sssd-ldap-2.7.3-2.el8 >  A c 2U]gP'v`Z-D~z<-ď4ỷ{OBЦfF);lF9S (6]L\$M_XnӺa\%<{kXpeD}PZ-rW,:=AfF=qk&Sk%ټY%}7RUuqhr>j-+SȥLwSliOZ\G{Uy03yC7(5- ImVKWb3aIyfgpd`jhSsQ)\%^mtsh7`JzPb@_&=vgw|쨸BohxWr/gP3.͘ϭp  g,sRlb뢖ϛ t~NzY_ZZ`8VWX@%RR3I5B$Ơ¬h>f ٿs/lF2'!A'' Wd[٬2RṥrYR^294c6e8262375649c78d36e2c7074a66863f181b8599e748834c37ccd6d8d3db911cef6fcdc045f84c0a16de0418a72eedf5b9e6Tc 2U]Z`ថ[Qķ0LTCO5OT<[fBCԄaYx-qm"S2mNk~.,]wX$g!!Ͼ [|qe'3ȦJ saWGG J癐#1xC>x^Rœ29cyh:E5"^ Prn4{Pう:x)s<[rW]g4Bd1-,-8r bL!g0%:]Y@%ЀluYEB_Ҵkմ.U*ݮ*ya4m !Wvӯ2MۖYJGv͵FIj1Kxē6H2'ba3շcy7&L 'Cm%bu\s]05tm?\[AI00l<'Up>p??d   6  <BL      X8T// /   ( 8 9D:cG}H~<I~|X~Y~\~]^& bdAeFfIlKtduvwxxy(Csssd-ldap2.7.32.el8The LDAP back end of the SSSDProvides the LDAP back end that the SSSD can utilize to fetch identity data from and authenticate against an LDAP server.b-aarch64-01.mbox.centos.orgfCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64)KF\=T4Ar W@AAA큤bbbbbbºbbbbbbbbbbfd6eeb030a9d04fc748ef5a77b77038b62ed2c31e791c47ca7bdb25f8aeaae298ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903a3d268daae60c7c31ebcc72f1b89765dd02cc8ef4101b4bfc789ef340af765cbc366c5f2a54037c6e201c5da9c20f2b2e7cbc2db1405d9398446192cc56a41c170f864b83da139eb3a95f9ef93a40d70b948199c7860d02e0e732ef529e465bb2527d690fb555a588070e6944792386a0f7257c99d5d8189bfd1c7c3c4293337ea63e9b5a43a7166b5317231ecb0f28948d9b9fef22273b05581d3bbeeccdd5f4e5c635f5869888ca7f55f2d17a4fe28fb7e7fb590a54ad7aa4947b720b6df9e1178e5b737e236637a45b928a304874c6b30c6e9350e6aa2578d95271c4e068e219e8294460555688f9609d9679da65a2cecb4d0871ff5367372baef1bfbf6aa679d665dc074b889a0c7ee9e0ec7b63ea1dbf1986e7b81b168d6b33905d950987fdd911f9b50b176286b38d5b520493cd3989107e8c23bbe4e4ec732323d16a3../../../../usr/lib64/sssd/libsss_ldap.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.3-2.el8.src.rpmlibsss_ldap.so()(64bit)sssd-ldapsssd-ldap(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsssd-krb5-common2.7.3-2.el82.7.3-2.el83.0.4-14.6.0-14.0-15.2-12.7.3-2.el82.7.3-2.el8sssd1.10.0-8.beta24.14.3bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) esesrurusvsvukuk2.7.3-2.el82.7.3-2.el8 .build-idbc480a5205a2d2939afd551108f18d9c7363a55flibsss_ldap.sosssd-ldapCOPYINGsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/bc//usr/lib64/sssd//usr/share/licenses//usr/share/licenses/sssd-ldap//usr/share/man/es/man5//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bc480a5205a2d2939afd551108f18d9c7363a55f, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)(PR#R&RRRRRRRRR R R RR RRRRRR$R'RR RRRRRRRR%R"R RR!RRR+utf-89c94d6d161a6dd65a9140750bd77a77bcca171cc34bd7f2d743f03a04fed6c3e?7zXZ !#,9] b2u jӫ`(y-o6pvb̷f g  _ zSU&;[n4N^9& RӾeYc$ҵTW:@:Oe<8PEHID\ZWMעqc}@R#"+^[|RSH5¹C0uL.o Kb]↝T"TV6IQ_I(= 7uާM-1y Ԫ=R=|Oݝo[ր P^ qMg(x^(@2W8+њ@q%*mjq=pW0V3G0 X ߱8 Zx6?ke\4"3ɭ ! ll썱9˰~FןV`[-c7UW U?ȟfinƊ:OzZv.˂=> ECP/LfNj1v;G ;CHgiCԖ{ 3^bA??ܩ7F m@uPTX\eJ;`xNϊ 9iLwaq6&@e۴и 3Y_td7*O ٶ^(C br:C:ɖAX!zqP4F T;C}M=sS\C 4YgfBS@*22iz#2ָ6ݖ&/#(ڞ-tUy]i`B5y%)E9APP9nPZ3H+"`W[&YJo4z&ԊAOQB_ӧCsW \U h+ׯLo ~36P/5M/:N̫=m~:' WaGV iG.@pj[ې/oˍx,u,EqV wdõ.]໙YEM+{vht4fXs^K;|+[`Jl.dݔ8Z7^YЩ-NBFlhkBM4NE? l`^@ SsTx^o>RSc+o1`OXǓF<Xb\rK{<^$[]-Ad`Wr,7pލ$]Ү^~}fn) m%ZŒG:@E|5RU훛k "U< H9bm kXm5mǁv_ʠD4߅.3`ObpxGm;Gy':Ep4<)Ќqas?AlRkQ;3^Ex,i~$cSze=zo?XmqnLbU2GV s'JB'0=,БAIpM"Q^V!(.`\jQ%n?z rӝߓK6ڮm]auJ39\{# R:,f)_BkT* #?lND]RǵkȤS b1L^U9z_qSă5oǥ4uɌkA"5NCd8=G=`͢+sPMXSbK.^ݝǦҠL1 乃\CPB*oo w9y|q<6P%v:K){% c=i>xk`VK@jK5B1gbhKa&_졜 W"JEw3@'f-y֠=gB VYAtCF draܤU%kdgy]VbXkE ߵKw:v>\|%^{Ȳ mTǼ{{ֽNݾaez>X6MAX=W=H͑Z@:f˧e3ʉp򅃘ۭI4c酀GNgqzX Re7Kt3R4h$L4Zֈ%t-1 J^`XF1bCN}[9D`ȃs>y+x| 0:^=2Az]U|j 1.L#V L.gZa7:]FX c yUi H.nQ@۱1)L6(z}R9ZU k; Yf\SRGn&g)6A(o~m# r޶[d># ɷ֩y5 2{g\6qN?e2HΝo\\[/@0uZ*ӫ/#EFɃIW9 T,5🸺בw * JgI?;Zh/ѽp(F! v Flf<.y O9>C`uh,^%UƯ‰ ͨZ>$ ]6SA]KZhJ.0UGeV]ȯ7;y=K1kٍp* ,qFLyꌪO8 U/*H9R^ڐ-?zu@6^ťU/_H0Vr9s*q νsRO߂Ч\~흞IUޢty,1Iбw}z|OUAjkCi ^ʥ}@R"SfyqO<(tߛclTF+էGpm@f)j wQvKO"2p<`ZSоy*3`rČ0fJxIbp)IZp ?,>;F!t+kmZGiDvp,?!k3zmkKKw:a'rx%oidW5^!rY*ǐV^e8[@Ƨn% Vzo2ԕTO9%m䈢N/6:@䄀',t)+{RxfFpcU}M0Yުʖ|7-c֧Wg)_yaTdi"89 _=]:&=*+ ~-_ј+c.9 < "95Wf@~..rtcqyb%X $Qsr~i-5'U]dߒ4n/༜z歇ϼ=K(ژ *4y5cLhZ+YG݋Yc zJS'.M*}#DD;Lb}}?-Ձfc$y9*H8AOSЪxt7oN 8[F ʻkC M@UWrptaǵ,g+U Wo~t$F~ggG?DƩ&Dh X$ YMz70bzBYGV*ثEfYq$j$ p9I?̏bu"̑ӣo̝ڼɗHicl' )8y KI L?J"|6.HE[^iYtx'd4 Ӥ2.OPxJTm:Z"9=!zբ29`#a |'ƟG't*$-=r~KT`i[{/r]߿+{IͿi(-|J0Y-S"Nfl%)AgTDerz.,П92R$B}= z%*4zX@]p>W l<|ug@k+>>다£`T@G\*l>^_s/sv=p@2C<-:c$fvDFfS̡gS`Mu "k@D#EʵYCn'еh.I2#hnC 959H!؁4UH1fq&p+`Lof뺢$ġa/ 5v%*U`#|^1xJp{*+H+ǜK4=s x& r;6(p#<<`H6ZǢUݩ6+V6C&3KZ%Ě'TY:MR yPr̻{c- 3:9fɪ'z0,7ZC'rɀҖ^_%^F1AȋRuOhtjl㥓K Ef2}Rdfx[Qy30&@9++" 䓵9`4"bt-8fс&` T_YuoiɥFԤTK L9 z=` /M,1;ԥ'tdu6ڽ|6vT願5ayU( (EN:?nM+7P@F5ځ?+e|IQticG#60Ṑ_w.B) ; HϸgMJ4cfL/3l- 2 Վ{*ݚw%0]-|e8\^!琚3Yu umkʋ#MF7dC<5ꝛ1v&I`a좷y8Ś)ž+JzYħA$ࡖ%/aoAx kal"l5fzB|C4X(O~ZhIIRcJp&EB24Mh| hG%( )-ĺQayz* ;nW8)RpԱyTGrԋ5qa ߏ x^YBou2f2R۱G]m/8ZaoS>pAQ-)m d N瑈^Ț@FWH=0J,4Bۚy $bxyP8ta ]Հ$*$97={蔢KӾzY*jszOBPA.Sv "7$cֆzp906_& za& u2 á!;":Uy&uGp3N"aN[l}pU1[s5VҔB:#0=Bs ot#nX,e1 ]}{F(9 W^[-5lWg{GspU`4D/H+Rd͚b# V5ÖKl~&(:!*7܃ciqDZCZ&o6E,A#/30];*nz6NѽDjj.r_wŞ MjAA #PtXx1 p$5Nieif -}a(NH~(z#GHao#s!Ȍ+OQ0H}᮹@WZ?V[YYp(0 ao'e̚aDC_Z8pL}_z/E^ 9ۓб .H sTv P0vx>+~'-%k[>i"~l^Nh0[Ӛ@EV<}1p<}|YhRLo#۲;Zw݅ r1/B}%(Y),n7.AD丕b`Y&1.T_]vd(9U\9뀐[;'_z/pűnPqpNgS[EwQ! KPo |]DUTˇ*A/q梼"I1?l#!(H4*b;U)>K1YD@ v f0(6MPܻnqf&Qr Kʼn[aL777> c -/Ζx502.)fiTwLf|Q[m>[} ؝CIwTf\'d4*2pJ"8âL g /YT plu7!gPTy*KxopH{1ǜK *im2!UC?\=V외Ոht(R)@]ROo.M$eq`B(#lO?ɝ*5Oخc+!wHMD w~}.K͇C<إògODÄiv56QH2&'?_0*D51 S+Xu֋< mM}ħ OS/&M\vl,r\1@2hS~k|x41oKӄZ3ĺ!CJ% –q\?%q)Wr b-H3RzRǸ *dޚm>SW=^Nktw]r+,D%[xA>sY>|q~m3~+ٮJyΚk3QuLZV"=71KyBaS )e֠FF[4SoGW6S5/Z⸫*Gj'<B['O;M j7|Dinr񥓵0T_k j/-'#*[HYQoduwna`Z̤P e a<ʤ oVEI5N3%.3YJ7ko@#e [|{$jsN Ҹ^J*F x~ϱrX-ĩsRkmk+ Fg4!i*յ=ÈC<D! U52O6*ok N󢘩n Ѐ$JJ0',`2%̼1Fj b`nX6%"ڮ7f rBVps9YFdx z|U)5DHǑȅ}`C h?cw`觓nkQ9qqF}87/Dl-׸1fbE\`<Ӽmk"#q`x|_Q˻YV.@)7ekx$?>SFI.bVmNAJ**ɰeKؒ;P) DE^X ȸ1' ܲ@,EyA%Km;Bg VyY[ד<8v癌n+(o(ޣ_L- / < ,fn2YB!SJܥ&dKajv4YQiN Y>,9q7 +Ka*0+{fV 'PނWV{\xc/I4Fw{AŽ ooYyY'h붧/DiVS&LnnE +Qֽom!Z$tDȤgvyCɝSpfv) ܍@ EP. XTߊ>L[ 1dWN< AS5nr5 $CH@^8W2\sSɛ{,4ε0Kv_$𐙥q#_g}85d~r]PS?ZzDuzI߱sP8ڜb#o6 O!Vih#@_udK&`mx,b{3W [. }>[7=(-":G;fQ0`.1%L`QQ_KNz3SA3`[i"\,5h9~G8 (Z8̪g+ڠEW]JgTn)K ̨>@r ⠻)<y͞MM]6xjڳI-e_N}ͽǹv5 ;0Z&$`'NIxwROJ-;TH9PAa~cQ0,W  55,y˔e͈;ɬgtR;91oU]^dJzizJBDص'p_]v_ ls:Gֳ:! ·a_JW+YX)K?p-$),Q{ҁ@Od 煝3UVv K'[mW!FhNh3( NB~$ޟt?Þ?$p,F}Ix"Uck[z6&qf GTwrgˎ#HNLO Dvq@Dܭ8ϡ_uO}'#$ jkGh>l`lM]ҞLh/1g-QckAeǦx>1H{`իކ9rxjfm^Y=hN9U_P$gƈ8~4aR08-utʩڧ::!hktl4Ӕ}qANa?r'Xm5E~|ӫgut#o{Hl!v b WJ~CtPې#Ǝsi6=9^?sJ6sT q-X˔J}.6 (ޤj"gyRp!ɟ$@ 5#ʘ"?z624NVtuIww," UdU)0#PXV dbsulK \B"s 0!g>3B( "iōRL띺 x7V}|-KH͞iN,4*hKʣ9 5‰tPk~H ޷[w gk8]^BbĀg/Rhk ܳztdIzE񛹾SNZ (2UO/>"0]+Wl0B69h(4dLc(`̌RKᓪ` {;;Y:jbV! n8s?q^Lax{YU67chP'xv5t3c!V.% ƞzW^˫ VګK4-F*4bBtZ2gN!$W<g@,W bKP 3uaQl(=FyxaG'y߫xэft}GSiNK8Lb@߃v Ɨa\hlb /21ӭ2 ZgU7zsðSup;k:AQĪb=Bq2oF!4Z@㉅17 ~;~ia<5i1@z|FDD\8D28\%Yӓ27bgY֦bWE$.+̈́KYYU]rv qƯ! O<~8mZbջg3ۯ~T4o"#֒6c%xSJL ,\AAUud}ixn)+.%6N TJ(wFF^AY>Nkب)~z_OS]yG of0 F3 EaN&[E98'?QIR6_E?~ aIRYp r+vek RX K!NY2fcDzczG0gemۯ72&Aeid#z-LV2+E1y䮍i{2ƑV tm2h fJXwcҵbOw~ˎ= )Cw4gRÔ)hw1MU, a\Es:b wzh`8"׏ ^8p㐟IF.MH W|7G&)bOo~͙'2J"7=0R%UN+4 {Gf3*^-̖r{TwrٿaDk/_|- {imxZ1bͤnŀE?o yJqα)]#'pq()GNw+RL`G% 8 YUx(&:9VD(r5~x<݁s^u?J1\ 0܍%J$}` Sp ݪFrp*]dc~3(1do j*S'XTiK-J#_Q J{TH6/-zQ-h5R ܵB>wm 7hl?4Iq%2HgYɓ=BYcK*ZLI[HR*ڹ!m? }bn OTwYED\96 ~|Z- B q@rOkӀ[Cmp߀ϣd,eo-:A~YAvMBv?@yLojv8$z5ra7anhCYd6}g(vg&Gh B)Jta_8p =l2J@<b8}'l^\헄e; ˂F>r(X̾d)l+o".L Єzy/F1Wq?33\YV(y$\=xLX~f79Gh WjwލPW)/%aOL- NPUw;80̒GTI9!;NR~1Jꄗh5>*2~Llrß` #$vo? 2cS07c* }8MF$T|\!%G'ѭ^7)U۳DH}Ҋ&⏲dTFr^Lzp/H WtpBOusM ^?:PÏ"3 yҮ@RSB{Mw`42h`9wYU #Pk7yb#Rctc~\SMjv3Ǽ=V>*)Ad$o2 tc%[`d\̷ J#zɐj/* xw.P'[n6=lӢ79&4͠.~YMZF m @;J!_[%Vj{ء^SK/+-8w Y* n'ۥ;#VzHǨ෧ڰ{H::>#4XRtL7F sd֌ahտ!x< gH鎪Q5j, 5K͓ 4svooXdf׮<$8}p=5M2D,%zm c6%wiԛƑ/u5]i[38axYƱtۼW8C9 ,|} p}#/sbH ͽUԗcqgE?ԻjtgyyItEwGŒC0~5_x]jӸ9'$x\,[mzǖn!n|ӳZ^UMJ]'IHo#<޹@̉CI 7鹁QG>dcעYۡT^6F;#yˏ\^-w?PQ޻CCX*`w$ U2^v—vC0'lnwIVtWWqV$; 8E.k\3"Gc4݊=ӝHʠ+ņ9i| m!>>+du΁ 3kΞ\mEUڻ,֌ `a~UZ\%f߯uH?{=6axM O k-@V2<[ir"}ٵ(%Θ' ˟fsw"a;ڭ2fW*q ֚c*K4)I );dG <>*~1 xZu6DM+EVfvzMҷɢ%Xm3G h)߻锽eE]BP6jIb[Bv֍Mɱi^ZcXZ]?a+Q-`-1ca*tE`pIY3QJI?r60ސ+2j0֕~d1~ӳ|b_IcU2t;2 3Ȟg~M83TC n2 ʒSa9N+kB]oFzUx%̣*BG(9&@]E$|GÜ+a[^Ui=|VHwɧo/8Yb7Њ1[Ѕ%fisT3s޹x`WT2u$FnxU.aЀܴMDvOZ/܃Ɗ̨a8/P c$EpC5ɸ6pDlpb3ggfX:^O.:vS.A;u'fl3dM3qUqO I0k.5:j`OP~ 7<\dL9 "|2\SksIqHPzäp3DErb~я EMr915RY嶁yIMs$hnŅ3k{Y ơ--cz)}IEoyB"% b1Ð?L }spY1{`Ev ֆqŮ" PhqHIޜ\q6>i4˨ \NMԬ`i;Axږ9E=N D'߷3upN?T*ؾFNi ZK\>{$fz2_Gd" !lihp_"2W$k0~Af%50cArCkf_,X\߂g@/"@].K+DF'2mk<+P BS$7kPqeϤO|D\prWu|40ńA:Ӆ4S "ӽ),K@? ,9##k1, nآn<ڎ Y)E焤Np&sܭ>5;\=:.Q9255@hKr\Wt$9Ydmqg.)ϭR4~ LYPhetaPBc(J(!}P5֛ݲun0Cy\{J۱m}4<BdVJ u)QiCTs­yN$?It3C!i߃ ? @[L%FjT'ǘ/GQ*Rbhq fx"9ӐQH4% kۆKIm3o+{fiX&3AT W{Q!l04,.6&H%IpQ~3U4Z\9ԉ; 8qx{X3"WV.&HPou!aD ozSBEHL:ؓ7x}^TĠ1"hCh$vD?|hx ԈRuƦӇ*{} cfgB4vؒOii;6 =͚3bKx{?L)^/9͸(']8n RD1_! G:we:݇Ib,Bfc(6R[T0ERoЂ@.hAƀʛMW=-fR1lFb_g=\bt DP,mV /sPfgucކ QWd<6'5zu-m3qp**9($[ǾO_,=h/dR/E:f^j*-CȷAj&. . O(n"yYAבBc4rx'.Is>LÁ1o {N_Z (9Jנ j[AA/.;~"քTځ=(~:8Hː°FP_yrnLQ5RŪ}MXL%5Tt3*,@t2YR h2a k0MG+`1A"RAJnUM+KhTW|2<`6"ESәMQ4=Trk Je4EgEYNЎ~^q0q%?JԈJd=$*yk߹:vNW`i|@U%l|[c ?O8&Do'bw)靔&fȀDiDnj?qMMޠ./;i0]a(0}tlDzqrWnN./u`Į[g`b3]U?t Ӫu ½Lb.1j˴B3(w\$ԫvv ߻5$dpS}Fd4Y/>I?wԲcSK_d^vEcYo#!/ .2Us$ڿJ#uHNб3$zH1+˧T%? "xu{ڲcTzD4OBiׂSL>{s߃ZW&sVx uk#FDpgb0j_p-)WWjc)%7)C,Οg^͊!5aD u'yg[06h-݁faH\f3Ec+st`NcoeH~01:?wVT,3~_FWR`np^X䷓ߋ<`3@ v &ک-pݭTeffe֛43*]&0 &[#cIxa/-HJdH<@W8#l443}9>o?7A>;k5,c!w3}&Ϝ= 0f>'dFЀok/*-T2u%oEI6)ܙ"T% ][)O0H{NVU`w*%QWD>{3E$jtʵߎf>;ݺbgMe"6o=.])3$'7=c\o^YSiC>I ;lH3TU4^[}s5;x4΃ԙيN(5W+[ GҬE ]곋&cƜlo@?|݇q?#YM@CvvLQ]@] AZ;]ʗ'8ퟞOS)UA5(5HB\C1{6Y{aP,^sVp/,d"UDpy3=0ˌ s/`*T¥xIM]j5R rRo3VNm{K1fmv&!lïv\hҨzFzfmfKϡ`|l anhuVZ,C@SۘrI8.Iԃv'9=P & ,,IBj'_-rqd_LFZŒY%kYߚi= m/&kxFGz8Jgc@u mV^jYbQ—Ma!2n%e3F.)^HGv^H;{ބ"a)e@C\|Q=mH7e 7[87j˿Y5_؈ej.V>?e틡NN>he[Z{ؕ\Ocѷ_+_/U~# D}ygt2Mt0"hխ\Ժ1~HM7 V%lR 9Y}-#\?=صM<9Kլ'`ؚIj"[vR0nUܘ~wb1[1dhO$}KSTPL)BǞmHDr&bM_7(:^Zjr $Ebqf+*VW;1[$N Mw5_/AYx$ڂuwKL吲{;K- ` 7-T5e*3dü$ r_Hv=;:Q)w~ߔOC/ВKך^9!噴~ki DqK56[ 01BCF;o >`ﭖX> !ǍGʈ*+e n,o~Y]9xI gtZ*o {d OEwhɍEwf 79bEwPltR Cl<`rNЙ34I6l,qP48 4z! Lv 0OzsWn`xV26?s8^DlJ Cq5P>Џ gaEpt^7V &n s;l޶scЇ!;*;2sۢF C=}#\qe<'d`;j ̡4Ϲ$ht?[K+{ ×|%A|; u=/dd 8u vZ'2,8ɱkp,6U#*RuRBF8m)D 33vV@^arK/0ޒ^oäggs@-SšQ)Q]97m}qCt)n]1VG2׊ijf.8݀VMBS9"lE!|I~@b_E | m~SK#NJ&旔{ 7Uҭ!)k. 6kr?']9&dbnSV<ۗ$3ce%o$cB8#vK8>[D8 i6;}iFBhb' 6zcE`iX}=-lĶ\U@yQqW{'0_gI%dt)ݥt$?n6Z]rN_1{\*]I& ^&aq /;hQEʀHP)~aƔ jzhxf uaamg苅*QFN%3nOxFXYKxgˌ\O%OwKQ\ 7č??GS"9]ՌF uэF%ӌ{2U[L Bc!W& #?q/i=zH*x-z&б~1q$#(hR x=e2{rE-Gf`jQ:t Kv@P16MkQ! Zp\]+YJEV{y I0t}GeGY=5#Iuܽ4+kr=%.qܥ9Iy1&knj*?ҝR9QdΪv2rs )u̞\ev+ea>"YܣslZzySg_GIv/ß*8VLkw3?串 /_}="NRU:T|`ɛФ9[svC|1>6n{G=F9Fcmbb8j^J*`+A-ȼsT"iаw5ȦC#M2q?]fo}\C@0Vm.GaFY+0pno}yXfqw@a7Tuq5/mp\17Li"=T"BCח7dWag>|=Υ:橨b$׃"p-:OκyEPG ХUvEw >:i*^᪻8+Soקm;xSh5/AV\mE)5Z9jqV=;P۞(YUZ ,!H!Px^wwǔML?C7@(P#edl|у7Vͫu߄sG۵L5d ~B ,cZ7PRE[fvV;`oޡ#Hq ٣Ss5OXUhC| *n\ܥ.'.x JQыֆZ :&ILQI4[n C쯽szrV-]@q:h~xᾸ"q1=@ިIu^Pw1c)NP#iM-qI$y$ƆLJ!=r%JhSܜ2M[xCWIDs~9spdÿIXC=G4FlV]f-ƏV? ^tFI[=H2:q[XeN۔QB҉9Iy404 LEMU3 aV(D4>C*I%Q֐ydfŮSXCȩɊ3R!Nk,_)LJRz"yhsH,4'BGyvLmd0Q^tK%?U< [Zn⳿.=j8߅{C xw=E╚A %NrÑv͐ߚNVПknuCp3!QqEtB@Y?A=7(yk&)vB~+IXE`)44(t\__rAXIm >|n2<`c߿7)|43%QYyN2K@ Gv$x5kCd7yba;;'SlUL?$QGHXa~ (El'#?>%&e>0XoC(@^F K,|$T ط> FJHEbGt:OEλ!O dKtiZmESűOqIE?Í1ٱT ,4$1ŌH|MوUʝKΘ<ȦoIcIhuTsKWun'}_Y54 &h]bd:weqcBOڤӆ U4mC]#viUTLz^֨ɥ%nLf5Ĝ n0/"F]+I=oyv OSY΂SYPOØ/BQ[pjW{%`k7 &>A~ҋ[{l9hmc48Ү5K"S&=xdj|RҎ;bHx[nuCP. OybI!v0)FH % '?a1E LFƕttN|EM9v!%_l ~UwZlG=69.m&LaD%}+#5 Ŋ)NϖU7&I֋m=wzy*?vީ.IP4u%ygmf\Nf5ݭ%Lv_CQСnoO~IEuN#i2V)G|(:)|2'|p%`೉qW1YjsigXXVt~GˉX%5(п WaN)Uyv]-MaaHH-9EOa=;[u}K`~]x*Ouկk1ҍjÊӴ=P}!iOS}2yRu ޱW ANtҙč77G^n\V#ǯ8#5wf-Kw03,S4ܮ,?=g}`O${ks$n|< v>;\_{>i4d;3^ 12oPp.еZ*l,TwB:J"DI;\\~gao^)'s].f@D8W;Lqg!h҅vtgS#a$:)ӉNw?&wp|F!}4 SNS4nf-VDǗx6nԃsA}&)] vm˭#}=O%mk=Gf:¥YF8EN@7}+S')g濋_EXm,ɢ%(kCYy[Ҫ?%T{QVbƀOD=*Ȗw.rS1,͂@&(KPCNZ0 .3h&tА#n.]Tu7HCns6ch3 fxska).+g3ȽxQj~ŋj  mNjMB#b6&~Sv]%*{g OJ.u?Mܫ #(#,6QEa]kC, *3L%/9H]f(:[Z#cWlABa*ﲝ-X|>3FSU5[8'gQa`ZB|P zQYS٪iUaElGZ7qH["0s @ c 4BP\Hf2߯nhk_j$pխƧ)8]ߥGL,`?m?-yH؀Ϟ$'2&֑Elكuud;$g&f0gCmW%_2`=y^rmFyI?QU{t@.egt{>aV`ǮH" y[.cYf#j_^"ԻVYv ZUŀ?8Qʕ^k]h3">$N?ʰrشJ*Bsb&#TU,Z>?O8;/d8y(o_-00D# LZ';ԍ:NZQ4]i;xj, Hz몆3I`7hVisY}5"Vn=24';R^( h]8yioM_`8VTV/7WYQ 2%YHay ]D| "塭OM؄W6["" <:|<76PX,ފשQЀq`|*|]cS{Sx|`S2^-z9wuWDw[u μybdأ8[_u)vN(|"{ۊwL^ TdLp=@`T>D\Nm1J´"VEI7_EN vfqK/_̠4#u^ vWr FڢG6.\*Ig7E^HTFV:(BI3 |Ӯ?WKMx>}c\dSGO_LF vLWs9>1Tr~蚵=C\zwj_հ-eG kj$6Dp:GJIUCWG5aw If^uVōx}he9AIkl 73-n&1.n=>p4br[G>E: jcpaV!UW:ۯlq$}Y,XP[PH;b|tjal$|6΢>8NJ;LU!Պe=G1^nTa">_pΣLa1}ޛ* dU"dWo7R=3NUW …\EġgwΝ9~Ώgڃ E~{@<Ƥ%4oJ ezv盁3". ET=ϛ!a-7‘s_vY C]#'.w?.qzKȻ'Ͼ$c907p_Zo% QLX'ۨ'؎ iVX CKL.9\] FSSPt H3^ZleS;5HΉֿmIlm ;A:+Ń+4d^Y-.Q)|{|RY_hlQמ* I5,_B >+yFmg}/LD}˞u&}"_;=ǽxG*C}1،Q^&5Ӱ2pWb *sxF:1ّkG7z"*+ZZޕ[Rܚ-+*28bn|~)\d toBϗzJ bw y Y1׿͝7#1+’ w%wnw(z3R[̯G5YyUKXntOjMLՋe;E0cgc[F1a3}`IXlMЌ@yVh {;/ܢP&`xB7K@T"v1[Tmb7r47mW0Z,28+.=\B=k\FeF^+qWeJyS$QL%)e?&TvS`葴ͭBV;Ycq(I2P/uLjEeY6'!)A?eK^ ɳ%jnl,'BJc ׽\MuU幇8H|@}б»$}e[|FX~ڷďak?jb\^O?VSgfFvg-{tI⍟8AkLVf{͸Zg] ﯑zbRF c3Ts0:dNN zFW C멢TkmXd5o9v$u9T+?& b!zеpXW,0s`PjlNyfˏTlc1m~h2*VQnQMuG锝Y&Q<#hM0|كcS$-Cܯ> M44s-C\7S 4JgڦѿHtۥD )+9t$M%.7PҤk=Ef+r<؅O.ԩ!Y#  Gu)kjӋ 0LbaNSv^8gZ$UIp+WsGjCBOȀ6s ScO!ÌL wt}rh)<+ W[iL $enhzzXcFO<8_^̶WYג+/XuiFjqg#H,I#h2`_t dV)ܦ 9t`SZli{B3tB_ͷ.; g2 閙t2H1+]7͊&U*9H#N(ҩR%~щÑ!G+Z\SݑW/vK,zn0QR]Z 'F Ts|~G(S0eBh,i  #9O=z j{r_ZJ":H /|ϝ&jǏ0ܷ*Bږ'띠s7A9O~l S-Oޛ q1݌=ݑкر~uDII6JJXz>i}rsz>4{a |)xt1V+DLS5ǝzqo@]jSB3G  l8F¶D!#Fg&, J98*O\>n`թ\\ q#3 )*Ly<UGѮ)ȷvNk5nM% 0d+-)Q*ڟp]`xuZW`YC:b.iE49eͿ8'XUG{\t$ZjE{y7#Nz}EC+,O>rks }#|~L8!"țFm}{UKR@E9H~{atdfNWaK?QH&lZg2  }$'/,i¥F[lzehT}}j;sOkow:sM4/p^DFkw}xT2*riݣ|_gII6ҨW0MjgNvw2;B+a [sG8U?/x]TzjOѽ9rz9SJo-i 8=УIGXŁ* Qw'4ҥ7ĝeYh sZH/cm81W^Td/]dKV@x^e $'5tf < 4wƧ̓X&2?މUFAo˦ v;N"Éfyzk*"PLS#V>5õGS U7cy̻/v˄TeI]C^uȕ4 ,kv9L *2=Չ! {+5/ߩH̼[/Ǹ1yJ^b2 ʛwJu4DV95뫈YOYL F,(+aG_dy̠]č/k:f/wQwjGYTVI3SKtM [> +=4Wd|a~ɦYd/G۟l$E/\s/r?~qvdQꭎHzf"A[^ļjQ7鶞A."-%.8vQ hXepm?*|cN_Ɵd{(5z] 6VDP3x;``3ohV7dOBU_M\o!o xcՙ:.LOȺѳw+)96b1/B/|Hg=|! V&ZAemVXmV7~Eֽe_AEBMְB³&`c+V~' 9 g\_ ɫWR0Ӿ9;, ՗t녃rn7/;~@fOGB-翤k*H,cL:Q@mr~7x/kجꫜZr6EI(`UC |t,':+dE((ISמC :OY_TS/Cr[0UwRbP6VٿzNizΉ6mNϑ5 ƴCkψ, E_<0~Hvx2Cx3'}xsf¥7ms5'sLR! /0.rI~CM8nƗR*RBEY P**Tλr}ݞ8k%8fͯ(0}>hihw^D_>Bvzt|Q15+Ui穖A]+2)wȫ_H#IjT61Ip9,1#2 B!<^@j ȥJhO%ǐښحXC^*Ő왡6'ay &O)77nKM'K Stۧ،O:{\gn4la4蕩 4f5YO1ouV'?<ցEߋ#9_bB؇[#D5fϥē+!胱W|R'UJkYW_%&VYIeya|cgvAWLQdTF}h2}ChmE^`Ov>},|gCVӎ\%Wޗ eNf/ɞ+g'7fHO@d)Zٗn6'H/S5s¥.ԊK#4k~9zl1붎L ruߴ' 8KCmǺY!/o%QCGh;{qnJm-rCNÖMYw$mҎ7 ̩ݶMl11~[VjuM;Y'R[ .?3=JBNzO b1/,:}I%>&DgBe~N_uI~m{N(y4jg\xEE%H=!9^C:vwEeɾ"I:_GR73Z0FzO7~mgD{WxL7{ʇ%"'5IsV W,#،Ux;JӶ01hQ,t8Q(9Pg~ PXaKHeW^{,lnKe3%^ك3=]!9@Az-0 {;^ѻ3?EmfK{'}(/!-D-+=a Dodp^wy"u'Z=N#* @: ҥm=up&yS;jQ8~LIeǼ̾8K;Gk85Ըo WRʄP+1Bٚ4C3 6a&yb׶?jh[UKQ(Fgw @as9X$$mǸS9s,8a)N4o}__YX{`Ä1K9-@;-Pc~٭Y5n'A9!5Ïds 99k[Se[<,\/e. im-թneA#ԗ&r=V.zI܆侊T;u౪o4Q,R䣨K8P`opa*eE cd+`Vr:@ ZGsXKӟ{}{㩼靵LTJڡ6bbPB"LDYt8< Cd1RjPe%BR8PݼZSp̬}eځȉ5e nmx~:˭;xn'WqxNP{Ԟ9c؄SŁ9=ި@24mky{X}f,o֖jn>"TpODR0$ ;1KN7Q]37rS欷l|O뉨bgQ_e֔MhQF-=&S8Y ph-WwOX5rO: _=C2gQD#-俄[G`ox3cTZhA R![} "uFN96爊S%U'#KD-j,8DBKsr4h -/^qV S \_- .;@̉/HgDb;C\#ҺنINͼWF %A ':BPF"#+6ĺ·\%?8 H%}͌IUU.'WH>-7,hW6[iȦIgLkrIo @BPRioy*b.FuK6GYL .HT˰felvc_5}CiZxYaV D6?g>gs .åTVKP?"(PaڮQ EypYߧs1 x20T1C&bEÓ'4GPVGɉl<4r= /S>lRbo)<X[qk[3Ji ~qq}p.YLTxӉn0OE6rT.-HYKِ%9aON8M lg_z8%ٳKPbp `vG( & ?\cU0Tm?> b=)4;0Fv.7T4نu] "g~_kA e5eQ*: ;!/)cIJ`өj#QC c'ti\ΛNmE6Gg{_eMweh Ltx+`ZOʘٮ z,]{/hv>.}s=B9K[IJ](>Myt{8T(U|/pDsGߴ7*g׳f_4Ws5ȱJj{%'\7Q1 bIL;TC䮠3.5們sz<^q`Yy@jYTS MםUI CCpz6NymbJsX_(oBYYHf+l%ӮctGu:x<,3 ՏC*Q@=(p2Vp0;#:5wdudɖr!Y$PVb[Rr3 Y=|lH۩QwwUV6}ahl`2vxs OK ^Y0!T>7 ~n+ˠE_)J_d~ϚK0?tӽĚ9jd!=h 5lC4%aF#'k9TZxBͮv(f.S(%.G1ߗ>JLT+m2 0~E zٙ- + '!f/jk-[ y@9@?%lֵ){UVHbǝmŚʾSN^R h[T@͟BofN1 ʫq %g!ǻ9EcThgFg]ݤ$ (b][5j!p6_}սd| RY֞r|pTЅ'B ?H8gxUgI(x%j=giU`v4"NxT;ˍ$Ei5OdNM? 1!;yj#R`H,BA5HbdYFZ٠Wz!$zΣi#gfDzc%|n;K9ރu}|d5dn3~c)467KV]pGl!WD葕7e3@IFͩyP BQF{([6dhM/&cݪN}k6ԪYT\3` %s'j' F&~ ' /PZb->oF p =Ԫ>N=~?KY&!Rԯ#du4lrh:GY2䚠;w6اvf oZv$nVUcys88-R}фf t@E?D}nKM҂q4밐y! ⻪ \h%@͕OPr@|?+K៴Yه_捺` '^rCG: DuGIԩEtr|o)C̷ jw'@ڏn]h圗Fkfv֠S PEy6 a:j}A_Piw?C9F 6 H  EOԧ5 ]"; BA2jLmmI _ql#E=%~zìH9,Tp:I|~s-~i]K[2pDcfpW7 eTثGG݃1 ~{vm(fx *k]y"g햗8֕&9?8[4~!jsMeCj+e4P0dXe5ԎY[6t߬ؤ&J:EkeS,6?O;BSz36T:UʔM#jW 6|зA#})|Ccz/'&bitK$W,AxOO0ЙW9SZ!ۗ:/,/3 [X?H5k\{'y+9K,`Jp36,ٱбVT!:BX\4^h{_#{v܏yǶp PG+$6ʧ#e׽J8ms2j44 n"k>ŀU669ʹ; gP5e['y&WxFydxKdhy\飯`<*5DSrX/Q3Eha )r-^ięF+(UX,N~kϰ\7"$#7嬛'bFmfֲf;5i#!8iԍAc#2 ]R]Q8LJ3v$'T A蹪UlŶj3o|. &EʛlKVFV0{y><){. Asݜ+7x 7`$=kpT9ȸgAJnչmiX`y=v/]J`sҹ δJ  i31Ty;ƹ@CZ-%%M_UژX_7bIg$}#jc3KU̼q#} EYQ@OC& ^Sg.$vexkSyN5Q2j2`h#ޡVCiyi&16kƵLzZYG@S b&h]@zO Alybg@UW1basKP㊔՟>z 5O ױvU]=[CСN$:開,OӒ_KI6dl0P۱W<;VRUb9Z34&!Ѱ тߖn/>]`ᐗBCR 2*`Wdχu&ho^R6^(l/.CkA JQ鯯 <m-@={ku㻼I&Z\P ;Qa=Aݸ UNJ}1ߪb".e:@٫+)P^ 0`_ 1C{&kerdݬՐ5_/؄c=(q&զ\qȭj YliD PAu^{'MaGyku V,8D uӁ.M`W#7'5L{,}ySyl^9:CHPGD,1/!q8q1Pec_y{6i FJ6ܻ3 ARDZt IxۈX?Q:yRb,xV:h]F} VGW_9[?3?H:f|Z7a:Ɩs/ƛ%K*]il9SJZߓx wlya'm07C'djztXQ+P oX;j7\祲k$H>A/|e+߹g,^YA\33Bh]Μ0tWt7CƊ'a1秱;qBõԟF2`'J/{G46PPqG'XJiS R#iS6:_؆ [=r/C=вFk }aDh9ccCjcBAq{1hoTs+aP} {#f)RX5o(sg3H.1(7nqT?Bs5F"1/Rly r ]{.> ,j`0PaɹEItUq`d#C@=Hz 3M)LlΩ!Wxj׋3}NdhsGO:v93kM5mQZP̔9+S2Ӫ#-m1҂Y$QOþR+^ L"m}ZdrB5<+'7`y|]$ l8ɸ08ӲfOtcԡg;Zo/XO!S8R8 m-[/Z#`Pލy Z"Z [bQ P6oH/+6!ܶqk Kmm$`VbNIFLC+qa'/]h#d5NLd"&AVty3(ߺ N6UxZu } -!4 cc-dx4/D`T3Pყ%QQG\IWFn0`nBЭ_ߒBQ[W3;J%T[QR+{_o5 z@儰R+:DFqM@hkJδFsN(MZ> eAJz1V ʜgBݧ9އa1z7.vYf#17BEw#Oíʲ@J]ӗwT8bL[hZ-"Y(.*#?Q&' i . [=2@=θ!$܆>tZ0}Q %62 .`" 0jܲA\IjM46\Э Ҹ#q'A zڗ{O Mt F8̳B0_,xb31[ԕqbF*N}QO>/0i[g3nɶ3)y uރJ6JhV3G~nZ&tjyڼJ.QM.v64J7Beb?",ߵX]>{tY9F7_FZM+?)D=rPNrq&vj ZO³(t$-I3fb8L:@:MN07 =կUMpI,&QWH2w^\ؘ'5pP}x`J.2)G hQyg? jkjc Z.;br٭xNĂL9R"Y u>[Jj2>ОfSNQV*)Cptʂ5inuFXFh[|?Žtu\ *\_nvh7_(ԶrUIn[GGJ4 ],I/<@ є 0ĦKRM\007ן(dSa5M`8.Y=ϼ~_lҍ`X?F;q{*Am #Ҁ^VSkS":FH,HQtPw^S:?P?-dJ\ճ!|i"԰BSdZl@@D0 yNK8 &g7B&I#)km/V#CQ߻m _|r!L}-` 'v6Nub`;^Z/SbKtUzj}nVY| kYpQkצ;PT 5bǔ!Nq+(01&hܲWl%<;z?ނ"4)EykMẄX렗GX&x2KsrZUw]܄^+%k(Mҵ@_z&.̳ ur߹.{ݴ9R!#^+~fG?Q\QV /9q`,+1ϪHnArۂ1jo!h-!tpqb(iZ]mkInbߪGB\)Rg^c\΢w}[VmNʋTd2rtQ&+٣3N9$aYd($ ˒16=l?3o 68 p2OCGHϭFcQ⽊杤u:(*FVj`ega}dyF'fޘJ*Uް0d@\9s S\RvQJۯ1ߤsQIʼ0Os2Rn9l7'ԭaߠ $!Mb),}:i'j K(I\pBw:\i#[q@VxR[:b!77772j+'4 x= n3Y̙?5'[jZdtn-@i\SHo2B@ȆL+ t2M%1";\+E{yk6\٤ۜ.S$M@"pXQKbR%|u( $V/ 8c0X's O~Y0n+i4nIAl(Tɏ߂  lsK`nL᨜!P ]j؁}>~` [CǢ4":UhuZdd Ui%(F?:D4!@}y"|G4y?WC>0H;8y6oEzۨvC;*[أl]߯OEB/j/a;{3!v_NKy%p9<z֑@_hS*QTIt0v@aD-8|h`[qJ/њ8"68K!OmQԧ%h@v==#e81|jU"4(o9퉳Gyq[dZ7|B-C+( ~"Ǣ ã:ϛ;|{*v?>yQwVW~)YJTXJ^lj/g\k[(m Mn5/57Ȁ>+Zt(O`gaV9ު.1oSs^p@^B4yXlG g` Wpmb3TbXeR#WFjhإ\d'j`l 5-phVaHowH5-n&`wlRbɥ" ZXT͎JMmr9TZ ?VΫ,08񚊆\[FQOj:W` *4 NKAz ow).:Uӥ SQ1 NcVspnĈOC08ѡNhՁ2ln܏h`4^Lp5ssݯ:M$ [a̓)GFя,vnVk ~f-hw8=+db$>IfG?IVJ,4?α1S6)TrP<5gq?ზ4ς6 rЋ\`*EShX@}~$>w ` M<-̤-4/7^cr8բ 4Att(0ɼ'ˆCKshD<'Ouܞ.i)jɝ^{RF.ׁLn@7gÕfTAA [_vG*pj}M{Lk;d :z_EȥU δZK1T6;#ջ>oJ]S]jRi"-I 6_[ZOuI/I-Iۡy1f /FN<5q( 1wSs y8]bZ\=/ \Aien`0578QAu0d4>b륕^ r/U^+y~}d 2 ;پsz׳4R~uqrxOݶx2퀸1ٞB.zbZ0/>r &lߜ-8‘ʢe*߳fk["vEv:]5ecآ){rltaDns[o<'[΄1"{tAh5yT]ݦP rUPOJW#Vd3~N! %2$e-T_ )P kϷ `#_uTQ:(NPgf^5=R|/C?_W޿u8bX }GxV5u J7"loqFG<<=iӃ(unh`OABvc'MiwIDrٚR-Ltl$TP-Z~ qto}TR2WI2KP=ֶ;ؔ;_9dXv8]eMYCEqҶ\ׅ>NGԂF|OS(A{!=jA;erϰFElq^+w0ʆ{\xk+՜]>;i!0Hrm ZV9/ug/xQ}uGM|J .n"mB;db;R⻂Oi/wpӠ[|ilgRQ=@ oɠt@/u͸Ue,1񤚲Te"ne#lrͨ zN( Ox#є~N5x>i][wem| ><1{C#E 8n_~? }_Ӊ P/d }R&XsAe)"Jc7p3J E+Z[bx4SݱT&8@aZ+r4K5rlָd#utsJG dY3L\{k ./G XSo6^A bH2 D] /gh2Rv4@DUg绁Yr֝g qXa~$͖"T'xk3Qx@Mzxצ;+6FTqx|,`XRsx96Ъ\<tۉlsd8jKާ>Zcd#݊ 4@ #䒡W X(X !di 0.!,>Vٍ obd-{2#=Gn'^slrCJGK`ZdB=6L BA ^#l4͎d/rp*CZ)Uu2ZDE߹k;YtP};_:绾`r*fvdu1ˢu5t<fOwB08 /PԘŨGza:8.^a=Tt.2%%4:ۺ+ (7R!p3U;N}.c2wIorSS b j>wna+LZ~Z;9a糋B_7&┰ wԔ#T<#>͋*D/V߳τpiW68fԁjAuݩ >I .ù;<]祖kA)/_la¦P0ZKïO LT-lQMGXZV _d8-G߿ @[LS<Ҹ OZ#.R3{F&]-( CT(vzb"ٶWFS 2OA$Q$aqe#e]^3}zk((2s,WYdQFa?` 1Tة r"h <8EK}?cxeFO#p|xMQAL4>"F"^Zu}n Vr1}g5Ymoԇ$FqԳn-Kػ4Ъe> $ HDX󥁗!ER߼)xBzPޛِd>ZX,ƴVӖϷb WI>! 0i?N}M U]62vNs75?M ʶJjHjtϢ7/w\ O..aۉwu+H\SgCmMko^(>yAv9 ێ"+0aK(v'`ul*L?ФܟOT%[50Q6#B vSTb5MtPyOe\\Z M u-՚ cE_ +@av;5;~/cad(Zlv}OիzC P~pQ+El5Z\ieej k/,]n:rjiyrtZhmæcQ4`2Ov541 ]2Pܚ' 0I͞B[ڄcvyJYkx5.GcO_ kKMx6,n  Ħ胡uxnx-~퀮O/7H3\;nMh/'yhBOگQsȸs9;e[`O[֙CyPl| j|,2CtF^V>@7ߧ%v>VjcY<+"N,|mݓDYE`9IԁݎQ>lC+()@;M]-/Pކit m&a0BJdpjUmd+a*oRCwg* QZ4yeF V~t7p~qIR\MM,`||pe:;Ouu۴,^$ܙ*]S .Zf6&+] +ޜ=,}"E |Oq _L i.=:W2F?z~0tv,U>3nFC@ZҮ'a^{&v!Jd j{@`m8$C2h]1Lyy5;ez"QHMdݴaEevZ3 &{>wmIa5yR=5JD 1%W7uhSg @Z)}0-S~FiO1jZΟgp{1Yts = z3l:ٖzk .K'ŊP$>` ((%Gi+19C{Qd2·D8PtbWo{%Dl'r{GO|Aؔs U^W'òL4B99xR"4}s^U ? zf :rpR$]cpն[`)mJ wIT: l!%'D C~ ={erR`;jg:qqM0f9 FwuZ7O`Cw[jŐr8!nH*8) ]8=?# ktw;rDA!T`_kWN^ȫeb#C,)ul*ɢΔH^Йxm;\b 3N0U'ljI%Q* K =.XLw7T6Nj9l#JdʭiϤ4 _l5ywFIJ f@_5XMM:c|.;\D!]vY}Wc~qбK^@&D\h htf+CScq+; F_qx V ԰SÞC!La 2MC}HM ѐ఼ɂ9 w:iثܑg0$/ˁm+Xxm|:ʎaRe G9 "goeF~{?{=ְFSa#$6;b:Dp| thFCvh&`:YoIćxqחl o{!! fօ Q.ǧ\%@ [5<.v@TRLD՝yw=&?FӺVƛ2W̫ZC+OE"V T^j_>^mVB9 ώme~蜃+:d+o~ẟB \~hA޹>ʡ{ !7;>s~Ō^_ kLdSt_FusholP޲|aԵG 9U8)2G,< r'|Wi{w"A  8!Hu/*hn2:}d͗z#P kSʗX8Ӏ1ps/ )J&p<sk"_"<]g۵")Ѿ4yˠ6[l0dlO1ԫo"|x|LA=Yǩkqu~ØeT7> DA2F:r"UYRaBdb4έG 73zfYg\LVV'BY+WT ҿUjOs4MeWʏ͂t{d*u˝Pݞlo.kfG' p$,. 1"`al)xQCҏJl'su9DIƔ!VF^'r_is?[ tS-o=OdјڸԜ\ SM&~ts25˳K~;Ff5p4i\}g?j vn փ6U5`&"m) P'%$qpy3rw\B*7wuUٖW3 F+h^]^`k5=: |\M4݃ 1~<Ͻ' ")Oz5rq/ Ẅ́+3N;u?t`DM?H b {J#"ᕲHku!t+MgjJ1kQnٚDz4.Å`qޱuGSb,ZE5C3G>FR6 >gd2Uv>~+IKwvٴjGơՠMp?X5MST TTkƜ+J-)W"u3dDGal~o$"hPnE)LnP\ȿb~ |׈$F3(V"G3BXQS ܰ[1VO- Xrﭤ+۠ԝ^*i~8t E_/r{)k_~c fq?ZA ɞT!sɕtD}1MOVmij-ݚ:2l(>嗺0𠲛k?]٢~D˭eFp~:4gGtL9< -r9umJ,'j?l W8EW hI&hܘH-\p9k1D `{xR@9ꜣ9Ԙ%;=A%Dye vg)#@>)Կ4c~),/6PCH2E+Itw#`%,:*bP\LGkkv13ODTzq n+Pgj5kSM17Fkfd?W>RLBz9rj^bpW- }xҬ–f_-&VB3"6^̀1fGjм{㎪t8N(ymK8qRpV!sS/;k?:9b6T>A0613oKee~qfY] G2cU?yL dV fDrnL2Z^ҳ`ixG~ hDe M_+÷,p)Z .RFhBGUmlZO|D 5]hQ|U6;&'Ihͥ޵VRV?vP2#Ka-LnعeR+ Dgr&o1 |u989&jpny,kOدdƹ)mcpb**\¬n<~$ÅoɖB\^u@'UPB] "zɟ%[k+Շ:DA8"[ތUMۮ>z(.r)5\ⰰjx0r3Ask2IWջ=Ndzni70SЎR dO3PyBYXV^,g2sXkعoS 뭩1˾`ݐш'S;+;I&*՛yy^hZ0b*ַޥe`wfxwqwEM!.+yGim^T_Wǖ9BfE/(\jZn;X}dg91no39(EW˃27 S ,k+w0a.t| ȹILScϒl Rn?jkOft1",` _zN\8Dzqg]?[壥"\ғ=v%yϵ""vaK_+r[H#!T:7U V2^v랲% \ 66s@f\rO~sOFI(`$.~t|ϺQ7[, ^5/H=c{ V腧p: yp=x Q\w1yFT*Ԫ83@+=}#Xzg2֜ ebeԊŗbYmR! 6NKMQSadjj3^gK!(X: 68W󙨘hÊOUf/R)26q66wAIOmg?hA)VVܯ/ʮ-56O`NqFs,'.QT;^Z NؗBj㪄us[[_>VCaky&h9α4}6e蟧CX+U[JL{!H"tbYTQ!sWAk;s&G!,ByĚD-XA{4J7n[?k!~. )aQ/.cTk;3lfBTji=A?R>S[II2=acTvGsaE2}0 b6mfMH!ak ujH0pώj3H`QX[r+}O<8,.|B@·Tjн~$I7/e+,CЪ4i N\GlҢ?|&L]7o Oyԍ+_^3UV+/\KH\!.;eow$sEԁ"[&nN!ŐR^"+&}reF)g>;cGk5k6&I!e!\7doM ƅB(Yk/V"P<>)F NvB!Vw 7 n(Oçs+\->6)Mtwb}ߓH頚g'ݢJ(6 2;8EW*[$qz ?r{hCV0UIEP$NyB/WIu>U!h)Z#GԪÀ_![ 拂(\@^9@A niKMqTDD>]q0~?|9y,ťU/?(K`Oa| ,^1r'F\V2؂;3%'PIrjpL.GJăMC&ʚp y!C4 %+6Q &]*Kd͸w}`O >⶗ePA*U4۶K1d/w Ct"wtcK4  μnxnԗJf `P>VZU:|ʫcмzl& `9v|X3ƒ'o2,1% N:ak64J\YS# (H*yqi&%`s{s!3E[AwBƧ4}qg6Bt跌S(t!,]ti[ʒp/HhkU0#1SF&K-}׸Z( bI3'ҖySxÞx[O3.$uWVieE\%ֿ5۵\sv~y[~+k:Ik<6FJB ^q'7ɅVe4:.o%G -֍6)]dP8"V @kz0r ja8T ;]p$+o8S?@$I_WKOqY=a;H ׼bڅC/a4V< F勁H'GI$Q J@?|Qq,Zxu܉x/ D?8# {+$^&J9Ĺ]-0pfeY~0Ԓ# )%tqq@"NR'1|&+RTtwt fgs-КcS_xA (5Le0*Z*[.\|5g([̾DgHv-b+ Q{2' 12偖f ͞'y.uq=9M)A^5אskI+EEi. 1yX A|*ak*˺Zvvl hZ')mIp"̮aKp+7!bmz^Kĥ}aXM.@?ELpݯbhɸEIǫD[ym;a&GOhL^ !|;^/9RYYEM Yܚ^qv*s(H7#WJ,5Y%=v*O2{=NedϬ~ܭQ. kAX}P~+$8,eҕwN!f ҅Fqh@{(Z|+xט!۷qSl)H\mE>}¹ ,D;jثüȉ}ח#Ie\WuL>ǧeM/+Y&?"A`kí/5 *E4Y˷\f)=k9RX؅t/D?MS¦7$1; 6o(-BgFZWNR1냿 w2 ޣe"kC:uRtݕDQQޚUTZHO Sҽe3Eu3TS8/e CSE MS9O4}_?d|VM^U%t( D Ƭz}Pُ~+*MhmQ[@#=K:T8˧5hraI8v.K?pb֠a2Rݝ'Pi0'‚$i>F ,wD 6 YD L̩҉ X4l'+7!>_ Ɔ!Fym;rH:@NB[TU3,5v;, NZirU7{l0P` 6qܿEOq8=!@8ep=8wGewٺB)D]~:]}=uZj|Fy xG,*r1/p)s^Ϥ-[z,3VDFRfTv[@_νd'U%ĵR=F8M몉gIdn.5Vq8<;+…#$U\ݒUMXD}ĉ/e$m3Yr_z{Ulm>.O,^+JUc g+;,OӺ.NreX*ܨm_1֯_ϱ qz<nmlFa O[Pnv^6\6:Ë0?Hug4Q~ݹe [&|P%m?aG~8{7T}T1yq$p? &fsV8͊Zو6g?8>$>Ɠ܁oK082&p^f9(q~6ڕ},bTGPPgԀ5F͞aDž>EЇ- rި3֡!D19FPc?Gv_BPԞ6S*1ͭγT򦖿Sn!:1ȡ+/"F hy )cAdᨉv=hdq&r>AZU{6)K^ (x{",i/L$"l델,Udf\Acy{,N2O!ft?eG.Rf`ivK,U[*WO}J(=;sEhzm` 1>{˦*YMc(YpCrOx숂ɸB*vy匣ހl5rC^U梱rw9(5%=גgoЁS?owW[h(GvYiRܲ`ۆtKA/溜d!]g6?MUOշ=,4r%Ź.IWgjfMo' Nql֍3&e”FԶ3%zqo*V̓u5ps 3J7^*E ,^귀"?`F2ꀔT0LT})j26y{ dֻ ;N%H"RTidt$|Ky){%9omaeϚ\u?CȼᎸ5F+24`_26$ʨ_ |Ə@U>@`j"p J;qUVYbĽxk!t\g@$==lo3|s3{Wk##ET=CF{?Bö_ 1;x%7 \cnyn(gPcb ky5[{:\hօ琷0d 8@ΰ?up^?rY\,0#c5Xg׸ K zeZ)yR)'u1 aH~2=_4{KX[GP1}LԺFg|D";/X=y^URlMxquf>$Kc}eO64đS{x"EQdSG\5Ӏ7x::j10Z.حY os\7# = ^ +C罴iGIY>ky̡N03NEqʄ,#ׄAkêf)=$%^d@[|]e5F ^<'{k-4F2CJ XeNЀy0 Z HZGyvYbKQN{gZcհpؕ7Tץ3~nzw Apf>@oϚEVshQW@`7 4GDofUKLTNnR@l3; <́z:جOlnȈn 0;Z<(]-oZ_FZ^ FoR]è7YOByax-CB ^@lj 061S>\hT`@ŕgkizJe5q x 0h/>fm{6V,]vDu!mJ*&{W:CȊ/bgZQ,_y$RյB΄IR'̷%9io.dS{\rQ sKGAe\jPx?`_[*/ WI+P"/`Ε ۫P1T1;?4R]U7R0|9CJ?0lZ^@=GlRƼ}O/Jܯ_ɢVDL?SC7hSV)LCivv^.9v`_6guۜ9.L2K^ lk퇝o<&2T<!ɻUj;+js?rH@ͱ~;]Uj/-oV۠NLsmV^.6λ-Vt@5 qJnK|f1|#'-irVL5O/-)5'!C&yq`"':W+Y-+v" gK,hL*>K}!"f>veU@|OijM_k>wI[d<\ܹ<4Uu6?̙&rⷿ:b 15ZX?G*)(bXBlD]F"ϛ|7LuA®OEf Pp:1RK,^F6p +0-ҕ 65Ë$pg`ƄTjPOROe)mq Y,TWm)u Ui )Gg}$sS2Awb|.6bTE22 f  ̳Y|z,2i5-6fU"RK6$JB>Lo^+Z HD_*Hw3K5*D4{`嫛{1J`Y;D(h7^A, Fsl[Ā>wu;㋋2I0cij7P\*4;w Ij/#q4MpIbQ#uu:><<1)\]g3Fuն}53%Sт !gJE>]5tAB!13rҖp9ikkr4~߈(mשjxWir/';yʼnیߒ6+)**t?\ HnaGb Hwxâ%?tls(n[I} M.9`[ޚ_ڕi|mRkEJp4"64L}{ޥϥ-s$9S:9p-rrg9A)d@~cI=?/Ekþُ&с]/ȐUUg5ޝ+@v_SakPB W-Ǻя eЂkdjӫ>ʄGl|y3TΝ=J_>b%/varPcFyɟbw[sStrO_Sx[QuFQSCLчx+ Rs@:?#- O@HM_|DJa%E=4?0lzXtLs10g}鎕YB Z56DB+M{}M<R29h\?jHQY$ ےzD hr̭*=)9lPwk # 23?"ſ >AIBU3*n)RSj.tB:MsFH LZG E ZGRH> X`=D>mm#]> B֑D.5+e'.ۚ$2y ZV }G#/t@xE{|ɅWnUQP߸| kn.fY-5RƗE^}岘YNBa*1T+;V=W\rtDBKαaHJT$ʞNqa~}nT4x!CKtդ[ `2Kayq1^|0`Via'ܔnJ]/5EeևN )IEf- D~@;42+Q5r ~},[t*88WӟV/3TGOyzI+# /K= 7cՔpgyI1oZLy}ܾhh6*T%JHr+ٗY`KW{7\qF8bЙ-Z}PuR! pX-~]2$@_5AX<|ˢВNN!c} ]gS~b%׸XЌxRL ԘٲY|I HyIbZ0IA.rl[n&X)Q45Tfo6]6h7ЉfecW|rLqܣkGm(y=Ӗ[J˶ŒEI:)|d53.Riݲ-^ߟ$ '3G '>㚭!%6aLd?IKTQ~>!}p> E݉x**JpCƠOܗbQL*ή͌M3C6:tn`\* ΏQW(vB3\V.WRZoBqfAi5ts[@~ Ww1(|t_[W qoBqҘC;pa4md4UB3;>Qoq뗚4*H#0_V΋|L[spR bA*͌[?m6I;VbX29s)?T0\]8bCRA wNꟛKjLñD6LHޱHE!y&q;mŶ͔QR0)pbDٵLRJN]2NHA/=NX>[ [ܷ_}l'AD8Bs<+~aCjbŠp]+m ,>^M W,tf+ c)ʿ4F6)Q*@!ar6_ @ 5-YdCwr@D\6Je4y,;qR?xs2]2i /ܴIYԕ u4?fơޗ; ~>!Wʜ2 ׫*+*~S#fn D akΆ]WW{;UP(j 9][ͧNFAѤS4aBny@!u6`{iX3+MwjR?Ŕ\_.>.CKn+fVɐ4T>-l=nz*}ذmh7;]] @"$[&цp_=r[`]#AYӋ5չ3l UFUede:#thC$_~o0_d1Kus Z9lm' "֘xvϚ.jCH;CƐq=z8L/s><10r5\CqߡǪfߦ]SWځՒHs/F2\;c:O'ǩ;I|pUt 6JcOMi rW_Ey`;N~t_@aWkea4ZA.UbK$49knWp n#4VVk'ICPr):yKrV7rMnfNWO x{Z޹'X ~> mp`ɝw皌T?`xo44ԇKT_s}ՏCu @ k`=ٴ!`^H ڂsޡi6FKPHhvqsfSy5_頀qMw%w*q|E_5C>wT~HZۂ(/CQ *#<-{PzǚtB } uȋ#yQ=E+_M&Ԉ222Lg[&dzKsƎgvdڵƝR&,6uEgv&[ fq~͛o1R-)8رݠo$+,GpH! 3"Vd8*t= bpTJ"l)V RhH&e"쏙Jxw'zÒ2q/٩X(V@f9~du%RD4ZM >Zt\i-LU80E^xZX_jN޶;lb51Xz0HP'{u\ :*wi5y36"',c3=QSC8xAz\)6z K?ŢbLGoC^dGFD`[sR ^Aӣ% H Mw*}OB _ӽ?7PᖙVRJjngr΅C:\*; 'V#6oGpM^s]8iɞXt#U}Ŋ>ۉ 8V9gGH5^"AB0׋h6WC/c8jD*"4"XҤ wn+&h緝b`36h2Q[V]=0 jnh;\(Fx0x:۷$pV.U{D{>K4/xeow< ?]-.Smr,|1/܀h/;ڨe6tlUlX\^YI5!eo;:q 6k:CiTPy8Oc,tAm1 RBs_z2mLeXwLi9Dp; ( @u++TI{Ǭ\AMDk|1HSCz6*RaNuDz8Uy7\evBiz($׍ 3 1~>17j0Q0psy2T룇yK+zST5F}"y_6}:uf^FTHEzGI3=Gg$IsʛRr>!+gBGWCȕ=r4},vCP!ž9a$3КSyPRJ_f7}L׻w<̊h dF.x\UkF}u } .AHu8Ӵ0*YTzd;)%񠧔2UQ*6%Gyީoz V׷70 Mg29ʰ'O7GBn<n֢:ॻV"?9Io!QX0obyNM]ވ @0@vyA7hB&+p{#_͖m*+H兂KE4Kc1Zԡyu>k(QP?GmFt7_s1YI!`Uʎ,H%AW`ؿoྷ\;NVR Oo׈n}XɃֺ[ժc\6*9E6RȑwJ]K ۦ= ZN{`+ŦdbyZLw2Gyc'+RFE M +})ZEeQCߔ R.6 Guˎha<v{[ev3*sG>U$+HJlq_Kڤ<#ӗ>ƅ-4hH-qLǽbd"{<;%]S炉Nģ5Z W{B*4.g?sHY֋? x`> ӥ < ` 򈽚g#FԭzZ1(َ T,\΃N=)L9IZՎNTRIfwΣf8? 4kvISbc _K:vuҦ?v^Hʦ#`żU)I{Tlѝ6R!;)LV\ӗÅ(m) #쐇RaB0h>/=/DZ"+a\KcW` dW&Xw[\+^t38ѭO4)mͣF:-a` q2 p-Ht7 CƓo7t0^]W+]hlR/5c /33 ʻॐ'܁-fD}K\FEYirMT3td1[{T#ٮcbwzp1.-]主\KHSH߀χ}@:I1.S6[) jؒoo'eML:nC]{9$_$iDP ?p.G~yOz] Of&c7b!`sf{- O~[m,W \Bs0C Y& 6Y":d ׽V4kxvjf~V=e P8T&%2A7x?MeªLXI)&z@Pu8ޣKC~1czn^~F>p&5 &! Za$deڹT 3}bkȶþnC,j?RSL[s#p"XgW8whr/β>Po Mh.Ӣ"n%,w<"\wN~=դE:0 %ɫu9JZ=;"jj+tc?JGhss[t[`nc/Ο|>kj͡yJ#YҬdHJ@*>I0 ԁP;cHʧ3 8NC%Xdtb&x#'TLaq2Y9@8pl rO_V< t .A"vGbL⷏=OfuiRvdBLZMDw$V?)ٱ.s%BxMl+p+yI}ȹ7Wy7cifu}^uSCámLLhMkAPr]tSʺqԁ{h+u~܈rUp<؏] ekcƂ-Eq ޼aZp@8xѿ\| }RWC#ؑOQ]H;h{-U]IӦݎ{'oh;J?Ȅc F|.^+; `nj Ik5oۻ"#H ,Tx^IVdݘʣlOVUFJO$F%&~dpl'MQɕaM(}QXC)ƽC ]d>;@xlf)ڀƖ=̝^14~dvw][6DkI<(Һ" t)}掳` W?k}cnt|& 8`%ݩLTS%:=#^;͇ӯ!~ wH|v]wy4tBB”DRXTjF?uX4v#g['pB3f*-0ok4Ż;~pCST> ҿEh\87eW;)#/S7BcՐZ ~C& Q/H-$3"v>ә'+)?iE,뾲*AkKrZOQg|hj-nI5e++fI{T]}rGcMO O0Yt@|X))3cUÜP~ ys~rZ}\zBp < ̌Ems5LcpD2;(GH~Ѯ Aly[Ȕ1,鬌ި`d+oYHzkF=x]7aq퐂;MZ4e[-y|}|?c5s%V DBې<C/\9d*Jo9rpy *\P\ %ӷAUs0'Z;mH=mk]Z>8ώ6◦Y2q i wLj>Xr|>.apߗKd)e} pύ]w$@:. #;I-&{$WB&kK_[Z phLH{ Tg">3B7! eqL52[:ZrvX1x"w0u)4:y|]|mO!j€G rx=jsPrϾDDpT(ۃ"6IIѫh{WE\9KSN9ţ'qxԵD"GS9xhz;v#EntUԉ߯p2̂aȍBzO-d YBZjl37BTw= 8:lJ6;xQMM{z^:{G:^Sk_xJ|XbzRԓ=Dn,86Q LBfiD8,dbߏ[-P;)U_ɷKk+N4CmW2O{ۋ3H86>?a/0v(dnu _q6o53Q >lfݧk*3@xBy!ޱ$A.,@b=k2xY!bT |Eɝﭟ  -$^ rpS@'pd"j ls=ɀ.ygFJ#x> &GPvss2+--:敃. Fe-Q]U8\΀D ÀxM[ۜ^Uv!וs CVSn8߆ :s\v\GVB=~4ՊĚjTJ(oFbo҇,,톲=8:@ЙEryL(}' 4ĉ_DzcT<_tUCJies:{#ڣ/N:g_Вǵ {!6Hm"2,`E1_It 켙Zo&=4԰Zv{cl7] R_aW/V-pݕ?TN;% cȏА3"iך;5\85E =o:H@JKN$B?.x~FU"3Y7"ys <$}ePXD3kAQ!ܐYWвo  K]D_ u5%4]'{!6aaE00ƹ ;Jr]nJKE9^z-f8Y[+.Bqæ D $Qf6PxEbu:MjX'{w%t`Rе2|j1BMkF4o2r5Vri ϝ]=ڱ SV{!.À6C?I&N yxV{QԄiɐX.31M,A,JPα(@Llt]Pfm*n/W mkh%,xY= }}t7aTNR6|U+Uo\k#=㉵^*FV|<*UZ08)vsRq3$Y?9Ck6t\%A(1}+L3k{[SeYFd"c֔XDq\D9w;Q/Cz2eIN hn+Nc Dhb5ShK"GcvF(Ƀ<9yֺM;wxY &C87u_=fS:Gm R@eƱsi$=r̹h9c&VҼB6*#y}o)O<;QS[ OhZvӔ|Q'! H.?1wcx\52ªF\urڑςlkZꎬg6GVPe hƭa2*aتDyA@zBnYNd"Ekq23ڨHqUIT5*_ aiW1o'rvH>',iu1v@(=ԼDJEGKKXgN-T k/+$!IF !#Vx!ゕĞqUO4}WYQ*g~[afa&He$H Ba9ccE@J,S%'b r&+Tr@WhҴ5㬅oĻ>q*&'Ag/jq7ivbo"C?ց*M]JO骘 #bC=YtpZN@. ƅE_D"wF!lt"cn?OZ7mvNUznv6;G c?Hfy[ n|SF9l aQAsХ[#  6y {l1+bmU>]nwa֪8N"k;S?rihZsk0rCb81cC$G:0~O1zlXyG8QwKԜF/Hc%4 ('ލw-ٞCpEg%qxkPne*kfꏻUhװ$-î%vNr8k.%A֡T>r-CV]'C9fI<d+m2M|+-o% S#*goYn!kv#ga8QZC$<-z̷Q*ѫ=QYұC'C{r5>*Z>V+C%g6 1R hېh 4sm} O4A;>@jzKXvVmeA~ϒ-DS4jwԧ_mij$Y0#,/R1HgVh2΃'19))1w@_l(͡X,DȾF08 Ru]^9#\Cc?3OCynlOCbyTqT5, E".m&vɆ{ǘ݁7&"xyh5Еp6dF m6e^>lF0'5dJy-ŧSلGe oID6xJgUt;Gkvƭ[nB~߲Btcix4ȯb?󈯭E)m Iz/ s G?)ʟ>M$\3ur]k D8i 5ˤDH+ ˓ߺgAZ GrN cz*zdƸR [jIt) LyDisYgX#w ,y]M}C[W(]2"#ee]iA沪^ 9y3CrOgS藑c6sciS0O;N38*o7Xovq`Dq !xZy)R=#JD'X|lb 84p-e[~gDLcs'ƅ|#&F٧0_}g[- ƊMiĜcmp~PրFP"Ao: \4) Bٽ-N47i wvd_O:6{暏[rn71հfշSV./N,QiI0"Wj.x' aL- k=8`]o 'AgF?Jyp4'Fwl 'hOQfssaFL+nN=C _ X)PQvsd2.ޣ)]|f{ C-l5緐d =kPvꠠ`&d,S>;I6;mNu8s{L{fߓWox 7L{yjU΀T͒LzHAC?;OMumYpN<%om(qiXB]'-ȳb'N+Yݾ'#$ْQϲ%-@%P)_7b7 !( L stlD|)vE dʐ] DPSoSRى˱w Gqrna-5eM,ޕǰTN}.c@GM T)t³@ؘ֗щ|kgJ]H^DVϙZ Y ?Am{4H]&Y^uw*Z /19VZtbfE>aʰZ»qF-9'%vC#zSjR ȱx#21/o9AcCDŽ<`;Xh8 J^l=XTCcyerV:x8Oe7„}_xl},Fص *)91 5b"~0%e`xYOkv O@5ȏ)Z5ɹdJOn܍a$9mɚN23dйy8Y%tA'x*$\8@_:>;6>U)_@ $g}!d|*ʘV25 3LKS@bF%: dOm7+(+!\!EAw]ͦ(&NI6j+(jp}u1N(>$/7<= ˺=8!g)u]ʄpΎ/Js:6ka,/Nr34eQ]cfj\{.t|!NAr '[F9GO$JY)0eW ^pa q# *q@-B /엝7(6FbR~3.F<u/rM֐*b~gZf* /RKDt_}j!("^:7'˂gh cewlx&i@+ L>^vʽJ~Xb_֋VlR!5lE{!F]AY:.óD^|`ic];NB?E'!1a AKC\ #/ޡܠG,IP*:,ry"Hd(LqR_#  h63= CߍDY֗`,.\B(3s].Y_BwSwVL5)ˁFA}SkI~} Nl[|N%*CtXْ o.>f! UAH?EG#X8&!ZSs hB'ٸWg]x"(X=8:5ĝܚ&c+GZ wԐDma4ɰhuN,ꢹfƝd"<-Wj\ kYnP]jEj#Ν) nW)qSЈ?./b%fřJCu<{JcHԦF 7$ ;MS-.57>vuE>qJ05|8[Ң6<;`Vmx9ѿ0@oFt&:-_ǦKqʌo&0{KiZ1$uy9 Ct 嘉gWq+ZEѠvA/Ʈ`urڧ\%,#npoՀ!R2 *Iťs`0 JbN|X}}LG8s]%Sh86(EHH*B.&1yd} h*' #({wTbѨET6؞M_b?0ZM`#X$Hd'2nE;T8lڵm'`$>'_Ү뺬s }Y,q?/*A#-~E[5^͎o@J@ZoXOJ=\H/ڞ4yZ[ô$ ,o&KLAY©Ae&aB{>{BZ'w$LI)Ś(蟸#ehO-==;}XQKt B%W g͇dɷ1?J*u|ĿdOJ 3BD cetépiZ0bBK$a[dbZ~C4'.N[vTAS Fƴb6$ <Ѩu*k6BZ3U. l5nx7dαHs}4&V+e}Ԑצ )ڶo54u1' OA. }ds/֏K(%hl/{Ր|XKfBJyXΛ0ATTńH>c0rYpYF3<8ჵzחk-=sj3cqtzC$]7!J DY܍9+\1ˏXnp 'W舁s±m[p蓦V<{Ǘ}w:N kL: Pwihn4Tp M AS=g)"AP[@ 9\qRԄi@膦Sɵp9rI$9ę|?vwå6Z͊ol\OJiVGfK1 zkD}cj*2kg)SI-7GZ6=V~D%2)|@}V)_4Z* p$@ 2lhiaї i [T`.4kl{\R&6ilecCņG-cnd6`K9~?`V7BYE3`1{ "Iz˂k,4bQM5KD)c1lvy^ bG%>Q P@OBDbP aFpczXTg&\L|.[{m[abceta7 ;<}8"*%X3Y=7Fw.Ihh}Fvw`t}oߣgJ jY4gctjNZmWydb'RߤpɪX*@)x@y4a.-?QMhI$ʮv}rP{h1ԳvkO j0h%{MJ)ō-\)Pwzf2e{c2h[+5j$kYj,%29K궔"~\R剉HIdF<+p]c3ǞE?'?22j,S1K)/#pSiA$#e 2Ua<ˈ%:) 6wH3_^-Y0P4K;8oHUr65XR@edvθV#EOE~J/[͛;[+pjlԀAsY$8?XD'(yͦ/"!3A-M yX)q|ߛxMLF]X(_~f]E5)z*2'jz$XbPR0[F1/8gCvC…4_aO#_uA$OKg PЙ^Ѝ=4$S=(5RNK|! @BP[m#6ߨ0FBƃtH=fڒ?/."H$LכP g ^߶۫﫶dvaf@Yx({9̜F/~TZ^^esN#7e@˓YP#ë?.fg/ zsC?ӗV*B v@7Ncb-|y+5jbߺMHWZ{3-ƔQ-ș0 eҎ 8)LXPx*0Smh')o;"M 7NCN7?^P {Pf>dei} (o߬d-tfלW1{#nX4xvWxN`3]!aH 9. F@̦yDCL]IL)S,h8>T D^DI]'4Z5aœ)P)Wc" Y7mF䙛|T'>6zWɲM҆N$b :x uͼl]Nfk.ĹsuW 1 1Mv fR%d9``ju4v M%᱾3A!p6X0GGa΂>C\!7a-@Dž1l>?*uLVľ6 :Fj;Ç ( Y7*z}&qS#IXfS$OH>bI5AaC 3VMvh)_vI)XnǫͯͶ&/3ra*Z\]D05P'k[f1:tV(ݶ@W562h(n>v_Ѯ(娀PRH~~TnT 1EWe@Ϳg|J$ɔ@xȩSU`S3r"6֚L,H'$vY2$c_fvRw"v/ )hW/\K^eoLS895> $es!A< 4C?J# ş!𩆋|c{xkc)-$xdS:6[P͖3?x}As$MQ/9 4R|AވaS1pZw)WBLB4T" k׃Cb\h,©kq9"!\|`|6ҸrR3}NᯱP"Ft,iN^% ˞xކF ӫ \FAX`l^gC㎼Rﲈk 0lq˸.vH0v/"$g}~W's蝉ܣٹ}xuqE'#g(SoIį@V@; HR JۮAP]q ~Bt>FY>,6(.3`y,UWJ@z \n.QRP-$vxү,.+[ҠdMOJfK-9Wa:sbz*Mʶ>I<ØD:y] 1m(?R{RnhKD+xo9{Wx=7Aҝ\d~6V[Hɱ Tk<^l:*"xv3G1]]:QMbvؿtxa9oOn߈ }.;=[Vb'\RC%DbETcUv?Q.X #$N$kKRCö׻~I[@`LBs ɺ=v90d~sOX KC T4(zk>(NZ3r<)Qlrş8LƮܙ|Wd*Ê ^Z RvX-{<ǷѠ\`l*f K?8윹?Qm$]a]رX$%r[dw;8%` :lX-BS<(7c:jv}n@h*i3q Ix{1Q# }~]Ȏ_*+1)o墲頍$T]zhS%HlE։SqBCl}~Yݎs~1 poz%u"} q/O$j"[YMnp}ChW-!hnE?;0o>5pM!)GP `Hm:odUq|Bd0]?JCBv2)2\W4e9Ѐwx1ʀ4Tv΀zb~^T $aͷIDi9{3j-$U13<4>JO wdV4mpm$a6G&F>*bHᖚٵU[IԺ2" ¼%I@z\N7伓@2V-C0 3թk_Rzg`l%9^+ߗ`?ޕELʫ=T5n#X\4Lx^ΨL&1 qC=>M|:H 9&X[Ƙrӎe,-yEfCNg;=!P PI%~9^}-ŊQmn4s_!l.xk~~u-,6±ٿ!z[ d~ L82l d4q_TZ1Fli6^M&KTFN 䰂^>FfV3o8hbܳ:&g v5|C qs3r/R x8i>dD!υYP sk_? XEFF2O-Hvaɾ?r3cu"bXA]1=bz& 8:A%H`''vʭI4Ejf@)%e44K glL*ìiچUen׌CeunimV#Hˠ6.(lѐuȢ58^JskrUP$]D\wP#]xő"+TІ@Tw<_Za^y%5*whĔ;?!`ojAԿq)6wcyD^[ᲷM,{;>@۾ަҰvemf6 ]GjJJ /RR,ͭqf 0`T5Vj~1(F4a?aq3*c x:_Uk1T_\vFe^^Z`qDxVZʹ`Ot|:X&5;3z4ms]e#⑜o3x]Bk!cPi.95_@ж m }_춫o0n3YN)XP!AJٮebP lz!բ,+MD^ON ؇k"U^ &Qw;qlOWW~N\/32ǀmRbW9ųォ5I4ʓ͠f8>4U& bM5K M"-р)85tz7_E+u'FmN "?$M%q|:"DhXvېu=әر0<%lIuFh{]Re=78_hx"^gG%OSSy(0 ;P٢\%B>tm;:Sh!5By;pnYFzcWqK3w&o4HE8pgn)0 mkhZ*%|Ṇl|ڍmYVYۿAE?x%@T8N+F28Aň(:6#2E1ě)H`?(!'p!%G1:l$qf61J".T,V'3c 0'<``N+W<ف+?H׾4c2}u|;l?$2ٮ'`LӵێTAJaZC: gWAZ0Jޛo% V]`XD2 {`{|:x`51d1-:6+p웦5S;M[`D=mfi"[Av*]h#NOzL;UHrm@x& uX3В^L%yBG_eʳD<}^h|a:F#%E$TȤ4W2ܣcs?nZuD_2gEtr[G FXTizHAqS@-Зc+IT ˆ"VXWŵŸ^!V:;lQt,@N]q"i?9*-\ŅC-\.dޥ3!!d5P1Ow(9a;zƼoN̶%x/!"U= z%IpqwQNLFlT++ʷcz:MW>Xu[+l+0B~lD墻kZhL"SoI1}#UWn,Bq!B*=x± jdD'^6^V41lP WTi R3lG'xgԳ3A5eOQ!_Y'FlWEz KO%Xz0w-۽ )C(bۢ&ӳ 7fDҡڝ?|֝ݫfC% yG/+$`[ D{>$W\ Ĺ\W+q;X =Bubmߌݶ[yX3:.E!Ϧ͹W' ƏUX %V'8{?rEҢĄj#X/vټ3='B/ky?3)UnUáY02 ᱦ͎*TѠ~۔-nL8 c_K 6#f"9%(n!7^)mOG~վ F&v}v*zl'8J)z¼fQO##Q0.[/&Aǰ%g(YSgDx/sl}([$P+QO RuB`w@QyJ;q8%Qvgm0q'y} F+7@X҄ @љ,Y?,XxI:=E JXg'6+IWu 'َZMwm{Jq&S/#=" Cue.@Z=]h9;_" z,O*;K9aH0UO1c_mg`t$s[rU" f3AOmrK=A#v>\BrK"*۸p@U2PkC&7Ř^%l2ՅRe*U16' ߕF$,1#?m(1Un3 Eڡ v# Yᾲ",L!]﮶$̎ړ>ʐ7'@F,e;4СN"ܑFh:lȕOxTA5*3D::К^CPioe 5M\*'pÃh@th%!e!/-(]PΫY0Qs*~]k$}ę`Jd8 U !e]GTD  1JSIN2*9^ϼcէo;:fܒ 4S%OevoZ7a <J?3,Ӧ"" z!KUM= #vl{E]{U3OS 4gM%PhkIZw[Z+$ J&?³gؘ̹[ķ e(,jfVvp9qˇ`ܚHsJQ,,BVW R| ¬w5X>L)Nj)IKJ4 "b>`{KH%_V.9Qs"?sNAVp6pW#8} SxVccK)B?r~;" Z6;YpP4٘0FwdRtdʷhn<&YpC@rZǤg8Һ K"FSx'?WayKdQfNdZ0D|1'GM3;Cw|xpA=ѫ.URr5z'M A7[@ kM443ď DdžzaqWVj.tOuպKY]>w,.0;hM(RYzWp`~b֝enGJΟSrWp=dq2Co2C1ӓef& kvG:էF.0̷ܔo}yAhӫ@w^窛[$ډ;cq\M1Vpϗ+@>01Y Vi-PѰoΰoZ5G6.9OʹZt8Be; \52sp p vn(L ޜAl[;sc{<~R3;*uw@QvWƻXN#5_[g:7h"S@3*->!|' ؅`îU7_KuG,+/Ϧ{!n}cn|b*f8) "Td؞Hv ^!ΩkM"B2hmX/s lp:t#hCT'n;Zm,O Vn+}?ȵvywmek~Tt Q_o YD`f'wA$AEu߬]чU4U+ƏDvF0b~RGnѥ׸+oZEG vN48\,SaM؏4ݻv-JB>1Ge:u꜌8zaP 6iownw*1&/#5Q7ngU|RNvW$[~ӥ>;tPIYLg2_JnWD0ys ~=#Nn- hC,o({vaі"Hvfpu2}{y!8.LԡBW1ҊZi;cQxlG=Zcy6*]DnwO-sjKFHN4JhA>uZ!`IF\߀t8LO{KcAIYkx9U%3RI].H-<դVM]E:s đv/U 7T2LSx6j[ G%ú{~vs^;!ئڢV )S"*8Ja|;BU%ST :l?#"9?B5) P/ E/d4fFgwPrmhI vn}lO+! l9XZϏ]24Z!4Sg[p(], +-&25.'Ȕ)H|sRpmŰJdP4\W ȴv^ac %WXCi8,B_Z>"#t\{w wW(ls nɍJ}{o)`32*y99Q-=IoD@kL`_E B 3z`L<'&ڱcE]$*Vr+??"X~yTgȵ|GSndzl&BQI|-`BLz}H[%O0WhvaQ-a*\0?P*f{XR{l 2@D~ح(wM p%PmqQ ޳`HO- ! zKK @" ]Ɉd~{]ؖy&zԤP [ң8P}"էP A+G:H=8[ኝa//$$ T؂Wdȏu+մSIrM{mŢup8{ёmHVXP4瑤F-{r'\"pͳ;l3B""Br6XpewW3RLS|jV;Ys>vIw`~5*kE%?\m{-Z'頉dh0\v(.^ =j4! *]]/r+W5Z|~kk ;bnϩ:AdgĂ&FG؜lcP|S KAmiF V ^<\}^Y2Y6?BKfngcД):h*7OT0]`Kb<w=Ȕ'(/|2Q'l̼tCr406PT0n Iy@6DjTRQpVw%)lPWYܤxiprZ/˗o~n'ܻ( M]3ue]ƻ/YiwkLDzufjC/*'>ĥ=Eq*R&ߠO\g=W*v:Z~Uj218b ^wϹM UznXwv=F5PPC3A9oVo|[׆U՛]C2 3l>tO}x(B]W-mS+DguLsFI?:W,z@ 7G/J4\u2Fv1|_5`Y؍WYF!(6Ww"RsX ;%`PU,&ل3 h7G=6jr*>buk5|w soJ0^ NRvZ kړ[9f ̀r赓_ ^sSz+h$TWmވÉIqW !eP,Vt]J,[Qo2@^kI"ٲ -%LV&g WsG-yj`H";4ÕaXT]jIӃL.C3=ޝ{pšOKҾ6rrϴ^D TdsVg\ 0QQ-p8QڨARjw |-IbQю""ʹk~wкEh2'4ںs9g#MIPkL)KYD6>DlYRJ Tk+Þ }ݱ):GNc <>6N}=19['?c:b"=Hmۺ:"l#V{M}ƕlZi𳋮v!! \Mj`r%q'msҲn$y^h5ԉKu <Ж+hI] !J߮sMqfoj`K=*>v|~anj[^ OtK&KrƎxmO A-(haF-ӵ70Op/tšgYrlEmδ3RipN'΂n[lL6[j-?'.>+=نs; 6m:~f* R'Bj9=Z`tн3ED\2XE}4O/fAr^-JzT&ށ 3,pBQeMnVpײ ܐd #1yjbX#: jqc1oWߊ́Lj𲀮bq+Fk.1{]Bh?q{} 'Or.A(E ,{YIX"X6TM@ne 18;SHxH~$?. a &kZWHz|U*έSY|O@njᬨ;<*O9s.In".Yk>i~{SUY2PAѵ5-d ѳ*`S F:V[X11<]%ƌ\,U GUA6${LH!*s%)?}{N$w+T W({lK?3{RйJa*)AISAMv0̾%_OfZë*f^S s+a ,^]F= aZNי"/ >\گA"@/d~>,"DLǭ4t`wUCBg ,; ?Y 퀭)~O2HŞйΐD]M.Cv07Sx:fU`-sH#]XۿףOM Ժ/aQP uwH!Q#OfPN20Xbٵ`}TDeM @rLW̖J\=S3/"EΝ#K-oθG8"9& @Ƈ(Ļ >lچ. Jx%<9 ;D/r1#!!MW$0ѦmI4z-FN.wfV9$BD:2w s_[p~6L8"+өΈ A{4W_L)y%<qbL$^;,8ϢcӇfG2;{'IpETU3$5 mf1?A?*WZ!on;WơWiSqȭ Y gɀ;g~0.]k]6dwrfq#]Z|3Qm۞3~+e39 #Z4=&6¨f EV *PlDT%ҹyD=N$'hP^[ЫM4TEp &l^yX5䀸 ?2Ednх,K|BeJ+[+Dfs!Ҕ/3V̑ݸ<>lH2>!MM?`TeAn,(ѦR^ҖQ; `SUXG0."YGA$aZRw:JC'b G6G|Un:!!N7D`TrH!*Wie`Ek;lHT5.@b%+u`vSC&|H",\7?,RK4te#nQnkR0L^̓@8O<7 C%l.C\ί^٘X3b<|ƎL.J9ѽ~ ô̡PGLњGcYB4'欳.Gx֪{΍~B=Q}jZ\YPIoZa=de6p#5;?ZdDg)p4;81ߦVu2wP#eջn1?]$PaԷr3Q XC2"˩8][9w-J–uSvg |e&2Bt>k`T`;]P蒏>T~yEPЇKc' E+xOf;ӴCi!P{]$Q/1gMO{=jE$iQ%JfoQNS4ct VEhIl]IZM#j'I'ޫ6 7UOp׭!2\wH׉P+a*Ĥ=SHi sǬa;R` ӟvN"TlZ ~Iyo[oimW֠M!y;#?㽫 _YY2+L!=]Ƣ: bfh{nmm NE7vh %K2&&D"1`C@:Ds[Sa>XoFoYdV@6J BlweWp Ɖ %t%mF9bmZ~ 00@aB·g;&^Eo~mp.Ǐ-l$  ?KOl'pW&v-|EqSxxamu0,פKg /q_B ]8 7Fu|ud[r#C)XmP9v9b\3a_AjL-Ըc_p`f'iW{Vk{obCf[7CQ4* B 6|X98\GĕWAҗa>2r'q[HցJ[+5˷PO $^ψc¢Kطw/k]a f> "j6h/PN$tLe\BZ2ެ od)pϵF`?hJ/Gwߊvkn N`DE4b;@z88`r$B+)b ̻u]eڊ=?$gm(KCɇw|:f@@IΥrx=h%`8v蛄+Ń?#I{pd 9`Bt5_gl`Qn?Bu@ΛPt ĕfUϟ:#}7/4 YEqa6hA%p"hxQJa{w"nD~ff6%s+>j~c3xbAh`>)c^;iX+OVLLs= cX"nK<'7/!/wWu\(1q~/8^zJo'y;vT9&ˬB'廎L^ILy=xU^,`3i1f9?XrS֐?_ fݡWDə`8$sg`@OS: sE?QlݥcO|V[I|D@嗭`j:"xo6J['^1nՎNkYowtBIfu57d+sɘ:emrHh~Ar05e]yNjΗm∟}.^v<k`Nl *ƶ&bLȽLҪ1^kvn1o`xqwbŲ:M`vy|PZ38I œ?XPy"&좙^ !,by߫:%Ձ\ ?}&*Eaxy =ĀJ9i#L6Q—+<3ƷR-xwYb qw'Mc8D6"?d/T/ؙ7S ӊޛ.5T-}cY?vjz7Uڤ',34#}/ ebqJ^.d40&Q^%I+_i3LLJߧ޲.2_^ $ԡU_[F!v>% ޲^_44 *3HN:&B,⇢mNw|-q]ҵclrrӪ@h 'ԣ <]y7\ M5"PYb[pD@+np8hBZ4&ժ,rג+ Tƛ׿Z`ǒP/^a ?`6F(!ģAMr$KVĜ13Zdpo>h8=\~~D#惿u{/${u1'kj]Z*JDx!ϏB=ךR%7?骐&u}K\kő D]asv(BxZg;w(= aaj> Q؊Nn[p~_߲W40R{Eˣrc07k|ʲp-+PfyL1qՎpz`H0:rt#IK¦KcTK 4}-MbNC8*θ [0Dh+wVIIqUӓb5[`?U$\n =R~hm~\F+UUa&qbLy+N/"b6Z6@~.7 " X$a]>ٶH\[QC %DqmЂ pMtl<&p]KP5)BU$1TrhAʉ6ƅ(GVOc)'v7V>Мͽ:WeU0jc9Z蚓)&+ Ie0@p{gYDͷ@7--A~8;#Ooƍ-,c z!zK]}POX/;~7Ls<}u?}xIޖh4ʗ}VcXIwI;.ӫL5Zt@Ӱ8/#h&ؖV,'MۧΪ:Qb6`|"68Ŝa@Bb ||R硳eHS8×>* '~yo<.^qU!v-A7WDFkLY!s`Se؁ cSaVoeB${`Yw<DLm|B$cu96N8Wo"OOeW> eG! 2LcaHӂJǼ1R;ӹ6n]4|5( F0\=#dz!ւnUᛲ7tJϜA?\T-^ɭ[p6eϪtFophnNZD[bx27p1C <eD5Gl9_d6NlH(nK?xSJ*Ƚ"׍~Q9~Ÿ7Dzd60T@[9U1YeȄ˄Jn;p`?kX/OU"vH@9 Q@6Eq.Ć@kj0O&<ߺl%ebvxGjDp3|'$iGC6LIiH*fJOa81zi+|$S\5 I:TMȁ[˾#JHΌi-DCgUFQ՟o8Zx /,7b46M" /5;*ZSu+w8/e\M5fnƞ m rxk=4G)⒛u]X`>s_՘.#~O??+/˒2wǡeڡ]eϵl sTkk!=m8~  r'.Q 16R˪ێ,y]}2H~ fc5]KwCuY|6!˰-ccl?q4vRz{jm. _:*Pid(w/hۚs-ia#mTNJt%JGLM R2d)4(8pFbeHh (pX٣=nSfATL%d0)qZ>.[`)8IDZˇbQ6هtE62y5SP_YO4%ZMBzjc k<l쾎]dK/9ї8-d?\Sg0zkjZrr63[}2kh|e٩U6mPkWHP o!kDq4<~alq7]0129\Q7q& WL0WE*^&EڒcL4 ;ͭy͈UMp|v~C$:F@;F?U{ +Gx\I*:Qw{kyy\~EVfLTg]BXZV(yOʗM )9#vۊB[ 3ǖ{_RaSIcŒfIʹ8kфK2O@ѱIv!NSMP+uR 9)1!So46$Q!y1̀e='JT{v.xq,叅ܒj9a0g*BbE~z_'G~$cނ9=TQY_Ԏ)*jMwOE b >-IFգ 'F'߬,`F~bs;"I.) _hiC4^CA\IixOgi@mk =&7< Y Xthdxw.c^FћF* x i3 utupaEh ĤBl{Rn"C^/mJ{ 29ycGzA%XXegzMj̤)G }u5~u_i>ܷ^(ӷP.}YkDgW'`0i[ uj4{?b|6VɒX!9L$|#%؞{?$Aoӣ4* guo%[9rUz2#.W0S . Z?;6='̅텊w#}Yţ `WG:PjMeM>b+쓊8yy2q/%D)T:H\ӉƘ5LS>0[W-B=K\#=N^b]d9Gx ,fMX8 ?6 ?\oણ7n58u.3i hRUJ%<헲e-8Y%tDȣuE.2d<3h[]Bi.4isV7.&.x<0HQ˷7]¯ c>l%Ail%>@Q훳95E?q>Ɖ(e*PIfޕY s^D5PG^ӏ(rg?qGsQYF v'%~/#xc0vy.tG~{?ʑPh|jLVXa )¡5UжcB=RRjo'ѹ#SchFxhu[-U"x;[uf!$B-aS=FS.:j~ w g'L9_=1W֟GP{ht_p|y[ZL.!M$v6z=rCj9b|>:q:5}o-i,nb& W(ùbIҼ74+.%Ct,d4$ ͞wMx93eSOv☮ilj|*49,0*am<; Ld $ZeiT6~[Խ^mMi]oGnĝ njO#}d#a]G~.!U/s1.#X -e@LZ :V5Besb#zXMt1356 V )wX 9r)k3@%{W 50*ROwV<KKnj8@yo^c`G gQ5 &|ʥ)Ft$"ǕXcx$ȧuUC0gSJ.w}NNԡ^bQkXķr|vJvj-UCux1,J~mGӅ@KhP;v؉ ]IJ{Nb*fqT jPdhg"8L~B0FQۓSCx^A3T"tS8DoUD4!F#ZdžŷC .6]Pgm8:~ ˩5 sAM'Ox5 0X ŠlvZV^6xRlݛ~Hi|i!j 9b$`n,+?ΕI7~sm7+n*/X|"lrt| +'m3JnMy84-HNlL </W`@&)$g?ILrJ':;e53Ti7,~ϡ\Mረ|0+>Ԙ&Oi lh Y" `)ռZ*W/XL˙sbM38϶LCW/aڣYa| ,F}po`] ƣ7l.˼Pc{{c'}lkISFa X;?,YQSu0\It?+8Zș6B !P5-p{!p3R4(m>E\cBxmǯ.#"`jy>Rl_zт஢8\'Pƀ%]v0e %7\rσ8HDY#U:4 DzºYάf8mi,S5f9v U}oz!t\=?4RkYזȮg|+2''\ w041EL卓ǎ%c# ^;q-Ak% x0Cdgl 'L Ah?8MNqt`lIW xn)~yVi˅ݓz)6ȑl\L;Zz\CBrx/rx w4εf sx0' sx ëB#B=~itDGBHK{_^ͺPb ÚLd~P&]wlPnң`@ -]/ݍaKlS W`mŝ TeBhm#9G'nѨlœnٛ@? !gYx*%&;,ӆ/jtN&\_XX0xY8@WG`ƽ ٙ_TY<;=:t+JDm-\ N{f Hm]|6N4%lޯ^ ay;@u^`2VGQg?3Q_jͻf n&wD@yFiD2yf|iM!ޕ"w`91έb!d\:?YPxhO?_PF`D3#б>ХEl|lCI…mἆָǁjD! tEQ|ԍ`y`Eug>:7(~hI=@(#5QJ1(~yrqAFxG=gjTQ=hnt-*ԎQفTw3% 1LJБUg˄-&RBZcq:of=Z]BS>UJFKp=A%tyMɦ 9'.ő[7 i?ȺܷTLq<(>kM1>d PxI{%=vcI~mrϳ Qg.=ws8 t5k Uaq=CXO_zihaVN-MtLn8-%Pd㡢X8 fcʟ}NQT{Cë)zƲ3;ÂO-f*x4o%GĄcϑ0mB*[HkH)|q" ţ4E mrlkKtʊ-M" MG,jܮOLqa=eܥX\IJH*\6fFcPܕqo- cP^,TV:3ݙf:Cg8 #4[g2Fqgh2X꩓2_B~[n/(nd$Re xU/xq(%l겍򧫙H s+9)Ӓ3_A? 7fSO,lIlݏђadv/C|5Y2{~3r2#6ќ>IwqGtEaé)s5v= fm)l"xMGcM#!+3O0kpxa= j ;|lw¼\ 5Cjdfm4\nV,R[}-Q\fq` >M/dFK0Au QaAKC̦e,ZA6Q]s-mbP1L-gtU?lWT<+"-$ fYΩW!z,, #%\3;7,?6%AN [-C,A2 :ߵEMޖH5 !h'h2Wz|J!m2\JIiMp~Gi,zMA?Nņ &HmS~:n&]F&֐]'%ZaAvL=ZA;x#֔T ťΤs f&Aߍ a&YvFdܢ:5(qr Z)L} 16*mq/K/&sTMA/L#_]RDmRZ!7? ">jlQzc]`5@#߾g><4Q{ QO{gpv.ךmx%|8c;oq$/l J5bfbR! $HhYY^sŠ0<6C$ʼiM]mo?#X^\>+wsn2,4%1| lҺ|PNDVwhurj WO"!y"k\)7Z\NJb {dG|dh7VQz~ǣp{b16d_H$7Faҥ݉ !K&j [)7eD?:WϭVh.R=Wiz> .aQ} ǀSBݎf#2Ms?]i՗²XɁژ<y.MW&6\&zCplh7*oa >M}ԥdx g#ЩUzm&B!IL1.右Y, 1%/oi'ey|6J(>\\Y\׊m\GSc1cY7HJ!̚aw8Hd>h-oFQ+=&~nAuh熇LxQn,^>g۠A $?R?^RpbXfL%W7/7FuܟzR4[ Zb˚=*uVQ-\Sh^\/Mc+ܡ@)Yn?::VK!NDՍʵi6 m=hNexQܓ 3{O7'a6oϕTkB?m+)S[∤ ;ӈq<1Ӳ{b޾ 8CU$M7A+hFcgL;ly5jO9Mm%KȦpq)qGc(#:kxa*T|DIJU~t] 8A8ZȐbN: ׋|K3>NwDRuckmbkFin%þoG$j(ȧK\7fsx t4 E.)̈컥Xդ>lLT@Vu vNar6MdP\ @9{lX alL$ng'|Rwyి˒os %.9mݴlkPOiykVulMet3󣋳P-wzQ/ĉz4c T7y0v3 pT<c} obE%0/eqD٢w=mXeŚsYUDHǴa}#Vk #v0Hpb1NYHmqcFo r0 XnEaYW8rVeCV^~+'&`s/%o!m)|h1KGg$%i-@}aHq7,%%y+ .jVIi".*ֶimtc Y&|8ՙ5~tn-6)ݨgDSzt!%RPڵzd]\g\1Hռ/Zc~?-S'ϗ %{D 5쥨.'+ĕ_`$Ø.y`44G(7{dg6I!% = l}H .lj[blsz*yŀ 9Ht n}'لJA9=6mțc LΩ$)h Hg+hj'\z&܇< D2UiH1 ScQ,3Uw|贚DQZ-sJhi`QL[p`hv\M?HPw{ɂL].~慎N2檐+﵅?uPQ<ʨT7f1 hRRw50b)(/E?ŝCl>nOju Գ@,^dɜ6iTSӢƺB 0TU٩o]~&|%&v?հ:~孁S ,A9qeaIE; M +]2ԁ)`?pcjX^y:0YL-4ҍW`N2s35e? 4tK<&/ }W} PfԻn]ŒUUCHRȈrgԜu3HK0µ%Py9]r>qr{a2A ʢprvZxK5]mh]Vݙܒ+dA? !Lms"،PaКPc Y|BmD hzVϬﻙlX_xRj`"/.b[dQmDmH8\SbM:C<[d m++ʹeMK-'ܾ8̓(5Oo]VN.VEfƵr27}tqʼnWz&1ufS:ݐM[AOS3E1F++)_!d"s1KaI%-m%Cg."Bp)0!G 0ߨǷ`P^^̓هuV$IzEOϦ֦Q6RK`٥ۑcnTxkz\mtuL.lsڙ}Bu9U 9˜ 7 Ny!ɭ ]и0'EOR}OiYqBL9U:“e*챤Igz=Z բ?9!bCaXhz>j0AQN}phM&L@ eZ @E/sjKZjK4|5~8vZSHRʚզ9Q%Y٪{)M; ^1@]#bg G17rWdwQnH-)ybQR-gjE@gD\W%Ft̡n)jjܪNkp\%IXXx2ɻg yӑ a@zjtLwa B.S۷rwΤ853۱9=טi~T[H w:JtǴK#I+.ʭ]8;]WJ}̲DXkRiϬҢѿ-YvS_M0塡^h$I9Nޯ0YDbL 6 F&IRœ^複MB^zlnCMi[z,jJ^??~}wg?| OP>{$z&^6h¹p;;&j ..j԰-K6wft3=7]kt -wY">Qbҩp;d"s0nK\b&qX2e=sS8֎5tVgtV~?Dc;nv"Ȇ#`Ϭp{Kl_ "­QObbղbA{l1#gd5r *६φ#dco©X%,ÿNsda`pǓm%@f%gN ϓ߱)jÌŴsQX8-xJY\ZS_1e)ʰ&˞&|Lc!9BktT uT<{< FŐnaKwk \1ͣ(yG}eJdLE<}pzQ6I:{'84= !=9vzkT)%YdQi6i>6x#PoMbHܨ6秛33,.& y$ޛv֭^ Vm ᷵dP'cAE{A{c!QkEm;HlkIr ˝}t 7F边pItõzx OMmS5j~V_|e'.g5C4s6 svJ!%Nf$-`ս"6u *&_\ a{xsz֤BM03sJt@(qھK }eqDk :ܣ\]:x% P2$Q/VFy}iygfe!v y̝MxBO"IUj;pԫJg'ʢ2q7մD`@FD`DCV$ǒrcF ~o4 J:6S/&˗[iyrQq$ .4;^73{*L)Rm``oJ9i2>TM@]RT;oQ:Hqɫ(CtPKB))^ 1$c^[}.莆Pf5a4MR^}Zzxj,G&22bg>&'Iu,,%tIl3;FWq~| U^4g~8b V|)1sԎz$jIpGi1}eMO5!=H.jROcX~$~g I?Y);iE"mtZׇ2Ir:lo-X_EnB`/>S,Lz֬Bi'hYi<]z=g*_d xfXy$겦ΐdXw9Ӄe 8lɻlﰽ.qJ(ۂѮAݛxBgW(d^ٿ0&i>f/ r?ַr;P/wc+cITІ5-3ͧ`?a~jqMx3"^C|R&IBcǻ؛bs/ RQϴH~(e[Q e$pBovXqietdb⧹NN/vn Yy|N\HOMO_4ؚД/ Ks*%wƊ17В"tԵ ^i/YcMzhd]]2$VZ!/NYo+`ڙQ4[s:X8y?[8IAb XG#=k׮#WOw>Dj55Wm\+qD3"ũ~|vA|@5'./\ho%6\C6͝N+MEJV^:V h5 GRئ(.w&DV>Pn G.biUKq;Trx.rxr.rx.w0iI(}/-w5i^IYVPV&y-ƈsZâqX C}l QsgQw{@L2!2vu&S~ݞ~!-3bCc94FCc9@Wrx/r o~(ob Ń}vD;XD\҉B $ B[NO YyL^쿛C_>vuS.cEB3M! y(7j[ B9p.uYqoh']Grz[XKQ$j c5\.*|mz_ OqVm^ϦFQsw;\- %P\fs$E$:jILA{+Np#xgFhPSn-w%AH G%LbD AZ[w ¥( ֵBmXb8lqo,a;)gi"rSo=hyOs! EtF=iU2NPbX[{ehsW)?FOۄ_kJ9,AU +x5#J$hcoSs|~p־]x.b6u*AM9ho%&"y9~v]K+0×뻥94YeZˀcwKeUkOlo':NXDW[x)6/=[Dpѻ,fv^?O_ >kۥ4q#$C͂+ukcs.Ct#/QL$+s̜q]NZh<ó[R@ͻ";BjaoƶƦSz+BnogG\L 8z!QuD8{b]E6`ݰv %W+Mnqܟlryn:aiC_d:YOmj,k`[Mt{\ 栲pqYxtJ6hO>?n=t#Kaw*Ha8v;M*D+*A ϛkElb J6r _s\)V'Fh2bl)9{a0øzsR78#GmwQ+ R*G{ns8gSKB7{ycTx1$cGnUWEwTgb~[VhY )VOXYF G2Ôow5'.+GAYNd7+$%+ͯܿm^Dh&AMX`n͂"pnn ::pwpnR1rbѺ!to-ڐ՚';@}a1e\$x(+{:cb͓ȝW4Uء" 0grVhOv~KBZ%LL$;::DKJrT;um@RIE44Өx`ddt9D (v&9ZS?ʱF[nTdMr<652/*Z é=u>m^qߏ[No0#dMϓw> (D|lJIO,30^Ug:)a#ǰmf +U͓ւXPl¯dvEB&&ڴǭ9&hOe8@HLݸba,oZec8 5'3^m}qOhF6[$$ܿTeYQK9-sfm.t H#=(-ȎǶ!pInts/a$KJ5WN[Fxrb JZL8"[ΈG #DgԄf;x}4>swsOxl Qr2;oX\o3=½`2ݩ,Pc_ܧ".m/44N%; N}Bb+&w_5tM-s:ywo}&_*C%@Woo]__#wyطl 岸S-kR FƼ'M:;*ܘ 7Żݘ=pݫf>R}8y2`2akLt.JhH݁u)Z"QϚ?D{q7g?Xf9q28MÀ "x+9m;=@h3UnVݳIobxWܶ buup0Z\܈prBA17o&ؐܐSFon9&[, m_0ٰ &ӛR]ܒ-:![fVuoAqA ?r;/'fFdZ]8Y]p ֽ-O#^*}ca=rNn-Fz:3N>Jo"~bO/|+!2ikh5+sPg1hI#30r{c.4?uU\Ξr&E_OTҺRs%h癐![\Z_\L}b ?TAn>`_Y"P߼GūhHW}tmYMu&́- Q A8(/^qq74.El! y0z.a&]e*Zp6u=1A܋nZv䌡PHx7EvNص'K0N0`ޔ&ù^}H1/Ab,aX.,ٻ-%@'OA 7bc&23 c r\@;y#sW76ySeՅbV`9}S<dDuJUN#ӣ oh1yT!YTgyghe#dzwQ,'jиMLq;w  zHhȮٵfOn(4!Xs S+BBgwu􉺪&AImӱRbV4ת4W (:mۍA#aCAF%˵i Ζs@ G Eޔ!?!lɆ1aw)Ĭj:4L017Pc`,6vvp~|>(Y/UB1N.AG⧨̥eRE*ru/ * ?o:i(r Qµz֎KOGe)Ew<੽"{=I|%a!w3-Xdè[{`bFɋc`"!I*Ek|֍DwiN戎'f|hB )T}B IYý Y¥hͻe]l>^gQ)qP?Һl"y,Xo="Z XǡghbTq7g`A54ns`5;Jwd,nزr*=/ (Fk`v,=-͹T!enuuv{oP"j"7 23N*ʟg2ޡ*;8U&fU0ʬ0lBk)RA9HƟ% :x ° /::,7݉" '-I "2Mz홣twЈ͌mhYȤp PX2msTtn#ф W- <ǺnsJnKggp(|jev'xsOyCVyqNYctٝ NBժ'ƎM;~ ~N8qM֛'8q⭷N1ĉcoxC}Q55w( ̢)wműv% +KCaB`pL()<1mCҐAIN5/JsOR@d!:~K8S^T|8R.1|.CӖ-6/+KYQG Y`n_bҸb71ѢzvǗBe0N.e|bY) s}c٪W_~ |R~sАhdc{3jGC\ҫȗ|iMF~Xwj {? i66;͛ޓLOt1(;f:1[imCr+x{s.F~2imh-Yk6/3^M6^^Dg:aA.r/lXw^ԃR#S_1` wE_\r sl̞.GV$5^z{L- u 8)7Na'g>/_^/?{~݋[o;K.X!qD}]kuB@7oX 7_XLW G5Q bN#(Pp׮._kjmTi;b$lҊZcS&_gFbR_h?1jK?P_UV{R`SZ^or}+`k5۝ҟ_2V3PW_Z  X4ɹZ$tbOUGU(8<]Iы'4}?0J,g[)lûpq]?07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!NmiO$x*$Y> Dn] YZ