sssd-ad-2.9.4-2.el8 >  H   (,e U] s 9?͊ G0 =b^a Þʅ%r]̣lz+E7+n+!4tuAt cSssq5z1BLdn/[HV>@+W}7{oKc} g8n]bh3bv *pfkUsN;Յ5L OzwV ^V 3JsM~mƥNˇhw~c6 qWv7 rD݇HWfClxˣӴ2,(g*όb5{Cuʊ 3 TeO&Np$[ I8S _D5f4aV-g /t˫~qfA.N. }cقkX]eo-je*ŚHH5p+l t9?6ܓ)c*XSMp~GR/_%57e2032ce475b5a85ba6e8c97994adc4be9b35ccda51d618128786fa1462ee47041335d82df8b96a6bb2a5a38153cc517204b8620302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb50067306502303f4aec15f96639a4bc329333e99884c06f1e2299139b2b8b2fca18561396ae98e107f3bcbc311c2aea76b7b7da12c8c002310081e08f3294eaf4b28103eb3466a4c4f74edb364f87ab5a8541ce28fbee4884a19c7159a59b7615d86af0cd44b89636550302047c435bb50066306402301250bd64e626b0c49116956f18246b17631c2a34103e3f81eeb7eb8cd417e01403f54b63b7674c46e74fb2f396d108920230697e4ed42b787f4a37221768bd18db7c8fee7fed4f168c1ca99d358c7bc9a1762da25d0968124f17e1611f8f22d53d480302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb50067306502305bb0bcf4e2ca031b7d6de3c6a3df1f7b4a200570f412bb05decaa6f4991d4458e1b4e33636ab411af3697fcacc728b3e023100992a9cea98d6aadbc3eefaa0eda385b74eb65dbbf5e24197ad7d2ae9ecce312926d59d4785852b7fa1c1a921c67c63430302047c435bb500683066023100cf34a1e5dc74bee4afc5710065b8e9c7c9e377eee877b8ea3dcad3c33a114b1c16d60d861d4dd37ce8402f4a9ae993e5023100cff719c81b7e052bb5d26eca1b59e28146c97db40b55ea6c80ae6c18fb84fa28fe2d6a8a695581ce0833927d5f79fbd70302047c435bb500673065023100d21eec744b6cad39aba1cea3b52f18d2827314dfdec8d9e3198994f32587aa15c45c2149a242a6be9cabbc67154fc529023028cd581e5b873eb7a917e79ebdb203fb0f9fc5cbd8cc8083ae11780c7883c8be3e50bb414086ed0a8a3a935a630c66190302047c435bb5006730650231009d4e0fe3018ab8bb3e6e63fe12425c2de49dff78da86aeab78bec0856e42f6f7da7022135dc822275c0e14c9846b99e2023015ba22d6b64629f5cda483ff9b80da2e305122816ce51abc756c6cb5431526939f19096f8279577248b74b5a25350a070302047c435bb5006630640230538abebc708d38701d1eccec56a7009da1c3fa48fd52a410054061f9698612dfed412fe6cc865d2d57baae9222d60bb2023077ecadc16a59268de2e396925a1e83bb6648b9706f205ab8076e3fd9de2b875f46fa93eb247cb1ffb6da9cd17717ca1ee U]q#=`*!;FFe`w9;U;>ى8 W2\uapݷ`vjCZ'OERJ\OɯKA28frsyԀ?=s.=*#⠆¥E7} @1shH}x;5VD H>w2 u&F _'|3i;)PڳfzK m2>_q^:o7.36JKMNȩNBMw 5єo[h9lķ*"Ѷ\Z4:%KY~ʋ#ӿpt:bږߧ/-E,Wu 02!5#1qu0hHy!#;E \ h1<`ooۛlDRdQ~t}4X{۟]H|{B"ZƱ[We9u6I{{zY59}r/rjI>`E?d   2 (EKT            L   LGhG Gtx}(89d:hG H I X(Y4\P ] ^= b<deflt u vwp x yS$(9<DWdhnCsssd-ad2.9.42.el8The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.ex86-03.stream.rdu2.redhat.comAbCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxx86_64'&hK:N>nQAAAA큤eeeeee|e|ee+epepepep15a80822a3239a024275dc2be1c95419a6d7ea23a8749fbd5706ba3e4aba0fae731f59109552d44dd15c4eb083c8288d0aab8b7c2ceaeaad4397cee6bc3e49cb8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90313fe4a92ebadab7af11866f7c61ce771c631cdea58fb90fd010a34069423ebc38df69abf102e37440ba5cdf6abce58901eea8a20d61adf01aecfdf02cde52d917f9b1f57008d51c05bb717f3a4ba27aa057ead6b6583ecc0576403ffcc82707e42c287364db50563592cd9ef5032fb6ce6898382020ae25979e68a2eb19bb335../../../../usr/lib64/sssd/libsss_ad.so../../../../usr/libexec/sssd/gpo_childrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-2.el8.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.9.4-2.el82.9.4-2.el83.0.4-14.6.0-14.0-15.2-14.19.4-3.el82.9.4-2.el82.9.4-2.el82.9.4-2.el8sssd1.10.0-8.beta24.14.3e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.9.4-2.el82.9.4-2.el8 .build-id2436a3bc1e658e4adaa7eb23838629b19501b20d4203f43b20e6b5c99718b00602a6f4daf898f395libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/24//usr/lib/.build-id/42//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2436a3bc1e658e4adaa7eb23838629b19501b20d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=4203f43b20e6b5c99718b00602a6f4daf898f395, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)::PRRR;RHt?o)^bqpBc"l#u^cq V _?-ν)MuVǭP0pCBG]׏U*]U/evZG e- +DL>29sNA\sɒ%Gϒ:^{s|ݪ˲"T,uIXHĮb]2,!>I'lE!MxTy>삯i$_2XR}9QkwڧVIv Xb k2DzӐP<,{ZJkIKIOpS Ѿ?dMw "6;jxlBxlqYF䆡gD09_U6`a&IY޷YA2fM+*G4_ϡJa'Y4]ڡ_󭇯;;w_mxp"6qBOV-! 77wS^~l#w@LW0愄ڽk @C6)J3 hM@+soeljx. ]|eSFC^9R"e|s\p>ZR$?ȓ1k1C;G{( ( lF@W׶4(4 nķ%>f0)/ЕT,&L@>lJӛOGuLX˂?A%~p}{1Tgb-*VTk <{Vhsm)DCK&Zj NҮŨ*ۭ7/ɫWl;7OgK^)ZVo1y|lSyJ% b޳wԬB a!Rj>e){Hn3X;Ky,򕄈^y1/SEcw ^H-ETDU?ҦMo=m<EfWx-+%t9wU)kB?]đkvA\35].a2*J:TO.-K5^eBAoT!< @q+c"+T"jAژ$\?LGWwًk%S "ԛޱH? s5oذР$_o6evp]ƢK|y%$,E b&aAE@tMi[*^EtKWxe n)=8u{вg=PE1c2kޱ*ฅ`bcBأ.Ge\ /;O@$EXA9~5<."ESA^]#AJ8S7q1?)OMY#i;C_-OsY٪Tv(*qb]މp}S udLM̤Vg6o(Iq˴/)dXcSg 2u˼Ț8-[M㨯,J-W j|`"j#-zo(~7O _@T0hnY(#uMs1C] R[pWMxƌ\f8Hju2N1b9wA>$̠9s[*/͎i{w{>;[8h2dZqG"@SG%:Mgb9m! /~ә zIxUaGv#ݪ.k2*-^]]U1׼ПzFB`Ƀu?euFي,Tj,]J˯i D~2k033e(CG?2QԻӋ:oѫwo涘Vr ջ{fo:eX"A4:; 31KS& #pदɃۂvL| kpM'8Cp\H$82򵜇.-axU"bx:X^ڎr5"OG)W 'zeW;?v}hۏyj…T/ FC s{dcjyL`kqևo†C@4L)N En8wPC|SBamcJ/}-<("޻3 ӧ x/I.υv*#~j\_ 侢RpqL<0M:<CP= m6ps%yEZwtۨ _$: [brh->-ݎbQշZr4"sFF p!{ Z@ !{'a[KZP. '{*(AHYj y#C5JEJTAx.rɡ^ӷp!g0RrlDW# &F\;: E\v N\%)Mw>U-NE7u2"3lC |Cl9p؍ [3A6pʛkM8ao??ꙢR?ӋYÄobVC2 3@x7$9])*(wAw%_΢D<ً'S=qvF";~ \:%pix!{k%Q Zb/͑L9kpB$hCwµwMشL7P{2p``[{R/%dY-nYb9;֓0 g@+:o@gC@xqcs-ѧ4b.MJI\ sr5 3wܤX@F9<-ɨb*D-(H)n|R.Z"q=2U[F(@5'ރ92nr|jHM%slhX@:ýd+rbg&2ߛ]#ge'wٸ#[@壁 9Di r@安Ĥ^r@&~sEtB4R@Ѕ/T<v-Xn:U3 evN{ʶ,վ(M3$X[A۬DܒLQµ~kV;(+=r=.LUHcq1>a}ڬI>>Yb}Y^=bt;?L1PI<-!b7Q]3UXEӂW-Kou]qe9 H D~~@hY$4kh=#R e!ƞ{,b<0➴-CV0F6tkܫ/R9w7ؒb;) E(;(ImuFx'gfD0yr] YLxij-]I NiHY]ѵqڒ0~t6BzJZ~HB@\s@Kh~s 5. QDA%G߯g"K6R݁lȌDH.x<Ao>1;5"M7YZ^,?Ln{'|*8?gue}PGZ[H SEK|t?NprWA gGnxɁQ_}.RII1?CϷ{E.7!>˵=#PN'@KnCG$WFj1Iȓ~a~w'/ϥjjtZM`EHUX"lyUG][eXf ~I=@[ekwHha |Wb?jD!^eےK2+7AS_ $eVq~Õ5BKLCO+\+B) _M+ی Jqa>? wϝlÓglQ6`O3Nu5NDO"8pM<:܍ E^W|Ѫm#F2 x}l Ho}K}_1WX&L>~:biWz6f'oZ\pJ<˜ϕ0 .Ý!(1" I.tjuTF11D1T zҐ7}p`앗!r S#p FQ/EzOuL !gXY(pҢ- lXх'GNJC-Y;F,j(VWתɌJ7v-t-8)͡wOR *.mMcvgx0٤f+%7&Q`wlE ƷLX:6dnV * *ۧ9/V+b+1!/vZaP0qdg}2 +WWS qfm+$ĵ a!bEc: ?m$M\t8DQrz$G &L^+:"頬Y,g\3@IbN?J:}Qǁ#Drm$TB7ՄmWa?!%t!]^>L=Gʠiߝ_vuQr5Iu4, 6p7*4`421`b DE@7:ˠY@.%73In*eI f]:U mvdM ) _Kv,^κ)P Lgi40Bv2BUP |b.4lL.վlftn[\Oi "ps}>]O??O¦;7oXհ?a怳#$`B."O&(m@yj O9/bh ?]r#X\sM(Ū8Rx0(Q}f /kiu!~1oZ[-pþ^H 3"}-SߜE}x^X?{Ӯmj}a?G ظERB|2 $kj3/huZ"OICS%;~-Qº[4=q?0a Ug>=7ׯN),t^-oQi5lX:Wl6=PwTWˬ7^M} Q $hO+KWj5GׯK/“`?鰅ئ<$P#m%' 21l#aH3.E$"0Q#Mwg"Qk,$n[>VU&9K5ΐD -pCP4sS%?%ɨn7S!j@w:=nw9F3a`W1Ӡ9kjA*<7<0]QT݆r!v҄v:z n>[.p\F^w`qAgM`]\dق spCk8[18  hJY¾~Nͺez4N+\+w&t,ϫRdx9 !jlfWuŭ0t V*#Y4c/W^Sԩ ]92|S'Go?eb_;Ee݆eUï2 !rwWPO|"5ɍ-y#&FOG˗2}2 oJ]0ĸiDYpX;/'X{$pVВB_\j1W(s&Z x@I&WzZs[ WPJb<{\5""+G:LhI~ 5=BIkD~a" SҴ֪ۗpVzQƋvh~ ZÜQa2~KeMjH^A7ހ4Jd_I/oZQ+:.6Ie&$9Vh6Q`? scR)9^lw=m9X0mIc M(_1[(UoSr9z ?/'!$co(nRO-~*'i{҈*,%(F,;SvTd3d0 ya#0[ IST{4aςI:\|]^у1L>+UCT_<-:92fP]jz`+"=>ƽ\Y5y&j3~76KX,$XQއu,>֗8a kY"6#LTz*'v&1@4fBzK uO*)*Fa.|(M|fm SbTa Ha 8mBx{n1CA`gɋ5?V,3q?-JBC%z^ٓi3 Ie_͠niNe0t?Ě!M"3Y+˓)0K༅)MR4NBXJv gb9}^KB2L&2tˎ:N6`#=qf\`}GXjN*6Uρ%>!7z7 o*Gn !]BA:ʖ,R#ƑZ3ffiݾc}SSF%E_ͥaQrSX!|x}·t# ~JÛa>6 <ֱ"t٥`zmd9C[,%*,0 ODVZKY j3MYqBࣿ/$$XbÛ0i}F&3шP|<Ws1xʬӉ1_Ǥ5U|ސ%>ޫki 9N )6͓BqDe<9?;^ݨmG8r*UZ?_dő [Erސ ǻC`%&0pjW(-Tf6wq>ڪ;D6BN=:zraM3CW.)쿌ч:=?|{UJ 6XҽKB'ti9fI~z O*Dv]h(Kh2ݾҦ鵩8 cZ?pE0&y"dL"ӭIG@ܪRǨĦ^]Fyܹd=ƭn-K0|DeBYKƛߐQRdwN:#֞S@*D1H "GJϗj.c8q5f.f&,A\hr')N@F$_KP?Zq]=~FRBoxqCXη>}_M~OLl:x/B*qGWK%qZxydd.RrmdcC]q6FdIȶx>"H,n=tjz㆓Vchjt=vG<緞DtHG2U57 ew"one'_AIK]yQ4+(V[}SEzOGt֩ݍXV+̯lƇKdm6!a50ʣV%*kCdI.|^Eu}/Wccjj.4m]e(gdC*kH࿃IX*1)]VAaF?E xq=B4#_ ?(ɞzykjCT#[7,'.Fhyj1^ ,EtMn-&|JGr pzHD'Sk ѝHQF_Gg~nb[R02 >-;t>L1kI vT[4.tdM$وrz@JwƚPZ&eVJR c/P=(']. pm2C*-):ʯPތZSXL CG LES{PT0hgTV`@yodMm'-{b%TXC1G6Qqq4=3HFxٜSzk2ͦ!2?v<Z --:Yt|dL:Whu$Gx '/x˜=>sۃ9<_8ea 2>mImE!]pb8" dUA'Y 4?qVO4m rj)a5& D-ZoaF}ʗur kCGŴщ(26.o8`r{haowE ]x.Xql=`#[*3###uN0'^V|R~J@V~&[Cr3|o叡s] .VcL=?g7ypLZ61 YS ;yLI6;=}< ђ'[ 6l;KD\Dpf[[ MVF٢sI *3!M&K,?s:+5i;[fk;pFGW dшVلk 7PM2osΛW vD U8:^D9[~> /^":[s&q䏩{Rh;GxbUxjxbot2)=(ң0jLbՑѤU'n :C=.4gJg~)i ysbٹ*Fq2hNpA{$;PtG:fnޕbfٲm;hQΑ3 1bovdP؃2򡊩X9)nM |-+\Q`D&`&=D{lYQ\x WMxkhۡm[ YADu[p_Oܾ'=:7sJ;%F3̬k'H>TT*Mi"p{+sȢJX$~-|)64nekԔ$vvPph%Gׯ7P /-N%'T9Keڷe{m"!|x&`iF?HEecSx >_<ҧAb YH}!p]@[utYs)2l XMydaNE`ano$cz} /rԐ7=}Glkƥָ~O$| G 9z+f{ $B3AuGfx}C7ʼn> 6F?Ut윝~kOhRB5޳ wb+P7lyHqu}ki+棈[8A Q ڎ<ϯ.rz]7*te&UKwc +AQ[݂)|Y;9Fhel#wM5VMH /(bluAԚUU@ `0O7%H ;k<8.>LLRS 6ttcPAen[\?ͮ;/ryHj;x5:v7kx혀yT9F2}3f B&J>׋ObWѴȕ1Dؕq-G/@I; (Oc-(bSΒ#= >f>uTȝɂ]5.FBܻ;tb=5dEf^GnmX:@N%2V PH77=[i4ŀ߯ Z*.%$Р>(Lv &U{}j ݿ>oi3X{Odt]+"]Ns|jPs\j/5 ̅h Վ[;ύK -;a;tD'@ʴ'd˳-.aAM ,B"287G%/tԘNWo+Oڟ.Tb4=[8/ S}iWm&*Bd=,VDQU@O @oGNBxǝ wM˕`t0I/iJAPeΔ xņ{LG`MÉE,JWQq,Ed:`}s?^"I|1:sm\x$8pnKްn%KEVq'/5{QZ YXޮOkkpOFmHAXZ$_c{Wʷ ,y]q*tsEcj9-"8X^k+Ns-eCFm'LT!ѲU'}Zbз WA/7!(ioO6&ߺMlf٫U.H2{[~"g$5 c>&g "#b|Sr|f+qFRK1 -g^<mFw- t[-.{(8D)[QGfweE#opei<ֿtX3gc-=Nk8£ao$Zpb:PSB(\ ^؉m`cHK-ƑH>sJc>}c^[.nv'M 0z^;iATc{=EQ»1TRB{zԺKӈ|U4mhkAWD]vqj5#Ryk:Ȃ.$Hn;D2H?eK Thyl ]ht/u"{&O`Fa d$fI8q!V8ąQ'OkiN *8Ah*m}t+:l#J^&tQ_gr!Wk+͉^=VQIVM 9A;X?0n8ޗtrf\H}Gi'(Hbkc=9wVr%|_NGeU&ZORP\l.]a M"C lsK]J4*v$&o[- 'hrQ *P#tekr.Y1HxmooVl֨S7s!}V98xp{ĥy 0SԴN " Z" έyxSm K$.:뜏=eДI]%_:< C׺埶5/% 77DޟU謲];1,lvK#@kdf? ClaR jjЎܘOD%èA]DRJ"[ 5 `p.n9CD,>v-4ȿBpI7/qcIj PV{!?Mn xi5/K8绱;\d% \Q (>,YŰw1%L&X^~ר>m,#cf) } n|9B% _2?`^a OET.[vЖˎBɢG0%՞,fL([-ݙD >Y ֩G9%$t'c]avCrlP/,d֯eқᡵq@,R+)xHبwՆ-kLZhIIZ:Ss& &\Ln[^~wѵd;>CsCZd nfwSAkrz1̎m&ՙe0w$ib~.H{tPHxBռ2{7FÒqDiQ,Fc4m4|ro~@g`2lO?lpHN;!#b\HwʤfY\'F&6MQ,v/TPξ.ϷSdжlW ,Vl+8ЈW}{+DnُRW6I@f$"Dus62jQ scUDHCRt|D}ZI ajxqR 븻/<1#llm:毲G6qUӣvx^(,2u@Lۊ S[١ͱGG*3dŝZʱ>r 1VB|BXꅝPH^}䟛kS%@&-Fc1S 1])7W'얚6n>Z^*XN[cSFsZ;/AY8*.@KY|Rb. qMi3r_m]9%MגnOǹ9۝oWͫML,ḻԶ@'T%n-£NǼx#n7sEaT:5nhL qQ.u1uu/hsؕOBNz+^/uV.>PH\@U ;ۻ0㎓? )4`Fp~WJAb$U´ܟoIc$i4iCW,cPê2k?pskzN?}5%_pWyTjެJ*ب!!w@q,]_qcT t^2ߪ 9L/AMٷOfݗ te/+lZ]#9*Hz8 !א){Pe$J 崹wi'DʣXP=Հ`q9]rxYJ>1Iy,[= nqY.ӑ1m)+Ӳ!B`2NBU,L]-#N{lb5yqkVPid0~FrykJtLXOR9tm6Ů Mb0Y$Pis2<DEˁ x3Im,403j Hvʰt Fg#Bv4g+7öёbv e"{YZȉo25Rq1#y+ +YXda\C Μz\9Ɗk; -\.,u5籐}I!Z1b@ %=iC)MBKY["v-S!=80rq,kJR^}B`@] 'Ÿ0rHB2槠׶EL7M?IB0]]^$KXĒ2P|9Ve~<^!gNlڙ;[gW \zy] TC椹 ,=<Qߞ渹k|+x,3ŦLasrζ8Hzi`Ѻ^aoA$cdQDž˚B;ס]wz#Y;z$_:D`\%&mޜTj }ӌʉ.m)ux{#َ6"f{ӫel khFLurh:H"pI۴Z>vXani7ca8mM#^Z^4CpeTAt9*t8$^~ka Uӣ-讶j_嗓~WAt ]Mr9S!9:}Avu^ .46'Z+~c+$}~MYypv ng^%/ =w%G3J Љ|Hip"69x9u~z͐ -wC n໔qloKs~յ&PZƬ:Vn-Kb~Xe ,Y oH{} _J5Jnx5\gh$SF0U$Ï^R tA{i%F%̌%roa|3 5V} e)jYSkI/O׮\I.;n'MD Ş|;NߚROnn$E`w|VN׍cpn(t‹">#sWKӰW;_nЯ5K/0G<ڳ;!^Z!jE) `MTnRuUT 1GNB\"&5@ ̣4UZ t.H<v8f fRAV)JQz5B;x77J1q(Q몎-Dmvh1j ?,ݸ^B)1䴙L#XdXō>3i|Jcv;sٟgnrŭ$wÞݖגj \/H|BVTh@7`kA\wWx/RO@;P˰2Hk7y9쨭*5'91@ʖ%2*}ZO_! 8ި\`iQ"tjm |T4/UiI MXu6kG %^(Rr ?5lNJ>@wXJ6sF}L"Gy.x.~b Q39=!3k7rL{#*;-ɕDŽ jK( >eqSjL}|13896i 4!5}o1=WxZ:LGo՟Io~}kZm4`pe=@kamִURF 88"l tQʄHJ?! yi'_\7z{d4D9z͐qY!H{>STU:W{ηUMf+.L({tpfcG:l.,eiyR.n/Uҩc oAf*,b42564B^FL^]hܔr亳 -uJbhKb"Gv*́sl`&Q(I2PS].q͒UråMhjfebJ e :P^n1o0{wٰ[7̉ .!^c;Z7WE"3ވY=)6)iCi$س ~RHnqq#]ؽn `mOJu> Irbׅ=0ϝ?ٿ̄Fk6fQ^'&g ?,{퍄2Wk!n[8_\^jҮ S!gN ~k-(D[s- H:#-D5ߵӈ}PԣabGv2ls/]]UJ:?>*b9B0i֭›̪]فE4?JN'$@7dYY&>C0>/Ďär$fxBd/GJ"n^ܮ {-9+L?0IL*F22i^ z9u)s+VȌg ̌IJh2NDCZ;ګJ8)kqњ3l{l.E]UHoXV p/ (V__0I_׼r]|k{ED!޾¿e<-ʭfy@ iOmlti\MS I1C`oH;MZ6R ( a=QQ_)kJЍ1jBW Σ4?dfN)4ºs~ʅgbeKuށ 7q+h`޳P,<,%En5g=e3Otw>$[n3N蠓Q A>urXXDJHLE m^E&`^˪eB4ktW,ʺo9-C G_uN '3ѶaxINy,Sn#i>ZSL@JYW<n_ pmBY7n %0Q`"wvͬ,9*ыE*yH|c6.Eeeõ4[BYdV^3B9}O֭̊U.|VW}7̒+9nӮkD}eE5EJwyڀ3ft-)Mк5ݖe`^;k:O!#Y4< S0ƶ=ߣ-HFȠ NRUaC';3S+cVƁsh7̙;(D±9<8}SnU{ʿA0N]q]5D7w C?_7[GS%-a%!$ w͔<2>MG#MV7=JG3n< ]%obo/y(7حnd]5oa(dx滘 (8) FA7/x\~}T)Cl5S9ne"m $I2j;1[*9 8 k4j/AEOY;>ڽ5rC~ s|΁;G4UO4Gf |.-F!طi`FJ0"ikٱ4=ޗNh=t,-Q?Ű]jơ- V; ZHR69&iŏF=niM/Lp$6XvGV%eXi+z}.Íj`96Vg?7  Ig!cxWs[c-[ʐE~'R,F w8g^2Y[}0_<=5[w𰇜AgH3M<ˮNcVU݄Ȉ=q<+rGuM~6?#4aq{Q}A{Tn6YOQhp<([Nr5G&{؆ԳSj*'`mm"+DFxɅ?XS5!nhCgw&C]ɢ-3™| _zүXRgbZjz;K8$bm(8x2;Iv:3Ff :|c1$ZgkFxf";_$, _oɮ!zn=}Ry11ܴ Ԃ&mn<8+cI_i_mba2uLM&|k_+Vq[R~f,gf~Y %=x8!ٕ)XmGcc*`(u "NF&q%XF))Rͧǣyx'6|m8uPXp=S<-K?5'򐭋עJʐJkSZ+x K 3VUm.M^u Tc^̆5̯@f$yEc~W5nrK ٮiNjh(3*ХfN'm[n%HzF0+C\ӊ_ 04нcEDTWnTj;42 )xr׺h.ћ=uP{9 -`gfb`ߛR j%/ËC4,|rgjdBӱBnIHۿVFɐN(ƀ!f)4J csg{@G,.F̆ܖ zGD}kL ahtuټ#4;i&pf@ݞXz||}JO·`T'^g}搮PsNL[^ FƈJ-)Ͷ,˰KxjC/g@<pkgm.}ptκ6Dp@!c̢-o27b^=[~h(S9N#sZnNG08G"U| ?^CnB&hV,^En,QyUر0)O1^O~TH|]$! B< 1!?0ȷxH!]j :1VTJSr-Hp+QN؍6ht>T O Q:ne7W2;`3 ~ |d a`,Z:0ȑ %΄yk(MIܥc52&QJMZځvՌG-e]dEV|[Gi%&Riꠣ m#,7>o|b{@z!gg)sh݂'RTμnS)*I3_N=Yl2ib%gza |+F4K wj(75R L] ͜шL qy=2y>b~ר5N n.7bTKNY.p9hpD|Ȇ 25 pЀ9G9[;…nTHPt{ymaDM+uxJ0y\[=i Rm?K`kq쫸 jye:@`E7Ae¹WLOF,/۵r/wۀT!y켁yMoEXWXqJ]yR^L4 tTKc^'Q*ЕQl1Lc/ D/׬&Fm`<;>+].__hjTڥ޷X褬G/3P[ƺ.GeaYr u(wɢu=`pnq<X;fo]A3BWfK5B_o> )418& ex"<= mG\QIIM.k'Gy\uzA9t&`h!e*ax|⊚ 4_,UvGւ{wJ!"}=izo2u}E5,i0ANq}I AFT@>.f"F7N};0SJE7չZrsKH< jX^=äA&º m2{î':b~LYÍCL۴mhW uUIʝG`n̄U#3b~+j.P Dadz%_(Xuf  l(zE2;rfC`ʻ6\WfBa'd+p){ƹL% Y=^Fd -7 Cr(Gb}U?y˲rUƊ>~Yq|v n^`~r@ͅ1-^4ɖ*[Xt54h:)kܵ`hI(Iw6X'k8:gEfݿ"5j{ivD5;Juy*w\Xk|RLAU" ,9wNYwVC Fs[4K98=y{]S1jݡF6[a)m+ ޗ;S /7v=&`݅Ϩ=wCǠuFj=h9E`Ȝ  AJV$1E( &`h,Rྟ=O)L˨N:o6;[@aMk,}KkT%U߷D ܾ[L@E.g%n%òt: %uY} 1τ) Z$4X$3̄HdTAj9p1վZbKB.R%*7gOn!H4ְLLBmx|4)9\ 2Ou^|u5l@ \rdeIl0jTɝ8JMUBa3N*^.d ˯!֊BC}s-1XnxaPm" S|15T-J j au).idsKT}j=X \ \^`(V"p}ZUpCYc0nwcyqhs=zتJHOW "YzG yP 7QD *yXO=ҧ"ERu 0Lːg(@xB'IMx8C-7XAvr_$<@$yGdTR/QhWJV]'4\٭aeĤƩF䞑dE3:naurLK-ᤔr~2\}[ c q<"6/1M_/HK Ky!25-F1 #((4/8%)ZsE#.t`Mv 0nϝ]woa' ^`Є `jC^/H C7op8{Nt9*n 8cY7uؕ%vgLB+K:dϯFFB[O9j;e VBiC2Q$;,ܦq}u [`+bg)gN@]z-sɵɿI#vđtґUe\Wӝ9`W~2xGI"cs^̽zH3O[έYj#+*!M0!rbe[2. ]uHXಎ +Z9K# 1?#HYKhozB/?~9^.*k>MDZL b/geSGeMep>۞QېP?u7Z2ہDwl` e挆_`^e/c XPRcRy!$C#ƵYPP)|BwJ..a+Q+gOݠG^/l魄*B#x bhڵ#)H]$zW6cU: Kh!',&uaク#BnIq- `0*=wӞD0ry(JƎ'tqءt*I?~?eċ>yo陼vp7ÕNMU_YS,ݛPi˫+ѽj_,BjoU+"HI.gR h&s(c> <ҕ-ƲAta[\.̀HMLur 4յ9;tzȁǹ,*3Y8 YTLNa\aYXf NxkM.8OAQT]Ppz Ԅ xlbY# aXYqÉ%vu5'6jUv/MpZ7){醇X2g/W$Ty94} V Jr~h%{_YD\Co± W}~qVmSGXb~ɕl7N -G)͙xmHD6^qYuD\ (v ǜf~, >$z<kFwe&l-7UmğE[;Jq&n]pVz|%;]K}u un6fy]p=]7R:Ke*fl* U]A唜 2xOؿע7 <,ZdhW9`z )[j&0@yhYI&6YT|LYh-{PIq9]{ftd&wi>v4c;URf6An6lU"rM";M̋ib϶KeĿ;lZ'ߗRv(jP h Zטh0ꭲX5`Շy1?o%|mwc+sְg~ư(h 'Eڇ0P(D: ;:s $ 3Ѳ2z?oUd-;JpBOve~P`{~J> *od( ahGPݖrσzr{MmӇ|kv+H{`[@zn$h5l@+mPyKasZEDrA:˦Y#I1FxOC,I% \w֓N /vlJX#hHNr^ xGQ(>חlc֚䵳?b17Ma(+fUںoٕ\цdZ*t ,٭]5pP9̫pnH޼WףH.E>$f |4*0RH0f;;7>S; 4g\$Kbϼk  .U5S#[dGCfa$t=7(8.Kl+D4u6o+I!jD V܍d[FIU;ڇ'%9A$X;m1 ajRH%uPQ,)ʆsKOᾐIï/+FR5} |?kو+*T[ w\MFA+=.i5hMXem);<.nUS /gͨ\f-c'?! k &>Ke<;7E&Rw2}Q){%>_P.Gi%ӄ3.o=Q~+TYib=hImd0:GgCroyHn=y+鐦3uLfqBi`U52RO6l_lh@`p=V‘C8> d81jZCY%l b=c<;y`vЀm0} qsfʬ 2^Xj1Rb=ǀ%̴]Cvaubzh !(Q`0|pafnȥgZ_A |'܎!*3Q7Cv Vr2dl_ k[Q9-l2?IC}"j2;|?J0 pb>"F5QO7t`N_sBRt엚:E6]߆AVz^nU*Ŀ{!`D'a6$g\2Dyy%jHM5׏zvtV}S-esWlq]m;xvgMf ,b,68vLvGnxRHۯj=ߐ.[/EyUhJXRN]+oeߊ6@Uc.P'Fc$h}C8=7=}Fu$! mMWP_puo =P92̯yg[ݟ13\tf> ]F5_E9,qmKFO1YsyB6$pqЧ"5cJkufm= ]ep$PӆBA|8ȞHxj~Ew} Ѽ~_&5ddUCz^?b6(k ?jؿϗJ\LÄv?]D$wU\EVT &N-_{тaYax f&Uٲ+e:Wclˏh Ti\ s``%~ #"٠ď6\qO/ -8=rwGq: S\81@DS ܙ.dc6TAs[;)sx3bLi[Wi`5Ծ;=Ppy^!o>Ea>J`Yy߳L5{%RI-r)L[-$Q=k߃nRu;JO&]{NL6սߛMZ]~ݰwTyain iխ(݅hϏ@eCT׷gWBӤB-}"z[l݋AۘT*Q];\2 J#LbW hKp0 ?HǨXx2Z|n{I\RPNfi% &$_V?כo+}Q%KG=^9=G5wc7Q7XրCƓ. Wϲ -[;03|pEu1{1-Pa;O e#v$5WZVpj;['X;h㼖y t$0A0y{umhr_TH_]"Zk+0},HՄcZ;514/8 E^m "EiQAfa7tPl0n4+t OI}%`p mZ84`o2B4\~irtmqV 4&zR]Uy ݒoɽdu~eCI@xD{UϏ<eG23f:\csCs ^̅yY~>H;cO$T*d.hJ 5`cUycR6R.#+6g˃ї)}5o\\/btՙ3e,( 5(d-ve%QE^0DY+5(s.5$ϑ^jFr>w3Yi" 'I^xN'S=M *_3 ZHUjʃ-EY ?kWH@s)rJjN1W[LVE1P%l)g_+I7J]ዮʪDyVu䑙@wNT}KzAL~ZMHLGkцxf"1pӗ[$! !;oscM \쨢M]u2 Yqg@UT @Hk$3c5rr/`Hs?Mmn"[gЯkdUU$oK4$ՂBd%nHp$p3^W^#@  /we@\(7`Yw~#Hƻ VPN xdJ .[S6 [68:붝v~]L8D317*L <*tFO Ōm](xRphNW(}NחN7y|Q @Á?^xѰj@HXWhPhϳB, G.JUl>z`7oÛeేX/1]@xSO27 Q5ywr Tcӯ$x~-&.} UGMb̉bڑyy61_T$Br@,>nr@dtM./j|T "@puL!|x@\|{k]]Vq.CZD4JjOWZaj79vi2:F-C jQ9s?&]ŠO\'Ғ7fϜv ddt5z/>GS)tgq*Lu!(qC+*]\@ٍ_ԎF7|LbD d:x~Xd? ک~Ǚ㵌Ndλ/ڴ!wcW;.y!TK|96%:_:'j3ş%lO4&8X0 ;uDTސ^$NoR_tVϨlsOO=/<07ޫ+q0'}H5Ǧdjѯr*lh2p}em*0XF6HAe_ MgTWmm88\dcWsT(b^GA[0NH!B >vf؎?lțw54X7(jfftc b:~^!b|ZKc߰4? @zEтK]O9[)ՏKD: UA77Tm*mZEEs>fp}Z= Br][S}[/d,{SI\{FkwL"0d 9jZEӿPO5j uBXwCVB3,6]$a ʐZ>=p2VgA;[ lغZ¨0ZS1WNE( 1SɡXn85e2nƶu`$`c|P\b"آ98sdTn$j&ip΁@Kzp1 p5*d51F,@Wb )7?^9xJyê'ʗzM{xl%gu1CLVE ȦNyж N$@z;)cfm Fq?n-psX 08YͩPr4u#"#exLD4Lsèܸ|NaT% P+#Vwljiӕy)Xh\~I]ke1=Fȼ8k؅WMUoZS7FOn`56j|z ["+kB;HeQ?ȥp F :Ԍ)ٌX۱i 5;hmUN63S f? n}ѧVJbKKZwD žQ2fx73CD 87F0L*vu ג5T¶ ս g|)"gM&WyxQ+o0Y] D+{9Ã%Ő Z3g|6ѷ\i m+|׀HsIb܅U+G;Ғ֢ !uhiG-ŝ毾P844q_HVxH) FZ(1_%M}WhX-jep)dsLݔJZ}(;J-MLS,eτr2i4 `\r87Dn"1د,gROyw XS?,mR-=5B`kb">cD7}rٛBa]Pfw"1?'QDS.4$"Q146.cLN i:#ag u3kWP;/&[%t@!h۹ǛyPt\: oj_xԹ@gZ@(&,a崔:+'$|y I~gY Ҋ 75qhe t?)KdoEZ0t2+4*X(7M?aes#9 M-ntհn߃ȓju|U|QJa ^XiWNŦDPKuYٰgh0l TLe8`Ō9_ <fbѻBm`ol&JG {.hk1Qj xz~'S5 a* uàD%q<ى-gzpg0F73Ɨr31C[?Xe*'c!D=\ӍX9PQSs2Ӈ$xGDOPxpCcn,X{s)At;3W&F QkEm9S'nG#Yo}w @d(?7SoхvdPY aODSs{zXg?ZRma]vOEOo%+P'Fa~OIAitjwPU!; %LӯZر/Y0!/)[9N?6*׺$BPiƙz1Kt7{/#|59Qt)FA&t{(ϟrM<vp `_fh(;,Ok"蓥١! ޏD3_VwCIE>Ex#&DC;{St9&"[sV:6-;hK5D!S##}T~HJPfF]9# X$(i@V mtI}E3cԳ+ұ}X``9NXBVavixȧxyLBzFi5#It)/u߫hWBwXbΑ\6rey|06 I/CW oX#>mvDHGYY*k9kynw1co(y7O7M m-i+/GE8|s=Rj <ØZ^7ّ ˘3_ùi4$5S#&v& sTz lz!,)=aBv^la a1!H2Tߐ)+dbV*r jH*wBT3ƈdw =*ncdm=V?Hb| `VisǙQOlExQFa[ w],ۡ .0zޔkYp'Xfdpr15buAt?CHiUآݲj`DgSmgO8|t#zia6}@Gx*IwP.QTs쪁he5~-G1t6h9-z8RI==ۻDѦxe= a< <=|=i贯ƅIJ8wjx0 [Wml6o{x)[n4먩lYE>ݑnMbI FC{ތقA #!E.myyX8 :P7g`CC,4EDou#HOWdz. jQBMD{,iG)sv4~Պl~D.LTq)%|ׯ|15~g4C-iА(IB|F$:>8̧ +dz;Lh"Ҝdg cfr#2_/Ws9 eBv)>nu^hb`vv̿I}? SE5k*8+,2N8]SDi0Qus[FM5_W1Awxw"D'\c!;GA-P!B#kq ZE;xFA/bFx{!g 1>k-Adj|d M ^y;}ŋz+y/מʐp[,SBsJpfIyJCEu{R}۴cB&=vҭ [w-a9͞gU oc\S>7GZ`v'n Y ˉIgc%]>Htаof-ek[r4D$r`9G!w:L=eч1Mpu_MF w ʔ6}|HU%d%2$sZpku G7.vaDô!g _د%9w.Ia^ (e,;l$L>{}.:|y0qR1|VA ,nN6 n1FYK@@bZ9t}6r?==ub44VWCΦ'8q]uDҧ |A6Im(Y9W)ᴙ+}l`v|D[D41RE 8o@?/eP C I\)f{W%|v 4gzHSJ+ +mckS$"R78S &.2vKZ=5,;ϔ<݇|}6o>UwDĐp\j8 95$!=wk Դ 3 O86t̜opnwyZ@ՎDt@ɷ%)"2FT@()M&heͧJqG:^bX {ZT28'#Y 60L [_\E y:R%uOF05X&؂6 GH6*( 5eqP|rKH\1ߖr[+7RU07 &obr{cR+ weO%!.Dp4l6kBD|HbvpO§|Ǭ <禆h]EE `x :YSX3U'ƿ̞"U1P0p~bqjzBf}ABz䑕Vu!~#ͩ\=uYsb}>m28* [`4O.eOFtB]Bn,/cuz  Sg=:Zi7 5W{&ovӇ2!TBEGݨs?@0 ' jRDqP:S0.!JIJ[Hj͞I=D`T,68e[쌴E{JISCy3OѪ!zLeU}Ezf_knPI_+[H3LB۾ܵw {,k'rcZgD?~-߳c#d1W1= yP‡٥B}L^ SԒW_{H>/Os%շnD1D"T=:Drd2Mjm@|mIZur|FRU1-]l<@ YSoR.BҐ~߼E:{§,xY娕 Z2LJLDY^JsHغ!p$D}$f ,Ry3ˊͻ1LE|q#3) bWq 3%M+4-%=)kfW5Dn}͟LmC/zKsJ`VzhcY'N}9u㸡 Ϙ 9+4i(&|KriJgw9hsز8rI拢ilp}]dMϬ Aː:#_S?s"\ˮf~`{nv| uKt;0m7@y}<⒔=sP 3,NWooι TrY>e8P ϭw vo|ƢjM%4JJ{Հ ¦Z%a ͬڼ,sp4GR;~6f+_fPAtE j v|)lrw\Im`p~_YW  UZӈK۾Ww֬Ow=#غ7B:|_?ZeeV\pkvdTѳI+@1\z# k!)"YP8FoDjpMG@6j~V>𸥽;LQ"lE^8OX7>-<6pCTw ܷ, 9j!^NpLF Ud:Pfz AZ7;[ .k~em W*Ua-׽8>|q u( Cwx`5 1{(G,V푮= wB24&2u{9:b'GB)Tv&;"?}\,̿XwIҕ'&>{?2f%߫G;mEc/Iy @٨ÿ]h5uْ05s&Tf .؝UG\M %w7h^vAodO1'#B%H9^KlnJ hS'K/ox9QO, ǵ^󦮀 #¿m -eȜȫ][y~4rŧ2OكO#/AĀ=T}2)ô6N}IP'=[h0xp^si2PY@s+.!FK z%,Ls>&]LJ47*;<\X mU6R:9=Y;^b< DHqMX_Q @NHkHٿ#]ڸ1{Lz @H8NP.9q^Eőwb)C53RVP"JkD:ߖKoʍzAiFC` |:dqgtD@Q3G'9E|S@t~k 0K,VT׮,+`mndT]˞)ޭ1#Xa8VxVD/ ( _ȜŻѴ7,2R s g$Ң0_]?W <]:(@Lޑ+)yMYw"l ;Wm̰e$٨eƩI! ٮy]f2Yhx2?;{:#T฽[AmLQ]8n>öB,6W3kd OK((矅XlU3^|K9 /וlhw7/zC9Jb$0qAd h">Ԩ$\.s_Tk殠R%%$ej۪qMdq$bR͆3@dWN/<D*7ē;Fll'oݱ9N~ġbmLYŔZj㱚nvÖݣ jS #i:qs J7CA2(ֻ#D ʻd䓮CQӞJI+eFyZH~kAmEs^QFuSNi]ج֬dpT `TUJphqY6wW}5Cdq覐-?D'$[ZRʟF@-S;/~$B!MB8c Bhx0݇&%XiS!KNh, |7ԍǍ8`R{@ȱ$ iPӦWvб]?+l<ojD-UbLK3.86߮\P-D83b}r)J~E1z7~s7kD[u=DEpӞBԭ7bPeĆP~UkϴRJP,isB2K(۬ECJ갖j5™g_MCzA/ڌXL->Бcd\j v46Ә?-0P{290 *gEDvxi˨8\u+EH^CEx le(bawb7>8ח Hh9 Z x7 4{t#tW}.oup\m9;|=7ċ~*vzalgG4 Peԁto%Y{>"C vU$>mp6!THGX3LXˣw鄝*b'\ X-uS":RQGy+(@7<ٷ$drE;5 L:^b_ӛ! (|WQ c\2H:EꃑxqBܙ,؄uڌH8L2;/|VPXy/k$FmY:sIj*~?H3  9PNfLcsfgsd!p|,U6w(~"d3-YC>1 ү7F>njWRv? 7/ˤ'<)KEDI{F LAYN!%hrDRh{Ƒ+|k.x$ +,xB\Ms_{w3#0ኽn-H9*M$4I mmO;mN@8mz4E`Xrc:WT H.~| $7&Tă)WVdd5YJD| )ޏŵ_yaFD3=HRVv&ږją3 V^3V+EL?;4aAtKe7=ɘb=2m]ZRK+j{3pX9>M%m.f\UV&UyRD4b1 ]\?mE= {]so1O!N;r?.:5h}l`*dqh1;M]WDDcs%z=&zҲ ̓CGixNG] PΤO®&cyHf Y箿;ڃj)Cو@]E%!GF^ N?6cZN4bqcsfy荀s$mvقqZ73XkGᦕT;/ [0+--DQ2O(ky SWNUt2{d9jyЏ6?D=YOJܷ*H +縪m3ϋŶOzZǺՁK?ם1fw#)ǹr_Cc+OWqZ'3`:0Hӫ=UԿZUgW'%c2>PT>oT@vq^.NӃ!m\$̬bU۟q'"\3v>$9DY$Yha("ˈ-3AO=e9ZcSD]:X {|QKۼ #EUQ$IDoӹ_w9V둔I}Jjg;I]F)ZqFe7h'W (rh5o7'eilLssrBVK0@v̏^MqC!eK2oP\͵jNg5ɠ#[ 6],KP.8 F(c}d ^E.yphı2huu.p' ySvIjY0c ~;VUh~ 7l:!5Jqus;*,hfU(GK?؝|$Nm21@()#bV};V (8/xUCkQoО9R64^wYRH؃=\fW7pRAo`i=MpS#E7+~f`FmOEb;sq*Y!5I::vEA]b'ӺEfY~;$R`l߰4x9UtS%=p ؛,8"ޯBf`LKP2:6k<cCG8V m\H22L"Fv[=aY/S6Iʠ82&in4D3v : v+4RqC}z֟('Mh;P2B]ϣTj ~i3JJRv_5 VjZG5c彣Ihϓ!ZCZ^NˎVVD Қtp-X"u#\9#ʄ_U~.pPUX޹1dM..E>0Wb?8lzV'=/C V#zdZ_F ͺxݐ  ҄-GoaSyJ#hdzxխh5y,X^XDuZh2%xe^$WT-,`YF<mbi8xhiߦ ;ibs:,@p4))"ڮ\& DuHvޮuQHʿCw&K,H87. xI6XZ=u5@Z$@{Mft25uuڢk`t|[/!g+T=StOՔ򘭭:Z̢c}1h G# 5sؼ!3[OkYd.-DK |>*|1"[%4s٦E#W~ΙITy>e/CA='Nn+ |oK+uJ5wmjAң9L&w4TqX D::Vb4?dIC! )ߡ.eůFwSa0NmZ^2R8Pޡȿ2a@-$5zHSd9)A:E7i>*v@Iwlǽ]) SxcEv:xl鉬^RإS%y*4Ͻa@8'˧91|l[ I]; ֔f:M^N\y6dDIo{3wqk mfI2}Oyi "lriܯ'pVCWF ^e |=?!?瑎J Iv`iE׍PlR]/ 'XM5/hPV7 |ҊQ.2W듳 |4\B- JwYLϸ1>/dY!J^.eڔӨ<דwLnj,7dG|n[CȲlH򮂾R,L U= q֬!:勧l2?()CnID $Nr˗**-U[ X#p lb$̮qϰK;~i}s&Ò.cnW̡^{3UANܧ;-w@T} oxOLT<3VN6%whLv^{xUdYR= u'RғÄKeWLX;n( jd&Kr«cm\'-)"Frԟ}mѫ.E"M:%Qާ&pw.W=gg z{OL\G>Gf# x`q4h{'C7\}Dh2춈CyMsPtx2&76>ȓu঳Ttgw<轮jw=0L[j2$P[gZh1i}QF\Hk7 h#ɬsRPЬ4*!YN!$16{vɶ^lZB&̾h!]xny]c\Ĵ2]m 3ϗ!5{YFqݢ^1HYG4Gy æhcaaދ+#D3t Dٶ@j2EDRy2#K)֗32jaD$$n((FM@Vtrg`ޯnͺ}kqoٟ#v,? cQQ!SAR,K. |HEZK o~Tq_fPo-Y C3Xq%,ṻ>´t|VM>^1 v"[A)STU=jXDȭ@Ţt1[ya AP)y:=}Tiߘ;"X EB? ZO+j7Bv,ˈ4OCKsDd%9Fr[nSnx.6 /+_V Zn.dڙ;ӏ:0V8Ru<48nF}[2 >*@WRB[ qlTFtQSQ66A s.Y0|ؠx7(m2,u u{YQU'`R^Jt4t ,\"?#gp&)nËMyȕB AH+ 5.]G*Np%j~zhθqfʰ'1@ @{,#']g.wY,?9I!W~Qd|jWK A*Y )e(Juf̋jHi%`Ma+ 58,XoQYQ"~WHyHm h+"ղɏ㤎K![dw$'*;XIDЃ4䀚Uº?i?teΆ|pNUe6˸Jd^ι/: Z!&f+&*f~TkyOP~K 3Pa-AMV)~n$+<`Ԑ_9#fr2;rݎ? /9T]QLE Ib`i4Q¾H$.\ط?tH*Q?*LЭTd:O Jz!'+Tse ±z~bX(ҥTo #S|QbI3?{LۙƙR<)` w|C : ҋP+[K&u qO3"Zi;7]h뻘Z-s  X{,'wKŏAI+^&-~|-+idň٭yq0&8JdE-+MA ތ >& eWUΏ5jy> Uh8cJm ~{)>yTv.T)uQ-ezn{6CXVȐ3Fv?EVyP=jY#Xjaw2ѕC2;Ϫ7VB-/Бi ޠѓf|w-(!uņ>.xYcH謻kj$G.q%VPq/vec)6%* FfGg}lTj]i N1oz~S;{)ʮ}E&po9{ z}v,f󑊊Rk]nEteHɚK$IRlX&]C샇I7Q\[hn(\ q74Lb4py[S0 A.7`,&eBh)x(q!B WIn(Q ԔPDVPT{],G/IORz-AaT`HA\ȷ9 Rf0slDk m;BVMV_nJ&@+sn;N2yV7VtoF*A]B^U=l$HBe Y."Yѓ)PR.AcZx)~ '_NaqDCFoA<J t43.V~O/.^Ց9_MCZǞ$O"}3r3O/㼨d{u'Fd>d߸Ubޑ zg!U`Lڷr_NP^9h׫ gyX"'?IZ=%oE\ Leu( 5:{M9!fֹQ9}{G =sҩKɇNw~\$ 8qfNo[0WQZ0 @8 U9ja;MaRM!lTW4LSty}'+Wb?Y70>[1#*dD>#)PǐzYZ"0 >ۙ+̡!: bzg%jVo-=?þ'V3q /:!3YMϬک2od {*.N`g"PsM$ЩGk2X߽EGn]\ޙBfh'M=X8^5I}f|oܪ}Շ\d:ס阭nf}6l"?\(7`ehgi,LT%1>J7INc< mpyWEme۟D˛|ybtCH"Njz{*(YMV.:B #n욪u}hGWM)bW lhQ3>L+>V|c=Hmsr1싃"XV^:;*==n\Mi 6XgSu˳o?n> ^(yJ4D>F@2* 70~lx fBu sP"BP fO OMO6ȼKU"@E,L8IhgiU,Yܟ%Iwp>;V},a#N^ϯQ tfXHrJE d,|:SX+ okS{H}یDyN}yh.Ȋ!H,Zte].O957AeyW[(8GmpPNÌ:}"oF@U˸ jjؗm@CbB%+/ny۔Jeg Z{իnee _V{ɼBt_G|Ml =J۔=ʨథS<=8l, \(=.E?o ~6P՜,gنDwLt+A:7o{Ny eSr89f>.tAՓ0A'=JFFqc4SgVȚ+Z6M8տOy2A8'͵REږ5`P. v7kȝS"!iO i3~P"[hd+U( xuh.N/H i!i%L)K#8/Sr>ãڱo̙"nxhg DoG#/ IOꝶoH5^pֽySS,_Uq3kَ J.&?n18E.icOv_BX:k1^dż,陮9@rEb6B g^/2& iV;?<"ҥ:QrM.b:@ZЄ8R)W.iتE`wW6۴no7V} !h3ooUB d '!Xā{Jy'(6vhjPF?ȩ ijx8X~%`|q,zŵ֪Sw3cadc _AE\O3A#ʝT*zMF&)FPFC=Lz [:TzJMr=BψbE 8"/2UWyPGZ5+7z9hJT=e%ђn@&dhtAC8s+p}@Kuyc$f+hHKK#*so>tصqN8"JZ]Y6RI=$Z!; $_KɎZ*8USɢ4S[uW^"XfSVSQ0A'X]۶c/;:;i&Ej1qNӘ`S|9Gb[ Z#?svpJ0*yiBe5gc#:}xoO1-_e@Y:Ͻ0Cxvrv D!д/(c yT7n^Flǒ% +w-wmTP&3+MFDyNZ݃\0p 0%T ^rW7Ӽ:E^/n\@YF{$OޟGJ߿HXLtP꯳Ɂ*.:i %R6un/7b=."CX1FkP(<!7W {}󯔆- o+Pw .l0t~ɰu6VfskJzK|6oen(D s))`6!_BL>k2yǯN>1 w2l=44D7bcH 4JMXc7„i$qV^@,_O2[II!u88y\%輅i3)!$y P;j6%鮎|#XAj/ױ=kPW7k%sVD/O_L tP @Dž( ~3@45u$j)GõN$uGm>}0.?;ܵ[XnҚlw! $.MT>, 7^zVs1{"Jw&i{7];4Ҡ>GåRn f婞"6F]J5화rCe.Rjcx~K:(Դ0c/#s3m? +M9r"tLSj]R=@2pKȎ:]tZ;4GITg(81>C}aݦ ;<|㸅90'Je5GQjWJbTgfne1`sO"^upvaP,x7P喕D0ӓ${!DݎԯF " YzޘUWe9eǫ4l/ySB ;Y4RfabEX?:kޝYX0^n$ElM!7jCM>hC|siIUm%8/U^!tn;bk]\)}ˑb*(# >h ;;'}]ŢJ;nݥ$EՕ>ٻ Z}ȕ  F,Lu$nj=#sƉb$QbhO9ⓩeomS(}A#6FxBQ:ĎZ"Sa6X0;@fd-]^{ʫ_/6\S}eJx/Oֶ.GD RuxUh)-YfWQF$:`2|s8skIY4,zuTiBFS H>;aANǥTyBoh"V)U|pȩ G\!pqB )=w5NbrilKxO(MT&වf0Eed8' r$-2O\IaJ457Ƃe=`@yWKFr?pi 3{dubk/!qU8L"&*0܎#ey١В.VҊ\Ut¤cśn3&Š]daPIIDrHn!?h@:;r &Jv2Iߓ 1I "pVRЁbnrȘ]lI"qTVψ `"[k2.o,XvGK(,%# j baxG`oT[w(I\`=[=L j,-td+aݙʾ#STbc"YHx*~9x}c;\u2_OfLgo4 'hK|>ciU0&@XRAO۫ʾTaRPCAdM(_jq_,d\FF ƷN9tL/VCx:Nî8`68]_-(~˱]X&,v:ثMqP-gZ Zf_uN됋fUʟ>?iOov\x{h% 2vJ?D()D0;Y)KxecPEm[lieif('ziqZX3=s7+^Ah']VXfꩃEd;c]C.aXU`Iƞ>>+w&ԴOzGT\{S[)s9$ ~]A?=7,Q~o2=[_ X1'aƳDeE>s1MYsށ"G7;NCkIKTWl`ٱ+X1x,:FHB`v =A:41'Z3VܓաddR#_PX+K?=Up~[ 튻1,mU!t2L%+^[?LtQ獤!q-҇xXo`^sSNQ46TE`[7t$qBfPHjtYjDb۰pxI:fL F)JiE11-aLc>Wylfr3E]IXQ9c=z՝FR+_Zp_ j_J1w!L)HJY{z?<鿫Zq=5> hʛ˙I .^k6TŖTG#Icd|~w?aʡr1_Fs7r?☗^m{ט=-kۺW^!XH*Jz%2!VKQfb ߆CZ*]~/I\ZGDp.%] F2?[}b F>[U6f2zv?q1( 9뉵 װM{0;1\ڋYK&5- Kr]Vg;Hk+f/;%MŻ$pmg97SrnChbU3ha7M.r]-&`O8< PMJ@듹ɬ:Ƚ4i v5]Xn`/0ٙc\=e $AzAhu@uxp<$ uKM:xxO Y }XbG+U*I07i== ٵr|@S%\p/M `+K SWo1?䀥E7msōŖ[¯~VF.`myѩ5`_p2ÂvG0P]">#)7SLIbuϲ%jlф^J3O;o82SƯ=[[gnc~'lAn_܈3[ H7[uWR|0T:"i v ʽ|$3d 2U1<&tw=+dova| |?(&p_ݘ|!)~Y#`![Gi B-9lG>l&ذt|g%B9M*kƉ-o<ᖡzr[K"Rn0R*~g[T6C cLѪߧ;|6Kl0Dx_DdQJB\#iu(?Yd9T-g˛TΊL2v4/- owYfbz&y梿K??*oz?=' D_}-$EqS=VLx)S jZYNua (J*~m2NuE "V5\l;K.2VˇXkK܃$.mw" 1%MqU05{mJ5*Qx%i_G7Vo*SZH9P"*iO:Dĸb2 M۟"w}ck>GN5=:`tM@S\XC߀$8|~%xN)k"D'HsңYt0#[[$^mC9BiBs:)TPd`p O?,:E%0Vpr‸|c@C'kfG|ZK@IL6rpVLf((B 2$."Q籵)R8=A]9>IW1#ξQoD2w/: Sv7toAA0S~d$7<]@H~v(*=nL? ˳:؋ 쏭PC3q"lCqPiCd=䶄puIHb2흱ؔF"Pcч~Lbӆ\ o[э`U& ;| j)j4㰧_\vX/h4bL®ZuJǤ×WE1:s@1A2 c[ 8gEy|Ŗ녎X%V8SZ8G"sg {hz~eυ2*3`)S(o@ :9ȾXW m%< #ɜh#/^ ptєx)UĨ x\tiArPMjU*"N/yE&%kc }* gFeJܜ\g3 m%^*foqL9smVV.;ۘ-s5>n{D+~@Z`\YM/-,21Je3yjI~pS ?/Æz@~1G1Գ50Z9DYA9֎D)C (f7aM1Bl>Zs@YE-IW MDxI+ⲥ+v2]jhno.I =Js#x\0TyZޒ>iuxY25w,Bǒ?/ jq("͟XpucWijz'gX7wqRDdF2M( {jX]~<)w1a  ljNۓ6ɱC_[uMK:~Rbi/kE˥ecQ]Kk 5S3P}G*)G ؁ [WYW /UF,o9^rVW Xέ0On\U:-%ʎܵNLBZJ\`6, l䊨J%n9'DvTm\;~ ϙ3{:d審,%̔ LQz~8 ΂iPB@V|/gbMho%pht1kUNv(\OHl_Q)|h+RDw'*f޲/# >wSQp]ɿ]/C3.1ା$C҄ 5T fa l-akWҰo{1U b|i~ג5i/{`P-vgwh%sƥOkuh1nM">/j@Wi{ *(۪U>YaR2f]1 %rUqkOlJG0!'p^l\(f IME=u!*g 6U0) UodՎy,jHK T]{dAtGEH% b( |JƑ0O'5-FKtmPXSQ*SÏ`b4̓kZA7EL$!U@vNĶ×s&Xq=O&|utča5UFb5Q5-.Jh_>7}},LٔԸqfkUW؎AN/1;-:7OE_FZ2`V!~m5h1}2Tu_r3GRli=KN)(1)566ԥZ9LZONٓq ObD0W׭jR  t^R) &ߎfeZB!ˀՈȀ*\]unjT<9#]uŶWng7s0Z4x[dMUSLbԓ_!G?eO^`3T͂B>C9ٲaЄ_Tnaƀl  țkѱ(<qr#z㟣>v74yB#q2fh2d<ڷJjj|@%*I}n53H-TR܄py X۾8{{1FJ6y^A|7+1Yw Pg\<@On!|Lr%Pc}”.-0y?^-y?CEL!I4>/,@+<͂heχ d`C}vH4'B^7X:k^\2ЦJCeo~XܯjccA,^T/%]3 `t}&O@/mDUs:~(:A>fr;Gq]C/KƦɸHJҕzoag7d|ah,1+`ĽQANԵ2@LÂMy6pyo'f TPOk<@J0gv[9  C80)Fo͑)5{|ZǓ.$>R(8V4)5:=Uܝ^e(_#Gt~5u⤢w agM4ز g!|$,UM#qЯap!13쐡0 `YgW|dR /.0dGScH[kR#|֬$u >]=Ww+ CmxOqGʶe!OWEl*j-?, E pliwܸKl;`cK oW6Un'!"hp2Bh rx~5PmT'+=66sVXD*:֟Ul[16->CöD6]"7n0/>H/Hv~NQ7ZP)<|j?3S ?R\>3evu~/YkFWcvyɞ9v8>^pOey&WԚgDnsV$x"b\#fYF -M>i=5`woP|Z;dV$Y< 5*!.`mVr!RXYcuk\5鯟TQkJ~Zrthp!aR4>;Ϛ};uvda%rn@64 ea JB^+{{G{m-:"LM{`}O i>=e!YP2^ K_XVG@,0z 9x3W?n91c"jP+]_\2tA]_0{`'1MxLt[E)pqoeZ%DMc4Nr6 5m8Ϣ[f^A9;#Șo2IJJ(%g BUb4]M< ^dH;QS&NC:! `Hz+HiAsTl\E9:,)`n<1ۍ5ᠿ%Y^m-@<3$U)$AS(]q*6~KGRu[o=Bl,n &hb@yF yy1?גaҼ?([ITHui_Da]hee@z+ZLSitU3& cN fiG(&f=%K*o! d72PV_irQcbRd6/j2FD* )?iBvmvMcxggnfqiָ`_|/Z\%QA´!鎼G"1mߩ@~|* K[kCt*xD65!q9CS})fUDn UgJ1ׁIRTg`$&}sQ7j?*6PCBnxNhxa@< !,B-G{NJDGB awP%|^GD 6 P n f]{\M˺v @ wjeWu?9t*N^hS7ѥp:"u9 5>ݪn#Й]څ |Np9\9n4ei ܪ)lސiD%?wpt¯3ſΰuf |n:#5\r֢PHr'$L=YQ¹[ M !LP/ϵY\he9'[woȰ2[[+Hy[KIk"+ ~Dlm=P,iD+a>9!x4b \$\34נfwPo?Ν3I@".9AJHĘl)S$yzՇU͛[lBuR#;o9S/J̺5:ZKKSALv۹p{ Ywvm` 1SU$} ؽH%XQeC>b ~+PsYcxNlPэWeA聆0L] @+|ƫjA1h,J]aW@ b5,ESF4M[R<؀iRl˗XXB m|q5[]|!_o&GҠQ۳biTD61BbVzv*\1} OW@vvq,3Y809xK+H"$9/vʶ;h8 vZI$@b%|QQÒҟMhRj,vna=G~HV.L s؞H!r1qg>7wM6}y}5PNy3V;M7w$t ebN| E<+Nf/aܺ?CYR4`4>jqw*]XSQxi26Zq!px|IvIA2K_h?*f߅mPqKmnNej?M`N|M#ɱY<`H&+x;VqE@jN#85\DRg)%]%\vp[PG9SY{ Yi9XQ5$a3?:e/lS WM&ƍuF @?No5eSOFnz5r-}U{::,AGJbpX/Kó-un6އ7XpϫekA2 6J79ARP9O3k˲$۷؀\TöЦ?&_#wX`bgT.WᔯjS8Ǯty8iM߁WplUf54țQs'MڊV1\Y+s12!#Xh<ʶq\lҍ жWhSgOYIg!rr?iDXZxGтt[G&i? T񇚉 zy/(Ͼ^+@5iME_9h3w5N!ߚjDžL^O (qq*02ݠu0E(AZ^kRI}FZ'^~-D` Uf = '(vh~ m67ɤ(r¿|ۈEpL $<ֻU{ІYC>ڬ>+A Ыf JR87Kƅ짚 Cqj:SVӴ8Fڰ̭EZ{%ŜcW +^Cz1gliJ6*$[: PZՋdbiIdJR!nۤ¶Kpnd $>r}mLl@ϔ^zW| 첊)t?Pݲچ?R#SA-1=Cƞe/$bK{FVհ5ibjJᵿm"\ 4j8btvW:Q-fEHNOD-ߖƠX4[u}C(Pm]JgE gKusgIh­ڮ걾6k-94[ =K,_(PbkYR3o&lu?( uDTNZFZ\&Ds[FH 9c0>R,Bv)Kj&@X!ʕY `5q ~LAjO +}رZ@=ONf6w1ݵ4ΞXøExd%B3m?$<+$,_ M;A/Uc?CJ>K?/B,`qPCh#C? >xΝNZHI-v9{(*6" j PpFɂ>231hNZ'RK5ɕ%9+/Mo m3LWc3QDi¼:ikVk|,cZO?ф2u7LhwCpࣾIbfrP՗^ׄA!\fk nKP%v m!PEFZ/AX cWk46njM٩&d^w;,߱pi6}{&f1+Pi* yr}M-/AU t%eԈO(9ZkM&\@Y\HIl(>M1M[?b(rǬc onjJ jA'n\ ^|cLE ?"!sP{0{y(αe[)M}pct~/>n 31<ʛSWRu|n ݲr]׏#3(c3Re񲿿P wZa!WW*Z6s䷍ͷ.mG6RB8P~D2wy@gd~C}6+b͚*i/UǵV<6qof|5|S]U9,غ|觽#q"n..B%ClȞ;Mr#H+:[ydTl6llqחpv V/Qh$ qGr9 Fl$ϬbSA;‡<ACs&]Hm:p:OBÒt<D$hLf} S]KD4@|ǔ2&x~+P56CwUD0; 5>ĸS,KTb6:sr=k6~ IvDmQo ho@#9.2)fup~1a~[$6.{C aI"Mc,FGLښ~gK|`enMv[ePef`營fʻ c,pyd72@E{kmf.DUbMfɾB*3}\sf'p'VR#!i=/GgW,cUSR@m Kgnh5ߜc<l se"D̪:ם@{M4e$~B\ `RlyMMJ3}dQչ$OY+O|F*$WZ^:YqGhbk׾.Vyq>ݣРN\^bt=!4% slMPڸ"i4Re\Wq oyE굊Q47J|ǰV/ Ze̐ g՞S\)h +/iC۬53qTFF"q/BYjHgA~kR@?CX{Y΢'j3Owgٗ$p5LaUZd' c711OZ*%} ChUgsVuӝNBvpzZ&xtve@I !4S6Yk o=CG%=<!o2oX{^M;) sى4}&)(|V|Ե쪟spRJKs2 >K'i/]j вG894Gԛ1~/BvWqF'Sf9BJh{r:Dt_J!ŰZg@VYvM-FB%!L\ILSh֧ud'`>GA uY٩~t-}ES$C B7o[1V^s׈$ F0]!<ސKk(hl`@8F!;Kxn=l(y&0טXQwwhʿBsUc$yh6kK ?X;%ؠjӨ;/)j3R kɛpmJK0ObcH)>N|#`sö2juFH +>^W5N5QQ ~.MS[ mdž+}d@ʉ?< 㐓a2ULȽct5rw֛xPv; UF :`e+$:9K2xs*Z5 ԯN4i_!y֘ 6x,nTq,NGx\KJ渭8S80WT[Pn71s`p!Nڡ}=%'^ҫ>8 |Uφ~rLkngb}Nma$ݱ3kHΝY.3P7GEl'(Hls-HO.0yN,J+6_>7i'KϛLԣ`37!}i5{#; 00@"#+jy>o1Ղ,r8G漗-Lә³z5F̜jѹ$Ϩ TcB _TA :/(}. ZUa16pGNHSo_/8fǡ77VsjN2La6~-X(Ia$K!h>o#yF%Jzj'_o81ZhHLA]ySd{=v [)c9;cй[.iba4K&#Wۈ9L3ek,vhg,&׋龋Łmcn)E'c'5YtϢL~xD6n1,h>͉0W&q: >ae ޼VY7Qgl="qcKbc K*aNG:wx3ΐH?߬LsFhFkqu=u%2)G-i'乀RI~Dl9kij Yc٤=)u},Hjc`? ^e lۮN3ٵN:VHfψ0ؠH07om6Y)uT]ol UTG}>1/ wZ3Jy1^#'_MZQK 4Zn?ggB.m7߼uUOFiDlFZ!/rϘsP=/ POeE94IŢYc,1j;Iz6)m~oy9YфJFͥ<}5X6 VKU?gو "jy:u:̼KJOƽia=]TetęFpYb2&3*7 o5cϟ|#m{aSI:/CEk<bvz*#0߬3xibLML)kjCRmVB/ܞ0 F+OHZ]~|Ή_h߅ &݁lt5dŃC_m5;a~wxn@an0(!hYu!clVp|}=Čb;u+zU7!\G(4<`Vg%tQ,9~J3hWUq0J(Za Ngāާl`nW?qʵ^ jn!. ђ|?6aڶS!p"']Q,c;BYMkzSڅXlxs*67!Zj~y.@zrK=3؋ ᥞPj<CnidN=͹twYrKF #x(gDW_o1)wjPdJ鷆+ ghp8 HiU?[-OskC]x>oTNP#o8AƾuPҰۂ0TB[W0OR+! (B`eƌ^O~2j[QW4 /L?udiIGK) PZ{5AGDUG),'QA/4G_-/9_z^`F-$uA̴ 6!c:UXM5t>U UҁWI^j !|g(ښw.>E[H^]X8Dfupj =N]4Yz!xEҢp'%%vH,!Ӷb"әvhGnX=[]!$%3eK GMxR.#2dGXb?WlrOf޷uH8ĝXDM̜ګeCLYZzOs7-&+nIxkfʃ毰cBYhm ;GQ#^o?ڲu]WOHq${6ZqыOnwp G`\x"GUu|,N/]QAYmJ8Wɏzc机 #Hj-У (Ι ]ο2@cS 2ëq3s16){d[{!O`vBu3RܤYfa.L!~|AM|?ho0]F`lZ ?xaO֒nY=!0osyQ͞ì}*fwNL)~ ߠF߄iic)eam>2_n$hcڝ@ǚfЍ5BF<-8loB&f/E^ƺaʖäJN(߸,2}r :.MAm(ICcmCMR ;c'ݤ Nf^xH<eD|Eo$9oL^rǖE軱w!#޻o O,EdЁ'(N;9v\5615q@yH#qus.ϸx|: P0=r0vko9EwЋt[O/\_'"I<-Yr~!8?͕ tAjR݈Fǜçj]h t圃<+]n͸ɄŁX׉a)(aMDYjGy|,/G*`ٶ*nl}_?$2|LPr(|#H[OW󤞘oab+ "vfQ l Sƈ+*y~/t=l}~MqJQ8;WG}53ME@(EJX`oWRkh:ˍF+\il0X+Eu] 6pr1TSҒGP|>ͩ(RE!jy Bs;?Y%P,XDͿ{a%=xxJUۃDM+]_<a} $a>0e ;g1YoB}V|Eۃx@g~NeP-]tEQL]IO!)zDDw]`rc?2rZBKA've'p|DW-b~0- ~XJK6U0vuPt]RīNGpK%JEkhX\-o3kuanQ&q^٩CK'ܐgTL䈇l7H x-8BNL й&>7 iT{\VN2w\wz!/U0Vɕ \olş4Il"/0C*r/^JKSC5Qv&ŽEC7f>_׌p~!9-=c4-w0s9"(&=%΍s̽;SX0̰ gTvepڻd12hjl8K["9B #u:o^"6ÚNPza&A3 w"uluUN;'G^B@jF\j{w"oxPQٶvuJ(DXfWYJ)'oҨnI?@1So"EzG2U _ձԹB@ E{E NiןW²W4*W,R:U&m+_!=Yj|]o1!N12qLOLe/:?3Otm薋\VՃH2ϊAN71H!gҤ%TnS [׭#`<5j?B2i&sm3r:o*kn6p{i]4mcXŅ󔳣b`0*-==a@]HhB3{Q/0.{HqgHOYcd΁́KΔ?In%+d.䃀[e>dx&oǐq{DafkIhgG̞nԛ(dadI_BMߘ*-}VW8u2x`!FVmyGz Vp7̕2XPf=V uϔvlU$;A13]yx%g-6G+*L&h/D]׋ 1*;yns0ks[u;j2}~nQ쳣gH*Id"5EâH-);Tkֿٷ2/9-$m*O.1-|k<?&,2D%9cص Zq2nž1/DY;/x\^O$]KGB*LkEjQůۂ?gw%VHzZlg@)Q Tx@QΞD=tT_Q^p+ɢu6=pr1)R@sK(fL1=ūc /5 ^V;79뭑!"~'Oe)8,pZTɎޛ!bz'Rֲx tn<t}= 11;;x3F8ag\ =`TqeM7M p`qxjWg}]%/B{B:? y BĕSP* HNlcTwjR8azWJicm%%VZ|71lQPھ'GRg_Պ@U4Ď\~iF*/`ASpmiq"hWMkgN9!$Y;n%,9+!IHrmi N`&I- $q~>kHpml4P쯔ez:Ra嗠|r0C.H{\#ZZA-\#)k ~ddmGx~%ǫ;0^%)(esgy5ү e]I_lj!V)ZfqKłʊaߕaقH̛@: E!1\]grc\ym>m]ߗct!xX܆yXpݶkE*W7)g&ϱI1a3D;E7z*@'L'_c 9 :P{ĸ/x).`[9tѴ+˶tbF׽^o\oā:Y.ۜ 5.&u1ƳL@:\!M*)xl~ Cup͉(X E)5v/&+圧/k; 1E]xcf3o@ -EE6ol\Yw9S=z3=^iAŠgzcŗY4Q-e=d_ f}&ּ$lc/ &jz(ey47 >1cѳGb &CwRok|?k荶džl_M XBEUVt=PEUK%(;9On?HʝS!ir}h#"|=%d?o_gQ:hⲳ>x.67̯a=FI a}?7 D΢j!IjR—T@a%boxL2ʡ&_ȂޑrNqM& r:(<31,$GR\ 6{#EL+`-*LeCzzvFӺ'&_%ӣ h7Þד4FH4*zN]uʑzf I\gN ]S/# j Q=qL뇱DdP>G5D|` {.A|~?1|b}h  kLxBt)#_ S+KeXP&pcT7(RS1um xg ϥdPa|f+/(mi;֛%xY눺;-UѠ 7>=;o-(f[\$E$:z7ֽ.ho}͘N6\BZ;Z4wiAM]E]_ .XC=tZTzvU 'dQ~rbkwVWDyr(XjF}VKWt=:6fb3ǽ8bko?ʐ5PxG3;<(":}g*HB?*nTx1qzb$,], |b#._Vnu ,X}Cv4}a)f53Gv"A1CQS2`x/τ/-Շ~j(`iG:,?x0ܚeHŅpC;pY6&Qڳ0/+}\WNx}/34 4-jMPrib>d:Ndc74D}# V?VNm#1 C+L(gyf _%aw"Sz8VgxMQlT؜#R UXGB!w䞙x@F]k8KUw眒8:}j?<]̖"fV}$ a5g`Ր\Eʯ giv!w_p6|vCPD;M֎D~G˸ЙyQ׭=4 sw%Rn0.$<*mv9 !j֪-udm2M+]:ۮ;)'m%BsA~C8_QfoI*VcJ ɗ󙞨ʦÈ,,p:yÿHff';({awdHhR%D)}$aNĭyԪvx=^$nW Y qaD8xnPJƗCRn,%~HCe!5eP[""ST7B 6pN%'m0qL!MlBc])ȺW8HOZ(}j{;iVyPs9oMײ w"(3`Y X~BL42QSO>S=k0ka`PR8 aFPd"\C,C#R_1L9xM{m%3PQRD+ v5ą6w T|x^Oo$lq733\Sl1?d(FC<`=u>El& 5wsO/8K 庴5Pˋ Vg䵶.sʺ}h=2 Fd`A7qJa0 XVZRůB ,}Ԝ7xDi 3܂K4H{gk8_FHU7}pMj ML %2 HrrM)=n4uSy)|1lmnmUi|Z#fӃ/ޕ 50I":$Gը(@xgǭH10Ċ@mTugx Dt{%?0ՅL5çlkMij[wz^H!G#bFqh > &Q8k\Xy3=U)˲Z7xXU dr]@8Gm]n%njs̴$r4jO56g*U7J-z[\O]#* }-"c#ej,Y7FPSjbO+uY2{e3;i&%1lm32D6'A*$ 0p&դ1 =&Wߛ]H#J74↦,/v q@ymmtjJWAJ_Qe% ZάRTڳq"$*#Ǔ}6B{^&x(x |"?ӭ2dᓺGLY+K ӣ@cPwi7B;@l;3`6[ 7g{y Of<Ǥhڬ(xu3!p;Og\'J3r ;\%0ג}9Wq(¼PݹSxz ROM Ny=uAofT00gZ̠3/ogc؃KPyB6ΐ5"Bw&&i s3QBR=\AZS x\^ p-߿ܻVi=g7 .{§TͳaNHu"mJ ^ Asp4Djlm_UF> k3u̖7_ vb|Ω< ?N笊OGVdNjtJqsw ۅl< CRB~ gU[?~oDm&]!E7Y(PƂ a d?aQO UBDZrsfW/a6FO rעS҆`^Kw֊Oؖ5aa2@󈈞u_۲=!gXoV ߺ^UD U!aNݍJD8JJ Jqz $2hV1,nx2^(Yط[jrǽe?Mp0/G3eӯ2 bGQ<FQYX=%[7V9t,(|9.ysd_'Zě=E06Ӽv0wa-_e3vhIv]Z]!膄brɔZ&nĩFwץM[/?t\ Idf@;/;0Zb̩H(: ~tlZc|/èɃZMk$VI+n@"`żaz&7t0uD,QdFeMʡ02 Fm.ʯa٪c9PLI{)ۗՐO=*/Ӌ~3'2G{XC3k/Gae?T5XUӽ oA쫤'V\x+a-17Yko :R,k.֏Mʸ]WmI&iBcY0&D x-J ΎK%W12V%TN)}I~#O~:Z_A׾se.G\68̸*65JYzf>dQ?~ND(sy6<Ɋ4cIKaWHB"\0¹Zρ?ϖ0WlREv,^Xr-hhCAC9 n뷱*_Cv LwԸ#1R.S`|OGY&{ߢL)ī,M9A]N<2/=hKz>HEțł1. -Ou >=%ysd8$tΛ'pu|IY{ΕH\s݊}݆f!D*4 9JKU5AzQV?O19`оBJL|H[Wʄ#,HzYAfG{95 pBc iuY?uQK~67mւĔ9҃XL}/R 0/~;,"aAC(#H.0Qk+#tn4'R#| ]݁jNgA5K[ 2nT;߫./6Q[*5~߄vi8CPTWP)/cա'=+B`LKyNQ+~Z=CBBT_rSaK2Kƒ^Q'cCrE-\}j󐡌 ioeT *_D<Aȁ2u=2trZ-+AzCr^Mu` S]q{Ž.~[{g&.*3Ӻ׃XmH~rx%h@G\]=pFbDz,|mZWjC*)Y ~}57[@F<%-9CN\B"6oܺ V[͋p6ggm4-]sҢL5G3g#},Oa2TF?zbhvJS8nCu3!0ڝMWͩ%?!'27!g8M8 7e_Y-ϝ#n8,o(ׇi`H]1ǒ=[k}LZwki[pHejJ%uĈIѝbN}qj}I]lBgItDj*Z|z>ޚEl e9X`n;b10?-yW*6aoHu7Ce.ʙ(0B}F+9ų4F M[o^ǩ$*V c[_HP.ؗqí7drtn7U0L;< ʕ 9.7+Θ!Q䆡\oHy}&D 7"T!_5]]/cJ~kV0ͩȜ@7bs2Kd֋1Bidy$G\v\iZ[:.J qo1^!h|] ߭EmZ>&41:^k CAR} Qr{Fo|-M `ٔ]-u1k!9n , `G*{&#tnǀ.߀УoNVj8v(Qr"9?dO>(mRN"A+m|dV%;nq%v3xwɚ^VAf!Q U#ϊ]^Js<4s~r!SCcjr8c* +z4K|=_|׫0ɽ 6kyGv> ;F@KR)w8(dml?%Ө \GlY#ȣb2B3I. t -,]K2m78f!`b(}BoS"\XB&pwJQ8 ;oÒs 6N-))fy㷤JC_t^U9w |^np0"{ak!qX! g?G/v<7pƝr Qh2Q|{eCCv<;zOh5eϙǁRs0f;%1S'r͸=K] Da>TPn$BIĶu$v2PuaK5ꖨh.("<[4T%"`(Fi*3*vU9'Hʁ3C~uoEL8,(b=6,^tr%l3VmP4 99B!ǭ ekhD! X8 24!Ӟcqa94uOmܓ24K#BZn!V2͛ MB0-‰:SѲ).*L!<)LNX[/9};7BRb [t~ γh :۝qs]y띜*PZJda`K5RAddŸ -WLa('fJS;}h [|鐷&!Jv?T5*iiL}A1lIkȋ.AcH˽HD}txY(,.l8|-J=L}kqp CPS(eXT5H hrԙφ3wTq1ۆOýrp9+IUNŴDs(#$/^B}M|G$f1{Ԓw󒼫ShwZbI:h-,yny: `0teQJW2&t[ 旌q♢}KbT,gnޮI|r9dlx,OY"nG-Dc!mNt+Ie{za1RbԜdV F+&ej -ZAOzU!Y;Gt_!c޿k9bU8ʃ<2 w:Hv5_0epWtƨeZ1\4LaQg{>or"y*HЃ_IfLuC<E`){?^ܘws;4WwI@P U^7D7NBGX]9?[|҃'%c`zV>yNM0,j~Z2h2 Ҋg`z zD^fc>@m;]m@tZ#G{&FҒ7u}^ Le=q/ F驪0Ҧ_QSK]>]leȝӛd)W=$`8S$ԁ 4M!{^RyrwBx]ųW;0"89fVmS`-+c1kw}tk&>|&B#5. Dh믻RbL:RU;6twpT$-}_Lr E79EMOyh| .9 S$kV;mCy+ͪôbdD@cz-BYOvbdUD&"uzy*cG@Uy__QU(DlurKH<(cIO׍,|lZj XO <;^e^l{]$Wk" p{P@sO.hdh_Onגb$jޠ]saIy 20r㍐!\RB FFR{h i5 g7Vn[3<$I5&gp[ɃYҋ!%#̉W4c' Vf@MFI tD/Bq4,`0oB:ɋD|q,nͨ\&}S{LP :(%en/>RZK+zʰʒ_T郷5j_WJw^*eT⎹{9̶譳̢3d?Ʉ# \.ٽ&onDlt*DR'OL9f/ls3Oh&\q kIQ bϨmcUZ>6^ fAz\gn2 #vS8I4=Xlx"Fp./a+q%œcuy\-9ǿrW#d] PG:)+O*du*pn y2JtrWA(Bwt/|&ݿ޲R'v45>ӖᲺԏIΙH_Hjh6*~()AEu;Tsf/ۚJ*tY;,rLׯ 1+i)Ay~mX_ ɈG)4l'K+1fيמo@a*`#is!iJw,F<@'탛:Ai[A}$gKw&nr"?k(sk 1RoV\q G\6%#{R':JWDpV{Y.b)< lHqs\ل뫥㛾Tk)1$ *iEDr*aQV9&wmjAG]k?sgN!'ƺ ޖnl 6H)6Hcfs2( Cn˓gLraj#4IB$*c@y3)ć0koⶐ)EF4a4Qo9! o\gapn7.$"`Ih)1_J/J\_JfubKI68FwJ!P_C#݆j9Bc){'9庪!#xy ,^4DHA"0֝?_mQyn-s:@X)-!$ܷר |dd<דtz${?3ܯ׿.­PHa".A paJ)?Ă/@艂u+ miJ)A1 G?N[VGYbCkn0nj[8'zxP\J`1u:]:IԖH;P9HJd)lOҎhl~Q2BAt| KO! Lw}]E$CEG{[T 5{{%䀸'a y dXsCkSSI-H5 r^=N6 ?Xny|>Nuz`[ek#'D\ gc7$2|V^a)ORBVg/MH9KuwˆI`DH, TSuSr U0q@5$p[S<SQR4m?&Q1e>Q~% (Pȉ?SuKۗU!fȢX_[BZg[#[ޙ(?`l yZaudy'')v  2`I] 6ˮg1cO^Փ2 By0x>OhH`0:&ͬB9ij{3(=Ã2. r/Z0uOab\66銘gT*A_vm$ed ?h-} 0>t߅5SD̟;E'ev܇T +O~K {5},͐j^4$NWa1RvԚw/?zyiMxv{O[JeG }P@@jr$YD3 *yS+?&=Y3Gkc+c,A~ѣs4J[KA3#Ҽt+WDZ?A(c#bM$]Տ!zHAq&;(L% ‹u!L(-̒řvg3c%<\_6OSMGmJ*Vֽ9ޤp͈F=ct![^T#R\F⠴8+n*tc T؄(fl[l_xZ7S=#bal#e2[|[ ~d7>{gu6ecY1D6>@,;nɲ% V>7ك 'UjOg;@dS.BNǽM.V[$ZkljWTwp5l"TiEK*B҃t2!5-P.gPA4C"ǟgҀT5 E,va Ǯ6ZOUwܠ>SEy?>Tqßl&̏swL44qkGJ"n5Ks{&oHRbOVcmjيJ:죳s֕v ɲ-ay}%wJØREyR~!ӆٶ^a8^Pf+М^IW;-7rچm=ns2tx:i.~ ?-Q{MD$04EÍrJDD: oJe98qc$* YQ/R\\URVwZI7dže1: '*+j'C$|OOM"x.ԩf9}WYX? S:)]'`sDI;|VXxqܿ4*9rY>b匌Z LBx>EpMvA]QkKqNXn|y/uSDUp,M~w@ VЭX6M"}a)"a`p)4FӓvԶ%Ģyl4m] (1}L"Ғ-NX[x̬dN+U4Zqֳ>;GG"oCL'[Hχ7Mꁥ3TJj{gQ"hޑ4A{%6$GD:fzթ6ظ9P @: 7zpU@.ئ^۱K;#XE2z bth])?kѕt\1'u"<ǚS2[VEN)V.PnH92ֳ~Q>h2u  "rObޢ*OHED?I2;>x)}zia[s h] IOiD/{DlB%Gmws/,+H0bH!VX!Cb~<̶h(5g xn-v#D62G#gIy6B v'3LD M.iYMp {ձIC-G> Xq64H¶BM2,X&\FP3k+x ןIoQmpMϣh @257| IO&\+}"I[K0 [vQ%߈׿y—2G!Y#ڟo&V"G#_̵8l땶!}r#`u.%fP* ѫAåJmQ+A #J{?hhH9<}>,C<R[CWg=fiG1yyi0nAcPpۖ< >~m֪si>Zwx2Xu ɚ H )UXVKg**U*P Y(Crk(ϰe- 5IJS:xaX+j<%T c}\Ӥɶ3'l+vb%Ae.weP&9K2o6.n{}x,j+n>0ͬ hbp@ٗSvf7HN)gQB(W*d)i9O3{&xC{&~+'g㲿~1=+LuNylh%}U), qz9[$mk/0UlA@cиfd:pDĚTȖ'lйA_Ŀr8a}MMv Xe7HRN;B -6slB]'BegpERAeZ(D()V :S_*u9jt3' l頻DX7—1#{2.^~ʚ|[oK8`b e ÀT2#c7te͛<]4]GϯaWe5;߂:|ygMOS`3GI?di,eXy6˶.\>7ai=+R6xhjR2gQt^))sUfaaKi .Up~{ =:˭^Uމӓw%HRA}yC3`,uyZ4dSInkszoJW񷹗b~0RIXELy^(a\>T6bk- ;{wla04̘bS) =UoK^PAjv(>!Ro,wߤ,lͼ}QA%x痕PɄ},I#3Fap/߶EL qX?7wѱNGB⚴쀂xH7Ce^v +|(ڏ=)%W-dzskxgY*ZmS3#G"@o{LR; ?4H'/-[ae]/" x+<#"Ԛ[ZA4=묡m a"~6bǾc:)40Pe =F'PMءC}F}w O7=w0M1=ďǵc+.c ɝq=CD VY5m4gw1΃#W=A2j*! yU72Jag.K7,5͚98mZ\;;?x#lChoXiP=%jղ*SX 5UZ;Yqm|q$WM0!=nEUI"-K0o:{= }'@aڄ(V;U}1DF^hX1͌.=7?՝mx[t)9w"GҊ坱ȶh4% Ԛn%M&Xe]q&_?&dgcTj+iQ\ڿRIJ& (q?c_p8G0 Eq=f-t5YػPó;tr4,n)Du%&L>VP䄕thU m}OK3p> b;̩lEǦWrLs ((󂬤w#+y?!NMl%x!=v\j[E'O C<|?ֵ3!1jWxz(;ϙ.1aI|nKB7˟Ŝ|A3f,mW Op_ }KkBH9~%0wO~+Fy M+Nt+ǒJK[&-FD|[tM6.[l\R~Ʋrn"T:הÀX<;ƲAeҗPu wP:yw^N34 _OM&YxĨ3e=n*OL__ie%Cޯo2fyMᔴΎWwb,_^9 8ފj gȈ;=׈j'{*9`K!Uv‡ui,4 )Ez4p>񣕼؆>-VI:-փVWJz MޤШSl}eA8Kv7ؑ_"xgp$[ .1}tym{U˕˝1V-R-un듁 gc]YCN|Х~'K*%8ܧMoSAƶ~Ot>ci8 Km̰"kxQZ(5g2 tqe`z=4f7RU 鼶8\_eg$cQU!|z{)I?k!x_{9x&R6ޮFjII. 4kna-= :y8ٖ`Fc\r|zuPL%oQ_Msq\@97$|[YӎP}|>ru|x9ڙ!|7A@hmMiʻ&1m3UE\ݏpl"b77@A| "e[J9gҭ"gu^Y(*Xm2#_x܊<`U)qIVa;O{qk)_uabGorz̿ )J"^DDgϵ@t8ł=ژ6[Xﴦ;I7[T7UBIt@Iי j{<]gװ߿3O럚aKTI~g@1Lg]tN±rWSn 'M=IIDgmJYnZ `mUo0u,k="ONF :Ы jي:gc"~{(,_ /KֶgpŒ Ģ>AT&w'0xVc/x}LLz}@"S$P@Tz3PpAPt5tC).";VxTLIRP6#C*FTQgNnFeM r^ڠ_0"(r*ƺԴ e(0}CRȝ&jTLz*ܡ[͛eb4Ss˂?|z`ok]8|j"Jcg OPeSK e&E#38Yq(d8Cɕuz+p4v*+ VyCKB=:(nvq'Wvt|:N'8SBLeQwK#F7w"\&CKm\֗ofJ0气4 ESwiVYv 0Ebq֪Ҏ_n$yd} ]^$zeKxy\f|y<}zo9EpvsKN:6]ddpt}M}:^BD7OGkcwg"M".\b0EcWDj%rjRC):"^7Fuw׼\(q!F5DO83r4=IAK!K+;ķx<]aXO30S1T4ϗάl|arxC'(a7RteZ  zUn) ;U*=תz;RVUW\9iƮYXBs F VLb p]`ރt|dEHMBz@==tnzgǬ,OKTp0n^2qw UfLY9M4"o}g{% 4B"zS#ۻ2Pn ]3͠L,|Qx8[#d2OBCs jVi=g0 t60*8 igDQS%+7a蜜aeٟٞM !VV&X,#Kap8/>f) 'S`;a ]+kXQG'*>F4DFs,!SRei< x{}T$pLRI ^-?dƻ lBqlS]Ж`yQwe+Dcf+ZTѐSN4/4D rv>GLhCVvoDa kVN=4碍gVZ/܎׃~B>Ofk'%%((|Ib4t|`*e2k0u!ƙc!@[{;]&n1@޶և)V0W=Zc2UY*aV4m,Oe+ióu1VElP RYdmXqk&VדǴ|;y?rε%]\2rf{yD%TyK8 l +BR db 8 =%r*a`Z2pbe^p͚"H5Is5fR+L&;_Y:7VjwW5193(A ] ;W5wFZ+H=u&ԣp4Ҿ¾+cE"T^>dXzq}af$P??_ .YZ3@@TH, XڶiLܥԺ8pxa,R'C3 1nH9?odu3{+u [VqUim+R pb{iM  o:;G8 뉙̩I']ʗv UyVb U/Fe\_wuW>2oa!!V+lz +; ~nZ[/S ASp_:5%HnvXu:!*Vz&*M*2'"WK8_=}:7}DC,8Ӱd0bo$CORT\@GCAMb|ZLnr߄_BXۧ(n^K3li}]sZ`2HFLY!/c0HQ^$žܛy}!)hӖ'G? {;M+SD_2G:U$beǗĸo3tQi ࣶUx" I,oTK#w܇Gbc ĴZdQ1c~yx I<=xU숵@ŋAN"A@@B !28 5|r1Ro.atfeK %cjC\! 3 ,SRH ֗x5WFK.oΚ8,^!l{q<Źԇ1x$f"J5$gpL术~sAEcGBHf'߅:*p(@xƉAԾ$ Q"ĥ \?<B{RtϓonEA]ߪYdH4t`PIȘcLRwxI@f$:! L={e|Tr1&=a- ;[W?Fz&2%xi!pjr&$,P|ő2q+$Ntt j ӋEڤ. "I,.EU;uv,33| Y}r}d[Dā|"RCԥ(OZm!4®ė1ٙ[j--5 *B(gzuʷyޭzc/60Cuf'W0ӎ9,îFsɘ>_vEv=X;@>hm%̝!oa]aҺ^v+ Ғͯ}7c@уT3Aî@VS&Lpݧ%zEn.&ZXܯsc*eUDyz@ :WfQ16%o BJs,|:JV :hn)\Ҙ)޵҅BxA(RUbXD"_[9qt Aq= %Tph3b0 .Tm.[BjsM{8A"y.~~657|+ɪ|#ЌfC*ċ*OR|,LՌy -Jo$[å zdڇ/\(_ݔB̼HVor'{(>X!K{yf hغh&cr\;˗V^DSY:HI`C" c mu 9WfZq/D>=*tqq.*rIDLD,LIx1ݒW{)#0ѦGPE]3FxPztB?FfF=}4IХdmӔ*g+S|΢ͥS.I Zi'^ )8!@ /f:W ^J)E7:eLZ;w9)2j&%_/%Qk*pz#(xBLY~#5Of ܰ lQTdVB}}riʟMmҒ3Bf :旅b@30+B=VCΑb=[|Hڞ *AtF:є) V8#! ( 8^4pUeFM'Ҿv+92< K4`VoLE)n ȼd]hM}^KɈlfgK0=eTUk#gOѥYfg{g~ofӜgֲG`ld۬]?$ΧS}He[7mԚ̅ӫy42DoZP6X*(#ZwQCu_iwhH D,`5LA8=ph"hx/:蠠V3r6x8C-av~?1\䵐TrUܬ@sP}@q-){\PQi oBt1(+"a hQ㱁f6ݢAkv]jDLD=,\ uf^%u_K a٫7.X-o?GI?и$p0ɟu: J=SY\J`.rK{ma:밍wfu)P9Yn yIL 2>f ORKSkf#;/ z@Y\+ -WP)|MtKs?-Wk M 0C8VkW̛q9)O%$❆fG ;XPYw57Q"D A{eU9{Q"VFʶng:-Yw 'P.IMxц7lpHGsz4JuTn+@F y,I!SH.t^&9K#=ƞJ|g&SzX"^H縪3?{wDAXHT/ްwL2X/p>Fk"|9 RczSM0yVVy{m{rdAqM  ?utr{+$nRD iHhqrst0ucYy0I\q9ZeCEǢt\U7:W. 4p`8 Do:5oP\sO^t1dU_I">2%Qc"b_vwec3@!kg1z1S}VΛ*IĪ:tOn2lÇQY7?O9sXOkvr67~9O#Cj;* AtQ{D}G'Aw{ Dx>|qnZ]ۛm>1Tdt>Sb tO0 _hڌEo%}D^1ߢon5X@fC5Tv⎇]2tz3**Tk37Ȃ.e鲷Y*4 7k.5U\2n,ENR3Nԝ {Tx|9yT#h@bi69èޖ)i<>\V Z}և/&H{Nxͪ֏ό*<ī4r4uxDqOZ<,hܺ#M7;x,;lV3))5#Q`A)i(/îC ,[!C}Nd:-5fNn};edr3xԬƧb\)cIa?j f2[`?P.+A6jbhD܆K_(VX|C`?,3),592,6llኣ6 ^܏r9ۆI*i".x賺 5 }~nԤLXC(VZ*x<} fqY[259ULi>ǎq\?:%[Ăׯ3i3l2LR&J1#9KMkݠfa_4WaΜ[ZD<0xC,:+XvyO؟L5-c}AG#5Bl2V8;p) `0ċYbۓU1v%滑6>fXND4Z)1uxw8+{!`ܥ'ze҃.&Ї]O.j pqEulaH N{tbɔď=o淂2IzV(zӄ[k+ei*Q?f  l4 $;ro@d=ŀCXQ\I=%ݞɢ] {po GYlrAء(ښE φ F:(Hd:x>$q?3Bz]v\ֈLan$=$p$?Y2\Vò7FtC. O @12 E5}è*9: ĥ6#9 Ok̫/Zs O\8YD*ҝΛD4MrmkU*,4OƻM`c>oT|.5pb隣xpgS1c&QΠkrzm6,7tNw<&×hOolP-.Gi5`BA|-/3`skWTOSMMf ޚ.ϯڠ~ c{oZ2'Tzu E8CA=*>@ +"'L||Vm$|@t+ ?8-M<[.ʗeʳg8eGCtcJU>Ea`Y EgEծ.T8ڧXh}I>ǔ{9zܪ13Ԉ38?bȂ:NB e>ou5]P~1P*KאwsɀUG@Y2hKN߈7vTMS XAaT 7}lC&齓{ ֕$z-.O jM>,؄g:]X= >0~*⦆>hl`BqVt'b_U%0219u&?supB8+NqHщ+hnK:i(ow>;E $tΕglegF_η{h3DsFo׸X,.Xk",6Eϰj;U\\| ;/ da6Z~l99YC=r5We\/!-z CƲ蜺uhԃyB>;`nBO(ƛ#|^j;d'/JGtNgF}Oikpa%(7 .ܫF=k-aΠ JR$8S[J^^"ʰ{IH(R켃a{/a ڼ=A#L4Qr2xtHcK_1 e0&= `NΕM 0,wU;6JsAt qxc`ƷOEJ>UskE,_5BxAzY0׏agswMsT:*aJc[rBSș@`t(mLM7') M%!%ۢB@FdaݟUe6 e~+#PlP+?U"#Ka^:C!FަCVt*d;wqMq>e8$Ī._8f@vGՑ֚$eηW8ٖ+Q -&#x(L#_,l' ֫P|iŶse|I-𛧄 ۘ`9.tMv$fĽ;IouMx1X_.OMWu<\/c*#GF;iODWfRYe)*v;5uF~1/G@Պ:Za¦Xr1zx^a(q*/SR~wGG\n]B,rRNo+ R3GQ񯯎i&AfGz㥞c?\$)|B9z%3v\ 8GX@bWoqk|Ð|zӜܦO\KWo%͚~]WFL=M2$[ͩrU`g1MasKXe3+g.oI(*sch#@-Pc fνS}"g(slz4_bbJ)5&ֲ1nV=IZL,T!WLr8=#Wz=ʩ qq̲QӇ)D/Hyx\D`D&?4~@m ]W7WsA!A])sx"!|o(^5k!dzwp@|S``6Vk /`8Sv}TJԭ~2eXEoMr~R"[ȖZ{^AoqGtkGd Œl5;PrYJO"mXɢqX\S`7uFHyN(2ǁ7 $f &;<"`Y> Soub9+``l2~5K< k""M)3IмaFB2cl"[ RO)8UjJJch6 EH1@XThְ&3&HـtR^x-] VնGsKOGi l\u5rcX%6}BD찓Gz wq!t{G=|?sK/Kf\j@h$5䥧aj3nBgVcJ"15ȻLkJmP3ѱhc1V X&"s?A~P []v!xKc颊Z%ɠJ$PjMu{ ӝgf[Z,`ɷlj{w1mV1Aļu_j1,^}<ڨclX>870:O5p Csą:V+ S֡"Rwmޣoޫ̋SN{>C)"N9◺JvȺ1b:KVՌPd&ϒtT*Z ttb4#7\4ʾWP 'Bǂmm_R0h Sǫ#) X5bF60:ͮs=/9\dǛ$>YDvX} K@ $ a lbl*Nm|Q#1,\8O<%R0ĻNTfr59:sb1&* $1Ƭ6j.!^#ve$۟UJѻRӯ+ 6rLC!}gN6GQ?G$gmc&Ϡ6q!gY:Z#v@@EiEF7|Q/JI 8MΞ*2nYNӐo4@Ż) rE>;:~U;.Epahhr%޲2\iK:S f)2)\42ˡ&Oo:]&Q;`-Q|E&?\B+HS3ctd;̜5i Ʊ9,.OV\u hcN)ц`Љ]l /f_(qZ=Vh3+j]ޤj[:(8Fg/ E2iiw`Vb%\'v~څ J+|z Rt fU|BrzZrxRp) j;gjw{P7xq)?_kTN'u}_*@KqFي{W8kQݦKfK]pM1Ҝ*7d~M9۷#+W̞h@-&3Π9+Ŵ,Zpz]'KKnXL+ѯ;Ϧ7Z3 ""UFNW7RKɊMjI﷈+ ^\ H#ɪ/=IJmPQx5Xo(OO#"kMz! \z'@DIadڨ stի Vȴ4IЉ|QT @rGTsB/c #ӄ ImxK&kqAE!b:Rxvɳ028^Rr<4LʽU0&'_m L)7ZN^Tzlw< ZK9鮒!ּ"~/;bF8nsur/c)?\ɫZG1zy5Įa!Lxmq=T5s <1y'bareDWbM`C9PayFVcI QB{}fP^׫营P85t$ѫo7)3.V35aTchќWe^sWp?GjƝiϏ>ybS`vz%uh>)E-5xޚ^9I9>k{r)xiP5 X/D$U[\xZJ,],Zy?1^z!운j(|c1ꀼj AHghn0v[o˓i:9x̜}_ك)yDEeQפw+A8 yW~睗O/]T?@1sD jd ²XX>&5꧁ن8h,6MD2$jYYE-(4S!>NQ"mNX`KDT Ք[4eM8mۉo֋$3񑛔q Wco.DYt_ <"ٯm ; dd8uR>ui#Ērݭ2VweWك6Fo1Hҁ#~GE _uO#!U#9uEn.AljN8Z {4^S*AE{%bƳbcP+|l;()[UM ::h["=7hT<\W J`d;R2L@$#.[F5W% 9_8Z p,=GB7m25dQ6N VA;=k]; a|O=i3N[Ucw5K=L$EyiDxb6wRquW2bas0F‘/FWqe%O8QT/TD8 Chƭnx]Ĭ-js?B-^#0f A [N4F$iT.p5oZ}ˌuN7* ;JXN>_g| Bxa#-1@wL(Yx7⬬sJ.JH;iC5U6Pe~u7-& -^PWea# SLg$x{YasAeԞ7+,CXH-2.z_W!4,'s?M lV&YG꿢s֪]xt{ ZYrǗ0G9mfŷ%;?sӫĽQezsM)ӟ5\m7 T[ 8s9e;`ɖe"ߢqf6O]&/x[ʬ1r\ |x-QpFRQ"a}9s<|XCxAL{[ l(8Gi2՝Fg~E;Qa+hCĖN2id6$ sEC2`WG']zP,MmrG+|!^_ǴBA$-!x<s\Pû!dZ!S\}GbI _lҩL#!L60(QSa!DPy Dw5>$ogb޸#u3`LѠv1i$α.AtMU"DEPZHIrWopBfbR^v;iiWZrn^͔aKy^C ž95=m4c7MV:fi=&ZD[ v{D~gb=|zyz^[}`.W&r/%0(dE10#/ 5җkؚ&4ܬۺX/H!%N:߰1`#gxij,N-0k'g-\3lVa~im 7vP<C #"sBIY,zO ,Y/th${m :3lx%FĔ9֍#Y9m|ܱZiK:6 G`=ٖ @ F;dk0Fw·dqz?H.P?'v )cYîۧQz5ۅOjScl\BJ6*@jz_vςE>Wnkz41(~M!Ӕ^35 [gf&^yL[~)߿wvA^)$tq S*5-F7 06\qu8&>7qڄڸBa*2\y朷~&or%Ïh߅Y;9x%ت*>h}A,3DmmWpVEJtu޴Ia ЌΖOJfH"z}f@$ @}$r*\VX7c--72|T[l ]qrʛpHKn]m)&٭.7zyѰ5fn8Xvhq N X2g*$~LjL*dJ4 r bGǚT¤3- $/]"bC J.#rr tx6V!6-Gg9YԃsT[]:mD+d'Ȳ"d@W[WS3.j6DRe: a['X o!P7 ď N_%.h *e{'̨ܰ 4Й@XvL` -9ڵ(~['[S  lfcM[Jڞ;t FICWx:_qc:"9t}uOaG5P*( Fj( ``b/5_q4d9&[_=l\@EFsԓ|E&r3=YieoT7#rn{Ͽ#^hFAUmWBsJ7(nIm}r-"DpW7 ?EL><^[GD$CA=2|v]tx?5aEYe0& *%SMH4I{]ٔUCd>>mxn{% 1\gabr':>ALg[i;ogyNjT7ZZlc1KXCX/(I [4ƯIEːi2 ޟ> 0Mw 6+}ݞ$vut)a>e0i7>p -or"cb]<ׂx'^S:E+pKͼ$g|i^̲Ʊ$39~R]"~B= ;Zl\ŒHTCH*V qb\q.j_)3V/,( ޥ2.O]22h`QPeF sJ\ou "RX TtE%lh< .Ud 4ZrnS v/^g]MthtmјdenyymD/C[eq~\'F'F4Xz=:t>e7L$Ympt,|sZ/-(F4N-A2f\[\vʢϭ ؂m[|[P3L@> xKPq1rQ>70^{$mn}Evf&SF@46ʱEn;i2$G)&E 6V${wgo}2n c[oe3LZX`6Xg&BMZAA>x9DϩE&І=&csECsNB^✕Xޗ7YITSl!8aHT#$+F.F'eoFBLހ3sD =Y=QFS/NbFbHlLhym9j_[Rj{q1Qo`p w-!IEZ/tpA;m" G~s7"q=wR$ZsW&o l^=g4>*eA[RⱧ^QyhyH,󬚁X_ KzɝAۺ+Z{Z~azܗ GGDzEo5&HI K<N9w^/ʺGqv{٘^U0ka"a >BM*>VVjAݼy8kr޶'͠" <^4TOM?y6"?lצ4tYJ'4y 4: :rob2(IfxKZwu 8P̎3Խ?D<~p:.` 0:9Ic;譨/2hʲ{JU߲tRqxmRE Mz֘ͪⲖe[!d4̪%;}a ;46ɽ dbb=yst։W g~.xKdn3UMu H aERcc\ Xc¤P}̤)cZѭ;Z%T5xdcPw=Ji!ꇼ^fi&Cn$yð4{g;`fӦٚ+eOQWp,ZFumQfqZ8`)}ӹdѡ7# rM Kxv57 g> <Z `+<>Azhk"{-CR/:%Hv<0UKo}ำTCH).cpٛGH:֭?ZE އP5n(k%b)eLrUqܓ;ܗGYx@٭=Kl")&ofU(-$°\:aN7k vZ;!iá,d YeM϶|P*9VOY^형:?32z ΡNo58ihpi"PqV.$Cd6a" 7/[6DpcX8J'4~ =sh1dDA-JmIp~HWK -L᚞ho]1}jaCZf siz:MAk[87նu a &$Di 81UFRͱ j.ƻSvc}CdwOָT9'XlEVTsM1Jgp^rf{1J ` -sD٤#ahP~yf6lm qVV6F"ȸ*q7W@y!7sKd)&RI]dDS(\mʎs3ЉU;fhaZ%:Ôǭ|qYM Zʀ|?=W^]2o.$,l) Hf={Hi[Ov+MW㩇 "a/Q^˔8E*4o#$BɄ#"uBH4OUk_μf c㣬1(X#!eQm*w| p:ּ`u* ƿR[u Qd!uP^:"㾀֧Sv" ׿ 4/+88b#|6<_mf +`Wd.iF]H}]*I,Lteҋ1. 8*;ˆN)q~wDE*]5AsP~L5 ;8%cPk{ +޴)h|^@+Qֽ䮒#D;LXw?! %_HV5KI?nͻ/Y Q$d@AK0OZD_=?fuK%,aDY_.\j kc|=ӥx'7+1QքmrvKies喆" 5y`Q#%!WrVsB uJbS%lŀ7sF;c\qx GEˢ붖Q "-ugȏ28 _/nZHff nEHNEm'^l|NLׯJTXIYw2Lte2cwY|j@41r J |\xWnjxd\\)0*nAH/XZ.@`%C3/ݠ #o8b(rOQ Q^t)=֖}EO0Mɛ lU Ny+\7} Ϣ'h 03'oS/FOܨfɃ}z&!^rA,]%6Bt~ R#Isʃ޵ffp9"X~&r2HŀrVS:lzl*])y9W9%DzO@lAv/-p,l:(Lѐ)lnl4$*t"e,iq:_M0օ}S y+ж/$!y^EJR6v/ hxYfs'yJJ ݣS"$"{ʞ xj_VbQ(s忻_Ai ]ϣi'<]4Lq?}j^qKaʒ0C[ Cj.@Rt'+nL:y牱R׫@(2'(vsڈ?/d: kNBdFYh#U< .*bsB"qGVK 6C{30 vǍHS TRɁ,M*>rz3UԸ05,fү.(KN^ v[-pgŋ} EQ B/1]%H,ƕndSxA _}>w_ 'E0iUBN4ё;&1ϫl}AVfNoFآCrGB;Ps 9s/[pxc#f^m+|'@Xq쥡gαFQw{y00N@uJpGlgB?ÉC_C,BAWInGᙿpLVc3m k|<p?@o"x[J3UXN ; y0ZC=VM #)zt^F}Cv.w`vܧ\2 ݓZ,MlP|5[nPPxo )^igV_?ͫb9b#)t )zv1˻/X*N&vgC=5}neh"[qIGDe->JW}1v7cb~e RYKu݌pϤ^5,l$kW;,$rp͝#԰mG>kZXu^OO!Of@rp{y:<ܴ9"8WL. DSkNaڞ9P"ET~༠˞*Ʋ{Cx3Rɶnqag 6BSdH/ĥ]P nn%oZu; y]-ogoy\NQwgusjnY:qi.{_E"ȸ= L.Y_ &5ʹ;$ ~lAACAz^YMt 4P:7❋Y#Qf jBh(4Fy Tij{y nU7ZC`{QV]w m뫫U_9YsܾxSeVR:LdƆ:6䲆U]zY5$oq p1S^ՠ$/9Q[NSL#k銓12,VsS4b>Gph&w>y/d!i ':faԩӅa[]ugo5|q18 GP ufc? A,4Y\h]DjJ]>B04ݫo?#J<95;v2#(nz oM>F[aޞh=\[L}R _Bw˗%edC#]2.HDK֬̓T_E:KƇ:p/r&,5.ތTC<L{CF@{.Br{.gIzLt\ˋc0p$6p%9=!*B釭zV=2"啹w}swt;+QGA}?ԛVDOD q~37jR:**702=oXLc|C^Zc߯ķk:nduF_@Jm;mjc`iqzGV-%.+4[Ycd?0t!a&m7_(f%h3N!PAU-G^1p4mAχdq}9 M?d AS 46duy,>jHqV)b!Ȟ1w3[`3̿:fq.5Y ePvݛ![-X*dž3IR|wL2=bX)ړP0+wzcZ 3<'t_&x,/jv* ވJ_h;:_wύZW sn\pι)tNINd?xd_Ayxk"WM苐P΂Z=|m7TVt3= X?:l9KO?v}aK !yxV++}?,GZ±!5IģYQ)XnDoak2r][:Wz7gن7Ct8y|~?{퇠h^B+Lp)gi 8)Ǐb}@WY x|1 9%y"E>fy z'FrFUxuP8vىOsB ivnjR`t4W!&\{x]0 qmz6UyKx` fMf/}j˝,}"\&|(5hq7D-u?dQIx*@{ܶm9 l_< ހ3VggiziĆo@KTLF:- ]6ѯ7yEr^NB IT>ۘNjtz|@;DK:@^<@4{}o#Շc$ E2JLt?4,֪8%&~ [ω~>ܢ05o]w3D~Glf<5fK}=<(9%~ x6:{ap)<5Yw(ެپ8lB`$R #XL6dxV.%2*Mb>O(ؤ \m&qlB2_`jvjݔ$ |yҲT#xv Z-3܀Bq:<+T|{ Z5" dtIde+~[] dDFCaz L/#TǗ|CoTJuQǵ!3n]Q;}2ޠB1].i&\H[lдbhl.b |GC*^]CrZ_YOvx"):)xA;LQZٹm'p3^11kh"~N,ꄤyHl!$Og'c%Y Iܣk4U UdJz913%^q wB=GvpM XU.k^<݊dN?,' ݬ/,k%EJ+|-"Oѡ&BϢXk,+ڭߔ=4cd+k>,=0ezt#f2zLO%R"'+b"L_0U3؏hdMghB8רDP_߯$GMDA8G7PXpcz˵lGEJ%m{,jȗ+׍hFlO=Ff՞Pq#7<. fha"-S?cK[ʘNƝ͞9.H 0 Bzf-fdP7z];0@Ϝ]~9\=!讧{7GR3pL6gEnYȵ.?rp0ZO3`Yqrma;7OubQ2 *ulG3YA N?_Xu WЌ1/>j ~)?T[,F[p1n]gLG#6Ylsr~ST;phvw8>$޿u(ǓpzI.VAyqL'w`^RP+Ru#~T ii4ȜX1hc{rp1<뉊UZ+ N37*D-@,<(L_;`lH>: d6e "%LɣN2eޯ|^쟐ʣ(.ٙz[ț/b<9X䝌Yt(tA3O_TZwʜT_1ޗ2riֶUA+ FkB24myyfU/z :I4|+E6~դ>/xL1ظ6dLj];BoOAxdwG-ߞoJ\bgv]|xjAk>N[Bi UCH<Km`fP#EB$z }<(l14sWYM8S0>U2 pJ}1v!=k' #i.f᭣lO"ra_]11R@}P₤oW E/-~DŤי1Gb eo{wHݯ-<&Y ?"twp&!tXKCZP]\TLp1 x4Uft7ޗRf`g+JI#{> `CZzNb@4( !p,NKNxN%g<>z4/YWA"і3BzqNn=j_*> D2{25|vH'͓.*('53TH,~;JÌdFhvSRBMҐVd.5Es! ˋ)@.~N91[N0(3>FpMOӋG&d+cџ-(3yfr'O0ʚٽ4r~T˶TᲩ,Z-R>+Cq[fGg&maa ͧpcK j YZ>HyeFϐh_.% 0]U-Zޞp(3oL$IGwAa[ēyq ݹ/ebAX~mfsm6V ]O:<d^[nLyss{7$ fO2>FkTh۲\{  | ?Ŀb9@IQmqtÃ`Q*=Dۧ5#U0Picos]ZD"XIM{jN1EG탺LM~l6C)^J"z J]@5Тu7hn^#nIux 6ኸ4d)Js.ÎFud`T"bl=a'G\MW.G`N5\)Y{>!lBPpՖo_C\]~e񾡑NZTd&]+OC8 sjrg"<-$KZ \9?Ds>CkR/1oAdӣԔt^eص\]9޵{ Ϲ$Kdq}]-U {*<͟8ylt O!%۸Yྲڙ1'K<`ݑ@\sEr ,lT5|$=ڏ~ORq+I\2vOdSiTƽ-jN$h[X&S8r}"N^*ANGC <_r).l~ & _D{&[ Zt5DHB|0.5a7ٟ0,H#ܱF#ɭ޾ښj0 {zWnXC|wM??oɛ8Y(W*xoR-N7Za!@vb2k7=HnD!|ݡi]:ctF[sB5o@ y C$y%!C^1ۭE=]$%HCՒƅ*7{==ៜ~U5靖O%A} u;G'g Hu5j-f7/\Cglnꅱa8e5,j_ӏlErP % 39ܣȖi7^x2~:piïNUYl{j&6^%;|@͸I[JFSANScyOu_ N島5އlQFH2y~x]S)y߿v1+ } 'udS}75z'M yzkNC [0%*Dc:*b~h^!Y<\7B<ЖU)^* O k ~N!kh;NN=+3z "hژW X.nm>5Eh^as.|7&/P¢&-,[rpU`2T __i)ݐdn'ik%[!푷ybl^o2>׊*Z'(HKd&rХ:%ܗϗ9mbCje$JTX…f3w 7o),m8  tцU6E!_~(Xs}Chz]Q7iG#F%uBq"-jL2h&zZlv:xTٺB&QR!nZ): v{K҈zvkp}Fe^5G3VP:ξANjb z s8@:Bw:oX"F]b0ZɲQXiz 3Iwz+ֺ!2simR'e6c>(OKfu.ZWI(z.<Y:(J.RqIP@5'Hi%K&:@VXE١%r\ 6_5Ғ^ɭ6-9HAt ?7YjԲMQ94{(6 Bk)UUIcwYz˷>kY4-\YX;\#G y, eX gsI}_yWR8DD@c+*)\Oh)UR(Qn d\!>Pp: K`1!39,AbH$ehjCd|\k@LL3GI>֚ ^P/H3@K}l tPQ/̀.>YU5+A[4u?inmw5%  @lǟE8}0(tE yH6n+HQ ezcj=z|~@&04z@An%Gam$J7>d.{HCSp0)e )Z`#["""BRM1K^_5Ovm1yyL@cb*(iij9BD=D`̇-f*׾Fı)\Q݋WIP-t#>8x,` r[sYX 5%6H71%&܀Rϭ5ZZqI `^n($"YWʴ$[ h2踢 DBU SߨGS׭1 pخWs Mӿh/T*ccfws 6YµYhoɀG96myd8))/xҬhY +_%tcoA+z,wV9 &Vbo 4%l>v7\Qcpoğtɼ3u>ZP乯:OeO;` WWJR츔T6}u,PH a3/ņi+CWʨt#Kng7)ִYOx8q 4=uov}/W3UU_`ei#1,g<3Q)=N9ݒ7OP`9| UgpSY~ȍOV7^&eva ]<,6HUݕyYL7,ON'z! ЋPݚwA/oˆv`/:?hb;ˌ('m_d8p^$ O<^̺*gڋ^ļU-b7\?0SCsn"4Y_A88o} .fp7CC|$);v6RPLX&"]6,QJqkL\2Z+>Dm,s-vU2ӖʤCt1Hl[wIU:zw{H8A"&7Lg\up,1zM3z$CfykʔdS9rd!|D,=W$-EuwߴY sͰ+aV$5j9Э٤jVE|C:ţ\=; ^QBN;VʇGA,L9g.0ᚳ:3^XR Z2vCAp6/:ɉp+H-ξ/nR+#1[D|4yXjɯ9v+z|3.T^'W\DK`d%[}zPL LJc)Do|Dқiñ 'q- ^$7;DŽT;2i#t)\~?&b < B%-1F'(£6s MZ 70@IP~D_&c&a2kLmdBrPVAJ,-}GFC9lќ0FT֧S-HLV[MeIZͱ^?hӣ$먉aޞ#]d Q=)gjl]q+\ʯe~@2]7 17G?˺>KuKwݮYo=Ějn 7Ծ#P<,RU!o \P\rgWXJ;DyқA^ߥ94o oKgeBXݿ<ǶV6a 9ܖv5XsT2,t- Cf4\6Q0#+8` ~NU67Dةı$2q2<d)oB9kPܓM0 &߸&\iJg;!9-=\^52cPsٳrH1)qZsZ9ZJ9_@F"12Y|& -Фg@5הh:6Pd٠K/UA)fXbj 9A!M^TyG1ζCRPw;fHF-)g7oj݃ܛ+:M^Et۪a0ClO}^8BaRQl9@8گ ]]E55 #C-1O7э $raxۻCmVZb ~J! #mj~%yaE=Nw//F=dAbuM>m)&M7y$/bf. J֜Qxtw'S|4] rPR8i25l&4(R ׯEӋX:""$<RH"vHx3UGN !-ʢ?Va6rDk%BF,qop\q]t1BD `l0̮|m@;QcSSjT"r1rjJ8y# UJђ+Re,Wy&04B5Lq6L=ħ4\#1b&#h峀(.r4[0W}>ilp3ӹ9D ;Ra)?~c(3qP)zP?ڄ ZPmoJ n?,Ova~e%ֿk3N) _ n>92y";z3W6.M$G՚mVHy{6FOiXVc)x6MѶ8|'t4SWh?n2A{GKZ #Aee@U? U!ȥK6o.2g3c30D>vHS>I[M\N;Vu$ @|I Lv|yfw H]*6}M#ةKwz_f٨>AWi6f72F.8O>o0=QAm;t6%/FFxoYPNc5"Sh"xߗfR}0{Hp-Y=X-\15^Ǯu] &?&oWC}ȷ`05>˷bS^ڂآΚ.3,n/0vp; dqt]#Yd3Lș`Qi眱]q_iZueP(È-9?EΣ;N5WQ Us@0RXu{}iRYC+SAPIt lӾA &C/$E3xIku ]( $ܲmA2KJ)qAW`,[GO=G+RY;-UH}  "OꭼnwW1KJ0jlI/Sei5GߡfU99;[q_yS;qQym9Czd3caܢW# p rV`@ AP,LD6kmA|ZƢ5‰~2t u:ZJД G7& e`D}@gɖW3!_u̞E-gJnpT zDݠ$kwCe=]p.=F4CUջ3dT8+ͶtX MTV6sQzDujbBԆu0,!3kIC~ 2~f ~7gG/*QE\ig;c^T}Ӂ7wa4X KI~2,6cLƫ^9kY.)VD,!Ub]^My`>WBZ-MO5-3/>^1sp5t` EoA%$1yZ"JHVZд]TSįQE .X-=(c$2O bI yn/n@*b3O%_hc #F: /v:d&?vV p#)Z$F7*++P)4; 8փFǧN^%f֛̣̏.ǥ#ޤfƨrM~u65l6iȍOp!~!E90B%D8˱0&L~iZQҮFy#_=1%`56( CV1gЫf/kό{kڱD63Ϥ/ |g^%>N 1 (UF}D,w)ZÞXߤ.F}-@7 veCӄOjcjQ,%~x|z 'W+X­jfʼpϑxwPs‰M6bI0yx &P̓mFt@펞Mr[1 #_GY}~xN^,v% Kyi_9ep>1#D>^ʰf_€.Zet9vֻf/3-~lSլ ŋNySьNKjEpF;TN i57޺R4Glb\זy3uQyWn'5LUw~fmԱyoִDMW(*M ÷ĽƳKܵ pqt{@-CӹD=O~-'^(!zBj*OUYk\"9TO,8QeZf :a n$LZEoBԨ5sort<}z7@]c*CKXWV8GuwŐkh fn$+ExJ`If;Ϝ !=`eMCT WeUZ, c^\nQi7Ǭz#xO2蝑V>di^k,@ A`;ȍg].ި9șӤ/V_5<1 U<|ݎ-$|-) V^E:LʓM"kћhs*KI Mb px7 Vx^Ye'uS0yY%-*%3 7Nq <^IM-a|w yIǯ%z^jμlc ᓊ;a ov#37)(UBQYHSVe&VՊB]in<QVnj'Q:4 Qg.֏ia5NH@8yFQ%I%]!OŢJ R_=+pق37oAl=nb49Te4`"ϻxc奤xG .ϑux9{^z*uaoXxz$&'e(̖SIͬ9Wi~Y~){^Y '9)Q|E&B`-2 뉡2gf "}1B׀- p [ZhcLExKTTf>v 7 Zd\䟡ob ȳNˆFWˎM`] n/&Ƙ$5nEoMg[޽)ޝ8Wp'>zLa{;2$cy@PФgqu@`fTz hÈi`abZS,\@8`P\;5 nPu7J7O膑h-0q*i>?\,6 F1[JE5+9W.y2Ύ& xF@j\gIږJbMV'I Qb+2ӁaDu)z7DJ@a2gA0q_\cs[*2&T֑_@Cv, YfjKzōqܑG4&j74ca:dSD$!QqpQRS<<4}k~݆&E)۞ЦWp 'Orc0o-cl @RjvPR?'ʪw݇6M g\/B!ᗜi67tq8K9(HeH38N=81hVw8؎BpwKvPr-[pƸ`˻ɛzA!\ "vΕ~wDsp)&qp(!mB❆*l 0#!{Q k-UC0m2:27#hcPvBB>GF`, }eO=VAS ]"HcH$e 1Kt)0O~6kQi!p$ί&E;AQĪ_ V0;i]le9E~^*}_" E"wn&5sⒷT>pdjzAZOKif.i%~j)SmC<ƟXD\1QH}awAR{vxdZȩU{_{O3ޖ;*0Eª>#=̪HqrHS@ISyMQoÃX)c?g/.!}! $;ԇe6ݦ ǙU dzoMB9u奄{c2܁d0}Hu8{Bϼ?QG#EW=!x_,̞8$xr诮:[{3Ii5&|du6JD1:V.jR2ڙyڽeضw/\]c"': Q{VM~tz&Py 5Bnʔ%xwV.ɯ 11}ؘ1͖϶rrb}~f%@Km84[P^ZH/@dGB`x_$Gol]wO3y\چi̬;ƚ<3p.պn]6n031=]n-I$-e ޶\#uyw}+R@SƜo=bj^m2I=C|ݻMپ`]Xd;}既5WT*p&c(dϛf'MxՔ0#,7Vp#3FMMXu[jr [Bf9mx\]R 阎?OrꋚQAXS kZ@&aDT'gŽ8,6)95'ߩo%חP?٬#ҍCsxut^򡉡5Ga+@rұ#"pM^(ip&M&o1-kv0tø+_NcSoRWXjK2Is^B\tUWųt 9Z@F> [:n.?LFVv_^YW'Hx 1xM=F ǸV+6}u7(cxts{0\ :X>%X#pJc, &} U-{w°ӛsQU=J.6cTw2<V$OԮ8'Y Rv]+ A.ӧW=i\p‹C e5+mNqWlV}JnO_2 8\[39$.!CH^ҏZtWXѦn` n1 y{L(BWjGI"w 2mx ]D(qqӔBxegPvq] ㌊Zc9)rhS/XQT*`a'V}AjKV8q߸"\;wrܭ7Qn{Sp 鑧tXE@v&ɵXI7q=+9qnB<$~S^pF<] F`_Mb Sq~-ܑ0d_7M?,P.C<~j }L'0[h5筷jܐ /Q5txU~ lAmEgeG`LS|kD" ̪d]|'J`<`շpB.BS>`Xu%MiN oOmF UL|˩r ֹws DW@M+lagoqz&g\4Kz8̋8`K/]^ҝ@uW:Y2/؃i0XRmOT/B&ݩ> ʕk=F2NSE7|Xp"7<@YvC7: cK;aese)mMsL[9&_ϲ8G+)̚iFJ fՋ@^0u#LffGZx'-{20 I,V\2r/^+n! g0@Ml;eg P^a7 @A n桞ZAFj ULB@ -Zn GC 4# qnV`Q[y|(yV#] \xj/VnɆy '/4PDp wobOO`yBHu#n#2GFVL40G |wp1_Nk돷Jq+r\0$1l'^!S@/ғI'fw-7D(;]w%i䐞g TZiP{m ¡?d]OB7YѷQavfț0SQVu"J%|J,%9(\0HZկ 7φWRÆ"9,_Űuj: `jXkf[`rqq:3D\hn-z%e'y|;fecxPR SBN*Y ;g ITĔ;hM[.bj`Zy2xWvgnY>6Lq2Bzau*1:eB:di,Y?=Oig?V/Y]1<`x)݃>--h/ p`0nvuԔtnDXp"%,^B(XRSjaaL]aHQ3~w2S 2 q[ JFɦB˼99"{d֜41GSptH]^:zzk2bCv+Sxtȴ2$9}zzБezƓBփIH}_]dzX\C3@GѶP }8(,Nj&Ii_sGd>7V~}S7tٰBSˋ#qhi2ģ%1v_*4c2LtֹI`5L*"l~yvjNY> ,`3^L aM)[r%_j&%:LS ܓkXxͅ }$03TBGޚL^7#8BtgZ#Eh\>I_3%\n= { +>4"0o>(8Б q̭|169gP{΅y _f|juLC'!yXosm&y93mF9~R$r}a1LkYfD;o%{r<qX]Nd6c@{eZ*S \Rc"ɶK_]!=!vw*51m4};:k:U $n c]X'sIM$Qgc,h DZo?^Hd&0+[ig'q/3+iLoќފ0d2m^Ai_.utx1ùVN b탆ebz|A i3!@vj^;rđvE -#ƪ}!k]_9'z,АIUn &)8'g)2c!ZսI+ؾC>nG@?̍M'%ԭ~9%LHywJYx)r{SR0LȠd!ӒdrԽ: l=5&Ϲ+,K$=~DvP~TҭʞF?&Ø(.%p5uBMԮx'sPp'|BUԞ/aDW㾳%w:/贈f1AiyqE Qug{Qu(֨E򯉊$Puk`Jkڢj 4aaq֕b9Ț.ᅘT )=SxQ$lx[lj#Qu#Mnw{R8$O\)lTPZ6=z_ 4@JE{_;ffNH_2D\'aBq*]5«;-hO&S~e4V͂6Fq-FBKY'hXSXjD"&8Xw|fwѵV6Y̱w"V~E,OӫA*~#䌲.9\6 e0 3yV$>Eq좡C’x&X+'GY9]`<ȺO]P5[I]Ue.]n=uF5cJORq&&5yTHFROATx3%F0<-|+E〯N%d6瓃*@?'N59XzkuZ͠{2˲Le$lt#LVUng i]ĺPV4m:V=8r;in[Y$#䵑nFPS 4@yv^ J&0K7nJ=>A&YuYTiRIifM$b6QHxabp8<F*!S|wRuc` (f B9/KjV/8,crT7S߽ 7O+ ?6P|oXrB5e{4 UFZ=PӮdRh\_p!#Ui#ĞD$x VH:iW]Kg5k *},#߄DM0c-lK;L=uS` ca*(CœDt@3PJ <}VX0;S~,LLlM{>Z+\(ԚUᇶ+}Otcހ2[IjK"+@8XdV_~|o.o?-#F^ɕ>#}c*⹈5J`7J^ |O*X)mwʸD]/O SoS[o>`J%DE:)gL>abfɂsDpn{6fn_  Bx/UtmԾdrmw&MAb Hj!R12V~@4K}O.@,H1dn*!V|J RCv^I2b|eDA LlGxU#a»%YѲ xĚi Pݙ}q ,r lxtY1x$}[t- 9{\U2  @"r8)RPJo +ԅru{ɞY/qK\߮U_D@Aڗ^'UaziӺX:\um3x k ̾ń0_}JڻDJ@z7 Q9RZ1R(3٧}zf] E]ڧTĂnui*TnxXst hTa@8j ::9 :xCʷmߊxLcjRe\MJvuKŝgIkeoBkr7PJlVn5=nB֮H˺~p9}ąX* mN4TJ|_ bna|2sCWW!Ap1š !ER>ed |&;ܻ^(R7dF/ 연$s/ uq#+{_Lk%ĮX[%d rqVbb)hA!<ŁF\ [^s4٠5:լRa,074#;% uxvV4TF bpS+bםBnX1r[=(5iXhOU;Pp4U~%ccژO~gej3Z(%e{#k7!E5OMA l犵yɳk* Cřf>-J*}:KiIGK׶K+ Ypꜳ*ґ^j_OB&bUs3W y[ZvklKNQ-Ch-*# GYR ՆJƪGƽ7%eü:/wmhJڦ Aj-Z?Hs띄EZrNsǰͱ۵n@APp2cՆ@W2CVPgL3̅Sʑg$[)zQn@'k!*<;kF{6ޑthبUט_s2՞ؘ9Wv4ٟ̹rz-#*+W5E^b08 m;J+D&cw4N-:XΣr ţ=sS.R\r&T{H ֡nϸCW"]>%\د'lEi83Uƨj-w'\R?VT<'IkcKe锗*;$u.U_2ehP!`)3 8+LlGHa v[ĝViuGܡΪgf;o@e@Us%nBcRi,! 2 Rvt׮ `z+ f-d_F&IԬȄ{8*$2Oʢd!T}6pUxyw4tɏ[nEQXOlȢ!SyQ8jjHw ׍'FY|-ͮΆzlօ:ϑVϡF{($E1s3|\!Nts4 lK QX=冁r4׽QԤ*|P(䳫3 # _ÅEVIPAD~tR5;ڧ^PEi۞.) hdb":FK(x9z~Dd)mM[D_+E渉##xaպ \vJf$JݢlOEs`6Z/@?*$u/W4"lv]BO)I@ЉDiTR~L4kԾTXmH]HZw 7_|Eř 6U2ɇd}^T~"pj~w=}zV1d!Z@Y,$(}.󛮐œ;R6k";JK RvʞcR?ڥ" s[xb\UdH:+d<rceWK1pټ# gȖ= Өm2% Q7p{ܘ$&k]PuevZV[LѻJx C`)= )n;7i[B}c;wE9ᖞ@r^A p'.LmP,uLa"Kq V[[6Ku#':I|I2qjBRwDj<;,n C54GWXHuU4"Yϋ"O>_rtZE;#is_/2yL }ib]NZpZ]QÌeq1х CꀘoSEE%3Hc5<qUMn9 F3w# Ȱꕶf}ndoN 䮐U \4eֽpsL=.&ؤF֣2"Y9_eM̶7-7+8>oΆfښ[NB>7' <`BoqYOI>- krI̎A-iAF[DAm >2җ*S^9:VqwԪ/t\WƉA_\PEp`@ M#pP w~I%li{ۧkRgLh}9(ڕkc ANdB{j\,`EW6ēR\UDn $G?%C# M@]bR 1 ^3Wd(X. "21ߵz[$9//6;G.hAߋLl-]@*-G}7~AENؐȓb +bJI~eeHdopq[o>n:b䋇|pY2VL3\> k|ëRvwTY0`W׋얿Vrl *e+m$@59*]E6s37O7u ^\;DQƩkfgr19oէNUgF!x] DE -5#]wqd0rj[AZ,Dbٔ6}}Ů)N@i}Lz&z<5[fa{йlYez?<×7m;6ĉ"|(QF{AM?0;0o/}&)/,J|O{,Ta2wGW[u'c!@p&` #BmH?7OPN\ MeHnM:VƦwЧҍPY8~SL6驾`uVhr#+F/]/ߡGT%43p/oF?( os%{#nG~(V@SzCC"{|0P)Yhו 4܌!D Ыaj:u*TŘ5{Ik_R6F IR7㟰[Yig~ B>!ѣXcz'6xԸi7::]0oha)mѓ* ~5cd+F Ot/v\RO aVISim7͋ 0)^G])ZTR"{Ag,K( 儅Njl,ZCcN}.\Ms0K^'uBLx'U%2vh)(S p~1#9ڬ~|O *I(SҬz=j-0A_]Xi MnP□:e`*B>'@4 1U]% v`=g,cQ.fyqȎeM=,Kbv㩻.m&*igLUB]5˷a.FWF@=@X!>PZQ qyfqhK^»bl/HN˕r}}P,5ύI$ EiåEhE\[카)tp^~\cW P.HJcE6X'Kw3)hɚK +%]S%@!Kؔ{*VFەeb@VT~27v+3U蛧ڿ&|E;/.VSǸ?K5ѓh&w}ּMɺ3.kw W E.H. P[qqHtu0su?6R'b09c3/dZ&H 3SKOᇾs}HR&3sL mS =Z㳋 g⩜oV<\/<[W1 ŁJlq" 030f ؊{24@n0-YxLvbSeZzԤD -IwZVp~w0gc ;`T @_OՕC"[Gc_p+xDhI=vĚQ8#AB8uln4 fK);씖HTdMk3y w0YQzO+DNfb ?'4^'z_Ck.hAF^ *^]] ,>"0)RZ 8@H ^}z;.xuҽ'(T,?j=8Bn Ɛ0d 3]`:(yu%??& in50@F$cj59bּٓQf(ΟPG0]p~ g_b:G ]xHVG۾2ؘ׊Aפs`TU!Y( C;i˃{OtOt*_u|2Wʴi4~4m:˭V栿 HjjC31NF^#a0hH|wߓH&{Ε$Vͨkݢ# "1_w S$x1DŽo3]rxwlԘ2#N,2~Kbݽ8\Brojr3exS'/}74!*"Ns:U?j@,/*JJO%Ԇ{Tk=H╓&I^ zV '4æf?FM9l.$ iË!ZR)Xt$岃CTӳa Hu Ƿ[JDa-hDnr~ǽٍ\ZnSã-BwZ9hoo3.lc۞]֐6Xe4 k|[ ܿt>v#"9c =/GϮR|d%0gxt%|oӤ1%Y2'9_%bZa"p,Sh%H_ٕTiHj>u[1>1BZ^BL%}1ükԉB{v3pӲh&da.ibf.\vڌsJCO,:XQS>II߂IZg <&01ooB f;udH=_(%1>nL4;}ZҔC6: sبe'nRRՇwğU/1GQ}[i lʌ ^ExF|+*^ux gP]w~7 膭zcLEurJ=v#<~H{|л$( ћ\Oww/|+ J+ dR5V6n|km2vp_,G~8.v=MkoXf m SJڻ휶S΢1koWo 6b\\AUxJD" PҽN>DjM<0y&<˓`Ѻ#;PKIʵx0 Wko\K^N[`pw8D)&+z=ysF3c0B==o xxOV ҁV3>ʈ崧 mj2HL/t.ަBcσe~%P {2lx54рP1~HG )axqc{Wc,cW ޮ|oS,a\ӄ&mC]G2[i9kۈCF'|>t]>|sp8pJkKgDʌ0` ] 0&zhQ /E&;[5۷Jh cw5憖 1JƎvYslb\^[G7^8f3cWG,D\QEwc*9S9LPo'D o,Vm/ 6texZ)o6xU]RţGxv@w8sR KK!-q6eטuedB`Y鏾l "bPm/uϰ" Dw{D +qkRS~ޟaB =쾧P;r7mӯr@%Œw[4RJR1; Z.9o#e= '=kQyq JS^KgZnN8磑NW! Tc_C(Э@ER=W T y(U]{I"+ Hyk=S~p6+stL| [”GGuf=c& PCw/AwE6%Esg m"amdLm̘FÜIڶ8Je*NUOlϐg /3hÈp'+~ɶS7*+YheKOY9_5&:+Զ-"AçixXmhb|҈{HrLTfOvAiloE ԇ];-3 WRf?ͩ.chg":`&\Ȋܻ?m6ь6-ϧO`,Ⱥ>o '3S xpd^F:M h7{TW!IC #xu:YܒjD>7/^:P'TKYOw"`V.:?|kE'Hoft{Đڦ9=B/!X|9꯻}xjt"@r?O}PH~0gKJP%L`yzc?*a naF;PsS+e%йujy{2%6U09l[KT>_@gGUA{R*rR&kL^0`3J[ll?=-f,I4VzL` pR:)[ GH~$3w8e{U:ӓ Œ:bu\F~ͪ5V] f3"fBߜ5kɡ5FDYJRMEF ), Di['Gt`<àl5J9UDOU!f =}m!Ңm3ߎdjV4;\<:ڬӳNg^56'tCË<\|K˾D '6h@ۊ(r =u1 ߟHV" /qڂe({A_Jx9-su1{+Xg>6xiQhј~Ǻjq"j&_(ꋽ=2E")FH%u'6OWAO?brON4s SPJ])?6 FBs:&(Xwx;ɒi2уbno!4@ݟA /1"z9Řdm#_6Z8H^o)Sb(Gt#RF:Nd*L[3L4rߢo/ a\0ss#IҩLpQ՘$(Om'H|6ۆ3"sH@̷TJVyAjbp ?-'[F++$ᦳZT2 T֔x(hnpYY'N"{wpAZ\ꛙr0ZC-塚N'Wu! :i?jhDph*XX TA?kJUU5ϓ&qʹ_H.sjLXM^..}YԴ&e{`;qNjkX@26ږ*7M Wc?ZH"mcXCw9.`u_Qb۠kǻŴ=/*N! Zi@ u &<2EJ bGZ{K9".qc7"$pc/5q]ɷ볛 <"aN;T!Ó~swyTʮ`WuVHo z-j6#f}]];0ި ڟW!8@WCVBfXSCиԔHձ@&x(ߙV^I`xw8T|X>xg~󊺅Y]a~((V 9|kDؚ15G$M O5$Wb$mͭt2'u(# pz˫ ĸCpn=B_iWWY@S3l7Ͽ2w4|塈o$ujzFu'sIM˩ڮ…Tׂ~|D-, vJ%5s APB!(|>u2 a eF2Un? RO]6ךQ4c|⭢-^b0gH- &^݂^{;oPr |Ok%<fr cE|~LNpq"&H?,; BtĊ`jw&+jMld*Y'-)HvAGi%ܫcez&(ľ_ Μ|Or;_>aopgNͧGS <9`=1}Pojfz 8-3aO R|"3ag-RX9V@ч~{  V5dk#U &_/lr;5ȬK;2N zRsήQV/8Fdtu䈛 HJ>b+D['HƈSP!":\oL>jIQӖZ B+UZoArIQ|qVy^zü1«3Opg#ڐ!~Z«MYGkF~8@w.XFȼ mFv$]c₟+㛅P&Mc$A+y"ljXua'yzY2QqdrkdڵcSQ}=١-0d> .BBZ/uP=ǗXX+!瞎{l&{ VH&_JYCDAcp@LX6 AC6@_z'4l>bwd]הT֢eFvhV)0,t ,zj s|~G1~ffvppϏNw< )2`+[HBM @(xqN^2 v }.G"%րSŨ.v/GOU{Foc!aNBV~c"i(J68lʳX閕b˴3F7uX7ZTDAdWyva5Nk#{49Jܵ۲ϐZ ~̓XS>#LZYTu[>2?S>$) .ZESt+LPxnRAWez@eMu>@@# }?pKiLÐ^ć0OY})>Id$T<бi6 i5řs{8#qw"ֺB/8@ W~{5=Ik ß{͔(1 7K<0=b:]ꛯֻSH2Ndp}ƫ* fձW"R"kcb3T|OV\L{9n;)aB>n?8,FڳA?;b[o.pW hIŠiY/U2$\9c:ߕp4{xLaxJ${Rƫo!685C fGW=,!x^[d; gO^ w?6U:|ҭ7r\'*T~$2L}+b -5EϚ$*bz"Ǿ+iS>TB1*?zjoX~Nk*RoLwιW± ,lb,/ Px{ªu@3ּQ+D:x%}( nhO1LO"(t OP ܝ JC/'`ia.~yWf)a(Ҿ<CM I`e׋O=[D- aQиBv1GR'vo}at-GP-4b ćZ+'ȍ&@)#G>8 J\WR:_WIIވR.P 8z:!L͂ `e )KvG6(6=qp=] @QȄc:-ƞ Z%,Lv-_PA5jS-%0trkl1 VT^vkpٱA]r<;Ean35K6&˶?o !]!F}ѹִ9a.@gJ.3l@RUD^^큏Uw*Κ hm\ MEj[Gm;2,"7D#mz +w'@dݫreɰ(rXzϖAvaʚ4~2[@0z=z2ذWh9:2ڧeRj}@L,\ܑϊ]9x8r/;i1~v1lQmiWSv_:&_VRV?jom(&<_?¶q._燾 B76iT8EV\=g ?w+˝]meuKz%/ oYO}xj/)V?L\+j}g=ɣ,Q?[QAS-XU>ܡCk':Һ=uRFj:۩u.]_)RH?r8\:Mrinl `Xd𒄸Ҧ=$ ^w" oΛXz\E^X):0D F, nwn#F:qo*ыŇg ~t Rdfk6!?loo`KҺMZ?9 ( I!uxdW$`H$Пaݞj<MIgD)pJX'\ G&~Na肩ZV=U-yW*2P٘^Z*nVA[A)_""ё2!2{wn1HXAU,ܳ`ChuH'ngM@DnApunՙ:`~c]\52U; %rut7x `БGIAh=jѦSI9;NnE~h <PyL5O-ΐ#bo|IcwK"OW4*`WOܭt\P ^җ%6ThKB= o4d۱b>Hm~ĢQNdQRI#sՍe@3vs{Ey3 :\r-Mud4lY)=RbXJ #bθ=N^%N")PxIG JlʥBk `n㏔ƁaNk}DSHIʵ p)m|Bhjr'? wAB$j~N34qyH=K/Ot54',|_Hl7+9,4ay! =|Ȕp"4x; G|[Jȍm]y8?|lH6(x!v!ƯΡ {r @F>)vMTfSmTx Ɋ~XiH8\Se⏖X+ >͈? J\r rGj%=] "EZE/wx-'4w71b/AFSICem nA&`gלixkU>Bm'X= '`A+|64,R0ȯEI2D,B8 p\/3j7ic SRj~eW(r:%OKJQ l-9BV}3?gרD{tqJčzYT"=ErjDesH{R0 {oR߄zxd%;K. X㊂$=O),K@п&ݔO Ϩ-rыaY9^BpB\EPJ+#-sC&r+\-''S_1mO61"^j1p4%/#7)8AN nvsΎpĬ23>r+$$Tc0vςP\bwRqkcFGu5X=.<6gq"Ɖ;(82 _ p^g5exG  c rp񍵾I51k4żI:'c-'b)'cYN?.FzÑ'c((FN ;V0W'hkB BÊ$fk=syLK,RԹCim%qUpǨG+yk"f "Pޙ~Q!; L͐ɓ@Dh$8*J2v;. 7ج=.<ApC3Ɣ3 uǻa}~Ɖ6=?R?XvC΍QTE'xH~qfg xL*E00fXmgک8WXDf7 4%-PކAϛ"y\%`a;'lahcf-p#C!ԡ[rϗL"Z~^:p)fp:RG֞"E6!zeݒԯJ)slxr(wz+s]qEi9\9?NE aUŘ'0ƒV-rSJ.IM vNY s(&sGB?Dixx wz|=k'A'0OԃA+b ǵW95HZ'IF!ںm@U2^@ kfC 07XRH'^ly;;^C֌qLiqG jƑOMn,sĦ|]掕v5 XFA*#n006QYgnb Rlk}xcO~Ϻ1Vp,9ﺧFLi\?ԗ8$z;b>V*_ty`^T_q-Þl2ptԥM%;@ .k5ځL ^NLba6_=$J|Ge B =*_oOxfrN$76n>b}.bf hn0(.X ӑۀL>6tAt1?%C%>yז2TMbpB/Hah6̖7BzRި.._ɼ)W WO8e 惈 GcEFA\f(2Oq,P}Ӣ|GS%ݮae ڰ^<Cd-͚؁G I5hLơjJ"[8ÇkvĤFr" @Q4>Ae uzPЂҨ*]b\Fm0`qD&OE{Ӷ?I؅ ULmCgB<(PsioKY`De m4~t-oo/fZŚ3dGCrP9Z%X8QE12A"#h $.?n^B] -NTi9#V7\D3֗Se DggOh/$ns #;bH3z'ݍZ+6=+tǿ# Fk$bp =.ѥ!j-emBR<'U h+*έgW_`U oդmL.jMUv?dp>N8吡e[6gx₟)WH+\Rmtv.27MO |qBq硇+jYbZMƫ~'"MLZ. 9, >po_zRIvg"KܖrnS)vRtMTUZ#1bIKoJfaj|3I8ˆȒT?=vv_uþ'c-:p;RFYlFc7 3 ]V_/oSGI'hxVRvkEGephE^/C:dDK6|.}Wgrsf+Uк;U~sCy˵MgJsm?M{KHn&>wm[a;C鄆Q_/IsO@ݍ=axkTzY1цbuqn<> pf!c9DVAuuL[9<ݢ/5Nr?eoP/Q 8l W\MH+Bvn4)"4wv~SoZ-N Dw`%Η^ZN*بWV&ʇ`4K^3W p..-CQ]biƪ 9yqx-c+ԗ .#?릖qz)1;KQ8x?o.F,wD;#=`_*p*袕K,33fj!;\*Df4z~ͨ"> 7,:|^ѥ+zLdVZĨH%u8邐{CQ7<Ȅ,P | Bِ?:61'\Ù/b_@(3nPochO#؃!t_m7ͩZ2T$`GDWEan5C1$!ɋA2EQ@Ę\g1\a /Bk)],./î2E}yw A8i ԇm*sv;Q76O:fMߨW rU XQbR(%!:+W4 tm+dZP%ɇxA@.M%'=palyӲhRִmIF4+;a/Yxý3H)I(& e2/N:du^*!X@GO> mJ$!j!>A %1[D) !1w<%a' q7P@2DkmgS{BXگ%m '8%s<էXr1zquWhX#}v &fuJ\ð`]uaDKwUJ-?C3TNr1\! .!,I<ݕq^7ܰFJp(K>GmbVsv )}5^]Ec}Ej ;H.gtceƄu XoFtʶOp嗊 +} mH(EIv?*U^B”!$6B>@R"@i\)fDZPp.nUf >W4NŽ<0)X\r#taP}"#׸ve>w.Jmy:Z]z* ..om5/ڞk3G닡ZK.<$]W ݎ4[\jӢv8nu4-oN)o通[fg 2עb%2sTLn"Ѫ6%KTh;I|}⢿ 0omKDDU_㬾J}~Ђ%I]mPwd㎐6p 8b!bqP\+`ՓOr_f鳅O-d k\Q֯(VB/kFY9ƚraqi8=]ܳ즆7U:I(0:*`idA?L-<}S{f['O:'}` ONl`k+f'z1VMۖ;b wV lhw,~?PfV->4U_ 7EA:2zp&2`L ia#VƼ y'c}Z?^vN|(E)z&ZA۹lNl}|J7E`SwbfH #Dawa-rX<,ׯ_Yy8k(cJٱx!82%Ru&:W#@UEp5#̥Qk+=6ʗ#$uhܴX9*tIfu_ BU&L+~R)yui̝uL7CeF)UWZ<["ڴuӵnjK\'a1`t __̗p/Aw3v]b-L:J,♬&oCRt`]b&t7G-$3떩@5 bXԁ/pnJV}u](zti}Ruo?nc{LŧVgEީi񩲈`՚+@SQX }:bV"A:\ԑ8b_YbTSE30՜sF9V?^|,4ɣ,x0F'2i,Zf$VfT_ʼ4BkI",M\GGu~]$~>FqcG Bq  in8{卩8M2ΎyS79=vP }P2\;R9}lEgkBI)sL8K V5Obf;UPZcvCcH6ine62z6&:~|`̛BZ fb}&5wӋm7x)'oS@œi/kR 1nER{h3=ugy/R4p:D1ǧdFwc*IOKre8<.[Đ _ 6F֛ €~;Jel+FS Fu VLkUAtbdfn"T!f2P׭$u#<jZpL{`Uh/VgM#`1vxmΗS[ckpeካj1h>'PJ4N٧,t*'&c+a7_S tA%lkӴnHٵ1VEwyy3Vև4eEx(MĂ8y_ ."O\y'aZBAw=@P8`rNY`s%T 4see-{@>Ajb}B[Bq<Ɩ#fV0:~BHDzً#/1Cy+.? }_U8^qGI-7Mp=gX}M;x΍yuFf#Tz4j1<wJ?0$T.y ! A3O+xKvc w-‰vy1b-21Ez&x0A~WvuiT օ>R9Iq6D$^f%SŒ60ɟF Zf %rx!ڔviU*r&#x\xL{L#k_mT^Ul,ЎKlsSp:ghLr@葙7>ǭ'j:d rePFⰎa@ M$b> )YT+JN:|0u|+`]b(H$VK?ַ;TFҸ#ff*ds&"Bu= =߁({ ";#YLzG{fGb E?ƋVhso\(3QÇX~̆n7}^hW5,*"GsM\pEQ.|jg3d^+0¨s)4tqSmPB&"2e}vkmu*l ;: CGO~>Π+U,k`3. 1Ì]E'ڋs+h#l5wtt= 1KtD9T:0&MxGx#K:&-{aӴsU[$C=lWRKaQ [ڇaĊ{ o& vѭ&nTÄfRz&5XMG2N;(&z.w9y`s"G.A|KKR<N"獗\Y[6.syY- *\}Iݝ&UQ7D-OE"Hlr*gƒC-47&ߓhŊ uj/VD-YApգ/0%djkipΈz V¹S^+ ,8P;ORR&s l4-{,l2[OMIW{;y+|kir̀:eDF\:*~{2o^ĩ*"k.yvI rP9m 4 Sn:+ q+VLOaa,=W 1c0q(zEӾߺS(=tT+}Lrȩ&qN*`&?a2e :;:Y9c70Li'ތ& S0=zƎjD>uw&(~ONBP>HչŹbo.*5ClgDzk+VMYLi6!YL03!OIǖ ԺOt$ȣ: ׳V%sR=)zl_L !]V=1ּ]ʷlɗ}8׬~FI} ~l/UԄKЦ@kT@ߜG/y@\=҂:e])tՔ4iًqRU^0A\m%PPUG)Y71HQ3vzEMkwM|R@bJ5)xZ҄p?`M1g'qeSO^L|GcKͣDÞ\%P!A;8ǟhJQ@XzJ3ZKTYnz’AETOw}[mq2<g޻kKC/N=VBڕ8Vlj3vЩXzx/aj} Z?aEDaI/n&c!]x] 7UZ4boƈ7<} A~sn ŭҍm0|Cx-*(A#:|U퇸̗މ Ͷ{[ 0g ( $PAq#͸o%sqY2%U1p[}jd b4Gs,~9丩Atɪ8X0׎gYUJZpbZsyw恌B4sXA8}Uկ{Ě(IZDƒ=ϡɰ4>!\~4{+5Dtzg-8rzs0)B푊@Ahb$r坻PZ|+\s1Q:*+b^$=Eٵ? 779lE_0 6;P8o`M( ҥac=h9| .U' #옌?/O%-crvV N,$|_Km&puE.:Br3p 8@Hww8L5a\%jE!婩p up1x"#OAK icޚ~Ԭ%kUE-i z5t^tO/u}sP̠+֗18crKwF;Ltԅ ?ux-am3)~)x֠a _݊'-=i֣s3l)&khO[=)FDi%F3зnyf4"F {"O4Had| I;T Q ^H C@Ou)ApMBN0Cpd]q~F3pa b(k{R$$$.rJ1":fQ'F= b 1ؗ+iãL)(n%IA\tw7gnk(̆(Z繸BO0Lj{:<Z5ؿ099X1F H8yFVhh bu%`8m" EwbV2ha=;@Wz09W9{XS?"O@56;H,;'Lk($ye|bzcP{z-²g /E8kv.s!>tJ{2YJ m3>Rd~ \b)KwЬSh\'7-mCr.af9ב֫rp+50Z}{TCo± OHD6ɋ*HXoSk:CX(8JoZ)M1;pASE, @kۻX݋)@5RB lS!urw5+L?ሓepI!2A-ѓn}I!5k&wHsTv& "֠rȬ9ï&A905Cjr/yI&bZY*;Я7>2lԒT{W&-rx)>\*BwΖ&. (]`*1/z~|C;vȥQt<jWT9<5$&}feT- t + ɗ-B'AQί$Bv3 vQO ku͂3t/l~( %:y=QpմtV L;%152q|uR(dk|z&G[̼cTnKVء;gf!zr4!3*+3Fͩػ`,[!yȻv|I\bݤMA^hp$ UZYhVt'msEz5 Õ([l)3C?]+Zl}~IBicݍ*g AjXLI{FE[틓epW_Ź!TRʳgظfeZ, D7 o^Y#rb@NTGpUuQ d71 B:{y u {*j 04dKS9UVyB.֏ct 92{MWD/wUkw@VsE53S> ɔǡ0) MɜCh~'QJirCx^D8]mZTK~uzz;FiSՉ6WHOD@+p,k+Y~dkdkQlk=Ke8zi͛ELjF3k8)}ܫz ҐRuىPeq^Kj*}xy*8>~z! bN>=kD'EJSҩ6jODEwB+Sn{ )9)}{3&1j'nHere]U؈?fi+7u#(+2ohŋgA AI48hReۛK 6#uF*^ p e)3ؗU2CPUB<,WD#[5t W-%`_mǡ\ΪŊQ *=Y[.ȼV雐- z2@y%҄s{;^_|mN!1k];d~5ַ@׿6޸pDNj0)]zu"hbnP=U -A̴-ƳkljI7NFoQFLU~SG)QZS媴=Rk}F MZUk+@n4f<PSzx]95bT +>jX`W/0eHV&ky(#4w 7rM6[KU vΏ3 SC] Z=_̆_WMMh~`O19BfT7C"k)|y&*ײ֖lܺ 7#0y-]0FU:ǰY/u-䑈r}*`0h,y cܾ屾mWwFE#/sǽuܭ7NfOMQ\5C5pu34-WTo_[t| %I-H HjKQIh:|MZG. zլbl [iVOӗ¡ЅPrK[ eBmO0ͣa܍oR ; v p#0$ #aKfgk]A;cVN[(9E*N֭+ܥV4qn-N>>J&E-S+>|TWz+`"$m}O6=p&Snt=ո9#OYKFA:U*?րAŖ,u#b@!d+^\3)lk#&3)АEOLi% *} l4QFb;<9T: 'qFNnmYbb\ڐ~U!fl0 Tw`ټqt8{å[TM?ѫA1|ٔtxwsR;ּ@\SZsiyKVokp$y?kWOoxJBlB$|n3YKnaR{_cCN՗%,|l=+;M[uc!YE3?@ $2wV:R!|(}ɜ d:Ƌ}mQ4:C^J]07e L&W6+9 jo[1+O߽wUIbaSC:{/( 0Zuut_:ϠM7[Lq!h 7s:V%g)j^6%yT J%GkC? %(LsCƈF9WţVqL}' F1~n_r?,$\ZŊR≏E7OKzקGm?~mAW=:~{5>:8>_qr$ã1G7}_m &GƔ+Nɒ h)1zQ<{v l4bpVJK̥0Y RJ/!g|b{pxy˵XbE\Fplr,x (O]WF{G idQ230HnQ-ŌqU-]=l,2e Fn Yz,`J1ѨlҗC8fk˛rZR! ,8kCiiҦlz˻HiSD|ܠxz,aԱ$7dM>X@ndOsr~hdWl3?_s3|ՃMФ_Kx?ܠYܤi} ԊHEy>/$ Lqzm{as$xu]륓SH½P9- n& ={(tT7N }qYU3uUS-|s "GRil {W(Ɠ _Gs͌˳IR WlXUUwf}'{#- ފNbBhOTb:IC{HCU~vt(h-ߍMMn ]o >~UlfW~qQ0707010000000d000081a400000000000000000000000165ca0270000051c8000000000000000000000000000000000000002500000000./usr/share/man/uk/man5/sssd-ad.5.gz{sǕ'?>Ez $EI{uB"-1" C(t5ᮆ$nH РWoYYoĺ Wh|瑙' $ m& #+'wKQgwXim8Ǘ; XFo[SwNo[xx]?R/lEd1Ztұx~Fx>୤<|F~KdZ#IFx)]huSZYSܩf qG`3#gFϼy'n. ?Dw{ÛjHu5nu'[&O]zBsQOSSoG/ϿtNySq/3?gdLDKv'7kQY;'G#]OOՒzQa/_:?O/z{7<^کj9;sx>TG"zJtx6-zg \aMlpׇpz밫MYx^A=Y&}1CPS|ST+ 6gDICMzߩܰ/}sM=/ >9T}F(l55 f,)G>dV. m<2}QïIJ&W&/2tIPK-sT4p>5:=pjb28՜&;z1^Z7ף_č4jXY xHmkΡW_Y'5p)'6mrכ1K.]jvюj',08+UxSyHQËW[*/SdFLC܄4\62֛' 2{'j%;Җm5bdkq5ߐXA_M\ǝ TK [pO|VpUAehZPƟ7<=F#o۪ׄy<gO~^!n7T2RZ5.$3svaF:~v)|W=Mž< ?ܚ* Wl:F-z.s,bw\Kǯ},S=N><z*d3:?1:3U6u@ZjeXm}|ORџ4upxq#L]N;FĊ.q9 o]Dڞ~ц-U|*(PN>°zt47=R[=^lc9yO읹=CHe'<7{o3˿:tm:tQ>DXtNSD*d\o:®"Uڳ+tHafyѦ\e ȡNuubJx_wƳu`X## رK^z \D3ݷe}p" ☓H׸ n>tuM`BMs X?Jhr00cGȸ?W}2O^ޔ#̾UC%n4P tfB8N~R^VQ0+k3b\oFjsClO4&/0-c>j'늼a#g:@Ё8W ΃@Wj#Ӝ`CS|E?^.:~ڏyuLUW àE[+!R\cEwԗ{y.'7.^VJzs ͂Jt4'7 xTm-.iNR"vV:/EaшV;plupd5Jz \c&J!j i!ڭEt95&>mV=郸ހ<>Gx<;߹zrI. Dsx^ͶŝN>IRO5`܁Qa٤т'YV5nj{iù %cuEǴqx#ڜ}QVseݹmF2c^6q#K>ԍm_tCEޢ  F^ƌ!Lܗ\)M6VgKJP~H}|4@[C"ډ/%pU] YAKFXD|)Y3f7j 6uǴؽ<ѿη ޥзJS{|  z=~ ZA/VCJS_ni 5wx#"x%=k|RZ"/߲w6OqBxGv͖(Pln znɚE%"l_;$gwDZzJ;Xtc/#B)npFV&BdoɺmBRT0z>ىhaK[A36Zg[Q^֡g*rf^ύ0 W8L- 9N7uMC$j4#hCk;@5gDZjd J:9]=wG})Ɲ<?,+%W$ N>EMw5qWL?aH7!Y[`Lg:h }Jsa &Ki`/cC3"(JkNϒ}1Ljp0ɳXEvMi x5Ⱥ%}1v&HGֶBA7P<+ϣc촚絗GߧO=wAyO1wƌd&ݑ~&4;u#x[1+6-h٢ .Z(vbtAK(֘@.#dmlNep_Qd.E@oWJb4r-+g!;$$ˑ 2kAΥHKdQɅjZd0NܦUOL-wkE>Vy]'>=6.&IqmL+ۭ奴Rš`bgXX)53:9p2w^NM5үWΖsMU4y)C*&i&zťYfwRLqa"`ǒH_ Xs,92d- ZWǏ9ɞjYfLϡ CfOց38z+!d9ٸwFk~%'΢PE|r[fҗ3M)ӎBŜ_.წZ2r\]:a6tSV1*nXj:(N%뛝SpX๖/1_=!~rz"&Eͦ>- 'g8ej{tkX#G/jvڭ9ѯ#L X.Y&3{zQy1.Ax T~D4 v-7}7!fߜe-"@@| Jr=@ 0YI0`LhmOd 6/;::Ðu\צ%8k$+&Wfn.g܉p~ w&T˜)i1^rV9=q_7a~IaZzmt}-&'8^Y(FM}N^8wLzb)鮐=9=|zz3ꟗ_m8b{(~g(M`'^{P)UYOd+g#:Gxs@CLzBL5lq%uFPE*EֹF8L >K%iP;&V+RԌlvaNtvZϨ4s"Q8r$񲇸n v.{d21zKY8V\9wjP=șG.z>酟eGtJNANt)>=p>9uߟHX?դdHЮhOCpZTʐL\|3\r? zy_Zj\StըW=E<e9qo^2X4WAD]&\OcߤZnS >! .saJ"_vs)䗴;ZѲ@V9@cOE.kJk6<n5S?gfiΫ: Ó#gň(;,UH\x}NG\Sd(HyF%sS\]7*^%>> V?ST5g0t #fF 2?$&[ci$wXmk`a]{;\ UX-XqD5]]J;dP߼">_Ҡ&:D=9p΍B<(C]csC+I/nM(2obr}@4U>PhcOԯBi&ϵ.h9CD͊;y55Mf6wr CNhSYl=%)?vPe'RuXz`:%Us(:Out$v!MgI4ܬBfJ|Q3{9Nj9 b˜^{WR㵱g`L'M^8!47LmÜj#O:'cC'EdV9F#8d` 97+ ==`OCM]5ly+XGW0@7`#]ӝlRFx=E:/#~  220ꝙZҼV6\P! AwbD8A W;9Pj/'Oȝ^*P5^i7ϊ%{=h^gp/8>*7CތgFf2IXt.xEd*ҧrȨ;p`\"鹪_*Tbrޅ4Z]C"̍7綸`le8U)!.u be/D^e=[j{7Q]7֙؇I_%}ŵV <ؤ?Ҟ AY-fS hhQQNMčl루 74J\ES!ևFK8 rP^5neR8Ⱥ,4iv򇴖rE_};@Q}RTQ=;g\"\$Vʍ3Li뙖ԉjlBV2A#l35lXר2,@ZݮIW7s G\"b+b!kr  U!JD,oxt3d bP vEEMFNs4B [4雲M Qsyn?c<%Tpsy# -"-[К1/#Z))y{%蛝T|+[;Gr%BĶζ=7~v[.[͉By%IoXAQXp51r`ݳrB˫t _. `.j^[^*t=r*"]Fv&$rI(# q -fJ92g y캍032 o'UqVWw)ҙ:crq .NwOOMH _3mHY512Qoԧ 枛m i}%X13-\OUIQԛDgd:luʼUKbfX^MCv5@*xoڐzswzjø\X[j$pVJ;qsv:=DZGS;_[7R[ =a)N[ .N5>߯- GNdNbԴv.7k?s,: :lUOyaaib[gzq t >?,ޘv>&7-cmN*dž3 $+ޜcw_`dA~MyOr/3~u@.7xVlDZ'VzDi&e+.veڒ5y r6H'#DѾёbg HDQ2wC¶ < 6w1 VO,uW{=AvH!ťehhaZ>d;d 9YZef[::KFVbڂ1 `7?f/EVlܩ.1lH^~a_}q׌{e7jQcXr'?2Y'/:AnT%T8Q0l ٞ)G0 ͂j[F܂g6 -[" v-Vt\H$7\2}u(%~M:kO=a 6g-/l 1 ?:_./%aglq;Ql{h+ETǎ`nrP"\a9Wu2͜hF宨 %G?Bn9_\VG|'bIچxNl LPF MSsߢ~:=l<#h,[_Z X r!,\ ¸G/‘m~3=|$NȨZIkˊZTǒ2#T/ D?jYKFg^н"j^H1^U82M8.liy.)/g\{8܀1Hk̲Bh^gȭæ<]l-J6-g@IޕwʊD詖nj gX"߸9+[IڰRyDڑ=**(p|9Kcmm|CH$RV 2q W"[MU;]1ty]өԨd(;gs|7fZKHE*W`Ӗ7ovzhJxL,=6 IE7q,iwG,oQ Ő D$M(9嶌h;1B%ϪyS-bSm,'A-P1~V0=,f۹m5]vpo:jh{ثF3/GXB{pO$KNIZ Bs/Pق6$ZW8֗Uذ{_wQ6BٙynhMHFL cOlS7 |]7Y6Bg斪~XǢk9 -/hI+Q/L/e)J%=*sftkqe|Fk6nDoƝbg_9I*X4݉OF}hĉ:gL }l g ;$E]~rg|P 06fuQ㓗FޚzQOɫ/u?}W:mpHi:g.uoX ܴ`uNlftApz3Amzs+ +=*?P7cϔ}CI TnGgrg; I*50gv:^-N#*Lf1/w|WPV H8jM#PS%֥p7ܔ̰:7]:Y%z"##wublu9ظr:mѡ:=ϻNm</!\\R4#".{&^$[ vp-u.ˀV+5D`;e-.iU.eEvOɈ{_U}.uH}?~Mg߿Q޿«D;}W5}E4{wm֟ԗg޸͟ $vq;Q Z9]B(Rҹc,of7*#+ v%rͨ!yh|y|Vؒ]5?ڏc^K>ioXSb&&&['iȢF?L}M@3i1J>-zp,?$٤JNgI_*#":ti4x1&$5rM6ᎃxk^g=GjѶ&i`'D$A_b0cAVi6J O 1丢JfQ#Q)uB}".A0o =G~Ֆ.RZ~ 1jUC&tn) `*@qFr A4So4Q:y\ʆ2h W[WHBafU,?I׮]k֚)Uj_W ȍ&O =Z]jv.y̐oɼGxuz]C_j%4 wy2-7қ6qVg~ȖMԠ-̄H`9=FtzMֺ6QR=ǤO &&JiCLx^aUUE.ouvBA9Fo_r CW |@DxB]mΪ>ЧU%FNu9/Vs 9NQ$F"ng϶ni4M$mځIS,hasjW*(1=ξ2:׶Mޟ`J0#".q?r`@-f?¢v|LDJ2߇RpǶ禦w(Rh]m#j}I?lKXئmޔt"}Zv HWXQx}L:\;IA\a:}k;Q]R0ލ,Z#MlΑ ^9gM&mLTm!PԔS-31RSӒ|JKz btmE;cP2`$ 2 3;s QR6܅dyQ^H5vf:O"&Ƣ:^޵Wj#W&P],PLj LyBB5Q0I_B򝅸Uo+\Xo\Xb k$E qs6ZY)/VDqZA'n IJT@T&3qW<J{?y7Ur|ي3eu@`6n)!$3m)=dR ^)װn97&jj7{m= ]|VoG) `ϭ: Ziocv ZVӵ^lUpM0ܿCEjS`5'> kvNVFdօ]X/E1=&Tb®_B[2\u?%? 9>d.)RYD+#7Y $:mpF9y2V [K&@ZuG"wX2ӳ/zK7b2 5 l彬ȮTa7~R J`+3XSRk4jסVq4J!gеF+!O^1#ˏ6^JWJ x"09پ8<8ljRl]%3 ŤVȐV_G"OH㜊KڅeBIЭFCC c޵=>Ox3WlQ!3 3#N@HkT;e8tO[G<\w/ɇA[Պ(@{G;' a/ ep6լ/FR|~hz8zWjެ֗FtYZп}ѻ(l K `FBd|ߐO]a]i[,^m6ջ8A%df3lQG6O hҼŘ7FS~) 6wȟ:&}r>Ps z4?(ViA c G>N䡣##R[%, >E iq`;HS;J: Ģb YRe1@[x{u "V"YE5f9%K&q':T^I?% _cB׋oYR&dX}%+3e'Ïqn OLJ6_šmAEbv <ƝC}`L(C; qGҲA22%Nbmg<.%lZ@Y F]s*7daDuѯi^h-|׃.to{ 5./3h'qcvYKKs8m,&@d)ɜZF&s9:U ' Z--9' R\NhP2U';7 m\ѵt- ȩ(JyX1U_o" zgg dChjbiNFh7u#a(s%q& Z4w?"R=8*R׎\oUz(CvLpW;( Bn3xNQԿK5.ny2%6i X2W}1v|E=jD#&htM$IJ!b6n)J9}uaQAA9]I!-Wɗ'EdFLDKʘUy|-Ӹո&7r<9.&0^0@7Wsh8K1`atVR]} dT\n&&1Z+E 8CɰKޝb $tvs_&HA;W_ZIٓ E8l0bA(b '3N%ZonAy>u(gO;fP7)lǯEb|%<*tJnM~p.7wi} ^0w_M U|9+aɞ Kv]Ӓ-_ߢZ kW|xÑyvn s 4]Y(^@q9j $>u F"O8[&CSQVxυf *PԎ-@(=F.L(; =hfzxPh_d15ii=y {-p@eZgD62Ȧ[lA]p)Sirkݰ8Jĩ16V?'^`s:32>i_m}zc8=>K,,`yFioVqʑ|.p~S5{!Ն+Ir^kG֗*x$&>[<5X-v3LF%e+j4?nς=!>E{]m]ƀ[tr攅dQ3bu$[o/M$`]3 @A;hDe|8c;^s߈am](Hd=Y:NdYgPPM?2?R0S0M, xXbI, :|FFM0p\Y YD!%'䭫hMYi+'%/&*jd+=lEW)#%xADBf\-a5Ҝ}gXM3W s!QT$m5>Hڜ :ө/&1`B6P1B{Vtr@gA:}QF+ocm ENeӕ%!GGGmRf7խ}4 _ֺr_=> U96OeMڃ*A.](>9_wLgae}޶5u˒J w_ej0:ts*SjAu~Eb4{eJGدHJ=]3T%Sɘ3Ovu,ǫjtg9corf')Ns\/k ~depV=kQkR!7OôT]zoFg^}M>ā&!) U3h΢sOA2oc˖J-_7lmS.^Ba( g3W8`[1 TTrp[5O8wgE3qwN@uE{O+ٽ[.//&mlMo6m;70j'8w1ѩZR-B7C_K2 퇶Lam'B0o 0[. tz-ps.9_93/MJ ',|s&T "0QV V*Djc)wgV9/A-9LyD =۷&AI3|zM. FΕ'mŅCG྇B#:2Q-^#2h*#йV~K˩SH?蹽a1nZ;d+Sθ Yg{| O8>I*ZK,';𙡥.7'tc`G~ĜJ~Iܵ!s&-wy- ]XL!y<Y7+VtLI_⇨9T3fJY1>U2s#o:,O.Mvd8SҌXk /z RuWٰ+xX1_,4H=-B_V>2.6s~TC,:VaƭK& .NoG΀b/f o3PGGde A{fP!y`s.DW9neUF:PC7Ae|Vf{ʎ]ttftf֏IѲ~1 ]cET<nؠϑ)"݀)p)2GJNa7Gtgc}ݙoz 4#*k7ߐ0.vbK[6,320 Vg53]|̥˪N5\ƭ=*!,ڕ(tSzkz._!P=1+5A UF?B[!sE ݵ=i% Ρ6 HյCL#nHOZ1Q `XvÄ͟,0Iqrˍ#m0%fs( ]9Zs~sS tꃭu:Shtz)\2#sqKP KTrY: K2twONc9bWw9xY1zmZ\;e[>dw2QƔ斉:DUJot]xh d,bKԫ )Xo֛5}.4B=ZKz K>Nj">7lōFwZvv\; QڨW_v+ެ8[p[zU}}8 Q\qRθiJ*Y±fӔҙT$JTo\8T٥*6D)j&CQI ]׃ϭҷ\F+ ͷ}ֻ5²ҁ3KwƉaA6V!r2˘tij2]-\W$U7ǵr2^C搳G{JA_]zc/L C]acծ`9 os5N؛'0 /~GTHcV#W]L#9W,WPn]C"ݍ/?077ɫ!zNiU3I1=և!xE]vUY2,M\O'n_0TgШMIrJl8ðFM%z?7RGorѸ[mOfKu6^-G37/J|J>^]SRC&|P6njU#q9害E3΂";׆NDXŒVQ;ٙ}gvIi'gM!\T2Nvv_(|Iƌ9'0 rNyK 5n[xiQ`Õ۪#~/`yk_.hDȖ~rf9m9+2A}~[wQS= $r}݅e,}5SOJE'/4 eRWf"KY{jUF&VYOɮ^ܽ_b:>\oе70"qKw޾2qq꟨ W&.qʛo9qa|Dw/)4ƅ .9>u'iWGKS/[$Uب3-{wI-{<~y~kxkťF [? Bs^ϙ>u61cTJB5/߹z{RA  =J$M KqŁ*D݆uFj4;uЪ Bx&x[40y/`&{6`"G氷M?.Q+\a2U;~*CF/r(*r>Վ>pcX.h3s*K0}Vޠƾ#?CV^ӗ~#!7 YZ\#n̈q&.%zd Ϸœk/IrR{mADz$1ݫ;/08Z/{̥~@d\"Sn@Mθg !xWf=}'^D+PNB3e֜zY>,M$ >Wv*\~U ?+Ra\!P9̼6 "p˝$~={-^/Kqe>#]2)Wo5(6WoλpSj|# ixofSyI ,xCvRcy.`qekKR{?"" 9UkSs E%hj/UEh7ZI;0\H4D U5}LLTB,TSFx:._ORfKS/A&[n>EqKh3p'zV5=X[ikzH^NG>7ka҈F|lv?׆kb܌瓑妒i'n1U10L I$]^AYbZkWӨ϶j̙g_yT.}sML$07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!\ N$h73~YsFSʠWhb1` gv YZ