifi}%_dz->CY{H_H4܏2Y(8J4SaRBJrw!6q̂@ קW  j mÎԘw4=Kx([#QC@ w,Q1.5Ҏ[qu@IP/*miuםN PML徂\4z7cG_{*27H88=GP+!qu!΋01B<̼bU'p'͚t3ŤdQ:.JPݳZ$y~D9¢D/UIz8Q:~|S`YvM7 b_88"SE1ɷFH}k)e1ɪ. w[L4ܨ`B>eW[ yHU;3 sgD$0^(-hURb}*s#,3kCbc&:vin$K:!@'MTUdžx{Zt Ӭ3ҳٝ VD¼ME#2\r#ϊ ՠgJLk"Q H\aEb()%`[>T5 g)-\9NoPTј, 0A~NKIdG "F<1$hIQzqA29]vj$?V.k#ށ_݇ P8WA-uA\b˞n\r'{=Үv IRsqǶո9;1XRf"мf; Z@q*mxzZǨ" 79<\4DSl^Ϯ]*$>Q0IwpFT}uKp<]c%\b˲q)QFW㠗)덿K(-C ,ά֯Fz8,o61ĝ4HC 39:y;JptzW*# S46a1 ~:'Y.Ã/ugiERץ(x9GX Vr#Bf]w:h-;n~eӸ@? !Ps_Qjrl+!WpRJr-M!P^o_Ո(x޴~ՓV8oYྌ; 2T;0h-"_C!#$ 7~֑ !H, =8%V@ԇ6N=w6n1U$ehl@AX <*~ NXHglS-e£X|#S*_|~r4 stwk C!"EܤS5\0Pj\TZ8jN~3 ˡL{apNJu920D.H5 G)@BSKrX6o#Wpۍ3垚~1`Ӣ1'Nd @fa?NVLƽ(3Xl;='m{:ټ!QH ETu.s!?wJkMgt`]5RT"QeVsD B7B<(IV8 "a%]g<іҌV5kҢ7B4lұHqϖ. ,ݽijc2(h/2J:E N}=êBPkR@jSJnprN ƌ(0tE^KO"#J#_F,&QWLǞ2dA(|#U5=9roa]y:dޗb~45k;A(iD5SAFDn6y E -5I!+Kp (-n ݚ;{uNWs,èiQF@5Qt'728-rDztJ2g!qq[<6}Zé?v$FJ, @qyާ%֮OZظ2i:ҏWhEx))Wa3I֯>9)4xh;S)%SYfoҋ$UdsQl)T1.z2Wr1 BD9EWU~?%H,n:M\1(fry|1(4O?ΰ!(OQhWRT;|Br f-)z0)6G]L&NҭF|ҴDNuBɳ҅7&[#/W?g?iz9:M?"Y7{jD N3s><-nE=Scϊq|Ds]8'Wf`0-,E <8R /05N'zEBUfc_t?@Z?L4-$7:c&9>Ѡ_GBy2(tbm(gic`'!c0]]TNO߹ A48>0^@zH`Di8gS~nc}j|us9;nȇt+?Q )qcx筦4yj#Iv?j*Cp_9-{=r)y~G|=;珀aeD:SQ&>ÒW eȞyhIc>`` 5,SҠcr7,KQbs8NLC[3%j}!/L_̴f:2m? @HK3֬Xq0ʂqjAy؏zɫ N~r*%Frдms_Dtk,“l. etxp5w.`oBD wXae  ~rN)96UG5o{RbMOkj9oF}f͵sEIe>u~Ÿ/qDBÉgkR> lnO+V-b`ϕ/ҦeXC/}'k;K >7|߆Jr4u'Cr[xԫOb i_)# }2䅜.{JA9rYCilPl}6QGdM8)'J'=2р1y׽JᏫ(~7g@RQ[?mCj8mH//}=UA}29,:W]dWKH͵($]ݽL;H^T2U~xP?K 챔e2TZω_ȓ1JCZ] #qQb:bP=klKۅm8Yo1\? YzgFY24(_ z@Kw.tW!ό"IxA_ ֔͠3ŠFru:}1]"S/A7vu"B|+~ypJ+R2]=b u +dȯ$ب19u`w_'s])|AH|=P1kH,p_ØU$2 RAس }a A(f+*m?|prM^5YoE'Ek$AWf"L-jVScVY2Gx֗AN_#'E | 68 ^z-HWxsf u]iCg0iH."Շ; j}{#M[Cm=MvQ"iqH,^GD\:!Cz=uOeao&bPZ* ʬa %TgS$τ=4S=YG* 14ny @"mb* e/]UNkۜ:s 7vYYcxYzpM77e:{XZ$Řߛ3 VgZ=#wI1q S__!O߁ypfŒ?HyvdQ`F44 8Q5^&|j+`ͮ 3kҎL$Pais:ޭ Y/KDLh_Fʫ.n2Y]Rt-̯vMpm6灎E*S03KVc 0B" AVj>crWc]H@kF<]ZV]_/wEhyGx,7ȷK1Ne·/5wllUЅ"5Gn=$O0o0H則 㕋#H3E2 lG͆:Ny"cXH}ɲ䙕p+A[0S)}h[[UeJ-S]ڢC` 2Y<nKSا,6}`7C^?x hf ߂vH+gvГ~8]9+fOFSo.OӶcoRyz4E y:TA ` #0 ,t188gQ,lK'Do6!-7 Wʙ×칚+–jHFdhdlВ`}V>atM@Ne'!X聳(-S|ѢR[ҌDi2J Ƈ|JǺ,CxU1sR\rO4HYXtp^8H=9{%Go 6{e U,̝>颜l5i(ۀoﭿypW@x83RR&u2˒ܟw6˚|B`n"ϲ?wYR7]&_$\]^hlUci!>3^ z:!q.+CrAË0Y3c2 =08g44(^(W-i͐=@G> KW0sv-KGG[R׶r " *vk /;`suYCʐ*Ӝ;n:ϦhO=`|)Pcu4ZւeIC*Zo| MI%4U06ٕ9f'kfC|t wl:գ] ?c$~| F Vی"bꑵβXcENwx*L>b>qs`"tP1j[@!^0?_}V[xFg$NM@P[VFm,jݪy7rXGҼl,(6#rX?wx<="{yBR e)@Hv6DrN$0>s"ƌTSe/kw:`z>0R;bT쒣}vz4 k! #|'EUw{qq/ubI _C~NuE0x΁#>Y1KlŸoQX1ڀBڏ XJ].(!2[Pu(ag a1$?bEVnxӍS1Ɛ|*%9 uXa$+ n:VR05zGAjoR}eUM<{L. Q3q>D=#*eh\=\?<$2j \ NoA]3s[xoYG舷GP봙u3zdzF+2m׸ Xdz32YZ򚵥]8Ui74bwT2lҔ$T]Hf-k@b#m*e7T'k~㴮֌2y4U0xMtY$Qey ;*uVQS _Bt<]4'ivߤcR)r$3$^dEc9ZؗdHqNhM6gYYM&m7jWiWt:ˋpmCG\,NQ mt>/ij ꗲ?N"<"6E\1>y{a Ubvup S G0T9rU`V&יo]X >^foBM,3b(%r~ a-נ%p->ݞ|rfQ]v b^YϺF٤*5nXB`-5fȧrLa{)/Nk3~i:(à)|vdR;&^50TC$t)qcA^u%mݬy̪w o=SwGgٙZU^<yճZc&D'sJ2$&s5Q}@II Oa˦nu/>m E8Sů ý`m P|/B9 0+7pD0 ZAJ_k"DLv`1錗(qxi?L=#BzgAj\N37 4.;y"o-Kuj ,Lf꓅/e<:{R> YGn4C[N9WģaVA'{\`cȧthD]Fi;h#VH[g50GP}*_"BNoSJaOuWYFd6#(Uk$ǡV ̱5uޡ6`26\:jyqs9'K(3,( m aQ%qcGe7ȧ'CwYqJW+ f{wh4iMk.xΏzHIZAi`پ%)5Q:b|چR1XEvYfr,瀣o[ ŏ(/{Qځv<9d+2o\H9ƕT>qsxثҠK).k$QG\1zw]C4ǛĞ %FvJ;6U/^S80@%3G K1ٴ~k*un*aeieWvǨVU 1|syȀ~;/+-Vy)y$y9s"` F, "XӜ-k6kŁ.HqE3)b*\ ͺz9a ze+~-&MTfF )i%jn|򰥶.ꎶ=4F/cc &!+QS›fYECGb -2B %D0fc,ka۫[ oP+nzoP(^,!'3Ԙv;XCķpGMԬ{ +RJl,Tr*(Ȳs0z :Kdj귥qOm{5"V&#d;<ą>iGkpWҘx܅`0@|?lY^ Ȓ+K.~pqg֔yyp>DYn%8бuyXWhdxk^.-? 4?w151aM*թX| r3\g8A\lY8{f mvuU6gJӘPژΏ/0۱RqiwX xLyr8O_'EyU)-WD0"n F긊;ڳΈxνE{Itgid q[07d[fC;q~Sb!4G+V:fgZO=*X\.U`=ֿ@z aHrP%BH,6I N|~[B kZ5(Uʩ9mmŮNrgǴ hjrP& f8rj8o2vkɎcMH PDce%>Zsi -6Ht"͹8F>x81 \CPyRι Z?Ȏ0&o]$4'aM6R6Z5dK3+4b;! ANdTLcosTY;*+X'"< v`ho ߓZdd;,~&JY犧SHnykI՚%ϙa>GDL3 רrgFbq\#dE -Ƹim%Kn(72;$ M"_l#!殜j} wifL Oڿ{-HfLS/㼚E=/1ᎎF`R'`!&u>̱=7HYW:ϵ*htHV[7!4TZ9HgX)H$YLB\ ;Żߡ[JДM sb >FH}jx3fSHIr"x mP g!ҙ>\M~*9) ;a_Q|q3NqʠkyI|+S<RlOo`%1b--WnPJ%D!Ul ,h~R7\<޲ȞuC0_9~} +0jiD2:R9e8՞ E5p^sa Xs7H$cT-|dX|!`+":]`GBMSaZJ-pU?!Ԝ*LnUf&,Jz0 UT Q9RvY~ 黚{_)&{*j€0[sKUntߙ>.i\FAlƸ5q؁ٜۣ۲*O93'/I|Ri͟ڂ'ASy6FרI1플P)0A Sk0bu(T} >{h8KuGKPI"rȘ+|k-cC;.P+OcG&M iV<`6P6aFoCiYGdﶱŝEԉL lfT(ޡWtڅO"23TL.*r>ԙᤫ^Pa\g.h#cZdZ>(c b=lPVC /e .:`VJVqys[ߧ y&<9D~1ǁ}+鋀.ݡe#?LdzQvhV(þOm E]?D{GdNf&jnd\ uTm'@D~4&$j!ԷZ&1g+!q3STOUװ!d٣ xdž!P̑/hhb8iu ޒqn EyAhwO>j.`h2iI(E]?J8n:P.\e FkDb*1(5|Bh>ƩŔȑve|R2lʋVWK)_=x ,J?8C3)1vF QGWx!3 }x@RiR.$4t#.MjlK1ac++XE"޽Pu!ܸH "2WiOџuַ]dqkb*k#PIU:s=-WU:< N4j QD. O]"˯EP& QW:*-,ǐ̊Wch@nN: y-P9P_!Ie6g-.j1~~6EǕ + cvFH_.> VJ,;JMGaʎ7%FAp_1<&nbF8N{t&DoV/˶$ ,EBya!q=9N8ɗ.W: ۅ]`mDiVSS;}m¶9/,0^6A:.~H}G)9vuU5_3 rbf%z;XK /6{q8؁w̱D뒙[6N|K^9J`ery@jx?svm^, #/s|Pm#`FM5S+TecQ:C~V@ y;[щQ.*5P-Z%9@Ԗ:)e|WY@'8?J;wy KSb밬"2jeµ[L&<T~}F 1P3xзw}/ՂY*=Gsx%͉l2m> JW: i&yvڽ/nIKZNhQ0B7U—ׁb?"|'Dթ;̲^ =e{YI[,|cq(p/ :P~@1]o7?`4;/qg6(]P-0MPƟƥR偣@6|u@Q.r.8/0#5C tl62&(\ Cƽ{2ht_'aJ k# Ɩ5:|' '6fR;>=?˺f  +> yP3= (޳!Ǔj<+@xAD꺿i4`V<=f{no̒qA`R=vGsF^T V)un&5zc-U@7[B6nhG m- ~wS&HTd\:XuEQec SB<#Ͳ~_n>%]v{m񈺨(gWrEbg7K:qt֋;)udɇJCg+.:J꟩xBO곡oLya) ṪZ- H~Hq8nA;ۯo7g⛍/ ~aB{Y?]=yA{s}UJyȫ:|v| P& Bܼ$4tn&$ lMPQ ;s{}MjG;FJ`=Laa9,R6l >pǽ}]9].M5L! Lj[dB"^2jʉl7',w^%pϜV ilv 3poV(q5崢sF퐟c=a҆ǀo o 7u9_0zJuX XQ1 8w*"ӎ{ O,KxSs}qhO@Ւȏ!(.fI(-G [dя<A[DV1 Emrr^ )ص)>QwZ]YWW5Xe kI xIľD~*YϧFrX} $`K靼l]7YX~=dUTM 4Qv:}ᦞ7ڦvL6S@;{c(hvM2 .# |ޘ=0.^u`.A>.*ٯAe=lĜ%1d<_4|V餪695ѻ- _Dcիʨ4]^!FuSح2p~9n/8~X;iNYNͲv9'_G$ߕx‹^kxi8Ѽ{`I5m8HeIG 0{M ){!U4Slt͍ C门@H/!~2<(Ռ+lbGPŐn0I=c#-[L>®.[e$%;+Hm<]h`ބŠNcPF}WMb]s*y6PԑOw]T'uxp@EsXQK׾^QywEpf  4[/k6 8c&j,gMHl^*Nc '6l+!uVpnl2q ĊtwG5|@QIXə~%L˴E@# lz+y?icOn( )\$ÛSI #=u\ k66p*!ea"J<c}6"L~o:/6%< jSd H+txqj^C>1'9ŌHenBK STcdXg>{mV%n{ SxxXuՍ_#QvRF7uLyFq?A}9͌`|FA# Yر@Dwmhv+ RCmĔ2 9׌2nqʚb u71lâV4yN ,2 ]ZT!P-|cƯ4tiYdux.tMN\꠵W\AthwV*ԫq`ȸx oGbz:w{'ҍYB/R }'Y.bw3$k wH i[=s EHxN $-M9'1U^1:lJG(?]3~$ǃCi=;B+g~-0µX!PmnǪeu`UH "%rحB=ǻ]7p#$KǞ-7h]A;{(ftB(\RK5YOh+]-heNLGR1-k8-vc^"+s'nyS=;*T•$.,\84f[7 ?mQ±?jGIK\lפ蹅,1%MM?}EA@[˓eWʡu͒8 JdeԿb]{)l-Av]@sD"yc5M_tdО<\"Ub l ~SeL /0{JUsڍ^~K'c%& -D@26NHw,H)k|.1 s @6W4ϖ.{=T<(pgcWukD #spzqNu83J'>.sWycji=ư%$ӄ8e^ 64BvbڲFWs+83@ײ$Ilܫ^HRv^s͘v0.`;O ~/7]Hk . Uo*v>2=幧Et-bAwo79xF;'mHcedܻ3gj? J) o/$dE8m.hДF%|Q{B0*O*Kc <W*dWײ=et5{Ip(Xp5&%x7ks;dCh ]"m[ti2q>bۮ& $={/LQC֒WAy$Gte<,GUeiߙO1̟Y-ֻ nOTY3$%6v+^Ld]۝jC$&|'R6=x\#пC/0h?aЯD0T)ӵI&)—wy 4] X13n|Qn:C&pr\d O\2ke0bF6b8#1(zO^}Y`n p&Nj܎%' 6\\qS4uu*c" 3ϑ<V]ʷJڋٖX&ԛ10zʔn҉XQք7y/|ii_qeH({٩ ==fq҇2t[q f/wب"<*A(%3J 1<:< \7!! OZCqm^Q;_H\~bB$Xum>dWҲ@sL-<0JK:LViCPbsEˠ;o.~s  ~^lS1D9g7'%Zа5],aY%K!r1 yimqQNnVE[P_0=#3k|?8ZZ_YM [}RŜ ,,TG[%'1kC>/ l YH*l4*̽$]bKW mWFc7v.B 2fl86R{*$5CMQ+e$?xBkQy,ۇw{P<}bAumIRLiv") k"5Kwo׬E=m2)`!'.47Ms`TC>l裨b֩(9 킈:=ɀ o ;HBjFoіc栛OƱx2۸Rvߴ,gcڱ+_;REd7v8&7v{yO <_AYhF-<.hbG]Ale(윝 g;f6Q&\G"DKɗy7dvj#W~rq5R%2<ekm 5PrZ$5x&,Қm ohs/tBN^/ JDMtm' KFCqJ,VDpE8vpzv?>ֱ)+c%w2`٪Qt&E.!p^ &V8=.rUAsKI,1x6壅Lm,zVݥi>$`=H!R`ZpkQ:vN%7v%ݨd>Cf}y{نu>LIZV懖ai@$ V_^\ғ‰0 e1/!y/"=sCS6ȱZ+;^X$i&GX$yH 7vx)Yj] HNDóˡRY 1b<ðT&HA;vAeO|jo>@HYᆞӄEz`oi0VC]x6dD5l{:/Q{2_"*D3jT-.f0bPc *))W6*K#Hec^2 fr}CɳHᡟ(֗xǺt*żNkk}o"YUsDz e"sI۶jޛgtP+8?ẽ4\4Wަ*$6_]ĚPV9oCc8|qd<f_F(aC܄vnǓNۡg!г).*bi2Sr,ڏ9 vO'o<[&U(D[( m*=k*|,°X!m׶QA~&Ԣ.8=SN)_no q{N`{K\2aVR*^[؅Ys? A4=i,C2=-$BLֱx_LgfGnimc=Ss rwG&lJ+B';c.u}[kR7@52% Qs8fDĮd1 m_Hs`SwQAzϴ`F,TC0+!!yG*aSm7\ '9W̊fQx:舗:H74QBp[nF`2{Z1/I27)@Q1#S|Xr,? tS1g"k*ޱA$+dK\+ )nwV7[OfoJS:;A- q1MQn46`U'EAS#-}HԺ{7=CzE5PѭE>[}側YM/ФɌ-O7(FQLhpEӐAv# 7~kۃ<߭%.CvlvfE8݂s[{Fl}d{TYB# GvxU9銐>PU%G/dn|P\QzY9V_b%WXUm'gg^uYIL@jiC0KidUO4!4ç{7]q@ U/-,L'e+.¸ZDS7@+ˈΪϲwG/WE'4߰NOZI&`s xT'ܧgD D켑6jP5jc #CJk=e F YTşHe՜V_2P) .'"u_BřB|#,ŽkH.*zØEQ5(rW&Z-S$8m!QPF $3pf}vyHW48l,+k Ez5zJs=ol$Jtm@92i΢&\oR%=̰VE܋l s<3qb/}Qsq\3%S؛`R K6~^, fMLȴ/!xnl12#g$U[) VZ'0YHSEEI"3~am/7bGљW'ڬ3+f`o^xܯ l7 s1jKL?r^21KXYRWpىXh1oZaFo c FC Fe JaJl5ʑsXTuv3 MLiνf˨4=z2YuQݜFm]zs C ;*8C>b/}ٖj}Dbl2*oPƜhNy't@)O]_ފ 6ъHohzq̠.d -2bR۽3(* ͖φlgտ)s網6^|;\o%-ӱ+*б?-Te J{pg<Ժ*?J.|}`H]"KБ7N{XJ,#q7\ ]k,dvA-`Q̄zv2bW$`Ц2Brs툊ku 4L