sssd-kcm-2.7.3-2.el8 >  A c -U]Po/6،w zω:g=\ |Jyz*%+[Cb .8^^!1@523|Jb@poHo~ys8ؙ ȱ̜3&q)ys)ľϷZw``.2? Id: / EEͰl-NG#HlJ܉:UQ/xf,_ /Ig Bʿ`zP_ %f5)#*8ƕF)ԅgA֣+JJm)uLZB#ecONıif8^d>uWE5-ZpP=;0r2&.K:\-(1~Qewnm=&Pz5NFxA~]>T01=,/)j46ec1f600ce3f16da31a24c3eb260c0a8f2fd2dba2d230f4c67a7935e12b047f0f32e587ee5bdd6c775725452a0de97732c5661dc -U]l^<*Xy0Q ˄vpd\^[ #=vC؞Aj\~Z.)_%A3OER?i|^L\& 69XmT^, qPsc)jQ*N?1n ,*i ď:yX?B)Zmxq5s]۠??"˽-Y]eY/{r=C5mYȉ 6bE]V_%U:>nMKd&)9ӟLQa:e>;G$> TbsP}ZMRa-p%/)Oȩ {(XpB?d   B #@FMbt         ]     F` <<G<(89T:e> ?@G$ HX I XY\ ] ^ bd eflt, u` vw` x y/Csssd-kcm2.7.32.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.bx86-01.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxx86_64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%vOzځAA큤A큤bbbbbbbbbbbbbacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd479d4c5eb55753470a4aaf1e843d50c82cada45de2b4f0aa3eb952c5ae438ecb6839546f4a7f6b9f2bd861dcd6c4a583d07f721b6bbb334de4f4281d283537604b4519bc951c6f6980efadab7ca4cc9a8ebe386bbe1620fcea95f26377781623980833e06e46e22fff8755514cf53e913f06a2136d08ffb2d958e942fb3bc0ac8055712340173c9263c5b2ea7060fff02b1ee1c427e486c7d128fd0a53dd4afa6d9acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.3-2.el8.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(x86-64)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)krb5-libslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.7.3-2.el81.18.2-113.0.4-14.6.0-14.0-15.2-12.7.3-2.el84.14.3bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.7.3-2.el82.7.3-2.el82.7.3-2.el8 kcm_default_ccache.build-id58b954d9a1b2ffb9ac5b38df4c3bd3c659966b93sssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/58//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=58b954d9a1b2ffb9ac5b38df4c3bd3c659966b93, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)/R-R)R2RRRRRR+R R RR R RR/RRRRR1R'RRRR R,RRRRR R!R#R"RR$R(R%R&RR.R*RR0RR6utf-86a2c220dd77ca655f6aad00fd1d2a88b08d431af5887eb3969f104a35600d2f1?7zXZ !#,,] b2u Q{LT2 ĻJIQujDM(8j-z1c8 Ԇ J͑U=>؀zI j|6rVO1a2rIW5It~`:} zY~0RjlvJ'*VⓔEgNmCE$|߇A'R@0vϛU!fSul q>yhQ>LKN!!Ƭ)Br}0ǡeC>Έ(Dǫʵ7h]Tr+3ȜMUp2Srch_L.(}${$VOH?F li7DG|)s j>^$>n_ρ @=cMHlGC P܁G1Ò5A]7[))n;HKXc{tcE 0ǚ?F¬Fki]{QZJ1IlGB`eKlH<ZC\:P椦+ =Ks*[+hWtkTfl@}TI+/sr{}9g[pgFh+T7ecY U"C4Õ}Vs9HMiA 6ݬ.,I6clxh> gv !L Z9H{$Jў6W(ݎaXMc4ѧ^8Ro<2E[ǽ[32tDq|m>m:;Xѕ4 RH\ UJ!E:\j,}5b!¯!+˕_mtyBJOr;nņ0Nȿ0 *)$ܥ"Z;1rkF"aM5iq^3N-`ff-pĊj"6Y$H.abs!hEc/`2nHYP f>(@aym.{\\g c?hUwل@ѩl̝90;vb8|v`Ho iCIZ/1+`*&}yӏ_ǘS `|\b ijuŠk10 [vS; '4b05߃8 &O޸8'_k ̀ LDL&ۿfˠFy @$lД%6 Tpo.Z1->Wӣ{g_ʲFEz%yRɥ[jN??`CJZ(d` 6wk덲/ :QM-(CuhNentwd%xa=C' M^wؙ`M#Gӱw0bτ*&5 $B5.JڅMPH5*\T$_ t\i x.,y$ᑕ4O|P|0;:lemƃL;07u#zwz$j CGo~Mb_B&lwEд?00{)zт>4%#hjF"xx1:,b@u8ewG kgulT,,_Z+˧i- z7\X@cF9 ¥0!chtc /vF|%LUJ-HNM[;_Wv)3}hHXm D9nή&TdFfƮ(!w6+II,ŋӦk$W#b,5>m;VQ'goCnt3R wgҖV!uܹ`e7`U+).&W9ӿ$񋬃&eLLbyO3 ,ƺZy`+D5!!+F΢\jA/z} XW ؼ1eBB_5Q@?tP@_~ LWU.j ?LwוNMyvYgEs9(T:gf46.Qxzag>ca)ɍL[Xr0y{=TI (([o0m^̨#e3t=~|2C)TR U#M+zrgCM6* Kw]m&@,5Z2GV lfaŏ>8` '^Iغcn,\2[yq`1yMn]P> = D0rԜY }VwؓD>rp1E;D;}.5s{'>|’C~n%Wp/yخ\ZM TAfo% +qvVu‹jv_C3wXpl%;~9  `p5KPi5ӛ8 +4J^[,2m'() IX 8uE.Lmt;3[|Zi5Ri)VLo@s} ꙼JqG&b0( UKȼij@3ᩐ P O:WqyD X䑵d;LoPȳ0s$x0Qx$=>AeTA*ы)|m۔ziw?pNX˗5in-I*@ LL5xЮfcOu*aV*r<+VDl4B2aQ1f`z 0zƸ{Oy)Ru jZ0k)!ы|a D3s (_YhOdx]T薪Eݽ.߉I>c2M.p gt8@y]{ "&~(%RYM.8}¯!y?'zh sײ6d1:W*TcϦX#yFG]B%eQ;[\.E.D[;SmQ[(0ZL`@] u_n_LAIZGD @CRbc+zvZz i;&;t@a`*9B}?<36B uvr K2e 䒳ɨDI5BO j,]CFI`y(24~l^تb:(5={Pնh1P2)vèp^vzfg qC`1YSi3?m8ZW9Εs:L 31!. d'< ?5J;m@nUʻtG2z% 4̨N(TFD^Fɋc"si<^RL,j04*gO56xڹ"v FYQa0NVٓ{ƕ+[SRb1yWW*9yOzdkӾҴ$EH&V)B?vesWBG}_HȈeDB:;qj6/77Ğ*؀gSIF@h(V+a[73M9W%5~VE V*AN(6`$l3PXğk4?#VHV2_,a50QA*޵A_Qet kn 0ij";4l$pbpc؂O5%mH:h- g`&K|qDP6_vםԽD1s$Ҽ$bLv1`bpRbL Lzfdߘv^)~ll!hJ4J%x $5(vzYٝ5"Q̙XyP]W 6WA̻ PGƚ.ݱ@wɇ= bK}!Ĺ]OcOSBԯ!V,">iHuK_5f$61dÀ#&2RVK&$:`e/d,3 vz6 > ֥sT2#Uhb׫/Iװ[aD(,3Xjz3U##Jw iKSk*}znݠ[T!o"iI㮻$D&Xy;-@lw lGk؞s ipUd nMU/MdOuOƦL._6BnT6c&-6K#ͧ1[黉bED<6ֺ|"CuU0 gE@Gbn9D C>M?pT-;UXx&FLI\sݚÌCw08a\^%*6Jnhljڎ7xfnzޠu^Fg S1fQB&w-+؉a0jB۔8d 9&v+K5wT&(_A):᲋`_s飪 =?KП~Q3pvr=CfD@cz[ w\_':F81'n)I nEA/ gKu7Øܺ ǜBXEb -dZ:EϢu3T@>u[O!X+2+ Juՠ x$k eGl+u$#d3&B2ujX\){oվ'ARUe i11Jle#6Jϼ1-Å]]Ƨ ߾lЖvkMYl3u Y"ᅌƥUIsjk'.ĝ!w(U|gۣ#_:S?=igS^|Ԍ^ "uampݡ}[Y|=n/r&k}̞1 Vl.1|.W0 C٦mRF1JV!}JjLIrZ8&9+} }``fFsNǴR!J|M7 ]'{'0;?nn'%Rk_p$_$<`-K<ۗ^"uB}4eDv; qIu 4?+`e9jGFWDO:lvzؕTȰvI/;vwV8Q©2}ilzv#Ð= 9(ӃS$pgMeO&hYP/+hYݒn~eʜ<*0z-*}/9M CHҖo36 NTZډjmК#$ЁSV;'?oE ,3l_ykC>=\4FI[b =쀼(5E"O14ޒ| l)| OOiOY4!|#̀4a ~_CB;׼wxjb6,á!\SVSN7Y*Đ%;pxvZ8rX>{ڋS>tQAYpC\Y92L|l ]ěMƁ hHũ*o}d|#7Gc29CKDZ<م[NtqDǜ< ,,r Fadkqz*c4V)ZB봁P#Jf4s4Ib`5n-SՑj,Q9`U{LQl-Q~{#Cex& Y{l2(^esn7~CjfM-9A#C9nKEOkSUES#M} ֗ ($5аrӫ+8ZRmHO#YP.{XG Kz(GxŪh)cJgAW@ U ÆC[2 !rSlj*L:\{թ0Ֆi%׋px{iǞ>y#w7_T.i7qTUqIǩߚؚ̄+^ lxrqc9*r/"ޟrC$Nt7GTLB<|BxpU+r|WkU=Kwn]V꯶^bTKyC+'ߓo51^PX K$ꤿ<!wXo>9M-\Wfͥ<[a-4ۃdYNîm rr)?h*Uy;s?RTV@مt zly L~5cisDE^Y%ibgHج ېf FUz?9&IxJ>\8!?1MQq(pӬvWC W v~8"h#`L\_AiGihd|#WFmlȻdmru{mw#%pe'm D= M8,'#;Bs}xB@p4mzv0 %vQX;U r#B_B"K+̀%,\ HrNҥu𢓦1l(Oր~[@_Eucy0ypq-0I[=4XdCW/95toi q$ 1,wxDXK޸U<h;\㘻OYJ+} ,7bE'VkcAئ yrNt'sKwǑYl"6@?r2bI°k01qH羚~Rz;L"lS@=q)A4BǶ'q(YsJл,jjP @+(\])P 60TN {~>ЖYUNzzGN,slי 4SEYHmǷQ2د30jڿ̐;u5j(t`AV%.b7g*kO^j|L4X5= NH }.]CàϊzT'c|FYЩzg.@Q!ҪZ;QFL{Jg~3lD -\ 6b́ .ZwU]tܼ} Ù8h)VpENBZu:q()q0;MN QVI*)2QWF @QvPP8AΧ Gw%xFɿMR$\Vxͦa~!hKuʛ@e&< b>,nu"eWJWir6L"i} *WRwk> ݫʀybQ;ǹ42LLJ~Fgb^Sȏ|'KW=GA E}NHi?!1eQ7Э똝l_yGx۵P-$!0y%< _"l]Ufm~ϞS{Qp/ # pj}1_km2zXh9jހ2%`|`e[y?h<.a_T9WNj겎  3;~_P #G팸]oL eE{I 32d͐cs824Cc-@\.ut=YWRJ5kH"U:Nnzi?T^Kߡ@KF~$oðFt)g.a٣oV/u$u!4|mq}IfjDZ1!P߀9Uw"zMk#^){O+R[='itn2!sbFԄjXCJ/:.NgٰF(˾]:,F͞ct~J6㽐dSNY\=(ky\oXAI':XB7|Q걞o1m#Nǣ3RP5 AzC䩒2&0yj'F״Ȟ|*\HotqX[G LH Iᓸ:GiWBQvT%ǝHK58}#5!M[e^V^[w8z|P?%:G?6p.B)q+Թz+uվ | wɋn/ghzQhMՂYLJN >-),aV l"S> ̏VJK#!4 k;*IN%P$yDž=6OO.f3H:Hz)lLT2(߽ݰE}iU5uқ].I"ڠ)k+֝BCEK&( IMɁ0@J["<|YҐV<_"d${]~9r!ϖ!p)6lRjx9s)LUarݫXU '`_Xh8U^V+c+󱏑R~qb9kP2ԓ&i+|"o ^PsG?[)819úf$'0c;qU- u?!*7@M~B[~)sY?}xz,TM}l:Eh yr%{z.b|ʁb3#}5vDAᶅo+ Щ+.b3~׭}k"fcC3t܋YF#1y/o_ &Q2JA 7¯!I=>YD?~s,H ־jSҐi3ˋZaL˨ai]YSUz)gQ>n8/# +]c# #DB9y/[7bK\WwDJ/6xgJF jy"2 7eWpRƶ!'h>GM&[_+t*`w©yZhϢȕKW-[FYk蘿auM!]:$8U: wY X4X {YLCj mZ#Q16xR_xJO a9$6BabZlU ݥ:dZvHry;};"n- E7*"XfGŗ O+2w";u3[plmRX%<}Us 7 jV-_?:~.u1+n J?lS.t2θ&L )f@5%1QtӍavƦ\\cHSH"m<$9Ŗ baD2ӇSn<"Z6]+;S/kַ:U^f]@9WyhL.Ԛ}w4ﭗ ܙ+ɀC̀)$'0 O21ΤagG k,M&3Z )7նMfozKGW;^|=/86&<m[XLWdGv# 2ϗq$޴龻/NiERRBmQ?jDa2~8ԹQeVM5~b\A|+i۳~rPhFEy`qg VX}K'Ҍ[MQhdLQn!`YG@~_Z-k .,˰%O[/?~/t=+Sdlf;CEM_^"nR9siҕPgYѷKLNFߌڡF+*yպT*3nV[@!"fVeji u:Ю&PG|_iON)̪ߧF qP⢠#7w^Ð~NcLZbEpZCak@TD2m ~FAc}>`/x`.8g֌gn.-5-A*[kG^q{D#ƃVNtXoWj`Wj꺷}IR@ Q 3IY/K՗qn #T[D5vt7#vsiFK[b3c*_/!30 U~(q_`N6;R t:n-RG%{H#L lLe7z)9k.ay&scFm F4u_R3W͉1[gtG6Ij,u|zRiy={&g2R͎J`LԐ!')4U`hJu<XJ$|MN4+ }(:Õ !i &[e&xf&w[pn(T+ښI;}!w{ִWTN)Zu"JݍoE6 PcWP3I{Bk595m!,6?.[/`eeBcm2Z3sN !*΃ xP]' .]k709-}f1-VZ]DyH&jyCDס&RʔAIuC옒N)dw iT"cMV̤mu}.7t<%ۊ܆*%+Ѓ[Ҥ;GP=4rx 1vFhN[ªd4D e`90s ]+ s#3;r03n{ZR"eLek 4iK,4jtߒo){;ѹı``녢qg%`mVk#JF"dnƅٛ{es).)}%2{a Ra,Po$W$I2%◮$,6݀Ov GwTf(R 2;ޠcVr\xjX44mٓ"wK\P[ }z/Jr :5w,5J2߱Pkpmhؑդk s9uI*G,bS1i"ߛY|el\K'W6;V#? @ {9@~捂ّd? hxk[8ELIG"=Waɕos҄UkNi5Tp#_oUvC%G8"6[jQۏة34OYȎ[1|5D Ps1ZtR:YfipQfT`mzͩ1vx7A,GnS,͂U\a_4^F5\-zAJm! e*9DТVT'i/ 6^,}A4h=J3'ik^a-~Q&E5m{["iTvdA?P!VuPQuhA r-ZJ(?K$1ߕA۱ߥٲf2,T/ &$4 c)7݅JX tfAr?;g)*LYXY4YHX%&~+P ~Q|t(@6W{$|Ua>(~0 L%A9d=>T+JJn-O YY`:\'YīX׊F_)-xnj5E"4|mD^$-%b T6ʧH:A')vd&#wEAU7fy2u.p &7^;ҥFkyQRf, ۲fG ?U<5HLe>ʶa^p=e*^SM#"sOܴf h:^q*F^hpWIub`ksoƆWrMuȓ@ߨ>X<> Jkߒ6ɑov&@@%ܤOa`ҝt}jT[[Bzihإ.|tJlNi4zY;$6Chu<|8 7F\p_T8GN/+F,0|cݨ $zh"a6ne:E}VU^صYlo]yz& 'j Y3*Pfd`n֓'" O}{y0Uě&%KS]?}¿[ÀO m_ NIH a75L1d5A##391~,Ixj=MwCn&kX;mBlq0_MOq,)&ojAmc QEʆK[Qd,KT/櫏,Tr \QbxٛV3_@ӎTڡUU4SŸީƹk6#Qv*s95Oxu$yH"~Fcv~U~S0al"]pt1pцr2hgA ңXFz_QMꝱOgI9hUcWj~'W&A"׎X|a)\ S"n uh0lٿzp@g8@8AO$gtf"=.-ݤ5٠Zfb5N5H(! Hd.߹f󧣛Gu'\]KB9tA & ݎRM=g͓[C݅cct7 `;^!Lr*Ť{;Ryr%/*x5keƽKV ϙ%rd7s$y!w h?sbKC^᭱ z/#]rL IFGZ9MVa-GnE i 8@2ew~oq\= +TI+ҤoN7+E*ff30ՇU8hZ8-e$CHx4♛P耊h؆N ճcɊn@&/+"^a+ ;E#r"pb^VשHzd],HQ Laf%UE|_E$JE>6w^yUfA"~C:LdixyYTy.ɩMs@hS(x -v6HƇy%fiKg\Ffh4prII+q HeDf5ﴰe ZU\:~g!=-bğ j*|0D*p6ȎBb} ԦgA3#&9{p}8dp:A:! bi)@S= W@fљG9_V(m*Tߚ5mJ7S#$B]|\W7KaRvHOy$G+z2>wHٽ` ToukУԔs/d!`y杛JSyr['{|-RmhYY4IjW$Z pՃIB KFhSQ!xۤKoBFC"v/ R !Rtle@ky5dh3YvSM Typì^-КJCQ<%iHO1}m62%~z?Mwbfhz-ye5:ۍB֖ԁבmuwP,^lwnrl\L^y5{u'(B4>Qm෥g*րBQU.yՆHU+A"Vz~D4V>WeՉwYI=:' +ݮڸZ7#D, Œ7܅9!<?^[#c\>+ yl`Fb~?@@>vf̒PSxb'?]9O6$ 3y\M# 9 D'cؙve ^_tK/0eN DA眨 p>'Ag^U= P'hn>Bdt #x1KjS?P/FNܾh{V]=jjZe}-[:> m*!B[Uߒ pKYYkQ0,`^[R~GGE>{C-Oʀ0ix2`]? ّO- g+ŽϾn4 tE|w0Yō$[,.kdCz(3%'dT#JKEGCܼ4'G/wbV J&tc6i$~"TuE(/@{Ï1*?]fq j?x R[2lֲD W`#q<2"9e_Ԩ!T`cv$=iJ&}U%;[pAR4'guFK#<セ#6 V^//Q9y ~ٖ'W!kłؖz$XIIȗS$j`3P2Us4䅳svKT=6ּoڴ6 Y3b\r] F7R̞aYxfKn22$.8F ?'l;+޿]>84k5MqgZ)+%wmJqР6KQnRdgO.xuiཱུW0|@# &F茷EatiF֐`'V% Vi>Ҽ+2}GLGFfh1{W;mxߜ%FDΆ)269SBU3w?)x}VJ?1C<?%HN<9J>\/HRAH/K߀G,hmF1d!HIx|ƑzË\J=ѿРX=Us5F^~ԵN)G dS4w)U?t&V޴blvxKC`Ԉs.7F*:VY@mK(KFA4Z 71.HSSU QJI1EPHOb;9҅~?ШKmp#{k0=NR{FMh~HqVrI?.;*_RR)eRxV.r1±3+aS6F;9[%uW֙A X<{'C}oqu}bK x9o̦I ʕg4UJ!OwTY>V'wUFW^h#w鰿(DşGlߨP>7L!U"14jGx)rEimS;HZ9Gd/p,Yן-ZJESsmD*{A#:r )V@~Bn{0ϡ"~&}Ȼ ;c#{ʇHK'uB/&\g2~Ad8wD|VvQ/#7;*H3`J|l؍qN E*V4GAi>4BZ<ۆeVv & UõQB?)lN%[s+KͰLʤMFxȧf2b`-vг"jFdN%Y\衐3}xqȩCڢjeeXp~c) W=H;}Se#Dz v351U76Oxz,mbwS@ڽSۼc[q(Es>酣=Ρ^tb!j6q洆8Ic#/%!&p(f}jgjYJ?>eETVǵB޾+js%LLx˸2#<U7:PʺQյLW}>r?Í V_iA; x=^FHAgSerkt1!P+wЀmaX%I`N&ǂ\Ĝelui=O3D-F0L!2fp*gek%N%VKW\4rS ' W 1h$Cfo=] )xNQdvZMٳeC) O.PNdEo+ SWQ2 rE>KN79+Ε䳱u@SqMv&-uA|;wQ/r7:OaH A$5"$fdd 2)g$4zK/\5.'MU4%ײP.8S6v臋}|raW5jN4BwL$#g+o֊|))tK sr#2M 8R  A)![]+&SH$#*,eHt@K< q޷ә.c =I̙@ 0iy@[1F-E@"gV;s1O>[¹`Y@=c~^XZ" yYc| }I+KPz3wb‚hmD9۫NiM"RRi+JLAa¥d@( bȊlmrI&1w?|"PT̈?XK}m92y;&"JPfj'ĪUU(,gQVS7E) 2Ң^9 ~#h-Yd#o2nDqgDDb9PkHx0#$wދ2^P`3ᐫw~}h*oWY%uDpaIj2H%Ag t׶63&3 RV)xl] 5:~{,Um0 mplqg[5yWwv 0'9و?ǣ@Vcxm7RmnfOaHcTP3uܐ> +2ן?79-[{ kٷ< !pl-$) P`I$uw^]rK76F|?Nn>) ժ_V,$ 4)[PF3fO\Gm`sooW[/%Y],!1t 9uDqew 1GWQr\0=Ư`*@pzuud@/iʒ'NQ%|i-~Q㷖ux8q_Hki {)f$ps DAYrM2?˃68F1_206zN,1Cgτ H0`-[@wK6 HG]&8z'Z0̭ؖ3CHqAD*Cɑe ԏ-C@2|F,0I7̱g !l#4xi!fcb[~sEdk0Ȑ^#?C͌B%sqncWTWQ5;[xt]jz@0WCǵo]VFi [ "1TN$|k02B, 3S; U m=*pvB*8+)#.`> OH6]c. '+Y!J-Z OQs0tޫ9|ٝuC2d.^7 <ؔ0tDX_-\nO+POۥ!~?m8[_bvB?'wnN0HwBqu 2>/ʈsyd)]e,].׫kBO.F"/ic,%nDN1Ԣy гm&.MSz =`i%+1~Ҕk; -rT(+}Ov_lmz'!oȠD`2yާ0v0˂^z']׺:}2<7 $yNA6)wd瞾KШA"/]5 m( eZst`o5Y+lmgALf BxH\Z m]d~Ix-ߧgiS2r@~4ɕd@/i8MX֔v2͢{UzJU3`;l5d$O( 8tiK惘0 !9|sᨚSABOGoܺ?wUՃ7KEUqg#[Vm=t1h i;|#L)7hyIP UU@G@b$ !y5RKX lp3`fIPP-bmaxY&CT -YF{D% $F.X*j ."& omZ%@qm^S'ÑS61'{C sX=_,jDct}[M/2_Kܭ$Y&ki aHXzE*BLXR7J#[Kxa, ,(HPZbr?1ކPf|ni VW1?.ׯAE"jnL0,bAuS=å_ 9 (e!l5&h#[.P}Ŏ+` g@E " gKèV+|rYv0*S-FG& ^ﳪr&,>^ 4D ]H83LM"תۊ`1]$(b=a&A9$_Qi=GBXlWgt"s y")#cʃbB,%.y z#'N^\}?@]݁_Ncal2Jܭzrf^(6iѦ`,t[KKCɣ5omkH~V-O5󗘋  *vk쌇! ܺ#vpu&9ki%E'*kp&"TM6٦ *V~C Iq=h# k"g?K9m\sfb>1h `{8| p|#Λ1/| d5z5cuC]~f@iWE ~;WKF] 4LSCkIN^ЁSqS-SslڛyvmZ@p%X rm0voz];_նSF7ԌUZ'ة!ĠZN$): &zn ə}Y3܊dz$9iekڿQ<?}1xܷK?c2N`!ug-h׿uQ_rgU TL7amOq8ZubكyA: vۓ'઄ٵ_pDM> mza+.GtݻHBϏ/;JJT@us'gKMRE Ro9]7njU+# yb; 3ņ?k V"aŨ>?4|[rR9sESs~=[8d}T퀊UIЌjg_2b0Ggk" S{搹4Ʌ΍uTSX8-AV˯!̞M"{.K5P|M - #}.sam `ͨ Eaf ySP.* 0bGA<\އ#~$b0pl5K` B&letâϗQ ;Qڲ \Zxߢ&œǓ/9Qt,cp4=%@jߍSf>gC9cuL_kʱQ1&|Gl&QQ @kyϖ!,'N̋ i`LbCg6ApvЌoy* "CW2L=ZBB5O ό5:YGцό]_%]+'j?g=SK *tUOW_>E_d+3O4.\d [ƘG'`.q0UDĹFdZrӌ/8We2t/ę}-ZӵyBejgޚ*rjty |hw`)°;,YJ;4gkƘ6ƐA9;fD yRgW0ѓi"C XyR-i>8Iz3Q#S)0/(> H[H2J aFׂ̨K%!%<D U+9:CTb`B44a Igis_qfއ((A$aU"x I劾>q皮rS҃u€Eʄ'22u$ ZSWF|jnH.Zg>"U;U2j p@`"ASKݼ43ZY?򔆫@" *tG.DW3H[Ue%!7 yOeOCx$k2 ]&^҆əh6Fm9)\w~\KX0@]H/j _ZAMr(go:Nkֵ#kw̋%-%4 D `;EP8)rm+9>0T;FMWm6а$MPJZrڝB+Ʊ>"2LB*\X&-I|,篂Iw*[ l_X\!&}Β< Cv3[K%Gqf/FODv`Iɻ-Ø~% bL/Oi=+iBYܤb  mVԃWxM@j1p&rCHS6 2H?xMxЊ``y*-yoܢb6gzxRig&zDNK~5B¿Cm4K+VHak1YuyTBH]'ukE U<`,c"ܵz$q-sXmP^7kzv(uEh t *Kt5]v:$y8N&!ojVK%Df``b"g],:GC2!]¶ީf`A+c4ӅIht]ʕ KKw hM#N~ح"<>DnG,C.VU}YK'ܸjdv7|u}_ǫtIUGwp _hTSí3NJKM\7T׆D[p|G;0$=Ѧ飰ݓj#bf(xEse#`Sו8.wF}}: )\G||Tp"PM G>v%c7C|`N1]wf˴&:µ0>+OP2 uF~=mRv\IƄ8߹K+1=r)ضt\~Gq9}:4 mU]s>I<1mH^eeCH4P=z3p<\T5{j3n6lA|Y3n5>l-^Yw!w>΀gBGs|+Fo|Km(HpfG07rorA̋p,sH5\׫#x E<9 Ta_һsCyhgq%bdTZ['UdJyN ZKg\],"I|\Ȟwm^"X[s)3*M\bT8r(f!&LKNx(}I8 -TԌmC̙c>$(ez\ "[VDŎ:d<[ſ}nwBǎ guoK*KG EwFEqJHutlM K]PFM ie77Qt;|8UP3pf[9] ngLP3WN x{StuV3d9$bSU2) ?M4V74E5f#ypQHEy2J6elԟ9@pZ7Q^\FIn8/~)V%&ș>Ec"%w*.Vi{2t(p_E54dQ,(zo/q@;^!+*qАEÕER݈̔,I7J~ze?=uJv-o`P{FgfMצQlN6sǸ%'ۅm)|.ASzY]T) @T/Q#<:38S`V$z&;o&O\ܚ}*ܽ!p|=籁^pK YБGGȘoVN45>"o )ee.Dxf[4i&eEy‹sxvi@E`2yk1% {5.aϚ-B65/$^s7!z(jxח ZhݍBR1F&8b6o=VE&ѥā%dţE3GE59RW;vC> IcU_쭞PPGUr83QbY0yk)CȘf1!ew{x$Ԉn?(! 9v檰Dy N̙z~ +퐙/TV+$wQB$I:tV}T#lEgTxO]1Yw8$_mpņs^oUOf \E)q{\J֛m=c-Iϝ'ءNDfϺ`IbAA;H<p'3WI{fd=5xi* wK4,s-Yj ,WrL$+fWYI}՚;D/&[xD/%IQoƙ7 JRׇIC~(=ݒ_7u#u9{~lӕX$aPo4QrY q**W= !Gj(m,S %rr`W[Tn^yC$Z<)C[wPycwMqNB\d6<1VaXzQD`PWq;15Y.&%l<#WG1n> mt7ݵvl7?-_GƝ }/!CyPbz0 fqs8"M%G/>0 q#mŚ_p= P$ƔQIA߳0k(88`L7+SbG78UfF3Ȥ~`tVS7Şu@M >7}n= x"И ,﷐:i,C|KӃGj>29刁Bz$4uk5rIjʩw]@E>4H;5$ƐͶ_]>cnt( ?/rM^ J^*xCkH` =X}$)?7rvT53S]xZQ̼\f7! 0Fb!OڗVmV:]y#i<+(]/N\x'%ؙ'$' ~ WLWH>,s=E/:|h[͟ Ml%Y Yak~UIOa3 8`aR>plt_9#(x[0rCESg9jH › E um/K>js3"Te%FauQ_ԫ}Z85bҿDz=7YYk2r/_"*rS/'1Cw`1F~ ^Bx4)6-wI &1mPTؿR\ϴBC6J7LQ*KGSb쥂KrKS'rM kGOsP߮!ܿ25 y,sUE3zG9 a٢faKmaWO1!D)@.5#974' L)Phh~C}&/.if f+dCz]l1{ `, /)\zNJ%p WeP ,.Q#6q##B =m,Sah6A=rȴ`:6.d'O *rRDunxi8Y *ej 8w ~#n]D_su5Qv~nl(>l7_۔,1겷΅g)Xgɯؚ KLNDb4#PDӖ2-EgHX h` At&lJ ,4vLnibp>QB:x踤ۖ6M ~MBs<@>f06w \{kKoTw+6[49 Vf0%iEmĝң~;)Yc7AlKElŢێH+yglʏhzљYYR-(7Xu:+@p|jie. kvLRAres95YcAWc3-sC"T)K2,:v+t[QDwtą\W0`FlU2IXܸ0Lڦd(P z_N=D(T Y#ċfwMV/7Heiq>q5+4vw)+.l]{&>8]"n4Lfo>W\k ̳N%dQ\jhzT,qH#ۘOn.,} (+ [(A] 'Dډ['>{)o E*uvA,xÐH(Ϸo)|݌KRpf_Z0_Z \6sR!lj=*j81cAxG]{1K *>(W:) XY s?_b|E1v#Sޔ=nŪG$DEQyk:Tm+wU#~J -%#Y=aeL"\Xŝ>`*a՛QIܛ>q:*@;Ȏ-"ȺK୆9qYU) pSjxYݸ5ZI;HT'/.,cϜA5LDƉFQ/7‘]GIbMv9In``5<3rlyecw#&$03y%P6g Xeqd)ΥN8gJ"8PU`-q5DKB8>kL_J(|n5Ys܁O"= U4eJ 3-:A)>kO\"ZzA b@Xs!6[?y\Xc!J{4[y[6qdzq_̂|"Vq`Jݵ50G~@JU5QҨ^rz]>7I&>}ݎ| OLo?/œLVh\}B/koQ8%=Am`?o"6Nđl1K|OgW2P=4;%x^7 'I5kl Ty"\Ɓ.!_CeU$q7*{.V7c>xZϐ98 ;LS~Yf̻&%UcV&ub\W7"]EǭiC\Ư[Z$Fze"ڳDF ݮx(y3hpan差TA64 FC%Ϥภ!fɟp#]ٺw˗p G gprsعH@_lG7hM`T1WW-n=l e"5e,5Be!mCs:>_ [Kwt8|ҝGhQ;KpCՄYI–}!݋ |_=:?ݪXlgFylo9 UdLKXi-ueU (iJWSqb`腿ݑ[֕~{Ds>cP5C.ҙUFw%oH9@lDDXh{[&()χ lUWCZWnaFpM jTe؈vh7UkjyV /ʓɘxXH&3$fw8h !Pj}pd(Csj#%{2#Q*r±M惗%### P_Td'HOnn=eTaϳ\ISϪ2#+%kiHͻCrTͲl!z bJ _A[o>IA~S6r 9o~)Tw) q_}ѓh=?, A~(4YuPFkrۗ@Tt(Te#fM /[$o?t17} ~a;opl8RĹq\Fڊ"`.E"៷8eK!wMLA*ʓ{t1UD,7Uşc\2pPY1h+Kpr9.{$4EI$C*ś6d&!(wÎ6+Noi#>/"LytXVīN*Sz>2HDZǀ1;k+\lůZP!m}'Gm0 =% /'I>65-.+YղTO mE-nBF TmӺcQɐ r[euwpQid@-sܼ)"j*ߜRỴ&n/0G`̙6'miH&ya$(7iĄy}F#N,ds:l;&rb.[);{U[,D4=*7f_z`O_>fU5Yn\\<4&,<9P^u;Tp8- 'SG=R(Lm} {n;="'$ ]T@#rhtt˽IDurs-JUR!.$*\b$IN3/ocgΜ <M,m$6~=Ǚ}F ?>@ lVAvdIZ<|K~Ya&jlHtH8\sn}'+؀)(UvU}ipP'e@dH͛U^Qnxި y<:oKƨ 9-! 1\ ɑSvtcQ]IHu#C>^B}umJ: XPw{9ѦY#q Ɵ]<4*Kº/2ÏٳջñFO_>-ca*(L)n50#2 3# .ѹ% *h+'CܸH")<?^eXK'np-(4bw$y T(بY$ش:? arx['yOA z.+Z Ӡ, =wh6J2M|Y~\֘撟[eà+V jF10YWN[n_o/Qj+ ˱nja.ƨl} O`ӷyk'͈2=M o/9i3!Ε^NY=hQɧ}m00ZvZCxVy+neMr|Ap3Ȩ:Ŷ>,양~{M?k#.yprqAx5mIO:dUmQgsȆ5or\IlT©:H l6`1I)ǫG#2+qnFvFtc~"yғGz:u"Q"܅]@ԍ*l%MYBX&њdAt!".OܴgDh14-8ft.a@T[zZ)_c*щŐꡐ4 /_GeZئ0>W¶$)!3EA[=ݓl [F(ҕlݙ[} ,BOT_zeDk-;g1fi>{IڟϷ`&# V̿*8>5zrDS\ Qt~˲GBUt"v2+m;I)N'KNn3A"EИX=}"(^ )oOEbdwuX$@ [zҗ_B7R}ar]We|cz>o'Ρ́%Ǘ 2HS!:>޵;g&A* Ub %B̺[HKݹo^JB*z 4OLc R=0+;^jO݌&6lB}jamA0Y望jk+WQ =7_HL}r!EK /YSJ2pMHNB˥R{TcTPв5qylhc\pE `F-jU0vKnߊz[Mw;Ov7@5>䠆t-5Cbw+">꼜-,~oM}yAv iH#W['{ZQc]fRy%'@9LS0}Šiﬥu-}|TӂP2mk 8AAyi ;MI"(:XL /*xQ45͝%vy~N!iW(_gtɯ"凞kа=w#>NC}ykYQ y :UJc .HD!>? K#h[d~؁TŎfdVoo3`}$z״ 7Dwdܘ9xA%`GA`JxƮ/hVbi3'ov;e^PS։gi'#tDX.let^:`U;ta1G(}X+柔Zui-~jld!Dt)]!SCu:4mfv(ZJ#"D6rǒwnfm@d JXoY~m& jC3g2Sqى\\?7M?:R0ML{[='?szs/JVafۧPimmpS %R!a\A:>{< ˷91k[?ZE8RTL(%"qr_iP`  U!O '1[[h[kZ$yc \X#Zm 6JWy ř`K(a]j;pNe{U.3`^ѹI.I=Y-c$ûVRӇ0L̓S{G%oyLq_нГFLl o5z#&f$Ƭ3%D8?$w~SjyY^6TҮyq=HF[4}0;BhVQ0Hbb\U` J5 0Pmʿ.[:Ûe}70~8 k?~kdӋ'48,ͼanmaE|M;[PErPn| 찤Hd[M&no23%Km'Rf@|*}la?w*@9v⮇jC* *qPDEW/8 PFve5DJ3-;i`TC24/EY69`2n1nբbhߞNvtW2IkN*-YMuk_ok5YkT<و4OⳊIoװ%/dHmokYLiS ]ɭ=E׸vlxQ;Nu_jRPW~kThJf0* Jih| +czΒM>^5>C\T&8%c}Һa%HCvKUa'2`QA/%b:ނ7 ) mG=1?OvE;EsDZVܶVʟޗ3)YL准43SUi깞~6g ZOtH<}7uY$rT32,C)iqK~-4>*wT1p -uZsyz~bi7#+tqpna+ அ:JfR%ޜKn*L| vk+M /0L7HtiSx*IЛs_ _.c)Dy'v]P|f}S8`eγ@AV J8 4@*T^matϿnAUIp 7F Sp$춳M{,OsA_lSòDYӔ(rլl>9ʴYݩ 8Hwn+Dj[y:yˋ U l>WKTT+Z]ne Fk,,c,Kq¢Gxn VKp.:(uH@@.RUeSD2,Xؼ`R`jw&8[Gl5 QKwAol[Upgz" yH@ǁx}`Hm-7=×xC6K ]*Ѯunc@ӓ2VnH>pD<$~ƲǕY׊K,EڍLMaW`}jͅGa'f\z'9CO5-T7ǚ؞rroLaYDgEn/w,er42hc9^y'Զk*4dj(_;# eH!e *~6%d,Fғi#c5|QCr<{-to9-}TD w@`w Aj)$A:{Avze LIfPޠT{UUP&g%I39hսC $RDQ̯GV33iEᯩTwј^'\T$S'?@Zpõk?yv֝n+b0~R"T3+NmA %XbE<A)=wۅ\I~-'h>LKzIsLf;CafI DswԲ/I6c[HrY~ =`E͞5x s&f|%;0eMmHI S( {U,9 YRa:^n):\"O:OEnpfn6#AJ>0>l1y~Hps+'i%>XԦf-S>HY #ccKb?7/ z|~P`9kk-OܷTwwGE6j1 Qъ<U|fL 5J!jsEN2"{xTH3 ojDð`/[t>0vu\< E6FX QӮhI?ԝÏ~i?-\R 2=:nkn]n$I:ʭGj5ƭVž%x{`Aid&Z8ه䂤T')iZm7Ϙ)A%hJ:>_Mt5̪ۅڰ%LK8 IECl}u|?_֮e/n5<!yyѸm#B}F- r]L?%?pgU݉gh_,jIfo0q1`B8Ee·hrR Dz4Pvyg!GիEy?.Р+!mvInH5|9z+Ԍ?MhS(^l ʡW1iC&;# =@H>]qWӕ%<9<;liC۾7*\8%]b.'.%?P?7ьs{иrdA{b]CVe#$|fkrgD; kT77}1&<B#&>I[t}l{WX&/WEN;0~kӣ:UPrÀ Z&rMF :,&!3P_͞-b"Ӑ޻1[A\eZvlk~BfѥxOIC 4ڈJ"= DpQQ_Qg~ ڣH?A(YA(XIoUϚNɝUa}` 96e=4 _aǂ f j 6beۈEn0YϏ8€C|pt.ГRuf&Ar0\lWx۱TtۋJPޕGgw Wʂ@CcD?r;= :FLW^Yir'Ы#I^:/=%%̥l#J&3!җmFgV -%#,Vx;lb6Z= &,0CMYpfmҰqB:*NȒCO>pg9L>%C{!#A\R;l^91$ӉVpK) B2[{x=cc1|;xw"jtnmao*W?Ef S.vA(dW.*\_{8,uϿK %g"=O*B6l-L/ӣ+23,_~FDLv &&W1x(2DzFgA|6USƟ}f,$@[fȕH.~Q92acc+%@a0(!: uӋiyRUХ5CQX'S!Z3]& s׫*(̘N[)kh'd7CN0ᥠz?X'j&%LfRK/w1dx9NDQ4[&EIF+$K!g7')U*XٝR{4Z]%Qkh7ﲳ%Azl8E R.-`{>4xꘓK&"b'+Ƞnq| .̧҄pi|YA7i2餶k sc.L:>|:Y5}6P-xb3 ?[IيzO ~83Y7B ,T{'֧l,m^g؆svjݺ߇<('#p Ϯ%zI%okՕI+E1M&{AF|&b1޵~E"iL qڙwS0;]n׍S*:lNT@z*PGd"n>pMX;#.jofO>Fg !J!Cup}uK -ØeksvGl tSKmtOp,͖V 5T˞'oLҨ MsElvFiOcG*Q?(5B d9u"0Gn azqyߊ0@~6 `즅At$kx/>[E;VS)ߋQei sdfQkXPOe6P ژd#cvt;~UM06V1OerNKFѬ"w'rgD{ן%`8rLl3 pŸ]u""57.:潬8{ )Lpli3n*w;١.9la-L^ tⓕj/;UETPd 32Q%<[dx,'rR@Ԩᙐ^4$RCʜCU(cnϤU+%IQ[xavR:ژ==͝]=v,Maݖ\Lsr0ffdhc*>  +',aT<padq4_ %NA`K}{]~YUпN¼u-;c﫽T\iӑނMJ-Z1 F<TWsp_T%bGxQ֪89D +_ȷyuq:$ |/=ςIA5E=}puݧcVR]հmS P,PY̐6}qu+QF1X%Bǭb,3k\&m 6!g&9䄽 $|b~-v{X5֝BCM1a(RgЂ@vVDu i_ ^Fx^3/E,`wh>Hӥ]Fe2n[Yy4W-s]Q` 6g'G9к!(Z}sQb Lk |ʢ'ə{Mx \8WRХpܝ-дMyb UT5/7oQ&2G٫'a=z.Āiib]*k+M}WT|#*YFOxJl3x~>wv})1%jzKz|7k72_(j2A(csm^KV;,iM?ymo88SFtA~O|?~|eɏooh>p9f"bLM6$zL+yJ9u'AYٴN0wDWkd 3~S#vjHL}68hQCTml֏k[TdT~=tpX-ƹGau-|?h؍y;ԇ4oꇊS,6 gԗs +D2lܵJ鐝RD4Vx$%{lvF ?]/YҺ,8g4.r׈~-K#];Ϫ5ž{8Q1M6)VQQhD-o^7 se]#!7 S`)r@1{e#4Ծ3_Z7?SN#~}(:?:C@C6$a9 oj/2= uEnhހWS/SMo:iQ(-~ћwlcVr~XY3 %!L(~μZyRO8;OA v62:~GLC}GՌI~p@qAJ~IhⰞkKXi8dQզ@iBqRp:q'8w=g~e5x(euAZN~r~&ZU7xZm̟bFS^@W,VP(^5g$BָK—QfP׼_0IY!&l!&f6Ɲuі䩒`2TyUoKh7뿨w@QDDNoJP(7 2~<:ȓHrTD}%R%hlWM 83֨HmB9"YQ4"7B,uj[L9. vHu=r6d3cVEwh^?)k(T|ZW+z^/-wGmZg݋Y.V8#e@[%|#Kn@3YN"Q$"eu<UwJ䚝dwj%T=ުPk\Rok&*Tz6)8oRbʝe`nnH qId6c:k`>Z_ͽ UMqjWp `H]V@Ͻk޶HUcXY*~ǜok#|q`nMLW^;@͜{Yܥqǐȵb.JrL5dRHρ=|&/ˈ ZI7)-7gH]W'*4YRY֦ߢ5qKȅw̤OMsFq<Ǎ̕OFdcsRil3Jc0Z;>,r-5Jc\|9IU" j4{#L4Q) W.I{V Ŋ6u±Hwh; &Nz*km;2_pҤ^N%}1iuMѨQ,ġUo71LW&'(X1V}-Jb̕$lHCnX{э (4MU4; >ьVDvI PDk_]eW? 33+GJ+a;뺰OݒI gSݿ7۷=7H=Uމ<ݷe4`>Ζ{kf=zs哾 jM]0QW_QI)ۧ_DH_ů,=[:|TßYv r=(wAt̻vñԷ1 e+Eё2㘦}ډtᲲK}|9Ƃ:qP=ՙ=} 6G0L\=RSI7!4'Fcú2>q}'&*l 굜caN *mrSW1^'.gMn5q_X䣀ɛN2s1>uåTyxBn]¤z +CSVFyה ݋X%NY)/iwoWn@5(5oxRO^Ƚ51@w2Q9s,2*Yi(/]TA*ac4>&ꕭ+v{|_/ `0]d&09)T+2.~R@IkL,u`eUX]]&Z]8kæo LBa'lec+&&dKD/;rb%#1.Ő*#!z: Qw<W'3Al^SwoJKh0f*{*_SYϊMӽ?]hʭI+[wP f᫊::S}_(n;C}.kn:SB}7wn趣g*vvON\PTS-v*`&}>]9qH`twz=b=`1en.ATğOqݞUa2vj4]X[+G%%"(p.%rέ֣q)#ob]LQf t%آc?q$/4J@&n&o NPzuӲfhE~4 ud_Cm `:$TC]`HLJSU8'䌋mssQ\9FTiwciUXGn5]%Q@Ӕk]0Ӟ]dpiY|Sd$[O!dk+͘]%w(JKDVjƳ#% to7PkjYUk%{;ƘVFSOSB~&G@‹gmђ@|E;x vlbJg$SBp]F~em$h0r a9wqHi Fp.2K1* P‡+O׍e ~o`IV &|#;@u=ї9fXRTqsw|u)^#T,=ҍ)|}VlI"[A d[|}}Rx|I ,xkhȡ"p6y jh =Ll$6;Ncqb[rpϣ2nd4Ogś<*?`^d|/T7"zЩdX+,%8K#H~1)L WJ": fB̑wH M\S)>~UB#UFw69Fǝ> 5(\|Z.[aofΒr_/Q^JCn͏=ۜHJcudE +*2 |DM%\V%k!US!FrVݴ(ޫ1{맃f,OU!Mm.ja;?/q5Hf gZcBx?5|i~Dn߀0ٙuHL[ZSȀ;7vR%+$!;;@W-?\ley-oz,pw?`q%bڕzJ~A}gG%J¿ofveK|6Up:/II/&bJPNNW[?G}>#.H5Kړ+w tJuՂe'0ۧ(vлClCbj X7@kaBC> G[uS'I@8_QXF תv< fQGbip1:s@P+ !׌;#`OVK]׋ 6nf2 ص`Wb '*Y^'P?P0i9U "]Z?6isl.f&U{(C'ZUý1%\Γ{9_D/wAB9$& [q<$B0w#ȱ_M:XE߂,=WO#.<@ozb$;{@8B?_j?_prgfBL{NwbI)-I\x~Pŀ 53oz*ֵDLq q'"j1\϶eDM8|vWk#2}QÃ],M1@/2NM 2,u_M2׷NJ2 ٵH=^=êA=; n8iz-p@5/jBk5]HɁ߾QД۱Xۮ/\k.cr=? TZmNk /iH6l|w@|,%?E%U%y E/ f,\+ ulwW!< >Dqem|* yK}wŞ),|{x{xC>fJͣQK+gHD|Scl Tb҅=NFmΔ>VyB=IFvt׎LH˵k[ CsL;dz]IuR]Nɶ]G]A\J+Z),V|MFkQ|bAsunnՍ,4 ^ahlMdΆޚԀTl31++K]oANC̞Ovˢi;Ϊz;+{߄։672,yf06g緵b/B k ]/dJ4<(1~RNfDT4RW6 ZLv0w;j]IGb{h@L !(V?VZK9uIߑdNg\Ba.<.'ͫ9wj] sBz><m \5.J &X%JSmQs[#V;̑$; \"P34uD4թ1roD΋_F/#=J=sJ*u7"kj ,:q2̊uj@As%D 2v] z>wGu7' Go5;>h{_ H_`HCnk}|$xlxj>lwDr^?fƐ3zȜRq^DtELW%='1F> @" =;ȑEỤg/rKÅ6Dq;؃!NԶIh[>K㚫WFVV G]J|]@lZ,[hM^)/v$|94,f%|1S`~cy^> NB/ H;:0LPs)S>%z6ZP ud1—SALj/[p0\z)c~=2;~OBTjMIefR(P+sLxarڕ$<^LdܸT rb(Q[08^ hN4t5apv-KmPa@\f"TB]Ø}6N!`B5K\[|6"l'~w.7 nHq箭뱦.q{'ERb*֛mXpO 7y` vwa4u~ EU:mŰWN"yf ܉Bů/E]ۍaJH3oWK঄;g&kRLRY]dR|VuRӶ1ii#P:2M 9ydwb~/O-L#$DIf{$ |j ͶJ:pvDkJ{a=="B*4SA VJ>$lө{]B~C2.!cX #F ;lG"1k:{s(oCO X5Öܑ yv ' 'dW1 H܂vҮWԘW+m̂m_(TŖc:]eBs.ԭ07MENVy7gWb;Y`dlRi{+pA)$sM{I,qUsE(z'0izz!'e _+ z@Ť<2y;H#wdH-泚Ϣuk-qcD< E ԗe񦡘>ԯ}/w1Xp|?&ja- aʧ4uVj5YK}f2Ń2>+]#GȐ~5sN<w3mMz~n됀C9Ji퐅x<`]+أޑ^Q\To |H[kjNvAwɐ(RrmRcrL'ގ)x̭f Cc姵y XY>A>`Wi=ftޢ1-E{qYGzy2PF,gu@Հm*H,X b8*:$/)I'*ћ #Դنߏ@9=(;]$>\]?p}[͸?{W ѯUN1Fn~eVmSV7r^:?#9#~H-,; b {wKA/b(!nƏH\,Ol8? 3$' XcKlm#wX nFSu4 Jm<s(hEhdumT;tD }5guRE͂e)xjP;M-p, 5mWue+Cy+"yVKq3Ւ C ' SCYO2IJ.P"TD"LܕP;uW4WiιeSc%lbB V65¬ CǴbmޥ#iddW;LYddP@k Eg^YU/gǓWjךcR׼DOCȰj`q Mm?R4U1Hn>lHcuϠ3e YR5 nFZ.+, ғ)PĤSHD$^c9(碨-ؚnw!h4Arj9^ Wc/%?(UƁjV}W[‰X태hlc]SʜJh󐡐ə+fniw -BSg@yQX`z9>UMWJU M g7cK~蒤=ɍg`#2(-cSSh5֕ #*E`i-hg[ ii뷳j)VTq; kJ]8JӏGA5hhۀ (}/QN qW["/Y]ힱeNݙ8fԫ}me>F[yҢhZt-[QBCXӔ(u?jiqҼt 'l+w o^9߫؀RPںC"qT Rzu'tm)ãCT,lTo  :ÐG:O상˶l [K5pm/+WJ+.Dg= `!ZCu3 "(ň~7W!Ces;h]$Kc)[iQֵub/j5 a;&- ʂٝ>8KcF%FߙXQeER ׁtj`V=AzTN5}jL 9h|Q +W'%q3[%sUP',Gɫy[:!>?sR  TT!0> &>(YϔP\4#{jf`0*nd,zTvGT~U֤LtFM]I ?v`$nZRܑ'zjmVҷS0U@S0n$bx)lCkPRtO&}![6g8KMo.gݐU&Du}Iy59IVX~0b$:pI8c>g>9"#1Xj.Xٷ*rӺ6`CE%;{۽2h9s"&bZ_ 4y!U,^{--z6nG2["0}XUT$l_8/Vl66ÓS JK0VV499w-Je f[f=7}(;R?d8Ιh}.'=5ϹdA~%,;LxfY(8J.,l:."PA vi>@(!i,MY*}!{?^Yeӡj{џN=UMmzv/"(}bNێ=Bns M]`uqmtm=5gp% .XF*?-aKps*^ŶTݺ8ܷ;AAIT0plЌ/ "H4tA(ߠ?Fb1ۧE!턼Jrϳi60N IEc5]e͹,,a*/ qQdl z5}0ZKM RGI&( QdWѮ[b%rq?-OИQѾ`!$۸$ *lul@{Kn/)-uiX絡>jѶ>caK8J'K%"Y$^"7킪u v"=s\Vg~( 3Ȓ]-m=z~ք}-20$ Z︸dhԅ!IFP"LXԔ>S8t3b7p.yuĞk`i=ndbhjZu*K!Ea{ib5ݒQݜF.)E@XwK{yA 5 d N; { KjD;9ɢM:|zO ьvyA5C91RKGY:ʔ9X̔(7n䵹]|d*jaA/'3ddGDht Z6-F.J flReaj5G.hz-LeDFGϨ-haxY<=* I|gٟ$/$d3ݳ?^>kW#`XROfg{cdZERrCe\2َ`YbcZym= =UmJ"tWw;%%4 7ݲ'?)}>5gM Bȩd9s{a5t216 P/&"Lzy$502nM2&ky p"u S'$!vyxUޭLϡWל=<-NV6ZAZ]F&95sOvGFDWbThKh*$@d>;N`l,ÈXpa HF͌ֈzLCN\Q2AmQ׃pK/7'&Z(U՛E/ɵLsLG%B.U޹]`Ɍ^vW&%e"%3EYwwY=E0vQ+LH|fD;t6Cb.ȘꆦCҘ"m*gCܕzKPdeYq)14Oވb6UB#JjksAU n/=F`Ec*FWߘ@VJ[z TDS͢Jf\pYdD|TgP&6H {g4d{]N559%4Ml G E@ AZE? с`xcaN`Zp_3'fM9`zT|7T'U9֛ ҁX2S6-sR4]kX{-K [q=CO6ܭQȸˆ5D46H$صjL6bFLazl|aNݔu_1gSvgԑg^dH}ap`uv?PKj=ZUXAHs(GD/,d mv]X.#22n51;?{k@1u)iqdRJ_Fd@^߹iYɼ+ qCq;|8oFN Yʌ.ǒk,~aƂҏN?z1уV hR6q*2*uŊ^\J = -a&IMT IhUC-sx,l}7 -gK $ŃJ鋍jTYҸ!+X?FK(! \(DYx{$(2?žGI.ɋ~Pb ϾTlն0:yuǗ7 sB`\ NO2+fH8rm [KFPUxLa&;HԿ,@T+ò [N< '1d=su?W pE ,%&C{VS&qT1ԤTs̲jIB.f*@%v&]:q j/Y|M| wּ{}%K= δ!F}W#ˇ4&eb/IQ]ųO[X^kt\b(ˁKt "sxlh닔 6tXnѪbG ^SW&9nIO-ۆfU/bض7t7Y֕>LM\S" ޻N,e,ҝ'H6[)P;u-#J=JRY3RJB@2%A`?*q'0o³s>1MDfkYrF}V7fJP %R.Yq7ktFmO)꟡ZDsWj_*z0.B߇%*5t?~[՝LQZV &:&/uNg)Sp]$' :ÒlMmݺy_h >9F$x:6ܗU&{e{9Rw"tjiAiu`S* ̗DxBK) + J&]#0cS[ز00r|sbW)VVpIk6n(ŏ3Q.S&~S#w}(4!>`GY /7=?ܫKWUmUx!To%F+8/z "ȱD?zi=k}sm*'ySk˹ēbC`5xMi=[J ʹRn["c` ^ NJnWy Ȗ$pu2BLjs*C䌇Mh g.yUmk4"(2!I,}/H}hm lr)NR{kwkU:j t2J#Mg-Z_+k0cf%y ݛ'ZeM L[fUrKXFÇGΫAuLn36ܪ@|VFD1*4u2 y[(nu\ptHeO]9״g{FB.읩/ï¼s_B^EpO>Ԥ֭P%zV|sim\Sh"<KNO bR5iH `վ/&1b{dSFA?}!c a%B;7ݒ0JZhgzG@EqP05pmT uk*sCx>nB` hjɣnM%+MlO&u5R]C/"1EL@Qas ++-&Zϱ7ڗZ):T쏴dh-(VO;]V~̩ I1NqNItQX&'8\=k߾P/e!=3-6}IGrhUt(h9LCP->nv{J_3 Ne@Zz.+uAXR'9^ Sǟ̚HM`dh4>C,F_"TnV2H!35/[j(VjB(-iN03zLRBt` ?5 JG5e F&+t+>_'SYI Tغ9ċ877hJ>yeQ~,d,a=?4Ѥ)O$ uujųY\!ve[?JCӮ]{鏾3YJM娔,2TٟZ <=j@t|UJ6t:6@LgG@]I';,@j)^gS)'+2;*e VYݡۛeAP2<26I_U7ZljlOr@{d)ꉮv&'JRn/cjs.`].Y~pURӖxb7WmVykOdF%bqZGg{z8.fa6 OSC F{ٯ ʃz;boBq"&p H<ǀLkDm>F3u-RBx&#݀ME֮pݗ=OW~ŚuчvnY"1:<2lڨTWIGoN&%i긠H8vSMlP?7V4SNm^6J'ne?ބl=1a~O4vȰpH~y8 } Sy6<VOh0|.p RN FUOS&<3 HW*n,LɭFw)x. "vo'\>J Qty.9W(nSe]F^gLٍ fKebԄN .s P9 4UW=ܘAsF3%܋\к_=)ATi]2)Es ļ]h=sK7!H8mL?=xjkp5)JX]!"!"`\z$*tn+LƼ6f0M gOC`0̕ÍZ~ut^4ӋW&0:+% 2F"í8l }kBI{&Ž@K^"|1%J:;zLm2k }?%wG@D 0, }TFՏuΙih<%M2k-o{ѷSX=Aܶ5AK&ޒL{ޝ +s<%>tst,tDRQC, }N֓5=~ƙc]r)GK m:yE*\.x<sa|jGgkC؉G ]d4IV0CfdIo_W ԣTT˳h>d,HhqA* P>sW*vI3I y7V`$sC:TNKu[=ق^џdt6@~ zQ{E-֊B"3XQlQZB0ړM׃6~evxepdhk,Q zH6a z"u˪WW|FK>"TetוqHS<;e?k7}я*0+4tO4BGlv|bDӼbطD6嶺!| Muy=UPKVW>v. $u/䰺RM@䰦LvU"^+k]] a1ڐ }x٦Y$V@D2>ٸv17Gi('dHCK!eANhhvX䕵2תpLć}_g >_Kf5PܗYrޑ7ȅ8WNFivIPL_zy*ZNk,>`*=0vG(f:yu\}Yv̍ 7prȡG;Kg̍Bᆲ.jR0pohAyϴ@r5ЦIĿE:9`Um(šܑGX}h~S!) ۟L`nYwj7XzLVd}4y"DR{@<]N4 k 8& "Ѱw(1oئ;l|&<e.L9dW?\IЏnA !o/{W&~ [=<ݤ}YG@}9Psw噭3z'm (sL q-,|SbnRȶ&Q<;AyY`5Xk ħyX-͊jQPÌ+u1u Ih&+B~]b`/Ί7gBrzr5>UX2"@&2}w$EcH>a"fjbq/tI ^6Nd^B[ERԞ Y:κg33_uwt$ QB+A榯_ kȀ Yil H:>dźf=cѱq(ۏ<]-NsIN@㼂艀&kMf=qDՊanWDܩKJ\I!~y  VLt Wj:xWn|h!2-:O8Ik+vVk"%'nNWczoث:[kWL|*sCܦSk/E-g-vjQDFS9LHZ9ݸUus /RFvXv=[>4AjZ `.G lYݞ@=D[] !6 &`եj(Bš.NFZhp? L'0"(K` Zюw|M<%exGSxQ4۾%=7IJ,@"58H6BǰԏB\No7&9$l12TC)̥;ьHs*<`̹yMC7&Gձ .iĚ/gӺ^pRCqH{)R7FsF1?bJQWiDQ~.MoU*F8ڍ&pzhE-r'%Oq+֣Xt֡cbDJRgIq|q' l=07兑.Kec?f*ƫQkw#)}\9#zR)bH嬡 &FtsbnleW!ߧ) -t?뽀N))h5E# *b6~ ñ绗j2k=YK4CO~ΐYyE:?Q rK `D}ӡ-T vnڡq8'\z=Cfv\ƣJZ76Kd%-q~̿/SkGFK\\"sZPE+wS+@*.:L;q:WbwH!PPWXW>8&A*:F9i&%>4Qng$D$dg6ע>v, m0EU3{YQrkdSH~9J`Rb@]75b4ޭ0KvrU{逶V{L?}4XM%9,~a?f@N(E8Jܘ0ā<=D-‘F#7aωo8U$*Äx!8Q5[?H.g e ZW n@]B}]aRE-y/AF'0 }aJ G(͹B51\O kAMTVDd C9Guc1$CAOM2 N}YFn":`E66YV|Х/l>D5i͇ ϟq JTnw5D?_9N<"|7T8 ^bλu| oLAssm?aN7T{3د!s7X]fyܝfxSr`StsH?uwaQ2Rs"d\l'23e%&ȋ"Mö-oU9I`1MvUsgEP3[M=y&<@ͲFO>τ+m=R l@5ꅥ[mRu/Ė$+r-Tyo ky'L6! x{*+=iQo] L27G zx،D4 jcv|IzFØݭэ?6M| {SM"[DOCD`j6[mNÁp;okϬJW#nmؒޕhx~ bi."fu jvH}35}Q.N-?[xC,u_c bnbFxW+:q` ]Y39I"6 R )8"q_kVA1oͰr5&nLw˻Et88Xv\' -X *nLӎ!Zج!ݨ! 2"gVqpc>wh9IY&KnZɘ^)u ޮu/hlvX]/uE/KYG|H+ >Ͷ VqnI>`cC6aZֿ7qߺ:bxEAi(aIFX`~UD~8*G3V"cbreS )"FR[/]I]fu( LBzvA;8waJj98:(lW8qU^OG*?]i+ס]@ŋ٪ :"ׯ1Ma #v,{/ e 0=#cv}RN9* UU/7:,xϼ4`Gnſo>845R'jn_P`)}ۣe%Jb$NJhw*MS K|C7~UEr_M8a<,(OГdD-+ op~>D/VǪR@m|i*#~e%sE Lpn &".qy=(>RQ}䟘я 85g2b~ău*ܳ᲏6HG>%GI.=(֙]ahՐ9X|?+=4zE@9@Q 3n \=ڞGUԫp"JW/|yB4NIltV*O (H? L|x%5h&x|U lu~:ZH+|:WԚ)@bC:†\q:rhsvo=_p{RaUvvD;`@QSFqőO9vQު/A@qtƢ08<2n:_DM'0l Dr=[j+l@6ٶ༏tOG[B"BRx뷖Ԭm-of`rMB{xjp{|A5HFn@R_4t[9\s IEUNǒY5Q,yus=d'5o{h_s6('܊=̦EώJA0|,,ܜƗPw;ê]#ZL~:џ %F>;tʷ Qk*a>y}ix55 >$W,{f+m\~(sp,'Ц7A 09,?R!&L—E>6^v4&caP7}9M" N Vn]GR&|L.zŻZOxKc~kb8|9eg|ѓDMG!^n8ҩyUU5~1'| N)Uh-U}k7"kkFC&4bmXk[ :P@aQ.xڽN }t;/UUٴ/P!N EA9N=Ms`Nd 0esG̮ XX\{Ynf!Zp'qlnq#r;g[=ÖiJQ J$?_'!M!emW 911~[d>3A2ސ1p5S q"Z?4Qƃf ըririY-_y\N8 5aWYq{\ZĮDRHBmtR1φ3] 37%f*Aٸ6zܣ!Z"rbĪ1Q)u( nC#1M(ǫk χsOƗ?UcUȤp)f9'[܏@8ɯ2d* ?l ]=N`oxwr@ t]3yZwA>cY %K -h2֗s0(5τz(Eewf7SpSݰ)#)o2,tm5?y }bҒ9L٘+Ɉ9/vqXl5+,lנӘq1M`_Bp ȡk54]Dv_fT`Ӫ͔-}hs3ȸ;E>z= (L_yE 8 W38|ipL;Fζ!">¨b" SjzSxtuF9[>Gn r6Th $07tmC{/o%( #^.)rIyb K了#! ӶlE,ԟk!ؼtˏޛ0"# [gAh> Mx 97۞)qvX ʯ ΨN/tF M0_b%m9] z6_dR 6%8s57͙b-jY_=! ,YݴH#TR&ԗmkʸ5<[:b~zƱdKX&HlºFb96Hޣ(9.vŘ;2N%=?P@2ݜGi]1|()9e^пp%8 TG,paoDPԠ 0|Qs673'I"Zz:Fp9\=*.qyC3&X(uؚSbF#Śx'*SQ~IJoqu: m 9bֈO#gtԸ EXĒ[P]mD&Yrԟe<#_FOY(7*6$F (:è/ >Vx\FRԦT^ ZҢpSj=ȐhB{\^喌U|qq¤ عr%9GK6C KRk{ǩMCu;ƪJP/)x{%@Ώ=9mjo"4!t: >=[ WɎp?1@h"gmuCC`~PiXQ)8v>BU2X8?/']$=\𒍐* 5Xhd:C#Mh.6LcU@wU&:ޛԊ܍j֗?/PDLl o_Sfz $sf[Kar4A2Fl5XPf)SWB JP3-|d g8ztP^/PMdmB,Ϻk$)ki$j &d"B)L^KF(ZJ*9Av52 xF3Ay$cm`VoW'bwdz(;mXf4=#E u!zgorD]Xrxo">bk-Sw|Ʉ4Lӳ@O^<Qi # TvAr bvGs$س*ʘ)o+ +)RB" 1 KZ|q+щ 63kAS\1/ *Zėt|jyIU#:M~fc.wNNSdrEssppHCJdgۀ Vcr+zQwTTe#g֜I!6r ~GPk'y6;&Ciކ2Q.pELHǡS6\+v +oӒg3GzR;Ii0gSPz_m qHEn?p,j TZAk:p r|z;?L@i/OشvK=NV(sM,5m\$N#܄ʶAg'j1.: +U[~@#g %'g~'.#ۈnHX nx۴.N{/K^1 DDpҿkX_tB[b88XQ0yLG;.Z( c 6DXgTxY L/ygb4vNTeVP- ^?MkQfm\]cOլM$6ioŽX&RvtdJn4$~`ԧnΆ%DV]FU h J#r 5RW}I0t]4UrI{,Refә{Q6y~p:2aDGRL4-g!Aձy[Q2h zlAf{(iEU#lgo|;&TߪXNI k? ;Ke;Ԥd7PLN;e\Ҟޖ˙G!2NB`4*&" h7c)dͯfug>0V>5y걪??By\3˪9g&739Nެ% d)NR 8L};ID[fA \RHvҼW .ybt-|P $)ѪB7_!"G&'zO9ļvH e^œֿ%D6:p ᧗ 9,osύFqzճ7]w,94S wVDZ"wL)ZK=0kjVu(=1L$MjA?8,MaFxQZa'# h!DLFc}iW\fqiS 8Q3z+.DX[3?( ΄!Ŋ"Oo4\4&N(=L0gҋV_vKW2ʶaVѵSPP1Hq,WH܏/A҆!j5ޓ b߫5!ޞ_D.'sKaq nXrml:h]CJr7إ,skv@}̷9ѭ,{D\5fp,~H\qcIt%nI`Z-s 4GG,Yػ+l )SP^& A N|bj(߄ I LIe(fSUJ͗kJ_?z>{+TbJ"4uYdn 8҉;&="}h+W:7AWQƖE׃~'ѮQX*T ȤjML-3o@?ABmJ0U9MZ)u;Us êul? $"jc2@sa?%H\Z9ND$C!ϬŜ#8;.WV* ؑ+fGl u=NV9 } ) ; xm3_@&Uh)MH-?:/G#d ]WH.K,IVMpD-}[af&ﯰ4PpK3"嚲V'승x&hiI=&*3$&Ћ&mڪu|!? `dƉ!Y-_%_(""@Ηup`b-":"q͡$&]H6ܗO[7H$]ǦB4J,'(T5ƁGr ]+zn@2[EBfN34Y=LDɱdӯ Q cKk'As5Q6gBq&XAwe;0'7 on]IH$cGƂMoXwdRObTIO mt$e0A8Z|ͪrLoD``ڃh f-kD)) 4ڱ8X|`k.$Q461@*8tZ@̇i<Z$WXIFQ|^oǚ9׌o! ch= 78eAB>5oysaJLŴ܏,[QF*U,8YX_.msU`艐*s\xҠ\ Zw~r \w}Ȁ̋ u9#KC@ίl1|&*+[wM%"V ԰FKNט_:(Cp Y7Y3BnmX,xV;{aFό\ADBƊ5RpaFΪ F) p)9 g/G*7&Ӻlh'T%BbƕYig׭b!gn@@:|اH{~zѧ?ْw(1ʊdD4(ɉ(j@92N {DJ ͪVZxrԈt{j5 őyQcqγqWBiU6FkqN'UfEx-=G܎#%b{oaFJIR܉mn߉PCvޝEL[*rndXVs#{?Zh8*ltgϱpÿдiKHGbx95`eHP||_d(E9au=uw8TtB㹔,yw0z$JXo>rnҐǛ<2VG0rWҶVb/^ƧI#xԙk(h VRs)CiXe*sE@ [.C9aZG[B{s;05 0ޣk5qlk eږ+KœFԜN$YZt(U|]oz<[o$2lsIU ao{JAG*"{$!_)7ж5\ e˛@&pBN>gAiXdG$& E2Ar/t$lV #?}x(QHG'%p)#>ϙ  _@EѼu omZ_@v󯼒Mx֥ߣ7ᢗaXoE>R[?Oy>>n|'Dw;9i#M]IHM-P Jϲdc3vo׸s23GC1mǤ']m@spBORGh!$UtT$ h74rT*^CCS9L2 W^_.۔"TχP4P m'.i\74+Z"y)_%f=?";ӨØ62n-2|&C׬ktaxL0O¥EK$:8?׻ZRն}Zn]i)&l@iY~Q*0$[8%r SCѭs8ȉm/JR9:@3T?23ȿ#X, qm8/mWd(hHQ=GBI ܲ< i)-#O,IaB_~ 7jSO˻$ Ρ+gdIYS_ZǣD6Yvu. K\pa]ʊ埲jgLEaĚ1j,yՍk"&e~ۘ-Uz;QLdJLw]6<ݸ>'󅱆hw$lիc}*@IrVrJqJ/pĪkH\P8x e,$q6864b2oކӞ8ٷrl }fxoL:PSai&>1~ɋ6vOBSGRj+Νeg;w@yWdk}VṴnfsEioĕĜ =$!$ MONQa ;M2+^7;[sQ@5[C|9_{%Z9=n=[(ӇzT<Q(GYI,bY.nwx1`'nǚ|X# V^Ke\pyb`Z Z-*Kl_b0NHЌ޾X|裏Fuk@B6XSv=|UczFc{vo Ҙ_Ho*pG(JVE8nKza.BD1(Kwewz#eRɓ#ilfxMs5E j_sK@V ɚ׶3~bӀv}g0{3ې=Kw=/G_m\NSlՒ|s[ʑ8ٻH*w_=8y_ʰJ~X'BC|]9T׌A ӍH~IU=ܙ8_14|~"ȝz~&WwOx +GDR՛^S? #=N5-ȴtdJePhxBۘ%^0g ;de mEӈІ Jnߚ`oU<(Mkǻ=: =mǪv)f_!̑)1l~e=dW6%]SoIsth|mL9^ڄczKA~4JKFYX)wWQ\mX]Kp#Sȅ[ ZۻU55X l! ܾ9KUw3+j!DN{u۵\OSz=S=JΙ&.;ft<"TCVCV R=.&C6JZc7v#YhY!.w6 # nNU>X>L,W7M㏬~W+2, ]҄Z1= !ޮ?`pSSIghH[H92ޕYbde ۏ3AGu慝 **7 ş(DHnqBaքėnk78@EdptYbڕDn--bWs AOclTM"Is KQv9.L3-Lb ["-; :Ewz3$K/M0v 4J2Fn<~CDI;@H@sOp6%R<VU  e{N鬈azC]:d饭OEKˀ }T9:̅~'3(;n*\+Bz7JV)ixPAYKBDMNj8~Qū(<>[hy\Y{ aeD$S?2t-yueo N6TwjgnMwKJP4K z+fՎ4)>L`$DpZBΙ>A5uhW;Smm!DwG;pLcI uEbw zL~W,W8+%L~]50 ;`1qˁ)Nk ;6֒& >4^K9c'$ΆlKdЉSjM$w Lsd6H/SUlN–|&̖q3|GEBCaOS.<q7-"J3|$! eYYs^hd0-̵N&#-$fB%#)%kE;;3(GT+&Ƭ^LǍ[ǵU|Eeh]&AB2Ne.> E2Б@ ZDɁN\>4G#.N;e Pߵ(:WP}1 m(* ʔ45OON4:~#pSP_%. 8znO;I\jx¢*˞&(aCטz(Q>A%Z"jLh@Iű=.ʒn@갺e;@Gb ]_Xxº޸\?/3|?H ㉣ 0bgܑBҜ+=mY]l +k( /);pn*Ò'3YGLPL(BͰ-1M*SG/*ZqIԆYwƾ kMd2G2oJ1q ?&>U,+wop󮆣mJ$OD>fЍAX•vqxT1{?~{S$?#3uG|[ȋrt6ee+a:r^& S!,Pg2axbvSN5fX1 u0KRs gO℟Ìj,xA놁$Z3_E\|/[I*@U<ԥIŴEY凋wuy(>82~%PoUќHrƫ6!zc.~`p@?U-c1``ײ}jT#0H5 ^w( 5$˝ݭyHP:.\^LE>8?S݂8xZ y֭]Ld⇊9N.3?;G#,D % LI`.'%}+xk䲗SVP/4;g^Sͽ&LٶR7JeJf28M" Z MƛS CqLyH;͢8Đ&qöۓҧ2m d:) T~Sh`q VLL3J%=z1zR23nZ N_q4,ao[&oU7Q39 c\tR䚷8zܳv "(t]%\ұΐ R-tl`GYaˢ7\%oZ=6@%dI5Up9HV39*MKa ccMqfuC j,C+HЙ.[L| D)՝OrZl)LT'Kܻ:~'J\+//D ;"QKk Ex%u`{$̮RF,ɦ&fU C(P=ZV yO7^6i>s%?~P)@tOcB?frM:;/&s_% z7+{d\;N OOcht%!َw| IYxvZ5W:YRq*fIVWhAdTZCvZjP'xaF =`n(rԃv^_?<(n28YY?j62]N"6B >HVyj4dXj3Vm/n@^<W.κ]d8<2#rH{!P0G9-O N*@I{[fc+W+)!ZɨҾ6[ kn.SGU\@$N>K,Z8"4MG׭*̚3'bzq=C̏ʙLD0\v/=#-uR0A|.{'cNZg5+}OWi^jEl.+'O`6F;k;)H$'Jp7{cӾ뒀9w`F~# ˩2ټ_(Q7 ` ~NK莅rqOuȉV cDE/Iɠ} (7zG( l!0*a Ҩ@I !鑲"l)Ďi: s)&҉ %'xBj!*&3$C [)G$ Lʻ<Xml:q~Gad[ oWI Z ]t&ݔ@gO)T]=D!<٤dFi`1ߕ> >6?Z4]!+=rzKRwNҼ¿wvuvOa vJt;Jp6VvBQeo#&F>PB@dn䓔4c[3rvdiU?WԭͳVl˱3$qj;UBw $;>~uuj-Bl̩:mp0ʚ,=~ @lq b oJ B!`pJUӆP LKeGHP'.t\YYe]Z"Mkf6W@J JŖ~?1{+(אxvY؅ݻMVڨ~Lv8'R=lc1O[\⅁Y#vpK'ٰ3R*os =4?.vy5sH8Tp'; b잗'NV1qk,kur)ӟW0m% 'V˷ζ(7O5-ϵä$?tހ :#ph0 !O>JҴ>N~޹n%~M,nDT\>U-wɊ|.zD 9Ժa&)Zc) +(8UvTҭ:kshkVu4hR={WZ\Jqjpi/WOIZF(N6T_Q ۄYA ֱ47e&=׿/KtjFFRLkV!AAJo'8}*zߦ6j11F~pT>Ўz"Nnǽ*]pKxܮpةnX}nÞᨩ.uz)$x>(/] g%Bb!XGNmMJN݈,;ɀu@-i]h:;.b.cb/C}DhzLUAC3dv"0H\B啫f"͑-ūjScmkC_ e*'/ e3]pk7yb¨I ۂω]dͨ칁w᧴)"xޟad&{+t^."Ejd w7F:fΔ&[4B&+f?1f8$T+!x-gkxUn_Yf a)*7ߝe5~b / ą,*[Rsg|(h8)x[ hxyux4"" n7a'O< zp7 L6o`+q $)q T,lLHs)qsY\jC(죇&\JQˣ3or:ʰ+]Ť&qE-m  :VI˓A :(tQ0>=I2|?LwTQszC1MVqK p@б{C  uVp t(E]WXH*L )I[M dլ(sR MƲʴYA)[Q.;FKӇyV?kT0>=ys&ZZw=^>K9N_^-CT`j⟒4>{3e\,K1K}6˝p8R}w{n.rRr\p9>xf7H%KIb^ކFCaYlۀ̎O^fQXbY_Dj[L㭒\7N[m^A0;L4T[x4#: :0t, ӳqL#<[d8B)ٲ}{X(><\BGEG:{1Ï7|ob2ŒtO(eSͶ#E+#0۱.qEOܫl.$Mw Ԝ<J}M2Yk;$J 6Ps3_x!@r,A.&ēaO ~9);8}SP(;ě+U~Pv5bӳkfI?g y{Z=dQɀ)mQdzӀ~ѢvU([4ߝE{ɟ} Z.DX ֺ9|JO>G.]03T׉ ×/ڜVx{beūLEW#<˅Ȩ̢ڒ!TCߜ.w@P‚18{](~8p@+eĜ]JIμ^-6<u hСYذ#9mh3eKc..nÜb+{T'-W6Y +gg' Dy(s h={6d>? Y3_Sym,*!- ѩ?$qzwvHX*if9̷f$ZGۤ O?p-,Qx~uV:U B~;Qg-R=2B:%n172gKGq5X!4E[W(4<[[=9? ,3~@>?;^Y t7%ՖDAhly}8h2/x\鯫oҶٸ.;n_[$XO^Ƶwvzs)'V:|FI_}4 H, ,2 n&[g+ {> Z.vLIMbhhtRT-t#/ c.œP<N95&F{MU`@Μ܂Xn##d;::P^7k K/i  pYU.F4{1 S7| 3PbgT mrcP/^0ꐽ۽m71z$YPBY$HiiGI|@;OOp(%ҙSј :AUZ]|Aw.߉ndgŘ&Һ CЈ!B+:n+$yN TjY?,/;N-q;2LuI_;%CsG.hԹ]86}3eU*Ҹ&P/vmpCW^$K ƈw27;ǣ.D_?Vp}sʔ\ +3RmP0 9~ RSSsj.A?;[xI!KϽJܩfBh= @h&18cѨjwk0y@I!bEG`~#^f!ʨJE-gu~+Ntq6fz%>@Ɨ--KK65yQBVq7i"a}Vl}"!Y< UL-@.{|2SnE63YMRR+`,Es|~p&t~L[?/ ԙ('MpsI'B|yk^RϏ[.wŻ(QWuDYzkoȉs7.ױW!F",]JJX[GPeHhb1Ff4'D်(mz,_0SjS%e%2:6.)so&kr aG^TBM||Uo 0P[)\]^XspL*Dtz7P2.˅ ?A[F *XC2p%o!ժ{)b|KLB3r rN6)30[ִNo7by"0t[W ;d1RNTYrpojڧ`i Pq0Hx1zߨQ9b Ѡ֋5OyFQ11C(:ݵJʚv ٽ.D!MՈv2:r6xR*V(}LivkZ*JrKt'PVӝ*լbk2M Ջ(d.q 7ڙT9,LO]sqauH4/:PI&0)::)C1s_gQӡ(_Ur={NY s) .b9{"+9Pؙ! r) ?1QUJ8JkdziyK""P0qe9MaI/V gb?FchTqjas27d\*cbiޥl-~俙O w<URB/ 7nL\K #eKQbk>hQ`׬EVYS6_`uX}\rKuEgg감t#h~4kuNX"ף00&.L>]ބS9o`@pƪ4~Q+s\l6ޞ}^E&Giu\Cs|\Nw ;ѫupI).9SX5YtJ%#3j78//n)4v(eb$zP^4>bpC!3)Wݠ) HnYM&yhNMf y3d*1Cv7 M BHw4"e8q]rfK 0bM=܀8z\E{u˪!MIýz F{/3Ny;ޥ<p# _OD QR 8T_JDbJ0MYp. '(ث&:1;㕀s> jyKg\RӪpy#5 i?2ʳڥΌn6\Ct xݲ8/ Cf3]_ЬCS(MfJA.-ZC3`RB_CKhծK!כb$jȺdzʣ@М1.<Ւ5nOym0HYr{;lI#k!Ocvޡߨ!x!qڀ>Ce=Cpԟ}w\E~e^f-#:'D6ֹ$]HAOgGC{?)F䶱)"?QMl XϯXYC nOVB}K3:` 7S3e^ Mܝ?h>_hDM(g `^.C1(8X+x{T~Ue='*k'KtuĀh&?sժl[LVהcwyВpBlDwz@E(;~FhaF_m{wvcvWPm D5~}MUS|6|nܰW7 iPG @(ɘ(>X.HMV˨%=Qrk6n90W RN%fo[s}5Ӟ~}_x]*e5l f5dQ,ĘX.dhu #v$%Lޕ˓uCē[ñ-b{; ɖ#Y˨JdPfo 7еQ6 Srzx絑hWO7ОoE@ ujk/ė80̕\ (B2j)M,o;(m"?>Xfipy2&t'g w(GRvV-z. *T7hFYeh z6zDm ?.|"Cu''VpB?L+*Է=/YAgq7?кLNb_PTn`@2r"f|ϝ4|F JgQ2XG%"A%J'hD)W_tèrg np;Ҍ[҂݀A/ꕁĪ&W.(!pɠ<8ݬ 2P9ĊG'+G ݋D}ldeB%`L<#X"h^+}AeO*T+3ݶ_!nWUE|2ۂ c` $ Hȍztur PқH{>/@fOۛr_Σva-B diYRw}rcݙ}[d^IG,sZﻈu~L In+zog 81M RlJ ts)\ վ/sX( }~4tufԸ٢{CUg! [V16]vJAY&C?-[̇tN!7S[_muRd ]G<>Wzͱ䪾hѵI"0!pJo3I-`G>Bh_ < tXP}0}Ҥs˘g'(T`M)SRh *}NV+ tޫխBzS018*㵏ĕa)` \\aٷԞ2sUZ ٮ]p>Eq y5ѷ27[ťD&!F^uaĽ0ƴrSpi j5eP)_/krR $< A]EZ_ ?US.kTvXS-r+suv}bK'͖9 B$iaT̳~*mIYXijV`1Nu!$r/> z+N 1դF`Sl_GHR*J C'V4EAf6eވqv@5ұDO$}@W1MK}h@qBfTLFR&UwQ;QlMv;74e'vz5#id{K{ֿBJԳqQd4ka;ӭGeł8{dW2%~7@,ҝd6ih3;PTٹ:°FueO_5i#Ebd4n:5 AiCN?!$bkBY.简G5J(CCXha S] T+3r@ffĔXNPr+x*03Mw@5[խ&űΖNXW)f Tkhϲb.&Sy %i$~Y1*W [ Gxhʶy+@sdUŇ*W\RmQFdp\oUO& .OHja~ %~/-97XMU)CѬ#3][^ut6_<;B=]Ӊ{ERzP|oe殰}4@sPZ/ĉ3oc$TW 7a`ljccF 9p/}`*JՒDvKZ)H!mɚI`*GZTH+~ hk6k 3:ˉ WHH+Tc4|Eq&AďL"Ug# }@饄eW8R}E&wx’jտ=.򍖭yWOF\% VG=PhWkl_f1}|P8Y_4d5(*xlג7࢘^+ Պf>b޺4B>=(ꮤ a)qx|̬係8QˏDB0x19Ď5̗'y&oA. a.3"hv)z:J]iM[px`=/R bNAw_#E<ǽ3+jۥ7Dwtm "Zwz+q%SS*A97"]҉NffIa Aj2L}rAЊ:r|EqHFPjJAu4k Rd ~B 䬖0{_2Kɨ֨P9r^_b2F5@Y(rzAZM鸡I)^(z>3*f `"\ o| J$9 :}v!m y5.:ʗ@V$~'rچC3uHMZJKІS Ӝr}02Krè%%:Wwg5I=(jΐ*+~$iY&oRJYoRAW"JZ3u^p6X?ngY0q&σ %s-,F,wjDjb#[,Ԃ4Պ>+, %ɝa„w2'N2A{֛l{:r}zlАb/|u8bՒ:D9o̵5@$I=(tkg!}iKnf*eZ hqof72E8͓q!$8wsim)Aj1Ѐ eGϫ)џ#b:Ry2sIn_PJxs Ls'VGBm"y$?6RFLԁS cώ28tL5ͪKILߏ-2>`A, @yNlM {Qʖiۗ\[,B!2_]l k#/PArxjuţ bRUBH\mC4h6& @Ut*0c$6<]P՘k>e (OG lݢ5tg16ܡw?txlp5՘Cd0 zg` !1`cE\9 Ϫ ^yc[ *!=kxPRdY t)5!Q73OJ3ٛ"av. Z=$sYWæ?w?M!$H1w>o_y6_G=JrNt W\Q1>&YMCRDCmԍLKxƯ(V5g\0 Y_4P8c,2Ce4#y{c%c>qmqŸLAAWwHm,xb nM>aW ZрD0>:QbhM lu<}zjdUyTϨܠljXgdp*OIl.+j=ƗF!.W]'"\YlU2J&^>RV5_B7i-A-UX#< R¤nkw,i}(`B'qI9Tr}vѱtmغmB U]fz+0!S.<Vsec(r/_ oY0}L"d4 -Ǐ)nxrJijڦ]+([)Fe" 9fe w-ٕ8@ unpx*tآ" Yc8 eWP*lzZ /fHAx:D0H-o))H3P E\A-B c@8<hJgWc8u_[kdxj_ ahIns|*C >Ѩ|ΞaGƞnPz)!sVD|6qME!~4y+2B,ZI!s p"*a"/XRCd@Ƨ]lfZk]I^F!†DuX(:qGWQ0(_- Z=>}3HyCWֶd޽_sjT7}sȞH3qՠI$ Zl2Ħf^cV~pv,CRJ [U oҠ4PKREx `2l)?¡w~{&Q4 aU(ŹVGS*Ѩ^GS(jnոT\q9Lxh( gUCM)%Tw?/ ӄ"v%XZ2ZјSά"hԗ'yA[KىE u cXt4.&p^Y/_A GڤF, aĢajk$İK-xu= B6RDo1z[1a# G܋w& .ZѼ0IL-!޼1Y[^,/$Kz +0z<;r*e+v0YJ"nw;mIӽQocnHOmD(zpS#zsE~A͌[yp r佝C޼iE^C  _ ͚VÖj9NG[z\&7χɟ 1ɇO ifu#I!oє=}^%=hYQaH7@BG Y?l.POWy7)1J]BOU[n\[q#T L旫%nj./m]>2CZp&>fu7O=p6#KHCUc-*+kXh2ǭ< Zx aydL2n9s˝>6 1s'ŏ:aGa%sg1 W(|0)(Y< :u1˧$!Xba$ !U?ٱH~\ @ih*[3;"]ćVy_j*M:1\K1A `m kioflw3nu)dfT[e6[iyj ;*ќ8\'諀2 e-iLXGbb;95:w Ov-B!턐\dK%3_7ԔoRҾ܁|ogumFyV|e }2FɠJy7)h:b)-%Ց 2RmaHV*QS{K*ز+m/N.=D^:>>n<(L'CM$2}P/e)&ՐQ=@dh||܅R)3OJ1wdu"#6* v/-xP3!wɯrl(Ұ ÊB,ͫjOkll7ї8h36a! 1ĪR}O+t]J/ >t<ڏfcP}= -BXvRœ$+ҺhwAJ#òbU|az16s.tj W>9密AҖF [ \ѢmCt| r %Ǯ.82$ x#E8nyѴޣ^:/gm# NYF!Q0ܾ7iENK9'1|0#hCiuq[sW9/htƤp訑R|Ort2[aN9"ff~v& _$ P42IMʢ0sN{B(ZO0^2GCjk!585T,MS {>!l/أ6 0PVm/O+ـLBpe̺(h 6FZ**pqʧιfkLF3 7iJnp_7¼Tglj Ҏɲҥ68|l#P)|yz)}-Pn6 I'<[iຳfZ$. !6q`aEMڂdpqЕ#wq,aTwuB pr!ds|{k|"5M6I9Ь#cWXk -k$F=Of^iVʭ5 w;8F:Wqdu3}Wլ^y0&%M'G#fܬ5A*&V sg7܆=^lTRAR ˲3r=у@ID{r+b׿<4wCCSҝC@ޤ#҈N}ڐMSw`9SINWep0˄DW;(?VTE]BDCeҥF{ߥ;YTg. %LU GƋ JS9jUC_;lٮtڍw8.G"OnJͅKCD`8R\ V BE̗h4¥}|2XR 6W^7bo.=/!z&ga=XS"ſRa0wS\%+(y{d#qPaidHD2QhWՃ ɹy}^4+GoM) lH5^A<;O5VކUHu:ǼllI67 eEj ېIK =WѺ%XcLc3hӤx׳n?$F]m2&LMKaw׏wW{dg$^pޕKu5)y.r.+gKĒ͋SoVIR(ܷIF{~-ᴸ-Bs>PVBbj3o _Z] 仩OZ=s1EcOfm7/O_9$Z1w,#]ѕXG}i7Ƀ< 8Q x;0نT{q܁PҪ9pp]i"bB9v 8?u|#>c=U^ NxiTeIƅ\hr7&)^gCHd!GЅ+3F֚QL 9UK8³ 3NmfJ2oImYv͌3M7e)/s/sNbЏS:8t͘݋^5v` 90au=.> 6J,D?hګ (HNRrT#b]N!(,@V%G@< ɉe373"7|e+}T>U WM'B l$RkAR}WFW\hP ::Z'|uJtOrl*9S&bztJ+:¾ƒcPB";)8"*o p%kE6VRG`^s.b}x.y v{}]h`lClJV 6VB>\뙐5Ď*qdHZ›RܕNchri8d$y_0ˆչfr;m$Þt?K&xw}RMY`_m]ʘSݥ.@m% )Yq@9=a4$i}nÖdp-R))'5޽(ćG. XS^S]sN# 9+ebc&\ex)?`t/6@X.q?RcvM`\QMmڱ,z#vNN^ [+7nAG~Q馆{["F_-}u"PV"m .C\̛^}}KH$Q:A xLRsmLΰRPQ:sjb"` ؽڂP_m mA jOИfU=iZeB{ 'a&%c>K~9t@-aoNTZ}`'{c/s))QG.}p(tGg )T8\BMdJb$z`W a;IL.N{3(1T5>~ߍ7|"t~ۡJ-z[jׯ>5@"#nMadfF(+wyKa`·ˇvgtBu0mߘĸ܏ ڝ"@5{RW]>&$LA5 )j9ʸb3Ӏr6~iZ5bi<.iK. AB``0kLؘ4ʃII0(`J*軤c $S=:tau}d1b>=d7l{QamF׸1:oRjp[ IJ5Y:~Vq#^4H/x5=ޯ].? Q`H32ʅjAs" ck~@@ĩcwݓCcj*/3b2θ1,۵J| eq7D[6Z#+6(}PXm0XE:MQMlǑ,Zlq7_3,uCy]tm>̂rxiky""%4<9?\?kܭgES2+'v&QhJ|2Wk#ĶT)W =XQ'>5Xu*bA+.O p#^ rѽ:.QjRR+˓>^}ܯc$DZ-5,4,mRe t5P y#)$YN>&=I$%"4%;鞺Co hde}dX|:]S߶@O3 Wjrff5Mui:5C}n0k(9 -̴l ~ۤ\D.D?zun7_l|qgwl#[(q2tPV OA2BȦ: B_;~^-XIa[@pS |OM1hmdQEryA~&=Qx*{鴎;4ze@9Yb&BǖHb93M9Nċ^>f|Y@Ct h+ϗz>ز]VnBp>R"iA_ҷ4y͒}V+eqF =@Xwh# tyx N D~(؝i1}NRë;0 n:$rC\%l{|CƷ)幆^GӉ)8UQy7ØL-u3 {qO8rj| Z8V`鱗 <-(U& š{-u p>_ZvQ 0G#ZꏹRu)x"5<7Qt+R-/1Cj'0AagtO˙ݧO贏q^y aeMAfm! 8!lSaI'iR{;Gf`WF T/zC.v:Z?˦':[l4qa¬FAYE0"3W(V>_g?y"j ߝuN 9b[|d9P?`&N}LPWW؀pir)M-~XЮ ߙ!3uײ)JEL 倹Nr@ )&i8m)m{ Y9}-6 4m8C6KN@p L2EѬ,&a%Ӧ=q4Y*^SvkazڒZVdC`nY#1dII'W,'Yl>Yr%kye Nmtx t=#p OBrvz>lrU~.ϸ]q!sĉhL.orSI 6" vibHl0 71nIDlMЖSdvK~fJsk3)AF.!*ZQY.*sne=j;}F+wB E3c얚]V MiDn|*AFmΦVbuTF@׶6{1FV=jZ]o=klO*_ל,lSx6Qq}s Zi6/abΝeRF6d{nMEY"3$@9H g]3)NX[8ߛf @b[DUI.$2-!q~myQ&RF\m( ?abCmLu\]!YOm<3I 3H[f-[*OxJQ׃,KERX>3'PB>&͡Fю՜@)r>q#bqӓUHHoje $BBl>𭇉|tԸF<ެmnSx?ֱ{E\^¨9+<ɑT7 s{3CoMVztRexJ5o8%fR,EN=L|VRH6_tPVx4Lˏ{Nqg( XOx{x>cS 0뢴"r\XXxR;e`'wdt%ou7{Cg٥̟F҄k|/~»ז3hC.)\ nE$.3\uq 9DxƮc:6`5[ꂖ/-cgՄ2u43ǴZK?xF}~~ug` >>V:K-iw0?лM>B(MH7Z|ɬ>ײfyˈnM<3G "d$5o:}IcDLv+WuzA̰:Ox ȗy4.e[@d05áDVg:#_桏8h4ʧ5Xܽ"^a-r! 3M*ߜr2pr)nUn|6wAe=tv=B}fRVOFQ2ؘd7*:BhONn(hG𱄵Thx0 ,`xyiH[}]k& Zx_t{oY#$%rZ/5w o1D~ϯD.J`Ԧ6Ö2ƨ]t{AS&csXSzpisu-G7{ t[TO9fBfk%,b @d+FH#I o3/q.u+:IOoonR:zb7y*$wF>5.(la<&,Q?Vc SF[ƴ $͵@c*TUOlE™˦|l9U2ǘ 0 v[|Y9ӉQB5cfp4[9= yb_~" S[Meu)ӱLk00bi㱰i. C=*^M\h-Y> ~2<`S}D4U/.(]e0{Av{1;o7Fpj΁' EreK$~Z$6.T ȇΜjA%_n&]iipF:n-A$m*$m9ns3{iBTNhG8Nx ː C3ɡZMzER2gg/5ҨQ],Y:+I|C&kΆ`Ӆ %tBMOү#K^~&LRI $qAGS쒲1Z9qq>y!@<: xs|~_J3m}rKŃilJ`=~n< &]]+EXmibxsqv\Xrσ:JyCi-_v0ˡJP>,^%75yEΓ!n/p_kzߔx6{I kˊ 4)lo' 7f-*6Uć +w!\Ă* /=p}|X:pMwZyc!~wb$ ONC`T.jޗVQv vupc" VFpcdKѣ!F>W ){S` P׆]az+A7#X[BZuR6x&msrs溼KI^e :L! I#̵[B[rEkxKw%8E `54)')GvlqU#8ʙ.~PoF TN^Õ 2('BR9nɍUjB?z|7뇲RS4jv%`Wdz:P }eF9S}.FkGv@xérm:py `F֒#R6 B4w; 5٦o _o殊qKa3?tc2vrѠqI,YY]ւjSh=,Br٤ KIM8 eM_~PQw 6?J&ؽS*/,6fzśk!KR`aHO=5gb'7#X.]einRFfduDGa3yٴeqA\Z48'ay- U3U,LP\+vI] s X~7!ePloHSć3M۩W7䍜Ѯshi+\ RB+5OQќW)5 v<ЭV&w?8y{5yz}U `@}nPQ<Eȴ>;jܠrg''fKjG"1=yɃ\MDG62 3LxblI'e=r5+H}.#nj[+tR.X8"pг7XDa@lc6c{#짏JڅdYi%fX/-~VViQSzv]S we)߬ly"Lv1ۜ#G3kLV1EUȋoVJa0~i,.~6Ţn5KIxNu"< R48fMt;I ̟N$ԎQڄ#ʈh=M(Q+nQp&siKY&< ,?[u/&tsmljm cL%~4yGThA")t'e2ZHp@5ϛK,otP0yFL Me6IÐ 뾶I46M17`H<5+"߸<%6 GOQ2|p|%;Hz(|]4B a|4fA4EjNRKuPRt)KXnF-Cc=ƎLk^=crR3yDvUx,w(\UeX@qNŶD,]J4\M[X,xH"wu <"2$hR7; ]"IEyuª/5%鳖MyTc1Mru K2 SFN`rCbd_ D,Z%_P ڷ N-ZV7дlZ&n?eo=3>ԎNf?BWwR;4b :R*&^+癒tž!oBMуS-< P^6 f+^6`O:#$C:n' ?']MC ]^V|1RP3OCb8E~FՌ[By0|3a۹v7V.q_<WnFx)c;JvHg!YEM'fZsn2X?_8,$NڤU??4#:p#NJw >-Z6Ae"ʢ{*ȿkDMPZPX> \&?mhpR骽f>O6QFE0-Fb 0ZMV/Fɀ|YXT/܄<cf7T)UR) MUվ(!٘i+uτ#+̥E_ ^5Q'P̷%5(OM*(/OL G0yld^HAL0Ǎ/5a5fn*6`e<}he5Fa!SGEkLÄ~Q\3HU1&^0}<"h3o?@dY00b}K~Ѧl>׌,ucaaZF!N-HRh.':)\^hAAh9e-[ bK\Tu7(#4E꽅T{x@L_t `$ yK9A>!i(/PwOӁϐ3]$u!oMEXr8ٺ]LM<Qu X$XuIs !VWvn`Jlޛ~B.UQ\ -J t%^@-] WiX~og[cSU\Dų2.^DȒo @Mc_l: &Rڰ8-F1֑qaJ^b;_'|{׌1 \F+K;¡t,?Td| 7حL1 V{cZ`@xqa9\Plh_[4d_^R~ gL-SKE2k︬ib2AR&eX. @|| `B'"5G.QCqvE1Kn1~AX$vYzGvx W}ѲEmrmBP9{-(qqZ1~Tz"G! n/7j-~͑(mfe`K'JOX+ Tّ1:=]5 sbO?s.ܙBA)0trjK,զ|< FI2oҼ*B\ |@q軰t`*]fG/ﯣ3sP`7jk!bM[fҵ 17ky>gSە4I *D)^8;d|4+";mm6Zdqiu n++օ۳Y(9/QD/CXɈ8e6[/|2iq-]$ɑ`sp倌u[3%sW+8&ԈZO\?o(Hv&7&3I!鄒W8LhB yڍ/ ͷ 1[O{R.Ar+G[WGjsq7Ζl 1ʵaz=/?:?TL<d&@SXDbX`6IYhV"?8\mrad 9Om֒v^ݻFXYuVV͉;m@@%/ĉT u@y㏩'>K|O[u eň.ߣu|JQ36ߦU@(])ÊwJ(I5Dcӑ" |l=6u9{mŸa7-rQ@+'t^0ߖDV;$n9xR/pȩ5-ra&_W~v:ONwa-X?wL1uVuoFqST(LFVl]AG%6-w\(@!6֨pi)BUUC}Cc= JTC,>tOv+dKu Owlm\]Fv/#yGM8 z)zq @ӡRS-' .Q4 ;kl,f]| y{}@k훩!C;K YOeL%sf( [L  {Vѽ-^g4jus=,~ѿO,ߊC~E+]oMԫs>qDOx%}9rMtk{ۄY5^EGۓ{ƒ  ,;\DbifOJb\Ұa}AKYKnLuưsok]ҫ߂?'m5d4o ,RUd'PlM`w V=<L-wb\$5" iUL3OA j׶C+5_ƕ|As̅z|;:XUn/P.a|R ^9vᩴ٪@qj$&,Κ&tuaf)Esx tEV &-ud4"{:hHZp"?H$wW!07QӴ}ȍ Oo@hy(,iq۳:U`{0SQJ1SiXsjv]+D({*9(ɒkj(t%ç1Ŕ97?x+8MRsr&MycF 2+7S4~A=ʏDQfZƃ0AC=sL@tr $Cĉ!'^p8PقQ?vQFguk]aEBGÉ\%hHcIKLL@I)ɿ`mOsZ^<sĢ=4{" Cxog .b(f?7(ܼPT1$88URA*тt<~4Jd5㳋3X~cC͚J 0s KJB9%vty *G$UYV EhZ}1(I3TZuTjBO?]nIp ؏lHӠy+"!5k)7N9©yp;Z=}2dk+kox`٥Fz*I#9frn`3[jF-x.IVIw.ܯTӫz8qa%(왣eHpAV9do tм EUޥGy kl(QPupoDbJFQciӫ8>s6*/"R̕{ƳXiѧz9Ŀ0* +ϗQ$![.'ȔFZ]ykH+T ڥMuG|IF8\sHE݆iō:v!q!L2HYm-prbjm*2GQcF`j;l$yr*`z^mtǣZF4<"lÓEGb:9M?:zxFTr=gʖ֐&X)d)ӟ< G BL9LV9Y6RHO(wgu LW3ܿBwgp\&jBCB Fe.ُP|h(wXʒ-*yRsر":|<LN-c9"V(H~!Za oA ,d }O0qoO"DWgrt$s_otZXhv2\w@W:P~_Ulfm{AY(sNfc̛vҪȋoSfF[ ~j#Tc<Oe[̎̈́%;ݦ:}]GF4lc%jX}a8& !tNCr ~06qHEX.(wY2m8o`[5{j\+ ,+^&F4lmu/&9SV;`n|D#ۢ;7뱰$ɛ7, vexNuo8$|hLÐoU(ƿi$-R$dU*m@asPApZM$Y8\FGo1 l AHJjP2!{#U"v>:Njp*i;p9V#P[>5H3`( NBX⿜tQXو {*R͠erыfNONoa阉_Vi($-6Zn騀˖IN@5S psL];_+9|Q2rhv0좁ȼZ- 媲)MO7> G9;d4@5fbb#TyLkY@/dU7>3娫㞼 $Ⲡ of&cv+ok@۞bv0+`"Bp"`EM*k;?4B']O/ aj/ONOe$46KX}kH{xI6Η>1HW E#ķCU@2p)4D9ƁIcĒ/y_o NK{vETA[o[dիj/]WR 1A;òUfػeJ!) d\G%!rY>"0Gӓd+r䌎]t~.W3k,|IdYK a%j+?JtPRn ٖw}M_s(g)U ϋ ߧV?X6L/ _b56t (z4U%k)g i_:.2GUчKsªgE A@Fs[E*Hk} VOES[ @Y 815juպG(hAʡSmoD_^AXܰrg "[[b:#ﯚo l޳&+dOyt8ڗ_K.rADUJ05'Å>2Zoy ?I@a^ܢ렸_:ڣƿl@-YqX@Mp$"nz\;카3|3,|$bfUTx9ؑGvLU=Zَ{ٟQ,pw6x-DZ^[pu~nzGmC'9LKmC´R&r JyqHXmvlz4TFĿȰJEǭҲgXR;։g8 #֨83&' A@ !cOF@dI8oZuxVO,. 2e: ۹RqTvf=^vEvme ]o$?W==v{µ(vRҫEfCLDÌ2m;\*KN}| W@4x4:~桂v0c˝0LW j >򯋀e[ΚQ&~` 5MG`NU(AX#nK_ n`n4uol DXQ5ď<*{:WY hSSR'42{1+ d5Afvt& ;rñXY?XyWZʯKVrno{C[`gw& c/̽Cy4 gxu,Ȗ* G͘ b(_|KՄPO?)R~Bf [ue.h,l K 89XP|wPg7~~V&Nb*ϗWm.I>2g>:(lw |ilD,Lt.!ےJ& ?#Uk-rV8R޶뎛oQ|ў2/lq:ො&|<2h,\Epsu.:zO;xMk"W.ˆ_ѺY/nbMz޺gX 8SQ %QXg&zw#v 2JFq(hl4qhԚ^v?= >7ZLM;3d#X5!cebgǶ-"Q!$\" 8Ne_ݪWHTL:$-MקexhO,JX+; Jv;0ÖG:afM圃rTOmCcF8 Q #&yo\~/.۸=:б zR!S= ֮E"ti:GꥊJ6r~P (ZmYre)բri d,=ۉ[͙q#t.1%GJgRdž:[@#~88`z=SmT(Q:,cE9|{nI^- B M]E͟z˘7%^ Vx^:ykB*e2U YW,yDd-iDwA;y yw8Q;vX gGxտ wc1`Ge}Rn^e"e{ ͈5m. a虘E㣝xyApKBnƣE)=Z ;eriFXclvAg|Sm+;MMEV 6$+IYAGԩ[6r~T!L~b\ sto\`e v #l,?Ofq__H~3.OS%Pq {Eg8:f mO h+@ RV+-4q4Etc m&aKqyڬ!a P0{"1W^3Ek1Ҽtd kr 'j.N]a!di 0d9^m#s̸+)}XfT.g I"{#bzdsL,H˳Ԑ\ f&DK:;s/JR w'a٢B5mAZA0qƛUI3~@F |cU'fg7a9=yn4 (n;$ڷ> ӴӬ'>ȣǦջ|'ဵo"7cN,3ؙcp:dMݘ*qZY؜3?W /jBu,| ad 8LscS%{s= T3 P^ P0zHDtCBgR|rg.DJ H'^dx Tr^VUP7ĝ g'T ^+vo6>H !4{])*,lŸ0H>pvF7A\u}Uփl:7!i:Y%`=59 2,!HAl9] ]7YM0AG pyG1xөşuE: fm=a8^/Gll E72VJgf-.y\.>޹B82| zFPjhT(DFA`J~On;skeE.9~cnvD,.cTM%J(舔;ޥpI ԢX4t_d3NQ̔ Pӿ!%5 j2BǗbwZH7Gs9yAi4˨th fSw юu0sI_åTc@L׻۰ϵʨC% XxLEF 8Ŝ>#&|K@}~Mk>t"F RupV[ -Nq& 2w~Ѡ6k͢vTPRzo9cB«kh< jFE͈q) hU"mlx¡e'(Lb?>Y_~8Jg"8=W[̻PFl%rO_oX;A*Б?+Y0u~X,] bn9`v8ƛ'B!bsoCMD˄qE&WFĔnmuANTҒ/tCgKy]N35qx~DZ~#9 cyz#JZEr`U*_Z~4 [P& Fxig.FEr:.,XUT,Tmro6eE3;\+@Av sH" hba)KnHhsr3N@W k2ڻi՟۩; h-/䳪~a=w'ic{f=Z'vo&zhtx WGжނnhOeioGT% ~`P.f{Ej]}3zyԍiD<a&w2 R C`qfMvԨ͠SѣRz VISAßxHV,K;s4|o|kAgbI)_ՋH :ĎmUpNfQW>3gr=yX7MJn\ *El;BJZ3-BE eLxM)v+K_UƜ>Leri8I%:l5Qdd+k\e *|mN%德w =|Gnbڽ#Vħf;@ 9JQ+p zn ʷP1t$+4=$LsMr!0e7FB|DfoR-6 ΀NmG1m;^+r\ +f{QGY"'!B '̰0h8j(9AjB 2?<]EⅸCql 0~|*H[1ipl_Ī~P@0e>C3OG2 gʖ9=ٿNh_-Cp<ƟgsaֳDjiѰyHI3B@?Z^w߶OK踎>sO' q͈O*bLQ=,.tq'F}Y<Z."lN"?3PxRl 7ׄ}COn%D>DFJrzgLC/6h?·_1C5ӹU3P'Q sq,z贀["WeR~B+o>Ï4yngd< ܪ<:'!zxefO1Te>E"J hb*@Yͪљ'h{(ڝNegxAE3?ܓ L bd=-zڵx{7&4fu,.c@AAJ:_C˧Um38j!T*\SmMd ֌LXc&oa>S6^Kv3 7\^CgGQa822X: rdv7=T`GQf]-'KMnk l-i ;Ȏ֧xǿ t=鸲=3D "H nXR>v"5#16J͝8UK'b+OH}}% 0R+Z*[FC_;o4.N* ¨,d_h,V?bCn Me\깭mXu 50vOc4{pB1ɜRdRfPIzW \ЩySȰIБc:8TdrF8Dl5o 7t>>IQTzurѻUrxh6!v! ^p΄V0cVc+N?~Qc ~;:YLX߁V (-tD).R@u?O{xÉKU @ "Pqcw6f bp^]@Ϫg5vn͚ iVbGXu|7.÷+֝JWrx IᒤlxC`!Ypo }Yl{nbLڪGhqRm>ԬءSl2 Ik+p(7 7" b1Ϗe^ s GJBvYPb(!c2Ǿf)oϹ֪~N1̋ |(Q7zI@C;tfBvmKK7@!FjZ_yIahDl(G9UY) zrpA8*17h{<]*up\1_#GcyP #gNXl:vMmy6MUn3 *햍pez6}ܰ&  N4n(a̜E\VD7Cz('(sa чp?d4ļ,|C\_ 3#~PsYT|Cg<@PBȏtf9)ĘdnPՌ3'0zI9Y94.94&ְO, *$k*`˘jDvU1L߅EVS9SSUQv 4I{lХe˾'un`䚒pϏAmPrErEJW<BlD|'Ri᜺zu1H#LY^_4ezЀ~6w{70fE4.k7OXpM 3+/: CAJ`aJ> A 'Ir,쉩Qn Xs#q U0$g;ɟw #DcH1r_i 8fdt+<-ƥRZY!0ze CP`3r˖.hzRkyJ@ յ>Զ^lQ6%yfFJ\o" V,EwcxPmmLlDZTj W@:aC4x _Y7Px Fu5:ȍYI0)XJl̕raY}eA$^.+F7S,ad$G $L{H$mFh@6tWs3@ r?$>Ru 6:NYknͩ7$6>^$oLcw!UKf(N 8?Ϭө 'D`3ȉ'%Tv>څF9 c`EK/y^5j\ԃVWr]Yzb>:X&xG٪Z,Z5]-Ii7)~WwKb1oI.No{K";( cxYmOV&7Җ'\Ȩ͎>^ 2̧e& 6A{Bt% `y'H=Ie|muW04m.#5;K%L'd?}>E$f̢FOjփjI*IXR.>34oR 7QPZLbE>ߐ(5:Y,+$3{yzѢe|i6ًtä{.ׁ٣Ó % ,2w$i>қbf)~͢~#`x4]un̬lS><&rB ͠.9G7ֹ #-$JӅ3ѽvʌ;Y I))ߩm Ai&=4jT%it>̒}Re4s NwU8lp9„TzsL_L2P*'*kUVdiYA34K b6Wkpޙ Dp"s:ߐn:չYNd0t"ސ*SK435Z$Bzi2IQ-3L.IHrM܉(D%olSv}\dCwnkz eXۄpN֭m&E"QzgD$%by@:lQ|&m_̕3qt"|Am}x%IYcMdA_ G8CŷVBM 9şXi*=K!չ]Tf`{"&'h? /IJZv ׅB\8_3N0Zҹ9ù]+<2~vaGg+%o+EƙqC…-֠ň%:CkGw;ue cvM1(VnޢǎJ-$J '>Y! M5k{N/W_NAC(=1Rϣԝ`kAEy CFs0jqHv@jK7n/U_FhQMVחt z4U˗!eD? \"7߳&_cw},OƧ~zHOm;Y$f[+TɴR-WzӽZzKu.>VIE"!J^kOY -F F7 GRj bK M!4V(_Ȕ&<=ԅk9JVyшKGe$9ύJPPcp1yI] e#"jiqbŧLZәA}}Z&HM8z9ח7+ԟg\DŽ'iq 3¥;⅝щW=O2^hžJ@iŔ]&Bo3tM'\F/$Kd*fc](@}dl}tpʗHLh2?y H +MT;0,ph,^63Kźj<Lэ~sΥ9䃟_hɗ-V,Y"1;q GX{j<9zRn;n3fvWuE<_G q& .S4 mt@L NZq9 ū+t 7HVCdy+XG MKwxUt%Qo!x~xh02Ng& fv{ѩ=m pVįޝfsnD'^݄ ]@'8VΑ!nw1biK/nj_p:؅Ǡ錃/ |eVYK`#텪Ty0 (15p''qDhkc[6&a^ 0H1D8Awb8&a,g7$'0ˍT-B-hrQNΔH#9Liy qs(#'!\_LDhkjIÎ6g*L~l ={ py'ڗ}2GF)HjZ7!2S~t3Zbf{yl&;m}ALJԩPǸӫe_Ϙ(ဓ$W@aS%w+z71K1fC,O7H`<٭#'ic'&?ɉ<+Q[ ^ⶮ'6}C/@K݊7^7-p"pؠwsa>@GThMe2h_ͯ:Pq [uN#ɹ|S#2+wJ ;K"?6Ex\&\24vJD-̮C*ϟS^?c.,(YaeD8CpOΥȂTfKYaʛaQ)4@αY?YZ fNlm:7&%V$Sd\2c0sV?&1}Nx#An˹MŃť=Z,v38İf\;*̔ U:hwC]#Dz{$<'YLN}:a<_|;1uk*xr\ۂ9.7,\ozGKGN7XӦ!KsKGҁbVKV]  $r~&:C+y2BZt:q>~RuHCuMB#|[| D/7E.eoCdM/>??k / 5A灃4D4"x& Sb VvEodޛū 5\gyU.3G)^pP@'U4@3|jmD͕.Ui1û|cei^Cyek1Cs N36:B[~Rx&u8m.Z @0EZ<ò*6P8l}mT5 ֺ**ܽSD q`YqC`}ѱ&$#/+A3h] vg޶P1GF/ VZM;O!o""ȎYR.J񔏞#5H%hHCy%"b絛'PЩ;Kߩ^"?@]"nܮH/a{(SF; MI01Wս[Vr/?01Uޜ&̮8ZP#yF@U?ID^ c} Ϡ: pd, 9DRYOV,x?`㟪SjO[ʸtRyP0s'jSUa7Pј`^+Ц3X}ĝ~G ju \X`Q>ҷufr3`.Ӵ#^K*V5%Scl,K'\XsqǓsTs]4QwTpD6>5Zu>hVE_8/h=o&Tr@Ԩo+$:)Mm@7Y!VWsGGt߫zސB/4#Jd5~!O=Kb\3CU1Q!<+djm+U7Zџ|1π%DUHi3 k㍞Y^DqWĵQ>!Ԗ|_21j zs wvCSL*I G4l~|7l^SC Xx+j?\@Y[?j7WtȒx-+ϵVL{F Ű7Վ "-!CZ1|'C7Q7YA)5nG1bcp" TNo12eaϓT&=Dt, bf}AXKQׇףo%ZZށԙAͤȝi/@|SGwd5E=c#^zS\C/ [FFaaF! |t/q:өawLO26G[UO#ӝ֜9Ӿy{9R40)pt뇖<*y6iص?竾!̃(;_ AxUs'|diz]$ (\8LiK rf%s۠[NcluJ!-|j4q({:ωѠMY/!1m"!lQk_D٠7qrMjY̹ye_sfZ$"ۙVYt4LWVy[U!q{d]*n%v=rG}I/&*%}AWi C&G7򘑏.ܹOڔ%!%DAe}3;0‸l '+)bjiB?Sp_\51^agV\TDk_c;rHb/t{4kJѫIhh,'{^ U"xFh 6|l*-E} ' cm<1zJݗ _n1Xc|eAv:~Yu_^g5=ĴV&?{b-JQVVߞ۬fh5 'JJ)1 E-0zI~6|!vΑT=+̎wcI'M7}b|S3 4 |iAƟn i@!֐ZcVyJ&JIDp6F7"Ћy'=ŷ9uEWNh3LN "*Ar(f,w!Y{jju^uEjd`=nILVIi 7ŽnVOPcbp`b(nOrE=BI&ϸ/ ա3t9D#*zũ㶱a~q Jx4w;d2}!ʟ"mN3&bK{Dcoz#d&of;&{Kǥ͋hHqW.kЅb}]=zv)eBn#Q.j5zUqib4 j˜i5'$ b󞡜F>׹HHsZlRFUؕY[9hʏdXOU&v`B4@MgQIr%?ݬ*T6~  A-nlv[U,GlM8bJ/¦>ΤWɸ(NkޅQ4FЬ7x$V<1,n{LSq$9)/G40{oX&y|r~^"E4Y\) a8(zl~UEl$ Ӽd:)HQ+-(ca9O۔ܚn-̚^a#<znMiY\yYTHEuujΡ f!xPms|r#GO@&W(?0pq[PID"ٓ~H`:o;|gNKAʎevW:%#OanfDwu./*t/_4TH5)q.sqK{S2xg /6N3?銧]躝4D{s @1 ai)6T*13y`nNͭuZ%k؍ahϱ RْZk%nYnM8^& GgT;N~RagM+sc2^OxXL&@1 /eCnK =];ySl&ApGL4i9:ϗu`? jw ڞPʭ-*]WQRy&ʼ?DQώCrV\X# +YspSsRQdʑK(yeQQ*N_ϒ<1{q#}cΙ) پm2 8꤈{H`@&b8ɺEL1ⷘ@pqh_Y? eƛ;G>uxU<^[Iv kt`D;Ypzhq#qabtz46^,:[ےk66,qFG0U?۩~<m~"]PvOJhwl'_9%X:HQ~2q F9YN/-Ir 3}vYzX[97T*`BиR-gF d}e>G}՚7H,GgM N p0]&^Š|-M٘InX/pBj"ԙgqʧ,.cRډ]~]\.߿HOB7x:Q4, zL9TK~:zzRb .|XpUoj9~i5GsDb^↛[:(ݜYy1,Ecn. d-H(P)Q-'mwk9Cp\"',p#ILۆ}4V VoF.zQe%2&yɝTWAiCI E7_ wgҫȤV3kM+,.UB .(Q h[ rrwXR+\livCX.lwь*|gsPNSt--C)D0?Lu=Ǹ s|b|l$K)+gzɶhTc@qͻw90kE~ЫuFVEo+mUƌȿL`fAB¨=j4u : hl8ЂR|k0[+0V'u$a"r/!\sy!`Gb*%) W)8t\?pHf5TF)唝e7>|A)Z !H4;nR]gOoT)#|R4[ s&WL[RB 嶆qC.bjo;)Aa ]:M;X6ASQY =)U 6F?'$8zlU/fPҒ4#P.{8xG/Ѥh?P䅼,mg:H 8Q NK?C׸<<x{ FUz]HX iG2Z1m?a#^›uL/\+k:A*uܮ)7Zq #4n7jxRdoGʿng:]%ԧyuX~*Qe4-y (D aw1G,+n'Gm^;.+dq)kUJs42^1RK^K"unxNꭃ4P .ccɠFDPWtůRӘTr̪o*ȓɂ-o?g!mB@-<]R׃4M u8Sx k؟owÂ!\gбZk,Ckr%/gNV=Po֎1.mH$wfc[gJhS_'A炆KZ|>R3@D$)Jo`R#ξ ~p =^F<ޗێ!~O?cHIr#!<Kᡤw9PUø _tk ٭A63sqp=iAoG׽C(έyzs>. qKHgyfFE%1p3U덃묌WHtt9yHtf)N9.GRY:khqWC A8N; 56¨o1W!T'؂"}PsLؠԆHYCYws뎎HڠNS_6 jDsfQo5j LzSh%n A[I8ōn?Qv<0}zՃ)@j"޶-`n>f,o_(vl9  JM(,G6k Ѷ6;x+'F=AŊ9B1z&Bڽ0E*2H @o26ka:I)Dm/qU$҅K:,м/A+cJq!@!-N PJFcV$Vַ3޽5dz~?O-"b9c#zq4 ˽-f{d_ KQUkƴV(enukLhek1ԗn}ccnRߊ~灹g;Zp! v \5Nszӑ,M2ZI h)U6. z$kh@*k8"*= D|PEDPW\q_D?TKbd'0\]Su+ у@K[j}mxIew ?x\5X߽ev'$z~J.\'Xn.D3y!J!",.Ë@כ(K4,DͿ i88x6ˊfm$XrliPv,FXM3Ј/ C VDf1~0y )hϭ8i (0J◀=M'/|=%bTÒMGa*S`k{[dCI > Q6jW0\ϽLaŸ:Æ뤰m 2X\SZj F ?t{Qx+9&K5h{1dԄdt6yuwRIm-M>ObX& zcB7dOt_Xn]=rz5_Aɷx'K2 ELЪL5P*D^*Q(_nLg[IN߶jA6}Wƒݾ`.Po , pcNC̫`*T=Vh $>˔Z$ˊF2U [ _θ[:^ԙԣpݜWi`/ +#-C =EcŎwPLWI19|VB)݊?Х[<5PWoj퐬Usry0@9/-ˌ|-akD"}YTm f .VRS7Qǂab 8q,!e[AP%{:P(c3ÈV<ꪨ{jRngm EF.yS}ب7)`+̫C|D@d:v-r2ҁrٓwmbvw'C©`q 3X.W,XꋮY )E)xʡ ݋h'y9=jADdQ1|幡_ kĿSVRZǟ?z{hԈ_v&Ͷ[& 癝ϋU mHCA0ReHQt倶d=IKTG\!%?`YP "7XY2mqO x4*?<8x$\m&yEO4G%1?&> C5װ>XU GQ Wf14,v㧁iZ;3Dx<> ?YޚoJr~X‚9S}dZ@rIm {_\ esNCjcTSFNSxh$&XIh})& ;o m}SI{%fq܊p t,hT3Xjy:[ (*"o0g#SǪ ʣe3 ĘYHru YZ