sssd-kcm-2.5.2-2.el8_5.1 >  A a U]ݎgRyf֥+&o#J|.zd97h~R4u}-i41ι@jʼn VmhboxW+mx8DC^ZzPAq߻HG"Nkѷ® _MP?nr)1E\ s0BlOg)y}4'^-n^O+t$ZݾkM>ʘdΆk{˻ĥ+IGb&>hP†/dσFh2}jg6Zv=70ob7JzHmeŒw^0H=_zO84/XȬR= X<U/x˄}"E nŇ ShݟKSqP(4p~ FmjWE9|ҢM;j (Gg!oc4WL5==> ;ްSP\|06G\5 }# țf4s,a ~ya19bfa1735c66f9621d7ec34063877b5fbd6b2d0feeecfafe4e38bef0229e45be0ae44df14c44f035fde9af712ea9c4833e5807faU]'^߉qs&yX'"-ɻ! )btgؾXQ~s:j~ 留t、94h Nޘ"p%] >oR#(v˅0LJTLHSϊPQ 0iC(Ghw F4"C#w^Kk񕢘3t㦶7r! $*A Oi_J(%ȭ&9o֑hӎ&iދrYYe+:'A8CDwd?&PgG&Tu{e/az-7KB=Kel@q07 ~708 I[7`1+yB_;d |Z{/5X l?&-U=:bBuאJ9Y6ܶ@ 􏹥0Y"ThĈSKwtŷv6,8su2f`% f;`"y( Ak ZBM!6NJ>pBrP?r@d   F 'DJQfx   , { cP= D==(w89:d>h?h@hGhHi8IitXiYi\i]j^j bkdmLemQfmTlmVtmpumvmwp@xp|ypNqqqr<Csssd-kcm2.5.22.el8_5.1An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.aZx86-01.mbox.centos.orgECentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxx86_64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi,%8EzځAAA큤A큤a'aMaMaMaMaMa&a&a)a)aaaa$a$acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8b4e29a574d0d8fb18abdee833929707d2486eab2d2c21cf074496be2e7bf9daf1910aac79d4ad74cac79e04d6c198cbeb21553ccdb421d6d0ef10aad71a5645dc0768e46b6eb3361dcbf272a8c4947525ce408ae13fa7290639d7bee9a18a99c2ee0f8515e9ae9c7f6403b8aede78f95ae725693781204cd24869f83608f529ffb54b1a7d7495078e7efcda6e9a9ef7f3907cc54f8c64a57791667e5f4387af4afea4bbcaf7c8b610c8311849c11b8feadb50355ba251a22abf2e5bebd94fad8acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/lib64/sssd/libsss_secrets.so../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.2-2.el8_5.1.src.rpmconfig(sssd-kcm)libsss_secrets.so()(64bit)sssd-kcmsssd-kcm(x86-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_secrets.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.5.2-2.el8_5.13.0.4-14.6.0-14.0-15.2-12.5.2-2.el8_5.14.14.3amaa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.2-2.1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2014460 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing [rhel-8.5.0.z]- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh svuk2.5.2-2.el8_5.12.5.2-2.el8_5.12.5.2-2.el8_5.1 kcm_default_ccache.build-id2fbb502f20603d1ca14da293b2c548abd98c2ffa5b76b0c4de50eb9332e2f46d82d6ead9b317ad7csssd-kcm.servicesssd-kcm.socketlibsss_secrets.sosssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/2f//usr/lib/.build-id/5b//usr/lib/systemd/system//usr/lib64/sssd//usr/libexec/sssd//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2fbb502f20603d1ca14da293b2c548abd98c2ffa, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=5b76b0c4de50eb9332e2f46d82d6ead9b317ad7c, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)1PRR-R RR)R RRRR!R.RRRRRR R"R$RR#R0R,RR%R*RR7R/R+R3RRRRRR-RR RR R RR1RRRR RR2R)R$R%R#R&R'R(R RRRR!R.RRRRRR R"RR0R,RR*RR7utf-8a6d4ab2e803945c0f8dbfed61fba7e23251fc347b9cc410079362d6bf3c617c3?7zXZ !#,Г] b2u Q{LR~F Nj߉bNߨinZH1̽ vjXc{njϽ;]\! Gá(R] ,ᦉn@2oȠ-%_}Jxx뀀Sb8Z 7Q!,$tʽ"ohAWJ<96NjwWr }o%1#+CӪH0خz=+)*g`S0ؾ5 RcA;\4 kokFf0ff [w4B\m>dj2L(Du 1kpTղRpE>t *:q<,.|ENX|gwamr,dv h[cHZ[=rã ̍<{H=Xp\\W+V\XrCJl%ӣMg#'6@XA|x@~P26{A"̗]QuDf qGe~\Mp 7숆Vhar4-?p"Z 8|'Fa5b׺ (WKs 0B#z(umMY/I2<^)` |R|Pd*^.@'~fm.^ #`JzY|ʿU,Y[rj.(V L3QhCx J 6_֌Dt1DWG!LLM i(ՌkmnMCЦ lEKdMH89ߩ.7/f4AjDHO*m~aDŽ-ۇh/|il UȢ[O;D nZD}ig\z-F԰mhK[8 M ~`P E$.  *lT/]XJźy- qi9lH^/Vq3£7'cb)C1생!u(|_ZpY/i'IsAHiZ G7ժ#T3rFl]IaG:2tUtD x36S kla6gf݆.v+t $XPJSbC,0*XЭvrbIjӁn{ 1 cr;V V xYfA6بfGZ;gX% Vo0 ZVʋ84\4mn@EJ$X ~ 7/AR S7m~QMSOJ%P^0; iF qRI6*ϦV'ܱ^eKVڦtl+~<PXSX#rRBg;V.eg{>9#ӝKdgIWy#wUPI8Gt 9ke1p~h*ڂMTB1u(!:^E}ϧ䝊ԧٽ")~(YoktOgfd)խҜRp]y8ׇq(t~y  ,b1 x I0Wӎ25w FVvOo.F(uraps{g Avb6I-?1\Q_D ޾1* "1CAXG .Hg2!ڂtUG mt^5l} rT({|i & F/g$W\ƎTFENG}veZA] NDΘcA% ENMV%,:lTX,_6l.XY끌ozbղafg;c3BjAW;l[ĵ[PMuMM}P@d{3S)H1G \K%ق<~@|[aTs,x6Ѹ܇Ob{ .zbSj^>!$xXp Z)A/Qg-+lO'Z$}scoB*o^c+<8ǫ"Jy g[96Mzp]--j;ρHϻ.hec pLOBcdZ$YEl  q3'175uaj;ZL=tym(eߝ2R^h2k6GP15~?Fؔ2A90zuc$V?xTV3F594βW%fy9IG&OP8Sg.р9U; xE_iMzKg T",mRErNd\ @USœ) tt/5ߠ&9.⤏=)sAJ=lG{kΡ*C=M7'S۩&H:ď#G 1)?/}*_:@߭T@R-\7-4 @Q2[ },/XR1P"Ѐi`oA) jI#R/ ykDZ+Q \)P^N׎",NJ& by\]ʈYwc%[_Vd?poaf'zV` [lx pL'e-~t5 a0c4]QI21=|ƫ/0ֽu{mR!:g |fi˴"3fڛNV 䞝GyZ_ 0[f}˜!) 䍑dU}zcגK&rpP;$DۨJ(O͗̽KңzW~pTK@N!(sLW 0<'^8u]T͢qheRK4e. :c^ ny W-+x^ AC LNclw7ZaȝrP!%B(t8fg%|dlȵ|C{ 󣝬bdx I]T!qZl BZT*J.f7<,//n >˄TiB)$]YNpH8*m|qU\tEQ?l, ]=gч=vl Beʱz@xa(j5}Y@oq(9) žQZG."zg{w]*7HO:\`vyVl6a89F|i9j=\u X?($!3~Ǒi=DtECCO5.N7f[z d KZg r<ڼ[Lp;"hā1bl,lZ2qzP!Q[Oq SHGttԹy9l`LnlD)tUStx@-Dj6h~tXdž\LaeԪFc/RiLrofDJHi]̩S sȹmsd[d`4bw٪+Huˠqmf}8,s^9ٌ,p2mAC R2L"1ʹ\{Y_6|mxW6*k8]N4,goyDE&_Sm։7MYYd Hv^QpLeeQ P̲Zl_j[ 9ܠ0/681v| o}QUøxGIE0|ϒ9]!vlDnGNJy f)W#!k2~ PgAb|5Xh]4)Ė3$caپNiН9%Qd]Qk*^2 "O3ЎJ2Zv1#%.=R;mW1f(*7^=8uNM8QgA&~ܰ;ѐmaSZ)Yi=]H|N%Q&(v5Գ#gՠ0 \فmZ Csɚ12&,zAO v5Sȓƶ}7"5 S m!jj>bz:%Bq|kQ~\!79`.1 V9KSJv$⭞H0| ( Év&= %"4S[2<ޖ_RMs{Pa.FB.nG8J4zK6]NVHޒ<%5\ TG;)!0Ov+iVjпqI8;c3VeڵK"_wXe;0R #Ke{^Y4BqH><+[|ڢ@X6j%_<Y !(GڢsPG:d޾mF AO) >zSn;$ڌB-%$Ypͥ_um[ %$=#ԃij@7iolWHPIAx. ߻~ ڵ] 1^f$3w5 "o14]js0C yQwh8i\*9Pp-d]y;Gv3ګk){\z!PxN  +몿~CP}_;m06{矁7f-JmmZMBiQ8ʒj/R_ !5xzY`,$_Xzd1Q_gG->FT%[n DJL*#>q_*CskgzDjX5°FV|pbV֧T(;Z8vl% I˳((f'?p&q \]hBꂱL_\igk&%F znf& OaUf D0S^c))=UbYلdhқ ?d#+Kތ@1fHf01+{Iބ 'f5tߌLҊҬy ꜇Zܦʟ#zcGS [ *T~Js0!H!~1@6)Rj8Ri|?5g )>b#eQD'Bzc/v.zĠvgK^\uJǪcKI[\2~UiAȄH( )t'aY!DG,${?pw aO>qbgP,Ak\- vw!L+\{VDS=x>H%R/Wd3Sjx LNCG6)~.&Є/b}0*<߼$rС& Vx-7(lXye|pJ*ȅ3ajVn*m=YfP`dr~|/mNgryTN%8d1tdTڥ7/B*(j`HѨ0_$> G㌊ݏHrechFcӯRT ne:OzT19#'r^P5-hx;SlpdG95y$gfcBlyFPb*BVObGv1[l䊓ɕRe|5OHs?t@>_~OX I:8ŦQXWϔhB{C9g0`6JR2lZ"*ZJ4~etŶ[yf«ݝvLׇjΡȱ d%BP?OQa&duaxگ`?B٠Dñ Hgv=X͞p*jG?7=Fm2=@׬UILJ*L* m(mNO9Al;:7+pb+2DkH14arY{x;oGr7]/̾4#Zж`KGކ mNp_̌;F? ܔ5>BCkJD gD^LwNe^ׇxײtN?Ԝmk{U2D#W[_Zj얤'{&3H+{20j\ I4.2T|-;mhTyEY-T`!Dv*79 YXv$3 dD0)SL Og&]Zn `iZVN" {7@P+V$ZS;p/G~s:'o!25 Z/Ђ*&>!bn"8"~!f%1z0ϻ7}Ŝfs> o=& *ʝSn'w-q%%yZC$%/Zާ>GEs殰_N ;Lz0!AUf7S)08R~ ^\4iVʃ[or-@i00 - 9E|‰x<0qX׊+:nhŶH|4=L~7&>\w7]$aK QvBoy@Kq 0{[ۋhqU?֔M Vpyv:J?Ɗ @U1 DUM9^:(>R6i#>vogTa@+D #Hx,l4dW d͒ʏn 5Gnv_r2>%WE=ջ<"fyL(EG4F#abJث?P'#ßei ;1fR5棬`_Xc%NFjBs9ؚ1ڛ9:=vI=I .c؋PNl G?bߟ2r%ڟwMely D*GŅ%r PZa#9ow~qy:,.Q9m,X"9Q>5bl*;U^,xƨ2Á )X[Qr˥Q+{=[b@U]rC̩7#,e }IІO X bb2F2b':_*=r,,V3ooH8I dʣ׀mDZ Qkkj}I=AZv^ooK;(\JM݃"Mc Φwj) |_E;t D_os'ɣ>خLd`[2U8(]bB yVhZST~%]UNz[kgF@gt:!Ca18!P=ͅvi2gęk89,Gp1s uёyT0 |Vn~+|~-=x[xxzsGw$̧(,gcI'u ڸʥkR96钰kql`Jm-9㪧UC,nh `K-[?j/s)%a4H#W8ƻjDswUЖW%'xt$~̅;QPJ onuն xfWMu.XL,HKjЧS N5QH`C*U{ teVSZ%Mڑ-k@F4RITD =كufNʪZ&4*&x&3u%e1A7siJ"%ڕ $bI1g~[si`N_ׇJAY>Ȟz)8ey,42.! F\+m+r,߻I@)D?:EivRFmEX(aq05c~ #C?c$^1R-'yE P9>P [?9vgx w{@Ђc0N<E0C4(o7g](W}ˀH6fym#PEv '+"nu)@F%]*6qãEpVqp)Q64J,u͸;-{}hG/-E ӠD"ӻ+[܇8]#fp#YhZU@ë,y@kn^E!4&;Б3T`zkT}fpkrohswo[B[Ieuy("_gRRM .Ou_cJ4Kr{渤_!<DE;JP#X/b'[haY4v4fl9Z)Vn(JȺ?) j!_Rfvp<$@.KwD] }9+e뺫uE-]*ücK?!T\ˡDB/;6UQ!Ϟs3FSW9"fwjAjeH"'S3z98Ļز;9qIZ@-Mκp%)CWU{G=ȓFxvwO\ vK |w3HXiQ]C}fbzpAi=U^DHUMYdi̅/0H0ƋQI7?X VZ5?Q,B$n~֏CKj7]u< $V eLr rF\ͣMs=`h}Ω B}Qږ=8^LXQBLJqxů!^~Hn[S'Tk*ڷ/E Y+uVf*vH"/˧qH^BftãڧѧʓMx*Vuk7aln;/u5)6޼AyVhľ2wtO5 U/L.6 gGLa T06j$WmH[uY@Եm8҈-eP?lZgq?c(ZoOJw}-|xQlHhvf=tE V7$8[Rx=vSOO:6GZ8 4jGsjvC8LB6Q_`#]_ b99R&7u($j#Qآ㖄*43#5#]wLhpK+61` yWmkbީ޶mpkMG J6Zˈ=ir@hN췆bNLʙ@#2!!4{Of*hq]PKWOG, 4ǠĠFm) f#Ȁo'\IUǶNK8(L׷wcCDfgs$J bڸ]/x. #Q9sߴJmˮe Ti0bӗʪD "Z9zZ˹>VH|g{8L*j-,фp܋GJ\9l^8<(#"HtM 0qj쬨Bgblw̻YgиR-߇'m6toAU!6\\ʽ:pp-B8b;NQ5pD:\:Ir-K;l R($aM;Rs$-/q R]AT (J%h ƓYSQԠ<ihd~d)İϤ8"|hכm=]6U& g(.M̔3c-@,YBMUb0}'h 0t0%vE"u5_}zBIZmՍtg!L0$W>b)-TjmVcsbI0c,_s*&{0{FhgSq4 m ;E Ӭqbc넼]j]+IiZɫYbg@hSMGӕQl9&6ÅCYIFbw~>ԐV-*'1.Wۇ43}S; -~Fbkq':Zkis=(bIR1-n?kc m(`9]̫"nb=r:SPSyQ)妗fEt~&$̌KN~F>ēg\6ڱICxpF“<#і ?ѵ,R;6([Y& Y#3֗ΓHHf}q\vb+PQ7ղdI*m21a:H!;D#Z+zm+.N_iaYMs"؊{pJ_j㞙W/EG$z+bSGb q9~6FԽ Nl*C>KRX@<W,NyƲj.4 ~,pMV-LgSulU3.m3Fǀ=vi)=8ȩ/>m,@s rQeOu>Wԣ XB oJ"O@?[e<8^[O6h V4@B? `h z|%%-#~>W"A5\dzeB_>]~YuQbAKVY$-< ~*9&~lK@`-H!BҹBX2}ު-R`&қ/ Dnsf I" ~MK$JEYhW~[bu\)$ (#&=]O*2HpvvCī>5sIF287x8gI=l}; /pǙS Xn75{k #OXT=GlSmf>9ʘi8d0+d!M˚ ;]VXv}ixR<_=C;wL8 :bIˎx| #Ǝ=RkimvNtPa,ƞ1TO_ѬI(@"&N/:S(ȡ?X{傉X3Th゙x Aֆ'`n%g5!@g/~~la~jÆh,&Ӆ1Q}aNl|B9cR%Bn4ցN`bM%[ih+>㩨mT PnS& -cۤS*[˼%T-D;,2oQ wzW gwz#ro xDȍ|e ] !vJ'j҇/88LM;EV~7%Z=sBak8 72ȡ[7 䧵W0ZYqyCf1G4ps`O ?l-j̞.[1G7`D#mD a>L_ۊv!`HΌچPQBvHr"HM T**?~c$"zp ]ɡp[f]{XZka{~%ln%1脈mI3=iD-7ף9?ۿum!t[lM nvYxHat͸ PrvQ͕:5˪pBշvy.\[9%Da(]q"h'Pb@s$*D|7mY;:3r >2 TasA-l&""nDEeIϘԜ"%NQ~ ~<T3eU[ޓ ɏ%]@ThJȰNpiN%Qa`8xcMkyR~ Ri(l2|KJL!sůs"*.Un֗)Y*>s5fɶ&gA€;8˯-ВIUfK_:̏\}5Ʈ9የjzcN_ȱPM(WV9:G ޙ#o=ɋpoуf͎5v0ꁜ?"a%5V!#^/3sUGe@"{$ 66 uY\1S30 q$3m ͦ8u>b2hE&zOy RrC/1f^$\ZPXqN>LGFC #fgL6;£x3'70v^iZe*eGoRuEHrkoЂ?hPHsd3k7AQ:3C'܇e 3ޱ^;ٔڂ)כKKcj;Q9SJvELq85eCWO-/wX'y ^yt%+$c\c|qxyx=/Ybpz{~HTYYR]6owj28)#&-)6"-ząi&-$vJ ('f',RمSSuq2LyHV{ 6 +wmUr [ח2!EW۾}?Uj٧#at.cUi%ؽzvPAGy, ghIp wS$ONѨGfW3ߏaH7"\b1 _4w+ 9K ᄚʏKuDS{<'xr_< ;^RZ:!z>uQɣjؐ+2GM9ҕ+I%[]kL`]La`2y@V-VsۄBIeExgZ#3Q%X17e߿z۩݁2MhPw'SWg2d0.~s~ F%Z Pb)Y4c5$ƾJa@!lV),Y5vi2!S%uצC~霆 F({^l%JSuA+HO.Ȍoq$9g;Hf|"QOb'tTZSЌM89W'XͲ+dQؔF~03__Z* чXc\sǏN#͚5 A rrei0^'3Y-2H%)+Vju9[oIU4~US>îlrCGv`9'}f/;)n9Ž4XhwYn%Kt̻ huD).Oe>+98*'4|j,oj#p6׀!Isx ոOTXMPE؁*V/xxgd. ]eMZxWg]7A ={kv^]ﲃ~Dj\8>+Cu{:[y6i?" n]N/009kaF  ` ŚƛVL?"tyYʼnF59Kp '2fgnuAh kYϫ] {LoR_N(Ly[ ϞX)DS5|t~Tpi;bG^?E h`cH}QnR_zeO &&׵>BuRG~ڎýzYe5@7qq+מng. 'r3fUާ m,]T"R#-3[}<$N re[9"Mfrya GN +=xC,_ Ury9}nwFTz>*U2*||B U̺ih*?sz.*gUsvw//zEߙ 215v@9Th;#R ^&Z+ٙB ըTRڡm)nF!sh׃׵OZZ!uۯ>PKo dYz \Hk|;_)(侲^Y$th~,˛2璪!`%2(~Is ?+X LN.ğ3#*"+ڴ/u„^?br;E/0%bJCyXpVzڹGۆ>{>jr@?o`{!M|"/4\pa,Zfw-6aĽ@%;YBE tN ӄa?RL*rsOcOžt*qKYQ܏u zߪhˎ^v*raSF .y|Jmobex| ]^mD9xSSj 0a%vS}'}2>I"GsguRPuPe c.X玭N"{:=A>!UJ$x]0Ό3(uyvÊ ~ag> }2-_A$d;%;G䟍k0@ ][c/&BKy`AAN1m YP A}tȑKh ݋,fܺ'in({W[_Yt t8lj%YXKg03ѳg>|b ycSJ2LHʄ;>2gځM1޳CLktExG纬r Rֿ nB#t};!LP-)N'8BohqKLZyGokĞ1Ի@RCԇ_A5^fi |oR3j8\8qoG`4{݁23Z" T&ݮ} t8h/q칻INe% 3ؗP-ipbW=,#rIlD+8 dqOBoHiּVgI%lr عiV?ʰ0P75%嚿<(\bItĜkA5#eYoa^e"a.?]lEV^3>_G@ <$;JΤe#5+*4%@I MjB}Tya(ol:(2GroF_͏Rsz{iՑC({o1`䀮蛅 Z}ő`gY&&?E ldy>tA{-8qfWŨJDP dS plBLT /v=%b VO_·1z7* ґ٨vJ$o.ΞL-] zOrf% fۜ&S b0#-Y[T!/W^n7Or~\RXRwDZ/ ,aoUCTL|2ߏ$߯2\HߍB. ly w/*db,% u {@嶸Fܝ&A^tEDirJs;nlxЦ(1EC2ި*r)Nl;5?.Ox8f+Zp)G*n׮k,oa#` MCw(s1'6P 6Pi ;eY`OoÄ>C^7N+ )T9^g AՌ,dD^իi Cf % p{Hܶ7oV<-#)NhltU#~Y&;y7ϯ58V6-TQƴpDvo( NU @˛GPh4e$ _\xJ%Θ 0Ȧ’pԦM?Lu ]P){Wu@= B96(t\0]7k_d5ꥑ.^h;͈lAA2 )h.SU k Yca\HiE8Dx;Wpowl)_ Ow]` ڈo3nrSmN$ g0!ci& Gw£8rbǖbOM32v~Wcq])'3ժFʰTN(L1\O 4[9T*dȊjg~|k)əEJu=9B/1q%9e3c*+zV>'nc4~,|j`1P7LfB K6\x)Rx(ɱ6V(ݼ[ZzIKG\3+|CY*#"љsm GqJEĴ70XOizitK7w ogsp24ӜTf($Y;3~Xm`rq~]fTt#a{#臈_Q%k\qd nL[%e޽b3yټ jFpXVF b 'X"g{jӎhhn]ħFće$ls:QJ8rgCogn$pj^t]U\HI<7T15nDS%yW!RbØ9 `L}0t#x9Є'hYxq iKve--H`y6P^cݧbrاh'ԖGԦ?FZE`~h9%]X#X%UVx@|à/|_yl?rA<TVdr_P~,;q8+^bx[z[-朸"hPGTDY*;|B:MPh62f $c7k)g]` |ǨW7_ϒB85n18y r.c9ȿRjGv2 v(r [ALտfEI/GR, U_= 3\RT8FIUOz3.S("nk9s.6FrC$I=܍L,6Q"aC?7VPVl3hkϭ} wFqeS?6 P1Z/ZpdJ.u}KN H*bqc >WI3;@VVA]N5ƿ<+~yh{ya?˚ApFJ_.TCw0O'wG{q^(J{sZmkJa:rK%ά qNJ=eDN SGh]?i&ɓh$*S^S ~`ݘ[]vi۱s\z띬`5coUWĝ4A)GG K, sH:9ȡ”<4^o5! b$lvqFTOM<=ѐH~|5-r@>]F JՄj@J?RV߅X S+K*S: r]z* 3LNHRGol G{@Ԯ鴉`VKwnZ`ae.Ű&(JwJށl!W5PVzN^jRSaD:_vHv.moA5xHE",\u'p&e#8L~iYܲ' x0fo 7 Ě& SNq'Y)CH^4W,p\XaYR%47lC#t, GY6 :ת6'{4$s? w}|FZ }KjŊ45+4'*~-1Q)΅e(rk-9¦k]K0 ¨TZԑ: hBD*ꇠP ~&qG0{8[F<$b9V A7M>QGTAɓ Zq[7I^? : UX ٙM<_ڱ_Q^+BAKw#9˾B5fPz( 1:]hrP|tY" /sOAf>GV/M qYJ*]3-I$m?. ^2ӱ8y`bA6ÏtX?7p}*T,!q١c:XAl&#c[fA^ӭv#\ 3GMvh@18{W.1>"ˮ xej2;5=,#Ԯy^ H**/8]~ޛqKy['E_wV/Thݖv3GD{wgJsksEqDil$;ܓ"X3yy?d/kh85GIh?^wFЊmCiŮ2u}Y5[WM<:7$cg oH盾rLv; TC5[n2&C~;J\M?p~KD-Qz'NZkY9;`a2 uAMB0ԤH}ᦛ7cӘi[ҼiC>>B("ӓK~v|Rn؟UW `*` ț wB'׵}`jK,ݓl#ٜ6/C"ӈ.*Z OIR*emBK="/F鱠3[e"CᶩKQ KpZY3}s$@fjإ@44`}½ $. {M2EAѶ )-y]l*QUs8M~1y V1 [ti^lńZt5ڄCx @;Eў]:b_^G|Х0-[ zI4j~型 7k)0˛f_ A}eӏb t&`;$u#uV,;N2] . _8vS0cp_hC;i3c7&]Dǥ"9h> {`Ypyc増тRgsu>L1!C\[&>xk0QKliI~d( ި .(Ė)M>/yYÓBX/gq_%jx҅Sd%؛nD@ͣ<Yrr$oSƒ"]JCuּ=1LbIK .pG1ުݳ)EpZYv0>L`O5OVI@y│7݇6:b&~!2%y uRk'R8." ;rZ쳣?$Ԛ.5`٪9Qt٭?tvJޯHX``,:\]c6;fyܧQ瓰:`ׯb& WRs׌^І8DV##/ϛ໣?}K-`8H*.VV DRc:bavkkoX[oԾo' r*񼉊9NpFc@@' VT&tgX}FR X\2F|n0ɭG97ozy 4K)>׈<;$2vQ]Tɴn'h(eT;ꖇRG$T|UoէPͻz:2.DqAڙ5D)C9dVGJ 3p'&AÉAF"P0#  {oҥ˭?JiNDN03İHS =MJGfcg;֏r<+moK!Jq!ZGyUhxU~8S缓zmlo+ ݬI_Hs BQE(DJ9qX[i~)M!L.%RiOKQ/ڧ{ 9U^6oҥbFAF/TC\?ZA}Я\E jȨhzyp pD}b ·3W&Q*fXfO=cc\iopw9=dP`UI(rexn56><"@R|iS7k';i/PJdDP-S $,ƻp Y8dKl⋭_s\S M#A.uj6:txN/?deiܸԩ=,T .ĕV÷b4539WqRcejkvi}y!yj/~qʧu2\Wg;A<\,'$ju$^qdDNbAVe [Y9WVFޝ^TAs`Jb2wL~ mlc1>ՋJ-G c*[…W.at˿,];MwW ˶6CT<̔`)}O:Gq67_ὤNaO_ Q$5 -hm$]2<€E(& GVQ؜"}6\E.+se+ 3[6I,IŜ8I& ôvĞḐlM)rߘLx1]Ƽ=&m[Zk> f@Yy&9y?4 pw|kEYcWYX^O4V.Gա=tXkp.qLSÎ$$ؿs; 3rb됔agҹ5SULވ9>?meiszGO^KTs׈zvƁְ=$q}qW{۰bB4۵F lȐWqq[]ao@o"tPrȑVW,>+ŌvW蕳J7H`fwn?gФn>츏-;'&DxNxB0_.pn:ubI9(⇗S1>}۩OmoQ=ųt G~EMv#v$"@GMr#2yΧª>n)-hK Ax+<}f,tx"'zXk @ڙ?fǵ:b\nuǗ\v`Ӧ^88PcF@kIljܛ}?XXXIݣDZQG嫫s&`~ s[++qVBi=ve\ܚ2N2-JGk妉qo+;Urq0R J$Mus%R6AG f~#v5sYZx]f;UތC_D$ :_I{5쒱p }!҅ ȶ\ߢC[A[O]Jƙ=r2grS9nLSϗ |)BE߽Ŧq7UmB8NYc@I5U8wtq;?J{RG_T Vнa&C ({FG3i؄B~nߓwD3kN.O.CSh0\~=~GwM$r {ǔŐ 8zfd2a`_K"}ُ8'i!R ,}e:oM{*WKyߠf+f_ċw";@ 3-ήeݳu֙>ȻA;CDMTqJɿ)7yjγ;g n5_63Pp,TPC#:(zv;BBs.031`F+)5 R&m_ =&۵=̉3MÃM!bG{FԸP)L$g ?2m_#7m\~?!S 4WM]\!܉8Cg5dυh%Y\\:!fCȇ3uٛ>-J$˃X7l]7znCWi>]IiKVz uصֆ|AUU?fӖ=&d+3CBst8 {(VSOڪrKqTp{e).p5dO?W5 >M trsn>RT-s\TH}M<ٛ~ !zX5;O+$}`I41\tlW7>I;&?a$fsnϖ!kXfŽ ~3ӷ#'~׺,Ыoע̈78b rBb>kwh"AD_'~I9o敁Zm÷qyk+5=lnӝtO@!kǗt U(b<ح.~[Ɍ[:shF73JGuaE|ϱLAW7zKnMpΣqHzP}V67nѥCsmԂF^HnF.84rMe25uDh#^4ej΢"D9pܯK]rtxIד(?F AK @ջQbśƾ8K]D8L3F~u_E1vqxOKͭLEԥL`>CR FpZ<;l\s&sjM$8n0V`#Xu=|WuT{`mrI+x EgQ9p,ƥpmMܳXjxPTY0@|  F@jnID;^XL$Y95"%]Aף7qY ~DۍnͅU]QIB"r)p4JF+6 igw?'GМt_gZq1HnO-a[Gox _؇jtd(˵n;H¤a2lY4< L^rhp QpE(0t襩@Zjs_OI_ ӭХҲ#[bu,j_6 rk{݀Xo\tnX{E#A)1_(5@7a;6v_1 _s_Ԫࡼ2[0ê 'kI{i]b^6);#u<DSR&@^$2C"-e9ڒW`.67DE6Z~%ص;Eχd3:HtmŊpP ?xR FB}h2^eKtd"ۅЉ)(F]L\ Y#m&T45Wz KbtI=FrDT>%_Jo@v#yP+|v^V'Ai= I x;A컯9MR3ox~I=ne _3_e AT~naJCqqݏx\9oFNowZO1Nlr-DŽM #,]<}wJul_"Uo%~INjd-$˲#BR@[ 2\'^47Sj5t~ywh7p5J;ñ2VB1(DEܜD+M@̥W| @e?.qV)3sPQj N|}{_*~3U, w")4M'GSC}{}\,9>[VWf&,.v2_J:MãhH:oϟS^;({{Cc@5hz){\xVk5t=O V6ԝ{M.I3:#"c'/et' ˕6/Ǵtvpp20%>"ϔeL3 ndH7$͗ ہE A5a&>_]}91= TT,zK*-#b)6 4 #Yz^)lx&8br&Ji-~M[ fiU թ(A> 9"1?"R[/̃!ȟǃY;"zcݕ8 SW(:DoeILU?m1jeuq8ȑW=ϙզ"_-✯{"}o]nKSN!k_b$/y޼R3?N#a髎\_sSPR=4K8jڟ;`*-Rb ÇS 6iE9;:TxsDU5#Aq1;=n+5vz"׸A$l584*J41r{v~S!U>ؠ_m.$5Ee 9&\v^M6^-|97oJTxz'ks B>J ^`ZU1{>zfÒt9rϔC.d[۶xP{wO; #}cAmLZtpn^y6!簛YFgsgcBGiR Tcg_DR.%M1/u? u-R&G=pܜx,pXٚFkBvPJ_̫IG|!,\%{ድj4]Y1uGCp$C+gQ"8ST._3ٜa<Bj6qJvnO* ؎~6G ܕuόTPp˜b_2Of8Z>r*j+B>\:-b(>eɆTehwz`9%1g\K/)]|b47ʢ\7=@4P\.xAZ^>)F<5EGbhT"w\{n䇻n jko3pM=l6"Л(ˌT$,@J0n< T+k3>7ygȄ' bvٺv_znJ1O_ pJE> t`*24\N2>ҭUņ۫uF-_Oo9M!rT#mݤKat66T%+;<Wc^qkkhP/"$r]|.:WrU16(~y<[_ 6<-H {8dΟƫDT kIuOGl' N:Bd݅ԚP/@p:K=xIǴSMw,=Y+KF̴F2/$.p<&7;~UfD2/hYNj ![:wQb6@~`F#)d;( x_Ϟ qcH dփ!ײ)>f]C)M"> D2l3dPC"slB_8yfeNoa8:v.s|.K> ~ k_M1n K59cNDʥTTPhu4&B.0cIKf'+ !: Ǣ暩z&g7->/SUQDEQ})m/ S\@l϶ O,0)~5)N _N(瘵qo;ѦHZwn7lre_OnL{OA 4 3+6HWcĎ 䮳 ,#s6>Бx E0"t\b`;+'ldiuN9f5E妇S[-7!/jCj.wxlk7P kfMj/}Y)f.Hb; ;:J`aP̓wp77R^6t%ҿd?( (g^G7*֏@sU+BŠia!*T(WžA܎aӰ[e&,B&|\d%ї􈦪?g.B؂Sp߳fw_ܐrGwù[[/%BD7&"wl;XHWےQlX"eg)!~/;jEhw-$0"\4Z m_EEܙQL{1%8vRkr`w=LK_z@Iܽ=*=dgo dV2 .bKMuϵ90 F kx+B%48yi7TEUP}.<+-%+kCw[^qCQ62QOZGy^"ơ>Z/ {2G(;ڭp߶.ܕ9inM| `wGDbpDu((.c* :99vAçk=tu2> !++D$ `W&]@ZFBz\P1TX_v؛:I"l2S v8DaNχPTPoٝHd-,c ,&( !A{W IQC~n%!wGv9*z7Kڀ;sz !`Y&GI|+0!"=] wOzF|KL6 Ȧ^=2E]:x$~=F楿ƪXH7G80EYUFtP篘(8^g3*J0e`]-_>l?>=hlQޛ\V\߈YY#a,{/# v\/~+KoZܐ:΍v|VV&*s(j7PTc252b#LTw=Mx˭̂6 Ҷ2I4'QǦL+^(3DƺC 9,4;;/'DZ Dr`* )jN62C^3UIB%A9L(!yt>sϺ8!3*ͷ E~k38g5H>}$ya@89(ݹJqY8PdzQUz)W.rBgTM7G2ȷ\!`(FTݏD\2 Ƿ a9(_Y]b|z~ .o ]С* m^ך T3Ih:]yڴr|NwcA¾5-g ڠ۽?~o}ϳ0a)H>D~4Tş32~^}i2 l(q1Up`3>ak!yx3[AݠxL0X-IcĤB?$I[r>ч(Yo-̲ˎPRq՟D, U\w%%["='[g4[Í5oYq95KS%ʙˋ gٻRHf5(Tߪ謵zU)OGN5hcq꿐y<.hM1$'fm0a;^ Cxz<\H#0k: F'-HWUdC;~+5ix۞U}wF!Irx +/W, ڢzҜS-gDIw*HH˶ BjEH:s &k݃| z6V90']ҭyh>m3A^Z9MI{!r07tܦ|RU%cTU2a\(<Ά®Vn/FC.7ȍC|oMZUI !&]芐G'fsH4𢡳/1h8ȶzE>O_$1P$mvΌiI%ꪸ-a[{guk{{+m} #5)C sXadDbţEls/;Bk,aF1$|w85$$wսAnڞmaA h匭#hka~`"v۾yN#;8 uzN+o)kw^CΚ+,(Z$૗Is^ppܣIp>bKm }qNahvdBYK?i-  Dכ}~P _7a3Fbե[>{( Sx/޵ m+L@ҒD%R^ȸx&9/GǘՋPdM5e/eJ"Ko%E}SIDN[[<晲 ,%qmÒ&K(q4*&mOM<(3hF$@9 HtBO=K[y2Fi#$j1OF!`P~Ya7\h֖R#O뎢Vk'cw|4@Z酯c3+Y-vm&er`U MvTMUq7Wl%rWk)Jenhl}r`qb Cw=Uk*5v0a }@Ňcy 9PC g:؀Ÿ k@M)Uu"W&( F>۔@ |C>$H=5%ZW2jnTq#0$kBW;Wpi2l'1x.u|TƢ._9 mx:A*%@5{.Wd6K+f'lD6T as s)O[J&".^ncβ^͗8.8:T=fO#Εe^N9L;-:#Ej$}~tFxաdl]?>!ԾBCOkuAcXc`5S274OXThI ^.QTJ [mxQ(!s ou4PE朤j;kZVqFqy_ x{F%㢲[u`uI봱#uÜtk(n"|mYx{S5e1T5~3-Ao̗,6Cb3KLFr)I\墹qf/˚H-٢+F3 ud-L9ZC"KY17YRҧ"/AgۯGf5#_i^4d]#U5WK4ݡm6CDxkG:љbw,$ iܫ䨦 Nu|joGRݑU5 :eGw&GϏR~h'm){ȟ`-FȽSw%`Ls`)>B=2dky.WSQ )K@9ƒƆ^ SiNq\îAaJ@}VCX-b~2:,Qq<, ɜYaWOa4$ߣ.FB2=bӫ# FXAbZ#c}RmN=]O&ߟu lԨ@B=A`]/Vq_!u1Nsk[X$htq51 1ej Mo A|1 `њ]BQ4ޔ~,*=8xh7YΠFnU/T*c,:G=F$aD*6LmaJ1ށ5O|aؚGhӻ 敌}-~fYytKPdz1οHWhŦu|?R>uOUӖd2T+2+9%$[UnDǤqE#~dYas;(qf~**ruYT#@ ! i#=\@ hQD3 ϟD,B01m*lB3DJ<$:냉h:)Fand{ȲȲ ֖rosv]|=,QX)wd:)/b-'MQ\隷<_ eؕ24q8:cask[Ͼ +օap46 ~/ZM/FRh_g I TcOb=Jn2mU{ GABrgq4^^9[]VULИMmwS[g#MK=\şRha 6-DRPAqL5^# yE}% AbȰ3StSIL)X //`lz8ο;rY56~;$ 8.œV^=_vq%$;YQ5@vhßTŚ;AL~ԤUcal"XKFuѣhX:ƓT]y0gG\ WZ)$`:2̿[,<'\axGv͆>Vv1zF0 I}َdY;m`amqj##x`MkJ/sqCk̝չlH 2јf35\rƜ2wrDcIY%̈m9{urR(do;84{Nm0dm?iߞy3w 2ޗ<ք'HUusS?%&UĢARP(Yan}} 'x۾m6/6Ogq +sjyL1A:!d#Hʯ]&k&`\_KCBn BcUNLKtw"w߯X0 Sϗfu͖n]VF; Ҋz)WШٌ4kD f{-b[ U!ebאNޣr4W1A\RͰ 8,j]Ưp;t h3?s嫄RHDOt!C66:b< K΁14Geis;%L1K\S*:+DOW/Gg?7x-Y-)trTdodj IN !&bNi 'z;r67CB Z_if`?~qhiq'N{v!Ff *%?NY=Ul3X(2Sn(Mj^ďkx"Lp(p{YliG͒@:k3ͤ^Iu"Nc\AL]ʾ:9vf[f&￶ĝ奈l=Jx8:2\)D%^-`țFaideb5ç:p$E%a_G|h'o'b=/А*)2҈7$o!NXkBauK_4$~`ЪS`NbY;$9,5&A5_չXv$ES/{Z33$W,Y091 J]~,-]Jog!\ 7WP"(#,v?R 7hۤd0_9]3#w"z/1 CY'Ƭ5w#w 1ƐfnuТaיVAKa4E(UG* 쮯n}\:S<%Q>C|te7)B?SbK8m]x[֭CzŴ#HM;#a}db mnnY.ЍԐSy1A=L۟7rGDQEKn ڱnY&8:dSUܦ,}QɆk$(ڢYX$4މ}7k.G~\jq|8s+M?awn,  CՃԮp,@\4h )][3=}˳ }N{)!^GeXZלF1ôvtPqAU JC1[L@S*J#N,Z@ovtEhWXRwbe \1X{MEԁ Vv>bB=^8/ۋGZ5蚅X5OQGtf@kzq,P_wnpXHo(\$ LPYu,ޞJԃHTUl=۟`x;-{T`$Kg,9rz MAtLiBɪurviL (X,Q xVjჾc FӐmq7 y:|C T5l4U.Nt5X;+ d{|$$x%,+6瞻]Jnh.WM#X6XA`6oKe^Lx HzO&RCZ+[um)Wii[~6pGxP?[Pݬ6qHri]9J!7L͌@|q%-a&AVxd;Mp Ej3R79ji7__oXo1kyMj G,X,IG)~fEE~%|qH{4NJIգ)AYeS&ޗRe~z{6>m1&Ec71܁WZ> Y`镗$9 ָw~9F@ٞ3|7fm{Ӂ()SǕI'Bh6q^aA?Ŕ\~I}v\w mzvRC:o6z^Jy !l6jx*9TJݲk{ytuzā7օhwa"ihȉ*Si: [rUW)NpT[5HJ)u( ވ %k(oW"r+38e68Wx6ώL^_w'Mm@r3u_eK?E35ʘD_ŔGqJϧ;yϡ# cfU(g 3dxsCz\?W]e(FUԧzyFD(w1q&/4"I`2o?WV+5߀t%FnF6c__Wn™*iV# M5?&įY╧[ 513_Yi'-( 'Ը9:x'Dr#q ~& e:}'] XêɋwgJ g.w WB.݁^Ϩhڋ4>qٛo79 CZmG_x&ԛ^ߔOO:qA9pr"kHgeN,eC"390RKJC[J\^DާEx.ɨyW{5#PusqEc<'*\>xcPJjK+aVXsN@$CD/qo9VR'b`_G5틃ײp蝊H2QrEͅ<~W|WɥLR3QV{կrP%ǓtL@2?{AqS@!aSw7 m@\ *o-nfm\ޒkɨ9A.n1iod7,@X#-#99no-~enDNcHljTUj|] 7͎7@bf pee:ꆿR·qܨ>gZ4`hЇ<#RDK 7G]l: GyJޣ~v|)g#N hflBL,-L|" fd˥ȾjB$Qu&6o;_3~Qm],2l`$/$KX*TN˟XUG5b3uA.oޠt l) ;ܵ\O l:So 'nܹ`GuEuڛ@[C4E ؖ"5~^\-z,SCՒɭ3)JuѲ7z 3]Z6`Cg7UNi?\t](`I&B7(ɷ5?b FS15_#W1;TT.tS+tzRᇠa;K <$X1YAhRG!Do;Oe'XF_rgE Vq]!D ݪȊyCMկ61/7_Q.,Wy50WQLgѫLMiTd}DErU(Xumy=n.نaxH3q5T21p Bc6^/FѶB~qCwXCJ~Ei*(2-qp" z VbzMFaawПеp]OO^=;m-:LHah"4}dLRվ`y@?ĿoHJ;x^:vl?au\oFС QWL]=6x.?)=Xk_9k FU(b1U3b fUӷJVV &!0ߡJZcY#bX!g 8 Rt߷{ uC,)wPħ=ťs$RţJD؎i n<LX }ᮄ}bO̕Ӫ>3)u8˰ٗ%4H808*dFu0bOIдW,Ur~af._>i.vDbM4Sh!0Rn~rSIc|s8sM]$;&ۘ+ǵh(VpZ+A) N232'kKmN0t!,l}"4G|U4.'F.Kf&_5B:{N{5_K_S$9Rb_>$x&;w+[r=iq- E;ܻ|c;O0@4$h(lam~8n)R7$^|5C]GbظH&nf? DvĨR"~>D]V$F Z#g?g53Z@UYPE|tbi}}?lyj!E}3)< lG4"r>!ܒ@ITuwLxrt^@%數?lnh!N-vcZWK?ث&el}Q u]&~upߙky{*de&U?]a گgN ruh .hw7LEV35u-.,hTK$ `IX]Z]Ht i$>ZӲRs&`Y pT^P%xP3^?Amv`sg8ĥ+Sب׎a9_ h!9'hHKo;9kB=v/945o hQ9 &BIG˙dUNN527Z dW:{Ɲrq2Bl 0,#.3@B՛X&vy/u"+rlWiQuVY>dNV_-1||Ħ.znmhK3hb5_!z=$ѫܧXL4u;- P2?Z% fI*T=IBXx^#uܮU~[H-Sjp{!n OeRbP'`Y* LK' ӍOJ*kq@Gb\?|ˀ/Jh:d]N}cvF7l\ TWr*梧ܲ{ Ŋ @>9QSD`zIW!2(䮧PZvG7~T=䜙5"S @ބ#Z/VZXp;#ܕHt;NE Wxh ͷp܊J;Z$,w6V|?jVO6xDQ8߱%;Puq VHbv!νĊ_Ql(ޤ xڞEX8٢q?J+=i1=~%$t Ȭ[2_<98Y_*{7[fmaꊠٔu2pr[Yckca/7ˠ:YNaoI]/r 34Bܪ;.gd)-wPJoc]'ƵJwYm6C%R^,42s86EAY'9"bR]Pq`J+d7Gd):r\+ZThH#S+ 4 $`96 MO3[t%rR[n/wLL?a gU$VhCdݳ+w2N({G'b.iVOZҼn$>/)E gK^amvNkPJ[*Khu3x30UaHX$}M[ VEFd9Zik6\_؍6ع#9.?id&51;df4{"ڵb/VH(d-ciNqB\t:]~[wicڳ徔tvݧd`<\eoyB˕窹d\Oa9J%J)A.mlLC _ZE17Ud)1`bDI 7 ^u'Ļ%XYE`|z +i$H7KgTYk2!Q~ulHWO;ȄҨ$N^໢zY$fk{)ʛvCfۆ%Y)zcg)`Rum"7Q {j pq j3&$=f]nq.iОΞJ 8{ypAZӄ@q _Of`{u6ףT1ճ, jvd%#uo kJFfHpHJ8V>@=gk O@X6a-6>m$K׎gmNN6Ymp%ϺrAl+2@%V:o'*Kޤ@˚wیPeJĥ0&#WgGc;}M>7!X0T+Ow̗GV6YwzVad J[~RKqMS3'hs@M"|)YeBS V"f'HbL}&|Yuqi{e?*~;324+SM5 .%@e8P K(7~K)f Gi1~pݚrJ6C?zQۦ8drbnk.AE7ɠ'vU*\"KE30({{'F~fnk!]Mi=%Ӂp"1j'`~ $=>ld}yEE+ғcJ + ٴn]VCw~Ioʱ#CVtj8K7 ޚu-s}490(6= ytt_b-;cjBRIң 3?N!NRd YБ_VkX E^]&@,H`V}4ɣNȼCD$踐n _Tu{0WRI9U\vʧ;=U=>*~ZDS(Н@nu՛/-d s_.{,eAR+񠙀% ݫ̒WSE)D{hZ`e`6xnYFaz/aEw|~,,DcbY~46xI$qu$ԆT \]X^ŷ2OtpξRIކxU_jhk_= RKNjI+0(%AǻQ@>i"@Da슠du: ˺TCx7V(qN4\;@k3g%H i1-m]%\=Q׳1{2Խ"eXq[?&T̓x?B~A W:>gHC5MV55^yRX  `M #}TJJzJlf 1,ruǹ>Ĥ67Ø}ڏ1C1\t_+ު/!S 0µ=2. E1TI$l=?RB*P*Q:`4]x ڂn9Mw 9FayDoR4ȁG,U;oCγ +3)W°!`а9M#fP, ) xc) v嶟F]^iqn8;xP xHv75m1l4)bo,J>iohBx< 6u[GFƆ:XZ6i=G%K>O`QhP%M(z%\J=|إp"3BSWY0eX`hpԌPX;5eqsR|s:L.f+['/M/ftOglG'U ,XMnH8A\ M%VF]q!7S'T$^1>RZL5)7(Mz3& ##3hui9E& ^B-RVp%/ȻB pm=;X8îIzƐD^} }EC a0ѓVh3vzz?[|=Uo45Vg,huTWhVȞbesCDs6wsbe\ wp*3W?Mْ[">|L@CT3]Ǐ4K#SwHe'ydϦVrC+SNuTP0>xƈ?E7`<'jDŽU.zʞzSUE-zUV*f?Qn nQyͧuUNJSF)}F:%ôQ:s/M= dyd9a✚!aly D |Rm:RKcgm KrDzf!UF̉R~%p%qď&1ؚ^Xx*W.m~aFCʐ?圏AyBݡI)6_1$" 6Wջ158g[eSsLHam\ѐ~^L M EH[hfl!Y@!8W-MZ!PUNPvDFGy<ƁB r[$aLDk҄m.A_>o ˧>>O@ w,],ms` HڣzDˢb]dVRg.:7o2^ {LhL juH x'G:n3JE]\:^rJŚa,bM,ؘ4 QcDAN3 Ė$E o{|wZD`@Zox؄$er_ Uptp0WV|Я`\tLESl|wyiy5mk}ۃ$]?&?a 7y`՛W(IU n0 + Ĉ@̖2!<)㛠/9*xf`舦>㵨7=[n>mԪ=)PbMXu YKPN%sD?W:񳘦AwM;h4TzC4?WE v T1|jIY|ɚpй'iZ~)e1 kw놪麊rwRv`rRfc,vJ:R6Q|/D OPHGп _6H[R4gL}R!;Sk?EtrtGpHa4.8q*K]! nu>xPuPqM, vvyǠ>SU;LɮQRuS7Gi@8Wņ.g ?Z,g y pUC9%2}! D̂1AA-qWlJX'{rcDZAe{[Y9U8TEbگ4"Rť2a]Y7dsz\-)$h]8J:=r2sƑ0@f0d)G`GTcy!mi-Q3FnEʁ(5n#w rN!2]&%V{ ۗY*Z@g޲ꇶYW ׷[i`Q> IAQDٯLYLqRa ;$|픛G׃m'{z.|6^u8rO-L6f8H47Yiԍkm8 #NJHc z]l#:ax>8BiJ~B鯠n೟󋳝֤`l.Kbul9lyMs| 1:ęCL: qvFZZlڔ;0\#W\324|V=}= B}DzPAУ܌WJe>)rre=e&Ft) Cl}]3ơ=gDl#ќ>\_0AdNBT25%ҙ#vthU* p;^?D25c[J/ J`9^9(g٩$ 7_Yc?tG*dj0 ^DXNǷw%P)Dm<@Le%s'<U[JdI/Kyfx #ψ_\}|$4)b^%7!á?+t,-bv2-EFaN^kSu"&-g?LiVBM Z%<.Vԯɮ:KD|C'"A2jPuGǿe.&kۦZOZA>Nz+U8Ŗ"vz}tEc18 ڷBl\4TIb1d=KUFqrckCEỜRVXBwKq!;eRn&D'1Y*,ca(jԇk=,kLVqJN1D/QyC42AtVHrs<bd1˼CJ ^ Wn2:ӆ@~7eЫuĐXk/B[rZ=_] mfCz F.pգT, qzuW-Bk|0t twU?k()8AY!Y8H5"RӸ}+/Xqə҂>]ӒC?ld+p"v'4teyxk,. y!F=fb]g k_7wO8A'DR.X(P,P9*|m< –Wx;!?ꛈQ2\"WVGκ=+4>msѲX{0MMZVZ%+QT_S11~(ʝwd!Frwm3P{L6Rw'Uˣ.=bŮ}7:*'UkTl^kF4++).tbn\,,qs)Z]T;hYL˾JX!l0NG姻Ik\`3<ܟ #SqKā&b QkyU\7X2ګD3cEe:qEep t^vj^pKCis{' iuVHǠCBB!K kvԫ0' FH SiY!STLyKkX- <Χ $u.yvȼ"7F6#Iz.{%[Ej=N17&'%)a2aTX-ua`T)&~[?MxGA ] k`*Պ\OG|2:iO@9XQHsEoMyț'sPÏiӊPr/>ڞF~!4ŀBI;As#mU1vX1c-=!u `_&Bp*zrTݡXv&CV__aV2>i7rC<^^ ){`2NZRtwUa5J wJT¸XyS}^lTiCg2.<9j:)TO+QFV!R.{Bf:*sA7?Vl Dmn.an6zkUݿb HnjM+Vc`F 4l^dW+ >QL^^4^kGѢyDuZ%VIM'ft쀺st/ˇ-{ 325l3љ>6O풯ܧ3xpq}I=ey$,R|FPŞtC)+mC83}6Gu]G4 ,gcxQ=Yb? pCHvڥ'9_l>9dC:,tDqE8DOp& 3Xiα/.^ ]X~4OM(O WI5Hfn.[ Q e'/. Af>g&i҅AR&F!Ov00(4!2jZ!2kE7=zVDa>z>0dmpV `.4ޤ2L 㐞v%xEH% 6Q]E4]gm&ylVBcn( Qɔ׬*7k \Ε_&b)Vim_1D D&jqM,Iǧ(baoVh; Uh)t*|\Zz 8yamhsdu%hݓz:O.T %}|.2H`J |ytRjǵO=W&Cq opAGOnj}imlb`hUt^pf{Ja+^VGNx,2vΧg)aZ!Kݔ {Rn>kx~olfCqu"aaD5޷` .XGVh s W5M ukLw.E *U.# m ^ n!B/tadmA@0\-xpğ`0fwIY 0*?U+eMBԓ Vcxm x`Eg(KfrF"ǐ>k0̠+m(YPp[yɵ d`5x-jpO֗EqӧBeBIC9D8*v\ ̂Og)0gy DљI:^MQ(䂀mO2×M{:Id MȂ _5 +oU v;}?T{F,a<2d(!7;ukJ{D@oShkǒ$\N :q Y؍]qXB)z PA̶L>#J&صm?Z bT#0rg&ЫZ'S^K?~8˵,£EOdPLK/>;!Ϳj&;#ǩp򥓌 /DQ;ޒJ๻FtVmn{׫',ː(Y[+S Y@BEջ܍p{3~.rh}XfQ29zx(ݳWcZOÍRx§;)_l}o6#&A{?8`GDe%|UeE9oG|WZ7phKӤ?u?gdTQ0 THye{;TGI ~TbQp,\i}uTRfG -`r)f``CQQn=yz- dU됚`y܉Yj/! +ڤ ,ⅦE‚%8 ;,b_S}+\igMvl[x d!Cՙ)dۀiI91FH6mV7C0$KkL3RF0oHu="~.y;$>5&ZEnF=wn i}6qH-@|[7Ÿͩnym Z[zC6SNC캤PX>5ЦW'>S|kd3qw 亽P529}m8XoxIjrPa1H~\)yBL[~>#xiE]zRaR誯E 8-4!DZjhZ_68aJ-:^Rj&[O2Gƭ翽XAuI,&7Ⱦa`6f5sa S\Y#>]3*1?7o3M"tgBY~'oBɨZ$^R˜8ӀgX%?gˌ(w~tNYܦ'͙"$r8*%tC)4*,N :.76jҧ+kc.;XPR>Hk =f_n^fs"'(8,0mF9",'K` 4$;ruVDWB,rZmP m;k8UN <]fN8齜۞YNDM֊{%Xe26h_*rE=ZL3eDZwEN$& Q]h${7m.<ܺO~XC]\IPF,E@j2~eM6ˊza<ϳ_N4W]}ր4}S4km7P\_ &L۔\^VAƵ.HJ3k#p1:tʁq V ).&_!U`X l{(,fpfIH ܈>~v1PWӍKG4U i^~6D6E }2 MzguFCf 1BR[gHy#`ce[mKsE1 `> =Imh!sH则\E5ߊ'P'ۻv`OxTaUd-,gC[)+Q BgJjQUgYbȬ5l=Ed?(kkf@^daFI72+f @} ,Otb߾\n/&@edq[|mjcC,ukc; JuP]ؓjtFk?f3(:Qa[]Ev񲧫e*.Pq>8yeޓs$(cUoZ/fg״ @{X3T =2?G܁hw-V9ȩ34f5!^_Cyl#9);KP"!-'d7V\K5(h 0x.q< <*uFY7~5k)Zj1tkW˙ ~μ WRZ1(aPLH9\oE$ vJ 625w,Ԫ=_#UE32t*% $= ܽb\(\i MmiS]5hiVxvMx5q9~(ǭ `ї1Fϖ0Gr 9ƥbb7E%ج8˺]3hkb)9Wo >儜~%mϜmu]~Y+7>F}خLJ);E>ߖf*a7 -J-͹ٖ]N8X?s1MaMI:iqe=%E2D"해Pm"d.ЎQ5 ʫߙg։V;KUǓ'[^`A>+r`X^$k.% ϜEϱ/Sb(J-JJH#G2Gi6p5jcnglIShzmȌz3B \gІ}H?PN4hO?.Bso$ Rqr]&I'|צCAyN[O3ƶD~PgwVvhFtZ2 2he_uBYj3aRK`"Vi[v:CY۴)MlqKV]M1G& Ⱦ:\ɭW6Fj:H[W~KdV{uژ=ʊl}ӣcrhXAK|b/9^ٜ1˘~`r==4ir 45qng:BZ6qv t ü8 EHQRMNm;dܮQoBjl 웭q1%8CA1WRJ&0~O)FvqQEާ\0^`=C._7|e[9uPagr%_ ?iM4P!nu)h9 $|Fִ #luFے^zLo.n՚ŸPK%Pb0 /N'@lNuD<^DZHAvGhuO[N|a~g"<~R\)Gɨ]b[\߼'\I욭U XAV߼_A3k9'x#/_eBY `l̋] -ZЇԚ`{b`=Sr4*nEG+NŰCA G`@ ,gcW=ZdvR5ǁm1QR<}Wѥ +!o{Sn17v{{G$5VLmh&clA(i2ߪ(G_v~i*m1.\=⒆+K  k? YS.[qy\:Gه o8#_f}+/55~E&hZ_.^=S0  o^i:F DAJbM&i"y"mDh^0p`"Ef f =QNzֽGoXӄQHMNwrIlP)5YH;xCCU4˘;_˅EN-8oKN[p">[vQΫg7jRK7{[;G>ndJg߮)JP2ac;Uk^K^!knPJF}q5K^)QvYcRO{}N.FC&Ȁ!>}L]W7dwB]*im}M :GthWNu+K_hCU0HLED˧kssl$bӳ Ħ*jyv5&Asz\]=l6*^ֈSFŴ]|c};Inc?:jg}krSY9nPyۏX}b/G}3$4Bs|TDƉ#a4P*pCi%בi"^=CU,Թ%3}:mcu*GISr'WVJ!5B46}ΌwA6] Fbc^7J[Ep8n/q s֛KӍ.Jvkϗ"Sl٣o_X`:3Z#M5[';rf]Ne0%cT "C^jB &QT2mD 美dQlR!(-x>%>6Mu3}i4i~|!:Bު_y U5"\63GL@5O{"zWW$s>oPx.NtT^gPhkRl:bv0HiTfwŚgxP٢;6}K7Npt;w=@zniw5ltO|Y>gx{,k9JMK2Яwef 1 I98eǵX rT 0[ 'GL9`U8l8:&ڌus'2FWBk03-LQk oBeh!dŃ{$E=RrEb2 LY{@x$j(HórQmE6m;l0.F{ZhÙ%Ju3x^, 6 jҼ+iQ S'FcE#ޝƯ>T̯"?Hu2& []K#* Fo7vJ:q1(w( _}/< }1L2M/t@(agM߬<@>:/jZ ( I8GbMq+\>ag h9}s#ftK$bTirJŧJ9KP,5gvNZR-kA{U 2_L.dCбDJdmgeb}_引k쐖57pxY{6mǻR͍ч4^Q;.F]nD?'}=Bh=$HۏRm m%y/dDcNl~tC+{V0#B!["j%E9巏[00,4FZ࡭M!0A ζ5LWpQ&k~מt3rbWqUeyGERMXJ߭ȵ p ǹ/?+8W c (M}v1@*jpǹ{1 aKWF YaK(s,9sEK;TQQ)̊B8F`,w(.^ +A1^:AD%f[,5d8t2䪺H.UM ; t)&t 3Vilcp^t'ƙt=_J&C8ev]I-߆:r0Iܩ N,M{MN/ڄis!L ~~6 KSW-i-֣lEq~[Q ?m&nctQ9D  w%nj؄9_Z^C9WlIVV?ק &WG?Fe~efξSק^ƙGyȧEӲzG-^JTayegЍK!u'CzL/+l&b[t݋JL%vRL(#3ʽj]]}LH{)~dB1 >w*$*A!m;ِ7"B$M<~F`Y3MX?` (Sz8Cmf%q9vC2ʳ\V>I@ŗSA!Mařc~Kؠ&ES6lEv)ӱ*.D﹮rE܄X7< H:6x,dNZmvDpw+Rv:]5t9p{d%4J(ݜp%ٛm#pvChWg1 qJ<_pKu'ےIXBUGEC:w@ZȪkE 4 J <~Cju!ſ5"ѺB i,8nw=fa|P{s\`Ӱ%<)TB_=wc@.!lK:u{ VWr¼'Hа~AEO9Nc /+p_4A6^q, b%:WUYIVqrap*mYl]_1؉j_ӮُaS:|/k/#6cE `SA3vD:8|;97\pKG̎赾Iw9%,? 1ȐjNb~?3 eJtލ9/kи"k=+q>ϋ*a+]lC!4Km} A>GHv!ͩX$w#:ޥp_z]'ZufVhUsEr>l<& A cﳬKv'ɰ]9Wox8dQﯚ4&:Yפÿ[7_m^zQ׸ٴECݐB1/")2\;td6+-ID^=l5j&vDBc^K6TXYB=Gw"׉'DAihy5la Ebh2BN C^IL*@: $ːib^8ˆRQʈoM6%m Woo! <{>(]-91QAp]T^+Uh. 3GS5Sg)+\jPFDo8,:+d{0~2+>ݾA"M $mG=KCY 'FVĆ1KnB"}x)+U]9g}P\z3{Bz +U->@M dr_տ,u[%)s{_Y8}nD5Xw?#pKb&m ͳ~+C`8)>ʡ"s֗ =R:(17g _9x3^~t! 6#iz۲}&XΟpC/pL,p.(_}UG.sε9;}T7&O?O9[%3mZ>!Gɼ4^xĺp%GFŸD#8HuO:mˆ/"hogmwYX8Ǥφ 0ܨ<ؑwѦX,O*?G0i|zK im){?8#EqS]ohC%Rj[?ã Jf:{1ɮyr9|wZF}oVkIf%pΎ#+&tjB7ú jQ?0#y o W4 fX^ ؕ~'+=tM{ҝI(/꺖*^)]K@ }xNLTPs?Dп1`.$%4_7 HG k7Bp#@G p]~kpWy?T7vxyB%'GZ>u")E? v:i5eJ@r}˜ߍY,!8)]SBw'u]YխmoE amT^owP5*i^HЍ$ el6O ן8z:QtM#MF,ni%6WF7zy=(Յ"ĸ,BOCgP"PɈwΞ18|IaU-5h KkWy3E;dSm sՇ 7י9[ߓBvB36 жczq9ӄ2}[b?> ZN JԐ75l爵(#T>GzCZեJ~"WYdGCT@^9Y?JtxzzȴgqE:9$רg3cB,X#ɇ3bY+kH:N4.zϋ(utO"$ߋ9ͺPa{?ktgf;`爻iCSsgL/T 6|^}'9SN0ʴ3<8_̤CH9K!P]$צwySS#!.яUL:foJMy@l~Up9M)t ?Gy7ߖ6}=ʢ}WeOs-8wzlmX t}H:"ڭ0MKJe4<ŇHga+$J<_bATomI6Omte/r\̤ <>,Φfl̙^cE V/]?jޱg$#OYy Gҟ_(qm]bTNc quhodmie ͝!jb2$:Ę %NWswK%H (.9|PΙCx\2zo`" Ni =pGJ;D~̼cZ,e?_"Nr.ˑ[E$SJ_q^ o-0K(MxmwBM*Y րΦs/s f ~ s- %\Kw+Z.KV%i]7o3X]Yb!4sï4϶1rZTuTZ}<&6l_qa\lr;@;]O凒jRn9wN-~X2̎)J9c)OHR+<{I耐[y'9e2ys= "KEL0Kd3HY1rYq\4F7g0}6yo`c!T_ݑ2ddNVmg~oe`0Vv>w3CZBJ_o^01Dض7S}~*œk6pn/Ug 2Z$߶aQ>Ɣ#TėZW<Ǽӟ5́xS-o " ɦtGOx*Y،E1?.V;6Wz&3( v(hfV]LuH"MB=(p8ʬBOV/ڮWWo`ˢg+ub4_Püaጧ[mk./ϭqu-x;qrp[t~3.u]Ati_ :dk< o IZҺ6TsʏZ#W~sYJvC\fF0,Xp>HA%F;o_8<[s=?Do%$PiOo hXƶh'IL8U}qUvNS} 9@c |t0]\)C"0Xl|&v/jݎXZq/72W*s\^ {D'񃏝eQdTErYo'3DXO cDt |+*XOM :m]ip2]g@[qe $($TTvm ,~&%b(-/5iZvOVPYz74K]3~e"LIƁ®yLx#"a2b繠π˹8'`l.e-<=+. ԓ jm%|+W/٩] H? o{pi*wܭ Z練x9czk?kJ5C;(FK1OS^~$Z2uw?ZƏds4I}5:mPC9 ߰ q%m25hrd ɯVHp}~5s-yZ >bAg޻9=U?/ʓ2 d71eV[1\ 3mJ=!(+r79+O܁VSkrhE~c %>NW:$p1m@JDM"4'R| Ơ-._v|pC&3G9%grb5̮Nw$M)3\;.b-߸*6QYF2:Bs&C $N _{ƨ4!An%by ?쪠vbMN46C[cEbU1Zᵓ\,U%yMuJyX9'ٞ?;z01/ 8=Cp-wp?|y7 p!wqg[,Q~kSdtaVؓ}V9Z/BQ>L ?]+LO+6H MѯjG0)',mSc<`k`CBf`5Q>]eS#h ke)&wV2eN&.R)f|U*ۋ4r',᫬, d<MƯkZ`zj+ɒ9 %ywR:5S"*ɮ&EkRQ t及`/ hn"2ҕl(,ÿ M_L}CΓr@U67RҴo ݖj g|%ZJz;Sd飸?.U=CcF6r%Z88"ݶUD"r=A. sbOw4ԙI@! FшO#)}v!-ǻLy*(qmd <kxމ)hFvǞ#V+01Ŗz6k=( '֚ Vgh|p c7=#+,Xx;\Y 73:$xAG%%ЋvkXgJU=n3vGkFa0ʨnﶎ)׼v0*6ٶźGF&E'yp#QhSz\[;RR6P(YuD@= QAŞ55D3+{[:d|1hq¯{}2U^MJ_'N7ߚ-3#+(y \آGp|!=C*> K-<N3{ :`=clzvHQ(gAdPia1j\7 kBlv2Y9[C(4On FCF)/nA#Kbϝӧ$t5}{ 7- Z~ʷdè(pbG3)9ješmW;K=w /$9B{DoAՂY8M;FAcyNuǿ"rc߃D"ҾRhXedbvef@StE*inY {$K:UHv@g]+o[ED tH>-ymD1|6G`1Wyۜ$9| |7Suwyd-ZrDW"00S;bVF́" _j nz3DJᑘC+rIeg6}12`taCqگ6n/ ޞJqpY YiP׈G< 4SDW <_ Czt4HT9%yf>1>oc ¿YTS8#5u>c"VnRxoTU )ݭ}0Faq{/y8Xvxc3n2(t27WkcQ*u>*ɬ? MmV16K;;U#HA]7o"V*l f]A6cq\7nU8F7K6q('68l(jSW[].Db&󉸞Bo#eUknKT'0T'J vO2VDQxڪHK,k•4l4rqLKwDR*ç92j>ʨް4aD^~j,?a,7301 AN9<ЎBhuTLjiuDA]JG*'g8wJͮѶj$xBϟ7}DU-YBfS2e[ds@74va ؈ WηwX|Mֻ麳5h| I7^q 6t'j\1zx1W/34o%b **2O4<÷n+8y)͗/9B*[N VŗA MAOvϹuMC1{ '6ps]u0r3OVvFH۩SE济/QRFap;<4AiM7Rذ`?pѼ>U?͕~ ?''ǮcLq eoqxs4!`<Q.9ynX\clP"@dׅmRF,ߔgsm?Qq8f j4L%~1lcCvYk#Jl'(=Md^;̸jKC'aux,_jTb >J]MnuV+ǺΊH{ihf/S~F[iEAw΁o*2|lʼ#7C“SbpP}>7ORM $ 6qo˵&ic$#v>EɊ*f8;fՏ{nD]w㴟R`JJ~"iC=XTgXRwT"+_*(X{50h&|Gg~K#/TS P{^?D͋%m`|#'Zc㨗<_`kuz 4Ւ,ȡzʗ(x5LF w(VIݫ"bW! (3 fʄ)ɭQВ(9N:p-}J7N܂<1h;Q{|$Z>RCҾͥHgRGŨ{\ XABMܤ c= Eꨯ'uu&#{[GYy7P񿺉B#ODЏQnR}٫)?UfB9}rM:5k' e`e2 'Uwo .0)%y8I?kXyxn|F*q7R~4<9f~()L-=CA.lI.Y 5Zs?P{uRܐ߽ 2e :Uӧ@J>wQق9?64jan~8| R a%QVC,Ҏ5SV^0OMS^B%k;s&>;OYVDOH^GI9Ș2))( lGA5Fb8ōι^Q"B,޴HрnΉsKr,-rrҰz%j?$ZǝPKҌe#RXg<%\^DOqȄqBZ25DաT M]#)kG$BisD7nB'f; yBg3:Le&O,fAH&%5:>" %oU[rq{7) 3 P V$H,04%Ȁ^kOZ _>Nr|)!aqIjjHn{Mmv?{_@^:B:pyQϔ{G^?l` —9fPtUVUI_r#GE]5$t04R95:,k}˨!r$RA8 {zbeH,F1В E0S0:ܧa,v,|&[i'@`Lflny8TKY^C#A iVg~n?:MKNOBzw,M '+ن$AX;,8x? f69᧧:) +oA QfF)yuWlֈf? 'Bqt;~;wX&/Dn#[UBg X6iSM0 WK"Ngo6 nvXnvF)TiKu>)~hۭɋA 2y7^+ XZm9ll{{{p_Jdg"n2j+\m]ZjkiǺ4NM/FM?\VSj4<B$ڝƘ ?#ZoY~?ovs$_J3IO!52`󱛇BY &ZZR0ZFa@^l$1wUx${3tRFwNvwϻ)n9[/5!K!4,!lOky*Ȍ=f%U{\qZ3Ιs.vvO 9U+@0 $ ($6!]ԮZΈj=xIXW?Eץ<Ի;Q:A u>veIN56xQcBYY@ yj8s-.iezDxKDIB^Msڳ K!J;Z}tzV?{ug[r %3#f|u:nU,I lvU4vŨ`w?'3O`ȣW޷G7%?Uѩ ^\ݛ]ecAT,\zDѝgndc=%Lqˠѐ)rUg:I+N qM]v.BYY%=ba &͊h޲ہF3F䁪.y8c rF[3R88TfF]D@6qhx7D[8 deC$Gᷟw)z5+@&_\u4,qBZ 81կ%T&)?N=M?Y7fUvtPxN =*a,sLDd3jă*Z\._^ȄsdY%_dr<09 ŵ3u j9]X䆅#C @X.ZcR)YTj)U_ d$IEu6kkV؞ (T|o3K^˻c6Wu!8̅㞻nh&7E8O{{'.ж {o ?K&]NjF|9꫽!0߾i}ai̮. Cې+}QrO(;36eiڞc? 'Wd:@E ܔ]u.+36"z#=Ɲ{վ۹.1m0侂'[' \ *U1tC߶)r[y(1fR_fxN\#1mhg_O3-[ n$47:cDd^fY|;"Fj┞<+o2 `"c51IhwO]Q49AxyKs}|1%"MOVA(ؘA[[Soگ vUhAiU9n0@W6n SI =G3JcV*t6_v& 4<~;a|._v^]=~R M;)?J}m/;dVU8)\) OBI>x{M1)#[/c-HҮ3]$K@N[]ʲ ԢsE)H(J۸)X:|r$_wVVB <}.[WT +1ۂ28}ף'8wsC9ӠRШnT ˧@ S0'Bgeˇg -%;(潔*t `S\(KzɊ> [A|׀APs0Xm8%5G}]LMk!p?;ڶ8* m~#w%oZ4+?d,b~q'ĭĚVgX-hImy2z%k₭IAow&OXB~Ny la.spXy\xZoNje.8dدl1Qڶ{a;5}eiWhuDJ3dS%rEX:o$I戥gKۨ@o3(eIAQ:vn9ty GDR[ʽRg! K*rMLIwH7 /$G7&S/t.mu{_1\=2Psov_SUI@ܛlGyқ$A%#cL#ei/#bw2Ec4,h/` H ɻE1#H\L%R q̷Hh#pҴ%M*r~\NG!rBՇBE .>/^{<.8iw=I!6 "Bo*q~,MqmP si.}Ѵ*qLÑv׎t%lIcH,ύd3W<.fOg4 (y1U<;m+&>ЌMl4o՜"EK6rb)}t17:R ieKGly̺|h:]}^W7ϺS<87+@i~Hl/ ƴD%kjNT8K (a[鈥C>܂ӕ956ѰfN^o*jDf@r`drsk 21\B,ZY"dg5 F/=%O k},;Ya3K _DXŅ=A-qpU4~] |p՞h96E?MHO]S2]7QK)Q[=&lLn4A Aѣm\&+|q)iz \ مdSy)6?s鮓q,\Ņ\ #ަM"_ʚl~0tp'2\Upʢ'%Ivm}zSfMk^5bDϩz =@NϽ RCކyܘUv{&>wq+dL[?'6JS}p {0½H,}?LN^ T=]]%+ŕQ, K:Gr(@hy5>b9 V"Є|:!_ͻ2 BcNh9<Xe`73t'rf) Wͪ,tqXLITlfr$1Bf,#}WHj- &;s8϶₯5~ÜF0ϭ_pYʮ5a!so1li4]l}?0w}J8+?hE5ON˾h{YD>P#kHMqVFBѡ}uMr BIEt81X 4:;+gu?\W[[PP_ꄱ :Ƌ8/:lcTUL_;s<&i/O#+ -,&i!?_GWEtyAxd$@hX/zvls}ݐ>X jޡLN?IZ&G_"֒Cg=$ # W9f%I0KJRe% G'EX9Y{hs#I8WN5`Mwdژ^?u(1" (E#; uUfTUU5whQus$K<ڸRljX LuOd7J[ T4E+w\S$'Lt-kF$z2k㸕:$`|5څQf䯘bL&$P-Ĕ䉮nF)L TjOk\&|y|[,WjZTVI0ĘM@Jt@Z&'^D\!쟴'҉>i +D@[TXGU"x7s `}A:y@ bk'01C1~^ ҭPLIL37Tl`.e5.2$mp8Q@ R<>qAUXYrzBdIg}=%֟-UsL}!Rf̣g}jfVMO 8]ըPbn;L4M͑Ua!= w=ؐ{sqlpЪ@j.('sr'z aHϰ|[zk*,q5 S$- Xa"q"FP>3 8Nɮj,(K6j,~g?ĶNY7g Y_"љI=[?eS@dkZZ2YBF}tr+([Q@63_*SM>3xT^l;$v84x-d  w2""ш=nuvWIRތF[ kAIPCc b&޾1 x{zN[F,ĩ|[Rf{sfX9Ʉ*Psb@L<]_ux hdKIy1~8􏒘ԠtX;Lr"*%r'mOdNUgLu8U Մ55hy>e5|h>CJ y8,tr_Q 6+2'7 ^4C,a )>)ϡuQ/ GP׭ 36pf$\en@Y(1Z!k{8,M)O=? 8h)y=JET_ئ @6/na=;|1L2YٻLlciH'lY _6H"ע[64w;plԼMҾhЗKEi߼6Q {k*J L*r+*Y'q(3D-[0%_}A&h9҆"ܳl? E,nF\B<^GyK׵c\`UXoDf/z\i-ECUY0ήc,^#"&J{O-[~S/Iec!;tkF۳LiFrxvSSW?k'(ȁl@`W֖dpy$NJ[9BA ֵ%٬<Js䐦 uOc0?STn=] qs/ Yjr52kAįO帷D72րS5NzHنϩGKYgzΥ@&N5ΰȆ_EԈLx;`c1 =9l3l^uw l`D3!L&m2{"iA K[.5(z at0/gf4ey5" &\n1D=&dm Ze/NR&2@5¼[/Z8q]^9I?zđdL>%!qhv钊~˵ 6&ˆ+=v60&mm ܮ^6 = dp$G Us{ܷ>wq着K'NaB6DZy^z]w_"d{{ă yF7qUƏGy۠|ϼZoyji"/GR~T4d-]}L|PI``us'pD)#M+> eI"۳:/2 qЏB AR[fkΎAdTD K5Y= w5iN'EZ:Mw1㒊"?(-6T> !1I ⮙f \N*]F*V <-P a vC]8~0 uP9uQa&pJeep#{z;;l\4/ݳĴZg%m) ǖ${cM+QD W"6UUCw_R.Ͼ̤[Nv[(#F#]q> ;Aْl0ux'Oׁ6֒sQو\Q֏ǣ݅Gb ^<o.Sqzx>~0kA=[k.Ǹf.G|OT25 ̵Ћ3d:Q7dSk3B+Ic!l*E-]¦YdqjR@3-Y%>2w WWNG Qj {e?a,k6N&ueĂ352~EKM Tґ%O~IhY@ÖI*}bzߪAx ynhPڒX:D\o8V"\S-cV>/nGE>v>58j5%y,oPɗ}t-mWL` 4}}‘}]X)r- KNI= es2@@$ Q+EpbdA"{^WL=8dإkQkuᦡH0}VU8^vKmfBNj9DIxP bGFbA:jwI%?axY}EM~<=!4zEyUkŀ>xUC`F1?5Z}Y,133(jdzb܃a1+djFa/ XB>PC~yrf5uOc+MvJAqWs=s{pn_y1/}T-f3}ElN5wsDa4*8Shn[T : %&*kt"Dzy`X"m@ d4iF_ ,g7:˻~uG"u)LB dD`TW̓Z:_F()zWYK:9*)cnrh{w_ Ǐyzn  5Os^Ϛ03v\Ec| BdJjK<9r,kǀPr\bbӳH}$8|BOM)*p_\a_ٱCcATC@ ͌>~&h +h{TNJpY:O7E!/x7N,?;ݶi Oix:l:75t!yaŘ KREf}f%c\r'ѵ4nrjqB@uLGj'#WK#hMVޟ_{e±xu=3,lT@Z3Ikɾ YNz#AL;(ى HRPnf '1Ҋh?[UbPrāh;)l/m6 ' vٻUknGQ~$AX^@F J:zQ$3["4;#_ܧk$?[6Zjn{2ݏd4l?^8[8X3X`xgAZfnNF |IjW77 [Rp`Q3{wQVoqآ3Oc.G"&N[4G>˿M`g>bo ;ٜ +(܊AUo[AXF͑Q;. ŔFΘZ)vHE?Q6xt [CmGGzp\hƓɏ@epS*gX,\"kéI$h8)IEbRu;P7~KX*TȱGJ zMya*PgҸ)xIz]j[g^t$KPIJ(-6dzzi9gY9C k{۲G}=fy3XWQڒA-*w b{EX:)!?99A *,pגGЈ)fDz>dxhX'=i?(St͈)68(.UF<:\](^xID1].ASG9 (Ÿ3PKXj7??"c>Zc/M;ǞXU0i:& ߾C)x0ޒSҭ 6riTآфfYo ;< 9sJ ~n Щ]y.32}?,6wKj"=2Iudq$ˎ=-K_DJݾgn{N)Wюć:7Y36b5~IS{g",5~5]qF*/pQ_NB$ r pñl*(_ƅ)f :bT&D nDiD6B\L~R`FF.lЊ..X$tfSjKfÉiIzؘ5 }-1i|"D[[ܠy!~St'l4$$3s#cg= $t}!FЅ[?М|B~~*]V*# FD&@/$e#رlS>sⶍвpLV.Ӈ|Pzqc=>j8[AR!LH o$Elg[p)~B'=n+ըu wLϙ{5-]ҳJ/\ K[\TZ+}SV]KMfۡ#E| b'R|D푛fwοx@m^4󥾓 d;d} K^o xKyGV {T$W+[bN\!IaY )iX$Rġݳx։ٽEy~KUcsbRO0dQ[sN)&VsieX~yOb()~zBjub.3?|lD 8)[e>Ƒ1Yʻq7go| of0(kI(W:ɁG5;jŢQA+0!_Cn^'k*^eOŦdJ'+Xn͕(VE# 0E$).ɮyH4tUBW*rTмɓHᢘʱגA'jIJ p_w p!KJB4B u>G#A?WWQ 86 ٷS=LH|9mZs~_j'mj\fB˩U 9 : LFŒY:@+7cL:ǎ2+ f^oZ1:oKCp^K{R1zU3,jp!6)7O:ST[/k ~Mnn*i|LJ.k"#\C3lD }ciY̓:ShDvx҆4vQg N~t-6Q Arg&Nް;tC.~w~ &vTVtޜzRfv^7}T:iy{GӵsKKRsҺ9Ӄ]\YCaϮ`hdE1q\eyyoPCvCfB4 w s(7m^Uj#|eVR܆NQ3ʵ2kn Ag(z!b!HakcחضGY?{\uX {xf鉗v FFtiy1Z8 4|ƭԟyѾkV"So <+r$dyla]l~XqE@TWo3o+x Q*TϦ 5ȳ #k`}.#Kr,߯Vh[ z.e6 -ޫrpWCMS KJ 4׎v /o .L{w5`ԾYG-y.@4L5< )䕳-UגW8V6 7`9kVCm;?CSԦ)^Kn-cj7@fRZqz员35./,35p%J&t7Ӂ6#&aᐶ Rm62&Xj<'o>`/d4:j0C#^f$9MxϪU_j[A畗>)CdgC@WE2_jl ݮ^RVZnGXV_iabD]dqOT0.  u!_Gdl,ڟ %;[pСh( Q֙Lh0\"*r*A s]jbk?s~v#8I|{Y+˪fbȟx>tE |9/m߼G%1g= K?m7a=ROܐʂaTd\o.´'eh7lČa!?:ekg߯- C) &7йfz RQH;*:ܜ.R **_d=2T9 =>(\Zt)|H+p9c_L# )Ǵ-Lp٠ʗG .JvhҫwbF;s݌/yۇ+Bֿ9 t1.]@Ms7ƺVߕ݀' @x WĬ[_G֫x46X/Cwm*npؒ9,<Cl@w F68k4GӬ!~bEU*Y܊޴g<]9vBbV#F "=N9 sER }mXmӶlZLXкG\-,.KVm͒ϲ/P/3pRJ8&13oA N'Af^<̓5jVz+q.z!`suU997tџ$ m 9 < iT"KH;aH*(T.c& ;+=Oj6BK`Zz~TX,ɡ礳O ӣmXU1ǿ{ęҰ!'2m$CǘQ9iSY:iR~|𭇌 X9w\fFpQj qs[촼$TDž;*w Fѳ@o'`Y bۋAP_}ğO#?7IG`"gM =0쐸=r@|9; +`hgn;(=e"|hǩni!}2]VG)XX+6_FS,% $@U$$*M6KC̤Z~A` ~\k;x>2w=_rۂר1E%Ԑ/;=),i4",(u Ǩau] l#:HwGRsޮ&ZKqa ^!1lC{P2"U{t3YcE-Q!vhT|h\ l'k w؎POK } ;U>]N0 ys6Z(TI_/P'飕+@!p//F Ե䳼o8yt9#D.90%Y8b }Aݝ3FO,Q8fy%ˁyZɇd .{k֪vҳhvLݰi vQ'wD˕(NN+*7A&: E;]4iŸ=A* WS }:a-Ñ߳qp&1tUA[!, vg,?6ᅵ: }r.2%oq6ۮʻ s7bȁX.P@5 EmM q)3^&8 i/9g8? mwPW)*Q+.dbp߲] G~(EUuQ}a ; xWTer̰!mJQNbdvE6J$!9Y'?})]',<?mj>ϗ&Y@\ `&H*]>eF,C; )q@hnϛj"ernTiN-o21ޡ8,WzNjlVҔ<[sm=Ap EBYxImۍx9Y)ZHSt Ʋ.5!0zq _V=CM1w 3:\/XΕFÎf_`iS (KO!#95ز n/,ԯ}$͎ng[i 4ez%]wraGm(*u?&ظY?|c#l=*go'i݄~!fߠE7oA랇jGWߣ ;@q_60iEd_Y1q{# BZ/,tʗ5AgzCNy+L"rCYp6=ٌ̜FmLN/ܼ'odžVf<W\>Y,.l8L?5(}UYEeT1rM6=x#ʁ~ w#Bv/Y`*KTF^nX /3MC.272EƥVXn8;%.!_ @ڶ| wҎ=dy@ziIƐކ_۞z_ng>}s݃v2Dx3=Ss)3LX,3V:k?SY䃕pRu͞Hn$R2Eg[|j;5x2X=B, \bb\ !f& -LhnGX, 0?OI}` ^6 , LCoY2q$s u}+]wG;5[8v jf{$̒_6 ] SM?Oom CH0J ~m_4\Wt;N yOn!2K Q)y6uT$jN0)8Q܉W|upTRƿV aޖo_r :RhmE4{) mQ)LГұ^Mc5q0̳8Q1q@q*MԤ/ʙO#B$̌6:KеQ4aXMS.~{K3Ru~"Aq%zK׹7MHNVoԒgdĪZiS"¡2ӾL-F*#QhFyD2{,Aw/2ghi[{.в_5Ϩ >8m&_\mS4Դ)cW|ҋ:M9m-W&磡>ߢ'VDi݈8M \ENVAlû?@.1Lwי3!Wm&M]Zu xKh%l> mg_R !޷(A N {KeEijb/'~/E%ra' Y,ZGM9x/\|QdZl='C +pϹSI %N ow|2Jb]N%c쑒te8Ǔ9J(ąs}ZGnJG*rn-A /90jk_Ҧ!SdţVd̍{qk[yAFvôIaB|`ŁG65qd2O.@/ &3 !ڝz,.ۛʅG$PZ$\T4q)9wq~1!PSWH Q~(DRK٠m@sEOIY@IpZXMPvsca}|1H1l 4 Fq=+-zK(8 >$8",9 fmd)~ @=6io { 8BBg F HnDuh7 .c`5n'P_c>8 %U쩢֝I`{y#ɵԇM0GbTd@or$$GGqٺ5?GY F?றqK:TޠBL4'g d"lSaC_I& g+{CLzeF `A>4 ;@8۸!=ݭLuLS-<_^@UuR^Q0܃`W\J:a.Az@MJ+@2vZHe}1cڋHTWQaWHr;Bv>ԅf۽7*d'FyO @yUpR\%>3(03 Yi(]ۥ#?Zx^:РrᩁBW͔V˻stͬZrPVrx\V&ubTҺ D ·Ǭ;/mGd꡼ɭ,aq0:InG|WiծA?RC^bn"'")EbcIu).b̃'+xBoE] 9d?{DN'o[X+vVbQdP/_֕A(>{ET t)IhвL60$9d1@ P4+OS}*d|3}94}.!b_93͉V> "/Rf5={qA/<QGR([ v#mS0^MLS9=O`)dHӨ7Vd4HVt :Qpt TՅ0]{Jm4KV 1{K+jvhYT`[2틴2`݈*)C9J*&7keSh;`Yrcl`-J؁"\3;~DmdAJa*8-K|LGL''k"bL͡ק[aR 쾳3,]%02Uws3fӧAEV 9xQ[tG۽0>@_=Ì~ ې 4]DhJp{[ C{"ap84m?LJπ\HL|9yDwK*)gkģ kY[#?:&/Fk"ƠT_5哏LF[vK/GF,BPo^NO۟_@1y-*Fčk6vDpq1Y#͖ҥV1xu "Ƨ35,,=fLګd#-5*P:|XH7rC చ#WMqА]h ^lC1Ǚ^CU/ "|#, ! Qf*X)XEGwL^0-W鋙>^*r-^( s&:s]冰؟@&8llmRnÁhTX; }Ic$A5 p$h>)[hIij$3 Kx$;c&q5Jܜ7,vYVh2d[F%tg2qdgFPWfșŷQ*? ҊE~GH<%+]+vuKzg/ InJtOUH58S;Q #hH) ?93݉@-&~g5?Z4gv U#yvkeI8+V JL:yy]t"F~p{LבyѲR MiZQ4.oLI.2~a-wkxW%-T봢kPYl RgFB&G_@@g0" pR(o茤)Q*aFn;>zͬShg|D(AE9d@Juڨ]|նi ?G¸]1UIB1sV>K[w&Pr"}m>#x1vAcQ8<|$!GmCc: x_Ay_MNjdza{W>fi-Y95wo =?.aҭ!;KYyF/Zۡ/Ack êhj`r3)L^ǾXWE">-e/Ȋ;!lAa˲nlY|jHybVa>4bi3~?wtflµӧ@X VJ16xnl kjXqnkko/4ɉO1;ցvct*Ȭ}O%;V*U`Aq&Άbt?bx?"=t9:HXuҌޅ Z*B3bS8Gk-/dx4VFWR ;;(9_VÞ+e:ê=ɟ,8rС @lh &ynՑ@9'&W9sX>C}idQۭXsJ7A}_1_,+[K3g>߹ގXI})#Sg˓q$`y*wжH[#׼/PwCM>r!|l a2wan:>P1 򑢂$r:+p&K$p:*G=-AJw{`7]qŊnWQ;xڇE'=K_KI39hAua>rLBMiYԻcqR?o<- ]apeFLAԔ8D]ɔ)hj7./,?w*-v,zGGL\jTYP!Ҡ="C %ԉ]!.榠O'%܆Z!  [Wx9ZCMh,tbjKg ȱG<7.6:=qYހ_Et]"<[:y4-Y :,{˯ l6Ef8 D%zG+İ;)I Lʐ1}m >7ϑ)&T@,j׼vLR=TTx%8QKKOAh&v3Na mB$rfs㴧i`W߁:^d]QqȪ;mkz|/ĞO>NCXt(h#y? ϝm5 >-̞e-[ZĸZ}7j}&qgO4GE$ +I;lnm<(q+puѺe ҕ}X񡰤bdJ 5}!kwאaɜ8k w$&۵U~_ҝD+yG#ͮ,ȁ}+9z/[F[ .eJc0Cqλ4niTSDXhtv^|0>IVD{5s?OPGt!DIsWZ87Dپ9 2^ā:P~Ovv^F[~J/E^\^3+n~Z]cȦ552Jypd$z!HG &|+G/{[3xLrhckaFV22TJ0Აp'^_"%DTk+ gځ(x'd̙\:e ΋eOv%vp]ʭf2gmEQ %ɟUr2fhS/~elEs*0<*X (S18#}JAS{ڀ=B_{\}Aat Vf CiʊxPO?Q1vCQnc_:Zk(M8 {{#&{8Jf j +,e@N" u+̂ @l|~^P_fJ7kxbæL33ѩ=_:F OHGFh^/!|/Zt圔68 ϰ/^N»M $Oq#Pw^Уr _ x݄y_i1uoڔ4#s5l@ё=_b*`,@#Zڼ2rޛ)`%亂S!|1^΁=EURv>Fzm昔xp}Y3X#gX*WCBʈ*үx5gleĩ۫ $-$|v?"iG Ax70W=-UUEDg&Ch(#~*7̤]t! zdCT.;H#{[H H-A7CʛiC`W"a|MJ( W]ĒYw~C` iœ7ڀUGEfI ZDw}k|0-I#A];LywHni(-2ojsaX n$2[ȉJ5^"^^~ERg9Q ,:FQPi V>֎;%v PCQK0D_)Rt=k̴DI7/8y` GM =oRxlA^D4C z0@>Ҳ:jV+q;@ .L]?i WG,[WtʓߚP J|>#ɦ0$W$>>|inrX_Su!xz$$0+=$FMмt&;@U@f.ߺ6 M>'-g\8,D?/5?dID9?dK&`@=dmJU|'g5\nudS%Qg|˷\m;rC}X|;3uɲM`X$M>Ԗ7xtY@jFa, 6к.!YJHBhG Ys/b.uҰK {.矌} ӫdY(TUhtݸV SKzC(NIB ", \ ؗ۵5 k2,ea#åt3Mjvx˜bI贑 w9_uc 6u1+NJ)!4B$Y& f}taJzA7L&e 3(9-m&yQ-SG]b*;t #ճ+d޷j3CzRn1[fӳmM0es5}Fzy4IneZyX;R5mDJjKω/,(eǺ& F UI9/u itʭ~f l"KX5iXc jl1 nɅdX)M'L!..l||b8Pxu\ [*|aYtqâbuN*iEP#K:dx;bG*vv2\ر0+ݘ9ylD؆ylL'>d[zЊ!9L2a4W ~MGo$笽,Kbazgb1!Zj ޠ&(TPv= p]L2`#7[nb]M:en}̾KpJuQYt0bȕ @ q^8Gh tlarYKu-ax|IH ua lD:?v~"_\Ez.9+oz֬"O>=)UQcS+ ̀^E~(3PH{yoiΐt!}ͦb~~nǴ yF򟹢2e -!V:@P4C?r"W?[4d")!a|ǖAoaG>ueaD-%=`(??sIQ9loJX$2Cu*l,;yv8&a]t2v6pHl ew& vmi@jIp3gl#V E(?跦%AMJ"Ɨ #1F佈ȑ bSZ{pA;ֳqOVZYGs {Ns_F2`cZOo&(Q,!۠pn4AJ{*l![Mf3J+-' }a2ʒoɧV&@%#9_.{I%CFd  X;"#8vM @yz^)Չ:> 8h?G/ {Q "><(Iߨ^Bɹ.UsQ96S?)hd>ܯ&Jkc`U*E$7oV?ok#Q&u8Xϛ'Nx [qKQ0EOiL |_v8?ڦ}qpO ,S. er;[B/;X}Behܗ.;ӫ۵h0,~[akVd~*|Qf 0 xgf/@N vĎY/R(~4bYd[ywaW7€+"Y=2._:5h!ԕk_51g "m~Bo9M~ =tY^ W*ڌ\/ecS%UW,ICX]'b#Sc@2)~)?~Q|Ww<;(ZmoRxjfJߜGns`Ӂ%FɠQӄ `A[9'םvGCcן{ 4S$ª帳E W6޶egw#;w**VyAoj߾~Z WӌUyy[n=n6&sDl R7k[ȶe8a*^ֺGt%i 0Ј?&*F=NÒjiD)#?$o-k\Z)kN HBW 'C"mrI= 3|-<ߡ: #mo3GN)/~:м'PgywilD,/DcLs`֌_(6Gn%`r(8tAW!-Aeq&(s7v$TLP,)xЫ "v+e;=ʾ^* Ma7|ԷɶѺrnjLzQULe<KqpbzsQ}Mք$}ܼz=ўairOIi Z~`+d7A8Nc$Nmڹ\ƬIIثi zWd*Kd Pl6|^X 1\V,r}>M|0תIOL >t.sV "!zG\ScuK@)S]h՗ZOp-!.kXUqھ|d3X  c/x#BԱ_R73yN=O_Y8aՈvcUfÍo$~|+CGQ,DSi|t@[ K L*F-WBj*^ X^Y@6~5mBGgKI|=^yodX<8/Sz wn*I`Aիgĝ4ߪLt0f>=2IHԵ1'jkL-Y)U5Ly^2Fⳬ)xu$y||*&9œ-$J+6Fq.Y#'E ER +{UԭXOZp`ܛ24%03 ۞9jy0%A V(Uw1'77-dOhpš 5%{3J|> (8YwKEVg'CEO%89(用j)2Q?a9<$&)\\|kZ)"kS4Gz\j0L@h."8;w#{/0^&Ė^ftiaH;(^f3fO NU_ky)̱b h)xk/R16-;3z VZ[mC_Q]",|rMKThA31t"Xh&%4|E5fG-_LaGQZw&hKx.x@78F zxvרԋFdǿKxN2KEݙ,S򃰎ۘ^ٟ ISVpf%QXX>7Eӹw昿C6ՀͺX?wr_S%P \#U.mTuާNERr(H͹h=9 ƍGeICoҮim{` -uGքW$6;Ie_)&6%*)[k>CW1X ̳#La\Kt{N!.kѷ9 ҢV1=y=v%>sN;MD?Y;rWD*HC,UyA L`o[[cMA=uj|m4'/]Ӣ3& LɻV x5jL&jU6MMl~Vjl֑/v Uj?[ؤ`bV۠9HB-oM.w־~]WIPj ~MFvBW$;XCLrx)NB:ɀE1;~+[ܕ1Hl(N >Ƹ=wULrB^ X S*":(>n(x;߁ȋ"3/[!''FpWʂhu*_aTb^9U۬R4&[oGW30UE|f1v6-BMXC{TIqwIOz[&7f*cmiGjP?L3r.}GEU<ܗ|@=U1bR,E/-˷[jkA +Z7e +.CE#L^bݲ'n-tb(:p&0^ ~B5*F /I/z󿊉]y-icٰOx =S|2WҐ׍VxV HWs5>\7?Qpꧽ!^쥜?DZebk w,I? j)hGyIaQD/{%O6f$O9 Bbی.D!sT;{4LZVXɦ  mscUmwAQ1uwp-+ =\ -*jԝC*$-Vp5՗ugJhy=2b%/ͅ-6O"]ea;αBI֚7z˕/6oY1RLDD I/Ɇ[zڸ2V^!m̖r}|'I9"(b]D9Rfs_wY'b޸CDKJGX"IeNS6(9giQ.4Hl ?pd/w`͉υp,k 6,~bw7CY3mk&FR1ƫǤyEiQN>B~ LcJdKcB⦆x >b7d<:G =p&h3Ё}!yˀj9XC@YV@'6ypY.{:6L~@XX|Wd 4cn/Uj -vRm4W˷ j@c1L?b[zRuj>5.uW={ J(K%g7 -^!ur{>!6M["h%ҦkTz2KA>[eJ%'QAU,cS?>Rubp;F'”nZHFӮ\@  }-1~PB, HM ]mu"ZPjV'h@Q 88 ! ĘfƺI/C:&'p%B,GrFUpƃY&P rZUW _X0P蓒ON'QǭpyWQ?&eTgs {Дx}ErwGн# ŗQ{rZFr4kd8ؠ$nf.^QOYe9^K WtaCwd1icyt =5 ~F`zfvc`Qu/pJ<ְs%|Wa4h1 )C}AAhչ9 1ū L dž8#'@*OޢP0:)_FVPm^,b{hR`żfnA2rm*cP6qBTtYlm7ڌeGc 1 N^<`cx]s`mFlxK-$vsX@Xt,c RkDc9ue2HAzd7"g5ݣ`ա OI<)a$8y6_j|/l~ ǥfC,xhNG4-͉)ˑdTp wȩ6 k 5l+O"uq['`$NI!GlE 2R0 F{cxq܇$LQk$9 ͣ9>Yb_W Ogu(YՎ>е|:{x`尺<,TEtxq ' qT\{*pW ^a ,bJqUSft_f>79FBYP*÷PLD4crAzZcZPouNW3PnqsǾ(6۽S~[)m2dyށ`Ӳ6=ը iF)BQ옿 LGqZ6/:K"c%' ?rqУ{#г_yk֞@UUS ٌ8^o@}:-3pzWJ'6%Z7$$oC`m032k+-1IZ@Sx%֥~·`7Go,A"lH?!H.R_-#7Nd"Ӛ&덃WC_\&fep)>3w* /HڃxbQ`pd }5 >'<}{uKL@b}0[=I*:NYYK9/E, oް?WB+]I% >T^-֟ѰX`)bJLySޮ[ŵrʽ>^6Ga,Nmb3.[$o=551hW2a37"$Fhv|sތSH=r]S?E5,P줓FjJ$ԌZ ɣK(C&4}8& -~@Y)9Fp!(񏓔nA|1 $BF1)YUc 8c0r5c~ޛ"`[s'#pxm5t`_ȩ>(, ,<+B yS\ hi/Szg.γ*}$M%7TФ6Zx-LHz7`kCh8.9`ny]?+x9Kא|tBCLj6[r|fDgxB\pa>3<-DIoz89@]V<%'PS[ QAu~n8+}νs=ۉ΂0Kmp&r:)/wwG-To{A藠O{zu&Mw(EPp\j~ b홲>K6צ&WTW=˴6h-s$B>Il"Sq@%%"-c噑ּXXm% ~`J=+|n58ϩZ!H\BDܨLY*n,@uYipʮ&~>^m8D*\~8P =QCfD]Յ$eyPl'XS#x?YmbKkwT-e|JH(c11a|UrAR ϋQfߐ -ȜQri]+Tgqc'ZEAr8gmĸl2`嶤tGk VƇ]`śU-x"Ɂre[ 5>祲@1ĺJa.yO\5{`%Mެ:_4}L! ]jN*d mܳbm]ALEzª T%lOMWh0:?Q*7)f ϙX,Im8Xfg1Iwt8R&MjAE-u!9DOOBowlqfufT.e JPiAeoXD\3gưk VZRT'o7&NLFJvܨ8KC Z6Xk°đɂܣeuiԲ@HlL``puHґ#bG 5OŸ,ϾT F)A BPxn-jg{v$=)σՠ6Q" isA2 pjVUzAayFOsJawA]hcYB,k\QAT̬*LKCf,x:+#xsΝA"^r'A) UP $6H'3r͹ r\-Z!Cfa+(UApe ,P֌\fw-]lX ͇RKe^32&%(nx)"w2w<V) />hK/I)OF*DX~VW")?|SiS $ 0xF:l\#xzr`T#1r^Ts3 jt-0#9ǂ<-T7}HYi.!a{:e/XP9Z#EdF% >x lASDm 6എmA. eĴ1h#C:2J[!1ӳp `v(X-9(ՉS:̬~tDˁ:5#ӵ7Is@^l*V㼯̳PM7DQ {H_zCu_*Sy)sTq‚nzTqOU znjV<52+gPO 1Rՠg+I73dE|= l=L;Ay6;W>Կ/}2t<Q[c+v"&d)P,ޤ쫻AeW,93,>ܭ(`P&J6e>Ҕm Itf޺y1{ajȫ7m,k4R.q>u)2'^52s]RBXL輣hKBLuI)̃k~VNE@||'Rp Ej]TQHR>. w 9h}w/=ҷ ‘пba(zϋLAR[fF"[0H?!zBI6q9}nL쑎-&VF1!hoY C7ʭu}Ib-JrL 3ďѩ[ ]ÏI-,½QHx0긙w 4|<)DRNJ8ih]z/і0 Y[AEBu@Sdii@Ap(ENf7V8Ѡ@ T=Uݚ8dXyY-x2gDxXkXW fv"VFN=q?u926 @y0h6BnAښajTSieivPo#c0NN:QWJ"͎Y2K~ /6twJNjYy+e+fFu.tgZ:a&p볗|W]%J &N4=ӥlq=IfE/C28 Fݢ6sjݘ7`ˍ Ӆ m#XD0F8d1y};$Rsb0iۘ{7!Wxܟ6*x)CozrX9ݸi|nOݗXZZ'R_5 8l=k4 %a>LVz3unSo^=L(@Wٷo\Mo&N|Gdc% E0~l6PœmV#vo9 a̳4X@}3te~("YQ:glҠUgQi4E/H f(q5ZsUc^շ-p T*H]!93@o`7+,E ]x?[}y^J:4E>{ KgC G:e8H^ Y,1B]1g@}r5d$MװĀI hyw)/v QؖX{(Y/Ea v@`<ZZ<٤Ff$)oeLjS~ayb=h Lhj6LѨF#8*J-SfV[r#:RX;jhp׬g7c̱$Gi}e 4ifG.|eE '=KTv#}SQS9;Q*C"qWzQ2REuH*i?eN!a_E(LE{ʑ 6X櫨rohKz%^!I}|*@zA^܄ P7QLgHO/y>-`1Xu0Hc_)pޟ4䁻\YWt)x5 b0ʅ="o1DCȽkMT:}@xiN8ʿonQ!chn}B8Pڻ>үTS +m}BG?W°i GRlo{G5+3fliEܖǸ|QlA-/ѿO@F(HR{zP'1np+BBaj*# ŋͪ¯nĄne.C)N lbuߟ>(Z TqijhFT+7R#&D X)ǶmB(G 4t{3'wT@-? DYcO 4] P bNV{-B7@i`IzzDN7*eZF(3.I7K8Vԝ /Bq&uVIy-{~'ܯد'(&.[N!E+k7`M:v[+=~ n;vyPGWd8ւ0sSDJo]2+ОR:l$̚u7 Dk5{Ë85{g SdRE,ϟR!h77z=O3rڂ(-l|fU3f?lukBx?n4\U?/3opP>1)~Ջ΄ˉEcI:;y.%ׂʢR밀>)|&sD sdpq2l# eo]\ZCZمFv)LOQ[.B9r8LvpP1 0'm?ś'Dk(q2"]BV-V~2l~lk=nz\{vI-dq.TFy40]쩿HxsW0*En#䄇0t+;ns/%ok*qgwIR`ĥRh ]Z11m @ (hl_w]/= @s#LV> ڻHײőglPAP0˘߭zD`)C:~!Ҩ)3[$w{To꠆Dt[@i ; Yp,l0BY Z负8|r&\,W㒐Oʆ ѫ5z&b"-"e ˶(^,kM|~I9s E| dԼ=kDŽi Foi|׃VTqߚ Ř3X[ِIܙ&@D7<vg)ƈ *:޼LEGHXWp)H90׿Jw2.Ն^Qx}?E3`0F})W- RcOhdYݐJnMXm*s) NN= _IUs_k%|vuv}X"Fέe70VyCf]]] O0ڵ4ppD8k'h\2ewhz{,H- d٬dNn R~_^\JBʀg8n4+\fzۻnՒs.`jێ[2M9UΒ9ʬ$4.Ӌ6am-ho&:mA%z>hU/(-ne{nk5>n5YI0$gz^F[=޻Hmہ綀Uen $R#s@Ͷ^ 6Aqh)~/WQ/l^wP. ƿf.񜿰?cN.e@E/[`s[.?L$Kd{1HBHRq$ܫE&n 7~+pت\t+?3^J#d1~|8>yJ'yɶ+Q d%PX *nL\pѭ1 UGv9ƭVQhG,@%8xr,)8,ɉtkBv8F8Q4}. < ZZ^hUmxJ1T:[6fVHc8{@(T5tMokZ[\Jd_3Ub(\.8eXք= |~)YM+!(#ʭs-mF#hcP:k/Ն XwC3(Lz!$ 3ݿMlo-_x m֩8ߑ8f4yOt`! J#,L? L=Kmf?_`;pK garsАnPWg>r"c`].WGS{#+ M&`̚o ?x=g!#|bh6S4M\ܫy3ˑ7eH"Z8B# Zcf[Öi;W\ax0Tkew$meWu՛2=M~U5.Oo?.ArJ_joAF LEqW }3 uU5 >Fo魽Kx[M'97 O~BfڏId>T0o9'4]91|%gSŌբ>]6t5+X5$A!hS3fm8,"J!t#< '@;(Q?+S/BfƥM(3>Ob=iD6 ~0zhP ,po?1&$AWoۉک$R66QdY;!{E$wUUG4#$k<5vB7xbePJ\ȸUưW8mu\͚)켮%a Y&W 9ntH;I&LzkJ+i>v7`(F$ 7~CDh#&g] R)l{袾be6N%df>Hрq{]kT¦1u-{&'OCgƨ~.y">((y*2[1x'GYcit(cࠝD-SVS%pnĦn;}3vqd:krc֞+ &T I%{.& Gnc&퍾xO6H%S^XtdžnE{}b-n2 a*НLlrJ>v'@3,Z\)teg M%j 2 ;֠M&*l`| Xq N 0Fa/&_I0bLb݊ N! "ԟobd}eI ʚ'I EO:I/bqv9cFj x!EV]%c)1?W׳;^йjt! _L,2|yItjh7YP&简Zy"j7J ކIuadqF v8ҌdhD2u~E9մ1A?1*c u"r7K0G`(.~GQ9q~B ܕ/Sg&$D< CC( 7&]h4$h[ޅB^Wc§z,`Ub -f[{LGs7V:KnT5َPL =$\J`CVYc )#Ҩ.t`?n֭3`?Lp&ȅ ay5:)xaGD1N z"=f;2;`QH l :TIW[0g{?tᯯ~h&Cít'*losFo= R<bR" O)p= g\'T--.rÍzXh5qӯXg~?L *'lbnj*U2Qx7_kw}a")zJ٬Hᢞfda `U~9#nmdw.H#yQT~!s̺ۇ$Us>GV썜ᳳSFP9MQD? *0cŲDyP.?O%: Jz$FqѶsB 2E#޷ qRKt+xt H m\2#Ic &@)'r 2<( XkP?w|q?h@L廌P3#њ#wlk|d}0t_,\fV>gΗئ(1 -ލҌ!jq988v2RL!/MxT&|Ò=K_xߏg>UDli.NX%'&w{_C8o~30c`u G:~nq& &k=Pw~?Y}ߒGBrXNw5`jnU&L?9~FʬK|lPS>A) o{Y9='L}8]rb3M>A0v2ƪe]]y-8 UqMs y_fPՐ `܍v΍NZBSLwunsBԶH<;Ae0cvݝ[KKN[~=ZI>|WfY?L1#na+gcQg~LI4 o0q⣍r&uȄ.1i{3P5; [oD(Y*dNmLCwZ${آ X0F?ZJʈZQ)_@TVu}eAjT7 xPT 72H/C4\&cŢTX 1]K]8DU46 ;q)ߣF"WWmߑ{iK0rg~I&SThqBo$dOS}.<ai\ͧcig<c/81OgS ;7tICkA^:8B%Cޕ!<È fcꑒ\YtbPr;'W4)؈4kE~V8 < \#27Jiき <; "kkILuYpBb$U^8ӣnVyڋRpցcc:m۴A1:56Lw3L&K`bG۸sG Q|ECۇ9!{$/]:]ҋ>>GBɺ"D#eϢ6%cflMd>S׊h }#f=AduVn_J& E  )jF+vG_75MbҔ !L  q2W3Au1pO%5bŞd՗6*Qj1q%ko,ʼn϶QS6g"F{$eZ|b==+9/+61N+Y뙘d2L,›OA*4B|#=xL[($|p7wd6§inKW.בMS)23mi*`2v:(6Q.e>K흪/c+CYÔ[kB‚ 'Q*aOIsUQf1'zMhxaOB 4n" TO]'[n'v4 9^|[-.zX[2fBC2ԶY E;Vb"ckGF$=L$6db]4dIL;LBʁW|()Ƀ?N[ q>mJ'[6!A'OABm7w>z>I2L)WO"dH]Vif\߼!ayB7"3cbz_?HD Sol"cw²ntYTE\~,q%XT {="\>4(үM11mwCm wNmE(fJ |1BZ  岅{uTtDuo#d'>ߍ4PZ#uo;hP5b 7PXI~kCPAr:Q :کQ^cҸ-!ԤBY\d|YJKp=6 x=*60kvD{'-}p?rðJnk՗If/R⟋[u%Ƀ%Uá/#۬sykX( ~y꘺d5t`'jp΂ORMZP *!Vtc$ %*8ln0Apeg] }-[3!m*[,j/)m>qެIџG|kgeY)vߩDl5瀗شT tjoSBhƨ妒+J'ÜOyL{g2[A;fe` O?4Kb038%` uT≄qi$q`%?F3ɚ\\3PZ2h|$Y$h9 b;T]dbF6 oIi!6!@ͷ䉧hy]QLd( ,ÆK<+/qգo7%Y07Z#L0#:&y*ˤ}.-.Xٵ;>pJ#w|6r8gt@](/'|yъ=7VGNu}L:df.#%1nSE:jdˤL^ZR_2"KɎ)Of6J HlbekIN wcڻn/Ƅ9԰3JxJɿ -6+{Y[ C as0qXƇ--Ꮌ ,"?W|1=-\K>}+ީPoF8LYo͚*cD&oIntGx0NtGXpZTc2; (aHB4ֈlYG%4&e^n42Fg"лi nw?)QfCy@e+]N&a7vc>n˔LO5`HVxZ(*Jk9c1iYњTFލ&ĞaOud.,@mEeԯֿX8a ':9(T_䦔5 Ue;kut\Ru(L*y҉ 9kFFe-[#A.yQ8FrL~ jihgBp1zpϡ"4x3)3Xz$ޙY@DB>A5bm?*<3{_wGBVNH|\S'4sG*~=ZBFY*˟ncX] 6*k 20̽~KItGuH*%ѫ{띦[|_rUPRV+ m7xr'ss! +$1| # J=Ra. «>VAKts0(X^-9"M̈́pGE%g t^>ʿ#Zxmԡy挗+KשoNV6 On[OyhB6WWsWU)' jNcZO( H]A #0$>B ,.gEgꥬB2Ql/O!K=qg%nf&~',Qm:xc6"*YF6[I~`7Wj\CYu~-d 0a_A1wF'㘔֡| ?Y,}?'d܋1^L_Yv-v9y>LO# cwc*#0]yƤc}K\/dY͉q:P\YgaޅK(ފIDjSuo.? Vݴ/Uls@F3X)':fTټg fTㅥ!o{?غ|3v5yVh[V~sx4Ȃ`TZ~[prY., v[W{ƹ"h2GɐlWPh|6!LjzQ `}4 `P4Ato%Ki y5-=M}OE?REϕ\،~w YZ4w.'DZRYR 1aUw6* u3,W)G_Xb).TӶV@FU5rWgSDHj$#R^M5P^YN@6i~4qL7[v,ʟ([xFDcjLyؘۛ gQ Al!_[sQڄ\s8r-zj^ioLվ@DK-hG%aɤݓB~{a]!lߴ-$aYᵝ{ xAEED6It R^Hiva&5T8 qBvZ*6U"g(i*N3B@:uNKοEC$j"WɬK.2|Q-_c0k9HY)JӖ]?Sf1Tg h*g֖55dYb=81)x?XuiΣPH6dq)E5Z/s,a.VŸ`@*M l펼JDJ~^b_D7yj5I{{y)X@U|!WOB7"^ykQڒv=]'o=1FB/Fm&9HJ74QN "ձt@R8sJ^ZZ"߭_w0EpX$cQ2P>:HRMLt`I$`br 0\iiKRM3 fbV&UM&d/ %]ceڍ3ϖޫ&6""*>hGeb[w:0f1;w j]Kuʰ@hqkȞכgȃ$i|?>ԋ̈́ugCsg{'dQ4SBx rzN3ϺX?ȍ}˚^."~6BT,g1\G* jl@ߤ=E*zE9Al q0 |#w_0l…3N EN)gSj&?z/?QXۡa8}laH{%%WB Uh{|;f(cƹ1#=TϧR3#0 a]d `9.sgt }iG nղ}&z ̒#nYTyţY 1N7-r}A"2S/TRjvIXmn2C,To OʌS5FU*};M#Ba;>TԷܚ +M`s pVlĪcykN)(Ȃ|q-}1tHgj߬z{]ZQL^TIfa"?Bl0L5k7tB.n:9< RT,B11?.1RɒdM'>fD2ifs DY^(Xx!9 [B>E/ "(ST_є$Y#1$r*`qF47XQEP8z,\W? QTJϊx-~a`V}%f4ZA~]YwmIv~[*e _J?Qm E<4P[H@LL(DPLEUtѣi~q=FfПMb0S^sKGEKSb?s:Փ3r¬KRl=ү"zwk;F)NpNkE-XJ(D wΓ1'{ ՐZjydn]w6S=?9AݛR"(ib%i @WJrզHS؄,s9^B29Õ1c΄a[QW譹k-%K`gShW7__:*X;'PӞ3-6Gd^k;-I "L"QsRy( \o;.eB=NTc:} A7? /'V "N;._dOP'nJ1|U4T8>4>X6 dep"p$57IYJc6duVTv bn+ ): KU~lMV+<~f=by#x|>^P3u:n4[,B Km)YZݣ]Y뤬$oi."'a]v s£woQqU0r$+rklTATVLI\zwV37RktjNō\y K?G q7I?}*{N1Qay+갬 fvmR Ռ5t"(zx"^{ LU@+e%sˆNp.f [ysB0ށY Tʫ0񈚅s5+XM%}Ҷ^nɖaJy Ա!~Pb t4M\XG  a#Fw1@,A#AIب 1KMt@83r3NT_pvېfEj`3UV0g7eNz\;&"}BZw D0u'/|28k4HQO=k?T+bU=Hķƀ縔E^&jϿz/v.\8O[xS5QRavd  ɡEP'&Hҟ#^4Qq6~b<׾~F}@ly,1g(Ok#wV9 cm@ǔҺ)Ȩ HJTw鶴r(r͡\ޱ&hŬ~$ۅ&ʿhcoRm{I>ne@ćW(TJ n#:QrWLkQE.N}p@!{ [,$J-Ҟ5t[o90, r|g$iJR1Vqbҭ9:nt|r0K8a ԛ4H͊u4K膔Mf6(N߾AÈTbZfod{AoA󐳂B@T|^N+՗II[ՃdBIƺץKҿLQ.6Xn@Tƍq%R0C h@OBhVXc^پ5w5̀T71rSV>^4 )d}\Q\PB'$v1 {xHk`O5NlByI+RI ɻ JьQ4[EuJPm:LX h#z ߎ?&o׌E6bh.]B}iX&|/ O h7p6l/8ri}Z2YF 8^vne(H 'O-2NԧW^kn9#5rE#w-{ 8>R0kФݞ[X{cnܯV ŧr:.zHn⒔(4nzo7 RWdfBD(bNd+g@\-?8^7m3o*ld{԰zs9OZhY/&ynH5+JY sp%s+lY ſd OE]-{FgBby> Jh~,"Xlk5r\f7kް7-73՛V<и%yae`Pq)LP9Sx1?GC+Rgqڡ?i!bx4rvg6S;R$SG0t&\NWy]Ҋw"rBl3kqw4 NSNV~~)M⇢;&B TjL+]=itN.7S-F-ew0Oac^ڨoedv|$(7$ x\9܆;*^ՉL蔝#զ4٩DSU-2ODbre$@~1ul#3w*_A:#dOä?5Xaui§e}ǂgc7:o4nU`d2mE:&E{fY)tJl_,*$P7hx.= .FIuXƫj09QI[l%Ƿ|R;["uDmAe΢A,q+F֠ F{ш_%4N'n ϫixJMHWB+5dgG1148<׶PXgi _#)0[jppa,؊FiF°Z[jikA}Bcj5樈F&Wv;J!Z'f4ڧ r p\oTsQT`@NXq3܉B`i/w HV]f.I'\w,Z;,ģ!2!@HYq /}B jC|z:DLc흋[?Yi4w]ߑA\Yv b>/H|K{zf=AHI]t2R=#]dtt6[F7,*" D% a@gflM̶E[^sȿ|}(\FU,mR!P2PZoV'7ew^z?/C^`o^`nʼ6RړswO͏4Eҏ 2; p6 Y viaɨōo|΋fb),ZN.\TPAUAR̠+ߥD&B7|9"ӢQV5J-*$٬$B̂IōBr|QEǖ!RRRkR&:&=f'UK8^HKX?ݓ4{@> /sO)L>4")W'(6 qu:{<9~rI嬓Mи}!T9𥕙zm7G!KTNS $&L)L9\"2"egL=dT@8ǛIjE\s?Z$ʬkNW^mmN}$k7e^:\ [CJturjG~)ic~ϖxh]xHH@vpIv4|3`vWI]y#ùE~g+K0 g[FiWE&N=Q=h*f`~mdy֬pﳼ@l);_WRVu(7E#̋_pO9NuoNzYR.>]&AE \? .\-/o䩄>arikZ (ono"$^v@pL8P+ˆwX*1cT1txM 2 xb~M8ɧ.mz#x-͠-Vpi'{409k+ѷ֡rX!U} n22(rFg;:X{Gkﻪ_p1zGZxV'ləXz8dVJv? nZV"#jȾAnS`Y8ٜ&3O#H`1kZǻxp`6cĴhڅ!bk0::UFp9Waeض/&<[lBk:2mat`̱š#3wl)<\*1:DqFocKZ6x OxLt<0}}δEj%'IZɴWb)06mદ& _1Oۦ\=猚Q3 AޮoQ=^r'򱣻%AHvQү.%S~'4vz*,ֈ)|9g=[x`Qa;N* ^Q(o?&m5y0qFB# 'LMi6q,ŀ$o@}M^4ev^ N m Ȕ&G: #uT(W↲.d` 6٠OwaT#٫nRieTa\C:uՔd(Hi+^*g- Er il:-UW|b='}xyrp+@.Nq gm]c:.r2ƗjiӰڂ_|Ǭb//4L#£gOV`t p ؐ4Z4 `i53! HG6C-q JvyAU}і  &MS?Ba֏fĨocy`G9o&̡& x=Rq'Tj_v|\fTa?GKȅPuM?4THSiZp`U pO~mP31ʁ怷" ÊcPF;hO. {1NX&_ +a'CŴ1A0>e$*&/&\CNПVEq&hVʹ[pU-͂n::#ǧA"}A-s2!> ݉vc2^Pd^jK0oh6u8s\Be-RYla{A;ѩy5Ix)49r:(B!֭ゲ ׎ojj9KO~Jcݨ0`Bg5Qv$+^Qpu;ߘƩj&ǵm͛2D_ â&$?n^2֣V:S׫g?Q^.&+f&~疣HffI^Q*T(9A7BPשJAf$hToa`U ,ު+RG#7DjNH{7U;z`xY;ͯR\Z:5#،V&%{QDnZy);lM!{@ zX(&&I!{W55VY͏+ݙ8.$!'rˆ؊*7aj'($w/)6ikzr"^WLMw~5\yMm= X> jG?a58̎0[gM<'=CmA!|2bROX`V xvR?E%,w`FTh.?j C2/ؼ:; YF<[+heÇАLݍR ]s:OAOPȿ+gwݝAȅ~@g;HmyОQ^xùaI7`cq=} 4»!3]:/ګS?mjB 9R9%gq\ 7ImVX,Y,$H%sr|,%+RvoÎ=ɹzvty!Xɗ@WԳ?\$ W\-Vˆ=!l'!+T4gݓ E>􆰒PQ+8?̦(Qɷ΃ܼh[W?gDeHuw<,>'%WV^0 2yo(P;;Uh/-~t8,rLE{aqF@;j5plK2Nom8TupL}PvƘrH>pEZy44qs{g,sKU&j{MUQ68T" >:GC=_lK];Ծ1kҖPuFVZX#ͦ˲(%ierYv#7v9X|?P8Qs BwGLOL%w CyO"W `ښET#,}Yxg8I?,e˔"LVdd~ 99ʽ7Rf ޾TOH{A@v:inO`q\8PFKHlKd(2@~-t (1j-F%DՆۙ˃^qׅa4-1+¦:k}D_M H/F:0\+J'^Z07n @` pCYi:rw qߙ['`gDH$1HoݰTӼOaϝMБurc= \aT|IfcA2g'yqxPfL"Dhx^kz(niIPu:\3Q]0--" }~up*K֬KRNZ) ^ztKI㤒+yQ7|[^UL*0,]m jE H-lv5Bmh?#ٯoSb?7CCbC3>s}d=0nH) aVA+Q4+g\1>gVr$a)֌_'DDl+;[5T۷tޡy4OYy/(cx#TvU\u| дMdw}&}͙\u''ZI6W!*!wV nC@-D֖8GcȆt}ADwOHU>w/[vkXejt8ܨDO,x{^Y6 oX:B62PgUL u?&{5TP ݾ|{G2뾥{ub嫃r1o)ܜOY\/܎9M4M68 [I=ء]TǕV@3ruBP3+n:O< q̹Ʋk}ԑwhAHw^Ϩo`aL*a؋nDfڂsN5dҷ>PXl{QB:Df[T0͙e({mݗue̷f_T84TmXY*+;%^F+:1fR"BE9 EH_w)Tb##Г;asevhFn('GN/Taʁ$=׍_$r:£,n͏(2|ͥph;7 ?z!3a]SJ+m7Y۟$*NlӶ,T` HKTQ(r[ jv13~]M/kV ؀z ~`2^K4 (g \fKDg55ǂ)E+B NOs90JRpL2դb:͵v $,{'JSukzWC̲tƝjDf|ýh~ J:װRo*A6V\4Dl*Fym6豠Jj.ghd 0KOۜ_6NНC:a㰻 oERPwD2=I N06 A] c-Is,U'퍷{B={8Ue>d%@ݿ4@2vD׈R#nUW:UMP":3J*J٨LԸ! 8{Y0wDLz!{𚖐aV'1f$b PQ >*J.* :48v%Vpq=8A*9y_冊0AߝdKn]Z|9OEX ɟ? ݫz)hiaLD M=T6E%0@j3\KsaKçh\E9:SE~w wU.IGꋱ붠<{bفP(L*1NʳkLrݞ :\I7:}y6ID9r"]NX?%̨05h? 2E]q!.7 ^o;5ZYŗEJj`r83Jpl^A5KD#}; kpMDg` 1+1{}ow \+~- $U,~(."ϟCB ]ag6wϷg,&e$fп ӨBҷף:)*4$F>)3Ԅd^)쬙 r&wfLN | w2b:U~Hv4 * Ă+U2!<:sȹ8/&7q%Դ!rʐG̜@̸,].%"q;jį !Z8Y*Hk \|8$ʠ6v^Du+JWw1le⸨>D,7ς9ݪP&ҎCT[>̥dymv?R{DY^>%4HAc~<` _UN rݴ噎ұLX}]._VXX~{(d/uVpx' Q&-H<؆? "N[Ih;.O { B}';R["DT_=~[SON3w&[ttRN `peA>SA3+8h@Ϯ1vI}QAG髖x3]Y/tB|#|^&f߆!58{";/of#q hZJZ݀)#[ؔS7Fs0]QaWe4 rV~Ye5"x"##|yaeg (&}y^fZl>&5ϖQ: *sb.}IWp$5yO%qpq,:uo5_ [쉍a+llثY+SvCUZ$1n Γ`Q嚓p=|s^B> H] NDXaoO6{`܄= Ä2K^tG)M$0N^IXP$"ض)zT)HF5Xsۃ￯)kBoIB.;Ww6T' 0 r8?5|N%^R/x){thR;xM|iGC6jWdU4ΰCgL0-kl =g2+Qdȋ} HTt2*<+\{ ̨}opSV#6ʣ ?#hzMO}KO\c%b*!CS©'&/O%%B(>&>fSͬ]fy.LNv9 PU'ɤ1pnϯyCa_K*lؾ-zo@zNXUėjGbxs)Bc GbJ+BToQ>H43꙽GMݝ7B(ER.D '5dw] D(ᤰCx@u>܉)b5u.sƧ=E LB;}YY}є?ShBx2'3c '_"toT/5u))tنۮ@8eR ߘ nI&hT`ʻL, w؀VG/K@PLQsZS}O8;/}ú# 6ᭆI^O~DI:憹s}vєitv[]r̅A|Zu ;E;˪: 6X)2YL3egY鋛<qՙfS5G/ ul>wT!8piҮӻ#TR-Jot5 ^8[빟-u;)w9"T^<8:NƯD"(i%aZ K\shQ6W5)rvb b.[X9L#gK9q=!xJ1 |$ުsNY-20±%̩ iҁGn[&2nG;g|6I}󆄉:lpci4;`MDf:.XM A9~Aƈ`oldy{΢1vGk$1׾&k,nK#Goe7{q~'H2 x,%HC oljp,YX|F>'~D[uZd&D2&he,H2&g蟘&Ō !?Djś X4^;._Ӥf8^Lؑ˫k=@bSZ #mT-)o##WVҠ |e,oRpn&bڑ-^ J+`[7[%!i*h-XS5Whҫ'QGacաׂ1xφFnDs XV5gK/0d9kE}IEf6(^-cE}}OXi&z1jKM;mMa k@<|e1Sm[4ъ`uQ@*bƏ \V)R߹4h6vp-Lq&ɤfY>KQ,l9P0YU犍ADP0OυZX?l4ʻ@)5?QfyaL"8##L4=Rڍ=\a؂\I>G; ,4oƎ.DlᐫG0#Ή/x $mi#v'~h8Lr6nJ `#Oa=@ 4`,r >=TGSgg ȳ YZ