sssd-kcm-2.4.0-9.el8_4.1 >  A `U](jqGw:OGPXq~O2!rScR8^C:}ϸ|sZ2 &9~m<3eJֽSm- aҙ5m%]Gu![CO9"Ζ5uw[H'?sZc|zwٮFR0MT".\CGqǚPy2BΜ21.͐$c hб% p*5QtD  ڭBj]ů=pLԢD./'jjv a24/= 0eR ;6~NN:v)-KQh\dm$r8ԡ|}`$IY+O1+>IzhS( wiXs@^5muISQ7JL/^pn aZE?|·lvdwp[?|heXFUpd2Mzz(Rtp^xg -SdƀVE7pB_?_d   F +HNVk|   $ r  R89 9d9(89<:cl>Vq?Vy@VGVHVIVXWYW \WT]W^X| bY}dZeZfZlZtZu[v[Pw]x^y^<I_`_d_j_Csssd-kcm2.4.09.el8_4.1An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.`1ppc64le-02.mbox.centos.orgg=CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://pagure.io/SSSD/sssd/linuxppc64le if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%,Gp.x 4AA큤A큤``!`!`!`!`````````91b30e576e05441743fcce027767650f498cf10ccca12ce0bafe8505f0e87b6fccd7e89b03f01fdd98dccd0577d20bda8a00016ff9fd59e06d42c569f340c3fcb4e29a574d0d8fb18abdee833929707d2486eab2d2c21cf074496be2e7bf9dafafdfaf34cfd5c1a4ccf1b714187acd3d1d23559a106b9ea7b7a8a03389c196ab7913da7bb78a658dd652842bc91e3c30bb4903b65ad8e163aa9ae2fab0a5858fbc1d859b62e921b6c74b644c448186fe5703dc23e8cf0911c839b4779075dcc22f2f662d812ea46586062ed00e0be873621d5fdb42f82582af3fd8353b2c9a0ed17cf523de4ef43865acc3126813208073a443d217baefcd9472750b365b0dbc91b30e576e05441743fcce027767650f498cf10ccca12ce0bafe8505f0e87b6f../../../../usr/libexec/sssd/sssd_kcm../../../../usr/lib64/sssd/libsss_secrets.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.4.0-9.el8_4.1.src.rpmconfig(sssd-kcm)libsss_secrets.so()(64bit)sssd-kcmsssd-kcm(ppc-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre.so.1()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_secrets.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.4.0-9.el8_4.13.0.4-14.6.0-14.0-15.2-12.4.0-9.el8_4.14.14.3`@`T@`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.4.0-9.1Alexey Tikhonov - 2.4.0-9Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1949170 - pam_sss_gss.so doesn't work with large kerberos tickets [rhel-8.4.0.z] - Resolves: rhbz#1945656 - No gpo found and ad_gpo_implicit_deny set to True still permits user login [rhel-8.4.0.z] - Resolves: rhbz#1945655 - SSSD not detecting subdomain from AD forest (RHEL 8.3) [rhel-8.4.0.z] - Resolves: rhbz#1945654 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-8.4.0.z] - Resolves: rhbz#1942438 - Wrong default debug level of sssd tools [rhel-8.4.0.z]- Resolves: rhbz#1899712 - [sssd] RHEL 8.4 Tier 0 Localization- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh svuk2.4.0-9.el8_4.12.4.0-9.el8_4.12.4.0-9.el8_4.1 kcm_default_ccache.build-id0c5b9d73644bef3ccc00939f08eb50a97ec4388856046a16227ea62e621a863d9a62ce58d3e7b5sssd-kcm.servicesssd-kcm.socketlibsss_secrets.sosssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/0c//usr/lib/.build-id/61//usr/lib/systemd/system//usr/lib64/sssd//usr/libexec/sssd//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=6156046a16227ea62e621a863d9a62ce58d3e7b5, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=0c5b9d73644bef3ccc00939f08eb50a97ec43888, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)-PRRR)R%RRRR RR*RRRRRRRR R RR,R(R R!R&RR3R+R'R/RRRRR R)RRR-RRRR RR.R%R R!RR"R#R$RRRR RR*RRRRRRRR R,R(R R&RR3utf-8670f7ecf3e0de6b54f758048be33dba22db34f8adb2f765c2e3452de8dbfa686?7zXZ !#,] b2u Q{LQQ:I8iv7euh*鍠{Jɒjm~&2хRɿ|݇!K\ްX*ϖ}:nP$V-q_$ٹH܀i(D Esd ~;wJ驙$osiŒ[փvV ci>dsFY9A# s.;b8rmoӍ0 {џ̌ar/5C ߄E)]Ne+Z+00Is٥Tm=aHNR}"o@HC~9_le9ՙTg "$(~" m iJYRٖ2*[dg "7\jƉWvČ~F0qv{ 6< 16|}NB$ ^,nRMJTEx(YKӯcb佧_Fڶk -H[,vH2#g֫Zo0Ȋ֌eY.09E~Ms|PAEu;Ɠo;c3C}q$˕TE}e^k]롙xeA嵯q%Oo@완-L4247us48dk!= Ps,o0Ias]1 XiraNjEņ6k#]ԬUҏ{^ p"~kx>H*k6+zI 9hL:oNx^6!UVuO,J| m7ȱC\=K ҽ3<61߻=PH4AkZo ވ]MۡǸzp>QiP%B}miErLvm6H"aKuky#_KC"}$ePKWkqŸ0d=ZKmin4KM B@P:>a&݁s;dvI'+`6h{G+Ζ=0pch KQ4 >r{?QA1\PTco<69a3ɀIf0rÂx0X1NVSJSPv oyɝFAܣI 8ƼκKbЂ(\ Wf]q|_Zg_dH[)Ih[b{do{Q0zs@'-s%ΝȺ_B%\Э'r7<ӑqkD5R-5/B:@&4~jۚ7ᣟUWFko /DN_V題k0"y~/bLBKRF7" 3e&x\;AT4Acj`3Y_^r_K1*e["y'RG oR-&L7>ֳ_|*?=eH3rJ:ỳ8Y9T٭e;h'a$ [^>+v\[bXF/&ۆ_HZzFl+q ,5SUOކl!ᓳ}L.8wS[k:-堛%J.l:fF<>FMS@8z}êQiv곑Q..AbR*yˀQ񘨴@H,Dv3u+,lN@fphV<HEy>ǒ'3r҂dmbe$bh%൴nJvtJ* :7U;yy GvuP=h/in5KW5\&:ueL"h>t J?[D7zQ?V:1Tjg0"O9y9JNhKyy-}  o]gVKKT] 1ԉJJ/YngDJ;QJt"LeIw?4\3ExX͆hC 2}jޯ^|kvx&]~Z6a.mkns|;ˉAv9Z #(8N6S#;㢻FO;RWtT3: a-s˸sGCx j *W;1ZTgRIc0<4Y׊:3{IVݼBv`Ob6Ri$+wάС9+L3f>i!_㟎2ʔS L}AO0V)0"c ӭM |)GtE|`KЉ%Àzõd\SU_J0`-n@jiԶ8N9P<hmn&L,6F} FrDj (3g ͟`ۭ\{t9<חn#٨QU$ys'Yx}*V>6q!_G3XL(zf$`Aa< ).qTԹOJsLyRSWQw}~xxY%pYJR7}]Uc]4b #;N ͽr<n}D8W19,*F[L'q943bm֊^JĜ:@IyՈп(}w< ([t 3dw!{=R plFCx2ʮ9.f mJP{@AA֢b_nf϶5G4 1G*@B&ZW>nKUCFk^COė^ki_ G~}z^RuDu%ْ~H9yLț 'I:vKXX) 49~5Re=ðe0Mn ]ۣw63"4 #\&'95vɞM#y% My{ޖ.;Bg""4#wsZ ʡr]ٿ1Xƕ>T17b1I"tz(>:× 3'Ž?:-^tTz`JZ/ݵ: GYX%8m Y P2dkW,fw^vNy2p 8oȳD~K%gZWAP~fYcY֫osR5 UqH*FQmF^HD 22^dv)+FT3;RּLT4a {A ntK#=JQyX*ʄwxF  ivmsfěc^JkA͍afIIwyA|ކdѺul=~'@Iɹ4 ?oBP9PwuxpxF]ZmKKbrfQ~.z:ҥQs߿;#BVQT+kUSUqJOƸ% qAz#j W#_Rg(_{ i?m_ Yo7!hAV%94j!b0tҪHO~+|GL)勥,jeP]h/%L&KJ+Dc®uA?/:}ލER1;j0 ۚL H`6KըΉW+_  ]b#D "!%.%>X##y2Y#i)\j,n{@ 8nIyf!/sEupjΚRAN ?8٫~s{HY Vb`n`W6P݈I{ʼnD\}sDpܑٶY1?2ςQ<)4=ݓ|Rd0J0QgB5VXyH6,3D48'wZ1\-qL!Cn).sA {f8 * xpSo1˺/:446zXD"эTG}(DovۂF8FY~rX"ҍ 1_Y5qĚ|wF-j}XM=Il UM _t> Aq?n{h3xC5_Nk sEBA:иfB\ֱPQwavKY&Je_ϜpMB>I>N=!eç"J Xy55]8q::xG1xj0E$ Ƴ mxtD|c~OP1ɶL57<{xpڶļH\U+x'FL[N#".<꯷1;YW)lGSԇ4Kh2cgyJ`ED^I\)`^M*;ֳϡ~BEp ,dQ5{qMSċ!P A YNՄs+c <9"AH,<=Yrvg/)C-vBn@?w9>.t+V599byc1kKK:VEP:H+4#moݹh_ZRu˄p]P>~Hm0U,@>JTX]o]eˆqW!x\+H+VMpo䞥O68eKsM!`a MCK[a}l%# ;o4MӚ`dna>pf'$|d4Ao[b깰GpHsn݈ʊ_9TNg<(#ap;:ZIo 3r15\ʰ SQۨٽqHYpL[h i&/@۲08zZOS }V>κ,y'%/I EGv~s#D=#aqڇQ2XrDZb+'8*3F`SC G*j̒RoÖzZ5Wcb81ĈUNDv.oDvscl %`j!sP"'ŒY,d5m.*k0d#m}"ZX'kah muMX[Ilk+# )$\AxKS^YpH|J Vm4YrEQTjlz1Ƹ.5,4jlpYOQsu'Bҙ󾠔؇Gfb72S$pC7g Y(j)TcS w,}8&Ӟ6嚬(|A~v$sd,,h7Ύ&~ Lf& 1y7A^2G8`^"xYc몒|Y"g1UfU7m^a3 Ol3#i\nҲKejМ'e5@Q@h5Zn8Εy)$KCR -}Xd\mCaTLTM^,xWA$沋$BJ {cЧƘMwXً)ab2QVOy4*KFZC 2>$ۏQ7eTy+'>bJqZ8ZhL%UznlV'ruI[M}[ `0a dSQaNz;u6u^apoc'Q]3Ψ>c[D!|uŻY@e!(| vk@[f>5z;eA\-,0'5N{ \58K V 5,_T:ws80 +F>Aݼ#CvǼ1- 8L#iE$p,zOŗK> ֆmG\fb\K2<]C <Ș"_m8Çp]܄{|ax GY#@McN?VcGLf%JX[T+#N2BLn*MSh,1I=kftP$uE˂ms ibg22TlޠOxN X:]˅BbtDUG2e"~vV,2o҂ ʼn!4LmO6* cMIM39O~ϋ}a; < ug"T{W8mzG| A(]W{1XF6?qPd"V2.ۮLsY}͇Wch}_LW렠wgPUekl5 zٌ\U\gXzR i6oYyak.Y- !|I_θc9CEpϱ" -ɥp_&Ud^n=u.*, OPJ9sYnˋM;Y" []xĖn}' Z˜ ɽ#`s¯T>4U?QvI:̘l*o0O((ǛDc<[g]F4k"F&}|zю҉Ru/S\d2Ј^x0po'$vE+VGzu(t;;Mg1 FMD#%I 6>73 rSm}yŌ}RR3cJFA66 9x|;s'$tEEgl*  .6%,t/ ?xTŃ@2v$`PdfǨd.`go`}IzU~fqq?gNc[l&%*l}BY1+@0:ba ˙{@6.t2EڱNIeITGNYnQۤ;t̯\J\4 2/Ơ&۬}iO: !'\,(i2LtZOYoK 4߻O\H:BȜNΗL]`?A*b,obXbwh<*VΤ’Dѣƨ(e' go64)`cѪٙdFJ$b!vĘA|KV$™3bn*5/sB,݁}e9B撯XU Y+H2TtdɰL-B3@BhcaUd3}X*^M)>g#Ur{0Na㥘`\ً hwiF/z>[Md\!Gk'*9v=B#t<`x֓C? eF)fen|{(#/`Ƕ4Z*Sh''arFwgom{@ImjQcn[hH3u9(FcFuR_} [<§~Àt_#ݎCzR]_rw'-<Ϫw(w1z)ՒτyO:[Կ2z){<դܒ^pk@򢡰UU\;|'zy*-s^]=:12Km N#v 'LJkR~hCn z$otcYz+)^p-VJ;ȋ^bh*JBD̂k#Ŧ@bsm[qc#˻ٖ=W*QBxO0'd؃%) ;۽J>IJXi#RǾ6tQ'G{a>? ^z׫֛r;5y1$ bmڢ8xbKsԦ-C{^61n8}MWi*qKRp_?~k>,Fl(vPzἡRĄKvCh8Tw4mkô_y h4] l8!K(~*ZZfD{msRIuA}䂈B! hCm۲F@RkBA3keme(6(Uk7:Cs <"Pj8_'C\\T YHw-,#*ਫ਼:;l i|L3`_t:]3p0dOR;G^Ur *0>K znoN]Q{셱D#:4Aiю`^! 3# c3]ܞ[C)=$3qQSFx׃9"'#4u7 #'3:2uf\HގZ6F"'͡Wm+d<\A!(' y/V%4,t -0A \k>0ʽzY˗-KbH*7l)b鏺+:H쨽d\(`G܌x+NOW7~h W i6cF 2b&8Dg[-nM#{5wRH߳m0豰\1fQE> 9m.:$X1=eڜά~EjQ ;9O IWF=*Mu"L] @2tP2_I#y-6]J V`[T6]_'LJf# Rhnja[VCI.6Kƾ.~n?vjRU6CpZ辄O[ab7 wn} C SRϭ{Gj9fH<K𾋖prySZhP򷫊X (1hBJeJ,bzcc']UO@Po7[8`*hP-r/F.c1>+\U2eԨ3D%a_zmV3PoQ'"I6W zG|4 W[ q(a፸WJʳ.'Aƀ]y- œa SHTpΦW\,bMcHW+x$gJxGi1䱻5K;NpHog`l13=6}0B(X_|]om.6@iڥhbP"GYuLL"N7VAyd<2fU}eٞ 9J9]ICazh.VwÕ0tIMХ0x^k]W1Bc-&guV?m_N+;=ߠ=i >:]AUnM}‚دbRrEjD4kcʦLͶv6W7EʆjHXm&l0Avq^^鉑+(di s^^ <ҥZY%Y _˧I4S}s#c>H\6Ѡq"=& 6xg^ (Q91K`Lof\2IkwwB-;K׋^FX%Ng&۔OU?$а9GEٙϪ'j=F`RF[u6π[y 6UGGt|rӘKZWC'&:ņlc{B_(i;jH&b~A5>>n3 x{  '$vſzX{-'0$j +dMT(:.$;5dTCyzW'j TT-rwBV)#>fT,}eIIģnl "gqfqb/aߢC?cHe;K3Yzl"R@]-hLÿG#]a5%AWrVg(oh=qK#Aپ֧Me !txdbʸHeXI=bg(=&I2cy^i2kjs~`^?Lh7&4Ak n,wI^lr{gWr-|zMO"vi-hu濷^ J.7 zEE(7X&$ 6q}k&6t&[2VOK'!"4MaQ&X|r1W6&-8yQq Fũ[(hpJh}i%'Ni |5fXlg8D^yE.J#c v;9ӟ! ײ_5 tہbfYȉe"f+iw0Zq=YXͅ.dBc9#;]\nx'G\!'D:8ǣd`_4hjJ}f4Rqm#"1}mn"*%%SCf^+hu:ب(R@K> o1hvmϬiy8^E5 S3y 6>Lbb"+ZQNԑc5lZ!n;ᾙ$>1SdqT\ 23|QI1xJ grbS %tӮPU=wZSVPE}ưYt/e2qVO{muШ}in6bJ&&b`K^u(oBZ-p6uf y~| e0i~ ovt5mە7p ؃0v/4.V.r6ZFsr lBprx>RMV@t,R Xᵓ>ijtV>LG#Lsn5M4JݜT D7]ܮoyΜA93]EmRNKA*sʲ&i]9*"SS2O!GȾt=X?Z 2o τ$o"N*#!6K7x]HO\!PϿ_q.v*~Ysd9*A^6&k]8$W]s=Vk6| $pkb IE peG{UVy,?lBP uxˇأ)q*ĨWFUDjl/jiq}t_k2&s+xM\@ܲ9kmU zv3ǼғΖ֘\rKNz0W66yNg_b@1Rʿ e- T;?-).`CKwR"|,k*om&c5q|NhhsAzFt=g7uT{s*9/TRmA*$LoBs̺QٰWtzcľѮjFm 7-yKS)>Az0|iW ?:9I!zִ?, uE#zvc+tC-1vNi ߗsujyo}u||k77T [,C ClGKcٕ5hX]EQ5-P%XC>;ZL|foypИU@rAH5iL#)BNX.>Ab{9^rة/~;Wq'[/S;a$@kd?| i,_dž 'Td;RJ3um ؂Ikv-*x5SAqKd=XS h`1͡Q]z9].*.IUz=Ke2fؘ~| ?֜- ``qdGpOOQ3\XLYa~U@MweCYh@1*0Ʀ`|[])97%f=I ps.sf+" j*c'`n{ZӖEvzASf 6Rk 1pٔעL<$˧k)ఈ"NY+^I!B[g0 5vʷ'.!fŠ:AyXpEܒC|?Ք2m+Yu$~*e|C!K n!B襓FIoS/;%+a/Wy S]eχCb~2lVO1 fL8ƀ$}p bćMx:G;r0X<oH;evX5:["2)GD%] 򂒞/x{%0&8 oV~.+JYq{ l$ҥ5xQ`,ҕr4叁̼w? 6|'K .!0Yߞh]"3̯c ijsEvS/v׏N,|H$py|ڮE0qh0pyh; 9;䅝֤CCY;GOJQ 睦M \6vЅW#mcE ]%dWA=wI{HUZ!t+Y^$zd]j(5P5OmDaJpNYC\O8.;Ŝ';(im 47\F]bѠ&{鼤vP:ia7nqV8 w~d˜_,x4 >uh}%t` 7L(g^9%=wTaQkea7ǖa>epueo~|! aWB. 9 B d4VF,/ЃltJ2%acKHIvط/{![6hrU()|"o )5SKs&DH!/e7!(c`%Tuv̈́(|wͲe+ HzdFݏXK(]: L-W=Q=N>Szn^ C~:mBx"G&,6`|ئ 4&*I}у9te}+.~U` P("7=,v= v4?h>LrQ ]`= ˁ25HrPWХWэq殈Mw7152 z|D"ؖgJ5!P\<&Fi*g;2gPK;t];_J\%lQ8cKTE+7.4~an1E/]SLj7̃ N~_©!%,)mǝd\^R9qڇꖫκK5l-KqBE^2'℄U(bWsfEece%!vQ*9K [ZiEdZhZVpb @9#l.@..L@5n$d)&V}A5tۣ lF'(t-.*!^R >ug_#KN +`i$,׼=ŀE PQ*P@i&lBkUWd1®ȯ, pϚp%Qli߫K˴ (A9 6ppkZCPr8!mIybT,MB7-#QG##eJVQ8 !bvFs՚\"sI:MP+,rj)TwU &J!qran0'@ r fX9ӯ;ǛA289#5q2Ÿ r=ܘ}FDOrM*`kȘBcc0ԶI覜}O&'tOp(О 4 /rHppDYoARw Ue\FzW'8&.͵p#aCDH5+.꡶Z-R=gK2f I'!L+n,ւ 2إ7!ƫ5y($O ~{"/\&TC1b6gUK=ـħQySY5|K)2&?}7Yrɨ"I3-HTban,MuD(Җ 0I!Q'l,GbBqf"Ix]>"/y_E7Zx.9PSZHK Z=.AG5/XQP N쭾d| K, z?`d['n_%;7F=*W֑iϘ1ZHeĵ|H4vjMdf}[uq$4W-s/fFI ! <+3KbABFC98UbQee2!}\?G󎾥>erj#,bDtiT =4*DL\W#0f.UWU6R")쀘{8p==ueJJn6 2q\ik:Aڜ;Pgyy}FެpT*j9 E[^^IHy_x /"J:bm>J̥BSM.z :,hcgZ-"nO_`koPݴnf=߇OQ.PTA1e !q`4@jB0-IR9gM)afzIԌK`jڋKGB:i*c𹪴SG&r0ʘ@,f`|~{( [3h3 P>Qj1Y8лV5d)sO¡z_c~EK.s%ϱB<; Q8rJtrs7.L$SU؆,%h[::ə'+ Mv-R&S=↳*: {>eOf$Z5n[fa3&*r/I q~` B3@-Q/8]+ėu0F%Ꮻqj JHYo"6NTFYC%Q<Ѣp<_â}ۚ >0Ina\I*ꠝ2i~}j+a`Ih)cn1oyx#g-I~-1)C{cL" l@/]My{q`ewֹҠS\I~ 7eY xqPS7oW{ʩ/Q{k^ p;b/*?"''ksNX,ԓy灸\ R%,iTkjZ }2eñ^H~nJ\HboLp+E^eYL.[Mq/N<Kz-5ﶋIPXy.h#?LM=\, gR[_Dßrn!.ٸXF< &8-auɟ˹v2h^ | !'3f:xCDK:5+rY]&qu4cluG73_4L Ntthw=jsB**ӿօwC.o^=pfY7гbDc2zJ~@W{/ݫxA2KMՙHkn@c[V/U)BYB4ǯq߿í~ Є@^$xY$nylK"W0w&|Gos_Y(Y6D/6 );AVzNZS%#bf44}F _P:QVr]ޞJ虽=&z/Na_rr^-a7C"]i*QcoѣoײDZƱeufF@Sla.繪J<d+ 3iBh^`DY"*0AՁqجk-rD\1L;Lj.|vAqdƝoJR¢`|*YE5U1kkbܳ_8ĠN~R,`T-m.[g}aN (V3.#^&u{̣ODK46:>%MC"1 b)Jn92Ve di+:2IBKlә[O6Q\Eo.? K.kn;=Q|τ=mtIjfhMX@ ' 7[WmR_J39{t) FϕrU|S<8a!Ԛa>YTjL:cs@ešN+pz$3OLfAbO0^2q')'  [;xI#'?R(ǩX3 6ͮƁeF.151Br+5>R(w)"0`d4$\TZ1l&qӪ~r> OrjdRmJJMvxKHoaGX5p9nB~i3_ uW-e|)=^GfbezlXk}9z و޼=N7<pKNR< ${f#?U; OAde.QaU<m<4I|[Ԑ jk<<)!q\e%TPn)h]UBm?unX&Hץ6yjWPSx| s+% Pgm 1N.:4ʼ(>d[= 0Tfw"ܳ9mK{@aވx }kI+lkИ!Lt}0EoY6spȏ#3!·6D-^ze ]Q6 ͻ:}GT!V-1L ݊$ѱ5R, ܶlᜡ`NՇw"f&'zÿ-2E^_z"Zzjo N"ŝzk(Jk̤w"vnlF[:|z҅d1|,b_.L HyZ-ūB\fD[lrۦ@u^NlM!p]3hL&:7sBk:ذ{~7(mA 8H | @ ZAdM+ LL0sa^w^xW q UC6wދ"`|9*mBkIjp pTu\t?38b^d6T4ʷ@”)r\`d[[9s6w =~5M ѩ:։RPAp, *;`AAы&=3|i8p L&۹-Bǎ juZn" OM C-RDxU+AWΈ>)90׉g{rĥحLE!8X#:uy ;Uz.҂?BŽ"AbGm* ժR 2>W  i[aG0.<=(KN_ex =cH ό&^E{љB1m2rg@&m8&8u3wZx٠W}sĵmBF!L[ò-:KHߨEމ8֋x|*ǪK/Q*wf٬y:_.g=Xu)yiENrg^(9>C@M9r"UZkNcs\NX`tcsUT*/g6:g x×5|q%!#.Nœ)&LIVڲN dhVrܞIve$HO!Ou ט{#*-ʬ*cdV7AJ^RPkگ=:$wUh;ZV^L՟XjtNjt%ʻwTo @W|0D#),kO&00 酹u"K~sn)pA z$ `^T^z7^C *_ ų#iU(eU55vI\:a5ݼqXOK uHIJHd{3;n/r/rk ] t`.&䥜LrOD8@-#B1 #pw%]z$q`N̓3T[fTpWRv0Q)Tq>PFG,e$gߗ:[-fśؘt6 9&Q9h7@ Xkɑ܄23AXJ x VDnN\z. %&^1`6?"C;5ZlCQʑ<:, r! HJP[n+#&nQpRn& C(!Q·)6}Pmz„*s_KJh.7\i?)U*l %pt6nc 5$Hes`~F kЦSCVVBn[P1&0nXWݺYiAYYBΫ$l]+ wܢj-}"4ܰ PYsCcXx YPhMqLlE[?*.G| jdH{qM?[byMϣVhtj .ݱ޶P.+UGMskeLD}(F% )F7ØhsT,I;R5[X ='l1_ qRHbLܢQMg$ v$F;r?h;޶a*1m>UvfQxu!qͬϓ@)+rɔ-J-/%puum;gEN.gx_6k XxL4࣍i`K2cu: dYGWv*SdqC&3q'a &|j5#R?|ȓ^mH59|1?J:,Df @-T7)"]( fL)!GoZ8$-evR#!t8a',,£#p^Z}f3fAB KVA\K/W Nvi*3]JFZ3|b^&J@*['Ƭae)0+>{PW~bYLG&-GQ`r/qU;dKzȴK#ݖ:rzhuF,q˖/9/^Q>!\)$yAB9Oy2/>^|_Q뷌6鉕G5/?ۚwhja`]FKEpw2 ,ʱ?+na90]yqRv'[7\& ^aE A0TɁ-:wRj*'NMjX-a10FGgCyم$=)\ 1>MTϐ @ q<瓲sx:MJpBثrobfd28>]yG$YH!|Rp3 b$n ?7u 9Ք{+VV[1A:'`J v皿>9)ȶӹK (*I IMpkvE0]1϶VtU/ʁcOjsS"eUCviWk2 h樶1Fbc6L KsndZyb䇋3MRds?#g5.E{|`MLK:(-[,C5d40L;׏QqH-JTU B<߶8~JSrz9S#-bl0p#tJqP)y6g~SꑛMF5Jߵ-m1" _ԙBTbG%r#iU?ea3R$r:kbi =ViЃ˰*X$[Ma"IރhgH+>74t?A\zjO-? z\DΒuWoNzIo]cK@x[IC ~!֫m?$!uf)MOxτ.]')M`n8&1e 3J~:9@VRe<(\CDPe^i,,ycdG<"_#BpTڕ70Z)?(:ZOguY*_Kgv*GDb;d$ЫӪܺQBtKLv4F'g:03[)w{ONQTz }a !N m:^F|oT D-5çg^ɚrƁML8ta5E'X*NU$ cN%QrTe'Ϝd4H3_!P[xҰ#{Q^Y' ahWv#1n8My5# @9/5y|{ˉ\ʫXI*G*hX');q ؏P{3{J %,\s:C>m['d:E^#|XjPhvWLٯ>mP' x6.52 +SeNI~dO¶L)5X9⭮?jK3PTU}X(1P])Z7h0KHR_1p\[ L4Nrzf=Pe(I&A``Hev?5xm"hO dDt Jy9 8s3q3>UNIW>*Leusj(rlOR\F6= ̫3N_au%Dy {zutk͆T|?& Y}م#B_Y/떑,FEL|.pJߒ0v Ûu @9xY^/g@K;G$AxGgekھI0+)uF+PZnйeܡuX6ݤ778-g`|5VO)j싄><@B;mTKƍc8z,*2yȝLfգNtًذ[.u%o,5A^ҤCWé(x Gol"u$ wV+nZnDMȟV [DU#sj5uMMs* => 6\we'Ղ7|ܚ~ysjbbS&CAق4:unx ۰KG fsQChUiY/Q@c/w)rX*)xq_>)gH;T@H #> DeЕ _͂ DU*!agPdjbف Ԩjgl\#r H||-1)m,^AIM ả\ ̢4dZk$F&m 2&#r,tyYL%CX*MD`U^)1SeGK )΢k' guvaR^'4gnā zZx~NLmQ_!Gz 5@S'EEAڱ'̹tD-[UTniJp`R.U>Յ荋Ѷ4[ؓֆt)zb5}llbvZɜ^6}9guQۢ&s#sY³fT)F&T+_p@ܓθ6Ȓ4#:7~-a獗,FQ\{z7}Μ-,l'|oQpuONVJQ0j0n 2zG3u#Dy,ZNZ*ad=Ifz%HdA7s#iFMBjgO&(IFʔ~^YuʐPZp&[qސ6N`ʃS90$gQܔ>#2(6־4@H 8q(NSc=>UJ3 'N lEށGŝΎ đ=8L:;.Bҷ1>7,8Hht4R4޿g>/M:L@AZԩh-{8jzӍ#ޯ%XBW=VP^Ͻ.ī\[\1ÃRn! /H\؊avkbO0, 7n)CϭDpEFe)Wz°{>a҄¶ùwc'(T#Jk~ܯs5,'ҷ,ha9_L^N8cnԑ9$ Eq10oQJUI{A*p%/S%-rSCΗ۪=(u?$ ^xe`փ.M?icl!=U VR2k=85H^wpWfWd3v#AVKg؉,~ jp^ԅC%u\6OHrYD+,"4DIf?aZg++eZ3۬ $>~Vr%?qn Z9,VzGL|Ѕ3 <ց&WFjXe#NsOu$P+Bx'ym ҡ0 ([j1Ksd@:ù(eh/C91czh;0?A "ϳDuxődž3|߁7 kGG0.Q ODfV-ǩl8hUDەq-kثc |֖~E֝ȶѰ\TC`j!RQדP=ƵHBsmNC:R/ٻR%]Ū{PsP}G~4ݵ2RƓA? te_,&,H< ss ˻+7xVK#H~܎*f̢##4nx#-Q+R}2BAuΛr,Ug|9w^kZeyɫyfFH3[uxz{'\u?8{>qD=;Ab;ga.z#C=Lv\d֏Zr$=ps6[ဦIٷS! d%ziMv>76jT]S4aʊg1g_"5ezS^.l:~O2m9[$%Yn=qD蹤 e|5N׭V4u}esJr*p0 zhSWN98yCcCX1:w ,ra6XU{OcZ]/c.? Jb7 ϣ^Hnwl|s¡t=V7{Nrh&V+sIQ0!B y7Yةiڈd0}ϽˣFDzwY,`$ 4|?Q+#h0PAvMA ZraR JŁqEE: N|fG`dgHPG>BTEnS%O7r88ϫӧ[ "& R$K}6}KzsGݧ4Rz&;0R,cd/U\x5h܊Wjc>+z_m/uA]cJmE\OSHyG٢pBDaM?ۘBJdn-ѝ=?Oa,wdY m8;j=l7FG/"EmoMwhnH gK9jr\$>']$>4{ib゙;б[^l0=^C*W=tH`Ha_3_0&MGyoT͘/X핯!`&ua_auT)(Vl* oFO^[B.Jl5L(>]$E=^*M Rc1:DvCf##y,wn&z PWu*\sMx*]x!94 ynUt 9n`֞:pSE@p s6St/ݿEנ*{"J1d]bvq1e;gP J`V;M LPӊKYi-h'X}αAv;M3K8T@ywxs|4A=^+G ||\oB<-Gڪ;&1=Me(6:hNj{T|RGdLBy}s|§QR\rn 8Qy>fKRi~h#%CϠq= R\Z{Q*M V{͸]HNa&Q`'BEPa`@5m璟yHrZt C6ݥGTN@G LE*^H^P1 .IĽ-t%na1`KFF>! M`Q]!=8[kKcva;$O>YCB(&/0FƎx#XI,U(b=DR pfvK8*?Rq%>6rrF09+Y.Y<.bɦ5y\YHmukouqy8Xe@Cg]G˟яA&OtbTEx!BI=! 0!몂{j E(4g)/Y/h@=`.hq]Y|oaVCS]ωϙ#Ne7>>ƼǢ*B>G!]@1I˯,&V T#9=&c|Rn59-Mt 2L2lڴwFKhKq%[B?$)~~Y <NtnU / J4o6Gj:>7c؇`Mg}%KWN5yC:r[,UwǞV*SPRJDR،$-"SF_jBppeBX.<YWͦ-yde_/` upZa9Zc,CE/hYoVM lpL Pꁛ`N3@馷Q{A!ݣVI&~:2Bxlt!78'J̑* ' xß"sW s֊:ኰdz߰!u#jmE]#@*q:y=ʁ+,9|KiNx>Wهd3x;瀸\.bxV=Yk`=\✸ WCwđYGtN<{_Va5-(sہ]s+aXJ<6h羽R.*iQ[JEj5|?ۡmpx&@O#蚇읤7`;@( {*٠̯yے%h{hgl!jdW`0loF)mYֈ $UXcB ~y˃KյW=4;zt_rb@f|z92}_=|)zi"+zhJ X9|W_4t$N|I|Gr=dĚ˧ʒoEi&ʎe9zsVЬ3CF mv702wG=~! K2׬n 8է1ɨ"ni(|,:Auemw@qS8>=<}=@PP(Yt7w+=wI -]yƴ8ӆi$%K v!8$!]9\b&rtIeFt *68h "-7;VM`:R$z)\Cn,p񼉽:&NERQ@kC)RAc{PͨNFԕƲpܒgBqvxD,K;~  f{ڋ.Щ'rCl%NnN1iXQZѬ %nxIV:;:}I"K ,D=Ai@9.`34^,#mct-aI6:Mjm*ǢG,L&Ph»c@Bxͱ5Zq'-/pHoBqdN9mD=3>F&>Dv49 e؀j]n K,$G>amX`W ɴiݚ_UVDNmS*e!*hWq<F'HCEo /~mehND8:{7w j ^_\j!`Z;/uiks;j9sB$FANH1#Q[/BD>,8K@/x1~Tҡ }gq }Qq^, 59{2JE!_76"8FKVkuBٴ8U6б"Td0B fBn}1\oC|!ꑄU WB>hK?*|)V?hFsP:G4]>C?w^B^y|mcZSh/>#D)VNE*e^廢mUUPpu2頋1M@N `J*"T0lLr$7q. =.gXbKBkߝWKFco&2B0r I{(U!!%]nm.kA3ʒ9,thNqrb&ʁ!߭I5}mJ[>*xl-zD1d<<)BAk9mV*wh}4+CYc@Uܨg!N\ݑ^lJ^Yu>?ɚڗ-Ccvᘮ O7Aq~|.~ bD V& 0޳?iįySCGG|5RXru+ff@=71`5TMѻܪw8ԨLsӫo|K}1占؉KMMLWQlo?ޯMG!$bI46rCA)Hm >R0QhqfRҥaMպ~CRwH֡[ϿcŒPcMen`nNtG,ERѵD3(= G1꿆ÜWUU TP]. Aoy Ҹn2yXVHy.3.'O v'.V+ol oYWT ^ffSj.X8+g4qHyuبR6{-6|i߀EP_!7ru{nr2K!UNz)?{Dg,W +VK^L).^mlPm#b`Zpz|A:ݐʶJkke*ؕ6+9HMlg©uM2N8&tJ%o|M ~cȍٯد7؟`~bˆVVA_?*/9]\^-PovPQO6f̽CʔB(3Q e,\r&67@U" ~u'_:%i)^"C${i};yn!EJRGWW_,UIn SY}WU0Ic<MP'd4yz쎚~74bE3K/{ETLyw㌊@-r6"D+ֺE.mVc_׭+FJ$(-Ol 7_lC2;[VQ`b48 ޸xqn#qJFQUkx(#43+d3Ф;2Q~5y] IB )ۦ9<̼*ߧ)AAd<]mtlv_u>PF8~ ϖ#֖QrǴe79UP`c=u 1U:r h9fPź$ =糀[;4'iP`}Coz="jVq,'R*MYU:dU!y>B{Pfޢb:ʦr)=2X՛$8];!84wzFndMi2ꒇ^ V[@H+S=B-\ʫStc 1Kc/m<.y߫A9cEb(7v/a=2V?Ηf+`h v8AQ8Dt>hyb8X^\9ŭSq'nx&l]RBbFG?wi5YyyT?Bxh%a~DpX8}NLoJLҋ2M{{ד<36M_څ ji_#z{>mOk㖾,;AFGIQntk+hua#ľ^vQytT `ن0#60/){VgB9΅aaV[. )݊|^D1}d01͐&^;a=\rOY eє)跖v&q5G vvˏBv5uigb(FJYa_kP:6 VA%Z ^^$!RYy=4څiz!1X{Jp gçvTg[VJAMx %_\0tڐf,E?uo6ʗk,A]&!" 79ڶ~+m';#Kx5_+xĀu m%FNjȝr+Kf5w'm b%7-V xQ6='A`-otN.,7};CI+#&Y{"2 hMOcH -,[:v=Ӆ7ejjE$*R"!b쌙]L!L| 'չԶ˛?䗟4%*|*(iyȣ!_]]Q҂F|ٲӑ$p Js;9﮻|ߥ >̃cb2<᧵P eu3gL]"5׼,ې+椂<ȅ-6N1Yjd(y'f~Y8՜V}L𦈤Ъ z_4XjbO6yeH-\ėu:(ָbY%I(d>׷k[0 q;&t9^NDBm 4svekZ.f[MyuP>;Α< E쓻&tw:S>O!0g+g#"ci yb|G&rj$SͭOT+⏼3}Ɏ0Q~,#vc.svշ%R fh2}OEVȧ9}OȻ53}`Ul+_7F7O)/Ѥ8_Y &=5IZDrS3ӕ-UA nF])&?X#É#}m*Y=6"-zJZԚA!,6p1G!~Tp4vz %g%!rMPXܻԝ k#Μ֣]: JFj%VD{J^/#a9Zp٧2-+KQ$+[iybD (H^C$(pn , 0(oC4 Rs jqztNg])qŝn6’Unηv}.2Ҳq '14;I9rXMO .M;v9A7X1yvC<W)c] 2aj?:_,HX7못-H'(}ƫifCtpS٩SAPI|Zjt =Ll\v݃X~a89ٔiZfi_qOESĿӘuwBTe=JM.mUo,Ys[?VW@0rM)>?^]zERNܴ[DEtX;0zp̟ .P~#jdžbxN]V|c^NMtYFpefO8[nA]K=/VH!a/%M 혰aŝh!5WP\Wc%vemcs߆*r)%)cP6$۲PMWYXi*bϮcCuib NΤ^H'KH ϖ-j׆TZTuz,Q-* &|h%ؚZΆN2t0+ *qćc[1J&Y_JĖ;3ݣgH$@>"1I=\Э RNGqƸpףJpa= :{H h٦%i7}|{=k$X_cwH\Bi Eck}WPJ`Qd(pmݚ;r P-~R<)4c`j'` QSUu%5H{A/%L ɰ#X3 ՙW;Y<8rT>gMxvj_5suCAG75 Yi`dG\-K[]i<]}e~(O.4l\8BgЄquD߫ӯvC+5vZo2(>~E^lo)gg{7ꄣt"z;\\A/jWZ Vu3əi_O3aA q>"v^[/hBHg<%uL(8`&V^y>8F(5\;Q 8KG f-ϸH ,C |Ftxn߾1ɕdu_{ilJ=-(!@RXqī=hva_պ#;vB8nFnEY}m̬CDei![[%lT2;f_m֜Ћ6Ozc7ޔq1 Z1C,2"aZi nڌ$Je?7o$z\ː:nPUZΤEKc4aL9w jۗ7_eAĒmEױj_&; W@; f3z.J NB-~dk[Cʊ sNMM]+KZ[o76~Ʃg[:XzTF'Xr r"xH/NKh8eY41VC ż$lo0M61q[>NƝzJ|bkgaO`rh1̦e6 6)+WQ>)%\= s Y<鼹!Cpp\^)Q^f)ar$b"\XD߲%%ORFk1DfOdI}jXD2kHfg&eL!e)HIUi7ͫGʺWu' CĎ@'&C4j P\6ۍ9Ce,l?f}8f'=K0 uݫSXJh3D2$=KES?l.$wL.nhGnHҥEٜ[q)bvVX$:$`V'e =uEQΫ@Qt-U8y5pG?F9Y'/7MH+P*HE6pm {jfs[u]ɍ[29>,OCQqFTmj\ #r_BZKVZ_K`/@;f>RV0TT! s}=WE1@sןU*L9׹˃:Dg@~ZRԨ#1hpyzʶ-}U\,zw@mNX\125~/ĴlJq}9*g1x2N|cajC6dfJoHcEH3Wdd}3y73i v0Fr m[eׯbY*SEo4"a׃^N.T0ue~61;#r)5.% rNDA ɑgd#yO1-.v8n#h:m@C2k5{}P)gͫV\cY/&=5Lm@Ƞi%KEGB͓nG]bq_Jx(GγuL0ʵ&C7]@8|nܺyH8yG3}Top66]֢R}z[-Q`*nm=׮dHR'*֔RM x}5\ߒ4;U*/ma(.W?7 6H烓8l.]!e .z饜P3,JU]\M5PNe'e=GZYN@[Ӝ '7cN"REώzyU(Z+ip/.1&94b>FȶԥT{;BNdE)%Ѹ4g(ma1<d4\[>cq祣.h ŗf1^/~N-t{{ j)B؈ߘ(~8W0+qdy@xdj1!)B+6Wޗ<JLjYZe;u>ۋ>i u{_*E!TEi\ุDz`(kɡF˰vŔ VHɞ ;?S&kprBad2Q58ˆZtAg=FgwdaaZ#Pؚ"A*ě&~)_#!;|3 J<;l+],lW{`»K2&Lmȏ usB@ >.8C'`ǀ EuՈ𒪵|mٙ8I DV F=; n(d؍{"Ɉ6$Ú =&Pl%'7ޕ0XtWCnzO7Ucž נ&%*5FR+N|OoC^8c*KPSaUP_i*r2^jjD-QSswѦ2ЁFg Ze[?:bqR.l-D 1C1S"ZLl4:Ov{uP T*Ʋ(P  kGqpErMSYQU8>z!@nz-n)7g BT>-((OWj ]/uq3q)?:"Ͼn=$$x[D28` g$SMW(p Z,qgKM*ߑ<{.v3o xgi)ALU36X3_'n[žhR=މ-zF/@hZv΅!` 3_6s}Lw`/?RtY84 3ޮτXmJD+Y >ѐsM&(G76`j/|bihT1 9 K/-iRVw YU~}Vi. f`PU(E%Q/MWZf\ݹɨWx_R|PLZyAʶT3^ F93Xv$\ pyLF5;~LljVvw7LS ="W] @СA ~u^(P'ͯ%~ftO7rE(d]^I= <`UO_0&u` SJTۧ#Kui'AY 1j &LaX(/!sX7оϔn lV I@L6Y|f-vu u *Μ8Dg&l>OG \ZT_p欣lKϡy;ˮD hu ?>c1Gxy+nqvJj䄂B:cm 6"tWdkCA!*P愰x-ޙ} _u)hUB*l|;D~% 6b -:TKzL2 \Pj҂,k* ` rzrg iңDŲVqA,u䓍{U?&5M-r_28bqC}|TP4>W-6u|* 8j=p~۟YׂgJªO`tп gp\M==i+Fsl9:'d=_%tQY#!3&ҩ Ym6s|NQ'`w#(Wq LY'zx2# doorn%2W9avX{̇/~k6fV0LK>uIsaxa/bc41Ap8)l0@lD5.["!MJ^1vaNצ9L_J}y es̽e~qI༢zgyle?&no/W+~=7'%Fۨ:;+T SlԖ0xѹ pWo4;ї ۤuA6aY>n$DnSo=?JR=?>־_j~H% rՃScv2)ZS|œ=l cp4`=`l1?[Ʈf*5 Mq<7FP<T ڡnw u%F;~ 9ؿyg1R˷|mlY6&w\N3.R$o}W{mn28|뽷?[mj7Kh6,o@A , lfhVå<=iˠ&!Y]!((@eqHh,bE9CZfw&kV03˸n>0vǜTٜ,},<ɇE}얱:WK[y a'@t૩˙#ڌ :&vkBF"@RۃELA-֍/-ʴXM 'E͖DݖX~~Nu!U"@60KnD({ bS}Jik^ˁd)XZnH vԔλb6 s@ʨN`z` sac.9%^ԭ8w5x$SgϳKiQ+=iZbT/kc:%刴} BKnjVv2OyFE=LysN O[Q OhN{asߪ[NҮ"uenB.e 'V^-b}!9XpX3 R[Qf^NG*qXe0ښ=Yɑ҈#I $V۟F4ʔ>^v(`'Ѯp*0 #c?_j6A`z Zr etVPْ)!9[ ]1tCtI .g+/Dh20&.`8QIGR..`6)#otvJ6k9m*OMpI:1v8% m8;,irycu'%+U64-#}LCOƤ!@@L- K7s~ [XX`r'5hY&AC|5fVRe<_n[r ޸,W_Q PH@DڲwgGk㓙q9nbsrS7t=뽳Ij;ќ8qK*uH҆mzwx2eq2k#Ѐpt%TtePJ$̹\ hU'h_S2?~GF (i/7 fmQr ,.R:ZFێWV]h 8<}pŤ@II>49k'il pbfdQ`ӥJFDk6K%-!Ȏ&2Lyț2dj)(BA`stpzSq;0}< 1ٌTWYhZtO^AZX< 4 ^^%,aXz؄3K2'*d&G~Xt0-v9ԯTNjG@ׇ5N%˨h,v9"|8Nx|V &:~OƄ}m "oǵ%'-ļCL( W]+{4z)i$f \ƺ!oyVZBpeW4o#ed8F! "]yg`v5^ij8M-+F="tՂ4rF=kkxZv.NM#Gco/~=jW3[d;,hOQEM;{SE5H#}H'4UTpf7H/f-yX|Ww0i+mVGP\ڳ7YHd{c0@#խ1b4mʂRQٟ`,gH:MJ͂D(˦7Qlig8leX!Ocȗ0~QW%`\GZmْ kMokb*4h<z-s~4h9%׆L]sbg Zġo}o;X-AO2 X뷳:<׻o{B'Wi)wkf'N)[D;r^,847 Tt@gE%t:G?ܔz;1E[4N P3B,gmy i7Ͻ=qDU#]|Vo4zqݣءE[?Yd2SzB_ bU-˹P{ ˋgr~xRh-: }( /y@ҴLep}>V#*ʸ2mY!/Й՘/H7s(e; FDtrTQ\}mSaK^gn,HXM.@O^~Vx dSBg qm3B>!QG<*)l-OtHZzߚk&@5g;p%0s9E^` WD;Hຄl:ա6Q뺮9L-2h,0 bs>v*;on eB.A9A,,to=fG5L]la=jrԹwG[K!9x % M$mq3 `7n$e饫م}EN=bG}BQkuK|+ z)c#/C0Cb#ݛ(} [a}=^ڱ ]}(O=S`rɕ^sv[$8`!3ŬGYq]T4sёp:9v4By"{]ĈF4:AavUH~!eeC9<2ʣg8Z@E<7l$ l&DC;R،덝$*{ lU O~ ŷNT@ jbb[5-HH]~w_;$W 6ڿ"0d#ZKsAèwfYmϫ>jrfyϛVR<=)R.iK/8O(/Ms-p3_@IfunBSf%w/3A jK=];zoHh-Y+hopDx\91^3FoF%l1S`p +3?Ķ3LDJ't0E0Ͽޙ^oQomigdCgCVс"0ط#@8O-$BC-/z,XUbVp 5'O^1¶~iBx\Ϣ8jg Oj;E%Z3`>υN@@z22|O>>ûh~+M|Pkcr8".ֲ#c Hh&]A#Yvspņ3 y%-HiJ>\3B%astlC3 P~Ά5 %1q*ur;! %#yqs}2pdtz!g[ϸi{ `u{0L6 `@ɢG'\.e –B6L6Rzn_h4{T6#R8EW4eM12ۈ3"&R!2\p5:vƟeO]vHI֕y>[Q+7a}d]Ǔ(غyr\p@6(AžlUyo;jG{r{6|xtF!³lu#Ʉ$a ,CZuw9tbQ$[2HF藋waw5~rwxg郯L)nGs(tGpɎlh 1" =Ht`s_]Z" M*csh~pӾ|N&jKCrJF̈́a3!/IE Nz1 XԎ .k:]^|w|W,9҈$;+僰̕yX"D{JJ5o<ˣlM3T'4*9uc%G >w-=dza7cjrn?-VLc\}@mڢǩs~7rG_X;^4mJ9#6񪨷X2 ˁyyzTk%F#")Nxl}}O ^%B@Tle>>-?*Yxm:yf{V:Jqs41M^WMVWg%ZuU^MWwD¶~ASQodoUw31Fc]j\,BdCljWZ^m 1ABT}A6犦xkrBjRv[$,ew&6 KDH>:D X? g@Vab5hqF)48 ~̌`5R+j&0j^l\Zbo:ot5s&/m88~MyjA*ۃy\G5LlX#aÍ%tC5O[nZŋ${,,3۽5)gkIƉ]N3Gz&~ĕFu-Q0־eBwJY+K_-Gg;tҺ$Q1TNJf(! n\p(Np\h} s6hi_{I=kO=@`@:*O5G.I cwCYV-8ۆ~EUtRql3鉡&dmz)oJ@tUR7P<ocgf*(q;4?.g_|NᴭM%9ԛdSe.p?ΉZ%S٣kJ w )EtQZ%MFrR{a/.}f`~A(&aI.(Dں56C$2.!@BqfBtFFG %xaޕ\)'._uPkz`ye)](َb 7 ӱ>k#)CŇٳ 8 vn6X3,%܄v:>d܇M+{R|xPmydboQ5WW*^=m2;&gRX8/@ݖF-Q<'Mvʶгٽ}5@("C gByz<[e-(yw Y4ur?R;ר7޽,];- +܃Őp`MϓH ~rTQaY4Jhы`P?Qv( yY<*=선mZdɷY W %;dž)buFho03XIU`]^Pj[_89Rkb[;Unr `w& 3FTy߰QM ǤE1)2 猽|i` ҫVap#(N-:$j䂁Zyc "KpnOdsʼntcw IFE"@>N5[BP[1w1PL1u*N4Qo58ߙZ!+nxj+_ ,'#y7:م[Yn|roZ*=' "[e$ˇi3z G"6l%^$z=Q"xd]d!ShfL.=IEgG$dfDfT_XWrEi|ʞ#T,$wKc=sTU*}{j$K-g&bmP;X+Pms?@=ZuS03L[;HI2hPmoz}AWoM pc9ƸuCqK^oXM+bTsqi.U yƑCY7x >Jk?WtC3{kz91TidzRZY/"fB~Bs@a&FI{U9` Z\w9;QɆ{B?t2`JVxv`dUM'bوRZON. C!(RJ2Goۺ;r L @mI䍴tl PCYj<ʠ֊WҞ{l,BI,۰R4R<.<1+g|b1޻pN>5 I/ ` )2P92_]Ŀt?pLM\r}c4Q{Terb:bh)h[HPd#h SOTN=W$cֲVe1Zknγ1%5~hh`|D9kQ9q9_q}qw@#}O'_L=dḳUPA]=n RFX'\aNrPZkW 8[4n0[HG;<_uT[PuB3%G-~NfN֓%ʆRP(yٵVY^pCwx~pmRb^V_!pZ!<:KQ!{`<[oelp-ځ|d`|ޡַqEVz0D."{qTPF/)kY9YNeKnlgO27թf *'IW_uNy !6zGҶ1Q0 e5w,Ko[sAK;Z uCT!tѠrYN _O*ZZ*S:#*M|WU7;+z0|rÙB`Ljq 幥)=ø3@%+d)$dc3Gxv8IT7쩻",{^۴GcgsnExsAn勆M M c}k)jVL pmg߁݅AtJd)>mܝ:;k(kGaęC;|gSnm7F7.d<0_,(`ipwNY㊎5f_䝪ū ~I(kD"d8\$XP|(B9Ak @3]uP$*ue} ]솆Wp=m=Sa{ȼp mNmF$JHk)N!<~ #}jMUh{d(I%xZ E!IMdM,>1:Q&n &`ޠ =klB%o-^9#tO:g!>N8q0h Xq2g"Q?!&6ud-cYO5`m]d{wQmas\`}<߉cRʄ іO<19hs sx( BPf_2? s<߲U;Z_T#t}Hm{xlɘ1]lN BS &1Gqs'B ~o;|QIskS {&‹uR [~<:iPnۮ &EӾU':P%ÍrwVuV>|@}:rA ʵ5|z*xQ-fªu6{AX8>yr9ai@V߾Bƻ#Nd֑*iv@>S83YUm'*|6Y5YN(m*wfӢ[t$iH qc\?vqe$t"` ozqČO73bJD 佣 :؞ANyٛdK+4} 㽭B1V3L4K% : i]qQCvh  ?z|GԁY!Bn3jwgVHŢ5d9 19dLQ YKslRX' C{dz~=E ;}Uռ8M_u<8~;pKkdEu#%.\ljR<܍ 1X0C З,v0+ ޞB!Vo0& ҁk$#I'e' N-1\r>GUb ihhJvdW힦gxOmR몗Y8d>ih^@]Bu NGT{ .;tzj ON[Rrٰ :qmsa tҠ?مqǣlZ#D {g%Q 9yW~rI$M0iymv\6燑hXnk߳2洛ndBYWiKgy% Viz^V;.fwMfjmY+eHg1"֘omS9rH?q kd2d0g422{"2@) !c'{ DŽeP9bv6{M!㋧Oaba1R%_͆J!mDj9qvhW;b>zw0~*v]?7+U&).Jy5ZL MR)*Ws芮&Cs+mƄ%/9ʳRW]4R<.;eT%ԅxQDD "e}2toN'd\wX'x;~/V+>Xm-40b,RG#kfY"8(zMC\FtRAʋ z` (j%/ި=}$7̀ 7qȄXov)Bg@I(=&i 0:ng0qFp{"L*}Gr|,<lZ AJ'P?]q{`ejw[HR]vOMԈأ9] b9Yb{ 8zqݓB֌ VEg\B]`t/c} d՗nڄ&ա:ֱ;ccA':1#tn4;g %0A()':qߨ78!)@/3rpt>=$7pKl?sy{=Nۢ%,{jB'\1N$W-Pk(pdž+uG:2>.le]+M+`|Lʹrz'y,B1!b6%#La)m1Mj,jnF 7.g­׹Q]h`Lz†i2PV*Tq-DH!pcbzd1-,^eV 9>TJӨ?] x{/ wCe-sXQETn ~+lӳ2oM` a/œ.AYkʴ⏳]]=`M H[0Ϲ}Hw[=7$=_kIiU[+CFo7d 9۞9b8<ۏ=$=Zڦ!#d'&Qa;'}vAf*` LK9m"S~w|I 4m.[| ev W;'6Fimԩ"(:fH:'Ћoce< 1%[nuyAW"FRU%/̒婥+V42yRc g84geDp:xi2`Fe\3$a'icDK\k)e>!Py2`yUY b rE*F*u0 ,I Auo'H:e.q lFZLf:JZ^qc̻"d;tcxӲ+qeG\5u4˖A5%c^ (6q&!W G&(e. Zq!, 92$ _eDc/k Jc߅K*썶 e;x+/CaqnhùN">m^L$rSޤ4$h?ghB"֊)9ιbh n٣~\ISV=$gEy3?E' cb[ik ?Nq/P{$.v<>#n ;'Cl/kdޑ΄jg6];bOBOPHZ Ĝ6_TZ_+̋-EZYUhd%,J!#YI… l#gE D7xt^ʉi.U #->Ji~,'9tg(c]3 @B/bF.3 ךedÿlub>ѹ5{n(O} /DCe;*-e4N r Aqr NkWkP[<:z8| 5E<.:b[+X|urXr#|:E"m{h RV@WT@, o2v³ө n(h0[ZsHpjmJ<|Z=afɬ|IYY[--kdB_?en*Ɂ^gB SjB{gq(X01Bwp6صRdjGjT8\NIriѨ}n`R~oZQ㊚ A;!m'ya^0Jtx#(`r$w$ىıp 1m^ml=%$( CHC ^ N uJȁcK[bP 3+"3l>7 ^Fd?+km>r\KzDT zQ3a]f}>^%(M K%˴Ez.%6#_Wu`f?XWڃ(5 vW708q?Y߶rJ3x7 ^"rvՊQe_Cv/CigW9pN0ƴ)M[L?3xph+$oh;8aahxNfӜHEnaY}OV[;nhAUz;&XFwx,"c?oﷇDG5we.ߙ1p@&gfZzZ0Q>Z]s(YY+I]`OױF&~>,Y/ˢC߄uaH&HBx[%B!hu؆k /OLAOZ*zzkQ'-}+w!kM.h`Ihsd+΃yRA ҥ=,1Z \oOAFv1(XՄYejLӸE*P1#DCB]Vj=u_q6 Gmcp W ?}gimzRWɥH$w[[ ؽj!h-*V UWo4=PBiVBRV^b(`$!AYY󙦆ʦڨjʞCF2?4r&wHoiÉL*?A  ͨCW1 $1*lѭ h/|}3]{{icVTҿ~u1f}F.CK"G5*v~,P썐ȭ:(wWgc)G5?bi;G.v0;TexӶ7(AbGy /l{]wU$}kKvN$E޶'t>Į(PIYÒy^yD__'Ȣ0*EV2ܱClW@<5%4q#W7Hh]_L$9^ЦHc"!tfې`D=a~_f6 Ě5XR^>ՁÁ,7j4|)t$F\Z9YaQ΂ _6˘礪T5+h7T>|FQ%?\w@n'=9(zqI uyxiư I3r^a?\u¦ MD\`$9{aȋ❻<ۄNg(iȭ_{(n;*?0uSQW;,&[B44 : WL,,uԟ,N{#)RvrNxŸۈ=6gpPY1kWL y5=r&Z_em'O0Hț'dHY᜔;T)WlEIp@ڠfm0]hR"_r`}Qwe$sسIJ(]]ѣN-aԏ!Q&xmK@c)BܭRSe\ *5 r)u1ND,W$L'AI|@3c%-2[H5$`Iz'<OyGUC1Ҏ?1T^%;ߋ:u;3ڸtlz_LaOx@0 ۿH靟 GyGR>7)T~L,p:|~>@̟~،Q5򝄼!u# {Q9Uj7{gQ\HB%: 96B?:o8(ٝv -E!Wg%݈QO zrsgWڞF4< ed(dR_u f,!vuTFx/$@3q9D'sLBA,ɑA3M A_%4v֛hE?}k]!oVM/ Vl 8.?@r-j5ݘ78ܖo@\?wQǀ`DhQ텆ځs://lT߱Z ¯7R=:V` 6^kuc, |/$k| =6$&6M Y?&7 ./^/ZCy,+G=AwD9sbʱZ.Zenuct!K۲e-cdvL#9slkou\kO>nաpqf%@{վC",ZElrd!hٿxD(ɇA| !`VQ-d(z$QA~P1JI6i}2M o=Fr>zm'2W?<7.g &XM`^\RL!e}D0fu+?V+MqX:%-Gn⃣XrS~n "s y!Lc Ou\gkM-)vF:D8iP\CjNEHZwNF `/&AF21.l|AB R$/:5ռu3>Tv=0!4>($͛ybqm{.< k>Gcf*TS̓KS%eb3,;]|,/ar+UAPC 2-rM„ے6@Ma㏓D)^ dOw`7Er@< )5,3Ђd;yiDB $83nʫC Ed?CTtl-#Vck< d_۸L9ԧOgSb"ta{=hΥόRLx>&qgF5`0[1WJ"\bS&V#ߥ ~얅6mYmҪ(",н ߍs4W nL-k|~`n."w 8=mS6GQK=b+lF.WZ ^9 /T6W\pd,b`gZ`ذz{td džM;&k .Juԧ2|=(wyjjf~D_>^ZC.V}vn50nF䤜\s3dX| %S!ު.Ro> uhDmuAe WTTj/MU*{M+ީX9O5SBM zZ k0uGq=ů> =qy%c3h.,!|_Ob]`FMX7lXǼF4EǏj6  is}ʉkcziiFƨ1ǚs(Nwy˟]BѱR;;SL&h3L.2ql _ 0hJTQ*6rE8LX6L ޔSw wzs8'q*EFFp`:XʃVؐ{õ 4 o" )RY諍Eƿ)rkv.=ҧ+٪r <;-~ß@m +݋XKBdŦttETS(gy#L|P_WNf2jه?Mޛ; Zy mz?ű.;K5Z[f,[ZɕHq;[?޲!锈={:݉(v g^N8VMatS&9]O_"mڢ*RFئŞ7>!C\NEpfY**ն˶X52+wʁ(+K2 |#M8'{{2YٚIhwM&\,ڔxCwT)`<)&r'ğxkw3*zrZدn|r=N.)j`@Liڠ{3VM-ld9̞1%ޡ%nvejǻӳh_= FRݐח85 9U!at8Ȕ*#Q_(T$%Jv V8;"CvA[*~!*n;F2lUG*$v'_% n # !X]oeip-ˆ O!;SFnsz *:QZaqCH?γy W;K9:9 jr t="2XsqP=/ ;=7;BC)*8*0/-OmЭvzB 5lqJRwG h*+ -;I JJtw9gy4B͉ JB9 "S3ZBG Zk;E. uZ>|ɛp/]Wؕ]1&sِ1rq9%^vY9._5RxD_sk7Aal1ksec>!|z5oN p-E0d%ʓ7@afSp .nDB ]n]f9q[Y" GE+LC@;A y~x,kof)&(s'ٱpJMt,$lSqMU/_`qZbbѴEk$>׉)!QS,U'wc-?|L_ϼlvNQݡlˀ />;9eP*17Նlr~[Ms%gYy#tC'j=7nwd#ec!a| -^gtl07 ru&9(wоQ#o 'Ҧ_ *WHrWAp&IRvJ lk#}6競@<ɶxX[FfPm{̩G+yOKGrV<`![~VCxvx8ofnπ"WP>me'vjn^ԁ2fzf> w}@;޲Ur0:@QNdbkc}a_?|nP}iڠdas*?ei/? [+ufQ[G|Hp-EF#bjJ{0715Sȸ %X-ߺ2[Հn/d=i̵(/o%9]KH'x;޽k;'E:!U"3݃}oxD̍: fj3QFc T*tςtzX#ߝ)}h1%J=7DbxELк s:=H5" B*SvH*胻1kCĠi ޟ}>3X;(jdZ#ܒ87gI޷y}(R ״Vm>w,+T)n/T? 5UtcWSIL)G4{e-8.Խ6=ܧQY#ϋ~k ;XK؀s_u7D,r0 ^>8ze+q)i(sNq/?%{'zn_*vIQeL2kKcl22@nܹX-t*Zx3Vՠ_wŸ=Ԉ!\m2|5Ww&8E"1iδ,;zg;=ta=#BC ~e*蝳eBKt6_>F\cuu:.>xBnx Ӊ3R4)fEPٸ]sRW+nw(ڄʵ=AG; KYÛ;s2hN~uYUuwHS~ 9$/#(2BKbܕRl,ÜdHށޞx0o9@ ,<[S- !$)]yaKn^tkhX?oӵxk-GF . ծd6'nqQD@HEw#ܜXm9IW#^1{bb03yJn8g D0(/0wfrZ+HE?ӑe:Cj,$j!nG*mѿM\A~;TZfj<S2:; #%Xv׳j Xdepnlc|mv[Уi|hDFa{1Pܞ}TOMd+ u*ɤ5, mƓCSCqH%؆-'BYTbahMSp50^<ݭeElߒ*+Y`:Zے=jpE̟̿z7<߸JsjzHΑͰgfv %i\lcvVeܘY?hČitBb/-~i:hSQv%0~7{(Ĉ\ {%v$RnxoGi#n "!XΠSx6U٬*9aVN9UC)ȵ17YSRXI-׭ARd~\.%cp|m70UJHgSbbM i=Npi}KRf.#Jmf /Mh@`jW,bF7SH .&CLB8Vhx𪠞G)TaӺVJQS 㪙JЧִ̖ci?o)>nnC=ށ@^d$HKݯ=!k&O֢ ?NnpvPVC+9=W`:dS%mU&[‡jU,6*(;/>KZTh5.g؄55gA]xےj~~HMgV$EB"Q "(d%Gu|xcid^SGS1MզGkΛڟʞM9M] n>6AMeJ#+x92Jh\ȉLqڢ*n{ Rlw3 wTcX4kkQcKwX3BYL[Q8%2;\Fc܂-lG0}ص_pLbjdJ$^"^#&6Z'A۲ىrS[bNjJC@,&kУg%Y~IL#HE<Ҭk%XpL4w:}DGzXQPgZ_^ƗP&6R_N*7SDjTf}%'pזg+<&Û(~>ygH8LS*Y5m" n>9^LP0? mQ) +񬍁/?T.J_I1N2X۠i6e.̢m,cP[ف4jA -ҨwQ:|gTk+%TC@-Rt̼}=A$pvv[n:>X eU&<[:dQH q{ƙ6$[>ʍsV϶=Jc|WV} t-1'Uo+iֽt攥 pZC*2{eFf:_%2Wvm Z>mh~PLR <.*8ƚgk8%j&F\YzaKnASRM˭&N<ܳ-~.aoNDa$3 v4S>`HlUTӌ0c-X'I^V>@Z7Q=.$R#Ni g3Z])Γ0/Ɖ#=|Gϛ 5SŮs0P8a=ߔѽ_1VJQIg$+9n-@+:Q4B<eu 7{ϖCTQA "ȳсTLqtUD2*%[-X1;E` ZGS?{L$պ7gnڑZ:a]}y@=Tq r ^M kēQYT1&wT{՝'[{XJ3=&Yzl?G(tOS#L•4c[z ZŸ$e3oK륦j1=+ WCمCH &V5|=L w_G.!k3ΒY`2@y0}P'KΓQ~-cL6=Moˏ?"sbcZD>{FkRBpQ{&#t~0E f|F(-$ֲኻOJxZ7gYlBW<ƀ!g)(WUHYc[X@U1#n5 U奿5链-SڥzNO ÍU(0voV(;B"ƈZ>]  qQ+ 9TFûG 7G`a=|z)s|=*Rle+-JƗ^5 u>`RhF][cLhFv'*vY愓A8Mq QªHOqHgs{i Emv"[91vb^kitH.WqXc׮B NS^ל-E8 gcM,75aH9SNʮȶD6S1ٰğ2VZNOO%Ru2Y^Mz]K-CN4&ޠ˖Y.hBiv6-ͮDsMG֜ +̯ݠ?׽iWn1`20$=Sý Saag`52jjgg.8A #}+\VUx=ǢqqffS ᜾f80"L7aLuq9r pqF+8  ~صb;=N0}gz`jr#;Iޭڠ?.`Bq@hZ"hLx2gJ ƫsl4݃ێJQ5/1MX>bu t5Z~i6=Ij3Ѫ]}tA {X.fjR-}WC5K7S60`ZR,\ nyt7StP0kqf^.@_kv_bl~R{ޤ3Pov6ݾkUEK[%Sfu|2sg%ҮR!9o~SvR:7pKr!E' oQ"d{fƇ,<扡?4bcVkt<)D"Q2=O&⺅uk'?W/2#h}c2륆rv>r[ n2 $3Sp':*2c%W<7CaHw#p! CByt!RY7 渮[0ko_ጊ@Q{8SÙav//Y ̋fWƒ"%R=w#R O:,֋C}@phsc#:bƹ Z |%w7ŗY%و:]XW +H~-rP!wr , G :ؙŤ&I%WJŢ_[ 6@#F[BšUFW??xIj0VaFd ;ybribZJ6\dE [=j-:c1Ȑ1 i^ܭLx(QK._ҽ! GikC{H~/:]v Cr}ՊXq:X(优t2cKgbs q~8 V!j.wk{OںB=_HO+ВP* GE7r4qLR x^+Zɹi8@,9sIgF5'ї̤+mK_f<(q-Ҩ5AuCV,8UdBuڂrNd͇"f:/eʓP@:UJDاٙLm#8H Ge)ȉCºKZe3:67N9[A_te"{:-L[rD:2瘕) ;QȽSHjԁwIh-u(~5NmŦ Yw f[w*yw AqPEzizgO+̴(q&8"x'Sp١X 1OJL*g1P/!'wϷI8١7HF{gCF MycZ^w1/`$҇DVQj#閝5 %X8ia_ɑlcocљA=%`:bV  2a I,3l*Ah4֛vVNJ :@{l2w.H*()1QDo6@|̵퓐greYx 5SYpq ~ҎZ|D 0g'Fh{_Z ieA0b |E<2Mi>s:i/ `U;aAM!SHۡ< ?BBDTRzm.ŇꠠrzخD_qfg+F~ѹ_Kov7aH] ¨4$//^_`}сbFW02^őcN5ZZ cBVk<*N;t#㙿!` mr#/rVTra V՝ρy 3͜(#d<1kl&s[ݧ-xvaK)|*heZ Lv](F)o,D02J3\ԉ2] _b}]SȪw/ h?ɭ@tB~Zk B])wLuG (-T*i]P m-|˦%#$uPr󙒒/rGvd)_$MD2[GsG-?n*~;|__EA{ӕll>5B!W3Nꗯ`_ֲ~SLZ#YmTA$Ά= BZHHi܁–+:$S?L] 4TIk1\2'ʨI?koa't=nnUü7qF׋bR\t O'pJ97^݀00N $ 9LH$,w)u RvB٭$"tX!sg"Ew.bKxxZI>]YfM?~YB5N$fEcd|'y^M5E̐W~d@QcsXS}QB sVi /ekk֗p4^l9l`Yy{I^Թ}y9;ne$h]sN:Fxle9Ԝ3!Sm?'\+#5c y_ًLσ!8E4Z2.ialBW(Oqܒ8 +J؋WBHeyxi9NPSHh2R0č;:>O3R uv'saaP2wnk#3j!:r%`&AOT: ج̐ ^R+PT)i]B5[# LQȋ4p L՝46uC@OpXm,tzh°l7+ZN&HZ8*WVb"OMݯ Őo2z­& R%X7FYU86 @i`bE􄁾G ̷VA*T8YYoOe%r`ہ^Sg^8BO%ou h3 ?"b"V qDMF#eX$;ܐ8w sJDdGV7a˸Fa.6wm`@(\vAMjòߩHɒ*)LX\X#tKs[3Ą+dA$Fj2Hrz*0GZp͆v ~֧}gݣ>C\|wũ޿!lMA1(%9tje*bw _u0ì&鷊*KT0,o?tsiqEr!1]qA5GX66xFc`MD>r9a 늢9-yɮO>PfWKӈSAd4};T" 󿚕7v -u,Y=kj7 &~YpV9Cd Hm_E-nɪ}'v*cM#oLEg|kX"$PER ˿V{<x])ZGmso)ͦ!(*y|)+?+-$+$-KO)!ԥRB+/xH^]ȩ>l4q,6N[CY܊#9Xɢh:qUηe#<0M|X}6S5sCÃ6`o^ !ar''y=0rDx= 3d9n1 AoGe^PX].k۬dlz2ȣb0 od) ˜`Jm8zS:! 5/&:||}|AU:zL^="a* v oY-pBiFk)$lq5i1cF j-v_kC@O2Oo[rme@)<qr&'o73_.V5 lE_ƙ,b,^@UF^s цCO3u]+n9@LD|i-SzR-Ec|y.TImĿӱ>&f0KCcد-)*f.+MCO6Celyfa=u )+f$oud p:ݪSToibGo:ɐ}ZJ+fFH׭|Ol7;ty_<Rc]c#b'qEENtůì@rb)Eղco|,Ljv4at =\Ǎ+s\rbUa.D^]Z>AǎfLU7+st¢;-yU}Ar&XѾ](4bBB'׉@M8i|yM>i:JT̋ix[G6AƤvܳ6E[UÛQ+tXXh?@\OJ@|#eӺ}mmINHOے y&ޘW& bU3ɨr\|J!\U)ɨT\88<d#U$hZEtس/ ͲQ@'ђXT(;v :[/׸ٌz.x0{fQI6m1*K]D]ZB+\EA ٍ!큫Ǚ&h+Ev 4!)m4ͪR"\_R9z1nqoȀN|N}A*lAV}z!W @FXW R޵<[* %;W$sptYn=>k۞4mqC 4c >ޮ5f#<~WEe[&/0 gujS2mɣ8 сNHÞna(IQ)U4Djs[ӚmIgpU}%Xm] @\c,1l.W2p>(4< QOJCJ fnA|^MCN A8"8FNȇsv֬p>Fi.>R^piEQgebG y ѰdsUf/'RYj  șkU$y8D dtZ Bǧ5&0Qg ; 0 wv|h^@x8%%KӋSGJJ9{>؅C/Qy楙dKC^*qXHbqjP*7<6:Y_M4歷gŔ'-JJthwn;_)T%1^${$h =FF&DZa;KPwmx(O^ l*URd{C_&ŅC 3c)'xAÀ30|&!ܘ Kd2jjեp++W/ŰAKvכX){h@ `!z}n ~ Z e376$BWGl*VB!l P/ #vvM h>:M$"qTH pWzuP+r♿=(Gwz:(17Yr]^58=y[Hpwr5L^f|Z6`f2ogeKԣJ rn*yE'}<܄\/'JnxSTk7RgLqBux>0]EJ, ]b3:zX051-/{$!'9bީ"'p2ritu4{=`3[ 3aj*λŋq\;vk®#N‰@=^/Gfru #CM̔{CAnP2l}^yd-)l\zF>vY =D}`C56;coT1S^ &X0Sѥ'9~&x d |SZ_I(Z5d2I{C7hDC16}sX%Ě@_s *KLF;4H^Тd}Lu)4"`ݴˆMs7Vf8X*Ѫe$szZ G@ B~9!o!PnjHk//'N#b8BiK+ zN%!o TjXAq3B:Ez\'zQm CbUc`LWSӆMUT'-αf͉]4$9vX}:rm'BƟʮq8NS-tMZUP?{t}YZPy _ ˤhL\2\ٽB\h{[`܎2_VD'N߃iz6RD@d4T/{@+Еs= '% )ݡ,+?/ߖA\k5+Ci<7x0Y|ަ[h1-0ACdaU_3|B0Ѣ΁!Fw) ^K}%wH,<_CS1Kk Ĕ(9>q7Vi9˚Eq`l.O_d \ Ҍ\&=BFnmӵQ>6h3^WP/JNA3|z7imB}nLPlWF A%ZYna=g,VPo2K*g4@v/ 3dk%7Ӑ!W?2[ǫ,|ߣQYBBrMNyOd~/ːnd0-8Z4)32Vqj:Q:dK iHSWdX5[XΈK=] 0e~:W~J0ƥial`U+QvCfGsʷI_ðp7>bdC~FWٟIX_}XsWZˀ2(b|@Oz$V;f 7 Zr)d&^ ; (brHQq*L]Qk]6 T Vq1s 9j1Q<&YHFVaHx \$![6zy=3؞n@u$+2_ 5@S%RێJYx_y2mG.@:wj oZ%dn,Ӝ1Nvi)}+KG}7m;rUufOw6{b̋s~9[NU=M1/ * <>xdP8SI6]"svJo9Y-m,_*$Uo!A֡%!=@<\j=)l!/HuLҜfܥ"R~,$gQ( 6Bǘ<\G5QxT9RH,AKŘҋ˛~©Rn U#`*CۈIQKȌ eoQ6_"c\$|zP6b!~醙e7 k}zKֿE@]Cء'z.m:a(Gy}8 EsMŎVl "RM6ܙlOj淄x&tXgIrV)ATyN^)ӉCx gkgK]m;:2ɨ\vW NLĺ3&~5ggr*^~?fZ9?'8樠' eoo9A'PV%,7{,LѺ-ѳ )xs%h>#Ga04 5&9ԓFg9A u :~+|fRA>9rGK,6[CK"3 %mYK002nE㐞F֦(9bU+Ǝ..;/x4=)a۟ڽjN|j>@4ݢg*.blu:QmE* {F0QZK.#VNKi-sopM{95 h:z!9DkF_\ŊOB\jl(ƮN&$]u򙌸_ܢN!̙M9#M$QN[I@_{w?%ҊNl\{T@hJ;#ܨ7b;Ły`lܧL3ۙ[Bg~ R$-'{BPwQ2@ /a|F]hJ?#A@l_6cz~l9O̎Ǻ9fs~~SvQݬ?WԾz=z3с5Ǖq%8m;3 Sopvu)i"ǾU=Y6 c&9j>G$Rf\0ٶtH}dcrų+@c/[%K"`2nS LH8XH yJVqZ_M^{Ѝ$s  n"Jܑ,~"6Ϧb\0>Tl^Y] j, P_e13uęVc.g-vCin //!yub:4:'j[qJ.-ڣ, o08;Xd4p o7JL=Gu4 l|<Կ os߈8z4=f 2"r-cHEϦdCZ'˶i@;o7;ͳjĊ8@:CZguJܕ!㽝~OOd3gM0YFQ? n׸а2B-:;m+&tt Vt @Ų6/ Mp0mfYf3/BM'&(m.511˖EN-L1~[|doeWpMثz]tؼgg6qUa،U] B9n$D\@)'ܑmg'N[9ŤٖEo O pVipq՘dNhw:L/8NKURHِ*"29>+–3_֊Y u ,&>Mh!`lD)I1%g9>WDE:k'HQ܃=0I Mv5ws l4:?.o/)/K! 1]H?K?T;G1nV?(`(8XF,CV$YF$p F /Gkϖ? PA .o~byVaԨj;[lBy:װr`% 'F B#kb:s>7K#x*gYzNcŲԆ+Y ~/W ;Wl4cId'MkLͽ#uF"Aϓ;'۟aXJ%ߤ+)ۉ|._zz 0eiD`>}^[ٷCiox·JItHv4L "7EzS*NTJZ nr)綵J[W  gk *QdR倖4) ۿIs@8qu@] Ga+[дCG}JkK,h|a^aK\v% o<y|1A+y.UL lb6"nge9B!ON_iA0Mf뭴pߩQGZ)GY(@g4 ߛ °\f{''/GY:70$M>QTH}x ߽q78~%8[@W\[?MKA j" w1 dG[R#<:|7z6"U; ʼnE(Wt臬%C2KxK[lrZ!ط"_)oVaOV-dJ_U.> wG[3R:To"BS3%M* `$F5ųD\U" NӬ#~ g2ިF]J&nR!3OW ϦoNwbf|[j1y^\ʏ1f.d=Cz}%d4/$[~S l1faJ 1Ac8c![ yяʉ`A7#<8Qb5-EA$_rwrsD'4Fuq[=6~7{JQO%r5] ?zW놀BùY2vԕȨbRMLfbnE\Ov ݓƅ~>G!,jyM UJrp#;ά/DjM0a1"/SqqS{ DAhkr톘f$DdWoZ Rbb=jv8Ti˞#"-vaŦOk^SD5=o ΋z5q GD뇭ݸz ,s+Mޚk=ݑ޾7"ih̎\ªO!\k Sn_ 6&Ƞ ?zğXdu f M}_ÂMsHGҜ1 OkS-Deӻdz }* v ( p8NTIjΨSF Alc1FTm ;1=GbV9]D(bGV;muzz}\1,XY8FZBS#lS v"tShrsr$jc木nCTC0?ĕ+!TB-6|ݍ&+~ HӀ+c e\hdANϜ mH'Б/"Gʚ{w¨@O۶($#q7M! y8(p[MEiY3= 0wPs:Dkh/dGC7[[w=bR5pݏ*VNP%+h8ݟ5W -;0\(])~{N'bP~kje9'הh?xeeE|343w B zw4tHV& {2ZH^*]s+kSxt^wحv'f̖7/d1A|$s|.}X52p9β+bfd2w70Ѩgzf$m<|alIi56nߒaw:a`!1(=)Ιj[z/7Eꈭ"3e\mo?s^ GTN]&#aC {-;3EoZ>W6n,Pv4O5ݮAݺ/{&I&b?;CZ@ko7qTi@blid(BB(RXO K] DyZ|BϘuN B:#ʿz߈FޑY0-3W"O^7+>0ذAI=8L[kYe j\(:~U| )l%4tUjYqxkq~zq|D1.'c5k ήXαprLy?QXՍϴi틾9bTE)epV$gcF13K>];Ð YF)}:̴nkڴ%/C֡1yČ׻WNi?S'M"U0x'$H ۃ\vNyxm9Mp<8m.fEi&M2q4"&h{bZ#Sڊ̿d߲h4]-'8OC'!eoO0qrRaUH2G_T (H%|=@|-7ȁ)E[T;e1jj%u%_jar2s<\bTX_*]H#⭀p>BPaT5w+辈,8e#N6$$(2u6 fǠ̦,qOP*Z=`"1"ոһpMLI(s[N]_C{C;ViO(l몊 8Zr;?X¤nQ?T \-wpl)]KnyfyA^n!= i1MJFc>!d -0xF3ӭ4#&E1Qƒ.`G[E?;X0UENtz2ŰiU۩lZL P8>x(RbQVt(Тn{\I&0^zKzXa9Cf~oG{ozB0Y/IeO^k_i4ׅjx;֔b'B?Pn*TiF9= I;FeO[[LW:+@O{N`בّeZz!͋TP+9"\/i!Puw$23a:SXg1J<s$jҬwx+8LwZ?gd<@-g*-eA~ڪbBIȂØM#b"Ohy4ӪUf@[dT5L].C`ŕDJJuT.87ĸ W؟Bc@ujaċYE&Łcm&}`ƱnG}殑;E9=740mv.s^۽T U*)N*p G]K/n<-ZJӈg\!Đ_,C%HʟuQ蛈!cK;yB?7SIy#X+t?v0bվ, t-+c~'Vܯ!)&d-1= fhV[\vHI{Ei3IV).:_>S E6Eͼ1k+8#\_E 3LPjKewllnv8 3-l/vth @lp5, s' [ƃ1-",dF3Y UV ^SS]Nm $>;ҲV8prDz'zȵ:EH#lսgX{X. wvIX'/`4iMBPUay7EZ'6%k~I@fȞw(5'}}3x_s469J˩o"$WS!|L)>JwMD4<3g]n faF]ꙭʬl`M??4?FjL3ٷ"w{OVTW.A >4y{UnQ?+Ԕ!]{B؅ɶG P/[d ވ(Kct|&ZREw.aG)R6oa h=I_1NB*BMG(p{00"87vaklD γI2urgsY]qD๯@'<,2XGgvܡs%bQe6qf TOF5z/G{!ue~I(왬FO)U˗"jd_cBԲ߬ [3J4(I`)k#o~izsHaQ%Z$A!6h>j⁏a݊ZI7ئ7rw ;o Fv5֮qZ"N5n7L6ieb źL02Bb<$.+P{"uvN ˡ%a5H)kqkgFeyB+(ɜGJyUt`~w83,c/ns/2 ט tO35"c~F?baP -%|ffuQo3"{^h1==Impw- PA"J`^5kڣ vhAeܗx4儱JN0B%U0LBt+?dvԱb|g縤\kg'2:,`;LS5$v:% A',bg~)ZJD0M4_b/pRhŦ  㸖-y-sQ88 KNe-ev6(X -/P?Ɍc/S2%m/ 9Vb |-Y4QOC,$E`&ŭ1Isw`ؼnXwG*x-OA܄ (׎Cni)ZnJA+9*1<"ʐ/GpuǤ'ٙG"bRbkh9Hj1 ELU ެ'Ƭ>v2~u3zw";ǔ}.SQ9vѶ8S_n0C# ,0uN@XJNQ7b(_^kIU{Qrk PCW/M1|S@6Ridz_3[o:{A5;#X6z˸"+G N2:6j06TR Ɓ6h#[PtkL2>EIpox1  3?ӡRrs$`~;'!`4,]cJaߩC}G N(}4B/x]=ъZ3 r)n' L+$!;AyW#6sggo <ɦ5%E:Ѵ*a:yhe 75&m=[^"|ƍl]yM0z ^Ck3ШCT*hr%F!!侣e:nVn]"RX{N`XzXgF2bMK&?&wu/u v#ФaF ~%JtJ.i;ɏ}} Pz [\յR刢+ ]&K>^p n;|&:LSiR_Ʒ Mt% 'K"'SbY`.={$ j,$@j*\w|G8üW5U q4:B=[ȢPUov15გ[ ->i3J~6S&2&kֳEA%Z`ܗz y|Jf&Xn&"bEOm=xK-Ze=t -=uv_QT&ڮ*6) QlJi9PLs1Y *Y>CJrD%V_K}6Ąi@ p>%UўtKKoɃhuC?6)$`&9aͩNXzVdE zjCI9j: b4Je50'-Qx]j1* B5r2Ps5Cg3H{m Sy0pˢ?8Cou]U2eD]< *O,l LI-ܷ@ո1OdoЉPԍ/0LSCrJz2zݰI\3.CG rV3ftE:/6([l[!Ox63nZsuf ܰ>[ -+ykCvd&B~MމPۺ+TaFCU>=q'kbp, P0 p58}X֜z_@zTr dI $a޺HCa_9#u lsWLրhMH ޜ}} &B푻tF%D.e3JCׅR瀉jd(LvSp W/YN?-3`La B+gL?lp}gV}w|^u?Mܮ4y]g ѓ`K&s0c@Y{*Eз{YgsY?Or^^ 2zg:Ziyp}3еJrA tڡ~` I#ab1~'WJ~&^V!fjY9ktXt Ob {1Hjg1,ڮ/.2{pD'˕N}%\DcNQ]s9]86BxM> z 5SNetwX39(pc4v&I7j|GIʁ [=è`wSF0;]l C66k:ު2w$I<.'jw3 ɣ{? 7R3w?oB?Y+O>kjg葦hzkK!b2ҳklq; rKL\@(F_]s\eQ%Vt^VoT{;WkJBRɾI.Ib1aƕS&37%>+V̘.?ȍoIs)s`x#օNgi A#[uT AwZ\ G!Nhp0v:S"XcefꈪqϪJL._T[IjǦ=|Q騖j|esuP=~9|9]2aV8s f[r™ϟ/dOGkK q:j-Mx,?*,dTQ` M] gNG6Ŵ/{TEH`&}p(7#v[3LBw XH/<+b|cjEC(=:T{0OSr+1 䖤żG<1 +St^з#a1UwF%8Vw%f)9߶;f}C)U ecwZ?̂&O~Љc7$g) >ϞS} w˥4!qw]TXk  ()\<b]pSVraBO^0#zp+PPX&eHBVK,9L[UP7K[_3C;vî kk^hy{V4? X(wF^۶:+tz-;ҤZ;rQ+Sa!cN!-'0:%?.P=+>;?`77`g y+x8P\Sms3@[X// SwlKj/dZHh7> cw\0%e 髬yZ%EI ('P0y\|.޿U)wHOayԚ.a- E28QcՃ/#\i+yB5yN d:Nׇgi Q`e׺l#.^sX`.ʱR`KK:ԟ<,2E`@EZ{hߑ*xR}22?lguu7gT<:o*UR[g$|PH(@xk;>9"yuFw 8KP߉% P0>)}QnȨjJhws=':g1dm͘wUsO(S feOjgΆZuxvL[bq;sa鯙 Sֈb✆iur3"ADp6?<%U0}i>L*0*АhS b4,;M;aCUE|8MmP1ykY. 8M(W^Zq)pĂ"ܸA =c?#7[̨l>*.aDnsR#/y]1.]!tMcQsiFE$8Pvވ*3 Xsk V*JVi#_RI?mVpزEDSzi\Juۅӧ DZ&vhx.OJy=,4 |]\׽c+hΣDQ>i{(4{X7޵-%R{9 hYr)u& 젨 &k8.@붽?E4gdF MۏwbDo&qJAnA:`*(i6ГNmm[_T\!Ϭdcp֋9`gcH D( ޗ>;'&ba/7)}BjZXph)ƁxKb$- E 5 |t=T YTm Ū! \+D8cGmx5EgiK<[ۏ.vs v8rKa@!A[c;Yp㝵-H y!HIl*v-ɊeՐ?:~9s@kl1-n#@=soR{ԾsںSR/35\gEpXT9z"|.t H%V r4P.USGȖRM2\Ço*6$CQ),R?1oԚSNVe̬5.˗eN!/kt.q냃2[j9tzX}mkcȉd~xoi O21a63ݞoQ*oPVTKUC) '.3콵ٻ2E$7!]*+Xgsgy=d/8voHKw'Αd$eѡp6a| jnIMFŃMuuMm6"LvAtjc@ď3Lxz94z/f0+HxTR3XgxhfԑL{UEEXuߩkXuLMLľα,wdoB6NS P="/UR@7a7(BR~K˭{TeVzTzZֹn%mqMcVNRD}F*Ys4= iผ=(Kvab@ȊCO:.hEaio*Ym[j5Tf u(B-:~Ψ*Re/R]{\d_'2X&GqRDk[ lP-YFy_e+")2µXNjk9O12ZE|-_=K#Rmn"!)'ArEMs/k3ڧH<و^.] 4Y\k_HU'S&`7}eD=_l[ίG?ryP7*P!PFa{a ;mJKIc.j衬^h\^[pu2Y!r'{$| ljZZT@ò^5q-VwUhUxݤ2 > x/iєACcXɜ{s}ְ>6B7ʁ6-E3XLZSqŁvy?<n^=fCr׿xtAjx :gPάxdJv♲r &X9_y9{ZG<~M;.;TIvTH%V VKTIxuG1S.'7d\J״YL/ PrJFGwӟrEv|}N{B̪u<0s쨈⯝YN bhĐ ',QqXr콶L)c# {NNrZ`أ6т(pKYg+Tۏqvj3Yp՞iQ_Ae`@`t%Ӌi %_;>lbA̦9vhzን%(_o EF#5 DtjqѦ(Ih\zU0%-8\G.-j% %!S*&0*q(\^L0uV5agb>TظNQi#`\5Dݑ$262=Z4r (z $9xqP~Z rCs˜vC2\o91XhfgܭXZڷaSC EDN6: p` ")eJ{͢LLbMyu,7 g.bތdSQP0yTqOʼnseP MuYa^5-A1l lV{ 8OXtwR)[~gtiB*ȋUVW8pN*DN,)\Wpv4~@^.D.S/:mI`-;‰P?fP[XXe1/m刨5-Cd"?Fuև\>Z)@Y.h&,ePď ]:WYz瞔 >|It%ߑvANkmHWZN\gtfC]Jyzl`B\Yy}b;Y|=@)Bع1ťc[""\$vxc *iw;q<:C?ra#D4h˽[p jMh3*>RXYG4}x@H}cvf"^qʯbhENkGiK* :"Q8K%pɚ8`L/*RW|:ּp)շ F.]%/`awAE8 )*e JCҰIA.BK{1\GڮBĢb| DjN_ p %~vg{[8$։?-Qr;V(q:S+!W푹z2Pf-r&uW,Kx$%$C>o8sӱ1juF1aDj1}r심K9̨HZd=h`U^B]QFaN &;Sz1<+>+柙c y]1;=<>( 47ֵy4V'r]#AQ ֭!S ,J 2 M Di'mqxncw~[ԗWn7`af&x[|`'"0ܝ(/ƖN?~ɓK0x߈ d0qWfaB|?p "ZI/<|ˆ:X_pk#5>~Ug~խʼn۲ p/.1JܔDnvb^tl-C^Ball =Yj ʨ%hAn%#hA Zvem>jd3*֙vy HF}1` KzE $k9>Rqm]j4Ya1J0*0ޘT/6+hrt,`im;oDf]DM{G~p [ac%K Id lw޸CB=TSwli؈~y40<uUɞ[DCcOw D[muz@ɀ$+]JR*]o2Nw!pK)+%c ^Hrx`\(IHquawqT\1/+2jXFzP(LZykf4j'J|^EHpz$zfXjz>-{ Ժ?+vI~z0|-kCmG;˹~N`Z^XI4δU$ `et7 sd d HJ2aϪ`N4_De bRi"ͳtd@/}5Zǡ:hlXsJr8e^0`A${>_DXur5&gSy4+LP/|lj2dPUg's'y&XB/wF,L3}~Rp:P}Y=8<3}%"X{6T#=|a/+ijOM\`<fy.&%FPj/]L(&7m_&^ݻKDC;8F)9Pz~0.7x/3EJ>F -#-vgt.Ȉ K,{D |W\[H 'v.X D1zT6~ x Cٔ;8[8%$- ʖֹe5t~<1<"aNxVz \U[H>4v !\t$즁l^:qg4yGZhQMmĶk 5 +DWXgG䲧x01S^a3,sz~2j|ފ! 䶗oۣ/+ 76pLF+.ILV`X?B[q>b"ӭIM#BޙҬ1}R40 eʝA~7KlѲ1I(Iut $ TAb.9a38Ͳu拓zjJlE6ӤLP 1d|4|V}:pPБI'4_NR4"Ym7P& r zӜ6 c LS ZS7U >ZXs'3, "rk7$1Fw<e0%pWN,B.jbQ H4F^A;Rgo#CIq::Z/}7Lx:q[QJ3SmO B7=lZv?eZHe:]I]9O=xU|6nZqЦ0 4 +DʕmȿGrr ]p00N餸( 66nF zLQ}ʳ)t0H_ WᘪL?j"k(Ɣ̱里 ڋJޏ<@~V;hY:6[o<_]$[۬0t /~=VZ߀?kQf|qZ^N%ظx%85zG:0ٿ 0}uieLzՉ9/K^%_tCJ6zjS+mG=yꠘly8k.Jtdw\tzJ [ڦV j/̈́jh& ;mA"v VtsYMKY0^D nIF=S /K¦z^ɥZ;e,ge@Vp CQte茧Q70E=߆ݭ C8^h 0l=$K75 n)ct17K:'U7X8,ƍ[THV(`Zˬd&p M?r9^3*[#4J1Jt?ĕyUJ(X^;\tjAuZPgDXGCDqdB\9%Nn+tqG̊ӄMhrĕN; L45ݜBVs\^.r꺒;D&MVLZG7 ~WiZΚCu{kځӊ\8h"DFpLɖ :.L0 '!>п!%%= nǕr9&ׄ6L>t=n3׎,#D4yYaP%YAx#O -/Y:!T;m^%Gc?z)R`Q'd=:1?)>E:P[;Z`J5-qՇ9YKصV Ѫ=lcQ)=9 Ӌ6r]3Q26Wo5IH5HgY tc ahۻ[ aà Y{O,i78_@o]PŽڰ,F>4;C0t!~۸V#6 T023ERK2آ0XKm<95Iw>)/Sή{eEB"N -Cm f.}$Mטx?x>,X;;da}j]:4cGqSd7B 3V C V9TTy|S=RmedQ^)hwk7nf^[M!2scV~G;G=B322A !q,`=Dˌ_=JKHP(XュlAӊIn+d&!塵'8yz[t]u>2oԃ…79=']179k"W0,.;xDր fn$ڲ?VV5D+Kј{xz%T8HoC;GC_6N~!d X<%%QZ1c` ˮu;Ee bH0p޸u]`ta"\=m\H- yN+!djDrCy陴=wAUسfW8K+RoL3qcɧkC#Xk"-i,Sy9ٽbl7 sՠ:`pYǵR JNՋ|)|Xp]8pr N!2߼O:($@q j4'`r"Y(*37W=dȣ[%1#YMָkOUB׫9E@͟y}vc #F2P6 mRU ZcqHCe! Z-&1[HIî^U#kcpVP+bYF=[@#֞ gEP^\V@(Қ##QÄTE>;?o Bi'YyPvPf;sHh|>Q=;mDDyy3{7:' zS.nRo9g  /s6kW+qF&BCnzg,TRqH1xFk^e53 @6k檫۟fcS Ki*]ǷpEL~MT6k dQ3M ?fR NϼD9|#kMVVTd7IYwR&:} LW@ɴNU7H1H>a?Evr ve(Pۨ^ ձat&ǘYdnm.=&YU8+WG՚P陲MkzHw3醯1 ѯeh~UUU-]W!%>&S <["?3@æ+.)e\wi#EWxTcNNYі8JpYӪ'aX]"芩 U| "ήQJ_`tQSXIC7NXj5PO‚50-/<_hȱ]J}p L(Jszִ"O/jԉ1B9bƀ;a1B 1VSݸ3 ei|qÓLW_#37>dU3p#$W !Zb߃LSH RR%KaO+ansTsdl@5ϓ`pT_ .v>)ܑ>Gj]dp8 5Ǟ]23پO߾Ԉ2d޳@IpemB1葃[P#cF0c\ZfLL~{6N_PK=z<*x9zBé0tNzT:OH>护>z'As)UNq;$GzsF .8g\f3r$Ə]E]!;z-CdžBRX?I Y;,b6 }TrcmEo! mǦ ͞e7I.u=EWhŻD7xz<qPϴBuE~4Gt1X_鋁%EyC䃆@N0f[TZG$ҞtnvCF20MM&}Y.x_k^lךKq(zvG0R&O6.8"%teaҪ௞ijjȀFT^S6F *䵷U@zϢ,v'FI"('(QM;jrߓYǺFU-u(Fᒡcqd0sL)PJ̪wڂynCٍ?e0XCY0&K@ݧJh,>"Vt=6W  Puy`kbr&2C#dDt3:a}X Z~(A>e#gV*҉hъeqzQ;#@{+H-e&!2/\[BݪrPgؙ)sP!+IC'GoSPv(x҆B3H( {Q (pASm`+jadlЅA> -@5z+ Q2;3q$ n|0оM$nEƅ,BK!dǯYϚ%hH@*^(SlYXjYCUޖGA Bh H‚#O==Y#{ZTF p84Qϼ^ x rj WQ#BCJ$wabyyo_)[ `a]P`(53^4zE220Cژ2jU-Ejp H2D̈́%&z.d6gJ, !.ӒJeeqSJ]Rmͭ/sRD{w5`rToyh=6pG&PI4x(e%Gf+oiTAy7IG"jTiه@':: mT}e0.lݢpyGБ[EKqj'??z%#sMs%=iVRh2;Kɲ.Ե4cMݣ_miv_vG[vF Qrªpeg"JvNcWL2'8Ng+ M\vg;{]+>,~c#-ꀇ{S!KkDt? eyxPT B4Ӫ'9(LMMPo,n}M|}'L+G%n.4 H#Iqc~ߠPT沘?L~oj,o`[l("h9x@R^O!pkԇEʫkKEl q]Oji*j@ {1rKM8_iOg6q(wɝgetIӃNq3>38 !RM,/9:`sFU~|Fܶ j(k欞؍Ko# Sڐ%il"4<>,?Q sfhꔖj=G"5 ~A *]_3h,)Ɨ_nQJWpӈG1?F6QgF ]`kTVDE-\:φN/@uu&^ FFj B:t#^;K+ 7+Ddffis>/cY5=Uc$s{>fąaAT% 0$?k Qe=x 7J +L!u }q2{f!%@Ʃ2v٠ff2u8 vK_/^KH ^$) לsܶ*[qp;Q9Am#_b"wzyĊblMFpLn^6ic"̨=Uj#`lz&V}'}4ޖ3oǘ @dt#AE)4aNʒyxG\Rwkpb7?Qށ)Mdjޏ#ff??u63.IxPL-#J@UNlaIj,f!m/k0d %s |,ӨLpܨs1zu:tȾEŎΥ/=<@oٱz?BC9ZʢAR‘FRίN7Rwp\R6"Hʜ}[ ݭOpKsWEz:~YV8DKAK/"sr?gl[_O-%M&0IscDx q|6{PYL}3 W`WA(U',7{xH~L(TD,#Ov`C^]V Ȋ8 V'
#'=T3Dzҧ±>St?PzXGΪcdȯ:vY/ c /qwVsdhC/<$͏_艜2wxu}1ng&r r@vXwÍEztY2RlV"!͇{O6" HN:IQH HGtvqr# 2;JPe;7w{7˛ϐ„9T<pz=坞@uݲ ?_Aq%7fץiWT(u,gHf}Y)zT1p* #la7dGuXBi '! C;_#f\ah8(tQ)K$^Z:wV"ʦ<꼳(!0%[Y,nFXr!JH3OHrkJgWHBUb;+O]ӆ)0b4pmo`W xQf;][Dd_mEk7LQ`uҿ.vO4? `2@aS"k*um];'iEEpx@<6KG&3GN{k}}=։~V4 Ҹē%-K/_'dߢ<{~w+'!zΕ\TXGGQȩQֶ[6İzFd@=* iu ՆǶX;6C]+llY9? 0DC:F40nY\ ^0Wm0s[;τ"[0Ua/ATZsxc`۳`aC}\C:a`pk@JPB$QQH "- _dc7Z DI2b$4k%cЇ'?5ȉ+ri &Ra"eUQћːOΟ&KؗqZ&==\:]*iWf9<-4cSȲr/q,o#t&% ?yI4/;_ŊB+<1-A% ߡ*PufN(FlW:Iĵ:u[@;zVL,NE2\,Bs 6[iXB)i5΃,m|,O3 9U1碑RV]3C dƆtʦՃGMaZo(= qUNj$X;%b=ӆU֎fAN+%~1N" SYK,=80`N޺~ߠ -?g:'*.rhvBՎulNrqNF9{{2*l7ENJ7lTu4؈4~5({K0mk/t.(& z&%22Ia)8đBv7Žss8L/_@t{^ӯXTw4ͪD X[3$&LeO-RkjWu!Ʋ]lO[7ɧGk)c"kz%E0'}2)H^!Ay%فvʶi! I`A)Զ7 RsFfLRWoϨAA=SO20T.yw~M+wdx+OukK+%5o;$OO0I_[}O,?kI4%("u '|yS 4Ee@bL/_Y, !*5|d݀shB )iKlв=G;bDX`w-yͯC"-} %PQ%h?5+ݟ%Lym} `>+! <90 ymWiP,76,CK^q)!69o rμFγc)'mkdu X͖N'(!t֬KgrKHk7N!Q0B9G%hfZEdO),:ZKViDڽ=h,٪sZnlt/IȉqN\a 2,n#FM6~:?K1'hp8Y4G,7xPTveWeZƐ uYEتG k[}lʓX/r9G(߷*"ZQ97 Fխ7X&elYlX oT -;,Q ,mL"m]⫝̸d{ђ"SzQ[2ǢBَ}r//DԦ9 ⣞W=xm?n[8Wcݱ&`O6QϰB&d&S *7=ӌCH-רL6d_RH&S$}GĐ>-Cg߶"KQX:Gs gP{&D ?ݳ.o*TiFaEoF^{qпisJ*ڛPTCp.=;E\EEFUk c&y]ۃK ..@,1ޓOu͚t095 0KvB̀ JqM6|u&\21@?ڵ1WB Cj;c(Eg4~%YG֙?~}#`0Ԋd]d}Z*IIxZ!.<ο`thteܠU\'4T8Y@U5?^kMtr։]3=\}{{߄f۫~FdlЂ{- ჉_,; ydz,3rխ,5aՁ ^ 3?oXAO27Qj_upXb|A@]Wr)X=Y7@?r`XBep{iƇ3?)s96ta]2*uIʹ`$tuT`vbu4ܽcYMy7<~UKuqBUa拞}EE;,'~C,xsKߞ ~'hi,xF<_ xuC*m.{ɔ$V F|e,&.qg_Ӧ_X<⎑vo7r^΃C7 7.Q (M*o#:j'IL5ع\ҳ5YQ#4ZU-=zl8&qhfL<ċ/Eb_8N?m]qu"S HFY$ WY[Gcn樥£6 Do-\P L/8&*\ 6ey1$ϥ&66&0:pT,-ZvfcϾyVZ Jm'|KӦ3r^^,U\#,W7+bZaduv%_4ȋyiAlp;?J +YbC,brMdSǧ98+w'}W0~/߽+y KfK壋2g}l<;70g^[b&$DO:aN< tG0[@[1+Kx{gx)cYʼnص:e***shmtk~x7:nE7l:<'-¹N\DAx~!{;OSΈ<\yr4v`5 ˢ[—W {+7qDvǣ].C/,PZU@dnI>m ]tPIF<'ԁiuڸe'J@Rg4OBW<^ LMzЙh2K13zӀhBo{zo$?7d0T8%`c#eiOxlAkЉzÏVzZwp]gob gā\hӞ]uDoK]cr~W:Z}YrE ȧ [kY74k[5sqV&U9M供߶LZ{NͶT+ĸBHB t?="-+ Ew_[]Ԛ*@,mwm)^:1_3c1xEg>7a;;XhK1& @આ=|g9?X]`ܧ#bG];~ow~0Ӎ B#H8} d0ih9^T/0pJ p&Ьڲ1P­qa )0twk16W=PFC8J|zBƂޤݾ\'<K aLɜs9z. X/ fÌgYt0h蝕7E:F6^ i$p'& +VTo9;G֦h:(^ 3㮰H"ߪ}nX=,_0WYw΢hyz܎C)!;ӭ5|cԟ4_82= V()>-j2$x4,HYîXp!lRA66+ˌx߅[Vt3dt l @w@yԁ2 Qї-5m$M(Y % siEw 1ؗ9oY燀KDsWBrA;D5c4+{=e)*̍6:r_j*]n5 ? %-t{a4 r; l++t-C??l}|^jQtQѻ?9IyOtRA\7|*.sJthl Doƈ\}C3 =c^s46C;OvK;f 4#vg2L|_&oc([;5NBw\=ud_0 ~"zj50dCtx@m 'H/ωV _ћCvAh[i cbLZo7j-ľd͋\ PyE/nMv&RHVh41uӐ!8woi3_mI-{o&#wH8GD$%&<k`(G).x1rPN)j&=u=X*NҞ&yoREJM|,,XZ_<$I{T:B~+Ae]PoFLݮ^O]xJ3e2ǺJ?V0$v09{lJmQJTDT`Iggi%Aʪ֋0 E4D c9 )cg,>=]n֥>c-RU۬)ZŻtgh!AY%黪L.SvKCU岑;79pW 2-BK 4tOlE%0GFu 1Xc`V(diU#<ޑl,tZO'ZhoF\ !++.OjRF_/`(X$Z9b/v{X:ை3R`'QLijӻb`9Pn͚7 \&T/~,jM6} pC (}N!Z#HVo_~i.B$&\KbW^Q.kYe'dg^Z"]$k)(#)|(‰|'m`7Pz3V+R8DX*,]0'&5ƣ:n%c1QcˤO5Me5' /'\7Ak#(D:Y܉--Y #+kUt R @NDzvk]-5Y ><'5uy] t Y&x!@ 'lc0T2<'G$ފW*ɝWv~ZMg4z1梀4rWK"KHqK e"YEmf4 .. \,O)5 QW;n.T]D.WQcN3WKFONC;*iKAVwYϪl)XrU%{"G-I=Nҋ{JD>C_V#Xp0#V>'zFqI(B'ޞ%)T|ݝ ܞ>$Ҟv}ȉ6ʽ"ڶ4~LQnlnwreYLiuh蕖S &`ZIhșeqO܅I?y8Ui0OՇRDŽ1‰Áq),~M`^.&$< nq8Z/R:^&;u4-!Kþ[ ')u7TF#e~Pm}WnKPvfdD|+)W_=.J!4Q"j-"Tn'.H8'C,lb |yNjMܥJ\EKUޱF6جRAU "I3âkM0 Y჎oKǩd"5?w,,ۊn y"quy8մG} 'P_.{U)2m=i|vD^m-D)ANMDx ҮӼ pŔtHIN^ZC`nJ9`;@,,ObLҌ{|6@g[2TvDc &^|ZړZm&];+nj^e0T,;[!}$d ;}^TFob~@Dz3`)9*+XvU2%z8֣ B7i8՚G5b0N)c3߭q%;&C KeAI@&y|*"k~ (Vگ T,ӛ`1zZ2ZmF5>W49쥔*nxZ8wP{qَ тu[89gUJZ8K4@>/Z`o8u%zvMܩK f2L8$N}ZXǸ lKԞB_IYLOsz"$-ǜߘ[DLR<ך[6@φH'ofzjHbqqVb.%=$lVS]%1۳u0hIQ`T7ם8Z ezEZE]%QSo_Ec7pƳ{&O*/PVv.!;Y?Wvc2'Z >vjh6̯yQU^"f{nĔ fx6\ѓOЦ7+)N5+N3Ʈ"Ή}|jJΨP4$]=X2ZY2-:2^8Sۯ RmϾŨ+Quh9>O F/}ma1qK/v= ϦسaabQIŕ]UsI].O0G={Q䜉:^cE%'_hj [UqNxjUMYk̥}[RiVɲLR3"FxֵN4-$, ){3D], e1y{jTC?Lu(1U )tYrȣ INҮ}4z+WŦ.u~®&g2 vmT9^1RV<W₠/Wݑ`krlXoGUw%!o') 'L\s O}ێd㚌96mH@Z1n|YUCҢj >rYpҫT>YWJ)HP&X *"XQJUh8gd1 V3둇75W竦Iot'j! K2RϊP5dHⶱF;4y2hp|!K΅NPX]^9qJUxY!Nd(.jHUA Pְssu[Z9aO.dk6~8J !h7[뵴AKi(kW҃GWq^\,.hnQ "TSxW?.Su>`n?'a>fo$jPBr-_'E%nj䷤ےJwEsy)=zM&Ұ?\IpM bjj10<+ͪT Z g[MV#kvT+ܰvdlIS\iEWu/(hb6 HBERTSu7g(<ځ4"o.;ԱEz!W=sR >T0?2fuA '/D'ˁ 1_E>Cʴ)6Ͻ,w7sruj 0)2/??|$Y6ڟ*;8d-xD<E|8K~]GńJm)z*Nާ/Z|IZ|'bA˻3>N afډz]˫MDCmA]@RܽTko]OJ:YP3̓p^2n$.ϣe: MĠo?},zA]:f%ӉŷZgH0Fqmw7oiG|")c<8 uqɳV -@QIڜRF\GH<܍MȲ2x%|h2`77d% h]"MwL9>HiSz8ZK⹭hަ-T gyjջTȈ#pז#'gY2QT=(&u6'Pߏvw.JmC7)/h3u*V (yo]aektَۅmqk{^e9O;hry8#JJ0SMI'W*fʬĺtM_öğ:r4Bmɜ/4{WB l\%X|5* ' i#_:ߤ rE ȏu 'A`HwSYY>tq3~N%6)+r:^2si/ApO dq@Rhjb(%1(YS 3^ſ0jv8W> %(үƈ <hb?T׎L^|ɽG >jsB]4w@[Z E!~fcd^ 1OU-0ՒY@mG52N Wb)W~*j{%#jƬVqr]v ",b`]v#e(u<Sʓ'-Q׻?[ %R!/#Q;lU!c(vR\6|KL!;cG5y PH }^edIr״\7%dEBj@O]ʦYbgj~"w^{(p]GtQ>RRLk=BOZ_ Q`DŽ x1qm#kOVA8"r\BcI< a9 ax/cs;(Kgfjwzok^Z ʼ#zG7_{]eU8w2CῶMm ]o\BoQR 2ul-,]Qyq6#Ce?[zr6oS^_" w~gB2 8[Tc .d+۝z/Q_brχ6,<b\uXU R-›iU+nhwEzȣHՒ}CF!s@9S}0O+P>2hLG>N LC;Zgs87)m>Ԛ2a+׀tP˨TFaBTgl} c9I>>)1yGЏ%)*CUDp|ۉ)zwynFVߍ8o7s.dɊ6{,3{&&%SiseG4rAk_ =ؑ5dF?h'A1M)fx"U0%IVՉM{ݱc.dR|q54 \Bb=酘ARU+(uFE7TkΜIC&ժjpCno]Zts nSPb)F=F:ed*' Eyw{p:fBB`-~;;+Kku\ófJ@0yŽR=S|R9&Fv `~ܮkc>wVY؅_ kDf5z}x/U[) s2n,K|x'{R12D-9{*{l?{Hi"~І6"DѵJx#j˜&tqFAoHmz!+SCFf L 8IKyNc)^!{*`CC wFa:&} ƆK]Ux򴉣~Ng'wva~vװOÝ7&ѝ #^+MQG}q3Kkos .З?v1WOA7&%V^θƮD VC@CJ/αr^?z,Xeh/#o I*9I%SN<7 o]ղN)B4F̴ܶ9dd;MtEkPRӢg٭9yR~Qw{3;IPoI[q.\:X mjI6-U-7Ba:F4Y1XmiހBu9>F页i[h/:/S+l a alyǮ"e97TĘ]~ #PZQJNX0`:+~S(S ߂bޏ |3uF .o(] bM?ͤd1te<AXy8R5#䞟E扲MH 7yrUI &Ͳ@BR7PCO灻R'ÇL%x@ww{`\OJލ)7ve<1H GF Ŵbwu|mً:necBX_:0Uk]&mXý&IWBllл|zY /;j&0x4[=dq7S՜ީh:_!鲛]Wwى6/IN>b/QB0Ɲ3טZqTh yv/S߃:Jq]cboZgw!G̻zp1]cj_=4}mW>B8b\܄Hҩu~,S˰kom_mS䏊lg k/k-dM+s'ZioAo%{y0P.-J*sI[X7 2gbˊdNigv4џa/F,)1bIp. a?Dn|Sװq;Ln'%nxPdqlwi2q7Cl:M QX=I`@ǞhY-hƉ(O] 0>V`b2tmަo}q WoZFy#apKDeIZ|zߏd=R&aήj5x\b$=Ҏso 2]f_i`ëeel'JhRNu:m^T4˼D4Ul7(q+>=?Q?; 'rrUM1Oʈ|`6 EBW Q׆b<ɮe΋ӊ@R~W_A xfc* &NM]qJӅ>KYK B;"DQFNL&oMuz+H)<,7K)\jE"#3ߐi4&LksNbP>b۴35&u*iei]VHY1uBЃ__.ɣU'sUYvv˄SGrt >YAqpl1Bk/b.j$U[^.,_ u!(3襘 ŭr1_Nد|cΞh^hћ.İLQEd YObC%m.E?P]>rb\MeSOV0Xt HNXiPsyG UG JA Kވ 'Tu(zVc#؝w ҆dJ#E⎋ r/W@ L^jAl/NWFZ%?[l^`4 ^I/[|B vv)PG0< ? ^9d<߄L<㪌qLxDr?¶<$T9tQ& [:ޕR 'cx)eZ-'W_{ yykkw3 x?vlwhGv$ϩ^H,o ŃK"l@Y$ Qa/VX%U(1ܤFY\h%S_bTbãX=6`LF5I7fzc쁽׀MtC`=y=nO?'6]5Z\gӇx%uhAO̠[<=r^\9N!D|Kk.ڟ"x^Vq:Z5j+TŇj?ae]bC**0BIQ =(ǔl'゙!u~&~ $WC!1?*: Pqd4 |bXp&I,iH&}~=;%pLuNɲ)2S-=?"c؄B8$KTm乨GK̃t]wt/|G u8?)߶ZBBG%=2_4ia9ߓBX6Kpƞ?{y/ &QeOti[ò8M$Do'=BaЇۇNBH^ aجa2W6)bً~,al&P'#W֖'KxK<#lחԋݖ}BQԤZ5uߜ]Cǟ%J#ciC^ZՆv?/v{nMe攉&" k&6aiɇma#yWg-r0x;e݋slЛpuӊ``Q~{3/+28 *Oo=!q^.MgklpdtLis]˴C%5#}AvD(UHa"qnp4du2 W;N8v{Qi'QLA"ϯ,#P8ӄnB x-^+A1H*R8&ђ"U[?T[r4e%)>%))zojљͽvf<9xs"S~qt2o\}tO ˇ|ܰ2ٓd?G;hLFEA]Mf9* O:$g&>_V%ri@mY+Wpcrs+6(ly60IlKzAM B3H9bl\ȦEYol.kּInK iw3ضq韜fADQݒ=g]āh/+7xF>/WA1i]o,JD>%nu ՖQ:ӚPZ7_Lp6ɭ@I{; OWnNXʅPK%s|9.pZe/Tb|A[j0jR}%)rpnjN3,@2F-3IٓJk} P^bLr $9]cȿq+tPtQJBbDrAM&aǗדSmBG:·^ r~HB3EXǯN`(eE$XIZObw^̐>pS`I)&Vs1[d:rfNBY4E5F]tB<)kpLZ/l<2ϩe8Q* >M18>wKNjO yɑ|}`Kft|>=L}Ah_TPFRD`DTm% Tf!čC/=k'䱘{ɬI}Zxh,+ cBXo/룱gCn`+ 5|/bmSm[bi/5{Ӥ|w$YrQ#*/z{cT#Z`SZnO@4-z 5eCRQNa`ǥZ|D1"sV=W;U$ _p?ºÛBzD~FSz:‰@d"K ^3J$ei 9b鱉4/4!Z"-̾@dF !`bkN(zވ3wv+A_ c'40R[#_FuM۹=p B0| Ev/:)$&n]@X.)E-=@wEGʾbTl7lO=b1LۍEb#uڷV2aњU{ X?tkl{`2xmÿ9mT=Rib5ۑ;d1YRqf"GaJ!", 2۸+Ћh$tg_&0EKǰ *t8Z1OgA;1F4OE8)BgyR %Y 15nwBoM@ XT@Ϣ V&d !@k37LBEz>\4 潴Mrdή΃$7X$.[@@)ȉAk*|b3#?mǿ c*ef2M"*- ۂ* (Vસ8?$3_X"v m4l5C>6Y̖H+.4&܍;4MK-+Ŗgz(_fX7ᗍK W |uOF "0,tE  ]BI\6PL[h' K&uYsl{uMJC:z$A7v釨-%`SX5ؿٍ9<531J$b>rR">ٸƵYB ʺZ;QL \uqJ< [mV,"ᵭ}`xR&Xی*f`ɉ]w~>ռ ۄxA? \'mmn5pTXM+2Aۢ] wpᢼt)?w ,JN&f;H (2sCvC,?j\!wi $JREW0BB