sssd-dbus-2.7.3-4.el8 >  A cU]6iMGÙ~Xh 3مD]QJiKUsu{96mLx'qJTvD;ga}]I,GT7 nZûق#r1ԲAk'֊k8K]yg=%>@l}q& 7R.~YRw?V]}A8=o:4@iTͣqEo ruĆph$1kaMdL 7hj.1cAf?RPH[a;@gujN6:bOfJ;E3d`U.#`]/a5xr1^B-=3) ]-}#ͺaco|,qcn>;/b6 j`&}`E>u~b6<-9Wf>SzWLijb8x;lpB,?d   8 #7TZby 4  N  h       P    <22 2( 8 9:dn>?@G H ID XXY`\x ] ^ bdeflt uP vw x y0'Csssd-dbus2.7.34.el8The D-Bus responder of the SSSDProvides the D-Bus responder of the SSSD, called the InfoPipe, that allows the information from the SSSD to be transmitted over the system bus.cuppc64le-02.mbox.centos.org۽CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxppc64le if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-ifp.service &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-ifp.service &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-ifp.service &>/dev/null || : fi%%K;  2AA큤A큤ccfcfcfcc%ccfbºcccc4601b3592d313effe1a70c44167775b06693dc9b72e7bebc718b6c9e8b094b8f09f028cd5ad8b15e0d13531d362fd4f515952a830f6c821442cb3f901cf292a9d93c2622d3aae3927e343297b9ca7434113b5623ce7d68a261befb98eb8d65fda2631eb70e5cdc8392c97e19924dc9aca4ddcf4b38a44ada079dbfd5f3b5c8738ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903f14b6f5784060811d6ccc96b02b18befbbabf88a0e609c7f0535110d628485ecd6344294f6553699fc9b9a2bdb040f140553ed03551977f114f7d0d7e7254e1c8a34113649fb542398496ebeaa7614fe87e93430061a546fd6a4015bdd652cf0a0a4a71aad2e5417925832e0330984e8a1dc20e3623b32f86c22a0da3054527e../../../../usr/libexec/sssd/sssd_ifprootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.3-4.el8.src.rpmsssd-dbussssd-dbus(ppc-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shlibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libifp_iface.so()(64bit)libini_config.so.5()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd3.0.4-14.6.0-14.0-15.2-12.7.3-4.el84.14.3cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.7.3-4.el82.7.3-4.el8 org.freedesktop.sssd.infopipe.conf.build-id3d48c359a75a04ab768aafe3443d54eba99527dbsssd-ifp.servicesssd_ifporg.freedesktop.sssd.infopipe.servicesssd-dbusCOPYINGsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gz/etc/dbus-1/system.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/3d//usr/lib/systemd/system//usr/libexec/sssd//usr/share/dbus-1/system-services//usr/share/licenses//usr/share/licenses/sssd-dbus//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnuXML 1.0 document, ASCII textdirectoryASCII textELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=3d48c359a75a04ab768aafe3443d54eba99527db, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix)'R%R!R RRRR'R R#RRR RRRRRR$RRRRRRRRRRR RRRR R&R"R R(RR,utf-8b7367df5b142ba08c69a4badda497a472a0bf4c46887fc1c11ac7924ada68e03?7zXZ !#,Aw] b2u Q{LUM5VvgWs}9Ifds9{@>Y ծE#IK02xj@SVفӌ%2y~89H]?g)Fc03󰅽&'ÇuPլ hƑ_>n 5[r(-΅>ۦ ^x:NSՎ^ppT?W QM JsL@;j1Yh.gsP}ɏ(f>wiд D< !"Y?7 'Morexjj1~ p_(Ym6se!|.bRuޭN4P!XwDk G*ܞqZ~m 8a@q&]%閸 S`yJ_qC'.ё;uo6ēcj}A.]9f.+8N "n cNSC hSaCv˹T~zQ˚졤 $(bjmV( iߜ*rs'cqR6@G=yxY*!k'5ToBbnUmqa|Ռ9?5f09qa,lV-y?ꆄ4`rS] ZqJ<rcSH Bt ZbB;G+Əx O(i_+f{A"߳矷;MWB颀@$/T{`#-_ ؕ}J [2s[:CƃH{g-M l6uҔw-S<\,'[k}ȿ/8S 9y`6z[~Yk'Rw4+Hgɮ3֬`8%HEbsRҜ m Lg\M~oˇAX|KӅw ^Sz@?7SK(s(@uOCj;Rcѷ$}Y#{ogiフ*=6qV.joW--Ha;cii-}Թ{ޕ4QI,KAY/ն_\"JLig-6n@ۙ\%\<CsFh@kHdq| G\!ʤIYlio*\6hFՆw|܏>aDѥny?6Ԭ/)?VdEʹ< ,36f)p2%h,GT8 ;`yt0c&H$n)+Nk6Y#[Vuja-ڳ>mQ@f)QqZ dy턽I !VܹK\l vuUrą ]Wa 0/^ۨK”߈ W`SlH{20w *llia_\x8T? G0Fg ņGJawGO>dKuAGV0*bib=XiT)>`ơEd`3@bVbh.c~Y{[%_ϙi@9<8$54_HnߒmF6ϥ|zz1(Ԏz9UەZ&Pu=C/N8{ ({4`Mekg O|>c^ZLH[h^Pj9q)|[ŵ)&.HLr+]A]XZs{ Z|q'h&H)a! |QE# ܤ*m̋k3T$jqzF7[cq7hITbyv(aDBXvO(~ڿJ]fht7HiXI\*8 U({=~!bdh(2OX$녫!+_/]SoUK=(Rv4 X /HiCcBAV~YYQ@%u1a'O>KUݕL$ ;|X$k80 e<^]GfmaڲÌIaLH!K>D)kH%0AjdkJqDs|rlz.$kjc@s@Pm LϵdeXgo5) Ҟ#?pM}Z QK! Rlkp[sp%Fo=qMZ/Lh$Es=c̓ P&߮>wJ q:}.,SD{!z * HL>@ZuG}(*DUyMQoT'oax-TR+LjD5hB.^UF~BR:-̙|݃@#Y]R\K1Zp'+p)فcĤ'~< ^ˆ: X:~ea+º=]Ws47SUCq#q{st+>5)ohAn~8pZέ)OLΙINm.J@J|%Cl'+F)72, l)Q̪f˙ yaNJlJK,#S`|6Z ʁĚ{a,GJkE#wi;.@KX_q7M4iH9ؕŶA͐9 M[k{;"VRyaNb7/\/Clnߜqa.C R:VN3[pBj]ߊ?Յ(YWoDq,"\rs@b_$:'!~oܢcG3eG0ni}f+ !%ЎMh9fRܻ{:bWUFݻ߯yXc| @vg!syT# WOJU~Gi;ftwj*7 ˏfEfy&o*qJxN}UÐiJA_bwC葋P 8Ct(Έ]WHWK̯|Wʘ>%+xlpgz_@9 ; 3z h5Pd:2(q0O 7s*m+=%Wf4A [`3L>t]უe Y(7U[@A^ȥWQD?BnImB#K8 "9V2y8," <*Ved_ªʾʁ&Y0tf X%[9Mg{Us 7bK'L)uI<oJd YFr]dOť1oKĵ7dP]r K f1BbF03\&'no7@3fImՅFMC\hNn!Q;'v |+OɏD!MU;=%!z=OB:yhs~8%.%nԍD6W~9a.hAfD$qsLkRܔsE&Z:'RzͪOm?ݒ3Mgcg/Wx  EUUҼN&2$);>`U(|7lot0VWPw,ay|:8/57ձ.dq`P\?OA:t5tM]TD:ZeMl5a> EBt b5`E$1w٤ Tw T #H)}PIi<r*k |w,Wϲ ]HwnQT9 WLՠ`O͍]unƯ.h쯫Us`#s8΋銢WBCAq%D 7҃~|To*FZS[AIU3z8d#fRoYXQ5GC6Îl=4V_ -_3$3WpTXSOW!O# Srڂ_RB`zߛU$U1I3ۍy6\䜻'=E%Dk/f) %-瘙w!14iR'밧=:t_W3<84' q'C$ P]T|Ԉa@PʥO;8yn=+aW&VA%։I0X5IPHaOC"k80ԜB1\@`VZ6\ծzd@ .^gbVNl綅ʴ)^^&\KىQ]""UvSaYeP 9ېF>Z|`s3ZiG0+^mj^U-ROwFĿ0%UU~od CxWo6ܳ<.<3jW{)o'zR$v| Y!$xBf4K@d7|d6D Lp]a*ҍBݠfMm< P[}rĐaE˷suBF}gaM$W 5JN#範_W&w98^|yqUH]GOszwYщS8{//gqd 5\gT)'N:E_=HCoYq Z8N̑ѱm[V$e|bѹLI6$@ J(I%+H[GCGe՞U> Q}W~ijH]E}d/0*JB]aal u;找6F[yƃW-;ҝ#?&UO&G.7mJ:Q9S}Q+dmUOvCgt(3eWj/gB8x>6ITUĜYNZXf%Rc{+(agn)WAW0~$gv95NصfJm-;f`t[פۊ,c6 >ER4DŽ/iO#b)e_t*Bȝ4[T2O"w;^yQn(!VpTeӇE&СJ3fMv?W@|avBfk}-hfICG-d8PEonqF%]IXjfAB+o*i.|o?}$l~px iPӖ(P? rTAbn$2& ?Rt҈1b:BI=BKՃqk=OL\/޸P~p.d , xru()0>dFrL5O١0+O?xefNR2+hg|l3"77caƔa5YʩPCy%!XcWn`!OaM8G?gGռeө+3[T imCw~76^ y;*dL25K1er[?xSP(πK/-WTfY&r&t8t6(l/agY{G֓LU1Պq ^BnvKb3"~9B[ "m霩=x@n,\ c'S#':=RX;A$EkϑҠjozc6$Ã6&0Mt&]W-[aVK?QO45gTI/K9[3H{;]J nl) o-IyC^PeJ>t ˃i7T0Ҭ tq9&J=*rY 2Anˈywm1;2/Da"u20q )Y0V8g.*JI"Ӥhoy( kX1]eH :gKϧaAkz=fe ݧthO5Zx\jb=;o$RdT iV/sA߫> g-4i|u , ѩA@/-EA෼|ÐTb<ߊX_.StI;@3/+/HEޒx1m"_*%{& '3X]]Eo,ME54ItXv n76OEp5s $k}yd"JڰNVxC26C|.6Mg39qVǰࠋdw:rJʁoOݪ+'ډx{Ƚ^|Cg,ϊ$@N0e}$q Xm._o\#ܓ0N?;,74HsF41>hUh7d@>`CG3?|+dNATaA{܉Rm估,Z ٺ:IpʂC0APo 4')ˆ(O#s{B,KUQ_-J$"?ɤނ< (&+Z-f#_:k ?qơ)1$HZ϶i^`|יH6]uyVAꚰV)Y* 涎1ϷW8PG),2_qU,\|Ck nom>邧2 P2oVo=@qeNtڵvc8[Ku1{[gYDydլmFNCӪ 4\ ^y\h .kzKI9uLi|W B]¡3-H~|#KLq)=:sm Y2{`0(oϋE3&f`O/<v1Ke>>fPDq+TRiƃ/*vvұs&u%cWlh(RAHEm'؉x~|޷28wKp=S{_ܵպ@oJ;cx֡FkFzwB>g\N[X"Ŭܦ(X4a:#\*䏼\bi;G^g%xaPnؼ[IW@:qll~LKc]YlMl/^L`ASlf5El/HzX$VDu%Yҿ6MД?jM UaHe: DMݼUiwV@g`~N(d:薀T!O*9$|gT8=+ǿT[-–))B&'y P\#Ͽ>>,ŕri1ug8"3`E"E~=C8M 8$K{tHcVYhl:AO* G8i %d$-e7_2Cl qs jZڬfb'@|`g?PK#U|8 t-Np*;L^J.o=Կup}F-#UHNZ H>-񊆉~֯:ϛfd>Yt-;:FVWs,xHQis`x'!TgyL6YF.&@3)p]?TΏ`Л>CBH!7' 4sV])mѼ<=hΐ7JHQ:A ^ij;=!jUgNf>vO|k8) yʳ_o*>W"/s^9{)8lv\r91lk7o+9eyBNT` iH2fNxS;>j%,*G8 bH,;E4B7WΆ4Gˏ.=YRaYXKRȣc6>d(vpmWs+gt˲˅яy\N8&R7&8]D8P!gn*q\PY<}#zVnvȐ9hLj!>,5z2q[5nf~G/Iy%h>)W'/OAߟiNJi2B%2ں+k32u!,'to-:Aw`>^\j*c,Ɓn|X Ů"y Q?Qug']P59 " kyZ8ΨuT.E1B31)?%:]+O;,_Pޭ蒖P,6?%Ÿ2A93j>s^[?DKX00௱ځ!\$*$%яh?% cv֣7A"q"UKğJ5- bX][ (-O1&WZw.pN'v6{~7YMsM; Hn9c14Vώ~')քJeQ?zoX6TtY@̐Cj[;:gKTѽd#8~޷SkefX;`GۮafD 5"o$AlgfT5H|Y)Ώ-b噌cGΥ ԁZl+P&{ pFOq"c^g)Z_FQHM3I=&䈬 =v ,*gX Y߯M)GPWAQw|FZ+C!h[e6ei]mqd;0(*8Vhai+-` wML5⋚9/2cz-hla_́I;t`Ⱥ7wFRPMB[]/.!&`Ǝ~{Q[.anOܣxZX;9FܗWS%b3xGJB5*aF[0b3[fwMI883OdktZBi /rq3c6U鈑XŦ5]5BX]MQ%by#CbB)-:y]uI$ ]/*3y/zPB45s'LluM+yo(W!V e9_w#8랐H=0/m&UB{" {(v҃#Wka^|g- d =Vh@ vw[^2ޟG=Or"6%2gfE9Ѯ~r{1GhyS4dPqɶ5Df/YWz_*W -l}?RNj0K"H |ѯȎJ$Al='Cg^\u"OϢ8ҲN,iq\|7m Rc[ "󻤨v Cu*͌#;$JtSO**3L 1NBhD4|Qai(rr0 &Hyq"wt˜(%NmBtT[fthg(q?aCy6f Ӵ*@I>!Bk_~BE`RƎ[x!i̇hۑZ# =q^|(y?O. GɼlAsܾe-o7i=5770󙣤,UdJ9*ȟ@.~yQ;tOwƪ&U)^cm^CIs=o>rKs\].t NQehR3 (հjia/"X! 4N2':%EIrdRiXp搡1 BgzBOua|I۱M?͘ʥ2=vK̬Ї /Oa'*Oh`~H@ZtE>aW;hE3 '(/ꏳ| z鞮5j|=#Xy~*enZC `;@K0f^?%,ƥ.&"faV?s Ue1 _ENkRvuG.݃̀ZpQVYiD̉2!dlMDwAs!a~fn1ZAݶBD_sR/D{]#v“3>Rl ǞrP&\ΠbGghM E*=$yVώ뭦='͚FG4:t7YU%d+n9[kc p LAi$bP cXrHրz[24Xcs57zCHmWojP\WObQg!̪ 0,k%u$qWqTCuO6]&k}1!kL*(h eWzÑx{W[>"z7İIR B%)崼׀8s"݄'ʹ{ef2v^IF Eч[E~|{9Y94 Vz1s[ Mcd[ UnxWVpVFpzHgl=e(FR]9!Oz(b/9YLl9](N5̀eBZ"JHOy#J [`z3y!ѫSxƒR)ָcr7yg`2%cZxw+*$R' tk{ g͙ 7Uf;{%%N Ȫ;LI|odQim"A=mW&wRkRwʫkòkI׈thY5.[R=D蝁=} V1eu3k3#T*3lDl͓?\Un) .\#Jp8h`$ɔܒQM|D SAxv5kۮUMG^NN"cOm یW"Z Rw˩wf/C D<p0c'ZXZޑ@\Ò2R b~Ϝ`aIe_~|vPNB&1[ųTmݿ[$IvQAaESkߨ&Kz).Sdy' 7gb3/}\3(g.fx)j =<;C/ ms.=98\t6{B##4E᯴j,mleBҍD&8 U&CC̽W/n 13l툭Ezu \{k M`*>I#40T66YE +k|%DF=PDE   0qh>2@խF_Ԁ•[@1[8+1! *cǔ:bL O퉘u)]P ؤK${8܍03GLV}"|LٲHRYمatvvv[k΅'P*y pK>_mcLи4R`;Y{4o+,i]NJHEatуL/Msa-ЋƊd1앞yk ΊV!xJAy:SM#ʬŁiQ?uL10I C$pDR Dy;FA\ ˘v 2 *ԃ)2D PvسFvAl%{cV1L [#~6bCm=Au'0 *JYNțpByF"}iinCT_Th2l'}kl0ljDnjzhWԐCad W2uF9xd,}ja2 i&*"?I y o${\,wXɺͫvӋ-tI$ĈlE~?7R %qvgNz-sĈ/h\"*ufPpuIYF `)~1DG:ޞӈ+@X{Xօ`GRor"k`gRs1&%EmbSID _M%+ٻ $y1v|?4SƊˑYj`r<#=OXus5L ! eNL1ׄc|&vh&rHX&YvG˟kbϋ'C@!&=|=A,`]J7!:^$D]m t*mmmܭ塉JS$lD, _cǞt4H9mOg22U85.rh 6ݿRdI2b\Q[2]J]W&EKE>H꫌HY3<\S#iwV'ڟ<Q{85Ue8Z7J,(@ʊџ|j~1]Wtīy>F5M",ӗZs7@=tS&#y OEQ[4V`MgonjE<)ڤ/niV}<O먘bK]Oq"`99z%3WK -ⵦg׵c)_kܘ2%!I3Y1FA;0_²V=]#[\Lt-B/s5ox]4ݕO )7}m1% +''3+ŋ!-㦾Px8Hf{o%.Wf2NA+4*NeMӃzgϧFE D|s'#ެfNf͵XVS;de@eDmNQeJK'P.C#c'? ~ɽ%<}؂ ($xb8 =| 9 (8E\Oij޸ u)OE$'W}̔Êt\ B:kE C GBAp.LuwϏ --M̶ ®'$ ->}T^Ȁ,֮x:ԙ-([dUhƫi &k5i3$(ȜΏe;@(|WBCsv!K ^)#,m̚>w0^ =* f`pq18I%Wm4˓@+iXAvݳ*FʟdZI礰Q~So[92^hv,{$^!wFAh %>4V0Z'( ^(jd5no&*S7P8&93k,{mz-VsgD)vl~a ;u ~JAT[0&q̉vj a!ffU#BSoB6M=`M+hZ$75Ko-U!s-d_nbA Ăߗ(p݈ zn&akí2DnQ K5%R`J-¸Sl2z¿B7݈<Jwd THV =$ܗQ.+7EE{9eBA΀guTKSI0o ?#+m5Cj`3VE& S ИPOG@U&dgz+ب?aބm/MC:6#Ƚ&IȊ36~B1!܃$XJqJ'Cc"eN~`ZoSȓx^4 r5gp6MR1@d?unØ(lEn!l< k)ַ&;G 9(]JɭPaSOh[UN36}<)ettm|҄SBdj,c0V9Xኯ<vQkqD, |$aXen{ }G1z\DE!ܬԞR6'etcGvd_4tg OY!?~@젃C2^RuAU F0f$$Уk ʹ "4EwԤ3_Ttrz *[zyC yߑ4S#P?mCڡތ+ݡHj#ߙN.q ݸu(b93>=DM?N6)i?%R0\3'/B7s%U1)*l8R\|h@`o }L| Z{N;Ν3LOφ{+%]BrQ^SEMj+ \KA׷J2d8u%KR$k"Nw^;olѐ_r bTq_EGm4%Sjjn߄Y٦|H3Lj&>>ϸ$yWc~V~IKc,Ѳ6TR$>U)ZNMK_:Q궁 Nk⾙b{}Hyg4C}sh'3w!lzh>\YFgwP((x#vD7^=; 7nF'lx`q@й+ͽ}UE8R3VSHG\J4jvMD B EJJŒy|3@ $Z~^++ `&M:'hzDԻOrD/eݢ- R=r*iO#U3DiaC^ Ņ] *EIyH8gG*قy??Lځ5w#a;+ ?Qġ5d7m#msAڀ#qtOJƘ)~lz2q:MhXtp8]'f@]7v#}-N ΃O(tn~kxgE 2xȳUVicT|堊7Hz6fYä``mY$,W Ϫ/ك{o`QSeEծ(OkwjF?qEQ'!E#%?+o0h.=ԸNlh3¸z@[\sڧJg,^NF]j44G/LTtܠ}±_ ؜4ƚ} QS[\*x?us:(8DN`u3%$A #5HGl]M3wJXb(n2.b# ~Ї,H"&0T<\8cX9|ݦ_FNŐi=Р?{)SDŽ@ঞ?dܠO%UIx#e3$r:RBF :EL;@[_t1Ǭ\ݐqjcwfJQɛ"Vvd%r<Nw_y(`&LO`$G,# )So?#+[W񅖪Yw_V#Bwiȣ!CG!TgJQ_BL:_Q/Wz{ }5` #v߆9ќKY| .Ŕ; leN?h 2+I.g< gjBj ȸoPaF9?䊯,5myg[,4\%Ү¡/M>a4iƧmx؃ǂ8'd8J0t%g/DR!ޱJ~YB]_co3dj Rbي`\D/4WʍGC4T ?%m8v 049`j%,(KIX\YMDln ]wwï}fAnHD=b:wd#՞O<>L~VvNm2:cd qB$H 'TnG|zs@}}Kx3m\ E?ajrIl|E.WRr19=dG1]WUnʖ5vG%;?>W$saBX*S+偙r0 d,[kЇ:HҠA#EW4K ku_- mk Ȕhw@Bʤ] vLT+:t§|׻oed&TkL(G{Gq~oS1ȳhjn2q_ UkpxlE`pR"ni,g)91XTdۥ2BYm9k r2#*4c Յ˚ܷwsGi>7Ʌ7޸ f G% K&5zhOބ*VQ]TigAFZmOd1Փ0]hĶhyx24P>WZ۰·ಝZЌh"۩DE; pI)T/Z\^L_Š۳ 궧,4> ҭg+!+g;zSl>5oы ߊ֔0Fr.(RA^@qlG BKPH9KK#h࡟o q⣳r{;dYшĽ"̩:nw7$C\(5 w X!AAg1P( w۔У7p%Y5p$ &$Y'?i)%!@delz@m1#n|S9p4+&cմ΃gc kb)$(k~PPX+> EHQEEgw4`ϟYǡ= s=F\!_aA"o!숖R2:ݨ+ÜE/P$qWP0ZXAAUF\m]`fPۼK{ GYK5Er s"$. h?Q蝰4`0V^.)΢Ӄ,سsDui`sU|eֱUԆt[+<֗rAJc2 10a/D5ni-P'ph8O`¢ ,t8V~0Z<;^.7 _c74G= Ԑ :{?9L|$C)#. 媟isJ ش8 _\ i)PumoVN}nN H1S/_(DYdAb<)G1xfT h;`M옵Ovֻn_Е4a'J#E=@Hu-8PEwm]do!(mWNhH հ`>:ƒn,EeҖvZ)0`%'f >~~y|2F$Q4h.HQd0M2Roz1O]Hw _zj?W~EЧT9T@(&yb坺⑂."^zA,VE~?ey2G?p@լ&q[Lb;vC xJE&4_ѕS(>Wu6fTA`{uu2ф)|0իpST!"0q4zUmIQhNUWoBiHY)0_R>XX=!q> 7^aԟDKN`0BwJ)B +$$$ݩW[LȨ4VԃybM;Rwn j$ˉdO5Xč0Y% Cޢ*EWE6֡;CNs`*Tu\yNG <P WlB1S 䌸=O3*ԁ ߎ_ ^'y&Y!~6{;S40~n{rNWxFh]:[Vo!P?Q9ʻ{ 4!hw_$z:|VPҦŨʢ⌫Г]^8=nrw+pωV#vpݭn0?ܳh 3'7P&J ٰ3Ih$T$2Y29x < 4~`e*w4lo2f,0XpOSF8 ߆úpMϚkD<Qv~/R*q4kʫi4z <a@k.l{En勇abRU*h6~n<"^I((jOA(MYvWL"{KʎF-j6! E 6i7av-\ٴ/~xXb.MsM4u}Lh 5sWDk4_9Q}ipZTOꗉ&BĽIdK@䜨rUTЈ*V$ (e/oL!p N=(['ˏhP$4tgK53-h^ٴ'9MmWÃF:xȗUB;+Q#O?mUS:gP'}wøuU$bgV?VHgjd,tnF]w'0le#. EdΧVvpT]ևc@Nqgë5O_NHBvR07՝\T}}) & o2VMhyu|51R}Zc`q!"aQXtyD$S]~},n9]< 9Pd :+q֒· @y9d0P\p#yBibr5ޥVñ5zq}7_o"A 8XvZ\v&Ϟb OV852ϋBc-+Ө`Z:R%u/Q.Z}|yY0tW.-"+h# B9:i̒p,㿭*wXWS:C#bԣ!ZJLӆC# TxRoDf<;fը&~rTЏm1 |_L+eJ2'P;sư;5څ+zZl0mm,Ol1u=ڔHl Wu!ZQTِQ.M6?1 _?xW*&JR=(T[-]W8'U@T2F+WN kݽH o*[1hf |`!=+ӵ(|ʀNY2>쿭џAGXWتRe}7}?7TYj~;䀇x]Z%58+#2k.oJrXf6^(s' :ꕌDoWC'΁)߅Ni|C몋}TKjm= 끸kuLXW?|DuoBOAIY>OHԸPI))=Ôf,C%A DR }} 5&:ij4ba9xR!=(~L%+6avpkJBL\S`HW Ul3/4k3HT<|pgK,AlF6SAZiT邅w?a866Oht: :,x$PwFXZKɒ-^4JHw;_B0BU=_!5Ia#jx͇mju>\7HV+> 5R("!{u 뒁X䞴Y3ZM5C<Ϋu4-bܼG.ee(e(̘X$ڹ*`\ҹ5%mx64&R saVE5V7h*C8Ώv t#\Vfbwv!p 5VJKfꇥQ|Xvtb=Q mM;p0x/[LF}r\>nA代Y=_/ǐY /m-B1QU6E 5=ত?d=LoSb ZLhʨ`[Wo2)]`xKMQm"n>xJJ{l#` P'JP8 ~NZ&g'f^SBy1re0EJ]O)Q8nAk_ţ6d\JooV5#]Oک@Dۆ3"$u]JSD(S5%Pmc W3O$zxau^(ԛ 5-յv2U=:F- ,u^Y.}hs4jD:~~OuQ'1p[TOx@M>rp/pׄ -94N7䑫y퓋h⌫Ʌb6Qc>9J L#H04Bmw,S%$v?}$-"+MK[4‹Nh>q7 Z:.`d`4cebF>׍xEq0^`0Yq yIV_a:ƲBBGU?mjo;(٤H'`{#MWRҰo5yRKsEDtU>Eಙ旀>PEovvHIBjDzc"HJnWIu"z#ђ6-UB5p$ $+*]2v{e~'ɻy75uݴ'mtz:\0-1F}ӹYzxPw^Dg9n '{GHsJ/T'&tk*C`V_ŠCse,esjz\g]Q9H@QEAF OMG~tcVp"/MRq5-m +`B@$4Fd)Rף^VT~rcA-j!BUiaN8k>g]ɨ5*7Pހբ 6J44]]Ʃ;~̎%cҦR+zO/(,4))Р|}ڼ;nl_Ha>^K(լ"&Y w26+f @DNμ{CbU5\%h^p!NDrg`8 FI4$ȗ@[ Յd4}6@6`.s!%7D%H,f5Tt~e}gq&4.D^F=r6j#9,jvG|IIaoAC>#5G)drpe*j;srz RO`-=Kʢ];YRDid,IzdUq%$?ΥY+X;fʃ{^%}jj F^T X1P+Z(şbk]M$|6~e  +}=eJ~:MS-7 oZhqS1H*|0^M1BUۖG|:L<"йt Ab(fZA 9Lۦʦ:tc,͈cFrڮ__-m4)8_2i@-3Ra,O5O 3U<毶eBEĚAtYKO*̆h>S! GaҎ".\_*#p=@aZz旑3w]sĈ\OQKͳ%MJs{Ίa{4~/;K7a2QԖʬ3~5P!uM[RBFtRqTgu: ЖG?0%Ab]&JE#"ːH$XC1l.C\7Z%̵c|PYhd֚eml(6f]6P j.n_ZؔADqZ A+;ZX K}n:4}Ѭ1i4~. 4$S-tBgߠey/qtu_ѾV$/M4v^QJQz/}|Mˉx$vZnkj,~UrRG1kSeզ Ms%t6j i$A5x:hxR=oyt ӧStfй]ڈ M8zb T#Wvm[hrnpLȦQiZ8~0](nW]4xۙ/_$O@ZiAX Q'@yr܀B.7\,8 ʣђk3?UƨĖtt(˿. "ՙK*dy6A] =q$A1d4OjR8`_A#(1oQޠj,lc-/Tuc/|ƔdƢtһ\6nPg$H3P P,KoT8)2[8\A[th uO>_Ĺ(sW+ݝ~?[|Eg") ܉d8(Nˉ*ŵazEzopg,]Y2)tm'=GT&{HH$_q>s4#m[)h,+ww_ъ ,}m;/Ląȓ\IR376@ $Nf9pqЮ-O wk®1∆GCuRZHnEQf@./'hȸM͈Z҂j-gB/˦U6ᩂĥh /CA臨a=j> ju #τF05yxM*fuIol3{>\jQY"\'1|7X3n4bvvTr!{A޿YiWeʾ I>HF>ޙM耤OB&GLQy׏g +1v4PSYƗsJyДZQ0d eaƢiln C2sی}l~9"N|LDZ9Dc=yVɹ w1S5p#`:jzȖB:w\錾Ww2>LHKe$ W& ϔxIܑToel'*F<'y!~)4EDUt%Qڅa(-ʏózlam®h*  cd\Z`>tγxb %SSC+ɒ' RZ@]QI^5$Ƒ)һx-HyY *ۧ GjdCAŗ^ni!vT;-hE_jqJpŐ0HN%\ n v@'B,7Eg #fpx| ^XCHmhyDtyC-q C%$P<*ox ɜeGwP)@veu>bF&h@RlANY' ySڣRp Z1cf"*s @zR؎-(h(,D0 SPcl>b '!id^ G -Tm۹K^K6hj{چ8!v:i-Koɒ& 9+(֎]-ǔ_ FaO.#hC\̞cU+lVdfq&R>~Q|RRgJ<,s>'Sp37`.j5c HV%恶UŦW#}GŮ*sx„ue `7҅qB) #ka%K 7Wa2Mz9?ܐ͟<ƩZK OͼxU$ERnmfs-+veATo''hZ;E^*Zao/MdoUx=<$<~\K /= U7XS Z, vV7S4':63†Irc+ gYye pճben/UN|öfe=y&i2Ʉ_zX޹܏XQ&i,$5U<}.Dr M0`>LzmFzOi2 ]5nAch<=v}a !}2$N^!?6>SJ;SƜ.v-U xi>Olu|mh1][͠F+Kd8\K;V1x9YDQ%چt23.y&\ 6E>]j&:89o5Zcjl-ğ قGAz>0|ЅӼ f,#")_-:XB3quWL]դZٗ=a-ɵ1^nkh@r:j2-/s0V7w2Q }lN_m8]\:Hh3++Lq]\p)pr1hjZy ZLmapOoԨvPP1c ow7~s:Ʊ\3lH3$y{\ eM)}[8еgం]J `rƢו ܉fJ kxuV‚y.R5w'=Th)GHyjWFkamWx8KH9nG`­ ;)X1V0C~V|m"{V{$tPaG<]ag0)!cG4HaWjN.97IGj!!w~p$QMB`A-xYvF٤ng2?՗4|_Ň<0+\}4V+,ٜ}> &ms}=/x]-ԻbzS# }U9'EEDsIAE(%9l..ߍ y}UJFy2B6 f̷3 %G'wdɥB3{zR24X"Gֳދ$St>cg;.Z Gl_,yy,v)F ]a~)fl ]i}+-6B Ƌ fk&J䫘3#}3QTޣz9ˌmf5pDET:>E"Է~rY%4GrO{;KSv.U5# u&|:oo@QkhHb5H`y_~LTMoz5R%avb!qm^>{nx`dB@`zvzn-Fƨ9:P0A+gu'%g,e>BtPhհC ߔBayАʎ 덁1=̯d##xڕ9dè' )/D;@;l,mAoS9_Q2+p)ql`8&߶wCB)v%`@(,FVG7R:=Qe_O.e;A,@>(kBhn`j.Y~y˿FPPRr樈 $@rxYo'A321P-i#ڒ5 /*mP?,ԱsZk>ϪrhJ[rĜ7dU9ݥY5 x.}NR꣎NNѰ/.zk&'T7Y8sX h[%Y8Ntbztar ySGOWcXb'UU+vfՖ`sV%Frܑ;>oV{bA>Ni(Q@?[O:4 d_9G  ?^\sqA'h(¶CQ~8ecyT5_*ub,`JF@pD@C+ a,k(/'c ;dq"NRȠNU~|;EP)FA >ّ(Pn[ّj0R +2 ==3yԶP˯ kI:tPB%3`*t~tV;D5%K[Sr$L2kF9T!yO,9܊.ƇSЛ:wz u01cԓjxhVZωPq.)[ ؃soE rF c8Pنl0fR[Dܯ%"K@3`r?ZAct'Q52=dU92gYk{yߖt}-rJ@IϠeΟ{PŭcnAS31FOp<-|QPt̂kU.+<~h+0Zޘ4Q޻hpܬc+rErcxI!k?//7?OD (:5`@m޿,K|(ϵ OTȘ.}.+%ҕ0 k˘˪f4 ,|y5Nk3V~g*myqTQ񷣻sa=zF۠|R%CML Qx3~pJ1o-~f,%{br$[v HS\[UEdxpK$-&nm&[ CaKCJ3߱33_J<+0RźJdV Y9S7Z|g",uS˙PJSY>ׂfVG3h} $?NTJ}\'K`ɴ1i( FteM5Ώ?vَx݈ ?Q"dЗjl҅ ,nqƻN,ԟ½K~VcMſk)`)Wrosa^" 8;,_o:ψ Q>kiyB D7V*ES+&یA<6\! ~ @@E&6TW<Ꮃ::+bHdi\p,#곓%*F@ @fi 'T{?'QhU*7+Y2@3N3kkVpȾZ;RP xE~c|lZɺQ)R@O/vS0bP6{ w vq>nd?`[8󮓙FaSe?lEH^s9&- Ů[23#u3#g@Q@fH~梊^IK)邯Z {  Π5XMNA'au$4vo?Y!zˆtsg: #t"{ sfi˘ĹliH .?^pӅBu/Tx䖶RÁ&L$];-Xq@J6n@rEH۰,e\)U]hU] ZY_٭A8?rz-kDS_|!JS 74VG߾5 Pb7% /sj{Ԗ@j'Oϓ\@|j<׵\_85v;_K};}ORb.ve'Ӌω`e67&T\7q6͊%Ǹ4Z[Ss F?z6g&.G@{8V^R,1:/ mdܥe(o^xg}{_|xGz۬B8+i#CG7}HtH sBj@[2SRco5eU1ǮPp'*SZunjoetRydwHy a3uJS9o`9/h5om3E:ysA$4U^NƴMW 2R};29d}{u%0 gQ eX)[O>⵨[.HȹhCKH7ie(\NIꌱ2 HNx q55,!"}`!ygR(1 P7"UkeE7VW?ỿX9مȄ.*=è\'m|,2A-6D,4uR- x]׸QJ^;FpԨbERZ-NYe7ѤZ-M:(ޮTA r>k.0 ?.A:ǧJ+o@Mc, ̌b+ܝ̆7{k`hf=z5{ !BgPu)w;UN'! mO+ H#v['M.S(bsmPZBS+ 2 דxy\utTރ1i'T^KژuT!QsYHc~@>IMpHjB"BSU@7:I%b@k.9Y~"wqy1$kO J1F(JARP6^0{&K/;:䒚纶`w ;r@;7_tO~^ p Rn1U=*b.kRѿPkHD8GlT8S]4.)(bx Fs̊]`%Pu#6FPD~ݔ{n0oy#-Q@87'Cw:vUw3i,wg=~3e1UV( 0t8"<-p}v>*r#j|0GC2$Vffgы QP)nZG,0[Z=2PoNQO7dL{xZ@ӊ̐H5 5TTvҭIp~?ܵ*0 iro>"O%-b-11U!ф/a<|KpMM 5쟫zcl&ZgZwT=AoP2kvEuh㉂9{kh?366h?-lhQ5#Kq|aw<_D>,S I_ʕf EƷԣy]*΄B}mK0lr&(V`iGH \~j#Sω;Š$j;u;*]nfsv`K0D,f(3iqXӄc3v?9C@s缌#!ahiwY0bib(KZB!<"aѡ!kl 濫z, H;Sk#O43TklR6x#hrJ(:6Zyl&{;aԷvu} +kiJjd<0"D&qtB H#|<^]lPIq8PVc u]N9+| 7ZC\vZ_$7T%@!Ms/mKОn㸳q맔9؊\ G3 |\o3C!˷ڂW׊)>}z.QǑ)WS6A!ˑY0j0.=:_SgO{er\ [EW y<hk W ܚ5GjS- g+oXkXD!" [Ryyn9V^p7i~5%< ~lNYϓ!?_p3V絊È HJz U h Orw):A2~*<K(ptIRE qPFv|jG|RҊ1nlK L\``i, m.c.τ PGp0XK%0[o;~oǮ`ҝ0 8h$w ێ]x&Lo5:}fd+<˱H qY'5kME^?ƣЃ(BɸO;&D/dϢ[Gָ2b]=yeEuz!tڴc\DU+ЏfSj O{-`s XITjv = ̱m~vlDhF/M-tNP?GsqEp 7M)Fhv#C6ad0H|? |6[[i(+:7W\PIH}d:iAe{Rv,&)B kk ˝[!}IJi@Fbtoxº' FHJ̹ʇTTa1T1[+WlFFnUB|ǰfFK⸴:ghYw=Jz+7'cRmQ*VWH0l&:h:;;ͮ^D#|jfaG"˼y`w[d';Y 2s-s TiI"5R T ʈDڇFUF˸iP,u.=]٧\ڽ&h}GLUW4;ae*P Ev'UnY8nєW(R#?Yv^F4ۉ>^NUvK#YPy!j.Q5~Η})OT.TҪ3k)e2jg>V{9$:L @BAƄz3\*@~xT2%"oVׂI_Ҩ#Lpl׮}Qߒ!ǟ*0LInUV{DMf20as:!r3@Mz t ˆ{\ Eo`CR(c\"cPTmj>Q>yLLeω\;Jgr@lڑ9G{_"dl^=͎<tC따CZu3p~@+^Sr/i7GM'D=}͘{ fQVX %+ 34 c^1gaFKZ'鼶?t%b8")A-pG݃h)|:C{*6l!{c,}?IqmXEI6tňi,ľ5 A;g)S=Rr 8hȸf0.2l`AK56WSP:'QP;69 CŖi ǎc~Z'UhvWU)6U<,0ߛyEӏz2Zz Q|t(5I|s SҞ VqBj$'t硠BB(NߧY4~[MǺ3U޼ȟAK/#>`t~YZyۅU`oQN)]Z%)-MʱAA$qfBļdJC=%oNK*(CVZTgLr/P.)Z4o“Zڡq;`jVD.uGe1#6S|z: U% .=vFC>0-T]Dz2D)o<hS"6C?gAqy‡BwV/lwr}>#vbj)Rx_V̂kEI]?6ds&Vw\yPY=&M&c~ -:6s-}PFԑ]|GmuS2d$Jo,.,@|K-p(7o{D(3ib|d [V:t&ZǏ$ EY,O]xF!!F!4,i{ё,(")CVrB4fڀ߫JءY1!2R &Az.K?NXFd-&>n|}dx ώ\FlCeñ:39_U~_8DR)("ִb܁C-'KSx)B)dey$-qC (hjG9!obB>nYy[7cWG640~?0uH>*֕>"<(e&e 7G_+mbWw12ژmc \?>˻bvܫdm+ cȢf>u'R!*RJ1#\jIn`ԖG7VkcKul+gl镁ghY7*9ᨄ)xr$rx1D { B 88%goJ8? \F`zמKS}^!LhźW紷9@{ #dՃ]KGE8ZDKiPTְXI6n=x2UyHG>e:ZS +6gؔPc:R +81THEˆPR,P`CLc?؅LzΉ*fG/ʍ+d,+П\!rAݝ?QBAIW+EP iOLW^٥xN-̣en-0Iyb0M×8^N9>ibLޓq(NH{k csY%Eg\uTp%)2^rȺk1mxy:p,O!5>cϓyLK)7x@KȐ@A@V$ ]X[$C؉d7>O MD˓4_H~M|zV!'T TR䓾,hd3js}4-Dm@Sk0Su@*a ^􊒪4L>H=E+ڽ}HǒԑUm nV8$8m;cslέtkybcbNJ)ɸGҭކ̻r|(H$ ]Iȕ4ʗc>b#Ui" '|r*Ral-~:RvRm$oh G›k'e!IVZk6BOsl7 ZÉ5/PpvťY?hf )cK 4Qݯ%?00r.ްVug|ƀJe3AeA,J;XMd5Y hdaӟ1ƶRXҌ*Q31ZhA3T? yU}zhZ=rqڈ;/sLq6IԄIm1LliC= h~ު[pj> dwvrp^2?ij49;l R Ok¨~Q/nl(,gCɑ=c SAp4M b^sԇ؍䰔Rv^IxE@j =YRiR;$Q2A 뮽<vOjݪCbXos4MLn 1S3Kz2;b%@6BÆ-+ƵV7{mt=g g> vGk$k6rJo9WJOcC;xb~#✁ Dً 1+giFχfc^<7Xn65;;яȀǁ<'v54MPd_p4!z- =vtĘ>K՜}l[H b4X<꛷h.(y. %F%XrgS,2-Ha"9u$!Շ; /Z7,ǼvT"FMڱ̳WPO&"\RO29ܻeiAIH炋 ȆI5j} LAdzLF5'/Waf.U9ZQzlA7EZdjN4$ȁltbc~>1ttoÒ#gZ AҵRiLpmL,HMGT ^&7scЯʲCf2e/& =uMMfKv}*ge%[[ƃZd5 'ؘM]4UA4 NBig" #:k=mG 1-2Oʉ;k6);^޹0yaihԛ0vxXj7E0~o/oBgڌ5CꀐFc)IZ=ڹJ!㍛ )Qaoæxo߫ZH~+(CXPޣs:I{[}em=s_$'SkjOCO#k&Ȥ Bim􅊳X,'0 ?}PVmW֞#=!bуT E~ x]@n-DdB>*Nr3d#dc'5!-DJAy{7f[vp52è!s香f`c8ݝ̿oƛП"4QugA4 ~0tVg)fr|Od1n͇S@5y;-uwwa*'XQoA2S\_lRg$k)O#A̍SεI$RKub3C Fsη*Lyd0;;D'7fTɣb0+t|k9I1K, Ȓڛ5P5ڋ4Mڼ(׼~sf7f(UG TBY7<f$E#2aoXJֲ;82vpCqn'&X-]qæ^;㦲+Q\&WIK>͗@O=MS-j)S UYom4& @g2+sȮxB4*H۲dҌX'2ܤ™ I@H`=5M_0̢iyæ! Ɣ@nqGԁr*44%M J5rNRV θ,82{pa="L`?-1C&ŶaL;LmMM1a xuO$q_V ݎh6Q58Y<)0$̀A@.6-ӂTLiI^9Riq @(!6]%]@) !bH]UKHP*-cK(ɴ0*Lmlt[.᮫Fsz@ʙ TE@ nL͓i9ߡ^_ZKA1sQ^(+^(]ކ Z݁ZK׊Ɖ-e`Vߖ9@(0 "m`f|uJmX-ZiԈB&wNOڈ7 hl2!E b3,Ti?Keݳ'RXz%7Ad,2(m0 e\=ȰKd )7?W@,0/_Xk@9q]cTtu-\g`_bق̳a݂ܥuΡJ2I8c^ӋqmV77Gѫ< 'i>#,&zwcaw$ J_FpۻjN}'ob*Dۺi@ݵ\t^pƭA{z= 5u}7ZS4UiYћyhv@T^d0(cHCO~1<6zzՄ~l4>cM:z<$ׂiIn07خR:cڤ<,QH8 {Yy*UyqBg HeG6ܧ䡄ʝAGW +| ͂pL7_͌C H8!uSKm^>/Jh 6^A}۽~cc(:ލ{6˶Z,x,l2yR|=P(Yp|quWWY0AtF'BVٮ  RW%u8B':ɌË4J5X}|]ʸ~arugLinO Ӈ/7`bPlW5H,W3Du5^4LG p;zH_-Y}c?]?_f#O6p|kA7_e ,$.{ 2@QkqYnuKx&҈LG&gCfMng=!MAa4jוx F&8fũu&xewCg*Np{#7VD-Þbg&w{+>t:-qn!x ڍ0ړ5=;6Wʱ Бq☏Ja#tƒ^AiJ|x)/LbGwV{~cmVa^R#H%KGߏoy4?\s^?,9)~+#Qsf] w0&dfΓc+\.(Ҳ؉n+W;pWw KxCw#",dD]!{^nɓNwN!+t%! .zx=!z ZiߙA;dȈd!gEfa2&*{/#~ aplW&_BVn0dNNb͜jUoPJ1Jc9Kusj۴bEac-RрWyCkWz역^Gs=^%o>DIe,4ϗQ$ MVq!t5{u&3:7Y Xc Ol8mCBXPȟzdrPdT$pLZ.%`]s?Cw-qTK=zxzp`*Sˌ)R*(JʵDf3z90sbx 79v[00;2]]:Ȃ-jTJ8 HQOe]$8AneL{BjysB69jӀO<+!^xϨXWm#i ?5ZXE;.SNzM ULH+l n{gH4%>U!0[:M\C"6FN\cW!!t: r;OѦQR5M1<נr3S[߅[_0pQNꑯC0ð%,3 T7h_*Hw~жTWU-B1!u,l`6#Ф}@6Rf8A!6nR!;C:f:v-ھ'EGn<>^_X< ^3ACE8t&pDIڢR'}NVw\je3nb3U @B"(SZY -Jarz2Leh `ss66#I y?DsIUb(̉aQ츸O_.y 0ot=n; 2  Y;mta٪ `~F*\ge pl9R>eϘ^ HN,pثh"P9f*T6@cDG9#Ѡ V*|&xܢU#y O5ໆfPk֠\՟Sja˚%>`R ;j$ Q;i1&Xs tZ3IX#Q2p'%vwL|7¾W'%Ĥ\ i!ҨnczzZg7-ӷL)[)4,`P_0XXL>֤}A#Yьx}]':YٕOxgǀ,ʜE+az^ '\by?S lE-'keܱn%D':$7!B\T Na AX>QQFRJB T,Sb/GRyA~\rFyrm3E\PoBC еk\x~Th#G}ҩ}&Jɻc@Hl/b>4e ST2⠻){Y(5H{Vhh"x\t4t`J[af]t02[}0 BkR82S,fK>BB1s`/EiczgPe)!Uz=JQKG$)MD0W i}j7LAll`aQ U6' 3ƤL7wV6c[iH&TQL^&WA"yYj6JvpDG5nr@\pj藔&a4 :j̋@Y `jH"fɣIPc5mfCR &WLEUSEMlY+ =;L_ @UAWpkh O7Z>%m4J>^mEy&P?z*~E;b5j?PRnd" (_a[*IxnT eT_E0ϑ)S$`|=7Qvoz0Zo~I~lBkjL ߫$RkOz3"0B B-#Ѥfi"&JqU W.lJajN[fbO;ŊXZb.$+bSx֫D$P-k4G0gי=Ї+y2t3*iqy0hQ]Mbˢμ3DbyTa[w=*TISk* 7s9y'1FvGsn-;j$һ>}\sWEFz=fX ,a򦰸=|=~,- ћ*KC" VC QiP59wn3S+_iȹ@|ζS9Yڈta0p(TОiFߓ &/8U*=[擳ێO 6m+-AXR?]RkupZALŮt6G&u.c#lES1!GuJHE;/4N)dRh]ƣD~CiWf"}(뒉2V_& XOm;KnClvC8UEb' Ol6QT Aڗ#Y}-e|Wc1GO~DBAcu)YIKdVŦۨ.~V`2&?S }"xF\v% 4ǁ1ZPwjd{B`yFqeBrąQ^)ѷiXo4yzճZ2Xe"IBhxZxpRb'Z t_uOA:WS`yn"1.ƒC̩T ,L9 _e`M7`~S N8gQȥ$ZkUPd.v[&1QdꝎ.=)3ǝ qrVlp| EVQi`A(˅;0D;ov#k-y=kQݥʵ 5Oir^>iqWE?Y_Oy لX GMnAv U 0*$q͠ E'ťA-%#so)0(C#ʫgRE2b3ccXM(-Y9WD^~ ܭ"z#%+a(<*ѽOP1Zvr/ҠFGmH*EP(iP&qv$Gl9hϒ1\_A㜊LKo6se_%8jUC] Ff]:d w)ٮΚ'Wc lPO~ eӡ aL0ޚ}7;6S5BPÂ# ; @IcJ_[_l]\JF#Hi-{SozszamfFV> Iw6 wx|!z1*BG(P*Et373zk 5_hauEE-d8Bo&75MKZK-V "sX5)=⤧Po6􀅡+wY LGBDăTgm^3A3[]{R̶bCs1l<%ꥣz<5bۘ)^+M6)wK[d>N}es+g ͚f]3Hw_ӜZqB ;t\A/.2ٸӧLg\&\-.|Z+ȬW-hEQ󐦞PAS0eHʞʡ:0{u; s{ojYuX9\E$0v 4x׭dg4;U |TeQz kLʞ86)'< l$9Kͳ".cj*gU$K Lںz9 %޸a]I>݊_}Wn̡k;Iq %R>$OgW 8l0}-ChP{|/_P@7bM_z*wԝL H)sd,-8R={NŒZ]͞[nhּ}PזB3 8899]eV$T™lurzSwjMF^i.Xe $@J^ I, ˍkJ$zN$ѨkZWJhmbjȂSM\?Sl/0&PD pϲy먗mrl `u=q%FPL*}3| C8ob["4fs]p{l$%_X]hM- }n`/rfE>c4\E_<ǵ"|J,.CY{R:+Y`]$*lAVڬ)|Gի+ kF#kow/s+~T33ge͑PrTgiaM/{;N8HY[Nx(~najXFR;R.v^e9G }͊+$Nɵ]:[::BhRt#ҧ GQ[& \ڢn+Zx)|Ğ`!JJb~lYܟFpr(6y- nNRpX~yn.*<2QEzໆ!ےMo3}v"f{RtohO3z7PŌR_X+:pG?p"`4$x_{k1Hny] y5ÛwKT*=DoO mu+j+d*ĚVv \ZBf*77?6k_!a\pK/\e.J8fl+Y JU?$anNy}+]s<3cU:@&bdaF'.c_ˍ<=̊pex.qDY4s ^<~dxf$ R;^S`0Pm& E00A,GPP ÞzG.8`U5EeXsX3># '"ыiG)¬VCc2&@Xq+3s~q|f7 Ѳzь5a2V,Cdtf'g*ly B/ djQ-}gZDa3YLKw ;62GP.w3䵕Q"AT' _dl(n]@9ETH+|k)X2rrn3s c+DvüM(Mwۦ l2EBf4Ώز5Jk;Mſq!Tpx0%[$] -|nc[O:Zdj7lc5n)RF5QWJoBY-!1C = g'=W&=#*Buqpܔ̒9 L܆jU@" gLMn}7kBC/#`[!nK!))+R_+!WuOXR5K~ mqkWWbc0( xM fqCaId5یP @ |@[M/*qCɒQtleZa@H[\1VE3\U^O:err ywi  ׵; |޼Uk7ϼܳ *R鄝_nۨxEZ3}ع?A?i]V kE:_| cȦВ)/ZY 'c5I<a3E)DO|e_;P_k/V?Ҋ#hݟ{rI+hOAyq "5>w_b.0IA;>$:)wy`yŖx-TxH"3Qk9Ñ>Gho~BV&byA I6Gy'4&E-ؾ{c蒆v2*',548.k Y?)`_|.%#$t1+áY{ Xd b’ <5HöH+]CRLeJ8M~ƷmQ~n; ?Q0|&Kl/.^QXp2[ v3X8zM0ĿkFAhDf\6 ]gמDR)kEpx6GZ_n- (ip $4ffE<ʈ/Zaȋ-/ዟ?qXΓC4*7 8T0 /d28[ޔkE˩|]8E^4Mi0hIh^bL}#l 忰 LV98Yc>\rpe Fw0~\ JB3`3ާ{ք2x;8+ԘZˌɢ PbǞ Bq!b2?pQoo>Ǒqj`ADY,aC6i[da")"fU-־*-5XzZGG/&#%PP Ă8z]n~%žfQc^ =c̄+[)jHu=6+P;ڱ QO5M4c7U_k%K>̒ᘹ!gldϩob僠f8dź5sxUp6)Iyoa&auAlŒ,T0,JSC5:o(\U`pv1ڞ蹚i &O{m<֨[e P&n9# @?"?`42^S@[IakoyeʔQ, 9 \]z11eKgAq*&aqK[,'BX'68y}{lG@W"25VƓrN0&HPgƉׇ9r|O{cDg"م0Thb*/ο{9k٤hciX0=8 zƯ %N, 1=:V2\u纀7Ńy!T;P\b\<0Ƹ'SXqsRe_^jC T}ƁG@jj,&yv-.;5/*~)Tqx f}t=RmN6j !q #lm8]JzM&6}V7XQ>TSBeY.ki[nTA`#2iҶFsjWp;}kN_6hbNEL C>G;Y2*QL cIyAF] 6Vh_X]A`\dPoYAUϞ A`,MsaA"%}sa^ǥZ"@(:9UZ 8|(7 3)Jyı.g;˟_FbYX}o ȒL\KR|Z,׺M)^A; 7ܽr /ݖzi(hkպbǛx+kd SqfZ:OL8V%ۓa n-O?' ^R.ZNϏ% BCbY ^wOjr_bBR{'y#:2 K2o}yx9 @s;P*ᯘ8`W|I,88~?惎,j.9MvŢ%N6-/.Ċw9>!lẙq3Q /ijŽP1p"sS+S/дmsIp@N?S:A(vgV~Un@+˯>Lz.|J^hST\MIs1Qhe-6ӧx?% fE1Jb(uJ_J}x~!gLc-Q=ok4Dnv#!Nq'‘Uj.ҷ.Zu!5~ҌxSsի?XQlGՊzKt@jC[|םڛX6ˬRI(tzAtA̰]doNaڕ E{XXg*=~k{" ͉bRco.'k/$|\bʫoW~;/ ȴK-BtnrxsJy0mlЈu\GvHp!:bM=U[BiҚlmF. N7ܳOO0 _ikDCt_GXVtSmq9x&椽]TGhY PvRD723iuL+¨A(qu'itGpX3'@L49%^2 fbS?Fk/-QGnVZtn"y j@ Mj3 XQت CIxSAPH-R/C61 :Q⤲ݳEFOG{r r$FpɟK@jv͍Wxi] "뙲5EJ]B+gO bEJr AYk<m̓Ef& ܹΖsMY3)U6M?ZS-0ϊveP403B)w%@//jvAX/"4ufq[swqGˑ5x>l^Fu:qI(5isN1دOc4jZ8}ۏd<@9Rho)5o5sNÞ8m V<.2 xHG1s4WO w'> _/?2]u4+[ lG3;}YE=$[ bQxu!w #U)P245Lm#P a h{q/,&tqkğ8]Uo 'Ѳ)*fq:RTNi=_fS{VtiQ?] O~bu)'[|wbay@[k/Ȃo"*K?jm3MȭvM(bdzqIUQ0`ނ]44`zʰXc@yHK$m&ɳP3]0baEYcN#1Ǫ Co.슛\Mߢsv)buki#C6('L/yՕ lF2o+8M);Gb' I@0WĐ/YpW>ntA&RvhƐvMx4D$X.pˮ 1p*1kk@ZQo92-[ 1E@(]P!|n E[PJ9 < J 5-N qp(K7KQyCok g(Hک8 0@u-gz͘SD³HVr¤e]F+}xGbm4?]Tp$Ea#zVug87,*">;̬F "4/SOo\ya+iʤѓ[6m 2%Ѻrv6 wvq.mOqVÐ@Pz݃-B|̕8EwI~yρ Hbr]硘gvC"T*Zcl+,V̿ߊn&Ep9WPxړPp<]ZHZ߄7K@"ISK:cXv(xk j-JgAyCzY?t}% +ЁV4ֽ9Vx p4:NtόIĹ'|En{vrA5(~"9˪\}иiR#O ?ArpKz)f[Qy)z׬j& Q3UΙH( W+q)m6S-FX C>˓+OU9g}yD }UoU٩Mr\'oKPj>IgùC.5C9k 4'1AKJL kF䨪/{N#3-ܛ{sTnХs F/TYOeFKjvn`26'LxU_VmްPCfAʹZO@bƘ U~!~f [|kNHj΄)9 ۓJ@X`1ǣX3{Qe{ ~zJ}i2Y趣Te7vK&"8A8QEdBYt5G_*-z`uUB>8y$r(I²_+㳀4rL'˜(zWڸrv)YV"a8fy!=q(*%" ˆqiK* *2~&2Ch(?IqI/,$4A&v*A٢vu{]V |QU29{ӮA4w-W5֨lʰs]`Fی•Y_T$[&#Æf 1 _[ $nIXhx<]tS_ NG]mR;He֌={27g |;]?~ "֪aSP1qWڹT(0ZĤ91q1p 3Eqai>ENr+FfSކ Q\ٳ+=̯:/LJ7>Hpܕװ0H7U#A N5L~A,1YaXl"5P&h~I%AшThf9d=XKaӁߏb+^$ bCY$4؆yx%<^o14) .ZQ)\_yg/ƻ3>=&Mvp$Z\v͸#Y; 3P+ݪWX`=9jGgbwiaګ[}Jo=Cw*%WhnDSG`T3x(_2]IH9ZXDԀ2`\T#G_2)U܌p:M䐚i$$_{ dZ+4I7,] iBM=(E x’V `=c}@Mܯ =`wk V  o`o*=ğ Lh|wy#'F e ZTgfv`s_ݻp)2ox n;,@B>ѩ1-5O* k`FDCCH9n6'N}LM }@+;I9JYWY.?0@@PKTjO'-,#cE:Zև +P#([f]-u, օ!|/c4_߫wVotj]!Tݤ2ȝfjnhۂ٫&F l"U>.0[5 ,Q᷎G#H.&,v!LNROH6f"%(vW{q b1{9ths@ׯQI{Vݤ:u>WbP)!6ه L8po[-5bg,"Ёwo@#̴ҼD1tՂY1 G.4e%u%+RUNkRJMΏt>NbQ(!~?NSaxS6ͿP? U3 f7h Wxɜ!/"6d' AsO~_ eAy k.Œ/ TbE< ȅlEfE]u-01 f}.3T~0{;"(# lQɃ{5aՇMT+ӛ@#WfvRyR ; w!|? $/+JidxI^sY)S`ᕍ<}`ɡ[e(h@*Fz,b >tT93"/xo/qX;H"׈Q7 O.,"DI8P|ɺKķKK-FS7NCȪnB\Q-RMn[{28jG݋|孢oX/t)// zJV/BztЍI*:{bgArZ$9 w yg-&Am'H NPk^TBbA_y?^r[֛Ϝ7@^Is̥pzl\13b̝l\A׽wRtw)OUjwJ7帇l!ʿ 4饊2(Y0ǣ25Iqp/TmW6'gd[x"+Q lċmw %YfWEG\[ tpmNJK`UyЎZMS`bsv++{3>kjT+N6_'͕]FnU[M>߅&43ݱN5?ބc~fx[B_<w:ژl~%jdH,gVw9:(祼Fǻ8^1ă~nrd!hw] /2AFQ?2\Ѩbs tz1QgׁTWz4@!fc]a_-ϴ䛧%> iQZ8I3 ?"_EY`*Q=xsxȵ]}axo ZS\/5 yR ,k?o8_JGѢ=N8=)b ū$jY X~+h[`ٱYTkMϭN*Bm]噬"YNݪᝢd/-$֭Qh'>_pӮZyX*IՁ7|JM-ndٙ++Y |4WS?,8?BQ%*1qvY+Kda kq5]btCCz5MI8fe酬ɿ@gx Iv+xBD{?f# 9q+lo0N9 䯼Mz.<jHKk5{900j]ggnSEhDouC]4Ub2Q+gD&~cJǴo&Z3h3ֱ#Ydn3sj!"p{0Qx1!9fQ}JwHSDuˈe*xS᎞BCePfy+w 5MɺSxoߒi2Sɫ "!66ݴ>I &Dv( `Ep\,TRUa ٩tI=Wn 3o,|nB$lw.O[?v^GӅԐee2Ǖ^jk>pLE<^J!P l݌?"`Bm{h1=p#JN0Μl!]5b3C`4ݰ!0EۼD[/`gs>} nx`1F5h&:ȫAA]J_ØbI0JK {;U?ŏc7EQa=J">SlYV܋mW gsFZAu 'PNʽ\Pí5`6 SnL7_R ;~$sEl7tae"8 i: F7e.R7`/Yuc7|Ş$Bk# $X}8:&0}$WT zl ;4E+ 'i&6\z 8@l7Vm fgy };_kFtk j/RLmסTv>CVv$wjkkpKDYJϽMZ`c$9Rhޙ6]GT0#^8atʠQȢoUc 0qs=5J壩(xmw6kg9?%Owk\޷vƹNlnKC}` rk2Dr%BZ=~v6o$ t4q״志$J[ky ;Xkv, eT_d 4zC'd8dkP;!G迱 jfe9/Rpl~dS?Q~圽tN  KG~3~=a eK&u n'ZF5$Xk"E|av* 0-S1i^^g NY@3Y4`L)rUl`sֆA~7ؙ-]w=N*kε#mi"PfQIMˮ67 *Uhĥh^3]zpbE1O dZGcfc_V. R6Lx.96- Ѓvm)GN p!|U'm\P| .ruJN$u!XMF,󯀖T0S5#Gn[H0U_N]|^QԐsApΒɢJyS,W;5wmR!.'#t,QL&|e!UN5_'12$Wh^]pgTpÝojڐAsC4/2D .1iXUl<(8C=QԪD? ~Nz {?R3oIpY JCP)CJL(D;#zA_?(zA|UoQPD !9KA6kTFOÁjGټGszζd3m݆=ٰb1Wzﰡ2G(<8PB+)!cv,!HqQ B)ܬ:+uɊ"=h4cM]Ϛt|Tzik+/eSO?&>Liw^tBIG{7CfJ^J]zr}Gⴎ>kK/Y '؉C5 HBԛ]86Wiߝ\O/9bZ+=]Io/sԮoxP}`+> 䍗ُLä(%H1 +8D3db*P֙у {l}A0o{|6<,aLX-n;";b)<=LlmuѻEG-75G&Wt.`--?; w a-`'G2X` Np?Dj--Ɗ޽^'.k7 ε_Y׿e."L)ojbnm鲎#RqT \܏k:Pb4H$!J$K+[әa} U/dU ףp/bѩs_(N"qs~[=Aݎb &klB^1"raL œC'zN}&߁\u& T* 0Eh9)[J7}C>hiQQcAC!ո{B"8SuyM6ٌ{*PV]EYV}tg` G級k`+JQ:r&!.N5Kg I&t8YVEžQ,5^e\I-'OI`KP֭4!)iNd)Mmm%mя&{kv*zHhtiI d# aXz|oGPITbΓ)ONVcKnX V/ADa_|bn5dYk[jt 5?2y8ojճ-][ʇ q,!;;ѿH"2SkrKop+1O<@%6HaKL-hwږ5rE+MlN"br fdsp'qi' QڱLq0V6?plCie*<"/ s[{۪␰@ZNYkMb*Vte`?RkTBuR{w &ȢEnӚNE|hJg|V^7 U^UΦF&fX9ŧ G0%aӿUVoikry`nw-(B.@`%476gf䪞%l;~*[fW U qV[a S_=yu1uڹ@_~u&`_2vSt`뵳DŒR2{4s C s)-;^TbTcN!(Fp5w:1q֐M0#G8v\cپuڞZα5 ʞĵ=M&029\JeTIPCekqL\;J`Y(LA {IuSiB#g^m ݕ+u=(VfA%Zʭ߈;uSFkdʧi ޻!5$+A{oet]:HYx5'gmD^ي_S` !鶤\\s`h.okY(U;P׍G5 U[_ں" t>w}9o*q͆e!?̄n h8Ufp.kU%%m"oSԂ I鱩gq0q.xZ>[kPpV7[w"|x82ҭ;Z*] eY#7}ŝ"hNҶi5׸<.A<ާ4wKfrTڢwK\P^C;5vYSKwM aI9춴"=깟Q|b:7ܭ+Q )G#Gpg#h *xb(cegDrYv$5{H?G0$A 2ve1^t@c$ܵU F3 "ԥ"~=hE@@bu8:xN8Y>H0NCv;C Qs7>PCա$7/ɶ'}7=+RqW٣-X }*iߡ饭w]KG…Vc8%7׫f]CUqA G5˂0=HPqN6Ln m٫foA,xh>dmau1{ymT$sKx䀊P6$."H$X V͚('G}dbomޘUsnDל yv9/ b9YP~QSBQyHҼ63ML-P1 `컀F[| l!sCj4p;6Bs!ɢaf+'I0_/D}>YLζܕi6KhUzH]r_! W%"rN m$₋Qb0WXUrȓ!Hښ[QU]˫܀SA}j:=%jiJ.o D^>U_b?1*$džWy1{4w7~^)PQ %OӲXb_Ix5 ^L"~jک-}-c18u3k-dl/\IQME@zS-Vh\E%ۮOπgRL ~V?6倍WaQTCO1J@:Yؘv'FM3&Hcc}υ]vtDCi43B5DuXn<ŬeW+`ۤQz>k)4yld8'BeY.v0$x#'[ig8Ye6y狢|Hl1=6KpOU7,,t kOrygXzFQ3xML~fyXBlAhbo+lԡ-,J''YĐ##G۳RWe "[fׯ\ye0Zv`!cyؓe0}4JnrqTXP`KŝK1ڧjO s[\W; ,O\V(DK@VbT"4 $k[B99_ \A0~ʴ.]/)%$IMPiMZ$Q [GhIM豧TsLs攗|!^0KvQ?{8a3\P'>")DiHqx}*BI.SK>1 !O4Qdt.LVkXJw:W"y r.si9op/P^VYB@f"j$%͙OloEJWJ'cŃ>[<{BHYjdT35[\`B.Oe/asҁ<ށ"@KE(D[ԢfK鐺~(FDžY[kIBl\sL;H;[ VA6-v/MJq&󈨣r,&0Cf|b6J?YPGIW h,hJ`f_6zfMQWr7X(tU4fU$`6 TJ-{VjUsjc6*a)}`iJ ,a:dwLWSG_H(D1uߧ aQ0&cdayhQĔwZ[\=v_Z{R}V p=K|} tgx,8ZMWՅQ1%;@XHN=#}絑lyg{oLQJGc ^db59S"},e{uLwCVVԍ3@jB?KԾ9̙,9xmrqytY+!rܮH 1i9VbE^lkVf!NKjmt3F9 < 2{} ЙŸPaPu} RKULH! 3پ$D=,;+u .følx.9wlu!?7;= `ܛB4%(jlj؂q,9·[[EKM]9J kFp6;W9XeN;iPl^>\D$oߖBWZy#%xzQyʟ,5d4m*>vQ奻=%kε{v4{ [nsr{*)eDOnAkC\GDGi(R"'L`)rq S Kh }h??zjiG"0] :z#zP:C摠#hqJT@$Y(nqudaߒ(Qsp Sw(h}Îqi>yo.)I./l"Π?6 虐8Ffܦ]#~HLuJ 6Cf!9Gbꖪ>K*XG%^;6`P"!!Zm:✌6[C\sa C]%Dߢ=,f6\1+ 2 љjK}eQh]]wT8i4| 7)|&t>=.=!`SV֑: ye2#_ -b2$mgej~S-:z响; n,|#{1V ǻC-豆Mh h^ qr=M(.<^AɀM:key݉ +K0O9`L1Q͎4r0.Dn2GXQAGy~[zύB`s&"ۢwffc9p9;Tq8uy װEf$H XyHnp6 sq n7}SØf碰S7ya-!egvrbXa؄tV"l;͸$/Hl]ֽś 9&fD/9>arq=;I] fFVZoRʖ.$<zIw1R7qO!BqA.i+fJ:w?Mx\3rfw gd ķVyX8(Fj͕l@p3jV$WMAR&Jƥ0+٦RI.ވЈ"Y&60{az W̛@гNKY亅6R o*(0tQAs!gxzIŞ{Y>V'E%0Yr09gI:#=}ph 5c>"Eg ꏹ=T =>]6^oL=pc;@G.\E&cJ[>BN|@PQy]%^ɦB|,o;fhmϨm\MvVMjxD楘W#884?x6l4D%gM2m+)H'<Yem\T=[V|>LS [.q?Ѿ6F oÜbmMC_2֯ˬU?iܭsJElyDA̢_L|T v%/wǵɸT0%oʨ޿VȧOD/[@gFl2W_aLEQ/Y6N>@ocgȴ ܽ#)hzwL\n~*)3-g%E\pʓ[ܗtgѧh17@=.wY6:뚍 _"~ 㘞͘@7ӶR@fRgoֈb7b:ҡ$0'Ù48cYfGGЃT&Y%{UC0}b ?:F÷-,"l_yͷ )4Y>uW'Oϝ-vx>b\mne2L'|ov97>_Feh-d>B3%OV^#|X3`G8@|eX)|.aIc*Vdy=7b8@u,&p]c_h  vuB?:6&AmfkUZ1f-tRg,Gr}kw$ՇJ DWeF.tp렔h-4۴̤.CGaJVن 4<>ӡkwͫGpq1ԏiD0u.b_nV9SOBzO_̩$FyVH:]+u ~*%’=mՄʇoS= lj)L[J@PadլU6!n&59pRwh0\ñ/uW\[ݛKI{-:; "-ƵC.vhDOȚkWrѤkvPHqƨn.\%BC \I+ ^+QKjr[1ZTę! a2!7]B|Q Б 2r䦣pQ`u |v@aF=F Ko+=^Qa٣4g8^^ą m}! S{']J)`߮q|O/X>ߣMrsD7b&}nVtxQ7jP:h"dҧ~Գ[GZ<7)tT=O >g *e½-!Y;/kl? 8wwrC{bS /.o/j ͉ 0KE(굃2p{ FcpUK^3*˲vHe5S'QzWb5ZUݵ}kW0KȮAi |(mh)7F-ERġ!R>%0dͭo ,,W'*.U 6R\a X65P,4˒ !pďvj=Yeͽl '͏a!aOE\+$لi+/悦KZ:S[N݉ijq>nAE`u 4\}Tohk(!3Mzb,paOI)$JW}k>07qxEm\ʮ V/pٷ`{Ln2akMGX5>J`ȟ^`[q˲N^1 jBOP;ռ6`pq/Y)%zx%;' ,p}vfǀwaf0ة϶9K#I@Q o6G`A|A6])&ok"b3z>u[Dy4z"]!N@>U4}{N;b̮RT%iJ;LGs~4lS@v0Rt%1oL#rL /qEWɖL05QC3g ;]^e\80Wp[u *`N_N kԐ,i@VW˳A(77LVXcP:d &j04ԒDsZ `A?~;HV uzƥ ƀnq?$"io5Z4e?gSJ%V@Vxج^ʤӚfd.X)u[]IV*pѴB[aIջS'îng(htM$q{Qܟ5h'`tuGc.bBPe/DgeB}XGtwA2lTZW@ ߐI̻'M]3hqӲDzI)'ZJc|T>#zzJqk\yƛ(hdET *3yF[pFsP.Ehk?1=EXôQ7c bFyޱZ3.UJ0X/|֡ b{_Ib["wfuVUh\;(`zZ54'Dd¥-ht A\zhX-::y3jlНO9q%nh/;˒\ԦLW ѾsnmN&>H9Q΂3Rۋ_o{ϸN Mi =L R׵mTgxIlCǖ=4$532c]g[-Ѥ/ý⁠euQjiUHb(U_ȲmyK(f)et$$Ap9k&V2+/gvQc @G?xȤwg>aqvyg;M9- 8yA5(o4_`o|[!vS;eÎ4{l.4>@[}Q^0PˬZV@fk#>^o0^: *$).[T OXӞ=(e6c,m00+{Y1 ޭ2[\oIU:g1 k0 榼QN1S148q X9SA>OuZze, ?¦;I B[7~B*$!pxDy;i#L_DmG=  NPuMI)'Z%?{(Nxnq!Bw7k SQa B+7gܥ0v vy?\F!71(8uYXO]>i^_V>2`CHu[AQ f*?=P]0]XMhCLi&h%anrz,yfvxf@/͡JdzԨΛ00;:&>GN 3=Kr<5Uζ{ *[)ZUi`nn9Q`׶$1jCvrE@ [VvqgU]=' 3h]iÙ-j$Qm~n[g֙ 7c8z~:p[Chϐ>QhJsv%1׺ o=Rm-]}I]M2Ʃ whIKVU=Km̆Ez1)hlu'yY/WY嚃u<_UrzFƼT@#s(['E& P12C"7$a3EA*̣wv#o1Lmڹ䁴#]T0W돡ng#!eW.t\ S*^2XȸPƇ{NwFmk.kCȁl@`JJ$G/PR,u% ۿ"GZ,O>/aarhYSP Ƌ&h j)׺Հ/\ؔ&iJ)g?|Uqbeqc\h37)x)r"ӖN?>8)?}!dq0lDKA L!q4Q;C`P≥vL(t J$ZaKبK ʭM&pVEFcLJ[S EVNUvÁaВR[F5ݐ&(n.; rC~ov5ZGkx:`LM-F|#YBLJr`)s9D!["p2֜\G2a99Ӟx:PqȥNw;k׺p $.nVWj @Tc/`G(LVXcPa?HMĩ '5Uӏ]^*.ׄkQ:rb1n*^:vhR_9ҞubݙqV8R6(!.i8sߤ檨<(iaIyŻ ߰,FPOXV\o<.Ä]) /93%W4YuC!4%=#5#K#´TWA˴\&M%ä8gr5€ ݾ$b`t6vTbBj Q_Zj)lAUimkꡧ %-S4\Vr{_e2%W_ۍx%[[xKH-CZ-rC9*11}eI8?ް͌?X%g ?J돟1B!d#9ވl# bz0p]H\Ż^@ǰЫ֝* kk;BB2=}`i*?K4k ֔qTjYNchuT0(â.Y΂̖IFFlC'ucjwAͩd#[ixLJi7xqgwEA=ژƎIk?\XB#!ʈms%Gew`青0oY#'YM2lc&l>b{Hy8z.<_%Y1 a,ki0TV˧\<J wz9pj6毗 ܫ'~m[A=(~q'TIJ|掇$h/m-#!*5T6Ӂp( zHȄP(N= nN* %X}DNS8gmaCf[`6a6uٻE'8ǣ9=9ж,>v1tO!,6Wb1!tW+_(spCN K d (c:C[Gb|dl8̲" 2JC.œ4IJ^$*Lc4İn-.O>p9&?`PZQ3}II_jߑ)FU"}?)FTR+ºgEɕG`Qx @")zl@B32? z[W>&G CcQ.-dCꪁ?lj^aN8AJTӌr*DJM6/YVA_(J\s XDŽӀwb Kv&"3Ia`p;cCf љDS8\d. +Xk~pP.E1[JNdt7n~|>Rp.X^!J]sX%9u|׻udjidyܣP4$Y(ky<-̲ttF;G7V6Xx#k`v>%"rC#ʃ<:9;GViD)O;e9(S]׎x-Cn@共 :$LDDI! 3TEtZUخqđVy]x`% E "]/x M^z̒)/lE;S{!mrt\s iP M :ь-g?WjEYW8OLR6=/{OOۺʿAxO=TW;n|yxS-1U-)OekZV2{A=e "ڛY)X%R 4A;! -sf)$ځժpNaUۭ]cRvE#%FcG[[aLػ<_!-0Jrfsٍ&&6?LAg(v/S0#T3wőއu`üM'Οۗht*drж:dbv)YT&cS"ka[ ?A c2.Sao GJ3P3P3ߕ"KOu/CI砬b{-qߒhcsɥ3 D\}Nk|ID51ˬ2qV5N`G@&޶ "1_&#\7Raͫ@RHo3֓{ (zQZC '؀-c_'ń.Xׇ"sHvlzX$dpG5#]6__1ׅSr U>e%t״3}}RJi؄?KQ•ᙢ8] ˤ3? ZiUNу Vh@N#<2)MObHb~3,bZ-2y{edL*Ϻ􁲸zBC~#l(9MpiK-b/SkEgd$4"<.~{Zgɬ4=^l_r$<fND#dV!)9t5=8=%Q}{7D%ap Xb .F >Us9hBg9 8i7Z/)JXA4)@ԍ$HUZn&a`n#B&BiUa Q8WjNʹnjJӖ9& 6z=ژ%}Qm9}y-H'~5<)*hzQw np\&"bΓ}O8 K}4p>FH+>CSw6Ǟ'MMpFr}?^0@DaQw'-._;)]ZYX0So{m[3Ggr1:[#2Žהf%HV!lэ:ua NƙMn\h1'p\E".,GZFOOKh{e'Jo]IbǁE:wh"KNEHӭs~yR\@d5X*?Lr MEq(pֺ暖L8;@Ww)0`/o`YӞl.JQУy|lQ]4RP҉rA)sh Ij|)| ʾ*דJJ$ ^ѐq-=DY=n\PkG̷a%$JW>Zq;Uʑ#jݟ%tڹl95 ρx=sRG@MEr<ܼ Oc!2)kEĚό.?l;1E܌k#щj`P2~g'XgZp}0h~$XQziy 96 #`;C6)ϦĿB6]34g \tdZ$_/=?O}KQ xFbF"}ƋM/ /$p !" m=/uC-6"1^P -rݢ oL.\)E~).;:%fcF,ܨҧY{@qY룺:$ΠR VV{h(XP)LxҸ,0$&FGΕiS*nV8Y2) ut2AvN~_`)R0jz\ |IE=ǔKJMc8k ڜX@S?{T #l`OZ8>_ wR/!ڼ?2 8/Ձq@(! k>ydSf'V~Yz_2Qr~E}i֞e<jds1Y! we:l zέ5^AO]V0-./sLfZ&rShypѴ}hأTP.qY!:t. r[ڌ1i'vPxW4]>Eu<Џ+Ўd/3W*G,Z]%k9PRc=y;9ȝkgL|VօUh:fJ%<\a? (wr%b&'k݀$N=jGkg22ᶎ~vc8{>3;n|".iƯQLOAVlL$ K}'qYAJ [) 18eoµ/ gK]\,f0=f,H^BĿr{KYqxR~)1`ŇgOsA0o`55<nRkMkQH##T~X~]s~tU/jl ^s.QI d NpLXR{Od!Ī5VrQrGbE RLsI _.w e\ }}Qa"2TdgW  .Σlԧ\S2Xn_PyѝBɪ\U[VHs@g2 @\bW~QhޗA }"<^΢[ڟ빃 qI`%GٍV! %9\0g5I4 q Z8kGhNbXFt_Nӓ| iyRi{|$aH$ű.0i4(t+/lٽ[k13P1fEKᭌD?55eW# ogK |F Y`WA`eO9?V ~*1:c(,I]W4+s4H];<ٻD0Y? G#ͣewu-0^.TCI`jjkQq!r~[e!Oo W"߮)?~,VV↠Fa>XOnߞ_5?JsqRĢ",rcYwxA'A \`| 7g exV0bK'v uOgE)`߃diqb:K:HO;@[ByM.19n |RۑxΖS}]y0&H@2POQOp!]nGu($܅=>ɼ{~c//e>ȄiNnaoO Vym%Ҧϑa 0!S SQȮRb5˜9_4T!7'Bр `DQCFuYԘk6SdSfĠ. (&BaЖVLæY"R+JGn  fT?@E |2ժ ǰ6v#f"ΤyWFF ꦻS@WX50=ATcz\RdcAW\.@$,>D%phot-WKi+9\f>^WY[j,kxbA}pVj7*]ozNiS{Uagꂳ|k$w* q5)2]mm $6&r`"5^{3̀{%"%J?<Oi&yk~b&Njjc&֓D!LM7'C#SɁ?@L`R5Dg" wlLi"1.I b& ĶvOqaQKrj.˽4U T< ; 8Q8bx[Yhk؆ARZet-r w`4cR6)1{y6zi,<]dF2s*1hm9 rwF_.ާLJhdȴ4zBUկwC 5D9.=Uș#Q-9QeP0YD dNGQ&Tn.\Y4iG_dSZy@&"s z_7DF$U: nGۈQK28$Vp^]AS C#¼-Ujv* |ͷ~N BAyo6cq"kxv^P[`Ce$ fmm&7E;d6&:f!5_M=ǫPV˴tc -"s huK Q(*ܶ1Yrzj'|m 4u ;Һ}1s8De Iz@@C}! q Bnͅh=yx3xq`e.eT'sLذn9][S=dSJB)Y` n@'9{ץ0A3yZHG߾RGQm#6?'#0}jXo*؈HpF푼K2)DȰr4s9$yxb;frax hl; Hf V_'n5|MFn]?|SY f^g4)B2иY`$/xoڥC$G/8w}7WG /V{PX.P JRYr"gi-NFF2U'3:q 4ꆦ! JX{߼D;Ku~Ϗ&fԕï$cd/Ȭm9՗!n~lؓ52Lբ,+ar#TON1Ճ,e̖,qdzclS7㱒>%!f iwmGxͮ7uȆ 8@0+B9~#l7.qK{&PSk3Oĭ {cح}[DV"g5tfa ׇh_k,z3 8&w+ ̗Gb&ʄ%Wa Ns')kòAR@?cw=[/t'O~h ~eDD))6Hx-fB"V9)o1pt{ROB>Pv,f>א;1/1:NĞ_l)mzlo6VVP{o r5 PB;Z $W/`9*$*y :PPi5 ~퓢:_\PlY?Xk(< “QBdTt !Aȕ؍vO'4BpҢdo^'>eh$| 5$}Prc v- 9#p-eyT5 Fr1V.Sȗ|C+@>@,|`H.~.9sԳbtҦ6!vD<'`0* Zk7XQ5>={*Й=g#EM,`cMc-L黮<1 V:$t'HC S=kv~23,|EQ~x pJӾXɚ/*,5z~LD? -o\Reve RdeF0y悅h,w!HźI5 KZ-ƭ BeM^&h&wzG?Zt&pI B$^=t q_l\? MU80jv1cc$m"M.PGsx<Sj(0"Dm.KX+52lCd{@tA/lXCڗ]Xzq(@8ӔxJbڪ[UqB|IޯDdӛݐM٧9eg$[uvH庣BzJ7nE%_x^z9eG􍻺8QdE|SkO-T5ºOM7o#P_C,Ux }77'%&R,8-H6s.vm#; ` |GvW PW=0gFL'\=8?ֈ.t ?Ŀ8+K0h\xsSɁx~ 2\PrX b >zVzSxW@9vs48 (KdB~+ifoPy6 u_VTNG~/{E^1Ͷ¡޽Ѽ|:V|qbg@F}w3}[ zfaiHluNmn:OQD({*]Uc#x"X)[-UOf!V]uSdTdшA .i;g)E?$eN%!0?B@{|1)tj(B72AlŠꎱ4dcVĦ8TjA-|t¥@G_ڴ8".X2Tr}$0dH8Oh7Ϳ(9l!0S6qPgm"5n:C_OX 17]j EWOvM >~g팊\0`ETR@Hc3a=eR"=Lڙ4Wo$]$uw(½1#3K5kBFms䯠0cZ2F(dC[Ƙ*r3Ts;7}w!mdTgk2բ:;NK:C9\'es#̝(COvT)+Ջ͢³wױ϶P-GZ #s 킝?5Tyz~ ZW!Vİ]/>O&6]gHMj e-|gH7ib#BPՑvMI?Wp:94^eȼr ̦qC3vpqUF? *4*Ta{h\fN? 80[ò2F22[MNsB{ЉMYd3PM%7F7ZkKg* D F(ҭR4u E:vʈc2+UskyBm1hپezZa'鹨e3QH/CVE-y쒹=1M P~J_N{Vj8~j?a[:[κwۄ<+JEԻ3$|o9 T88]U)8}baOlO0r͖%I3B #1WTq|ƎLz/Ԃjڈar,P5#t^YU"dTn=,XiUa@(dTEߡs bb,M{bGcM]`^A_p@emT_[2YsO!A;"q,'/g *9Wr#Ji[D}&ՁTArsQnXPɿ١gvtQ)us`jP pE7Ĩr5(OVo5:*BbqqoX _?kfA\MKXd;3RW1~x3{>@U25| c!OH)T'Q)ߓu&^Q\r){ĘVr,7\Ex@c!0J=qA -pSS3yQc,ч9){*!S+Mb[ [.{*+섴/nTD:F)IH]4-k4d^)w|AG܁J"LRV5*XEfTW2eu 1cd#ˡbs8'\²8vt(6#tV Sgqd:6 B3/tQ*Iݧxud"KDj q1H0z)RVӍ[9Z:4rV(cyJ~{c/)cS[ŗF2ܢd#>,AQ:`l+yx&U, Y ߦv!dI0sB F?ޮ['0G(8Π@;+#b UipQ l|D\l q^%?NS,\Q9V\NoˣYY\4 y u%/>|[n`9t{FOUVa: Hx6I(*%C(eƯ8Y-RINRLX,ei@e*Xjsb*ЌĶlD0̀b>&+ljT W;AK uQFAY{1jFN\u%PgH~|VSds]+hDYQvl~J *Tw=C0 h[Ϸ馷.5mK|⁦U[U@ik`,_gzb/^rlMi0bF[c/i?pIԯԥT&A+uoE25)5ne:$Ӱ\9* Pt#ŝ`/=$mzYM>/zDi'öWAL 5T+rDtPه'(. l/a]H&yЖ|Dɤ~`Mq?O(:OUl;sO.ޞ37w]T`XJl1*ĵ s(ERCo]:Ĭ jrS$CIQc۾5 i 3بp$FOt4'tc(Jj:q 5\yEʢkvLAV ;.&CqYɤ %9E0>cEzOVt6kÜ ZGDFJ)Rr~R( ^##hDmcB{Z*?N?])U?Wkx;f>ٳ46]6az2޹Ćfo  .XI`f$`S/yP*8WGKN=s+9(gH2$/qQ8XqdfP@jDJ>Ƈz7Ճe(3g~>Z|?9,g>"Y hWW֥Dcy\Phm Uw{2 qΥ>WFj"yl9B j`C}Iε蟚hZN"A@8nBX暪9 Ć> tz*D@ׂӐS=C<6vas`D?CJ1`aAOT%9MئVZ%7X;P-(k}Yjܶųx\;n$~ Jk'㨳Ȯ)ɵopb0-PGcˀrs_dI]&WxtH27cU*6x%o=gW |Qa_d )Wg@znyՂUwCMfP{sߢ՛\ʟéPy4k$%N5 3vUˆ J&!v*T07HI8/`PΚ*[9/N |pk+Z ݀t{2C+!sVCMK@20R"Hu(ꀍ~D^4*nhʲgBnh#cFN/6ug.O}gYdշy'GWÓϦs_^d9~.z8Wt<ȣ%ëJBM$d2УoN^-X2t}COX +q/e!"}σ3ŗ{naqQɻDx+ãk+^ٻ>CZƇ+(б U1@ s\^S0"8!) -RMfssCX`6Tb'r)%GfmoX,:>]Ob# ˂3鎸MP`۔$dat8F$@HT(7ւY%fwDR"eZc;b-dt؍,5 $&*1VRA4jkB@︰Ywa p}վD4)K0z.<$A:J_"%вU5v~z4,juQVxi:E >[Xje̿&+Oϥ#0HpSR?'H *4}b9yRAK%s [OE`xq]u#ڼ^ w< AmceL܌osm1 +yavռU2xUGkZ첸.jj# d].VE%Bcp"@ DiC7k鼢{^V%g.qOm田ȵ%GbJqh?v,l۞*:{Cѳ3iZ'b@ԟ" Y).2vC eBܩ“j9=Zf>Q2xe p`(N;b ;頠/\v?T$˼g{o%[g$c#o' ( qU1TvCH+ kC?/׎:ax[̻9Pp4茦\V2jMijdF ΁ .?sQAnE@Oo\%޺͠zϝQӲiu=-tϿOTg^p69{/oq ps1xx†AУ1THY3X'1[!ExL__"B6:ytfz4."nXWxvZZpWpPƪ>Ȉ~MOoj5+ABNQ;t]C9QE?H T?~B(o(u ʴhFRQ2u؄!^^-V#4s=.޸nD͸H`Vނc݁R ]bjn+/GxmA˒ *6|"CƠd3J<זmRݤd?p:!ip-1giY%ݵ.Pݤ!Y*Ar z],lGL,ڞRͩ'+SBr8|71?W sneײ*@;?ʵ0 fU,ݨSzFM2%UQގ] =5Sb/Ib5WI8}dekw\o pЇ\E$0E4kӪS?BOTuMS{7*.ﴶǨŞvqUX8Yџnc7VR<2U{o9_G+JzUcۥhz~xEv>i~b`ȹӂ,,W\pz Ee&0#}?C2a6:6rGҍ' rơ·22X6>c!6 VI'0mv8? \?c.o|]>MMm'oM4{גc\>sLwr<\=?$s^JBB G:Ĕˇ2~ X`rs߱X(%S38b)9Y,s!g')A4 5^ݻ`'QqCZ7tPE_3hj̖S1h!%)>( B4pg[3.8Kx< ؝TsQu,L_t2:AFf4](h҃j\$dc!뎄k͞2&z[ }cA FZ*)Rg;4첾Fe;T+PܗJaq q,Ӝab)0Su)ю1Xah Ue 1t dUi q^ *{Z|taXa NVO'y=ݕ*Ӂ8cL&jVl`Ӻ66(2VO83D;b7!en пDcrDmqHݼ;Z氿({at6:e㳕5%8PQ#Nn2s롐MijYXUV{ GbR%.E6 _= 9k0P}/I]\G/;,^}hU}C5h8F8\+i Kr!8a,{qm}[fNٕꨯrqR@nzZ OUiAz:B '8(2R.yo`̚Cz3/hm .k Iu.Ė/+#y+p^2/l]q%1z#\򹳬X~ {Ȟ2t*gQh4g8YqS(vj/ӆnOvQp 8()Bfx+.wg;Ȥv[J8r qyzsƙ>[qrlo3tZ7pIbA>%F+БE=t;wqޥ<@oM V<3j uxMZrC߽ gC|g/XGhHl#ebJ@R Z] YQ_As[35l_,UD=+Qݗ~}l. Eo Hsg^uGnɢduq t.W ?XF ASwiZkH`: XZi+5b~9P%|h7`&4P 3m߸[̓-FNqpSlm2RӻUs24>祳APɹŜ߁Yϯ-衣3js5-;`R?V8cY*"a>^"wg\8ǮTZA#RFf ;Ё$\#@[Cг@#0U$C1UDfVdHLJο'/֭raOQB{@!QS`0]//D5:T,.!ZwƿYzQzrV$ IhhC뎓$ 3L2v]|O!]VQʑLɢYC:\uMKƚ M?@!a]%RQoAiGdg6h)1%aA.k` T^_|mj̜kDR6 *a~% v>u/hegz-X5 z&1^ɡ٥i/*i5+Vo p0ؐ(A2NL)v:a>]ޘdXV+tzdJL(G!׷AGfllNPyoj&$%?}N f{`>l+)S#-`bAOt؛Rz_\˞qrQ#īS NL*=h{&BB[f;km}]r5״HŁ^8(34$a0R@0#>Ë];B9˗,FVmPDM?{asߓT};ϗb7Ga Ed^aR,D .+zIm~.W#B]w ?'QI Pwڭ,'*u^]9̙*J[抸/[߹ ctЌW¤y\ES&1@Czo8=]+&qL#(6{LXޕh# <…cʩܬ\6%S6eICQ3?YgP!9%,K(icxl_pF8PRtq2g r| -+?ZX~KMTTj l/F~qLv/t@Ğ]H`[PGEk/VKy;,T d(%ҽ}QRX^9{0[3?5bMNv/{+$1AoV5N-OE+CtO syN:hKވTY.h%ޱ9|pDƇ1fs?QY+igŒsu`jFR"(Is'RSS}';Upc&^/=PJk)A  6Gv5ʻ8I%a c}q|廏 yCO̱qKd+WNn+=40Я[jt,\9`{ۗƄ|q$qwA2,TŔ8rh_s|`]D[Jr.XfXɰ RXڶ_&ʐ'$u RlK0B? cZ̃04 )$O\B:E4|o5c#%@B'$thè7lvQk~PzgȂQ@(23pW+qn[4xN8ec)*k*臂c]%ЭW#kE.ZCm ǧ}U7'S<&9VuT~Mi/ktՙ|c]S!Ø$r6k>'~r'.6vzsn,>2]&I m2E^1{ {ʏ@ծ wj$Q`:{|yhUD$=9k϶uxSxM"=iILTmq|Q5[(kM9089P FpZ[N)0bbJnO՟"$Wokp=RG[k'ãx@o]|eSҝUWnŋ~%ILzbKH h ]X?đ'f&v_߭I_b4eup:~ʹ@@&'}2=9QEY1 ~a2 zJ豆8lCA`ZU(C&ﮭ$EX3?pJN)82.S^3}wLl| WK;_ -[GAxWH!EYCt&A$rBXS bM\2u-}db|W}C{X /A?/݀GWPWETn}T400jM?1@B7Yf.nXQ|/=-{jp{cƴ1<$# KLR DRdC=b( hX}!HbL' k昱p͖U?؃. .`n1z9kp{t[ʹk("$;q5DUeO`c"x W{7C[Z<pPEB7{~弎͜ *Gd neHCpc&2rU u@}`0aShc^`UIy nUV@q."LU!gPҤ,֦ ́@JͼL cNH:gGܓ d}HK}Կ8AfQkkʟN/\ig 2kژz,t2 v <)KOJ(2c6nc4KHroWD%25Vk:ğw3T4<޶q *27ZHՋX8X'LZtPŸ|꧹b'9+CE1n>XbjO^q&10TG2Frq[WPj y.<zKSle$Ǒ>MnuE ND%0:pq]":qua[)Ȝt'Ƹj٣uBYb!~~me{oC{IAlŬ|d|&r4p,BSˮc2$S;ϨIJ2`M0W $ * ZjXT .#M Ҿ{i0J:c`Ub]su^MDm`#.Te,W3KQ~d>2CerD#;̌sgbHYb8?~sd`]LCweY&5;٘U$y:M8M&oYnɫ p-VS*֌|65ZYSZ:4$Ƃg G fҼ]oQ!B3F) 8PDD_M ͅuuk8^E=XB)Pg-X;OTIluT9 *tO=cuBYwߪH)%cQOs{ފn^Ed%aEP)5eބ[LbX@3$* Tq>Z+ºb/%] u@a0&ҟlA=t<V9.21ۙ#WY hX t{}E(EM1+jj7tR9|pL<_kE;f=jKu^[?Vew:2YϚDpЀ a [_rͳyyorݐG4H35 S!-EׅgU2uw3.\3yZޣ{ ”?(tݙ+.hHh_qnya MV#MvԅC YRJev/91lJ54vSv}2xazŶh-GuN^"r?yɄ+\F!Y :_&w盦([Y&M!n"nF|-&k]7w}Oʜy*!ʟ\ e[J&b Rg?Ln: xXPv}']t{%vzzxSD w3XV`3g]wFyY\4AɥZ7d#[p }Zl;Ss$pt~Oz[QN?<%B!*i8zofН}z`F7XF ri1YfE{C׻^^nXtФإ1xhJ_T)Ddʿ3F_#ɯ۬ߡ 9貵п?gctHr W+~k OT.xrK^r4=EPTs.EӢ"ǚ]2`J3@ʅ^(;&qawt'{(A(݉uvЩU:^,d-wA;MONXĈ5l0@M+;O(-8:9 ǖFLd"kYVA-n!E'B Yy!5O=\c_C]~Y9V)TQ;Gl2wRG!Zx*M AX9HSםx:筒][U_9!lWg&zouZq"`:(^+Ń/,%St…&`S! b"0Rh9tm8#V #;*YhRϐQa%s.r!c_ތ/ xn;t (%Z8Kacni{H~Aېv7X NښVoU@. x`ZV#Joᄖ]mOTrZFR l%2\9<(Ãq|D]x9l )+a@ 0QO^V_Nw/>^EK[H0՝ٲ7-OOGP̰%qF]wة3٫UxVxDw"izKz)6dHU-O*Rl*7lU91m2@2%*h ~Qކ5}qlĢHx1QO¯ۀ+8g5z-b_0|A+HuJ }u.Qަσx"$\pnK~Ow;=ю3,0-ٯɧV}c9fjaL;6&aɧ+8s{umBMH#} o|/C-PbbppaBduZ ~ |qc« mτ4|g5tz+t / y  /`%L1g?bI eTi'.8if\`1W+垜;mOѠ7 +No^vf\Z ݣ֎#Šsw֘L` U9 bSǎyQ %5d#ެ[Z[7Z!҈+c2Ǘ*@2bg4Iv[,#݂N(A寁y0c -ze3}9g 6kXB3O#׋/#? 93V7-:4ThV( p%|yT\5(pjiUa'P?Ķs/HMwAcDe0Drq R%'Ď-ntaP@a+. OjFac"U$bTD@tSbNOvbhy|ƃ*7LJ2֎>E2,izSl,l0Yl)D|LNssx7B֭]דu&33e/ي} o@i3BO æ%w xfBnzv&#Rr }^MrHb=o%Yz%"*~$5"{ڇ46̰Q3QJ,?s,GݴSatp">-?riY_q$Cy8^rCP0W?7|is"i)$q RaLW8ړ1YsݘkYvʳ'jb6Pkyu]|Nv~j_C i88N}늢/2v_SBC2o wYo80%[GHo7$<)&ca#!F3d2y5%<1S~|9Y1JA4[Q#$̆|e|ICUjC54`ʼpZ&&T+((40\JlA`j,#9CС3> vrbv|:*OȈN]mCLLYm~ļ&8\B(p^=?\Nx+!5RCPтm`?̞l &mF`3T%uA\enp {V[(w=i2 j#%C6{C~DNPw_ߢ da[`|#Y!hBIe,ޮlt:.EE|i8F\HwF)1<ܯX~$'ifqx{4ЬMOZ42 w^iIMe[f}v +5axi/zk]rKC,x-4k+ݬ'Pw9tƱ-uXe5B<ꖨt>b! bD8fLcVLvtWrFo\PoZyVUrL{>*@`ؤt5\'QPƟ '<@3(/,@5X[ҡLt-ɱ>NH.lӦU)BUEO5"R}gr=ϼ]pv1SN'TKtђ8Է* }ݚP= S^>_d|xfy 1"`u<ݢd3*sMFR97E7Nd_⻱Gi6 tl,6İ!>6w${r߫֙ˠ2,]ab9@sb5־0m-(L/ Cx|+D7pNb/B,DqBts!k<N&My_eQv,A.Ϫ:=9 ;$q+gMַ8bdžT&nG-0oJPssidL D!an%] X?qHg>.qLe\xwG\Mhtt݀{GKM c`|MRef1{ =k$~qQ<ckpb]w (0LR jު,8ء/WC]Bٗ%BA);l3Ct¼njA3$F |Ԉ<$ô_ F (911-JgGI?B6nrK7N8ÊFv1F[WL DGR ~%j{ W~x xuH23  mP/6?tM} n$@82+,xDA~1ݴeQz M_PdR̗&\ 3zQ0fA,dR )hqQM#Qc6rMC&ju _ -{th-<BpM%mArt5n+.7VYtna,["6tˌvǃRv  +{ aˋTj DeÇW$q?Vϻꝰvǹ?Bp|q2k.[@&~>69 I8ms:_~6"5ECt Ъ2s#̔g( Ece;FM~\w@/ZEU9>;ðm6]rrf QBf`/_>)ne(o!,=.So[fqqVlJ!bJ6gƪ~pnxY(KtֽcP+4rjO+AnhNZLYv^]qTɞ dJir\i\Q2X2cYzsd#( r!BZ" rp3v4zCUE0QNr[J*v>EP}cyfD\隊:y= [>nqbAcxҧ #iÀ--T1LbDO ɶai^OU+r+Q>q@M, KX2:s 䞜QWvԤЗc's;WJm }Iyp؈y8@GKrxL̅zHEг "~f&~_,2Ew)T:2u#gGa_|(]``l sw#pG a8/q*mkDwKٰ6K<± 78YofR^J'*໼~]+a.!BD֑kY٦x2FQO`uk\)KwL jy49-4_tOi*Ȃ8sj`RkNQ7cP{ 9$كšoR} V J\T˅#=?= n ] Bz+'.gRXgS䫜P'%=1 jp֌xDg %W镖j#LҟfF`ʓ L~51rP_@Ųv{2BׁXwL7_q}يL ss}Jֺܷʨ$.:;6ʜPiؖ7dE8hSB~ ZizI[6-7ҒZ-iwX}92N.5.J < R՛s0q6+V'Ò< OƬcʫ IY ot!WK*[1K-{ϷZS ~W`M;kl=Z.Q5LY.r Bj׬Tіcc *]0LEqٚ8l%g*ndm.CwDԙ=WIZo]\l 5Wh _CPH! Gj/Eb0;KAB) cNaO\0&.xϰP+m5pOZ߮71Xia:ݛDɮ;G:g಼͞q)Ql, #pE^ݶ.i\ӀO(>^ДAô-F#3wCBo c>=+l,j5 B{+hR>*L4vGAc ޳.ñ ;Jyoyiy0nNd˸]2[ɞq8;  }퀊P-G/7@DXӝLbOAOVr''A2 5}b⛘reƒYLU-ṳf=WX>#3%BO[P S 8mBx{ [4:y$xs6qF$!0e0v{pq[>̀]2ӡ'2stfwI;qWHr\\b[Mޙ[LPǤZBU*{uY݇)CzDvGB>$^֧1x5ږ.5:2ZY~P6 bݮ)L`{8*o-~ St\LKVo>kwib**vEBR8 |04m$(%cIL-\)=eH65ƙ-GY-rXFI;]xUNIhX'Mo%p#L< \!S5=(iW, DFG+7Y?C]x%jbjh!ςDJxYQI;VKyĊӒ w( kFby1#/Lpd3kZA$D3`+rQ؟4s7މ\`">&2 ,zLkQ [YM;baj8vCOܼ<ʌ7)Z0'l8GPMT/(_ -4}p ;Y ]1Tut>Yj'.D:*tQf":֋5H;D׏e;@K4j,Ǎ5}O!E%l+ %f+ #ɘPu!cg ~BU5샄, y&` Qf*_ sCG}- ])f_,*YSA<*^/Of2$}9lJ?no8`0 ɗ&m%y3ZY ZI/Jg>EA"wMXkOBq;pd"ҡիNyu$ʽ!s mX`׸pQ|n^GTC*~jFXUwgԣ(6m0;_8bcmI-!(V )ͥN'-HV'HTw$$CP5aQ ӾpjjnH/tE)rysV:V=&Ÿ nLN ;=jߕ8[ÎO@R:w~v4еn)ݶW^>vY`uD63v]r4Lϓgk"vшƋktL Hnc xL WP~ Y}Km1#Cwkٱ5[3CPǴeUzhp2Kdx H ,3 icxB'a i a*Vх'{Rsslsp*E׬eK'#^P&OLsgPwO7<%d"f}6+=o1$MK L>\x4ԭyuZMT!=ȵd Rx՚5/GJ/g!u$ئJj7A]5he,uq2߱~,%&Bϫ{v8 U׵ndž'M!c׶)ܓ.hNig6Ml6 ]"ځFpDDfx4٬3Jx.0z6@,b<߫Y-vu} sEk7{czG @?G]oѦ$cb:K$Z9"U]pZ.IXѸCLᕁ:D;A M`O* Ped`}) M51ʯ)4t6Vܷ9|p( I.Wq˝녙苜v4 s 6mTK$ɪe(r\RB+(յ~?Da3sE|;fy`|]1r.[zrOh&Fy2 J 'ߵ=K1ɒyQ". qg􅀻L'720x"_573+l`9;NjH(ԩ?+<޼~ ^nq++ ̂S3yr0P-=~VޞhYk! ?](_mͩOxr^0^J#G\zw eS!8¶K1_Ded Oۛ95   Vl4{^XgnL$4N)9p!yCAx0ZڿsϴpT\p;Z7eL< #IPk]F~򧥉 X} dBu[[#oҤwo0߁[?B'/rJGP3X BfpF q)UKQAiP“G$ՐCŠJX~Gs\|@qoF| I21W'Fqկk\ə%}z_*I䤢. e&௎)({,ziL 5"~^jj4&'}6~zRUӍ"P Zp;ge]:wU@8k=- ~r8%\axO:kjAZ"|C= r ըⷙ7* T}aٸ>i gaJzV*S2+i+uvge?t;Ԁ *5W>鈔x!-떌?醏ya %^U1UĴ) ~?n 7 {ms< qR4Ooywi* bUcck:ѪFfH.9彉;fG=^;96j欽גO2JA`_U0RTE?ܝy[\l'O~S,EaS~Bm ^B,928ƕf*|Mv0?Ցsxҁ=P{%g %6 {c.?bѝg*"K1=sW YZ