sssd-kcm-2.7.3-2.el8 >  A c -U]5P4I) ZJߖ '!В*?yw9$ʯ@T.A1Yy@ڴ}i-^jwXa1&7]8Qzc]԰N@ƒy5*Odq2?d' k1TS#*Y=Ns6 mrGU/t#)3N7=Dq}->_u49OmK"[LUPȶq,G:2DjA^u5>Y'hHqIw<$"婅H6r4Nk;DO "YZ$Uk?)8]YE2LP_Zל W!5K 52pza1-y^1z3+Koei1j[MYdɉ>>nqszS"#SET2հQA! x7?`nrx98d.$b#檦 %@b(LQz p,}oFEe&*w%IGߚJ]sjZWZW iQ_?۸փwJBrCѾ`F.&(<>C\~2B<_6A9W{Tݛ~}z;,9;(y_+/Uq ݆HGwwE2oēwPfy B+4k>pB?d   B 'DJRgx         a     Jd :::(89$:e>?@G H( I\ XpY|\ ] ^ bdeflt u vDw xH y|-04:|Csssd-kcm2.7.32.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.b-aarch64-01.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%6OzځAA큤A큤bbbbbbbbbbbbbacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd4799a01adfd7ffe087c8450b79af3aabcb7abec0dd674228bc37e7e1e953920c51d9546f4a7f6b9f2bd861dcd6c4a583d07f721b6bbb334de4f4281d283537604b4519bc951c6f6980efadab7ca4cc9a8ebe386bbe1620fcea95f26377781623980833e06e46e22fff8755514cf53e913f06a2136d08ffb2d958e942fb3bc0ac8055712340173c9263c5b2ea7060fff02b1ee1c427e486c7d128fd0a53dd4afa6d9acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.3-2.el8.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(aarch-64)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)krb5-libsld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.7.3-2.el81.18.2-113.0.4-14.6.0-14.0-15.2-12.7.3-2.el84.14.3bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.7.3-2.el82.7.3-2.el82.7.3-2.el8 kcm_default_ccache.build-ide7adbf54d1b3b2bb8c3659cd22ea918bd962e0d7sssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/e7//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=e7adbf54d1b3b2bb8c3659cd22ea918bd962e0d7, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)-R+R'R0RRRRRRR)R R R-RRRR R/R%RRRRR*RRRRR RR!R R R"R&R#R$RR,R(RR.RRR4utf-85eb21c5287ce5bc06224d63cd1e799137e7fc63a56a4758735aec1b690ff9645?7zXZ !#,e] b2u Q{LT2ØQC"֩kN͵%LB~2s?q^hW]4*놤-E[Vj#d92l;QLɫ,X,]+ ,*kWb%>Yǩu)&@FUo)\αPnXuHGb;ttnҁ)1~%.Ԩv8M\"G\SdNDp]sns" %4/Bu7;0-ש '%wK|6W< ~k`zi,<helRPxmAi^Uf RHgq]sn&t::UB4caPIRrJ`@,OԿ]Pc X{cZc؋M8ɥ7P!e=60l[?ZWC6b|5 =@ Y!zMxNn(>^Bn'MJ6M;vڏȹz}eK*xO|˂tyA y"?7IǨ)Q=6m]KQx0Y<1A2̤n뿃: ًh8b˖^R怛ܵpc 7'+읁U_:ƓV+*OT%Zɡ 3#X9}]w  O[heCojVDTukF+RG4˸pA4~F'um\hb0:b.ق4FT&Ăn @$ [ s3e)gw%˅!@23&ϛ4Vr@DS bZZ^=ݽ^sRK;PZs ZzW6 qaqI(B_1o]~m,A$Lseg0u6Hx 6IV.pjV#MQ Xw6ȳkPcGfzkBu.Z?>A<ƶ\JD@Ŕ#ٕ( *rY*`RwHI O-Cӓe/ӯΌ\*(s" /~4,&U#p3cXb|N \֨~s0cE`Nt u2EQ\>†Cx 5FKX^P؋f=̓PTȞ;Q(Ϭ{w(OV؎iՅ̤ -uLFXvhxfHI/z0j-Me^̶KD# Nx$/>|Ƭ%$SqJaxOz|tz )7VsmHwAK/Sy+.y< ogy?|~ע.*rȦ9;Rp=é /(e"Yʌ*]՛zkXa@#N0 2*;^\=/1"G?h{ft=w8wHdLۏM_|6蘊fyxI5P2uV̈Pyh<+p<ȱ1LrIImJQEn([GmEs]t{0ՙTP@o1>!.N"[VAk+l3S|m->>VBnXz1&gҀt5d.C*D퇚Ĕ"&j'?sl3Hf] ^1BrUAmQAK [}r%0I}P֠|wPa  VN7"`JlLnU bKD[}5UҀbb6ptpEQV2Z rA29tܛmcDT0ƣ&恘(ekxͻʱ!yNn5nS0kJ ׶Ȳ~cAFv!Eі8*%W)9w6|+2',KP&nɴG+bi^hɥ5jN~-$+i[UMt`ߍӽB!ZR#񠝖a]Y(PķC-JR>[J{T{ٟ9nỰd*BcvmF`QАAw , D ٿ֓ !ƖJ^xAP2\Ex_>TUcÒ*՞qK*~T=b}qH?((y mܩ$jx[(z#+ q2STBnw;%ZfVR!y>h-"3̛!ȨYj}7k39 ZO엥 V~t|g$ mć_m^*SoC5\L-ݭjrB3JլFϤOQrsb6vzt6x:)'7K)WUxfM=4wIeru3=19"cuŬH]%YgR>݄}lw {wsߴ9DFI|Yr翝p hm}m?ѣpgB%D+FDc+]ᝁ s7d]=t#p3HMdXE?-EUJ_M|1S d!sJuGMB՛wa_pq2\=M}L`r2"*Z5*zWHT" %k >H>[WeJC{hTH?dĉf0\#YJ!R25K&}BdkD U3nH Mن$37KIqKa-vZ0WM\W&f 2}[Շu@j1YQEj~Nf(dy/Z+/=IN\rXApԮ:(9!f;ROwcqAT;%ϺRlQKe8apy6vpqr* ")76_hWtvZ׏CMe27lH hn^Kf, L[|R_8M6նV3kkXO؏(HYPUfhmn v츳؅b\)յZ#E@EڷBm_ % c]SRЅW5 SmEмD2yE6 P>.1y|i%7֚^#,&s?*`j}!9nOK)̻Y䓨+1&LMf1:Y?mi ÆF7>NeŜiR ӫ %T5No|3lwxyrN<G~(jWtcƖwɨ g.W] .50&QGW$>FDLC.׀M l5O8kJ&Ø{`˸ct,s 3`xֱO'QbUfG':`IWR0 BhAJ!a~/Iav<׬RS'6z ǣSv\ VFd7v`< ;Z&^2$T&GD*^'KF j;ܓ(~a\`K7'ga>dd, /@5t` }<ʊgA\q&UTBuډY%ZC_]g"WqCLed4@Ei7~^J!EiG֌0\Q GOף6/fg<Ψ O~jRc1dc_<\fe 5yEWӪ՘ZO;edayJwyfyuAg(`jkR-/UWGhpml T<£,4]UGP./ j'+L~ZGf6>ظ\ ?9BA%dN M]j{tp[j*XDREz;css{5|Ss+Phz(XAxn^Si4k:\3zu)ݖ4|/uEM )G + ?&~RfYcP d:px|ysj=-;7B-1jܿ1,%n0OXO!TCDђ_9Y4 yjǎ,uܷLCi$:Fi Jr*8YBc.;aaQE=ob:gpuN 3pgRS2B5U}~^yeX?Au3;eBILG>fv.%ڿw@Vܸ,* v&DT¾pN6iR4rz6rdXaK_7Dſp␨\e+m =ŁŖ_M,W` ш@nX4k͜n<21n[-~(mK,Ǣ:=Ѹf~PU_=iV8FJuzrIS4#+UT⠌sK8A$/Ú3?(Nr,‘azh#V4@=+BO +s3H$7A\X?PM"G`n2,Qq~J<NyOeL~c(oec[}9$G k:JGA=71Os]Z#G]4/ cUjv%h'DU=` g|_|DeyTC6ʡX~ GMfPo~2+\%l?KuEMoCUtQ9&LdݙYgB~b%2 t=Te~L_رKיg 9?y(zl9o6Ҝ9[ĢEvKvս?+I5@3O-HѾAo 9 dA6H*:ʵ)(?Ȣw8g)6pwLS*"h჈ .Ow^5"2"? ݬW7ăwk`m.4rU)SB7zD1[eA\ K v -@;U&  \VUzH rXwḽ 4z}X'XM|,Z"q x[End…xQ7p@x|mʎ&>r&ahYiX4t8V3Uk7)&)Fw$l,FCkbNxs&bD7 mvE{ QT0xP3VJs.Z% * hAnP؉72e\(4;v?ducH)ƩQ/RIP2 ];-RiIvʹ`v |$ N9*K ]\Z;5k rGg4X{,^Eyi_d^R\.&@KA'OU21woͻ t!pq\qPso@ChڞZ(t[Y _g1靮`5n3+8→ n5[ri&1ͤwRh^ |8xb 3C*GD 1\rC[%fJSD^;.ϽKȞ8k5z{Fam}cCιH0izR&9[*\RX@Vx A;4E\z.ڍ'ax^Pw2.2v ]+I[|o}VHL\78q.hq'cR5ٰKZ"]cIʮ͟tr+f4bl'7#ދyZnZ:؆pżѢ=;^<ȱyE`ӑ ڥ+W҈ZO?PTF=R;Wm gۛh¶wR DUvw|@` :NfonRG+[i2VRȹC 81oSA* szm;f~6PR\GlCdv}!3UJ8*ѩ @Y(C_^}4aMҭ~k^P" {xK7 (xiIx Hth~>2 ? .(7OY6&%hlKlM%C1Vv5ZyY:ѣMb]PUť“TNk9ˤ1[OIhgoD,_C Sl+Emzx;4uOu¶ D_]Mscrʋޘ{3\Gmlh5H0%A&|.e4aIB4y @^JI[mB? Nܺ V&+G02I-OJ4y6:ZzG?1!/!=vv$HDcG2RM>3vڟg 핉>λ#mSKԎcw590gNC%&ݱ=QNcNlgD+v-T&lrvicUJ)<DFT}f:*xPo2k/$L̰NG?me<ֻpޥY;G|k.{Ś =H){\因mQ30\@܍0߅k%e++\1b6WKx)Ţޘ^G&Ufcm ,qf&Mo%~\S&vdHո6[cw*"S5u!~ ʩWa6&zwqV-wKK}bQ=1w2>P[HP#+kspd谿t"2]^&MgrDU:"̘ ;/%kՏ'dD-Gٰ@,czm8.d]RR*k4kdt5C)/OY?Ek@RÞKep/E<|$O\x<鬗(/ Ђ؍&e%(Q`!30!?- {Vg KCz"L0HjlW 3qyA|)ERnj`΃uﻩR!~4@<Ң .J$ؑbRͳd #fJz{X\I+w6Nae|vEiw-H!*7) 9:z%U3L' w7 (y,_'&xӋdOAyҾx4#ގ .[C̑J\" wHO9ucQW ך>*2 nn(ᕉjuq2vg#׹𝔐SE5EhY^G2C?@aml oJR f5inm;7$U<[Dd!^YK$LnBk>4kP /T{^D!Y[UX:>,zhBoi`w5-4.j;S'ʽPgD~k|2bT؂aJTqx h^~f}0YSϴXL*7Fr$UHJ&n,l"ngkQ/(0(ħ <2~%7)8G7c)g:FÁmG'kC)fpnE\&&rtc٫ 8|8á42%c D &SjZ-fle0>omu "uXWޚhhZx:}5˯ 6F})\g,f3r[F0X"e!r[*Y.EWsqk5gGII_XMjYc NTbqg Leӷv*Q-H9HzU|D,$m/yy h zA Nnt ô]RxIBK8wzm_ >/:_o"ga'v'9 vQJ{ ƻ\,vF<A[yk! UZrPD%6 q'=nWsurp3&lU~d1nLKqX#<3G0ȍM_6|]\ktKho:'9T`u,x$YG9"Y6X9jlB%QTbaw0 bk H@XK3Ҽܙn~zZ[%Y:!p)Yzg,(KucA$?D__WZZxyw$Ugx#B+ bIF$hht{xH.AjD UhY|f¸Wtے:\)Lws)$Ѡ\Io3Gj^ kD3 W{]~*d.YJ?.aͲaT [(WAK/l #òAd !tJGY8M[1jL4vx(K˯ocTHӚil2rݭ3i8u ɝVYp~*E ܈7gUR7 9, g #^,<#e%feʫ6eRgM({=;fɏfה[䒳i&S, 54f`J͂Vȡrm|n(rj>IAJ~3 iR-DYЂTZ?lSw+eHC?A(<9k. V"Pݧ@֏LHkLG%KX-mD- Ε~[#7lV4 u)к  zqqy}^5vr!h }Ԫ38}`o[c8$ġ8l9pkג+m>ޏ<>gsME83eym: L*g{M2cD-nWNUMY {]O JDך~d ڞ;Gqп#QvZ .Vc1g>H.eЬ\ ˚&KV\^TܮZcHQ#؁aѴg~@h!a;:BZdpRԖ.ۦpEyv6huѓ2Y^-mTjg:?* is,[XQZg<%zBEz,/MA2ru nഇ&'Lm (SacI\P4he}=:{_&{JqgL +塰s \0|."w|鯠ay4 Jw*2[v7T$6Y5HE#/UruY/{W12SGBKIXr'kMO|3%<x'uQlB2}{} D=z*kc\X0*qε/*RIDL{Ru,.#0f c%w͚Ҿ/IiڦOt7޽gYD UWذ%bΞcf J3ǡۭo)2<^癓s_z/qv!Q6yA][3ڌ9ef։r`Qx.ut L}CGdl M)v"uÄ>>Osz RbEf,)2KCHҫx3h o%8EB1"Ŀ} JtE!)8j$şroƖL+fmTXLAY`Alr!],`$mJ8XƈSC XKއD~:(#B޴ E- gF{4GEҧ4&IGe<>6H)0S} y)q)/u{ O[DDlm+nzT$3#bL#`GI!;n~ĭ5:j6,e'z˯;e}S)s!qȨ\L )Ą] 2 l ˜ҍ5=~a' x$nl9fKL0»Zl^!LZq!F%.X'&# %y4deVTYR4b [ 4ql\v +V!3m=]@n@WW:hd!d\&L4n~5Rg*`|+ ;1$E#9=ZFź4rc :LS'GXZ|AG>Lk}ҊM9ҎsZBu' ƺ*/[uafC9[iւiaGkGt$}q,L*$QPQU[VSͽα79:9U{Q :"MD;b\ܣVdEfW8"&Q`"wڽ8uv<3 ekzcjy3$8գzPN8mA[o!럥þZA"u'R|F6>^{/1;"T8tgOV%du ;*c|9pT Oķ*NE"z87tSZ OՉ%TbÈ5I%`q2}?#H~ZV56 UgU?YH &]Ԍ^pV ua%q.Z^xm( zPEyqWp*hxJ8~|Ib_8+rS{g'Sjv*8G{*R=:Xz^uLKƪ9_HEkA5)jby=FK< U@"%oἫ Ea ef-}WԺq{@«XQC1i3ؘz.hJ{"Bb%<`ԩPwJ,|~x`.“Lw$.ej)9QP@#nĺUT~.d,pB#L;NEwš,]JXDue;vm,"[:spl4,wse';T}Zv h[V=VT,a_oz\U'c$ r&8ĠBK@ VSYRkrDKY`NɤqK+C:$-vLQcsv:ZW%E:aXtR"y~,>ĢBVA5B:Ƽ }&ݭ%'U(~[Lk3Bcl/zR|p-4 ·ɟÏuPʿ@x5 $lDH^uw(cZMoߨSRX,>Md1zx0&Wo)l/K/`)*q^;$yşuh°~B /ɧ_驲jnZ:ϑw|`^ZݚXph !"c;K 0I!ioYLMIWKР97l3<^i㯥W>c'x溌]bhEPB6!]!Ou'=m tVvLNJ3M`kJX3Ƙ/H<7Il{ WLBk#E)@b,TuU~6&!u,i_,UxIŖ@-+1ZQ\ $n|l&|'9..O(3OOw-eR@uÄ S8'ҍAVr̩qW| e:UDIWxD[i0Ajp /~CY$CCk tպ~9tۜX(swͻP4Bn5ƃNW לr 48l^s^HT*݅uC/aTTyAZUv8ű~%Eh(+oǯ: Dws#ҟM@pg*Jedr)kfϯ#B]T9|%XR>Qׯ o D>mNDpƠHփ"4:w3l[ˇo}v6$;BaL<̼bUK8\M'Bmpr/..,xԴm3{TdV:$V|kIQh6 OvK p"wb- F݀VM Nm`4=on@tQU܈S-[O׫^&gb$_X~gz 08T6-ӡkm(Xq/W HZ1(8bzbh +~\#{YF,-5ўj"<шs>'|Sv'Bwi![.VXQjuBKKJ%Pk㕖iPwd'.nKiZ<ڈ*&~bM5;d/z} rlۯua<9e&D[7iO:٪P a36(ZonY2_2-FLIdÂEeE P}"ft`?=K#1lG~ص5,p] ˅Yt2hi `i6F~TY蕸B<3b8-i "~i_$Du!֥.6䓍v5Z}|8+oz v>0pa} \XGkҩ| ~-QS5>.zMF|1~l t*2#eoxogXɌ mu N{#hI9LA.sP XonM2!b 5? <)Ukw&&",XR6nQ{,-ƨ\C&Km߬EǛ =|6S5}6 Ygo3^sbb}pLΫT?u ax0AFLUPK#Mi'nSP&snh LҬeS98FxC)ߧKɭF˕WcrTㄕ#.0AzDuI\J&!23@܉=Rjp?e7Ao.Q*N!TG/SBy@[+y(Mo53BZ,ⅿ{In$l*jPMdZ16 pfV882ڕfE]j߷_Oxwo Rc@~2#_vè|IxB–;j4שO74:-N;.Z98ה![ɰ^KF,gڝ0.3P \S?x3{4(1pPdUSvwz~r11 ;ac 6V))k+1sG3x$fؚj?-Nu='.5tX!ațys?oߵ݆<"6u_ 8֓e:91,VnYW DWsZMN̟'b5|?)if+9#׿&W:`ۥL҄PSoI~)AZq˘-\U@.v1'ܤjqΠ^ḒSsưTTi4{sdș+?`Qq Χ!FAS7d\i?BQF[zzxϦ+scLV ,?+q4'/<+gySmp]kI@Ǟ9I_͇cƑ^ %b1VfD,AbSl|>8s8A{bnC&ݙK}_@j~֔+h"B(h@rBWT]e0?|,yt#C0l^΍|yr,.tW*,#vY$)$8DWlЅ0R֩?uݷ+v r, Z%k>ʡ>U>%w| i<]rI0jdx-[qHY6~~[5fC{lFNZA}ږnYeItKyԺb-Ȝ ­_nU OMC%Fdm< 5Ȕm~5Pzv 8mzK9 jpx{Lxu PAнj/إ6Ezonw5{}: 8-Ɯ({E 6菿YS%aey"،V;ӱaW*dc"n0yXxXQD=KT:ў!W@BtX&f^!Un.k+* EI3 :W-b_>mYWIfJش``=*FBm5݋ZtU gqb0dvNǽ:|ٯa#煋8܁5FvKYu@gHd;HE;tNo?MV]L>ʹ>Mi4q'b)h ebM0yG1pJ(0KqNL/˦0?p#pRvS4ҨG!Q利M)d? ^pML2 )^y:K-yU"+uը 03.79B@0 Og]3vrob^J2z+D/`+21,\M制G 09L6aQ4#f岲<2K_Ԃڷ^h-7B-=|/Ď- /NXE+0GyT^8DFuiw$2u;M+E"oόT) 1=WsBފ h/qs͒=R\倕xX&D} B鵜#!aۇ.G<{-\odbE5 !?xdr95AeU2z?՛0H`(fGRX4cvEFϹGH%ѷ?!kvC31; x ~ShHR6T0m6v[c)Z&ٵ%ѭ <'_;&c1 Sq߾3]pt%(?N9Z}?bg.8@{:ev'o-KO藠-O{%N+n+X"bA%(XΑGrzIkykiyt%p= .5<[DV]6Z$&uJ * |FȈU#^$fDi"I.XgT7j7z}fݙAbqy'} diWvsp@otN}X</T*ԝ، A:D!UND.+yrPIlA[L`G[N%o*U("4~#L4[)betU'`4քa!@2Fd{_~/Ў j~_[l߉uz)j!Q&mcı7oh:-2Dn7$+`HhD4`})6vĸ"хN+% tZhζ7}E؎U)KB,!brPImdoJXK;ֿ@x27BgJ%Tu}F15#^\iZ_vv3aIU'*v8D޺R.< b '&R\?sw}'Ces|3'o.S,3ku5y(0'qt]P\ɒD|͊ȜBWȸ~, v<(_0N⊯v*!+LcdY_" L#6WxX}9N8B]8&̖g,o݆-p10 XG` EY(;ϩd?A{ȶ}#i: X~"Kn74gwc[wF̫J,6 \Zв}z_~yɳ%qw&KPbXz}1B [&';UE@㎡X40).J;|%o7" hS%eGh:$0 YnG +B/ oUuK=N_<GS2 Tm2pwFs0~*h[BG,V?2@ RV|,2T$I>/6Qs5D뒖rd:9} 8^[m)Ouf@%3ׂT!Fͼ1^M+*f7EUvau8 cMiAVU0j[4[<(srq?ŚE"9{v>4_Ψ< ͯCI'Cus{˩=g>&Ls59jk,̽;7Tkc|ذ=M;JY YJ6pr^s$rXmʯ}Q$Ωf$)~txp鏜;Y~ O)g^~c=Um m.w_aYwUw4.qDdL"KDՊ@v"?ͼHv\2,5PCO{IYB{ʕZ W3ВyWdeIQ>\rGVcM,HTsI؁aw1AljمC%/N]F+2Xԙp!FT!;yY>fyo\+ 3 G?`#4JԵIN Dgwť yp&k+-l0Q$eؙ|Uo˨EZ\@PY SחW)Fx5$]fY_pn/>4nCd)DoI&xywCi {U4IGj2 Hx'vfz b`~hJӽ\"͸! hEq-0v?j]p$n j {­Z" > K0@W!upo>m) ?1 ɯNFP a4Oge1?b@AUGq*y\>S# #8'os߿Wu4G4 ~zQWwH]"w]&C,\j~אk-Κ<`6|r)xsyְ # 9L%R t5z3H!C*]ZA&ypψMQ N.zFaR#䱶z6F,d Ag.""rHJ5lX^wTQd[.:ܷ(&VYH}xþOsR'!T爈(>G[} ФEܕ=̘?Bn_WMѽ-$:"F]UYwGWzD$ j7򬢲{?P`a^Eo}e#rLwbn8NmC󻤛|SDQE;`'!%z+z9lk ,pպȖXs_ePLc(DU_\>?砟#(?5rj{5uJ}} ؄M~ǧ>[ɻQJ++8suZqd9p߳ߨXa"~Rde~ NN-{ؿ/I2.x}Jr&8=J|@oqHGzR`(J,s7g# 4IpS܏委϶kJ L^_t uv] ܄:Z4êkè;PT4 QXv}^E6QqΨ%<W'"yDX77 {f.%/nVΌoZH= Cf eq9ؔ5)ڜ?6z *6βůf s,|TT o4h{E=`KwZ%iUn_6RDv,ѧ1M&+Qn&}8+ 0E@ J)j3$ He>m+W,Jew߁FC C|Mh"NKyd;Ծ)CPv)җ,w1%DƔwWFeGs >D֣AG !=sV}C-BLB݂\I^[Kb)}C5쿩F&]$q& }Ō ԗsT.4H`E>k-8R@ySWEm_y! ~͇C)"`lxٞ VΔg |fީ${Aoy{emf >rlʻ8օ,QêlCN$z\` :~\P7ۀQBϑ@'rĘP\ۗڰ2ݺ*=gQZ20C-yg۸gv{췮;v6OGp u.6"T Ot82C$ƅszqƇ kōuBM9Ӌ A.Ґ]j[Į&ޚ&*_[L{ͬn6 2Ʃ V6kr6FKe4Uڪ[iP"p^1rb[c먫>lLgd[ 呃\7^%^Iz꜆cF 5?O5}?1GAbR8}0ݩXI]#(,{󗚙S AmyG \gNtn FJrE-*+7D;k O+{CsjKϮ0qӱO1΂;%o:55Fo*2H#"T@A}ߏOeHqF 7s]95e9S4V ՐĠwPW;BH|bT  ?0mAԪB>bmZoYN%=@SvՑdXSEz &Z4whbiiKxN:=bHLOd VNQhY9_]J @yڌ_sLVkM'v>6X*ѻ"`cI.Љm$*J4e|y(yV^ od/`O}1HLz K->EҝpEC~&q @o:Vïm]?uk4aق"su)/y=snUSC#mK %Eb2' 5۾?Z" 5$CezJx!=Eb-3dԮl6j=|([R&tëYAE)S($9I3| ^cW#(s,O (*`Xd1BC*,|W ?Tk Xj>=V}H XM&A0u*ϋ$Ped"/{L.|cX1(j7 O w"k~Vr9O}N^[y(Aado#L~<^p7J [୾:H|R~Tho[;[$eR#,%S&U{A;P7EuB'SeT >m~8MUP2%+{'JoCWV䅏l9ʚ>4 ̓ T7p1ƻ1 q`'\K f.v{VG x^5 9ڟ[TuDz´^l>%j!FcQC=w"6Q2Tv˧Ft>#8Ys t/joеjlV/G^D.D5&KENMkFLx[E(bH}ճkPq݂1g X>6b!ʢM; ֑ZO[X2Nb@%l bL[swM^<} 8QKU7̳]@MoN§__E+͙rT^rL#?9u| 8\aw_V) ?$ jC`6I_+vsl6}uSq'˕l%(+ ;$uA4{N5;WzUy/0xXo<#|s<BZ6;{H(> ,>XGc0X0[]]-f7r^ ]m ҭTqjR`j8 kT`K;: '&ǿrEB=~D(oe U>N M2 FGV0)1NF)IpqvJw )//'%>fH57]+˸^x@N=%91# yjGi|:`!㧱D&:8p ɑa$D4èV4(,ޥ{XqvuD5DpL V6Aצ$/gj2[`r$I, |lP`q_U 8BMg pl|O$2%ec;ppes? ,o)]K&ôhwd LB X'6Qߎ\V"ogOpzko cu줇[j䦴Xy:4P5 % ls]Akmol_C\Zg`eexf5eRdumaT!7:) LՑ<HC[)18_9AZ!eD. ,EHEܗHrqVcJjZg+o7wyͬ0ѭ'oSˠ%Y\3h..-b+nf|:Zr4!gy= +CS/p&+o@zBj=]5q4E><Զ Pt [3$6ԈM{uQ$*}3|G :ׂ-a'zZnWWUd ]SV&/7o2sM:C d% n$M^6VxuS)^;$!3Zc@}bȰ@#2;gq aUDdSK9Od aHkz02ap-I9Cd<_[ XUIC:NtnUfߍIeDm$i c-ֳ48x]= PF "rob(Po#;*Pon>ćI@]g莛Jo8g Ӈ+ \ob#̪ >.ėWb/֋Cq`"YW[@2ƜeYKAcɷ;.#^[H~-"w~7TwE}%6&k$.efRعHk˗fkrĿ2#wZXC ;h"^erv~~8]< o>Uޤ 22 YSfa7ۋ-5ئĥ9IqWJ7[&3W e |PnvC4b3#[Oug 6sHLx:,D%/1~a" \gꠑT4Jt5cmGZSܱ~>ˈ'|/,tl̘1?NL>Z0qhY$P{-+s_277 LVM)KP}|{TH^gu&5/*qS]+lCq6,Atǵ`v4A0ݽ ×"'8\Z뎦 .2Vxl1U0-pMc o;2{T=E/PFؐM$\@U4UDʥ³mg(|UC>@lƝv ;Y\awX߈2&#x>F`t\ѐfȐه*7/#:pΜi>KMvbEI H쭡 .vאb}bawAE>G^S=xozl4(]VǍAJMpŖ3CCc\Y7Q rv8 Up}[k-39|;n=豴\[|>YDY==aV=-Sq>àZ"4ܱ*͓s:ρS=ͲѳI"̧?wiCeF;/ `5 p|IWu~+~:1ü~zSgZ0b }[C@pY=6sEfZ}^(6ˣI fգ]}IW% \J˶/]ŴJ,I"~Ay&/`Db݅WmGhxgd¡41rKE;͡M w6^qp._Dv Jm fvxhFϵ9 'nkGjsG:lm5u. w@ aU fۥ7qx&~j!7a+;o:{}HRXsKS{aOu1σQ*4L1O!J,S7{Gy۲5reW9&AlGtnn/RnpG8'] qҾpb8+ÅP? {x;Љ"xͨ+ fXP5eQopjH+vAփzhԟDʤo$I@x+nilUx n'y%,UtzKいHq\Y  nyq9)O|vKW=O|;Y 3ur-+XW_kyfo̦p3)״Qpb<&R6ڌ>B -g؈{M3bm ^(ܗ7kruM-*KsL"ӄp1< TM/` AVΐ8[0ĹtJ2qJ] F/伐TKu֏L5tK+9lJ|@)tOsG5D_cO\8xD6x>_/sM'ڕtjAA ;_pd[:e[4Ura% 1hK7 vLsoX?rYHM u>#$CH^: $*M|YW7҃5O'OR\C_h1lf5s{rÖLbfL /Ԧ.=]\ݪQdX jsN(juP9 .M]֥rWmeqP܏_-Wa3mߜ<(nkHH/LNńɓsQ ^ ִ4VsL!|<~Z}[Z}I >)7a0GSy51mB/ ՖdYhGr<1RX!+#݈g! JA.u\W&NHdL=N%9pM7i/?rn zf.%H2­/;%ۓm򣺗ۣ\Jmfh}WԻNx]?3;IA9r B]kL{oQ=4lOR`cn!z>JZ7RE}j@d(A(3H0ReN.xN޻6kxS#H|,AQ˪_TV/,:g@MhmH,Ϟᵊ[1[i'x@B?9SCW~!chbh1$YTr%2edCݪ٪ŌoJ.{Rò/8|0_BaՋm )U̓7RVn4sq9@?fq? epxd!^n'`ۅXpCJnuU&A+^zko'$]~5[^4R%#WǿPdtVzͧ9]N|/ tQՕ$eLÒxK>ŏf@WrIU{ B щ`-B2ߜYsͅ%B}E6\rAJ('SjU2zbj&>a@bijKC"l_oGO2h  ` >juN7֮)GB&S:// |R!p§&HdK/9]kKwFroBc͔Й~cVafF75GNXCx`._ "H9YUlk>Z37pv\ONᐛLA6F6nPba@c0Xv)⽜L.aABFr!j%J G) V]Qo O>: FEuuw¤e: (Yơt+DOMUaLe j!hn۷>0e$qR]U~aUw{DWt.6V7bVtq!u+y5OG`$"¸AbPL]z@⯾=7lmGuQ1[E8D eWڤi#cX O^Ss|IC!IJu #aΌ0Y6͙>=IZrGגrG| D"݉=T@F&4JXk x#֒ͭS]uL{#QEveg,4sKq5':QSyI_n+Zk:*T,\Xx$R {t'`\kn nٛ؈ @Cp{ECZ^\ w=lCVq~Ђx!*M]7rBg†+*9ۤ9 ӹYM-<8wV~`G(JکJ3责ń8&ܱ4v867M"#ӊ~b ZfAtdH_վđsQo#]y()VZ=er&`ml9C8c1nB$JoA ۢZ)qdB|:*R*]Bc h<뻆%p]`L [i.y0v \p+^W:?-֡$$;9 mK/EtF-?nLl#>%|y$Wk[SNLz.aX'oCFGSe!sx2( yw2WYVtlk/t0ί'N*p-"t^\J;'.Z[YsҠl n`YMZZ՞KdxA \m06=Ubb8ǦRH?ƨaƟ&%z=7(4-Ki*#c-/^1A]}7O4\itQr6Vm Q{A#[L( k`*-w("*;5L@*E /(aeX|so!}-6`fHqm Mѓ5m KrU~# @ ~8PvF,KyDsX! }<D hJa3x~.MSse MK,Gej ;=' ݰzI,ˆH~8 ufvCv˹/^|RLt=-mW5`:7Wzmi`@]zyLpa_Ac D Phhx19{k5 '#5zz9̛@aJݿ r ݸ:K}6Km0GxxԢL3b|%qStgl24; CuӰ tjY&N&ⴊjiotLs!x) 4dwFyy@n ռ@oiF)1L_?:1;8zb3^('p4@ Oز=(Z>v!j Z,=/"/qL,8RCZO4fp s=ܺ-I={aWĩ3LuصF'q@c^ADˎጸS]:'w9gԥ)ˆ:ݓ2G_7Ol5!!l.>De\9p!Vob׎I5#M&0I\(]ܔ [C4W ^<ɩT La1m ;pE`nx qQ gsaF*z)DD fI75/S6iėr, B *GvYeQIusv{ b k)H*R#yR1= A?0걷S+Z9 =ajj`ID˂N"Ӱ[,}T~eݮF" !M yz.arl9sJVLk ;~kr*7&/t<h ֋ .hOß L~_ӱc@Um *,y^Qqwr+hwNNNLM `Z 8[.A<)۞g66N's85exjwn٨upEޥVQ^|Y-76/UEQ[J?S`¤]t k5yvF*"jc4I^J577=8@cCu>puWؒ{y sp)sȇXOE ZE"H׏iȶ%fXF/北_@cH'ȓAA"X<)%O°f>ǚQ\'8kz=~tytBm* R/Q8?#},Owֶf#hEAw_H9LyU鰺d~NEt.1H9xw#:֝l \1_&;{hHFY"DQ H!$?Ȁu'Q9f[ŏ0Y,d+$"Rj tNU(ϟJL0Kb5#cn}>+piy~JH(`PL>20cSɻN^ܕV੖QR|{]I{zF|Wgvc_ՇM/4܇N?3ӲƽY}hn6{nhފ?/2kDT &lmGbջ.`=i׍:5@Mw 6Oq0Ʈ=uW=b\/9G gD L_R^ە63VO!-FpM;QZ2ob,I!Zq7HE+e?5P1 &z>z+ )O2!LB5g|Ȗϱ[/QΒcJ6|I(yap Mx9r ~R_#[}w ce]g6Է'88.Y~ ]I C'ahv|Y3' >  )K<}jV=q?戸|[jflb ۉD?#@1i$&tːJB#Q+3pV]]`C@܎<ŋVsqfOI^eBO٥ ,ZzIÝd("Pêq~) ZYQBWsτ|Hho^հ 26 TJXj=?;ѕ8Fej Sdq(8M`<(ꮛV`wvKU[J?A=}諎 =o8HXv҆E1_izȥl?؞S,j;SR@ߓ!e<+54ާ}Pju2 mwҜlٔ: Jw,F$ PC:JŒ4]iQ*kl?ci)ۍ&-h,9C XS 6xk5h)|ō6}Pci'\|8u%.)#<)gQv--7D\pCs[R6viکV !nkj֐$ :(]FN>X1+KBLw觋 @1)"p(!=Wk$x;קƐ%3Hl̒*gL3JLӤ xRn s0h } mc#N3;#(ᇘ*rMEj/\K@|).`TdԓeOԱs!ۢ)sɕ#8V@.ONl.oC+u^Y#Cfx=8,ͫ8ClNKSѫug`+C&?kJCbbqkHԐ)HtBׂPKwp_@1tƟ k'm;Q Ey "S=xxfsdov*@rq?G@ޢ' AN˸|oGRͱ?˹VBLٓ2Y7 qiglG"sS=L,5mB%1X0wmn\* GC3i*~s% [l&97`U?+uN8័OAA#97ɭr=\ч* H'l-{R_ Qyv2PTHҍq5Jdn#gWN_e|}ds$! NH[`ȧFuG=)Xli-NSO,j$K %̮} Dݫӥl'5eVs ^n(3/RDEypᬆUP(:wEaC?(lܻk;1Je|:Tb6ԁW[/R~.4rշR[q(k2hBŬ{z gn(uvTcΪUlvug)C_]kq5t(uZ,XA)*"{I2\cCMr`ɽM-?tPP-iB&Uxoi|>JU@M jfXt-3;Wf{e<쬂li ܋ >.HPt_x'ASsOIF31_\gErV5g(< {oL>2b"}+s Og9*|x)@qι$.x(}d-:;2f|:5*%!HN;mvF֝|qDLT7:ʠO84ߴtJzPx"M1đuœloX).62orDBH؅q&HNl7϶u ϝwYtM}N/pf4\L- @"e TWԞCߴ1Lp2ɒ;XвZ#Yih3g:ί~OFVKiΗQ@E@!U 6)2- <58>ẈjNq;4-jKNCΌcBw5nz((Nz#2 ŬD6k.Bts<ߡV< I4S)T?S)ưQ lruZOXEy-U}3@:Dr_9o 5{!P ,Y!,~ 㶇¶ GI:K:<\"|M&3Du tTRFq@KNOcC8l_3|!K܉oH wm}~7+c6 BWi- >R3kHdJy yl*a.";!z8>ʆ8(ȶ0NJ ƒəR2003-/BQ戾9.z‰3U]( ᇂ# @qC tjPE I CS^:DBR ğPo EouEV+*gyM*u'Њ~;ep-ԕMPs%t'Ӳs$\iiA >g4Mt?ڄzAP/чZZ)`V}.sܳq@4{N juH5>UdkŽZABʩݠShQ ;RN/*&K54z!kڥ $%>;n% >sq :CgIɯ g)G+^-O=D!tq4#iA<J*X Ȇy&VZEG>O!qtLES in~ lo%O0GB ^Y|Hjӷx[ (&kDyυ L~.W‘Nߏ~t)ۋ7'"Iw( dlinxv_O,qq7838 ȧWw!pd>#ɽ&F^r4Q[ 8m? Ѥ=A(0n_+= Llԗ=ĪCնR f9L`ʑḥ:w6jn *z<hʺ)B8*E??q\TŜ41Q"&V!Boh>V{ Z,")S2`[=Hf 4kaY8tpL i!Jѭsڣq 5cl;FwbX;O9> 9ڷ_Ԛv@8Vv ^ sw6]R@u*80FB /s|'p|ReI+EM{]-O J2* _:y ew+7 kx|5:W?\+ 3hpV' Y(p}$$rW{{ ߫/ q<zp`s{zS,}0?s$ ɺy#ׄ4ߓuQ7Ms\ܵA})щ})yD9llUڶD]E6v|-A쫍W)__У~s ~3+3g ۪l.bPfꯣ_/m{̒'}oF(ksE$u;ǷG3b62dl3[b"h> ;y wƸeW麒j; nmkGkp+(y2qHooZcU(V$89IRFHRYm%9&ܧy\Ǩ8(l^KK HChE 7;Z1:)~'!w'@ĭnZ E5 z0 S%(>,+毶5O\MrcA?WuX]묉:<$돨wy>QܕI,g*rG; !Zv F7؎6zξ}J&a9K|!p==j%&,bH>z wXlxtD w>M:/IL&m`]zo}Sp]31KfOL))73e?`Gb'YCaE fApwvփdYMSv~S;n"ƻVsmP M SaOҷ>idd 9x@u6Zb\r߷O>U^ v%V/cFvA֔/My޲ HFuttw,uuG&*{]{glwДu;֪: Y]2qW} 6A|)oO9 \ 9lWrk&Ou_*fΑF3an6b6=}XiuQmY$k2׮tiƇ{XD)AQ;?drzbokYC n򔈔TQ'e bḐF];â7B |ݑcLTxhd(YGge/M4Ro4~ h$b҆uM,1;!Z*j4EEM“#οH9wdr'gF Q$tPVi6-vzP <q03c.k<^H)9+TӾw/vvN|y6tO?s[]DFV7!Khh'^J"w-цA{h7֜>Ee5nv}"B6Hlf'!BQz5M&[D?d"Iq8;4v n#%,K֝q IBW}]Z=*JDj;".^Ў##n^L/\-+4{?9|sٿ`rٓ$߆Z]2!fN@ `J[nuäv>QCq{kR>Ը( O\NE&NePGHNOn^V')I:: 8yL2V0 1O;}' ؖ,>n+V0z,y&$<ɗ†L"wTRZ _ilJ8mZ!HD~2!uDIYu%&]eq;kc?HW{d-b>͓ >!'\L1>6& cr)AWۜZ8VL Y @6*sVqC;BMh)>r II#΄5<3]<[B\J$I@+xJ%ؘ/}.1 35L-ي.rUX,{n3K# ]v6?(#|`< !Of\ G6bbopK9 L}/ [%h?@~31Rݦ)sqVc]2PG̫5K[^Hڼ JTgƲsd"PIfn\8@rkA'M &D y]PaR90*}+ 2$SU0OCNgD*XH`[ǵc^6?$&58$a7&lqVtԕ_ 8:+K!s7..|6j(!ę0`NnFPz~iEjROݞ5"P:ώpqM1Uy!5;>\6];xYww쨷@ l)81 }8gH4@tq$'#%,[֐0u*vr8{.Q[ YK)$q7U@T9#MVeY>`iư.n 5+/g>tfgikYfb My{kc{Y=(Yw)R8J#ӢlAӳ#c-::#ofCc 1$g6|r0Mڱ~fa>&}7>Μv4+xy*fު&hL( L%3H7Z kHuxۆJ'4-=ᰝ{c0/#;7LB@O B׵,W5(tJ9-)ϹֱQn,J[jgc 'm1Ÿ|x%Ϊtl f9~3$JOMcV^JjԬ;g99D0=Д]7L~XqKA%}eO:69u9>zL:_qQie$D$l=KHZeVoBy)0o&"i !geP"2`39CLƒ)ͱW-Ua(N0' \ڱc& їQYn$91Th9cψ5HmR8hB \HKJ El'."#&N BYdWI^r4Fjxi!Bv/ׄsA%<;{yΓ }^"CG2=?`))3'ho(68J nqr\Tpو ES8%7Uʟ7~ҩZk#G]M%1טh/sB(@f-0xk{lln0QgXqon w@tRL 86,cC8q! r|uD:M?aƏةVQʊί=I~#OPS) v1~ܐb.~@q + %SN8w˕=l'[8GT)c4veZ՝OrA=pZ)y_ť0+wy, 0ŨT{H8-cHᶤLjxV. } XUQl)Esم;G=Fږ>{s.n`I}D&8pyvT1(P< ~3nBy)@=_킀Fn;S qui b߲6Rڛ 7X1l$j'AOmYDXR]-y!=t`DC{X;¿g9J&lqH-0 ŵSz $Si'?Aȳ˸!{v"%蝖iLZs%GX~Jw7E8Z d4,u-o.QM=iAM7 T)~%u/"1:+&d,[C}.FYv%|,pU101rYH£݇Wv}Qϱ2Lr=4,): Z !]%=IC؀%;v2PI.=9(hN__-N|:W U#ebq GPVkFӚz%v5~-$P3 %zqG$k/eZ9>H3#pȫ in8Y<%:?\rFH`q~#&QUr6 Q9DK=$N)F:e43R<݄!7'kO=ꄬy/p?;v8O o;"U߷V$L!WedJ[f$;(xȳS4=KYaeZLm: Dxʑ~ʬ3;&gFm=pOţo0 5KU/ɼ)\b.ȷE)A7 bU 5=hC3Stku$E\\B6^۽{IP piV|Qq} HHYq9:W tA uVpYV}+M!OTt`k1^!g]-+]ZXS.ѱ8'B~`"C}Gp/pMc9nUEh5.*VBfmozq qƍ}^s+`G[X2̒%i¼;/8j5N D1vՓqH%~ke47yM>}DȦTۥѢd/0M(Ѕ&hc`,y>g4B&/"sV]W$MɍH~fijĎj$Ϗ_d[TŕC eb\׆NBSGpґբ-kݤqd-h %EgX!#Pm̃t=P]d:abd7N>0&;Qkn{:*k"7ℙJiH^9kmRqi$~"~L%P2Y ߬+ĥ$*mAxHFf f N+jS"_MW`V-Mk0r~Bm:DIwOLM<&GWŠ]69c>:-葉Pl1?2S شdIGpkpIPv_1ĬP_nz6" #[Ȥ| 5\J0U`G?TA,]\ԎDkA7b=ʝUѭ9gi ')oi!Q3r~m6lJWHG}z9o@ KӬfZC)|4f0TyV 9t#g;$1KWԺkȆF9H$A9< E5~zTX Sr"&\U-"Dxr$VecuXT9Og嗒r>b.ExqBNQ߈.) >ǭ=-ރ>r(HW^@sOo/G"G8%9ҭHjnY:*a4kiM3@dS/LJzDڕZ<`* Ӻ<4fLި좭 V"Kd}׀;Zpk'3l2#xsӧ]]vaeLPF{5T)SO3?f>'qp(uY_W|*T܊la@ؙr蠅%ѶV38 b#ʟuзLAbN5H'^tE ik~>:/EkN/8Ԥyb"!U ,qIx!a-ۨTiu8,/Tֶi <*k[Ƕ D <<-ĞF%mGDd>\0RӋړ 6 ^&?<*wwCۉrbZWU4z|713%}Ne>.yqA7vG)Qܝ1C{Գ;ҴG _OLhmv͛ljtX9 ou76 A()Ge3!%WSn=Rŕ(}/Ul/D.)@::-qay\_G^donPPo*,t%d'Wo`S@]nH'lZW-].f귝2ʒg%@ji׀x|U0|׈݅tUsArcc']o6gQ4+sflq(wjpuKK[ rrr֝of:) XSq:l r6)X"){`|!HyP!3.nJrk>$&LDQ_ÃC)Oo RsEnSX;Lj?#w5O2p< 3}Ңw&[DŽju ~AޟLϚ/%A*R|K7d[ R_5 JQHSM$ku^wѮ򘍫 g5˒^ {sْ**/1T ڱܠT-}(/(1]:[KH T="ˁͮ/[z#R.e*9RIIYY>'t=5V̻ )@@OTK83{T?LZc!E4haV^ևLT\rC^g&0)&&b"HH6}FԿ&9ɠ N[(,uROS%ٿA]+SHl#&#+󺖱Skhql7,\8`5ewP3ܣ0'[3![ ' =dR4U$nNPUv8>#DQ}(9fhbr x(V|HFgIlYwz 8 m8}Ղo$٨JdF%$܎bQ'ޒ|*-?CFvԌ|]t3EHʏaf~WԚk1ǫ OߜFPRkX\ԕ`;atˀbrT(U *J3o>&cur&?fI O("0%S #n/x l`v47c^Fz`w]TFNn6^@H8pӥAl8'ǒ 6vKk9' JD4R˅%LRBDE +r\9Ė9ȃ0:Feg>7l|^uIc˩> F K3KE\ Bw5P[O;HAZ Mό4nwdϚբUlJHSiWh5خWWD`XD 9je0ơZ#%9?$b޴, <{t$Mw]{`b3sjSf#Rܽh}ug]uO;VBFC*b,0v<ӎ }2Qa*`*$2ϙ+W2YJPYkUPŤ9h 0AUk( ;P>Ut-KErdgDTf#m~{|lKz nT7<.$>m޷ f@8q+PaS90w "2@콻qykY(rİ2O*E9L@GFݾ5aJ325B ִhVl)jt r?OE`.NVǭ+@ԡukhѻ,bbn=QAy(.ٰٰ7*z?d_jfUf"#TSI>eP>v6ciw`F˿ձ-X<@GRs`vXA5U*Z#q  m΋:N#h%s^Ogo12;>jnb(6^,OGH@zw?q |'1fH|oYh+:!`Qm5Cn *.J?@l67#‡%򤧅ncӎnզv9^LyGY p64q՗-yL(?I/vƩ۱M*5f,rݾ_]MP` J/=}j*`BB]&@pؒ6BiC0iti5&/ng8.@'?RSC-tk^ E"sܶ0k=B7wixm͢4qgp${9Q^%B}JSEPPD(;כk٘02 M ,iSE9Us齁Ԫ5g1uCWe3l3 dtRBWg?~^?+EbѦ>#0JudGqCElޢy";' .WC5nsMi=M _kMz*$ ((k` 3-fjh:{?x Z򮶂BCaڎWQ<;+F" BSң:Ir]j p&b)jrgS޶ۄ~p8dw3q8Q)/홌;fӏr_gZH?Zh? iwuL.$;Żmd}%ᆈ*tp;YYtLD:|1yU`UBlZKTDQ~wo^Ո}6C}h#de<N '66㱀49BJB0u'cMZի?o Fر̵DXk9֕&D!S.f /C,ZzrO;g)`-jFq|\TVG^:M@W?A3W#~?ޞuF YPO!&Exe7|b0d_Mt (/6VMaӹN~uSJ 0.^%wʌB|I#S^zEdBo'o瀛!K6J:FF͸-'is|bna<\;ۛmQg+iV8T@kzGׂ95?┒x`&ԓ"\ nj\WQɞ?u[0h2o,í({15Kmi!ODoE%Njɟ5FhRw_)yPNӊw q3jf,@I| yKa<',K3$E)sJ4Msnd荃c2uMl]qwv\=RɿfER Pj(*h$5s w%J8Ct!N­RNfW[<7䯪2ҵ_)>C2iNᶪM[E۔I܈iXv(h)dt7 a4,Q]`Zt`@od h΅*PYs,Nf5"yg.BAÁ:(cJf*X+LSn 9i+kPx"i ՈOs/GJ PpyQR/o-{QwV[$v`͌Gq`=;(9\ϗlYCE,x<*H hׂG8#Gl )<^IXh{c m7SXҘBc]E{#> u|D"\R@/,lYWD#wTʹMP20[o}'>)EmGnh-Wv>Tjt̃B fq$~aIlĄJolY D7FQMpP5.˷4=!My!qU}=qV{)$iI2!t mS @z-9F($B"KkPX̒r8!C;Ll8,EXE ߓB=Ⱦ+gӹnm@S܄V' Ŧ5T&Q|{UȌJkP/H6ȪPm5 g^S\դ'?1'"m" 5}ϕԇtlXc;n{‹+20YЇچwEP $ZV+_U #moZUi;m9f5ӂ3`TNvО9`iAϨO ?; {=5R+;Hݭb &AK#H'U fak.ӁEGj 넦#)o׷o1ԮRh.ݜn*T[]`̖dtk/ `N©\v>f[dž ?@FQ-|s,X&9 |р\mFXV1z<-v.TYH:z_((Jd>eú8$EL{GzCg p-hYʤNT1>n >>7k0YGxj MiY!fFcPuL8y3RDkK}oą*B] BqR`$ۘZ5~%|"yVNpblz8H%77{Nm:1=IXpB@a[KsDAw;aîIŮ cQAcfe(z%f%d]U.yOh)Z{9ZwdV&WŜH46c%!@&PFV#*5gnqL5w+x%q"V4`[jؙZXieb6I3Q.EگYSo/%՝ƣW7f"ɦMD_@p%S|`dC$:HŌ}p Y2N׌ft1]`*ZOUջO>cBwM(@Q$ W 4ibY֞WEl}kˏ_:Z9@T]^Y$]zcgb| *T};Ɋ׷)*Akͼp3􎎪%oFQ GIEYصUoF@c,-aA腝'R7C-s?FR=),yG+:hɞq7a_u2[ ˳d3/Vz0-1fnPm\ouGP޷6#_I̦aS2q{Dg"dBx|:g5ZYbҮLS)9^8ZM+N ZvKCbdqH@k 7vx1 ּn&˅WBwzkZOuyev 3Kx~=%ՠp)4X pi?~qvX'w7a/u*.1Qpkm0 B𗫣52ٳX`u_Yz 쮽ݶe"H5;I4M'P"pѻ~c2ٌx3!U]6l z\ B\BΉbu:}l٘;`O30-8K~[p:'kZy%̡FfGl%.(2]^/?Ǔ*~<+!xHlzR (呂&.?3F%A?@.wFbWD<`E?=oNJ(SUq$|+4ݒ-@68Cg^0r `?m+Yޢ~<оCt*SU:Va LJ\XG{sv# ,ӻ[o0Ns+Z*w{ \$,:u7n=е)u9# :MV~ h6TxQ@ADqzw,ʔ'Nox$zLƎ]bRԖ E`{1,0'tmtk׮I #ltO"AhY|^!ֆ=76N.0A"&\jZKհI2g/ IV'/miݟ\^:ଏUbt7hbCO8ZO.hssjc“W΋R 9j:!7O-c'oO|2:ȭ,`ַG'I{0|SK9r'DϮsf'6sZۍP*9u7`K/~r<rŭ!f7nDݷƭ4D]:KRnӃ#H V̏lUkɐV:{ zIrfl;g7fGFW!P=8<_Ph!a"qpсDD4)4yq> :sA^W6K7K}_gD?qeuН9i MP/gr K?dyTߎ(k`*cBƼ6#ƣ 4Y.i b1|2Z8h٠3p,:dJ0ECJy R˹P o].O|Ϋ] k`u)p { ==PJ!$ڪ/Z7f6J?E~m3?VG\2j0u:[Y]X$Jbk`/]aÈ&ԇ?eMjUΆl*C4f'mHfWegwl+ k RkrLzA ]!5*? thgY>T݊ŴόPSʘ Eo BY`E2 ;Y Y̘ӠK*JV#+j'hϸ/0-n]o)Tvix>/ԜSЙ$m8x}[0:kwytlkgceVRK(>2U%?Xe-g Ji̗Tu>2WNSdKDy? qd}HbzÏ ihРk'ŜWCKPz!4Y /㣐?%tTWڝO+:ǔZ W抍 wLW/Ʋ CIL<׵a<]k.sQ|bX7tM1z4{V6խT 2&- ,I zÍ&MgdUe)p" >ϸؕE+:mU|RWڂu=[MicD *N2ePqO38ѥ,UM&-'J*vZU/yN_4R:gyVDGR͗;}:^OĿkhR1j:i>V Sh:u/ Lk-^s޵3ҁUf˙\+Z*LQݪ:Q/8g=>0D@e k#3dO~WGb=4cO*'A ]A7,l<ЖBD~a*sJGP:4"rtg!Dj3 < %NØ0cf"8#'Y0ͻ@M%.)N:>xӿ+-tTg?r۝Ts؜@b;0R>OnH)fZR޳=h9Z ['K;Fjӳ)yJ_[@,KbQ9(ʻMWJ: 6¡w,,jASwJP_I HOsaF;:RN8!2u#-дmGI\?o&M- ~2Briw^Pc=SqVůfS_!ONbNlC[a4i˄zza+VxmP;﹊ nz ƽÖkwO"eɁʶc4KuL0`Բ|`XQ<YA(Dx&4 &n n w(Ѷveɾ|g6RR6fѝySiQQ ,5b_=nLco׭bQMNV>Gi6#қbru+}iqOjk^T(sK# 3^HrinMtp `"ʖgl"ե2)°xGH]"HH4BS:D6=`Zl SRԯ[.or/_y SɞGq&7'(aNJͰR:;WU 0mաR8av:JAX}nL/Qr Us,C /]S7LOHl JIyO5 :|7ѮrnƔ4͖MG$io\ithJYkaJQ=yE]k7EO3t^9".5bуZ{Hc5 /"a-ooi=VPn5}j-j2M̀??t5lJ? X,7ȻD"ae&o2tSj/*2lW9j0 5s/tO#}l߃@Yo6H |dj[Sxš۰PjC,;͊%bpyMZ_-`9Fe[$k2irv6jqvMo"p3nz$dBAl vfͩ7R'۶ofy MMaݜ F]L@C-%me~6\U&[dc,4 Ij:ziҔz2CbVxU6ռ<0 UCȪP;^%OEtmxȮ*2Z>e ɄPVmf ^޻;;%<(/jVQL,ftDQr9ਵ!Z:b72a qݘ`<0_)N"%׋csBW0SK86G!PlGv# 2B- ͺ,`IO X^G9[ {Fsc+P+6`{\թ?Ά+qC"L^ܔmL}tVY5zo޻R*$BA # VZUs{y*U "+ms1ƐO!q__ ]"Ѫ92 ؤJ:v;LƁbpLAq]L n @;bKHR,VLe[$i`˙Lc_H!oä6 7"wu:u(l1F /u!n5phQ;|Nd|`+ u+X&)uW_e-<>1XFB#;^޻ H"Y6¶{w6|rsVA5|hާUOCßiq͟3YEwF3iS  ؕ5*3im66E"m `ڤ;N\=gATŤyIb6$E<m!cs7 t2H76[JG_FM.Ml0B>3Ja =6t''+uk}AP5/"a=E}%t!{eS Bp(a6Qj/JˁBٸ4N [*xr,fgy էi4zQD09"Uv17FG$y7'lLQ MQ( nݚ 82 ȾF, RyeȻNhq"b&>u)4mp]EXL 3E,j,wZ9~aak7 >QhNބ78eHq&kq/Uz̒VOvFzN$<~̸I<n [thXyL-!"AԕYr0^}xNժ?keXqLYO"~yvŁמy֬$ӊ}E..+U-0cyf+ɹVABi"VR%Uх$FprӵV&G} bK݀Ɖ^xhUhzq[Q);AGgg??<*<:TW5LIL@:|Z]Xhd@ؚ̪j>]<3n}jy7o9M 2KZ;` Pe@%2Mgwel8PwSHVv\J,x&o.9o^.3G>S>U/. < j<;p~nBY{Rc+GʨnN=߭d^t!uVc8lh#GP'&d3[êp|&ʘA(OitͼJ{8?djPi.яE\W#b";.:% DPĆDBE&Id¼D-NHF_I c(9Zl7n( EYMdqb=w-Iq& x)iJ>T(7d5 n$gfTsVCǍKƯ:4ȻkCrB㼂hf *#=l{H =Z7ƒ %(?%_t8ʑ<& & SfNkxxYPB$O# ݄٦ i e,I*_DY|zbG'ևkQ<}<5DX(T;U WnynӇk'sþZGg6Ŭt'ɱc*fE:)c -@df,?(?ݳxHp,t=ʏ<$ĺE]('6=)b+0J@3sRz')d}UbVW#r,(vL2^&͏3UTӼRf8/Q %_=2 z@ ;/^[HB304]"ZyOMt,Y6 eMg =!nB1Cd\m(M;R\?DA 6ԡ,}sHt8pNg6QK[)9ck{vîWaUnc#gM^ _e!D ߩG&?ˆQKQ͹%KHÙ'TsyP,ll1)BO 7}BRdI~k1#c={M~:e.Ev]mA``VZ݊I[8(h%;6)^^ V?ii$D4N<ЮA:Wr5:0A%O%ג$ ,)Wl_ZIx3#>H9㟄@!ŋ5=Z_ 'HY$)slO=8R/X{gb[JB(<7}"e إA5;ʻb?kfwGn:.MH&ɗq_^nu)>p(QZ= d7Vz-)U,}<)6Q;pYGaaf~1`-( ֭};HvmvvA$e{HbB߃;cp*J%yWjd]j힐,zPa UFNq9Ɣ²xƴ0 >e 0n8ՎxT4>vT\<faEvs-tzr"w Y CL?AҀI5a1?O`HQoMWBLF <4:NyGoEu?ZV8`"MrlYEb^s: >(1S"Yyd"u%RMa6UsK6h"K=0H//\"\vwKoaHF\{uIP'{}]G_ۭd=tixknɓT|[s/9NͿ7 kDfDZG^U˩8'v5X ȃxQO*!LBE)l!=ˑn2 rpQMnqzm%kj y#a%HnFϰޗ*Ja9ݴŵ5x`d u]dlbc\YwV>W$^&`6HA/Ӧ,#ceeD4b Lz3rM1ZiWx9"ҽaG+yP/%VЫO52Y) + Uߴ_5xM422`^4HX:ឋ=/'cJWǹ/j=8c@ L_$ s{.U::5K%8?Ȇ/+!dx4t3įX/d ]] Pc:A:3=⣻D#zȹSi3OuOAx+ӥw `U&&/Ͳ|ey,)<;oZ\ ]VӒMm='-=+wQHwEv[ =Urő@b겤 Mq f21L*{0ez_ډIGjOֻ,~& P5׶}ah5yӃ+񵮿6?Xr ܓYQuBrޘѽ#cgp"I> O( zt)uOg!؆fe]·hrد 3v+m7¶Rz.sZ쁡?Z_!-)[sxiT|N;+-]S匑5ԙrhֿR ey}śHM}aL$2\# [WT}[=;˫s-n:aLbnH$xBt*e_űygt0i\/LYUx `oU{N(a™"4@0 H'J&y0?"-nOT?1wab.[O͆4p^˂/16OB,).n.-6[hWqj \T=1;h9E zW&%)OK<>O2\Ԗ|'cRY~d*][?^͔.)H)`(P{>a~?u8W޷SqmZ$sF{Vb棳HHЧ&G dF|8{gO >7C!NWcb [qlᚩ0}B쪰#e#FK@&9‰WY"IDjN B17'E}}ߑnB@/;ΫT@9ӣ{AxF؎laQWoۼZzFGEro6%-!>ِ]{{˷q齭3 bAQsRT"h ]F6"rW$?!&+w q.uwsa8 Ln̪wo+[t.dtHڮSlB9hic'#$l"]R͕)y%Dby-4sژrdv d.r1 Kg?󠬤".\Kns=p3#РϒpzAԙwJ?BQ6)Dα==vIw W4*K*. Ghϛh/ٛ:L*N;w591Fg,98b#a!mK. xJHr,{׊?B2& Jԁ$3W!S`k~1tIR$%,c8;aiKG!A!%Q]9ljr+GBo;Sb⬓K50a\۵mGڳ[`$^fyVK?e@P3 T8UzPYR^n5œW-|{7#[ 놔Vu>w>,VHsҊ͒K-;F\įC Ϝ9 t=l)Z 5y ^ zNrް6(^ee_K;q K͖ SJj[{ЬnqͯmvM_!0;ԏy 66Y?*#1^شRl|F,=5|Y,)0Lu, QIC!PµWPO^<΋)R*ȟBEq_b&$[k^qo鸍{lR([C>21S]IT@IMc}֛!aQX,DT;MS~%~Ks)5R UYށO%""Jܰ(x)vTm(/Ċ0^ Ֆr`?S"2ѻP(^ȍMJ2r ,@y,YnVY$c_no2hʿa>0W.NJ+$[-W+(No?ǥꁷZ+w"^I|:؇eIi骕y.Vc?w/7߳8MBrjOW;T%{0=KWv!C@T~XlʷB~ Hfk*(NFtgQB(ֽEV8_"GKř?? 漊Q!j_Mԩ~uQ|YPaLb)b !䪨1ttDaYo[ҵ'5ȝ1)\ꭘ/spyA^[p7A|+\Lsj6hM|j z1Й #$VBj["MâLy3fDd~AeW"RAF&N u 읇\v1Ѐp((Wbhm,5vU- ~ͬ-,r%Ӧ&T]Spۦa|+6ҹm 'ؕjMhHxH)LUQGnF! F $st[qb_QHm?@![o%ɥ nhƯ 字koĔ&IG+. D#3*P8>󁄦Uqxx"RAEĵWv"CHU8 | o=0`c][EM+03Ϲ뀠G6UD rA$BHN i#Rl:q~f e*~fg ナv0,Xc.LF G)1@Yִ-6xP e4{*:^V Z$π,a[=3->ooFTptREtL/DE2Q.d76f^w2!qR zu[WwC4QolԜ1uBqrF"CTqc#hv@u}_zѴL㗍<:r^.>?XykIz`9C++ϵy]F\W 32;R,-o>ظ%xg{8^` '$Cѭg[fSRl_Éy8E;@#jJHhgO઄ƟKݳ>8*:Sd%ss:p g+HɺT<4"t #J's-Ddua |3x)c&D"trJV'hm6w]~{]uD|b{-,ii~>+QtmXjj6`H 4u?)L+a5\׉ӟjf^Md+z)=*=:Z^Q<6ذ})TJ`RGS^*-t&PbXjgt✠N-IRik&9}zp3 acKͅN;fq%[kBGdf+]<ڧ6KG{9>#O'%~ (imRgKR[T,q~x`]$]39+t&G c۬ |EOoݛA-7QvZ`=Q߀!XY\^~#[( 45u3Th+3yZ  <ީƛB**IP4IѤ# SWqr0zyHZ)fzB{Lčr /B:`%ԒLp(o7N5% Qs!֡*˛꫆Phw*8ƶ-ӐU -\ ̰2rdɜvh!NaiL5^=irh'hb1w0]W^NKqS VAOX{Sǚ~4;֠l]}zUw >L0?,EtI:<>\{:|Kf]=+~W4&ADg a@k<5>钆96/By㔕7ml Af X7(gQ&$aNF?K#Hg3,\*}`C6R xO"/]W=K=v)$JյXjb8 3 jkZ-Ra(C}kD rf(z:0 A(HQ ¨tӐ'UƷlFUP@6 1UD< eBhPy|?W *%Ow0'豻6/@"U,e?rv W:o{xauK ߱q_Q;=űB?k 'Ό3>KJѱōJ*H?֩<_#1Fyl:N\JQNt'{"1E!&}r%bċICU*x;~t{ӧWys)yh ~٫ G1`J5t8-d̆(G =[ᒒnu9Uic&ӐiC@7=9ҞhF'\  t Wk  dwgb;K8~ƪ2?}ቆ@_7mnKv17ǃ@8ňfڟ^4t} |W*x.*-YB>kΰ#ő_&rP rzrPvUBf{ BZyz౸0<ĬM&NS^o oOxv͘-|K']%s^IM4@;45Bh@;:O*.@QLLOE6݈]5IEpNORD0Qwcٗ,lz-q ?$PՙXA 4!FZzsA;<:HG^!st~h"woo݁`JuT|KiT2.g_D׷6 ǩ`H×6{*ӓ"P<-ڏ`#AIXDzM|%ɯL-\N^?JtoNΙ)6a#=ߎT-|\S($@ ڶg۲l)O`fGKcO З d3 @ ^eЬ5Q4peFԄT.ޕ3*HY:o RWrXU2;8~B+),)w?lBwfJΩ{EG-h .#5-tk[ cRy^ݥM4#t9bvU(+>C>(#kL5.|-Pٴ? <  rk[_5k(AmQ]@R)(^≩L9u e8X4̾Ϥ ӹV(5B/gE\mrd Գ9PI2(ߦjryhXޘ翹.3=a4`zWS ~e;Rr( ‰9~&'T|puM]s=?v@QpBBU J߄{p$`;XdζCboQEbhwA۵-t`ȥmJ' g))sa0vzz2 xPC4u){cJ;"Ӈvܘ>z|]D^OQ}?/e^4;&ϙl?T 1]B_1[4bTyxn),(x[5y%%yD_oX$ dKnJ.sO6IPvc;IMa&վia@L:0eKuYò$*t#aCk9dJR }kPl'V3|b*;ɇ.z\TK슱 < W%VHJ!"^r2#լpAyT+@+^#>>q3F_eڙzd[qmHk@-k8i./op;r)xj߬#W:J2\5cZǐ؅Yﻨv=3%̿{wj3pӀ50ctV(ƧږWB>,'N)N.1CIIy3mPʼngir|'ʁJW 0"PH[ pQxil_7H+69G?`}OigU|dڵLɨa)Yc̕Ė:@[X c'H2FkJ8GIyvIl 嚣"T ]\O*rȄop`e/ṫgXJFڲбitpG~qj&r2B!q^rJX08uGMHids5w._IU *]e㌃4\y/KXxsMv1pd(2Eu7HhFWJe⤥ h2C?Q{tu!IՕgרPu¤˪̔ ~IrLj_[.-86~/Ce¾ qhpFefO cJedbuyEZJD4ڙm6]nlj lKz| NSɬ#i%/xXYvjڮrw׏vD-Hāo+] 'qD9u MCwRF9W4ʰ' tK!(x h ٳFEozRټqHvz(dudnHb㻷I:t bc*ش`u07xe4c)(ls7.NVkJM2-rF|޿ws޺.t}T ¹*ha.<$yN AiUQ "VTT0C}%SNu)![/Ĺ _+OU, ü*cخ]?RI*}Z?/l7C]'8$cH&>jNFw$8{՞;br.4 I:x$<_5"7J_*g/~(RGa.pקZ=mNXg)T1lmMrqmno|nlhoy%j 70sk|uOu'wc& ̩jxdXt:AD[Y8M8,yk@ g[Ԧd%<9,tԺp6 Zitjib??hCyܠ@q(CVu`MAH.LغDpdx|%Ϛjвp֥ _ bnlu%l0 vv`y3X绾3[L9gw9C1yyfk6rqhA T3|>f NZHKeLns}G^9Stj& (aL]Brt촜X ZYS6IHJnP~Y&̤@;0M ?q Zxj:_WGRy#ɫ+zEEE Ie\9=deSוu܂lϟr+3OS(jo&][DToYp\/"{:I= ֐Wƭ Ǒy >ܑT}=GĽ XKlÍW~4Gz6u!]:ưO+Ǝ 8 U @DHC\AO UUȺdt+aئ RP 8$G-A@;W}&X4z܀ 2%\1iot4O ؾ|_zRn7 X)B+>[v1z1yL2|\P7idZvV‡>VI{ތ.[WkƴvV8 ؂@,`z% NO@!6x9uuԡV!*y9QXx?T!-etʾhO@$55tker.Yb7+UڜsuW6l j;_ M&%I"bƏ .&Oj {£YW34P쳓b2? s5hGGVK2v>O&}Pք` >&L3eڹr aŨX+RۖȢ ?*2+@e)%*:í1l#A]R@{m$ie{> GnúP3\ &5GgaxB?kщпg5#lF|pk L@\Zi2{* f_8P^K`Wm+aJȮ"Mn*ER6M!)$ֱsJV{2F1)ZrXN՘v"21wV+n9ٶ3c ETatռU!x1\^׫'gc$^']CݸeSWVm/vCwmQvVGhwJz*uVäUM:D_`KVE*^J\˕^:@,#ǑT2(/J6#ZJ򣮭-)tJKo$SONɝVEtęVLq%T_8R-PuF)  D6AF*{#q,oJDI3>u 2Lj?r6bך 9ƟENc>H() |˦8 M s!1uD}{lm|(zX6xr^@`1(3,k" $kl$>!GHi78q˒x+]c݄aB98lg4!q910yD1D=N|L8x(VC@@}‹s"<'&EDtp9qS8S% QS(en""͠N Z T|S%i}ԅ)%:2B[}lt<Xs޿nE8ԫ?]҅w]FBT wړmCm6&,O3mc9U$\vBp| ID1hZ% |)M`#h Luai  b6T3K>R8!#gf:GLߎadt1d gʜ lf35ݬP>Ҧ9d@Qeo,Ŗ)fP޺Y_@Ș%HR1FC5Q_ˆ{otzm^˶Z1ԱO nn'_aH1ۣJɩhnWTTn!6?MJK]74n6& Z]*vDn TѢ$%G%5?,)$~vrF =0JЂqa! ̃3pՖ\z3YlؕUܳ .*7RZx͗(!8HuzF!02hs8{,$d@a.LkNc% IEr.楠Nu{UP͕. I듒ȵ uQq&wg &s@.a߮'co$QÎ,`ZAbQ4q`҄}y As3 !u ;3[9nVkr `;yd+&I.Erq|NA*c PGQOe#{koM=WCyA1œ1o^>Y.Ϋ.?Ԕ 5+$v9"C{Ηk:na͜~E]ui AdW[Q/ͬ+uunT<Sg;`Z t?wL`ؐɛ  4} #תƧq[i0Ux:4ͩMd7V~.M,;iaJ{e"ܚ!"< 3*]zxAZBʚc[n>V;IX^r͟o䷣Eבc]\tK%\9`d'Cָ$[MdUI"Ⱦy d.joGBA1cn2=>;x@X exW (D/Ϲ^ɔFz}JW uH RIaוBŪ =oKA1~GZ((q`a8=yXMNIVޝ5A9S?bIw& Dq uba%e윛+66~g,툎3Td3n14O6w$|ԯ'b[# BJ,rT){-]#&XO)㵻+ŲN:z wZM Җ;1)f2~Y1Hjc,F6:-LH6Fy,(#7[TAiT@jGPͶ{fz*'i-\Wܥ*jaOKČ'{HPC5f`YLvx?-DCq!knf ]m]-䆦Ws6E;m#GT|S'أ܆D6,c%9/|³ōl}-]1Cfz(w]z 3(]$C:Sv+k! &DC)J=t//ALj16i__ʆ}8A][ܚtC'` J,"}8PZ?ֈ?3Ȝݟջ=o:,xz vG벲IlTP85!4u\v=-(%Ki"Iw9]EQb aw;r)5w0btx !|wF_;)_ԧl߶;"VIqfFṋ+cϴȌf!@be.Q[l&6w4.=BzxpySnWI ?c u%F]Z`:"z??E4yQY/*RV~ր )2iu}> H ڭK9] ^yev*]qezt%mKg%%z溪_lbS (ZIduve}놦u^ͭ( q)r>0x8B|Aw34흣I׸Eu:ګOO>9flaˡ07#X\^a^ q zâPgp[q?VeAxŏE'IZ. nO^C9Ȋ"\cPT?ƌQ~XR۽-v(qR-Ar_/+l- M3O<ݏG"xtl/`=QAAVy1ki5):X]7t+0}r|.vIheк9{8U7VyƅJFt [Yl@sU(ڱS<Ҹz#r VhF{p4 J}=+M7[&8؏Ur6y\ 9J?m9}2|џ>9$ULT)Du/8}AS[lwP F6+Gdf} !2,eRِ|mBu xA,kc|\l^,U@BU6VM)V!(sn#S% a6yˏ\# n؂ߎ;AG3! ÎmQiHj_?tj `-]ά&C++u^uNÚs. Փ"$dXVCѨKV}ԏNl!g/>c˵V)eel(ˉmgVìZF 'D !e-d "vş<THi;TZͮyU ,O8D.p.;,l'zܨ4\Jq [J(?oքr?+(*,:41_!/%@?_F^2X5hHEeu61zŒGXh**-$_E8.¸R*'DQO T/q=[NA*ә5_T, 8# wLm{,dCC(s|tEsxD3$cC."?!Sn?.MF"t\JF%io*" ٷN捷cjR#*=t )y+A1m3 ]͒.44#\a6jh9`px/ ;Gs,C)<ˤ^]/I?3aiB|8amݮX=4ފ);E_ F&G{xvAȎw ]mPn4D8ZFxXS?Qv̌FT\P'݅)PgocPL" SXxvHcy\#CcKn]jin`tڴ[ a dhnlw8%tK!+Ed'(權yd?LĚIDm_1U&7ߥ?\@AG_ /T"G5וx{SkVLLw$ܽeti6G1M&" xn$WuZ9 [,s;_*–(V.b\ ͧ)y}9&F'cC49͘تqK]n.G'<oԄ{7;Rje^0.!O:B|ycY/ۑFMY+"r{ '1u8lp16+"0r5ONx KM͝J]0oK{`XP kķSw])(&Aryb5ʀR-o nXzW(D ~ 8I_Ȭ/=ļqrYSwGΦ6Gk:dZs]|B,‘[;&K<'B$&Q-)Ⰲz&iVs:syDcGkAG!~̧~4@O`/kQzhPVhSmwWAS? 9#/޻ySKx' $IS UR꺍^F<5[=o=!dy/>R["CS_o}HjxyfC0B:ΰ.RhU?dd=6/,27I 7RlAw0+zT߾o8ےPܲqtB[ ${,*iWNnSF=|o[_;Yĩ]669Pbj(¡w.\E>W+/o_b1Ua|Pd+‘z-jh.8&,q3xro thi8V%gRL\4Q+jKݐ˜asDL;K%mGi]` ք?yeTj`z&@ ,rmJ{m3WrЖֈ*eVy>|{-#(e[d %__rD q}|y6SFnKSzg>jpcc4Au30z"I/ +DSiVIOs_@ ,k@kVf3n=a(ŬhQ9nU߫Ru`FQp_ y$%Fv6{p .5i0v׉AXhAB'*8\s;7zHvO34b> . gȂAL1Q[TV>;rV+uZoĐ-ʴ~jBol8㊅(j Y7Z~Cɓ֝΋{娎kIzh@~Y{1 $}}@L[rBWdgL@dDVZ ˝Yv[y6$logطaߛVsMG=8*{%Ht =oЪCPBSpb)\^Zm $iz%q(z TycO|C * y~=S"n0 ظs~ZSCeIZ퀸Fﶃ O"/$`~\ E?{7 P|ݮХҏZ|$F`x'ck AS1]W)uQn+Pc,핫kXktuy_Z ɺOf:%DB+.T 9%,?mЇC#ν0 3)$ BԵeȪ֛;S)}H']fgį$>82rVsm4~0L_Jxh֕b1We0}{8)9r Ike}`Vgk9>G~zo'YA,O2#B7=fɁ^ 9zK,Tȭ؅d-ZORz}ؑE:2Ÿz͙'2mChݥ0|ZOrOZ5Z[-=zR^1yWΝə(7 t5ˡ 9 s ƺu'ƣ[6m?ƭFTݯa7w7S󦉢hr,*F8PNn^U0 >$YeQs5Wx|;,U2d(J׬8 ~~,7 D ٸ%Gs :٦=\` :.h"Lhl)`-7~pi`E[S$BtVJsږىJJ(&+qI9ʹ=PzH ƨlG a`!HRle%}o yYO*44Ik8Ok曵9?mt>E*\dT,c<.~dOE"ʒ<ÿ`Hz~M檿roCiEt^cpFn[jwɎM*|ye> ; AILF@<៺cҌ~ "Jx^G7hgރ:M< J¦ Tu6BCĚ@%;ߧ}ƃ(?Ȝ|B88aq7Q>Qbj6s6D~Y?c{i-6@"́7-6|tmC fCImvDQ[J_:F#e33˗X2 s9H|@P|qd&~)D89 L0 fBI&?L~s9Ɵ~`sOU?<{ux+5A7e۾0kT/M-aƈgծF)q1ueI!cB͏xS3IbeX6:Bß0?PnDqNfa3ؠЃV4ҀH3R^PBQ7e-y{KHspXFZXh jDPnKI{kX v]?ÒxhdOm&_?5H9K)s!(x$DrF'!y<<*[!/^$Fj^ړs?8N}!u?(N ҩg?{Fjv;Wxux F}M-Ȓ:"$revc)AXjd3tUJ^ݝ osKf DTZ~ݣ* 1ycH%`wρYA򤩃fwghϙ7^cmzYj{_"O# P,*iZU1%핳u[n&% |!f("a(9LdB~¸?RQ?IiP5<ݤi:UOZfkM'7j%^^Yi(Fer7g3P`_Ao[#/1q[ve4DוX8=SN+9֕weg|zoImWL:}$ڌ!ْ \<ڬCbl/bK)@2-bE|dnF$3hNH Ǜ/SX/"H1ěWԾ{=9"kRv;'!lE(dfjt`:nu(>;E;nRמp'iG2f&gX)"J"9VUDVҸx>AeWFNlJ~_g%Эi8]bY.k2&KjFt9%`n4|n楒)Q5v Ax߶V'7^h7_U\Lv>G39_uۀ;w\6*¡՞k!{W~b}j6F _?m\)ƥ"Q!ob߱]B?c۾޵G.Ϸĺ5S@E|buҎPV̚`LzN[Db[vb9օQ./YgJ w!V8b7!z!Q4,\T6{|+S1x(pk*M3ZCؘK]ꃽ]t{ 6L'ܞ %hZP#"7D5X|PC!7wQa"hXj&/eT G9wטm5mNi;,/SF]7Ξݿh@b_iB~u1.@&;s5 )/K\eЕS9KL?Bzahbґc,J/廑mL* w<.Y*t'=)hpؠ N.r-HagPILX{{)0"k<0h*Y2Yîqa$%wa#] xZa1{[`8(,#)&h3^1mt4;cĞ=3Dj)𦈃/"g=ie|SvݒׄH+C^ACv{;ORli{CL &&i٭REoc%6Z⇙aNzR+pu[¿ujtl^=[j:A_$8vm{ۂPZ~T< 攆ֱ|kEvԕZ5 Six_p5}-ص54a!0-| ٻe7Xoc/=rӂ$!""'?wKu=#Bk6|'Eb+#/o0.jڶ2rD՞f50pH"`#  4./fN UU,+=h/Hԝh8g" (#p[ܑ,ͅ?C߰߈g_V3ewBR=ƲIrB[; IcBupyLNBEedOWwL::C6- B$`d<eK賢%"8=]BG a$gwYl+_dGAhK,k_Ċ>1/?lBzpƼ MERE_.[ Ϩ'f1e@HžaE䡋U2}eHW%gVbx)Y]r(&NOcqA }Ak rz!~FAyqEĿOjt{+q8sm?I5e&zY`Oz˝ujɊz6l'T9X`,F<(8(b*V{f6K#t䃌6M{s S,WA 봁@&h=>\9ݑƙ4}&6a(bgט[A Ɓw3/ potk9n|+N.!B>^HҶZO3"á$@n SPA{XRUDcn]TqELETם,LfW$K[z,\Y;rl+ +݅/r'_$Wj2q[;>7$ ōf,|!fͅ_W>iEbfUP?QNОfyAB'%HluTiyHGo2shx,ge(Y`Ӑ u$G,!OpfJKvct1z[BS?6dƯ~g6Ka~;e 0~7/v ɏZV3o$4?lj=#u#<<8xz$<lXm|aKpvsW>8T!an8Jͼj(F({mVڦӡܴN;/UVtVdZGcj-q"XB?7 ~=2vN0}r  ЏT3ߠA!EѳgEPj$Ų!v pCaXh7w4=7,ۇO_4^&# |&\:l )0{Պ$7OQ# =݋sOzK9?=ƿI|w`/7Xִ(MEh839eH w='㊢ԏ}čc4 ZU~|YsƁ1ɖ@R&roU>x« RBӷy- enuĊF=Mﶶ@g6RYBFzdY7j yNcwC1$8&eѠC#SƼVNqXJZ ]-X<7Me;+joIiAQ,Y@ n3kЩć`׻fѵ6@Z\ ?͉GN A$V@'Qޱ/i=}LRw%oTw9< >>"( Ɛ-W8m#R(r9QżJGf.b8:+ͅtpŴ>G f6\0sU" ~ddsݪce()^3_%witX "vC$NImJ5ûF74OmI"݂  ^!Yչ$1NzþLqVߴw+ܛQ&8ͪiHG?ᄚvs2J5+g,)8уg5dve"}3nt\w ,.mUĮ? ck>J$¥?!b؀yIw0gBEe_X;y3.zq:CD`ڰgɼՉjq&ǝ%ψQgn~CxR+J c)PVf_:$\J'.Cp$8Uu;MݡaOZ#C\$hœH@B2$5|I?†*J>_8VcdK@܅XJ`BESe a~l|qP4Fs *R( Q^#wӨ5|Tuꂇ;F/qf-,{&ngݹ4/Y \n$[n:T Bx*]جtsYʎus/xkw`5 B6Z:+A()Z3!"IE(+B9[g}F]3< ;N)$20C| cHշ17w=2Bo l1_Wi{Cȶ'29PVD \X0BJNvdߧ?Q{Ir :8 %IlAv!Ol5T-pKF"l YN.,n*:=p֏V/j9Yqr|0}뤈_P"Vg؎\:ŤmM)L(1A-4W)}JOh:nvcw.*vu0 _8`C{Ϯư옗ڵٸ3JbCKJw,8&6Z`l0cpoNیIX8[ F%qKlzE=AܧW^<[f!4UXH2{öl k=VzvtO\a/0|x@2F9]%dl8R~F¿B`aZF|1Jsb }(O EICXï"g`qC^Mwo1Q[ V&mmE6ʉmF̡v8Lk`!zwI=9 ?Ohy >Q;/rHKaGG;5 *aqNp/@ pa4t LH!2ar gڵl=ѵК)6AT5ܜrUC#O|l-7_cA^x^D4áf!&{9} j8T2=(Yը;̙`홀L4X3@nF%=R  WM\0uUq:c?br=`lPö]Z) / v!b$ x2%r͌{cvKbjppJne3Y:O4ۉPП1(,MykǸ~G8Ys1ЍW5^ڝ>V1[s!UvҘ#_jl&>h6 ڑvk74J>+H愙\zxGG4$- Ͻ\8E+`p"Z_WfruqG%|2I6JKQsZPz1'|e괋*~ zkA-mC .k i]@XƈsʋK37 I㧗e2T"=~ e7:V7ŋ{Lߋ2h](",4u6xTvgqa.`1ZwY[`jMd-x -TJςlUD[~'OC"w"$uq)쨄V]l~ewn>a+hk):OƨT~(b)iV9]uwBY(2bלjo:h@MwrJ³;tsX$50G^T9W鰺?:C4IWmaZ!ͳ3Z\w|xQvPyho5N\ kt:F+#%aL2zc97p3y/G$\j0u؝eQU_Ү3(ݟ{}ilh鳁M䙯kqpEGdnُDdlב-Rf5'*whpC,?D%i`Y[G6SQ/;[_oCB\1@E Cyg gQh"D@<*̌uZ`jD@X6nץB7mQ)($(H6|I,z_U4gL. \t nr`~kb:gU(oӻ&8kRP.Cx{W' c 3E:J%H 9>;%s̝nR0\*T41@F,+cV3N>lqh"kHCe R[4$Oq$ BEkQ[/C;0$/pdiVCZG<0^ :Ee#BzvA^zC{'+"Xy1nb&]5ηTwuGiV~&@GZB"m@ @CP<~ѣqR@g3**[؉6ԙ_=]dHAB 9iE:)1SNZSbstGbY/F0{Y. D坴4\(ŵLNǞiu٦u+rx(P>Eڴ[O@?յ L1iZo|(rlC/WҭLNvWdka\#[&udnjCw >qpp/30#NICMq:̡^;b xKi'5PDh.zG>G*Ub}]Q%T/!:s+n@Dm*"#.]Ճ~n9 @YzJO7|UآC֦a5g]juO6ʑAG`sZ֔m;,t߂.?@ B@`I Mo ͟ p JR[+Ac4<+=r}ey3ʌa YM'MlΈl1B&pViS2#i!۫RtN"R6?!'ZVd*ښ 6ZQȄmD_{j!o8NMT8mToa;T,.ᇅ2Ao=ҧ+}sTܒ¬u҉`]"jwU^19IȠz rPfQ\^:MKAmÈSSi|<98m'9yz[ARKHBu";aYqU8ۮ5ċ(}~./[e:Ă^ )HJs:j&+a#7‡6k32 '< /𩿩Cj$o;e ʲ3uwLy7b֞j\mbBFo&ZD IG+Huk2L+MNC!F%&5 '8vm }LVxo$oq &o+%JT<$θ!@KD]Y84e&/{?:4lP=Y&+?&7%ۢ< Y[.ELAA!_"UWH1.@p Fiڏ$<$NѿHv88I#W祼.i8 cz, \M*Z;/kLV-7F9~yұ|Prj N 'ܞV۰*by("x<2Py;+̚sq֒4r$&e<N^̶+׀j1N_D|UzIZ]ɜa0pʝB,PD Ĕ(F豈.ņr]ڕpW N ۷l{N0dY|FDkaVO6ɲ(YQ=3Q-6S4{-͈{|x qM-`%lH˄ayM 9GOL6M *vH6|x v[nIfdoEX}h^b41,V:I%vxtx*:50V=kOāe+4A=uxۖ+p07}|nI)0oFVvpCXZ覞h q90_[߾0G7 1b*W*sڲ~#;2+H[8j)Fn $`wh?z,B&V-$ktN864LJK׌h * \ǐ3` O%E9I5Z0vc--2l+.=|,vC8I5Ќ09!"ns!?~F\T菈s,hNݏk3q~Xt1E!䆙y,M{&JEc=PT84:\C*!GuMMHkTh@R]d6:5.o$OT0@7irCʮB^ÝNMQ(&"M9C"1 `V EfDZI<#,"YgíwWl"U빰̢ l\É%l0[ 7%AIE~@3Wyǣ4S3~! [ćgdltsνPsQH GX+AC6 A0 "G@hO-B"A(v98+ve]ɥi#]қ:J FQLe۽_kg4<j%F*x"Ŵb$/*Іs L!*rt(Ӷ "~6~ qvѹ{֨nX)^UVu3}nC6Y'~a.1ᤋ%zAjdV}G|I!>"ȁ c(:/.O;mT ͝Mͼv>:)015tţMs;HV*Ӄ,3۵"`M\_-ڶsї {pL-KF: +_k?; gv߭HᔨzjbR!g{0GgNdX 6$ ՎϠƐSV7@nNA 3<%fT`@ [̣}{"4ln JZpotl.r~{~JٰoƦ.+q p J ?]?V cj̨b2p_YsomUFQfOB/Xonq2+|⫗\u\^xSz-+aߧoSշ.]Mt{5qBN ڂ(4_A?^9$3k_ {IN ʊgP+j` *~8J~Tڭi@t l8W[CAer=qE)MxAԢDYy0e }-g[j9!Rm7ȍmx(-1)^՗m 4{-v=jˤ0[h:{3;k/$2ۏN DPJL"i!dfY?DYulno+#lEUmUXxn!4]=?$DLf=[V@Ua΢nPh?D3y1WHzZC=3=s7ŽE&**Ɓ؀gA6vLB鍛`j=tEQInC/[bk98^:n 8(3azvnq{ǔCHD,>%rT+~u~ QДKg% ~|7=*C3^gVn-wAoP31E /' +!ƐSzp?U0Ϻf}Į H┩> Y`Y"y"u}Unloet_ -0OV*FwHSuYwSC俠niTA=t\ Ĵb.eXAXjnĦp3o) cGKxU,ǿ-p&"BteF;;.VXqR?EK ( '\ӚC }JUhW#GX  #Q{PmFdMIU,~ѧ>CIOtB(PQ(j3E >Ω*769m ک*HGZMàU01R+ 6*oL=Xq4,YJ6:?Ȫ CV vs{2(T2o /`/ku' +j*D /2A; E&v2@3MB\5:jAA2Hd`A3; la OYVLHcpq VYFYca^CNJв@!G`nQyA2_KI2MPI{B(19o\Zq: {y-g+SN?$sphyIh)x~ӓݛ7Vn+7g191Ԡ%K}5,(Ru4$Q+m#lvxʶ{Cnj WC})3ؽ*5 &adk& #dU`G|cm-%\:V6s'~TU,oN:ӫ ͨ c!7+7Ob]pO_^:inQڲy#S%fa޴bI={pX.w*p˰TGGzJnAOsgtVA; l0M\͚Sm/Kw I}SmgאKo9'W[R 3/?ڶb7ï|l½PUh"^i7+ϩ+b͓D`{^v[Q#D37t)In].g,!GFFG6f'勊ӿ~H Pgsj)g*Tή5gޟ/6elybD'EAufl3d)vӸW3Ҷ5'B|2 [ڧ$h 9¡؟3U^?j,|0v}͛†^HO14uQcshjfՈvh3']5KCZy=?3`rϩVtui7yWփ;= dmKOxkȦΘAGy!e:0^kF$@K(G,9/ e -] 3n2picO'f:- }h@/Z?,ڙhRq$/Sx~DZR|)Cײ7f_sv~h'6ǩՄ۷bD/,i䧪ۭy,p$6F)maKkN"^"{za4:"s wy²b,zwBɬN-3af{N@¹-Z /ϓ5KMsJq?HmMBz|T)Q OnB">Uټnhg3YTƒ-u|_9~@oA|m]ciM"MJ4:[eڀ> z %ٸ IiJ{6O?ưhNt MM0qnѮJ5]zȱ<=YO~hc,E30a)mGI;NF]0T#(l;ѳ)}#+Y/(u,+kdP/DΨA|ZתF 'Q?y`LC7+JvuN$\Nۄh7ݢ3ܕeopLJ5_]hW?C 3QT^ڀNکxz[_(ܧO@Q.Za!NZj@'3;5t`$y@), fuIoUk*To̾ ,jdau_0;m~!L :]0rp/\T]2OXlmt\@E" ͊\a]W#p9, $U6Ե2(7 0N®bp>Gew >$eC؇#S0 ([ q)s@HvmKC Au{ah ImD"CȞW>yxsR"]Jܰ9Ǜ!;Y(˞/}~!gܝwi3̝KlTAF57 ~6id?CuanVk]\cD }m9> |7I~PMj(~ŀ =W m$]K,(yHl]t"IO )f'ym~cnf:r8X8ŕZYcƳC&QcgkzJૺ2vN9\Q@4]X_7G7B*? WVk"nVx6k ad^G-ϴOu#,$q?Uߍ-qTor3.C ?Ydw6Rqrg]".@P{4o1TQyqu+hB4y_8P,pC? .BI8jy7X$y$dݬ`}0A_*>R1|()"|dj{7n6 E4# >Y"Ц,Sdl_ 1cYJ-) LG+ؘ =|a, ӒZ.P5e'?nv'$ԁXFcvIS?,1&Ml䑲Uͼ;*/,{sV>Ho>4fPql-@m@eD[i\t|73IVr*BOw|gk&/H7\9kSO,)a=gϹ_vRoG_I{FF^sר栭0DSth &1 ʍY',Ws(xv3Op#C+ZNrMTO:=<y }YzڒDh?Flg;)Ԝ˽X|?p5zע[S@`G\sllC$2eFBίsW.[TF&+XH}fkas׳Ё-bN"Rߙ2كEBvNh _ h8j?ʋu a}V8hewGgЬQjs<"P <nY@O3#B; D͔oM1@ct]LEEI䐟&8: ;4y bkϬիJ\ZFu#+pJ) "d5 MMOK@GjOKH 6xGϢnqFW8GǦj6^b$5s6ɎtvrL(Y~8nOAIPAʀ{VnWpx;\:C ԀAP&z9+^*&/\+pRm2NZy-9.XFAm}cq/Yi |05F41KXTKAQO Z54x|-jUFbvBતʳAS9z`\RPχGT7.C5_';ï4$qlA#^s8q4^@BH<ꮀ\Y`2 ^(yϷ#͚=J§Wh9Yڨ=AwUT w]ؤ+!_G=oMt?4>s BەƚMk9b]d oCVū[Y'n#.,Bz_*ʙjJ*[akM8ƌ/4 k*ǹg&^8s7oS&k/1|R䇲@_x2xwQU/`Ds`|U^d46# T:Ğe3Lo6.m,/4HHBvx,23\rt6޴s bz`(d YÖj$L?ō7&n%j`/) liE)rm2-s^(Cʻ U>uι(vnf*X9%7mf::sf|&k+Ku)DbԀ_CNqhÝ/0K uľCY]\W.fMD"Eӓkf|^A?Eaoϵ " $)X,Ndw&|\$ƃNҚ/~RV}\a{L摖8P L.c $.L֧v#H@~3 hQX+8 }cGV+*si0 QNS>]i&Sꢀ 2zA̕ :aqf36ǢWd^=?ˑ`ujʔ{u%ĴCE&/4s܄E跲tm[Sפrr#qsJm`37kS9|.'#&_>+vi) laHjqsTZzlhPi"q览Q @աt'S{YNX6#QPrD`z S̶- *DJ?6/2g} J.;uk\^e‘TmuJ'0#zc"}8 0ߩ ln"6C&]pvɏlPt E0S<[b$TBLj noBXkVfn'ȃD[~i(@|Ic15Oq&WVP:%:@-E0'sGZ E}:DV&S IIK;6:Ⱥ`ߘC è$8əζwN%Ga_iX`0 ?WL͙ Z[TnUy^Id~Crʔ{6 _DS-EǶ !M2⳹ ~XeӔ%:>h{IO0= 2P&iߺ_WI(bn%99zDDBZe)k0;sղ|EtM˥n[( -8wwڠc6u^p#)8A=^pC0'׎1l CAezŸZ7(fO!7Emfȸ.'>1>ۋY7q$R e#&f7&m/{" dDRog2{ 7W9R;d1_WfHB<1MO1/bc Ӵ;1{SVo1HY"bLŰ[QXZ!)iT\..ikGHƙB9Diok8QDpM}@]5!v&2f*[shQ7”<7d/VDwCX7FUAL_yqywny.,R+F Q 7Z悿S`+T&(p=! bF4O #Ҫ d)rzE+Cp+D6}eDO:}$3[=N )3#t$TP@UЃ?*wu<9У_ys wNHnf\p5}01#SA}]Y, ot:NZLDa!gtqTXSiя1oaΈNzT_0rx1P0\J#lV. }RPnʕd)ZG^u!޹ԭo^ǕAGi'r`lK@G5"ېxrFUSx݁m\8AdԧyrTg1GD~I=R&ngkmJYYBL!b6j u@6F(4E;2}p) K!x SqkU鋘k`xiѺ|~`.ٿKsvЏvʹ7%LWYPKC]^c2lS!!r'<՝LۖӨ= j'=p|[Tv<s8Y1k*3Ÿ3.)½.?˹OsBIE̜ceŶZ<|iٳk qGOcGY/SRq{D gA%h6r3 *!;P,TDj|>{`T4O)l9naRݦ/b[Qt TKa(([F&XanS)/mzB1{ի(:E|3>oP=5j`=77dB}@~Guw\SR$2TW0[ T'v{VRˊ%KD DיstpQͤᡗ엗Oe<1Q4R#.gUs(wK""Ͽ'b>@]8"\ D!<0NG,ca@;9G8'G^kic L[wK ܵ$rG |9sC{B_Q9Q'O:74B vmuL &ݡo\s9=*3OWk]}dϫd"&R_yKPэ"dgy}b ?5S;PV a<lIYp ҽ>*uԡG (nUq(dZ=PdFõ.lX}񽌆`|踀u:0y|ѥ<~Zoә}bo' 8[_K 9 O.B(l!@nD LHjƃcm!{$Rh;wjGP\ KXjapZs T10)ըS襐cN}j?Gޱ~#.HN pdA8fiUP#X83c0.Q!d#zPç^c]S;Т_3iڲ/@w.Dqzj2{G{cX֟PuH2ٴ/i+#wK=PTi)ϡK;vM@*iRG.γ|m𓿕Dk}N*&9Zhim).B7)[dPr+ a[G4?qz9'p{nUTNDD{과oJ, uVYߵʛI.)4I#r=:X 4Wh)`gRyM +%6vAg~X D=UH#Gkq&I$խW=τDâ dU6@xo1N7.jVkQiGa!u9` 4r4/L3 5)ӥW(BXY3+ta/yv? adޏwQ%:Sٝwڞ2 #2/0a0ץ4?&P+D TmDIMM#(oo[@4ft3Ѐn&>EL>ɓmdX5F"=Yr!m诚N0M8pR,X8v+W9 肒J|Wk_m"O SHZuALGZϖ#pCXelk%'mN߿I? u.nx%>-FfguO+E){>6?LB:ΡuΖvJ"Db]MEϔ j"fFoVgҜ#y!at@2Qb:$F{KI󿳐q0z_!डLWޙfբ9| _ZEw$rEa3K~/oOq]?VM3-StU }[ ^bj!;6'ubjȏ\bqQ:ᔻdCm`3-b7*9S 2wШ$4G֮`O0y./ _jUZhAEh))wc7hX:t(H׌)Vta"ܑisL2 oɓs>k3"5sq < fٴ;w=,=*>d w˦K~r8eE9&H1-@%ǜɀM߹6ՖY1_T<3mK+1˛CL*9w9ŗDOYYX-*cPws˴D@)|;(%*-F>V3yy&ᨹoQUi<4bAG4\$z,Xi4[nٜԑ5s.HbK>%=pYlŠbŪ-!TP;) z0xV) /E֝Ds7AIȏD,k"d=5&j5K( *kL{ge/XT2{wV0Hs䊜V'^JqHu {2ǮeJtv$\L2d:F4lewH[ hU..m+<{ JN+;X!qimY?1##>PLo#88Źo)oiMGAUzKs&bDKg?`*}~ 0BJ15c^6D=oQ9Y%EpM|np>EQ+/bg:gz9miaZvp^- ||cLqI{z|7%͉pdQVmPKb2]lڇFG> $  ~a.ސt[wƄ{M(K2,- Ijb"}rU-x( yڠei@u1+"GoqE >C8k3(tj|;#ꂡ;ߞ'j/$\k>#B??3*4%E9yˬ҃a!}" eP+֬կxT?oTh=JGɌ#>YqR0N@N$.v' m<QuE须x`.`S{WHkVqh`A4O;Uq;bkUw<[($$)>%$l-z#kة۹8?hj-h +@~lo;Y;f+2&Q͌<`֥|f[0%n aP'{݁j+)j첏M?&2&PF)13))k 4n vQm! ru?9qS A>WmF 5(`hu.x=3) }fJe%d-j"$&F`-6QaȄ! 1Zt2Q0\-rC AfN5's16mi Iz* >m,vO;͏BI2;!`ChV`Qrz0;לǑ8Q}>!v(٤ 53Sμ[w)nhX]#CQu/Vl#eo=,xo/ ՏYyc5B=|D3.DW34ZZ;4]#YR~[խ%g@q8dq 1Ҧ9 n! o<{ߚIRTl{˞5x[Cwpx6eGM(t/ZKz 9>Ɠ$P*jD'f5mnp(HErZѭ'`iuL3ژXJ ){r $i;?d al,.gP^I>9#HpP% ÜJ~V-;FOp9{΍Z Qp-37*=2JVuEB ɇ9?Vd FOSv{ riӭ:5i3!r0T5)f'0=trioL U)˳n0)Y{Ca8+*, Ch]zWmjth}Nq-K3NYcs'l+Kڊ822z+I?~b"ô|aH5zgU(lqʟl@5 nLB0}8Ac%1èh:7Z) [X kdl8R m%e 'T:=䭜ݬyn4Sxn3Oc=²OԼHOi)ў?W?! Gx$q,ɴ ]\9H^s :cOs)bަ=3ݯ;Y/-f#m: ;L+7 W(sHu"IOuGƔXmIsSU}:L?dM)RC,5\Hj&T.&i Ql{"\!=rG[*%`U{ Lg,{70cN&q~q8Nk$:?}2DUlSCZ,:AÄ"y,\|`fΔv N ӊv3]bq?+SL mgc퀐l>;aIAU:/rOA>\ns[c9-̐h VuZ9A{@2UORJ`t+u4)iȅwmG˪`G/&-dhZ)f21E,e]Ӵ?+H3 _ y1QRI7.^M%tmp7|Jqބz]Ȟ͢[Թ7\g(m@m_/pgU%R@OYܾ?9Cay DڏSPҍf>d GLkgLDBt zubm90e *ԃ7*9 U膺D ~<WY}l<f\*=I9FvM ?&hmcQ^ oM˯ bJb?B\_:~}A`,;7NAl%v3l߽U+֥c{yk r0~\$NZ*Ka |ş[+Sod.H^FM:|ѧ/~ޥtCP yF\ /+0s6H3QWVh͗-!狢j<\R3nQCNImGbOq VU~%AV+::82}i‘}@`=OܽaE]8\vT??0X6c5k2x)Ugr+4Ӑ\lN=(~[ a\{Fg9jsd@X`:)Ap67>w4DYV 3(혾n8{B\nq m~O[_@W=R`ė^Rwo^c|9ެ[5Pens'-6lm2& [[3l[y}ַZ)D۽cy"o-ߋv\^CIvc,rql̨:!w9H"]˙:qb gS2tSߎ,Ywe 118\=Pч%?&DKA7硤E ?ϭqQ-S ˘Z9cb.Rw@ ׏ŅAՊ?e6>|W->n'j*08zR9jfRwpFYwb;prl;<Ʃ<]{\8$յBs_3.XtY2P vٖ4W)cTW/nou 7;@lH@oѧFԉdRW0,Dv‟0͋D̃E oex#b& /𠍧ZBAHDcg ze +=?ĭ|q.Ô7AJ5P]^xySE2t5xnm^@Q.<f:Ҙǐhj=*SvK)eXbVU"*i797hHɡ~WZt{m3zڕ^h4kG/ҬjO ӥ])~Frю꣺E(+,Ji tJs_x+-}~ȼ::P5Hhf)F?,// ǜa ^sn:\ThrjNJweC6E '+Y([ͪRY`Pdc-/r^ ]p}bә458)${qrfMiP rAC }=kQ"pzK!at:BKPiur> ,vjozpQ4%C07pS=vp-[9?d5`/! +g<3 %5PQwN}6囬46^]j7~yk\J#O?/npPV4iH>ʰi*sK8]\U&?&N%*& 'ͼnV_MvMKmRFa%vrGoZy'rC~?v  Rqɧ[TSKd^\:[1Rh=?)C"C3Q,˿Ux`a1.qZeuv:(#[h2to.j˯^1~5l}sɂ +yUE5 *R6k9WEL>o퍲r둥yȐ@NHaIG/%X-ῼcZJ7wGbZ>f?IIZ) H9׺X9R>q#F&v_CNo<~yPw«Jy#.7OVssڤӒtҳB$ƶ^rmݣ*"-ꫛltPN'B,Y.@5R12ABoG7!ڝX2v 0}ABQK@:uEL*mE&T6SʷSݠx#I܍}WX=UA$ 4̴| &HeM#չy8uò X$H s_ >GP2+L+O XH!Rkjg *Sk/`͗S0ތTypuiy⨞>q]!jYl+|(sR"*I69KkAxETIS7**lt0+B5 e=B̀Z{^H.p L{ߔǬwl7id<||p} i2qvзA;83KT#*-Xg#Db=ŜTc hW3YQPhAYN1>&z2oVBo7~0*0ە,F)ilHEi&-TJ@+gŭ+9tw$t"/f=g 5 _Zh 04Ⰷ6%5TóE~ӮꢆVbuj%4.` d76~oc 5UVv \l !5Mŝkw1Цp`"S""Wf}B‡:vG7F!Fۇuگ*@MTٓ(S:n8x,r2d=񒪀'0jc(4bp ?LĤ?M&}0@7G=إO p< c~Z ,yyhms$ +Cb&^f9 BVZ2ۚQWG.[+1UEtYLjhahˣ7|2Mʱ .FKՌZ||V;B?_p} )C=d{Ó:cWϟG@:ӊ+rv`P܏a si++\Ng|2#:L5ׇ7ou Y>E&~\Qҵ\;t'@mBb@u.ۏ #h 0 OO@QECT%nٵ?m̬ob5U>}3HNPgaR^<CKa>/fhG~n*"ȿ?s1=: g8Hb1ϱKDEF iC{ hT`bO`ӸDFdVzKeUGH 6&82"B\v}Wq>61<7v}`. 1 #R\o_`E(k$ې$FOp?,jOSRzyw?8SJQA-Eܗjt;F/fPXlE*mz^mI<[+*-qݦ?t3jͬ{яa& p;`RfX7 lT`@3KwIISiڡFfXfOwu yx  \uɶO꧇^6JTVbv&;p1ı^U>R*J9&F6PyaGYv٥rmݣϤCkfqy5H2fL!2a`$\&Dإ1I*SFybYyTYN,dvXӗu!qn#b`U#OU&+oQu07~t}SiZR9tp9D&H^UCL*I`Ej̰FM`Uś%&H/◦1vC!=:\;~S{b\$Rt)&d?@axR̃*:YOةxVy#9,A-~*l|sN#$z<|QҪ/-.0ݟqXw@J>? gK'I'r(0ʫzꛓvcJ}!Κz61_C畝 ϳ$UHW9O9͸"EҜ!H縵'a$M& Gyvh}Y.oװ%ChbΏ o̥3x .ߖ,1 ږn|=;dh7AaJ$v{"ysm@$S4&m|n+xz._46N睗DQEPס2ߝI[UȔuمr糄H:ţێ喕A 9r$:95qͬ?lw ,Lo;?Vuvp' hgJym:XjuRʲ hE]Jgɮz  ˶{78jc/C]kղh:G\τw#Bz0vO 5#dYaɬ,,,l+;=ʻHGHTȧʚr:L>}% 7~)nZ,i=0^ i*JE2h73fH>HvZc>nTm4#: _it]Y|8QܞFww:q =ڵuui MK vKg[a8uoš&ˈJ_A{qAJS9.;I1%=`ovsîOۊ㹙Yun' +GXY7mݡÑiM\|*%`T[igގͅK`ZI ?^@cwub (rG bWHwf#4`C%q)PThj/;= f[rEր ٻݧE}cю%eЮ!@|bt Qk9Si_:GoeZҸtNns* ژ;0[|GH@R>˙p@V[M–B$@-ñY8Q:ogjl(4<$(}%j>:n>Q rq:ڊ/ٔy. TRQ駍&X6>c4dR} 0E<;T`l^XzgYE!̦q-0\J#tFV9! erdT&g\l"# wCE~0Ьw|@7 d|u FMg`e<2 RrܚO'\W,;~ ]n/@BO@e<߬`GїO܋t_9T_\1"Hyٱ6ryc)svUuMȋbQ"('Fb婦; ަAKm{N /mu$sD[~҂gj6C6vwLdT$ qInS 1;˝I4VĢhr, goTO3FI672@,\:m[`5U^5&6R"K< ʤ}.~/΍ljn!E U;F9J:,P21 +:5d]6pJ㚫_P?<%;ޱep(T~K|zR0ܔt-MB5gB*ؓ] X;_"Y5v C-WiGOS>Lͷjr/Qˡ,/L$] )X&+π#)Y Quk5c̐劘jWDw`RdD*ODRU:FiXW#1hcHu`iyq]ZC9N$'y,JXWH?7t7-YvK.K {J %IAR%k2>m5:q8Ĝ-, A"N;(dI _{ y,@ _[PxE /1E]'j M'HoH վ8!YDsOK._w!X97hu+Q6| A-|v m DB3X(Զua%+cP7LF𪧷Opf3 `ntJ4 `XKzw,}%>%^m٘禧= Q qvjs4B8F/nT{Wʛ}. TϚXn ^ r=Jn,u0&SJG.eyt4_&O@#>^.$EDmRViHz\ ] U,LP>NIhÖӪeG-練w8rG F获S"h;cey30~)t $lQ!Cu3Ƚzm;VD"YZWo^۹R]#OɎ/;[/SA/DaԠr&v>3ʅiJcU{:*/s\pA߁vAeeݩWFi7~/vͶC{Dc c*JzvM!f'2m ?qp 0Ⱦ\PgoTsQ+#8 Jコ{ynV&Fǩs^ZcQϥ"ހ|IPm7b^ly,zAִLd6+%|(_l|p!92yμ@Q,og7"\? lTg]dLf/*95Z"n2VeNј]i3 y ;8J>a* mQ0j]TiLUio= S>.4~VzrtY/t)(AZ~n&둹ZItOA?c[6,j}, r6#(}Bp&AثfyeS=a.YNJ40[v*M95 s_\ gA!qIGM dDpUYE"჊%9./ 5iG(j/W/OGwбL^*:54ѐafzKs:ğۡDJ͙"ETTqK`dX ^ vnwbO+`4 :=7̴]"ҷlgµzK*]vnA`,)䶯IK˹fu^WS$7儑(Ǜ׹i7:^o&8بUgPj{5B[nWXcmZ|38[zvIi"4=Z!϶Y^ohG)ߕmS"Ê.(KN_lQyGT;:~mq=šSĸ lWMn>zGdv)0U %Y^ ӡ !W?pDR(*$M\Zi*m~X!Bb_`Q5? DWkDk==|z_WW(g?O/?]#ha\%DՏm<3|C Q~oƖݜr?`X/hpfB׷$gJ +I^es-Za#{~zzIEల\P_/,miMMKA$ivaq=[s7׼/EV=yNjˌgd|!=hp("ъW)"Dn̸3w{Jդ:$et; ZF d鳽#IvF'zN;z[@Pvk.<ip{&y%$KșQ~dqVcOS0('aOr@@:GZ[Ìfd(p=ѣ >S .NB gB}ԭ>f 9 Wezfdv-yM* $ m`ڭT|^SAɕ 15zKD&yͥc`ҡC³ .s8]X-ԬrzUȦݣ01Its}_`m ~@dl)M+ϔЫBv: !=THm4UՊ䓇CA׉.<"I) 5hIʼЅ6 d|~sZnaRI*Al_f̝=cS3NEmDz%v,Y3c#vD#{H'pt6MSbzP/XB=lճp5{"f^ݎzU^>gyԿPazh&19tvݖ Fl͒=] 9f3'9(NŮ-%Yv&GK[:jWԲ9*koqj=~H㉑'" \CP^;Q"Дĭ;totGAع2. e\1BpF CVGl:>4+  rP_]{Ra|C=i܆4C@?+:A7*@hX?u:<UbgO+|,C-鑪̵"ul 5 sBDB)AMf;hkrHT~ˠ*SQ({&H(AeB҅3 !Ss8y1\F ȜjfrwƮI*"0 dtQ@k Z&36d)[e}ƛ$<;LT {tتCɛm03\M{LaE#͡oq̊ڪfrMHOBeLc$f6ޢ{XK8qȵ@4}g]+PIգ(0ܱٔ#llҠt+fں. YP^a_T1!3e'oLd ]ëZo\U$n4yu 9f%o \6zFEcP4)Q$_PsL2v;j5pl85CVOV]'.*9H͞@N[rw[,%y,"aj%(TRU>![=p 6Uq*~ h.]璘^$}q޳usf~8z&ބQj ! Բc1Y12\6Rοt=[@s2S5{~j[ UBi\Ћr1->1P%QVj""L"Q&y]A1TYI<+D_DE0]*pL˪iG\S!dm{r2̹<*KFRTGtE,RcYn:Jvs7fJb[ K߶Gʪt삇ьf9`}ttowI[ 9 OFvjmMmkr !+depnz]ZԱ5f$0' 9:IoWs#)8{Opl9G24+6v>gniH~ 6i6 1RJo; KsF%Ǒ݂7ozY!ϾX.SAgE>up )&zIKG+T+O4 (VE-f{]m?<#6ZA׻ZfII Vger- =g h7nhL8l[ f% YHs4ӄgcgKDw-Qo47g޾J75Ձ:ωhrm{#~:_8#$SK  b̀vvȽ( A()ӫ>4N`b*en^ȅ'oخ(L$T>D@%4+SҞmdcgh!#?mscq!s`ߛC@e%j7{C3y{WH$\Yjfot˃BC">9 NV̰VbDN_}**s ď0]4ĵReV%:0T VL}oSG`s/ :r -f3u$ICRi<"~*oH%4کB~Ei]-@ڹU8%ӏYQL=ó'@rɦl(Ω.Wmq }6l2rZwvXa1CPJ\ArSfҷ$bSX{}ˮ6sU f߫~'o bg6n E$HEpA_o~{V.ij.n+Hn  p=Ǘ,Lvtɿ{_{zmX &y C ̣{p9%,]cjT6iBR(Z )*zKtCW_G3cБ+&3>--lXMB>>[MϹz]าifˣ }}o/3f@ YZ