sssd-ad-2.9.4-1.el8 >  H    $eQ? U])EISj u"i4o.~oz/P`pr .]x&2s3WE^Nh1G& ;,e%czF=6Hiġ˞Oaԩ>+y>eΘ{Ob-yNapk~K!`s#T$ h,l[W'ZA4QXCڪS%Nq2_>3;cפ%!E{>)CtO(W e>[%7OQ/jFWnSl: Ɋj(_h<|ZmL^%8_ˉzSJ'?&n[\.Y0΁$`fj/ 䆐)tPdQQ 7?I.+bИ_PwW/\y-vaJck;7`/=5fSuג:J _l6,z {L RL:FR|[u _|2e114a302d3683d2fbb0965510a9856e6883186a7552983fe22e2d7c7151a27e627fd4984689014a9eb3b1a8a2a4177526acbedd0302047c435bb500673065023013d4ffcf6156af9e870c94fa7a9a8cbaa94b4439cf22e1a712d14bda12b776088e2665f848b8451872b3e18663cc78b1023100a98ad673841571f1ed96df55ea1e50e078c4f01180a004d8d788d857862eb413726413735866c198a3aa8a6e5de217150302047c435bb500673065023013d4ffcf6156af9e870c94fa7a9a8cbaa94b4439cf22e1a712d14bda12b776088e2665f848b8451872b3e18663cc78b1023100a98ad673841571f1ed96df55ea1e50e078c4f01180a004d8d788d857862eb413726413735866c198a3aa8a6e5de217150302047c435bb500673065023013d4ffcf6156af9e870c94fa7a9a8cbaa94b4439cf22e1a712d14bda12b776088e2665f848b8451872b3e18663cc78b1023100a98ad673841571f1ed96df55ea1e50e078c4f01180a004d8d788d857862eb413726413735866c198a3aa8a6e5de217150302047c435bb500673065023013d4ffcf6156af9e870c94fa7a9a8cbaa94b4439cf22e1a712d14bda12b776088e2665f848b8451872b3e18663cc78b1023100a98ad673841571f1ed96df55ea1e50e078c4f01180a004d8d788d857862eb413726413735866c198a3aa8a6e5de217150302047c435bb500673065023013d4ffcf6156af9e870c94fa7a9a8cbaa94b4439cf22e1a712d14bda12b776088e2665f848b8451872b3e18663cc78b1023100a98ad673841571f1ed96df55ea1e50e078c4f01180a004d8d788d857862eb413726413735866c198a3aa8a6e5de217150302047c435bb5006730650230645fb151c6c8dbb147783c103b15a15f8fd54fd5592cc4b921560540e2cecb626a280be7166ff1f05866f01f4d4954c9023100e0282fbb595141ed49e128446adb65489bf22556a94c94a663231285e673a39469448b876bb42d61e834855ead6383bb0302047c435bb50066306402302f47954c3a90cbd00131041eebf49b51070b7884c263b4854e26f9a3361cf6737d3f33ea8eebef45eb7f57b9d5641b9b02302d6349b18d894b8f5b8b3bc5724398d84f299f3150101c680c4043a2caca7224b1c6ad023ba105ceedf5040ec655b5100302047c435bb500673065023013d4ffcf6156af9e870c94fa7a9a8cbaa94b4439cf22e1a712d14bda12b776088e2665f848b8451872b3e18663cc78b1023100a98ad673841571f1ed96df55ea1e50e078c4f01180a004d8d788d857862eb413726413735866c198a3aa8a6e5de217150302047c435bb50066306402301e1c632c69bc2b3acc8290a4bef5602abfda9a0def7a10712cd98a27ad0a26588b90d5e8ec4139694b816e72688d768402301256a96fbc006757e447f3c1c02daf7da865c47168f75ff2c4a8b66e406772266323bfafcd97cefb75c3ab8b6dfa79810302047c435bb500663064023044880cce4a55ed69410f4315c47b7e83399ac16f753d705babe2cb99ffc6154f580c5bc878b8c1584a86da1b02e705e602306439072c198c10fa35f2ea9cc6daa042df6c355064334ba2e93dbb6b03d7bfb048f569cf19750bc3f6dea8f1a92b04a40302047c435bb500663064023065c6ebd777a00fb0a9376e8a6a61ea292563a964d4073249bb1363fa08247961fddaee990f4921c125e3aa5d2056c36302302632bc482a7f39c3e35bacc38adf8579d07a9a21141c90398320b13786bf536b3b4af3525d2a8f384a35a18875f4d8280302047c435bb500673065023100e3a2bb0b8661f4e380694468a14a6a852140c9cf191a5f705fd23e9ccc8e30c324b80479078cf87a4f0b4e6452f9c729023011d6295fca07f9be426966c80efc5245fb4268b07b9f44faff86d7761d0cc1a3a8de731511fa85a4326478fa830c78df0302047c435bb50066306402305e3b64417267b4854896324cf52c69b6be301320f8fa26f4d44f57b7d6709d8c41dab3494146da47240ff47cddfddad002305c3f93d09b730e7c5804232af66117fbceb84b282fc536b8e9fa98c2806e7894667b4e267af726f819bb74699c0027af eQ? U]U'5itPeXc2ƿi.xPVJc>UVDk7y@1j;mI?>vA,mDֱ;tAwaU@Dv'{H<*ixMg쁤.$N,Ut;.Zb (ƯVB|cAm14 TQhTש$Z?[>2%,!iwUv0Z+!]֝J$loV^b@ڄ!I8N1(+2;MloU fn #C^BAl7>3$Ή]/sRL3Pe+\#Ӫd qiV[s ]ӥ/Tn7[Ӷ\$Y}| 1W R \*q{?goD0*"Q|m9wt9Qbp ^4""i \ADdt ?oPsMu$􉶝@eI>`E ?d   2 (EKT            L   LGhG Gtx}(89`:hG H< Ip XY\ ] ^ bdeflt u@ vtw x y4S Csssd-ad2.9.41.el8The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.ex86-04.stream.rdu2.redhat.comAeCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxx86_64'&hK:N>oQAAAA큤eeeeeeaeaee+eVeUeVeVcdb14c9c9bfca93aeb398da5c7395214d1b133dd4a2e784f31022f5c824a92b3e835953818353b7ebaf993596dff93745b99032bc86bee5be93f7444abccd8168ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90305fe17e80a3d77e671b2392c5305deebf3f88859b494f8c39451065d5d6150fe2ff78fdc5c32896f8681a2ad7d16e721581e2289ce2978ad38a50c5093dd258f26245c7b9735cf7427470e58de26c527c83157f5209ea688c8a0eb0980856fefd97d89b7ad844bc26a4f496ecb1861a49f455fceecee58bfd1d00f7d6671d4e5../../../../usr/lib64/sssd/libsss_ad.so../../../../usr/libexec/sssd/gpo_childrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-1.el8.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.9.4-1.el82.9.4-1.el83.0.4-14.6.0-14.0-15.2-14.19.4-2.el82.9.4-1.el82.9.4-1.el82.9.4-1.el8sssd1.10.0-8.beta24.14.3e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.9.4-1.el82.9.4-1.el8 .build-id8cec21a1c6ca5c98b916091b5328c9092d5d2da2c00ffcd56dedcfa675d33a992a395f5760fbe809libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/8c//usr/lib/.build-id/c0//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8cec21a1c6ca5c98b916091b5328c9092d5d2da2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=c00ffcd56dedcfa675d33a992a395f5760fbe809, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)::PRRR;R]"s0V i}Sq57rfE֛~$;ԹZ/{ڷ]]~xq|/U?j('&Z hK R~<i0WvaXZT}qWUT"黭L,S|~_Lv"pQ`L!ĬJ &y-鵊58OFIBDni) b$[-3zR4u,„Ո?v::W-onMJí$u+VUˡWH D]ȳ 8š\}xuk~!RE|@S1v@9,wS~Α󯺎Ӳ"П%Ӻ#m>18Osw2~ Pz%O/? p8}@5AdZ:QV[d[™ X;m/IBoླB$c9i:hߠ~JUb-b3.h@\Б4jtYCn'}s$d }9!Ӛc#Eg̿ y|&Se-{(ng73HNl,{zHP !4A u( q~fzM Q"ȁq0qe6Ɯ&əij`+Xd w{]Mޥ[2l9(T4uP)`cĝ uK 0.2`B:S (bz [97]( )JL%N$hW;/oHAb)ӟ;@nØ3F =R&c> |,rKIg1(.,M7x}82x}Zp+H`&Ⱥ#(-2HW>rHC̠P.c#U{֯9)odx$zSL'ߪta_q  ,6^;EӮ]VBQ0pgp].[%c &F SiS'ʘbV8m.~GNP,FY9Kf[p8-'DA9 6`}h!R62ځJY>Dq5W5"~l6c_Oi3Im}ͯɓH_ L<fB޲XFIlFJd).q W 9Gn*ׅe6Ե)†rsx_SGvpM!&O$ :[0pFb˼sHX'G>WF}oDL 4"4D")؇tAi)6 &>k%.Vcb,CћA#! \]<LH^Ij$Ô5ol (zG;Cb?/k6X$a9&djfxcɖVViԜeg_fj cHD;ETUBjP/M*6T>lc cxw~p5rJahtt5jr=ZG~#1O"U[9;]U6<|WlZ|3 Cʕ3J].w@Q0f$1@Q˜/z[Lݳ3b0pg@I)Эm$n֐WYT_P.Lw&q&"%j~<ƛu @,}@) 4O!n>.CC@`0I5R=WOĮP2bb/#bW 58.cs9=t(NήaږLI]slL7E~tC.6G3SfDe8.NBo;V|I?: ۢI α(R !GQN<RkkZ<,"  Ƶ;\Qکmh=W0CNCڳZW4ӊ fe-V9v {oD,mgcPe]<#CCd?LӸ y$րO^#c]X5ʌ !zZ|Ixv:Xõerf_:o_//GIwnUb=R[YYG@5o>_:*9BiT]H 2R;td~xD?w-խdҀ/r"6]yPʊ,+gfzkۿ%>ޚ XS,U4f3!>-_*NEϿgr=Hzb'R#ױ&½ OK/_!f16P=3] )˙.w.!fm3/A"srWR{u&ٗpAc5IZ@ .p^ɣVq 0&H q)`ѱX?"Uԁx76 r`hD"_Ølf -Ym@[mVCc3~qC451)N[_UlѪ^8leK`[~|1ĈlPZ\ eOyn1dcٲE UAaFD**5Ս8!s0pk<^E'g'bI"t~%4҉덨Pw:yH5-~y59 Ϯ.glR,2%k_ 'k]u攚Qr5'] øIt8C./Z3Q{+a8yVkO9;8C?{LIc/8,N~Z=kjK}sE+cB.UuE8xX6bAR;^= ]46=Y%زwR(0#kDuwgJC,K{Wq+*9.=n>P`f8YJ'i] mO?z;q[+qosOliیS#R97d֑xH)L&s$Sw  7p N,Ɵ\~k}5!QUAH=`ʼnb1A!! P0T]ыq%A> ~2}-B`x3N2꩒L^7*"qVCR2O"8eb@m=\0S|,3ԤyA?w;$ p<~6ځY:qcˬHd3v: s cD&nB^]]& ?a6u@  7WP*N!O19v+VT6fK̼B\\kULr볲;qSi|Ҳ dpeiAv7YVv2Cq((3F%T P(ѱ]-S26Mz][gtg pSh𜻩#omsGT446*%$nL<^cOyO93#hUȔxזpT_=o@0${b'kbA+K2r̢#;E4v&b B"`T!f*,2 zNj{ӷ!_,A8D%^u_mnW#8Dr?WlrLiS zFHyX1hmN0mٙ?r3RFSw =bp:6x\):B(ׇhG=ƅ0238`Yi兰/x xb[pMV `RݍQϮfKHYBvuZ>iݗ%}-)z¿}Ἰ0V /&8DBTϨ)f np>5F];>]qcMgH(Lր~p@$~kaS?N` Q z4>&LbLY׾6ґx*]G@9GFXT_A|aNc‡jA̡qJԇeS=#Ak=_\2z/8x,.4EH\A4 גb􋮲pZmҙee':i ]E&toԀsUwUDJ8[eV_(-,VS=;JD _`*tT|k3nV.ݾ }Kpzz o_r & [1ӚL$_^* ^eA{ł5K |/PkIt NaTNp,҅"1eBA:L9NAp0 &Z覂j8xK؟Y0A]bS7m/G$~@&@CXG=us/GbP4P,=DآRM׬okHY 9LBːӦܑMB w9ި,Fשڷ#v̂i4JFA*QQs5=eeOY 9jx2ep @( 67}8r#a޾ Y0Iڭ=`5xvEz!͵3e"psW/%"#_RUS%Ʒ|WꕶVo~d_DdP&y]ÿ1I5=B\*>y"iH{RE#V&PAcQ6`D! fsc?gҒv23P-4lG.ޔii˸OE d6[!CY4",Iח{=92YVWD^\LGFFC3!ZIST5K ,ܴPU+ 416,$n!pr=R#DϽ@/q D/{T@ $\ʥjqǗIy^*%+I3j[@xe¹#%+~s"%Д^r‰:1^穗M~iVw/d~EmaEr~3ֺ;/.)@5sG>::j_B加oPx?lR=qPp swzX+:K.tYӺ_g&W&{Qs6cX_` V@>o%fbښlRJϲt=S1 osdPlܱjiytH)~& #]?2z o>J>$f}BޒT~ `S tǍK(m)f/^l$u'sFu(j}QKb396`wB Ɓ"ǖv!2y᫠ =/^ O{#̪_rw 5ҰIO$#ie9JxFQkN +ϲfF?Ng7]:ΓCh?gO=fNzޜ{f#*~k&3Y{C>F&5;`톬5T_6" JD; :[ qcɕ.YmqR~JĀg 3xM]XXOМ4S9\IK3ZX+p2hǦKwۣ!ֳ9@]GOU߻CrURm Y$z$^l*|9_e:QM]vbI!j}5d.ވj"mH,hKVsZb˜2]grC=$rґQx(#cCn3_IծT"8,G56 *ezozQw7?-S)l*Q+l6gcC'Wxǁ~7"cGN\)}Ed{nο"*}ȴs0)M?.~^c[>U&,v8W/Ju-=0ŕC"mS E|&GNca7,ߕHK]?U.;n'惆o["Τӹ`yr>?-lеꍑ/8[/2f"ތku?բ `KYF)R^qF)lx_1 TOQe)jJ%Mo nw(#euxhN%#0jD @ `o9FKX2HZW&Ō E"%cdžK^O2C\5[)vޱ/yYgf[Q;$ҚT:~@h^|6WrJ*R\B剻:ы7j`|&X/8O%WOFAN 0}CTSP4&XKh2Xi7cjҽ{ s52i11@%1.z(Y'rԁeV/BD2v giתTH 4y6=ӤGoءGA&2&&T糦2X**7|qo;"m:4EḭJ\򂦀hAЄ" *&{3LI~><2![n~Ɩ0"?k@%8EԻfWё}\ um?HVbp"t1ޕX-[h^ü3qVCek~ \1B^)cWz#HU;o|^đI'.S)j7]+r[|ZMFc3 u\јE(?;_% Ѓt99ce vʫ̼zA $Z~:;6cZli#oV}{)yxT۳MBĘ/;1&{]ky0qC;6 /4T߈ Hf'mXKK~)x Aƌm}R!=Qݴc&Qigb3SvL̊;ʊ4~鴳.jqҤM?U͞+Ch|Qc31љ|[ zIb<Hg̘y~^q o:ŢL,YUEl&'Vl2 t}xxb-Us ix33QN4Z QXmc-yҼ aXs;PDq~pc۶coO-DP0DӋm>;.83ŗ|t8ⶭH ltO;cU uT{&y}g"u7 I`z)d;$غ/_Afv+@LxXj2πg W{R5IQ;&.#qcgii.wrdMܣ1Ӓ9)~l5b0z\Ӧٙk/6h lz{sWpb:S;%ky \Q F=A]IvDk~H7q/ҡHd{i;/YɒPvizݑ_W^1eh෾i%HKCar xUQKiu c>0 Qaa-ꣷ1?/ꚮPuDft J#Wy^]Q=쯆R=@mvcA aFgfݑX$՝qGX)WOc!Hw_P*$,TqD5M`]rnfըU1pj91\3~4дJ J=gL5h?rެ !%^+8~mqu`FgNpC7T u0+ &E9&53G(%+P7D[>:Fht_"[$5UY)[ݚ=r4^0m 5>-Ksa.xF?{_oj To\$T)o}-7@ U"7V yRn5Cm;bxH)(&-@M'tpn_s e2*j}:Rp$jS_-r{E'R,J`3{EU(ՁĬ̓~\ȮAW#&ðXtyS;FU}iR6Œk)!V MG P3<=XԩF\>! eoXCTl hP*ɛ.Dk(Jm"] DkN]tQ/{=y~nH0 7x;^FV[̎Zu~Z96) D4~r-ZMt!X~L|U 33z0Wn=꘹ to# InJ-K/Ȱ,A\Fw(:x)]}L+BEo=2c\lS{qD)`\U Pb2@s=hn#þIw|c(]XDrq.s} 5ڂMD NsN}m9 ckHR\M-k3eG'J~-.=f.(?iqjlk aYL ֔ɜ@C}Ӊg=(zt 󶟗qk}:0}/#Pn1ﴧd +Wm~U,fqNjecpJm CB$`D-뀆VF>Zk:Opup|j»+(ꨵSA.[a6:p-S[@`SFAFr|,0ץwR49vSev9~hBMXt'r[J!"Wpc Iܻ+,?,wT$+ZGSs F o ߒޜeD-5~3tJF+4[T]!PZ5w*D;f1>ϑ:&5X|f3F!;x0fpv/"qopc vc߀h"qͣPtTQ v@sg !fRdnr~LԲ!%>_د){Q#Cq~wX;qPXҶ6;? ux GR22r/f1LB1viǹ;X!Z3Kh`Kx>.' <7J3on-SPFǽWlTW#mwúñϷW&;G4|4"吢%IJimS|XR\6>ySBZ}bz{Z{1fSQS^i+*D^oqB`8EڍpIMbv=cq)!`BaQhG|i7'MbFq; v ZQPkg 27wkbQ&|}ݒgjl.}FçZj?DubwŪB-)Kό]Q.!aU+!~wBw 9t5|4HlJrxϵ8ܒ.rB0dA4sAy' I 3(k,֧C?ޒ\*Q;*R G)Jir6Lա.ʇbdw Ѱb'Aw {+pO9xP<Ә1"D?uİ 3%<$rBŸ$H( ~d.7T0$ti=%_ Mggﳽ4[$"ɦl0kK0"oЫN*Oig ϝYO뾖v8g6Z:e`gr6꟒georq@K/OAu5p~Bx&u![@̀h~q E-I+Z>:hٺRDchʞ'DXmN\Ҵ]V%uja%H2)f[?ik& (Q {ih#׾!yV=h-T+;9U/RP[>xzi('(R5JŽ~.*˗^tnPGmA^OIn.6 4ޜycYz/'֋cNt"[D >$K.دD^;k͈D~mjwW37"not4 7ˏN5N_3ɦ&qb~JyJgKPS,\iw!Va 񁨤dy{rEst༭gH/A7BͦmQP?@DYM s!w>< g`RQJt0H[]uyn&@CeUD߯_Y{v>oHC||"ׯzz a M{#02JpAV1x",9S 8:C7p#Cj/'kv`;WtWțK>QK8qE*fLT$0øɢfyA7,{ۋCӚ Z$ȝ]@cZ&3 T6~,F9ݥRP1QlنF #,)?Gpvj ewxz!5q.uU>?~i"fk%# |9uyf蜝ƆA[#Gij֤hyS`4Ī RUZa(=4"jE0anHLG-!rZ#:JOۤ_)UEmF+ #쏪R'rQ([҈t[mKSA 8̗h6 4iUH5]; ƨ/=v;x~<ŝ-4mm~ڈ(O?UJYLp섉ܗqPeˇ xsl,g.Aŵ>\~ I+0sAԅN=@ĻKQj9y]}w߫63yrx|ۥy/߃tz8q^,\CWWdr/4%0ƃ?#@=uaN3TC~W0RCq™$M԰;"7?H Ji7mFw~i(e5}Ƀ4{;Uꈃ"'z7xK*K9šv\ ik#hY5cbįExΏS{oy,U/ۗ8NeEu5 ƹD~B"y/ƟEKt.*hO&dүZÃ`g+ؠt1Gõw+or_P֔2f9-ԍvv1>1Q? `sT߉ 2u?M /L@;O}uY\z40'<@(Km`ojQLGAyQZ{P8%I]M- ciQlIȚ줂ZǾjxȂ=LsD;b:r2"nl)؈+ԋ̨#ܪz/G !HgTjW7{m[%LPaQN,Z/ff1g vh*?ro.?)*_8nq :dR E*-s#iL2["lqx;ON)V70|puG}IЃ6rnآ1dX$(:T q7$,/I8)`"&uOkp0x!05tR/2: 6tu/G[j]"Z[-`HŽRZG9bhMXl$h[ C}H;k]#TYN_m،E«M6xqXMvf+ }yGX7]/ДI{6cKG^ e@clBA׵c틜sRP@/6㜜:o[ɐWDiXi @rH㢣woS E_p.p?@J{!alludԜ}|jTlhcS11„޺: pj`)' '+4:$sjNrs-s€,څ1Iצ%ՑZw|)4#0!;42.e7P늪؈6=md$+ ,EFi%HD{:?*Y6*w(y?=:%KP(4L{[VۍTKrWc4U9'lDí1!$-{.[;n1 Zz<v,xˆDt;Pp3 @^x6*|,w)7SUAg99'G!P"i+ܟRa.+S5b zSH1X^A3xΖwJJ'+6j"20}TVDCv?Ue{NcT\Zr]~|[8my$3EE¬$Y*=A\31r 혐=+@09"8R9f3+(զa.UpMam%= r_v$3b1'Tl[*C.[r; *ONuτ덓ԛ븽ɞSxH"LJؼQ:6ư#%W} zr ؍^4 4$W>@:$'ToYk/R_kshψԴ(9e_ᧁ$Vf!xCBp5 [@Q@zТѹyM S;%$".mFFu+T''ڎt١vax)gaVASG.ޫ;ll7p&9 &˿12р2D $\<wokaдMnM%y&P&N±:([,)/S5O~Mnk̉TLN}qudU_+Ӥ. 6גmils:*ð{NGuQn&_f5oּid$Ez ~_9yQ"ۙ0Fdwq2A2f`Sܵeu ͇0x u^jCuE? %amEGh%B!V_Lɮcר@?$6)E1P8]/{YdžZ(qN]ݩ|xD7%A, }})TJX)!l&ž&cfsN$O|b)Am&`*=ъ2kHVX0" i`P'{V!ֻl=j2;*RfZl 3rpH%B[L-|cw(?F|yVԵy&=X~JJ Έ4*26jQD"-`g\=Rh,Y 6@Y7Ym Jɠ_H+ 71 )㐎+ET[S߱"u+UWD!<#oa9 ̮iٮZ hT!䒹-un5R? R]b෣hL yt^9' ڑіHU0we<Y]LƢ?Bj?F,sOq|3M`>jN'5 堏-bDudg;zY'0Py8c`1 PtHVA;PcǏ%)6T2Jӱ7sҢzBkLY!~33 :+( h6V]-kL p4&PE ^c8tnekRRgճuE5׈ھoS.-K-ݚ"O HnvxFLEl7+g7TGbsjDuՆi8Y`3GE͇Is1kBf'@WXK]JLTEӠ,ϲ[x3uTaSo\ \dtsRhJN D& /}Dqs#bR pݙ1RFw,s%Q窺:@LݣS MJ˹he kxwn )wT=pAt1^V%e5ze]itI[B YKnT+5kU?Ͽu1&(pu܎XVY<&{(mmKS,<`#S@52bP 76Bm \qF'ƭYc227e>Ub܀з2G8@%B":nZ]4i5 yثxrU ̊pW-X oMDZLRG@xT9&ߋMS)fJ'cGlIuf|<37Nv(א`T9wG%oUme0oX~Y$^B`.z&p꩙!߬84Rln5$~?=eh%&sVzΤߞC$35n[d7f'f1mt6m͑H*|Y\g>ݺn,yʛC&n t4O}.s|L/_WdMپkr.&R "n3+*T)أ1^r:CM+TOa8oՌ돦4lD Xb ߜAX3uXќ x乐 mJ\ lͫOS9.J<7X屜ÚX%x{f) :qQU^ T=ygdW_fc+w‹x6?,N 4H:R%~*%= 2s Y\ 3nͽ=!c۾RyW\: Ej]X%\93+seX\(E(-;po@ h{Hj}^+GL~xH{GyBʾ; 9b6RP>}; +:TwG1)і_1K@=GEIa >^y.+yf A+u5 !UQ^,?ɦHU-.E@ 6+#m 9A6ci k P9*xb ' =;B*KNݚe2!D>Wo {i ЗwCm\GrBx9-!˗60CNRsq*{=&]}cj\wҸqgNV>D4BwX2_2x%gsQu;|1 Y|WδW$]bE2Ⰳ|)lL4Obr[1 b $;@>`u>o޲T1jt_ayt!|Ի"dz.'龈bc-zоwүPM K O I!q%z)B0i*ꃘm_+;S:n|v# R'԰a*"!& +-sshC2̐:I22Vة-@o`fsL@y8ScE57O u՞њl-s~si@rfr!hӂ^5P`f>#C [\A2;pX775?FZ/qYh(^E `<]iaP$ y.'8Ē/="W؉g;AJch:Xd5sLGX SG݌+s9WHdfb g\ Rb*@Zm](o }߭Vi ֢aR;͏69El&֑%YZ3|"ujwGr]<.Kj'qM*"' (Y+@`#wJ;<<$ݽۨ< x)4}mU F|v~yJn԰~jrecFu;}9hjW最;b ^GQwTb.z y<ϾT̀CZe xr(%d(qˏLcfv6w -9k 8V}I|mAcr`߃=3z]3|4@:Q٢kC6.*C_|ߊ&/_#jDAeTgnKkH ~?'D,_< r0>#a "K%I=x`7,l )I0!h&L,RZas >mSS|bVdrlHTRILhsаv!6o 'izޮ1BoU)JBLUBk5,|?g9ʷ؜ih~^y[;+fjiZPк\71wx6P~#gQInލWO-EsJ$֤!Td[B.QZgGCsYˡfPS O^qZZaXGF "J'c ~nf_(S ?dF*R%rbI3^NQ0]{͢ 4f]۴~>u|Ⱥwj1n:?yݘg\R |ǸP!I^i CUЀI6Q^\(v @bأZ7 .iӈV}CȑBc/9{e_)2 R"B!RT88 ._ Sctbn`]dKg<oܑ?Z<^B"XLBR6v 3U?[?Q's|#yV9{ S@M lBh V3J4hnTL%[,U~=@1}ӗ"p*+eń10/0d')Ep8W EZڴ'iebV1b1anG[*R\`]Ӛ^u{~;_5 vˇ#Yb-ЈHF"Ejqom(U͉{ 9]3-LfەYof7?O X.y_;0^fM䊊ɪ邊nE4\UR}HV(x\X^M%D7W *nӘh;( N#.x\JJy9MA|kKdrJ}8jft~vIяxM;6VdkV#VymlyO\Ӿ]Z/p8g\9;4z, FOk6]!ϒ9dn Oҭev.󴳧'dGS}`CϤdi:,4;ݟ /yR1+B/`FOYR@ϛi#zvc-f4I뾢%jN>پemMQ 8f|plܕΑqz`p]E1Q~i{> v! *>*a]Vzzr\H1ͳ}M.AFY/LΩZ-ԩ3aTtl()~R߳x+zd֬wAR&-|uL^t*PaB -k)g[@$M^].\ɱQsu ~)o4{Eøi>G;KVۓa:۠Hڗк/k'{ >C&?"#[ynLuA]$n ʲ6Q!rBQs4 \I2= TXZ@UX9̬a H{swD5 /*>q{OaSuG-QʤyD[y"+X׌c@ /ݩ ?ء3;.(:c-9)qH>!!߁Aݻr9 {BwH%gz,_ً#;0HSn#ZVR"40L(Z&dUvV] i^8$43U .D_Q@EGff#v QJUe)8|gNv$UVn6uq[S"5c- |sDɤé?VeDn Q]i5y2 qmnRО$V>KAb@t ?Jc=z1ONf r%ȳ^2 zvuH|i2?12"H:S,AATO'ڗΊdy{9e%Rk݇e.gRh}l #2CI-ռA4g]41Ӂ VYNB`V{vb5@{:tbG|ka%0JLQzs3Aݗd?|]%/O)%,,;[7> _1DX-GI^M)o^[0Gʻ% g7k먤Ȅ7q mc(i4dЀ 5@;%&b]'J]E4ɤ|W.'RI ~mWڃM g!l"p>y r䔰(Jt: U ~/Zi FaMѴ 6i,@Q3H /)6J2RV2%isq)X@DxU6*/-g Mw-?m1,.R:rFzHV#=#GnÈSnUX3x+43P\Ƈc֮Yf@ -z}9]ΤQzK'(ړESV6ho-&OYadiIHTlVa^ҸzRVз)zv>Rȣ#ܭ#b&+鳨 o0D1jY "E. gp(..-_ȱX\tloTT`nZiڄ_pէ0GaP"_O`#e-&U3qT@E@@X82\|uIT&7cf(GEeYIӤ\qJT _!:LGMxAvxjr6(~k -d`n\ƘRe& bk=pF€XT'#cEl?7*$W+hu\ }[$H[Yo'"nH Qp]~H/Tn]NR<6J-Id^{vxLaMj4gC)R/34,2 p Eh/voEjw-w\%ށANCFALM0N!_$\3%~;r:О]Q柳"][?yFN\^8-fd0NKPusB.7;'_#7R~Hܛ ,Y㗑lBYT~Jk?H4TBٻ?PhuNPysR;{Ys;Xm@V2>`#~$<-TE<t3~XJ8Cr\ 9X^\ &@ba&UN6:L?*Z T h5_o o d /T^wTLL5ib[>s]cy6N5r~POǁ(r!̓OuUiXQF}W6p {{B)ùlԅm;LCP@l )c.}eE[\{cNVߙ𳺈g+,/0~dύ%gQ~<|{ DDd4\oeoyHsl)ZNr yS5˓N] nSBdQuZ/zwn+`"=48 ww2OL:sc Y01.l*{/ P#vIj3" \Bh ڑr4aJxwb [s94@/I];o.xL%14/S62m9Jv>yknV}~q*t)V;`p=¤{(H{ʆ4ȳ,L4ܻP-F/K+ِѿZW] dzynWji7dbK( c=xI d9]u|)lsw.ʹ^$3jQau>k4tj ITQeζ4ڃGB'Se [Ÿ#y~u=]z .T2ZlFC_֎%R'U\Rf'hMAԞ+[䮞O}1q&3R0$aRy h$S9 g5Fo]~?v^ n `jzXcJìȴF1k1/{n Kb3z6H"'7h dIwy.Mż˧TW- @O?wgRnfVGZD-J*c:%֡G˻|RyvMH[Ši0˶Ԇ~HYKΚ fW>S6IF8"/lqo#ۗKijcc;u^ F@LG}~$Шqkm#etqayn$GmdVN=V[! JV8!/)űjL-$7iAMV ,E#[eӸ)rd)}ټo 2vN|{O\Ku8dE?" 9LPN*YwGvjDDLR/x—a TkgLrQt;KP Kt_y+Tբ>J VAz[ } # v.Uwg5'.e轙_7 1)Kkق(vJ?r .R5 Lv{؍XRRPv0&[_y o*l&%_@ιI[Y41 _ʘbM&ە:R6EdMmqdb`5u"sC窰Td!@;^,@_ AkH<LGST_h9~S)[CK,c ~Rܽ[X%<ӿS%K)=5Ja&évԶ6[ ]6Џd=ܟNa`(⿍KI}}:VRQƠqO[y:WhCIjD_BѼ4=C8zml1xi:K(0BK*!ay4uwoÝE(w-M-t?vPk?UW-tu_>4s;;HXy6+\6@M6$O>v2 6.]Jz^u-( ߍhk 㚸sPHtnك[/3t"\U-nߎ!RqfP࣠ϝm3< 1>_rT Uz,j'\w•.9M񙬏EA[2mΣ33*Op1rHjϪLCј4n /x~SyqW\;RJh*v(00hP8Ck&}F$Pw|퀍ص-8O2}&=? ts28pr:A^TNν{OV(}; B+N-DI(w_g]+aܦ3^Cwq%tHB?\.(G]'N+K_ڞ$GiS@ؽBםOϸDkčl)lxdoƭ y>CQU+6Lds!``zZ0rI5Ήp.=!b1sÂIɝ`RT)!+HAu'؈-isg m䜦4 #C2`-s )Ioa%iey:q*C $ܬ+/l-1e!MIcI;Meg;)[w؛45F,4BQWA{S(nf,Dl3% "s@f0L"W™J"7?jAA֧S1#70~L*͇ܛ{R8v!Ȉ(Vr ٗKk?d4eIASeG&aB !_֫eǟ3@j ;0-QqW,\iIQG V=lm|!C>S NdZ &t75IK@R}Qj*?{AN&'}_ MF_W!2{J,Lr8gfY'z,1:iL_xQ 6>ʿjc1u/vP5@%c4#}vYZ e&[Sꬋv4 xg4{ 3dz #\1OMܧA'J#D'%Ć&|\VJ @om$_D\NqM izpGsȴz*Kh UP_ë$:gqn+Xf$U,8㯢'~t̥:cb5IϏ1+1"SXmVFcVZFtBd@KIx() ~ԻAEǰ揜#C4)xIʪvzV$>1o:PEQ V%#Z-A7`~dgN`9MM \X.bd M,N4d`)! BK\eAV |Jŏ8_*>(v[ȊyB 8LG`Th]gx1̖䕾g6fjoqW\#IJ(!ϱ{[^2/2t6A,2/eQuh$C֯!<9y[:Cfﰋ_m,BJ c᪼}EGJſR>B_pܽ-MQKn4Ơ)]c(`BATGй1 R88mP/$Ф&WqyJJO_4q9Eih|ʂm[~<OθeGT:GK@ \AtϰXLLZ[y4ޮeL(7!R){@beXWJXTcdN8oq QEh>FߊLyq7iDk/ufl8%cN-4o_I걨M"QJ8ˁ"(n Ԇ:e} Ĝ hRZx 5IغS>=hN8>=ߺr%kMzM ]oWW]͌~RFVl`ɜ %mOGVecLpM2JLy Tr:{=7@]EyOI 0SW #e"ydat]󶑽.,="{ژL( 9KktƬ }/'TRDM1'ؠؽxcTK' )yn8f)N=U"XwE~DW'3R)aQiDXd_+myArMUvEĭclUQ2XKgC4a"SF@,%ԡgs^|N x %ITbW=\< -u2K}m@B5捓9b}_+u9P\6xEv4rsLP8q@XJ`/[b3Te pXA9K'E AeߛmW< Ȏ9ql.5^P i LZ(J7Rj3JxFvGnW6/+FLS1Ⱄg:CE.77\ԫŭN( /DT-RtdWR_`X6gHEay_i`*tV$ʑ՜9yZS ^lWۗؔB0IzŽiz=/pgD pdL&þأ)c:X$2 g?I!\NYW!1L@VHzmq2V7*i&?|*hYItBEgȽGrHӶ=Ck^Z Qlx^&Ӄa?dg F0 `79dٍ' cjЯUr{Sqh5[fQD4[83\ڊ >E Kc?Y:)e]=rS|'yv YK=8o8F^?>ܜ&::QX}Aqxx&vfz"+"Ǭ,f$RԂPpt|A)O62u `QzdG1il=zB:g}[|(m4: @mmy%)xnR6gy0a 5s ɤ\ձ'P M&'h߁egi6?9=OKר'^"9vdem }UIz8^Ѣ[f%w[wIqUxW:nBj~>N#/LJ?}L_;ft&^顪^K+}3ֹ[N > 74 XZB0•1鿅i+ m<-^* GR1 vcTίR5|>hZ ekXR RNQzPg 1hbgݫo1T(A;5ڿ4fxw=w4i;W:uc}Y%M~|}w0i:^Om/f{";xo&b"s?;ߖ U uCeUm[-@=9j_\Q-tBE.UQC`71}߆%S!z0wƀ;.^!ߛO?e*D LOABF';v\ ๅ/U[5Y4f-UCe&՜ Eo?:á&౯ܞ" X.:=S$;b(mnd@@.UUa\|V,3ed5t3ih(g!/zz۫BEyn|7i iM^e䚰/|q͍cBp;3f^B WdUfeڰ($!kѝ[b .pF6Dq1H5y7G|EDHp^?Ql`*r`XWTgJt0᳒ZM#S2 Tp01J%7:+{ }t(EaM41D=hyr+U_lt1`pXD@&&3?r{4cr^\M4z>JTkE}Eܺ˘L+TKxPe3nf)h L/oʍy#JD,Wv{,nqJqD"veZ$0P8zw {95Tr*xX"wRA :1" 6q +UdL}KEӾ}i_c!{O{'XHKGhq%!Z2"{w±@{`cMwՅC"nG#]l\cFM&AZ 6twԞPz:  row}i޻4M r%֯M|M݀ъ`2v-ȼMӧtQ4A9*w®g 4n|`~)i8Rrb8i8zH2UY0~8N&u8?FvM0ɴ' J2߆<S0r J=,@Q_}}C}ß !zDXoZr72hP&6IaI= 2G$B(Xoy>Av5FJ!_jRC &{0=m[L㌬?1V2{` ^Lz@`1}{q.+ՠEx`ȯ7r6:'bv[!f̴G=+ i#0z ؁lxTڶ[ +=t{7ߣ3/[ⓇjWn{$p4 O+ bClOh{qc!r+ɕS|w^䚻Uv`zBJ̮hmU{A`81QU#SrU hB; ?z3֣3JZR~V 5rR5I4V>uqJ V"Ǵsc>^#P;S]ƂA z< 8O$W1|"Uv XCgYv="@8پ+V}F92=KH,Vf1rjkzE$&^EaiY~FKY2zanfyFMwwOmrM$lZئUֻR&4C!(9OukMgbt9xtF۸91w*fsԧ|e(# V0YJҔbq?n 7Z xU9n8 R{(b(9 Ǖ| )(nܣbiQˡ6aBYG 8[`>?v^OTiSzҔ{~cw!9,Va=|] JH"kN|$G g3#ޡ}8ˀ6HC}G* k{E7hJvxYZ'p+ Q )aY+*Ԓ}zͥECSc m)[Rռχ)J@Ao8'ZW樂BiWG C)8V  A?"I@|(=M~mٻ4&'hY轄?f_=33pC KvF床O=V$(pOJXZ'%dfA( \6";)0rt"'I( #5bRgᮺm9Ʒ҅r㵖C:;6GkpMڊXp|"u\bYQMS1m}1ã ,]7tsȄ!7^~sill,O.\obG#~z*'ԮO9|0l)h1zif}7^]Y?q՞c/dVMȡ3(tHK>T_P.C muMCƁ"4%VPm1?_G#; &1K/߷6zq La% #TE^D13f0 gD'uv#f[(tZg1hg9ͳK!bN5U:ԗz)[π*RZ$ґK4YS&•;6߄Vg2|Hַ4E7Hf$3[RגDDzv>/PDr=?eЏ~@nKXVӗQI#jXCcfKTkzXGpKܙT6 qs?f*;{aKEq a_dVt-YlJydU-ĶBV+3Rxc&I^7}OeUމ҆nfJ˶dSR[u,kQ&3W%GkB+[f3Eo)^RFReYb7\sE @{W7|ęq׻aP>-ƕI$`KI7شS?nM}~yJ*ղRk;_B=~US"d%+ UK]j330?KlSVed^lS1,WJxVxoZ-VЀQQ%~EqqQa+t'/k?"6N\t<htWS,a^ WJ:',an>xl4hG)N9R 1!ÔPIo5t$0;MqӐ2CGeKs.7&?5+ŖU ]sro3l+S J cdb ~(k5L7;+ 9>_K <k=ŵ$Ղq;]ey#>=0z!4e` ƩJ)pn`vuVQw >#z+p=c<#(N,R0UrIl'kOd Ks[ )"[vQ{ xa%~TJDj\Js恚.dei;.{7+MWTB4?x>'- Sz IJ 6geGL"`$s:BoA<D)bW"'lÏh_\JdzdžE I\ qU;C9ɅH'Y,-6Pb45vaJV* \ G̷Ag﷉3PgI~0rAk+REH)3 JDmA,_&^BKϳD{I6]'U-E0嘆Xe\%)\򦡲u;=$V֘.Ě^HExVG˙[*$޼N!C CÕ&cߛ+Tm48E|-_wY CNI*WaLPJHS1v4ʔ LS?;> rQtp uPGp78?'pCRuq6sSꦞMղ^#f'WL{R'ut}I5:VX|a|4xdhN_AG+G YV5x$[}AREjIw-{s)q:#՛TP1CY,Gp{rb|- ~ R^*N1dLֵQ0KRk!S$$wXD= LH`.@X$0MCYpn]+vCML56/!`

IQH|3Ӡ;އ on˩?j8ΕQO`5߼ =$ 3qQ]*A6db~1yj\>6eRML)VW ~dZ0jmB 5B"]Q=" 2cu so6?t7ي2l-u/3]Dg_\a?jzN0w/42qxTO#Y\CQ}aT@EO&BJ=%%\ڇt i҃p8q3R(jil_ hǏ7FjYoܓl/΂ B.x_x|Q*2٫F#|{_ Rz$,@Tj_,߭Wzh=M`G6x νydOI&TGћO^b-)GF|/&]X  I#,WQ>Ʀa3J6=eej 䑿 }WGDag}æWn`Y<*heבA$hΟҕ)t=4`r't#Wz+wLz|S;8ϊH5J`:o6l_~-jVPkTO2qBu2(yiss0}۔$Fxo^7X4cSEjmx550drP-*ɡ#`Mb.ET;hrCHO5l^>E `=>_ W5@$6௚L׾aDmY]^Wv9=i 2`!OCK Ӂe^HWWQKM%pVm2?|O1%S;7#O~p 5D`J]KWi>XneK n[ҁQګ&"E\>.yMҡQsBcQ@EE<^J.(_wN`~rj0G05_ǯQa QlfqT]a0F/>FZ8{Xh\~vJ8vdߠ- L#3:MAY7\gu99x7E`*x4jE:Ȏ3/m@{Z̸psLF o[ d|.6i#toQc |aXlwR [q$`Y&Ԕ>j=y b)C:[}=4kݨ,O*t3Y@X av% VGXgq_z;E/GT]nչėP#AIeec]|| ې=j5X!M^^ZcM[?}~UGʞ)k9e\f?<?㤓mPޖ([5 ُZ!KeME+=Eϻ&أYW ~0ЃPEJ''h#G 3t d, bS/Q4 l!Z{&27%bZvA ?OKfU=~Zw&Nؽo+ ^pķXm=(_xqD>Y )/ƗQk* *3xRCiʵ|0w`:+'rѨ }a4wu_VbN F艤YsPVX~I,AiOaW|%V/:b񳐓wQ7\ M욹E@8ọ5ܰ',ӣ½;@slD"a+8)뿢Wpٔ~KDrTmqd Ad ^[!HoPHwPyo,)h `ن~E1k+,g|29̜w`WKϷVy# O@B(AL ;RlQOC-A&[a|S7cF];Zž58luWJ$g`ߜ\أ#ee|>~အ3*\;]jZFM_Iukߊ*<HPl07 2>01LGjeOYE ?t /K~ilo7m)74SφӪ vR"S_|IS+?6wK""aKR0Fg I45#Iqп;][i@nɏ2/8+& q{/)ȡyYR{QOb.:= ʰ%ڼVg7LJ k׊.{;56 % 0}B; 4bB 'C d K$Fsb?=cצ9s9 Ud  ͓6!H݅5F3gV,S[N!sbR |+,I ?Wq!0SIjAIJQ3a zcc,2'68cM9C.0a9 Ts|qg7TO A}W2ŭ3oH,^~ZHѦ0P&UEk%;^z}av&h@h~>&)B]EzYuYPLM{ NXMٮN˽ c)_SkEw(v.3^N0=!vy8+yXqg30s=82F:]<%8ܧ8=1H8uo}A51sFK9[Tu)s]~ w#۟$\RRDx⃘t)0E,b.“4@_K^ dUioD-!۵1Y;jEUTH\'sN0 _J7_ɸ 㰨T` 9=J^ŜwG#(!F"3dҩ1#$a<bb 0}{:+0%Jh ?Waq)(jt]|?Pu$-tR,ƾ֦"]QA>w'rǷ,VLĆJpԊi2."A; R{K`=ul; 󺋠RL6Dyֵ_8vC$"=QGP菌۱Uwl/~/C`16ѣT>d>>y\{LVV_2S5)[h >u LNE;%!/O9sA :IW;^܃Vfeix‡ 1geY"Y.X퉹"Ï@\,ɸ&toVu<-oͱXk'ف>l,GS΅"enв<)ZKjS"OX!/ ~7Aw˟>!y|^D`0.+:J_]-F1!Sqyg/cdK(hF] ? sxm1K6}`j[ @@)IDj 3ySWN*#_c燁*+^X-H?Dlˠy_,yZNmśGAQ (m|5. *đ<_p ҘjEӆjxIKi](ٹC1DVm`yB E@g_/j'߹ŝ=Sf5M :4&R*?$eq לqumm3?<%5`=*0~ @Bx.u̫E@L.u=32xo~Vєo)|t췣_\ݐ!s@P$hIUPͱY͹\K}-Q]1Sb h/> 4^ԬR؍w-oif'>.Z:"| 4l@ LYVmYf0PV82XX 9K .q 31Xzńt GDce"N#<pa4~g`¸;Bn{9jץddY+]pjMg^_E&q&I!=eIJ oM޲@1=Gf\52c.|j*LEcBEN#KSИ %\7.nyu[8SvOYWMmc FriqYl:=O McvO=9 ~kP\&tӼv6Eyf GOSun_1&2|].3Sd{UTQ8abMRK ]-mGi c&,*6X6_0e=͏8)gMҩYHxu{}W+=1]DA`[]t|=@_D#Z oqMBIVKBb_]V, Z3%>,9`X:X?,(ZC0C8qg2YcZ 68 kJ|ÒY<,N,Ӫx,K2wrvuG(zx=2iZHAګЀzii"WXyԾ]NH'-f:tlB?~+9rG2tcde,A&RL\=P{;.UMSKkqb(JkKO }!7?}SzOis_mmflJ|Y41Ŗ TCl;;T(}Tc  SB萩q=I8!bT"RSB#9Ub{GRЄ"t㬾{ AxD<ʛ A)Jێ'b8^odNM`#aiђISbrdٜNuA;c׃Sz6bhf$Uu a,_R AE8r-a$d}7"_@>96}gavg6Χ,-4eV%M > ] g ٱeX-&uC}lH뮽_2z0?sWb%FfGHonTr缋7 i&]J{l&)֞/. yLw h[|e8prqKBGP}j,2 0 <+E"{Cf3|'@W'Jv^R4Y0V'nd #1Epʽ1[TӥL4Yex;Bm0#vvQAggJ]69v2=Qj;t]z/kh..ڙQh:޳ Nbŋ1Ay6kQFc6g \ǿ2Ytq[Va8g'e)mɴ4@]zIӅ*꟠-:+|6+СlFKD7[m.⨏߲&+@SHq0а,|fKAU&^ Aޝ"qz3jy;mbY3ujUK"^Z}*?d?8ћ4FMWI7@ýspdewE&QU!ԶT4;/rƌ TmJ+-oZM\ÀG7?͡8S$W (?/{Y!Wk=oۉQJ^諫Ԭ{X}q(pK%$șt'=-7!t > t%:A\QoT,7s@PZ)[î&U'"4È"Xf:H7Ѳ-1Yj*0.+ɣ.(j48NaMp,wܯaBlܲRogΔϘSQ,c:%|j_4bY"Hnh1^#kgM]O/w;j7_ܰ`@{6!j)$QB"$d;hL+ KHTiQÿĈ+ P>L/HQA`i}4&h*Z#?8w㶇^vn?}GR~[p8H$NJ }K$̻RJ/Wz^f"Ea\*:R `ŋK!xqƠ8Q\2p#B4<yJkY BKNf^úg͔N2F>HЀrdC DБnqꎖH=ϫleUe#!7Fmu|Xfd$>v]-LTO_=(^̍uu?Kj4ѺdQ1!h6&ár܇&<s=.Ism(-XN%6OH!׷5nT"Xra*ɶlXLbohVITIqf-`Z9>,SwG"lqWyg-]QI0ՇIց̰Da%#CmϤ9QI د+ߓ5Ϻ61 t3]g/} p"uCnN=K{kx榜[*5+~־YƸf4%ykaj9GF2+68Pkҍ@hdײx,%CƏ>SZ-kd\ݢK :DŨD7=̫ j1HHWEZ} .Nnltp!c=sCs o;q   L >ߠ'Nj$[ps؎^;VbUJS-`Ӥ:YN (p̲҉hEJ58} >Tv]NҌ7,W~_޶):*JLS(pzo Pn,o_v>?B=?#Wy|cw )5Q=;%mN\sSb)uD5 XzGv jBcDZCP32(/Y<(F+C$")pJ>[=_$d:y<οkKF.|]N-вynwoQ$.f4j~Ss;t1M+TU®#!7FjнTeFƤmxi̓9R/Ifat;X414; SׇNkpݦ<@ ~P³#ŒųSISajwD>vΈ>=BBU!#1ǍzZs;L )_F~7535I,@0}EZt:qdm;iK1cyj`fjIKA9' +1N?A 7 t/Law.ʭ-ŵ*Sk0uшƴ=]lcvj.RB<FL\ e0iO{+pO7ͬV.Ll /=1l⪝ m\n1J:TF$4C;AstQ"$zX4xZCD^6\h;3pldm g^6nS3/AK\EAdm9Frp Pw_TۿD?*{< Dy ~{.`Lu}/TO|q"N?ݵn 4o࢈4iͱ(G\B L @N+l')"TCZ7oVG|wFxsR~-գcb&j'@۳a5* q1F&!]{U^y+I%rgư/>j:5 1g|0G4nO[&,ZM|`_[pglE'Jr <2!>(/qNO! aex!>1SX]xB#7g$ Lދʫl/ @ɁGfIU_Sm.2^e~yitѾ5u@uU>Dr^WDLoe($&.W.S2tcܔŵ8K6XY>CɧZeMm,^qZ]K){F\k w?ۋ!&,/r$:_'BE\1IO4m\0״uYK7CN1X"Jjvh\/P?򩽍fPeh݋gqn"fn/,CۅRX)qX/vH _'ni(L YD;LѽP;ްzCe#T|=LF[_ܦS },607]{_"2(J[Ul2[:mՏaHGCT\L#1._U|S'BLYtE,B#ؒҐYB #mgxCJ6Œ)Z\'sf!XWC^޺óvli#=d|TT@ӌ|pD o+x N`A B[&v١M/+@yHQ "?){FNe>TM Qwi}vonT kN;EN)ZO`{sm9/YaW8/ij!T|7DaL*YUTT(!_` Z׺(u%DLm-v(FcÊ)_YNld/2ͅRyk\L>* ?z j8^Mo+Ӯjqeȟ4|0'>hƃUwԹj<m[e#zlqg{mѧS` KNU†Yy-H eo H }5﷘Sveб &*aRuy2yPU'Z1b< ú+E񔪣$hj8E%1׬QU>; :nH+w9[U8*YG4q#޾L!QKcOr&xp\a50y#G`:{5Jb&[]0ELaᄊ(Оm b8|:˕XyY=hwLNИ4={4\cQLs&Z_1TƵ3NT! q =-Y`tvo]KқL2"q384ZڑQ+=&~fHbq @NWn ή(bC!NӥbiscۍO~_H#16;@F @1T*oE ˍ*E"M5s^ꈯn4) Zq Lq!UR9thѷj27EK?މ&zWu6'` ֲyxIH^d=R(Gq L:PG.LƋY[`O@^NXcgS̡>͝;yжf43v'w 37HH n!fw#= ТDiS8H!y\ TvM:)UZ a`Dq|0?a'6q#0UT`f U.Ƨ9 >hi-ץIl8x vdY}'8~\$ 4fM X3>_㒨&lMakR Q4"[i6·@:HZo& f'+N+n26]}xԣiyöK̑Jzp?tTJל)9L3rMjdr ;;7l2%h_؛-M-VgBM>JFe; nrWB;G1*l]K0 _cߧb\M5\aύ["H 0_QY]jIiu,OHB|څ!DM {{ 7LC6U1gn6c8҇q4oCL<'RgRQLp$e{S,+?cjyZƒt"P笩ۦ(0 ws|R<>}sD<5ٹ)BOXW#jo6X6ڷ4w rKzuitېnIQ1rU8iS20qU&&ۗt 6 uu1D8pΊ"'AC0{e $Ef < }]:\_}=-Ej̽7TΥP9,z4az4`sM%#:UJP)CyU%to`֢gZxZt3ϞE/Tm8xV@Zaz%̴%Ʃ3PE:80r!U\Lʹ,aQ*!wEXY'yF1:YYE#yEq] ԃt$4 {%Dl/TϥCK Z tW8LQpnbT i临Mڼ]=hЩjh/*\ }7zLFd4ÜGaM41"UORެR.Oݣ;ִT7$] <2d':5=oB QZC\ZohiL(Jgy9wgsZD,\ ȳ*yp -mI~'sQ'\0Gdl=BHvyU ƛVg`/Ȑ|0o$G imnҢ"4BY[ +QhXYVMFOԚ!yjG1#-`!HG#:ZBl;,eX;Y&q-dC _v;E2=,hSd2)>Gdp>=BrG?aT`c4Dm/dԈ'r ^m6}A.֔G֚dJŽ̘*+Bw #, MuYEs7$u<\U]*]ѶőqV ])`̑CBL(WLX} gvnS2cap6MDSeĔ<2sE4&%f= F b<޽P%&)I얚<&H33du7HO7L2l6uq?WUL]u]m*awHD;?$]g:قGD.*?p!g9r_VWLou;4WTdF5zs&$Aց;&×J>wQPgd1T[ V[@AU&à(csmf\N3VB5o"M`QYNӦgX;ר3ߟVP 芄2?p>'džjcv.bKojb2A 7k-lN= nU(6R"ㆬ\_E;]q0ȁejƼhT-(Dop5`y1SE}aUVkR5焬V<_,Jg؎"*n0ګF %D#G;:<;ȸ`@"X>h !|,4z J0{Tx;V볭0Q{Q̅{Awna"Jj45=͘@R R PI[>|i/;`8`caO[`2ji85fI7yOQ($CfQ|zʖMy,8%<ҩ7wpm_V-_nqV]IN ofv-psֽq>PQ1M'4]"ŽŊBP8ƢSD3j'zEu!Օ.s;>ȂsAk­Z M)+;G dT fqJ9VˆlXxaAь#JDd_ֶ Uo]XP l}߶HelL=Z){zBHKVٳ1X97f<=,vSwB%FLgᨭ%|([WպAXPU`ƕ83Dl!iJi v@$`\OLgu> &&2ZV۾/V.A\Ԋ%e/dzPG _}G&6Ĕvo`v8Zh>f$&"[HLU7Bd'BZF+;̱)ϤsTål̬,_qzo&6([WqLo8 yE/nm z`)&w/NOkU͑:u \@aFs%1Wm|PSQ5Q[nmIψx9O=z[$:w 8.F:4[50PZ|[z]]EV(QD4 i$|8TC1Ѽ/dIS qZ0*ޗ0a>;;}E!h6~ĥyS2<\ǓRfƛcfD'Eur.@_[JoQY 0W~K.׆Si Oti'w8&2y q+")JW/JL#ū,kNϛd^ۥקNYr>򱱋 _q׊B}nP"k&Je5vhWiֆk#{,Ŏ_u7+Twply¯'|ˢUxD<|C٩ c?VOM9KD M{P%Gn/ Q1+c*SjmbWf}$/݈[f'rJeQfx̀57DTU3&7ǜ^bT!F3gπ>9 g81o~̬O G`EEG |U"mM`r{9+5D}$P`0AZ?{(7SE6=>XC|8vp "KRzhmӅfy.z[ e;FsH?ͻzv?TtuOVlr^̞-8OB&6m{>15MT=z^N?.7N\ȑ4ܵb 'bH@~3p}uOIt `je@q $w*ar:zf8 X9i Q ^0ZoK %7l˵F*p4%Xɰ->꼪q6+Ǹ*`xGY*tc W5߄Ȁ@"FdЌqݖ|pGk̔<> /B lp'K   N@>}_ms$$C]u`6|W=Br0χ%80Ґ8NeKxR :~{6:J}BqF 3K%F $I$3uWŞ1˒m[UT)1 R-@74V?fqp|E2W #kjd2.`\y2J9~ጤALr٪1ߒt-e?%6!o7{&ˑs2g\vY#h uрs\T1R>MAd("#|5 fw!î;k&]KAZۊN:<mz6>b,@.Y,(l|6(,k5˕0ϊmcVy3`c.3bX˳sy _K9\ Vet: MvJV'gǢw#:ItUYSPU]kiA w2 _Z,kbJߡGqMK3fk݂=;`ú\ș'CR߳!b*gJIN[%x4@j8hF;yaCap^굌zJAv׹3v6RϪWX9D98b7̞J0Eby070' =G2U?Q1 ]FӮ+ޗYcldLG+2v/ yZ -DV¶I&P=jA1>:lvv[#пAS8.P[b5tmdDG EvH;#q, f pQ Aߨ"8e=[yb4:U$ z*sz8~ٛk3%T )F5qec3ZkAjQ$NTR'H_.+vTͧ^\O8ix_myL^+&İeh H)DwYPc;lʸjR ⶳ IQLj hfLf;A5M|[?a&%y(0BR]wpcT`ЈKUZ:r)`/ 6*A!+e@{vų>Zz]}=P tg6ȵC4F_ޚCW3@]2ܳ6Ԅ%ʲho1:zK N/ڵ5wj48NlΞxsR$\I*De&v$<C.%G7O~t})W+;^ S@ {. ;b6:Cj+;۬ H-澪Ɏqa YE A=߹t6 ú/ s ^3*C_QKHĔg/uTقY@PFi_ݒX+)ImGû< =e|Y%f"ZVtkx5˄`Ôi%R7,*Жó}޿lOSD"ΡMwp[\P6:Er4^D̄Jˮ;n*-|+ mnl0I_AoV@+;t:up=ZkqGb:vi(7TnDE݆ yQ˧BZUUssoSvQCl9Bm>,SQh@;%ho؅NH ī5 /sR?V`&<41R0[$W<]htjd -Jyz'nи $\†5Jn7i긧Dq/Wߓr F6E1n+/Q 6R舳zR&1*BB(쪔ًᚴg{( VQGoBJ >ꛑ'8X0PuV+Omdy=Շ,.J?9QNN;%Tmi?~dsJ&N |.#q L&ӨO]21AjtY=P١1;z6AI ͮ4ϲIZ7Jt;9`x[Hs~IxJla3r_0xN?N(-=3 b ࿴$>iMsEժ),׉ǯ7lgc1 *4Yx>_SˑuŖFpa|'Ikuu{ݓJu~Z-x5_6Љ754pHvnr;2C$Аe%{xyuC,Vk}]Ymn@Plm:e$wXhNfE:ㆁܽ@܅gM@Gç KT|"kl :RTbiGٱ@.V/ֈK'!b=; \JgϪ Mk)+$mU߁5ib.kkq.( !I|lH-GƴGHF;kg~4y J@g5a(?<؈+ p 0o!1}yLw?72\Pċڅ{Yx;{8Sq3-ǴLp g/\h_f%ОΟm5ipj]:ZBGqCug2+.vYcEQ¢st!'_Uc qޠENr;4ZUßƃ>>VPm2졷SKK Jiy5)G(H&:SGjZ9&p7:M8@m$2CNF`&AcUXV`*snVWبh~#)en*\3w^3zJ<,F>W*jNyCiSñxl2~y9X5d`!@ gz2x%,73TV6MPDWm-,j H;*&Àkoselna~,]#.ԐeɕumQ#bӋuKRAK\qZ,_A;|v;P"x|3ݕm5dB?RI C[َ#u$5y]]s%$> ȿr&x_P5]J 8+M&>Q?tXʈeP,SGwYRτ2|a=~iTIg(wI8&', ;94~ZFyEU=N}xl +t7bE;QbONohUCv*|7]`\/C3<409Fs7X8{7/j{Twy-q XW?nV1O6^Y;eP9vESsszDq+;z+܉gF!?UlxF۰dej8O .>owje a2>~^:kG⩊,QoZ3|wPZ\*f(4ߝg(p/䔄 sTU"JGCd#Y/?AZȦ6r6ݝ-ga olm8Ǧz$,ZXVjEL֧:i|g^Z*#&gĿ%&~'b&V`.qpoFкF 1ڍ`D+2m>/(EںFe},NWI#DckKdӕ/mY.81+odrFQ uªeGQљTY93u޸c.*.y=*'1ögN o}#B!l}xJuKqƩ~"oȻ;~MWa>Pe1‡uexWJjb#fd3ymdQ0t77zD%v^֮ ߔlVMы n_SyW2m0LC "}y#)%_\@Z?-}Є~casܡEaVگn@ň rBB d( 2C{D JsϏTvn,xf9kޟ'|58+"&qq J=o:z5_l5@ $H/<%WaSMi/VEx/o|(,xPop"8~~{}Wmohu8ۼU '3-uMl,5\XEQ93o *I>?-$v[0gނ J"{ ""5wNU&9Xg6D{ޕ.mc su.p7 % .wM*4>I1aLp͙U I[&) FvuwE[gl &&80Mz=?W殖: ?`g9xD5ۯض 27ׄ_<#(YкF.{SڋtZ>d@Jxp}M: =j"jD_a-q 4AJveV)WVmYKa `Á4GU/UM#WuhA'&eJ>`׬9;EriqNo߆lg>@n+]WSD'P`q{_/0vm<-N#2OO ^i6LH( >zu^ =]Lئ=Pqu|/>gs='/dXmVfkwi@)0rV4b^h=O8UilR94aCkQֶF盘1`!XE hy;P%7k3w5Ujmbsjixi \OaΝd1L̻͔ NtroF9ThKi`Ձ* m =zv'8Vut\vtE͡i. 4!|ZoR syD7|zz៰JeQZO3tZ^hckf]ha ?)HT \ r 4DúD dYq?ѪUlU(*&+RL$LEY`fYyo%Tx iW čŻSsX-Q%m|xNe+> 㪘o ;#e K!woSRi }&x\Tf`wf3ؽܪ- ]/i9|mnpg=)wuFg`灀™Jt8۴HXQr"0 Z<we}M_⥿; Yqopay$hLuM44S9Lqu5\](I:lRl0-!>JP4Mq '.[w{]?xtI#N?H 4OLU efzy>[7-8T%416WVaR6PÿNaþh&?52i!"eИČu-O! :Zv_pcd7xWB3zlG)*`4裩&ؒތJr<6SOBYJwy uv\}BcP'sݪE,SnA[zo|KA/и 4|0'T 9IθҝGv.翷'I {"cT+2Z<]D~뻁TJԗW," ǼFc5<2T_`s>W݁&nptRŃ.=j׸2Tjg8)z>ugnn(iޅ갹V*#E%[ωn0/s:7{7frohjчdpL6?i6iye\d1Rh2` ۷s̠l=*Xd97ܽX"aI冸8n +bof6T+`9Lsr Tdby"G@?9?랳&,r#@0 jO^|ЅnQɼشqrqX.ICi1Ի肜w=uP! PpjX``~Rć+$jwJej,rKgu1nf}?~6M \V}ZmS* }7cb6I֚Bm.~=AxQ 1žNB>D{wj;ǖG%#o5!_ePCp^7 "Vg%2?,A,( \Q;uq 7~\λ6:?XcO  ٗA\="%qUpQB@q5Kw#F7!ֲ9-ZWn$"p4Xݚ)Q ݞ w] 4o")$52M9}Ou2@nwb!DK'[̗$ΠP|1O֟dl(U&gJ[FFr%/ܽbion%H#N`VH(}˘Km!PRFK5,>@~k|J<)EoWB@pbXB-l};[|)Amn}RetNIٻ ˙cE{⺁zA >?d},2 *'ZZ=jyηp٣Кr+l?m|.J#MZoL1<Z~X*\>k(3իD4 n}G r!;PVa7͕W[:uc4r2-8̑9g?>Ʉ I< F0`1{wzZx  u[jneGY0`Ęn ~׼r-x%@/lPV<"4xP 4 $1T]Yᣕ{!Vq{sGw*'魴eu"D>sFh2ӎIa4ƴ%qD5ndOY4O;qH$~85:-QcʿzI/G*wĦ7ȩ`ګCJOxDt7pcu<=KE'x؂00ұ`ݥx5AM_r÷[,fM BBCz| ?\ gL e!N'Hp"e7kmėvW9Ya@'R8H z^ϪV~Ec篊OPc >tY匩klc3ceSvyYbZeģu=2 ^t= J*20*݂_'a@l^$F!)ؿ[@Ī%O(`L`q΀rkSHC1" W@A\ 4t _W^T]y-ROHxU<-E0b\ ~nOO0ـNZ+K]]$(:‡?f"BX$FE |F 3䁖.' >ySODh^eKG#h`FACrZtA]'jLI5@lJ}>PE(a-}R+ܶDPzUZ)R2RQ#]k}G1Ogrx9WpOqP\֚E. Y{40R~.4ӱ$eۗzy|oUwɅ]WppjF9Nm9H7 X-ICZtS&5W|utA}HhSɯvV7zDo\fWrWIGqq Txb[$pQh>kI>عPSŭDz"%ݿԴp:(ezf=6(Bdqi:YǻCKZ+rAxio,@&=[raE~xxLĐyΦ^jG~eusꪖg͎\J迡?å O>+|Qv.k{O,3oKx NVP~Q>y7cEZ/%I>%#:ތM_۫ 'gq ;>DԿ}Ri!fKw`s:6WT4_%jk!SZFC(`8Z+ D?/Kd_A(BwU,/r3 G ZZBJesx[u;Q m+bɛ#dh:䷟MY#ycHM8B!E1<>I/h-B~lRrcٺG]WI&$f2BGnq B}KD #2X}7ulq`pR-.Yl޳/7+0-w(  v+򪏊b#"dFլ }}Xf+;,s}j*Kʆ~Q1#1"6\F" 'L;pt pɭe6([@k[[y9'1kT$;_ȘXE:D5h<Gā4N\CTw'NA I-yx d? z|- !gIݺ/.UO~u hK@*6?AǨ~Y.'(x2]+N7;d4+/ Jפbx$٠~a%=zj_MLkOQTܮdVهN;MIn(7ȻptF\ηl5}dTsQD96S@hR]ª3ie'|X=_ ' 8BDM"z,k G֦ ҍ#־g$8y#֓܍9ԇk#7xk/7݌OSx*stti㳯N 4pO$t-VNQb6WPXt9TPٞIa1qYxl(Ky ^ I[ 3ge<2|NOЏ P(J`&;Ivىv8-).eҦՐ}q/W2%Ǹ}GU>nYmFE+!;?ZI8QBNiF.x8q4B4aMh{/Ըp :+9 Z\(WRF[●|}E$\U#M(gvY~~ yӘZ\Zz:5YNlQ("9w$#hܵp O^t5cCũ߼FXD6BBMmeUT,R~W޽%MK.93% ȱW_ږAFnW#byLLU:IQ]]3>+v i+Ņ՞ދNbmCMK?t jf(x2'Ôb tǴrHuLA2X5WN59S^/ّPNgL0G#.f[i }&aui@j@z*2l ӥTYfD1w dF 7璣NY+ nG}kj@[Xr9ҮcLšff[2ƀ~w_pdz[)\T4g,i[>+}<ĺD;tsDC8l=+JFc|ؾQ'::ף-Q;۶>B8,|itMd{˖/|K[AwBћʐ'.Zز鱼3 -Hp E$ ?i!1NapE>n~@EƦooG0w.2b\op8hpp${?)"|82IeTS]gNak$9)gmnhŐ)C^ֲdk ԧ`c 3 ]vI[bmܕ$V|K@s={9(8xL[\liXlBm_>5{oFWݺ#v0&4KʈGIOV i"k(>{u ((hcj/2RoGQCw)0f#__h,'v+d(l*K-xe8Mʷ0.P/ gk2CІ=P,S mK6VyuPA,l(n*2"Co\I#Ppʡ=6(5Nw8kE^֋iWԑ ~z)aXs/# nzNv&ԍױZS: &c;:vRޏmeE2zf|S~\Iz-;oHȻBKp(Zh^^/'ab>*ڄL"_PNH[*PҐ'U˯a拋h^A8x=UEn| #3A ,ual\n'~#p4E ˦PLG&;˵蚓& ]C?Et-x)B׍(i-EcT&Jl7O=>̑qJ+? hU9g9 :-*\  cɵCJ|nTc,E{@^|l ﹇~vRwEl ~8+Jc6 Wͷ0.>) d $|g;`j8yعKIl%/DgAI="` 'Cz|N ջt!BDj؏X&7\0lԟ҃,Y'T-{ ] O3!Pd0j/<;\g`4O6w$jdH__ V$)];kJvSOQ(xEN/7K͂ TqsGM`PJRҋh#dm?8^`F*ZQL3XgѶW:GxIF$] Va bhdZN6扲uLj_:C,:%w_\u6CG 1k r@Nf{`LMmrd Gىx@ʴ*8oUt5)J)X *CӧoD+j^M*[=GϗUu3}>1ʢ[TB.2a Z"fя!a_F$XoҮyJOY@k;r1bu%,'A "9x`j=mcD~V+)F lz%;:xCGTN̆ĺ-93w}pᥓNNp!E,xCRӤGj{+}i-̋ڎ|qKTµcBVS87g1bbnI 5nÂ/ ] p9Q<`dN F6~/r~xbkNv"U!膕c",ё!i43r!Q2՞dWU}~WqMg~Jxh/&f4\Hщpşr,8<ޞSN^Pfƿx,P8fE0|Nr8+;Pmx؆߭93>Zmek{Φfy!P^jfxs#wU6R2ʔ| bQD,EJ8l^2u'NRԽf۵I5RS=Iξ|]֏" m*!,TtPACҰT^_%wE$Éq %@ty"])[)mF<_Ƃie@BP2hW4-AΒeIkCKCxӧY#>T4 '{'2N߸HQi7,jAH:c.S~`aza&|v_@uٗMLcY$Ht.(o 0N>N\<~&\kQ͛Ql~GKga3DoWG+K _rv511Vήkn mJN{mfVzDIA k5"Cf{mUN Őmxmg>7[ {[co ռc'Yg`Ϧv&|HWEwpwi#WbY(ۂdZ];hrкzU!'I|4"BÜAG[wE­dQnϐ̘,=*.Ix0i )mbGN[9g1( ge%[tW+, L2fHdj }t: ܄p[3iS}piB~c'>!R)rD'KG,O_KI2AJ.AZ?ÿś@RйUU7cˊbɾ~X;&PkrWvyכMӲ=.͔zٞߊ[u۷Wig>J9x>^C/sU)m@zYp7r07B%!9#S5ym#n|Pn`aJŪU0(.PP۸|\a8LƘ|2Dd38Jh(Aq P@p:[4HhNNK/h;J8x|e\<Ms'[W =pj7oF]՛9s; +=̱, {W|tL*"-M]q% @&"|vڌ/)Ăsul| J +(`-ƺ.TD ?qqwiDc1v],%.IR:1u^_Y2b-j8n=/jvXLs(]FR*ѥ̱]>ࠒfLlу{f]AF>H\9PC]4ӝɿ0oV~˃1BX4<YXwͫNv\7xPu!X>EuZI;^J5GA1b r5ƒj Y1J hzmE3ߊ[=-*З;kv[Q/vJ *Px&(A tw!q; ®ag)x=sNEsa&WM<&ji,{'ק'^CWc96.V]Lt07[xQ 8׋Oo(.ɉ}2~\kor_ϴGC%|0gɜ~yײ~#Ҕ[tV2v>;t ٬U%jp)&M0zhgyEܞӭ큅b+#ݹ(?ȆyUUo E旭 OgUe5ka3i%@SӪMˍ' NfDY8=(yljTz%hq&lx"~$;DZ㜔b8;>nЄ)ia|L󄉈̥0J$0C͓gaїšoe'Er)v伛/?KGSÂ^E$0^N_tQZ/I]\Q޵ U5ۻcbЧiP]|seNFѴI@¬Oۧl ˏ60l7$#Íc v=T lUÀv.5kg<(g,@sJ0*G˦_UgecXP~%=UMĵ }oesuQ@+Eg(4zFCddS7+J8nx@VTa,$YIt_ RI)zKir胴[;c.VoW0DeX$LyZa(K!.H3]]-]͵2`cQC iRWW,zPP*"6V+wp x<!҆ mVnЕ SZ"t קwcёj6b)|.:;@6M)2> u3IP20!tic#$I+zgx9OEV@~xXܔ=0 HjӮ*bt T!F)^%d-+e|G%9'bTa+4[v&K ϚjO:k kcJ_y``h*uaroՋiv(gsxpjK~CrԤH"F!z :\!)(oƿg amK /׾:A~cMC ʽ X[a)Xf}4h+&~c~ nt{%.>¥-Qj- J5sPNÚ{|v71I  ӓ2ZdJwt4|{8 ]4jɭRW;Jd ÷i]#b=`(9ܼ hZ}d3YJ$-w+ 0x:+/TKRoBzBڢ=$HWw0ns06LA5&U1=>o]o?.#0H?a' Jcڽ$A%,j5'SGc ǜ jӎ!*c L@V9!XAfuE{@juCO!@U@ ++$(n1eLLyBx0[("S`uPc~ljA5!Um ɨ~g7*}h񖳇 ѡ%G&9`(ֽ59o^^*14j! ޵/:FyhXD%_=Ǩ"y'׷F})ijH_yg{VUMpRe؅Tt"i܆ Os:Kw?a)zzK5UWUbSekMYR~W%N; Rd勋tHB4xtAF6|1lXCHVx=f{bvoe^ZCYuGA7@>&؛BXbj4:Q"gFA{o_cؠrulk)Tp-b|t2Bh6$Kw ]W <ʪnew(4wDP\=ΊY顇>zj] f9=I_4; rƯ#ͳ(kTsD9_(9<;# ZМGw%i+TI嗿v)Bº%`d /wt*<{׊fI[ v K7GҊGq;y=Y&_pmxy/N!>hF @[_Yj,*"uf}e3p6N^S: b(f$ƺǬ8Z6dWo 1o !/+Ɋ`OFPp0_ٱ@/iuV~VBXE]"V(%R@v0 }g;NhQ#SVc⫉޹J<ثH$V_JCevI"Zfl]*@_A=Pk @c]?_^qxPS .)`ȷ)] I?*hÊhn%ewn OHE񢞎U "G*eBKqIH}j޿?/5e)m!%abBCk~QD{D#:ŝ3־A[R{glLk"QХ#ּ`z7}I#O*z\TMw8zb`炂KoeO)Um%Hᙚ Wۇ#?kA~GWvl۟e g2$aߍ# 'T]-fZ^YQvl@-OUyI}uX=5z6JenѧfyKj/IX>I16'7V@{Nj Axl +ۄ2׸ks_A%חI͙!f?ୗ?`j56 : Zuz&.\T 5M 2&1fNY|Ta%9W5P%B;P, .:)6zmt~wj ¾?dsaC!QouG Wێ}V>I]+;OW4D'Gldv˻Rx%_?&4P\e,8j\@0Qa )] 8<*6yB FAS*DŲo7Vk..%rKmV;U@p:I+X *ƬPk pPs~%YR[-yQj7LM*o[Em3 feZQբu&l_ԑa*h9eSj(HdP."}U0Oа2k!B hRfeCU,P}tUNհ/4hdX5%oJľ3x.0/2(i4UMQi+԰e{$uώ(բ#MAW@-F%ǘ޴$)T LkXzHׅрћKi͑pI!B}ZgMtdJoBX 5((aJf3J16d]<ql I58JvO$?FKͼ[)ARFHrTlE ᖁ?&yл٪T;?.TsE(=*o'26ɑ-1a28  G\K$1n-B<96 gOXc[YRjUe U p} '_:"'dh_B̾+hK%Uɸ]yHaŵp[.w(r370jhKנW'LM2m3W ȯZ!MoSi>abJ0}Om@% ΣGE'w/WFs4Ej(C%rQr@L]w8u*oQpfD9ߠxl䳺bJ5l$و n@<PVJ|jWHqCD{ƗM"HKᛕk:ZZ}oK*J?qZ%kf3驂U)Qb̔ɷ7'4[Av@dC H7ZrL2.R*CeP*ƀ2ɯc! HlUaJz8WM}Q;~Pʌ.I"6ͥXo!gpCtl*ðܖ"zbFhdF`% \zV)atxBReݎrg}$q7ܢcX𗣫vuU` NŷoMk612},XD` W@U35AuA{z8J̪rǵ)֫s]U9 {! Oms R0Q?S D;l?U}~oT|Qӱv`#SEE+ikɤߏ,%H S 3ECe#Yׅ)!aK&ƼFdoߨFN%>OY]CpC>(E;xNti\h\-{O4#mIؐgX^R*hŵ+.i5Kl1+_@`sp>R>s9ĖTwYTL!𿻬@`g 5̆j05{ld8տK)kMY~>O|}BDġ,,)'DbY0'ͩymՔ5Ӟ3.oKî!z>˶0T?41P>_,7ߢm?uy_$%QDbXoOe('7&9OůV BvY_R#ӞZ&p>HH^"cڪTf]{v lE6tQIiӥé gOaW!]]YͲKZ*<Oyt[סـCZ}tvmȉވ lwb 55H#< .ľjc5!niJIІAW7m)wxi?l l!4ǔ,!Ft;5.T qxrfY2nTg$4gB ){{Sy<z<\N%ci1#n[j-srXXn%h.5rѥ3Iq?X:?"u$;[:3乏g*mlbOV̆ cP oK`,@E(a?Ɔ: EVU[|TV&yc[ "=r!uge|CEkᢐ!J\EXi洞gY xXtra9xe(%{à5kQ\ (~"+]Nnk!\jy4~CۨX95]WdhT@\oP)%ROZc%tgCnwj[9"nEG8ܨs $ RXK̠>nl w[{ګLzlΆ屹Yt++S$zVGT;zt]]7uф*n4sqEuYԒ'>z n ZJ06姥[{~|7-dUoZqnHN"c e׭dO\tFWӷv Jqp 1GH֍EsxO%G&*ΝI) A@^X>\I$P"kW|G}!f] 0/Ӄ"h,5ȍ81vgdĩz[S]ڣgzuOٸ:8$Yt^_ 8 c"0@(|R&c*w(>+R!d~~Ƒ0d_;kij@r6Pz fU>=aQ"?i`VnMTxbo}`o(?0? x 8D'.> 1T#OOcPֈ9.tԸ;藻;*3jy=b:nӄ1 h{~pjjsSVxȆkOD0 D4exiq-q<(ueV{/mE;oY``U ~Oze Ctuu1qD؂hQf-3rϚ9"8#?PM ,nQu7,z#}! njJ ,bJ@Pޱ1կRXNo㒷1Dۤ~BvNp`b|Rt)kxP|{gZyT܊򠩁OUIZy;lKH8"C_/ (ОᢁԕGVT:[{\~@t8z hCfkv!ʖڟF;81lKF DUw()R8K+Rކ(['r" Fs̹ DYSSFiW^Α1ch!k.եKJHjaA9\h3|"L}%.Q-;cLCOdn]U/VDz>篡\[//OEM}jo|Tc;ą8%6 -kj"|Тq .d5:[zD@@.Phd0;~ਾ<7bq3vpqRy"(rCX%(t Z)i!^ƎcciVEpL Ge!8UVv'ԸԡNrԝ]yd".\(Dr8w$<,tZk~6 7N .@p{N j[/N(~9h7c}l_J >UL麊?3fgtqI%ŵ@,?iݱQG;Bv{jeO.UK@.%n£j)֊pR^\QnܷNɑF;x֛r±<4ֵ,va܅,/hX~ N`JCNXkLR]pSpdA\2HNǻZ=Uʪٸͅ@OR1Ǚ=i^= M@$R΋uktcA v\UxY-#phֲq#(a&ZcÄRLh0xɉ |JGcZ:n{ F칻ue HyE(A;TX pRO~]}zPsq).gDB]~QBR01Vsz@r@~uHܘDb$0Jb̕f63T/t;?J*jugݜdHxiǟӉJ2zx޾p)<(pі r^o&Ӭ\n; yGyH쳇K} A k~p4ݼyu-ۚͮs9UP ]*C[b#b̷Q0YvK`)~OY6q.nY Nԅ&_/"Р UFo&gvV !Uϧl[^?(IwiTlow08Ԣ&ݹ]WFNͫHu @'AM%:rDv_8= +1seuXl[ֵU_M!Vè {S_ zY`$!SuJ3ۂő$ܲ煂(7$9+ OHlׇl&;E2rPMmBx& 'Eo$α>v$lfT޵25‡W*FTǒ4b?V$?H T.pVS@Q% 3+mg96l1͢0/,}οݩɩGr`Zގ>[DcS @L)x>{9,廩3۸D8zô !EjW^F0S'X~]5ƭ3l$j"sNYGx>{taYѠ?QmL˚VO#pK7;{9e>$ mMɇBMWcG]Rc e&hP4Z}g[}F Xka& ("ݘ˵:)_krIqqn;'@2hѩ` .KVm;*+j0X5'8hFIqBShE'M{#{g7AbĜ7dN4}T5PYncXn:v8k,mؽ隷2SQ3:Î,2FI֑?XĜ-76I7-qW384#@+/ }r#v+= V:⧴gĭXhBZ)/`{Dxi[L,qNv=M: fP,g!} Z/*/2yN"G`jZ7zu+JM{ ZK`9ؿ' >AYoޑߌϗ$knjx ø3[M\;5?'sÌd(nȬAФMNMm(8yŲ6,%Ф+H'#t +½LӠv/MZ 29.Pp}\#}|%)([7mօ3cTMQ>x@F19i_^_U(yx'oƏQ,C*ٌ^ގQ\Lz) xXA0I#p q `Q ??y䈬5 nUз b $6g^hҹLlrHiڙ*WqUr4slkchh Aet(0 9}6q '#362(1[h$ՌT LݗnůS?q!\9@ Ssr+N']#|[x@ Y݆Ot|&~{,E2@WڲYT󨪩Lݼg:vmTΑ+Ap/ bM]\w.r ҍτ Z%}-a7{M4[D&v}?yvj@%m''Ɉ G#9P<\1i~WÚiǡS m@&/Tnx5,goi2'M =v)D0<)!lC~Jdrz7IHB+}H]Hݜ19^zG4hqw@nU0ldV w|a5}HL2(xˬXiMRշwi&.}{ DY{7($Ú>0KFļnbVZC+?7G[2' a 灏 U\dfAFw^#;Ƽ@FN1^?؂\y_UðRޛW;2~6Rb|H-IvF=wb"\XpP9DžӤATiμL|0(w2{1F}RPMkwЄMo}Y+݄iʆP;n@uN4t h][L#?t-\$\`MXPVn\ JT!lqtNvl>OP|7K\ u߻VNv90c+}y)?J (`v "_c%~G1W]lM`=Ydԗx%x1%aP6 5L;Hgn' oyh]"mXīIUN-5sQ{IRH[$/Lٝh^7UJQƺ"eC Nmum}fMd'ݼ s&~Cp}jciCo9v$!MDAbωT!d&G]Gxm"|"k?Naqn0CeK>*p{\c6 =,/Y1R㭂n T.*[׊!q\dYdeIt4eswBpV!-Y(810`$dĬ$৖\./t Dۜk(vSl]5e焦Sכ}J(B ޷ GVdP=D:/>[v,Z)Bʉˑ1L $vPyP{5bzC-/ĄEGE ]ri;4m?awa6{s8 )ۑAIV,{x$e!@q"O{IyaXr5YC,ڮe:$]_E4)ID]-byW-B6ѯ/Rqz kw'NIz ok<:-E4T%p؎ϓƻV* 'a>uPO{ $}pJC\= $ !pn@XiߺO0zo3pd`/2-V;q t{*P6'02.ROSh=#|쑼 4RHovRV^uûu>7Lك.3:YJҿnyNgNcםt3z-#r5E,G;@/+&B]9H՝ (s/eNMpqS$^Nh VsgcW^ .$/+$j rϗǦȻțECAK$kKx߽<i/H7Pڌa0u`[}b`î8Dui\4q.w''l=n^A :F'ᎣPRe9VWshҍC۹_}ȁm3K޻9J$2ۃ1 [B(1:HC->ATÛ/H̫A y$O0S3Nilz69`.V5/ryh̻[.^r D=`/EHwAYe 8=WYg *xEaNuJn0 _8.C`E%V@|$?\ˣZe>w^ٟ哧a}YZE5MA#o|ފKICPR3},ͰdK, [w)\_qjTg?Zx0~ 3Z_ڐ~n(W⑩d!h'Ʀ5zRSXGw&6smxcY̭ ȗ4Wȅk}R ҧ)1'_[!*Z=`'OtOlWvx@_cTo)bN =/jܥL`8<ɠ Šoh1jgur^o4Zv+Q1J3V Ӿestb& *gSn8z~layLgwu#B(<k+ݖ)?h4X{2ʽRkG8@Z]G!kh9֌ub6%lVUY99*7ب ߁`9P4R'w.?vAxoS6utBf;&K}0 ҅@ EFp4զ,'U9R+W$9`ңyo"w(#aTDg5EXM-W:S%70"@=&wť n'' V9R# 07!(dOeItcTnS i|ß"gulQ2"<}]x*L V? 8ȥ6}v8؞?i=CK,jj[ -I,L&[ Msw6 Ùf %)ևPbk??ʮ ]5LO@F-aM\n6l!#MB6F4HGأf)*o pz<TBЛJzA{ߊr 9Qqm~HeL9ZFr)*c q Jom kpMŃɪ- l4,[BՔ:uG5wK5Jr c@߅lq&T_%,M1ʂ)0;Xy|0 p~W".3?LxẄ́Λ/x,S<&<9"lRІL37DO/Q%8guB0ۚhsj̡@+|r[|^,j%Ѽujt.̫d>K@" Ù]Qzʬ‡7>{G&I)[(3UZ)'OlPq=29\Apoòg""rΘXfe)$@V)ĄRE r]j6)Xo‹oCW&&({6EI4U .e@z"Y6۽ |roD5LkvXa-7&y!9Yp^FY .IJ=fpx/ zEwi!QO0&ov foߏ Le[}.ܰj$fHPr*4O! L Dc(2!0l#SɌ - t?-T .TT݁?%K2q%/#߾N0S$?{ҍ20˝)TA5SJ}=y,D%@.ђBjV,׹uf0xe__b,fWbȝA5:6/)k|:0b1Gja!+<4Z]_..g6,9`q Z +G?Y|Ɗy>@;$ʁ-4kuK0_0j+RI^I5zfY0P•Iܞq̋Iw$4F*$U`L]Hc55 u(CS]8& aQ?1|ېr%xcUNJZ Բ$֝N_u xҍņkS {}oOv>_xFwp{S^mQH;U|M%Nj 1Yk<K^:5:ʙb34$nBK-6llfkHp粖Kn Ty&Ћ#NV8GYְDdrHd2ߑLFV?¤^x(?}=}!pwf6M]1@1l eNc?u?|>oDtK!~r?ۺw\^f?QrX'XH6x.mZ 8Hb x9LV(fZ>BBdԍՍqYͰVع[= y%-2Vo5@U. |G* A4޻0'آScdЭ̓,8I0B? ?6W s9Bn\ro;@[:] ;xzKH~X9NP6 oO"嵟ppzxyK{ K͈IMú~Yl>T|ؔ6n]bB2hwI {I~`9<_-y+X,94e*]%QcB sGXȳS)?@b/&S<{@Q$94+UjD Xѩo*2iFcagZ0_ X)g ҄kڌvq_]Dn5, )p9ڗAL<]ORi.Z{6n3df{YM[wKr7*,xa}kZ~Vh\#g]&KHK4YF!nӛsKUpG0VY;R-%/ \ǔ;V0Ճr.[ izbDv;Y;0b!MDaG^ a a/A>K䧒!itk4ٖ5GSŔ/>EC&P&3{NJQBeX|͑jȊٙ%^soYQ5;6y=WlۜnH6z9'L +̪%yXhY! hG&6AO`N;,PFk, ?W 0RH%<_hAArb4kQYCؽvxePm5W %_]RrB =bDܽwBdȼlӑyG~w Ѿj*Q#ovwT6W&- }p~t5TL2$[> dF=l  sI =FJr9%^btWG3^`6p{Or+r$fSNNzd3s EVj-v&P|w`\5Zՙa[.0\PM && W9Ǒ .VND5UΦ +!5*ny}{!kDKqkEh\Yr,r]طqh(1߳KLNɟl4FFZ_ۚ`oMq;(~`ޫZ}'b2Y$A+TtЕyN<ΣVwjj\zEP4ٳL^S\(R37H-|ͳT(G4޽{ VL mYR‰WYfU9&sBE*pZ$fUG0I A7.HڇsABEniii`/^YS`mA:0{N1nwc7+vdǶ]Qho)D?y px6W{]L@1IbLҒUH^?g&?l#Iy;J6TC&ZZ|'c6=5~_L%b_9)ؤ>r2s6~ 0`xo-2]R8< 叚v޲/ST'RAkCuP@F`;0LoIzXed_d図pe%wҤkX (hdWM*pAf̑P Yh:l7yholy$'7~(k <0\HuL?4g1jv72"ͯ5#aɦ_'D5_vDӻ `!GQ0X&3c.F!>l:D;|R[.)X,"@\3T&APQ5Eqr=0c=If RmSԻHDDJ!h4 R^U-E`&&ʥs`9hT'O'~QQ4ξz.m-Kh L>v"`՗ |cP`p%[^,&ΏuѠ=r/]O‚uOsO`A!ҽ7o8_3E]Fr^Rf}>MJ. !j(B^ZPeIo_$Jurغ\/5QHju Iy?_2BqTuϺTTsTd BЬ#ŕe$=Qw3r^48]EHP,-ZNxZ!a+8_WӋ}`.E} %D=3뼙5z^J G[uuW0ی ` 鏎#(j.Cj=,|DGjї fӳj<[3F}HhUhd:KKQ=zV *bMЯ:(k_*ys!^a3=LBgOPF?>.oWJZIy2+?ڳx[vdg%:4<5 w10T@%9D䐣Qp)ΈX͍K"ydWIVmqQ; Hhf_3?dzN-9G6>D&Ԓ6D(bG6%`˜ '-={بʑ^Fa_s+!%!O6Gf+1'#iD8eġ?Y9ƑvoA>A"i1'=/>e;b'hz#p1=t)-5LqD\zY9P.gݏ/ 4kx&A 3rVKJO`7mxS-4!b:+uw_d<{w8M#Y#>(a o<{_wμc{-.FDrMC5‘4g8޿ 1) 9j 'mc>|NL[Z_ ᫄T|BU}w-ٺĖ< 0:C]%kpsogh>L:k/J1Af%Ee0uܘb*UH0bخ/I|1 ok[lVp^}%0уg9~ c\v{>XI)3҆[i/t/i,0OpΗW1k-d UYھEpv}W!&N* |042od{G1by10Y{ʞHwyn촌-YSLɴ$*ѵM ݑ{ +&^ nQn]W!xsc}GbؘkYډ*-[]xQUx;<ǺGp(YN›K񾈰@g_0g9>}tnxg7,ɍ+mOG6$cy,݈քD壅5!4]'M~2z`QеP[h5֞UZ͍ٸ VbsNnj /cc12v dSW;qO 1t>d!<;cѰO'7 Wep}|]1s_o3zZ[[@㜥}-޾ĐaRO.DCR3{~wtSO [#0&.,ȅ٪}p KR]F˂UIєF_)O=g<R?CC &\v`PiXYK]2֨CöeVռvhՅ*vF3Œ`[H2zNc4tZwK䡆GZM ^U8'irJ(~|}x#8hz'/ TA=]SGoH9e$t})mGKEn\} t}#'f#X$}1 ӖQ=*Zp?kzx^C`RGfύ#;,t\[Nj%2P0ipnD4 .?#a`V&pyU8j,-^ST(,eZz~gdbs\}qCY9M7tJ4 ˄FU폲FTGu|Bk5g(t k 3Mv6B"*TNkW‰tI&ȄL#ykb*;ra,2;m DQyYw|B>d` B#뢡5w'XpdA\ p7\mÆ2)Yql$)Hoz> U;)(R_>DAT}o)V'3g_V!㯵'- v Pʁ+)Z8r%^[l󑒒ŭxNiMpY OvU a1FOǔJUϝuaCuAX/DqKΏquhֽ-+9J=R92Hmn[)Rők<\ŸnicZDLvh vb`Pq~w>P,H2`yW cܡ([#5FaY" $gUCN/'{.&6pVlb +xV(w|2R@K3k@tG#@D9%Z*E21 Yq tDڪ mdnӐqWtM0w!7*ͼf^" )۾s_x%^Q-!xD]ڬ;S E"tg%vv3\'iucIdZd@w-.Jam#]*u]iWb1϶΂tB[`GSmŸ<5$hVq(!y5f3c\(N1Gּ˺B=,j,Ѱ0Y- Q2߹a)PʨN_B#&k5a?Iʸv3rmYݾ LlYgZS[vk'ޣ0x-2fa~On[T>CT4?/.E & q,qFtm-d/Я,¾/g]VP'xx;ܑpvmBy0i<#<T06$/pXHOF\s6/L2J-Y(ct%1o.VpPq7kv< :cޓ vL?=v`jkG{}38q) 6[PNO(EEJcأOt*zwNCg LeK f&U{cCrPkBebEwnS[D>G$g`N[_}=7TҔkT5g{b~|w{ nt/D&u/[ ;?^ӝ(@;k(ـ˟&r;]7g)Yz1h<[yg\b,$pOQT䨂Sq .Ki9Gd Rk#EUK=C$eP2-24hO4| 0mmۮ'6Mׄe_Zx:dkϥK TN"1!ew>Yx2 v$J&/ 0!` Z L~2xoێ [u"cAXq2d5dY81 A`qɼߢ4X65Nj#9ܨwcr!}R5q]^"A}d_fsqeʮPǓZbݑ";X yٞWr+$j]xK-MMÈE9Izl/hc-m@ SK3n(rdJ&pdcV(IR\)lW*H0mN&"V?X|gqBB!둁)aB`T`R;Mw}M;1qWK*\x@ ,O |i_F)3"+vCBQapK"hl! m@U(Tf@1B~? wGœzZ5CkF<Ѐ^=I&9j+gL9:vbVv`,\ɘκxS2ZZ'FF$hV>'5+4e門ݵ-|9-﯍OݶhfAhL< 2 =k0AQ?{$3Z6(">3-u%ǂ)CPE=̯m}t@s!V@輂)eXd;4P_ pt­֔xEDƯ #R?6B6TS\idYYkn-~ח BcSUE5`蓵&jc=5Co5bQ fjMvUdER3.MxPꮾ'Ks[{SBE*+ףpx#t/l(?tp7'Ke8:;'}j$CɳHެZRAWhME Ica]95YbPb6O=;[˥\F"y~#koUwz7a[ TzNCpA۟\K?Á7l\J2L8t&]ҿ_Z\@#bk*xkD3YΊE*Y[0ku yZ԰`Q` >N |pﭜZKx3{3}*]Z[€s-K5݆>QyfK1)'v IQL\_аoc(d|Ƅi3o+ t(I79ma5fZI_99!H`¼mW`R` *.Ga3dƟW@LƱ ŌoF/KS6J扊۪O2U&|"`Y@I[촋t `'"rd=}=lkoC21 Ub޿ˆeaPĨ{A!\0TcsOcCf9/Fą̦!䞨H^ [cw|S^S .jf#&?~fI{~̛ B|l<{G HWjA^>ǗD&.ԉXN!vF<*ʰ*OP$W;<{$" IyD!Z-(Ҝ)S֥u(<&k"Eo4'E:!G+&Ff7@Fz X 63jZgS4\Eߙ\kʪIܖ1֮O{!mib;~ )7<##whOQI)TCLjQTg|Hw+&7diTA\0lSh_as6 PSwmGy4s^)/`3|" $ .0F@s ĸ@&[5qLB #GNPW2dqYS9+fA8NeFԱL~&T I.!@h\T,ޮj513q/S.8և0GsLpcsL4;ǃ̽}`,pS8Tdj v.?i)Ach>^^)-u۝ .FMx[设*%<J Z즃Q+)i`ZfM@"Y#~c-a2!Gѫi`-=fj $*dҲ "HK_W_}O<(2a$bsƘʩMsdGbΊ d3'9 IƱǢ Ѷ6c E#%OZhhlLqq2e 4X@2QΙ#ǣ:t' ZyU&"Rް*'/6-O1*?r(`-Xt>+`$_G޹6} K~`N<٨Z_F"-l@xB-% ;k?'U٠kZβks2>2Klej8_&],WQ%Ѣ?C^ErG\5P! [{^)\\ nUy{S r3`2nf>{ ^WWu{~4?&T5'\GEvᎳ340tyX-AS-wU?/_ p݀=΅򱒩Ht/~s/0" ۑ NwI>׌KvZM*PiF*dTvi4%-)q~g'  `ڀXo` ݷKuiR8k_G5UXh BQpu9[8c'+}uS1`cv8vQu$2 J-#rxG AEr2 Lf-8Aם\k1f[2x޿HF]3 6Ldbg,mL]u3,ƩsC|՚`(aJk@9wql=NdmTt#}OV2vhM"~N[P?9e_X7BQ)'?~T͜HNe\緬vUw>e|hx`.B-IB- |L^b 8EFZ^Z۹`~{"YAI^5+s?DŽB/w4C[IJ*%z;{7@.0FJ+-s-Y_nKPj"$U7Ä=QXiI %oԵM>8jípӋ HDʎ_XѼA~L_n <E@oխ4*b"/i,VOhxf~g boڣ:elI18 $AQrTrw/REtb~ 2 4ꤶLOn?]=?`^8z5N$2 ;m ?x}, [_+7> 1TKk:[j .GjBe5׽i,/,E^ #pK É+]8d/O,‡+LFB # ;#5S'|}BASxʝQTXWe?ɬtKZ؇Ȏ "AWGx/=(ƼQ~ۭ" k驯_ (ƶRFҍEURwjNCR wkY\D cEV`Ƕ  zҿŮ^]wT;(~+>A:oH> ߷?!U*5 n_SH`{~o& gat IshܲS)E7ubYڶ^Ѱ%rF4, Y:YQ+PS%z&ZPZ& sW.!pGTtw=]UIPV ͊wM14LtfAm5aj5[ARA ?+t`.yWc?z咺ȋ94E[IX|-ߨ= nfRvZ >Go TVB>4MYݍ$z qk̢(UyC]g n,2$:S&Bxn3IMwXEDsmcHo4Fwkv'<7}SUK+ .δ]E;Q)gz^Vr z$l?hwkZy3,׈P!^8C00`읛G^g+;v% =not{R{uk8 EL(l{">t*r"/‚#W"p-dR2;ik*ѿZ_4ϹpM:D.(f& GN,s[QP"h6`ు ]29<5LGpyu*; 2̭Ź.P p{EyIN&QP}<\X]@TKر(;o*+FK+.bn˿OqK6 W1AX^t-&%F|9DO˩Ȟ+^L\T + [![:mM=:jKH*"˳>`cUYhLY9fO] "%,RVR`R4B8QɍHQ&IoL aJd/Cen VL]kw:*ј $roa:_dq9W3n Lt) > 㣨yݝfC^AD!Z^mTnt#AKLr&gDDŽ9-TMH)BƄN{1Az۫ 3Vv]fEnph'&LꟷnJQ_c;݄^uDQI&v]R0灾t-Lނ*|+!ZQ2@ea$\QK`\]4Jk!.x'iQ\Uj@pZL(#A4l1gڤ :nBN1 ,~-t^zC,/;NQLi?1T c=૏όWH@Fp2dn\q']b%h p mwiʎAKXE'lL3%&O%մqX,2CTEyD4ְO7uF|IJsuRͽwPoA\zT)[#2<]fk83? B*IIټ}{߉ i 5']yE3_B@" 1s ԍV;5LM|`7>=׆E@_4oDs jmٵY9ބ>Loa9r4x^I z'.`[h)7_A9_q&Pb,"}&.W5Mrn֌r!= 0xS<%o+ݲf!_^qfC府3M @U`jJ%y$;Yת! awD< Š٨vjCVexˣ)禦[*oUCUD?1@Ci"dgO~Cl?z GrP4&(A/ y_tIEӅF7̤cwƉ8IO:U^R{W}8%/o}Sppgاm A~;|{7r*MqkܚpTp~Ƕrp ,~XF>6iTgơC{tW#{r&`~i;8eziۢůuMn}J˃L9iȭN:T&E,A.?]1(;^GOotiZ kr`ɢXG/uy LMz  EWUvWǾ!GgZkw gV"xf}-`;<G'~S hIv /u>+h Zwq@04tF.9[%NX#OҟsB@ m":k??2=-@v,3xL/1@2Q6V!O9k'YYܸդWp%*l2{{xW77H?`#n\ u}(bViUgrT/w`#oUԿ9*GVnGB$d2\ ; C,]qΐ8[j; ΛT 8:\ 7 L&-f L%·1+nJk9S3rM;r7Kh9fJ9+X,ƤZ`)U>Ď 'VW!JUk٠,4҂Ysw0N(u_>Ҿ-guƵ{ c$H.GA5;gL+`,g::s?t9sւe[*xE7s~;S >oN;ٔ> _s| #B`lvsTRuMk3 ޢESsCs9 [\bRj(Ŏ!}2U KnG Ew^`@ :R_gaK:5 2.NcH/%[S^|;XBx 0X% ޒ!Y܀-jKvQV!L[Dmt@Tdሽ& PIn~I/< OPm_2W/B;^kTDx111hcpx`[,:n9xnxN ry8SIskڇBIi}޶M؏1-؉5BF1 :6Pf5zP[-.$d@ <0SSf7]Bw2+w;/yL5jmuKc%3ɦ8Pu ìI BN?S@~*_@:6͎M@LT#YY13Lv5SΟx "=zgI1Xg.=dIlkw/?ؑUFi|בƖX{-%͡vӜDՂr͇ۣwI".3NA=apB);Lh"B"ڭ=-)Yp3">$O)2GL7pTQV xBkB6RX:g}^7IAuDZ`QRQa7@IgLJI@phƪA^IxUw7K&VIVm؀ GfRoh,Pwo&UK* *U*O!/|iľ}x>O;Ur\3yg j(8A d郮"Ck]wxCU1 b\ d +ES<ȀmIb>D^N_=Lsf]ɑ|0AWiDH"2 X({\C}͢PMLRmI Y@SK=R"`sZ-{0N{`^Ssc[|! v$,԰r`?ΰ#GMG󯟡Kv lkrQLJADUBƂ^dmc{[v_|JkPWYDsxoaR+ ̚z;?3pN5Zz=:/0_?*iS'of=(jQ,UoC)!?lB 񏃩P^H&^\T UzWaQcv{u+u裏λN^~Un/S\/Ä́{?7eX1'R`]BT .=}XAd]JMPvN\!q 袵d[G`U8B)BeUX;"}7N ƩrZz+8 *͋{ZW+)ͯT/2EL$5>ISHdK8 ~Ʌ*'"dSs׷I! [K'ѱfP;bݱM|+Ԃv %LSHψ3eD>[uf+~5Y6Z ?oCD t -Z=&OPeN%^0_~љ9( r!r" e-}X陡kqA Y4 0$A\x-JX_7+)y\>Dy7a Oh+h2NaMj-yw( NU[T<3E{(ۊ cgD3&xzߦ}Z؝-ORf"$ă'*^<6%!=n.1"z<#uP+dH ? $m1JM; & Ҷj9R* /Xg` /$QIϖ"ʾLٕw3iѤ{T"!^q; 2/QyaW]OU[0ϡxU, 63zVz̘Ŏ },Vb vaAZsyyZ9G`a gAY~q6*>d4_D?" K`!mv0kZ1/Q?TFCAYQ Ye-?&ҭeXe{LMU )͝;i]<[5Rm)U`ˆ.O~QN7=ws-) AJkZ XKF.-/z^P,j{q<̷ !ӛcP!"qq ^P&(N؉.cxEE)zR䣲Ev ۞3/XZ'Xcp,Sd&Svi25ss_K(ReQ2(#B[9YV#Avf5C;tigZAngd׌S4lޔ +Re&u'my=|s49NI5#BוɂY`t@KֵRgD7l');Ni[, Z$-bP'Aʰ|RDEшcdC\`F<}KBan晴@գ͝R=AZF=`J[& Q-; OWЛ ]u Zi g8 l P%B&l ίe"ϭ͋Y>'<|ʇ(/ R*뵋O>8d挝MQԬ:R[L@Tr0f5̐#]ɹѶDW@_Fڊ>\=e9N c#83`+Me'ą_W۶LCA,p p^c,FϹ˪"ܤ)@oo= @1 +XsT h9dDp콼h1+ UR'"NJSaH̊_Pt&PoKwbwaUd$p^\瀠(;ɯ>>Xk/7Í:yr 鿫oRt%_Vz]{\ UF;B.`1$A-뜞h)`R%_^;Yx ͋ rHh?nEᚕ]HH @~1_R1i+jiHD9 ?}¡Ԝd萰eɭH0,Ev-% gOy+Vgo sH>wt-s0ȈZgP7< br%0I}:oJ@kNԕjn8!1IT\L"F{6!^ $PݦX+]ֺL&v!hXjWlQ }{ZA\cgV9'iw+b1M)S7ՙXgz,?nNx&j8ۃڋb`EIUpG)#jա XlU JDb@@aUTdxy_ա0*{8a|znr =G v;׼e/aY!H{ Ķ-R$ ˵6gX'3m_W7~.)#+2Q.6{}Є 0-7Dlr ={a0_˛t3758J3[4yK81G!9-3Ǚ91O]G& z)FM9=b_*ԣ2rf2r3vD LXFՐ؈\ x`6M "hN>N볾[D.5I\kύ"&z0e`/';ZE2Ldhk]G]IrauNS7(I#݀1m{{(coWJټ<4U3 cisIe\R[M^ W@^NʪqEYFPƏ\TjU\}S+tPj9&|5T: yl?"(2tBXsDL)'r3*ѻ]9nb? H.έy7!nӎ *ˉOy8>bEpV],qXQ7%V $Fk]1Xk#Ψً t$ @%&N |\E^bs-x#RW4[S7z]z[Z.1!PLg(?xnU(}Fml<|w~r4oUsQ_=Z*Hzʯ'ч+tm;PU8դ,S| J֢ ^0xdeIeCs)?=:MT44Al ʢZD2 #niHK]{U&L{ThFzu,$?Ҿpz~m!3?="4n  W\2d'EqͨjTʍi0ƅ&YveАg(VfsٻPx(zcO?ZBCbHS@\vFޒZiSӫ,d PrENڗhEn֘:,Nٵe.ׂ%B\O:9a,J.H~>♾z jw ;zx{D8n Eu|!.{_0 Mp|sRq`eI5 *2xk}!X2 .gXX\xaQ*V]61XК %EPJoxq$pvdQ {\)!S0 |F{"fqpλۧXH[$0viØN`hݽ QxWg(q߄pU)EBۆ" uu^\|0 TJ~/v?lHݿV$; n(~ЅFZ24[$9Nd/q#@qٵo(aK[q\٫eRtbz0wĝ"ȧ>'V6vyn`NAJٽGU5MxT5iqNLcزi$ Ý+vg^13 .bmdjT;{MTxa%wC9 J]֭! V\onsyz*TJM |&Z5jtX+|3_Kc0ޭC{~ I)ڹ!3'R҆њ&L:nA^e?3g`q -U:|蟼tM5zL LNF/TH$=fH|~4Fڱ#rY*NP#' ud7߆A_캉=\s.`B>-Vn_h@ },y3!7e m/toH\=|^[@B 46 FE/[; *?<%x`t$NZǾvysF1hk&\zàYϧ׉U1'J/vbqsR6B]{]pg9YbԿ?ZЊ|hX[0D1(o:~F܎+PCޠ|6nR 56]\rX+ߍ#|etm]LlNG2ڱo֝qvNSE$Ԓ(䍮xD=SDhQ ȐRG.P*+t/v_]:dUhDBNuKxaXMIw^BER xd$P0%D)5q:2jߒ@75džDI!`P0ˤcK7Sv W7vn?]7k?w޹2nPJf݁Dz >QCC(Xܕt+xL!Tj/sT`!QǸ˸CjrpAX=kRa֝X y8)C+i޷:zz/ _́cN䠭sHbp)P 7Z \{sͥ 4O!o5 d 0+BFlŚˮ`?0Qsi~pyNNepL}[$YYglմN,^.j Hg?F&>u;hP$H|ago}}Zam[PYĠx2wr06!oRg{{/C樌:D2P41ߴ#Xre#uY ]9 jo&Eﶧ4-vJ)QuH1M Q3]OE%j=eo,yL$aKlT'b|<ȤQ({Kx&qc[FբA<4"=GvvvfqPLTث -^p{~\abI۴IWZI:ŚNʧۂ:,HQCE}~> lB;n`p"CN[>|ָV(<ߥ|TyѱNdsfӧ;S[ʭޭNfC՞|KRcF4m| 8H'4xso6˖+{:h&G'@xePy* 9mʇezfp3EdcY$m.K36qCÈ6Mv z06M͟4g DLsjHSa*{6V Zn2M+O%JHN_q`2D1Mzf¸}/˳F%>8RV˛ٸ#$)jl+(dG}ᗳ'n3:I#$EҼX^:fSnvc^c4G8+2Ϡ#+u?ÿ7-W_9VC 7 UnmDW.Gr}va<ƑX&SƖ]d"m+uEO^uhqfvќj5RϽ@_ @s;~HNEȉ` X~ @4-d5xCF E*MW톓H &)6цO?FXGa~cZƲ@YK$y?:L 3Tx|㴦;!WW ) 1gCbao5Jl*1jx$gKKKΝi;^1O'π/q_Pw1WJPL.mV#usWۂ]StEGP Y,γ -%jdϬQ忓L1 T@& BVdVL:Ȱ:x}iwH2b|"H:1\lc_F}I Z(6NI Uu31Aw'KA*ᷠ%^Q78_ 8~fgcH\a☒ x}~Z0 5P7 zon.YyGQ.2kT9Pt7MGs ~PQ ?x(KO/8G`f}^xUR{EBjhJ:Ad(Ӛ|+4?:4S"!(unD05X!Ʀu ̚gr ,qj80gS&'EN~--X>maBUnwb2Թ8F9NIhm iLWgF3Jߗ_.Q$Z;f~EdZvjrn`tuAtGrGC T6 %Hdρ,a { $Mwzˆ@a/j^N@VqAR?a=5+*]3W9>oI?ozŎ按-3 $q+FY7(#E BA s\Lؘ[k@X3 (=[Ѝ悍L }Tb̚ThJM,H=EZ^Gk:7]G,!a̳8]eq'gذNuQ,n*niFq+%#XO/Ttd!dvF+&mV "B?%~J twXv؈Qߟwgg&[0&~i 3u4AQ jy6MsW|K0Mi@V 5G Ү'pվjv ;iH(ƮH!_}vr'aT@죧Vikc[mQUytlO=@U֏﬿ ˨}Pz;Q7GkEf Z󰄺BIu 7;^>$?v&:2\((.}^`ЅC`( K !N[S-us^dF)E(Hr׫',Z9U\Sc8Ө;ֈje愫n mǨn9Չ ck:_$q:EKqs@4Hϓ>cԵ5Z1'5>XcYss:T%Ά: "}`a6Aƃ!kݲE@NYp_hTOqg*CxnmP\z!ӯB!ӒTĘtm-BnNZjRkL}נ&%יEY;{a8{o2;X&:N1SAsfbׂ/ve"OV GپA5}zdӍI)/Z*f!`m60+Λ=b”`vS:Mj֙7${iswA]:)Lz%nWi߿H~^i8jAuF+#0T;vG 3ċ+[O$CIۈ›b/+92 'TAkAah7UFsEZcTPM&t3h\'UwƞSkc˄ߋtkCL& k2+h)Bєywp([R 2yCR16FUN0;y% ˫Ji-aF#Cp4*5_JdlǩI0~4b넉kCb۸& jczmor^~-!ɽH$u?ְRt(O|/5jbzǴYbI3B_a9YͽȜ-[^ak*b3ꝣw"IXjn'qFxBw: z6Ib6ZEs@fɂ9j";5a@(TTTP/^ls1Z6i$9jMųdM†òcC! j7}7:dk"tGiWe z \QE2@mqWE%a.g (` IoLZpգCm%oQ[JRAif)bSl`LKB VGhJAl/h vR[zr9c5 [G4 4$u;D4( -ۛ4csZ1\vƒ%ظR;?sM0CbJv8Yְ~P+/A3~.nZ !!/-h/[9ĎUaPM c!?IT,R:l7) $"jl1[ l_ [\p[ᦷF%y6(`ߤ C,5&qv#n^41lmbY\[{Ls0_xS3ݤ쇶~}{ Za;= u5د*e~mxAW#bkR]F@1$>YZ2^|--4GLǢRwBd*]i!Q4oa՜ӡNH5z 37{w'< \i;c KYRw`G,ʴAzbʹuy޿ gt ަ|BxF\~n/nOsǛݐ3ؖKx–azkJ۹ߴU(LgH:Zn; J_7΃У!)Қ~'d xPqXY8"k3zI8>ԡ.,-ec\ֻ<;6]XirNa ^"*qq#2}Ԣ[I4!*g.FqJ'#QqdTVr }Rv^d&x#.(6YN p+3w_p + 1L.N>,Ni>ڝVN&oѪǁ^U=r~=@|+⦲ W s9O{\`V~5c]/F\Xo-#lAF;8~S*k14\?{3 e k(Y>EKc9Mȇv0ezn(L3 x7r)8ԈjK#=R$;Z?iȫٸq E]YƱLsXy)!qMM?5nV3"[hdep\˂%eĔ  G@*hNC(5_mY yr`꭛W )qJMXԞM.i$+ΞyܜDͬ| a}9hS7m<~UE}O߳hd!  JUOzU@Q`FV=e.7Uk; l*ͥ,ZOʬ߁}]w-C)6^9._@26ZdJE "vK14-N6*',LUXݴvdϪOU9U{%7Y5kKE; fpg HFbQI FmZ%J\|ckHM ,lAAl+kۓR'u$*B EQ"쏲Ub2m 겦N r`TӑgYWAX߀w-ĤLZ P(+Xi?c ( '$fv-{ _|r  $-:Cq"vƲL8BIn*"}eYa]ː4Pxqm6dɨ6iL.C: [DJ+YLa,.zjE&q0)˖\n< բ%mm'8^ A#'W³LcYAgCv#fuQ1ާJg$ܜe_.Vn6kjI2Mىf,S_% S7?掟Sʢ yE3KЈ UC'C˜'-:?͡}VSxAWpWN UVEEڵ{牗)q2<ʖdM]g/d"BWR2=T8\DD#v+L~-ZFm WǐCџӂ![$h [p)2ޏ+Aw6'뗰wE081`0>NejeɢkoAn1=W{Z[لIV~!㸭]ůy!{U>`Kqg70ΨG3K\zNgtg`r g}~PQVK^hQJ !Oș f8A-Mr\Ɂ鱧h\c8 %"$tʆ,~pOMh-T7r[qG^_q|0l˗ 䃺!5cXm=RN|aC YO PE>xNu!9>* 9Z+N{l) (MZ*IȮa[kG"$F讪 %uku_+D(dgH85K7@ޞ J,Hz'2\>̮pRVowU> I|Պ~z nU؅/qv]rO|mjpOp*2c%C\ FW5eۙVF '_H}DY|at>+P ZQoВ>᳤)بT-G8ˋ[i {=-yox1~yH)uUH\} i5GL}sJ͉XC)IQ 'pѴ _ d[ϊsyw9oO7-Vv&60MnYl÷P#+rTbU/ 8EJߥCZV­J0 (/0*Z>r qm1o}EMb1P-a/^G"g0I?Nӵ5T1LoPrZI;xsy!PV[$\E{c;`m\ #,O$b zӠ CfE?^#+>۸|zfsi. }s>_ XZ_' Mcs(R7:6 Ps#)s/FH{o2KRcUq ipC^}>pAr#Ȝŝ*Zs\f( qS79.+l%O~uiE=RЧ}$YCOHs29b=!In'B .2!z ;Hfx |t2ftY Wy4W5,X,7g^<̺x>zA^ͻ֐] 0~Q>JDOe,ڊA rѷY967\N$o KjyfFZl5L=3bn66vdW>thPZi2cc6aS1t ad\NG講kh턉[ڦoZ98JAc'UՐeck:TzMɚ\ʗHyYst&!븵}x3RiwYRi7z'cA=}q (H̕b'|}P`b$ Qh`U1{b_K5!'C$RROG 8;e[f CMQCv).:MFB2_gO7[3gk+eR *wO|y`_OgNh w.HOS{!vZ=4jpm˩eW%N'yǺRDXjU*,'^<'}9XCKRP ^lXaXp JaofιpR Sy|n "fyqֽ[8GaZ :J>=2*05N)IlPGxvF!Laf-ĉB,?!W$#Q@Rn$̗_y[s,Νhb^F1nHW;lS,c`z;8&EW׫*t;ڳ9TG6w jUKEe_`Gn0{-t 'D5$ˎw]^xxa$"q. *+:D؍{2E1%BA͞™ڏI8Qg߼h gafn᜖o{C.[eJFA{w'KuYԷCBv;IGSi? `.}7XYS.Zb=sh}/y;6|5rMM[nw>0>O<)M:@mbM~+_# +RxlsJM));߷}&K5voͭzݛ"vӶ) b!MffZ22K!G~|1*LH/r+WRMvΌQX2L]@eg[CD 7)gqtaǘSB)B0pg. L^5,_ 2be-x'JDmlsH];pڶ\-m_^ vJEZԟمzɖ\%Czbų`Mw ^4'?'.!0T箬*[mZۘZRj0A +渺5]jw‰3N5Ȼ&^=ЏTΰ ;zhkˇr,B&4Қ~K})" L<$nm*k`DZ0t9grQ10?ő>,ee.#sq-tNv̹H'X1lmL)FY39d.mpe0_wg}\A֖r4 m~|0n̹&0~OIB'Q Bfh e_ͨ s\cDnYHY÷^VFnԂ+V苘kw:?_Y]*w& yu*?^Ag Ss1A+v}f ԛ|iWOMr|aYy4Դ'cB HDhanI˖Oݹ j_dl̨: VGs[QR W5%OQ9<w?6^+琱7 S>CFd)^a'V_"'U8+CLjtj +FV 1]h|#>/QwƂxF ?y'ۅi:y`[*qKlMVZv=h?Z57G*ZJ"E@qXP {3|#S,ۭY+I%G3$cŢsTK !ePsܢDӹpVx*Qgj `ɞ1!'wڽ7.j|EAJv/~]ݷ9K @RAըt~g:.nOAp=䨻gàǘ5t̏dA!-1vrq}P/X'#d]9Σ|ͪ\yEz޼@qt6|q=_R>\ Q9!aD?(C2TG܃Gl;[^MAؼ#nI Hńu*.^$?"2N7OZVE7mZ4͎Zv,[3@<Nx#RmuKCAqpZ a&(d_[Tovf$iP[F;脲[CYr64yi%6pAC7\Tji™k뜹"p[ [CSVhe*5 *!s, D8nqA'6.&Bδa;yjX i~bV8EIw }/#Rv{#: F@:пؙ̈́$,NцĶf _V%mzQz~`ʍ!Kږt'$AżK5:<`$1=JrAn{lX7HW:n[C"l*.!f)NH! A-#A=}4Ԝyus)Y*e:|DA5Rs O[|ThȄ~ Оw8 v.admܰ8Ŋ;=;e:Ea~UwzϪT - ǴQeO0bM)(:f_HĹ  }aCk>|;'ǭ7A%<7{O0J6NG/xW5jArj`5L&PeP7qHnM{G1)`lyzpAg0+3DOn4keu"{IiEH@į-b ΌdtZާN`|{^pSH1B/11)܎Lkhb1M2ZXag")S! 5xbhfDW.*s>ea^=$g Ԑ'$NOԼsN u${{sw(]JX VV>}}E]P&K̻f!s[ U*ikc n8[%TkpO+(m$]xDM^uO72"Jl\%YeޖIV2>{;tMWz-%ް@7{oəg̛`ם\!a"#,ةDB/M;<ŧcɮLs @솊R oİt̟c%?byZZd֑0X1 nIMi 6ZOǀ*b6cpuoW'sOx0ǭ'o4 k-N (rJD}ZۿxǺ7*3:Afv&Tˡ~{->ҕPK0;bCޑzNdO@綟$I)ި:\B}w @ Iv⃔QÍs`$;~$E*5: ~hƩr.sȳ?I"*[L?wTܹ)GͩQ6tˁʨzwn ,G!op a kĘC eٽCnu-_dq6 D:+brĎo?25H>Sa0#$Pҍ=T8SK,FpCo> ԂCȓ@e1fv Aa!<9 #&;bgNu#S̿!888qyXڅvЙΣ2[0Y;!Rg | z/)([x#"jKGF^,Ϳg#_ΆC:kϖ]u?H_tu"8վ8q_3$l~K~,_vUtDB=(^j2WWYezp’N'? /;3#s):ήxn&?װYASy1 'TTzgT#ޅ gV=n %X1|3MEI?\Rj>"F 7s~ )1x'3m^h ,Gpw-YOOw0](^h4ßçQ~HQ(;h*c"c(HS3)l҂RɫWjԿMNǤG4{[17W/kfDy2C4-Om3ndIyOO/pE9$8#zV5b-襒z^8?ՐC6siԅwoOkD lBѓRWMFTau/E*]'E1> J%Th? smD[@2E7K|krQm4ך]#KQ68~{Ml4#=u{[2F\Dyj9# K\"-eyIȒM:?%iȕvsN66 DVa^v7.(gm/hxA;\~q]WM@m~ѥ/2i{9^PAyh1[q\4+[ q3q%5^2~sҖLf&QUXFbr+1 )'}3q,7#S"AMrhWҏGm'C1REpB;rusY'ӵPOo_.*V_YY gwyPV+˧c/KE~ԯbY˾E9NcT&UA}١ฑ#U $dfzrd짭x'Q剑Q^>S]4]ǔ _&WQ,*n TfEZ8Qf ]2O[Ă'!P=WA!wʆ‡&(Ơ^fg,qp׼+a).үz0P!^k{Q=N!?E̪pÈy~a?g\Gj4OZ78O K[9T,&\sp;Db3dcV YڱQ_Jo"}ӫF@):[k7b^?ɿ%a AJ>ѡ+v3=2; ]NҬ jjxS6ENZt(^DTv'l3!b<0 7>U*҂oMCWz>Ir3OFոXԌR2DVqSmϥar-5Y cnt2 US m8_$';=VfܷI'gHhL "ru%# Y,i[#,88o} 0 j/Oj5^WK5/V?(r%iI.wH-P/ vzkiȩ5LI5l-Q4>¦(CN00`ep!iBo\I̫+6J%?ŖB,m:{On;pB`8ڭhȃ`#ۜ9  H2a&MȽamMeZn\ec<e?Xxn SZb=tx%E}K[JCdo$OѮ6u+Gr{a%XvwERĵBRokRCߟ ,!j?ENVN+ϔ rUw`ߐPDџ:eLJu LyΟ^r:8)' %صѐjJTF6lx7k iաa!x9{ 5*)>fbdKɊ Rѩ9[}׻^)(ܐ Зn5gh۝~Q^^dT\ j)حݏ_r =A"w A}ZR=kT5"dxsGBijq@0!>]HTwv$=9W"P#D@~ItZٽŜYD֣qeW)I_RŠ#< o^ҋ-Fiu#` ."m:уL%URSMB* 7'ʯ4Xd Zɹ EXK-x]d"飀ykS-qf4PAͩ+$D)*K#\wB$jIESC#^x2u y?cj6,O4dI Y a Of)]o=r#?׊t_c&[5f{m'7)b$/N}+bjZ;b.|kd E拌?) ?W[gmd -~.$XR9z c@_")=+ a?(RӲdRXdS'7Y~I^4 ހ :_mI}`uUtpABQ?!u>WH tZ>B&?W8*n+9/H-KB%Ł),}>@F#S׳͜;ډ oZJj'.jHXP>Cu@cȄm!wZf~(ZcoV Z̫>+cEws!][,$j-%H87SbLqWzIr0־gd5:'pUWQ5ڜ$D?D*DH1/)V$ӱ|Нy7;+`r*;6`n+Q*Y w>>c'ZkTaC5jGc8"7ݟvR9Qɨl;lݘ>juj#\ɬJkb PUHBbka֒Ȝwa-P;N>;kklv+[mrB} \%F륹PoPcWp}ЉALO B0%M̩*߷6̯hu# +uzEK㊯LhVK0IaU۞7$l3qo.'3_:g֘7:H+m<5\IEc$-{TqQ)j:}i=G ,2Y*ŨXD|fn )= Z8}UI* yRfe>נo?S~cb7p #zJCn)c-F P~|TGyEצ_,orJy%l_.YaYLSX>i *hP1b%Qֶo X)9rBXmrmH\s ->EƏP?5R̓Ǘ]IԒFx[xnKněNm|eX-[搁nij3=cs)G\ҡ T?&W)PDzq+p ޣqw$TӴۡÈ<~u$`K6RK`[mxS.=D8aYm?Al2l;Uo+?ȷEчb\;׸1 bbv?È|)iOHP ul`Ur?98aɴ9JgtƂCSr +n0it;N㓢DAo$/5Bd {p}H_Nbɾpy-/-$ZO*~d$7SVjcF3 e%Nz1r1DPi$a?FW5H\Gd4Pjdӄk3cM'4 ZMxMC<>Z<kq=/ѳbf8{r/vfsލC;\T/ڍv;y0_;H4]`2b_KL:7u6VbV,D=EJ->Dgހ0do6 h6!1tpHvO7Bqz &k}l6ʭCQp} ݸVs2.9hXڰ.%fq7xLq?urvS/o7GYּ45BլX8çIrwKIw߬L>Sat61]Rǒ4\Ӵ1j\z`p/nO?߃I: 6wUOo֒b/g˲Vo OKK !Lj4$A]EE!/VEi>lP`F9 G菭62z,U^@y״a2ͲX*#,2$zޙ_U MFޒ]9Ri E6M Yɞ#C3dq0ۥ$/9S %tky芤;CZj8ȀcBT"( Bܢ @:!ˇץU )`Z sdAֺ K+ .`ӖR;0 R|!^~`-EK q8b%Gu#nA_ei=Dmh L;^7LMv[&R5F*)vf=NWYј*]9Jn ĩijHVBۥ//LA^_T֠xxe8 Qp |r78j*$AU1=%:e^hOb4{q΍EE{A?"e01FіȸeXl}6 hvBG' j/ Aܺ,VvuZt< QG ǟi3.qmaKg +'f{s )e;WRP<@1WЎۃp*@;Q5㒊{X &sv vy `|$#bx;~IyX7zhooɃĦ6%hxY2`ErWpJ18qEyL((ゥxoQޒS.ap1e>G+ m9LD)1+X.U`h{с7D젾zz=~;- /X̸œD5P嗹~;[ߖ'n) 25(BZ{胐Jz1>Ǩ3jG# 񞽓#k_Kg>Dk3{kӄ-lQ Oc >K2!(1dJnLj[iq[Y2o65q,W,0{r7ZUZ}o^!Sр^˵ul'[9ċ:c&WH|G?;S V[VYsXXLDzʿ:[}&6`0vyCGC1?[ b ^Ss.eu?pnEFXFUQ[4-q\Bjx(c8ʥ1\ *8fMC}d=+[+hF=Z] Oz'"q#Yۢg&hݒgyֈOEcR%CTAkW\z(ʟ)()^6b&="ǾrrP)'رD_3,w% Y$FZrwr<S{yWB[&K5**ʋ\>ϫGr :o*߯bNxfSH:+ !n UÖe&_SW W2TA)R680Ev*ك@b<!Zc`4%u"@A)XDYqZǫ@qnWy_z\aB1[ͤhکQ5x|Ost4bG_PAҿcBo8s:\1l|}`NfdH1Z'xf! wvcfn 6@+7{5[c$d\E6V-Ϳlh ;%X5!S?#*FNQno (Dhk1)>сkQ)bh |aMB7\׹ɛ< hng{\ol@XXBgVbjS`󢌼97[Z;G4uI ?lƋ<*^Os;gkNl/͔PZ+-UCX74]KWN͵ d# DnԔ8{)C[Z`oj_vEH0Cbc!kcJ?#($Z%U( aou@<3P;È8XXDn*"y43d4. ~w, RM_ꇤ7pX.84,Vdz؍xOU؟@Rmmj;u;e8Aݥ ]`hx橴N#Si+_`yF_-~pvUve q s,r09{Tql+؋TҕBmAoA$ pc>.hS`ɀ=G!Y jI͌F7HUy^}TˈJ+]쁃?inw}=Uϸ4۔î3O67+(cՙ}eWEoj u< t8,!0:lL^o<B.z>n5 (a.C ceahXRssVTJqVLߣBl79yPy zbf^$ 7Y(]0ZTtZK- %r '>p3yl%m=ʻ8#Ba`zмv`<H&d. #Z_S]A4TV':6ԑ2vƘKj]S s\=5ks]c e{pAXKm/)w~m=0H0BPFw L߄$QMW}< 3[ɗ AKz#\KD 3l4k~<7|h^2jj;AJF~*Jh\:(&W+zZPVN@.BKB9$Υ*wVruS\,V,͉9P+U׈<.66m_zG;V4?kxH-; !h; Ic>̕-ZHW!Jt4MB7i׌NBHEp+֪V^K7_L"tlKņ#z *}&` ^6_e)2$+]F*d꺕($%`G휎'T_{9J㎯4 MXZ꽗LZ P=@`xIJfOMsD'U߾pڶ>YM"X45Ç&ݟn |B7{ybxF܂f277jvQRQ%ju:({i` fOscQ@gW˟ no7!)ţx6ʾeNVD6H|&PD$98"5AL_,14R/0D̛ʲ+ISkިB k pa?[lۘWVfd mI##h}4",jX-*Jf$:TY8UxYcԄ&`1 穐WYs"=o"0HEO9GΉ aDu. TlreЈbVFvzJ@դv,_WA3\ ^l7='NԿ- UCm1mȢ~ 35wqi"M-\ 9s1V' T8J|!׀vvLL yŒnmRj\?M-X!+sڟ*A8< B1+#+sI^o'A' cF;Ӊ0 ,-6V6jeoLY8B}yy;Z],2u?!iSb'dW$67PL5 ڡ -9FNy9NYn5^~B2N T ̗=;F$9&x}%ȅ -+ :?QE{Q5DU 7Q?JQ K;8]/|-@0 RJ\@{=0@g+YIԞZL\'sF|a6]66{.L:AR'RE&!q^8 %շ hl׌(y;$,!Ig*0H i(E~`긿 +RU{*=>}Rf TVnnzHμE5bXdy"QD`]pd"pyQP蒂t&b @ݝF: 3G= Z"8gg#)g&"_cW斗i;%ѭ;};Il,),Lmu SsZ"ٳ?ًe1 K^Ak ʪ'f?&I|e!粊A(iXodHtTt;<=ϱP5ߠC{՛)S< ga6s] G0o 4^D8drp6Agn%121* ׁ?%Ƣ2ǙV ! T(Gt$`ͅj˂q!U<ҽX/u{χVh$.bO/G5H&vs#9l\b~h QwE!^rl%!po5_WՄC̏mbs(A˞gclc6VCJN Qە"6YLVȐ( <{FxVձBɫfAsdQ-PvДTSFdysѻA``4{8m$[aՓRcOgC:e&\k'W6S.h o{R5"gCvg|,wwܦuʂps;`+u}뱟TLGfͪ^ul3&\lOp-}oCYăESE`vAYg`n29jDk_-[Z-ŀnHa`9Jx˰'\ʵnhPUF:1-!(:)o~bA>_0"d{r*Kxf_9=8:a0M2 i7ziAF@̾c 0S~}:bqRv6v+!c-vp Io>?ַ+@^{ X$?1Z*3rMJIRS:iNZx=J#h)ni¹ԡ|.X y҈IVόnQb A镄S:US @ h!-E¯~|rۼO$jh]c-6Rܐ~ @IZ1:ZS@AnibXcN];2 NRiB;#m䁁!wwk@VJf9ecY7;QZ/B.:m CU}U5C󍏡PJ`F'1D(V KfrB4((,^g(A;(?Nq*]\+ QvXp;F QH1kWT-` x,_c»Z:|'|/leig#nӵ3،cn2Cocœ@֓6蔁+a# >?~(a&ڥx-Af7+5l.pm3{b0>="(d|Emp$xS0֔FF6xq 1Yc^h?&Ƥ,(7r/Zhb*4\K/uNsD%fan]tNEڽJ 05.+C6ς>[ڃ0Lml6z;Crcކ I/C9`]dd @ǓT.aZmה}vb/=2>=,S^(k~˴LyX L@ #Щ۽{|3Pf ߳%8wv;X՗7ß~cq]Gc9vu>_/`mt& IwhaE0 {3 y(!5dHlj4FbהQZK5uOبm+R< o$@4{Gr 1΅kMnhpx'1̺mJE%O(i TTU]-/˦9}%+"xğw -qNg?9de^ S,[w2F{7V9˘Z5G _.$1( AK ѐ+L |I\B "X 6q_S8[Ŭhރ{HY\^E֚>X/= 2ҸrӹS-ɔ=[YX B?̷=>IP6o2eMhMX[Uۗ*޻vI]"[EDP4pa2pÈKlQԇ#XfQYR3cNO;Q:9+hC'%~-wktj-I6\kHXRDgݘ;nyhukt\. VLY1NKL)ϻyOu\:(9rtZ>GrfY61qDښN mh?Ro:DI(<~OgС?JfʆS(b((}S4`DA 'EGB0&9&RmlA5NƉt|3ƞkVENGp6*hr5CQ/G5s"&&i *2Ec(}xj?ɫM鳫a ?(OSyM6|EJ2gMOXV-b| N-+|Y47QbebPkF3$Z7p4ykIq<E,᭿F H?a/,WR a5t X"ڔ7g23.xwv|t%3)ҽ (l0+ʻo/QB@={n jd&sC +;1Z=l ~}1ޗ$o2]r}'JYZG\GMܒo$3 誮UX }F/WY׀93g |ioUQ9xD}tF^ [W~oi̓FW'{U /]cN2LheV\׃5D) @2N'W=yT0fMn-w#_9ݽOn⪏mIޜEIB,\p Їds̏ZU4 v>~ #u ĸa;Fd$a乍9Sߠ:y՝+2Nm-5xԖhs}.G\t_bcLg.)?J;4 0^B!6&|B!/@v,Ydžv";p͟A,CyS`m.{G+>y,x7VK~Aw"Ee+_K&ȁ2JK=?|a7z``wt{go6|bSV>2lj>%6NŞ!@qؐa#s=Ϫ !?V$Ɍ_`K qQv]EGcA;7/4^dLAQnx:y1,Sذ׏d#L.h?iQe_]1j }t/ FfԳF0,6irK¿0gڎԕ ][,r3ozX:w>HAES1h|Yr R(@+,g䘅jzlzL6+l;TVk)/Zeu^ۤ40.5m] 8Hy_iNOۅ7qC8vfdcCe aC aY?ll휃zȬ\FԪgPǚƢbG@KS؜#߭NnT71i!Wí˜r8 3#@즇7vC7"`) 0uךqsX,G9(2cOsն֌ɂÚ%fY+-PFukVCY԰l$JEr4//=EjF^vs |q${jb&3*o2]v;`)gurBtN6c9az(E|@3=k}tETw0Z rAɄ΄ Ga 5K<2uvB:ЍC@s<{Xfj9,;YPL_0"CU ^zz؁lu4su}R(> |Cj&RE{nfTR뱓t<??,VNa$u-r/~N}ikkM]Fy)< yxΊ87FH}J Xf"as.sIw!."21%=A%Hm>U0f/;4ؓ[J+a 6PVB!+pLFl+.2hO0Dx}ūJ2V=KMT|1p9^K&%v;G F@'L7FT+{\ =w%C_ڰ* vFRJgm;3wT?ˤ @X|b֋LMRWIV- ˦ 2?vO<ުS' A˘Ʈx+n=[r$'8lnv>&￟*>SBW 'Mf NGmdgڲG6 ㈁uX#i[EbtH9 %$e7X*;{ CNǘjNފUs,e,GQxm`:$ʽa"2l Kf p_)Hp\E!eT ~2myJ\W<@R8!.{u~1pLW%wzfSIE:^fM&v aC -Eѧϫ*@HE^JS]( $ݍ}u`|SwN$ѡyqqfWQ8 ϝ\gb>-Nw1EJ䇱HwZ7!gM#}di\ @ܵfiZj0 7Nη5 ӷETV|Ne7AE7vԄ7H??xTGn8I-rVZ\N=]1zQDʷ_E9I ^LkR0k$qlM^-|J8O;g0W"+M~d CR9@4&j6YXD2du> Z,n+asұ\j$t/<&3}4̨MScTh/{5+(>DNN`ۚV 魵\2^̾8wOP\sn:EK%9_ќa3 WYoy7ygh=lM@ x'R*UEVӶK0i%)= ?NUp|kĪvbݾ3X6@V\oƯ=&~U+ˀkzt,yÄɘQAQN5"‚h "bu(G5[:'C9{n]/Cp+fF Eyak*w$C^}%oBjrjeq3/EJ4{|vP\ct`0iw2~O'iheH {~[׸5:'K>Д104.PT!\yϫ,ePkbql}f[$0h/2xH)$`J |#Xv7}c>B̛O,'_Iop{NfZ e8*9bͻ QIr(W3NX@ɻMoi/|?5q-ӻj|ZyYHuun./'c< ӷw =P9.$Sh};)NYQ6ޫFL Y]tƤ Lr!\Q&sօmVȚR>"#q˗HrMLV;f+#g,5w]mTg\-~s&gꁎ.;ݝ-f$#  #3A2h\]PLI?0O1_9,ߢp΀i !8,&amgD%U n)'ɻ~;މ3pSFDpWiIі!$~C-QDI|EUK.\N7!nv*k2وlz˧G)V JWy KZhMiqLrcuԛe<m_'2ʟOδu?dPxb>c(]íbRpojbnCF!A,1ڿE 0O "23f΋k6d/(S2PQ )eVDiJCGj˱z(W bF 8%j$4AL =P6y_F,*M֥mGuE ұ%Exp7Chh}B:XD^~yFg2F`-J߸4he6 +>j#pPlI@Ũ%˃$ܟl7ԿPz# ~i'6 <|dHg~:lX1K_' PۉPmQ#c8\&9kיpmM\^|='b5S)XJ#μ#OXpw7jh'e`挡cP#?@| 7'sDrU!GB}*.;\N%1F ,Cl TmMϲP}PAhN:'Ul:WlwF)!}i,Fg@>rh0>j7>#qAx tZxr頺{6ϵFbBsGtm|({,Vl~+gq;s˗k@_V&&;I-aci'k`̬|<&d!\rI^7K(P v_FϪ$ԖÂd蟫&:nSCuq?ҀP*ldAJB'E@̈́8:VLipaK7-qįQ5AYUmW&}ZtABTh >@[`p3]Z'Ta+eGa;o$ F\Y`ψ>N]%KP^BR ;ﱹҝjΊ,H-,/|iƳ*q*<6AK PU7.r 5PD@$P\ %l9̨L&B2C_*V֮5B;h!揧= +aۮ hϝ~l}4o]=1vc0k^[j@SN[W q kw|XA\_3gr ȔSϖ?(^aI$/2S"b],&ZWpaE E#4Vq~ef?CUuM{i ]EbTMkrXb x˭&OkeWlw_HpF^#+wF0 O ~/5у f"0/s/ujmɸ̧tcmH] @B]-Gs -M[e<^$g^j?HBQ'^\}z|h4s]BFoU_9IE*$31΋N@N rNkJ3ײzq(|h#ZA`SJ,vZ:Xr3>NIU(/_Z%Y(зDo~8yo/ {P6%|SvXHyҌr'N{FN^g 7&(S>a;('V #H=?UPk>Nru1 (UNb=^6^ ƟB⫽}^@RtTYUV!jFX(} &!s7#(lvdR\FnG>`Z*C#m 6S&.!%#\:r L8kzg 'H3섅Ԟ 8eOc\5%9>#j;{?qXa"0ȫK"cfka"3ѣR@0L4tM8GGotGvqgpO $JQEAj9zy7nYO.)a5BIzoiBJF5L;oU4 Y2=R;DF.]EgTnE{ѵU0rQ[lb2GR8 A Na tk3i˨[ EV;ncӮːlJh/BI$+m?/+QƯ5OG:e) pWxFGqr!]ۖRĦ: VF ]6mV5ʾZ4,[IR_kwc'NJ'#4TmրOT _!m SJөHZ9=Fĥ+nUF{wM\ Ž2% v~a>G&S*FNsfG kyԞTe"nc;_$\ 8G@T\x/h#JI9e<Lq4:竔b 8;0a!,nJ:ӸooD3>oL޻ON"7;F20g#C47 fvX92FmWwҷ.*2_i=?au\nnOYz  V/È,DMypAg.zXfx@.Ekc,7^!F$bH$זix놡4s\we'hـghO``,r>sp&Xw[B ߁Ԁ$탋@@Ru\Q9< QUe~<1?w+ I\4{1h0G0D;Cc]ާ bÿvr+^}(y#xQ4#LUlgRl>Mry+_Wo 9>q=A0 >/wD`@}HGEAꪸa> 5,!zE"8lt"v| CYrQY=XP3O~C *ZCrk T)H`zr/yWZәk/uھTdB @xz+i11 sΚ5|M@)ĉ |æM|ҧD_ Zi7P(P|JH11tAl-PAø8)tMai3xV㓔ݔ13p#%{yFO7&gAɈF |mA {}+T~;9WXJae˨rAQ\ep+sN~63_=wd$ܗxq!|j401E 2~UX W8@(QfzFA}F;WլY9O |W )̗v\z再0Wke|zP(3ԥAurO 빀igY37 qbj rxYl^#UYV\s/a'y|x鰨* z 72J9!͕:v.up }޴}T7d-9SZ7hVjU9t+U"kz:w^rSRGA"6wxWWE4APd9t# tڝ~Y_Q+넛OքxCxnALF !gL#R.ft5A,DfB@v뺣2MJ KtSw^Lw%A[,\'xoHBįTM֞5B.^~ƣ&2M`[ilon9d}]gF/&eA͌+?31}NCJcqVU`J|W d_6X^AFpY`514  D<|<=%l|[Hr V{#f}PluB ,s ̏X1t+Sn2nS m_je߉YuYgAû+MưUh*}jo4!kz~m3ןEnC{;u:l>.<4GFR4lݿsJR̾glI{DNvHf W]QF{wbGҏTŊG,3~>ROW)a eUAW. 2D$.ը=[o+TL. Eiu{o5,0NpcGK=eZe6rWėn/r[C3؅Y8z aW^b!ȭ(tpR=ϋpJ#VHZvondB7Y|W]X:/?uk:MN֠zł h#%Cգd.Hf6-x.(BϵH,wR7ag]XaO"+eaFA @ClCN4448|Mѵ5* ]uq6E`#}88xP^~.蘜܆7p  ?JԮ;_}$[fڜwyUsCoŴxY랪&Z?8q ֣NLB0k`k9fRĕß1V>n Z¾4΃r-OhV-@W3)1i>b2ik% 1^Lrc+e 4woBb&Cÿ+m.ɨs IP%/\҂b~\m}]<'Q^qy 8wv}@k1k Q[9d_h3E?P<[N1~6XvA vH w;`ƢwV-D}"jw/[0naH$y#pG̫4ɍo圄G3Cs[aMzeCA\Ѯ"U:O?iLrL]ŃRtԮ+&&rm}GyMEWD=05AU9qN-p+\"2=ZI*F~ =M*)3Ipo\::,2679YwϮ'1;Sb [L)}v)~ 5’ܡ~200^ O? e]/y]P||SO  dZ|djŕe]9 =iLE.FvN$ qHC6b p,yaڂ}[ w)ha3VFFJY9S[߇nXgg*b|0$u+G+#O lsM/Q (3 ''ve:#ĺ`NӹK5SSǂހP퉨}ӁXRlvt{F%T"X=]r [pmC0BӳRLpX 5fXRJ <~uEc>[])*-NI1{:QM%-p:Jv&K3w=zh?E|/EDw ψܫF-NbUV*[G7gZ>&٠@#xw~BD8Sh|vfmSHsi0'AANGAdIƫJB@>p=pV3#s+m:Ooch;[RBCO]>H2T})G;f ?[☉(DãqLߙQd` w^BF0jXH"{#`bkKO8|Jb%4\-H1B!so SA['W(~C\DW̧uImu%q7UJs~>@]Zwyr¬pIVt;@7U?8DhO9{VZ`LBͫƔ#|W$/մ}T!)vN GBʷSy7 L[R5QǐTzk%--9[HN[MQ) vdba9꠾' ƀL'u癐x|xSeQ),yv^ Pluθ␓uLSHr\Kn|4 Nޙg\pϡ_\gb|eFaJcz 1dV{GӀҒ GK>|+яms{#9dzs~.ه)vMQepul+ )nQ7E$ ̴J тMÂu?ߴ6l\MZ9EtXP*.sGRkr2Pd dv'FiY%|粷V9w}xU/ Ξde}y1aş'-nNUҀsoĻ ~ͩ}!x4a I/WM<14jb"Q7c1DrKD+A)Q44a-} 7!ЇW#b餣vߦȿf+!g,"uFм~f41cü_{hBQw 6$a"X5jOH0U Y{3!O]z0KM(@:jͫXR;%m8V3?&7@%ykC/An 7Τ! nP{S &ibwJ[%F%Ua8 Cݘq)?nhopܴ 3y>*fK*d?*tך=[3@PbQn}p}\S58p(Y`KqeeW?,8a.@mD}NWW`QXoH,`9Bd*a.;(a~_/xk0wfVԱ.D8_7 Dhyq㉟\YpG׈}%뭇IsRǃrJH@g?o(7X 8(mV#D  8 xQ:C('BĽ~w|D"e qzKW(c.\mLƔ:Uˋ&fCKAr+UKCרDxPڟizz'ʾ$ 34^auIY.,on"0iL5 @qE&ڦ::$ `m*wniJHu%&*#me.v~7ZuPt;*!b5kuݍfrk>x!_F^UH=Yd\ ?[PS§jCὬW~VIL䂼e[㛃{\]lХ]K9gy9Ȏؕb)S2m[hvhG/1rlN~^d ǔ'WD%2o% Xt-`/~S.ɲ?{B?J{4'k/7v?Rtk΄6~=7Ԇn5 -Bݹ )g(ƳXUilʵR`pڽOUJmhd5 Uy6t.?myp˷۔[<֦uH'tIj9aӦ(X -9|+y+~7p|'zۣ#iS"ʛb:G~Wݛ?sY[>n&mf1ӝZ.9UCS E@?s3'+-d:dl5^M%(̞PnE. ZhB2ò~Z4 \O 1?t?+BMye?P*m,[ߡEd)nqu׶['`p79u&G YJGV{X 6FUIͨ#|ϋĀI_4+Y/Զy r2UPOS^Φ áa4w!Iha/zΕҪd*{* IxuDS!+u,וCR^o],gƇq &xZ}쳺n}hn}r@?NNI%fhXĈ>\,vL4w'QKKϣPWdchP{8K Dj-τI2_=;IZEQD$DF:d oFlbA0%(8m\Th%4G0$|$%/\L9w kH6'.hm8)_~$S^N(:[n' 4ޕX;[f*5ICm5bċ.xGWL xI/ĶUB/.<44;VUB1ƽӆ< !nJ{KFRAr"4o ˹X"ͰJbl8Tt1՛Q+QMz#B'x~=)LطL~O Txd\RM`ùCq8c-;S>gԽO݆1v1?ܚ.l8Mfة |gX`6&:^ZñL^lo]YIwҙF `͔SU5ȿZ @#3-dh>~ )rr{!d(Vkn#^@fc(!'~čh.k:6*#Խ}~T&P~=‰yD;~pb-?IQD=H,!frGd%ōpV `0;" S/hG> ˗u-C(6'L+VGzmոm]<ͫXe -E@Y1,9MS[6y֏&r 5`A5wMV60(D7S J;Hrch!EFa c>?VT@϶'tkI~\RSE*y®Ơ'~R3X9˵Y4d50;=foqN//r%Rrc ׾<{К{k\1mv^ϵ6w:Iƀ;^&՚Vց $o%8j$.˫wա Uf,QkX rLJ.?*b FjA~~e&({~5X9ymTZӻ9m,R6ҫ 6IVgY-Q]TBO@r(3p/bש"h$}ɍKeX:x@uRKa!D0 bB::G\m).43GU%|ƙ{. ]|O{ #0\k&I6Y"KN3oL h\CsSs3 )i?x;P2 tY44<-.r7ĉPz~3-LBlI"ȫ&\Aagߠ(R6B-z?uZ~95ko{SHZ5#E)CfYvbZ_oU–^Y*͘^茿G300{&dzx0j9#5M9uΆID3Q Zs]IWbث[<QHnm %:2 \.AP$1dE$F0lKS>$kf5UǡQ V3lN d>@Ktx-\ayCXiq2  0'ac1ٓaMx5˜Z| #CRd$4}"{5IE ϐsıq%[O: p2?һW6WSjr:XTx?nn07!,t,g\2~l&(ZH{[t{)%!~Qyw:wx3X]E0(r'bAԯ_VYp+PIɵ)xқq`s+TڂV)=Xۨ  #mz;:zͷ ԘCY`=SFsk1ȡ믏;*u)~.GΟߘ->[I,:Zg ٺu~<{n==@2%]ӕ6Pn[tJG_3ׇba+4X|C|_'Zq 1*o\y&(Bw!۳rY~*E V .O37ke} \lsAVPW5$p*}xa9~_Л3O]mJw(YBPִnG#:]Df܉mlgxN^FŌj>lV?[H_Gc"ʌ_$, ':i`-p~c7NH$Oץ^9rS*#ɏ}X? a.* W|Cp: MA[ڠ#Uiw彰Z(Ho[@8c~g|P%n5ޔX7HZQѳdSwv$l!Ś2FEj&09@~# [fTH\Ȏ $ :Vq_/c1w4ޭ1(n0 reE]>ՏټGQyo11Q|($9zC oxrYUeٱ!@ PǼ1M_FB`g`54ƷE j4Y vsD;43[K0GlC4_UqɴOtz7;+>fm M&zQRF=D_CtA%$ꏛ#x3$t1AP3A w/$,~xLy{<Rз g5H]8W= 4Y*9D_ Ƚ[qE(_˫Ņ*~+מ>?S_ݎGT7fo)X!*+I0دXH]u~*d2$L7,:Q?q;0W,rTߜ)tscWL;{$Ĭ#¦^g=ԇu_QDAZaZk 鸿u/.ݝ#6Alo̷-B*"nJu,J:&Sռm% K$@`k*$K eD[ I~KP'3 $'0-Fr56 G㐙O2)cܾ9~XH-06PkA9:o/^N1oO~8zųӃniOX~{tk|tp?|>n{>$H7Gcn Sk7F#L(HM)%W˓%Sc 2U^/ey8$KA3 *hńᬔ lKKa?|ʥ^B, qkĊ>4/ SY4*{%QP6u_j Ҩdf*aTt/#ڻ[3ګZ`{n)vXd-Ap% @-4k3&eYJcQ٤/p>7E崤BTYpJ׼ ҤM%ϩb w!AAћC *"A# XcI4 n-k|(AV='ίf&cfC>?IYyDC w#ť4P 1"͖q홍>HMg=3]lI F5gbpM;{ ~T}(API|6_dy+sI; & 8/HF1K'14C{r6$[-p+L>̇{PX*o~ >Ⲫffok".[6EzȭQ'A<(!gٰ,L14,OF<[x'l/-ӣў: t^!P>[$o$>}̮Q0707010000000d000081a400000000000000000000000165a2bb56000051c9000000000000000000000000000000000000002500000000./usr/share/man/uk/man5/sssd-ad.5.gz{sǕ'?>Ez $EI{uB"-1" C(t5ᮆ$nH РWoYYoĺ Wh|瑙' $ m& #+'wKQgwXim8Ǘ; XFo[SwNo[xx]?R/lEd1Ztұx~Fx>୤<|F~KdZ#IFx)]huSZYSܩf qG`#gFϼy'n. ?Dw{ÛjHu5nu'[&O]zBsQOSSoG/ϿtNySq/3?gdLDKv'7kQY;'G#]OOՒzQa/_:?O/z{7<^کj9;sx>TG"zJtx6-zg \aMlpׇpz밫MYx^A=Y&}1CPS|ST+ 6gDICMzߩܰ/}sM=/ >9T}F(l55 f,)G>dV. m<2}QïIJ&W&/2tIPK-sT4p>5:=pjb28՜&;z1^Z7ף_č4jXY xHmkΡW_Y'5p)'6mrכ1K.]jvюj',08+UxSyHQËW[*/SdFLC܄4\62֛' 2{'j%;Җm5bdkq5ߐXA_M\ǝ TK [pO|VpUAehZPƟ7<=F#o۪ׄy<gO~^!n7T2RZ5.$3svaF:~v)|W=Mž< ?ܚ* Wl:F-z.s,bw\Kǯ},S=N><z*d3:?1:3U6u@ZjeXm}|ORџ4upxq#L]N;FĊ.q9 o]Dڞ~ц-U|*(PN>°zt47=R[=^lc9yO읹=CHe'<7{o3˿:tm:tQ>DXtNSD*d\o:®"Uڳ+tHafyѦ\e ȡNuubJx_wƳu`X## رK^z \D3ݷe}p" ☓H׸ n>tuM`BMs X?Jhr00cGȸ?W}2O^ޔ#̾UC%n4P tfB8N~R^VQ0+k3b\oFjsClO4&/0-c>j'늼a#g:@Ё8W ΃@Wj#Ӝ`CS|E?^.:~ڏyuLUW àE[+!R\cEwԗ{y.'7.^VJzs ͂Jt4'7 xTm-.iNR"vV:/EaшV;plupd5Jz \c&J!j i!ڭEt95&>mV=郸ހ<>Gx<;߹zrI. Dsx^ͶŝN>IRO5`܁Qa٤т'YV5nj{iù %cuEǴqx#ڜ}QVseݹmF2c^6q#K>ԍm_tCEޢ  F^ƌ!Lܗ\)M6VgKJP~H}|4@[C"ډ/%pU] YAKFXD|)Y3f7j 6uǴؽ<ѿη ޥзJS{|  z=~ ZA/VCJS_ni 5wx#"x%=k|RZ"/߲w6OqBxGv͖(Pln znɚE%"l_;$gwDZzJ;Xtc/#B)npFV&BdoɺmBRT0z>ىhaK[A36Zg[Q^֡g*rf^ύ0 W8L- 9N7uMC$j4#hCk;@5gDZjd J:9]=wG})Ɲ<?,+%W$ N>EMw5qWL?aH7!Y[`Lg:h }Jsa &Ki`/cC3"(JkNϒ}1Ljp0ɳXEvMi x5Ⱥ%}1v&HGֶBA7P<+ϣc촚絗GߧO=wAyO1wƌd&ݑ~&4;u#x[1+6-h٢ .Z(vbtAK(֘@.#dmlNep_Qd.E@oWJb4r-+g!;$$ˑ 2kAΥHKdQɅjZd0NܦUOL-wkE>Vy]'>=6.&IqmL+ۭ奴Rš`bgXX)53:9p2w^NM5үWΖsMU4y)C*&i&zťYfwRLqa"`ǒH_ Xs,92d- ZWǏ9ɞjYfLϡ CfOց38z+!d9ٸwFk~%'΢PE|r[fҗ3M)ӎBŜ_.წZ2r\]:a6tSV1*nXj:(N%뛝SpX๖/1_=!~rz"&Eͦ>- 'g8ej{tkX#G/jvڭ9ѯ#L X.Y&3{zQy1.Ax T~D4 v-7}7!fߜe-"@@| Jr=@ 0YI0`LhmOd 6/;::Ðu\צ%8k$+&Wfn.g܉p~ w&T˜)i1^rV9=q_7a~IaZzmt}-&'8^Y(FM}N^8wLzb)鮐=9=|zz3ꟗ_m8b{(~g(M`'^{P)UYOd+g#:Gxs@CLzBL5lq%uFPE*EֹF8L >K%iP;&V+RԌlvaNtvZϨ4s"Q8r$񲇸n v.{d21zKY8V\9wjP=șG.z>酟eGtJNANt)>=p>9uߟHX?դdHЮhOCpZTʐL\|3\r? zy_Zj\StըW=E<e9qo^2X4WAD]&\OcߤZnS >! .saJ"_vs)䗴;ZѲ@V9@cOE.kJk6<n5S?gfiΫ: Ó#gň(;,UH\x}NG\Sd(HyF%sS\]7*^%>> V?ST5g0t #fF 2?$&[ci$wXmk`a]{;\ UX-XqD5]]J;dP߼">_Ҡ&:D=9p΍B<(C]csC+I/nM(2obr}@4U>PhcOԯBi&ϵ.h9CD͊;y55Mf6wr CNhSYl=%)?vPe'RuXz`:%Us(:Out$v!MgI4ܬBfJ|Q3{9Nj9 b˜^{WR㵱g`L'M^8!47LmÜj#O:'cC'EdV9F#8d` 97+ ==`OCM]5ly+XGW0@7`#]ӝlRFx=E:/#~  220ꝙZҼV6\P! AwbD8A W;9Pj/'Oȝ^*P5^i7ϊ%{=h^gp/8>*7CތgFf2IXt.xEd*ҧrȨ;p`\"鹪_*Tbrޅ4Z]C"̍7綸`le8U)!.u be/D^e=[j{7Q]7֙؇I_%}ŵV <ؤ?Ҟ AY-fS hhQQNMčl루 74J\ES!ևFK8 rP^5neR8Ⱥ,4iv򇴖rE_};@Q}RTQ=;g\"\$Vʍ3Li뙖ԉjlBV2A#l35lXר2,@ZݮIW7s G\"b+b!kr  U!JD,oxt3d bP vEEMFNs4B [4雲M Qsyn?c<%Tpsy# -"-[К1/#Z))y{%蛝T|+[;Gr%BĶζ=7~v[.[͉By%IoXAQXp51r`ݳrB˫t _. `.j^[^*t=r*"]Fv&$rI(# q -fJ92g y캍032 o'UqVWw)ҙ:crq .NwOOMH _3mHY512Qoԧ 枛m i}%X13-\OUIQԛDgd:luʼUKbfX^MCv5@*xoڐzswzjø\X[j$pVJ;qsv:=DZGS;_[7R[ =a)N[ .N5>߯- GNdNbԴv.7k?s,: :lUOyaaib[gzq t >?,ޘv>&7-cmN*dž3 $+ޜcw_`dA~MyOr/3~u@.7xVlDZ'VzDi&e+.veڒ5y r6H'#DѾёbg HDQ2wC¶ < 6w1 VO,uW{=AvH!ťehhaZ>d;d 9YZef[::KFVbڂ1 `7?f/EVlܩ.1lH^~a_}q׌{e7jQcXr'?2Y'/:AnT%T8Q0l ٞ)G0 ͂j[F܂g6 -[" v-Vt\H$7\2}u(%~M:kO=a 6g-/l 1 ?:_./%aglq;Ql{h+ETǎ`nrP"\a9Wu2͜hF宨 %G?Bn9_\VG|'bIچxNl LPF MSsߢ~:=l<#h,[_Z X r!,\ ¸G/‘m~3=|$NȨZIkˊZTǒ2#T/ D?jYKFg^н"j^H1^U82M8.liy.)/g\{8܀1Hk̲Bh^gȭæ<]l-J6-g@IޕwʊD詖nj gX"߸9+[IڰRyDڑ=**(p|9Kcmm|CH$RV 2q W"[MU;]1ty]өԨd(;gs|7fZKHE*W`Ӗ7ovzhJxL,=6 IE7q,iwG,oQ Ő D$M(9嶌h;1B%ϪyS-bSm,'A-P1~V0=,f۹m5]vpo:jh{ثF3/GXB{pO$KNIZ Bs/Pق6$ZW8֗Uذ{_wQ6BٙynhMHFL cOlS7 |]7Y6Bg斪~XǢk9 -/hI+Q/L/e)J%=*sftkqe|Fk6nDoƝbg_9I*X4݉OF}hĉ:gL }l g ;$E]~rg|P 06fuQ㓗FޚzQOɫ/u?}W:mpHi:g.uoX ܴ`uNlftApz3Amzs+ +=*?P7cϔ}CI TnGgrg; I*50gv:^-N#*Lf1/w|WPV H8jM#PS%֥p7ܔ̰:7]:Y%z"##wublu9ظr:mѡ:=ϻNm</!\\R4#".{&^$[ vp-u.ˀV+5D`;e-.iU.eEvOɈ{_U}.uH}?~Mg߿Q޿«D;}W5}E4{wm֟ԗg޸͟ $vq;Q Z9]B(Rҹc,of7*#+ v%rͨ!yh|y|Vؒ]5?ڏc^K>ioXSb&&&['iȢF?L}M@3i1J>-zp,?$٤JNgI_*#":ti4x1&$5rM6ᎃxk^g=GjѶ&i`'D$A_b0cAVi6J O 1丢JfQ#Q)uB}".A0o =G~Ֆ.RZ~ 1jUC&tn) `*@qFr A4So4Q:y\ʆ2h W[WHBafU,?I׮]k֚)Uj_W ȍ&O =Z]jv.y̐oɼGxuz]C_j%4 wy2-7қ6qVg~ȖMԠ-̄H`9=FtzMֺ6QR=ǤO &&JiCLx^aUUE.ouvBA9Fo_r CW |@DxB]mΪ>ЧU%FNu9/Vs 9NQ$F"ng϶ni4M$mځIS,hasjW*(1=ξ2:׶Mޟ`J0#".q?r`@-f?¢v|LDJ2߇RpǶ禦w(Rh]m#j}I?lKXئmޔt"}Zv HWXQx}L:\;IA\a:}k;Q]R0ލ,Z#MlΑ ^9gM&mLTm!PԔS-31RSӒ|JKz btmE;cP2`$ 2 3;s QR6܅dyQ^H5vf:O"&Ƣ:^޵Wj#W&P],PLj LyBB5Q0I_B򝅸Uo+\Xo\Xb k$E qs6ZY)/VDqZA'n IJT@T&3qW<J{?y7Ur|ي3eu@`6n)!$3m)=dR ^)װn97&jj7{m= ]|VoG) `ϭ: Ziocv ZVӵ^lUpM0ܿCEjS`5'> kvNVFdօ]X/E1=&Tb®_B[2\u?%? 9>d.)RYD+#7Y $:mpF9y2V [K&@ZuG"wX2ӳ/zK7b2 5 l彬ȮTa7~R J`+3XSRk4jסVq4J!gеF+!O^1#ˏ6^JWJ x"09پ8<8ljRl]%3 ŤVȐV_G"OH㜊KڅeBIЭFCC c޵=>Ox3WlQ!3 3#N@HkT;e8tO[G<\w/ɇA[Պ(@{G;' a/ ep6լ/FR|~hz8zWjެ֗FtYZп}ѻ(l K `FBd|ߐO]a]i[,^m6ջ8A%df3lQG6O hҼŘ7FS~) 6wȟ:&}r>Ps z4?(ViA c G>N䡣##R[%, >E iq`;HS;J: Ģb YRe1@[x{u "V"YE5f9%K&q':T^I?% _cB׋oYR&dX}%+3e'Ïqn OLJ6_šmAEbv <ƝC}`L(C; qGҲA22%Nbmg<.%lZ@Y F]s*7daDuѯi^h-|׃.to{ 5./3h'qcvYKKs8m,&@d)ɜZF&s9:U ' Z--9' R\NhP2U';7 m\ѵt- ȩ(JyX1U_o" zgg dChjbiNFh7u#a(s%q& Z4w?"R=8*R׎\oUz(CvLpW;( Bn3xNQԿK5.ny2%6i X2W}1v|E=jD#&htM$IJ!b6n)J9}uaQAA9]I!-Wɗ'EdFLDKʘUy|-Ӹո&7r<9.&0^0@7Wsh8K1`atVR]} dT\n&&1Z+E 8CɰKޝb $tvs_&HA;W_ZIٓ E8l0bA(b '3N%ZonAy>u(gO;fP7)lǯEb|%<*tJnM~p.7wi} ^0w_M U|9+aɞ Kv]Ӓ-_ߢZ kW|xÑyvn s 4]Y(^@q9j $>u F"O8[&CSQVxυf *PԎ-@(=F.L(; =hfzxPh_d15ii=y {-p@eZgD62Ȧ[lA]p)Sirkݰ8Jĩ16V?'^`s:32>i_m}zc8=>K,,`yFioVqʑ|.p~S5{!Ն+Ir^kG֗*x$&>[<5X-v3LF%e+j4?nς=!>E{]m]ƀ[tr攅dQ3bu$[o/M$`]3 @A;hDe|8c;^s߈am](Hd=Y:NdYgPPM?2?R0S0M, xXbI, :|FFM0p\Y YD!%'䭫hMYi+'%/&*jd+=lEW)#%xADBf\-a5Ҝ}gXM3W s!QT$m5>Hڜ :ө/&1`B6P1B{Vtr@gA:}QF+ocm ENeӕ%!GGGmRf7խ}4 _ֺr_=> U96OeMڃ*A.](>9_wLgae}޶5u˒J w_ej0:ts*SjAu~Eb4{eJGدHJ=]3T%Sɘ3Ovu,ǫjtg9corf')Ns\/k ~depV=kQkR!7OôT]zoFg^}M>ā&!) U3h΢sOA2oc˖J-_7lmS.^Ba( g3W8`[1 TTrp[5O8wgE3qwN@uE{O+ٽ[.//&mlMo6m;70j'8w1ѩZR-B7C_K2 퇶Lam'B0o 0[. tz-ps.9_93/MJ ',|s&T "0QV V*Djc)wgV9/A-9LyD =۷&AI3|zM. FΕ'mŅCG྇B#:2Q-^#2h*#йV~K˩SH?蹽a1nZ;d+Sθ Yg{| O8>I*ZK,';𙡥.7'tc`G~ĜJ~Iܵ!s&-wy- ]XL!y<Y7+VtLI_⇨9T3fJY1>U2s#o:,O.Mvd8SҌXk /z RuWٰ+xX1_,4H=-B_V>2.6s~TC,:VaƭK& .NoG΀b/f o3PGGde A{fP!y`s.DW9neUF:PC7Ae|Vf{ʎ]ttftf֏IѲ~1 ]cET<nؠϑ)"݀)p)2GJNa7Gtgc}ݙoz 4#*k7ߐ0.vbK[6,320 Vg53]|̥˪N5\ƭ=*!,ڕ(tSzkz._!P=1+5A UF?B[!sE ݵ=i% Ρ6 HյCL#nHOZ1Q `XvÄ͟,0Iqrˍ#m0%fs( ]9Zs~sS tꃭu:Shtz)\2#sqKP KTrY: K2twONc9bWw9xY1zmZ\;e[>dw2QƔ斉:DUJot]xh d,bKԫ )Xo֛5}.4B=ZKz K>Nj">7lōFwZvv\; QڨW_v+ެ8[p[zU}}8 Q\qRθiJ*Y±fӔҙT$JTo\8T٥*6D)j&CQI ]׃ϭҷ\F+ ͷ}ֻ5²ҁ3KwƉaA6V!r2˘tij2]-\W$U7ǵr2^C搳G{JA_]zc/L C]acծ`9 os5N؛'0 /~GTHcV#W]L#9W,WPn]C"ݍ/?077ɫ!zNiU3I1=և!xE]vUY2,M\O'n_0TgШMIrJl8ðFM%z?7RGorѸ[mOfKu6^-G37/J|J>^]SRC&|P6njU#q9害E3΂";׆NDXŒVQ;ٙ}gvIi'gM!\T2Nvv_(|Iƌ9'0 rNyK 5n[xiQ`Õ۪#~/`yk_.hDȖ~rf9m9+2A}~[wQS= $r}݅e,}5SOJE'/4 eRWf"KY{jUF&VYOɮ^ܽ_b:>\oе70"qKw޾2qq꟨ W&.qʛo9qa|Dw/)4ƅ .9>u'iWGKS/[$Uب3-{wI-{<~y~kxkťF [? Bs^ϙ>u61cTJB5/߹z{RA  =J$M KqŁ*D݆uFj4;uЪ Bx&x[40y/`&{6`"G氷M?.Q+\a2U;~*CF/r(*r>Վ>pcX.h3s*K0}Vޠƾ#?CV^ӗ~#!7 YZ\#n̈q&.%zd Ϸœk/IrR{mADz$1ݫ;/08Z/{̥~@d\"Sn@Mθg !xWf=}'^D+PNB3e֜zY>,M$ >Wv*\~U ?+Ra\!P9̼6 "p˝$~={-^/Kqe>#]2)Wo5(6WoλpSj|# ixofSyI ,xCvRcy.`qekKR{?"" 9UkSs E%hj/UEh7ZI;0\H4D U5}LLTB,TSFx:._ORfKS/A&[n>EqKh3p'zV5=X[ikzH^NG>7ka҈F|lv?׆kb܌瓑妒i'n1U10L I$]^AYbZkWӨ϶j̙g_yT.}sW$07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!gպF#Ț66",]   YZ