sssd-kcm-2.5.1-2.el8 >  A `{U] a#,/dGΊ&;u .쀷1h'Q+3}ciAd;WG 0 {#>+_g>uMί%7?4kDꈁ*epVTr!hNp3}p ȥ6{UízC f^1a6c3d0f6208f8e0d91be987bd1e47ead079c45d3b659c3b1ed25e936a0777497232c279176f2ca3e1b79e3dce35450b32e88acc@`{U]~Odža=\ F6f@Ns|iB.:Z02` mXS"Ź_d_=?G' }.8꘏kgͅ/%-sz/~PhK1MT\ \uyo `kM3O"hmC`e,)rYyd\jz>)Ts ;㐔ȷϦǨɂs*]@hgQ m8i;F >sUIb;lҒܥU“zR;֯CL~KKOHSwh:'r 3'`W9 X7ZY~hRQuZlZoKfË"X HyS(n >pBm?md   B 'DJRgx   , { cL: 4::(89l:c>d8?d@@dHGdPHdIdXdYd\e]eP^fC bgDdhehfhlhthuhvi wkxkylJm<m@mFmCsssd-kcm2.5.12.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.` ppc64le-01.mbox.centos.org |CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxppc64le if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%,4ځAAA큤A큤` 3` ` ` ` ` ` 3` 3` :` :` (` '` (` /` /acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8b4e29a574d0d8fb18abdee833929707d2486eab2d2c21cf074496be2e7bf9dafc329040aba3b40acbae3d0b96b8190b5b710edda6b2805ac3f70495301615f02d5b173ac5c60d760bdc8a2b30a866e7429edf47aef9d047602a5ebcf76247612a036de188ab955e9a19de9d4b88a7847b7f1e55d62aea8cd00d38f33abb38bd3353b5665e3885c8992b660d53347c387ec2c93e46b34b1fb21b55cdc2f4728fa0385c7131ae3ec2df4b609d6e76728881eb18e0fb6da0fce602def11fb16a872acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcm../../../../usr/lib64/sssd/libsss_secrets.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.1-2.el8.src.rpmconfig(sssd-kcm)libsss_secrets.so()(64bit)sssd-kcmsssd-kcm(ppc-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcares.so.2()(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_secrets.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.5.1-2.el83.0.4-14.6.0-14.0-15.2-12.5.1-2.el84.14.3`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh svuk2.5.1-2.el82.5.1-2.el82.5.1-2.el8 kcm_default_ccache.build-id2bc37eabc2f1b42f14e457e0731ae8774a1768548c7fa6223a54e82c53c0d7a31c442563d8a1d09csssd-kcm.servicesssd-kcm.socketlibsss_secrets.sosssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/2b//usr/lib/.build-id/8c//usr/lib/systemd/system//usr/lib64/sssd//usr/libexec/sssd//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=8c7fa6223a54e82c53c0d7a31c442563d8a1d09c, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=2bc37eabc2f1b42f14e457e0731ae8774a176854, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix).PRRR*R&RRRR RR+RRRRRR RR!R R R-R)R R"R'RR4R,R(R0RRRRRR*RRR.RRRR RR/R&R!R"R R#R$R%RRRR RR+RRRRRR RR R-R)R R'RRR4utf-8999dfc7d861e3dc15e1613a3768ba02604e095fed354e21fbbfd1c749de31f49?7zXZ !#,p] b2u Q{LQ >$$^Gz1@ޚQ`1$ZdZ8Daݡ ܇ 5_̱39kȂ"Qơc\A|EsA\ǢTtQ'8GE'K2>>0?ǎ"Hܶ0> p't*[4?'}}2i&H=bG'gZH@&߸ 7lFt6K J= ]-F@X9G-+wYF{'_m2NCn^rbeeWkLy=k i5^=$ YrOmI.1ܔ+6BaTjaWVj)g(MKQ7c #6 z|ׄ$b+Ϛbuˑ&#yUW^.yXUXnŧsy{dMQbZj'tgN<G#NpW'eN0mvO]vwJ G\ +']a~\[a J. H VB*I5Q5RK˔LOG7w%?r5X-f AD9XKXvD+5Qwh`&+dj3AuwB Xw]F%^;iN=.yǑM=5Y8LfI: 񬒱 Ux LM[ Zr'&I^(dH4FomjhAG=gإ ;7h%6`f(p?$x,FIz$w8ZC0þL̟xSs0iW4uiS}1#eI)Y 'tVHbw8+lx|W Ebp"=ZSj@14o("AbD-F9v%*H8D$8Dp1G1/Q1Q@+3x4]q ͏Av sȈ3Ϯc _ycmެ%C.|lJEMcT/[+ )FHy,@6HeXp 5i~7"etԽkЅk/@Ǒ[(`;uB*'ڮfdj Vakυ-1!h=l@EBړ.\SgGAIkeo ؆Cm?_yTyKwO~e`1! ?@.19!K]<"<g;NL 2T,C\I||1f'y]pX)P}}opϯ{HʚH7*$EK 'W!UCaZsIlHh4>ӄ}S M5RC0&!_OTgVL4+_@G)x"F`@P)BE#5G4_,ҫx~Gz:$9#wl xDs>ܳv4D2kzu F(vg4֫RCSo;:I&nQ#/Ṧ~5].H F|Wb:n{)Q;+ Τ y"KY/b*l:!6:γNkA?`:AC#O#x{7 p,s'nנP>0$ .fS˷HڶcLC\T0c(fQD:O/9"jw<Jdw7-rmVnꉖ1\?Y6F^@4=AJW'<L¼jUgcDxtTqz.\6U1"vE k/G cCQ5U*`C?*kQb޳0㈾k!6&Dn ΔlvGn^`eLms46 gStk^Yq L* `*k<]t ?Z%*"A*EcJ )Y(m.@k I'.@~!zQUķjDC‚goܞd{A}GI%jad& evBD`|/X| ?JMBaMpsv`- 8d~=(x^|?^(eG9C-? lshݚ̭F^7-DX$']PbӤt>]afCׇRL%;o@{%=8OnRIⳔ|}29a_ZOM@^ `V4Xwք;xXiGp]$T'܌छjb؞:]ԆCp^b޿/?"Ĝ-UU -j`V!zQ1VNl&[FZv4z ooA/!rfw*);-Dr>*E*DWIvޙ2h><鲤k+R2ۉ0i3~JSiF9CRdb>bͰ:ul\4I+\~r`F4[''$\㇕ -{W]?n^3W5 W)ebDiEPuĂjk$yx/S σuyW!?܀jOP78NNG .j~ef,(GZC^'#גGS]iߌ>Ӕcg (*ç2-n.%Sd QiѼ[sO43U)F#;R/$RjdUY+Yh`<#L<|apSV֧MMmKI>&G<(AJh2 ١*qEgn"3~5`c?<#/6\O͢kRxZɸ_m^w_][5Dw ogL4G|;Gst{sdz?GE]NC 8MZ_ر&e ͺ7=s/Lu@-?D5HCH衦a)R Fh &ZPRLzoWrR^ߎfae8WPW"j?H{e>kNWMH F,.>uYuR!lժPE,wں <' Pȭ9l!AfC.hm5/` ]K.%I9`kՉ+t e pWYX/ RvdӓG5#$WO!̣f(=E *ԓ.aǏ!ˎ y=N?N^a axOcrl- :ؔlSʤC UC>{b1?a =*ᝁI,mRj*0sM:h8JW܋$tIƳ]X_ w2B A}@(ЊnudHCUHy8#@pzJPS5椗LA1N~`'OEE,[t2/\ʛLmh1h8Mg .-LmY pHfN-T})mD\W- }lhI s."2R/h=UEs*|>ӯsј ?T+fT25e}=iis)%*ioGWtc;煥x4vjwe$ xsdIkߡ@_ [:6B  zpJb Y(ܧH',@6::|=CzD [H]2Qlb%ULC5DŽĢ:iXxQKIGy==C&hf#;sM$rF?f/4''`h34ea,>v=*AT:"7䍰Fk~={Ϸde_<iqX(\wh0/0v x\.6c,EpG e4GcC")miHav3s9nEct 1Gj0UH@-O s 12oPFZsa3sj^9( ꩌ~qZy0>Q?,T.K Q, C6߼YyxG>4sѮ]Jn[EC5AܕM )P6i }fqFcMCjɖrFkQ[/QV!{Du/iػ\VH7A" ĉ懲%O0 a_P:6Oz YWQ>3/܀N>7爵Lf3'uC,H> -H)Ì$v?tw ĩV-9ϊ;V*vD0ٛ*q'Uǀ_t.'ۉ Aiyѭƻn ݙ`POhL.^e'=+<ɖ)#딢.q{2j)b4Xe6]4+M>,)<ܾ۟+i}sxm,r'E9.I:䱍oB4P4*S%;rqd} 4b7oRLC\F/khV71N[z0U<ٚ3D?-#W+m+()‘y)1'8h$3Fvoe5)RB6u>I{p{x0IX~z,=Kj=Ш{uCeC#5&ȡEl7W'9Xp*ϡ V\!)B쯱 VjX~H1wyq8,65oed+s؝ nreeJ{@{:ppQ#v\(*tZ)y9,41N*Zqk~xOܟbP=I]\,"_z|ӺULt?e^ FP0?!:[Jളh;?c%!5!-}=T7c%N ]-<[o *  G .* &G Nzk~.Art&ڈ xi&CN:h`4-2ǫ˓.0+!*7^&h- .Uwu*c|\; ғ;x4Å{X׶  1A}-_' T bo-XQF9.$l50 3{vWV(^}TlrXť, h"b|a5٘Bf'C2`s^XH\^Ш;*ErjT>$RPnAV8a U5:}=p^ZmU{+ e=wnc8iAAK-) Qiqw kuyj~fJ8ԆAk>F %RK׿?Ȇ-IJh\vcVi[TNϔ:5>53I vPo&|YG(nzhaIɾ/5.LF\YB; ΋m;ᦟ;li>`I uXSϷՁ"\1h?+kKAo5(x0H.&M*۪5PS$!> (1{g9fQ oEXlIuA@Sl{.x^+B1I!kmaImh,;BG1 C%ӐΐwK^!\2$;;צ~^g΅WDt5W u<%t3ϖ5YBș5X_ uVCyZ_;\Ӄd6>>LJ0 abd5! ࠐ`4H6ŲW`$X'9ua<=xgT| 3*hGd/[ NiqzIAFy JPz}zILSIsc!Ż_g?NxdTkC`l63Qױi|wDafC䣛Dth.< P QYyLY {lM1̏ssװt10BB][xFXhlWuRJHb.7 |bUs ' f|!Qc1sֹ\@C~Sf.H1 JW=upcΏ!ЪE*6lHTщGwEĬThQb1U\?٢?b&>/嗊Y9$$I%7$U+$(s|U|-Rʽ!Ho>FɼϷR̻"*I"QЍȀg7(>"c _;MC! ),39d]]|$tB9[jDܚU؎@ͱ;y W84$yDL۸CK)zdL.T=v l$9fMLKe{*mʭLvr+IS[hce#t\li'w #˾sMc/rZJ>,&ϭ'H$W-"{iɻQ  ޚojb#ظ<5!~֔V$3(OR#rTUb7z7[YH֔7)U\='B$E h0p _DKU]/ WmN5SdM;6pyi+'BFu v̬Ֆ$|CdZBV ]~Vy #5aCK'>}[ dw˻:NdÃ>Dm@2"o+&?_7 GAÞL'ōVB&gi<Mg( De9"/`/Rj* B;4}FoȺh'EmdfUIؕ&j7ħ^F{oD30?UwAr{KoL+NflWتmlߢ8(l8('Xj`ěû=Ga;ɰgzMC98 jH$5x}`o?(9;&ԁsWRX:YI87f ˏN'jUv~)rܵHҨE{<4heWHiCnG\x0.T,}Bz˼`"ޠ6e61y|;>J/ePv FKSDǁ&O:O=}phy%Ž#ŒINAZ@SA4' V-KeuOY-}=-A˰St RVI{ 26 وuO5q.=,u YȯQYM w'Wꠗ趨p\sNl]0]f26hq}b p<ge\)TyC s2nŧU O~Ƴ\ۓ|)# A<EI)pYZ^tud%Yb&nxHc-Q<4͎E?9CFMpUd`SiLʐ6%QfxԱq3'FCi:c=TDyXorB@N'HUICZj-<2OG߶rKQt G8$-Dd m1Pل殻-'Uu;G6jg/RFcpb`ۂD c_aXZ`rm&O .@1m 1js/`aǷ_xJсS_@ӆpG}ij.s7zGI??8Бf8J2#lU /Q>@vWל[OYU1'l90-O0VٴCO\Rz%K} iJXK9َNnV."G{j(KS  & \) 6}-*@YWx2x'HzK+>o]6*lUSr):X Fp Ǒ-U0OnhěmH1 0TzQ G-+Iҏ uKGac4Y.kr. ]:P1+mc;*chr!}: XjZ6_y~/, ?{ca[zz`E.fQ5ͩZWdmox7J/,Et@uCwu)oVZZo 8]ȳ7.&aC㹕l{:AorrWk-lC+[lMx!VXd] W-OˆRƷ~,Q"(VS OSُ01gӜ:Ӑlеm Έ* (;EsϧblTcHIV4fP ԃ5ચWlOH^y#篆&5]^4aÖ/a(3d:aYaM}+n{Bְ@(++F~טy`N_:r<.(F3dT8[-wr p @‘ں:/q5iB; ջ9j̖LYhЌ řR #bL~[O7I%N8ϔ ̕q$6 Zx @{h;c'J2 fPˉFb{c!BmzxC $UV͖ t#*vIm6mq43$=| Sv+G2:ds!9իX(@6󮚢gy"qOanv3 =kCj UwiGE(h*` ma>/"Y/aJ0BSXyxgH)>Nx𥉉⁨&Ml(4i9Elª]RDs%8L$ۉ#_E1$o =o|;hYmw^OJ-#M6 CcͿۊPzR͉ro`'' F@=W`c̛gKN剅5I!S+k ַ]6-ViKEoۅB`&FK&GLAB&r4" ӌ/s\ʊҸ 5Lj^j''{/O o$Ѓ :)i0hWE} loħ;̲\)v 1lE]U4f (gSϿˏMN"m:)Qϊzﺝ k( ԲhmfN+TѲk  :C_ 6 |6Hq2DHw OR)P6J 9sy}c藥j6\$h( #[)uzG{*bzsRc"Ĭ{յ8C~Ms5)LlX뜕'j!&|SpwFA |L̵l4v3D"i^*)Ȼ-A=N5nϼӦOYC9'ylHД2GYG0VT1G]2 ȫngamƈmzg"ס5ei,n}Z"b`.*[ŤhVQ!(d6] S 0 ݩ.E9og0<\aR_$&QhR1+0Cv(- qYtwB[ 9 3OfMZǖP# E# 9m{=en$#qEκ'։3`ÙʞyD38_Cn!xbbG@d6s^_HwtզѮL]g,[@WK g,@KSb9;ͨJ7bܐǁ Ato*ݪ*GVt r=VUk\pSf:''G ;P \l7Pvvz- ȇ/Sm-#ݑ'I =AEFS#ԣƚݮQpEUbsnh~i:*؊<^{+S,k+e$tu_(㾻.4W^;oE%q_w5Q&$!j0-Ēoby!Ii_tc^W뛹|| _z9*/x<-'<476,ImB3`v*Fv6t&&WCWpea6og9cwGbg69@QK9"MBK–Y.{t|Y+l,jS}h8\e1u Se2>A=.C_򲒷zZ)bB\Pu925f;I$$UΒ51Of8ϱ#B(u$O7Lz= 3G9 #+tA W( 4u=xnWA&W ?eZ͓TG &1"]6b|5[4!K8ʯj>wMVaK!msY/bxi]*O&F|S#KqP9u$> zZ ;W6)< eُ9+\A;w+m-Oˀ>m⫰c0!aTp{@Cw`rXͺA`R ŐObZV-ʠ!.vue?M21<ԔŖ0Z&kA&"!ޥ́, $n@`Ps1Z$~UT5BF;ԔX؂gH`{7f\8"]+:vv᝗B3ZYZ p:Y?uc@C\jLTw1beӦDM•ؽyط1L'XKЙڿNu# 8 ?rp1z:Z ΌnU$M~T˝eD jNtH%\pۄ'~Y-%sV%p[ 2 "m[ӥ0n7hr ZI7J׋ ",v֝,_zmP[xfV"Ь_UH}-+\vT@e%>*.L͔x"kB7W QKUIQOq 7ju=̎Kn&/3Z#]|]Dsx9J2]0l|+l:ۄ蓟^z7ۆY,ɧD%5U<PdMi E7ZQҲJR}+tIلQ@T:nN?a )ß2(@5j-~jؖE[P]qS pۉ!X?;qC&l"PWU:H5U-Yrߒ4G9RQ`OR7X#3׊/C ~or4m/KԋTi Z0bwWBy:6{$kgi[Px`{]"})K* މR;^W&^ z"*&M;Թ+')薇='mī 7K2oA%/6v23OWɿAtVQ5}EMi?؟p@f[fx(EL;v. [FTPy0CP6SuBɦ1vZ]`߉JLoƓp=kD__HDqsɼm02Ld9bZw"ߌZeTY֓ѐn4|\PL1 r7Ғc@"M}-Qo p) (̤~&՜;su(J9U{pϦwZgpN.ʎK|HY쑟ٮNdIMK5aO@.Bm݁ڰf٥$S0~mJts%?]aOfRIEg?={rp[[هF_Y0$<(H4*e5>d<.~xe7^~ L|PCO@a=K?EjLj$6W8o.^2BL8nXY#XӦ\e"<$OjA`oR~CWfA砲̕dWhvMSh044;wmF#}?q'v.W0pT#Q=sy{pBoOg=,'YcT9J 8iUt}㷛w.9G63 F;!Gr2 k$ݍ$qZ-KSˇJ5Twօe*[_$G?M̈́1Ҿz6Uwg, D?'ѰomKҍ,iWLx$wmgI dWIb:$I$5\I6SoI!t )i ڬ>KAzbN63W) w&m[I>)\]&nd'q>~i}|i>ǠI?bjj. q%c%X 0EA>r=bz_⬎:FSyFjFOF ++!L¢sq֦m?ՁTMVfk˛L"sHGƏ69?Q" X dKy=<mxt۞@'A&NSjo(Z>jitÆ<Ē$Cgrb#rL'!}G}CP-}F8K=u+?KXo9A &ȁ9"OrdBGNeqmhu} Up7Y}8=9U".= :CΪs|pэ۹C{x}*4}\g05.:$:vשaw FǿOHݭG#Are̍PX1 sÕg}վJ; N2S}ujވ}&;b 3AlQt s_$ԽXqo(g?]EuN1ׯώx:`U/栁G T,nvI(pǜ /U6H MPyz>y yXI椞B@Tx!Ipν_lp<;y  F$yhuծ;4X[k|Nni-o!mN;߳O7 C{T@P|#w $?I-D"rg\d;  tj|b"ֲGy:Ǫ`g9`Pdp vdiso"sП!|n3z |zO t@ɗe 77_L$H77Ǘ2CiDR bM<|Dh@?"fvDTN!، cˌSO D ޝ6Eb8-dK ó n7SW?*mlDq& P@W@$ \ꈊ ]WXBEɖp!j{i[ofNCBύ`FLњWSώ!I@4, \!u<˯c!0Wt ^<9_ ^oEbn<W &00)UD7 Rm6#nNz7-c_.}P4q L5XEʾ[dj>vTwGu\m\aq>vE7唩'A7 ! n+u̯ɍ٤*`m7Cn4vW"'vo(I5G3%K߆=O`&־?*\ g Qb?Dèf `ֹ.bOCٝ+U/R^yգaQ0V'54hrLs"9ݖ (됸T Qb*ڂ0WOx=80cGIôpSoR $4^?]򛄝tT(Zу7l .&6B:a4_(<GF/]ρm ؒgHwa^d8;ZZi@]s~V86TJV}@4쫃úHr s|E|.d .-gxw6TG@m<c|?3.9:۝\+{I1r'H+yiN"r!=?-۸o1OC0Tchg0g6[qlP.iMb~!=Vg XX>U۹usY BLVCp-k^H# ʴuD+CjjZ;InMkI_gm)ZqtHuqaRC|ْ̲12Chm_4niy AeRF~ztMzbnrk:l^ʌͬmeeӘFu8H0a0H%10lUE{}'\xΙAAgtBNjkgٗx)!姦[Eyہ4OvU7M)4`cߦ<_EA:-҃+אXI]C9WTstˈ6]E}6֒w!IfH*#6msYs`D]6K BCQ7X5ΈWe.ԭ eZeOqUH|=:eul|7k}@\}r"s]\ z3q A6[8ڸ<՚qN+&IWz)fc=z ٭.7F~=u{' .C?NeJ! Y:"É͞W.w:plQ)$aîCh~5i2 ԶlP5d? cAm$k_똰{SГ_FRgN&15/I1 F 2P9/+‰"B땽*b. 9K(W:w9\jَ>>.J9]k ^㣢gx4?D4_QI6 q RK%"K>b|VS5 =eqEݍ4a`$5jE&@FէSrm(Fnӈ 8b SϣrFxnGhӨmO{"87;@0Fŋhu6LЩw&pgKkȃg+/sB]&-mt\S8#^q@#]Y%`W|*$gJcR76dzhb0|$p!L CR"%Ϳd\w4]@ym1骠ڨ{B"`]ߔDrfm ŏٯ<-Y=o:0 M#4'^>sW}LiV{[ ivbVj5>NDmCi_ZߙxZM#M1fe0 p- rA^#z ݗ[CŻӒcYJ:=cLCyl>,X.?(G/<UV1R&҅cF5YETJdg@G<{ǧi#ծ} $hGF" ZTz]Τ;5/,NOVU_Sqrj-*0I#?$4RoGkf$ te<&6K,`_l FШ˓ DxhVveu P`Ƌa gB' ۣ ȺG? pI98Ƹ6M\bBNO6y(XAku͢Յ BSQl CTd02X0Pf0 q^c 2pemaƺ|l8D;2ZY_涝šg:2 ~6=IО9~3џWQIzmߛ3y6=2KhI 2[ ZxdYC'ݾBm$<(#u q4󅒮YS/mr64ojEc o|F:1gQYw :T/`V(8&`3y5F!,nq66vTew,lWf^捡kZuxvģrmMv4 i pUTiJz~RJ=gP; K;`+5mI'LN/rTY8`> WlT>XA믔K5٘S \ۄ f>!|XnBc\{^I6O邪o 3 &9X88:j! G_G6@sKYD,Qя_c.8e! N'a/֢IxOTG h=+G E8p6lo =t)+o#MwJl uC`Fhȟʡ)Q乖bt[n<_[cʟ*Uz}_Όo/ ܱ+uCw@k ?8H d&-^0y >D@stAd+dzم-#x8 i2UOg ݴĆ`pF{[!_& ZJZŭeN[diYMzOsAL3{!I~<}/o4ie˟tXL?d/~$bmIC!\-+mUd͖Ne2OhV1EYa-KKι4ᭀ>}CJ?u'uЀgʐsi9(<82е!us$3"fUɣ9e&q2j2ʊ'c0 rfp'S'"%7@k'>_ c5WHp?,&my*>[Y10ya~Grs=*cj=UYlR 7c\:+%{̩ 3\k>+l1^Ba O1J #E"Vz%e3Te/ΉFW_^ 4* 3]WM,j/32(߈rC Ƒ߸e_W !_dڏ$x% XΌyNcOT%ɈGg]Ǎ TMȃŢM<]IK iJ=1!ykKn %ou:_,'C1` ׸p_G3o*`emuRy s#LUO)ȁ*Z[nŁؙOpQs\~8o=ϓխ'3whWasWD-|=x$6wW pJ+@ B 'R 0 SMk!!Fe7hp w51wegj j$7|{+@'Qf|X$ e\!%Ruʩ.#K/F YIC` g/mԠ˄È*f ۂΚJv?`GŬJ 3d0_ͥ: ҖumXw#3[m#cZouSUx [yȃ|p,)5t8t"u";b|lPtA ř/_LW2/CdCzi] tՉ'0c v*aV'lűy 3}@$.Vതt޷b3ɗEwr `q"ػq}cPbkb%ǭI98whѷ8jnO0vo7YČ3< |~j1wS}0Sx q<㮝ʅ3hv-j"mFOK%hևѓ8pӕ7Č M{㬋q傴iɳ?AC Ħa!NZv}S <7<>0e.둋z~nI[Ouߺ!k{%=,g,#&W{ǂ!AP޵8W1;oK_î9d!O'SQڷ⊲n #''˘(Hq `Gx;GB);t?bͮBgmd&7! )J>26,9׻> =TgwbJխ.Lr9MW9[OsbzXyM|[T6_=:Q/jŕ#Z1?jd5MM6UDS(C.&P[iŰ\=gjRʞF&x rƅ є9 iXnUR YP}b=:y+A>Fd}-0@=|'}!7]8UeSi5MCC?v(&H/8z@8MV >O&td ϫ[rmFd7/y'Z̷F Y )3pH\qI%{T[MwC3wSZSϧ}TfqR Ҕ?܆M?L~[aLם klFz+8y0VeF&7h}cJ@Y§AMY r!3rCy+p$ "(ڀF} !<IS r?M*w5T#B3WPr:J%WދE3۹>KQ}|M1/B|E9qiCy9[50(R/\OyfPKZb٧EV}3 ZNO ( cwgS~g_O<9h_HI N =G)k@84(tynC4,@Re6JPhF+WPt揱_%)!cqs3E8cEݜ炔 g_gtB<$r,pa~dz12DZ$uX,,toVW[#:Cp{T$%Gy{uRlf= vFeM=q޺gmT#|1ޖO[+a_M:d"2@? Z.՛E_O7J"\rάkYMLWb]IQX @1GWI`%5aZ8PB=ܾV%Cʟc u L;LU43L~-0cm4u<_%b!/ӧD =|F\ )rT 'UVx]M@b90@F-= #a#"g{%q*b1d q8vian cSs. $p BW"S2i>I-5K['>0n7qy2)x0a+9n8~g ,ѵ'l$t1F1hn>WJ>FVG{IԨUˆWrFpˤⰌ9Td2펎WPsxNbyW4+ȥ D0s:|Db*K"D%m}ˎ> q_u#*lZje\yvofN,TnC'E.}ݍ 2:]Q_!l.ׯ:,"}} ?VO` CZohCeq^V:@#ge H(g^@3-Ɂp8lga[[]t`?)'qʺ-'U)m4Y׫GRܔ6XQiwwcwF<϶uae1%twyVj?j-_^*'WECJbPfW;c N+t0+#$A4rKݪeq{^I]lWS0Z3p8KSXux ɞLuPo^y~~xj1qnNI2LsWhfTwh@#W߱ЂeG.&ҿ/,X[< 5PGi17Tѣi=4JV c![7Y9`]#RM$oˇ*B@[;œl Y+ Ut':屶+PՈH^N2sb,FKY@[;_Ձ] U^ͷk@ZCvI\H"rrK*F/ьV]iFQ GP2ܚ[m`14t4|f^.LiE1Da<+TmGoL/mFNDS;͏DauKO"ٮ*fdoJPPDm:_aUKIIiN)dθiG"%mH9cCjߠ~UG'FoYvtoQ盙OIe]M64ezWbw7z%sG(WZ|pF,]O;?ג` &rB!a[JjmSSz`/gw Hq MJ*&a쏰D frhKʹ $츺;?d`j/NJ VJe"hp|njjGpّe3+E>D%58"եۮ0+zyEG$%k. I@Cp+!}3k-)50cI~'1mdq\-9 7$yYs :R>Yo#7E%ˣ6̉[2yx{ 24BЧ9Y' ,<=f)&DLi}$&h.DZXf6g :є +p|Lk 7 ҥ *2CH _w_5vԦ].$chI) Y4)hG^{v/Ir,?4bdXyOн |@ڇ:.>WD@8ת:jɷlLeq!`{M Uxq̾ z:QײD &#bh`b߹MDS#ib_=$9X_"4I?zu|"+ a*3lIPi> (`PDyp {iez##2SAk"@>J=>ψysCh`5[vsA[]1NMhANYS fs1n[*'-/3l[RLn"TT29p+PHun[V S>#+2pqLfe״R]޹$ G@PH:K nMhQt V|^Rd<28YaV!j0|cwU `,ү}4{:P@C xRL XV|ddg08xᆱ$a|=dxYX>b(93t=ԼR߽;I?4Q.eQBޑMKS!/tjukv"-2"Kc~D ǰp!{f6g݋1S-|R4`& ^jm]  :}ƭsߨY%C+~f[s15O!ADu.^fRElwGutXjE, d'G6ʺ1B@Z얼R{l G~"ǹqMB$ _(BpnI/Tu@rVWL>(d}Ll HZ~Zorě~/μtvh/SwX,ÅrQJj v:Zɓ+Wc4@nZ 6iQE@ _[P>6o^Հ_@00:Al H7ZO=C M[қdhLLȏO* C.&Y?Aɦ&e?.u< [ƊpPB:G{feǒf.Ca4u棧 3IrK \i+NJ)M/k s%A@x }n|NvΏ2ڈz;G&ن2 (A{ .yFYzv?k,Ӧ hQ"ݖyk,ŮݘmvjΑ XS3?EbWjԇV@M\DLHWP rWKũ}0`TiShgg:cuq4o`˵Ⱦ40 ]h:،F:ztP NK@ Ϧl+ж9ץ" k,(rroj HĖ=  V$RIj}4n1U~E.DnU}B:;_Q)R==S}:?ZHTwp3M~ p !^酁\E⛃nW 7G=pi%דzޢUO6ZJvOFnmjX "mB \ZSKCwP]]HN@ps267kl؇ԪgV[NH2Rr[Y?j:k@Y:Ċg\mm"C]EW,tÍZWe0a3(CݾkIxs~O5]n_;Œ)Z$2fG_W" [q*ruyexoW x42㸛0DҪf^.*ФMQlVq$}q*d:[y^S)uԜ.UIiD?iJFbvHq*uzo1#rGpEVs~VV+S0-ZqɵLsJ?ۿ K+AEGQгr4R<]%U*/RQFk vMCi vOpԁh@DiZY]:&[ێ,C:|#;(!˃ >+$͜_ VȡP_JCUo{brK$x`Vb KRpKHlNͯ&' Zu tEEuD`#)϶")9yT}[bK$ r)CFJ4Uq!$}&lRtPHɖWDe "2ꕻm,՞n5 2i0x %4Wu! anKxOB^Q((PRǃJܕ5&哋~^oZBLS12 sEy9{Xu=452#܉@,­B`<  D^>-22&D蟁 aYaC?{a+de*Y!#v|o+7W@JTCj/LH€ұXj\SᐿnGYoF#{v"XE5Ev [b,'go&Zise.„J \ŀ=3d<#DJ(9Y~HN[} E 7F!: (Wط@LQ Kqu)W JvTTuGYC>`}ˆmf~~:GhVOgbuQ_ۚ$(Vr~%mt2@5 {8q#zD_s/;:,AI=BCmg#2A~Pf_*fk>ݒ\Jܦ\aONOc|# :eUhES:<|P j]VPz)+J5JݣI]+l`fD*vmI XdҰK}$(<&e4V4b!XfaE[X;]GHF Ve U,}N*2ß^A AP ;1sϦSpptXz4W-Xь-*6 vYon>\ZL ٟtm\^SwT [V^!py3:h02̯iUH(65l[O\MM?ee+Jf:ҫtU"zgމ[A+r#>p="I0zp2$ UU8f}C̪줯DTxadh3a-N.|WC仸N˾oNo$V>Rܱ3rK'G2VP$:kaWszx ZiZ Юδ[L=Fl;,6ְfB0;a6}E=gs,Ȓݒ`zsnD$ZKc}-{X>!%48X K/NRɻ!I?R$Ԇ!*Y(~fN:>+CnCKXoN׷uCODصb}YaQ{"mb x&_MoFsv~fڋ.5I嗟$YxcLP@ )_[M<.SGu,kȎo @Ѵm6J<.HoLP x!|+<բ)=ullG:.H0Cm7c, QލRsx #n dsh\Y/8U(iA/>C#3-Ў?>/ژ[o~xXq@tQJx Y(0b[)kf;F׭ԇLW>P&2Acޤ͐ J\]bu=8'^YGQr tM%gUR0je0(\ݯ)j,EP4|T(Ƶ&`vRW3orܼ!xsߍ/n%\~HKhPg@N }8w<4윓S,ł}6}{bHS ?fn/;ryYW#GGMJ&F*7*9f2}e\q 1OPjx!*kFbjӱ0 L4NiAX\ެe90㻻X}G5siXgwLchG-$ǟ1 :nCl$8_IЍW@+I0הi2UKtJx:Y IQԴ$qs֋N4kH:p?g\s/joUt{`ۍwk8҆MJ\TeBv-۾:DP '†d?_X]l>cgm ?ou0hC;uɆdHO Zx[؝3Uo_> 8 QP|A l;ߋ@vԄr]Fa2/#=vⲮϴPɯXW?qQWl_O^W=&L_ &Pa`j4=Lwpv]h2/ m16Vg|es440  (U8A<);,'z+ŝP~ sNѮ+Rl6cFؘI_JA[4J͙ovx޳rrE_웆=,}Zg}W\uF3S_$4%Y(د} ]^}1bФ~? +Au]w->]|޴Kw 9 8@иj _{|Ar|jh6ߤӧóAFfScQZsQ*b2d!M$+{̲zYE7ʋq*f,ci"9W#覹kA ; @v]IdiɰС莊UP.ˀ߅-^G` |SyR#SQ$@KZ"t3`γS7PEg[,B 01o"OZ@zh+ BL"9)w-MO X+;LU#GtaEJ88,RF_Іzzjcgs#`Ѝs&#ĸ(Bǒ*Vt=1=-X{L=4a/luS(-[틖oWU&u^ƮC~SKXTˈ؇7٦4>ȗ:I ij$KT7qfZIǾhz4m6{a?9@D p$op+n2pQ?ha o"`I"P Fܑ>* $tL]:H>.G!Y҈O CoilN]ţg|j#kh0/=xMzvm?߬aȻ3i9:.]|jZҝF5"|2S*]V!LF(L灺7D?˶L3Tr +>ŅJ {[a0$!"dex# O̷K$9D uOА"F6AlODI-7I9ZZDKGsQILO1s_M20*N 2K*rZ"&Z_ifˈQ%UxuH$C~[%hw{3'V gE56Hv:}ݭ01Hfn( {N LĐ.]YֺCf^ݯ36ql\I|ӭ˕|JfhW OwQꕂ;o2h_%TK5aHM:LFW@xثrE;=[J_"{jmz=* ,iE'#O剾rx@7IۍtrsJ{ʺR0(x-Ob}_NFRZ;3wk&Yq(xV_H;lEJ"Pf\.[)RoMGD}s1ϥ٧B+#dJi]wPa{nG43& bZ1??{T (NxDŷHyQwЪ9_ <y+_z$;59RV HRwV 9s)(F $]` *rBso:6:B J]>×r7[?rĴ"]nM% 6JRVulHY=.Rڴʾo$LYK(.tEJt&)^XDc@un;H% i Lև㨫e'oaoVs û]nuq+s#Rv5#c.fً vRz6:.8FKzo$b(9McNc|i/5Ϗɇ%t!QvҀacr5*].bL (u88?@0[kp6{Ƌ]R,7Flt`E Z9Gw7~'2r3lLSWoTZ`>+ԧs‘\Z >DZb~hG9~%V'_1?@F5fN!FSc^+jȂB/HUq}(K8b_xF[@ۃ`L œ8Pyz!IAQVoa4<!/y,bX) מ,9AZйi$ $EL% jHKYd<ekݕ{vh3$vN"YR 4:T[SrS$Mf1k¥Z;Oج{ɤpgGOzk4{֧VS{3WEhM6yU$f]X,S` P+oM쵴*]ϓ9olT0EւU>*"X~ &EI9 U\Iט_BaeMW͚s=Zh은XǢ COUJ堲ui \YΥd8*0G,c?VoiՈZɇw,HQ^Z<:=M>g?0ڔ( w 5'~3E?9%#͢dÏ+!4`{oŹjF%Nd @dYxHٯWZ;#q>ILC SF gSgr7#df $!aml2f$b]83&"Up<nՠpRZv(%qU!u@A*@Odl*/Xe`8Ӣ`Q-2eMQ7=>zqAk`!Iļso=eH( dD֪b#uSz.ܲOOciS!/SS}AF,r+iTdɴ2-# o^}zY#tUsr/N=ym3AoRH$ܗT#SJݕo|Sc BFK7`Rr~ާ'rc2`Q}Diz,2Ov0-SC(ׇ1Bd]v$ůǧ=0q vMw/<1-zzzeT%rb<<',- Y6W9>䝞ݩ1nxm!?/%ԫ>fP^5Nu|]?zi$[&%>k?Uk"WlվPRTEp_dJi6bI7mif Z^XkSvBC"ժOt ksQ2R y[ 13}#iSiY#^ގ`qΤ'4;}JR);dLI2$w GTf'Ax];1tLx:% P}n&7䷞  |H׷YFfi^ 7oQdrp@C@#aJ=qJ+E82Vbt-&Wh }vx'˝Oįp)mY}^g8Ѷ}xF$L{:+ Ad5a~']`<R! 7)]S3Rb`*akJ+i34ݣGԚWCTWȱX̗@^=$J(j/չgY*ASʆ+z\ ȿŦ=Z%\-lۄ™p 4բ^{ґD.R"$7|l.Xx>o:/zDE~T HØ/6s}L )OzWZ D9ΞQހ,o5}0+ K({v'ab11cTӧ{I2-FQHnw_=PX2}q|`(K}?Xc\~Mvcc܀ Ƴk5u:SEvܿ/$ͭqANT[XuJEe?6"XR'mz)NgWH !ɿ[R.1&̷QwqCZ1Qԯ-M :z2-fPCJ@t iz;$cnsk!N[?Z¬"A Ipz!G!"t8y(haPCtب6~H?đ@Oב zآA.5Ң-V'`q us}ؒN0~j Ey[[}CUj 8痳gh _{c4\f7Wg(RdqܻRϽKX V>$-{Ã8*Rku3;uw{r6y훾nc!.`VA #R;Wv[F;o2EI (u4Kd78w"&d/[4^;!}})((o 0\/wq~",-ϔ&`k! ^%Ma.1FԸoZsH6kx W<]Dnt9ao#[G1sH¿=mg54SPcG<6l$t U/e`)K ;5jr?@Ǻ ox(WncR xa\~'|K۬G750/$*.G W׶Y4u.SY]fA+H1e>5f[[8(74qGQI*HA{ ȿj<|Zt6פAC JXfz:Nӽ+R}|uȅZ: xOEuOF$ҏ%J0p3' { /ūv̢DyHdV ,tQ#[3 |kPA=e1Dv~Ew^kxHxv LREUd}e&C#wKݕU69tڍRuރRo]Y=T>.tMTiDӇy0n^(Yq|s39H2S9F3ra\rXx 0e#^colrZ[U)K`a.[g&XAM;i=8K5i.>ވRXg3lv-T0p _) `|U|J1wS( 6^ g Sb /Ly^g;BT-yjjvӽmߊM<C5T}*_#z) |+QT4v<;B j>!wf6gh{znQ \%qb1{4($CN.tIaF:x*B7+"&%:|M 6noO][Y5cs׾nou>FrWWcMR[srt[E] 6< ">w/o&}#+^?A3?,]o&eBһ7k:џs7 <`pF՜IޟG)1[{7`3^لj%"qJto`KїdK^l;Yd` ÆΉ'+@(.q,B FZ x FBaS|e!l6=#=H8D͎4G|Aipҳ ?i\)fX :76w&_bhmEO?zs/ufD}(e;ҋ. qo:omB"V% {9z_HRv ~[H="K?r; 1I 6lNC *iK-ѡ&ZG~̼}sLSe1wkv\ީS"mW|D":C>` qL@%o7)ff8UjVg3 Iɥw.J+e=2t v]⬄Hk'S9/8}Λ:Ny_4ǵK )\fθZFO<{ hȩ|ʇ0uK/ǾBi2DŽBE`+EZZ;A:۟mL3qGJT,@5+#3!.RkGu2W;9$Ak{hP(K f8|0ut`j[ZG:^:xƷX&>Km*qirwf'"ɨT/611]kҳ tI_dUѐrMĮCE˲RXևBpXS&"(4_ ɎV%} )'i\huH)ض>?=!t**\JFʕKox|e ]BcϺ,}#ODȠc~n@gȟ0DO)T2vL16$:('QR % (T֍ar5azx]d\BQQ.N>:Vod<'s?oe0K IEb.f N#YX. e ѷXܴ{! ̘х ;9+gpCa!__$QEt#ҝ2ǹw%GH6\@Rg:Y9|9!! JSNEHFzW$Lc+o 8Y41` rX%wu0TU!7g`aHO]/HM/_ď#Juf`? `7*~|ɺ1VًxբBd%${e֦@ݜ1} FJ\]<|q:ri(Xڙʑ;`)B࡞3>"ed- osΔMԚ:/9UҨ O֐f-ZuJ`1 }3>9-RLx+t]c}C u%,Vc[:8@D@0!'KJɈڒ:$^*Y'cuﻨ(&o,*9"i HOӟNc~Dg;rI@fp@'J%? XߩѺs~C߈#%Q}p)޽OXqZ+ NlmH ԅI|~&{2uՀG݀D#֟31mT3j&MI|g_$kO1>Dc,b'2I!85R̎=BYa.;-79*i 4O.%r 3^e1J,%o%1N:^ O)EP [:\>E , N| jq+Qw|BL;mٚXP-lv&orbCp[b<`ðVrX̥I7ŅTY^*ȑc FIxY#s Rpnt@(WpZ#Fڊ 06b Zw=mAk.Eb)[x^|:r)08xG/W8D̀C]kjn Qi>O81vi~跓&vՙCˡfٽ:e+\?g YJ&搘S T$bYpJ2N|d&Y wÜa6+i;i w21\0yfs)F {7!QJ|ˣY.cо$lqsFWNHN<T[}Gb!., (AXa]:Ȱ3N8]`a&.hG},B.kOϵ3;|]vDj~X1Ie^td)I`lrލ"&j%SEP8z#qCT#;ؗkeӞY{ҿ&(T Ln1cV¸k0 -(( d(8_DN.t8`'{%W];`)圸cWM v-S wg(fvxɳՌŅU.]|wG$r\xZқ, E/TM*v)WM{ | V.= ޘɠet9e\G:MX`&6dGPﶨFxB_-m_U)}Mw͟0 CAjߩ|Q^抎K;6]nOl؇?TSU^4BTkDuS㷘@Tn+Ia y6ub^*|., k),8IC"SRc{M2ؙ83 G2J 7KѠ #hTfb1q ș'_"rsW8<}B]c祁G%OrHX jSTP7ܣ/BlHwysNYӬxxz+ӽFDVe*0kN5MO5WԤ$0%ś,jqEW SɁ,FA-|n=1ns snA=]t5jUrp Ey|f&=I+]]т{Ďch,'m Nj 2eK_}8S5UdE|$Rto6M9PEQNNOܷ8gfr.xHed4crLڈϕʕtVjI5yA., ,c5hYD;?bx,_'l @#UZO"jQf|Ĵ7.wwz?Fr&?` fdNd1$=ϗQ3.F4=?v/nöFEh94Nqr.&0&`.\k47Tf@3)YR(.Sތ48V ۔ ͵Hb6ib^h|^NH>nL25Z9z0u1H:8}@>G)2Ql>YAeIo;mrRUYacïHBtK`޼m5g%o^\%L=8+a y =5+L?U*ٵ\b'b®_6Uꓳ{_2kE|-?H: O4KQ"s 9fS,_EB7):oh R6 I=ckhQL3B@ KS9}k512a0G/1(OUĄCQМN\&o$EgSkAhҟظ;6d9#W[AvK=> %A KX:m#/ZTkgu'"B?rUT$,tm=nQPcQi'uaΩU8vd\2Dq~D&Egmu7Ϊq@N9?[;~qXکy>M*,U1I0@>> \6G4󠶠әv[bhͪu븻i7^ 0OUeG u_JByq@/qz46ϲTCJ<P-`8-9!b)I3Jm3z]wv-D6n]x N_~8O(>X۱?xe_ԦT UqeziC<zdTMϒ>_17}[*Ѩ{k!8w*NlGS#iu!dc܋E^V堭\鉓&40s4yeÜćp:Y!95B=]tUx$UԱXҁ >YZS[Lkn4]EiY,|'ft#8>^UcC o;yD@7J5>o f{zD@DLNqb`s[SOLkrqaO=A/ fxK2NEȸNQ9M ſ0Y=6z5%$'TFĸ#OJ d%ZB9s5^_;0)W)* mY9ĄgmJBP."/\mN}*Ӏf-!]mWU*OH9 xBI !k/“)O <~O"1ϑKy ,eDvaK_Eh3 &oHӒ%9Zžᒁ>@/jNȘ~cQh{5UĎ{PT}\t*w'' g2^|_GV9xcFp{PZSHͧS? v0#?m!|7t 8T5\%;X!+dפ}x;yL.rF]dm{v^l#s=lb܇ޯ;b+SghY/%A$:c#֠] 7(;Nfv<]}sm9SӂkWGƛl iܓ^ Vnl ىd_Nة 8ަki|fI}kap%5Ե 1(WH!d6aAGG۔,ڞ'Mή8\ubvx9( `:9od^P ;5Rv5E3RU~{ɾbpaCV-NHrZV㕑أ+#kIϝ#u O?ݐR7Ȃs07lW;4erQ:aa | Lw5ژU1UKYȨ;`peIq^?q?źD]DzN-g\ybQ<.\+>3%L u?c:~% rxvLzԑֽ<>P4(QoD g#z¥6QPLg~:!:4Ϟ>eJ2K!P) X=P7m]se"0w#E&>]Ą Jb%ߵ9t%o@\S_~VN%gHzGvyI )}zq˾MaÍNxN>rB;=s0QDd ;IN"U:bLsy.<( DdfD &d8"U/bV&4"^465eĤak}l-0n|I ʙȅ #+B򪹚&l 9DF<BWp|pژ2L%$ClX WʸK ;c ԏFR08{9.2  r㜝,^|djqխJn&Lf_ xl`5( tpҦsS.6-';vSD",Y}p{p2aѻjIf{ e~Qv`h#+86{.qH-|t]ouTWәd_>Nb&/ysͫ3+ FѿTS~ЇIi⠡$~VkB[b]ƉP8i:(=5+:DOhw;<6ʌ_WXǑDC}e 7$}QM]3$diZM -,;Z I.5om L_&dL1x/ڀR* X}H}fqczi-WWTG I+eg nR %lPa(tY4>->?V^.3p~5#4#쩟:ƒD\p00Ax-H*^Mdz4ƙ |* ֟F[Pe#2r-!2:K ol9o[K6tkH%In[gF՝H4Ԙ~ġJ/%~y1c*=u{@D[p0LS(ZHq3BI7XyaJs>^VY3TLJ.& 0UE 2Kl\(3i\Bý\?=-%Q8ޡX UpȨ? 7Ju_w AXNm~{X9 շ e=3|x`},pˌD)>F,gIf ?sw$ֈ`hJ,**P}:D>r @n>>WeyU wP)'FP'XG g5)\J2RٮtC1ENnk/kҧN*aWvLWZd3u{&0']FvSxW~9 /_yfH'lWOnb)CeiC]5">b-|vybcLYSOo7閕9_-!\}珈/gdy@2b|73?t{6;t0(H&Ks#Xc5  Y53?6ַ5ńLRcDLބ$BGNfزz{ۧ`upT] 1R|ѧtFO_?DiM[EgAkwv_($" }z"\%k:+u;H>}){`3"<0g~,4sK=+]'n!ۓc~, ^S !A9; 3yنw R4ΩS1Drv8ݪk޺huKAA 3rόl3=D /|LN0fRCN;(Y#U:x?\҆AoyR䜢kzpzlT]<޾Vz'IC#t6KVY_u}Oxn݀ᚠpՁ /k-\Ⲹ(Vyoc6‰aF䔀}?5BP 4UOOKqh׋ޢ mQIhU|4`OͰ~ xY UnYz,ЌvYpiN(P^#/%P"Vo:=GFㄙݙJ#H sC9GYJj@^ !:ӟL"ڑؕ>'jtSR = fl<~lQZKOtio0m}l(x5US0ٷnzГJc8u"Y34LS ܷab[Jm^C$fjB M5 mFŹj_wy'T%7[Jb+J_ ^|TblKnv`ibYTwRu"P4Ƭ2CNJZFG+K)w7L5-%~J+4r$Z[bx֎ u\,CI}ʚZte*I )lϔk4{hkQWqWd woJH:z?QxPVL}e0Vm%=W2|!AE]n =,p+O$U& F [?Yn"kdl4Z`@3uG,wXj)afpp-QbȦ0"0. j?[Zf= rnM e&eѴP(ow_$#D*]2|WUg2C. xF|ur: =KsRԿ"%*MNƽ:h9G)}^ w6H]-scbmEP0CaAzI"8']t!) aL*1X&`S@ 8hEEA4:6w:jbjyLIE"eTf7EfVCʼncMwbdܻ~c6O`&Q 2#{d% 3-]>cOrb4s?CXF :O7wŊOkW)b tz ٽKz6h8=Š^0W7ֶR}a/='Z!^zVH;f{C'd/ 25cmܳYBޡV,c8LwoV7Agnx[6=.UTJ҄FR"3Z223wE78%\x*`'68:XhaMũ DoHŻ>վ$ Kzד+/CF8#ö#R' ׂVChagJ3ra]^n bU<Ӿ2h%5VʾѬJ+fJ-abkp[T-kJ;g hw12ӂ__]Z<8¬-{D=TUh<ڤ%# ^T$PQ>R٫ B#vuP &dmBLpLqtVam[_%) Ív.jz9 wh9 ALJSj%ƒ"~86-d2fEI1v(Ū鍭9u׀6 FTx+r()Xev/HJs4 &!. h0V2}:\!qhK*tH߽6R߰:2j< ㆮ):8w+Xon IB Pq XzSTեY#dG~pg :r%nuЫDSČdb Q9 dnK2->}ͥJGj%D~=*B~+-ϤÚ\$4: m7aSɿ|KH' bd-C˪6]='D%OQh=1`?Nϣj&oQw )KDX{SŁ,& rރIQFa 76ʶpɨ 䄤xIl\S$ *.Y9y)[m8!@H/-m|#PڏgS89Ɠ-dIYpvgI̢0nVlvχ.էUVe8ݿ%=w7_uאJ"&Q`44ye@Q1y9 `03wL[(>CCWj_H}S+p?cۨJ43 %dv0f_d{yQ:‹:XrO 2g(LGG+x{]D<8lCTw "(`'crm=9z`\ K! WaxŌV#e>= +v2cX]_q &( $ :%]IQiJ%AאF.iw>ڣ8A=gH ԌHYy}؟Yv.^SxSxPB#*$pdᄟ5XNqQL;є.[F]U8C8m-a0i<76ZLX5!=,FaaA͵"uoaNZ7K-B%AAk2.yOJJ'uƓFxxE?q ?gtA GW˳$5j?'݁_!Vrm*a{]J|REY/is|7(ʎ"ޏbC4ShỌP{#% 264ټ6wq5⵫$o ђ%?_"qo&D`!\yXv:z`xm SThz5H96WZLDDoDz9L _y Aْ wWX8ل+\{Pb|3I.ol)s^)(hȕPo8H&\^ 7Dڂ٫.N\*C;crLoׇ4ޓc/8yQ/'Fj}rZdG4;=-^d.}QڙʔN'z~A<HtnG?&:#/a nf5g 9/a:M ! n _+a2X+ 9y,2i GgPwbo*&hcp1.έ?}YK`rZ1}>[*"NEFR£Ү1yr׌ׅ>Iz|GXIW{AFSW׼`5Wa;~E;+e~TY4Pqsܒj1!7vQV2KxTVټ] l+X?xxQ]Jd wE,dXp?bv7+QJE0wb5j2PbLxWaӝ 4sR負?b-3t݁#WhY3`KsOȷo+J >ˡ_CEUڗ \)rQhQWIK uC@_qمH9b+e s5~|rԯX*`yQkL۫V&_keÆ9u|8!ˁzq[RAtdPW\uDnNn'[* gL5\NG[#9şe܏ _~uқU%WAAKJ35v 5fx? Eϓ"#A;d@C&.3‹M1^e&}:os39EHMqtN[j}߃ yf%.]֐ZxoYa.Z!97 YdS&bf\8st oBK۬Gni%Y-$ܹdw qѬ`YF; u6>FִSeSeh/ VHf!"*$oHR{uFZJӏ- Ղ>,ܥ+^NV&͆=LGq[QuaR^fD/p\eh-bT:b _ j\lKWr ,J]?X,ow=&R&CI#rjI\ bU3snxGW9I]y XղJkN >{ 2Hb.%}9ai[P"TM䴩(4SpW6m֫>Kcuÿ˗Jԩ `𷽀CRYhXH$}<*c ˺&߬ψsQsnD]GnV$|~3vmD[` awrַ6Jp7j1媨n .+]ZIh$FJ[& 쪠?@ኧz㽝FKsvN3ow)ZLnj@f/%NekV#BG2g l"< Bq_c#m˩&Ҥy?ɡ[-µĵjr~m29 *c`ѩ{\AR61S<Ȋԋ=ˎ(2y<8ec3p@:J˪ۛzGWxF:&,TIӻUfx2> " N,VM=SS q%Z׶ޝ@ z+ɷ}ru8/a$ [^Fk`pJC⨌>[gw 4SSխtBWQN =fQdžΔ/ LJtvA\8ݘF!ܪLm㰯 Jx;-gѿH(!a0g`4":u4{d Tb,W@>PD4UѸDJև9;®A6=ѠXOVth" 21Hԙ ,vsAGՔs/`سRhb]-Ս4܀pZA㊑qGĈO]鯌bOrB){9 G Andae a(6T!PM=xyh)V^}"$j.I%~Chqo(^H(Z`ט#^ EGd'J\4:>aZ+qe$m1&C%=L ,_QC^~>mw s yj!=:$ xԅ.1fS͖ %=-]K&i; VUddD\\>/'ְD.L{83ٰ&jcq\лt^x/oF/vbY~X~ux RMFizeAFATli3u`e`~NU8܈^Oܮ( =d&pe 6񥡼Ԑza ^9.Ac9L= -{8֣4`ewm8q*43,>Sm ]Dхp UU܏l²ȹJ~ǓMnX0mH'qt-Sp#UCIxpI]f _C]-˿7i6.c!}8IDRP~-!;FPqMxo_W'Nȏ z,c ]R,C7'm)]Hݗ-y:T3iE'@w ym hg$@&pV;<>%5T%J[R] m2]dXcjl o%ؗ()sڈU wjSr!get>`.?PgoU8pa֑!DR 7ޱҔkWv?d*# ck%/sJX%n7^up{Ai`v8zUEzo4/jy$ M0|v6gVgRdC3,r}IT7uv9Y6>uK&GO luWtbqW[2Jʅk y .Ƭ,FӉ}sљͦHdzzlAĊ+W)eÈ߲"y7 |xMbAhVyh>B:Xa=W}/^ BT#PaNdctP~K$sA5|L<"E(IXRR&&_YB Tfe]J"4".U~|6 I ] *gv>g*jJG4$eҲ7]qU`u1S;+h$@:u+H!9 p CtF(K>s4/<-8ߗVcۦi*4; ku:{Fw>z{tM3HV얁TR]}ANWהn++ų7_wr@UKyCI$Cۙ7oj|^]%$Z=*ydפ$pyNn _A!QȂ<TT2_]~Ҙ~p=(BF .qliSYVji4`=j3O˄q%7E" {HJ}i))D 辉Oe4- ПF&R9sClM Fc+G}$7Oe;圓˓dkO( _?wZjܰ7kLaBu Qa 9#r5& ]I#kHirmŋc`1[5ZKYULsS/u2Ϳ2L|DzMsHHfƯ~$hj=G(l| 8tCFؔ,m鸛O.^ID̺ &yϦrޮIS rrL}v[+c:}_cD'[T_URB7Q6 ؎\ 1qzm2_V8< L-߮!aT6WrIÝ (Wv iY96iVϳ2cT:ibtoUcp|r毧c?[$[ Q텾pI-а mp[?h#T|bW3mEJfƏ;HdXTnhHo=Cd0+Z{(Քdd_*GhXPIa&F-[qZ< Ő9zVEp5n !ĪA(ajD*' n:GC6!|tC>˕8z6*$ޞIw+XqS`lH5NTO*In=P:j}G'GAH3O(EP;$rUެSAdW}sOUrMaA#Uck6k:؅8DD5%uo,ěy2-?q1)ܗ?Gi|N'ҔvɁp8:.\F: ߛBTR'))<KMC|ߩ5b"IRI2PmG P űu}T0 9v,dԍLa XqP6oUQc.gx oDY vg0Dh(Of'Q \:^W H|:zXt\FQz>o?kʔ'.-K4D̽n$ēUf}Խɩsʳ-#˲$W;IǤIkW~:bF)SkS[fa8d%$e|r ER2g2H5 tPbJk#)0ԊeiDȤivu8)X617Dͱg*|4ѱ]vrǞ ^R^ lv~m)x|S^_ =W͈/=gWm&tM1*i0nsf,ZjzzLAY:I: .VoN0 F{]Db ~4]U϶Ltè o.~J8:jͼ+2ef='t &wa:zVUgvCϏu^Fa"J| ‡UTQvx~PU5Xѫ$)G}$H>W~x)g81?iձZڐvջ <3"*nB>~c[P; Κ#JM艈 Xa_aO%C L쉆-Q-Z}_sD≞!}sMqٶp=rHXHPislJ C]5˿sH/ .m(D!> ZE<>Ҹڔ51ܢ4;6ӟoߣT_Nl~,XNO#|*_B_J{/MΌٓ)UW`*0*lÑ84TQ29|gRl+O.ђɌVwnd$VsYTVDZ/24ݳOx߁=,ͳ<\U1U_䟱R@? z3Dc2j9H7k;8!#M,bP8M?x9*j'tvo{:>]|M/5X3 GX1c{m:JAʳ-ku=99R W]m/3Q>2+g¥XBm J/0XO92ja,z9P-TpiK@Lf@0L0B%6'UA<181ύj[䓢qAsNy$sp5숢ryABԶjT}dnBFHX%oRR@ZƠyM§؂0bLj?[o߉GF P(WvџqR i5אl՘ܫc0quVc`sv0p!6+"'-@搚6_Jx*Y$ɏ$'ןv|Pg`꽀GdLJ$tiRQyAXî^]2)UŠ! 1\ v(I2c%ڗ-(?+ p(خ'%Qa:Ho):6h5 kZkCx`o_%R6O)Xeq!Mw@uu2M)0"DkygWVmr+7;XLXl 'AlIrgVM?5h% J^ +oӗ16~Sش>z|Q))dL,fi61^*́}),iR}RӶUrLAtpxT4 ԑ;4?E!m`$,^9#"~·D+XuB݂f7ٔeN@* 0-9ђ̸ /Rs('WE1d`Z-ygi[eL /}aƫa(ww_t׏5lpbZw 1%EvYmߩ earڶ3qt92L)b`Z=?1k:Frdʘ|G295$pIOJL2Q&JG"wezS ]7N|!oSZ0 ˀ}3k>j~2yE;0Qp:Y >T)r(\ vFN:y*o~14TIs{28MQ")+?cKH'~}$cm6FP$/O54A)v oVQ˾ܶ/ dQNY'K5ZhCMx70ݯڜbR8؍EEiqSU4cXn= k3GZ_^XH8&)}\ M{g/K#@-'{\^sdҶ|\1v}.˕M'q`j/ 8&G>L/ԯ_H~À.#_COrKW-"KQɢ|2 T/f$sze֋}>( h;z}bޘ![脒Q{ޚ3鐉L';ǹ>/wz}r`sahEMn> =~; ۛ'1@^woK=~Я8pCuEyF`ĮǯIVdr  ʮ 'Q2mE6zXI-X!?jǰd۷教6fJ]O/a+ ! !StseHN[mcGYfO1꭮C)EzM9 lN; Kө#ƗK\!wm.&/Lj]chPU-,q!f??dV~-\ۨS%ptFNZvV/4icO:#Kf |e."SK9|!Z' #,H8hJ"C[y#l:ٲs]vunt1k+n]+`J&$3fɻ2B?ՈJ2u!Wīg$-[P\iɶϹȅ{ IKN`Rӌh.ި77 -PjW? Cm8sCq5q7sk#j0*$U3ePKve -j :Ó!eܲ'\Ռ0ڨ&WS&\B}u7p rAb˜NQXH$+zaF[zh/ CTܶ}H Lovt6 h|8%dVDw!f`nP ͽӬ&fHsRaZBGb&T؂JX<# ;ܭsQ > !Ȯ9m{Bu)|~ &LS4A6b#d"RoJ KaFJm ¬Ga%;JG Srhf 5%'k%,Jo9ԆJ%cXAw@V'}I`;b R $<E($|0f'@C NHpH[ձZ#x~&[e2D?09[Reo'cRcHwӃsORl-ħ*O渊R\į#E2J:\E>C4(hbs-H]=ʽMj gfiſyі'3[D u1{<4EEk5:-)$ܝBe p7c4Ih;[Zd2?^Re.j{-roڋ㞪3~3r2мmCG+YCYV ]7:glEO'r #j4!~5ֆCA_t_v=)qR4mc#â,q꽴^8 <ğqǵU=Wȁy:֮p:- `~3!:8gn<\%,㢓sR j9*[MRo.bWu*ixvة'5XRf3X. B#\7qT3mhM:0g &~+ӟG6RVG>~^DouGR\!hr+h**i+IRB?e4%Tׅ _ПQ?#ͅ<۲® ?G^3&g(Wߖ9͌%H  Mԃ p|+9>s^KĀu|LA>ֽoB_`à kmP/i?[30߻xLIA^uY$8.݀FH R C&Om₴>ߏh/=?nߞ7(y5J:sk 㸑(d7YQ[N6Gx)y[QRwC.ϛ)RZr"NT{bv"SA2tFr}3MiN<-ZRǔݒamyٜ7qE#R5xFG'Va0YPq./7w!bw:rBx&.W$Šk' &Ug8SUVf;0<":r*{=sL;+@vTW P_ʴ'$h&LrWݷ:88 {gkdHuEB<ߺ]p<e>RD=`Evbrqu}xLZcoOŦBup.l$ /Es]]Mb3 \aF)o |Z͟R~`èa:λhϊ˛L ;/upWY>׍>n~Ä@t[* ;|mD _6/igG&5>~ɛ~V8_ /߻ ^; 3:))R$VCwI]tf(!77POGT]4=>Ƴb+&f3\SFR7=XN^XrPOD rj,1C 6 ASHt=5S?%#.AʺS52PAdHOU>yu2<To͑H|O&q| R7ɨvkEtzGÿ_ 'xyCu>:^7q:$Н a0#UWg"w[^|2@.pTLcS5NL٨kܹ0n.QQY>lX=i:WUǣW}ާ1QIHli6Nb+5DKE?Sg8<9KdsK@#qymì5!',|F0!Ry6Ed|*w9$arX\=ƷMD|T`-S.8 ^SǕH5ז׭ӉO+7<; d!W܋3+Wb(,QG>lМυpߗ>t(6f=؟9xxߚ* p49 Mqt87 #wMsGPoPkY%0wtl߿!r3#M McUe53kh*Fa6t'u78M3ͨT {o[E;D[QO箸e`XC7D: {шo1A&q%о̔q)4%dLlEy|ˈWRS ]4R^4S#4%X*6Z8,0s,Tf>OT͛[7cECg5JJTi2#_k Q>T)S :)[*1{hŵ1׋Ik#JQA[í`@ [^kd=pLHTA٣(Y=Ӂ%DE<[Eϸ\Ijƀ#c^vPFNG4Dc>t7feRKKZE>DQ:k'$uXYE]>ě,V6Ћ~ WE փ0ETXHkC ,^"drV*ߝQp?e'J浘[A՗AT ]6+:s% .z7#_xy&a8x4 =/qEۑwC0{ɇH~X8{PH*иnބQ2K>Zۤs5Sh⴦TITKE+^$Y5.oSf;NT*E4٦A*[iEOH%,% *\>uIqzǟz6\//pWI2X-ր&&/$z~_Bn_p{vS#kJŸF a1Bm9[uוre<M%=9,d&(=4y8^׾ 6U 8P20 G&[؆Y|XՋiu@yQ11Q-mtS]g"|K5MY;>R09gcO QK)_fS6-#տKʩH4&=[/ùW|%ڀKs>kw@s]l`7FaF0A@IWf sM?G+nG; YvsҽsBU6^ +]6UZԓ]&_9.^츲6ҡ; 0( <;ȳ'9 l7!:+lb կ7kAɰ>v |&FbZD%40.fKU5Tl<_a)a ,pˍxL<%TASqdual Hl{\mogҒ/^[f~ȊOr[;mb*G<{+uͲTdR˷}lԩyNgW[[d^2qUnc }6S2~afܴ!"7Vlc<&'\fj.hBODΔ@e҉eJDxXJZ| * >xcy- LPD ڻӑTB0E ]~j,KuC{?pɞ/V(fb8bSkduc5q,pIza{ZgvX5׵6o@wV,{rhY,\j ̲ČSa6V2" c% s̃*CVcjE0O-eych'j,2&@4‘g^K A8дF:{0Jʒե 2x-A5mE Z^ǟp>/Q?G(MH҅ U_KuQMD8Opb7Oԋ2¹Q+QVpb P])B_[t|z/rFk_:. \Iٹgy4Q- \N{/ Dsxђ뿐s vi,w|N @ o*ͨ* Ϛr{ }Z&[o6cqsI̭fk: IV~MO#fUoA%9:$F>4fB6W(NIxi$*WI_ ~B":_yTugf,oJuw9i-q1%ģaj4&3hٌ+0N;̽XŠ-y ^?w?<7,fpVc߷@DD9<+m~|{h8c{8) r')SBKp-KRO@\aI[g dj#8O$'g/4Ve@& 7G~=~qf_ 6>Òz Ђ{Y]AZQbsF49!C;tA[<'iUlzժY_[5Ma^`,q@RY׮"P7Y   fy oUz /F8 'j)ָP[Zr3YhgX{Ɋ xZۦ|:+EW9τ: *Ղ|)FG&9"guQ1zik;+XTXZ2{NkqMuT  0q$zڄr8l$a^8is`Z&)lt3&P&H=\JO!_z4  A^]ơXj,Eߔ'z%>s!̯~=cytJE"ɻP\yRJRauL@*nfӹsqwoi+^y4%B?&rV]('ۮ #'S]P:.%\D 7K닸L M wQ-@*a+ǹlLr6R)zgs!W|կeUd/gA iL>/цSހ+%ԸJYvPg!OvjH.MxJ!n 9Ӥ՞7NKzVF怷 W^&4xljI ZCZ;PA.L@LcEs}{ӏhc=uml[pl%W)LyЪniC9wkVhԱVu0mQjnF7ʈvY*Wy[EUNдg~3+\=$ԵL67ulj)c I Z7NXYܞSKTzzuSvkyyb2O$$=y0e'|7rY\OS{Ǹd|"] tcy.@nhs|P_ J]k\18u'W|7s46}@|6+o@ =_'b%Պ^sg;%~ÇKļF*Q̩<';AT!%{gSєH>qRP)JIĔ؈F.*=- ;H^2A~KGhEAUIphn%eFv]nRO%G$J9 B}@y<:jٱXOҤ~Uy[ M$i*rhʩ$p>QFU_6"~&ۻuY-*E r瞲)BMS% sP]sĿN`-+u}Jl~Bt6?RK C|7y:$Q V)n4 !p_묉=9#±…enEfgz9 "]-do'Id!.Pu{;y3l9p^phpױ Ge9TE,4U= ™?u;΀'Cv. Sr pݩN;1~}R5d$a?⾞8o=!XeH5.ܺvȖ@ؠ9ֳ/`"CJbaiRw<*J%:葽nDž1mL\iY"_^yfGUs˺>+Րt[zSYc=`7{D]U*:9]3k}ZqCCXq<.袣 04搦rgA)9A4t-VՍ a0ƬꏩŜ{.$y2Ѩx1fLGTW5KlI;8"_~ʋ$`96sxH|7_NS88 2'5-L[=йv}tu b+^;Gӛ㳯og%[|X 4T3 XirZtSGۼ}=?xRypvkKLӎnÊVBfw:61LSh9DnNj8%\N?!P19pWUkAu|b58VV*U˺%ͥ4@1):6/ccs$Bwεd;&qnMnvHVvo >3 %)/$ad 'ZnyIsćNU,v`ZEas뤐{0K󶒵p vzr(V2 H3( sa!:^_j_p9Q5,-nRRDOò7WhG "'FOB14JcߛG[[Stz=96I32!@kCp9]'=k C\Kf% YSaԃѮa܌Z~R=ŽeQSnnQ(|@|$72@=܇6[kQhe&p*8W=۝Q(.p~{>{Ch>p}KV$Nirgbf7R8.-r?VTl2ځ;%\eVl/W@D>]=%c!YAeܟVdw|pk1ܠCaRYt %Z#}d!O[y+{i&߬?.<ŀƒr+wrN X@@bEqt5|;IaP2ݢ>q^Q/#T{6X,l&ؑ8CpdXXCt4-afH@i[$qZE1I(w2e}"s+0-X/\5=ۉ0V7)g-ITS <##}¤l@ҟ ,.ڊjv|?ƚtO5x,c|>mwęRvҵ2, YN5jM҈ :d3hwT4.X1LX9׎;Uf2#Blm9;}S何]%T7?#ݽRDMyST!n9Z?mp?[kn⼕|u$H \Ɇc{hrV44-,91}}/)J(?JX2!yRl%#YNYܳ.\tاl4e|~@qqŝ/5&Odbs8<\_ ImfQԌ qqp~UvAaQ dA:3 ɓٷwa?v6IebX=G0p`ߣ72e.]]#yAd9MrI0^C7p"hZF ǯ!7,Akz#xS0^_Q0+ڑз\⭰[2Y':Z&c6sDIÐ[%)$4(c^\~hҏ;&e'xHߡqάv ua*$ZMC21pb8 XPlQZj]\amR'| wCqWU73_RKv w6ayBxOV5"Bß'8|E)a.p'T8ܡh[s"a(-φ}e16aFdL0@3c5kg/|@GpKXk[2j;ͪY QCDVzMH.흰݆/8XS?$(:P e#ٴSY"mx20߀V!g^RK& &s>Q$ lŐ;a`Bb)iH.y?d 8-]V &FeҽFU_t:aF+s+'<ѝUt0CC4Â]G=C_O&񲏢%!%} F6ps>JBj)@mjX  Mm/Dqmu n5 n"SSۭz D1 ca#;#>~fFeͣ&WV/FTQTbQ)`~cc ξ׵eٵ*̈ΚbHve_MY\OdaHTM n!dޡ`W3#{L.y768V=:2ו|5S5^5nnT'FZjrc :گ $4F߰%EtU|㤲M{ ^v@Cf3F|Z4B[A3\.2R|բ3|7qיqM;v l2߆5C}E'wk+N Coqɞ) o / ^&^.QЌmBS52v;U~ k8;DkO nKc;6fV0UD'qȆ ,f,(d?)&u(%EmSru"X@Iv `쑊S֊ɔy]T?;"C&QࡘY[ThW6=|FeSS Ŕ &SRDŽ$Rr}:,E(M99<|c'sD8p !E׃{_j%4\0_pas *h䱩 d.i䱥>0.C ߖ Xo(m竩OPs04Kdű,~QC)r.ai&8yX Pvt#͋k&Ѯ5 CJ'ݏ<Յp>#, .H#uBh씧t+!២v|_u t.͉TG.| ԡ@0owGWwUtVY- H djkPɌc3Ka8fZ=t)$CT}ц]NѼAexp#£b_@/ [Cn;N`EC_$"Y"*+INkC#VF?JֈfV#&$&xseA5">G,Q|s*p_P50l}w@ KHYC?J&DMq^CEhJb8T&6ߔ,D[2ECĂ9R[[wlj*h5 IR5v?eUAV 7'uiv >"7IkxZb(nBքc8lU`KP͆&." %¥W::G)xL 6ݩ~~g|m<Ř ΃ӣbYgJ+GMn*8[<\ZRI<7?iOS}筤hgC^"< c=(G- WAwa?q"#>G:g뽗&[Qj'i-$P>?75NtM.\7-}Jw+U;jqM@w4%oKB3y>˳֝`/ :`Kg<ݾTGvF0Z%dFGDUK >9y)/֐٥;*4 za!JGQtsf>~5y`3B5ݷD tWB;n.RNM|}5|C]8**Q.~$~jQ xN$;ח_v~n tK*>^VDt&7GCӖG6& fX8pÌHd?KD5^xhYWSK4iQyGYGp/D"\E1 W:é)28r3OMĆfXI4PI\7kx^_J:[3r0I D8;̝FF~U$ܳ78-2-ZM,Jrk1)KG/jh)Qp+ڽ}C#-uaC:[*lѐ(.$5ԠO"}afkwN/(O@z8lVr^^`olV #d6&3>p_@5K3M1r[5vsپv<3cMtCϮq 08SivPO?y]E HZDǴ9Q 4}׮l@ " .wF5 d8MA| tl^<'2Qx9{㲪]w-\LyEYP xO\gO7PNiF~3e(Z*Լ{wny NVCi'bfOyO42'm j< x Wg 0gn::X!iUD9sPF]4,P!<d4<ŕS "f5E?Wۧ_E$gqm}-#xRB`D׏zOv+Xr8s6gP҃@ȼ]"$>P)ŒF3xhp5 كlxgVnFa!7x\/NUJRJ%Ϥa_1"'¿ZSߌ;YMoɾ7|:6w>D7!NoBVTѮJ^,6~hXm ^S]a4tf8%`&a=(8lTjsT`ywZ`( n)B|Ul~206լ L*%7*Hduʹ'bY0=ʁ,2O(Q{ KULcs 'Ў-q8kCibWհIuF):|Oos^3Ƹg{xtC-:l1YWћ?mp5,&{|vQb3O&0u)p9[ n+#orA%/sFp:6|KYM붤RvFEe~L([12zkre}`vm^XÙ;r|ۆ:+7_PɆ6 #61 ը5m淯Q*x1jNwVYSi٤ 1z 99L@zln`?Q吒6\&#k@< m$0rFQ,Y /3g&|_SdF^˦=ψܹZv&O62sl+LAM-VJo U˃f1~M4*>X =rLXo Hw_>xPx2(٥uFo=e#3j>3x@Խ@$@= rnV'+cR F\)nip~OKwIUnxϞɟVpƃӗq9pu!\aeq-#Gw]Mz#TpfkšЖVeFk+Ħ~.5ozWmoA nJVCS va1oo.+ }_t!@7kg 3#CpmZjȠ:2ȣYHu=ӑba/7)ZLAWiod+-o"E;PNXYB _[jbu x5YlcE~hJk7JЈ; k/(ȫDI+S&Z lm@±f`ii|?bNKWVLDoRfFJ_$8Hq\"6h&`kANsưia[w4DB]9WYg$c LA&P (EbGY|l.x2#0={Pky (k F~Z8~ix$ 0̚9 O۠[n"D|^\7*#=)PnX71-)X7\zBjwoOkTVzvQf$py1I[NG#4sJGԿZ{m SBx{I/veAZRɡ_U:TУ utK1]&~\)!2&߳*/H{vާ$RAH*%"|KZ-l'cI2q {bOo茮=|k):9f>_ѥ1'sh 3fcspZD̀<`;jW$2.q\HVL'xR(–qՄ+ '1>C16mQ~tY,W=&+s9mDls)%i?qkEW[4:fQAJi-hK(cqRp > OH'ϞTQ<=N 'I9T |6'14j4h.5.Y?Ww=1$>tdf8΅s/>F ^ËxN~R .E+cg?C[o扗* Cn0o|gRYelMZlY6۹o֔%a1plx1ůvW=9{GuT.kA@.S9"[&/tZCgGe%jjCAO4f5$^4Tӹ>Belʰr?AVVu0Bn#w8xB7! =C gkB9XTA֤ \Ұo?Da<5p(^(8d\lVrq#%An"g JuXtv)U 5y͠~FQg~qJesDߤJsgl4*ÍaRax U&IAXNJ6Q!-bsl|S+'FDq#dQ\g̈<<4+4ޟrӴ8U-ؤlj^r&N5>#(L/uu|@ OH>ar!Z7oĴґmc>pk D:UN;REqF"Dtٛ~~z?2F;ETC5T:Lu@|(86J]PTtr5UliIy 4?GHܥtAM6~;yj?HECHPqJ6G@K=&Sc):Rs2+'L|%I# .]&U]8~5`2-;PwҹQm9\jA{HrWcܒpedEymn$2 z<8P'{gjc6*e=;&1EHiy(zEΣrخ\5p(©D a/~SX|w悸"kn${e ų?s<9Iz -:qR|=n#K>姣UGXgeuKQ`UDf)r@J~+W[ӏ_# dl (M4Ng9B{gU +Ldlַ+gKnҹ慤vPU3ù+I4Fl̏[.Bel<&-E/T]6* 2xcn=0][yvw Qr^'`;@;}Tl[k)(ggٝ#XOApYp {b|Yvr,YUY*s ^0R rsMJ-)O뽠ڲMs_nA5dڡ!|4Yhh usU<ܓ&' nѓ=q3 #HOhF_ӟ88#e.~RDLSoW<6V%CG%塭Sz?Lm8зST 4SXݣמDsK4GWM#b'{P^T&\(v]>WAuz>>TGtL\fx{Ejz8Fds6q>)H6|] !uIrNF!>Vdv(Wg_0qD ڊz&7%M {Ǭ逜nΧk7:D͍zg`TcP1FxU+v@SRhGc/ey?1҃#l?u+@C3`sAȠk/Sj_68=kI"Gjgdߟ5S()9r7 K^›c[-l[oa)ב#MMZWR3@}.?촃T7 Ybzoz1x13I% ÿUOm %/e=-k%MaqLyuclgV4tް܄R2%j_P 1N>^:)Ն6B86+^ ]u{gv-ǰtn8~:^ȅ6, MHy߭O(SoT;"6٠u%6mot~l־2xKz(P 3͚ 3Ù)mDx2TLiwreGJcKR>fiRV,S~?Ey {ACkĝ(qۗɔ.$Pt4(JK ﶗ}š{Lݟ&S)geTs4u&FI+1l'F_ {?#>qbp0vZTׇfv"U>S9kIFNa~_7 L';M+C btԖwIy;̌E:kV!A4'k;1cwqY254X?x̎QT]q)%Ľ3eZs;[:"$`ykbDSu[3W_aQMh E'V֤3 wD5Hi 諍} `)|,0(v VI DЦ|QeP}4$b,veW}&os>/G?"Ϳ&ffHͥ^Gh{4q ]ySCq"$woL uΪ:&-:ݰY;_iģLɧ+L&$'(,š, A%QSHy/idI3y tQtGִ |ִ Kd>{2kgwDgNc zۡ Az2I[ Oxp_F#@uכ{-\ά\u5^b6xFF@ `s*$ vJU|w=rcHT8+&۱z:j)m&@'v\ִH Mұ{z}6ݶ4,V4i<ʾTY3;,𺾥꩟L(1<(Qs4gh"_ ,c*3"k{>aĊ?#蟤3L`\=fT|m`njxzLY̴NPۂ rx*lTնD6:@ ,,8O<8)v A+*^b;W}ZtZa oHlEPi!* 2U'q52"K5e>~Ȋ:øF5T(1PvIO)fzm  8&ERS$[t~  *#p-huc ln 0F"$EP] jnT`9o~^$ 7.};.l9ף|T%c(IW;Q t:%_/Q9YFqh`>&cR) 9Ըjֶ H7hb8+g+l6.2ofCZ)5t'.zry8gKYc'7'7{ZD))>(},'I@@"p-/DGgWzl ܳWdnX* B0{ZtU5>8ڳFyV=a"*zndľZ롈F7X4ȔAP,`١";ha䰱 2|4ݶ^9Z3p Q=E5h} en~0AQrgY,nQ'0jWc gZ"16.:$p| 53{Wijo@f3dn5..6y;O*貔`]0`?vC =w`U3$ac[gMC7O/Ra']lJ:FA8π7aM$[[0{ L~ިivL*sbq%Jm<(&U'aJik4:97 a$5ػkL֢+S#I%/I/jU|C r42qWnaНIH#etzݿW]X\ a͋ǻvzgܐIAߧo 6A%~2ܧrj`BUoqʔwsWNGC_'˔g;S0s!?5AhthRxQ4b]{xt +c{|=- ɥ{n$pg7%w60Esԣ(Jh[ $^߈9%^!6W牫5$1<tgFDZ'lb@z!ne1@5U q{TsM%!4s$.ϐS9 $V(y |_hvwBt3ka] >E'nzˆ4K\a>"o9|v˯ mN5R>ٱ}V/d҄#)t5#>5X֍cxfn2Z@5F}36R5nmm_e:mz J dBͬG%~9O%cHMRqWF<X$0kfHKx` ԱU~܌M ?^Ox"D͇gzwhv<<|)W{٩s;V[ƁDe4Xc9+(~z=k,u :s[虂/%۲1;Rjr9N̅\,d{4ӹW&aR4iٽP+/Bv*E)88;RWS޹Amaۋ i zG,7؄i]_YI_UTe8b! u'NqO]lɍH{Ɂ U_O~I9"oG$!o^*Uލ ><.50ʻ 2|ϭ}2/H$Zx6̈́k,e\. L<v~0"䰼o#(!M臶NxJ:6J iF&|8vhbw2 2+0X~_p׵/I3$ Ɵ1K/XLV7"}17/~.@F ߵ}GQa;/M}2U}3^ŪpLm΅*fX LmW\Rþ[*{}V y'Yşf/2В,+F{RQDW\lU.QƏfgڪbOw'R@@J!)6TWF3˷b^XZ0*xe_GI h!]8Xk`π1^ ա_pȧQ(7ڶ;YI3ʼn,o=Qry. mjY$&g3*X[fOp rn'fjUaBf YhK]0̿)0 i0au6k=ꞸzRuFʁ+)'s¡ 90!셂TT:u!M WN*q"MunUMr>by)Zn@^8yhE( o[`ݚ./G~cՅTVC>Q0f;ϣ4.-^dWI02k_@\s}h9 Ӈ%Vbߴ?',&}N\ *2bN\Wv'$?[>^\|pucI rm *^ $@/4 `wzS?ҷϭH!r;64h[>1=4(V x'r9]iPS`t(wQX .MiG+8+mt땪DT|^a @I)O` ـMimϟ$f8 w6e#T 3l0S&*D! Ԟ<3[J?`nXɃ.s-l;AӷP9dUA9RylʳXd.H3p iKSKa8á_h ]%o7GOM:`r :O:BF^@B4ViGlI+wa5;}C%ae0/ bޥ Y)DžZiaz-T3%DIp}lIDqbijRVMz;*" _oy(#(=䂋X mdaM0:<-Sqp&=Aj; Wx}~@0q"KkxbyC˞~hMf0XZyVR } Zνu[y@¾\I'f`LЃ2#>f6!Ȍ9V~@C.e{&BMi fuz2){J~\YL]::mt*x[P ՍAxsr &?7җd;7b,P Fee,9 .Q&K•iMm6>XsQ:u?FJ#s#3cH?g4ZH-yɥ(f{ɿcZ5p0KKл`۞F@e|77 pn6تw㼀+ j@"ƫ(.ILjn^QSS#jZqrҌf|mܟNNX8lT %l1b^@5pOpmy>X)hh'Bd>pK,6?IX!)ru, sŤje/pɹ`~auwF&>6 G|9qnH&E, X'P`tvg`-+^85BLjbz" ֢5eZSokK !_ȱt}kW3eٵ9L.ԟ5ي_Ki,_qaԚ}҄D A'f1;FE1s-Ld_MH!W#pկhgØW5 ǬT۶<;NCKؾ "7}SKkFI+,~N 4-=!:rň@Qǚ HщjW4^|q*t͢T~ι^;]TH(;f5!Zl?Zĭ'_NC\tJF ޕHQ(LQqЎXKF(XU{_"4|)fxN UrLlϸ;5w9f7Z@d忏pw)/G!kq:[V!%.r[ޗ $jՁ8v̂d|RFNUo PI#HTfwa&^uؐy(Z19pEna"Q@3j URL ^m#E@$l.e<1u^cyzWMt-']i`,wlT( vV褁^s,&`x|tVm_oJ#Xic0!dy)OhN$"; W?kJ`jcbUL&)?ӐGQ) Y{ə|[*GIa mcZ\QU G$u GYH$GLqw#S^cBYI+j& vT4c]ѷq!Ҋ95Fgor+kQmzWm.B7|̊F `a4&HPy۪w<3ghyCey:Ꮇہ1?Lv OLœItz5] Q=*V" 3kH/jP0L ?qB{niB2&0.I5xQ9J-Ş@7Os`K,i_h3 VH\ҴD ¢ƼOD=*0쟀06 u. {t%=L`BH6V_#/INt!Oˠ,EE$-: /=qqc*%3jU,cwR)(h^~Ҡ| C*עs!&Z0YyF+f3T}Ϡ]6q _?݀?ڇ;p=fuQoHlZlCeH "3ga2Xi*"_#*'f;L=,T]Y*?Q x# SOydžq9 IIYqr ?M'AjWl"ip1&C&fc6H?d")TX7R8=C@QT6!;}L%ƅl;>Ux&5ʼnd&5G-5@HhƜzufxDq"4 +F DO2tnլuEb-= M!28lm`>0?MM3ZT>zV+=WGBeJ; oBgcmi!qƩۛ"ݍ$oF2c(^>ц_ t =cnWz54 !fPm>ֺT* ~p}H#.D]ea@i $R^wiw hgZ QK&foZV "1j:0y+'8ߔ! ws$ygyNj)E¡ۉ<^!߿J>9nnBEK"8Di""`.bgp띻l#S'`vs#fƉ;G_}8tK3Uˋ!ٯQ&Y#3ԥKRYar9uc{'Rmh P!ӫ=(^jכS0[ O >H:mufJq{ِF]RDOG,ÊE}oPCfpG˚.*eIFBVeg&ɺF~;whfSUs\«/ Q~e zHq~,W:ԙT͂\b;z8u {,ME@Rx3;;9cA3+#"4A苌TPߚ<^K\5p 8!U[` =Lj ríc4)n~[*i'b&')ɒhW¾h܃sm #퍰FkIЌԣ^-cB|i=>$ fNu4/!(\M\Hs+߂1.;D):1A8d=L3%#MܛOj ؀rR%h?z+lߞ||wbjzqMa}@C7FLc*4#А`1 &Nn6@LZ XZ9|2 ?$r{֧06ΐ91BWG,-jغ Àaj_oST?4 bDg|q ƁW$^*F(SK"'?ӘH2eP%07r1_sgDaX~C~@yɧxŒq2bv{FWQcC5x%77Գvxve=J-^DB|5NLE]mO-}qT0F\Y00m+Y&DuHZȼ2I5DбߚW#2umٳ;9s-d4p;J*U6^mDB0ɒR5*H\ZS*oQ7F\XsT=K(n gVAAq3~h_ߘlsF5;7$!F.uã/ |s&64 F!e UҍM_ co qCᵉ!0+hW:/+ƦŤ^N0lp^"c Z 4hSKDgMI&V^Z}OY1a~WèM2 ҟ ʒ%0+i( *o_xdhn+sP =,;OVؿ?)S$5MF>|ن#oTSvBoB-ٹV>ཤ(NyqiAndc䪷l"d :y{u5))ApԭOyi?@mYޫxj˿p08-rVZXU[8~ bb/ MeȟC93 W׋*{/CR .swv 8<9-k!įbMRg=dн)KdY?9Jm-㩉x0x"~v(5v FU70ݳ]–L_> 'AR*i#]!I BoQw [^MfI?#AgÌ pMsz<WzGOu0:ȏ1FeClF9񾃆hc©mNwf!jph)!+-׾nYVsXmF=@?;1#G zp)[Ft:T`.&2-.Ll9B1 :y(^->6$G5@lImOt9;/e8 ưxMaSq:{)U@a ǙqQ[nV..%*)k L^89xؾv/bo(V'p 5MpA%e$bHːF.ʛƮ !7ݼP?-Ggy]#эshgf˄*Pѷkײ8J[8}?'[=M'ϵ]6gKC}KUf16i?LemH>",55"ѸfJ#PZ+E;Bȩf͗bH_ RڄvI^ENj0+Q5}L6ӀolS ]>/Cb}[AX S!>Z>(`FV^5%팿4,v7~ CL`rԎ^ ($<C paNʣOؾ2\G0D&/~2Q2H2F0HYRk}=٠[A6~֝$n*${/JzΩ|CD.Mi8H3/z!8$ůֶRV}!p2t1cf 6lF_Omn:4w/+!aґ: MP:ꇫdje:fc,** 7w5*VF7x ߩ![䌨z;zG*Z^Po9g7z(PcQJ!,ilKKobvWOyMrf֎]hyz ɴP[QUkTi|ݞv8YZr13Y(X-L~mU"3YH]~mt KW9 eerc%,3R5h `O,a3רy7b /WOl(0ah:L:0뢵T9nLk $9*HFZ} jw=,7xRed}<ن @m*,K7F,J~E*pmX_ *ؘCV%~zFG)t]k/ "Nij@\NFJd#'ɜiYE,BwIߎ9mB0Yd":{9րIPn-VJ;<R 8#0)(ZR*,Bdd7=y%^ L,73O'-RT9'K2Ӟ(f(a9M ? M`k} )AOɖm-~ . h'2?Vny'HVAc ~`<|~ u҆ૄeOh:mW!VfI6Ϥb=Yd/u`UaK  4iP$RiAĭw"?YN08gu`~I#KjL=16,/d Pe# r+F.J 8&DHpc)>cjY= y0?'% q-:*xoEʾg Y5jc>_63 !Ekb@Rxzge!oBI.&׉B{ aU'gWnuO:4F竲Hƺb@~F`w"&z0!I&v;\\bGh\793J8,Ƥ񢊥"MN 4m@}<XJ S0J*aBۅGfOPFT+_vovD=vwjn!X(lyg 30II"K N/74NhK$6thM>\f8wzMAXE_d-T+R| 1*,ʺG3FDrj(7 JdZP3[}}T߬rn?s~Xܩ^  鮡 NmjPZ/yt@ٝOAW8=UsqqMz2tPbiS|ܞC@@N6<w5Qy/Qf+[s\SU%?oiݧ\ݩQL6.My ye[9h Dcdnm% fpNbtyO˒rZϿע'Tjk33PW\>ax,+cmDI= ct_0b;MW(7NW2m̻_$rn!:EZ:CjrͼJidEL>r4SmXIwcaz\0!KF2EY]?y'(Hucŷvnd"V!'+94 oz-M˽hxl&{a p\}x;op?T` e9hr.f5nd+%? >ئNSN2wgԯFJ[@ϲu66"xWČ7#>.}w/[~eQFR ¡ɟms6GҘU15J]M~wGKHfdGؕ: AZӍqQEvם1{$gem^ Y7Fo*oh΢Ń~L,V2ujZwGQ־̊,hR k:'A \<yIi bIֻTƒ%+FXՇa]8Ο/"tQfGHc-$HdG@NHmy4TX2s"$X2G1D% vdvݞ<~=qS_L 2x5/;:Nrx˸ ^^= a&6b@4횙N{Oz]vfU%\Kx{\9Um.yZ#EӽrsR$Lٝ,Fqv<  E# i[LSxnl+IE0^$8t0>/IE/hpGW([ vpm~YG4 P#ц9/Z (Q2^b]&$IleF!A=VfgM~WS fkW (4ݻT*؜v6<(x y, <5PD/ђ4ۑCX5X{ߺ7&yqjc(G|$pip5 kuZF?AS`Ō ! BI(9b&z*\`lC@Ʈ8T@K/*N2׵P8,623\70+%5F=%L*ޞ"VMԒ' ܚ'CuN‰ib0ٞ+ ~¾eYjizzjN.+`$A뽓+>Ԩ1S\9-}]maȮqPL[@A\K@:ӳLDza*:zb|٩ëy:Dbq[6u%.T =o #QL޿vIy!aN*5RX%@4Y03qh8* CMA琥">WŅeQo-.;M1PZ4ɁrY SSYYa;MllZV)ؼVϹDBYuA2gNv ?\ou_kCgx7W]yM` Eu%V"֜"qѠ[e )L2ߣW˜%l w5E^}4[˞ey7{>Ru\pZ7[&=8s,~sYCp 6# X|Q4Mҳ0+_c '>m:i R\%Esmr^13zgqb,OY.:w1X\'Zсz)[Q(PvuE0'OPi2wcRPO 8_{wa Oh<z1)gC3kE]+\*Adk\EټB΋Eە|;L[,&B\gr4m#i i5<yƕ8<N akY@Ď;|blO*oL$M9oԥkE`4\OFJ%t& f!V)Fޱ``5ORMa\zjn5}1C쵞K#T'%S*t[`Mfyэ>JntƳ1t-E_ZTjHے!O"rO-U~#[k5F^lwϐ)1= [QE󗢾܂pЂ2 Ѝqx 9B7{O0<Ų`?~( ^NÀpc'ȏ _ JG˦i/C+eeG> Zntusms_ױ7]켆3}QrT>Z, F:{0Ae2EU;/)E>&|O[I&u ~`Ԯѣ;ktմě){x;\!2ӓT2]lL$Gk$[}tβS\ &?T.Ng𮟤$я`eciV*u\r%T4SkwWSy⸽넂 dPv:IX"a1GiʋM*Z 3Ua< <)~9 ,["40L~-HR_#̨dtg9];a&e>Yw sybg|Ky>"`${ ^%1퇨gxAx=83+nGOh%uޅ 5dM }hFP iܚ1c.8r<po[$pPx]G}q,]|VoStLNmpP;fLܭ4;  Ӏ+`LbZXxe"i/ooLQ vQiu@z;4*+cc{wBc(Ά)=L;Or2vb8X.ݸcqZgwX* sͅT+<:T&>7c_kSNixJ7ʊr0$5'/?gL^ ykB%u5}lsA < :!w<̤ZC;k2jbPz|<%Fp I:TˍeDg M`%d8gr"+v̄ NM$\m =P6j@EBzBo;-^>~ppU?en@B}~ĮLrTfopkry+_]xXq&oPWt_ b~\Ocm;Ş 6Mʞ􅴒ΜޛZ8q?BBso}>f{|[pN1|d O%BDTꌦb!g Vbu]Y@: K|d >p FNxRHK˲TݯW nKFwWmRɻW1xKPuf*{h. ±XG8C^ݳ3r ]rJJ.̢~"-EVTRوtʈMW)NҨnFJG3>1ԏm>@Bp}фblь\\G 4??٥e  >p6$Oh$BH 9ėpvr72/#ƠKƗwу=#L2G>Dyp:OϾze]bZY@׷W_N i;Á[BÑ>Ț&hd,Cd#7iWR'ʣ XuUԸiWLYR48,@xQRHq<PBJլjo47AƗn R߹-IU/vXNCOgfyO?\N |:cEC`<\Z^"s`oa#TŨ !Xȁ8(+sod bt.k0@s)T6fI h5t:a-QƯR6҉_9L~0XTuWz zza}m.BWUD(hI-RoG"_^VlيJ98N `.#Tl&]2>|~>;ph'; 2QL%imHzNӞN]o$p,}ݮU ."ϹQG i@.xA &PSB ^{?1eRy:if.^kdL-4? sؔ!HeDXei31ٕÝ[|8Itn?#Y. gXmd [8mG9|UuL1)w@+0[3Cmy3/#TÔ@8D*G45]@K/(Eu%G1?e%m{='Sry~ۺ[@hƇpZ=kX]`e8 p\a';DIחtzs)he_ 3qHw,wi`vJt<!lC.FJH7  %uP0&i@k.'ɕ\߁-"Vp\w/w^8+ǓI8,p%[Su>l-ELlq[P_6G\'ER-7mVcfPVRGݲbmm['#NA H_RnAĒ|S21:[x(Ú/ujn&109k]"X8Iqc#ƞVz<?bU j_Ʒ&?+7y򐺕WLjtv|tCCRh0ؘieQs K'"Ͷu!sk$4=VPbAi bJµWs1nw q'oF0Xazt^Dbp,TLCfA 8oU+244hdh Ç?Dq4l#JVypj =XLwcZxERge.j[Ğ5P,7w2j|:5- ] xsjaC:Cw;CxP0Y lyQPЎϾ: ߣ hɂ g1K;|׵`}e,zvg@6QI;I]PO‹?_dwhLzʖ1">9SI2\̯:t໋ s,[}&]U GW)qeNL0ъ^K̟Ք8fjܜثSg AiW壕1oB _{`+MV@!yIq?1t*{nHI}ʲ&facȝ/ˇrBFbbZ`aT9z O}◭9GamD@!]J)Ljvɶ~ Swe hH^<uƃ},]`pGaHuC+G#'ѡ}{9Ē%Gsa6B(I:iCrx SS2z`B."D㊔Ŧ$eo"Ӣ}MmSr]=9:uX(̭ߺh[h%  )X &72gn8E/]0ј#-(H98KaEժ|_97ݴ8a.F~k5ZlWb䎢Uî9  ٨#ˣ"Z[h[+vBgͥ_%NUwzPW O v )d 6i /WAS-[ l;}3(N"ِuPTksZgttVΈoL RwxNI_4Fd`p=$&Q.2 H%z֫y(v ~E$Y#\4w.@i.Ow>93Oc|)- >& YD\wyf3@f!UkѓpW6m}ftiM6+iG}[t+/UnB0H?XH6i` bwO(å06Aq2$Vl3Z5PD>Ժ8JR%RjYiNBwiwaɆ읕?>Pǭ謠 .) HSAp'V\xQ{{٨οh Go UٷU+``I@:9Tp,z⽭cЂm\ՒZ7~(POۇ[(4mK|G6egvPo &dQtr[j~N=`yz6?I#&N k}ڢ?eH˛;ZxK3e\ \#,'erޡEmJ/Oj~z'&ajwnN~^wj,1AZ]f /_+@]"I;fN-N '"J dbqF##XtJa&=yIY:ZxE?Ⱥp#M?/Nu3^Eh_L|` ZKc`Q9,,?W6EǶѺNfnFȚU'cc; %`\햇Z&!ظ%U>hvtqYywL0Oe*hݚBn~H=a9l34 M7u$,*ƳZFg̹#,h\~KAwR0yӵ V H 9-`G[˜m!Lgpm.4"\TȁrfD> **^SCIѸB 4t" :jf> 6m;\6n{K5z[e AI²-ŇGJwH0c&#zxS iMb&CCq{x~P]H.(W*cP%D mӿrzuJ_|R{Վ0,&HQ8ne r~;]3!+ΡƝ8Êdz"fT >@-0-@?byݥV ]#@f!`@Kngo7r'IYQ. UѾ;,̠"?K!c$`Ƶ.MYeZɪ~| "`v2oRr C&J-0 %Rl-Q4r}ci7( خmDkt.Hkig-ث ;7Ta>y((MpI uA?7|O.r-&"018Ϯ .bBw:LKJ*/O1tˁ}jF * gt2iyO0<&@r-&EwΣ팁 Tw5뀦+UNxjz𪝉sv u1Xr{~p'hu37G>Nһt%@oz< b&F;܏n9J,(]Z#/6!_hsSr W]:-9yf1yYFVou|x_Tl4͛Wue,cPBuHu9 {9ވYZZpc1oR#&gbUc9tÎE3@Ss`Č \" pqZI#E>zF;qpkH o:`;[NWU Pݯ@V^H"'QZ(\J7,l_+Wg}AŃ̂yo=p<2#TpY抙|]t]_UۺH3cͿe*>xFا=-"xٿ Btyh[zû{JCR}"Lxymes(MDh@K'nO\ O; BrНӁDAz MO %F*_e'!`YkAрȌeqI!S*RU_>e)~YFxÈz65gl,A#%"w`B#/[}[i'//UCohCA; >J߈7W;x/!gX4cE6gsrYT侑);rk?,{*-`i'kO\3bϠ[AWT'vGfvo&E.@O_w_pvM@^ocڳփO;|6Ty} $e3(ghlD .Do\e'nI'Zm/"2\5}H@5irO7*Vvt OsnI; r{', Ky܎ Q`xNeuQB: QznO~^-̈ NF$? zQ B} fZIjEUtY~W}ꦱ_Y^e| S!@dEuI3Ǧ]ʢKSՎt=mL0I?I ܄Sw 1i~zpxr>ȓ'X@ qL89}f -@(&MP #/U_ft&t ~]gvzr!.S~6#jFȐmA¡ֹ%S@FRDWq: :OG  ˠ5cfԲcfZ=c__/w7@@?e$6+J479x&#_~%3;'-vESzT SĻ"70-ufo&Pݍd~?. R{UFWH 'B#I Kl?6G B+3 GRr_c& z ETlaG c;q~JYCFϦGɤjT6S, blojPG&y-DR:hQi-)24Aa^8}5< ܕ)Rq]}P9aՖ.2R%*ʽ߽gd BNy^IrK3t98CMWIr(o,:`4!}>6vOIWmu1[24Q4Nqq tx4#>뗤3ȴ4YK7йgb9]}7ƏҴ@܎ wp'ZrJh1l.op*K7l۲sv,;?C:VxiW³yZKB)Zsܷv$R a%{cYw9R(_: RVXzP;#iiC],  hub i|ڽ ΋X{蕧ogh pHtGNg~u">VAw>!8-D\RNĪ0+;X),VpāZqܻI='*?s+IY@'!_B\유Aq/9R E$h;|9<1FvqI)?azoƳGCxi!a;{vOi)4= /.wOSUOv[wIMbA>qRȉK8V|!GJYP #%?9'[:vsQCXU;kiTLw9(]0˱C-e1%(kY GΊ xgIz]{^Ŵ@P9;[:ǧaط8̕CDѠ,/;ֺ͖&Ztw4 k%3{C ^Քv(&h06tc$^#w$@/UtAc 6'Dv8XSp&F#h9_ڄ[AF)_a䆙N,ISkk2! Ģ4.]ksP1PT@zzLY>5m[Z-ƫE uB}; 5x8䒰> Q.]_hg@m;+Ez/Wx7Y2jK)M)d1teȺPxdvҿ#h>#%+k=km_Q3:*ø) OS? hdjE]%ؚ"籶DӓF:XvC;5#h[8j^f9ěu8q%h+eQWYape2M 8 5Ts션Ƿ#d4NBho3=M4$mr.ЇW1zgpfP OpC^Y@4ks E2\=)"fl꣇ =7^{biH=Z;^FETkwy,4NmA'C[ 3| F&"?Z ;GHtKT8LLE8vH"Z14~lzy` .Jn4a£=@p0#IsU ` }G(J=e*(bzwP+!u N%_ךʦ~,/-^?8PaM=E&Z},wrܯ0oҡG> ~CHl8FJq<"$,`Y vX2k;2P׺z +{7dִ3Fke+-QOm0SD˩k磙S: mP毑"VS qR/>LH9_>8\kǦFLGwgnj="xtgԬb5Կn T|fzx?8r;#Eц'π4V?%:on\?YY"$q M8H?VY xwcM8쐜ѹJPLJiAHAժ@Ss\ эAPWQ[BbH-I=ڝTnA-8_>؝$51VBv.F$o ے$ֻ˝_FR8{ԍy4Y4'O5v#y|;p+Wl[;Cu7E74 cmY^ ]lB+? R(aѹ)Eq\)ˑ3u.rbת4pje#=vҜ#%wbWWd"־XhC)l(_9$r-uZ WBsX`8l7 2ԛbn6j~l?T=rݶHBm\gixqɅd`*SF^8e_͖rWz$E)4KS'ZƙC*BoWP;_WĿ0.ːή/&,2y_#@mbǤB1'IJ|WWk7E-˩< 1B>+ ~cB: N/INC~2EpTHK7"OV)4v"/UV<6ˆ2Z <]/Eu"K\Bv-yU&i'8 7lYd9FDO$n4:6ƘxK] 4oJ^GW2rIjlqd o"mhx>0>2= s=: [ $vϪd u^;oYcҿ!i+"VNhҽD+bpp>+~! fĘ9Jt\WRՍ hV&ƨdͫzq;w=Q5` *Ej 9tWoJ/ [.9r"m݁df;ȶs!ȬI56Y3жuw:g) id#&GxDSv<m~LZ,Dz.nl܇[$ҊsPbc^X@ZTF w?ɇ_g3e#W4[C\YcF:[M 6 Y0tx`gM6;*A/IoJQ-W6Ψ{"dyKZvy #pKŇFH%.b%9y#iKAl\a*њZPZ3g{/{}&Je2}?S!τ0?xm 3̺>hx;E4TQq|[L2WhubHPɦB?>&˟h8|Kj 4haai/6>n\wwtu91K摖U2mgtǻR# $ p΃M80y5pޟÁb'A-hF,q W 8dHΛC~f?<(ڭvkFSoG:9SD6=ECsY%qox7?Ůz?XjF9\j%)1&E TF:aPp$wY̗\B]ѕtP2J}K'OӵnDx!ku\ۮs7>cō)SQM6}a!Jp!'OgLN 8|?btrϩi援 giI{.dִde1( f&!8N[B5z࡜6撜& d !3s}fѳHTS8gaCG1;?0`Yp!IhbVAFMa "ڸOvXooj> 1xh} +T?Е1̦!̬d̤+Nǵ厃*HXO!YNIbpd{h>˘D.5YXT8#rЧb/K5Q+e1Lu=NS_H2f8/dNz2rX%7 D=NlLH(Wpa,H;@Vs. '8f l5U&c JMϸ|pjR:v+Ԫd-6FXp H1]9?@#4E I*l6PhߌH7.{imNd1Ď? w5UsJt پ`XrNRmooyޔDA5Kò|l eg;"LNMA1 H^][T[0-i]5{T6W8I擔E6Ȳ@ݫFB&;\Hn>[IRlSPݕC qq4:#I|}3}-%4>GyJwN2k/W'l03Zu`YJደԚO Ri-S1X5w\@r#OLK׎M2K万[R^UҘke4F,`jSEjߞeGLx&H\ G_wcI8qN^ 9j5߲i`xU\hUk=|P ?m34d0OWI%6Ձϰ⨧Yﯗ_EWB9Ą+l4k7i1s}46璘(s/7$ٗv}-\JACb砊T 1x-,uw˫1ORଳ8'|@Ťz뛝hil@􍠻sr&ѽ‰Nؼ("h΁iCc6uj~/UVv ҝ/7}sAF76M/NPb +dn5ԴO!QN~+2 e W h09 ^+ޗ\*$=agX C7˪ 1k"X9zSpQ ,q"8c5hbFٰ|}|쵛0u|20R%,@4G?rpO;@- ]ּy;繠ZCc1XzMVɅOuR]6M MjQ[T_M];1Z#6,b,ky P/%cW䍈 rEqQOKRtQGXT~>mBȢ05&C8fR m)<0iݷmҪU/+n-Y1'gJB],r5ǫ(9cokE<2h5vuAwH[)o$Ҝ ȓf@;:&/vg=AVڭ+LKվ㷄b„Af e~ n!-,dJ2]$e~ǶԚVFH&IdkL?^![+tvӦ%络]pB1,4ð焴G+gUk6@Ş0qkcPwzYf-osDc/ʵ "ѩNߍ{)uQ&Qgšc9C8- 'F.- ct֚aZG{?Pz;h?"+ <;K`h.q{,nb'"Tx6CsP99qvx75a a1MJTi_ 7!ʖ/D|p) كh ! U^4I T{h+V*eE YI z3<`"p4Nj" ?]&бBђs0%a?z9eG잧k|~75ȢXm=:+燛bAEJ'2LmtMSm۟kEy7?@{P('ˠ?9픱\17nXib_ @ Ɍ "~IH NY꺋˴V4s^i$׻ć?N+qt(G]mAԹjkH^Π׊6hi$nkC_;HX}^T=,*207Jxxo $»ۆۍ}͠f`j 0"0شtb@MP./FRo*#x\tGI˛ {ܶO&QL/q-Ch -OS%l}M$wȑ5s?PR??b"i-MOvAG{9?l0\[җN,}瓺8ݥ=*'1+,L#ٜ0BߛhL:lR.'\ۨ51b\@;Wp'`[ RT> ؽ۩ƸOߘő{;/$?֢e{'m&IiA&#LՎS`im^%[$iJ%1nrAs~lGDi@c0wD:p  OO9 i{ad3zJa jH̡WS>B\ JFmtWD|TtDUd=ĤqacW hgۢW%۟YT\$$w.K᭘:=En1p鉗k +S)!7p4#w(O+J~DbvpvJԻ'U>qɸCǴvJg?T\9.7/x7`/y C/5v@ eOA.# %+ <%, ׎12oFjZj1MWwΚ-Ŋ艽׶vF A[ {|C?SU'3?4s#-\*6釄?6b ,B߻YpS7׺M7C{'#Y+ah?A|Zתm&B6,QRSr80Xm}i,;)C7CKSzunpnSoCjb,&kħ^U\#ln4g_z-!~\' 5W @̸$n _.$A pn8qrj7fH0TL0&:3ǵyï|$оnIqflq.A-'r4aH}1KO8_A("\}Bh0`iY_/Ph rTQ);vMٯ]`WH"+0W^Fւ4 blD¯5Ԩf3 mo䳍W¨-R0-c!2Oȳɘѯtn0miNr/^;TmHC4P*9F)w"ŷ/|D=Lju$/)#B*+W2i MMDn̉N,Rv H+W$Nopb Z!ã ʏL.|RVUBŠBw/5bPB>F+rcSe<24p2ܰ 7 fp$ؔo7tXZ}JQCRP>bK%bTxEA)L;myU9R^AprL  ? =Wnk*B(o5f.fSajt>G`)jd.bZg5aq* L$rRpR;cPV>ڊ,}ؗpzQ i]Oml:.RG yqwvI2D~]eqQ`dI1M~nݤ"rIQG%\׊qJ+D9;g Rm*oϳzlv} {5jq: lew᷈vmMD CcDro r-"~AʪX Fwk"=CR(8OFv):94֬L* InyTc=C<>͢ ~~syْJ8_X6vכGijH$з! py3VgQJ" dfc$w?)+pu9hk$'dGf( Ӣ2&9$$d&Cbk]{@Mځ5)?#o-"VIIN,P]kTDb#5,IVStwe}^]dLp'ӆbmJÆ4 H!+p2`v^1-PCr } z-ߘMŃіYq i~B:;ǸKö́}x ¤y 1(35c `tSndfH IkYԛv9A|Q> 'ojS2ʳpGz ja$N  ߔq=oi9 /nϿzU#tĵu1o ?&Q%f~_jv V&|~]moVcws})j]ų/P9kMJ*3ioX=:۟Y).{#eX *IO E&էc%H%Vm8a 7EnÙO  ]&Jq+C'ss'癩[Uv22-}lH0)qQrBw^S4VOʎUXr7A\6U[u^A"->Cz˿|\#ۻba܅Hm4gsi~n.p{@ *TG _˜g0 OfvTX˴,P~g `t O}q` 0nh#"FH֊ӄ޴R'YR2Q(x&Q2LC[ÙH0L`&8e ˖ ,(9HbߢָҎ*PrCRTI?PI%>N7lA 2Ҟ)S-:cg W,>󞧊NB} 0 .IC\aZ(&°W{m4m4k:#p8~[IJAcmC+ݖvC‚{䵵czkE͓T4RGDz\/Za㹚hvE/& B$G;MQartnq*FJ]/}" 'qH x:bw&N1|?(mkKOTݧ^E"L2NefN,x8aFhS`|~hRpGיV~fɰAyd ϻLZ;_}A~jMe-ˎ!RP}}?wN^hUԩ]ZE ,KHO93U׆8z .70W 6_Ŭ/~}3({__ BY~ŏ)xZsZ^1[/΋lLТ!P7aH&jpXzspS #qgrf~ Q>6uYwG@Ĭ6SHF6xQMYeUZJ:%Fjvc980eQ$sgM|d8zۋum-fERȯhDM2qdɤGEb) `UmzCg u#?@H25вvf?S6!5\A@lSx~f)5U !>sK(!HT:S2= (Q/8:z}KA"sz(R$݃+%PZbQa@gZnxbN0 ޱԊ%sbAX+xqZ6<ɋ"]"q+Pll5+^dS5&e7y(&0|L3$(N 8.:GKn(=. Cc}mhr\-b8{姕=q9e*E ?/o^&N 8aSƮNE4K`(Ϳ6sDžgs\@:@[|YFb1v~*n˴uΪA*uo<98'nMGEr vo=[7KhZ"Dpy|Z=#Sކr3 (3)5.Pܒ]ix=J>8C#rM$"bB:!mPGMiqCg-= !j$ + KP"eM!*[4h-~< h."?5RYMw,~@JtӡW"#䫴n(ah4‹w^;O?I䠖 JXL8FB2R 9qFQ&+>Uh킺@gu0fxﭩrݚh2s0r@}9Mw|;yH apʔWuXZw,x1j#7Ar{WW~%Ktkˁ;;zsoZEF(>șy6eLL*.= ϣ"ƵH~;,CG-kzreŨTaTC4Eyq+~`ECG1[M`,ι;f߯"|@AtFj6>FbE|_ $dR$z-P;MrZ:W"%۸7 q. /M;A\o1Xg%H #>PAڕ r_}4- qe?O>:ٯL)>AxߜC9 }8ẇ<C GU870 |E,er6 BUE_j8l@*`mbN@*OdP؍V ̶ES-R6U7ͥʐGز6m0E$*%rT:O-$AXo$8D_^+иs3$DWzߔul˔v@ hôQZ[`@{am'J{'zOTiWdru,~䣃Q \^cxĠc#_%(j4"?r@ڱahv`ܶP4t<-VͮO(~Ȯc!qT׈+Ul{zg ySDװ`[A^/akZ_,êum`Mw5,;i+ pR̓(-X*}F@ȗ .m^5.Ts{H"9t3kCta[TT?(F [a@/YlDC-E5+=EJj:M.s3-% *q7}H9[}ǫԐy%Rdy\9]W#@:|54(~"*WA;W +"#9,Dl3j:b6j:ed_:MK朘fh Gu-ehᑧ Ǟ5zn@' X0T$ C5}lי!KvOvW4yXd5Ix÷ A;ȧlW0ggzKm1,-gt́գ1pw^^1 >!qj\ɳMUkdu3kQ]K=.wܰ$ go8Kv ,j܁nSh9+Ac~-u.sb1|qH>y{^3KDXYod?Zq^` t`L4d%o囼5#C2wR./V:G>+yEJyo7+-Qnڏ"sa˕g؍ 4v0]yyf7N_´( Z m8V4lfz{9r{wigҍmtC')Gĕj<4^ӟmgĆMfto0 3I {18[pPkW,][N8BsuDbeBZ6BËFI#/V26gtqW݇ # #<#j;XROմ5.1JL5+Qi}4 :DGd>K~@y[/>9d#id Se^]r csʗ a2`f|O7'pG4MB}J(SÏO 9GY(xWI* ylppآ/VmBɟ` 1Xu{L'(I>ǞO.J[[|^I4DRÌ<`x: ds(ՖtT+z(@HWap39CEM/CSDLX:J ,B-~m,GKN$Dcs'qg=}~dR+;-t1m^ b|sX7.pY2Ҡ7mP?#T MZf+[hPi]Ոtu?$M/V9 H?u|Vt' Vvސ5c`Fl`Gt1솋WO߀ 12ts9΄[?d#׈@ޒ{= y>OXbۋSm{F~- UզY ?u>\A]I-pu`UM} s~|D2j_<,6Y.ƣ$V<(O DǏm?岯Yno> Ӌ'QUj:hu94苛[p9@PUMI&3mA%/{H'z[WP[B2\"ciwe͠Y9VWE6e-'ZA8!4Ii4F_7'$OP!㏵xi?6|!wԘ};T C;4KД Ww5`q/WG(Y~9Mpx"ݕ2}"ZXB,wؓ V'OvU8g2[nz ؃601>={YX *X꽗PR/],LCIˋ+ 5< xqAH_X^=#^{Ri:Ek>L 1؆L6vA\JzE(F\P2ʳaI^G]k1۬1_KyG=e˗RǑ_0n戦1̀K Yؚh "Wv hn+NU(Ja4xL%()@cp(N:NպMjo#(2c)-j=R#VwGB Y 4&!VU{Uw 2\ #= )B痥#}(mBE:9ԀqSPQt5~FMN}R ch?zPIV8X$t=GlGC(] Z05BɜXiȦ j$Ohw2*O4 he@'B&7@w:?}Sqc9'l:{>YRD2a(/P8E9c$f!>mwjۋƱYoM},  u6Ual6j),Z͘ySx)cˡH8;]7|ni$*!T?#x{Tf /͖cfnB.#,H †>}Ͳot3p^S߯deݦkAȩvݴl.'8,9⼍Y!*?2Io\$n‰A_fr+škga|  XZ1rHXk˖Z{ejߑKfVr, -Nj-zw?L91':'1tmEXQ vS(g0deO!U۷tx<>TrkH ߹+ẹ{NDې{aw镋MM7[LuoF_rh /kF0%<80ghtmV̛tmZS ,xW^}J գS$,ûZ[|95 اuQ.îV >N"inc4Y )˲L7k\-JZ}º{qQR/N"esxK)@x UnVBzf8wLlϛ/ ؈~SZ/*q?lv$It{ AU>?";V&_5ȕ6:Zmj< pwd!z23lD3w)~eГpnsu(  mg4hqlx|/)H.B>'DNFfP=ymfj5w#,j(D+"t4;h?܅1VW-kC١ׯaR<ָ>?9J< ; wF*~Rl0 :n8^X-0O<≃M"wYW7(Ny*ya%̷F[:@M4o{)k*w揜) | .Qa͒nGffZCE\AͼUm8);4n]J(a;Չ:=Ho&_!~DݢHU9* x헃_Ԇֽ޸@l o볁]\fE̓^ҖI, P>|g^1k q&I\9"mldQzwC}l,MzHy&Q-ՎLþ~Tp#X8CXzVW5CU0]zJ4N^ѽ$gS?;2CT#wIliI%OHs%u vj"'#1.eR?o$'Ds[`EɡH#c.]V~H0H{\lO ,o]..P kͥ1\H `.ZmF~Tҏ~).Rg9n v*k,  6 ҂9S۬"kc\=פemî$geSѦQToM@Nw*(ہ~;Tۊ|l(n j.;F%ݴNVV)vd S,@< 'VaKvܙP O+>YJY701qBӋ_t$|hċ>`_$ >f+lt׮WΠ{~; a3NxM5GȯL$% -y㐌aK}|܏# ##GGRK=orQn'nBdX_9/Zߌ!k zN>{J<|l޲)8S%)n; Ǟ-/&#N2ӑtEYOgxF5O7#BPs߉a 8E 4'+ї.v#: 5KCx+zgSfʇÙ4lA-_q /M9_F[F䉠7K8o1@ qt?Hp: ?Ib9&)%aP'o,M6}Rx@cP@T{^k\Ecg}Jؒ"U rӷW:fSM=ƐqP>ג(Y@VPWPfG\qV@fcʨ|fUI6loЙJcJu΢LjW($G;z@$lS~I.FW$tzm\٭T)9s5}H.Xol.`[[Lm]J%A6G|bP[:- )us50_Nsb6J3%޲zT|dk= ~As ,&)'X%Sn (@2mP5i)|EAsxQա3eCPp -ҩb -m '*Jo壙~!0lOb_/N9RD 28t ˥<8O49/pRߧe |ط=uXƗ%??$C&F̗dQO^~c8›dK@w07s` c4AK.Z|L1H VPGg ]cŵŃi7pddw ϜD.ON:ӥԨه[ BH#z#g]CSAz E VXbN~çtQ @?'isu8^r31D)T0|K.92>4£Izh˭jxBsde([qYW}I46AoSP_}026>GVoe[w*l'!GbS=&Slʵ X ƏS>i (1#9RvKи|<%x8O~JV\.܌#+zTQuaQZ QM#ZiX  Oʏ*)ң4uw}/ ,^U{PN>3zEv^H{ G*IPȷ "E-8ZbY ooGEC.K  LgK3skrs@1Wp0|VD *ߥx-T}%[lʑ`sOwD=0AIMiM=L*X,- j\Uۉ O/祃ITFVB.T]x%qDI",,k-h~G@B]f E B{ ُqe)0P7I#͓[/$kqmTlvػڷ!R,70ztWsR 2F=m.urXÛTp1ZgnMŗDTQENG5\.~=snTݝpzASz)x싌)uOS%J[9beQ} XD&aN΁^!` m]*7T @끢u|rЬ(ڲk:i]x!bB49`7YB<0 CM5ʧ.b>qv=DX=`3?aB o|΢F)O4>l{] dL1Bݢ][AE5F2e^E).yo- Lt|J9r_GWKK#uRx=-uA 1fnVغlwCS0s)\~I8nJ8rQ@:c<`p*ZMnI&m_iFm~3.{*9jxYp "[D#BV^f(ѺPW<ޓ;E.ti+o}陜DoVܡc PQ\wB=8fvܷ|S WӣvYGjSjX$%_p9^ǣBĪE6TĕBr8Swmr;;祢#bkkjDإ߫h,<.H e%3"uFb᱂cVZ7FM]-'_kt,n):Y~M+  ZIr B[|- EHe'*XiЍҦqkܖ7 SyeC/߃'+JճC(8$n/җ *S+Xymz?4>[DO^-TD%"y"tHPM =,3(~Na?5=qOsĸ4*ѹV faD߯o+B(F8m U!id;OB.=gd{8Ux2C^E ,dzvwع6Մc8W5W{&fF?ZS/q{w8m*h=$уCS3v%} GLmx-ANJ.;J7PH.DN~̧-sL&d=NyMﺲzuAW1 ӼI;4sgΖ2R{{件7:a.;#񆌧l(ce>![t:o57q |;B(DШT4~ T @tF&I"]K,ԣzT ohyrѡCM( =3W `ff84F>*` PlأAC UHu8qw O? L18rmUGڝuO3١⟙=:~xa~ŊDc&k=$:68g5xABo:K 4><2k {\h,3F' TGdjfƳl?o}RW\=8l {|Q V8,R?+ WcyygZz as˘ȴ 1VԦRr0Q u8.P}#]OX%.A2 ٝ<" Z x Ɓ>V1 $*9Z2O}$خQ)$@6}z -݂ۓP"t㦋i 8HmsѨn7/v^l/B˽Cafj2;P_/xOn Ʃy9Kdw{ !6gXdZœ Fotd $s9P MU&(?T9C;u, w|,$e8(xA9"\!<8f1ԠۧWޛ)r =l& yйvt#ƤIwqIR0.5ٓ"myҚh陁OyZ.2Ύμ la_V۵mL?{^?H%NyC&DQ-:6 lL'C(}Ub^M1CJIm{SRuW`QTw>(T\~1Bn?cSg0k (ַ+;N5"h~6'j).n(6J@Ḱ,ׯ_|VŰ2J=*wf-aD6iFPA?ͫ+ȴE4y%rICU.)%bI y' vnh8Tɡz'~S<[q&)RvIԿ>?dE4Ox҄*¿]Xf 5g)0yZxY1NqdʃN% .O$qG?Hmk?RdAb&5XəfUˢdѥR|M:Z8ŸiҾvhu=udXɜOЂ42@*G\ġ,J2%9n_Hȹ6q}I4c%={id1UhYDZp#qB85nU28BJ@uFBg t1E9EĈR.oS'4Uk7:]k! c9ATD,Q: s19,BwKERGt5S!9ւS<:?ӎ.jW<V!8m^4.t*C1!]a u?4BayM0 ]݇]:v eN& 0O˕SOv{ ?۬c@2XjgC|1uIsQS8$t.>]C P{.< Tf|RT7X|!)䲩%e =ƾ*>P:6.XoC2Ǯ!O>uK~虪(VmW[lI41وayM{2 L N;shG:h#뫤.qIr:q?kFi5.naAM6F1jDP[GiŮ jD;s;N>K|@j@v[dfƻk 6'G2fݗ7}Op@L0HÙϕDq͓\W]&X j`Q3y6]2VY}& Tl@>rh"֨o>]0.<f<%E6XV_xB?! qNtٯ(9J W[?ȴۛ;ߘ.m=7ЕN<"\|*6~ "FsǕL_={k@B7U/qIݑ X8֛4v$.-{$-9S{ Ds(Qo6G[pٰ[ow"ΧuCL[W-cF"D^{$&{150o,[ aDG" 4Z^ D!p(3BsΊI(`hLTS9Os8sGC)d Kϱ,1JXZE:dzU[ '7!Za"UYz F ` J~XyWSֈ{8B'`oåkZ EIư&^Z޹&C=5drSsFhY[pŢRjVٯjH@au/['M&qGބʊZ?~0<7S~Y [6]g @ 5-=Xy.)F6Hg0O2C'[P^Y[khDH[@ċXؒ=*~&NӪ^`v^ur{u>ݠL}[b)-Q} :Ou,E߳`Cvbc4"iQFn=ߡ|?~"aY3niP@`7Jg.">ڂ>@VW =X3ŜvתjhTT;~}JU7g*GJ9eTjyUf(D63,s=5sSJqxf*vwhnBD iw8BzY/ݙ!̍r[ЪR.õvHRz #(o /f/19T:$%Dks<8+ҁ]jb)_(h$?cȗz~̈́rբγO36_Rj*b +dzcx ϛOo3&s#87?^$e1Pvm}?nevDጚv*$jfxi>b EzH\yMِ $Gz4=XadowZ?Dg6JhA] !rC2=$r4@yfOihU߯OPf`o3Z&)AEWWNgIh {NuVAaAezOLG++WIW+? i s|(FV"6(hTX3y,ZH9Ɉ~lx"H9 EZQUщQL4x$5%d[A7[I[hyHAݗa]1 %W>[5IȒN/d4raL5TZH`@ ~bt*DJ ߃xl#bpƒs J6(E\d#-iqǗy_4a뢭;3Plu2)5i ~HP RLMo -XbnЕS c6HەO\SwffrX X]b:y1SAQDYګZFX>*P"Zv2~}8i_TP<ձk'ANDc΍:dsE2u[5lǥfjddPK!$#2xGTPǛ7R {7z5m(f%64FĠH9MZ,}X|k=Ie#&؅-L0/ϕ,Ÿ9'˶l:G۷=H@G}#|v>-ʪ(&WdC' v8c-Luӥ!#S֬Pryl0VECmOFܳI~>>ԚR`qWu4k4GL|M|3t+|#va8xcҺaҪJZ{f4/+AsDqHOhwؒ䉾PK6UG"p@ϫk5DEl1D[**q:a.?oF٭5aK<$-B'J;!_$hRYXUaԘv6+T:N \ K܈S rh=cH3$tJnog9jW,IteBG-@L&P49Л:g_uݑbyx$y4eQQ2<9ߦ1icejLx3vhVLz`8;i+-Ŕr9{VB@ͪ (HNmaO g!0TّT߲=lѸ*_B,1U9N,T=m< $qu:U~G#M˩/'Pfrqg;0~Su4Ԩv͝9kB31G`|݂W$ raE>H,G]t]\`.6I4"3n0&~y Ko7t?58KB[SŸwFhqA #nEzCaupb|gPQɿK' BTY%g̙lxbqn8|ᴍKRGv޳KPh[vIS'Un@ G\<_0X8ݣxIQ'f}9?8:`.$"﫽BFkcc)$w ;"1Y2\]hmHR$̐X̩h0M}zC=jбNHV FEGp@T9``iQi/ޢ1&wMgF`bf[K ^: OQw')rL |)FzӜJ^huUJJ Qz,6( b&̑):x@ e{©e *Yk9`W$@ɓaƣa؈Zs+xx%JAQ&xkzJf,Fl>Ը0bz<<tݑtÖ|p"=]/ Jw9<>Pz%cne+}H7P*_O~a4$ )n75L;s"!C@PMGOdYK$3ojVJ ԣƖ qH1/|x.4()vy_0ޖ<$g#-\Zj%Ab%l*'QI-,2DZq}) v+ M) V@!)& WZ2DZc/~: 'XE5(,.My> ٛ7^|!iTZeӖtm~xB[tcZ^þZHAe@_2C_&w X &JI YZ