sssd-kcm-2.5.2-1.el8 >  A `2U]G]A@VdZְ\>/E4 hU&_4 <Τ2!!k`4G9ۈt>yK="Wh%Waǧ`1kvOA(ce+CݻkD B}iŨՉR_ԐϩF;yw3:T8WGCe^9`g;O= R޵S"QHzQ;{dj)+ O6Ɔq.f-0;QDVFƊ~z R]3Ν :+"= {qNU=[FG|{htO7u_l=.iL_e fYf[R}&!jjYP:* CͲNԆ0I/H19;OI5D!#K7 F{NmŹ<4n{!~+{ikos}QݏϳǾp[̏A[֔!*lقf(i}ò9f6ca151e8bee26d00adefc54bec3d81ba48dbcdc65d2cf3ee578ab364a5aa983a92686d2b85eeacd7dfdaed34c7e476cbc64f1abx`2U]6hK5ފkQg";&X ܒmE7#}Xq;u2@lACWInΒ*wVFE!#r}?%?g^Ee27~l렗kS/f9x6!Q Fnώg_67Ӗ7"ş$fAzݱE뽣uVk5VT; wGcLW-A=qFXpCgK d UbIO/".h=F%e=J9rovia t)ƨ^X/?qpq)Ard *,lS?@^;%r{+ǖO_0`_K Ja-b;`dՑ{AΔ_pŭ1JiUAF[D!֒X- ^ ZaN?gdN3{?xG06 [=hEyi59ߗ0>pBpP?p@d   B #@FMbt    j J,= ==(K8T9:dJ>g?g@gGg(Hg`IgXgYg\g]h^i bj dk]ekbfkelkgtkukvkwnHxnynNooop<Csssd-kcm2.5.21.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.` x86-02.mbox.centos.org5CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxx86_64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi,%0EzځAA큤A큤``````````````acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8b4e29a574d0d8fb18abdee833929707d2486eab2d2c21cf074496be2e7bf9dafc7160506153e0227a1677fb567b8146034410eafb459cc8c79cecdcc33991a75ecad543a37f67d58f5a9f539a1d9939751f87d72a3ee776ee25e04bd493861fde11f423eaa0a346210975e2f44e4d663e439a92a07b8190d67fca995b6355a044019cfca48df77ea06dc2029af75d78b4e8b134625a465a88e85fa870a0866259023e647f560f509c57b8dbcc1a206f78561cbb45842c124143f34c2ce49d858acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/lib64/sssd/libsss_secrets.so../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.2-1.el8.src.rpmconfig(sssd-kcm)libsss_secrets.so()(64bit)sssd-kcmsssd-kcm(x86-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_secrets.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.5.2-1.el83.0.4-14.6.0-14.0-15.2-12.5.2-1.el84.14.3`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh svuk2.5.2-1.el82.5.2-1.el82.5.2-1.el8 kcm_default_ccache.build-id445d47b03efef23b035a031184b8e8c79d5ccb6d9dd5c68832234ae6b90e2efe3215e14b53e52esssd-kcm.servicesssd-kcm.socketlibsss_secrets.sosssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/44//usr/lib/.build-id/83//usr/lib/systemd/system//usr/lib64/sssd//usr/libexec/sssd//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=445d47b03efef23b035a031184b8e8c79d5ccb6d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=839dd5c68832234ae6b90e2efe3215e14b53e52e, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)1PRR-R RR)R RRRR!R.RRRRRR R"R$RR#R0R,RR%R*RR7R/R+R3RRRRRR-RR RR R RR1RRRR RR2R)R$R%R#R&R'R(R RRRR!R.RRRRRR R"RR0R,RR*RR7utf-880d12e9ff6ac103445514fefbbf8c7b42c8048e4b546f9ce3ec6f43f3f9e5b74?7zXZ !#,4] b2u Q{LQ wF|͍8+@P0IM0a npv!ûߕlm Y=N^p3<.axsk} 4;/s:wa[n B2 W>^V/Y a~AHw~#M*ntU#ay,@h}e*S(=U:s$vi7LoPNzq,2gl Q@P|8cHܵК>iy6oXv `xӻ"Rz(ggS7^Zac{XvG? I©e.#rZ=-@w"e ;,M#; ʲzѸZ_d]zSiWb#/aC+Ӣn` wdF>&jI>]2P瓸s3tel!07p<aG{2]5 ӼkYHA+WMXACJ>r˂/F߯*V/9ߪph1=dMIi{*KDXEo.'Դ0Bd0\3ƍ3#]3]浃ޏϛ* m'TKeRLZ"w {p/ LR3Y+SɋP!FL Ѣ"zS[YWKя3سy nVoT_PB(Ԣlý;i5ߺe.٥ ށgeV ;p!9FәlGL]'IBbSw冄pkm~) PN_k37ex%X^ N/U¬L~Qo.mRFJ,'NN| %b|tϼ>c1~8CwWhw4lҦ!jDQRاG+xpYr[~ <@9Y0 u*h70ᣳt Vh՟V` duՂl? h.`SFqUQ!AỾC( m;FA)e+h7%@,lhK ~~QH$ :-)S^v.[5%-E0JN!P&0hQ#uI ?X†g:\q[v4}~ry膛3=`Az:=#$1VX !s$7JM#m_3Fxwb=U| Y;V'яj8T_mlPS`a ;ļJ|?vҚ7 ?+z^=n*SГPÈ="{ %V u$/,N Ʒrj7KHqMh01֩\ݗЈ'I/ii;F'S_76QFi8cKjpjy!"ª X(x4ꥋx{}7"`#9A*e#)I%h/! 6a)+1Hz"4 DZ^-Q{ }Jܡ QL51$J" ?I ⟖yoHHZy#|Ă F>֚QU`)c۸RrQ-Ebm_(m ߓNᷘMs`= Xie-en4|ڌ9$6 ,xPׂԔC91WH &]2-@$X~SD e^mjyY5\Vk7N @nqp;n}my**?2%xio!wX\G$0Qd vN(Ռ1R.:텓a\S { Q~~G%bu YBܾ|54r=h' D߶4aD1aT6] |DIT&ÿWBa1H=!9zPZ*Z  >f6meV__b%fA@6iQ>&U4*RsS6n Q&fvrĞWvf2v"kh+z sK,fsZ}ڎχ04ǖ`QwA>O^? YҿAoUe~,[N"hM_6~.#̓9gm[ڸ7xav *3=loVK,wU"pi[@6܌((8bDͺELog*1:GY'\ RCL' f $YBg/i^k; IJgפ&ݩPk"&1m/u !rۭx|)מ*l)'eZ"xƓ=K}~v%gz\s9,/qDqFcٞ6>&^LGZW$}(++5}[赌aS yʱEtD@uRWz2kp&Pa!Qiqr4,yPxeB_@DgV^8n~4tF$AjfL?vg`+ʥM)ض |ZyE䡆`%*N)d~R(D2k[Cm@ l9Ȉ  4 1j̫Y XonBD[o`$Y>P}$l?ʟc_tHzm;.:SAD㕎k؋(vltpzm+,݇|Y<>ً߸5aE|w)0JF>M:4i( K]4-{[M6AOFyd֢#Ya g.ˆztHVkss7O,S>  Ι='<_̒< _ BoC)l\IV7$!bq vZqA+h;} TiM0cPn.SlKa|vC[ cm!1qU8gj~u@uM>ؤUʆj< ZAz8V6~V_E1rbY߀׿pSamrbLqz|U׸E+1:M"^3hntB[ދJEU.6&Ù4A]4AH~BǀD{W%iHX ^6 rMɉo9cCVٺȖ͂Y6 whߤ=3YIJ@Gw GHGuԍ=%`WE-16 T2OsZr!c5AN[Z#^jVbJ/V$\J23"FCV3脯E>W{"md;ԎkV;Ewcqf6H}.8fH/5a Kq!y.@V!dsҹӺ^Dus3k_xYHy}fJdɀV;Dsyld<<8T%R.:#0W)=/`Db'vL\"8֒rXțⵤ@.zyUvQ\@.P1IxN 5=?L.|J_j7'WvMi7K}W}Ru.“TZ) kԎ E>ٚ)]JB%"aD up1=-{/VAx]WwL6D 1!''e6R4O]#?r)mE0#4ouxn ]p`-Xh[hefr{ 'TG}x-1Bԛ|=ri;*`kky?0uxZq)!ɪ-0wD'/@=*8TZ+LM| ?'Po.;IV(Qm+BU`rN+7ch"֧ʛ׊^vjtf180 |01 P`nt 74jz}|qu]S}Яuo|F*Jمy2/'.?UfK8\N9knUz:0$ÑB6*BA[P<+aBXT<%($2ݲ^=ջb1BA>s->`XIe+8QS_Ex5 Kc}dB&نl'ړf_ РT5A`ܳ.ߜ&kۻl(2\&kHB@#wА M41ѱIWM C"*\.65+%SW_Lĥ1cpSՃO(dzi v>K=.mq.:AB ; 0Q <;|*ڇ,Ţr eȯk Wg ȟ1WnXM ,Wۋq7{5wEig~IݲwANkS^g]-[R3z/vekl1w_oٚR$Of04QJBxkc#".بXRGۃjf54M3tNΚX$g\c }zpNHKP.oO# T}x@܍mTĹOy簝+  .mAђy=9*3v>DNn!CȸW%h {ĈUmDR<"Fq@C!7M4/h*.ED5_vDXcza-o0IxɝEd vlr`FA((C%l`khg@p_V7d\t4/ϥש_}k.TaH4㰚nFz(&{BcN>)rd#vkw0y,>M ESr8 Wl2[%ԹA{J!"?:q}R !4_(U};0CZ}ޝ~395_uaYG ,9jobg[Ҹ޴eTs IMy ywC;%l:]oF翌1SD9sx[!Xڟ 8~Io-Y&\P/3|OgWlhG0szZ8`]XP6A܌hT9Β=߼8EQbH(nF7s94<쮙6ܺօ(6m\F@}#P3%9>FF @&?ˬs6SfIq',wK3怎gz'fkLYyM|ҜoMnQkiϛ9J2P[hui{xׂf HX)9B!2_;ev]}z]@h,%_8fpoS%~m:Ў>qӺ[)s^^gz<zl # Z>\P5*7 ءS5jᅫKQ\~h$* ŧ4>X2 FC[(  U-e׌J7$n =;cUav:oЪFJ"ڶ\Ҏ*O0ibgפ4,].SwfTَc8Qa+N\|shu򲏭յeFS},XL_\^L/h+3!)4@Pz8ˆd渡R7z+g|K;BQtB9!Ef|S>h'0kA(P;bQQ: DbUWh@W9Dg ՞]iS2{INSXVn!SbSȚnso;44aZ~mN v\pqASRWF Ѷ3 zmy ګoqCRҮ|@'4Dxf@pJP >¦]7[Q3".:uVV^6a:Aǭ7@ya{Ҧg*ќTd/{Ie*t tz盵35+rb!Fcҭ8̮y~hjAmυtxy(jBן:T-H+CMNKbc;U\ȝ1;.<2iskaY}@RQ (~ ˣNzoeILu[?Q rљ>zvxL^Jqtm[=@A>Kx3 *hb37lNVulH4 G.Ki+W%Vt(iF9>/aMIdlW(J%Cn)-!#3CnBr6-id*`$C!~+`aY|IζOܮ*.C%f&W:&ɠhrYRkv_hB ʘ߷"jzkN:& :j45e1]NqF/<2gIg9nY E,\&ӑ~ӭ`h(|PBꅭAxtNpaS@qƖ>͖s+eTC^*`zmt^*p#1|BRT){$H '%0KEI =<&Qʕ;y'!75&܅#4Bż>mrdwZ0@vO딠Ys^.3 ka7q<'rZJW%`4fgw(|n+~X7]|iK)=UZV Ҁ ܐf}91iQ$MXPxC2> D67ģq+w"Zs&I QwجT3Κnq҉Z}09id<%(ΞCl1ƹI9Fr;u90b)tl)4Cvfx5/_DO>(M e0zLͥ 8?P"EMυv*S#41Ţ!rV<[{wi6y+t s4dEiiϐ~?PNs/f$ ͻJY6RR )u@`a Y:L(s2(49 gr`#lg| TX9qbgHcMwtMbvKܓ7 n4rҢm̞ʚ295RSNKO[9m@׫U2*4dF(GOѫ`8N!̷_:($?'f}HoPs&IzS;׺!ow1:/Ojx2uC̦Qٍ5*ۭ9KE_H+I| ؆"ydG8@%{|}H,}]uÛ7xk \U)̯_DǢPo\C%D_U:^j'GW$¤P2ƹLXY7V :T$69\AnߏbPyCX.N p7 #+ ޽(&+`ozLa^~"{zw#Tq8 i:lLtg*YZ˰!k#g7P@O.VD[6n_FMݖ31.82Va0ҿ'Q5f*sD1ްDHaN)D2W"gVg53tX&Z^2Ι,KO'YƟ`XpGkÛ⧀w7[X|PKAH$:\ŕ2 $)8i 3[\'9+yLzG-vK`a`Q{Pw6%2J%U_1$Br ޗ㦿 s)= QD$FbWc|+ evPR_]sރ£0ArMT Hg̀~HWuXm2`"YaS iy7rtr#?Jrx|fEAnhu F3@ N (meKkRQ:O|ͻ }KlATj֔ }s`"'2 ^53|1i&βЊzLعeY$/O{j58GPxYG vNTq;yL{bOʺ n_}^rd83D_7j'nd `({2O)TνrHkAI/鋰=y8tUcJFδ?UD?_)n\;m8oFal#jB%=]A3JZNs{Rd t\UM&U=W#sRJ=j:Hv$5 hв- b_jbb{%wFmz.iX  i/Ql"SS3CeE\\<`۶. j^ w ]68Hd})^Z=USa32. .R݋yFܑ?`$hd7o/ܼ9`Ʌ"9\OR3@cd@iOGq2WTHƶ0fتjsbu4bS1jye>19Vၷ%9u/ݘ_J?Tf \-OM*=? QıiG`WQ!*Uy[?Np p\_ǡp1Bw"mDźG}HO5ʷ0)'Z#@0oZ³Oy)ڿ,piBj'%´d/U~% mD؜kD69LcJA2|>n_܏[Z1ڍZ簃KOш{`b;W8aҺjTeT^ ,~< TYgkz7)O'k$9J[$_0!4w Z' f`iq=:iD>-21e7oȻ:t_ t7K.TP[{M- {#vE#azӓ7PtBCA~2O{(s&0+ "YhIIZ;O9Fw_\&~63F6O]kbUEt=.SӦqD\Nl䖕 ˃ Pf߯<"#y3:PbP{ޮXzb/"pwc' |TmA9#,^I,Vb͏#UxZ~yuRq$3PlA^#ZjQJ{ղ `;nO^cAć~(xDC8ztA9@OJ?ABX\PW4AӒ7ؐP(va.| 9AG"34zFzxԊYq~%~Ch"1eeg0FhDVs()H?6?d'%Pv\&.jb%[aaa?'̭`UnL4ʑlś*: SGabZT+>YRe_dKRw ~ſs$ {)d&?]qW;g('uVB{YV gp=%A`*cQ#! !q uL3 GO6)şcEBeKEJ^th}qrdSlrX+;@'>tQlO${w[zx.E;mM4$ p[5U1-~x6V)֮t1i5lƈ?=A}px0[#ɯ7QF?@5+Sxjt©ϒOAH#yS<^SD6Ӫ)*G޺QpjXkTyϜ1SY 2y'ghAG.c̜j2 G5*JNS\  /JXzP¸a< x5FQL]XEЮ'AK6d r$3e*'r}cqXDK s~̌h] 4>r=A32#@nʭ5@KulFVmtbf˒nhNJ-wDYj % z(Zb(P09)n6s$_= Vah%SNa>lllj Cr83eȈ$s C}sYϰUH5L3a0Χ$k1F?F(:%^t-㋯u$CxJ3Vt{j)JӞx j]ĩ{cy.⌲ʜjsM/Nb\!9r%%1䚔؁EU "0C ( L^ב NlNo']|UGqE>β5xPEE'PT'Z;XߜvzPctE )\)WaH#ApS02<Ԩ5i2S>:D`q,vۉ!~(bu%O6%}BI׳Rpm>Az[Qu|& 7LĖ>O<.X!wkg$h< 4],a :"1oVz47vx%D"F߉Z"'t H(fvgN-y..풡"j 9 ޶ԙ_JpQ䷄#l {T-fvT #sc<*^! $SA3jќ jbL'%L1zr^b^sHujtFTk( f!5p/(Ҏ%]v-s6g--X5!av_ 3Ӎ! u4ՉP@)A,ưRgkhl)ƫn7M (7kvzPkbi. [^ש7jSQzZѕbo֙b,_j(p~A{Cۗ"ƅxXO)uLsTvD?e GƼ=C47n`cڅgϙS9\ownF!Tg*˝#Ts^V*z&:eR9Śc>l^5pPخ]8 cX]ǏÞo%p|73TzQHQCn<'b _BZ>z9#!P;ټs\(Tbh|KRgJi8ɵ5s*=˿U*Ql;'ڇV^ko!V8y& 5.J&I3HJ%(ziCO|wb W7} w|ӆl 1B[^to8!T]޾{戱 C~ ~ϫZ5w.xM)=0&k=X5ޘ ҵ抐P"F)+SIg 9BJWek4(E9te[AԦo9*鏞AY'q-S?[&|ho LN~9U:t̝1];y1\[]7ĩ5N};u~e@r)xHV~"DD`,iPؐ]6fs'c`h 3iQ,Frd`%nEqےd/NI/aqĿ3}'G60RW`2_o{4 S{ghFx!.{kThyc*uAXWR٩oynq ҢMSqɿ?>=<×rN8zXB;j1cE#z\3H Du 1Naٮmk3삿Sf`@1ÐlH#acFy̓3ӨzC b_!ML6ǯYͩHz%F~kvr^[  |KmNUPE5-%`U,S%t] y/6$7C'>$Lu'zڤ[G`g⠃v1;Xz%' 5e@.prF֒CY{a:mIwٹ<ޯt\ll&Wvv׮'\DgDiLx*Vu샗-P2' ${y}I,3<$ 8oO-O":/͓nټ;sy7$?s>M%L/`l ]IęfȱQ3FњwGyyq7= . It|K <w+L7+lٸ;X\\vSZ}W9r]-h@515 [Osx謊mV>%*i|!< t/DA\ЁMNZ.of\OLď(}3zȹ۴Ǡa' #ڤ' qtABKt^JF8-u[HaR$.q{]]YoaaW&X8{ TrU#@9 t>[G:w/cA:eY HsL8hSU}_- dSVt &brv_{/ oX/dﳧ+#*߷u--'|,^!F HOC%^ v]۷D^ɘ< h$=My qѦ ͽ.ߦ2'3v<0 t,LsqmfaбĈQ1^:Ux;zl.7-H2P!$LljÎ'~c>ί+؋E?,ۇ|C14-d90꾦3Ჰ.He {)P917/-#= =L$>FQIYՃ0KP{,.tnrPiǠv?:'6A0z7Hjv艫T6#lDuuYiJ=hb4%h.`0l%{*X@ڽE G.-8iQ;^M'r}YG(g9n$Ӡ{9(i5(l㵗|E)&(^Y|⸳[GD|rk''BO~ O tL41%sB J@*P +aAZzq645 >ҋ:B;Nj2?HOֈ3[d_?$`AE,ZV[ϛm)?"/}bRF\iCK^ }-ӝԯk'P~X"HYa0g5 JG_)Ȓ"5wpYT_hW.q9,  IY>i"ѻx-`<2?})UrּP G妖%7_|"dK`% Yf:dWL=%,ߛ Tyҷ9%SsQ]{pEؕsӿz)=u#p,3\暍=5 (a )\Yyv|gߜ4J_yR+X54`N*_#Mf"t._r}M/2:mAXaaVBk)^( >K֚r9FKhq{}GV< M, ۂGhS>YHHlXo؊ϟSeG=_B2x$I羲&1Uh&2fi({<%dQ5oHI݃ qَD%ac/\SU6pT+-ic<] h}zlh58OsC/GE+"& *߯@_.j}@L*SŝѫoW`%r7& :yJYEzB9k#V _=SK 2 ,9BФ[VÜ0,>8}#Ѩ-x rܑY;\}XYtaAgA@*Q]4'Fw ed˦Qe[f'.\mĦ1:fW Towrw,2um_t%d9yҋ;׺7Zp2T(3aqٚy㐶u]!@v جeǀ.Vdj=g&*p%M1f_L r]6ݣE1ɬ[ML5e#A?D /n^^tI{f%gײTnA&x"}w1r?%UY&X8l ^?@}ݩC XqPd'Or E@Yzq]D]e߄.)3LX;'k0nH6FHF /OW6q"+]Mr{#z'Wn1<7B6WGB`V1{ItsI80I?wJy'>|YqBL 9̉;דF:#r.y2Jd7W{dc-g6 e 7QzyG{mc4q.S\C|@ ٽsȦhi#%)>Ei4?&Ckb<(FFkx`DD=,F% !vH5{h,YT23K/ ; tqa;<$_NBjd8jF'x"J:n <,TFamPV!w : FJpʣs":d|cM'G༢=-lM KG˹6k+g4aC`i Aiׅol"h;D'hiypA\BjviQ4LpLFl .Yݚ~zbRY[zBLJ&Seôyj'R m/i̶qeEe#qtmJ!2z.Q,&ݷCM/2:U'0]lEsE> nab0+.|Lt'$n/TJ2@̥)5"+,֟'3~?֋ar+"9G+%'VdG|OL\W_6P<"X*| ;4S d9CI܃O7:8 y4ֲfW+k],n\"leY 8|R;JKxDX^Cݝ'Nܴ`İ]1 Xwb1w՜i&? T+@y!̒sldn#W+WlgT!xi/!u-"3*!gӒ>ܰUPJPo$%Ӥnq6Bj-0:XqC/7) {ChÃL@X~#2:2듋 t~PIR eʼnJ٬ 5.&ؙQH5 3jq)[͍#*mz`٩\<y%(x^|h~ҎUp2ŵ;ZVs{캚Ffe~a;-KqP#8QÐ8隳U05€ŔLeZ9afFO'+)X%qtbk.=8[mə %G}<- * B7Cڞ,^R"<Іڱk6D'JЅ:;G/Z_yle'KU2kJq ]VKZ"$-Q41)j \$[c΁m~4M%SwõOJ[:خrbދ)xC `*wmNRNtq SX<(2(´_M}.@|T8woKJ_Wrӯ!` )[SWgKQ7:e+,$2Bk^lR<=0xIcN`4)0*.QG´l{^VpaiJQ!@lzcԙ 1)-^\x%17jlǃJ-q,hE![u͹>FÊ<#b-IspHrܽWZ' VFNlc=5U#&r]t)bU.ݗY`Z*zUqTG[])F45 @wl}Ɏ2w=qr ,7M. dc@L9I'hju`B`>q{=*՝cv5( з0!`|òpma%C+ GpsZ Uwv|883Ӎ XȦd|sp+|sas9-fbd oWf"soPZ;C\@u,PJ:Р7!xGP?YBq]b鎄h{ʹyLm A6p3\PG 28NT!pJdAhˊ*zh8/D6B]3mRC8(It i xߐbd$:'#hk=gǴ 䶄D b}=h,{tu>N=o=s4XqڲeQYd>k̼iv(Fe0"vąSN3]M_2ciq1y pN8ʟ2T_V0 Oۂr5sڃL&;RsW :/wkF0$hJVEJ[ы)aRK xX#n逗H%P̣N(re=:|tecFHsW̉_Lr*bvaV[>IN)2Br_n+P@X?U:Xë\ :50shl~?d˜a +E[SP5~Ue^ ƱH2@VE7[Z6t&nԯR/dNKm6ջ) 0&Ƭ#->(19?;&&"u^? b_~/:9me=JUs.|$=- f!QChҁrn+ vl4Lo͙Xo?F0/NI}p$`.,^,G!bHM F=7]G-! P/ຂ6k*kB;\Bmͩg,RlrD{Mp)"A`THL~3PV`rJ0/.3l+8/ퟁuc^ն@aUM2=1uQz쯒3 zdڳ973sDTJW.q7](&nW(a|#k5?{cя[pN;. ; !t2)('V׮;*k^T4 (auyxmgQP' p?f4H' UZur%SrHBXI\o@dj!wrnؙ>ST6߈nq wy᳷MoD؁(B8 ͊,QupuT.em\<, IT]TaAxһT*k/,ޛcE;6=LO#{L]]a;hVi&-~*YF6(!iYЃA%nī!w[4jbJ7"8DƖCLy{< jSn w,ICC>y/19Y{TI|&91Iɯ#` (7#4ن9Ԡx+ hZ;ᲚEamFHk=m3"ƚapA鴀6o5e2oEy+ej"vl/Ł[/ qEVx7lF:x {MQI-U,7Q&ˌ$v?.% /8ߛaS\. M#ɳC%}Kxuis<0fdd S\h6J;R~Q7t> HCRed Mfn'x_TIp!ـ>]/% a;cQg{d7`=U F$qfr̡.чr(G%m܋ ;Yף ɺᗳF :\l@%:cy/4 ^&6:U *.1dwlr,Yđɇ9#i?tnX;'A-\v@#ٲww9k& y0R#lf;fPV'`3\Md(6 0E_1N(I% [du@JTiIՆt5m#4,#@49:Ve+Qs:}V:wo3Q8,3-^(EVj{26PQҥZ;<lͩhW\xͨ Z͉~/"wsl^:,8UڜKJ3?Z$G5 Qh zG4yNnvI,|!(} .tN"S$F3eeʼ;l.jRK(xAՅEzealS\egP $}eN$88ߍsuV땏 )<4'x{$ K/JbWcnDjd" 1 | @̛=$NZ%Q  ?oYnU NVw!/EylG{"2I|&];q.^q_@lBN`_L5wmZswQS#D+wg(e8A*O R?"EV}Zr- ڌQ@Z:q&{+v@Rv&hըyeUOtx1ٸ# Fߴ7fv(4t`dj;X; #'Iuq)|9Ӊ ^oGQlWu/70j5t;) /GNIg 1KpJp7^!pdHI V\RtQưAؽ4[JaATAox:-棯Hg(/]Ft`¤)Md ZhOR w%E r RVgffS+]+js ]{*,aAHDDgɕ!|\ Y.ʭh $QڐҨ<0O *ZRpg54c6~`Ue۲j9T GJ"^_٥R`۔ \\W6hv,T]PVuu1F($?Wl.㱾ri;-!ֲaJ$tP}b%Qk ['yw,Ep(Pr8ʼA^4"U*P2 r8ZL*PƯ.ۤo"xՁ"27jz(Ru *ξ. W"AׄSI UjQ^hxL& \>V$[ř>3nȊĭq1?T箎m-g 0ڔUo?xjxcri rY2?{J!VBѾBp7{)(FǞeH| iN`JJy S}ndr (2(z AMPJDeM\ie3­p^YK=N^ T}m1$#d80'hw-n'~rRu1bTp^@'c"DZsu,+kq;d* s PAs's[wJKSxn55tT;~gAW,l< p^Egk؈izOMt)(V۠Wd)XVJO8GrluB:(_A| -\2}^j%ߗ/&TU[foqc%gR @v\۔(;glWPqpovo.?[v~2\|A7K51XfE_ z CD 76v03Wְ &9,sqJYX8HrGRA8yBl~/&qO>%ffd)//+]{E3Mx@ NXSrطyKZ< m<;O촼a$Vރh]Z' +e7b؎+5 5dx2  Ae4" HNQ|J cEM֋m)>8 Q9j|d\U.NʫQϜw3ꕄ`*)2T~{@=+AYM"!kfK[~[/oΐ-ieuMf Gw:YK.fZX8 hvx-2dz/'Ue OP~ wfh7ʎqc;Nl[M8?ZR;Z3FaSt: W]̒;Ii?=f`s 0(]4j0Uِ4VCbs {,r¿aq$*pv[ZP(hx4gL0sw/΍[UE6DKY ~{Ny\)<@y6[i7|rad{J]de nZtA0yQ)!\2?Nv 6:B`85M2˸]j)(k kabsXp.7}ز] ߣRޱ0t.c{0o4j=WULτaоՄ_L䅕7g4gq5lϋk4v9@2 +<X'\8,* klu)!>RIKFŀƄXL}YԽ?39'*) A\ra `l"hƔcG)VY,ͧZ^8FgOmw8ݶrhi GE\C4 lxȍ- Bo?KY{Q3Љ 9^i3bYoiGqzl,P@P"V\˦jTO6OA9L9OJ]Y|] ?Q OJ%4jr1ź\1.xE8O?R\)] n΅(r-V-YI V4&?7OC, Q%eYC|\3wf/ץT'/mIx7lQsB\G_m*%8>D`" BFUlV7ořc-zrXߐDN.'Q2 Tgzh+Gwa+邉JAϙlmҋJ2BX7˰ nB߯9@4(7i`@whNG@n&D)ZGuhD;8ƀ>$2"E-8}٤d٥p@]C-*FZe+ƓSq`rZuw!Q!20|)|ۼ 7:Mb]\L*Z-EeDCb#~!@I n,F/j-JM?:iҡRYYΙԊc8ƍsUPjV1Ucv lN[W,2qՓ;uSְ|b~TV5 >)1R 3Cv 51{[osIBH* $:^$VZeEd!谟 s}!7c,y/xΒ;x*H&{G*r<tJjA>͐0LųV*q[#7l#wǺRawnܔ*b|DVWkw{ݖ41չFZ ڄW=!YLX%_6*j~709JC ٙ#TV,[|\o6LwŸ$;W;\JJPJƋ^NtbxPGuʼF3Ubj5K[q CcDuyt`qRK wYbKx : =y~l" ';Hhd ~¦)2H*j{$f^/򭧐7-)sZ`)1K4Š"{9&]BTwu*!#)NP3;pt5y*<)4 `TmRoۑVV 2<3 g_jIOòS Z@EFG40Eq2ȀD%FїGq-jzdKvV`ոl@}e &1YP^㝏w6T%2B\(ռn76olU/T {(⮙C ) D.EBYc>^; X:ͯB82rda bVݪs^t(iAT}hWȷ&5 CNHq{{pjJ ˺'4!Q5K:\VICuU^K,T|ne}FXA7MxЈ6s.޵l }7W/mB|җR^pAC׊[ED:y0tUǕ< cX9۠v_W /pfisˎU(N$"a7z/!10=+aQ. HЀF?@i۫\3z2'ϒQ-|u+?9خSuqoT%XQ Ƅ{ k R#,.n!!k]66dHٕy`kJlLJLK~vvJX`Z~AA( a{ţr|%hۥADFu i[^[kNJ얥YὛ};JRGݘ.g捬 &Gumؼ-.*OeVa4='U{1O@[ъw{2Vkes+y "6V ~)abӘVdN(4:4ڝbXt6FzRgB>_,"JED6SbEW83H7v~RMٙ(f6eey?;3002RikTNÁƈҌ\MCLuy@| 1F]ȶOr@ĊTx}Ps! iS9șM0=9Ʀ uoD08VrAb裇$1X81Ҷ(GW7v/uY5Q]ȓ+x'jjs!&fh [8Qb yQC3? 2!T2 ;ӟ7R[sdɆ>γPDXY뫾u**{R.l3 m"*sE;N\';C(Q5Vğ(sߜJŷZLiM"<79" pՔ\ Q p]ý ٜ.kҘcDQN=S\n=;*^l;k0 2^Y@YAgt%s%VaQvu- (g咇 E.Vj`:]aR6(?X4Xv_ԓXG:8_l 2_|Tq^p̺A?MZR98HxE[7}AAaҮG(Hk$'{bkuIhY.;s?,Rɡ"#wРD3F]aO7ȏ@KzyI/Nٷ!5~"VHƶ)2_}1;Lo$и@Ɠ=aG;XE*{lP/c/ ^\i;8wU Oҕ 4KxH}1/ p.nD@'7ES Ac-I y}ue x W-ZVʼn9=l~ag0XB:_~рt8AjzS;+wEh⵶}0L,j^뭿;k-+yEj˫i[RY-RR,jT̓\Y Д.ՅcɄ( 8=pJ gpua|cLWUځ0:sl2 Vհ8dI2@XZ.>wi\ԑSHPB6J BWL#F7AtHΐ|>&1pOcډAt5wH8kHvUe$AܽY鯭)%-( s?X\N!=T^<%jvZpTלy~<|UFBRh]f7DfdC}ݫS nbwmEf8)lyWlc78.s剂G'xBhkޡoeʹI=` 5Tt皳c/tod9{mqkhfEITƲYȼ@WzX[54]x69[U>1qA:mJvf7f9:}W1sϓ"*|蒈kB^HlW " |nsl.g!R0ceM"kDzLp2ՏVdNcb ^ Ƽ{uRgjIO͈^|ov fq>:-v^j{q|8"RMPl9gItiib[<ݥn-!Ģ[EzҴ>UnN(-N1*ńEڠͣ|r(c^ˊC馍_~6W՞NA5 CX> 1&&q'B4;f,D\yg b~3RJ BDkoE}ްI~k~ڵaHJs zU$(Q'Zj=3/]LRh}-pj{f7Xtn?w3xu)^lJ%?daӂXEMNVUMpxx%$ Lc3|*dbw(xiЯOCq?F3R v6nʃH707y0n:{=`XE*3l.s|v iK9ʓg|B_O8i ֪ :&u z%]aʗ_8oM:j{NȤB ]|W%~,d6L%s hS% p4JF]$f,h2X#5KOQ:.0a5)LB|my7 5L?Rܥ C{1)ڋ%go-זv?0p433F{ƀG^/χ[JIo p4_>ИDޢeS Es ^{UմyS˓qϡ1N X aV-^A"p@&)Y0II#=J)B68ZoM[$%:W9ϹeZeip8̓e?eSD{z `-<4ty&ࡲfP;k0e|o|;%7 AGX ]I)kiXdX?Nq,J4mm+窣eI/hwA"2<t9vBy!H7_s%.@G{7Lo,}r'0q,ߏ" }c=SΘZŪ~6g ,[!Ndr-12ZY1$T kKT9[m&\leG :!)A 73%jTL[Zj6*u\TkDJGj|ZQxW(?gS8offvsz)UjwtZݠcSLwy ?&Z-$'h t!jd``_,mȅgԐbq_˶-8SVdraѐ2 qM /|(Z\f.}!k!LZ/MCy?>@P-8HO݂U;Įoa[~h5myn{!`iAQP`~0r8PX߾4Cc="?z!2M6\Dcq<c`) JQ`נCfӦ}iQBnqG7siiW$a ;YTCY/PǾډ]S]g^;gA*i ňG"f\:@-2y6-3^A^gGC aon5 kǤyu/5dŴwY6J#;\qW  ҰVbflce, FcYC%`:I^P_#n Q,Ҷ8Zw|:T@ܔHX#&kZ)P Xq.F=ޞ|KRU:"Rw-e8R\"<r1]r6{g Ehx£ٶXCk3uvzvbHv&pbmgKƸr4'.oU?tRȚ/wgb4..6xiJE'|pe^ |8eYB#n{ߴCs95\9NZ Qm8AV3q12zƜX0S&gֵ+b񳗩.D[*LAn(wRj/+ UUoԦ9x__q)(!/V )3Z7Ğ G&: eX9jjclYU]Ҕˁ 1_a˖2ta5UVfC,V!<ua3 "N8.rԷ2j hCAPƜ`-ȒTiIGߏ{Yɜ3HXLͰjj֯3N ߫lRi@Iҁ>40wh(ρދ1?meʗG RQUGGѫ< g6aR|([߿mMf7qv*F@{?zA5:$ooxM;U-~X&Oa(POњ#+n@/LkMאMXz2;TzH6y.׼$PEE $CȖ/Bwdø۶Jt1(-U%['mRˏ>M M a^r)#oZa,i]kx#BICoM'\vO7 i0ncoETk/Y l-otڷÞc?{0Rw%5eSf9 `3G\f@TdȏS(9p@#M/tC|gݣA9 k)vK80@{ c|/"ok,,;/5` t:6!` dLŃŧŃf7pN݇qIX  'cTivUo8s \@A*1MSOX +gn:NDkg{z%zʾ-9'qDU`~3#~=fjY+޺m굩q8QҊRrW怣%j!-_)Nva i[\Ƨ?LRAtN䔺S%ʕJ,z;0W l_]1҄2Y 8ڢQ(61CقGɃ`ԠY)yTBIb2NٖT\*\䑑>`s˒M_O0z ȣυǥ} +aAƯxnQкdEL'5jkA)󭫛#mxg \P-}O '/s^o0A vRQty{UvWBxfߖ8oľ+H~ΜΩպ+]Ou YEv95)#SdK˱-@r *mUvŢTԈSXa6mOh1B+Igfr(|CB$Eč-͞+(;.ZđҜ˅.A'[KRܟy}]= [jcvz>S+Qx= 43W7lq{=9: K!چYh'wFQWRjIlzև+'u*wZ6|XeX\HD㘾#*"=.pr!~D ~}/]?ZדX!AY2nl w51װ9Bt@ O\:لp_ZwpǼc!zϲ=Y0^/̿x׸$ـu(tAgaoqjgsES;a%'baHWGF+2z'enM$@gfMEd#@6ϥ:O族=Q6!n? 4g|4(;*Wacu *m7aa~ ÆꕊX7#G8yRt:f{^.7EB9$]x@,Źj5A~Xf6C}pYQ/-60e:Zg֝.%քhvJ9r`+zkh||@?37:oH;|/YK˥7O:2U#f2gU =#<y "|ˁ*A;'S/*϶xLO䓆u%񩛐)m@SZ6!<9ߢ9/(0!BA@V}<'od>O'↿laB@(>\ O R.iC7_ju~hܩcF"`F;:ϝ#vIT4w Bf.a&" 6nzjHj*$ww4S[Tu&Mb EF!RvF'0 m x&(ўGK=&_1,Я{2,@þ;&^rorvwc ̡J+Q-C9AhjZA }VhaEH`\[lF{X,az^- Q211 lQ nybGgSr =6rI6/w$2P`l"7,B!k([M-~J. ƍHlP`Mg44̿E-ɸmo2L[4Š0G[]izxK{ᮬD\8Y~S 4J|٣PM0߫LD'ig(LMO0wP:vaOAUI[R9/ו15,uyD.`^N灮G=Np8-(X'lIG@v!Y*۶H~]EKlONv5[Y$Z)@cC[3`xe,fNr{hE+dY뒂~U݁6w޸Yoa9bxR2⯙ፎ@:8nA u zfQ omFU)>P:*P-nr9y2 #бN0 *nVGa/ ,l]CRRYj"`h`h2vTL=t>4Oʳ{g:jvܞG tLph`p [^[t#-yԥ _Yb]sKn0U\:@ [սN&y`whEh9VSn_(A zx5l[7Ŧb<.02y: {O#/_HV\ lBul|E슮PtSEY|U~̄wt 8;C)4NJK#G&۞?St" 0bME!nHW:}y%L,4/GSnjVDxlP)0DXVA.?"PTT|b$Qگ cqc!!CZ o a7FcˮJ8Q"+7zQ,Y:l]=?˹vI6T1J:FCz[p~ܦ%TߡY3(虙e+Yg73J$$ -kP _˾id"/z\E-@8nɖzzT}ݫSGw-XgDbMR#`޶[`L#C@;ST-4f+&s }! [!h_r шfv5 lJ~E\9pµBc'/{!ƨb<8<ܠU-}?ٛ͂>M MP)v w&#aȩ#r؇`y/ي.KwtƼ _&D*~:jME_@_D`|OzUxyu?+w~izT&gCEL3ʐ^Lʵav[FMi8>8ode mԿE߰Nk=l 1dj[l#z\b>?&4qTP@| .Brew*:Vn˗=M^7B.f@& t(dZ`݋"?܄`bh7^i`?d& 'V{Zng-.@Plt8@(m30(4%P\ܠZQ~onĺH<3TkoѿȈ)aƻ|OZ GҪ؆VRSKgQx2OQ'?׾yWE &B.n.?rn1'=:7ٙ%x ƓfG֙g_{%1t9>Xͦqla AGa2H6EU@ǁ3 _`DDQ]7v壄[uè".~ٜFt?tF韗ܢ3V ׎kp0ݏvBGK&~:PTv,G=8ţ9#X 4"dVyeц:a5N^ ܇ kN<h̡t 6p||z"uU0 Hs.hA6YGi)%l륒^E=ӕڛ"DHQ(AX d܅hln|ڎqBQLkE ^J:Im,xȞߗ⏆e(r9,MTO!kV/–R/-"$fK>IF5J] ?yb<ϐ)@iaƿޯ_$]?\,@PCtNy M32wTئ6z^׭!C٣uNf"Soeo<_3jDzRDZb4>~ۮC䮮 z"+J~G5gzm:93>P{bry_A5U0\ޙIf=̟mZi#y-> J.=;+(5 agw6fbkO X%QCi ;'x TgCX}be{\ f~0;(* ; GX mP8u3U.[lŗB.xf]LϸS`)_lo@+>gT8F/a`eJ%T:/*_Y`H+iYDW~w7zթ_c4֭UAViz}R_[' H_",.ݓE:d1Ƶ!7=1n!_xA] ).# i[L4kקߏm&\DMF҃hPM79й0aSU𯉸֯ˢ} N +,F[gA%vBMd=bDLτC:0D{}l9+^Z;ĊU {%ם}d n5,?[va[)zaI?tg ΋&*yw͎doM»xu3̳d*O, TPj$rf dP?p)DBmg8U&S&֚{y|3GQWd"?׽`2g gۆ( zZ6a V\!k6(]A;sPT{AѮCу|^}3WEFN=KlT %\ ddR_Ks) oM 3,z"D!PX'݌{ҽ;͝ @X~ʬ&!7)[M=wKtAnũ)<6i* zMOO$D08V Cxˣxn$eOA;?,9q,RWxOVڕ2T5,yWQ1=#P_⍋zSl_Ռ}iE0VoDpլq}Pg+aN;9-rKAVB\ݵ=BT" ?̑ga('lSowk`7%]!]EYW6A7`0k^6|Dd"^w乌\BDm JQRxόW5Nb& rr|eUcG]* jWDbgly R9 ]ԄP3HqBef dp nrIB*k7vY 4>;SȈ wހ84?!Ogv<@qWa?Yڒ9$E7^GOp?).gye҃~v\5[AL9x} Cr~^kP.RĽ5&~$?k> &~$@m09ü-A h׻yz+hzoOVViL>}jea ? %ki=`H{V湾*ɕiYL;eKYSݫq/ڄZxKo-{ =q/Ȃ}m66ΰʳnXkK'4(ld™қ^CXvmK1`(_H%7jq/Bq1wwǥ,t gn‹<^ 9[;K.5 <+ ZI<1Zޯ*b*d.As-LCxO2)#|4 .C-Ej<,&?FAs>%iWeB?:U:0GWٍymHh)@.߳4DWmNρ*WY:~⿄y<sSݙ _%z4}Bq@w&[^68ZpH>D/dĻU?ӌМyfSIɿ{<%nJu &s&茮L]NMF.d._Z5&^6 Rn*smLrt*̨11VgYY4ۧ v{,=ꎾ`\5FXJ-Y46avtg Xkĵ>#]lE`!8y#ژs9JՙCrGj{oOgھ0F}ۛ:ũ]Lh`yoeB /EǀӹOG|i4O cFwVJ2xˆ9YcvFNRYػ:yY7"pxT YzĦƕ5 3?8P'Dz{#R*@XbdO:AvK f#*E-/m fL:q6@wyڷsl 3_~ 1S{G$`LA|̳]8],NMbYmFDs|Ԩf%<.idn=H.BQBc_spvg!u>B` KZMpFClم4Hf| ̠!y՝L>Wƍ/^O͇x `uQiX7G.&>n 1buU22t*"]95[MGSM YVA|"[Oy^5; C3D_);_w-V$s'G@(+Mq3dЈ|(}Y%ynh^: (G!^ UA"F(qGQY1y{c>7ȪAlědD {^F.!ծ@w&o\і#LZ4{*>K,w?d(ua̧2߿нTmR|$]L V"iPi^&\*ynSQs+\Mf>B-M{flR#@p_2[ ^B\T9uZhH!dyǍڵ In l^+foLvU"*+[9q U۳%tuN'Q+Pc?vD&@c>odmbl3;8gԙ-:7Pji\f nfnDt Yچ°KAܲɇ.W{9L.ji0qIL-^a0-u" #K F#З6:H3`0\w9yٺ2{V# kF> Y΂o%൅3X;;8Q)>0Ǚ TutP|+Gr*DįU:c~7RȠYaoSyelwLbCS/0܄ [%ebljoo^O-A|!>U M/ts.ƧG8G5#2U@hc$o| \PG4fW{B8 +IQ1*4ue $kG av*)فдf(<1TJla\Z6nƋ݊QU_֨ bF-/Нz*Hr˻- rL~lvUV?S6pl7cZQi6{HRaХŽ&AUg7 t?@e|8-0"U;wsVwtuˏ-fw;; Q?G)wʜ[UjL(bpAtPqD 廹rm$)':rIqecm׷ "Ħӌ1O?~E]Xbo}>^G&als)2͝62$ e;%Q=$wEPz|\l'sb H3Awo4v/dž#nLJS0&vS\,Md$FDԾReeGuI 犄qv( #N#sZ/rqd5x=j3E$ik`P=؃[L찖MS!rV8NX0/#=䉛sג1g8.rESf/6Zk;F虤|>KHA9LHeL@;\:_n{5څlM-sBɺ&͓] un(&8 kſ*51*9꼘n@eKqf 7Y-xfc?1[q W BnPu"HJbDxVBldTf@M?ЏyM֞{7("5>1W!K5 ^0FJGqި9DImrVObi]m !KDKcڋOс923Xqy 42ͯxAY1鎋TfJD.rX#4P B"?zJǕ!sld#KDKֵ2[f#~6Ҹ7=nMMW-w%b?EaGٙ^i|ouaثXt4ב8"I*RNpYS`>s1> KuD01dE*WO2ᶂ@Mc3OhiMIm9/!O2Q[{G_ЪFy?(5z qߊ IBv)E"|6 Xw?S.^xRu-Cl0mgE+|~ӗ }g~ .Bfl;R .YaE#8،$ªtU8]8y>BՙQpk%qN\[O\Ȱlޕ`fu_gdсPpfЎӗFD:L~EbF)Ϊ[9l⽷F }"]5pμ\o6BPjm=o VjڃfuhD^҆|X׶Նht:llg?ڼ4nZ&L_m偱3Uh( .f+!`"GL} \x^9C7ד8R]nnYϖӲ ow%t5#Yd9ajûV.w$".CZ d齲*BujTwbn!9(vhbqp*u^/h`PO j;YcY[4q7ͳ`D>Z魒!$6X e#:$ܕa S.z?E4qb.LдWy4unJ H7ӳkNPsLMo4*A^h<60]0o?e>; jLa 3SYg YG#\8ClS(Y@j`8LΩ~9kӪ:$r'}B6|y%)@Aj@ΎM*^o̞mbϡ[hr#{6(]nswΛN”M `!蔃Ӥ}A#sh 'f3 mz^.7,%йD-Uq@y*c9aBbxWjLH5lgxHWrsD#w[%[^& 2ߐKd-zt<mO%z g=`&w{1?i*'ôk QU -B;^#ْ(OfH5NG}qu/QC<[WSɪ/q\'oc %ōQ?7r*_q9ĸT9Fq \`vSWFS %ҺuaņDj5j4j)6:W86M vPJHR Uu)###R%NoK+MZFѺ*҇KPW%&V?/{fWÂ.f:^1e_8J3)4J*!#)TD#lh\U.yf3iH)lG!s9vVUs:>*?╪_y͡('}LNkbiTjearK7% %QK-5¹x2tR%lYT>יU-cK~SқhLTIR`ɞ[2nXjb:@!#l~o`=Te"}}ǖ$Xtf>i(!*/;b@ X^4V)Qaqx Yc"u}sone> ܣ9g|}6tĊ{tCnFM0n^߰5Y»v[5|ɚTr_EJaU#hjK2 Z c øFDq­N&4p%osf%LoS1O(faPPPΟkFyZȦY"K4;1XL} eQ\ j._tGN y6e, Gq?9iT0:*\T"Pےb8x#5Z=:`1ay hK؅ GK.JI! xaf ۙHvs:q>vzQbN{8χ<8_g LňGx$UJ*q:bt|dWC>_l[ dq"i\3^5乞okp fYWQuL69h5x V;tav0/U%ACv.>UF={6.?mET`W9 'iEVsGoA+eB㿭>hfiT[9Kj&})<[QlM<ӔZI:4v_)wo+cG2~uj@; 3UdUb]I8\JǙXX/xÙAd+V}#s`>7F =&!Xp/vlj(ql9f?ZMԹC.'n]LL4q*5byt7Q)×W-LdٖPHSQ]a3{I͹kot2.#rMsLl` 1 >ڱqۯ9>4ܔ:P݅+ˆ,4p%\m?K` =[08g_-Bv1+rH#4|kl:Ϋ#E >ʚx rK5 Akc'=rNkF'P(QJgbՙ>MF"r#Hĝ²ǯ7/%>>k<+$*(CD@+#\)k5O26$Em& w)m) ,5ATw{xЖ(H61 ^RU2GOXM(U}"ͦn(R+hc)h36mcOhcRG˽$ϚU|!P2Y%Kkt% 0E,:'[!7ijBavc\h;~[^[D\3]y#w7NRJ(ݹ|7Y  ߐv.*`SF\d ie0B˱ډ` ]Rrdr!gO9ifY9fj='8as(vhozx_C)s/d.䗸*EƲ }juZ FWd491c1Mm(/% n*Tw*-M9a/RmރT)O9ѻbV^Kjqo\7)*۠zuExJ,o| 1C6_,!=8w/Ҷ$UϩZʣpSG]N Ӳ5g Ȗ }Ј Z_֢Wy h ,R)^2Ǹ^ɗqxڍy}P)I0e>F*.WDф(#MShgvHKlBiSgm*4`҃fTQĈ55­w–:SS&`V,HrOʤ][1 6|f1rSr o~RiTvy'&؛* :|m X:ǭ[PQn {&v7[ߌ>_sOڊF+qљKĖj,ʒB.\賯ɑHWThPsT%9xjI ̫r>jbVNp+>z#C PJIhVc>3sQ "Lm&nRrt`HPL/2Y"*d_?]҃e/_CQeD)*Ez%$}{@W=GZ [mݯ$5b>zÖ 'pc IY9< =[ ~l S,fpig:E%^0-$q^j)j dwش`S_ʗNOjnWjS]B{," qqXi} C?ʄG30b\^gX̤}0k5W+;ظ%8#e #:+oɭ(bDadD^5@fhH'YJXHXMtŃ)1Cug%F W^d`P!&2enCuQqPU\)o]#2V)y蒶r'K0Uvw5Vqe\ZM1/-pԚsU m$Rr}`-0W"#MWn9E Hy)}r8)!+)zjs*vlsy[ɳbZj̯!bzH\=&JȘe-Bɢ3}&ٸtөBkl9j"6p,7~Y4[UQLvek9y+d >|˒qW֫ .d(( )cr̻|.OZ& ƙ! m7M?)g.O0j9ױ4M}l9 =X_aw3P`-]ryx¼ sMa'b#^os-g P,+!0+RgJש–Os\*Y{5fR*TQkH\9sR}ϦgZDB&̨Ƀ&odݥzj<{;unI MaN  ₠YlCd K^v7kQ2tH T}bsoVm _Q`@'xj@mreg*4ivdRH觩Savנn>%& Î\0>M.t,XVh|̞F|MJ{ED*S#:#Ktd4|#lhp&Yr@hV_ě[W @/]045Hq˖A :Lؒ2V,-EU]UFAXYː3Yisc͋| ;"*N2X^L2rګk<vwJ`-Dy&x԰jrN90L6^q3E)a!DS, o$XFz]K,CiezdB…Vc[BE|\ e\!y \.WtnY嶹߽dzD( {B^} 1$uCO(ĸw<;4 E`hC'9zCВ?|]ږ`ebql-ʞ~ |D3Jµzb?kEBQ;8WǷWD;},NLo, @ېdBiDt_CkЖZ~Nz*羍{'HuZHYN. 갎v݆X[0k%4=`ߟ$ 4NȃrxS`Ah :ˤ:-}``o L /`<$\emt,f"O$4mѤ{(^p;*N%2d|~͒9m: ~=oBOl`=P6M S~p^m-$a>L$@ܹL%c-}\ɠCwlŰ0H$T3`šO_XsifgmKC!@Ÿ"7"~^zotbtҎ!Ak$<3OY&38*yLv[8Fs;A)dճ;'ɡ'?e|nj}Ԋoxk[)u^M܊xEjUrSV/d~tZ: Y Ig7i֌2%mWnو/Ӆ<cPvj䃧BC_Z$NB9I"!y3Mpr%[M@ Emz8 a桵6A߀Xh{d˸{L>:+/"n%`><ܶjOY&>-}Zeʫuk8[*=S@]yUrZ kՑi,O lvTɥ} &|80emWZIbS)K.ȏޏ~-$^j9NKF#{"{-Il:>ICBqq+U>MױsZt']^Gb8zyNJrvcNpb1ɪ_=Lx 0FIy]uh%"~򮳌BX`u" ]׳īǡ;\JELl*y n!)/G4H;-ܯT/%t@ׅ^gQ#lҚr+x;PE&a?(fz0r3!v6gquŸQoHt%qHFtb{k4, *i.aǭnbaR9,[9bs*CDž 7פoAZʗ|nZBjR>@Hd8 0iD_0#~u{PԣʣtROt*m[p01\E+%sÃ?_~J5oס/VYOe~ =MMxP0w럷/?_ K 5w}װI_g3#94Pƪ(Sih wff{˿l;4o{ ҫdfhy3_)ɧsK./tx5G~KF Ԇehc||46`"n=*VZl1Zwph0r:){O_Xf"3įxXM? MLv3]%KJ#LW)xK*,z"(ZJhYD"6'A4 dp$T;&$$%{$.UAsjà?1ѹAWϨ+ (6GDCx׉Sj7d2U% $%)@a1mm5μF|*aY?nj:s!]sΰĵ]o\7~4kjcA9?K{u4z.[GFc|v\pիuT[{ )"g'k+/]W2jgTB]6YܵcQn,̛7 ^G S_{<'JhȔfl0{cw`Q8/c uU-=YrUL et-$U,Rآf)&Y2[)U ~H]OAA% Q( APwFoYG2O0ghS?oAW(VRaF\קț&T$ݰץY F.= popc˹TDolzٛI'M甅Yj| jX: |h:ky}qV{8NV G?);?.y(q\o!zi'깬RmI˱ ߖ4Y!4L,,"5^)'ri&dD(Xh7Zpbُ=W2ݾ3;&Hdl_!7{57EnIQ(zm]GFox:45|aGYC*xDփtue7dgx.WLɉveR^cUpp0Q */Y:`.)JnubT0I R9؝cXƔ\R]j԰A30)=hR/ ڙRYx 3V83Y8@o{` Zɛii5½~-dlO۝v̮hwP7ᐗ̀O{3Bz\wd:H׫X*Tn|>Ӵw[ϒ{I|xF[ @ N9Iu3Soi/TBdgO):"m}w`h쉼EOL`Y}xwHΑ=-& QF!lu0i*}⊨,DdAK+{eD JR#Xw&ڿ7Oqn?ܱWvKj&a bOi.%7 P1GB,#(j}!N3x`A_\,~>_bTzϭ>Xy,T nAryypŐs-G=zHS]d\Q kh &Yަ| *Լ}7IW%6:a`!H0bwꔄԭZfZ+)$+>cYhf|T2\o`+ >-'¾<\ߴT]W>#m_HwzU k;_`1b=灬 XҔPJaF6"SxUv}UYXQ/`ٻLaA%ڒ!92&FW5;lF8 )ti߮n`3g*l@SJVǥ]wg'?y=<5x&4Rk$#?.hXl,tBo$R7-Oy=&6Yt6001jj!C >U26`@OqM]MO?lL-=ѝ'aۡi:b8mۈ'Pf*^A>@'`&%yz7oXsO pHR"]/ i#*ZT(W->SXBmv2[ţm7_Ԓ8-%,фCQn![@)+Ǽc{kZ͞*')jAaKe oc&H򳮃-ub[ZÚfWMUrp폴~0o-=P.On h" ,K fS!W NƴkXd 1꺣&1ŘNRQ5ƘPXp '"6?4BZܞ0)]Hzd?0>X+Tv q0ct'?!'y@`ɠ0+$ qVPAh J >2 5aIQYvR}3ѐ%[m,RH1_(qeG91E;ސ d・@܉8q XQݝ4ݨ'c`_>6ԩִ;*YK[IXlBCem!ŻY4HES eBnhȻ 8%"xtWArBN%ţCǴ,YS_@jSXT+X[C'nճ(4=-Hw~z0 `ŧ,)F6"PE rB Qakђ zҨq|1Rv% z^{yf\Gtd0jq6S1E-AG* >bn?B[I)$u`<_f㶌2>Z$Qٓ?_ͨ!ɣ^R})ـRKI3gMP~yא|9fbքZ5%qrD jv]%f_ Y-/'hivݺi4їZfһ6ZO ,9 8m ;v?q5Pigkϐ||F>݋rNB,BsEz΋_,NHA?:ʫw'mاcXO>'b@"\֮u޳5-Pn@)jE6KNh2- 3ߵ=ϳ\`wd ÒS<i P$(gKS{z\Br/E- +WF K Ȓ鸷Q BY{ƍkĖ.й6%j0T[I_\w Ӿv[U\~jzX^AE",y8tS6pۊe\o -?o#F+I qGw+CBΕKT+ &Cs KJVgMcm>!?BdmVOfѧw `=x;o9 tԈ+#)Pe ה2t{VනG؅r l?}{T&~). Γ!q4,OOTXMR Պ'yRdL^sz]+ +N jDE(6 VV&QA}ٗoQ(NPO5GK!mQ nXT3_Zc<;΅M0dEjU0I`bN# p(lEV!`H qSWח"}O.9 YVVwhKj#4ak:'7?6}+kx|urt%V$3haDah 2LEnotax+/劂92bM˺sh!Hf:Tw2e{:*q׍i,Z#eC3QËoL͇ojOWϥxlp{2BF-%paBtvTQF6??Ԧ^ hNVpSnSHA3`Щ9:T<ԔJ{CV|'CC>FW)#ڐ1Uɰ长pVl~yn“e&BI+Q4B$#pil&[ӭe FX@3b0I:iw734kN &096BWݦfl(ӖQVFe>M60.b-7\\ǭQGDUBEaHYnxX)ĩ |F2Yq_v:EUyY(wO?\^-jmJY4v)$!#s/8pbFHr>U"֎of5OF, #$ηiʢڀـ:OlX9'8ɚ5OT)76nFxS&͢`A M{1HNJh՝y<:>hNԜfsVkpSoCdz۾LU RF<pNč&Qq?I+wP"PW67+ȝYS $訿еŹI/6eU:)5GVAb/4P}I8lѬ=pރj I{j`ywS`i&iFE.)Zxcw\ů_Dl .>3eku9J؊]i r҉/ WRk;teE74Qv:}י%nN؍w %,4S\S\E3CLb Wpة$#z Kgd&^]jc>7i<~{e*7#UeAl]_ߑX8ּ(:YXnLGF$Yɯe%:J D#]/c.CA*B%l9ˣ w.mę(AG$ٟsM7;QCeR%L𮔬;.K̳l׈] X BTlxF/,KW_x3C.SF KwO;VH7,?Clr&[ Ƿ;VM|(W*E|qB ʕ|]$`BH;8嗌"23'SVyPvS033'ᤠ,SG%rEz+cCC %Qj ^ 0A` {X3lgBᢔ1AstVִ9ﻤ*STB,[U 1Nm.W"=RJFXs,ެj;P܇T`wp}!9S%y$<.C^mw8` ^հ`ϿTӠQc D6pтZ5",hj<:XS6KS<51{&&R'}k2b[I`|(feY>9?r|UّkJfLߖh~ fE"v,nMq7Y '@9 mXVEiwvh7@ ?p ?H1~P¡o)hU@ dQzȎX4d5A@]T):Sd:ֲ#͌ϋ};:qG-Mv!G^-sP܍G#?2Q]|IL4A]˷еY& @:"ضltCi뚄]IQ%Az~ʮKϤdIDl l](' bW0ݱSa'&=OIA=8%XEA`kGJfQ0ig')<K p)P"KM3eW"OyV +_r@#4YE$fp b;1eb(wJ*rnKDaP)SWQ˽ V#a}Wj`03΃fRmX፱ q VxysD8)!QƿmQVȿdҮ%v#Rc({u]Y@<ۘ)z,`z†Zh]Fa.Wnq|W'R]N ) "K>eORpBiP B$wccGn櫠g#B5-UP!Y]MCpEANߞ(JQM4 -o+6Or,*A;-Ҍ&_9O|=!,&şsBV#OqYL58PKШK;&VpK\~DWhBw>qդB%yJvB_ b6f'mKDyha% )5*7lN5n7m1*FFl!wŸ奔!VGuPo?zƨ{ r&wS..byQRW .~1,}dijD$H>Z3>\%d>C0I>Lxt]?wvV hEDgԢPQ[iNpLvU14u7 У?hBR.$pDuj?tЭ`dSqf'MW[C=ߚz x|Z¦g4bdT,@1*atyi~ <" ՋOj9 ߯TR']'Cqji-%8.=u+DU/ jtǺke]B}cryem[S6lDܥ)@$n? 5}cy yogBAA6W}Z'I!  dOvG"5I*}Kξ n xj7Yeo gg{qkIH=IF>w&Ymr@'̧ 2N"=jiUWR7ݓE@voœ .tvZFѿ:5nrna{`d=ho^`KԚV!Jzz%x"[̱9`(-/m?|UP&7AOiu-`$QI1afLuېthBjM@?3I#ݽX9m7 m!?(s}Kqcr,5F~7j 'ȾQZK,sw=U֔ǵv4PR쥘E%5IӳlLcl{1SYV͉2Dr3$I#\o޵N F<.U!=sRʼnfв9&b-Ȉn#vW,!JL>e{`&yZh?eNJd6n$nƕWP$jcf{EBĽvѡi#MF{ 7Ü!30^'#?PMԀ7;Gm r^+Bg0eOT#gA<>vc`^FYF,hd#R*J"_#٦ƥ_ቃzD_ccTZ{T,x>k%>bŗ= VN{(ZHnOWp {}喦Vo/̺,5#AޡjQM/YTJ O5ׂӯ)!ZUH';@IGoTU8䥗uF@߈84plMbM%'0{`G{ 0ZnY=t0(ptV%F2fH$ #;`h|̄NH<|bW6**yaWz-#,py e62aڬIެ?^^Fmu KT7uoX]ҴU'fz$yBewCV*,V3yD^+o>NZol3-O5 ⾍f=TVLX/hzT? +&\y,l$7[Uދ]l@,-7:b?ĥȵCItQaVY2|%c(녳ose9r8vZ>&x=+Թ\B7_bS)d1EralUf ^%nG:q6t0C0j{ y:+5S,3}SԖ'إ=]Bx~ӘʅM[+"Òtq&Mou7B"zX"VGac#GMYVbSoFQ(5g9*|2oqܥtXCF+ĩcYc,眄 r T?P@C:'L005'M׌07¥P1JU˘wGI_'@kVe<#mYYD]CxC_: # >ϹڭEG5k<[p4ReN}ߠ:9?0,"42u2G\UAu^}` ő1S,ZXmIZd85Fҵ4഍ٷ1ǀU$ )vU2SQRKăsa>-M =f,24گ}yq`C!WXvx?Jv7@4bO(ӏ] =pitS|Mw`אsEg?"ZU݌/.0@72P-zN6Ɯ- w aP*]8. B4(O;:ZAE5Xq^]^s>;1i30+XIþ5?_-Hnzg7}!~KXIe[&͘i @vXi=$bcAǷ ){%qx ,>:40fH* c a;O#SkT\?э(K iYش58l>[&mm8LQ /Ar5$|]`JBu:753ӰE|-xZNLRyP̃gso˻f1Q A`Mv~QaKkĻmqe.[x.fि^wۉ. *ѱ$9ȤND.RFwsJY5`l=*f|K@QǍ㘉 j)܏Q<+ILnS)=>̍g`z:37oFtgZW3LeOo탡)_;з'6֗"wze窛2s EJkRu*3(5^ P2`J:$PЪllgTa\AOQX" j%4}TMRvPc'sdaJNt(Y_,8w[^(c#ORe<f[&KqKXx$$U.1!OOњ+xEE' F߆>\o21Fr>PoUMͮƁ^j \qkuqZRٸ[`wE=ӤˣX. ՚l?l@ {Oy/l>s?7Qgoc t=JItrmbf3s&Ρnnd[ Zt˳Cѷ=G뒱ͨ ڲ+";m `$*Bc@ "N]gJ5a+%ǽ)inmbL>j4Q&HE%ܕnʒiG_gwӪg\֊Jy%0DS" i?0尹vH!uXJ3$z1-Zr$9鬅';g~]5T:E+6L\e|Ox]sҪ}"`40S5ݼAOHղ"Tq6:3kGxzo6Dy{3MG܌%JCunH){a]@nY@# ԙ(gd%,g%.Gs&6*yS2g/:>fE+nSRnP[168k(Uī3<[gבYϞV["vEnSY)f 'ۻ4* _H|&Pܯ2HRwYn,=djlsz|Zڻ$23r ^Lg/Ⱦ4@Xnd\Qu41C,O E)=p†am"9 a+MFBU2y (^b0ѹI?MFVqYӺ\[2n 3M kNB@Y/TMw*vz<UOvM)K  _ܐх?sBj 7ZGz',tP ɟ[yi%jg}ׄV\܆qeunO ]g`fzCqz(mi " G>x)+z %FU ´qwW]ZU. fm}N37ިs EO i[n 3Ѝ'kSN,ܺMEd&.3- OP?t ۍO*mUVeʳpJw\_tY]Ɯ*f%W2, ;%1jFd+5?d6G]WOeE7 ;㎕TW@K@ŽJոFD^W_; )*bCMwA ~Mu~~}JdaE 7LˀKe%t1ƏKEQkڳ LNM3Ŭ&ЬlZ]"'@WaQnl׮Y:d'\>%ᅅ ?B'{= Rv۝]9zn +`!8kBb,<>k]FrȲ{ҿ<@I NմPE- 7 ,}o|赧scw}.\ m0N=h"Ecqţ Y.Vp+TɴLTSN3j1~8Vbȿ2ռ.6E D|i6ۘһh5b}8 t;ފ ^_oJx{;Fb W"yXS>,EpLvh#Z3q13 :_<>獦,eus6_^K6c}ã_RtC-v}oCHf1w8--T2ٔI28^K_HC˫#!l:xVHhTF-CpR6v2 ֛1iw4$6)vTD!)p#(ZL8'5->%MU@i ~7~SD_[mZjRw,UÙ zJ'YA*'g{韁d+8K>CUpXC1wDko~V'rV.CJ&Ή6Rf mqwاa/~]zZ4Ńc~Ҟ)uF=-iy sqWCmIwP{ و՞xm%> dsniRB?J ضe}#,r*|do4@9nB166rSfDD>}@tƚڌۊ2SW,r_%cuSҊ]vl0t 8UCj $`-NΊc5$+ߔOfRC<1Q ⫢d*YֶhI3MhDd1U=J9!+OO:; )'R@&l(ͭUP@xO*HۊVbfp`jw#{ܮ7Lv0y0[/(HHV bC# 1~"`ChsK147QIē0sav@Y%7,-# G/0k(,hOZ^[x(@Xq oU%6m׀)ޅQA;`9! Ap"!$- j;:$z>pHjx*s8}vOkv IXy̦ͭGUeEu@X\RVOk{Pqp f=?l.n$Ƌ~q)fbFUK?rJg%O ܒGw9⦆kFod# e? <$p;VSHV)o 1ڴk7 2b`M+c;[e3c}iBW,U-*ɗ ?~ }%a][߻ Y\6X >xȕ}3s-h#pafXV iW(]lL ]k FFKtan{hY>*/š:\b>D%=@U0C`ΙN(A? pH{^7)eiɟ.!XZ Dj'BR I Ρ%̭9$ʬ%5{g##vdoW2mfzR\*L@䄎S}xm:ɧ%>֭v9t j6X̩Kheaf1h_}P 1E33/F9lwfy[㶰_Q[Dtsiӌ4t)) :"Z?,Dspdż)LI_D}DP=pju0tHԐ/)]dԈShH4uCE(W\Ux\?ëFU|MƉsD/sNE M+#amFm>-&u#V>4(Jn9:8!t3HV Xl(d@;S@d(I?}UՀY= bu~2DJR` )(CץƢÆ҄oaI%xI>]q>Q3 N}+ 1yV-N6FU_bx?њҽQ{ Nw]1QyXj0=!$Xd o ' *~\84A萉,>`:Qݡ{|Ƹf[LI{@`k!fS(1 Vn*q)vNQtp3Xq^x9 /?'gRw^4V>ÞbT!e[uYJ-d5g= RB#8w>飔"V*(Ss(✈`Kg1űK A@G3X94!o&W-i%D`hCQ:r5*pb+游8 f*fE6i\1{l{T1&ݮDБ\X t sZ?0M jXI]>R@_څAlvو<%_z6'$+цi/{]6,^Cq_}-A(mv]cTa7t! 8'.~vUQB=6 )%ڶ[x<[$uQ_(<Ñ^@e;C aJDZ.*#:<2%Ґ`'7nl 㩐FaMUTVqcq[h .w|_\Ь~RH: )-a'P0R2- "k'bpI"m)gS*jңtfr&{J#*1!B ʲZqcr#yiFHm!1UI#M XM}v{>zw.Ypԟku ,;HwήA\ 3!YciN:U )sL@>n2;/8V)|du[\;=IZQ1 C7.o[Md\$9 kJw; 1> Wp~cGy!Eėu?'I!@l#Ď{Ҡ/Xgl1C#yeة0 pY5[&چC /^-xz\UV R"!ZR̆=1OJ;,Kj7ȫ%r;8V0F9U[mѕq=AFP1.25n;tU!WdV^#foxOt^w;e?APU;NLflZULDU7@z,y&#Lj DvOkaE*n"]ݬcRgҝSٮ9="=oZ,3R'}4xeBj}1BkhI#35QL\vB̏92}>bl(`{u!zo6lI1 㺖scF,# @nA45kj0T"ղ *߲ l2cu,L:n7ـ[uhoMUfV' %* gTgY@e'z[XV7rGɒ9ų" Vd?JPFW ؖ-|L@i]r>$CZ̃sS=m9v|p嵜 d/2Ƒ}~|Qܤ90u=k# tB'IᒞO*}mf7#Aftܺ2m~ż_ 蘴C'E+LcjOr"L=ͯL8D7{R w'HvG,ȥ W A 3c@4;J@ =+x+M5',GkԗW}fE_J"^KB߸3,xHSݸbؾ`V~ %="0NFzuԷ7v\_ kQ0_غn 7]XpftQANm! `G V%H91bt~`b }cii=)p{M)(Xj".OV O@ԛh+=IT^%dYdvJAڷƬx}4T\SN*^_bVMѤ( 2$ )5zofIo9MJWǛ$4剏&bƏuA7eKcoƓ<ՍwN"FqպиG$Hrߚ]g$ 4&V WIa^ZOݣyj=Q & p eDyF5&cz1!:ӇQjQߚ<>s<[ p+՘@.&W][g+hm(s廘y?˵` ,zZ#bGHG{_~}ݾ/-Pux֋xRե͢5+- ^Wh$u.:) ƵR(R~Uhfv``VeZL5>=H곺ssa30"×!46Eg9|W:ra -=TTnw,7WlX܆ꆸ]:f0Zy>CVNtyQ}-jaN] ?WT\lg{b|Kћ:="G\t6֞>SvQ"Y~-_n k"x!JTU?^lE>a[?~"a|wd>Gx_)P߅Sj:+=&2<چ_KDZ, O&$ZA!OY^]#*m#D-^U(Z1jQD vXɐ760yQi7[ר1xDޏ+W3|'+9˙U-RC[L؈)v'# ~Jr,%8u{!'$|PΛMj=^L-3 W.|)SJ._hY$ŀJ5C<" !mXGnFPe\&g= ˵ ?S#'覠D܊+S_&`o>"mƽΨ!IH*D&=${(,0/.W8N,pq e9%/"_B u$!z^wv+NI@O Zn#zCO?=L,$M5&Q`K̂H5mͽBzELdOIڃb&X>TUK<($W5Ceʫs;< 5YER" u׭}wKNFLpH6{0J&WS.2Km}Y}Qw J)>^ D߀a&5_& `VPqMqir,#|M9>}VYYSq90tuk~ մŊ4~9 @_`T?!nбK@7XC7vZy0TQF{S̲$@alS)IJLWWb+ϩǾ JNiMj;]q :}Y+cf2n6g-:n0^" (4HŘw5J47幔Op /R54"jŚ-.w/ Q35on7nt_hGO !T)"a.RdC TH. 9 &-t]R|` a̽ $@[3"`:@.}b˂Lb!Xh>\3PeQGGe'.tj%q*ߖQ I6 #8G qH{a]_ixI`HFQny)Ջh/k4tgJzZ=k}lb\iDj( lH9GEYFkbuϨ@|9VAŷN[UVFP|,|&M'=o/J:~G\2c`[ť۟Vg;2"V?6Y_GQԚ5Mʲ qiS),0,͝Yf*bMkm;F6ov*Veń*Jm0Q?1O~ڛͳ4/:RkXE/}/Vk ;*\&mwWH͡YʰO4ݿNT^;׶kC.wAiFBdfХ XT'DANюO`{U'dSk1jBUZuN[thbJ<~^nv vraGvL8=E\*?[?GO~]Gh!Jz,S2*YIMdBz`w^ya H6iƍ/&&3g켪mOKXG:UdqpBg§ ǝt>i'Ce:XƒFu"Q5Y\}.V&dߑgŠT Q81 N!YEi$CeplPl\5qcrC]ӟ9hlګݶv.u)j$qm)02C4܍'|2M TX@5,b!,2Ƹ i_y*hΈIF"!)V6v.ۚu` $TmeOEIXE2F&tVNYkDOs}cwVu+h4 #/MLgBg@djg3ʅ7ymN[DfcC$1Ӈy.>ZE0M<(,BɳhÞ֚zƐ25 Qp+;a|Bjzr^u0jg5 y9 5eUzc-Y+tX;,}Ɓ9)z+\- !6<-[QFpGDJJr whi8*b|12H.;kHYKiM׾iI෉D4ec>d6iL֗I ʫA,83/E.S )"~0/e[uC.zu4q!gezӷ}Nm\,d龴^b[&j_$aTYVcfWj2qiE% ?1[I-}(_3z$6/U+^qh\7CG 6!@5QC2a豏`F|b>='ƀDP{rC#D {7φACݩ1wZߗnZO88Ax+}bw";0tC2mVăE.?XsC%`(v#3;z6Ǚ]U%q\$Ȯ9I)Ʈ߸"RPƺ$uS/ÇA#ױVBw$˶P}Q^KԕR\58" "AtK7 bli)K~n;}<2n!5Ew}Lt޻AQ!2[XB&/Z+E C(Ъ4ĕh@3*{]@t)ISTIX#/89qpl}ئqTHIl}O4af6\>`zßbd$?HHȄ0\Z_-zQZ$' ~B%;3uɫ#ퟟ0`1JXWF(}k(þUKd###*+mc1E[o[ng24_a#:ÎJW@1!쁅>2,+.hVg-tk좪}Gd빅B!+?Ѡ BאIH _wg@\EؽN[_>DLۚKd R\A~OY2! Ips(¬o<U<_TBly hB'iTX ELI(tZQ EҼC[S H>2\ En|u$=N̛0<\QQV ա%o՛|$ \H6N'D0r$HQ9'FF3pZzU}Ȭ?pdlǮ]y'`1ҫ9}IOR P;Y zaQ:#eh:98ҿr} .AvẂ@$czV XAt.Zb@z4d FԖPiL^FmthLyX|Xsm ԁ͘EO (6m$ʕ H((ClfRYhzA08j {<$a7 /wl (гE#z,JniI{?dTb.QGa]W_^>`+Xv~S&c}@*¹WhNiQj Z5+^JWD3UNTq*5L1paCσzLmQ.3L;@ʡpԈWüF]߿: qfk?znh!,mh*&5(C`/H;'rBG w77[\Ek2dr 2@y>JīV{N@V&)6V ]X)]hi{d;K 4yu8uD&4%x$GWD F$9'xŢGDBYbfkwɢ~=z#&|Ӯh"_ V/;0$7eN)kr1݄J S46"،4k a4 i;e5ﳗj1*n({\)!!fL%]6+Kއ(QECfJЙǀ[Wݫw{XuWؤ֟;+ˋ~7].3>`!6%xeDM5TwhZ'6[^) G?3QĆ8+fx-O[F9vIK;tyѿȯje'z.1 & #OK lX1D+ 6`jO?h%F#g֚}nSW S Y l͐bUK"$Tjfm5b|1okg-8mG_fP`ߍn '?m)"V=iV̗iCN慅}dRk;rP0"`R[n(;ph((WY":i}Y p4 >;5X.6w[{u~[3-.&{L/cmTh|QѺFZw,..ѧ/HD98WY2goPQ4IDlRIEԯsr+f '͹ )2d~- ^sov 0]Q|/ 6!U.2[>7x V~a.CMw˨4֝ļ,4 ZqIPT>MWchTgWXw%D-'z 5v]^?17`NIˮ.gNH{䧺&g4keh(HXIl@GhҀ#Y70Іڐ>jR> +F)2*s9}#[0iqB~䑥ٟ`rRYf~$ߘ7:N`Xn+ϣ#_.ȩPX #֙y͗ x_+pIj9(Lǒ,0*C羊I(^d&(a,Ap$!3ZKH#.gu`Q9+Lt"3PoՓd QH9"FC< EJLN 'T YγSba߳+?~/tO( BV,0Qf5"WdzȰ$;{ ĭ _qi PX*V30&{̒7W3]=TuP̓}w 5ĸQ@R(T0r3eđؠ8)s%/9HvI 6}VwOhwEPvӈ1uM-4OTij` yNS2p"38~k66 ܘEXcֿ'(P20A[ 6ӎ{Enmf+W&@OYBՊ'C:U9bR| ‚t.w"QH`QPMM6";ݷUV%c\R,g=t<xrqĽAR^=HQNԞL {6)9\l~73#wo%LpJ8iuaœK *'&~"Rc<`pC9B@E>঺k*٫P$e8B%3*dFS3gF /g\>dƣ =9L918b"ZBtjV(&X+ Aq.f>hml1p#{u"c%߲3n^F28[mE_AxsMXDv@ڐf?b?XIgKح@-lTֳ-hmҲ޷bgUlaPQ mP4Zߕߙ {U!k"Í5P4[Rkpٶ7>FUU"LHtC^=)0 <pXwk.7 h.nSy Fzk¾HN <_p_wtj-k:nPvLxӜ+~ִY ); U.1M~V[c.pJ1T+E3"x<2h=+k5ʁk @ak=˞D =Xk%<9S VQ@ V_rķ7'@Z W >/J']W#vntHҗi6A̷0=QYAe, 6 W% `WC[kTj7fgy/fUv nFՐ6cˍp2E +;yV\=EM#ANWڣTsiKc=kגAW+NI=KV-S a?9c B"hN d3%zN! Db,1y{ZJH 7U`,zu؞]8Oxu?ßBf1hW(!Bo,Y"=`CGa@5<8b^\sVWfe7Yj՟g5 %-||.y)X 7j~@+r"mya!-J :솭WrЪI*uϊ8lrwpjJ(-`|;V |wj\$X6fJy5kƬO慞4 w'dT h@G%? I"5VNZڔ5M6!C]@5b:DZQ@ސ0]yW0ik;rr" wVö->E␃_+c[06P~L]8fOBݭ>ka}{ iezot/0).>g-'ƚ{8$T,I ^Pͫw>@L#vHBMpyMlԋB@1k.+$Evأd :ܪ6T0?q7!Sbv撔%Wpc 5l|b@7EӋB+(j.fjO(r6nx}; :zڥys H͏:ǰ(dҜŽOAnl\9{mdi2T)j?$Ȕ8Z*x jJPc}XC|C5YUIOPsZInHg+)7+\m@Օh*")C>_E\~DMPU w0AhzpޏG}=Uԣ-_2L LL\ׅn%{~hb5'K`yKD?%@3ˣAb2vǗLP!EM;O!oV։s1iLE,N5F}$@%ۥēQ ۢۢa_7t(f-%wjCҘe)ݸtbd 9gSLpiXf!_6kO?MsGn1X:'/X 93:i L(2Z;[Kධm3/'sP5n j7.BjXlP< ˉ6?4^ySoh3*AW"k[#؈Fѻ@֌m%3Gb` &?f\HB )ŔȤF1H{t3?ijTH:K#R ky¢-ܾLRJ)̡o"a``K- 0\8c\&T9ms+v^YwL76}yi?\PCW:&|qgXU3m.JL|sҌHF t8z# E68;0<#S=Q`%{_zD[Xid)҅"x2plo<惧uR7N6r7ždC榇YUזO6Z$R7Osܨ!{ O@GYZV%azkT%Y:t{oj+  ~3 o+2IRI~ ) ٧qG_3?F!`I0=6U}3971?=V= U­ܭYdHyoQ`jAh6 %5*ƽ=Ӯvh@OI=[4}<`rW0 ꦎ9ڀU2 }/mVv_YF7^:|w1ef8~$Gށ)bI$w lMCc )Y<:W^"sO4-M&&&!0SÐ)[:\I^P8f|-͌6g#1TF~ggch\(fȢ抋2- 9 G,r*ՖH&&L5i_FP>^+_agWiGs4@:6aʂ="Wp# Limכ-cŏgִr /;$f~xsM=G._\;Y9߬&3Jc'H5=ݳ+%83d9Y#rιtꌄ$_?ݖՀu.z"}p'n> );tܬ@ ?C)?nQ-% ̓5O˹( \ J`EZGýݺ:'WVRD/8vD:E6#i1OCF.]qBGii w<@(- =@m2N@̨6NK8IӉ2Ee2 IlZn`qWʹHR(ΠW nug"CޓKƔᆾfR 1W2r.α++2Hǻi74m+N2-UG?vJay9V_ r7rvZd` q /uUebՇS*]^J*Q3VTжm? :>릫\vdI&?^&i$1]Vv`W %1-M˵ObWй~8р9U'=:=$_XO4oz83Ժ3bFٳ;삒gq<kڈFP= ߻ȏ;=nd:. `\3HfN]n%BKJ *c֗ܢa~ Jg=Mxs^ 4G/^#83K_uۯ_]zGy:fce#պI7I[?.t|1pH_N_1%SCgHU<'5'"A27_6]I"G5~̲GpPzKI D ) G(zGu {?*rs=Сw./Y6$7  Jw=ƚ Yf=x\O ):"Q@0@6؂N&= 8WTLƅݠp*UȖC ǓdNH[iH6u.NLtW?߻m9`5iN"}E磋ȏζ7XPu|,*5D 3=imd#\gd`;$u9(kQ)'t]b`o"`I~}hqWX?s=z q)4m`u{c v{RʛWo6dΡ@?A8#`3HE}5S~^Qs[qk>]׉{61Ih?6"a/WuG@o;4ʸE*!cfp`7&dgxx3{w-&+B-'kV=6vK};g#82)[~C= ~_0QX>|捫bahҍ]z1?x[OaO\5X\G7o/ޮ*AyT\rasA(u®Z@Jm;#{ w.\f= c?=!.!IT9l _f1F-H1_ }w Ñ5w3!D,CۋZNVicɛ0m >i'^tF!/rl zd%'C2q_y%YyV_Jco-2C^, 8ifO LR1̼%1oаrNt"5>##V_zgY&#YFgkηb10:eĒ,jP~`RG箤}I9z>H߳eSJ9X0NGogA2b_p((c9\vեEp\v2'7!I~59UbOB2'XZ!E.'d_,V=k}BJ> R7@MayGtl[>o+ u8~k2/vL 4}nq]$. &hp"X¹0ir%vkn 676e);goFr G'cKGtnElqOcq_~UV`*€k H dL%f¿ 9ֲv'& U sZ ͬz=ol| ئFV ͧ¬'pp  }Ú;a aGdd1]+ah orβ߭tA: +2+qNZ3YǶ5Dɶ̇g>HzI56nPŰl7 J`y#trp. j6z)xp.JD̎)~+"$1[s .7iiú5kuw+zAw(Rρq" w.(aƋ++o@13DR:/u=[< 9JDCx6 4\ZPPRe}3E (OX|!̢@ dЕ\bM2Jۧd@y3yl!/qܕbDt.Mb{V&WpXWsT VZvp΂'/ct.?t^9~ `gfR="ZiMCN@m#K}ZD,W7'O3AC6ys.X1v|SvwlAPwݘ.]E2]pۍ% >i !wޑxEGKw#thVt辎'P%#ٹ\Tg n|^D%rH@G@ҰOͫKXS4g8n~ݔȑͬиAW!'+0~ȉtc8a$WLE":5S 2)dBIDw5NJ:_n핟j]A!!GD⿶?9Nm!*bQXSɬ`8yuEOMӟNeTl'ܙki=,  Ϭ|Pŗ#۞}' MƤ"I8L#~5 hG*zmUg fnym^!u d>ob)| ܄Tv ݯǧY8K֖A2Xه_EC6ɤFa0f6"8_:dTcG9.*)IeeÒUٌ>|=U[,SAȓmelrs:;/%H7n'+h/h`DR+hh ]Eq.u\'UY~GNCLN!"Ig wbgVeMF d{v(ƅv|XB,I^|fV-{{ddWAcJt}e^#rp>*y2#Mhy'[!_s%|jrrp pm^%XDžWGѵo@كA>ÏwhoPlwaGR5Aq FOUQ_ lEwaDnsŗ@ bwp]c9n) E:D\^D|5VCtσbµ?`Ԗֆ̺IWŗ>P9n'}=\k&3v|6 3u}M l2U;Gc8y逸`دrT3r E[)<-_3m:N<fJfRW4Qg:)PI3v2q\ɧ]8~mkJR|R+[h*2!=s..f f*"Zmdgrfc %F],^|Fǭc!Q`MYYlzMԴ.2 k4j)/ &&$-^,"Ffmf֥m}yN+AV@CKEH25@LBHU)jy|P!8zД%#jc662*(@_aB0eB vV_cbknА|ab.^6ʛ i!5#.f)+=(ݮr@2ҍ|} `#ۂtbذ`eT^?s9ΰPҝDϬy&e ԁ J_{0Uq*J׃62'{3D&e֧%d=1 k]/B1 G``)wNZKIaǰj]rY|ƨY%M$Y֖u'BYnm3|`xier#% fK`&d ZF] pqٛEߊ3>ɯ5OQ&}ճG<7P.sǬl` #M]~c@HٱT (A œr }QgQ @ X=6̥ktkX>#J'C:]}vU ӏl8ׄS6+~&K+! {Ne%ߡ AЫ0Eõ͙}5  9yV`D0KmB,2vV v&=ͧ?))U69 Puc =."{&MC/G8.ޑ>L-Ct ;p4n\WѶ:E/fW<"h!C4Y+JI7[Z,Ɣ XϏ IIs"2 tί1uWfӭ*pcd!3UFuos$Jw)Xrn]UyH5zwnxWс׵%uǘSƻN'HZ૛$k\Co*9x pPILK݂yz*ɮ1*92B7\b\G +~n2q}˜&n,7]8 B.6ܨLJdzE5683PLj Zs-jC=&LaZ2Wť}@epWq}*D>< >?ص18~kyQQЎgxD NO97VÁAp&'eccy5sb*iηMɒi R%3 )Ϛɜ9*&g^ݠ,ՆK=GNh,,5/5l8i>/͝F ! zH?2 RQ>P"09nE|Ed&K <֞}gʜap7q BB ?~0d; 'fdh4I1n40FFps",IJƤИ@~;%rZYz4`S<+ޚH-v2i 햛|nc9;Y&7X\[Ul#٩!flj*n֗{;DKe Oj IHT)=/"_qleO| #-;7Ә[f4:c*Kew,2{7ӥr]wXp]p sșv=xwƳ8xB M^7O#FbHlX_~.6ټI /-߅Id Dϓh?^hwe݋~wuțY6j $ׂ}"mIU -](% z# i~zZ|KVAJ "p@qNu1g%J{kZSWv4o`w]ʉ=2xlA o)|+?#EMs+ߊA:Y"uMJhj/4 o{9!5UIJ$J]*/lF{CX{ F~@XVI 5W߻L/+^ݿ-? j~N )1E&\Dn?͟^Nx3PS\YY=olelL !vF1f*jP"8yHHhlG2 >pTBJ2&6p7cV~?{@Lϭ+ɪ U!}7ĝP$Kt]w-4(B~mҘo߂^8h4Ns@1po_nb_(B[\cm:eRf:'Q⶝f eT &(I9 qr Ti;[rҢylbcZ&vEĭg[%=c/hZN*T E[` C5d<9q&] o zT?V^}6. Pw@v9s苘,[7!zCOsͳrgș{o{q- d + q^}ݍq+iҨ8 ȭ|KY-%+`1weُ %jqOP qsY-ca0YPY4GCqGm;/Dtãb$}Q`r?1,u=bĠ=m=VtˡH[5ݐSV \$6fT mmW`M̧a\$BF3xvkNS_oӍ-RkoL0&A%g,HvGBf20e= ]¡Ӵ̮3#K$55Ɓ| /F {mT0Я{{2+%v'R_{V! Bb[~',X^V|k.BmO7_dxF-GG3ۢ ՊNҎOpJJ0Ҥc9!ü\ӯfNg N>t7JW3&mvVΥ~ou%_ǯ0EQ,=^rnh$s ɛR!䋩BӓЖjnu` ( W¢5d1DJf lD5@ 4CcozJ e'1J{@OlL5UnʚE,RqѸN 'UZ"ݦG{{&G{b>piUz}ပ=U@gL?'(ӰDd&$UNjvʀgՏ]E5Sjb'RSWl0oYԳq>ZnŐfklp+)2-0<̉u Rg?Kdx#[k2 x\H $IM6V;k}6!x?}pTJ/$Ðorv #6 .DpZl\O/ERoxI/{C0eUB'΍֑yxqqْCaж?㫖UEaru.PJJ(t}ߤ7c L;M"Ѷ*Njmn ;ËBIA ՠaԗꛡt6j}W7EpyTʤGucxAUN"IATܶ$g< jq[ሑI*:"aụ8м Z!eƙ~C@UC5r jk ?`N̋_-ӻ~iŚ)%|Yh)|*&N{ ;?"ԭϨkI`~̈>qxj^4>yoOr;RIPq e:=_Fm]5Z/(s3':gn/w .i4CYeh  ̾ɩ$YM:vݢ9NсBCǩ48SUY5!%XgQ)Z&h*v9Yz遙Ҙ1.ӭw {(V-<8%Y!*BT$I`vJfy⦋#'i+6[GU\.{sgs\o\N"*{C%᩸J"[}68\lj'TT@_hke澺 F#U7 Y^0Õ,+FWmBDbtfSJ,َ3su$n#,oV-7QqV[yK| W~HR8nhvLpLmc0C/o) rzN(e7|XMz#}y#gTu2_*9ɮrPR {SW׈2yfULm+kʪ >) ᘍ+U{^9,"K3չ8޳%=.wXTLIn>aƿP@O qQ28&6e+ [W6R1.rkÒpSd2>=ߞNe`Q%p%?[IZ)^LӁ=X6y˸3*x"y̺2;9W hk\qXl˟Xray2b$ooas13~C.E}ADp]Р;,w'Z5 we"  ÉS~>SU* p-+simBN$V'92]!;L꿆20 +7TX.4}E[R>ad#Ygo%d~&)zؗjM^aID3I3u53{-6 v"=?D w+؆ #2WtlV&?%H)*3S]z{\Q e;;;;Pk}⋰L`O^* _1gP_w7,]SIZtƪr J+#H*'Ø93Lk,=V-ғ^.@.a\ Ɓ{Jr?XV5?`HDޙ8B'sÒ+OD>{lɓyӔ#Q&A8kacο]mtʘa9` 1}2f9WlD5ʛvyM/ dQ`M(3M~J #pQtAV)eXJ,ڕ; M[O9/h?yS dT3j< L~kd~L晼ScNf@F)Pӽj-G QudS1ۮGG{ivWYܽAE/: 5=g_Eam_Id!M)%r) GFcQ!Ռ׈G= GECSxmV Q}:C3jhC 3h7>l Wz\CG,ީ -{C KQ%ZD2/x1!Ͼnf<^@vמT'dԒ \*ݙH{z9^ԅR UQLX|(hFx' 1߻C[Wt/JJ.J!5ia˾0:OeWdO@"5}eDA$ [%Zv|)HOw^2w\)bU;YmcAk|nHV 1^3{ kU'a}d|r[!P/M\#x-77hitDTnٽ]"g&# cccj#D.>m~uz׸*M яpc9xئrH|E5-`.p:+I#qU FrKu!;?DN-!`/֣:I YD0ɩف1]gBT\_X#ݑ$d Aɜe9r4hvg&:\>$s=cmykvU~]F'vaj%gGUFŷ_ juoz[T1 /*~r?QS_4lxy]Qbپsyw|X "ӛ퐺lnynl|\w {@r"ak%4+KB[};5i/f kto I>I[⻓è ް s}!u$PlV` ]Ů4L e}l?x^ uQK'` f{HR=XTݏ>ZYNodU]+h7+hz c K^l`1~ӨŔEH/o1/Da1ĥQϡ.,A4TLv@oFASK.YJ[Y&Y Գh'Z{٦SU;bۺY7#XQݣ!RvHPO\)\t7}t^cGz3I Lm{.\kVX>$L3WT1K|$OLa+4eNbbgY+ɯUHnwJZ[ oqR%{WUyDڅYtTK~۞ cJ7 ;QH5 ,9}esmܖbұ~A ܸkh:j#|YTPvP-*9BDڕ~[E]2+К:#ʙʄa oYSJ9$5e+%ѩL`2h$Y{pL5;}XN*Yͣ|'ѵg{ZuG2zvNKca65S$J -[vL$fAFRϬ׆$n`%%qǜfN"6E\\P|m8]vD_Z$e6FF} gJf]ziw\[ oVu<  zlٗi/20U_4L I+z؜d=H,̦#4kRlm> oEYz\"]J5,2jsYO%C9ݠJs7=+R2aŬ%'{BQ̝>3S/ZaШX z.\d\ՙ}A TX6X&i$F{>T2Faւ2_.P5weQ@: І[4[wˍq`eh |¬G)84Pv 7/g.)^+@Q KiR NYl0@JԦ)1:뺃$DXV+03jxĝZw8ݵ#& f[+9:ȹf8j=MB Wr=ǧ#o.$}(G/&~jckyp$Ε?#AI!lc^@Ҭ޺%hbevlHZUX!8 0v lJ$\X{#hʗGj6`C=SaډTb\ܝVM J5R/|$smxCAR Լ7vL-5bDe#~A01^gP~IeQ@(kczPUkuL\F^oS3 Bq%7 ^TuH`XY ʂ.'bՄExǝ3ؗG2PDbA'kF g?Pp.!T{7V.=S5Q?GVs]/ 4z4~a=KRNJe Obr"ŷBSPxHílAcUq1+vY:PH _(J6O?$$-lժqAƍ4i=ٴO%@J$6lXeBfXoloLhҘ>e2]v tTAm>χoujvvL${%!:7FbO{raJKl&fIdOB4k[aI )aL@tz좿837NmI(z?>CՙFV]w&۳MՕ3L31{-UOѭnELC@lC@0="Kb_C:[]8Tc(dM)d;& %35o8d^$ c/1(&dpdPtҼKoWˇvx\mJޏRNߩJMuHvܞo]Y"`E}ilId9+1| @K,G@o=i%Z*R!;$ SW5{3fN<3+;H.LQbY3lHQkW7UÌ`k'dMcIT#],V҆0V%\س?ܔ>9ˍnԎ0o3x4=abGы1o!, dHق@$[B!m+ak!vR%4ޛΒOя=9dȊ+Bh4fUވ>ɔ`5Ax9Cd, 6!dh0ro5@Kיjo1EүBÔJ Aɳm7O[=G{XA}QL!!Cqx@|?7IWf1nn 6uiToKh!S;Iˠ 01lQ1[-T\0x|io |3NnVHw$۟!Td5d55W|EFUv|u[Tc`KVmC\#2-C=%1km.+Leρi Y84P+#DGΞT%?$Kp:WMSЗ|_I<]*xF#eDuN<5Sn SfMX窄Z͛4$7wˍ)@uH{>%@zk7b;3k-Mx7eJ'y|ߧ|=cB*"3ZW ĕŤ=d\},S2'ݫFH6chF /QQccǀ0s(ks( oBUGBIE% W#N#!80s!+-œy\Od~z̩PS*Fj/`s>62! f!ZZ{k}^F} ܈s1&9'#vRME\dL,j\b&8L x# =:Goh qZxKr߈hF~iD@|ݼ(+N[o*"Prr5O,A/rƇJA6R6 s1o&<48U:(M ёLu:Ss)$e(yxi "B'O 䱦h .jiLa7y1't aڗ}ϩ3Z ə[dV4'S­!Ԓz}/tU¦v\ԛ+ ;j-ICR>n&yv>jϒ]boP1uiEK`TԢI6pA :sGeardHlf~\?¼?s{z7>Lw`d2vCesOg&.JNpt:6hi*VQ0F5w=آoҵQcY0^HDKMPh~' y>E 7j Úm4xЌ #S "ݞM?#`K#|y߶z@:E\ T XFl-\VeҵT>f-de x)~,/j ̪؇6 f2BM __GN{bKxL?|Nk '2(:ձV#rD&wp2/ NsOAW4ByD۞g4\q0?V>/ZUpdjSK ! 3 o[ @;QL?EյvliJ rn }|,~bz7#à`e}޹*Qd+]ur=;t^ Z.V/%v l=RhI[,ׇP%}R)Q>.q/gJyi,9?9f2|haWZŚTWy}UH,]=9xׁ0`Hovi#<0podkw]XY2g5B ]90BF '/,DO 40ܰ]*|dMӊ;d+^Ğ4bkFLdu2[R-y)sb6AQG]Q) e@r+SC^rm1ɲ&s_ZSREU bKZOбf[Mm%2D7&R]oúD{FL=422-83г.ҌwO}t{èc>HvG/AcGC0OR=qADQiju<Le3#uQ%E$zc_I_`;NC,zͱi0 7M5ZZR0&V d>m΍7=;DQV:SDѯ1!#5e]67xSM]QZo AW K]l >ިƗnLO>i9EGw4❭֐:͌3hvJhpE0EfRPeKL9!:ُ,8?g$! fh%M"ϼe"' 8t@$+5ј(z=J@H]6;w ]|#3Q_D ؀0 9WR-꾱366aN3xWex`q촐RwaHWQLWz YR:׿Preb5MwLz!vQQ<\kTk!j̧_Թ__N,=PnuhDp yp:$$m09?t/5X?C mρAjzk\u (Qjc/J]cBM_VVףi9(`״r(LTjx ԭp Q" /"٣÷o G?7βQ=zRgCgZ3mLqVM٠$DPP5 n)(p|Tdt1nξ ;-_A~CH9оq ] tQV >`J=10@$)m*]|*'<-MLUY7Σ]toR Qi+5!_%N.b`klF2aQE毞ZMLX ՍGin.à&L}މܻ{+iuE0]qQiEUff> 8-6'rƷjx28vC?O,UmeiOXSV !sA~Ck<. 1E vnELhǁԥZ4<_)&ĩEjnl"0"D 8ۿaI6аN ;/(KqJO*[V@9mtY0t]k㴬uՀO*>}] OdgD΋KR;0vH#_Qfҩ'>v(he%HeWAh*pkJ jڣ<73+ גF>-%[js3.+d=+<<%LG,/o~@cbdxyEOx5h0Hh&5،Z )֖# 38UaӢJ-(]YC#V=6^rolŗwO堏DZXer`c#mdXh3amSӪj}qj5ʩn~]{%] ~&u4AQ l5  IA u&[W OIy'pH趣*sXчx0s: Q ߬&4 1L 9]b=N/XuXf;ɧ%VhT3^҉ks6r ֭ ][ DR%]op˸0:uW)QgסV,6{;y'b׾K' m*%{RtJ.$ 6.-D{:_as~="ѯ4Ŀf4ē.;xrj_F1sn543TIUY >'w]j3ϣHfTq;SDg *QId0`>ׇ-vsf@'0[',"dt'm ¦cT(>|^oNK AX7\#by{ I CFI4#N$u' Pxn#3 2՘ٕ@2 ϥ>]q 2w(m o.*Z/H'*ٶ`9i-6 C \hnPuN%^6tݮf^9^Χ;0lp<ÔjĻOx=XγML5Ӟ]pc1q[.a?[ 7 l}ˣ`ɗSPGj,wK҆zn./sy$rN6aJ^iN۠cC3 OI e&eƕAg'`N'"e?cD$ntWf'=rHpg29(.OXhEbF)f[¼L0pO|o@$%CP@auE}逻-.=Z(#5 ?Wg87yu&vl;?\*} yg^ٻ%{rTba||k[7K*X ȮtcF .ѳR*rf 3DM>WLUI+0瘙NQMJj)$|*`Sz45ḇ|:ڂRl:ʑ &ƚ u Eyj_C6c?+d35ԲVq[-%}dMEk#0(F7AX _J x1@ 6\J{K,'$sD200 y}A΃],RrC.4ÞWkɄuUFEaDQmb>NM݇3?ϻحس_yBC(E' >TQEB]&iN^ꐌ+E?'Z\t=}ig%bj2'f4ռMFn5 tf18D~G}W0Y_˶DMԧ 4f-7 wM>D9 \ҙ!2l^7!nbz6HRty'|yUUqdqzGFy<ݠuƚ7P\ߓHMgIy^2Z%Y> B \6?_ٳ3%j˿2tͤ4G_d`WuC/)F' ýbE,ushD!wUÀG`HdҀWuІ-MC1b4B]>to0"ViO GbH%:Į"H lDN+,>=Tx& z ?8i6P|ؑN;pvn):R>d#$XgQE QCIXnҪ/OUKd%B{(O#$A`m5h5*DoYp'jnŽÄʌ`өǹS֯xAvFdTO^[kid/tV,cרy%o@_2Aib!'ff?b%Ym ĭ14Pxϟ.C)>AԃfDLevУAjBbekpyGҹVI_ %D X.&B}:[)@Y7;L0`kOH^Ӕﺗ$BItGVi褣a3O꽫n_cCM/bAӯ8p?S7.\Uh'Yc[A\.Raed{w%cM(I6[E&VAޟ@GjK\P[91I઎RN{$3$;{n|u!@ 땴`X}-Rʿ)+`\ٗ/# 7!c:a. W/ qV=6<)Tii9,1lV3g4nh EHʂ*YS"3v/&.^$7Q[SM`O^TkkD_|;A(xdqQJ$)%2q+G"3I'npS<1dY&2){{GjK60MWVHރTsh`]>)esѵ^mx. 0,5P.™P. w)̢TfX (|ԷP{q˫ʦ0.`W2钅Ґc5S !9ڮCb fkꐵ1ԯ0/5 ;P΋R>o3_:m \Va@Iq>}2n yɐJb{NviLXGcijtw2壒/5aۚyn<>RP&CmTYYR@%)~[4 fgU=ⲟcdoKJcI~iC/3rǬ (hywъH( уAPv' 4OƀF,R!ŦRVwRŅ'y]z֟S}5!?@R͸:%R{ˇOTB)r-6sc;a-e3d*4Df8CCfG1~e;NN>[1dNa]7d;lґ"* [+MH Ƒ48 QBD9%%ĈjCiziE <~W822xZ~}~8V2tJqjz_,nah-9 WU^&|1_amo)1I4{n^#I"؇_헇z- /m]ڠghKvش Ƣi'fÕD۰< ֣O<$YřeoIk`pEumΊ>MRMba(D#_Ce08{(>,S,ʩqf3d9=h5u%|F ܺUBApL} IbƇVΞ %6{H&N9d \^Nl:hNXT41h%(=Uo^t%H"Q>\iZHqY-@\4eQXB+p+,2 p* c g/(B '>JQ^e ;et%\U1A]8&~SK li#,yθtbb6r`^B?E:XPٳ${T9`xz"=pFȌȍ:xe'Ļ~ $rG2^FГo+7q>{78"P*8ߒoMqZ7|1$,b* گr$\OE>$|(ҲEw‰-ujuԮtawiJHxAEϥl"H5H 9RAJgqxj7}WPޜHbu5B!{g7n@~@ 2aiCztOO˧J̍Vhܯq#RpLը Kqc7` h /I:pX`󧐺zu'[L NXJ8l[(;HKX`U&la(xfeՏA?aXڄϖЈm Xg*`׏E>*:6HXsW=νH՛j'U|g)IP.M0fթ1 DtL:ZK@ 5VVC 73PRMZI2_i35QS9)+ we|Gٗ,V/xe:NY=2 ]󊖧T/;Kh<&aY}o7 vU](ĎB7;=-e-is6+@W):G"`|G"M7!plGft\r#^Nlt@=/"F/FuM  iB*m{X.5ԁdH# 䏯>IZOta1.o^ӽERb Q5ѭWn?ß47 :?լoiR2!cmpΕp\{9f{VJ?{kA-$5d{%~z\w(d?$p. RA##X{@|"u&Tm⌭w 9;0PKyP8hYnF+ه.//*dq-ڼT_bADLpJYA:9m0v 'y@>"Mqң8:|*L7|\ceͻITl]> Ҫ;}%uڝjL5ѭ£>cZ15 HwT0S?Ӏ ܛ)T;$d=+=ߣAop(fqn?5}]qOe;օ}SBԹzG's|3TdG3E%w]zMm#ĮN㝇q4q]J%T.Sr'StRv3$&H@P AF˥2>gcr`M Ak>ǯ |X{Ԭ0H5@f= +-瀈\iQenJ#册 2UcHkj?}ЧLB2g+[m.G}!92 ]lVT?U$lEĉ9/~E/bL-y5)(()NсLrXhdMHJVx3`WpU WMuI1|cnXmlUb2F.C%#2a":K7jǻ bV|Ɵ7$׀Mosjhٲ]yC4_%`r\M8{¸1Xst}G5mS>l+XI$Ety\lPn3[3ǫt,GMySMӒW? 17PC[SlJTIgX )shMh|p͟:^kDC (/T+ӽwPpDȥ{ 9w3x7s[D %/|aGk;inPWJ#f@DQ,+R8ut᳎N8  J+ Aח0Vo!Xμ(VI."Ar&)v?x"~ p-<`RPx*.3|f_vzŽ!,6kr\ZSVp$2@y{-ks U)C 61 0yN|T=7M^襕pW?H I1])5RuqFe^D$4۬iHA`yX&Fo wPRO-"4%7 8JYJ knz*/r^QZu eѾ0vR/݀.Y|q&>XSz&DkR瘻S,ݡ1%3Nd+J?`YNֹ:,:WxӸz[f%G|kTjܩo=0!:|{bаyu]j(zϠ~t$]5aN&Mµ`Z3<}$PdIOjkݱdt/X,uo4D>֗)Uɰ=k]YYQTo X:Mnb_AYtvky9O1!,P;TW*F10P4Mh4zsof:huN~_BQm?1,ȜGm!aq0w ]~eiٛX8̌{EѝBk_CGêwKZg4$_ciT~Y=RKT [V|edY?-.U^ة]X(Y׳4]wm:N+7@=8'D RY} i,^b嬢L6 IP*4W#o0I!}?(Y,vvĦw&Jf*NTsz(>Cu춏ԟ`Ck0Ωiz (u^p P:WS pD1. R_yvѻ)lD99.TiPps nn\a.[ᙰUI;Z -nt_LPDKMTsf(֊N6< H/$R>A{%y+бvd `62紤7 ^+cـ`I ΢k?5]KpL9J[750wl{6 DxþyfFH:*Iro]9mIt}yVW9i4RUM+N,@R?wGJ{jJ>Re@ɵ#Ύ\j^dN34cJDMxFcyvLYR]}pμ:%@N_}!2-㙢ӱpJ %e¥(k].}J0Cv̸k~aɌ*~vtr=y\;ByAl-VZe]E.Lgt <lE!!Դ3z;%Voᆰw7!k\ҺeLv?!jq73PZkIt`Xo̧RDK- 8vg(c.m\ӇOG E&ò34]7?ju^Psyu5PymلOf>c~]ԘIctPedI;^Gsc/I\9nXw_T2͙(lO08rQb?GPϊC,hkBIkczv;v[)`^`zgۣڸ"&faR}H'}.E-4`5dI oC'BVIл{ OKfA G 9 YIjqHw-ʘk]9R&zjOo8LP\ͪE}\KN`_GF_ɠ2`g]1f^b9Ӛ0ms$},tQ(=1x hHZbR9J炙E)bW@,)!Nrv }jt G_9jGUeI]E65z2$>StG{$oʶH8Vz,.lN_\iTqK, m:88ҡXFW!묶p)CLV蒖(< *?p9x;e. jceW.sd?f-ޗBBk- d'`a11pbnf6(BL*.6^+%-_cuiݯVҠ֒UnVm #`$&zn}nxcq<\ѹaZ_Bo"σ"`qn=/onP}T'pZ]Kһ{x- R]&3ES; Y.iƒDI@E;K &p+=T$"-Ju9pLXN4 HiΈz =Uga*LvUŠ}P~gr!HjL(1Sck"m(0u ΁1Vݛ";6ymF#,=۶#pcwLw[\A XXKĭ.$$ hшԎk#5 /ʢhԾkx_.ZWvݚ*_["ZnZ&I pbґиC)Rj&3 rgP&鰱H>c#GۚRtuptp^@|Cg'Hs7sk77\Rq+Yϕays_p9SRDLRW}ص̜ژ]H sx" E@o( =h:ApӍjA '  ңr4閨+:@ԹVN̚!"?蘤ĭTZ!P|_{DD+,U mGfрoqU$W3;ftf^X>HH'ovդ7 L ^* _7X7.T[} BTі#0=$w)ҽM] Xjbn@r%1Y\chEaC鯹9G6&KӝLA]{Pae؛qMDA*H0}|H5l^S})j%˜ E|%o.OAg=sڄ]{(%{]-Va24BNbXխ"T; w3AeMbr͑\r1Ybgq'ELy 9rB4a滾s$:Nlh?wƓH;{cкD1q\ԍ T/>5?B:mlA7\m'Z8wúy]`ޱaB'[TG?љ ;v LWi)GLnO 'Xmb#p~/SmE2uO>3{޴ G%K1sdlzm̰0J(]$5IT =Zh_[spW>VMZ"2aHmPru1G߲?z[/hRɉE$4h5t- upDT $7:lL:=g^hIuD"˟" kj! Q|0tL Q(ThX)RJ j?7ްT ҙ':e*Nҟ^#$/ QNs*YO4w qǕZxL#ky"?u|,jG 鷖RQ/KD- / Tr/iW)8MOmh}/_ܱԨ {V~J@z3, d?4aXs^_CH䛂94ƕr# %nmK߬OL2 ة PEl[Izߓȫw_zM>1,aXJ/223+0N'rsdX`*J,ͼwb,D2=8D ?C'SJ_& c ΁4/*cwm v>fUID"bڳ$m@t^YF5& Vg#>R'*WU\qZ*LԀWLHa$c.G b5,yejCq(}fOCcژ9G*I&k`*gW5B9툿CNnRs8B^OI9T6) (Q ,@ؔ:39ŋLXnHL E1Rq;vW8KH8\#4bfxF(kb ?`P߲jQ8_(Qa2ܪ &յLKE쐤/@Ɲ8zM%luT5e(QqvV~2eTdMU:7,0e'mF귈b5ش?T9ݬIݤ9@ ƞ!Wq|EO=C#ex4edH1it\u/Gqii4 ?jy"H]Ν% &V`9𦘅%Q8$Qjbp_7H19?_,L3V'~ # ,f웈5{cB_3S4hEFJK5Xg ~Q楛 @(5Q@{=)#R:p@4ߎjl(L0.UWAЛe/L fhXh`FHFSX-PY d` kczlvfP,>=ltVKYș7 ʱFIWD#43JƗYi3PGꨂ+lVLLL ^8u@gxN\rVSԘ/޾N:_OS'@d(ba| #$P,Ő# cpCa&5ZL ݔ7kIeK$ejb e&UZ|*~XS&6;WKդ(WbE7Ukr'8P{הO}uiQkߢZNXK)HԨG5e΢t}"Jl n6a{i|&Ԇ ]V;jk:`@d vGIh]qjs\jrvKuX|UŒ7wa/JܲoӣQ K OȓdAyU6 ĝ=0mhIP+ovJ n*C8eyxGJvSo{FԑﱣW?G ˳9tu=4$V1f{O'(-+&r3.Ogчm E3]-^;x"2I-F#~&6,gXU1t,=zgggnOS#!V̸dJ=*&Q\bܭj?Ғ'Pƀ*ܜŠkFiҒ&$"о:6s&OIc~W/-j)>,wRò0{he{b[vā00 B+hnnVjUv+ .!]f1 3yw0*!3(4WAd5%|]#`"~fw$JVFm- . yҡ?ca;%LШQbѺj\}<$5Es}X,Fd9E,5m _)Q>c#3F0b,h-/*9WO:H( hmФ >_-nț^.bYi":,"A0!x G&q4e%8}X3*,N S.O2OO_I> 5ݔe-Uu־.{>GHx%39!\b#&RXXbUFYxǃC,Z1h_tNrKg{vnu[ VADi6sѝ*>ͦ{ʛ^sA\˱2zbv(Iv4QDž7vSWO{ZMaJTpBGVrI7.֑.OԾX o`Y G?[$ 7qHo?W<;K,Ix|lPgڈvToP.!*So5X#\r>qg'/p#nCҕl=~px ж#>=kư0f#6ihH=V#Ge{a7g {lSY {JmmrNyU m~μJG'-5#2ԾS+ ;(߀" ;`_T=SޫfNdAP-lK@d'dmӄ1,' z q2!lj!k5?&ڏ!\l"3h|ހeܿS4 5ء/3F+mwỐ)?m35?Qi*\`Q }N,6 پ&^.Ʒ$/ *KM Poc*A>21,1NC`ZV_O-ύ) (НhgKί]sI)Ow0%Av2ўE742M8o'.ǪO[GN:/y}E :aĨ~ s_*C+j|W WPFCް$ {99o_TpӜN]6ܰ-.'t.FY uarMBmZ" iI1O&dA;%WK=7:;xі]RemJ|{(tgHܯiS"$( F,mjHEJ_Nte QKWYBM "EvMZ]Xi'ZW1d7{Qݟ?k cXR{ PToz Y dR}#e&9̴ fuҽ~DL ^(5@ÿCEl:(k!Oa<`HqLPT !X%RB|tQo"­r1gȎ'nr̺CȐ7h5&9J,mQ'c w cfɅP~n/f#ru/E_KVZF m/y6`OHM3#QpR<`iYD?Q4c\Xzjoal$D5w= oap,M@A$ꜧ)i{zd EERJ)ƚ,;azY3c0vauP] }S#O Oͩ]z@wغV.On9 "QU)HH.3j}mGmʦZE`! P"<ұ?K뷉ހqrdu2{<`SA;⩄~+hr{ m\9`' Pm dGwY!8mS?)GyVbiv 0K ¶nnl:yf7(^N%#rv}l`$ߵo‘xLR`A,ztQ6Wg/7sRE{cZ,^:#TDJ>l5~gs G+;T f25܏mn&p!E>{Ubgӥ?@";vvCC̊L?wC%(^I#RPEi)Aia&&,08@Y++HiѴhK)硌 ָs0C[@52mΡ%Rt ˜oZ zm c6%{14lGOJưrAHR4p P:crC#^U'Xw{L.;WM<<6umS-ΤYLÇ{["v.`PJ@|ŹR=PzH&O>X!$uI az B'^N`;BZQbڇWc 'fIyj z葕>g‹ԎZlB[Yy0ATlry(*έ~3f[ݒUacA=&}oT 7z55k.Z1"?ju+] p|+Cn$7'snH_bi6 cKBg+ړ;qMT\{n%t&YR5M;bII>i%>kQ@4D#2Xf.geIb5w qJ\c UA)EPmw Z5H1soEF@|#0!󊻭(5tG{qLvnZU(i`?s@s]dLR`Ob E@Z׷R4 v1V(BnuIK^ G>eOs6$$\\@2t0PÇeq}YD< .t,w'j|-+%.i _d2us@Q b}8 8V#A#$΄3 Bgrz𛦏Gd1F'wV] j!e2Q _!vQ7}75ԋ| f G-QEݠ1at@ųq/PQu*g fN+e-C8\ -66FK<^(Un 4b*]zzuK8Hc'g2x~.}<'wa6GNi~!+liHtd$H;<M<-(փ%crZ8 ?zo'< 8$K~RxĬy-S.rX?>yv5(H)ziLtlN Ƅ \N?i W/SݨV+.Z"CVWPbtMv./r/XiR{h ׷y%1e!g&9]3޳zM/MJrGfՊZ< r*/$"c* j-g¥ nZ$x *W]YG􈞩๢DO'BSBtslwyw[G ;BE5dgHg/zqL6%JTZԕ[ 5~TJaà*E7D7&[ٓhk!qʟ+d?6q{ܕhdAs|L:Mpa=]vwu8uM~};HRo$:ÀT,/48QAz8d~iJ/58v7[DY0'Ʌ3'c5h7/N]Jقn1OEBuOnmA:8mAjW]9e9'źvui Tg[+k?hx@z?9 N!T0!.T&L2+"?Fݫ"Sꂝyz\Ԫ}O^Hp|2| \9W'<6 &p|lKZt4:?ZĞiz^-<Ʉ-}M*5MҺ}]J@z,B#+"DGba=2 8aI&9X2 ~_ճ sLhD&Go5Mvzdѧ7i73k'Sl]>WH&ONrRXϝ9Q+jIϦHwXK0yX1JYW$\n\Af{=Z4qڵ9sNjuv:7!8 D3,"R wKg'eL&VVҜCjq@2oztJluq(KPD@UJSw:7`%PN8|ɀnؒc(ʩ.}ȬZϸߖZݲX2g{$cl3uHdR,!G=WT퇼R3b~[69@`tΣ-+6Pc+KCONCĪHH' %$;)0Xt.S2g3mhCZ4%W9P#y\RiuTV΢$-?/x@gn?-kM%w''e#;r%nAf Sª34vRͿJ[6pq9;z~9G*FI!p9O}E1mkBl[ߍ/T{Mcs'pxV!x/w6qWh$yJXKquR.v((8H#NH؞>*I!<'>w!l<1t6K*ZmH+[D'zm${2a&~UbSo^u0n ffƑgjŽLV]UTT~~L1G(DF0~ݹh.%%$cSNSNm%B ya v@ aSʢh1gVdڄ(~'^+G,׎K[amq"[Đ]9\VT(*+ލ{{|@p͵3 yϿk dM`PNoڲ>wedi|S$}>}'15>1},+$A eiiCDR0K͌!LP8kH+~A?3҂c}^[abIL{(ǁ%Xl/E+Z#܏mr,BY:g>4,(^2>ƮX#bf qbHS SxtTEvA;f+!@-m,\B ")>@ usmu@ghwL;= '٤ O,P)kŒ&!95OG-hZYɂ-?yf\`p;t:퀛/ ȜMCsJ0"f\N7[P:.SG3+4O88wӊ 6a 8FY>"^|de :buE^[-v68d )$TS)gIب$9t%.ML"{EA&ּt;WeiW)L巫@xc :YZO #PE' .Sײp:]3Lk+6Ñ'ַ7  \zO-,CgEW.)[LؕmSc iG4N#Elټ#ǀM"̡,#B8+]P@TJIG~tYQsj}9Z KHfyiy}u=A(ޗZ7i7#iSA#u}&Y{O(K=U3IFDM:֝]ܺ2oK-igB/q#"F#C@E,I6q9]D@{IP69A+qLF(:VjOQӶMbPu@↫8F&x܅ȌD4Op(G6oq|dj8wӏE LؕZôh\*u,ƨGx|kt6mAIE;FDw}J&t|:(aʱ_ Wr}Ttj+_ڊflxNbzmQM@Ҝ~fy ދտC;8'*kL[9UGH(!a~wWȱKОhCxQ,,TCU% ? vrBdؼVU7-(V5cbj#ۙo<]}VҨ$eJG.Йŭ*x5Q ?H,p Hwu,U5^ ߴ/$ر1IoP4.ž94ʦC]=_$p#{|)Q۬i|yWKe4ZJ'ffp]M\u֐GaRkqB@4°|]80s# H05hw9].r7?@ o&(ƭ }3¦pN*wXs~Y9I覲u88aLBgu=}ޱG uT"o|g#Us㘳ed -Tߋ_T3XxjY_5DgMשʮMyKTx= lp!)Gm}LM1@6@$%|l*%8g x=yM+E!ӦkOD _3x{VL71h ȃʤa([eaϷ96fL:3`ǞP rSO3Rb꯹+lY:BOHщmrq}Va$A<>4c";8ԇ J˹L8(Ѩ駃ߐ+)Dti@R'Zf .ZH,B؇ȝ}B~֤ 1}x q- mBJH/)"jH#.s4ЫtQ3: JB0zjÞ&ڠoOhУAT$ ?<x{dAD436mZ8,:wYRo V bK3[zd`x?o`kɔSevoA|\٠?i d^ѥFVY0ZAO jӠ v1BN3 Ĥzǐ4Y6c*2)DV~} (\Rq~v!~ռ#o"kHCP½B>Ʒs]2Djp3߾k$$v$o0;Џ#F[ Eq*}Y*5vd4CCm 0CX]eI lX4Y\X&Ggjj/`2SŒ6V4ݭUz( EB'u)͠1{ϚLcԫBk4$VX~K]bO=Ee6zRIj2aS_JD@xe8d"lr\{U4`hlsfjsi ]el"1g Mʩ4st{]譲%&cl? ?󈜹+/2>qt:jxQ)ZW}dEE5cvZ3'Y3[sJDZ. 'Gj-@R`AatBV[R*󷑱2 Mf?x/z)2 ŝwey>^]헉 w35tX]ȹ8rC pQ8؏o5`{|$}Mc. #V%O9Ǭ܊KDQ*\ر[W$xEZ]G̋RqP3& [htf58jzA3 IxCgAdMϚKHr9˭+MUiknm3?XRcr6 ~lb/b5X@-.z*SV“>|;NB">d}cWK}$e-B1c`Ӱ2wgBѫ@Y+ZlzNepEu[z bsp/xP_AvKlR?Ίc-DdZ+&g}cbV=xq:?vmFJdݿUj9@3b w [sܺ\=&GYi,QonyJ/.4B"#vu8,0%|%J>UY:AUA!֕M6C   YZ