sssd-kcm-2.4.0-9.el8 >  A `[[U]R_O :jP 2HǃaadB(Ӊp'T_OfQXz21^z͓LY'f s}~t;!O>/TԉphV^o8y>~L섹$|Hsbe"|>}`kd%$^ehin TTB҇L7Mr.>( McJ`yL\d: r{Zt:)գ⋔<5ٌNH G3WF߶?đt;T eC пZ *C..d]AaV.y763a7ff43aa873172fbf6ac3cc7fd282c2987c53ab862ffd2f8ed0aef2d95fa352e6d28f3acf493fae3de84ef1ce9b70656621488H`[[U]݁wa_6ZC@͌+(a Kq3**3 #S_Д*)c'66iA?,tS}y! G9JBL1N$׺'c iG+++ײ5_jdϖQktW6[7y.1x}(!W"1FE-ΘJ--~u]u8#<5w[Na0M~=Pxj l=9?֬"('vQ z\ܿ {P7Zȝ֓`+ )r9=|.;7NG)Hjz[G1,HӇVM rE u0#}1)AqԼWtx9mt:}m4j>$XIIKAycBFSͫǸOH>=# Jկ;j_֠ӂ#3ېu7$>pB^0?^ d   B #@FMbt   ( w _H= <==(d8l9:c>T?T@TGTHU$IU`XUtYU\U]U^V bWdY,eY1fY4lY6tYPuYvYw\ x\\y\N]]]^Csssd-kcm2.4.09.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.`Zx86-01.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi,%G@ 4AAA큤A큤`Z`Z `Z `Z `Z `Z `Z`Z`Z`Z`Z`Z`Z`Z`Z91b30e576e05441743fcce027767650f498cf10ccca12ce0bafe8505f0e87b6fccd7e89b03f01fdd98dccd0577d20bda8a00016ff9fd59e06d42c569f340c3fcb4e29a574d0d8fb18abdee833929707d2486eab2d2c21cf074496be2e7bf9daf6fd2165aa833e56129a387c6bfa2c50430434bcecbe669ccffab8f28fb4a541d106685b33ca2c0f509dded7a791d229990dd71e1ef5f6b72d931fb1ef94abc1213fa25690d78418e67a9c8bbcd60fbdba9e95613424408274ef8f320afbacc2f1f4d75d41e75e1db652ec7646f425413951bbb7146b1b7697eff44ac243bb856e699220a1152c9bf406399c68eafa834a38b13df8222311dd28d0c6065b555db91b30e576e05441743fcce027767650f498cf10ccca12ce0bafe8505f0e87b6f../../../../usr/lib64/sssd/libsss_secrets.so../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.4.0-9.el8.src.rpmconfig(sssd-kcm)libsss_secrets.so()(64bit)sssd-kcmsssd-kcm(x86-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre.so.1()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_secrets.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.4.0-9.el83.0.4-14.6.0-14.0-15.2-12.4.0-9.el84.14.3`T@`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.4.0-9Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1899712 - [sssd] RHEL 8.4 Tier 0 Localization- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh svuk2.4.0-9.el82.4.0-9.el82.4.0-9.el8 kcm_default_ccache.build-id1829809c9517fa4ef5a8abe0f0b295c31d7ca8b2938b1c095ff53d1faecf1975d52998298dbaa6bdsssd-kcm.servicesssd-kcm.socketlibsss_secrets.sosssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/18//usr/lib/.build-id/93//usr/lib/systemd/system//usr/lib64/sssd//usr/libexec/sssd//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1829809c9517fa4ef5a8abe0f0b295c31d7ca8b2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=938b1c095ff53d1faecf1975d52998298dbaa6bd, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)1PRR-R RR)R RRRR!R.RRRRRR R"R$RR#R0R,RR%R*RR7R/R+R3RRRRRR-RR RR R RR1RRRR RR2R)R$R%R#R&R'R(R RRRR!R.RRRRRR R"RR0R,RR*RR7utf-8027f001851f790535506c5d39b6c3bc897b1033061f6f2011f02db6c36d0f9c6?7zXZ !#,ǁ] b2u Q{LPٗ1[kPlqE|oz89 HN /EbhÁ.JߍF.$J2^hY&\+0wko u_N)g4v2{*D^RNMpz<q -pˁ]p7Eq 2g,0xf~f2 uSgҠ9#Bp)ᬪ{SKm t2}q@{ X Ҭ|磉rΰIupmOQ̠4 h NaVy{OjfS ŐÞyHKd&BS対s^1l%Tqcn9w:;ɚuZP]7޵l3NH6 3JVJ $dp6Dx,ʛC/%Un^5WwU߄)"zK`QH.,㔸/3iTy_:*xϺb'GX~k4aI#*Wx?m'lNIomGnC\Bc#f 3S*o+Q]zS4Z;OwR?O$&P/4Qz7Ԃ ؾ4cyC1v`OC=Pe)xa J |`+hk_^ZN>785 D_մУMA AߛR_XQCbHo{gY]by kiv=C\}<ީ. {cE3ca/jWƌ0ϳG9_ Խv_㳵FcBq=h,%'vǣe*zNC?VO۠nn YA8&pyI X/٨k+ceawp6b PGii-P=ʹoЅL(|eAC_a&GG]w۳T.Qt v6S7 <eb Ü&%wF-hiYRqݶ PLK*p8f9>hSz|n%~Yobvݧ_\mʠή~;|(fEdx0KȖP9jO'C4MuR2ArCC@n_מl<"H  8Re<{)[pK=)ߨDFH S~ <Y+X4j$f.l8Е1ط9(#jQQɚ:̀OG,:$]VR eԂo^0˸fydO_:4F`8iz^n \Cr>D?bVc0dC1AsVO;=K{e0ej£/a X> uKN|-XrQ躰kӿ ا MtP؆o0ŸZ:l ɗW?V%_X7 t[mb Az z >1B=^0ξ*Sa#cH. Q-`cu6U`"#9~Pay-WWeÄ)⶚+2ɷ#-h>%uWD.͔b[cM9ѹ Ho Foքo^u6z|ՏGtK/5.RvDntv+@OhbgfUuߐE 5T"qr&츚\}ĺfŜx Uh>`2Y>8tp@ERMo ?}#uM0gyJ1m3[Vg-80LP:d1(y@Q*kҥXVz;:|؏؉H!jbh8Hb~Ėw\׮.$h&,_Qw 곂i稵 ^`[Aƃ32RRGHz Ȑϩ H jJu$YȚP,?åGZ% u:#yF_ZUjc m@1gG1<2fs" KaQ&.(ï&?`r (l&1(㒽x9S@FP["D@`ڌ!/F 2hMA!G7 mהZ4{1V2٩fjӝpؙ? Y-`R$S@D% _h+8Z$yf_5AKʺi݉^ x̨dZ,5[ geJhZ I`#3VNy.a͇1'yMu*!AGd o>ugA: ;ofysXǘ|^~>큌 5$kT1Z/<uf7'|0$,>0yDlcx/^]V"𒽠]5?H/ޡH[x6 ^8g`#^% H|]DZ%?%_^3v rj[BP*墕l{A8 (X#18EAFXm[(K$uك÷Q*ژ3ka)`@ vlmq>de_h*! ~ai&}u$bԺaMCoϽw=3l(,[Muʒ6q(\H~XLnFfhf{.vD4{'v7ħq؜4r1VZ8.(S\Q(H naw?T\77*F/\7L'GW'S"EиD-n,J̇Ssݿi0gSVl~=GL: Qr 78œB|IL!i?T4` [!`VZ }RC'{cw5*(YTh'"йYRRaSwftzd8B>"nF\U Mw\ad>wte]@A7;Rk5ąv $egrR?*AZ[F@Y&69Q(@w=~bk/Tx9g_I]C0%X 2SÚEB#y\a8qD~h7BmPxIIp^qICb(D +Ή"x̄=+i[9-􉇗1`Bee ZQ;t'UVcݧ&7a.s 1>"#4;‰㖸E|7XUF_~%K=H{TZ\LkY]s鷼oQ],Z_gvGlK8$h$ z]釉HDɅ~˚{‡r(Lٞ).5skC jo꘻wE-V[1.LFIJ߰.'F3D,RnüpuAd<-*R0/7 ܋~^7> pb1.Az AhKQcؤ^.z+> ੐еjE%6(8k ۰;iGNǀ`<[PM^bKEh⾺F -ód3VxBk-UB (_l?aݔ6ve5xt?9qc<$7`Nvh6K*,l/cw %P: zԆ͘wTW&&<\_w n?3F2]=s!K.j=w;9帼yOP9[DݣŌmj!%_/B OdCC<ק\bϟh(;[mJe= WZwFZZ0Fv]JLt2ID2+@ E4Nخ@P ,ց̿]1a^.{3|}<)V.I~mUl-8q6b%},FmL}ߧwR˖zX㍬#Vm$' r^QPJb#\pN[ vWLc*Tjxd{3-q`W a.qjoc(G%[6z(;%]zAHX!2P94eI sh#?љāTʧ@JEݧ%_W2u_S 3A_;7x$ .9|՚DPT㑛vkbޥhvzumv4i qp~un.Pu\Df|-*|mTuDNE>1( 'X!Iw8*ũe!M !2XJm8a >?O"Fban&gC{C2;igKj*}q|d'q.%*%}GaTAχ-8_*wo{K}ïMD~9栣59qi:6e";l5-Pbt'e #hϴɲE_eowOhD /6rФtAʸ(V܇ LC˱=펨".M&^A;I7@_ѻ^[N̾lcl'vN_̭ȯ\gТ# ) 8zlur%q4ϴ<>Wd19+t2 'xŜ?BF9oZf֒ň ElRڗL.`$5fbFzŸm8qY4~SYAd0n;׬~wAFnEh byKO* hTY,KQOJ ?537ҀjXWl%,nYL}2/jx{t>;bZp }Ob86y/8T <}0D࿻l=t [K#oxZ-ҽq/KsTVM k0f]]۫1vxv2lj*7-66AzHTP8NN^Ix$luZ?.$ p%83M->½;acݥz ]hyB/6k( QQ)of&Q 5Ѫ\5&YvԱtS_~:9ڃ28KY(O) 㗸m^G_Qt;s#22DM/[G8]B-ή1-}uebn{gvgDOG0$PYX3D+wψfs1m+9g#)xntw%"w lQVl!3 Λt'GEos ƅPݠ7,>m~m`k aPV.e֙Uw>#mbcUk6D`r[a47i);R r1BJ&08|!y ~bx?}= oQ]ͽ)GWZѸpq*f OH Yhݶъ^% el+ć%0n- ?H™*@Ev C L~F4C[ g^=>'CZ׋ͽ5!Kt]+AC.$5U),) 8x=)3Y?4Oz "dDQ9q6XؗM^L.fC2)`Vprbp:Vn[L54%l3FK8J< e*"dm{˼z53s0tZRuc-H5x[3hqlծҀIЅ*"8,7LmAqd<^|XFa>vh^L?0rt* il^#(gLZOBt'@b'3QITrrs`|]f mHf9K|IL>wQyuϼ%XZ;KpiHzgx? mR;xa=@IwKIQ|G`MƁfh`vN uΛIt9$Sv; )Rxz(g)sc @/t $rrRgUUCFۑIc>޲,G-OhUIǟ#X$Rܒ]Zʒ %kb#b@^4D) sڂ,Iq`~d"m~Pzoi ʧPSqtrPgtR639AkJYkNL70]*] q }pÙK_ȉr$mlQ o1@6o5@;-.]w/ /9b8bLW#/8" +[}2 IQ@*7h:\3 VeI!ndpJo! gX\xg+xmjR&&ΐfUcql'`XV}wdi1N?wd<ץa#w>făoDg%4}fT CոgjR\+J 'aՄ=J4dk;%MNHs P,y6[,S0E@0':y+f,Sb Ɵg# + Eg`LR7X<@ߺȺ#v2P!yTe~>@/J&^Nl r}ʞz ~{h Dק~.Auv8eJъ骨B0eyͰJWN3 삨FUW-<Ʋߍ >R}!  KZ%+P.̨S1b5tVWPR ]B[v $(ڟ)Ta$ tИe{"frS>)e$GRT1-|#O}\"߅`2=6/`-36O+rvSV%b,֧*42 u=!Il\״D)B;!(&LqbaΎ|Ҽv<؆I.T,ԾXÎツ4QH6;N7҅̾5 i·pr\V#P8>I/r^h6YպOVxl#f6~@hEY+| $ Co [5 5a\&8g׆(TVεZУ ڻX\s;| :nqeIPY 3d\D2ANo;ਯ'5䊠ʎp˂1s^`s5g"VrŽ]ǥiHH \9u:Ճ5E;p,Vձɇ1UAS;pf죯6(A 25HFW|PV\~\ pm -]LGWҫxxX K3;+y>\2@D*u=]&v׿:0O!zTl!eޛdɾv4e]v)wj}^*}mn/xjDs~^܎Ⱥxo)y)ҝdsҔ7pINJy FYS3^hG0?(gXσmDhj-I80@:^^ճ- h:)U?Ap܍63&\,G˯Л)6D2jJ^2bWu*5L/ZD^[&r"^]95`rkl6_^i>ic{?>fOm?+ u)k>ΩAKǏbAeƦv{03#5!E& T U8Y~ IZ!/:Q'F"͐6U[oU 8PX©pw㒖Nb$̪3dI%@y<7B94L "IM9jFgU`:A+"%>Ex`  h˟0mm3OY2ImJ31!duHfqY||UfTAfB;iBjxD}١73VDF_ 8P;73n༝ ſY-'8H<`~O!ORˆʧz=ȨƿOhlˈI:<[hBF4V*_VƒdvǮfm+9&]!fƞR겱wr~Ep@Z3`c'϶ɸ#oOvrkDDTVy$8-MO&WNQϸ7+wQu]PUd]w| uW C[ؗdlfڮp'~qzPXm[U7l$gYMd*:b?ryb Ȭ& ݳ$rzO3"oߪH>fIT]`ë"*G2 g ݄[GFs_ >id̪,*gEpTKPi hcKy]fw]RۂB66$9hGB["G5Y{)I ܿA8̈5= f4!̿ Hyt3à Ao|:lyLj!sD(m,4@▙@1|@OCz4m.-Wc!=.`*"EbY-]-=ĈQ]?֦¶k%7Xw[bQ|TOw !F;)Sc`}LySuA9N|qnߙfEI|t˕kXِ{υDVB&ݍQ1SՍ rU-OQ-?u_E6PЫx2PE5 ˱;"1Q Fm)GdwG*%,eƨppR"RiMْ7@t21"^qM,Fn?3Qm~{c kĈ>۳bM &%pUK((?Eij11G"cVj)L C.|LH)6D̡'#y}=X]1ǑuWr>06qX%#u|23?h˘Mđ83(_Tm;*jm5H"Ҋq"T)m^1n1F’mi;N5/>Ġ4x Y -RSPb޽Ndua:X ɡU]Sqct,8";:aʧՖGr3U-JCp\%Iz3.ֽP[u~kvB&Ya빺>մY~x@uSWFŪz>+=uR,[ W\)(O|ڼ8t=U操?-czן|{e]aA;ǁ >>h7KIaM<,}o| ҔUjc٨ ùӭ[<3pZuյIgӞ1XEoÛO.2Deߜpj߾'Þ!8vGXx^ZHˬ5Ag~HyR ^Z0[,ZhlPBojoM ;^k ֢n*ii*#"81Rr*\g"&;Gg+HFr2B@iTsJx\g;˼!S7kNIյz!{9Vۅ'Mg. !ާ_W$} hC 3'm)ҕ_RepE˻LND++g@R Kx79598q(.ľ.)/BhEv^u.B b U;N ҙ-3#lEwDe~R=8^ |J,IkMbL?'`G:ʸ 8U2SɔQ-3ZfwS^(mR))ϙ]Dbdr 9XܩI)ٌ<ǁ<=SGo th]Y'hE8<{lYd3~zD<, xI^E9 8 ZX{y4n6( ˪-rlLhFDJ.2=oϊ˻SԷ/a"&jBKipV vn0wHʞ z-l<9Ej \@E"9NJ;:ALPJOl#<6P1,e)8~]-Ҳ$HBbt] Q\8~㋿h\vc0#Op9~=yg+ uN85W"a}K ȋHk7]kxO +Jmj]pP$F3FOrvب [؝~Ε9]Io@NAFGq%[5W'U˙?!sUX8 2MmcrCh + uьF𐒣%mimGo,OW`[$a))3IK,^ZCo-?h z(}^ۦ!2у\CKtJpjz5FKO$k̐<'*y; ѳ5ݍJ0HEB"M& mUp$Sv 4 x5I7A`[WsQ]M_{~sɑe4]P?<ҖA8jw~= 2܊x{ gtrS4:]^{'eI11C*x]7V۲f`=N{|Ɯ}JҿOHD#KIiE 8e\LV |&PD/U{>qp.ၠ͹HZ??SGaU&M+<^<\QaFW`hLa Y]869 7 ߧ$Kkۇ@.ьފ0]fAc.r @Y#@hk3s0*dsAfl k< kkhYصZJ7kzRvVs`.ϑlm?v'CbizMLڷtV m([܇ }`#*uUsrB437]vƭ++zu@@:3$'*mR(by'܂L(atu8PrZ@a3v2 1#ۻ[1ho\7J#JW4>7Ҿ^LT@;?q~ƸL~r}dXm3/ p*ИbeAT5vVwaa&)F܎@hmkX|H;4J|$M ] *aA"Sc~$g^X8Y͸85@f D;\^%p1x*FfG*=}9 RFZO`D1n9K]TGJ\0Xx !I |*骂MYc݌QSeiUH+fTr' ;EٴX-q$|VKˏWʦ$ͭ%O`/[Z|k% ] p?wsZ+ no2Ӏ(cQ'؅QLtj)*A-hގe0i!a4[Kla hGʾ~Sgϝl%`~%0%E_'=N7j8pSqMlg uߒ R!0 ߰+'"]#`oG$}~cJVSwą }zl39Θ h,#fL']30QBlsQ`RSΨξ%esZq`8+uEDNC(u7y~.^QGE^ItЎXu$}HHȟv`٬VDx5i E}6NfLld8z>%|FS` 㾞0eN;Rsԕn᱗%T]e iŃKjE&(4Z_n{6Tvr #2l髚* hy02lrE#SYm Ocde(+PYjōB^qXV  Wo,Vtc\sg⯉#C캯N|*wd]'D`\И˖nظXOEH-X$#V囯~C#UhY[ Wq-TҾ4ۺpY3ELM%_! rl}[R0ɘYZЄo^qU|}zaX d ?N"TgTLNqلLq:Mnb_.hx"KF4z?8 vlRAsE=dPӮӼmI BWo^ԒV̎:MhN8i N^ɮnya8-}%pQ|ެN6D!FӪɄJ[usgQp>8BŘj4VeO$*其 |a,^wk|tӥ>JFemN-G{(D-r+qyt2[Qir8^(msXE2-. +aڀWKMFLI]l ]c"=(6GP] ”UBjYNMҪ/ :/)j0$ Ӕ(" CqOeQCUQv;n'{p< [W.AEs_0C]ԙd/)Fs t8<AXX,gLefQcNCsӗIpFߕoGHhǟ9oYEA.jmV.NԲcLۃ <صK,L_2Eua|lI*Ktp<Gcnْ2Dɸv #}r9g\(fS2nk'JlF3MU(3 F}vؘRE,k{PG= |\}%#AH̾W֢!6`\`!kWꔦ1x6*_B*wdn_dpm IvbPh3Hi Նf7x%cBt//VouM9"|nmJ`49䠱itL "]1 k-ʛs?Zz@ 1\ԯ(a[bu- QjL0ZtYMC|L֣ w{x _%Ou/ͨ264lŝS|㬐:+%?PbN 0;$Ȧv9Ͷo(cLU/Q 鵜V}<}4ir7lI]پqP^>"ìpbP qjd8)PMeYRrttHlhÞId"h1-k1̒cfe,@Nwk/͑=e<TCZ fp2|M[,scKcI!G52:^/~۱QV t/#E+YTYN/okhYW̾aaC=~4W׈ٹQ߉;Zs SS M6QWflͤ+!;-v]LAu[(S> }՝_}nqG*C/Od]ThaSz`r=1Dz%Sy#%acXUv \Ju^&;oa9}p/(8ωJCQiwI̞.\M-u*$iWxilg3oIxϨqLfpl`P( eBs/452'tA o-!*fPld".Š`CHHðjqWߺ-x#h!Ylú~uAUrA=N]W jzqMXV&hP'EnMTFSsڠ}}xn=2I+l;ZObe}$0 l{HwkьF :y-Ǭ;Y[Ʊ?t,+x6αՒS'v; b s}!R8LĥCNy=VDZ a6SܹmM6wh9s̀z}u@5UV3!37,Nt+_P_Cl(NJ@R49K Y\MDITmDMO(, BSQ8j4L2quuWGCa *rՏbzɉ'"iIxڳM#6zXNZIݧ7?e 7z/fTX+b^S{paAHo{zC:F:Q)ֶ=2^2'P(1-f[d7_Hnk̥:z/@hݙ\!ȑ* 1υ+ P9hY*]Z j8hAt+֤`ܕXWV! 7 a5MyoJ^,R0nwtqg{%VMZAab]ER_> 2yZoaЂ}e[ O @zA Ɔ >!fx5hwz/d'I#:VMlBC.{<}{lVQ} STE[Ǫˀ4vh5ZԲJݾK^BȳIO9Ne;D xDsV?Ee`iA>A$+ΈΟ,}SW i Nc^>mYՅZkiHj}lk~ rmtMJ("asM3_t!_f:ըek`E w xpbw V<͗EQtG@)/{IL} \.V>r^J=RE*$s(V[H6S˘eSEi9ni3m-h1TfkA~A猽ne [7ok%n{i_IO3j W1f9Iӆ xjz诛E.lOt ROd7a Ǧ Z| A %|D͌Wu;ܧZ:$ilP;gŜW\{UP:ߋCVu%{C<2>]ElH,l @2?_LHF`4-ە^^= v>%Qn-j"e>u T9_o5үϓa"Uj)cRBמ'*1P“a9xSvQ{|M@::Ā5y~4Oて@.yoe6eto~v2DKWo]x´uX3+#,e+FerȂ~))K&- c&aY,xCN@4(HKH`mrE`;4=bLXEX sY7WC͹Z|cW@ '5(8wGϭZŰOGn/?jJptǵHZ:3kt{MqRt6\VUZ֥Vc 0_iZybYȝzLlBwoi^5&.=JXx/խK)41>ܒ soؔ#M =*չSsF d̹+G68ݻz`З}s_쵷"T!O#WҚ >ū:G)Ր]s:]Z^L.3MX,n 5&Q 闬WvXչ&Y {U,O"Y&7bg:NuQٔXWJ vH! "- B.Y4B%}.}cFI}4hi/;qu$z<Ϣx NC#HrݙKΒ!.3HR^H}bu^zm(feha1BLm )tݙO{{3Q4䯧>L}GNEau:۷?P/>_k r ;y%@v`a("saPTQ4#&ݕG3'=F'Wt`kh%=#Я> m&S&䣪 K맡E֋yM1dH!g=7P>*Q3}vpp󆖒Կ3euu 98nQ] X́[9ZCo^cx4H0,fXb{C>S#}O ~V8!G>_%˳sYaޖt!zͻIA4%~mvzr{Hcaj!L߾ءA*9O&D8Iz9LإqC(\t"xę3}hW[=_Rp,Zl")~xؓ0ڭ!FMj'Z?shgzn(4aqJ5ܹ^f :Tvf|7Bu*,Epv@? iyC{JФ(y65 cC )\$O/}py)̨#}Mfݢ'5 o}Hkc]S/ K1Xh2v j-Y{ejhP`C~ߧ!H]Tά4\4C$0<|I#:?}QBٶrʙ ~Q)L&+p >inJM_1Xf L>FfC`p.؎k )'gn҂7^.(\m7y Op'q9샾-| 'p)hB4HT4%*o F:ה] QAڻLYc"P v"$ʩ 3m%`>x6そw}, f޼7w`J3pMi#E6cmV N&v򛒆|뱔d}RPr=-<@XagvPcZ[q類z !+/A>5<$]@:2ծŒ[qqzÂ\;LNTK0Zm̀vl#GCH4חx' s2`i?:o5(&˻@-PC~Җv}o3VxZ4u/@<wM zL Uh}%(c Q98sI򭬣gf=ǽ>!+qP͐<Ԓԙ'5u+GYkt;fx }}֌μQ:0d2>pj%rnLqY>/y11Qa8cL$t}9v!"ɵ-M՗_x RGD>`NwOt1M#W47m8#O%LʢE 9YI5v;}T̥pG'|֮7`B 'P"XE$|;m6So\ I^HmV1L%:[YA.KRCQHHoVs3HkWE8>U[`?sgN0W̫Tsy3ClUju@be[﯇o\q9HꐫX4(|K_]l `H`4?cKxz?t5ΥOX9ސ-˕Q~(՗myapOON`-]ԁ:D+ۺ a7_nCE`!CD*ub=_f$og/i-ZMEL"r4*g>ȳ.unOCň1w~Z1Z#tb@ӽzMxģl;-fn2|VPC /K<6{gݲ`Ykbː[aV50.&xzڭS,yxC@Du8>!"0wchs&>0i꿊FpFsp2$[֐bx,oe'Sjٝ9LH8X|VTtz$z' %4T*wvJ&T⡱*,^&~G~h`(-vItKP'dRRyuL5,,4W܍j/\&}S똆YBb0o̧x * 82Rc0:+&2ӗQ7**pU} ˩я G\ 0g7AvNP]j X-((j25*Xdgz[c?[#8YZ 2(,Xqyn sAD89!ܝ/C$_L9I.";HCT=ZyS2#}-kߊ #.MY]2R%G[9f qS`27.-Y0I`fxDS3s6,b}6r dioQ_0$r|*jD!n*#+v@={n$ߟmg})pΘ3]_?agBh2zTؑ@D ?@"E[OSR;x >Dd9 LLGLǞC?6G1!jEM \VOO@^VՉu@9:ܗQh(7H؞>J\rS[zqk#Ŷw(}ސ_.ʋ8cP=-Kte[Bsgl{hLe3\v  xo c;0xq4#"a =6f qGI3nA/Wٗ@\& a=| Kr0,!l9%e{p@"1S'dd>\@ret`aDI[lwBä\c;*&0aCjNAQ9[^kMGmk)z[@:eU65A~2l1fG6/$5iB[FFN81EnΞ8,L߰a7M }\%aL)XhEx*EFt 6Vgv-q|[;!?Pá{_z#)/Ȍt v~BvϻaW;&wI@,JMյvTxMzؽiztt<\t[1, rrDy{߁;(Y\f}fUPbgL=f L*2KdwISLtߓ`iAN!u¥GKV 4-RۙԛRe8|_@Z]Ssz @pq4~o,ؼ s*ѩ7Ex3m;t( ;_PAmt}a-ѓ&b=>Ix J.tRC Q{/쁄ދ~V(Ku!v%:tXDB IJd{ye{/f67>R~nܐإQ4 : V^[s%dr&" {'BbGjߕ4jI8q$T*~;ۛn-j0噡]J-<|`bf|-f rI82n[CQJMh.)((GqhZy1Iݞe;>%K^B gi*\z+ʵBʀ$3- P Qd$$ԦjH-6DpŸбQm>we xa}}/opO8@"Or*u܂eAB*jWXښZHaviY O쮖L_ܯU<\^'htW|z/5P֏qILd?HG5bm˯sFsjᶃ<)lb6?ݚTR!96Sw y/AE*c6e`?|Z)73{^x9KkLjX%_`̟Ӹ#Qլ!Ǖ<'AARo]TB:!_V(e˒Fw@ūJ" 2.(lq)De88>|;Vm ~T==4hg.~D9PhH6#1ImYQ.iy>8?X|g?&S?㶡$Nmf;q'6tFA_LS|a8yy.]S @ߝb?R?FjpDSj+ffFshOě&bIT.ō&w&^.KWO:ƇqQ8GӏTNtVW$LvdZu^3 ?u2.;JbusH7X#.B-Blr"6SqwgEm~7Z64+)n*Wfz,YAM7FCy=Wm16W&bN&p"Lr߾oCW!S#\S.h%x?o!W:q AtQH:ƋXWBYj䆀b}= v"7vv 2S5V_65ק)xXFм)S1#>bĄܘ$ģnLa,6KzI5Kxv]JqQ$/1L(:,aPs%g?oûejv#U1EWyT#&z,eAv7!{T (>XыzRpұ07%"ط]81`#'r'խ 껙wOR4a ze*y]:؏DzV]v}3-Q͊s֖qvm>~+IvuzQXpAY@64@(`k_>cЄfڎsU&A/I: hC,QvjN%V)BҧBRsMb-*SR!yŋZa!k3& e^p|~˫Fj\+eiw"֬P@r<\?ǾLѨU{zw/=V^`eu8&In|io/9~R>?\첫d Net]k1RMӓdr d7%+E8-/EG/ڎQpu[|֋D!X,1тE㰘hߢFyh,˂ YRo!ʶ5H3l )j0'j]U-ɓ ' 5e/$V=CvTAR2-$tެd ezNɺeŧٳܐ/~XB篎{r5g3#V!T#?Z60(Rd=W³tVL}JEu瞉}%9h+l}j/d %tґVR}ƁG9-kz )l@A p0]9N D $"w6jBQ.Ў)~wTخ>)v,c!/:酫UPbM{,gHȄLERfS"ڢ OlhkָpBSL^E:. +CQxqq.Ⱥֵco%w븯-;pI\PmLCE&$L?8QSyq9@JˮϢ.%_'a3WMK._7*ϵ֬=V:aUD:#˘xsM8 Mqm=/qT վpqÿ!D)-(yj~M?rd6S0rM6Sܸg EЄQ ZƥWјjjv5;eIt(AK&bN6\*Ld B*kbSCd[oHʏ?\xD3bPF5rkI#g<Ϊ@I}ks]l#1_dr_h!{_`_`$ػSo %Vɻ ͈;J(l]B+8;LH!,eH ˲/,}]5ͦ9 u6/w3%Cp=R*>Ԝi- ?zg|Sd &(gÞ&NCY˰XKr6 < tfˣTGϞ 9iƖ72QF3U{a3,V2* SykoolY_919nw.>%_=ZJlG4:Ж::p}+b-]q6;.1;cϾZ0K:7<}O*Fmյ~wtr@k"㌎FfÅ1m7~ɁS%Vi ձ־$͓p*FnJ/Cw[Wd57:F" AǂgDJҒ&=CB~QoyhU"Yg#ڇ[ᓣw҂uUz6֥#;<5i׊Δx߳as +۽nMZUQg?s&MԼ$ |,+E|g}+N _SZ!1w*)bYw* agGY ONYw`m' .GKyr&+)\1?V5F\k#iQ${Rop,S&]SE"q 6E[&8Dq,y;(Xb8GEoNVYX8TZ23^PP2*xdq$L!~CzHr;` ы[ߗfQ xIKQ^/qMǴk3Uɩ,VYco0{ya4‚;zULxbXn[qY3ʫa|skU@ݴ0wu63}H }ifK]d~aLDűK.z'𘑚DqN_b]aN).kC S#5>391~UJF36y=~0ҧ0mM<4HkAa*fɲYjȠ2{)0J?d1m䚙&2'u\R NVOjoF+}t <,eO,m"p|lD Y3;_W0%h: bϚ-L3BCgX,Z4D.Dt($){ELUl Vf/Trjq 3g'mT#YnV iC^B6pJ8B jI ~ - %8F[ 1Q`%O>\@1cRY: X6;Z8g!jH&[VA?θCעby_#&֬ fĚ!!#7 Kh?yɘD(;b*-[!(x%"dw}hpEQUWhmX<3͠-*i/,w$P,>f[)=$R{шg.Tt{{A [O 0mJHdeHQHhӪ#:hY;OGtN3B3TAbo$w/rm /82Z΄wCĺg1#s8,fz 8(@"pOߟ\z:{k95crPI%ZNz49\%#\~4Ֆ ދUxhN BAdLf(ia/] ]fQ,sBZi|?/[Cz9')ˀ =S\ӿ)ceᣖ&XA*}i(=nJ 7զ!; ̸ lQusMizQrk6bo-L -e,JAdiiVCطk&=c(Sm/|M]dvmaЁcs)ы' \nT#4N=w@(u)6Ĺ(A9^E/t\M$p oN]2tu]\c_LWH_`7VԄ5-0ߏX%6cZDDʸ!ZMX p 3lj3%Иv6WglN6(V ˃C_`4ÂUuT7o&*fĩ_ȋy܆,xA.K o} vKKvjyC#lS=Dn]#ۯxj{ mGE? xCyh_F?Bw 2'w ?'T@|?ʣjCiUݘ\ OOb¡k)xQeoLOe.Ko< O/Ucȭ:3TNzi W ^ H[v,~>lDq{8m v?DY,mn:@OEy̟%>R59l>R?`&{F)sx~` mEJxB O>tjTʩ o4jA'3]>= 첨YښU-4+JJ%NQSc |! )_Eւ26O~bq!aחo6'Bb*_x&䘓8^KV@  7W0x1ثH)苆dB"pZ%6jռ~H).&?i4d"2,!p  !v|!:  7ן9}Q[+fbg=flKRb;d/=C4Az#W]Iaؚ$@9Dp4{U}rhƄmAzUY[Q.&6Xv@¦?arǽQ@HeK{`#:PA<yX׭ &EzR a2$ ?pNPQ jNIτ'ʽ$1df?gs}VFձ w%NOF *LKDф2_MѢW%H]VlR7cH R&#ol[p^U'S7U vEE@H4}#z|q]O*-r}O<44eTٲޮX'0'ٹ%A4:4}ڤ>}ibqt ktS1Kfnp si+2J@*9ЭF]e!AzA|3\N.I=Uo˞|+3 k}G1.e,D$Pl `%Kh oӊ']W%昽Uy)R=qU,`:tmiNـ?7OgGoeZH=à@ q?mH& %3D֟E E4fX^R@y E! ϳ3w ٵ@N/m65&Gy o%eSp Av|<bI.>iޭG71bn+Æ˵5lg."1=GB6QtbA 3dmt&kB9.nThX^Zܽ Rخ;$; #8t0Ϥۢ)ߵ} w h:t}g}|U2 .$Px+ӊ1 R8{aJ $Mʆŕ2lB;QXoyriwAwK|2!݇@@ oNw6PNE䜫Mi Qr\&)Do\mLa8`Kj/$gP -(ADiN Jۢmא".;W6$]B"2L AkDgJK,.V;R.+Y7zT 4)6e&,8Y܄Hu`0P70 _?ǞX ;\&5r/;F,ReCn2pZ3=Y:)IeEeEû:Xy% tiB5zb8i:ʷ,)|u'qODHAُRjgM7(] K|)X>ZoM oP47zS^M[MH:mFRݰɛ#@kX@*Z(GgS@aQ8 5g,+L_2N^RABj=y Qxb(Hr}=@CWic~v1`Z:58\Vz.F+H#{:79=rO {P?i9Muf&0tM&!xxf^-uq삼U$`"%j=cxJݼ.J똣ЄD,B+晠ط"s?0st[&/N݃@W(]o[9d%0AErd=nqȃ͇l57ZӨNД0q/rNx}A\' m45QGO쿹W/GOH%(^;.<Ȃ81u5cBˎ#%3ӳGJpz 0%t*DS#*vǺa5o"~y]dC0K@C)&qXS딥y&ND‘,KςgW~ 8[y# lfvQ)VQ!uWژ3wښlx&wUKOLv;sMsTy&˰@yb6PTlZ 3ˋi?UxBD*kGҩ~\uzZq c"TP欩(ZOl,DڿE<#B)ڃ'}󲛅UwO"1>k5DD]1ؔﴽv? ARTq*i ?:2Z1mHHAlA)sllftEhpkEXKC\߿.%ԼA$w김FD2pM;IG2{5\^+1CBGᴠEaS /Y!PuNb91e5싨.,tdt_JcI zb'[(Z,(w7#K կ,HΣ<)_*#ھE8y~sj͏dɊ^y(:-+[͖w\A}|̚ NY' 4 9˂5Wp&&Dh,/0#6 oj.71Jm>t!fEy;k68q ބ1zDio<=ۻ${6;`v֍\yBX5~ۦLH~F}cIw~46yF ra+ݦ6v~#a$KFKAwEu'v/dq:rGQb+ VA  K њHPSaV լ%ŊBE3%{XO:{b*`yVhH~h}^ H>BF$Uk} 0 tFR zN/#eICe!fje24jlп[1shaqJǶz {;vsVr:U;gz .glxL}*ڢ4|$&22E KԫDy y4_9n5_u3};/TMnj7̝ǖCaJ 4&uU,&ਣEAtא;z{1giml?}E_U]N>*kLQ}Nt;`ހ\k+iOј_> +f 2Ղ(?Pb0a9L(aդbIhy6g+ztrqJN. RL$]֥8QU{=ikkY:<O>;#w<ЛuGoq H 8u2~Cs0Je?bāݐRVn4]+FhdĴ1G1@=Z8}gk(O.(38C~%G-Y׃O5]u+E &Hm|əTg{w-5"`kWd1oEXmCR0g`C<8_HQa(VMΏ ?~I)e ?!.݃>aA5 ̀sHHx/-$bYotOKʁ]7C"z%FQ"s5첎ۻyoLl!+LYt\ 鮦uVv'%+$^fMX#)IO*?,)r6tM+3l$ \oކdZ0C/R!G;ZENcmbʇ%$vʜk%,GV'{(@]dtk|~{W)xF,ڬ0%UZJ5gU!ܬWM(PFpFZBWUQ'<=[{T3C?' i`Y&'Hd¾W\ݔ{ѪV0m n`IG51WTjmٗ~DB}UyDmx_h֖5r\pFxN` 6-:PFr2ɏvW8l ]u_rwo7 'iZ|)**9?r;d{gMC2rNw#nMإQ)Jn -YERT(DUsS }ó"u3b-cI=@=F؅|&.8MÈ-l7=v4o]SW?y[ R )T*Mꯉe7@eLr<%8ptk'gB,m52?&F8iKEc<<=Rw?xj5IPjk ɌǪG-wLOz©GY|#wŊr6h0?#pz qH4uE4x?҈J VX^){wmdDrBFfoUK ]/?i#[qrg" KI N~a ,\L*˶b71"qFM(ON *[4#XN՝9=s%4gv OԦT i$^Q._)L,}R/% DPĻ zĚR%\LmLuXjI`K@sJsd0t|)K>^ w/ O(k^|0V? -jd4L2ǝM^XMgשn56ȳz*]Bp_Zr=GɍQg:ɖ?סE$lN=ΌMk09F]ƳP=V}=612OK!E1o*Ss qq38+<|҄C(ֱO{H(r*FEb\Wp(E'd!JLN\^Um~ܷIzrnԓm4Q'J6E^.U>a6zۍi GQ;5uګcVd3Ǩk(ll^ć=O:c8Ӟ4N'Qm!wE _oI͈NAK!Rc-WQYע+\ ;;[Oih@1 Q8h/bjT¿0ZP-H&tY[߭`G%اrBj7vY_FLfuKCE O庯3 :#\-/9]duK?ZTiQ1é1ϫbPtpx VȤLEyxOj׽ۗyLW>jWƛì :/() yC3.v/ C>M=Pp_WU"ڲ )Ե|/c/%2Ћd@<*6|)UtU*ZjQفf{>0TGEz#"aj-*)8u`7w{/ݛ~:.T K O_GPa֘JO&<_|!Ydf0+/Vm)N]Tx5]nM*zS!_ZPu34qm* y?<TR1D0$[9}-\k.ehιOnVf,`Nʅ4iv-CCxpIsr{ =s3%& ݠgz37-M;CƔ]  LߝtjS%wg)8© r xGZ' sI f 49ƎpUi:@"lߖJ CMU5j[ ra ǵϞH# ):e) c`<ʾ/Fb*}eHM?e:dSxP!1ߪQ/,[v^Uό%O7Aϼ4SSyluwU fr$H;Pkb6HXzpVa4^3g΀p0rUE!(K9{>>sDtLJsÌf{Uc$4ۼZӵ~9S3h s(EoY8=?Fbk4Pl٧_o^k9{Mrs{.P #,WGGZ[ۢ=j0WQ!'UF=+Z5gcE֋*QENJN lLYJ+fyfN~XC=s1>`Usj9 (DBd21K1NAAo޳YugT:vs!` eW;~zFY}rlldZuRGl !!p}FyU]"@l=LVuei.}?iZU & cGҿXKlV2!RTN ()T<Yr*\7S_V۰NWVwdUk gVv#7U8n Bk_h,iXfn@1O\"\aBj_J"k6X}hupQ^ 0 ˶O +kf &[\Kˇ@s"SD}Wg/40$΅ GPI9TdhÉ[;Ĝ.o6qxL%&.T{V砄mEz 5߈>ik\ n`3?goKo)TvnuGn.v,:2;7VV% 5B<ǝ̫6l*lQ22˾ߕ瓦 39M<_9uzMҸрhJۆ'ֳ\& [ɗ ߈n g߻zZ݁0f^N:9Hy]fPԓZhkyگ>^V{_X(ݓ16~B+A"p Ii'Cֶxp2%Xo#4nT=L9+a]rkO=An>.9ZECD"M[( v ͥ֎ i¸Jw QS̶I"gSZ D5Xg/c*"L1cam85v@=ly L9iHn#eKFx ҴJ%Ef4;N1sP&݄u*BD2* FX{Cq c=٨„ۨIr8TrvC9v\0VgkX 4!`]sniݟlb[89Qr7T#eg"bi=K-\_~HLە@;b4/B oT|AkD^{`hz|Dί՟ .qJ7G% j =܉S82;- n;|8Mq|9ɐ* - 2>ag^*2kDJI>߲vꈲ7gsk3-V#bd T8gvlKGLmNfnSo{CʫKֹ+etaJ|*'spθxA‘MSVȧDbƔb Ȓ+̳&L. %B׏&q~ܗ#]PXvݦK&?2jwS۝C!dHyO5VU#? lvYkJUr:g+צ_|*:O71uRwQgZMOS\y-U)"`՝!vDbxeG[)S_Cm_O=2: -I;>kB;r XzP *kԫ%~ZL- 'DsV-T}ajE3{U/Vxv$xU"vY/(o۞'՚U.b|^FlkНMC8mCYL1m <|3TJT"О"0l}fL=] VOp>,\/_ykHṲZQwPo %5KS_?<\X4߽[=8j}_R^ĥOD7nMJC_qƆ|dzhZZw-:FzU!HÔuyzLg(AAƲTN5§FӮڒ)#Ky'POO:'Na`ީ0<&BCIv 4m/@I\D4}/ oF~_0Wؑ^#ҍrsQ.Uv➯Wm :dʤo9Ŭ$5.^ӣ͡|ۘʐ6TJM 9;wt n_4kG[`+ ВUH3bG7pXWZؘ(;(1}fCTzwXemizk~|xpݣ/SuohQ=7~5HDhYh t6&۲l!T;QqN J)gTWdZt[ٔRd7pJTf#d)0CΡؙC+fFZ ^mBnE#i_5Bh]-rodÇr?D V&=.v:=_G";,0#Z0Cgɪha&^CȏYe*U0e8%7Tw; w:lt$|aCk{?ڄɀt wV9ۦBD#ʽ\sQ\ԘP TDy\*,N M :b ) th\0Ѓ$b-Ҽ+(p& c4\A̽d^;RV=xF ԘAWN%EAl,?df/Nk˩O}͑ Nߛڨ0FU΂>C.%Ը{-aDhŲ}u)IMH"}ԗR' KiԪܫ=07u(A$#f?S.caCN:|1͏8Ko`Y)q!̇ !`3\ +s4 е -C!4Jgn.?a`x)ObB0Mn)W#zdsmDHs)N#_Eif*HuU, qM wQtqXv5c :x DiY2v9QpTk\cxFj+ Y+S>1tpi7̑AD ]="Z.j4w,ˬHF\Xf^$@5Lmdxgԙ V3;&Owac]'@Lqfy+2?B+*91U+Iӎ׷G r>evտgyх/鞓 c!6Ku`b'^%e5,KWސɼL5ok8]DTˠ|#׉V7{d n;A5SŴoX_xvnP`ɮ W\Zûx85S4-ky3dqjV `c'_ ^R`t11|Llx)+58[JufUgq*Cvsj\ # )b 2= \{y*{yVqRJ-nD63/^6^,@T_Kzhn5Gݽv> 'TU2y{#hݔ%>)܍eh5>M/߶+5Le咙":ou3vhq{ۉWZp #I/ѳbܫЁzf*+G ^Y#;@FrARWC5 Sۓȫ9콯eOs9ps@YsZ _)ֲ2ĆUWYLWj@׫>^iք Vh tH Sߣ~p-M\Ԇ0ΦAxg.sC[0+k*!H6e#:-A8*ͳkgmIyn?_@3vC0!QTgBRxLU"qFWpYSܪjp03+etlwY n'[ ċ?Ie0P=nWHk'!sGk,{(Fėz D+|<=7/! (VLl.ZՍ P wäWQ={Tz//4vZ$ϹS4nۂh,B!,m3Džcz=o< e 484#)Gwr9qK#n\VH$ǩDuU#<'I>n%%~I%9兽$0zN{Cyd#owS6pKHJ~်lSg+}`os0:y Ix9}Jya.L.R|h He5<ax߉+x 5Hڥ#ٔY&I4ΐWء{Rc/W/ڍ"@L X~=g3͎=~~A}Y->!S%@B5 ܓT[f+:ϧ dOA^O;O1RUlW4=h6`YPDگmIQ,*1qinVkj7+5CIړv2ð 2+H߉Z߼YPW, >b(y"s91^!LN o$]fTz|н E0*4e"ykψ/GUhL9#&ʱطB@űl]o*Bs}x͑6>cZ*ʙ ]ta,<9:o?ŠT"E[#o(ᨨVbO^ͦYt?SlmB6GAE9F[·{ 9#:{$p܊lp+$DK.Q gLuk΋](Q,ވ 򍏥dnƎCaV޳NĞki -W?t@| lJ뭟Q>ͳM'DwtH>xDãxB/8Ty2~rg*ZAc -> 3&p.dq"/u RE}P|K# tʱQo[.]eT1hހiP;Y?oTÈ֖Zl|rHqϝ WɣsYd-Rd^U'M%* ]HO?5;dbM%`I0B`b߱2܉ ~cN@r܎\dARyL XWEҊ>CȘxvi 2Ganb)d\ P'e?R3 &l }7[~Y>Y[+*pʜ٥ygA\7"%|sL~HVM<3}Ӧw`6!ė m'/owPPY@ 6ea1˂Or Z°au ˆm eێP(7z~M`n%TVAр'?w^/ů:`؏)團;mلE-[n9 U!wn}æmw M'sԢK؅-JA*kRCW_@Ą7@ξU寷dx_ tdVK|&@$ T) R)ɫ1{'&i~ц;gcN dgwШtk%EzB z)R&B)d 6I !R=?p"lę>2Ϥ8 B<>ހ %,i[U|k\v_te2tMog-l$#hg0969'ߜ߳i K.V"%MJyT6C`mS m/cz劫K-'_B.27B7Vs}'[]P $E',(~5ͺ]C[1`h^\uŪXLyֲzS%`/!ܿ 5wSl-boTҋf\1U3kuFϏ(seOw&SU[' ؾԗ!I2Zʚ*Iw1FE_CE3m8i=];wlvRquݘzaS卺 Q HM]?dK'ęivtl&-~1/{/قZ {f[ꃊ`x` =սqd'@i7'a{!Cp~ XX˽-Gɣ?z8V);uT G p#k4xe>:RѤ͙ Pt\B#}MtGKRA.>#6tDivMnr*x`z1 > d.J#j{Z.+3$ߨRv5 YU,:8<)o:4y&3ߥ,/4?¤Xfv4yp[36Jl%X dWNeuϑݝ]!b][<W/BP롳nfv.)K3AcZ/FP+тr `wE{ fKS: kw܆măO 9dɭ]&6+ԥ V֦͟V9j0m'*yOvȶ%)gJh] UD4368@h[N訩ieV؝EiFöϔ+]$ϯ6ۤ <{/DǍ_^C@MMm+"觑_7A <{aЌ+dZNU%\OHX>:MȹdIs&{-2Arsr 5r} Ȟ7wPZNy䲾W7(uQij8f{,FXHMf‡;7`2oC}q79pS:K Q0^T=r1[MrIIgX 0*CC6x"p*2oI*Tn$ 0R\1kjn֕ӺĿd!">3mf * wC[ 'wڿ.lWF UV 0$X osݞ4xDM[xU;Utc*AIYy.J֥ XKA%WQ0 B6νjXyb2el_t(E6/xkyZ;KEe&'=-et xuVr\V;K[r$'ކUr xͬg w;Mlp8{J:ڿ!6ޜK(t/}i~;ڷ*BJ;,Btw7 "4>Y_a<hsT@Kus xO7pgE_|IwO~A/zana9(7*2g+QD#Pf$.ʀlf'G~tFs_:TXhA:Bm ޙB B,.Vl!)Ԉ. tFHU`ll]7)nS%oernU- \QzeSgs%}Z jhR8n4vG`O} 11#U<'WeM˧o&"6"E§x. (=df,K9MM) bc-Vy |T1?TB$oע֌P0z %\GbI!DSo5>lnNלO]h@Ff ˞7uj R1m{AQQu]Rtɗ\Z|ӫ®mFbe90v+PA͝u~pWYsR,GjⱮq6ӴP恂NqL rܝU#D/ ȫ&\ ߔYn,Vh!Ť hR[e[/Z2M8|:6Q/璇va4Jy?s"0FDW1*Էfb.n>:ll5]o5S1!AQ`F5ȜVpZ"@BMO۷1-L\VSeֿͩd rҞ6g*I @"'$pqֶ"~ӭuWeFWTrbDjyF >րX*OKhtLqc oqE_:ZjCw-cb:Kv%wͲ V|[SN{Gqp *ad.twq>5mx,B1Oʑ*YkHkVض:PD0+\?@};@+з)w+%Iu,2$z7ȴ3O 29LDf,u/:R}{ M;#^48#}iLƢ0/X1fCfg8#C Xw.h)Ey#ULBea01)4? s cchTW={!s](BDJQLGѦlޞVS{$CB} Tt Q҆oȶW@ v{sh!!c_D#u6 fk OqbjH?07@/|-ܾh ]od)Ml0Y#;86DʻvY@JcN͢ PewQ5e篾n݋M/ MfR=  !H>A\`އ{L.w!dыMx^l;c|A.WթSi/Dԗ4݇b{0<ԅbNAٌd}V'VI!VGUT,IE-,,ož Jϩ󬹊C5CnSBFCu*_-\I?7p_#'xG$f[(ؠGKL <):(tsgR6'g^=xH mKr8jRӍON7*81j3o0Юs" ? 0S@$"c|Sevl${Du9 a}Cet7y3? 3/00@ ׽ sTfI޴\Yk3am Rᐶ1L!O$xdeY]I^$ gPI$떬L~!D){ml.Pt b,ijDkǔhSh"$K5ep\[ ˭kt@+6+~7W4*(yp)4ڛL &~w{\y(O%!P_$0?s/\anDpq9\I>\%n ٚ#C[ud )#4=&VG$wan}`>H飔KWcVw費٦d17#<"Nt[6ujթVگ2Asʵ[ޠj<+CkRb γsUw-$4upmjP?wswk gdW{kr;Qy *C$?'0Rٌr ͬ-en:}7D2 61{sU/i1t"hҀpM C9M >Eik J;:P<@l/dD)FG/d+Y_ũy;,-A"ݎq  ߨQOq/_X۪nVwd9:V&AV\|cB$ٿQ.] ;ji(<4p @u92uK;u꤯OT*ecVUyQɃErL5IwÌ} uOu.ֵZs]=(& F@و2Mkz[Buu!hWfg؀9m" GMkc5aS"~䶏uτ 6O%jZɩ-[P$)rMX*!iۑu^r~`K,r&&lf@t׮>Ȧ23jge~'\~֗{)owAu2zD keF(S3(؂o_'{!.ڇ D~2Hwm鎊r&Dñ˃늪ZmP N&'Dٯфӹ(ƂB8DJΤ+lYۮʟbǗ(EA ui3x!1yׂzU3"jd`§i5ǟ;Vͧe袀+,o.EőB%1T|Qۥp(,ήҩ.%[,~UHFɅkI~+2E:܃sGvBX[zi⊼V|𻝜!¾= LބI#MKlv?nݳJ_iHw})ˑVQ"%1ߋj55F*d >kl1s6"O)O+"ވda!nۙI/67#(f6YX *cj'tHMN92UQ+ ksLwEk[žf$@wh[%o:E՞W+#5?Ykj׷b֖b"XH"NJ_bbvX6`sTӚ ]S0VYhF*h7HI#({ j=uʦ-T+06jS{9"}y d 9ڰߛM[VfGU: b`qwJW}/ w0+n$eh⊒U}Ȟ5SH)}gED^6{9t54;:ͦ*D4$LvwTſnؽt *هi麣XO:⋣Y<&xitO)T1.|Ap^z#%c[F_ ? uk_dakx( . x`tFwwvѦ]h;ki3;\k pp̖D ժz-$7!508 5piq7'鏙5I`8"2Ds$(w&N,u&]8Z}#NU航6icx6@(lA|ҏvzN77^Fw~$_0$ aV?mChR:W\(tq?FvG?262ߥO @.2ᘃp^'r̕f sԨLM΀}CW;|VXmg9lt=S?{կXc] upW]3oqRcZi6v[,V>m\6o |}|PI9^.hkh|AU;k+!rʶ*o 5QNΏS~J"\B?v̖X$J9yL̬IkaY%>vnuyڂ 0[6AwB52Gow3:/2෦Jb4Ys&kHш0@tqfc@.36 hw8D}4E44T@ӱ>&NgLgZ6Ql+842ޣh)M3xW wњ;넦8*&Ɛ" Jr&_1kgMQj˃| +([yvuΗ)3z"yØt"pA x%#t\-GB5o,gtQ\:Tʉ~JsǠ<s j|­(!K=6-/q|e_ЦqUflسXګ]Wȼ_<>%b&Ys FnD>W 6ay6Q+l?}, _ h~5X?'@jq}kPVNeA2W,6'ކRkSU2 -'A EU ù1UGoxoƜ=|[oDn7%Y ي.bo7HNȦ>i+sNiu@-4Srxgi+i?q5:+dg@>oR% P%H?G3M ۄ<=ɮ|2_rӏd'}JJ5.CzUnGZN;C%/U]ZbGӍw^2r;ZÞk.:G9] dfOaI zYajHuSsW.FDn+$tuvrjV42rf2dkUYc'y S  u7XHmSl:b9\( ʯM0u:`v(C뢽J- =1| q8Poц8 8m>J NҊ;jaV()e/r%iI$M+g, ;aZc\6DZj!aS`)wU:ƘOcTqNrywU/4(mU m# lPCE~@U~dL  #ē=Gp4v$\V|[6O=Z+mS\&1yqdx԰|DaY'iYF6Ո"4ys*okYVXք'M(1\˰U[+R <@s݅USgc rt0K럺gED{\ֈEGS[Rx5IwX&˖^+H7gyȄrc"QL֮kZ Y2 P Oti9/8ٕ,`kj[lٓ:ݞJK\B# _ x'0:*Kh٠Vʛ%[G,sL^v::_hd!O N*w) C GޖHJYa @>nO%wf]W,O `H83}ގ=[?&SK?} n};K,->xgnL7LbQD̄X^& IIX""UTT'O$uPҎY5.:r3HZy`l!ߜE%Ⱥ/ _H Amac<ڽ9Pr H7 S a[/3YHku^N,XM3|?˩}yRtҸ([Nsa}z1ûᲨGM8ar<&½Ci{ƿ #/Nv* (qjW>a]20>^N]w# #_}Ee֡K3lփhC2Re$zVIgxn뗭3IݹODT}Eh44k_vC`-0l* )ǼW<ܗ'X- )Q,R<>A?Cjn316J؇s Zqa>Ja`rZ.v8=Fa6m&?L|O-/{8r')}\׽W]@VhX)C"z<x[7!h9>q}YFr*zYvaJG̢^Q~*WJ`m9GG@ۏ5dc9 ew ޥ98^BWZcfK LAb {sS,Gbf^[yK ]=G5rS¡AZCI<  nʳᎋyNL'!T2&oG ,]oUYC^ 6ګ ^E@t;JӮt<+B@7[(LNCovY.1FU}`V9Gw R6vi5OLH)cEe"Nܘ }TaEۂFلT )I3%őP%er*l8lr%ը܅:'+a=<-IR(LjXT*Q5T]g!qp@;.SVBҺ~gjZoҹܢt,3cڤM` mx݂IkQ)T`m3׽įՓ50ۆ z$]u wo#?l8XC^NxMCSk~93x-CL&&6NgxC2l׊A8D/5+4s!k(ܔ.Ԯ'Eաy!OFfRr=S,.v WV_t:Rc sH-.|e[Mur^/ [ECEͳs@4C4dPqI 32Dg@IN/_CvOˈlS`Ը9|nˢV)6'}ѡH?PԠ 0V>mC,̙ Fh4Pj[IwZn pPS,jo}`A?NRPNIO…T{{ы mPI!gmr۲m&גTNdj)pBduӜ~rqEeub?Ƭ2*a-><<&$襁r@bDֲ.Þslll'T9^ia`p{a calұLĔ {v4\<@f%/yj\1TDRe dNOb ROͩ0&wu u%F+P/Dh#;qOowH%9`*[?,`OzӭOc%`Q{"w>#!QhkcZi%GUi9EF @w?5*$$ʬQ|>m#m=)\[iСRYuv3[9q¯~1&dL9txylVz;j3N9)1зJv9kxq.6jF"n.ߔăzw)OV%:+q^{Ú`p/agcm>b#̹gJ޻ /YhorWIzۡJW|Z^1L˴a;p(BXb̫| ‰'Bɻw;UUq8W.&" Gbܱ^ А6֥DAAX:u5 C|j]ljT ԋСJ(&jc_rxة0;A }EY~Vc;&'o:`9O logJ!. V`<|(sc;;HWQ09Ǻfp\A}hHNeV!瑏 InaI؃31n &R0BeѴ myN!ιxeB;3>/ydm -;\Ȕ*k!1RD룴(-&ă;p~L5l=nR*,Fjo~?k~mD (IvGvgp_t 8K 0A )cBUxk~g;0,¿5<}M_Q"Vh2ϰZTO2sYbQ]Q*\iM lW1{zt?eTAe ~A]Kx[wy4ua2Gj ǏִzI&xYwgz kA, fu~ FEYʘ [f6ʴ6$">1>嗕OtEJrBəW\=1tNfaK ?\5ԣvd^;;X,:2jD3*XHN)[aH`8@O%Gp W+ߥLfg )/~+tl&BR\⟐u/5[f2t [sBAo-zGGqgXiJqOm(j7eo8d;M|%0mSp9kpOAwk5<&)P@*U]m<޹c؇W,hY[,AyXL.?G8F^[QQu"k| ۀyJ_nl'{}I]>wi<5y ,4{n Vk+߫q(I"ۿz_;^ؕRJң8 ގG\ZWc t=HW'?]֔q44$xtx %f'z맗,L8X_C=eqwu]PQtTFa n+nsms)ۼ8c=,OF=z3pzbEKmOL,2" 'lPА5>@=uID7,Y06}Q8Z/#a,qE cO)H@&Uftmϱ˪̧I,W  I ӰfO:O8.0 ΍,k%G#7 / ٿǀMA"ox}x_7uB^nqa%eZs`%̝0cu12Fi)tS:_uzқ_iFt9er3eqԓK<xmF"M's[zv*/4`f츄{`Ek+9z4JiO7c, l6D-֒_*v"G?Mi'X6u4iyk[/slܱ| Sb\S\x3,L>T;25Q2P_&qTqS:`t|OI4RP+$R}!ڤl_YeD 8sS])%fzl4N)%q?B_GuޠEFT Ӊ$-g8q:ǝ߂O'iI? SuX$odSnE'Ķ=-a{<NZft K>NFItjM _TV604FR8?xh-hee l:Mᒏ X#&yy9k,"DcMN뭻zRR' F_b6H'I?X_1BG)nY/ns5cooNT$ ZzkMluya>]pDP*Dkw!P)~aFj:T௒i^y- :fÀi̻~u󉃈mHie?uz-b<w{٨r + .hĻcM6-,컊M}?w8DdOE(QE{ (l FCg 1r;HXm6NFHDsV1mJx4.cJ?1xw Ƭr^wmczv ^ EJvbA $ }HwS}QRlPi<|v_G ^a+cbgKg r}"H#d& 'Я5EE{[\Wr+S0YB—f8_n}Trl%xӥ? F\__o]=B"kZemy1͞˅Ox`(?e™oOk@) G !f&M1u󩾡l@'QIhݡ&Y6G|x<WbL3"_VꦷygTjB*MZeQtFsixfF[~ 6*s|z PJܐ0^{AfɒmBdZk%|;]|GhӔ,U_LCR9}rQN\x80<ʢڕ`qh^!#O\|-"r13y^`{TKmv^9[k;<4{AV4T`rz usY7>볻(4M6'Dna(*7u=dv:< ]кte]cйֱw`lg|. W5 DbA- 4/⅊!?s]_Wrd +0 8Vvi/-Zye{`p2䬀rb q{t h|"l՟{F vlXƜX8tv?}p*asǪWR\#Hoxm}xGoI~W!v ɡܮo9ԛYΐ%/F6h;#:o]!3Q)]עtwa)>Jj ka~qkջbl9WgԹQPw진߅Ayȸ1KL["?t]FHLB%L: Z8#X* F?R~QwLn|cv^^Uj5#緡hܜ p˾)i"VL8 v #򾑕R(o-z o ]U3m/ӳGm˱_Vs"csg%dh#4)csےm.OFqu.^ ?zt3"Omshxk:9WݦHYs0pI1eo^mWǧ2酖ѯKO(>HTJ&RR2{POE?R*\x̸Z9AڨK02&*};0thQQ1q5b6:Wi NǘRu׈ʟm3l @s{tcQùZ*F ֺ ?ϪKrz8|DnNF  s6Zx%G*B0JZHģɃr< ?%ťf)oRF ":H/굋|YFR^@ضZ{,ؓt1wdA&ֲ/{R_qØQ5Tm5t!,co[%x'0x :S_8$xvntCs:? ط%g/v:;2׭k 43 w|CMb +Dpf;ji8*`h7ݒ]aGZ4<#tsOӁ$Fha1Ք/z|^j0dUke(iZ4tEVř3B[AWڱ鷓`e=Y8WrG|[@(JR^2ؕQMyӖx+x;E#aw4yG Z\Ll~h5xѤvn֊rW1{+#fF , !=@li M/;ѫщP_5oo2f)8?&ioը b&?NZsFpi0~Pk`'‡e*`IΩk)L1~r.doVrƺtw8ϙKr`M$ծ|eIue<] 9;uVس.vaO\-2UH{M,n,qy>%bK^U"2Ux|#93F_9e״+o+;SS,:9[u$cel/]>|e(s z Cs*}5kL(S bAOOyZ RYY7˴5׷Cby @x@7Uq{>Uo2 ?_4 \vGCRz/5^*wVTvS'2prRUgD"i" K,Fe,36KɖEh.|]8S^Wf*fI#Ywqc?O3l8]m엕^g\Ct[ ;;Dþ2SZ#g $/o YTs,-;Qd~($ܗ~ K?:(,oSJ6}Ԉˇ 6P  %Z!fo!}C>q`2;YtbЭN[: -Pv#0DI)\ 9he55Q9s 4!dĕg dLڔ̲s@/ ?Uσ6|)<~ ɭqkDE*pD$ 'ԕ7ҟ˥i2ƪGS3:ugDGۃ@2g."Q7ShN6+%fNmj ĢnUp q|9 * )>beڽ 5@*L@b2ƫ- QiH/HdaeEPM>x\ `skyrJs]DzaF MBjQ(*U>x9H+>{IDz*i7-dƾ򓓬4Wg/u1]ؓ3rwvX>6OPnuh^(x $PO&㤖bv;U ×^Y`w=>G\:AxDW<"6=@:Ԣ,ωW8c.Z']Monԉyyc^OpgL#-jZ㪁TM?G7rFK➨/laGRM)EƢY@T_ KbE0Aѱ[p{ p*ƒXRVsP~7UńM][^,ٌnG /OH: fJzrb=)29y`l$5gQ >lfWG P2)0ԖФ~ANm<@Ho @ d< Xn a0;WQzKIv*& #$;/QP'u$ Psw_Y4[hihӃE='G9<jQ`k\ȕ;5"ZIdDLjHC}ZbW3GO2} UBʺ?址r6nεEQ_ T٨JaC e?} q~|C 81U.UMGZR/];IlUY^٘l@ 44Ko?dԫಪrd̐薪 Nl!]ͨI0J1«L!AVNW2ɕ0 ZBĔA*$dˀ`L1Qʮ …dcV)ݮ cM戰gGa4at]m/EU9.oGms&3.a+-٨=zf/k 16v \_o9$~a70Z4( Ve(Lr<[3%ի!Ot[$hrʇ[;7ҰfL]S#+{xO,¨Dh-Z"ԟf[ 0NbD ߛ =[j{um>xM-J6a>ldO2=u"~ǃyw$iV]D'!T{T  %ݴ@NyF%QQ9.+z_BCpPUƎd9aٹ% *2VA_26',S>89Q,N$x!qbk)}Jv, )vƉB4ŜqN'q @FG(NeRM\>]=B3,-~e4 PMTY( ҒG3Z;0*=E$ I&]TXc<=zԣ_)sE~Ɲ]k)W`D`D =,4L4!|HA=M_LY-ZǥLtoܯRGixÇ:}W*չ*j4kG 2$r>l(+  km205fH( ?VxH(9"<͇ӳ9y髄h;C~Tw1e9QljUx Qo;GCW}X ;*%Su46,Ls*dsx+v3-@) 癊řWiL#G˼^(ܯ{Nz=VINqaR jel ŷ,0wBvJg.1 /+ymA=q>}i:k h _؞}/> 1QY`C"ΓR)Ib9_ f9WGz)ױ#VmejvX(֫<88iUN x|vLA:wtnVAt.p "#i!+ޤd%E3&Bq:2X/# B$#YxvI@uBfy U9T*?ba(LQo`1.gR5CA"Hw#s6.FM _LUk5"=\ = \7L>\?c >A,u'tgň6Akz:=2 H΂t=J̞:ou6z{ygO^({(D;~ ?-ixK.e+(~8~ dԺO=7# =\G]Y7ƒ7Q=y&zCEqpO/GmhZo^ sY|]lA㟶]oG%ɫ;3D*Tq2H'V.*4'#"=)00:蓼JJk8pa#wXB-nJ 3 jfn@袬ImmXVOm<'  nቄ?6$ZY_6`OآjJzNg\],esxDaq&m/lrHa.NoFo?g4R]R`1M=#4p;ĈKRp1JRo°d!K=]|*~Ӥ7pbΦk[hHqGQNWwO(^~Q[Vs眱L#IpJg-?]ȿ'z;J׽*X`OX>MF+m4wUNk.-Vo8V#B6$&N75ӈxR^03c񶻜X[U#NAB.T2o7IGvEDN%s޶VVK%ou]9^NLP!dHf2Eep eWDjؤ@NL(ubE+ TCTG#oy,;(Wg :\B]J&:&9\hVp$n[ ۴uR1%)]rW>*8ěq9.eОwe̪mLN+ `^*5÷J(j_(W=XM\dٯ^o|f^.)eBs(zS'5g9OϺ*V=U^d{Àed٘`2Hi5vy3<4*]]kF8蕑!2ߺ9N֍ZپE2n I6ԑ, ӿ6-6XZQ@lS{d^@4J՞e*b*6Gx&aQ-a_ie%&'R3`O}Y3"++ipB%E@b>ׇspxv!W}.b/b8J}I?S.&[g&q=kR&"U/D,~HA'>\uz:L Ұ3P 7b?$ƽt'fR-ccTn,t΄;=>!@ Қ=s8-2m@7?J>gT_DJ)w3) wx\LNk6JNBdS&E$.ԙa8}jz9oRȹAƕJBB1hmBtŸȐԄy}`P P9R굶ض0;R$q k&X"{ e>l>-<$l?rD~sb!A7E3'Jd[$2=FnM']G򝜎9h0:ѪQaB۬짧uP+:\aqk BuATQn88(b,7s ^|W π3]`2e|t; o&J?eRou~,)auiC <Oew5% :Y^ 0.@#DVRdM=/Cf-mu VBI-ֶ`ޜ<=:XTƸk3E Eȯo vP8#M5Yt?^|U.eȃ}hd?קgmEȅӪ'xJwvϡ R`Yp^)+uC>`ऑ@&OKLt @ VM;cʃgHXbϺ2AhvO5irqCz$69Sa8`z-mk)s,G#H5YPRLQs~myJ dġ`0s8.8MSA $ƒ&vńM.xMG^q8 @\^P6mYf8rN5] hɐTY" MvS$e->0BP{~iJ7q, 4x,-K[ڍd{ Y_'TqCV%э[}{AD_1BDqdaSͬ68Y@|-5x)U)8^9ˊ6&į+riOcgϑJ[p8b & л] h;s!H6J!@Qm g:VǞ6AAnGq4Es/4u* JGY#!.s8Nm8 A6.o7xkNV1I&fIFWʌD\?fQ\C)7)]3pW+iyszze:ɍBa=Yɟ[ +eBRZg3^>Fg6\m^xz]o#Q٤dmƬ!w.k[ۏ^$b<:wPx(M'y-$wS5rlu&D*ia*@RYb?DܺS7 1'uɺ3>&7<0К%h%bt[T/+jʝQl,b6GǑJwuawd  ^2a,alFJ%t*7#ȣc(YWL0D})B@sЅe H­1$qLY !m_QŖ5m( M ea7nG>|7t:i]GյϲT[0'Z$f]t[c2_uM>d[5-]0Z],̈́H6֎:i_R ҦÑ$kHu#˂-b Kf /|kH@,P3 C@1QGˮM8W%稘eޖv=[F||>pGF"-5.:eCi^<~XĵkP>1oKZ1XlpHJ5~b;lCu6;lƌwU zrSQ𢹱_EzXRې%(?ȆcVyф+0xk_\ö-OO9rNz_vqYu)8ƛ8ID2s0桱D|>wYͨP`54O Og_%Y0'CWwuP"q9?Mh%~$7\ 2B Z[Ai,[=HCaLMXcKUoKn.Q;2"YƁnPyOG̟uCW>_P'?l0]31 7ڱ-3ȅ{0?ot6̂g(4<jcY^%ԿYWzF"[9ЦUMd^B7GA'HZl'=7nKuUa]v);j:{xєpnfh2[|haɎC F*0lѠ~FUB" u}@!EVDn?P{){7V?Q!ۉApW 7~Z-![$hd>«"ĜB&.?w3{rr- B !\\.0'l_zM܌+ @E5}} T*V6we3!nFI/CUĴlh`jI-V@8NV}?cznz !l;K~{I]~^ a:_3H.CRq- µY!bbQXat}.;On?7xns~]91M/|@Cp8Q$- Mľ *QƠ:p\ElÐ"l)١;K$|<93˳ԗF M?_2g XR+T!8]zr&vfi /qppy*)&Zd3I`Íhf`b'(8wUK;0$_-\J(#QU@ϏYep<`1gڣ'@16l8=ZwOTUV|NWpdx&J&-#M x$)L,J?Vam]`ѤD^áP%P˭X"0Ww9)My39ڞ g^LZ36RQ'sioX ?t !@ orG͊MuZyYjߝgj<{77cQ'gr<1_ڗj0a?B=pyqV]INUs`ۇ\~~ނh4gGVPpk| aJF.u:3jU HFdiuRg kYOG's"ɓ`畓5ȕ{,(<\_ʣ@;pnX(y= CD@QUQOPmAvz~֚]q28f,M}~?E{yA[Se#B^A"iVC$>zyǻ-Q<*%>wz]piKQgLՖɶ'^A\RxLU>=Y=w[^`b[:U CWaiَ%MS<_%24U3&(OODL2-a#ijsv)vdgOGs]/?޷/!qkaN}BGr;M,XKpӃA5fS},Ee-Zv 4̙ BHNyՂxA0bX# ,Q+;vj|?Y?v^Q|F3|j}p3ׂSH֥I ?vٙHBH +~߳bc["n<}17q ~lLKmpfBj?5i; O̥'lWF{LW={v+nW`ċ8ˇ4&t߲~QGȹfѡ; / askۦ$#HH5LJ f]^@Fɓ R6&||'uz1-'6`x_$M"yn+WMa-dw75;1wesScuLuQZNA~R&(bNq?i H TZQY$-!pcjR"Po􇜅QlKbо2Sq9n{o@zk 9s^7]b7C;܁ {x>a[<,w ͮZ.mDk[ǩy;53t)?GpW'V+'Sǡq߲gIw`M_ؖH{'24t A߃`S"WQ'>5_3%0+(S<9? r9e) ҁyůCV3zr0m,Y),_SwZVOU1FQd+r'{…(gg-$^3A>,] ʄ|L" ,N0]-b2h/u,N6Q!I%.|6$Wh6i]/6OۣμlAdG8h֋)4֒bI^.:H7ޒmoQ9J679#S^"4uOƥCfYZߕ3}DjL\]$Cu]LR9wmʠjE]7ZuϹq - NG^ uf;fӳ`5ؑT?i`.ͧc݂ͮkRu}oX[Wq7\unt1ާ:k0'8<ʼ/"ko!J'^+O@bkƒ 82?fFn農A*ŗ}uȓUІͺfg\`\!m'+КIsǬD"YTCzxB-n|oH*#16vؙy KďW6wTcC]5 )yO*byR„B6jI[9/nsȤ4~ZκqJ9Z(x(&:hJ]EX +~)mc#\B. {b=@ {mYCB4Jb qE?M tR|hPo8Ys"#4ɸ$ft|D{;vYoWgKƎѢhXG`?>OߗJ#%jDMw%)hp.Q$+&n}L4alԭv}aɄeVih$$ZTPٲLO[VQl8L!?I^1=hv3S)!ut :B?6Y K0g['ҝ"2Ӿh[^ OT\ a= nJƄkr:8ju8|p=Lӎ4;c'7~#~VVw RE$Y"VY'zlz| " \9"r'xR~S&bI pTxˋWpPR$T77ƃ:@A=6iV":D zIœ/Fl!BÛ>91T00FUfS_F_yue@o|ǹ~QLF` Mя5lE5<<.$q:0/GZ ="$%_4Gefgb:]g^Qfr[PֶZ)RSYE2 Rh-}VP :n&bbB}+죘kW 0(G c]DPƁAVɜ4L$~_?LML|dPK!4SJ\ !:$֣>tL_غĊV9ep2F"\xN!Zb2 R=gϝIX&ntNT_S8&f][+qFGQ}u>#ċO,<9Nq6E:r%09ޮΞk r-|V.eql]* r$Be^"1ntMX&+׻Z)^yMK]\.-|ɒ=!(u&fdO<uc M#nOx] @1"7!FB#ԪTa%)'l?"X)KIbfu_ja|kiCz5Bu SAQ ? tR="Cݰ .XqE|&J~+E+8h 2ٷ RA9Υ'|'ϊA*|*u>j =l0#JyC#N )0$9aBЫy&qKDd=ry;}| T)G'~u;\нP _o'%=B#ܿ7FNЫ8)ȋކR7 \B72S4S(e4`^P0#AEo1>3}Dϒ)ǤZo")]PI"<@yZ^hH)1cc0)ա9o xLD:/՗Ga5g 1E-Jl#FȨew?}]Od{9H,->S?HJ6@㬅Ճ҈[_{Ǫ9fv&};W?x:j <+R@EW4yuUEpJД}2'Sf= cCb ]a v̦̇Y8OH$_{QSl~/pw8B;WXdaXs8TOȮ.'=TN{b\xC 3I8⋾ @*iyA2^fҐML37F=1kq|$r$ m5k3\R @c+ caBYXHzبϋ&R-S0`$g Úoкqx2D} fWM;pG5 /hwyJlM8Rh!57JmF M~{`Krt5>Ğ4 8S?h2wZӪ Xn<Kt뜲kXP)s&*\zmV @Vq֤. mLv-#%VpD/ Zԑ>P&9&ܜcBg @S7c&"ٰ=gYTp Eˎ6( *bmzNO e ݄M3[:y#ԻE=7&so=e6` _b}Ea@Tpfؚ&h<c~*Tz/w0 o@`VumH IȽ1`1/HuL=i'zWGͣCe_A-.n4 z?=/dMxkRR"8YJ$K穐Cpu5QY'Tת6F dO-T+a2[ZN,#Jy{lYB7=^Tbmi$Vu]=ۧzK{@()".:VZ (H+Z/3,˿uu &dL?XR6u`x7[Ji~ȩZmBb9.#L/w ڗ.}x=ĎFl)݋<-t>|6Ύ껸* sVc T=yN#IJr(^FBV^dk3 Y{Ԁ0ŀ+g4 m!g&JmOsTk$%w2mDQ6i">zlF }~vܛ(Hdp𚄌Hϑz IYc(g>gskؐ?Fvη t[sO\A|oڔ&:jKv5x}1>7{Y[J2lYN×OCv F /Y& B=?O}I^MSLNcv}(W׋kl C»2Q9oVݨn=Č4VBM5`x=Xvty-Lh~ka@}U#8$dc3YxjqI9r~~&F#/9#gOe?6މs72j!R~;v %FA;E jBáj:QL3mԢE}Jh'hcBnq--Gus5?F|uJm2t=<*nK+6^|y}/cAɩ7Eh1I,4a8;j=2Ȁ|Vm =9 I֧eІ@58 0 EAd34G ~sR}3Xu*%s=QMe zې6/S2! >3g.}AI7OXFxM=1%}Kl'9.FWiZf0gR(-:֊~>YPt^.w/-rknGؤh4-5 NQI瓼mT׌WlÓ9ӯ&Ҩw; 7a3w¿OxO j/QUckGM:/U/0|货ad_g(Ҝ )xU)} Wjw߾ƅ Xw>FŤ.uD,uHؘFH9ab"e2oF*L-NΥv%}:T`~^Ο `ʋ &я}vW(o3 "YVkTYK}p}LZ|t/vCif3`AbK߻=kwI6f8q܇5 ڮl<5D7(r%TH.ą0'd+ ~JF=SYZE1oazYH%]BU繋;}y&% yב~l r:!9/k!ރYY yDv7_qq(Y!UqN"ޛ COFTY܉[Α/G"bmQ#LZ2%CUH"5ebE /~KXFӮ8*W٥\~*9 ҔyÌDW`J F|Tlbȷ#ãր0VBL9si#.Y`O savŮ`cٴmTT g!ՋJahf13IkA֟\= UϦA+Vǃ]0w% F.xԍ'%k3A#d_ZI,=G>>pe@ jBj綘ȩO~SṈ]\9Muz0V5ϓE$W*nbbВi[\!ZK$ZO94xf1DBr"0yDѣW\e .o%F .U5FleUr#H466I&Z4:cI gP6TD^Тb@ Фu] 2S7׊]N ?t>qz\Cs헳ӯ33W=Tg &߳č*yO4LF-'εs} 58ls 2V2 H74I^وJ9mn;=bf_.^✃Qx%,(L *哳@9;Ca}z|wNbZ-o&w Si]a݅s:6p$@+V`qm~qHEdZsyV0~ԉjy&!OFZՌ06ܙƑ`?$F>&[zw)Z+>n4(un傈Rw N>Z1뭸KpV>RE ߦt ydBHqQP'(هӵjf9J/%!FL 6qst%у0%#c4/66 58\}d*$E#wXb3 XKQ"AP-ޤ3r6Vo­0"zt2 }2 UkNvPMGL҆h.|s&#I\tFu@C#wlc.xi0I뚴nl7P}d`}ʖf#~9}T잣_w$^ʉ KbgTo8%G`6iLhsX3Mtg ki2|PLʼ%qjFIe$%xϾ*\11`; 6h6!36e6`M]0t&vv搱3Y|ЙsPdآ]šbAU*<7 <Rq)rCxX%[}V4JSU\a^0.4*$kӳ߳Кn;gdυP*Pn6갣>%~ ףz~}d܇_qk2eO'ryNؓabmy]tաG7'gGW+_+ja)UjߢkL 테 "[pzjEi"19bV9ڶŰRӿX2炔g167d)1a`25wQ=Y[ϏOeͶ?nx4 o+x~Pe{A{sAkZ$$~^5&KU-XVL43aV~C}]D6b^UI/}%AcX5ЩlUnaM|Z/m;jϥ-ޟ ɚ$}Z80?]`;ɨ =!U*Aő1 N CW$& U~V@a?YZ')wEsc'jud\I緯tҕ oʚ7ܼcv2[ =?j82Vfkh7̃DR>TwTy#SQڗ2f@XNrwءh]T%69ZZd 6,C@B:9ĉmڀq pD5yK(U7M>APN3~13ng[xt цlhT4xYBh%iu=:XS-x Ax̘%zֻ  `a@h(YL-:raP L@PXKpj?M3.,&WByU>.⭮Q1۪SPGJ :cRfpBj-Ѫ-9g[>2f)XYsNV ^[ MK 0D[w, tڝu˰p>:^ [fSuu$e0f$XqTWe *f*lZ<7kYgs쿵Z6)&jp) d1plfq73~.nKs;5BQסbxsZ82*S0l%X6{dЊ'꿟PڞTUg2`2b Dw=ylA܅#z7uF .aq>ݷ.[u2Hh|'M`=w':99֊ߗQK:[|m`K22 2F?bvhDL~TJqlji"$QLߦ\'T)HK:0=JkBCt؆OΩYDl ?Yl p1*wU GYL [^[9U6B}=f(ùw8y[ۭAdmOIUwC8J-X:PiD:FjĉhE1ڪ^A4-Voʪ X6E BsLa2h$o<F7r+Nl CHbz'Trx*D_6[KT8QJs ?B*0Sk6tC *272!=|jd opj1(< .cxuqyUqtY٬ʌRBS JG .G; /;Tm1LJPwfw4>Nb껿=6ښׂ FqihX,gP-=SFx؎޲RWUqzH!#i[hzo8BM=p@*j?X;Jf-X[ˋvqWG|/8Kk,Gsh, WDZ:1k)pwK=<6 j3ݷTrٯ;45r\v^l |wbZg1n+k<> r bW$y+SPs[@6'E?KҊWWhƎ~[JzڔV{A5(<7[EX-ۢA݈j,mչnЌ960*D!=sAfVTo=ڹc?[r!:/"97jjd*.gbs :0q~<ʱ ܮveZ8cY ֭2TϽwG1{m\|2^Θխy1c!rCJ-J]镨2dw, =CcV)%Iy+؍t=QBs}0cѮA}=q9'[h *%1 --U -8r}ٺ·c{}#!C@ gdzYhXn!Uq3pC:goХ MQZB[6Tךݏl#Gk" Et]}Lv]r u9|iGfHv; "COzq"7x6K4@/aKA+exj ;M-8( >v(W)<=QYwgR#OoB+4xI;>d4ܓߩtr/[x`/2W>mYaR%mEϊ`âz%'k@t[o؀ քD2 /ٰ'](f*(m܋=]"R'!9 5g+EVIJҹ{|rv no@$.12cpR]Y=uRiy^q0JGD@: >$Ϧ t=&{X+q,=S,+ <~"踿]lkE],oGUF>eKLeb<^[q)!*ADaV} G'{1p+r$nn0SH^ JCy3)çM 7wϷ} ўө27bt lG]M5PNƉwa[MGcvqsX%GMwX${ER'ufv9l&97q]eF[ fE7Gs>O3&^uJt0Y$:ET\ .Ǿ]SMi7֌}Bp;~UK)ͧ7[Fi|lnI"cd A#e$)9}navNkيEJ[ =+ n rhq`ZSAAz"9UK[ {` Ȝq![D͸qo '7^211GTa-ZxnprБ ~o6o &^|y|:rASFK`x5$FH8h*iGj3ogxM Mn VK:hV"ܐv;Bg6:yǏdϛسXf'rkP-LT)h_\{kup(<Eh%۞w KƠ ;1^ [ж@-.}%a3ڽ?XA ¥NwVs<U%n}> 7\И/G:Ƣh?)(-f6-/Д[Vxm@p;BıwtV(ɽ%%Bmoy I*i,2:+ZeQ`Kغdn5+.шՆ4 W'׌ԗcݛqA?)f췮vd~,{5t^%O羂rPn/!Gv&dH?@X~vI¢k䉇 ~'E|d I@_ m\35vh'.qSC& êdLW :E;xI5n6ξmTgI.ds`MRNmp<5pǯ,/8RښuдQerN};9c박"5][0ɋ~sms~+YGH1U䦥)mp NEEXGd{Xm;Voo\j-qGlHSXւz*(edeeqww>%<+cFѷrf{GG=*Df:|!՚۲=\9#R\!`Na$JYEq;Hꎕ:J?Թ*!=,H6xZA8ޗ|xA&## K҉a2- W^ L5&ǷS3,`~`> aV2 L*ڱ1!F!ˏ^, _\5Me-1>q 思EO~ݲRJbc"rmxTIx;3|`.NMI N'}^'ff{4 LS8~7KF 3MF:eTe_8H^wmk*_SͥK'NB?E$(eov/4.E^DMT;Q73ѪGRN٣y&o +uEEoAwߣm¦ |Dzf{1 DdJbIM b˔aHK|x1ph{-k(}ꫣ(do#Fw1bMΉ= zT^<1=V1@k9 $svRW3t(rPAMwGڂ83VJ:B39Zo^^K 3T׵ ˮU)յLk4aadL(0+@$4jTUr빺'4=LL=ˢRX=9Y&6pҮ6fJHk}s_~L,/跉#E^tFȸn$1nM]ZO^XtcꝪc̚d`'lWPYjbz􀬎[[||EPIU@0h(n5;W IkteB[bǫ>\ Q<|hLd~q#}B8J b)ӝxFY)8u(:!1EȐ߲p0" u9\[ES:ފԢsedJ0KsY:?IIO.YTTU"cj3jk<츛)*J:y87tݣLR9csNe)t{> KV< ƾ3íyRBZW&K)sR-=|~й7[[ʲ8}.3IRjOEtuˍt\ai!Mco|u>dVmIY8#7UߠT(7fW|-1<Әe =Sӄ=Q?뉒ΕwHM i)Ss-23 O8Hq+|*P0ʘiFߌfpCjI̭*ќd9kPOv*=͗+t+S`(d\̪_m?ghzYf֙ǂ'H32/ QA= i$V3='agf'Z?ĩsQ0s&|ȢQƍ WZ_ydzkQ8ؚ A.ʤytazﮟIm PR*n|TH%, z&"[b $rc=D>BY'm[^[г 7AK.nW4 gtV[xkHnAmqZ39he+:H]\,x bv S&0ݥ{CJk)8Ӣ^B`x\X[* 8B s+1L= 7o ҔЗ 0AeLx#VœkbYz R׎дw%1~5dyh|;Um?×;pmlNy;[ɇ -221,닢>J,}Q?%,(\\E'k)gGe7/mjY$iE!cv0xMdnDK L5o#]P(7Q q=>sډ 7OzեNh?ȹWX bY/?0/1+Z6= {p&d+ŔI6AB7׆!ڙ~ɲpMS e\)jɑDC!n?:?TAtx B0a=su\g7J+kh'^NuD=fPqHra~odi%if4(KަrZR;+;T(P @t~'vk4%ε2k Ul.{<%5篭Au^ N#G^?8O\&M/W:!G5{u1v3? F`v$v/х[,MO#+y 5xneҿl>O*~O(XMz\5ADXQHh͞|ֵѿ\rI?ʨ'd՟\Ç| $g5KZ0Z_/%]j1yLxy>ZSNm1ƣм _@C6j)z⃄|-b{]ż+dzfMg<UY'NJ \lQg hEzo;npj߽d x|ӧ O,"u;rzI2`U﬩GnBb_M †N#Rn0a؎z3뺸,ϩʯДdDIDU./^H.W~oX`B!,̒JUJM$t8G`‹j+ϲD2đ3U+7\K66SH/UAwtZ~Wk8}WwVaw Ij&_]`*ی]$K/ hOYZGOx.=xt*LhX]](&D({t+ۈ@cP]LbQ+?娜U \hsgF[۪=olQQ53C `4>r7-=O3~)g.I]|Ӭ! L2A~4B/@*ݕ -*)`_ -R?@?kEZųn75uFݐ{h|uq*a<(x&!"-lL+#Pa&򖬏'XcH\L${د~bޯ߫-%. ܤJ&IT0)w6-q1O-L, ?pUr}_8"\E,y%$\?Wz2{:mWf(h W_UtfJŖs8DcQR(oa7-S*B;>}s<0aq;#"LFa’1w2R{ETl([T%b3*EvB E t!NB5:oEbKzN~nyϫk`z=ٷo Pյ̦˂ `_rgumJ rJ^4_N 1F#is]Ű .fRso8Cy\Vlyt?TWA:T,jxUeHsh~pS.{,T,|,`=zCX4yޤͥS=s XcC7r?=#vA&Ů1m,6Fg Uw\9m+טrU[;gFb %{xG TT.{X\3DiPvKQG !9HO+^XBOyUVFdTS*MŨ̙oxb}{pȫ5m;V} DuFF[ #CYC ^xBp;z0QBt514$TvN~ETˎ9d 5*rB_ wZk_?UDӏOoUaײ67_} 9x&V "qe+qvRy%+"/:*HQpm>F%cj}Clqz\6+D%S+ u7`*dY=KL)gDkRjc`$Y8R<~/)(Pc9fukВ{ SnM|O՞7˺UwM\635;z[]= ZSֆ3ZԄ R]}";)sb5@y,AN3BOd4d)zv]cꚀE2s O(tgwCz f00ߔ2[K ,lF*\hN/j:z-۰+5Ӊep_=Rx %aHMC2A*zb|1״\o*m@t ɾV>D]hc++m.LdVr2Q4&‹뱽OTџċ@Ĕ0AГWA'Zc%N Q' 4 ^/Y[*^+U,u8_oA&{RרfdXُ?Y}a:ECAp!KfBK]6RCMWͥ;JHjx;!->iM RZOsTd_f햙FRg>h L"r;+)|e(,&'#C#GKSw'Y3|a0R5jZآ>7Ѱ7x5bI#1`MKw|XLh,$-ijCPM jРdnA4gJػ˽-L#{qb߶Qg%J!eYӑ3r17+z$ۺhtV</%AT2ٿ)ér+o*^4J7h.gT~)w! Qv 䡫ucpb%UUm4n%~g/kfYp}e}2 =ԚgsF77Nv MJވHPykM[nAFc, WI N<7mA(+2ֹLK4Dz)mSQ tN0t7M#;v6H )5f\xZ>#'7jI5%Y%f*ȣ`㹥9+ leނRA1M3{p/yV rrr@votO`~>?OyLe>9;P)#j^ O^`qL\{Jo._CW `^C} Epc p/%`SP S$pʓAI~j,C#fuaY ILm`|{Ϊ5'#/m4֐wBѢkm맟eUtzN7ۑ׿ o3+t.Rԍel٢"wvJ=b0,t: Φ rh1}̌JN~,!G{Udd3#bYۙԭ`ҹk"lIpiAq bivzunQ,MP;U8 eH^Kǜ@.{ lguRsO ~||nttXڵI%~$CcϮ_qfB gdhxaгjC!`䎸DŔJ=^.W⼶ZF׺qňĘ+.'NOL,ODH Uqxv:\p\ ^혁nZ}jX+?ȡa~L]fN .)RD)8TEy|^\}AAiK98̈́GPF+NG.ǒ#7Xj y3T=e¤*P 'vZ\݈ Mi9;E-0'ƼEqܱb]UTtu;^HL0*ҭ$Du~Q Qk:ʹx⏨3ʛ╾y?&ͬW}Xj[R\OK jt1gh>bu:+ 2~ X;xRLiD;q5;M ]{"Y;h̬2~V ]Q\R qe >j~Xmkk"%;!DV1e^Ұ+%]L`[9'ϙ4OvmѳuRamAs6Ԋ R?vFn"yms.;0e*@F{\, dh'  p/~Ʊ H:zv wvQ[298)I]sl2;6?_ZYry$ jBPl)wYZ*,3_n,T v NI7 g֢2툵 pWdQ_Qyh*:47ՎCU#$U֗Z q<ƘB?dሮXMfG雨YGݦl`?ޫh׳ڨ+b s(ɷvK%w|hRԩ[&YF ϵIOnq5c=|a+݋U$)pĖT8BcDnN@ tSZ;j:&wЊFWSӜ#fo BV5O6g("qOMw.Ƹjx?/CJ2PVrB#fU$h Ej,tS3ǬqUҎh((QəUX۲ :*,Ie'>]=RZ8ߟ)Lqtt1GkC@H?+Đ̀\vNRy@Ɣ9}OŠ**v, #)i<)a0Y)t 4Y^Gg/ `ҟ4_:1O3-`a aӍ N{dq"5%5f+04/M6`NcŷS_NS;cp#?yG"Gb`Nu!g-q5MlrV4@ #r*-hpThNH}z~TTYᐦ+ S.kNޑ .19}ԩA?<*ڱd)pHcY6|=iL\"L|b6?ENd عLO$d9+@<5Xg{+,!)btđ+sw=(ntr ::4QCJ[N)ZodZ.9~0zԦ+Ly9lNb%>X%q6%ԛI?33Qn<^b-yKq/2Dj݄x~ti쒘9EFBӺp|5A䒬 N8 AH1c7|:;xia~q嶝|K?j=\uaogt DlЖ׾L Hb/wEj@,_Je=~bwfS-|)Qܼe jɊC@(/"Kjk;;$J0LuV{PP' ]B@4߫by/tˠtx3Rj`n#qjL<-:bbިK6scrp")bq\1E! vkO$DXP j5۳Hp{=PfɰklectL^rуztoO_hMGc6Mҙ-= SPfJ]ލ cboN;QˉCSHNkgt]ը(!KT)QGN%7JAT?s@0C^)i0VÆyssYLToEF/ U)$U#Eע4(rD!1KَKv;_4VìbnY)6\Zf15O[6MsSr6x(-ӫw+fgai&yZ}RMKłª#.JR7,".4.*qXP԰HIAD.IKOW~LmeM|nMc,mWmVgp JQʅ{)brQx*iI؇7VಒdBv-0z2.Nr7N4ziZyV \ iH4 ~Yڤ uHs dSF /-\h)U@xlDGz-ű ^Ew{; _onbMsʽ^scg 1ZJ@Soz/K;c~W_t/0ҲFt@J#1N bu7\QXS w /+k锶AMre$|Bu(ŅͿ>Z}[E1epi͏:zc(3()c@ۼNH+7^^+JT <Ȟ`̷]Mp^iοGp?}mnGqmTg?|<㙳O"Ymfta |}:E0:ɋ F5)?M9nlVUKŷy_xz|,W%`lK.}i TWDyp>/ Sߊ5_ LH-ohGxM -;cBd+;.ޏM52; M,h?>9rP?][xs[^*"8Dǯ.Z9+_8X\ِ;(7UCw0 c nAi7W_f^SipBU{W .IXI ;IOYsG'|f}OuzԂuo6’Zy5}%y<8amL*C.;H&7JU/X#u.tŘ/7E\ ,!3#EiΚatphBp t nɦFDn.7#檈KX냙]qnA!>Lϱ b橛 %Hu}A / +0p98u cpjz2ϸXbfgi{֞`ƣ*"-.\4ŒY\ӽa%)Z-iSw+,eܪMhlf}pU XHG"?Õ #»4دyum?xKR(C_b_ɡn Ҍ<¸.9P|*oGwd괨}W5Hv[WiAeꗛs1v&&L[_!^޸z$;ݠbDSƓ;*8F(7:Id~&"A }LuU~*n" ,'V&o܀'i ,;K (^j2 z%-t=ll iԶ?=dS69Y^GZF|[KVF4 l,7h]X`"%j^WUh 3D0AQS_y8VӃ^ .BeP]C(_h%Fb2@| EzHS]:u5`3ς ]l:,?H_MU&yfԄAG5D("Q1;"`=gM<.#2O QjHȶ..E(S]grPI1c+vEc;3D2r vV4zji\"#GD'⻡YuMGͩ#j2qP C+}hUm \"vS,Eol%"It=Xo4!Q$'7kLig`=l]۵4y$EDi-DĻa U&xꭓpݻ`,prg SzH<504a80zf9u=ʒl)-|J";n@>ngAtӪR5DJ'т+ )="qh**}n^ r1^R^8id ntLU( ~:YDtwW{qHW].x_T{n;r߂(mQTxҜlt5ƓqO-\fWJE^`"^<-]W4$~Ԙ }5@!v^QRc}rokb,΂^VgFP"V%n{9(z|aV'm1f"}"F= NX耆{o>T/?=dޑTɧ;iI=Vj0_GlhE doaܱZl̑,{W%myZLlY!~|*kW뜹>aT/E ZO ?I N%  R_:o D9N!1*=1D=Y#Eʼ`OJpW?QpfQT/-bKj}qln$DRO])'eiJkS ҵ|xFWD{4~VBq>ް_%ap#4jEr?\hR-'x2 X(TEP^Ն 6l7偂Zc~sq CnK54F .,i9HO.*#7H*+€cj.Hh/cIzqO 厦:ENInR|+lP_1Hiޑ< BmE-Lk|]$q> Q{[">/%?TKCeݰ㻰&oBީ{ fڐK &I8QPmivU3?/噐{{l|s ( ؓ}4šTŒeR7e(:)Ts}{IJ+KԬUW, 54S{Qb0ms 7V#\qOͤ3f\`^pmff3G[5WȖH!"pZ{<6#oT{FڈF ˑSsSiB3eο[Pe0'X*AO 8dBÈ9" hKAFUk]Z\שּׂ(Hqg=1NxL{em0EFԂO_بx|!}Vv!#(Hρ& ű~]_&Ȗʠ!ҙE05O] > Jh zzI}h_^AEB@QI/9zzMVOh9u_| Xʲ,I5>f%8K3gVU&h;*C j/)U+zcā+8eAe1gؼƷև/u#'N -% q* w.l-R`p4p?/c(ؙSn60]S²:4跹􀖷]>qF}=tB'k"ďDBǭ)”nLhK-bF]1,;=ih)XZ2{k%%0WYqyXv]&%W QR%xhQVl3#_}=m\5 Y8s`\cʕ#RW{SsX{:"z&#IA+2\cǷ.5vۼ);T;n\}zICX)Umg1DMʇD+֖{c4F=b&\D Z)D9 iV8Ck@F:u@NX̝M/a¼/A;d -Q ?^b7ˬg BzhV#L`!~mk;:T /bkVLoW&{ө*>|>`7W˞ ȸJ݌5H(Z֖ft5#gT1AFlg醈eޯkk(C&YyH4\^įQV6R4wU|.i\꫽5ΤIJ zY'|a AќLao'f)[X.G`鐉QHuo1y?ӄxEK8?$9MfHBo]]K5CW?gޭNKUfGe&u(Juܛ2ؚ̽d:CF[S-xYԝ\~oE# bX=4oZ4Tڰt;Aih"~~Y|)xqH^C"F6"Wq %eK"B/6!`A%mJ..YK>駖 j%Rw1j&$/ MQI13$4{ޗ:WA=  }PNq]]^/qg$[im0h]/";$i +?lyLyKVǿ05p0hLӠxZF|张%L~RxާcuoςId̄U j3p?ve4̯x$)ChM9N Lg ܷꓛ P WSw 0@4UW>H mEg}|oaPI(";@l JZB2}N.oS 43h4a QHޑ,^is>DFvJ*Jđnj`\$ȍbl(ghX;"ॿ.kCӹ:4V1[<(K%G)R*ݟ}sH#Z{KCH؋[ ъJ ʨDLʒdeMjx\n@ T+GX- k'Ƚ$vD7.垕RUNIԠ_`0 0lme~K18SBHE&s_˛#Q U0αvfj1OpVbQaN1Z(]I{=4H8㷽/0ȑ*W9 bh,=*2mysv6^"V$DBqn@(Dn~Z5K'lbYE0<65鵯rpB*?`dwx忉×A(v @[?0J! 9Tx5ǝTiNHչXᣩs(h\n4f>4 )x̸E]lBVzn'JvbJ?Ԣd2 3ɻƴC!VO,׈q{#]'=Jt7T-̸ |4escjPUӥxe\Y.e74= lYa&Oܑyq "^ѭZ0g1=Χ7qn[ {+U&([yũ2phBCl8gYML䍽I!l1o_'"TA2 >*k&wn_9HQG`*~lzرqcq#;,DT#׌"}ۯ(j}`Ae5uV9Xz]6`. |W*r#yA3n11~!.>qPgnWv_K ?uH![Ķd.|i$[IK(|FRg7dc WyE LA`n5Lq7+|zm!A٬hA~oX V5@4?J0ރq  4G/4UOaxaZ:uƹRl@ΦS)}p6^q*0Dʃ"! N!^fv9"2؜`fuװHlֱK8A%8^=}rt.qI/^q$5%J =\+ܙV/T}L4H[ 4IA6EdR2tKa]U?³ Wvp[?96[:Vﻛ&&,TA3Wu؍q&9=" ˳ejf0H̹NեTȠ,)e:) lyyXh'ZoQO=]sUW?dVGy3@t163W_ ][a!CH`Vɝ1?#mGwz[S9 (d6%XF:bg8Xu">U'%,R JR{wIۥӄpk.{x;0ԟAsME ;QI%oώ:TNu*ȼM<$hOnщ ~:(elZS3_$Zo݃@)t "^Ǩ;YCS8#D0xYNcbժŬ }-$%9ߩh- D駹Vhnx~rW1.&.K >bܜ2ˏ[%xcW.LC~NI?~BJ~ȗzN k ə;\+D]B.;qoťD9_0O QJ&rHS^ܠ}+7n'>t:]-T2SR7pD7KZZ13n~QQ?_.z U :v`T6UdKwḤeɚ;?Sp̏['eeJUx]%Pzp㵢sqy[dS W-8$7M[aaCv,NaA$o3WeGRRKںGZ< ԮB:#Y IGiIao+a=&;2$MbXbЋ (Qqu)&ۭh!-Hyދ?5f#_dau8 -)MԺ@ƠѼxG⍰TFPu6.?㌊,{NEZ_!?,MKO䰖%<x<ue7Hͻ\ؖ<0%Zvmü|u= V#Z7FLJhltFFy,tXc% Tw |[i4-zi[*kLs|ik0ֵ'0貚PnyoYaTO$ x4 hġT23_'W"&Ą>K[;%3۝6Õ41"kŬFL_!g]O 5IY\{'59-=g`XKID!,i*.՗.7YsK5ژ'r4fm{š]ܞ >`H:(*KeŽW,zCV8!91-vayy|Jk'!Y!F%LMTR 26oYXLZ?8PT )Ik}𰒺2/؟.[Ec`x DX$;|κVSuF55Zem{b0Zhf i7܌9JcN)SmuPN[mDLGd22W<]];?h|(Í?Sn澳ucv3r+6$?\խ_ O5G@~ykS_Sȷ졦- 85)9 JU}Te.Do㠳QPo~۬(?!\XB?u#a'$z}Ƽ31 5Ĭ U("TDn!a p8:'j,Ϝ c8tf3\$ÓjMru3 }edm qE -} )k<_I- Da.Φ TiCc?!K4cdlŞZi7v*c!(&ut8ЙxLf >y=ܡZL~*;Y$"Q(Fs.^J@pGqZ i[4+ҰVdu/iυlbO<'pq}ۍwC3`.@>X*t-se Hdҝqѵ(I*G~+t}P&W>/4'!F?zvoc:  ,XB&@BoF|H2d*#_F֍֤L|:?&Jl/'3ƹK!SaHr=&Pwi-Z.G2_z 5VlKl2?(& &o57 2=TgĻ v]6HV@=N۪8w1Mfh,ʷjU]';՛|k3dJrB?dΦDWHEV86Zh1 !B%cT z8/[#JԄ)N̐7h$^}UXI"MwzQjlq_Bme,Rm{geA|Oi!ީSV* EXS-_,܍u!TBܑҔь׺Zӊt+"[3cʄ[jtlW,.$ I8K HpdSd\mSmΑW?:p~4,b.yv7rikOn0Ww@~tDÅ6Nh ]҇(QZ,'/a^pBRZa{7Uį]N3J;-Fx*!:+Nb+-<ヴ".lP &| ݿC|8Ep[u#dgqS }$Fj|f[ ;+{6=^t(,(B2ȝ?ѝA: 5Le1mwCnRdE4V4 B*t!]camjb>'cnS[ֆl&ŅtFoC{Js_V_rܗ5,/nq^cƕ$}4=n7Q{)2)N 9D[ҕ$lr8b*k.ṁ- g Vi-dPHWlZ0 /?#n5t\i.t8lրiS@xm##/J,d!|pfV e.bqO׫ ! qozM(zH\z$\Le[% .yĬ,b/y:zg't|6]\i03VR\LԮjc0u#4V@wΚ|w)kSpz-w8%Щja[s4hƬ UwF^كڡ%;se95C2qzV z>Im wA e{ DІ4&HNY0$ |b]0 N̳!+Efwx> Dw!AK9оzoaDK||vK'3:^~s9%= DQh4wh\YF J9y,"':;ou9jjF@>ypm.p>qGE) >#(X[O<o[waycZ/i(v|4^z7" [6vJthԞAT8tL tSga^Ut捻\^P, @xt5UbKLԓ;>E]F8J8IA3[Tw?)A3|'?ddC_;3&o/UyK\F'`i.+7Wu50s4sm]}aQ4yzD9i&RHBbt^A(w|)Y.htztнh4Wzt|̛wg9qm:ـAQF1߳6Zt4uNlzj6p8pufo(ÀȡĘGN;'KŸ)Z,eV"~Ts#9Dݴ}G>2;sۺz~Au gn7|[@ǻT{{{JUu WCiϮܦ鑝 zgm? 6wU`g j;1W2Ӄf*09sqXL/`_`#ǔ $A'ī4oŬM"«AK<-ikۼrwj~3%18]"-:^'"x UA+oZђn l]s ir7K .PP uOEՎ.$c.1/?+:aߓOvI|il(kqzU:mIă5st}]4B*|9e2N"1YqF6;SF 6P.cj,4Y}+S 9S(HQBѦCG>)u)rIJ^ūe=DX~2G^U>T/S\Sc׃X]K'OKJZ/HrNt vy9YRYw]]G$ya3&&y}{ 6G5<-&vo3md3ijq;1"kJj,q@E't$:sҁe'hgٹ|ԲQťAW;⊫5;TX4kʴf#ƲW ,mEs<9BP{Ţɇ a䴏H'x–%_@ga;mh$NNME+:0~hdžת 5`xFQ_g롧Ɣ.dggHM;^jE}%ҠQQŲ{t$ѽ31P`H.IT϶#<ީ,8}W&e"@&nad3*m&*k{>ӣgA*`vֹDwk:D,Eئqjy<ǰDSbj;hǣ s`d*`B3i357=Ջ=1BvjJPRGS^`-D37.`䝘&K-:BI~d>KK*;* t\N wr\Pn7 Tn^6B*|w'UW|?:nQ~ʷ9j2TXE-4NjfV )"w{JGe#? 412 !3" ` Gӯ)KeHQPt>6.i-WfFkoģ$]fjJ/lB,%ÉtxX<86>E[fL˖'[ T.o %'RntöY9,Z R7#\p(ZHrw)xޫ.Nq}OJm'\Dցpgr>;UH S"Hs ʤծ9 %;ݜ=FthTO!vk[2:J 6KA0CQ]Qz@ЯBd@(<g/C[VzHRVC&ygaM"&O_ H[H-BK=z=B5c䦰J" @,> UĠ{(I\M:$ 4^*|^-G5ݶ" VÏ{Z PIoҮ8_H]bT[A㗛ЋhKahƳnjBzHwߛBi-T%y2Mcx=3ZClG2_")rʔqBJA-.xq"  x۽xrXQ{}U5r Io[s?ҫK&[Tiaֶ A#Vz4 OX3Jc? `c%) đDҼe*Q4Š7Cȓm*v$&yҹ ԟrB[eƻ5\V#L^mۚՙ0^'`:sQ!Vv' Z9"!~ӘfL${l?kh͐dȋ2KI0)Z9w; P=V m?` !+=nhx01_T{\tA&s\_=Hi?ѧ[*'vhlp@ ;evܶ&EG.v0Dq4dq h.ChUD㟃lh@cϝpj,2ȸXR>ܒuK_L&kJٞTn!0)-كyQZߗ.nI.xH9Rvi9pzG=QGa= ! Hkɷo/*Mw8Iz'ϛ! ݱ,sbm` aJ4G)o+rbO l%צZҨnnXw/W}vrf°:LbE4ŽG*Nm=S Es]m$VvLԒX_wp@4筒oTNGż[mN?]:k0v_}gU3ajuQAֵ#Ej2bʡQIرǷB͎Wݱ/xpZG(w-Op~'@-+Xl&^S(>]hsV?aDN~D0쬶 iUӍ=0EN=p~M0]a?igy;!dz_7iԀ/єEkoLo~ \_$i⨇-BteYQI\]m΅'1%RjǺ"Dި*0D="|eo]`7]Џ*ސ $2bQNk1rʋx'6".)c̎geEd1*!郎)O]fN]|lDi imz? aznہKCvR@k%T+7+}D%*"kvR=smhgupN֞!xp?k:gRtq%3K)(; 3/~^Q7A 53F*L3dSB.=oQrIqw:OvNwt7Ӏ*l!uT^^K܄F B| QK~o͏x ˟P*T^$g(`i*Ӓ$]{ʥ+p|Zw9/Ɓ_?|(#B;ҪfSGtX#84w`xe6.˒"cm=>wXI&%D/׭D%[Վ̗m}+Ubzn >^v>%3ǘ??D!p.޻@+iXLXUǫu4L;I"!;r ahuʁo@9 ^@I܈=L֢e[#b0$p{i oeo@>ts43]>|Yx}iW̒Y~fJ9mgCcĩH op>TakLdCgo-d2AoO\7GcaD'h zۗ*ru#y#TZ1 qpe2V'xM *=i z!>H?`, [-$U/ϋʗ_\kz&l}@..N>yK.lW@z߂} B]3 8[> Ɛ&]AS+>59ƧK^ovKd:Qo J`ӟ~RH:^D Pat]twɀ/|v O! ҫHQm .m3k@Y N2&LLAz^IR\ }gPHx^z[zqnHFnΙ!5|xA&t%ޜ%ÿ>t\Ca*#TeVE/5"Vrq#mRS̶+Uuꠛ 911@L%nA?-gyghbbR)n౜B/{6IHf\1ekzЪ>-I/-/e?jh4y'"`7AiGyq0`8Yq)|ɼoF3;dsT QHZt s44D PE˃ʄ*|+7%5%(]5-U(Mê@TߙS&j;*ȗʧ%l䉑DhQy@v>OcW7SdrHAT// _<v5(E?z^~<#4VK^$;X,\8<,P3E/rIf.MABn56ѻ^rn'1M~KQ~ ~|mw^S>!7 ɮ!ۡ"QosS=,9sȩq<$( T(c|㏍}%2Z֞U#J2wnXHjnYpg";i`3lOuZGкQUt=m^< vtpE;3mML1b3׹r[ )fm~Bus/zĻNy ɩ@J y\6Y'g$u ѹLѝd{WE Ce{(#ȍAz?wF|1y@.!uIc4b,N4H zw{up~(-ɩΌw'XM @dLeQef^l.`^d ?⃱ӖE86Şb[nh#&7sak`0J/I!W]N澵mLr ^{PtZZRk d_U%(C_UE[@+pp6'̧=t n13 ҽFP=ʟ =eWhBjW OWLb:^psCkEX2;q{R"ZuV8@lO2m׈k ."x$+a_xؤt&#ߩ&d4fi1Z*K53;`@o!z;9;,AV'-fwxɱ/3Lrju ۴0 T[*$ n/G:Ӭsku  ٚבRKsKz*8*ʣE>|#^wRvVNؠN &K'*Gd f^?hkIJ=O@*'+xb %(XX6qTL69P7Fajn$cGvDžpxڞ @Ֆ.kRS[N\iO Q{>t16ydX->*K^b T'3M/YET'uK~4ePBK _E> ++m6uUb/j(<8kNވ#i4zfـt0byl=j_2QȤՄ.Q=ɑ aACygf>xX#9 TE -#)m)+@eJwvrj^OHiyբWSd8x/I&Tし3p[Qd>g5yrΘ%=FjA9HJ= \?aLW403"s+[g/ܰAaٟwQ\q" &o=T a z$x1&>ŗiΦ/ |9hhB-{HQP@7"L𥡔/A 쬬P#&O~԰##"aD/,"k2Q}Vn:>gj,"WUYZ_w'HdcmFN"D; 2N߭? wnۨ Ov[_lg&+BdϧN[ A,\^~=uBÂl7mdpNü':ll~NӦ[ 4E0:-+VrFr̎U'~]qۄ{';1jg,MEB>Z(_5+&a0&R*X1PF>g,9vNH!ZNkBHZ{pJ(`:吙n኉6H&SPp'j67 3Fl{nU=vWk87SH =u%[" w%UiIkP} ABI5riBv (븮趺 s!-80y#D"!38JhYݢ<73DNj)Qjo]^&QrM+) $/}aG+\|\O+p҈$Tyq__PQ A&3ŤZk,xeC G:q: OAy,\ҷ̥ 9)vcLt#PH. >e]p.'Kk?PqIZ^a"3`T:!Jcrls.c.lǤ]ɮOlc;`%Z>u7xcp沅x%D€M,@ 8ЖC>a\I0)bQ*}>#@p:Qnwu<+0^k[\p*mn | q([r{g/t`xMESWn8qTzīc!,E0AY !/Fg'Ak'1LpfCھ\2\Y:g۬z_ŀpz ËI銠%OkD%P:C`(Si0wN)kyyJ#;OG=h[c=oE=bJ  ?]:vuafoy̯ݹn^;AX1?^ϻ>G<ج!-U/ {alQ׫mgm;Qx+{8l!=Wt+PoEGLuzˆT3] I,ݽ\w}Vbbm,%s{:n,[ n p72 wqr`,-5_Y_[B4Zd o gz;۠o61f̈SJӇY 2 }PkExbɂHp 0s3"Ͳn!.d ~Z]Uh5fj>fVD8JO<ó*FֈXՔ@[ۊ_Wl0"r@Xk J !(IbeOJ CTy^:Nb+J$s0p|N҂% *{@Yh :urXWR$ʗzև bsbɣEY6{pҊ@[;7}x^vV*<c17t D젅fm]dxWH$^'v4g&`FZ96zozӣD:"ZY•4DJEy6c >-$0kPˣsƧTGbJ<ϏX^%9{ 1VWLH5R'PXLVg:,#{s/{<)_ \Ԇm?.\yDKωm'2"؍>fB2CH<DHMY~Kj z//_lH>*hr 猩#0Cƍ_+ژýBbZ"{dE`T ̘2ɚ'|ޜ,@.ѰON*<=7G0$9ɂ,c~OC̶7L%(\ o`|cxؖYGk/y[5W3MQzS(vх? Hg~एW+Y gvAZt#!zن;B1Laa= rV78`#D3qku@).ϓ=\.MBNy] /]̷EYi+4k3%+ ͡mlE^lEU)WM_}/<J>KC@T'Kc1Wu "{ijX#`+?_w3pM>|ၴ]->;^FZTcE_ {0WHp4(ŽeK̋W[a`{S近 `؊f v7T+)}#ߩ@eD@5̈pX6NrU<+K; hR,ZrCp0tNkXze*yk}] %ft$$#N̟ʦiHPLß٫L ;cpk'(?_Ý^Ž?AYcv"jYIΥNim(U^(֞cB+0]E-ڇ"1E5ҷ@J by;KplGF9dInk}$t]ZR9B]i̘ɢjsըD`'5xyKA; pl*ЌH #d+wf+'ڴ؉3UVCY'yBeT,٨*^?ChT& DM8֥+X*mϳNPEwr'r7=2? NT+pPaG2V+D%S?Y$%:pM3_8%2;UG@V 1uu>Mp9}yR]u%əR1BrH^RW<TpEF1Bo^ #msT%?z ,d6 zဋ$ES𶳢N%eh}KؙQ6G^4ȳ\*\B%u[`,_>ĬLB}E5^]Oyd cZSR Hhu'c[eBKݭ7K0(HU+M>ANI+Y~W Xvɉ , %ڂC W|v7VZrۓ.}n0}Om1đ8@ *|wmֱsÁ|ϔ7HjH [JRW( SgCh\vQ ."N6@di++ &t;[J.)b}a|~⽶fC4B"ED&C?ϪM/G5;>D2Vଵ"M1}K7ZrvXK%nB7k͐S* vTR_BMcxqZ`yPR?iQGl x}J<Z%omtIY3++a:@GMOG5 0gR}fXKHr/i`^MZF7GmڶڎrOdcХݨlzhVs1vtl#\3IIyȹLeާZY?ud<%ιD3_ZyM|<[_=iXP.- !['r%2s+"\" xG`vX#_Y7%% }7T}mpJR]U}A-,:f@R:A:)D Ъ/>mci(>n|4ib׋ߙqBݳ,7v6Ol"6\a'-eJzވ\{.;15֟9#F}䎠 ~u1,d`T)xTa_%r/|'Z]K[C(,J_Ā{#{uB"yDbꬔw;-,:eP>oB{bf=xlziMv Hnز-}44y6~4?LLk>R|GFA Gy7_#[ uNOw6.[uX&5U=d!k[ZUp(FݴePQA*}Wu{Њ@m&'~lٲ!JKz-I%%QxgݽTK-5ƣ50:bc0x勽iP;."ɰZ$lt|Y:`}M B2=xaWBV{hù9u|x5o.CPя:Z}jO05%Պȶ KrejReY=:6\yÔ9\OD?2Ⓗ 3ь}qړTȊV 2AW4vV[c&Z@sS%"W;-'u^$UMg2;xZ:k Xfw;KoC=^!% nLz^GB i3$7G&!n_bo MWI3h}0vzx'yz]q NCu!=wun?E#Y@D\|WwN1_УŤ2ԾXJnWNSiBfmW--e{ȮJ1G%\zLƖ{y{ $N9*h8ʣFa 꾫?g.!*!3AWĮU]s:KD'‡ ȗAhXcp5tv\xZr!qrFWRuޜ@O1-Koݹ0{ɦ'm"/CGE&`oK^z2SJ!bpH|k,Փ'LEUc(=-(P _3ikVԟ4s_2W\ \3fN=CҎ{͞d1Fk8չ h.~.LAW; g-ڑEMc4JtC軆zg<ߛ RV> "D'mI_Ug+~`_^mל"NJT Gt @lCy2 4[9cG^b2C=3y+8ݜB74?v諸 ZaZ껽9V6߅W(du-g#MFp+3+9Kx@aH*C2~"M暞p\;88l&%[:uxۜе$OsNyy,=Q#sgj&^BrYrJd^*} !̜odU{dk s{V9e<]| "\q:kMZ#:&#_^ ӨoZN/h.dtwkyRWe,l]4֑YM={復e-P @w[1?hƒ2sOryI Tr2a|k4lGa~]i%4cdp9>BlL_`Q.`kV:B 5y~sV[Oͼ>!HF:,3`vԜPX/kڼ4xI\CȂuH"j/c1T3[69"aRs,\Pxؼ#U\\wBGsv0t+Td&ʅIX I[?4}76s,< cp͚`a(a9%1Iي7?CXH[$+ C "JAp-Ȍ~{xcӀM V"PS9ՎQcIu  Dl\R~}xBkC= y㩕AUxRO_Y}J32xLbaתLz([`ˇM!U8*rE?fqэ^m83,p>NNtؿL{ܽSQ!ԯ"= [)|d3˅k#*ުG ]0o77\0%۠ rr't}hS*ڂթl] 54֌@Ӆ0kڍzqt4%̌oJVS`Fv#|".rP}JDR+ȧ&RlR )}]3Gb!-`={xq1*8BZ*Gi[]ٲ"`,_>+spy_$M o{'ϾֲOSgBx$'s$klC EXLe[w6/{gH,3l)D/+ز[D#tU`8/1q.ueo܋w'@,]gxKnRogliHiE Mi-aH=Цs ~X+s3; ÍHǍ/@kbuc3+Hfz1RfȰqVg$x}IBn+Υa p|'SUkkaWġ-H<M9:+v \Royĥei)OAWSAQ,>jtHA4gmG`Yen\{ lֿDܰlNb#vvG>xy~fYF{̓B uѽmM&!t\! #h;Be)@_ACRTVwI%rMg ^e|j޷Y ͺ߲8?xڬyEL_姿@7LORrPc]]%puqnS4FwG6J2.8&fB s dbvx,H_] `ѵ(0e:`oïP$Sl,DA\a!I OpMP-ށN&$.̟iO# e{ LM-vn_@$Cؖ uB$<`( ,= èkWML"))]-خ: _|mGӍi3<dz: n~σJ{L> +7# d68w~br > 쭐CLkE &8Uf3,Z&s֢qT(8cZ^2 vVz,_Y j ĂJ97z|WL:t=pѡ(!}[6խL8e^ ûaj4VGV.Ơ"cQH0 .SjIY4Gm)uu(>ٱg Q۠Ͼ.X4+7y\t=X~ nS̾zvlTzBvVTaIzly&DX/"=Nԫ UtNy׃\6ȁJ(=9~62A.9!^YNM8,'IP81ik .c2r"HeyҲ[M\6,^X]1Zr6rlr*َIԹя9 #9 hD!}a;-ޠ5V׺CuJ3ø,WDgc,f} q?Zݐ>$KBIqWȃ䯷o2rfT TSycd& t=}l%I(77^PeȅL9|9 t}+ Y&`n7Մ+!r-N YZ