sssd-kcm-2.7.2-1.el8 >  A b2U]3nzna5R(bʌM= Tz]ϳqPbXP&,"6IHD>pvL_ƥW,̂2h%Bږ#GWܵsXJfhTٽS1[\My`*:؋B̫-rYO)씺SR)_v7CeO!GmN^qP=Ff&s()]#jc%sM.q&[e@q-;]U{6bp7 O+?FjG8"+܊gxX7F4A'f=CeJq1>E\#PaVDyT7͡['`??LWW5)uͿ m#Њ sAWDJ(ٺ􈷔`{m"˳ MC!O:-!y>pB?d   B 'DJRgx         a     Jd ;;7;(898:eF>}?~@~G~ H~L I~ X~Y~\~ ]~ ^ bdeflt u4 vhw8 xl y.X\bCsssd-kcm2.7.21.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.bǼyaarch64-01.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%6OzځAA큤A큤bǼ4bǼebǼebǼebǼ4bǼ4bǼ7bǼ'bǼ'bǼ'bǼ'bǼ/bǼ/acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd4790ffb8c8fe9654acf74fb6a2117b3468f59d1a37e8b6876752541e2a4a0ae6416b907006178d6e3434e555213cfa80ff804028ee216f4a90e3e0589294408213148df67e357d956638ead5c7d064c2c1da7efe20e9411b6b6cd4907e8dd54055066498c13119015d0c4f773017bc15c3d1b66c27c59556a42c08fc096dcbc30e9fc063fda29b78cadd67182200265fea1ef84e9a8cf710aa20f72958cbad96e80acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.2-1.el8.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(aarch-64)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)krb5-libsld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.7.2-1.el81.18.2-113.0.4-14.6.0-14.0-15.2-12.7.2-1.el84.14.3ba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.7.2-1.el82.7.2-1.el82.7.2-1.el8 kcm_default_ccache.build-idbe02580308dab2bbaf994cd02cd3b11fcfa19849sssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/be//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=be02580308dab2bbaf994cd02cd3b11fcfa19849, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix).R,R(R1RRRRRRR*R R R.RRRR RR0R&RRRRR+RRRRR R R"R!R R#R'R$R%RR-R)RR/RRR5utf-8a1e7ec4731c523671b79837160803c34c2419d69fcbef1957e59615f686d691e?7zXZ !#,] b2u Q{LT/~V'1;,Iŏ;Z*4ᮈE CbOe'Z\_+jDfq*BwT_KJ fO~k6_"Q7~GQ{\sR:{w;4.#b= Tt'l~{ѹAtC(&"+;, ~Ȕu]89]G|y}QŴ\v!VԉqֽdH{e0p\'!44ߌSlG63sl: HjaTĺH0}# .7n|l9&#/xO>^ stɑť{ i,ӌs tg'#Câ_C<܁wΨ`6fN`/k@cP346)}u ԙatүvfF?3BGI5/R8/jG9aQL?10Fs/[}rU)>t@7.$y!|wv P!;tԻ`I9Ў/,Fהz^~ #m~)eTm\9e.]#BƆO`3 l6QA8B%5ƸW:=!P1ݨ8c,+u"ɽ}GE0 iyql/:1^4lA^;N²v&m?gB5,bb`WW/wVh^#9^ otLRo@a{x&"vS/dSt]!U4錗/ 5X2Qߩy%ذOg^l 2U}pikx 8*!)Kkg\X`7DTW{FVSO߻#gP8/۠j#d&q]<XYjwSe$/`uHn7bP]&OJD"mгm1tO**K a/F2J=<ɄąEKS4hy冻Z.o瓙W0[\<}Bh-* *oXoQUkV$Z\X/hT͎s QQEHb= i&~~^@MP}BX־֔k$}-xPcQ$X2{2E[4Gtp^{J FgLY@urt(u5X\T$)^z8$آ I{}dm^ 1?C|݁!MI?9#yw4)KML8vm}c9'׽.UgJf`̊D6a #>ğn41Ď0_+aYpvvJ #!J<%sz"'\0-)@sֈIJ3^!SJ|:wp3BջM!SG;5dDy"*a}9bR,NhEY^Ǵz_RgP\2.(c]a0|5h_rQv9-g%Z7Cm8/lzzKFmKo51Qybzv!~ЏLj5F-h%.o[3:/'Ȁ8Ҹ(|H+|EOp/)"}@){%dWgH鴁| ܬX~ܱx۶zewxǂ"PCvYEJݵQڻ@;5ؔ}F`A%p*3}XpKhetl"ȓD^āC6`lkSyS Ň409J"-f`-Vj}o쏄WD>}RrB})2GΘ+0PJ[L"V6jJ~Wm . !n.ӂ.p'Dy'ݼ\KIDQoKbaAqX+ [6P\@ot9ͪ(^(ﮢ‖urNYgo۠Esokֶ+){ծ4k^OLhuEit҇/vp̼>> A+$?iR28CEI]n\0A6W-ND&@ bG",~}zړc >6(6;#*_X@|31loN竈T@if*ώG|tt74_c(kA ME͔yVcmת Y7Ճ? 8+)?6YI+ʽ:x&+8G'51MrֺuOئ$yDW!! _+[ Bh2tP䚽iſ+8ܹ Li2=c_e'וih^f|{!F*'C]A, \Oѫq4‰V as9Sa1w?趮@3dClNCRP^N?C8:9uM@47~US7=lu~Օ;E:,W_=nwJHzь~lؠ \)1C$2e䋐1y T<1:ZfDxS Lv 5[ 7f/Y=p%Bcd,&545%t1>w_΅훧4ZY~2+'Z, 5!Y&AkƀGyQzr LAEǭ> i"ؾ*Jk"A@C92H-tݳm7'䘅mzËEh@B8r'uțq=PwQ@ Za LC޸{𢀛ܚvq>۫_(^fz$5Re}lGޝ>?Q6rgH6S T%*0_9GXmƵJk[|`}O]颦nTf׮E_LȣQrUax 3湈<sq|p7N]ǃ}f,ъ$H4q~+AѿI{妿eJ"gA z+9_i|۸͡LHCnatddUG|Sl}i /YE`2G/KLqS<036t9MDAa$pfnXZQ[foepG5?]ko]Gi,lcGv9"qj"iz $҆tKB] Y=s056D:? V+?jiLBe#FoB)i0z[+êhB))0T;qY?BO.k^D 'KڈъG@v֜!I IjO`SVZ)4M:Ww&2 87\L(JT6m\* (;vr:9օMb z^Re=&%A#rI( w{Q]-ew؈,{55wVK ~`Sus Zx $[O//Ye ju 'vrvͅ섏70Ahxi6{hnӡt"|ub_ nY8fqO9j#,c2rtC_BuDi FniND-UDj EI|yA1KW帿i; ۪#)$ԓm@V{٬P|pUe,! CgSSu81%7Goz|u8YV!8`M&? mqfX1A7s)ARy3o4Z D8.o=N|Jr} ?r0HcUr \q yQi?2꩞[IY_[Z:YE 6,cN$1¡U{ FʝÏv^pr:x97.N ྗ qbcEi\9V[Q"ZF S[& l0L_v_{slWENa{t˵iRe pI|rQ$0PLE7k+Mf'yxV\AƝofn^͟ |n'.T4Q@8yf&i3U #‘g<IKhGse, \}HfEX9(T`f"NYY^qg9EK|x* ̞w\/qFDf,mvXO *BuG4}e7i(H1qɜ!*X#*Nhcf}~+Pػ8[%4sP,[*]yUaEz"SKs qYHFڂ33b*79教=fo{r5JSj h}aI!e[ &6f ݿlu|LMʢ GjMUAġ&;ũ[6Hg^X IyH9p8'I]j^|XDYz|-%+gmO D_!_9CO <|VV/a9N '܋QS̚DQ0U%dko@t^shmϚ_)E'_q?G(;_RY&CUz{2RmF1[57n2)V_ALW ">|E~*̆nYK:I\<!-+2KL%(rmd.n"@W"M땲~PS^g[$fEJ Z (0Wķ#r242yF^@qP8Vk#oFY$UD8")p]}g-4@(#_`ѢCi(n=${`dN :i N$E+TGIT2Np֭1 6$:ûHEoB˹Hh>z#歼kqV<dTIY$[`/ wixEXFI wύ2~{U'*izS> .e7p UHbկ;.(w4H(ض+}DLC lObu^DR]u ʬpOQӊ$%NS 7$ z`ᎦJ7bֈ z}iٲj,4TؒkDPo Sat%%K1P2 '!'Entv}ݍmq`=4)ov4Bߵi|9=;pgBF Ԑۡ+?+E>.駔X[)P^S8VOYzyJΐK: e fxtXNJ:X= vU+s?B#6ڝRxkÇF|[jyj _[ HpcvT]edr&}?[a-ދ`\ Sַ~kH$.I_rUj -sd'&$~E|njW".h_a@Z]q4ϵ$J9i%}o^^GNf8yZΌj#Xsn@sSn~/pCŕmԘ.׺i4FQX.{5 3}j6.^k43h~$C~/bb-E-~ŸSC=&+hD}\mq\y/ iR0"%Yc<7Jjא-5.ȧx 3p=PtP{jv6;hvYFoNrGKd9>M)~m+^3ĖLX9uTJ9EkyhfA|ުAYvȘ.H5&A}m("zִِaϘb;u 5]~OHؙW\a$ A*0 l®+EŁ  77c!@<5ﺙnPyR! o0WX,8s.gPp}Ǽ&d](;Yi8e\=!h:]u9%lXd?KYJ\"Ǖ^0`ʙeaN>>X-ْo|"CB10bX4e_W l~Ьv;mL 0*vJ>d8WqREַDj-Nn_&dZ`ftuAdvrB"jSB|dƸ)/)fI|Oj=缢>!n*6僯rT 1e蕍v@F5蔞@cW b17f̼}Gr ;regrǵD/oՏ*ѴW%#9B&aOY6y7fg#\REF}nl堤MS-|<(nz@"b>?fq93Ecٹ0ﻵa "aZߌآ$>hr+wzXEwBWazM>LcdwB{hY^6ih;v"Ӧ$vETp˽͔u QJihZO8=;}M[)kgfWt۝ui-$A4؁o5YK94e Ta7=RHGzp1*Pd.j2 2õ_!h2` 77'0ȃ^b׃5eA\+\y ,Dʴg}p< |ֆ2h KW(J. x+cr\bc`вf릛YSbϯUZO%)o%,P8 -;ڸG`W>4!]I'ecI0eP<|ښg] Gk)&N{X/eO;Vfh#Vߥxl내#3,M=^ At܁W!wBǾ(>p%)aa)@JL>D.Tꀼ%G`,RU7Ytv-olS^V#C-%y:6?TƽU'Njy8݄]g*[HP%|R 灍࿬qφ,ӨXZf8Ш%K,OaހDBS黛;"g[e:GAv4(z=%iy/W.s &\ﶴvK~:6#MmDyvg9uH wi"<{ƔԴLJҧt>쪆M|1$ ָw i˜d>"ף¼X"Cs,dmE6e6{z1@J`Utʤ+i)V21uPR)r9Q?SIdejv*oưӨRi!'Un uS6"/:er] E#lCC6|%E`5;e?eR=d& M rť^Ӿ/'׵A`#GX܎US1T*{'Le44[m) EgГ8v j6֕IWHA bAn})JJʆ*nek;zvkb@?6#<QݢCϬᾋm Du7YQw8#~XX=%UuUӨvyثEOײ -|& `*ˀ9.)6XZdučfCF3uop;tqBaxfNr1_ {dwBV. iusF֧9Hr& bHq3K47HȎ8H0l͎:/a/Rnn&Lhbd$ 6q@T=dCP״+BzǸt!3 >6 3tP-7 ugQh aU*;8rtx}oHJ1_x鹪aePhd,}Z-`&K*Sw$\7$_ֽwКx7s[}l]Bx!Ddڣ"]4e1-FD%k%Xj82UlK=En&.u/87t3Ϧ!,(lJ/嵒Ri XRr_<|an *v 2⯱ް#u^ŭ~Tv̦M/ x>߷lQY#o]YKgR<W:g,'j_Tb ;ʎp~2Vڎ@~dYǽl`9)(@Gj?'uRt6\vT[Pw}Yp<[PSݞ1kvy(+Y W<(s|?C8>lO< \R+5(C! *S+5zhH5T hdN>1}&r;bx ۽> Δ&U^s!*IXC ? <_Al όBu{725B:2tߋ)ޞnf 6e.r8\&cňHJJ \5U;.m_T;i> /x08(l (wR|Ujĕm_- U(ߊfvGߑʹ{iUGN[|R:nK3{ѐ j,BŰ0H<]\#!{)FnͿZ9/>7S;)u n`Sk\Ml}v4/ZγɉVے@.UY:X[̚$//H}X~pNNe.>8wT̀mQf ͈3D_)>uiCߩ)<`t hA@ad vY\1CMDBտӋnœ#ho%O|0׫]m?IƬ8DLs{o'Wd;*8W91""D3j &>kHku SW- row~6އ2!ad\%*Ґ48f,;AiD4PYxbwx[ 4e/+ HH+>#,g4p _*J71`8q̛W.vkv9Λd^q^9oLqa{Ӝ_ Soe8 6=$cD7EZ\$o?{ه!bBݖDn-Mj4{̆\ \Ku7)O >Dv%uøe]Z6Sy;]G!\^'ϓg;Agv"fOMglY9@aNB5%3tJ bނJn\G/A V%kYK2 f+mg=$P.Y`VZZ,pFys訢(R{b"q\N{F=Cn+fNʊy cY ay ? g^f= PTt'q l>^K i\ 0O:)\yUj 54 ZP}'H^>kZCŷf&8=Ź Fܿ]iBr[e Ӫ ;H"2"6~2Q.-4fV?Ɯ[G\q#v.zW^cKU=Oo0ﲱ2^Y~cQ(eS҈,ީӷ[bAmȥmcj*Ar#Gu ʪT?`BN`iI "İ59zΙ0wX s0ns9W#=1)cǡM%=eF'C>bG"&^SlsbAX v):W%)(o!щĐ|吢&&Њki>2to+ޑsSF 8 n6.![6c<OHS9;F y &6:l>rĹݩ&v rH?͛\ctw"%Ěux͂S*OO~ǁR s|{ubf^rh-JBBn:F-V-0jpjsί^Ȼٵ=h/J>*'S›ERV9:,<;klભE r]_v䟠սDiOAp'vץ:=uM v7 _zs|cu= ^)LY,KhNwV>q:ܬhŢtSW.NOfi{X=tR1a\'~HW] -|Q,\lm3B&RvjC*E*Ґtu)k5%Ջ&[50 JR^ Ӭ:sJ?8h$;bR [<DZBnrpX v$-CSuZJBLJ*\2lw36=vwʃ.X8 Nwz}VCZz29r'RH@|:'ysxI)cr"x m)0e𝺥ƙ]H lơncKp\}7:,|Oadoӄܦ8iM)!N&P_?hU{W$QHz \r) ( @:L(<2D7)EzΎj},$~d%VKR+ iHbir?y⏲Mg8+3m &$2nȼtk>i=MF6|%lߖ2Yv .Qcg./ASoMA mdMxsu0އѣN"|8G[^)۟Ǚ=I-+e32.myzF*7"KZ:i^)WLG|\i4\a}/DaA^鳼"䄕>?Z#O7ǖ܂چv }Ȼ[l1& g.Ik-M+&wl.P`]"Ej"ti]beLxv 5aX/ u>77/s}@"TO8#3ئM}guj&"΀>2gyTl^!]39wZgN<\QCe0I#MFݻXnI'aW{IxRwVi>{G*bI=߱4}sܩŁL]cAQ{KF*)1 ▨#)^-#71·^kzuǀ:IpUf)F;DM\+4FQz6!o@"c=9#R{)Hd()rxdžҞ7yH:/Vp=4 o{vJv8A~@>QU0L͝q6 yW  [7|z9u^fg.U݋<8"ީ@Ԃ.jx=jGsl#6:.5)4RnDfV6DJ+TRK8QmACPvN CI`l#JG 4p %&s@gC@@Xt?n+ZVY_|>zP 1+KO\'K? fK0rB+&vf/h`fe"$_dѫ 'SeY諧b%R\O]ZlOLAT}[%c?{wu$fϘ$lkx+kjb(hH_Uφʘf탧/9[ՏzM<6`؛xEЊgEڬ&G$:rTfʡ头rZц&e(v,wmiZ5k̛ihx|-wk/~oX9YqI`=cqcJ=Mj5 2q ҙ|LMZ' dܐ>{P̆*u5Pojݓ|9QcUऌ}XOb0lz eG4r|{]Y]S[+-a"A2UƮ+YNY\؏*|NmHXgǠH> yr'nb +b3i!je_}4 sup|ۦ^=isbLV6ҏ\I{EwY-/ni~&5nx'$æ|c5s'-Pv5e^QhS&7 KX#= ?4QjAb~.Pȟ:P#C!Ng$o^\RrOD)-ыY;jspee7VsKL|nG@);[zdG6rAkAŅBm%Y! m)+Qph>G^z0j۞bGB7х<ٓ^Zab ;~T+<$9"5< L$HѕIsMbWv" _u)RY bJj6kti!KQU )i:]SƐʢ~i ^m[??9] i-!5=5U'dqåapN6k8Lqhb a.cNJzBIjQc%)cN^C2t)H@<[,Y}- yC,?9T`nT%A…M(kMw R uf!#:',ccq#oSZ #\^Z0J}llWlL HbIC''vȑC(~EvH.Tnulj!KUwo;OcU=nʯ2/96WۗXA㮑}?^~Q=S >_UMa<,2}ބ`0f([aJ^fg1٘ bHIʇƔ$w̡z |Ҁ3~ Lcz4~ |¸6&rُ zώ &&m?-KZɛwE\?}F/;2A5uLfMx=90G鵬kRhnI;9~m8MϿF͆#辯\QudyS[`(aNF3UZg]9%nDLd@(z@$ )AhCV`ĈfLu<دL|=xꁮh}d?{x7(KR;_7Ju}Z],~ƅ~ O[%.!yG~(VQ/Rkv8BazI03Ah% nH,`'|H !.2jn&E{eAi"xvn9}-E BҤfxvCËDJ۶ n qxۖqHp3{\S8zXne 88sB(o$xd)gI&FhU)S~,t3xOl}9p7MNx;:Vr5JlZ +:EQ*h]2ؚUEQN[; }r-osONCOPt?t&"5cO|,n[wPoy}k3ypL%WLEX1^NMQ*:%׆x<Ƒ@#1jf7-t܇Oӱ'үOrxU^(猪KA5_%xa$;Fo7OT`+ziWC&ٳu $3xav|X)*WE9-̶|8p<ٽ X~ܼDƒTa-?Xr֔}ᖑI`S y ڦQEG<=ʬb2Mأ\OΆ qߺ [ޯ=H۽[rɣ\My CʧnsFa<)@y"~[k@)x$o "+ȏW {aẫnO(kPpFV 8|g7fn`S3aWmgi榊o2FA\|X? n: ZivGbJe/ƒFH騥)HmiE =R˭Uڥ . ~(4P华J)6 ;M#Erdu#{$y#G%o^ERX փgm"#q ?vh% #%u7FVD4~b@Jy}͝,VoQniS7ۏyoB̈́8횭9pJƗuxlnڢc-LV sNNbfGRTd.<E@J Go.eG>76/R9Fmo.t-恨qJ 6?<93Lj?aHA3_ ]OdIvWrloM>Xn.yd-(qaB[$[V8X6)1mKXrT^ÆnX*~ U7UP0LVA7s^q*]1fCLY2(lCO@ϒw~11%Fz†Q;jAK`-v!r]:d|9>ZXBȴBu1ImӐY$Cyvo\Ԝ 9@k 'XgJYڊzeBN )``!mϬ %6G ;VO8uP [(3xݧl ٣Fds_ii'wN$\.ݏ(Z>}gCc5xêZf8TĄ견p0Զ0p3؛ݡA(Gƨٝr`)U?:G=4౴=o."EH)]^n8rc?mA/-ԧD^[ |dtF1+-mvk:a b&+@ 앏K%?OQ} lkiD .%DxFSͩPSy]K4l5w_̯rD ܞ(A~lI}i$|e+ߒAMgƺm+xu*a H2 OQ"܀U#xDj!:%]c/̮h]h3Zx2&#S0L2y{Ն/]:Hôɼ`Qw45B<ᢡXUm$8jE-ama?IuLSUO)Ot9)e:?p^bⶤ7*RȻZj?Y}p=5JٗFƝurKޛ&S/ 2\::h*U~{6G}ec $bO͞rOذ>XE@E5@.|ufa=l ϣ N[YJVϸHޔVeۮpwPwo}`0PuJb Vr3EganF<{j uܱu,ԅdF wLw ĻVd'ǖ*Mv3"sA7ۓ֑#h>ᴼF8&:EHa=?N!T&o̞C*̄3ZF=i+Hyi>%2 R6wv^B06 tPQ]{tzg\*Uڎ& t@{?qR}6'$;%o[s2F" H*i@^5 kox?05>x %쇇?-JnΤ8ZSTCfV5=dQVq㮿*3d[䛰 U'Lh2` ;-B9L<*JuS`~&RPڜ oENhSyr~l½8Whb!,a[d' Cj@@ >5Ca+W?*E Jc|S`6jsw5*=R h;NV S)z츇イUL c#J n;j$f ^9](ZEDg-v7D9qHgNJ؅Q .dQ?S7/R+mxN`ј|" [S+{6-PH i:4 'uQv*fwMEeVjD,F]^ T'vjsw E7 8dI.)L]+ԛV]RȐpZ j8!d!r 5sǮ[$%{<+cm|CYwr:y"IPd_~_Q45~ YX,W0c-HYѳT,gr%tǹ/1I\WBTǫWi@Ŝ=?AfӋ #;ǩ4bfG%ûzZf,YڪSU1t m 6Ŕu0?uƠH>{DUGja9VrqZ[UZp<YUw~cyGO0h݃c[_oKz]5n;ṛjjW%Bz[[E,M>q1ǂ40*Z-iőr_o01rʍ`Z9ݘ $tW|v7*|NԞW^9^H0S6L.0|8"Aq5.:J}7-:as1"m-w/`zf^RgXXMHȗ89gb? x)`#+px@7朤/kf䔱 -twf5I-_:plMjLC{hxΡ6{myڢwj( Jl>d@|'IB*rɗE.fXIk dR5GІ a/1}9:ۗVV` jS~su_b3n뫈! 8[e`RbK2FIU(RԼ9@c=L/.ݜ k%KΕКNȼ"|l1-1ATшǒ5v!^ S2'nJ(\-o_n'6`W禛7(B>qV,`J1XIPwRk*QMj,c0{%N>*e9;u EM-cw+Sp`@Z'VxM "y2&ۦ!FzЁQmҨ.-js怄ęX$i>0aK]!)6T`͝nB3mÂC(v0w ޥMM8*x:`r)'.B[XJPA+ZL3eB ޿\?NuOWĞnr$BsGd&FmP7 osl-eRH -z!M!ɀP69a=Jj8v1F-;%ps]9R=ѕ #^F3U|n3bbƕ=4!&A-2׺=~AezcWɅ S3#MRcC 4 $q$!m f~15͔@XpFT SH2T$KL70^ ŪB\I,\Rj8$8_t6.!2 q҈c؈M)#v M]؅js.\4 ȟg-A-wQ&b# e up0$p0 %ne2zD &-EJħ~DP3p F# Y9&w4I %j38ڜqr$o´&}&-o}c:4^=xu/W:iV)WFY6eDZs XH_ Dݿiu(tJfgYQfP}²!_,Ԓ**bv z ]WB(Esl%D,jY0{T\Mܲm7ed­okpjeK<*d&MH%``|P~^l84>6)}[ےHhqnF %#"[Zɒsr-' /4TC;gqbm0`i}Jq3 R6 /\9@H4GjFԆDJ$^yU& &1WCêM4C׏{O|-?=G[>OJ#pHQk#.űwe ODh#c6Ќ-\{97 b $|m.=4ħ #I(/xd3#CH=u3@g q.@@wDjŅTlY,[RNPi:WdS{:LsO+6s l,"%NtZ/lGO&b%J@}\"M8cB3ڊHrp\=!˗e =숌 %,ޒ}ff#-TɪjIRI¢6a2&e@;^쀭&>`Wp/u:+OO tCG& 9=ԨA_Zn06w>7)$5 8Go\kLGw,[qvdL6CX OUjתn:K:&VwE>2-Exv%U.ˮ$] w K-M|-u8: K`tX̫ͨ]yX>ƒ l=Z/g%Zy^12XNEGs)CJ  b3Y;WCWu2yh'lw42DNnPD@Ո'Uz7}~&*=y4ɡ\ ARªGԏ!U2\ 7z,,4?'-pJ+e}h;>lIM3WaCA>C6Q8)L:ZU}Z;?W<,Ӹ]vj |.!4{ldd;l4FZY -Dsj]ѓ,p$Pn" bJ'C5/W5S_5 H9 cx@4Tܐ(Y+dP;sA.P!5<޿0G+V uDKrPyēc"%DSL2=v{ڏfo+K췌)45㸣ƂQڇR}S}w7(YjΣ5"糅 Yu4]#`:V&LJ̨}5.J' 62]r }#J*]яH3t6byJ%|""n0{x !f õs:¼{\<:9o/151uc@{OArboܶwk&efxa Ʒ25My$җB\}+/ DC4i{Z!kr@v-_B; qX)wRLPM9agaMn!7zQ%WaόxzM2 PSJZ<_b4`d0;Y#}U(pÍޠge]O`t4*GXu.q-*-tO8qx(@M`~@+W]9R!c*=JxY)N \L63ؽ0u\+ͷl !5+uΑJNT@(P:5{9bR ,xP.Qo +oB> R`6&屲Rޡq)5C[ZρH^dئIxƫ9hrWZSK!Yg%)>|Nq'2}=}e tpVɹR"U"&,J8m`֋hyϰP -*}UKEn3B~}:WZI9у JT2i¥J)[T5{813nmNֹX.x:~!fk-R_/I`}Y0gB1?#ZGw[ \=&=gAI.T Hv6Q&)r2€+qb~q4}SThԡx_-fDDcFfjhSvOS*-fˍ:dR:f_ #∖C) q뮶9ڄje +pD8Mx$.$ʾW=̈vB@~fkFl0}S9P?H;z6^YZӤnMxqA9N݊Pzy,OOmbtB/MQ-BƚFat4csrX"Z2QP}NrgפMI L-@ȝ@*F %l)JW1 'eSչG&1}۸Y8:eQ԰J<2lp 6ܰ|b0ITD&2;ZAݽ^}mS9Ս/&y*ZD4(1k+m2ҢI;.ư&zC0s /hÀ/)>y%Ps8h O=Z\_A"GZA6.œ"j^_>:^6f/C ~9cXy W6ҽR{h|N5Zu"[NiaL.KQm4,繧5IO%g|W=02*=9/r]%vAJwEpuV  sB!Y@t;`m|d |#9S:B@'Rڹ:Fnq Pw뙔Lw7~sh\З.*$,#$?V [['W* 㑩g-ju/F ',42kEק%=_|[;C}klG3? xt%/Dwe!eBu!ޯĴG7,d춙Ey0"S@xFV`b>|ۦ00Sloj7婙"&U'*c exEK5XM7LNATP[ȼyc!w3ᖁM a+w/gsUs#]ԟʆ6 =OwvƇ+V@YVsg)=aC3N!dQj:%O*OYSd}f:k|]u߇d:%=X?6ϯCmS8QN#)T#f6]Kxl!Uoj "\z0^r-lrm*n0{:)fR7@:5`+/Q@ X vd9vn~2D.D_L]]~(xປ)'hiz]szC#TU 1=gF w#(5:=/!oOc4nBy_ɲE'PJ5w\P-I,w;܏s@;Xv 6BJh!^}= ۹->?D9gsiFwVd' UT"!6UGcZ!l&'Kdg?{طn*f~f%)nvg;T5TVɊa ?6_9c$YIdLrs9OǓs(RY~6Q4L]3׏ 1>$"(gd5,!E<׿z;!_nXrfB>*AYpOY딽L3j~6o=~_%8!mOeLE΂AMg;4~x^z%%nh@o##%je# CO%'XGb2#Ax=Ӟ94v|_"g:?0>4+:%cxUix E2 "6,<Ŗ, ]~Zezq50@gb^YJez6ҼT~v1"ӊf3,P=@+j%.7p쐹[c[!\;8 Pr}n{{@ۤKLE&$t"<fzW2TF (%9ШN4@H1r-yݵ\g1k.qy:\Γ̑27ևɄWpcSB! \mfIh?gkOmx 1B+ƣ2̨"bT22? "9(^!(qz_#ee}&/y g?ӛ܎t￝cRdy;_ z?24FEN~?V|ۋz5-qɔI>ASG])ibnse+\ݟ >t@D᳼2`"E ')e!RŖ{3nط];ꁜաڪ$4Vn.RP4w 1nM)UяNjM{SJZ^G_@7DŻqrWjc5аxVv@=۟O11K|Z_uգ_ FTC1dKb?m \z7~ir7?'DnMfH,i"KqqłZvjoY|@NFP(ZR7F ֔ANì=/2_CFBwaA`Ց?y)_W5|9.?\\d/H/$CiBfS].!!8C) aB.Tݢ^KE"Igۚl'Bw䳐ym*xfNO#0[UEa S CϪYW6j5dZ%naF !]1li_(¿M&.&ww[mǴO;H;4\~EedsLpye=6}1bc}Sz7, +VY}ZS2̀"0KӿBopbaGT{jp M$mLc&+7Cx^$,\Q$%o&X׳5MKP_mư3^> ٕ` JeR*2١Ռ&bA!ruk ajBsa1 1\0@coXhC%lg{^=݂?qS 4ģ.o{Olnaܑc?v*{òC(YsUd8O} 75!XIZ#lmmWUU{ov5ᓒqrV6Z,Epi_R¨Z_mN5|==6Bhh"1IҌ}׳7-#@~/ԾgM ATƮLv _y̤NA3ul7F; `` jNbzxF,*$iXPcS3NmnoS7Hz?shϭrOwUHbdea= YZ[L YnZJ9`uݸ?/u1%(! 9Z6}>awvڑ884@02 #3"${˝+cI!Uႁ U#aً6AQdI4h|0_+ ҍ|pTU =ImGis۴CXhP2EE}ԮXqY]mg2IzڧU:=JW.E")k9㷔twj;t2;+B`7_+9+ i꫕PR8|\NZYCJ-or<5z][Ɨ`ܾWNΙcͅZ;|d;Snj|9f Z?Ž8qWСm% L=C47 BؤGJj( t@v/D{t空 *}b.="C2@3}G+a\ONZЃ 1ԅ  veS0?p άÛ(goe% Ylߒ_O8AL">~,,Ξ` T]k v_ufo*OD= õJ| ;a6<}b5h}Q~yf yIj0$=-ۅ.iH!áێ^S"4a }ǸƟ'@!u8y2*,NбRSMS8TnO*:$;W.@$P;cRP`i2Ў&mASz7OדYvVShň)v,u ~6-{۽G Pl!>d0IwiMO8b}a\iF&S`4ӡ.`xVgQ`\X$8M<-AˇfmnnlD\ e~iQ{c< FUŶ?,.;ѷs$a57RjlcCoz7ŀrMgyIOWI3-?}r[@ϕ;ծ*\z1 чwAAnت(}yKNnz[W['ß"rպ E+ӌrn{jه](7*Ro2#a9U}j0P0~esnH)ΨLOWG Hm?Qmq!W׊"h|Ta`,(U4ܵ@Jn04yd[12<5;.M2vOr Ϙ%S h0wK5 (?%M:EɔJ? k[}ۡo-^ O1g/wŪ|Q^ǃ\StrN~uu1avq66FbFl|CaVUDji$/Q-@BǏ)f7?56뤚&:QS!4l$ӢДe(iq‹2L@hX3ڲ;9c 147 a!%XAMyJ&5Yi{̽ӗVۺb>ٷ_{!cWQ(;Q*zN(regf^6fK{p; [=ʟɛ fV$M>KkNℛxנEmp͈OAL( =\~>ݐlB%R#l8dZ*:MY*z[OpRm$}om_/Et7gk `,x/\Qi^~E^e(%]'D/(g.#”7L 1sAM͇cZ宓2AIpدѵ\'sUTo؇TٲL8˘z=M_<DŽeJc TyJԃ7L0<$-BJs-zb^ qJ,W.J,VR{_Y;U7TnH,NVDÕV hךMI}MRăa1I͚]j:>6phpW a:QfU 6BAyXVc$FxDzS2aΉ0\oxF lgw$Ȼxo.YP5aJD"L =XCu^4]?|#O秀ͯoV5%{!{+_7B7v_Ħ%q9S(YHnoتzIFJB ?u#7^rQao5dV*mā~Ǘp2\Ylc=s$&)! ۧ **; SQCќ\{aʦcb E݋]R51*59ONyy  "7[_Ʋd+ŲN-=tZ,Fa1m#myYy6GT?ϟ"nHM hbt=RIAPf WXn >\ ,ROLa!+:k#m{DtE6;5yAL&G&ܭW_CzauRJ[^ ./uU]}uзI OH ;V*v=DPӾk{@:Sֺsq'DE[mXl~zҥ+֪͓t;UU؜8!ǜ"ɯ6'^bcj3ߎ@!M4/r2ϓ{cO;4^mv" PaЯ#DIFv]cU\[D\G՞'2_!)q* KuJU'r'PLoMC=@~ AQ+R% olDf؆EYn;Gv[:pgE*95Ft-Rs%iZ8 ׺UڍA/,3!(jj+ Q׵U\D1zoNWN̐ĩUHqYjCmo\]ЊR/*.p{)3rKT ehæmqP\C|>1j-#>r%aՇ/xd DS#z*c'Ca,D D-VbͲL`SL_tp\K_I[BEPȎbNOTESfo qH0>g8qTVعps|^`iPYYaTy7'{:<1Uͨ,iۧ"O[gP3#n8eG2v~N}3V,^7BЛۢNqtW(XVs>}xt-%ͳH`=Z53DH=]L[-u:o RuR[٧8 $V>YԨzDŽ~l(O >B,4T2ne>d3,/#1lD|-?IL fte}E%՝RHAG.JJ^Go)_"M7\[@Lt\pm|H{n),/@59|GoϋAiJvLSHx!hMkhW{i]4bXTz6Ch jV YB|fn)T ȳI؄NL[9%m .Į4XTQJO pvqc:H.[h L^/&ߚU CLKF- n}y`{ږzw2yΖ\1$Rry*Z[b* ܼ̔Loi7"tTB f^ߞX06WD-VEG"= H,;7 p&6ɊT SECwa!ڃ TU9cֻ,F9hQ*sl#k2@@Elx,.,hR92>BsZ?\ \SP*8.[Ry/Se&i~+O< 2m5 yl]XW@t34mLU[ˈ9!4Y7L7v?u ϡ6~u# (trJF%,T鵌ȇwErY JLA_Q u<2H>ns1ESr}nl0vn=1m`(֘c;6}nޖ'$:v> |fbJwe=p$+8tÇݤ栜;etd(W!PM,CyGCʹYp#0M,ŋE99DPqݧ7H?@'0֙ZW7ZQyžd9 >JV"Rq86@ɋWCy;Vg7{FV{7*R qsR[ <[O}$PShJ\0G!mBLK+v$T?z[6'}|}EB w`%p-ڗV[%=*߽_aezÎ,OH|PVzx˓?΋;|sz@;m3N>xSDٜ@8-#bt+ko~lMsrQ2ol?G58^/9{u<^rH=qp03578A-G?n"==L#GE7-XKP=/~Kܣ tY s?rՆ4۾>^2-}pPlEzp&el3vD3U=KR@M1>,7E'aXDNryUHm>G@=:sФ 9J<%ȉ_P|a Aky߇91- g15"syՋ}=o(D:dn/ )paWz{9 ػX˼6p_R{LGVbuL|"yi0{yԽ .U^Mkxڟhz~Q2ն*@5t3u^v&F׎ҔL#Qҟ\x%WΙ1L]ꑴQ|N r&`޸iwu4f$ZT5##^< Tvu4:xTl|Uu2 ͻ(ZmV u\}sG`ƺSWO OZĉI:yɱ^o% <9 s^U""7[5R]SR:X7+94E1h;rB#5r?fẓ Ui 9("9#lx`QDO2(V*x8%- Pnw0UKД>G6ɳ^"Xxԩ]n4>0JħJJ3fQд}PR舊UeǪ3/` 5诨u-]}z)C57`Il(sstߒ9d _-& yﰣ,.7B\^.F"'FV_Xʕ.G;_?:{%>+psr{m2>ӲPs^8^_ ]<5p2gA/pAt #<"jN<+d(vff8ؚ4AiTb :oY:gYن mS<jPLY~YX`;PōxXlV~''0CE8Đ̙XQD^2xuhlFHIJe*y5r[SL;|MA(="^ ⊄ATev;YP)ق@5VK* sYEtJe]w~WIs PB4Vw?65\rnlQ뵇hh6$4gy:Ol hq+"x5X,Iyt,&{o  8ȶ&Gh\] L<^uIU}5 ]<<=E~=IΓ:-5^+dʽ`88;JǗ=$8,G 9C]6],Ǣ/6kE@.A3e\it)O"Xѷ9Sn{,c+Ψ\5= a8_:j$1lKj T5Űe|%Dđk#Ax4EUk&- +iÞC<dX \P4Е'p^;WgmU!a^jO^PL2I[`4X춏椴/v 2 Kz27":XQS 2yӰK.JUq ^/g~6mŲd%`qBhHqSEaΝQ! ݯ4ǽ{N>Jʑ>4D?XL z5R=15ܯ"83%20ĀDgbZ_D]sӯsF Dw [2+ wYj&\\\ W{U{/y@ ӣp@q~=, G0}לBd,mM͖Y 1eɱj jb>ԉ06XG/Gn]cWeQn ZN_'DƤQV]V2ҬZߩz]0mlusU8`p'Aɂ7êL"+W$ssy)z]7+j QHH,.T wfzvN%Wkdfzp'@r! k]Z-տ.;$N:ai.Ln%C"j@PjuZI6*jxc% G,lS## q[ 6ɗ.<`:N oRKF AaK08 8.nA4n?b \Y%luLMڶHi4?gH:1SژrŲ2;Ktz /&-n#]\Toeij.:*bŞ)̦j F`'])S0]꫕ߛ1p4:{M7T8Dz x>D,G{"g¹ҿ(^v)XHTۅxS$Dgڢ$>`> =!g0wƚI~Ѯ<@t~}Eq}Qo%h:lcc" nupbUµW ^|x$ NwMM8(cu-nѹ-BB(go[R,H8 `}PJ+=K@.A R sOikr.9J YsM DJ¨'*6pSZ˷:fmu^A7-T $ejLjL,8#RAc1r?zURN]x."!vq"7g&T}47G|w2 ;z[yQ ڮ8ج_n6V͋N˗j`o!34{uR_+ywE`/>,H!v>E 32Y~I!.1)ÿ0#QH9{yPU%ʇE'(nc0W18L gW+ '4,2jw h_8 h轴PDKZ,I~JL5/&ֶ}E{Ù=ts-TMtMg"_)e"౵xWwjd`!nkdRqWb,hG>O8E 9雓M݆@蒆{|'b$"9Ɏ9н9C{dLhW~Hln4ȝ,m˜4 Ѝ36({$m)3,:CnpfջA-RGGdH^68ei pJ:5X NGK c%d7Kon6E/dCbЙ4x"?ZͲ;irdpZ%R0𜪖ovG/8(1*f4T?Zv!`7?25+lYAk'*,p6Cqu4a }ބ9vhnjÞA%6XsKAA_vR%d}+)"[\s]tp1R# ySsN6huwPgtT*LH* l4ʏ"[=EvjXbWydn [4APUxH< fjfAMeG6y kP>AA(X!4(ɋ3: C9ZQ!v-=m3GD$t&Kp WZS釱L~A`I_f#(I6}%&??w"^2;7m*״ F𽔡jZ8~ R ^A|ϕtYt."J@NGp˾'U( ӒѮ2c2<[ξ+b^alR:zͰ!CRU9Iqc3%A* E ~f yfh? U׉Zyp,iI~(aYB[faVB1US+4mqH&;7&mY&\cW9&\  kH{ʉ-L?*x"o<)δ-[zd(RXC,}kcJGx={G@8LЩvL $".tMGɯUBHX'Tc ]i'j6lX%S &Rt$9%҄(zJ/5s MVc ]3ⷾ q4g|IQ&:b`%J(d{2(4Oqls$yIìZ]MquS3N!_NpjDۍmdb?Q iGakXOÀ.\UK_J=CͬHJժnFy5PoVzLnhFbs_Y尩B} G_NH!*>5)Z͞?&<h-/8oe2]FHmJd;+R`k sp kx9ǣwd Kvˌ#Gy[ "$.- >VpZ%!@|LE/M 뉒bo =}> +j7 uOq5C֝4aK,妵w?[@O5Gk"|B?IcoH}^gn B6 e>d hI!ŭg{wr{j{%\fJk̶_k~kf~EwӇ4`R{坥eP]{*R` `%|g'n+y\=ʐkĿbq6UҩZZ775W*^5 vtm]ҷb^kf4 &A|'Q#P\!g 0esX¥?SwI=I;pu8:ȁ'.D)SPeIΛ;fѯ:{:ʅVlLSTyJRqȊ]CIᯛ?#Q91E#WUmab4]υ+g WTWQE1iyC3"*Htshq2tpUb3Ͽh&ބ fvfM-x"M?K.9i:%F z۬KrTSaaGd=׫nT,Qо &B)ȪC?d٩ <=uNz[De̋"-1G(~oׇpSwSb]ܝ\Fa S+lY |J ;>VVߥ o\q@( fJzm5ARolQRMN1.sSK}[ YLMM1yupw?κr1uGs^[4Tp*ld8!V0𠗾EE<蘳NM=lK7Akp.;TP}tINFW?ڪ^'Jt?xWJ LAz[VN.̋r&dap>+cZ'YΉƭ+Aa-ӛbvoRs( HaTc@V'raTAɷo;Ndicו{l 8j _Z^#60b ^5sv ]L&^P v*K M)l ׮ڣ`iAY{3*| Z,vil4@" |9'^WRv~QEnR8_G˵fX̖C[nNd[4Z^^|lȓ2.:~͊ӷ*fEpO\\_khn!eATwO%@ԐȚ`>ӄjs8ܲ [{Z^de6 0SlͥІpO6マ +]fbx$//G7tT wCv׈p[qWq9Orƿ CUVv(ǥlpz9m^\[/ՃCqC,-n`/ @ֺ;7:# {"xmod).)}/"@h54nrH-5$~f@\MOlkWF'29>8zeHob8=UOF.sxHyo-KJ/bЂ- Uafm|Du7@FK\C >~F}`ِI3 Y>O)Ȑ5DACKGsg]\,d X\DGEe`""VOgܹpO`4j0T V)oƸ;x'yE2JAsØ?*n 1q- 6ɛzaMsl1_e.)W>5> mΒ|n? e*%v ImWV`gG|Uuj>vœ!݄ӿjI5ͻQckV[3_>H8WVv%&\zQ{/~M+@Db0ss<54?+E#%mX~:*BRRts,V"م3FP.]K#6[f_)h[@}忹5=jhj`ւ,r!*]:RݫT+zX>ɚ}l7MxmT )-DХ !uLywcLq;\i?カCuO`ݒuibnHyj졂Q<{c7C%h1`:"W՘)j{̝]lUcT_'iP2p\n8,Rdb$ a%}!7&He*Sb/B(gXAŨƍ8i:2xA^a5W+ F ]sp7K #C3m,:JHsM:r7y*U?Hg森vw;LyxkhP5_7_k飓ƐH" /b6[,+P+Ԧ Ԭ樼y a]W(VT9vl.)Y|J@z4$hlTzLRlnzc23f5r^_ Sf i?hD|S"&ˠdiNѭBh> i p>R d0+RQ e@CJcdlY%cPȷ9t\M&['rcݏC*{bl6 xlM{Oy< %rknHd(jQwя]qd>ξ洧zU3  Cs0WjUWSxm-'vU¶QQu2d DB4EdOm>Fgzt-Ym>,Ȥp}, . .vq.AL[>TĽj cQ :gЭœ|Mk9Ős.y#s4;=J6x5=rEe99$B\xgcƑ^7.#dzQA"$oR  iV~ O ޓg1NI +YCub=_[-6$/KJd9m( 4 g;v1u?qLW'P*6}^A-(Pn5 6u#E' it1Q&qT%u5y4b.7K&O̅ok| Q+VW ο|Q r1 Aa0*ĔE2"ɽL`Rԅ_β [0AHy-WJsAv0ī`@'Ag *>8^H&+o_pxâ<%vy9zidĻS|Ks&,09N_/Xu8&IuP C&=)B.mV.X ěWbZ1*D?bjyXJߓU}0X/ޮ먈$#<6*'3o(+ `#`=ը gBcsб h+vzi*ح\T4E/ߒwKma &=bR KKT3-I3˭}rW1us3p;Vc~J!SR>[we~Л+HaE$@5',h{M(`ndPx&30nR#J_b C[$[*}i#G v;hս B zfB^N ]7e ;5\hͯu荸`,WfX8WɍRbf/yXE]bET"f\s@kAr}J_iC72vOFsɧ:g*@g05_" r8Lhbk,'%=kA#D>~@S奒i> oI;:kOG.6ZWۂ+2yp3ģ}L s9ortⳏX>=1g8=waS_oӘ].}[L/H 1U0`oWG#TZd>n[sZRC*KY9M&[Ƨ^({3hv8nHtt9uO7Sm ޫӰT8)P`@yb7$sC:`v?l7gqllr^omW-:)}S+<}P!dcоis oP n\62LOaG35 `0 p|Ntt?g2u ^d`:[佸IRI;s`~^I$;-"k)}mL3;s}@byhwHntfs-_3MWKqVטcQKS%Hxfʬ},_nbgKf<Y5&z+o׸4a+ (,[:4 Bc_{a8xlW a^ #o#OӋ`ܠk#^3 TZv?]׽Q>>u10ụ\긓Y`9)\?jq}e@@/U:nŜz22 9,X< kHxz$0ކ p1MzYpQT.6LO''}$sulػӇ :) DBQu zRٓ]2oe!؍0TL4И{=6 ,_HQ;u?,@FFLÁ3S .ySvfQ֋%Ӹݬ]*ȸiC.aC;7x@l~cXjg֎v`%m,zS ,Rqa~ `Ah @>ˌW8yE] @$V:"X lT</}pgrf!{RO֚KsIqc]/n+P,X:["˞@o0u>TL5z1"c`CktEףg@n oyC+<>_ m)M^M9=v2 N6$@|1J}'.[a1:ꯛ0ڲo-צv~_VPz簍O ܔ1xUG/n`|/0P ʘy᫧ٌ%%6~ mn(IvMpO@ HbYPbTMq-s26V̀ƍWӦ_s~K Ǔw6Bje .2{-K,d}׭/ k75`Z+#l>Ooj3@oشB\2':0^.(F#]pMh5  Be *4P.8N٠92fE[K I'd9`oʔ5:rbs4!YA}+,*mSz eJ!2Z @/-ݙ&+? 3R'a,}׸@y/&S!>-cGI!pӸMa=(_j&,gTiiF:8i#[tr/2$㱼NU?j'NCeu<{`~2 *dwjAEzDSwԄk 0˂!7j'<;w2ϪMwgluv\ޑaSKȗn %h ]'ZG#~}A^A(T -г\~[ԉpo.\LsgY_Q {)xH|%A oQGނջJV׸pF}CQ갅n'g,z7q%xdTZsC!Tc(s?Tty?s)kQg0Jc*C :pX<MQgxg ;*;p=BLdSGz 5"..ya/i_b=fJÐK|@}8U) ]>l EKߨeǹaצbv,;0ZٺK&;Hd ?g>6=.mW%1&6$5Ռ;áfҏ~Xt2-cM1?F#ksW+㍈ S.E!s}kC0thڢFr`Z -(bfkC$ql1Ѿjhd#Pa2yHRs$q#ݱ&`f gɇf~,2;ӐlyXNў?|qC^.St8Vdb;(/3GVPvbVfx"iiPrU(7k؀S[ r@rX5e""TZU \'YN̨ n6k>DꙌRKVgQ?y~z8 ^rwܠsk4{9.WQqH't8sw܋ܜ]&c+&QB]ݨZIċp.$ <,2z%簌|u >x߱q}o$[sG)wYF51UUeDRqP8΂HA& iV~e]ݍxW0RCptĉHF.BbJФZFʑ)X"/^(&JzSBa5 #*>oR)f/]_'PԂq$'T'p­W_OP;4zRpNIZ?wl'hu ^ᔝUI%LYn7U N=#Ig6:#Zc{1U3 NNvz|4q3ѡ9/]7Mg?VPs\Bd<@jr! X6BI@"P2ַ?+ B>c6\EŁb2ʽdTnZ2L% R㿑3W?%UAa[7 )rheYy۲Z*և~P4!dLw\:Tgs; < FfXMt?iv_&)~lT\ݏw)i&0/lT4NZN,.LCƓƣ|ӏ#++|e>N,-2x~*[ P)Ȣ@/m*Isϲ feRX7>cOh( lOGcɎN퍀<\t`)5A~RyÅEAr=L,ig /ygȀ} ӧ#wD)%]f!Om. ˥M@.t;@Dxo? _S< -fɧDveķ>C !ӊY"hTzY(?xݫk}A[]}?ϙQ3floDbPF6NN"z=ַxA GL5`EE~.ͱ,"W'`lauڂ(N@cw= `wQ(].%QGd6ڳ6xX?lcW~pRspܤ{!٠5s6/Ͻcҡ6~E9<4&zK$0pΨ76臸F*>%-A |o{eI-G>mNrGSiO g0iwYɢ|#vQA >[t] 2͸:/Gx2“]#ܒ$k72$)3jel@ΌpUG렔 nSQS@<ʌd7g탦D9 uL2B&ݟ6 *gbX)gJN>!paSQlS?UquiBE֌Ɖ(.q@,0ROxQ$sGyz~q4mtb8$Z3?ˊ@ۈ WO"Tt9畤RSq>T[Zk';l@#"#QYt8% 4xyɱAǔe`҃iPt뺟nǓ4 tlūIGHiP5h@o?b90d 倂Sro3QX?Gߑu?O+sTsƮ:k$V_9fД.܆sՒ"C3J%DJt97)m;@'?J=hH'un4~]w&Eb/UVAxhC4'dHڃ/R0^J#q"pP%ڒt9@/㳑\䌛3< 6Ddj^_M3_& K7.: ujb+ dԲ5 D7dwC%2jeU杝eu?5O dkcO{ w}*p=/0Z*u=Ӛ9cݏrCW+Eqo7A UI"9-{K"),Pz:%|vEڼqBtYVQg4r{<50*ؼXԥ\*%Ӏr{'6|hy|ܱ0.2_3x4NX+تd5*LvFNs>k%fӲa 3bP+V#: y2N8b`~Jz6sIڰ̀5g*8[ qX2r4Byc}*yJ.byXT !Ns0v{5[ 2c|i6R#28 xҼawɳQsV'ПؼC E(raNj2=0KPrNTߗ bV!:wȧrBʒ:J| =;4UrƠ z ?%ho4=M}圼fCӌB ~sgȱ)j%JZq !\Z TVf6,~rSe l<ÔSv~dƴB;LեSt!@ɊW{,jqQIڀN+ k?w49\#-$]1Usq5Ż/JA9r=_4c-qHݡg">5CBE8#S;BkW3"n*dAl qRb܏BQE6 '=+?P2V4yov?q ?i?vLKzyKꦿT=)-=)% X7+}-gy{(lY{=ieQ˃b<># iݟ8_W}F^ɥdO$[Q\HIN 8y=b3/Vn|Чu?tS$Hg'>1%&.JpH6[_r -.(^՝ &2H9[=mԪ"LK`ȸH(= 2ojVMsS?iޝfZnHd|ʚ}Eaa e$WB Hc éW$*X9T<=#/P_v5OJ%l18+,*>8v *pwYǬ޿׭O&עoiƯfn5M.9 l;NSG`OLG-:Ka-K7hS8HDY b!&!z*hGJPXzقb, 'L5.!G ^؍6>Ѯ*|Nt*ҁ4USXndR5c<Cӗi+4F@,me1wG)g{ܡ~R(`hw K0WB( N<;U2f4n;&\(E8 eF;~o"3{gXav! 8yr_(aA TVV{^z^! e"Z0mo kү$jt{'%om /b!N:o^yi9W&esxX3K[#a,4V64mp匀~'HQefJ3 J~yŹ+S-9ߵ^HJx+E@=3)4GOW׹ r8]I`]&݊<Xc|UG-`;ȁe0(h~3b@ߗr]+uH`'nac\+P'8n+rERܣxf>vk71~(h_ޤ!P7‡姂{{D8chi T6!';!C2TXxʱ;kvc+<,SU6%e&d+tEpmjR,C=qWnȎyNJ+3Xߏ[F8.զ6M8m~p('5L)Vބ sbP!G ,C@6D=SdHctŌz3B UL:TuJ0Gpw( ΰ~5Dv:+yVe2$Ue1PZd%;Q:1½Bmrn Y(9ꯒ 3b6I5Z`n 6aY7x"7crGXS^2S%@=);׷Jp<+G=Ĥ %"4ݖX.~d/LNv;7'#$ڍ\\CYI2s9{lsΎl>NfG~Ne0>g8.єcNfYWzu^57aSp۬=%RD{e.Z{*4N:MG`0o].'hZgs3L6u1j. 2j>G^g՜k=Zw!f*݃C;qC}*iD+2OQ _lv=QkK0d.L C!ĬNbb{Wؼ6bH % zt?U BXĝej@I`>ϗ"rZHKn^&8Ƶ3TS,;:6Ilx0:YM [v__lP՚ϙ ql hO:+H8/4˯rOl;@wr{Eж xeR8TySXo"pQQ~X0 WHFGge֏~-K΅3GRGNoEƓuFB;ҖmaCAnPGqfκ֍MC[Dtǿa_`.tӸ8Fj`(NO?R%7u(8o0+S?¸flb5lEc <[m4h*C^Ig ETbgL2w~L.G",j^_&MDV2 JGHݯr%, )^#2tq]gއ6E8|삀;DºTټ^fzM [2ɤYcVYɆj\!&˙c,fē83Ckр1n-NoCP̬kg@ 5cDޏ0W:RVP4n IֽJ+#]1ؗ?vN'3!f\#M5~[/2<&9[j9JoEֹOcQ QΔzeG(:YA ]Y]Y ˘LT .E}oC6yȷ/yʴF69ۮݑ+4J;C Uc uDZLư fL)[KW S/CKƴeSMlwUvc#My5Ȫ̜ݡ5&@1yP& OwM]>oO iQk>FA{`阃y7OːϜU_xCxI i0K|`v*x?>V͙ .䨗Vl8pH fr*q(0@0(8X"X, p$ hgתj}GQ3Xk Y :(YW)q'Ft11.׹˩Va^AXg_Fsۢ($`)KN#17gADPnl,^* 3(-hǯ: za9 eZ T:y' 0F [AY#nF;<ݘ$|eCκhCmo`kӽ$~$L.q׆F{i4mr 1zA;AvN$+0.[>]VD3|7Z$UhYLvԔ3_R"8AtsjEByJV0̹E~fvŸ.^y0ڠvrɎxf]g3~3JVſ-۹3zih8j 17 ,s@/qwzJ*WbZZ;&| e% ݟ*J;o.0l (~'HNy$I)P $_UQj4η~(YL\bDX8vSu zB07S.lu"i=;ݤF7b Bn8#m(B YkV20+ׅ?jbcb=_hF2ȻbTYE|0%p'}.o)B.p\Az[c% IVWjY|h@d\".;Y!'{ҶTM*ـH55Y։ c @{̴ Gdڶ6dT>]l0%4≾{K S\?ȶW2aPStI77%ⴭkAG# Njp`G^ßp坣Q_Jf'cJ;-ڌ1P 2_2~ ?^#H=7"( ɛR|Rqjv!zqkϾ( ;V-.yuf(72A|KV*GsQ p73I TGTqX ^BB$Qr0\QLlcǹKe8jFL#8gߙм@5̬뎾,VF離0zȭQ~\eaIxTSoWf+ĻG ͙cnVU10"') ,m/1;E'+dxa9?jF|c:ZyK?KO9Pޥ k'kӬȮaCc,EuOQz)LΚDx!cp%k L a!% ׈QMњq8 v|2eD,vY!{DuBYAoazu$m5@pr{WAc4l29C_~ߨNl{_bZK έm2`,G[>O/~R% -ƈS,!+2Kbw'm[3G%%}tvrnx<3jKTt'Jg{,.kx3'^Wև(S(kl/M`E~xK/yoPH9֨jngcٲ-P?lƬ^<=1 *y!6JxMI^9ٶݢ櫹rs*bX"tlcmu Ő{7#dVH+DWH'H}Cpۉv/ޕa5,m15KA*T|lQG4lkJƯ1(N ڒ'gX@z@ ZÜF^q=&晩a/VK)2/E4 a5`'ka(ȹg'ܗ1PhL8s[sEf_=hc?c|%/I av (|9"h('+oT_E4Hcm|EZ& "QfzoTQBwԏoaڹ:. ̥~r ~g>!}Մ+uU=b72# z8xNXԭ(|}p6Fâ==ٿdFۘxݡ3*C\74Yا: U~<p%*y7=% gR$5CxQoj^,,˽ӕ2׹P)%w#GKn.iY"6 DT懷a/yeZ#,#N\ƮO|koF\<&cmsSC'Y^oh[fd817Ooo/U-+ۏY *6-Ht"{Az kưü'wUSzWE˩ek "Xh +>#D*7Lr&nrѣ]8đ J8{kbӉA]/VMqljW*/M%.P͟?t~ Bo}[1lK㓟1o8.}SXTGrW|_[R^/2o1hB˜ˡdEfSW@vӑTb5xjw(5 ͨ<22q~۽rA?mL11:Ea[ st>2i$5E&^KK#nSK3 q`xI ,r7[✟-ʛ}3$kouQX1󂰑cvfRUƴS1/Mt+ 6bi -fcćaQ(H\AD9-y \KyRL5Vw)3$!oΨ;ioqb0=ЬdeЅ$x5ZǃOeK$ČH0t^ B͘N=Ŵ%uVONX>zυa A4_))nmc}j" O٭} ] P{ٰK!W)Rۼ eP[pdέxY? `BM*~bG"Q_:^?r~Hi(5^ v]w y|T=T8C@Ī{"%:0æ Rgz5|EifzNtc&x듞]شr!r1݈U 6~uG}tkB+65ehS)̵4ksI,579m0Mup¸~![z*0i)YĊ6zɴ[VZ؛zSc ׃*!q&c%.]c$N\7s{ԏM6-lpfvrLS% HǁQzlш%Ӄa"%3ݏy%1b}N*^w1X  f|S;+^W)AbjY_jtI@H`}2x6fQy:Y9;.p,т k<n57a Id uGFǾ3hY'U1.>Ux 6Sj#lJӋmĩ@<( @`Lys&;2-ʱ:R7d7rg]yBƪp<*3 f @5w N] Ⱦ%\VRQ ?-{# $wPu]CTJ MzTp*SGr*2rcC)2&hpX?*Q 0#5SS8䃕_. ֶ,5cB?OؘF#z !M"q)ZRwlqHF`Y_3 HC-G G ­鸻xw4} ]/?Bſ=i0{Twk:c||ɶKt&5|EW ` _b[lV z üz@nYL8Y~}9|(’UNpqZ +?M+ŐuZ\pI M+2INTE7xςG~\#Kd9q|VA uqԼ !>^Yp1y^F* h .=ܨ:f|A2-_*\+72Bic×2j@#X29ͽ6jƿ]oyՌAd' X`p R կ閡[s0"E!+h@F `=spM  &dGcYCK82^pS5d}-F^O􏓹ЕW6Rp#LZ#)k _Q^{ɟt2+C5t־>tf/@δԽj J3=1+S[ IFKi(x"N;,ȚF/m~G<@Z(,3fOLr1XdwG&7uj t-U< 4݃0kn̤#qɡo8F*z[˺ iW Cq)יUojޙb6v@oT5Cs`>5BS<ݡ/Qi^hUO;?ۼICuH\_~ye,ZD1!Th8Z]OA %d~!ـH~8Գ0:9 9($$Fؐ\`Z^^>d&(ҫO]vgOYY[Оڿ‚#Oq$Wb7Wf@=s‚rJǻ{&Ne=qʪ\cD9V>WotH.J7ʱJ̈L?eE2(S7.܁ _YEi[s@6Ϸɾ8َˠ-tUh+sAU0֛4ƈ&ꢾ#71hw3EB" %|ϻwL&I +>-3I|7# HMpZSj0#)n L*]tn"֌֒})Mfiw϶=.yllKpߠ O9uB&.?E>h/̕s<{IN J(#5M'QX>kD-5%N Xbj2Ul@FXY[BjLs1Щ˂d?JHa%RԗEyP <¹ͧ]l3] n4!rH nORco &?pwvNm eeo| ꌮCTXkP gKU:b&3EfDш0nfp#``KJ'z~K1|XS[}7Q H Q8qcIU#x !,1.KP u0-tsC9u~C>E|_d6w4 x*}sIQR-_k.(8?bx}*$C 9|{i29cS&1fZ>b EAJ/ xҞ뎒M4l[k`QD|vIl ^޳[#h%Zע2_.(Iڜσ}*dhWfQ-GZѽ,qm⬂<=4R؅h@<U[Eljkq [23jHJb؇BO]k|CW&%~ܵL,zqiNcAzM}2G?q90LFN-;@G q+A'9s5,jȸPqJ4B$h З_v:rO}D>7.#>heh5|\N!+*SSdy()1g}y〻g&xBgɫłQ:O]HZx~Ng|s'~l;/ᢖ8Z ).[:y [[L φ#|ovS IHyS~n^L+w]\%?*n ocFl}?Բؼa Ibӏ,"_vg!$v,AXZɎPjtS$Iy=O9(*[[hڬu1WPsQz\;;fDv~ukWwovA qIB ,eSNPj0zF B{u' fAai!?da YltE*anڊ9ndiE[ &@=XN;}:aVr0kԙ&7<8~Ť~!$m>sXrt+gdoCqDr/rQփ N<@ͅ 952KH+K+EOѽLBX,xoJkM ~BbN~* <OC5z?(L<|n%fz2 Dyug#>.}y=}b%rl~Ժ Z#kdcy10 }xw ufks$8ŀ CT6(!paoK\C_%Q,9{o~Y=yYkkH$TsAC&9] zڌDj/E]++B&sØ;`;D?b͙2zQB̞_+ӂzcxA7!UYjh2f8|p\mG @d8HIJoDC%Y_Q?q&ʆf=[8D1Cy0Id`SR58T0аBI֓Q/hKiW:d6@ "5; 8zQ=e֢aI:}(@n kCJL&%ņpDjXRY;8YPidtSo|?Dʃv l*Dfbͼڑ`Dc+}=[t˘V2<^1Q'Gb:vorEڕ z24oa_3 `1&ZKI*ґIrڿ7qF@;~PU@:MXdz\;&zǾl V,28Wp u3T/^E (T,9Ym2<(f*zns El(cG,T7*MP&[|3lq'2saR'l6Q'e[Bā2?j%*Sj49Uҋ!۰# Si-[=;[cǪ^iZ07mjZk#H 0̥ (\LU٪h=p"ˇM`;##fswR9€`cǫ+p;.hjY3Nd'X]y"qeTkS£ hWy=/3#6P{0J/F~vSa㦧>GE~yH$2duجuc`Pf!崦<,7A@Wm 2i4{\۵p³yKgZy.KhBzhNEi¼.0312^f{!}v)R!x\lkwG@\8"xU; `^o;x̛'LeQ|_b,ƗE82N^q\WB!}6!^*P1_|+1Y~y Mk`#3k? pa9TV=ʒ(q+qquqөa S(IŅM1`γ1-XpbO-FY"5'l7bAӾ,/ 9sg r+WfY3݂.Hpcob.gU-?. V7?LOh/;C$FmLLV˘L{ *"K*[eB3yo775t$qECƕnf < j~sY:ý!qN]cDM͗ÓĄu"31R M7XW:tB3ÏHL;NR+~ {fו ߗWN}0@h7 poyHUؑh-;F _@ElaA/ئ(G櫯#(=5Hd& HPp@/h=Saíg46 yM7@䫠W)Gg9Z|m_"bȥCFtM2L|L-vt{2!Ƽ>ZyH?؏߾|(_D3&C8$9ӐE\#c7c1UaX3zJx [d§e n6Nk\$/+,͑JiFϥK$lhZΧdBfu'(oPQ+UAf}(%b3N Ji'1M@>-C]yisB$4C1'?:ƌFRS&0y]zh;,oϲpy0ҧFܐS/@?s&8,ʽF~`=͌Z{ٛѼcKRsNl\AQLǡQM~;̶sWnb0TQ\LKbTޔu w8 +qsnԙ֍sBd:?D!ChQ]MP41˪CGpyboS1Q/jM;A8ezkfp%'r Bd!V_ZfuJj Hak}ZơHMV3j\eᶳl޻nāxԇ$TGԴ|Peh>?VjKqqqf1,=E;k%8^ Bky!{)Ca}7)}lrl|]"n}r3(3YDפ+ ?kU_/VE$V0yЀz⯍{V}166l@tu`Gs6+2 0T++q4^1ٳPMl40ɯ=1k|:HkbMfdm0PKhq'(Sk^h !L6,2פ,-TPnPi"B&'^sMu]\pV[S|}Ix<bOޟڬ9Fq&98 \uw<+˽Ļ,-a ث_"2Cx.'HbGa2q[^¾4K*C tPiOvG?07 yWPȹHt8b5J{mꌰxƱur\BD;æiҞceq؜c7Lⴚe"I*O֒ 5T@)ItZCʚz<7.4B~D) ͢&] N +$ rZ#{w׆2(/Rb3;HOjK!/[h7ܪS*﹯yeɝ\ v`(:5<C&bW3W:c+@^:]/ifwb ƬGin6M^V)`{udxlQc.&4iaSCF (/6?)kXh.D dXuVfq0e6N/saP &rΣCg<34xlI{0魥]b7$?KJхayG0\SZw2fc*zmsPpqbcz=nWf `K+bQLJݼDk.] 4E{RJgq`/bSy] Y wUcފ<3kUZ>H *OtO57,ַ!!axқYj {N1v 8srĔF m "<z?WHZhpX cT!^J.1ԋD,ְ[\bWԄ2 =a! :DsZL2f ͓j YC<|-IE8X]b=]xK"1~" wKR0%\o.ԪT-f^e#1.k?BľNVYY)Ԃp' -g)o%vV[LPq@e‡vv9;%weW 7#xo˔/VuY&]I_[ZYawgMeO*\65۸\Wr0/ܻ*Y2?JX_y_:CAXbdm"!ŠS<8'l?uD(wl9!0$ۑvmzf,a9 ݽGU҅ kp X  ELY NL̬4N}gNn5rOMgO%n(yyIJuȉ8D"Yƭ\]-x gjbӖE"A+ڃذޘ^37G< hmWʓ˯/(pX篝Š`YhIR,OMu7E*1̥`g,BɳUE~ PGs/4 g](ŲMbȿދZs̛ⵐ΍HZ*hanltOZHL_`PT.m 8'KƬ^쐊[P'3wF:F/OQޭ"].yAf?S#S܋~#{\4wG[U=_إ 'Zrbw1䩄4arxM;3'(k\+[j=&X7*Ix -E,гY'+@_dFl*5)dRf1{XYQ{}>4@%l8sK U'p<⡨:s > zNƙk5$!rY,DcX<?^FB!ADNG6sgј!NDBvG#62#_s'wwVSwNğ8FX5 γ `;@%[(__R NTQN(uxr^ D}*aG|ENyY'.fCn_g{_ ο);ރ%Q`J}Բ@lt&RCP<.{+_D r<śHhi%N%x@fߜ9/ 0tm`,%aV Qւjrxڽ0~|ƜYp')g/ѫ1ළVdp{-t<*Emb@fnL d{6\k77@o3{@`-ߩEYP[)iV>K= xA&rLX ZtNaARq0q.)|M|B@=NmCeRc~Q'>(*` sS% E!Ίw#vM c3Ϫl"#^Mid~Py2'-͘""$dd12p .KP?;||N؛BO>SF5!=r)vڼC4yL{R[@҇a-Pl < } VD}CP<]SߍkZ& ~-$C\#p5T,9ԘJ'+guM[@jnvp,8(==گDHBAnc#CѶs?f.Ӈi`Uf5bh ݁ޜ{.k=kҝxJwYϝ(nˎ&6-BsAe?nF !_EO64nLGe^k(iu@nV%0͞p˩oCYz7Hˮ%an+|ؑX*NMOU?8|o%+#Sq/rGЊuVJXՁ)ʔkڦ(uKw\ ً#¸/*[K Q,2@tE3DE&=f?tCRjKU^d_~k[hSR~EӴFŸOa.A"}/+Ͳfm0~=dT)J@oa#5%8_EVRG7~!{-M"0(еᘞҧ0EzhDA* lgcΦNY% kqE."hԁǁﬢsjB h>ٽӱ+Odnk:̱-qTs ҂B,+^~؇pu:[msw2qUAu տ;/9sZl,Uy>v H̵7AUd>.(㪰{;4gFA&Zư4vӈ!4/pmoԼҹNI >;댃OB #b^snC={4A{hZ$IF%T2hz&L *!߈:;eLdfāuDj@eER{=|])rؔrh3'@VP;Lr`%!yZ+C$fu5 'IDȎ}iTbKߟJB:Կe:OL?W`qp(L,x?s)jSPc&/qhNGlImKp1t0/%˦Bf.m t  eSE_0K C'dcF :Jo,UVS0ͥ ?֣w "ln@Ba1xqu}ؖlf>o# ?Tm-̫֒^Txk/D9p1s)p$gkVAAA<5ֻ;c6˄5<&#t_LcW4y@E+;*wžIe즛~)jǶԚ]UɄU|=?)`j.`Nvn;zu:ei@51 锼wb08xBWnǤjٗ (i&UR%wS3'BPfzTS.qƨanITj);!pvٙ>JDrafk:7S/U)~M~rH9eIJ Wa?2N԰re\cMA]*:K@{=aWJC[' u]0)_!~ \`({a5bϗ*]0ZQcIyWR4~#::7w<67LP}Q _tؑPly?NZ6[xϯkb:l^QGFt1,q"TָJE&YqTV9 V"lr z|:y*;8X- R4f+tc(jg#Gd>|lG0/zJ'WyEf,+*}H_lp0)_xYI]W1c6z>,I< ,ҶU ߻I^m_GFWa-"jel0[Bo4Otך2AYMÚTQ$)TU|Jm+l70޺=[PN(to[)OhA2]/\B3jb^w)4FLT&6[TAKrԌ{ 5d0+C!O,xcuqVgWRcytṳ\h‘,M€iruދߡĨ-L*TTn^bk;ΛJ #Jքw^}.+9Tbse l &eV;zsE=D wew-1xy݇< +wBǎ;v]IExr{:Hkf8eӘ< @_L*uZveׇcJY>s鏃8ъTv s_F c"bVn#kp~lz t ezu?dL[q[21ͮ:av?](oBm,L~ʔȒŇMB6i*NWV4Rqq[Y.AT1YF+rI򗾰 J+ r kt'\׫azO1mӀ΍w?/ssV쭥3nѾUu9$+9OPUFD?&QX2xҦ;AV:m5F?/9΂S){Zju Kt&rkba;kɉ&25!ۨvOܣGzSJGL72mֺ4L :,`oBa+^r| AUPe]0K'vy|bһ\z X: $Ǽ1V>y.oe PO#oO}) wƮ>8t~CYW3={Yw[]B oJVgیN, I#Vc%> Ă_x<`0}VQ=`e)S[PXmv۔gmтXe.l_AV~&ac u򢫔,V\<$wd Yki@yS /M~65}krn\bRyr /2S"蒍-uT{Z_/XR(MӎnTR22O?J`y>zgC:ȪYDoyRЯæuli=A|m7. J-c5ؚHp5 ֐&_c>A_a0&d/Wq.ﮦ;]b>k\PER986kaDP| 6Ժ"zJ?QsHEPpJ sT7y]T?ԊB6uvTjWwfo GCWc^Jb'ىRS <:}>PP+0G@ѧY&9%{g-, <\@AWGa_h1f84J$םsIt%"pRʝ'ԋs yVD̔WO筱6T'M[KݦM/DlL-cnfJ}}`CgAT=^neg_ڋlqN].\C'9:5bt.M`!C->whg8/9K^P6muA (?U$ uԕ,9؏'۠8R7'_W*95 v99R $ߧdxULi#JKI:Fs7g$M+ r̒l"VVtCi(USiގ_j 0&f!s08"ceC}܌`+;?my.Qf1pdT̨UFZaܻRbgoⅲ^ AeTB=]H/N6c!}H%-aQ>z!4`U-{!.fg7K%2d |7;VP5cç-1%Q _@ҡ!pqKHq8~Rf1w~Na 'T`e&š%TB$~;7u|#%v1=(~dߺt؞WvC2fOo{lP-|4`HفKxk@ha+D 1=3׺FzP'5)HlMiS/ SzotT1N#Z$.t6~5ewMݷM#/$?7 칮jMS*`o*Ζew@[cX7 ){/}m.ubîJU{sxkQ}&@^펬8 &zI` ہtd::W2*zf+Tn p@gNyp7d8a'1{V-Ҟ H(!#h5&<'%-mҝ&U0bm~aY+Yb;!#qBT XRnϤtl#y!Ly=W# UD·,>?)1)g27ucB,r{Iz1h\R)5,PuqeqVN!havroyT;rkBarϽ^2ޅ)߹ÝXGy [0<^i.PB{|U\jjQX||Cܨ83:T0Tkܚ_<lX<ꙋk5L鉣 2<: (GŽDPXTcX6( } eFC(s"XE"ry$-iiKΕB3rƠH 3q_ڏ/Wppx5X͒vBe|LVuQ'ӥi{HTh$/M͞[8 qRXcf9\6uyVO!u/DN!?:})nc)O}@vm嘯}'^dy-ROx_'N[Q,ңF$`{'b.h+T)! 5*IcvitoxF.'>tk&աXiZkéA2]xRcS#'CmBw S޹Afa!c,6B!)Ey R4eUآ, tyVDM呙0}v¤TV\@p/1L1^^avM-7!0=gd (6fWoq# hK?Y8Ć;zG8*b]}0Wn}ߩ0 o381ui{匠6}4P1DąJ|RԇA f 9[dRޕ#Nh8 Y 聾Mup\P& w1$?T;/9K{&/,9L|z ^t=0;oI{*;.Rœ7CFe(vETGEC@3Y7E &In% aPsȯW@D}uL_]^ R ʸj,tR$)V].F"A<%cBE&/vg-%se~9n`u G?J CBһZ{PLCVs|Y_:hI<$ٵsUwqMJmK< oRa%|w1aCz;eo7kBrn֘)#ȍv`XXha:`v쌪&F;l봆*u [\cf*/ވ0d ^ y?8/-0<p-?]ku)v UWÁ_i+Av'3g i (G,5<+Ê@r~`k|'29^NJCI71?:fQ]q(UۛEH&<{hNU1E͘ IF1/LeWsћ*iU3`}9 Q`T0rN٪oJ/0YhX!dwvKf%9c~&֋y>X;b̪3W]B#x{io5Sӗ gqA]XK='9|/i"6G^48A CL^ƃsN嗾K7:3\^p]JSzL8 e%ObK2~/(q\7( 7Yܧ÷mجJ[fy]A+*3E0dͨy,ŘFB+ 3!M uΩK1-h7!&"/6K?fdw[§ ;~m{m mUPTrjlĺBYq;ꄓe7\3ee=r7!>kV=^̕o>ZqTp? of!.WfTC2g.GC5}ϧ7|pod! 1*-!±<,. +>9{eY=R CvB*D|Mmw M E.!d`K0x.m(闯nB=ڇP"|׋Yn)J,+#zCvJyrV% 5vC}q5~y|b `yKZM2_J~cmrdh ƛFA%ck7sHDvR8#mk6}9,W^r3ܸȺxKw|S$Wڼ-ȁTN 9> X,dUReѰ "b'hJ.= Qvx96grn}U=M9UJzi?\XO,_f??g#3ͽl9>9q)DWydSC/؄5 \|?lF3hAD'G\ݖݱ$jxp=* .!@MEܲI>k쑞D42 !.rd @&aN:\$sV̗,iTuʖk4Cuwdau& i[:/h27,6BSu{ pN`ae>^baQT6s~Cꗼo r[ nPVg/D=|zS͒"2B"m)hu5 TKnPb]f,>KNw0qm<J.Q;am7R:K 9.k$-8[#ʳÑ}'L+|:!{BXl3|?[݅ٛbuhLM-Bb5L-wIj4 ݻ0W+֔ *'_C |X :־[fpP'9cx%ݜ+\nVF 0Y}F|ɸIOSzHup +ǧAS;K[h7oMZU^Vƍ][ԾMl]aXqGij^<J,kޕ-+ s(Z0ş>Y\#6Z2(P>/9[^̀' ' UXdBz0(m6Iħ4 ,"A*/DFa)VkZa Q#SEbz:5o::nq:+)|Bp]Ϝ V yorל{OV*cdP{S('ɾ+pQ`` 8Ka5} zeP}@+96=h]Z%Gm% 5SF R*RqNnfQx%'v;DGxa>T1F;n12ǥڳ@jbOe37 6"r֡\ kSGg u,`kgnlJTDBM5`,Կu} t!O7Ηm}{m w"f0bGx# 1tָauw呦f|M  z_{ІS<ԜGw& ĸoc̥pY7i1fksR*-YEH\jhtӝF}kQIL? J3[,/ Gƽ%ͬHq 4IgBX>]=ݝc6!ޮeoOFu/tʓE7~W⛸v͐iPkjRʹ6|zngw2Xo *W𮍻uT7Ֆ̆p׀.tc"Yb Un#L Ng8^xP\:8"?:( Gm*4U BtӢaftv- @rYZ@$#B{ iڍ+(i;A0V caQҍ7HRLI߸Yoj=vAlY*KlÒQ#\1iCIJYsKIK `1+2U6p-n` z.[a/IP٥t 5Z]p=ax 6\MҠUl)V.HWhoȭZ9^k1yQx:f/3u(t$٤OVP:Á݊fE|ZO>"% 80UIjqM^J.]:#>M{溵ư=u?O]b^+D]rqZ R/vJu=EpduUx.Ȏ.~ {u⦘ #$ !U*I3 |V͂eZLzCt,ݻU\h=4@/P[}ʰ eGb$l9؞،9av2Ԟ"P5|3fag|f*>vFϓXT+k!BecZXjJQ8tkS7jM3~xhn :(D[w7򝗑qJa-MZkx2"/~"&@rev/̶zԻ}1Dve<`$`?;19ҙ_J,:'Sgu'QCѢDKq7R X|P#xP-"u/>(7UuE׳ EfHK[NBςYgo4?wx2pa~^WTC8hW_X ޔ|cgcO>QX6QSጦ9!ܻl<_>TeUq7S4&7ox.ɲ: n,]Po4A_V}c&[d6*ͰOo<8Yp>O5VUM@T!MH$/hf֢Ud.`hs{`B{g#o)|Mpĉj:=gw.̮#X֓Px?m0{j94]4i;߯h">Q4Pz^/,Y(!?]]LM;I_m9Ot9=`Iۭ>zDQ+ە#,2K qFt`8?G`v- hzw 4U}̗/uxw7i~>|RUC'fNVͬ~tQƷc2JZYTZ^K &tiOup,*eYn0W/$i')i2H_첟ւQQɜxW~a;&4C.#GUoR\o'mRdk1L'tTh%-Rt|wzמqI\?Ѥ1F (=O"KٯpRGL؟,n:]HIWs&2Hh$q=i! E{WƏ>n'I>]fL+.:q+[{=mdhSmM&OиpݤhR jY8Y7?϶19w:f @ ?gEz\z4 E8#ܸ^^v^Go\{]VԀJ@,`;bk9 ?vRZBnCw+2k-}F :HxO5Bj@!glө 6[`c0qۜ.N 1S?, 鍳FkP׵DžYf';W\Kv)<-qa* sBE clP94/C!fG)GQigG9jsDWӆFG5CRU^xPȘ"wKw UNXG~1D5ԧ5qm/G5yⒻ.:Zui]|Mw(ꥶRf;9Wa Ǭ^E2j)"7'(F8gy"Ћju+o%y=PR댂%WA qz> TZٿs0|/IP8yW[8[7zl? PH@z:A>ZiJePΏE׮kct{_?qa3_iŐG w[V jLL"$/dy >c Fel֌~{.w&R%Dݳa H:3lv+]+9lAtB4,#t#gbغ!+B+] Ȯ_@/xuY3_@Gd{"h̥mz"~ᘌ{fx* Cذh866}B6k}Yx[f%r ;KYcz~Q{BX((Y'9uf Pp _Ix:>ßW0~sZd[eP}m|$YCX1.|Nb=Lא6sb ,q9k d&ֱcLq)Jm(̚KzSk|%>KpR&m_mowc)"H5Fۢ"5~~1V6Ԅ^S662_2\+)LKݓ4\KP>EJY mLw&w*Ӷ9C ߅RHLY 3;V)Y1#AxL(R!Fvb'Mƚ}a:R3$5XN'M?`BwZ_[pN! r6!@U у:t_WBIc5BWON1ƥ%UOʭ@[cI* 7*Tn(&"VEcަjDb>N嚛[Rj)*h\ ү_a$n̟g`8KIW1S=?qf$%8B'<63p VgصϞuY;׃  k#؜il7 fJNbx]}־c H]pg#Y馍Ll7 _- R9p~+a]^uW֢[;ІJKoenZх0zt_owke0Pi5*"3pw _ATX{x ЉfXWۑɟѯ)kfPB P.R Mh -1 g(wܡdf |:i~m1a~LυZ:4i.vx%R;W +µi;`1Noo@4g_' z/~_YE+UR݄. hI 狏$Mzfyf[HQC_*AI;#^:1 %i( 1h0oS.hpzN/D"N^$E7sJfx-d4g5FtSNrX$q1z8Ϩ7w^ PRxt]4bkǞx)U T<Teno,X{K5IAoW@O _K]ZP hLpwT=Y{ >ۜq槫uӼ"A]^jP%4<u):t{Jtsh@.wen.2QF_FҋRQaII. ; gz#0vQ5OAu6/ cTC?-Hjp?Q# Nf/+\ʊx  puz$RqIFp]ܻI)$QUc4}#F spK]+zˬ@2bZ'^Ѡn<ҁ>bFS/CtR1 {a*{ּI`A6`Y!T-}"fAeqĢjhceDDG0)lW0EUSl ,eӀO-v*YPjF}B>  S5&gI6g#9ۘI@b5k?ػ(Wr#AbR|aEUWss@ ,-Z}ƒ6bLJ O]KGs# b:e;@Nf8-\N4 TR%FXhV~MQkql|A+($m&Ȝ͈0"꙼@VHѸ惘$-m ddyJ}I7d8( #ˉ Uو._MCV;LFS@pj E7R3s [<]BnjjNZ*3S9^NИh_U na>pBuYtpMk\pm}}1L mj |j5x*{tT̓d@K0Max`O715YH}hgPP\%mݮ8z ʤG8ˤ$3X9 $^ls: eW]Oh_D 7 >,a2 `GPGbE;e&dMnl-#SZCx$NxnQZT4n8Ve@DdSG7a$<YA`׀-v&G㙛p"JrW!}9o9lIyH]2+ǑbXX(!U77u*#%ɶTFH=Y:Щw!Q@;~VDT\a|6Uy0Qdqà(1tƑ@`NN_ZjB%.Y =SQ[=ރ"}j"iw+],ԥVtr]FHt[SpӪv KLz96#kirTpx깨 *9ȆRD$!↓_H#y$HR 3Vq# 9W,Mc5+Sv4T^EEӕ%Oj$ O !ArU8{݉uںvPm~Ўs15p9K1FZLϸR堃mL#of3~9"Յ_0qZ32 XXF%]CKڂ/I )~+hz\|9>Sp|`?!Nbx=KF9q:]O4<$.~#ompܬElF{>4]%iǟ).e 鼎JԒAll(="LYkڮ33yL\%XY?_qy]V|n,![XKk|2|wG- 4;l ;Ҝ0Zj ?#u~COYg:Q)TS[>v!FKg̏0ʭt(sCF86;=8Toi$r~#A"t-n/^DžoHBPTY4?3wv0,w\9SP24))ﺟby%bDG%I6)e-sscsy(&Up@aU\hŦpPln],iog<E7c.'`3Dn#XK<"L:-ևd#)|>s8a~ TVb|GW?Yԧ|fFhҜx@u׼ڥt_q2"d-MU3U;f3لJJi`rkz0/.!I<sc[pLt}j#] [&AO&E &S]2#5<)X'YJgHxw33&nNr=oNO,k܃怲*hJXLp%2rDN_Ϣu~XVj/\ a[&^SIEB HWoFZ4LW)PTW*+oT:v6im[ GI{T+/Jo>00ZW7}n: 0Dă+ a0+vپӬIO3B<~`ٸ\9f,0Ϗ_D1"dg p:!\XAlz֙ Nwdҟ N98'|78Ւq+o?}a~e^@3? ?lWUe/VjlH0*OoVh4OChcwG")!ͣڼ릊\\ J%8x=uD|"β +uB1gzyΥ(!n: vfԋM8O_bK:޼Hzu8Mv !_fVIő40)2t- rd 'n-WGnK;ZFNIH [|n 3ڠgy-Tf%\"͉ a5\EOgFI]kAu-8Oҡ3k{+\_5rc70e-A Ȟ40ھY]s ? O3D!HҲ& cSIq-Ji2 @$cG;d˄2iׄ;Y~yAHgO?ڊ3N\PgS$eEwǞx-}(sN躂6?4jB꨾D)B,rL5t/,qAS`2KC gj,%uphhpQ]5`M ,S_C9=Iw7ps,%:fve< -[N|:Mw ֒UbAuTc pSgDvHmB[!I[:]Z=PݯO0'LtI[!zGvs#`r}'D? $K|^ʥ1K F[Od2S8;6’ghwLLÊs5UH' _HWvl 2n>U1I>XSDd wzw%`J qCWlU905q|Z h\܀5qxDL46NSSGįJua8/TcQ^7;kҸiy|"~ `_͸yOմؔ$BP.0-FV39>Y_8vb $XÛӈ 5iF * :y, ,?}0hwqHC.$FahY ^b_@1#9Sr1 /˸j(U,Sk( C>VeS5+Ǧw4֏W+3m:͉#ȇn+[7:e ]Vim5a.ÜL̰﷑O|1pXz+&}.!XSxU 84[2NJ;,L,3B.0tOԿK ڴ mBFcaoAduڦ$b rxRQ;fHߒ]ޘ 7 ˥}iԼ p1}sRdb(P67 @CA){e,|fiYs0?Gl-=uD]F~q"$xX0\%i a^OՇ(˘$] uJ$GpWl'6﫩\f@s!dnˤ"'6gy S 6>woCn~"T]8J=HclJ#4=9KX~n%zEF+ hP_i(L\'!96AT-c.њh©WZ};RYT>@bДvm"t!Dǔ'mxy>VK[=VyLQƩg Ӷ(x|3 A)O,JL|=^u 5NV:D糿jߙ~XcJd}S-5tM}A[QJXAYlc'bBkum/uY hPaW, > VZ0d@2@3vEp I@= #vj5RL&&RK#L6)Nc{@AD@. "@3P)2|Yޕ{ww _NMk}Ppj.'d$ˁއ$G"qs@<4/Pt ^/4,U=V#2x4sr__2?x V8S|lsyFLUMB^OTސI> T AB#f= ~D/5`^jGY 13 j|mn @1, 7X?Lӵ㉬&?R_&'Dl$Au~q1ExGfZ~D <GY?TTEtZNO\}OYY%^f|jU!ZW vݙJri(5F6YteӨi܍Vy/ á=8Lѱ3Q_4n|wSSuYDG+0~;gB]3|d| @܌UId |̄c_QįMC/^CLsy/e%;W I(]>nպ~_~f@ N}}2-}tM%B./}_N N\(aR_i^΋&F륥9ѳ]_ךs#19N]CPH(u{[Z&h+~6 zLVҊr c-aSbmvW81 Fj4-|F=Dz{Ֆ@88]4nP]FaM4vRg5TpfN-rF@NJJLO H`|J]ݍ?v{1ˮtM+!w/پ91yPNgڥ' z$ygCel}7+qHۄ| =X`|? fdl:Pl W>!D pt/Uq"ޫ{F0}3nkDz2 Ӣ o>y%8Eړ?TcO^g5>ZdWĩe88qܢOde`sCo&UWKS<%ޤ1@e?oq]Vқ {1|j\0#Ry\Cv0}d\Э'#h-nq+{G:͆#+љ#I=-: RBNp+$`[,mi6be 4œ>u]n/>RWx0$¯>$?\sdHaՏ5YE [`k?}4m0s-XRA1GR0xJAJe)Ij.cK;]?ϭaZB̫3Sƍs_]T9@j7;cϜCM6G6n2/TW}> TρrO"W :R+ou B[qK`P9`zȎ`j͞zW;B:?{j.w2'5%԰6p; 畗JglRj\b J_d_؎~dYSAH[Ig1r##E:Pt*"&N/$fH@oZ;Ξh:f-[  D@鈈{n4G7=|^Bُ>+G($$ L-ӡЛ.novy驝q!H"r f?{m}YLO51cЗ>zrKS市-aeP%G7^~F+ KpE)_aLR׿9İڠB\Ȩۃe6Z1nKnϱhRx2UԇE<4鸘pzE@v7rf.w. XSpbZy~TkUsh4YKǾFG^+zfw` K"I]ϹqEVQVk9[\]^&{|1xRl0Pgt^Mc uU0 o4q ?7`eKw4ue$!ܴU뉓DTf?FC.Ajqj]j꼰memF$RlA)|䊗+E'S /IL Z!Hc-X;v/DȈ;T3򵂗x 1I(c%X*'CUҿx z46p}1SnY$UЊ3d4{0ߒIu`X$ЕU>.=UP9ZPTFmNG%ra FPg7X P 9~*2s[9cw@e{Sg*Brz#Ivf- 1(YR0{(i;ޑnY >O9y>Ճ]:-Űb;SjQ rIL(4NSw6Ym&z# rShqٷ$kSN=nQH9o\`vRy է<~ru߲|P~`]Nht:ap QnRr„KG ~ a!!UzwqD]j.Q\b}ZAw*'[dYMTfUXVF@k").a+!V*  rL\En4 8Kؠp^ϰ1ǚ$f(,nRo*f ,bkoE/lLS&y%B=#3WMvB<;zHă.QAXi:G" H9)n#}ieygGOFq6^ę4&pZlqC0ĈeIOO ݧqϙ*vi΋L ,/KT`PM+ \!FV.^2݅H˙&41ȩh-`ί&?/O:OF恺.zAڅF,ٽTU~8K@jo˄K[;Se#6*; ǻeD}0a 6sjck=76VekYƊ!I'P(^WK[@B8k/R@9@|PƼ%M'vCǵK iNv ~+^҄+jh asRf4Z= Ѭk,fkF59^GCJetai s Baz"p`y ѓC]nJW781:,u<6!DQNcth8סt]+J2/bvp#ע8OmPhR]Z \eHlI¦RV~XƽBEZ$s((bkZay\*1M.@[POngJM=j7js'759.(/މAE`+"QOzc1q\hH^a],X9Ԧ >9(32wA7zi^Feb)!LnRU 4x&,s!L0;K N=*ntpPSP]aH(|Bg# E;aFJw--jsAxBs.c~bp:r X-K=+4 Oݠ"~ʫ>p.DZӓ ŋ/C/spxghJ)6jb| !N?_^k.~(dMI+tgw,<<0``ydc ,r Sd{81o [? {J6. z޹o*=CEhLb!]+j1'6B-s+!&K~?}*?Hr2LH;q=k~|!V ]{ʾZ ;[x8EAߵϼ % [W:͔*nF2x`iCeGx≅k"~S?-G J2M'Ba,0RY}\*x1]((?)c<]dIS7ܿX,A4TJUht+dJI'஘1OXHiUP3a- II&057MdY"mυoZ+mf/]rs))šE0Ví]_ξ25En#KF_qBܙpc'@ _;aӚz ƌv_($'D~ fdrT.VlDuכE6[nFhP?GNR8v|Gޟߢ,b2(sws|#H5x"E$]a1RJ,g8U2|j> ˣ1hv[H"jRSKKڥYWӈTtjj?=MFȉDYe}EjOVǙ<,emH!= F=hpUXa?-E<"ߖv!FCRkĜ0fcMKQڧcv@>`k6C! dJo2m&0˳g=?Vx7Jwfc'q76 (JFFXNκ̳דI\ fnZ 3sٶxO5$yS$gl`lT|9LC)~ܒ0 S[eKHj$Ne̞vRAS*l6HŪbQT 38=?۸{Z+,C8We&;xq)2QnFŗ!ٌ,v(Nm+Qy:{Kajd7$p?޶QVydH"!Ϭui9I)f rqq.b{40< jVG$?"k1cdqI y \{W񈉾ܓdv5 #&EAPꦙ m3Ŝ_`[ +wQ LǦ,"!MW]L\=u2aeP>%G7ܚ19߳ i(+8GaIB>3d[ɩvg$g5Od.O}eR=5o~DF~t yuuIOfQXΤj_XêP ttCïT˜uڬ< sڵG.)5=:Ը IT`ARG19}wȘ2e?}lC['sD7N>\Ky9+p] N;/w~a3 s\1T>?3gVl2́lkI_m%4( d/pyEOJqb'xhS" |꧱Uu0@Ɩ Xߥ"պ[ sc~ש-QcLQ%p` h\Xa2:ItHgPAݔ>o'*h4rQǼKrOLt}V]RZ@@ *kN1y$&ͼ63!yڹEGlt;9ӦXT}uDd:>c pML+d!z?0ƪ~aIjigyu,@~mct;C[_͜Nf7TBt46{_;WGD[y8~QDv t%k̷l]HB0t(iL^8W2b0A>D,PH(rd1sO* k>PP;_T Q7 U4e\9J6^ڣF >>M֟n#ۦBOO |$2n5L#CоDF,Z&r;tnst5tsncB`$n+2X ϻ<)9خ袝2JU=Mt*S&g^$ǯ}\jzFq;7*_ s2YTA{j,KY*E7>?,Nh;LIr5a@.gcS1˖u?ßwNwᇯ3}ʑfd!W,%2]zF9MI[@sՙ{u:X2W]:_$µ{ۘ5fi҆g2UO{. -N\@)G;g78VZN` Ӌ5UK='1F,/(ZE]Uk4zUUvVQϸlB!klg/3<#z8 ZvzoIa@m?8􏾮ܫ:>O?뺟/nǖǥZ ]lr(gU0i;[Cs[I{\ b >m:C큨Sp[?',=@!A_J.6ߴ<} G \sGB䳑_,McS2ga"wfS+&{ρt.ESLzOimY;ή?^[jS60;I7Xl Lsbf[Yv>l~}6z4cBuB*_y3fɥkEw-U%vس>ze(jٵMK*m!)Z6n0Ɔ##LiveX*#i[9x# nfG0e'\#Br}Ǎ&4Q%jo.lVrTT.p>>c!@EWM;%q=s ' .ՋɃLyYdz`H&E2ZgakJ-k{sYhzzl1aMjQ7Qs#".Vd/m,\n'E!3#nl-w_1LuT!p~Uwyl\eCz!s  *6!)/"y 2-K-er0zj]͌Wk9VeL.IJ%燖$07xlyӱ۹{DT9B?so/$ %%bÉ~Q;^GiWWR>)E5{Imm,n}Mn{>R !U0JUP ̝E)2X**`jʼ40N1ټ[e rvUL^Ӄ4h?c]p^"C==dVjtpʃ<wHgQ<-5|)=jp]0J~Tt1p9C]ք(l{1\cf >&*LЊ#Qwg0rWIqa.\"q :d,@r?f2#@k V"aSlo:=KGm,V}ÔutҪ*g>l}ךݥ7l'[EoB 8 G.{Lgk+ƥ䌲w}p )x&zzw .d0 rH_ɽc&Y15)e~WupSBJ @ f9PUFҀ}i4f~Uͦ3cѽ_"jK=?2M?JM,ѠL_j3JI\v4,@dZhΓTgҩxZed"ȣf1{>mAf `c}Lm?Fwl)⻏@ȣ; o$HkrUs?z\r,L-L4|G2N,T4,t ٯXX7}u\t[-*n/1ql23ʆFhw`\\NfKē@smrdΜxD65e"u) 83xRX@X:u2ҽ-tkv{#wP[0omZ@)aI%@&+Vn5pwnb04o0"7WNфX/[ro$k ԻeGdKn\g*.7isE5\Ab?psgH,@x2.4̚b˱,`44kHւ h6k~mA:^!ivk|Q&+ oz+uQԎGߘg7@59^is9=y #׍D,h~| NmMc<HeӵQX.ݬRTSmgCsJ<.Y6*ܡƱ8N8F4sknnhdPe$MUx ͔}:VƒD9^#fhޟ%%u꬞V9jAJyBsYكi 0liW\ D>AsO2̮1/eq9B+ZȂ٦Htjf,e֭kT^:OK 8bӏcE" D[2/>"ɯy3S€mv|n&nx߼X^QSҗ|:HScXc>@=NC޻ Fs -蓯[z8HZ>q#PGhdaV"(~Z׊I_;$dMZ7`+Aq>u^bhYvܬg#s s X MeKBݾ(?uiTĭ`AO"LiD qL_oJ 0,YЄC}E1|A=c?gy.gmtL{94n锔) ԢیM䵘ATL04`P[\U?[=ZlL1Id 1DWB:ED^ʦB1k6(B%2l6эR搒H"c$Xa[؈݌ՃE }>C5бJXVdf:=C|1ܵz}GmjhCKOSL۹Ï~UH[~A0?TL[ɫ, v p7mꪥB}5HTUτ 3R֟pMuDcEfXF?Zo9FhXƑN RiS4W;9XoG^>ʉTH*hL)7V42y T,bԒX? .ہ>#]|'EŽKhY'q}[{7ϕ_$3fKzBcKp|ƈa`m !c$Mp$''XK:@HJi̲*z}L١$x&.cSTZe0YKW~~ԊOS\?rF3HoԐ'[ɫוUlT56mey196'L2 [PZÚ3Si%ΘBzJ \6`p7gwͲ6Յn<ʄggF5zNwȍ";A׫mcEdm{L%ix}l#ZyLF(*,D$VE O BùcD\3_fUMn|5xxJ>-#mi/,ݎ9( tUuE 6%/C I;4-6o i7[ؐEy׵ Dzp~b*eO<`8PMJ)PٹA84zĊn4NBF-.yW1÷2KC u>J3e^龦q?1۰Z(J1ؗ;$ᦨ hʮQ dSFejH[ߝH5mJ`L^:S{=dEUJR okwJsn/8cz=Qmvtsw{!ym%H;jہRF 5 KdP-z-2鳊1/rxzϠ 3mw^%r^ƕqK%#掷 Ƹq~kܫ6ob&{ѦLK5k7kx_7$ɉDXwIO8ٕ68K)2*eEa/A0[x7MNm qѥ,";wF_l;i{I.ϻ68 o9yLt|Yŏ 1.M-F -X "u?v®_-@k=h0VYssRt0Mޱ]&uN1 p*fX(M6;Tucncq\8:^1$T=83A%zUߊ|~'<`~;+0\`e0ڲ' ? 5AOW^a:SgtpFbP-0(PE!Ë{]ۈJ#UqQpF0PF&)b|[$'9֨wDFCbŷ:Tg+>q5os_ZPe@=sljX 3~O ԏC%BdDBhM\cj|alFq]wWRjN#d#EqtActS3Dh9sm,Lteqpݕb3WDɡX^־z2}H˚t5ڭ&OfiUjB@UP4hll w &zK XB0˅n+4Sn @y auxxMA1@Bcs,ayt3[\t,ӳ4-_T$ujy>MJ>qQݙׇ5C,Ҡ '|1Qo c ,\3469y31smA9K}qS"bl"Р~:+N5MPP%YNDȓ"XS#x gK!^ò@,U)5jqIڢ.Uv ~Fxh5P]tzn/6SC7 ou-f~ 3&Ԛ!k%}䳙Q2ދ(B%noëKjYhT˜䊒ͦS 67sbBD.KAA}r^FW' l+"L‚f2v.>qks=屲A.ŤDA"H$$ADfw:.3BvEZkDYBw۔1U U0֊xR=DQ#+Ht֌k*mo# 6vo6KЕÍ;&aǑzGQ"Dzݬ&p\ -Zj3t7<1tڞdYJ);>M ᏭжY}>:)&.*l1B1J8ʏK^Pȅ%uP["wQ2XV"͢P[;w2Hc#s4x_COQ???Lc!RKZH[g@BBlazC2;oYȪ$+t悈DձH}vGTMnҩSڇ٥Uo [_<$w([z׭~Cs) CbڭX(N"dhtk3[DE݁xǿ5bfM R p$ |'a; c@БF2eqxȩ{&](0s1Jk5ɪ'$MV'_U9+zWMh4A9SҊbGcL՗7=a,e/כ "T^Hh GC]bKКNe0zS+:MVҪSrL;"yxةb~;g4PqZJF:M HBS;j dzS]ƣ{h7[zz/Ma5L cQNd>#aF3 v5\\]:,@: mf/4Eʋǃgp2_ۂma4[~~>56OR<.(dw'85zJ;u( tCU<.7 ? !|OZ5o96$VaD{qEJ*,ϗAnG'Ócǿ 0ymqb¬TeSH[BaL/yK9٭ vXJen &&WFǿ:.jǘ8Km#nRf)T\:s5T4W]G26F /e<|nO(A. 3qO cC]5c9O ܸ9 %.bxbkZ@-V6\~FXȷ! {IYn=Q=cBxCn yp7]F'!FPUW [2-BK3'íH\V=z Kt} 6-/s'# A*"}նtP"Uu 7_ggF߲a"s71> ⢉@PQ"vtHodۤƮۼC-j\g?ۡ/+r~1aKf.p%2~k Bb[ 71A} 沋ޏ]*)P#%c`ռ猼4L@[9~$8Vɡ`IW&*LI]|9h@fhCPN(yaOY(>lPHq/qfqtvVMѓ,\IC:i2HU5mUI5ccijnhz6JO߮4ꞯ7SyfSkxX<"KH1 4kF2y6Fy*μv@G> (oJ3jL^݅#'lH PN&sv3=u8D8A1AT>Q@`rSM-YltQ'ySD_f\o}\4ds?-Lh$G|sm:HTT+|á۪ܸ_cp).I%%sL>&,-'^Xa'9Ww/6QkˇH~X;IibŒ!bIB=r,v0^+?vLe3pU%*e]¥8a`b`NjO CY=Y'BsqE~\`K8g?b{_IqS =c/8#c38ҝ+0>W.{|Xo?:iIai]AxǼ3"OBqĒ+9cYńf5#MsИm5 9X_'5ݜ:\cPuavsP^?γ;sP!btE#}x\ @|nW% :ckƬش#oϿ Cwu'\6|02$tuYTcNa mPBO4V'(l{} ct.QXb<=.Lfc| N>Xn6DӯUw!2`UF']DN}n+/*nIr![|UI3՚,ͥ OkךX[bSyfZϿgtٟC2Ue}!k ƛ:s zYFMfe܍|ߣuZyjV|No%(/\%vݮiw!ӊi*dQ} `l!U50 ~T\`m72$'!Oٝ Hx9C8 u[v uD1EHAzh=3IP{TEpWYXj䥹6JS)Ә 4y1Ԭ|cZ&,vwNF(m|OJe(H,QNc |PBޣ!a?]XVZI>GI뤘~"|PTsZ{JI#:`n`4bkb?8VcTƚ,luo'|zB"ԥomU5Ä1 mj-ܾuҒihM sh]uYֳ.N.8MYW|h#d*_bM]H%ڴO:x͇flu"كg0KBƬ$řDH?P]%*0n$ƌB]!j.r1V%b!"Z$yY.^iodrdM-y^ue"[Oxmn,}D1WtxZʝp6[tGdboTQbs{fw>N\S>NFҜi5P$~-gEU#S0ND*Go)dWz\`|O`I`AT&Dbi)Ks%̷MjHk:J7aup'_sAB"˺P4J 亹Z>jq?#AOe]v( g aV_J2#~hPvN }H^9kTlYK/  D](V2=g}zgź)!ҢX^`j/QK:Cz6z#|64_i 11/`h˃$PD4ZF̡1 Ye>8fo)ES.*[ޮyi]46<$LuRHqP%*Y76Gʗ99,_Efb孤t(v%RSx8Uz]KG'|K#*:!i1չbIVt A %-8zD`W (*^H~i.֥oQt>Qi5`1;y[XJO"F|3ڿB]W#n6O+i5 ]>U`0^>FpD,<}lX@論]l֒9aonh_\ci|NMLF7>HF :fX&G؉m}5VEuz sHA50|lV71R#csel"ٛ^Q9 DѰOji0/.-CѠm8߼5pupXZ_;כz^Yw39z-ջVb%w)3:ls;D[u~Tov-'X)/R zsrpP*i-]g-?;V <~gynM'Z`miS53N&-K_$s0w!aCR{q{&_'leգȋtsaIB_Hac$?qCv"~6lLm8#,l~ >?8y[)\vE9Q嫁8keCMo{~@do}ĎN>NaS#T~;Ubaʃ~d)1@kʯX@2W}Oai栈So"<D>|Tqb}R8gOSr~GM.7⦶OԷzznt9w6GE v)kl3@b dŽ%?ϻe+?%)-_Pd:oi>jX*}Ơb)ÜH4_{e 궲 2-N,c@wg,,с" Da@&=:DTe֎C@2 +eB %Nn\x"ȃ o@:(53݄ZˤvB@:^,L0XbH*ݰ3q68zI6*FM\g & y\C7yL`fQ:^Uvl[޲xOUZU~X83Yn%7M"v$yo‘kg!E:Rڀ50w={ؚhdXڴsxUz \Y(DG?\%lJyxӎ1+i{&?mǼfXq!'!>aO0Ĭ\^;Cz|(Fq(g))eG^G0]YÇ,A{cY#64詐A /BP4F!F~N^f>Hbͤ{mǔ;CxΙ{{+;O}Qx75 %[t574Y 84la2fz#>XZ0+Ok4i%|$_ w&cv$$ƩIa\cI6^'#}UoTMJFtQ?t0eL@-"Eq2}^ ;>2<+8V{O&jA^tp{}9i1Yr9ӻPD+"(;45,j!~-+!>ӫЫ߭kF4Qr"ݠ\{)TwG}*g"ĽY1 1PzV.i~垐>˳ $IܑKa=QO)[$"n5ITOpSOaYeH~Ь 8)Bd|Vuj>ãM)PmJS*C/>7i~jB );~t `zaL #&-Sϱ#O7KE ߔx#D.0|2/13>,8:E8Ơa#YR1y2)qRzi"J]!4ILjOSW+XS_#SQh?=-+={! 2*Iæi|Ҳv$=mм:D}<~G.bXBJU6Lhd:p M1+cSYgbㆨƖC6Z_s:*YUl/ٲ+LhZX(+g2G H&g^;*tZ.K:߳-4=ig7MOb:l tZ6ڇije僦j1ƆqvZͺ*s7=1.@a)H%2Ɣq&簹РQdGoT! Ðo /p9s.?>}YVYD:is"uLjڜZ7Ymk^s8'^SF+ Cn '"bVTzoaޅS[-I@$@? tҔh*T#o~@s]McX`nܦtEJDbgDh[qyL[28Š6,Fﺭ28(6Bc.l᪻~.u\R\k'HIAd#?/N,uQˋy$ar~q;ν&VHb+]"1V,ymORO-6.a0fI1!Ncfˇ `{lH9ƅ?mӳk( @d'b/WAI e8A@ETwpB[^9&29zbǫY&fqNrc}F|}W礽ȲLPcJy0κSL֞"F4#;lr05PCmҚ.5XO9sƖCIJ6za*Eq5%//?F[O!>˛ ݜ&r~MbF{I>Kfd-؛&2`XϷl4 y( C~pS>,@F}ߠS'jveD0!@gpmel;%*:n`NU냇߾nUpW,Rwspk[~&I4ʆx% {q92)u¤ŵ2KGʾF0ttOdCE>qIf2Ҷ[㭥 zaRBc"W CђPMfGCmJWQRpsj~#gH;Xa1~`{bܑVXXv$N/Q*?gR$@ L%MމpU>P%<]\h澉q^kڱ2,Y}#btRYRK/)eL]/!Κ"5& ~R'RV$?VM\Vyh\.p|L7E+yڤ/~3Nt%1QXȜΨx[AKZ7 ]X}mTZU}V$EK%JDoT]E}N<`xvq%% $` GA\U+;-ݎ·WMܷy:~ޯSj)!ݠxUI gFϒ}Z olMxn\0E:ku-xgzk^; I{[lbcp%z8:+E( ԞO_dZzbdUs -7xhFڳ8Cyl[}L;98MDZ YBe"} մ&20H6d6Z;%~]?(!o}aAhTSAE༅\W@"^UӐ:d!7uuP‘+k8Ǖ͠|mhI5Cb3M]o/NQ9KlX4]RZ,iz]l6瑠pDǥd>GA3L&{ĘtX kmNd_ -X L}vC$&l mQ0Z{EAx>k'=^IuFu|QxF]-yd&Q\M-8tߥR煓q1 S@3+=֛ Kf}dc'E/qVc_"{8P/{71`A,;cP#LsL.@ &+Z&ȹxd}َ<8ӪϹP+5iez-|5llTɣ?ӓ9] ϧe0WkDٵp p`HmOH0Y(i)AyDOZ j8vh B yxt*f ^j#PC`!:r^p΄&TA"wn<ښA}2.ȢtA129:Tcm |L7h/JGk 5|dGrhiE /Wf[0#_pMC T٥İȑYE1-hx[?B }"5sQ޻2®^ 0D-݇gnCm?dz`6iP\@X<̨Xȟg0QqĿSI˼Ik7e Rs_[[A2ۓ"PQ@,uK )EyNi?pc.%(Pܰi%,]MVQm|/ y%Tp2ԲZ+*ߙJP'elP҈ YWẻ*=aoG*%4E ș#BbDĄ#!Dqr _9e~ k.-B *\Q]j2`j`  BF2M&y&HB鄘ñ|Ja4Ӽx+5Q>Oi$'~Q˷ vzh[4*ec&d$tL{h nvt륑%k lmo9awE6+&ozsvk_M4͝WF6DR[kZmRZda\ $TTX>EsxH2 qkV^TpYѓ5".?]@`S % d`bIfxd"yH%[? -Q^K񤽷Fշ~tod6҅uޓʗL'~Qz̀Y ߁7CFBsSC/٩g1q`>@c.SA{ uOrLL|Km \W<$掓( Z7[JQ~a>`slʬ2Me|5v1Haa]}Vv6u@%G<͡oFM:e#F&Ն'L kڕjsy!i3lK&ٮ;ƩEٟd+J J~oBF 849%A=LHAj.3XtrJSsVL@ Ie[LW)M]RPA8*b=1C<#ċ+,+poF }ްNj qӞkՈp2] q͉/wI}jsqHFt+ M 3b-^8>?4ت9@E|#zaG,@q4cyg FugEZ..*P8? 9t6*@]6>w.HCjsa!Soc+XtS^wiG=#UzB<>hyaLmG;f~|{'Gds?(ꩌ7#̹V o1vmM$ z?aP1`3<{) ICHe bәiwm L?*犨p96ÅE½?52+eoXƅP{75Yix /8۔Y^9u6JRar> p*yqһ" 58%|1$Pv>Ds;B[*Ճ0kl݇$^^36_$C6A(Ykd}F-0%Do[S~N44 >˵t*BԸ>PUE1s/ \lի=ɹA <[A2N8'>YMtmD-A^I<0 H f>7.@UB(颶 z\&Q B=`x2O(DҞY#g7b"0{;dQAP9yd?#PsR~=3GbVa你"rq*{< JGOni#8E95GYqx,˭ur=W/R*A-c^2tV;~&A#5*lAcǕVP7̎sShMzz]&d&rYL^!zI3cӉNT땀4O4\,YiIFGnP[~?A=CIǏ w#,m^Ng ט~S'HЕuHeƥ%]BVMpI/k,IE.'< ײ_d'5z=a?_S!?Tj ϑ&<4xna:[MϾyK 6'iu䜊:1@^DbK2L)FHF} gV-ld)W/[PPpՀؐ;d>  @R0܆[\z5i>E"Q:ߓXsv^U R{,{{Ž!?pRPnwsGM qPVSY2.Xhp*%, n:J ظ{ BTC.ls31[7 d[C%${a5G߄)C͙ձW0ЅIJS*|]are{/Ba1 #83vvByVW+/Y6."1dg ]ܸ_.ߛhKIlRb6 %Bu\ }Kѕ ֕ Ԕg2i3Wk!9+OߝKRèyrcIx=8ZF4I MGE/ NqkD\@8/uM0w]?S9a.B{b+l| ^#臗o&2OiQ*aN=2&xTZҨ~Q(!u,b^f LXw >O)̒?jJzP+QBk"mx:6ȍD:oEcj^H>{!Nx<"OTj"`ֶ0aX_>~k ͻhpBT1<N~F F ?V1`Z#5w]o*:CrȮW\5ZyQD'5g˥ gU7[m9s{]`NHG~륢$:+*5l??e F< Yu< \Z憻bXbXiҲǭW zkDJgm0hɗ<]ꄂ{Ӧu1g=ije$gM)&精D\[EϞE5vI8 _0T5›"AS(&/A4 ^WR K^*Ւ:|Tq?'7I՗[}[4ld@\J= #pY./~ ]P5 u!Igkǥ 5=VIw/\${?8˓O_l_u?G|38ArJ'i Xf؂N$M)uD{{s>W >mB-?0Bˤ; ޝrH:ءL}]ɇR1/THeMK_f(O }yQ]tLIYrLF<$2=ǺuϖK ?r%֐WabkS:߬gf?fML_Z񑶰:b 0ucdeTz$D0hЮEq 'T}*i%E0w`SNPwYwcQ7ؑ7tj)|Vz@{%㎣pD,el=g%7}G7CUdFV@`aVC o<RDaR$avD7}ޠu&֛h NSӈMSg]јHJc yL ]<ƈ^>KQBK r&@4Ջ75^o};=K2bbf+SSpJxYGF;ⱯhNoM\JQkq~\g"t̸*!@ŲT_/$G b1UL};l |=%rmA@)nZMж$ئm];_|f/8필KT'ҮJ29/լ3 &˰z3#֊&b'{͊Jر \Gȶ ?̎OqzxկsШ H2,eyFjn 3LWZo 3UAb ȌnԷ+ODxzB+ Vx2?sҨAENc;a՗biCl#2`_)sBv>Dqvyߵo>rl7dC\V,OW˾qj3#nBd4;;<9u[ܢyDPVKZR+^!QtT"[+*S2.re* ?# ]U57˭OËZ64*o$p ]ҒscCv'z#֞KmAtvYǍѳ\Q`B3:p[!s/aAz[MVG;b:<-'Y_$L: rD 8u~숱ʀnt<ȼP2-YCn:}ݡڢqlݏ :2Q-Ĩk;eswgZ+¡V@<q^< k['S*OKa.$X$[tQ8`D#i-e+#.UGͺ)rTᯑ' e8_Dw~rB5[ {sȥ{H& P{"OBσ*nmyE1# EAkd@$ ,5+X"-@+ Lsc| j tIߊc ]Z+DF*vMRqD( U˜k$:etێQk\ď\uGW.[%EϖW]t"-b hew!Yd83Uѱ8T,h8s4wβơa>[8V.O”!n+*tkOrWO9&fl,j\!;dFmf]@Ϙd7YRrs^OU7%qx ܟR+4^W&jw㶹A lpu4 }ޒ@JC(Uj,ֆ>8RH6߮&zGZPk+02Ly;m6\JűroI EP¨g?m/%ܾڔ{ GYx؁2׀Lc|ċb.w.=_Z' M`V#ACmμQʋYpད{@{% }l8JIt+{{ï.x`",j)0l{ԇ\AGZɞm*{+_b_B/cW<[Ck߷&%#-H$A ]ܚMaf&@}vW㎩ = 5(Z|eloIգuaD[/.)  Q^RwO¼o?7lzlgoL1p&ФqCn}ЈP4\07Y -e|R@ ps_LQvpmk 4BDz8Rfwhff4B&JJۋԫ鬂fM/ \[ KLwMr7y!-nhCP"PHi㉇M@}lz4dtj׿uj]۔ g@3ťD~UEw[bhr}Kny x+hc^yx)Kcz_88̓ko]OVOZ*~̌9y*MBNYd+-yWQYJnQRC< "0+fZZmۿצO F@ pΘ-!V',7=]~eb)!6/"ENDZ^h_O-׋f仹>errzȾk2fqxbPKdˀ0ԅX-W ZB:VȮNr]sX0jGg ?=Ld'(< ('P6[qC Ef?ɂ/3usa 3԰$h". PT癵֚W:1=4R"8Qz [A}"l> Upd1/':L.{Kx[g[zJL ` l# K:C[QmN>8&'WX#4ư;}caFW΍ѯݜi; N7C1$ȫ| 7Ѡ,& E7FqQ}:Ҟ;@dM^${T9dMElX.Y;UliΡ&|{ vji%}.;y PDO|F0 A/CՉso{âh́4}|91ہ ҄2\z#09lfO71MmϮF>V/`j63m4ēu=?E RK8LʰNy%G(eј0PpX5r:w?zRXi7Dz9"tu?8؞FVQAEtd ]nA|A quM:_8S$Tv$s1NAR:Y7jkZQ覆ie qglj3cFAzX^S$Blѱ nCj·7@9!D[LKs'RەQ5B'aMɻF*H<ȿjTȦ<0dpxYn#/:G)-;>Ei}@h;S0I =?:gSSq<$Z1 w456Gڳ`˨.>(w89䇱Ҡ̔QR$uu,1~Ǔ}m5f:[S8}?f9(>snDx rnAdrpչܥDu0P2!Q ΫSZ / } Aqs&-'h@W*֏l `"|Eb.#CԴS&-01xx@Ba?vv@SmvVJ lBZ(b2\ DzKKQ^&ǻ&+hDscyH[DL6Α'3ПN#%c/h G-7 c}=_3AcӒEkTҞwځoqlߒwkri @~>%>xs,GCmԞt@Dl닧5wOE=0 eS*:/T%+~K\`뙈`AhH:M*?KϦ=9d+)*ﮔ@ݕ\?*I%YƋJ.=./'_"C~V/ vg.fg/BJ ] S&9 (es78Jt}vlݔa&OxMvwD YZ