sssd-ad-2.5.2-2.el8_5.1 >  A aU]TTxEH[QϼWTs];.Q$]fXќD5m=@I$)aG.ݗ'jXWlgGDvу(r;a,Y/_,raԿ/¯w5HCQB"R:sYn_ 4?r*Ch{nuh͕>L|^HS&%I'6 DCpEpt?pdd   6 3PV`         |    D  FF \F(,849:cGg Hg Ig XhYh\h8 ]hh ^i bidkKekPfkSlkUtkp uk vkwn( xnX ynRoooooppppp`Csssd-ad2.5.22.el8_5.1The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.aZx86-01.mbox.centos.orgxCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxx86_64'&txK8=OAAAA큤aKaKaKaKaKa)a)aK`aaad8eeec91db454aa9582e7e8dc18207d7897afdd47958edab43e5d4112f8d62dac88eadc0a218726993334dcd9591ebc6d73399b564e1f952bac5e386bf0226498ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903c07bb33468c098f22a7449205b45b6e26bfbcdc19806758e0f20b7491b2c055afdbf5e6e18e497a2dccf74e4ce17c26b7436f0c6a02605509713b62989e022963725192be57b77104ebc7885a0d1559700cc0effc1b7503f00479af256e33894../../../../usr/lib64/sssd/libsss_ad.so../../../../usr/libexec/sssd/gpo_childrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.2-2.el8_5.1.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.1()(64bit)libndr.so.1(NDR_0.0.1)(64bit)libndr.so.1(NDR_0.0.6)(64bit)libndr.so.1(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.5.2-2.el8_5.12.5.2-2.el8_5.13.0.4-14.6.0-14.0-15.2-14.14.5-2.el82.5.2-2.el8_5.12.5.2-2.el8_5.12.5.2-2.el8_5.1sssd1.10.0-8.beta24.14.3amaa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.2-2.1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2014460 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing [rhel-8.5.0.z]- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) svuk2.5.2-2.el8_5.12.5.2-2.el8_5.1 .build-id7d657288c52e589839573847aea8482b71b338a2c6c3f8619dfc377b9afd93eb19cc79e0cb571ed8libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/7d//usr/lib/.build-id/c6//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7d657288c52e589839573847aea8482b71b338a2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=c6c3f8619dfc377b9afd93eb19cc79e0cb571ed8, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)99PRRRq$)dE$ ɒ~`֪qK  cuP:vau%7'zh}}%b\HNI*7myg p}5S,R9je1xܼ(炮'])k헼瀗@z{\sFJSý.@CbBΫpP4լ-0nߪfd6.+; E8T4 C#/-ݛ} %n_n_1֮B/ʅb3pVW2=S[+5lØ򍄁5JxD&#l& $!b+vPGA bZuQ+nosgFiZVQ~*TPŇߥ`V{ 7,w;ȶRu+ÂG_Z0*c5/@X석ΘM"Ą_͝GYed-GZ dtm1U8$Y.Hm9C jKzWcq;$ %T'\U~:ؚNy$+anGuIU"FbMIׂO>藸.ޒ6cJ ҭ^RgKrJ)@ee>d%"<. KU2N&A~FN< <-ҕGdDF(ר*VqZD1-MqAQϭoNr>"&7H0急9Xd(\s>YϣϞQ~a1Z65NC fOH' UWϢ6;`$"͂?@dzVˮ&+7<#4}`f#>#yև+"x"֭hڼgf+[OnnDȝkȬZ (4Nb.ӿ]2} 0Aa^/@os &o^뛮|S+vs#H%ӶBVaU>Rwݾ>G*?+9LPwƺ524Hb_x k[oѢ5s\3Өgk]-=Q"aht!*0)q2m-9Rq^>5=NP%lr[ڴF"; CVϹ5p4Ԯхb]@d^/(M KwP ayjn0XG9v Vɳ>RHY [`rY&B^96ruz񢇓a7 C̭{.׻07 .C~י&!i7Ɗ9"MU^f$|?559ZvEj,j7Ĺڶ\|yK6HKt~h($# 㖯~/5$0_ ""< SDZKнwx} şSBhS~C'n#+-LQf _"~[SpVvTfN(!10Bil4i |YSr ]%;{O3]p#~+U>Զ>V%afU|=]Oxt%jB!BzFj$Wj}"ff[9: b!U8Krͮ:.&,Gf~;qX=Jϱ>2M$sBJY9iW=3m&1 ۭw%:0&øC;r96!/N[Mz-7/Qd@\Tf1ۀWnyB_ZFG<%UJʑt9Q2lQX@5K*@>$+r̭ԡ1y5q!zB*RLIٷ7S/7ɶf=ˮ Of%=C8= p13nrpjpC= K*:eթP*q2 bᴋf,N8 !<;h-$T5!nK{BVlsMz N0]؄@XT: Ut&(.G QtȌ&@&{_3TNǐ$w-U-y\`@/3LAj h @[^?2 nSCk/v5Fͳ8 rh_5-ƕ959H$@ɶRW|ŸSB&AJ-q&N"|hN9|0 ( YQMSʾuAܚضa2GN#i?-xPdߖ܍˺I{_R9wE7pMFI_xY9F"cR Q\G1/ $R*2zOfs"G(׌h?_G}v+<p )ժ)h){X@m@a rDᄴxr ekc.G_fk_$3g,lg.Qa#93cVKSTz>˦v(ͺ}ƃ>[~gH>EY|;A^x:LۂKo *0.f8jHL¬z;8 T}5rCüKY'>Duwu5 9H3+E1 GfhvPvu}s!GՑ F2JbH{6hK]WݍH@n&{; )kG?? Oy*dA8G~{~O# #_gU>Yqk:Bm OQmi:.hpUMIO&D v]SW=X+_ G~oH7&91A)˃D$iL5ϗTXCyY:F $_K?Qt`O<,ĸ3h_iU ï(wQ2:fbdAYB2J+V+Q끷 z^5uF}F-Y9,pnw6:_ GB!(U`=L^Ǟa̵E\壐pGpk̙}N_n!Ľo $}Q܄Swa gjc_tk)F 2b꣥i%ˡ+ebsoE,qD_[\ O 9nHFЋ j.NTk ="Ea#a;b.26!xk!%MhjIױ|/J'LjခI۸,$EN&&LympZ~̛1S0s~2oW[v>K?~rsS??{[؞g,8C2ƽѳ`;zًؖQ2rl{ ]<5HkmꩮOi!lP/'h'8I1{c?[YBj[ )ڛo+>+DYb|0bv|i릘 oht2Kqm^ڒUG@qu[=t{2أa#3 5\0*.)I%%Z)^{MȀxMfFˊx?gzƞ7 +R-)U}2(|U>> v KՍ#/"Aƹi@6[ʉ"|^\_Y`"2+?(/M?B ,gtpL,yly Ř ODMqߝ-4QB q 6[ô>dm^74L|mo&^CHR<=s?w?.XYCTh9Vz*\j+C_·2/.obP68貙vƂn,Îա sXz0nEee" bk*o0/̐f|_(]dd`*G\r\,:N r@s=6kySSܣm.,6I_GYܕ>A+l3Mq[SdVYrj r6G2O`t奧e4X3TɎ|33kgz ]{)JpǘMG?u<$+LFD{24TWqZdM,<((O׏%25{6=1F4!){Gs-vLKqѵF #p@"uMt:`#`)qاlpׁw0\|KD@J /MeW9% ;« ?/q{ %s#/aV'cJ?kn{>4!rS^G:;E.ghLok( gʈ2q`?s埳altˎKsBXcךJp*}y$]A~ƹ(RWB5Sϒ̞ռHV Jl(i-x悬$qV3m$~osZ8WEػ>#Dr@M#c BsIMj0%QHIv<.dzF @2]k`.V`l&-CMXmtIK- 9tuZB*4I,¨K&q}ρ#hD*+mdZG;2P/SZ2 JΕS0W?D{W)2'SiC9f` 5y3 5L$d*m|4qii +5UIi ɴxq~zķoXr35͝l_*$56Oo1 Pl|J~ Yh`ܭ^:ur~OT_Pp-.k5=X9Cz9`vvi*%S4z}}ݺF}!SKW6 C_*R#6#i?U'2#4,]+y _HRq ?c6RA|'7iN3f0 $OW3fxyE-{%>Hҷ:q.0 { }f!o>\r_sEe () g-RZ1a$HG)ze㕅x{h|rJ@ƿe=t@' xDO^F޲v;d3^{o<w$ eR8}9wUKCVOuF䵍5KEB-VC28hp8}~ 3-]Bcs}v 3n$@bް΍і$ Aro{^h$̲4y-wk#u9}QewNW@W-ŭH Xt5 q8P^;.ЇYb28QA%)IԝcU㼌⧪ ,bɸIvX7-d&۽ls:x5WcsO[:BW>jAi]|`A~a^fHKONS*Tt> ҁ:0rE4q/3`&rֿNIceð$ =O(gIц;1[2Qs³f"j:]ay./\ύ[!܍a9] B_dul^eJn,U^mZq"t9(+Ç_.]_ceTZ~3'o"z[d2KEkSb>@ y o  _gD.>6&q6Tg[.??{S?W̔C6 8mHi+` !߼ 1nv} ^^ iU]q& a@y $!jsj!u''%X?V_&-!X9T[.@(RuѭzЫ<;б`Wϻ|OVRQ]a{ HyQ^I.,nkxL#i¶k-@1@Kg:Ȟ ~i A8sÂpQҝ%j'\J>P<4{MǴTd[R!Zq7E!,v=Ы K ݮB68<zŸG]?fY1(!/S/M[ˉL)LUAKcw#oPGiJRlty >wI0it6Q5< @p,C!/ж^ UŦoT5Z83rp`2˥RzT D j87`y@IjG.jd8>W {r30y5O]кr*O&]PKl`1 Fݼpp*Gelnr1t9@{i"l3/eT_Ե1}|sF I kBϳ]lP:fW^HqgR(*w-I6;Rb_ xl7kp8D E43)cqdE1dsjd`$fQj3 ]ml6@UY%Z 3uRȫ8U mH,vK } >O{līMᾐjHm|/l6W]{cB6xq:zu}WxX!w[lG!u ry܀P"چ*u㡣vtz+-]ۓjmZזD藇ҝ.gM\G;F2plEiC1(T2BOFAWxHeWo}DOjZv 芏\n>;rMy8rۘ Ab*Җt Ώ2 -bJ b}ǜfs$Ku4OÁ@OEJHDfpHͅ(B]< wO5B!)Ax@Ń/7h2|P7p?xm:Օ~0WG%'47Xj#ߊ޿tӝ>/0ࡐ0ݐIi4㡱OETRH*DX6A? |; yckdd?u<)DSrT5sQn/A[kǗ~$o_#D,n+U<JSx 2K j`}\Ɩ< фʒjNb6mm=234iO)ׂT\U$.Osӕf+Zg 7pOF6k>#:@r^FhZH_+Mdt8Ht236^,)v3̨<#*fr&d` 5k 3]~ 'ⵅۀ-r\ F?vm5iR/eX6D;@ cF[>U)`lg+=2w2fթ*~RO#g~BɭdxyfVW܈!` BK$XyI%dJ\t*ShiƏ_P4AIm#.*,T3IY2 1aJzkIi6C)5XqIV꩕xQIٶ8;oxA7 h`vc U]wPʦ7HUm pDxZ^- KlBZ;tyĄZ2tg~R܌Q^O(^Yg !8xC?$M!"Qւ%W(Z\5Ol#^e֘TtVycĕ\/<0ǒ>YR`I-m,eqΌi־I ,Q%gՑz#J9l 7.JqTw Y 68q-b8I<-ٷ0gD[SxbR|:KH<eIo }uF}C[ENC!%m8-:_=tp\H$)2WLsGOfZ dL)e-ikuCf|^O|x R%L(~YCt[6"c|׏ߗ<,4jE"eܼfdd` W&#Y Wҭ:IMjDBfE 5e3$bx7 8L迣@3U_'jfiδbD!TX浂*}ɚ+C&p_k=cvS\?/w$os+2tħ-M:>B7''fB*@QGgy*M jx={^#,8Dz-Qn 4yA})$pŘSe]aGۓ꼤1=CJ$*~/)>Y+%6ˑBZ14Rݱ ?#puUӸXUpsėSpęh rdki{f_FMrSX"nѭg xHc>{Ebϙ >=sٙĖ+w>v CR hj+A`r\j`A"2,0bH+I0*#qFwס߼žhi$ Ps_@*g#ƛ5̛'sM=ԈQWuթvN"&zGQC8%Mݴfh]>pKjҔ){ Md!-Z'rx% !Px?8%afҬ79Xc8@_Q*I"< wĺ<HoSCF!Q+l}^nG9#2+W%zun5dܴ?WCϨAWmRm) !7qNi WF.'j]Ԁ9 2mtrϸ )r졿Sv :cyU-r-ԎRxךM9k @a/fc){W=G2W A8ckGwmdI>muZ!RUgXKDD^uIfN+%OBqu*oܯy.&"QMEhva;QIb2J9Ք 4-##'3j( zL騾2G7+d'{(f-s6hnܶY}~ jm15 _:vl].%g_ яK%^sG mq6x=:ɻvZI(c:K,اVgޔU{6J]ݗ&0HũB1jgF)'6؈/  w >b`եAe|%x >:p~UB~7M&ٱC(eY&oށûD<ˇYƿypFϘB-˻nP H#Y bn*]5[;Og>Ǩ;d|@ZJLĕ[o- bf >R0XWeZb6z3UG$RUO' +.htpVFU7W{;y=HY%]U eGxFŸ=;Ng>)- 4R*llYw9>6&D t `A(8`qrr0b6=) #wEt/Tn%* ţ3X-C43PXJ`}2+#$N({,x^' Uʸ ~mPJ)X+3c"$0~x5)ClCCQ•ƣC$/*:rFjs+ʊ'"oM#Pi0H !J];0qtO7 kà-Z6K2#FTZ+Z~c,S,">?W6o vlEQ%rW:sP|hsj.: ֯QcEPն=k3:[kSOX#B]qN~PswIOrWōݮ>5b:QLi2YtoPnͲ.V+$Cxܕ@LAV!l9^x >݅ғ|`cU}RmV0;K&$L;뚚6Ղ`mp@c?.zܳoƍUA$9]ȃ7T4GV~q0pq0qA,ed"$m(O}ٞqI tߘ#q~Vr-\Z6(WDCmDsğf)~|Ef&tv+^|B]s ^#HC5qnJIJHL01) )~ܐrh })Z>n2~$^]N5B_'l2ūBk?#2~/r3i}>S>m7c[sae avwm#['hwi}K]'␥'jPw|=aR*1љcL(s 4KR혁μn^]ԋu`@ϴXIvQ7OAL^FCoӑ 4)8heu>?vtt|=5(G XA:-=9K#+˿PM ͇xI(1 og>?Mq a|XKppF`TX7M ^lH%&,v޽vLWHi!# ۧ( .ln*95 Gl/a_V,F/.ma9éNj2~W >'۠q5J\VҋI h);3 in, T Oz”ٴ/E1=+,zp&8{)t8^4jِs5q$滧<]V9YQG*]opgEV?}2@8νq3Q[ ɑgA^ >QӳK sզݑDSBy 9TEAVvWBwpMa'F}2YAP 7orPHM>X #6$DMۥA/]m&R&m;=ɿL]/f>QE&{z?અBB>-Q̥pf۝}eô]Z=Bgv+ fiqŀ"T %PIW} {IڿNUȲ׳N?ʝkQ102 {GmBWr"8qnePdI1Ngk>Km F%nPQ`&D?,8-3$Ah!Tk BB7#ߕ-\ۈfPAIUG]ݟmSxeC"=nooSIt| D S 'QˈKjŀ-H$>w Xf:3eX$k+Qx>*?KQ8]kRƪq]lP<ßвD0ǙգLGvʱ'OFpS[_B5^u5C)o~[; @0.E8ʞk#)$`PC&e/zMC#a#c_9_q@/] 8Mz&χ׵^/6AGꦛݘ;@p'''2gQS@i16n8 2zǷG?Ut$h,r=~XMpL$USyrH"ڬ %$_bl }N.%TESmʮJ;R{Q>[>9ȧN\'9l-Z &#~#d4œk%. x?2Tjr ˫d jN.C$@BmB\us4:XnpUAQNy[NX9Ǥ;>oD uOR#5=  Z!VKbcB3T%黾q|d/Mѿ"Ąi*{!? |hzǽOV4'4r -lֵ+m^K{BZph㣯YBU[E  R^2㞶,Ej~Z.YRes_Rsԇ_qk6,%ۿU Ӭk7>E+ytT-oGۥlȒxh <=ѡѲMqsت6<[Ds#txԼ 0/pύ3yIҞ˜s B6=-uPH 3 V'J>#.nTIxo2vhUXS!BKé3Ho*Y%SZ5 oxX#Fa`iI/r{Ʊ=K,Q: ݞQ- lluKa|B߫^×k#,̾P}ZG*n-T~;Ӄ+ ! K%,U Myc%?5q샐6$=6v,_WGzb ˸WR46k6=J-~! ~_kW֛´JO=@ Q!]6+ |`F%ʏrún7%X \ߜ7oj,樏S&+7ili")N2_v,J].[ypwȂ/2no(>1Ф8.nGdrBjN+%dJus[ ~`FUEhǀvW'̣3mMMa79I??-EzIUʹ~ 넕Wa}1 Aŏ+!6S`J'S rWφkarx$99'Q9_/m%!>?x r(+Kk<۲t?Yzi2 p_f#Xē~O3U^B%y*s؍`>)bIE,=^ngk\kvEy7h]!eR!$/ XƋJ>>`Y)(ܦC10:  =>.δX=S%2y+Ư30AMҔâaYM_'i[%Yޝ ̇gz,YxZ2׬ 2X!eF^eX55Aӣ3zS3'j}Ukg-Ul CP@%9GSU< \J̠CG/s#8z)MGڀBY -6ɸTō{4-OchR ͝ب&/0wFw䀜/= K-0JһSʎ핸=(674RS{.$3r4cMa9hŃF)Hǒ!EQ噈SuF{J0.#m)`{6I`p/bV@ێ6!V2n|L$Z-'1 IXGZWMfEZRrsaABtC. " εI j$o")E,sKa]M!ۚ&Ʌ&4eTHm ,F ݴkBr*pG23b"LwVfC>jcI&&JuB e?ެSټLʠ"Fh\cQ(3*3@N%24 PX0Y:{N?|}2D Pwœw7tGo[XHq]om⃨ܫ!8;3nR3(_3 wNA$D霪 [Cm0&Nrƕ^i@QSxfQ{c`d]<:6)xW$){i jD~L~ /J{v϶kwIY|SvҾ1>{摞cR ~x9luX@iiw_|Lk i:>cTtH{T 4*Q L 1%(u; VͶE@\6O6th Gno av5WRN&|^;u T Hᶞ$ ŧ&V5f3鄨WsKgqJ5j>m*sB\E1J1>i*XS^4LV&^oޓU>bF_A5V#oJ6L*ţx^o93Bq1=~ŲF&*f_;id&/O^ xHvG*RI-R+y'iy4ף#;/2qZ'ׇw˰08ivyDڷEjaj*.0KuZPĤ-[WBOpιK%:@5ƾD2IXIh9C\MD|I;>V2 I.h[0#goa@ qF-G Qs3+--z%vvz=Y5V ʟJ6A<|yx]<`yǻyh`\9|1q?xtruER,X胣;=>rm/dXnU3'yyw 1@HMDaKT?<.8qo| ̎3 =^'#ȪZ< ]wlŎ.ʨ&bW=eD84sfH<\iKRP|LVL77EI{orz% i1M= L}Pcu:N(vNJ?a`e'>LK;5躃X[ @%Dn(Hb"N\؝(z .g7R7n?JY}+=ըցkFO%8V\1s+?GMJݲhr4ш֙ :9! #fa5,T]^(J s=f o,?lr#1INLTE\}s! f;h@J79}/='d:wݏ*E-%}}֋/YBKjFw\ D~Q$v^b|D9XtPI{E;u LM)0*0sx oTѠkKZزЌP,cI֋l$)${]&K@ _u Ŧۑٰu+IS%{,?}z ^ԒY)".H3(WcҝZ_x:5ټ+pL>Dܽm| oáEfW<+ƂGdBXEfGcpФլXwH܌,. 3t{b$XEX_f*<׭c]3mL %A_vWaу6\8ųMX4,GYBfdTǽ]{1bͻ?H+>hJth௉%=GO<3Hw|f 审$S|-c{e>1pUuhOEHu8y'T!Hh ,Yt!cS4ꎺ 6͡EI([RpF-u.EǗ @O˟!i)?6|8 PxLo}dhFadvAAIj('?POq_7!=[wyڌM]1{ЌD.TYOI$ ~1rfyM@ڤA$:9HbAպI^/lpxa 4ۧ:2qÜ7? C<V09ó .RlyP$EJXt =vvԩXՠ?K< "YeV(m ض/q8YWrfڧ!hM]Q`O@!g!cc#tY{7RR@㞾J !=VN_3!nٯa5 ' ڠʶ'{HZ\W!Zd?:M3P?6`7@S_25\ mNlkdvJ~ {1˃ [a{8P9?*IKE|>tEpO\[7ΟZw]OCu6Zzi6\,B״K;)p @ 8Ѕi1K4XgEl\92n4aAUs' 'ryB`DJ\# YU@]q(qD7RIkGkUƣ ?n-b*B/GGau\Ft@i=ʡ6l6h6TܬIͣ}88sG4$={f,wړ淽g}Rp/6yAΩ^P8yD\χ3G9gW/>jȄ胀_-kET.F3Tb; πVNIvwSw|!.̣W7[,9hlb6#bm- b;U;7Ή?J"6j-+_(ZoOM}{7Y>q\"_.mU"4{4, ֍ %J?E2)~ݣԸZ+Itի<&S g>@o 9SHp2lyGO7v2ٱPC"ǟt,npZ,AM-q>(793Oӈ6"48C${(q 9-m D ^b {h ppȉWO|46 %}@ @ɱD' '@U\z3T@ Sw0IfQC{b2ýY fN;=yRn!;`Rlĝ'5b˖,e۟&Z M%.'HDFJ^XXtZB"Pى;"E|}xYP蜳SUH&ygp7fOwSctږxZt6j 嫾LX}.\+2|2{EXƇ75ugs?4֕5m?ʨ8as^Q#zXj M߂+bҸLb):</U#C7Oy> jmA+rc|PK n,'gK:@,豘KRJHt`KJ<8S,geܡ?OǷ:}HԼ8p ,m? jo qx*A?r6c5he:wpk0}0@Mr]h"*]z zJ L~Ó̮D"_IJ$Bзue*#;FuDaW.hH_dƛ4̦$qyrp!amb9Nt ıȜpE| 06J\eQl5E\Ɓ' T^~ζO^&2%XF<"zsȳ-|hEԊ|Pd,_xGIť BUe3ca_}'٬I?{[-keeyAO7{Xa({Rh XG۾˫nV8lACC4Au=a4 x?9[+Q9 {0Q&nf򢪋Y'BuL*,ңsn3YʇrD^H[*4@*2[T>}jE7@&/Qr"!QcD?Ԋ}Y h=aVfYWEo;O̫%\HB2P # su"59zw/Dpݺn0;l!fiV"8vۂN揯l}X8w"Ma7̘ﳼƵDIgVF/t7wTsΟ0_l>!:ORȸk2԰c6t:xbeޛG֫ ]IEМI]Zse08hTn0-AZze*]MSCx#yD޸SbX;{p6]rcb4j+sK5MHfcc*e"r9?V¸z/#(yY9%aуdCT3eL ֵU?C,@L @  ض&0 feL.-EhʁaKNԧ  ߁sG`¢"5{SÄr` De $;E.u8ΕD-}7 'w4ĖF-C{ҬrؾX``ذW#YTGaQ2- u|BoʕP jIlP]!="K(BiAa"u_>eK`SP `VClUx;V7N5.taQd׶Kq)=JCHhulL`2i /HFIv A܂`^)w5~c4)Ne$ő}ik*P,{ 0& Y_T5>ل昳&0% &8{kV[-|&5Eu1BM1ZM<[`?j:g_61 S%PV˹VӉΩ0Z8)G-3":թƟ0@KT}x3wUd庐JRfwfJ3φo\7 G+W *qN}Gtɫ|LVRLxg$}{{$Hznω:6k Z-TK)KqlTIh yORO)=B>7L%{8'\x-S&Z[5J$IAyW."i-kj@i)Pf~MPʝ`$;lD{oO@3W+_ZL*D6WvrRHjYBP~N#c]e )X֛G`t+m " QЏo5,TȷcJZbS+IazW>(WDɘȞmc {S~OSl' _ɎS1HP g* [-Āu\Vԍu۰&m10Ԃ(Qs-ݿIƇ\ij JS=':qz Tb8N@ Umu*+ׇ( ʂ=~}~{[~3#'Ypٲ_ (+)&Eh>?tNT@3̗[g=hf2f)DY|Ÿ_ T@XW('^2/đ "󠶦'c`(_7weSU8r<5;Z g;&-bjRZf ,+Oex{{K>]IY<3\m#w\i)\ҷ\Ud5DzDAA'B=\ʖS5jNqQsyE[C`"yi&c Ï7"bwa9L:QaT %,a3!–ui=Wb=>mPzg_ m^U?n9)[ukb.5 azL&@0RyˈkwV^w r\jc0k(~>d!#}BO/#&ɀ yJl ֆ k3O_GKRO{y^m75ǧj;F0.W gmћ4?-c)\hL 蛡Ǿ7SỸ}ӦKm6& r <> ׊ruѤ!4P*KYl).ZbSaLQL'4Fa-ֲmDfW=+V́i9jLY#ӰV[5,ehBX\AZӚP:K¥*qVse ]ʙ,]dZי&VE>.Ia' pYg3u3DvIi+TCcX=*nh>8kOh<߼+^(B|tYf\s`0[ -̛iVyXCڿGbnawP XWDO_߻P{ãf}tYepEƯj\@e/s(׋Ϛ m4zS(UC [+Ǘwamf JIpP*w GW&=*TJ&']ϪCGр M'F%" P0 EA>b48EA@}퍫&5Z໷>*fE-r{fDmΏ,/ƌǸ01;wfmzVЏ!]6\BY_*I6yG1145YuD d/\,ƕSjbMc]_cϨl1K)ߦ]c ,?S%#K".s?`߻`نKkGfJM(k+8g存K&cy N޾dmep Bjh [321bVPvˠ*b8YNq.CwqIyc9'Ho:6;Op_h2#?P<~gexQOBK^YpW)%-7K#l@B 1#VO\jEĐ9)!%1Sw k}ѭP3Ëaa+R%fDw; A$zG3:PIsU(yǖVX9P&^Sߌ;x-*2q\8EHޏu9(^V!c?;X`1n w|Lydq-jI{u63z.M. 5\>d-O2y%I'SYH_8r7gV5\\?jb1mK |O ; =b>o)#,anF3Ib%ѯYpobPGD JʣLdI_9I6e{ WqalR8mʳB%L$>nû6 )ڀϣ\r* 31JwxZ"5ٯj/=7ig~vq(Qэ8 {<ؾἸq8w\k T]J5%hJӠrEy+8|qncfʈ$-`ƿB/qOǑXuò>dqƬދZK`w%q\ '{,UBm4=Hgﰜm=+}= )dOJ(OfTK?lҐ3`4_ /o[_J7ӗf|'_{%@كԼKcYP^b_40=V'&w@e7 8lS&y{ V5 6ex멷4]U4u[fe|z_C-kQ\a7; ư -Ekf8#tx;HuoG+[{>Hd7T@7hj,ccӲǑQnEfcaH \XTyXK(D52`s7tF;&f*q4TZQ\@ _0QϨJ#x-.IHaCk?ilf| J=^̜RRA^yx e<]yU:,h?%KE`J[IȻ{"52Ɣ8ӑ?5> }YTm)*{ bѡI?7ʰzR+#WO07"ɁٺRS]=X?*q ㆿNN0#=aav v-w+%% 0H)=}|m/cNǴ"['J HoBds6GP -CqZ5jL6LVAN"#b|@ &!dUvxR%)1|+˪]LzX@2g)T+)z .r%f6𳎫 pFw".vP:ήmC0ip6R:sXDʡtiZYnd7}}GvTFeYD=;]}l0}=Z83UZ߇e’?.PTd\`͌NN ,Y^sqV!zqßof@Dc7#)~QFVv69#DܶOHw)21F}Z@\֡Ա|*='pfqन2}[Z`†ŝ87W 鏯.aL(fT4#[yJ+ 5WojpchzƏ{E/n1M9+"6kB VyAڶ!8)(NSӉ3&fyZ .nf` b{~%iih"uS! >d0FVd E`ˎ‚iշέmbD&qgʡToѿLjd}r(Jbw!T7Kh%Đi(J<6J0SS魳4 {ӹL8s%c|;p9Id^zc)…JS4dArV3cs,U%vQ5$cSφt_ l˚;ŧ]{d ]əᎁ=W`0F7ޣz<_> FQ| +˶'%xn{B=QCOO3T`>TI5: oH*2·R'/汧mG&_gw Ѧ~5V |ao0E\p=KQ^+ȚQKX̺k eMj F'@e{ "&p6ȑrh.ɠP jPC|q> s+*Id^WnݧjٿDc-4 b\*Q|Qj/N 9y`)&OAk{cEX2s FDq-<>l^ b%Jّ3ח_O ]?Rtڊh7aT\; e8945 .hق' ` 'l%G&Xr #&ҁno*llb @.1x?,@~IR*`ސSQ^o6+4he7DĂDi1g SDRX>lD?<74M6`fr `*^Xx*p#'$b#t^`Q1 7w)jzaQ%~t֍0;CL8mgy$bs.8ʏ6-Tɞc.}Onc"x!Ne' +x?+}sVxa4)q:%ii튎(5nӕH) 24'aY|T5C^mq6ۢ$j,f%Sc慳K'Z2"7 ؏_*x`En YJxEb*MK|@eyM=ȆC[9X>S.HnnALmՎ5E_քZ;ݪw(ei3UOcځ"Z[( Gc”k> jJ&pRlXoXA!HSW FC  Wh%LڑTA0N6jrs̨r\!Gi _v,4F] $vK\ɯ,(Bh CV3C&QâЙUnA R|(.֖ݙK^<|3+C:N\"qivCGJuU|#[%ah57E'R./(bTbvDo386f$VD^l"4Z'7\ [^GTNa={* F#v;ai';VA*)2M,C4lJT&K#z坈hЗ`T^٦Đy(g >j>K&D,_PGQ嬨j 4WMpזspff7Kg#OԸ&I)]4N('969 <[צGWDKhkgZ9 7ȫRuRd"M,c;! F#ۆ ,rмh_ȇVr5mxOpsj/}0?qHvhТ)h$/6keŐ/Kk@@8wSkrtz#nо[uƧJCnR_9y#ڃ&h4BKS@͘'[Y2ߥ;<[φ۸cYaw&e<?>RL<Ռ=]> 5HP2[([<>tU[]N}':03SST>ƽd55 4o~W3iof `DҕWMYk:i&%e.ʷ1N98<6TQ)v>~#o?@P(jgTPaJta4]`ؘ$ȁFӔM`ni˜6J UL ʇKyN.\DphG(2RN/t|Xzvma(%7|YKXqZ@1;*2cc*Ѓ65p]X-ztn\=0mky>r?B'$L`D ОePбrh,y[;mRop|SN Ix$6ܘ4 ^s22z22QH^o^L] @t:eUUMk$%㰖CvݫG9m8moECc'崖0 qNS|eVBN$IKl.uzV+ep6W wwP;Ԣ=ynf4ßn_Jyh+'yT c!9y&W[o105,.Bm&qtjcJUU'@^};@'˭p33@:1feC0,46=r`چߧ/|4ӓR=yG*8!>e9mzkWoSڪoP՞!4xxO7-=?4>гq&OYv:e%?WYo<"`]_s8=F:6EGħm=/x:YÄ<<ه t?1dem¼zQcV2+c&^Sd܍V~v} ;3x7ˎ$:w 87N rsџ!`D(нyw^سc.=.vj|ATЇwz-ha9{5D䴵Gl&^Z?_IvYϒ8YpآsySn gV0GBt_\d3?'YtNsŃ4D2uC3Qq'1[57`ZBEEgu5Z_CCunf F/zþ,<>8 KA[((e<0 G:!>p-$oU 5Bڢ21[mU"NGC;M`~O@ںZz/(Q/7"y~_J4CIaɣgQ\ d§Os7h2dRh4aXgEkqW=EcH!rnTBcL D.~U!P觊)#0| r둶4>q.{PCBٶ(X֛tpA9y x X.0[<25sN'n |:zp'R??)Y@rtx[XIΎӔsJRӐ^)m$[g]" 60dR[AЀ:Ngsޒ@ƜtڂhSK2sfqЅvY]JeAxG,"tD d_>/]5 'D3.JA|俲fPӥ~-W+4 2ei)$5ύJ q+E _ća8s&s'B?L&< ^HF絜{c ;.dqq1K$Նю y0MMcVY2P+%W쐇?kc‘K}gD44V+J0^#VmHb6+a1W>'4[Jl+Q}ny":T=e,DL*CtRLvAe gP~RlAp(^NEq{B'f~̷ejD.cGND}G+yUҊq d 0-`A¿Dg5_" FіMŒV䇼)@{ldOSFZw"Fti-M#g&SMvH_sW(mڬKN/3/XMYYscInDSEJDCAnjübLOdKSc3R٦Iћlu?4`JV'c+%9;4f2,2U\rC!ֲhhjԛopbqٟRx0giB$1*9 hX*צ.ԓ&}E *% ~IJt0; G Q|ݳ.yh*2fYK`) ^ 3Dqמ0MH&B~i`Aזn{ 9 lrriu 0G׻ cGB+vdVRg#wtbq*dix{lC[q~/EuART4* 6.s "͇G_m™~.Uש!\[Z{P/lzCjd^"`1`R&/^KG]?` ryca>f=nOOQ`64-,dVj '/hx{ăbRq.baړrѕ~X;E`Ѿr-4#ϭq9GD-y"@tz$mD5Ѥ[>G5 1^pm;&6Z<PnX_w sr_7>P"1yg7]nDrӼtVnww\uqDB*'#VGxlvW~tb5eNVZOwf~E?SLDz$W9,u]k;Ivª?~+7aXf)OE*"!GM'}:JQS=;7e[f^S-мR@<,}1WnsbNؘ <)<ӒOE.9iBo=QoisnWRHrʠDy3s6&C?/Ldp3#,1(-8NWAItmՍf*Yăx{'Ew("lk:$2ŬYPg<6]s~6:zAmwMe@2}MdĬ]^πTkٮ,j1SLc@,|*>+ܭHa~͖./q? /l DlΛ NEE! %G*H۴~пQ+nf!v,-E}b|^$4g% tt*!9Z5h*u)aAqf2HݮEӉ6`JGOLJb~u՛"׽s~9A bjغ蠊}y-!\AJ~r|湞xCiS()Ća" |Vg(ljH(9_iɔD5Y+mozq&,Yzx`vDF*VP0u 9~ԡC,R- F gzO6Lc_ -< bL HV0X}0 )us8IzY#ăEPcI캏#r Bm5(WKٯze'{د?_SFyUTN#=%俣9~ 7K* Vt@?AfAh P@D(U`KǥlٮI E?* M+Ф紜1\m]`$yÓ_͋되Gꤴb_ EIRV K.!0Sڨ7gJ(_t lGgmj0FPࢅ*6XEQÊpq]^բ@lZ:ռ-PAO{8A\y8w.+](0LT!B$~d,sw'$ٍZPJQ}edhִ. ڛTy?ƆC as[V OeVCcz޽׈WH3 atbI}\ҥtɣbp &MkP;9bAKɅ3IC<tz '6O^r_ǜҪ_+Ԇg0m3=- @X +S7ipꐋ2Lt,c">9o:^,A{@CީCT2\" ܀}djņw=@|_CaQ\]~%EcAAr\SIr,KdvvUAfOCRЭE ,嗇ӵ ίfKS|q} `{Mck0 V9=ELâ_xB:sS1'{*}<bYKΕġ))BfBZӉ􀔟G0,t]xr GB&i8S!H.J+eNQX}7QRZNɣt:EűsErZZse"K1!OyaW! &fWǮԘѪrtHHSVSnًSv:LQ:W:xRڕGoPgeHg80W ؞63a9eSQFC˳(BJJj1w|t=ф .%b/ؿ,7uXb3TJX;wT1Z~",A`wͭ=*d7᭠v˲y98F_o>1e{p v_ uÙˇ*0}TxZuLKu8)ߺKz+Һu6T{N)1a-AT醊K-G~V[/p ]أCJxǞ~:{t>9\j]|^R̓NJ㮍uUٺbxOsuݳѮhfw/MɗqW))%nܜV4HO_TZH*Y"ywC\=ȹ#ɏ"_KOqI7PA/"А"ڬ Gd9"mA2%HC0hV>o Mآ3yqab&נZ{~%rQI3)-2ׅi]U%FOkb,xc`"OKA^ڍU7XX-|Adtםݴ 3JE|1Fۻ}fՊ?y$wKs]WC-Vjiˠ-FT?0 ?gj ]mcaJ( rNyp."H2`1Y^"&x3s:ŸjV;f~ t=Z/#@ʼ[qi4lTdPcKm~{oM*yQ 5x( O,hH|7z/ \oq(gIT'XJ}{/r}^ N y>2iE"¦9oXdUxl[ vYUz2(-_m3l~W{slZms*%ĿAG.ưR‚f E !>ʳQV+  rE=kd6 r"Һjaf"Fʰ3fJq=tˑ{   .rQB[ggqJNAWuR?%4q~eMo 4tٖhP_kYc| Ect}Zhjaڵ`)ZNFFCd1@ěcz_r" :Hj|I\sނ`jKt5btcS23q;y%d˗4C獋e%Mݳixqj^<6VCQ>!f6 Ȉ?n O bs@ʎNx-L36dmi{M2{'[@s5Uk<'q͊ᩐF7 ŗ/%?\2-Q 'sR"1CROϐs#[%}qM/^f2]pnf w̔!IӇsƍU00.)Kăx#{wٙcڦ>OyoJ%q9~Ak&H7Icit}*̰y9{&2bo.'L$4I O"pqjeU љ1O!l]y!hd`^x߸2~LsTyHMGÂ.+OZmXjsZNz6ҥypKҶٌqY ʸE>.K;D? A P|8!>^O%af>{H2Lhd:tɄOjgzGW۳vΖ: }g̝}e)6[,[w@q%pIn Ѱh.34[ؙZ*\9L//U );UUh"*Lvh)P\ɻa_'WŰ~u0VR1-Dt|^ I2wQdS:*2Cz{-HWPtr;5aFu?f)f$EWlou.?:yD\B<#͊cKy޸ߖAjV٪ܝ0 6$b擏D c>~1Xrڅ8/&sj9!W'͈l''VFvHA`\\=Ts+9IQ 1n"a#s~lrU\Jɲlv>mlS񗍷 0ٜZ7^==Ox[l\Hۄ5GhK*Hg}/^+ϭCB D[nrR@.ʬC C4Ӝ߸ym IG T%N$5ni~F {6WOfIEcޕu}@m 8b7#N.\(0H$3q$C^kT:j$ m,#~wX)ީ& tm@yZA8[2l;:R2²$|zWu}MF47KEaVxږqllu4I$r^EC4;#':knQu+hڂL3=A!1uM;̯b{PsYjN%He"uIw5L(`K5R4QwKB 6zҟusS9.Vg9)"׏~2dp^zO@M]<'?B} 'tGKSMF[]҄,S\h%;k#Prp:'L|~V9lɥO,7b/bpxaA#x qHcw*Z>OE0@X<#V)0y>=A^-Il~5 3u~~1'\LP6x8y޻ [5h?v PU_M8?K%UD Pz{z2P;^GI@N6Y qj4#2NxJ0zh8M*3ş(meP?*_ }PMm캱^RhHǞ\6 Kv``!BnNf26#ULOt]֋)3El- !C:#ODGVcaQ1q<"o2-?6b~j\76$B/ݝɯʘ03@At6SlPFٚ|dJ u g%M <<vKd R-=6рk,QMwݒ$XY)D"MŢr~ͺgkf27U(R<:\7Wzۄ{8R H'mچV) KVq.ފlre]98 \![9l#Ѹ#qOM`4>to&LvȍFz̀/ܼ˛e5߲Y55555 دs3Ʒ8#@R胂SF1ci MF\H&͑⎇ZvQ歸w&+"8OFsWJnmhQL:rfD~Lqjoiw )X1`Yz}=3T?dT kv[w^vj8 r%-f;q.JnԪ{#jT+Ҕ%gYxX7 z3g}-Zwk4?{7(@ld +垉}q@V2^1Bwz aF#H.cc=Drm<|#8fWG6cK'(#ёTN Sm{ ~َT]W=](xu?ҊowjT\[!uxM:!i'(o({KZE?9LCwJ b EjY\WB(Nh䮤pnlXxd{O=[|$6R ?]iQŪ 61zM:kk.^yI|jP*d>H~o:$x0/6V?QvE?L:hHm7_LJu2_yçJ#uݔ& It}p'c`7wZK.E&J ts`8qAkzݸ!?f$,} S!ϱS?ZC׾:Rq D^ʮ]BӚ *]# 변\uFX־o ws0;iűgrܷDE-dF`i0ESqvɂ ck$׳'WfYȻi=AQڏUDzC[i$.C?eOXAhމTx %t@,Z6"SRpK쫲0]NГ#3h≽FQU>Mb)WV?Etv)y?M^׸bNfki?GŸy924=u[^d򽲌WWigXeJVP6%r,qP}@& ҥ sFu dy`DG^I.'!4.`p{=Xf RJmD, )},R`kI6r6cς˒<,J]iyb蚎ƄԐ@?޴31.~S鯋%J1:j|X<A*K=RJ1ЕRJ)բ]53?o L/GǫG/Rǫ~m -k ⷨ ;}bR27*/UYm ^S ?Il"rAO78 ;BtƳdmtU TcMN@L#<'!i[#/:u@%ϐ,?bxOTL\!jALq_(\EB+ia_sqb0dٱުkk]kw#%f,esL{+M!\]vXuٻ'uC䙻 9s#pZHy>˜>&SGTs*448s#+,(I.(a?d˅>MOC_:7@~AO'YP:|gs{[?{P>4u- 瑃}nz%(V r[%uᴺM2Wu JOOX5]KOE2b>H 1^H7[ܛڟ× Noׇ׀׸ DMH p3!rAn$a8蕌ẅ́ĺϔ8+tQ,w2N<ŦPqBa:HlOc1~ `'>|F'7e3U,pz{IG<޺9W-p+)g{֒>bAWFVxt2pz%lzmΩ]χz)DA|ȵ9Y gT=NT]&it.rt̨<_=XzD5o]˽ B^S= `x_ ,DH{p]XFBp fE Ɣ 1p1=I=;U˔J!`qQxIsk`J(oxA,.=D`xLS|=Yʹ q:IX+;Σ-,8bsW tSLԝk67s@ajaqT4C^K^ i\灇L/K1Ƅd?1sJyj5.FS.Kn~Q\D|]q§0Ovq5Ħ+ŷi]Q;GwQDG*LtIK3^)u =s,JF$?7뜸k۴5dIS,z=F:auX`|J*mhB+1 NjzBغ]-p*<|ݯur$óuӒL!x$3]JPe#)AnNeVsI(vJδX']{аH~bwU}a@'~Pc?+x`K+‘-Hdz㚹_Ҩ>#í1 L%=4RMكgm3T{2H}/U)^!0Z5$֓tc}+GPXP ΢8' -4"V[+{GtBfae90J#Èj=i胷tȲߨݿN@-Jsa6,kx(Az$nMWՑ .plX@ -)*61&!ъ*wb56㾀Եɷ$1}:iubڽ?K:y+\١>ʠm0 kսGLM-Ԯ@],'/L"U *Oh_NH&5Ti~~ml-+AZN?h{ѱm ^TGrü';.H _kY(A ,S{iu9:tU~w\NPʿia_U5PrŨ%ޞ;OPZH3{MSCN?vrd 96!z7M!p%PrkQJy%Qc0Un5b+4m!S㉩<>/2Gў,_=1.Z$V+ j~tVHNB|My}Iw913y-b1 "u? c s jOLiBJn*,ЧjMT_\iYJwo! `GB/d…jB>aбRyaMS>öXid L`7 G2p}>м#iɘu9v~Gmq- !AIMRst= ݦ-o*^!7a,4bI BL0~Q`\*n+W@ﭰ,R:85+c1OSbc M╄A8J],:!`52zJ!1 8$= {}}%<hY*PfA/~@ʠZp\n1hks^%4_.~/u8b`scKtr{MwAr@ͭ6loL"eCO㢻[/*\]H"D8 Σ%mYIەѸLTy 8} &wd3\ [a_jS&o;"*Qc [ mRE =)ÐhիoUŵgh)t^j`* 9N9W(UlOk'O$9\B-;Fk@LJe}mK/gG֤cef@TClxԤA&ؾ\TiU˕ƣުa_T7Ik·N  5o` nT%,اjs5*b?ӎp^y/G=bc(TM5~Υ f9]FwྥaJ pm#wrdpVlp"@o%Eӷ0a>@fJ? #^j|^r)ENtQư9O]8vݐ.V9oz$JEԷjh%SB#XC^a*DtTP90Ȼ TVŬ=L.t'\++oUYo7@ ^11Λݭ6L.`+bCD['~_5]}áY| W"~q5tg:~x,AnHG$nY'EPqcL8!m]eb;oGMnk\:Iu[{6Y >ˊ̭9d#z]n1H.u'\ˠp3?}AA͙@xnTݹᎆ{uԾl,0ߝ Z`2awW11x:v h:).K[sp޻~B&)X/3Q}/&WnԖ=RAnGAɷ(;}_8R1 ? EYv,v4Cy4]]tIʍ^Tvcī^YNJT%[v5,ދAHe u=%`8'Y$xxSZZERsԇ`-`q({g瀛 YxFk\$D7#ol?~!}^gt܌/A )GB-oPDCY | ;6/ ~{z")9ٻy;/BgjoYLC<" m&gs|3rFx)曫VfHț"D%9 = K䣯kA^j s |ɳGWߤ"^[3>OXr by)BGhnGI]h =YDPBOқ\ KetiL"9Ҹ tCHh֎YIk!|߮<˸W\asg6%XHrzzPlձ!ԅDc/LyЄp f5l1[I(.y(0rm0>e+PG"*+Լ~|؅J/YT{q`9\"@K,&9^\Kw{ODVfWywrGc `U &ֱ{8`VJ'0%d" 4ԗhGmHk9Jy(0FMvx?X|^uB2i-˅{ uc֛n!/lXw'a K6 F^Z%(3p T lx?Sw jxF=\e7ÝE Q.y͵S`S+`+'(+IOõ;3WH1[=/v bg' 籑n{[\_\EuT)S;R5aHф5sA ˳Uѳ]]fngЋ;lcoi9s1Ќ"_$㸡UGb څ LH[ ~(j\P=ۍu4k zFއӱAn^TJ܌,$$Ro1: 6{ *K go !ꚅ,}+vORlVԵ%+ 3t4Bk."G[֐1MY25ekqZIEgDp%SJ @rLN3q4)b7x&qgT@_W#%g_ï[84ӯ>_=X+9xJ._)LuJm`]GUPD;㻳N-&+*pvi AtI Gf mM3]Je}P:P+dfMXūņu!uKX%ʐGN0 k_{bnikRbQD`5}F1‹Hs!=S8^Ayz閒X:]%J~\P}/do`q"d6p ϫ\Qx * Xá],kR?kUN@{f^iC5Hw8l  W2Nw#to{W{NV=d3}I]EHL 5 }FQMdO)ajqw`s6&sK(xG\G!Ptl< }tp4O\/E_LT iIpM R[\@4o2Ҍb<WFG"Pޠ&d<hԦMg4:-KJZWFvA`oi f酠vrp[Xv?H~R4rI?F1QkLH7#%o.Tp*D_Q=oNzD8l="z8&)Ao9ZT<3UstMu.te4s7= saV""q#x չ\`nbiEg*r!=e/UQ-!C<$n^w )8\V+SIpQɛ90A,S vi.*/vvf ݽ zTZȠ3kl&?(Ue', g(d XVH`7 {YN8B0)@Hh-`Bn7c3?w9"f5) ZqvTUOŚ_]:McjyW0`9lSFJM[!bV'0V953 I,urR8[h1wut/uGlSNDpm.< ݢr ¹b5sҀ j߳/psك@ӗZdq6)L\c& >MĤ tZz,]M8#FWXe%A15~| *-7g:X)6sn~<$pbY\Ue(g'u8o݅QV QErƧJ=$ ?[#\)c C2Cj gtvQz:XpT*Z5rAE"b#],Sgp\XF)+!z &dyot%GﱁI@@o)Ɵ%jH*6țeV{eݪIa#b\BdbJ9Ki(¬ ipX?aۭ>:c>DN,1{e)c Xn9mגuW{u#t|$G@9 ,n.H1\C1(? iQAj鞺I.`rg4̱69T{A>גDR~=ŐMswh 4a즌a HD χ;pԹG,E֑ OJ_{4i*- Cv[aNg i5VvKxiB{e*ɵW/ҕlVp_Ee Xo#Mй߿w*UT2JHo}Am^Lgq;5(gMFSJ=?ӉJh(&_j# gQ35w}[jjxLٟu<@wϼ׽.y1Qdd4C+-!7T1="f>ppJ`{*ȿ s=FNh-0;^Q 0Щ c1t7;O3$~Q}2F5$n7c#i8LCf"o<.r+^=SMf_Ә5Œ.S-SIR8m?t T!CX7(+؁]=~dZc% _PGxT]V,,4C^֕nMre.9&zdk³g'/dy:tULT"~2,zc!+ku$'hq`\yaQ$MT:nٱ[hrg\FTvAKT\dd8ӐkOqѤ{1xP]!]wT4c7tBPGdxzcƣ<ͧޡđћ3lu$F,?{iA!Y`z_#O09b"hB7~%\I٤z7 5,QL zWȲ-sG 7>D/o(?L% Y=_Ɛ.F婏K`26.>(ԁ F_,< ߓ,lbel턿x B9D^"W)0u.tߨ; tQz%+_ׅm~h(p\%XK(ڗЬR@X,BN,'^m9mDTZf_OOn KmFy)J-wj0StG=`2Dn@iqD Jcm#3A45W $W RP7~ݿ) oyVʟh`) ")!覴歹@xiX|lF{ jh]m5Re*~v ʍfN糃,ҕKP R\];(rgH~0uFb&Z淡4O<W/}mXOm.@O[ ,C_sڪs&?o fܞ_i]{՝%F-r&NFrOx P܉ fa< 7Yþ֊8W Q":٬ f qN8+Q#6r-FbH;r& ({ x(e8ffK,?4*V9&o/ Rg:~|BV4͝sxLqb*:sR'}IX8PYR8S2 .|`XN-\"3]4my~J#Q5AGW $ luA`RCt~$b`ӁgaU;VF@)[@ E÷'dv 򊆟ADqɴM`AfcGP2iFVdj~9a#To>Y4ۖ&5!%[5Db"@;,8TY-ÿu~-^=[}$ ܊'ח6*]E)( 3YE98 | 2W!-Fx„B8؍a f{U.uL{>^Sq3o!si>k dR#"'~llkicS5^֯ױjLfk%~SS-tMG[AS/&M+P*EIk\>wD8=tR@o&‡˒!s{[nv} Dp 4UJD\"!ݎc뙿͢Wt_/7cu _-7ٝ, I¥fn =ݿ! UGɭbQrZ}+͈Ϝr;2w%kd-Ql@lsYgQdj{lDiу6c)iϮ,?iܾ3,uܖ0p"p? b"T B/N 50} ]C"!,ث45X 1ܿ<9!Qmb~Ϻ`UCh.|BӁB#$t{ ,:2&|5cx倛eT XT\ һjް_$P$i9>ZƼ^U|):%I|83k=,f",-<3Tٌ{7x))G]3{*?D/2b~#i_"ABP 6L|u+,XHd<8÷@LVfMOo9:KGC&;vTTv0#NM8ĵC>;ƪ-U0u!VOlS0m'DEPcb18 DA;  H ǟXA.׃7kÞȫVպ{(9|x'[N4XL ֒`8ze3).'yvs)Tqb[(IXYXeV<*k熘"šy1xyՔҽim"2d;eQ4b~ ?D(xve$`{COpKRQ0H8^W`W6:x{j[n\Pծ7ڙJ(23l wds2k+ NQW+vIjWKDV_%H^ڂQݾ[qg\e5&pX8?Qg/ 6(xXTd$'j΃5F@\OCf}Kj#D/D6Ym&Z!3txu%"ˎA$6yolbn;0QҫC^jO25"9z*[`aX/LX,Շd=zF_˽>rF^_%y @؝@ S">̶Z3|׍hLHɹS@j[yҔdqcKIHDwG>p 0գXy״A^m3p&:VO{%_o[mNgX -UYIOuπ5B Mkv-+be4k3,^u\gy/-Лp? z3C0CIbj $j*M'0M. f(W>ڲTZ"{8Ȩn@[7Az`C_>}sΏ_DnR+6A)Fɑ&Ծ+~Q"[n>#ٳTuQ|.ORB?eA6/S漫 nYӟ{#{^kLxdB)OA»Zꈢ~q7U Oo Ҥِ^ͼe ,6 ݻQl!o[r`%-W͵ ǵRIIG* +DꭽU- ⧃3s JbWDVyQi.`fg(D[ LxPØ O80RF@Y4 OweY)bI-u-"38dZ vUp-6_Z!*nT"꠽_=bpP/h/[rRB"BG߃aßggƵ7rNwVvT)hHtզ染evwFU6mJIh ~pp݄@RsξDE]Zf*bpp~fި&É{%v^&$)kx)~_6-ǦK2m>b߆Z9kB8ǿ }#qvy%ÚcC 5J@HbR [뗔ʲ:Bpb: lw$QnԕPpq\刢vI5^~ 5 ŴV䮭.Ė6pr٤ZZN\^Z<7@n fROxD+dfQ(mftjm%@e]բrͬ (;P(Ćz(xҭҝ^Ky.X'V0(輈'0sZ`vCv*QMX:ӗ3y_]@"hc ap@W+AzMXGVT9@z;uakDx8W"${  lM={85lx1ż9( _9AaǕ984Z]Y AGjjaO#xNKe22%U!Maw x?,B_}+D df#_9Αr 1`тeP7L˜Yb3ٙTpg@9G|w gb”wLbg/6 ylAX,Gڴ?3ӻ^>24Z6RB% S9O\ȑ|~{dE3ӥhu ;^Vޔ%6dl{HK`-Z@!Aħ^OQ,WPƺB*0ood-YVǼ&nX4nL|>=)|>z$ᙊ ~Raشw^[4=~M_״IpjAcGj'X}αcҸ%ӘIA6߅rEEׅ[|InV|'[2'ьtn#)2yhdm Am08ň -LiαzED->jB;995IwTԳ_rNJ=Mgˆf$'KQQ X&eLTQevZ9HK#v TBqHe _`x8:7<3+==>ҘIXi`رATa$G $%ˣƸ T٣1M:cXϔE*N#wu9ySCݵdk&|UzeSkCDfz&<6P>Qvx*a6oEӱCpuI_fjDP o5V$Rϥ#r'[O˒c~㺷D#Ɓ{rzD`D d,iHIaAU56WP⓱8J)7若(hKopRug3I w[mUM5̛ |=cxIzEgl"`X:X`} ,-,""!/?x1dgA˹n@QcU~5'ʮbKfHwbA!j9HnVI刏\TM_桲T"tUu,Zo&yiMӷTAjÆd31iW$=x\>^A^HEfr0~p.*0 0sΔ8᥏`~7jb._vHZ G`S+;?A>QXaUtx+ =ȏ_\@ckΛhيlgeT|)gڗ̩ki@x"D</ D$Jm9:NXC%9\G#+&ڋ~Gǐ¹~R/ڽI01U2ޒSN^N˪O ND@}-Z0o]U' p2:%q9s,,,^Ț4'ophgL6H\pQ9yV^FstC\=l"e,e?$=o>~Qnmq $,0}%XKÕnb!¹U;M&s\K^AAc=ĈB% +ȶL04Y9@qk-E6ҧg2*fZ=hC{/qZ|BJd{yohg.s(qe/s`$nPߺ=W]cs;;7GuN&Ɨ8Q3\%XߏwWiBM)|A5= k AubtΡ#i<GJ-V7hkr:7\Ʃ6la8?Ma{u˫'e*qg@fNnm:;߱Bm?:=>O%xH KO$<>yPNzT6)B]+ 0@Ik(ŗ6#]Ӂ_S zwb-pVٛDU:4? V=Q e=vO2NU_{wq`n;>+q\< Wfk%!G7C(l:;mJ7F=R[(4lc#Vc["1r:q =O}_"m:J120 Sk,1YgzJ˅)m(Bx1P5-Š\K|a4Dກ5%)jbP2TN&~9 m(`n6uj7# F:ft/=,PO{_-驓`r ,Rs30_%}ÿ+'Vw;UHa[KksethGb~h/5":m_rqd&"gK@ElS6*tuP4BPq;8i+8s<jKn<;h(`gUFͼ0 a#qQ!|kP]=oo( nUJ4j|5TFeFoE/7?.!xNf2'5\)" b!dQ;P.v$UxIN}k"~K@%!a|nACEˣ,=JnJ~ A>l:ej%?TFkeЛ @?fur\pﺌl&1 [c7T;Լ6ybÒ[-̗˼»`JN2f yrjbIU %pH }=G{2aV|[(  J j鼲nh30UslJL1-5EY03"h2Q{)Tb;uxvøV,Gj>y#sT3Q,Cf I+>fa[Q. f ʎB*7,ԃIZPXojH 4|>[MŴpkt)SSڦ75d'>7G㏲J;QH(=POyiJ [6h\2@S:q>fY͕Tl },,}opC~aWrRB=`_/W{C~D O1[+HO|>'>!ыs+d_]KQ%b~ڊfSYC4\`2ׁf˳@U}yk`qՇ䲛BBW⹯EΊ8/ HM5lC9Z x&41I, )zP6aTl55WTY[ !}W}k] o2ѺnԹT.Ov ?r TP @p >Jl'ӝ}Hl@ab.^&ѽu4տ`2]{Pg 8RLp)SK2s2 n[\ ja<۷mbhw$Oy,d50[k~KF,># z<4K㤹& y) l#i`wIs  O`rH']Ϙ0 3kJOD">By=f|5 a B*m~gxՍfP"̜e@vu5Q-YM~E>`WMӗt&<c"1Y"Q.i ƒs"wA?2~9PG'5>. X\)%[EMdWԣSa4`2$(Vk]U Cyq]t%:\Pk0wV؝NqWw&Gq94e V"yT} b0+ec~Amstl WPƆ͚^G֨Z\1azn=t7o_R'6Tv4[+#8l\~%9L䊐AΆJy|ZgAr U.Rl4LN$ߗn+Vg[.7W|uVZ~zؽ</[xgVYp!ѫ :+tY>'LfU a s] w!" F9BY:OJ6I_œ?oFW}cNwcd.hq^MEV2Er0 G<pow4ݵ腯y$&Z7]qdg莉? f53ּ @y*8;Mwin` a:1QN"VP[͆@6*q@0y Ron3ict*<3>xudcx!WFqvPDܓ@(ZܗxJË_Uww\!uVIEрӄ)@7-[H98_aa J_ [? F1j]ESNf83°*Z6iļCr0v0dI2l…q\PZt[bwɳ^*Zo㯺&hb:ZTƂ薼F:`iFA%vƱ}tPX7[(jW(ZX?yQF!E:^PmuD0v?!wI(]-t6нq$k)Rq?+U:Q.?Хu! (*uvÉI 3ז'odN3S-ivǪCEz Gz G&g >u'#|Csv6)#/#34GZBG>nv=qGJ=M,y x29ZSl337'9ħ>{k(BE9d^_XnL%׆{|1Ѐ!Қuta M=$Tcr ^b.N׏[)`V;'uw{rFO!=,F#'D;wu  42ىb~׆ J},ם @9ʭU/(ȸ!THJˍ7%#GoWU5 AZ-gPc Ֆ+MM*Tn2XI\Cf]0`E^X`؎{$ `ӿP,y/tF3C{N˗P-Y<n0z.9&?#RLIRFJW{9[M&};8Es2Y^sqeͭ7(ycgsK>(Or~z'`J+wM>k)D^3E!ZЗ TsZg50}{N;ړ\q=)1&ĞF03>;dm3.z?;`b+3l:pĜRFU\c+>k<Xq?|K[EF )^ZgxQ2a`em2[𽸐B'4/ @/7 H1?IGWܑSZVB7|gS=l|I w&Ya=:مyqaf}B

,fnX4a͔Lj59igB±d5Orkf8ih Bwb0[t,Kv+դp-JײV~~Һ$i pJ-mceaГո!boB[HjB=P8lNR9uZX_/=si tU/VC=p8>u641۹,.vY} UlJ՗eMhAELPW{0l%kTT  -<;qۼŜufw*9rmgvȤfBs D<^n=^I_?:?)`$ax+8)0z[^us0˹,r{WZHt)f?nQ/`=P z&<]@%euuf?٢{h$;@ӃV%nItVYq]7SV6?05w7epQ {g-_*) 줎y2QhLfG0Gu\9>w[PH}:S7b`yǴt:5'Ail*648_M+|DsKRHu7^C hxu?l[(4چNjϠMHّI=v~w7HRz9B!5,"yO,"fsC֓,]Z|be{Og vh^@IJ-2i]=5|pA! xKX r[@!DR)qD|NpR^7ɌYob1Sߒ,3ꦛ{XW_؏˯/A1 :lԮW%o*"s%n/W/18)1?4{).+.+ݬih[QbWI4;%tp۟(d 5ly:r7R $U-i"SF6U$I>Ϛfzh"萜m]77Z"6r WPKޕ0sTXy3Wg;s1v|5Wyr q+(\i?ncqU_2 ՙd i]oWI&FT]~ɳK1ݔOhC7Fpζۥ5_*Q x)>;FT0O' E i㒵̕=މJ`vg­ƸJi>'qePh(Edݙ |ryzVjhz ޅ]Z}'n ,T(=vnnU_"KM$WjV'5JNdR_hmb5C1]}+͕mi)IS,<|6OWxBdn 꼂kmho,F:MyA @;Mx:3JEC7t{'ݬ"e*0D$%m~}<#/bZrq,Yʟ(6a' h|IW'9If =/Y94gu̇}YjR䗵xFkNYCkWuǴzBnٺbt9g|d1ipE;}% B!)z>*猞Q":)7L5|dyM|{~ ~Hp 2-S6 23N,5:I}(#,k.v`~D Y)OXP]>|[xDՏHSs^Gߊ:[Asf_yO5=ԓ:6QN'T 0gŢ[sĦaT俯Sɤo3!  W#]}B_rT UpQln*.xbeHwƆm#|#bno!۬'"yc,t]ͮ$OGAKKuh|50By`t Mr7/S$3ٟ^( M U-Dܕdf'nnv'2]*ͻ9?'^/'+k?ue\37 fr7=﹋ؒ`H|N(iQ 4'1 iVqaKu&+(\ziWP`Q"z*F5&|t^8ÂfzQ^[Ra-sq y-趐ӂeE}|`1OCյ2oqz05-n481\VtK&mX%0wc8CP஦AU2H kojMSX@=^b)o2 ݃s*y+a^+6qT<cCBͭ7 vtSCyL$uT:攞ı6%CC߹j*wZb5t*=>*5ymj2a:ꅌ hE<ԭ1XUE/ګ B&4@dmh5\sd'5rmJHQeҔ;@JޅiZ/vQү~B?3"g7vZVbJxqpԑZ* * Θ%%˒!H=ҌKyКxុGχxgDϹ)Es%9fbp" $}L5ڮJμkto xq[]6p c4A@atV 2+-7g( 3*!b~[w%s|hd_gA@.".Et_h9f%Wꌐ4u.FALGɶ3wLËY4F$P!P$wC(Q ^ #U-{Hknj]HP:^!H>Q&m쏂EG&[5'S෇HeS.eq]̚:uSMO4[GiTPΔw{öOI\G8 5#NȆtHPwՆk~խpV3hV pGELG"˰+Ƨ @2ElӲVBC[!bA@jP`z#!`Ĉɺ!2.յ;8˞ym]c֜G mxMaklE>ySD8'sELE4Mꟺ4'$<r&`yd( V"B%MlQ6SN1D_.Kx{/ِ$Rx5%xӉT8gEv(4EH7lV/CJŸٌAkr3P4CXi{JѸ`AB?#O=R= G|7};_g{$BK<%|3Ns Ϻj1߅VU嶍7tvۖ{dtqXԤ3a}dod.]pcb B|B98P۞8+pk r]jʛS`k=Dmډ'}UC8Rm{{F63QkZg/] zD9LU7IpI332) y4u%(܃0K`BB μǸz`m^RM ޔ`rVB}OdRJҩ1z' \sz%*r"gjE)mlyWAS.w?ɑq$&گ~h!ŀW^2s.q3Im@; afNbe˶G-Ai=B֥o EE?q &ٱ^UVMXGxNfˌmK-Q0mX:(3L$Qy7qO[G*f*|6) Y&L)@xE3s"|ۿ}烲m,~k^[:o %K!sk DŽuY: ~) V+8{/uzqW8qTO  h,2,8eF39Sa36H ѣ8:d"o!i=$-N=(h (ޜC7dU۰+*ƒ 0IPg[,p+l_GI`ϧKo9CE(8Ō&n;,g#QMꮶ'ƸSDc>JP3lbQ<0H-D-VSAoHix 17)(\9-ӑR4Kҫg%8}jVj+7JB`zz~ Y~nTk]@{ (On$UN 8^NA[MP,7+xpXkÓk)dLi A R1J:x{gc}B`3ZE~* +@͵Vgcbއq,Z<}toތn,7$`9#P4]: G(W (*,F)[j=B|72|2H~$r9jAInTØ z'4%3Zm47\i B#} {ltX B>-,R@U`LN/,wŨt\wWY4}-C{5-)li`(\ @Qrlm5c@ ~}^7i_o1B3ouzQEhjTՙ^(@ ;W(M@*Z6֌;֎ jV2_O( B'ƿ1t;/(PtfФ[՝R!:(#3W?BK̋ | %= `fOU_&/:η9qyƖUw8SJ܁mWU"{l:TA,̢{:#f[S;ު`pW \UYϚ_c@ VEۈ=,l>]ёiտM*<<1~pZ;d>q[w֑e™-Vѷ}OU /ExG/WIVXn6ʧL**Q?ЕX:呸qxlFv)& h ݖ+ ^CV +57?`cW*|B8dz1龝`)t ;d9Lv?gZFD&=-R^{^Νv#;*C >'B,-:{ @9Ξٷن%ل6tꦭ;EdeYk<;Э;Ie|YAJ~r*yr5QNߕsYNϓj\B$%zF>Vgy67QdxpB dLt`R=N,!V `s·Kk#˩>;A}6\ȋO\KlOxto‚HDo;"*¨m9:#g!s_&8SBk^NxdI0¡{tXb^h5x.Z;m#t{-E`Ș֫U/0В [f_̝TAxHj<@nT e0uݡuz&0h}%*_Xu }m/IYGzf9o+ G0F`Q`-:?c2VcFFE[`~d7{Wȉ^izeOՌVZ̞d? 47A6$ŎQ=gMXA2DLM%>Er\ҝدz_y.MB/gE-.[)T ɐѰm받gL r<< l`]\-F>[[@$٨cU-x^+O SUټd88L8I ςJ!snE2tZ諈cW=ZgH%Nw Pi_nhr)?(@&uofi'w\#ʈap78ډYgi#ƤWc$]ЮjDKIX&qq.X2?"^;\\by* v5LFPդ/#uh&wz,uW4=JGGmл%ޛX׆ SCcYsε  e*IȍJ[@Ȫ`8MW3_Y«-r D.tRax1ΖtY椽#e \mێaEӋRV7^hI2 DϢ^Y>T" WR8>#j븹?QE3_,u-Rt#ꅆe3[gS \btDukvPcR+2zTʞZy0NbhR(p ?HuաBpF78Q|ca"m9}.~c,tDu;G (]d+'7SbTI;k]j]&Pus tgLBZ\!,(^;e$'N-1Th%^Ik-*3Y>iCw2B~ Hݮߵ9IW"ѿt@[<ZIUHoPS;**+(e\ 4.Vi.纱:Qd:e>/y&GjJQmz7-&UMN@Wh5XC뗝b޻]i`/ͭPCL*ᨚؠ[++=JWgt-{bd$%@&.B N] >(kY g+t6P9 oW)6GadU =TXDL0V 7߃]ѠxX8=kޕkbOނ*ĖQP}ߐ@ j)]b 91VhdmBS Bd@4< NhPlr8MnΧeӓf~Z x%SR\*< µB]tO< ]WIȹei<TE0ʅ?/d5RZ*e;^nZ ]T q%"u+s.=]`n=V>S57,j W &Oǰo|GgQ" QOjc?(Xa3J>ڿŷBɏXEJa TsLkn0!wv݋70D'r# Օ~cDcQX%hIH(M>jAYIGk9-n&Bk@Tad_J~cKCQeߐEߛV)Hueک} FX*dqޓ]`TG/$g*˰&FMlk=5qjJD2q l2wl₵3 g{Qjr__|7oϻ\ٟ2[ * w9K9&ov;#)6`݀;^λ)Wd?@$NH"`Sj fۉ "ڷ4ykL' " fBL>G?/d'cV33jPɥ8z> Ĵ+Fo?GʄaHx"L㔂KTC}L;mΊd?ZO~prҪW9e*NczH߯*ԍ`tst”x,s !v!xZG6\7+i1ncTt[af*U'+a^y "VvD R^_g[^%^ 3svu\<T Yoo>0k$V&YW1;)3"eS׿k 8שb|mSJ=gM)PU2A{-dOn%B\Џsڔ+^"o`]ݹD>jx4 s ᘥ@[|Uuߔ *t-Dl">B*>>%mą-^2Z,(}B!api50TxECf".D F&BsL% &G@~EUVFZMZ5C `Ͼ >i*8oՂ"೹x-d,r -R:]TakVN9-8w!`7 Pe#9B?чpP-d>ǦzHo '^¼,;]ŐvYL+&aXu 6zq_[}̧Dq~ώŨէ]A4/0LFֱ^5ߌ.dH/i&{?3ԞÑrzkߣwdgt%2fX*bcf"SHA-NI.]ۖ ; ν-P,+H)Y^K(voeXk357o:ʇ^!OTOGBN: : h{Q9PAkq.+Η)GS}q %-x-)j~z"!Y`0J@k8@tE ^]w(aEQHp344.'T,fQٍ:an"Og\ccH$%7`:g# Қ6Lq,yD|;ԱzTxCJ ! vHZmz ?O(t1 I.Cfa^񁳆sYFTOBd^ dJ8t.M(4c .?W<卶5,qӽrjN_g !B꘴Хw^bRN/sZ~3%*g7i`їq?EǨp~AdxYQz7vuiJGnYybՁ`YW yȚH:ToS7\/ZERjIBZa6a"4˃D^H9n8s`RXz}0 <t6+HE=JϚN_)Eag !eOIhg8hf|AXf_;Y* ljMu_zb}}@m3k9e w]žrrq%[N Q A#X56rf4zt>SH"O[U&(TXܭθoz[R)kih}9RA_oDNjTN<0ݯM(oPnEHTaY _XU1R73ˤ' >Y1*jY 7pKDֳlsmuP,yKXGv7\Q@#eoUiPYLB?8Hz![= HeRcKHkCC?t ֆ93X+z{,q{alXgL9`_Y>|Ƒ|z7F63:/mBKf5@5z jъ~m P4Bݗ,vz\uJ9Y$OY)^Vӹ(~l5⏀ u,b®st(n7GlAk0Ƒ ɐe#Aۢk&!s`&YG|Ѷ}`yXpD-l#;"-[a7^ vfVggL@&wUQ\B#F옊)}%Jy \CHRZ <K|QM~m?{HfC@S~:ѫ> ZR^;*!Z5K7w3̨T.qR!,sr[,"'yzhpƜJ!=ֲD [!,H-r_eZViC27;3}C.r$XICD Pѹ{t%4)"SL]Y@&KlNrE<"P'[Wۖb6cRQ D[‚g]̛yG&q# MVP{A֝n;.&2Lï˃ tVw?- )`GzҸIi7ׄANY8]iqKA[wk"Y&2IGb0ؽd7&@#Q%6D{ ?g@ 짻z065e[^,FdCeYuʁI_.&B C}M=O~.EJqJN/LVuL>6̡:#eέRJ+/1!뿙F ̵u+T@`*'H#Jů¸(dQ.SM~1ӌcIYz8ĦkRkvA9ۂ/[ ̓&)@Iq& 'eZNEq nK9HĎh&Yɹ38}Y]命4lm_<Ƣ-al{-M3!契 t mkՕoDn2TANM*!ݩca`DwvrB%'LѲH /bt/k3$vaF-<AA~歒{*,J= ^LmĝQa|wyHXTbGMy,~:7Vs#EH՗57;T˜Y,Q-@1oW]:3c OA!Ls0{vu#/aѠ8Ҡ*%P2:&9 `s4'e#=LgUз+0h3D;Y6D=p \#X}E?YfM9v0JN,]QbƓu2Ь9"c[~Z%pYDe Wb2wky %y}wH*>R(i+WɝdGix`7VbD?GੳKtF #@`wyX iQc]FpȯMiPɱ ;Wc< hn Z=̖yIfyE6<Қ>,w($bl Gkq Tq}5uNcQ5ԯ-x?b (Y.LzӁEHf̨"0&/~Ԗ kG+"8Cw+ě @ĸ(}F $j6k!4~'18-Q@@yx}1A A>Z_v>ʬ=ۑN^_CZ5ef4&XœU.eI7>՛,zł^l+tIGL@Gq7R*X5vaO"`71/+gk_6⏛{Sde?պ{l(>A_ߝ޾,axNݐjC]t ח{Jbi}/]Ozd(`w8ghhԾa]ag m zP\vfSȫ' FM:_Ti^W``8HJW54Ta'7ᄇ&s760ND{-J{E)Ӵ@t_/SYG3'!"(y>'p+ufV#[49#NbQZ&J&e|u \1ޱQ bjo8!{(~"/YKU#7; ` ؜T{ӢQrײAvomLzSIɬ_UIU6zuQTʰ4Aɽu+]hQA]`x R>{ٺ4& ;s.*^`0b[ݖue =8gȇqٱ;C^gL,5㊸9dz _Y;p'7,=xW0i— ¢(ZyMo|8B(N6I@hH-8rvU?Jd~*o1g٣pjIxT25қSH=xњ2ӻ]$a T%C4H1B n,q2-?K7ގ IVAcgՏ2l3+ +ii.K44]@JLwQķ=5Nog=G_/`BoKFPC   ߞ^)e?S26jIG>R&i4IH+m {s6gnLNQAa 뼃[Je~d$"+1 x~O՞֑9TH+ 8{w>%42kHߑQkԗjwʱ#~#xͯX-]N#ī p(j>+WPqQ/@Qy_Zyq< 2)M(fmY{ÃOY R3"9'#X>%䇾6jө~qbW h>rNX;XĄk9]S]ɺ1]۶/qU9jǭ#` YDžk)~5k#M0#ڰ?OkKhAuvPA#I_w KJ;E#٫%OǪCtv߃pg>4u")4QxziG9WP].)s~PzWf~/+J֢yr0:MMV25O;ci:ߐF#kA/%dlœO@|p$ғU;lIL,ICrCq?/{Ы_/BLora`9O_gá Ya=r :w1먤'T| 3j]@ńxNgõwx3HI4r:Xei+lM ,oc?22a,eN7wKq /)A)t9 Bhśj~j9iMJ٤SPz436kHE<" 5%/ љ,>5i-{UNpj6rygh[6s˩!M9Q=-5}nB%9yOcA-Zv-sII6#ԃfY[S} ̵/G<zÕdžITIV1nVYXcUQF¼󭅰w &z)I% \dѰs* QLF^УLLai'PHQp\b5WuUBƃ ݇fcy?= N10{I&STQY([ D($ [XXDN/{x$vv 0~Ly_Ikb@d#āYţ0eQ͝/ SRgaՖ,FAW8) dXtecpPzBO.+n:*/DDmOJoasDy۲² |W \#2ڴT䊎0YG~҉o_RP&E_pz͆4ˆc , Ri!'!/i^ژͼ 8]`6`/l*| S`AEľsop\6V :|%!nAPUS 8ُ{Т'c$-.u vMlF8ZC>%˫`?cSR6,bF4w*) ;l¦at*K0$w we =~0sϘhG=@hP0sߴ($H,)^x{Nڪ> ~Sr*0O똈D{y< /+' @xlT~@wyVA 2@>և4\Kk }][)4QwmC8:EN]jT _KzZhTx[Z!meB Ez[ąudTp/c.GSV}&27wBrĻ2C RqTBt4YKkudך÷C;sYWN:TOͭs0R>ݝx.cNqgA?J=H2gY\ZHACr6=(MM5O ]_?&F-𓫩`F om /~g}j46&)zMQGJtav?}Uc'GVe]YBxek[DCRx T{(B?%TU-4+ZSgp66t^۶M}{%펔@)J 1}?'dvHw(*J}b;\ }vavNmك|hEqChbf1m`rq_q/CsK;ݕ)`qHfStu:ܩunZ~,1;yaTE -hb;il*5Qf=h{lOrPw&"j/GP'ߓïo7MRc1ڃTmtqܖm95 Im@?a\t=\)I?pLhӫ z9s2`C'HYuypUgdUr=ԄӚJ\hQل.l)9yEdӢF{.䪾b[z擯v"m! ߰47z0ȶ9 v9!`` X[k>hg2(rkx  I3Ȟ=2E4oWjB)K!_Ji.ۗÞ.ӞFc|S *ww \ffhI~:-qe|NΣ"E]_=*tZON™c"=U3?Vr{-4S&v먯aba66kr0但 l1fA= QeCͺbJޕ2~'&"SB}zBF ;jǹ5H ^$O1` c4( ..c$ɟ5{NJ8߅:7֘ ZӅ5Wz^ܽ#i҈JOw82Q 9Z* i\G^gνt;AMO,ؽхI/lM_f&pR^f=;O΢+@Ԫu&Js<:=c\yKȯM;E$N@x rJ/dO~ 5uf'Y\Jv!<)M\]voVZ߸@y#bȇd68m͸l"^b ::Ӻ E \_j b]wvޠ'Hh|r:"IJY6ǏI8@<àVA@X؀ԲϨ̂ߛ/@r!9pĉo:Qڲle*3oԼKS0QsUM2s)Q%*2SZˠ6tniDxeVhFXLeAzG&N"dF̅(TӚjp#d.q/ե=B>岬&*{)3n“D|\v$D+pi-H=MGFMxzJfe JVY"pBHʖK cq\l>fᖅʔcM j~@ph32~ּBhbp=J eBZ]$)wrmg=bT(-aW\"  'r51c5#Kt.C_>j;Ϗ|q.?fٿD x~%0z52FA> Dy3_e@~*rfFe*?k47N=ewɕN UoUq(o.x=˞i ԇ-3:Y]  H'ۛc}#%3MQ.CaHӲ#+ѿ,E݆˅q%3RZ˷F6 y 6}  wvY۹7/ ^S!Y1=W#cjYUHZDφZA dUN !4m23=lU-vN_!!Y+vUl]{E7u7;4am-mn56׈ndT0dՈP^A)n|.*HwR\hY> Av1k)YUչ0 PNi4!ڻ}@4[DzﲀM[\10@ˡ]Ti+ r'oR~&NB怗yLhɰ5Z`NUg{4 hX"pF=B Db MI,vgD\7w .YGEQm}Xphլ<9D=: ˌIQBXDU͎FD-M 8e"mE7lS*? DT[J ~ \?~2+;UPKpf~+QU«>j L^h?D#;OKӿ8( 2UgL>@"kϖ2[f,8Ha+PajRzE{i.*KO0DumX߻U\r_5u vFKnC_8&J;R K.tC1Dg=M!@u^*WtsOL;l؍p擎!ZA8rD4{)ZkD,rZeeԭ2l+)=xT{q_j'>EPth*-Z#l&#*)幓,.KTNBCG(  !UR@COZҌgPMcX^>B=oL-cû7_\0AJ6UX(Wce6_ht~z"zf$UeR/ECo {K zBc }=}ZS2O5udlr8e@qbX[]aNC>KXJyxغ'`OhWhvu -[D r$P0<%;,!6Ӌ{i45[xЅrh)+_t̓aҏIOH BϑRN;A| wØ߈1E+*.-MCiǼadHhZ>L\,\#Nߒ  x^[^33!̞.]V8*?PhD4$%:qS ,wzh֜Soѐ_t`,fuNʯ8`픈q)Ns`wUlD!^AؓiurMe;Q4 {knXy;f q{=3F%OA:4 ,?8s^7tU¼Īyx(A,:PϣY8>ͪ$:(Q [mf.5^rR|Lj*2_jidQ]@Ea~%h25ƺ$G*Ĵ#]c2vҮjLd$aQ_?)UA}Th:WqSǒ+b Tmnh~mJzz:-A:H\ns#eoO05mz#2p^*bqS0U4  MbRPW]F*45#`'Ra~7ݘ,LCkOm?3Co!, 8Qvު<q,u`}-k(ɠ\!T3fG*'tD5o^ơa=oвSGǣT_ni%@\qK zSE&b~SgH.龧pHEۺ7"+hOyxUMQ`V.7&dĞ\q٭K"טzU[nf dk<a $) vrs5rS 1ׄ}űt7V$~P\+h>LW_af1%;D'4rw|Ņ MA=5E5?k{%P]ZUB 䦄tȖ9>5+&ѹ{@`e+qw{ŽIRȲa{oZxOs"omI1t 0VWOrP'؟Ğx"jKh(@eR_q( ,lpbx&.q_o>-,{,_ Sӎ -8z{ -`:>q#"T/ 3&i~Na9jN9c50J}5ʌdN@S[UNYK1t?UH$ׅd'8<ـ)B9Nr9J\Di0yL^6h"d񛱃9]}/v '[_IȑdPא1lFF{?q_[ԁXjY_N?́6ƅB\ҺٝQ󙊈ʋǬ6BmP'Zjh-GG-[X\o"\}Q#xtãXȮ|J^O@ӖĢ(AcIh)0 dB>mt7%g hU@3g|8r.Ka9KYUݕzVel>%^ڢĒȔSjK*Cd.*]cd(u>#'6eYI|#$ns^e^̩Ҏô-td2(:jizw"sW!g(RvW= X4|vaL7+CtL;mlmx6 I nBQ{IQV C+{a^`hH\,fKZXp*/YXb_[% 2vуzAeqq?0Ei?"nWFmXk?92nazp[Tw4(yx)A!><߯~=K$Xgiz͑B uA+y< PlK(ok6`:?W?{lMJҁh>BvyۨUDJ@耧޻{fc6 GL3)VV?myN2[Ճ@"Z2H8\w$q! Ϫ$.NiKJPt> qf?X -bX.jȂ\aN2!hE. ᔫ+4l(.+uUoNts'So=uqOGV2%gwb#Fق2;㍅DKٴoW$qfeANA[I@(ђVɑX}ԑOZ4oo?_eD u7eFgonLZKCi 0Ǘ<X1cgg 8 X 7"ֺHILՓaL;uHx }cjz@dPvL7>7p8dD5Ƹef|g@#BXI)Y4IKpEM v\C"!J=F@y@-40ϕRx)(~nrP-Cǔ$mW%D.oyƑ R) $u /U2𾼜GTKvGgc ǫݰщ2@Kf9fQ7t5o\z}E!7~ gCDIL=D lo-R0 BkkВXVuuZRc?~BXucoL4uhMp^\-zoLZjLH! /hGR.W&py F,s ^ɦDATuL}c;d ά濑Dp'>;SqjJEKQއF٪CQzGwt#֤|,2Ѱ,TSu'ųQ:yJYڸ^6P9xL`_- sI綳lZcs|HkV`fce j!=KÓ'OZt7OjySռL܉Nl z #idHo<,<'މbdä#;CAެھWQ?$/ y$aU4LjAY@ jf})HBR*t9INU̗Pf1, BW*ڑMf,sY4:k͖JN`ޒ$4{Ke7 ]mBHsnrqF hբؽx. 4| LrM:O|WaX(pXաŒco='EzXu?1 ~4wnO>J>Fò(ټ h5@k E7&&ю-ArAg3iFr;WlqvHc' [:1´标E IcT$v7<` 0>oBf`6!Ov>ow dxZ(ˇź(0uVkO3 SѾ6E*S(%Gry>q抂>Ii]f\]"Ɓϊd&,$#g0[x%D6Z_}&#OP@} :wȈQa)vc K'z gMt撋%Dl/!@>@э\vO_ Ԓh@5G$Z|&(L6q"K 8J^J#| Vnw]5(_Hsm?w0cU_8e&E/%ki,>`Ph_ ]*8?\WȺ?`Jܚ\K4aoU;clǯW0?s+,uo/楇,߫i;4mCkuJ ߲H]s)|761{'EP{ ?55Hkc%-~3X+aZZPcz;ڕq9eSs?2,g$6# |f)<͒2ivo(t3E+NU邾~V=,Luhy.e]#xVS2|Qv#tQuۅXٳ=4bˉ}MCtiH2q7׬F֓W]i^ }Q,ɩyTXu`q*fPN;]|o5 v|ۈc993ġ}iЏӢzg mRHײ 8(hS!THWҷ,E~|d9џ|lLo%&EMU.{ɈXB='`/Km|p>l lf⒕-J.r`uUp+eRIisWjwɦ}lTA (MHxӍ wg)9>#i;! 5кg`7D*vhTAn<+xAwDpr7]"dL@$n8G汝Hrq.0>*VÍ~9:'1^ri `lau }PiCԀ>3S-R؞gD*w̹P5WNsq#WS5vZ " Yz&4'wZN:AA=BƉi!@pue$2j/ؐ9P>R=G#>Ip w&8u4 to/Fוvg$G<,6[ԁ"c(5grFHo9fԎ}9ԁ ]t`y,QqcKҨz* 5䂾TXL#CEcWd.֦fmI{ 6б+Tpi]p :桦|\<TPeŅ{w`w1 8D6yZBzTEmӴVA:~S,Qaӯ*̮R"y^Vh j:?2%3NDPQuPr}I(f0sE0A[ 'gQ˕mRî< eB$ 31nG2hQH^Ak J!2(-v#g Dv%{4 g Z-8q3m-̨ĵ نf5!!-`Л;G7Ӟ5W=)-nu`ΡbᙼyE Vbǰb6#;6]Ux1YĹXQz{Ts"g< 6Ս̥S}̸i I(`_YC&BY{?;I.e=|)jz8ODLpe56Gr浞 <*޳}puOL˔^AeJ3g צ+NO+V%qjWզ6xsL(R5 9Ў&\hHMl0 om #-}=UFC29=D㡌u{>ҩV5lmS$Ō|k9Cݠg:*\8: m/!wiUkr;ońTg_Jd|fıhzO`b(XS ID]͟E47KD8N=lkLZm%jHQD-,F?|rK/0?C !yfro)nɐỹEjvU@xb_gN\ Y#;^P: 2Qw7h]#8{|>Wv6]ߓwP tܳk RWa |:_Tcn=Zd> k qSš(S\Θx,!&o|gڮt-z6Ivz3 uXBǵv krKɔ(w2wkmAB@ouBL6iV|vii䰬~vAף?uF7d OouaWb?5n^CIfLV/G;u 55d9F.0{rI}cْWu^QpN% 쯡gOc_'}q˙R,3MȥA/yMߧz%}4  I [v&E˫w˽pP uY1%z!U&sédWA!e&J!2:Z"t>Gc]'%DcuoP[!C0 촗Gk֎ihL`vB>0+Q˜BPh?aCߌ~7!q𘼲2 C~٣UI,B/zaL\vǥ\-c߸A,bWd4E;HW!\)%uof s_~1rT+'|7Dz5r'P.4*oMG X)P,?t"v.Ŭp1Qr4jT{C / t?a``͸w\-in>O$0Ʀ4b`朅ca!Lp9ںYﻢi nhj->E#d'g\xLZmv:yYd$7^/DPMr:CdkF]dݣLN"/0hnG2.PzRܒՙx5"X}BEcȞܺ_LƟSS''g")jeUAnmw|$Ȅ*>쎎x*nKNWx|LͨkxʷņA ^W GiPl2YI;CK՞Cc.l߲UʇL-`2DO4и /r xc{(oa Hj1+[?],>ڞM{@ ¡L4Vl6QQo: hui>QinG%w ~mB)N.t[');|Bl%A@PeM̗ϲ`Wlh :dVI/.)"&qUv" TK~HZd)D'PIm]v (T J薌8#HB6 T3x{s:s{w}$Vv53b쵵}Rg]#%`$taX=h䷒s\;" EvX]dSI6RrN= %Ȓ]-%|f916?sh<*-zP@8\f뮎i jZ\+v7ǐi,Hwr0hǟTᜁvHÈK/|i3 ,JJѻ1zEɵq"=Ѻ(ǐH~VFɎאp+M!(8y 9|Ƶ g#טp#\}y~罿9@j.d8DUjvXmA0rbbK6ʒf?O?' '߇3s}[pziMmpJ=*\;AVF5o'SʐRSWM0#ԽI7ʼnkWwعc`hZ*1W2#WWd)˽9$- x|<֍pk5˨)?SIOv&n1b@ͺ W`9Qu ǫ`CQA=4!7 4ѶcXG;lVZZ:nTQxwup$^afsB4jO#SċC,[N"b/qY#cmJaUBB44,Ti -RMNz0N.b1pfsǂ.u-zDU9n*Gy|f^ 0uIJccD8ˑE@U!Y= < ΒbKcKCFK\?l{G~#isQxSl0tp{CηO$0|k,v[>@ # Q^]ԆHFcCw~3ˣTFwY#Qǔ Wt]ܮ'nd"n,|gb ~o2ÝnNɀ7, o*1 [9sG_魺Y>uOίeJ`2(e젋u܍޼dvw?'5zYU:Z>{dW\k;w*c-N׏}&O+LT0kCFGわ{8rq f!Հlji?+ }p~z (&Bl@j|=r)sg\oب~E[JSll,iP8,5Z4BG@bTY, rES8HeNbt8r] ;Y>)4TRʉi*QkȲtXG~t2b]<;aɍƿzZ< <^dT: fl*hx8[I䏧ʼVj:LBWr^%7ؙq3dWt-E@3`0`RhbZC9[ 1'"|*0#34\~b'dj}%4Wta;#4M7~-scqYo>@@өh0α7h`)f}G͡EI D2εȃ]mL?R>rNm|´#ޮMFX ;Π-!@_厎!wkc${|"f0*lt֚$W)m&9ᵟ(!}a^Z"+ވַ.ęGĥ8{O&38 41L| ľ nǛ`ݳM KP4e I+jS{#377NN'QmlmC6 Ghw_h#? 7FvfT/ȡɿvqmYfkZ~V+, 'kyjU[9h~se#&ДeS2mMV6%; ɋ+veiMRg}]SOT592U"e.n'nY4mPJ;* Rqd!IbMY"2t|zEjkX|\"JVʓa_[?XǢsmp[D癪XlL18n 6b=4́VTp%$Z;.iQD2-uYlL4,uD6׭Kjud`,$!)G~sk~yR[VԹ1P DgX9TN9K=Hg@4!/A8ֲc'Jj !} V-(ڧ^SI(*fdNMl/ZԾh7%_7vD P~R1u2K*sᢕ|]ʗN 3I#殪d+f&b?^*\+bk֬ڼkmE<΅M C2uo"otM9hfqmnZn, Bl+?_37Od [u^MgV(RH Y #f:^ߕƭ|T+ro0_QҿP0'K0^c-IU G 5J3 Rh͈Iq٣»2-&iϰl=Mx؜MnA5ZgAfzn+bcŸ,D9ud'|ק-i!dQCݐKvcwC&/KF2,מst_?1|Ā)#.x.}䴃.m/`6rCjD>eVJoUkSAZş{Q-/QN}()0ElwDHq>"/XޅYTӔzP#= bj[ װx ^ !+ϙ%B BnƊ)V80B{Żj^PNRжjO  {!x57pow $37QxEjLoc,p k4M+TNMv(O f+ۺY~kŦÌ>;0J(J/o֣ i0prszjE6DK㞦(@Pf]L6TA3 UX(j0K1$wag촵n"M(>A-O^$& W3cO;?<G?ZfGډܖW iUi9+z+]]r<{~RlD\6=[oݏ%mJѶ~7ngbE[xzwGS z}~teCM Γ|⫊n2U~Ҫ8Z@Ln8uv+D=oGMsѯE͵t4j=N{&^pFԠjx9G|//LrLm7 +1X'"LE Z@#ZdY ,n :p/slY?۬цhK}CgJAHsT蜞~԰W>p<>Dwp_wa)qX0|M.u?oulk9 C;}}V3h"̕ @R (7zTcZ&vn#qR5}aBf!eh+a}=9`V 2VNzLVV2tGZnb]+43%bL[{\ c 1 Y2k.ac\[C"- K:5feHE">p(R&m,] \D}F u=#‡~t'*$J<7d$P~:`ٖQp1…y c*{inT{ojf0dɒYx+qSDc ۂN5ٯnv<).% ^202 654#LˋAD+M%o I{Jj]xŔZY 5JX3Yɶh~ذRuv{=5 lYoqsy}Ƞ"sG?]]J_qv(Z*\gc&Lqv.71B{>ҕʥӣQYeq_~p3]fR8ey:&'sUo2q=nd*8Cy0$$Z"M[v4[_/ UDXbJ2NvܸV DnqlnJB7R0Psi}b4Q}R-ұD+ ~ v$0Okt0GHZ!X}/ϳ+~NN"r|Z5cD3Ʌs4HomNxe\]|wҀ˿z/"(%W1irO_NfQW0eV$),hVa6(a`k*h;;W i OQUI"]K>([ےlb1^ӵzI@|Ei(@j&>]h@Ђ ɀR1yl Q7λL\õuNbjLceH,I B/03hgWz_e Va=f}v,!Ͽ<&fV_aA۩/xGЂ``> {2 ʼ9Nd~ yf]ܟW+o &9fW.qx&h{-iK&JCŧ?Jz st/gi0ڨ2$e@,ɋZ Slq0cf )=0FGa5\=ԓONw.lu_ڱ񆦶PMl0i1YX^ q&Њ(ݞ:S}*(K˂/_37&F.R&ִ;0ٚ:w ssQ҇WU$CCYI;hx#tm$T;fc{w>iAVpr D0!Ȭ nSgoܭ+C ??nfR }W.SirT< w]BW}@I54-l |ʱI{>*.&YA5ӇOlbď(Vt{Z=>6PQgaM7~ODIWMqMp %x;>IЊޝ!IVD;:̄Bl?^[ gE~/kYAJp0rO#K1Fj+~RTrbeKN EAØ NBQ. HS݉휝&GGH.P&%I6rCQ*ױWwX鏚@pg~j984pOxX&s.bY{λ|iKz SLB${uzK%$phq)` L.W̐V)) CG?G̑*Ngoס} J뾌Q746Q1i#&+Wf-ECt@27j}C2#EkJ|yG2|/>Ϭ~~>#E*E5 /gNV9KҎ9!;뵆%A=C/} eY,a#@1⃎CE0/$u37ʲ/0~$nuZ ~ΐemRN@>II0:p|e Aı/M**2V7VBlŤk̵ WR0T 2Cz۟ay_Rf53`&  44_܇ZC7Zo m%w)߇z wބq n[%gZ&8S-gIY[8|,| (ԫ风% *pȭqB9g)KOĊgfV0?( }nuW B\wODg|*㼰X0^/Fv?3xzf -d OKd̀,QE~-9crnk=6&&-[F6v;G殍J.H I&v!SJ }^ϡM 5Fgl25 MOTVFʍ5E:\ڲ[ÏfUo6 ^3dž5rU4zPdy6Zi/w&{gXhqʟ*u&G8i^Mm3]m47= 4y@ ݕe,/u2뭧!V>j:ޒ-kGmgt;m4p a9cT/cIe;1_EuݑA4sQWC3&%3ZEbW0w ieot?.^͂P@{O9Ļ$Mf2Fpͱ(ǟ_Tت{e EVݱY29 !cקNI,6è7'wT[;kI^Ȼ6&$'EA5,|,ZN#]rˌ]P!&~Xy9c7]i*2Vϒavh sZZԐSHɗi2spazz0R?k5J 19\~ ވHVeв~lW+TKG:3>pfdBU[7uh*UC2J+zØDCO+]qA6%e(,9@1sgrQZՇ!7Pɳuqh>% N]˴8܎$ʫ((}36gw{Po &y]tԘb̰fsh64cO2I'03@YPFdf/˵>\I-i̜\-d2/Z7 wsO"J gz|\ t4F'Γ|˞qDD y­ytlEs&EdɽZ1Չlpbxc3[3fujB1CZ&fV C¬Cװ)b8R b˦.Eڽ˨ eK{%Sy#(kmi I2jU!فe2egרpbiWשwRQڗvC9B@";ႮB̥];65`$/XbAE'$syRnڄ8ɭ1XKn"ڑ@S)apy|may¿^JcHqV HAM@pldW:v&¯ܷ о%O ݚKO_7ϴ\#ʵqyhuk[,u\$v0N=8/7ƃsX2|wQ^ȸ"ܔHaUl.| bױYY/vV2}5 3ލd\ۿ+J# ?tSLVm6>SOMp\tZKԬs+/9Oc&%c (?"H-6" ŕ}Dh NrC@"|ub{WЃ[ŵhʴ1jm5#<=<0&Nc@<ϹjRb EoK3z"W9dLڴ&kA`6C%t+"ծkX SkH!hI%| *N┒CsNr}R{hҝܦb!l!{[ ukl(ic1^:JI׭+&wWJ(5wA(ȧ./.0fA>/d0߄'f_|&QǿcVSojX{^!KIׇJs]j@Gm=3!.y'g-Jr"ɥَth5D+2@#U&r$Ea7yq,Q2N%?[*aòt6\d*b?FK|$̊g>~DLQIX iuSf/X:#9T?L^oaeN^enG!d:MD]䯳'3o&.)~*z_#Eԁ8>sU]%^6?P ]ӺS,^3̖]i6gDhtCmzIH3Vb\zC9}V\3إUi5 Riq b*8c˼tBHzd|wPlCvB&QN~'V'vH9ÅqةbH-ӋqM?7h$,0 ah9Mj%\g/2 R4SO.j:P%{qW@h߁y7B<98XSNz e2T{M$}J ϓsI=vt7V,EѽQ]D dϤP;נuawj UUbNjyzD.B'#XRxSww_ x XV]֊msr~Op{sŒGdP[֔.f}1yxZ3*KHއn^z?O'>Hfc ЁryjUs;AHHj ֫5d~+)j>]&o5X]ϑ#_7^D };Q/m yj?>/%d 2lаF̘n 7eJ+ }ջٹBFwC 3( \l$wz|S+k%t\&Y"C'=+5{,u:ax:"C U0Qj;DۅBq3.cWɠLϩer[վl@슅}ݦhl=`+@wCY5GqDP|%~-::FkX2K3Q}3UIYƢyWz7 Ͼ"e%;\ě޺x y ?v^ķ "NJx)Nil+Kt86-E$|!mpD/R^o=iٖ,*1S#޽-Q RQ1İ2?6-ts9bd]:("eZDiq9{YgXv'_{.%MQǻHZEK,]3RH?_VS~*-j! ?-¬ޥyv\"k$QPbܼtrDtŠ-P@Q:48 ݛgٝ߉ڟet`H|<#Fͱ39W%D?jmR<,Y@ }zqD^X}eFw#Gf+^#L^ZXP{/{v*>]g3W RFPV(7+@ͧ ů=~r Xѐ/w636,um1lm [| :`]!M}S`w{4_ ~]/|`*2Y-g >;)͆#'@JX߰f )iT2vIZGW&.D3tk:Z0[ezJ ĸk3iH*rUO=nJ%F QE4noPs!czòO%tᑓ&),FpP(Swʺ57uA֬zK;YrǛf_9$@(jrGj\4&8N#}&xCjdAޜ<C3|GBr]H4Na=4MqGH3kۚvZ ľqIȒ#U-(Ta0:ʽ_b0 d]߯%>?OoLz<Č*rj\Q0[b&\ɜB,WgK`y mHy#n䆕,ڋtCP{l DiE)+:/shܨrOIw.{ư;k]#20zv1 &ټ"FG;;j*xӋD!Dj:±ƜBp;uPLRGiSI*"H܆x _ D0EYqz|c #G&j7 Fvh铮nLꄾufje4ha%p{ Ԭ;5z ?:39.kj;7n"_:YQbc6LrfexZ@n~X\32h|-ƯAdɎ첹*cz %Nр\[taODiō8Ok˥(5\ޝ(3H׽M RgA3r"Bi) %G(Z FҺض֒3>)!m PW"Rڙk]-1BѰV@ou 5zCl]+oSe2y$ٖq y"!|B7ϣ"/Eb ,1#Si.|hQ{5ݦ/.ʼ]/6WpntD"Zmsu>0PjFѣLV2=t eL-@̀X3y*1BU-Pd-cǴ"z|M wçx7b'[$[BvM&/[gEˬMu)7ZNU)NfJB0 xHaf\1 m(㓻8a(y 9L%A1y(XAU:-k/!|bL1_Y'lN5m\qZAX'sS@8Z3d>ع]M+㶒pA@hZ_@i~_1\KϦ5ȿI,ggWZIt8x5ˆ[D\MЗݛBRԫ gw_0b@XwfKk.GeBNqB_&o+ γ\E 3#'6{WF<sҗ#'Q4T)#ӛ,Gl!W-BЍ=1L4(z4:Yj3b(5Ttnxlr2> HV)3p&R5]2A|knSi+G?r&L<ƻ83bT|Z\3~~H<]5ڳX_|Ǒ:hǝ#!U$}$B?v@dytG) ]47~9fלHӥT6{gS:;;JfzjAX['y@?{p˵=Jcn~^'(]Lm-^NM`^]`c1B"}fz~v*Ze[U'宓 j6HVuHƋ|)$@.8 Ge-% ށ5Ęh7YSk-QY';<,Du 0qDG,rTasfd[J'7K#Lhl23E%vOwc^$sXwHh3Q,X7v*:b=W_(F;~[riD%R`$!jNتCyUtlzgC@$;ĕlMWS@oZK5:%Ph=Z%ܘWVf{Sqď:ۻkl4_.,ٯ dt@}8Y>u6 k 7hVU2/gBZU@t/+0DM?6{/ɗ3lExR}4?u6f  }lzwLN**;Po<NVXd#Sz,<ν,K(5,w_Ĩ)tn)o4ZA*nwM{d[HK.9Ze"w2hObS {|F럷>4u[ncWB <B9,<$z#I|Ħ0oTh[w~ `(*{awHKt5,k 5ژKiLUΗyEU{­gP6b/jF6V)BcH VϢ=\舄_Y|k 5X}V^ƌ~^<}e)r~ƣ:fz,Ys!'x^=]B&{(ڎ6>ԃF:Ԛ)d<5Ipwc93>DPt&fRֳ2a`25}BN=v%žK9\5Gs6 AZ߆ ,76&~QqIٟV;R!O 8bXWN!co y+='ըP ^H]v?'c&i_AQ4}t,fQudz-&@ȓ6{ h$or1ҴBy6nx1 3qiQjqfCꢙOk‚ϱdh^U/"AcTDDZ 0hjŊ+M+_,_Ml%b =6&f漤r'Ҥu.)D[z2Oʄ:wƨ.fxmfoMKNJkBQZ5e2(WBWW$g0XEAhڒRRNp =3 ҀR8i٬9_(&_. IL4L6ou;&T#`'ѻ\a>EBLQ51 3+xT jQQvCH@kAO㜋Uʚ<߁MAl !YM'QA'o/x$w6LÛ Y>||6NsK?1lpFN{}}8PTLĉ+ z"%3ǔߎ KVKzJ?QdwɦRpȃCLt w?{$h{! F钩;=bh"$*P# }lTp`t2O 1QY'B +gZ^iiSrOvVZ[; }v3]"mQAcPYwLV :3ʤl9lR8"G^_A@pջ^Sɷd_Pe:a̦5%]ʯ8f @rsQҚ.YMه \+4 DG|'thQX)ֈ3JuEFkT k=#k(C9y#I]&D+ PI|3B'hr^ *خ7+B?AG+YHqr'9jƩ :E4Wja#EYtx[-N&5b1Lxmt+- 7[-:D+Ro?)較$%L,zڅxrhz>5Jg[ {%/k<ĬPÕڕ²)ȣ*&,836H 9")'j_T{/@:Ey}$!T*5.%fSrQfprɿª} _>ZPSBBQ(9>I%% 9KRM+/XfTHX1$t4p3;Pմ|q&h50`@ A|kg\Q[KA>`KmU_dM 6v>T<$b*UK{lN[v'"ϚfC2#{B OkKlɾ4iFt.cAcj rIs[s2adc @p+ Zda_I,#<%NT8 C`\ꐦ6xh~(GsN|p5TGWpzTtHL|퍨ŵušPH㙶?+%Dj8h.$I@)T =[R3k i b3'Iх3gV9\bT¥  0C{Xo)s|]zg|C6 |DTR9af9R/ 5genft|uoN!0T4譝Ci05\HV7xiTR?OFv%Y ʯym0,O 18TI3BcX5z5_f yVR3^8fV BUfHX+ql .#nByڱ jF\@3T$N|Z N8Oؒ:D2G%]CVB;r=8̡ZbMO>94*2'3moU5>eS$F뾿/+TI. iJbZqrxҨF8w=w+ZG>tb)Jup{'g=<w?.k{&IwF 7#-I4;.igb_^w .7]nxe6C^Ŏ@]tv]$vb ƙKI!+ Q8ץnoƕ԰3 ީ~M(x c#3u9hKj_Rgm=]/+j=730Usc%MZ'9CL@%xd#tL2,}$@eKp=b]bWP'k_Eee0B.E ) S}1Ry)-d B@8SɒK!Nzy!l(..մBvU0CbI) \ [$3)W{3q{z9 yg2Ҧ(0'G8LsҠ^V_7݆$cM H +W/`Q;`XPF9x@3͔xy7{Z[?vnT)LܗBѩ >IiXi8oҗՉ߿tL sld&ڛ9uIC#7S~J]Ë ,TNTIɌ YQl1gпGŏ߱{ik ePt۝3meBq0ګ;|2Ǚ"b2EIw\IT-07E@8o\T된/nY4=ãۉD%K̕  #TzjvQa1s[$i*%j%G(NKWuu_:l'dO\CbJ2])Lf5Y.$ݽM/8g_y NlEBB%GA!>A뤓hO# 2scyIrB+I\ Jv,XdRԢpwuWF$ >, $V/Ic!Ġp|8jm†௳z(?PyQǭ4T7M>/Aɭ4 -튚qԤ*⿃g?zQX8 hă\  gf%(/3m!no @a'? 9b1ox-L ũ:AQ3"u= Dlh}c6aZxvL)xgnN pco&~zYH+׹.t ɹ!B3\HU/Av Iv6u?: ڰH;MaAnDOHtNaE͏KW猖ꙺzfR0=՛V \PG~npH,KɈ݋ѿL1ayj? xbVI-γ~^ċEM͎ OCpTR& ;+o.z%ɗ"' o6M&jR勛-Qa|cXz 9^WNUߥ&ꇉmFI9*z }|{$r<syߓF:xx0A3ri9Ev?\Ц &ofD$tEЗaJϨT҅>o}k7$V>k2WcV(+VW~MtZ*8q3iX6 1i|eo9 (pƇi*$-p8c~WQ)SbYD9?UhKHYʁ3,7_)(7>h˾@Io/H, Ӟn-b|dΡ敲v*1P> Dy4uQvV~:$]PIzÉ=wu0wR7[@%TH>z)As1P(u eH5}9;U |rCNJ]Sʅ C^StmZlbX}ke+u]{sE{:Uv 4I.v*2h7kG^rHm%(լ /aɪeN!RX*3ɜ:1x0k7_4 !ϹTۉ eL4R~e*?̎9 Jm1J)hsqwVz0"s UE7$ ̺R"<2žչto }"EcČ). ԰sWZ# O\ h]6:q'-uOǎ E'm(N~acR&eʜ5ț^ˇ=o-p\Vtc]1M $4s')o λpt }<0Pۘ E*'_6)^Nv w,*fdg+t{T/to^,cȎ,> 2Ш z|ڮߒ^``YU&bY~s2D9M%eR&RTՑJnWl~BiKҊ_g*db[M~(X7tMӯ./xNŘ'Ry)LO[Jh1 |e#L\qt<\y6a`:35޷/ʎj,Gp1l& o ٭GJ6;Jb?kCA*=`2e/Spasu.]@69`i m>ey_ie ܁Kk^ᑂvn]LRgFN:|SO *aEy啐QP9VK.~ njv[v{w 4՝UWMh64wMb|HTKj[AMyo`[]i!|J!{n!+ Gb ޯ04Ӹ HkCaؗ{ch݂W2C<ŞfdpXs:)lg (#>vi. k}>ɡai|Ey3EVsb!;(A<x1@E7苈88aPxMvv\ "#s% Ǡ:!uʆU6 sPb!D9]fted2? bӍ%P4-I& VI[ a1*o=џdMDa;q̏=g~l*XM?xR/>>&cVAN O k5T0̩o۵׆H}N;L?Wes~AiUݬT_sX\8S0\J&gJ'/FX|o~X9{Mh`$C%2ϦbV_ڵٮHd}ʳW'0/-*m?3#>`zNyVw>Pl꼴xC}GodI.l?]:)Qܷ">Hʯņ25Ԇ7;[ >P> k FSoFa;qr(&V/m2i`!|8e^yϘ, .B>W$3EZ=` γJ f&R[K٦* 䶫vtX,]?:uUq֟|ܭ'&|J#Og?"SW$\pLS Qa_Z/ơڷo*: lwsnr:m2οwB'_Ccp*NXѡVNvi1o@Z) [$]&rQx={J[ t(`q:7z =@QwP*#qMe6j_Q6 ]elJǝl(nx/ň>8D^+qgdh ŷ'ůWL4sҜjQxCR]xT:~LC|7!N!W#guqS/IXv7\\fȨ#Fʋa*g%qu底*y[nųx,ʼnIW#13.n d-ٻa|VJW`a7C`N?#Ydz2Fدy x=w㧑vه9rb b 2"pT oiQ)鰜n~/FʹSuNh͋ W@ yT ߠc?[ղ RwV*+JB.!p8B3Qʖ WP;. j"Hlzxa5suHL:Pqxiff6nimtV1ӟyGv9ז p :s`JM[dVSv4b`C=m=Կ\%\X*;H:ήUǗdBQӷߺ }L_X@4|}yVY?r+Wc7Ƞm'6՟#;J_}y7J[iP5XK-w;g#4cu!BJ\u4͸jĦ.SL4cn蹲** ^h\ND3 Y)0hj?GIהPUnݶ ]ܠ$Su3VK` EW>"!PP:Dtyĵ/E4kjݥxnK9TU3t(0LD]O{ {C[ܸG[ ko8!It&-aW}ۛOa,Z̳!'`E$܂y'&v}5@jSZ?OI Q.^y³VTQ$_;v6[H na}Qf0FOPEw =JbDr[㗚PZ2NV-~a >T ?냎ۦ?ɘ}[hEĂMH +w \ (^'qe0ڲ|g[z0:Ue#`,YzLSnă ]-L}7!Gj޹v"8E!3<,$|UE/ _&ZC7I\k7 \{ lHY9C??=VTgh=W&#kNf7Ȗ1<4_ݟ4kj?͹c\N6DԎwCL 1«Zb{b xWl}mƁ[7uܒGw<.OorB7lsPHfmLE]=m o+;.!u:+Rvl)l_ܹωn7M-(TcHƼD*Lf-@SwБśTaHJyu.^IFB˹VI#bdssLξonnͶ,4XƏ);?_A^׷:^Qd džÂCt !ŋn26QX42]] h|?/+W8PayN朌,ZvE]pPjx4W݋Z] k 0Fҹ|C_p:5ߎSI DQda Iaj!^ >K~&!Tֆ܋ $vAna?h5a9tn`;t8bN9[ߓ`UqF,ĶSnf^x(PD0jjN+UOd ښ9Oo#= גF0*Mjc]jbPblӄ?ܷ_/ Ce$0!+j'(Nu\(n#9:@dFR D4t:c ;C*";^pB\Mb].U[RM#l#DyķR PqE3Eυ% tks&/=?Eɦ0n"Y.z//:-4̵0AF_^YX홪tkiamaO?#ƮV<<$ cǞpإKֿ'4KƜ7gwDKms=w3L|Rg!ePrkS{X^d,` n\ )h!. @ ZYH⟹<"V5]~uyQyZ0 C'ƲgF'5-$s_<|AkA/L<>@<=`!e KC̬ ,>u;e3+dNe>^%ܽW$rI O\a4~o:94 ఀ_PO+4_V3b&@8&?oKOl{np]1eJ`ق[?ZM%U-0d[Jlcfe5gЎ櫄)m!˸#3`I:C~փ**WF Euܦr65ayrNzQK"<7_l>vyC#8,F5[;}bꪇ/ܖ׮dQԯ"W O0d0XjB+LDZ>X6C8@E( a0I\U[@uLzYz#\ ?_BOR>䉧Y/MBugc7<ܞw96TSqGt ݦ/Ӿr` S,w$Ulmy!l™NmWusUbrܻ;x=f\+bDW/R&κ w%{89U$U :7G-r\ 0 ]ퟴ 1\Ql7Dҹ1.:["U`|[x)@p45Kxx=cMA^?ؓgvvs\ލ|*}ŝ=LV6lρ[cC7.wD9*8Ǝ:QHTmb[i %c76,?\9g*NЯ*S.7yL 6"Cp$ &mu"tSD<ҝl2 12b۳h }< ) tϳ<(v iF^|$6G otSrMhB8':ئ,rӂ{bײ#$U>םϲFȒ4~էZyEjk*0PUqKa~۰)68WRVhpC52C=aT16z;&:;ZMovGxF0> ioK<\xak%4fK t֑/sQ7Lqc/=}ç v}]ԌcƱޛi`tzO&>Ǫ 4S܇6~CcMR t\PC6é_.^RH3Kv…rfr/0LQ Z gﯱ8M٦1 LQ96ĐҊPG!| HZҔr޿+%~]ЃN2VeN8oLY]}a 6qv!Y}P:~{lg qS_FXe4(?V-Luz!kNc견?8t|&vR˷cWM 7f)A"3O;{\pch]qOSmnԙJ}cDn7v[q^9\>D?)Z )$bJ3mٸCYB^uP!݆cV>L޵fW 9DF%z&4A%:.9%=-Q&FoR [cZrջ~E xU}2Д j[Ow;6tuWO6'2Mydyln[ K˓hDtbdC. 9,8b|1" R_tXqG^$ $4IrY1CڊՅ:[ˠ!`qʼaY!@ YE䷵?g' bWTtA02Lfbe{B;c鵼Q@ ȵH8.Z#fqf󷭞.W(OdxH4w <_/0s_*nueYw't Zk!j!v;k)?eT-t0pE7LȂ2?]YҫtҏfΪE!ra`츒!U q-6Ab# F'Բk5ʫ%ܿq[W>-&&tF mt`~Ì߅UoczIh]޽_C _e :ppY&/M:"i 2״c<^ݻC 4o9#\_o03LׄAiXZ`O{R)mZ\ "ݪ!pN^C#VklSڦ .R*C&W\xh KEWT4Kdy%+vv&0(@yNA]0HWo\e1ˮ eGVmJ/o¾fh:I{hSWe;+tsTao oMD^H͝\exA gNCV]ƶÒ#}XX6}^ (+2p걔sj4U͓yV$Wصd<1WFF<?A3!ueVOf䲠.Ya -B8(֊dw6E2*XO'$ݬ ȊG"~fX@ yuc4QF?)- uZ(JMinr}O\ԟeh v 󞑴|=[fs(}aV( XEMb IfW ǛP1ټgO<ힿ@);:]Fiv$7V"Ig~9õ7B d?F_Jj闘H\-~"S ʝ*l3ٖ^խ' 5[=0V, P„iޝجZViY:Rc[E6F1a"$xheldM1v ~eSlux6E%e%Nr3M]Q7‚YONv+=5Ǔ [,)z1̊ &&J')+* 37|@kQEU#GZT 49moulc3K-_0NÀ*QJ={%S5U"F!B?/2uі42˟:Dë}nq[ ?B;ۥ8ZAXFr:Ty^9em7m yڽ275G{/pAXaav'o[E>owUBzhbDv'lDU|JL=MƔWU.nG@QfiF`u)REϲg+kPȮIѯWС\5x7}CzܛP,O ThKBËC4@'&x2}~"l,^<]I͈2P]h*q(NK-ܛUbw7ļ.ݗUiCcTelBZv0dET &S5)I6OrK/id n{_@SLT<њ Ù@y5c휩ENc7`k\|5 30<[>jzGLU/v7j$c0p|lr;-BR#fd Vm >I;1>gLMar.꜎9t5A^T?I)w=L2TVW_ rL; 'smj lv=KLYAttkM\$s'B✚iF& \e-Ns!'oҢ9WPz/ V]w0GwˢSxP}jр? /*F3+1K8-#Չҋ~$ 5HzH 8Z%짯sep~,C|`=V]r W 3+`Q%I9SuDەv#?.mw2Ծ~b~U=61>jX7"f lz\G oƣ]ИNF+TIJ&K8¯%Ɓ(&κ9T|9p2 ˼r=fۀYϬ-X "ܬ{pd5Թx#VZ]|jI)ҳpFr{SgsmرobtwGZɈlJ`lz G{p-RIoS nr̄ºh7;yB"69#㼮d Ϣu{55o7y`Œhy,Cks*yDq"E^ C7b?)wuPkz %^#QA}.>2|-E>/ 4wE4#*d,H^ CfBRnՆr[Z|x"4Xd&X2(Yy?$x'mF'xR]dkɅ.{vE:dkUG?Ӡ$j7uGKa&A-:C U+"w9EEyfL.%Od/gIRbWPbg[;هxF)5s 3xmy!|WK#gx5<• H EXd̞5; Y,N> Yt,$o4*zUH~'։ˆ^+:: R(jj6YTn僳6/0a`5rxd1t կKH>!ǫXO]g=H^1^yAJ'ָ?z[j""{Q9XKmQ(ԭbs|ؓ?rth۝*4!RJmծt@}!rOmaCHG"ϪHݫ6mP;7s؍ߒb}{R_f#YKsܖL{r ^V8 3x>T[Ou@X>߿\xc/xiR)"~B^ FY.&ëYQ;QPH pTv!$~?UhYGKgټF 1%x&>IqgGوSx* շLÂ!<=_1m2l||թv+}7}{Q&+3+ t*e'֘Qg@opT#WeԂXEžF bz/yX=VB&_]@`.Ƨc+ *p6qMit 4̆ŮQrίʆ#<$ e{& 12W2J0L)nC$ITZpL S'A(XU˵:w. o;'ˆf"v)x;Uv߂`l~%Go KT%_"s9!^rAko ԾK= YyX{lk,{y]nToU0{g}< e#WjxuD|]_2 %ssO]"uף]!| muk=»5t&,>dp}k[169}3SP=lY)܅ V{ӑ6[Yܺ-TYT1cF*JHR/c<{n24K:M bW>Euf9ږ9zo!X&H #I͚ʟવNA'";f,6`f0X°5l?f8?4ߍ`RD?TzL rWGHH{ DdK=c}!fR3OwOڜ鱙84?=ex=Z({;$t=q"m$hLf~#-ZYm9bzϕ:h}N5C2p=c'ՙRΓ *7^CX`҈{`PaVmMvƘPRil97Bmk:?4.1C{>;ϓVɝ:Dt9N~g8fhn ǿ~;g_M xGCPN@LCҌ Sk2S[WuU*"ɫ4ԃ8מڑZq!5qT-D R)`;Y[44-g,_Eʁ/M!5 KK46^8d&!m~?"5릚8 ,]N:$0qYYyPL>:=^v1 #bP1bae6S`揝fnGϠ6![4CMdj_~3{Qs7])Fq'-Ȫ. Z3Y:> Qq3*gԟJ "YF݄w{)wVe"*aIƺY8Ϊ(7էjOCTO"Si,2*eGruNe)%vGiɸXM|` »rkkH a$Pأpm(s;TM%Vgy<h!h/3ݹr?%ӾN q%̆3ns7[%hby~:\P=} W|rhfgNOeg02H5.µ_inq> E* eIzi 0'}qCѯcpŗg?XE_sXGR-9C?-fg(٤`kVWq[A΂"7%LAO-Z6^_߫:@ i2@2?<0ǹ/^ Z=lc*YuDFc)Oh@K֩ivAf WMNG`/0`Xk:mCߐvgC֖#Y21/Z7ܙD:򌣃/9ƹ'2wºz^p\X.p3ą Ua vc)e7l8`J?3Ɲ_ߨxț"{\pE3~AuX1f1F,رg3֪ D1S$;|TQJ]c]G A N7]ϛ"$jqF.m46tXƆndu.R@s=f%H5=!K>amJqtI(V SP}Tg/~w~fo.kAqOPQU_/$%eX*J3\Q={9 Uqǐr̼'`5?k+.s? @R1V`8݅ZL]ء]5l0Ζh; ʳ]LH&~x痙ퟏORJط Eiػ]j bmI+ 5U :B'cfc$W22]@.UU_o#J;N_Wυ :zk 0*,3SJ,Hp$MEbel2ƞM6=#*7n">}FG/`f۷-;:]Їa:J #$'񆡵zmGWJSi5t!P} :b' {02qrEr5J`2p&R;eYܵO0^R_M:C$Ho%XD|7<4 ͥ|v\ =&av| k)L+C`gn mq[V~Y"b0DHٵbH kwBF^,:r>#6*ۧfHtq83)e2b}/;t͜RYQkg0ۃEs@sX}mf|/)4Q=C=JTX`'lINؿ;"ʤESK7㗘nO:oŌl[rK]-I%oN:NF36L ^9  n_YnV P3'VG @0-WdIL)xHy*c&g~ ơ].j e"_ k]xC4Ҿdi<~S9G'.WW??G,H50MnlV$=k+Vu@2Y=Mx}8jk2x'SecxdWz us1WZt;WD<=%s/r]e|=~,),#KKe--Db ZAach/!#]fpK;AN )/C%89DxR}AA飑=Icܓ ~ #VWjSWm_\S{tqE@Ɠ 9=6F޴HwF-Z}( I1%Zf/r{~Yk ŝ%#et/`mr8|~ oOZ5GUy*B1%} VS͋47z>\MW{ޑlv"?RWR|oihcsQo"~kEw͒U?B:=jnT߿P7T?3Aسj|ڲ"4"6Ԥ,3 1r ,~0rꜜG$8gM~"9zDẢKaX7 䦏Y[kjG#3z~t@FS} 2;6(#9la(3*SH)jOU>Aq^ra}"+qNszuv-όBezLs>.l^F(Kz!%!ɎƸKM 9nY`r尫6N1 Q8o tٙc2Gٵ(m _:E}.s t>dwS娻pnaB'$ApJgѬl g\2Q9=hj (H 6PJt){|.\22r~І/QfsŮ3ϬcYX=|#a Jh ;jA|O ʑM5}]B(ҡޡ2J*>vJ }'sJڝ}L Iџ@(,8sX!.LA|ӊ-^!M:jS5/qƾWX7:JW݇8@nM 2?ؖ1$^B{2lfpbTH![0ox֎=={E)6i2.T]|^-wJD q`0x%9з6.?`[gcT.3]2_3 N "CrBoުQ_(-:b1ʩx {H|Yl#MtP*I@.![V ? `%b4:.Z^xԾQ+5Hmڢ;#FJrl!u8z7m*hڬ5b("q~g=da)&;ØSfF #rF``0P1:MIY"6l K,ࠬ"Gɬ uuOEe53Y)Fj[2>MI ï0$ &yQY"K }^u_T!۱y 7^#Pr B]Cjeͥx0gѝ/SkB3iUBbk  {h!+d pov#bJU)r *2{jqohvk;q0yl<.sRP%[r\$NHP4QMX8g#BIAItӬF/)aԇf?XlqVO. s`|ҏrQ?=l#pXXlEW]v${Z+攥1R:c /p>FMͩD)\v&@GBWgd3W^Ј%FRf$ Cypxɽ.Eg-Ha Ak&2.p(42̙)ۧ%΋`ZC/H;&S3/=z@p&aAܱy-ͨW#>[ ókBRLrz?iy1}u)^HvF:G lIOk1pSG"Vt7ɻ77"6 [zMw`9;ɯlL͐_Jr5v'wVC3 7FE:4m<ݶOǪt2=Eʚ;Bkh!: z'$X6v[KwZs׺1w<փ^Wz'7(F%11# |y4#2B7m)mׅ6Vmo0[_$c]h>e~(HmN#{"S%:Z*Q%}J@L ! Wz  8RMM]kfӳ~Ntlr eV\Vs-  r q9bCNAVw±ݟffq,MtWH{Y-*7eӺuygzH ,Mp4]n+TR/S:êU`>7)D0ג.teaֶ'Qj南R*%}9xE1% K;Tr~n-8hטԋV~T=:ps-ofz{7P^偪HUQiXCC^  总t^~\>}RlMZ̢~(KF4f*`$Wwx-Xٖmm` 9Q00iy  _ɀh݅4] iͥQ$ٹ9щee(f5ml)?;XMce敒Mu*o돝>ȤT/svԣ4FswUx-4_-y ޗ(H 7U ދ'W~1SZ*  QFfm֥twaƁ?Ҍ>0@Z:rW:Ԡ @pn'{$%1b/2t2OXh`ik:[Nߣgd(#>P{K֑FqgQdqn+4@ G1RĄ629OYW0H =D-~dbЍaVi>J\p@!5_x>3Fn3M55uFULǘ#^p/4dgS!Lџ4{#$@8'QMyU(~]\? cnBc(S!<сv9Tm\Ek74S NtʊՅp+ >,$:QV.4's\yw"7W8R0pxNbҕa:4̼oaBx ]>΅A ВM<`<_0 O3l! EU .wmNJQl[?oרToG'jZρbR 2p(Z}MO\)2J`ţM 5 $rOe]rYR[%XNԄN ~1#^A?6b 3N!,:nrVi1gUO!5qq&nS̹RG h\yum+Yߦ7) prW)Sæ Ԑ~C+̛cS0Y7AzT8hU6]W43:Q(('xՈT$DM|c  5u܂kSblb_pisWduRƜ%e|۳DA)U>P<~4~΁>|XG3z|U r>-l.)?.h 09xwzx:5Nй68FDTVi+OaB_tN !t /sxV% ؽGNui):?^ s_Ք6Qx=NOQ 7I͋r<*-xz/zj87( @+lS0e)}˚w/7U6mAkO((~\ԼK:(@-_5{rz3mxM{  m핗p:}\SUaP$]'pZQ^9^ }+yïA'ꤔ$tbO|eu]8Y 947P,W$ϣg4(Xwܩ!&UQNgiR,DͺAq}  :J|a9NL=uO|$V$032iIjbŘMGf6cͼAǘx*kT84{}LO}|;?pD=*Sץrh}ap#Y9W}jR|o\2+ U;p8RU%NWuO3$]n4o :#&$P/}Vo#& e&."Z*wUJaƆ*6 4tvsОmހ9!qHx,j9.edia#E;S_CF a2\X]$̦)o:'% pQȭ*3vL%9v֢[m6xc Zs_>n,{."a*]"Fς&-[TSQnΘ#'6Xt+v-mL Q#P@wo &Q3y0EdʷW}ί:5dske;7OI<6TT*~RFrhi:"E%8R&P9d&M~y/H,ux$ A[\=Rs#P3Uj-F:flCcFW*$ 2C>X2x$FNM6+fު:}ED+cB"7+4m \x 0%BCpz6(1c#Hi}.t;sz0;u?Q]ZN_z v&je⪞acĒЄ$q)8(CgJ`% 7-sr :.{N e&,V(@ێr0A/6|C`ۄ~/C2yuɹ?WrbjhOF%,w2(Ęy!Y^C: nZ#s~q,j#9M^R[7<:; *jeJuFG2wm1d(MdQ6ga΄Ay!}O|a9٫g;W-_ T1DV`6$[́1y{.l;&(,DV.>(_6; )dXd3A=IJm"!{#m5yOF=u xzrDÝXr>q*R/k?NTUC{˟C` ,3#u3kô ~o"6IhWPLڋCk 9*,ۏ d*TJ:@kӴaj op3SPLεE6U,lrȨVvaZDѶ~p}y6)?-0P/:{DAE-yŪΡn(mS 免tP2]ƙi:Sv>$3SjdуqRW+Jr(֗E+Sv{E(c:i|H74Y=)a?rUz[cCO?.?,G]YO|/l~fo]I&cɆu)EJ Ԩ$v4Ⱥlbb:KkcZ۬*tNSW~uښl.K{ȒyR2o2r:ms(yMߛ%ǍJ&nz_>O_` }k_%<0# 3VD*N#6e֩<%'ABԌ͂;;H}+:ҬW4$O3w %ŴZe#$p)"8y%t}b̔3؈+ 4";$[?NsU+I  #gBk`vַg7jD{ǝJ㱃Ѣvpy%G_ffZl]ﵰx"R*X UA>dRWZ,WП *vm$*G rq ,KƖT2G,JϠէW5{'n=yL,)"q3"ނ"g_ۘ_Ɩ9\@粠7Fmb 0*;)Vb;ޅ/XיݛT)T3r[@_szU\6z01{rz>CŬ(؀!bxu"(X&C ޷5XVlNcH jRбkF_dqh%Wߖc,} 0W"=zƳbdZ𠿳Z]RxܷHjzeY[ HnFyt!_P$UqB;m,H-? $+rAR|T[3#n[<d?xچqÉPA]K{\ELؙ @zUȀQW ]_C^\L6~+,`pHOBSыЃ;)=)nfi<\,#SIMB)p. 㔌qnD6Kr$Aud[5фcwUL*W NÓkSgRwĠ"%4w>)Tv9~Y=1#25դ"ķc/,3ڏ^y!M<ϴQs?JE/T1{BzԤqԘ. 0ϔN/NWv>mսb \g ְAOXvIhkeIpBߛ !#@.%-#1feޢI"]l6,%È$ۮ4_}|2D }GS@Eȿnt\Ae/h@桱q'jt#sJDu\߇eF{iU(lh!,vSoqyf՞]M7+RŨ]"0v ^6nyU QCUG 3(7CB6,z[@ZE 5}D!҈ Un mps@ؗ%$~ 6|y.KUDsvjI ɣU#mRk\b@f9)VhxEQ[5H֢̒Ȳ]`MeT #:K]耭|.lQ0W&R&AI Oǽ yc- &&md-+͞"ˌz0[\~ ҨbEgtwK360!Tpa FJf4ԿbrP}i-r^A2Ǫy*+ M(ޘLardmo,R,S|b(TԦAoVW8%SvDZ/dj/Iu~qUM+SCc }fT+a/u4KвE4 `Ey58\Qwi!ْ۽k8LqE|ͳ !#yXtv!mʷH L]Wa.NþNI ?Iіn/-H ?̍-߶ސO4C@t ̋rFf%H <度3U֥:"y u~0x-39^d I!x߄,&Z6=DdìaVG ɿ7L|]w֠F;0S3y6$q5hg ˡ|Nc_r :?_Sd3ǃF =ī78߉!.IzrXݵkH~Q_@)'3dghSM ܻЇ {DT0h^V* ,fB̎"|a6&l|&LrL e*hEyfX!} d"Ý?f1u6%`#֤3?GVJAi|=.Q{)T .o;'M 4O>7k_,<$io*Ю@gHh 犔R&8 '1<.%dV;2׻^^AǺm>,?Ɖ 1b=OSloʝߑ`L+d뫢sFq!uD #ǀwj&@ 7+s?I9J-gC`M!ȿ^]c۔Ivgk~UK^ZƨP8ݩ ׉4"FB$;±-ed<Ж~ː܌mx/ ξ!w}@:lSRcnzKDqI@ڶo UGgc YC^l$*{ _#Cؼι !p("'8CS`NC>訯OSBML˞am~%_"29-h%&ͧU5h.kuXd;"@PA)t 7.K&&{wpPECAEG.ņD$V\ۈpcM ဆtUteU8HGĸ s&qkjer&C֤CK9Tal 5Nm8_˭5#i6^iScZxմ9J ƕxJ۸㉼2kvbI!t6I>uŚ/Av9ؘ DkPY=+tn8$΢=b51vKc\|_dpsּ{z:s@.52i$,Nk.yar3xODsR,a!|Yc 's-r cp˞2zMV 4/{6lyXWE"FÊZv%N, 7є-޺.\i%fsI&ZnTP"8K[q19]iζΰn`QYsv7)J1Gؿ}V2WqE7Rl&:\rK8Rǀkhr)yY0k?Ә s|.6*`dI:5{]K\"P-)##Y;foVlt1:|+X :oS!ߐ{ކMu)*ɻWo۞Ai)KͼLI:x?P|r_Z2ן,<޸z rF,w,5ss]0F2Э1"VIbk-NkV3q1}lVy U_n) A>۽+)^ G3(bj_^r4b0?ʐ4lfE9CPZ`Hm_OT+Ǥ!=|qC'\9KFdJc ɳuW`]EH7-g(Γ)Yd&M.XۜW=ܚT/\馉hL݀5XtLf%|s| zz%@y͐0VmA㑹|,TTր68H_[E55,,ML @QQ(,1ǔ4RO@VDoBPA%.m&)l):Egnd~7Z}U@q~AL\˅lk -[~z[4T/+H>!ۿĔU\QwD܃X[XI|g h/.ՇdlG.2Fח|*HUf){aWKNVGw_F|Oυl`WJWޤ{r;P؉~Ad_m2n6JKriL Ě`:=Zv7+Lt)Xaw!$ bvk&֙sW@[cCڿ!/yf_*tk⿽G'ϟtR[2usE v=?`@*MgFD\o% ݖvO aMUz1w.|uI!x(p: OAB8C:.҄~G!gޅnZא^Zz(&Ы1J-Ŀ)G=7*ScgY1z6{TzKJ2v5(XJ_tV )AqD@ϿWP=BZ1"U^$?L6已nj% m֏4 @# YZ