sssd-kcm-2.5.2-2.el8_5.1 >  A aU]h  >Z\K%{S».GqYcH45X&0zְ.Iou#cl&fT.CGTFOع?6Ϟƭ5oFu}yD!y80qd myoY/zi}|Mߡ_z SF)1xX_AaG*\J [i LHґ]!cn|iC,ԥ2ˉt31^ʚ.*fA 0O ^ՙj&؟c<]0&`I6+ .)7=xm^ 8.JdTc Mbv!DL2| `jo lt5010daddce27753ce233bde8250b156660f1b18a7a29fe94da3d050edc2348ac47fddfb0a6235ca534ea8df2720cf9b4b891a4e50aU]ÉCC 􍆀+>b4ri*۟"m`q+T"pB֟?WyJDWUǯ:a%)vNUG46Hm4Vbl=_w bdX] zy~vBG%۳b43{f>Vv$bb?v)mzY"0͑~k#-A=fdN^))Dݥ7L`l_Gaي 2VLݵLn"-fR 9ՙ9f`?ǂyhX9jěd-ͷ>hÞ?J,(G83@y#h3V]/!I =YAm)A*j تr.0.!-61ж|H_p29;b3l^K` 2N13@W=se94եc'㹸`>8sjs2MI` T |2n"?V>pBr?qd   F +HNVk|   0  g T; @;;(D8L9:d>h?h@hGhHiIi@XiTYid\i]i^j bkdlelfllltmumTvmwoxp0yplMqqqqCsssd-kcm2.5.22.el8_5.1An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.aaarch64-01.mbox.centos.org~CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%,p5@zځAAA큤A큤aaaaaaaaaaaaaaaacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8b4e29a574d0d8fb18abdee833929707d2486eab2d2c21cf074496be2e7bf9daf538b1210837ed926fd9dbc55ed815404a0e7af60d1ef855422b773e06c323574287ade1a3a795ba0dae810608e9915693192e865931e271fa3c12a30e6d127042ee0f8515e9ae9c7f6403b8aede78f95ae725693781204cd24869f83608f529ffb54b1a7d7495078e7efcda6e9a9ef7f3907cc54f8c64a57791667e5f4387af4afea4bbcaf7c8b610c8311849c11b8feadb50355ba251a22abf2e5bebd94fad8acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcm../../../../usr/lib64/sssd/libsss_secrets.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.2-2.el8_5.1.src.rpmconfig(sssd-kcm)libsss_secrets.so()(64bit)sssd-kcmsssd-kcm(aarch-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_secrets.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.5.2-2.el8_5.13.0.4-14.6.0-14.0-15.2-12.5.2-2.el8_5.14.14.3amaa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.2-2.1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2014460 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing [rhel-8.5.0.z]- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh svuk2.5.2-2.el8_5.12.5.2-2.el8_5.12.5.2-2.el8_5.1 kcm_default_ccache.build-id9da6b90c25eb0e8f252b074188e5213c542fc3a9e996ca287f6edefbf2d6e3acbbce3a8b4cea7246sssd-kcm.servicesssd-kcm.socketlibsss_secrets.sosssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/9d//usr/lib/.build-id/e9//usr/lib/systemd/system//usr/lib64/sssd//usr/libexec/sssd//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e996ca287f6edefbf2d6e3acbbce3a8b4cea7246, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=9da6b90c25eb0e8f252b074188e5213c542fc3a9, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)/PRRRR+R'RRRR RR,RRRRRR R R"R R!R.R*RR#R(RRR5R-R)R1RRRRRRR+R RR/RRRR RR0R'R"R#R!R$R%R&RRRR RR,RRRRRR R R R.R*RR(RRR5utf-8b36df5fa94a7ab88b5bcd85cb3987ba937ffca1d5ab3b343caab08a619838bad?7zXZ !#,h] b2u Q{LR~MB0RͲ 1hk E`o,`Ulhڄ?Ac x,&2-gE4؂U { (Ncb,_X֢T\~/n]D.~˸{65hª?aܩ]H!R>A_W$bWIKC6穅[pJiQ W&_&lb֜ӥVzcH" (:6 j&$=hbTky#U7˧KԄFh@]lSO;s cP;QLQ0?f*Jcs#f`vliQ/|I'ԦDK*qn8v=Vul>Sdx Qt$I4i.lk T#~_G^#^̍ 5I$^(M*p6Պ+"xw%Y #ą""O顷KŮ[dtJvv'? 'K um_fKIr{XU%lOzVf}3=rJf8ib)춖zDs ೟lyg4ͭK ^ p C"q~؝7$F~0 Q mKQagh@3r41Eͧ aFl$QA">㻝8N%D]{Dc6`5?uU58ņ—'OgckϪ i68/|CW8I,_tP.V7L/!LmxoA)o '(RƂa0>n3PQqU<)^=<596|3|7!-ikZE<I;e9أ$$]΅DC{^ŧzidbiW %G)\GrּDpVc[@uL|f~2H>ه2 mbQ$FPV _teUڛ^o%Sd@DSHnDF |y:0N*6kQ$Wi[Nv7|nrxV̶2:Oy5 Wp1weNCI)$.7%k A< /佮r. =%̩{xH(yq0Z$%3dM?ַ.BRc -ިAHn 7Rep1nYyo\Pzَ Wvz_Ë%SIѲbr,;3J"kE!k n }<3hwGrĊ .~]F*!Wc2ǻ:f@eQ`"9,ӕ В=A˳Th{4 ܞ=q7:务hzojDʀ*Mn3 Zqڰ?!iYyIFꊆ >8 ʚI4B\2Zɤ4i^!"`'aΡQ+&c7b}p~3Ts)4Hh|H,43s 䜅 (i$<oFW޳XI.LNmH'6eD6C z1 s;bO HZOzr矆V){@:|/poJYS?k\9Ɣbx*y,J^ɳ _#P݌uX0uŶbzckKī6^&MWnsC7FGx^К*+"  k4%+!K]4?d՝F@9^Q| Nꩱ(Z }y%ۭgGr`0Znr\'GLnbGf K#5䘳w5}_1`ΆS;½AH@wb&Sq:0'lbfRyXY2^aOTW}#Kż4Q"OCvi/DǜNS} }\3{K Fzܿg2Z_fG$L#5˜~Ji=I֠D hKt#BO[7ۃW,؇jCB,Rg,o 椄]ϝf5ggHrs_Lh¡GE/&z!t} ݪ*].EWҊ?x:U:tFJ2[B}"~5ի)!F*FƱfس.ͪd^ vײV;lߢD{@F֫\"`|ׄL'r(ڿo}!`{u[hd;=JYevDz =Ԉkꕞ;\DyCDȖ,3DQMB6y?:jx,"Kўt&wLcc^7_kmePw2XN[.7'^ CZb`y\i26/\dŸyf4\bR#3PäA&9ˆ2x85Y[!n`SaίnǏu +swMj.?/aRbܦ)U-pDio4j0`Rm}ANjW< PpT㍡19T31 a婕EWs*|A;׮"*IfhTo΋j(NvD/ !Vj Әh4TMgOl 괶h:QJpx0ik⦈UH][[S@w"}\ |B: #zO^ 1 Zm:DKȠ"T"X߳`ek-0b@AfzʜQB,+Os[&UǯjI~[o-X0%bU]qXOqF8CRB2 OT9{#K'tϕ79{W*?H5%)%]$_~S[:[qNm|>jCs@;-FxNjuBn4 qr-"'rL[.+v2S(q6Z.aQ@qNǖSbI2n(l>1da| 1tq2^{4œNfO@p(4i[pP>K?Iv Hh=R/C(l֢QFfZ=PTJvQ%@]|Sy Nِ;EHcX#>E,Ogf(_Iߒ%`]â3Z/6Ez Tbh];SL''ߎ nWEm6s 1pZxvn Bt*q?-PyobysQJ rJ^PGMox:C8"pO7@ǎX:Іh%h-:EXKmoh|יG\Q,)ɐm#ww.k-3$S÷Lȷö&^%φf}7[#?< \g6~++B#oeӈ yqW\6'@ĥWx} || cC"\-7(8Y)00;IYI☜ 6=]2^hJe dKݫhYkZWZ9ar]}Qb|g&~z S, ByAȈW,0eEg"yU]Q sx|<= \P4}MA9acuoB8~lvrW̟gHBquB#wZl؞nGgА:W%,l [a,W )lϟ WY6Pf~*)B~~< ,Ch/H.}Cjb?-CP]ɲdcW9T[$c{ER?q3 dCz^y!;z4u 7YEIlhBƉ 'rv4ZG1*`]n@$|'}}|ꄠϿ^ʤ7b;F2( 4Y>FbÏr !(H9n1Y3bsb󶮄 Bacp5/A@c"qD]n X. 6\O{"}> r4!܏,| Oi؞XTNenoK J<6pfwz/GAPP VY &a@8ƃ'u?E?ʺF¸IV剺pʼn;vV 6-^ iMg$K$K/$.%coʂ3h#'JZ٘s 4dckV6'<~.°zӁ|p6x~f8cl[Q DH̫:x 1o&W, nMmG_W`8J68)>y|o)\ϩi4f۩+ꔿ tp:Su#y<B>aZzC5 1Ϙ3ȩee fZث-fzbi!Z;M$8gHRYKuϹsY`Pzxei)$wE.WhqDͨ!c.9FE}yGgb<){3>׏HF;-m wHu#흗"AoOQ'#7})^Cn }Tz@W O<5ry㛒u\H ^LFj+!U# (#67E*6\H0+@?NJ:!|o“Nc Ts.t$ e{O<t+KFOc&TcUhՁ )G߲E/vDQN0,]VЗwi{D(uʦ0KD"GN6Э9 #4H\xV?6_vx%ԯ ]TӄrKeT1ͽ-RI6 m%Q./s2gDb0W.%Nӑ.>/6Wt%slY^zd^Fr|͕=x'7{,YXlf3Us/A0_!Jc/BfLd/աzNmbbG@9d"GhUi*N Y7BGm6]~͊ZoNqrp*Ajgϻ-&hˋT7*.*YMw-[q\"G:5Xr O! _֜ݎd3S$b4Mqhcv9vs#SJRyW{h@ ߏ=.bQN~@ĞcCAІe7=E4H(3.hA;ʝan|.( '݄?C$.HLpbZGe2lm*H?^}N: ԩAq<)kT8ODQM/f^/*R$KUt@ֆsn4,׻1ݸ>0vKoʛkZc͑3lc|* mPir Ǣx՚V"\)p$s#*I3EAUW4 [#?eL B"U'>]<3AEM/_OJH6|%oga|+%V'`hB6;1v\Tprِa$Rڵy v*yJ2f}YJJ#e^YcZMYh" i"}{x!+G y7 <}4r"tDT()SI~ady+VYc<1rx08gTELo_S\~ۊi<P't:p!$_s˾f~ɆK] tg]Izl,LS,/vcngb,B]<t.㥗(jp^jDe E Q~W- qn*4JzG@Yʁ~[PDVgMWG!grGsDN$٣M2I `& TqkjD኿\c1]{1KcNn+CL( =k\w%]z6 磊f>1 2uȨm~;1',^^dT(pBMmDĄ!{_Me4Amv)NDC3)%eL{Ub"[[vqQtluY[K?{+V &jU2wDrk_D\SZt9 (蠔\:a!+t R 0, SWc}ѐ?DDčM&=m~]B$h1j@^ *bZhĞƁQ]ٔn^xBxe#,PZ[xiN;ù=ײ) Sq7c+sr6IIPP،&Ӳ*86eA׽B,ɶz+>Kde ~YqR{ 4/ܶ{-Cߤ$zAf5K'$aɘi.DpI")L> Cڞj'_ZɄQ>r VϬזʡ{.~J/ZI41lX:"i["K*<Z;YVVi}Xر,2~n2/c< L\ߊ~n8y$mt"FNim8z88/ֹX*7˖ǹ<IHŶPf ҅WвX*ʳ7Zǻ8U{:jk$ _Wt{Q(ո 2Lfn5gN=){?#y)bM D}q Lt7Ĕo4#UEbuB⯴k "*fl8kb ^` Ȣ9Ix1ک J1~2{)-( i| Ld-)0k.*M2s T^ԫa^ss_1%'DI)!9{F"Dy/z8l"Zω+h,~P?̩_]$Cge~i9J3ÒfNK|l }Nr;5{淔Ŵ-e{@oɪ$깎 &g6Thッťt"9)[̪k]k[$PVzhDYlSulIPm7m|XYҕg& ?)mL+OTAwG59'eqDjMA 5V~8ck0ڢ7('~!LUٷoX{c}5[wJx~3ArbA5?P>c='}lbPͅ+U͖c}Ka"k5_7lPEr_aY`y>볗a>_}[{džw]PqG}A_\͹ykb DʗIǑaAEs`@QASB)Y\6NZw` `TriU?(*Ɉ|5Hg'0SUmY]TRʬC% #I_XrVR(hM P pA-5d)Ymb/_omK";?=W#,:¤ nŠ&\Bf/mk) ̞TC¸1̷.lM (ⅰ k2}z /[u=SıtU$[rУ1A*lYm]̘LݥicZA1gv d0F)H>Ueuk } aS)(Xly9>! kjM2_AÛM Fcz'I.#cvV_B[!e}bB3|BrRQ$AxUm! V:fW_Ka?u6qfFTPtDVIҘb0,ƆzA dv-RVj@v8^d\ xBpyUJ.Nx9;!|io,v]b5_C~xίc,T~&,Pa,e$+2S9-|,H%!(z(ZwcLne:.4Xc=WZ7FhSE_heLl6M5\ˑ'X +F6cIS ϑaH:*4[~)| rwhдqCjRc?i4FnG#YSC~up򍇁t]8E3  D18mkcR b@aqŘr] ݌D: ߪ i8 z!λ@dk̐&|`ؒtinWj+do.h ۍ4n#xiF±S^tfzP%6.QS$icLC`Ε,YkhJV$']@d_)8!#\rc[dcFJ ڳ +&͓)ޘHhfsi"u\dwSee4CO> *CQ/cų%rgfRW,T8 2[~*ؼ@W/?xxJT\C#ڳ΢#H3R&ߪ ">= gտubW$U54+t\z©ɧ׮HE*7^ϊLQ> ^A-).eYE7{|)I@HFA*ϗ!hAz#V;6у;>[[t2R`..hLo@T`1j>1 <ݕ &A;|GmvTNVk(oY€F^e:ϠO׿rA)J/07bЬ~mݔ:wWls⠂%r0[ 6+H\΄Kmm*۠WLL^gyHz 2 J/%gGîƚ OOtJk{NLӑ%%[dM˽ 唝Dҭߙ6Pf%a9af[r;<+EΞe|wcB^($07ǴEœ]?vt*ޛ!my >itm hYzzCPM ͞]}*aj] 'jH6 t~6s |^Qt-J_ WKUPH4@~[\džao0eɽ"F:zulf}LugZV?<;lJ@ `3W.M Ai9Z3"*Uk.T,W& ,3 >kP ,Aݓ|+*S~HWu!UV@A?mV޻*|l1.f/=($t[HBöۦr[qD|꒷RإV$|~H+0 cZhdZDuϹAК6/{}/Vdp 18y9 &٥ v%ٺ !Y4[7 !ǹc5GVs 8MU z9`%3d~Skx{' pUs)r`r`iIBHa(dDd 6Qm; +wJ|f1\ | w1DP}R\`>mW6?୤C+FkJ-5Q'a!?Fs.d~o#=`nIwAU&Fv ;iF)3i!WM_ԫ>,QH ._RLC۴}Bql:; EIv؏n-kD @OnO GΩVx|kzޢw!b@UHM79NzU)DU7 'ke6b۞ZqmTuݎNȷDP(d]雫9:ȥ KL6c^XwXs'i2ѭX9[Xk[Gh?εCR^!rzP*=cY,ՀW)^ʆzs i2k))Z$yD04R̩5skwg/;c'AuԄpUJb|w qFa\<?[r-dbLҙwN¦ɵ/.m([E?qHkzړ50ޤ6BC.4T\~I+S<"SW{rئvPٲRİsEޡ]ʰ#qaTXfdlpH"K#+ML?Q?LR"fCT6aH15&{ -w+v9@M wªX= ^f<$? ȡ_n A?A>#&3Ag}Wuݞ~zuDAf07 /$,y)FA%Q. yД_`Ksխ]7FsT)uwI0T80ZsH __sS۠<s$Uq̯!/--AJe]>5QJ]=ۣX~vS^Q&QVv' mOX!k,"k"5ęB? _I9 GlN!Юq36W _-Gۚ>i'qvpif4YzY \e#P*hqnİzIy{0{Svta6ltFeԢ$_\gdl1] GA4qĞ~Yf{աyG䂡uR:[#KVm S 9^v p*<5,"t\9ԪԨ=^{@Mlb>n0HNQ ըx.|]&*^a>-kڔ i\iZwVmuçܦ(oQuA?~Pџo,zC&ٴ=esօZIhQ%P`ej-lXbja&3qgk ff3~J&'+`ݕz`$ύS.H=3 8n L$Aq{EP_W y|x~wH%yЃD ~F;N0.άn(BV͇ ˨JSD[;x5kwHD.% {[lAD$hs=|ΈMRozW} zϫ͎~Z;y&$0X͐)<~); ;>zx[ó! ̔~@:D,&Vj`sg#yi GF=9ay}9h?* G=.YZPi BP#c3zѪH1kׅuܐV` "ɫ0#>;ΉT# ܽ!KMz:hԶ/yxj6ah% >Ɓxy4(V6xGJ%<`_;\pCz9bxM|pq?%l=^QV\x`4VaV/a/{i6 /8Yv 35fr;1 R-oS= pL; "ںckE&"a=aTȪI*LuY>#jyOKVp\by ( m `rD]Y=אW݃7' '!vB8w԰m%q^)B)]%pI[lJcɨ{'60Ef{,.=6bqƘ}Wы3ive/N8mx{XRsK|G58?8J NZ_p`2,'TyD~@MJN/_:^2Z-0Hq*A@w 鿭`nzGлRX[KGؙġGWVT9Jc "wpړ .f|@|۝E.`r w;#Sx!T5I8elƐ@-[HۈA0&ݵGFJyk'KueгVjy^#4n\;Y-oTZ,wDP:\`g`Dr=JGe7 \σُIg#vpr7 %z4)x|$<ٞ@@٬Z$e`g<gVM6gF _p6x! t8'?&3F % OJDg ij60̧ p!Qx2u\&f Zg02s6~)Xl BZՖq2YXR笩Tb3@JLl=òG+ ̋<+<(eν xiu?G;, hQp0/k-C}|ѭv0ZWnw2e9VN0="f#5[j) l W4Y!TpaPq5lhkh|COeK6n!$uMI E w^GCEG&@Slc ]Mm )' &43?eyhġH<{䍇@}| %4@{4  7c4r{d ˉ p> >J8\&fdԻst ]XVc/q9zo5dGк fz!lƓpNԕC3.(t#7`3^0"4 .0r4(iE vA P|\9<7߷%Y[Oy:*WBBZI[S#3OK& yٸ57ڧNBuIv~-H2|"-,(y_Ud.drUү)O( Ϛ!ݰvetn(+XY<@C㴞N'A#EG{O^Ol2P)PyGSrǴ5/kȗ68ѕuD)2>vئ[nk<~X?|S4aY|0^B=eRT]2*7Xi)~zt2Io[BE"B0/ao`a3]4xK?W)f4=$U/P r/AՄ][quK05v*pkms1Vs*SKb:V脨w;B]KX8nc kZRRv#"!0W9VCИĄg,l@a hq< COvg 5̇IPReI/K>d]+8R 7E:I,']g-/r5EϿ%EQ)l>a=etLZ٧tH3=J+|nc!,${Q~CGHȠ[cnH%s+h PsyrmU .ɾzR3hF/&~`:)ł7/=]4O~N+o' CqPRN;=9$;\'vڔz]{,d?ܠ t>Op޽Zۅ]ea"f>lQyzK~KV.N#͎Gt^dkyTVSoӃC򺐌įIpE]j%igH16{GUƺ| GwtŎSf﷌ {\5htꫢVsリ{UmWra>0?xӔUU 4rWX#r eO#xFÎ\!v鰚UK4d K*fQZ3N:\tb^V3^:UԯH-y^65Lp,nzxg^~^8'H4~wlg^2 j gyK &×&Z} ^p@mu圽s7F][ZEv߁lxu5ȻUҁ$AX76R>=MVy'@ U\!`4oPUW %խ6_CQ: S%f,V{Z M T"f7G3ʯWXq HW0x un:)f y R:8:hSʳVL`Rc}V5b"g.[rz0O)Ϫnefe6:G㮬 å}jjv*g`^ f9+CUx5-`)m}Wen@\%5 oàqnh,o,8= $6X&%#{쐢/4#ʛ3(b@3䈷LQ? 1nqa,vF30`l]߽;̙pAT |Ĺ3p ҌPwls5&mfGGa^+%.B ě.vMӃn^O⟘x{>]xgks۰Y9Y71NKY.bdtu5e$XѬtUD - PtVCtD51r >}~26‚i?XJʗ 8h:zBJI!i&fY8gթU!2Vī㼕[99L^+r;P껦C{s-U_$OX5"7yfI\L8IRCRkSjc{dCCy[0(GƜɤn] !]ًJM qv[iy0越&)1̢wfJ /[ xd֪!&?>#5@^Aw|wʥ,a8<{xS]3K dJTw>=1h)O, rxd5Or*Wμ.l?Q*A?@p|a>Q`[IF+*;z{6R_͇ww 2Пa]sR lU%RȤ"d0U#U) 1\NτiN\f? hv;=-s J&l=]tjDAΓqEL`nUԑ3У]ח"쐈ɾ?/ VI7lxuxť@wd''~64 r> Fs;>Ϫw ~ױ<0ªӜ_.zgݫx) 5HIk,#bCL'#" j~^)ZE񥂹ܶOr,E&̇`&S'0TS{w~0FN':*ʚΖ &)`;l7B/Y‰$ 04à6C_ŽMmW|)cHD"Q_D8EoO#Y()Mr,Lؿ2bW"5#N'Ae $'%-\e^(NA=S Ol'nyX@QRg&oVВGws6m@Dn:v21PZQ KP`+ډ]+.>eq;ID`^|sm{9"x+ 'B^8ۧI/ W.M䖦 kMi;Y9>q;GW } $ яC$%8fJEY l30}}XXe1.n̥~5|Υ!mdxiXD85nG-PM0uG8m7h1rs{e ڝq :/Yz; ̸C"H/l:MkH⓪6zDE! SuLWJ~=::*)v?@XJl:C,=;.`v{hc߯?,m?^E0U/Qo\nZWo= ŘVmAΚl5ɏ R۷UaeXc^NFCMm-)dYA*0r2NDtB#¿7^![xTՖ;9!( %2J3:/3de|Hb(3E"JvE&By? D[fVzu$ݩ^;A=೤ge4\T z6bLNN&c~`zs}uNXV%$> A 0gJVJ䠕Ңfv$}j3V&Ø-:9PM'g,sEb:u*b( EyS/[r8PwNC$N uQuO]8f.[" u@bch(VM(6ơѢ+Z0zTsQ~[OT$ M NM6XfЙϥXdGi:O{]t o&@/ ) š"Z"D+~ g,H$(X]@?孔܈og:B* i iQM/O΁fJVtV~d;H,k"k(Tªat=k3 ψ|-5+MN1j-g*RȎr1!7B{.' uMXhIITA0_cGrO}B\HƸ^mT(Mɝ:'GϦIޢ]S g(3Q?y͗Z W,lή^dUxl;Ұ=={W= 1]b$I̧I?c̴mc-RTKp &!=\侵ϔz,ݜ֙J vG$U%yy#(-FP7UknS$;:و_%aߥqf^16ZzQ`kU#l,LG]JB:7+#] TdرNSd0,E%S64}NmЏM=_}ܿqW|⣄w#=VVݏhx:]@h\Խ7|jX`#!;4a6Si򔛽+`y4LY{:[cm"$1:a Z0g)#|PX>uw>S(F6:(CFT7K8䝸K`Iʽ/z nl$j9nj76/6=;1yzxr u&ɵt*e?P_bV5[z<럅4r LӃOy_L$"}UU8pu8- *{2\I1`$ cC J6=@Iw|93.P\j,QA_oN\Xʁ|*XJ"l`uvghn=ئ(X͚)ẻ2̌HqF |0PF]6'`W.S^$=d_zZ1<Z,'JղXPX^%]2 Q=#Ɠr#jIG-_ϑqAIs}|m̖o ӔrqC#ٸi? `ik4?EƁ/euA]%P|ŠU_j@|:7p(撑UOS ėE V;8+5&JFq>4|Jju*-ae]>iR[bv{V(d^g6zWɈ%eD9w"r s!1h ڏO?6}IӣXqiމ,O)ZT:K/:" H'+^=-qmvMQy~YfڔFPEN_NXDd5ur3@Ӻ=&s-dX&-tMr|fؤn^y*r4fj84o̶"3诺EQܢBpWJ%"{OcBp!;/E_9Z%¸[HuP Zc<|aw{d664S,N3Zꄻ u)A/Pehh#! x3k)<+?T Yʣ_j00I '8lp#+(h0u"TfqAjk9;pgZr6[(k߲7\,e}t|r!Y) ,BikLD(8n5/lJDžn/}}>xX+@|_ @Qt@] 8&ItP^[:,0k7iiu hϞ;"` Wz5ԭpv,H1{Ƚ@n'RvqȠF_-Q#̭Mȸ̖hw؎|Ǻ Y j:?\YP8 *`T-DAn@E-{ʒӆ njsPF>hw{$OKXުEaN,X4p B޳AGZ"JoI1#e\ύ]V?Nǰ BdEԅ5.Fd.z!<ρDž)"oM7`/bk°v⵼usi'1_%W >70.1d@&>VCTDlcYt]5KQY=:C/_bšF>X=F #S.[{hUɆ7|^to>RxV9,'ޔ ueH6TCpD.^:|6Z2*xNdpifrQO7@C:mSʇt^X2dsstW$d `رv1@5$8yEo9.ئO.LѦ5OiME,C!9yްccDv}/L;.vTk8]80qMգ诀NU(f"7't;}@‰L6B>37mlmyal9]V2oFK82>H037ŕ$>HDL-^L=rac=y8O!S=~_mdZ۱Kq[DKx" HZ:xTČ> dT_XgZZCz3H~A[bV!ʇMQ x慁3~A q<,ՀHE6!j!Ǔ/H6-lBUy l1ƊVO=! pE=l[JMA.2oS=(n-~HW B!A7Md?Oao$ǹ alG#Yq; SRQ0P"訋Jb]sG vX_ ՟am,q5Qj']ba"(ip7]t[æ;xuLA aBC^L3Ғ8Hk] =0ؠc}S)x"#DMuX sb^TruĠӣ hTIj׸鱾Xoq&d$*(:G%B;= ^qrYĭFLc[i" zn,heIπb{ ha]SL5! &|o ^3yN_Z`˽>xcZDcjW[Gz$@]w/3$Rlf=-180u ~bw+4aY:К֚ 6|d@p5 12b<"^ YO&'+(dO"L1QCd5חBqZ,}VϟB^i0EF>,,w2v^SꟉ}'Qp%zsu& ڊddn&r\="Mj̔yvN6v;=dzB#QEy^QmG6WYl~2GP]S7ZJY99XC2uB:`Y#q-p J%a1 OOuChB~JE]WId*ءd ʌxv/ $zy;+dF);>\ǝ[u /NYoZQ WQxSLUOE3\"S'8WEy 0 c@VylA8~%!leVtgp;=\9!YS.OzDcCO5H%_,UkDS1igzŢтt6]_h` +7].{ kj1P i}^S6K0(|:E^CGK.H׆f ֛[M62#(pWF4rff{\g\o3ܮ65nhW#r &XTd/ v$qE5IV$ iSc@㭯`_z{_5\&q{}A\l[$)@R6ؒNC-\qWQ'qVlŊ8_6 /m#i/#iLpz\UZNM%9J1<>cb Yv~ZL5i r=\7'>pw1,QBHf$a@.,UqM;tw2ӐƂt5+,J/ftpX2MY1;=*ݙn#|uHsJ)U!.E(yw K p|vB(l (y`ĽK<ɞGCH*ݾb>ΖW ǒ`L)Nt 3~dWR yc"]T`OK<p5*\4*Fl7P!O+CpG^h=4մƐ,j9]TZlwzޮ~⟑2gI ? gui%,J;ߙU~Я鳇EeQzٶyYaH7܆@@d*b24}]oo!YInsjᵥk6DH!Q:qo2Ls'Kmr}`137Ak:zL+9*V1ZŚJcm~TVm#ܹ_3kF,q ֺF=SȾ`nm>2}_ƄߍZyoyc90Qؒd卒]+ @E:roi8JW~!7z DIB**ۂUS-/q8''f sy24?ex⼱b+iwTNzU[)@h ϻMq"p{גA[iԾ@ZN뜐{Aޑ4-#̤ݜ(e,@ʫ*\Z{avTy8н$7qk7Y>@:׾'clPay}g}n2zQ Ph=覵>&9}6nQly\&$䐁`A\p퀛`-ۨMɟbT LC=:W 0d+|w;]"ߡkEz6PN [?>yVj&h5j Th;@yq/q,$@%hZ|;ywu6kX#qIr+' sz |BVN]Ĩ XK̑'SZ N .4e'󸽠zx:1ٿA |D dU ,AA`;]$`Ć 8=2X1 U%q!ĪQ]aDEw[CȻы$&UvO]}GS$QDK kL3~Y@n9 j2 %s[;^ZYR[ ߼')t<ȆjЯT`h/#^$ f]%!S0=oMuB%'"&O_gW΀ $D,בA2A'.c%Kx\˜_B*ɓcyeIĒTkKS<xZD=ᛠ]*DbHؕ\gElV-CA= |sMtGxiaybn](8Y@޵n*bo{J(zu]$5CZjuS%lҘD?Thv6o"F̽tU2QnqkЯۗ? ܀.vȘ7NB a|)(2??gS*B>Ri:\_]yYyhV 5wGw aZFhDR~:ߝ![b؜Oܬ?:@,pbVbۅ'ޥ4guU^.ҁʳ9d YPg;r)zy!.t!֒IHz$-?q&[%T8e |Ee4A[bs<4@S$-Ayxa-V+F:~zypGud)0mgz3wk.𒑤+vtY‘ߊ|: Iv.X20)Ȏ6Ci$(NUB?G_ Z5"t;$=r޻4@<0Y 5|~ԧX7]x`U6cQ>c0~?G_%8!kc3%o 6A U'ĬAzyeܜ "E,E$a)x9@:ha,I4$.5E6%+C96GX`] (h#է'v[s~Պ1zCS8\NGLUbgA_"G8U?@T~S \`tqR{9ǯ\m;ua=Q%^?4@|qhuc`*obafbGؗ7z Vt΃^kZezdHk"1@۞e,G 37*gDIKۯM<{t!hD+iKMs$Z@I 7%5>Q:Ւfs}-!EL :Pʀ\چ6(,)1Ѡ?> pTMd̶dt3+t3N>G;8z(ư,(ٰ$gRO'9˫z2#1Ց U ̾{IPi^vZ1+)āVZbUb \P:; "<3w=j. (6%)d0?DsN@8XtU;f̆ #HIleR32߻mӆ")1f c<ו.fBNWٷM~X՜,+Nj>^U$R:in!~="غ<&$!Wd^o#M91ާ}i˜wn䱫U|?8) crgrXj"3+j2Fay|vkxۿȮmK+d[h=\ 3#-z GdsĝZ’EqF g&,8zUh&MRW[eR{Y(96C4JzL8L%Qzn!~ C`P;'.`6\ ]V, $h-yh^ $"ߎ7f/IΞ H#B計qR T!P&p41e؟0!uԱf.سlڣx=H7j'80I'L $DF9V)?*#T5r4]ݦ춍kQJAZDw,~ZZ5`{gqaIQZwl;iaLuLeO߁פ$nگi(g\uG`Sg^XA9wÔ,h]h.(Z4upw<~)_$e?oɑWD,LBn֚r&jǁx ,sF~8obq[2Pm $FZ?L3..^tFP 9q4%LbڵP53p)˧zX>U0}j]iK47L C5u&E1Ň|rbeLTբQ=FG'i+7~mbS> Kŝa 0و LG_f'aR& sulFMpf53!^<@yf!$~]4b27Ny*h^qkyJ?SO W[mBn<LE%^x}J$v \ag.Tb"`uw ȩR>W! 6H9c  .Ӈ v:rJ;\;e~'hFLe#hߩ6p,1z4un<$<ˊ &.!rSp=h;ڗ ໙p"TսVLUp 7\*ovS)JƀlA'/wqml-ZĜ~E(e8Bhu} dٴ(9'ңօnz ItկrU1y]| M뉭vssM zӨn: !Ѕ`kWg3ʗ)~b/'O $XIEdSĩGJ#,btMA o,8HOȨȘ7HFp"2`ER[wZDˡ}trir84%4zs0?prȧ\ |kS8\E:N ƶ=[H}X;%L9z=B6svE,).b(.TdO;Sߋ`Rx8CأaVO#$5N#4T{F72"q84#xiAX3_Up~])0 >ˬ{jFs3F䔍TU^\\ <26hhV|7? (!ƷDzSN?iv%HО;@jۜ:з09/zzl' gW-GPk &VY_+դ $6$($P&àrjpFs)Bv1 ,'>bw\2meXsD "-\B}c@D~%Ϸ@=bЫH&{ ܲ3f2#FeJ7JtmWtVq~,(ȍ_($KiK X4q_='[<'/=>(m,fMSxn"֜$ǑpJAS͔_Ɣn< AR)g$I r6=vq(G*~oİXAQF%OVt8(*aEA$5"B4Z S1*Duh ,b5'ZMB6T0cz^E2/k#RʡN&usR4U{#z+7iZ'̙4ݾwX~ëWi@Oބ)ԃ p#SmdYj1chX) C4cHQwFdjLZ= ?koY*r?Yd!/IK(UKȿȔ`duyA +Gߔ'_iQ"bxG̋ۯBgq*'&I٤0MI .͠ oGl2藻5Vzç$j}S ɛ(Vj?1m(YEJ6ߖ9`B_CWKJo^` =kbZgʕ"mϪTnizߩ^^QR$7̗ .Cp=fw<^:Vm71fN "Çw D$ ;+Q/) T: gzCD7?/Ŋ<;\RЂk>ҙ1{k;"W..ɩe/,a]p`rۙ|U4 O.lyqS}Lr`k@~5Y;^C\*6@5Y@Y1%"lsvѷ *PՊ葅]*o_&Qw!諾C,60^P F9ޡjHHvԕjrS]eS T4D R2GccChPdQ-+rP{_ޢ8}^/3tӘ3_. &ZOGsM~1$aZSpBh.$7˧)@,1BVk<(x =bjؐvboB87 x69!jSsΐc k|&!krJGL#qѳt2K4Ux^{~JZw XCM MF@[j0X6|EyYs(khBXFA;N#fSm›#c%ޭ#`շk.(TLЪCxj!F ’Y}J7EiEBrB+ ,nh`C7jnx,7ЮwPsBњ*d!SXvV?{T?Ygݯ+隷]D#7anU=5vBD(VA%8Y>d2AÒ/v9JEW<1)W*gBGSYL ֨c ETX%.w$b2c9N A}"Ŗ3Op)3=tR$>{DZ#Mntң'C-;@[3c57*MR~.DU焃,>Kv@ă3:+K 5*(emJuſ"1N7H}| N=Bz@,)C&~tXiJ,fWk>ɢo(}5C]b$m lWW> KX5*OK?Wh0qmY~ _~!KғƄ.8].'(Kg}زx!DA lC/ V'mTeHrmLL()࿊쥖SSSK>%ݪ}\,}] bEDrQcp]DgaV:sPdiZ }(TfD~=L?f)X 2(z.dtq2 %`0ٻ7堸V.}kYR(iLDLH}>0EQIQ͙Kp C|C'[3^/J)V%̾We)a&m`+HC"[خeB4(,K!%T6jr,J^}`x%U 5 hEϊBs 2WmyڍI5`h 7B@bZOF[hxT (6E28Mtgŭ[Hk0^pbhz<'8AoK6Ckf Ws9lw].i 3a h|^&GC"ϩH[l^жvb{$6X[!vy'vta+\T`[10im|\0\$ ;kÖ"&=D{0F5j<2&D(iݳӋʔL{tV7 80vhdg˜3INaq׺gu/W-[ӊ.7)5&;Ⱦ%- ӇEؼþ=~3);P7?z6>ջݺbqSF;R0o~4=;O- ,=NѪl|)j':-'pp 2Sk dO$^*LwCB-*ެ;Jp j4:Ixf^Z 42pO8sE5|7Gٷs5'+қQۚ垁b7\⤣#TSk=PGR~ԯSb7Ep~gIJ⊴JiGJͯmt}ו^iSqP3T[/2r`"P:Ks!(zrIqaFtq{afy:ܸa!v4_7H˛ n_2i#9vJ깫+;B]a$7l-'C#LBGִd'aEqdsT!J*lqE+Ds$zks#iJߔNV0Vor9Tx3VöUԛQ1nޑgc#v / Vܴ1Z(k0Ff럆Lp8A\ũgUtܪimM&(G wT!a 1_2X2uxհ( V*tyP$JRۉ}mt}E gQt 6_/x{:9[[$=S||rhLP yc:VQ[hN5| *Gw5ܾ+v = 4ty v<*1o(BanT)U9^/gU{ 0p|r>jVw׹nR J(kt߆ 4GPUߠZsc_B~h+tƚdJ_[:+qk>U]t-V #8wJ;/:&OU2A, $I^;-Qʼn{ۍFKi\؟|J5oNk voܙZ/;7"3p6ˆq7$>_fbb3Q/B Q\SlsC)ʏ(ns?ܲ]ɮjF#D SPQM yBSؗԟ >#Eل6uyrG ?5S =d" ӍnJk@KIO-7&X9Nz"J! oZ֤w ] mס1AX^cM*maзcQ<;fFPÁUQ=KTZR@V9PHj\/y!  ~Wgf/g=$*9dR0fuzzv3p5q`6mYh US %QaT/ `^oհdq{+g_]|5/k"(-=# .]W96d㩤lՌgY=/mhbW#h\g$4X.ڋż>eu TN'UsȳC gU eSA!J1ϿD:$Bڶ SYj3 6c@"Um8gxd v0()`pѡ]2L,%F!p(e.gFx^ߺ61?^14IݑPkzǀpk%IP,,$|>_ak=8\T>jcFoQʄ#B4mMl LD2g ک,ŗ6oXATLBlȁt_ֹd.FtQNR_.L~;Q;3^MB?P l2lo#;Z"{ƄcI2q )-/S+J6"CRDD&HZjE%]3儁 U7|6Ŗt %Ű~ج> D (#⇎>jg?e83V+! N#blS3@4 %Fڇy!ҬR4dƀPZ+zrZ.4ɧœcx@c <$}F:ZxSh΅xD!}d <)dFBn1KhI܃4|'9;Z:t]sR=_4ޱ(s(vϔ|u )"R9!$ 3ϿQIG_H SB*l;S*3h苀Ne,81b ]$}u|_ 5ؔs_258۠*8z)V"h$B_F.K޷/o(S@A U@lqn1qʬx5?-}+X2_4m UeU c*d S.b?x 4ǡaqL9$aOFZG8 >$U@5qs ጄ7NJCȝ1`EP͐aCnwJg# (}h+F i58J@Lz[ ;D vT2CC{i]z7&Df G[N婢3 t.O@)!f" @Hd:xSek EſbǿJqe@-f9DX#z|ʦè#ܹi:׶EYdk&GM"k쫞<$Ԡ + 1oQK71=-Lm\E^A\$x_┋|gDx}8P+R }+6\5 F%R!ۼN$֍VIyӮ5lY#@"z_5hݗe4W:%ypqShbQeS!yQ8k˪ d9:^vpƵCgooO 0!U~*fo1V7\&DVk5u>~b_)_v=E\A&ޕsnQ]VТ/[Zj9x'"5q-eFϺ*_ڰce\R\{瑟h?耵n7u]=!Oõ@[Xq^ȞFuiD} NUsZ䁸ZNHh!wC>iUuŴB*^G=/uM&# v .\Ҧy'Y>ulʶjKͰ"7m@Tc Tf!ԗ'B"!S޾sfxq2,ޱ[mшD4]J,х{K;d}hѽ QKF?<4b >, jH{36njXf֬ۋyfyfJffb:eػqdL T}aXIP_7(|BGK ι lbpS,(ߝ]㰯UWpH>l.k]j9.+&KPȷ]_L?hR/Q {(n=dwFo67M.SSAŘ^x2 h5`KlM 1 ߲d4:4#<Um<⌦K3F'1ic9w ^8"?o Ǹ Lx:̨dGyƷ]dyL[+mzR޹<'Ŧ:dqK#`@L)%S]vRҼ䛷Iq 6"S&גTlX~5UW*/;"U554m *jdxlyg#/"G23 [#FVYGWo_6z.:zTy Zႆ hb47IUkw)ŎKhS86)0ǗFaXd,liV̨1NxKUo'&3%(dD.gxlբށ}G)d~OyNR o)T|$i,kk}Q"KϽ~V06~Dzev0,p&皓%[RRve[j|񧫹<8FBt8Z0JeKҮC:D-c]`cdoљvbCXPT3`}M=3%%)wYʣhU&w jLt)w? ilv|D}^mn};^PrLIA\_OAL v,HFK9'EMXl 2"gt򪕤ȩwI1Bj2NOq4?]S:0 g8 *jxa߶Pfaþ]"]w,ײW0nHЀ/ZS,ŗɭ@5Z>MZŝ&d,Jq 8U*tU/͜Xʙҩ٪̨CPɟJH`$W xuT81ۅ!ۻQpOԔ=? _fM-[,L(-0Rt"2@gzFP"` @6l_Oؐҿ%/;2ol-zb*=L{ |PyleE:멸akc%Y) L #ApA ^@Wq9v4Gs\)lJj!TcenlAWŝO|5Y5ݘbٟuo?SOTv.hM wrnݥWz6L{HԋYS4iߡ.-WL:viVD'z2bPi=%!mWϔ_( Iݜ(.<?XP@z ϹfZS{Cڙw:ҩR`G[;Vvg&_$ky,d[Jcُڲc7ݻT9:a'v`‘tSbC!BoΝjVg(jq Ko}Nc38R=ilcڋ/;iqRubQ\O$I_%g7 Ԣ>kVw{k Garb&$FCPOr|M%Z*1l p ._b@4]rI% Mը4˯@;[#bIۭ=0V:4A26lU5gqJ,Z}$M*c X7,EYbyEt 1 h^q&@a!OEt`[4뤷Hkz55Ů1YWGn:5 @0Zї.´}պ'TE #>ro%V HJ҈NTՍqv)hO`N .ex0wK4xvI=r{)'[iv$7鿕8VvY1d~X7iWw ^NFFľEW^{£}-/LhKcy.B#nR-{U=!6)N g>8 42$z`)C v*cl[ fB#Ӣ<8}wN:}mj#6iΎb~Ҙ_gC(ra (f?bR%jPj<_-KΥPpG$jZ)xHk]]jBҤ054DƮQ_I='Cf1ga|JrًpKUKr&(;ꤠUw9'Kr5kîxw1:4ނF<׳x\`8}3wV5T]f34Fe`/tJM^y#LL2~; -%3N=xs E/ezGMcݨ/K,%B3ly5xBɣ VIV,pǗ"*Y+5.B>].7o+"'Q 9kKR'e:NQ.zp6mYZڨ!Jq mمl~bzBi"e,1U/͡PֹfLaRMHOW`bS8^{cU sSF?H,{u}q;gTš%0۷yL@ C 5ujty8ΓĨr>-  ڠ(Pڮ&C0Zj TꞫOÜtz,xҔM.r9IB37K zE™ SVe1CWC\,V8͝%kGX/Q§'V/NT譍~B]b[SBz0r~;ua {hGc" qcgٺX{=0\A*彦\F3ֈŵ,!'&=|=z6{yXuƼG(0@/p`2WPPDM)UfA}%06]4 x8Ut HhQe"!ehAL4qvwChQw\bqPS'eS< ,u#_Wo8gT٢1ﴪ@Qb~NIݬfeLdv2$d*>F'(0Qhb4] lq|l}9Y9)) b[ ԝ[<; RCcR)sv;MbW W`!J.u;1A/!@;R(Tpf !s)7IL.}&aONA7kjB/:•]Ƿ fq<9/8eC-'T(y|tۏ.EQ@"L6z9qN\@b2Ayq`f?ݮ#LfaehL93H d6!RfՄCOŃh>2t|/LJn?c4-+,{Lˠ1_~N,]==R]n| 鑨D( ?EF] ڕR"^>7|@{Ң~L.gW?XϒkHi1Nd6,l;R3B2~& kDIqVfIQG hRl SgMk=mᦜo;>* $W88UG6NKNLO|drQ\dAXe >HWI8GJv\6!ϭm<Ԕ~8>mUI.# 6L^n g_o0J* 9P{*h?Bqn-;޶gEB(&0,S byl8.݄Gj!el Lp׍*=d/j'Xџo9+uW9n(>!~& *w(aXoMAZoTdeS w|)XqJK9|֐ y c5GxG$ر/,.Auf'5fBN~`uJ%A&FQ~M ZrpĮn^tLze ,Ug&A(a-jh? {H#Kճ'pѿ_UvS%'KX>єNU%JU%  a1Stmp3T;q}4ܴ 'mgKZ`0t?+}`")K#/۪ʉ|qG~Ynd ڂ(g&ڸDS]2#6^^"EvS'ڑLRX(^/~4dzػKs$}16c/iqa^JA Q.lIy5)_0j+|xI(<K{ 'Oz`eSyo(-u0rz\TT;0}1\+FA)%dH*={*Ynza MXbe~a[O&72NvC|^/<3f5wr^W6 A@ x |o[k%NjSW9C6\&(n]PpR'kЯE?Y,ϸ79}i(}#(qsFGd|ֿXڦ<U=cӬ/bܸk#vՈ?eۛ,k=Og`y߇x-= l?ȴ3y1L!1"Bj}b|޳>#uõfu"ɧ5QdV m+xu>Ru<qqL$Vy%Ki ]EXn#ޥ;3Qu~t+x#CDGzil)%zI(t % ݒ)t|!SUu\ܬ־@G,bZ7^+}d.r0"'wb0b7qӄY~&&$؎ީj0OZ?˫bh ^U ӂFc|2A!;U:/ #hE>%UA2z -m\"JENie;vyFș'MS,dWSy[  jV"]8m [rIyb(; ~j` Dj _XK8)gRc1!2M9cDkFJ۠o21|_"Cg@`ф<}**N8-'L(a5AWAG)]G+8Ϗ[en._fJ.@d#Ov0$w/ DL6)B30=wZsm2|>ϵꄁ1pTF~sz4rhLvI,6ɇC]f˃>UfІfuRg*dg\ dԅqt <, !LfkƷ47u6~e&&%'>&5~R^K%?_<3ZZ&Kc1E%:aG=sO)̜gvņrEVjb=94@;a\qz> 78[ۦLkh_:4B9P('!aD֮L=>k9Ԩ+oŚh=^/`89<GZEMb=sg,3 `w.7+ԉ\?|4DPξQJ㐰%1SS0hC?e>" |o-^췓͗P==zx-%DUΧc~UeqLwӁM\]WYB&hat,(Cg˛T-# 6GYcTg 4+ٸ2T*튐Yل,UvZ727 -/3)6$%0Xmkӻ ep7NEȿڀ 5-1&HTT]6' /haNWv% Le4cU N'|}=k͙3~gkmX)O]^/'Ȅ_%.Uʎ!ϸI:k PZm܈`[oN6hio^w92BD u*C2[Np 04zS^9-sJVTj\jG ;FcI)kH=j5 \r,}rW>GN[7r5*%}܆b[]t1=<ØWQLoM֑D[Rk7v5xJ(!ŏaAw'/~0- %^*zprOUt@ٝJEÅPo}jA=0Y:"ޚdq|T[>D&naS;2J8 6R$[+ y" DD]_k]{ ҹpBpK"EX޵Ͱ, 1}$/U1:\:}&[Z5 N?R٨(t$螯hQ m8D+]V F=K+NX<lm)$9 ļrq~4*1bs7u}3J{9BroDyHϏ,~0*ç*W@o7y+f{ѫp5eԦdV`8ҭ_ .M1`Q+P*ij^l`}lB=iъp$uiq9)ɽ]jde8d)"̄ox?oT{C"·w }D$J8xL sDy^5ڐ .Q&U9_xEwPxtSՀ%D% MxZrW :!FU%J3e\ĝቛ)|͖MN+!`D9L+G?~QmuItL7}d!|}\f&6=jG9&/dȊ j-* ֝uh_HGI;Z.N1PXm!dg=Ɋs&Pj>IVcIEJԕL*qlgJ |C~ &Bmm=S@'+ Q}w_&be$%#N6&c`੃'s5CKQMttwZ>*/F*у}W(9 ~7xHw!-ډQJCo f@p2|jy:p9^~A6(L6@8n; 5׳kW*Fli:T?EXANVVQFbe g:ŧPq+% W*M.zlNȊ9 :ŦgR!R'A`YM#&/=*l.VƂ 4~*D??7ХFǩ@:/~rCXmΉ ŦRjVe֢{npWgut#CF3g58KTvG.>ZnGQm1=-v|yUJa?dSS,J,G)x ;n$Cd"ι,O]/}K7<Rk;YV(l3r| _w) l!5QKfʘL+w҇9 MtrLrq]B"Ru+IY_}iڔ/MaQsmhoKOhQd Tsg Ze32_58VHmo@.nA4"ēAd5$?j"'Q3؛$(WK#ڀA5<=8,.ug%o˹ a!lhA "#Fe8}./B+ft/oL3rԌOI>0{f2{|AHT b0oNAXKZM=%.:N{< ?6z1v\j,5? 'Lr {LlSME4U ;-YHIͭQ 6?[LZ')h5ßw?JW2`M$׹6tsƾ<׳_[<:@Rz+d>z+tJhG=ƭ^qL0mSkEaumǏsD~ʔ?{0"qFR)Qۙ߂4+|s_4d%[*g_r>iLCЬN/~h:I?_, bgi+( oWYfj!^.-AY&<7鑘Fz_+.]bs}.5#ո nQ,R7C 9# ܅$*\?ޞ:#yH|c@2<=VL 'TZjuv(xv#5G;NR1ņæ<<#;i-$(q14مʼnDd391:?fB0힜$[u^0ro芣h.@K`A5=Ed'VP .Z 74kٛ~do1=nJ@̥:#]I|p|@8eӎgm"aH]2p$7!G jaq̺J4˭|w* G UmϨ1 >b%նfDPCƻ2`k/4sܺAgzr ??e$}uRV/%HOmۖt6&lY}'?,-(O_m!?K`ݐ SƩ.<O!xC]$|{oϓ/w@_+,%#wC /b[qIuQ ]$O9{U{+)*WSZB 6ȑ[ЅʮR7GjBl7Ymq˵oZ'ky2lܧ,IG,W8O$5*?¢1w2;0n<U(Kg^JM5 7vA#j"G"13W7GҘ?u ^M?:錻n rͨry$昜]򟶾7 =ilIkv-qyy[]~r_[B93ʴq+xE} Qոr0kGWa)Y\#6N>誇N 3,AMny0t" c0ǭqyɅ4-,z덷)JsV ^ˌH*DY w@Dib&6j3T()%2m!jK0 C߳f0u xRili#7r-W$P<) P86NVD1~K 0'=&;9k/.Ma쳛D' qSY/J ^ l#u5o(eSYv:# cn@+$N6)ڕ54 ÖaHMl/aԞ`P?!+x tܒ6HJH|x۷ؗ5Vږ@yD SF$h7q "sYr1lnR;nE; P_]!no,V]YR-]ߔڬ\AE:k.",5_q'? .G[f+68BaY0l"~=0$[ U>d&~؟׉D[ꜟ>yAtb[p#1/aAJ[JWGȞ+$ɵP7q6.IDXbVj3ُ{C^9tZ ZvidZ_$[٥]AEmp|.be~} v@;uzdœ2/_[* b,6!A츂1AV D%84X_%4oϡr"cjƠOmIg!(7Q˟hJ/uhY ”tL69.S]]Z9=_AXi`?OV-cZ F^@tXF뺀?Xj\mSWVb/h.,@| ?t rd Bs.d7*, rLzJ`V;iAz)D~g}p8a7.7(޴FϤ> qJc>X6T;&FI\9Da{芊kC{˝r$J 鬪mc-뵁ә1v+com9*70tтYZk?#uI&MnFs/_xXNi닱-:4(ETKyRDBo6N|viij}ċZ  E:w`Rt._,M2D`𧌫F~þȡK {yQHA\pٲu\kJ?*1q;D|QRW,ezx 2\n4l@#ұnNey&9^;<`z Ӡ'߰t+~[Z| EYT)l1a7Q)8I)k~u'WANWEXݘ&kv;HҀkr#ŔtMY([c"`G7!pZ)/R:V!R |6N9 =Pz~GŮ<0y W"ޤTFgFD!<i! qۨzhMlJ8~=5fffNn Uqta6:pr큲j"Un ?v)k|Cs1[$5nR$&ZoOݴ0է3 j=npjO4+h%D.+O:>$ '#_oLb=eNu1y+½s:w/ӼB)97煾 x]eN"a/!F^\'T-f 9~5>1p$!.k(AT6ZRWkfwfw-va4vsqf"n] 3㜮is>PbYE,szm5ZE3ȵ+@fҳlTgy=G#'F!]` #5*'9&(\dq5ʪZW9 }@ F׼ %yqj BTUTrn0[73jCJIPI3 xB;^&fYa^XeAڦW֨ r242#?:N r(=AJ3eNCدVDRf9~9u9Yv'Ŭ6kz'﷦>ćLWMrCkhzq7,uTQ?O3C$ >8$nẗ́|a6e@răUpb.sJt:< MɈ pZĀzϖ> ԝ2[Et#f_{VξI.rūZK/{Z+'2Jy@>4R+jG|=l&$𝞦i tSTv-/U4k4ATRwYӃEs:v&?bȾEʊZ*&τ/9˅f%-6I9u STyAƧE*z"6QǴpS%AeX.ѯ{F ǷD nj9_##ynޜ`bekGZ"J+y/, ?Il H'1%Y_Y;r>A ]"mU s79Jd:dl[^cX 0q7B@³|2&8{V0 r/,sJaAXcиYz OU+ٜ+r*r3SLq-*j:vig/*$!0|%5A5t$ m-CHkf-9I~HÚ4!L Ok{آxY>3Rc 8?,T0*\tMB8ck\TѨ,"vuuw*g HQ':@[8D ")k?D M)C4iqYbﶓzR68ﺄMV/AKaHosZsI2X" -h(^Ó,I"n<.r% U2Y7<,߽ywEgu4ѼA_XPX ܔY2s58/+FC9Z]AfC>Gf)@r؆iB7r]?M 溯6NR}-4TXWP6ñbCߪ*9}V=Z眃zvFBc ͦj#U.m6INr*̋CDoplc86SQgZvN⩐*OꉱkFCZ^XNؿ˾3oSz乊53:sj zfFc6xO2@t5[ V r`<78fB̐ҳ8Sq4ko.āv]0֖*J3SCe1R ;EMɈk=GaD3hl&NuSõAfV: zYfBj G]ZbQ33`Dnw]e;:+#$$7D м nƈ0ڒNkwǗڻV=I+|a;&*T1QnG^]{X )- e|6#;+Եڹ-V4co ]cx2oXwEzԡ8v1+$\p&r~jkr1,AS֬>fpHƒu9:TU.x 2`|==`5*| S^GQ(۟(b݈K;M>%W tdзmp(B=r&cXզӃE#%mCLrV׋?+t"3_ҘvtK[v8]JHS=e [zg- ɐ-k7+n))!u+ 'BGW` ϊUaϺ*u))O~ .0>&x4`[L8%.&dq/(f o(Hu[cfEޠǧ!%1~󲜙=-ۓάbh?.fmOn4<D7۰ʷj־b ^ vv M6q1[mHCf:AUFP@oc7#ezKTj՚,<. 9$(l ^=O=J?ref#inPPNe 5'`.W%نu1Au`WrVrG5Q #QX^w ]@~+`8p%]56ȷ̪w @0 n錏^3# ⽮7 v]|s޸r&iVtkOx'n#`M@F2ԡh"MW.Kx/Qs.mНQR4z@Tu͜ětقVfI0sAzTI~(g`ۼBwt>0]W,6_QD-en"*{ Ҋy6b+0'ccIWEFܗRY&Ӭr fH+fB] rB$`ȍYwPM+%c7O#Q*gL#@6$3# 7{*[LCd%?`lOvX`liއ$^:-c{_6<fi4q`ujݕ81ţ^,R"F<+n8z@=9>|A<,^Z3ؐ`85?5~s?իVDdw./;`_fyV^z@ YwO,ʁ34Y$ ' Zp~GϪf%K ZґAs zT=f9a=hWb`$iLFK,{^ʍxװP+s-p#hū'nd7tJ-$ wO!WB*/̧KǮ(=b##9O оg]1b@JTM!z^)ZsۖCB[_9}B럵^Mr"x[SswKLv*G9tX1 Z2?A$*&vjps;(lsZv ߲Kz9ٱ+:\n Qe`AI>]l$m%uK k#Q|ĉ{+/'ũ>g /%1o2*JX/19JeՒH8X{E.i)`%Ua2)ue =}ƺ{ 3Y:v:z>u-0k2;Wz>9]_ԯK'C<[z>2^숱?Ȁbi9wi[2-LcG8nr"މ% Y;KvSXalku"\޻nl>! Dd7Dr=lQČrT1K.\E4Lvj;P˳PsLQlިQy2m0&G,0:\*PX.S>7;>n9cڬ4.8úF`S1X$mnDtDǔJK%$U&㾕/޶^+@r)'w*`*z4Ǘl?oZԝjE& H2aK<ᆡ+;`& PAkå,IK35 }[>Q4 `N+恓 OL^BK]/?3j@ zSIG\[w_k~0 PJ%cI' BgR"l?0OFFZtFwgWԑ:UaO V*|i;fkΡw;K7T'!Ӌ4*aWa܌ .X7v=ڻ KY/ 3  \=^M92]YFDAT5Ϣ.vZ/EoɨYVȆ)YCbԎA݇0f (lNO'cq 0̰dSUgTu6 ӼOMV)HBp_TsC E. AI|4pZnOqF!jDXlF\QN`-E}(uQͬ"@\ VL&M2 ,;3Ek6[Ch2(Y6>u,i\S,[EY5@Y,DsNYCW}%Ddao-֣s瓞%ʏ hczԒ79okBs[zb@aO<oUJrbVH/ǘ)&NsUk|?!nN b&:H%Jˊ!EjK?Fz4!&Z 0 <ņ~?*UL )i~P6i6 72, -<܏7.Q3YuGZ94iF0{'aO_={ߩ3J#4-tEo*Sm`ljgpblu:U^z֪5n==llW8yP&hR!,,Hs'2w2荶 =K,k鱂ЈG=#%nIJу*}5-[pO/і09kL- ֙4~(ҷV[v3RZʋ 1uũ¦ElPaYa*UQPճrID;mϩ>Ⱀluwac'7Y6$tqmyEE訦]$vƹxꤴ߰ypY ' M5b"6yQD¼ ~RHz*~ # < c*bn+%&(+kc#ɣ  &տsφmF5t+NiկLgNEzR6USm_tr¥CQqy07.5|_4+!+IV`爵 x$nXpKJ8{QP_'l]H2:-#())AȊ3:w;ZG!igi7yiچLdIZ3XIcZ7]A$h!%tZc1RGO5lFe("I}b>fČe.!6ZjĂl8I Z6Qir!3X:"BUjڸZG8z.IJʔ@sGgpğ D41}w+*l=!EP"c#!#;!,۳J`8۾#vF_2&= cޏ= Sj?MY㏩[a=,ve=b0{ Ip74L?O6"f}Y^=1h=/0%#5l4Y% 'H'Me3/Muyxͯ9O~πi2H4Kn^_A`Hk ml=φиv}-K^m M iwb ${,ZWHk{(iCb[>$gu;]71='ZcJ>x{ ^N_De%a)5 qq6pö F"G=^-+`zb}cabDK7.!]}DS S]@ڔR2 OM"H]u3T.dpʁ"ɸUX5"l@R_:N2i!Z TQоq^]wfՠZushs#Шe 4(f_HT )mw+;&pC1kǽH ?ybe2Gv5ġr;G*5V1\ql9gj'i*U}|72le៷ !6:ovZtZK`)Cxc׵&5|8LO/@ঀ.*-Wb7MjD=V*/f{;M5U[@O%R'Ckl$󕡶N1*UNS=2ab S_X bϳ#^7-PQ")&A/5к]l*(K>TEhx)/zv}^ &aNU&yuh/aFf͊6ux,vaKf7'E}Fr5'"jy" TäJ嶿HQn!>>ƻ ~<=U/Rj+yfz47Bj0`z O8{c3_md~cǿhqB|w׏R(Cάȅ09Ohhx%+eaƓ4Q) ۢ^e9vL<,aocn;^v_]okql~ZqW$kD[c~* %NJ,n~<poR۪aKb`3Y`b!^<_>12jkKf£aiv|EsvʫLo9F/ee=-$uPw!u*#q@^piYFM7+ یDH^/Q1M t4tR62Dz4#l-l*.i- q]hWEXKs]T1K$}KwdtJW36VKRs&MR)hL(7-$dn~V5ez{oQ7CS2etY䏿B>yt.$orZP=-^}Zi|r{~};AFLHzCьc)Kt,7l1s)JTDo5(W ^NU[F%>(RQC _ l}gKqoD4 FJ9NC/c]` .nU^5 q*ApaĬ!f$W!mW8[/Cbމ!I6JbҚLŃ*rXDX[(`])𭴁CSG_!fgMF}M֦F0Do? Tv>aXQf NjapfD$Dmz2D@-n+ՙpC5ԋف`)Q^eJ AL׈޽lI㛥v)Ή. ]C8lG,{Ќ3좣_0 xܟP= kct1i?Ozs'ydE1=M/BK3Q#{i`)|"Q$5`GÛf=!Rt\7 J TӇe@vt cyRs8eӚ4 Y/@s|dմT:2dYm󋇽wE aҢ8BՈZ3ͭц9`1::D a  5_DJ DE~u$BkZ:w|?iڞPkN0W4QRhQW g*4f`3̤qaLoxb")ʫTdB' Tδ F홼Ɨx!@[.F*eq ~%[{sm'XijXq+ޅqV''1ݡ釽F^ߺBUug[Q7q2ANMOW\U\'˥䧜#A4t:z?]ܜ^Ot#~d37YO̰د:$:&tD%~k;##!i޿N\ zF yX+l /"%ԷWI\bn~c[/F^G3Ь!eô%@/T*!/:.F WRl2!2r~fӬZdu!`9HDnTwMIeVA5 ]ړJʶc؋I™7w$5UY[F3m?g:xe?.XB~Lf!Rc/XG Ӵw LC3wV¹{3jX zS)=@Ϸ#AݬOׅ[sd]k(7Hm@7Q29zliCc{bF1p'&ωxqNlPzL尃d$#\Eoϵ~!bB٥>^ B#)Õa|. #(cUnp:tY&F<۠J[$f9*E4dd"d ­ր.ҺEJIJD{~gv\uc{Ol' ؑ9k |9/r{yG &^w1"R0#pgS$ of:pfa 5R}hSgSBTU=[F=*S)Mq-}R $9hfU_Vp@ 5)?ocF;iϷ1pjfsje鏌V(&j*D8A'\TǠU&D4c;3Tm6r%vxC#Fx'kŮtg{\dv'h&`{1a߯jW0Lb`?^S l]'NVr']jUAdyr9eB,I.BŁZiaWvzJ(MQOJ/oz}*3%cC[dh@j/,_D=*1IHD,r e?dۏLJ5b@HH=tugJX&f<ƨ2A<"sHTW|tact[Mk4m{p ;L|mof:b,9,$t=<Ѐf#S;W;[$`wy+A>z"?==-9]Ȋ|naTv\UUe+1i|2C%`P4.>)+r LM!؆!h9.]H{&g-ooZC;9PZrNPI *!$qܿKq~nF7RT6V T y5/l(7t]MLq@i$o> WzoG4'HG[քߣHDN%!ӓI&c> =\\.5gAp~#FIu_T+^%85A( CJfᚽ]@7/e&-BEOB7U! #0ꂩx\ew=}Y00x~>J`[XJ8W-&3x^!~ +N&R&T)ULg1$S[=wȨ+\.7*+wU,T87U$`JXE3BsK.u#޼179D{Q4^gcѸ:^KfW* g9Bx#M٢Ehjo8}g@gJ H}6M4dr8R%q}Yk ,rZ6|Z/4o)#,e66gzF0OPsRO Γe-.7}RTm%zIݡ(Ma"NC׼:џca^UK*mu;$npA01"U!7q'wV]s޲uHg8紿g2rS 㷎8oHi_hm209*Xsl HfQ{>'կd w'duie޻wFNC9$UB:,0eH;2%ĥ9Q9H 4 :Xu B/3) ̯L9ُLK2JfgsDsu_NKN&c3I4R=2l;xdiB2h+hFVY6tFeh8XUw|V)L em69/Гp? &}ZFs[a攵݋1Y*۹Oeq[kQ87!8YU+{ _?7醕w!#ҙj0Q3ak1Y3/ϳf7}XἧhJ!V/)4YCH?I\d([noeIk]s*3!IOcVʂ}wsg|>czAw˿@tӽ@p݄JSeo!؋%(VpA(bW/X<0Ń図JPQu YuPcf"iS!sۻ9E&||=DB#9up_x׼|ݐk5wpzvLҩ*t?5NivY@c8tRCNF}8],Aȏj koX00Edh3зS\j2&:30>Lڑ-܈3L$83܋ 4o!K3ESNNK|S hHvY?cX^BYbbKyA#\FڐM^*A [\e2[SFZ37`0Pι'nf\aҖ&ɰf#ZSg `y<3>"Ng[p8UU<م Փ9޽1%_?1)$u܇xmys h LSy.*I Npp})uq~-7i)5pL5J5hl%zB"|/]p.ܭF z#fI_>WHKQ--ln-*y$)ѩAZASP`t i#h(6>" y( Ȣ+ SŨN$3HWNhvy>WvR%l(-4cxj4kOTW8?oؿKM,s6חL#KyN Pz,;.QGLۆ?!YS"[l n%2+(r;ңiU:?8E!Ĩ7R* $pJ@UTcaYԚp ?놿!=c msR^Y@-!rm bU{.ube֠I3gjk|b-> Df+{X"'ͩF84ڒ?b/ߛCJf>p(ϮȜ01{.%>ʐoW`Ё^ВURI1`npgmV_H?;䛐}P1;Rx'3H[pz/mm#9]*_kf<RHo\V݈!{ҩ$_$XY+O|Z`IE'@9|ѭ*SSLNI&RrkfOed_yčF>,-بlѪ%nԺ.[z9JwJ^5{ 5Pp6MT#d 0ѹGWKgC0nwd,ܦ8?ޢh84ޫ8 E$~)k7媓qbiM 7! ^<$q§f2F'ś> =+_^J Hs񝠖?t3V]Zb!EKH~{y=|gR[豆jAº'I9RJVWč;kaZNݧa#UJBs/Z?]v>%2&|[p?>sRHʘzy %iw7.|Hrh=z5Z%4`v2spi&Pܧ7_(Q ƫw'ikoq,r8t6oZ8Z'rf < n-Qro'!S+o:B-MYű[ )8m @$RRt@h;`lЯ"QI(Og:ՋgNv^(q4\U0Hpm1@ @D/@5DZڧ ROO ?#?zVe{Ȃ"aJLQh*\}G.%Z;ށ֜rtb*;Ad$fWx@Hب{agg8I9b"4I?/}یtSe%HGn VaC&Iޯ?7NcLbKpmFUkjW聱\qΩhNm4@6_Q/akkonϪah(Ekbc[4˰]˩}hQ"J; u@DZ9J,%uk<qQ7S?: iHz  mk%@u&6)tBzy+ _5J mzoJWY]yҚS[y]U! ,_PTc2p}ap~P[Jl*;Hd]2XQ(B /Y߿,9>?PaVĎI{1'{7Hw'l*cS+H^Q?B$䠹3POB>{oD/^ɤ NmZ+v ot\.%F|AQ%ߘ܀)N|0Tӄ9s yDb*(:7D6"a`JlE,S{$vƩfHs¸ @~CWy]>O /*4S]pەڵ3Qb9Jz+p-sw۳wz9cp⺧K-Mў3u)Bs'Y7|&2Vi+Iؑ-Ad<L7⁨{,J+1_%YNF`PV1a7X.Ds\s`ffn#S y hT"E kK%y[탎OsCtu9i '**`ez;tg!r`/vSkE y`3: ^bAnDݏ';Qˍ32Uқ8^&1HL f: u-aõ%g/0:Q,O7_CkXe}[*] <`}5͉0N@S3̰pDY9EaH bN3;Nu{d eR2!4Htcaky =ָؐ2.?WO_ۙHa8(se\.=o E,yR,w@e=^*Qxŏ2gԐ-m熡1Wf/J8f+DRïgm᠞ss s]eo'ʨ\Lr:R dnK~j:Ozy4"~bDGR:Cs`)\J/@bQnsȜiFE͂lHrBƩXn"+MXg=eW+x\3?dl$m~e,u-!Bv v4ENBuRt@'bfYyKTA2Gwm ʑ[^E}` DH@ uRmher0JEupl9`误vN!tߠTPa\ˆ5o:u˶x.UU) M1=f %_8ϳAiĩxյPiyOу|j<3;5iB޳4Qw6j@8z&]I5[ãebIx^CT u*b`pX΁bhAss[7B<:_˸*6yo`϶fʁ}r@@hAU j3-&71spaϱioa6b݁sSXh \1ܛ}ͱ[o5A߃`70ݫ$3'#U~8+c'x>6`'#;^8 P9W%៝kEBy;xW u؜3j *?8~P͖E/r@zʍpyr!?ƠVs{c`4h[I6^]<v&[&!N|J)ȴVa?%Ul=ry7&jWsNxo뭵W$Md-N8d`O$"²dSqqe:)+ޤ0O4:YMV~Ш&+?x )1Zy/7Ո> 1nu!E6*M=6̸AҪ)M ]S$hd#"7$o=>H*e<V]Eea2O}YQ{b}WĹE|sNҔS@i9C0 5Ty 0p42[AavbpQ qSG3- Ge9S0gC,F7Y1)+7i9[dp@ P\=x(Isj<䓪jI(IXqC.#K8>Z8\І!95בWѮg#Ԥrӄb r\Vm&۷ÒZE i"Uz8~0paw1|0-mfsK/oR;C+L=~ wG{~|3yby:Fvv|Hp5ZjH=Y1ubGԸՅrnk0fi屟'.1ہNm¢La]3@7< T+wTA8sm(&&D&26X[phRݏͯc]wA0g*mwUFq*i`eiՂImZw4.^<3ߥϩ:P܆6tS}'F'rl(1k$6C YM?P>7::!/\R~5YlmT&8d9s޶[H]m\7L@LҒ5: ) \97ɗr1d#ۺ zv7|z ڕϐ.0ChfXH)4ƷWHs y-[:bFMCǠL $ܹB6/җo9PϕE&ȊO'P"Zv3ve2ID ɾCZy @*[Ӎ\OZ>ݬf]si4Ǡ6v-3ňY샦bm}Rs9GA Ds dWj4+% ^uu+ o4aMZq&*v鞦4-[j/n x"!ۈ}d<̭7WJ ]E}0AzE3ڶ*Y}a%a5)TxsɈc[p&&nM2>3OrB:w] zQME,">?H=|r̙R b^Eю딙?KkOT.{#RZ2B!1;d 6-A< 昲(N/0 nSHyIDt-^LZ)r/>w(SaO}H1 Y-yyg[&^$?OLm{Qdo>Yakdz`O|l%  j(b!#uz\Mpр:I/:L'wMKt1\>p"4f\uPs*lLQtg6w0u1ը% @y)F<;O:r'G95;u$,Z$.!h I~ablWGEN5~*4%X[V=dB@]=ovq{u-Aե%{a ޽6`7Ռ9_%ސOz]zN)ZY_=uMǰ8\޳e`nܿLp^8Aqf_6&GES ,p@/# A9lRlMp E73,NA:i}R%6\{c0c%݋HNNb {gʆͶm t^Dd8[{c3!7>랔!lPpAixDj2px8;yۙϜhn\b;E௵b\OĦ3Q'?}dt6>;k%r,}iG(˅PJ9F,H"$Cx`:\3R^MsJ66; id2SGY"HLD"Xoy"qϟ-& ~u~e[:3Dbo}p GXoN7ͪ tGBl=vJPw 6QtzRX;߻\<$RCRPf1#WhI#Oϥ3|C[)s%'l4e?_Z(\%7X@i5m- 1 I&l;L<24*╂񓟞 V }u5O}Et:.oPpV'-\=# g+gjIkAɠʗa~& ^j"ZݎX)~gWyЧ!3|*'|OĀETb]RikݖI㣛Yw(tN߿{BX]G[D쵞a9tX>8p[HT8nS29Yt;j Em IA!"y/B0h "S@g?ejV6VyKNJot[*)k8- 8AI% O%vNYITb䋣bEam Aݤ1oC;6aJu@lWSQ@;`#vk\kak pFGGaWs0ۈH y ?GuƖu5oFՌYrŖ!jR*( ,Sٽ{z_ :47AX啢tD j  ݜ{R,*(R*HQFR E[|GT=xʷgGbfuC=wg^V_$T ؼleċŵCA4F2Ss|KR`jSǦ'J0o;ѡK\BF$u?8=_p*ubj+9}4@LUw} A|wI&܉މVVBѿޯ 027X+B'ԖY&e,=tBA*R/ ;C_Ï6Vh9 b'ގJ"p"]^J{5N]kM^sdWUmmDT"bu{قPN )9(q 9u|أdkv-%TqTg΂rE@>+Q\ `~a8rBuvE!` K0z-H_QHu^)  @60pI" Er PYiAT[j0}@y#!" nza$Dd7gY| |<岿./bu~yP]'|_X'}Z1%~YRQT+,v`&/zeF;k~,bY%s^ZƮƩ "2U\O<0N-?|d B><}Sap-ZfEAͻiF6)' 3zS2F?&սjeT*FOfӝmͯ ooul~ R419mpo<br^C~8gۙ|rσ:'RJ͜trJzM> 3(.r)g2xѶ3MQmxf8XVvJTmi(J#b_]D~Q| 1; P݀h*`Yub.K},qXRJ.?8+t_׈a4YSR ^OdG ;0e5~z=GSnX.Z5٦;3y9v[6| 6=y0l!5*Gϵүl^UVk7SIAtA^}J4JԷʷkG{Buz+(V*^GȬF>[>w\V xPwW$+j޴m^R&pHQ7jI&!r5O,zy?mv[RX7Jm|8g↌TwBgct:eWoYwޥ,OUd=5=j)Ɏq3 pBH&&ųVY=r`brX8D57=F5 (!;Gno1U? D] gU0燘~*D Fxxb}H/ZQXG+*>lS0&W7w@"t\=pIKdsX{vޤQ!)7$ާ vd;u#:_K?|i20 |F:*m;Ѷk2 I {,䄨Kp(T$kvp2X>E)tKppqPiziSpM-'ҳ4ݲݘ:UYDg2EX:_ϒg'D}P=ifl# ?G[¶qEeʬ22#@Y)6@&9p;Ihcg.UcFoŽ ̄|s9'U塃)ȯP vӮµ~;*Mu,Oj>SI,X]/sV;c hFכ&|&f[5BN&Rօ2 {pL~9wLNc傔O/W%O[~Ӭx+GXŻ_{0\42iw WYA肟mP9~>5'':5m_>%DLƔ*ӫ?yI&k>_6wRm$ /*종"^l'Ԩ$d @JV^ng?nI(I;h;J=劏??o^z]t3NЦ`_5`|[.MqmpDƓ DjdžSU*LBB~OVu6IHɜΪ䓎1GݻEfN4JT8pRUB\@ܒs Ӌ-ŹPpu' +nrrCqݚ(Ĕ܁4G)UeTl'W; } H# `Ct}j rPSAP>) ppgoI k9o,:^"D},6E{)'kW"z3"|@g{ Gh-nc6ȢD y)p˛_y>rC!|U,aƻL5K$F@0J Xy_ВO* L|r6-OXC*'ߴߴA] ozKr-ҹ 8.u8n^@" }zLu` ]!z&NȆWoDVr3"tcz^UyǛB_Ey lAAu괊7'A6D_rcZeEhF(S_ FHY+?rTJРɜ#t;Щ]2`;NWmu1;({벍L}o%-5v8bRBf CSuiıUYwmQ8J?*'8tPv>h6ss? zr~#qz⮔1"fr}W1+C` l6S gڊK(?LJ@\qLT ne28 N-xFl'pq"Z*NNl+]ʑ?g MVSvyiBKF#Ҩ8j=PQ6y"c5աlr)c_>Ⱥl/n:vM&&kg9^Tj?¨f -;$ّ'o]ϐ-5>C\ Q }*J_{%_.\Y d.~cE\ P`ZJywT?f8Oc:Ȗm= ~<$6#Ѫ0}Cq%:Bvq({Pf<$̑^ݝD\Ԡ ΍ cNfX2:ܯ _FHYK "Uۄ&`%h9/>1pE!F1[h5'(޷P"8yzjS)whl:0MDf myde),n`Bm8iHݳE2޳#ĘPm/geY.[YE@)'5LPGfֺ2@<ȀA.dy X-Hp^NGG9}\?IL+W_>7}mh}1q@<Ba4R~{6sJ:XIC%<`&#<ԸGߐ|dǙ]کB Tp(49t+^O0\:$ ΋ -d1poj1BS)E_JgF<,o`Jm z貘:!zVhvuxfrC/ C ď-4Q!ʈQL^A}Oﰄ %6hyO~\a"YCV&SlN;͉CyHx^'ͶII {ƆTFCh\cZ ଎2U>о5jR3-L@'"ێ{- l}À ;(G3>ԑzxa@C1*f L܆~a0Nj,FQW^Y'zV!nmhk gmnֶ. ֆ' GLbBx/6' yJunBGK@u`wތhQ򊖬T? z]n(8&sHu5_dU{{cho~ /&8qMS \5-LGE7:DzYfd?91yS5:t? S"]qDV"9<}c@0Ska\8ph^D]j<jЯe W9$bH|ǯ<#PF #"qc./F !;3huHv(šD@ƆclЮ㒉ByK?nb]Dg^$uٽe$:ɗ 9̃1*DRըYyW}ܳފ(]mij'G Pם:$3^,y7{ZC M`p(u3-шzV}]œGitOۡ5+l,DEe^|dYh|Bselns}(nnOHl{Vkb}"f_+~nZ<0.e)t:]Au'iabJ7i%k_t)Z f2[n =HO_؂@\Prtl"p}%]&ov1v3r$ڦN'VM" ͝rTqR4EӖb('VeEXх8ϗF=ftT+L?{m0EWn-u0ԡO% /C n(PQ_#Qpl}bC(0KE!S+)4~:?0meq^m>o7 GktzG7ansim?98n[Lh n?Գ&^/ \Rд%14}t'V1QW^mn7?w=nœ eY;B7SZt#W5;v+b>QkOx}hêέy[|'UQhTYb[]S6DC]#[_Eup2f M*IZ*^/@5ҍW3#Y=Ef@țx }aa0HHra"J5Kas J,$ ;cZrkK|`Pgj}u5ax/'Cs8 B|ARoqȉu]ܽyBaf(Xy ,QS%r??Dncv-p2*)zؒbl_+FSr!NBȥ,DW /g|ݲ2kVx>t0([:^γThXDc vEnF\}^Gqklܹ[t [vMR *} b-Vd(MT9.p1*qsUuJ6뻐Ƌtf'sh+! <ˆDW\VJbB_-@yڗu ~ږ6of5ΠɧdFO J2^#"8Y.-(6]\ǑME@Q83~Y"L W"hk~Ān}yQPp:N;EFb|͚~w? _~ڊnDeX sY$)KNDG秤;Hxݺ]S(->+.Q~+id1~A]`92&SSyC9[Ъ{ǸWW~hҺɬ Fc}<=RN1RW`C6`3:""7'Kz* i=pqlk극5Kn/00aW+QûYc\pJ0t[{T.u}$<#}m/"˾-c$@`#WF!^c~ z FȠ/*1ڼ^<<&)Mol(bb@fSD XbU}.%@ibt=tёcH`MI1T/~~8?E6tݾgdfgi='$0e-wX]hsyk,"j6& a fd۠"J%:TjW p~IyEsױEE- |cňNzd] T0 u͒)A :h.p(Y#j.N{fw)z9b?dɞ0E93@11^E;K6q :hU;f |}S⭝)u\75XrvnaU ;S)IyM3CN> 5ʌFO> liԲY9#Q0}pwZbhf/jw pvB2 cp^<"zXT<4 NoTAxѮX|;WǬcKb,dVdkLpHx5$ nxC~`Q-=xٜiRLۿ%tL}+Бy,μ̩9gQ4-0rαkŒ^c%:0By#]NHVZ9] l݄. {]a)y?q|ő^_dn`9sG_Yۺ*1S'd۫vx?,&HldV8Xu]KJ#ʕ$OIve=biBqACںwzZS. ^L>LK8W4qU5#Nq`6\[n2Y N%ӗA}uwA=fchl߃̢x1u$AᛣNdp2'{Ç?r3 `SdB{zҖDzeAu0ݖMoub(8]3Cz6"01Vxe_Sȣ{XɓE"r*ǁE}p{7fՁx'xjvT8|@BY48j˳$6@Wؠ˙Uirk7>3^{=^ǘaR]sSn2\ :N,,WfCףJfz;W4' eui >eIpl_WřX`=m~Z9TA^ğ20 ~PW@+LfMi#?L%ZB^bTN}R`k8-@JˌM0P lT|Ԭ6d"9@Q2Xa%C^#КI/6&]܌>5:1ދPAU*f>;fX!i=8˞ RA|g+߃҅G䴢$09* ,!P@\V-Z+|Gs7 ߛԐy9THM—4jq*85ºbgH,_ՉAl`gU43$,i})a\;@-7\#3-v)ωy.=*/`I8dȟQ`Lp@vld>&~w4ck.h­%XǔHRY;tѮHYRsA7-6vq!:@S3V׳GBZqt2Qsq=ABO4UrJ>RY@Ѥn+(] ϐݾc]?|;J ,k?zɐ"\DHܡ׌Q`pkag9Coa"VF=ܢMQEY@ |O5N+E>b?3 _7q㈞zt:b'h,}Estr{G^BoT1'9b0`h'F{@Q]ٞsuG ur#z=y{&N]K7\@)<|j:vjf8YeW:%z|]sOWt$wй4t{g(Vo9Q1D1}eV:϶~L@oaZ+H$~DrX />) wDHTo^ω#@659>.ŰƋw:}:]sGceP&'񏇹Q@Šjlmž&f* 慬+e^ {\^יl@bYKC93`.wt iXS6-0o%|c/2%"#JWי0;D:NRz{XScI)|a tjJ3-P.3jKr@3yAn=8"v\5ǰDarwȾZfz/̞^)/BF$>[jd[",zeLf>Gdc|6+M G%H%yv=[ڨ)Y*6YG77{:KQI!_ؼ#7-sZmEvh =-6(”BOA2B8Y)^w1wWxj>$sYvؾn6hbӫ(l3Ȳ.-lLV6Ƴ<ءb$Bc3u+"Mz߹BJGp@V-[9mY{)Tvg#) SloՂf%=X+JEJ!~b=<_/hq)X$f?}Bm~Ȁ78ԋtrt|^kiV}ZlFF>I\V}2j&Pye&F/'\B8%a᠋ߒbKؚ~ - gigX" ?ؠa)RTgT,&&vd1zy3ϧdF>IYlCNT|A&fAO6)pb); k=Y_1K!3ȑ+ ? 8=}╣\?y؍N4qxZ7'td9=RQpU.5ULtHS('c# @kc[w~/U:FUQQb01KzAbkAB1bk2419`soSu_Q)@)ϱWEH]}#po5Mg5Z ;8i3H:KA=L[OKV@_& yc/VKE:p艾YWIl>mZᷣ"f?^>IU2ew,xn׆v^]H"iY:"?-bcZmXSp K=~` }~e*>N&̔GlS)V}R6`hcZe({ 5q72N_y"zƬ+FtH{ϯkh@OAԔɵ;\"#?w]c }M^LC:xGp!t_Hoc*|J)4VWn1l`&jﯤN9,BmgN{v@GhV~fo~C S+/r?a9ӍSz Oa(.lP3W -bˑhI聲œ~_d-K'y퍀RGLQ@-='m$#-qCdzfɞhLO9=bB-F,;f]<J@p>ݵC/GTve34OS̟n  {# ? 1>2]s QB5+{Lc݃uXldYU/x|ǥ2ɦ>z_Z-8-]%~~SC gSꦓDf:ҩ')> G&AdpKl2Or&..3X ut';~+B܇Wa=XSgӺ2 Y؊pFq(厓tctD_"~wuJC`P˧aSdWހ\Qz~IOJ|0׷m&"!0(= Jm#?E]I9߄f*/]A;<9*R$GgYfXc<2<յgnJ쟃YL& Zf%6=U6[f0!& wggkBQ šcfvdhBZ^Vv-ﯽfiTn9|``aBY?H,mA{Ih1PYƆCnFr$ ')a:0i׋ q:GEA l#0K?'A }U`Er(29 yb"}t>+;rϽU,rffwX:y{L^@Q& ܣ+Xq p`5Aܕ*b# @U#_"EkHGvFPZu=o8Zkfɴ 3CJu׫$,9Ѭb yZC*V*3=t`# ymb؏v?',E(([@ovGDy3y4&M+6Q:vqP}PpoˇALwo 8X:*ҜcV^v/K)@LVK2G "l#wDy~Fks_ ,8,|9x[in Dz=xtdAhv Bl pZ`?'YꉴьYAN~ĕ>_L*a C@6(USi` A*ܙ ?sY4E<uOlmdۂ[LO{͇˔e%7(t/%8mU}IqΥ9]h́DAFwV3e`db#|AVmQc9V `(z[{(c4T񙇒%2xPMŸiV&tϥqŰߓ#= sr.9AƟ9e7KExĩ8~Љ̈ޱocuOAQuoNQ4r.: $5*\&Knv]<:HUN+Eg_gXE:䞙y#ɒ5+^Hoz%#c4.-$nvCN? @lU`L)M3y@7dNTl܎$yלk R/S YB~y}y)eyp=pB+[P!}BZU}%'&;xF%ȁ $_"olcjiyn,B@M-LP[^;[-S,FPBO.X9 qjF8nE2@/tj"da%:¨hw]зe}}5 ZxK[,\ܘ]b0J^%gO0Re1_߫#b5=xAwݧsJt8"#e!K '雂+d,^BQC+'A&I5% <%B8 (tMɘ@OP J. ],ج/(M fsԈ㲭N1Q*+yAfKk-f g$ +6(>A]!(b IqЭ#4SѝVóvؚb+Qo8 ʙ϶V]rzFgw3o^B){Ql9SV=&"Xg|!l;'EgЉ8mǫ3"K:`y uTx 7- wBhSy}!Dp *_ͣWe$7YMzXIэ_ep,^mmum"S25?<-nrO& ɓR ]MTȟ;F- *}ԍ7c!uzfjQ@!W. O+# NE,[OWES*wPTҶx)b޺,vl>5R(TG5E 0SG0[w^ y NVSU dϒUc֣YzeCaFt3fxSg O\}o =UhědŇ9*ŅPs6?bsysf|^"MoJsR :/ܷEqmo58(PSE$une,XL#`;6,ȨPt$-te#DgFGyy)VJ#k 6|jG#7zRgo 4Z|;x,0M쿼s|U >x^" 6Xx/ӴC!uzX!/}YݤɡGX(:a֔zDRgbWYHW\"wD1FFh@*y¦m564B"bbxD˙V*'sGM/Hr,?\: Ӊ@/޸!lYogX^T4iL_vzT6/{n%HsL}RRKKQ15*x !1Kg`hHXDo%%i;}9PHi`}Rvr?O+7ok# j,T{!+:;KBdϾ~YM,b/&t(P߈ѺV!qW}ϽkE2\E!5ְqym|?`G~L)a I 3:ҩԒqubͧq!rX7J" ^YPأʦKv2J w)!98A4Nt ~j[(M59‚?"7Dہ" =^gX%0x⑇Az&[war RVLByvMU_!7r ~ޔ!~!aZ"יpXP"ciʦqrwjAck#+{$1R1G}&T;{4H@= RjH"'&^ؾ?۽텰?GqoXD`:%eՓX@~Toկ(^f#r+)&NNF\-,/(?*tya٠MY:@ T{:66(Uzڥ%46NU{dsy1#wt#(PsÝ5_Ag2g}Q6A1o*#*S|ͻx|I5-Si^.m%SEqE.Ͳ(r`oSɕ%{=LF;Np9~{D~-C0|Ŏ>} oAz-iDa]S&o-=Fj}$;R,[d'.uL{o TbݸI6ӛ(^K0j1L9YY˜Rj!ixV~Ct(FϾl\"G:]I'ȜtI4~̍{o/t=RoӐ)Rbp$i\ fԮ0P|W$ 2C)wJA9Ԭ_M.cIқ͡6rhUcy$J { ^(I>nofpR'MK)]=ڟilEk)V fZW(6d CEdͶ &*|w snGhFu˲K%^x H}Ƅ-XϫO;CE  ;)W ~XiDjNIm>"!ؑ!%CV/(=*H|܍=! 8=z$;1"_0]1O;y@q-^(X/wfJj/Ƴ$cm;uzz {^: ibA},ryC2 n4Y̒ՐR ӏd9bWX*/E{]{ -K5XZ';y`骧БdJBpL0^D68@oV̿K)e>k=}c)[΀*l7qm{{?Ola{=eHy4rE>h$TeI2g!AG#.P5X'9-y0eAx1{&۫"lf/܈ `ݢJA~ӂG\!){Ļ]Y (A?ġ_ѡuJAL`҄ !2Rti(aA]9t_yh㾎0[WĆ?=|*١0mmBoF%Q ԅE/g Gb ͬ]BzR5o o$D;tRLȽ%(:KQMʹf[=LhCO-b%xemQA c FH|/2Qܰ[e <QZq]|Q5k3npSK`yt٧R < N7 O^+$ !'9+Y+t5_)VpiBC|J&|ԟOXcX3Vz=tCS7UqOk=t)/$Mqqa,XWB&ŴzJԣWMa}ZK[gdYH^qOJh';痖ur{m wraGBBB,,NfV^)@ar {K邁yATS<1 Ej1C:`nYMH[ۺ)A%q/74SE4x+|ʀZalZPǜܢH3 \XI 0?TX*Sj3J/1"A|p=uC O+1" @E2yeMj>(niL4)`{R}[*m|q7>z2 Zě&E0B rhcSax1TPx.A;l]6QA/Vo9QqoHŴڒU2;Y?aJgrOȶc&?m׻r6rKXpj "R*igi&qBY-sՆ="ScC4|h\qt }b$hJIhzaQZZyOa˄c(Q ºbq:r~ q *azj 6^ cVBy4>lS^w2>P{PVWE]Fj3iSUL; ޻Yn8QBdLfh.v#RnXZǐ?Va9y ">5n=vTn/`, n{'m'%mwL{e ݾx0dI TLYވFvV?`+>N0|AHd5v٭,t&l-ju hO[3;Kzrp@ʪ Ld"Yl('7͢:8*r}N%Ļ@J+r?5 |/mSs+w]+/& 'W8s1 !u0~[ @4hفټRʀb6YuʿsdE70z\>UNiW;皔lI#˜L7(N HoM="h;hk(|,HN^֏U*90m FoMA`ϐ%#OV3 ݁:su~.C:2oi%U&32yN_e G]/Mpma4r=Z.%a,8~, <衸,tT7mnGc+=!O<'z..T+K#V4ycbv: ?eݭ]Ƴ&a95bEsJߛ;]2WnȬ~A|Z; 03p.@?{qGp3`33tDy'mVy-,_CZc#KQQiB9 Xde벡SYh|܋ J3AW]3y@q$Ei%g>pp(j[bENqj6z, JL>7ҙ.K.0;I iLfe;Rc:,7#hK(H#.Ŷ7y]8(0P2_QؾrzJõrEbM^'8Ws֍kuޕţKT噹bYuW"H? 菳aj$uRRY(*c(^xfC4l߸#5 (X2a[Jޜ٧RBD\'ч_\W}jc3~ +'H߇LN/.ٜ碭 \]%8X<^2м c5\-zqeuH<IJ_mw{h5w/U-jЫxgijY$a/ 2l] c:L]=*0%K iW#Cd=EP86 m YFwm('^),tw#f+F;o7FrYIex#.\?. nD"H̗o:Kţǯ> ]]u7>Qg>ֆ4Z!Wٮ"Ρ;19=o.ʽ[g(2Y~M6F+8AknkTVK Bp3l@[ *A(`t>J%hxI:yr7:N|NW$- j\di4)C24xAO!)o%%HO9fn")a1nxg OA6۩DseÞJn+z^2ETi8qy( ?3 R EG=U2!gnWl,}PxTQ˜_o\6rBʭ 'N80b("G."0~FlCR!^J{2uq[ʹO?.7'ѫoA7;ٱaRBdpZv;/R ^@8N셨JuƝ"vyç&sl=NFy$ L@%5DWdߺR..j 8n9ҎHpBF EgccoO3- ,jz]hξ9( G$E[jy$]V\% $ #~MwԳ`­̞˽k7t#C[bM: @7n3 NnBܮZalSQϑV/oXiܦӑxweQz!<|iމ}MC[m-稝y=*?DM -Px)5n0Bz\5+@-Y}iJ*ҙ}*&66E[;HGK3Ehng)N^jdghCǗK7Fq U-a˧üʶ»V`}.k 4%IĮ!_"8% X/ϖ|:" f,h:HW_n ,Q⊎#%ZnְhY8_Q8:?hywWcGrخ~ u,MJ0@_M .wǂ")1 m򈊛&^-Xkވs>?^ƒ+ϒLUN :p'Ao*i+c2h}뱇eyE{6lv~4MO1? ӛ+&!a_Lteu O_B7MXl| -ؘ `&~ !TAPvK^߈2B/DVԾp\S} ]w-i z4$ME]vdkA4CV#Jb4!9щC:晴V|`4z.o6A s$+0GʫX#~8h^Lg|&3D/ρA)|ڷ4EfPc1#>r6x(V?伆#0Mǫ0=|V8).>=&MK<_PcLC^[o|A:)ޥ!1.nUt}ɶ̖GP4Wc1RK؀%L,.ZMA0N t;@An@KDވ>|`SC-MLڿGOe|VbX{4lS].p^lUkMMK,Kc}k_= Jdͱ7߳r|PY."0C(<3O\8qE6l†tAF.KVl8J-pReYbeVvc2Z:~rĞcڧXFpwê~YUo&#Zvku,5RV^x ?%v'c?X7ĂguJk{-KG2A:R Gl@K/ʂO8mW҂lna|Nm4ё0]92*Y΂3{VQ(tw. 9.3b a1Fv{&ъ#$[gdYK Q {c;X 4p@ohǩ@6|UfZnNֲcMǓ"J6|V"{ߊ7' WbfjV{ހ܆Wo=t^n`It8#c ~ g**^{8[Ul$OF{H=S=ssжd'V=z2 G-n ocm; TFדn}cS$ҫδw`hK /fP[N<--t}%M#A!};)SXr_4/P[N*"F"UmP݃_дu2%^KW1jVtCU :GR?M`#P^`=f6p/:2{V}4^`Ts~KJ \Po.Cd.;p,nP+__ijfR ԙn 4C{%Y[  矱oN4bm3kl$x utc#4K?u [T?@.҃iʹ=(r g%}E@0Qh]P1rV3ĴOpx%KՄ*k( a4R9Ki~F ݪR'#ǽNUؑ7 "8a31g= }7YS oy5n4VTƧQ![{h0(Ϭ&;eUުmDzaqw峀Iu=gjc;*g\?Q0g.cP x 09Cݼ M + 426gMGᮥ8)EJL¿/k3`CggݏhZ\XF;H}0x{cD-Χ"T*{bII8Ǖ&uDZՃ98<Ëφ |ruח]D0PC:A%^SnCNX1D 3= uzY#jAZ[ٖlUr0GodJ* R.. ? ̑ތ.|рKvlA:%!^(rMObql((J FǜAs ^5ǂܨh(*ٛswB &x,v"W9*S"LvqFô[YV+M QQ YڶjJA;;a},3@~/a(`m/4}WMe?ɤFȑKfzö-q$)M0"͡O=g_shHtm~tx2-9yl&w.ryGuSf1UBv# <Kb\4Je=z8flgisr$Ʈ,<@ 3`x„ָ^Wu0j2F˅&6y]UcoHGG _><@dY'y p{H^w@e9oߨP302apQ3 Z?T9a+gbj ,H(EϽaȸvI:Q_jC" yg x~.jڞBHw_iiSH?iϓZ[6ym{C>^JoD f{lH>O͕s]hK ]W2U4 IIL}zu {N-{|4#Ѹo ve5%ތ N&K: 5ߔLsGO=)qQ۾hq<|vvzNbu@ nj "z~S,fBIgYYg Qij[{*b~a%=*7JHQdBMDb2Fq.TYmkm|< @ `zG!ع EZ^W&bū8?Q.h^hYg$&`x QF (y^ D%H-?=d~GW`,@[`Knp5w8_10-ݤ2]Go|% %iD|w95%ϖnZ<"lod'$CcA.d oS[hi~G[OkqGc(ZCR$g%*X(|NSɋ__Pj[ $zFRYV{K!F^HXF.wOp 2 dIW%Efu^:lNYo/viJ8>+`9( gٿ75|Mep:% _*L5λ^glKv Y+۴ 'yjo*a%{lYĠ$CӘÕZO%%AJY*vSna 0Bu T)ɟfn c^AL 8\'p.8XOStvuT5u Ebdw5M"g11mW ?XKMD_r)vq`3-]EYSdg>*d :&ܳ -* $-7xsV>GsoVe\rrcgbf_v`E(%"@qK8\jrNn-JxHClo ՝( J}yfwL+5Gl34߲r\f] lz2'@J";qNKQ_3%\^8KTTٶOjZ4=M{A-ZJS0B ;+ d22Y+KFḳYjPU07fj,q`+aFG:^zҊ1% 5 h R`%){,_B@aQeb= JAiOXMR|bۜj{$nPe^RJCު/5ŰfީI{6’a#SyzUޙ&(|#b603zuFp&Iԅ|xv6aabZ9TKe> a0C 0?ϷҴ]=K0N;&Y?XW/+"sM0"yC0mKV7rHƠ홛V8)гH4Mrc.T/msT+Yi5xIo缂/"+t9C4.;K 1V"K)=]|ك5}qzUWKՈ bS\uDt}JM[̮wTO5ove$G|X;{VJ*?äV.`Mvkt \DMV=KooH!͜&jqSsk[^rwRϒq0GdX#BQ"<FMHXCx&$}o]tᡟxD p0| %ro+ eyMc`6`O`f `'UGÿFn}?L}j&P8yw'"} mĒ#՛}$WQœB>Yޖ6Iz!D~kql}*ٶ[u1\>3I+~;o/o~x . sH}nulX|z3 f:$!i}DI. kνĝ=bcg mINƗ^禝?}Ep/>q;۾S|:ibP40(L!|:n\"kɋEu;m%-I1z1=/x݃IB4՗ؑ>Ϲߊ}T@%,SPԢhsCƁFҀl6! e5;tʑD,͏Tez"+}62>IG&(wϖԾy6q+53,t IJԾ$`uP_\zXdB 4c\X ش]W)@Q+GT6C)Jj3YFmrUvYSbc;=Բe X^' b>7*wg. q x-Dy̕Y$]%րs&Az)BCSH%$e_)MbS޺ * S#@)2ӏXKWSL7dgɺd^2z"R(P4K趩C3\V}(W5DOo^? G˦HvE;4$,^сڎ'$,GqIIݲ4 Sr6:Dب2=lycq^YxR7F~7x#@ y_5m015`ǚ_!ݮ`f/8L>h 7nd&et܌45%tR$>7; YDf)Ydp2DݽL\5ee'{kmUktmbx,^}ݯY7A`ns S<,: d(L^7JkU|eM>Nhj3ƢV#G`M!xuc/&^hCYDnéxoV4Gd7c/ h|&,DoJ޲/aGIarsԸ'ݜXJ fQ)`~q&Z rKd[cMџAށdm0Mx9bq6q4ԒF| vѺP):_< +i/߸yh+;yqxߩ bmh$lKK_+guG#NgNRԭpjX:)9Zgc-I_fW*W`c-Tc2$[̐ *Q I(iYmW=)Vñ௓ /#6+LV Kc]b51 iݐ󆃣?-nu<5'Kg,`%| FzP{H[m OvSHȃ"QPp{CO?D(^DSQJޚ7ӺU+Gul״-*`?^ -3S+z˧pA C/|ۯ̋< xpT9;Y/uUT$S"EHOBǭQW`#*{Hx碿a_vL8Zi& 8$NL8Jvgg づF`!g5G\'_BoOFBOu4圶.0=Դ=PjsQ/hԅÂ,Wg!pkăxV}_'e /aA(dt},=VE5 TfoK-4^*㈙b#Ix@@%.zaLE{8}q-:#HOvNT Gmռ%IPhLn)iY`hN{x=Vsgr=[1Z`>3:!mNRVjIRc=j.0 D,'(WLY%9M9X:_$dF-;W֟͆*Y33BLYmx[Gj=|Z-컌9>=e#gYʠu.w~MB"lf0s 8;N7簆ca$?b#> o׶RA%=YbXp8k&O rZj dMYHS4G<0amL$˪CRB<6Q'_U7ƅ¦J8GM@f2`~ש}e+Z/{o6 ZůzЄUp-Yw'%(Z ;"F&{c߽x e XM>t]\@'M_$ B2pledrXԷXhF8 K+L .Dt?XkLQ Ztӝl~O5+; 5uNA3;Z+M, 6[S:)F*zg'_aMs6BDv  W R7HT}&2>I^~D$O9R e9ww@%G L~Ja̫ݕfХ~BlBӝpcaեp`f!'B"xVyD<5ͼ測 k ) {7;ɸ߉t?@{ҩ5ًONXQGzKi&px]nD\JSo|p@Ōw#"wlco\+S4V=bcH-{UU{(BZ(;*;_dgƯ`(V\e ,(O(bƶ|ˈ}C@o3>h{MGٜ@Ŕ;/#9s d~X"f Kf|^`㰬$_}_}/F-.)Eqn^/]@U?@t6*z\?Wj´%mpGkj@X{n+1H#x@"xtaK4x3r$q)># A 4ܔ@5&oܦ4U5X_?p׻u%yЙcbE|G,_ ?jMQt" (5|Ы͋dU_cT? ]JOyE/\5\B=ML; M̼ 2giVB<`2>'k6` N1^ߴ7$Wu6~$ᨫHNgujG|<Y#Fi5r4bF _yהzw=Y#~ȲqZ,U/8y]IT^*G̝ q2'bX&7ftd$!"՗A q6)4@Y=0e e?ffnq![G t\; KeȊ,P^@Jבww#+ˮ@&Yu tC[ cG*:f}"=u1idW%Xp% l3 y[q?JGXֺMrtYuL?o_3|T V `1,zPfRJj/Lj#?j툓[X}4E5?9WNL!臌%fYS6&Nf\Ί}CMIE%n|lV3%$Poaf}8^򋚞ITc'08Bx_3kPцB+kWSKMzLܶ/ɖ5z.8;o-'3#M퇸 ]WTBG/b)/%Zat>`F: %5tb{HB Q{)q^a`,rt Y#ނ1EJɔJF|kOjQAS)=zW$+=r1EFXb ~\~`Ycd{B {vw\Us5(mgMѤlP d?5uZ4RXMͧ2$V*A 8!2  $DC"603'*U/;wX&CDH2|3 [DP'kۨ&koE@"c|y08O9{C\ .|0 .bX7ZDY$ dDu.6:3~V f z\g8Ut[4,acklAԧQyܪv3!Eބ+m!zDMvf~F؉q|yuLx=q_g8G~Zk(9t.*6"-1\gN.|pC(dӂȆnUn$F6 G(ʃ/II{ x0/|܎f2wT8\nLuXQQE<_ZB*1/ǓPzGz}k:(aAXH})ZTjq+Zk?dŤc(w Ʌ0KLCM` v; K44<Wֆ˨EUZkMvp^k{I'B-H M`)x*/&hER/DǴp[!zY'$CPHqu, !*ZqմemNNg̺LhD +#O ysȿA^ܾJZՁs+(5 %w`b,}F;.~4.,Mn{KQ}ҏ g;Tퟱl;iՎ34.Da[1J{UzU;h>rHGZoc=R+S t@=U: 7|o֋ 9.JZYrږ|̯ γT1m.`e%)ZL4#!զa[q HXgwsAHD0q{=vmi\/0D!@1ܭY%ܞpt CVC޹'YԋW*"G^h垒~ Mm AB~e\T| ejM~XUðHdZgM6v"XLGs|I^0-M,i^ҡNB z'*KͨAMLBEw}bݖ$Gy1H;ugG8нX-z!(.M H6ԂGWО[%T2@cI?p.5d!sZONZRD '͈RIK;9,Tb uh}:J ԳZ {9VxMd젞]tSVo)Г@EH7觽kA35Hvz4x]d=*oFY>#7k3,T@$ނ;hʆrIغw#Yy[ L?:hϓ䕳ꕣz>=.O8T 1ցPg ' gúȂTo#X4Vz#s#y؊leK2[Jc43D^Cs[ܴ u|M$wb$FP)M9Zj:7A< V @Fo/Bě"|XleɕƈtŦdp5o7%W SplZIЌp>`rj}U Ob(ӎK G@ȓ7i?QƑ)W)-di'~ 1?=Kf\ggjSKA6HbhtWDΗ͑\F]FQpOfE?)9XQշ[z.K d_ H./fpBSM@F$d%@Lwf4P]@J(C6ˊ(m%2D WQ|m`i8D>1XSJcqDB;Bȑڲ{¡5ǻԺmO[ :uhR &U^YޒY:8O -A$H~RcLт:v@ZW;j嗽H:jvcYߠ*X4WK~X .75<0Й ,liVZˑD\ڎEvU+E{}'RǺ9`he԰oTc=Qe@M z^P\y[cX="FDoL 4~c,qfb+^. S|HLzr uRޖΐ+ -\R/ # j|E Q :!SCN5aa^ F%1G·<1W?J< x[C>W8F0>SX^k 8M#/{7Ő;?:AEb:UuA y v`~K] Pr]©)HeBaSF-j_?ͯEe_t&NTh)~UIop{.A5aKU?eimv:I wm'W1ɭ/0č4ϖp:]צ+B,g&IZZŕLơ׹͞ZYs+d6h˙_A"A|WpnR=]vʏ`>'^" ߝ?lG5JڝeUa Bk L*݉|,6ٴ7>$W9 9t Ӕ2UNJ?9Xlm>TH SDy5cZjnN.<|EfB)`s?ي<" Vc/B$:YP74י)qyئ𔴨,xzWh)x=KiIvBRS7S]h L&逥d qvA0œaU-л`8GDs z5s,f~-K6i@ 4Ll*p}9<.w8-iye2M0ySKX.%^HZt״7xWNKs-853Ny1O7>V\FzIhA~Ԭ;4``b`ԟa<ӇC(f^uO-1=bSI oC<{63[UbU;"UD8j$e~N/JSnr_L PuAY/ZEg']&"W7F3(A2ҼAAYyu6jPE`OKFa_]"?9{ku-@R]Su :#$oe:K{Y}38@ɘ|*2,]2TפT|╷J;/1Yycqŋ&&qӌQ 0jly*EIoN1 wi>`iۅ;x.  yeV:߀XIgS6޳͌+ڐ,Z,J%jR#D蟵&à(z.k&py\ӏǡЂG3,c$L@)" C8M8FE𑞪643 o 5M~[vIW.y?:q 3 X6 mV0*ž)өy$cAD6JyߎY~3̋#=Tխg5(G֞⎈aUm 7$ Ic ){-ۇzOy֨y*V&#U3Éh'ێZ`ԽXkOt;nrJ(urgSzp\kokT}{s:~[$feb'2vEm&6@UhTT=.{Ӈ_p2#J2w~tx$cfزd}F꯼fg@|mz龟|`L~y-OI^Nm*P1 -KL혒<%U“|@X0>k^)&Q Jm`~ҀT->E5#dG9T@9ba/_dv[nr"6%~ ԫeyi#Zumi3Qò 5oì ݇~r.I!i7@Z<麀`,ybjQ-_>=!eNm=W|ڥznjcd72,*2._M30T*?˦ʬо/r/B$\Gߢޏh ljJ-1hr&6l -kQ9|37/`lOd52?S z>+T&vOQ,w^xT"g!+٤Mz]xʭR˼ݝmq퓁ieJX"G}31jꀤXȶ])d?jZ9嘡GӁlMQ5ƔUrEgcׂ!6 `=>؛#"$CN}3ٿt,pOYFbp+ұXϓkl-.!OBB:B> *5iYiW8"w!Cg/R|Fp׵zgk(scRsNa71$"05.8FnߟjW{;ovݺNS ã:RɶWX1rm8-kIpI4n Tu픴*,RZӃigB ^:9 ݊KkuUб8"vW5 tHzTC/v@%^PSn6)'T}'3@Qڂ*.{8{PFpHhLrLRJJ- @IF  Tq{9j5o!,EJMFlѣ)N,)ڭ (.]9=IH(d6s?hHmMʒb׹ I.2FnS&tCviViX<8+H[s+K'"CVyHKҴO>!>Z"i'#^cOÒSnFqGF~$0_hFN*Ap:k,a &>b{bѝD^=B72ݤ3}ȽNTKWҭ)C7ga`ǘ>8QpZUץJk1SKkm#sF UWKx0M ?n"/0"]ds %v=Z#/ijڣ̜zW+~!{SHPգ[l2 &UMj{hv^uS f$MB N^E yLE]9n\$CɴXdSce\JM;q=e s6JA(PUjG3ZgUPl!K= ^W?+_i! !=;G/y<"==vwzG0&@1;F%!|#(4H(TZEHԟVc %E Iч{d$ZX Q v3aVӣ{"&j*´" k.SWCSкYZS[Z(xEo˥[xd̅X.*X``M6W"+e(|*ZlA@EpA '9*K%~oʌp֩Z&Z2X]0r8TN܉#_dQoߧ1A]ûQަÇn" (v;H0~aj*Dd`h )|ɂS7$aX SlnW7-IqGT9sF6QXX{%|g>ȼz/TsnweM;rf`Q(R9%::,=w<עN{]#Z@>j٢SI9CVsh@[HvE嵠RAG" 2bV+w_<0VF#,;* _$fODo d>7cK3X[=u?딱᫝ä́|DScr]ϣbixz0-2;@]tQJTh.k,P(9R\>FO$=2 dYFXg28hy,y/b3FQ{y!(;x"6}FW،d[t⬵/bm}pI2g˦I-XI"ڜSx{47<8\p:\h_k Yr 5ThCU1}ہXI6Gt;E~$# 2Q1!CƁ }2:Uv $upӡ\$!!-|y+~$Hkgautsgut1-\{ 3ǓS#G>Y &d{޲q&̮y#$ُȚĝ/gu+r+Gs}"\:y1)8s-?bbOOVCd,^KTTYc w/.^P4z!{Wn[.+Yy4C^|]?fzgxsb?lsÆ^twIǖH\s;9Z!z RdT'/XnY& "{XNkɑDf,c%&۹2a05˙cr15lj\[VI>s6c_Tx:q/%Dˣ /d[}KNK[3v3(GGoԞ;bCDVq}h^~h3ez/-/MEŭȩ}\[mkaOY#Og45S/$r`z=ɧ[r e;QԜ݈`2.C>DÊ܂p؊&˯ m'aOI<(Ӡkd* f -k3CY.bP_^5?'<##G"~0Z2W^_NK k>J+;3޶oLJ-=ʊCHNmm/(̮Z09?ˈt5()PQz:t9z)@S¤I~Y~9]Ǎ%,_~иuh=w󍗎dZ׹}#9[@l"zB9,ϵfM&#/{È)f15b X^ ;ࡳ G|k!>8C=X"=J eq *IoF Ƿ$<ȷQqɘR YcM@Wp;{7d̆.ŮYǬdLY)rV]zۡ|~725 )LV[{|Pn%&~dڣdqDPL\d8$B_5rA]{6⎾’nGai?r6@m#ut*,xWNsEC7ˤwXm#n/O҄++ĩ|Oqu0HKЦ,Îz+ hAC%`^ Y7ɏCs"֍Y[tq7rY[W/$b1q#x2/0C3K؆صh5!NJi9\ vAmtGC5U* (Cؕ@ p$nm`~R p[m06'c=q1@Nowum;H:E+)Fl1qOBKZ?#]!8XוּF1v2[|Wg>&<کx*TULۣBBxi߭t5/{\DKK} I~$RdL-R/*?pIiv;&Ho3Rq `gmJS-,?@jAd.?I>8OzK_bQ wk۪ =URDîYV7 IKﰝ :%80$^ KB2e,WO.AZ%Ab2:;&3` (T/xL7]v?}AIN$Ɇ=#:Ot洠>PVGJvފU3*PRTAK{k8ѫgdWA YYpC/p@e¯9R˓<4z5u=IZJ\5֑ܞ&Sj='@dBfu Wq[cG 1:4 Ѭ un>>j1+U-͡P/[^y(}q&UY$ռ6}YAs 89,_ 6/.\6_%8k{GMPkjG0: P_f~hҠz|1hI9f뒟(ss O+ʌB MLE#uAՅRJ+}&.Aaen2g,Zֆl6Jkp{++W[{`OojZ\kR̝T \,#yӺVr'{$,ofDSMm|u$<=2'3g}X Qؾ4{O)u6ij?Q~oL!g'i8aֶ!_CC\Us=cмl_x{Dn$Cӏ찊 }MJRآByE2 'R?`;H i)kIv96 9o'HĝWjN䯳e$ǜ¹vsL''RuS"$L;/ңiط/ (P6JmFgGu;v>Һr#oˉZ.9v qF7*ct|pnMY-+ΑV2PyTsݏwZԽgl㚙Dqg$EDKsF[SAX?=䀟̶ifCjbhS,K<>>O;kBzH7p;&,X4.]Ca7k}9.bFUwxpt9gKF}7 VOoXJ ưП8vȫE ) .mGl2fX}xPWL#!;=55t)A;(10EgYsY=&btB[29IBq訊Df IXSYb+5A{gń&OC'*c#e¸lq@DīcXEԥxq<:.bq9}5Ѯkυy$o`.g tNBmGuXL+bş0(OP~[HB[e}Y6 j-[EH Y}++ EBPs9(X/n4HNS$10zSuBojy:g\Ũ )0S.i H9nl21@b7_D}`DEVY ?.:?F.x@9*K\i>I8 ٱADL/(@ g]@ȥWL)"6H!xG R;-rM A h\Xlʖ ~x&ؙf.:6 q#:BӂBQh܍MiWbmQ5t!nNy5cO o9)atB)G*LbnWd WЭ'FkBd6}؂lvB6U\C=83*05{*9" o{PC,Kژ¢M<ذګaܱ.ZjRQ`$5BѷT"+JP"W5:4ŤЛ$ʩG^f!g6Dwi͵AeQ*fzÊ:1@^O"A _i+>۫_X1)BN SYNs&Vn2hOqtrL˔ N: Z,yQ?tH_iCBpXbE0KElxwä7O) y / ITS#2-dXF`|",-),9/kBhۚq :LJF<.3s\3Aus3hG{QA>ˉ9,S,] y"wQU;$l6zh瓴GJ,+v10IfD)RC>",6c?і|nTPaz-D( q IhnWn7K@aNtmTrLHpUNߓ8I"y8O%V0n卨,GN♔FD~FnNJ\"`{j +M Ś?pjk~fTd* !F;OH| xd] BAHsA6mC?{E،`?@]Tʃk ?]EeVe璻Q)v"pGJ& 1nX/tyG "%}I% yfCϟx{J¼ 5–cle5BQprI/ U&v<'Gkn$Jmߗwl•Ti~@JHTFho*<6y"1富cP! ax0hLjDI Е NEM.+vfi{ wYNO4όdݩ5OB9:`8{KUH0;FǦf?-jȸ̀pސgBwCQo%R;tu=xћ}+[HL9+sSq{pQ#C9 isMXKP!QHOVJcZ,Ȟ`1<z|V9ę6GV{IF96nM=}V Lo&A]#+°E[*Jo2P^nUI*B܃ ^ YZ