sssd-kcm-2.6.2-3.el8 >  A b1U]<@, c3*ʽ ~%ưqTϵAKqfɝtwanj)+`h2HC9ݹq_&ReEx:+NߟoFQ^ZQ+\z;nvVPςohܿVY(BPly[u<9395LƇ"7WA4._6y-FwZL.ly եy8_ZB"r*;SlʶB2p-=>k0kUG]z3L5E('V3m *(.$2v CA) /ᗥ /1.4ޒ[-C*y2w7U~HdT{&9hkRs@; mǼeRZ9 =a1J ?S~옡ىg6 fN$0DyuE6h>didpC4nB >.{.vb91x;3&-ޑ7re}L_JFF"4)0250a762bfe4419c121c4c7dd6f9b26ac8cdf8269c52d53733f7f7a6d0f8bc3d7e5f8b482aef280d9e102265d0792dae5c270a88f@b1U]8ulkz(}vdvѩ4B iGy9t^ѐHB#"SJcE"Q5%CShW"00Ēd(׶wr(,/Cnvq0*sןrT|9f{Y9yV /HM^V\pJ@p܉i+Kl*j:2߀3blfX*Yj=ϭȘF=PLA*;z C9’z%ѾۯI0YNZ^x)uP0G}._ƕ9?M{lΨޙL~_pKr$Kp%Ѐ,fʱAd .f}pB|?|d   B 'DJRgx         a     Jd 88 8(58<9:dj>u?u @uGu HuP Iu XuYu\u ]u ^v bwdxexfxlxty uyH vy|w{T x{ y{+|h|l|r|Csssd-kcm2.6.23.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.b.Wppc64le-01.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxppc64le if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%5OzځAA큤A큤b.b.Fb.Fb.Fb.b.b.b.b.b.b.b.b.acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd479a058631e6cee24c53fa3bb64084022d4fe318584481788c18b65358616cc22e41cf3e511d463c401bcb47a9a421910e45824a23b345db419fe4b7351ee6b93d96202519080e02524c917c01f21777451b716e276e48dc8ae9b0812adba52306397d34874c6056051ae9f3723932ab5c84bb4e1f3d3ee5d0ae50fc5862dd07ff90f25d31c8a940d224d2fb3267e3a61c32bef14b37994b0a493ef31e63f6d7c36acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.6.2-3.el8.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(ppc-64)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)krb5-libslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.6.2-3.el81.18.2-113.0.4-14.6.0-14.0-15.2-12.6.2-3.el84.14.3aZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.6.2-3.el82.6.2-3.el82.6.2-3.el8 kcm_default_ccache.build-ida3328ac8cbd9235b42420f5dcbad0e0883bc6a1fsssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/a3//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=a3328ac8cbd9235b42420f5dcbad0e0883bc6a1f, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)+R)R%R.RRRRRR'RRR+RRRR R-R#RRRRR(RRRRR RRRR R R$R!R"R R*R&R R,RR2utf-8ebc7317914dba045be7f936c6d3bff2cbe0e6c4f20251f7c6abe822dac1986da?7zXZ !#,_] b2u Q{LTrUQ~Lƾs3n.&3!]h03 wm)5H2 Z J1o Nd}Hn8J.K 2@(5:5Swx1axtLO:<@7DB-v0%n|aM(ˡ@pJ̴ > #eFwne.|!1>xH]=sSgcCȄ1=HfO`{Jݗ:w_)'w[$J0tu~@{ b =x8ī "='g:MDk{j~G/7FlERt\ ^}jD@<-i.t$T_@gQB &Fp~͆7 3TH[r~0+:QA2j" H6Rr5&_IB{axqeCTKx1HEFS .KeQS.]'J/Lgh+ Y1SUSh|gR=9k]Ncϭ ~\)n6=lhGt)a;OZQ#K.,ڨ,Y$.g&&jbV>4>mD$ףm˸q=Yxh=T?N$K,9`8EBé'#ؓnI h?6P: D!�+Mw)Nw߈0=lO~ް8h?ʱοټo9x^._3}b?l|ŵ 'v݁Mz>LmPȼWEa/~jÑ04Ryvlnf*(OR0ME&?pF~vá,qZ&)v("™|\^YHxNud*sxXgyu Hy)isL w}5/ 6r;n«Jg&UNkŢAA+t^1"Ggodb~5R4$ګ6@B#ʘ_nP M!#Sa- vVɁ؁iG6h~'l>C1ђW:.iܫF#CЌ `7BnSӮ r t,+H~öx#R3CGRQU, lF PZ!==D@3c񫫻(?q*Cab!L x\$;)$B`\hk3Ǩyޛ_g\^VS!p?'rrxg}(SIq9? [*.6E0!6>ƫ}Hk =eslRrQ$zE~%;2i3 ߭!GWnsdUjn`QGq7-!$9@ ^HF":K$N\7V%aͯޝ&@4!":K_T!ڇ0H=zP=D rtåBV~.:_[5x-h5e=S=/gVr3ik2uRGFXX$e^_c1r>ѧrB]4ta Û{ϵJB8(տG^6D?PAkŗ77u^=Ճ0NQ<=QymgY |^a9Ix]ߕhd[i} .pK_^}^j&P4[P ?-:ܨ08k< ]fuw:ٟ[h=EBlRߙi%Wy:C|E7"&9z1!()#o, "^cEg~?(WzYLÕ*6AB N(sb%D%PjT~ I~:Yl=GxZ)q?Atrs(_( g+Uҿl9uj^ ֌}M ا{B=sS_i*j#bޜZ8 \oYWKQX qlHVO!Ss^Ӛ1HG(E6O8!)?~o ūE2ܸR6%p2%*:a s7.Ov~|[ON4W7 ,a{-k9׏*-J$Z:=n^;N'U~hcR0G_+6InjӲY(MP٠4AQ+,z)$yڴ|󛜀[aI³nG1fEs=v-D Y] #==щ`$z'lú0d}cW/ H_5;z90Sk91Jgmfv%ѨMpZ>e-|^%6Wб0CMFb7I_^Sz-lǕր ,Y'Lj$yܩ䄾4H!@ ur*.8[ǹn_#tdww(x?SWtUY4梗F4KMvxc…qy`A'e&F :ZlvN`ɫȬ9"38SZȗuLӥJgrߌuyMyYe`CkLr߷(D"&nn<@Yh3 ;`&>FrҔ{weO_;Da]K<*r!suG> T%!`;=^ @3I!cw"o94Pʾϕva+њvSwӰvČI4&͙uZ䛶w(P 'LP**5 ͆xi=xhTTho#CKǺkT&}%4#2/K>Gf?! e!\P)G%]ɮH3L R6fD0$:H9Wvj@|v'+R4ne":'R$P^"I"g}O#s?7;JU;Vz>TŴԺ-&]AmպTP 6!tzZS۩<ACi=21c{5\۠ I}klPq^m&鸑VN&FaN+Z.sab""F^q֑sS cv刋"Ph>5ӱO'o^*h|.!Af4!40@,$vY:sxaٞw"m7`{GdD2 zRfD]5YA D!V\~8 ʜǎi5YAtOpX(no rr}Q TA"?qLU{"ir v,ΡJhP?0}N#pqСV\.܋J_=HTYb fmk 1@-15,Q/'6tZGk*m/GbKU||r߹'Rrku%>գSEKll5%f|Z}^frzaY]-/M)7SChpA^5QLZD?AЖ<"lAGusGfDD-]'ԼC?WЫjx"-,]'q *w-zӉ!>u`B*=J8D@U|{ݛg݃-8îRݹȚx:poպ8VGOj(@sU涘vx|'7вP,SQI8 |k4 d,ǽƓTU$ʑ|C_lYt*?.&u5 XPK?Ym+{rTS@k*QN3JdA8uBϯ"߾g>fqݬDJ(r.&7h- h0ϲňr*4VJpu6ގN&pg]MJ+HփfDczV 7j20MNw)o~D.>e] ^S8!bp!c[7g=W>Ԇyvfg^n|jz=&=Vp'$[fVY\bވZQh2$N8LdFa߁8QŤk[X#}A4dp3[aKIV`E8\>V|72L,]vJf#c ^Usm1YTI깧jUSzC05[>+=zqH3Ƒ'ٱ.$->HaANd~{޵GŨ<}w^;[Tc"^Pe5C'˂T9Vdj.,V-e뽨f/t|9a0pQB}vq<&ͅx̬$r!u`a.J5\&XT-]x7(*OI;_f JQZ` 'ͤ% L`'o#ӰHO]n\n[䣵azQrrYYOdlْ 6ir õUǁ! V>OY6 >b{KhLF0±˻o2 bVoʯq0*9u8a價oqڐybjJCP`sg@I;B/]Tq7OHadkblW`GՒZ~2Ertภ1"%aFʾɻ zs-Ҩ#,6ZyS8+ICϪ3{sZӤ P/}Ls+ttn[:ߔ6؛[m v:!Usn^:ܖՀ& nl7V}Y}G6Թ)-|[ W:SZgnlMEcgzb?硛)-n+ {E!Zji V}_. FՊ81#d\tV1<*C.-ht2S ሾneVC8EmۘBI0+#%HStcv ~$ŝ:=L)͡g[L%[˓G aB@Pխլ9Z6lCe'|{m FDN`pʔ#Qhxb]^Sj N4czr/b@zP0ԍ"@kƛ!>ɚ2֖݈KF׋.@xXm!\LὋ@p&F|"\;ZsG LFT*=EGsk`t}!Mfs"; *0K r{\V4jnqeY)eTVjL56q*W'Qz;I$y^ `,.ukp۹1 I~VJi!mxãc4]4f,jLUD~ <"e;vŽm pTx$VK$K೸Ȍ"۾mIJJ5~@2Q *EˤJO/#5IRJv"ܻ^ʉ{aT I])j445DpUlB ۚ:(&] k%I-W\#нk26$]$WQȦLuxxhPŊXHkHSu*$(uOV46dDV]T|YB"nbY=A; pW1{s=` i#kMyVry\(Hj 3Ua O}1ov^WՈXcT6$u@* $0~. P0;(v쬃:[}ڝx>4աӤjP[JWXPnk+HyTLXª&FH֑v '3w2t0Ј=7aM˴LtDqJ??vQ>d(]DWC_јj@E;sFLD8b 4h'Xj#U?~ί$ /O8~S,2JΟ}N#pñ'{Tj|Kwbt͞}Ec]8UhN} 56{P |O][4K-Fvu.d'nf'3V Q3W9XnoэHùnGd8X`ՎY̖dyR"凲poBLO֣ͯÓ"Z(t䷤|܅Oovo45F䥊fnzb`tvšD N{rhXkd{i© y\H%Nߒc;AK3WL+@iq\#&"U'\2Qَ(:W w3I'yơD)xH>\##ɽ9 }ׅoX Nfbr#dyurVbm{zPx_&vOh{¬nl]Z5=A\[B<)WD)R_qjg2'Dsp{h6W{وy7+t:\k;}YA\ʻ4bh .R|6 Ҷvq`vSx`P9e2e7 x`F/t  mP\r2SdB%KR: h51Kٕԍܧ4.:&;tc뾛%@uZ6QmXRӪARUn\ֵc?`t-UM&*G#(09;/KC$-UA;2P {`p/orғg Q1 !j^Z̖]Bk$/̥p>[.Z&X~' @B7b{F'P*A%.?MF0t^"Cm>Z'neUvɂ5BnGg1:S[L϶:}ab=ҒA~Ƙ[bMסo9$I!? "LxsS؍fʠQ99myFIq" DnThd+X׶s @~:-)As{!X/tBS fDvZM*1;~?/g/pZG SЙ6qC D'`]!X fz`*IdVް\Cs—y*wZ9&KD+PRuK#s3qkWN}x #lG[|7 z2;`ŋY*Us_l۱ B0"*B@+=`5(a^YaXMS<.@&9b'$YW/@dO! Fi3?3Ͼ}[hDPw<#탳O1@6u0X9~{<1s;[zf\zNJ^s['Sb84Z&,VAdHNr^\p_K Fflߺ6gue^ʡaW0J %ָ 9gmBsVڎADc_6YFsI1&ql]No*(4Ik"[:>ml؈_A/W7Le0 |/m[t̔Rl nnd[{ \ eo_v,~f2pú{q'|)gd{wВMYY9M]Ux*9Q?c޳Qͩw] Nf9;KD 4"zzW8g:#txp( P{^k^6ЭįU7( Sk`(:H<^ȟe%~}4lPZsIY:B4S2yg)t(|JF_ !ϧo]!h<: jra22kaڨuᥗJtY Y8V=C Ѯg\܃wVU*\3+6$otE-nt0zIC;AG,)R"r- }=gO.8zҐPو M V{WA>_調 _Mֽi =e_G I' EiYw8Yۣ,sD!LGϻ2~~ӯH|s us55gEM.<d1^$G,2iŏ$tH[_zF7 ?:CTTIa !=ehuЮ/̦Xz|&Jʠڤ8? (+L40bpyǍ0ep i! U k*3~ܜ"H}"ܠU=8Dse)]I9 uߜtOqKZe](:]r㽾bo%4J_h%BCaV6HI!˼9)JAuu٦mPD6eV1u`ylTciG&D &K%̄>L De8\"y~[>+{㱲^k5pdkNJ$E|If4CP2K,ILIv凨bt^U.ȿ90 E&a\Cl_oϰPJOI]lcreٻX%QgNMfa5َqh_q_%,gf$h#R>^Ը_\Cu"Ac{j#lrK1KiQc|71t^`Bq(ivwe?<(IMLr#&iOJGM>%f+0$>B b;z60#Ξ eCFp. i0#kWGРMw<\CI \h'_GYv1Sb [uOv CS3=|yR @bFߡ]ZW׬VT:]0/H7ꂜ cm\أ5rcxu qX@s.f0\9.Ug͚k“f y yxyp(msɶ(! %bC GŘyjWVmUY+o$™ǡְTz;!Fmx_wB[rtAvڨ`oxoLP'H41 x4õ^NnD-SprEnZANiUEfV>!姧 pI*N0B{9&2B[nֿQ1rws/b2Z'o8K^֤μ^OoRM CbhӪȲ|(f2,,"|`yWP;7֏#B< @ۤC0QSR?laPJ_SK̪,5"'ʜ|q> gZ,Q}!SY|1펬6ýyOBɇu+U$X!c8hdEKe3/i39?S+E-A^F&iC. 4Dqh{C ԙv)ֈn(SNbB'cuYb e&C%,X5h_y"M ٛD yP@{TdǢa mlA͠z.ql Fbg (ѫ–-Q!] ^J_0A"f+(A5`*T#/E~u X 4Pi[Ѱ;fcoeRXtLD+ApvcxIȲcS %Uj/o0q#IvkR<k{=oG =P7sKd\j*+p46"Ѵ͔zOUo$h*Jk͠ܫ`~ 2#} ьБ>wy=J61ERSe wt{04[ L O}~}TKj9!Mr^8Z*E`PIWC1ij#r6E 7xѱE[4glg1PX,JkOĥWaGnX[*s5`S4|`Ɓ+~O$8mm%:SeT Z)k&5B&zs$̫$ [*( D¥"-S0k-[ҶZ;' }] c/Wʪv{%v $ER*3r~ǀ!F3SZ|EGSmdV$ Х 6oDkfO9fmv չ:TQoKKyEV-t[RN 1^yxJ=_5yH:B=vHʫ&;jaud6)6S{Q7zBr7[R۩ $"4ԯA^d@I0 r޼0|{?m7J˅\Ě~p >  Ae%RvYŮwxrlD{jNڛcZ7*:BEX:]H|"P+Ҙwz/SeiԠVyzN ´V.yV{\.(պpArqV3xm+˕ͱ#RshAazS6OHQM0'QN\T^\.\+vYr +96{]2و܁#>nC1p,l>1 jX;o<.&xJ[im 5@e9zvǵ 6^ +yI}v J5 Q↣Sc5DSV@Ol{츺򃀚 ϣ@CRg­F0ΰ+99ڥ9ۑtkSh;dAe*bDM[Fgnn(nA=+4#b~.ԘCXβVuيơˀd {_HWį("(|=vp̠-U>;$~+HHĴ&f.#QKԖ qNW9 ^S%3?lAenAZ D*U1@ [ՠ@E}h|,E;56E\y?,}; K,=Y{T{A>9gJB9Ջ pU C]s>}VI"dTW 1FjK#y}zΈkݲcYVj5!|}+~5O jS{q*s̡_z{r#Omu(,c I(rs,ɛ6RUm*jcx1r hݨ? Z!q"]4=&=BU]U 'ʻ,|6hWiέD/~@Fٔx>T?j`m^ >BIm:Ku8b* z̚+oֲd?{QB'L {x̌azFK; V;:o#;/ih cqW#)@/}Hw@xSvҧC_ X5.7qAn/M.N/QgЌ@Jmza)ϵ]*F!] Y~뱠JG(.|a&x G B%Th򩼑ݾᆐP'o4;F'rZF,r0tX@hkMqo&f52L)zX^݄m}CbMo掜fd[k`;[*iwdp\ n^tZ,+o~D.n s{N݁(OZt=/H@OVu񩵾9FyT-$ >"ڙ%҉܌#- ) '󠻭 NZvYm:ƽv\pP#KIrg7TN:(ichl'~FLaLjr忁߂xܤH/,h⽮)}$<沩U̯&L pYQH{iG/f =7Glk}6]Ȱa_&)μ ߣ1lT`pC&a5⅑Xy?d`!dDx 9jiP)2eJ{-mߧ0I@9% q\?v ⳮAI4fZa\I'(kﳐ-6a"OtF @VC;ur5!:DF8_nnGSݭ $DX5aqbC}=v4$|?ok"\f>' $+Tp uʡԍV`{ٽ`?o4j\nljBHw2"w=>SJ :byGL^W[r7ػuiYǪu9϶eMia=y9Qn$9ХY\AM%}8BԮA@O(@F&/p :sü-3܍~)/^mgZ⧜TDLJIZح$΁sԘw'h 8G(%Wy,]Rj -_3y_I׮b I{qvPR46h (Crj猬)k4meY(=J3/_l &dfRyI;׸5@* "[.9^`q7[etIe~O]' F8 B^jjYc*2jerh>o'Xn#;To߈p"3RG\YnۚڟV8|P9bC/Mj PF~F'Ѩ2Dwl&y5AM̩Wȕx$ֈq&:,*KMI)t~ y*Z݊7 i/~:1Ј?ܤȥ->f~[YuŶIHM^id;B9{7lCnpAg\)O/tipr1@v]9ĉ c~g80cFSrpP1&'P?/XzMAoa HU q.Qu_;1&ʹSQl9)e SP$N#tEv̘(`.7=WR ZA[P.%՞X:GZIk\"#Ij%BcL61 wr˻'WH)\*ˮ(dAGf++2_#G C%W @ VPiT&!tn_q֝u-PߊJOl2faN.i+"x9!IG𬮬 *aX5 MxЫ0(ŸK,n~ָIBI$TT)@ʪ$MCdp%݈m "#l Li88x zf?*i.^uNy }z)<ż\._"u,;02AQ/iE61 ;WHFʂ$SB_(d2HzDC(b0M 7%SAqFhT~m o,nVsn6wg4 w2 66Ci7!Z=*3C)|E!*4^0M(9K8/::/Æs^*B!F`c`NxmhharhRWsiguw'}dmPZ#ox#J4W[ !VXǒJ8j;%{## 6`lWQpmMWgC؀4y#ٮ=yn  T Xls)}V,oF<Ξ~ d%[ tT Lфs9C? {v L({kOWyvvMyMktvFKyvU)ՕI6 b:b\KoPeRft-x Er 00?qٱTXe~8~ wkzgQR漀pl 1!9Cm6drAcE VJY?~]dÝ~f2諸p[-f /:ё' Rݍ 8ӭfUπ bEVKsPwemԛLV}CWGVQI?&QÙۗF.T=7A0isUȴeDuE^ވ M^lj>Քwѽ_ۙ9^tak*8| ,?,mSG/s!6X%p|y,`Ƕ`9]jhI E@dCޙjhd}7>p sk'& }a&8nKa*`sO\$Ҙ_*=z6Mo:\L'W4SW8qFUpe U?;N;6/7.X7+!=u[dq35CCom-r/8/$oreB1ԡuu.oZP~[;ЌQ\sp/y+CA#XbvմLI 2tsnwSG Jq A)-uz(pB -&1etL}y]Jrx}҉0mtb~{0\Q|΍ Uhᴮ7ňj?2NH8_P;dNI4a ы N!?#.ِ5DR[gY`""nmlyC;n*!BV#J+>BE!tbm#1pO.f x-itJ*?_XԱ\AW2b]r^Ub=x:ңKaЌetm!͸Xv,MQ\v!|BiU|mHwedvX:UfrgΦff"Pժ:}~ˏFKw$7Q8푘ةBC"lᾬ{Y=?ʓwEa5ki4<[Jx;72ڵuKeO3'3696}RFHtvzcȤ0 B?9c9NKSS  j7G(6`/Nޖ X7+1;?C,݊лf@X"3k>lѨ=lNhԑ%&e/ )UN[{h:}+If_>x}#Ty678${Q!Ȣ2*9̾D)kQ51wt@jY7x1?ɋNσ I!qӀ@sCPِg[iyF ȏ25jp_\UFRʠ34rZENDX>!m1\0]Z5U }祥cCŏʵԑ?~aHD/Q}uMrx_{gE ~CfYuårj|&ChYJ] <҆ӈXRL .RVbt!e7#SUx$&\y8x1A4_='~kY憏4wtKysa0&dz-20'mzٻVڣU)ה0zF} TާS O@:a6±FZO/y*Y=O(Qo_6[ sUE)_-9uP-~kԦ^F|[DZFRo_7}l I->848#_츇jCL7* ͙B%<1+mT0 h`hxขߗҠ6S[=.T-$U)AfzNPuQTlCJ> UO!GE@v7QI^0/PВܭ郕kZܞ3>ܦZK *s~VHw^TG:VP}q,i ZqtQZ+r),;, U) n*?SZM߿Ż?EWp%#1H⋷~ms8YŮm>]8A;? GV6gj3|C־>v;V$ tzQX3˞Mhǜ͒2c uAfߡ Ngc-;9Oأw~M0){ XtY*ۍ=R(֌n7~S4߯ \zѳ^NmY!Dl}m 5&T&x1ydq$\>ͫmPx3е&/&JxwN]Djn\9¿xʇ !`U7{ۃԽFT&~7T H3-^Kk?gcI*@z sΕBv ɠɤ>MxAd '&a ͸`qeeqz`j[nfKhp6{4|2c6<M:jil_EKq*I;b4 Po;\2 I<Q g0h"_:`ˮZ!V;C#4jh)o /b7ㄢ1b.BZ_vW0& Uգ|~bT3zOHzW^e%(YД&'| Z^kNQګ>d0?0DiU"j*t!nwM@HEwXq SoyEѨPqz"-G_::_`c䈼 GT=[8֜w)ms,Ump,Ցݐ%av(UǽvJ8SQ|o"멺 jJ׋dO\4%whcY0tW+65Zi;:A !˱2fc 1^ϊk\D$CilToߙ!`p;;|@,&3 Aj4φ.N6E!eG$T9=۝s3PoJ˿<:䪌].$5s\B Fwʋ1:Uo`wq(H!{01Pa#] )a!R9/MB6a%oWsTOA!;E$HWu#e7W,S`f<\G;.a-%\B/J| 8`.Vmg0n͜{hAs ֳmՊT ̱1Shrgo3_&m¢ia߫12S^|wAxGJ,=,(ug܍0//&NC@ɦv"R+vљb+'2r'fA#Y^%7X顥q w[l%+JB]RO:.ֹnG&]rIwSS"MH_3m 4qr&]{$ĩdvͥS1b!lZ3 LۊM)tQ)D^sFb /-{c̉>k/2j%  %@詪?Q[j>͞ sXᎦ|5' g*;QSHHFWO~vc ؔ OXnas*nm|lyV3D3=]ﴓ@\U}ƸygՁ,:cTjq[Ʌ0n\M-sXF+"%r2Z$/5ݒ2:ߔEr.0A%-$XKXQw?j]xi-<}<_%֟T%e X;nֵ!Cz$i:qeW˚UL׶1̮#"dL;117狚ڮn#Uիl(a klV,e%`ġ0H9f )H\}q6" Fj{+u4da˚^+x}Hx4Fz 3˛zUW+c2Q3R7\:ui'WC]16^.؝5"^r} V"P-VYoneɛ.Ky~:(mZ5RoLȎR.?d`ah`l ĭld;,V)v-_3oZg50NQӔл>LR6,qJA˃-/);&k#_`."{Ev",u,sv7MTT~ه^3DAY15-Ąv@i*6Ņ.A^9ǺHm -H!}A3q #_܆ױgV:SеYlPq<=d&vLK|HSh'FRJN˷_I)t5sh"W[L"^L+@df(o#x u{w`@u|7g^zSƦJgō{$ 9ܧôe(.QNC8N f-ЏFԶi̿RB_0Ux C{7DƟƞRV`5$dC9SQ `[W ԁDzZvL>RTTM;B6&_Nz؈sꃆ*Q9V2[֠mBQV-3]S)ތaZ %f#=%:Q ٯ yhpGB#8yu,U!Ʋ&.(!'NF$)`40^Zѻ&nH Q=z1x+}pU.ȋcA.<]rF{v"WVB *|N>yV'Ud7kzނݓ̗K &!"Odn *jĉi.6Zu+h Hy4%ĎB=Ul K կw{%/:T?$G3h4[Z ^@v Dӳ*܋?\g+L `uHQ܈\t&v?I(lhi_RA8yGj-;RT`#xM6J)1YviH8t6zz. g+'i!(d]QJkTn3nӢ| /ǂ*?, "PT&נ.*Y/Y'}1,w/g<]v?jN16t }y [&T՟ZlN4ka)@&fa&̽q=m\g^9T+9\sÆUGxl>@+jڴ)iC\Y{Ά+=_ƘJTg-Ά%U? N`G="MM0?Փ63eL@H76_VM%mMҪ2R5Ijc]x%A|WKTA8zނ#%'A{/9nI욋qVk;(>IB"_3֟RžJ. Qf=F5~N\h t3㬐e.މۦ-+#fi?q+:)c4!!(zJA֓yDw]g؟xu@ y^ʒlZ 29@,n{2 69K-E?n3He{ͯMp"Gk1S#jrDeEi,&Q2)HAvTOn%PĴcm‡ʷQ >K-ΠY~v1h1;-Џ~Jlze3a9qI}?栢Vs\{SN0ZXңv1[b( 䏻15ݔiq1,"?Gv:;w"v/@Vۄ}N/W9h<* akն>‚L~O"7Ɉ'?0^$ńH22h*bϹ.2oiZ|똌)jT x:t}6D2u"*ӯ`YFoyC]IKtjJ+cRn~CgM?zO_k#ƬI? #ش S@5{%YsY»ZQW>Y P*D_gEqƛ*#VZfzڳوt :h`Xv@77b5T@UX{;?v.Kbd6?kNJ50M<9{(:o\dsPեDwQ`_jE8J4(27Ѻ{Y) {$`gbO̅4B~Tёbj|*Q""x¼IWc]ܑLQ%p ޘk/BZ)| fT}OӮ"C#u\X8;eķGJ;ao<~cTR]wrMm@oAٺ& ɯa=awRʫV^+qn\@֘zZUC($a$J48 փ? 9xpOiW~(Ld^ӿv%RmFُzݎ;oG>)]p.i{+ӻCȂJ3h{&鉞*&'7Ey lam Sx84؞#%NX8k8f8CɗObЍBȚ1{b#4W 9^LN)*졆 ? ["~{nIOs*F^t@@C|?h!6_h5 y>捲_vf9d,\z~ %'f[V .P|6 1qye^24#񣞿 jQע3C:K #:ְHe綝͒6\IՍ)C$Y\~[SS BxĎ`dḴ_Hj}F];KgI` ~ fC] 4stM:޵+]&4p{)!U ;H?>sHZnc= Y G5 Wb>@ LeU,X'JH$d'֤g;B7!`7G)7/;Tm|_vNdUf,D%\8=Ѐׁnj2g1J%zٟG.G?إPI!j7i/M3"ӁcdɓNyeC@"A|ʛXyS+gz|Ѷ$Ў?W31%tГP_j.z#;NISgxټt]VV'@eҡ9|ȮRtLn86w_@!䓷yVBo7@RS 􅘚99fasW8[EBL/J2Ry"JnΔ`40XS"HpEhlH+ )^[ց~KZ8'V9 /|E tD 9 ]鋖D_z2 foמzHF׀㹯4'`pz#:fg<{,{<`Ue݉,* .S1x盩k,ԲcaXCPӂG[h+F3\.7{y/,Mr=Dx!52r>b%`;f1wҿoBS\r"C)#t?i9hhifJ+LdFd^£cz-LJR|\cFb;Eb ވGv-WXKA8œhة##d˴`Z%so!jb%7K[x$/}ebʡ[N|^\\ɺss4Elĭݹ?O?o6h9p 6TNI[NerڝlxGQRkxPc }?DvѨECHMKQ skeDŽ qnl+DZ) I_Qb!֓%@]J&4luu"Qv.  (6Ye S>^H՞H&uMWzOq6Uُ^m{,#Û(Acc삏htȘ͚3QUF|w0%.>ϼkCGX1!b pڜs@*(5Eݦ5_d԰spҧ>*X`kvv22>Oc hӱT_)-B }br&+pikPgǴj.,y_<&=S@7JiW> Cr%t'qkcuĀԻʃbmi1)T594F`A +_3,jBw")ռ=%sء 7(J| L'cb E$--EX8<5ppt<;:XB+puZm̽\_$JDC(r51eng>Wf *u<àwF̌  }%]`~X۬GVҸ?eAg2×YBn굾ƶ>NPvwxa c u]^yB!ũ>rYґt-ŷ+=A(O4UfV,LC|uxUi "'E|BS9LpSn [q]4g>] 6r+BOsЧoF-[qeȩJJC: _ɐ`'#voA6˦#9`ѕen@Q: 6p*Y <ߡ PO Fdr/*^'=E?8:")aF VF^Pʌczci\5\=$%>{ZXh"(f;N=g14g0[՗S= /7@:i,X%Q1*[;Ѥ_ E\@q ˬ4Ke?WEMӅ+&F jYӋ\3L+#q1p*6~v#bR3rj7ӻc+G! M/׵DPE [E$mVo+ o0MPЄȸ:PP%=uָC? /Ww࿶TdǾ<_Ʃah;},&X 7 ڔ*! Gȡ`FqxohKgX5aY"\?28{&y+S-hZZR$R6зmvŽ0:+Lqfc"񶼶7v"@m)J݌_;wI\1[/-D̳v|!j6-TG"թT5᛻)սGxdC'@J I{QC8lO +9P5H?rEq hƖ!Y g8`[Qk>qBY^ ij]Cn(|WٹnNʬfw/]6w.֞\5ٽ@X4 ;YV|18v<^{^e#|ԍc)C%EЅ0c{CN ֹxڻBF5+d?wK3H3ӣ1ssyEPW,P,,~ZJWה<@1m~b([[:'A=7r @ v;PWt{ؕA7/uO^3u7@ "F O$c!>ܦDVwA B*|q37fMSOi1)sU+"ǙR7{& T["y-݊w<58?{8ʵ=|{h|=5 ?fcɖ M XZ-20i쭵"Qog|{ ǐ%`1\]cNDӍ53VF萃qtѐkQJ*SҼ"MOVr)*v: Zh`n -I5b%~HД^P6#tjS',ઁP- ˚+°0@rFs>>=tORf'6: Awj&Z5 l{nl5_Oa{Ǯ;J"(>^r#,!o;7N'I*V޿43,6iҰ] Y\Fv$ˁ;BdhRp#YI }IyL_$F:6ז&j5(rW-4 =+?F2v%K);4PYaT6:R f_nґԙ[d6=¥LZ֜҅ @*EѬ[dlQ>b`PHɌXGGOO;b|lWhtOP$~+߾襔ov(V=Rluf3`i^K)pK4+VABeNXt栮# `9 M[U85m%_Js(ƍM Sw+lDZ`E83ci/DqͶTGH"ۥv RIp"H,N:${`֚=~de 8%#]t2w閇U o6uMs% Wԟ<Yn_ MZh$;@ >IgTζ~sS&45q#'fbI#+&(煂1@DtV!֧D}#}YU4# F"C98 ^ZM}LəQhXO(./EjO Ŗ{:$(21 x:"ĉ{_|ʈBH]`0f[A^tk4+ف#}3v/ٜYb2"]P( Ia"arbMȺ'uQHњ*>ː+Ft0p V|v"c.OMhr.>c4G4 `bP3&5HrJ,F&"rΣ.LRBj{ ˒)";vV.t 5%䊚GL-qM막$x/:ԇh}/I"-LZ]B珯D%ݶ G~W1BCJ!w&Pwn^_6}'Uα۵6 ke1کXj[G^ų[8MmJEkܞgXwmYo`މȂ@K@EHH-j}U^lam\^PuBF|Lm!\*^, 80Xm J͂vPv WL;ӳyʖ{Y;ҧ~l=0:CU|NP i?"d/3(H+IeKyl3ou(ʀ{(/ίw thM ď\,NsgHTIOKJD*lZ"׻+cf˄0gˎ\J"%yo=j!NSy%GgG['0Nr~i:D8w}|֦Y^&[2 oiF'd!(B ~_Mj&!'>Lxkl?0 qW5[+#bH!zEwcsC^TA$n?Ru!(<ɯĔs6b5 ǂ{>zVM[Bh ]X8-q\ p34*{TܭKC $?egr]Je|^ T~K|PGNw߭ LSʒ?+s7 6PQqwOu1э3n{ζ&x"{{|梗 _Q:EuR!4հrpd{ #$541G:\YcgDw-7w*7oόbW$J3[LOピ=#W魋d?mqGCaIU)%iI khdݨڣ(TC߻A&n,h=y} $SŢE W˛SmjNUBzz"Fd#rybP7O={ԗb~Qŏz,lVca~ MdNjrl|&TDD\Iarg_:G9tiϔ݌oJF#piD^k* S& u;=#] -E{-xCVG',ONKM{;]mpF@ IeߎS7j[0Ϣ#Iхk^M e j GhshInD{߰V/ -U]㰈¾-3~^G(X_#pZK = GԪgLd<+?©Nω8`,^c@nܶ/uk;2Qb9_=D2 ~Ҁw`OMPwNc!%ef#!wS))91h0K&@$ok?mp֥dj'pк^:s)o}ixKxރ3 5RN0Vl"h(Z]CECתclyߎoG8hW^ݘt:2u%Ln;4R](b{R$~đuc3_e.{XDž3&Ϡ_/^^tkl:{h%?%ԶSkOUm?!iOn tj(a-zXc$AWwk^YIYL Q[CYB7%&%(:M6ptz2/T obvD/mCX*;\C\B34? ?7=7ugShRĪVIRe1;#lpgđF?fp0 NGK1!SVЪ[ 3%oOd IJOLB[Ռ؀lQu}iM^B>V}YM|9阻: @TtSgqk$'tZ3 ASd}_T zl8Ȏ9%.ég+ǕdH{=) $U&|`G[Ӕ\I!ّɨ: Zu1rN.|+|oSzڲޑl 1hDAviLeč8TH vY ivh`A:\)[J?T-idR\w}/ 1ю':DzwI_ o@>I@َ]-< %uJ1;UɋІ hVP ?-/#,갆 Z]NےWWta.| a ,<$ECө~]O )qw~v١pR0 `-i|0npYQYOUkb-؆PɝVXp<{X{K'8)/w ^ `7!=2zm|ɜ#B"%w 0zmQ6 [MM!o6~32Wa(wꩩKNG%;flH@RzҕJ]U=^F'Q_SKԫU`ev_卟`vȅ|טd0%$[^x71qѫOn05l~]>C-4/vJk-A^wJpszRqYZq @|=Us"pzޯͮ#: B̰Le90[ɝM1Syۧ3[#@Β -)&"rl-."u;ĸ hwHA{U!9=t¤!1i1|bCZցZѸ ,R}ve݆ũq:׶™!r5~yG, 3ObKPIZ[ib1$82>6:'f \\iPsc͋8fH3cyS-j}ɻBMhaj!kt sa]-4:A|GpI'J0!Ԙ6i'p?Ja%4"ȿ+-N.qEdyr7@uH̰"a =qiaiqtzYP,~X*UR F(Uxe_8&ʰ!eC`+y/z*7q;!%>yhY>lh#17Ny:M(͒4)" akFij 9:Y3޺тBqVL-=+xkjA- 8P(lMS\f*[x:krhncY6őj:lңЎQ܏Ti>C}bz !Y1fTu3+ Oi7{mnm x 8cM\߾5I$> '<P9Rd%mI<߻$e Bu75OBVNl]x;f`սBiM3.%w ̇Ad$bp?EzVbPCf/X a,9K?x`e6gś7F0u#OE]5W`kT&|/g :6@n+i[nRH}Z8旟\DJԡYh.axQ:NrޏsdRߦ4GHsGYPB<.Eƫ'G_fܣ;7yK]~L4xɳ\7쇴9BW^[o1.kھVi嬀Pģ#ZIATv'p3 VS$v,Vwi9W1P4Bfcd0a$:/mPR:#xbE`%D.+n#R߻"=m6?hjToH;ni:2ȃ4\e%1[ ʙnl韁dmpM˽2[z0 ASђb|m x-D7 ͆Soc?M!b>^%F),44Y({Am-%:7/!cVp!xu;Iyޞ}4hb7RoؖX2#9^dfk4s<NE=qCh&7vFeijӸ6/vY=֞"AL(+6?}N7 ?U@tΛj(i- ;rFXHL\/ՠȐ3EE9l;ߪ1F!=_f4؁.5 1L?&XXLXW?< C$Ib!]A W#[֘HzC|Uy `ݬ3>'mouq,tb,0$syNp-τp劀Ã-Ci%> YytχWLBLR@sTWW$ 71x/v6 hx˶FM&LM搞ovGRr ;Q31/t=/{ն}JqT,Ov#-q.ҩzRk$YR6-`'_.}OXbl:貿 f-c1Iuu^~[bS(Kٓ]CɰE,7: h#9E xw:$Fm쪔'WwnyKZɦUvkIXKEc.a[uv3&wTM?OX?UַGIjcǂ5i7M>5?T+/0? hx]"X(}`y2~dq~Dc63zosѡNTxI°L%e$k BH3X%{>˙~vt}`y;1+ Qj a\!AEЎ/c TۮZۀ:bxˊIa jP"#|*12U ϫ=-RYQ0 vdjS4UqU2̦P<]zFJ N =w hZmt:ʸveF^q~P6yGrZC=`F%2*RGuĵBZzm뛧V`u3:ĝkRNue6~7qj MNY|]4*jy*,P.NcTH_J}zM3zroНis?:4\ <2*DE#o?BX|p,bJѫ]~cz{w, ubpœb# u\4cӶEX/hYVcXe=iY\g5Sx 2.^^:MQ!wH=zS N(`&*<ǝz12˝>8|XdQnD.hxs` &{'rG#NC7v)lL1a&Fӻ`Ajm_:~-T!(]aR6D&- *# הo6* JRl4|iHyw)ʊU[ǸN(͉+caWp#Isv! AN.>,7CHuK|=I8eq!Uk`K ϝPOIۜAD\svVq#I}ēcJh MXeaE'twL)l8*' PqQ"@9-y-to=q2Ȼy0N~B_w{-FRunX6`FgCRh^mƏ+.Sa[N|>'y!#u'`V)mY,0{S#^y}UP/~*9^*G]/ ƕEx0DznG^Uk2˶̈~vNBnQGաP5@MS.Oϸ?fm7+P'- )sOAF{DY4To3iH|lQ6{ fKI Y9<\Rd˺W͂^ZX,%q.YȬ㸲{}ӓ5g{5w!'xpM~},WY FYxt7>o}Zh)'&ݭj nNOSIYdђȜ4SY)C|uAi~zs !WK[> ^H?V}:14 ȷ? Nr~@r #mSfb^ˇLm;n]Өnysˆ2DQ :A?۸XkqK=8-ϢITQIft}I]:5?^" ,G1PF<4G\) 8'8f%t`lEv :ZVi,nH$V"3ZpAdY]aĹ4swpX颋>sKį ^kZaniCϒHxR!xQl}wÛ.FͶ!XE6a"&54zZ;V PO-I3w_* @'1obVhcW |51G\-U4\?>YF\Ez󿐔<\`pЇ;;)m1ݣl @#4垻R{pQ>ܜ؀gViX\)yB2=vHF h #F*e~e+r#^hptiҍBS[xû7H`qz>ڬpJf@XX?OѣOCOX= LeK(8;l,ҎEfL+efk$auc8S@p*CtBgr&P☂ޏSmͽaKD$c8̈j'+TonV,,J̕c^IZfCG;v0 TFDֈo3+{G~)5!DBְ7 &aߨ$;@:mmAd,!` M`NW'x{ ̢|˂.^e_YHH|y%wgT|#&_KUD%ZJt׮%4FC,+ !REQ (8GrlH|2c*W:\3iw7(2$]uR/Hb+%ɶ~xԀW[aE~{>TdxC}ЈNpTlmc C'`P> /vHR]˹kB/_J ] 7ƘC;t8唎giEF/MAInK>|?Ts%N ,}˕vU .;Z W4j>NSrBʳTV\cM|U㲛'Sb1rr{˅@#x Lp\)DlBuimpٽOˇY<0ozL_yWQ:<Ɯ^)ddu-1&1y 4}N>: B[?Z\a HLU2$#R t}qɷk2 2n];_ >WG<s#N8V_w5,E-{KYB?^$DVƩ)a"ԝQsptԿc <6e Qr26q MLZQI͇J"R+A] B6Sb|?nZ3e#B:3s?7WJ,OCNX^.?M9}z6R~b,^FL:L_<@L__odUjlsImRvmG6OCaŊݿ׀ob9s}ǵ:s ,Eg h9G>= ŒQ;FXK!l.HͽR p.[wxXpt,l<-mʋ>0c`u}b0iZ/MzѹLG2Ynr`b"Y<cD[8`d><.{$SPd\@LN]|w]N4ӥx?sox \'"T񝆎G&r7x7H)[}ʼaZ u?]x=\KɶojI_rd|'XӤ\)!&FvO8Dn%F lH2T~3_ M%fE6pf.̦xE)Cc=4ԪL6NkAơѢQoOHuB8KU.0R$ ? ѡ7KD`J$[ jR0,IF?/IcNrs1, XڅLl(Vd&A yɆC41`(s~Vd;*A|ٵ:rsW48R\>E.^׃KibF7|F,SB+aL㍌n{m[+Vi~5T<+uH ܰrH*LF9Lӯu֭SM 7XVQSThyJ~7I!ㄠ2ۮj2F>_G;YÕxs" 3TM:*-!ת1AY>¨]*Ȑ{SOW)}‘L7z=FdZ`":F链<\0>o P;hHpsMbBaI&c ᑈmnlQj|quNczϑIKB!9ieΉK aC '"W%c uA&'?*gAY) Ɲ]pǘ'o: 3JWlGn%3 vrxHkڭĜ@[%֗M:D+T0-pw7%C@)!.,-Z aӊ/1-w2݂xM/dAK)3'Jb^c{MX6<6)*(΄n׹Vm<͍Ah.,PPwnboҙc}-xSPS]1UMXP1U$4Qi Ds hW>rZ,T;t _r+XK%ws-TApχAVv"~duMzf\+Ra7爵>fK)yZL:L84rN [rE,LnGk]ajA%U~i_zhϵs:$j1((&}, u'_ar߬2}@$>t8?R2^([^̊8N7qEcBf|8l1 MJþ5esfzhK:u;0K 0eV%mjc ٢n煸"말a)[|c8$a\ 7t!Oo9fvpt_$ͩH|')5f~YPe[vNQz4ou7є!XRQ R"˱]FmHB/J $[)Es?$W3IzH]lmٳziiyPVߤp+!&J>*T= >'vN]9W'Vu)s=#ĝUV= J)?}ϲ|J4?Ȋ| ߾d<Ӿ H-gqaS39SfK8-I!ʬīH`#H_F@d@vf:"noBȳeOdN  ze0,cv>,kq%c'ԪdvޏrȦs è:.joDyV(o:WXק U< [dA!zX%NH0x;o'@6a!|p,(7J(F{_#UCitQ)2=+4UcWz#&Z>Hsqƌx m5H y?̃ dzыyOA-gËh'e:8_޿}27o(w=RvAeA<{N7U0-v[c&g$_",r:XakwG Q,Vصu&"LPs+I w?gxVN/9yiRLwYNm])cYi( 85RnႬ %lrM'ޡ/3pdzm6G!\Fzu masD`)2 ^䣑PHx[Uz<B;얤,R ҇ V r;{0YAϊc۶Ůk6GGo~pr8 J)'Մsd ׉nԡ:c@&p-\(KBY;&?Cq:roJkz#w.MxjT[ V'$J#49E.ٰ$K&x%[FO111ض=o#LfiRw]g^_yd$E Ԓ/ԕ{brAKwĭhMfBFk0FtzxPci+'iתh<𪕥[M4~Z |Z OѮt&Nn\Bhe[[h_1֓Ƭ~_oDgUX r)A( ݰQcqHO2$p`&>Z윣>{(Y֙M4FEsQl!E֒=mw5QZtd1O`ăiM5޵~,â?7~͢uD^F؊{#p*5ӯPH\S+?yJEf0P/,ZZO2 (mOcqJD)YUn48Q,7 LWwPRdS}9'؁뮒 sjv# ݠNp^=k7hˏ`c12aYDLIڎo:5% m;jXe'ՙ( ~x~Dҕ #mIu L7PtRIA(V$Fm@DʃB>= =Ǵ6G >I\d8k-tRE+S<|7l[^t wfpdsv9`2YXyk[gW .+U Е\#582^~sggpˠOgfO L *76oGAV{|Ҧfni*TF^燧~tvͶ`.E;7 NKKMb 4@0.E3zH\Jx! ̢SQiޅ<{w^@+E{G8$Ʀ…fsH6*ai>he"P+xQnAǞg~WL7b\h:^o4J{:t;0Á*ܻB'/ٜSEnLLUt_|R]{nE>ubb'ЩQ#F,'qpCѳ䞺J+eU4:8hhT')efXL6Ux1{xvOݿۭ\rR=ӥc ɢr*x#][oޫ84<4(kwۢwzGP5+Vy$_UJIˇ3faī9* ySP81K}M{/|}K oyR 8)8뜹:f=3&U8kjև/g6m<ʁРeH;n҃@i ON $@'D38WsRc|O9 ,B4כsSdmɄ?#J[ O겕-GjuY noGqJ{ӴAØNnOgqW*b+|{dp]R$VLϜe@PVz{'Sg;F&}Q.ۄ?,9cM3o#ٲwk1ؠ}0c/K,1#9* \C"Xx/` ; [݋-9D~wnqT1;Zk9l82֙N X!6FS*fvu`|.EQe8аy:sA(r6Вii_xf?]0 <if)X~|-_J |Xi{ؾ oJ>JN6uD9iJdbqyyOapT|V9Ш~Ne.v6{&GV$j3?>}P+7;+kuLC:K2AϱC`9ſD0F\IE70ywGpRs}2 ^I>8_+? ֡<-Dy%xmb 㣄D؟}My"o:tw] H|@|йkݼ_eϡ }rEg39F퐓Y",cSع?Ys^v'Ti;l6:!1=~e"n; iJvJU jWZsƁƢQL oFč_edO=ɤ"-k*|No+O1(!ޒSٛ-!eJ9C<C6ɵYRe"]k2ݭ[;:'5,+Si \啌ǶNHdaϼ`vIZJ]"=m6즢.cǥTx5@,[Cm-ߛ9e.)ׄ⁐wW#&5_y %y2X%[=>$4NP*fe'>W#]oŲ)痣Ǜ΀?Fe"t0j<*T_2R\И,h Vl,*A5@(wr:x;i2L0z@h1ؒf*8jHiV4LЫx~~pYJϤhCd)]X[5òQz̶i~T}jυ6%|rjҋd) AC=h,+K0 533_SpV'.(g!M.s-9ʀHU΢[(a0LD޺ؙ͐ W!Ce;tS Cn?eK?jR$~DCJe^ASN{[B/A۳#Čy1ɟ'k*{{>ݩ'@dռ{XS5Ɯ+ɈDG(u8v0Zd6(oGⱶviG&J4 MŷӚRt'p[+LœbR+$k_0:Rw.w_3Lz5阼惑 *E: Юg7fpO@HiilvW4<i fycIe?j7J)0x/mS[sXz';KwHR8.EmnֹHWY<7)ռ}.^xJ$"x)I QS}c1B<)Y^!"rM,؎auvM} R\9 ;IgVͳr&9[ĕ$\uE4VJv DB5Ml)m `z-q!rpϜ0_ǍXN~kIM~jDB" Ҳ!g\ )8»t=6g2Hۨ ]GxItO 6-EF_/z8уU.HSLv$M)XgɸI ct")AGgC(6:/,(sj> +lQ%+3А>]W %n4td$u D/Jf v?@4>D:/E,TTp'$=Qc0ى}+D_<"LL>zY#d24@-xK]oƯm;iT!,Z5CCHYݷS|ZG@{NZSmte?hۯɌˀwWEtL]P˙N[K-'PaŜWFW\嚁.IUgqelT8aK(p,)xg;KGCQ(q]%B4|3uǥF j4L:*Nly[A?xZ{3r/$&se0腑5|0Z`T(=dO&0U'q\Z`jgq6¬MCn[[ r*ձߞS]LbM`iv2(kՍ 8(t/p+$'Xp=O&yN4J #"'EܨP F;khwW@tV ?qt*"sAvdИ 껥q$1uqcT7Z2X28u'-y GvE#ָ3"LnZ:jB1|xSC]_}:M=*z?Е,gP)y8-*[^t A9ƐԠQ̬7nq]߉ˣ9SDӲ:(jse\C@=cdƴhw/Ѥd5$р&4 ix!/J 1::;5KN}M%ѷY_M^͜v~BD[\]Zzj޲c̓75}S}0wlvc>*TJ谻jTMR-%A ;} rDÊ0^Q"Aa\"ogL LiXԸ_Qp/"ċI{{W!ІKeO&{ۇ\mQ"Xn}-|eH9JRDNXةr+`/wR்+HwJDo$S$R{'s"U8 5qY3W!QԄxfDTf9wpmϿLteY Yޣz%' d㭉j>OLZ)#=ԡ1;`\|[4sqdO/nD(16,ίney.G@">j!H\|ʆE"F=DR`T[IFj}zNnKuX(4oBi[Doa):JC^f`#X=4btDs E'r;W6-F!}xhż˚Ɓ?rE52eET`kۭ}K;Pxp W<Bnq)\[`C[*AK#W?ph>f ۵(0Bɵ#~v9PDC\K[t;ڟ(l a Uچ|?)_;s_ 9]*_]<-xO¤N['Hع3o#=-둘%dNҖ |yp-Zpi,iF33)Ě樊uYd{ھXߑO A2W4U^_ G|GFmh2ǂ{߂ aM2u!DkU!+,s/ͰYyj{6 :Nhvn *Ɇ ;Xo/x#sW؜jEf_>:eqoRR+/y$y2j ׺,5:r GxwMq#V*mnw83X 0I/΀))t!&_arm",ytPF#5ۚHASŢssnSz\$^J[nٱY$OYa:+jl>&gQ8 f$ȟTB/J wE|/ҝ:oʋtc`Y-^;~u]ѠYNKŠ6 8GOL3n+Au/}7P3GS (XSpF9ėRJl֖ X,A|ƌHoEI U;x}Ot/-u+dA6!s,,M;Z~P`}_zf]||onӸ9iaߖNq]PxOTbmcZLtZ!ޗ+ynY-t DgSp\@/&u &'R?}^AXAC@r&~ R/8)(?˓A{ZL|@s-{"۫7 _gk18dS1116Ჳ w_W2v.c)猻GEF^BϐGpgPmW:, WN+7PxQ^S(Ȁ \C8ƎC˕VQUi ^o{jI++}$4rĭ5ic)[&/$sZѱc^7W-Qm@<Zr;[뛔q < '[ہkhޕ \/ٸ#lҩ]Sm6[з fPivdmr^FhK }K"'#rQڭ9DiWEwlL50>N-O#L¿lo3m ٞzIbZz )B!罾lpww;%훌@<&;:_;ks4QhHfjl>5>JI |pX,ڳ]苼5MtPΜG-d,w DNSmfYχLYY<x2u5W3jUr&n/GTas,~Pg$˶CqRL&kpʑ4{QBR,\c99Q!VVbr9n#zsJM! m*$=,NyTN֘߼ԡV_YAF??tmgrLGƢo%vOKi8 /Vo'b:qSȪu/7v<ɍGt0*V$V<ҢqC `UFXNFLWS=Ϗ"TԜ$%1XO[Ƅ~StpX>p8~hU#30c~juud+?԰:xi ,z/3iiJцj'369[:/ ׁnV+5 [*H]ޠvaD!EBAꨛ$ъ9#yjGVjw{ptw>OMؤgʗʆ&r0 T_ǑJK|VZXA/e/J8<U7Ƕ)^c? j@8͛v3b[kӊPS%2Mߣr;^n`XE(+7i8?)JQeUN֑Y$Aߧ)*;t~LUcŀ21hGR 4T`\ǯE$ˬښfIL4[LߴNl6srY.]Mz4aVaY#}MM`VV3A_Pj9K3.ejSCwӊ:mO@Q*0Y4lIߎGb&`evʳg?Q),h!7h:0w,SQrOUZ /vqbGݰykby }!ERJBS?qŞ/R k'$ !t5'!BK+eG)CA$!f J > T+bؼp~a˼e gQSh84ڳUuI %%aivCP+tg]LS*֡hb'].v̐yoXdD6\sZSϥ!g5+c).GK8#& `T!M(\Gكh:#CzFާ?ຶ( ܴL:+~'|:>U{E;P+ۥMXRf,(,puABɇe⢐DhUuXpFWJ?D>,*kl l<4%=o/^. [hnXwpᒂ͔ŏ DoO#c/zs(0+v<[85"^MO1g)"gёq1QLN4/ߧU~+U9!w+QMR/_F hR hmzꨢ&-P8#RDGRպiy'"RxaSӶewHD%l #\D?*Cggm IGzs7HltI|+u*?vSRY?_yv->3Uƌb3;qorʓQ'cR4.]; ^MؾmF0kE+n9dDQ|6g-A=8Tg0vէW-H!T ԯ7b(qxs ?M N*n#͹HAcnw;jE? {AbSTtKI8Tf-8cr%8c?e0*t IAA}a3`4cDq,@g†a}.HDXQb">E#p~TNtBqAYBb*r+}7$Ola8 v7|X"IIZRHxXdfaN-6 ߺwSۢ$S*!"4.ZM%CJZ_X"p]_ tWNɥy%̡ d4c PJ#;6Iw@XLhw)T na,keÆXef-o6:ڷ{=MMM=l3 $ő ?Ye'h8L!Yη@'}2]eU3Fݚ@g0Py^$Q.H ݘֆa0_" 9߃#QAG+}a_9OCs,YA! 9+EӛT`9n2%\OjTWM*9-i9Z?)-+<^zxMd/D+wQ!$Wڤd.VzC_ÝyH6uE|Tx@+}$10P~kTׯO?3YS0uR4}R>tWjڋOֱBuos3A~uk^:`P^N{FsNO`lZ=?1xʠpR<3AZN@&C&54Y$=eVӁ.Вk6W( LAzY&Sc`H{ڝvfb PUW6JY\w4ӏAr0/M@٪r<*~G.KuOf#lzVC,x@5 .eSBi2N|S]xdNrW%8k_fZ@r }tbeμsѼr c2)p"jn_J4b$Ui D3tδ|&o̯1acpS00_ˆ0Qs2-]({F۴Mȭo,#+XCjzLoUKD`e$͝QVZ ⚺3wI`vEƣP+ʻՃtꕢ6DfsFw R`r&ʇKQDOj|.p8Y@k*5 ;y"u`P7ܶޏؖgX9@V5=il[_BgaڵŦa>a\A`F`BٱX-14!d!sI.:!BDm07et~fc9 Ͼ#/;EWN( 7O&LoKӯRYm˪{|QS!k\۴vxY&rSvN":\;_3brJ8A`!Yj1YQesQ؞򭼥Gu d#O!m{w4"t*Z>F̞g`WX+0I$kpsz@ X2鑅S\_&Wh6TldERGߗ$$6|+}x֠Oz;uϞA3uu0sE2>K?<9ITʀižE)%ʈܸ$>X0ό[{u"Nq3T3P%]'}U_4!a^*3J#{RijD)M28+5n\"Q@ 8 :*u~8,̉~{.xvdWMPx܉56O)Q*äO"Pk8ENc!nwviL6Iۦԟ*KT Cܨ:GtnF\g%IjcibCJf~8΀j oޘ 2<%c9#FW?rɮBT)`pS܅? Տ__$ˎ{DM{H X}D߸ VݗT1Ǖrϡ: ! !5s,׉rj轗o%HX C_G<|q!PLv38&ӚS] sT)CG82Sd he\1qmfJhۦo7"LuͩOAg]Xhfr>u6 ~ sh}nߗQj[ Q`!XS?"QuB T[Y\R`hsfLژҝ@XϧYebA&y4{V@ F3Y #PRf)?Ga|@y?λښ-҄%wDvh#iY@ZdyL߷ђvԫqa`l yi-BK&"3QMn_$֣3e: qFܶcYQgH5ZγYJQ/U6k5r¯/TN9yQqT^MT;_]EB !/8U׿h>/C1?A& beS1 AL3A Ŧ>휭`]EOMEi㏤` 6kruX^bbl?gxDY NѽKVƸ #g[NߝɌdu\&*(j5L:U|XҒe?RHI!um2s*s=3Oj4RqBl8Y[):\I)柔bDT0yWCܖIBd|c%:gr͜M"䎙:cR,wb~~ϙĢϥ8; $^Sv rfLR).Y@x d34q(8*Xdf`̬cv`PyZ$`pFAz}%P\4bpuS \9#p(&굩7eFy^(J=BkQNF*QPU-4U3Y h2bxl0v;CmYhD[DĚ-$!$<;K t$|)||ͻ1x%|FINʾs1Q zJ^?bOSpa+pjzG߁ ľaθp,wIOQ7fBRȴE4c/!F[zdE=Q1FBzo|6ć,v XcEL2]fOL/fn&qǎ0ċײF$йW2#& a{鱙Ub4T.+ЬJJѸM ǝ.MS|nL56Bʴar1|?}VpG"֎^)n/Z)wxD$5a!` Zw\z{ӖC,1{xDa=?^~L X*f7f­unjEbӭ+Boʭo}Ioɡ@g xbrd(^SȦG𘋕7() ~ѮN"~0jӮ!ETL.jt6KKe n+/6 +]dOᦴngb U*O@Ԟ>Y Mau&PfKfm4LGSN ipj?{Ҋ;^#ײmg>+B́,,e\9xH?t@~x )F#AIT.&/~Io]kd"pǫ޼cB .OY+!l^Stg kt H<^~KvpЈ1w{Efpy:D/}5H IWi#/Ɵ(qhX($@i[v /2( 4K8{d6Y\:k_2Ϥt~ӼG23+1%[l/85-&AutyesQ{c(80em+1ǦV]1zdq@<a>§JِTR&Qؼ&f?Q]ҫmV,r|JXѯ:9 $=_T/dX!rQʏLUI+D %AYVmx)U?zq2^[t ;{"hk-կWߍ,{zmC{7r)d'"I`1xR^G 饘1?`*I&u]р 2; OKԠK"2 Xm6%oɰnH)2W /-̤Fx#<2)| 2-e཯Du >iu' ~Θuھϫ⬶n)ɑ'H^ )5B8Z "SKUd|osO+|unaH La~k Ic/;ak*}6I{6w3n F?݂z]M:d}_ T*qY9;*rFfy IcZq[U=,) '7Z [&.H^sp(ӱH. Z@r~iW9ⓛ\2tN>ڏ.a3jE n֬պxku$HVdBk KnWqsW(/mP%˶z_"06NyUߒ{i2 [~,@h6xZX sF{DQMC8VZ}`GT)0$2-Z#,wZzSSN8m s|P#ї;)A, dzwXlts u ki;~5JTO~xs&<9]>"|?+RvK"_ tVnNfNN:wO:"igL $tnRif> ˼XibҘ9;RJ2)u&Lxf)m ]G'5^=L³)\Hgkǘd>CbFj^ ~zm(Pw?a`؊DbQc̞t ]SJdEoFs>D0q_Zvq"~%H sgYCad& A -M׍N{Ṛ WK}i2#BbMnv);F1jizRhd痷ITupG * C(T &]'zgw1_u$۞Pxtd;±%ôCb'DˍYBM&(1NLSi輢,]D9 z@'P4| )f 0q@1ʺ#vA(|*7oca`J..(/B ~h`Sl [:!+KiJ7_e!-wH{E6ANY׈9$knv0'eާe9ZۭcI%~=ZURٞ_>*mqDja8GqئRp `a*<:t˓0ap*n\c= OMձn ‰+F75^(}%Ԣ}$[o"Ϧf/am07S A} lMZ٨N3ƹ.at}f{QAi+ۡEz]{6r~CLX0neB0i':gŧ N4ՅȊ' C^c_'4j#lsE;}+čyܩs\If5+ \J>M8?o!p d"9IF1 bMoEL[,Fi'Pb}fn K8j}{Xto&D%, Uh{LȦz_c<.'MgfWYFlMz,_5v%#WHOPL NuI__ԁm)pDc+L %אCJ7{("y)EF_52{v+|'7q-E+viPʬ 4K{kUݴe7dI >x@`n5{?yZ>MGoAeƋ§%TbXd 3n7n$>[gg=&&uCCvsVRͭ|0es1ϒV寲0+6I郓 pQ_j'S )x^&o:+~ȹ{Y3&/PnFB Ռg> 7$415C.ʨS(PwweMJnJe(%= 6r/SmbDUܳQMCUPBcdNmɵC(Jvж]čQt?xX48.&Ym@ Ѻc`"QO9Mx  RN B\_N>*c ezMeku=d..7Qƶ7 򸄸4 _{8Wb.F2\#9UJNjkwR쏷 =[%'~X]M>tdN ۠} #ږ<$ Ь %{yqqKȐ,,W^[3͘н"=}2VMН2NOԿð +Ay"EeA$Æ5-+],/}kgSUֿtopݟpYJT\^Ҟd;zfH}0XSwH C0tllt}( bTkJCiܒ.5Ա Rud 4ſJ1yU=xCk@v`-6,r3*(A˪l˲F# U=FqAK $0v  8U{Auqȑ.R= (jC++N)#ºPerdmAgPZe)-u86Mqޭ{NtRݐ}|K3qGQ)f'H A'+yv '7@xӠWO__,2ǭ&8Ґ\s¡UҾqe8i$ nC>9 S{s0.r/3l!kXdB! #4Y¦ ,|qփ2>zp. +c׉n~`䚖KX?'֚=S)@ Ԓ)I *# 7=))wcɡFV&ATЯ<KaLS0r0` Eu-uzG=29F{s(M,DF^۲-VSq3[%]pä uÚLIi8' qA}# Xfí g+??{REjY᎗S'i熾5rlH֍D4Dɾ$ nI$x釦^^@=LYS:!H$/M%H$x~.VWZ-GWg 9E|Ō)!#-'FK.Ii[kJ9L_Zv ` ˾0qpY@X8T M" @p=lcO9W(Mf uk|YBVʇ d_H1vy &ϲ f,&P.SV{mF9D ܮ{'x˹u|Ͽ-8T/mscɻ!iBKl",FZγa]y` BɅKlz !.Cf {nHd#2h o B-_ЋT9n [ıN!F9l@Ǽ=M*E]mU\ZUUQocY3BAV:=nj6$pO勥7Wv?yRO1m4^-V> >%:n^O}: H#aOmȦ\ni$ ǙG, eGwv@9ᙎ*%1gCK ~.ހuF!|3|ں1ZK,8|c9 wIrN>VϊBoPahJ `V#Dטޏߵk(cohqF5/nϿrC6x6o@lǪ^ #/pMBջ (B8v~khY^nc |h%:j(Q]i&n7N^zUWb0{] FHVNF0oAe[BKXgow=% tg.stV3T-]vLLj*<$ω=A|ugWzbnt?8%uW ~R`w%1Yh kכCkd &'| bhlU..cFa-3"SE#\׬๗A7 Wߦnl(F g i"߆ɨ;ؠr;Ɍtz\uZ@qqg4 QP@9vڙaoPD mXs0+L_YtIW4>kKr1˪_2XsFE4e6j%OM_]2zyVQ1[<)BWr'~cEQO']6#D&KӚKi &,_[/kUH- &:T̏y W7 1HGuN7b3B(+;NX}21d V}FC!r] fB u>_#<A\]xCάlT .LpݡxFcG>"準rcƍp(;"oeug 8j_DAY7ѭu){{>Ӏd .&h`$*swe?b(F11[s'-yupT09_&N/z t H0q")#3}8dz͛ ze~OC8Zj ^n܁s ʏ tܤY)Qd"2zBe|nh궻+.|Z?2W~|azIVWNgyӚ﬛''#mVt+TƢQo7z|h/qG``4qM3AHL%u[ F2 =f"[ u\.:j+5f%TQ,f`wٰ7?8)]gҪh)vN)'KLw3׸5H_qʿ4hJf]δ!n5x~$H PmWBרI_lɫ8. (AL>w+Vf{!vDyi_x"izOΤeg?hj0s*|S*Nf= 9DՃ|u U\:m>iUkG@sZ˸ xל.VY*m&*)Stuʝe9/ljֵ|ij[&J S9\z3^Ixj5rZÉ7Hc뵨$XքD(9F#WQ[%ȁ#?P+mU |E| >,#65w S׸ ҏM#tCʟ((J#oҜɶǪ c'J.S@r%g6.͆udv'iFkGՔgJn3{œakJHɢscɫc{W::gsBu+Xz_%^cGsՍq<9>ػT:g;Uf>$'sLLT~3Gu"nƟѬpM.[@_ {w42b*pi8$1_Ϧw'mrl{IyI [Kb#:jߝ)i|r; :#CQlY:۫x>5cխ|hk/{6gycxQ}:*lZ)OtQI*Hxile˕gmcLn8oU&R.l!IJ]aMfJ}'3hm(e5]"fhB8d"LMi^1F_A.R ӣJ=m&XP-vHېưrX5{' G;Axu ;1?a02\zmRAQS+nVlSq>֟2[9wh]z#oCjLj.v}@=h.3Sm,>6SՐ@[f`;vXSCy# 8uf0t_&D>0O!/ iBUW|"yT^Q QF_\-6^ ƪsWzoC/ì+yRf~芆wF!"׷D &U.Q%@ð`W I_q=6tTbnA{ox7܄3G1muHR@>p8P 6 GȶVNf\6@lNbt٩ $#H hȎt]L*%6cq=&tn( x*ח/8֑,na<$ p>YȤAV+Y 9}i2yB欄dpb4z#goP:.C"ŮD@ޡ` ؂8Hl4ax僧_ڡ˺V1AL y@8Q9aEU2 %suֿ'm"JI+LQP |[C壶DŽM1ꀌ`/| _sgcʒvqqiHvª)Lv"JTI84S?Z>T~0,g[)n[M'Xl^!cGp]ot] 3TVqt_&\ d U UtwҞsO T&lV{hˢ&dZM0T~Ҭ|_Y YXW8NoQǿҒmdP0\xb$P $~u`8 5>?ռPsS3W4S68q]&08wJm5wMTpvԱlKsI~6 qv*0iY0L3Լ۫x{uqTzpAJ觬C_Fji/?DlPQVd(?TRF{6^TZ9ZmȞ$ؐp;ܩ-.RG-x 7|9 mO=9[ =:t:q)Kgbb7xQWB#P uEdo=X&S$UǏFޤQgn z,&N6d5>vTadPV .`w0!H1@7^ p~Ɉi=I>42mۏB֖vJvfփic Z+ܠi ?Ç) Tu1E[>],X;Ď9ڋIIYQWM .i4/ǏAY #F9)+s` ^K힏7W49$/aX "N-Ҏ #Wlj٘L8ID43]Ͷ]g\n2A~ݡB IQfxmj)6$)A8+j:Cv#;Q\6H / 0.hKu7qrͱi /\lw.]gL5L5\&ye~'`ڋ̋{aiyEْ^$ )jtal#w٫#@sa*q@crsW)wt,? xG;_ۓ I׵9M9vqaX2>qXÕک P)#ik.{#/Ȫv!<7ǚUȉ+D% e;=׺i$/.{,׼fB3R*?WG,{k9BDDn%$Q.EWTŐWLpcc#?2>]YN<2H>P;:,06r(|qM=:ⲛHU})gdm6.5k㓋 ^Tְ,Ő"1I=RHW*y4#XC#A>8Y 㯯Qp3=1/7yt㔎K/O^dހUƾډH#X:r֔1ICe6ij66ൾM0> 0&*z\aJ̽hĆHBb?%@$uNTKѭ3tʦ==ɾGS6&:7?@wP_*#9S:-B:@nӞxy_w2l̗vؗoF.1A2/+R?j!q°l^g>.."!7] HuTs$,)gkr>wu $"J2 .+ jG驍4(N`sĦZ`::QM:U`%BOm[CQdF*ٓ.<\:_e \=@Eg /Y < R^y;E~sQWD#{Uȓ!1^ȉo8~hË],Xc7H[:,Ζ ^Tf34)EG*i:^PxJȞ]{lP؃CECي ggxURx|j+vW\FpL :5 ,}܌9`פF8") ,C]Ĵ\԰`懈i1"p 9q)xaN:>Nb_0I]H.ZݗGDvJΚ10eH2EZV*oUolсSk?/6Ne"&46e6zmPjsG<ճ0\q~MD zN(KkdEu'RV=R@6q) 7}pŸl7cz}\9}<,, DDQ=a sYL?,a5Ή$Q0 iW;K2W3/W^42#ӕ)s xcp0Q :gӃ{tAh&]yGkɆ}|uQN)k{ |dzMYˁi+\k"/ͪSfBTV"e=j>\{v %o ]0q#ᙹdzql$siIĪӂҡ +bӰ7.> 2tK Jvz) W5"b 2܄@RKi짓!ZaWB#æ@]B@,><3Z8;~%W淏^ p$њsc>i…sP) m>ʮf_&H V=TZh\:@ ?#zTGn+E27)w!c^ ʊ!}j QRMW<h_Cem<u AV(/<:E lyĚa% K%q}b>;q\݉1PnS#ZRAȰ&v5f0m.9ݍ>|`+ ٜwq+;EN :ls2\x&=(ѧJk;@2dG&`EoWGIMIu Ne2l='ӂ*T"52NJL {4TkZw ܝJLQO8x{)( gC M+sGʹafUR73^9,cW3Й'%Ԥ;:lixD'U]uSM5pQ0:[$߼@r+F <΀Bka15[#*QUqR-^,8Q!Wdܘe uH,ǹ;ʅu>MTy&bn;lY} zh{롄lflTUz7y :\w',R`Ȳp 0xt/D^vZo3$,CHJZXL|Fʗ0j3\!qJy(!z)qTŷ([κԒTY5o3uw8#ZM%Mz7COt.Ph?~" }6^]g6ZoՎ$*\UT=t[.;HfAX_w|*&RJ1{V Zxn/ N^Y: Yo:{BwCK!oa+AMǓ)ᯊfn $oy_#IIs:'[~%fbvL1Ņk'|ܑg[SԋOUK?]<+d4_/fUCv 2dl>jCjAqC"fszA[jP۝9k !˚_Cb15q|=O,dk"Q{3M#bl 8\¯s<3hC" U iˮ]nk]H楍Ea@þbbO$uyW;x`c@(N0adS>2q{X`lH@)oGF*x܋@ wA0RPTEZ/_%jHg ”Qk펹۠kQTF's#<:é(w:'N6jb$1?= YrD?oa9#, s0e?g 'Tw>j'=ZYyADFeUJmܿ0nDi\mvD4$%{,_bG%츩ӏy#ǀ|(L!b1`jkte+Q,~Zh#\ QJR]9#E\ a2:T20p n\We@ٜXt2R>#Teq۞Rpfh56쌭V/=껟M@q,FrxK87 3pmavO_ݢ/?f)8ڨxC V8.؜ P$xA$R~ߊ}*ژ,V<]3/AupځN^3c[*-"\f \GV0x6a +Lc*-۰flކ(WACeY2\u\pVR$sÄhAXۤ1Gb-e'jJ{ 먿7W~^``5 ha)ɬ=zm\Kۡ]ܡ0/6W;n϶j+B]6>F(Iɣa"*S[?6iTzr?ZT~f23PC/[2ܑ#ZE1r\t{D]]W[LkZ<# .DYP9\A)hD/'1[Zd͖xŗ(GUFzAme(/K7@Siu5;<`{7Dv GOgT1:0^SS7 {t ,}kŰhs*o֝@koa8BK]&:O,ѣ9cn K4Dq&$.o/)iSj3f1DeD毌%M}T/^>qr\oEÍd;} 553b+~83u/}/Փ}8ZXwgUA+AzیNl+yq,ڭ$ 0Nuo}P0\ǭ(Ý2!k$mvc#2\"oz&+e+3G I><뻹0HuӼ:9Xzv,~EAE,#Í1,'l=<\0^ezis׳$?˝Y_Yz1j*\͵[su+:MXә "kQI}oWyr-e}TWU3Jnp*,ac]P+8>:tm@xfcҢژ\)-FݜF8DSu`1Dn\jbD; ( tr1`3otiHO+eiw3, 7"]dt1Sn6UeK5+Au72^ .>,l&/%Z4װ;:lC5a:>:u\[–oRN$5_&T{PdBK.ShP" ٘4D^ GLG* 3AkҺRp/n}TGȁ JS[6{+>ʅ1us@MvPv K#{t3sPxf'#DUp@SǾr$2} v!lʠkt 8q; /)N@z@d*}ymM"1[NKA5%7w' YPCkр쀨5 Vhۋ&MBQ1G -6f pn*NFZ`f9d?usH"7e !yg܄^{nCA0V{âÇn!Lؾmܺ`@? ЩIo\~L# 2d*l;9X_z"s_pK.n,3JܯP2! ndG\~+yf"A@Wkԧw'﷝+$}E$=FU iN~pi=+upIT&-ZQȼE3 XA}AyK9dCJg )4;/jDY_:jMXx卷`- {N p+k7_Z-ߘv AzL:f4uL dY w-gsNT=N MUb{y>LdieP|W|>^$!W4GTbOvs*i|1^}zt'ؠ&y\8xjsZt*XYpݱH. 0ցnobaq#)A4 ,#c$OIhq j$lX]Q@OR*FNa6tfCcIwGɳ٫.hh?2C6Tj.•Ć%L^hw*m_0_Ja7si|LX2-ßn\+#J9՞p%(m&48)c'˛j;d7?Xpȟ0/* .'snu6Q 3Ax|>>|ӿVjYA5Gy4c Aߌiz# ]}>ԏSO41Z} {Ytacx*JzYG(n##qzPJ; W Зc2~Hv0_nw5m/9]Tpz/7qyP)(ǝabv|-1bU"1o.?B4+@HQZMQCPF *L`o5!)$(7cJMȤ%K\Q"%0Q/M25+)K7 +S{9- !BKSzާ;#oZ- d?}5yQ"o>:'"\r PXV<νKrEȧXQ:Ö́9Ć+&nf !@ ۉI[+\y1Fn6űH|qo ,ǒ/uN6FÙ&)v"-*MsF<| vTcg'볉=6 eF:?^ߠٯ~Tnʒq/ -@`V.CVq%x<ݎbF!r:UjFRP Z:GRbizHνn69ΩݒY|p5;k>u׏yzťع%4I[-C]nXD/Fm8oD+wd*h]츴IC(ki}ËU5dnCR FR,;+N2_ Vg@BE|Qw cA}mf%N'e1kT9/B~9c̽0s Tiv7Bpi 2ԤGtPcJcx{t"Tg}D"8HYVژ1&I#2h>7ͯJ$b> `% ;w"<^F1أ@hU3B1ӣ7Hói*Uf;/(0jr`22^AQ~s$^gH,F iTA&&M ?l=Fψ %|{ /žESR f)ώ' m(3<[=y En#T"T OPO躬8]Pm;34ťu23zliMP~y9QRЫVgx^ϪS17X%kdI` *֓,eMI.$EAa ׏ȂK@j>7=Y&֠`4%~&J*4WV+#æ_k4UA6taI"Dԝyج2o-ѓ~N9Bǖ܇iroCaAyNrC؅?9/yjNTߐHs#9<2%a?35mȞ=p2Bn3LӮu[*j> Չ5֨鼠˳m-ϬA~Mڹzz$kA~xr!2e=< ܵ#EFV:鈱 cKuZ@c`(W\?:" ܱYs9,g=E)٫)^@>D~ ڻ<Ϝ<٩jq&0̍+)ÖtS6{{cxUo8KbD6'5JP_h$-e/wo '%Pt*gis'\] Q;xyY)\@<piIu͕E}4)Z8+T؊莺tܡJsR}ě92F 9_1a2^ZiQ?TP'Z~S@ X*.Db]@G0EZ,0:{b65fuf }{E *$99o!B TP(~!l%04}U{T ;]9>H}0ryj0pZ~R-HZ\Lr#C+#?Wez\6%+-!ִVP15f+u]$ƽq-G-ڝH#v>Ggj.ω@}Dt';G0"\{!fD#@5“ޕs{ T7giYڔTFv ec{ D0 *oֿܵȞ*>'=}fRtq/b NCé÷3_ÂAlc~]|Olh?x{|Qauiޫc]5~6U3c'^KQ<{| "CqBI@RԤ&]HO81ǸܷwV:;3DYF@J09d/)v%65jĴؕN1V RFő O)0׺}E΁Q %X&Fil@uSWgμm8N>%#,ڊZ mɏ#E$k!VoGNA6 ĸ]AJ4e?^z-?L8Q4d$nݜ,+b]ZTůә吢GgK& g~Jllǵ$7hid< hG]#7u3swA X{z#ikGY7[;mc([Mv2_urF1PY.dŪ@S|${ISK*%;!3=G\ aBnL'Ats.~Two i,85ڇY".E5%D9.&{ݽGS\WM ח1.uÚ913x%:s|B~bl7 ?_,}DyHD` ^*9C(B}YqS96,D}c,xsDxm迟’`:bHקFN] 4TNd:9 ZBa|; >kN@)qo@}̩)&JW; q1@;Ep28XF[siV4iȤp*΂Z  x#v)E{֗߷b45U,VЍ:ݜ[ >, \5P ʥJ5UF_G<}Uk(߭EReFC6{\ɠ+\4&IxA`pP|G@K7+;2;q&# ~NFĠdq/#Q jK`.( )RAUd'zjKnKEBr kdБ_j|x2ۇ{b[Jo C9ɬ]L=襓^Հ0jQ<[BLw@ V}W{]dgH kŢlcAk Uy2D@ ut!:ځh)^iFC TAidp&X}q\ @_ͽ R*ˁjΠISE,?UU6G%*zLe1t7^#42u׺f$Pʁ #>y%XMDVt^O:-ZM$b%puFŽ46 U*mאl/nW(&9~!&)gG N67j^pi$^k:wջ,Z+KR y3t,٥-drys ^nzQ8750$.B?B 3rp'\"^ov:'N^I3nN}-|e6ydFEF.h:x?Nk!xq݊Zd \̾*kQ蹞e([ȸ8̚T~QFn< I#eyj0U8ҩNDi(QYrL:J®A;n$S5Yư-iSuݻcc@Fy=^rTPyAͽ_!M'f^c6|cMtPdCQf&`9@7'ssW򡤼aW&BFCmHJMDMGU (АiAWﯰ7j)TUjuG/2ٺFf:vѹ}<4%aOʼ/M׵hTJ="(=^Ae'>*#~ݘҢPa\Z'zU6@r(5-034&-޹   .j+<"y!,mSHl_&Y›O-< XJVf/oz4ɍ%*2Ε*z12}.!Z%Ek!@n&֚ra ܑBCȌ_oM-Ⱥ v=! -8.7FdjN hoРX4M88@@nE @<ԮLew"8ApnnK9aR?iRvt^6q8㧬-.F xYiC,׷MB@D;:N+&M}nhI4&U!~mi0@zRtSn:,S׫LNFL8MA畵$t^f9uʧW2F4Jј?zR g 㝠43r_H ּOxիߋ}ZڠڠE='dlȥNL`>Ws|د6P0ۊt` '}c֗5K9!I($ EFTR]i|`G(V4wFvʖ.*紜QөIn4`#p }GyHgY|n#dyQo}Ov">Tv!& IR!xڬ_}8*xpJWzxlXK{+j!.MQGBya_0VMuP*fH58H"ierop"<-GFigZ.mg#S#e[{%o$1abtcz $ 󇌪I.:jEvD4e2FpSx]}[AE y!/>sׄnȸ?;7+m2?Vigx8@`3 _vPވr;/].?fB?{963%q.V˜:K)2`0pB*ԏZ9|gO5x )H+>8ds7rjԯ* efYS\g},\s!76nH egBRJ/p9] B> &#c؉[zE|4i`gN9*9,4~KsrmUWoeLVŜLrmY)}2k|9wEWN%C -t+A=oL.":m @J(C>T)`1Zy\Z$"S.D>k~fݓ)7j]a«-}Kio2{!Kz[)J3Û}7t6y |i9yP0"spM { ḻfStʱZBe4t/.hЃ:tג;z/e{B4-=Wx1{[FB%wƿkxǚ R *L$j#gX0 Cz%k U܎U)z\S=oM; ayL\H$F;!W 5I,3Tv?k_@Ԟi3Y9]lHV?HAJ`9 c|oPz,7;>j^:.MϽuHqa-[,1ƒ@?P P,R *{)B%| k}*H7.rd9Z-pHlfv*PJ'VpB~fE<6;f{gVv `4 6 J!HCTp1k'SeLYatbU&$oEZKNz;@?&re}A Ii}!Ȫ@5:f^ҺXdҎʦ,S\xh8:K %C#2(N'Ct'9'' @CLֲW0#^sWj]5C\@aREL<N(IV|hSF[OcWAձ3yh<:gXlؼwEjV"AW˨ԕ2HR jh[u[F]M;layZۉ 90xYR9lyD-6GMAG 3{3W9~A$~4oW'kb" T&H*GA43f7ᄆȗ,Y0)~;N>teu!x9 ņT0aEQ'1#ܑė}YKTpQF7#6 2L+ mXDn\*@I(" *_Bq`̍Ս_V) O1D .:Y Q=TwSRx×m$~_(7c8lzЭ~vSXhPFQ7Ԕ4PȻúu C1G_\^VZ^'.vWPb+8B1]"> oQ$D'{p~R~&2A7tI7z_5LCLQJqS2ˋ4pC[![- seOKcL0ޣlX-~镫Qʏ2D #g_51S GeinedÖq.oW1.;\k4 c+ 3eQZ=%~HI5 gFA'ԼU"2<'NzqD>a5IŒ)="Ƥ(Zl-Zxym? 㓓|fE2J_/ţi,3Ϸ |FrHC[,2i p#+I25gBkbS<KW<42Bűz[* xΡz;Vkwv X\F"Ҍ֟>+p9Hy=%!홐dbQ3eT;啝3=ڶ￞;)F8Zϗ;WZ#dl?n~މq"py?Y'yH,fojrs,pd[bI24TlB'=nb9$e)#z)J5[oQ`֞sW ڻXE?Bv98J=n ط%)d{pu.'&@ bXb%PG*# .!;bp0@4AB*Z> v17X(܏bJۭe@5(WCG9¥f/p6;]$e=\bH%si!J5Up`$*P'^$~ )15bĉ)C!лDqb1sM{5{ M8Wᬷt$ Ɇ!;v]Swa[ۮNa2gA=4Mw[dz2T˻5Ț"1 / Y: cluX|0YNn4Ct`tЖ@"G5|Va|?W;akhE8Bo'9Řuv.q|7Ȧ/w?FgP3w&83X6ˬ#1n2Us%pma(AJ+N7 AL1A2eX]KCm!"^x2-iV7 ;pQ;Ā(ZǺn0\ 9ER$|0 8ҙãjo5{qUޔcdjKcz۴23lY7kOuDn"tB1ARJ᎔4xQLDbUP"%^F'~e:! Ի,Oca X{%*^Z咑@e,tmtr=(GHTh0rnr pe!a\T"owⲩYQc'^K ,z€A5K ^w۞lXz@sВVBXv:VZe Җ*k`Nm 'ᵝ/kۄjQoIȨk^q}^=ȎH fAj>z 9.|X h}^ԒZ&ZYFcIn=vL1@++F2 >ZD%u{šz2BXN)kSFLT,}xωBVE9g5TtޥZjl탖mFRLmY._K!4=S5@/4yzJi&rƙ\:Fw``skWëӫه|4jƹ᲼Cqo~MBSނXc,]r;]c[]Ge\",V4LOHlӄh$M4"ni$1# [9]7k?s:## (f;DzYJK4xDo$VF wrD& ׭>Ae~OD]hOCq ;tS&l5Yh!h$Hد~ձ}ޏ| FWZWN::;1k OD:uHø_g7KMXoldj,~ u<].cE7%S@}GU2&V=+k軛F%BYfF4 ?2?HE@%R#i1|kذA`LE 2͇Vm|%e$2ru;OSZt-LܔfȜds!;%u@*ys6`5fD(9{+ +T}ӀnBb~7{5AX'+s}ی.*29x ˣ3s+MkkJF},$s\ 2tEZhlr)vs^rd %BFÛN;o](G7k ckT4Ѹ2-(]h35BKUkNIF TbŨR޼0i/vȣgD*i%k?/ -JU[4cdFT;:i9@W)R,ZN@m`0 c`m"N"78G"^I9jSHM|\s]M:WM?WUsaeeV֬%qp[!)(=EАu l;jMO.=9'5\]bvOOx_*(K?%,@봇C$JA2\ *&;V]Zh#r}zM'%^jÇ% y.vNfB1sԋp'Ufڋ)ZeoȎE"gǶi=;2؛4X^ V]a#GRֺR⛝閅i+nar4(n;92b4eg}`qݣG31;4&*)WxuDl"u)O*GTeBMY}Lz'jE$|]aWVԚU}kWAW=׈}~dC7ǻ:ߺ!Mqֹ{f \-  s>lړO<=Fˉ~OVaBYzW`?.DuàsBKa4:\ʄ*xɣs_$/W?_zO+.yqmnS9 $쮜YCgGz 11x*yB2kz֟|SLeYgQ AOAh_ HQ)[7&ȱsuU}s*^=kX-dj=YvmMB )bjBBMK|#nbt~8ކLjwEdt OyZω\N=8K v\{=یbFŁ߉)/_ lMt% SOEn@xDkZnˋnq1^;7|#ܺ}Qc? RCM2TBTK!Az HyCl1p#zco MYK_^oy@69Qȍ32[Pn&KLҞA+[Ck8@ g U *]~8):n}@JS+1]+4\ Tڰ#;\>_ .6ˈ2^@D׷IR7ZT^Gmɿ+څπm$'Ą3 $ v >oG/Qo6.16,[<f4c $Q3(?cuՈe'iw+(BD}EJ(phBe:Dd$\#kpXfy$件/{ \oGxU|8TgRR1rf^ , oVK EB4.Xꮏk7rFֶW*v1oqIIÔ=iVeiCx0Ti(^#p.N!|kQ"]aY@誹!E68t]k͞xGɁIw5%Iig |wp*z@"cH?% mNkĤLꥹvi`/QM~14˝XrZZ4V|s9ӹ)>[%^Hqу2@$rk J~w6! OO I5:+qӚy1& 2#8\_6_Ha…+?5~X\&u+6p_ӧІۜ5٫Jo.m7D!y6I~H*ٝj_;Nꦦ_Ԉ(p[ICQ:=Bhs49LAP9[@\TrMU,#P!~b' l,e>rqsf[tS~3`iX q1Ǥ`θoEq~G>H1ؖIH"1.s+3#2y%uOۆɘy]I}`SvuS6$a!URdbo-Y=JĺP=>Jq+G2Ɲ0!%ݞU g3[ݨ%No4UKsq[T/,{\FTW_DfC,Ԟ|{V2~9()eFj@1^JƖk"e(,+Sç[sDZ֍5bD6M*8@7z{׆F=K(Sw֫[)hצyoܥc^FH~Qv3';>/^h =!.kM}V߱an^Hمh?b)$d0_Q8yx N=͓m3VMV |ŝ-a? 'okp ]:~"Z%ٝY^^ؖŒKh>d!{3S0X[&D<2թu]ZnenaܚHK'~gyL W*QK O`FrR, ܿ63!Į"c@-2j CFwV\^roN*&$}t]VQ΂o|fC> /TCͨ)҈;DSTɫt#@ƃ!' (sɮfW5DȔ2!#7@T| vLE򘕑x2n5ssxZ„y@ǟ`+#HFbhidҌې3a?"mz9WíY7FQooPoCO)^k/ بc4u+7P:0jЂ37 !u!zwPppz0=M0Ft4nzK<SQ暆3Y]f%`K2i&!(g$WwXof햗W?3V;t:/' oIM i:pRieä38O^?$]&LG*W(^n)9.8jVvۅ$h|fYqVR7cIJpG; WD.w+T{slL]ZL~ޏ4-6~k/%p)]" NJ-ħ QDM(k* :AW\c<|# &S2[xZ }4+ |gK5e\='yy^pAp5aq%I$զd6"`%1I &$"ͫU.xPN&Q>cp/7;hߴyD (0ƎU$`B$Ѧ=?G,61uVuKЂ 9[,nLn;$SH3'>LK8R.2Q³uyL&M2cwɷS>"c&IJ[1+Ț[v}G4 agipHnڳiysiO$jc,?J)Wqz хBXzBu=5~ӈ gf;ғײ;񠻀Lp<ƽ^S q#E2hu#Y뺸ZtE#V%PY_޾i#*Gb*Z{[!LNx׊wؠ YջF)j3|}!|n2/*XQ\A<4 #sX*.n,'>)?Rg%(v%<€Lɧ9%g7b>.AՄh9}{sY=2puW&X]Jxh@gnspEV&I}Lͳ$P°z"Ә2E4˻;OzzW[X0> ~XJL!{ݔ)et%緲(+CXO=SMz,MqΔVvw 3J9غmK#ЈR:Wz{'DT.;}Uj*qGNfC*TNLnG_T>CȰ(rmO[Kit]9. 31S’GAUo+(G a%@ o3+ƱWWO2Ek&u"UuU\%~j9ewe2E"X9;\Z2){R-O7;g(#l?hTVcP6}RP\5TSƀee蜐EhVo34(dI"I;BV!ltL/7d2Y;D@ }ge1Ti$Bu{-qM9"MA.k |In6X|?N טL| toLu{* M[\4Z.d|FhR.&dO?/ɸ㚻oi 8`U6N&2R'6 }ɭC&xc -t{VY:=7N#8gz @{ ,Op/h 1rd@=qBz tITx t%F m9:zyFk"VI"rxZf̞MOJ l%(BlsKw}\G^LeHq&yG#eIDgLnl9#3Nǒ{.6>&@eM΂ &묒 '1H}'LD)gB2F)~_ş싦U9 3 TA|OOb1[ s/ ګy2 n3# ϊjήl2!˛!`j({ s }NB)J}+3a8B6&@.F0оV7`-EsyDad6ߪwMj=.P|6;^lk=娖`4T7[Wjzv2VWL_TP6'l!]p&ّ7`J(6;Z)Z7"{L<뻪ͪe1h1حEyFhOkF4eH4.6/10~|%wr$GKЉ̳QiY@H!i@]o8S̱rz!tv$3خrhGGe>UPtKhw5T@_E)*'&|s /߂t(9qUi=l N ]U֢j,?hH^ ^ϴ-|~l7Gܺx1v3 lRml_DBh κ|HkNY5RI%zx=h2oe6\Zs1-;1[Lsm/.kDC2~ZQmb_'+q&3IM׌^fB)#Ȇ>UhefD-2(<:߁nf&la˪[15~h$Yz&}>؜ɽ,iX I!Y &+??+d< 2 Hv;'tļ+cbDnб<08֓2o]2u%L?%:K,yn^3dUS}WfԱFs|Ą /_VIr)ʼn >;qVR\Mg:(ئf٥v2:˝cJꂹdGr|h~ (*f/ࢁE_M 5!C0׼gzd疭g[vjpS G.G=S?2S Cʼn|;fVK~2b(/=zH55Y UwLޙ{$Z%w}QS!d:-kH89/~ўj$ejh8Ua3}{۪ ڢD" V~W&_Oy}MNȬ/]=vŧ2p iƃ%!&qeB% Chۮ"nG'<]hM! u;ˇxE}깿B6B6|&>;A'B6&:WCk"%ȓwDR/uy??|-g-e蕆+Il+ER],0Cïl@{Ff$w6GKv^1Ii ݇E1O^!qN2ZdyDMb ޖg'@EX ⶻ{i˾meRO%oղYAPt2shh-\d4} ``9hd&;psAҰζGr!6A ytL8.+ĥai~IVe9H]|)I;;*#*F5 eFRLde|QO9\0,WT?twlt?ߔ|B2I7c`:rennjX[5jR^ElB,ݮv*j0 xI7ҥWD$߫FwV˔4 5f|4:(@nBKJA ?L!){ Od_o4Y8xN[g9]sE8}D{UM3ĨaQD/tF֥ riziD ޅ:l*N=Jju8bFEl$ g@ƮdZQ›9u:A}\L4$!o#jlڬ爲_PוA"St `R ' C1j")ЍC?QXVߢNE@CW+c#O0˽61vÇO-؛Y?$z܁lIҨ2Tg1 6:QI3{%(qRņg}x}EnOu;lqU#xT4_GמKP R-c!|-Ne MK;R;06Pkr -l #U3%;[+w Y !ck2~s8Fd  m vrQ܂Ǩ㇢ui%Tx'nh3tF~4KX`rc"Zo_̩}~Ht5 1sijO0cl\ '+!0E]B|c'찀~H(-7yW8/^ZK#6d\CI@OBKul#LmW&,Kz&RZǶx3? ca)2_ʂPbXe&p g;3#&fuXZ3rwE!OFQ{ovC <-Znw_LfC>{F; !ȴ*] ]}4FHw Ođ]%8[Aoδ&g';ЙC=)[&}l?C]*Ghl q: k D2J.y6y kC,'PZ,AEsٕJ-7>ǟ*6_tm+Mmװ0 <ߪgwJ.;Pቇd- W$nf 4}<.I)gɕod"IC= IkŰM,:6jjsK4g$o{iBG%6_:9ݣ&C19T%29t=V\&KתԓJ?3~Lvs+Nѩ4ENtWDcpz֛UT=Kw( ?بMAS,pB ewl:aӒN?2:vQxs//ȼyxHFV;wK!XR*]"*Օ!o#I΋Jb $AE!|tɲxtV2ъPlWoc bE)wGuTJMzJoAJ7,'P] W@ hlX-xx.tL=p)! `Rw%VzՂkOǐESdw'FIq *xE4ɕm\X ߘ.AtWy?dTumD?tc٦ f"?:DsDUxFқ+iqnu 7Й Sٞr;#10} ֛?4:K0_Pfyă?QS\R#õ+$6x|Ϗ*QT)7W^ -6DWXp&4/&?Pճ>Sr5 9~\^:3@v@{E5&"aEmicK!zcxd},-.S:\y9SS1>lyup?r0ECYRbB~Jz8XĜ1Y' 6qP-TsajE'S:1c|K&MJǘ@}RoX5BDϮW zOc%V]&ޣW`RP P >ɴ E5Kl)NI-:6с4TZ. '"g`,ފO9W mBsi}V$=ɔQ6S2*\ :Q*m=Ty[SW=֕`6E;s=smh3W3g f*=oʻXU~*DGON5Bכ cQK)/S|T M!z "Hr;1:qypB>[pSZP\ZuSfb2;L&K2=dDʭPg/Pa1|O羁t\n `v[ ت40/yF#d4憍^!9JKG1jpBC!Rsڛ*¶K36aQ\΄K>2\ /ZIEɓr;t_:9:<]~,H5&_g5|Q4uU=Ibo5ry'{RCROO!Ag3HF`|҃7OV,|vs88J`cppr 0@vz\vF cBw?s93jU3?nU C|wNhR퇇qz)*g/tf 6h'L>ܜnr84]?eݞ苗VUE0tQ#9XErim$WKJ=_9?aQCbz.0`=o9 ނO:BF"c=x1܄֊s>cD>D-jR^ٌȢ ŋ7 I({n'q,B뱰Qst-kKF!_fAK޺oԠF,LC`0 jY H]Gi#Q>\{kvIwTDݡ2rH*bc%N!53oVI/VU2԰ޱec?\uar;nrVPQ=UfPtBO_Y1G%1uZ2e($K$PF8`]*p @ – `AA>6Ue]U].>΁h[qVnm'_t$fYDiGF_.\ ;W fOjقj{GZgbWt3rEL[ۥ+PP24D/79GQnw]c]=v1^=s#:8|53~Ih`swHo_Րn1f* ?0b9#`yP5)|x\bABrR ,MoM()ySڢ)t/0֤&rBnKx4~cr ЊHr >y2"[,yJ[܋&Z8!OvJ,0scRGRτ,ǔ d.au43D>|&~~>^ dj[IkwBU 3ktM=7*#FOHIؼ$7X'&53T7[DlҘ3+>E9)$Re`R9tyH\yK-⫗p܍$U'b¿UTKjSuH#5ڝtM:w kRj&|*,KFn GhD&VYJ5qd RUT4tQ!) y{DLI?ѠkÔ> zh 1qif8QQ4=D!*g_.VWm;qeL EF1n9r>5(ato&-?E*{.1 ".]V]f*sOԵZ@A j*__7m}b2oF\z>]RD=<3jˁs.CODv=0^aC_|H/pEZZ( INjO~@!vίY@7oZUlZ|:] }&(޿hN`ONz!ܐz ?(8 O*cs /$i\M6>tJ#"J|t?[㕼lgbQCb h r% ɔX`7R I?Se3Sl/o~\Gz'fI&s†*7w Ũ> 3 *@@fS/츣K9DNszKG=?* ;bMVc;QZ9J+N9/zZZno k樂1{.G/Mfnһ)Ĩr HPjeC2/BQȠG~SЈæǓji>ޱ QrNjÚr[t9H!QT9zBqݙNKAݢ埪&]q i ,|]YrA.0@:r`)Q=n1N5vȿGȜLhwqBzD;0E=f.ԕ@!_OX5]:N"`+,C9ж\=J^vKoaGl'_O)5py7GCFpdՙy2`mWܿݲJȍʲ[2ɭx~~n6O~ܠJ@ȐMbע;B4xhy௸'3D&/,M90Caޙ)%eن9xW؍F(|ރP xO+#Kcһ֍Gn"s a;nus)g@}y|7x/AhAȝt 셗ES265e_p56)_E{4լ@JL '%5_ZFq/nnا>/N-Tz}WDk=*Jp04]Sڸ?|ZO>p|$! u~ 6X @{%ԪOy$Zwˉ/($vtz^,Kt2%Y-Ps 9s?2Gkң b |xRC"XOVA#-ǣSYFh{utФq{4< :AAbcwxw}1P̝2.^ #J6b 7SLp94}&,PW|`U:]E_ƽ| S>D7gpH!Fa /ov9HI77mXaKg>CFLE--do߱Kn@oEщr3AU٠[(;$zFe" Wc|7aШtMg o< H,x&>B=x6ڂ-T蘻?s*B|Gz6fIGvŏuze3[.p) ny `Nѕ~|uze_ߵ,b*U2܂ бFp!Aal(^XED5xf#iYj5O2g>nXJ02O :|ݍoJB^CMlDaیOOVsܕX3֝bvsX)uebțC߭hke.O۩ٟP½dYB*yaz!' *B xW<+4vebA5A 8B`#zN.)=1Xan.Ә2\G XS&jj[_m6ʳoobq%|2<6n{S>4aMqY^+ /M#l+uWſ.ϋ+KJQz# {Ls",\?;s%I8]Qeզ nC&fсT8$ib8[7D:̷n[uU2DYع* ף7 Ct&䮞U4#YttUTDc$*r4T.\erU_z(JR a>nkVTKh{kfKhEʬ \ܽ-3.j.ZBhRjrx-b6 VkYw_q;Q-gZ6mRD"nG}T:IH>CaWЕ_s?Oϫ_c|`w>QvѝgwPi,-'˶y| ?O g㉑C/&#] p2zB<*i"L$iV6a2auvTꖠf/٘h˫vU葷+ X8_2Hs21f@ VȾ>1m^a#t) %(,{1Qײ$mћ7>r'Mi,;Ýu3mV*T4#'HalJF9c i+s.ff*\ }|]c\E<08Qk8 WI+3T +2q熑R1{eS9eVE{}irs >aJo0_<)@tR݀3 +Ztmpaw⟳~E+/G!bqT4Js;+zɿPg9燃_als?yJaUfCB[/Kuv*n[ETm>HDr!A^Qx^xؔĢ]E8I_f]m=&2jM h?^e\xsR owy,g%KOܷM.p:W]wlPd&-%fR5mJQH2ťtbڽt4Wk3[([]4hUZ71|2D5HHVT #][s j&( !\]FezgF`A䰢NS5)W;IO0M% 82pS'he+c1dRrÄEvJl&S[F苏$0zwӝ#+$VaU>1w<, [=bוi/[Fx 9/NQ hAi ,]g,s]E`-47R8 /r[ßf~EGؿw^M@أ.7/fzzHd2Rt+" ܗ Xr>k#I1>PUF ;+Mv̹˳ Ü%1NE}<=;l:g zpOr!*› D ?L913vFioi3r>7{EΪWocU3r)܄+ۤ)/Vֵ/^S kq %voוoxKfZĤ57D_/ 3ᔹ $&魸å6*/R3xӡ2 EZwy$wkƁNxh {d7bJ>f!A݆A& /K?0B0P/%ڌN9OG=?&މ[WKuClASFNuyn!|H;9OnϪ9{Q!3 ݯ}#dR2]7U 3jm $Ymi@kx~9# gU>AF/ q8Њ"sjHmv 33dR=l7vaXRc,K %Nյ3֪Ay#o[usqB 1'rWz8.XkcU<7/~V׆X~ aQM&5 &#L'Pڕv5S٧>;nNd!&Afl"$q>pѦ˜B('l(|D|wW`R"mkyuRƎ*qv:+iZDp-L.ﳡ/f;ù%wpz :1ƻ?*ss?=k mLg?*Q{tƬAn0bE?e~fsba}P3&T&EamG}lJ^#f)ǸD0{n2ՖˀR+tB`&_"][ev@P wAx:B͉G^ǜ' ^W~pXAfrgzXmg6x{:z τh ԎqO>Ij hy,t97ACt6´I= +]-` A㪋cvsF'S¯uY]uLA+^׈y$dxoS1rG~A dQZk)sMn㢩(G[N"0oA2z}Q=vp,f@\| 2|{gBS)sN'J9$VstQե> ~N^X&mGkeY&\<, gxkE{჎Ÿ&cXO\Y6\WOAiø xwSxf[fZK<#˞Hj0ͱPf.brzνWd/t&pV,RDrY⻊hKCT]FQxoW@,,˩9'*7+?}E_1zT y)芊N@ǧ'‘390Zt x ?[yL /:'q!ryNj0l F&;F!.2(sˢ8ɞ<Ģ8vR+5ig66>FH$6˻WwLra'*\`C2G5qzS@4PGIIc0o@%}&N!MMQ]^Pdλ>)Xb毇ըQHtf/a5vYӴx__\)oD DԵaaaQxYY7bɷPjfyL_3rܚރ><ĕ@ c[@Zz?^jWT&s P;C]>?(6sx) ν-?ur<3)PV y/my@}Oa1VHzÆ"B;qFE`lci)>%H0MRy/գSoN`?p_J:@H`:*@,J$Ұh~M.g>#^cPYzBš+͗C MէYP`$&jAbPtPBt*qyLd/3z zCnƦ)E#y~'V2ӟL6 yK8ɛxS>[dݝܽk_Ģϔі~ TPfc1k}mU"clB]Gy_cvKŒ4%o`D茶خj|RyM-^Q y$[-ث{yk  @NǴ-L&0$I؝iEF{L'U1k׶xo΀_ F*kַùw4 h)eBbE')A2OfxxW\bPSB1(r ca o#ߗOkvaBع_tK;Y^[Tu` W$ ea RT:\%P϶o%ydh&ˏGȾMD70=imD^aؼDznhZ狃4m5.^g0Mandgcj',@ƫ:G)' B9d#BK]"TF]6].ߟ?د*z h hS>~ ft( eB KBUY/ҬօDx{ Jiy%+bEbzz$Li%ho Y?)zcդ(49,hVzRhVt?X=7_?.>gMm Dv(i~oK`gjĻj8MPn%KhHIIJ#2unUqSYmL{oaƨ?Zx,jn󯘒>7 *4ES ^I'$wρovD|v غ aٯ^o˴^y T DB; (\R<=@=#bՇl㇨ 'Oe_fb^-yd۩Hi+PxaUWWE!FJpܬjg(' 잏ķd=I)[0 6 3ۖj\j ^#yQ#v6rO 84 ƥ`/1lv@}?z[+j>&{eYτqߨFI%ZOҬ:i'DWl !dJ ԜQLUzuKaԯQb+.OA!8? "E3PK)GLjjl~h0h@}لgrr`2,Ժ1 ,+n(p.MKisg jB PIi0Nݢ4Jv{؂Aeo0}Oc䖦wm= [5 "<b}6'Th ͐H1A OnNfdaʑ=[D#F2<=csSt+ރҰΖLL }ΔRQ=A}ۏ‡ؚ6Wl _O D,QZq%w^7NNR)9H"FP`I |qS7#r]r<[ .t7k͟0bƥ-'ڿUoT^w\& ;ΒH^بlQ_c;FACRm"@V=axFqj\ %C /z`aєUDZh5UrBbB-Sb.U!5~VJ~TN^\'SÆ e&vV@1 fw'rLNȶjyCV6A/S]STǪIh s3NzվFE:/cNSw7긢x AG7(p/ ؕsQʊ.S{c/GIu?6: n0Ť@EZd̰섖Ϭp{31H6u5vaF6UNM =gx2ЅZ j8Z\z@zv @Z̺~s :[k7J ݔ$ypH!-^[ -_Dlɂ;F,e /:HOm?vR].92*G%:ѥ59 uY!{P&v : ~1P.de 3xL8Kd>NS|b'\CA#p3|ңu#؊<#SY)xa{ߦ5ҵh)Q`ͤhؒ3ǢVq3 z k e=CۓEUG#^5iF'%3vQ Dm`_Ej:_e=u y=bH"7#mVZe^ީ`fcrӧB1-u p1,%8cAm.fgT96B5nFʺ5Q9SGx6K>&d}$X8@ڿbp/> 2:2*Mܪ4?0mvq-J%~-g.tk <_qc@v,m_ݳK~7)?  )gdzQ~nF:B @b>4, Z2o)fh +·u t͆Y7 88j99[ S(@:Eꬶ݂l`BsO0$~=ŽԹ,*_ii"O)(R΅-̓D7{`PCv }y"\LQ"֫#jٰ3!Ϡxͷ6l%za<kHU ^‚3zPyk~kE/aKӴW͜Y_w+Bo޷ݗ)gċ1n0~qN8UBj)b𙷌&utNLJ Y1+PY|ps5+7JhnMucLI&8⩪KW BgQizg! UK v̲- MT%YYTQX<溺Xz8N=^[kRR;p|Y?fkxô늞ʲpԞ3R E f_:}}F!=ugE8 Ь{(JͲ1G'2eLmSA&ꡏ"Zl*qV*Q 6GYm|/?6Mvхi|wrgt6Yf*_"!O.X}EѺ:Q`edWci iDuAdw7FC#w'W>X bW*V%[[aS:=7W&\}0Y a(#brt7QZʹ2h^ 4<ɋ$PQ(wpoG|;kɴR^ݓ];o@"P.rQe8:**F,'? L&nam{姏}%5p4ݱO|M]i M`Q ͶVz77d_2L>^/xWRU6&G{ Hy*{{ 3)2u|l(ު{iK +iqcXyoQ*rt?.b.Jݱ]+=Һ-[׃L4Egy7Y&n]p<jA*zCX>j+7HRAfrCtec;8Y/h(< =pmFA чs)$~K.R n('w팃bؓZW`D:\Q"uDuM=|$Tt~&DOLjߣ^=w!Oc 7^Z 'U v{w tBa]wB צ5ibp rG%eҩE(4jvԧĩi.zB0ֶ Պ-2A]@a_ q \mtZٞ[2xIC;6&0D{95Tq; WT#g*g.!'h񿪃OiLdA~IApf@jkme(|lM\-ݠHaw;,tEs[w;=$=o±}pgMOQy-Qzޥ;cۢ!T GNvx8ȒK~J#gDbمj~\z(u72ܽחՆYh{M=NЌ-*3pS#[ [J.V˄RʶJ"`ܡGx@5F ‹ ~bmT0ɪrqjH{D>Q/aɬsE׷@[w?uRuuzF5"$FszA£HFF\QP en|80PȣN áIs%gtL֦$,vf;.˜lчȞC7f'' ž܃Mu|$ 4\K ._ wcbΨs?nBhAQo,6%môƅbSDpI!}1'i3[6%)K6`1-ɖXH׳6&uȶ3@uf+a"  u/+h3~K?Xt2M>ȅ[Kl!+us/ h9T <8,UN _싲sXg,X gHEXM )*1.^!)ƉZk!N蹏}zYd>CgƀHǖ-NJnX7O]͊kq [x7LPm~WANz仼Yc˝ȨJ䇋А 4fO`vm\_:,f҃}e|G)#Z弙άG|*J^ę}Iǭƣ>=DLC3;Xy{@QⰤp6 !~1INe'\NH$~?pqrŵ$ o=u-ڏ7_#[g?Ǻ~xFFM~(,&^Zm?nsad l7Bry}[m]dxM߫X{/!@"j]_Vk⩻>+JRDPtN- Vӌ᫸4I'z4ҟGY+7u [ t` jG4+c1oL/l  WV }!m6LwPSK'uڂ㉹)[O8+D]q&'VN3/7 Npb>ht45]V6al>{!\Б[{fK+Z5{P`'X]aBa nPxxfCcRTŊS{.5SA``@r?Lj72]j⓫=yrc#AFJ* }\,Yόi74!fB.]Cyk|i{t5Ic8FFuM.w_c0>2ל;}eORV%Jި`MNGXγO6Q#u'L!@ѺwZ40zDߘW]G>e7`fC]?6Ul)F9{O'KT?$-ᐎ5=s)!gG.X69<wɩ`28^@!F7TͽEK1߸F4jca#(! -=h'Md=ҕȥGhy/&^S},"+٬Hq#k۞˨2 P,'t|k[:^8ͫ?& o8 QeAcH9 n{)e'j:mJth4j LCwFDoIv3J{n TS.W*%9s^BnYg*ҳn3' t`$45ĵdnnQCDݏFܽeD[J{d(XwVDvb Qd&]Ơ&E5Y Ov\,w1Du&biS3'2)Px J_LAR``[mO -G 5ˎ}rt4xG݌' ? ׂ0icƳu]7Ќ5Y6wᕏZ)s|^ ,lr~D&!>>œ%U9vG@)`H!+t !!w 9VEVQaGбlY&\!Ő0:Gf7MxG9DŸbVClfY]o&j\kvimўݜ[k09- \ٲVB?.l|$OzEaAr/79KF[l)!vr賣w/XR&UV2(MЉ/HoNne':*-V6^xv{ڲ74?*V j.DD:!jV)d7d ЃH%T-PƧȒ$Pz@ ޯP16Y ` _Ӽ?ל 30@alUȝp&Ѵ}ِ;ob۶XRTBAb.Nin Ү~BicW2J??%E@3`nZKD%41)m 1ӊhvX[Rqq8|̷mJ?XXdl'XV*N̠Ox\fEaU>ƈykoAݼKGzRp7@{M: O6 (K~x':3B)Pb;)LVpf kWQx~$Ȼ-\ D?f':呰[{l?D73^7 8\(x[ cMf(ZkIՅGJlFT~F-ݾK,3|.(nW!x`L-?-DP$n7Ӂœ 7 ]`$)"i" jZ)vqQK=6(=ivQic8bU\KI#;qTe`3 .F6)">ˋr*A ]=,!) =Elb\'ILQ޴L*jq{{1.3yKH#A2iWL] 3arfԬKAY@G~~[cKoQSc$wy 8߽@=oAſ#iJXeQQB6DjXiEnep M Cĕ"DPoIL$[)ݸn&u(o`Sb+ȣ *b)tdCx>s*z^e!ClJh_]!e4e$2y'P.ܫ;,r^D nFw<+OSOV/C ~=Mִ;Vv&v_d]*Wa}P-@+qW|XVjhy;U}IW$ٓ~%c{tYv φ,PG R5iVίv8h,K x~:muTeyGJ*l}YY7k`k qG!$ϩXF(jax+f8J!'p )sJ2vt_P[ JZ/j(gX8pZT`3Z)`9p]GR>S^ >u1'Ԃ|O{W!D 3!:)8 {\UhB~\=V*&EOIϚӞ3Z1+ʬdMNBbZIrtb be6@nhw_|gSvqW _1 D5چWԏch:T \'n)dM'>=B1l&oP P#KR:%ৎ.ӻi+Czkm鮾|solڰ=ɮJ;r叻GvVzM~]o){%f}DC6l|G|g[F Ł6vǗ/yL& Hoi^.GhߨW9;E\ i*/c2C]&HšC!ORrR.BD>t01 ,M"{N/GCpg~BF8phߋx[C ;5!q@0xF!0FjtMtW}@Nо.3-.yӊ"*3!DTnHP,GӋʐ,{hņ93JgȕS@LEU)TU8vowg7Gc.8fi#S.l̡]oZ5b.n[ XxGkuô3"ɝL+` R[uF;98R:5D*av?wn1 {C/P!"yNvFlBDٺ*7+ñ6I"fԒJic"mUjhFECu*IYjjI&gI0Kb^9IwK$(] &0~*Óp?pNQyy>QE5:5Mv;Ps-7<ҿ]Q HN eVЎD~dPMWC/j*5]*y"}e>)EF(:O5lrMNې .Zr2qSÕF/]ɡ,Q05ȧќ0\lkRK/Fю٦4L ތ ¼YzV9t!. 0~n9')w/-,y[x'Q^Gdsy,h,\lׯ0$}mIS˜ *'5n5b 76 |[):M\WoR59T}?M?AyFc8MjoTu1W YGRvED r$NS0IlSEnFleᎾ~4fN+tt X :JhEKvL?Þe;^&$4OY ]uQh‘0ۉgx.Ͻ]XuvoRlgN:N q%sս#xXt@1{pZVjh<vTdM'S/*+uO<$tR6Mwx=lQ|[_S &Ax I5+TuGylp%2Hfowh}`D΄U&P C}$oF:',vR+f"}դ'zJXDؠaP5t8+TPH[ۣSTrk]kygKQr$ FaWq@ԅᆐ h%w~["L8wl9,EJHY8EIL[$ `z06*KMSzk_Fx!6ZUGm#8xH=%EkpA.Wk068yMmy ŠNCd\ol_;f]%\M1&?>c#/hid``kAY+H4 XkKR:޴,HV*ڨez'@%[RAA-@3%QP{޸0{EA򕋘k\1speb8x|OS溌kM`dmח2d׎!H?Y,VXl \J:'gƴ+k?ځ8^#~*RF^>R튴 c]Ջ&3 wSǠ,D|>,qN35\W>Y~z#,ack"!)`1z! ;w5HxϩPe!d˟_\l aj$=d3gRͤ@CkNJՆ o j@|NJf_/I,zS R Q,ºH"t WMD*.Xr,g~@MSw+{/6)#a0N):yOUnLye-r-nT !j-ټ7r.Zn -Q*m~@5WR'?5q60Y`f.A=K,uSkxe"kK P2hّJޭt&9.] Lal'.-Ju b:+q=wX[s8LI!-]xm``;ϊ~ xb6 KgHqBqGX\m,L^F_GTX!n=iw؅ƠFسKR5^Ŝ+նpuCÊoZ 5#qf$=m~,>y$3Z{"eFr(!'̇r(^UƨG ^ ;haiCmPE]^:h'~m\!AbX.(A$L ?.p`[y/P0B|'}r4̲N'7jS޷kJEThERpdke /7a\L!:UT"xa]B3tDGA 7W>q\"`#:6q.ة{{'#&q0@|_ )dB~2CbqA3 P.E[;SKb9Paj F˴Z)E==+hF/vTҨGBM꒎SѬN !`LOt͗sUВUsJ~ $J&5^ _`:xnɘmY2j::whSkגDω};8г,Nd[x贽B~ (Z̳D"xw.s[QMSzNŔN}Ƀ5t`pDR}:+)!4A%QyQ^!V.@'[d(yx1Y%x*6NCϭn ԭ2jmkY6${-: - ㊄K+ǐ,6R*hKܢIx&Q#іY8/ͬcsAP-c#cP%uI-:c w9XƧӉJA.S=zWOܫAă tZ-谒H-b! v۟@"s xgvZy훔7F* /hy.9߶aO-۪ɚAiЖ37FAR&(4"j.bpBs,>M,&)UX/w P̣0u)U0f6yRaNЯl  Yns gꝳ%14@_ŷ ?/F"{^mUI6YjxAu~*HڠNF3Mjd^IgRڬSHN@X+틝y0QFg?]eivBYydϠ[DF?"@vg0tjF%܊3Nţi+PWjuk26<}-5∪ OjoD6#fYO%g(f @q{ kݷLWBP+e : DHlwb`՜;C-Qc|CMTuGBv۫>ۮbu%^ E6IVNh *)Mّ O~'NfUܪ6$VHt B82aBd~8YX[Ye,3w)x+X'{bӄS]{6O)1tOuDjՊbwӳ9T3t<5jVzկLJ1M^U _i(3 lCdwZq«{T;w$Ly{M"[zb~=lD/*mTo{!Arpb]YBDH.Vt3{ȲM >h}v6yL@(:=iDzۿeWyqu35=Z8/i{biYC4숩LVYq\#92`LEm)3 P)W) `#'m,Nb֔El)e3}/˚&5AXbZdr Z*[ >a(bPy X_5 i"ߊ͍%VI E!h/+6693MivdՑ7L/Z7x bCGZ o,\97g~Dljv-OЦmAm48i]_#[EFjEy= =u.Qw 4-(BHrawhX߲"fFE5U? Ts3Om(?-'sYP J Y;,$k.%7MPljd6BJ~ $ec &W$Q m®nKfe\t#Cx)c e @gpPOڊf#aT3Um,L̨}ח+k?}Nj`-vȌ&Yo>u Sd&A?QF>A?SW>Җ=%_r:Ynq$Y&ݭrQru@cZ'ǚW۫ n;}t!MGT0*#ɫyٗ@rJRhͰ *8:5^(Tk)]jMt/핽A=KxfDsF0adh +Yz#l}g\׷?(lȋ?Erɭ;F۽M ګthșKL<7Zf 3%&֮2rR`I0[O")Ȑ\ |LzMa9@MrOJ}{8KQ׉un:K̆ιm\#6o_Ö@$x}񞀔CЭ-Ȱ _,j\Ch+r r[,wCbF/+#^ 9o.9x$ByZ2c;ʒ5`oR75H$"=u*؂/ d~^V'8-_()`*5-|ź󓿖miKnc3Μ֩UHʌ8S%&ܚL MWgڻtsІHGÞխTU$ ?*7>Uy 4SqU6\>"+C7~o - ٜyЮ-Kn I* g"6 njlXΝUcps_^0⢿`F u~; ,$U顗uW:3Q_X(af=$լ7QGuƐu!K3Mz*|Eqwe |\!#N)󱜦p 9c<C|/kss3v֯9**{Q@U-s,54a|˳ V=[doR WŎ85hjI^ԥ^&דG>6gpSZ x)Y2 Gg &ZhPhDP{>F;i: ],6%W O  y@}buൎ|B [w=HzySEͳ >7~ /}eZH=Bj!_h:2>BP ^S\@hjtRH +T.T(цКh'Z^fkQ8MBc(m ׍KUͭ? .$WLH6Pwz@5F'-7QO͔c+߃LW9z'XZuy]S'|{em{,5GA 6@|bÕdSbO?mA&_մbE6a'd#|eF1EY/ "sd]͇Ԋ= rQ0s=JAԞ[ѱeB sدZ+ugc55#yn4Ӂc+a$Ň?¿Z8zgCԧjAқ4QQh3{c˿VqYo,+۩HxQK mDqNM@=_~Yak$/4 U?psX39ZLX[XOSUDŽ͏TJ2VTPܤ/VMDIHv1: y0y5orD7bh 2Q]%{m?k(jLxTCp!}E(M=NY6k>빙nG_^ ٤K1iy07^+?Tv}AvZֽZv;/RT7ȓK:P*<-[ͽ`m}8${`1w.&p"gFŐHQMm A\QҮ#1潒:8!Yxǯb*ePW<Ŷ1+'~'h]Of~HB0j/o(|r"h +g2"|?Bص.I!yV 4+<~HA`,,w(fj#65׬M8?>$՞ZGi+&u%:(O;b\.E` |"Rg]'w_ J N0^!5U,3.TŋGo]6,~(ߒɹ{=z7l8E8Aahˆb݁2UZ=fGO{O#~Z1X}5>˒sVh` J6~>,\bm%=[}7kaҔ'w}*s8XX Ns3JtR} B~-K,$0lqov?>XrqtJ2I n b뷊]+ T|DE=,5"6@Y}{h4y%93 ]G>QƲ 4+RaC Iˤӵ78Oxd_y)œjL$ Vķ݄#J"L#w]i"V>Y=j&3fV!VJy hwY ˑo'?VMCF kvq%KigO8^bh =xչQn4ktLv,>45A2_mcV@03n9]+拙!v^` 3ܦDr{O ܨ$N$1.Y[(2BQCszSa,KT{bx]55ܡf|+=dV\a%j%xV/1[g/fQlbdmp&0ɍ5?ƇB I?H4G\A+X< hua-~_1r70i(SOSde)?9H#f! gEzg;R_h?͂RB r5P@)g8Ե9M0d{Cmre|@ATF4$~kȔӥDʞ609n \?6l˲1o&A89? p~֎9E|M4@FkTF~12[=f_* ,pʮ3[DNɱ=g eipJZ=_ &H0cobۈMuʀxUh.QYKcieJDQvEUItpc_ժH@JρAnb*:V| [tnkm*./ &=0栞=} HE`P1uMAՇ}pbj!E u⿣Poxm{ 8wБٙg=h *pZw'LPO<3٪cڅ@uᡶF[NJ5Y1 >Q[ 2O\Lt7Y3'#iSR,'۬H2;a!Xsrd/!Oڌ%%ҬKq:S˕NJ/ *OZ5{." ;Zߋ)Ĵ"h˔;P)!aMr[Щ ',҉|@aтN~47wsFy (=ERyQ%?4VIdiؿz;Z9;K4y`ʰ|і*ER kH9C/e=<ssyU"kK$d|U$yT)QsDN%k ݽ'چ.+B!*BLNE%QY㫒% ]UpH%d[/]i`]iNoJ]L:+'ae e" FΘa\DLq"j [IK1]0?a5mC _O#;X@LͫcNW@6/quFkv (0`3N"Օ%~^[`2X09%qJxT=kjulɵTv2RzZB0_JnFNk Nvo8WhюL x(G7Ʊt3w #iҍU9+UL|p,SLn9ᾍ?i m.ۘLL^Mѧ!1<5\q_4<,( Jo~◨3lBJ(h%U_6w6IeэGOs~`zJ#*>3Iop׌w)XrimȬI3`$.>AJWES9Zׄ8^8}m~pmD~>*1 _:\ٗPI #nUi3Hwnm-ߒ.ψ;wO"Ha m}:X`d*]ǚڸ|ri)4;OjG<>?%ѣnUy4P{ﵔp~2:KHPz_s;r5ht@u27^mo5ţqjw(/g" =xY}dZުƒ';֥'IBSa4:=[~⒅!p)&ȖQ~&0B6'w[B0tLS)79B G󐤴_: j @p^ׁI3@iIRct\ys~FQ tĽaR][ή u_̴]7e=ht\Kq mv)W֥_BgJ?@qtĴ!bߥ0H62b, U+ ̾|Phi'_x #4kdB{T0m/tKKۖV_Du\vۏ&xwZ քc=$E[t<һ&WfO0|ZN.{L [;ImFoj: ^|g?q],$-+>򦃪!GL}8bs&7 L+jY#tQLO{l$:l}GT|;=UiMyU igo2iZ`c;VV>Q]yw3GaOK$UkR/CM3)J2l«879:aI4agRpӯ* %xzЍa&6_ǩo]t~}U*j8%X]e2[`W 鰇:e%G)nakC/d էQEj $1-<=q^' `БUh[K)= "GҶ YZ