sssd-kcm-2.7.3-5.el8 >  A c~RU]a @(ehfɸ >D#-Awt lj,qfZ!DD5ƽa5Besܝ GS:ɉ/ <⌯:W @8=~2GNvq] 7 5Bvd!]iUd?5&8\--w$FGkTEBu$nM n @GΓn0֨ O: x]pG v)*]ݻ"in@n$"+ĉ hIa, u҃hf: AC*0"cĢ&Q+8yfP&u|ã*VTr:M;BV+*ԎEQZ֛O`>A4/(=Cw`0d-CvnH V1RϹ͍gH:u2oIU?R6^e8zk+3vC;skAטc2e1e81e4404650fe66a2a9cfb7f363a79055ff27b5b270db89f3314602f804af199c684646c203060663b1525f36cb58b397691ȉc~RU]1&pl=EscW_DZV(5v rccz8e ]v^gɁj-lW.n] 3ٱal\ -  jn6r2pK; sU !N&*VCB_F%n UUSAtV/`d{v\ݜyǘ>6`SL*p4Z9e臏' ` eYMrH34[)y#ؙGm?4l(((rr x|>%j7nS+-VqRlyDd SMKmEFݷ.J^͉:nރ]P}N]$7o%2/*xٟ!#0|}L]BCwj3#)Tg9^<#Q ӣ.ӭ{]hգ!zd!23\cаeQ-urJ0OHW_>pB?d   B 'DJRgx         a     Jd :::(890:f.>?@G H8 Il XY\ ] ^ bdeflt u vTw$ xX y-@DJCsssd-kcm2.7.35.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.cs aarch64-02.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%6NzځAA큤A큤cs cs cs cs cs cs cs cs cs cs cs cs cs acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd479184a96ad76cce588bbd0bb326ba2ab14cb0f657565b2f9f33c7c9d5702946658f2d93b2d7fe61bdcdeb9e4a904c772b539cd2f8a63a5bd674dbc8440df10eb8f845c638257e9f706b2e83924795c1dbb1eba5883ae45a6b2fe0c2708eb2020c8c23d944f3b31076c2f7adce8963b7d0f2164bf4811c845b7c292397deb4a0eb78bc0b4bb32aaa86188652d85534adc3c69627fb28c670647aa70d4fca5cc80bfacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.3-5.el8.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(aarch-64)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)krb5-libsld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.7.3-5.el81.18.2-113.0.4-14.6.0-14.0-15.2-12.7.3-5.el84.14.3c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.7.3-5.el82.7.3-5.el82.7.3-5.el8 kcm_default_ccache.build-id560b14f5721dbb76289788a0999f63859e799932sssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/56//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=560b14f5721dbb76289788a0999f63859e799932, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)-R+R'R0RRRRRRR)R R R-RRRR R/R%RRRRR*RRRRR RR!R R R"R&R#R$RR,R(RR.RRR4utf-88a1433f9c21010c44f6dec3ec88b71b5dadd70c0a81922b93f6121fd4e3c20b1?7zXZ !#,] b2u Q{LUVB61>|4ƛmk#i503 ~шgՋڭȕMQ.vKg,,bzQ"ʏZf+u7Uͧ~9oU{@#9kNl0%|_2}S3NA0qd J Sр`=r\)"}o ae!wRE_JfU/'}ЌyNI/Ea)WгlOZJsy\OiHԫI 3,ˁS71^ϰTݧ~E$!?oY\t3Ԕxo`hǍU6#6]M2AZN,WM. lԻ;~.ùxs nj1)gPp:pWja;؍:w|3= d!6!l+v_9+@*SA!~-6D+l&*34r=C]|f0U>:[[ nnfԅx[Jʥ9= :&-zHutT r#:J5/͔7}w#EB,=G=*ɹ/Ӝ_pثgw:?IJ+ⲀEBA7+[ rþfjUz_p̪{Ka;HdYu{ɛ7Djj76]ra!u5R$BȞ_wSa'I^ijNxcA1:Z>lv I=S|"by2?H˩(߂2Ew{V>0hk3gcJH}䧫ʹ5(|}R Å'jdb?BẂ2Bۜ|3>$l^ so=2Z`[dejD`5R569et=b[}>1ANrXaSEd-  TH7h4Uc<9]}wx~i6~)g{WǙgCֵyQƭuWnt,Gkժx>@WmtPJg/t 7/]Gn"6kI/6zt?KZsG &ݿTMj֔u>&+C:5AAGE|.y$}}+_-R[2o"~Is*޾wD|NSS=l1JoxUEQV m oπ7+ 9JSV(ʶ}TEt2[tO+hX:Md{ .Vbtc|pe 'k[|[ŴY 2(MxXۛhMc|>Bp(Mf2i[ A;nۼC0f6s8LQF7/ } D&?0HR [ ceN!v'-olg@YEPC+AV0NJ,ٗT ^Ϙp42yYYz &9>Qjf7 "w+\DS20OtW ۪0Ǝ b|X+vpHe{:j-TzzpTQqB4,֌9wݲG[ٸ?H6TAkkWtnPm !#hLo3^ nU[3X#K~n/M)YXtm)h^Yx-ZjO'9/d 7[?0`*+0WYW WqӬ1ⱴ2"uf1^bM}R:Ф`deaJt;\vZa]M B}H&vm$8Z8nC3hW2tW"7&3vTM.WSGfU--~)2~8QDT)efB=bI_e{α7HF vĪ ^!l6{d,Є ϺR0U$? &j C'g=/.-jI2ZP?}jx.Pή@Ah߰䤶lVP3ǭxLҭG&?gge)"_w9 0o۝r~tIU%a2n_Szb/#~쪂Ox')x:Z޸\_!fPU2&x WKQ@Wjb&ͽ”_MB+N,x]iA-o9Lx%,O,?e'd5앾7[u&Y) ȮLE}Gbc1٘'.اopOXc}GW]U'=Xz>5ރ`M\4z~. ٤ UpYɯ)%;NsƝfٵ4;q}. RGAy,l/:"^ԇ4jȓ 5{ 5UJaE{?Zdm ogW=yoQ|fdI7r3ТQ m=>Z.B›貹ľڠmG^pl/=87[ HN bg b tOV[ OlD%1ã3U~WkQѶ7{cD_;|&&? n@x Pw}Cy7]f+F7ዜS%Yh8jm#ɘ0rku@SӒP%R֣-yR,wpXAhW#Y F8LIOdg?Blm{*&dW$Gs쐌ܣN,(Ԓ\$jID=D%9e*Bj0ǖ7 o8'&aPk#q5к}IhL2IU+# /;wo֑%3{pGr]\Mf w7oE9_'GT~ͿZ)WΘ@~aq[9 8>ST yߕ[j@sٯ.lao[L o\:4sVjɦvV/ X]Hh=]c{ݶT"r1E,sb@wjOji#04cz#jܭО3ހ-m#d)7*GӬk(N\ QȊ ̿kze+=i18X e x6s ӐdٽN,Y~#XGL?ޅپ{:<<g7JWy;ѓ|qQ,@5j: ".X:nR=2]*E^ XK2>#s01b m(T}(n*i8 'kpvX`i.WWT%LFéGEiң.+9;'nɢwB r\ +~VRs~jrHժh79 :TiA36X.x|b?oʎ_ Szl {[*6z$%C}4F*#xE%8Fp̞< K=fhǐj8'X3hNNs&޴1iyQh xTtBW`-mrTٟM@DEHKLCXUdāռŢMgxћ*ڨZ3_ZqDX]1/$hS]N$ CSSŒ^gl94@(D: B<%]s"OmMu lC~OvfV=kEʐeY;--BٽN.OǵH}pE~lB4硻US ֩UJ<}{_3qB<)qJvQVZk瘱Gٕ'5#G;n8' 71h Jb{Th ť;C,#9;Wʮ7Ǒ(<"T2FI5O.Ijؖ$7[ZnThdfK:4 )2>! |FˆAfWh)e6`+$+G\{ gBz d՝={A5(QGdl͘-6˗YᮻW: bTGx iH9)sӁ.$ Ar=[ NeI+о24ZY#j4*t8Jp%5ϤH0nFs&` IQ*CVO[WO BvA]_hs J}o:J_5#P/:\7#3Fu} r:&\D'E-¾q3ObtbE:gPН'^- i }N0CK<@a";ޞ sт3g\!0꟮rno!*Z2 @˃*q6@ÒwϢ˙P'da-6Mփ7dte[㔰8=_@R'EMm.R}P JsCiff:i_"~)mxpKau?x.Z5S24[W. ~^|~Jx2aY2sz {.KLX1UNTڠݪ}=rVc͇'j`B\ihrmΣ)10_\0xoZVkP=ힴNDZuDxgɯ/zj‹m"؛5 =}hm1vpKsɦe赎bVEXon7[t P} SRD&U[S if1#\GH(CGbZmW4[ !hb5quOl#fa뎅XXt|SDiI"Nr]dhhgjCN‰@| KgFW;>:fsUo$egn0jQXU=IM6RbmXŒ3#. Z^Ǻ7,4MTHpz%)B\eD'$t/׸Zj7z3 ;eA`~ &WՙrѫmNrqN>D-|*[=}ܹ̓HBЕֱ` z_B=C nv oM PLڛBc=;n)-V.?WP޲sﷂOتlf ^:w* *PsKMJ@^a߸F4 *&E(F!r'դ*:~ޙV$x"t S0]!GV^JCx2wb<Ho fY jS0gul~}lFg 僩/+$.~N:x |8ʢP78+Fn"ƚ#BT( ng»;o͜%CIDR@[+S.3h/!?kcB6grz]Ivۨ19/R4͒ 9J;⚬glE;Q("P=Ø@D@,/iL(i_76=&6yy j/;C f:]v@D.}h3~œURkɾNZɧ`Wq#pY(*`ܥHgn+3F{@0bc5i`慬eV%|qw1SSL8xz&?0?v7Ay6RNˤES70jELhKҰSyf[W{>cu#y `]Gr"|w:^mC fFž~Cf}Zqk`i}d̴ ݍDux(<)ql{uɞ}&0F]S-͞ۀ?h ]($;qz da\ Yz52Ԡw ܏I #7*"~XLhI'JϦ^t>x1uj [u+z %#8MK: ނ0l$%Yl.7S Jz(I}FEz0tP{=(-aX'&a dsheت{P>;[` "搙1~jm%kZ CJ&JXHK8=g X3Ƒ*) 3ɜm 7'g}|FQBF9sd t{j`tmi__N%j̃AR0~^^r^WU:u>m qq]_S!y^Hn= ?x늌o]ﶨU#\Me~ЂLN1Тo hRiF=lE G1ZAyG2pU_:}:v+Ț?\Lӿ#,r R>azGw,AfMv:Sˤ( px/pHNɦ]p Yzx)uִfyIT 8il~ eEm=IhGjB$^~Ich ØW]8 3r$Tkc?UzP>zdZ|S;*N5c؝׾Qw Q˻C1L;.Q=[}3!#mB6 Ӑ$6a"~.61km!olCk#U^{, 7WorYe86_vl_r҈ԭtC]L6tyw(m;P9nOzw+H^:2'W|mq"w"H> !p r;slYn."F1D]cnho=Je-$Jʅ+jސYUO9JAqhN  g_ 89X"›/,9S6l% Uq6@d C+GܴM׎Qijߔd )jE>(|RO|;k{`qJ'3LYh`bSJ W{13P.„d)Vew4UTHABK{y#M(cB nkX.Qo. ӯmY`G&lûBvjK\r@-8mGOlɒN jHST`+c"M-L̥0 "Oxa-ِDo)5eP\E0]ꙇӀG ziw}su2N%(."T.Jqa"M|tO}bndr%n;UuQAɧƐޏpbb@Gza y_V nOz$Z/k$K52p\xuHN gH&Z"ܰBҙRk @=1kuY8A/K?ʪ;·\[X{G z+zWd o6T]^և{ηDr=d պv$Ca#d12'8#*=>$u.v[f[~6ŝjxtm0`]ОF;w9yڏW/P%%X!n,2kkN(M;s°o}(=܋{]- egp2f5HқX/TJ!‘m OaNZ@ m)^5jF\1\\}@=n, wx?$r5PCW̉-6lp R[ K.`k`z!R-/8QXlP 5SN!GNv]6SND~qu{ҩV Խ|P; ]=ߤǫ6Dd4۳#""g'uLN_SؾNqQ@ݶ2~0 Ooy$R7˙zA(Hb-L :7db\1b4͹g)w<䜃m,"idoE7`-+G| k^AG^+m~tc /U=m+Iţ}; OU;ԛ@pm ^#i0'D1D_+}B; KGA93rHOqD ᧦գ;nZ1}I AJKra6qj Yҵi/x{9'[8H .vT o;uUPEݏE\ j0AQNiSIiiVpREH# A LCN!m ˒UW`bDM&@ `YbLOvR*hxuvo/i{mEY(H\oI(*G]uֹPRl>?#8IJ7oѶ \:)c/Nbz 4^(+ sxzDQhW.)H#8re[eHӮQa'޹П1UF͋,7(6[?iϴm4ZqfP2ɫg|3=|6w@}S&vb<ժ2!"^Rd9&džZ#JkGE!p%hV#s6b{3Jm>Jy9.TJS p괱cK+Dܔz{-+ckZ'n|a5+OAnux̓+4喥o5A!lqVD up"w.P.8h& PA{nх+<厞m2zsm* h^7kNdd&B_ levu6$9NǡCR IӢ#72Âfx _Ї Ƨ,#+7F 6(/=QǾ\^wIaTd.l7:w[jK -[ d/S*>Er2|7-@<;L I o5KF( 3kJG?zCqR :Ω%?eͽ^)b\#U͔<[Ҡ.*Gۜ-cLݕ@$6R-87, SPYhbN}cIbS5)GxE w\YX̶H![P8I^ٝF@g"bk%)"^Y4pYH (MqӾ/WlGFXU]#I,$dXT0Eѝ?r5'l׾%X/펧B9?l K@D[%Lq*56L5GDв=V? TuنBO}UrH_q#l\JWvA/kן_[SzyxYAQniInStyAI .H ?ҶOO p{xFaR!3+VkrKq:KO= 죩T!["M'xf#M䃧E{3,FG4 > ,R4 JZEr֢X`:$At'\K*b<ձq>F,QKī-fcyi}DeQ^wߎj+> E;6χ{ozd.zYdwvoT8|>ߣ8quܠ%eڽ<~[+ ˤ/y֕I֭&҂DwGIFV떩 B~kW0+=` B[f2#Z72-Ѓz ˕>!C+DtM˞ h(҅|0,1H1$:N]T+(=Pa <󊁉(ͫotqPMJ~տ(bn+cf?juPjw0",qO;*w G1-42LTZe\>NF5OȁU"s(3;/XM~Rp4sTz6clR+UGZuuv!eZYkjH .Yhpᡅ?6B˚@{F6~I|e;wS#xZj=fhIdv;jEMBQGQ#a+&Pݽi6Ұ`W~B^y"3KIxgl#x Jso.Lk\-Dp,#SOnc8S;+:ٰr_ ُ9jC_u!V$fۗTۙn{f2@ְ|(Wi+q"yX`D;=0Cq`Qp"kD%#C}45,ҚFDLT9 vI5 JaWB0؆*6E^}9>1KɦIeN.?U*U;=9w _aR1xfQ.C[9n@UDOlylcN3ZԽs3 Te˟3#0m w OM=# So]1X~>[[4O̞NqD; ΠfPE5hA^J+ 5Y9A)=Ր5IˉUP6%5D)lm!g*Lfx5j 0&u= 쬑]bܵb,R=fZ"Re0E;=i2 8` Zǁq.1bn=&}kU) F⣥pWp?Ta Iyͤߣe|*ٗFcj˞`qA;2>WPd1yD?WG"'1ī9ԀbFUoMh#{8/(:y`U5HM4çlè^YB[B(S ة>- ĠC7.ݖ.$ ƑU qn]3p)]nmvV/k֯`H>9> GWo5NRA3 xQ"Ŭ}Ћy]]6BcZ?GyC;|rS_4 qs3vp>&KBxQ"Xt~>/]XviZkiQ;J,(K#)*Req3NgzsʬV"D8w{׍N)SK&XWhk%iNc=g #k5C.f)()fVź̞CQirB3N)-9;w:wpUm$n9.qw2~!mN, }Єi5PN?-'M2TkJ f"MޝǬS뇿4>0&bI q;ͬ6&SN^@{'bc1xkY0EA:Y V c!+M+=7S7*]N"0 ,|Qzݖna_*{R ;iѫ1B3vʎZo q#_c#o#C(t@7 h(J <:bŒp0 H!?z^K4]E?BfÕ)2B?mPI \,GU`?ƃJu2rby^g?R=Kɕ6 ObS*BEw&&W}=.0S@ԛz0u~CŬ^2_]xkmA}_{:]b\!GO3L2^}zSÅƤ(ղszu*(|'խm~cHO9Zϛc&&2^wURw4Ro t\A܆!Mm%`p'{7'WkVYeY#&3xFjmo`2Kq*I'CWA;T6Na$)I/F~D+I6))B8FEJV\E`5F$Ĵr@ [55EW|7߫VLǐ}AWfy2y?`vZr'Pũ-f[m'EKx[4 9;,@ia^Dgk}v2dzkʉfύS܄>YH:j-!ׁpͺ%xs'XЙH7.-ST((b2;^gR`!A6XՆ51 XZ+hteB7(3:X6';~*C4;ZS~[2+fi9mJuy6:>< MCHM {SǖF"9f<1, 5u%6FO)M; yf OMB{[BfnͯOI'@nពN?:KwC 3gQ} |e`4{L+*PMm *Q[fYz~{T3jQl i?g)(H)χZgPw4kc b*Ob5m3+p$\:od۟a,C؅Ȟpukg(,9<^'~ѩا/d0ٻd۾'nP`2PƯ.O']iNrX//t ;`uI'w/|Gf|}c1t Y4^@DYn:#N\n^>tc ~KWUUƹ|^3C<<0S/x.XLO?e[gxV$ez) PԷ7Iڑm/& 1 *|3=\V4* vhr?CrʄJ ˉ[5,U$ːT S% <[d$Tb)ҥȝHD60OO!,"Ɏcit6b t/ kdna:_TQCLţ, HV/bqӎy7Xm˜@B5D NKu{'*qatZ|gV:jZ Em&kl>5~~)UA(*YJγ4'Lx8Cr>:z7o:GgHDhͱZp;gO gRsؔzN@33Q`Q7&OK'K%bp3z+0 WqX0X#"Wr"H 9 ˴Hݚk+Bκ7:Dȡ3MµPDZy|mY`V嘾S\8K=D'UONSc%ėv'gW,#K ޽;IET34 z/˥O0nZ)fsuȵ E'Tn.YkD'oMU^_&JA*zo8 tœJȞ\ca.Zl *=!7wOK4"l{;9ZM8EjJ)bS"{G8f#H H>˨燐) {ޥޡc{-dY캦j,EFfSuN2GQC=OHJn?SSz,oę\KQuOM[Oivg@ᘽK7t>C{Zm4n 7-O]uwv#~o@->!hSt}W'p豙 &gӏԌ;tk_c+'򝏧%N'DT]j)]Y~O爵,(.G<,eV< EܽʨP/4Yj2e)F"Y!9gB~]fΣsoɛ2`(\vߋ; 2łG,oܪ%Pz*AUaMuswR%%_: N)#\gGP,2eQ9!c#[^ltԇʳ5\5y0\o9+iT\B!!Bi~kByҸ%^үT vAD`xXƸ!+w 3-oH[fQ v?cR'qw󆮡m: Ykmb(q˯X*Oְ8z;.͖ 3*`vdrqGB j>ŲHwˁA)#/ׇ}Z"S15 ه?4mYF!7}Unku3KH)?,=#Cz]1YqQnb]:37UյhHu3dCäHX*4ЙC9D@`xBB(F*O?ؑ|=p'f!:NoavB;X]ޒB{#DŽ*oն<'Tq!c!N<Fa iRXHU}H?seJL8ŲAOp 8ˡ 4EAFr~d|m_^y)SZK%)}Etts]vi1lWwww*LP׮4ؿ<1U=s|6Xo%)A]&$8]_mYJ.➣ى̨KJwzV)SY*M5E /Xz6(m͢b`ye@8*!wK|98ͯb^n޸3op%EL}R @ Ã-I 17F= \avD{ZmؼT޵mGpQHDAr(_W:8SAAOܭ' C"\!:_N'~RI5,`p^iz# _82ZK]qBW0)<%!`>\8Ž`LĢ +4~9Kˑ "0Q%Vr [ s|l7MA!~2}_܆.٭EN (' 54f8|z̼\j*|ͪ?MIVY >rGM$;%0 eH23lo|2v .cIMwpFIL%ְA YW}gRP*bų6 貰 )=dQX;h5G!̴h oGأuǠF`r'p}X1LfM[Ȗ :[VBuۈ%DҠ т#!9m]bD즲U@y&NI^oZb 2)l~>5wc9tk%n5'n鈌,Kݍu/,Ck.XEL(SXg;]z ^oL8N1k&m;H;#|]D֭v/5f\*7۫̋ت`GY jmuq 4ţGb aπ3'U65{g񅅒%|oA=x{T5k4CC]ùuWL0#xȭYuKfg YA5l9R0ސ嬣īB CL,c4է2A8v[ kbAQ[&k( &>:Dt(2r*f|rMr^©&9XĤ4ͧN>yɍb.AY#,lWyd5 ?dmC?rq-`97Qb_Nh9A,LY>~Hi>:LP(Q{N8+ xHsN:&Kt៘C*5Pϔo!7GL!҃,%HTؒ΃iY6 I'2f}RVu@2psYWkrTVл9b%71c>w MvaءT}e%-)VFo5JUN薲m8R %~|,AEE'K CL,D/mX#"xꐗ@u׫|^SOA 3&sVw99`'ءQ:nXcNMg<$k1? J1uy9{cN桽 @K.p$?l;Ga Ql&Sy^To|gwA ,js釷xg?N*C2Nj#pLEsZcrLr;.`@kЯFliipbSWDS¸m;auk\'.xRE(IsЂjc24B-8/!; _Du|<4)S{$ڳ|u рSkMLAuxW E(F^ر)0Vhlӣ6/5L7)VY'@q8c3t=O_Zز/ Ձ'adI5{|.~CiIدgb?Bj*dR"[[` '1qL>9}JSJMۀ˱g j Z(bPWtN(P` (ؿ ,R]`{ӵT+>\ )m뛄DP͑ZTctSbfEpNs-_Xj"њ?hkMo 4R86D?>29 Uşݞ)ceUQUVJb[L4~_$*@$* tHthF=؃%u^8zx;l/Up9X+ȤhfWK%]Wk1q>h!0HZV 9Łգ;*B7ALݍ:I>,TP@d4i3%<Ay5!"gHHkZ A?9 ^(iʄZ}>\ͷ[]l`-hmca2Q4.@5oe\G.lڥr pPsٌ"x@-7.ϋ-0($Ӂ4MU zN%'ދ\%tw&$_K BVQz߲Lv^cp/:ru*7DM"S"'ECX̿* ESTa.bn |Q=HܯF$dރ]50OݿH&?dӺd0֜/3ؘ#.fk2O9#8ԂRkm~;) cMJohzIGp;1-o+z+N>B e:̧ sԜT  q[rd/~{^rėca3=gxK3F̌ORzFKkHCCrWf]F/r' H/L.|$>b=.idB<3%<ܶ)d aV=0\ ` (2/ܷxK$`ӏnsdވ\aRȦ,Hqk]?VkKcWΑgT! Ɠbڦu~I %kE<~p{9Rߘ~F=y>⺏e!͡w(x$ c.c@ņLj`c|?bPFG2*cPYDߢVSP`-C7$m& X5ʄeOY%TpFD{ptqQSкZbv(avt̀7˴.Edڅ7{1_QXpVxsݜ'ߠ\W6>eg-piO_ z5ˤ )CWК^v8  -{yLBLY@ ciKJ&<ߘ$ߤi=Y4EOc>h/ivL&+ X{A&ﭤ%X6e]z  %_ ً)ַ"RȆ'b⛺,1|hrq {n?}*_麥Ysi /1yjǘUpM=őߋMj).h$>!q ħ!x  iJdT$ ⧁_bj>P1=V)8oɞvMmy3Ģ+vD$y]ØL$(6J9`AdvSI!aث0& =<=ǢTtr=C>QOuPl1}C)ŁkQ|vDȬ̏TT%ͨ'@ ^QX ѬUD5  Ik[4fǷݮ6*ENĶtk%{[ tCk%Ӹn%L? .|cs>߽PYv)Ψ;=v w5/g XV1j*4&Ol#6GhBH?]KIZ=Qr[Q[\6KKW].u9@/!"^2wmIuO(;~>lކ*['|rE9*R@gO_*q3beߒc0C o4pW!:E꟰+zzY|k8U YECюixX[&YȩdG8IkЭBxֲ&:R99̕ڹ(3eZS1+G io 3{XصI+h10ڃJh$߂)RWJ2_ \dA`XCWO2!/TvXa-?rHy-]FeM;_M)΀\NErvD,Ԗ.wWt2ad©HW@C32ұNai74CΏeQ F4?J J~s)k؞u[\u4)g~ _ M UEuoDjDcF i=O;`CY%ŧ׹ŶUёRa85H1vLƞw ,IsIsٸ #+iZߙWKƒPU߶@3ɟ %b?EIj½ $7t~5!XDHakhlܪ컇 vf126,׀/&_sA"_YٛӒq]z.E]Yu[czdF5t? 6e( /"'/8ǰred kFo1X9BW?p ]Ȳ%_DJSx3Yخ.;$wP\b}Uhbf1oO-t6"Sn!)F%5[2V"B\{D$*Y=vΚ;YE>KEO+/($m"٫93|3lG Ql5HNKDFĂ"/{y5sa Q^qyKdJ',E\ $ZE=pTL?gxַѠԤs6Y㱰;8Jt?*Dϸ@ iTx)FqnB澮a&AҴP%\^,Ƅ@bgY;>M\.8 ,,.IKVѫ;h{V Y냾N{=`(4 goSU1!cԁ#FYF(}zjVBmoTJ83*|{g9ɼ1? ZElqQg_Y: tqXO2N)G~/*v,S;ܙiLw-Ìb%>A('Ej چv]˺o"ˆ볰6K4\u~~qxwnpZC7Re׸ +h#΃>.̖V& kb+_ΠZ7O%F˻F4yo#ti`+w.ނC8ɠf[R(H @\X`wp>+ GI#3r9l#~ )bhgt Kkof &^ .ֲE@Ǭꝅ?Q1?}{y.i݌IRfEsjNlrWȳn-XSe\GJ7.p{vߨ+"ߊKIJ.aPǙ>OYB()QCF??}ƣ1~Qc@~u1ЍqXllE<;Nx0T5^c0cT2ddBIo ~w ݬ6R[NEC,:$γP .0{O]y3;sIJj=x2lr_ Pm*N \90N9,O\)ԛi{gCWe]-@RmarڛOKNF3Fhx%;_[U>1}l-yRPNbkl&KG*ľ𚹶'*b /f e-zuNowg-˦7$AicF#ެRf*ncpG&JMcw܁r7|gtp:|Gqs^~@2:2Y1ٹxEŮBZ ;&>:n>H=T43+I25|W+;Nb9.\ꊄa(y8": Kī3cā_("\X= oMFxŁ (|vVVvJ,rе# Ħ"Io2)gn P#ec&~kCw'1= - ]O?E$yHЏ}F/?B4 !szuAڌ\}BÍmL Be'^{|}O):xXT QD "myN4zuDo~հAN>.egrK+NdẠn0N"j6 5tW A< оfd?L.W H+Nj2 ʋt >KasƬZ$>eQ|2-J*P%bSx-%ӊ >vηn&rBp\zmB@':P=b߇wMhȌk- Yҋ|:9]HRk>&'v4P)>2 Wn 7wӷ^VAINGpvI䓩W4AOKm\?~#ZfO-> 2dGy%(SC1h4Z.ޑL>lcLF65+/ϼ/ ]o:s +jO?(gt6jc)'%ZfNC aGH=ky,^ۏO32#z chFR`D9IlqfG9R"IO&mͿ8j_URZѤH7߭k8!4澦j0^ث?IDfQ *p2$͈Id,sh]s3[vWDL rcD}gSx oSm`. %M! a)uf֤S _v ZYĨZ~xAMu3i{Oh{,0?2'x8Ƶ~5{&!4{g1RD9j{![}dh<k_i=d1Z+|i6 oR\T*_bb \J8)LNs-II{HH{261-N^^ ?oY۵; o>! QΜ#Cw٧t$OC+*Lߩ Xm9 P1;Z{ IWE e1"'-nҠp b (B@4y5r@A#R[Ǔqn . (]}Iŵw4] J 0(-,@eo?t{^*a6 h=˦S2J0'il@%4ۥ03Oo$J \닮%Z)sgIS sv!JӤhoKׅKy < -ȴJI9ָ:#A9Pۏ!Qzӭ,2Fx̤҃$LWpo(ļ!'Th>0.o+֔'mZu|Ū<!!dpHlԀ1#rԌasC ߙہ H5(ٮ>svQToʥp{tiІ\inU1gݐ^An"uO2j8B.'o&d#R0{eL2Bv^ ח:9 ($_si@G}S;z!۷E6Y?aPHF_wmk'c4Hw`f=5.8AmPVWTap+:  l.]g,058x wJW0 ?h-]p(NH^<nbBPBZIUfxW%ں;$N`OЃ7vHuClRJ. }IiA4#8/\Weh/(h0Jol:K-a&xPYr" KS*RxnN܂-yquzhG3eJ_VLii?l K" n22BO| bB "$#>Y]Hzg|X^9+[˿x;Rxn.?^яhF@Aiio# e%T1@ENUeCYz!Qz/'W|Myy8$ fH<3Y6}HqW׋]9h}GRS?/7y6Y~R!iKs䶰DgBEnR]rROُ U9H4eg<ŁQwޣa$"XiaS/PvEx`WFuĤXUJGO᜘Ꮯ>FhIZZ|o6۴w$Lµ)  Szu@s'-Z, 5vaٻ|p8"$0_wZ_>puocKD́Oa ͗% LW [=ԃJI7a|iK\Wѝ4ah7)N!8nIͭD}@bI;E<îΐ"e6ma2t_ɂ&Ov(wnfMk.t&݋*"ui1 ߳ 1 81 rEh8%g[UDd ;i?FrI)Ymy;QFQU:q\Wѐ5A-86V$:l`l̐mcK['t@C=@Կ=cN0yuu>Ymf]*јp! -{BY7גϔh (uw>A]db f׈-. eE&e=oNCQ9g]rj*Bx 0=r0*`fAās5&F TrqjݱRk>}7;8^tv]* OCWbӔM2\=VDJRQ `?NbP?u6rsjqnB$d\j[qv M%}D6tnh/>B6r o)ͳe9?χ.4yB`kTo%690lj>ߋ= { |Sb\/lw/c.j_%DT6oq)Pjs!M0^ >{^-l]hWnGpRzp}fXA&\O,NFSûQ=єPLVTӹaܵ}o0JdtwrtSqOkߟ"l8ZL#lPp:ti7IDӔ2l!.^$/4&,Yo8aʎgp1,JKauBX=|8Vϑ!x6EqtO^-KlTF]}LjRLG^BI0xש֒Picu"-;Zqc',oY]8 zʾ(+yxq#fw1(% Řf  )cs g텾d`«~Ss`%I<>ɗ:D'6f¨A8*3m%VH]Y,ysw@vs((l-Q򡯻Q|Ccd㲯B_䅡N- Nl@,ۙ1 n}cTngصv lNxhldhSRK?F |/6_2<fb%.i2Ծ)!eim~"YOWxA4|Ia2/F9< G"lwqUܭ ⾓}J֜ 'hȒ*Œi;\HYŴ KxҤI.*ȟ+ٽ3]B4J-ntXXP"3̥Oh͒JO0^rc"deP " X'a)]y~qswb0i~uR,ŸiLa3WZ(^gCj2vv߹~"ˡ_ =&Aψ! H5D*gT>' %H:$+uC J ;}obiO Ve;)24J|d;V- /P'EXHQyL VSw㼇 _G SSM9{2r|oɏq y`PPLWV$YZCM}ΓdM_ݫMf,.)N"ytk`s9x:lԩxpGLχ2>Zdn=i/=Xjיf9l:!,@(op;a#>LENh+1_菅Mq`,Bw"u % >M40u/wj4b$ZO@, ƅA#H0:"! 7UI_vk1><]ȏЗ"E{`NxN'LN1czpPS놔(.]SW5j3*a>0W5H{ &T[cB $ #+fs 1kj oh b=ÉGHy- fhp^)U<lٜ)nΉܨJ(^ lk6C&o7>Ȟ6U/0#ֵ S!R[)/F },Y2"m1=s!ڑP}.[ʭ;R`[AEaĻl:.Bvxu[ p̵y _:?_APC(l>{{ȢЋD(߰Kx=Ȼ˹~_xJ_& {ٜ)6CgÔc$Z'|P\9 ][b]>}:gewXP>)JBsx0C~fitЮdS#Q[H_x{ IMCI# A>ZY̷ڎvQ씦x]tBA|Oʪ52³45a{ˆ %1}pdqZ% v`w,GzvE J #i1 B~IyL`zV;Ԃ0=6 0ķfZs9* ~9vKFZK1=Ҙ%(LYzKd"2(#ҊGN=g껹_ 0w@;esm0$xޯ=}MrS/6IR,6]w VX*K궻Kvm*¬˂uw}#Q~q_1MU'P7Lj!@vܢ]+̻eGM 3/l &.3 N5/{fT<؇3(JwVpAEdfQvDtRn*+KMZہIr- 1˷'plaMB0B3~=aە̽ӥH}=A{wF7uaW|DQv="{xJ `U:؈/(]jh]kc2<eE/9eu8`^(*DS+LO7>Cѫ<1s/ }2QMP W2 znId W!0}sf)y~7=2u&ټ"LiP2.[@-Z_''-C>]9j@P{s0 e-%h`@ Ewuʨuv;rYFTTl p :]8 z1Avƌ@m+B;i;-{A%R7t7FY Q^%26]:-I, ID@atW9{ ¨ TK _N\M ?,w8Uxg 3_֦<$߄^[J`eE`up"Ӵk'_M U`?&3`)iC ]GL2c_\/kv1ec^.?u bHV#HRC9-/k㨒q3WU_.kgB'# 5זM$B2Zn3?_ }55WFzԸ?f _qs[ȴ :ܴk|dYPmY}.alg?*ondOt֯wR~`UkydB Y 6 {kFII oh/ioXl2C51N/CYqDmZD^!&5ۺD~Ӂ!_"akxͤ!_y/ӈt#`3/5kn{3lO~ 3w5*pҭƑEsgISV6# T%{bO驃Ow0޺S޹KynB@f8xԊk3@AL[|,j#I[룪2pGs}/9$P?[bU(ZMb2 3hIeU|kL;/ B╒FhkԗLsJ7].y4Q}S`ES'춂i3655l~K|ǢY{K@R_Ơ~ϝ#'ޛq:v׬_-DjepTPGjӲk t=!2O0S84'HX~qj2sgd㲟%sWxȯ+>4tsSQg3\Ԯ ' b Jx"k+HF]3O=V?Sm}OSGlR)ǷiڥLBi@{k/A0sAA 8gC)wSow ũxGcQ$`駂@ĩ]z0tMBkm)d.Ij^BCG&7pb+Y>0P i Y+87/0%eLLH^Ke:3 6PE! `΢=b{"`q|OoN?tQ  j[؈~T4f?>)N]$ZLEC)pYk?'Pg{Ȗ,`@'DEjOw>j9i{w|yըy֥ 9:(l` ̹3zO.0&:yV';G4ݽiH=?4C#T0& 9b lq`to]D O!I#o?fkrQATYhp5!4=:ow *W[QyV)Llsi^P_cۨ&P񅓸edi-x!ͽp'nvzすG_%$]ȗyy9^9i9j%8;( &ۮos)\aǠLk"E9..R[)ԢPfDTo(&BU ga3oClH9kBz[ -=D i\< &$w )KVM;Z}6TͱB2 |F&Ph VUcSJ"@ -HD}9Q^3Qٗy X Wa- !kY7*;TcJ^m25ǁ79E O̰0߻@*3d3?Ht[b֯Y8oc+pd= bIrG ti+ߪ\ћ }&ԋߥu9q '^d Y,R*Q .@lY`2tm τ t}s%.vyDPaJ+7n>J "[o^Y&G[Z[,͛!(Xmٰu-*,B}S>qƜ2Aۺ$. UUM6-(8p} 䒙E4>6ss&tl:aȄ<2!_mw6jxr%_N9*yN)͝aZ!Ct@ync=Hv;+MLzYHҎe >̟ GKe`ۍ?h0l1?ٝEkR"֔lg^tGA"U2o5'm-!yb=nLk<*@',Q(f$֜`,|kŵdu]eF.@Q#h_nY,;rz[,Y{2cqKI_5Z{D OqQU{{b{\!]/ș6? E`@,,K2iRʐeԢP`W@df\t ]x}˷⽳~&pN!nB)0e9Uޛ^fSK|%NRr"(-?!x\̱Lo@4_ Ш4wxʭ6TDj™W%JFױO f,v;iלX(I?O NR4wZ@JOhq(Akdu<`/h'WE1@^4Q;\DWRO_OBa(Rǹ}bi-+ir|3^ vC&"n* +O5;Il9G|.dw;)0S}\0V ć'XZt2l&q3@,K4-ΩIծoRaץ¨#&}!:G(ۻۍj/nMfLբͽ*Ky :Llؠ|'< lHOUÅRBn w+*Uڰ wcaz%1P*^>𗟡BHNA8"rYACܰo64_@wK_C=#Y-tcYXmJN?qVxؠ_7ʅ6%SFoY[W9c.&daV8q2RtR̦қCB6cKy'5.[6xwBV#_=QmElA ^fMnbOqse7[6W\G#ߎ \Y~ƺsߴ:2N_f2'u"LZkx.*?2 &&g60&ٽ#di ߰wV}ǟ[:ȟ3B2||e_Z~CP@f'{cե('O^Vq(*'j>|z>}(g_NڊKj+2lޠT< _kfC`7 nլ155b.`VU{c&X(l T)8N"=DG5kcR36s5K-'?ٚWAD}ցbçH"" *"vU7s'd`S쫛z5&Yiv&z?ic]US٦3J<u͏3LH8 Ѻ4]ξ$/IklL0Jf*)5a;_JY DZ,sܚk"y.:V'qZb۱UA\ zhɑ<=k?P؎ XA"s* QV"a28M ͔47BPىBBmE'q0>CcW5E,Rcˋ@>ۅ1G$\73,D9Uwe*9,Rg0 _hR?bPݺI/ N=1!ifc eT\iOL̰ ^FYmE2OAz=Thb)8@ Co>3@AыG|Tn0= <$x`㦂0wOmuk bGLEFsud#1J "S-&WTݞ>f+PKB0ރwS}8rU0>>Z K9FS'q ׹ %R:7ØࣗV~iiPQi!3KHlP/dy m\5AwA[FQTɔ:ۅR2\bhD >Q~T!F"EBྣz26^֑okJs  UM=DzG6׵zS1dA6s-I >֡IK-*] s?]'rm&]Z^_LFjr-?[´Xt627ưc69/h'o }}WX֜Gu,//鶚x%%IK]K5%2GGQ@"'W Kh\9|ZŒ'bvyL"EgЮL@aj6\"SAͦmr!A7acq?wn s:=R_τyD[A> .s_q7)^@A+we[}= Ie4 _ lg48;ÀяS1;$v8kZzR9%ux c4ł'=wJ$n^cy5~<ЕTl3^o~𨍙Dņ KX<Տu=XTq̳7DB6l-C;lBٍՑFaie&VT'C[ܾosnt-zM"֍@o^zX啶궁jKjj~pi*݃"b{\Ë-#A@,.C)\AWаk)ӫ:z% )$#Zn yQmV="LcY;AZ: ztu?CfNܓX2w`1-=do2gj' Mj*CQ 9s1jPnS&\5~530`(8†ӸtxJPqp9*EF!k Թ4ȗ]W^4T2Izx\p!aQnrriD4>IT.KOWLeC5&7iEd͇讦( g+N0eb: Zn hCӥ~<LOx?rLXZ$-!XԨfQAxdzBRM|Frx ߦ6rtcܶSG(ɲqDD/{1cShF/FUO2r~Ȭ2;IaNzWO.\<׵Se'`VT\nhq@Ӗ}z* DO ^Oe_#pMCNS'm($: QE㎇V=;^7ޗYDׄG7Anl(Jٯ?rN^nJfV&–0Dv ^1O6C¥| T^./`0Ƴ"6=*sz2=eĚ΁%27?*-$X$Ye^f fN"P K,Зv7Uuj}7oa2)7$THQPA!9.J=̚ NC>8_H2V|f6eU@TD>D h#}%hzeb{-Jʗ9ɲY;jR_pR:C'qO*itaQwKFjeaOΚVܿ l%vhJS>2htp>~FN癊jϳ(e;{;DZ %{rj=AI.iP~fW !8"y+QfX̃*˗JCϢw˟dc8wAvnv|jO;ƚπyaƈjU6q3O_p%Vr\'"߶-p\o=]r@o1YfiHqIg t$@ cegz-.dѼ(Z{%~D%K9BOam(#Jw& HW'RNwT̺ѿvӆJZK+][PB/l&+\spǠØ.c!h$t{w)\(\Չ:fg4ί0H\ cahI"rPE쳶rm=oO 8Y1>;ol.cjH+z4@]f\(YHhGj|mhs{Gɉݗ{?tB$ OP֌wXՋNkMc1qoQdjU5Cal;Aaџ{A:^OGR03uv^gMcSk zhsA/X\jiy$lx,T 'GdfO cL7WRqyYC̟Mb 8)ePZˈ5Swr pb6JZSبaⵌՂM+`GiviOHuCw7t!QXFd^\j!x."[XAcuN T=PjRi.K4]lΑGz|;}'[z}y{Nkz??_8 neX(vU^*'uBHR`JG0AE[j*W\ixtʤ\/qI葯MDz Wk L;]C6Ԑ MԴ列f%9ih'g/ KJMQAw7ZM/l؍+1?2,ɍ7.s6Mo9¤ 13*8j*>4ֶ _ٽк P-iNkIH?1/+@"em5Q;QL% By7&FcG$&PfKd0D G>]Xk3vnqZ\"+ w{<ӕfzgt#\6ףfIjr%%bq7SjERCPz`5XQԐQȴ1`Z/-iQiw] \$];x ϻ?U `Dr$*%F8wJ;/)_2kא|6*cp;oz:YTcj4*}@`^RMxRedH%W#Y>EUڪL D(?\DRKD΄P] WR~ ځ37^o"9^t2r%a VvO 2\2骞2?$[I%&^]Nmr)Hg ͹6~&6tğ=*Dr)FytOq˂.4A,W4KbBv)tԇ/|䗰K'3 9Q7[4@9 z qιHk?%DeRe|x3w6в1^񑅾@;㔳/k\x~di7ЫI pMC5a~u `wZT0M핒{y4t`9]WrTƸ'r/rk3ˠ8k%(Y\?] >o^rnWrXMzG`RBc0rGa޺+n-!)B0ى_R.z*rځ?a+mǸ,lT[m$s9 dBz㕺GH `աc8|H)EjE;QrOʌ- #i~7.]ZSs18KEW vmE\e#XahT%hcnChmVgz|/c\ң 8ɑ 00S)_ƧH${\a硪uPmdk׭X`}v|@%tS=bpS65qsc=VpҪ4#7^ "Woe[0DL$i!eև2#儵#i>^ 4`cjKm|StkG-Џċtjdu¥WS dP uPoR "%t]um.w83LCWf/2L?ҁ+ /+baV;Z?'Rm.ܔ[Hv nQ)ߛtڤ)n#"ءCx%aʳv)IdϴK)sսKTڷq7M]w{# }88ko0W tcYC5?趢?X.k7)gjfhOn*%ɤHDz/)8B&t4[Vѻ xzq<# ClQ %hWa\ұ߮UYO- wqu>*6?eܤ6x?bjxBGШQ:Ұq]!h3L`SXI5d!c~B@ށjsN#oKDa9U_D*+:S\?ȲH~yl.{#GPaJt|]ގ}- 8lĚS.^DMvk6-ln.eGƈr;^2pG>M>P:~;rlE3~ǽq 5U!(`qI{fޓp>QN1رll\Nif\6[#$闫>*ynLIv+rl\D`EW >k]ǩ |\^YOK2 >T frXS- $rD Zam%{b&xUn$+q@x]6nyoX9";XU|\eg/fq^ Τ}qxs l]h>R 'VN񘒑n;x#۳s%H(z"8dU;|zd 1yd *ApE!khy<Ϫ+{g1zp?a2[9YᴎGKM =4xqʱY,&ErQ6.WObF,8e9Lyn$,rk DS҄{QhÈ{L'֑cZl/T- Y\UJ}=.*Siv\DVrʯTC9?/eӵU+LWWwA"6-Pg<5gիbF֋WHr&_[JQ/6NFXSG6Ug4V23b|7!ŠQ?{* 0 StIZ!zsS"%kU~?̰5,d5 zhyC؍r[yu~Rw:3ݶ ˾Vd FN|p4 @׏97aIL@(5'Z`[ᧁ0 ?<_L4) T1Z^bcrF ̰ }cJ%Kx{9T9SFBC@F^fEf{sG>vIz9"eEN pɝeQ;$mJnlfM RveۆF(V4$K1k}0s%`@E`( /K:tT%Rln@Zyk~q[-pasvRNE>GykdI&ꍠj% 9/kq8 ./v́)#Ac6>S!B{ߘQf*C b 订-a^֏k' >LWkhST'o786,cζ]/HBѲ6I]8>70Re?Z])Xʐ-{=`@OL5ZB# \@V;{WTnx$'֘ ǂ 3O||`f]Q}&HFÓ@ ҟO<گau3>g{?k; P]0 0ZUy(dALbTCv4k|^O%lBل.lN[n->摫H25| <8b擕2 8#Usr9j[llvgI)]J(w0yKZ݇U2KGwMM^*NmGހ?ILf! Atun4Hޫ)C!a{ڂIH8ș`8y`i  7 =L ;NcKbg<7 >{/] xUM2x{Q4k|.1tAk 2KFyKR/ ucreŪq]BU Ent\f dWm8>ewB}BuҲfRU EάѼUC<2AVxBoCs#g>BR=Wi0r;lkz)pyVdYxkDžluMU8O vp@>DaZGN[aQyU;m/T5\h\vH-2@Un}_Tgr[mq dvzDlti =T!1Rz|RW +VNu~`; ?Jd@KPH+x",RE(WU${Fnv'$r2HH0ο2yX|c0[`;U5juPr˭䋛腈F G8[)espۙAi'cf!cjChX C^S P*v>PmSć--\xNڡ$}ǀCqPD cd/%Q;$7LB5;@4o{D)A\saA $ph|=LG^`-,T Iv"<7("%4iRIe L()s/ul)vPz"B7mWnFü %9OYͼp-ڕcwPOo0^AhMˆt-Զb 6 g*06{ԯ}A (?.MiGԧwHaZoص 90޽J柫[JѨp9/zqˑjS` ʅpf!H$,LrAu/%ܧX.SΌwbJm Mh`?&`q2M_'#Ggo`:nkJt{d(¬kY_fҩ%y~ Ju|)%Cz@Dyf\Dq5fy%b͊*Ft檥G ' 5_H'F-fs3#s jf0i9dMg#z#hHu<l2LWϕV\m m*kj'_[׃8y',IvFR725|8ۭ{X6XHiaJ/~௽YUzh3qcThxfAcPWڟ\cJ;?uC< #9[=C5p>^R8 ]oH8ؑ?hpg+mC]Dl6@A"(z69/AUR/q3WdNJ zT؎sGX,kR,d߯FeAyt˔BZ^ ?ي²omw9ܯY~|7""3;xz/gh U 8_k.flF)5.H^D/*sbgZ$+03PB"WJ~- *}ێDp'\_+oӄF^xX;A/I H`4 f;Ă9vL@tTagUaG|@jHlDFI7η:RdO*P"ƒ2(01 J帟~Q/q5ͻs)!fS3>M C]*Bk!{lSh&?5ú28}uQ*O<-2xi7o_JuE_bݙ>^ m9˶ٕs nr8 ?]MF`$2fْz)NaXz%D]מZ|3p8GVA(']xA,&y8CJlm3 d:kރ̠jGVd)WGEÿ@!)D- "Z[ۨb6P}Wן dd!|4jLX(E] ^W.U 3W}܎3$'|3Ffӎ![>Ho/B XY )AI^A^e}o iOzfSef;tvvmmgϒФ$W$7 MEaIn#vh>Sē?|f_QBueNu?2>ن*qOĞ8cA٘)i,bH08>5; /GrFqNu6:R¤m;K^ \CmbeHޏ~gW8*_SQҜD{(̛S/015o] f0eb.*YMVRݏ%:QO|j*κu&@Y,EUތ ,$m%^brHW7){8d _ WB!>r.̰{bNmMH+:l yOV0Yxٌ7Uj1Te7D4)/gmI^1"ڗ؎⵨U`)JuQ>)YMe>1 @uדtPsnL mȔ1/ޫ !K悑xƒ-jPP&ReS;h^d|Fhq\"ۥXx/^ /e+4K .bRre|u_QRRDg| 9ԡCՕ Zʥp!lZKKq=Do'l$wrO)AF 7 sL禙b ܛ%^)k4Jon}aNYbR<6.H,0izo:*Ҽk.A7O3eouUm~  NVwh"$!Ȇe7Lߟ[.z-D)(Bi4AтVcI&cϰdv٣5gQBh@t4+T㐢0{봹# ьTɩ & 0VOd)JOu#.HӖEy!xHUWHH&ڦ9ZAv;4k;ETVhS‡ޔΠ(߲dhM*._"*u 6n;sI\@?& EɃʤ06_}BH}WNcmd=<W)ItX,V5=P5TLbcw|kHh,Q3AKDB2_+#bQpC''B ;<MxuFE[3Mɤ#ٳAXHx)> ABhNNIxp~ yj D@cWE-El; iS7EchfM-P:-IvDK7* LZB 晲A@N,&ݏaIwS(}2$IWkWפVDJh/JbKN3nqvzS&-~ybu03.᫲ƥYmpn 4(V {悌|eEOv"☵sgxZ8@m2NT.p&&ibMF) uCjvp;tVW#hUH)Vߙb9)L38/.5X%028vަk~Y " >ʿW Sb̴ܑOs _pVlOB.@h,tk QX57 I; +u%W@# zx#GIvOeSN1(^q}B m9>\U/㊝gdy/Rbˢq%+]*p{Pi #hcƏ[ ]8cDhcH3nqT۩!4[1P}[_{`xidx)Vz#/_}٤U1j)dzH`Qal"ysj^lcؔ>ywCW z(0ߎUo9z,RsȅU 5 ʹHn|ͤ:Q A-&FWLD<ː8`h{BüE.5ru@pHGyŽ0$cpOZtL Ysn.FC;m4MQsM6_woЏs4B`!f5}z#c5q=:ElXH-̊> /*|}"5/*5X|NK{w g`HS`nPűߏqWRp\Ap}Cߜ FI,C6cւ o=+x7ǀ'IZl"+ ;)(Edz ݦ `8gzie6dIbo+ލUT+h";g *G˰9K/`;mTc"\ ~W?qx^8 )[FqI&-!_"+@\@5r}XM-1g{[ VXp50K2Xn}m(葇Q|5f@ 3x'J3<-\Xjyea0c" ,M%AsՃfoA$)Br7c |(c%FHgFZ<;b?%:6( 9W5HM q)-{> WS 92%x(K9}-֚dy zkIMpȭu05%Aőr?hozH7r_kR͚%(hM&eɍq_ԓ$~4Up\ 0I3xJ4 3 eZ`rS7tZtif̏W}~PgB*jS6| 1j؋򀤯 %aF7 fvu$Lu`ӯ3rCe=koȕBuVE 5!AʂF䗀)iy{+.VavTv-RH;٩ZMah"-\4D)bUMv f"mOEC?x-*hR!fئ0Q)OwSY^@=Q:DdkCO 6g*'*j_`?~ʟՍ_|RsY+]f ݝ٬ӕbRɅjuC8?m";JcQ^YEXqttN"lJ{p>@ fCgiId3U*kW y1_(rFnHn? Ad݇\kӁҢCDYk>D*3̟%lm+"8!brVdI|<݉Xzyߗ`3.,{2A+g ը˛L[Xx9G@*#S&'v5cMeV_eV,ݍT =fR. F75'_Pb( _#R *\NnUfIͺ?𤚿 3>U- J{zJYc6\hၖXS?Qi~6Ҙ^c; HylE뷬1_zR[/i 1?!M .e njr$qbݼ{BFGVf%FF(X<,l9'x^D`Մdɶ矾THOc#77hO&_#:DtTNry+USV .ۄRۢd- Rgd$ybdӕ'XӤ@ ~|,%+ Vuѹih4u Ar`)QJ]bk2ӓg.)ʴxPIqf.fsY.1#]LfriV .<8տ[cTPpb, -$,?0"!Q>C 䝍ݽp21P}6H" 4~XlI#|(0dPPRxy|b{y;<,v ]N `4Iz.wU*oJK福ð <:͉!3Zhe};>ZDDF&.洩֝r<)fӲjbN-݄VCw-Nl8幼Ban:LePT<6Gqtu-‚})fF1A? ӷMLkḎv$Ѷ"ʵdk6b;CK{Av哿GG^|Y&ky._`yqh: W#Afyax-bV?Q򂞈z@s)S]e,`{֞gt 2A5o~-8ԩ!;:.(~h ô~Acz5I|7t*o Cj}'9T C uP\uq|VU/FP=+>ʮ'IŮψƈ<ϩeGO5[$UԈ_x0##k:EnZQ" cY* ֆEB3gܼ%t g !p4٤i*Ee]QzNq:lפ1%O Q\P smx)/Y<7WXRfbz@7"AW.,%:'8F)7{1Hb/l#+ҫ}-Gg]?z\lZWw%e &pCA4lۅo*KuB\ P>-.G[rT){sbsa"Z&R+]`El([5~UJP+Hb Y }!(JJiC߽?*JK q]0 s]y!@\߆-GEdQ XG&M h&H.1V1puf%Ψ'i=\c@5<@Lu#܅6,Ceu4_Օ Nql;RP;E%0IjeUOuPA/tH;]'GzLfvbSE|m ܌l6Qͬgyw[`y.\#lb't֌2g,vbh 7+mN;6վ'.4v)C?_(~䡻e?;ܦi]%S$k?*E9 GWM@؀ݐX Q$n X9m&V֛oRhU =;KINAN+Uz2UI 360^fgN09I?DTuȶjT-2pf~ &LCx?YcRxn=DdqZ i͸e$0];3F$Py/1_3K7I4VdȠq;i}ԔQL'7> cFc GUF5P.۔m^^\92c(x54̎<4k3P @3ҕlɯ`Eexz ovOri LRd!x/+'X fpFh%Mz9c8fk[<%FBZX.5 n_A%ƀ`T_?k2oWI s|@MLx1)m8Eg'2DŞ ^.O;ZgA Vk;X'cl+TŸwSS_0i٥%:.zNVX9$lE11AmcVEG%O ]56ӴX̐PO6!x=SZ`tXWq˘޾33J8%Q1W[Oj;br;Ea\p)Ga ’d% Y'HD~&qag Z,ٍ̿Fh`Kh{sHf$# U(u{~m=FƘth9.K@5QONY뿸ܑ$X}/X4&;J[ VmEp×#w]y5UEIpb$Qk?\ْ̄Rc%Pg4S:iJM9&X( eA$ݿr 3>̠UإtBVĴ['BkdUY*|dP-uW Znb;Xi)3dV,I9*3A͖+M35 AFy$ ӈCI }{c f-y#o|V#s)hiɨMrfw[QC X+_"#=~DG7?/I@To-=]w84'Iial/zfkD ^GE[>;.hևne+'sK3;|?CݢMǜ2(ū#_9ޙK \GAd"x(9htZ12_yȍ*tS~'[D0[Co!QdJȟ/}[2T]o ^3#-Gz<AScӲ_o]@(z_nw½&p((=ęRչg Fi?CxEaTtf,%JIrj}]|:}vh<{3r:Mf4;D6ϩ cj737}!50}a$j !)Y:c5p12V &pXgce">ui/BǼᬗCGK}[slkPR% ZA67}}q@ os sl!SZ4% (GQH w':+pA0VA33M sfKBQ0B a ش'2uT~Hě5#4 SX|g;.TqQ_Ac#u([+p(ڳ_7,@&3`E>Y<:IӛZ2@.UpH + ꧯw ZW;^cagFcP~%H T?Bƣ6M)S͖@"CsiD`N@jUƛ^ *k9FSHW9Հ8r)eMݫ9)ށ^}p|puXo!/xCZ@2TxQmW|AZ4%6SW*u1'iy55MKʨ&)[w>e} s^dJBEӝ+L}W|ʭ.^Yt_B>s_R[bKI6so*17K$C"R1w_0g ]F7fqR+gut{0U|>H{Y  (ƺW,KҺiCsLԥ*Z =f_KI>FNgMm^A=v0k:cď`{g]z8{JjǮ.q#dbg>^ :}@D- n?.C:ሬzb\49Iv;.*OS4*۲w y8jSK UH>i\n–Za.ެƿ1#;:@`~$SDZ`D#,1y1R˻p:%j .RZTzdTg ح =YmRBa|1**NP\)EQkC0eƇDJ]p  īK rǾMћxtlty`1zϨlCcȸ4']J+@><FVsא2E1vVqj2/^JC/1~:1s_~Vpzy]0 h$d( Vla  s@rڱPӉljU3mL: ׷̞ŻXB@!yTt(S'(uSy*|Enq#"2O KK2_'5.c9FŠ&q{xʤS#Zvׅx(j pT=/(le'aލfٺirs0 c6 Zݦ}44>M L`$FN?2)y>eb':X<@ZY9ؽ!ߚ<_Bbl ?<> [EG 9X2:ӡ2r&$0HמR\g<Rg"kqC0ӊE2?0ZsG0-`$,Mn>vwevBd[-ME>esΣ~6+1U;] >[!an tQrm`NW1tGerF(ɿ~fees&b\>T(2sC97c þ#D!D>0F]{mvC({?SJD-0+Y/45,h"øΥk7fkp@fͨ?5WQ,nؔ@}M gʄMQCǙfWj W(bҠekj9'ޜS[4r![..=ǦGMp*CbK; Z?~T;zHR)FȈY=Y^s4%-4Q؟Rz?:'%\I0FCuv7jC09ȋ=> &n1Iw߇Hu#2B+~ JMFkJ ۇRc]_5px攸(] SNI8+"#zǡFN;:T:҇9 q.WwG_El\|Au,&^I~[3ǚ,Qrs ?&\+\a7jZw` _]O,=@92ã kVy774G6HTĮU> 8IAF$;?Γmy*Q)P]ETEێo' z$Ad\/U>Qt琊x8=%ߒPZŵO2EnPFb;3;#6f*RBOпN+B y82TtzgoYi7497 X1M :X|+u, rA}zj"D9f_7ww*l M.h^fʀOWAm(F "hak ^5*e<@ay^)(Zcs/N2N2y\lwGVdXZ }n'lӿeX%MfsSԨ(M\v=]WeD4jkxaD;_&l'ۏ^E/Qo ; 4sp~fݷdr@|XY DLY<eATM!jZdO.!rqnNbD0T䋲dgu5YϜԽusV߂Ko2,b%Hᴜ##Ǯ56:`7m<[-7#8 P"E)M ;=ՓOa 8lܫ7[.<㾜wK!qgևvhn+wrHExI_2&G"?A`3q}޼dpsԥ``òqkRL*C*iSH/'] ~rK n,.-d5G 7)d22I9Dp~_CXW W,6:pÑ[)>?,ge#A1lB% j/9uˏ^fl4< 莍ÿI}֓'^y+f]ɇ^!=wbS 6NF,&;,1ZȋdJZ5َ3סu/PxКuZ*m 糖:;T*i_6JPImhlq~М7j6Ԑ*tsR6 kHQ;ǀ@l>Fr5SRcIҸLl TEɺtOrA>cQ>f͚Uge)'tK}nKu"ឳBC,79Sߐmz$C\<;NȒ^TRl[&$QI!+4[0^ N~@icWob p\ްHt*6ZQ s$urrPpDf H/j/ 與q KztbB] =1.Jr $a3ș-b-]~-VDכuk&/DLYrT}32L` vtm__h_[%|rgn),y_AܿvѤβ}3yoՐ e)Ì%<8qhN;n Hۗk8  ivCჟI>n Y‚ hۤ2d+v \66\U6 &hEסלMu!¤@z5CE| VTaHE5A@O9lnsciM|CBIs=6gC1nUc; vR¡,^X6 |X:,c%QUoޣ0+uaQV9:E>G ǽdzB?$!M d7Xcu@vb#+*9v]h7in>կKyJ̭L8cO<&j).q }9pɳ Rd`<1dCרu WΓa)Yfd[!)b޿I7Lݒm=%l3]}V^S~fj,b2X#-*ZYhSbu0KuǤ[6\09]W1L?}x &}e6f9sE߸ 2kA]W=uGh;'ЍM)]C&4I@O$cmJIa܅EXFܓ@|ͶDП,V: )+cmȔ@"2 }qf| Q[)f!yԝX|| UއHuubGOo_-¯]S[ _'\Ѣ B] (O?[> u(L|Աj~5+?z9i.=CRzɊhb t8 \$,;zga$DUNSf%?.mBvxd7!0v[I=4ap t֪D'%[o] C a Qs[+_YǟUwWY5hbfnז?B+7mZȒ7Qcgb, ôЈc!~{8i2r0 q)WG݃CnRs_?+wMjVxkGՃ6,[;\&I޶F<ޤhN]d")`O.,*>JMz@0¿J".8qU{Ƥfx&,\<0"rG `زֻ2P)+w^[|x*n ;3jT/UաxsE]kY%*a/Ӣ\A1y<:bʹ)D2yZh61+^\n$Ԯ86,]Dܳ0.0=T*2#kxcS* j~y/Vz&Rڀ9VrzHaN<:d0S)_ _ XyRTDY͓i}^ $kt'~ETx1~X=ՔjdU-VؤJpnq;ƈ,W0%!=mTB' FdVZҵ<4EUo pz5/AM->]ӐD2\aizU5f|CAXO8{DX8mp.ک#&Jd0⠔ ]޳{a "w % S. a7 6[/&3Q,?t yHsdr>xb{XGɓc&#`>?(=Щ%Yhv*AmĎ9|Odn{͇/_x6tq`c2E͓F@uQ'x/-A[7e$q̊*>&[U^7- vU,,U5|?{xs/ӷD͙0kϛMkU(Ҥ2=O٠pŦHC_iOb E!ptRVM?l~*Br6(]3  @>2.i$6-%ݻK;$a;m-&uYȀBssbB(ӋYR Iy/XsJ3r ˯+dư(^#VU=CY3!mNm=W 9*rx6mk|jj\DzL6~y*,,ު^{6>`pK8]#Ak^K*([DXY((QDriHߺ 빤j=fׅ{i5]5lN[MgTY4gGdn T̫%Xԩ:*+cfuz*[Gr0LY=jiy5 uM3|4CX,׶]D*7R 蜮TZ>3ډ3XG!H bcah8 o%D\YKy\և <2 f>gmd"kjx.Rl̥6A.1PqE) +9UF(e5 XAȡqc:ɜ*saDAcn[Cd7بVX2ey  JԔm60q`[deXgՑшn3RSS(?\+/O>pM'EM;j큿7 dq6 di)Ow@p{lC9d.=]`֖k@gی ̽߿vH&}x>B!{+hXOjidٟ]U;M.+vS P&)peXW2\%7䉘usھƔA[m&6.hWsV@y-6XE;F(nȩ ck{HECfy;b  i'j֘( 4߫2%0\njp҈c<[ $/ R9Rh'qjRڡ [)O׆KR~%JT74':A4,/teZ{U7Aj}x3kq]ETy=2ϵdύQ@j!w=@tr60ճz!q8fI*D")} LQ vx!%F2%a @EqJF<$ex(fdn-ve^u&I%+,M [S= ɪ!;a >3&n2 ׷[Z\9oӄ4RiP5Htb؏/7Ae>ja9i6Q!߮ @mPp#R`8蓼 VLma<N8ə5s/Nƺ+_/LP[DZcHUz良h1s|z`k ȦȚ6&.y)Jei,KH (U\؟BP6G\yGK"6f}PPzU,t<3e8mu"?ëcC4eT<]+1.h="kU Wv ws>6g*mO۵{G \\(u(8%'B|U$q{75(||O`"͇ g$ 4jQ4DM5YZqXZQz0RD~{6g q"++/smUѭ`P' F7V,ɔYrQ҈yFvAj@ +g|0|oca,}+"!nz=Lnd'(K3+'6!/>OE;>:KI]8`uݬmn 'i0U\B_0bj;{WY?^0'L Z GRj}4KLw$*X 5Am8p婀Kq_!IQ6샚x9 8)d\ ҫO[_6#~^YtH26 y,abB9h(B͈ Vܮ_pTE ǻ#AzX=$4ؑ)cb?^`Ղ gR$XHe52xʲuZI{8}觛=ͽDoo-fe*']*𮢀h2S7ZC"REFzo];sќ2 UUcϵBw];Dt8jC2U3D@(LU ç'aTU5 o8 {(8D.! 9rHzԟskdB^w w_Q㙉;_ \m qU&xd>%{NG}>Z1G[`R;WT#IH[}FZ2Tyão1=^1h++~}i82:*hk} UdO/(\ v@!<^CI{sGj|HNfڣʸ*Lu/pĤ\3l$+ffExF*Dl 9D!CMo4~DbB6 (z6Ź; hB',n]:.YǷpcn/߹]T%b< w'~ pY+6?bkTqR:@m+HM-63hLd C $_QKPQH^]xVY,;CIzC$)n>ºl! 9bM/%fWQ:i+~8Ƨkφo ЪE&K Gҫi^x&t]VѪ5 sq 6e.9>ގK=9lSFQrOHwSGOVZd>(E`a&кA :۲hΔ99x{c+ٶhۤbS!T3xARхQZ%egƂ2ogztw5XutW#2 +KzċZ.I">NbBk捕ξ ©u=Tzֿ`R Âh /mE)߷ywPX s;fYrӍOǼT~ 0S-NSu3wA+ w/) ;֑.1ˡh̡hE Qz& 92)["|i ? ls܈%TNBf|'"JôoMԡ@d}JKQz!VF sr5<(ߴSw'On;w' Wgc@cQ fL yԴ 銮v**D-p"2EA^daoL= пuEE(\=`#+D{.:4jS-"{$2UJ#羱b D|~L4HtO~!gLUPxR3.n2VgX .xhȜhRJjdv1z=..z ַx{A,eͽ)QȕG,GjҒ5q hU-b+2z#Э|{LS ?lLP{|LЮccR_CzNl/ѡ^M7=G`p)ݾ\Ge C>M>*Vk'/P(dXo2mfDeT j(I6/7g YJ; hux?Vx%Tihªޣ$~ǔȬ { Mf"-Q}NY8PFho_lP$O3àxmZ28+XB8`2O{E`涥0!й[5%Y \;n]P1tSxdC:$7_LkpfYguYF_|;>r[3Z2s1:aW(pq!)W`l9JBvҗ]ucm3oyPq^h!f Y6IaÚm))Сۍobinإk*7(ub8.l,URqC=Q&N@pbT0-Εhne޲U1fO䎆/$Bx>e)T<<'P^i:DrY}ۻ@Kb\Fv:̃_Zn}?{i,@ 3$`+<SK[bXN\ /1m@5z/ϔ [UQ0tzCk@4 -#_~[Jj{=*Mɽu2%Vxw/|yۃowX1C)mWݛ}nˉRv%5{S ;㘤>Q4:zŦ\H -.krɂiD]Ń8 ADI6Eg7 z+_9AV% 2`ibg|aS1Zm{^@AGc\~?, D E{ևV¢򺎅slqf-r8e5-Y9 juӟ3-$)xmx-NBl`Ĩkܦ1N>:OH %~ܢ=u+y-zyxp#Ǻ.J8 Pf5#H,*w⋏#$4 8fa"IQo3^kO66G\0BPm@ݧOfBajR`77X1Nw5kF^b(ƀں5-m=T8 4Pvdd7U/ BdeeISܶjx$5@یEȕ E1Wz@N H)WQ8Slm."iw^ UՇIcχe}P "tMK`DK]s waȫÿwn0!Md~FfO~MgMnΘ5(vg PD D$Oy&lSyoy4~ѬpsfӀ 21E> nNEK˒d!4=iC` V$izˈ]%tϋ@r"-qKSJJ4zŔb-g6V-1WZdy2H |2X^TVUsRP4A]2_.j8fSP.Z vɡF{?tC 3~Qi QHIobcY`|z B$`SV>bh aPܐé"g Zwy}堂jcrcn9MLj7\- ߨ~ q^tZ}H{;Q\o|AZAzPy &1xMGň2Zrld .&;L]d3ldkT.˂, xT!;Nå(ͮGܖSKeOQg*ޤjaXeB#NǢxp&y@k8q MJb^g J,(`[8*m_֌dŽᡢ%:t {)]X1x{m4)QgJygp-]ó[о4T af1Z^{`a jOHk$zY.U~ijh+ WޤS(5&=+tNDoSxgM)NW/lx&sB6=&@Eg@Fy9hqĶdL,``S8ۗN .y;0MF}3 \: !Mgo(+@cb'$. Sn% y Xƺud50rKz' 塲52W(Tg J것"Q! ck"AtMZy   `vTJ\]9;KV|!Kd9YOXSNơ%ku)`X72| K`}1KQ;qtR\`8?a ./^hTV*.Ӏ3ί`)0$~0a4(jb֧:s G.(N''F$?KSWsMLh!ԟw)+%|-Fvvޛ])OC&De2ODⶉi*hzzJitUʮcFA55.Lzӝxd)x. G(xBR]U{Sؼ\+أ%΁ԕsQ*--vm>>ux 9r8cxer{VxEC ;yg=fn ؇{EB6[:`k'.c别P܁<0OHuAp@aLGC: m.qc mpImD,@@zTɃ,Vˡ2(\@Ng{~U54ެK`a!uqksgNGE{g^y?4uIy;XyJOwp*o||M.= 3*=$^ hX%h>3+Ԓ g@,sJ8<}5O jEXDElg)+j~/ٺ' .s;ضy.zkV3ĘZQ.>FB/BDk7W=_,qZ-%HƞǴB]4eG#pArahpmpfCR_ W*z6v>t a-xaKɫ0N\f!3/ߙ{R e:p5R - BV{FGM a \kQV&f^HC&q+AEMa`?e2wheMPzl?dabmҰº(d2^$$0H#smnrtLw6ԿRᒉ#7VXQTw;~WBʗUu ؂~ /؅P$[hr'Esn1 B\ԑ;Bi.",]ilXMV61XmVͅ_00NuR**7@>AH̯\a=$FGUQ>j:G:K\ {Nk|˅f\X2K m P'AJ:D$;.5SX`R 4-{u C})+ YM.В *2jF $nB Sȝz@Hb]DJ)2V &/Tc{M*(|;WQl`s(\B;.( ciP1еߐdQ$n>AR:֘<|]bz*V\vd1gh1{{E'ӎF6{W7d-y"h\ONٺ"K3!|1zi I[HPq&yF녨c˂>.[30sА.շn:l7RsH@vR4(GR꓁SYPb_!&&o㝘`H6F,"22Rj}4hqu (@pH͇q#Gqt,5 C\>}v˳@9V-yϙPvڵ5U?CClj|i W+kE+=.ҥy]&mU4VjK!T՚RlAè_v.$Z\58D]PEuWAJ~plc&Kg3F>rLtܫ;t `ڙlG tWF+@]XRhп @:oWDMAпBU1O11N ddj:rҼ*`xC7H UIzrZ1;hv=ݿ៏/m[zXY[m,19U,/X~.ъi83&zbPlzކdJe@ kQUh0ytn7Z%M, <+ ]qWe}%~=녷/=4>1)9^5AhLo *Ѻj XG G 5M/3J~t'r˾.M[UH7 řbi<W`ԛ@JZJ30]+?Tx g} G\@YB\S=x3d4A)J;0cg[@]66F v^uX}7@mW{TXl]=)=Ђvu%iPa{6?`bH1]k j);cJND7g-4܆! 5=?WyTE"5O)%(Jl4rOR[YnQ :m[XIs"kg<lJ艩Fq"27V/kruݑe{ԍRƺ‚o)V)`G A >PU_{{%&d81w_ܑ:;Ex9E(OiAr̆b(4Q=.`4ڲɟŒWtɛgo b2BiMQ)AC"Ĝ|c*՚cND,9fMi!8vbP6oTMyuC=.τ0|mhk} Ot4v؟; _o$+bύ8 ;Xʦi1ےI l$f󝴴\)jl!iSBAUAE6{Xjcˍs-n4P3v8Mк]Ý(w'xqS (ޞ17orDC8 |JYq`پ'>2R,DžÛfQ^u&rW:cd:|l/ ƃA+aaMk<lvф4ǩRh aE鄟 GM16Zqwn ,[Ie>򷷝?TCo0w䉋}/:X堓X "}d%;Tp oU1QU#nXAoJJK#C>yi Axre(w<%rN,#2{bcin&wp)#"E+ m^  _L70#L|k0C [U.ٷ8} EXF,ܵmjq9TpIcZ*Z &Qdgˠϸ ,W#1<ՋOC7DRĐTm5Oo;T:?#zQB=k "o>캃,OծyYy`e./ҝ2'y.G=>.)aRIXB\Â!>&fџDalF' ޏbuex:'[hn/sgTs̀D罍z/l7uu>3f,(4pO!+iL{HNմ#}(w BI+LyQ\n?{W# 8 7Tzm.Qr&B =펝L׎>P&ה;SMD;[P D}4ԕWD{tuߝ]fsun9"T_|,MrUZ n A]'C+@6dplO™c$"{$Ӊbm/̞M Zcع*i"U>桟󁂫Fp1͌"orCLlfV_wK,+䂅mVhqm{Gr>cG>ʭ'?)xf;j#[1֞f\`}B514/Ye + "aDpUÅIr6E)5s-3/b,#^X)Dv%}f8=f)xR/#ddIV!b0vssz6ɲ@l(f( ,KxA9*~kůOtsK`AȀ3څj0М3)zBn`_&h[BlW<E?  nu#^7PR)f;"W ƛpL9Ko#nAcjJT[(& )_+P79og"`i4vD!`:% Kair*R=j$I ^hFeFg#|NN [~˚|(a*tLln3r]""O=X哰NxϠa=Tpw; E',Kcx@)f?#oE] L W^7#՜ Lxz%]5~ڜG{R"9,J.UQ s ]h`Cw]O-ggM[6΋6)d| g{gn^J{M۸qY_>U6)@)#-I~f5=ӥ VW9+%+lD?c\T{ R&_#bGY;ʨmOK6ۻU=8l~#8Y)H1'!UP8{JIzY%TAʣ*. *DIkDr0K%0~mpv ?,:N{+աOѧA溘! fj$/4&@3- ſ7Iyy9 q)~`*ģVװ`t˜Lfΐ(PPK5t `[Z1>p}CgrVcH)9,XFқvDՁerF ID>A/ŖB*{}FR0x{e?hp2͛*S|l9&YaՅl/Uc\ɗNPLPPYp|>DjW \z >!"|)ۇIJ!0素c̆Blϛ :]7bi7,(HqpƭR? d{ lT[| Ŷ.=~::CdzX$> #wv#r^~Ig{ ;EڔiXK2W!sf$s<3TtR1O%4^/_peA8˽2Ꮿ%(խ hBT(QIkZ]d,8BI2_. GuTo,G۞VjSj{/\]œr$BUlFnĈ{B(=UF ~Vj b{R\gayߒ~6 .',_D/GXLͼ`v pi#ꓦ9\+fj0sD, aBTL2Cp^=ʝTG>Ljȳ9kIk]s_s"ld.o*= ^iѐ \ϧp@"x>~2]d%T,\},p-6i.n-gvQHm*E`ʭ w"/oX6?H"f?%ow΀`B$p--IXˏ^mBsIhʞmEyxb{&->ǸrSuQEA Ph~c c}rQh^ $Vy&|ToNBaDCVCu*p{/(hRjvqYHLG-)hwf;(*mws)b4VLY3I,ʬf΋,DJ!S!n9r+'#\x`B vn%B\[05d֝cB8 ;!6Hl: Bdbjoo&E[JbP}H:9Z5GΘ: b7P5IER-ohy/AԵ=veʰ!X!~E*`ݣ\v4ƙgɦ!'o}X;U^= #FS;@CAVepʥz:d?-$K)—OF󤾜b«4,BӚ%.hZ 5| D<@N^DuVO Ѿa2d5#9eha!nu5'YMsOޠR`p¥^dށu}HeUM?4 %B"Sc'+ᑩ/#QX.;ǵCZ8ot,. -da?բ1rcHY/DܔTP 9n 7LlK7 63?(+sA,.uέ`2g+Ұ;MѲq= D\9:Rs?ُB΍5:hphGI(h}-F{dmDjYj~5%31 ,29r9( ? c@Ʈ'Ɇm<[2 F |Y?S LdB 5rp77?^ZC<(;oEo莾`L=t:6[in] &0b9] M@@&5gyc$%D.2Wg3S$iyvO6)2}}S{RE2Q}11$Q恙2=E&Ay$6w1=I+H*h޹+ ^~d[ƽ!"#Y GewOv?ꜙr{&{17imYcI_ɾu >3E[DZD 1xܾ$eD"֊ٵEw98->jQg^Ф7Rw*ݼ"i̔lQ eϩYQ-$z=k&:b 90#Л> T{1{mr53!gM$BQݿ%=h/xkMäHSR#KΥ`qGg 6) (DSͽԏ e{IȮ_]Q6f`0s͙rD SzL߉Tk^0"wugS .m~u`'TpoiRE]k%`Eg^Gp߲>Z\CrDZD7ŠiRRt5C'Bf[ENǞ*'zmӼCY ՉUWOi(J8Q%g`+ަ oŧgҭrNjXؐO}yюVSUR9/_[m" ]:xzS <Le/H\E$c%3T A“~xŁt4\1PO+%v;RMc[;+eGSNNҌ|-R~]"eiO.B֖~hxCy}&s(m#tR9[nI{g4yi3*0e9xa?CږzV"mp"E0gy'B *$c%i^*L5M &zV$&D<Z9W._hU\7~ ڬ15{8 6jaoj(жH n5xK XTVToKuH_]f*O,RXq$‰UPSD-]9&jHF4 9ɍ01_Äol8l"a*䷌j{[g`\@_ qi---5d֞9)p=(i 0ztU71wz: s-TA 1ήf"w qb`08H ^|cP D2/44}Ų&"uWLd9Ƨ(\t+8A?è;E0j!C dI2[}Y<  cHA. P&t;%:晚k!g|/uUǚ<]@ kP+Jā 1&7pO "]p vO_/F0/UQ~~R1ei\Tg`K"SQs- X3'ZTݺvK%3#@&eFCJjjɕaij/mWf/kߘM+rH[f}>rl1'\ԝKɥg^k0nyų~슟3l8Cb 0?_ !y[D'߷YXݟC{EҶ!C\Tѱ j7I=qEL&ͅZFcias7h9O4exP8ҹ@D\DvH Cx4Dw3WJZ,w-RO^tV2jZdgAU2AGbC"]KH¦v@!9 F<(*ߺdR:!LhģcW {mb~9ǩܖX} vAI#.x'SfwʷTzY+Do1ZJ$SUqԚ`FZT}UaPCF-䐣xa~|SYKErZ(LEjܯKD2+){Fqƥ*"{`t&ᳰ'y~YOo7&Dˡܭ 70qaD4߭GMb&R7T۱|%HUI+ D~nu .V$ԋY4?4{&*ۛXxNQ5p&4GBӁJa]@N oppqw ntv&]H o~M>,J¤LU Qhk|jsHw܉HZ:5PduwdKpTet_l157 ч{dNS}_i+% >uX,lkp-ja3DML"TE!ظ\N, F5=-4oi$6Z h1vk "}ߥ'Oh vBX]T1 34 T8+S+Hf=HhQ.**~@lyݑOAߐ2M;`pn%/Ŕ%:) :HJñ1 p}y&hDdֿzv,yLraAG}GT#{N Abq4bO^3̇|?UK YeHdٖZxt?CJn+i[ 93ayUQX~+hݳrVZÒ4qA @e1yjcۜI5e57`  Q9NhE޳VQ3/M"*#ǁ8u a^']TKѨn?#.B[%w]}x# TxD n[4pUuBu|*O=ɞgUwN ȣ q^M~s~ $OMQ-s6 deF$ը["Z NGVBX e&=\.dcE,m!I!B#m^a*H12G V0x UܲE뛹K D^"M[;٩\Gڢ.Em)/R% 4qtӖX0ZKɳ2~$ϴ_b3;Lh[p%S9BsOQPV[Wd?[i`94y2,HfQm ~]POB|z]y2`{i1#Q\C 83{> WlXn# xH>%}fp: R7|T@Ċf>.eѸ|84+Bs$jLǫ#"Ayq'l 2BۻK^K!/-GDjil3d+ol[YRm;b'n|/t?d5S<k=|WX)G`ׂ_`Q<\6 t jXA,܋&͘2>v- ,1c$sI?1V6U װ&lڄs?[|G_sӢ#@N<=@kl35Ex! ,˞T5vR'HR3@^Y'g3Q mCb UsmC *,UkY$͚uE6<̭ =NJ&=grm*?I,eс}@oԯ<@>%V|8ŔM)Wۤ;opx"ZiHj W ,ku dzЌhTio6iB TXw5 ^Umb m)ull>LAg5!Qf~9zFD`rCvѦG9|68,wR@p)V x˻pȢu'{h`$(CbZnS@89H2+L{%ő1wb'R8Nr3.窓k_pxFTx .P, SOly2e=26wt[k2&s~ޭJ!ϑ/,61}U5)]Mba"cru,Dk"͵b+Nc$TLxL.hoV!>SanhĄN'Bd=xfFCX%i6i& _+)4 +qW43ua8dV&L?\|hT1q}+ &g/Q;j4\֬ۻ:*BD|k5^0 l FڰhiǪ\oK*7''=~utJ f,_{{Oe_HDTDUyYوݗBxV(vZ1VMBz :n!؝*lKI/ e9;G D](.oubC<=df 'qƃ@SD=~?x^:21GHe%+(Gttݍe6i.4έe&hBg?&.4>+06KoJ2zvjZ,ИYFMZ h_)/t\ӼŢCl%NB* ll7N+fR^Kj^)z10;_d19߅X6>߉ `.g|*ARXp[wv xFx-tP;x$,_d= UѷO?c,5R&/tJwfj!k =l0}5j9Qeʭˍ-B"8AA #%z[D! _#AJ8Xյk`q+[J^/'.\iP=U=NQ* a &6q~X^yvq?-. yNXtxnv'88fXIh"Q` sh ڌe(`K@ωgǶO';DIK3N&.BMV^ႷSOۢy,HC[L5j{p6T#3fM2_/2?e@@*L@8,fDH&Ml)O;N4-}L5r0:%»m0ȕuu_u At:d{QGZ|,vGm>p%4g1}ӔTg\V{^P|<%  *^WD%p_=΁@d|0D+՞|]w_Dom"DL ZG.vx 3/gCEb9JM+ysEDjM&DR!VEui"Ngz)L*٢T$*+/ZIz8 1[7bCuw?H[7tvxE }}8x9l*b)%Tqh_  /-Rq-˛R23*\3:6e$#>'+0*/䔎R#  fŢ:|oḰ-AL!@Qb-عT7LQ~N+ _0N%mm"NUŕ#~18cE_zg.7)PO =:"՝.9M ov,V8CGEאљ6_ag9HP}%`}z #KA9*U )yqDV;A%)ö6hʦ)އ|D[_Zyhiol PaL#GQZ'B0'~؏]BZt7-#QoʟSįM)IK>a5ou )8e<شv&efżl#f1K~0-z~./fax@H:>(QX`j%"k}B{,(JF@ =89r @Z!N:6o<LxXN,-)MP!d t/ܐ.CB#6#`!m%DUMAݎ}ZN8Di{yKKgX+ԜTQ29эKWGߜ6H c Ʃ`bl)*3I*<3(Fɀf_XG傃m\Ğ<2jD+E1i=ņE,IJinGsL;)g[|DSBso1ivYxg]. xiX/&ЉYTT1E[#L `X?u]a.Tn"(]MCbLW"o%T!G4%qm*<ß/<`,sBk SReȹ7Lύb&+1'p.Jɛf{*pO} BGАɘsF.dmjr[󊈀3(U>}]ZA@1$=ƼDװ5_I nlTaѝ+5@1re 퀄K&l.ٮ[ZޜQ(C\<5VpԶ,>jIom-~xk2b'93\f7|n' "1LDy>h{3m $b.^2m, z"PA aEx~3<|apCv#dx 4.ʮ)XzXV=~ط-)WCs(DW].rykd7*Dk5x'4%5)1㵍bu Og_V( SQTOj̩$Q$T(2c=TxUR㿔z@[+JQ#(ݧaspM:oVquH[K|xvue?FEBq)t5r x}BLilsSkGf`Ǵa@ % \jz{E-F/6MGyb`dj^E<aĔ'fz ȫu"0?> *c *@J V{(/(Eb^C &3BXUv"eJWw:'ƯK-*ٸۃ,V_E)u}?L- zI/uT~tMWzc8;=hR-#p4bȈ`>%@xB6Vڛ~wSρs( 4 3]W$AU1z񥃨@tw!P$%㈣*#&k?%b@0GCVh?Dَz$/d!6 rC>+Y][6btqg#߹5z!IS!X~mF wI]ݿMbp̶l/ [S Nc MAmSJ?g;os}"1+w.)<}q?bDחm<]P%UkEy;&K*e~V1WaS `K 128u YCS2^uA䩶V`$R ":-TiثʎtST,YdL?~ڵaMޜ\ S0fv`Y56ÍbƾE][ծBz(XK>vD?!4r\"p1xZ w|~ʆK"Xuxv[Ue3R%;l]b/ :/EF7]\3KQ )^"] l>Fe Xj6 r/(%[hmĔꤵVl~G8I v?}M?:n;||2Xz; DDV"anvQf$}g/ЪSF‰DV[S۾pԓqb۫lsA7){yq[;W=#7kEd ȕ %Q_UC?&Lʸ؜'qH“VsIa0X0jZjzO䕒TFFx/U[L"on }KF\{HȧȂX悲HN6+&H41`9`P@dKc/lҥKeJ~.Y=i*[EW \+seAx<=gLUvڍ="Xcnh$<=*ɽ710c. [It AU^6G}~ ¶U5 .ˬ3,idVGRej8jac gǖ^#c] 7(>#JHc+1s8_30ʃRlpʏ[`7 ~\[[ ~ȯ̏B/e6R&)e,qG"7m|Kdsz`Wn`X||Fkwiʏy1^/=7Z{Xk4o^,c$|QJg]LA _.w/,lS<3]o;Vm>ʫGՇnYKQmT-\XSUm:2OO?Gh745<9G&; 1D/9 Dfa&tr Aꢖ0#6?#xT$S0gpnFa_optj @,L1dصVXXmo%3G]5qeQP jm*UP{OAG*u,/ZG(N+K%7$*n=bW+ >u+4xPE͞f ]ϗl8͐JvLqzac~)x*߃n/}*[޾kY!,4Yu: kˬvd-iUCcbV|H2NN}Mf3O_F#Da ݁3h`x5^@vK~`4b G Ƿ}׸ puVyӖtu#$0'PՔ[W[A-yFߜ4|%Qa BLa!—2\c2sg/ Ed/-3YNFhJ,e PL`&cWʎ v3sNЀ Qç^kr(%tl:{>\Ia0cQKˠa}XmSNP)!u @8ڙvMḌ+y|p_P7ò香W|SmxӋm h+GЊ|0WabD&mOS~Y/럵Tfvс1&™uP pbG]S_ݳ:7qY.%Q^kɯ3|pCȟ6M.#PK,\.$̕\&_v_>)PƼd&2PmKo;c,Fz%ktwp-\pZx6fGŦn!ofhɐ'ʊjHE}f+P86?E(gl5yQGCVie+K(1h DB~Pz?#tyJ1C\r5@ n0CxQiG6kv1T]R+ ԅM&4Ebܭv>>yK ͷ8n^hY: 7G\Z(#˵H*=t|iTA:Ʒ$ޥ+$R\=$'DLI)#`ߦZ~ڰ)T_Tc ;8t3+xDUKxpv1vë젥iTA*jntO| "O~|'E&.~,]$ *N=:N=$*NQuF7?U$+F$Fo-~P;aF_% h(LHN><ܨU)~iPOR`&d\1iY7~rOGa Z!8m9٭9T6h\ꓢMO2|18 :bsܐL8]P$x mi9%\>2ؽU5:rOSo1ElNx<~qoz3^bP"ml#Ok4jnv !D<Z/3v2'R!2/ߵO:TW3|z[ )ˢ`ن7p}h^P#X9v{yA7s#ҝn~5ma58Hu—XH>^pB,ApmnE9mԊu;'w/k-AE6:މo'?{p0dulM`zTpU@VhB'xܨP^ϴ9[#7il#Ƨ#.u~~2?1tg;A[`";yvĞ9fE E)2h;M9j_g%Od#8*S~V^[_:FE%N5DgbE"jy89[eႝVOVj>|3DiAKr{N$30\6ۙӝwd춢}F֙Qj`F L?8sdDk?4U|\{IBokoi9,.60!"=sƣ Mt=#h@+EbSx-]`VO3y!"o4TNm}\438Ay+\pPY+A ,#S an5ŵ]biӼ'&ٟVUJ)KyE5QBITȱc 4'dǔ$ )} d; sM,~H\/C 3@i vJsZv;ʎı{ՏlU^,6,uJy}3dQFzZU@Z)lpء͗`&Ƿ!T` ѕ2p{#ZnѳCOsЃ">ř~i,j?Ayų"5:4gM?tU覞12+,t\k$*X /rH3qv?KMԖr(.B/6j<R:2G;7r0ڈꍍ/y.b+w(ۄcsZԺ3ȥe.6> 3/I's| Swm 45wpY[3Pʐh͢U B_)-;;*7`K~z|;링Fb{6~4R8YBɮ0:>|]JX]] Jār,Y0Oݾ3;_wXtA>LN"n/2[Fk~wU嘤TC5mzo5Ԋ̠==H)L9u )Kʝ6.КYѫՉˏ&khaV\*(O?Y&K5\:p0G@jN=e*QocM?̕X7S^K8ygˢd:Z"&kubr'Ezh&Vȅd7x'<]QA51z:MEOO H$^^bJ=[C,ߥl5pP'E ;[KinOoM1~1v,y/X@lSUnq`lb+%ud*mU,е!vSfd%@{p= E;D8S# (VX N36X]#dĂEZ͜ nS'!dl&E.9f0hz Ej_5vV5hY1U\mvಭPyd+{>Ů9ު"F >)%2TL׬k5c`/SB{ㇳYZTd!l%[3"@vKlT2pg3u?E+ҍO_0X"X9qr̯:k||6$@"SpMpRj3DXrg{FH:ݐIxLBQTئpS8p*Mpf'r>qiZald]0I^@8NImP}_QuBlu3Ojru>2"Bo }6Bvf83ƣKt-iau=鈉Zxlru3 em-*Z3mJ ]؀VE\N6sKt`M2Y4Uo̻kflO'rA1+6 {aGxW!}㽰뷵*ҲO@&R+xCe]oX1$ >*<9UQל7w'bܰkCx94 ?rxjX_myJZvܹ 4>lǬAK@ ej #; ˞컸 5n@\-kُ 7zά#!lF!,OJ[B \|4SN܎u b1H)ȉ +Z`k\Bh?rcʝS(XO8YaS#~ωB6_VD߻<5磐%*6b$%6ֿR?`n>.7>F5 h*g<[A&iQ^$M&YJ S?vBdJFQ?m[T{{``ahۡ AE1kK`FM~O`lu8iNC3<ļ &D6p7p] NF-Q랶-)ewܕX,h| Gq*[PVl,νjx֮ɿYbll~YNW1.b)FU΄ n2@L(^ځuE1ٶU^uuL)v Y2ͨO]׏~ǎtRw2)5.J I%+,G"k:΢c5jXe>GDGքhptj03uN2i4Z3Qj-q )[.RQXg¨~8&~fR)~v!cW&[6 .z16d +m\qA]#Q8JX-^L0$x.۳&/Aw~ Užh5c HA4XɞR؉"K8`/Zg]Qq/MX>e~3HhQ"мBzֆWX}-L+gu@T@ 2Zo*[Xbڇ#W_SF]@s bwjB- X0\#ȳtKgh` OJ9 ZNgD]nSS@7 X` !}v\`N|g>Ί| C@fLjw[^7u~ ʼn@qN>mdc- gOH#iaDCċFo%|ž}Np4\}&]Cg1ggl؊VpJF9,xI ņvɧX`,eurm_iZa]49TW{baԥML6$=x@Jo*XY9lGeyxTPG-;n3 ʊ8vMl^oh|D'-,T],1ʾ1!AH:ܮB0h-a>r:p#dLM\|xޔo+i@j)n+ U;>GLPU޿opNI@gL0>"a APhZ<~N29`k/@h_/+b9o[ZPKtہ89K?,$Xܥv5(E$%0ۄ/P_T3.{(``3%c0#R&%O:ܨ;T =RCYF{*vt(DH 1G,mnҎsgFDn$P#8|fv ϵMص6 SKLq8VOFt /d XlߣlGm5G~dKlH+i%X݁nJxdRnf3b%oa:tp5.RTx""i#KA W|B"єP~b>JYh%")A)C.`n,/1GME J` QCPj/N7Y9q/'w$ } 3F Ydr$ W*&CGľR{ ǍQ>Vui5 /ba`3RQ{/Q7 ݋_+E b7`ä ,ScuZ}W:nuG)ZM ǿRUfDєŭcC9Fn Rc5]_4 ł2-U\ц"@i v97bD*t]iHZrL}s>GpOӫ (˕jQz 1C?  }xYr/W}^!p }UU5!o=4'}-PY]b/ÂNtfPE}1X),uFU <)` _bbk6ā =Z;ͥvٛ,[͎T; z\h ."4"ruQ,ME40vT}FE.`oB)ꢲ2ԲVy>fs~\B\,G:y2G?/;X[v (|hj0W:ri~Wj %~9z'C-Jm46&fu^Y斿z Z( 4~Xq΁|25Sq#R76 eV4d2QNp>/?jV1&yFEr|r< cXe2FIՠTy4y4lPƴQ@E,SU6cL<<){ Q_~j*#?R# 1e: "4K`{ ޫ-gw%Lk!`]%Q!Yt1bSLJ) $& ʍJVY^M_0M1g\ź AuS@PmkX^ IbQԏ%0ׇu†-E0H'7Qegz+IJ?c j 2&( A%SlIc ݉bHC r3yӔ_4rRJ0-'h~y#kN='4J85eqǰWkne/K Fb Wؒ;o8ek[d0tc(]W<ַ kF[$FCc6󇢅_@W\!~kg4G)Mgcc='fi,1^ j$NyÐ ){L3*~8~cB#,EP>]G3eR`,q$,1k-]4X&{O?GdrfBu+7fA|]Z?1N7M7<"A/pPO39SIyBurh"˔t oc1Y(ev{ oE9vGG"Kp${OF*[ )@n- v9Ϭh?ˁQFp}|15i{PWL/A[8-^=Tk=~(.d%.&cEA'co=`s& PכInS7ƎMk 奨ስ߈ srWGj|s V5AjœvcSalm5A` ,t=Q)9S!s^S*ҟ0x5ء~'lEӊO)(tQ,V@B_kb* lsyJQ: <^ӘNFJmig UҦC;&ڮLT8 Ѐ'/+z“ڭmD!)w@ A<vQ~AU34mux0y UdY^EutƁ8D0,=A!Qu?qUiѩ|ES>)_é h6(dt+iGizBEye\0E K+9zj\lLADLd?bq% Fdx't̓x1{6?@Mܠ2ZJՆ)/ ?hރ4_%$!"Wu5: R! ֚({Jr61}~DEA򓆠}a?)z3iOEx >X$C3ޣ*xT{ ԫ*K9vsoJqf ޴ 9;z-61s?(V8!ET=UDd~&Oc*> -GΜg˸o5BvֆHX@}zzbN*oABMdy, b7Ã*S#M]\R`98X# ړ:>OZ3?Ĕn,;-^f}[o}ѕ<%;'m!U*O1YDΜl\h( \^, "\Ş3—ks 4u[&̣foZ7ő@|KX%,{*4z W TMU5U)8џ YG|qZ&'1]j̼dr4vF-`66bihx ָYH EX8cKLf^Vc%?α4jb#+ŗ*)̌ 4Dwk~~X U*{1 hĖ {f4:mhx;K,I2˘qp*&N-q=q5]nU9%}Ϻs(0JWVx#VU#VWFb>ɲP %+®nl Vt)W޿N=@: ್2Hdu@I2ք*$<{Y= c`s1vչ $’I~&2X4(\pX7l˅Sv}Pz0{|>3tp~`?b2t[Dz,~6A/oHJrj 6=$ʭ AA S %~҃L]IAKuz@RG{Von f[}׳MS^wE(c?`&L+g^ -Ř!:6KYp _.*r8W? .N gUv 65|c܎YX"15rx8VOr#"H~@@>._@؁7(m$옏3tT'Jyp+2k-ܢXVs42F.Mf, "l oYD(bS$6,R˱Osc/]ZQىW`.KMCq}%'T4 ?[B~r.:cb8ϒt-y~oCZ+zsVOq(1&ocyI_/0obf]g4iV_/# iG#ħO}Ud \Q}+r x(mM kwbUw.;pYeI>5 )`Z04W_2})UL@'{[Z0@+]SƨE+T<TsUn:#TJX'|M6J-qq0?@h B*9S ib!#|RF&dR*@eVGO-Xe9+y3>v~d+5 ӄȬFCr4Kql1wTJ(fdGF1iq ?O#].*kK|go'/ڌ#72:W>;JN^? N&@+@A|Ư*ټVH6M!L& ;vli":-g;*3p,$VM(e=$&=։-oLoդO 8ЫWN? @Yh["qAmwda4g;iC%E\\2)Ki$*t)&{ΖW:!? oU G\Ssr=e*,zBRzX"*4v1Vʣ go+ﯥX40[ZpЫԒ!-ݜ__W4S>+>*ղrMFO<0ͬ~R/ !o!qPX/9_32`+]LJIwik@4a "{Hsiy[UDΏ8 Ga_-IA=MXw)"v m Oc0}2cL%?a7vH$~1$N&u!% WlsJ; )wqP\\?TˤK"Q*HLW" ʙF:IV}k_$k]${^Գb֫zՅo1' |q|!qSգ+Ƭ[Wkۇ0a+ҋڊ0lzLdMBz/Lguvul3d|n9yX؝ڮE\wiU~1ݿmއi͹\qdiZ?׼[9ttvoYMJ#` &tyRXij Hيg-r.q!h~B:}齦NI_+S~_Aqʱ}U+] ^#Z+Q WвyV;h}:`zu~rӾ(aoZC9V"= R#!P5`t+oCS fJ}}HQYu y]j#`-1ϧwv8rFmd._ƛ+!^8S4J;1 NMv27~F?˯kR)W8Pg.5+M4ODz .WVT@tꨞd.yU'oe.QK.OI5ɢrEtpnu!ža;W㒦M3½.艐6qfJ'|BiGIid8~ S}X^J`̣)0kdv, fϱM~5-I( w)_Gi.g?tt!wP-ɿ‡=龄D, L,{No0<ݍ_!+{u< WFzQhUf<,_c4Dҿ7XAJ#)>&W<5k :ssO揌irNzljC]@FvW?9ALʦ##Pz9BGoo;D 3қ1ged=*ScngڲhiXrb3%qv,tLޱ'9͗/O%[f#ղ^ s"p5zM?Y!t15 A?ֿ*{Zd|وI~尔c9Vr~W ` 3v9n`t lݮ*s _cG{mGɭw&KFBc3bGxH>VH6t'-eO؁Oe8c9T%|pFA9*? L7e쟷@4cnYBbCE0NjI@t^81w̺:6TW'b `+N V(k3'gL(w1oɳWg܏zO[*^4RG`DESfMs GR <*y5.FLV&7Gއ x7YbP)TJD\f?`aVVNW"rL9ZY x Te1Z%?0< {MR1#|jo ɂr W$Q2Y~NWե!iZ\ċe\jA{Ƚ:^ZwܛtLX/oc#Ukh.(Զ-QN~cB B鱿:/f[XFBm JcA.#>b}f0UcF4E@E֐|!QK{"H;ɼI(gB.JknOx V՜A$FvUTRlF-. ,qP郼cRɾ?P'-FZg2"}r.3vI7ͥzвd [CHX<ƚ,[֦ (=jheV;AK~1a&`_R­҄ʁҦW- -yMt1״&)YR6[8coAB뽵j0vtʮɉO#7brz|?@VJ1Ļg U9H C`H^zaH 7D!~dS.}MꅑͼoSwDfVMc>+I@\d"*U/TRg&ag_ל'i|!+}Ӕo%Mk㲬SO1bo+HU3p&liJ:*Z>"WqsuAX^> s<[8FDVXt5}ńbSX &_Am{҈F؟`PdAF- \ڕ鶠%nGn^3q>D9i h+鯢3ji)s.zibW( f%GZT^qC cR Eޙ?%՚çΓ7=klz?MW}T cK(c*_?tx{0=F!9n$i:s3pE V,eugُRYHlry;gV]FR+L׽۲N1jTY$0ƛˌ 1˹% ,a [TDe$:'.4DUVaT\6^GoX+.3(v y߭\[-l7C-HI92WLy(̲o8bg)PJR֬eDe6a&H\db@@K 6ϭY3Q4OP7_)07܈268$agh2)zQܡ%zV*ZG] mF 7eҀ8́7\F9̂ͨ c^Б۰ )j$gjW_NMu.gUAtA᥷01qRQOR;ڧlwtxQ݄X2zk+jd }_MG zօQOx} gIe3_Op[*Eygɋ[fQѭw%: Яױ(F#wm̶zrUV6n12oBqy"2F<;gy"+Gg˜w5 NɋC. 'W[iήw =M4?/ ͡Ĕ]17_Dר7l6/0i%.qɥYZm754²+ X$,A֍?>´E]Au%eNt `&`~x͔\_ySNnu9lFM ӈ #c[X 2s [^5o&O#:7rUjc8`zS]Xn˻UnA&s;bOk}(] h+ZdnP {a5de"Yb+҃7@{* e& V~H2߆tbEW:A8j(PяۇY~ޞOaIEcG&72\m<KwD2 8E}ⰷ 8F!VP7&xDAN>B܉~ځ"tE*M>; {CP_p UO5ҫ  ccIm6bޥREm{`h6@{D+6yENF 㷄-fX6߻6<ԖͻB)7CpOcp:o3&" YZ?:ĝ@{.3ۡB!04|E54Oq$O+z~I_mC8h!u@1LYX;`ն9n*oߓkkra;3-s%pW=܍$R9%mPq\L\_HDM* N×u(#̻V@JVNqlvԛe -5KQGZ-$ b;qnxM`~񐁥mxׇADdIe$ as24XL7?V6dv]΀MD *qw(UD:r:+!/-T'>gCɚkR,6L? 0B.<:A-i ֹͤ*#=?laRRNmI1{rVSמ0G.72 /$8h^#(NJR*oJ8NI!}u$>K[z 1-6.T0~.sjTayRpv䊍)iÁ/ۀ7,gC k)YΒ D0*SH\ &c$TV>([WRohS/%~tIܷ©t<\*ePh 24&{1Jȗ1zS$ ]6?H: |cK 63ʢ4DĐzC 7;橈?t&Tk= WӴ gnu=Cv4ѷmVa|d 1ٯi]#&͝1qO-12ЗPlʯ6S-|EVQT%T+NUH-aʑw ^SqXx.' _2xMV ya9/=GqΣfD{Grg-e_ [t_sB`k;,$ih[r|yگQ&SLƽ/s[o5lunaoDڪR92UvykAd]磧a8ЖOE^{iP*xW-4ٓ`bi()>ä<WtgYF 3l7,%MPٛ0]}tFY3&X,XhQw,bSɇF"Y7?2 K)7OV2K4ģ=W$k 03j^#? o^d?;s7Ko?[g-« 6L$!Ơ g 8Q%n֖"yP7M]S]1CJy<rS  FkרhbL,N"ݏl@>pqTowS(-W)Gl$^VT壙ȗ$yXZt@cu ^zI;'euTTeMFF!'"x2j '+s&Ry;M [6 B^A|i8Cy`IJoZ*֋}-^KNL3;LGu\[ 31w3^A7f"n qJ,јlDdDdm*WajPOZ 8=aɼ]0 +G׵l/g LWK+v5q$*8S|s <`Kq?ܓ8y䩨ֆEirt[ YDňIYr%mqg>cn[ POXsωeri^b" _~盋+lZ3Ŗ6\\?>c d_p-xiu WL'3MԽhWG>lð+‰Ժ}ڠr-TTlaR^`eݒѢA  ־mul`gI|ej~?ּ?bft ܒ|2FZIKr2?hz"qM{}O:fi CQG=g&gm-WTH %/|muJ(vO]g) o'DK'Nn|`YeۏouQ¬?k5dAI)wob*Hs8U䴛6od OQtd/JKu臃?=avJC>9?m}+JHҍ A4uS% zbS0ǹF{S RR~'|b]K>< _ osr{ϵyR̟$:>g/~fWŽx6$kFQ5jIk Yv#+__C!>a^3>/)-_ܗ-y/^٫tp6շ^l& ֆ r5`4Q==U+:!GENoõgQ\Vh70G|r?I]svVY œ$x: oJ6;YH}1Ibn;hy\o%TUu"ln\c|<ζyr6-i1MSQK ~\tx2/S }]D$h;&.t+쨄?Q9`ڌTL co5Y~E DqwG;ARA< QMzl'7FU^nKĒ $fP;x3R6؜Uh)d[%L.áwMC!B)PU[݅6OJ}./$h= syK➔/*$rtn 0h"،?6[\]<5FPF"p #/lpjbLVH_4p ףpTP R 2F g1dW^sJRuܗԏL Cg!# FFᦸK7X2Oܪs$cS?6' ϖoXo&9_rڪIb3{𙟇MRohמTa\I48C}Eugp>,P?I}s[8l%ju%EyɈ_tJ{p rOX\/<悬;"%S t-"@36!e*:c7Q!>rO`҃ePNq'oF嫱O>a0O6һƲpf[|]-!] t@C^זowzTW;UZ傼pѦ.&W]4D4P\R/$hP #<0 32v 9$jas6kћдC#nHws@TG<0"s`BPsA2_ i一)nߙ{v\~yRq!y7^Na- Miw|"'3|OLQn9n:vھΖllmN⛟ieRdƜʲ٦L`D 7_z#ԧVoNL]"X&2 jc67B.T9E_C73kdDd=x' -~e5⊲I0jl3fWN ĵrirgڳu* 7!$n*gդ-fqoWx7/h;4!5տqVd 4 S4g  ͪ?`A˒{zqfpM J0`V(9jHHAy39yP<.\b_A29ly, ŜREÚ-#?!ʢ*KM'D&_|X(}VM;dpa@p QP! (!څH6N}O /I[)G_̗>g^N ^oA=9`v(;ƏkOgV8[K.<]>EmDͦMư};cTo^Pp8ZZE[Z~ /L DK(TڨhOxgN 2D`;mT7O@۲XtۇLwxXXn3[ | #nrj4^54}P [m /VEPT`P!N">TfӪ̲!܃co)V@26 ވu+2F #r*s'Q Pig}!=%+,!Ӻ=iL /~1蜲tT xTWYMr'pƿA)w*L;B8iܿ"LHn&Q/SraUk<(g/C H[{8#Np퓚E'W (t<$RzT2NʚO '@i^_z=rN$y`}J3'mn"Y[]7P@ٻ~j[NӏEx`}{/_‹8 ]k-@DG MUcwmf eEL? 7μW4d-[<@~YMյ!ރ0(] id v-|wv;K͞.fkfj&vT ᑰlpQ r1e8n߈Dr,0+_2TxlCyDX65siS$X ̈́z7݀w v8oK/}-Wr r:u/thgHC95͑įOu Ps\WW#W QIehr9$lŤ5Ƨt TL#xD*R5n4>5IqDDsdd*yIevCaw6hj3#{_.TɧPxG8l'B1bMTjZy7add5X0%+??f_#}/Jܪ^auAT?ԙ70WTW[ܩ~-B~i!<T?O$Moh{u]dSZ6<6 tc/++Z"l3(5*oU}1mv@:nxCqQfGFӊBH).>c2Q8&;,3M!(c%8ϓV$i dmxfXZgzN_Ǫb+V^_.=}  Je[JRe=RC0tsѨUY wqnh3ɴ *s2ts5. nl)Nu#<>/4{?^r,{T3*'3˙.JN6rS8镅tNz?3\agduDwҘ)sT%a}h8cXY)2j7Q:r8v~T~gEf͞OB)qxn1q Ig]U|W lT'Mw:e6SP43duW&|2fHv30H(ґg('dkP(aKI59\C! HRO7C%նMY<%n'Auҝ.T`22Ylyf(%9dlOXuu7`]۲u,C*`M6}ҷ0qP@2|OĀSͻ3ΤpDؾ^v>+Xn@> NA~YSM x륷^Ҩv>znCaTk^e`(ƨ\^E?6 b栞9w`ati/ Y2Xk<-,i?<چF^~YɐB]džzؠ##2(``Wm"`#gg GwM/48 QX5фӖrN#Gܛ۷Gl雔ˆ^rH~0}9c2R!]6"t9'K ʵ2 CDn} /GX=x.ycTV;slpI ͜I&`)GQc4nEZ<xYMfjN*0FM!ck\{{O2oN 0?,2N){~SVr6kUK0E)W65LLEM80%r{ vnJI(*XDr=Y,(mm@ip8B̚"wP`$)BʖIy(=^K~Pߟb :-!_,7c "ಸ#9L}KAGZ$Acnzs?xA- :ӄR)w{{7C8YݟhUUZxl)uXL=Z\Kf9-^hz}#iK0V,h_`+ѐF939_!>F<cD`5 ;+\ R]| $'jG^:Tb*䓭 vB՟g4lH *oʾ}j l@'.IK fp7.?%! q>jr͔=Գ Sիٌ@b Н|!l9\(ı-S IC:?KrwEP0cʶĿ(Tdxj=9y#/gSEX֟kTP;uj&TY^R.ޠbI2I9]+ Jl;Nw$ZM@xzP8Zȱ+ iL~C0#}\MBAHv5$2`߈ lLCvB|HW61>zk( nuW2Tv-)n)iOusB7IJ"Op6-AhIbfgG%jN/>~BԘlCgǺܥ̷h8.Xl\wvE1#foIH] Be2imrr0lљ[g/F>| 9LHgyy'(j h kʸLq4 \_i@TS3݀Wfk)5?`;uFo~bAfM)r27h ٣OTmZc46ksaA]zvWwSv_WcI~r4'4 }@{ p~{S-y+ GHv$v$cn9%뾯(3olL$;C3pVvfW,MfۓBtϡivV\ G k82 k>3&''Ў iNA5!Q{gshޤ>x6 s@U/SBO^2=&_/6x]!@we*V%K39nckPmܖRqv 5D+o&ހ=:d),~<W8[Dpej\+1B.7dnmQh5[]ta'UH=E9'+2.Bj'|6YR0_c93IJǙ<ױ ̊ge(Tt-w{"i< j17Pbjsm˺(0iqHCu*ID\? Dlh. h`FGЭjʱXl#"0--K-6"HrH< Bt[v-_-]=ye BpM. cq$z+$+2WjQ*=0HpdN-nbфę|>~Onĕ9Ω.T ݤٴxjYLW{_Pr/ȬX`w#P򑟡edtW  fx ݁}7'ʷ!YJ21kQJMc\Ad,\̳hWHÚ^QVWmMmcD:QaFJ9K]H ٖ5׿9T0+yYD:#*eH-Z'# .0o* JY;;r@G ՉH%&'Acf'4 g3ZM`A~A#+^Ftx_ Nlc[h%3u"*R'r =_a^qa)(}&ětfȘ]ߑQLM={aq(_.?:JX{Gݠ!K'J/{&qځd ts/w/ lokUliº9Hq쓖EhdwјJ>Y@,M7ACK7"t~JxO{#[Fi4\I.b>hSOIz|Rc%1wP/P=%t? 9LIm8Q^ V쵹A.zO$hCِK؛'J]dt+>?f-nIϩk¸JA/Cu)4zu˰c-g8#]&"AS,FI%152U>e-Ba+/ )qK֞ ¸WR"UI#韭s1mg:.'֢D(zm"pd!^%WY-%UT j8R9["ȣ#/_pԠAqqJΎaAd ̈́ w;l`[_}9T#"Wbhmٰ-o"JJ~rl8X&PB1b'jIŧ[.o!0r%E|(ftEeW(žY>e`8㤑_^6v!1$@gjb83ddôz6R>bp u ˓Delrtʓޠцi]_e6FݰLW]8v!!gzjgVCFf4jǠƜ4.JpQ 5v#N^7m_%`VDXM\J1Hێ_pݗ6<w5'/d /ȶV3dldA=W 3 .K`߽vg&Gu j =oCo=#5-GΔŃ2}$=l0`rkz'?P=6|(It Z@K5Z!F8v&jc:bJrb:@~0e] [>SզuFHe*2J|_]֜y4 xGr}b\z]Vٕz5B8 oņಆU]6T_;+.%ki,]@;jS/Ou/mu zR@#煮6>Ќvg`rBr-I$c}2.0ьEUKPG9m8< xOJսrd\kGqHBw<#;T@9Z;cnV;3DmIv/4:P$p-+)3UvbI; /=<1ձwE9H폀i,܆HK8ڄUN4{AN1H.XәhJnd7pcOUiWt4^I=(Tm35~q7 r?2nUergkaU{Q(k]J#[T|7F?R+țu$ӑGʺYt}76_rAϬ 7'/|TLfݿ^agRz&+#?}!gTFWݺ@ƶnxhT6XK[R(EiT^``NM~bE,c|Ɨ@T\"3Ex Z f^U4ۯ$Cش>f?6/oNM4&֜fGnɩv|>tU,j|E(jv5xrs%=WJsj|e}߹aAY#>wo8.襔<.^gaXX%]@RrBV>vPzy3]ͽr>f/ g%~5%˲Lh=а-횮f?g\ari ĊQpH24]2Ⱥ9gS$\7L:gbwe5CKL1ƬO;!ݣF&=9l=[| #S)@L\‹|&)S J/đ^5\ /??oE JCL ط>qt.^{&H )I}$Ȓ"jX2ٯ;˹x},zwYB.t{U~Y䊽Ob%3L]㪉$ekiG/Kt이?$' W8s/ltrKHA> p1@Z< X[h?#)5_ >]R!W:\ZeL+"4O28\4IQ祘de…A=[Edcic ,`/Wwą=fnx7GoynDUK>ƍZ^l_Ofa|""1Y*z;9Ac< ٨5RAEM))iATa0;?eIPUbxQ ߬kplR<7""lr?#2S&u@ҙjp8pi6q:qj/1'1E#@5B_ YK0B&aLU.Z+.kx)ZJ- 1%01lʬyz"r{Ev\U} ƎnqjE.'P9<}70E(?s^f^5laLUGtoLކJX/&{ז(['@T^ ]BT5*#ϩ8Ъ=b'La q;PHj_YCGى0:# Fy]Ә؆C Ŵ ި=坸8BfF@УgQWDe+}#9ȘuV[3*g-EѬYzO-ͱ5`}Dz&o%2Xfθ,)F= R(OпŒ.z ,ֶ|3:299}) [$,vtYQ?U" },CVp(/1,'0)_[EIP-hP8 <=YcO@!Op9PW >ѣMt޸+iRb!c (w3NQ7&A4J%rp` 5e &0Iw459n=lG~U!ԨAYY)5⽔Ŧ6 `U mmϊ?|{4R$_mzSw~XEá!cQXN&pUV5$I;wC԰W,hԺ-b"$ /Z'CDe5vCkA!p<뎂] u Nb7RHE}uJCʴ 5<#\aJbQq(62I= rvGoQ1 W&P.7ؙdx.s=`炮3W.$J2Lbۘ\z%$n^Tֿ hN8 4( H~EQe)|8[ٔ7Ab[11_VהHqNdyH%z{W]iM ]dzoMD8s3yyl^TBWkej09BRaPS Bi}= ہ1f)a ;* 4芺w'dlNO ɑ뫁1P% R%MPX<SdTvQZaks &ۜVY%I^Oq.w`US\n@-6$T6-46)@r+z\sFuW&47u19_(?+{xKĬd~$RPCHD6r Դ)@$J$~Am-|<]+1(<.$XWg3^/oEr1y4J#P( b*68%g=)k Ĭn=utU5QB Kr!62|[%U3w΃PQ/6x˯:? _&?*$i4S:>+5\X~@AW {#$;eLN5E-W s`SjFiRbc>Gue^@Ty]+l9‘qZ'tِ ӒI섘 rUxL@.Mh=Z9]őx`-gR| N"HJrhJ} DC)BYzZV$}Q2ŪnGs mNjͅɉUW߄f&Ə|`̀yg 딺}LD]72sLhK`vV9y3Mϔ]ED%*5T+:s-A Lk)$iAPCݬzFhxe>$L~3 6MKLgc.N wuڞLc$%z}h`b 7nv Qζ~ | Ak1ZD .Β҄m]dYI.ڕM5i`Ū??syy!NQ30 Yz̬cX3t+ h^ $ mQ_ʅ^ ԥ,b<+YJe?CA9㘾GbGXt-GSj0 Yw#nO0!#s5=J\"7C/>dAiH$~_CvJ<Y7]fh׶Ǥ٪p5җ"ؠF`dtO+ibwmẌ́)^$Acrd۾zWy~b.4dӅNV$bʺr7)W|XN:\!uvs};;\'xl/6j ThLU]y% Bi«M7ȸIwpr%5p#Ĺwh դ YZ