sssd-kcm-2.7.3-1.el8 >  A bU]mXz 00S \fVě^.kUv|<@ʲ2fJl:*U|,SV'ΐhAsrE0#MS9Y_R;wϒ߳Tu3-ػw Z3>c8 #Ӑ.cZR3fWF}1XPa?qPŎfۖϣuQ1i1{$w&6%^,5/7CSks<('91+ê#}xDsa$+.B㱿~CCMG~^ 0Vrcr֟W L#ЛH. ޯasPM M)d_9ۢl' O{h2Yx08;P4BM;TH8~Rx2g]BLC{Y?4V}~.Gq8%` zZkUQ-6fq$6=Iw;ޓ̻ibT7[Iu+cFE5 lVag+yIl|4hp`ŮLi!N~zff>w{YcӃ(U#TPøPzM%{R8JVi_rKF19J|G9OJy _t+dpB? d   B 'DJRgx         a     Jd 99 9(S8\9:e&>~R?~Z@~bG~l H~ I~ X~Y~\ ]L ^ bdAeFfIlKtd u vw x y ,Csssd-kcm2.7.31.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.bڇppc64le-01.mbox.centos.orgxCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxppc64le if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%6(OzځAA큤A큤bچbڇbڇbڇbچbچbچbچbچbچbچbچbچacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd47960ea4640f0c6b098b82d0a66540acedaac70e4dc15bd884c8679d8f1c29561a6914e3282d6390b088948b22e5816b84bf7ef50c49a0065c39df8474eb6b751ba3562d4d92bb54f39c167a9a0b42072e514b97ab8b4d877e5e1fc27bf6cd1465c9f167fa444f1d0dabed29100d0e79f02ddd0ce4264bc65a1fae6542f1ae35033c2072b46c096377a8ce40fc2cd96070545de6a963006724854710696adda599eacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.3-1.el8.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(ppc-64)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)krb5-libslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.7.3-1.el81.18.2-113.0.4-14.6.0-14.0-15.2-12.7.3-1.el84.14.3bγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.7.3-1.el82.7.3-1.el82.7.3-1.el8 kcm_default_ccache.build-id554aeb7eb42f9807d4e136569dd853e19808742asssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/55//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=554aeb7eb42f9807d4e136569dd853e19808742a, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix),R*R&R/RRRRRR(RRR,RRRR RR.R$RRRRR)RRRRR RR RR R!R%R"R#R R+R'R R-RR3utf-8470a52b514bd2c0c810f356903d01a86e6a7df9d65846342e73cf6cbf2aaaf09?7zXZ !#,_{] b2u Q{LT0āL9-oAeB.n 5&ԪIj-1 D*LVǴ_ |-Jk&g1Jx (h +ꄿ_HGQcl?u@/B\yw3[jnn"Xs| G,TJ) U$Xmg:/V>-ZNM+ɑOG=r͙G i C~wnU;?]/I\287!/Z$AcwwDӇ]H"/Q| dMXLm4ߪwvU6)KSAn*P7 ϿG3+Y02zn^7-ɶzMX[腯AJ)DW#IKV9j9:"[YC ɜjxw+v Dk PpK&j@Ni^eM/\^%d/UA:!,N9;5aKUv8n@bY7g:QJV"j:aCݐ@ZKU][B*c3e@1yeA WǻPvg58LμjTI{5P`V ;ܼ+j2Ŧ{`Df(6` -X6Tt,IlEtHѠ(we!J5냎]F5P!'[4(vjYL%?ŰO{FGr|ey1L?sCG}"aJv?xG 5Kz 1%rKRt_dJ=kiسyZ7#A IH,7@][9dA(5kT~t t#$C,,IsNhK: -?=~dAuy5N}SL PBmw ;*$1+뢵/ {i)wce 6m+: />]%h˅2;wb&)7WTr.D֖NzLR7= m!G]}M4<*HkAn2ΎP-X}y/ÀjfJ&%קu%U~'ɨq ,Z]P&iγA,ڰ"6q1Pw 2wb|tS}K.A{Stޯa5a:MLf1˦^ʶ$'4/Zaeb@I!b)K¬Feui*Hw3$+KKq,q_*6]AڲUye kpQ,\xW݇S#S v ʪlgRBI0`z ɗ\b YOUAlk3GGy2qmYoC/r 1뢲XE6|L]dlnaYn_1D1t`F|9Iv៺0ރ@A^}zAx>-Sdl3qpg cU;ڤ<_>_;W9KSJC{b͎|>χQ.rk%܏eDh7$*vԖW*7c3?Ň0f[wwK B]hw>$V}w'q375L$hD).3|GҼql4s3]TX35sAa~Uw; v' Bˈ}u>h}pU:V@H8l)N/!(°\!l9 &.xOȢ)w3i,osTc.=/N)B0#la C[UM_tel:ԑ ''DA4E}&D`_|2Lp놋v;6Ԧ af81IDе~S^^\BZ(R>n$Q(T|eqQFvY)k`+dJki0QԘuZIcWe3:9ZB?3(32v(χ߯fU+yHY9bv%#`CD}?m:H:Jh!ePώ~*-w댇y7mR'qfYYbt#ZÔư\q^󘲼{-]/o<Q)ݼ,N^ތ1se& %nUlι7B큠8P ZNটbzR hDׄ&E݇^x 7!ecp7oCatǰo$ĕ{fĹ&֎]iV4X VrNq>*tDĜ#I?8/) lz>'6oBMhOl>P7* x ATkz+BY^WsZ(U}ѓEb|OaZ4x&ƨˈh-6J<`QByՋ(TqevN_s1q䀷k]W P8ԘH%@&:R^o#LWh޳MM>}>~ T}R\|uU_KE@쑹1JZ`:]PƼ%el8r`T&}&3AlMpZ3_7JO}'u Pkkx <"*ٳ w9'4x{rӊny4a,Η(G^\O&=##  8šTZ%H&fe'$rh@ =]ȲV}a(#:{䄨G舸YR,+f1.fZ(l2_QrK23V+axܬ-EC[]Ϋrl5N8IT[e6xtpu4 \e&r. #^Vh,{@ BAcU"f1;up_z#Q%<^қ .w4QQn D0r6=c3)̨n`򇖉TRﹰ(FM^ Pov:{0a Vl08ILWyj’WZ,8.8$PG3z% (E!MA{ͅ'fO#j 5$8}t. s*~?Af+N)bI.t5e|QmD%S_T 2f< uC~^700%,1p7PEK4:wP}ŚzVXN6 } 4]J^;Muu.Mst [SAUlLw5^k"Oq |} Q k C >9Q~:"}d)Ǖ6]*AAߠB]xmnSQ>ItR@`lZTCHb95E:[kPݬRl4@;D޼2úm֙5Bk dE~ΫsRYU~6 d|}4xy#̩4SHd"1u9*ñ'|3o= yus,Nke3%+>k_]3D f-%ۍI ͔X 9=0f `} CvoU2ά}(/]$Ʒݓ95 9!jLdqy})4G>= Prypb̤LDy ~6K~"6ˏ)W;b [.WWM 2;#ق]+}ݗa!@g+\Srק9rŊlHT[,f-{sw+ a痑c~}f I5W=x? QOq G\jS^Aqetlݐy>GmG>TrH؍Um1.$#;`z+zmǃB͑/Ms[s4UY0З*_}6 Z{i'0Tڮ9#%;q ; U aBZ*|LF1 ^|456e_4(ݸ@2p=&X<Fϗ_=:KlZ.EjIY4P<3@5D_S}w1n8Nu?wed Av&@rdo-z;Zi;vc$CN2/p[Wx3ZP` j1AP$83gFh= Kzl=jy7^򣓔glpCU0tj=2[ ֻsrv\޳8Sr4couv!A{tN_疵Yv$s_P!|٦/my@FQ+%9S,BSN}`IU9RFN,uw hfJv9L(nM|>5r:-,L)ˑZbl}_3dO bg.UӤH%dZլl1;0g[P ~my l[3jš7 |%nGnNٜA4ݿYk'T,z{R=) ]TyѝH1 \XBLV$@n,z?B0jSCdM?Jyqڧ\Xf[{.Ǯ(s*)oMtTVn$+F0^K@ }u=,5g`Lu(k/,Kk |t_ /_d~x/.Ah+9Fӡ*{/d4r3lWvIYXQ%#FbX'̥I$eXwGhRTNY.U(upϹ4],O%ΠzMK&&-11*w;&{q]M?zA6U_hPk!bE}L[ig 2{~%Lj^xVysL8 ,fOmF04JV= vVJ#1H҉GeHio/?' Ш^J}D(úW!Fߔ <Н\6Z깖  &^P=\6ybָ7.zŇ+9 ^Cҳ]lͤ% >6IGrZSb>Am| NAQ∅^'U\J aG =1.!.Pǹ1[֗LiTBH%m)݆M(k]eH҈.3'Xh5J=`ly,{'/Yv*,L(><"PI578.QXs [ StwWelSkbluh|=䢂fMѦMM9$.jzPbd&t$c ,%+Me RNLɊ7T9b]+`󶰅ArU-JMe(0{ Rv8aF<>f$cJ1*2[y| آ$m }r2~`W3:݁zTE~#Q-מ:[/驒!:-G ayrEZoWSjk, i9{i5)ιꍵ2`/~ x#AZz=l88RKDN9 O&ƭӌVX(D>AǐӤGiA,}4 6jhB:!Xfrb[WC(Rsd y$3rHˋ.`.Ee|F7@Ⱦj @՜[Z8%§nێ35Btպ#i U1U2Duĥsde?2a }sҴ4-d %tYUGg"qD}k*&V}~A~>7^47d!(6X]c''%ag$dn~_ͥ7ӢY*mvFi|ƓMsٰʩ%B*BBb_h56լqq  /)Z$b&կ+6euui;HZ1E%ƲZY':;i$rm#n33+~wAF,V~_>"*,:{={:PG D⣚X>IC;J՟Z}?_3<?4VC@F뼵6;DŽ(1Jxrȃ?"-`D폣 9!a~93tu*lrRh]pW./[2d! S;;Vb#3YBAu2{5+m‚o%0 ^^!)`3 Vv1yS.cs ]IO} waW$wD羚++M'n{J_kR!E$kwl8Te⬩ ݸdx!YoɹF˲QdPf̾:u爸l']r˳:?J6CF)Gmà[hRBMGK GbFWXy{J]#ܬ8+SP;/"ډDNR29z _Kb6!X>\n]Չl = k R1jr?zd'+pK)Q S>CF,e.2^NvzZ%8iFRt: £BguYl6) wrWgcjܑp?[F|³{Lx\Sr|񜌏M)VfGnp"k]6 }J"Sjp荜gt,j2)U~.~jg m=>mktO/ C}'@ CpBMTp.32>枮Aç&S!F0tՏh-YSMˆk閫\nj-}t~E[o./_K%ԏRntit^`\_.)Ш&?2HHlQ-QyUeyzsKbyn~CT5RL>]9/])D[` [[cEzx4->\uUT WC b }à@\~RCVj_]I3]4 s'OP][\MӞiJ:Ss)@ O-ζ$ KY=:)ǥbw9&QyhNF:.PFS[EjduC7nz Dzy KRzGS;#Dw ;2=+B#&KFL=X{izN+87f.[QxQVo˘2vG8Etk*t&Msx9(&VdX_gԘa%jL#%Ԇ*Q1ߟ}%+Ǻ3QH7|.2=@]̻K-D4|cx+r?'-ZȆn"'t U5P$7ؿVƉfZ4k+hxb6R8d&hO5D/;O.;Yf+ "2^uM(@CCҦm뀍ߝ_IiQkHlϬ̖k(A VMkN|d¤8®?!P7LNg$INHY8cbRf @h[sϔUNKXd Ѯғ2IWA»ZxWF;gZ5YB]gO7 J&s[" _uQCQS~nƋڌ}3sN`Oz~q{ ,VNQ^Q%'K.J&2,FCEFD&(Yg£H--M `Î֟twU{(Q^9_qC2抁M8b '6 B\"dQVAƜȺ`J.)𻒹Z* 'q. cX(v ijFaErd" AkE M7`E Dz [ KM˅~S~~ l! 0&TQƛZKl/3IG=g' ذʽ[ŦbP3=O?MgnO^JpNל/mK,j(eQ4>Jy? D2/P-Φ7yu @WoFmDCVRURx]L!X&s{Z99kS˕k>aU%*:'ļ\X{/pT"N_Crv*"QOLbMwd@T}Ç~5D8JΊa87RO+1 6~'1Xoko */8V+v KGSj& ^@tS0?LCɄtVd陴1<rg4WrF`r`(njS̀ ub}EE=HT:/C3babv=Ϯ֐^= ?A+F(1hUPQ=I- %Eӓyo nQ،|GF%䀱wC5w#*Op: M{$?<f;*Joay@s+س-Y!d=_Sf#=eJ!Mq6z7UoAjC)@조=׵JVcX56 i~+\% ,2$$iGAOŹ:x0$OC`d;xyTwׄYL='!ow6TT/-zts[7kȴ~PGuifR%5F/W ۡ{䎷Zg0&]ߛQ׏wV?`dz;5gm$Vu(D5oW9;:tI;CÄN"XuK6Nɰ;1L~wk=tˀJ])"2Ew 77d)z|g.CDY'=Jf >|z>Q9]sE!9ѥҨϑK3 dH[2mƪڮS{phE9=^mD[Ca w >cSA玆j s95#EE냀ꪌ l2Q OgKUZy¢V-{tbIr{TDdC Eau$Qf46-[\UR GR*-} Pm" =*dJaڞ$4젾*RJu$ԑ AR,~0uH{IfŞdy`]|ʒDP^tmv\@u~k2 kWA,qa] Rڌ[lPf[ז?y?ObH69;+؆Gsy{BkW<yB bSt^czntV3 VNh ͬƏP"JQ}Y+6>uzmx${ ,#rPϸ~8 ޹v?_+p031Tn&`:{B;-XWد(QvwLdY|Κ7狮K 5/lW%tV2N> Ѭ +yGJB`˱ K]PY$3^0V@";(wJ},xZç R^Jj%|C uY%OfnA[ebx,JhK3&[ƣA\c_Rz[9i]]c=_a|]rMnbXF7n&ԯ. K: 4 _mUgz8L"`=G~A[{BerHVJJHot55^44ZqǪ.>^ozJ* :c;"Ks rSt~ā0T&u7oyy 0wRf́g((c%gH;z𫃇 RD2/2u{ieF\(uuIeoš>^320˞hp易Z &' 26z&WtCT_l.F; ,5%$Udau%6αѨ@<EonTJ7 %M7 yXHoױ R4W\$6a϶ZVse=j-RV׮Y)s\7j5Xi-"Dzqo1_$csR%yZ>,yԳ4hhxW)Ca|p wvKe_D)boyzWh7§c̞khR`3,c0OTPkdC/*A|L<s*y1R@gMEYh77T+NLikDXenk#AOzvYa I5BCKIܘ !8O|sh ->ogLeA]`jgigpN!b:-4 eFFZLqӋڕ_g+&kH}K9ʞ̮c9211$b{8J RVcf"[*LӃع"HOaΎZxAFhZ/B+:^yFϋΰ W>i~6gQE&<7r!m+I[,YiCzQ' Y_a}R Л$Tsrk{W_/}3 蚗#%$N*tNg)O=jɂtJoYs.%%E2>x T2M?$rDb`we4jPpq @U- e=QԁB9=gWM6%c[U.ڕ lȱ˴Fʯ71NsDA2qYZ._~S &*@twbO Bji?'PC-"6N;m>Yip\Z6zEcxW=ȜQu=E*қWUY7YQ?"wX;|I?dc@ 1mb&2Jc[Vm"x/%MIQj8{TC.E@W,yb#YcVEaNyؓ `{v JN3&\NRfhxH %f-Arܪ ;|vyη})ca}BNԎrFVaMýMF~n :K3#kyw]9Z miuf|,XmC[z1J. e҂ s8 Y)ˍElWJi Mڐٺӹ606oݪp ]4TPaHFhڦR|2ntv3G#׵DKOXsz11_ʶ7`Ͱ].]!7[idܭf0ZHMcɣh";%q F2N;{ ݙыܑk̾3a-5w 7%5vj&+ݍ,J91ǭW519Yzu9. &]6'NY4#GI\Vpb)ڙ/?m[s`A 2k` Svp7А'z)vx8}5}q20tjX)_z5o(ӵIUjwA!x;#t^/'OY8fV}@ϜG?<=9>LD}8k騦a^!ԓU 7vXE0dXyDi\i?ͽbr=cYwLpe\`dZX9!>:NO`< ;ݸ4%Q^a~4YiJWP~@:bǙy_zDx~/m3 \sQ9:[k*'GYQN T1 Ÿ9}rB%y/)c3~OŪDd_G.vFS 6ׂq#_ܟ8'kO%Fly]IPe2! ?K8.9t| W-Q- V//XLN0$Hk3q/d1\ע?P6L3s\,tG繉qX9wj2зG6fO|+"I:8BƊr=#^Nz7dE"OZLC uVIJ,= $C )r۸Vsȹ} $^13'dN"S?.%,V ; xpWtIӒuPBhi@ff 7&)Y٧UqDM`wY~q +l=oBa  L?"I$E8#UYT"yvNčH%MuY50\,vSp@h vP` VyFR?w)_GX0Cc tΝg2!Ee_3%ǝOm6cz̗fاoL`ȁ籇d>'oVaZMvL4U$ڏ%-@a2^j's u=^@DyZ1q橧۞mV%@ޏcY_OesZisph_lqdS WC5 4cͦ#p]5v+L\dW]_pnܟvAOz*w LȎgθN,@h OоXfT~9WR |eE2<@p]#L;R01Anm*"X;Jun~1p*U&]+GXe}$,6sf(>)UF~D bV4>J $5ULn_{_KXTgfϗj Tې+~gX;`+R+ Z0dUdi(ֽXfƵ=!F%)ŒSg>dGc!' +(bOv)5m/;ۼ]*%n'mA2'.`PY)eZ.d`!8_f6Yi28UB(b?PFD1OcvIKL+1s0' z }ĕv6 ;8}ݕ38Ϝb~E;珅 )rh=&./ŷl"ЫUV@TBLp۷k*k?B|Н qle1!H;e04v\ rȧ_z -AY]qA^o@P 3tjxW ~/L P?YEI!mBvgHXy<+P#bX2q$^1YM:!{xF:QB^D:\3/Na7u# $CZև01' K7"wޝ@C|sEv5*7r{U9u;"7F#y'BtXƗДcθ.sgM3v^WqB: 5"k %!IU w¢{r7>k`-']UC|'̀ -n~Oi q@!_Z}Vx|~n#Rh&PF@d?;-qT( "|1d ))+M} O0ڸ,Ԉ,$gL40߀?dGa z@$n,΀| 7o2YBC|!=7P%1OТ"LXa[}jY ӲBB]p'c /m`d g+?$Q]稪~;Lpx8I6bK,0{E;8Yl`%3L︔)hQFPA/yDXUHslL؋พr?mt_2W Za~ E񻓷c,5=*rRCP n (?'$Yk&RF ¬--Mf Ӥs>p 5/T՝2]$Wgʽ_Se'#_H$^uM\\\#V^$Οy#k5Ut.d'~_ĸ |r_d׉޳N8uKq5괬p;g7Ã<3pWVB?NBhkt,`BU`,9g%32$4I/?]vr t:𞭦 E&lY־a(9τz(R8ըJD3l̕{SA1ؐ0׃dvpKQqja8b^uhmdS6rԹXZ]-la-Xvn[z"p tBҶ9t '<`j\Ȁ za7,tu1AmZ-`G3u'#µ9Q^/_~aeQ nP }iv#$X)5=e*gYQx$;㳅#cW5,#MT΍dj<);`kiߵ yRD`((‘btÉt:oֵ !k2vQl'aM+8*xINچZ*Y9Zr} ?Yы}cŽhJ+ F3}ȴ(.-7>2h&' ǾVwWq->gP9FӴS#!`Nab%ŧX<`~Q0>U 4EA"d;-w1V5՝[͜Xu|hl*9S|g։7=O mtp1^R&Fzϑxg;D"QP<5[UeCT w~r|oqEa>Ȑ!NrK1 0 r0WL[E̬צ0:9%![]_Dʻ?z2 =[S֐xD \~UEfat?,!aᨡkw~w͖9,ߗWfl{zFHe*@iHKBы&X~9'/-mZ&  ݥb:M"p}d.FY\)]%l.h# )tSyR)Hq<˅dSpy MHRӰ&2Lυ` u=+cES6xu6sվ:(=x^Rt_i1{Rل-rIm";7KKz9MlnRf?h[hI!W`2B(fj:M3,md ,TQH@*8.onH#/NʉiSg{gĨPw3qS$J 2/0>k)ss ahc.`Uf@-@)D#eۅP#\:kM7D{T-[5tPM_ǎZq^dE=\\j"%Ra\,rVK`4}/v^41"1Q^!H,Y(*hZ0?ڐ]Ѿ!;&W<.\wd />7b<\ E[BH^tzuR+ 5'd]D_Q1C/ډҭv-E+<~jC$Pɳ|_Q*#%N;>آ~=|}qJUTV!lԤZ*' axӯSYM<;Iܡ_̫cv颦2MD^R{?'Ӝ5#iMP:|,/߈jA,#Q L;]qi"RKA',3At^}\p㷮W(S ʺko/M"dx2YO+[L^B- h0vGT!+bZsk(e z{(˜3}o+s:e>BcDڳҸx7+B0)E$>aǖw+a o#u'XjWUdB}9aVOа27嬩=GmE2Y!VbV88j[|fwЗ]Mya,\=MrE\cr u;pҘ #{i8$Xu zf=V,meUY\tS0*z[ZS=许 өi'Ȓ࠽,s\Is~T:W+GL[mV4f'krSl(yŏ欴k ȸ[#2Un^ Ӡ/7=Ϣ'd$Yҍ>: D(opHZ:y>)6[]W_akaןjS!q/zogvC?Ζq Tr;Hľzҳ4@iCÏ2AvmnX`Q?Pn)6)8IbF/r/k`}o i?*/ⱏl3OODq_e0f[=hunE7u^WDѭ:cj r 235)MJNRڙf=.(gL2BO#+O--n'mj9Y "E4 4B2 ap]UXG(]L&dȁO#)^\~sdiH@ l .{$HC9ᮾ42}HͥNCU{CYc8~d "yL'Vܥʱ0Xc VCk::Ot@v_OR/?Y`4*zؗAvG"heCNxBĴt;XJ oWL(N׼[ܜv!_ e܃2⠯fA]桄 \?.M 6;~>,aS|x  S<$(.L*,؛+ͯ"[2vy;1B)Bؽv׌r.WO2 -uuv$զdַٝVACG!qa,&nM50"ZTCj%崤):h 9@D6ƇL~se|X ,f gRYlEU;a|wϲ3jCt5eQ8$WO.&@OeH!=rYxNBSGX&<6pC,2o>U+ FDu2)yhC9cN"HO`.0c}XÔ~pVzДHO}U#:e23E}\|,.7'`'N.bo 8]28SkV6%ۧ&ͻH1cIz5oҰ4j5Cm`Iؿ<مcV8i<]M=ɈDdo*5czւ+-- h^6N:%iK%:<.UЇ` -gOfO? 4+O~ =@Vxh?=o yc+ÇψνTb*5?],*=dNdfyvRqiiT&A7ZV<NJ_?B_s X'Y; ,y0:FhK6Db8 IOдbQnd*_Jm3,06QzeލWkj)ɫ̌ʳ`~i`'H> 8NEO̦# P3#b>c-!HZ}`+ɗbHq~{AJڢz΄DߠMH=wԺ!rpZdM_"LbvdWӮY.|^W_qvjra8Ws':{f~m-}H51p\4˰alWLA,* 3#Fh=mJPNt Z ˎe@i)L_ׯZ=s`9z^,Kxh{8i4()hHFS)AIai9m)yini s>ޞcf\ 545Zl\'J4u&)ā pzztr۟ Q0Jk-@-@l?|*g<سӂ;a\3HbRKUĺrf/P(ӂ h32N|&(zs%I1O-\A mKxᑱ=ax ȹ\(?6ͦLe>%~ɝ19[` L]dv\h)8*aqnSý,,+ܑm]y?=6cl ix;.6rS#oW#uA ! _ PV Q_B 9! >p+D/8(_eQ@sx wD("]5C'%hP%F݌EtǒAe{yך~Q qonv33L}NzIua M50m52' 䨎P̊ו3ҧqA+rf-M/ZQ)9|t|>5 S[D7G:OPBR)m99 U_z^o__kʼ 6=)~qֽ kG)&+9T9wt- &-.-Ԍ_7pyoW*tpo=^C9Pr086w]D6r8e GC- NUڐw"&jݳø>Fs()#kǝ'^TQW$&hq+WrJ KO;϶C3\c5>G-˩g7y9ʔqF0 6U]W`HJW$kF- ̝牙USp{YXpknqr [XYS5͛sUزE+8IOgG9w'jjOǼjucQv͜/CQѷIiH!N 4 y݌ HbseCf`.gM#1dFp {BseP\Vi¬l[MH7pbtDi@'۹I8ζޫ ev+wX+8t<';),SMInJF@X:ٗ|jx!5^>Sziqf5E*HA 7,"Qckqdl7[|kD  4}pAʚ帑Z H+A*p3r=:ƨ?=y2CZkߝOYgS@0sCŢV<3΄qM] Z<Jfʥv#K8d}k }GlZ/DqXXCcVi]m~.Dװeh 4<|vΎE2Q qSL3F{o#˅<],B{ߺENԏ{a|yo9PEYNcFX|~5 tL^1꽀D87/[O{;+ C,< 1-$AOnk$L c6 ~V42vZa&bE~MQDJ$SlB}PŁ/P iZ_ozF;.HoZC4yʔoTwytIq܎YV S[*;u?sGRD[imXh0E:V\ӕkR>ۛ~`q!IY'06^c 墖ڒdN]N"ړ~Ѓ#6J וWb0IBs=Oj}U&PT۹=˗Us̈@׮O ^]r[ nzXQ[ mjb8WnͬiqȤXKE@C2d޵9wEee%$k`(uV9= m9D(.7oCrY#Cm<,պwį$o'I ALzO)8 Iu;i}8@ZTiQa)5HCu#@zyЮT  + -RdcUBLswxֶYjT?~!vmϓ[ -ڼ#vsr'˯Gi Kڴ$Ƌ3T%iHgwŇ7WB2KӠSln3{hf fSe3M.dO {lƬu{<\xMyT?F)^_{:xP"љ)! k)2KҪj,r \U2ɦC;Ȣ"'H&F*#|[g5ru(<,q`B߾2RSTN^DV[$ `1i[ܟޥn~bڞ{dFNaE3U$BnvyhάBʹD,2CLci.DHlƇ'Q5#<ǛBi Y:~o',ښqo6uI[̝ڰnV0Pzu8Ils;iv.%/w .G$$"NҸngLt1NRG^-c#Kl9$ܕy (3Mּ|z8[05|IeJ+{Nb3^\X>Mdp6EB+M{nx~K &QsAۃt4c>U!ɣڿn SMz{c7X4-j[RB6J繾O1pˋn}/i]p5"]U/9?<1C;UG^de-JinB]n!"var,L7Ka|ԛFd/)7i`^_HPDVʏ0pV Qeݱ 57fU--%'4az{Ίڃz'm'1gʚNji~/'Np3$liAT[nZb;MVN&঳"CzO`*]Fcﵣ(K꟏\$;tE>jeUߌNagG`Fʻ=42oA.nۢgUCۏT|XAX9weOPڷ}>?PcBB. U߱e1s su3PbǎIh xyR΁wOjlCw4'jWƛ'ZjkL#מ.#MhbHf%CĶITOlֿ&qf=7IX}/ 1?qbh('G +E=Tx='VaPŎ]etpFM B~(Y7mˎh5jȼ.Dtv8^%rgRy h$B JzDP UFe,2m^&pSxY*N_À,f5LaupjGrҵ 0Ozy[1&ϛ+W~Sb`fj ;ݻx[ZSQ@bBg|'=A)y+8/ G㮭R*1WȀ\,t-A"x,$64/Z{2.XO<@^xzYTzGS0ss,wTl&x\ $LjLevBwFpҊI</6!@[{.Hj?mϿ_j_Q;_@rb^ExPkݧ}[ feDɎnOA3":,yg`G3t{ uff%aL.c\Y&8uO s30J3],qW!B`gjW,"*ixJY'^4VVBy@Ga6&Y.}H 5C* dRGjOнU)]֘L.uBzK۰i%g-vP{6z)8#RA-! ՈMkQHtR>;s϶/R D1g?K!WJ>"mPcU0NR+a,3^ܓ?uNiPM:7.ʁ'@<| R^`yJ%5lejQs'3tI_i.(ư RF_ 2"mDvLE)Q6Pm4aHx3T_a&.k'YjUpu9r}xsެX"9BFz"`dp_ՏwkrfߏX.:ᕻ(tPVeր $d/DCed-DC+dtQd-Zx, *,ԓ x'8gks-VR ؃jO*"IPqp_i9832Nf۬,Qc`5P}Ċ1f{t'@yzo.Xᵬm#eQ&@4;'1O1؇C:Irh $> x29m1ªKGYˆ_zKDp_֒v{KOEpkNL!摂qf|zUf쾋2 HUp͔uKSꄈn$[kxgRd=7@(F:S`z(RvT4`z4,{+VX ЍeODŽv?㣮 M}]FO_@d"wKxY%yD? 혅vav f(DܩkW:O37k\ F GI+m`PB""چ:ePmgojLϙ: rePx:f 8 WOw S1'} r"Ddm?w("?&7BleuP7}ZF]qW~aBPY4Hj_xuh)0'B$P8 n9i8)iGXYJmw܃3+sbP柁=`)9ه*Qψн6!?lUbIڙg4j0GWxck/$.7> N)n·WlƆe!=ء􌮊f-X+NcxۛKbK뷤>Oy3[Il>* )%M m0V4agf G~g&Xxuve+`'LP$i &s%,4GrPu _ā `>S7PNEYSiUG9ʙ=^>\ad~PFjqL c QiޑST^ǧorK\pd~à;%t;RXh$,礨rSHaV#DBiXpR z#kk!o%)ufa̿NZ_։꣤6# u 0n`7@چ{\.i}5}9fTp LW8[VN+ X8=G 񈑠T{lxG<-a4 &7CedegfIyg:~|?:s7DE%=˱Uj!teH-ZflvzkȶF@Xxs5v`S|*+(%F E$+(!6?'BBTs\5mDm{5]d)fig(/'ˤu[]иPӱ7JH;R§`$FT/OR jseÒLĪ8V(U"íq_\OOpa{HF2]':{G <`v!=.͢;~2ј^OxmeE*SU4HT?ܓ_'1 d%6uSq*e?gVJ0>K:8h_9o䵺0 yg2剳 5Ur! d}Y}U&]3e< g估F4#΀Jp6*e9n6d~LJ*A>tPE-J0uwD>5m[v@4Rǜ*˽ x@˼>F~l+qrZ:M97wWrW.?a4DUc{9(N .(' .u+FZixO8FӽOjląl'K'z?l$FNO,~2yPJ;^OEƚdiyוجSw4[uΚ\ji g~s黻KsJ{b]v`Iv.P͌.jS01I>wwM EV< c2ݮ{*AU1RhKnIФC(gh.PEUjcDkOBvCt},@JѠ ‹sR5dB"^ Tw3L[˗סؕAJDDYӔNFНAe&ON55fb6TIӎAQ|\,+2ªE~ϕ7fG%bAX[&^뷌:&ƀO1h]ݙ+]Y.ݾf9"p}lfHUE9L sp gZ?ԧCl[ηѓ`յchA˛Hs_U3#J>9) T&#fZ8fKOq7J+L5O*8Z^힭/~ZUtZCc9S^v \|wwPi4/:[~[Ns3FgÄIm1)Rq4DŽ51f"c?QuîJYE/\PDBмR.~2*W|W+<+gܵޗ*DI ֗O½,o{wث/it((<-"j '/s&K8\sr?]&o>u#2O 1MAﯱadY*)Jbٜ]ц.dΌxD8ou7<ϒB4E֘}-ЖjB?3x):8JM`LjUvHԌCn8Ɩ s^xdQoʻ'GٚlR qBnc; .Km F@7]4 ѶDYx?X&N3t-FR ' =79T|B"vN`Ηf;unṅ%JDD&%^唻O[+Y \Srrs7zwޝV tn>QN4hĠoל*?4Tl gʒ&d1ϺZs\oDXˬ 2Z*_~cc30$U)䅃yl31z HM(wtfp]?/G63B"E>_pCA_Dq D%9>@,wj2&-lU#TG:@9:fعN$ôg0JI c=VYG'l9GhF;q,!4D% %@Q`ϵ;o=뺻d"_iOaoũ:2jNӓF7[K\ZYs_y%L I"_m;5%E ͨdC j ӹJlrI(7؅/l4]*"hhd\Q1D^@JƿQj~FGC01%.Ҷ9DLKC)F@"<^fzm $kA,'$Wp77,gc6 !;Mw^ۡ"Xe%NoE>@ @.xLwUAC]1 W`*$I\&%cOR?l4C?NDʍFCoY|sNM>ڒ\kI{ mQ6S]~ٿ]g \Mak ?N>?89c0l^ۮ_KafM+֞VPR0c{)jmlO?J֗3{ؠDQvo%'ى6 DUcI9TxSӑ-`;(WޟdgĄWPTdu0H׿|줎0SUʇV\<%`B=Ҭ-*C]v`I>|W[PF]*ֽr&*!@{1weYC]cvseM-놂UݰKIQ!N!F^ٜI8 4:&8`ת9u/D'fPC  }֗/B b9v.mkQ'biO,:v4uF"E0Rھ͸񈷍k{@" -a@q9TgB6 ax=EI{hdZ%%phJ~@2В TǵӢRrN[ZWP(V)* ּLrh0FU&>whޫ+VÍC`[~զnфZF":&DA5"wk멺;Mvf3qE6X6[=m "@CHH,ȫ.$4t!%6?$Zk:$n ;ħi~2b7v\}O,שriӇ׭p1Š`\Za21C3X +t yoY1 'tǨ%@I]ӵ_vQټ"CG/uR2!}<oLԋf9&cJ}pZvrB{:-p6O`ZQ_^=w4bU`Ud"nv#`ϔݽ%x j M;-0\eY3ݡѵj_At\yUjB4ݻeYBRD:D`bBhia" mv,Ek4dMc Gd1)tf׶k}ʨRՐTݚ`pG$~klM|D"mbIpٍݽ$OhuyA1!,jzmɕ Q=GWH{OSg-/ )W!G!Ɂk=] Tq#[Oc6[ZoXz5qh[?XT5_vX|?n1ha&E/ˆ=ZuBM%ɩgZVdmFgbko3T>ݍOjh>-z>]VKN/ *IktlJ궑R1l2Dg, /.y _uΉ!v+jI BbHk!%qFTКڼJh{]C)Ɯ&۠)r*%*'<>!3 U鑲 0c؂Y$Jϔ[XLiKx,%b=BbO>0595 '쁿@22L] wcd`ͨ_`\'Lɔsrrq׮%6A`lOL?~CL:s a\VwT6Df1g5[bjF((sC銛/s`tm4twI>7U HU 6Enu7Aθ}SiaӘV *Ep+A&TxwT^rY`rӦ˛؊LyTů͋r`i/!7?j(n4,ayqy4qH^5s3;!^)+sj.I B "e2,&Ɓ \P)}R9[1IbMBG MLfUǙ{޼n.S֣Mv餽h%: ng޲ַvIj(zc|.Jů|e1ʿKjH#XB EM7MiMS55+ J =/L_Uk(hhnP.v\`|#AN=QXh"`7E b2%W*FOR]v"fs6\ڛst5ð*}krsVhyBvs"Np)Ժ3,-` oWfk//;0$G_A,pdZY;vm[:բ]J!iP'p0/rk ]'S/90aMm:gi+e.X/*FUGJWإظ/O'"0p[Θq/Qid,49^Xs;Dz=BwTȜNKl3 ܭj2'LTjQm c5kV~'rJ5<4`m@=|K`@1o'oB ɏԓTW@K/A#`]jP b]~FԒV=_.;xh6z6HFudA--d\GR|^,DF 2OJ:CXJ!2e)-Z~N A<5#ZOÎ,xa=Bg?Q(a:4!ө 7.>RWʴG߅~^1''R"EY݁mF󫛔.ܢWOE?*]E:BepG fC#aM`8jre_uRQ|_ۙy> ΢:_?|CE%V6 SvQA"*T8o}&E7#ijznz7|MPEMfB,q;3|!J-鄭Vna2>k\& [Cg!~xڨ.1$LvL8G#ń|M0g枍b:RfPqQ<-l*>eRI61ҕX9JZɎZ#_6BYr"ntMtRRО[zp!l_-*]-CvČ&7OUHL$IϕL. >,X~{ĀT! f||V]Z-?n2eoJ ;%̇5Sjo~UI;Bwo};\- 2uIzE|U@~$-[ƖP:2X1 }'_{`C[^ "lLGG#G_HU=֑H?ދ1?Ѿ"N8x0.Z吜euԴr*mV0[`:Q2OD$B91}RX#|~2(O~E[5iTCg ݭ}F.=G߭ls字K\kG'I\8-:% 5ʲNMj~F3&VJF!7x"aѰqf@ F6^> &79Tb4q"LEo0;tօ6~1Lvk>euZ,syƄu| /i(ro^|\% BE:,BF\ai9ŧ D\#ɹ6)> ɕa nؿ%M> ZcXB"8@kwG u7s/q0v=ɴ4l4y606dpi.U#1"G3uY[%hYMҹ,UYM]/CFϬJo@]CkжH>_l%٬SOhs87~M:Uk)" TƝ.Mg=N,5Br}`D^Z h^6uCd K_chD BUK*fMj{3Z뾍H.VkPqDXcK=.nWR+x +D1?0wd7@r@.ZFXGƿd8yfQ!O:-RWv/kp!dN\4g -ϔXׄ`&ݥU_kYO#0QvaFiL=!vTIpVb.8H/5 h(YgN+ XWj&-|GWs228IrJ7W)OM#d}o(8N20MT:Kh JsFI%lmKI/%-!>l2 Q+n2=EX]F_Ѱ&&L]XP~V'Bٗ>劉J8ץda!~!@hXWID S{ ukkc0G´DcQ"y hExF?v&-/}廝楦/?Xc8^ s@f |ۻrSF&#'D,;_̛Z(#;-4TJ 1s嚗NO$.CNlFAED} F~ƞ{hޯw\):**蜗́#5K2IAyeB(zoWXX\-_ դ49Cט .4ن ?IACd(;2} ե&+7PJ6W[޲`S@|T495ƻr•_=zFi'p Jъ-,IA { edwEZv~2YKjsO~(LISگ83U'7qӊFϊd_a4ͱ{-Sw:㉐A] ZM1$DOJdaL1#9|=/ Nu Ѧ7fyk>HpuJXR<p#գm^%udFIh}V+ۓ O͋1/(5QDmk)eWJf0qTtETyvPuDX.o^ԗ1+dpDUkq q46,xĝܐ| ($k'>]&"-ɤ's-aBڤҽQÍ/o,R2+q恿 ş@!?~ r37㉿ r2O&]!e~%@Cؼ!:וv˘k̕yxrB㲆~ZL,6/ܭ"r-V\7q=Ex\dCJ#LWl:tLQv=S=M]|Ry5w"ݴdp0[DJ9!$w՚hă騷_h5S`갱Bß/b0rM>`5%5)0 z#6Og?!ZE\n@r-7j߱5dL/Ϭ!3Zu91)XgڀssQbz';h:,0QJ|906NFw5iYgPLsv!A$咢XޖB7;#v%ШS8}Aí`aoplK|,g/Dy8ʦ}6CD}/N䏨| -zuLO!AM:!,fƑhHzH<<]늈6mƕߴp WՔl7RsW )L)-$潲X8.Sm2t(&S+AS'~@‹\ֲ4"vBMh:6ܗHdׄ6$zu [iqAz]r؉hfBLoȄP>>d \a!ଆՌVH4_:[}:af<قwl9' ykE,J?2i]~#[eއPƘfjx= ݷz}^2/ 9P;U.s2%L_ʲ8`r?]lKPsOR oA>KCw, 80^TWt{XJ8N\Fs5ך2Ѓ{c5Q:( nyf H׽yi K\Al^ͺMS&B6j>{X0!D\ l12݀:(N!c}2@7vC;R.r:>!9u> WUVGh} C5D(?洽Zc>л`k]ي6ӿcM,۫ݟ<yKĝA..& ]/@#巢oβ`/K7WLYޱ2SD-2Z Lꡀy+Zhxv{&}-c>YGgjӏRB_$PRju*[f9v~OmDEd>^Ù 'X' J"/+17Oʞ<41ȨZc0`Oؽ-Mv ^ޔrJͧ*軖0.Wڦȷ"H,kFG!#ESc(H@npM[\!E̻ Z:aWP@4̹xz6VAF>>LG3̽nKxmON~=gywN1Af:TJp]` hyrMZW@i^G#=MF0Pr=qC{{i֋ 7TO "SR[몪<{4y WaۇHFA.v84{ 6yъMॱ`d V}{9(HФ,3yV&]] ~i^^?rR}̬cM E@e={Op X٭%CQ J6@N i_Ж_F;7z~Ȓ ϪE_^OPC5n(k[FɘBDC -\ ho-Q|$KGzi Gkv# 0_hb.hE11+BP|#/ lGL\$TH%xYUtoWeGq{ ܉@2L^4nrf鰱$IWklDԧASX2͗s *mm'Wgc_qݸ@k S`5ŜD']W>0uh$aFGbM9[:*/{5۳ѫLw4c"Zz0K_2'%A-Y[bp!vmi- UseH.HZJeLRGkv-G.mDZʁG0$?ljf}&BGڏ&u:\3b _anH@pֹ/ya^WpBFk*hyA|{Zk2Za1Q',/2]&=eRIJA?#d._F+Y+1n!h+Q8js2'Nʚ#0f>6pI_IL%fQO=dl:.H{ +OBFxC59ؒE~ihb>FXl-̠UY^膔2&Q64&n.0“cBcpx12J[DxL6il[QnqDa',eJ1 so%p3,W2FoB gcw줍)@u4舘,Є+ !]|lGa~h8(Nbi3ČpLRv.{n hJuq_*:Q2wmBhc\& V5bHH9TKEQO#@$57{IʮE =4f ܗۚKTE u;AAQX7 +9A{PУ W:D&uôpVB [._&%U+q԰CBvJ 1Ͻ)^kQp>{px)6V g~kٯ{|1{^habO+dYYqhX5 c?{9M[?HՊ=+ōئh[ P$ mbNk//8JSfB8 )U@B3W,E/?A!$0$pc0J. ׁʰxϧ %.(07G},CaLHUY,-\;3QF\~ XZX H9*/]VE~`Ӥ k@'?%,I?F^&d5DZC(b6]' > ̣zA_{?9tN\AїdpC\S; WA짃Ghrc؝if2(&4po ;Y0,-vSZ "Z-]#K~FG.Riru]M1Tqn^G;hgSh![1km.7>.6EẊTʼ`@4R˪[';4x(;zt".Һ1D|E,PC]H+EJ8ixu$ aWVL+퓵ZmmX=zMT v21э0vdT1e/yMO&q6+pKSl2孄]Qq_oj߬38,,kܩ_T.5>ɬ LǮs os6~ӯQ1w%yUW;Gk\9vV!8cnQ˵fzR9ӧT(/9Kkn$gQOEq+DKFLwip~ @yRHhqN8'\׫:ܵ;ˉhc(@eZ&e9}^#]T5PrqDZ5W)vWldzb*Rs|SZZo][@4+.Ӄ󹌠ZC*U w FkwZ} {2pKTaave+$ gJMq i_{ߕ t/PwQVpl<]Bw3|EH^[5ng*]F<=sMItm7؜ vީ苤ITSf,}[5GsA؎M;0>?9 rF؉&dmd^zy?6K8'~dt+tzzfKa;IJ*8{5zVM?ƔQ6h."T8E!UB )GCǴBmxt!SU;M-sh! sh18K,1bbp"\;> {{=L thYAxNB> ࣝ+0nB/Q#9f,% ̚6=aJRJlyQHÐrO:є^?>/4E!cC߱TCJ\ݿ]Ҝlo~U=6;Mm ϩUZq>ߊ7,-fc!5 Sz ARi/GN^ m]eX̹!=os sal3>MX "(7 VG@"KHi0Z?Y#6 *4ОVġ* 6ngyONmayD@ؿ ׍u^!LSRE|5h*>-70-Eo<{"Ch7L0V9*GU} W><j zM0;5Q]n ŲMU%" RN tĒp0N&_c`(Q=s27Q ֈ8f+qU& 툣ڰd'B$`M)kdҡ'` Hp"U5ӕߡr ,.Lv ϼ͒,Tp11ȇf[l dƍ Squ=ѿrAmuz6?7UfADC^oxojkDN^۱+Y|:o$0{*X?[6 _|l@ubYAY2:`r.ẠYǓ|UZF|`.T7S%\D=&Q&LUBaJ1"H~6.j kZ_Vö=';"?-vXPEEqW̥;^~ү2m"+myC 4;8;=N}i0at4#mg?I>E 숕l mΙ3jutJ8jsW%Z`֘2LZ{~ka%}O8}Ͱ?nӾ݌A;O, GoJX4GBLXc< Uc|QI\bwTd(Ѫ93[1;I1<7)ciZ [=]LLe3lQ>#-zj+ŽmtlpʸN9-mBX'Rׁ;iK"|Oۈp6Y'LcTg].5`pt~lcI6ҩwHJLbJU{Fc$uAG'9`::s xod{G pXarq.Xc_z֯ IOl5@Md`sh >`FLqWqVٕHիrb7L iAjZT$*n`pԡ'yXXվ\OȘ̌V#-D?)#sobwC췫Iq^1ŋwX/Gk9=χHX{Vn6u/wlڑ? \8:YKi#q>>ݧ.7L |c͇Kɀ CM+SHPz*[&˱@ įVX ^%Wv)goiVη F:a[̓x_nJ Gs#5Y6ug~6l#sæ 5 Ia ݉EPsSPMom fԫHV쁢;a:F ` `vy:j|糦.|޶$]_2|oGһyʰ5ǯUcĔ b'mq C6EMdy5T: b~P1KВ{!en5ah9+a! ٕ;?&$m$!>ȁc3>,=%pƖ]%Y±h'eV6ƺ9zE'im?91g clwCnd7}4!Ku P*@*+Ke£0@)\[ HG% fv9?&IKcg˦2VQcvՃߧT|IAI2gɡ“t*dф655gIA2Px㱈#wܹgÓ@F\ _!]&^EbnʡYZLmK`:_dԂupH$;&HvSFjB\Ĥ/mvr&]Mߔ ljÍxVd_V+Y!LxrTx\{Gq06 u$m!O\H[@A.wkO~tijkՉP v)eeB cij΢I$"h=3x4%IgA1Lᷡs;Y?q3,:aomH>F:٦"f+B;xd8[w7OGL.g\͛ŨBQiIpSY˾UhŻhh rG825%L[t}l徤RUKj.׽>$3!Ve> PvK2s-;3UgqjwLT ui]jr4cAK+V7SkbqAq%%:܏ >ޖL ` d9MfR]^2o.ʍ?zհ/%rڹv&K 6ZD{{ C=ΚJtQJD50iʁ-hڤ/Te}ҺлE[»]R#ط.3To4 6՞CKߚ%<&2֕<]܁jh?Kb|r, 9Ev;9b{J񀉝w(Ȧm46dCznt0鏌aPVJN>*4v݌F ̒ nK4-]/kCxϢ" %o0Q/%mls4@gT õGaRopYlэ‹ԪLnBKP[I+}o~af-(QęU{4 Åi5hW8X" R2:d]ԄllKڥ/ɐd;M\vʎ:0+Ʒfp1%$@ YfxżJ% >+8v a\/P5)C5'H#YZ2ߍ{9j-FJfCm5KۀRb5]vN^-ޮÕL0xY]zo"ߔ\yA*Esܶ^-%=JXrLdJ3 ; ^RQ}]5t0L깎nI~Ϡx:YB=rY8?S=;@e qӒV3X;`gjw:S 3K./TS@Oh(Eb?~NA8cǗH+RxCalZDY-6^$@4X)ua* Bi@Nz&_0HD%\_pmU3fGUW) 49".Zq-?)鄆c_lr|u(EcH7G`gof:Q\W'L[˃2{g+LaWX/S('rEgx[n%o*]PH3\Y~Y _!CDMm'i.JMV:}' E߬MN.vTU* Q|VmpE^FT=A&Ԏ^`Qk&R>,5Yjڈ%Zi]J7*t5*A4`ZD62ʙ{hG,sAhZ,O aPO P4ζ~q߱i\58ACCpu2mG؜{Z"u:SgiוּWR}kh +s&_1uanD)ŮKHMebHI+3jF$¡#ٟou0n5y鰖u#S5!||qj͑L]ݜwkYY},o XTN|meǾۍفGNYU<'L@:!1Уr H%4МSZԛȁx;' 1Ŭ*|ԸJdV cW9իEw07ݸ\ ռ];A㑔J5EBdޚޞI435d1,o>oJZ[4,fQ(| ps -;WxseG@/"9^=7@8?^0A5? ?g5Y"@"%ݝBd}}Ø P w:]mH>]ܸ>06[7a⢪Dܼܭ_ҧbc{0!0iE)2(bA%}޺uBؖ b.Eٍ)od G >%;} M apӘ]!:wi_ocbE(rU{9BُMlDp |f!ozPpƒ f ыep9/ 뿎$|-sgIV+XғJ<4VopQnN ^¾BluPKx_3*|ׄپs +m*ۼ65y.\lH5bA~i($ 2D-rӞ 5{Dqrxvdc0j _/b1@$IguʩICY1IV3R6LDZ҉5dig +g{Fɶ R7^+jW`*E?&4 xDk$2NᾅvWϷ#ŗ4I @H3x$F, tdC!zeC%x+$+`ri8;2F2Ư/<{[ˌ}(!)դu3̗/V|֜ޮgŶvhVR#Sf*E-pp=]dCRoa2yߡav%O2Va&9TS,Tx}Ft^= wBIr-y1񕓎 uiϫ!!nw ~-ʷC84 &QX}Ug9)*c8˭[6zX֮F 5;yxf(Ľ\|A4| f^K/jVy8,%QsIUO禮g\v+ŪLH(F?Q.{:&ieaUU~<2bcI}Cj8)o' !Bo$ 9!+飏iP( dO}Gd}.`g$ȹQ 0,}"f>&0ڄ }_?KJdѿI=0$~~xiǥAIȔݺ1jxN3iEnzT-{mk Lmn7*e;/%NEк'a''2kמJc I.%[% Lq##ޛ7> VaNhn RNfʮ2=g^.y'hMbݤ!wf$'*P6.( N1_Y8#M*cG ,=Hp0?l? <ߘoR:/Z g!d$ڷ4ghKs)<];Ve;=^@ǰu;h$2{l:!q?1_:ԏ0e*~ȴq|D9ʽl|k09Y"IDSNs LÖpX8WdGW%w,0!ZІ Wn({D FH_T;D)X>ϖ-~Fl+htSW7ݎY*54׊Iʮ*S$xDM#Ȣ"2ק+5SoǯP+c@X>'R11`2<֜dKQͿyOu@`3'-O:a4YUt LjcВ e _|G1عh kfv}mC2W>\ޓ^c F;oF`}sJwn!2u5 QfWF.@*~͆]eGϷ:9g]iT >pO \\ i e"hƥf/H&?k#K]9#H3;$y^iq;(=8`JyQa7 )LWU|R&6*bAZ -Pɰ\;ZnM xjߵUPIZ r?GBt ܋mxqaѵ;r'['j03]2wb1g7N(Q-*ZQ$1`ʮ "7{fǒ-JS,VIaE=hYg9(ۓ|&l{U`sn|l%?VF&pvԐG:(4URbS.HdDΦuR$WrƇ|ӯEss(m$ėzҴ@塥6{1,m S ;1x QS.ཀྵȍxPMJ@Ǒ/]^a:H#ԙ08Ӳ\RN]1U*vԔ=+PI]}B6d5~=/l4yĬ0مƄzxoX^#?Xb" 5˨ 05D1}dޔ;{0> KR(`) m4:}I_mIfy"ܟ 뭰c!6M>ݺWƽḅsVM!8;#!3 :|IJ I.U5Xl߉|tuf=k2b [Ц,ZX8t)nOҿt>utv}sBz0Ntl$B}6nf0j:Mf YXE2-ٯe0&YC?67ˤP<'L1D,@TadK0-D*PI`񅚢e}N f9r /2k٪*2% ;8鰐[P6'( ( %3BidS^Q|-R7y蜶Sus)nz@;cN*c`ykZHcda9V@r|n>&hbbL] [L^umk 2_pJ "˴Ur*VmAsw7~X a  ĆOׁviu_̣Mh'Ë'*xK -;::~6(^ݬ*0I^o=bI|Q5x~D.Z̓RVJth?J(_?X klXS`(~&>SB5`={Ov ^o>zz}+ DpDd3/@x>gc_:M9h#:s&L 7 D1M*.5 3?.`61J'>l'm7ӑ5FTx흿(:!5=TW,KP#y pG-4}|YVhl}`r7r}㕓?xۄZ@G2}^nKہ/{o=|멵S7u&2ָ.HB%M. vF4R/ ]DϦJƩH9MUTX &;_/i23DbQ׳X F5umc4.h""ٮ(P?}g9+3JwQ ɑx^U?`^{o/U&7%WDD$W!Ob_iUzPFUʪ[/R6O ǸC!¼˰Vwy`C[N^ofI 1h^" >9gR2~e%Qמ(,M27rs4J/c yOwĴ(9 BI#ѫ3uNOc3,آ7~gٰ*WJ=4+׎2(~k4ALVJQR6?;Dtcɥ Q58y'BrfAO/g7Tz@bM#$ Rj" ֥=Pd=Z[Wk3>=SSivnuT˶r85T̆-{;Dtdq9 #_,c1J3% $9G| °ٖ6;ĭ œ6|%b3',k(HT0ȧEz;CwwF+6j^b O$ė> f H}XLMEDu #ITw^i,JCA#DIvzoOE`\(6=R˭;\ hXm=rk>ɒW.^-|wb8ӨZ1q DPZ5VUŗ1Rg \1'4g~6V>E Qy8&Ir^-T}%;m,]"MG%t6q< tM\+]ib ww{Btd8~=eM- oWɺҹD@7]C :SJ>x(N8]Y@Ɇ4皎Vb+4;7 >g\?Ǽ|[^ZT;N1 V_@!$ǵ;p3#ő:1ƍ~%8P:f )a* 2jm lLxgְ3>yg{)4ժtf#s'B,\FKa B+Lbp&qU!+Kg2exR/Aw@U=Q=bHy5VK|>^z?7%7ib?' 0,OK{A0-Ls9x&0nE.X@Moׄ'܁M6 ?ƮJ1]J|T)1Uő^Ԡʕ0e$ܠT_ZY1)(ؑc͈\f3%8ܿrҥ\W'*y48L0b)-۸w S Pv9u7˩x/\^kXs*q&`U:ڏv3!-Ϫ@0?20t %<{q 8XɿzD{^ yRMAPCG:SWߒ /b59&:Zx>9=N`'r5RLR\p2}u^ c4,Q#Kf;9c`J$۱wa98FqzMZw@ow|Law]ƍt66ɨujF"i4@stfh#; }d*F n+Ecjt\yn.RrTa֩sm`DPa}wZiQd֮8FXBZAX0Mat0_vhGg AqTh9cT HScFeo! 2pO%M4>} W{3vn@ҲѤsa)]~"8J">h6eozZ)6UҖuW>iQ8$"吤r6WGZ.)Uۖ,NrkY2+x&Y/qxe3f;|F7$7r1Ĭx8 ׆ICֲPZa޹鴘m`fjfWLR0RôRxjV =쉇ŦhBl +^ /Y&V oZܫn<))=*{,:˼w1P+eWޞ3x{ɕXD clWnz0vc ţǮ5o*}?1C:AylcTmMZb֚Pfh7c2Tfm`= `bԅ,9WMQފw%pJop YsYoP-ԉRh#KqޫP' !4F7IsC!KAT2auwPhj-=9Ih?=M0B3D3I \"a@1[@T:$}&[l1PPrw7_-iF|*r(,0`)EA[^tAtPI ĐD(rcBX'ƒ7(]'{Iz+k,%u &kDl\w` I>kT{Uw_Kzeң?>_/7Vm&[gIXͮ; <+b&쯪?F52}y~;W6ƶkHudK 7;(T^Hy)w*LXJ^^AEeqĥ*]HS9@7CB::㻒Lh>{ >,i1K xFHin4ۚQB6b j fYiz>Oi (EzapړԏәZg,@!+s,xaD̙ LIJ~FbOqGݖF5GHDGSME&ߠʏlؚ%RyYRW\KrJ&WpPr7=bf& g#Vv&vCK;8`sr`S%B  ޑ K ' aO*i(2(bw . ztE-hmKCObEJdݓ# !yN# ,ug֚ϫV|Ws% Pr 61}Дn ZdC*-^.FDKATPQpbG\b,&|ATIY {#3 'v~5ta*6679!v f\#j#FZ,jE~QTBU"InnfR"UGө7QT]`. I>!bp FoaMu@ugI mῨrFk߹{]3"YeWZ):7cU(ϒ-Mx}Jݳpoi>lƥUR66U0C7(n Y9fagQ5͋!E0X:_S`ξKdhKO~̋"lyPBr|٭o.{E"@uw+{# xPL:GM)9il*@VXT͇S(QtZD.t= 3'ޤє&=]2 |rϰl:V&-} R2ݜ%[tqȽb ԗ2./GGӨT1QG9@{s]A Ʀc+hu$+u| ZbOg8th+$ƜLԤGudw1sp&Ƅ~ڛ{E%ޖOAqUPfUh'G z4J‰]sNP,ޞ'y8`Fęz*9ʜ1n=ƍҋhӹ4\,V8K=x77 ~ϳs*Na !nQx;(2Eџa9&9kgN ɖޥ-j=3 W8iu!s+}YƳz'^1Ih6Mɲa_xښxC"xzb * ]Z bL+U13!mpk+"3⢉g $kըpۣ":ʪ"(DS@`L딢֕<衯(A#_o CG>\,ɨH?hd <:6*JZ XDn[bbKD!1sak-!zم>2)o<0{!t)^RY=%{.6!jn^?7)xS!}[{裟kA5Aw"X=,hsq5Mٗ1!'F&sXcEșn7 | DeJLҽ@^uT||w8%1kɇ!ұORx:8SF?(:lELyfr!dnO!31zT <=-9$|}9fDHxavsoY,jay>cPZO8i?I4٫!3w,S=zyPp |h^Yo Fb₽N *!g0n*9 0¸s' lO'we-q'^BXw 4B楁feV,[3h~3~P('y1u/͛bӜh|EU~2]>NTi^(+*ov jjbC$~f$[E vo6Zɐa[VV|e* *; 7k<^7aoj+gIb 29̏B)xMA=T# pSwQڞ qOfll,Ofpr#Ă]+xiRwn?BSen 2xKP  I)On?,ጇ֐#Ϩf:ψ$VK("**%7F䙚6^X&d~j? G+plHB#$8w!A'ܐ& bٍ| Y'X؎9s:7ҮoKa+f9r脵;>cvA6{0N~&ZX4~@!Ar@06KQ^rO 0zB2H,NIR~톝q,s,<7 7fޔO'?3"}V)CϪZTja(k K^%<bbCvR=L^Zcxgxy[Mv(E]C_^-WrIw1lg2Q4IBTV'gkS NNK!媭A'+.~N pc4ݏC˸6}˯Ql*r-*X@~N=y7!޶a7̴|mFE8#4kKDUfzKKH:9EL0tk'cy m7kLt j׼#a !,$Pmxt-JkA)lyGa1 5" p*Km93K꟣?RpF_%|R;gnὖ< Ck0lU9O5cu\):KCUk uF08\s -jػ!*H5ѠEiZlB@D7qHC|j_eJ0cBĽR#>?1[y7y ŋ{x&sih,@7v%  BUqdrEqL 0NiHG˳檽c\ҥoE^%M m*y"ˈj1ILSNHͿ6Ry ¡{5;3CZkao9Vt]±xز9H _̢tQDޯܚK|s9ںDGzRc䣽̬͋ʰWnЉ<,t2t95`~B]eʮ´i=Kx&PŠ%|Y<\e~8us.*/,u\Yr[4F8jym0$EI{A\'(v.+AK#a7#`a +-~CU)d:'/tP[ =wMW+ܩp*€-ka},fĦ5:4|f%? xcϿWd[)6cQv0ͤ"tFZt $ec yw%WY,E(T[z<؈;0k^Aٵ΃ɖ Gap#Vrl\z;sG :)uDc<e\8q Ш(c x0yR/ѯ{IZz[񨅬ǝ0%kH5j7[2xaXEgfrvYuJt%:_Ibh՗TֶI|51Nf$saF{qٴfC[&95pNhͲhs.ъẰSK K;xJW<{r֟Qekf+x#1D`n+6,5'X_χP)S Wa% 7G]=Si7?@ q%|~[4f%(n[2/sk !Amc^ꇔ3QҞН覔SMM/g}DZN`7ڟ\GF?5R^P{keRa`I=zv]M~Z8SMFʥ&.茱ifQ`]BeP NMw7Id+\qئ.h_ۜE?~"7!]粣x/6BF֍FY!E{bvv5>HoM[ %Z?G/őPPtT݈`lw=m{qu7uYy2yW"0io&XEФлC6+^0'L00*o@y?*)$̕U:*woWOGCPp~m(f/Nq8h /ES0U1)+H 5Y^!z16GŅ ݿb1*YU@ډ=v*m2cz%˿qDtHd} zOV1~5cBJ}* Jo5#7]˯o:`Khf;sT) ۖY"hA39"7k_C" u,ScMsmQ&cQf XN(aK_U9^V_@NԃB˯e+(1To3|ܖP8 [};9_e熑Zr k^55"#'xUuXusT-;zZ}bsziJ(jݎ)ət%hȰ>F`DcM}ȴd`|0[aShRFw^0CM y(e]UpTj[[V ]9eXnƨr`hj"+݉Ҭ xT4ZN)nf;z:zdrTTlj eՌ]1 9H8gzh!;/:iuRSK>= Mޓ^1JrGde MH.(Py߇8ïzdbB)a0I ]]'A#b Vq{h/#OgpԢ&c5> 5ۥj FUt|R˕891zI0Hw/Q&gXZMoX۬n!G$<\DZ~-w;cLkvJӅu~w^LzVTUO jz$O U/LD. ; Q!})@Y_H_SmݕW=yۓ^ 7$$){PIbmtfQI> X3,f;y!#.>vxݢ*rD-(T&ǀ˗"\ nBMptwG߭ՅQ]ِBhx&Kb[Ud4q~K  G]گ2&%C.gk%t&F\:x7 ˶؁O ,D_n!f2KHdduQN{ާDznK܇{98|έ2W3 2A-.hdj;nCp%d/wb ^E8@~fW)1[iI+'ݧǺa$K6~SGWvڋM0^ '2Jl/Zgu1>%%ʽ88I#X9 @By&D}U}cDtoRo!@.raQtOaƆ"1Xeq<_!v;IRB A_4d\Wϋ4L_**dnpVőM乡~zxܣox I 1۵ Whϐi>=ƃw+I{$uJ`-Iz$N[ih|]Wd7W7Һ22_l2@ QKbljfΩOjo' ͛-BRٸJoVC6AZ94`Ӡ;)u~9C1{JANϖRCk(?lC (|T¢A n?elLIR&&snL~Ώ<ZzffS /"TĂH?BsEUToC.CPڈke.|Ba--NLW~we1{^|y-j[ d|Ʋs]| 5eAV $ lS!2zQl<~(L!vbIOo4AsD1E# ΀HDmxT.W%3H3rQG ZIqFՁȄŹI(<[Km?u ѡ0urҟ&YJ.WQu\RLR6<]-{ :&^AN}*AhOWh|F~h~KYgIW`f72(ԛL O^yX 3sѽa +M x)jʐ OUč+|R5D%.ޱbxmhdh%ОGg+70 npogF)TclUX(:ُG2® RA+h?#^dAhn;mŴQscb(_Y_ͭ98^w.o 6z; 0SA3k\Ւ6;v}d%ԇ~D*N] :9{_W3"dᤌ`ڀCN &`#,P)Rs"rY/7VVR iӯW!Qk4 T SV]zkxɕR iju|NS/F뗛`sc[NEd%:7H =V0[@S(0CW=~ %G%6} -*ߕmw\=E]^ÒxMM?̂ 1SCĬ'뫇s3Ç}&nlApδǝL >w0;~bȪG+T:B˫vK CkB:E:kjf+N6vr;2 NhУMTJG\t#A9A 9HƔ H_URꌸB  S<^{7H$ [;yb~l $ݘ9 "R:q֎2u_@uow5empϒQ)KFހc7)cH&IMw[W DTh_: B2Үj38B2aCn<# +ֲ0vѿi~⧆;p)F̩1' :Je+P>;:]׮02濫}Ds=fi 4Ɠfo+eSM}ZO iż8%5 e)H.@D6x,xHHU&QoWb՝ȶc].?!" K4% ,#*2XOvVQͧvJNL =+$|*x=Cb/XO;Nk?)$nrZ.4_ 2ћaywOr[wSuǚPA'yƂ{͙8kzu wvt?gRd5UdPd~$xd UeލLRؚ1D@T8R?JVfWOйWRfbU:Yd2-?$iY*ɯtaUH؍Ϧ?bڒ .]Y ㏳T#f1ʏۖ2[|o 2JqM1fۙL0+d 2:$t1kM)匉 .Ǟ1]FB#e7]쯜yY sj bKA8ƟHz !w |1&scsΊ^tV(޾R?9gFv\vG6c~Á͏ t-_Ύ%;eZB' / ~%Dr1ܹùT`rjQ1q bq!PQ$Ñ7tEB=qFzF.g\ Vu 1L|~__=.]1A*1MqZ$.pxݩXang Y3y OUURj,ju(mŜ~#5M3˧ήxPk<؉hZ^XOL2i&CÔgQ9`V`&Cy8{8$/J)8/Ԛ<(oO >.M+B[¦?C,kl\r ,9B.K}\+2q "*ZoEa/e#!N2soF2zݑ3<8;[ *AnIeQen.^̞J>%)pd@|-{0lfO;.!5;rP_THd\= '5+wT7PкfZ#My[ϖ֫ql {'t*K,lOοG4$(eSv!쾥J\c)=;nXpehnHpozD>(/ "jFS/.s0S+_h}{mAsg_Y;e V+Q(%|@A \&pW ͱM&'3T&1 Ԗ%OuW=dCzF~OIO J*9,paw݉BbaPoI_x0< ?~1xP)#Bx?jR;{.KvCgKHA)&HjUpRsʘfި+Js ʩنΛpyBE>D%^B A,d pBڄ &QaU0΃eM{p4K!gFpX2P͐4<~c^y 0Hۧ"ЇZo!aWB wdCV WL~g`Wpc9h'}*0ؠPh[[,9G֧- #t,ԫ?%A.C7zPh@Y0S)B%X/ /\wVx-C4d}hkvE`){O7MqY\:Zt]CdL{ڮ -ӔA!(׀b=tl ЏIɮշᵂmb^d]ϖ >#G}9zbm$ l'u 7_I\Pş@$l ; e 5Xo ! Ѥw29pΛ+ˆfE5Cɒn:l LO[ZO1O).cc2Q87n bl+3t4;:VD/އ"c `02u1`Oz:ZJ S@ꑢro&6z1P9)4%uYC{@(dDHI_ yhPɡna\!'v7Gy`"a=h+\Ŀ+:tm/r66<֏~ MVZ62@n,P_}1(Z-4]*@EOug;u[5Ϡڔmз33oiL(#m*pƳ L?$Q)xזR+%ʱP]Y'CS [g^U{o xr\\~j:|BH{S\YXM%=ě&/.1<#錌KX,x'&YСSJy%- yM}vP^3\hr#kUȚwd2#.}>5d`xG; kvt=GQBnb"<YKGXvw T{NVD>0Ҷo.&H)V)W q`ʽLZ\̢ tb,8јv ʷ\f/0jmaW"+U\UU Z;KVD]S 9O:ǰÝ'\{m#y@Arg]l۝3 4jϦXsW ~ZvQ=m員₤&xl"_L[,*N}3qf]'0tKPVQ0="~Qruqn0K8.ʲnБR{*T<R?]on{?%ͳ|Buh[!a=5<lz<5eR&l@KrHtuZ91*s >h䑙_y*t/b#J.[|؏-dJ_w:Nzb=ܟc+BeR)I' kJt@Fo|aC/R$[ '{~Q<$ݡKWyւJPgDXQaj[:pˈjA Xk6 P?=ɳO"_~.b?ho[?an)h#!́IP|qEY G?{b4+U?w4HOLPng5W%%J/_ d1aD= ?B#wGc{}5!( o =-=uP$$S&U8*/X& t>)+a( 9r aM`ODi)!d]6mё-m#h1zU41+%]KMm.w,t"cPM4z![l_<~=@:(U|E6K+;.d-(#`7⒈[.@3j0%[ԛB}4LС8c)YZ.KEX[ ߕu%{'zYmn^jU A.+lzmj*1SE Zm8ٷZ5b'{nB[j㎍2KiSܬ &3sʺ_mR ϒ3 j2 C!a8VYJL":ܽURCʉnxec4˓ *Fy!\S=RfSM5ы:d$J?Yh`ѐ1܅D{>V갣~ۻF퇣N&̕ Ry+u]|XtizZ&Z .Pze0Li2Uu""T᮸67>=$‡I{a d`۝nev}3อ<{dT=>KmWfW F^F/ BJXrNHupYV{nKP<)nDЅ)L,nU{5~/E>K>nm QXʥ>N A4gdk\jG:oq[Gε 8_uAts_Öo@Q^7Cvs"Z(! v:Ao2EYCi/ڝCtBTjy%އ-=tKZFi8h !N)÷{QBY*C?=Rhk;nBu$=] tq4Ğ^P˵:e6 ]sľI[ۆmzdClv<iM[5Oq Oz@%\aNWD9_¥g^PJ1ge5,q:Ge?pUָ S걌:#)=`bBVlˁF'9HXDۿS!m>td޵n X3lҎ:K C|ψ&Y8 0y5A H7lǧA"rk1ϦTҬ41i Uj Z\bV~Tu!鉘3FS}#դ#cĖϳVyH{tjcIiz樭(t: #bjP2Nó:5%\~P ^"?)sD( W! 3 8qH)Dphܬ&(!~wDz[ZԻt0hTJϏPwh>z `=*&ϫ81Jygyy_=UDB:5M uO\=9ْWS5ecȜX /]z1/B*S|ŮH&nfݍ rˑ`\ɺ:(,F^^ˀ)<3 Uvu0GĪ §c/X:x:w" ׷cX-jȘ GBqp?j٥z*g  2#8 PˏT%ERGmȎAJXTJOPb(NNix;LE0\It"}4.)n$ qNJKšwE.uR$9>Ic2dԇJ/;vV\p6B y`\]6ˁH?wi登(Z' K5А j¿Jo?sbrQYo60O{p0?Z֪}0xgڇv~d&_K^(u-/LVZ^ P$r|ZM1BޞBW)5+9ψ#k+y8 HvCU@E 2eposL{ctnjTjKBrx);yOyU:lsoUN}n{8CH0TDƑ p?unȊ HLXρ~B'؜3UtՃ|vCEw7(थ0*L:\*̸"QzQD'@v";JX_nUQ&`w-̫-Hcd$HGDG,ԩ >P9B.F.97(.976}e o{q2=07k+s)>1P/PPI`2-h;Vm.(=i\hĬ +Ai-*`n#|4Bćmܽh +5I/ϐlgf"=p+yE';;:ۺ4, Gu0ng";z0)Q֊.HW+ h7 q%=e0oMD$\͠xscIq"9wW QSIG5y=X+74? C5n3Z=х 鶅RD`صcNW?EMՏ\ ی(pW =/~J=7sjBr+;4eϝ,b=l a!nzV?"zE|]g@tu+/ɒjHWׇU|LWJI2ph B/K4AT 4=~|3wJ0p<ʍY)N&|NBL˧%е}xȀ{זTӑ6)|~( _w[ͶXORbBѬQ>Z0sF“e.+|-ޕxpX14;S^v=6=7$IJ@z0oz-Si4X4HI^Z`%㳍ﯛb bIfd f]g8  8R$Jٱ'Cl7u7NYX&Հ]Ua-ZpxHYHj;Q*&ɨO-'5@T{Mj92}'՘HFIB|N@Ij𜁔}MV&1c1$1ב\y,4g43Y  q#ԽcV+fN.j~ Zna~9db=Qq)@XXc+UYsuL7T Q9H_#d|+Ul@0 *hjkò0/)k>Io`Y'ν=X\Jl?=eZS6h{RyJhBņp!Э`cZHYwjhX8p8$zI)1ׄY KsYgy>-at*k9@No_Oȸf7X$W2k/ztFD{'qe(a"z, ^t ~TU0 $FWڳ%ZrΦCJj*[ehdET5,.1X.r=E/钤P@xsC/whl Ok|LÇ> &\dIW䱡 KRx ,(6' *-*GhnLD4(Bgo׹vPƬ 1,il>ߺޔrn}tqh}&G0Fdi_0ݶ?=?>>Yמ\z8CͷXiޫB6}+hT 1 毀x$E56 me1\x`XchȆ|$N-d:8!a7=}ԄR MOρ.DHk/ SMqݥ#vrf7 sD$*!o\xx›O󻝵/ɝBx(M;D K7EFx~-CWK?-*_.֐-/|jkxdR?UlugepкmM0 ̑Q9=> ⒗NV%igY?h%Y$Qϐy+uS 4`hTbg5D3!_rQMa)^- bCoU*>`gQ:nrരkjs?=HeK 򰿅3/))IGLAmZt0ķc ]WCt:ٯ%ʈ(cUym{7'/>5elOc/bؤW<E×y0W]~O!ePojݝ442:U*|:\Jyw$}mp0NJv@0"904['.JA^Pa5s3V5 屻6=zUcr5pq. GEn pIk-ʎ=ekꑬ{@ iWLj5vbOts U [HN˝2|5-n_E:UNsR8cf֥Yܫ,ZWN hXCICtrl G~4]S*4_0Ti7cأlN9QL1tA-Do\+W[Ҩd;!Y險ԆC[1M'y&~ } MT@%~Gu{yX.E3GIn9A_MS&(AqE8(>trSF2|k(TQlЉș8h䤄~)$pޝ׾go_DHhڙy,i#8F~i1uk*P-$!V߯_&?RuK?hwa[q.ǽ\zY27sfx(X9' rС;rpocÁ2t;В~)3a1ۃ6PpFZwq^J[ 9鳁S#, ɼgM:X6q{: te*حF#DzF{ԫ(~ ĉD2Mcl[E"WБPoHF!lRmm'-Uy2&$OO& '>TMr:7o[v+݇f]`tTKp*; JڏnKݴf`%a 1!s.`'/+) ^XW>e~7iCZ1.ģ &t ,;72/u+Gyr]#oLuK%>K]3 JXJSѩHdd6qA6_X bã?OL-Z6pև.-e?N̊y5k@~-A`7fCcBc0nT,vݓߴ)l刪* %1#1vXiCsxrԂ b6+D ܅_}?HkHH,Nf^z[t0 k])OیM4.41}UPb"pv+R oF05| oLِtݨ)o-D ۋWK3'EL$a b!;v>KڼH&+ G/e; L6N_{7i,!DOgbP~ڿoڭ,(V>Yrl?~Q9]`SbAxw4:ۥdH>e(VlRpM^5R) mbFS2@KhbMC_7y,Gjpe ewb͏lOg0>^]G(ujQx{sg- .*J}+3`'GߞGvZ+a&k\cXǡG⻷K")&U49s7v2Ș2#&)=񭁍E;!${&65)DpPH?HɅ(sP04Q;{Lg͓d]N_K0w XQ-kn Tr6_)" ڍW/-ALjܘheۇI w:^8i wA$4ʿW!dҪIDglT.ͦUk#Ff'?XgI"(K{hr b َ*bu(<$YPRW4nb+y&s- TOB~15dդ>}> 9t`r"Gxu"al|IJסL3 cP0sT./]U}~׋5R>OhDgrv{c_vJ X6cH1L. u<r:5⃋MLsQ !ꦓ~6,,f7^:# ʻu.: X,OdRj23d,}хv?F0] 1ԛld'jDH79aҞǞ@/Ѽv׷8sNy o"g'X5;, E,OCvNd85 G-A6~f u6ayvHщ`ܕ ,q V3D|Du(Kh,G̯{{pk?B}S5@^FxXo+^u l.\ZTҝa1Brm/S;6t%x;,2$i(Fy1]  :;$̈obH8$rC~l@W=#}= \r tWqr*qLVxΆjN$Vu5+9'1bμ’Xj2T1 tޯ"U%y"O\9m9VJecM(5P/FlQ]ԃ&Rpd l$>E"gО}3][ҋ(j _@ce(b/ Ybpb i<tU߽o ߵ5zXm77~J Wmʼn c ?񬜲`1LJFf>׍wpvb;'HZqpӡDW-&z u$4@;a* ge\@nNѺ*G\ @Bcv=ѻ›Id1NڍJ3"NF;Wy}e{U4{eHRu@jYgYg~ dcw#[/Q/ۙGRӫŒZIH\ ݨ=<=Zgj&{3#vSL5Խ[ &Y`sK@c 9^-ꕍnBމ`_1Eፆ r@ǰڐ/ cL,HڼB$s̱/sɩ8ܻ鮶iw*[sVai y_ِ:Aw?Bki>yFo-FM:+NƦT Tݑc1dž"61ᨬnBU-!K)nTb ҩBBF>'΀.*6F6fJ1H47ŁLula^8?"̀8.NȟC%-p!|\ Dx,W>*"? K[ ?9K5"+TpI.J>3$Iuѯ6+: _9@܂P {%p81I.KzbpzaQs]#Fm*Io#~'wzh1bki ۟&l% 7jO@>([ `%g]ݎtnӃ^it΀((biԝy#R(}d nϲ]띷QGE&IB47pSRl) ƧVՅIYCX}dۦN_;fFV"E|9E:8^CjF ~R &D(;b'<հf@mUҴ ,lz3˒!#Bc ߱$Q* "D[27HEٰ vbinwWƒ `[8*l y _6~F4d[5.}y{h&QXWW_s۟a ύ:HARai%Et9b8c`\ pݨq3X?ZJњ@SH7c N?G9ӎliPAgy/RAFOAR7}OQC?tʾeDCc$GږTύFQh}n^WTT]as4ۄ&E5S,)mۦ6R ;vyY~*cf$x5x`CU~KLnE'3 &*xI Ec99/W50o 0j>M2blD / ߯Z E!(_OyF)k2;8oC9C/k3Mؖ"zAl@r" Ҿ^|2~ nia\ kePiGR|sN]O>%N,!˞MA`m6 `) q6ob:ŐE{Ӝ.F!H(x[llt݊k1 !_q_3/l`%lń&/DGFD٬އC?;32qy"hצyt4el< g<[Jvewc~ׅ)A{rH4PC u'OybʿLyks~&@vzbEŭ,Fi[`Bu꫘K|Q#,@%#x.#Oer#{_3E6s)âP'%ۃOvԞ1 ZFy ^EEiCs\i%YiN>Xoף"԰z_ϳW&Sy%%!֢u+@ b)ki=aJ[%G|նs+@ᮚCI."7@xBL'ZcgWĬɺhab |%Y.äNlLcƥ~(yWTc,[-D-ۇAu($dΟ™OLbn0d莪o>z4$x), ϏS=E12릈!hؑo!3$]~յUrB}0fGېte$SYp> ]\Vvdג-,0NHȷ ,=`us9*:b%&~{=ro8A8#%q/\Ŵ8T_EqTsNQ%.> @, (커M3zjJ˜ &s+H?qunƳ`siljKG޽z7\P}MY5ݶ|t_Ȩ]'d9O vn$A!h=|%I9!5%1 |s;ƐHS[]ڟJ -PHa?2_u-@إ9Y[{Z ”]HC8=s}-h7f1()-q7Z' ?rb-:J#y)D]G9؀,{v41_fS*6L0bk 56>D B蕁>y$&ױmc>;m"g/f|f#e2ԶOQ %{[%a/WbwTBVwa|ܢ QřjXIN~/G^YCl2'P2@n۽8Viu7R Q,Ư.w^H +?!b~ۏs;Qǻ ,{<,ǐ6y\C(d 3d nF0=a8`|~5Xa(X4 }Z8ۖARC7;s-BuD+l9 O 0'ȭ{S0rc9%_3t ~R`NF_th)OcԖv*~ŢhyimFjL؁_GtPګMރ~ sR:r?h$Ϧ@@:yvݒAiUp l_n0he>UhZ4l`Ӷ2ݹ坊ʂZ }ކ 'f >gF%ea:˴ya=]uu|OE*jGU<*}#!/0=xV2'zj Yc&] 8$$*\гed1 GSr@: ֋G'֤8y#WL 2muOQ\I|y|Ii?l10auҫkإydp??fT|E7J]v? z{4XqLdCV o)8`W(LJ'k aԂN`HS/ h7E{_P3}Of(UK7 Aۘn?]::,y!qtcoLs`7oBAO(Q M P.+' Y5lF iwxaIS:/՘{^)C0zdQ993 /Q.=gx&HcDS,ŵ oÏO|)G e ^Ow)}?"SGHg[~b첨\,df[SX@-||N£Satzp28ǨbqwhU:a#*G6CԂeu$.FA#2NP/Ĕ6d`,J{%=Jk(rH*OeorFSq)&hJdgM tK9pf+/kME.bT&V6.ۿT#K:2le%?{̘2x pвVR_.KeFi]&(? G͟\~0%`r:z\%_rIvLT6IP_z)bgx斤Veobt^KQ.M8KF /?F=1.lNN4BSJ#F S {, b s dZDVV`To_ c2lס=nNBw.PG4,"MXU49bL, 9;1m)SN7ϸ63׍}cWJ$(CW0Lo@B2\sF"fU Z|sIh]{~e! Zx +~6h5UsDŽ4cGu ubst &|}hci'epPVldc7{n9jz ]`k aLl;L0>%\1A?b[SA{qʳ 0&!\㩻x^s󑆏S|G26]Xç\&jr2UR$0&6]+cWiUOh)^6{r>VdmmFdᔹ.Mڢ)7b89Ϻ1m^ t %ɠptʲ\hNP{lΉ!AB! O^mE"QPlcޱȷLN梆E"{_Q U-Fc\,OOEE}*P mc1ɓFŒDTu"._ Q@@5ޚ> K[\䘠bz(*}pd q͔B%924GO7 <Y]' sٺIrW WZʀtd}IUĮ,)?~/B8u $&&u@/eȸ2@[C{ QZVoAXelځOVϳk_?\GqY]vr,4LXZ7&L|qRHqt h^;㱳0WP,?,x ]I,Gd/"|Ȼwf@{;(l;bWws:a7AgڅΥ3CۂAE{(&08lp~Fv14o<iVywI71Bp N~2Y~Շ̦!z1=*}ꌒ"8/;okMȪΩWt~\׬xZ$_Rg(YgK? gv VH﹖`C#$Yĭ~ĻH%ۖԊKUQ@~!wmjcPt4'P?w"kB\lPA)QEtX6+}rzHjáH^=WUAT_öW׍4}_FtCZsQK|5sޭ0{Z*Ͼj0~.n%(+h~0[njsdI3ڌ$ P.T %|aܫ#8|N}UʀᐍJ+ppAеeM~gK­/p}&tn,a =#[}gEC7G7zh,&U!1sYEI˶jx^@(n8*ѱAg:sIZc .Oyu^K4TJ2b@IڣvM!GCSNJV5wf8x|^dGT8Ug0W [3klƸ=愃?ouWRTTf#9S݁}ڇek>}Ƕ\$'zVT ۼ7saNLճL)F*˽hb+p@`|{nm 5'yr9f[ ĸ~U=;6lq"dY~xO]-/u(lr8jGR[0R6Otc~AI|Yb2֧巉S~RI :^ 0ej!Q9&NݭSAvQe,N2A7r 8RI zdv2+͚nd*MWׅ[$ #D5i>$|r=GQ#irz6.64 %`0]Va=< @ϝGկKLW؍j٩Qh6'[8}yAF uթ0;,"!)j0"؊`~ Tʘ[-NVjn~f[lז *`3?νp*di+"!m2FJhp+A`VݲcR n1{q\ ԓ hh/`jDi;fѿA 8M"Ts}\oz?_ \r?‘y!r{3V$#Gſݜ3HY(>7y1왖$NsxjhuD cx`bzU6F"MSbJ egDO&ƾ,["L^ XԵeHé8rDQ2ޗIxEY6M`u3j0^&]<{0;v-XM!@`o6UqAz#)tSUL*}vPPul@(`׉> +MgFwB2mM~v]$|5BQmhR1V ]d\*({rf~]'OsأLyLKS*[' o7.Ʌu3ćO8+*\謔Sr-r#4Y T PPBÕ!/MXމ$!9(M{SI-%LZ-RUd$,1xJp "-U(KIm蟰}"Td~էȺuVQ]K~N~ y 1j zu>^ie>eMCszA0K~5՚heDT#>ڐ&Ҕ}֖eSAzI[ӓ^^\kRw|?rIjC 2Eiց4&X/S?Dx4+db5`6_TB+%gS[Oy:Fy1{ķXP%ʶfTuzbZseC/G MZtrǪuv߼ \'OKaŢ7~&zxRuSR~8'ё@|qfPyZk){pf9#p2kJRyr*^XNr.3ʹbHRDZ){HI?arq`5ƪ FP7b GEIF勛>a8sW? s'.kȽ[E 艨uD3x]6(cPv6I~54߬2/c p?NT  AYGn!qj*(]>9IŞб9 m3䘲l `.9dkx9 "݅nx[z*gUgxC:WQsh9J~h]7 P7D&Ԓy7pym<[hMS[; KfQA=†Gm%pjH^rٔ|"7'_7ӔHzyz`@jnSLmke"#DaKsD쀚p7YIBL;YʡB&eRrKN/o+Ԓ#EvqG sevvNKռZESFܰCu8@J8[M€M~h22jxݗHGwӐhk|j ̬ko+R7I1xV`|sbq.[xOGMl$\hA46Ww0v犚=(ʑM5X®~{R栯l@V:Ɔ_bA3g/%A=m5 R63X+)({OMF۾$/Ů M ?Ԣ-6SZ 6]r%dONB2cǃƈ(C3|eL+<̔A! .g! KzeBj]W/)ޠgH铷j!.!i,mxȆjl-z~z*ŇBCSҫV/hoťlˀ߰v9Ӳ+^"gq} $ND*DP`INJdBzV,pmOb2y2'PWz y\6OnP0aƛ;|í$`#LXz&+I}5(Y w5\zt -,jȨ !cO`:g6pKrWD0~@Vݸ\v(2HE˰pSv69@/FY[춼SZ(g4+~"nbL<*^:t"O~W*҂!ޞ+s3P5-?\ g~Dm2V|S{@-]@!j2bK|1:fjo_Zϗ3ħ2ՂSiZ4̇ W ML59h۬Uz(Nyzr_#{H@`qh/¼BQ4Tk xξ#{ŤZ?,٥x ǾrqB1`:'Mt>aiJCw\9@T; -ޗ\֔ݑfcma>:cb.7hCCZ䑌/9R@Jƒ8oM7!실PFfIF{1d#'Rv'O?Yr?0qE۶wCh hW ngV6C1ITjVlHv ?*pI{d]?>0?TU3ШN72Q*Qޮ'W9* đ{$P,36E ,;jhC~S'Ѵ˴/\Z q%E=Z6JY̤T>&tXcf1aNqu&y-t%6AQ5@CpUEGHAh``m xi$|ʵr˪HO>}\%a$ZQD{^8>7SO2뾫 #[9щ k?~ 'OA;2lB-,UKGd+GLjɤ: S0uj6b߇.)Z3JokS;ip}CaݩLV"hj, Ld?II ?QxP75PdZY}zzzBD *yO~$$RhORG"{!jH\AĵqYDlҐ5Q ;uCenROLoYsdB:[Qk}`%* >Jj^uN!93aWڐ\F<ç+AI`"8*\Iij]L$J8i,Y7Qb.5=x&Xٹ(&  Q?j^-izG`NQԝz_E![;' 5v KIx:WG<"ד _fo;J[)+Q^÷J*QTs9Vl*\Hx)Vs2}k/)c#8Zr>j_pS8;K\@5z}AD0(eiA>D{]yR1PmhMNFMꅍ_qho|mWDqU,_GruVbl  }Gl6c2j8˦Pvvܹ'B[:lے\vWUL<:F} ccSN6X|&$;|n2B_Brf9}nCIywRZy, fZ|^I?ͫtZN.f /&8)2IJjFؔl9NapT/E /Rp)DX`A(^uL#0qO2{Yn#RVJs;؁/JV-M 9j_=//NUa^3 dè3߹!pdkX$U(bNY)<Т͹_68ښ x1~ f]T$mUؘ a3@Kf۹Q9j09pAc9 \(0\8ig鱐ХM14%JE? K]jM,Ž1 t%W咏h2np-TVZ}ț4٣ Y+ Di캖j`6f,=H^ ۇ\ʀr*mEFyAß64k<JNyhS!~协ADőFKNN56U1uɘR@Fc)=JJ:۫ nUXuS}Cj4['CRѪ5٬Mx38s'TLVr(r0/C?Nnт;S", 4S8dB=lŖ&)u≣A?,e#TC|(4-ZX"QCL)0ygvY͒c )1=%#aQ,K 2*THeqO.QuIl 8愱ll;r֒\GFHT+iG7 eߔxj2|D^wb-תWYΦ$-&=q>(N T#G7B|HÝC cvͼ0mX!!;* rɧ9gT8KyDnˬsQڔ35K7E$|ů&cm:gN\0\'P<=(*0f>{ _Ll@ΩbU 6{ N۸+5Q3 }꿑IK`p 2f8ǃߞy2M>0y{8J,V]0[Fz]Gό?q2#e}v g0}48& ɤV-y C-h ec% fJL3S1 ˫qRIi kn&Y]oͭ7<˚%%@]\x"Nzߪ:q(+@k-+k{@m'itU6NRvOt'Zq_T݈-)6Y?be`j d-ky6Y!xP-$. W\4vY6N(J,WTH"W3[Ω;Z 2)_߅~◈KV}Wr#M/\MGi ý[cvܪB%PpV]ݢX-ļz`("-!l5V޿3۞\eV&^+sJ26:NwntZ-fnT")-;lPZ%[f䔔:"S%uCX[8ekIN^,{Bl+jaӂʾѣ7J'Q/{winaj= yVNŸ6M.ɏtx]QT{ϏUsQSpo0/Х:x^y]w,.ĒtXD%(%`*CԲ^Q^QmQGn$d*b%3㘵Qxm*"E}T;L@; м! UUh#UĽ#o6˻.=t,-: v0 )GilW)Qd1m4U=PXc&>C܅OeW"ѓenu*± PX}3X-1թFem)xi,iѩ`3"B3+};#ȎNr+v^ёg*2UMj-Jc̩ DZ:%s&Zzn1D΀! (b.l{TjLeéu!F5DER|fX(Y"`gr8*J*t7+~ FAڀYXo-}o v8ah ~L b(,Qz|,ވmQ/;˺/M ϹW=^E{E}!%8\SAڿؔ G> 3UPHdq)2h܎?P]za7Cܦwh%;':+~*-gK):Hju3eIoJHb7Y'>FկMEGI^N;.r#se쑇r'60>jsnn!|EnrXe3Of]d&5M\?ۯ;ML>5ظ B;J!|.~怾h9#M55'kn*sd+,0d]bcvY@hʡT ӗ/J%bR}~z4φP.>oVjfZyڻИLV@Fw4&B)ٚ?$@O>cXOKFWؤVIAO1 kWZ hi4+h/E^XkPL кd›\%n/ƴi*j{U(16GrEP#O] &16eSpzAl Lb=<Ջg+̴<-Z5u(iLS5Ϧ1#i;4MiԞ>f>ڳ#o{ns !.{!rqs-:p\]F%|}XЅJ "ǸV=?dbhxUIbO>MoxZ"58c׉&Pbd>t1@ əWHIs43L" Q(-M>V:q9:!,/dn=@[pxXs7Ke-;Oe1au(;+΅K%;IrνH@u0E ۇpإB.{Qaǯ]0iX!ۊEk6T6b['ݹBt!xyk zxeX>`lCO;)+C=l2hD#dp`5I9eG_eb+_pYqZd_Y[NY O֋,L5HCA Eӡb' vz7r+9D|O ec|?$zwU^%oڡ]}pU]ӓkv;I_*T2U[8pwu5?7%>b=9DUFڷΝ2*~PS\m6k?K J}#}%7GPn8V'p hىbv.!W'ȺM7ޘoJ-,^Oj3[m yN-7q(&9)mK-6*܁̂IJ7NNiY l MDsBDŽ8@eU%uG!?1TC?+wP(Ʌu7B8 WH96@Lݤ>;7(,dcQo Op'C{rJYjO~֖/kź[ 뭚/1Űj܇~-X=:, 8[nwƈt,odVAdctǰE9ژ zwۋ#X51t(0Y 7J&|AǛUe?K&pSL1lnU =Ml@/E98 xzg*HV%qpЛi,{oJ2k;e-JBLaC8xp尙Tjv23d^qbP"5;8ӷZͩ54wFuY'<_0/͹6I@=$y扚4x}EqZ9FimK2 40p3rXndH,5Ɔ&4+F> >bDp=#A9Rw[YdcvMħX[V)DS^fȃ1}N)>oEWWI6r'4F2ey\/ZCGG/b,}w:sP9j0F>۞. b[e1d²% rw}̷o8dgJx܋i=$d)pEPvֱ 36x*cFm,Uac#HBsQq7{5cAl؂~)0㦏V[["h|(,Bw#Q#&uo,cB[,gȘ@$M/@T*RnjϷ0Z_8pY' 묳Sl>[HjF!)?ܫ{'g9x?R ꊘ7<YrHf 89%NaՍ[J,hEmZB4M28JzT2QB9Q\eڊ֜<(\fg@T V`WS*MxVhdjqxl ƌ&ugQ@Y*إF+C|j%28q:4m8k/7<85e 7 mazO^F\$ -5+{eٯDU?Ɠ]#\\)M@e~Ԥ,A%ˁhBeBh} ͆R~G>WґE=C[ 6V@9<(.mpEj;uv 2t9MBbfDgv90m[:!3NZH(0dSo;=7FOP$D֔拓!ZT* \r@ZntR!MjZxxbkSΚ3!xG#*/ͥH\]9!򮏤jh>_Ĺ(:n?iN!Q}[윶QS ȧ V%.Duلԅ5yg/*W82q~ g,d>hAxdzu3[hc1pa1iaM+F߰2!,=3l>@Z]ag҄`5'#{OH=d Oe ѣ&) Ӗctco\fth$z w}_`^4uB4JdsKIJX&5zZ5L^q65@=KI4eXU ^,mvA$~%~l^G݉(&C"X<"lr4~`GXΑ^2[]{ԝKH,輢'ԀMrCK/fj;<ӄVu?e'8phqHVTֵuFިc`$?HJO ;|]?:ЩuWW4_tRǜ?ҵ4NӐǽA&xڡZczݒ)NHnu;$\yPr߿yLBNj,Y Q |tkh3 x$-oj##gFPPGRE $ʘeizrbnt*p"LM%gj]so9[9X WB I໚fRA:~iz{7(1Ix1i: Wr8Xj2uP£4[ս*# XB!)(ث?m2-r)7bԁLgt:GEj?!w~2{@ L_e`|KfT^ I0c&57\:WEFn6nfFRFDGiek Dpk "&Ir.ژ}"^9rsyfWo#fJ wDIXRfEVѮRߕzvˊpԚHJyrk,sl*]?eWOV%h_RÄUmq<RMݦw:^0v'ҥCݵbz h("@v,WX*e3&ۃ%EM*L;a.DJ)ghhFhj7;.AdgÉdЯTTP݈w4= pY1\´% q+7ɾC( : R{~b_㦃#NY% rۻ;2d zΧƶ <ٓu%-bɛX[y2zvU-C6讚>~,GW(4M0˓čیS6 ї.kDQ}NybU+}}m5 ]l#/cц;f`myf^Mf }a,mwpGBH,Aj'@D@^N[Oz֐l},otE(EBxvA [1 _(| ^7T6{ݰ^ |W4K>YF=MF$& (tج(aT>](>E ‒;MBg1&j(OL@{bt Vaj+1.'LUZ쮡Ų7ul/:=G[|4pHz@p2oB/t- bSk%؞JB_fIaR@s]Jgt > ԰ӊddwH(,,]. Fr-Se$㗝qA͖>~;{ RB-FQxS*lb+'4mb/4AO?F,O ,Z4tLRZ}žHmd5}S^5]++d>z-l?RaW8*w x8Xb14\9jCLW<G鱏O*I-1c;֔qG^Pb%Bg҅Bxu;GXMCU`Bʑ8vjd-P'ːp݈ˀ$%H m+7 h/qa~RiJdqX_._0Q-a2s=$ cd^0S0 5nD 91. YPơpHd'5aFF Sad/`FFz2=D}pSF8\MBhUlw0T7kڔN<`>cSNdžO'R7(~ޱ.p 1A%|b.*tV@bfr15t"!̛<> MUi*_,St:n,lw\2j7Ivq 9ⶒL1`5Q.P$ *g0Z~Q/ګGOѮj3p PmX"ӻmWĘT"kFr)M5- 36@8nVdŜnzG6C+ƃ3$9xGGtpE=1t6Icڒ+)e*k0 q (S{ GTfuSGs;i߲5!@nj?qe:Pho}uر+VQ2Nx_\hEb^Snf5;Vݘ84Hۓ>OnvDpAɛLNI0/~ H? ўjһrF &-ɗ<,M;Fݬw Ve,/{.Z;Qd7 l,ex_,x,)L Vn$9U+iQ%Vf\oeqyDX -Y6).f}%̺m8yߨ߼͠DM-š/%beؼt\vwxBsrDA]kY|eċ[_$ZV|O +| tŏ̄.Gn~t7Q A%gzb`kf#ZphU_Z kF+R)N% 5)1΄V#sl"KJ$S%ſKft.1z/S vr |Xִ"O-iyD($AiuEH';5ʐ!CvxɌBc_BАif52#n^ku5{hy~;m(ҽs "'ibz`G/+E~ R~] 2gs0+18 6ΑlA/~Ik+TjWc!?H*w\)ե v|q '[!q;VrDMhTQ)Ú>6V5Nz8nID{RJ ;Cc0N!R<w̝I@v-QxpJѧV1Iv,Ѝ\>ҵuF\a s8ftwB%^b-+Ǿ3n 9y*ۗycO 1f[SDyUc9gV8`.c&8W/ct nbdp_.>Ye[2c9l7t[*-<23]ي~Q~›pq="an X6g @)X2EjwmDT?g"r ŶQCvfZf3'UjQ\Z8 VͶgHpCl駞NQQU\Uvʪ }b^w챱[x>^b =iT]6Ĺ\(g߲پS񳱳Er;c{Y@m %?9{V GBDPp1Vx=S<㽼ߐ/}ib\. ñ?(Xнfwm=Xz2\Unk#:w6 ঁ >}݊(q$GnZv:^cFO8i$Ne5K߭T`AqMv@}X9"O}xj[#f4\}aM*9""b8u䉲7"@RFE\N&;>tExxl!6vR4RkxvB6ϱ`8@t(>ZfXU0N3VtsYpzꖧQM7faB@\&Rkh`Qq^=D_Qۯ+)"~A0\3ƠIyi`DJ czy:\(!M6`;4|WʽiVZ##ݮiٍznY=NwY-^,<;{o%(\~Erod0;4n,3}A븏{a1<0oaVIx%Rj .c#`p:+~/k݋C)jGUݸI p ܉{dRMIi-μW;xÕ]Z Vt%?#Iw,^C}o"|Ē'@ac߅yIئ0S-pOq,ovGLp&eE";f7N15s#˓嶎٥V c#Qq%n.g#T[*VzElZWPIF ~S% AUG^ӵ'_L^`6QB"U B]BXbMhxu)9#t@8.ʣAƃDv̈)Ga[ 4NִGG9N!ha PdI],p@-KBtQʧ‰u-g ; i "Qy1l) c8ZrwxtPbN> "^|s~I"Goi&W9j|"nDԋ6~[،?LsW$&VUN`y!m͕2*:+"S2})oSIbWYv! aZiV&[\.h@B1qJОt5^#8nɓQ}4|_LI݊V\9ծ2oΎm c;sN`F2#-ya|TCc!хL.}hAGs lТ3ĸ`Tҝ[6]y͐0-ڜB'~:0V92f{]Fn|ZN/tW<}mrzDtItf:bPOiǑ]DB` Eb,`WyR? ͞6wXy/ 5MllV`cs޵aEּCSXj~3( 7 /{4UoE(Rs^޴pM52`Z&SESH~\:굈`¥2[dzOolXNY/~y:D:Y)½˧ΉlQиJ5}` O~ks0lȟ*-At' D.svOۄ?Hߎ%sWm]j0>wm3!KQcx y%H'IXUNךek9z5#b,r_͢Yd b׈B><ٕn(`?GEd3宅eرyWGL@o-"Nϲ.G]۴<]CwDNFet1;1%+MΣƿ>Qz;bb@dS{4s_o-Ucx$ZO@O1$wGCհX@0G%y=mnl̙+}CHpv_V9(Hy\U9Csb"? Ol{礦q'MUDžd ҋF8fSgXU tN:5ʇޛԁL*m wiAE`U%Bw n鴻=hrs|9&͓YQ߅*>$O!?w1IAlD2{Z'az)_{e[D}\Civ :g jn$y̜`i|(.d>THͥ {<@Iמ&#gOy r/ q9o7JM>8<#:>Y͉ҭv}M -V3|3G! 8Yl~:鵫La/;+=olQ/&z1Huša0Y?xTeU߼6N(nF+z9Zr3~ x򊉙?04>6"@mj!بԾ}yAp$3´ c+8+5n>2&½zbb?cITc@FPzKkJ~MT3tjz&7z?)3n9Mnd"Bw\[,)4g4hzvթV[zHㆱQh@$nA  Y>ic*%V}z>7Q0Bf ɂLu#fxm@[P lߌ։bR.PW?ˬ 5˧&jCe G:>r4.NVYSR6,"BN1 B}z,_p$k bv`FwwY_(*qFߣ ʼ FFء5!T=a0էQgNm%PX;NbA>ʎiZv\/dۈyEJ_ #МIoop73ȃmG.Z5:3̟#61#PT !mP OylKȿ5VVyQڏ*3*0|-cL)MKaX.آT+DW?Ʌ?_#q sb f^gBQ\] NM Τ<ABs]]'u)/>߃^SXDL xyN)JCwڢ(?IxK%lκʋNaiS~?k̪:xTG[b2异HNAqՇX"^H.\j4m^`:S6~e'y[ kw+3~+ek7_cΖ]Bh_iЬ"LvQÎ?-1j&^`iʹCۦ@+\Yz#W3a9PXQ(Xc@xR J oX0&"'G\8xR:6FP&`AY36V"cKq_5;& {җfSGA1\A \N`ᘵ 7at/h^hIsmY@|mAЭXya8 F|<=](6 Do<JI$Vr]͛Lwmg> n)jݗ-w NԠfFZK>U(\Cb:qo0s ӟH+CE9ɶ4wp--߂- 1Ot'+!4N'yB- %(3179~t` e y޳(]C>!<f#w&oL~d⩚f >-K!/(C&D/^aË'LlFy--;L\~n-C_c5"DShݙa!v0&ƾ4~Ի`FT0dّ?`<r1~w[?'y-'<z@E s9JMB>]VtAƄZnZWĶ5ʏ׆Hj A˞B{4P-<l Rb>ԋB?O]pJ~PEGVEb(Gk+d~`C¸dWܸ>C]=Rp {a6ho lH%Q:(tRH}I'ѣ]= ,)*ly^Ѹ&88v&IYqp vqlƨ'!V']+q n5'{FGV:y!TenvZ ~)vzgBˊ.@%sh=BiGi/4/5% ={gqGnhQ!(pX4T]YmLNٮ\)GD kEsxe^of[UH9t.x_AF{me骡0gnd ܟKCam/Tסsd5QG}%a TmnykXo~4VRSwcOPi::&1>Ƌ7xnx鑯wHyxcD'Ԩ>8Vo2&9J#kى=ǑwkfJ 8zX>7.4lș(Z1w7[X[E5؜ |kpqɤIoPTsG4jήpuF C<'H8'* y2@[229.tҜ@Šu6S3~״s{΋o9kr@(*ngMB2 Lpq@̃pt^>{)~|XM$i0ZJj IC&h5{McNXDHIǣ%1VJ^Ez8A8/=35!75j 09 S ; ܵb%2O"5xJb2Qy#%6 ,7T=g-ވ3ՙW7s4YAϗ-_Oδ0 _Y?K ۓ&r*цL*}HTtHWӏY,efu :-~Tx^))E`X/_KERQ/̯#m7.F=$sGL:'iT bew32(CD0Fi&K) tDwH%߆sŽ Es2'@@+;FĴ$"A2ѱo,)%퉣 _j;67k6 U+Q֯;R9*9<-TM-ܚCx#F5S !=n.Q L׺TW ]&ۊ)2?t˜s0菀6EbE"E,ГZA?} c! ǯߵ8vIF:ʵJ! -˔Z0y:PWJܬEk]kJt}a~*h\# bVBAW,>XD\GB8P-n"pC{(`r+#\8J0ק[si#ω\;&m`~з|y x3ߕ5F@`{[x"6x_Z, Q6^@$ 7^JTA/b8&RS3w˹#Z l,``OM4-XKGql@ QL}^iUkZ])KEmU~lCzt&;"7>|7CZ骑t^mL4.y)P: 21pKs6d ?1=TG h1#\D/fN9tFtjw契A]vJ GEφTP )fK!7TY4}-!QKނT|׼Î@* eaXџ+":koRyY$sYV < γzx7.q"uj^%ʺz1E浜#%>"u+R[#/tjufΜXM;֒iTg5#Yc+'ON.h/E}0ӷAJɥa:k iaC+V#= 3V\%LR٧]:;tgU//RTdo*=]ٿ*5@z#.Jz/*Cű0)JE)-L&4&JB2ե1x'@rvH&ǏK.0u~ܲeٺ1h)#Ѷ(k^=|Z!W=e(Rh_]gEPJhx Ѥ"P$dŮ2cŇ=1ɷ^AOR[s. #N6+dJ*p2;zy}T }o`ñ$A>Et-1&j N?O&y4JȞmc1Թ~]lVٖ7G1tx̠Qo#%;nu=TM=L^3τs|w* qT5Ufc--%Énb $Hyށ͓c853gVHMM;K(oYCJB4t`w'b@ 4 G]D8bM\] ՝F]-Goh?FԸtz@omO s$ź;+ KB;,&0}rHc>WrΑV|>EQ%10X2*0Ό7uHNSkk/Y*J $^؉ HfH }lyvB mW1kC/J2& _R_s[ӤWMڱ7RYA: c87%9-|z*$w>tB{뢈KnPkn1'-N640H&[6|N 84"cFe}/FWskA8A%s;d5]3GpZ>[exB% BɡXtFp?c7n;u@*zW㳊Gj[/gP!nuRN*qHap2rCҲ;ho̧6ޗ~` ^a,B.m/+ݫ9J/&mQFQZ%)ѩmz4IN =`E,v ;in:.ɭ{n, Ԇ@ME6U1`@e'7 /l[ 7EZu A@`(#&ANM:Sgš",P,q:G-s9 I"%DQ#NOj٥";T[[L"yǂ %h! ." fH<3-B|^ݷuIzs5m6\jD=j) &i.Xg2y02E~-‚=UMzL^nwvW;T֬əhĨ[q/"97w{>T* d1j*%QA`KT셏s_N֡RX\ƑPcǹ_Cް ]-)!4Ⱥ͍|F,9٘karDz=s7M&^e}JIj3 :.3#oLr޲g&KEyQA!~@PmW@̉iǨDe ^H,#lfd71[?x; ?͆.ak./fDБ\J巫S1pv1e;B=r |2T h>,C3= P!b%.S]_du'z\~o=:=gʇtsi0Ot} д<2{JRNEg\Y+4I"NwwRK$ 翛Å\ʌF\L ? H&i!4d׈]|-غs 4dU Ijxw%|m*`u392Wy21:W(n1i J&)>~ [xN@\Hfbl6inl 3]!6Z^rq3\$V:`ٻz>|4kXSJr_jL$L,xqK>|d:uP0ܼ LKxtݕ^(Zr?6-s.&vǜdT'R0!R@7-^c;BL&emIXo4 rs8pYPS/C!Ʒ{:"I&.@XN-xw ZT_.fk`{/6Y(-mS0#p+&!R.Cs~\Lgzt)A?LFmJ̽8a.iQ)/^>3[ OWƍt x#'9gfD+L/ ֟&DB/Fr߸`uZXj- c6}jteUAJrVbG$&g11 @GdF|ɾWX(`֜x^Նᮧ0- WlsKA9ćU &vZ(mT[?l UA-+~Wr/1pT܄( HlG C!k`s6m]tL.A&^jzϫU|!5r% cH VBm2&=)\9ǫ7j:$<㓇~U BFA2:r /*W`j/bJPvcU'#, jstDZ d=RUttyjN@"9ZӗRQBRyFT=1.{Ыzm$_LЍE7h?]f5y6OJn-OI#1`#\̫#f-D`-2"Zے44+![wwjroh8SdO] \BL> 6 TG[9fN%{B"?|ᎳͷٌE߿qb7#| *zǥEhIŖĈ\R GXG0b_cZs#G^8 \V^Ayz _Hf!(N,I yH:^D;rfN'aJeFC><8:6 M$>Lŷ) VU1ٯ4Jj $z{?W.~[{.6k{b*Z@)9zU0.2ΌZw#`72] ~߷dw6-}n>\ 8Ϛ<|BF5\)ҾI=˜*@Y{)] q>%z2<|D"dNlHu]@vݰCƾ x[!6E}aLiY͉#rq|ޚS۹4l>hXYg$?k%3:nE\WTlTlNؘ6%}`:J1񋵜tfHaݷ.r l̨[q1oк\V.IВs8Hydf^_YjGs@̡b<ב\~+VnqPbs?T7/_Rb oRܺA'7,>ְmn&|ݣ0#e:?!{*%~HPWKq& gG}4ھH՞)\GG MB!6%m˦O_Bl ΰ uϲTEנoLo#IZ~e($T5z4H(Ra"m/r)v0#`<{ Ch]ʎ''r'/n5(n?";X2.HuΚƴ7_:hDnf>@#[\X$ _h7Z.'Nq/~pƢa?ʛ~g㊉Qd |Dp 9~5_>JOr]4 -Fp ~#'&_R6FcZQZK© mb%&CVF[y\l 'shWηp}2> ZUGY*|3X|+lyl K'(^-h<Gk~W V Ɵ#C,"M4<#my7MV]jRc "V= ;+YU;vae \yZdq! WY)tjQ AiT{_w8[ %3G$g.d"UӜS-7""|Ua8c$Ddt;870l({mWc$'PplNaẟx0ěX{Mߙ23#ڏNp* Nh,Tn81ɫ1'$K W?.RA1sx/36'0yKS8ωt&{2'1ћMr-Qrpd8bsi4ѥ;Yz3}J$ckxyaUZQO׽|mV^+<4iP :N "@0ccf+ޙT WNł[5?rVm#Z/u\bQhdV4l?_MHqD5ʬnڗqjM R7Q= \[C Cj_A?Cɐ Zh6'LU~QL.OmLgmގ#M{9^ISO<'fKC)PWC3{C^ w:95ƋabB]'_h1+MmȏQGU_,W_PumqĻBd50ޯ}<zʼn1 ~+Yh/:!YV^Y E&;F;l*xjו[ .Fц1.7 d%#̋ N+klA\8*-!%&p?g<υN 3 wOURˉF8m-X۶ 7թ/Ӭ23WUȰ`u Cg8>-I.ӭ*p)W~@i/j24@X7?H0n;_Jv,g ('%î4{sHHc ˎ?ɅDA/ .LN>HC}KdG, GXX#|Hˠ)Ogrk' p& !Z5[ajW nx(%:l3I`Dd  -cul+3\AڎixRJ60||ܭbXLd-Eػjp+z<ƛq(mZ)HϊMv3D< *x\72hCQM)lgJ䃍+mg|Qg8NKriA=q;W"Cs*.z] 902w.fPDq&C_Ȑ-qT55;OE u&$OTTcH@lˤ}*ں::QɨyT]G5xp o>G&F'lP~C ڀHUZn16P1'CB`Qr%aOQʩs-Y"{6]>@W=^R;DC|L"gRF)EU; w [A `΢3g48~bFw![MndWmq߀_#dbO2jM"cE'SU3>tkW=CWq=biԭ}N ق[̀B?o$t&J xX5QhoqwS0F>"m&Q%@gʰ z[LaUG< -N|~"0oװgxY.6' V)-jSμFб;&Dc巺 ZWJ..CkxQO<HKh3CTNǴMF]_\`Q ?@mWوd/LJiP6.\-A/k{;bmhk·ڪRgyȾ;\gߧ_ oeo|^ySaѬoH]5o'Ý0\O;sT@yAieюő >%Yn?zU ۳q= ꛪ g(ji ]#)Q֣eJm7XI"Xbk0Xn_9*2L*3q,17R5}Pc)=1êUS,ewhAәfwIѱeX& 8N'ss,!10aX6#Š~|d ܸ\UCVϟ{#;H/h)~[?qAb^O5B/0vN'jaCV8QCVJ)t]k6%ct2bX%pM''Yc=y7BT(r`< %)fUO:Foա 0hqق7,LKpx B5k (iiCGߎ&e6.=Ժu5']LҌ=0 ^5 / '#+T'c@)8,U=KcK`fJ+ɛh^>QUE|A 9}HɘQ4嫓`I7B4:nqm&?G8\ށнDf시& DꢯOvJ?M 3mNN+"7w]Fj-: 0~cJՕ Ɔ3e{UnH!qhl{V=[p}Cx- `rheSF1iw.^%G7 =SLifJU'I{dD{iՃʴ-$O-BwBuN[zr]:w`}} Z lI"b`ڏ%SrhQ:3 h8^e=KEڒBo,?/y)]x@2ji5rGP%~s)SKAΎ:0E,BE_3~|X+*mбB$L\A['3_m{n҅!&,쇕,Ԏ"!/u;:-{~J 6:iV$9.,&u/|_Dl3 ^u@9RbmV!zNW7za)6Z+caMVpf! "i*X}bazʃ6 ޾e qMF}j;*u@r 6:$F-![E 6y)Up,kcIHϬhRͧw3 ;ayI*ea0%7=B.N[C%1U˙-*nZlIKz|gey pw,— TsaPd0T,>=CC؏ݑR_ /l,sK@o%#o'sx{i,&Tm]p0_EUSl*D;\(~N _%}  <$xn*݃qj7P01vQi(pt n3%; T.g=gCs"N֞-ԏ[eH h%Wj C2XZsF-8*X`Js?EXOGr f8{>Eeȓ h]1_ƨz /I=M9pA1?t1K;qSI?O KLPaK{v2a8Գ$Kmu&\_\@P%~_YߴgFSNwNk{d._RKdf-zu2AC*hYF5!I"pi ؍n #߆1KdY[|+_,=ӱ'Ei20ChBZqFjfyq;x M6X`+[԰@JpaARObr'Bsj}(i;vT7iުc Wb%-FU kZ &Ǻ۫oh ?Şϡ?M{~ K,8,cKZsrs|DE^B#1is]$u)*x $ @Uԭ5%vnu#%'wKS友f*KEUK.s./iő:_2 g<ݔJ? w_Y^ <{\NOv\rKtӃqh1F@'Q5W(#\Bu73s;pfd/ՌS+P8:27ώ h'Klg s[b5a(f՛I>j ! :)е,Jt(a$<磽R/тK=Sс`Ä |v"0 {0Ԟå`o$ nX`Vg;;-]Ny+W:A|؋O!ғW)vج_w2_ $(<[Do)E&MH|h[@1UNG.eC̣\Qs1(>>2S2# "K^X.ocRT$4QCX#94x0dF?0-1/Js{KT.L,M8]'pdT3^)Q=|M݋TݶpY`א77n~!.>JlX}v~&ec%ǀځwS&*ً\+Hj%ŕInzH\fX;Cn|k8AHnbp\ힶ⪬q%h(;A@!(NN~EC9aX܆̌Fx(L~^+MзGVQŻJE]{ \^.tZBé?G╾aA(x͸=%4ЄљeDI%(lhPDlH 4T"<@.7"Bw>{Kh3Ķ@b K9'*~NmLg0&Ů-x]AY6B_X=?FZAڬ?|ĤWu R2eRKT6ېF8 |^azHaj6L=crOloj9[įW;Y]PuX6V\06ƻ)(Om GT(ȳ;E N Ӭ;uDwG ,Y/.2@RxPt{  n.;RڀE{L}ڙZ APŷ*q{c3WA ss,]'s1nAe6O&e\I#v7g6ǂy{ Ą fsXmI(dܜv1a|5{y eFT,KBXn)B`IJ 1YDQ|oz'{wqC3)f#2`>搅U6x ,.wA_v t4D* "` >f)~n`o! P?_\mKؓ!t MV!&0}oS~Þu2A u*`QBZ.k-tNԔWgrCiI:Ş@.' |T=`D ҀŐ#JkfEYe{2$SZI>]O"0,}b/*\(9RԆC[hw4M,j%>B^ݩ?c A8bnm 8#;܆b _ǓIjJPX˜1,;͞r֟RtD`48bDzϧjR0ȁ1Ę_y>G](I _YqǻK|atr'(OSH'w*>*#=lz<~4{͙oRnc{:v@crǎs 5Ot$kՑH6)84*vNaddBC6ژ!} ̉BqcO6S!8n$kvzL+ZS>u5o]A!cݚ[Op-w1uژޑ0ܦ.,QXmbdQJP{CqKXx JMWrvjRAm,nbXf_%M&-}MKٜ_Mއ lXG'&񃘔gtQl ފԎ:bTs8ePG{5,Ĕ [Gؓ>ueW(F'v,`?)P<;Ha, =L97ht9r$>XLs^2]W6 /dt BT83۹zf?-*Q?di~L!5]qVn)xGG4>-d(-ׄẜ]$v>L&8$nɃAU*ymB-=Zsx BSOzCWW'WhEn_у hVTy6gQh@l}l~EǸI\HgerͰ/?Ksu=XǑRAM(E#`3n]o ǞNu76HouP=BL* ۸;wn3׵P].`2H%EB"ߑ9G[[6D2f8 zעčXb.plvEVm,G{k`͖ ƺ yD<ȣhгZ)TvWأF|bwRlY$k{^ğAvct 8bsy{40yE@ҧ%[H3,1nlߵHsn{KJBt?[` *& mX#4:ZJ7h\}yf '}O}@VEtxgFf&fN{ihȐ@EwT%LgV_vHj8@ĺ"=?en@QU q(2LDzcϖSyc WL຿G"G>+%u2*EV Ӆ\E?HэqQI^>H]RtV/c0 &meԊƕ`4VM߮ayH&\X<ׁJ툭k$M ٥1 gOp]VkBN@,A=d )V N'#qAAIUEF1l`/ls]bMN|(BR,˥oF'z-SY&A{ ^elkW_>ck&1R7ۖ!e5E&cC*DUJMGd4vj7 '4ʐ"Aj6IXNU|f!l<-P.u)$Piw.p)ɱp8Hʙ-{;AA0;Fr%p0fo͝wD%*.S؟s)n+<\v ֳj4h\1Ư{k⋌B婂!94֋1A~(|wd/m 7Zz$y MN~#Ba'u0OF6}&}Mn(.A%:u> ^CBzf %i$_PLz,fFwDT@+u,[d4$`͚V! U_>ٽ(\~uҒ]uPlZRib:ݧ:R%nZݒ L*s* ?z`]"> nF\zpG8P{V;bK:aTHJ67lVǚM^6( $fdžqf;F9x:E0-D߹`B-7(ye .'~d, :+`"BGP偷+Zu qʘ-c:Ֆ3'-``J-kh_M ou=+wj'Ա6'(X ~}*)o(ӏ 6Rs !ͣ6l%c A⒇]gs\_tkD3 fHvw:^2&983' R,b hEEKk* ,m4pScX*r]yRz[rIxFNTvJAHIWJfK@d;@tђh+ZҚ8Ax#E혴+h_*ҜB8KCm2n~N]T$qx>5?Lk5: (,)# NX&Š1_g}ZqW~'p$~Ψ͸eX|@:mASm iQg7FD*8:ZfCv+*tdɜT,g1jFhgVROFr.iՔ^O$FM2 i " M(|sfWnMBhaFO'zz4\~F=rL, .Qqbq`{#dEb'}RT'q[ itgw> 'T_xM1jeGg6MDg3ˉ>H9z9]AGdNB]fQxQ\žʛӶreŋSOa;穽H6y^|WzJXbdkJ-53rM,*yiuCC>" xIY@IX0o=^%t)Dp]!;ɮKX* pl,M ! q5wӼlJV& \nb{r厥VnB(Zt$t ffcuƶ| r2LwU1Y!JuSBAj[U F٥!HӒY`|Lb|уw6XNΔs d3]btHYIeϓoEϻ58 0 ;F;W$U=s#NB4;Eap`Uv:p cYe5{Zz=4]b{Kkk(̟:ŸJʮHس ԯ:PBNz .ʶ` 6A+ZC;'!2^~BI#xa#L6ᯖZ8 MZ"@`Q钞TN=3>U` j=lq5lnod xWl:ە.jy8_g~}ڥ+ :5$R x:#Z :Nnoʿm8FҀ~;Df1M$Ġ"~M|űRܺ5D~g`gI6j)H1YKݷC ؓ: VlT0}rd#*hʛibWNkST8(KLf45ԇ&],͇"؎+wdnbSd^}3h'o_Pn~J!Gr QXG  Q*9!M+W^l#z0ҍZ+X4uRv`:=xqk*Q:nu3SoL^y'|++PnllkS~1$gez Q#Z_I"}0IV\[p ;{x4eJj!7?ڂ9j$[l*`/+TЋﲘ |Y.j4%41`۞5!#_a]sG9wE0$&o*5A7f&I]EK:WL&"7gŚ_1,, JP+sL3zn XN-׶Nd\Rn7UD]ȖUٜw^f tU$]'pnJJ*#{q 7!U>QXHZ:3Ou\g^#bW'J>")4Gk=M*nѦpbn 8TbMGx҄J_URB*Ɠ?@ԻO1a43u>}Pi75'5/:fR9Hjҏ!BǍi̐Y t-JɛphC14LJ>?’):y,Z/UnaDװw'X3쇳[l +)R3u - l>lt|h\5BC Y 5[@@PW!e(g[_]m֭5ٯyxۨ.ٕ+ ){KAvSN킦8V]}kk]1K YՖA,z]i ؏lyN*nƉc۸ԧ 'cb9Ng $m(K1a1I:;:S4gva4pZaR5YTI"LP@&W= /*7j5s( ĐVoBxshͫ}v8VZ@@+ǹaczk? [D_Xo&Y{Otx;ZJjf;X|MU{UB-)iYËr.q hvsNR#'Nt!֯fH0?8{`7İ sKFʻ}q5P4eO 8)d_xB?.):ٵA0[ސUr4׉O1 :>pZN a_n.Tg~ B1nmyNn=*I:jQZK6\ar@MږE1k.-2$?LڴQSnde/<dŞŗM-6FmA򅱜"xY#3RY˧B#PIIu{e^ x M'ZD h~YLzL6 {hʶQa\D1_v((w+3#"֎%CvHN=givNy-Ёϓ7_Lo*[R^ Pfܜ-5j^ ϱh͚ %J=F@A9sf`^ɟ:=WaOU,~S:0`,."wqySL27R&a% 5GugE͈'ثPѓ&v680Č-(7K"VxL;:_ Eyu"}'ˍ a\s};WЬ[h:CpXEckw&AT#މWOw4тDbp)T& dFsns^b6 EƘe*.c_ޔUXb)B<(q{'W`Sk$yab.j>β5ÕJZa1ĦtiΌ2kG,(8qV*ШP\ķcΙ<)+DŎ-'+θ+a7z侀*gןZxp86x@k~CgT/:Au;2^3Fy(EIE7so&trx"A hWTOl(@ƅx>u/NeǯP֞ ӜIn(p98U&@~'TM!ِ jOZuCerqX1Ƽj X_VJEY}^}.Tr Xڌ3Qo]7+wު0ZwkE~8d~IN"Vy!*w캝$W89enKO`uP8 ,6Gb\P{ҟy<'dl:>8{EV<|VGF+ ;׊!zcm#$6`GҞ{-ÛHDi1ŀo~f)=#pvͦ, 6>/߸IW>&"N!/ F$'mvB5k~WI[q\@AI]kWwVo ͉˙g,4=`{xD#4܌!u%ლ8}kjb27R-@+X '9@rE;;kU.Meg{10+xBbC PNM{/%Ҥ%F0?U4Իf(m ч.Kw͞`" m7Nˣa)4W YAD4ӌAh#>LAQC0~]a/tRzFTT[Ri]nʁZĹC8eAƨ ZqgzS=+`#7qD=1 za}/v5/_C8q$N7Wan[seɧ v/E1\gl8IfDbJs 5̼5!t'ݮn,@]tdf7KA찐n7EY؝0.'EA%;: b 㝀n" ڑpM>Mũw9O`*1_+\XpUApACu>bmM辰^,}-)ŗPA9k6ׁEu= smc AjwՀKxdeٿС/u pjEX[0ŷj ;QunQTV-.”v˨AZ)%|'4#_#ݦl#j 6G_3$;-Y˛?m'uqCtZam =@[Bwt11a'zaC?[ IEsңs@e5<F91D'AQ=d{Vx64Sz"PMP/\CY\hT=ǥqHG\)pHNIf dIa?':,be:!ӘfV?ґQ !uy2G!^hXO5*<2%LXkMq,Ap:9T} :#NȟBF9:)!oXiº%H3VD+gU<~?')M[ sZa8K^c  8p C{bk1C>D/Ds*V;goV%Ak N% I:r>կCж$#[>D\ǛADEH@/_ݚ+6c` KGwTׅ]uj-*(A?&ppҵaʽ|jЦ_ذme\BOlɢipu뫭2-tȽ|gG0 -i8!ѐ:p^'5kޭKɯj wv[g EGl"iA4A3Yq([{!1fG\eM[`;ƨXT7 MŮ '8|?2OKmh.ҥ ȎgS M ̤2Ҽ%R9&LzS[5l?jʩ7j5U_uGN# e\H@|7:F;DvoFZ9AA٣{?SڇH^n)wrݰ;RIS_AzO@PcEC Yؤj mPE_4!4Lyi^`]E]ܟL0-ƽn2Wg "W YZ