sssd-kcm-2.7.0-2.el8 >  A bץU]f25° ;#?PǶ@B2ȡ`L1nB a1JJBgD?Gԍވ Y!خdUa;S7ttr;̚XL\k75T8n,Jta H}y(">`(M)1+<(kwrl !ژQκWYnoA:PB-;g\g>Vy~B 3f;D&1@i۽+C!;}\4_hTo.c="˒ 1]#LI p .,~ aୢ|^dϩ+:5Ts)Wqɦd;GJ`HDvh $[ᾱ4R;҇ֆoACސ~\nkUwCeaG|m"ú'ꗰmf$Ke,8սM Te`&.no`9q)өzXkIr?V M'}ub3xv;G%64S)̥9w.?1aA_C /zf2V=Gҵ~UzU[4Lۚ9ͱWi TdYymMb{1(+-+KցyNG{4q(l4Mz /$mV}104-C6XS\N%C reFUt Ȓ|偨3PH&UJJwƯۉk$`6[f9ڇF6D#ЖÀYRfܷQaS1E] Bj*9uMSY1a? RLux#WBӱ[}'8<͢*ˌ>pBP?@d   B #@FMbt         P     ,H x==H=(89H:e&>z?z@zGz Hz I{ X{0Y{<\{` ]{ ^|R b}/d~e~f~l~t~ u~ vw x y00<Csssd-kcm2.7.02.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.bx86-01.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxx86_64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%vNzځA큤A큤b;b}b}b:b:b>b/b/b/b/b7b7acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd47963b95f12861e9e2ca876bfd31919d32b9b7d82cb82fe5c622bbcda639cdebcbc11ed12e7838fd14dca7ebf9cd28d9269f0fcf0327fa244f0da4882514f1671dee5e7f66f916d1703ff4034b41f124673b637f9fb94f430986c18725685396567fc5ecc18497c3a84ebc34bc99c526e6bd183ee5d563b89f1812cf7122c27ab14cb5ee363ff243164c528bb4b7c87131bed1f900ff24d65e1e19b0979095d42e1acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.0-2.el8.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(x86-64)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)krb5-libslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.7.0-2.el81.18.2-113.0.4-14.6.0-14.0-15.2-12.7.0-2.el84.14.3baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.7.0-2.el82.7.0-2.el82.7.0-2.el8 kcm_default_ccache.build-id8dbe4d593d92e9058217648ba3c27ab2090b0bsssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id/1e//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=1e8dbe4d593d92e9058217648ba3c27ab2090b0b, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)0R.R*R3RRRRRR,R R RR R RR0RRRRRR2R(R RRR!R-RRRRR R"R$R#RR%R)R&R'RR/R+RR1RR7utf-85e21e06b5cce5a2f7efe382620eff0ce703d7fa4c295f2c0cbe6ec18950cfaa9?7zXZ !#,] b2u Q{LTo ExEʨ—@*T1xުngk}^J[L?f/.Tdh>Ц/ Ka_"+`rzٗO&BzuZm۲{Ѻ !}x8W2c4kom-ۑ>󧣇*Y1 ur8ٚ In=1"9f!fdiHb ?4:J4;%E0lV\B !R92ҕc}hǹ0I:omգl6a'd| (Vㅀ\Df>"sŷNkݑd n& W cf"QXz 6W]Ct]qoYÜ?{ǜ4钚6`;J\թul8G~"$^:[vK= >_1<JU~F9;Mcp0>=b|6S@ X=W$7/(xvm p{§rşI%( țV w3vkՂm (}Bؘp&Z9U5Ps HEG[Mq87eÐb8\^D0,|o' )ie0+l@ sc))@@EyS7vwdUmv@6F\d"EvX@2{)NN& ;~͹}hpZ4"id~%]_eq B͠i-XԘz͐'?Z.Y2Szo2Jef @qXzeܑAL M`S,Q.**U,BIXLyelq>DiI ]n@(i|z#w sbAu%cL;vUO!G43KI ^W38g/*ѴU69/f~3]ՙ,žf$T5 Y~T 6' WL` tƙeVUZLG.EMs@eӧIvw|C!fJ|ۤH'DٖƊ*6y-q\Zsf@z&p)YB"a|vG'AUt3`OU侯S-K!-+k%'ҭpi\VO%ce.`͠b1joЅi#Uqojm<5/ ޅڶ?}'r#Fx3{;&qxc0|T@rǭ [%ۃ4]E"UL!WeMklp3c^Ȝvxk; !⥆=q׊&qxOgߑDh[Tr4Ǝ1t+ęFw+lݖkM 9wjU+F :=sK`)>9>n"|@ߠ,4#ciV^^nf/7$k/X Q^ό!3h)s?0/'i=62-)i=*6CC_RHziׯ< \a+n""Oٛt օ"~Yh"::ʠ*HЍj)| .a}exx$tObY+T nx q6|`-lq5}9\)dԖ} "\ChVl5zi`ֈI:}׍[^[YNV~cPzrC֞>JN&`}J,BMcҵuy4+dGY.1l&F53>\ R?q :R=,k݅s~#PHw6(Vk [[RL4,/_#yϼbKzZ]ysn$+53/nd0?1"}Fl8,6܁y%iTQ.<ۇM|$e:SNbE9JU+QY&I_q.sPf+=qE?yz7lB*,:P)xR VhBgcCF_B(3V{(5fev`^%44Cu!壯`u=c@#B}HFfO xn]W.C-sonBJI5jd+wY|1@X4(bATLqM*c>I (zew4PdvjUlF7@SiUtʌ6G AMbgűoB X7{T>j@8yt8lRH`1ZS; )EvYg%rIn@q07桇c|q~Iyb}@SB'~ Ev U;]#ᰧ~o&+ jw"6ʛ|J㣣QNnS`\2 C|5a[nA yn(rZ _@" &c܁Z'밀ae#aԃUսg?0+荤r~x aZ&V 6%V. |18DׂE[?:c,)32@WBWRc @,tVHɪ`$#~@]q[_5G[{-^nD(%Ck y0H_䝷Mo L.w5yۍy>X*=̆[O\K^w#4Z%6\:؜($Xh4`,\}Jz8&f((E{=v)GetCX?:`4NPr"#ױ8ULZDmB f >2וm=,=2꬈i6A?xF!fb _ U m0?UOx/!nߣ}ԃTH.h`4BMwAq; nSvU[ )-0} Qp"U 5Hi~ . pV:v%"D?-;wE]](sA+Fw-nulAs# )nD'J(K+@6d 76~C3YOSGbx xqR0%\R3Sui& '3MUq.[&"|2BNL{'Nv@1ri}Wwߩ[PalVp0hg~5io=hFq5e4-MKK>cm4~# l)MLq:3v|@QGi1L9ڱC1{U`04 Z'.^0$۲f][,D(3^J"+PÌosHofmS@1KLTގfqֶg >̬]0VnNR^>^+I!^z^f1\vP Ʉ8A<=Nn,nmN s[1T g1_b.h7s&WQd7+EjoE5bVl;Q[Bqqmb/N5MǢYhrWE`@B3Zuc4dp(N["͌(QXiݶO-rc) gN!( k?꫗-- 2ݸV={X XCŻ~Msac>sh E #).˟Snҟz1Pݿ{VA ሑ5E3;#VwDQ@<gO;CȻ/̹RrS :t%aV2{) GvٿH:Y[/ QNW ("-q(kTt/g؛';bWKǭa<+_wIqxFZ唈2YhaH>RcVY; =pk0&\tydoVY%l Cqe+m}Lt#we:ռ*=Xϖht:OҞ}TʰAp[Q,:Dsd&cC5*s]iۘːrSq#O;m 1Б% Q =R*}oAL:#N>UJ{qͭ yT+f:4멀*o.Sj=A7r`xw;R$c38(Bx?Q)Hu:0l0rWRbLJB h]!K6yb9 Bcs6lqG-)!_3WE>܇kc 4Lo_3 9WFcg6o}祾ؗ3Gݽ`='\nɹ-}+}t wF#s!?l:+kH]wLY e]QPO.֑9X߳;{p?gܺOظ#w'9(BipGGk0"b C%Z~;#(ׁsrISN5bqȻi6H6<HWN0-GsJ .> ی,ŕ@, rE\ڛ3KLbf" ;c쟭-gʫ*fs@tp<))CɬC&\EJy^zE;{~<([sDl,0r5rPB$4"B=!L.-R1$]^l 5%4:ouwdכloB7y߅>1-:- OQE=vȆV}Uh, 3[=YNV\\Kv6brOERG[Va~ޜE.3xBT0?V_SVleT^U6wj{bz.}Df7) J A;a9wlc1/"qfΗ]`SXX2~P\9=E6:iQ\Ucz9![uʟW_LZ$/bG1bS2${2~֝^ P20]`<+O{ϟHDe^1S5rW{q2;5k6w| SUaɯ`ڈC` -P*o|/bk[ǵfBQ)Cq̓K`-9$+c&}N<Rpa ynƸP݊wzlDNXPDM^`^W9֞g̟ v&8݀k<#>\P(gl(rWd Ody%hҝvt8 Q9 PN1gF+a8VOl>l#H'M wSC៟'UC[ }#7iՙ`+nR@8읱},iܔˤÇ'pf5b,n;1.G|X(\FRR&ۏ5Ÿ>IYk RO5 AwUL IL̀ϓm-*f,5?f9E=Bs'HvƊnH 힍 J#vAPX71^*q`woEf{SmA:% ( 4Ѿܟ+upq] 'M5km+ Zm8(?Et87f(#³)p CX5ES<ű J^7p^vA*ɋ &1ݒ;Y.s>au4ڣZ!h<;a l b4N70gmQuH˜?N,*m4۟*#%s;UMP׷#NX1X-k +_=sZKo?yo8nr?TT(9$_{Rj9 #=xGy_w鶯q'-^7mp` y92+AazX6<ʙ?:"D+hu]𪌢nѫo qv ˬ dA4p 䛀p Fy-k^P{'dUz>ZRؒR q-YL2α΍s%(h2w6r!̕~/(QVԦ$ 2i`NLM`Z&. *4 _qg܈SfRw_w ^Z 2ֽ6fn {\636ڐZF>7nn˟4 }\U >+sRE BweowfQ5۶ X}ܞOmUG9EhkxL<6N᧥4\< wà83}R 04O[̎Xi;8ӮgAx%{*FvEoBFw官]s m.{yɁf zXRn%tqկFvxPu}zGV8]w'U'nIHtSOPhYq6J,ǯyzR7ߪA"HXk Rk;^2D #\@h we;I]RYz0ApYSoTr"IĶc9.a~hAk+4ejA@l{4kM8Ʀ;hhޗc z3W,0oy9״BfH&/vOq WJ)2\ks/HU\7#Ejωݹi%vZSSBK!Nm0XUkxhuJfG'E)G ' Y{n{F[ќrbXt r~VKӿh5(irK0~Iꝯ@ό=ExBDuy [lȻ{$Rf!uPJb?bA!h+GspV>=3.wLaSaXXRr0ԂX*h]0UDΥ>RpJ%Pr8c]ᵡҭk$J}) --ԬuWIS6HV;J_Έ8M4'b4@hD!cdrgoGP~8=J>J$ *c"Vq6_c`IhJ[!ȼ0szqCà!Lb P~pgKbu2[ *'L m<"%S{nhjfc@|vjkmW!~y_9|::ஐUt|=W1]Z4Mstbu).3nw?.J !X ۸THڤڟлa^ 5pFIYth"e7iv~p|3KEUHؼyEWѮXkz~~*bLKFs5OY5X4r_ۗzܚ=DݱM&CqG2dVR+j cxVe?v@A2Ǫc|);g%bt  *ʋ4;LgG#fs^Y.upR%LD8߆] }DrG*q3 vh n]]Exki;`^OTqF6xhGݓӥ҅r{틲;mQya\C ; +qvdF8*t$nE2 PI;55 Xd~ӌp;-֓v&O]FL,Z~q`V#U&C>Z5#޾(jÏxDkK #;[ \T\7s[F\uFDk2| 6qFK}a?-^#F* `-&\Y^S}{?aؚ،zV֊ ZIUojlһldpril*a_ˉ?s/B\z`JUBd=+`&A#$~8UwZo:SB貛?<֙ȩ^z:ׂv7 qfh:Sm)24937 bDh oCE1mi8C}?cl fG+%SbP/p[sVwMR&ݙX0vF#)NC͐1 Nv̬2[R.m; !Ɓxc7: ZMkC˧ZY.ru.AFG?촕VÄ5zJ&YK- W7Ox4lu|QUm[OnRʴM'l8yfo|eԞm]h|Q$'#1zw H[[r&\VaiIs)&>$I(`UQ,!Z+(yn@XprfE֗P=Huo':yr$\"kNzߋ_mP7.azk2=g@)&a ~uOI3;!KÍG%n={)NrR|q%K6 eh0ޜ<qe& kgO1a\ђ2jC:e6[ j˙_b%'$75&c!.4fB; [Gi.|;' v m9.6VueRŀP % ` wߗyEx)1:d5Xfa[Yw/^(1*ObLfk,l)N0wc5t3ʎ(-yH&HCxqm3{mΨ 壭/繦FL F{VK><{9ԝ7'#wd%LU2Q6XJƤjǞ;>8gf^Di\o"@):Y^4b xC1%+~f_u=/Rm]1G.#w\޺yNK+9IxDno@PSZHC 5}M&ő3u7LѾ<gEvd;B$͘P&' Xvkѿ|icr#DW_&jJ# o`A]i{^*qx09\sRt;A`-;|aoZ s%|2eԫ_Ţu7~w}J}ƞz^" A`KsQ}c&^5vg.@SShk@}mߘ+x"BˉysU`E2-V$O%D/500UVX?歘f~{9xkw܊ʠPg -dy'+߱XWJMBNX} rciHl87IO+'T.vD8z-c]vzkD6q"Foﰭ!u|:sZڽeE'OL>"SAw+?rk|͎RnOsxqEX8&QR<=Yi%IGS/-łh29 SCgQ͛$#A=gzfK#Z\RS0nO''T%b 7/V,_)yDy5=8%QO50[$$,]&J|+eRGA.c>IKdfH}Ӹ ٸQ-r<,~VRTK۟W8\g <[!]x5{}L+HtJvͶ [W _v Tje?*G~VVR+2$2g7?/ y$|.˖y81F,5~\.8kg()3Kw#|điD8{PVނ޲(la8mx0{[O+BjneNp$}(F%ٱmsR$1peTuhhfʌ?8nF^WO2%n=SnL"~8Qaᜉ3gԸ2'CVfTwXBfģn) AK/=rbɊx!|nN2qRv (iW|EiRBQ)5B\qm`@|kz3}ӆ|JmMon~r"Fmo*5"laO dixhHm"FZXjbӗ3HQtFEײ0o ц=7 jz//5tR0/Rʔf6ɏrkm^8kb͈g-VlDj3g Gz%$?Vpkwor#+;Üo[뱚'.J#PgwcʨjBVFs}$xzuG_yB~8cRyW(չа~N}"4npK+.wxM+0^Iz[6K,åVߖ1QxThȰFa>j v*w` $;JK 4Idl6\YNIiaYEc8oG2g*2|ҙ ̇=<-窭0"')/*葖(_u(oRPŖ;p w% j&c Zl~^,:{}mip7GSe[*ڙ*d9K!Wu;l}Mo#Dmq9񧟬7ԉϣ„TSڗ_ _ӽuFEէv0tj&s2B8fWQAʸU eUr ͻp1d4*f pV}1 Bη|E`G2BѼؙ^.c)ɣW;~aG)Ev 9< TN1e P=A)R%(&uH#SՌ@&3=F]*"6?HՏB]:;B;HD=oYV'?/Ku^bATڜhNHږ'k9%?mghWP_@[b<$T ?Axw6 >'ty_)9iل6d+: ݐhL˔,e:L0FTc#/U;;Q7ᬫK6S@T"mɓ/Typ.^_ hq+[ڔ͟v t?˽@4NԯFx upoY j^bփH3˕9>aOYHಲ^ki:0_v̕~ QE3B9 R쮾g([N"C8^^OWjO~j&.E3fp'P';ߢb-i=s= =ѐ)k|.BpU`Mnj DI833mUO;<ҽ]_j#ƹ%W*p"kqD2LMv@)MwH`+8< s*X/E'aRV4$>Ҫmɋ쵤R\#րy\ \RYט0ZYB4&uU:Bv%jn Q?X$V"o;4LX z1p,ȪI OB59g(QnuѨW$. . з:͐)J..*9; PjQyD`ۉ&^>u*ASBXr$A'!^ ib@x"K_@ u>$x!ܦʑBnqD~h%,w@4wWuJmL2u.B3Җg%t|8֧Xh|1O/έL8&뿺KyܢWw|%8Zr_8aG%>X&5e^@$}Ao:mc4zt1(:jpvh T&4nu!tb&kK^`p At?RųѱUpq{+s~\NU]]6l]!mȄڥC]uKǩOn9@#^`ED0@t\}PHM,(}D#ɱSh'm?ئ T{S!b5<n0%3zJd%zCoQI?љ7lV#ǃ`7]4hY|J9YGSE_nx_$jif>U" p]kӍWq/]n$§Bɭa'& U /d}q5y!RZ%MOmeX+O#A]|+,yaQMZ |7wm1I0q\ hV~!J+Ib ;kfۊa\nO!YN{1:y t/zx^gzB|o RO2U[8L,,OMMF Tٯr_̗A\Ϟ* Z Yd@&eoN)z^1 O=r:Qj93 ƒ $ۀ*+P##if¦IWP%3=;LNk= _`tEGN8`U_j\K9 Fs ~DTwJ !o:ނLDOi֎/1mhbZ̒2ԉCz5IT]LcH,َ@2j+-lԩ B[{CD<˗I'o ׃N00? .ztzU# ]t?o-; R_oh]v@Zjh9P`B,vYuG[lѿ=OM,Muo\Vq`497_3-3]/B,h*N*r]>iKgN'zf.oJzd=_8cq)Kmu^ V"[mFr6T<3f.8&$x> 5F;OV $, ?MCK^_xNt& 'w(Yt7f)g!GNxoXOB&oJk]%Z=I0Қ)4D 9D&KmԉƦhokȇ\_fOJWagVƐ&j`-&w2j5q8GmЇ!ۂhR ! -SU2n`D4҆;VH6,}Eg@Hજo\j;}p'MuAk3%gaUbQx If<ɋ=MM0,2ݳ<Q~k·:>>Kr< г(W({A瓎ЉkE.K*lb4˼.)Oh_vB5_b쉵jʪ}|6-eap@s_@Inއ-!iXA]]4ǧ; n'R_Cc'T!st)(f/k4vECf1D>n('KĻ4rOUnZ1/G(6]a(KMGﺁ9.xd\Mnw_@!\j$E*NZ f˷}U5b>%F'Y҂b =[aGӡ^( j*nJy9䯢C."*Ewì #Z("V9p!R3ZC{NO.)b u(j,4 jj4XAKXS%Rlޔ~Jޖ+ѿrw'Wm@&F)vQR~oڎߡ2kvBՑ C8cJϊCQ]zgl7,/N$x"ql3= ^/?cCR,%8]h[ǎZV)ѻ+.@v&Av.8= vP[b![YI"A/V8Nqp<WJ˹21yndϕujL0\ ӚKdRB9f\H2DŽX8A\M 0L$I`ZE{'3<+6îmFsC S^*|LB!K^b4N)J!8-}F'A?q.ͷ xP"q0(.dx:Q5'1 ٘/Y8>$`䀸'oS6EE=dFh糟>Gm@G ~PI͛FGZ4:bn$~p,\c91@WXfX..[ 7dpCBXv%?QyG0 ~؋]˭6L`KdxF4bHfkMg'OBH%JvyHQ͊\0M d roQ_Cg=JȞpj: dp,51ȑӯt/'T_*#oJqQt~M1̸hq}Yc_"߷ޗe؀P` 8[‘imE]A+k ;>0>,'Z$Kp$fL3'*`| Q?Rߦ#|e(vV[lEPb{xԁt50)+{]`*Sʇ M՜M>H9Жqy_4e{4#l: צ5%nc#D*#𱥱ۘێ)pADELjr L$֥MФ-q;rf~paw9{47١^g n2Y&+0Har)cx7!af樅3h)lSv s`ǞAӉ.Ղ Mysb=9"ުV-e@YӮrvTS;.iF& c%t1v^Иw*MvoL>fEcϠ2ާẼϚ|~MإI#24N-$ֹ_y aܰ==ye I-f\Wr~;z7܏LC& ˛ݑ@z"hb.΁ 4gmm#u*ﭞSUasKKph$n~"w̑h //Fs`>UgtKPYO'q-j3p+T]ЕH_7s(j9b*~2s}q|eN%h3D‹U"1יz@(d\" P$a Ma,JY~&yqNWLEj B7 sGNX Er!;];#-do{`6gRMP9+rc6re4km6QPoYEDGi@=H{*#Oc hŐ=O$梓QG'Lvm(VʈM V3u?ʚZFZ`bjR5Q &\ȫ(+e(m04x&K@*7\'i/ntP P1Wt9,?@큋3\t@Mc #y]Eӗ D`'uR}%';_2ܣ=E]̅ "d+nlpl.L_4HEkЫ'MH<1 f4Pte&tN6Nuul*RiYu=vH / EMl'o7Fm# %\Vq`paoNMa3IW_u<#cɢt ]83:V6(}G <>ൺ>G9^(f /eؘMF y~*x9k)qZ(? p7Wy`U^Pb蚏V^o͓|(] n1ώDҌse}}*vXC@)/dG_;a9E x^b@d-DWe5sh w&BFme`fCCE&´5Ws 좒ƪP⇛m(2f iYݣyg"m,S@\Bcf `*>uȶ:׈4r{GhA=iA:?E#,G9BASrՉl~2`ξѐNu T]ppJ&LKg0G~DGpz_+GV?ERAXsMVݑQABGgԫcK?V '}A֙9uPU-b_;$- >Mەf%ֹ64U@h5^Ft|j"DRcQίNaWO,|UvyִBpG|")"caru!N3םvV~i5SNv0WBM@ _p4kFD6,ېB܂y;[=(W3#.EnRTP4 hZ@)3v9{]h&j<Ͳl]j2Ez~MmRǎ^c|ݨl`3aPK,mC%˱Fl NyWYH/NEToƙ_vY{D1'әdʗN&5|e%-sD8 Eov`ьKF: "nO7DT{@~2R j_s;Qbt3XbkLysJg-a' =x|H4ep{ )83fU{ b<K ?yK&t-ѝo{TpVEO{ cYGԼnGȴRaX,8#-\v`Q(,3h,!Kn+¡9{s-wgBtiA@jʮ<u.L3]ѱ0pZkĝk/ `>¦@Q qE)`QvEM[+4^)-#gvt@h%yܙ(ry̥Fݚv]5۵}<Fx*r*Tq1^i8_E[ pҘnvtP9327壶E9PͶ>D𝖭žD/O47h!>jS7XLA\t 4(Yx,_\w`ŐKj',csQ'y4z˜ |[5T=᧕I[jxiO3i[|w|{#hR4d8>7cÛ{$GeEs:2{k0g )?FTY9}'TXiL{!iԷB"A>-3-a 2Z5˟9*."l:htfYʬ,o)Y?~F=vGԑ7 4.g,~(] Wp#rUQо)C2]^PΜêJҾEf2.'YVNc[P J2C_{AG\k/#s}d.g KuC!ce"A?aN2 >oJNۃfZ-`@m_}gOY3ji$-&~pǽ&+H>(@q QI[DޭWoo|d_g'b "s]P9e֔?GjKwi.($IGLΏ'9Ry1h$2`c^raۧfu&)3 _ zlYH]1cEC"n֏GŬEe/ѲmKQ|Ոku8e:Yߦ*< m;Fjcs:X1?hW]!E;/Ii-@eN?2+JAx؈UцRRS X,mҡ tqR,ȞPh6EyAI'hov85\r*G`l-. ›\c1|⽰1Ӱ| w@TXa!7DpUQ쏜Ө矁P^U-O<{ iz6rΛ rOA u' upD)f ֥ 0rזm86ٸΖ@e>'ٖ,̈D_k0t]&"O47.z.utl{hCh\?I2e9U+Yt|_1ԮG.I% wY[/6mZq1!6k[ p/'pyw^U T6PKkq/40a `P)M!C.]{^w6?S.yo}P%,A~6ksqߚ(mz9ƀ8?RC,8 |nj=T7|bc(S uSI* / jᔡW,.:g!J/CPJS۵,~tɓSO~|3\#yo2wS_j~B  eZc{B/М=Uܺk(TXXAo{ȯp' Y/u]&V*H@Z)J'J&`<_-2i§C7=:e"?L=ϫsC5džyoeb0Up:n}r## ʴ͋Fn ulb[+U#Rd&w \,o u䡹h.LA1UsU}_e>s2 ^+òLW0͉%Q58st/2,疆.PSty4 ,+&(A*xD/V棹hFVRFcztp L2=pk:Uq$\%E\܃vbZlvF$5B#+#wsjM/,jŒ_Yܥ? B`r_"VfxW';?.Zz g$qzkkH48x'щ$w^iMTs9\`v c]8v% ~nWrb0aêa jl18M3Ȓ4g4pl_OI_XT]*6eWkuIHd"|UX笔ݾC 9-׮cPcz4oݣ`=f#W`Ȣ?LIp;rۘ(G1,8~'&&ByA&%9RMgQa* g(v)gώPG/1 _jx$eh$,i]дQճ֤)R[2#:y c{-lΆnUhVKeXCm殙[K S27UL!uƌ$9frE;8|, *YeUXξTza^Zji'T._o.xNJx?ۢMD@v%Avlwi&=C~[ &MnJ̖FYi\=CD8W^qn>'[}ŧPd)h{0"@ڣNa1o%6')UtELdyY CKήf"*Es:|)4[OsV7&9 _(-k||MR2Z%#7<}%#ȿγ/r oOHh5Ys)McV< ;i3Gr0S gdeϪwiAbKϪi> ħEFפY]rtH&/6D 8'aTkn[ Ҥj%z=F,o>(︌ (BFdڒ4(y˽0%X#*08Ӯ FxdDPAc0qh \f+.v}[Α{/TBUwu0Pa,ÐV^9WQϷ0Ģ1p\CGՌeH"?\)Hl$Nq>07a?)O"X lu&=kTQpe5+oK.: (RFF ϒuju@ {G#H3Z(XT})tYt@V 48: ؆wBꝣgTQ2c=SJHnB0i@:'PJ?ӴʤӔ:SɃAzt/c d!2%AΛV# lrW\?,0ر^BJӊҎAcA>dhyA`"w_!$+LuH1cd4k4 B5^# S^9pj+j$C5mYj?$BWٕ^ tlHp_W8x_mɿ&_h.X4]DZtq4,ڳt{R M߱nqL=THF x :@ժgd:vj XM] 3Yn{r##|lǹeZ]c)^ή%E k8*sh1 6w*NiC!᫞B͉j61C:R':Gx^^/-r<+D@dhWrgoکV OT𜔿P?m H3+p- 8"Q*8Ge( ߔ\Bkw޲ eH<տ 271pOl>'eMI=ES4rK~sUz' aɼ~)1Ow{BQ`V1}="(v<4C4ic]J1~h%l Ad 54 zy! +Co6X~~3mKESgRhᛉD*|v&MId1+?PE>;L t;3Zgرҭ^,%丗EK̐R#Z -`bacSXgAS}\-!2^ju -_++0@ҲŁZk &t`4rFq ,RH `᭷o3ΉS hd#B ݧ7H"2Q!~c#^ X97>BNUJ±ԟ*׌ ?O;%eo>-|;Ɂtx_>;*"ZK 'bxzF}KrVI̤n62T4{q&3~pJJ{MZ>_N#!{Q0t˼6aN0! o-:e{<.jJbH߻OJb>_q]LPڱc1=+{ߊce-SҼ_kk8XOYI: C-TMpƒA!,m"4@}1b ժya>d]HH  Y@C*c;eaUf# BB7kVN5 273PtG}xx?v t-KB僖[Ѳ,WU8n*^rC@%#UR1x(C4$l?ad wH"҆>TVR|B nֳpBj0tdɛ^klRXWQ,2w|K>1iҳI..r4L+jZ$'3L|{{NX/*,-‚u_'J`kQj@k(|}߇mkMs>@c |x6$+FOǡ!iPJW$sGC*ㄴϱjw"*+QjQABOtLă; ׯ "+ӥx!m]W;?,C.zS{8{20qJ%CǪȒD]7:v;t}2/r؍:q*Ɩ-%);ԓM}dR9ژLex/RzPnY'V @8nMAU'j_l!tf lⷻ 1r~/fa[ޱ9ȳ08]4ke [ KuO3ԎbYc7:>LBBXL3U݆!`Zb0W+m2i;MQ&s͕v|R[H_z1V5޾1\6IB^`fpKl&_f~,C֠TBow(^n.+sG`T` 5Le{d/| RU0 zB+, PѧRL%xw{Y'J_j ik}br1q? !? rW|R,ڼCRәBce1+fh# ٭<Ɲ\6a`@=: _*F?9ǿmmiG[ Z?mOQ* = ;N_Y1ˠBbֵZ:!(_8Ѐig.2^a|=qO:roٺz.ʗbe k%$oa˙\$0~e;uTH sۓO3fƐ|FU"B[::$EKiI0jS #!{Z:4f :rryS71ɺRjtԨx5җxTyVZ-w]po2;g* @YDU )%y'}_z-VA |ze)1o7I B;B fr ”gW7M=eg5R~Z%;5,]Zy \K縤+bnVr:ڌ*ppPrg4%Wv$xw ސbkoy)/qRLs]?-3;|s&ո]B-La0$hSւZ0z .sJmyn#GV3k X6׬NMFVp|#ŁonJg5gPuaœ.k?}x:TҐnلs(Ļf9">6M)Rv|noSJRXd3U?;0LeT  qg:`8 @4{$k+.tjzW.)=cήHZu k* )q K9>^ŐS+572RzOgd;J jQ%2nKAK\ZN`\bi؅M_ILq76: $MDj-DT}H+F/FGw"E|%$u jsӘV6[E $u4D>>-5~$m͋B.粟4誧Uw Qa56'FscB3\uifLmVL?9FJ|Խ0UpFCK9&̷軌b lyfg1eC!NlDz9{6Ӊo(Crlb׺b~)cf-L O0`~wD>-f[SCiTPm_4!zqrrR U?M~ )di,Y`v濵`jZMTTD㱹R&E ja#vk\ē3e0=C#6~^Z{Lz&Ņ5bBn#o& "V}XMh@`G҆Ag$r+W,uQZr =ϖ?(EM&:+;X;WF{9?v'*_U}}6, ո'xpN?U.8ry 1=VQeyFIeM*4V|H/>"h&+nC*)haP.*ʧqYã_l3d+vؾ~('TܯJzOT$.0=+oes'm$K`\NaNRD&A2 5aHWIڀݘ5<*t84i~6KJ(00uhZkcb{**7AZ(ө];^!<{2.tY_x#Y}@YBICg#?2A,MH@l̘;ߚ k~S`8;ao]}=ϳڿE'N(Q66ّ>0 ,6(}#cJػpݍ s(6bT4np}dz0/+|_%O4r٭QN"YBSWF)7@ۃ@ĂG:>.CkWYZ(4265GRbRlhϩPBfy(2ޚQ`uS77KzfWhP!5,pہ HrtߓK }IWC*b3\jKm4H Fm\݇6gsɉɧG ߃?VQyd4O*D~ EtO+44'p%'+q-y6]n9B~nFT/aO(KrSMWVlSa#(“dS_.~zp'U8 43Bz\BO}!F ϧݱoKXVrBȧ$xk4ƲֿT#nU$ (fA`q=K,EW쮄y}=;C\`ȢnyE~$g80'r3!0#Ҳ&>8\芅 fme Ӈ(EB)OJ3VR./Q6fK>+$GK䅻 wmG!g&rC4jp^i{eqRb>RF/If|,@ﰫ[ojӘ/GMzb^Tt=SS+Czh>D\z-2 'a#P`(U I.^J`rBx@8A3B_%*=o<6Y.9 !O]:j{m3WtQھ_'v=`RFO˲j K/\ja gjY<[@wR31q9WkϗBsq)Z_넲h v\JNLXR:>xwj M#ӔR1KհwMk3̝dCIQGC=#N5-Bx>X,+u#M"54ߣ hם~' +:n nN{W>&<1k*LC3aeI; vWyCaZ޵D=3}I7#\3TʰE_*ynYHͬ^) ܴUL?]RvB xxuN"uøIɴ *!si‹ :rj%|ƏXΌ a?S1=< e%M6mF=52}|SLwP;l*o3Yf#NPK?G-o`F&ùMw'}rmG*:rVDa?]81R_Xpfȃ][_D[(V'p\LI,I)IKSzTeFZkQbѠp)dE7cZac*xK(vw#P yDS JgQ/G"㱷e"#s 4~kO<}`r}ju %-?Klx]q녇ہesGp=m͏m2WK=h•BOkݳMSW@LA%뚗 3c .IϠu9cהPHjYpJaM/?syh-~ަI+zݭ;z83ץ %YT Cvm"ru ^so.ɭ$"4dO"!XGvn>ֲ×oT rݶ|VAM+WRFSASv#&..۵zѥwif.AH߱Ni~IOt'ʒ&ː>%2lCZ8o ϫֻ/+eCXD,Ik'oYS ԱmgO- i=H@ aV ?vD{&@AsW>J!V5"v=[}&8b~-QwoawQHč] K_WxG$)0j9<tNY&9Dqb [{0$i{w-L9?OϪa7X BcMБ1)@LYƈ|ˁ; W!@vEVks i^uP+^Ļl2&g.eg WMO{WCK&!pI T[aoBu-^onϠlѵݾb̮}RSt&q;a/w*SkrDUJ=K&ABE@Sov|"=ʢ _n}$nⶪĶBPj1YӃ.XԹCAv5)9]doF(!1w 07Fj0ZVt> Nr+ h>ǜ.a*~FQ }]jN+CYL-}m"[q֢<9q]H Y(˃#y3DGiëI[*i3Q07 z/}f17\+V]/by,BȪ9a"}3=NZ* 1^ivH95S@ip]IqISaa?Cڀ.s| T N` Ab0iG%4)J$<=TD!$mPfZ )$PJ>$tj"Jv2 c:T9O"n5Я7ӊ0bRHzG` [$<\m(pF/V4Cw@\4esH}nTG|u^w9YH*«SRQAUV݈P2}:3g'WglM\?~dlj8"oP yeuUǔ6]aP.j_7S道G9/2JՐYQ$܂⠢fQI ׈4ZP%oPdp f Nf[m5NE Pdѭ"4cE 0ltFnI='KDcuJB1-`MJ? i4i%j9"nwΌ?cKJx%W\e bS4jDƕ3J30)m6C#Xܣna$>wLD{m{F-ϗ26^וiiI; 28]? YƸ@c9Dfk׮.wfB穂S#E -Rd |uzr~0_[N5L;i' fQe,rVW=C@zG!#spV\UdD9`u.s۲zAK*ֳ2+aU2IGR d`-$KcZ|HY?~<3q> _jś`APkf>vr\񝉀fN+w3X"I>Ĉ=Y\o^5KϪMI*$^D2V:5S/PHF|:s?6-sBٻwmOOi_~68NFw1Mi^T%4jVD$|mW5RwœxW;gx qԦ=8-6{ت`H>93 4ay >Onf Wc=7ԃߤ;^E2JQƱ/^$뙦 M;<~Htil-nA~kx{KWo p% [2 pђx}]B!"âH/lT"fk uǁ &p1vt&3E'̰BչpnZrGe'VDxg' G 9PVՙBwg39_t sqVn ^?`ثaac 껛6gBw_c>u7=:hQfsnVr-W[jo5n5Hh7q}&y[9RpfxR 9IfwpK0>;rdW\q !yX L^~dG^v=(V~8n6sk(4ūTHGg|ȄmlеLa{m"l3\t,bIEuz gٞ~}V6YWJ~y1آmnzq4qrXr~ٶ*H*`"ŠEޘ P.oP5S1@e\Է5$$}%r>v>ʯ2Dpa,ډM7/rO :[d#(3jVph5=Kh $Z,>OW4>`?ݹRwv*-C'pTX=_1/BJ28"ӳXN^}AD3 Z4Tx(8?#+wQQ} ~' D h hAS;T'o܍DN;KL-X~ha4\X'Z0~=2cZJ" 500']H`_r3:7#{[sLMH7GOv19g\P\ xz&vÂzIVPwaXYCϕ9P*JL?-?ص8^r?FTuފ+ ")%׉m{1 up|5 (IqO"kQ)a>?){~(,@m,`}SuU͍UsLC,u*lIhkMGhg|NJQZ`#OW`F릾q*GfwVߒ/Āk ^0 ) [ w[\_"EaJZ@];0̩F U8&jBFvG^fb68(xR Z`^0sh%Lȁp2R֗{.x;MRiCIuW|^[φɛ Jf"}VLUz^"uN +|L`]kG7I䵯,~6y,ޟj$yqIv/` $ʄ`81UmtL4D7V|/V4ĿR2[ڈk6rF *yoܾ-J17K3[]n6twE/i%Ot0J`tE:!6} aֻ8ue k&paG Jb.]8OL3Io\m<,o)P鵽deTiNh
_\ +Y: H<="2W=R>6mQؼk&UZnq:iVXa%RT%KTqYJg |LF89_Fcxm-9pGK #D◙֠zǙ~!k-0ƁRG60ϣS!F嗆P|fYmwdRbYCB"H'Mշ̺$^W9NǮu_+/\bӵ A16捞o)Anx8we@?vFr|5q}lQiX0uyq17{L1= k8* RաDKۃ3qғ*Z7,ǫlsD=nWavlIG }eqb1(VDѡܵT.E"=Ӛgkuj8z+ʻ%Y8ܔj@ixioii@˖\jd,̩#9g}QNrNdDZ"j^B+Uc=EC 5K#5*ueZ뮷,8s R#Ԉ4Z\Dn݅EgfN _%.fzv%K.*.'2RQ[!υˆ`2S.Tr;72 R~-*5ʿ6WX6U[#9< E":GѲuy_]U R_ Js!t0:)GhY Ͼ!#-e  _mvE~,p@nJyu|(O=Aھ>st^S@i]bc f'pT)^N^)>AKR횛\I k#B>+7W'YoꛏrJ;@3 `LAɂN[bǬ-7ِij _db g6~ Uze&pZ苧g5&k,7>;-gB^}<=Jtڜ5s_arC;4ʯc)BUe}<'HPh F ^ۄ;T;ic/~%&Thcg#5j!&Nސ&2\gR=iTiJ9S`^={fĀR0 jW Ǔ^vIGI?UL m J.{YܽGMh},4$H NDO.ѤH̛Dhb+j-Z:;l`GwW5wR+w;74rb #ctPRs€2|ֳ "{2$(I4}m Ԇ=K*R+uj9-ԝx‰~WG W^]0e|RErJkZםpC)'C趴jI6Aqs U$qMrbu KJU 9^up@lAvnTnwVfn-1bB>iA6xL'4W30x{.}s,\>)Tct:4jr۱.H2t&A tuq\=+aH\/rՙUMDt6W !$k%/JQScP t;kO[(C?Wb*J?>%l L=L{-PI?|a`M3QI?5 FxQ7n /fbI'̑RQ`&xpt],PDp?g}#[彏Mh" q=GQ~ڋLSL5OBkzzC&Y6p :B-G ֢rj vGi1],(bY^J*jsiWܐ%!8K]7 X0Z Lɫ{/I^p@38nAs_^nx YH/ w9b w.;štTˠmO^,?Fߐudw-1D\[ʧ`mm@@?dQ"Hg GW}DU#|wcErӘ@綩-i!O#D uGSRhBa4c)FQ y(E*+ 1 ade;%SM 327HcoCKǁfyICHQ=+f7IAyh(|$UV%ur;Ơ=vbg:&'TWq%Ϋ Jwb?J=u4r)bH<%`A B~mMqve՟"`ͨ{'v 򆩯V5JXe^Bj鳂UqKձUْv#g-TgcƉfVd*@(Z;u™'bh3=:=C@j3*^Xglsa[/7)R:ĕPKAԐO$ϼ{Ltmv7=edyx5‚w8BKaX<}ΚL&X]^ fswRׇfRAčh]ljr#@~C۴À3אiX Ӫb\o><jHP8[X_S6G\?6$dd7o+fF|j*Z#p$_e[NoD$U*v8yE:Ҽ _q iiE!4Һ;!36 8nFv_ƽŁ l0-1<<<7p<җΆ~dP<21A;8X*t7~ǡsE?&7TWIBҿa1Xxgpaӧ(eR߰z b/W\s{~&AĭU:I` R)π91 #]%wzlQck t3vhYα8|i?^t*tX-Ǎ\leZ rdF>}_pkv>}*r~ F@%NH޼}V\gx(V_nT8  \JPR*4G1?H<#f%ۮ~uc2dpR LJ}n {S_;$A(+%H2DyK^6J/*F2Ci}ev쳷eRs|h%u!;bk׹c@ ҩg~ޗNhTK8b4w뒭W;HQ4c#1vaCF1ˉt-῎v] 6&pk##6edG&|ixE2LQ2R3L6ci\*HS70eo+pIoJ}R0d46 sa;v?hU~u.(D7Dg O'U PvI.T$64L$u1]$dS8=E7aN1mA*}iJUboDj$d,9 J2r ^RFe~Y{Lb@&!.BP`n:vc:"&i6ī%5I;sX1ӹ7ZV8|z9E̗w+8w?mfc3;co")G^ݕ eEWC:ɳ3 ڛy1{~kT]oh$g )Oư&;:Z6nk:*3h$JZ'j>F 7g J쭱>bpSbl(F?AZ; IcZFĆJdIKA]\'-yAK;]* {/8dvϕld)Al7}~m7lHbEμlPFR!9/c"TXjV$/;'kمz*1wnMqrN'2DxqfDiZfP:x%^8ZJ߮-H2L\Rs42B]APF u,G5/ `Di>*ΆKZ'F2ƏCYw "ю.NĢ.G $oKLyuKDN @ [#ˆ`4Hû#ۆ"2 Wef,#Bd^:7i\JP"ꚹe_?X,Qa@D^xʧEU8teV׏Y%`?5JOh~9![4y랝 pLRbI)l1ٚ՜D=Pc`UO&6cY ?>I9wug4 Sԕ`ϴaVg?HNٌ1$y,tׁH@iI_ JC nmܦZ:]Nb/kf+?`yTv\հH:b*M%EQxXuZ5-!Z.b?[505 D+MzxIKkF_ N염c`;6z'grW=jtׯ lg8 V o FIָ#mDY9r\?O5B}%NY<6.MW[MU;s2z7vD0 @Gvk<)xNK0ݣG  'U›tu$>PK;~63?n<%h jTӅA^Lp- `z*3'\V{ lZ =uzT]r!&zl <"(J$_Ҥ9Wu#]?О}D.Y_:Bo5/$!w\Nef~@Ah2"oG$%XCzYv|B}<9wcQc9Vbp's%I'?_ c9U|r}(HvPg4* c]peߑXY_'Qa*áIlXpS),?y>mb[IvTF5pP=km3,8ixl/= #HmM/+ GfA ,,ےQ54Hb//k^U:ҀW6eLZ)(S}: h_eqq 0(θ76Fm%WNL<_)˜W}`u7 >_SFsiF s)*@(X{v|}ؗUF0:mj x0nge")M xKۯ>[DS[ *Ë=F1NJ6 a^zO!+&o3 LknA>yoW8͢:*dGfK,v?ӭϙh>Wi:.lm11\Zv8v8&ߩ-@'K;coUFHJY81n2T4PhT68!O]vtg2mP,)Uq=aDqޫg>y;[ǐپֿ!e  ɶ^}>\+F!њ]xKT.GT]q-3RtZkpbB|"o8N6]jEkz;xXsW~G dDfbQrD84d&5ӳdz~[>m|zWkfRwFaxvq`rB~ ۲=~?U± q(2L_LTy_§VZUf0'0O{͛#yYR$B-Kqʎ]F+''hǂzjI۱W@o(%ʽʬi([~ Dn%# 7%>yACo5Ymoe}sA-:tqą!-?S4Y[h;Iu ;sW## XF&_^wz7JI" ibh;vج>]D~]q~+~r-HzLRz;$(Un9n3dR!+L]6@+:މU6b`g혾1*+8X_pոe^_"TSR%3&R !dK3ٿٶqF4nNq(@(!O=K,`lƧYI?=?c9{:59k F,p9| pxZ܋`p@& y"mI\1^XѺlV/Ï%|i6bƏ[kT*ICaD ԥ|F͂ :8^!hh)t xcpsi*t6NE)!uVIƤHqVwPyfޣdHd(V<|,uֽ얍m) Q+9e\-h0۾ >r.s9ej'9Iݸ䆎 }m9JY\}1\7w^g9$^c]^Q8[DQf/D_/΋f`!z9F#[#b Ǜ5v4 ޴bm0VBT>dMI` Ϻ WV@-晪Ve)XK-7+SU%wWS#w仭E+5WY9Y'kD,IM-WZqf < &1xaW䊢]3)TmPT;pro3J D' O 7==-?a=?Sn]#ii><vS>{͋Jq&֛k$jrF mlQ\M/FFN$'$Bjx:!Y4c9KD-=QHu`9M?z 7D1lVR $hBV3/0FSAzvS顁7o0x|U.Y)"h+"5"߁ƍ$C() 1[1u >%f'#03!QT"]8ͥ`@d&D[Q 2l(/[;z!-ohTm2VCZq6˨ $14 f&;LEL҃EբYHJHsP s:-%5v7#Sϟf oꩌ@X`sr'IJݘ֗uMV"?v*f];;K^uZNEf3r:=ںulh)r!ч<8 {'!X|#0WW9w~T/Gı^$S|5` {yG/X5lKq,)'ffQ ֹi:ߨ>,\LC|U xce uKЀ(`r`آg+yTܘ?S=oy,&8z糍Aj֓_ [_5x"T:sN'_2Fx#tf-S'( Cel&VjۮxHکhİ⻻BjШUE֡mk7my]=Jz HKd?6 t ߑ?X/>} R}5CpǬcZݹ#_s"hM̶ϮOiڈ3KBvm82]^:[?YH-2V`(߃271^{{}|QdI֠Ꮦ^_<91y\MˠUO*-Hu(sc_Vp甓ȩG32` ꗸ:`uXwD56tbOvn9r=]UN7gIp!^SZtJl`SVKE+Uڷ)@TG 5+ۥֻ*'2< utG&f@t"{son?(,׺+*5u.cz k|}ןwDL%_49h߆ECzt>F8GԾpqw ,lVstY^y K꾙%h.azIj9ZNni@TWmOR 'eVbP>z:l}0 ssQy-KMS%,j:<~ÔMNd~Wl!R'N&z LxO90΢z=\ߛ4)MP;*:{|]Je *@ e8u=ŦulrIk4ō%'*k F⾸Y<[ֲ`&v:1) :(݌6S+&mLc9Y(Ue~iijj\]F&ř`է;x1U'j5t)FeAg畜 I f7!P}]Jw=)z2F|E-U|TLx0a o[ ?^Fڼ1lPob{'G%M׬UgA|!̲H^4NW9>ǥ} iS`\ Xe;kX$dN=CƾQ9-tBE.&)ʐk 1<ވI{qps^EN#M+" f.ٔ}s@m o<]z D1\N}]UQ2,Uȟ ֣Bf.T2X @6g\ 5Iq"&6̝ @{gR'!Ռ{6;[v V=ڻaf<!X˳#-T!GQpy^YߚKvi+u A06#]<8zYU0s\I>BP[Eݷ"*Fۋ3uN@vwL(RaMWD=&5"6%fnSsvM?{1η2)(d:śpA*lv7R5iCBZNL6@:xc _cgv C 66N%pw ; -fE Z$R{u,Q E0.jܦgYZ)d16*@5QWWt`l65 z%3¡B} |le-O5,v){-ǫp z6)wW0dރ\[$#>݂F2Lt!&%XZ"rZbzMQR!{Jm8OʭG­iX  \8(a~&E}\_$5>V:rtsss0kI{@D`N6jNJ.Bm/r|4YUiQJ lM# y[5*&T>1)jxn'8O_%lQ=4He:S0J='8%IYtv&`|'Y:I7Rތ9䵪-Ibb Y^@V  7ÉLiuh3(=S1 K)cU{إ,?ћ —&jMXrl~1q[p6~*zҵ2o1^T3 Y03.N:QVPo5++DCmEz ?$]0 o߹=7ׂu6j"p&҈|bR'>+㯯SIi+a褠8-iKZiӴo|iCh]@'W~f)_.rg뉆&Q,\DaJ%O+_ZiirY )0zG^]V%wPNa}/ݵWRp,|)l@w8u0rHmBSa;7:}Bdjҥ]59'd8rёj}7eU)1}2DNc.:{lzOG89]k*e- VI4`[QQ"'%WqGw Q2`s<*C9(J T4k-U#j@!˃ɴnXҸŝs}&H?FC)[ Q ]7lRT71}g_Nƚ[rc&8{-t a`-+P0 qZNGE(46Y)1USߗ> 1L;,B:E,/-gBNi7ǎ~qj?KUY|mbVH$ف3)\IZLL6PlS$IlV+pd8,nFegz{׼ONT޴:fcr 2.@|-5nU'[wT~aAU9*?iS$Ow+Ƈzyp&*B=61Z_$%)]=\X{0P |(:FullrrS{b Otj9 ŖݢU$4Nj@vcŠ=)z%2D/ bLiSzld#gsG2'V|t{%l9gDQa )u>ݨ־J0^Ϩ *'LnuIOUY6aSNT ׌c_t$e9qIUebח`xtZczhVտO?.LS_*VWΏhYW5|iL9 ̀^,rkjEjuxCV7[N#Byjny+~A:א;o!?IemJC&Cp1$^U7m|l֌:Lo2+[Z;4((*3;,T TvKHŧݦ'I]'s/#oSix=_03 o[6E=iPk;(Y&@_~@LXޖTf|9>DTc l4 P*a!?V0UTޗ5nى srvIEZ]Is2V#|K'̓sGL3L&nլ SӖbWuMunvq]*۵wD|ulk8:=e}ÁQ~gWD!؈,Jg<1}5MʥMZu9{WE1={?Ga>K8e"ۉh'`o9u' -ŭ!./QĹ*1w$Gw&4/Xv HC64^\ؽq@ ثEH bE)pj7塭m ðɔIbm!v 0O]PjOR@Ⱦ>UnFd2hg0;Deބ\){yK@t=}b;hAL[y\epN8pyzIJYrpN<;h-J Ԋ*R?g+fp }*fk `>8%C<|CETpE]T&2H~ )Tlj6@?90t( KWqD=ǜ$ ~_-"5\` _PoNo֠5Zn6Tڏ2 [4Uw]1@D>^iG9#pB˗Q'M߶F4Qq`1d1;.i.tKQ  ZDmj܁8#G'X#g X=&K6$x  dr_[-:J3m8ZWxLx| +Tq3*P^ H8i%p$ >qB&)t0<Us*/3vfXkTUxH\-SVJGӥP]-NCcRU ԀfMK!Y.i-*%:gJ]ڕ7Yc v_G-hvuNјbXx1gnI~&Lr-g$ήЍ? nfɧNVb`uea$#Nnߘ"թ22m+} -x)>5YQ3ᄹƯsFNwrI9^[A1L,(;˧+;u}Ҋ" ^֊ե~ni* 0](w&WLv5SR,ey4 .Bj$E< +UVd 0rm-Ju@8@ΎU1)@~:\)p f5j$`^~V4ݓv"Z *ַ/w֎gK H@DKq"ڠ<+|*T iP` Ga9i(_5F$~]T ǔK9 I;!HYCKRxrK9$99qzO[ߌtgP4` T+缓[ LOg?P&-hB߃zY)(S/vۓjO4g/zDD{q&hC^Zgq\yw]X508wE.'9\XAy& [<K:ZVqGoQfR{yA "`@ j p;&+RL e!PDܔeֈb,j^ 1mYxO{;>9q@ Ųmܼ Ł lߖ8A^+R5Lkl,^ mq~fv>dReHRBʝ" ĉ/^YĤ4gcKӒ? m_Jt[Bz]̼_E_=#4?)O$bhFo9 Bu(Ȓ:}QPx3ْ+VaOfA$3JhN 1'qX%j#+ky7(cOh}fMs#o` x䉌DpԎlQ[MU ES^5Y54z݁~'49ԮYQNƩ]uȆrT¯qE.~䷱Qr)}95+qMRv /Lt>{:m.c9~t0SjuI#|ELPi;A)^7r^=$5ѶK~p,JTVb:TS@O͡ =$``K-׿}M&$'G+B=FGdeP 1= pu4"Zuc wH06F9 "KY󹂈䕮bBpw:5l-=2ÙBj'k]bjktj5M;R[`8 vK7.>kaJO;.csIDžڀ,L4{f 1_d?/޵&7*OFȸ)Mp LЅK [zrA׺@3 Q[ ۅU|O EJ_V~nMkFo%;|p,JWzAev9栿0WUm/\)Kv32L[y/ūBycyc) \A] Mv?L?L__/ifiWKl$Y>CRNٚaYcvobE[_V/ *dז ZgotMk[6!Y'"R2Qof.] =Z'c苹 C~ lH/N ,}2 2NE&yB @Nh73@<"^oɖTPiރL?&UShبN|ip#]'^qRøva$W  k glsO٤-d ]k!~/> `Z)$ w$c%91PY.FA(d$ci%LHz|4f Qbn45.,^CsjH\|Lgu1oBׯ]Y/pf`z̯GţuawrOl'f-.{U%-.#v2™He[nTquvFdϢJˉa0; IKAJ?۴G :~-U7̛ W R?|l߶i#PAna3PEsIS:"9w&C=K>8f! 5ZͼIxcg>Y>sK氹9]bP ):y*0:O +$ALIco&kH_n  Khܪ)_ 6 F#BsKx4M\:ޔYc;fr ZHI &a%\Ph? ~T(>8npucUM=܆_an/Pʌվ,J# TTW ,|X%YW2QuL)Nt̝\z6G f@ks UѨќ |HLah<1!Wᔙ@/GU}P)aQ'EkQFlI{H8n%@'SMm/V\␩1W/L=#e-  ʞ=:w37S6%;yo`ϷVlGM8 ~|E8<,??usi  yC3d~1'&j6o*):S%2yGYd9.9ٹHM^ ܭ `}D4SAg@l.Өv޹Ax@+*,@Ӑl2[H㷓 v.! leZAơc =@L q-_w?LBsv#PV?y7j*cJc 1A7i ΁}p"L7Bٰأ ",2dˎ3?37xʣ iGMPYP79^~>Ŕ67ԏIR|bxy]u>(!jDhYX#1j$-4!0[53ىHܸ΁/0>jc<%D0q{ڴ AWBlD/Tך J˴Ҽ1QE灓`c$eоtP`hMlusW͘8d}[NULk`[s ^'~J-מC<k2ͪ0USu'xMeVon;[[uDNM~V&Ыy aCxR1E_yn &0dAxaHn'9K'%P&pgʗ'ȫi>EinN$٠Ϯ)ܔ(QL.'|`%F MtDL@Tȃ[ m1)ф PTsVX|Gx%j2ZV0J~'2\vJ 1w,vU`9v*[p(oZ50moe^&o0)ƞ<>|ɞApC:^p EKDs1q BτpA!BgЁx4f4h/dZe{mǁu'WDYkxjZ4#hsq@ 8MK$[)lN: 5rUHjhFP( 3GnJ>Y , z oo|lc=(B&y`AǮDWHgÅDPV(ʭ[-zߦ[Y!Å Ah8 jMڭfY~v"%"&MTW;\r.daae+.cC]~c4 Z?X yK)~t͛":Ѧ:Ms4:-#?A*ar$<:o$#`538TK/W[6^j-&O=r{DMS99{2=hD,ș w_^zV4۷+PnK2#s)IsA!yCrlo\oΰ`t- ~bΆ9ЩڗAɤQ'7-nT.OP+;! ~,skSMSFjstsZF/l6a=(X8;o }_NRd{MffEsyU \ryz30>&D?eqƃǩk$Ç%=*kNXmNBc]T@C p<(PAkN碓*:>D4hgnA’TQ΋qb63!;x"SusE[0(Ãf-L<:h3fkk݉Z=$@jFFe! >Q5h7g(ŽwF/ԸT+aQ+:ACW"&Ýb^ pػ""$k{]3rD9KS"^iaa&)j@M;ctN .F⬳TԪ;ȍp{wb^&n̊ xʗLS ՐL+η#Z^>IԆV|Q5UTYV s1p}1vEՙpaj1Nc ::G|pόjJx ǰj!u^CqQWܿ-[Uyaϱk6 h)jnyH>G,4>hےڢdtkN?7]C,8]`Y~0[nPfD+UÎ`n\5Ln5-mVQOlV4cߌ u(Ս$o9%Pa$fv,n"f.flT!HgSgi\ 3XR>e]nMe#=K6<ĦsBD LpD/f++3޷Z|O&Wbδ|?9YYCop3(EK܂U\,uϩ% DKdAWX#4^ >T?#U]lo7/3Pn t5ѳ3MSvdN2,fR++)z0cx0#Sf⊢.qDŽ[Kg^Mcվ㒸1\}tBK]|D3_"wg~-7>ưҖ PY~z_0X+y^ܸO?'iX攖(ሒxdoÙDv9FZ7hܱz? %Qn GdWj [DPS3h\z;9 =]!$DuV)J hiI`/_6Jj0x'.grAsLPUW,v 2ʊ/Ǔ7zJE2JZaDhN{Z1ӱϞ\YET}mǣ>=^%jtMiZpV#Jy M(hz(͈| Eg ̐&TAosY3CxI]d҂6I9Oz}?!;ZP绞k{"R 9A8:0?xDY@dpx+ \*y}u6!x*rN,g_!cC4FڲF0sڲn۽6.M%H o*1dWL3gZ͘ϴm4 #@P@L}(Ie hj [;a@)MYAe̎&ⲎfOHmxy%W|G>j܍ܽ {@CW>6U5KfOo:K)bǑ`)ᤍ`˜]x?;ÿ@=&ux黴!O Ʌ Asii0PH6rE \.y6mN5hfMBc{5;Wnϳ)GAQ^`RzLl>*DsW *Q" F04LsnI%nk"Ҳ礪v ?N 0}bVh&@X??.Gm}#1Fx;}-m/2no'R=̂6|c= {+<dR0a{]MK H./fjV7`6r6pӕHuN!jh>Vqg(9Q]y=Md<Td;OD#];syf5ox_Va'&Xdն34@v(0>݊MG(25Ր\E4IDa9!f }ğā\Ԙ}YiKv!)dAOZqBm5;=@B;vl`dW aC) M]j8ЛvAڻ`?S2,鞰C,t^BT-lRNto*&6@=Ύ̏iY$#` }/Ss%&PHU/@h;Œj찇esi3=߆WHt4mSo=K`(!l^{q;1ՙ/SQ-7  Z}c$.-(f)"7`"/=8*\{v ,b A/_ZybA4:Lr:M[3"Q41}Opo#/aA6I aTFHyT[z8v>[#DX<h{ۀ[S7ÐmҸ>#d*i__Q44͊gn~o4$mKH,2Kr - 8R[- l;1G4|re1 ?>̖d=ivm@"ŵJK% c8mۙ|")B=\iE?^ND ),·?#'O-NITڷ,@H(sɻ=h csnnJPd6S` v5<$c:e{nv}JdNyCK2NkzPI'}u'Ë=h[: +A~k2HZ=jqݥ)]j6@ݍP틾D3ښPDS@'ײƹP *S.Fg3WϏX:.*pMi%sm7`tW'J86`S{)#P8&ʝh?(LKqgoJ,Eqll ',ɩHm7V1O;΃}jȈY실+c 6[v>@9?4YKݺ2x Q2 nv"QHRwJ4Wӎm: mU[4{_KHk5oa‚6gll sj.pT8T?q/0eOgd6t/,O_ځTZEixHr aG=e2VgJ[AGN <G(X,G"vJY,'D6: ;ڒ5L)Q=Hl[rLCc(ttjm80@KA3U9FebQ`~^t5IՊ݌PF& 5A*mgdV}+0`0>7p{gĪUf _hq)"(giC9g_<YM\uz"Jl"y'd#c\*=? z P&KTihhSQ2#3Eh/jnc|8{m 9[uQ gjx Jih&)U\ʥsn?bKhtG> u0=ƹ1ٺ5W"/F@]Kԍa׿.o/8 hV}U:r/xȽͩ!aaPZ0~rey0!G4{ۈ6֛7{IYrJ[W/^kxx;B.-BA!9]gT.)%e"P%G#|#$xӴK~Z"\Y]"=iwŽN 3k }uL7=:OStL[)mO/ּL?M+` _]a |_QDBW/%ګzɁv1B_êHϗnv j|'oQPv J0Q$ьMͻY0Qd9\0 DI bȿ/C 7 V j" } -䘼{RwX>V'6EN4Lu[-J7J?_KkpYU@w/=ږ'QHk/H)yxIyb #_f3o@XZ6A L_ym ?GFJyb~.ap Nl~É.:=-B.g53FRDYTꇸ>-s%ΤV頭 ,tu+!] ;YWib2uIѤkqcb7\+c9 i5:BwF]>3-;^m&QA+ !( ֝lPS~.1oSGK׆`8m;'/faB(IcO\O@U~Z:B$!L!`fGH".Ysw׋&r'@k1=Ɔm]ueyAX "?~IݐOܗZRJa'޻Q[M 1W@!گ4 R"3Q]=s'9Ǔp+Ï: -e$S4oB0:1Mɤqblbo;U'~n8 |DJmu)CQ \v'P0}H) NE1Ӈ6 &LM&v `<"ԅlߙBQˋϩ̔GZ2έndMĚ"yP3xQb}wV֥M,X2Sn H>pV4?3 NA='S_&t\TQ=Ka%L;ᶰZW5S3E3;01DLA 3 Kqbk&Bv~hl Rk~ReF,ӄ9x4 (ګl:Iu$jKV[rE.%p>M |bRABɩ5ZXž6D^кt%;QF6} QzMRc4$$_{#μŨ, 'm_k? ~; *%LGߨZ~݇вIû'يLե>!nc~{*' 6їGYt"C$o6vUrpNV8ްkZC;,Sď)Ғ]?=uxKay<#v)Lr%isFBH"EԻאZ`Q !+X v'ۀG9&p~5wR"L%|iّ٥9ZȂcտ`uY0*WExnḨB{5g.]KHh:8/e,Gup85߮kΗY!?T_Qh6Mv/uw u|&W sI b썳Hԁ2AKRࣻe>8mZDߕ]v$yibD (ԃvv06k}aIgE۽%^ңt{)Znl"7!ZhR#1QżϻfBkj9W*cTq yϹbNWtpVv(QF= fp#{B,p広&#ߐٹ ;}ʓ;hp"n]|-df bfvmF;ⷥ@׃F '{Ւn.$1Vp7GUH=3= <,A(ˑ*kt&NG3/@ԉ3T >%;X>bUy~6Ob *%A$}C yLNFZh|>xX8i\ nibdRu|;bR/OJC)B"$RSp4b{Z(*YB_$H=i:SPUAWߒ1ThzT;ơ WԙqmwMPsaM,1=F$ّ)mG&xC~r$ܺHH*bǐetTMS(چ.0#*8 /rC ~=W ZO!po0RF"tYrL2QxO9CPmI%Y 2=|r`;θ{ēYV2af53roVo_-hJgK׼(T3㖔}WV[s >{tN,;,d:);ZA@ ڠS7Yqi)LGxWu55\;PGj?;.d}N`);v%)҂+БKNNyǏ$)laaS+.1Eg,Ū[&VsF?@t`j2y (şPxsLbhtsv,ϚKkWȜ9Mz$_;&-1/9핏[LҞ1s1֏T t$+|8%!?aNNw2x"Z+6 /n,QKYe>"ejj}' `iBф00ʰKa[bZ8T)'Clxo6ٹKOFΜQțiu*֑T*F rK Qo:鍱ҲJ "H%b!s۴U=RqE-Q(EW\0YdthT<" !TXJԝDyJ4jlۇ79TzT[AY4پle]2X]rm,q NDhCY xB@dDSl-$!9E(Bg> sKf#zۘyi`OaAf){oB/ VXH=X{b}m_.0sT|>UVNP`~YR%3͓T ͟vB1Ny/⹏](0?޶AQ<;ԆgRV}R -ne p`puz}_N2,։'N&r.V TvyT;KhH+Ev!…BՃS|6D `\ҶB/M1>FS}Ae C@. k3 kσJ0T՘~Ln0WUzn.˅&FNhG:] ϊL ;'^>h^>~ax.iBP=Q-FuXB;{f]L1%Gք2mttɠ(X.WԬ!{rC5> :ZlG[8y0=߽Qg%4` (sirJ3ةqܳ駆D1y=ll!%Jl?K ہiSxňVyff5@ +nMMg,I* yS<$X$)o[Dɉc̑9?j,za'R9W*L $2:njpɹ/4![w3SFhk05/UGX@AZp,#]xEm)O%}v,ȕ^ؘ=8A-J@{fRni^neeW4fE~ .P Rk/; ES9=QڔY&Ud<_;VUkx{m:\ˆ_>l_)C1.8%S8_'q+Gf 7//ZSΌɱΞRw#k( u,yOlA9la6RX4+>}hCфy6VÂ)~ mڢX Nȋ^4]h0hj"7 };Vq͆y>h0} *?vr`l*];N]#.{ϧ<h?#0[1Bk=&oȴy qe";lM.qdtъ' >fpW 8-#"MÉq.:vQ,2ģZgra˦FN3gzy>騖lU=,qF"Z=_odPx-x"2$[UbkY@ajw:^YgѠq!9AnhqI>v+ 2ј#F""CQq#e+,ʁ.ײ'"UӂVbϴ(݅<NGrGO2(>3JJnz sͩ.FN (#wR? 44Fb#]gb[<`[pJ(C[^ZQ$%Ch!R4SA5MNvM0!*c;8T_X\pqVY1Mς7!d B"qg c]r(by?WL1 -&=gr]'7sVM ͠X+f] @ XkY* 1o) y+њrYrk>d:)#鋾f[⽎kDGG Vݒ4 j3$N,J (D܅n)lsv(M=G5MNJcp f]ǃ  Oσ{ W^MX^.ui|T7F]OwbceUKRfPf|ⱗxC@u AߝcLg3*lx<*, QAr|X%(ay;1{U6K~ sC+ﯟcN {!9h'wŽiEl]$)M^ @/񅊹x_D M28V6=~\фGbBni\4 } ]u5)s,ز\hmEajR(9Sr=JEXˀS'2U /S=OqJg~98Cc ި%=r2fwp.apmũsEƻ9Z-Ta9!S'G nORRzd&FwT@qRfBu}m0ݻzaR-}APuM4*Aosb` ~hVFEB\?Jt6%Xo¾"YI#&|b]u"U?H+o<72/1 9~9v&=q02#9K2Jǻ +3|؞Ag&u,w!RM-7c탨'4x?6Fi5a}r嫺2*{.)rȗdX*eq3\G|sl 6* Qka=&)rc;9lI!~j>}͓Z#}/j;&e9d F̷Sgg[F]!?jFXuM_f.x# :pMq5:⃄?57p|{DT-evlǓʐJex9+DLnv 9'h&Vu^e4#OUwccm{_4fe|UF-_M>pVs]-r-)]I&L7sy~!`cnթ2ϷǴ|["srdy$RmZ!Y0חP!P~6(#؞6dx+ yڊ_?ҝ01i܊`# f3*H1&*>G3 AWxA?އa/WCރ_ '\^ $\IzhWpͬҩmH!yC9ʺ48c[̉Dx1A2Sa{0[fF1vJD1qR2hVhcpg۪2V[uЩ_JU*X([.+滎+GL"m Xp"V:>~@d(\KkE5sP) fK?*;05VHC^{85y+AaxJa1 V:OF"Ó%;kPIH=MFHcf~TdOir L4Lǯ1{K 8)Z;p8DiNMOmP'wd(-η|^&^:>6]bQ<=|!3$k#ä^w{[=QPHb6xӲ;q B)χH1^ %ìX8:FjCED;"_p. ۷.̢! oRcJC.b&oN|[ڔγi_ bsr8ѯ$GV]JRcq2[aO"waIPý ˩(ni-?1&dW/zھgdQWs"#OFD9hvVQ!ihE\A&xFF̬٪]uf֡`dUTv+2r"T†‰=uS8XkJP?8ZρB"&:ܞhK)]䊅p{f^6IoSljMm fznZ{Zdlhf4 Hi߫FI#n=f=x隚dT<⺭#0 K6b$='[PG;+Tn2ޒԉ7ޢƑhMp4/TD/=}ԖRW|a!4MN5+0 yK{gKAf|t^esr6_Fz~C0i^.``V{2z[GgwRZ@` T8|Wu72kK/fEMlj(İ^ȯ p̙-KIT(ZMjİQ-Hl&Iȡ?U'0e`ˊ=k+B5SȰU@ ֕uCDr_ܫt*e ^]J4"VuUTx)nGL$%) 8 J-\/ 23tL $SQ{ \;%m9`%%YLa&UҺ#I"=%">:>0+؎ߜ#jgM,['ν~\1㵶c.]0¦LQ z7كU}>gEPkJ`5-or?ء{7 $؂v??FQMSo4EK,aD75fa!e~ߺ6Y˗4'{)􁖟kG0d=cgA)4x+ H s~{$$(QXi)lnl$Ȍ/Stz `*uַL$K~k 3LƬO\N4R*m+FG/cq_pw(bDz_I`5 `680n)Ӯ3횚.mR<TJi )ׯ"]Vfsf||ԌK:AZ=!d1rs񲙁=z]/k2t_uڋWpxZ%"GM9?4{vF62nN 0KodZ@S5ES**)YBggTwUi eL:2j Q;n NE?3'餹p ;㣮QFŠ"/+D*/G>Mb>zh}A !]U)i2y`\F^ԑg|%>' +:5y<أAk]!p ZIlb8!Q'YR))S,|3ppnfJܼ# P)?SF*y Swx@ bd:;1zHc8B7|b[x"˖0_Bz*|U s::ݠ_Fj KdAnl݌ܪeKvpl5F!MO9هF'qa@a?v(:lJ+V}'ZaV=w))S]roOްV!SV524%f$+KWcq-2-@pWB`Ep+}lI>Xŀ\]x|w$uojj 2kUGۈ WKf}Zf-Oӡ\[w֋Xsr$x^4O݌ CC&QJPxf@{@ofW&op M; 1=_SEZos錃|?))i}3 !ѺBQof"97n fW6@WY/:OIǾeo TǤniZ~G9EY-(sj J}# uÝ͍i5_ljݰ4EЬcN@-QfIRnV-G:5Ppn-/,UhdN"1IzAE40BݜZOp&r>Kաj-=Z=&UehnZGT|lIy1= !=8>h H:$ʝ[zW$,4&\H'}Яwq@h -/Ob+Çk&EPnN WQmZN03zlD2 W&H^ Y۰Uxzv[=%@~('t}n8~y|\`aCձ'espA-LRɐ AI@/[YP\%#\!ztG̭mEZoz{[jZ$l fmqKz=l~5+"nU5M`RC2)&3ӹvȩ//Ny /c\P+Uk=w`n \[Xi28!Y(3 G N@ o9q+UFL%2ao)]{7#33nv-[W%s0}-%-yBн f)=7Y7P'"7PkWuX5=}פO <,W_{HˬLJÆ gJv濦Y_Obr?N5)H_ʍH)0jMlg9*Q8P83Tdj&w,0Ǡ(o&!`6Y#Go Ee<Cڛq 3&NuЍT5.JmCzkgܭF͑ߥ'1.RO(wbcL[nMcD1b{\ĄgTt&܌яDڏYˀJ V,ħqA"aT ʽr=B|զO2$ˁ{_o)ANb2,or_i2NxEjQ.uڑ(HBL}O 0D)dWMKe5sG~=ngRJK2B8Q] E]%(lثQQc҉f{Ny>lyC-eNg'kh<nG')ԁAgUq){]+Z_$nwcDm6= ;Jl:/%cܪ]X,#h@ L3؄Ѽ\>UKw5q M%: Iq45D*. |C|^tJ(13@XE A^*;Rޥs1HЃ\;Y&H$: [A((P>xd0R7/TRaa,xnBt3uGӸ^O@#dʞF'<4E,Xx@BpqXH]?jI9iz~8SP=s=H9"A] K,IZ܆>eٮ54&x&LӅ1*.x2j;ǸrY cr.s >SU{Qhk#=:ĎŰNRmxꇨ(5qλ RV%}fd'ۜ}RnE2a M,7Vlňc : (,K\U8uyA6H@ Ȳf9IQJ]9S/NŌ怵RvT3V1[=|Ic$.]SZ@t_CSTĽ[ \=LS[fIoLM A%N<Ĥ0CgXR2oKTMK|}kym[K}W[z[34+B͟䳕{g'YjSK3-;[A;8# S}+PyxC sɉ7f Zxh=in]8W2C/C*C \enT^*?-7N;ktGS݄ WcYt0h$8 *tp2u d u3E| "#W' Pl\Tڎn7^Ruи VW&%R)|3kzB}l~:ԏJ ]t><ݻ ]FD2~=?gELHWD3_fQ]w Ʀf򛔵#%91'M*Kmo,Wif^3krw&|B P r%xFJy`{p1}B{XKeI%^:_CBh 9&Ϟ-+`*p"a8>+&zm~q4ܚ`]1V!NĚC*uVv,Ձ_7ћSrWfg2d\ L, 0ڷL07y}BH'J {7]"_ם.y}j\ Sh!S=Zo?²ۛPV||( ;{;=WlH=3^ye*_= d~n8.L0s  aQJ*f,-$}@8_ero:lԮa0܋-O cրq-'e?7dr3n mj|3?#}~/(~6h9k`9swG]Z$!5KxD Ww$2@U = ָa8 sNbNޒJR+[o`:)e_4߳ ʆCrR Yj(nzmz yCĺfpH|m rkK5p~4ƢbHe| rο.YR4 ^z*@p 4ry0SgwAL&82B:0EW?kVCǏvs4(*Z"I?+-MW uQ&Յq񍜪e#A3)ٻ OXdJ2vNq`kc?, J@C"M DwTrN+XFwip,%U9v:٢[yzVZnGkXjߴ5Z1Y<٧V[ox-73CWڨ!To="ٵ &7ۻr%jζ7Ytr0f&\C%75:Ksrk\tp2Zx kk*٪8Guk ?QVq\+%rH0)M.#pнA}>wDWKJ_?N5lKeM+_q@ltFS`:&EOsџCF{y?$_kxpjP~O᧰{Gz6!GOSQQN}O OVC F5ReS]%opHZ/y\rLoY^s_iDرxf _ɴ'7VZrM%HN, A~=o7jKƵFk/>&+Aj7(,kʫmzJt$KW7횂f[d` uWbp4rq_մVnBZ`p7rH%Pꢊ/%eKz=m:Kciԭ/0p1 GR2D7sl)<[e&3d-|i&sD(S/ca=,M4fC'ydPVV]6#rn,#9qq_@WReIA^0%'EJs,x%:ZpRZdGQXzAاJ`bEG HE{y-!wE l+nP &:q2/oJ  ǜ0<82.0iM\d5iu'V}(bK|iz GqT6T+:uA{J,q|ƈY|kSAY.~64 X9`uB h"f@d"[gnx-69xp@|ODgL39iNzB,R䒢a^t_i&2.K'+RK -8$8)(2ע"Z7(FI{='A(ਃ1j<(Ӵ|{ENWy "ƫ4xh;0`¿K=u 7BaF}{7V)pJhAJ %/5e[k^F|I7C?W :%%(ҿp=baVX霪y`_aeMTk=h7wByt3w5$C(ME(⏯DK.3/ٟy]4aE<qԙv0SUnE,]tփp\OaA6z~3@|i"2%$0ƍL~v uMj`gC\>Z{c49y%u<-ɱ9#E@}kSuض<ܡmڄVwSS(eۗ4EҋaXHeDiTK#!n '$h{ph@#;՚1=ѬEOI=?MuxR-8J!Q\u^/zD;B"kJ'ўpC ޴]"X!J~gpAy%Sǫ@%̴Avd< 4KXyHNo%at;] ]#ʟu;B)l\ʤ8 d ?:G؏3ckoi^^M0iMz|{Qf[ߋVCHmBLÅ"Xi1@^S27pɡtwʫh瘷ɎdRs . [m9q+5m rԗG&gau}{8b htD>eF_~6\ⷆ $V:s9pVZvXkg.i<O` [CѠb |?Ji(@Ycfhn0SmN} ʼnT0)@ : 7NZa\@UQveph(t~oƳC i-~cp{^HzXͨI* kf@OD @LXm} *3xX_Lʪ[|EDGTS)2yڡCkQAso t^fj9[!L o;:"\#Qup4F-|d|OhIG̳)Lg5 ) Jʀk_D* .U[Ts Zct'8mkef&c;oï+#L[K~r;/Sc!8, Y,W 'Y+9axl?Hs9ۧ;F$M _^}Y:kK|5*ZL8˳4(εS9l6;iOR `*Ťs7=wzUjWU#L+C*=kw K~^CX lV-\y EW-Ig9K(W,|ݎ9XK\+ c__nwi]Us lT!Og5SNx]zB4|JC%0FGFkV~d~ˎ&wAwxo[kG#J*^l[(n (ƝΆjZ({vDS9eTCPt; iRşg{Җ ur){ TGJ_ W5NM&E9,E%3(~Nse .Vq #h$[*E?V1&rON3 ۔F"!Òġ%zup US\RK&!N;iRY2 $ SISiN0VlX1[h3qfN l_A/9 DDu⯊[ Ҁ? C}ȘQpDM!)Xtd& e\U|+XC$zܮiXO=ƕmvo-@O$_!D[@(yIQNGxg@/RXݸF EG_(gb1A5.zmbA\5ilo} uCL`{?eD#{Iݪ} Q7]DU$<tnU=H[^澰(OAv !DcxGd>. :pŜ "|YB)XiDmu˫ˁvr-?(:rG7DrS" }Ftk ]: 3r-˄9o>ߏkWVyHHƉr?9^Ɍl3uEzP^ ??0 Ky/αg&Bbj{7̈́+JiC>c-ж,3cq^UڋGj.#rYP1Ft NMEq CZe|?JkB*8`=rdF GDЇȄUTXrvѕ'"69 Eq2SMh2|`BSgul6~<J- "3M `,9jXaG皎EkefG}6Ӑ9\YF `itw ?. }ґYb=AJ@|id+41 ^, pq?d St?XiCcz|Ƈ*҅r4Oσ1' IR+x" KņTnFj yosY0Vp^oyAXZݼG @&l5\4YN^HtN[ZڰT^)k4+I"+W0H5sd0/E$'l/P \[ؿRWfRw 'Ur)q< Ƕi rcmr1pDʫY@e7د(Rh$ˤҕieu+<eT.ט _(:}}V_!@]{%j8t"Kxˡz,4gahHtnn0vVo_0H TXrDVvȺ[LKJ?0*ͼ%| T) kkWmdУ,(v cν-vT.=%i&D@,wY=SܟQ<Vb#G.uZ)ggCc( z*`zXm*#ŹcVBAf6)smExƕЏ,-yWB[ LU.ܦI]W+[=fG qԨ$s2~df8PxoM!ÊVXT(f]{݃y3P׷|m 5~utDmc%!{a;38WnL=!ڿġ VF?̥+`n8 Kٞß9G+_E<752һʩW;1@Qrq {o{/ `o!~*OqXhbF_4^6A>GNAu4\To+ $Sl#X!΀3dڎd)*7j`cV(. q#[j#YS@ǣ2BOOT\{8,G1M~.:0P$-w9t1(QW%p tBD I# ѮJf_lGub)qCm6\ 3g1TG18ht Ӏ_#1dLb^ZtH.ޜjQ9|v]F2#"Zsvr֒1pD= $_˴ Bz qH!:5$)G颗eaR\1sen#h3XpvF2j"JtƎ Id{};E&iߣf鼛܈5)n"^  T&QՃ'3R'44И nJXDm^$ZGQKHZbАdY//!^dC3| <6pUO/7];CfW]6λ"$L${ȈC\ lu 1ls—R-mnCm~_AlL_rcַdAnroZϥkgWXy!) I~woi i /5ohm>mL+k< ~|FG po.!.2Iԡï5U_Jdk@΁IuqH5sɁ(e^= 硓wI!tgv3պ=a]*nNi 8M+ : lLbxzI pM^BI.$ΰZ2))$ɦ܏ILtgXt9~ 8 b\ϝ^cȜ|="i]BXFߔDhSxAi>h sg :+l>RRhr~1ܮ0JOTMbAJv!B4^Q!RS@ ߒ<`HIwUS`Ƶq-gSQ`ct8u]ii?Eނ@1]?q)vf2 0Γ]r˽۴DfXw Ŭ9 7tg]'&\&P ;C$O3 GMGfbQiQkR\D[bb^;% %vTR$سn]KDϮ0ƿ/yrl` 272;Y>27PmJ;3(ėE`'Cum4DŽ# U N;ji+ʎv:鸗i6":V'2ڒ:-I?eқ!.Av ܬx5eii{M"LEnx-1sr( &b B5PLjG9B ?wDNמObRjf!#bvZF1\[,xYI.8(äQTDk jssV8o``ؾ+@sNUlvvRcIJKLX*  m_s,:<u#_'B|?IꚔyHP+w;ǭ 6nqg!r |;QnUYYw>ޱ5%6E6ұ SW>b ޣ>Q㚰˦ ~ 0/ت1F;\Ԟ u@vv7X rjWBzZr[R ' 7XYm|9,aۣDސƷ)&nX5{e"D=˟N} 6rm{}HR=>&xy\|rF_ :MK1ÃlC7å_:*ZvC짚AEF.Y!- F:j"IZVcw `D<*pAAPֹ PoŠo ou]+0JS П|71̕6 Cu8ONQ 5H-g 7L,(ǗVpTfIުJ._WM^0*7B{#GBK1#u%wP-pLc*xTpMRXncN&P 8'6X \G^D?`Gl_Od mx?*M /宎rynnC ߌ[ epu0yq[v;{^&c]Iy~=o9jrC ו /pH_+|=:q䶏F-kt%4;ixan7l:l$GSfm{ ;Eb:;V.HSB{&^ ,? Sl F:(E׀z E/{g`HaC?2\?>֨qx@ ?2_v(ݍЯ]^6joتؖ#DK埋ΕZiZ| I_San#2$,էp$]X l8\)$lw^!,, mw.;8fx ]-})RS"z ?K 3VC ꢥ桧Ĭ%O24ԙh 4MlWܡ>yXrM'mSsz'3gCي ZHW8\B>]I+k"[3^.B{ "inwnCb7֧Z`lиAlA:i)T%-w}2COX (?Nb @X58\߻&|ʱف.Њ nfYZֶ |a=~V -o+y)HD'cs۩u2iSO/p8&/ |L4@&S iF@gF=mRm02~Fz9U֯:[;X9LS*iN8HT?~[a:]ل1_ޱkX1[Hovꅄ^d SB|e`ׯwυF{&όΘ;;?2H/ybh1N'l+Dy):*'͚q7oF= Ԡa *X&k(γQݺ)ՅB 2z,p53!J|NZ4S4ȬC6x]>B 8G7|QW-;jYk>1jVװy#.)/ζP638dԍ֙o 1;(5Ioϲ(6zNy I>+SU q ]U5QZj7:+O|0#=[qcUr5e;"&{4K+&(XQ*TzNz!-gbOH[hFx8%]dZi~߮D&L̵X&Z[q$ˀ'7 "^J*9Rx <l,  k);C5<^!`~$"vlWu5ln|hw+KŶ*ISpbߢW Kj;B=~1ыUC̚ҽ>AOZtL&@DGXPg}I73P{*ȎҊ:W}&S*&Z*&Z|'coX $5:G}wC7*ᢨ6?T5~'E̗ o雱$ eUFIш6!*.UקvCkLX%>_ExG`BMxb:H,3jW7rxPWr  :F*=7l/i\cAZ ܚ:k'hAAbV*V…4WE ~\Lw!+0 C6շ[y=a*i%hB+o6nF҂rB}i9##9ewߒہc5;,@Qm$\ml+G(I,XE2ּ3jCL*b":&WCRxyWǠZ.02(3guJ=^1@{4F""^PᄙY7w/+AdmIABU]̡$K&|zz+asI_O /ЅIHp U,c% iPjr"a6i n\i_ir|*S8J_ܩa,ZvWr5C,MI [ #y2>(3$:MU 1ȯ]P0څiSZox"R-PJeNC,Tlj*ٔأ$KR VudATQj8TNs+d2p!unm^ ^aB֞KYsĬ a"#rP- q|ie # .8\ ^_9k8LzW*arJLz'r 3htm|(zj~}"y0{fO "vjٴ`}p-{<ǸDfm1F|]cK`#U}cX19/2*`L PR0+InZ2N>R;ʋhXs/BKܱVk{r&Qtj2blߒeKd\4gμEh,DZXer4q.$mWؓ4 =?oHdE>ϟ`8nT/Ѝv=9H(>ҋd@ε79ilU\ r87y04?Bb.ZZzs{em}Ay[mRpȖ:V?*?.KK`kFH Q iM%jN*w–NyEi@\C`}"ؕci;8@^O5/IF{"HRgbkʴ s[˃>∄Ҟo$&#!wj 6\%*`k"ΦARulkՑ {:ၤ-ёks5GJ㫀|%o~=ڴhb O_T:L|~lIhKc6z혣K'vxgM˵% AHe A &jbe ynnt$h8%`<#HZ@qWd3;b*«PYs9 :i|9q84ng)ig utV3l% xF6dw0Ynʵ?c`#pb$uW\шU:\$_\pfƚt^R|Zv+Pn[)zxaLGlh-kߕ#m$HGR~ d0s/hpyXJohmn\oiL~shahҭa۶|9P㭃ѲdLaؿpLu3phtg(DNݻC,963>OPгZ_gEYDAGlط,@B+eS3S9\L-š+fa0GXJAdY +إU䮒ư o%,N4aOc(|{9Dߋsf玟z[@FwbV: ozMq!{OF=F_ōJ2%]ycT4 w +?3˭y$szVT٤ E$FI՟4 (T-}?a=¥vv@a^7%e7CbԒ i(dC@i2`B$N&dT&)Uq0^nXr[W~d\K,}[zۗvXb|q&Qv(YUUPaPGu2Tl2b|0&xG\Q{1X8h"eah38d+޷'mT/>PWl-MlӠ@dnV#ƒNtg׹t9 yKߚ{+Ő"0V:oN6vc~QPi;]͜4;[G}r~3NL"7#^gi΄9+,$ٟ,T"U!z1f揨$ y)nu9a$f"@ë |qxwmsIOb,b1`iPRPg`JPBbL6*MCvjFQB?oEo\M805PN-qe ㄊiUp \ 6# ˪gWsHǓl_ft{Kv*Foxw;0_6*k sRQ_W$I^tD]t3E`(t25qʪ~"۟`4)\"ǠDa?}&Q4v'$;[P KP5P TtvGOZYlRW(;o*CrgovɮnЭ{}!aYF1[g^E7Z$t;]?jm#!Æ5ɕ91x@^x~ZL`SɴP'}d6\/c[ VP /TYscIo(t@ڡdae"i<Ԫ`*S` !tN#-A^5~Sϟ$kKRMvO^ %nHy]j/BtG4r=>''6#I;`;2IglDt6DBOu쿭s \>g$/ 0H":  VkI‥JV98y0m# oIˎA'hɛe''(D`Jd܁|4 Bda-ITH,$_3@-qiٟАQlŕ;>[[> | .H3;JLɪcgp]Ql(.qi[j朄9i!kp, M#׻2 c6 iAV yGFh'J(:VUzld!zaZ?d{|':R.â`'jڝ#ٰT,hCR,GC`?nZS[Mŧ9@쾄b .cÿKj%\ 2HqU: VuwLmIyG?s"g|098##?j*B<#tŽP##@ƴ+]Mw.ʙf;͉ P bTby|5͓xm)gBjd.J\j:nyKw;哣_wV6XU=!KLcp֙ _xۢtRaNnH#Z:m?H\7(xnY$;%]r`/?ٹ;( ]N3'L /_J$KdQ&ַLt3?djMQm`İ jlQa .Y;p* AIuvPud_9B+Ŭ3=\ku>.&gepGcuJy{ʼטYꁵx)0`P᝜}ɚ{ uZ$9iR|)y棛w+&DkƟv/:aE15GoYG;np^,$ins55'к4/f)J߾<ȨgB9Gf,a)JS{7 V f4jrqwaJɧU=`<k݊ ϙEHJYkr>Ȋ8-En`12g^Fz"P1F1(6&)SLu5}Qdc.%M<t[[k'ۃ´sS[7rnų+¶. Y?¦f%;q_ȴ8VKβMAQP6;tG!+;r5ހ?oꖉDa}| vkd7(ԢU>r)"yڑ{7D_% A"0jɀU-&$ TEz! luU L&̒oxDeDdtYGZG P٘[6ߘ⹁.'JEBH}^sl MRC"y*4BF<͈OU6@G( /"iLau5 Dbz,_x iiLHF0 ;ɱD\lkKs{yVP$G|5-҅#~@ٶкy.|BҢB2't}lRŃdpzk9NF8Ϛ\o_c|?xT]?C:WUbq& yGL=. B Ce]5! JzvEOۥNAR::> h!oL@43O荰غHTXvhEi.6x<.9  wh520BR.SP2G+sʶ߾aCa︹RJl\zl!oFӺy"Nica7Am`4v>W2pK£d|]J /(kEǰ ' f]!ҨQAbכU6~{@" ? gjm8.cy ϋJΨ|6,|&jk2|au_Xz%*@we=C=O$y02lNbteߋYӱo?91 ѣL{ő0e^0(CG^ÖyygkXmI?I߇E@bfnR>WDq&lYetQ0+ń ik ntV1YeeIggKU1K.r/>dWP#iG`Bt;;Qr9tU@坵u)AY`\ )DSɻPħ~hߔXujUd|T8U"klE+dSE|_E1ӫb7'ajBoD ҨN̳&Voď|g 1Dzy P;/!wMSzۡ 1_fH:^6仔QJ!tw%mWgЭC܋ZtL"WbwskA"ю̒H : s40[ҝgXOPo21h]:۾hn( (,Unr!:S&yBCXU;(4ʖb@>aHyVS$CYSWZv<%m EKՔ&6d?Yp)Gys&Fѿ;*7ːUf%}Yĭs9aI,.`0DTW* w!vue{޼x_ A3/%ֵ3!P6q ntDGiI}ҵx']_vg܌ou5P^" ܺˉiis3 ޸?y+r0FmoFOye{`Bo *$ZS1KhѲ)uANچxrktgyҥLɓHCTҷMjSIԀûp7Ӝ ce=MWCƙЦT8-פX&|bN$ټǼ{x#pid7hYxi < -=F7GRPBFCW~H̖nگ܍^a[p8FY?fe`cc=^+4-v瑳EA?{=2\4ǹiU |%= "1DӇac{Ϣr휶[>k:YiXwҮN2,!O[+7b R4~il_#W%~a长Ma1Ok\«qa/@OkUX)X/=#!;0ho| COq ڜ4_"N6f' l)`枱eR{Y$98%QUAv }dV75n6rUcak$ϻ왾 xm!*{삛?nNKP`2 %UUtxi^z?q2S,GLL}E$M|b𼏱L2®6f] +'I =JRE︑tS[x^oµM=Vy2ء" ]J&9t|$gBW#* dǤ"'ln + ?SLbRc1{'ъBL'ڇdӼ@h9h|1V~FN7n5!YiÂ鼆(tu^9^H%/h٨C1>wWY"k}^Ϭ샹Vc^0& PuGgL)h*N}}jC̕7=xP,Lp>3fj CܚH[EֻN@10ONP=(I* ^ܯLLqsx' 2 4(c}:/oElO[lKفw0 -T_׶j Dp?i4VjWǹT8hMbBf/_js:#ZGuS4+crP@)*U!jYel迏Iu'}F"! Ⱦ7n~ % 2JܑwȵAdc/J9 EhyoNz2D}ﺁR-Dl- -_bJgP5Mq0euu@+r7aDB`Eɱ~E}K1^/nX4{>}5R$'YtM?.p5X'sjV ) Vh ,yȴ + pbR' *x7(LGv=&]qb"dj4'IpXSTٿQAQ'kcbgǔU,ȴ_(/gs0 N=f5]:T:lrG^o)(יe2Ps<^resd7DKmyiA2+Ii>箜e "LPWO Tƙ{lILl1mU1f)s 3BWp6Ğ+0FbJo>TK H XlGj6K['Z*]n.ga%~ v\G~.5VW3^mVA@ĒBT_|bGG5:oW D]1FqhgsKC @PRrw$?F]|j3_ ; I4c޼|lV҈ONz0./TۖDhz"`!ܽ.`pA+{=e-:񌣠1s{&3Rub KYC%CgH-C3oOnSu1U{No{J:$ENa?͕iJf'ޭ+&gUB5G;$S-Dw%Tz,P1@^Lo^WVԲϥYA ;;!j{\R%2zA&O%|s],)x +N-bҢw`yxLhٓBvT8ldpԥP¤:v<҂#er"a XDour;a4-y ,s2 0ȝ b nEw&̀$>yÎX萌kû[6Bp0AkGSYID"XBn7b~ f-'s"⻒vK\=%ԣ^Ky,{J܈-#)Ek:%@\065:۝"1i/V/2 ?L,_ a;`v5j%BVKE%XcOd?5l5ڀWzy&{-Rg󰔭1rn`84Clr2{y6b/WA+Hat.qMjM)%GA3@ T?{SN_&a0;%y.E?j:؜D@0ֻR3X2{%f튋je K Oۖg (bSX>g> < Au'*z#s >H*Dhju'yF־ٯkat-}[ :h[9L|ͦ"wr'ycis!4ͺAx×QL)ҝa*vz K*3c3!셧ѶF6kio/%M4` Dz=:OjI%'/Ad @:W$1<$&90n&UR\p+Tu4 ؒqWe7Jp#!jHu”$ ߞ0W9#&:osqdVtD".^R 7Ve3 Iq$ j@u/h]1LO\ӆ|-)A\T<BcgX ˕͔ 8#4Ɩ[6<ØG̔Ф ߘ_Qdݨ2҄TsIz605ZǕ x0M]T5>:TW+r\Vt jE Ep U<|8vnbF5mrկ7#q\'͙oly02vbhJ?^͵4g)Rj^zB2~/ݤa ps JBݫt/gαU>1Lc7dau4P5@4bYHZw; UC-#^T`"IwoPžN*)1V%eWC_m"I; 1ŚNt6vtm: MP{P l 3WH̒jYh֧(l#_fhuGyս\Nw߽̎reDW|#= N`'*b&AukۦCoKu?@ʋb$DGϟ/@ 2jW|IIVC \(9ѴQ ɞ&V5ڍn `%uD]`FZ2 4 ӍR >ҰH2Re:e69BUfnhTN& ¥ t+ ! Z'bb //?x_Ԏ44F ͇xiIW`>N"zȼ8 #gd#b>z-iPƤg&U!/{IhR@H\7ʩ. !;MBWAxm/p7B7)}KCk}]#mP#i(7JEaX#tz:ʼ3j@K'uX~6W$S2Uq7!I(tc~2i?"TیM zTe$BHY޳rN,'U9EF•9xvghAHa/3!kYL֘YMxc0b2 N9R&Ee[ܖHј9t/K^֋X/0'xgr+uz;ԡY=ܣO*AIttɵx%kܽc`uq'1kd:2 fI!:}m׮V ~a!W~%PHOD 0G{DY4GL*ߋ%=}LyK$󲪸Y%xN|*vNC?JG(k=!𙍫jsϮrKQ_t*hcE@$G 1T|W7En)8> xPliRߨh`l˲iƴ-kbQɮ$#pI@?іd:u,fOꤺݹWu ,?!nPCWpGii;s?vl?'g߄Z#N3v{Y5auSVWK9ݝo';c`SW]>?C:nɮBW=kJbHJ*>B|)΅IkJb[[qS%}0fn͋oD|T44!g^XߊZ ɽFH'Azm1SaID%3GdU>P `?XZ|YTʛxMN5ұ+_zZA?}_%̥:; S9E_9VT33 FI>?Q7/K畂cvK0;x=fmAcA sfe=tx>h/*7Ý t}DKhNs%~ ECy?$W@l2 oYýJ|>'tnIly&6zPӥp98Tm[i;.~Cj(NؙpI#ωiJIkZf}S"Qi[L'*#碲_K B+yJ8 }i;7tt]ѿTq]PߍI L31(ce ~a 17m =_f*sɃHMы`sJOWBj0ۘa%eJ|`qpԲ~ƤV"&я8D#b{jz+k+ʙoC;O%Vծ\NkD\*νe=W#2ɥZ@Ig_fAJk|9ƲmϼlW9|DU+~U&:tԍ!IQuO)[Оs'Sh ':DB6:S*@(zP;9Uvsʿa V5$ƴ%;¬"ڧwxLw:GA)?aI܁ q{ !;=ĕT|y\`so&+K#IΈzBGfTԼ`R^1  ,j+c ыtib9 Q7PiPdNj Z%;!}'jnF3 Tޒ8&@ΎԨx!픐SZЂ.y,ݥ'Kx'2DVwVU,GAݦn_|HXσ;|D#Z O1ĝiCd=eiukD/!HO 0)bS(,n+wxܴUk^y B>w_plH#[:ҷJ9oi-y .Klw74T "/+]XЌ@tM تpvj^n28QGe]F.7$BeZk4m/ڞQD)Ni#߇]qVCCvㄹxźH!"/:Tkq#גn][>m|5R^yn Y\_SŰU>;o!wfw 9J˝:&aHL}rWoʇN=Gpz|>96n\-C slե mՆ[}UnIi[ [ګG󁲃5ܹ``րm]rMz橺E~>WZ,gjs4pD:jۍ}uMԷ7tН0vgl~Ow&/|5N%~^\oSđoϬ=BtkpDEV괹i;%3۩ƈX890\lGo88}dC K(@#rvֈaPP*"~DO ZMѺ;l\#ūHu66)1k7b5˕?yyZD݇!++g2`y2bX lYĭA'GZ ie^7OmiG: Cѩ%I9RaO&͞):]w5H/}VͨqnG2JkVz.mG4ŭw)@M,%썢I5ᮦYJ:?6%SÓ7^eAsMhGbGlnDY^-Bc10zlo)zCUxCQٕOku4!E;H} !s 5WsCN,QYJ)=J^B*bd&L<{RXF'wV<<]EZ-+%ެވ#eһ-䂋 2?$ pP8VpÛc/Z|C Sh,+eN9|9 ~ȭLLJ)gvs #z* a踠: y0ȑ6t.gzB飧Z#eJ=bNa5ҬP0“1{+fi%~D:%gJqL' =N.* ňL!6I1\1<(k9:JqcIBȳF'oi}Y۔`*ʁ@̥>>ǃ:'霿_ J{Q!D!7+ /T-`g3K9$2Lr%|t3q/ʼ-2bOkl$z h3-gf8'cʾSofIxM*Qv-xjVOdgFe;B*"h|nj@'Oʭh `,ә$pjjI_cqm'דL̺7Gͯ'Bp3Eoc!֡1?U3{Volb{jiAMdɻWM`40vws̍-Wr^U؊zK<_Kp1@B @&`%&ytki.E.L{~#ǟȫY$}sם:B$`熫z =fddl-_+WhJ[ KQb3'ǹHNJ[u.zL1<7HZOoMuM}Lx3vfj' 'L$&d=ui5 aMM={ŌOU]`;I '&tۗz`҇aBBfUg+k61+^oS.ZDЩȸJ<㶡9Z+'FˠQ(S,o8p x-}B% s}v.:hkP~N#v_f1E]@ƾ =F X2rѽFۯb?3lJ1|;(P> Yw_}`r0$g/q#ulAC1+MBvU=G;xn(8[i7|,D՘8@!25쿤ao'BPN?)~2BUwMX;rU"qavj0!E[[َR;`\Ƅuz%@tk{G;{8AF$oj͍y1Mڠuo!)]ItL \JHPeg_%ü9-/: %OҔp!=\b")c1F.D #ԇD;/RÕJ]ނyi -T9%':;Q"⭄NI* 2aذL@5Zpͱ+=ܸm+C.5m~jO?)!)qԔv{5|i!g%fP3r5}SfYYk쏠GmJ!0,E[]0Ln{*LFU5͕ *9+wv\ IEMNΞ ȯӲ$-Sb$;GǍɕe_Z2[7^Ge^ūh?`Ev9˷ zG|[[f}R6)`c\q쀐N8<-ٌsr3N\)"VS!(텄6/W3~nIy:;fWXRT>/t^9?2b.^ [k%PSM~T) Kx1r,d!f('&D[?n369k!>X<vmpS
ny?BM _LRhA'‐ !~I7UeEKgC(Ȓ +;B$,ef]`Rz$ڤZ"WQ ޜ0ZAUS`тEP{gF~p(h\6o{?|np?PΥ]y7᧷圸=PGK_Jnq`cWңg=SX{Br4e, T!h״xx;'\3xѠFr ecO V_hx؃ Xͪ 9u ѹ $( NcZV՜>4YwO֝ ^8g9'iK@0-t{ي3c\+Wڮ.aeҍH q6;qg5 @}~tuLH3n˷HY&Ã?Ww0wrKjFdB5.7ia1 ,k? -)lWj"ɐ>1xA˫m6p&q-S<,O(#5P(cBbZ8-=f 6Ϲ7X}r ;L&Q*[̪ H?۝`A#$o:js+ґ3d2{5QzͧI|3sSڱm X.a,]U|xKlArYljѼm6g:L2Ls#, + }~@ i X  Wmj!M܂񦭬O׃ḿ-" 4h#vN uhrO\ҽ=+;#r]]-Imn1Q;I:r&]i+`NWöo7%8hfEx<3qwtztV NW Je(0[9YSjڣ*y|aQE+hSikoA;˱rwZ/CmZ;LE˺2Q2A(5Ôc]bc})uH `T-D߉H09BLt UIO; ikڝ\M) !J#!rY؃2{9nm䪞, ޷Nva;Do:2$(Pwp@N2sk4s f Rߙ {x ȣ^Fy*?K/<[FKpzpoIT_X*Aݢ^S^bjnV)id#0b2xG-58XϕEʁŻQ;qYZLK/sdpEAvguP_gNj \~*Lu.mQZij1WZ1uw SBLBAic|A=p{en7z/0bpyN)Z3%_`Qu֪lE@ގB({1F$ѦҌ~=((~dV N[0G9H2Dm+ 6uJL_Qy4CC4*n@zVVh1\i5tDS. \~Tr|=vh*r{6EQ+姂Lm ҂글*a݌'yb~p_CYwENcM!wؖ/7fQ/ȖO+D^8!D?FF{je5:ۣZP`G G8&Fa* $y{~I0wlAߤKFUCD?t(B*N(w zÖN:)ky]s/x1=5[$!Yaq8X4wFꆁqľ1m0Tc%qtWn) PAt]ODgaɹQ]gBWiLWş|l )i7Mˆ$sPqA3^`^?>xr_Ro^ߒB]Acszc!FF@\@p=b_:!P-˕l5+%]lETD*GhXR ܻ-v){XUEЭjGKs  拣x(gaQ>r7L˼45N a'_d5ԽS&А0( |뜌Ɲ${~9 ^nuy{vK{Z>Ӕ).ZYoOfℤyg:,ZGV) FYĴT/Ojb^k']v=鋖68g~<<±]#!&6 藧pAw2kV"ZL s&@0$gqn 6 b$qvFkp"4~܄#?Mae%7<7 =@^^QriU΁9PX@}OI8vicOEQhS0qf/agg˱&$AfüP15 $NNS+ %],_-)  hqA:uB5*5_޴C0ظ2hX ROZҺP@p4|c䷖ºTZ5Kj$ؒb([%9,~|8@QSnW& 2Jrs\ f<ț2u8m)s2K2TgG|$Ӝ͜%fn!,vSdC2<+5sQ=pl:]^!N{#+b9qȬӔK32AMn+CY)'+ť6>٭\ɴTyAE#4|hg\̽8:|C/D營4fr_̄Mګv ` >ZcJgpa㍣1Na|JT}j6<9%Z֏xY QH pOIW-GʤIMxڲARe<8rfBR)#<*q-Yyi̠emcƾ۪.zI#wެw.Y5OJ;w+O '2!1&閎|(ﷴ\Q4GN2]oJ 棌j}WON_ՄP6sF8'y *zv"\!T`_vgЗ`|Ĭeg\4`NP#X_4%bKϦm)N79NssMϨ)xQŅp:SRp }^qF[vGWi-Sֈ; U~ptD4[z.tJC5mP>9a>jl hmiA3Vu#BU>P?T xB|K+* Isi pc=x Wꥪ\pcM)3t#K63ۃ'{SP'N;˛0b'RncVW M5afh|1* *ƛ=džB$LJ$Ud85(ۼ'vIR@\ܶz\JNf81vٶÞ|Z _.҂pa_B6}umn謐b OC%B6l∀`}1O1"͏(CUTt 2}~o(8R Y];C'LOUQvA E",%뉓/ɶ&Ja;vUaoܥX6 W`:Hࡠ'SB?(5 vĿEWj xL1p>>G?d;tr6|2Yr`\RP"bO&duY8yTLw/LM?}s ppL!(V|'v Xz~Z4wLWXeXƄٽ(%#;|%BB_`QU]0 %[3 w.sKz{S0Agjx*BmS()vǸϺYȱPu%?UTK%_ʰE7^'G6q'%<"{0¡xrd}94 .s&S \6P2+1ǯ pV'5*>s`DI= i_dΩԜmG OMS7m\fis^* >`l'\𚇖\;B,DU&~6͔ۆ0#&J;9G&NR­UB׸ [1nc)ppo'"~/ھ: _I0"gn6rl^o.¿tFOD|b :u*:ej3ۦF[\l7AsɥFec뵍$\`(noE$PoC0mt` mL\ RR^5Vpϥr=BӮ_2eot*KZ~g,Vm4LtQ3:6K vZ?s$|K31C\ha Qv9 }> d dqd[[;WNqtKhUeU0n C~uCǡuLl=d5T6n7ojOׯټ4AG({|cos%;EfMnRkV4bؐ n n ]2TsfV_~ǫ[PSUdQ1=ж J*yJ˲.$ 8S*v6Bqz8:p\,wiU;HDÒ͔ p(>zs&.CKu:C q7dP*[姎GeHHoX&F/CgT#n/o:|qrKFnm^ζnԙ8ݙ/ca_rc~a"AǖȲp0s5y"N;|_rlI(O0H6NԁO٬ـIEoWAC_J ra6Kj [jσC}YS0ʍwM-yQ@ODBiY8Y[}@(b*C;" |-Ï_Z2*.Ti pT~tBffr8 5D7zd̘ h\VPc^TNm,c35^ #mގMЃ4v j|\js91@􈐍"W WJcO- r>5Xssf=YA՜ڡ72^ٜDU.Vc @$&IJe(/؅G4y3A&$LÂv¸3L>˨"?VQo>L!3t#Ksqc)emwwW}&JώdEAx[en^0V…<)Y_cQ Pr8kK8O,!xpi6qz~2.fOć_.K~ee9UoL*$y 1r;NR;>ȡ>Wx7ӥ*lzRwkͨy p5yY0уq?G[]eiFiH]@E0%+V;jG(x`)dmazam 99հ2$ePDH#:faUw4颁z`.LL L.m Eu+r<)VqJB)T5Qde,ëYM#+f:^m *@ $IG hsul=Y*g@*Na% 7c}{;-9K@DſУ-}"ET \N'zz6O(P˾xUb?l C*j6ϞXC׉1ƼNꑃη zֿ+l~bv0Qt n(f6Őko"n8~Wv$.,5t5ϊ 5@6+J퐋7 ?[I'0V6M€G@+\0~`8ꥊ{>RW4%4 ˓l уavqeo0ZEYJ_7l"5Q7Q sȈ > @:%vu5lGe2Zi9}52{5yh?OWyj+Y&Qza*s<%sN\s-V26ˮ~oHjρ0?&A9%>RF kx%d 4fFs0|rH ־JCP%%$~38$!$5wۮf}T2pTFwaߧe\!&8M7k:`5*_P[P#Q j5 8{nL-_۬ڀ H'}6]w3Jyrv|fv^EXh@5+PÌMs^D2.t1h? @'-T5/96Q]xC0+Suk>JQX:(ՕFur8Xa?%UT6Na&'w k-mߐZJA>~u_l5^^?f *uPgڅrvE5:ԯH{2hg;HV91&FELi?<'E{JIt YW(!~G%*0tʼb.w1OI4кOU>JbH7F#_|~!O '41bP+ףxfqIc{)S?H~jI\<\qS`X]-P 1u $-m0a8vۆ!3'BVJqo(eȌ0"XN_{ ,PpkZ;IO;#f*&)JJ^cKQA~H*#3dh|v1u@8u?sP7&~&*΢HC%tK^VL$ {혿{~?91[x+&ǜ~yWTn "2,1;`0 1;`ѫU )ҬyrCKY(j`cܶ;rQ,Valv CTͫ#CЖdb¯:~V-%rF 3]|,iQUz'H!ÃqGL]4!肯Gkm}t-Td=|V\ UهnO}d~ &k hBBlxq#vh?x9Ԛjc`euש2͞†!HXcr}awƓ5L@97$O8jJ [?>eK$9i$Tw3 wD yQɮ%5.1h7*s5Kb]m 'B()_2 ?']ni(%rQ j<\kp%󝎎-[rt{Q]̠!J5I޹.hv,ƅUUU@IcdXH1{ LIr{R>bӓ ;D0= s:0iw5 2}PH4ET1& evګԏy(Tv]bN7cn0Lu07LP-#VvhW[%4WM?3 =gLHY֙6'aHK (LJI$>[XE@;!eCev-B7rtfLT)QprTF<OK,xW1/>`ΰ-o|ZC|W{VULpCx%{.j{03 6 IN35ɳ0QRqwy(7+bSE|iRrf<6t$L-M̏{4ԕ(GI3&'w$TtQJ.Bpf᫖@ZQxWBVZx3&D+C}9%P\S?Ʃ;OF&Wd)ɻ*>J_tr&WiJ±]F(fTRL:r0o>|7;ۏ<\}b3ήF.cӜYBGPR>Yz*QYS5KH2ᕝclxSkEB$3R[?nrauY\<\B PY'Ɲ) =ţ'fT#κ|rH)u'n  @jp qI3 H V2+9$fqO*X k_@r^LfQ^V ԣj̵ϯ^à5ڋԑ:c QQEUpҲnAAT8l6 ?4VA!}kZ7L U_8f R7yE2;'=n⾼x_ \C7w}n7ڊ6L|~"ύxAr(?庈܀I֫Q !Q|g xrS}*cu,xyYYgW)V^{AH řPeyD 5zE$PXAْ} v٢*PC@4c)ͤ(m+L'RהC<}* D?2@MUhOVuVd'U (dvmZjg5_1ZT/ NZ87M,0xT0'aGTgbKU츮MhOl1kqgsybZQ r @2#^@$Ms>./Ȕ1yeb "(@[$yCr[$n}Бzi۫>0ħed3"!(PCdwAK ~ ixV/.r6U!կ{@ _wL7|00qċB c5?_ไpL Xa7fN+b/X`_jB 8(O]j13>~&! 2OƪPC3{Q#34 QGdBh(=r2V*[´lC P`+@l#Ⱦ! TsX2m[B.ʐ Xg]6#Ak#GJ+3Ǐ~*jnPBiZZ&lIDcȬ<9SjX~,R|Ró580`gEMٝk )CZHr)R.(6{|,+ {^ Ѻ]"zw7ܞ(zN0iD#=e6+6 ⓰kWVK%[@ >yREs[?zr$tO$&($O_ZSjagsT51}-w`z&CCȭL֏0ƭ6>(*RޚIV H7ԇVO 1r,(qv󡉿GbS3Q\k͑;7\kɈц8w̸Dڰot,\،@gK$Ha ]pFJ!2rye_YE}n|h{ hp|*Rg ֊'FHoUUo}2ҫ_}rE}-# g8jzN"X+ߡ"4UYhPY>)n=L;.~W 1"B$RʥTH/hQ9,t(h{m3@4&-^4&P^S6TS彃HpW? LP$;j|/ʻjn\#?|'&a S ؛C|1* wf8ABst pC 6ur52 O R ݹ@eY'xƆz%M+jtWta*O^]84}hM!t7xݒd_lj/˫Oa-ܧ$^=#G ?],"nOEy;r/Gs4nNXHlEAozkm[RSY@yL}~0`^`#B*A&Wkui\qVE A\Yӆ">4|6Z]CS;c%8gɇspGO`kpNMKT/1툋4C,X|=L V@q/P$JSLpdOTQ:D[%,1uvuMd/ܮ^N0C>C5V 1.PT_n( 0N?\%{>3JIyP h\>Η2OLqUѬ*3hPw A, d 0F^W!gI}v/G l^#bPmALYT\jǙeG=cjxRn2CA ^jS$KN*ӼXv,r tF^ a:='"#uTfB!c($Gև8Ξ6/I.zM.{Nݕ ^J"7!\/W?j|O AC@!$>_Av\@q8UR۴of(sU-sx=Qy<߉I5btao'$^qJc5,k֬恋;7:Y>d 9}5m{$q)kI$;8X$ǒi2IM x3zTHϤlH;@+Utӑ=a" L9*ma jUSvD JL{̢F H%(A(n/-`W&, Ǭmn)[|b':k;8h$Uu7o֜(j x˂z_p8>h-eKߎd+~ɻ}wۚ+<jƍ{Tyg a+ΘfQaB`H>133<'%j $`dUo#CwhN\Xpص)@,gؽ=i{(IThoŘT*;7P{m?(d~j@u7E%9fRP)( #NsJ35u4i؜ܔHL6"':CoqX${_)N:C/&7< zkR8_%TȲ9F9@yb*_LhK%'\ZջK䧀+4fHzx +Bv{ruM9JETH]'G);O%xg$)r{rY<083zUxeK7go^7tlS,p&JLŅMsQO!r[Ul[fP<3*}z)} zL/A- azB/]{YY#ybCTࠗIɕӊ RMT%^ \ iƑoVNc N۟XQ;{dڴ ({hkT&..Ԉ % Lסf=8mvZZW|URW݉Y$-*cUR[f&'Ps!;̂A%1 ߞ%xh6fHE:Ohݘc+P?Sk.#&`C&h 9vf0;; C.)>uɕl@UO~ZO$sރ0CzqF=WD fZU>eIllG2.ꑏfH2!GC)Zl1?6)hO{[ꮼRohֻe!5P[Ѭђk ƕ,%Ãz`ln;>1xef(tΚ@'VxaBNOB;5uI@fwVÞW4),S43žiݡHC Nҏdzf^>XD Qʥk+|T1 /ǭlQxwѯoMRW" NF3ܜE(O=HCexy]Cye w='14_k3X6 ?r64Y"7͊vچ3d-\MʝUjA;Ȭ괻 |+?]9 :&4הuiJ?&U\"Qǻ[E}QU*.>S>Y6ެX˚l .5׆Xm6.TMP΂Z04biڲ_;5yFr԰ U|]6\)b vOJĘ]VyV(*n]rxQz}iЂ^RkhN9)D*`sU\W`ā&+kP@5Aٵ팢lڌ1>S"">.kL7ko16 )6Q4x5]R<ۉ-wGJr*gQR{oPd?"+k(zۋ0]|LMϮc26dH)cnQdxG1܌}ܐ/즤~uѢ\ii }:oh.8nh~Ot2 g#3V].D?ؠ* Coڦ2U[n\4Q󠻂BvЬj,^겲E!(T6bx)1BhGgFKFw9IOLV]N'STqQPIC[Ar pYfb)̃J>_aj3pKҀ¼/`iV--$\1T c*بWKOJS}2 䃂׆yvI3 w9${S_e[F pִضL/)d!_qn͟.83&ePbr""jlDƚ:'/-!8r:W/oe`+X&ixp]ZgPjHZ쿌R{pI@UMB_M 7b0$GƖ.H.QJɲOv UqF͜L=,3ӟ1-_a+?75 OQp5^f%Xzͮl̓. J$kuXN"T~}Ac/Bmfh &TvZZBfև Ә?bc2Du!kKSv|S={L<=jjJz,_5oö>3`~Y  '|7W>5@*o(x>{\t2 u8pS+)&L)DQOT-hoGI}!%PJ82/j-Cf,-VcNVw_oAUHXDG륛llqԚE:5$ˮGlA,O_ˤI&Ú?Q  O˻8pD+,YC$^HO=%i[w:*x (#Ei.%;RSc^{ }% Wl"ھSN;1A@8"pPw .'L][KA\nr 5TE&(Yk  2! P@I,[ȟa+Zcς?0~ZרX?lQ2 H@qHY~{lۧ(|2nnPxNx8W8e ݌e}M~=lЮr$FJkڇ[Y~ɓ\8._ވKfAxC粗+D'(xU{t+tEs"*>I(6fO'"&CO܃;pNCyfm܅ A/ (imFzlEdZ@ĪO/rMDఝDV͈;eʹ@d~RUY 䡜jDPՁXA0Bזex0QtR DV`wons@1{nmm9V}rǓb&-=7a@ {iɭ|{|tr{x[f[}sə*w!*t6K($>LNlAfI[XWT} }ÑdJ9#^/x?6*;EbZCbr`nj^06^qܶEŭ \v,E בW*j<$'z`mg)"՗pm@hKf}8!z DiNs r&hRgk3o᜙/jfQq3>^DЂ}e{zGf꭫b3N@eNZ:])Ah:A=?v`-!t~ΖP#k-͇7Z-HTnǞ >ԙ;O>xD&Nt,)<߈YםzcxRob]!aY~40%4@,?k%gxg M">[l]#dCSz&|п-l,gMrc8@B*cO_ԝ9ݫN㞹qo^ZY$Mu. {z-C3.FsC}%Gii> }JtN+9- R sxȚ!9F΁^wt)!G['3PCѲ ǝт>)9!o=Z>r^|&bRO!PʿXiA ]i .PT{UwLԹwGvETۦ_ݣW{Kc[JwjU7T8fKŴFʜ$Vjmd~JUM(V A6;|FKe[k"9 ;!a p r1rpQ4mnm13q>M R)ɹMHKj>4VBxHM茀P%iKh??4$_L<>_y.+ P AHiE6y|g&K2^7kVI*+( l!xK|Ѧ_zu4wI;]V Mn.$"'ҙh ,/Np?M_ uHc2T!j2. >x?&;޴lVmfW bƏ$֔yf|yWeԆ~qW޸ }G *%JtMFFFZq93(1"_ 98d{m\"H*FQCC{36.lˬM&)ՖWU+'2"&'0iɩ3< HL}i~!wpR۩ٜ#Οba-)v3xQD-y.$^_S*9)QhO4'w!=07ŽV2p *7[N-/pԵc2S)8vjwUK::JȐRP|m>%49 C!p\|7G,R5p<` ,̳CO4l^+SzQw2>^f5:'y'K5h*-O7uA'a\  V6Þ_H^ֱ.QJ x;cL RU'U3+Iԋ\ch_DžU^("j^9:?4g-FfJh{qDAP:*$+cGS)cS;q_:WَVG 2){ow9qJ5$XYKor]ED Ɨuc yQܭ `e70RcהEhҐ;c ߠ_>//)2Q]7:0Ml*1<&IKfvme? e N/)Nߦm#XRDw2't3F9JjT΍Rdr/D$m%뒦^ !f+SvӧaJi?1҇ QG0+VqmmՖƳ%{}AZ@]j|\ dl㧄| Q'GEk̶i 0l\6'W0W5^Ml2_Г("?|m'\Lk }k{3XN&.$JxnXf'X!Xb 78NzM1ۋ.(x` `, ;ƨ OWFtx+k#7o" Xvpg$wX?f-бpoËr1kt'sg(MȩJSRVvϞ ?5YA`ĭvȯR9q }h@3bA 9M@&Rw_ݧHϼQ 5v$Ei/=(7h5 +-Ξ}cɊs=jΦ3K{OeC:h1+;gFts뫣APaیy#ά2|",c? |gW9FAe1vo5X)R84<a;m"-$+>sGĴtMѪ ;3@N򶎣 伖Fuk#ZwL8SIVysi&دsB!P~(v3UTu +] =g:G#bqvB! 61q8tW.Ow w ۼ݌*ܰ @?L 4֘b䩢nK@M2` 3=˟vO4B}f3{[N$=->ZA%{DMHwx D퇽P&1RoKzz]B&엣*P  ka\@3=-2,1TA1qJ;i:X+ZS"{о-I=8;Ǎ-`@}H"=87!lJ圞P{OVYH`0eZNW5,肋6skO!'TJ(Tel=BBT(MZ)] PZd8xSYN"m f4iu_I"_o|/Ӵԫ9|_udIG=C-:B{/6hu)6 wQiVnZ%/寑IC~uwThbo~jK5kz(/rQByӌ t]QT||5v&l9⮑!U6oΝjuߡtHFZQFm3%P!/<}@Qd%r owv1ɪU7eX͇ygc~yJEElNd2[EWjSO.b ݖ\tg}30z0j͢hWfe (Xng/Z?igt;#_ ]Wcf YPD!hI &_5"f@Kmh1/tnM%'>0i;Bu0$jy0ׇmJ&Fu @`!4JO6~"W,k4#RorJ r\Vvs:v\ӣ*U}+]I J?,GNv[8?;Yxzi#[QY5Do Φɨ[/aJHOëD'm~xX{=¦uNMք|=ow.T,t4c÷(Jex|GjQA3Z._ ZM*ՔuQ-iJ!^Pi|Gok2cM}]. 7O*-? :g|T\d AK]ٱЈAc |~by(H(9姮'\uaer(c|&i:Mf0 >nD^(fa"\̠m;I {5ȥ*7*.Ԏ sx+y8B[b$q@*=Obk6:OKj)O&i57k&6vIؤZr߲a)Y}. VcyV2)D2p Ċ꣇_vFm⑖LUI'Rob{~prAuύTm5#,Zɶ JwK YZ