sssd-kcm-2.6.1-2.el8 >  A aBU]AD2;g5ʽDŽ(ri&X8rl~6A ģGQk=𵦞kA7+,=%0 6(~}xR\^٣f0*ՅZ&_q[Jv.~1sxY_!\lkE\)iZ:e(IܷtA^0G4>I괺=̉d6ܗQBnIXp&!B᎔̰iK9q~MHGDWIר-+uRiZVN\ 'Dp09ϭ5^FNIM*ܩzV}=ڍ9!;P۔¿xÁcb[;&b7934e0abd3817c179b2f14e16fcdd73c770188565bfb8e44a16598fb3863f94d7081007906da6d56aff68492cbc319ae8b26beeaBU]II,EY+aA/pk|]HD@m!,Um ܐ#'C-sN#fpwe`#%TX1o&ᵣtH[`i/I5Po6C hp[6H]<+!뤗Mw+B7 _-▓X濸1㱧%b,D`C٤ 9:`Yx-G/m,$Z@d$cc6AvLRԘE =a9fS |Ֆ?i!vS3 sVN0E% ǔf?EgDzPӰ/fb2\#ڶeuWeUZ?$maPYYB~SQ05v +?J6RVA&TYɘ$#^|+F@Z#6WMW<{H읒iX u SĪbpۓUQEPUHW6#{|S>pBu?ud   B 'DJRgx         a     Jd 99 9(s8|9:d>m?m@mGn Hn< Inp XnYn\n ]n ^o bpdqeqfqlqtq ur$ vrXwt( xt\ yt-uDuHuNuCsssd-kcm2.6.12.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.aЭaarch64-02.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%6NzځAA큤A큤akaКaКaКajajana^a^a^a^afafacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd4792cd0bc20d3ab21a0baef6e76d903e4a632e1ad3c194627aba9c760c3c40ee7e9b5d15791adea18070a7f98d3657a01aafb2c05af98bc7151b159c7a64378308e861f0874663bcc8ecb79d6609111fc1f097cdd928389282fd43b7026dc40f5d1b85e61b03894a2659a0cd3bbf2dea0610952ec809c85a8c2772d948eb775c53d9745dcfae65b7cb48919f5833c6ffa21b1ffe50c98a29a3a29932e2616b6f6a5acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.6.1-2.el8.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(aarch-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.6.1-2.el83.0.4-14.6.0-14.0-15.2-12.6.1-2.el84.14.3a@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.6.1-2.el82.6.1-2.el82.6.1-2.el8 kcm_default_ccache.build-ida76d4a1e629d8ab1d701ba1d53471f8c2d118a09sssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/a7//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=a76d4a1e629d8ab1d701ba1d53471f8c2d118a09, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)-R*R&R/RRRRRRR(R RR,RRRR R.R$RRRRR)RRRRR RR RR R!R%R"R#RR+R'R R-RRR3utf-8331b569ab392ea7acdf6da76419825cfae010259f6063e22bf54ab6a84d10054?7zXZ !#,Ș] b2u Q{LRwNƑ}{ԥRs{0>zjL J#ei^ mga bSc]) F@slԴr#hAR5+C "r! ٖk Ӌ+ȷMlh}?Ͼ"dv"҂: pRBAg W8"9,dsJ+w]Dz^{dcjs [2^! ],9}i<=lj#/p UfɆ=0Y7eR/ 8sܵX`/]Q6'ނّ@.k NǏ3o[<='"YιOF,P M&F%>ݴp>(p0Q=6MbI?MH9O&dt#|*b߇yҸcsM]2M2e2g%ΨW-3 " p#lU!CkSI\*l-5C+e~>{@gBa8FWŬc0LA(oiz[WnoIȾ5X9?+l7ܸQ_# t|tNäF9Wh "p)34a'hv&0t0Gd8nFl7ieHM$ "Ru5H&L\_REuzṰIE7c¶hObvQ0\Пj e,@0O!-T:'(+\>\"yZHzCaAPϹq6i2Ns(9pZ_x9gdFftq: oߪEf'ɎފP)T+5\ud^ Pޏܥ[miбoMwTjG>9jR?N԰*#E}5mڗTsgŝaWsW ͏B4Sc.`I'ٿrO^t[Ld w9SGX]k-2_yl3 y^Wa?ټ12ԭP3 JQ?P`YJrJ V䛂nZjI&sVfL^Q"Fr`Pa&BzOs_ʙDzy1lfA.ņ8X褂,xr:e[yƖNr3 Vջ:3GR 4? c,T3ԍթMm)zƏ9s"qׅ< o@b[tFT4w#Ʈ1/ &Qsp=>-/5y,0M0)׍^Q=PG|n>jӵ]hs(F?%$QNPwrŘ!5{NűT/#3ZZ9;`_]ZCC 1j mp6LDM840,$!~R4kJ6WRf^ 2wE]"N܁G{d| pqlht  ¬DXJ=qX, ; BcvgGy' e05Í$w'9`1s@9"xdFc $^6!$yD0gQn (Y8ʵ>$V|~-DG;mֻ{%.V٭9ov Gg\f-sR?|wrO`%v458kW!æt_צ=^qr<#?fw ]J21fV~yGNVzOett_._/_px7R" &DJN3F#}TTq dWoΨ &d [ĒŸLAN͕H*v6phA*} wqAn[ 6.gȊj1\|yz=\-3SZ8g#aS. I1kۥdHmma9A`B5e ЙiIh|?J=RaR5UI60Kfn'rOĮ(]mс0M5AV!,_gKn?>0 ϽPk3pbܱ#af]@f8en+<`vh瑓+Muo"%LⷹW{;S ˺Il`JxPM]rzGcS lI38؏Xjw5ܜk'{GR_Qo:w2rJh80SMM.0 +w7np)bջx_ _nO\.ڵŠ ,jWӡd6g]8o!n/;AbAopR;?òcf:X"4 'm.bV/m^Rr#Xe"$7?iJ)Qc%F&,0`Yp"Ѹk_[Ɍ?_ܐ H6y))$=O45 C*x޻]t:o :dQf:O\W5LtIib'o+efֻt Ҝ/OM:U筱&xq=ȒEnɑCM,.S`L~rilE=*eN /ncн"Tkk7s}ٽv%޶@k.cB: |+36oZُoP$&ɒ8j/ᴧ!n Y*OG஌k\cf*QE6S:٬[ԉQ WI3׺54] GRUY !>k~`M'A;j>ʇZ+(]l #o j}Z%SpI;A<:\@seckdZ[h'ND9*2Ig h/BC!kjS/)?ZӖiaex.bWhء+oϚKtMHRjbV+s5/>JI`*F˼cQ{] @xBj h!Qw Gi-1RZOC!ݳlEwt, QRP''.E)CSd_v573X eEʸϺX08O zTGJ A 5FR_ _K?t$/ tv+Y IE5=[RLЈa@쒋lE4vd,\[`u%e(58 ;"UCLڧ3 Iհ!YId{/a!kPQytڟ"LXXvőIꈇf,^C0 3{1:b7*n:K$$x (RZk]!@V:sK"9⃽M+g37_v nhʆؗ"vS 6Sj6M==1fۭ,{zcXCT΅Ba3_uW[V9m?78>h ;gp7s+$+@fVeŻuM`* 1B xxSjh}W31K :-ƥkN2f:J4 G}D8-=J I y>>5gMd(k3=]_Ȩ)EQXvC0}Fg?A6:&l5v^40v +N=s=d`>E6dk6dc%{L4*XbC&$VP:wi=.A( vŴ96–taP90C X:rdWb )TXL$ $`,6EʆnVM)Tlf`i4=7s| (o]b .`ʩuݸn{;yb[qz)97,]RIrKqOsWր,(g=jɥ\KPB3ɐ3x &`r7"A6,!a 跂K <4ϯ0i4 2IhKs]dS|的~tcXX CARD3")?4}n&xCtJ-d&su(tut'??ț{Yv,5eBfu2uȳXL8]cGूx;`X: ;(snYT .=9E7c1W@ KV]=J xuc]V|[9XݴIby=c>%5޴VӃ&DuҺ}.1)7 **^_N#H"sI[FVyS'!+ڪl!<4oLz+ ajRܤƃ?0;14E/)Wکŗ&Y0ˊ.7?5/)S0{b;ί E* K͢9_] GS35mD"o@m?3F?϶p}k01ݬya[RN)Щ-gAoM C(`P9kVN+ye/Cxk .( {:T;>M1me0&Gp-/s3!4ݜ>) 9Y5e3!udQ^|IН]e{74WfA,Н,#*6 8g{IvPde1NsMm1/?,#lۅ\&;7 g)-ES<Wi"R ?/ݾ ^8&'hS([ ﯘ/5%ht,ƹɂad^@͌[5"Z88'Akǁq |MtJv_M(qٯ– U%ʺFKC&U7KEFAή4"'eoƺ<$TJhG0&g;?u8_$m*D;]@f59*(|:0W=Fk`0$JoA &D$ÔHm+,*%Tζje9Oq&}<4R p߰Y.AL@@06v 0L3=C!vֆUJ[ݰ G>j~cAsZI9#|ǁ'䍴a΁?9X0Fz]1Ka:ɑ6;9DUp:|а0"Q(&7/v9 ǪX2 Ա,oU3r.b3_YƲj̻<݆^"994ViPOovA_jl(λF׊ 1(l&Ⱥ\v[7k<y5-j G|DTF7<уDܽ91ʸ]S{u-r(9&,bqk+lgOPDN^ddnzPpVӋ feml+ 7Fxɕr?iC/ۃ#L#eО\/-ўApF6S,0};5omw@ i f. ji&KjHq$^Jj+?88Ң#EFI*ReI^+&ހ[\P֒fGtlECApa'v-|MMDj!=I<>-`P\v-D_4Bu)m5Z^e4|ru \ BܲNCZF:V.ndҽV+8ui{v6(3H/GqÁ o++.H̷Eh~:Ha CC\("?|HM4( R)>K[# Hu338̽ 5|P!d*BbhG˪ V7j ~w 3/\U?kw4L )ǞTy݋Q`؏_~Pllv(#h>LjSWL+Յ>SA_P?]HbK(3eGH26 S~2ʞ1=0WTrhR%nӄ=rpfbbZQC:ےf1?}7"fҒ]iC)~wjz3$ޖ-S҈0C[ _K?P*%a_+)IwbKʁ ŕ s-DU~,a1Q+ vkQbUsQ~PIcRleŷ%71CD^|zS7YA'ɟֶgxdI?5O*T8EG<vлhZ6[x $E<]hQB:Ҁ%iSuԘz#ͮ;db,}VM" ^ˊt=m'8`<v!9֪R:V$\Ə>AX4b2 Iq-;g&:5T8Xbo ӆT4NmtDJ-0hr6L@&SbwzO&dooJt, T%48~kUQy e*S1 #i |=Z7,ʷ7| ތt1*}ՂwǬ1Eڟh],v(׀rW/*L,`- 첈`de5=HAa_cͭ-hsl6.V#];cHzxu:y6ʙ`:vu@UO⺛OH$'D?bpp x,Nяya[q~QOށm Ő_\X ڌdF/'qQɺ7K[5D1Aq|A2yonʰ6Ƚ*ʾ:Xf#c͓XNXD?*Rl X8 =-6Pw%2!M|+!榳uEQO2\8H:=!%D\bПG:ܿ_Ę{DXINw"71tֶֻc6YBu:QyZJG unp[ KTJ_KG]ef&5hz\- .R7JNrY =<26<̩4Rxomy2,8dCm >( AW$o 'Y%M?f2; ȭn!cYiCalDrwY$Qfsc)>BքBZɧKT|i]C ٶix@-UC7V_e8b:$!yIaU&܆kH"]Z%\:iaF5 VNcwBR%Í`s A&*1TH{%zDbސ7|\CZWP,.5˕NNX7>>2tfakF>5$ z J" L43;9I'=4SzhCE}u)$y y2W7]=*8q*M> MYێ&'&:_u83`@*$f@㍋m=C"՟pm9ʚAj@G>ԂiSLz82Vac/<='̡B4uhe[/#_[ !c>)o~VBaR/%qNjT]^K=;s5 0Bf蛈:Uex*,+x*LPŋA IFլ*E:!z!\5 2:$]ՖK4{JO,g:Ȗ),GzcͲMgޓ(+(b%*R =9(&\M1+a 5mߩ}]y :x7x3' $q*_ ,I{! C$"Q #'GȎCjB(97#ilYƙ)~@Vfp4_}ӵ(!хKiB%ʚ HLupm:k@R>b '!#yl ,avyR d #;Җ=s5;X.ir*HL >xd[z8p,;lyW׿"Qinu\vMS!AĴc.M_nQd߰W8:'HI % 49X(QP53|e xT.),}(=4Znާ>J=9Kń!%r.AV*؅f9@#߱q(BV lr}K~@Bb(m&u[e^)F@ [Y5t;wG=1>U JE9W͛xં|["sTP@9ePe]yCh/*-.•j\ȭL;UɫMtjm-±9 c[$S8;諓u k= :zT7GMqfeT/k腄)ܵ H?uN U?:^;/_kgoCVO2VF-֝.WÂz?1Al7τ\,PR㡗-jkHI*1TjP 1NtoyYI׍ܚm ,A'{n^ݩ:b#{URgO Dj| ﮀΎ 4"lkxfKޣ.ﰑ~JX\j"T<'_P,4)ҹvr}*3x%Yک|n n&\l(2Ə:agx@J糦k/#f(R XzUH/Հ[:4Ol7xo<R +}U,r]WXd6-2moddE1`9yJ9S8[('3c_*!늖jMLQtnd0v\ tWt^_0i6ke+jG(tsbU͋嗹q1 Oau&Atz6ᷴ5Tu/7wn1/,/.$ln)i0QD58k}h9GQ*n7^(v__ ŽT)`僱dO`XS}GUG?ԭe0$J6-YixZ18=SAD_M`~-d 'Ju5d=ӏ=ͼ^2l=7P'Jx2^Ϳt'+ؗq?Gmۘ]ꆀUk\hsTZ~];| T|sCRݠݡf;[~e.bT-%r6_vg^ D =yŀG?u~6ZCkYM.=A`fKeFVn)o'1.U?=&i` }*{5mdGQ\ "_'xYy|W> 51n 8,ٵ|xTcp$E@;RЇ=EÉ_X8d 6S_CƉis0 ArsS@jC3h|Ӥbݪhw7?Oqu I>z6Dl(?Q Sf93R|ۍ|D :F55cK9ש i,]iRRSncgi'Q}zB^V~VէH1d(L֑5r"û[5Gފ&wqD\eɕWb{C B뉠&~ݼDf+7o9=iq˨Rtdf+Ƈ`w>=ae&}ʽq;)wD_fvɀN5*3T!m`v'|e}'/Xuɭ if㨩5AwKܓ#vetQahUs=HSAdR(8w}mꮧ 8HVV;wߒo?Q1-Kv8))]VB({оZ]~D)oŎIP^UhJ'T!-K6ѳ܊_mw|9~lS#|?IvG!{ sHft=H&R[}eSl/֐" 3"Fv(S Zn֧'NE?<1u?z>yOihTWs؆$LOu˳1Wm7#ĮytJ:C=CKkQ. YQ V^o°Ҷ6~{iDlZ?q3-IoWSC~S/sZuŎ,w#ۍZig5Q_b}Ř<&v+ ha@t/чx)1,f($plD:؝\=bqS$24invJW-bI蕣p[3O}0r?:sO8@h'\H;'$!՟h_wۡ(hX6պtԍg?cNthKBr;,}$cafDX1rg 2{85LZb0 g&iН-#3Ë eaP3ԸheR}d|{8G8]lԱȯ sP3w*rpcDzP鬫dQQx?p%1/O'ާ]H+fQՖd;q]N51 F(JQ}i+jjC*߸4^? j j^Z,{:m[.K^#. j^_%m5/ Inz)hr#2 ?_Q49b: y(D3uَAY}7\_o,UUi1DqwV y?RÎM4 7Z%~mCE27&%dl˩nV WQ/P-02K)ZC|VX_4dv>r FO[]$MߙZ 5oϐ:8Cs vZ<7>udy0JqCGjw>LY`4L[b -ϸ7?GXq)`$n@ˮ㸋W`l`.˪X){F w/±$V}T%8Kd;`c*a_X&|qHq+;D"4im8;xסs+*kg׻ֺYN ƐU| ˞WŴQZ|.##V5\6.@yPR@W 9>D)?ցY.nXo.אTƶVU"u9 m,GM(;F/P^| e`m&ж|U5D;g 0iK>Uh0b=3|eB?OeJEotR]f[Ce1$UNat1+ Ϗ8@pxc"3kԯ!,x/WIXP%|>FGydWH>b|h650W90 tLa`dkwS@[luig Ѡ³NNpZH K.KibhO7Ə giL`pgpWbcNwhK% Ɉ +B)?ڼ%^򜶮slX-8>Z xyԩYflKG/0^Z+cC`Op`dK55 a*;oޖ/(1c–|$nR~'C [BϵbtX4iB5lzlOrPO^-YOP\60[O,_OTSDAf݉|]2hA5eP4"Ӎ4㨙Qkύ̐2/,Lc[fHc:_W~q*7&vMNx7mR86g  \/ɊmR[[=ܷ~T5˷[bL+L% },4q9䇏x~@Kjm;Y`r“3L|7J3Lpl}Xݷ=0YΒߊcL-!kP)ZrwZ~?+͝ICt~/gɞ0DX]^}mqHwZ^ ܽPS|qׯ%Ym&EcȴsGP^2g(g!'倕%j.xNd@_|_Sq67%6?R\F"5@#q$Todߩ!+ A,[l̬F㣝mNf*Ȳ4s2vGeyͶzT!Ƶf>RXPs&I 'bU!|2['hju:N?Pm.8dNV{{%Bcd&u/ɇ*= nw'vqg2:\'l));_&`Tj?7h0zf"j wc{>l:{&L39ahfP2] A2T3X F3ٸDB2}-k̇xy3K!v 80s-0^f=S ӊ` kS\=ǔVaɅEǗHrDl@GՋrTqBWװ+kd%QO :&a$#]LpTc`7D(:{}h PC (;Jz2 <|4L`:NunSa boor*x8"ȂTT@FLh]1WVT |)EHTZL> 1 QVFqg]0H=gFupׂjkcLFf&#[gcXǜ0hfpe[1E ȅ!3WG.$/41V1>8 ٶU߀q0fp o,g̣H#w sJf=K .zBq*\Zڽym)2+7\%5296DHYͥꝤ*L9kMD'bR|) @Q#xf;?ԵqOzP&{T1qƶЖx%ōvSy\홀Ɵ2)sx ʈ!JÇn=*MӋGRAF^v\xxB(Vo$ѧ!}C-<<6ڼ!/=L zTy@b*7`xy2FwhA2/ElFEX(f=% ~Tn-L1mnC7C=de$[VuWﯠV8 vlfrKE3XwǙق27$=FquC0 NDI6S\olF E"k!39 ^:KƏe읺FY j6A>y,زs>*YK>=!. 3}Un8/b׆NHsI$t, >X^z㑠TOUJ nXimAu=:N&[B~:M4 smUc;%>A #hj>@qz2  $zb9EB"$8 f#Y{~@êGOֽ|'JMRU<`SqUj ELô@Pgi*iHH@wa2 .F + qxΪUFNdGAVx 19{VfBт3ڜ qeȖ7 e5z7i+JbWp)cLԽ[ixNTna}6"ڏĜ#KRdz_*|>ȳǟA=3`d mLfZ@2m=ĿT\ J;eDI"6(ͼ+f1y19~% 𔤲Np] fpm+RX&OA9$(?B@ϿkLNo+Z _ͻ)I:gAzV:C|/!ߦUiO;UiޥlꁐzC'FN^0 As\Q, lU% {B[`wfYaY4 QY*ƒ]k_Zd#:cl>г~uj-n5pш/O; b_Jo"*($?9-{1HZAa9lJS~29&=$!M cZL|g5P)qiPƐz[q(^K_Ω+8z RThZ-΁"mP.(:} 4,ѕg9`If lR1(6xh*O!B)v&^ X򈖂|!B`_~z.m{C+Cڦ(A@NYܒ_BK@ qz^7EhWȅ~MBPGOZ,$tCn^M1gL̊xbG`ĵXv~Jmj_[-ǻ.$NdVN&.2YlicI^GR%çj/5 [cLr:Ļ2̒QT 0{ @׳`f2z<,KArѺi'[q gzofT:!Y6AąYҵS-NK30W hUoğ'7%/ Nr2"A?87c: ՟xh6s e[zaxqSVJZU5raɗ:rQ4SH%o/2/0rYk1#` `]3G-jBqHI< -Ъο^?oMeڤv{߈ܦt4Ѳh<MBe T}~^YQ4UO j$?kz~ D H)2R|x FHOl5.$xEzA %ɁBOƀ'INX|}a`l fo&1S|ٔ1]=P^}(zz'RHWóT2Q]Жe4X L}G@q =! ϱ֮Mjm}?^T^Ixޗ) ) yܛ +P~@hyxꟽG)9OKָ B՝Z,H:aGﰶtjҊ5K>W]-ꘊTwpc-NxGM {iul Ҿ+~735lc.g-jAIxPjɂF\4 necru inD"B_ZXw5$"#Eպk2-6- LQjGv+; Oo@ftYl_a׵~iYpxLX'Zz7`JśDҖgl|C+Pt3Aw~y<0mpkW@_BxnIX‘2>Ta#vk'kJ^9m\fgRkHJtZpp9j܉ 8nLHy3$%XH1LPjJ 8:G/H\r%+9&ihuwf5'Lc6eNXU9g$F#;QCK 6_N.i{lŌ9!mv#ļCc7ЕrG>vZǞ4;s]$tBnZά4/5>&= F_ 5E 04J(:r^16\6; ]绘7|"Z{JZzSo _6I7|h6gfR"U∺dx9u_P7 t^@~OE0,yBrAD34AL@g|@&w˴ub9S`L(rwJto9 E p40,V;o1-N-#YaqI BM}@ cpߪ7(y~ǧ=g4oDIÄT'U\`S++$%cK@248+ƪٷ@C- <KN+SRbI !n˥Ys1z⥭lLD02w9KĊ_zRntPuHd?G4mҬEW|6+F/rTыz1(VnLًw\|938I/p,b>}HiK yuH|GV^Xۭq /Xe:.&vV7O7JNx$&ޮOqR!A܋p-e &R$NZC;i"W.Ch!;{Z2&Q\ m% ȴA=fI ϣ_CG[6(<5edgD_'#{>g S>HQ0 ^6 {˴S. 4 2I١]ȓ#MU[Q뢠! qX`C3Ut򵥉M;-.0UHfP֔lǂ2;ZJ헙w9’Ds'm|`qB`)%0I{AD#[iTez!`PN'L:94YJ-VT/6KG2PxvI(1y7b9r7 G>vq&gL@3~ cv:aSȕ^K6]F b"'>gv8,d4c;w̤%yCB+!IjKs@Y}NѺ;g+4OCɻ>(E3&70Wն۝ ` Hn͔2#@Fv-]c[f׆2<3!%|KBP|R JS.́׍ ^yN>hGr@1+OA /хIsaF?olNyQ(; BD lvLE3I%|/}b2l4nܐ56xӴڡHj\)՜ңs}p.t(tc\x yj`~YN  ` Uxn:}mR#2TEARQ1.e~VyƩ 9b:!~1UZ:Te%Q]Qޘ*"\yɧg)($"/pl"8+k;Ј,C}Zp3XM4~SRy7˓XwpH?5TuW]oR;Ԥ)4L4RTxCFJtG0|,,3~&pCHw%quRH|=d+_^l]ܐ;yTB4Gߧh!{sW#3,G~$CgV'B} 7oiQy Nh%do=WF9ПmyOnMت))JqQqwΦ@YJƞK33]4OB,糗I);PF9АU|ySBOUF-NׯiU Ͻ/fF|d%5P)4_R+\7p>s<m/e]hy${{v^jom`IP]k VX-{B~~aW̄.dBS)،2Nk袱֦8[2 `ϱ4t*4?6L'Pf%0}(Xm\VY>cby[IDM7Jdα>0~ʒ{ʟlD8tZZGq$"4a͹ P&$9nk[ĕ&)‹bR_ej}C69r9/JH샒em{geO0G\SʖϚ\KB:})1i0q;w 40+(WACzqX{9'-:zp@ɢ>L0'vtnS dc$#.w~ 肀WmKsقLByx>"[ll[Tk\*P;vQg`gI `N/t*8㝎,Avd_ϵOy[/hPu,R+hvqA<:$dPx˙MVZGFl* K)V s96K24kߥE*dX@{WBera l棥52>f*~,ʛ7uAQоLB{#}"6#9lhZlz4j )q)k #l (kS~a_08CiS;ܔDEhrp I zJ0-@y@#-ɕcD{)U w'V'ŸEozQ4r-iTf&A82(96y@Ye`,ǴK|rM pb2ǯ hYT4@RF;[-GUϢT{O=X2tEڛ~bٽ&[Cwbw.{-htjIސz8YSυ~Orq6Jܽzy8W$wAlsdzxbvjal!p -7/$ l,,QRLY'$#sɁ+)I` .@G6S컬bWtMsv_:x/$Qd\ǥ0oڞ cQLNd$Kx JV72|E(JŌ%up7c\;f6b^kP?YFX-&R8'4ϵOfPܚc&=8 RV(;t\#98q񅩭+]ofnN[QQz4Oa 2x03qp eQa#ɸ+5oL=\6}سWY2\+?&/40[%8bq 1XXmԥοQQ# .CG29cT*b5}ߒW-8/S49-xWў83!r4zbpW\c|s7ko)$(8Aogߦ}^]̛btxCb6>^r%`e?tW8a(:hOq+RbV@Zʋ u p ;YIdª N9ŦDe>=nY_o55B撞A8k2891Cvrr ԠxOn"헧D9;߇Đ*yPWHu!XPӎ))k!Uj=O:[yA>YMr|c5WD8@x>h::D(e{n ZLӱſnuI;ʨF]7U74 * 20 {ΈSK ]F or13K %s7Ou@aX躧K8dޜ~{ Kŗxԫ繹Z\H 8.B6 ~> F2}~ʩe[53%Xǐ+!>v*>~E믒Fl~r~JbuЍR33R\BM &Fq߄藩?bi _I.fz?LR OFPc@w["ģ>&D3t:E}LJ3#`THDG&}IIeP ( $&zUXS0ZsB[pK\I,0HW8p~եE#M~1K^Rz羹ϵ jݙ SڕY#˼sBKqğlog 2w+nHst **H|3LM@5)goW׫K C% !3 Ke]ǽ1ūx_f[T|!CgV$ [fGF, A~Ҳ~jDbrS֧.#Gs0Dh#kZębJKcx/4 n_>$#iB^y/3ȧӛgC#u*Lkk2](CB M3OShpkQ][ut6{ܮb昮[\r&<ǩ+_;x""9')9 K@c!T?aQgG-|J(_V| 7ap'϶QV, oP f vdCX`~a)#t*'E0Z8miF JR>̆UFNq={o=BtdXG\KM* W!MaTg]^q=w.*x&UM0giM(~uDGۙ˕NlQ2ZO@ xHͅ#. Y*j}Ќ^cUM6KKbX7>)PryF;@_`l( K+>e-hIi b1n8fRZXb%5YQ:bJeR5UWD@/cnB}0 ưTZFW\K: '?hGįx3h~ *ti.X?CP"wժ (k@6`LFd%oÎ|<Rj@hjc&ĄbL~_I>z"h:"!sUlqUe!Ua(k!5ҤY'pNW]>< !G,j, -L?NXNOpH$/_Xv&-d9wt|فfԷפAZ3ZBխ7@-p];zW++ű@ bE.pQ@rcsslۈzp՚޽%aj;^=uX(y6{\2^sav9p8D7JȒzIgzn4F/lύ,~/L29j*;S=b4KF*K_?Pqs ~h3u>Z1I` ڧ.\ebxQ2|UZvK~3fűzu c"l UAŻ)KDF|sl.;wkk`RFLT +']3P( C&tߎ0ʬulgxL^FAشζ`9j;\HR -F%?)ӕ_ m,{7cg#6ĺHC;k>yfJ9/"Q|[8P7Q$|G Ybt 39}{Fz?։6Enf\>&,KtCt~"u)gXc-ЧT׋;FUsr\7twj"hpY BrF-,Q֧,9βp12UǑmxFW,D-\6w?Ѐ"2ϵg?'DhjsaskLW?C2}:̬e`S|EJ%jYCngb7HBXZziR{ץ#tF8U_KH0]?rCi|/UP?&1E7ǷGXICOMc:w/eأ@masQV]I71F \^L c/TxnPloXAZ,vJ=P$2Z*&.%esr,BԈF`*ZbsWWʘeGsj d6oʮ-W;.ЖkGӀ!{T|6l4vv"7Ag8pՉETAh51{9}0U8rDxaBK}mYY kL,CnFܦWI;1 ^Xq\KEzQ}3}Qz\ -%f^Wq.ǿ@c7J7`)sEV~UlE4O,91fOa[55ކ՘ 3Y>YqzI?F]Npmr+C9JGᱢ7[ &Tl=79Z%=(N$;hXWBje TFY;^ԥM܇iVHx3! 0ɴ.*v0Jl򼙼bkL vȠ"6I;+e jKģ#V' :Dm~v h6zTyv^KGUyK?避yl=.tR!N ZRSA'V5nN.3(T3іrruO7k)ht-(j \#WTzԯi}р2}8'`IN=_ -p&"+-;-jUkDx~]K N/0ʚHM]QқrgqX''jC2gG۪`wNRaZ&TQT#m9ujsT-~'$h+B\"J3u1d62+Rhq2BLt<Ÿ OyurG6fr"O?ǦH??RVX*߾}nNϬg\_C% ~[CP&ykLq IR`ff9.Y{߻1}Ngjy! dNr !3u㞣/S*BϺ@f/\E]NF-kY!AEKT|',\?p#ROߴIN V@@a)|GlO?~N2?4~3P4FV&W |t8\A+ۗ{gkhcIB sg y ă)V5.PC$v"Rc'#:ZR+Z u9S;hd[NJo3Gu8śE(]]b89Z 1:muGFS˗;>J0HaG e՘'$+i{39cbR ^h#ItyM9fdZɱ0 Q`i%1O5ߓ0z/Ry0 #~UXҫb!,q8?jk>#Až?|W;xW{vhwB|oH1+ѭNO[UYu{Pa_EGH\:dUKN{P_=q1H.DžGd'rI-R}׏N 92 ?zPZ b K"R՝8""k,ˣ-c|ZȌ&oeV؈J Sr()\e3,Us4uO0O_- HY)wB8~Md[ia}Ox.u)rK^˷٦7TmZ5"֙q1'gȻe#Zٴ]Of-QeӃJPJ|plJE!xfsDpOl.WI93eq^PZb$ຬ3q얨 qQ؏z%Չ]'pUQTY\sdUPR\҉ʲ_?4禺J*OE+mc3gM6<' (Q&l rAd_T](к%AJ.J3 _VDOcc644:Hr6aТ9-;M+2qHj.kNU2{,6bS[Fwj.D7N%rx @Cⴣ%: %fʞ:B~_99+=ۖEf;8f RWDϠڎ_ ?9,lV _4tuFW̴rEŹ( ᴅsjrw_|p)$?Bw1G5d "-4&*!DUXilNzQPV56Y xg$Z=_3o;d|s-Nģ_U=7 p53-w?aB5zGarif^sɝ4(kjT")F/G!<` +^V9̆j5qido+GBDUrnHS F{VhHVeˁPilTǣ|Kow"D)U>ȩ YeL:͑>$َ4x(@~z..@)G9}x`䯜;H˔wX2XAvz^u[ ) U0;ZOV[{vpC6Z\ J{Z^`iaA#BsppW,H–ZG4z5h"ρ'-U fZgN%9hJh/J&>zz 3ҡ)`bkfuO9|hFB$CCՒGS D ^zDRRNK! ڐ, " +O3zSȼMahX OzQٺV!gZ™aF:`2wַ0W0&F0/;klYb6 rْ˖! iED a:]m6uryfmh(A8ttp淥|9?Ĥ Q$3(H'"FaYݖ p'?J]Fz `"Z8^LP&V6]J-1a<'Xd[wB)%tUꛬC+TZIlqlBQC/ .:|,;v!+WPx&\܀O[`K?88#}pN6- 3)3JTY[Z9JםJ_-<+()izL.`pȼWF{Z7N<0.#=I8Ymue(D83':8ᛲlFٷ3LY*|9?cqxraGM_@Ll1'POLff0y4kS{qB/b 7Ƌ:1 2\$,7{ۇ:GĽf*4 kȊ$iLS?1fյ!,r[JsU6CCi5ݲ~6Qvj N,UP}97fŲ ]ڈ(5j . Ux?@:Ajn`q5] [ȥ)C8V|;t;Kl} "O.<:L q{5VV׼HV?* j|9~QbzjzGYxl1™˻F Q .e n1ƲI2{ʘ23:\ɠʤ*ox+G*GG/Yq|A)x?| 1Zo YYBm;۳i %$'٬·+@"\sD3V;op빢X[.t6(zn$sTPGTi4"׃\` LakFQ Oua'w}tĻtAJ-¿[uNWױG$sK{a߬2R|纇2w]; P.Rv[y/S`E&am=Y"W:J)+TaT'g Ni1E'dgiܙvWܞaJ!KƆ,@ޕy$}Jz4,;޻̬v9?&*)9E j]ܺt,s:S"!ODXrRBKh E' 9Ϊ*d/vWA.ȩ^oO:R7rP''Muڮ%6j:\Y`NJ9`<;ĕ{rJl@ qήc*w|f P!D1 g2h|U\Jjrh[K^lcFךOO}Y J1edw2Ҽ>\7 PߵUE $*ǽ=թ! d\?,OL/F,],N[ _!^n!ͩ|2ǜF`7F*$wiŮe=BG6a%=2RQ,\y*%>ӫ9V!cyAxˈ%G+rHfEלe^q*X*ǭ$_:z;~VzG*{t5_Wa?[*CToB.EԵ3紒#+bY&O?3ƌ/p@.5dEcV&L_dD-vHwWETEҘ%-Z$Ix}N> #ߥVÍ8P:^\HFDkElXc<>P6/ґ󘾯P\K5$02RPKWطB>n:7Vh 5mՓ 4i%J%ޙz(=[+Z 3{.;GMn čʹe3*Ifp)~b|hˬ@Woy߶4>(_ď)(-x|(m|FJR,"w$-ٚjBa",=)m,Z8Zﺓϥ6P&5V#z.󌕍k6_ D #6cn> Q>Ok#~l9rG7y DG Fl#s72ӕ͚ST@@Y;+`DiҳL3:z.I{]ಌuGU-?ge3L)Z/%8M&Fs+eg5A|Z7}x]zlF}5W:=o.j؊[ƣNhg߼Xː_mqRzGĸp)_}spO/AwM~m,e˦rZE5%ʛ9+lPpYfϤ6Mb"X3N qu"D{]u؂M/= FJ}&S֘~&]SLiwy UgnBv{/dY n ,Ce\u9.ueDes/lI4ڿ ;ɥF Z?;S;t |(lG* ct{۾%;="^9rJK3q7g|3X5-App_2?>oރbzE@@Dܷf <0`8s=\OjH{Ә"io-/=XnF~H~:"{%D<]oq*HAw>kO|~Sw-R{Y]6r}9C*stOXNg-z[^y[B55؜J M渀?5G'ell3顉c<+؊@4hԚ- ]Jd-0Neg+ jl!DDưCXNm#5}eERڗ~h.?7nhJl2M+g4@J;D]ۤDF^Qz|BN`A6xW-w:r{4~a9|K "*"'2F|DDG+5B@ RXܠ~őnNP1KDQ3hG^>!R9nP>jIYZ7K&*:wR 7!|Bv_.B?G4)ͪC>7^=@w ($oĆl(w7xԅ;ENGn _#]0s𞌠b*IX [3% b]?ƧT&x5]Aur\q m4$H?RV;[yR+H m8}piV ܨ %B,k珀 $=M΅A{zb=Y/ӣW'S^s2Oqŋ5^p¦?|G{kTSv9X($-Ssq,nŠ2 hDrwG'Pu ε^Tԫ$|5|D6G Ip*ɀvy$*8*ً!&v/fB{) T8Cwa08ctQq#҄Aխ$,dQ1 uG;U7*3wRĥLhI±7g=ϴm& H=Ў ɋFG2@힍Szi䌚J="F @R(y[HάC{mzT;@BjN¬̙5u Rd8q* (n3+%*xvZFj\v!Ifp5wq99ͥFHwLN (j-Qd=9’ cK($c1/\" ܜs(X l0S4z$O_hDQ 43gQB  ҉04 <ܨ_Eg#6ێBSڸ!BdsRJCj 5>dP٬&I񝍀aAC zrmCD<̕)&梃T+nz7cxh=f8%o61A@Ge7L;)oڲU~li_Y̖ƑT_>E,cQ_'*Y_kkJgW 0ߵ9SprdYDF".[Š[mr-9MZyX)Hw^KN+BPU$| _W5:0b=-傔)xox3rS:I'@ԋOtgrWyIV~,_K"@EnXy6q:{#BZ{SjV{gP\Am~,C"O䀰?6}Eb9MKbfҶE VnZơ=Ho" e qDGPz.+[]-M"~.ӊ{$ "%Nޝ!AZ/538o(H[6k6Qۇۚ ZDV,Z~;] CD|HN\ۺj~P,QIWWlܿD۰i,v/8^\\WxyZ(T~:v/]M).*k5築A;NM32T sI@1*Ye۝A}&L^e!8eM#M'C5 -#7j.t s9MWAR^j.0R I˸D :רs/2A-,EexA3p!m`k?6LDv*U8}jу~EKj zz6+F7H겠}Q)VCydjM!r3mAC So)'Taݖ^%m69KN[טyU0oU|2c\{|[/L% 6._NLgMG"$FMJD,̗3U+mM"4S{/qCNdf,9t% *^;:4Zgt2RY 7e9ĝJO]=l+yۂZ wt漽8b,SѪ9e|N$qq[V:RaS'+&^ۍ0aNwmK4q$% _v3"rSz-SG|]HA ;)Hidc"=0ѥݗ F@A L=:`%\z$Zb蚙siv9٭p\z[ AyI&Wy1xmA{%SC*Hr-0T$´ E+%sJ_1aE %QDzG4vwk6kӶ;QߦQXorOĝġќ %VÑQ0n TRT&݂DlʓX7&u2ʑMC GpH;Q+f]|ƣ-"3٠)$qm3w.#T:ﲈg>EFMXJqm<~Skctwgɹr@=W~^~@4pJ%چ:.1 ZsH99N^RWH${i.ST@P+M&B9zYXG <@x[pC$u,k?i7hYO(/P5o{ıob/::$Gce^juYaJ%(%V/͍ _m$pC  4ZwdK1g6rX^1c Dv!d\T$S["j]G0h!_H?@C/'E#VRU6@=Ŋ3#\f}l>혶I/9şh"%{ ArZ _lǦ#7J-NO VVBcs)SAVݠߤ&İa\k^)Y+<55-xzww8 nd8utn1c >pL<{k|%3DuNKPutv4͔r|$P Ӓ"sO ΠDY\ޝ$>D ?|u&S^Gu'|c+wYRet5k Ƃ֝NIC` l7\ BxQ /'՛S\*=n>v Fݩr:ːtiI$\=)'/8ʻ-C!kf,0PΩm}SmwQ6+IԳ>ȇ0x*6jΝVjNd㰊^ßS}UWD JƳ Xs^&6M#k EsNɂE:ס2QD. `HVM "c= ~Y(7PTJ.t+yb5%`7?S| oٕi+/cR f1>#68 x@"oM-73JGBSYз,m.ݍkҊT!}#vo/ku6+Om27|iyqXGj\xEttڥV|N0ZnU0 )JÕr/@=x _nwz{DpC{T)G[15L-pP4zw`A58Ig{߿5|O`J]ݮWIJޤ?>ΗPeuEo[Z-}rZbArX#ݩBtw z oCaY,'`Ωr]hǗ`( *Ӟ0k]ø{S0Խ5~W$SM#~,&zbL*#Wˈn>o=P=^:WNX;%CHL* )XS*D:^M\~a1\JGXnCp^I fFwqPA=f((`#aKd`J|1q\Gb!<L֏6Xe'!\^r[V#Vuņҫ.ܩBΟ\gJcD@|[SC@/iKؔW~n{1˺ nd#'ѽ ψ{!4}xus̻IvB`&1I׺0o e|LB#vM1eD?HV$ q{Hhɘ@No ޜ,#$HNn2Vq}SGAA%Ao ALI.%_y)`ĩNQ K[00C^diπtixod3H͗LKbxi9\/~(lL*ϺsZ]m x c(rM!RI7~m٠(w8Te9ӅhP":LOy鴣A]] {e}fR[*ST"36٪rtQ1Q#:onD<5ѻ҉aMlӴR)=UhVAZj #?b C90GmmO◰#|rD&)"-õ cX͑*=~SR R.ʠM nrv!ef{Omo؇rUl!X2SM赴q|ܘ^ XI'_r؃ 4RwQbc3`݊.{+w31L2 ,zZя?@gFJzM vN}}Lsسvy~`!Ԡr[.H@W|m7\2aPoį@(W8IO1!_Oyiäߟ&?3odnx {˿!1,W="a"qlo9Jq#ZҙޕrVgќ]wPkf_vo^c8^*wkh"_8#a}Sӈ f31x6HL]CI^*7Z@%H)x&Fk[Mx*@㜬b)E{E("4SOc-!ii`gC|rmw3Si+MHtDhb":ji+WP9$ghN'6' } ĬώXYGac,LJHT>jK~<ȑKR~yι31!HgX-POHQ~CUA{wA5_g]pdtXH$yhdKBº MzTb!<t;Ox}LKͰ$)5n2?Ll&%4P=fhҠLKiwQd?ڪ^23we,|"4M9wwe]hBn^?o#+o_~?A_2doRS2^.[[+g/3,JaCQ08P+3S#y]ܠYhnK+xpd*+&'߽pZ;=b-}${.o+]QH- _NR?lߞn­83'H׎v"L8ڟ  ;Rq[\uY-y.QhJB>MC5ǟ$RjB4h}QTƄ'L'M8>-(I b*=bb#&ϢVz*#auDwב᳾ƨ'J@jrwO7;l+=e!YB9X`RdM { K@읃*W~nqڣ`Mx_5Lj$f97,C q*^,Jێ444ѩ.ag_kB8o! 8͘FT%@ q2j}ЉYDLH"%Ɛ0;NQ֗\na#4gC * L"z/XYY]ӭil‚fכfȞݠvf4oy~! GCe* *LlƳos<FQIq*^HJ>O'!Tu|\Gͳs;aZc1iJ8YqD{,ThڷȬ 7bJ+xxlgxF d N3}inO0k}GNva },Oƌ"NeB? YOVjJt?cOl]`m\njj F[dMLe(~+ܯKk)&y왕hpT_ąH&O~n3N_yʗr4vicL¡锄{LƜ[!|M9N0>4ͫRbe-|&t_;pDg:7 )ܩ(݁5d3U-k^}(-7s奄>UL q `o SoP ziRN%%,̡ȸ[,Z"xMB&6b7 Tŵ^"ىVˊ:d~ cp4Y v+^% i[J ĽwRa"!U9V~|Yҭo@{4[oe@ʽݪwb>:~smcg|~r R<|#|XQϦn5\)&u: B><ʾzwe ^LT b C|ۋmA xq27>(nGj:k*OE{wɫfMqŠJr:@MD ! ;nPLs%u i. Ŭf>SeJglCfw Cߎ L(+YSS:S5ԎK,ZZ欧yN 5`l.jD.UTrh1Ezb,AfR=:b}_h?y wT{Vd6[BOFO3zߢ\-HkX'/ f}/jpTr~ͭ >ǣb{y_N{"0uR,}Rp,"l57EDQuQhJ`0<(~n'T!G; F/qł#0? ,H zA% Zxo䦨VLTY&^UQ< cQ]-#D;-kX^م '&H^X# Y5\SOz#?#fKœIp^N`c|x\)( f-:;/5k\fJ_y4r܍wŒ7[eyS$Oxuܘm]%9ٌ*,> ƣ+Ie燘}$[k|.)`6WJFtEbsa]i 4l?(!Q7[8S J~8G)5 2/$jdc=&0Iӻ;2lGrЉ2dzM$c{SQ#qn\JR1|*s1/6|8@xy]l,-|R7$лQ`bo-P1Ndz2lÍ#]7B?Vy{m劔ݒ{#o"[S_Q]SvU-#I}rGjE͐`fZE i yfVs8pȇ-y(+F]\UNb{ cʕt*~ ~%:g6:8 DL9,vFlG(VQABj!ż#i.`̱,~ %H*\̦?U%}rt 3Z6P҃4zYG[K $'}GsN?ԫ݈|g }>Gg㡝IsFUe0(ZV;(XrvrQ^xhATHrvݫŔm uH=Dk|uYj@~D0MZIEsv0Zs=LCĤJ@MԢ̣=#4^"z^'OK2NZ[K. ]CxĝmO|q?3q=DçVq3Zx:$A,NjoT\"_!ېLb+z]mAgj0btI {oq.ϫEƷW`7>q;lݍkz?6ߒqd lO_G'|bctUH{GX _xC*^22\޶Ѩ>Ǟ 0,|M$7aJ5R).BYWk?yq=lbfC%܇5oi"BJ:^<ُ"梡gk袕؋"=id .X$n MC5hF1*B#Cރ!26!U,mcu;pJsa>rͶ:VFÓ2!sO?͸">BU5e._+p4D,!cNuJGL+Y YSY'P|wm4ܭ<UYuYɮM0(A&/oAOf Q慏II]X\:#d -̦<9Ƨ@D7\HJI s$'-fmf}z[F-q4?OqrA|+M|u>8SK u- Nb-!B!.zXl$^\v];Aoĺ}ohܝ49o֓/ "he5Өt\!h~pkP6qM/F3ሽ~#Zs5}3vA=?KjpZr)aU -69՞+0׋"| &M!`5KgSN jKJx|;[Vj0PY-2$<4,~} ۋo`/EK?9TM_Z&@P毌ljqp6zsCh 'z,n2_xUzAUoXZsSh >L;d :׃7q 3h!D$<yK+{I˺;ZNޭ_¡Zp+p~Ыha֧zΚĊm&MO,!YúKIU{ 5ީGHLP39DyqJ*iQNט p>"LBP |G?W>&hp #Y!>p柷50j9ZRvWjbɩ[? B< Qw,Y\7Dq2[h2ZLn$F/ =@UGt>Û}{JuCQ]HFo%宙hR1jj28($ 22MJoARr( Wc4UT rhDH"[t;iy7 i @M>, vW2 XU.vjm!E9Hm)ņ~SA)+5SGE(~%]-Qg!#FsDk:;NuD~ xq7AԺ>OH1 >Ds[¶7$Swĭ1EZtG1(~*/{H>-f؅oǶ(1gr7xβ ,;b VZXH6tW^]Am JW h*f дKy~øGY]]*{N&e!U }{qUJ z¯)$2k^BDk,M A=VlG-H QQ#K@s&,CbLJ(HZDN\*(vߚRĆ╏v\Xq5M^J?`k]OV! 6dվ''7/Z)3CE I[x&\'Et1qݱoz_Gd5͸& (>9Vc_$n hʓR[l8S5Sw힐HF;7IK؞b jYGhBֳ&"԰0 |%gQ N\s wWy@;WΎF !D$_#;24o/2Y^#cGwK+נʠ%x\؁!ݨ dzL%u>Rhgl\ E\K(8z)(mGA6 (^A.!h|RcxHX(+k?Y=$9߃HL`.m83X:,+,",E9 vLW~Zt{["m~Y6.A,GOrIxn c/rP)A2Jj~QG ?P}ZK'pzQG]_uQ4 1V8N4i[>$c2Vr@ 쩪^I^MB~*/ ^M:kPWn{$"F~k$3{| ~b'$zW&7[)/ne3,+`DsiD}rv@z|}eRc5}v}ņrcOG("g!cn#̓K M#65뢽 D'c5# o9kϝ1y Z;Mu1#זh(^[%}[9d;5;QTے<\ >k\R=Uqxq#V+0D Ur?(fl`T H!} 73Fg[yȄ/3_#\%zx795*qvuDZm_~gjv/G3[کF7b͘O=-3bANo}{3ɹ`&17$מ>UHF ߕF-{+G* '<~pH%4t=1UYX)(2uVX^V Y1ݴcU\S noiSB8n=$ 5=ș:RoEޒNGnصf^-gf8_{1 Ąf&= A(S@oǕUp{ؤcܨ>n`ѐܙ+gZ&Ηk Ouqjhca6je2FFSj[l,E&&TEc)A..Yvz2I T 틣GW_ 8^s+<"/HAF~[o]hʙ5$4Itj#F,_hD|B.$rtATH+-*O7q)S1k}.$OZ5oy똿v˕/r_`:`d|z(ŧ"vϾNVyX sWz|D2cՀĈ]|2r꾞KQ8hL{:M6S АЅ b{OxZfAS䏍΅ g#cPiSV1F0 IRضwIg{NS΋rXyY}Sh\a.M's\f5d`Ș˚s,ݤZRK rR&&ğf\H Dm>aʣ2;`ĭ#kh{!̣X\KLߝs5V-qh#ś@AgeAWwtխ?|`h F1?DkDžc j)W(ϷYWyYj- }y*s>ryUƃ@>V-+wmyoҹwk1:/ZKK~e[ߥxbAcMS>Sjhr{~h/NzN._'|#f wXyEt͒#NuVf&7b(%n{Gi5R!:t5BF S1lcdm]Q }jB :-{|@eȢ;7]vJ%pq"O+YFjU£X&ӊVL̋U~?F}'⠄$ Y\U,R9 |G|y*I_rf F i}lDYC/xQ\^@S/eEn`/Cb +A:|\`gPPV~0)K yP;yH36fKAEe+9ҧLIߒ^MuA#`4~Cq ]{XJ('޷ Ũ,Ѻfٌw#{bN " =r{'T(ZbRrq>5tI29$CcӎBid/8FY3 V3^n8dPZk9fziȋ\ɉU3w^0j [o/ܿ*J/3DX=ݸ=-~w{ LzUN'p]ߑ)Jk26WFse!࣐fcSچމ~x'HV̬|zQEEd.% OlǛPeDA?GrR DTXgEbR#?M'+u]16c,J\UM}NiqY愣IبU8kv+|ymx3 k Cop6dp*ly3oS"VVZgK!LPMPLtle*zCf>K[sID$pXKtZ̶I㮡ykgڃS"!ѡ޶{q }uD;hB*1WAH(?e݌}IgL-:@V R܍ )YHoPjuw޻d 4:o~Q=Xcg~%5X0qJ@ig٩Ģ/~J3 Mߣ]L~ v\y-گ)~B.y~!LO%HJ=k&B|И/~ LT('[}PpJ%C8u?26DۉnHxg-K}|ש+}ḷ;exz;*2uH̜+ףU$8-;`;<78 Y@jLc"IwaOyqB~pbJju/BPPF[]9.IUNTh^@HEPc&Cݸ>VMijbdw]V6]_7CPG@=u51Y-8g ~2-Ly 4EIsDW򆡵=Qe3ӽĐ<[Bu- C{U$T*t'uq=-H-qMlG2eR>RyU!@UN+S'lM-/,twcb k@df .m !5Î#Y;ZwΓ NW@ʺyU++*  J9vAFĿ >ҙBS`]u3jd$ { dtfN:'8M4qӝBeۦ0&S;VR̪9\Lp m ajըoAF;^׉]Z+ѢUͭ&oMɢ|l->OZGRbI0Ck \8wNd֭S]a@?EVܚ*ͻƪ`x1M)pݸe|n"O%k f]i 'kp[BbKIɧ=]Ѧ ^ГY\QS9dF]֤mrPE,Vʳ"%\H(x|5mہT\E*#>a1fٲfx/~Ax4OۀUUcpQ]  0ضBfގiy5#(܍ed]|B }--UP̈J DDo"~FaD+D#1KOc|(.eOiqotH , ^XxC2-0 DKgP"2qF I0/GPw O. S [H9rq{;~&4jc$.Џt7Sn]׬2VP8e7PP(a1;N t4O„YL9?SVl$w@w[2I&V2bdxgka0&Sz[]Xjis5wh]y90Zb XP;T] B$`6 V[YefF cFWhf UoԄR=nM_3! ѰqJ~R+Х# 0=_^H񫼮ouZu^gpy4Q^)pNm]$2wSjޡs-9rj(a*vք/{ce غbe#{3[?*Й|xXNxhwE9wZ ߢ,3`YOH'+[1٘6E:/Z87AQ3lB P8s0rI {6B/s9"1rF3@N庽}ĺ)?YjwW}\Q;yǸw؆ L |(e0?ffXj+iW7ܱ(X0 >FzOkvP.8)]G"iײul6zS#XϏ!8Z’) fDHE`BF烼5 (:uraL+eLSQ5 :&=4*')ƺǡ3Y\W׾WҨ9EC-;x^%]NI ;/ET rMkyUeW!xm{%E;4)a{#SK[`#pMSkC4j‚<\͆#A|CTr`ҫgD>RdFxsXeFms g{lI)Bqa @$.M.HņXGw!E`cjf&}{_m~7CI;PW8i`ԱJ4/>;ql&O΁5lF=Q9 1#=fG@:`@BbGPޮC c LfN]oZ֩:+E!vؚ A,FfKC%b|LFt ƚ9ʐlV[Y9MӐw=xfsPk &(mAsx=ݣ3qXّ6)?^MXu H%ȰUwc^6h=#c0,K/68]DLPV()! g0XFHs>wA\}^灄l*xp BTcrٙ;HK)ٿ[]^{2[Wp@MU;F"ԅ8+QTAO}V(0[XiK?6++Ѱc,19փvq)Bb2a K&XI@t˵=ӕ<o, s3TktKE R`da4෡:x+hXyDG!s7F-sfsW{m~E }1TÎE;_;P/siֹkL φ_;-pR6.n1Hu4NUw +aHN\T<}'&SN{ ԜW]^:@.:8+GL}qE3ZO Я߻(TEZx@0[{Z#?InG~vzvcȬw^f8v:UoQ,w,ݏ{HTIG%u-^CL2tUõSB^Uda(?U\5/Nr mǕ̴ɠXueR&[ "\iOh't+T;bk)p(=fqS/!9P W D `8gBCUY'df3H3JsTS$9ܰZ+pmȍ4&[` FxI?ٰJ,RR+\+TTtAsB2-]Lg:PG,^)E\X[ѻS>_PFf0.?ņi&jweBy$ߴAg/v%- &sQ5ה򯾘-j MfDAL@( [!g%֬)t$% QL(XkP8|ò<|tɡ^C(( GNԋ:%|bo.NFa׽18 XMjqA|$r_cÏlyµ MwQV5߿֔*s⢸=3h`6!8d\n H+a6WCu/|7bj4ԛ V!醔?RXaXA;G g yQ_Їh}ТSE%yDπ7pLZ02^_#$g("Ri/$̻v"/&z)iIk]AQaݑReYqx0bٴA7+ ~XB  ;Kb#ps Ii)Ka?,Vk+jw.߬+ scnrц9KL=oW8jbi`i*g,T31'9oVOY])U8q@4A2X;9O4V7$CO/pTsٞ.#ZcM܉|x7PNƙ"jͽ 3y*&<2Csw?/WС&Tԡ4L?inFʼOsyN'g!,AWlÎ=%j)`"I%ݚ֛i@: ^+}VJ?nyf^ؗrH$A-X?+f"x> }wLbcȺmx9d:,0'vnT/hoM(vXyZATO_F7}R#ŲɽL0~cR:f ;EX(٠H80t¤5`f/Yd7I]'jx>ԹPT\J:4.'܀ )y 3(v2~'':թMV; ^P9@OD n}Z]ߏh\r-PIY?na @ Ú|~M$L͌|Pѕ+w mxF2w푬ȍSzíxYt\5xFArJꮄz̵QN}6g"7"}Ed <%BL;+HY1n:i.aţmD{n k8NE' 'mp0:>#!02Wb kzR'RX1s`dFUa0-K$Q25/rz`)M9wXa+Ni' Ϊj\+Ni'QĶ4bM~e>a^\LfىVlpGzz~ʩ~tfLm Z\ᰗ„#˩96PQӯycfǜaْb?,q̓ֈ$3Uw!(F4Pmx< |54X3t1jWw$Z8wKGk"t2M%za7\Ӆ?j)z84'&zIsSG:[& Cso%,#ܞOVtN!ʵ\h* OAOxdy14R΄)KgH~tmZ՛ dSw ^DAE%V(3݀CEƠLv"-0L򹼜LuÝ",<~wG춝5oU|sR5k;93uDt;)IO>Hk:OYP+X5 'P7*0L }̝2&y5_[ +BL6"b~d{IY܂!y H9p"rgnw!\~b~R7`}@&/k!tesze1*.m@IH醗dD" `y**=ۼ9Wn$rB6U@_]'\ yT=U dR+f"zoQly"f`|0y[~Ùl("̳v֡jD>9#hcOl7yC^q7BvL'[4&X)0dwOicDrAi+DG/"'ATƙ˚P_-^-P󂼛$+FK"mH`4Ԅ.|nG@^<I;lA ʾ9dHEGFS*O?YxobMǞO#CWN!+A{\ps&\#L)1gn ,ah0>򗧨 cTD7 M?`$AWq)B@84_x0j4TC& |}[L%s-"1$ol@N1lշ2; Yo m#G 1pء5XKSW= Ɂ)GX95{X7VcˍbVpVo~r&#i"9E=K\qHOW6&dNP (׏53VcC9/z?IXMR:!S) X|7=xOkm(,N\^f9)Xn>t ]\{jLUe7:CyߵHv_{]uEJ Lmg.}hm`$}cnV췂({ЍD@2z =K-.v} SDyćSsK\F۳8$2f#3j$eJzR[S>e@'֬ l?4#XBUթFX0Kx6 FQp")nmF4&dD{nާ|TLJ{]= d}ȳ.gLa٤3ÿIc(`dN<('Ǔo "glwHB| T6~wzg؆yfQIu\;#Yh YB7떄ەnCsÑOLUc%T}-cJMEk)$=)+ ^y!Lݻ)I$t^19&{XTohhwMvz՗!h͗(:9/Wh~TgU=U*\M{5O C+U1Z^EMoR o zx4dv-dʯ>tXS< eZ{ mН=S i!d3 䪎Z0eX,rUv&Ig־In {8>ʴ)~RH8l:skyΦ^M_#"st]S"?DGxͥ^GA!!30 2bK9s$;_̜J,0Nj&'aЀTc@O;QָM-YO<ƑEr! `{tj+BOfǏTޞ]%DY5;Ey5TH+j[I4 g^ 0zK-a} 6>]`Z(wB 2a՛k(a(#'N.PqL+DU{>+8:ovEz((Ifkv⤇zPNS덁1:5K3AWU(\HDJHcU#j@}^7e}IτԠ\n7\& ZP /AWj++;{ȿ~|(_L༂kM2;4$W^!]sՙCy(dð;ֵZ=oxgJx=VM6n%y4zZhg0ee]6ˬ8i ]ht,I{NK{܁M})TIAئC=̤ w^"aۃ41)MU^b4-.ؽvtzr V+Tg&zce+CBc5EUJcm 'v0uW+Ԟ&/.\i,ϴM9/whN.( fq?r/|'2 S9XB&RqI4cnfNPaJD,B W+Nd˟Qz2] UͅY;sHY0噇XYy~UnX%ݔFA2b#_ m, CnT9/QU3bVIKo1 0-3wo퍮g]vJd"\"+͹fsJri|ʈMHz"6 aR^Nٱ :'UVCӝϸV[3Hs{D#b ZO`8=M_]o$ F \] mI΃~/j-Q!|T" `$kun2 V%\_V\gj!0>E1X^Oi:b-a3 X@FU#Ѵ~2W℞X 4U,w3QB0b/zÓcVq/Njӷv'Y8jpg0Fwm]Aj1D`FfYM\F%̐B.Y> ny&/A'!@*KXY<):24 (s[F<+;(:zK$njjjn&%m)7DDLuj!σAcg%QSie O-w?|ea6"//V"~R y%r z?ya=NjLV_0U%?8mDL ,UM›NY3]&_M~R/(% A?n%$c1 00Xe0~HVtP()9Ǧl!n;l~0^1 i40ED`Ɨ!6[ei"[gū$tk D#)HNDiodp)ߌa ÒUŃ12xtg,^յ\ }gmEEX;OWj*(h>3&KI(řSh*)9E = ~joc?xoG:{@/OQrrgB^DeJu5SʤJ۽:: 8;>~;p5ceVN*ɲH)ma-}Ua4i~q}ʏ߄p݈3D9޸ Tpם gsW$/_&WP##rvX˵]H VfL!zB$yOMf߾E:i <"uQ}S)̵2~ETCawpAٴ `wsxJTt ,U^Ei7 =*ov?*޵16=/tNۂ6RMcH֝;JꚖn+M0uc QPVisCՌwlB`&gs d/:=2[ g$ȀB"_$mɫ%aM`U(DdȤXǢ^"pD~af&6Jr#1:\fJsLJ<͘+x^s+VDjN>oٴ㈓>#KɸV~^ ?ٖߵTf$2h(A5kXI :"_Ÿef i?ћG=fx'/:BxUVh7Eu0hթ ^2*Uv=)"|˛cTMȡ[B{_k٪ ˥4:q^UFYNjLa*9 qøp۝>z>8 8e8c˪'4|#jj*Ǣ"P>wqFfi2&%Gv ^\b?.kT+ŦNP3^U}k (UNywf1ۯO?f>g(Ȭ`|p2ݍZ_fzn$Z&i+ꊱ_j)a|;/_%`[~ .Ѷ]܄ ;]bP{VGoc)!LTƘ}Gc}~!6cZ&U4"؇CԪwo-@v_*Ƙt:T-ANT|dmuɾ??s~:PVϸ!GjMY_=MsQ3i9-H1N]]w ڕIDFl\NiJ6Y_OO3Xr/PgBuzL&Mi^rr mggGVmWm(GG{g= `6GSA$ i{_ HpFlx{u9 d5YW`*+x8.ϵpdeаa>t[@,mszTpQv֐TppcIBᎽv᭖Eo !"Ymxpa~΅.eFaTgί2Ar޳L֕dBQ D@!e՘T5*?*Azbv|~Neص /?fdaydz3Zonؚ/u 7Ieo×C/гF)#WOʅtȋFh3탠n4H´a Qn;WL屯)Na&שPjmi%x9(P~́5?w~ 4zkBFlF4Ԙ83;dk"G7#r7b~siе6aݒ׺v6bW䆥LHT"I4{`CfDfT uUm!䂗,;k;:Cί} ܀z1R5tdtH]8p:yB.>DzRuFIB0(HLӶU!y psXd@T\ TFZFkm--w KÇ p4o<ɟ?9K6X͈ !rv;nYY"˒g874i1g PeTPmgE{ a+ eh, 9Vwɯe ;Y {&4HyՂd J_ Ļfh"hx׌* b&364,{;coX l)ݼ2W5W,<0*9A '|*enmOc{ 6+QR&ѐ(:bh[oĝA;ކIJu؏.D>)|[I+13P9\wv5iKwV@S?vj((zɤ\D+.|lݚ!Ovm%q5H=':UQnp{M)BfNck*xAz[KθayC$)sCMFMP ׿7 ͢"M;]W+G:X^Dxi;TsG`(B@Ƅ\qڔ\WjZܦs96<SG ,`q$t+ڌzy2?bn /ᘬZzä:lK,_i#'YͦFO*+8?f8ϵ(Az* Ή3v.SwA((kq2:嶣F^r̎PQΙ[ळ++S(Q!.,iY(R` [UE0ENVS=gB$za?LDPFW!g1@fD$AQ̐mr6iXK?;Ε8pR&0{vν\[J`(k]k,ȦOi@|Q|KYx"lb k}_u tM9\/D).WwS;H8--t'pii RDFVxpR ;M5\,೙ sg&=O EJǫyjM1f&=We[%q?FayC"VG έ?9T{*`iz++4P5Ru ',Wgʎ9gAEG,. PYڿ6vƘUr=p<--䉌ZrcnyScjv_3a(ƙ\y*  uB^uSpL9Sؘ_mwQEl5_dqr- ޚ>c7 q(bBJ"9Յ,2&h= N,ߺ(&hP.pY!'/S'[}z# {FIOu DTU4UKBzOm+/.ֈcDf{1GgNȳ.ά&ʔq]_xz 7*`d#2z9&ȓVzbCXۦ_bdI3cws-rA#o@!4O@fa潇\ض r* d,aJvX0ع$μMs0U~{:7&1v!"B(u\#h p)7 ce %!z2M 6?S|8NKPes2y9d`bk1:<sM bQ{'9 J0OԖ@.""P8bsflkrBI8h9TD6n# K})c)3%u ^u%A}!]T)`ae$0r#v]V Z.桚:`rvf[UVVY-֥POX>!L`vM4r48(7Z(]p6j Oyg†Oܟ:/HX6R;-NV 쬇 0#vA!$$$PMWeqx%B©-+(nP;2,1os0Ǽ3{Lk,o XZ\N _~lP c/NЁ=:"[t X}/5] |LUd1ŕ/j`99Z"8:S'Oqᢒp3]MJ"3K  \/0kt_]U3\ ,SKVq].|3TϽ)F/x[E]V3$qm)L?hco6pKbjcKZ_ÑioЏnC|G6|r7FF:oag)$<@B䆡,L}TJ)vdW a0c" W̉W??"rnmMVFuw\}NZN̸1XEU-*BĬK% d9>7HnD}2S͈=\ftOv)Z>9gEAP`S[q{ Lp:$"5%&A6ħR=]a ?%9D ou0M1rhIX dk>_uJA(Oh5GH=f=l@~29yC^f %(hĬg[֞Et Gz,UfHĸa9_(g&S3rq+A.qx>燥eC/j۵i75&9䏵:3:`A s U⺚|7) 0 2ۧTM_E @T{TYz0zFCfPU}u͂_CS͐7z2dzNj b vl$ꖦ xYm=nZ/`у]DGւ\uМi?"MRd$RGEd@gZP\&1) !a%ӨҦyk]m궽SoȘ詠kԹUIJd@ZR%L-ط?-* J?U}hE4XW{h}ZRvI0NY.H})5yg}g#n }J~qµZ~\D`e=3bwČr).۱jC- pH[+c7Dnx?MжVő{@㕅0'Gr9LļKn'i ܄{&j|0?ϷU~ Nl&D.8=}\C(-ԣw76soPzIϞN%S/L5FpbW΍W >ឡr @m+;w+'M 8[`uyx=NKG_}7arꓦ/@? }#o"ls^=WC%de;鰽ZRS ze6 uS'Ԩ䑤N+60*H^pr@7A-\A:1HhC>P+)@$nU}o/iR,-]y:Եl-̆!WcZV5Y*5v:_K#mKhL}ȸ Gn vUؤ [Oa-'sr4XnJXW{NIy"eMh򾓁əߚ/\hOa?5o/4C5HHJѱ'#Qҁ{y3o iyp`)QPkkF_E+:rkX@U0}RT#!Ȟ_H.b cG@Q;/oΖ@CJZ;-\WbV(=Oz OZ{Re[o{t SSoOuYܿDn ~pP=x=+DLJ& -| U_z݆G~9v mOMvy@}h3x&.NW(#y!\+>G)gwkѡ V\&x L@0%`<ߓ2_-c>GI,R&]pcMFITsv‹$F&nEm|sXyR[rD1*U\Ju5W n$B M{޽/ RHї5j' xї>e7:x,uhӺ V9(txs?-iG-vr@( ^~R­dzvjd䈙擤1 ~RfmGr)q IOZ\^cMlT̖by=U#9.( ۯ Slq01q;䉔Dҗ|ځlL_ɾ' l[1Ѣߝa5"8YmZ(#sܥ#[L2V(;/z/eq՛g+;`EUt4#*t41rƫ ?sؖa۽3$pZނ_ĥ6t򊙬?Mi 0N"._Vg nw ^Wtp{ߊh/(35#ي+xe*RP_w$d#CzYTZ3إ#4"cŊb%`\D@W>)ɉ39lB-68Jadn;$_nSBAXH??:0-1s葞E.hwRžW4ContRғ1.r{0xy?ᲗKaUs7s&m/zB̕ h9Al/<,^g_Ch_g 1PQf.Y/ʕ4DHzM 7sm-m2.ARL17Y;\_Tt{gE+Jۦ |(0=˾' S 7hxܰҖ%ԡu yZ~ɩxB`6G:[{x!R.vc $Vp( k'~N`2+޲N$ty6&z%#/?E[FA?F1,vͅ]w"`%uNYB`ΘŘ&\䑠'A u%&ɘnnyl`LA+ @ü«]}Mgƒ,lwHfgօ26GE5l~V.rrj4m"W I/ !1WCcu I&ޜq _ʧi⣑ 00:^η  z]I.NX:C Պd[ҥrKd*ؔbIݚx|@QP4U׍ FUqʜF"Zmva {)]f`/(P 6 W샸># _("g("u+qA{p/ElD/rPI<;Yi\pU;Pz+D2R|+ɻy޷+i%;< "}a~JrGdT phc"J8TkJ~%ro7XM ̹|{i\V_T,d0gsGp MZ3^!f%]).@:'ųZ яE,v0~-C~G0ĩd[:|H5<qνP{S/ +xf2 MfOsKOT |UFFUsn8D]d.ʯ2dW, fX@l=@'֍bMbJ<9nPWMȂ45"gиQy1~u[cѕcvg~\` @Y2"W0y=O^znˤrǢ3 RYA(Š0[gDM"٬PP*X.֩0!^߯!Vaz~Z8xT }{:<0dYj>nRł5V'z6}k$os wgiS{n_@/qHڻ&-G{L38#ts0!GA90k`ӝ/jћ u‘ȗѕ Oc(L #83x!ˉOQ&PdZ#ʃV3D\Ec?0k7IVâ`huc©=-jmQmpUXAz xgD೒W5L)2a1>/˃ yF gTH{O|bc6LW`&}"T-?wh N"Cc`*<1'Z`O*`4rfdU (-G< h h0A/~)N9r|^ECIe0v ZymNx6b?)Ӭ}옌,†TTq-*L߰ :Eavlɍ?eJ O`8+~S:)w=#'/:d`GwE Ց#jE昆5ƽ$DogL.f;zp;): p6@<&+qO 1QЙ/ժ;x{"pZ•[!îk?ڨ(,N'6..h뱬a4~ew+B6RꪒǢ j$Hp## Ί/3*oHu^;i읝} @a{ߌ"%*8g:M&X_NJmQп"\7&Ž ĝ jz nqy$1$\<\CB*sW845t^  ?Pc;yلq;o<4[c9G]Zhx;aWDB`v|v#1}/s=KϬϔyS&j- X]CqJ97sɓ)0dd7C 2--QN(HJn%md2hBU¥2 /uab^$7I{gx?;ޖ Lb*njqʔ$~>{F[P.˰dP.=|=&t@(98 QBrݜSE H!ԤAM(o,Bb<| oXW? o;5ɛߍf+Z2iSJV|ϵ!+EZNVd>5ūi"Tk!nZ>KuSzmX8 9Y؊e 6̴n835 NbAkS϶t(ei7;/ý=̀|;nM布$!d[zG98[9;_[/&9db{n>&;q5V%@ʄyۥ,CO"7 } ɣզߓ= US5^߯:99y((چKd'`O0TES'v/LFcͷFډ8t|}~Ѻȶlռ`9c冷7Bh4L 6v٣{f4Z ((ZJQht>%bl*- g Z=>)Qb5;2*1Q~"~B/Z9jGsg.VȔ>my#)ol\$LiTzHM CH(潧6=SұDl7F)M}=Zz⾈뒲0t Jml~Ҧ?̒zlĀSKE0Gֈ -ƙ^]-ݚuI>zr^No?5A"IlޔT$\TC [0_L5ZI+rZ-ӭ8) Est֫4XCw(A}=0eK˱<ӫ{U RMz KgvK ^cMR(>ŒZhkL<'\Oe~VGӶǰL:UI,['oXf`]}}觿Ǝ9j-ϹKml>JX} p R>tJ#0m΀<* ɖ^+d< 6d=Cb0|:fIՎ0%@#> $}|YBǓ$1D ƹ!w|10MKn;TTi [c|S]حٌu_kR+] M7 U {ɧ>+! ƟT"Ȣ\tuhZZ|7N4B;!=`/$t9;P+3N[e6sʧJ+Y}M`>aUﶃ>si$3Jf21~ n]`dgc8!5w Wz}d G!}f]PZ1mRDKx48ſOA}! /kGǿBkHEJu_nd_3рd5?иr*aZqVd͂vJֵl1lNސ.4OU7 LI-UH*7\ZM[o9^c  pB0DOб2^|q 64;L#rvrs(2 YgxyAI#TZ}ΖrF<.+<ȣ'P0jxW 6jn4,' =/)+$t r14RՅjwEyN×?Eԓƥ 9aN_y1QL&9}SC'њZ]g(2L%#lrq[(mFK42 iGq8#9 1J9B fwЫ&vVG?X=-`MY*UZi=OH0y J͔5LM/Az(,΅ʩC?֦d {At&aaԠD#VYh|7>( K,6\xJx~ NĤ,Zj{ri/i#%2OXZIbuJXt5y&̢s^D+ @ lQVQS|wPLl k[W6iw+BP.۰c*bD>€95$<ۦ?IϩYM[uѨ3Gs!ZŜM="䮶 AbEhY뼏^fkޢSGl_LBc<i2ƳalQW|'N}`FJGıʊ% y LFƋ4@jO]mT?k!1@o‚dX߭M1iXTtEn1KwYPb"h?PgvN+g1I^[p-O1v:]T '\E':q _߸2jn8,WH9/h^B^IDXԹMq]Z\h=޶vMBDyfΨ kZ- F.:Q_/ˬbSMF[ a ~;5iJQ/+MOKAuZ \b[ m lE厰U\-@,4 YO6"Xzqc'4,Y+ ğauaqT*eo1n.M\v? Vҟq@LVuQϞ-fN ReV??* Xaz|8wFKzNo2f .U.6]xDsID~+^/K J} <"ED=c넍]5~grѺ/'S\Ս0/BkWܔÚ돭`Y&SĀ|c(|*$j%RQrY5ԡ ʎ(!$Dz-8」n&wJ-?B v ;`KA^<QuCk _ЧEh"VE+OVyLNR%@c(636)xaTRF~O 7$YO A70.T *ˇjzy(Pbp"9XoNok먆J7ړ𻠓q AI6Is>Q,2! bIu,{Bi2Yg{i: 1إV&#_J&j\l\DF)``sƜ7 G ;B=;} J8I zY~0vtEk^ 2ۤ 'NR~ I=M;'4VYMu7@'gk: IGu ^Cwf5ʑLsl|=ӭo*Iw:0b(g9zMguYI+ɟkVXՀ2yLџ>5g-yv'b1y"6N+?jys^ŗ!2v8vJa<]\s|+@qߜ L)P{l&hs u#o!D^_+Ȭg4E?*+8e-f|<{)W# _Soyhb, N;!E>*w*' F#aPo+'" T+5XB'Za3x)>!> W~$ϑh`\챠.6+]rI{ ^aWoR[aAxnmC[(OEck` P튩3ScΏBDM5"A>ȢaJ:O4]Z#í2TgY|z΂9뗉SR kKZ~F %4d$B?:.j3hͨQ.73ĉ^x"޻zDjEtaZa773)QY1~>b. n'Іgo3𡙣 C .iR#h#?XSdܭy-獖kqwݦPIQr e6iK0Uvwqx`dTjBWfz" MY?1 YYr’fxn bx1KjIẗ́j -#MWGBzz_+>ڢ; @؀6N[#AorVI4ibt݈RIbU ڿ{xQ4NP+ςdt)81faխ,q6u}Q.<&"&.*dғ$kf?I}w]q? #qw>./oRdIݹEG qe 7__ȦtkLFDCEV[fӸХXAR'æ!OTT$#i,@7zbߓG6B?g6E彴:sϱwԡfdն 앴lI^$64|sͅ|w լn)GH-߳ l\,Kz2=|kN//Y\&m"TN}hF*:օ]_ Ojտlj40o Ħsш^Ӄ)&ЦyBaKnSC:; 6|N'*ڲ8B4 ':9 >)ַD\vιbSw%)ƕԟ96D20E1[n)һb,ɪcw/,z.V`і+V-~Y7 FW{̍ U8%gU^Ӟxf+t`L:ٵ{Y9])M/Uur+OKE#AI{H 7A05j_*ҥu">Oo$"xoRơ]X>MEt4:S>Gթ 7/P͖]u'wPC9h0pGM@k,yղ\pv⊵6j>lrArEK5?mOQ7&1!\]* 2;~@qO#P%x6)As;YwTn!eZ/|¿=+lA:< @ 1 iak}Wv=çȲC\•]$@vVhOov |+j+貋 +18 .~@HƋ#⃖pޒj||օhؘR24MW _-f@b[F$x˿Ԩ~W^pE. 9_VdRz .>!*s6΍%bNcR[;h|۾:?4x`K{ %[c//lzYUDKwVn}7%gOO^<ʽ{6E?XO&n3TB hb6.G1W䍕}xvʧȯ1poDZe5)pOymY8.BԂpC2I}MXy?񇄨H̭*5ΈazՖgs>~dc F氵X5W wRD>s*fVqjyf^ig,.]5;\, !y| 1e +jMS$%g06YM*Us#V_C߾аՖ`/\rs1>˙8u3s'M ".7$W@W\H/eFPE)R0'ȮO=nZ.י N XeZU-s;&*iyA6s2g1H/ɩ[M?iEllex ?j} :ȹÝ(4xx!l?ρ8WkEj;~Xm:NC:2Q ӕ?cUgQ!T"~J-i-qOI O'7;ݬ=@4hNA. q+_"d_N.n0~n>x8@1bݦzt,GLòS{1?~E{? S7LHiߣov >iѬٺSm!nbl¹y\VD0ΐ&QAgi̅nūDأuXec'9cZD'8,=1n"!J**󳈢(SJFLKQ ?G~#g]qBU c_&d9/'Q<!%^OAE}z'未n>! c8 $u=ɨ<6FU$( t 92Ly f)^D!L'M}9PM9M `1vp:Zڝ:w V^mbLgRy\ȭA i5x6NGkHۉQJV]\L@2NzŽLBS#UΡhmaB mnڲEf|sϽ\#%bej(&F2y%t1O@PXhtyIɷ֞Cql+E˶ICpK; nnOx4:W57tY&Ђ1daY۱e "5$.QjoH8dnP+wc %:Ya|Q[Α^_ζT2PBFI(r)/2w?Nt({t;G1dvAk*./?+jB*A )#cFb F-hGaͺGamro:~| / Q90a/1@╌2 Wb 5Ta0j@Omޔ ʓ; kۓe0һJr-,}z/a7Sl ^Z0Va' d+)hsIU&}uJ>6 Ŭo'h|?){xo-K 6Ɖ>`y{X4*ʶJ`Fnςe- )f7[E91X wIᱯaJziPǫ|'^wcrSm񧁲0rwY؄ճ`}:lbYD d^ ]0=.I;}1pUX%59̿\t*߈Hc|\˺2!b \b8)FҚ-aY˓ @eKڂm(fR3U<~Y{BґDReXƛCCE(uNA~qrMj MY:PQkXȎ#Ww6ݑ3^Qѕf0Xyf~&F];;#K=YȻojJ:=B~03@;J =L6>{_7$T{l:d`|scY xCp%Ly_Or~n)kKKQNp#Ob?MY)3]^=/%^Vr$UlVe@ }lв y55l}*4M(P!|oA^7w0dӅȀrnE`I1O_[ r nTg+}6^DY'SI}+gRt%UQ9df ^ [@(&qsh/4k {FIHJsIP=鼇n_L9vL("Ş3I!B۩;i9WbO|зٽ͊ඒiϻS$ : 4-} $`7ҥ?PFLqE,Q|Q UϵsTk`KM8vң\mAr l3t!Æ_o9=gh0bI&:'lP]M9ԍL9z2oӕ:_%Dj֗Nu :ݤgEIQf]#t6E=8跻iI(2c*F;.~5gO>-I+qk H«듬EurڀE&|]VAJjT8X{?KOy7p7cO]DzM3V9Gx{RUȲwN7pjh\fYXC8O7ǺPK=E!V7>:\&H{{x}1]Ѣip*5cZhdFOHg Dq6*l$FEN WJ#'=0ws?A4BAOPrCsw1._`.hVIeySe;4%" ?'>Kbi]`q*+LM`aڗBl._@+8sW|[}u8g9E./`$u`4MnߎS<0 /FIFvL"d2!ax菻rc][S\gXPk\f ɻŻ KCA\%o.] L{ޡAg5Iw9kg$JTţ$/Q`{=y%6R~|bL0eto)G U_"i3p^@ƒ-s{ ¸_޺,5 ?DDӦY&αK̤!M Q;mͦԒCXC vԦwvڠQ]j"r..a! \ӵX K8=;"T' db)c|F5ߖR\J 4Ľ3hoiUjVܛ8s,W f'!jm/WgsYWv)Vnکڭ=|,])Y]ƟV؃qiN}>v*IݶJrz4z1#B5Qhr_l . 2k5^;{ T8H&&jtsXnL|Iӯ*K~L4&+8ʓ1?;ߣwk?"|A.Lz0Dȇ(0^&m GTB^463SlCcbV"^dNjb -#0Hg#sLm'k9TaQ5Hoٳ5S/4–wǒ/<΋IP m'3ZOȃ3Ec1#!N lpH xS'cɍsca" tbw- eSB,38RvHԫgr9YKJጂy<f'ģKe=؏Ce Η3j72G`cm(=;Or -_ i/b}ݢ$&+@ls O(j7orXsT5 3K5KQP>)%>mJE !p䟇OO:~ؽ ;¬uA^`|a c>4d>yU-̎bjydTԃ@;+#NY 8gއ]3C+zR01w*c#66-bf(/]ι+A`O0w+|?RyEcn40[ƯKy%GAa~~#6tkȌ #1iI" ޅ鷙S+d_87 @؁o\Z_Wb;B>rn#>VeB%V1|Ѻ &< 9TQϲPA4ߛ $o+$C*φJ )HdeRy;V[a׻̰xAQ >w Q=R_֮.ovV&2Z.E֢޿N5qb2q}lNUiS/ĽM? DG4&߿Xg\~rS%p:sZ,?v,  #IaCӡѕ|=N䬕0꾽tey^<ԂGCѿS1 ž _atU!s `JW!l*˶9n𒫁JS Zb |D3/o@КdT^HЀ9BQuZ4yjBC+..<&u{k\OB:otafp^uk7^Ym%!V>M''`b8CaN609H? 4W g]\iԢg[bg8lmmԙ{ӆZaNysHr;:< :203mZ@{f5s51*℻Px hiՆ ,T+y{2P{;QwpςK1E,D`M6Z]{ӂюUMUN$@%4#G~B@ 㪹M8]A9sY"N GP&ג䏌 ,TBu-S>H27o"> १)"J'ȾQTAoᆇY0Iūלq)b2v,Y4ĈH6g>Nt!7BK:_#WvpZ2㾿 ?ȍ1~jÎ?&uQGmRudtV] .S@:kC>/łmy-#u%?h PQFPzxLj`I_ @MWiwY0u̜K2c2^[TR`4I`v0N] {,j9y M-C< FnYg;HMBH+7-rLx'@>x(NV.5$ 6DUnuڥ&Q13&iY@>9(ґIZ:uhƜPHÿO_{P#n6Dɍ.Kzn'Ŀc!|v*yR68R7zP_-LϨgjX\Lk ]`+n addkxCw#Taa4WA69بΎ졘rՀZifă}3w ۂ o/=OrG֢gk8a 'qOa x; Kb(?莏=O]3^cxɗ.(@G{Q:"u/>Uhڌ@ޣCC<kv#ɚl;14q%^_e: ^4+7)oBQϗwBd?k#9,P6ufBwE+UW:p:p]T[̷NK:m{ X݁g[8`Ѽq5UT>U!lC_"ߕ'**g?:6aTL}$+ݽc#t ]ni/t(;T8V,hlf^nFN>2ª(T=3Wo*'=:y:Fn#kyDYgIG2l2⒘ބF2S2 Z/lJ} n{IͦnV$EY)ԨVqp7֩hUMlv1V;ÃUdv;C޿MR`dq>hp \eXiZd֓$k +p% yɉ=V_&[@#dw얜6 7"P2J;|HL|MNw }:0Ŗ.f}EO'vdWPL"CVrvnt:9^MpF-gKi-ob+/q#TU-Ym֎c3ջèKr3H6HcV8o)Jb ׉@nGGwb(b$-۬N!P4//حT7ƕ~P5] ݆[:B'Ԁx !:x21bmRksw}#'kl{`Da7%Hw{4G)cA ɠP } * }"Z APk] Z6B{d;qeX5,,ҮT,ΜaRs{.C@gSmg Ot? eSģQQ8Wչjd -ܚ"ٕ(=N/7Ǧr.pA쟮qIǖgm( x6XwBh>9>o!kxxƑ ١|'? KzTyll{-U\2OKV/4 EC+.^#q f JsdsVCx3z=V # ZTO:uL4 v(nE&>LUڪD34R@=(**dW~Dwӎphp>l_(v2VVY;˃&o2+SkV"\v.~FP2/#~K @y+y)쌇JUE#TDbv-` cN!HKY,q=R"H? -S>UT11p*7#8g/sTߛBkR쇦"uf챉d40¸>-h R+b RX]EӀ Թ^}*r뇝a%a K["kdM͚@|Ԧ0\dpt/bSZ_PVL*,y 3ɚ5"+ILxаٓAjy֭nvpQ0S =rGpwB¦.M,;OGh+ԅShUid b9w.@ yl;f0`M$ŜL>Q U4t/ԅF ^͋$Ӟf!iI.1-V r$l˯_lI|"z t=?9j +4(Z"|>V1cDsOItZڲ]a !`q>./-YID3CP k!)]cknoݸZnt .BǕ.}FU"jwY`0$wfjb \@}27ؠXڪЇWݣu"jۜV[RȤ PWDݶuS@#pUtH7@%=|O XAd! >MP%<*xƢ& //3qf4X20a|e˿hP9Ng^[Ng=S.FCE.[r! 1 ΪfVpšJG=d DpF$W!Yp`oGE)؊A<$u-O^T|س+A+.i&[.6acKb9nPkt4nVع *2Pnc-=lR"ʿ0Ug+'װ%?7%rwvCg@,v-fqi(vg~՜9p mp_dj踢B%z]tls2YJ3C9o su7CR%|w嚁򖽡~h fwR{!9[.UU[w&;"Qĵ;Þ:JqX{Nx|Vzp rANM tX 5 r1<+M+duYo N!A,Skr}m93i]P]*e5TqO@T:ڧ&:vc&Oy;YkT)ڝS3T JAl&aQ!h8Ob=Z7[ǿ G|M NzD%PcI&ۋ΍+@H~<7LT!tJ?%d1!M(KP5ޙK_ՕF\NBj̎*8]W='E;ZJQmZq2t'i"2S"L~sY V||+VZ"bU'Uغ5ݝ99ZO&+a+uO_,`˞*/dlM-‚7>t&ơmd{e 'uNu710 eI㝣Ge.C U{ᯌɜv#e₼rƺAծy ex rNh򊟗w~HpN}ሞ%0*mm`.µa f'$p AQFhAQ˂Qwڒ6gٽ'1^oMo nʙ/w΢V(FrB%k@y|mc2{E2^j#ƈSw6!괲 ֔V q\ٺm_G 0%@TϚ'oۡWt9--TSK@,(cN^kS&KjPeƀ3c:J~}R$Mo8k|h@_),^24O뤋3E-_nUkNFbԴG_mdB^ q%euldro 띹 %ZMGx*"r5MӖbɗ߯d*rEd^iBo:}X <5xpZiF%*M""°qI&#!8qY7RS˫7>'XRH3@__gَãg|6Y UDv k{1SH_Wwj-ҙ1zv\IM`\6od ^&{ iL,~AÚ:cU }:uFa$ $d6Xm ;Zjؓ[UMy /?4Dh4ЖCVCjdغ9U>cC]sxBTxjfp'Fmu넒^湒:%,-~PmKh󵅂ꭑNm$ *`W#:R ۰p#U:D4H̝1sf2l쩝A'z8Ht$L)G2_Vے ZY@X#j<=y8 p륟e+8o0BlֶG;O /ǛLˇC*[<0pXT{j(h4ِDHfAOWԏC Co6B.o" KK=c h8 }8oMFz"ɩ-}?z_yH¤FoMvL.vN\),őbiQ;TڳBAzh^ί]q [!9zOw8Y5l`l R7@9*ZM^2Tޘ`|0Ok&/h! gvf]Z^k.=Z1 銙a2B l@,{zDt =QA!:QU8gU?wg|r)5(&a^b?訸E47Tk~ ;E+ʄQؿ(ezPh<0|U*V4W=e0?Atk,P_6H=X5.ӿ ۇ1+xL]kXӘby==uaeyZC鶨FLLLV[.3( v56u aq *G ;45 ]C %pfAyt~<:a2?~Q%9jMtcc(᥇k6BKEARD lQJ˯oDV=K iECVn?ߠ*//0LZ3 ~6N/i»A) ٖ8!N>WٕȝćpO|a, &^u=cgL1S XȀ`.I3fuΤnkmP3q1-~SV$֯4אm_יBPe]\%[J$~/Ĕera1FݷӟRkSۖ4igĘ3liG;gΊT;oh}-mki"].D^Ɠta0J[inc(IaV)̔%.8RV;)k|w_,;QKAvK1ns]HNL:r<[7aNSs#Ep`,lɸ)Z2 9~؞'ՇHN:@ǝW~)EZN~ =8gX dk=; N,6)SU)\>&~u3v~sfw:7T E$q^ՊIJrNblLa,=#(Ti ~} n+59tQB`Qc .B 19c6j6'?cnM\Ox`Km$'pn_I޵ ye@z{{ NBϛkNU@85>)a7RB/ZEvMIQikb/q;NvFoy@q6 ;*Dd#eϰv@.ٖj+ԅOV`s՞bRsBmx.;5fߢsG [sK8U2BUu(,8鼓{1 K;wk^44E -ګ3B~ J#1O;:: 9։+n 1awٵg{oNoumm 367!SYʘt܏Y_('@UN%e*YZ+vf٪)OKu!]Q#z83[ϽD.bMxn en,sFUi/BA^6w/s[CXYK5X1K\3L¾It 8qr<;SMx!D=1AN B1]#D|^GQvg=@l8Y%wTn92+Ñ IY(n|%_ :;j+цpz` U#= u+s<(Q36een*pnO3YQeExE?!㻨2ШW)BB|fJ C2^Z(7A60CFIΛELPyUciR5_@s 4@zfߢYq52yᨕH@G1EÈ1i@)yh}G_pK-CG|ONQB"MK.f"ԣZ܏Sq3&(l)$z<53K7<横bb"o|f8oڳR!_"Gkyfpn)nh?V,PUA/)74(Cv -SaRʐk>cR'tKЂRlfWrUc9;PDUV&S+lRKubt68mS-m"ޫB}RwOvU(pR @Y\0ǫрamE  1 I##p*^=@3nv5h@OF x%!`@AH:谦5i|HЉ45PZpWW"JU઱ C] nάxw4+}ïiC*cp#(#I:ˌ1]FX~n_dVt,Oixia`fM5baV¾\F/[:yL* M:ZJƍ4ڴp{+]0%&Z Qu ^T_uꏀ?3^/*v8il`ZXgZg]FDW$!W8v9킏Z)YFK|O uāxNC\"40|J MSBA. xuexWk!_!X(F/ZxB[o:!":gSX[63P7vS>D: yٞ4:E ^<zb݌ŮjLl 3ͳb+]-ɷKFN m'TL_6"7_mD>H&3_Ksoד`2CjA^5:HDǵPZEϞ1?>d9X%G/zlٲ| a'8]?fLHWBTYOdk] j->Բؘ7Ad^@^Ƴ+)ݫ2 Rut=?{#o9Dj+YP˳JLO!=Zᥧz3>p1U +d=,[,1I]E|5o#wHOL\jHqǖWL f z(T뉪aS>6Rqf+3>ޣV<~X08.^./5[Tr n:~2B%8z.emc{zBi: djM~.<ǜ >XfQ>%Y6&f}\G_12 t#h'<\L%/$XRN,c*8Iͮ`rIy}bNl D[-cmA\M`?"N??fSU2ӜIjD`^W{c;"vd ~~yr}/bK ͝oo8ȣ+~hs]JI 4Wˊ)F.~9e 0kE ͣȟJJc4fXICJz\o?nȊ}'4AHq S(u]COtx0B!rx\N}9i6 Ǟh"mO1 mBxY1Q_.I W:0 NU\y@/ԡ D*5 w|:kjik%D Y'Fݨ@N)DW6Ár˺ ,K9O<{[=1CABL< LU z͔Or4д:Ջ].F7H4WbG>˨RFju2h-.-$S4 KI;f"]#XKKOOi&n]1?!3X'r:[b :VчrM@GaX}KicaH#|,Vhˉ0 _ߜ$7/$] ɉG2 XF6|_SO] ?ȂW+ˑ aDbI&,,Tiڟ\>ԾE,rrĸ2 (Z,_ΐ.U!5>B(,e/BFɂU2<7W^M@IhmWf %"6bbmdvЭߧ%b2Z,Y i$Ts=giL(,*1o^LAj  xϖ05M;bk4u&Zb~0`L3.dsJ G_sB.qN 3h&x4,H/ވv{p^K!),B`O$s7"'H{!1~0YC 0e_2qB7+uBTzLO54}(HIO+j):е[~Z Ƅ5˽q񑡺tUsݥ ZEhc}0W2[%ICdZ<,eދ#L3Wzg uKqhd/X2OhAZ׾Ѳ JoHP>Ҏ#' 2% gfo`e7(wK-6sW4+| ,mFo8BL> (Wrb8-l g =w[T}q sgUeCzéleDQ3(x vul7pj!V<<_snWba^LpxzmXB^%60/TvAܑTRжls4\www9^[+ܝ =C@bQ;Xi\qؒ^Ut뭟zj08cTj\fcܭ"]@^ :gTx!MfEAԣy,  -քt U{ny(%'*"(ɱ Nm=] (Jְmzˁ*fH@,'\rijHC腧Ize\<)vsϲK#&C cLgIc oU6-;3{sOj3bQYb &5=t'0|9W$HѺi*$GDT zzG/hIge"vEe$.s\pX@$ʐ.9X\YaCkr0zX^ngŸklhOr8=|b >~Ǻ<{]8:1Bg^ !\H>+X%ڻ&7'jnP5o.XD-MnGV"n7hx r ,CJʸ3`ǯFOq 6ԏlG}<;d0W8ΠCzY3jP)$& V}$E@զ^-F*t{aPIkHq"*\#I8ݳ?`6*|2睤LیCR^vݧ6^n#N``l![qߐ܊ ۺQr񹲁w w?IO^WǐS#lȉWZt3To5,yp.&5D͍yq!;Z\p|p^9sf-ܷV#p'xZ-)ƨde,DPhO77M,>/{J1\j1@ߨfP~i`n:LM}YN77O\a4ٱ՜z!qƥSqe )Ai6)Wj`G M [d =zFsRzvt0X:͊ru4iss2ԾԞ;PL}%4wuVfpX5T\ i$ gw肳X-'wg6qz$fV#iHC>HB`ln>Ff[r@3“ .Xaz{{ |5ao"CG>8DkP\x?e%9A΅Σeҿ.&\=^uobItۭ>mڑ(SC v\}#홛PwD: }hv؃sQC ר ZD rPe}W凋&0 qA^$b]V{×P |GU"#q0R?jX~&'V 2rx]7G&ѿ}SzoC/]Rfapk*ՒCvbJFߟĢZAv>#5xc +9gHd ԩQx{s%' sF$0sGj8a6$\2!4%H9,uzce?5&-Tghhc;U\2ĜUXHPV<%I[ZYIo,@3ȃ:e5.(؟ .1~SUdp]Ӛ:{.{*Ukyh`Ik5'5 P\=TlT?L{q䘭392*::(nt*t ]5ʍnft[,/f庺}98 o?5y t5˧GXY׌wa"nhVMBqV<ʩfr'+@2_LK5'ǕQ$FPmBg&*dM~[JAh{Vl͙̀gON# -{J4r!&,ЁA!mC7|{uo唐!"@w''%c,q') .\}xqe3:i9Q# .zJGiTT%;5(eAFl=g?Ӱ UNj: "95 Ui5^GՎ*k[7`8.->'uNO@Yk %p]ـV'-Df \ʞI Ws]Zn }dv^Nk,tLF */W Sۤk B"#' ȸUn X{܂\hrPeܹPӼNQ)o$kH/ӖiO9TC%{P u QL?D⸒ezXF ;f/1BØgHpf]aq e N(EGꛥTil@3 &D.u, ȓW$ q'מyڞL&v9RJT}i0167jXUIos&(+Q)ER^=}(ſ\ 84Z :BF _hS"^8 " QY<..dC܂5#x!I.ȡVJw)ˋ͠VǮ GUD+C |pFB=<#z 5E{`^$w齰_5c^NS:yUFCS6' >jyKx}t6cu빖zDrKp3V.yˈ! 0J;ة;u- y@6ħAQ*$̍5$ X`rR5"_>cF2xJ6'ee/B;)\'5>TQЮ*r6BؓK7_1f ,Okް~:f. Mԫyq%WDZGڲ, \˅pJT=v3;S-HuD_VTu^Uk[XyQ6WK)J-פC'JPE!yHHuWMa991NO/"ʊIϯף z%+ν2XT ͦϱҐ W\a(4FkA&9ŊT<{uvmVaNUa@Pj:DaJƙxmh][75 Td,R},MN[{|#Ot<'AP_I~BrjÄS/:иHHMcu 㟣7XvER6WuY}].K6ocKL Up #3`~w֥ suL*p$9{a"tCmbGRm@Io/]׬Jv$1( ?2.A܏q'̷.Msm;զ3 1/Dl^_X4 G6vh ]f8: .'_B9d];Wel.[-MV>ౖFx~?v!~d xrk"B>\ ^Ju@&)#L]tv& qW#"s0l}dӉu{rAD/H2XFX63:GnR8ΣD:=}W&1*%iy]>f\/* 6&~2dPpr Tw|'jfٟFW%NKjNī mQӖa=h;$L透 xGZlJ`eT~m/LR xhC[Yug3l(Eo JSsU72HJ1 + (/S;Er4g4Qdhz=22fEnju}wsJs]egv;'Mт6[I fZQ =XO^\o&7䙸:u_ ]ok˔^am{Y4/`IGa?v˥zї QelE:"0_aJuKBx}?}JZފ x:тdiS]ifs̭b]o+ CPd* ܍Y2ZG5*h$BO:8wEm9#XK;IǺwВK Y`j/'8w|ײF‹R;}GW!]B ; z[;6)-Tg!뿷(H< ,jG !qe&9^*Ž*jk`XtO\ .߭w40U]?' S j%7c N?2Bep*vAẀ3Y%W<"t>'ȅ$LP}8mT=Ēlwt (aFcNDQ*C%:N'd]OB|Qup3LI|cTqvҎ6~\Fex\Ѿ1J) @tvNbE^d޽oP @Op$^F<1Ұ]Ώ05Zҕہ>8KR˦H2X8r7kٱdQN]ٙ{Z1{Z-:Y R ,Q^el[;G?Xy+*7ͨp# j~AI( VY)(/y])J5?Ϡ:OFPa`pO6?1A3 ,^ ✔W-_2N^媔'>ֲ '>PqؑDϋ6 GTnsJu!?pQb抷Rҏ"Z̫j<})N$Z1C6TUCK_@X\<ٖP f&m*By\UeV0k"( j)m/'R w13ynL1Vy"W!ѵW@Ƿ.z\_+Qj~F;*G1T?Շ3gAG7yO_XL@exJ 8 \|>$ 34,DAKLEQk]4ۏоkL<%mM7rXUk(8%T-=LbmohbJa;UtKX~eLrcPY&eRr0?Ka ]+sPXız/oULĕm ,Msߚǐu{B\*Ꭳd~Ỏi]$&O0n5D Tӳ\Ê٭zn "|($7Tg\{mxycR9Yp?RY8-( *$yТQ<瘂쏥Gn 1xOwNeq,$%u]bG_BwB6A>#3="ۚ\2XF>cRcv|{MQ{RR4΅jicC!6'T_9/+#+x$to+I}C`g2)M~QYS@XFiO1Ƒ{X5 P"4 +Lnqa[)5[zn,L'~We߈ ʍWw,CN*TFE%Xh h"LDqǴiIǨyᆛ!2VPŴuMLi10984BZD SσiGVH\D g&; Cm6oLvKr{S^Rm+L ӓAI?[.ʅ$7Kjw`f5'rӥh bZ-Y`{u[x`< :W 2TfRm4J? X>ײ+n&j\ Հ zjV>衣‡MbBf@;n9;o&uDX],D/znrC=: Y?@L5#P >0 BB=5.ЙҚ / ҚEȪ(y(~׆VdVF~Bucu!O0n/IVC2gE w-l9@kؼFFUD} xnLA?iZj08+6 %5a%hU?"1JwttuUwHS5&P-&:)BT.E8Ӂw>f\-?\*<q5R޸WcgQ$"5{+HRT ~s^f?C7 np0!PDfz n?l?R:ƗSRr2-{y7]6m`9Bg%v/F.L) b\Bg֞7<}SDžz}|9ZYG: I4 ~!c@F=lQMJIwkJu$b\ݫft4z%#;L?}[xq?K^$Ki>ͥQAow]Eu%]eo)3(P3hfBmz{7csvrHE`fm),&1O5[sy,aWKhsа]ѽp;M5ZZc_̫p)HvAC7_^`[ʭ_%fM19,,p"nN#ҥ:G^s$rNNӚZ @Ʈ -_f<ρ'a(86!pP;CAfG>JҰ9bZOEŜ8]V6c. 譇;﹯@1y.md^ai4^U6+[c;ami00~]%^lR|} vjW~x@G>AD}[Vd]Wg""?)zg(ySN"n"ytרe`n(9F✳cvǕOs\PL6owdF˨Y }R֒{+=N{9] M"7SI\R8H]?1@6%!Q]viV+ <~;0>9WoIhӫ[_[/Kao`cK~Tex=9P,If1*ZsuB o6'7Y*xzL1x%Քu5] Yȓsl5%JÁ#T~5}3w*4hz㴤~9zV5L-+T/L$l7R 5:5gV`ZuZqr3)Ɔw`+&-;H=_Va'$=F1 ! ]65s;1ǤN:v9'H5b &V7g&(gF$r.=ڐLRTjC"7q91Q}DQ MݖCsUi ]J!>V?=B`;x~TMzoNrEWm:fҎnt][c!4$րZ68Vjs+F){+L:o]h9[&~E"5@ P&*\ >h\jP{@׫"P.o`ogumyjK2E~}FBoI._8.uH(C.gZPlȇ!({$Ue?"@؞jc:**liM3n}åH=%Ѱy62gb^IFDFE˻X?E3pRd%{wb]7FLla edCgV.WXhJq@yc`b=~酏RBU5EDu@VJ 8zSEncLggH|[V͑>M[/$o\^[᧒3 J&TWnfVi5`09u JRD u_&Ӗ><4e*\@f7J&U?gW~hel9Kɯ<$̞-|с3jm a8m&I07p"j&n_a,@ovxXd>-H$//H`Pa✭nM%Vv?@wgʴ*KiZ#"21uZb%gs1ޑ EEP#/; 8Ha"rCjZ%H ǀT"o8"y[=P?85.Up?ABԕOF[Խ7wyB/`Qwx1^EmR½ R5aaO[g8Xh?O%^2ú:d]띯߆OG,W2\.Tbڔ԰,fIO}Z ! \y!h:Ugd~}4N*f"oj$HtlJzzcGkXPN<d8ټ999wK)*)_|/D;_+>/HȔh$iZ_(D<(בt{nm'2hԍG<6:$9OX@jCU3XDa5>7 l<>a xSayGA9Fa:U(,wp=Y@z8:l!VJϛ܏ȞoU mjpK&x9nvlXMU=I0ő$AWLH QB&$1k*«5.4M!TucGϖ)ChzamW^+h-I-!ڤ"Oz'ZkSͷ1 F*CRd* Z/6s$) KtN@ԑkeH$ޭm!b7[Br{;uKd1pO?.%-ÎVgnm3x4vBb#X)􂯏1T/tQ YF}OU_TfaoHwmھ2[1*,V a wYJEϫR$Kq31D(7`Nn:|EJOIHQf>yEإj*:L'Vy]̲=+`{'}xeza"yD u=V*u(n˳VrOYPU X6q Ǎ°p-F4Bsa"&'Ҋ0Y\.?N.$2j^CCG>:[גK` <ԡ@"w-Z'vu]/F/[L`j-v]M)Y wcg1$?Л$X53iٌ* UF|յKYx2)a'?aTj'E!T8VYLjAmQCV9^%á-bӰfBOiI*;EqRsv"p@ȷ)Ub bW7ՏDd#Iܳ~2cbmhXih .'샡pk|tF回׀pϳ&ov6|#wĨvx6YvI-B*VS!aTWa^-kgGR0^\6z\{W}$cϕ GAU˯!6"҄."~x!\-J?hRp` DnH̗~ފ\4ٵ;>PlZStw ȇIyG].\fOo@t۳sE~ХAtd|{`?zc(rxrWXsS9! tLpa( e k?V:&>!d5}*Xi. :%!Td!xw+/uaPO" Ժ?ǟ_0!,!)*xg*t)4ɅaHƌĠ@xF86VY~S/KOq&yإULDVߺ!W?%u-gJg={޾|*fYa8sm⾰4ьor"fyN@BeIuƿq CdyzVY c·;i:(OM)E5i4 /nP14dmދI2FqSaOspgzyRpM[.gՇi!(l$esB3 o>o۾IL"ݻ^HsVL[VU#S]a 91 Ӥ[%qA-~2X&^փ)oYcfP@ _mPnҲGĎ 1SmKE65`庝PkbW0ݟVxElze)sB' .燻"z$'ZB/bÓ AEklp1ϾSqI >Ҿ~WoI긻xLo [eÅ72̼t# j&@a<e1LO TԎup!X`~BŁʉz>9"[X4ؒ#OuY```۞ݴ@M*$3퇯yMqv@o5'+XPL(%t}I`V5ÎI5ԒlYA!VЭRdY| а! ⩝) py^M#0j(軑AC'|m*:F%;|s2#nRz@⧱,iuPGm>ϋڸ@-kjG?64S3hE䉴H=3 BM9e {oo9;kAaVi6]5QGm6]7-ܯ{Etm0#aASqͲ #} D+f)z!K92 ɣw4OXoXGޑJN:H݁ !)@_㩧Q}j%dl*RT^v8QSi%IPN ueWkCT&ˑp—Pq).X{JP`fj%1gdíu- &QyB7%a,#6ҷIq3e/?biOe@,-g`0Zb5OW4'rv@#g@|9-+N0fq=>3e* l.v;,N NiA;̀u$'k-²,6\BlΩ9L"#?geo*R֟rB |R΄WCr+pޠ(u]m$^K&c'2$( 8L?tUށgm5ʫqٸN+D9uVĸ{;1)zQN„TĀ|?'B òn4HC}r,H2=|mCzka&.OgG_-2U %je (:C[kN4֑m:\T7zO8Qy~JΤf V} Z+q'#uitL^I ]+Pt1LC{9ITx-N7gTR05.V_F}RELVAnB*0z}Ep XGQa)/FҸh7RS|}z7x6SƦ$wr~vx4Ƥ NClM`~B@&?%;o fѶB-<4HpЗ)hfr|uuÒ4kKEE{,!=X'zH"-z;nKZBJҐ!'}K~fthNa@)2'zHi2oN?䦖;#S؏!Pv\a?@ѿyb:֏OpQ}Ct+ " ⃵:-l7tF"+ -oK*Y/j( -x3_-Ƭ|NwVXLoP}"ɵ#_a]ۙGt"7Jv8/\{qAHVQ9Mr=Zq7yԥqr#tVqgup -PKF()|%:I~/৾F.!o20Z_ҙѡBxAvzӡk:O#-*[هJHM 4@Ux73`VPO-EE ,8\f8{׈pMx*zg_N`2ZbjE5,Z} sjAw)bR20- Hwwo®a!'(HN J&Jtq7O12FFē[Z%DUB,'%RqrGCPVoe]JIRhJVxsӝģS +ےaQ:/sVI`*[W<ǀ%$F7GM3T W&oV ]6O8 [хV.J=@ 3&BO yE(!d* dZj#FV }"+tFaq :z~\)oSNzȶ:" mL@j}#8[s rIok֙Mf_bkej Vd4BuZZ*ɗ}vg> c3ѼH?xS =|)X :=.2 ŧn?[;#Y_3z%.]sb_{σ.m%O2"ilC< , ?1?,Hz\M&-{t)>⍧H( .ػJ 6Gs B 4QoƁv3|'aHit] ihLg7Gaf~_|iG#U̯jV>L`J7|x.N1ԑ={8=5W{͛l(7Mv Qij:e*(^oN%z u[X[J&P548`bny] !*8P_U|"-b2Н0&lM*mlYP 0P@=S::ҋh jMVB/XgNlS]2/}yh{D)' 1`tJܷN?$fE?W Rpy(dduqf2Mbz5DwQFFC#VJcf&j\^^:Kf.H\YHig}.qk[9G*Eרr7/8Tk"lЮʥ_ӕd4Q: Y0]LQWD9 ֪"ʬuU̲/M1|c:-X ~'qͤ9,bC}'VBXqMua=ʉ[ b01vi J L{d^織dwnJϵB3فm5bE)%4tʱ/TEcr0+^!&&_Ꙁ˽J0;7;R4X}E铷g2++:n9; ?q}i-?T;1_A|xQgOlsbsAPcDc Byl·)I^M3"P8mvZbj&>JRKj )>7b$A8,*5#ᏂɑBN-ϥ}gx4w}ed)/jڡX2qX ;*y1ЬգֹreE>w[2tX*.;OA M% >VEjjGO-efmr!̅d_qD)xç79 3T:g$f׆̸JE{dR  Tf5S& 7}rV*<q#+:LUeF51(;yA8DN?_T@c d'K`zNp} :5[t=Af}<ݙ\H ֯Kw$=~ a-M-4X* rB]Z#Rގ5(/!h`t3'̓&-:|؂0nzɔkr= Ea>t| 슮/|jxrh b >(uxfW@ELN *l\'զ1X*ƿOJOS!R=jYOcI#FwH Z` ;Mq#ɠAƌ[a/\2e6J/k$yFuKμya{xgƗ=.X7z{Um8BT;_W>bͦSWaFXg=iQ#e{{9&7I}{ES~ZҾHrc"5niW6^i ( 4$lTbE3mSjd[O7VWf"MsL}WHCF)P}ܳB"N*PL)Z1sjZ:" ˹S48l}(h[h"JD}5+6IJxbZwr Et:l?Y}!j77t}1yG X8V /d:gl \[18Ff^R:>90U mԉ2zlU 97RHRVM8GXqfIbld86֯'N&b-jTNΫ{wVn =׊dmEu:[q67'El YH! DWYay.yUWK\GWâ]u_&H@[G>`݄A%EcE ¯~Г z|.CCJ\`gya.F; `2^_q|h2[# )늋LJxausllϷl``ot!x "8CB*NwH~Kk#o\Ćme) ETUs/Ul F=~r0vP$zfX3k/Z9Z Ճ̒ym=DZEuT[H{^chVےhOg rx;m ~mWM3;0wchpD퍲CxUH-՗j~GGBʆ(lEg$^B=3WW0!'OD#rSOwjRݢ{wom9NtP)FSAʱzN0G9 -㺑CouFMUէBa7.Ϸ8a0RC^C}o_;itC8h @WrC6L {u&̥K nDc2=Sp?#୅xHVY}Ll8úفo&iڌYy߼.jejݵk,fz]Usu'u^g.s6y4{1P|j 6īЭ JIh&3& )-,b إN0ϛ゘bٞڒ!Q (Bԏﴧ-V `pK1@Zxxl\ |FaH ҪީhF#>0sS:NJ@sy5ȼ(?&$cAZdd1H*Xs>b?t7PO ) 0)(AY ֶ,!k4nH5>>OsWvOo=)z ^uMa_|P]|~Kfa4ƈi%2JrrQ*ZDd'3Ԥ3#Dh?I88@Cͩh̞7K E蕸sj^[hMoh:+SѦj?OMEH-?" !Ӎ-.mp%$s,Ni |UPE[^1)R֫e~lxH>cQ>:ߒ{`QVƱRl%;'+ʷ~'fm5ٗJ%U)tHmaSDiS`w5W|TU]ڑlP}j!dA!40&W whWSo@k SuMwX'nnY<3Oiqbf rÜIsj5H~SX7z6JlV߃hH 7${L}MLji (k7 |4ߦI{.6_xxEɦ㇡PnpMyuϸYPəh x\}@ZeSn[/89'E8]~z^8B0EUqMpoVHsȟ'PM<R O|\9.6:[DO uŐ+ ZK y>lxpT C::Gaez`5Ѿ(n+mo^x;Xb ;ci5?;>8RGK _sbg*K|KMlNv,jI|ӄʨ$"~.t=;ʧ7/p0\׻oF0ŹI^YcEvE[!Kqȩ}WJ♒!q`LL+jUZ. &uѰf+\aP!Nk'DDK\NEŒJ6{Or7Izf_`0F/|NjeFsH%k)wPPy=-21&fY-nMMlxtVDA_mj[CdgekKj e//{#`}{=D"bZ&Qt' <%:W,(_So{i7Б;Y֩o.ٻ8HLb_-pzf +p)&T]jjk QrރF4q]!v/}&$"ExiSƐ؉yt :TIl)ai1_}Y'j ]+,' بqgĀ[ouSn/&4n,aG2$?y6TxEV/#yGpO>֠jh1--w3]#BdRA я nκ5$'+QӚ8 xݕha`|:S]):)jf.ט!;@oWS4)5WzW^6Ҭtx0)nmcuh& -\%8|s]*;fr~'2_'ס+v {FHL,LRhTڹY.^ :Rewv\#6IjZ_RrsKa\AZObP yQ{ҦJVUKa ,cKi<| I](J:&ҏ>"sڪO E)`ڲf0+HFeDYy!BS5YfDL@:m;,j҇=UXG*9L9KvcWć_F:Wo ,ۭS\FA+ԡ0~g;ZP0N78t+-_! #b 3ْ~ef>{mNA@zPSA;h/gzI-v{d W| fyH`(v˳zo(JE$նc%J_(=1|m=#;":'U8wh7? \eeYR^z*!=0]H;?q\ٝ ^K$ @, pŜ@k0>n&.}$hRXm1M=h7~%^Dp*Z" nq-v\",Ap^ڷ6ln~, B=tWD AX%K%ホCVJ6a׷`!2 ӣ_Mh ~)JW3*UYJxvT]CwZW%ע(غ͛cBf ki[ӗnC9e=24  ;ӵɵLK5{,;[[2Ә﷪2k!dYŕZZ%읁Yۈw˖M. b<ə)͜B4&{+$UsξE7璭2Ut"q޳EBw1ݎSs8HMӕBj_w =^6wHDŽwh&O\NR2?^T mYĒm&@Nwºv\cs+_ x_mRxdgBIN"%QFHHS!)hu|)A?X(,$ͅ>@ -gvDZyPqy󯁴:9e8Ѽ{VxcнfKēb^k?sᴜM]hՎ {cz3s}꺞YTUS5D+ 6*ANj,tsߟ7:KV#o HqYE1rbPڃR<$ o?m_l*; -s=oR4GxcUعA(.#vU5tG|qX|2YکPP"! lG[ NMeixz|΋d0zdl"KT6ƈ&CWOJhhLJ`ǵt%q@{*anz'{¤Ѿi-)6/pX9{uXi1tʷV5bG[ iSE[H}j~l Y,#,6Qd8_$l#jc|gTCt.;˟.-*|oOd$tmUT7lBg;}У/n G$GZ4QCĢ0 ^"RܺwqSlkFfVny=+m1x.i=zDE3)ǯC, *6#y؎% Q5 ` `T(]]̑{8.Km-,y͑75ƾ *¸:coUe?$@<SlQAGuӢkJ90E !tr˪j 0>֠(P_rv:0D?YCڊ| oѿ3LG&ݺ[:3S)CxIB5K|䴠%TWq'QT*Aᚉi1*"EʴlVupMeDE$p(Y!,\օ9^u;_͚ĶHʁ%wB4 om)jr OC0)H|И(0e?J%bfG䥆.g$" Z<5A2C$6TGWm5 wyEw(иxQf޾q3[vl]x4V%DpuȟR';B]U& G]KĐxtE\&zv X15_FHRU扺EuWU9_gE%:U_r+Q+e_sP[[1aj[P㠖JJ$9H]6RqѬK%=Ako\#U$ү넄g$.^BBiY(߿u'JX?{.9r<s{[׫?~4!Ъr$s@a6-"+vDsw^FxhBVrW-GNP ߀agl> s :+ůvx<i۵k;5 {I]J\o i@(RP6+-C 3"*8F1)Nb:Ť`7hR 3V遘cX km4<$i vsD Y?DosǣH+ 6  2el̿\&S䁞t;16ā/TT>}bfY[*qr Rʨtϩ$Ep?^M3$wi{R3xY$א k}#Kaǫ5Fèv܈Ǝz92x1Ѣ$^p{(6 1ismwu/ zyޙC1[Ϡ@9`Sw|bu9i'@v }w(\qF>+A!yGȬv*ћ\dQ,>^w9AMVy;HSEПRMPߞ YZ