sssd-kcm-2.5.2-2.el8_5.1 >  A aU]*% )+Hp4g JsE=;rsCd +7}܌9 DϣnZʝe(=7V2{I GmXOȬGGqݛ$/[om|soGm3`Q|:)INo)_Ƌɂ6){m][{'M](j xc9[Au]e^Z"?%=tpTdG0$þ4@yO2W»JΘ']#&]6:4u(#n F|jKys&W/%Km/G5fu(G' SV>dAM|h牁YȩǐzְIJ )y;ӈ f~9ID\RG`I0z&z"2h9fpwr%` lJ#͍t9x cT_.d9f45f2dc10d4137c5e2d60055f5642a52bea5a94c476f833f8d4f55f1867607308cbf1a3389db41092a1df4f27fed6a95a860d00ȉaU]e-5f@ tZY_t,ϡ /;Q2ek0.uw+'ybcqS[ #ح, 6c*)#3L O(G{vPܓ2YPp(G |N%J{pBq?qd   F +HNVk|   0  g T9 899(89l:d\>h`?hh@hpGhxHhIhXiYi\iH]i^jw bkxdlelfllltlumvmTwoxp ypHIqlqpqvqCsssd-kcm2.5.22.el8_5.1An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.a?ppc64le-01.mbox.centos.org |CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxppc64le if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi,%4zځAAA큤A큤aa/a/a/a/a/aaaaaaaaaacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8b4e29a574d0d8fb18abdee833929707d2486eab2d2c21cf074496be2e7bf9daf63de5bbdcb09dadaacafc574d67ff3c7e96ddfadebec422327646be91df73b800897f09c5b3f440fb7080b00113bd6436c5735a2dfcb28220a3b7186b3cf2cca2ee0f8515e9ae9c7f6403b8aede78f95ae725693781204cd24869f83608f529ffb54b1a7d7495078e7efcda6e9a9ef7f3907cc54f8c64a57791667e5f4387af4afea4bbcaf7c8b610c8311849c11b8feadb50355ba251a22abf2e5bebd94fad8acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/lib64/sssd/libsss_secrets.so../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.2-2.el8_5.1.src.rpmconfig(sssd-kcm)libsss_secrets.so()(64bit)sssd-kcmsssd-kcm(ppc-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_secrets.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.5.2-2.el8_5.13.0.4-14.6.0-14.0-15.2-12.5.2-2.el8_5.14.14.3amaa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.2-2.1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2014460 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing [rhel-8.5.0.z]- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh svuk2.5.2-2.el8_5.12.5.2-2.el8_5.12.5.2-2.el8_5.1 kcm_default_ccache.build-id551f588bb800c7f8dcc7b7c974d75e5ae5ad17a591a027640a4b984abbda990529244e5f4230fee0sssd-kcm.servicesssd-kcm.socketlibsss_secrets.sosssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/55//usr/lib/.build-id/91//usr/lib/systemd/system//usr/lib64/sssd//usr/libexec/sssd//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=551f588bb800c7f8dcc7b7c974d75e5ae5ad17a5, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=91a027640a4b984abbda990529244e5f4230fee0, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)-PRRR)R%RRRR RR*RRRRRRRR R RR,R(R R!R&RR3R+R'R/RRRRR R)RRR-RRRR RR.R%R R!RR"R#R$RRRR RR*RRRRRRRR R,R(R R&RR3utf-8b49889f049eb9f7812ae2887607fb23add30d8f51fad8c93b9cfaa727ee4b776?7zXZ !#,ְ] b2u Q{LR~MB*zPuއ>}Vs8D^HdR脺ҟzG)̾dwl3WXp,3Htbkq V1_ȹ\H42W OA[h4J xf+\$ sSR491@!.};E\P-Ha1:&DI`3T&HKi$wKLj'16xz/VE s25^6&ٍK{LVO_sA˥q1/9G}@0XF~~v-9#Lp%EwGxWG{%Ɇr:trUtvo5Gktޔ"(ߐc+6 d  |Ig!i n}?GgJT-[R4NvzMgWQm=;l]~DnGƖa(t/FT٢1R"rְ;YaB&URf/P?X?a.kuq{VbhtcԲsբժ)Lu[OIK;,\`;L,C#[fc'6Z/ *M(SXtşV`$&/vS)qƤP 5?`=6$vFST%3q׬aSnW}Aְ=X`gu uk5D۸M>-OԱO)p_ _Å0<"y!R&ؕרx.=\l"tϥSԕ۞.O/ zK쀟ݟaq^g ī8&ى,i}̽X-I_h0DmtDYboy\ɽi2I%e?v]eJME\:/ %U^s}F88@B;D: .Mq}cl0+7<Џ*i}j675.d#>lgѯ #FE(_p O$NmCO$ݖ?85xA!J nbdjBnTj|6y [Ѿ.j/~ iHwWXugFNV-0p т>UZ- Y_m~(/߆+e";p5C'x_e89Ap4~gџwo_t2J~68!\^ۆ'1 ?qB[fIPNE}N4̥mP sg)DE%\xr ȧs=XŸrٳlB5Up-=U=:syX ~*MG>c盌tzGe0]'W'u+91=iU⥽4rݗ v4ysOPľ'npI$;W gaKy,uW|͉2%rČ|1o{e||_Tv?H5Db 8p%T &V˒eQ~uHl֛<yr-dl 2>L)ݪŸGKٗIa.?ZADu\Gҋ#\11b'6+q9{#[s&iZ`9qN zE=; Js`(j*\(+Z %"* Qb+cC\?G*N|Y9(X؍^RgU 6}bh'c{nOӟ=>nJ捶^êm7I'm+Vq2jPѼx5\\+*=(o lI4$9 EuH[C}jcJqneYpν-a)M`F&^x,w?u|]y4~I7 ye\zj+2J;=f?TIX{a <+/~uo4uդ PA( I" ZcW\HD |)2&{s/BIJ~}հ~a,aF`7 s05KE1Dlr˾D|lu}P/K-zS7 5ɷ17y^R)[Eg}%҅0^հq7)`/c uI!ȨWu;ۺeNJs1%ܟs} S:5h|35֦To6ZP^w@IXHR_}|4Y&[K>2;Sz =)r YÇd3A-tuۆ$"wtm;s~PBMKNmt/bM?Cᡇ+:ދ@ZlRk6oX/dG-XruMK?4`2z#wKB`^M]i)T!4Vd' 磖 0혥R4DZ;ؽZiuE56..絍Xw;݇IH6QUZ!Էh3p勰_r gl6U.UM?*fauo 5Cc!*-hM ×8ʊ@i{0.5U0 m{sssњJܬsD.^c1}pS~@s!+U+dqK0P\ <1~\ǁ*`@|@2 VKe"gIYZ+x$ "+TV9 ͠\>H_q̦)*#Tgi7#Gg`TK/I똶"p.0k\m8S ܝeL W@4j d]`=Zh‚rAr{fhZ`RFi9%xep Sew9 0p4h!w"Ვ:\+ # yC+9):v$/@1GտɼBQ"\M¿w˙~@xG KF2@E |eH,4n gT ”x ^MH\Ё ʪ?].S@Qt]"KW9CZSqUom6`T ߞ}kb9mp1 [;n}*. #&jA%G$R>>GIaL7$>'&>,ۄfwbG Rw1Lsv3떜`B=tV8ЎRPLnڋOL؏=W*0 ,s3% My$G%PX}J =&0`>.3ʎj\SEt}՟tX UFq;tφڹ"[,΢mݷAfw݃U{ފR"Щ[sNoɮ&:]̚N&>O\gSXؠ"2j)x!:8O'YDԿ^@92A`36 G3T|L9%6J$O q\ȣ6I3,u6}>b1FID>w9TXyO݁\쨃}LJ %65Mfv_:MZTT¢馝$і&C+>~ѺX(DDzN_|s+Ap8DD[E-0}yߘ:e_-H]B+r`T\+x53uȋi!hђ^*7+}/PʁdQk9~CqlբIf@-dL|43 Ku@:qp>Q@:qF}@P؆{ FsF<*4`I$3],B#!me,+H(c.C#݆5 Sɓ2=jU G|C ?4lWZB䣮M=h]![9Z!.m5u.( =CU*1 4D ] oׅ;wTDV|xza~oŀnwXq ߑV@ hfK%׺cl1UmF7 ["K Q !>޽7N:-m3 {E!7hU3P=F,Ndsj,B.&륭V E/Z4aʛʁ#K;ߡĀ0ۯ(Eo7K+|dYIW 2ۙNʈg1HoSyhBͦ.= L.k~GU_;u$b1Vq&"h; n[c鋋cHRVa}RM)5$&Y##AʝU=RXV [$B:_t^E[fwS"tU$RmMa4\PzQSU(壺 .f cݵO}f^v+<)8ВZ%bl|ePJ(DNu 8ۻ}v)AǦ!^tRdۤ8M gCoFSKoHz}uI!Ť&iz%oAtaKE^%.K&HjM af*)fޔV`H!PnhIN=KdM0z)9‹3• ެe&nqӎ(Ee ! Dܒ%)a[Q; ; }`32101ttszleu,>o#Me__e2YGI/D/{h㜪DNaͅ)qzZC(JoQvb6^Kcy5睟%ǺɌ}|}%D]6S8T&ۖB! 7(%,YA=X9z܆e,5Fr#U5dcE6A "jK˩]/b%/ݾ(|Rx}vЫjJXrx2.J!ls,)QYm?5whޔJ,=x}7_&ZߦV\bU8ã9;?|qW[R>"XAJg]I۪efӹPn B'b 41/ J8mF`:̲&Z!6?''{:\Ue|8o}HZH§3뼹·o\;gXKKթ ^Px֑ {mSW|fzlxm"8AƗoK/4Gkzc1n  L/4` s隖oւdP|2#毬 H{ZGE1>o*0]9Hwɝ&ryNoq!Vp:&!H*&9.G$!Ti*WI+ b0_ȍӾnd&{B59\c 65Zecj>4M<!'˕x7fEO)j'beyH,^kt/0&3sCi\ːYHK|;-EerFbcj-V~j M?.ÍSJ61ȝ(?M/t 쮣Vt]15}iy]G)qVf嵩^Sl?u}@d9 GP猢 VPBm-q5?3'Gd4MT!fJJ,@cZJ܅x0K)WB"j( cޟgl#~i@'BI 3&똺`2o^vHЅƝIʡt5sG8EŵUz`N*\Y56k,9lS&xeBinl㥋 fL2]|Ds j|gmyiǸ=!6?sbjdc7֪=|:pt &z \ _SlRc@$g`Qm㎖-v[η|^d P֞Hq |9&1q8o''rBmt˱%D~&G693W19Xɿ!?H0笩bPBzAWkg⥎^Jw11_PNoU}02Hn4J ?юS afDo/z["jw{9TUH-"򪼘Èvފxqb$;MΞ cQt/y.g¦ cRwsi"pJQWP_/?MPVɲm.tT$7ռ)B_c $e]OCbd) Yw?:⇳.=0-C lR"@ r:ȅ9<njX-ܗ/$'o&DiE;ts;,PCD#;be0jQ/9 GɝDbS6Ɇ+yi\Z1@ޅ]ڟ%/$Q&uXѺLӨm2uF)ѝ xȥRGU6ځ}B샊ltP<-VӒy9 :/w">ߚW7Z¦tOn*2 R,at N 36fIC1L Ǭ !p9&xMw&.UC*usėyBmjp+/NKxQPZ,[ :=5hT{.`련VB9-LN4QɅ 84Y5v78@U)#q/SSc"(;w tMMkcS#4A]HJ,z~Ϳ | fV'шOqĀs,&Q]|Q?7dt( M,NEk4afN_1ӗ;6f ٿ:%[2Ce4%o~AT6P2)xpJrSDbm;uڙ Mڣ,#6"(&P^0L&Vlhf9ML@;m^#K_m]Q2ď +b"f&f;E14>Zw2-e(Թ/B&sUm7C-Edx#I.ס~Zeb|tˇKX:~ƍ2Kx5 < Qmܦ JZyTP/,rVΖWگI x?wgo>p.hA;s^\9! K,'a`2`=xRo @=`qWȢIqabwG8xb,cn(\3J+AU1ݿF׭"diMkaG/Z[MهR\W]ﲅ=hQ5Z̀I s8`O  ]ew6|f:u,hӺᇼ]5"澬f~6j%a&Ao2Oro3KG|&Ӎ5M⿸%z!Mf g~Εt^ڰk?֖fܿ-rO5'4兓U_`GoY{1`H^l޼7߃9'OO:jIڇ(%x WHǛKEc ?"D#}NL7@.e-tRWZXt N!f?pxL4Ԇ1msʍ<> s09>?_r4a5ǥlFLKAssJI\n\H6ZZjJg@M= UN)XۅG% ]Ys4=ZB!+*ˣZZj/5fu$@fMh"tqWti)lq5[qsʒjSX֧9l~r! t ^W#݈#am#a >uHY`*&m󘔚,w>N5E51; =Hv%Ey5Nɶ*J sKvy2tVɚNNkDJڼRSøT ޲0m"*ܪ_Ÿz6ot GubA}=yՎLKx  ^s=~;Yu“wVk -`(VP;Y|<:^0G!걡IDFä7U"m:B+ f?rHoylICӴSPD&Lx*0\O(ۅ&oYҗ*h"lB#r a=I@eo;/{WjJvb\T#8Lih˝VU^@,ףs\2{e׿RUQ2BG(nhf5˲Qkj7|Z#F˓}Σ@iKO~o|٧ռz=23ss{a|jE)~8:XwyI>k3IoN**,,|uL1/MIks5$VF&h*0ӿۊ,1.fvgJ7E5Ixqo䉏mc} X %?iɀa@9r?ZEiT _(AHrujP\g(m߱uO~x@{j5H#X{UX:؉5Kqd`FSs _=r=Dta 5HNPEOn\^n6 ;{p ﻄ},ƗvC&+K,KB_!TeܻWwcF*ģy7\K'6tw@(gcT/˒,]ybe6VctdYIvT^%scgEsmJwiѷ6S. F FI$.1_K3g2A2Mk(l0iѱ_k8T@}N2 P(Ye:L dє#3UƟ(*+GZNSTOٕS^`Wd"NSަ;N혛:K2kK/HHe Ā\fmſm O =N#d&֚uWmAvyeb]V#Zzٸ¶ 4"nO9 1,ИŊL4D [K%)&gf/K^p<1ph?^ P5#a;Fi$% u3U)XDۏ?19읗uU[+aBDYCuJq:h 4]E 9ʰ6@4fk~3מTшri3ԛ&*Y_rjk`H'`r1"o>w)*m*LJG2jѥ1a6~ Ad\ UΦY*S9&9-;49ImMGȀ&,gUG-T15Q34;,DiHSa\L3„P,4G6%9"@EX/"|Ec |&Fy5JJ}qXD&`!m)o u,LRPGh, _{q<`L,`uZS CdSd9]ZA>f萹  Ƈ[iC&ڞIș_iY SYƽ)Gˇ& ׂ@EsLE1||/C܋N:>q}'R:њg$#-"*Bi#JwjV2i˩*iU/|lz>xypSJdZ}ӮQC׶/MI=#3&qrN"2ԸVƝiQU6ǯ'E&s:OhA%5Ĥl~xzM_/⥸Ss.#qIP}@=.-e;d}wXxt_S8,!KT+MW0U]7:)Y ?4 t06}C'sy/ ӎ&Hl[E#oVv'6@g 81Znjx9u WAb{BINޕf zC~UDHw1TWoUPr3sX̖R7ekE˦II=@@)I?5!*rH|, @9Wyeǯ6#lQ <琑D.y:S'sw:3i:&-mDr]Az7 k4QK֐H4Vxbk(VzD^WYL49|7M̀ P_% Otm LUDqC*.W6+G6: AIO1V[[uHQb{~Zуq*w0#Lc?*A'5 qW|^2Q<6(Z͏UJfʠNP(K9%@R,x\M֮HୋϬ6ʡVy>؂F뾰 tJ4۶.y5ʚs,axLm:1Z(& /lnA{|:}FYۯLY(Hy$$k)u_1-:J "]겊Zc58pltm=>Md!o _^"\J-@kTk7kE0Py:ڡcr3̣54;Vɿ. ^ؒhITt}\ĻNp[162~+r^ C< ۄ bd`^HI0T ᎋ#E~ }~p{21}bӶX 2R^}2#Cw9al"a4_1Ad~$dFգ!"$|OY|TPܤ+S`]{P-JK:P&} jr)sD|9r3+@CMMϰ0Ӧ2 V*3m |RU3'SEݴ{9*-3Rh+n'Zm*b?u< T خ_m᫪f^-fCx4LFӳop2)Dn_L *륅@6\@,~g<Ȱ5Nל,/pNADD3+͝gS6X큜/qs"Z]ZS6j݋D_il5G&)4NGzB9qIq3GmL5?R) ;DFżεUPu~ ui;N MjvH!wZ=IOw@I2LRW{wܚb3dA[~fS.+EcrkD}ծ\n]tWPh{yV49> T_R<Ս-9::(?{;y2Bsr^\,"hLPV1rGoQT75[Fnc"OG\|%ghjDdU1/uL\G\1HFjܱfr@_v%'v',> $] 6&2qb_H0LEXr;ϝKKPz4at9i݌WueΠEbS!~,|+tB܇.K e[/"V6ܸq>a IS:qjIquJ![{i73[uNYx+:~I\c9pԣn\|l]+~=ꉒ1-]&`;` &JS쨦hg|!+HTj |=& }΄p ڴ@:X,!?>M oBH?এlb[s7;[L9F-Rk 31YʋJ(4b_'ު)uf0F18Oe|kx7S=K:>ec@8&dm ΨrຜHkangUxJg o )ON_!/Y> 4f~mƴS ky5qsSbQ>EQ9*EO,Mreg [DyLYgҰ(QpH[m/=v(6aa?Xtp,s抽g\kJ }7iœtpDy+:C`m̩>kr}Ry=ې仠Kx՗=Dܦ @[eʩϏPHi~' %|ig:^;Ye '܎g"گv}vNR~qlhE0jyp-OA5[~('QR1&鱷&k iav̖%lQ yiC7/j؛"~2Mb'gx#8v´I^?=ٌC|&/-V!hA`l:ƕ /{f2oKlmG8?\١w𹭐+ώ$U7DGSM4qi ~~+O>;a+t3juLJ w' q_YrHѰ0]luPJm1|cQ-9s7ҧGOZc<X%`02f9SQ{m{ivʈбr<͏zt;4SFRUL>$RbS׉/+?L-V>1fL`&f ;`B=uihZR^|EXSZ5a2_^OUW,ni:7djxG)mfgMR0J煨ܣ#6m,.BGRD""%$um[UXv. ]鏊plДhǶ.!N,2r:ѻX l#e&xXc!i ҵϹW>tv%l(T3L pz)'XZ[qK&.yh %,~ YiTF1ٜTƘN\fRd`8+zQ3GhT8` ' 4-]t* &$em%f+ ɿ;PЃ۟Ps] l͟snߑ_Z{8P&|Q%媴Ig#"N*ndN_2 ]xVaH@,Ѩexg[͡A^60Ѱc˖1ɻݮbha<7x`w Frݠ۴(䯴E =Sod9}E숺}ŖXɑ 38Qc&zPuЙmɓa݁4@ޅ7V)E(JiYZan^ "iBZ4o^Ɨ #Nwf~+iR$ޢg s^֥9P"T./fbϢ-0=FEGaq[֕*H7vnisbcp)@(E)[r}(K ώFsP8YV; 0 _=ӱ,)+D&wpLl{t~4Q t *#Z+H+zHxV>)TsjՇ)Rۃg+P;|^u?5`H0/G`_߉鱑mx .0"T(] n^n.va]q˧:PAy&&mp.sӟ88;lxb=ֺn ҈ ZuQONg |( epg:ֲ:n/O[=t)zpڍx/$'Y/;A,RBci SYA:y[VT2Y%N n%CJlmxCk&-"#-k_/44"qT ĉ@/p("}ɩ/O2e͓a]nDt2׷H/T uW]Ʒ^"t6ES]o@E[Ls^}hQ<kÌ>13=r}\7ƞ$"VfEIŞCbeN~r1/46cL=!bU%܊bQMO4%a5TM;=4Ur8/'HLy $% | `( E*uϽl|}om市&!=3f׾HEgO 5@ rL:"#Y(1ńTх?:KZ~_ w`rKPВ<3n9hE)uM|R ~@Ѩ/ǦA=Rt UfeĹʨ$rIU ;I;ME;cVC™+?ɯubq]>?C|.}Y:g*g< ̗ L/f?BK\>OUsw2UByӵ?oXO]P/j_n ,Im-y@@bo7g⹄3 x& r \=m`4 ,JHЗ9(DQx`:t&2IOQdgT暅BL'b',*$(lȡ1aN1|B% a<:ev%d1Mp(rHูOXC?}4' =`}-L8xhoDYI{&yB=PboOu⊬}'V!/UY[Q GkD *ߧ7.2GIYtT"𝺙ׇe5i^+)W|IlC/{ /ec}8٭i&5jN6\}r\WkཏsMnL +W% $et˜ ]&P8UXk!0<ϔl:>4[X!&n)>3yky+#;+{U.hNocjiEN %ΫV+fC: ;H&= oU[:cPqQM!pxabH7t=U6y/2mWSt @8 ) u&wAS 6z.k f!/[ڞv軾9ALO}bB;8LSD_NZRxr4)B#K0Q"]!A6gܙmp7UUjcD'{3>1Y&~mmIb#V`xPmVzm]!64zҠgDŽ0> 2Ba!>ZX%R€z(1y&Л5"Vlr$jű-Jc2] mgm8ettqx~\'v!+2hlpy{SA(qJ TByt%>z=DƱl<1bJwr"v{}"rVpE96}-'۳9L.m.s&Χɕ]W櫕7sTi'EZ>3QbxH`C-Tw<=ko_[f!8aty)DSWHLW0fG z*Uaf(9 ߉&YeUڐs.!i2(vO:~a\ xDjwSKfw~ҧ,_}\{Gؑ qT^ &X-]r WXrLc(y~@F!l{:I•K_},X˳CfK&? ##cpKms Q5re RaG&4Vm}?zR V椛 z2^:VぬD%4o:#X |?_8`lƀ'vWrW8);G :D2a+zܒ"W-Y$ ti~n皬;-sˠEH'aQ?BdfrZ}1#`S&($1i_\PyYYbؗ~6{r'`+lZO֔0'S7oJ7q*"IWkR6mn`˷F*;֚?f>)t?`ʥ ̿Z4 +2ͥZ?QD3& NpQš!AYZ$ue+tҘco/2k,('oP}9"~C:Y 7f4ngeIj Zzu^"OBMQ.Ͻm 9{ce%mV3h2`x!d潏\%wu(V-zm@Gm{E)9ϼ302NK"$9EYQNI[~4=ڏ=d}lV}JL % w$UP ;߯ p{~`!7No2 A\n F:pny3rW𚻵nF. ]Pw2lּ$HM~j\⬷)u /jf]#;Hd;=_*aM#O6GʑGP^QJT0IjGa&ӫ Mܩ-NOzv57 C[Z{2~_Nao^{ ZȪL6&Pرc#;m^^Z,T};Sj뼏9.8"cW q0Z{eT޷ig$`84X[~)_&Wפ)M]EJ%kw3pדGwo!:;;$Z ǓTp(N34 p)REz4^;l$]iJ ܭ$ԇ~|fPy~_Y=^P33ܼ݇7 dG݉%MQY4>iET,~7GlvMΘdS򹑾ӶG 8ON1txs1s~#V@Qgwԇ*W>ȈPٻ̪YV"N|]'u ZaRE/O19nÀkos [7p7,躅mDǪH] b&}ZKY S`OR,/-j)y(5b[5jcY%tI} jT\ra}Ϝ!$FZu`YX}x#xw2 ?/ j(690'Ax!p $nFK *[Xnu,T"fݲ3CHOHY \^yWIQ;v_=_˝Ҙ4Oq#g$=[6$==C-ݧsRY2ޗ6 .ej4GФ [* w(]˪hoi}džuge|[_BXpF1]g}q ЭpIMp>ܔ=&p'(%U[N͖,G2+)&b9[e+{8DiE } `+Y.V௥yǵRCv\:lNc Cy-#mHiO NK!D#;ՙk[S5[9wh&M騾Am4!؝l7M[ xoFMn\69,ɋu&Pwc^.'Lgø6OL^L"e ;Zm"2]ˀOFSwa; <` (9~mRQAi)wLxK'ϠI&gǁQ/{HEywŸΌ\XVgzhge!F.;d Y|5"V*!B|H2^;Q:InH$| X[eso8dqOMKVU)*s}n>w C1 !0RE. n=\^cMOS[ȝ⹃/&Aa 7yWK'$"c`Ni-cA73C~O}C[CQ=SnQBqOpq$Û,2Agh>o~֎0lV܍|Kgشwp7F`~)oT1 -!dN:ѱйՠ%aQ$`xc.B9D O/FndgZ02wj޽' %ftjXv9x:>.W`ӒdB634[& Ȭ'u先3>aۣvxvI$S# ÚcƀϟP!":KV .ZK{:$5Uqi aq3?А*M[pPr)G9J[/A@ jtQ,oc?As $sՏbɯL̐:_Hw;TJ4f$ |.tyuL<$ *qDqDw7uܼqiL,9s(vv?N{rW㵃U'7]:qoC{ZHG+2p{#dՁz7LE:c# H34ePeM{ZUlFxȯcit$?XaL|~ݎ[gAwZ܈u9te=#ǃrėuSĮٸ5R(81Al\( GǞcgw|pO F:Q$ )*wCͦ{Wb?x.&$JW!J>&ȋ`EqO*epiA/I3C]MlceB\X`zQD\+b$![PĒe9AIuL,Ԭ*(_lb~h < ]C *>ը.$wg71b}j=}qnQVCNU/y/kU:ɐ&ִ~ct f."'F&Wu)PCd10%,qs==Jɱ:6yvA`\J9]p-q'LF3~c ZXHj9H oM6\i} AfA-j]fc=a<Emǡ(qjB5O7F,}.PmEэN-#PE\[v-L|"M|,%&a K.? *y(7Kٜ[ ty [ ,jpyd^~ ⾮J/D:yϔ5<[L pQ1Æ@a*}qy +9r8 )="̀Na10U|p5iѴbZ~M(h¨zzB|w8 ܄J~` c}@ NdZ<:TQX\wg4i\j5cCpJE OZɊ&G%_M7_(iaH |iai#?6P˽*\#ݹY0IT+6lnp񐯝l$U*>jW>DvG]p[4eD;ۣo;z 50j;Su^s흾Kh 6P_N4P9ѿsԔP__\l3Fpkk.G(D}&?Hrrd.(YZ,}av6Z,@Qi璄mmNr.S:3P^T-ϗc_vuϨD֙+ HbFZnMMϸ{Y`@mH =#!Ջ'@b:m]NGSvͿ\ H8ET|Aւꓭ,[t"h`Kl+m/"M.xĦ7{6̠C]v}+#[ ˆ6@F6aLlokuG.bmW!@No:g+~5į`%^_zNT>3I, b 2wn%M4,P1SGPrφS jwgBFnorj{j9(zgCQ7I dCljo]o+GpKZ(MϜ͓~}yErJyS#VvH2R陇"==-%lDJ:PHwqiWI$u_c{S]pM^~s|m<gJ]E~^gOD$'aEBKy NHE܌h!Sh5st0 B$-w.@-xA[ U573hs g魴;1y<'=B B^h 㓹^0qLor>>_1TdB 'vʭZz{Jrb; RkkfL/IeQi 1~Ґ^#~lAtjN(>JוX@/2L9dUMj]mCR2V@a9"c8;zM@B g8d|{W^NQ3BЛ`_GpFT0ksFIEeZ=pg0ъ%4_ZO""K7GHh]xtgM3 AoԼM4SJ\G*="U]d[> &D՛iYn2KRݸx GXbdOBCW2tn(bt{RvDǿǚ R" ]Ħ_âJZdq&OU'ү@Hcz~W;יgixg7Ȁq;C\4SKz%'txxEB13C=S]0:b~LGvl:mkM!J]son0/ޫU. wՏ5x$# C?'&QNS6kPk <}!2DD4VMH[EݝDyUQʙ г0Vq-Tw$cu0=q2I}غ߻g%XlrO`$[菛~^Yt{:M錑B?%׻3q:@16L*I:R"@Z1aD̼T@}щP~>>Q@Fr1Py[&XVΈrxsQzV R=P>C+w>@Im=8L: T5(Zص[T~W|DKA]JjVw5 ]kDޟ,ѱ&`iZ?uy_=e> KN[fPRGaSLw"tjSqx|pn^i9st^>ԫ4^Y`ZD2%+T2?X_S~OXS, <rKpاErfkOleo;gG1ᵡ~SXϞLJ ~&"ͧN8V4 4 ݯ&f]fs5fج6z##Q;cI<]1,B ێjKbjd=moRSkLNy8TINwB 0r6 ɖ e`8w y`df.}l @J8'w%@;Lk[ݲʱOܗ3t]4KJܣS+ tvii= MweHZm! VF'YGx^A:5t?GFin y20ּ $S;bXc+)L>".I([2у,]/$>b /\ 텓7\cR]@AJZ"Ⱥ0$"I.l}~zb+YIrMb8nmy\F7:Џog\h]śl Ӧݲ˜ԠJ%].qik"d9RMA{߆up6`]/`9MSG4 s ".O=/ UY $;-+0 궾ħSxrxS"9Qltx]򐮍SqCpmԧ/VO`/sq0ٟj;aYZ?jqzN .K&ʲє{|ǁ㷵 hɎry[|U)ꓪjWېuH%lT\oh ƙI97ZRm8_+yKmNLe0VHS i̿Ng?knM3Em~ fY7wT}zSΚIKעa1w%繏X58-Bq#M$dB"~}'ʸ2#pz̑H aW_u̱<'+${ӨLvEZӼʭb,^s;sA׷\7dϓ\a%l\轨.t`H~,Bt26.Ŏ܈^0q҉&zVu˘96n4qtϲ ]{t aw0>F!Zڥjkb0p ?F*IfY34N#LXI0hM`Hlb pB$^]3GwF?(2ޛwơPA`R9vHHD7(pEΊI5tSlLhhk꿀MVtKE6`%/D}67(~Vq6BҖyF.=h0Vɏ[(m8y!<ٌ$ۦiJEPwY:"z ʷ-ōM-ejѵA\rb(=qʎŰXǥ|NIDZsD?a&jNX};|- !THM/BNЏgֶ"3yЬ?W.| e(cwQ:&;#opsV*h?5 }R87FR yp،WNln|?@XWilN3}0G;qxηuhhvp'Uqh6bVEv|TR!ݠSF֙`u o?tR-d祸vIR̔;yizAX\cZ8YݑeLkd?yP9gDWv䢀fɱ R3 G1h?{9F1YHo6"t>jZ\Ebcĸ_ꓞAf*=l B2ID@3yrӀL:a_8}S̆K_~q#\lnJ\6WN7kG|4'8 nBi:?rC-@-zY*5-n,]cbn sa8ǡeKWUN-si{uI_;7:o#(uZl9VF8UBd@.:+ƶanKe3nA͉FCWxc|:G݃ w ^&ɸ#NR*M$GpA3S 5+[ˣK[NKz,%қow}E|܍W8o ې n^a WRaLC(]ׂC3T1ϕ|F-WJ6촶 N+;qO2TO6w2HX :f ^‹?m:4~9;^_s6U0 1LKTkE KZkL,>Y kŠ%4?hnf 2\¸zXP!g3">5"X0%o~JtAd.Z`~H(|U8hƦyUۉ8֝'>lv7@grG+I&>ȖgDeUn'$1b_\R7N\&Q wx J0Xdx=x<9Dx퇫'U1ͳ D&!^o:m4v *CZ1:@Z RsYv+Z1CcpɗSeL [e;2=RמR)W,l2w`ZUDG/ՑA`IOP,S]2LX ܐ'lRlH7-HЙr")6h1J{7Ҿc9 18o0,,/6A'`  xl*U 8lIdY+j+paiqQ-k"r3yDO^Xm\C4CF>|.Оdgj:iܶVYNEG0M.O$!6:]$'`wk8/MțӲƁ3Ao/͉IߗBY}I~oEZ6tTꡳ|=`~ux[{u$Idh3wyo˄5ˁLR'p܌p+lqM0?J5-߫xZ u*D"*Oe@ LhKE9<2s8N?v`RoJf~:QDRZnV> p8^)4PR&>뤽lʤ1~t&*nSqc?"#Aʘ\5,`P-Ω ڗKʤ7sYވfẔ K씹#v4v\mBK`a 6(7,>J%mQOm}r~44ʏIt.# 2վ_PksO!/>!U/s10i"\ c'EPd:i]o8n m/&'}p.w[ ފ,EP; h4A`iēell @0-adk8`}|Te%mu' Es g_<:W7?ٲUH%JIGh bY8@OtF\Vem9WۯQ8mJVܸ<<53#hn惂HxwSpr"VA#ۓOTgKWmӬI5s챳cbz Eoq%H), 32RKC`;$zh{ٴa=Tz;QCmӝuP3DmmQ+h<" $=AaBd%|K켢E?wYQL tL~Ed6xjx[iju!/1EWd`hywbתs&\;Z7z<7Rb/R@<"مJRٴgXwYs24Ѓ~3CR;@K" 7BG"TlG@o1(9f>SyEJ uD)QsLe'UGӑ2nw(qwl+js\sPc0u'v'ueC/s,D}T͒\ʔ1;AdM[tǼ%yJYP.<{SqOHJU&#[PJc;V?xt4%H{|ϦDŽ=vyµKt(GWɓDn_":%c`♷j>2iT+Hb=ЅeTwxGUx[hkn^NxP@H#b-*]Q|^{;m=r(ATTmqAqGXELQPXs.X rv3FRm5lK+.AL1.C}uߦ,l*{a yKJDN-{]}X2a{0HSPF~[k^jP[Wʟ*C`"Dm rorq2JF}+߰W8 ۄ<$ݸhנ&|<ڈGu0Y?9dGQKl cj&æʓzDH6O w-0Fڜ|1c/L{*(g/w Yj'CG p0p &aJqL{>P2Zj2tCD/#l/ ҷ||&'()k.?3$X䓐!¥ru ;n"},,|t 0'/(3s*Bz\])oe zMW) 8xJep~cP.ukHIuca,6'NCp;PrۯoeEDO (ېA&G Wl@NBӓvPDzΎ? U) Y^tjCE Bve_\;ӅٹI`T(f%ɠIdמvK0yhncH+hyv,972qUP =fpwIh(o!\oR2w(8 JCv]Kr<t[j|^Llˠ4@27?A5'K2T8:QQtEݱj} ~7Ų50,J1"a[ uR[3e0iFzrwQ?t{b뉟^X)K3>[Fm|{4w Ԇc4L k)?u` 3)1̴X)U+=n8uoNzfՠ/xaQqz'5$xk=9}o×)w`6lƼA~6F0sSt(2I;ɘN4{IJlJVʃBK "a/|&~t8ytHu"wfK-\H_X&. Tƺ odIDo<ku[By]JY}Opr+bD C19x8!ɬW6^st_7 G.P#!2)jdДGmgz%d#\m[ڭmh8,!eĘZ= 5IIg^pkz /1*ϭZEeh@GT~].y5%z|H(ԈZ:Dtoa+=uB@ҳAˋÝh<}Xo@5:|DcO.Ȼ"'s@Yq,|ȟjBI>Y&[D ޢL- "htG֦A d.`pl E74Miu` \%@ABBq`:f+Yz(j^&tEA#5GgT&AQa>*UZX/'! 8:TK2,swXν!6_YL3jGY% wHW*zMD2ם@HݕE(>Axb"H̽QtBL7 S3Šf,\kߛD6I]4; b8-u@N&NvI;/@N%+Q;oq;jAVZۃA^7bŘncpxhSxYg5Z~O y{S8)}(:O<_qFXxYRWzA;뜩d°h8+R15qR b'NݳcTWFEKcIZT%N]FgiO~w[o>e; hW(4l颈WQ&qWBOAlAiP9ݒ>~d܍8n˂P»`stQ) `EE"tKI`) ZeswsCh*XCޡ&$mƔ qs>S,,2gkr:y f;J!m*S6VLtIT) Tgmfms{t!x|8nXN6+fc a%ͻ$W,CXZg ;ׁ v |y\Lv?6)nfB k Qn"yXǼۇeF LT'nH*W'P(=zvE'sAl{Sq%(p';ڢ l6M̝NpimIǖrUZ^gs $e*{կ#>@pyki{_@WxvxRQМO[]煹I݄DZN0/{!:nq귵nH3殮eBEPn& i5ܖ<Q\U7_'KĺborC۩嶧 rBPCx[:m/j5l,؅ޯs' @­>ߜ‡yHщUW@'i]l *Xe,nF/`i͓@ؙ`fRZtr%n[ ک0NlʍPŤX]s {%E'J.DߴnY$Q-A@!4 R0ii|@1e,(k/vZtvehh`tn'{,&ĦjIqti^wZgb X-ͦ$$jm[l؄ CYqjNȨV`+3BFR>ܦh'B' D41$ԸAJGBj"%r+⑉;;@e%5'8[, * m!%0 zUV#Wo} I ,}Kc?W'BN!s<~%o-6Bχ)(+8KFqng,c N>C7Bew%LBbgEy#Ci 66bL%]YIsh?C2rU: )6#A 8VpX b{SXHo`}B]'$t跐}Ya`4?Tb RDPmEZOAӳE`ԩu8k٭Obbk'/I|ZB*-vu9 s[<'!lOcB?UҌ<.tgيu2a' !.A̺kTJnsGsAyEH=kΒM LnussicR9;@'Dgg5;7%5Lւ)U ܧ""\h*[-TmoUrF//M(.oölu{ \r8ϙ.p7DqQ>;DyH|K?.Uluz"R?xɂ2$qSTzcдR9,g;,5J=iIGsangN WƤZ]G?P?n2V9 &{ nn'-?a3[ "ˤ`K>ݕ]B%A%D4Fz$IYQi:yoR3j ;5>Pt=a34A O^]HW 3;^b76{-D;~}L+=$23^Եw/?+Uƞ'+88{&5\|* aےw4a ς~-q(8Upޑ:Hܞ5%l[24H3+y(7N+b-ЪXz ':J 65R vEU% 60+2\;~v[ˣ~) Kӄ(v-^!Hck +D&?2G=1f#"6~\LX=,גymjjcф螦Z*S^~!R ܜ,'#?mLT4z?J};ֆⅬ4M?r>5k +7xbbaHʦORUp+:t_N SS"Cɛ'gîIjS65.V+m# xdϲ(FrFf#{xj?ayvW7¾g`w'xa`]}*IC nӭaW . 8X͢׼0DsgTWi_}rCXF$T6dvR_d2 ~7LIaMA3#ȑ&$Dєrf G)>YYP0Wbj^su ;#[XK 0-7-u`{F{SjȿGsF \ՎusXjܝ5#2 DmIۿ4l 39d_~$nįG\EEoMZ5h,]޽'7aT墖acA0˂_kJ({>^)@x~Q.1|K=k[r0vY9-TB־Gv5M3!`؃G,]bR&bÇmǚ?tƒ0ޝgйhV훩k10~:,X#na/Ep 鷶yBy'{ dU3ZFNghpL2P6&|ܹٛB,,f8 @eW8l+U=a)nv1x!xZ'\uEm g첒'JE_fV-bYF@"K8)QH䙵}BC#u_3{ʹAu*uuu{tu>ZBs7z2v2 |·k)}0g% sHg W' wؙ))0v||hxR b>9a*:}CKwNB7E?y]z>졅P*O9/W*~/{Nͱ薙'@ɭTfE`jdEށ]{,gEnnZ* XK5l$7#Ǥ_0pfSܭ:"]qUmuuh2 fyducއ'{"X \|kB*rQv #| I05{b>D"aEF.Ǭv~LNVRjMfONH o͞p o ,V^u i 0=G5'd?wd_swEx*n 8?@]:h39H`y1I< Jw2UWfW^ӊטi |'HW7&IwxN /9ȉZv1` tG#f3'=d}anpj:OZnÄ:8nx-8Eߏ ڮ+ /1.*zZcb{w;1}玂DqK0쮗NExoo{2߲ņE \pXxT˚9 Rd.\jQ[_ "܉ dw\8$nؓ])b}ȴ)@5asl(">Xw"1y*rF\8Dp/p=ߙ=b@U37mwdOUWair,l0U:ac֣Sl0)+^21̷Gcl<dL*>"c]3]!DF%(![oЃǸE:V=xE'!<<.@sƵ`Q&`} "LJ0&R~Qіg6v-VK5'Fbju0o|:(L%h~ڜ b|Dn5h@v:a} zbM+Rc2'0c$eKM8)xa-#,ؼM,@_|ߡh-|)Ou, :n6J\qD b sް_Xn13o!XEk~m#ۿd@ȩ_̴s/2>|>.̱a3Pwz(|$Tyuc1x'_=ɓ?F?F cz78i (0/ߧD#F/ CmFF#@L.<yWʶ:)sUmms~f^~)znjd@"-c6$="pxΚ90 c@%؍K uIX3\%4cMo$!0vflK $,[L1*Mܣ^@T&L~ɟgJ{[to$xM_~70HXxI*c"\G} m[6*`94bOUζ)Et,!ܷf _@F)8~܆/ṭ5k4˕-*rNK|s#g0բ^GG@J=3oR'sb{ƭx'xF p"K3-#͙aߪw̐k,Q5Շ J&.f ,7{ dc5@㡛^U<|Da 5[ ] 뛇[ombr{Ac8)om<-JDspKU\٨SO!){HF:|ڢAcS+ x1Ϣ^|I}g<:"1`v "`ElBp76jve;5dF~X" q7m;'LG.AH~4Y .3 j ,zר,pN ~At,β^ /{v]Ne&YxOYf2+D!ɤq8u-iFV֙O!mɝ+$qAԢ|"~[⅀aA#c3CY`?t mVJpazt@f㵞ZIGVgqic@i%/drV8of V"$R=R3 \}Lj0- ^@^-P'ܽ=#DH axȄ><]$چTN2d RRKLY(Y>4"q|\݉/R$˱LIw8,3 puǍ܀c}hśu`hXydڟx\/B=).n:`fם ;e[+[+gXtafBz 7r[9w4zl$Yt}؅ z+L*/6Ò.1⼁^gƫ߾$5 J1?%šI}4׍qG|>%m[_S2b@*lRlgCW6`[3gɰm^mתWF[4YB uRG0fp q)q=0yбPBdadN-E}#W&v?2K7UO08S{g{DMN,ZԳNF1q݇_=p,ž;QOXl|S($8 z1::#H s% SCePfՈ r oDլ >.&ݑ 9.zFS[@t7v)yo?2 "7&6?+ n)cs*k(PwL)!BYukP\MT amT4d!*BzP¡m]Lv!m`FO`qLC)E󾽏;nKr)S璊"i?/%68u('?% 7U&JpegEUG!Jֺ!{܂oXc$A~{KBc8G} "CIU2%B!EBFnS Ɔ"3m<9dIaZmKH:֌Rb]1Bc'/ œ#r` (,IXxUa=#JI]&k7*ŏSa9E$V9aV[w+_%Hx9(UM7Tfp'Ȗ]k//@@|aoP57O5;0}FszWI*)"Y[ޗW'BWz9Z ?,@L,Ej3YNo!\~f/ cYy#[ɢ%Ҷ4G_/a-Ŧ~:@֊Ҷ|{!C(?UZQEY{1o4zFEf;4!{*Ms/6wFL}Uk@Pd]f o/c+ů{j+}]$WH;lwbbTƧeOj3$+\R['a;tj?xZFc$ۦQ?qւ"rd\\}{n3KGY_g&"UoN^/]VB뼪ZޫMusކ/0>Vfo_eS]S-fTJ*o\+Pj~~r#ftؿ3*CԐpu&`{|3yJ6"DMc@?HKmi\7FSPT h.kOGHOap3nAgiUh.r1r/NqވR>WI뭎k 9#vby * j :!#B^ !wzҗ'Ihd6K77d,SvlN~sZf5"jFa;E,|1)+0ܘ|ŧ 5M=|LjׯAGEk u\A`˨$hޫxDœZzTmXV5]5[)wըDA q‰珍e6h[Ɲx$hɿRg/s3F-~eO 6O 5 9Dgp#Ď'`sh},+5Q$͐6_䊛ի֘dښ)'j Zhi*pZurE4HGAc`In"Efͫ5E=R'NpOą"BXp4])/<;N a&QB3*?d``աuO7!Kn-&,@[fQۯ4_-!׷qa*H&@@ೆӫ͆(2Fώ!GЂ_>0a+gM;qi*rXiˉFLe^|?>)2m28 FKk\6o7˴Dء>mjQBV"7utt| Ϣ/It[Pq}4B[:49 HFV_#6ԫf/5>њs̋\t8)LJ0ة(L|>,ٓutJGfB)LBpc^exZK5IpR!D#$K d4@S'ϘԙXco [BS=5̉b=2OPPᦿS'<ۉvB?Y7hM^M7P])ړx0ABM1)3W\iIN'}YQF~zNZu̝}nvbF3U}A#llzpZ?KN}0/9! @qzͱoV.Rs戵 6H( A!?<뒬ԡf[xEQFj%gʥV ռ _概N^[ʏĀH̏(໥Z<9^_@Ok: "A@}AK!wSIl,4rDZHPH@p[ {^P^@/圔z.؀aFo^WӖ~.9Ga?u>NBy Ml) P]@A,QKk|c/\qL95Ջ]]6؇@PbG#oyDY~ df_'rGy}k픞kqos4.r[Q,ƭEmE 궰f6P9iHWS: icPc*."2V#C+W^aZ Kҏ5̧]|Džq_SgfC;C[ |MsӁ30eXRfExbFRg?}NsxTV1Wׁךߜ` UWiQ!fx}]u:2t΁?tehk~@`a|*"* ˆLe&[El{yRd?jQ[`;MU2}YM9nm)5pG(3ό7v\{-.|֧9Z{L!6bc4 iֆvSlc\B`#]ӡ2j;R\b=8(>+eRaF{_AL683w+ġK#D" $L@`cӬsh5sR;D/ceh֡&K#2<m&>)Qb Ɋ$wU4Q~ ,]Ye"Byu] ¿=^^DWQU(ˆ?fvs`Ɣ}/LL {k Oif$a*ͅ}u tP~W5/LIV<ž51jDK# Udzm1WX~mZ[ṶUpY_J^>$v@,r6{#\]n^@|萄^˘=z`eʜe C8V|1@w,)ˌ:} 'f1UsMY.RLfEQ|ܔO& 6` ոqwèt%]5ayQ}Vɖ9  GANLt5fJwhK1n̴҂ @q3pd rdr H0ͧIތLs2O ۧy@ݸ>I6РE&$+qmeBP:(^ I % xȂJf`1>M84Iҝ d[0HQUg{g3Xďٰ*P& qֳr9y+1V{=as"CSSϖTw3Ԯ'9Ð0MTg sņsל"IXA8w%F:έ4Xx}˙KJ[c r)XYmx 9Gt3uޭ>_]y{dmIt+hqևVW!ln͒5`e'RBM`8,N`nGgG]KBhkSeP &CF.nX8*7Ӕ !RLEg @6FWctgQXbj[;%^ (n=2y9+rd/#Lxr\uaD0bQ!sL&R`\_g'M5}O6HF"Op5U3)1UaGim|j-8 z-L̬w\zKO}r9M7Z^k4^2z^Kg|%s (RSҁk6˶t 669o2L.f'P;edvl% 呔~snVeT-|%N{ۀ]ʧGv 1á(2wݦgw ta_0e?u"gjwyyI䷨%VPex݈Sr8]_#VsãybJFL"H z" sF".\+O?SO %(w7F&܎߲喀+bPXY¨ZPnSUK$KgTsӊ׉WLҰ=vgC Q~~˪Dw [)D hl#,c<!5ʑEđe7O}/n9l-̉B0;p pfzk:Ȍ2>Q.vSup=q3w&luސ^FʹWē`Q@{\3x2v0Nkқ`]4{y.GJZLB4xfozy #@Cר}ܹG.\؝D(ᴐ* Qki;J,u =Π{D5 "e.@ 0?!AcIDg7T#Do2񈎗ш1a NK24DF*#eyuP<5|Nzݷ*ɨ6̴fw%|H{lq nO|i0OS.x. ƱXS+}2b#tqbBq>-BZqҰ l[hyGas-p qRFtcQ)oa&"v,a8N &$ Q9jz{:is<jR~BmP:H\<ܻeyzTy \˃{[&X#)H.e[Յgi&Fǥ*}B 6t!`#Kv*4p)LD,6sq~g&nmc-7.hvRYNA7sYhlnE Ό^N{/a@犌"yOLIm6ys}*mSbWn\ a Z*d"i_0u2w,w5VEpGL3 MwUTV6 բ0+8j(!u_dJ>5fP.;۶qoW1cjd$̯O:;#n'e.I'RX̓Vz'NZⰒY;,'ԫT^ުX>WW$mo-_:l<5Zq&pAj)nl1 ;/vM 0N+O*(>4Ãp,s[evW]ubجXFР!n±%Uf'* _R%)Hf͚YUKtx_ٝ@d2S p ;r[ NR73:W/>Ng|}NBitngh ^cPͽÜ#1a4jT+'H>ORj3&g)8RRF- NlwRirc­'ޫ42zX ߰+Z jL/~]\`-Qqd$/p C`Z"LaN(-$7UaTL2 {W:jZ|0f}"FB)fW rs]M 넔we!8:.ۊ0iM-P9 ׄba=0i&-cؿ2qEn#e_7lE7?nbVX_"ZGp6B%4T;dAl9a9K,h\³ 69@i4kKȱL\5g h(D2H9mP{zWX]pZNV]$Dz'~dȈ=x_qrCՆTV1VohEJ~Ԁc. @qe'I+j[3|~KuAT,y`cIƀc]# G`^¸tRmu A_o˟3k#p1Y#S}ͱ5lr G]}=8j!>8;?BO8ek2*@u !z\GZ("⯪VOpdu45ŻZOpE KK¶-Q~k!J{upņ' @zx0zIb{aJ|'٨.^@?p=bV\RuD<}`R!e4<n4ؠvy ,)|j;ƼJxB-Z"%^UVqV9~QM*v$[Nd\LPuuhp7NA)?#d068fowa ˆ8IRnHv 5>rfYAՕlJq TnU>ou8O*xυI*4i^ـP6&?:?|2$_L9];C|ʔ}n:Au.]JدxhB'>8WL&z^{N nę%lkAGNk ͷ"C,5D \F/vr; P"x-{!MUmO| $y%6&Gm`@ W1gٺY75*~AV)V5B^mN(.-E[ KpS d_,&qN7!29^tr'hMRs C 0h !@9 zW kfh}}ftK#!ImV oMҎ uuxt1iqAcbz:~!wMexYF!,ϤK;qRG ep5CwwM/)ȸb[?Įzߧ}JyX: =[sS׏T/B1vY;̣yFVQ'Zʛ۠Օ$KNlϋbtn?ZLI $7[- ߶sC 1ݘrC+G-G<7, җ Lĩ9ڋ-]*oWVS,!!,z9 KޠrBmwa%]YXz"Ah J0ė[`KPi%)̆oةUo" Zb$Bv3f!-f7nsԸ߃/OZ4 ~3?řqݲ3r6ܻ#x ኌ8v#yFݖZJ&k|AA)$&=n~kXCMU^4ϖ/xg4`uj *4BD)*e8Kv (uh$>. X- Uʗ leRyU?7F' .u~pau|=љelК&r@ ۡ-څ?.*̷@(gO2TPapܢ?f7$f,$hjDm}I6M8U2Tx.} Oye$ҰckrZ8{v}%M%Q &O74ٮuoAxP 1 ͚{ Uڠa*6]۴"Mb3S u9]=@7ś@[ь2k(ӲW/i.Z z*ܫ`d(].}]MeSG*Gv3MPAFCQt7ƍx& BStw)i^r{twD,~E41, chsI2Rq_42s| scȈ"VzیMy.`8cC!&yB@£}<VmHW{iN熘l}G<Z#_#D̼o6v¯(AZ;G\S84%kV""Uѣ g眚.?ܙb/ ꇡ.FfƝj ]k`|o$FOq`EbOښ 孠{ |fzWqxZJ,O\rԺLu]vCu!x +Y𓏤`4>F|O%6 ?/q&Ԛ,[f@0N@IHHy>D08gC5Y!o<( xGޖ_s-\kX^wЊ~O0"D;>Ci(S#^(@p`@'¼(Wxt'Vu3%)%Twn,yӊ*o5WrL4HqVuGj` ǁf>u0^ #^_'վX-cKmZN# i[:vbH()9ĩE dmdOw{۱uSiC ^%(s+fƮ"$ 4,P*Ɗʴ}*jWy8{Ze-]MRU:*w]'!%p ?Źl`/px H^ʓmj (x0 L ߲ :#R΍dZv]6aieORoW#|x*FTZʻ{_Ԩ~?XKJ6{twUq<T4JkԤ9z:}|C.wM6Thl~-Tb"&"A;\wh~7wt4Oū .44;]6M Q.fuewM'ǧfݶd͙~.iP.cHM3*.Uş˳ʛY^:jV~dnFŇX!|"K`NtȔi)5y ff}S9*i[^XݭXü- D:hX>5DdJG*%`:I1צVF7/= 6Mor̸3(z^-0BXTc3F\$SRKVK3FO4 ` $i*9^?9r!{Ʀ TevK] 8\V(DQ?I<v (O74N~Eml2ʋѡN._4?[nֵCFLw3J'w-!/U`4|mY`vkcGNt~V#1Ft*?kw3cI[>*>WVU]4)$,FϮsjc]dWx8\NTjZ}TYN2m13[ W͐pqz4qkf䫕F`*7{(2sn<ܼD߬t8:,3jO@]\vu2#$сi* ҆kSa ʆס="H^*tAHc/ϐIM=WMh;hSN<_ @ Ee콍o¦@;& FPgu xM~d+u7ɲl3]2O"́2uS1ƽ>;`gN@`'z|.;9 ^O᱒ 193lddR CqaNI, 20#V]0˥"4+6Ún2D7weŴ,T-w1=䥝u]t⻕"NgBCdH#h_Px菂uLE,GúU؆ḸQ8ZHԶQWOisyB;peyXsă:w}M4λYR$CS6H)G b<7DA"u#un^2尧/b{)`ܬf_E%]kF-8'W"?@ɶ&a&/HI6LI.FKb{X/SOpWE:}Q81zq{&1JS}MƐHb-c']锭?wOĄ9eoq/9OwF3V'V%[ *j&%-$oW調&5HvtF7Ȯ&¦BWt*3w](KkB03=Uuu,/|P'Le硯±ݗ#6@ LM6] "*P+5*qx*\˟}HN?%dahj.wG ҧqvA~gQP:BͨXU;ě?=gXwEM~茋Fl˂*ʟ2U_%zN%u7L]\?>^-4gF/DdEH"pZp6?~svacXG:7asVwY@f2sdPW]ڨ?Gq 8y u $iq_Ir1>?O5ʒq]Q pjt(~umc| V &mnkTUx w6xTpy|soS_͡1w4zs(L3#[|OT1]G4_6JKsbɣ8(9bbHc^o_RIH Fp0"+qw&z qa8{IwR]Cڀ 9Za%2 Dwr哲&hv5~ل/jvɄ][Hʮk2gLϿ^k!#{]>čq`R΀#/ސ1iFnv87 T֮ 5پjULBBlg{-as|Y1$BW,:qgG v]yT%& %Gz]ͧsĸvY 1C&M(aV^ăeRݔ,UBz ?UT,*F-mQ?oMLm7,fYDTT6Mjdwl8莲3=oe:b)Z˪:EOY+] \Z}zqFcLbu>sv]&;~>7RMTN#>̋*LjjBX5q ~+T@>[ڳk˗F$`>mP~}*s1N!L]#76,j6/r5ݝu(Gm(~:;waj^=G_N 't]'(hEՂbdS' )J, Bhl%1a99f7G.OG\e(ڨfD 3 =vE#M}yȩ ,a-)=rACo{ ɍ3i L_$<)ʧRRj,7~ΗMK6\MAfv}|6W. 0XQBg)nz냄0)Zݲx#jC(_am``K*x63 Tu76"Qܞ @aIM}_jʰ^r߼b?Tɷf֬%VSeAla} R d )Ə6DP탫I_2Z>5 V}XAxZa޷}?FШ\7^T U\y#Vn>K~5d)jT 67%j_,aqk(~kpWSY[,`o}mit-YsÝ<]6X\轨Kage s&YGҽpDK4\Ix{Ք[ 1)"C!)T;dcs-EYHĵɼph{>7U> 6G%+dF~iK m YK͂>1-z\S֍SHg$QV~r"chAv&ˁءP'ԾE˾Q:J'3p໘oM%G`BYeOMUto^4 i3pkhgYb_yZDs_,`?*'׀mEc$w;+izM dBar_^jM %̨1=M̤qWO qB1'?>l:bNqdzߢ-ȎYO< hNyҒ鯋',p Tʯb"fNAWZU$Ӈzf\Ao9&:Y;^-1Acvng+c~9Y(R&ΰ(Z?Am\i/!^j"!eO$=0H>`]E B1[%49k,X߻\xS1sb`6hxaIU7#v+A}[tN0Hwl?ͬqzp3EZH}u)l n*ڲViL\GJ+U9u0>+rĐd-W8)]V+ϹwC{%\!#V"/`Jlo6>!8Ac ?iߴGF LwU t8)(=;Vg X7PD30dAhzcl6j_f7L}u&VVߜ fOCxeZCw$+5`I x 66@ d N& HgNZJ y!.5E峯6DDf:|.8ݸ$QfE %*,x BB2'/G$t?>юsmZnV IӗNp5҉r}i!4:wEl\{1|z@sttH$5 OOܱKdvG6P\X_~-1Bjo<ߕ4np}sYŒoM' Meuab(=Y/ 8{LL4R倄TWзTrz ? RĚxqd}fp?{9(gyŗĺ}#TWΰo鯲-3 JCcWn6"Eַ>Ď%zO9At'U ɰ.q{K2sck m`W' pD?:U/4&I/ۏ,7tU|p4y|q>9RnĐg@~^3]x6|mddXɚ]oyo7v`U( Z_x wCk>m\|\{U]*bc[ Ow.AIq_Ƃt2<΂GA1*Y|OĠ#>Da*pB`oX؅ּV4rVQ%$Bo]EJ?_GoKz)`dp:mavhU:oz5BJU\"entIu|<q&I.76ei㹑X C^/tyYf%R jԋ8IS˦][˄G' w՞'K\xL=-E/C1OTȎduLn>7")n`>ݝ":9g$cp5b0UQ5U%߿o,yϠp#b5)'~V:ceh!k*)YO~?>;`|&Tǡa?,&#X_:ɫSUM6vv;H3Vx@3mj$?“ ӶKJ>:xA99诲7*?l<"1)L>B׍ROU]< ѹw=B7!IG][j'Tt}HAx IJF:M#`f\Ek6cVÍzR4d.~A <%?=vsrê0]2P7=Yky`]~)A_HvbO-a/!c'S`yq DRQ֤VS$З t/7(+XmHKNP}V;%.-@B2%Tm%W|nA\NKuâgjKJ!G*&E_N?nQPxsB.ˠT "c=ݮqSf+' l #fS+O_5S:jhKuEڹu.k'}D(|!2a}=Dg t-*+}2' =j̓N__S#}lT-n(4;kXZb; ips`C˿T= &̒2-̴068r*MuZѫ$B*&DJiǦ1cI*6ԢɚZ\wRt]q3gJWn7m5}-5* S!V1Z; S(c6iDifq`tt)hLEң笭{ƒJ 1a왑7{ X0پcd{|fkK(ıhhx zq8BDŽ&Tht`0i|TL9}18=aY$v@l$s Nw999&'if OEPQ+mSlSU߀_5+g'àySn;r׻?-aoNLv"o̪D>AjN
6X-ި`ṫ(H_J(a~\H!>?JR˥=/9},iۑ3`)Mf7IJ 8O`aۆWǞ)!W輽`#MG"B6DPV (rV Tn%* U =_oq\WJgoA ʟbRxJo )<i{G&?qxw(E( 36ڗM6cǃ2_`2`S(٩KZGf_*Aq$&O7^=z4B̛4w-L3p`O ps6JU!讦aKvRܷHh|C^BJ͊X16t# SNI01^fV%ŅT&Ͳl xomb;$E¤$}S_>ώVp/2g%'l{>(Q9c#K/$yyHy"A1s ]3oECMDXIens ј( SRv?p7-A],›ndo|8zl5 D+P–YxCTc81&2)L؊ܘH'Y?vKMo1Z5(Goӻ53C[KUXP]-1f'0s\ܗF+|;*o;m2A;| ;1J@~ɯZ%j8&_EJu(/]J8i~*ɿtN͐ޣsKLΐLh2cUr̽શqxKE>8@_DA ?o6;')LqI!d-jC<#4eN"uB;%rxv d; |s .)8͋?K+@tAK`t"|c 4׋3?f=@Iqt83Tߙ6:?Tܥ,l ,wvca̴Yb=J7'\LOB"( ?8!P JwpV."YL Ŷ@U N 8鿉b_fmE*ݪB VZ5]yO^.r\dD&n֯Mi!" `Rk0 !EKs`I] +)4UAdݴ4H4!ƗKͻŖg4O ]KZ]~VZ@hӮ^풶6tOl ާp .4`MOJ)@B4~OC>Iڒc87\*5v0l:nQ (s﫱AamZ#;~J%_κZ|//W2S]RU'h>ſFOR[;^ih 쿾#4"=Gih+h/V"RkJ)%dӀ)0]kYijb+K+o[|ҎWɘlb[>s:Eٱķ 9#ᦚ4 31|ۯ rх7 l5:4Tn%sNFkYr@@(TKSTR@dɐ&]ۏVzclX\Q6aԑe&90]=z>oAxMkمIk!"Hݒ{$A7k ߢKXQg`G٭*lqHr 㳭ԟx+'THX-\[P_u:xZG,7(d6p%lڂ@US'[_ڊ{x)Ȯ*J7>h=!+|)Qe+F7vL-vzLh</ETBc+w,n;{Ҁ悩 fkR,~cAYPs %z-;އj:YR&F߯pc6V5#msz~).KP 7afM8ԜatU/װW゚-8A%l@4GDM 7m$c"-E[xoúAh8IB̞0VpM8N?OrZ o(iJ"zϭ ,q|iK4i,,ڵ^Um~ʓ5b͇Tv됢 ǘ%QmKwiNns~ 3jȿc633oX=T;P|wG+b/>ᐩڅ6?F,Λ0LJ(ސ*NZmJhu`Ą+e¤mG:;aWzhLtދ'=%%Ő>{!uQj Ns_t@O3:;᫝(dOaDy[~=Qf eR*#2B5 A3*:Ruɿ(+7))K{^(蓁"&]Fxϳ䤚EY-of?W!BuXC唙G,5gf'K=Y?!~S9,U=5"H,aWLh~FkeGtB;Al Lyz?~̆" ^ 43]pR dd) /. f9A s-|)o<%靳^&U r43<𤴁:DB\ ,S}x` w wFoo/BRh_bܰFZfIt]$hZsPf@Np9X8讇m!|d^VbLtweV J_v8j94{0؈01?"/&:rVV._: o=dTgV%Zv!ΐoѶ4o]+`IEO Oes3I[N(]ncZ[q""6$;RBX%EoKC0釆bAarnK gJl++>tdN4Ij_؂EC'>"H dUϿ=b-,bJ:B4vo?1>B!DC*@B(YH~&;-9}wF%BEj}x! -FUmS>FAt7~hB4r|icsq[m ^>[X3 &p_kE(`',vzr3d;џ@bP>B~g09v%PToS5p3@w_ k?:\ V/ྔoz}s뺮O߉+;b#}PpX3:Ws`HZOq5'&!XYrus(+PJpLA{W. -c;?$6;wP/[A0 %*ÀFi1keqo$߰Ag£C>^=q6_rEN͗;NIT5҅ {քS՜ĠsD:Imq~ fsȞ3T⇔i%)ק Q+ȎO꠵#+= (zi v~f-ovʃ_-\ݑK u%(6ijhTfAl~nЕ~³!YTr eRnO!'vIu$Ko:?iAߚKrQ%ݡa<#peė?;W$gW#;1 rN`]NC~^o-4P `UU *x2RlkoU^7'g|m)2h pP՝Vi)d y<6qJ6& mm@\oO7a=uqvQp)̍{QGƟv_@۲gws 6KLwҍEx0/F7r#Rq9˶vX4#dWH&4/ Qwd_8hRk mri>~ T.bY gn¹9@[q< )ycՃv9+/V}.|okZh 0%+%Ŋ[ouwZ.դw&=XS8|7p&2f$X@sjWf=/z‚z!K?ֳS5\s|EtG#̢i8.@ӳiqgo v]1]ר(B4N3`&Q2%)z9,܉ Ky}ғZ.e8\뻌t,,ޚa*J&V^N.l'QOu)QZiDrԭ [q3 |.+oVVQiF9<'.}+X/?d8-r{Sg3N:L47 _s$Ѱ8g?77csἧyU-ڝ]xw՞x5@[V*3Jbr}FY]szAj0B [t Ww_? 7$(])8$d`+}eh8ρwZ>$-ƪ P.K;+zLj{V6CcxhlG4jyc%'CA?Ĺ9޾EJ}_ ob3ܧ\ ӱ $W*]/e%V%(sԅWw G#9_fe7Hw)wU{x<#=YVvCc{Tܙ/, !h_Ym%93G>)ӻ"'M[tmU-oH̷=G`ͬL*osmHǹRLN;L3:]/8ŒJfkQ-0aWc*F_h=vC](%oiUǪ8<ٖgb[x.UX7 / 1UBRLt3p{w$(0c7[{1RP;&D'zV5Ћ^@'YMI*lץIJ[f/K1\ğ(˒'Dt{D݋lUGXQJL0Z74CX>RrϹY%ayjKmxh(= fb Ns4zW/7 2lڞm57,a9s)5}t{K_/€t񞕊ƯsF]|"a;M+ ׉;/5#6;ܩx\g>'d*pV8lq6q Ϙ-˔Y2 :wZ&ZZffe=>ucy1װLOGNZk#Lx_^U22d$ w[Y'> /*ۄJ9@ByXkd,p2lFnqwz5X|͞BqS_yMzoL8#4,f +ۄ.,Z!wG}hN\AXIԄoA3B~$EHO+U4 !z)^*enijiF@p~#F>VmPlmu'~H;0uJgEuvBi,~ly8M,`ɍ},ȿ*4Vo4x9xkȨUkiX>}X);ڻ% gorJ(Yv'TMm> Pa_ 9>~%qY7>:ʧn>2h}Yڔ[Ycчr\? gt`?k+N%frw8}c>H=~# 8?N~)972{HAR~X_ٓp'[Ta-#vg! v" MӝGGpTN}o-wג.i{$5TڻWSB;7_}yY>hohbR WTZ%N[l?;1{c`Ex7sv/d{m:o2# ab}Dߢ?q|˪JnU9\a)W]}Aօ)Af-YDQop<@`J6B1-t IIWK#@laƭn֬- z{Hk6 yGFY$xո edG؁lBUmjԸr["q 8s;fKE @(<zڽ loݕωE$u}qNyVbWU{W6\cފ/!O K/ƋlNƁlk=TXT\]Mo#B0w5`ۈfKDPOo^%[4H3o0sj%l]ߙw:.ƠX;XVW*"Y(ɾ;lBg-W.t¦Ύ  hTK"GYj={Wm( ǡLxӆ1̈́_X>)vo5[n ̖Yf5-:-M_+K2}8V?ZCty9f)|&Kd*tܚЕ I}PF07s[fm&Փ7t O"= PdkeK_䶏6WIlE_Q<U~!|K9G;&?P¹K@ 3FJ`s<NYy-Vr'W4mw|J5^B'c`Z?Ct~|\TU"ӪC(fJݙ]Tȓ *iOJۊaBUi^ٱ@zAu |5 W (r 0uM +}5Fk1$jE7pYWQr7~'XYEbck`-ΰ[tZ",& *˥xgVy/ȅ9[&JӤ0Yzo-]@>Kn )Ŭ#o;tլx&];SScrMк RDUvMɪ-JEpʧߺoBa[!YC%\w[]1 ⦅dϜѱnx?j{65$, ^fjl:\ͥa6>_4)lbBl\tϴC>NooUw[l8뀛Lܫe0r\ \ ^S9H[ޗfOF):"722+bsuׇ@B2@U3C9 f?Xu[xZrfYn<15 NiK'Ew(U!p78!ꥥO-o9^!Wqs*@@<''7, )KQ(N~iTA7CzRP&n$\7dwⷜY:P1eNImυ̃y/,|:aPWr9mSV`Iò'0&VQ "CBaeDQ+Gu"ɛ2I^3iCMtvF0f;840l0H81]ɩ~ -r%]=L]XVuq3Z+[K {Zї.Gk5_h Yhdԟsō.O=ܿʊE\Uab|ra=yv|iO{GxQyF/Lx"Dq[wC>D3y?Le?=&4p][16Nq"d)ޏZˁC;dJfX#o;֜5a?g~kK6Oxxi7? 8,!AxФ g24hpHs%#72$geCK#u7cWQq:4 rn֥.teJnc ko&+{eC%3J.R{2 dT9QfKrԲQ.\{91/>ɓCaݫ*FMX%fF# xy,lCNfF㊾d['lYZTJ( .P4e[)L1󙍪plMM4.# `RegCxoxtkHZ4 vk< tROoVqs8-Ȳ}QI8fDcvn>齐FLDKtɦ7lČCg ;2(uKi *PTB"M$@F=Gm@cl=01~XI=lNfkjx*o;Dy~zyO_fakn]vMuj;Q}̉=^cR J Ap2`amNe$O(lCOګ 9: $xϱDoF>335K嬉CpATP&N2:N/L}6 o//mǟxF67Ja8izͣ^ \ o}#)`S#}I {$tWmx#)9̜ erN o9Y-6~&T͐Ue3FeC ]4Vn~$h uQ_e >{6(?XZ85Gvύp5:LV0]ulT HcfDCu{T`xLhoQ&ÌeGK8,# mg΃ixn}՜~I8QC[w޳ H|)Eqt+[_ ykdmv2u}Eȩ7P)[pmll/0ug5l܆3L2X~xc)Ol޽'mrQ f\?8'I @Ee޶ iS-;6wi,@&QLF̖WzhʥS$ YzЇPytP{R΁j3t!Ȋ" :rowndfUA>ftoGAA:_mx좼[;YZ! |2G!.[.9ҞWF?=+\ˀH/j/kQ.7i*j1{6ݡYH)!4XVo&fV5ZFYGq/]pܤvmClXz< %MA{A*pFg/*,ޝz? LRa|MNSF7l񿊁gKC!`0r5NXKFURgA<1dO ~iLX I"8鶆cu$F`UACC7I4%BJkm_Au@Ök?p<[竞BEs_`ػn4 xiN΄2􈞔 ~wJRK3qpQeL:aYL\d,^U|#0:}N^HRťؠ!{|O_c< qU>):SA#iWyOy=R-.SAy sٗ,U>`t28 ɮ ilȱvsjZһdlԣQZ3>5ޛ.މl1=KYeKQ󝏫rUFkÝxc\u]X]l\k,* 6;VA7(hXl >|d;a=բbkmD)I{1TnzʤJ=Y2E]4r@-1z|cm4 L[w*t"iͬ\x$po֬(]Cnj^$! EYVun,rpDDlI01 i *OpxVg.KcFADۃ_>gb*9Ey ȫPuuDL&t,\,/oi µP3"h?yaE+R3 l* p!r_DD .6 ^Ea+heZ5 X wv۞afeYӔ*|fmr}t©%H[Ò[Tݴ"fue]#r#! "e[tb `HVta!=/fxdGGτ9U s GVk̭Nx+vwx6^XL%].h(oadɽ ^ɾ=H%!ghIeh:$} T'C b-Ʊ=R#*hG]I%t $k8YKsMz"Q~5]ͫ|~كq"0󾸛Ekit8н 6idq="ZIHжS=(82"ܴ yQ CS%fVק`!tk8mD[{`o(N)DMy^MYQT;M\Ch}Q/SQ"շg@IbS1ۀa1͢ OwcZAjrhѝ!n_{W9 XU(C* Q@>_4 `;)Pou x3 o˜@B1|7;lbl&3`'8s|+k("كJI 0ϋNFon~Wec 'Jb՗o2R“L .9 bI.D*߅AeFL^Zy()!om=Gp 4(>JuezLO|0s cO[%EmEc%`geC}<ŽW.FY&D`}0/Ƒn>ea.#nFV9UHj~e!id9۶FDXeNU~Ja &JxbaB6Re0@lR4[A/ 2; tCIRQ-Nб?YM.'%.ƛkSlx]N5FT?]&4%Ŭt:w/^^^?L~%*r 0`kB~ާ_ "LL vLM_B@ b^GβLAAm E]۝nHԯhBZ칋k1( !=c26˺|'2U7%Kw˖|WG2^ͨSJ%IQVUM#sra'8[331<Y}]:ijB(djGh[Ӝ!އ \Vs 偢1qεDGz)aL6ge3R[z)ߢY}$ՑPd/24q I,S' Tco";9U v1qd It:jrʮe/ʉ08*zk/f3*q1<2TvRCThV,h^Tw t ՗#'%N\R%bP zʮcSLX D'hߤdцBIq% }WV\&GXMDCiKvבT1;|nuNXW܂O#e:螹t慆xu-C:#]8^`_Tu֭K#cTJkLE١_3<߅ig Ifu`Qf/t?Q`=BHj*@,Q4 {%4IJ[;b$RJDȧi3e-{@}MҩB4ȧmtbM ]?VBmFdvchr qG&Hʰ^-IhKbk6($bNgEF ByqW$2@+,{Y(OoiPE%X oOQFI:;Hzs`*9O CP(.wh,8aӤ(u5ZڀS+%+eH"RJ%5jF* l]hea9-+*%.n~SΖFsyu"G)pdn, "2zfHͺkkBqvc@:T5.N?ӸQ5]Ym"PO¸7n?q.ÇP!F-2 MlWGtfLK)>vɅ 8cPzWdJfj"Y`aj?ᾠO,J1PhTI[G3\%Nxlq>I\bq1 ht^ EC!Bb\X[cHyiG ޘ΄U ׬zGL}IPYii#kvd1e*ԤқG354mwJ]x[M~m_J+ӤAC$J޷ftrHR0=_Aځ%Sx G {M vETW'(6HP餎N'j 7,K_MrB-ЌMdK \O{@D9`>1ihW#n(V>O@\FO$VWjw5,z?ME:oBm#(SJPnG)GTK+fgغr8j@Y/ vތzj/*N65A >){烱#"\pu*{. Ndӧe}?W| eo&%sT7JQA /x==]eu@$O %ۍyn^}[uAc*|B騙( 8P{aϿR?)ܘzgX9]%RvvWJ76B*aʶVǟKz)أna $ݽ)ArFIm>eΛ; ו3lGzhe)&[$ope㔎2PBpRW(? rr.'tď.k!$v9 E1%uj&DR~nDDĶr$w2-o2vLدm(2V%1ac\;R{-XocZ&'WJ#3fUPGYA,ū h`T9:غ9TQpwܟ S<T 2#)A`Q4v0רgtj"a/qGzI E o8p'@Eюxl *l)J=KktV͔< kF>RIHgF8)@hCiJz NOٟ ?TM4;g|E./jf`b$zȎyLys-s +B͜ }6DxQbsLhF$Lk=5e/tv]ԩ9K:wo aw>=kRbPբ݃dznZ~//X VJ$OίKt\hB3UaWJk&&Tz1\`.P(.%v͹ f{['yBgc{!}?s>눂.wNv N" *e1oK:mj$˂.<䵋4 ^_HPgX?t6vbDL Ӽ8o}B}&PvE39^'}-'L"he^h)H h|eEԷ3Mg!E,[`$!_2<Ws8Z"0{*eioJa kv4JAYxD`{$64&vIE:!ydlSŤ|gG̑Rw^\1'`Z"QotyΉ Iʁw ZP0 $uM{EU UkO*x(i7篎 D&eMCFgǻ6|MO¿<1S@q.-e^'&^?ȅ"Tl]H ]{Pm˫;3'ɠp}.HI&5RFp L=:x:"C2;Z[?.+N:ȓvUVO9$ϕ5a]cn!Gt >mۓo=i.= mT9 ; t>đ9k直}.c6 V4W56KhGp/@\&eEt{0$Fe"M,f\:.][|''@޻nN˛6-O%dY}l%ҏU5rL#ƞ8ɷnhIG{)D\WȥE!X*p򥱌.(։o F#D/gX6 tc by0F[H-}AQލ}S3h '͹)G6%M{0GP*`+bE u0[y@}A _註; D, "Z~ )Z\[E=l( 36zґf,T̓d>U/HOn ÎP ^,J9ơFeQTYe4Jõ d/ugZ2^?+kZvoSp=%? 2 Bi? 쐹5QC5`\D| stH53CzOVPܼ}z6KD'fU]V%g!=Wġ;k&=y/׿-x%_Q=DK3M Ei_)uH ۼ \m荒oAf5ټtq4]H-{aF# 7`=:zKa=VSPM4q;WD$FYIDxsؿ̷v&p#yfTqw32}s,oQ/ tvXCPR\s ,7Z4$\ AMMLKKQv~(cL-ScjaUHT1ٲ k/B!B$L1‰U]oys#~'fK6Vf 1gj|zPMt8m qAgh_}/?F/r=9'{} {&$M-W$$p<,UhL2WoWv ) -qI'TCK{ ew(OoK/_bcXb~F( 7]V=+.:Q&è{+̏3wR"7=ʌ@QVCyV''g#9>Ut_<*U;X4w:y1F 1qSXJ vH` Z2Z&iq3c2vbaoT$TA5 d1bIzq pH %eMV ѤԸI%bډ9 ]ɑRtpBiN.><dqڱ `!sӭ%vsdg#ݑG% zTb(2-͗ k-TNs4EYy 9s 1JsjQ뉁APPHf4QgH"#˗PAN$KHʫ8h[~^%b&p^,^IzO~k۳Ϳ?t:BEVi!g4=W֩Q➕? e@Pt\iݔ}5uPHWܠ$V(uUBFgX>Pv1hb5ElVhI~3&:v2!>WoO](%-'Cΐ.X|7 iEu$.:,9%@:! ~oa~M,T/d|)4&Ԇ[{Vv,`5,bzNRP ߊ 30 @VwDW> ]Rxñ #Ag$8KҽHW-kQ;KT\$0E|'h>)=Ruj%1'IəC^s0F{VG]pxf؟oE~ӫY+e`5X#a'}ʼny%3^8@vĩ?k$ม}DNG/hd U0Se,HK5qExTp^(P񟼰8&a#%l6t-OTN`o}SJs-;r@BN8yuqf>< 87w>l#jzLŪh5~;ׄ줙67U<|]-j3ndVE+|(p=/ķvcq׎FIs3]40iFÉbb_RkFZZوI\Ҏ1'bum? h~EvzR”#s{0g"_5UBRmq%n7sz7Pɶ3Spn<>e`75 1wZ?'vI|% .=[;C|x38`<ݑzn&=gm?pep-^m!&9=2mKk,zQYڧ`qٵm" w nq଒m#mTr6HyڥFY?0HyO +<`O`+=-ܿ ";>&SkQ7 Sâ$?qyvlpzru2>($O(T*~0N)"#:zT,zRb_H6W:TD\tv˶pvbo᧵A94V@#"{'w <7zpv|ϸW;E}mJm{8+4V,Y%+Gp!SLV}Vϧid/8T )-w(-C់\bGH爡ԾS_0do^իsˎ\._Eep}JWmPqmVN+~Xk=֞ijD!FFt!VsTA[1>g',Ow#TfaCw܀I%w*Yuu =݈T+-&ys[|n=B!@~q"oLf_vd2\|<X#=)!.Vn #'|{(Jzۺί%SKJP(A#A `F .Am~]{K$!0ȚhbAC!||O^h o 6٬f`P4)OIy/!H.5ޡAγ|DxB]}~5 U<)w/-z?ۖO1EZ+Qv0d"9^}܈|F_~?LKU {u]WAx/PL DVFa6&O%Wjȅ就u%X1 i2Lٵ|7S|xLݎ[s<7\FpZ)¢ @`MҶH?[#dlSR )gp˖&lQc|i ͝YwnGi;60rPD!p.¡}4',)óSou'"mM,Oȳ}gl=Sf&ONcBgՏ$N_*']L ^hld)Fv7rc[Vbv_Z@*t?;`[ IaIT Ɛ4k`x޵:9P9lcHw e羡f=O ofVVXqb*x% ?d?VIS'8غn-d]d0Űж΃QyӯTR%s36B!8\9ѵdzwmWg (2G\ֿq3D;3냳G&@ Z}VSO4'v\h K-ᬮPu2&G4<%'DM ]*t x?߁jZͷH8ٜ%YrX6 A,nEE1B*8.!LuSZةc(Ldh}GK 9OV%UGxs:i q-rSLOR"0oi6{n&!HvR4E9727}k8pGHXT@w`<#D.mەؽN;IRB˛ZnC}m6U{YY~hdžsW2rl :ú]<юV ؜^yS{ 2 96ߩ픔z_zDjcl@i2i?L DWيV3 Zc׸a^s*͞4͠y A&CUu˻9Z^:??wgA C~&Z%BWxe ͭνl66rx[>%R#u4EAhH˾r1KΔ{XF5M~X'*ȶ(~2?h-4v$حwA"% laS%z+Q);wb‘gғz+>]P/x|YNX?[eY?LpT1^cn&YFUU2@J&p2ϵ@CU%11:ֈ-~Ɏ;k UƐ@h\_xu6GB,[ЕXj?4oi3c Tm:9̱8jLbe`xƮG)o'q~jWړ~ [c"ζZ_BrK՜销 ,GRJ+Ԓ(%V^R" U{!du^i T hs4FJQQ/7,.۱*K`w~SHGOh1 \lDŖoiM*nW5PI9xu hj&_nM)_Ҧ#pEk>h4{͂a"!%ۘFJ(EŴ8Ic 'hϖ9_&P|=RCu^M@Z-T{1g/,4Hߪ`@[2u뾧5OQ++[893_Z]s@E͠諻8?lPfd30#!V٘^?D GY2eo[i鍸N,~Y_~sM#I6*Ę&_ 0F-dldO@YR7gNC?կp9ߕ+l$1fVxC0[RRaiPT)sZj`sU^CT9UݬUi,4zcd ڡ)x\J w.wJ%[*`k8ѝW'DO>-a`;8:7Jd5&Ql>᷑0P.)灺 /[9ȶyP74=d.[7RQb8 ٱHmڎ#U@wiAlu4[>稹=?#<d4]tzNYaWĈ{*txfDwb= X0C{QTd?H(J!)U2*s}:Ú7!2묳*6ާHIβ"k=CAv.Po-)O {}8k^&QzeT}cҕ,yYƀPl"Lk~:DxԈ;tbm8w޻7j3XLH4;κjz+dh/<@QVd64yIū@iKO"H GzFyU1]1btYyUyt ^?-gtjҔ,ąf.r U|Xv"s^EkӺ2Hߛ ~^}b?'_^a#'Οe| D|ΞG5DD>TwiI/en'e䠡ك*=hZo|\"f 8#D$:&r>mlF/}:\̒< Kzʎ0fC)4 :f뙦5Z2`w-&:~4;d3w>gP~1R V$)'ǡ|v>'H`{.,F\QԪp.#fS 't-mg;,6[;")٦M5˽ۚ0jg"'#Q$oBQ/# l ]\_ܕz;i?&W okr qc#n_V{R" )7J@`A$;f(vG"p/H4G=k ΂ mߧ"0K7J*ž~40 gM9vcFz"JE). F yeIu)%iC+ Ie`?uEڪH"nB/D#:@ŻplzI|$at)h* B5A MS $!V-P6H'#>'HҿQcɞV~C zTѯKhcXֹ;FES"R=Uش\'܆e?CtC "mF'eWL=kַoOd'I=;d\$}ׇ; 5Jdץa[Z? l Eߟۏ[R2bd0Àn7c*WɑsE*BwT7Xj-ቩeQKsn_ٽŌVBO) ~kbya೴> ;ADCa=M' ij륛TfL#<-YNՁ8 q0`7;ޣ1X<{vs3yU)=?YU(Or-Gy.9IN0 un'`-H ZU3Qj(T.|Z=ɿ­}-GZJ_{ qQ.ء0fyy "ؔUêNJ[UlΣ+s{2#4(Bw2Z޵x?Hd-[\x*wônU Ш *˟vs,$'WsmҬ,^6BCgNsb"B[=)?*`' [e-QaxiP4 .;J}3[wA fEs=d[;Nz:fUc^ã`hWC?3TrA$hkQ9OZ_- aҠ;ӔTfmY3;4^ ͏mWHUsxv+BBﱛ[nifG6O'LCn% c5 #^DUWF]R^'2s< Bڌ\raTyk'6h0Sѓb\"jzʶATwd?܏tyΘC~4*yZzgo_HJ2ZՒjDyj1vԄ~k8?rV֜Ob*7/2tR|( 3 uPdy*嘲,%co $qr|fXk!C#qsM;; \ Ҁ0(?,m귶*>4shk.{Q,cbK<]7cgy_-Kd} SJ|PWR eq)hih=LG~ME"S9. $ۅ"GQ2VJxwl7t D+hs&=y @{VY={BdA6'E\dkClx뎉fI Yq^=e2MS:u(/`݆ "Gv͌_JyqWln A{@I<:Vxt1`#uxrwvFez#e!\vRFe[]`:*i< )noN52xec5^Flg^*OZ㤝BuqSVD"V"OS욡@2@!l6Z{I MR9{C.Y~ h7iM0 qy%7}Ԫ8bzwY2Px 18S`5o /y`7\WDl@m"IA)<)Jk$@.Ǩ疳 fp?INiMbh.DpZsTpzZ'ss]_'S'O sj}1!~FJxhuJ M51/.B\GE;8aRM"r+2aD= UcʎN,94ńִٖN,] jʮsz}xdpWjb"̦,= xzႧI={z#BG 6 8hw%#0{!0, }42͕Da Y?F؍&K"5`1'euf%0WgMAn"; O9IedA=HEQ jÿ"6Z74ivMD?H[p#rbثtk=X7k4-m RyM P Th\h:ѺT_qM>1J"2 vvC(VM8vO9 bz "\hd޿]8++,@]4'i ! *ᗬ` 41w't&i*Y."Cz2wi#lRފecevlDî] &.#3UahIt%0E'eޱ2'hNxno"GD07=lȫ)a< <좞m $whz~^˴RSn%EPm@M^綜C3Zr_viEL)  z=](?* \VU,|lrO ?MHx& )L5&H=-6L! D'ο+%z&f#{ % sXZMՑ^ )Kxi\z}&F21{,&VuqDvBM v6gOX|7F\H56nQ%h8z]32ec3Z3TWij@ 䖧 yYgDdEeI5hrkhܔL*1:{ubTRqM;#R5uƋ4f2Ex@*F!IMi~:~`r_j9/^%X̙?ofbL33ڡeꆨn]ίWXz"*&C}01q~ =nEcٻIO;ni)M_ :}sLNV??"Fbj)VhO`Wݪqmb=p>wcOBfI k#P [ՅEs3`;N5n{C5wj6o?\x)|) =-B ցCci /{(+\hNTAκ"K_ 2{VtVV3*IcLS@E0LQ #R(GWvE4LD&T Vu%yc :A\67%*:>N Tu+j,$Acr֘E!sQh-o_&h`PP5mdrGճZNIIi?5ܴGMŢS)\>4]iI"W-4;摁{-HEkTIoM6)a-*B}%ݎ{,5cef_y 3ʘڥw1vBĘ!>̫5CҬ@lXjE=Uft+n%$?|soCi*+^fVµz9f*M20;:`-1[w=tRt`%0}2Hr\ﻶγZSq&}L5x pluAq{56ZbDY$2kE|ɂڶnXq W Hˉ䱗&vP,z فC'1J~B+z#2g%=q$C+Z}# 6r$RM%*xjEC-Z3I7}VPv7Mҥ-^Zoi!GtKr< z_t,)!96xCfd:VH8sO&kJF->Wm'fvp(Tb fIG ^ ߰:E?YGrP;Y g^"yKna数O1XBtHv;3unܐ:lvbR?U2.]\S?n`1 )b{ ׶\_NY4)V$s>*${zLrDxӟƮ]T+a+Ot#d˱j }Ic(PūNMN4cd-KA,ԯ2gZu ]V*ۙ>bs(ݧA^BTf9I]XM3cd"Ňm} m-+מdX)JAQ /A%F}{[|x=~2G7ZgcWAqmNl=/e/4M~wz*'2ޡhZ?gy>᳊8xGWF^YtM wl~|ȂkXh=F0 +/ 5d> /DI0RCԓ!h(0V|X< ǀ*Û}O7ו̙m1㰯XguLҧv" oGF[qyͷj\[z}n L@k8n˕{|X[IC^ZD ƾJ "fƶ`=gE|)ѿY}R"9yO͌AcF;b39h&kc"W\vŸ [EX(p6[litʲ"H}s]8*~F5j}4uˁ9L~Xt> $)9 c:[)~*SZ^f[s ':מ޾Vo=JeKf w(X̚t3BMgY6ez6˥ָ`:lr;}*t5.=y¦y݈@nD% $.+aH34 3Hs\;W9q1V.([yF_/5;k؍jŨ )pW 󱐇z,YHr7'#thqh䉶iIs8%gp(6V.e[_:lU)t/⯌椏gyo& Px/8M;A[ xRyuhJ*(!VpH% aDm//}hgr39S^:4D:UOw?֟7ri55t{MuܘX.:WoBODgܨG *!z+og3*s جBЩyEZ$Ŧ.!|^V8^Y Nێ%ɟ_i<_˩-AfhvՙOYDs$̰3άq KpxKq# 1jNZ_<"˓w3Hl{w扛~AEXn)KXִ'h.PUDlgʊ #b=9cuXz5~&ﻑµg%ݵμzh/M803Uep<va!=XbA_aκD`ZDk=^Z~z>^Q-_UsXF.%.a| 8HVͧ', ]C+w@Ȥ3 Nfi $#?Oё"Y}7}"oӫPb6zHNh4F2Ԝnvtx *\ڑ1]Q oӄ3r +3-bcZK6_@B@%=*=W^Dm:қsߨczHxAQ7[I"\FZ'">nSG`&D}t/䊛1Xl&H tD[(GQP_?6F- 5;p]##Eqy4~)qsYP'F*'eFX'{Juwp5iQrbXd*~جč8)!5Q"Rgk+VGq 3}*H^B9Ҭ/H5`fI/SV,-!\h))oX vOi96".'3QQ}%U3wɖZ*Cz  3B76G$4#)OU:Z"iuj/*_Myk=[,,:#7a^>|&kSV^󈁦J) ܿC>摁d`\FeNRT(9q {=մݰ@R ?YQ^w7\7v@)Nfbvs}dd ~w- ]H"p֐Ne;3Mw!/>sZ~tRcDUG ٱdΆ0iXE:]˜Al@0sWEFEx v?&9?1= c6k& / \uexB Ȅ{ijnt24ISAYiο\wVE$abh;V=VL eR1_#@s([/ƌgM"hRɇd"~:BZ#,a>oX(!fl(f Ρ}weE*Mx̽)mW"HB6uhGSBU_?Y7L.>)QFb|**g-Rz E>660;j;iV\V6,+ Zd R`LFF44ŭѾw/c85 \3W;7i[q_'OI/{Tt4b!"!Trf@G5>if<[7?'3/Ɓnn5'ޑh"$Nve=$(}P;aMφ;MsBԥg6Ѫ*>V,|cTK~BgpKᓹtDG/D|X2| |hVC:B' d;7$J7j_Du$+v5Uj''Z|:G2aO9VzJMuzdpwİJ(T pyH92Kk;fV4 WT~wt<&L J&ߞO l!۲R5l7y[} i/,T=ᝒNQ^!mСa;w $bU퍁:t2%(}!h=`?71D >w#Lp NlA"dYM':15q#kq#m3*͗(֭A1X{YГQEŋ χK:m8m>wb:QԛȞj_ )1$MN'.m?ppN`]RX-Yx]ֶt[|=PkZMڙZ~ޙj~^#9Mf$¸FTMr'j 4!Aj}R6f? ˪o ĴSrBHahUԼK;+NÞg){uiH> P|>7%wrZSb q8;M $0.jJpןR)[kC6TՏes=R99 |`L_>m7X*q{}H&wLӊdĖ_ P?ĉ&vմ o|l(;O!q"#qK4(hԘsn0S`Н bG]b4lE:ɟ9,C%H|I,PcSON2&Y6m5_h|E1z m + Yss.KO^1,d?"Z4۹Ǣ>>RW ͺ$ */ V׭)5}R:(<5Zy]=i@Ѕ/㵤?wOe*{)kЦIn 5nQvoZ΋ӱ_J_)&|14pt!$-**;,v`B4QPsrrޠ"l( iPmS lt}qcQA5PH L'goXOb`mOEB9xCF ^[zdncgLߠt9i" 6fUDC,Pcso[ Ӌ!qY @SWk$}6L~_"{d4@Mxg)s8?Ǫ*ޚ=Gf۩?d M)a|"_Sy_Ļ*jU\ (ۅsN{%S(O#T$H>_af|\ƴ0az]؛!%(E4L %L@0,;~W@,>;hGA@6棲֬VuԗGB{OaEXc'39ns( /i˗YE,{d_Kk($k k!*gQ* nN@c vsZ? i0p[ :^@" ЧpCf |PW1Qmg0;@, \coZ:'{VzJ(:v.3s?%c=(s0[&4߭ @PǪ#WΦxbZU9 ,әl-luFD8:0hO.29ct%BK?݃K:HPfo/{sJ DL_'7{o4B}]9GP9/\C|EqV4 "UNu[,auqb`P+DSCsǐ ->y(Rhd#?S}UXRc$NWyjn*y͵SJ4Z0UZ"ű>t'r`Y-"Bt"w=\PAJbuv'v5,,pD KRopzPEXh3:L V,"m[v5ryd_)LY?BCxh:$W1nlDaL]-)SݗiK@b:}q>@ZBn-G&7 9KecW9'rRMW " luaXQPV5ϸ~OC,N~6ps 52Raie_8%&`(@Whqݛ svmy! >E;6MyZ4xjj)x2/d3zq(ø>Yj2 b_ lFxxsh8"U Q%TȾeYy!#}Zת.3  qC=g\}1^hv*ArX1|?p7%n:U v8է1.aN6[#Er[W&8{0;yA$(@:Gr $ F9 4LrOȧ"41Q #Z1ol)Of!%Nbq1Z_VGh[f74mRWwQzijk 6Gܫu0:|%PKqC`4Luqu0rk9^rW M 3^Ԁdžrm;?^nx&41j"ktb4[uQfqPT. +wӸ;F6/֒TZ5޸$A,v//`3a:sua;6šMX _ * KJN^/8lrT:T*5ILqpv\ j!p!3F5l٨LʟLLYU^cWRU3nmd4Ȃ}\df2f Lu򬘮mp00 O'pMWHXAj0CNiڪʣC}>)h?_0 yRцgYן/&ތj1F V!MFW3k#Kv^q HFD+fr28B@HiVt>%M#u @*--A *O "MhuP`-M`'-sn[j'z 33՟AcdPـ7^NR:)sHǴe?^06n%GX=M x,w1Uu+~ˆ7{Μ̦C*뉀n}HHij{,=뿦/6űig)g 8uG f|a rQ q(5|ͣTB8/2`*` M[_=hGtMhз=fT9 .coyk`jDb}]=ڕW95._q>l)k2W/W֝q> _v~\ j =1/XxX;ְ:]>['ɓԿRxNß mONI3 % NIRDޜ4;@x<)Pn E1F\0L~d`~,VTP'P[d@f_Rd‹2,yE.ttȄa4IV25_kw3d{n]BYkqjY>rjV"'o>H^)敞 nbsG↧rqqwI*ep:R@fH|퀵 l^WhJ-M^BW ,{{FB }LfҞ;<]o>'PzG A)~<o_rpc$E˿2)ص#wt:!$VUTG@ z]$E2}؃xNxƒe1́ p**}!Zj ѩQ9 ʲq#'!5@5B q PmX7ږ(w/az@H:fi tۣ8)OoXaPޓ[Z؀j *t"dK"~^7'Ą5Jm($|ig#s/HUzrE(ػG:#-)6H`nry 7(gNc9QKhzd8r*c~rq~zwۋ(eAaGr<#O.Y"0R+w<ȁD $&סUи~ajexTs0ٚ]-r4BF~VϪ 7jh]66hzOk{au\l:ߧ胖R>.#5 a)SKhA) /{qqR Vq.P#5 аϥϝyOù bKQ8C\ W85ۃB)'lf!Hf}^;K(4Zǩ''-:>aXؼɃ{\?00|r[ jv@ 6ҿ?z1L͇{ZYɏn^hDi:zhdZzAkg LԐ kj6eP]غgL/x Ϟ41=M69!U'b7$;Xr&W_sm l9jZ Ѩl~]N$|L.S@u?]1w|i* NoD5/S"mb`s @QдP!Fq+4Taf8heNG&6rmɷQ1A8*>-qNaR+½C Bޟ5/ B'I*Lkگz՘Sz9KV/V(6I7 r^Ӯ}8RtozJϫKyMhys‚Y8_  R>x̎JqPu4ͱS{[shm﫬j? zpw_]L/g!7R!fuaaL6㠰FX20J[|@盁GuO0/톫]a .l̲= P ,/&y }#58b2nv SE& E  G82KEKi> xyMLRO!pcs ]S(F2H4aNx9S$%5VP'JĔVaLn~6KP 娻p`;̃NW+U1NiW. yTw}ǃ tKxVY)[6PnHMD=)/ϱz2Qf?aŷSDv'״!SU|9Ե>܇:vwCt۫ +q^r}7BIz-5t*Hr5ARe趴K_2><'ϭx[IΣnree6^Qwe˧؆r1)O^޽ X%24 ;)KArWWS8zSh1 Wij-^w{쪿Eodd$T{e cU%wRVgT~`nj7t%]2-(?P^8i=p{hV !qҤgS1*ו8*e`W:tΘtzŧ:V u e`ci*.IJ>KrO鬽3Yև9 '['޾X%v&.S 7 G][1zBs1s rqlJ.R۟b"RXHfuEd9<\iy k[ܣ} ~|< ТaCQ -JG/ۑ xHITR5Ks.37^<sPRIqj揅8J'cc.ʱ'D/[{̬gi+ڭND@IugSֽl}Vc~QxjI\F<! ՐX-HPnB?3C>]NeXLb[5Tc w^oqtal.eҗUG%ai6w@qqcyP2EETعްqNw%~r8FF#(J>)UznkQ@ZM4ЩF7<#Ӈ=JےډȌuHlŃ;V/u^Yu4 A!\+5 Ҍ~_m C'3at 폥Nayxl8ͼ}սhfUV0pǸ%@j #<}f7Ң̽O |9FQh'{$ 3np lƂ2w ;g3c̓kd>79*GCR"('X *FXMg Kۇ 9~qaw+(_E=R5ܡjV鱘ab }Zy\NUC J9ޭ|Twh@TJI vMZxɁC(ͳG;<% h|zrP(P(CB"/ёaʖtu(xXaCi%eMja0xo7Uܱ{b,{P <{zհfG }i?XJ&U„dVVYn,낮 FخnkJG 56 ߸kW7ro׻5 EkN.7~-L$l:Og{ 87/Nc~N 3KAWg o+aMQ7"VsOrwы0WI ʤ2#lwEF]ԛ?('Pⱸ$>-A *Ga%00Dx=SMޖR0 ,,_ K)R@jHWR mF ʪ_8;N%k\a ,`G|5dh Cu/'2e ѻxƨ4bv bsE +Yٿ}ij<ʻ~(SDѦ}UĜHtJo¨^S׋]WIq4rYpy7h·4ksZVl$+O|z:$\70G0'``l}3=OˮZ; TѲWUkKS;gW`K]ő=K}ϴB#2ڲ2FZ n>N {p:c* A@ۉȠm +uUNĮ'z̅>YU`tJ4{t$z$w)9Ԫb")GZ;lY 4i(k`gE[w+O>9YnlgASO! ̈Y)IM ^݇C"oma&RV{OQ9 .wK,Ve"=/\.Q%QI t%~Mq6N-Ҿ}DK 6K% @?)n*x!g 5UUVU\W :vBOPbt{Zhzh=3*PCz,٠RYz4[O>Q/MeVr{g^X[`&5VI{hwSᣬԊ=l|ل8ěqX(p EEc2gaWAw*_F1LS2ᡃN6ұ 9+BuY1c%d *ܛp# S̚8JM 90-K{c; Ru4hY6L3 Ua%`T1 PZg:Gw@+Rg7fgSw:=j+8{\@G@Q^q &My{Xa{hRRzZlL*Ћs#1|4U>]wQ;5*3EsĎb;7 $+H-m&a&&Gxe -'=i!=}ۯiBZBbaZ?#grD(WMD3x.&@=ҸI8y=6EގD6levf+Ϗkh#Y\/j ߦ)U?O:!QҨ'iWI@Q'Swk*1$hw+Z"ao :Zc $ߙTnEekBg*_E . !ۡ\(o5+ !8ty\?EYCJ~OҾF[gtY{ $¥L?)U=іvC}۽8u~XOәQⷽtx|J>磤E-hsd)>Z} 'TAoN5zG?+'DU @L3'ZΗNxQ0޲3O!Y,)sPU3D+B2((ԴB&Q(W3T#R*O) amED͍V0Y@ F Lb>O9]gDز3C#7 4($3_w3|E#nM\*s+)^z{LhtUQ!yp%?$D=W9W**JB{ K*2yo];hD2V0H&7Bcd? PJzwgg\L_V$ţҎ8ZǨT,",}56qݐ o:G}P:z$Ta L+Lb.Hx 7 G[ jRyh=I4B`'oU}^?yxAyі8gp^fЇ9O'Sm'@AjO:j}_dFqdʟ} [mY;ٕ9g#@""3Rv;K^$o$ձڣC|BU2$ES t~4YQpAt"G+?lcNqGZZ_j I+!IDd[jtTeDŽ/\dqd:u[ T8Wt#-И7CnX-*,ԧbAsMct)~X ҬaWh1n83;ӰQ7$BkVTAiIz):*xIsQHicp:f*t7P&*} >N,\ 3pwe' >Jw7er 3y}jX$lY%r_j,Aϣ;'Nn$/D9PY&7ud1a} 눞PhLA-<7!k*=p{TW(V9O 6e0Ujs>"Fvv܆#ڀM۷C +{Z*7l;Ӹdm+yF3gqZPu^BFwJ+1tLbÁx֊63R5#`;@/ٯR80>Q? 8"5pFj_-sTNmh#xBNA?jU0|xB o*rƩ04R1"YRyt_"-ߤ-'q<3:X+Y 6]AJTV^cEZY`i=[$*tpzNϓMBU/ m9-MQ G| m&(p*F/l$Py3 >pXt$);^ ".dyѦk#"x}Pv u 5 a蜛:-D}it s,4{}~Uy եݴuBckwXH{e$&?p<3T3H&/8j\h% ؀q H^bjze|j(VK2ր0'5ʀ"hmmX{㇙XB5cG$4(D|hjua3t3ʮx0^2Pv֣.?\ձzݗ',ҶEe dAgp58b!΂Qʹ,,FGvyO{-JG{O#q;_lة`+EB.q7 ăƳѽ́&Ku~+ _vcԢv͇ћƦ Q/rIUf6c߽ofh0wvu֣otV(Ճ\>>4^g p]X>3fUmN =p6&!/-4[q8I\c‘wջiHM\eİøE>bWptz"3>}~V6\YR-z΢})t~>|?a;| hҀ,E :Ke.;ErXiRzgڢLx2O@u\Zư%_5ͪŽ;R$:5YުزcMZ"=C%s[FkC~KHV[{xTa ;LzRO-v~!:em6%uA:(vb|NHC t (dE\mj}:Pi^zKzp+? E.. llo)Jj=](X[P:nDsNJQhzcwFp34DFk[ނfI~ 0kT +*"]z.,rX L6~3uHIE ~vkk,)p=qe瑶>43bOWa:;t#o!8aK\VIQs`]%7t͙,bBT pG+{}" `%YZzX&IRgڄo2m)tLߟK.:fHYlYuz9N'#_Y:8  G&r|&%]Z2LjYR .Zf~&LR%@Y^qtwpt~11 n=AĥfG%2W.VS!(6WlUQX'WT NgǒNe+e"yh<ʭ&i _pXY*Y/\@__UMH@?0:\19`7+H$ݬXU;i0~[B> t+rXJ q՘lMx|CzzL;1jle3sÜwM"77ij[*ҿYѪr!r4sO$⴫JWo6oّxQa9Qo<|~l%n{+xəDR|ԔNIPj4||TRAuIufML% <tqi,fg Ӣ>K Jf5/!Ι +$͂JY\S_tW{/^Ym$sZ\KA j"HBl74,^ :|FEM*kda;AZhcG/m1Vys#=Ӛ4l΍K8Xa:Hqn_Ӕs$b=1fWo]$O$ 40:P:&Ķ<Ŀ Y9|mN¹mpO*uN/u"сp$:GyaۛC&JR f4,73uXes7b?;M^fz2uvscsW +"nmw7E xs87wrrEmjt&G2 Fv`Hm':.j ,ϛzfŠ*ukbwĽ 9a; G-&Z|ͥ x0sҌu@51`F{1 gê oY Rp^fڧ jlE =4#C-J( P d=IxՙJlnUqt (#[)~%ĆU1q~iT)F$$?mh{ :,%)  3:n B5LxvBi}lI[x;rtj.x>|Es*eĨE}_~g%W97.K*"7WCd}AJhLD`eێGuM֩xڗk|0ԟ":b+${~!j!8[^I_䱘n (҂}bwʭE709_} uBW9ȓuLFm_vno͔_G F ̶)pvjǝSpP8o,7oelC$3aLʁ۝F7Tu% kHarث w+84=3<#aq "t2i9(#1%R+77C>[_mFu|v?5'?zUyUCʛsZ $XjE*sD\4BԈWPpI@P.7Vc]fZ(UD$g,7BpC?cZ4NآYrܿ 2PT"q Qb[u &?8jЖ9()O I=宇]}!Ӭ}Pbn]a*'dGKo!yXO&&~o-{\;u{<92cG"ZpRYE=2f]sܬϽJ$\HЌo+}jm+ fFP ;䙰Q78y(Dԫ,Z:qN< 92 P'|ȹnucT2󳲽P\Jzȟɞ PH.$j[rϙȏ6v;v!`RNǰa+KF䡏ČnBUʘoe}^1i,%Nc,4h'گ @JKy[ȃgrȁn.JVYl;ڔsG9 ۆ]㿀d{,v'vCƑF cDDK0(G0~X4~͙QHu4 •#_~;fQ.zK񨾮nGOluIM:@T4G\V?!)΍VGp ̒LMe2b6s0~) Kaig@ZW}:0t=UqJ%Gr'z:RǶw.,7Q"XB2Q JԷ-Jb'C(v # *|*&FlYR{9 xgXDиE|4%}֏n{gU>x>n}|E'&S.'w t5!kE;l$1ZyZl  Nӓ;É1~wv)OnE5Q!#TLX2R 8ˉ| 3ACtT9jV^+ڛr' `jOΰ>o"T㱐OCHDy[",d/љ;؂}aZ}% rAed s3 A^6kx |K1* ( ʎ6 3X\ce{-=F`0.rޥ^bg`0G 3BcW 1΅U}wl:'}'+%Hu1Kkzל]IKEh|ewŠQ/H=dfb%]/:`+%̋>±N5uDl ŀ߱ղO':z|rKL8}N(mQ>x4>0f11%_X5s=rL!b]fUB C&A-eR{6|z]:?YJ\C"{_sE2 Ъ4ي:-T7IX.^}H㱙?›X.Qsi^HZsOއ@O ўZ\Vf pQ4:(]$zEm4$]6|S-Iޏ0z6 ['tHOs넘LNtj_] rn7Bp?3}z'؏DRjetSH[P NЉa$wAɌ||\V G$';~lE;0 GLJEu"[M}yZedIƖU`@e$"KLza^i,𞭊Q %yBs[i|? ?~uR@a?R $eM) k]pƮ(qZ<h qn~Nv1Z*zO ĸ8ZK'ELp:lFLS"0޾3ݍD?})E SM`T! b@`lT*lx|fh-$%9d͓[T B W`?ǚX1@9(Q,%OҞ5X.jWr#^O6 }3aת1޺w*"ᇭRH4;$DsAs\۲Ny1%c>:ٞisOdԀNeڼK?u_ g|aGU.r|7jߏoKCRϹ1#M.>.(y3/=lq3~Fp(hvX6P^/GMpz9y|!c˳ݡ>'p3b4.oS] 3QD?E*oMlĈ:qZM uq>m;u =F18m-8(MDZvG 7SM']hǧ O׻OmgICjKӱsNOc \O۶&4n m)Q\h./OkV%|Q(NKz~Ra Kb͉Fs/pa>}FNx"9۝m'pi\W셗GKV{^:H6~8C~<Ǖ,"L3sB k},K iHI7-ygW칒MFj1xUg yJq# xarRs 둜A]Y||7ca2A5Ni ^.ށ=9TXD @9TԿoy> ڽhv}OКx/?D,`ByDCU+?*0N5keeRl N&O:z_Dk8\ F1 rd ߃WvV} ›NhmبkG*: Fpg][,cAUn;;i$睇C!Aq JP oЃ ~()](Śy5n<֍tK ^0]LgoBeA؏)+ -/<&O<. Dilؿ+Ż8}]'Kd_.&0:͐ ^ ;0{"Rm %/FPȤA02߅2Y#^%WDLFd,:5ps׆eAc116zS0ײԌ/3'~'|=wI/Ïg"!ʛ3ׄنȶŷl4?HsXvC]: [O8m].d*񚚤0UFkvWv_aՆ-w˩aQ%S뺊).* SvQxYÁ*;~ZYzvҖui ^,/CBVP-[rq$u}AG'pyXZ.+1 P "x:;!/{E|e ?T̑ 슪ZOƩO4]Nf?ut݊;ZvU Сvdݚ\yuȄ3 l~8j>-d ϻO7I?g%0& %tOF;; :9d p>)_42y4^۫1_ƐSvQ;)܎#MZDbR.;([mozmN4gcg11ǭs`~@ (HHmpO>yTk  IzMoUU|b]UYttJ!ODGHYYuz{WlHv/ 2|”iL^s5A$/f8N]#eI_=~#'[gV1DRd&.Fu F0\F)ҁS_P&.e5F:Fz?S0=_u_n/P%ۦҡ5* 1<<~S,/!mpLث^&4s ^Ӑ8rm->YTswXJ0xN3-*r3>7wI[WSXŢԵ!*eO^9TԹ)F,{3 o7;^ujd1"XiR0K*Bt/I;~@PbDE 3,aԢX-c%zG>z-ɨGb3fG&ׂf=W!/z< Vjj -;=p\p/j]lj'_v˜k#Qkb`F4:yӁOmI] A2xfLv]Q<#?A^[\]UKPM47wěn{XdL*]qOW @?ow00+2L%=E :3rk?@Ҷt:u+Uv\ ׭ QULS10(wsދwQGR>aqԐT ;ZABzȏ%MY "k [&Z `heD/j#g#֐khpR@nP6Wr#72zfXEKU<8d$Qqɋ}Dʱk$VeS^ cdiQӸ5GOj ·TdUJ YN&y:@_ĀtW)"TFH-q>^ۼ~p`DSA=lf{C]5؟.|$du7Z*s 6%:h|D掗XGH7TmxŊFR-䗞}oIsd(l0Y"Z NtPK-SEDI`Oi=@I܀Dxwn}<é* UԩaaΝ#lǃ}%vX(riuzIdGgT r('ǟvVp/",6򟊖0>j>I="| n,cO իbkN^UT]2pIYKD_g/ SجW[TȽAuPDODLz m?K% 0t:?87ꢄ6~3ڭK]Ɋ/U%ID>)G39QNW6ܳI$JerF9#(l-鹮MZ8(sn~&S﵋N н&eB[37!?aVTP4e{D(>a=H~,|R=<``oȚ\|adlݜJ5gnL]_E!U1L N8iW:Ȝw*T4kvM~[*ڃ?slqX( } m*}qKXF%^VQu'TeYxUNC!ahj5Fo!o}(uA7/CC\:5液z;1MY8.ϣЅ-bQ 1/~6X0`fnAw `Wc{[9Ik(`9Y: ҃P!6 d9zo_~+CvXx̕7h>:Po@.9})I:ٜwby79SU6D+ёYsvb Ƙ,$ (> `'w?bQ"LQ'8v4!?x #]k{ijz<u$GܧZIWr?7ڤbaB+fi+bzV0/Wbʹ^S潰$0r+'K{FH", 6eӦjv1H1 Ĕ_S0A~R]a1@ JM?*S{HM6'K{[zdJ7MԦSnx0hχWubRW&)!na+K' CHr:9_ys8I~,>Y7؆c(*`fqˉؘ*sa=4¨]a:MY(}4Jt"ܯ|wqj`*7$f.NV~_k1k3viTCZqeWDFy,2`Y6 9-T`B!xd 1$sЪ.a!_v#-o$<*h8C_C\=挬Z2f+"NzȣoZLet:~.7eȵ.̙ҴWm>"/YnNg+ bR ŸA0{9a2*xpij~38RT: e\)4Y|<6 k$u$"4ׂȫ`/3, ؇wxDOgT*j(+?ːH >M8ٿ6RDR!/?q1s. :er:$Pũ<:wm58`E )!\1;=i'LU%7Grb­|.v&Ji]~ f Ps L#tLLZ1<>t M$`` Ŗy DMh[?a/nwF[|@zxjCݏpԹ01Zh;7FS6pw?[VWa Tf=(n[ > $~c[]oŔ^Pu+Q$-4l!k.Xr%zd1IKӋ@M8ܾϚ6Wdǯc%W <7v* r0dt9]bcUx ؀rՠ߾r>aL?M(QC<|: PGPdTiT7SXf;>)⃩8SӨ_jy}7#)+yDطmTћz )C8ta"\1Hs}N@ԗV&QPaP:"zRzƑƮ\\ȅpLx/O %n Ӧ9XpֵiM!XxP>NwA DGCÿkW#@up[AW 1mB2cwt{'>NF(IEpxVrl?Vd򰘘COY~UL7nHliܕ 7P/D3lXMZ”h)w~?/IzAir_!G8p\yWH#;q jؐAb0,}j!`mFzh-DӬf1I \$pҀӦ2Slip=AU$bmzx?Iv??Z4 3X7EN.*+bU`/U0?~ U2Яf&爠T-tnqj}u7wWgYClT+o b,zz>i= td,g7l`P_ݔ[~AL\O9R ɑJwud`HsX{ͅ PwZUýD Xvr4weg|aWЂ,%|<}5c'"!TS.A3bjmo'C=*]O4]q odI-Sqh[q4ܗʞ@s`|'TWuoH>87`4[d혠d@"JJ ր+#CMnvSXQ'(*d߀1KYr WnC#n sAN(z0¶b//ZO_c;/ۺVZ? $*̩](4pp ONT%EF'C0IOQNK%垾勒MVKa$v/إk2anсUu0Ň2Kj/S^pU%"- :ܦ4X/7[`{{:A>Hqtz\[šbYm4@a/Eg]ՙMq%+ڋbҮT|SQJ îTGO/"<04Dd Őt9`#O$Ѓ Ǘ{-Q޷ ,iE犧ХE9MsIyòn?9mbRM8/F\6=-uLsYf453ے_(,9 wl5˰(EHjЍZcDWVUXTp0hF{)4`MyIotu :.i(3j;.Y[1 UoRwZ JsL&\~xrGyxLHq3@ Ps DPJR')?BhV+Ke1er|`F;~s9H3c'J֞$q;,+tǁ53?iS2m:4J]r pږklgUK(epp~ȸ_2&{6(\ YxV`_[L$/ȣUnT!"yR Z +HZL -µRl9ɊIr$j|ZMEpq*O+PRs{6R40tA^5isq$:89 ASWYaT#NVF$$LW:d,]҈|>_5:Z:W|u*aϗC6%we]48{x0D|DXR{'jt A\* v`K}HkgTF諚l]k"G;3-g ԃe*bcZk%_kD:(jwi'ǛX@|+SD9Z1=oesr ORB*.eǘYD4Lhw~{ >Z*y&08۝Q%mel~FTDZ5}P "r.6[~7FkuHN 1kvn/xfk˂%끎g-mF4I^FPP}clXdVGyqJJkLpq+0K34)*8kfA"3Rx /2Q7? 4-T=Tէ`{?U&eE |祽XY|hS$e3~zc,} {a7''Ct9iT[ 'N2ǬΕ>c ;! ps#t[?%-]ݺD{tF\~) j,7F3ժf۽-=ƕ/)KK esSjpD-ypNt::N0S x-~~n DYoć2ua}p??r|iD*VeCp$2I]@.Fڄ4,EU㖰g&i)3#y36y(k)?u^ALIR#| ^,,$]6g[L UۆX +i>ԨW`A}rX Eҍ"q,~Vv,y2F~мA5x,_6''Wz9V/`~*]*K2#b KHht5 v-[\ g0kx.6hRJ;RgL֨7Cxᗕ2m~ Xa懶*(KMd͕{݄hoS~nЬ=YnNtCX['ೈ*H; ӈeD"&Q=YKb M5ň-f2S?0p' rC9k=#zO_8+a0M0 *m a&"4qGǑA=9e#-dxoF 7Z*zl#SzOG~> ű O>D:kE/o@تj: A'8֤5zLGճ+wVYf`Gꟾ|r"N(}ٟpIgcާQ͞#{~<~N?|+c hNla3}96?s6z4vfMn<.)$uvù'vkOp*װX,ܑ|6`i~uin: Q3Na.^zzF"i6c2'u$ ;Y_dĨZ[;5j2EܜEOd! sb}"ۢ36y︣< [ʂYᓚ5fWYRdqk9}|bCfK-qDsa b_XjYT Gu QNSq6tRɻ+7A<Ҙ KE:NR48[ܤYπB|DWw>],(3 u(ǿ?*:C6_)WY-)EYxo?QLfI`a[Lf;oVdвw-t!(FJ@y:g+XcYowY&|MFN,cj$=p9C+\eZ)UdQY PB,?>DP6t8ҪƶG`S,Ҫt 1u/(-˜OڞdKBAH=؛ؠh#쐖 ؼgENn^:2#Kj}2jQYODX R%/`\&@}%މ߯"Z Bf'1ٛxH9Vۄ[Et]ȓK.Vx!T|Phe8D9=cIBe3?B*Ö&#1O=DD2MGaSa0ӽrS6M4tձ^2`]g7VkBI9۫챿G܌O*K@HDFN%dw#R^0\xoJ碔/"m >cTSTS! 3ݺ ] 1X4ج뙴QAyS#=gVfԦOG&4kc?JCycOP1<67eU=U)kt_~Oȏ쫶yY$آG2x yDFb;ňLH'| =`CnBiS__d\{)N琖_G? ֦by,"ߔ.c6*8cPw&{#7g_H,z; @$s@ɹ{%^}<|I4, b2?#T90K.Ae0")Y],֭N,,mL4;\R^uhu'BIkQoЯ #SqNħfgbR0 +rEq3}(\BFyx#U9C9TY>~b9X'v1#6,dq+ 4T|׃j]s&T[r0Fٙr<^qDȆzD/YU]t*1=[rW jX pwffSz8猇>g Sx4.\96 WzUr4na jZTQ9Y|'MCO[cWgƛw2;axqpCG6=z?ŌA *} 0ec8U"gRӽ,)KM3IE {R5؄t^թ#bhjo֞Q'k;~h}-P\bS_ӛr#ddP cvwdH{ 1{zW_C2!{%ǻ9^ǎ+VWW0R&$bQpB͋c Ŵ݈cmkK +Oþu;IXLC0шl~4|Yxɛ¨n}vq#tvoЦT!1Tˑw첺Ain?+oBpCH΍"\'gʕ4%5ra_(D'y)25glp{G GNǂ3w>]~ Cʏ?/Cu.CMiӜ a k0툎Ύl&A&Ξ*"YIXDͳF5Q"^+]#dCz;L;ye)sLπ)̕^@X.fv<ܑ 5 cF'gaGX 瘡l| @hg{өSvjp3Gcr;J[ xeG=9)~ yl*g/녊JCfHE#Do]K03u zIVjP׃>MvWALjbL* &Q^LR='rC`|iPD(SKKgCjj-as1}Il^7bÝ|=XOԘ-=?ƌ1C JM+ =zLzʾ|Y9;!ǒX]M=sg1/sH'J곚\"q0~4& J„o{ B =CI[JFPk\GUdtAl32[1uJV, rI@VدeAsd?uⷛ&k)|!:Ho+aoXeN 7?*s\HzG-zaQX.5O{%<ťEy,X䋏4C]C&NY6;)Gg[EKf|4P 26/E

sj\SoںjLL&x#z"" |#U JQ8KݩF[Ւ'||2_kCʣs9U]_/ _NwZ7` 4\{Fn W &&7/ʀb Vgo|(YndXcy-!G5to7U+g 6xHȃuRD,YOOw@- 1EnuſvnVZC@4|Y5*R?^F#ϪD[[1P!1ҭHL;h@MEШ¢c}!+;\~"銠Bܼ#wm5l]C1TZh[h~8F 69k?RrzZs^_"Oy|Dc3!vPjy=r>Ϫj``^*{uB y)Y VnY05.pȎ͈c=%2cVLO*a\8ysI: b𲱻)پOk$=m"}=pKbiJ]P nz&($qxNXGºAKw6w~`vss1"8IՓ{Z8q+<?s/HOqD g8XPUNt߱A/ٰU5or6 D7Heu{溙 Z6GV?ݼ6,_یsB &զRK7>5i6In!3#b8{*J@389 K~^R>'5}7qt뵳%j ]bJE,TWqCh~%RӽD7^is0&ˈL!%+h"UF̓e dZ9b k& }TАCu+: 瓩{dዲ["XKn$:TqhT`BSAӜX:^Jn$iՌ8-DŠeZ9|::-+J& %wN;vL7 rV*~f]]\+%Uh[Oe͕G&(VyA輫[>#"LF ߀!mKj`!d{d?qo$FNLѱ\Jn؅* 溌7۷Lr YR`WoOjO|WS*\zrpKCxI JM [h>e?9b($i9RKwK]USTvJA{Iq%3V9Oc6vSiU#}9ן 855 h`!{vh.D'Ѧwhx5:{9'b')&Kff~EbȖypasƳ`g `Y{q,oHiv Fg!Rz,Ο "̂ ԰p3KHX鮾Y"< )"^s+ ltDx>)jVv\Wl6~ `:H4mvD1RuŒ;'{W)[A`uBX69؋`,jQ[{ZK#?Ue"mI;F}K0,. {ɾwte/IR&IW ،{J+f~#^^f{KnzhQ4TFBfzd\eO;X =+ 025㢺3J ):g04ԏP4Q9j]sY4OہVeR 4 ꩴسn!_cAJJJO:NmDMd{o7 Rc:c>O:,KKVnz=B>} rgcͭbg :8-zzE'#{=~,ls{6kh g=bz]WGf-⊟OUĎyyJ+r^Nv[NeKĦ?12/*54qHbr ֹx0Y>YrE&qB]F[+Qנּ>z e'[i*#X/gΣ=_<vk2'.-aJZtk.j!8kq(iQ?x'\O1 %5~ 3 I[4KyѹJo@WvK`o9AS86Mf̛E\2A%^0 .SA_7[˸J_ tqQ\dfK3|a&RjD{\,Ou'-JUˌeԕ Zgؕ_旴 f6:T&,:]:^;9ׁ(ذZ\:|Z kטvOVuN.yF`6CC;Q>֛q16їRo{Κ.JJao_pFpDwӜ?8h o~(M_To7 NƴBcsrPmAuXK[qS0}5{^&6efSpdS=O /fǜ5ٯFVEFu?/+B-m]_{8=P {mT3Fw։Dkng#'!tFxq!2^}}'Pj@Gz7wo)ŀzԜnh'y/13m/%|Փэ^dzm, YGyd- \5Mʀ]:/aT/+.LCWEWauN1G[773\$ rFc>g⋀Wyf?Qx$'%l5GiKNlNKؒK6ǣ !9c1&lTƔpydG4 N E:K3;W^ede֤Wwn2tW)OEih7uΟlN(B{ep14LϣT[?FwZʪ'bѽ}h16]xVs5~,R3vu~Dbc)AnS wVj~hk޷lO$Wũ3lYh#a"YN(.l\7" T&vπz^Z`JĺdbﱦH[՘lVuXvd)bk5kl^u!+N;F4R,+҂慵NͣTV?D<,\oZY,PrzfIT4Iˠz3:G-A.Qר n>d==4 x6IP[]B u\W4$6Ӽ9Nns妰MҚ(:Sj4Z1Ws.%ǬU>Ԓ>}s7 e'o5"N@[bk0iNc +6u(Y.D*+T6HAnDuJiXZ0 7x _JQT|g]F倘DI -j4y"ov_}Szh^0".s5RK<;惐ˊ '44N,G Lhۈxk478ȴ\f]}QAXcM F, \5ih7>2I`RYUm=(c#{F%HRPri:W_ %;Ԓ.Rv=_Dv`ۯߖS q.WkR !zoK3!8TVHTfE9rMI7޺CT4PlFj Uhs#I8o#(97cM½`D=2Qb<4fV~ #<7z<62("{C>IG!7\뵡atAr\Dk 07Fُug3*~ 'F("pE;'V/#.lKFdvbe^azFӹM "^ pTC K gڲ]\9I,]go#>^ML`Tiq NFF\.svԯ*eDkA磔nkfI+q`ez շYD9f:dWASy9j_Yʬ0rc "+@K8n ّsR"½z [BXdxYگjd3M_|?e@8Kdd3pk 1$1~ X0!$(Ş՞\F8̌ yZFI4u$7Zbhk4_LKzg= =q.sm=˜$x eȏBěi,#-Ҁ2+EDzM9ˊ #lЙ+nٵ )XةM\)?)V8([RGҬ!) 鿉D+W -Ce>h^( ۉю N- rZa9-[:cygg^ AAS]H _mNjGIQG Zߖω/4X_XbbG@Tc⭸$]#wB,1c+V^ڑN%G˔\8NAF(1#P^e!IV6Z"%45f{n[@RҘSOnu?m0fݘ dS>Q's'#A+쇺e>bV1b89U_Mqͯ9^S<X"I1u>ՐQ( yעYb/; @6܄ QӴIw)h?U̡;ѕ9'N zD~OӴZ{G> ;ckևۯ@7ȆoSjQow#!fVG6M#eX$;l:n^%Seo2-sI5`~XXZO ]g^DtSL;)NMqO}PFD [q@呈53U8dޢc$ݼr{vd2ס-r\>\uh,I[v[*YoF_Ŷ#>/xJ=JUUYpK4u5#chJ~f'ek O1P8{NM Xqн= 켂݁gHJWXj#\UNrdCq&S̊(u>ʛt34onjyd0 iJ"vBn}/u%>̌xHQMT|*q:t~? jpIܐR ve^qbW>y qI' DoxE0Jkjx+1BI^+c,l D:2q;SRVۺPnrbX f11jne]׶<';>rvm#4bfR(`y6l,o ƪ9AK GcyGt+7t *S?UIKlii|\*SˉHPR$C󵇌T3D bJ>+ok{I15UHG~wgNȏ,ZMuH[?B(յ 4IJ+awǫM㑊Cb,Jc-Ȟ Zd{Eh{ v23yq׭U) ̔mum9BWFB=t<75.^L*OEG-:GIpԗ >dSj"Ƕ:ւhwyk QMbv(baQ)hI_7:fv}tQ>3L }u1 ]!M_u|,<>,ʶdkEp J >…3&"IL}|綮C<;K;-ʘj%f+ ԴN=Ez&e&&,`K*?td7.׹[a8шIsuK5 |H9䏳* sm&A z9`懘6cCht:K3:|_F{ιոNiV6^Nff$ϬG06ginTV 痑]a gw;@ ڴ cvt7Ұv.s!E-v_b]b8eg "D9!Ξ ؘ fR3FK?ȟhȥHa9铛@OpU7z"]fb:Oh%P?&B VϒI~j( O)jg@g%ćYy}7T-W{ܙX` !3 0 S/bծ{nv'N=..XM'KV *qOY)/8*02mzi =X@L'Rj IXez~$mq|}yBM=y\p-F$ XVFjS"s s+,3