sssd-ldap-2.7.2-1.el8 >  A b2U]Kt5o;S\SÌ a tn⺧"n<8^yK.d^P !SjA=]GIv,ea|seؿH Զ`Gč 9{mJ(aj3䱑l66SKrTaz^3;Ɉ{OZKAoY( !sauhFlj_DИocp~Sg7RV= ʃ,~L'ûzTPs)I F"s_c2-3ɴ]R@|`sS\&YpQOF@f㇛] dEnTȹePԬ_W@\BvNYXC+͈euKSw\q/&Iw;7)ׂGIw5J_,K̼*s Wz"1Yx5O#z?cKVHdռ0 vgV%RUZȿE_dɉP CܗfZYE97/lB†W'7}$siRՇD,jLWj|vm

p??d   6  <BL      X8T// /   ( 8 9<:cJG|H|DI|X|Y|\|]} ^~. bdIeNfQlStluvwxy(Csssd-ldap2.7.21.el8The LDAP back end of the SSSDProvides the LDAP back end that the SSSD can utilize to fetch identity data from and authenticate against an LDAP server.bǼyaarch64-01.mbox.centos.orgfCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64)KF\=T4Ar W@AAA큤bǼbbǼbbǼbbǼ8bǼbb=bǼ'bǼ'bǼ'bǼ'bǼ'bǼ'bǼ'bǼ'bǼ'bǼ'5ae88c6d74499ef1add2d693906122054a4e83de62ef8139d226d3c17974a9cd8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903c4aa9f6b66474928a79f81bd781d80373d011feba129f43688732a7b021abded0fd7f1fc76e4770e06279a7170713c5e08e77125aad59d85988f99026a9267b2243e17f77ba79930286d8ef76e4a56c0afc4f6e4578175d37907c264026cd94c2f6463e05c9cf3513b68e2dafbef8ff6f98b0894a21c058ada49a9153a644cf10c4418bd41bab586620c9b4b89de2925c7d7c985f08057143e276aca507df1116bc62e7ac6c36f29f971d217b8d8f40cbb5035a96513415cfdbe18c6d4448cea99ad80604e90f8b2561754fbd77792c3035a299f8fa7cb96a4b6c6a402c0485872f7504ec87d4052796ef17e26e81e9278418f8e0d2f091a141c71c5d1a8e35ab16f03580095b548f495b73bbcee2f0165ad7df2c46d7fba0b5658cac3ae3162879d8d86bdc392eb8154c409ee4e3c685b0014bb672dd5099e77718c7421975b../../../../usr/lib64/sssd/libsss_ldap.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.2-1.el8.src.rpmlibsss_ldap.so()(64bit)sssd-ldapsssd-ldap(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsssd-krb5-common2.7.2-1.el82.7.2-1.el83.0.4-14.6.0-14.0-15.2-12.7.2-1.el82.7.2-1.el8sssd1.10.0-8.beta24.14.3ba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) esesrurusvsvukuk2.7.2-1.el82.7.2-1.el8 .build-id9bb5a0af168b9c5eee4560b6be31ee924f05bdfclibsss_ldap.sosssd-ldapCOPYINGsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/9b//usr/lib64/sssd//usr/share/licenses//usr/share/licenses/sssd-ldap//usr/share/man/es/man5//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9bb5a0af168b9c5eee4560b6be31ee924f05bdfc, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)(PR#R&RRRRRRRRR R R RR RRRRRR$R'RR RRRRRRRR%R"R RR!RRR+utf-8978090d332fe8ac65f4a54ee2d21fbf5d4438913cb6bce3f2e93a90eeac05d45?7zXZ !#,9] b2u jӫ`(y-qihAO? xJN9g >-mQ`t-KyxrL`  A.D(kDݲX"+Zf2 I&GWɤĚ < q=S6 0p lz Wx.KH r܃c %r<~'5:"Žb׾{|W>c=wkvթIbmчShOG3a`r2v,(KP(0f=AM-J<뵉 8g9Lx_)Ԕ3-Np8.Y"7]ٴa-@Rʖ͟@}2v6|0àT}Z g] k6Ƿէ/NN7XU;O.,tqBvi ˼-FWp2%wX^g"Y,)<-cg!+6D2t*LN<7m{-+}B_|^,-9m!ÃX EʱiڼSD5MNɪQ%cg-1:/Ba!&sQ?bꃷe Px!_f?8`kh6Ar!*o v>(P!?kjc}KZiX{zgo*?\;rl|:/{r?$9"ըRq56Rfrj,͂1@J->5ߨƦq8D1@fd<d  &qx.tcor.9lkF:][X<,;{Z|`*w;Oc_bd~ eq%( 7hM&.?]JST@5BGWٍH{Gqyk~#,?ftiY C77; }Z,l;{`%3[Q T.La[sYc [G,Dq<)zL6YK{aAsک b(/B_dl:?nVkz[Q k&M)"ޭ}$i66sER6 MӻW]ҳXL8k).2Ч6>B]|XCZC'[^Dj/`M_zlVr;gk m&N뫠$S9}"y%BǛ]_gE-%u"`xkڿ]w커4`ᢚATG8M[Fk~(B,gp=qJIgT⍥ .}l\;Ys8(9k8i۩ؕUf"B-\3#qJjߑq. t^"|x .b'XlFSA9."!Qz+Ne^0DKD>?fǼZ_otaLyґ YZiP`" fU [B7:sRRݎxn>;aɵLVM]%MIȹc8-@fEQ7ohQNcS HV=Û`"+D&<IM{g%)4_ȋS 8˃o7. mʿ-caa=}-NBhEevHn)[獞?: G:c+S쯄ua2&I@!jBLK^0XWzˬWշ_"n~:<Td8+nZȿn jvuůsQ HHK00|Ag)ra6L]BW+_2pj=N\R$YB_l@0!d<׆xs CZdɳfҐku=$u '7zd$ת ;"s,4{Zޓ֏CpIH>Qgӹv(:*᪼.3q/0d1>}>Cx WݠT7WݥRAq:mSՌH&t3|Tŝz/!lac-So tBѰZ _@m1rd6on-ff˯}1Gkн*X$"4\Z 't/>jj"5HJ  8tx|x5S)5!KkFk8ЩsjZ6ڎopnJuVBfxv d2KGGtSׄBH<;ށ#<{^K4 q7 C*|'L)8"ld6IֺOHuu` $p%qܯ{BY8T (7 R `3a .Iz_[2v펴7? zHmvAv-]'C9+?78}TmŠ8-Sy#42&  VRT3[R0;@[vHnb0Bm" {y>BXؐ&9]@Yp](V25BB8oRFqɼV)0?ħ6$J-(XKʞgչnUg4_/$LwG,(m/5'G\'/ѤTzy obT;DN_FRڢRFK)6Vr/9fΗ(~ϝ(" Rj3ssz0'Ա53i ƃlK b4+|`( fށÞʫu Đ^6r?z=+HWWG8x.`*V1|lL\4,&;ֻTuXfnAےeRHcĿoR . 8qvfm d:,n[%+Zb2 I'8T8H6p*(qC'qZրL+UMĵb *]SvHXz됯kt֢:)FVG}Ռ8RFήN6ɏ=Q49& N ֊fvKCKźBsʂ{D p@NoW9MLNa\ѸZ7M~a+BU Հ5'leWg(g8{?֝ƴ'Bo'e|wsT*Ě'ӆ-7ե7,g\|F'5vٞ.Dp.0,<]%&I,ȸM:n2&#w< Y4]8. \ sQ%fI ^Lqah3B~ _79Nf(GNˆ [/ɷ~ 1'<5M+$bQ darV THIysB>ood; WQ%{3dW5z/ 4^1JR-Lp>hXլ /CvUL<؈‘8mv]L{~N9;W#\ŃoBlzԉj\kCCƻIwNy/wQ?_E'pL X!R.?^W0*qeB|<|1;k Uzޖ K)ܘsxƳyge<]5F7H2 4lN܇߯QMh6_v ?m@7Xe3?` }{m^# >!UkdU6K4xYJ]"ߧSBai49+/Fr?G_*P%JZT='(b|Q~K9ΌO 䪆QeLCN49zU#3ڌk,-Ly?o wƊYޭuSdBIcAhO9F_Dv^[>fYKEk de)XTwY{͎M6ɻ4m%| K ؙ7O{?֠};u4 ok>]G[!UO+ Zc;kd^)<À@1 KuT[*Dy(H@w!-pH8ZŸ"چ6|RYI08BK%ent5rF37O pv\Ϳkٚz#?=5÷.vjljt %Y4gzܮ`DZ1KlfrqL+INB{)(\q< N;?גn 0pEx}&ɨ7%*UHSY&+LW烒OۃtnhtП,-mO/"!& v%KU$󋷢*dT1 Bl,y$O.T: hRRZG!NwN?`TM^XIYlfc < R r7w,|zjVT2b%y9ЇxYQzX($dΈ.pbv5OP 56raRbt}wq!;B] pv2wDrkh˂:=>|dF,#z 8-nyIV_D+I ?Lޑ͈{yR8ϡlrt"} ՗B _Z.jW X¤.RS([A?"]J}{R?/c x{5z5Y.aW,c{3Ϗ]I6{sh&HX;\sy\_@F1,IftE>:/$LlQy@jw=TԌTs:ʩket4!Q+QX$. ? Zh_ 5`W}%mQ\a@L)J&uhS8/VPzvs޲iQR%}N(_ɼakCh,_Mݱ@*-fkk0/m(am+ݤ-,b2h*ǔ3a#bcU%_RXL%"Vƴ@ROJbEsƴV2qoS5T {kԺ  Xܷ,jAcD̾ƹKmE u$dy]]ό*xJU$7%3AMJ>C] O1E%)EG'pw. //]v%"yC#fLW)pϘB_c fyvB vR y#hu'UmO 紵%ɃB1> 8=I*6:mgeasEs&` *!o)sk%9P?߫be ).o+01OrJY[S1בI/zӨdx/K{-:@9cit$n/QB^B/BfbietKĶVxFp5cqoy8 aS16, \Q,ږ`KL/ #=G,氆ge W]s` ի=:]S7 KI4X؎\Po(R0e䄣kiU__ Za_~Om/4ZTAEP?[.p?Rf|upsΜdDd})f)ʣʷUW~nkV26m'jIF53;S"\';hŲ%Ο"O̧jWYQ谌Kq{:ϖ)->]NhR4t8pmuo^b~F8xKi׿M6և@^ڦ-(zn T B- ꚄJAcoqlVBkSTO㝺[bbgE#=˪/|j{u *ZA;Bա;ż/_0W Ho,d5if!w(p-D;ݢzOaʀӖ5X xaFTy)j[ct!)v\hNh}٢ wP++A!U -l͆D\SZ:Գi@Ee"e)fl)4ũ|m 5*Y*Ι݄j@%M;]2IkTә OZ#8±#"2xz HxTQQgem_lR\1nЋ淚Ǟ8& y%6* DQ@[I6y17F@.w<ߡC23[` ƵAPX 'J:W#S]:XAf3PĺK1%_ڏSHN]6y3H:cboWy7n ml&jkVLƅc? >Eg~Ϡ,_屪WZ}g0gYR-T(>z#亝#J'8 ŁVWN/z rǙۓܫ)y'̡R1h8v| ̀.IQҖt=DP^T#C^+Lc%W Sa4/mD]ّ->gn4 `2 @{m|t8J+e ?u h˜YF)rutZ;(hJ CަעRȝLmq%%Co ynh|Dy%6ohv"|j!ʑQW%} Qz磎)\ XMk*T&4:lfA, :`.Mxh%^Ը[e׻56`^Hқ5[;Uq싍fa}7)7H~m |`jEiSNH[zE:F? ocXf>7?p~n\FH7vYd:3OW5M];)c,&<7ziHx7WߚXƩ2vޱ@ij8/)3<ͺbض8;`8%iQHE_nFh6)/]Q;D a(gT,&ꨘi-;OpgqU"RvZbD~B\Gw g6 э/nl[i+" 5Nw]6}KܳZXQIR)zL#ά4 ;ZyT~L wۖ!&yp4EOH޾:LꉓkH' 8P}ɕOJ?'0kz B)*R S:6(q|_TFC[Qi.hlՆtѣFD{xU[C kG;?)RF])8}Jn7e"`b3ڻb*ߗ4'x$&i%*g}c濕 ʼ %N=XMoe!Dreٯ$)^ _,[$ÀXtYsB{ Mp =ԸXJ~qҳ);P!q}]ý_&ڹ%:=d]e})@v_zww8fkHc1LgFOV^n#kJ4HrfJD|t0d~Vy!?' 8`L_`4x{J ;:Gfj=I$` ښ`^GYe zABZk&u!N7)88gPPjh֐ ^Z|1N]v%>UFЙc"@#ZzHc8SxuhQƶfiC!/>26ߐNU˩W=_ICßwm#.-VC'T%-j$]:{H"{ !k2R! Tv引iy+W*O"Lҧw_:2eŐ P& [mO=r mtAWh7vU gPҷ?8(>sH'a|{.?6Gͣu^ B F58 r^8~ޏY~nߘcϛ՝@w oIJA{$mT: -މG*+OK9x/XNiT2*׸;.R1^2j #X*"4=2>)9`3'2ٻ_ N(Yi@[@H -p)4;^;jY kca_S-@R|:7~.Mvqk?w4K]mw>c8&Hȅz_bka mޢd #E&?S!S|P&Y PX3`~2Trh0}9B]]o(O6Q 'gFȫWRw>kɕ]iOI\4L6wp*IǡMY9rsj2hq|dߞؤJCVQ!A9dy=bY:PdCztVnLMhwTyMKKWhLHL \q+׼F.7ѵ;7': `n:3'Ł5`xO 12{Z,V 0hT#hm{E1sq]ͻ2`Y|i/vˆ :ۛ- NJchsTKۍup1A"@QbAHϝeFpBEVQTJ Lj(SF ٧жiEAk$`C8rlXc>V(ldyk_rC-٩خ%B& N]Q8Q9(w{Tm4 L;viDI؟5{CZ˜PQI0?oPk\\͗  ܅m&agbݣ\eQ!t0 dw7s%KJrjAWCk1P))u3 j4erj)j!R@Od0hZXUYOBB祼#a cKG""?F R-WofG<#r$rx)jnEF=Yǂ,9qo#IzV@ Tt-{~oۛa뮛 ^[\̓|GP[faȖ~? ΈO|73:T2'gTg9.۲#IpI5F_ !WV*49*VFo$R2dtIx,bu%c2 W*dX8oT.w.@rܞ8UU$,@y~5=&M9,k ־dm[IäGȸ4b,!/Bс.K$N&=:YRX?[-8B#붅Rc(u>s,PY7e1IHJ"v&Db5s7) 5KY˿f:y[>fŁt&T2V CVybA6!e{t+ l,_Q:j}&(ΟQR?7d~$O;jW&Yu22Bi36XE5Cr VM[QLRiZ:Gv :thAb(EF=|"=2j?z4cZ"radL^?-lyB~76(ź+~Qqgwm{\k.a*SN&^ қt6>`A#9G OĮ <+ˣ;wm}5n_BL{I=# x;Ddy%Gl<];eH4=Ҕ Zc5a(ʹk #"JYBp^aƣ25?! toJL=ydˁ{2DAVwjݣ -Ke0:= >-;Mo#B7Kro0;|Xݢ*.CwgwLD0"M띦]t}`d+TzE[Ԟs5eOr3MpG-sd6wzIA$tXH<ˍF0h bGqZM3%MXу* +  ֙U+$ „Lsf0o . ; pqi~# 9k>&UmX د;oDl+?룾!Zd!7L夻sчeGtM Կ#exf5V}w2ѓnaש#)/s_j|{`N%$m{wG[*NK(IsC ĺ܃UHiȘ|P^B5b،gj _ɏDžic=O7eTo%5@kG_R>b0)fGDA&{D "F=TA'W pb23j 0WS|ўJt"xEJJ~0A9#D}8zZu\d~=pmrl\d81i!P Dx@̮QSWr!..rn;u~x`M+Zk Kuc~DgN#,d'A1t=%:׉yx-6CxǼ1>vxYH9fo<-q#^ GrˊojN5uH ߲Ӣ( RAL  ܓ;NU]1zD3_bCch2gX >h ]k;^ϛX¿a0QHmX'2Ii׾ѬijV^";:WxLɏ kۇ`ŴE:<*LzV_9~QJo~YM>=䴴g^$sʎT2%JqmN2&saN3gׅp@ےu@;-Jn# o:z8j&-6o] O_ nGK~t{LQMYLcn ca%;8h\C%s^@e;*}_^Eуw6bLߚ5BN2I8;UV^ܩ5A V?=RHz+gklGoH&[(M8Aݯ PAI;bQE7~;\*;P *-{p8!o:lPmR@{8HXy| A]]HzBj>D \WQTͩ'6"-97Ur?Ҕ+t`~Yx+(c]ckIn-JcD3Ձ~CہD{g3w8jSCW>+1j.KeD_"L{bk]=2!X K}!IΛ]T:O:n, rCMw'pĉd<?ۂ9j[6ؘPA%2hy#4?,7G@Ӕ$# 02kn/{$* ~vbTCzi1pdcӉ:҇c .@PAD TTиX,2/g *ZLe P7P1&4ȽԖ skruKy/=+GG?TN~T uAwy@(S 3*G(،ƪIt!4N﬍!8irĀ9aQo>p*eyE&72o"nh 2\9Le+a]O1װ4uŃ/iIvqȠCYf8\[oĉ؈懸d_z ZH?ࣉ9xAb`;:/ShlȬD jjLꋣq֞h,ބb0|Q|%f`>BKlta)wAZR@l,p)P:ck&5!YaM ͇\Iri̳~=@# ~8q-'1GϒȏBM}thVXSb-5lKgo̿#xQL @j6'z]!MCgNpg.ʚ (L6dL$'AR@z <_`oh7EOHS <H404!`X Lp5[ 0/oRKQds9,ٹr_`~;\ db/ 2-Bg}Ro5?ٯxLTURbLe>#Dz=i*mv+GN|&&orojM5?a._&`J- @_gKB͂'*%A%Җ9A8d1ow?rX5Q`,W]f ̓aAqIy~Z44hR JR%*mFBӇ`GPkF5J'`F ogiq+@Y\ѠtRd E kP0II0y5,8_ܻ䊮ɛ{$Ee0Tsd;Tm{D1;:{MrD DFyP(0R`<_ΏKp.؍]h_${wU6lEDMBCT#P(vXWj1mxOQe k'Evؼſg9?z7@8@d`_KhZ~gvK# ;"%V K򓃺VR5wi/3c3 3ڹ*gP(Yܫ CF~)-Y2q %FA}㌾PG3rІM&3G;VWZ?| o(` ᠰsf: ]`wXJOEh6,j%qiI Ɠ|Y]H-YR1bCȡ1 K<N'$ѕg^n!(_rId!ʰek.^,Ex&h(/o >]$Qcw헴gV^*XJІaOqp}#QMW6DK:W -Bjo>8P/b:# cTs^B @z8-,TbE=IS}c˜s#LA |,j ɣGjZb~ Tr#6$"^Ȗ2i6 > `ޒGK S,h0+v itv2qY*yDmWgw+5&E#0|_ #bT?4I&,Ux@MceF}֐ٔ}an"YcՇ;߶ `NͿڌtpw\p+Q "dz~K7Q.d3)$$Zi(ZOG,ar.8؆ P%u5ޑ%%7پ.'PD#=@sKmYɄHyUT<ܦ [q6g ĩN2+!ŧ䲆,wpw=`̚ g8]r&GעFx츍O^~dD8 l33P:9~ILmE]MS{3L}o'ca'̓\q|^%뒴%M/ME/tSUoCJCD)^@zA> gt/5T[Ev兴 [ ҘU ِ-$CS!I4ワ7P_ 0 _Dh>p^^m^Kwx gld*<lm)I;3 ߇ewnvіʒ*keOwCᝑ~_UkK}{`fBqdE&8Lh%aHǡ'44G BVU.%`~@`0(O-yl/ 1_3܋Ip.|[J}åQR5 ; J6> 8-j4R7 7ʺqiJ(\ !Rތ 뒰H4fIض.?1ne:HA~~ mݏeo=@nϲ8Z,f:ZO KX}rn)!$^pg'+&FG )c.èeI{?x8L'OGJwKYt& #YofU/`3-%E7(7#iEmLIobnc~'*]y-ܜH:5g%BK ki**{o=;4F $6)^r6UmxSupjtaYG/WEHN$ӓz c1I7[dkk,*HP',Kg.'Ww,̼Ot$mq% 9|Tɔi[ 2= _nym$$ 'o08Ux"WeqiKF;!ǦWuvgn/ REʂ)M.['`/;ijH0nس49KW TKRMњ0UY%tǿ, λM& [uG]gnB-|&3:Jc}2;@Kۗn7NdS5i- <&$nV!=S;5-+r7Fzd0^ aw(2vP9HcL{l A)jcP"na#JǸFX5?R)`BM>X|:C;P_i݋=9P8b/H^ ZeDMNJ̖J+f\ej=|V_ec fpL/-A1.Uv xP+€᮳5RVKp"'VBhRjc/˨>I^$̒H[MjU ֤*((Pzbsy__֖[{%b] s٪ @ƹʌ_w_;Q$yRW;E︦~Ծ3q\ߋ&:>6F>Ta3SGH :ɰ\?Ҏ/Cf\| E`+z}_.h1j+vS$ ).j;(PG!s8y+//r`qDك棺>2d+,=7-żRpjrB0"s*` J-bJܩX?o urdXs|j'y[ۥS'^)u˦ydu?FB. 5H)$7o)BS$+.=l[LT?eoov@ANV.LYf1VdSܠ%jt}䙋ݪY'=yhlm 0"V?K y]ZAU!):tVZ y7Α߾ ™aЋ6X0{npתvq끓;-փ I#4TZwS-\ bnWN/4^X'jk *{] 1Y 1+/yJ f67Cf:|w/tDF8.&v\1֠ł-i8&n}ꨛldJU6oPMk  Ődb<'9;H1 &h#PO*bi1Βӛ Yr:K9ԍEͳBw{cv-J;M:/tj<|.>8^b2:/LM5j쩢kEDk?۳ P=7\I`,m?9ըq!o(8Ԇ774r~Eﴇ7,!i! @ iE[r8L'p "RMAPwL 'pj~{RJgX$L-jME OA/<8T`qy+y>)f4λj7_G+w'-Y ⺃Աy)).Վr7-umǶw_;39R'1*Ax eD CRö;5BJd^J}ڞJGq=)úV,KDgy{= (#҈9"u|3 UE-ZD <Ύ8tGjvÃ`в;\ۖûNFEV<4GXaE@EtENyzqXcW?gS'@b2Iv 1͖irNE+.pUȈVTEHԞ͢2/2 o I1P|/ m\S5'gQ7kLeۋ^1^jIU췘^79Br  rW:ݓۿ*0~~j +|ZG%A~ΜqK#-RJ},-s:'Xsl V1 ;4@'M [L}~12sKTzS3= ۙCH-m @&K"'{aJ[NMدJ{6uT#@ ѻ- j\ EDi3b^]>wYg(>nz!dC=Ex}|֚2nnI9ٮY Yɲn:E=^R΃y*Ȩ$RA~q]Ь4Y4ڧA-deRY'*_1%yi2A3^NK7bl8٬  t`xlt.})U08v>p%Q$ @E x(R'ڪ ُVbtLGr2t&W%W"! z]z~hC eMMS'o-@A #Je5Jlxo HXYL% f -{z7˪φ-ڙzD:V+h*+g0Gb >:Yq-2![`^ZtuW*q=y/~wD]:^5t?si}"y }>Ykx9n sSaoiMəz (.QDu$w dSL̰22q%ΗX_ɕO4N!SnKK]}90cEp0$)t | Fk.К06i:eܼLe7j;z; o @%hk) 0'#¡X} 9;u-`>;R1S[|,኉ *TDu埪qg@ N]8yJP{WS^E9А\3bS͈@^]Jqϫ+#<*9N*kwHh-!XPY ԂjvzJ.喝׋^f`). pt@=%f{=Hi: O8O%Gl/AXi9.\-edlG); Fj ȸK";tNYX<NvOڬsjuwki ANW} <7ӞL"aQ aDc BjgA;R\?i\,9OZ;:U=GF[^Jv޵7J (+OZ=`E{\,ce>ҷhbbpCc*ף@\2;5%;Y-QH UG:) Lȏ?W)-#D"cwUȩgkChEum#%A=ktoW߰auKJ'umY(`1ul:+&T1`I]'; Oxȁb/S,r /.#BXHt+s9Ѵ4@XuZ"lgZ`8 "[Cuz=oB !RUHR-%_Eq:Uۏrc2r'X#X {\앒>Cg#;w%'ja)"g4yb3R2(\_?- eD"i(\\P K_%O(j|Ψa T3 jp 4W) 8&7HTYl{{^ZM$'%اCfqvN~\Nv9.pZ׃8gݒeZ-/O%}Y4%Ə DׅCQ fdF"@,9pc>l^Su;%%I8z!ݣ5(&Y Ȳ* ;5WPlu#riN8>UOݨ]uBB.P7 F ,-q)RGq!&7Ȟo$v,C~qiis2f+aqtFiԾl2ZDy ^@o,{@ODFF3+V{czpTu/S'|s;%@đ9V Sx F/)jJ^ 1c^mr]K5|4*ݺ)eԙuj :+su 2? )68Ixp'*,uq6lo`F9vL~e*면r(.8ḁX9zZe2R`ME3cGvia(edxp1͎eo)0wC\6R, '{2?P LƶltzdExN@KzR5[:n1 7b":+&`4}PU":Tb {i+Z_] јxҖvC PɂX6g@AҒq!ck,-aԟkI3i;B7ȇ?CZ z@"-:+2`8,uϑ.}hT7WpNQ5M`?'{ZrdjqkbH k"Tu:s9kĔc% Y 6Н6/(nvE ^C gF#y4W'A,ħsh1|ey`ݥ_3>'ISoxi SkW1#cw &=#PSܽm)mPqE@gyw ̛vscÃ:6ͮ#e2>s 6VZiym/;/Mt3p$lkk}?y8K5w2@j`YTn3Mj0{Ā'<YSeάh er @7wϬ |!k$i2~5WƍKdLw7#+ڲ.tl%ָV'|C?NyW!8 sǶ+pfCǡ9VubtY;Za!!n—o%]oc> &ZyMLǎԧPo]m۪r} B%MkQjӸ?Cq/q*yِ D݊tys0Ϩ-z0Up2NkwZ+w%:A*z˄{ZLrշv4Qm#`s~{{Z(b20Süä V3l1ެcko]g2?[ *T2bdJ/Z [#[[n0gU43,Đ_+i]>g@g,!mʰk*OdeqڎGs^q͐J#7ƫ>IffO-ߨBjx?0 < ItACڶy 5rW Ihw."o Ƚ%}תvR񔷍{ \':Ȗ?HBl( 1uO@d*>:pc|۴pm~,C4?OIԋ)d y؀`̄ &?)ԘL|3ԭ)MHj!\aMN\+YaYܱGpP`WD 4Fξ7ݾkJ zR [N-afNK;jp=J>U[X(.~ I ?NHɤg#I䷣B%,]ӽ׵a| L壤 mQ F~jlβ JLc$BPj-Y$&Ϟ EqpR#ď3_2wk&Gkm@Cr[s9!w͊v bH&&/j~Hh b]qsq32 0ݽ; DZ Gm{)$=aA>"۶W;*E)Rq.&c9쿑zFʧ.WJ*'8m+0RA ED$ՈIt 7J>Wc`C _<(pT(z?$EspZJ\4ۗ -bM$'5{la5hиK1^wTFG}o j$/(gFE GtM^R RyTv$Mb;Hz\Z^[/kmJqФBa0} Jś;Lz$:o>nTX/+ŭsldgK9UW"EѦ- ; DԾp&nѐQ77MwR$ɟgm+>B=; 8=+Z '6Bny5׌ޘFN..1@Z}Vx:H/W:03Ny=qr(,$ją3i+mOeCȃ1P\\Kl% ܗrSlx t6@25w\,dJt=u,J`j>̹UkPn}a|6VUm*!>kAMmV2:9Ka)Fq /Vֿ+Ǫ嗨'?⋍^UW`SWilN`M^d2J*9} j_IƽXKKO $ sʻGA4Hɵ,pmPk{+vXFO_2@  %?'#:Tiz'̱87¹"#VٜU\%Fٲ DJ.Zmf@[e:Hb{#E jBSZZMtvpj43W7Ǩ!\9iY=:O҂f, z$t~0UJQuwƁ@,#w ܼ^UQMAm6<74G"hn\B6uIۂÑgAw+R7D,w4ƿ*>!2oA_ׅ\q "`\#8$;g0*Ftϑ[\ګtgp޸p ]qLSgv9=JkI *IAR3Z|̒zL q\a\ws\>12gLUiLB.2,e;㰒 1]ԡV7{fhkX;SKt]oKlYMG N7E8;;v$cg)uˋu{Jʟ?ԎQrһ%9Ig%%[mTTH+~r&/iJ>B*UѶ0lz%1aJ^w$(8xC(X$p˛QPO7vo"_sWwKHD~C|׶IvaH\b?*yb l@{6L'-Wnt@?j%Ʒ3~@GToZ{Ĩfşk>Zpe7L_0s( 界T䎎RG7A)#iAhN{6- s7>"!3+[prm\Fbh{hJjR6K+҇7~B˩ᷙ]ўw_mTf4(F}aGbB_ GC._;떊MRCz&Z*"xz( 2=בּ{/J丒+\{eFR$`?_Sf1 ^5+Ll\I@d3:OmCqpfB&<0bYd,:}$AĻfzvHV!W4' nfoq-1 xOՑJVD`RK>§I':2BƼ6'z*"C:HK~u^G1հ)J:-醳dJcLLcr5|9}T8jţi7 v\O!{&xsnIKTrG.cd{q@6E-Xe Bs);ũz?OG#/ ۉ1^}emch?Ar>PӇHVԠ1n][5ND(pp@7;z7;R:H/ |\31d& lgZa3<(:4x'rW"H2slOMtg.x9 vmc#er\pNm mb+^9_>odžn8:Eɡai4)u)?u{܁pAͷ.n\1?5d֢k̝d7NlDy]%,, 4,ը$ :S=Q jz.q$%a55,=/&#=%!]0^8׵CFF~ˡckcW6e xnj&9I;IԫN %D(ߍ2tɎ^bUUxj8cRX8#A'讷#SwYU._:W20 j0@k(zuVnt˜3>oD='nXHۺ~.K@[ĝg,7cJ#Zl++?@?xF1U@/4l }h3-De΅qa(c;a"෬ɿ4?1.dF\QTb(4`_ D7d"K O-1s<~~F&3K+ 2\Y w)kQ30bEͶ35*_Miv*Fx֑G5A5ɧT_b4r0i4Ϙ ipd R:4թ&L\TC\/+dLZG5vWqV믫l`Kr^b$mC&JaT,w<LZ1ݸs&IhȤ3JFy1b'QNc4As`PGs%MY+)h(9{&#ᘬwB>aa`.&XRt)g NN3VY}ZVHٝňv,Hެ FY3x`EМ()}=&0:.䂋l@.نC Jaik^mR!{gG .P$n3+ Asߒ0sڧHtq5o+Tv#HU "RE/-`n"\Sg"mOR^!ў/n}''@5b$Tm&kf[v9y\9eLnq5kT?~4me׆MK[Pdg G\턹 uS/9eY`G*c (-r3:7Q=}:(=Fp|g׋K-dݳLMdQNX^@VNW*wgiSn8%i~{#me`!BdoOt^[8~b,c\'߾ak /lr9Bg%XCZb3/ϡ䛳(4TDntR\DŽ0sG{ WjYNFJTaql4 !y-q%R%ĠZaPXa1JCC*\ u%1)96g "їmAS>Ҿ>BX1dʐ(Ʌ4FI`V+=JQ?uݱ Sf@~OF=C:IwCP6l{ak.uda!i7D.cМ: }Cwb;D 7-X]uG Y#2i#]S=]1gN1&nNj(c%k|u!o(/rsv˝axaY0d:ߡ[@I8+ %S1-'Jc*/ IcK/1@ m^ZH(@!MxV%\/hT I67[A ekӤe$W1vŭ@kX-}PE Q+ӡmr$:<9FÛ % H1[b嵯7F]Hp1x%X_m@Ʉ iZaZjQ)Wb옊`XFm"gNn N(Rl>L5%_\vsB|f6Ѧ+UnB+ܫ+L[kEPгdUG}N|:|aWu9j"ji[ƚɈiՉxH[Lsm )3k&6營oM꽵`U?qg7PwUfP"xdgs =mm+/7O[ M,})ſXE5%m֙=fEr:cHȰqi9P5$gy`8w wW??(H1:DS[MXkjKDB 6pTXePOߵKU. ]s]rk/}t/G`Eg5h^ُ~S@\ G@c*c4 <:@v)8RG:;Wid$ǂR6cר kyyl1{dB˓0A7ӆCVs=mJU:G%;;$P`s/kxfmY+l }xݘ԰OJ;7Gpi`y'CeKmMㇺe\ gt4|,T/P 5,Ox]?}oMe 7,U6gNbeې!9 DX'JN?`4yl.PXwy5h:` ޙ'a6tsFdeL{DYwPja0igodpˑP$Nsp=}v^Vo٠|To\u+R J22I2T Jp:j ̘0*ҒFN"&[~苁a#E4c iRibĠ<%:O2}r*8|gWNFM9utXh8JbZ)6YܻBplEי qh`6\.aן;L}xkܾ5xjA9 SE:y$2re幧C)>vj rH&`s71#vrTJ|n`NECExD_.ԣy5 > V<\K?YtDzS5p-5SBY4ƫj$*UJl]@>5gK 0auS":QJ^>9|ƕRxS?Pn8acjP$+dvNp7UHoaVa"Z0:.կ5 qTgޜEL=n b9oBp`V%גDp|H:3Tڕ{{&&K\l~% tṴfDcG0EGG+Sn#_4[8_󀬊WwU32ɰPV<MQjLRLK x x4IPG?PܚFr uˑXc-Sށ=~}DX ڮg MP Lb"CŘ&%zXT:?FJVu~ɟs"$K\y85fΞf)u])fxt+SVvŸpCߩ 2,7nW[~E+ϱKqn09 V[ LץWeE~Vޜذ>@Jj5j +\ ⢗f:]~y Q-ۆX,[BKZX?!3Nb($ٗȜ |e-}6͔4.Ea\, "+w'5AKh5)q )`h,S{s IcFŲƑ/wzAwqge/`"+T "ZƉZ2倷S*CrO`m֗iӎ853W` =F N8;DdR> HWo4M,aG=tU{N㫒{}D';Qލ^gʩ`U#ݝru"elAaN\ l|ߟw#>{@) "MP{&<_E *ZQ Srՠ%2L4i!ݥ|k>ز93tW$kIz(Py~_ @Ҙq[:#jlO 5h@gr+H` D ݡ[ؔ<έ۟[{kK, ~'?FZ4fs)j>FoA7YcB2Bn!JgʨFcR@tQanSrZE{V KRc͂Weٮ}h SUwJi-滅^KRۙ:+ /Vs(=X\}h9ݳ>2dl%Td7st' 5Zҿu4m5(v@Ra#MmaLgFܗ2^n#1BX|8uIr{Z8 9}lm & :y,7a1O v6!?q6ۈ\-QwX-V?iu>@~ɜ~)D#087`Lj&Jh1,([ '; ˮH*i43l3 d6n$yJ= IF䕏!+lry*>ٛ^H}P!z z7q} N#s i1H\gLGW3^qda+2&[ej'b ?6ԓ4Uݏ|lSKРx>/?˖#rF*%|[hvfʙT&zvu 35 Tʄ˒";c}ԎV~]aXqh$- 0DtChZ&PEN_E.?C˰  5 v>*k 99%*1d:FInN:>{KdY!֐sdn]&!볒xY[+G!nZSE]Tk?Ϭ?8K&nՌ>H?sj}pyh,,yPDٹX(=#{l'Tg8!69VsO%-N}0D /ɥXRs\`IδkAn4IګStdVAQ7{ܿn*G! }jo$~Qjb(~ 9!s@O 8% 87zsҞU:x6GX!phYED{GՍ,^J'*el޽KPA(sΞ%ͤudxvڡ|MS_|K)=׮.=&Mmŷu`+\pf7;E\%(ai}'󞶟֍qAB]0[>2tp r=(P;GYMQpv>ۋ:{"Eɼ:/`H]>8(ubcuO6Y ˽~CjnyWHe\{9gAlGu1c&B1(M!@{ JW|~YQ>0Qbb7M;Z۱ZS⼶\ m .z+/L~RpqռqLjzdF]HKB71xGFޥ.?ZHغk?69ھJ<_؇; ]o4|88K bvsC &̨;F8/J²}aU6Q$s\bMK0}9S )V9>+]_4%AJcƾő I~fto߱| NxѺ:>-+VF$* }AJFA[yVU!%A .q%]4=޹[1Z (fmHUA(02߁.uP;}}dTNī̜gbTYxE'Li+J_)?ekӓ 7`o{@Y99R=Ǽ#1uCn)dҚn˹NJ`5G;821T`@^ {dlwW8HQ&ҷVTpQ=bcI1*MtӬŤ~nt~cIt\gO.mKnq+-q|x*n"{CJP `9};ي{] ţΙP :F?5-|kE2~ocW|ےQ~UyQ7`5դ֟aoxǻ\J\:?߰h%}N7L8XۢJfE?e2!>9@_L1hW cɬ!30Ya6~ G wPSB})-ZxHwEZ=.{X[6{!˞OH >":ׯT S, 9ct0LǡJsA.6hX@M~!szk'?Xb-VMй> V%"TqJ$krlt?2|4Gu=Ս\0\zWr5[ri‘2t~&yQT9?"'ڕ'g%@r{|تD$9"&$[T$ PA`4 ѸAgs2C\bfbh8q}Yl HFw% KZUz9B9جLFn/GGw"j\Dž i45דNG?م0JwJĥL!חe+tRx57INgJP9=!7; fY6ݟjkɨH<-M';̹-ټ;<[2 X**&%&}[f~ E^5կdLؐRF&w& ~@~񼒈.UUp~Da1} id3u3 {wAlpUgUT)vr7'Q' 迓u/ Fdس'FˬzH0Bʀ<|&ۭ>#u]s 9 N,.d%@|y!'Ce%Rt'T0'!m5}"R36C=+1X8e\[w8@2[U͢~+j07kI^rW%[7 +z\=Ez^7;itdzx}ӗ(;yyEM:\P(knnӃRy.uI%ڿ0ܟΖ\SH<u s7:7Π5%u~>v_bW!CqFl%c4%&@OV5ŷi ùk^WbWdGOG% -QR5V,mE\,<p21l |R^c#۴J?Z- 8j*JY>Mλfa3j<\AZW'ꪺ3{ /~Պ/SL$2 uCj-zȵSA! wv7ra}_?# %8 AL{֦v\/"Kz0)n̕SL%%0i$ݨP);"4ϠajE n¸2n#Vµ~)pb}by0VG_t*6%2,2F)Y,tې?;8q_@mW ;߷}}$#A&4[&#yG/ 5r2Ow6)%^ۆs\ 6h28j֣'NWWUئ4jx{hMQf4n_Ȱ|ꈫ$6o!I,|l$QW"] /,Zac']z4{J ~pkAL ԣl̜6wr0鄠lC@؏տ{pϲ Olnu`|E->P=!=ڰ YEWޮK$Fu#KіdxE'B<8(nB%?Cqk>M>m܏ ֛dK;]xF (4],>s, 3rZ?4o*8#uט8⣫:#MÃQ}CyG\) 'JM$?DD $$X$RTeV]T'eW`dM+rzH߷1{%rLzRY[ QP΄t, i%Ɗ^e5x0o,gҳ e Yvj}cGH!%y]z䝃.L; TSdN\uVs} P6xdV |ċkbTR!!,%2hw25GA7BvBCV(mΦ>;0H'yȗ <6zBXxHL/jMu=^RVܽOW~n>mLɢ# Wg8wt#,z/k=-c0?ZX\2'<=o%? ~ 6n.GJi'@_bHRSU ݚۭx0\x4@qy@C4m|$0E ڈ fߏQA WT_a|,>RY$PG:42_@M]YbeXc>}> SU`Vys%?mPecVM{b!QԄ7NbMiT#t,:bD,(oYloDd0eV}|,c9xoZ|D+ w~EW*U4 /5D幐XxyM/0y^k#ʉfW}y1,j8$(s<Ԝ]Ԥ o`!n p"q\l0_Z'usvH} AoPYm3}/^֎Y͐.Wv8q&|=uWiw@ ~[+pYY&[pNYGmnzS3CtJJ_^-C }!L8'J ךlkFdvd@*% "3-TRL gW޽%[OY!/WQ"Y0=#mo1>BB.TDlz'2iV'='aX(&kGvF9W8MHl/UOa>qJ_<.UQCgIRᄊ$e61mޓo&@:`'lBX5n w7/Rm\vq/;]<&pT޿h@B'E7qu!YkMWP)X9ehBhZ[wxa*xT'фpOh sP?]Mưpjp# ĵHKUd)R!S⑛6)A!X`MtM>"|vY@:a(ypd.J b\>~ h+/vNwRS֣Xk`2`nyb~"R 4ͪSE'xrD%$Sv(Y_/{~*ʪc 60f"<\,7kg梈C*`!Ȯ,ܱ.rޙ<%8Pq;èZnXqZ0|y F1iU]V]t?ݤ|Q %<Gz Oz|V]Q* *Qf,|]/T \>Lp46RI5.hP([l8SS)dJP^&v>6X%bZm Y=\=e+|c%MDTR^"U,fzlURĕ~ص*+,JܯX΢ S ')EKw JÌh 94SK9_CMIil>l[E}dIB7ɧ0|*΁4ͤj(/teTY.A$vQ-&4 ,=B޺M5~s׵33Ie2Sө׋QbIǦ>sQQhtomy35G ((i4>X-XW1 KuBR AZiBw<&mtKH,:D'`3?l;CbJzMDy.dr$VKBsǧJ+/SֺaF@;.FVBT DrM~Fs!BW~FSOr-J\=b5\sǹi?Sz(~BD[Ƃy1:Zc0;ny4($ϲ+Õhw!  <$Ah >1aUoa2ikO#\ږж4a{G]jg7QLKOx3O@^eR[JIk֦4mQӘ.9R#y=P1_70h?M2zۋ8 (9C?0LT.T%dnD'bv[4]%BTfbUV8z_9-<ַ8XXoXk-i { X' KX~ʝgW^B<4\;r=wemFw5.C>U`jʨӉxi.yFI&S&H\N؀Ͽikm~s5j~?4b;#G*ZѲxtӭ}[tfW,kNI9@_ʔŦ,'`z"N =˽kgf=h` ڨ94"µnuKqn*O/6$S5ߞ%x*b<#5yZ 5rOD5=Sh#`oZmu -$ +%w8Mml2RVYJ^h~\lz_ӋPKGr`1wsG aփQ<5e++^Ip6+E, |F" B ߢEkn-KK`tb059g#`1}˴&Be4xgjCW,/m6073Alx0%շP0T9@x r!M o ?gIߢ UX tmib_9!8=W\Btio6!u4[gOk4<Wj/x33͂(V9:KQHtU[9 _  Ö㶭1jro_ar륃@03s#C#aE"l=Hw%Jҽ,97]r@/j3D׋ *Y~`{5Vvm8кԓ-+;0Qm'(VvBO:!:Лޱ 8sU9j/!:H^8n <|é[H Kw8l7ʐ}b$ 5p>4&~K2؀J|ff4XqB.'KX<:KߢEpcqc-5dy8,3(Rn`ȓJܱ{gBoTfx+_[L졝1Z?a+-}rgSXaB(?uG v[IswP`yWcm#֜rzZJ G)+se578?Ti.O Axx0Hϡ4Kɢj+ 6\YgΞt6#0K!ӶNV & (#];%0΄0mgl 1GAT;aW_N1m}0)>}}bAhC%t&i|rݶ` +eRݥJF˟> 8]*і2 [o^12f$e)B&(JMT`,bj:gi y%|7ϑ<&5bˠ!4]IߠSNLE%qc|e3kQvH/eY $@dJ]); Y=ac88#:ϲ'j ԉ?dc/Yz{ҎC L?tqȅ8`` c.t,QXmf[06L%-7YgW>8Hco^@seCST:g u, ڛ.Vp95O7g|bN[s^s{:v*rG.n c+(<潮OG_1bC{L :h~XRhXa5a&#v"hJbT U|OmvteV6U#z w?MW]rW1,USI? ̒($x/ է_Mŝ-ѻ ! %E+r`2mNV^E=1CFJԱ}ΆfL;¨f,]8C(Ik˖"9M1W/ $w/pE+$D'9)yTóP(Ō\V}T|dfGR?HkTԉN|!o悓_tȀ;T $3G$oz 7#+íóa[FW qެ2iE=+6%¡7+$`e(M؃G&T5z&ʌ|ܓEښ-cT$yMo#|I3{7DSm"^ZѴ; ֧r\ <LB E9\f=Ά3)NI^M E6Xq |^|Oi#7=Q%i:F!=w?ѪB# .%A,l?9=14&߽Kf'3J 4%1eV<țDCe9ȷWȈ+˻]LMf1~ӗ y.!5Hkmsڵ:_RȇK.lxMMnՋHb:df;F0@%}8& R_ʕ>UFR r&AfGMv&~V>wd&9u]lFhǞT! Y4䯟s5SFrf:m:VIN-ikx>*8##\o2>ZVފ<n avf \p݃~]Ke9T_Hf-]G@.qp~D`.{w`QNXX9%Gfd{oziz/E]Ms~![ίֱ>g'7zrA6g&)EEҔҰ%Y2 o2 X)/QePʡ3K$4& a"HCGʚY^Emb+)U1MtM 6ucH/6&6?DU9u.JW4IiaqmetxOQ 8gpuR.H\ Z?V2g m["iR,jйP@~9>x*frav"eeqB<D$E^/2~AD`/ +GrB mD&H]ޙfFY[ȸ BsϊrWxU dlTL8ǧ{Hj]VKXiSc<#j_Λ_ĮHSn̡NWɳVG y\|$8ӕF1;4g_+*3--ejy`@LwKw)>0?LE)­kMFcd嵒Fq@N"cKaXiUs(Rx*u)?cscd(doK?N~ٯ(|#-<m] Hajfӆ fa6N1l'BTy[br ~8M9jPs[Dx Ω:>ġ&?P7db2;D3^͎ iRz~-Պ3S5v#_E}:e)R6-43c1H?ŭֱԊc.Hm$o@j~(9cc*uD0Q=էCVYEl0/Y/iQy  񱒴8Z{fv<0} aĦc 炈WBx}0 ՞3KF s9ts.nU k,2 "[% g0*JhVmDOX4Patp"*kşxt]'=DǠ>B8x0jeJ5 Qya[ ޹ach4KB.I̹y>ySzHI/Ǫ_&,._0 3铈8)@p!C\C* z%F8Rq?U(yA%8è:B }#M^[R`$UtG 5|Hj]Sf(zu葉o\Npݘϛ:v_3'5ܻ@!<(nE''vL4?~ #`&3qD7e#ǐ܃R_>->8Mݯ{0`Rq72"ʛwy"_bIeB 4`[HVAY(J]r1&Nhgla ?Jˉ^b ~|ݚb^+=+ u}e6I9~pdŊ^Ho$ZYկOR֏HQNRICGE>J)-BbͥΟn"0$KUCd>\{41~֩]_ Ŝ+B P θU!q0[FT#C9퓕OR=Po`N\HnAf6k޿(#kՔt_ 9x۫T[Q_IiCMCz;e/wM/t#EVmX3K9oxE!,> a'>=ғ΅1$F_i: uVlkw&AoUjy‹*7-)UC9ѦyHGAӢB;re[`XwN,g~ C`TEЁb'L%3}tmYkY@#7o OO>LL 3fBUa `۰mrTGGKQ_"!ChV}7GyXd6w_ fIvhN#ϫ@sQ-ד\4֥UA4]r.,p<@'Wi]mFwkUU0`r3c,jי9/R "~9AÏb+,[E~(vp}=`ZkfNx>듾HӶO[Rt)!q:$`14o?RV'AF\m3=)bR+-FE+GG%хr2xx*rVw:k=E3`sOusQeT~8%3xAZĐ]IE0ĸM!xJDs-W"xA(_gHLh5z+t:TK͂/7Z8@)/zu ,痹.> M؅Ϩ&eM=m%E͖{3*,=xjϙ`)HO--.V9o؇7\6Ks:hjOtM`s8o//Iݱk|ьl*Y51z8hd^9"nA?޶gSÁ}vϟ|0{2+Ƚ*WĔCZ!#9ɝ4xPz%eTۑďA~_J,Z&m։G,%Fƭ4vQئgDӬj˔5gQaWޓ[ޕ &VN;)H8WNu]Vi 8*U{ Pydyw^Oy߃ƵL"PA4AltQņ,).ʏ\n7Ow˱f^B -}iJ<JhцZh,7ӅH/yRn]ݛ}OEAf+CDFnf/H"Ohi6\ ۈ× Vae81$c!v7j#%rowlޞB" ]ˈG7{C.\]C1=d7PQѐWH :$ r:1?J7Q}rk;:&Zg~e9(n$fXۧpЦFk3rn&)jז'NέHUrB}s =O;QXh76ѫ ct,VMm<1;^sepbTq>]DԌ޺I$XUY^{F 2p-zѭTM Z5|Ow Cn?¦)"5R젆Y|adSx 1>I\1=tڿO!Ŕ)jȑt/ =Wh&[I +b17Ju}:'Wg~SWk̇nbCf z5Ֆ6t?U!GG@DsBšv}Zeﻟ%tU pg[˴^(œ8cUTҫPrg,j c5~{naZK3 .-*JޯDٔR\6\ܽsHphպ yg#nN`%~v,ointof^WĊw&l+z\&02 :$c[9)w q é,_&KSlR[^+N4v#WKܻq 1`D@Ti9 َ w/L[ѣۘ+ΰJYTFϬ5ɔHN+lzK>WmPpO"V_ .96-iT+4%_ ,FsW5DSz:ɢ6Y"]{ܙ<:]ڗNo/4@>}lnLԞq›G$C}:qjVdʣRʲG@l/[Tu>Omh /e([<7_M~:lwPsg$?43eˎw9/WU4'u8oĻ)73`UӴ\ہGƉHFd1KO 8&͌aIaj6ryȔSA$e yZ* Ok)Pn`f0.v=:HgiDw Bd7HçHFy!*);SqHIlcG(aMON ~EdIC'TLFqE׵,0%ʜPi7K D5]{^e=xa=׈QDap=Ν& X5'dnP;Ÿhւ):ypƸ.K1Fn?+*r.&iϤ*1YaovUdh!jc/~D#UKpٯW@G=tpBB,xP*S_^$ r?]W:;T:)$Kqx$TN(QZ}2W Wyr34ϓI婣] CIx 1ڕ*3l-2 *j^9X`a.kV&l'QG~_{ZHIq-f6kl{¼g7f?RYhF)^ry,,}͛IlqenѷAB9B#̂,vET VɃth[,0p)c6Qކ >ReB2\$s1據^E60F H@" {Bb::܀}b} mE|i[3%pp )&E @h Vb@ e3s6,S rvJ/PszTѻ d.4.gzn9UW]nO|kb9 )} vӶjcg:z(7~LH(RVщ1#:?4@O{vSDySvYg&;(vkz( ؉&5)$\a2l :Zp)kѰR)u#O2J#%/L4TL+?1&SB;mEZ jL-P0YSR~܅xY#! #Z)Al?`{D (HoFqmC-V@M8Sh1۹_+/~.F@A0lJJS?4s57!U'?FDI >L1YcI?? s(vMbJֺީ5`{!Yu5]eV忓fXk(G |@JB!?#,URD[DEjUC:E9dF裪W POa*& 5W٫e~{_x[9Z"CԤwN:X0޹zuE-H[6GMa| RZo-= pѭ6@d g-"h v}\_v٠ɵH)6Y֎gzN[b˂%*a&~8B2%ns|sU|fԽ68 $Um)hjA+ݼ}"AAIZ׾q!)suxt6&/E*N=&d nlr_Oe)5L6BCrqm(,B :k2xZBe11xomYo?\1|$]<1BՋ< 'spA"E<Y:ʅ&nS<ީ pT8# >D bU}@-??uzVM}xO1h  P 1fz5l;.4p%j4_we BzZx:pl"ju[ OlBHH~D)ՁڲsڒJj6E WE/ Ks4"BȴV$u>U`I_1 +{ҿo\v bط7({IJ}J1 'ŀk0jIjCL1"3T$&Df`%"c75L}Ui0KJkymᝰIXXlnEŁS MӖϱ<5^凌P ^l&!E Ϳ_z<. һTBE`F .o--fj$0 lsW} Qj!{qwWHI :8ͳzZ$7Y#zzNaV2 RƤ su. KRdd^/E!)욑н\,J% 1QNaa|(P/u<Ӌy9c8b{n@zB31 .XU㭷 XKiH&C;g>d܏$UDL2W\{/4u \Z@S6wTC:D SN%[YȰ*oHY#IT6Uzlп0gflhr1?U6ؠz` !%P6= w *$cKUͮ>ڒ9e3cP-Q 7ERzѷ?6u%*'k@@lz4Xn?]3}hXC9GIPY]C%8BLj;~=c0]"uK6yE^ 6+1CҚ}#("~cxкm}k΅dmgDCOn*ۿ {D ~jm(C/.zf*ef  L0'mسҨj%C}>w'{ik1}oKl{$ W&g)v1,2}R'4VI$W^ SH*Cnr{\/.'Hy)RP)&esixİ"O\>v"D@+8Tq''u \NVeҴ mWFR"Έ\D5Cg}:B|CJs{)(h~tP*GwrGP2jS"c_UKZoh9ߎޛ"-.y}x:O}vD~<t 4UE3,瓲@aM2NXpwz)Huŵ-\ū>h:c}NFVK6p}% .ٜq.$7'+ cH):?J&~*uDQV++.wɗ܋c=/0i+䜾'CGej6!F_Jb.m _mUe /CھlId( Dj +p jsNJ{C;N؂ sҔ'w^1rtq+R#Bhݭ- ag)Czoݞ/,#寛ocܵVaiRމ{)(U,c.k_$A6UJ׿\C^\n[߳n%.!Xz0'$$ޢ~Z+!k8DtXD66Y.єSfm}%c.$]PyA4V !FrЏ/m(ndm R'Xw9(cMv|6c, µ6pkkXomȐӉbp"Y^SK¿ 1$WGevhL+jjF9pixD6Upʗsݧz@:)vn)g4v@ 5\qq@{ʿ+֬Dh}2C`\¸j7f<('J1Zs9rkxM^#; 6vNK-3ӌ[50=]WX:L"uXjcVaoٯe\oDɄWRR,UD }Dwq,_=W^y촑L4 PAkmC? Oh{GèeGX!PK{ӫ ~m(GE7(uK'f}<$Jd,K+ M81hs8Y\Ѷjxe !ſAFu*k_S[z'5s˪\(;J} $dvZ+<6/nHB1|VGA/*fN(< nv)޼Cʟ\H".ì~8؛O6fD*E Z03X]eR/뭰30z+08#NE֒/ |THE%\AZ+ j _x, ~|'6@+H’"hT7]u]Mպ(HڒTREGֹrs-z`KIi6THU&y7KT;'h%q(B=v)``EVKF>Smlr"xqgtA՝/' 2r=ۈ J*l@L :~fb*uL =N \}ۂƴY!fIlFsbK{5e+%h7LJf+ڦ+뵟F:QKKǬZ1':}EK'^+SS &sུx{^eݍ7R|>Tu>G$=[m2}B $aaEU3NPom͢x~Cu0Ho6-,ɱ@G]tzxt|UO%\t5Y( 8 mB?AT% (^FL[uUӬf%$>rr@?tЦ\˝";F#Sg~w)=Fs7u9}"La`j R[Uj*UcSr pX8`QWT4?0آB]X$_օ`/j oUMT.n #_82'{f\i 7o?VEGr=s< u͠6</!9GtTYIJN`DL0|PQ;F1.ǔ } Zȵiac!j piH _ϱBlTT=Rv&As_w3L&gǟ?sAj%vP^nb$C됮z='OC+("*)z,yǥυ)Fp$6w5u(ҢxMjŨ־Kޅ^TA^wEInh_͠;T's,)Kt=B->Ll|Mgf=\I9Y:8-x6}'8ZjfmvGuQjNgPwB`UnnQ<ev@~#Ғz̰FѦ#em!͵4,TJw9[`ᚨ]yW^3cdL=7Wbfgyc^ւddmbW:~Ԣ@ ZFt VZvbkS@~pkS@)gV}.TT[\`<%gnL!mՐ ԇUl|;x?&w,+ٷiZ}bjvE4JČȦ\s1&W@WέL'+qq DU 3?Vr^8BB@#NprBW x Go1<@/},K6qK]:j{kGԩPĶMq)wji4c,zzv7ڥV̏0rݵ݇2bR_1ܛB[ݜr]:<ȢgG7xXg86;-P~gudlX@K RI7_@DW'~ ٟއSΨwD`9BGd) >F0%cY edCemw"si$.}{h8#c4iܙS?OY.:W7O˸JQS(Ѿ6*}k=!2zn%k$ZBm|]7UDUܼ:a c Q|lVI'qW HvNnEɛ9yH][kGјwsM{n?:Қ_́WxXJ*I2&|-6֛8KgmqiMR 7z?FC)Q}/$4uE9 meXwh4dqIr3E$N@" @%CWRRDӲUM"aAj9ٖm.3 ,"4ݕבgؕZkd_:%RwmZcI;U;~ljչ S@/Yߛa .BūƠc$<N.ܗ֭In!K9N=2_г ]R@>t2I+`+|]@\? h'BV9u /x ^V.- &Z߻C`3ݰg4qi% :ugߎc]hjTcf-36?GB{4{OgフxhߊBw 4+BZ=NŮi X%鐅0 . BquJ0 3(z>|)Bxph5$fCIBT@ÙLj`j$"^l}@ ;-ˈ\ ̚j< 1,Β !.i}Ʉ(BKs2օwN`8,U[ Vc:R',H]T@s.`!OS Wi*Xki ŇEw$&`J/=-s):2aN[c^!]uqɁ@/&j)re&0#8P78]OFzSQöoܯt!cQH.* ~~7"x™tb8 SE'#q8F`<Ӌ@pXnEfCJU)~0)n{63AɹU?vX rHl. FcK41 (NWTpUfvY|Kẑ?S?97.8* JFPKɚ^O`ZUY/S{Hڗ 4v9*[/u&$CjK[,Bv8z/Q/{ 83SwisUMNybU|݌Sbm嬅pNF{NlNFCUA ЋUy9hBNցr;]_Lj!ÊWu j迕V]Ķ,"r#es**FëT|q|_萯 XPOuPOS٨  (Iϖ΁n *VZy"nRтn+Q 峝cϞUڴto @K]*o5)icoPߛ :fTsyD]' )w߆E+oj/[uTS"ČnƫܼU`#´*^ Ypڷ"YD(Iq#wrM};Wc8*h ut/ަ|/bE=A? VO|וKJ'E||j(Q'Ƿ2D| R=)b?PܱmGr?8Z5?)e*&1 wP҈8Ѩ.K{$8iW+G.ҏ߰md)/1ōtmY "7O21i"< | {1n…tm<1į?wx#!1Լ|_-ۉwJl":үu_掮(W""\x%*m^4\f/-b&D[ExuWSi4mP'S^⴮6dD3/$ĩ`um#Gӏe17WdP35\r9Wm1Fw@H :A ~ /}戄Gв )#/nx.Sto'K:kALSa;]\'̑Kvj&#<:a^Wəo/MҠ9S,3)$ޯ]efՂHova,бv.'M|) H9jzH!d-1r(E3Wr3<_*x4VU|3(^"4ET3w8pRiϤ'eybU E^:Mw/=8P7nX[B4쥺k7h'-?`=9T4sp۾@f% JgcG;B= +B{"{j80ֹ>f4qH4c֡m1K*>rXf0- x#I*MqA 58 < ^`(yo5:xt!ݵ8l[aw OZaE I@'R9uhmVm嘰 9PT,rƆgYTg&slԾTrߙ Boq),vw2,Hyӣp59D⸓P'2_2D3 %pcRwJdݍEyE;Օ!x1] O 1c!4iZL XeKƗ²l7{8fX5b ӓuX^ vmnk1w uZ6푻ǵ ̜}97ʾJr1]R H'seڮe5A}?h,8ϩվ#D%>5e񒗍8ٱ)/ o=zX?+`;4B0DPj&k3*.ʭJv@W/C )!N.osD6Gkd1%Y=VH7m@lX<<%hݎiH DE˼SmW̫h8`FokSSH)Cij{F1LU-!XVvku﹗ح,F3r{ C̃Ix"\b 9Q +)B_tCs0y])L$?ȃEo8=!h̥Kڱ 1° ڧY>{LG~꒏wDQ/ -KfmĂ[~\#Q8["SDZ]Ti9Uc6;jT;[g8riш)&ż`,벃C`+aEjhA%gҔ@mɝKIa_ rv%88 ‚VFաPXa*$ y>qN2pt/8rT\D} $Ho2.I޻3j9[/ʀ9J'X(ƛ&}4Umg:D.5*ӣ|8R<ڔˣ la}qoetK{FF!9a\GG;ϊ̇EV;9&BLݟrJ P'7U'J&# mmv[[?R{kgl߃}[o=.S< LU#"I?$̜FhBF`,飱u ~`)?p)L;G8y0ýU fdHtYR j8F LPh-iOT iLa;5E(Ek.B֮Z+RݥTpl sN I佹q0EvZlB0}tfxq';>F(c2)wfcvVYkȹ 3noǘېIQT^-|9ۢ  /\{niMN?74Z4%'/g1e+ts&EnD8In^[k=0(VHzr҇pПjsyn;cGn1قk fVfNQvpwi=Nrt ]Z@K _T^t2$p 0HmWSэ@ kQ ࣘ80\q}o!* R&zb2] 7!.uŠ.2s* etWeigX7%$ [ gsC),hL\s J,{'өk{$.ee!qs.ߪW%NgZYpqH{R27dHvl/R!Z?[b]%0?{(Jytr~]2O#c*N=J)fplSڤ԰yw BL))[Ӣvm o@~߀M m-Ԫp.H翳eg8 _6 .pR?%1x1Xć,TlmJmn' Na tµ-qN蓾2bP:VW襗5pLph3Qe#GR_$gclTmGt98{Ϝ;BoyTu6{#cY0kMh䜆#FQ).p+/_}'to{d4 }i+^M-RAp?ٲMuwp1by;B%_M?f?U`:K꫋ ߖ*ٳ/q6rK \E"bFKiNFP}aI86+>>!S QJ)fntR.ZoȓtP"JSp,!a@,JE `~5|Wv1ӎI9o V~EO^99ԌʮFߐFFTIK)$ϗx{m[N1]Kxሑ? '٭ GEc285BÅ 8)Wr͎sVRU[td,4zʊ6Zf6@/o}Zv iz{zuHhǘEc\]yo#ۢ]`OAWLsʑN@@D⴪z\ 6x^l(z1R,|Lv-e (l=a uvTRGWRu5;SCT:W\I2M-ˎ~Џ bl(qd> =|Ft4L \u nj-_gWDTw:bP:7I5g z #6P<6ct - a~dD:Ih) d 6DCwBh" 5G|d2PNh8QL5QϩRo K(A$ \vzu5 .1QFGGq*: \H$J4cN9drZo6 )(&V#ر3AT|%bo_M7@z Z;@"os9]P>gRnwrI{\K0#]pO-U$`K(D? 뜔Mg|p'X6'C]? G\e3ki-V>% a"-7Mj˗ġpt /I|"O(NRJ m,;E/1yWf¯D9@6;m9RgVw+Kyp6r|. gw4:>ƭsgVt dO6ivQ)ձA$IOgL%삁ୣ ^sy wdsSMc[y 'YTgBo3ɐ>`6Հ3Z_h]!B4pb&:v9El5|/"K%q"' bAc.^+ѽC?5_v {paZXx=,OSMӖuhcnzrS5t}z{rUUHR| cDy[SuH^QbKXe8-MZ,)8),fuSw2Ԛuӄތ#1$DaT4Q8RE4DcV$]}قiǫ<}L 2Wf!.JNl]\$|%+`#=R[*#Ϡ L Yj5azȣT _paKӋ":/=]HݲQh) éb@׬tA-Mny~yU9Zh4E ?q;rk`nQp =U,I=X5[/s' 2W_#}#ZG[KCŗC)QJ48bOU X+0%`5LN|:{;K amz:J WviZ7GЯx[ʁ>q'!Hzț4ݬ8LN4/ejIrT-wNkAKB$°$iod co9+ǝ.lX5cٔ_8z |NU#oC@G[7dIsVMecS+>C̰zOHrx*=ijEaD˂x湅IޔE؃ ^%$Z$x Bjo:Mep %P0 -Ac( ۍʠ$vD;$83m&X5w[dc*!rQ␭ sncc 3ۥ\,Su|YFPpy'_D/rW 5RN#iohH>fAbx H>&D@yHS[>bVk^ "6RnP6 luEgMax{EjM-|7lҷ-6``H%vK_VuLH7^n'_"&0ލ!yU-%UGlԕb4duD2-vC'@jI#O\Z[ .?Cku\454`BnvTŃl1׼+ NLK~f56B :znzit= he {Sr5D7?J$3K_q|p8[7!{Ę@26qWRݑ/;8TTr[&(ă[ 0ԣyG]g db"LoER5Gc) dW!3)nNDHb663@`(foμ^DNU'1-/ފ^{] #b7%?$I/L>D,\OޒzuI>7Pz5B hQT$܌|i+o1UO{7"1u,{{“-sÌt0#N[\Ml:2 ng+PN8g~\z E#n^^u[Ћ|0&3OrЋ:f xv[AVuU4U1slCGSY >.JN:~y4X:C,srq{dT!י[Ƅ'GȘoヷ;;Q?ٰb"J6?۠0DiP. /![SWfdr &օ-"w7"NCUoT<\vXC}Ob+rVΎ|簘pVJӊmmҺy97)”V)#I]-BespvS͔73! $/׿O-ܻG]P#;RWjCk@Lކҡ7r|U|#P'7%;`K͕ ;?/x,ۧ}#T1J( ;MIaolU<[Si͞Ccgk=|h~+Q^)MUTxxZΙtQtICacE/ѷ"q7޽I$V{uɢj"/.+|-u^ ;~k_B0lUdg&j'VYͫLMX]? s4C$HÐrwi.iSWR L"rPnij~x'iI5CbF !)2dGSyXIb"@oMppcm&W~y} v#C=L+j!Da/FWd`Zg_,޻Rg| nrSH3 ߭H7"d׵ JP>|Tcu܊Z7VSu3!rJ; )՗ P?O\õVXT0gnإ$(B?UTyt*zMX tjK*OǢ oID?COHK@"ːD%A,ڙ)0Tɑ wDt 9T 8秳bu!%?JttZ6I s'L!xs5Y9j[ÿ$1akn\p ibYhxU͂ꬮ SlnC,@Hh3!^[w<S\C$\N1N:9S]IuOipuɈq֟?C.Oϑh\ m!A:T/«ɀ qk3t^B%{Mv^, []dPr10PՐ |iMj~^6ؿSfBI땷R1 I=eEr|`T5K\)P3F@gI7df;A3j:E|nR4G~[ٲʣqI5Eh7rЫhQ܋ݖ74߬x;J`嗎_e}J?5oG$p.sPuV[w}V(f%19?\Wjw^æ)uɆH%6AJFjUX!My ˤTIerܚ+ykqh!"=w*SE`xN(f9$vdz.C/5U##=ԑ`Lz4۟LK {{H$um#?)%|8o =<|,㱘ngԔ["pə!K`Ym!5BބX֬;|4:i(vz]K #oD.Cye5)*?1mbxсDWS|>TzoLpq `5^8`0rgk){ff sS*%tXބN=xxJ|u ovtX~s<8XV B²mzK_]0B}H磯L$"yP@%䆬s:IuJ D)i]"r=N57&NiF'Rvgx365CgK b5n?Mu *14$oN0G/;P%Mwopi<V(ᐡy97Uq4;! h㏲ՠ9klJff>fm^+3o7zuN$B~FPb}7$aY6ҏ\畉P}Q>;/ -Nd搙A]9dJ!TTKvxLC? sBya`1AxkiZc|@'D+g N`=guύtJ;c V 2[%/29$Y{o,|<ؘC gD !?NKT{PkfB%p/iο9j[D8GKvQ&—/P\fXMñM:~[`Եj5={p`89VsQR½Cbp{ϋR$t6oa"XAH_--+1&xi-oC,uiTe/Y[1 $yGڳaS3i^C%7K|?R*1KTv k$ɲV&(Z ʠH3 dǁ +7W؇9$ď愿Fpaerd%XZ\Fgԗ (DsB-L%}- m'|@O:;oܑ~,-F%qӢe/܀;}ܩ  UDgEìHdv93[g `+B{Ǘ؇q>N /Is,5vOά,`s$P:ɠ_`,в$3m-֡b:F"Ax8Vqo5d|ۉHȢ:x^C)[LF2V`Nwh!q$ t^)9VkY|({@+!{Lm;^5t/+V-Tk85xFO))%FIS} Fל?C9i[) p<Bkd@A1Iёjyj-Vޭ"Sa̖*Sx9 =g[JBjE\@{=T@/QXW`iͫIY$^K7 ([{%r6(@mmI-8Qdd˟>vZR$"$ =N*JN?ܾ٘_4lq2S(f7eFwenԇU"P/ R.ʯyZ%-f2pV\(!wYmZ2ۺ jR"pNbV<0XyzJwWƵRoӐNY0 5zH7цZKE*WG-񦃄<~>+tP [030^i.=*B;з5hYz*s(r/Mx9`UVf[d6jrwr# /Hc&άHFꠙJɰK2kPe  ̌Ԅ'ߡPnQg 5Pz;oEaFPV ^n%uS"f"5E q87#~"Eϻcnctkg2"i?Uv@-,QpLS`}#8ۊ31.ά{U vxbi^/#g4ʦxs6o~drms|-vQU $3Ui F"7uRGAW^ ,lݡ+m%1}-X5JݸCXT"eB6ra"шA{y ϱ:;T+}N&cx s!ԗ ՠ=sFv*yI/aSxgRk CN*`߇#3fTz_EBf}2r4ą ESN:5((&`cd>Z ߼$jkq}U Fy&9Rf D0Gm "浖,|Ռſ~xh3b\- &i5 4_#JnFQN;,{ADРU"~9dk[S3-5.բD';.`X;zF^Xgl:%֩zįK@.ͺ^Bژfxa7и2vzh񊃐L+`{UT֥,3%B-R<|:;‚%.:(*?ܣvzX;%%Rb=r] WA!r?'x`*l$ ъۇ"̂h/Ǽ`eT9gf,<*5pΩ׊ C1 tza+5r|nK%bQ&/7Zt=/CO'. ǎ Gg~R )pԿa6{7sBRAAR`n"e"z~ރu`坕$l;h.H50[ dH`zȗ[9$KR; /mM|ǐ:ޤGDt]S(.*Z{ x#g;ѨVS?8a$V G<=V&V((w|q㔹tBY:0D(?4􇌶Hx'ε#w1'чMWh {o2woh*#iW3N3-vѧA.r ΄lI+Ƥӱߨqp8eY7hW=K*rO~S>"8zZAПǶ‘(3 ;,vbCJNRF12}@n^ {٥ X5>n?%Mvn\[9C 2.|%G:uIMTф,Ĥ>NB<p HH6l9˨%cϣŚPƭh齍+BPAw)cGbz$ZYCI/oИrbf.I&\- pMP3Lr)AJPGr/CֺigN ?b-*!ڃ5ixTU_Ȓ`4{X8wHXH 'B/ڥ5 leћ5r[/i,o4ήrZO~21e:!~B8(V@Gȇ&-/@0hRթnNGaˁǷ"62q8ί1ipYeXge~p$Ugo$30 mt &dx ]ΑCG;-s镹 .Nu~L~F&T${ޝ|kۍsq&6TK@fk3 cW ݍL;Xy_Jl)H>)NXvSoGqzt*O#.ߢVm_*nBF>vZ)/Ųo$A4޴OZflSk,1xyb%8UɈ5zPz f6gHTQ(Γugo:Tz}p/ԵysDRTHw'_G3Y`)^'`~$X8d9TV`jX=F[UzsZi: ާ欨{թ: V6~axBF"3Sus_!j)s;:ߓd2WJQF}s5P*J`L#Θy_sMO vER% ^gCN,dJMVdОb9LR[cczA zld31vfMKF]qC[. A)p8[WhY"o7GT#ٻ\ Ɔr%ԽDbWTƀ7 |deU5=Nㆊ{/sّ;| #bֳP*bwHcX;$7W4Q{jHdܡNrQMHT ZB+N@|U:mouP[g"Y I . 1rsM9#-x8uⲇ}7.nSd V*]&n@{d\-u(vD"=9_l 3kW!06\7D}'jWP׮tw~ wO\d^Y9i8;nJWZU&5I=@J#^|8$_+=}WF5y z2}`©XnxP=jc%2Y+r- wRd7u#W~.>)NGLu+ ɫ9H=H c5ņx Ǹd:{ !T}t1 ,؁A2o!Pb;TG PpL >ZLM6Uѥ Iy%$KČC^kitłݪMh51sY0_߮[,o[7l^,Pq*g^B0[;d{cӕAc?l#8V;' ?{uu$pb#!+TG6MZ%@5(|=K6$l9 CsZ a?>m.oH)JY1+GMĔ)teCL(ӌ07f6R(0KG ࠶%A8`Kjl RSHEr+ʢ_IE=q;V9,jtkÛPaE{|e/ewCt!EJZHO': ;B;V\mk4*&@s "n VzWc M'q.J&R M }s,M a2쀏ۚG1z;t&0zC61]%K6ΆCA6,` ب{Cj+jkns_ iIFƏ[yc G"]1R1\=ӷ!< ^_- ť9Iz wf\`%U8*Krþ-ZLc&Vg,ZQHqLY*^o{_ǝ ]ejC6GrDExYUcz9x66 ϏN[[-,i_d}\dۡگ^E΁]+9'U>tpɽnTL\>{"\VP5 XyxM)@ հ guAsg1"K{~ЌǧqE\K* S- !n,TsG:Glza)Ť,e疨ʩ>td:wrvlvCc@ѽ<i06PGl=F sxof "JO4M^$'kȟi8YPj1U:P4%yRV2^t}ɏM3z{.D8$0*O.] oLҗ}:}wIǴD*kպľ>}>pzce 71^K?GA?:S0Ddu7R`=,!̓^B2,+6]dT1*@cm,!dჽG>WSSPXیN+ͳ! ;2 :WK6~DgV?c5iC.٢ JG8N^Բ6Z:w^0A#7lw@j:)20h!Ceh>jXu.~&_0;# >xuA>}SMmu ѫ :y^f#\q5B|Z6(/d^?D'Czً3J\6#owҭN,LC0R"W.s2g@>(0f3N3{= 陖s3eV@s;y8Z"3DkCXeBxrPMH?pц؜cK6Ʌ5T/yb?:\y8}L PfڦS槡ϋ T#b|cZ? qnIp]=w` !O(ĄuSb~@8"A.-U;:jrxUgKN)Ř%H;O0Vh bc3"FV4Yx I_Z9,+jxy)WLp*KgK 5;A! `ZM}ұ?DUL$* uc %lLoS' g#ae]w1(/{O wP\IF"cˑcԄߺgAAL=(?za3 I2/DXZ8cݾqR.b2Hi-%*;8hl6] b?^_jH_`@vE>'=}"?vaݶ6s:i[9D`Y2<;V&"XWR'y_. ̰ MB)mdN*p!+iˏw7>㒑LCYAKX~ӺLZС34DxA`cPEVI:Ayk']h RN7=<#kgXs NG@A, jU\cp .=ө7 H"؆sM/0l=źX Ov7y-TZViSlb _cxk@KHzy>6n-h'o8tsC;oD2"pN%) yC!-X{$Ф9\;850(d/slI3A%]DE*J8Ի)$8.p8NU,25)7^4>Ρ2 ~dO]I!OL%řKhL"_MR.>AZ4(:(nҀbS,na.o"0 7N_W>r5FSu)mX|S 疐bC'33q ʃ?/~W>+T褘sN-u٣MrnO4ve+ҧ5dwX׌*4pUL1Ig4P?՘W>ݏDk3ĥ ɕ%rsJ*f=&8T 8tؘTh7V8獳pñbC9R=fyin+JR +SM;4orefT#X1T2|{%B-kڪ GL8GXDޓ&R%wރ¢^W>U픫_$r)= @/K2*\=Uy^;s̤Đ KuCޠYsۖ*O˵?^Q`1n JeKQD;~{Orw ׾vrȢܥ t>ÃɹQU =# ;1԰",|] .Z |XzGN߸w]LJENAŀ5|5A60 hϧ-]4eB'kM j·-p:)6|M ku0yUDxzy 7ќ@94kylb҂~fg~]h"2"%|Do1wM~>ނgˏ(b"݈K:w1N7)nj21`"\7ǭޑ$*'HPJ/%qI2=5JR޺<_RqxfĥkCJq腄nFN?%b{,kV8JV@z /0s&b{%2߶*ڈD,y=bNzWR?_|r9YG"|3E'SRӨDž{s)5Zt@3񿘁qxn1;ZSZ8g!A"<D!Z Vh5IYh!ێ S|wEo+lMQ&$QCF2쿯hb/`qPMST,fmQ+k8`̉` 1pGr5tc6¤I29IOsdc&0#!Q$yRe/m4֭lJ6 F[/1URR&0#ݐ&Gr]/-W97$Ӷ#4WmqM80C-w6WpO,\i]%?3U6IK3szI;d 2Vؿ٩Ft?xh /h%=VS ~ sзA sJQ5ϔ?y\'&iF$u6>Ɉ1(r]l~ JY3kUxVOm_PlDZ&\?z4`$|#3aؚ ҉s`f(_ pX:jZ.=[}uPzor\w~ @r;Y|A$%sc*Ζ $C SPc@b/,R[۔I}iDqw2ĸ&H"7@ww0*x ]p=hA%g{ ZLexjdH\nI-3| Lj`?s}:znVknYɸ ..Ǻ(Ւ'R#O)WFQ ,|4P,~.%yhr~?C@~! \ 01&F06:D>"V҂*'>9lZУ$bpEFjVub8r1([kJZ0ḲBֆSW]e4]mfU; ߰xU,*!z,!52D6zftѤyJ2 ! idwUoʱr mZqW-|X襜Ⱦ콀6 #~8-+]RR/ou>%>9QHgpoaR ĸ>vF[7DjHMɟT!ŜiG]:\T D-ca>AڅO4m*;#`yAJ7NwC׍dJ\v%aא{U䱉{k8$,}@]]?CH7;yz;Vr{M/Y=I7ԍdm:-&}?Gߜl*jޜBլx9 %l GLyF)<.f+Tڔ$c. /IJD|#-1{Ӣl^,x %@Ԓ81Xs3α4צ\vBq_KMݸYXD- l!"h@^'܀%U^ Fÿ233T KSYLJ&.4PZA l*3Q͝esE_+lvh_/UY^.6e2om}@UK]ߣ+)ĸn{"S#y#=Px.Y}of0nm bpv~.HueRS8. _|_5b9㙀RQn uzR<_? ] ŭ<oȯ)rE\CG6!jGmRg@V#q+NlJU:1("TTNÒy E&h۰[ͯ/POs,Gy`{[TU+-°#=]?NKס4ʺTYPb ZN5gĠx t!*6whٝT>$h(-V(.;P?p ,GBPjĉp3%wNѐHܗ*uuacOUr]8X[Gu_dBuo0f֫af^AenySu^w#532$ >S٤NA CK>s<*IDj<)G q\+DbBGhl4P*u5Rd,"ޓg&G}NVUsFkCfQ8k4HY58jy9/GMX=_wk '=W˕ꀴ}1;韧פ`L9If)@ ?^M!y `e;/XBIe0v(+]Z_ 9̯R(Gy5CZs0oJ#t Bs]Ӧ\r^b [g'IkC:vdv=X/ ~ |m|±U`] E}; $3\œWt4)p~uv% ,P%-9l2VZ.[?<@^( (9$ÖyU[;隔~mxB,:f,L< []L.zZN|fgͦN_X-2L] auLY%!6)7_;ϟM32$TSϕW?Ƣd)m"4E]*:BUJD_L22.3Y,]@٨@ɲQ?ulkáOv yŧNʧHNr%0JE٤IYMఅFgd(TnlpE.EB˖̖7U'Jw|a,Z#PQƻE۩7¡㦒_W9>L׸.}̋pse/V0 ++3w;.*2vT0zir;9s@BT!vs[JȺ~T"%;ttIme̤ ,@wE_:gVS0f`AA9xt2fwzf]KGaЇ¶<(N3#Izep$5N`ܛV]q.CM; $IUvH^N>e7SPfoe[S<96ϳ$.6wکNq0"ffVPm8M}'4y>vq]25}u ovqO y: ОMwT w$2|4Q Ome :OcPWsDChM% uCm zA%Y<ľ-t>oOZ#њW.j/Z̥>#VjDh "v~;F c KRv(AØE7 TTmh]FPpw u2h; ;(y;29`97AR4䍸@t(("R.ܿY>Cp"`{ =ubݗ& ̷X.?ɟ(,l\G)w~|^|Ϯڥ13PpAȮnZ,=a4吖HcJz 1l?haP笍YZf(Vq`2H\ &oVcOZNV 3_#j&:TDo &DӤc]8u3ܰ' <,[:,(R;ds$LWFϔPIL^U?}Y06lFE={3)J7PP HQ5"upΥZ|Yna)61~ZmeLR+~DQtGַ ;I0VD"\ߦp$Oubs2_̰K}35t O+]B3I1Q_$sMidUGWҤ#YX NSFդSS%ps3R.+1!Yº^:} `A\˿| CA7#jNEr%8湪KE`nwԀ)HGs}"ͰR*HXS"Vc0Umټ7QG^#cҕk$ε 8Mj6s {74@T, ,y\&קk]fǚkmx Wr@Dc Ӯrd#ұ_v=<ىݥԣ@ AU} ʪNG MV׹-X\Zhz5*"Z 1y\PVO]o%b3 >4hۤu o܋Y=>G~3VMrEo䃉)fJUuAco`,M+ܦ݁>賉_ro8ULyN K@P計'ksGIQR.mCA֜oW8 dHhJ#j&fag?a} )νO𦕵 ;>pMB@=:k3cܩt]O۷A*^QJ^`jgG Йoֲw,Xb2~8ISV02#*s?rHF%1T_CWN#_=4n*H%I5M8|{DFm@+ɍc꣡rY6-X ɔFZL0&k ƴ34QN$ fygqa7?>}~PrɇKǷ)4L"%Ik_;3@cxQFaZ:C&le^e%+%0D ]3f Qkc2`F:8( `14_ .k3\ׄ~` 5yl>5m-a,. or6ІP$$ga{V&D6>K8;9vJ,vY3ah$uxpq>˂گcٖtkW "ޏר4ߊ(PjAZoѷܑ=rj -noHqgA]hHCn+ 85,񲥊)4/)@rq|?G|L{§j˲كn)~:iKS.{6i'y k})z 1b93mutN٩<43Ь[?*VҖm8񘉓 W}Fahm #l ղ*vY$0knnp!scQJ1&F2پin8yO8% X'^_J +X uSs-MyhغkXrf(./C+S" [*)7fw MnEN:ը`FLhmV=XOR:u^cH^|%1L~/O+8{>잉Cص"rx^K.ΰx$dU O$ȭZbcu+ ]Du}LLf'z6D錴7g+;_Mrc~ƼZRG:/C܋5<-%^ nMj (s~w/A7}om:l :*;ymeN{*r1Mof/cI Qz%{] esJyY4>TឮҌj OŦdS- ұ~xQt%0&CB*;VdGg,T]Z^ /⎻oɣCsBGpt]ePN55\4hNL*eBK9- MmZ$>q;#I5uFt|Yx{ӥ+r+(fZNGRk;5f`؊QّuPKQ}Lȑ SrG˙5 2"*,DiJh͏)tvLNidܭeG.9tBa+wTXiȕwEMUd࣢;sKdW9ɉ*E1h5J=%q8Re*0 8޼K 5&JTIF'ɺَdWKjeⵔAY΂5Xx&mBZNے# 8KƐ_]x h\| y cKDP1mf󮫬%1uE3 dPPcwֹBThsֺ QE@"N>9Fµc~p3@_[]2ʐ켫w):8np D"l&}'3i{r0Pr _a'~bgwK:jݚx FW[>7BuDXaKN7+c1ߛ?_|rO#3G]ݦH6g|4DPSMnTZ]+|JX\A5ѠK'`}|6)yՅT MG>'5{vKIQXUB~Y@#!ӈv1SnQ;f^J]f"֛gMb`v6H;\n͡l>ow3jN)l== y ÞM'Ib3\3V~;.i>Js\ӭ_Dfg)?}djS.1z>Ԅ|X(,aB#kHț΃W%9i DG%ֶmqun/{XFYg&9[͊RZocN5u!i¼<;&ͅWuN ‡t7mCW?äd#}29OJxbʌWQFXd(WC ήewI2"dzAO;&z:?驥1n#@XD`K/hb /(E=?_>vYUkO(?7.lX(%ٶ7R ڍ OEǷ0.@;bu,wiDek5$AXn (PfZ% fY`U~O0جW"5ݗH;Pq %"w쐧tqx0_P?;]ҤW&aog1dLWθt&8_|:a_M,%`d  '%剏Dn%CPI D+oaRèŜ'HW@9j}9=gb'+>k%l1D/f坺r\wm¿J&:棎V'CEk9iXAAˑm(pZ35ڻ*D#VE;uMDD#c-71Vgiu^8t7k|`{Ggo` z4j4.WX>ޘJV7#Ϲ)#5X{Ga?GͭjIN6AcO4}R-ow҈te8&:0,&j.*βhLG}oFxI{ 4_{RM~HV;mce!81g8C̜^܅+ X2DU例=:xq4TX >]Ն.7EhᓫhuKuw*kɤ8>Vq2ӞJUmMgCAOaw@փ?؜(ph'\^姨ta$z=7<mc;&Ph)>"' X yf7/aHт> YF@Ŋ6LЫ6dTk =Qhw?YH|b {K~ {}R=aPXSevSX7ᕔj+X0nc@!Zu\jx+??iV㠙/k1yCKQ G>ǞY 5eQ8hO6oFϚiؐyǪO:nof>OFc cw/Wgws/l>!jTqXLk{`,6?&~TvS m#$)4:6)Qiu+^+OYVp魤o;ELs }awX*fY;h`Em$ȡU"b i{4%$Wmvc9[Jlow ݜ|wt҅> yBnqdAhIb 58אE3素(@P%蟒嚿JXĥ#é-u!{_]G\uyMhٍlO2?k%Kp,XLC.԰HJ4/P (611KrH+εvO &FOǜ}Wh7:( m"̻b+!Z2cXV!A$2F Z(:.7ŖC'`$ikcEc4>Ef|8;ChtGsy.Iͽlnk0sH;`!ӠmG( q\%Ԑ b?ܙ&pB8ܠ TM}42ё-. 5 bgPwRaEQ[cIӟSJ=_ Gh-Fr~['~IM+RV[FN:E <.qv2A7q ,;K-,%Ct;k;YyxdNu#rQC1] #/U鸃ǵʶ53w֛ If|7XLA{O{ KF9nbz 7 [)* 1-. J3J?(gluĊ0j(mry)'WVGi6H7'"Ѯ \&uß |/BBh.%(Mr;mALT~64\\ W|$vVfdc]U.־BtkKxbʒ1KU>%P؛ՠ"u{>2HFUju8T更\8z0)ѩkri<6[`A⼜Pһ>mj{ޤFMVpimɫVZT h|Jn\q46W1rbhP9}Jێ{z;n1'u"EEu ~+ANF/EIe*(id8q"'W+clS ,oT6p†QlN<f9L,E B5|g,y{Ž13#cNKD;`;$Hg!fa/T6 t:ftj}25 3-~I"Fz9ʳ|sϟzVi^F%g ]0 Y+_lU3S5#'B "* 車A!R\z+;ol X1 blD?=soS{RfH/SKiBR_%HUJ_W^{lJ2m9w@[ޝ J7Jx`"3qʦدC!MM-Zjmd(P1CKwQ # =H Lй [D~VeyLAov ^Ht -4)`0SWPD|DSa6Rōyh@ޙMc]ST1_!igU{MdN7g` )rpaQ"h 3uX$*.a-Gy 2IVb h8hetSҭsLLrϻ< 901҄2cKjo@R{ Nd2Mmk}< -=$R˵\E.A @qq7*U|Dt[="%/ kn?J_f_^d~k厱3. gxI\ 68W+)2wyDܵy+:OUm*&9G;KX-H4Q^zv8^N%(ketc+kyFOCoPTg!&UGpTxT&13H֡$쟒YhAmxJ֋R1g9?K8g$nLzԖz/ du*]m5; @}F*Qφ7AT1xs1jR'dSPB^ ݆֘g|zǁ4r+&w$p'E?*ALId ;Eo f?G<˔${nOQ~\DOG JbZiA rqVؘX1v%nOg h_{BE 3ILv]" TkDv終~A}jlK*L!7vQh|V"{ў6&ьiYXٻ^7lL yV8I$H8#S0jҾ^ۛ2|!Ѹ@xy)ȸ[rԭ#haT5rtR \dgzn ~¦JHADM[P`+4 X}D9[Lи2z7_-Hhs~U}zzDj63"_>Ů9d@D{o \[% E"18$whIXRJFB}Ij3!șpݽlvVhQ?Ay({DDѓυf dH0;X*xTɰ8A BHk"bs2Gu^5{@eՁտ> +:7>YPd˩V}K@u m9Q](R0KUlh>&D ܏\#z abJc5x D2,4k3[|1kҊ$ti +i 76 85-&:ZܝЁ|5Y d7sӃzM{P>ztUtL m(\A jr⵽SREYd#e(A1M'6$z*`Zo6GIe*X0ؔQ~lEYG&RX'&'Sv1*^N0A=[4mVZ"v[Ҫ"loO8}@tKq@>ٔzNPƶ\u4-Em YBAn: RRslJ:8ooeQ_PXL#s(uEg5r3?4 >X⹐!?O1B}T[D.9>֮v)ޢU53mٜb3u2Gbɩ#\ \NHKq-"W =%7jBLOUPSs;3/8):Є]^.vSH#q`&ߝm`J4[qfkkވ՜:mR 䭮NJEZ#_>T)&trD/,˻_7Av(ҚoՍ6rKT$O. =5?9ݒSr/^#I q#R CW\=87#a030lZxYC y@p7ӡYX5)ȇ.H$etlKDm-}"C1?`SSܛ#4L38xh!0I" Rԙͻ}xWH X ͯ>r l.0bLBT餉j',V?e|!R`5Py-Y u}yl^nJuq/ת'`i]di6j̞k"afj!Ю O\kAd]]w0c[ZiWߟ秵-F:\3}|K-9W(EsVi \dK?;>Z3]ϛ- ܛo'"ÙNB=J U8D٥R*M<"a>=8PxˠˢC21=^'ZȻ . ;J"80KV<\;_{J^"*z.HF |Zڃ łiиыA-Nڧ;&:s70uF9o: ue8B 97d?zX-|b[i$V;-]_&(bͱN';*t>vJ݃FU}10+Q(hO.`ׁki$Eͫ+9+|w'(d X0m*bFrst'c SN=!Ȏ ߌ!iu+Gž{&Z&1 \j="s\~/I Q!n)1g~񛍇Fesvr94K_a1\ip{dJiUz5٨iҀo'8I2 *"bPD&`7!iuCf,1ܢ6;=]oky{R'G1iy$&kQ^ T'1rs\h6ioa$׎+Z lEfQ[?`s\ɍo ^4|#DpZ. +D%  rʇXin4.; Ys#WD]Gߺ>MRG!oxu[wS>v=z7 > GA:ZyB\J W(Ý,B터sS6/9ɢ<(c Uq9` ̛6-lp2ŏ4ŀq2[!֊K"~UP]5J0ep 픽"/Ē1[ˉr70eiQ'phD+R_ssE 109ys;!{+'&9&1uPb}}WޕA7@:VntX M1It 1B)ǕIDø0aHů3y"p%kSf奠O]ߪ'RVΛ6*.t 7/I.(@1yerx!vk){Ȳdvy/z4 uϒXĩڍh;y;`C`Ҍ\ r[j7ۛ2@KZG"jJJWnNJpKZ[?Xaդ&we&Xd`N2p}-v] |ݎK%=uOV7R~#:݄6b}Y?k}ނajp3mcton8Xv%_^T=?{T>6M R7ZֺRhmVl&zՔ8 iG;#v@F^@U jz^@P5"DBY=ÿ7QcĤ}?, ufмQX:wR=eLRqI]-G1 6Fg YMB!q`r`5ua@ 6i֘x_[Z枨 0,h]ʜ_"Z+܍gA Q+MYGq8L ls"Y1I" a|Q jyPTMVaSavT ,aNG K|gid f/Y !ѝXuҏP&` daś?v#.D|4:Zܦ =du3 zP1fJD@WB} $h6l |zkIpĿ ϫk!,/x%+ZJ?eRIi^23F&j)ɫfR@\bRi%(c.{}"3OZW$:0zSEj@w"zY3n';MSTė򍃮H6Wr;C=K=8(F/Ka-I(d 8Y0vp'[a]JqRFi]9HR٘?֧9K 97vk L<(¦AT P$Jm8Q %*$e#sZoZ{}ڴ*Eɢ|nDh췕wQi: CAŰLa` ^eբM.m?=eH)zӧ;: \z/li}|BZt" /Yͽ]c{%N&}diz{GKkvox{DKxxIѾg bb?B7VŠ>M<ƛ%)|i߮MUwc `ԭ*ԍ@mԷ+ꗎ"s0| ڴ5lXAgˑ3CuVD 1=LϏ,yV28/Gt b}pj+ҷ VJYlk7k+!̄n0YbmڝvAg",LY' n/S`v;zZ` ;>>{<8Oj"yyޢ#yDJ{K>6mܢ?#& w\S9@C׳4愰>s^@AގV>hZ^шӽp |%k<,J&Ew-$zScnJ @ktð{SH\[V - X2ٝ.F>MnB]7ެfȺu!~aG7ݹ>V;"Jš%@yGմ ~V'W (cJ\`gd] -$ۇ@MTTxZ"l&ZU`Hߜ吒8转IFF\_-H)S"6芉һ.1T[6O@^u NK!ƾF ڣopB\9cRG˂3-5<8[k#UB5Ѧ<6ܦSaJonr6b+T}+-sU+;wz dXaDmY[Y~[kB<]?)DWz.=. 1j0OfRa0AX2nk9ߑʸ(ERA5Ay8 'vņH=6.,|GMVWݾiCB[/'1-: ^L? %hA/G[פFU.UDϑ;!zΗ+efWwV1n_#~ *[ Lچ%vMۃYIqy^XU/jb#TL " ?ACM*}3Yicz^#3I4g*X)M3M1 ZѨwf(uY3ǤK\_}#1=^q3X;ctm>Zeko ܺEuy-`ݫS\^8>".>;O  5}FTk'K"TŒ/I~(Wm? * s4"_uP􏫧zܤ /abq\Tsխ/[ه= SCFx@!ޤz{:0U)Fԗl{-&⑖?h1u3qBȑOJsqe<īi_nc ^gdv~)_M iQM 4-F:TIX2Q]J&q|YٗddBv+.e=bd`5E؋(c1!P+of'`gqoE,kHVY{Boc̄% s*,J9T1+hAH8ur@,7׹@ $_XxNt3 EĹCtӇv ,#L>uk\P ^;dSC  >4❙vN ҅}͋d)%%dyLJ&zͥWSnt 6p@4p ԖTwP?1tFNsOߕ`дsoqn`w6ȢiU\p1Hfe9K$H,=JhÚa ;Axzފ3~*SM1j|c+7qf18%lRAD2]E$X]n}? .zլ*IEmRhIU&a` v,9O`qE}!㭺ȓ%- Dq NkH 1=KOw)<įicyLSZ"cp踢~ Tlפ5kR3hldrqc*CG6τ t,lWNxȃ\Ի<3?t#OODڧ O[pԶu-Q7jMiWOѮ&/$xUSo27&y3[5V@ i \ 35]M"y<0&v'yu5(A + e >-@H)mJ.|f{b|j3*_1 0Z IDBaJvFJ% ߴ"Ĕ-*AVwJu+t`-g[iGvE] ;_to ȭR?HqطxT2hUɮeY o@dvҍ`Z1 rs#~}*_-vbc _+h/}O⍘}BCqj:kM!/ONJ ?{o*K`3]h~]ޭrH LYyw >'l-db爲֎ny ][- ZʟFq;c:1Q`l.u[ :8fZap$Fz@@̳aǙ@h^4$9z7 u^eRcﳾfjL8sw% <9s[zT|_x}x@n׭L$?RߴSԺlJWq"NŨp6P Lh#A 'vt&7f8qni:;py@=qZLH__PuKVP[MKjePȝ* [0DﮠGj- *'FYTǛ.ך"@_rUc L:9W8) 0uҴ|Ahj!~NųڣW1<&O$pM }37WYlom(tUE*xt QK.uI-"T0ANp+9a&b['rݖ'|k:~mGkīqPP}~@2l ֍*ܨuJ gp)-@N[v;LV Ki#\z77]}CWӴ{ l_TÑW %2@;CmjZiz?Yw/G8u0 9jqYԐuD|d8 I`ߴ] tIqx[#Ɂ~'R2w }CoTpCA'łp'gL9XHSMJ_nH"ϦP4ĊS۾P)r{- Pdm*:/)DI0)[KhVdy)8Q)Xεi DCcIy+E'|ˏE33wD( *ŹbHeҿm|Ke2[?rDb&7)MJAaCG(1Z3GF*>i"lQ`/7Ŗ>ە|K 3O{c*gdo/ Q, sּD[3fUyϼk?{==LGѵ{V+#'=[굔)rU ock"ab!6 3z@cJnGXPY֤ 9h`Al kOF?;+&7}Itag8,n||DXDHȘACCJS}k0s_uZђ ?WZvŲwęj;*a8c;xld뙥&1(?I"kc ,si}Z_n@k^4gVРu\sy^~4mNq9B(Vh4fH!ڣ`R,؎7R_k:v,ˢuaIV>T.IiR@K7Ps^8̗[,a"+;1)/1gEeJ>?.7 YQ9TB@vyZ$/c!\h;k@JyS┾S1< b6iLs:Mop]7y_좭M)w^b>9Sٺ"$T &$Ts7'%`4*V$oE;ʸ{ zcN}Z͠Moh.v)QPQl^JUTARmv][S%HA;)ጃХ _#?% ̅E@ɰhcQ4.5'G*$PKO2>QEVDs٪O:6cHYx±%a>%fK(Ru!i nݍ!tiԓaXN[D S2컥 /piup5QGy7ozHw^ HUULf2 6N"rev H]Qǂ.b';F /zanWVH,s S*YGYR.=MaVZq0xz5G09gĈ `Q~$A}~u>(5ԍ! # E"ل܇l➚W Uhi&4Fy"؞4ڏ+*BpGs~p=poauavuA Ѓ)y4D"}CXH~d^l)'һ]K89LUKɞ< __1{୨"}4/or= ^ yIh&#qŇ]v AӇmcgeƽzV87CV`7p;" KAլѶ/N@A3a#)|־frs&̳/9 .AY >̫#1 mϱ󋵧U‚-/<R\,v<(.5qApݟSvk]WV ?q߷Pn.""3Bm]'xi~&(T" T,! kd̝OSg+dpAˏZ(FG50I V'/J" 0݋>:8+n~Y"?Ѷfp~Iɑq퉦/`Լ%N !% P=HK^.kmm꭮h@VENmbR&m,Qcs/|~yhgA|V K\wɆ~Itcn/rY B8)Q<)]wzj rt;0.0sfTߓ̨H ~ =;m8 Mqdm5^sc?͑R +L[",k$shs,o ٩ROo?W-!F%|RmIH( Si!2P𯓭x lGno@"J>TFEI#B CUܿ9Vȥ2GVJ a?M  #b5om݌{S>^[}/-bԮG/]"VQj&a(|*BqeM/ga* 췊FNQ aQKZASΤb'{$ښ-27:EQ zzKԘgXQ)kU;K+BK+R)O:eU,gtD; xV;O"~Fuw iEia)eLcݍg:Uv}}_1L~"K_B̟_K,˂Cq nh(g9s:xeǤZUl&B%I".r!|˾@IU]㩂T=jםGsdb[1=DY>CrX1P#<45thrAYSs*9*]@\-:/*H%.E Sol^-UߛV ck.[T.V `s4W`8x z@IVScsu8I(6TqilK?43Qm<8c4&ЬVV-f]oX{I&nTDmB 9;vinass%&;v{ ӕ,Pkr6C[Q9`RMNB%pT2LpU (iZDS@;=;wc BR.}Taf]77"#i,@| W52`Ź`_W*k~)ŧ?@ q D#ǵOlZg)PϪ،`/B'TkwR${dj2$ ]uo0wc_6R NyTݰF-o؊x|ևLXAbQ)X\Fv @$}I'"0ߵ3N!Q^N;wFB5*n)(^Izt#f*,f1зDrFT \40||JkK:O3.$h0;YZi/~OQl /q7oOV4Tƿ\ _|_ Lᓅ'N2Z@S' tL`{Nhϻ`rNgZd]/ 3qTGikMյ%ݔ(89Ey=(MHֱaj@AłeWjo/nrjgM윣;uPSc$,p5 VC1(0@#<֮ xAn8<[{Ƥ_.El@A`0{?_@zsZBh Xhh Əse7F͸_\͊%CmE&7[:/8_wȊIی[nM.nF;۲F*Dr2"$C%' 8i~ {hRʼnNcFFYL.UZcͭ+)=_s(WS8"*6*̊m55fɓij 2:ځB@ֹ4yFqA+jAo5֪it :V"r朲Xӌ%-N-@G整15KXh|VaQdߢw;p1\vx*XW 2//T?h_*ZDҔkD!9 0FVk:Tf2L0W+ 2F brMkC<1G d~KF0^d\􌔀?!JOQ6-y&}|+ˈ9Xbt8^ ({ 1l ;hq]|3 e%pB -+QFk/)mC;n3kN[q T#b>y]i.|BUl{39}.>Ԥkxµ%khʫLxI /,q#L;fbLa5SycC7CbrN\,ExZ .5D06#P,9ۡ‰ӂszZ6N>wf!sR9429fbo_1Ur!*d^ rb1&N^-Pmpx/rx//sٺrx0' sx0z*ăHn*P<…_<0/y*>d$XðfjDW[*2B94F(#!P0fruwyXl9R.o!Uz!tXۄFq'6UYdF@(iby;ZHQg v[4*Ƣ0[.AEf6BY2Jlɺ-a|]F36b *^h%>>:ceU:qoBrvf!>fVώe$,?{@ c4:ꞙ>wi! v kz"BvXoĠ:GݳfԙL헨Zq4ߝ}7(/:}QL<_|oS5EFw'hixs+c?8):O޷=~*CL0ttti[1x2Ppa[85q|";Ѣmh,d0c%n7ߦ5u#mXmѮA䙏 .z@pR}Oc1BMDTRA _^5@b}^Q&`ٻ$j"UfbOsۡ93N;ơ\?HFLOJێptG\2aJ/ H2홐f.337*ĸgv&o꣧ êk漡Rx3<9XH<ܮߒa $\Hf^4(TICU?6WL0W+ մLwvYrY'Hb6񙻇zl} d"z|ۨ 5 vs٢C#h ^ (c ۽lj&#8pJNôWȍԓ-( [:p[#gb->AX2]5AMVz}Lf_̻\9Lqs#(g""dr4'Oҝ?,Gd3wQpĵF\]30.Y[ ^XrfaA`=83^i?(o#⣤Enλ/_)0;۝0obj"WB͐YGY+Mn|'9#E_bq,0aOӣ<:;Y̨d~PF"@TXP%P73Q %tkQ>L_ֵBȜd/U T%r6E(JeyH;p|Cs6tzJU 3ʘhTv2r٬k~2$)M3h'kդHj;!4u;7{Pnӎz[!Ncˍ$mZ^O.VC]ܨ/Isrn%ٙA 6w|:o,֓ksiC<^]lRi/,7˕Jsb.p6<WujShv Լ *(:bܢ!&jpۋx MPLU[V=Phߩj?N1nO}+b3H $#pdcOfh(Cշ4;}H5P~(hJAme_q{JFz9avl'6@CȳUS}ʘc4ZXכx7B׳g3p ! `ͽR<䖦Ug8J˨@𬸖~> [[b"mI Ho Nv==MIVy1}cGLF{«﷎wmQ#%bc)}c(Z%;RH{ 岻zqDZ$\6_>56х~a@Fdϳx8ҶrTvN%IQ2ğ` 5dDIh9nXSD|tІވ5%5Bq3\C~`}wc#BDI,7w~pF`k D=Jh?VJ7S%hrE7E Js\˒.US,g H9lc)>ttD4DX" { Шcn|:>:0w?`Of%Xn`;i0Dzc,YO&cnӿޙi˵f^+~ Λ;Irc 2RXz(C@EvHo# vhWC1( cI2/mxZS?+߈&VEj]\- o0y>î.w{mZUH}WʍfV)ױbX$Ȟ5D696ZUs(\!޵X̭ & Qkt)='gwbhHƅf {–DJM0я.Εz|hs;Za讋TUڲ{tu>ï("tj+ig^IP{HnS̯Kl=jKCL>o%pIYoJO/+WbW>ԘmhØ*E@ 9R"8x؝r QmxC0JnOoꥉlc7ù!^& n6hP 9/En\!A0qU.ጶA3S|\z,;!(w_EL9M&ayA`T%#[jdS{ZкYy7`ä'#*$6% %OJ0F |P(؜*]2,P_XhwGCgbRw EN-HxbLTzںQ!{sɰj5%I!8ǨEڠ{,.i|n<@M^x]4MHmŀ3=s69n)a5,PU݂-S؟\mMY30PVce%"`2YI<&_T]8\a@K"}F7-2,|SnaޚU[yd,.T˝t^nwKx0q^, XM3 "զ%tX&aQ / jKi'Q|h]sOB4FaYcbpR"1mXU"h|n8Xa@rsySRGtu1[gGvB3[QlX*Eq{ I'؜F[H[7~% bIZbc3ut!RM3frIs KUmRں-rZAC|Id<θd{&Gu欷E4b =rŭb&q7.є{5fHԱvm~z!Y:W t2{5 ru=,OA>Oad9R5pߥL+q)) O IZ?8mhH3/ ȻD6mzmGlZ6~ק}v0%j;؀3xDBa`u#̧tx`Etx ŒSl"JPl]_%$lO:IE:2BwIQo8y${)jK q0K^k{#?8 ͅG ٙ;|RHnjbC5$[_*:à,6۪[᜷J^1 1C݃[I6R@Pjc{mX d&s*D <=RD (Zw ^Ik,!¯:LjUqF)R dT9Ka錽*r_i6:f=tVv˜ZZ%Xh2f$W'7Tw SayS/*J{m=|6Tdn=2*ՍYzrE _ԭgkiLz KOq[ۓZ…",2&=Ko-;Y2m ` u5ƴm$.~$>a! Uqvj[רeߺ _aɣOv5NFykxByvKPkC`||qXuCJ u` X!`#s"n ntc!lh6x18{LE ,faُB ݒ9 -BU_AWdkUR2Y5':F(?R<$ ?pzzz TbNWDAzĹ\ƯO&y5tLЂh<;\ܵ]^RMW+GEUw沼8>$ DHduA8D[>6#T?BPxQyZ;n3n&Z!ȋF;F=A%cD& NG2g.n5+5$C)Kn&_zWS84ali#rKA70$BE3ky[p@:`^CC;l2W!r^Ga3yAۆC)ȫ;ZT eU}Z7OE~SjVPr0SNd {,-h^9@`VBhOeE+sjPz#VkA$(3ZD޺.LhӺ~=\p*#Z#:4HYV2,Pn˜dypֿڠ"́E_8NݾVTòv`NTdIAB^JfµG 0#bWȨY$DgMn=]Rpj`XT9Eԇz˙},b-%o(UIꨭs[ʵZZ)|3"/=FI$jV9eقut$!BЅc4vþPĝ3)Dv}5f7c`60sRHJ4>˭rr./NוR$9:.{v<ѩ3;T3kYAs؛p)8~I9o93oX,X9}{CFJ1;~-fd:sw_ـSOߨ#(\ꄞ9nTpM҃ (N% DACzO4UJcIY}zTFZ@#^!"?#[)*7L;-+>nļ LJ +8j:<1rub:Dt{bpm-*," pakrx^#kXOA%ϛw%te"DlxIo졆˜Q :4?u3C48z)x5HU~N TƽFg3U а]6FF"Y'VD-K(-{O?fZQZRbors]}tMn?1o5\p=+nFT DW(uYIY2 ܁ ܪFz{IY6I~wuMf\଺^5P/̪#-Ŝ4Jo/DBy_Y`#fޣ jf%9 kTtrigZ^bbnYHB1sgГH?h@~yڿ8Y/h`MDnk/l5-ѐ:ɱ봀jтͱB˳1VZb^:rTmܿ>I 4W̞JSa["8RNZg d@T9aR\&$9z* P)g%ԒPJt=>&l WV !EM>a: džWhoQ,"ɣؙ/}ɉmpR]0KD B<}]ҽE>یDιU-:Hx;͙6𠨟v8Nm= 9gJC\0!`0\QGLayjӦ+r;|Ms~h9 eu0Ә&(Al_ߙB|i17Eq .lrѩH!FR[#1k/O59{%5P ڟtV5^ϙʫb>ރ>Y4Vk3$㢮'Vee FEN,[.[;l/Kʶqk{4/5%j5Cc-rA9Y <τNaM k)O_G\F%3^IRPX)&8#$\T3m< dVT?-Hg /P*)V\sY1{Yi.37½ ]B|k1Ӯ4w>!?S}{?#&4 %ü|!C{%DÝ"}D;`f#%$D巈n7N;FsV-im`yRЪu@Glx(@5wHڵkՠ;ZMMjWJ.LྡH@q]!F;a;}̈́1(E+פ>Z1[bE WĐM~s<6 tSsaW䟎U"%Z i1jF,ѤEuTz)6ȑbiRe܎D|x.rx.x.rx.. lf!J mb ]MwWA!uI^1b\V.s`x%gap:P>?H/hY3hH] 0}'gHw2 94FCc94Frx/rx__2X#BB,h(>/t0xfP q,P14fV%PFǗ:0]ݔXLj:w=qC{&M/և;PNKfrGD)I@eFRXF WJ5$/F|S܁ap|QTk-GjB ~I F#INhR׫v) x{\PJga.\ĵ7Kbm-0Ɋ\93gqןӁ:,.PȎ w؛ţqJQ-pc>ο^HT^X)fW X7yoJ[F7@b1'0\oXlS@r"˚>c:79,ĄGmpCݶ*ړEO3l؝,+=RX+#i ъJeZ'i<#ćc\*jʸQLfEk%[J^40n#ܻM3w3HQ]+\,4Ēc^QaFUUՙ_Ƅdg"VV.1".ѧL!pm%(0f͉ ʠ|PwJ0I J+d&IP,V80X$#_e'*߲y3;EXd8"[6{dI/N$PdXLk$gt< m'^ae8Þ"nX$r'M)vhn:A?(ٱեg6ӭݬ_Œü:}I|4>Se>/#펎:풮Վ~q]ԇ~3qs0:<" 2͹4*6ئ8!Fw$ n.dNn8rmlV.Y0M l$̋pjzuGx}WŖ[&L8Yx䝮O7J;_oo%= Ri Wՙ'NbJDj1lY$JDU &T&+zP6믉6qix{N SA%2/S7X-<@ `+N{Mk[h88 /6U.n)n*~R+%pN ܳ"d C=HFf "o G\|]7ܹ_= /+߲ӖѰ8ރܥ-aVcE:+NH3QEHv?Q%™5!Gf%?G`t_5OA\]G)|AT0ܣۡQ=6|-Į-*"_0˙>3(QΙܡQQ L$Z~* >%!V}v4]\S<0QՑ b9wN@ʲX.p¬E7Za;I%,qn^^D,jp0OYaYyʂ "> +V @;V Ј蔜-1R!D9U+Mu@]6˵ ~-˥Ǒͨ|̈6=W| $-&&)|>z'?s?gH:]{{-6&G?i,T TBѮ1o8ecGᎺ`7(= gdn~7x\D*YGNGc Fc.5:Rmwk] nV=iԳOk ^\h m"'YN>x 9wF0`r{FH-ފyF۳~~P7ŌEUlu%-ya]8 V74 PEy[IxF6d-"7фfKF¢B`ۗ6L6llI;?&m6DNHpU[zv\F#l61rIQ)!V"Nx4tAuo˓JߘsXS[Όқ߅Xx _JȤ@gZ A-6>+Y=ZH,zA 4Ƙ 7Oes]\557~65ryQ'~6UTG |(9~l,y&dȖ׸Vk2Sp}U[䅃Op+—F=7-Cs` BT.ʋs񾹀׻(oqf a'x=@hf93GL~pX' 4@We jݽrOLfg?"O)Vc% \8'ϝ У1"L5^M;;g*V$ĈXbNƔKsgG<1*Ub= Dr0ޘ"񹳉\2-gU-\xݲG<9!d@T@QE1SpR ۀގ.Z0m]m/7sw33QF$GtjGabnJ1\90eOqu9c|96DQ(S@'v 3`h17mp~RL-r{Dfa?K} KnKE ЉScP1ō«.eBdzv2W2NވՍMTYFuaXGj@UXN}dhQݸCg%D?zUidY|)] ;54ngwӳD#``jg½-,(^1kvSk0D u73M_"Vq\=bGw/0ʶs]ag?}jIPRt-B%͵*g,ʬx`fvcFHPmQrmm-qP}?q4@7ywϾDG@[aL]!1Z  !hd !DD7 y1`d$ M>ݸCo?Ɔ`&Oq2Jc "yjU|Pk&K)*s|YTfѻh\k8ϛiC儣J܂ppm/xQYqQ]/O$'xjHopmϢAlsIXkHL 0o4퀘}"mHHD4AR }Z@t1=_k(iu#]9#GP=hBlGhnUq>d6{>chRq#shǓFpo-hm..FuYF8Y@Jx .j=v+b% V0l4H;qCg<'!UaP XNҝ;"#"Jjz;]+KzeKs.U|He@Fl*}(][+ȼZlec0@>ӸD'jh'٪̾wNYr42+>2ڵJhadP&06~I,N`E00l4ȋ*yMw"ÉcuRBL^{(])64b3#zDa'h+~29'97šip2{xt]'_4!|6=dK>虤<5 @_ $kS'3РUjܪS`X8|avg9xPɩcSc'Ǝ'NS7NxoL1q'P>}T ϣCZe Fe9Kގ}nj!CPA}P.7+}52ʾ 04V25L$5K!^ە^P"94Ș! )@h֒Σj[Dǐ;#_$;H@]6ׇJDm?0Eqb5)/;W%GE,%70p(IQ =H$s9ԁG ~5uuM&wrF>M^ŃqɌ-: vnvvK&~u~ɡ=wV4V16#xщT_OenA Qj<5vmRzWgԎH:P:9&-W=|ָ\kTͺG{Y>HI6zފ}a 1q\ee:~w-9="XY+A^ѷ˜yқcCN$%{JָI@"-tKbbp|/ԁeLmzpMSNLuZ=)2artX/k\f| d*B%,n-YTae@rz;)Ź"^7;1Nͫ9A3- CXڸ$=.EٚU T;#zrWqbv2mKz%]N$=ွq4w=ל$bi4Di!Wҵٓ0 "$f26Du_C;b|ԿWCZO]y1 whGh][q]IyPXdFد6F DL#:4diS͋ܓpx?Δ#U;_k,~>;T(?`਋D дeA ,ye֦v;cCz~6[+ŗ5744ML(P6gc*3E#X'g;sʂ\}E'X,8hW;;a#;߬_=4$7me匼Pd(.)j%Z1t_,ꝩZޏBnڷ04Nk$]e EaN 9:ykrbŻ ^uŵѭ߅LZZ!n&f B֚M̮@Sͤ;<28 aiX ֻ7=88W >]Qc,.lu>wҹ EHQZ./)z0+~Aٸ H'5 \ l(jxA c6]TKaPcS꒒^HħGjVj)+H}[585PWI|rZ~7ԁJrz+N+6:5ʫ:Y4~0A'n>hd],W*i=le9]oV?+YlST( pOWJB^\/5Oo]?eYc3 VĠOP¨,/@k `~fg~6P}Vj.V p_jQMl¯hӈ+#G1\+'ڵzZ[(/+3zXm)5c֘u?תYѼ<خ;iO4