sssd-kcm-2.5.2-2.el8 >  A aMU]0zSb}}A~D)?";5@6k(FѵTu-kILr}@sY߼4-{gm?曶=[ǫiA2Io(C"V쨒rtR]ӚB#zpf́$I5i&}#~ta}u =p;U{zc`7_x ƵuHeaE ~/CG@X˰AFF,2l̆0U: ?_5/]F7UT8r`; ݀iR1n=Q9PƄ{{7ɝ ~)&o,d ύNX-ݗ} :^Gp坫X}$ԅ0 ?6=Q/q|U I\9"%U$~nZ ]Vv~ǟ323dc51d5b7372bcb9362e7714545a5f00997f1f5f56f039ec565e5c243c457aca0522ef09f48d5c6a84158c69a9ea7fe0088782aaMU]WE,bYHrrd> L;ʔ+ȏWWmkaA f]q *:tY)Ed=pPw~OHW&r ޤuOfGMKAcuRaNoJe %仦d\K7A-0-FӒν3y_d| $49z^*)zƄ⬪תۧ|!8Udž'%aK?/6FTBjU:*rUO<8j?E,DO- %EKłuj#ǭB99jV :7 dlw%]be0F@X^α3q>A<٪m'Q_/wcpڶ*9W,:/76|zff£qv8{ k?-DetI5AxGZE lص1O.È*Cqy!NsnZhq eh"Rx3g_ 1ҶcmDy˃`j_VG (>pBp?pd   B 'DJRgx   , { cL9 09{9(89X:d>g}?g@gGgHgIhXh$Yh4\h\]h^i bjdkekfklktkul,vlhwnxo yo\IppppCsssd-kcm2.5.22.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.appc64le-01.mbox.centos.org |CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxppc64le if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%,4yځAAA큤A큤a(aaaaaa'a'a.a.aaaa#a#acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8b4e29a574d0d8fb18abdee833929707d2486eab2d2c21cf074496be2e7bf9daf2569e2bee3f8ac8a0de63b0b06ea187d7ad056ee800238c512a8d4ed82fc389af6cc1e4598525a8acdfe5334f7d558778952d3775acd7f393bb5feff11bafa6dfd341da60a225b72a27d5279b3993295f3293905102420d77da9cf2b7fecb50e5508180b953426cd1a8f5d61bb945247ca605fa5fc4d8edb1fbe8f3aea00824e08a5e693f6e2dfb646038c431085f7a6ddc89427cedec6898ab8366e5b2057a5acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcm../../../../usr/lib64/sssd/libsss_secrets.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.2-2.el8.src.rpmconfig(sssd-kcm)libsss_secrets.so()(64bit)sssd-kcmsssd-kcm(ppc-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_secrets.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.5.2-2.el83.0.4-14.6.0-14.0-15.2-12.5.2-2.el84.14.3a@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh svuk2.5.2-2.el82.5.2-2.el82.5.2-2.el8 kcm_default_ccache.build-id0008a6aa33b1b799e27f225135ba3c1b5dd3636b99bb7f2dcfa8242f13e7dafb2dfa76732aa4034bsssd-kcm.servicesssd-kcm.socketlibsss_secrets.sosssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/00//usr/lib/.build-id/99//usr/lib/systemd/system//usr/lib64/sssd//usr/libexec/sssd//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=99bb7f2dcfa8242f13e7dafb2dfa76732aa4034b, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=0008a6aa33b1b799e27f225135ba3c1b5dd3636b, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)-PRRR)R%RRRR RR*RRRRRRRR R RR,R(R R!R&RR3R+R'R/RRRRR R)RRR-RRRR RR.R%R R!RR"R#R$RRRR RR*RRRRRRRR R,R(R R&RR3utf-85477666bf9b981b2221ec096a70b32a440d4ef0fd5b19f9ad1dc8534b960d1d6?7zXZ !#,] b2u Q{LSD?*{Fe M8}̿̍j:rmZ}6 97x1GE1F΅;lE{k/H6Y44ACKlz[I9(K>ڶp$ow?þRTOP/mz.vd+)(",I F"VN&gGO)=n>zVoJÏ^c mѮ͒ 9 9q~,u^7{9sr8f=1[psȴ!<,T-7>}*K,_byfd)/(/㩪9<@ƿo(;S>$4 NtiǒHBm4 I?" c"t5d;Qob$YKb akg/B}=J"%D(́k_Đxiy[.-yD *Ppq;O ac}k䦶i?  N23}d4,T-eU(Ϯ˟ Ed#px%ŃU !$Lyjyzk |fyW4=m ȏ)hY2ǐvՀN;\u s!czM= Թx qtZk#Ul"Hf)M=*X7 CTË K5\i70 T[> hpܓ޿`Z KKf nβe4Kp~xƑ@I{"@ٰZt?ҷD?RdqO͢:RҞ)L|;MȣL,$`sv18!aKqy{j=z[&lɋ&q'(V*Du~c +^AIeSp~A]NoT$ bTxoN)Jk hI3'eރ?#Z}%h~ԪMwBZՓzŗ?igUQ,CkmZ~QѸב}[Xƻ\E һ^mޱ;]/rRTOpD<x%U˱NؾfX2i=f0b#S . SV՛sl ^־%x^g9& 4tvݝ<Й ^`CCDTz1 T+7 ;snN81! Tb*/]tL`ᦘ7a9yZ/GާBMb_L\jͱd-*[t &*ǪUVD3B6AulPpRVX+!֟\,hN+l'{2B`%аq}KKa3"g螠[ph^/_ԷZ}YKٯrOGTF-:eQiXC5E%CMb='.wm`uf5?g Qc/7ރ7mcsŨ넮U\z.} 5hQ 390Xc> )"w:J| S3a+{D!:>9W}(MZ'zF:[G(G@#]}ÒОM]v} &E2Ҏ k]bI':9#-"jw9K (vhI5:aLV0~ -疂PG8*5yɤ}'vOX ?iv%π -]$>mU]9Y@| eg%i6S+q%J_ɘUb м0C sWBFbɳb *95쾲PNr8wpӤEb]7UyhǗˎ66)Nvxۦpqa$fȝo_YZ+.qw'9GczL( I$)ȎXK}zuF%WrWɺy>j[NXZ3O/<I.|DSJy(~gtgP;bk?hp0*HC{w%5_j˔Bxkې*inU}9%3o9SU}i0+!^/ =KZ{;ճfvdl:Lߟi !ӤySe_BG &KGs<D~aHD8Hk^JȿL+sy,K* 8HRLj5{-w0C=~ClhMZ6[X@/يo4x=>y>nݣt 4DӁͿtwhʄdT 6-E7$]^~%'QLIM/҈{5۪1ۚz)4B3'~RțMk!8_s.[7(Viwꙕ[ ʺǩMV'0(̻J-3:tl& W6.dqA>ʯ7l@>3F=v1JCBi(1Ͽ?|=B©@c>#iR0jRc'k6FYn[$z:'aeT {%OP@u`?\XL) n؀Xt^HJ]kNR;X%O潎'>%3"U-&Ym P2Pbsp,!7=9GJ&]\^vfksT5qQK-VC%q|`dEm?Rމgb3%ݔ. k:ޝ 7YgpuR虘C1-wľhT;eA}"J;дjޠ?)"(eZm ckZ~[{hHАy*'#D҉"\BFy`^AM;}誴U_WYOӚ/)eΓNV^O/^Gr$_>K> epOp7B'6%0mbebVHD-ND2G?n@Ih)_Ua4d;əݺaVcз7 Lk0;x*Q6jgmkx,yQG$Sp<kcvpD} ?qm?aQ;/;XB l?aY|' 3tG:(%nXd|;ri .?R jځ839e[BAR_Ǩ} H󻘟Msk}yU!8ino=/M`3[-K@1˗{A`V5gV.Q}6ǠZƍ%|DEV1m(y-2ᒆ(ϚzCbuTz~d;f2c+b`DDyzd?j}ZȬ`nNV Cz#VG|c^0ΊEĉ4eA_]F,UDmƒvtxezc5!K ƴ,jY16MiCB^e+ތnBL/~j<S|F$=8wY˶t#eACj&b=F@W2/ W'3G1y޶ɥy3zJZ'\~Z- P~E)x>Q4 ^$!-MW Ϥέuo zi[ߞ37iMvQKsB> wu0ԝijN\Y_l<^>eg*[3!K~ZÆ[X.''wYjj窣Z*xxBt x4p J?C$'`E]V(&ǃK,_F'W`ŭivۛ}JayYh޼R듫D(ë=(z`PޮS|uz lQʪsS5U?V= BFNXzߖ;BGarvR[n.4բTɓPԿq~AF.5:$MAxt)t7F/藵}D]=K!1j;]PG·vz:ZA`& p+/?bV{Mۡ.`8cWIƖziK:WP.uL`ɷ4p;⍀`ȗ7OyÚǓ #eۻEKG :O}.ʂk؁u#vDFha bJIO7HBUR_#g.;xJ،81lI @MCv=9 ,hA f< 0B}e*vSv|- ,~7e{ C 8#V<\]EER&rkIalqL!2s侀Fot`Vv "5I~_^Ȅ$i3 3pҷơ3w2#i >a?W74h qMVVQ{`6=%PAQ$/1!fbG0z!X~Nf%.ͅ1"7-'6]y;% -/V[ݤ/N>' uYߓTPNQ`0Vץ^*VD̶y!`N2w#hn0M`FOnGG8cT_D Bq< _)R A)qML{֚({32BN׹f3K;^E1Svn6VЁktŷe"Ǡ3]EּchZ?>=.WϫQV f'mDaQQ>jnbzt+0EQ\2~ iϺFWQIcPa,ܬtlt(PO6'Mu[ zSt' KI^;,7EKh@/̸yzT؅|Wrf$ o)!6RKk̝ښ-UGJH OE(Э8k#?p&-Azh{=r ^ԈW!nQK U{Ne+!ow{ ˲މ*@S]5;lWX9A h_\w!=n.X U!@ַlPZGka7/Zn)f *-$;fM$P[d$K֬3Arg2h)0=qhiIjuf%g:OGm^I ( ~ODgQ,<]2"c@)!ZYxSGM<ʊ$geQ2xБAsTLM K_n.)a+OU7n!@ohܷ2em]wڎ%"ESrƫ}6 ]zI(ma'GkXM&ֵSyJn`G4E}2}s<#3$((ڴ Z/D?dw*yqQ~p5҉BDgWçlή ;`޳;,jwc[1t]T|7' 5TSi/݂ܵUIKq3ѦȪd4C]71n(PPڨ4~KWC@uc3XuȄunPGƂiV V4Uܒ_";AgkF*W'w>=ĹpN.\;[dz|[] hzx<(o4~s:7ˇnpeolpW㙘,Ɏ6}7NM3X0!vH߃^xy Z6ME0:.⒛?cC&_Bgg?iB>$yY+ܗT{ lSQwa4}-1d 5D# KSΙ aCdkpTtg%wVFJƻM/MgPB`zI{?,#ޤ֊ >}KQrx2gZ>K5濄7MxX*DJY\![ݥ-i&yWd#xa6/OȕxAn U?7{=^ĠL5z0ߨR<0hNnƛ?N.0B*9lXy;9POJޡ PHy[xMG} y;D/l܇&j[ArO$Iy\x[B=b YNpTE=&݄o,4ܦTGSuMҗRx|ed;ws;5hl-2:f\!"s"2Mz{-|3 "Ȗ%J!eOh[, ÐBdEeU`b (kSalϊDE#i{=?&6{Y>@.N 'Ep)C@2~ W 0€σ9J +<c}R.9QMp8smYBNclٴlIk2V :a,S0xNM5*Wդ 5スtjGCA:47 /5ˤD#O>@#+K#d;ݵidVI男EqAr-숟AM9_e,399iGQbT1dtٮy J0jvth+6yM]E1$NEF5? $9"6NOh]@b,1)"۠,E钗9Rި-Wh𽸔"Kq@k ))kL D-\Y /L:u95fMmR"&zyvoBS[H<DM3 Nwt]IwL3sց{awHt%oCbQFX:hq`x9ѣfniin rll[I3S;vŋN7=gKM:"H@Dg0Dkbx|LfL~]U}ʙo3t0z+hc EƬ./s/ ,jwl6Ʈ**0`CGrs{w^P^aٰ,?:.f^`.sH{!?7xe(^'d'W-LsWHjR2fֱK O'OeA:Pj#Z7;>fux Xȯ0n\!{t)_5 ƌэ/# XU 9O^#@豟^" 3>CX\DUU'3zW+!pHq)t&3<˒1rf3of&\Qc**JMlޔ/ xiU#m nu(u'itbЃTDaQ|Aplg| vȅQpd*iAfb3_#:6/KbɸavOHcem2&":qz҃$(WSI" G\ƨH̼kNT\r̲=R(1dã/~,94kF iP>[UH")ٗ+7RKq2r%73G &szoL(xA F' cL6NRR*s*p풏XʂƏVc P`Z!`.j,.H" Y8(Y_َLg؃vqm k܎'%ǧ-Spљn D.QB;eYcNNQֺ X7IǍUW}^jVB94> 2لC~ P"qt8?x~cRKGa]x[%-Igx*w|虇1OgʾG$sk0'ȱ^JnWn pCN`?r:\n7̄o$^KS>j ==tM6yD&k`RD+_4r'ώ)7C! ;EFrifUXdXRIMA)wj|) v@#Lɿ$ t?Vp!T$P"*@K5?٨" Y'dAa-mQ/$VON{x8F·ŮR @aFD9y6XXBH.֊H4QFLTEK}vt| CVI(Жn^僻X9Cͷ.#(gMuʢ5jBsQG!05o1gT^t߳i醾_$Kbl оĪjN6}oNKZJd5W=I"JߨDKTGy\BQ_rjg6"e'oߵ*oAwb.]( zc=t1 fs mU=[ʤ /r6J~&~eZpTOȽOAߺdn)O@)Q Meji.%G!Inu1aM MM]ot0E&Pl)mˮ"*9cGhD$Hi2s z&FEȆڑݑ+ϛϮTzhwh05h W鈠;nzd6OZÊN tW[|F54 Sc/sϪD*l}%"gi28vVfɾ6aKCaVN󧭍ຸ(p2ExH6gGC6.2Te:v#L:O~ak{ud2{!m}2g@Sռ(mAG|0S W̊(+ իѿW6ư6cњqzO;W=%4߫ hWw Wv;?s,|\Yh'GƬbD +>CΜ^ x,L"t8qInEiO*Ǫ>Mo77cW9>f2=N qQ$,+vc':oAa`AvK^ "5m9w c? =1Y.mUG z)h)A#%vvN@kS5JXXB,@4K>Oz%^jթS$RۭO ۩w8y}vF/tWz\M }~z6K?h#P UY1G,GكR dU(9?T9m>2CjaKysoYo\>#@؋!I{dҒLg<_?'5mkx)yN9 +MdFZYMrYy5\9.i5H5œL,a2ANByx)hH~={,>4 R11=H[ X@)PB7i8]=;{0%|ٗ{Nա=6^)`[f4jQK%h}|Ц|:2Sr#Z&19,9k"'K!FhrElD-0F; ڣ3gPB7RYh(%r\¶(PS3:U֊}~TW oC-կJi!J.>e@]F~@DݭHd~g50e>u Gel8k9O17o *4p}8+z,ah -<sY,C3b^ 8Y\ 8=6]v8RT A*X 4=.FEkhmO1EI2EYPr>_ BO vF/bk_p i-J) ŜyxħE]Np~û 3&"sYF٧}x8JQzȸVB#$}5d'Jt:x;G`nzKȿ"|gn?-kz5:})gu5AjPBT8( S#ABDa"B1WMBU<[nz%Tf_Т !MZm50.- s3HG-;n#jLq) ldP^*o7_ 6:i vSR2#W A3edW@ Fi58?H$$ܴJpȿgsd`$L[G'*_+'[`9 xq#s5ދ67~;˻Y3u0 Ko{{Zy&NcazO~ۖ?u O:_ E +5zݰ#IwEXQҮoꥨLs'Ux$$@>DՅ^[jƫ*Aië,#5 &3|MATW#Rdjaa9M@m r}C4ߙ1!IĹloi1I.k{ѕseҎ4~֥9Z]GqI;+P'د=2WиT\jW]ۣc"D2Ըn(K^hFn46Xo߷#蕧U&dB$&)qlfTroX.TCiJ4O{cўu.xթd*$IڢA\]-j볶RV ڝ[02W'ڦ~oJ|H=r8r3>uqA=$(Xo,&?vڬ4G6?c<;6f 9e#p0 8!Mۜ!_yAY1ڋRG_˨d q haEṲ&=ϲpiqb1)[hBn0lB8OnJl%jMHgl6j1;] Qp\1[ p9M7W'Ngf6FbQZ_jόOM CV,a΁ZPT:O]$ÅhM ؝DTOQzh8!V:d=y=^N#|38&vxN0 Xv;hNu8T>sa?KW.)\,U!0ӝg3zP oѥ+k9&ONkmIҞUjfmrmAv*R',$8n\ż䛸]sWtQD>.lrqL(B;E:^:јn=5I70D;eG7?((kN$C%_== Z]( ך1RS"i{)J6ƫYmﴈ#r76_T%,0`{Rj`LC7lGљ T7yˡj4ڵ:HՔO &x  bj~'Kq{cbDX^ zЊgޓ!C-}D`JM9-"4g+WDTMoVm٪sN!y.܍̚XCZLVrK-&݌q>Q 79j<^$5 [R /wm, InL&"Iw_o{M!Cb}ZEynwx`>$}㡪?ˑi 0>hocOʝpOq>ӠDJe]ٻ8Q0!wo?VڀPIed˹oi knwd@59@ ( m}= A\,}2uXCVMOءxc"ۜQȅnGQnbS锾ߗTDIO]7$ ӣ)NدMA^zr8.VnYCy"WݙGj&^l(9'/Qnj;Y6NL5J 6TQZσk /qj6yCnAnO,#ۊ$JOo?U([9)clK?Ia@Ǯ q퐮< Ͷ+lSEIW`Ip ӥ"3^x)2ʾÎx qnybbB[ހV19N⌣̎ .$="Uqk>ZQWn.L.E? rTmX%\9umӏ<KН擦$ZAAlM!)ݽz]ձS{(g1>b)H>Qr4,a&/jhwT;aQNehDb-/s"[Iڥt;+m‡TYsK'pYIK ILϝ 2rى-G.5gL?e"'?R('mEfA7WN. k5nwTiy3A-C>G2 z @%Lf]&u"Nm_slȆ՜a4Wd>:)}{1F< :#(|^ޝ_\gKК;"VN2_,iW"m7)}uma+؁Wcx-g4kfVךP_bԏOV\%uڏEs!O&)?IYn:zädH1c]9 -)c܊|A,CJgfxsז;Q.XP9^VsXh^pӘCl47 6o<oomN$Kp.!UehG1H1E&5y-E19hgUgyN<&^K\A9g4 ד#wY,x]52ٿO3SCj?vLoS%kHLUD?8Iju,8VKHxmQ]e$L)/zcw V&>ku64%gthSؐ]\)\ G@/nO8Jkb=%ڣO*m0 FSQ?)_ 00"O9HbK-P@ 6D}vŞ3" Ƅ*-zKɢk46 q%_0科2ObD۝}[6@^}U[O3a?iNUB:8,יm?o4+ṛD5o$g8[pt_YmtH$U<Ф/Gm.'I-E|+Ҵ3':{`rޖH4К[Z.@Q.k)5r1&i0vw\ 8p, h9F/D?BfV@9Ğ&-͊=9wa@6^e#$j‚ @NrTe*+q R\e] ?$wT_pk1JM( l\KU o7$xdKd/0 hD 3j_wl9YkD? `0SL_>FqMMW(ՏlL!V9{%r{*>g!O ޏ&?L_$dQ B'V+ k rv`Ύ%&@[w?ւ̝BV\vqaKn.pk~]V>#0Pf$o…Y6L[_M<\;1#"# V!8MV!zf\>vVWHǁz)ޏEdbpˆVY HPvyټdR΃ &qHț3MŔթEE)_:ȔX9 ' __I} q9I)ОTqJ5.2ݰ 6*{QG9a P/%܀aQJ"얱 &9K%ɀx;7m\_D܌ P^g@:_-c-m.쫦m0$gȬ6!Wj*k,MFg+o)∼,?/cVV܀3wqмY ufX|2- Z#tdܦu[5tśL* %쩲b}JElאE1+={p.R!:> 5(ܱs3tq|{^n/~=653ŴOv34(mD2 蝕] ٞXYDBz~W !8J5p̕aaˆ{ڵ7] -@ݲGKg(1K¨st0:/ . s‘("cգnjs4I{:0J k@SuF{[(J-nb$6zNx. =}x2% #`_ХӼ* T/(1/W6ٳ_osA SLF*4%n@,%ԁxn@kk-L'7kP-Rꨟc`qbpLfsm1}qMc NCX,y!X ^5Idp5f0QtFa%Y=;\z5n£ ? j Aۃi%&(.kpۀm%)t8z~m Xpck`i2$p>iܲqW*L6Fk[NS=E3#> XXѵΫʖ37v>$TU5h6 Ui'<yc@| gB6|t(fA!}x/t/ȝ e1tϭ@OR9VvNǂ3'<"ݗ18"=ںyߣ v߈^ģ`  ^Y4[?Ò͡@+u"So+< 7ɡM.}U, He%%][ AD.׹[v50x7 ޾KO2|(' lq+_ x?Qmgߘ(ЇpwV`""QE \$ 9JeK/[f%&|5cEMG^ \k6]: F;)*GK& b:GbYk!LFd&eA9o}~ړ+P x ? 'zADL:lY~ }^rDbFMm;z+aj]92Zd)=?Uw%Eq[<MuA_MV|O~ț|C م~wn߿JN&bPv,C[63h 1@?^y ˢa3=7s@n3P4w ( 夯yP|8< qN@K٬ýgUvjl9l_\&np3LU4c "9aD@yfB|@PI+֤y춟^nMR"]$kOdP? W)fxQ(A4gRSߑ;|q1#?RiTkOWTkt#-/UDCҐ!G0)wՔ| lN ؝0DJp.|nxETrnޝ˕zՔ BR߄ f1U8IHW}rS{ͳfjD_XOc`vKh?}g]wb|P ifEDAjͨ=KKMHkFZCBNI:xy(pJT.aFhw'UzJ y1kcKi:N+/fc] FϒH>TDQ(Lݧ3br܁~3Ѵ!?=s_}4a*yhPjA)jO?0Q3+`(I Ҿr OIf6"m6 *8|`GTs6D+=wV?m|*7̑oc4{˺lR^jg(EMN)^[p{bX+B MZ{&(VT_S8wkpsq>'c.|%ꈀ0hwKHU@Fp}#Y|2e^P.Jb1o!r@˪Z8vDإDΒ 3a"//vRX[/+䉄bӝS Wou"tv&ȍy̆s&Biꗼ!Br1X|1BG=c 涿8K6lV`mT/ ]"ػ;=W@~[Usb3z{9+qe=eWMbsmkA"~-q`~M5n/&(jmգ+o3U^rҺFYU=@oja W1T6$MfN<X0~& x ]`Ui+Bwc]B) -=WbRH/L&縚1se]; Հvݣ;Pp5Y/0h}Fdeߟm9oݤuCs97̫6$ַrϛ5 = 81<;ӢRXz\ ߩ.vc$ykiT2`p> M~a"6OY8,Em+$dݔ%/[b.F̸$:D`zt#"iA L`@,w+BD-R&&Z!wEm7vhvyqu+65.( h=KԓDt1h8Yb]y !P ݋cMB  88L8pmk2o**?),-.YNbhyvI2gy'ںe0J ,!ev7=.ؼ*E-b %WV:u~2l͝C`9vƇꬒBLSj9cs/zBeHtMKA6+ll?[rG,}nXYxU fJP7WfN0vzY0 Pn}1nh-MU8t;w ܧ_(g-4gT ߔmKV0;3`Ƨl /{"_,Ȥvc#^/)l+/$`gg be*<e#eڥ$Sm(*4@`e~GQId><'9 FoٷZz|~3"ox|@c"LbjGcz?EN|le-]R;͸FudLA䲿+2!S-Zk(e8מ T&e99)%YB46-;oj']S`{E/qԕY&sK1O dp8 Ч{@.>ZO=yI Re΋Q6i bNӘJ,7'[u> L4S*kϟլr l WPǹX2VspFD"G-:хRג1h0=Y<<4 6"y&G0gB&GOShB?sR)ڠc)q:xOVfQc60b~T'W.Ƴv?Z >{S\۲x ~SyivJ0ooOE̸rw{smB L0:xl7d ŝJjםr0 !WDB=n~q`֕8,xkCk%_bUNU9h{$E0AUuͦm0VC v8C55mIp"vWd쿘֕F|uVT9襩G2cɾG9ܨ\L/sB|@U}%{UAvb>xZU/Me$7G/W4Y %Dhvb${:րdXf'Ol"C|e9ޒQ5~lVlda֦2q-$eQtDZˠBTlLO3}|-מ}U"= dWͲC<mpe<˅H2.zR`SH$1; u?^\SyU9F4Bc$/-ZLTAe/sPeeH Qh)ԾEba*tP]ŸOh|_$TLQ\hBGDX>oHE'V޻j>QFs3߶䣓j%&(=-T+ԽW=o:䀽j"}(M5di"e%>[prPSHD}G>/G)t¬͜7\(O2"=gBȗ:7uhsׅ2r,`]igrϜg #m3ჱiSJ赢1f"n o_j/&YIآiLv0\}xhcmHIT Dcz3:U*;4 C6l4սQ'm[mɟiEЕM _& ^M8iȀ.hms=e1,GCqQJښ%i3yeĘ:`$"w<Ǟ'5\W X ,QVZ0gQM(jKʷWM=w8 2;šHRq$(W@l".iԵUl>Kwܰ|JyUƉ1G7o ,=mܾUk2wYi#0 1\Afz-ۙ2mkQyRg) at޿5eDOy&昞q3GiǦH*'PPڠШ; V76tTXő\!=?)C,) HP :r%:|x3\d+OUJtpP#NK}H*RdyEkgLcF#ى\CCeߝfnh 5i6O?4_ɬ`}AkG 7*Tax G~\#P8"`ZIunex~R֥@Y"9{Pp"E*Y_YV5\Kl;GɃlQBXp$`׌oیAN[Ŗ݌'e%#M. ퟜW<],.W4, ,Fp7atq"@K$}K6w/&Mr;;6vCHATf9yEEvaP<*IG取#[&tWcI;CV?' 6'M$[N"\)x ~]&!ˑH3NNZdY:aD#$ f4AdUv Y*Z8Fۯ:fOm!] İX`.:9^ɏAt-^ +sD#`ef ``Y9]tewTZ3PC(Mf}4ǭHE ~Gt?l A)#g y},+L XN &7ְS҉|YI^;Sj;"⯟P02 ?_TZg1¼ ^,Q¹*iR4BG22V]V/9bz_xXP12r*)'eHX{AEZVڿZĥşyU-;e_i9y[\c6OW6JfI=sI7,7]+LdϷU0Q*X i%w>"aq5PzmͣE}T0]"܆KbM/7.q±jyۣV߫jt *wKFEXmˤmJ̎ճ_j1h)%~Jbe\ULتۉ518.gUe*Jv~Ժ*y$=|9?Zdr,߈x^!؁i?σk8MKM($ F@kشFj2G.|1v0{A<"GwT`HFEGODžfL 'y|" 1 Ԏ`0W9&foS,\Qm,jNR]: 610fux3N2 ڝ|R0Uj (uڌ2ne$Zap]|"6Oҍ ..~-Tk6MWצbf\ūAnoÄWm ʺCk݋ K .u VV `YaCDGB=8H nT.s:=B'pxiDqg݂m#Nᅮ@YT1$ g-Hc60 ?eE I%<0YG&ȭ ^8UMw]3QYY`:U ^X hFıAS, B.[rdcYhG]i7nyCYjm?xBJŸ L_Kc؃|-6ȿ5i#RT /[}FgIMJQb;^%O? Z3- ũorcV+!c+ 4[]'nU O8@[6h[ VŹ8(RtZrV&5.7xJ)SVDWtkSp1LѧAx;R]>'” "ɖMǵgV qx ܈hS#  ^ˋŏ?Q qP]zQn lA<$t TNWNu|@MECզX"|re's'O7E] 7r }_$K=9݆ؖ7Kf|^%Z{c`c;Yנz54(P^0$]&\_zP$qD8@14r_蝁s-0i(7"2rM[ø8☁4“=hwH4=g0p8rTx O[[i־y!%d$fRX*G'7DUxNWnRrhR$huwY/D,zԻZ}0tʀXQvyMxEQy:\hN)PBSEG0iV'xK+8BM%EY$ H :њͧ"; {E 6kFYՇZtsMS xyQQK8EC[ }b@1`"]5z!O3Ta-ߗY5&Q`7pK6hȼT_M]j(y s\[R^gPpY%![iA 4_K/‚4Ia!lSB-)8V x_tWdoАlPy=qE" w` h #ise~R`Jo~LR; [csy[C9ؿ}tl,K)3؟uEOJLD?Mo(R2YNMO(bOcϦ&F`kN5|ܢCϰjB̀P5A7CT8pG ݽ`m^DY'zRk ok!_cViF#o-Vbgc,7^aϼ7(7 ];./5u!4>i: R2~P?^f cXy6#y6vz)$tU:.V7`S7bp~[,g440C5`1zח}R]ڜAn+ONߺk@C H9f 2$,\"V*wz^9&R{0صwŻ*f狫#oWjYzQS#*+ uuӜ@]BVvOAGec65еBcsƎ>DԾMӏZ6ƕߺ^t->m*GPa͜X$ ÚiUtR:NQF|\ɓ!y Uh>r//y{YIKc _ÏwJ9eK& z/U\R%+[0 KN/}ߧŴXQ5"Ļ)3KM:Xm~v%nnIa'ۘHX7lUHe!&oTj+6Z*9F 9Op/;| OA VmC&Yj C4Ϙ9H0KpUf9RG%]fQCՄ@ICk֚Q-w0\&݅ϸxJ7 -@|gxjz0rzw#r }W3Q%y} ;"q*'TyF~˿[$#\S9qI ͤ)BO5`ÞPAX8;YͥU5ÈgA~sŒ <J;`m 8;*L_3_(2 V!Xf|:Mh6%Xtܢh*C*<5A`*Pf-\P JyzvY1ק'C8Og6p4I F<%\gp$| gJc&$Ɓk"HtPZ*[ŮƄ15l9A ^ VH> I \ѧ-ԫ%CKVtM $;r5ffh3 ++f Jr ؿ41j+FFRSE/ь`&' %lYo(S)c]|_+ *_7[M,[&Z@qh{܁yqm8UAmgf\ک&\U촛 @P]e|18Ÿ+Z3tR+L,C)$_ʎQYX_Sܡĭ)GF;BJʾa.˪ZC sIyVO)j<`I H[[>S\tl k)z|Ylip|\;qy~ݮ"7d~pW{ ‡],&oE [=焍r}B5*)AOs),4p>'E1j9.͈Hnìy/=onFDݓKWnBsGdc!Qc0ۡ&ect qPa53GJ J,AggGT ?3>Rt@~.peϱ} nޞk!kD_m[Qy~(D\E8UFbXHwq+'.-; a rUONH %(jnK.8^0r<* Iua08 }J2Xr ҺrA) zgzڽ(CAՁ>OV[unȑV˶3 p#;^Xs[dIϾgOCpti'x:2O+ %/.eX-cWz>+o@pF< aXKlc7u23-6^ޯłzpPpH͌7fzSۡWVPcx CG ԬMrUED^]m"׽w}.;҈++0J0N'?G$B!.1&Ϙ䞙!}dl"DgV<|4 Ɍt b]^}N=MzPFуMg8[*A< Vi ըM튣,[Vb8 q[/5asis&n20єRUL@شG[JNK11wSuy6CbFu+Ruju$}2+vrB<`lWb"mW>J, Dy}(kZ18«9>ͬ0F: lW-lu6 \fZR/3vfv(O݋LgaM F8 o$kӼ\j ݛnC+:y6~ci:pr3N( tn1,& Rvz73 f.i Rs!=t+DcڳʺY pq׸?Rp}=hŭiE-Kᝤ;\RĻ B@Сy/kv_6Xg{;2zˊG_p5P,Rmn)}h80v^q!P߃4L7Q&oXNط;jJœ$͘~Q?g( [@J(N]Y//=>@TS2:6>ܚAG39oE)DwjWUԃlC,RM3WTc ͈C*x?+iݞV2[u'[e^٪-1aUIV$Tٟ]N% " +2q|Idbɉe Jhʪ CցP7`iӌKA )dv*8G#\z( kÍt`o^环X.#4y%5~fxw9JnC`hUta5$3qa~me͵|Љ7l3?BWxȞnt@[q)u*exZV@Vm>D0 zC.ƓmO;/;DR?Ů& 9$P+rgʦl'Utafp}B0NP*xgSy:'h\1QOl!槦C#honS0jqL;s0hgyp鞏}qyЖ f\hGX"V\6mx=&HemB$PVM@Y{uUBPb)ߵ{.Cd%.{` }6تywp¥;l)˩Yv'ĿZof+)8ڄatB+&gok9CM_X3Qh+ s< Ph +Ixsu8 6>i\{c F}9sh /h#Qu_goC6Dv K$N6έf5:mW=fz$2߅%Y,sUGZ:7 +]z])\aZ˾Jj:@:YuXU# ,(/X# #N<41]cc}A@xЧtNVlQ@?6w]{[+La"^SsqpsxX\Gj0"K p0LVh@&B%D?s%(G%.BynfeW+S--GhOY昃^C V>tOFf 9["S譣{0L"R J?7&D$8UҕLU2c#;h7TP>CW/VY]W]ʌ䧳 +BZBa_;H>(jٓa& EД`&HeQK؁uo=3D@|`CE1R~t1#Vwj'b0 aWguRI{$|砠 d|5톚QPº zo> ugٜo].e9BTƟe˜fm^2z39RVfqJ˥D>FAU FtuPxv#P,gВSąip7u<%p\vI* R횒W 5U*ޚ } zWʉhXj .ANŃfk tl$;*`dB#.X  Y* Na1~řT};p afkmuMQZ3)=amZWRLP 'Ng>gs{A`wflts<eHJ@tD*Q!|]DS.QesͤdILj!3I~5Ry2>̢&E+ګ(gQ,J9NHQo`hCL1h0Ú(&E꽎˻85O-zƼKnԡ5gD#3j[fs8:[VXK)<ćdg KvKԴFlnJ#Q9ip6$lC%TihvcPW_xeX$uUL3QX+ӗΙpg4|r(s{9ЬnE`]7֘$[8 Yn$ub\>%d1XJsky+aGmjY&m9ۓ OX'HHKRKk"K/yz˽{NH9!o Y4)udic,_s<$ewɼr4+~A$ PD؊hv(lڍ8Pz,HKYmr?uS?Dt!9v2< L?`6 䏍@ݳVp٠Ќu[w󉕸A5OVKyZanyZ&s%]6T.U#UiUJ&LY0&WF?jxF)QClj >v8pr ~!co5"7ΚOçy_ڧ],-䈤`!Y5s֝|xE}k"HD]xT:+Ɗ^󌋴!3YQtdB4ɰZ1́ԺMeM.ڔHz87pd SWnԸ~] 3.(@PlaǴ?ŦsNeL9;>1PC 7G,)m)NBnue,]/s29d%ݱDhs\<{@GsI/=t@>֬6V>M<$M*Aj&9 bw5 ,PN΋Dp2]G8qA3f)WYmpFT3\[Xg|-S)N,0B'~B㘏cճnސ_YLr {׮AD53mc-0)#ɐӌ7,Sv0cG^RA>} ;Ę 9c/f;Am *{Agi,ꥮ }1Y6u$|cpweM[gliઙEGsS~|@wcW&f.;\RT}ׯl}qIXlC77ku|cK'Us>KJ~4gu_bCNbHR9u`S8~g"#\Ko( 2_d{ (cי [gۉ[?U2KgSϴ{3[sHjKnʑWL{ Sؾ gok幦,']XX7,<Ϻ+~TMj&KsZ ŃlJ0bG5B5:?vC@9nV#qb%#mqMm4&-Q@?u̔g9Sqrg/b6{׬q |lېv;Vζ3M=&AJ +{Myb^v@L9{+=xp],_Ao-@7)#7]_2dם.u\QrρHN zEYiOjհ;{:qWAKGW]G6 ,NwzC$\5-$L~5s%k⛠[TV|<,Wsѫf`Dj_6)l6hW={(_4+gCDO1kPWڋ>IPX0%i!څIM4v{W)IWF0(;>g ~g\$ʝE1Zną u UB7?+lNPhb+6rB``VWra'.t$_y1MiC'Ip_C%yK> 뮭4B(a<Bf@-0_.Ǣڵ{i]δXǜUP&7EVV2' cݒyb@"-q!U>\Tg51jxAЍvVG%yn7COe_|yZQ;/پ%PH2ut&+ֵ6ؓԈ[7%a @~'Xi]Na~""pEpq/(S41KG-1b y)blu$V^p~j&u<G1*/\Z4ܣ06ZDqu9"pze}Iڟoie*,2JB-NeJŶ#+yݘK&y$;cJH9Դx˅NmZj8l .b-UoIhS1.HV2}M7ǴYAn-7\6- fڼMK8YM5~S'm,Z)|nvaWXL*ihHQAor 9u2]A1rXPq/#C0{j١qefuׇe++w|('ʱDVN1RzR"GVh2"62-(kM_xAaiEz~(&ρ@pBJ1T=jk`Vnd,$8V`}do*cp=')ǀ1k{uəO_&w+2jb7mfɛw_~?-姐bz#h5FK>{U\{6qP q:t<{i.rLMmr}q|:lyz H08n*hy u tw{7(uxwY9k!A}c@)|W,*d2M4>x_;}Zg6Ԧj+L"-J}7e$>c&"gJ=~eU*Hb#Kyu![L@'؉*` љr~(>T_cm#xw呂x)ø" *!r ٓƿ'fݵφ 7go}}bGۅgS5L@9 kV8FCE RH(K\M1: }Z}`Qokc8}05rvUM3Nδ ^-(k#.:nrf/xM`;NҐ)Nm!6d,\7K348Z8!`$01ا"5uBrK~ rhtQV @K>Q2B I5 |a3$G(;ƆnOXYֳ MIy*)ұt j)lW ɻq 6K{2:сvmVhmސ3~Ž@P˔srWwƚӗ-F ]Ƀ=}).EfJbJ ۵'b6J:vΠBb׫_]1*_E1}?CNՁUҔe^ON<ãoxa܊ӲyLrˢ81(x9PLU| l@گ 6Kl LJ$a@fTɆ*MGlhXl=_nrT$M\)#tlkv`ީ˹;-(.I{܃ԀU+0o(KYfm q6F֡⎒L˚A|g& ̚^fV$k_)Jێ`t㾅>7ISrPSN.G F+NZ5EJLZ2cܼ( 2,~.s)(٪38<` ^#JCAiH1r8=&{ ɑCLGJ ov_3=ߗN2 2Ϩo\1JMmw2@-UyUL.`^e5Ò#l4CiEy*1YVtGV(06lb][yFƻt=/^ ĄN,O(%n$1*¦O*3dG"H!n7hz oZNrKum@*d d?{<Ғ"=z?\ݼrpΤ*sGOlK*whӈrǾof %/9_وҫ#5:r`m)A!<-=DྋR.{H{?ľL>U_XkNEZn ΩLuDk9`Ȋݨ?Խ|lf/Tnή'}V_DD`i!e,6S %t+GYi>@rEz}㫑Xj2BAGeGB`0LNl. jњv^`M`czVGqmeG5P*cAzi1RK&ye<ߗ^~ш&UvE#h QmGsyeCXoߡKH6 :Iot^׃i3m{&p#ƻ{0GVs\Z;>6"e+92-֑W /B<[6H4[9Yډ٤);[t ME~{mᩒEܛB>I|R <$MoOJ\(nm=>hBL-1Z t|&$N `!){J~̧CuQCK'xsf[m92Zo]9IOSPVe;Wݬ qlJKA *UJ~+\zE/^=|+x{xաjbm{@0d%[U68 !U6>`19.! '-mB,h`J7 !z fZ }7aÎ9bV4*t޸harz# nuqrE;17eLJQ45{-_)NS^p_ D֛P>R`RNTL 6n}YKUvDJKf&5YI+PZYLWHLal&z7aiY);EBa*{\UbtbK@srO=x70DxInsd_5i6TMom$nzj{ [I0yT6R *ςd(QdB%6eZR]f`IؑII{|EVM'A 5|+IؾT/IwTa[XkCeS aVu@ݚ;t:4vc- F`Uf(02Zo%yYAZm˥շej$yA,R|lz;kh1_8XiOelT ?Hѐr~R@"8Љd֨ sn9K]hB%ܬŻ>bGcgQX91GGN]P8mJkUiGJ& !!D}Ϣ\U0+sV {l ܣm&}~Je҉^wZurQ6+0W5tJb\WJ8ZG(I-1p?Vie5~tނ =U5Lr#,S2چf!c{#"v10A0}?D×j9>M<a2$1#3e~l(qgT!fF-yOb"92 D/ eƳX=!S/Rۜy]gr=a{Q>8X -w/M.)H)T[ y2S% ShxҀ /CŰ&"D #bD0nC# L!GpC$Y Oy3jyf(4臹Xo8{ xd7/3f3T NXvihB+*D&Ci@bP'ދ/gأY_v|apЏ5 ,74n!:I \N/9nլ>+}[s6#vT'%{Dvlq!{ O9THͧW>5WpXv2r0A-RW3 Z}ihKZAIGU^Hdh!Yb%YY7,ՠ ?~!AZ64nMd$ 1+,L6 =A>ZG4QPy68lyĽ4tCD ;Kȥ7y M,O):C]'/_/K4A֎~" :( ^wic$6b κ{uvG1B׭\&wd2QDiMJ-Qt0ṃ;rn7CsDѳKG++A'':]qhc~P]Qx={/A5 4zWkcdF.B!j9NeE{TMz'FA2# i4zYLF {HൡZu0Ori_B$g[aF0hxd`Kw r+/ jn̮pnb"!J"Ϟ҈Tw{#dX?S\. ws:V&@mJǽ4RnnQV|XϱNTCI-(w:L7uB ?#*4KP3r#ĚMÓG_b2GGE@GzF49&7㝬,FJ @q=/1 ѧ&WC<#bm= }$#hdCd.qkڝQ,L`mMM9Vt&l9u]gb>jmDQ8tzd#N}\CV_k@B#d~ 'gg ؏V%f wvYq?oSr0y㕎9GI[3G3"DN(OaM|>Luac(UH;\ 7/J& Mz#Jl2*\t渱Kz:pRk. {觚w8ы*_6e< :Ka 2,KQ5Luv6,@ªcf~<\jc|#!{]\L.YfѥlxKE!e9H=<85dn"ͣbܼ"NWCrn;*$3x Y e3*F|.u5?p&ʓ\;z~W\+'҅rV'򟴒W'?ivHZMF|=p%gDiWoZ鶵2hV/P'1 c^g[~d'؂OFyǗj5+iRHokH㗧_qr ԃJp%\ /*ɉ j %[R;19bcq/KL B+GK0TW$jw; `;}ݤNs 7WU*dA_ F8gOwrm y>զrA^ %ϝKdvޒ3wT[  Ҧ*(* sFR -DvSKSB$!tݩ`;W*AY{T7cɖ_ÂVCw7^I.„ rr־ZCԦM$)n'q{ٗ,ʋvq{q 8v/WhZ-uY- Au݃:נu{/hL`RIT1Ьe8Jpki[x߰5r_ng#n?f ?g~,]'IJ.8 .Uj6*[}'ѸfO&TJLD N\<d]{fE{->h KX%Χg% \bֹq@ND;L(nNDr4Vwg5A aT׃]PvPH2@ucǖT:s3"|"9TbW.|9/ O8KLrRN=;KH~d&~0s"bN"k!|ԋ*Ԏ˶C>lJ@/2PqCu2b9"vRx@U dT`1@dnOvd8@6֕ĸVeQ _W`0b_ .dC]1P=$cO_{ofЄȇc@ `<,(uLҬ5?QdO;c Q^ͽ̽$29c%ȿ a4ˎU˱?D2i !DVfH 5´1yy%A#Gݪq~?0_5R0eA0X$RF먁qOߎZF72o3l~=JHѷ2W.q9i hH'BCA {#PL?YV9Exc{T;{}NSI6q49C0i5<¬ΕVRѸ]?Ұ0R-{JؘCT<WF)5N!wq^,N!bŢڊ"rFe~?Ifֹ@+"(Y c(7"F\iN#ls!x F q{V3.N(҉oǽ1d1-h<#87׏q >a@zYyxfTƈΫ!N.haST'jeW}WKxbcxi FѶ>ȝc%@ĝxgZUЎ YiB}L=ݭț2zBV`Eo*:bu#qx T9W`R0ׂB|NR6f1,X0?8)œA|-LՒ+VyhA8q)╂TVLW{yW^B|:w롭vnf6EHP)}b.GGHS3$ o꿩T>pz!n:NC,;kiȟ"+gLVn X TRfmڱN[z ru?K>Ne&TMwA1QŎln[j]ҋcl`F#ud='C!#t(0;{`I7ȱbHI8$Qΐn=.KJ{&U2pQ 2CQcs.rڜ>cY|bFi *R3%0HYքژlB ܺ|?7LLJE<%l!*}%ՃIl5 SmJ෌x10i~2 NeDԎe;Ckg7H{\5Bw{D4;Гߔp~O֬,TLݱ9 H4tJS4oQBx)=MȲ=bDf嗜SU q[-~A-5b3`K"C@W5Rh~o2 G{){ўI8y-#ϦSbDYr3|%H\SqF5 ZIC(Ϊɥq24j_Mf0y<5r/v'ə3{HXZ2KM{ fy A0Dk⍥߁m>.SZtjm뇬Kɱ"7 jƬj ikzhs%fZ;t^v8djr?)Vj+ymDŽ,No!gRl\7ƻ*y=ULQU>J'6f3hEȪq*XBs!3RRk zD~]0NWCIwc\s>ƛ'9Qu>P)s֊7lXȡÂڒ>}A~o134/^n53͝M☙Wu괽賉F$F(E h\!-lfa|@4S Bbcs: $fjpc4)] W]+T 4ӟ:zH$d/< OB0~ )%֚l[T}y~#5Tae$ĸUEgxC\<5G\ya%&bvLsL{wR@Q6t*{x'9y3 s`ҧ^p? '\RҒS/¤|'7:\1i' ݅ET0z1W-T'^\FEDO ҾQwf]gGW90:lBVF98+e6&:!i{޾屾)S0l1_$;0]$j髟Y)ѓJF6WN8bF+LR7HS4xi, Uw|aPC^}E*~ Ax֐Nˠb{@G&k.P_J5=ȿ.hzZ+@o%nqV8aa)*РBjRb8th [r]D˼eƂ8/ʦ}CoJRnE4L4uҊ7(?QHM9!ZQ=u>Ӛ(_CZp b-=/5L/U=bZ)ڑ Sٯ[zBM9zUNb%BG2zJhpXkr=J.iյ`^v}⟶|p -)6muS\i.wHhnCre,KtjFuOPZ{ .͇Ä .;VfZ&o2rߌwRHn"Anfr_⮡աf 3" pdI|~ >'{;77#61xX&]6Rɂ0;=&Ei"5iK>QR\D퇉~+9}p|~PJޮ}h]b`yT‡zWDhIviq,]A > dy mo(Ǝ i[8m5&k+YS(7PBE4#6eNUD'֣ɟs-ﮘCkMP4o,У{4Oh^!jD^ORRS'UKOԊ9S14yXS0:{ru9ѼN8Fv'f1 *lEfVqtF(6݌zn!zbGvw '<.2G20AwS?PR"yH)%'?n!6No2ywty8(P $?ʟNƪG@]T㩍7x[wCړǾ85+I]300=k6_Q+6udX_‰dDԣITn0?S37sI>W:|yPA^7f5 @IR ?߳HrQLIX [uBr j!3oX +[01" V;Ej{l$Y]#68p{k+06ެuW,T-0@װ.bE7v*5|%(Ly9]r>I12%Rt$p}3YZ)\:ӰYy),FK9=OF~XJi/_0}f&s&Kw>֙c Y KTU'<>"\I r% l<#!TRLnfwq0d=*p ,cg\tܕ^#uMʙkYaQ.80XDJeAH'$Qw R"|Q]hϚ`fq2/zw 5  ZR(`CDC3/NbT1XpU X?ʓ d+a52\f:C]R*yr'3NG %S1$yg3*)[^{g.BӋ*w J@EH RZ!ᆅIZ;2G0S}$.(FǜȞIl"B^-mpdN&'bDOdDEVZIa;.C%@5ߐKbq"*&y&Xc:Ld|hqI ~;OB,G'$}R<-0S}WIfWxW@f}/{[YlEX/pa`*p*HOCj  h϶KhN'2j´C̠ED͛)Cp wq2K?Oz`y@f!?H-P-n,*SMg.1)г8ԱC4l r߅8Ϟۇ%eG7{.&o~w5X2v),O [d.֍pP)G]: ST7aykCqJmXhao''b]/"mf ĆPRrŗX' qOvpxYzrN 9ΐ&%ha"ݕbvck|yOQY?RxS9>T 6nZlD]y[0aqI;a.0-^||-}g&8]䧬jjR~eEt8R"ѩ"3{FTg3}ry  SW1TO2;Y, +S?1tnV'WT&vzj2v95qKuw }fFA7vp7]B@ӎv'ibN 3mw*5{p:!Iǎa=.ɂ3 V"sz[g n@&5*K҃[s]La+ ;7v(jm<|ϑK#3l3+ubO-8t(!~ j'62\_T&ZUi}:0Z{0]Zeͳʵ+ &) x:==Q%~Y0Q,zd*dnM8WsLd;p3i:I1#![|Ƶ 3gyT$XFD.`R}U*=V-Kj`.0m}6*$@ѣ$p` lS] &X)_0i&073f哬$Ma֘[Z%'^EES&|߽)/6CPm=T ρ!di!i3  C^zcHkwCb250?0,X4uO{ !Vnyf~nW噏ı AE]pa0#pcFnŒt?7d9Vl]l`F^ xAKZ,.X4%;?>v:(>' [> aOƘrRxYAGpcȼ4\>Su@Ug+](t5}hpQ# ,Ñ3J`- SE|Rz mtQj0f-}AENJ Uks]4twBɏֳL#i dS_ [Tgzsj4R\atMz/Q5,}@ 57=߷R珔Ƥ-^A38Ў~\xK hlj_ڤ@6 i" w^oB.(722Gb&NōKq/rU4.8)t|S0fd/ [_k:;Dk)PxWPò0$#6. #4٧58?+$j35+ āGrǁȦehJ 0So5Z¹_z[Q]~>jm r}ŒݭkT7;3n (陠"'c;(or F2VwNcm֥u2n0{gJ~Cy wAN@ !-oB8G&LSm7ԑզ]Fmo@޴ȶq&9*WSX}|FX(F^oٟ= ZiKcYmY #FE(|&MtsMYA8k8aόĢgcDήmsM]\cE5V.h rf΍GzmuXeհ/8U<' >>V0o[:XYSq'%,@59C954YgYR jS* \L`wܨG&*:;ʰ|~p8Af"j@фb`({Og?%.]6K^ܭfXBH{oBWc (Ph9|fȶOJ#9;kz (n s ׶1hv@& c-.`;N b>WuoWGeb@)u2H}^Rs-!]\fL>eN g: u RJXn:j2ӚIx]=(ĎLyb0)ȣq͆EGT)fOf9@Zt·q ?[J/8NO.Kcuίr*y'aT(Wtzjp@CC.)]~Ƃ#2-ǯH=@9fn槵HOGJ]i \ߧ2g!* *vӸ}z{~!8NMCC?3pB}|lK5|P{xEWw2T&`90~;UGn(AX̹B{)kqWIUeO5HZ 1j<`.-"tj- U+|ky)ě\rߦB.tDw+G YDZ.˲le^ w+&Ah//v%>>@>k3_qtJ`yl g=:*W)weiއB|";e.\H0&x|SrF#9+l %]FU9 (RxO Jg<nҰ]b\}7HI',q{"k='I 9's?^YUsgi}{ M3rpthȝFd|2 c6jF|n?%!@Lfsvz\SdRJ9kŮ4_ 3Ly.Q@ݗƅr>#_bx} rJϓ',Id1\[gO!dI\s?mUӬPK w8yN ER & WsV5oU^8c_bΜv/ lS؎+gRRtXdpWO})d﫵=FU=34OV1X‰B} D I{)So+"8cZFzKwiZNJ*7c!Q+_^ܽC?<栣|E- r-k&|Wa?&X akj (^ûK_*.Ҹ>GRU@Pb_^[g* ]9p8dCHN8^<5Ʌph݃ fuHXP e%F ؃=<13q*iZ)wb)vSj/7NMYۚI]o?@ըs!'A0S3Ev"=˃=qkŵco ,"*^joH4se̳ !^WtrCm\v `]nEKh\tQYٖm)u*;l?2wQpOP{`\J2+CC/u.wG*qj|O&LLU ?R" ԍ:>:/+zoӢVXVcK(^sABLOf1e*(AGi;B_rrd児6/z91q=Dv~Eطj~D7oYӑSD&B>#7fxM[5sPwkNMt313\}z>+ OH0ٝ1sI%&,!"";G\*NWv,J*(QT;_}Ry tcs|d9&AL\iyç@vĄ-7}G6J^9Uo1zO#u?*nyB3˄mI'6tXNڴvXV#Cb7]pc}08.C-@fO:﷒3'|j@w?#΍7E ,TK/aLS~^G9* Bq#?3ww.ezhg3ik*;Y3DžijT).`dPaXvr\xٖ_Լ|weiC U">*'HEtЦmwTΗihmYr'mZCquY#&khplYt"Nl>zH<^2A:KLvq}6=\+LILJ{LY3&'B\dDo+\V;C'}{!$J_n ,FX(tÞor>oċ{O˶ۉeFB+>2/s&IsGlӞ`0ca"\,DL,&ܵl7!UHR@*Uc _NS:\f70Iu{89US *_QP*uDUP:YO–G PkVxje%; ӎ}f\_jCƥGRYkBi/bVBs$W 8n d f+OA 4MXX\@B+z?h4۷8<!Y}W,䥉Rxۧ i3_h>$a"G84 :kYCIU͚b)Pdݑ-aX~l F-!,B52bEHWEGl7J# 3GQ#{ k#?&B t;hFŴi]G'~բh!߬8+3~lX+W]T:G$C !C ?gr7a!T p)N^BB?!Rq%$> Zo(Qn#I};BqН])q MH\F"ܸc1c(rY꽔:p5fJW3ͳ"QҤo fOtRS1 Hހ횆oU݅4Ӏ RA?WM,,V8G SC!Æ!iLZ5O.*52GH|gbzS JΡ`/U?9[E_&jhe8F3wVGűHg m>vy`Mt80%Nc6oz-4ZB]S?ʐ Hwn MN^tI4h)?penVmX %1s1_y=r`,dnm˯H4" ?hPoyL/!e$&cEpDAtn:YRuH€S} jV:se#̐hY(]6SNfqZCmy dz%Do _ܛ *9$Vai@]64-i!v ]W!3DUllkD5\] Tz*\k+}y )>ʼ\R6KpK*V?wSA9&-0Cw*N3:FB0$)ԯH)]+[b?g9)9V(PK^^|\KO똽4W2s;!ubn-[(aOtܓ<.C 9GvMx+)=JM:AĘѡ`,5d߯%w-Z׺jgKR$ KLϭ7h 1<F$4lUPg}$_XH\?X)0δ(Zb97@/?I}oho-"p/^0&=Qx/3;[iEGIs|E_><%C !έ@o8h%oM{Q>lǶ/E)r̒`QWQOaq, ; TrZ~Q,}rҾ=L>9Y}wk~/|Rh1 /a=HyR^K7CU G+ΰYQ!s}DjM`W+b]UXN  cQ)YSX0yז]]v%c bӴخ<۫Bd#[*W!_>~!Y-qsI\:lF8bot9_} aw@3ϴn99g*^t@Q!]i iE03tT5u#31Һ \51ZCunTmȑ}Bo6RhI5y`o$op=(?~%˥$"'g)[e/J!9g-ܠ*Ip~`'4I̔A1ߩ2N,^PQZpSqd遻kC8lKN"3АBW/)"O=)X$ɚwvYP1B4I$ y zk9@T},quk*Ŷ}by fePĜ\ؼm}`ٍi[ ?ĕD{˔_܎#_~bTQ>d$,r HH߂;y\ٔWqXCXt9)Jg:@\3$dOv@zo<)p"k*uwb9wj_ë·][+淋ۮJ<" g`kT915:fUzRQKoIOHQR–d< e)EөMUVLChshϘ tVEW0Z?ר/a 3Tv2,0O;Cd8.w>/§Xd}12V˭ro]c2l!u&!)ÛQճܥk> HCNH/naKq8*G8X#W>u^ Im?N=tQmNK;遻-$yOsGDd9("qi*(gF`^ sΥ3AVBj~UM+kc`^"ϼ.-:59IʥzaL"D,F8K:#QV :Vgiw|ɛےPS Yz1p^c7ۓsK;lo_u!jPn0 )Cϙ<@ey(hΑd٦y%?Ui߄w}=S9!gٖ@LCJsGr=7`ipDtTMq(-~y4Vhݟ[!] x g^3ns:֚~)XaovI-XݯQ‹ҼZn4)Hofb<=*>{q`LT6^n!MI:ȥE t/R[zxVf$'x{}jii X/oۛV Sa˪s<1z aA 4{53LA4T0!Q+3[{B=wa]ywP]L!B)1A>`SfzV 7I9(Ƹ`<^k/3-^b^c]Ns#|Fܘ^ixVFs؉Ts§n<-$X#na%~zIaj)#w1LXjVC<*nXGe+F[z ۪+v=QΕWg/y|(]U,8uGn|`g$]/V77Rmq1Z"ӔiCe}QŚjboj\# .O't}TJQ^KnlSL=ȥ@^(Uԍ]!̣G 2*3^BQ:&Mؾ}kXy6g"CkDɶa9IWNVS"U"BY܎>Dp"Nk lڽP%r|_FaBP6OʧYrvNhga5J"^7a4 }"n+#0yU+]-X>Υ<~!Ua~3 ㉺p10ln0'd>bN@fjzR=4 65lSB| DTALx dG*u*8W=8X*ܴ΄]뺪 &"#dD֍n4/Nk}|\ci2Oh#]]x(uqIR:_K7IM䀾%>do?&[aiO i.Bݻb61;O),ܿN@')KCyeb#ـIaL { 5).'^ X\}))[5$5\ϗYYIؔU8'1 ~b8ZAAUO^1 \E3;୉ɱV#Q8=BnLP'`IH.JJ k2U* ',F@IM^Nler ,iD/cl)~n=W(zv4VśHiY,qlﻚ9ǜk ^FI3w0PM3E*97C;MB+iq'qbccH&$WѦ/\o(`M'ij:]-dPN0Ry;LQAR"p|My<[1~bj%3aSE6zTIz\0hg?9TDG}`+{Imљ#3# +W΀ O?ʵJLPNcN(@U˝״mHHsf/-57_qSrB@EvY~:RyE+Ipy&c>;ג t"p9 ;$:\UMq魆mqe0ZiUdrymFXF@DLN LW׃mz?qLz`,?YFzLctܶ -ۡg77 !C= 31&xRa, QTXP>KȜY@k.=008#OҽpN}B~ELߎQ$R3Yvoʘ!/xH#uI-N6E=iuIC)>S-$v8Uj"QMl`nV#L5\ܴ#!Zn@!'ynmnpHl"Nn-S P`ζk\eMc8ހb r( g9EjF4 y~&nB_Bd{sj`fl1j?X|By^-vF8 `gf'xMq߰n fо`?) <.J,tM ΔE{\Sq[^ Z'm;ܫ+)yEņ˧>L,76cGҷFS!#bp8AM ;S5"QchXf#ENkxT{~a zSKò~g_i>dGHurk`s jV/b[G<6aX6L !cx("pvPYc7wemJ1_tQ/VMֶN֛$ӂpi݂j|A,קOfR9~7lw@"ҚW)0%J.7T׳%P֫T ],]7ua{Hk/ތ$!E~g5VgQt]ߑ`Zh'MZg@rUQŸmFe|G ,XGv3`MK;$k09hi~d@q.Ӄ}H囃E M"r4J~*7.oSdaJ65D`̡*@p_ ߉D݀K[Ą/$TkyQŪq߻>= em dIelU =E z DVK'5ecg"7_Y jܿdM;L&ڝ1AҊeh2v`I(>@,nFR*dW~-XƂ ^E3vtb>tP*/PשL2z(P:I3Jm|?T\1$ . X|"O8 rvKLq#1Cʫ^_ ']Ks{5R!2|ߤJpHʱ(Jh☊}nb|%a7{g", nzb5v,(1RRp ~&6pmKYzoѦJUA8Vk:f39a[YVäy 2hMط䈨8MFqd>@㨋8Ҩew޹ƕ8ztq-rM9٣j5HLy؊~-xHIbn5L9vL8abZ>ĤrT( Bw}PC y`^B89C aOaA"&6nE>_,2lΒH,vh}hUmm('يUNHy[iIjXi:b WL< IzIϾEлWfNG M`eB%*1֟:q4%8>u|G*@B%IW*V36 ?]>jQ'Yq,1rgg«{n4o[l>JKg+A d[.)1&3$YCcg:nHxܝu#'} a{g':wb[ Rc>?2tX9w7VF\5g6+?P4<~4J)r]uxaқWFy^|݆b"S:pn[ah p +j}]GPz?տd8ņ֒ Ԛ-f<`ۍq0Ӹc丵Ng0ai1пN97 D(Jw|sG=%oOi{nZeE,킟n \NAAO8> ʶ7Jzs69/Җ ^tK?: Nأ 7r5LX-`\OqLGߔ%WYXiNNڿ:$x8-Z9*&Եzk,밴_R[ 4٤7]eNc)ZNk1m~+ܫa<[2foE EFnr"/kNޓq0d 3-ĈŕڿEoRhQ@DwR8AfzN~xu/u,.\{vġrKbwZ R-0FTtdܙZHR=#kq9P,ifuIlLp~u*x] -*%ءtm'+,,.|4*Qqi~Rā] Z_ֶE sN>.lr?D|h gHGZV/1?cO\~6)f)";ĕbȗN&RU9pIZw;Y/CE0PNsU A?R$٣6XQ3`Cj"aȫR)_0 y`!U,9_,˅fjLm2Xۃ֚ ,n^70(mrIh-'{-WE?ۗDDD8:ì0.ͩ{JԜoE (:QT֥ܧ06*ggv &ڢ>y+w'$^4Od_x_ZJ> 4X LN_0]FLAMfa\ CC=}"ލ`gaq xS 7D7SִN>tF6B)X˧ |=/Љ]j, lLR;xRDzQ dῸ:˕*Xpbd}ZFeRiﶫgh \t-e!ΐ9; ͱ<Ô[[v n4;Di.\[ߟm![F&$dDlMXg@%Hё=?3?HBn!#lǰo/wG{ ZNXdznþNh:Zb N7;_+L+Q6@wIH+jMDm^_/)-|kKpxZѵMمyfb$3#ՒJW|pb_{+>.|LJ!+fΣЀ (`aC=0W2P,g^i#6n8А;]s>VO3lXTcHz.u.1Q^ބD rw$X!:VQȁi6빎Tae&Y>7trfS40г}Y,ۚ{KVNʛ]N QZZS"N47  m'G SҁE3 hLj;sKKO5AڌJ֥9kz#VSn`D#٘qiI$"G]pbsPD'|U#R*xOȶ%F dSv iN-Yʹ9zw(bϫ  x)͗'  ?,kM0ᨛ6CJ8NcC4̽׬>$d15[_pAj P(ede*d"dZ>LnqMڭ?E4B27=xY)tiT kX ue*Xmtnꡒh<=%@C4vܼSr2ŽǢ5I'R2{84}83;x*/ߣY" ɔB8v&Z.T 8MCT+e|HoI[ bNNqUV\j8(Γ">k U#Q3G(r;*Q&.jM22On@+ϒIe)TC-bZR㪡 )SCҨ/eif.uPqj,"*/jJ;n*(TjT$|"y& ;\qTtcsIt_lFgE ͝xbŔ R<cJ<x$n׊۽`_m)(P5<ΣO>(Y~~(Fiu4^2f;9 :2H_p 7Pxx*JٍTW2l4?%c\Hi݋Nؖ:i@zE5a@\ZƵ0pqKuCq(qKDNǭnt A6<+|Iheꘝ 5`W?Ӕ: ]Ԑ {*!~#$ҵT\%c c]gɲd3uo*@k^,i\-̊4n`)JO:!zAw۵=N%\i)5?i(BK'#4{$ǖEYp@|nڧ(RA:QCV$sw)r!hgWͧH{*nS kC3Oĸ>ƯH1i =O77h[ nqkLgR bTKkW{E|e݄J.?4_fOi͗Ҁ3q^{GuӦ&11ّ BF+tAïqxl,Fǖd{]yrF Dɻb~x&Ģx ;xcG]6R.G]:=@PR_ 3&L%]<ܦ^ HK "X",qKwA Byz7{xR J"o҉+zvV8X9-Ƀ2貺WU4o|#t4לQ)O&`φ۰ ^qky8改ֺMZa ɚM;л%S8lo`r[uBDs2 ]v }a)ͣ2:P7v)[]  qIaM0q@J%РB%vR&k `x`20Ƒ<ĉ&(pSQac#RC Z}VGsh|}I;!t$O\NAq[]?#hǘ08rH "KNMݞM. =_oke圓KBϭ|khO`nɢ8r%2环AWJ(Hs6[k$ ~r  =+('.PBrݼɫ4YfcuIR]@)%xn?],^pe(Lύk m(O$FΖ6MBCy|- SަT&۞!41R< Z'r}u=wՍr#CP 9-Le~#+wզ0l5a@2Zh ȍ%A]qp:D8)w-0T:xw#,@}*,xXO,)båѿDXՋNi'1"Qy!,3A'g!Rwƃ^PD;%\$ٌ;W*4v |Y"&Tl+5409g5n+T>b_]!}s/ZR2b|r/"~ FOԫD&\r#^RHԋC.+;G7f6x~p2fɘH5p vG9+D܃]݈ni:֢*^e*/~#G>Ҙ86 l R zىB' U/|݁m$FCh% D'Qx[a^ɵa&;myuNwMK;xn=MTR^ `a˃fSMvBeO0r lx#j>t4 Y\*)뱩X Q3q>L;M.,{_vd>hp"1I'd޺IY~!Dg-Y u>ᮬ B,p](d 7PbV%.VD$UUj¡u_ )lWYb} 3,CP]rC}G0v0 .y-թ mdp[v=0{DjW_ agzhKm6A [Mn6sƊ~UŨGA)3}'@ҧ;'<VP?c5%TDH+H䳍VF_ZH0T_mn#B@ytwѼhyFbFԞRAfoQ=M״Гz}>~ʋOi<ڟC{_/}XkG= z9B\צO226n[G!7p)_ FdC͟ՆA.jL@G#x,9^HBѫ5 ܝ&ZS$qrDQӼ}Ӧd4 xW5p(xy)h] OD4RP9q3]/lv8P ȇmJݺ(VSrdT )rT)pbDVy^)gHW#e/Hc ʁ֣u/++Qf^\or<(Ei~M [ 0frO7VJ3EMCvs yvO6岍a2ۄЧ~'>G1J,#3|stQT;MɾK ITVCh &8*pZrñf]x$ߍu V]ha8)N^'i0HkD\z"¶]@ͽ`5K`@-@F]/yg]6.8=^s[N r8# !wz9}PE'tq)oFӾ9DЗzXnd1>YɘМ`43Ay|ye{u-6a9(`lgO#8i]ιµ_k(e뫄-e4kh\k N@j3 ,f!e0m/wxuoY@ -ېjA{í"/y`;19EN`qPxflSR-~Xm.tP#u5aXb=ha*J -j qNm #5ub >kLs.-k$%}FluDnP$`ٟN BsxoH(%ڲf=ڻ(2MtXh?f'*$Laƣ9NI_ЫB ׷dXJ.'0l"?3ʶ>. zQe<#?9ngǸ D02u+gJX3J9ﭢ[9Fٿ֌X9y]X1xz.|QBd3q1u;T2k3|éqf?:PU|ycQJfӼf})h^nN`kPڜ:-4zw8LXW ╣_:ly=VF7TQ2KyD ^n˖(E e]v t'LieP) HRUb8'TPPu_F0 b+Z8_%>r!vNU{D ;""*Q>@-qT_xy.dZϡM~~ը*)qL@z[ zhq}~Kk3U|2<:Z V 勝4gO$ ?t*Kg &o-XĂzEyn N˫# Vb$5Yg58.Gp:DI6*L:?Am$$#^Ӹt9s9vjZ ԴFNW2to>ݱ5 ee Z;T`}3kӾ;cJEEvk9;ZǤ*_7(j(@D /d3̾?%nvG:5`Ô[<̔7ӪZ2n P|udBMYA<(^ OT\s/ yOZ90APꍤb,X/Hc?5\66&f)-C\ՙW1( f*5SYJ[a4 d rz${~!@w2ό%/1L۲Iae]4}޾ìzdJ X7k\r/(x~Ѧ$/Gy_m:wM މxGX a]urs/bHmpԀW2((iTUL{nKNRiaIlZg^.RUZrYds 鮃&ǥ?oYh5lS4?$z8_=a#TOɆTgJ"yjzd Ɵ=N= Hbn>B@NbFz~?߱͟D0;)< Z Цm3-{Èȣ 0$ڙu]=W7QtR!DOp:aʟkY\MOul-x-9U4El_CmOȮ^`cXVKp8Su)mG.hb!KH'2X Rird(ˌQA||6:BPo m=m^uu(2Tul\8:f++Qmӥ>?\COinkTfI$J~Hw$_O-3yCt Ր[m<=/njYi2c(X8A([ظʳ,+k$2*6Er"$׺a<8d #ްtx6ii+α5,?֛7Ҟ^4cD\ ℨ<*N=2_W`z {L{870+flog1,гtŐX$ֿ@_hmFJ)Z%Ogtj?<_9<$~GB,=\ 0EKyݥPvB9;xNfdZ<\u߂y *:q~#M}lSYvt2dk&ڂaF?s:ušBzžE 9M+[(C}VD\N%l7}B4 5g_[P~(5*1lt[ 7 <*"E^:-y̵`_EdB9r4#?yw&߉SƙJN'8t |'5 8yƲx7d;[%>2hL~v%U2hln;6jPqgFGIYE.Ajg{N,!@ף6XUi(' ֶ#PGP,L\'z$S03=k jwI|5!=kNײ4ʊEg9tb@Ͼ?-t7LDimuK({s'H2;^`},CQiwocI"ħmxv Eu;D9W1vJɻŸj"$M%BL0htu-ޒ3vٱYg*ed8u@lC2G~1<>d@kn:f T/ %Q?j52ZW)7yD8|6ʶÇPC!~faC-.ݳSps&fknC}@n"1 ^ vnocR՚Na\CYDy>tl>U.&e?$^bӼ\ГUj!B/BenVA$~HJ@jXux&]I6ɋ70e3~2fb/%I̿};ޯFJW9 2XIJo ;&ӕCz!L. :B'zav7&~b|8ӘBRwFpe6k4B:8?Npdb"QWQWfd*자W#twx%р):@S/'_;e"x[1 >z|=ӽu!%U K(yYEо(ĕA?I)T@km ac5̡,%fU~s8 E*\!wMs/`CQNN/ّ,'l rS(%;W %$&J)IIUI[pp;%QU%#07pi@n_^C9na`!Cgj̢@%KUvݎE{NG `igUɀK%dY)o<\4u=`ur涉:]{FGs];+>д'; "rcTNu-WC2o6y"; R{R8mszΆi Q%n iHOϕ1(f1H娮gc\k3uЎwn,!KEO6ֈXi  #K>i$ L5zD`aq8LZG:@ypy#Fje_ [ʰ2ԂJ c}6]^Hw'og >n—>m6.JCjc! uɟΕ /ڝ/:^x1E+kT~FԏĊO.R .6nmĕ=ej\f~RX9.앨9}U3°/ggɕq:`z 7   i0@;_"09j >,M/TE<jhq;S`w֧ ]<=JMmX== ;VH` w kB N@Z J:V;!S۶ϨTpt]4.[9\0kMx 5kaħ 0 Y NZPԜRw*nf m҈Ef  #r8vRk W`8G!KaveN^<,5dV+ o 22󓄆\Cq_Q}`;Dد%@׻=~]N g\IktB)KefZ)8\Aw\E% 7qCYZpGIPh1eWAdHRySa \*wڬkuX 9x\-#dVՉWLYg4Hۖ!#hw,h=wkU(ki|n~LFׄv I;?mSӳу|.7RKY^4k^M[r3k[FnhϮ]^ 'bd!|C1U_x/~쫞K"{ɂSoG;Y}]'ًSJ(b׹r(mxۺ`Q2?ƩT}ñ5~Α萂,S>!V1F;hI B?r ($(|:Цo7Bi,FVsy@Х5z;WAh҈BS zyۡ" " PHYŻOս= 4Š)x-}4q/׮ڝWoS B߱ *B"k-?M94vkᔰHk-Ul='PFNhzK: kྶ{[x3_>GvL/Ǻ((=`,2iDPlb}h@ֆp.Ep/$lZ?U$}vD/O".s^U4E%kyk=S/x%\i@D By~L+Qڇ@Zas QE'hk[օd^ATBeGKp 4Z5}1"yXW&Q3޷9L(a[cCn)d GMQ !FNeGa!LpŷOw x{>kВy4.ٙ92nW"ϓ\ 7+rS/gSB  ^A=k!< 7l@Fc phArka4M7 nU;xzxhR:!Q)jOJ 5aа9ݳmī78ܭffN9:4f-jVDLw67ttCNG౽n!D+Ċl3EI24"Gͺp]Gl5/бϤٽPI1ne|() iZ)-N;\r{H]R&'T&Q_oHiCГT w% +NVG36 a~')$?In^Qv}Θ5.4kGfp5^NmOӜ铏綱)A.Alck0k*q9`C%و5zteV?)U)S Vk7X#:ʚB[杘s5E vYkleaSH ww-Z~(mQq(2mqmAPPk I X_5I2^2lUocokLFEKgjBvb;r9 F 8(n&2WY?DVH/ZJT?†eIbz/NP=-ZW38!k}\-4B5zl cJEb~GIY~)mG]"C pz"~˫&Чh$tȿ du0oobVNDNW55Wzj:U_͜\ũtFe}bVeÚ9*F@PMT󛪽$J*UDt*1z6,>R;|s}tz#F9586SGF[O[ώ +tbX#0aoeM x# O\'ƌjى1(A(lCIԯ03xq|jDAo!6GT'G?m fĝޫ~3GT/q,78>ozq `nR6OQdg$T؍PV'?Gc:xbհTFktYƜVGX?bwTZS"ʆjklcvBV=THKh6ꏋe}щJt7JnK>U]XϐNu$΄aٻk¨lBIF܂2?vZQ -X޾. m!T:Al @5shrʪ}*K>5O2y5I h.J^$1ʼ ?@X'C;iӉT]GEB^ 69H<9N ONodjix:Ξy RA_M((t5nKJ(1e[F& ddmCYYiKBNH}sf$AAGLb59U~S e K ih$1?"O GBgh:rȸ+?cʐ^_ m&cɂ=chBvp_){B}j_o!׼uG!>1#j}*k5'e Є㭐n g2iv*~H biu\sd!{ )G_DCiK>&_\C=Z, B}Tj'p+ޜuaА:L_Wa2B(awn)0VK!;k# S\!Z{bXw[q.;n)"ԤfYɩA^v9.]3!T/qG<{}b:z?Ye (ϸ9I^mj5m_([_Q S ̃AzZXze=5XwCuBf$ؓ EmAtmߝkN|f'ʫPU6l1\BK 3Jglf3:{&8mVi}gt$Dߚ`_( LYzojS!q~ )|'Hy C)5l+2> -LvQՂ~Vj:uz:t =c~ $GȅP:,b AaI2RuORqF Qdp)^nkhw`a[֡ $}XO2% ^ŗճcOUV9}3/Ip,\%BB];1}u%y*׸<>qFeouHV,sO|Mq׷>۱ӰQXoYMz6}4m=>8A73FCc ˽ DD0$4$J[+#?(%_ $7uĶAL|\uֈ=x͛i2|=tmB6 IEx>2opxA@$};b15A>^u)"/0;'0D1MwJ)NpKۚ]q p*& FȗxXs`Z5J$]:TF+l7K:u64KUڕ4Ry@wLRƱPMz,Lף롰P8W5}  5\. PR; 3xM=̱yD(~bz3qúX=56wSpf9+`&~1@XI_fO1kATL9AX4\Qb4"&uևHu4`L3^;Fͯ@v>\H:3e(WWJ͠/&L5-| ,RKj~\T"lW8|] WG KMZH^(*v&nNFmbOdmN}3OǺNwm{W숽p97Tgj;ƀTBT;m3ZH wRҷ9y媴1|2=h*{E|+v-OB.xyi}y΄1tLx赟:VufV_ ~_Ad ]5/mUɎ&ٱߋvK4+\"l'AB`RPk'+>;`谦U<9 J͔jom0D;@i:umU*qɿ}7xnU\@~K!ݥoV&R*mJ!8ho:Sn pu=`<X7Pc:d+w;uP '"WQMU$)l8Mh](6?6R Ⱦz"^ ٩S/m-{#=i꺏iI~fXzLE #sבЍud|?+ɞjQz3;DBj,Hs Cw#9zIuɮ`|rހ(مemGoOWm:qg)dgQ,b4߰QQ;<8#Zܱd!Lα?U7Lo騃{ba' R_e@4Ub/KQGt*p?_:9h7#FÈ?0/9*U10۷jasE,yj;^S\ysNu-^, pRf]+҃qRa`YCԋŮ )^ľvx_Z$rOn+C6oXx"g52kaJZ]X3°9[{fyv[/!*ւ5[Tl/o ٜqKC:m?VHw1{_MN${~ >e-3ӹyVt հe]Gyܷ$-G6*2Rr$ }v#S 8įkf.)|W5QH/&VMFwF.lO{i*f'=Gk" <[7Vw*iy fzUTqVqgY%C n Y6i1sO_%c&R$ DFIc-v^ Ѷum5 p bi͜6LOq @U**0b)قM!/@/CTUٶ̶xC$ .$jm$ 7ui"àV^9]d%}Rf2БnDW\| g!+4 ɮ" b5\t_!$yۭ+CqwmoFa Qvnv\ "PdօebP:.'#UʹP}9 g`)'Zs3X 6A(!wF 3+Jv95{H `-P NmY](vcRE$ׯbc/yiب8!'U|}HWQyAXsĆdOZ0 4Z:"Ѭv/`%ͳC9+ܵ̂oKiZ*Do9X\|fX}UϜJ4dD`@w9ZPÎgb.. h 5! APXS)D<ҲE%AUd gn4IwJy| η7<3.V蟛QB[inOt_d$sG)$g-*9){6,zu =7䔍T"U.]1P]q}VmPk %'b:.FEj~dI'"=L y' ĚDJċkJ&~bV€}e@eGUKN>W@Kn˛DM|K7+zJi=ȕ$4 xjQY^<oSgu+3т YJm~1dh,QqjrAC|Tmb#]C8]$8.-k @y+ϒJ23;q%B"8,LMo_iL% M5? TunMu<@"̼!-ƫ tB#L 7z50LXC-Ԛ&½ _'tn/ŒJA~aW>+l䢭N;1Ԁ4HʟĢ7-Q?$qGg93A g^\0yY@bؘA#1f |Zv}]> j0~b#A3מ:g4l/mx7+oߠ2|T~W<""*OA:0;պeM.>4sP 77_LZy2:]퐓ǘÎ cf, tƮ +uƽ!GlC=lñYtZפ+ "%6g_UQ80FbgDF*h3gJwl%og߼CtyzS_\n,nRXaf{)za#E)tyuluԖxJ0H7"-J\&;*,b`σ$8,,”"ږY&{Vkj5 ̀Y{3 `EDS`Ot\Ӊ2m C+RQj9a4V#.WU黐#Uҵy4+FL݁!"&> ݲJL-N9f@хh`inQ0.! ͸Hڽ6Z92e7=:CTŎl qjVxk7 6MW$!]7۫ɠ07ocG\o>g6 ~fd~qh C.w+0l3EtrU?6x:P݁_q~pe3IsURvN 88E[4~ t q-Cfu:i v}=&v[Ozx[7LN,$!0tӨ5k$N*iB'!(u~9W][6Q؏;T3,3|B3{ =G-z)ڀ~6Ցeыm'cNJ{b7Py7DZ]/NN!JQ6${>$fQŽSQңb G@Ę :-Qȿ'ʑUUG*iTI7b+Yh@6I&4'$QT^ԛh< ^qEj#9/îir,ÄKINu~TA CN )}Hi>uI??;\BҊ^<\U?z`9]G*ORX:wd2S+wM:[#Ue[YxPk#\ϒb;aŝś1*GS"?j#Swt ȹax \$@B7xyΟR? FFL5Wpj<0) i}=JX+ ]Nէ۸ zFKHs1#V92&X%K*K4!(v拰y&)ؽb1#<8dޡNȗ6`Jq](hdTD2~jIx=u`m\oSSM4Ovy f4SJUa,,dzijƑNirHPm GWj[rFH}C!ϕxT+ KO-=;blǘNɘɫgQ::$T)qRq(۾O~J(6gT)A"ɭpdVdr; ~܈6M\qPw0DrS-u:~m(?5TJ|`MxB>,7FQT\gGp<$WPs|vI3I):h0>X?ʹ'PÓ隈q~CŘú9[ 7̦6IB@ J[i'= uOu *;L4$ 3`Ɖav4iң'9,Ӑ_NO,ЧA%Ees*B V8Iv8z7L*VBQ׹xvV-W ཌBHۡwx?㹐{н&>o"m}R/o'BOݴJy@LL5n%VSGX|\X i 4Ii8NTۙw$ BRvR-!#A!7O,.>zzWp?miƢyDiY-6ȣ:49y7qgU4ĥl]'wl,!1VHd>6r.掕,rӜ`]6ɂh:;3/,8qj =hA9'ލ-pCq&! `Xˑ@aww9&b%1(9$|B $?H{v]DžsQ^c  gͽobئBV?!CCYJT H ?O{|QtV@wgK'RL TcOOF@W^Dʔheb&7-`/,f5:p^#cЪ4i*vUk.w2|Uzv$ v t>@xb#E /};`v*Jx W |ϰ2ͼBRggvkgK2wVgV>ރT:qЅ+..gLBFƶLj Fdg~+nÈYw#K2 P'Duii~ei[,O(j|.>m$ t^ 4]io'O\ag0|Oa꩑/?-m\ʚ xηצSYcWH!Zl]: oFqT/$n?/]u {:w"ҝ-X[M왹bfr97>E=f!8#"_RRz9 ?aA}>iptXk1f.`K<6tɖʴg<_OT &(&[PSwFUMN0Dٜ}/xGO@>J\*u/f#ƖfOK|` rU2 R &E>}(êm_I>__AIsS껓o s;jOHdLsjdmN1X {Q0ہ8_o8=&rw8QFw^+&)v޾}Gt BXеrMu'c59?ǺppM%*0sWk3aaL* !Ib`[G\)\J?*U*foI>Eݿ]owїGn+*$8VQchǺ~vt\4<||j{Fi鸺=S̅KF>&W2|9J " y a aCc'Y [# dͶ[ӾMB%֓@ov M -.0 .Wƻ{P =efkABa?0{6=F4 a4/Mt< <ÄI7:) 5M XS{HSw{i&s=uVӦ$*JY p-T zQ%֙4 2OZu| / pR^ReFeI/~r'5!Bνl%4SGu/3nZ5y&I%Gt*{y/.C" ݕ__w&5$R_9:)C.`-!GaOe46J2>^Vj0k@7~@q$~91ѩKn42ڢ嶣jj&.(Im(MΖ ,|Uсcwd=]bIgHaz 3l;)v,^&Y(JjN s^#^Qyk\τrG %bXYZw<8bx) l'VR 3}=y1R0t&j#ϻUR끼= \K ~$m ɕ+)vb.p+@ݷ9.6nM\%~j0 r([L#O~⹈|3B̔aB* ^/*݅n#M L_=`1!Jsa"nrGø4HtZn!={t(COb\LX,K~BoUuP"mAђL@&j*!gU@OFQ])>浀l43YjBl @dPEq @sk}<8}2xtnYfvy~@0SMBjG$14B :ѻ+n}H[@3{,qZ/^z+z}N!㊪f81"bۢŤz9СuL<ї|P\c)s|ڞ[AG(gcXװIl]\Pi]m, 7soL/)Jly0} {1.Y 6'SUGL(KO/S DH( /eyj%BcB~B7!gno[s?5 UnJ\>Sc1 we ?l`D2)ݢz>(SLqȈ^}K+wE~ڒMc-~̖3qd";`E2~F&%^RCZ? 1x\`ji/SF"&㮩ࢗ!٩b7)hsFIUS8JmQHI> :2`' S-Yt,Jc'BٿO6s}2*$ɽs:`e5W%X/>$R7qI=^l':*|~,>{"o\=bu$V z ԑ%oVCVgW$1O`P #^Gle; "H=@%7{hxN:QN)J QMw>w{qCޯQm){Cmi#zf dLvӛGVibD <=(u-BIMoUQ6 ZpOTVQ1"0h d*I\,dΌ}|Nȥifg8ؤFB%tx!䯲L}ҟ'ub5!n5њv%y~)us>/SCklNt5^q^-E|̜}~rmS/O"\("|.P1;H!Oц,tSA`{9v/X*Q_$E=WyT@ҡvGbOT匍з- ⑥83+38 (yʗuv+`4M&٥XOrV(J2R= Cw|J*#NIq/k)ow3ƙz3QjFD0lޣ0{D=Yb/`[`0z@@n \B |:!78qNo(kh`?&h{4 KXryYyL,iΐ8[?Wq@_\*t^3~m+6E K"Nʫb3]$m2kn>2gv6^Q֦a G*#Z =YHdJc5i(  ӅwWXpf<Lʓdp=Bc uh7[DpK`js)2m܅^Ōʋ5qLeż"5*SAĤVv{ #2*wFM 9qdB"7L&@O PCӓUE3uC?vvIGaV~7I!vL{#- w/Jċ9ՙXK'5uP,7&s33&w,G8YͲ֪lÌE{wټ2z2JH4xC`B2'4' g/ g9ƓRKn S!wyP >?h x鴹ИT7 mCqNSBPi4xʺ7n68p mtV&΋JRh"z9%<z>[fHR_Y_I Y&b{v7:FR+(8ۖڜFna/#K=3#jʾM[>EbnGzjHhfhNF?~.5Η̇ }=>T߁H;)  ST)IF״ig5w^-"7RǛu(u9}5b_$hBƽkUW 1Z]1vn3~m>}bz Í2\R2E3dOl=zg~Vqh0Ğ!= oP]L2?]yRiiZ)ZkcW;7,S4R K5,Mr"ICK))?LV Hc|+Tg R!2H/NEq]1~H%yF\tY'U$kdަ_#>Z? % f$ g 湐?$Qi`\Wyh7q>V ZHnQl̀?AM0o[_?]/!3T8BŞEĚWIF1-$hqXyޒaa䁙:ywrt| sKq UR0\YA<}_ퟒK_̀PAR"3; mv2ME !YÕnj s2rGlh4Al`q%Wo$֚Z?rrJk:z ADz/8͉(ݗq4;D<}W&N "t(nRL8r"Qv_QG3$fBWPj~0x)5 5਋nb@]rL q՗`q7N D4=qc`mj/:̱$4dyw {<0bL-yҁ:{xo 2٣[v+FcO4G`(-?8ΉkD5bޟS+k[V)lquĬ7gB_7.I$BLr >9 OɷmF&&͞aھ矐@)"l.}hClGoT 2wd+/*чi= RHTr!_pWEK$+=ϓܺ-SW?EFvul<; L/ucZRZ˜UV۬``W&Pr Qc3 كvv]?!bkǯ,{@"5Oj CJ0,>k1+{F{.U,VR_`~x̑VLIbZV$`5z@Ҕ^GY_etj6n0B>[f&͍lX&Wor|̀¯>k PUfv'Rp&Xc4퍷2c4_* "gO*Cww9= 鯕S'g]6K ?Kù@})KfIB#LӢY7'Lu2yRU2^φVWfMSGA}KrwggtFn&3tuϴ]B.buyQ%6R檏J|qk ||.ܪq_[H_RL4}Ǘ$b_pM9Z QFDٳig?^孖HvxiJ-vQNk՘tuAQx#MBx^(ZFYs"FB|sA0sthURi TaƃC7(IbgCǡ̎We:)4 LCjNUo޳P捁=&uiݹR(>\X1$A,WHć~']髽-,?{tI>wKuֺY _0Ǡ 1y)6fŀO(Һ @P0g J Nq O'gTB @9/FŹ3xjjJJfbժT2$i X} 0#GPX$DȆ?'1<@=O0hA Z'omG`C-D{)ZmTPB3UևFb(L| n=D_& +lʤuScl Xp_G'A95 A:TY|(!ƌ>C5H*OP$!JH\W&Q3Q[,n6 M|3F+kq+&a͎hBGMFx5㖮=Wv=ߩ\bZa<16qLw4& )YO+1ժBNXR6V2 #J!4C*}p8kIPհɀǏf ;/qY cф3dk)$軿ČfэMSFT|B"4+s[hK;J`{4eOվWEY^}~+5IjGLqsO9cF/8 3 pҖj"l˅2_WxbF{%^"o'D|9ieC,jLb俶 2{Y,T ݓ4%LI9=%H_'EJߦh@t SMs Z}+-76kw$H)5QflbPvC7#3JI@`hܥ:q[W|e 2 k<|8o{֩#i!=C+q09 QS,I2 b?{ԺPز*?$'YsJ9V |< c^[ˮ-E3(2Y[SNjG+X^m0YҨilWL?Ncg7pqD8rW` GJɆWks]ckɑ6!;Øm;Žrّij5Qmwjٯ,֠`c{4dq&zSy7T*Ts+-#6ޱ^p$.-$b#NuA:ə̇YbmG W2Ӯ8X7St/ۜbb8Vyr;Ps/"R<|s>xU! ^ `" ]sqQ,PLʏ^8ytyctc:֦ئ35{V InWr $ BlRmɂF[N4 T4ȰpO"Rfdx$j'q@ֹѬ9i{)O#}1*㚳O%z`6x:GєLKIMy&L-.FMڀYW|k<5arFуZcΏBЎ1mdkgEz " t!X_t ]qh9r"~[\9pDJJ&O Gag!1joo{~c G#f!,,cχ` hĻ.Va|$^@rߥ؋IQɑ^螯n.F`10 |O;aPL4L:KVHe٢}Slx~12li6䜺~Ph^Gܐ C[KQ9  ctMH` (g:w٧uBb?ZG`{ǚ@ᬘ7QwNY[ahNPіBծԝěPG_Gn,J(V`p+"ꇩKUJI6d!FzS2].ŏXvL@c'H J'S '`^?ZUfzmTȃ è\[_/QΥ܅~T1$ Q#݌[9‡{W۟nBGOg&9S#%}phΤBYIruq w$#qL=[fodܶJQ}cfyw͋=|H]Qr;$6b:9L-(}c#6bHۡV,l;0ϿeM<5be2[ .*n#I[M si~fR~jYf͞5uWn+_m0"nQJ\c# fK(2TA-bp&Ɉ!J?@2I .ƲMOU EMspb+T{ڢy'_Z(e}ju{m>ݛanMq&k$ 2DnVQzн$Rp<-Y{~8N.f5-`IZ=hp_Q@u;㢎vQ$/u=TsoǝZbnyQ?D8l˸hY'F-P8.~sf/^7.2(ۜ-ZL8w29c _GS0Ϝ~V17w@gL$:7BVD@ܤu vy"ioOe||Az&Ȏ bЕ|ﻝ ՃN; uAIL5(8~9s;1 .1d.;lIG}% BQ9ƥ3 h1w_cᇣ!,4;8ru781oai!> (G["2i nNGpfěh\fmh0Rm( &\:#h6#kwLS3&۱3Jǖgi(W Sؕtn8Mj ?4]oU|İ Gőy*F1m2/*f kޠ{ 5@(@X/߳~Žv02CkJx1(PΈ b/jCYd L*JpA!(-ۛAb!dXZzJo=aBJ*ifFƎcD*HejBuZԁe. l~ ۡm5ȹv(SDN-p5g;;)sЪ?L:;r۠ 3:ާQ^aDG/2>)?ch4)s=ơd.q n~,eĿzq/M\ǶxANj}gX@~La@vQEQøqqg<]\wp6URǥmxy9˲'wcGZ^𩭿"j]CO^V=T c(^ ym˅gY4.Grq5Ͳdu5f=.A߉͡P 2#_Z^v21p#{ZQ;ZVjl=TR-Vz>ٲ31t~tR[3LEue~F瀿p܂[= &Ϡt+xIC{B6=Q-cPސ 5俓s;'|PneY覵xIA\\M@$nT]/aUeduh)tvvDLfo'(9@k@ K=RDV7׈La~J@$ Xb2@8udydatoa심̵<FK8Pb5=f\=S=o A:"`4:e $~\ 9T.cJm7eV~VGUMST1W@Fܾ d u3BY%zeoӓ**HXTz\@MnŔճv#:ޓBQbs .OK9 E*}_ྔ{ufx8}㷸6I2 TPl2$d`ƌWpkYU-[Nϰ:?TcTϻ;-X 3r"VhzmK u7A/W`eqVh?qRRcbk7~jp};rz`slLϺ`hLsHpHL fE\jسf/1 wnhtvK#薎9R @ɹ]&gSRSY~X@U6m*8}OPMvQ|5ǹqP(+ f/+;i>GAq_[ Ӹ^ r$PRGjnAdd !jqZȦ "b]gog8O G⢪T |,e̜ViH;Z5 K S]Jp*WB>n"&&+~]֢.A_){xgՈnLHN)ޢ/E2TyO`q"]rC$Z<#^KF2'#ZХ=(7=wC!x7"6d.v(‚-6!~´rtiv-9qGe6I^7Z %EZ{ynO2VC _7қYA ^1 i d9$ү:ޕF1N©4OMTqK ً oId,̙\8,N͂|N7~L+k M Ln-~x YW ~gd?ͼّd1̎gN/8&?W$$Z?nQNS5_~-o5-Zv2b)n$&5IFaJ5}Y߻b9_Uu yeذ]*F<^CWߝ"ַnwAy_vgY0V-fe8 q5lKjDco;4^9]OwۀΏ_fM ʉN90M!}t+SNr}:ۓQ&3 .q]۵r2'0F:5H/#aX%!dC]4 ޣە)!ld0%"@PǢ MdUgOuD>*;iOQMĥ*lO>جY:Sk&HkK8 EYŊQ] [ChiO?jw$/A"(Rk" hmb#,m?лKC,KiP 4꣯$nJMFߚB $RčϦ1fn. O+&ӣ@zlWGOaH'hm賿[2HOks][VbvE5.}咎$dRx>}&dSN,P_B Ѿv!ڲLw eRJ^z֤̄$ig,^j .ދ![:>&A6h$'z feU|88\>vsGfNp!ș> N7{NJ (bݾQzGW!Q󱸤/܄z/nH#Gt1_h9 /|$̍=f')Ȏ&gCVp8'G,䭹fI2. YZĻ9HI̽3*6euI ~^j78<+>PMRv6=ΰGr?,G9!Uwo6< kh߸4唠B4rb¶V>| * )h|cL{Āpoac_CיeKk 4de&>ư\ϋjrF> _9E LF7AT2ZP`V_x֚~%UZOIv(ΥF' DUb1[9FL&MTRY٠D"<|9D uVhBjo+e!ZT6PACLѹcTQKpkK@TRKBtj9<{VCR媶\nԀ=uxѤB TubląK2&{vGbckr6$UZyuRt(S풗0 UZ]trU&9~g,n؜] "!A0#?=J(4QWϣ%tx߬.~XUIW HA3Ƅob"duoP4]֟`Kp-{vD8P{"; >Qa ^߳?VrɊF$ϝ Lqqǯn —YXKpdzfu'pU)OXlwŭ1`";'',EkY+@j]ҋM9&8b X^tO m#$ wħsr@K:$ d:p!Ȧ ,B6Tgrr?u99#@SJW*S&w㋖ƊJ\5PNadvdA }w_F sL`[>!xpz sƦR!FOIƉ8^T$T6.~\GmXS_{TvZǽ8=>;PK_0ud>62˷$> OIEg.9[=t6Kd e!qnei .`,wn# p .[8Ֆѡ=`%mL1n\.:^m!)//KO>}xw/{atV]+|_6 lkdI{|BRVGVX#5vh."Ms|[>jW%)iZ6 saeӕV5RSYI&1\w/5\CWˇGӆc{7BsS. 9LFQYsNox˖:&Q86[)E#)] H\[876yCg3i=Qrx6^bR$\_)B|7?5f#BRV2C _;*fV?X$؆Nk,gi+=kD+yX5Qȷ20ĭ>"p&$VJj9Nr :٥չFlٲt&% 1 ONάhҍa:3X? =@5i [lE T,ڒPa>/4H =eϻbwq >%&F#3H۶jzX!5ջAI&YvFtWrۙi22KV0HՠǸ3✅ӀOu@D<p[q2r$N9k}T !%Z>;1lȓ'm.=\H~Ȗ~ eu bnp*:0|?nH$~zFlKx\n&udynz[AG(Ķ|t|2z!8Jk 5S0eyl8e}m`5o? 4QGL 4T۶x!R{87FʄXwIxs}po/е;J?6φs3pCn|*쁲D¾4GS^ٍVHLG6u95#'Z+pͼY]n C`|j?"xkRaEw s׋y8EW/O&z$~}3fx (C(?_ ؙsۨ]:4U'D]Ȥ54|!]K۔^Ku8Ym<W'mFkv7n61hg]QȨ'3F$iz f-Zڍ8E{7HnU[+%\:08$y / W$!*GM?t Ե[R/*XBIkLyxh ieԵܨ 0&?o#GeP^}4h#f4g4rbh.\xk1ltcW%i"djA*q柹msXJq@uCE_>z j A'[8ug%3_ YNB׽Q6$ ES/QZC GNjm Il3Jj|^V1s$RŠ* ;'7v>_>ɐg2ϊnf?f *> DwzJ%,c擀?X;0Gd_ 3.*H,!k{Tx"LAF12R&-N緦Nai)6PT(L| ?_@960wh~IW%:Q{hܩrLjҮy8Ra8<$=t[('.<*W hS7x* S PBθИiLDG+l,+#V vi&̵縯2]$ܨ>`/?Nt)R|SJʨ%gͪ>93z1NB}Iu,T&y63CO%8nDIX"y:q0Dc (&.L*nt\}MLo4`p͵AUZ <"Mb)>.X 5)sFC, CS`k>~f9AjۈDK M-1'O%I1RQ"~Ҩ^R#qȘ f$ܭVC C>HbäO=jRuW#88ɖK9Nb&Y2K3b;{h%KCRV<0Ӕ7x4u!8gC mЬy܀Sܸc(",k~}4qo_>0uv t8k32Jhg5xCE" G]S.)7oҶSZB+,Io*U(cv`XJր|*VYBs%[dOC㰊~DC&' m@U3xP 8;? %p< BdqNzT`pC4 ]&&L6aާ>$Da$; cQ2y1DᘊڎY*ŜO;[ʣD:Dhw'ڂy)M۱\RLeoQuh]5N;$>O-hq5c'&blG_V90ܪ`j1ߔP'oMpӷdq b-G7]?)?6Ov 'x%ɷO^r[1m`DV݁^Yt&`X,KN B8a œSo޺.;L i")p7>\y!*uPM0vƙ26͔y:^ǹ~#<nc=_hx9ǾYtǘn*c-_x8b_Jޢ;an})-xp 2fX8imp`bJ ,4@R$'=?08i@Ĺk!QnjLOŃ1h_ ~{W:D-39=QlMmyAc䘇Zxe)0R s\ĉʻVGgbRRܾy7ִd۠^f [@_i)F5" iZ=Db\JvP`0Ko=ytSߥ#Ò%$Q(䲯M52h\+ϹC֪'_ņis_};)ƫb Q'EeLclBf_CZu)H*B0A& OEɰl{&O;,P]ŒFJ( 0B+bS (rX҂[Rc۹\[wy[lߎ `vLKwHv4IU1`zdD$ᕞNMDZ 33~&U*P|fkvҤs )QfA(mJDyqJcc "A@O+z/ܯ%Izؖ.ۃFGQ`iVJΦOMRiʮ,ۍ;Y&2ٯ\V+e*]|( [&}z,.LTIp@ 3ҐWAS y (QXBQNCAsmAEͶgdMJ#f%c)1zTjR/DƨWXxi{ms }4Kw`4!D!|Ka 72_vl=ަE4. !i~Yn,)-D6vR0{dO b\݂ly·3zt(U8KSf>TܰKE9zf= R:6aó*}})9$_s)%NoA.[?"4wAY_-1ۤov^jq} Ur'*BZT 6ؑe[]/x {_ GQ"Aݹ@βpHZlWƺ+YHy6 kqƂAKi{@)'B "|CZzıq:^>cM.ԺIDI9f3L(:8iO Hd@)Tn{hr13{sKҊup0r3 B?ހ:q;Vj=.VǢ0@I6hMͯ:IQRLw̱h9jRӏEǵ{ޥCU8it;FNLˏs.MdNmtˮ 9MV$5U8?0#mb!;1"8azZP8*Rqx̜?- tB{Q`b"biCe9J| ~܇E.Rڞ7QVpۣk{}l{tHX[ϙF+#pM VA:_K^ǒ6lLBtV-(&@,Gq=? K݅K7ݡuK|Q{pynK?u|ü,i9G6nd\!9KvZG\]Xu}ct:YCkׇgQKK@XC&M\ot!c~n)F8fhq4EV:!DO*g zcog$onLK4׻s>NmrT +kM/OsŃ0f1(6o6xtL< Sퟀx'FRJ k{ӵnS#~ȋrdEED?CƐ*יkKxn+OwK 2X2A!Dn;WhGZEUmIc|O$i` `6OI9UJYuILӿի[f9_pKT!>f(䉽}f#Nv |jda0FQs YfVw%YaNƌٻ%1:7̮;pZ XϯSNRsRYnk974o<>Ą/י4Js?/,W3\ xYla[½ ܎Ip?v8B8R&Uzq}`Gf[]f- ?{(˭|ܝa\KDXwE +FiOܧ2Lݮɇg۬AtK彀h'lZ8l\PvR6)kkOxi[k֝= D -\d" nxQD NU 2Awiy.Gجk>o5`erPP4%d*rY潄R$_õ>ڽD$fX1 폾 uomw~k(3g6# E;~!1Jp%[aձocp-u]^|[ ԰ԊsMIݯ'k'{'Ѫlh b%ZzoRc~a6EvȖm{EuSJP'n4FĖ9*:cmSt>_m$ 3e&,[UNX. ?j x-z"D>w3N6&NSen;ؑ٢le-Y&rMd 9OzΓQ|1^9% /%m ƇaB,骬%.^xǝ_W7~%[ ܚfg^mmk^^gjxU 3YM>Swl,`T]7B'r^7T ВO?Q:V^PL4ƆW/TaP6fE5UdRP+yzzG ] MiUɝ +?5I7ԏDwz\OY$VA0f'@c 7 R?ǀ+ϼνHձvVwugnc)YЅyrq,}߂yvh7"$=2k"O9/mhǨ)KjQ] O7!'X -„b^,I*"w,cW蟮/4: ۆN~7M}2n8J'H9v@?wlp%16Um\یo9GG'?sq^Us5W8eu]E/=fje~aN5B=/~/9t- U<z Ԝ =EpvojCs}w&!ѵʵA[Dh'tdžW".%&eς>bBZ> u+fDT03:'55z;7*IqFN!V"H-jyus仸}HfZ>V&|,0"N)w54\ulIAI5Nә@lf!] 4S$!ntkpG%p ~LnO)RI>];;k&opDkx!Ι?j%XOq ?E΀O\paZ瀎܏npElw{r>y߬: hxe@/(XepVHiF%PN87P#Gx3+m:g$inF^<!2LDp> m_B!_7a3ǦX>R![5 SH;\jGOU([Qz_Xσ(Ox=&gBq>oS?Nio3<*s~^W4ޟMOyыo=p`[ܽ E{Kh3.e]48³p-H2kK@XZdFNcHzhIo l+:u R%JCQ #r;ª%ӲVXs@jvmiBCߟ׼.83CHȫv5>=?\Juu'ҐXུޅ]0lkpUkClTnXL7t_`C(<)0ZQc]lvZz/O|-ٽ}0_ɰcC DXVJ֒L LyÓeDkAN| 56.UoF/_5+aQ&{9ɝ|A<%'vǡWP1nH ̷e'T2p!Y"?@$2Ixcngߊ|~v2"DK8W)IhX1ʾ5[$ p6}F6i.~Đm ànyZ,"`-^*@~g]; ƢJ1:򜮬l'TW?aH4NTt$: 1vl!wXDΞAD̜snz}0Y+{O&~V@+Z˄OGI$K^8s5-t?]–;zwW?clI=Fބg]ospd-XMˁi n+W~oqW?TU}WnN3/, Ie/I ]5uwl34#>jgsVoi؋,5<T2KUoPDQy JtNqw5Okw1OiJHrZFjr`hWP 2hۜ=N oՀ56ųH."O"X=~9:pb |(Tz%ʵ[E]~`j><(&;_ }Iȋ4C 8jn>hݐV}\Opx () :~P1knr\p,Ӳn o1vNZ=f3p5>3'ii8qӪ/_زr ].s)X,>|9P,RЎqIirm#<tuC< VFxR'=W,j l40E*?e^'Xlh#2 XV?2Ǝ =_QH`{ >Ζ$$ ~A.VӿZn ]Q槊:et$`4S8Kk{5xKv@"[5vOdO鳅$(Fo>F*U$5zx;Z hG)2#t9{c+Y"~z LyZoÕ^p*-/:{>̭{MR'/ߛ/AqBn[50)qtYc36&v1s&/[Gz!{ïM:7W[69-W)L8621 UM.2=%O9IQMn 1֡S<5SSU4}H.SmvvpFIplݭF1V HT郵M8@W܏枰Qn1VE%PJ wW%jX#FjRxmxrRt7?L}CGY/T 6Hb/l=1RաVs:Ʒz& DnjUVoj9~CG}xdR.waݒFQ PnD"wC]>\gї/[ r_f2.Sw]H'Ʈ^FZ(De;.mkG'VV SQCKc)ʃ(=4vY/,NSvuvYڶ}T-0cUPm1yclMhvo-#4짴W؟T!T/?]j[Rxm)$MFmQZHt S v*rA>[hb!@*#]=l\l>pnЃ1;zk_`"1˜joyd%r$RtȆ Q+9!܎Ve GrQľǾX+){Ny7U<*0ĬI2L&^I@.nAW0ՄcO2{_F7ǘ0paSCYw HolYƉt=,͠esҩ 62kg4-ZUJ ɨt7E,pHL.,r: B~KW&}-`".(^f^(Juj` s^' h5wO}xpą%iͬ?@"{ ծ ܬ8<`Ti~֗yL]4بYAQ3c%LL5_y <+G. zIm>3N>)R# '|\jRWzpB’ԅ_B }blONl~]&(<&*׺ 4+}ˏMk-2VSR2^??{,(!zdbWB$sY63א;&S'F|tt˨ O3GX|](z^6^^q)u|M18x F鞭\׾$D={1cp\%,dP&15K {e-dZR:(S-QNukp&Վ|0,ޤdWwN~ҬBRة; [ˠنwbh 7%幼b,B.:!!xdᒰՌVv`]]Sk_Y^QxLlV?nj'3FEd袑r2 ! 8FEWN(ne Xx?U+ dN/O\|%3(~nuc>[ψUKr7lx ZeL`O@d s2J){!,RH7\>ϝX$"dX&7Uop;&/F>R? ^R#>"Uqn0%'Z ,qZ|RA@śLdC;3mQ3a.4B"7/s<10hm~KuJ,c(Ru0=. Md2S($wڒe(M bgzqA®4.5yCzBmգbțE/q%Mu$Xh5eYAi/xpƯf)}F7}3<ݵ/ug{J3xʉSUZh"9K8t}b{)v(6/Iuw}0ѧDf$G~cpfZJXfy~$N1;k#fߋh@T1+1[wB{̹g&LwWGOZNA0֏+jő???*.1T\b)߭M狡t(sZxgdp"i[EK`h0JL&W?jPG E?K m9=tbMJ˴ף#%-Z]}~iYaLd $_> ŢVe8}V {w7:s=hMռ}|?kFnR1u!\)Si濑LcDNǾRj<ԡwhxRgpܝ`;9t"4X`^`HO`I.ZhQi7x|4QZ@* H2x"לv4}uYAlf]s9}L8Mou tZ.0 dv3܎qƂeC=nS^ 9810^X38 T;"DJ ݶ- k5a shj o`rl@K۬;%˖ s-]1A0 >u5RXygŜ%P(U۰1 bCkqbMrRWxKX/> o a+-&]Ԥ'WM;/?;Pٜ<,}Ls[XHv =xC؞ SLGp8EKI',*Бzi2r]ўq$t9g|O9ttB<ۨ)%$Lo<#5pH~Z#Uauzw: " 4g$1C|b7gG٫edz[FNBx'sPWB 9t\I_ ٪8Ȟ9j`1Ayb|"[2麓QSG2#AC(;R=i+Es0GYykucqU7Gfϗ>=0x>ڜHR7}bг&Qb/0طK5d.GCH B+G9s5Y{S2iݸb4I)Y{F{yLœsiTs%ZTڹa",k[t=z T0 b65i2)}A#zw-X!ҵx(7^viK{UM䰍_4._s,No_T..ZEUj&o٢Ug^=,726(54%;s>_舽u<c,'*>;d\Y3Hg r:ΡO+n'pbAN(caZ c 5GuW9Mxt$c(~>n"77`|r5*^a!!Rı!ئ8Xu}߉K=0j , 5z /\1ŲX@˙C& }]f  a05,fO#VqZ+~kT.i-oc-[wQ2wfmw|,tGm{V XA?e%n^b:m!QdW_J#mR,@SK9$KՆ?m^nt@O4Z3ڟ6px6}DʾbVd V"mBdEشa#j76?3]UZ3o=T'Cl4ᾍkZ]eO0}$"(f[rL8PP֠XJ%4%j̭ۨU e2zs/sO'pM&QeYygD*J: -u jFiapn)5Gp"%Ceƣ?Rx 9ߗbzMk[ny @sT.в^H{Ƽ<>=~Sju'?z'Gitш-;%.&i4 nE?<勲D} %է%K -_]K wGşʄ3ո̂- Y8Fg9"`d)ŒC.D8)t[ϟ~V*5ԒV͝t!͐y JrM6a+EluxyN L۾@2\ Bk 7;+\,%3S_`Ѹ:O$ h=ტ29W-On e=܆I V߃}d t䋦r_9AmͭId$+MypX,{2׽e}owJwb^=ti섨p!uH>-ZfH;r-ɾ1Xrبߘ==anheceB>FgܩAh7p^6vԍ F6[/8~>vS_kw>\ D&VF:dZ2!]6`Ǎk3a|;iLvPYhK0<:'"{+3F7Q$)gGAKyKn)@)|eI+$gIfTG=gfƞWըE;;#mV}Q>pK۾DX`ޫ>n-rTXIO(V̐fe W`<:nϸ4Pd={{ TgdDVei>Kqo sOF~ָFY7fʕ@8»d R`dCkaf-BLR.7D߄o0Yģƨ)xeiSe2#gFH.yn: @e"e?[7<%VYNVῤ&-)*f5 |Z8VK6#ĺ5pY Gm 5C, eb+_Vv;zjne/S0 !&(|^_A,͞q( C>.}~ Am4R9uYx5pί\9d\ S/ok./qM|mUG{[ʨ]1Iq0ެMWoQF|HoN'n1TݺxeI4Wyl+\ʮJIOGd]{PǑuG}{^tioX"*ٽa1Enh>֮ʎ  Ń}sW7z֗n3G36v߾q=u~8yoNK+?Av2hf 4 5P)U3`$H`,#`YZUGGk5-qm l~vXѩNR 1 4ga)S>'F4G{KBySu]vȰ,xh<+,k˫t޾3"dϽnp!@B'Q&j9J˗>.4t-`јa'("I{c"*vicEWi mŕ/i!60]ʅ ޝ)\K6i1Y:Cv+$M li{(.4_+ UWs8' ~ ơbFM΅O[$T]Ip*bͿ pq<-jКsBC^;cz,:=0A)cpjA\c^:Af\QM"_4cR&@ |!CVI'X'JpᶖxF{`$u-[6l1!j %KxC拶\RM,{~1p!vtMt< ߽$V}D4T`!Eڌ=OpT5ĖW\xy'JJ6N-J9qTm5r $@B 38Y7 d˦Y׋GL,47hE*_6cu]lЬEƻ[p=]YՔK\UB\؆=Ub" mIc skeaw!Cq#Nft\#P 5#\pQ> Z@䟚{fǠ3ܢDv:+QnԺ<=Vhw$SlZ:vWK,I l'CRg`u%|XwUjZKpH@OBgS=)m L]U%u0Ǔ,ʇA(}GS6PBh2Oq oue pxB UKyX!8׍jzg {f1q)Ro '&v0d t=Wno h-ZYJ<[џNgJs̸ ,[!Cs$b g5k_-橛KfI;|5My'S:/WI ހ6h.0c9~^+>@Mc ABpcPia%V#qQl[_r$°䄲agaznw (fIV*RkȎ!c^/-%i 2LU?h,Y-(Glx#[_hpr!zL٫Fg#"߂'ڄ 7j_p轀@Lطo?\T 0u@E{Ն1w"\JQ3G&)*V56cP8ρ;dbXA~9Xn6 UDz7 S5L!7*i\19o7-Ԃ*ܔM- #\!L-4GlA#ЩL6D ;gT !UVOh.PSB羴foԷFin665Կ׿#zi {8C5a u=0I&`={Q, s).c}*xEzn|aJm!CRYctK1^C#D'r/G b~RLFE K(w3*T&å}=eZ( ik)dHwG2b/~ fhOÿEIĪ TQT8pkYw|a`ig,zWg0l{ e,+1@JA+2[LY/C\kMT~09h %|yʪ&|VleHS}5'~mc'2ڋ<7ImX$VKKdz7 UWt\kr ,J* ܘ$7*M7[LW\8 _ }健=RkÀbn, ޕx_pm6У6 hj_GV3I6A3&ނYAd&zm3/ 5cg{K~zs/!GP1ErFuKʶPutsaFi)WuHcShIIUP} QJ!:G4XqW]sv0$2Xl{_(Ae+P쬡9S^r ssU-EARx *):ui*v& 2BIy;$z:9D'W]3%Bq* /:0U Ĥawmo{[BJDdR,CM% 8cEG9y1(߷^Pʮ rJ0' SCRI-v>[Q1 hpٙkXHk7>VE˘z^ 594BUpu|2N G.Oҡ׺͊ݥA_YS2j^ l\xCYbL1n~8 fðl u&e" ÁB -&l V,g";qsz1^i@5Mx38$3 ˔ӿz8Ѻ  ް֪ܯ 2N8C(,u\{Z6_߃@e>/^0D̥ݩ;ХVp "!:R*KL5QiQνF94|v5|nC"xk!̴b%Yv3[ɮm?{{EP?xhMR4mLh_dJ{@ G| D. Ӝ8e' D΁Szfqc 45gץpNN %CKԖ+l_\ fTγ:vbx_h [y14NPx䊧\#׈ A7U~ @JquAs[wOgl'4M\Dn(p%z][X-WR"˵[b61UmX 7܍'KrސӚ'Dp8H\ɐk$DA(* ҄jcS((\7xIĐӴVqᔮkǽN6XBw'~7c'd1fWٝ;EZ.#\M1l=T%"m3$J2kӽuΡt7W qb.P>r , {~CB@?|T~G?er6G5\8k j{׿A$@~ez#j7gt!|F&2U0xv}// ΛG.jjhBv\CحC#}kfkU%_ifpǺ=kÌ!Pt 'e}XTj'#鍖7e` I'#BŲz$e7LdȖ e|I$[ic[qY9@A'bnaaԭţb'=|hjQiӑ m?gbH(oɎ0{q !ӵAKK* JBDz@ų] >}U)[:?W s!Xۯ!3jbyFpOɑyFQfψG%/ DDmuwmƣ0v;[<3X^žG>wjSO4~1/AX8MdԌ5(ܭg)ĈR>5*8K$KE{v13{?}WfmKʎշqaN~67-ksLkE:ǖz>2[/ P4X\OAR$(ХP_-ø #j|{ttc1P;Tp SܧZcd8cpUL]~ 7B J|*%4/s,n ĠN'k,7/ n $oމTWҚU3K!X Q'JʧۈANScr'>0D|zb${^B6 ת.G14q#mTaws/_U3\>.vt K,b+ ~9^q`>/\v'.NEv)^޾nhK4z+ DN#p}?Ԛ(  /5:Y#cݩvAQhqQ]۶A#Bj@  Dr!fFUy/C'~^AUOJpV~? =cH0|KEf' [8VB7lX4 ?79i<ME D??1}X0͔!:^St&84+K*>U'N@^WDkk~Ý%0ɓNE-c0}Bc PY5L4W!"FʺTO>9ȲGgƿF3it,JkpQBqqP5QbY /*80EAnY'4@PdS!fiqŒ'.J;cBT$|:@tcbܶz(Iw^~(싣9\O (nmɦ ~@;Nh NF_g\ |1-i9phUx t:Dóv %gdliiG[Ldy)]g6=a"̤agN4OIq/Э`l&+ }-ǒC*!^Svf D hKѼ$fNUZ}d΄#/M2zy?2MBG,TFbڝp Ԫ=:P-iM [W=Y(sA/k2$ AhӠ&r/w 9Rai>"",xQ42en84Es60<ڄ|#mx@#Ob/(/[?1Z'Zt:?<F .#&qFr/8ލ_aZɠ^x+ 2Q62Z폳3vs;M^ +vqkMU- ;iU'A~Gc\˭JZ?؀גKO`k뜲Gܯ!9=?-<isj&FtkESX:G 1CvgqU}rQ` Uwy4juQig<| DL_PQgA>0{CF%04o,z o+7^RY7-L-] u/|{Zp>Un5b9  !D樵8>UARܒYjE^#5Bo Yڻj` $g&4k.t?+;@B{BHhnN3<"4ZMcci:M%8H/H.RzKA<^ k^PSX:d W $`y.Hv'"F:U0 Gxy҆#L['162*2$01MD^*:WoUc/d;N"k:Jon 0C&Wx9GS>_ⱟ,uc쏶P\KGnY7"#D u7#R*hZ[9FnFcG0K{bv[fC|D.jc {)yI!exɪ1MlQ641V0ϻ1:zMHCGѸuZRX/E SZ'%9O;60NJ -7/b1l Qzن| n"-t0"$*ئ4% voVҖ\ikA603G%lnPȆSZ;` PYhS)!ˣ_l$"@沠|;^u6p [e3] ?5y[ JT°Q!7sKY'9; 1b:f83!uCt -=D4;zRݐOv(:_>d6aui$JQDFg[=4۟HgenAO9GqkL}=$7L#T\Y}v .Jl~BU$fkť{_z x俟H/T~{&ڰNaL+!U ̮Y*o m~\|s8}wMA)y  K=A!GF)ۀ : (gC07 HGN´߹rvV]r}M]lu> ?C&@x{bqkw5xa;$Aa^jHw]rJe*H DY3لUρAlcpjtմch@wCZ[m34X^)ZtgdQW`\¥>ִLs[ r5 c[*1Cf,-cgS[ muxkbmaO].ײx#Qa0]l(<ߝC)D1BHY$J W`IhE vHa\nd,QQy•[`+ծ7CnGU$}Fo,Ey凉F:VΓg7SXmAIZ|oZU+KIR;)ijoA`oBQS LSQ\SsOӧtÎ9F:TV&Ai+Ncv->B;V̈O>Zs5 %~c9jȇ=#v. G|Sc,y-[8^ 3JRbs/t='DLp; ݤwh3ރjÖvaW Gq4xP{LP&l̖e='J;Y Yh64}~K˸:Ti[*40GwJ%v3=$!w{P%ѫ ~'E%' [ÜF [Fvj% /83#h5tw9u N=;O췠T ~'p*9!¹ze/(c6f4΍9:( J@sWXq(hVɂOW .)nBjʣ|D)*%@Wc)cdSw"?ȃ9 uH?Ȇ#1Akb#z/[5 Je_}^gH[cshqHɁǩؙ+`Kd[ mq:pQCb@u2 :ٷ>Q[op.R'w[2 5E<\CZR贸MY Sld_Ѹ+PdgBX9w\ /Pg8ޓ9x> v{e BJ8_ϐwWCgF'=Mv2#7PanZ!WdVg:n!AH8ne#FVPx~),]n_@8CG(@"4!Oo"G"sn:g`>[HszG%P邴f&i<'WssRr&q5-|ᨄsHao'kx[K m 85)~kx)7WeBI56,A?Ε#PTX-']LO!XP;goUC"syk΅{k $b՚ClppNH=}.pj}'H)Mfs*-ߖմAic5Vw2p' ^:Ѹ/EW~F{7!HD WJ1;-fU @_\zݿv~= 8v_DtbsrZ"'Ƶ1WHY\Zǁ#ν7 OUFzaόLbg Xpo" 1*"Ȥ7a$)Q@ ߌN Bӓr~բ888PPqͅK`}{}N8_y1aԄxi22K]gW i[;AY-K/`YM;daU2o_N9S)SJp3LI`!I0ѯr6+cfK͢%x_1bQ[YO}*'/̬g'̍4M6/: JAÞBC8ǩ _HE#h6Ʈ ^ӟ9AVóTJկ=LרgiTӽu &yaRz!ͥo“]'Cr&m uLEpV%Ei7dfzKK෈r36F;qu˗LYa6 Bi9r혁Lܘ)g 60[44-gĀvnƃ3mFAЛG/ 7̻yn<>ܲp A|iT:l+A&uZT c`̡TV}ȶWH&U35g8X5'JpO 4 qa\W9mp(lT@q,8QitM%,icAWo+& g^s=Oe`e1Qv"T=R"-0o'gY?YV.bIJJ·)K]w @uyhϙJ1PRRWj-^q!BJ Ed7hk:#/F ryA43ni݀sx5g楬PMSmZ7#z{0aڗH^FsiEMj@.R(/=" 7.qq|;:&*K7 |!d(:E"[ϭ9i_uvBN1O?SAmjF,zcU*S𭤖B`Ϧœ{\1]7'L0rp{h1AF}n6L4. Y<*gK3E Qs0.}awE3]kͬ=xSVb) iPwYn#}Ͷ6jSGHgqֻd0w/,Io=NguB\1cpas/9Rv/ȻO:=wh'5oƳ$yP=(H<D1wRMոoEl%;~C. AQGV55b)xm-^T/c5 1,ZhLw3hR fĜʬ#en_j%xth9fӷ,z|7= 2KEm|01K=J߉3+maiM'\m&b``*$d`  UWK("/k}WXEDaW'`l~s9ÙϧGL1SC~YдF~,ED60LNyC%yT:cCV#jrH+ X I^wܹaP?`AD~*m?fہ&Ϭʐ2mvN.]]+/mqk̺9[fm>E8&RAs[J` qUEKh*ɓ)yWr98pS:h{-o"miHټܮ1#3L!:Z8/MfhhnVGg{u_WOr@"nJVs涊H" rD|4`bXܢ`8.SKZX 'L%6cr2,(W * >c^I` "$=$͌`@U\܃5G-(VQzęN0f+'[)~Y?9#a?+S=߈q-= z#$ȰBӁc:UTF7;xav,؁0+%X2=UKɮʶ؆EeXZV%a]&UP:` |JW0pWeUrK] ƿ W:"(ym?Xy-yYXi`/@h¹?| ,C\/+!dl2mXhaqKʐ ++O*Xxkuٵ65}qX:jj#Qؽ!C'O#RoW@fhjO@$jH[dg轎/c3,/!`/ctm1c#V1Sl>Әt?sP|g< f8{. 4@КI˄匃jj¸!F`!܅yLnuQWʾ>үS|8D& -*ZGL>J_K$?:+ܵ_;h?’\Vm1YEfكps.^Ush_[vGT_C W{2yQW!eeV\beo(OTҠ|*U7b=ٜLQIvv_EL ӇMǏ;.3UAH~,凹'@yVGW#NOVkH7I6 IlޛpXiL 1'SOYW!=Q sENC` e 8 J s͝:.<$Y KL\J|٥6i%U>Ű+J ؜A2Ѹ,gb$bW&yznصÌGz>{mK{+IWNG rE ߟM~c;lGP߲ ڶ4/],͖y׻t-IE3CWeœ>n); ƽ7A'xzBcișy1{f[w&)狃;oQ&7Ў^'&`! }zvl5O"߰=>nkq0# L }:o/sSBL1{}{&ݍ&2x*Zv}8~5BXEvV,:YG*3YΑ4~;x;qFxOYdXX z,׊mZ蓔ILz6XG +aJ뻈rJezg$ f{v\;-Joq֟"UgL⥲`)8OU{>'rcp0N,IL\[_MC l`5]`^H^0}D+xVmm3iݗNJ(sKTP21ਙP<肮PCV$V,3yc:"u#&5H㝩!"@#Phz(Ruq SK` mFjh&R@~g>|YR osw(Htfs,#!Y 9SKXm4ځU=7D殤 I8\KMti\짴O#^CbM_?T컡 kpc9v7hB¦3].f-oY*JU:#j^Z >Y3'lV'5Gu>NIEHFS,*n:`k{^z\tU ܓMFam }G[x%+스wpt{l{h!yZ4cŅ4f" PRs -fO#̶!:,)SF~ 5]F^m:[P*֓/AC桒i),Q'S 닋|d8>I~\Iv"_[w=_Ū}=0P #3j!C{$ h 'U^qWCVy7lJjoa^Ȋn=hLVkܽ40SBX!~vxx+e#MO :L[0W Q~NݫDw[14pmQ2ↄ)Lm>&}O$TK\虖}~B5҉ 3{4B6 T\F7ʖBZ~QcqVg ^WNBm~Fj7.D0lSYm+%#O!A(f#z .Y Pt(Z֭a<0E-#ͱU88E!H lyb_x29ƀ*H oa:*A"c͜9gݾԗ E+4 D+N#%OPIo8rRŷm" rTDB\bf) ѳ-S1GuAOln [Գtl`X*q,g(:$#4p տx臷1ɬh.+ q7O>49'o}s9h4Ik\FJ@]yg, % $KX* dT\!gR0FXzrDn#WdnXJ{7Oyol"tM)}`H'=rCU z\u76S`l7$C-vYYs t:麀wx*qiٻ%23gzu#j E[]CͅkZ{rVӔHG);9]2idXfiiϾ p[Fb7>7C/46# 9߾BQ{_1N-cɔ(X˭fë+(>XԂ~G1-Rj^t<*&[b+CʝY0pIB7MfsXId}WK;ѽJcXls7L-Z[ LYNn R .,#]#((9w'MU>-(Vi~ $ < <*p;vA%=A*9%r1)QR#Ica1< OChHESCZD/HfF96Uaj"ςQMZ%]Adm4;͛T6_h-Ϻgߧ 30RUm_1Ѩ\4 _2 ):EՈj0#yNV`"DaoM] 39_+-g`0F0ZgY28ǶyIRiMVb]b#ߛT[5+@%sq C'eoA0=EWSA. ex뛽>$Qle8iYϸۭoJ\6Rn#ҋ Ö7|F/[o3?ŇkkߣYֺcEfD1o; d8=?LlbH  FwjeX8Wwj2_1H.WtS`X)Uq2,|; a гL 9 d2 iENvV)l//ńK8M]˕ -&T/LnhrUsa̞`&Wsa;~OϾXw&Y"'a=^c/GͪcB=),D9.oEӬU?ςG"akuڀ fY fݘ =`e1jB[`Q~1{L tP;'L@s9C 0VoqݤNf0Jد,ǝ2ʾ*ͥ͡7faЗD2DxoC8ep;t5uϒwgxDA_A.U6U^tQ`׫z/rOec&cRcN 7xj\U:ې67J>CЏ5?\c &:;̓_DϯE<|=qrةO}Erɛ\JGv7<3 CԽ<ԓ"<w#NCI!ȡD&՜Kej,1Ou0ԙHj0ب.kDY%ZCHnj1d[H8Zg,įAjWr*.6ݒNVygR9։Up,ahkVy;dj !X=P ǘ5{c:-1_9[5c~Eԏ1Feb֢k{5p/Ebb\3fTy z^`PC߂ʖNeb/rm;"4N') +2}Jݐ/$m{+*2))ޒ?R0Ǭ^8y_ɨZIH,9u?ZyT/9jmh[stlpzwi u#2ڂs_%LGaSk$!kdk MSꋠQVuNx vÿ^kstdm C8/T]~SSs}BdUn` |SZ( #=aswp5Pᵀx4H pdOdq`xmz ܊2+j8p|%hdmio1chd:0{P^e'BDHY8os(G_s:AۼEۘ9pڡ@k$.P/T="@\ .8p~ 1#]rmqݰ`#tEȹ' I, GQQcid>t/P;,2mqSsrvgG%]r[(<> dZQy>Cw!e̾f eHF-rF#Y[ C+gSAӂ+iHm%au̙֪0Jk9x!i+w# U}#ք9mWԥ09a,pr"e[l?F3)vEa}TLvQgY4,Vb`!otwjZȑF.J`iߣpX@}5s0*5";(.$ 1|O`2I$ 7s4]c"AwTR)PEyt=uJH^K@X8RWih*cLiW-5HRD1dz!!Q]ihGC<))8Yc!p<*&JH/ h-g§Qq<܉n t/^D^02Y­4M4/ju>lsd̶"naW~F5qܼMxUdHUQ!11e=Gx < a hFM0"SF8%`^֤aE`9>u§Tuֶ[" պb3-!0RlG ٨p øfq|$IGWj`YA~H^^lwMRAmwDLF-1&&ڛK-!_-l 䎵"DnU \Ey;\=b>!IU.Wǽ3]ޮHAG7)&vBV鮢ҟV| 3~}xZSЏ\?hiGNv+Ӆ;Ζ) 3(L }FaŅW5SxWiM'dKW=0/G>va!7NEE~E lLQ.;8ޅL94 ] IJ X_}<ԢҾ 8@Mך7hƶĨX|l[Rk#|p6!! 6bn燰oW 8"όyș0A:?R=Ξ &_: j):VWu' O~1;H>sXж݈=.Jq kc~.PKp,`` .|pC1f?f沫<+mh|v_0T;9SA+n(> ;pD誘P㶟%jtE `{p>OY8J呁镝);- cF!lU7gA=Y0jFʓf+⯐(5'[hwX{?%iYvEe>/E|mUEO[@ݭL]Tv gft1t^F`P GFxanZ\#V:oX#|C EaNr !`>Am!;5vmXߺ6ƒ,D7a xz*1I5n4{Qk2j<=E=:΋x- U^K->6jՎcJ`+m=KR0SPlĞ5̊d,>ȟUy8 dΠޔk8^%-Üǧf򳺉vYwhWn:vG5s4rhʏ9lOEvyD(/dPNNij1C ǷK#|uR ^{"YښԮYw T nZ! qXgχ6K@_$L+$ܲ0Z4+|1DWjxgpMAXnq 5huє!.zQ!=ԱHZ r!{DR)(zSE'(rgSFy<R?.\e9h4Da Cp鋌pylqư-Na|iqKzŠ'\` 4+mT bs]%ki&{BU5tD}L TaR}t~p6$̾zrP 1ϱw=RjƼ^ kmr+i:{7Sƞ@"Hb([V43Q]9`'GϜj>0&̼bZ;xlǛ2F Քy)+e jr #m-zW3q1K>9FN4H8gmI/0Y>]䴌jY)b \{nf=[|cKᆵ 0Q#: 32Nsa,jRM[ n,BVx!lWHt@O-|,6~ܞ؍$)!;۶HIku ,t=ѯ.NΏ'ܩ\b(6'4× s*-}CT'-4ZsYt*Y}LJkƖB{3 %t3HU`)D(_ށ?,>Z-rk[A@3F?-3JY5̕+zGȏ7[DZ:-9G2 S@ 6׼Lߎ~D'1|lqLzs9;$K% 0K 'Fx#DIq*Kq $_@=WGjT׏_rhRt>fVRl{Àd"dq &G߶ YZ