sssd-ldap-2.6.1-2.el8 >  A aBU]ũt?n擼d(yzb$" 3vvIո=3x)\aUu(ȜT^Oc/ XMVr \+۟Jp43+ t_>J Gȑ23-cA^[r.t@ `o-f|ݎӓ~`q mOg"R^f64hQ('_Pv9c 2NaVOn cvuN):pJ%i~tHl>/b>Jb }j}݌CWJ^ɿ=,KcRӦkU9/`ZB q#+MQafb9f300ce38a37b06fff66a946f2a7582b09c332b04549c2a2e3757814b997c71a12d63315dcc245fefc65c24f70c1a7f1de943aBU]|J} ~9V!FƗ !w=O_#RÆF2GjlN܌aoDgń#XIU (J_M;F4.3IqeƫE<ɇWʹ.lh"CREq t~z>I_kx }-[9{OXc;X[RgI4` 8l@i"645 * yJ-9{ϲBRXnKcyrΙ>;/Ҷ#ۻЬzM|:Qk!fR_XVu|9-s>Zuu{ Kɋ`>Dž*ŵaa~0_AhA:v\1Ҡ >p?t?sd   6 8>H     T4P.|. . \ ` e( t8 |9:bGkHl0IlpXlYl\l]l^n bo dpYep^fpalpctp|upvpwrxrys 'ssssCsssd-ldap2.6.12.el8The LDAP back end of the SSSDProvides the LDAP back end that the SSSD can utilize to fetch identity data from and authenticate against an LDAP server.a9x86-01.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxx86_64)oKE\=R4@] UAAA큤a*a*a*aa*aEaaaaaaaaaa561883b7743946407806c99a2975806bc400f82f010c967c6af50886450b2f9a8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90377da4a75a59c4dc14aba36adf254464ee95bfa6af12848f794b57e63a44d85ee03781829995c20b93932ea02ff74936ee2d66cb791c9946507cd99f86cd52b196403456cd80159727b8d518134068de3d41482576c3b39e6d954615e3a84c029248fa374695c07bd12f13ec712449f12c9b32694b9118839ca3e4db89d68ae4966d49d6d03b6bb62eb55caf9d613a481a6a314d2c10cb0113f86265044605c6d73a29fa224618da7ffeba64c6a6f4c912ba9d466c4c0df79e0033b4f55dcdc1633e1eca780dccbb8368d6f333154d84510c4d074085f3e202ac785b0dac879cacad0c3ff50875e4ce0821580aa376bb0a2c60af0f07571f8781bfec5afa35bf23d7280a5ebcf53dbc96af19323d2947e1d31967706cf00e1d92e64d82b5e6cedf08f5e9f19c8c78c4727e99fa671c4617b815be5902eab7ae84a2f1f17eb531b../../../../usr/lib64/sssd/libsss_ldap.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.6.1-2.el8.src.rpmlibsss_ldap.so()(64bit)sssd-ldapsssd-ldap(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsssd-krb5-common2.6.1-2.el82.6.1-2.el83.0.4-14.6.0-14.0-15.2-12.6.1-2.el82.6.1-2.el8sssd1.10.0-8.beta24.14.3a@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) esesrurusvsvukuk2.6.1-2.el82.6.1-2.el8 .build-id4e7d9068b3e3238f714de3cd96aa954bd9757498libsss_ldap.sosssd-ldapCOPYINGsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/4e//usr/lib64/sssd//usr/share/licenses//usr/share/licenses/sssd-ldap//usr/share/man/es/man5//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4e7d9068b3e3238f714de3cd96aa954bd9757498, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)'PR"R%RRRR RRRRR R R RRRRRRRR#R&RR RRRRRRRR$R!RRR RR*utf-8de2a86448199887faca93b32cdfca09b9a61d572ff199c93af964d34a299af82?7zXZ !#,ᚏ] b2u jӫ`(y-6]Ť2= !ǏV4 !X#nʦw,LHq5oh4QFn7Xl7 ϝ+/s4 !URL=lw`yr>q({HNtm-/Ӽ 6}s.ł>əXV'GiX/GD<Ę,-V:6@g Ȩ*.ujdCin6B5>ޖWKȈ!O;B܄k_΍36.4\ŧb@4"}D+n̆o>K8ŎvZ+tbʃߝQ.3|x)Z8Rf!7 ߾/YX}j;Å#qb4M..3(2`#]9vrS:a2Ew@q~_"mtOi_ڲ~pYb>ql)8.o8*, {SP9vU,__ԼAvA2?xϕcx3l '̧E*:ai{p# !Z "FQ^xQ9)ysw_vCE$Myn~D΢YﮧK8f[R֔YL9eLg'bI?shBxXkn ׌+S1|"f_DCh~L:Kx4:*OBMW+om:V$Z%hLM }N)HrcaA@LݠXDt#4\ԝ(TyHRIq`uS'}Oܯ“8XxHYit̥A#g=ic,ԥMt\| `^-!2xs' džQI*,:p3^X8hsqGH +Td}`]kEpf["1D0uY)t׆Yd hLu5<;ZAD$`W()=ƧOӎ?@`X=1bb.Y[TJi{fYe2t{&b:Fc:7sq7(5Jox &&|wu:3Rǰ8rWMx:ݝm٠E$Ж'VLUF)[O^H{LST:@eAII2II|'+؋=USﭾ{-G>zjZhߟՏlٚ 7pܨ~+ xy8VC2;IFh1CP~ ӇovV|%ػ'?Ʊ$opYfiж3 C|oM]jK P|[|ԍ '=kX'̌J6ׁ4m$ԙ ߓlvi_nro;S+ 9z"PLV0ѭ8֌Me @wT%*J39#Bњ^J-%qwWOiӎ8kdQS愥Wsɵ9tm:naz bpGD&F&eϣ׭ 6C]:<.N8)z dl`Msyc o@O2"'\t4ĮVg9Wүx5?XZ!J1sF}P|0M ݠowu/h ee>/}"&[(£kDԆ}"ciֹBZlIvYi*5<N`ɔ˭_\9BǏ׹9j-xX+dyCn1H<1+R3nt+|(ҕ@^Ӆ0hD݀% P3A`|s|C<0xYc5 )/D_VJsW\dN3PrGnIzcu Ʀ9$8Kn_dN5ܮNJʨ/~۝g$rCX#.AsQJ3!3lޚ ThGAxݓք켎lHL j" w%qSG/kSs\Ye/9FRtZXu`mO*9Ǫ].` x^LtrmiyKqn/?¥e']nma -~xȣS}nmTDyIz,p:d=$3 -*k4[ڿuX)-$+s=,U;i4s?G A/-1yBA44͔LTH4P{89UB~$oUmQ` 0SɫFDT9Ov>7z9W.#Z ^q7mAvⷈX[?1! I<%>Ӷ_J֎a@$LQ.' kΔMXa4d,7b d[%L1#%BuZM+Tvˇ,Ħvshw궈H xGev搱CJKZ#OqeʲY+Xc26)F*+zG Ny[H dhݾDgl(N/ej@ɱs#~Cɧ=UwSTad]2\8щ0|'cdXX%8BrnhTnWqՄSoVȈj G0BY+]Xa KeQߚlܘ]>4mtuaYb!eq#z;_A84!p|ҵM+j9 :9\hu^Z Gu*i҆Z!>m)4E ڷy(ep|L)Irt7ƅ kV&@5Sʀ#gID:y1Zs HeKŬzOK THsO?g 5,xk>{ddh,9^2-9|!16YKgv́P=<:3v6b_?,_y J*t2 }*_/ɁDU+Y*Rz* (RVjRj8]{}Ĝa}c ℻;%\F1^\!q[8?Wa5+lzxX W[mBU$۫Q2]}ud謃!T*Th;8y[1I &}>j9p# ϣjA;8=mҥojȀQ@2E,i}S'*셶N卓q)IAtϝZnhc ~`.Mbg8ʾq/n?Pne49x"zG<xȷoB y-lnٽ[Q>wbta'HO^Qݩ3c ›Uw6J;YoРp-:&R;O|G5SZ@m= HZ(|~JH8K|Bt^CW %V`JݽfYCb5piD'Q#aG'"Myٛ>EJK3HE 4:灴K{*Hks$]g YfAT0 DVe-$=j'4\*>}6Isgu;\+q vX4 6k$@İh4{?d;:Cw2r`K#dg5'箤..>Ã(0 i"t(Bَ\LzCGSB\Ү- `sܼd]G}Imb4<7/}3`NrUOsUtӷ&ݞZ3oT?Bu2d WA/ZAaJ4i :i ˢGEuO['9v+iȑA-$FY^Ď8ګZ\hZ&MfWk#rC܁BD|vY[6e vw 9٣`IFK/i]ĴZ!8'v"6O?Zz' oc =&˅.7rAbsZ3W05sVy+.C8T1۠5A?E!y4^տ[L _쏰k55쯽b`Cv>an#Z;mp&T#ӕ,E6ڽoHEm \eq=bK'FƊjP"KdL䞯uڵ%W8@Dê:q>6︹6Wc¥|Îө!{h]gD$=O U:1GP;X`.%^x =u@Q]> 8G~q_ :i7cDwnO%VKq4]l[fksNkfUV/xtC8sI/P˂={溟%-PDq'd-hd^Kӏ5g]Jלv'*^7 }tv^ǼϝbLTHW$7wE ҉hJq8?3/PP40H;02[mBq <vņ%@T::챆goP Sy~ ZqOevPmLC. 0vnc I+wF Iq4EB*Ld+1 V΅:E}[x9^66 GE{̈.&aYzt(k11P&Bgf᷆_q8mX-&#hMFgd@XPʜcD1t#I#0Ƴac #0? pa`ua--R$]QT៝J?Υ鏏rY~j4Ӌ}^J#3C[Z}ݰ=*^G#zͥ'j Nw@>XvOc_)ڎi,B jFm HZJYqY+ZOZ uބI"TbI3'a?7A ;Ҁ(ܨ\=b3++%0y^ l \*6yT6?`bΈL3 ; L1 Άzۢr܀5$9Mbpο@) ]sCfEse 7RB:*mèآL]r-vdwBbK܍R#؋qiyr+ƸqVwyDi "Ɋk5GTDcT YpӲ99=MҎP FLxCذ_yW/S' F||f̜S(ctvY< lv82یd!T۴yR3 W qɼ*QW4ZFcTXY$ʁ~hçO8ȖfPJ=b}|hivw#F\׾Ȭ5!}oܺߖʋa!c((<$ 1#ʘI{f_Ugn7 "5͠ԣX4UwH9s+_u|0?a-;$6li.u}uYڽw MTD/BA|wy%DYGWVQ#qp yuGNa/8'4b w4 e9xyY~hIV-{}1%,~A.J1l'G`H/BkΘībFAN=N $6m>]}pL#mliUݛ w u3'FATi*#n:p2S"[r?m` m~jhg]).~~+٪ZūG1ֆ:vQ~b k,}eCd8 mWz_k7]Q\#^ɺUz}[ya5_^ᏇL|}CE‚zVPbM@` g,e> ~ EtҎv b|/lExd$P[B%!fzhG~ѺG0Xㄯ 4f/倏R  OMHXr  _VC ;c⢰ӟ?ܮoQGgGUlY= Slh $9-c#Kfcp;$ #GMMd90Kw̦(8d if#"'{ (odYї xgSCcL*Ф3amš2zP\tE}:HIqnJ)F#q gbk?p+C\s )jEs:Z=,t|lr=sюզ\[+ ʛ+9O2s)VW+J.F@С3D8 v^$̽3$&8R/ ͮe\<}V/3I,'b{ z4(}BxzY4E =jJEqh=kW4P4ejgDdHz냣IV.*xaU\F 4;]SqJ3X6f S#Fx0 ;_I@/HQ '׻'e FWC'mPQ޼>>/z$Y]G8@P^P=\`ԕή̟r CY.S^Dɋ$^"װbüO,='K@_iqO8(hihd vN֝M @I~P{` PH`U]88Vз/mVxE$ Ҍ0S8UҬvh=e]806\Ųۖ6(V>z(MM2j.ieE jw-n#xg_QC ><͸3Zɔ VG4sND@akVuM`uy)yY4I h;"q=F>TDᩥM8%v0B[ww=~*_& ‡O?]1?Uh,(1<01E(͐^߸MS}KYcV="^-8B % )*#;얆Q_YJm la?S[GC^Ԩw3ЎѼPiI-ͣr $a@jXӧIfQX`"fCFJ.h{r-&Z"8 aI$Ik |4K{Z\gJ j&^VJ7U;tcҢm CR~R!Ϭ06D|fXVY%b¢=#I7>hůxkB15pQW>^ *ыR@q.R~mr[dxY,I$1U]Fb%=}hIɵ :OTm$S(mX,Ȧe&V|ʕ΁saHt]Yjfz4>&T͋MaJsdž.Y~u䙡t8l[ca` bL*44GBpq ,`cELG&8YBsc<܍h5 ˤ@gugNh57 ̧\Zn)IIƨ2|*2HP~s Y%a pcjɷuy¯}on&E9$;aoDw*e~N&"g lϞb~=VoiˈR䐷}Q|n oU ֛,9uP{QM;Y3Q8pr{x_T;&v*YȘ&o&R? nCJ|h5{׏5}H*r$*jLn+^_Fi T3f4?;9`lmX` &5>>޲.i\Twi|wFc76Q!9i堇Λs~C61f.tCi/d8Iě̪zLVQ~zvq[unQtƤ#+Ԫ ,F.>@ 2JW8R)1sxkҀ}bIۗ pҰE+#RӪSv3*{ (*|d V\I(;P *+ =ݒ--z3môsy\֥:@x$٧*BrEwV8C}L:~!QAeu7= 8லȱ~$dHɢUh^־"5$0/u +*.wyg^7eoY.ag1 ~^Ġ7ɭkY=M$JDv:Ȁ<\Δh2h\4)E `,-}]FLC_ѽ, Fjkmv~;@Њ4w4`Q c"ShpE5 __0^wfXCUªY gP'uO>s;5;$dsP s P4)rhn]s;ٍ! pJgk)m[^2\HO BuUΓF%:JͬlW W!WsK覆!,K=kmj2`5n)̣U`d_r~;D;CE!HiJvaoD[++TT.-5r_蒆"J~c2F+#0X.sdmᵫ󽨼Hů4f,$"gXan?Ζ^F=]^$KQ+g7Q/btx1`4\mCUg 1]n5.iE{|O;❻ 8&P|Ħ~3f9Шy=@- ~qāe66.].~}&NŷDmNv&~ f% [}Ǥb[4 ϼVif ? VfTK +ŀ-Ax[iUl]\em+iבP8N>4<։|lWlP2S>JTC"Eq GflX OY>c+g: a ,אڜmĉ^Kf&,2JW/݉K`u.5v[:aS$i ň<(7ha8}a؊߰p —Za±@h)A$inNi? ; _^!xjYF7⢟DPuwvjDVFĻK/ k8\F2,u$*/(A~tߙ)J(*7ieʼnH@ }i5RﶘYIV0FFU;#g*f>(OH;NMI*sstxO(C !fq#ؑE]:"&a7nIȶvs):W ]Ĥ p;(7+d_m&-Rf7 Bp#e1o8ɱ49[*{N.5Z!UR5O'#d_GSZO۾,ͳM(̲- VHJN0 mi0*Χ1'B9 qBC:V^?:&+f Xg!7~Z5׮(ƪ) -%:(.AbҖd@d"b>`H?(T֊ C=Pp/!^=i30ٛ:f53R6>aiW\tnF-XP G Cc}ϤG\Xy:Rf\|֛l_b|R&К 5z{oK7K8(Q{ 4zZ` FƭrB𒵈$,[5z-aP5" l /pL}l9xjcEvǛWc(e-Y${}yf1=O=D&VE-IZi,{^6GO !{ 'Hyg-DB!A[ -`ė omGg3[UaCSO{ɸvނkxԳtaJSzEtgf׺U\5'm+Kɵ흯_ʳ*T;ۖ&S,YN;q_{Nq\5*QM\ U;;" h쑓,MKi2w 6[6%2P( (`}9-`yxֹ[BzktP&*΍>[ZpBn:t5n4lPR6ac(Yc @o??zs(o88Q>|ys:i A"ZJ,봑\fG2^{Rвk+UPOkY+ ;T/3vocH6{ *IHJIo&}d{ Q }jcY8C7y9}͟#bSdN1R6V׺~Lʱg< +$Gs'Sӆv:xC/ Lh7n"] CVZϴOzw1)s4MQHò㔜on>ok!CD/]_n,&5\& @@Z TnpJ}-A=Xe#1uFp$UjX ZޒGf}8Rl 󮐣mSnkˢDź ͠d+gKOdqk.ccpTr"-[0 !nT1j"يz @eϠc"pex.4~SMQ*6Qş\p6+  (P}=qȰTzrHsH a)aktVl!>X|q[tGw|?v04k9٧~)IK2J,MS{Q_јg ]-("璻|_×6> aA+MBwR?qdKI,;?^C;kU kSy]'HӐMɃ:U/U)}(pġzd㵄.pF;v,EhW r4T˃F!gp󿿂O[TFD=LBsIFn}%dD}5'y>2mI)mfq'xuy !}X;]E" J. FJO\Ҡ;]ПqmnO>q%~ nŲ:F"K {V U :_y blJkOȂ x+bBsiilI V }4;( oXXLsz4̣рPlTVWޟhY'${Ncwj9t]*%)$ٛՁ luX!步kKdiMBˁpuɴ=8h9Fn!hsհԗdL| "0B`|=`V-> '%Y)w`wMFq/n/~^Q07R"X$MǚŅskT]ϾY(}iWicIy5C)˄01߈,h[ć>Y؂oƔ9`r9`Fr ҩM'h.jfw*x=m)I,‘ ` )oWY| ^{y&ueqk'eFUنYg9* $/Y;!t }vFe_S"]յ bݵlJ6+O}x+OKV肴w>[fV ꟫B}h(!ͩ[ai=|@cEg`Ve\H/V{jrZbά{-yQ܂=lK`5O"ϫn9aC ++eOxOü V\-9,'(j7DvPAXo jx iS4ϩ>`єJ3CX{I& z 2GoNȷdp'Z pA&I0!IzֽUtcY5']){]^dauF1َ)I6$6w8]n&Zi]fLfaH$Q0wC;>Ry卨;9CRt<;b\T%;7lm$x`YNxЬ@1]ctyPiF./]Ž:&6 <{v׸UA-vC8GMb`Re?J!g((@Z 3B-!šFe DΜP'Ƿ+# Hz>91|;xlI:fԀTD$?FIpa[I(E'1;c_-4${[tn[t~[x紒Ȓ7iMZ( v ?'OJ* d"elӜ Ym;**Dccid&T%)l5!-t_"Z|HFf+j1c@IK$ѝ%P\UKƤG( )洱}/c̬F){mT ǘ%$$ڵQ*u9ZR;T<)^:2C)7Xvupx߂FE̕4\'CQ;'+;/n8H8mqLeE1i 0t Glg ؑ:7|d@N&r SJPk <4 jjiz߱HC"^H>w%K@(dTjnZXGԘ_PU.D|ArUWt29zi}BuBLNTQ ifu@nEܽ6ENZABvOY$S-H( w 67Dne8`Q4i{c#ʎ/7,W|W{F(CA__{`(ve'rc鯩ЉsQSC[`!|ӟ'fI+3ѣŒxf>!XJ_PVDvݎcsER147pju4DAK:xlo13Ӷ36>›HL`KPI?(oD0._I( TOmB+L>OwE1\6 # FLDV`IK;< ןM 4`X'De4|s-|EIBg MȘQ;y DH3-*'\?B!슉N1m*"\g 1^ Q v]˦=_aͩkyzm\T9A| (GsۅF)X(ǑCv^FƻAty,*l6ğ':ڿ7KuKal>@Xd.UN"1$q#](c{"TQx_ <|hV|5ڏQp{6\z!}q nLW8h&S¸yZ|]" ]FaTIj!PL+v45fG>x-Ɛ z0񃞼0EtZ H924\dXoGOg?,a_jDF1DLEDyń wDž'xE5s\ +~Z%c?}7=>抸(m.xC!Pfq\zNbwW^Xey"YXZG<)T~^ }&P7eY5UyaIfK8VƱ'>%V% ,4V5(80c==Z1s˄RgB)?74Ga!IaBՃ5;+Zd!UWE?`_(0*4 O"~EIV﫨\{vAeG.R+}RC frN47a);GF8t-!DC̟M5{&=KF`lnEq 1 >$ڟ=X߉=KD!+(m[40n,/u;{g@P5ںC퐊_ΏG m ;(4נȚfuLhNQR\{ oE4,DJ'Jcz"^]7YvS;lgv,"|꽙.&T+ZM~W >vӎr3W\z|VYuljy2T߁'b61s| oPq$#?Ttݰ5)&Y^Z1 ыsc[s zAM͎pyZ& g8_2?\QQBvH/P?~|!{3m7&*4Ў t.n 4PS_~3=rϖCt!/9oڵ0o0G>Qs=or(M7S!bܶ?}St8L.ٲ?0r0—|3eJ?`u?_Tām긦X^@%1fL BaqvV y'z6s}D-uQ&cķN4[2\j ޼e4|Ti^Q6/G#hY/ۜ.⍍~nn )(jی2ɩY*:'L'su脦z}4ИɡͲr|g .}&l{iy}*q[2^.IQ;H9pGw/r\mRܴ aFC]&{C?DJACع:c QԈx/ܶr@>Iw6%*Nxz4i)'k5XPGM M;TIP,^-[Ç#yEsr›={.ijxR})FP;S M;aꄿy iJ￱5Uc-ɪU>*ˆ32%}@(_t BRɼGLm_p@p+dK8Jpĸ~~m4*M)kQ(=ήU[]_U()=t۰}dC;Cfϭ4,*:}6NMTXff}@YD%8aP+6 Sn@9H%&M+"pxt]$v5"ڝd`Y͔C_;6ger~i`0C\s~!գ*!~xq2]4GX\;gL||;cG)\ f8c%Rt5f" *r2&CjUei8C| IQu;W= S0 aWPt/|j|W,EHN .rV`n_0,I<)~WK*ځug2{ /koģ KpԊDCI+0o3dm&p*b+EYn^?d5ڿ/padC45x|Aޣ){5I|.޼Lj+o%i}h2Tceu #ÀɘQZ30AP' Es2MF+s iJ~묆/'E[iVOƞ}mFRkG x)&hYVml3G<:m( 7 a8=<,*; D"հ :V#[uMڊe5TS\]\&? Xܲ!(>P"9 V <| `MZy[x'}c_ajPg56D}N,ȅi"4mְ<%e࠘̄@ajC[K2 ,cW50|ϫi{=1ܩ?6>hX$lW̑H-7h hKxٳ=FuC /V\`Y#ɻd?aii0m{ۙ(DM(ɭ0UpUoND)>wT!ž(ά!'Hj bW l_jSW9dW@"7xɆ?!ٲWl*;fByK: ;ζ FMOO$%&%?ӽ_9V9|sn`]!TzQm9]0!o}Ӥ߫OBZv/PlB)q ˀV"O![dWeuד ܲ0L|Rvj<.0N݂W^d$aıHWٹ:]MU^;$U߽ȉeobRJRu{"(~+#lS r_ iV.{`[S_c[f`n#Q/׋@&NsCO\$6N?W_&$kϨW 7*\M[Bi|7E^dX=\)=*C Eqh{R9n K.BƁvxqZOF e.:D?=jgߒ ;2O]{!P8>\fb7=@>Pk_.Hp΀u!V26].Bh޹FH}e!JW%LE>o0gQL௸lݑ3høh ؉ ~>ejDދ})Cy9^{`TEDJęuKS8#{QRI]~Mr\wDǴ "vń_Q#cRTcY7*#?C8t͎]_ %t7!.-v=Cc35xn49Ex3:Ƨ1+Sah;,4جKM!%֧S;.~ 2z|v;&%} 2Jee$4t\-M̴CI@[݈S.T?F΢ʺYG߉"mA1_U=c~Z;a|R "1`YlJå( (ip*g:9CDTLc7ǍCAP&Ib e>m9 Q{-(ofR lb'6x˕<fRvuygSk rk(v Z[.٦nKBioǍ3,BMuOrN| Ese ZM$RGNi(|,ujOGaΙ*!Jܱm?-V,Ї(լ%SM@j_К2`p$%$pHT mʬBN!Lnrw$.C.qwc@F;W?WOuk^LٽY ]S]rX~NHo7wR87-c zDro4vH*#wEVn`x0*+/VO]ќ9t:%|N)RYף6 xz+yڮʱ/+IiϚUz}_L9/U%r_E/^E!HBrPƥS~6/X8}+s2kvܐ2US}q g H:M2P0}k?c.QF Ἳ?S"=T} 5iBA=0Bpe|Bݦ f)C w5M@[7dk-`'Fׅ;憞@) dej?#yj%*(}IK %'!n?inS 7N7Os~Aݔ-&{}"k)j߹<\UYٟ&Y9×r8Eiz1vq G 9,na 6mv,کW *Bg?DFjHxK rcHjDvOB3NJ2geTںC9"vWp-V<#3HEh="[넀B< d*UQXULp$嚄5ZX1tp.>o8e_9.E\EhY і 0 u&Y ;9ה~a%|⒎B fJvp-guAtHg%E;=/;&WKkiE@Jv(WH9h0L$/ԡy&Yc<vvk&%{C_taLPIqQ/Cإ@%~=2fS~V%ȘH Ql)iT%P1,g1_= -u֚E9B?Zx4s< Z _H͠tEaQ b+ߒ6J<%n$]5"=:-+bn_?Xd'  Dȉ⃣Ǟ V]%/ }AE_;$Y*\CP^onpEIih8q$aW #\b@9`\6`%,89P 3緳?c\\0HJ31.=X^ `p!#hSnMVk] CT|yV\ R%xG;Rz4!@"eYC0Ջz}}{ڣ5>ו^`T#p ty.G.`Vhx"͜,^Ēb8C!Wt;Xw5s^VOKB[Go[Kv4N1@z-^oO?cTj/OY %*Xd&uŽ, 'x3[AkRG} 1LݥpIK+~ ip-?k#ŸD<~-?+5tӛK[G`{"'Nq1Dc,CUl(Y_Szw;<p ^:Mr5qXP𥵟ګ\%HO%poGcE`yP_#T0?r2MG\Ib4l95y|T@SȍO%Q 7$fAt%jw.T<ҋ-՞ WXIs vDVq|!_ݢq΄et/ӾBv]ӫWKSX$G ,CA$Ú1*fSd^؆z,ϲ,ywym! Էz +92M0hw#ʍy}.ѹcH}oÁW/R1Et%xӧ3pGiqU@3(Q9[񰈆쎉(cv:²ҕ%tL_&]2hs,q@ uT eoIPpN0}B24g1Ћ= tT`4* g& T'8KG󼕙`ُpdEJf,ȑU]燙btO^]I3S,k }q7A/PG¯%%^SqfwFCQ)y ?X6g 6Oři?Zs=kG̳+}\87i!{j+OL !n] ku+7敪!5&>[ t- f߇D%}1)02eE&{~{>xGbb.ھodE׵(kQ\*" J_aWUoFMټpQRnhMSEt'vf.l\ ul 9HG$}= }kk'Cw5honBrU o7D6+~OaJm;$dvL=rk!ev(00G#VM-8A[ ߰ROb V_A!R}\r|[ K%CNsU8|^B4D`ܧ%7 0ŴV#ŭ{; +o&Ki"\EtYގ>t\1@*<zg~B'tZ<[Lz)ĝv~t1`Ǚx&&o1jJ{kqi-chP-LRm>1{(| VȦMP |YgPuH߯ z2GVArg4^\c!DsEQУ4B92\ !1釁߳|2`Q7Ua?HUJ'd[9 0]lnm9. @΅f&Mu^<'';}LN>YmgSe4^ȓvLp"12ؐ0̡2@&.R"v m*TOWtnv`[yc+8zT WCѝ>jOC`+ r?q?8 zo ޥNr#;j)W=+:Ow"b:p& RnN l ԌYJOlҵfx3P!1]Y VJ@2:ۑ{TF -!#;C`O1ŧWAN53SOLΣ5,Y=vT9Ix 88 |QcImJ5e%WxA@sofsTc>PPZ"I8w]hUQOɴm),aM0;nVÍ_C3X6ftbvž}^@۳y`,E¤<큁PѢYxY|),թxrGVWFkMhLG]t&i/Cc'㝱 %rL!kg5#}u*[}k{: vgF/dJM1Z^"3׭Ѯ Fqɳ.{4NmH}7"Wئ0ܙkx񑕱jMdߏwsGbU0X U>HT5E.qњ-/?rGoJR dD_񿇞jᒫw9[VΠCʽ*U  m%ݵgw:sc%%ѹe4>Gs wȫUbkeEO[#s[yy tpam!ԊH=@P;W7a?&@^Q X^.uT!DŽ &+L+bpz-ʹvF7.uOr&.'8Z ˕SRIq\iA`3/*& (*@Ng(-,Di{@T1 * !p~%ONr7%yM4hKǤؔZux}璉E%lAϛ,eR28")4m,jXR$>>yBMH[PBzͅQd"㱄+ 3DjrR/X^q. }if1*5P-wN̐JqÀaQ88*ZPhHSB# M[+`qRhakkkAQiμρ"wQ65p)4A[TOI:_x&p(ذPHecaG\[6$RUTBât'Il ziaaV0Bd{^* /ߥwt€[/k1FelU=B?`!4l;N83d=Ϟ/hR)M=NN6V1:Z%Yy NS;dhNS5Wv+>le]Kw] 1zE8;8bsM6uAnx`N½WV",x+ڝp{ < m`Ԯ dBqE 5&J(#BE)xgjJ s'W|Uԍxe̋]j THX.㽋.|NM0FXҾۥX96^0e}Bqo@2$xƚEӣghc5ur|9S<j6*-tVpJXHА$ĆvA[hPK3;ː:qv0Wn-KT<3H!<"E"ѧf("=S=F1U|$K 2~'0q s?Z@ݻO4%+=tr$SxaJY(eXwK`;g{l)~*1+.0YY7&Oyu:O-`=YĤHkx,榇vA {ķGěqSFT\и]h^T=?jQh 7ceLH'Xi1ZqΈ)<ӟ@ _ufY6_{- Ośۼ.;1i94Wȅ{ZsQwQwC5Yf^)durZ渟_rh̟v#4}3o4 y(6dd+Okhlgx\8zިER})l6K$ɜLڰw۹^g`SWY27QyCU>]-cS ۔el-Lhzd;svAgw{ }df*E %g=/MJlAoPM-Ty6cOfn"ƊQZ<#˩Od&T$ZOSan.3Xlmͨ="隅]O#+ڙuђI^6yaM_Zҝ'=-+A9@1\ȻFb<{7=' bP XqЛ^XB.([NCdzDۋA-gHm_P,=N9msRE&M3l2Sk(?uѮ-m vŭ)wF^jRV˫"?BhZV~-c(mPEDόH?o1ҡfׄcTTsVo؜6塮']+)lfY~U)q͟%P{íKt5'3b-u;vu/xTĞX:3t|ohAXVz u]m.߂bFRCGS$}F ҙ|J!`'?Q3XxiGŹ]\b$r'ϰ,oHE.^ m(jzT̺Nd_&8k< ~D9ԓPTIwJrba͓2K$.m D ׋mΛZ.zj8f?3]{ad5$#HPikѻ.0񙧬wtKJv #TCf|,%Sy?#62DwN3 G*{څ:v k]gҝ/۶poˎt8A,(iQ+!̅~@aՇ;Vh5u7|ҴYzM8jb!cG0;5`>%rԡ Y{k'с99H|F|@/B|A`AH˂#c"6ݳ؁ҶނvQ6_yz̃>#%G| gYJgEB殸KZsHk|UMS9BsV[J }9*GI^ m4$!?SCEsU?ҿp'ݦO4o0XE`h(1;|v%pOd^5zIEʯF m>_}*$ň:B!Y_XBIuAg(+e jY1Se,? t힘xp.a_1Pwfy\%"mpH\YcνGxLmlWf}:kT#PXz=bBYVJJo]3 5ؓ"W4o(Baqo`.N4jd-TmV;ۋ?i +ϤVN)rdRhWZIb9djTtIYn&LLE)*$v4f,f^`>vG*diK~#mzl|"1 Qc-f66#eşGj( \wW X"&Z5=跽V Py22;Cw9 <]"W^+!\1q ÿQCƩH $ǽ}BHDet@SgxH܏ :(%Q}z'2}ZY|Oy]XĞڃˆ #I%BԂ_ύZKjLw(%x,MXLiwR2D/\dTZCL_5gyLj%-Cǖ_8<&Uٴ*VI=WfJdP.\i&IKGTp"d1Rd>zJ \J>uNE:4(PIL tKX^}Je`2D'q iS"kđ$d2"4Ken+%#LXuӚ@jџQ0)mK w= A] m-bYq.XemU5A;& skZvRPo7\&腇TRBr>ݬl"gU [NmUހ7썵_ xvI\E &Q&c_]Tv2{SR@&_^"107L 4|`GkUBv@&v\Qܷ 1 lDPnJ4CZuҢ51{A~9Łb f\Dw9:s-ZgXl~ؒ  ,?@PT?N:$St~(FH?jq_" rmp:Ǘ oXV<w\,}\Efiwk nŋPM>T 9 91/ArvRle_6X l;Ca _S: UtoNb=<1f1,x|YrbuM%t&q3(^s %9d>x*GdM/ a2\+ߎ]Z3Zvqyd5}Yw? |H<7ηRD@fL," B %~+y2*O+>:ba^CDE/Źz kE? TCO hUoD@>d}v"۱ #n.Hx<2(e7R(`iAyAJFqsD"L!5ao p9悚npջN}[?eJTQQ0RZ?%z"#W5- a_srT'e\K%Gd}(B?ַ=yW 3NVEaO16E8.%Œߔ 蘚+Ӝ^TS BPfn֠vLxC%xU'q *! 'J*VD4X ұ6+gFq|grb50)9Qaw$22઎avvN*qkJ;r.('XۣJHnj~18hbQեT׎ŋ1˕}$E>إark(ڡc>5F5.LD)Чv읢Vz͆` Ui ~eW,6)_tKIR'Mtٌ%N FSI7F|[rC70J7IBlO6юD@IR?@W˗=)g&8Lw^nbZЊ}eYQyHԫ!{jrT=鶌Fz\7^Li ]QZ݂h>Hn !6;t o2e;>>lhFQk}}ھ:͋H7 YTz]'M91Fm>ҦIV97($NXka$ =Ѭ$8 (I[Em)F]nsR$1;b'% 0 H_2ƺJvZZv֎lSvm.>M%B# )K7)T;0\4o'~˼YTK^?T.`ig>nZ\ _V#yy猬)-WE7@*|9Rhƒ12x?$V#Ih"iWrdsޘߢ1h] j0Y;<{+~/kkH$[W+)b`]kr=bRTaОcY }k ;L pF~n_ =OIDBfF=hKTY6>.yxb[Bḧ́bpKdo_Nnh9yE4M?cB8#SB|]]S1nAbhG䑒L6ѨV(j.* 3@Rǥꆜ ߾2XUdӢn d='Cwo%ύv1T%-؃ѝRsQO J{b ( V./a\wjUсsTjoS4M~Y1Vn6kR/x7KdZ @mmː |jm7N2(Y"jN|-6h4L)xᏵ/- ^#'*yWsDT(.UU6In[R2uڅ[ bѓ@p6h?v맾3S57yFɬ< %t^t"VVG#?zwwRK u9|UWV#M.߱Uj ].7zE&Ⱦ";-K"P/z9?yjKHh#Q#Pg%T P$:nxR 9gx.~L0C܄$,El?(^~mN?@ŷ}]I]Fn)@Iwjx!8#TGtϒauD\I 0,e(81 JD3 FB>lٿkHbf+r\ Y,ؽ(Y)uy#n삖Tp$ y=S :rQZ=ӃX~r1*Ey\v PNJüڦ~>yÇ}LXGlj+tf"sa8+y l e0ɮ*AA@ȍ'T"㽖p=5׫PU<9_2JX)1'ݠv?R!^.O3\7iyʟb ,ʆz"NHIǚC} FwƠ|b z5d "h+bH9AAor-M$h dP%E{n /Ec,lc Ocz~ FdupWn$hURG8< e۟]͈FBZW(yaf:6`ZYi!wBp7s%ɂQuNUݷWEMޱLWۑ'~eO̗m;4<@%< 4`?|#9(|_3e_~gl`j)޼?m ]=@Dn:]B>6O]<\(_ʏ=a>/?A(6Chyº*4i>F$@R@U  ˒ЕjnD =6ODR8ⱱ0,lzqh:+wŖ3A z}NZJܠ a;TC]̪` $@`S?^Hŭgv1ΟJ$/y)Ɠ$87.a -۳}?-~gyfۿ(D%d9(]N^ŚD>%VP z<W)sb́rC;h |@磢#BhIˇ 9) 5+nkѤM,^Y%Q5W9,+p"CK""^ܯbL_Qb%)'qǻ`AGTa3cIkţFBP[ǹOdM^JM;E7Gm/je:pvgɧ;4ع0ߵOc͘豙FPu1J%r7D]E"+ҍ!G3c#d`Mݏ$b5? ̼qM@Hߵb;@ syMol`M[7BX (K}, @@pW17Ok+OF41r&4#TE?߀D*{ZgN*J@ߏihgv: 3Mn9h˞?,1D:饵#]:9+]<}L $e}3S2"᷍o\`?4ZD+9>mL˶&8up)y\(ocGsV#Z%7.>t}9#=tBћI>QtޠO?k)ݜ sHo3>DF s-Ou<ݿ"RT'rVRRca})j*Hv (M_|rŖOo*/yF5(I0llp+5O?ivx%ˢ4W" u3FY,7fJrMό6X-Jrtz(GO9< E9s-;Bme{͠o5 $w-xMJp6y(]s+ ZLN&Q<m=E"o L_|m/CoLfڐ;t&q YAV 1J v !8@FM|`>M3bTu ѐq(7a`:*dvz͆wgZ6 f.EGdBO>Kg5 +Jw~;xO~>d/2uxIE7lvd Bx?>N#j?b{dLdۅHdT}y Z9RM,5xS<J:=5UcQ 5xKlպTG:SDYYK:'_l*0g:ÎU,~>1*nZ~^[>H@.1eq,U}oZx]NZ܇D8@E HK8y٘X _I={3i'/'jxѶAߺdPHf>zTuࡺē_asso2$w%l <ԤXh]=b6#l;_ǭֵ%L!"ʿyf+n"l(uy] *d [LjmL hq!zI òR)#p54.U!+p{IF"ڊr,nrVr7u} 5=$s+C \ k ezdPf[XY2 @ 2!pɼ3sD8ȉ3]zA+4>O& "[2 3 LVNNDdk.?KGynv؎;뒖RR*xo=%t&y lIJkWyF TgWt$al%,tp BF/Nʕ r#Q@f0Dj;2giɸN3Zlwﳏ֒bJ_ǍJF'pFjQoP5V}9jna>ɭ5%0[[;‡I/*X#R,?-U-kX Fa,!t&d3J=t*c*9lj B LBrhp^$CTvJ]!` ~=;E% R±6:(諷truX`~qYOAej#<+hj!]JY7%]t}G#{mAZ|Ō9)08rt}w53*|s;B"%E6ך:Cp\Ną1 s,n5\U|DM j) G 8pqge JevOt=yƼ|GM^sVd[D&ea~.$e/Ǣl ` ֱuڏTRW:gv+̽aCҧUaqsoǂ7-ƪ W*rr涶 Zخ=+4[&Wybe_m6ڰ?@/o>CF*PV !yDN.ݢӷ$bSO%=9;@-oh}gZ~CxZ u^QHOi5ȗ9:UXʄ=%7WxE)fJcYS7:T뢬ianNKLXv W{ >wĐбcFKVsC}\{ތц..'ܵRf8m D~=0%_j$.`NlGe*,-쓴ܖk`~F-$rN9Dn8`{Kw$js PEo@[䚄_<ƙD EIFJ"v)d![İ D73sؔ&vmNr9|UGyް7-mnRoֱ!?B73zmަ(/o؎"4n8Dk-opLBaE=$4."3')/%QH𬽼cWY1*̈ՅoE,aҎW c6"NgS')J]53Z w [e$K[m|ݼoF79P tHʮŃ-O0718N@k'ZYgֈ+>~1wW}6ZN!ԳÃ1T]= svf3\/:e^\]N0@ 4Jv$ 񟷨OV[nhp"/>[ /%"#l\%]#ۓ \]H|QZ[wv]j;|C8jh |:j2Ǟ:N&)s;˦K?uQeXo55ldiā'YX#oS y1Jߠ+Rn:{s Z61y2MBO enÈIλs 6YtWjR NCdG+R H6X5[lMZ;< fBpE4\WG䧮jcJoOQ/֖i}OL_z(b?5h0Oi썋iV?|m_2DSF9:>`RO5u(vY¬TL^~#L(iےVGfmLW^,@C1EDzbVk{ 'g(R0-eK! շ29V /r_ z TМD2#Gѩ$ewDxIWfHZ*؋U04Qg**Y5*қXMZqwS[Z{rnYO9ۼH)-E'r\byQ3nTL)M}jj CP 'TƮ 2C?&J=oϐW!3`S \CkC(_dcq$ AGGI흓JR?%kzƁ :_9X8Ȭ9+Y} }鿵ŁADHǛ@d#]V+_{͡ @̓Ykcu<7j")S̙h0xN9jr. GY7Ov2T*|]7 {o}4Wm.=0)b _eVd fkj6ˊ=aeuhi@s#oSy ?UAIeo>?̑D~mZGOsyEt1&`,TBEb22뀜-vWIags,ʴp,L t y ce@;%IY&/.~et"k;$SS+g` s' \8L@F눼lhtc[S1zdWf<hWyEm+.J0embӨAޱSo\paqiq}oaO1V BCS *kKzv6dUt5IsE:]׆E@NT\/ -6r-^"K&&%[n9B W-׶I2@_YX4 Ւ`pò=c a|kEEg'[MQljD)>d`N 2 ) %MH˛ٜX /6_)Bu/ +36`}g4)C`2'zf (FPg`|فyF?ѰTp5YtJlyq6YUZ}/GAFM]ZQEPxmQ&CWXƎ*4%rT 8;b5<%3RYHSgF#G}pXe2~`iͼUtL}3#"lLc\)qL3xQMbԴf)?wqR` N4B2"Ca8O6 'CUۭ+V,᷎%JzO1giq{?+{taU8!ɕ-4' %g4S.'2knZ!-EҌn*k1,QbAx=m,P9WS "gsr+|;7%x)!mmGBinúw~}^]oJA,p'ێWa:m/z]iTC *RʈP|wYȏ'?W]\c/.Qk7>E[A[ħ=F:LNFWB?3ddG8)rFmk"7;1(~o!Oʨ5c 7ٟ[Nq3J5 *"jObyl|M:.i<3iTA :f$U:,: U)o@HOɴ kyYW9"!nZ5qSLJW%%t&.?ZՀFS|j4lMD«t 觫р1<``"T pv}[ٹ`P d#]k||}(UwUtxP>geI%g"Z~AQ Ycn=kk6 ]b-(g+aGK+F6#6)A#}S`Prutk9l9;\Aw9#c-2 m NVT,G5Whv؞TEo&: k*g)@SjoڝŵQ ]ʾ_0z.khc@ab]J}fLFYjY!͖eʃޗWQz)tᨥdĕvys ֤ 6FԀ쉢Z?shj=ꇷVܒi]lPIek=t vZq?.-mE0x F=N}~s{m`E7O+ڸ! +yevYu|~wbr7wP*$ҋˣ,JZ秲#=QQ40>z̈́,Ѹ:\#f{I/{.<|-* *WwuwWIʵ c5c+-aeu[<ë{GN ZO."susCd \!&Ny?w ?7o~{*q=;~`ʗ7瞈#obO @x!KDqgqMͥѐ^]$KQ#=.\wh|<7tw 'CNp !y1g:RsO/ypm{[?M8p:b?;ɭV'gmy(W_d7o-49ޕD^ɔY8ĴJIX:eTVU.ঁgGwKMvVTdע9#,g)u@ åmU)$]]hQ${-4k-S+?F Ґ񾜴d#;t:wv,I8ԍKYlL]=-%zEѯ 6ݛokUgk sFO&VR\^zhT}4Ms|9jbρ(69-S狕%'i.;wS9,K/fd7lqϹ5En>xW.Q,wڢ^#E@'DQ D33?ڄarj32g>O4 Eĩ1iuILׇKAj05Q#ΰM 8PgjO9 qT3۵4Sw^U>x,7H<+MК! +)@2(|}.((h>;H k*S#.m/0y=!r e+\E<,tvDzMӘ:%+ zrf((Z{+6l1d,FGy.0[w 9xr5j:f%73W- ,c%PjzGb-$;]$0 TZGe2TLrtn2 7zz8i6lWxiq* Ei:@A4/IX$TmRh]Ӵ{ەp>p)&f#*jKvsfj\/-\]\;<̓摢9,48R,^k0smȘY J a_˺Ja04M Svkn}EDE3[XNBm; %F˵ǙK7lqߙ`~4#^oZcV47"y/ 2A擒{`)9QA:|VeOJiB8A>] bTaLp.̮tӬoݓN2s~(jlmQ"E1f /yAU7 =@nd@ iY89De|?!Vk!c\$U7zаÉ H x$:E@O 28SY@ř6^S@}1-[-Ύv< x! #B%/D_U)$Âϣ%ҩ7Xe`rbk朥rDpL&=Yi&*qԼ×88?1{8W"x`]Mm1eT]g1 ^t$NXfoc WHԮ7@ꔻ\?ūoz?xu^.Wcp L)QbSW99=NGZ''ЊlA8"@Xx*4aJ[M#i//,'dƵ,HґT#1\W2G9sStъ3\ajD I?13SB7b2iKG>F|}2J4|'N溜E/t(B2i'M԰s0vFwNŕ̌ ΁ɭpUu_V0W+n c?+~$x6FX؏Y7osjE 3+zڎ޳ {Fu64ښ8x?+5\т1Wrg ̓ =UpA'X{ Z0O̸i<;7"ZEiWDSm̵e`/tK +']S+F<:B{T ɫ}cyLBEVq7G}06)n_NPerHåSlL?'咥h' E0M.3ZaA=e󍺸oN*tJx^3sb1W׾69Rt3U{ w}@B .&&| fbu$Rwx(v̛>g?B6yQ5-%w;X_ŁB.Q)# ;UarU:u'b񮧙a0I91TSB$#,lYVbCk4woQKO˰J>O1SUx'rs&T,R77/g 2& 'A:?68W6U`b&Ć{.h+V^cI㏑!^iW%e;? D%5Yo6 5뉆琿Eۙ6۳Aas xewWRl4/??! {Ip Dӷ"2Z4ۻv?mQնΓ!vd.{uUM>@YIk?y8Dg)7GJ0~I1t (|L~2M >>sfz;@#>2? FitvX]8Be^p~|^ZU}< s)dQA`|IUgVwz"-懢wyVx&rߟ|HHU& i=AaHd? =.YP`GJqRH*9wD00l/`QYU+gQc4 I~;O'03~9UzL!0]Z,C5x,E>9c2GjAy9{]ѽ;`l5̌x),Ylj(㲪 '(e"e/&p> ;يBڢ)xy2w_UP/Ul h[ׁouc#0uyTzʘl4ssÏgܦu E1u7#[cGBe(֬,pe!wv y;Gx_(a (@4f.Y_~c^(l qAC}wm]BRm<d ,@ӊC ^)N! ^̎ K~1s%ݻ(XTR.U%cE sM͝H+ v@sP] x){2o`w&!MsZ TI X\| CE+e%KQ|i] jb,NDȅ +K*vTr QI|J49&AEF0@޼e>(:I)3e:ʃ~Aڞ4Z[G רf.*kyVcNwt̯l"q=E%/9_&6Pm~fM7Y e=bBs?EqA=·g1 n?'D7لQ⾏U`x<V`9NtF'Id2ءWv),عo7lZ+]'tT >rf1mPԥʐM)/-3+C&`cKljDǣ!U1OCl#Dbi vY_ϨǘY7]&1tS]JX5& J_j)v @bIxs(m\SE_Ctʃc)/E/|lkQR;z񒋯!6-4<Q n<:m"H~Qq8c;HU23iҠRҴ ӎUWoL @E\E-E24IzC`ֶ˥w f{ n6'`;r1"lq}ݼ=M V@~ S( t<Ciy8Cj(Йҳ}ې7:x5T ͲYFfJ0=i}?,Xa@__- -qp1/e"Uwqp7IM gH;{ rWp,S)$f D0* "d,sTs2r>QblRB7A{J5v)#%6Y+φPM>`D$h%Bib4uѝzx/sI𧖟Νm^6yC,](#(~,cs PH 2iTk1Ġ,-r=.ȎHхR 䘇ˠtwH{C]{'PdCd[ M }:um*7WaB|@p6-^[L[ h؊6Eۣ5JzfOH 9MыmGQ|gomsXYV3\Xp;msu\ZA:ɦ{T7>6HVEɇ l&_ 5e5F0<{L A5%hk ϴau +@]4^A5*.pfjb4hΜ0 6uMy+KSokAA{ahȥXtŘ-q,Ф3Kiczi+Q܄TNR<GFEfm>BQ:(zi?zσI4(g_$*0ҔT| )ͮ >REDDlL7r%+'\a}6/kЙ?9;&fiX;MӒ\X&WUIVOun⃭3nZK_ڌ-]A!}IA&{N.ܝx~ zo=I"/6;d{JߛN+_Z>F6!{gj,đgmeZ].x8C ݏJ!MJ`}[ס\V)ӐP@pv@/[lTL -(4e?'=gh4=XO.BPl_Ж;419ma=oH咐1;|ζ`=sϯkZkX)2(Oqc,-di _:JVS<ʹyu^'lNC Tȕ(+Dj`~/_bY<0帓Q~C'_BakM`?F*Qc}RJ]-Q'KCL㘧C,[rk7S[l|g晲G8;׃[5e/]=$tJ%ي8[yVkv:3i]Y>. ڪ_ k2*n:XO,IQwEx$= @( q'.2M_R[hUC PSiKZ&c*ƆshQ́N4%eE-^Sc)P sC\p rlC׽,;My19G}xY1˷~ 3;~$t:ڽOW;]V; i.Od^M3Z,hQF  FS+ 2 MAV$3(OT | CX\%(5}6i R*gp3s=tA^L҅IFiB_+b9!7+5V4Swp xKPaϣY賍?Í "HS#(- XפgSl \umQ~HۋH/whcTa\$*ٌ+#{iш}hv$X;=X֣ŭ~Zۙ-mЌ6a 4XKklEh%&|/% =)A!V0`P{iLG(~Lߒ:He_yƻ-IŠL]FĄ@3i3z>YxXLaE|O@u"&,`ZiFީr[[3+$TvX˧?-iV"«TSZREYUNI|:@Zeww7mZ6ߗ]3w1_J“bNeYo4șQi,Sh A_4A}0`O^gRk6z/7'ܷs1:vob=sl&ŻB(!z =SqCE*ꖹ `QDg$R HA #˒Qwr3h5 NV\t9oK7t>dk!CG7YZ3 цw*qU S1s3d6%zbZ-5?/yy+68GV"03Ӹ w Q^M 8u:E}aB0D#s@jOT<I ɚe}ES` F1Ň^)vS˞NK+ef%z7qy YĀ \Vn(8(V2krnPEE AʩG,E8"['w=cETiLfw.wS&P" ԛ@,UMsDB"4SeQNr| my7UN45bXƩ4DͲI~ ]g3*HBz NMx8=(,zRХP5.Ȧ@ }*iVLFtuJT-'NbȏY30& ]qn@H句k҇9#.%Bw)e )+'1z\ZFC^pw{8=*P;%鸻.+>r w$1*UDa8>v1Z*ϕJSH2%X|S8`.kzGC"Z۪T_{k,h^m lo] Cgmy&8^8!]K FFuycc5'O$Es"$n % Haq{] {}[_~F$>R">0±: i -1clxh\\?cLj3xnw=@9_W"[la~ع6KҔ"SbE&EmJ{iG+n!Gꧮ>zzLg&%&ܗ?'T5v=uFݓ;\ נlVS!TfAdu*h$9K4]üplfyyr9{p[aS5i>S+ 4#c>[d[ {,ʇRSҁ^sBRD&'75LI IJԈ];r*GJ,V=-d1Q.~.N87uüj*h,62DWY'8L 3[SvyߖPU C+ S/I@dsLL7lC2Rn}iřa}k7?2>[{PmDsFbẹqKeKi z frF?NDK(4HmX@P 3KKrk 8!K *\;k{vvlsDUt6Z~< uYE,m2ũd ,ǣ|1P9?[sH|Xjc0rBB%yS 8d #i{dv^ޗܜF9BP~nOӝ cc<m 6~>a I }ڂwv"ɡUWT QJ4E`O ~?o ƫ+w^\mj7fLO"Y 1J}o}?3=ﵾ|O g { \.~\,mr;[-+v{gYk4Jʼ82 *MT{z {bRồXrI:8I 䧹H ۢ07n[TZَ[#Mm-*;84AOA KL#^nuhdkǶpy$k(H)MZR@k5'ĝ0v;hj<R֦IF\6 oqu>|dV zA@-r-\i'+eid |zMjQXȳ Yxw9~tV3-ĦB1XѬv$82"|z3LYMC/?[t֥si>edZjnˇ9H('ik<Tw4j085Y;7lWLӌ!KZ}2rVG]H!\-罹,rr0[(e͝^0WC5f\h3Ҧ:ϝLv4DqGzv[ckd97YA2:6V>aFGOkT,Πӳ+ƢXj貈!vRĭK TϊL̀3<>=pp-%m>|tOitggKq4 SCi#:cdV2Z./YAP;XP@aE~ #H~L@mTr~rC'6lh5>7e!)}_Cg#й(sk;ZK$ 'Q'~)}Y-9h,7SSv.3Z·ICS 6{VMTH" *!B:$MVXJ/\ZפMBswcz_5Jߒ}D|ߘ*ӡo q BR?4Q31VD|ip!zjsDmbYOMRT¨}ۡ܁6O2x?i}+ *]A_/b ,ci{ DSC_i ΀V-xꜰsX#:µv s}udG9Zv?F(K:L)Pny`'%9:OW̘c=u?LK{M,-=5w@_RFI#-ork+B rC'G# b'iwPD'qZGZ^}iޢGln5*jt ߉^ID/i4ـt*-ZdwŽeV&t~d/&bS2GHH8>ag .C C?O6g'jpϺΎMa8=! lc &-ǘ/p!߽7X ^d0sg\VQh8̷~2k}>ZTf_rɊ^;+MLuzCN.)>$ L'3k$nFqNTd[cy˃,xAC>}uzeV &fhV{.<z[EgSD g'&ڻ{{`1=nh.II,nܝ]U1*K PV aؾ^xQ9[M=LewHټ/y,Lɸ2|5;{zx?-iTx yOCNJuVhmN\ʪJaXõ#cl0V| 緢s 'BeQᚡZ^=ۆASYA Y,qCָW14]W⑅(mNl -Nl0K*v4;|8E3F: a?Sq=(%mB 0*L#EzI<,Ō}Ie"d2yhB7p' $olԤnE\ έj{5/d2S^.ݼBq?Ȇ GY-g1I^aqNRLZ(DPʑ#ͫ MK{w4)ߓ-SUc?k'*ϐ3ʆf{g\h]ګ4R"Udr{LRN`P2 w) x;%Τ^%*}^,O. <E,GX 4q_@G !РKsL{Tص:awxx܈N/rYxicMJx83P;5K S]TW1 +Ɠ%ڍrQ;V[`(7M0w="сWLhv.U~E=6`RnN.w ,Jԅ4gRPz1|6 fG!`z- +0&%'Ňs\7r&)vj?\Β E50ka OuKU9 ҆w>/a])ҧe_QK!cvi7bS6~nڡO&!S\׵2ƹzrˆ-oNq+#]D(:8l|  F7ly~2QQ9 1F4\{)53;wKPqߣ@X$X3A{hxe >}bf_]"b|>}Y1Ќ#_0RN͞Q3(7xU|F" 0DuoyLOүPˇF$CUdP +I9OYig p/cyMj'~n9S p6ePA@!`YfO<3v'#s3޲f{d\4YmOBK!QcO)(7)}`e«Vk( ƶIT9^idqۭʃhϺ*SB+p˫#(r%:IJdޤC&rQa@ wgR,0rFMu#[r$b(_0KTrkk3&J?a+ـn8HM/7&;XNM Zksc̟WβsfEDA69im*ؽ{`չ;`p +%HgO =} od}B؛ѳlμi_81d_1" b2,+!i]\ܗZa'vN`vuu#@0xsek *;g}VCR2 Az"ɫ,3 "D|m O2 jcj f4Kԝr4iTG;{} Z?\t軸Oj]{Crڷ%C+JA,X֙QlϚ9B<4#WJ27▕;O!FĂ[t%'%d^YZn1 ҆l2YPNN k2wH`! x}nM7̥mZi+fvޙ8qiW55*ΙJ#krM}?tHdOE7`L0 8/<vՍb"/Y${w*-24Lâa҈:rvm+xSj f 3o_j(R$VFsbSy@'mfo>1*pzM"{n /0Pof ~]Ll H QhaC0Ї!KCqR\t8ƛs~!q3B. -`xG>/"E[$ yBj@sm/خO蒿k-1`TMHc,Dž(Ukū }z7!HFCP^@ik}!f\7>رVh1iby}Rc Birnno~P?PuÅGZe2׀ms5dVGQ N^q"I'0 Aղل=Fgvcቩw*'ЇRdwνX^sEBWAQ Iwtؠ8!g{n}L+ ?SGZN$_|>ێWrɡLѺP4P`Yy"t\meGuys6kP/s.R%h>6 q51"I3DCc!rw:)Ԅ l;{i#oi2vBͤc(:q ӫt`2ToPx8^u͔eK ~^ɉF,qɄx(ۛeyUw{ 37팹hH1QD([f@:(* 0àMgRuݙg7)W2sf2a>Y]w*gqv6֙x._]Mۼª\*d kmeWxuȤNF%ȳ$K夞HA+{Gs쓨A8vM,/&A[~Ɵjp / 3\nhwvmr H{JnLMڠ7`mĬ{n[[2uvyēV$ej| 77O_N-r~!RyY8(J!~O㥿N$O;/oazQK\f)j9< 4}sRcOcfA|1B(.`i80ݘva\?̿v̺~ =΄S2qOz+BUT ,EV#:Φ׾XqӨA $ו~@D&r~>hM suvcܙ"h|k,*Փ]jg﯍dE"s'K@߻Jw)±ťrļ^nYXy_@5_S]y% jcf>U3')Ed+ \٫Ց);"ٺbDEe.$ZYs͹ IR*Ԯ4:"&QjWŅǚ 92-|:|ٔu.,yJI9*SBhK a{v5wuNc.*]$D|K L a āBtIjWףboP-Z&xBKY .SH_63L,. 3 xW1$yնЁ](a@-c(| ;?vgegc+G*Tp$M;ٽ`9е|sBwOt`27K3vz&CdD*ΈHjF>|}Qb5Ƿ>F . ٍn'b4F{MBH>qpr^h͍rI-ĎwA?9Z*v=PYDTOB=nPqe(p-⹦k7`L9-ZnHmYLW ++;P{PǴ6}$I\9Ej:@'#枿!ΨHu3X"dI(v7ztrc{1z>Tba'$̐I8V~B?O g=(D'f6+4F`!!Ʊqvٹw(gOQ*u=Rd.BB􋜹Ps}egdEkLJ?s_o_W,9kqJ=&,7/\;oQoZIQD[g =GOwϝqWEN2{bHp{֖'`7D&s(ۺN b^~v>:nC&|zO1[D|wg"IWQ+Zp }'NXfSlxDG] )d[v&ʪ/Ì~fԖ>-7WA3up"?d;jx (Dr`͛gayW' yp+-]FǩvP)8ܽ9;4-PZj{Wz$$# [ i<%hk؄<߫]M$X[BnzKv"'3_* (Rgz̙$KǶ A,5Zg y*sC:[Z{Zr0YNuVM8ćWgn&_#RAڷOzg>^q-8tHO/KL{a/~Ї2l]BG>dkx~20L9`f©@VKz& ׳TiʞA Gkw\ˍ |ऩDsXS^o4qH|ZfVc"Q{">PoG^T~xbjbLHfF۠:֧p?|/$lL.J&2741O%Dg1l8WiCgGۼ?#TFk߶;<۩]f=U. E qR^C)>%5lѝ2֫Lra$Wm`c{ow' Oիo]bq b+Mȸ` p+00i'teGK#$jR-!CF.JPߣ:#C@Qd 79esjUgRD]-A>1iCDg`ax4^Q T1n;#Y_[DdǺ{@b ɴ`Z|12[ŤxP;pFtL<8lg[oo }8Aְ,®{AG;\B`/06j+c6#dSD>m֙4]> 1| A9:%"x^eB|G) ZK s3ĥF_hKxlR$ O;Tž:F_̾}T] u -V D@᪑N٣nn O{Id2Z:o*JINˮjGw )1 v;7L礼o?cPqLbʘaK\q:]yfq<6/\;M/RLOZ[#ٯ4zg| wFYy@[L_%-Կ%uج^E9'+.No;c6XZ11qpho^t?9K":5g6ZA+9 jo9%HekMIy0N1.ڬouc݌:K1 i'^ԱZBEA%':8^6Jި6y(3t!TI,ymԸ8|M\̴' )A>Ų&7` Dtnτ*t nH $ġac=#/ج][ wC/FC6^ؼyf鏤m0LkG9iF3LwI^fBը)T r?Q#!ۖ2 \1 `g$E|ެL -&e$9 y/IR2 UØ(3[dt?oi` _pтѢ-JNJj'8 Lퟲ.$Q,TyǢu85 !t!3dW g"u\bM 4˄ J:7ƞJ&`ݮ\7c6O|LR!iֹnNGy3Qѻ꩙lIOx:h)|S4I&8>o9Βg-7>'~Ra?]JQZƵ+p_ޙw҈eg _9W1z8AqÂ6)R )+g NpF֑ĸڏ=W^KN\˱P|KtmuGgs_U༐҇1Ũ9-m'thw!P=[=̍.axo(ud϶й7jT' :+Ub}O.V,f@ 6_ܮMGA3c÷{]wZGK~ yn*U/&ɭ魦i<6^!DX4MdȘQdJ`?nὉ6yD`:KXa*:˪`Z BotR&?8LٽS|K㬶OAD~{@ )XO,0,3q2S0 4<0 4/FE;Y־9K5dVOZORksHBԺ}uo+Ϩni"OT'r6L,MqgAYf#KG\'\`HqMɩop~nƴ)BM "#=Fs8l'jMs\!lHkza™@P$ y0D6|߽񥄀/;,BOYu'sPMNKQo>Rd3ӂڧj%}i˟,1©-!Two} 4Urِ3|vMql8E:x"7}T ҲKslHV4f!\GgˀlO}) m_q$6rj(ہQ}P> rQ[gzu)t;ʫ(.e}}{sq6hb 5(bk`3WX@^ O}lۤ9Otb۸ei>d:] 5}|,iSf_odZy K# &)ls~M`hF^r ǵͼܵ,lOG3!_ aVWarѧ$宀XHD``Hr~rwfp2$CڇN}`X9jf^ÁRңhGnk&B*ݾ"DvSzdZMzo4ӒPQTwImLSM@}L쭕|Nz *Dqhuvqu|XpYr]27 z feаPwk'q1` ;a&bS6[ӿX_+@ ~:ܴ7Js([_$#.w:4Z&C,M\(w7gJ>L ;2G52O>WqGqz5p(F`4µPrsJ}:1PL&eZLª ^=SrPsPh)jjE9N{&yS\wzo^( jpE׌rӥX߭_qj,'+&bc\`e-2wʨX:͚ӓq'%A99؆fbxܱT+f(zhf iAMaE YuBkizE*q,b^_"evN5DDW~ }b"LqI3d < Ox*\[@Ҽ)[Up niAj>J?? L[&Qc̞ ħYT`Md>|M53fv;5VCu? s,vJgܕ a4tH"\.'Xq^whYOZ R{U2u6XPF D5o<d5mfi[>7 '؋&^DsR^JG^(d&繊nM a9E[r"\7vjBtH-JAi/Z2ʺ؈y2~ H| La=Kkk&P/{0<ؙIеd'+K2M ((ߒ3#aºhSD+cjy?(e+oWH'/seVӟEJEO4RĜ`jv*An).rz/V0I:P -QWLjh<ʜQq;R:E36 8[gP(AQc/HH2M*mivGeOd)v-<jIn{qȷu- '0k>Zx.`aFH4we$wab2لfGz\vuYuJcW6e2*7G>:-9˸]EaJ}V ğf1,BQtv(' ^˾ś]Z;t| K\~tspS0ʕ2=]brՂ3=@R@3P^ qǦ]IލQ4~_v"Djdv"Xw׊pQ>ܠRa78[^PM͹Ǹ,aѿ3 Y7WKF3۷{9Eɷ{SC1R([%I.H K,bz[HD[)^x9uE5Đ@ L Y ¹@1F% MU_L]"bo@uVCWfǀNw)zJûS;Qj:g+M≠v#P{89i m!>:777n;g5M ( "_ҌЫv%jR0,4K&M{Y2-y:x>-M(f\+_;y>[ν ?ی|(^im_|4ya)iQvX>f oP=+ǘRmVnӰM-Ȅ>e?sM_&X?v,ދeW9d %G+ Fx3ɧ+)W"kZ]K xFVFI#i)H sIN7ԤaOV 9WK'9yܮF I^KJJ鰊Im0Mn]#ӏt l2 ?-R $pe{OC(T܋ZU+UQl%f=w\o8$`zb4Qu8{ԴR/9Z r0d7ɬ *" 0n+5.<$\vhN==:b̗uۂ{)he-/PO -(YCgrSi' =f ӸG=Cֿk68H]%9e҄[*kМp[f2GJ. |Thy;mQ)^)RH{ًզ,ئ?=p3PE4M3j" ±tdţ7ND=NіsxѤWs)2;ⱖl"UDzhlG/t뻩@=c#~RjGTC5߿Q$`zP1ʭ\DƷ'ɸVkU2ظY!Or:}fsyԓG @"ꢀo6zCɓ9gm4QF1N lLydUA+ldwyys7(6~;=,ͅJ&\8-*(B8ҚҚ(^ZO+X/TkL>+ 3f ./ 6cc1>(c]e6st$aBҴlc*6GԈR[X"ian[,lG 5'`닛N:av;ϩf9HI V+).JMVxBMqer~.[zA(@O%GsA+ezPbWF ҭ<뢨rW]KA(K6Ly.4Z'ꎠ]$032_Uo='nSq,^5.SYa UVFK|D'#4>yv4&8?q[Zg[H!P]v v F#z>B.dSveO1̞0 ;Cu& 8ܿ-vH~k_ĺBy\^>!]j3D,pu38 S7s˶~n Z5rmS95 #kќw 7y!ߥqn+ۻE o+kYɧr5+BI`dYS,{xSb|uя;Dg'nNF/m1g䘣t-kЮCqzefN)݇Syh%G4>nrO_8fh6n7T7qu%ǢVqPT?F\yV$ߌeO-naUȤUōI87Dmb,xz w(LlV,#^끆NXvE^ cڀԘOJ @Hb߾=~QeTTdЖ ->/sl¹˳1>뇶*-wO8yL+KǜH-.YJyMxCJ@TꖇŰB| aP{jgOeB,E tg;Z Iw4"\CꟐ?hS|XBp fR(ޱӀjz8˶5S:x% Bk DL# m Yw(us*=rɒuD8o4d)e-KpC;HY{;4O8sqYz\b˭)\@Sd3QAyPA뽨,2@@ֳ !S1_DbZmPsn!vOJ*ʱ44},2kgr/tQ߯a~PY% "D{n~m#){=nB(\L<,~ר Y.|~ "%~(yƆg3HӾcMY^ДgO K nøoJ4twM!3iy4zD(lm=p,fT hL֝=I&U,cGE!䝔Ӄц?7|qp+b5yZQJԺ8Y?āT71xs ,˻5Kqa)'R`.)|buW.PBF Y2 XHqp{w'j3P!P] | 42M3?i+O 2RZpgHm|$b'd/wVs.!;" W\L0COt;^V1ڮpƶT7Á5!1{rk^T25c>Bgv<-t{aO";Fw\/WrOIJ){O2y 3cPZ.b*]j(.f$n! 6ڊmfcyE#|`mw/6 #H,We/6*! mUDT*|n}%eEU63a0!HߴQT, Oqm D$1zלnQ֞ m1.@Ķ5&.UƲ?} ^KN`v:w%]a5t'V nwF UCW`%,<쫆+/_`q<3^J ]R>b{J OCRf=1h.t= 8iIDSTT_*ZK.RΌg-m{V(Giq %7@.,S WPmRl1;10IE3*6?s`T=c]N7h]ȡд,sd`g`a'~{x46U&;:z]D0EE~]_0y nU9:Dɣ(4˞gEq[):󛺛4{c0h#,A}Vó?u\v QgPA>|ˊv)c@n#Wh0h[ T4d9?OSzTP6B3+..*XSFN"ݩxmmu`5bq(MZ ߨu!O| V驑<WUX'4 ^[bXg(YP҄n,:$gD:bPĪCYK7`~+jeqrDx@YuR' p=CYk!ƺ"T Gڄ3:|vXKK?]]K~*R&eӐV$\j7 09.2݊V,u*Μؕ^*M'tY7PwTpv'F%v?"h#$A6˥|V`&N6p8fц_3)VDI?LNZ2VnNP@;fc~juh <ρ/p,x#dkGJnd.w@y.aMnzJMrZ/`nL)3!CpEXs#Sgpp.$U\Q`ņ$-e%OF]lf׍T]ޗ:>&gKlN  Gۿy5c3 ?(z5XYmX{}ADvͣMŃTQ&w$ w/^Hդ _ $[½=܊;VrTa(skaзQasׇ> Kh U+c@+&ק)Nad~߄q ae矮FjiIw륪,ww!g{bU [$;|[^ƹlU| +>M atޛ弘Q= p+B]sے )'h\ ?`!S9 &۴Ko!+L4\?B6|}k]aޫܦUb%:O0*`؛yo^Wᢆ΄I3|]xY]U*HdoĿ3Jlׂ-ˀ[wH$5^~x@V OV~C4ٱMG!נڱAUЖz2=D.N2i;HĀf&9ӫKn!9^;.M eiFa25 ;UCF瞕&bIig2%jm[I\'PV.ĹJu_V+ݖ[ 4- uP{-D[{n4YzK#clyD:̭ @<cĘCuGvH䬂r#^̴|@nփܵ"rǭ<:8G+ݷ}Py_-'- ؔzE-z%YH!39aBC3Eƍ0@p{AW: 3W.&4 ?N>/"`if>M Vi=EVځZrL j#jidVSoH cSaa|>ڔ5;ZÐx@eΈZmJi@ִbA8=\<|!8N3ye)VX^BqR&9{SknOȈJ5_] .zڄIL#e 8@>dta%_rϺFSVs"ڵymj |-==Ox'ifrW/zc~J-5Ň$l9pi?lܟgptpee27~gM X5` km>8c /%h=`P,iGH/ nee}ivxz2Մ,n9ܘŅN5僃XSQgҋ/|@ԐX:WϷ/I 8CbҴZW)V9-˧7X)Rwh,ʔkbw7{LT*)H);ZHN1)MG ]h֬j _"[}Cs%yG7PXb3ON%T+=br]e+]Z Ү>r`ٜcY !.GZX0 'x.@Ѥ#2RW2oӋ2q>VzL,QY4':0vU] mCQ`Jc1%@P9_pUwq(F[:fxhD&mU"^e;]]Ty1;-YXE߁a9, )ê)rz%r] en3) Æ n#뾫pYc! /*fqiPgźJHVU` qk6^:#|u[1kJ5 s<:©VaE[g,`W*4Ev")61ɭip¼k5b"@ʣ2U v mx|,9%!!H}t #a;C\iW)po8yY:t2R;m?2$+VdeE\,ZJ(#Go!7v4;YϪ! 9* =5i=r968/5w{rpc]uwgc*L zlLthк|e`o7$ ~'b8!M<'Џ'd:\.C*{V(4SE#D 1us! e YܟZoh*ы?Ǜtq;v ,yBh 1QyDpqvW dFR&V2IڎܫG"  iLPfuh` #2C] ,8vq- ^u[jot@eK! $> FzQnY6<[?sԪ([!;2cW)yz#sy^(W`%Tp^Me4ʓQxPJL{ o.hӑ$7iwpXU-2ktCV5S~bo$Yk.SEb=V?ع nU$uXWSكwQϓֵ47>g +y:Pa! B/=qWlҗi]?,_i,P!vԐJ ֧V[\I)ůt?YJ*YZ,Or'ϘڝFPS@* ʶI+Ar0w:,d$?vWr.Y-~xG+6)'V L$C̣ѷ/+`kP>H,ۀFה_rUb""VQ5l_2=QU_l&|G՚3%mA8&#4K_d>Fb 7(=%7G З0{?v_GkH? n_羺LK8R]GƷgȩ{(7;2ΟVT)4dlS- _bZ6>G?_ik|ttRȨ=wSe=œb2n 0 AVY='AcBup7iO3z\ O>1UҀ.OpcjKqTcVᬎPq3G d!MMNaH;wU.1; ,UIF Az@Emq>8pT@k=rǔs+󀛤K[}G` N;/1"S|\,OH;Z0>'ɗ{).& #du(bQxNql45ԅT]QxpG9"> _::L9D[c{>?w<;y0Gp3 %0ɉ7~"Ǹ>zcdOb8e&K [iPN*:}':4hum_?а/icO}cYE5ؕ9P͆fmfpuEmv KH6#~Rbp+c:(s1 |cm^A~m77::Y3}l}<VbE-H~HѺpLztWjJ8 OAMGٛxcg*$"MsWy$hu Y5; DƳ)3wxzy8YҠ&51Oc TVzRQ3,_ʁajp|0 RPkdAFA% b b PzדImfF\uԧ@՚v&W4HoIɿYryt H8   _bľA!"ՄC?.use\TH?jc ?Tn 0Д`Qě0T[ FA+A__fK=QهΫ V3̞uV `^sץ1}5yM^(UvUE@A |+pp؁!4t<0(C!0`%[*\R۩]@XRV6`VxZjܲ]Vx<ɓFc_϶nz+CMk\M;Z[9 H̥=GwHf=jx9Ћanǖ lHCk r%=5[)i7ZM N%I |&P}0 rl=FU,E `W$8ag a0@]_.sGCߧ$-YтNH[, x) 41?ց|^\N>vc c (?e=\T۱٩ <m PF(׆xؖA<_[͓`jNi"ߔEG{9 `7g& epN >&7Mm&{n3yDx{HHIRO'03 M*6dmږq~o8^N?R1m2ڄAUm=ȒӰ-l<x.Mx솞sf}ʨV >U]&L Zg~ l廨CJ@.d8q^d-[) qVM/1lPvlKx;t᫤ {K$%زFq.h;yrVZ9jLm[ Ȼ$>E( wsDF#;^ {GKlou܀6{)"*ό@' 3e"St.lx QWoYJLmgrnZ)(ڸL.[`ڪ"tka:9Y=0 :!S0f2pB]=qveil^%e-9ݔ5_Z}ݙOuZEĤ@eȫlZ_b1Y&rG8vG6;K7u%৴)u꒧0eAϣ,wWX6%njQ4fHq)3} &$热e:"yݐӁ$!gnCr>v}UΈV_ wJ{%$p>FugM QVw,ơ $Iƍwݴ}ї44VAB]ǵb;;YηjZAkpʹ@BQsl(^Ҕjx5KDrnkƇ]U)ZYNćm)m޳hDED8#Ȋa6pȽ;zVvmfpBm6`4G+99m c4bbg倈#Ţ_'J6A/ z)hݔk]{t]#LUuE/*Fӛ͐CGkY6rl#Plˌj ;땡Q+>pznnT:gLfd%F//-"YEǍxS%L\Ҧ?nk00rh 7U&#fR) 6z?2;>^X Ef;\]r]/=i&*Q^"pM"Syyd^w|LQ984vYeZy[)@uC AiEmܼ6V3Mlp]JDt,o{K3@EpiLsw~X"lX9jԧ?z,Ʃ>[;~h i| syb(Y, H ^ `>o#6 Ԅ4S,,u~PWuGfʯo¨4H#$sV &tyZ%1T*OFa)Ƨ_ܙb,-ş &,3i~YE޾(8Fh6@W2ghS%Wlbv ,hZp^^EVRDp5Ժ+җ*(yU܀a/7 n~ '~i]$o!"r,6gg ބ^jT % 'f=Yۚ m_ɀzzeCQx$ u(x$-B<{)@UCen}u Q${j-ob.SSH 4(_JsϚ/ ~xJ4 o2.J[kV :ʂ/wF@k/;[blW-fL=1> % y  =O飐\:K¿J%S4lK0Nʀ@IW8҆c9rQn_&NOnIo _ދ)}r˔=8 F:JDڽnotD y&k@60j[1  {G;( RcSȥ` L }Fzc-+P|QX9 V.'/ZB??8QiE$8![0xAduC1QCVFO$'|2+Yzt1N-)ANmjR)[P,[raJ3jK]yv(\ƶ*YqxPl| /PEf ;0C qSBxj,WMMsϠ]E:aڻt5">YW}w)B560c/TuwT0/bd_˗;Y߯?)0;*jQ٣3W]WMFźn3zEC;w{ZR5HOcd@~0yv߶q >@'񌡐3G5r9scĀauљydc͟L|A;!v1l]uAf3{%(Ϡs 7cDT yyA&wBo2]X(V?0ҿ큅V]Z>I%,ċ VJʪmcȬ py( a9i v Ydu{D/B65zV`s+]m + o'KsN&{JĻtþyFg>=sv9]vz\&g~  Bg[O`SS4u"0,nxٱ엘o CVY\ s\Q"PPW|' %wUo8;\iK^iTSUҢa)s2c)ݺ u4d1xROAؐ/=6F]N۾o w)4e}Rƴ"ա7Ҍ(ud|EocVɭ3o",K8͆@GK>!UB@rB~]2"bpod9YRd~,;r! t5 S4ZYZ50B/Q^,eq):~y w\FTc2#q߲TճT hWNFܴ oƸMwcsy )FϺ,gq:͊_#{CvWΙ材S5 V5K2fL<8y7bipQڐXp4AL?Uz':r3/ɝaH! #S6}rfC|y\(,(i9BGsޒ~Ͻ"l֠x* x3K2΀ 6.跨 ؅omF%DښYr/TxŘܭt#Tj3j9I@3bnĖu'x'Msdhw{Ţ]gJکCr -N>^8J9*cdz=-C;^'r? 7`+~lک&MRN OXI&^h疵-!5A# 5W>xk?ݮ"@C@xi2xCstR 릔0^Uh{yp44h=*_x#?:&#Ěq.$YOu[܇eᎀ`AڠУٽ@`"^NjWQukѾBS͌"qyX L0l[7vN::gx8M<sFܗՔc zN̵iaT½h-.0ϸi;uʺphjXȃ<,S30غ81 z dJ<ګU 3}2ѱPև *(;ϗT [ߛ ި9,q&p<LyOZ+clzSlyDkxͬxJ1F8%]C@/W؆;&j#c|w:fS~|qF+a2!bF/|@Ը˒e/Fvh%n0Ż*>RӸ~]{ uf4#!!V-g2e ok] Էx{>f'.j%;[!)ߩc/3_Lz q )hpAVB5lVg-rsQf]֚BDQAig0 X%ºD e}qB̌5r1G!"e?KN 4^ⴺJ\t }2y'Fk }pBcWbRE!sz?WfQDXjlt9%q5 9;ўws'"?LKV/&  ݃PAAמk(zEѸlқy~o"gu%&+SE㋲22f6B1t㒧 Ihs$Rlsa4K9Sy‡Kn_PX7z=KŨخi8e]ߥwzC_IѣW;U2Ӻk_&zɕNrs@ZhG|6 N#=1)-I>i'ǷBĽ0?Nu1 QxIᶃJ7Bĝ%[}-6fvFݓT{-$'O $pfxR@P>.ݟR~aąT`ћ}62e=_FM9tJO/$T¼g;xԎ_/'g*n Sz݋R>){o؟ u2z ?8_f@MƔ"| zIY's\>}nj:Hz=9=M\j S< $6хVC5zՏ1_n\"ݞ[푎_04`^ӹfu]bDoW)a1 ~apkZDY,qϨ맜G(}'bc]ː2o3ߊbJNp+ b:,Ĭ)S"5z oɹmJRv%}@VnCm͕y<9-δXWT2EB$m# q>O{q)l4EՃE')ǺNP\(a:V!-d 6 5]҄ylGoPci ,-!'N+u؉PGeɰK~+I6f8{cI`Հ\i)ltJ'݃p~>eA*OR_is)jN4%A  Y/δɶu0M!~CAޥT~2FcT OOk%7biL3FȺa+1r1oŜzbR9[3 nNlg۱Nvf3%xQrz0Ԭ 6 ; };e9h'R=9Q:(re0|F`@AjAqC7$ A dIg:m>œ]ɫn>{6[C2MR7Ȇ 9 @)4gHԹCQx-t`v'"İ9Ӭe@1\j3 Gh;#||2iwWXݟ$[Mp.3\/N%|L\H[ 5KQQoSƗe63E lh|]=:RhH޳z{CyAuLQ"%}Ro\ALQcčF0Xx5{Gzkܜ8Uʷ'!eE! )>ZY:8k2v2:Se&)ʈU9L4XO A).}7X`F‘de;ct1Hrj'/E4Gd,M=PWGao7J+ok W"Y3v)+Eo0pӿ$"o-%6J[8%d'Zf-O)Z] qQXG;@f/ _\sY3TydտƟO0$2;ų2,k*fMf3`0A9?2t,*j"&J=*+džb25qKեSJR鿉y!Lm Lh3c9 iR;nF.k`@;7LwS NwIiS e xc^6^ļ7Y雳KMCY6/A4Nsfh/+/ϥ h̔f*w>z>ԣ| empf^4A%@l#cip=k*&?JW$I4t ^=ͫdXBzf:NE6 B#ƇCG;ʁ0PixSSO,^.jH >!jDۊ;`P*X5ų'%nV?&l޵})R\d6k¼yBZBo FG|>Ŀ{Uz mbu]~w(1E;[{U^[*)7i hwApdīgXe'' h9P%F&(}dӢQ9+ПY8Ao`oxk>٨^~W -}et&KAwՕt[8^.-|KKk#9BLi I?{gμ;2eԗ@RSYL;b\ EMK2/̖;l8h-)8&a3ՙۙc/l ;#4TPg%D%g  l.{pD{utjn G|Xd,hbACDajhUW]ѯ,y[g]o/`9U*B?4mru}CE~9u<#穈Zb]=5bt9"r )U'h JW].nt%k A0@V2ײJ\ A㬁`Յ=ejҬ#8mz"$]5'qxXW2 i3`KuG|e"~˒`@E*_5v) G\6[Qe'˴*E)C>ˡNk7p 8 V&{ZWfC{RV$~M;w ƹY+$ypV)~e$anP&v&S /g>@i&#K#t%?M#J<<ΫN6.ri,&bp3l~`p৖ @WMOA94 u=crѕ8 r5QaYb3|dOqms<В;r]OQ 0TR[w!7Ѱ י^",\*BQHa(gxY 歃$UӛI`~7eQD@ }rv)bL^ܗ!۲߿dCR)t̹ BOwjs:_ׅ#T]&bP\&@@F:3;*f D #=T$geY `8` &^i}\[yM,BoWNl)虛0dW@-k{. K;%Vn[-'N9 swT#9JԡJm$sedQ}` [},uXdr?JB}%wLILS+B&_las[=_BFLvT.C)TZ%MDz ɍ[F(:fȂEI(\>ᚽ"puaDXK_Ե34K4:WLj̕JZ"GNMqpn}++3k덞p ͞=7v^9^މGdx¯AGm_+&ÚB,]dj lhikvBܒ8-CLK4Elh R:Oxk6S^.z( ߻`-{8δ=tJp\j]֦s%}/&à|?eoQw_T쌏۫{,<};ꊹ Ns!gߘ<]'*`ͅn 5o6_?8RtM\K+|R-Cyfˌi_ "0&B*qD}0 T:h-MW3?@#5Wڪ ) pcރ[I5 1 %ـW>)]Ksu0GÈ>C 'bOh|Yxܮ;a!o5ao/!S TzM{& ,9H}_9dnßʮ.tϸAa՚8l?K <]Ҳ@6Lnl'F\*q)a*{LfW P0~8sRvM',s#d!f['ZqxJ/A|gG*́f `F7} )_ȽΔ?أ=UJ6/qoe3BL:nmrӺeOα {u² 2,9hռ J#;`fOQCxE2W=/Z/qYv0_v=-=O^) lGm2dI:gBYs3 :~_qh2)t]ZǙ;p9~mӼSAA^y7b:h6kqC`YEa2sa]HS%w6AY'n4,f +Aգ7j0CI -p?d13sJPa7Cj9^"kScc\ZQZ;vtDu0cY&J$A $z4MdWoTo)L~Jl @Ua'{2[wp}ָ쟂uGS~*FOZgSS)H(E(1L\yU,WN/h£|-Os>}Aqt}-d :7S~!̠f]8>M]VSA/K Cd77;}mSAMT|Al]Yة .)i_'?h{5t:N! FV< da.Mϸċ=M']i䛄Uԑ 6YmDq|/ 7ʙu}WZ' IO,e?i;1Bδ\ I$F/\x6 %r- U|2NE8 `&;b\Fd;iuu:!+kcd&P&"(qؓOMBf~(ݮhżx785~L;!Ӡ"mlcb$sn;#;h]'<͸_LO,_#=nd;qY F/eXxd%) SZnXBǽG]Mz fJcI ѓ w +dmc_[#glOEuAwك_&j!?C`58ȄFKZP\ UJ;sMm i*1A[87.r2֍/N]T=1&Czm*3{\@M.rnhAfY0KCj.mθFA(%Ac&TˆoԿ J75s?pl'mT1]0MЛvPIvӚ(PDI lis\`L`nl*w 'SVմ<ID;ROpIM?Y #abSwIv> ) j6z2-آ>u~1h"(JM [Kݖm@Ą b+6o_"kg}վ4J-Q"*Y!@Y ֏uaیq<ݎz /c}N+d*R ODԟzVڡ= CҤ=*,7>-1'n!R4Y7J?撈+HzT)%-Dc6hH(2aVOwmHUqsT%DH:NCMZ}I@S,K엙ycR:QR (x5%jL k3R+R8 nd,rU.I'Ɋ\q=V[uyƿU;0\t4TVyi 4'QnZOʙά mRT/ Br!BiEcxrq;m @۬6ytE8-T5vk?#S<, G {]NKg$QldhmwP |-^SL,oR|0eJ|gC6,;""ӌ1l{mDS vOēyCdc~4÷ޠ}Y]5ݴKB[~@]*hk8f-;Q <]Av\G.~1ZU)SWk߲ 'wȱcy$Ӫ|>aCW/6 b_Nj(> 7tȯ٦RL5#k[BQʙbm6A}40eEBj=0 l<:d?5ދ ]o QfqJWo/BN xG`@\4k'qx߳axlpܪg4\z LεHӈԴ:"^:o\ZQ0*zh~2 P=[RqTm`n"3Tk;;l_rsljkHϏ:XP~x|jewnǤ$gEq{)Ľ\8|Xw Zs8 -Z&>V=oںzg-]srl3y|~܇M08܌Y\݀Qs6xa/rgyj]| lAQF FgQzPr.L a5ap`=?7<'SeB{Ɋ},/!B8G}(,UGЩb.[.¿)=yҤrG l <)X~hSn7CCVd;oj7RV"IXԊ+O.URUQA#}NmLliGBzL\Ƚ߾ yTjYxG怶h@|g3 Z}^IdQ̑!R %ڤ/V3nRWSv#+! <%g+p֞=rN/{m#{őn V"ZO39뭔oWB2U(H隭RkKo)>ɸ}(}!2DK~3ı`骀:JOJ=֛_ Ukaɥyd/YOiUSo) Zy-8̷z˕LKʟ|='@9};N15]ϬY)TܮL3Ċg.؋Q$|ݳ&57x!7Z BtQ+|):V#o$ 2'=~)R9a8X_jUH}G o{' U+]O'z@B@)1Ah6 7r<_g5laxK.s=]hqƖM#_1rL2`J s=b$;bc;~+$^k˺ԺS؃ 7v$(Okx[ܐ26 *"BtEߛȴW{_Pڸk#nym[ukSRC%wóx&LQ%cwmTφH}I&10B¦<0D?NWge*[{}+y'$Sk2GqGD" fۛ]I ܔ5!3/_blDžqn}=oBd\'?Z'ACw.™Wzb|ⴧ*]~ae։d5*Q!se;1+ 9_}XnJJβ7,$$a"L$nNʬnbXJ =I3"PT;:rH.Ip"Ǧas!1)StD98X0w,[#fQ,oEv`W0Hs,i'-O ȏQ]zd^T>%E;HȻFW~ ؼYuݤ Q7vZ""7G#s:Q_qk7[| Ø`W1ʢN/} {~"B!REIF^7fW(InPiyXT}m{gBQ¨~ǯv3('t6.^•aaFMTtĠ9L'1Mk5Ywc^nɇ2ܟ6x1]w ji场ب|( \LksPܕxfꥍJb疍Y8C׋Yxc-@L up`g}rL쌖B*xH'xCTeov%@V@˱Ԇ|TC(2ڻ´i^'c(QjapGIj-EYn*c![$B} (l4 KhvXG ]|M-؟A}_!~r0iUʎPJE!9HS?'lx#})~ gzU&'?7[zLYrºdzCoO,4mKw*enTݞJCA-5V0YfWwڀ{;ʔ>6W;1P;?k`P@ȺIbH|QAI&7EW:sGB=Z[Nͼ<0+;*6~g}㚟33SGlL-ĽJ-OX1e5V"H@BNx&RYc8q韫Xúd$RŽD=$4^`iK,]y֢)Ғˇ;mM7ȤD1W2! O8| kduT>5VU}: nâ _"ӬI~Ȭ?oD{ÏCWgNYg[ WaSuj 1wsH Q#4NnѕCTqD9oGZH#WW>ZKSӢtX-菮C C8!f9VUyJs("vu@ <^Z{w諸cK{VjҔ\<,zXT1(/^0髉-kɚ'f l[D>זPDtpJt׸β)u=Y=f<[*iHkB 쭷fJj8NdEr5fy`'@#Qx^V`y{87`ZI߈NǯZrq0ZK\mt>ج#A=O'bMҞ-$i!ZuȖSKJ!}? s( CXmLCۃNݰYظ9=m.Rdw2^fM 0ZѻAGՍT%|_5j5{]WΐE ,0Z'B jWA)٩`b~RF Zc,%Cn[Bo""EL G]q)+.EU)60lz# # h!$N1'{֦NNi;͙QoAQ ۋe .j1ϗ/]I&c+oGrD(D#,_'(y쾀Avzу ,}fXP:io;ϬtFX]ZR;c“q࢞B#HMJpD b)Ŕe`W`K* Y:-?9U9DyӠ Ӥn%VD&Ꭲs`KS>PZ/M`M:n摶W9da@\-œudg\R0FsVqHKٔs `~iM`@5:%¤za4U¸`FBwt %|~)<ش@-F@[lB$m6㺵m_>^׋DW~ "xSuBZ`!ʦ|[́?3; {M,w>fNhVy%0U҄^,m,`Z.izn&tFP"QOqI0϶Uv6t+ipncכll `+jbF$ZQ 1O]!16꡴Z_qcj@iKU \GUɋB+N.Q*rO㝝{wl*6!:4 h^R+foL|8-LV5=܄ZNr d'؆e]Dfۙ^.#u-)-8>$.PлK+NxMnA<g.|Ǯy11l㓽y9}ZK#fP.fÀ{iOR (sl!a5ݩr)>` dt/4wm:Q,G-t)1cB Sr&yP`FHh S(A5)l^:JY^~/CgoqlpH+sUG=tX/=h4~9d#OU+^e,ure׫mM@REbݲ&z8Ύo>c:LF|& i*3Q5q29?( ZPJX7Nk iǗMk"k"44L'Ly"Gc]34='zzy@қ ;rְFy#8V%ayE瀧·$9әZN\8c2@EG,j*|$=/F<භUEUgi}@!鎌~47`I &eX_ |4>ݦ+uv>4*m^N:5dx'oqFX.i-oeKBS(zc>ưq2pgzY:=Ol#<[bY r/༟1(Nl=8p=,oNM%G!jx[`YY&ȐWiiK3L1{`N1KI X(ydI6ї=q~w75m‷Y$E$.,%@R[ +mBL85ADoA."Z}*ڀo}Fd&ͮ[^k#D8uS%sS;Ew3Ξ?A&9hY>UaDAUCJ LES''B7e b0aAq0Z};\|2 _5I~$`Huc2NT6C1L?!s+Z\ 6,AZ^*T1-6Wv,MXBކ e"-(PkǢ;!RKJQ|]^kK#ӈA1<`e&;@*'·Xwr,ךl KOT.R5BE1q`…ih@s?v'?$d\0,)0-9ǖ0Sçm<2Am$e9@yc4dhi٣· tHYyɎOuZ^U3~|F5@.=^+">ӆ$破l_evMQbg^yKgC\%m ] Jm7]:XGl;TFH+,)&2d'M7wWĩn0IJ?WKai3ZEUGGT~@Xd>D+zkg^AAq#&! ,~\I!v]VL4n~LGA5n|::旇AsixG|U+ki絵(TAjP 4Ti:_蝹>ZZ ˙T8S}rRz%r$A[mN]8 IE[N:HCy ! 9oiĤDL#rfl6|[;#$F7`DFc7d8CG,,p XWNcY$n"4P5Z@!pڱ.J?ΐht@ 4tr(AE#Ad)fXWZxZ[]gVTn{i4|]آh'K"Ui C # H@ bDB0xǪrj[Xg}RkD frn6*?n!@Ë(?2o0aJiVXLTf^i8W>#:m~s|ezثF0+c1;.pA'8C+:3,FL{p74M!RG ÄC;PWL⹲jn@n0Zc\Ozj^wi,E-^EϊH!ǰCf:4Ka%><@8Y0bHĦx[帢=Z橯uCkh_5L[(jqݎ&jo|4xL_s-ZG҄n4P5pQ^ߏԹ`8) |6r7ͦ'GYK$auhau,K~3ΰѽi]Y/urg延ork2U|k;]N9qٵwe-}];?k͓R?L@>#l1Fc;LS abq|\A h]崊. ͵ f֯RLѵ _ ,R:l6$'JKh bmaƺD+Gx -٪8W2!^hUYe[0)e6h`e%oB0x Pޏ:!u|iL"f#>?+E AEWR~Ҥ2%Pu eM^$ eZf=/(ƞt)9r )Uv/"+ʑQȽᨼ[+>sIDnakGo3 ٔpqLWm %MI~^~貝C<^/iD+5 (m#BtljNH3WKBQp]M T6w0a^⺴X~x4s."է2> By-~̤D8㕐n> TZE@l|yE#r I+29/纭B1ezrɊnVnZckzh2(XZ^9r s͉p ƜaY.3ݔ8̇x%f3٩㕓߇7DJ'^-IJC6j,0qVVnI4Zy]3eCeݴX {lrCgTh}i|x¾Q4a?뉧fs/Oy^l"M*9WV+x N׼>r?əHmisW$?taW/If%oelg^Rh;~{= pѾZ-Ra 2 >eԂsT2$22e^>op]R'30z֥F\Ŕ].w2}M>Y,yϱm.S2o;1`?:HPeX<)]Lm<QCt攤ςliόM vdn[Eu&.P lBx$3LW}8R@FU)G H|poy%UkM6?do.ğFxkl*ypLT5PZX3ɬ*څ9x? ip~;Pf[M1|G];bhGrᢺw=UY 㯄ݯ?65(fތAہpBH 0mp͐!~쒉M| 47z0%\3;ӳe!ݕcLB bIdo$]K_@!Ҳ6l]/]ku*pFW[]i,(QH:I*Z(~8E倡YKP> 9H/ܝvT|cM[r/!7]&:vk5UJ˃XR^Y2;$Lk:W<DzŮ ^H GZcTY0cG#DNAdDҍ \tpDM6oO_E8qtl{},WW\fk0dRv R?";B Q[͖^$bTF%6ޱQTD 4BrTnV aEkk&Ѕ+5C:WtMo2O{S -w2:Lj$)F:XO"I(y*>5u.bF+[ŏh|?@͎fգREڡnjKe`H $^P$d>sG%lUe2ԣ`!yJs-n|jTB`Al%=)IJ6pІvnfCdD1s~!AJn5ym—h佲{z@1ɞ55%^4qʖFnQE3Ӗ]Ev{*`'WS৻&;:^}/o - Ɏu F~(!Luk[i=tʩoXRV-J`Jt0wS(mL.[o*hT?90yћJu4OY鴡m붂qj"VF>ۗOpR6{7/m߰r&P eyÎ[ WodO5cSVO4܆FZwE޵ 0BwrV5j&NfR 4R i\A ԣh{-n:}R*<Z IF.iM9p61Պ ʜs 2N+2i!KƊ˩D$X7RMz_#'ܷ+Ο kMe>ϛ8g7oB-ҶAYgc,+V[tmk /x8$/h^ om* $§79n ZQrdŃ!9wi@Je{T8;\ODYx0THt j$w}ӫ-<0` Z#BW+Zsܧɇ,̯ZqqvdD{M_[jjEA\cJ}wJ%N&Y74]Dc75lV ;8zW@%q4JUpIqB4Nlɡb9%z[' =YPG%g5(j2zm+5jLa0rtI%kʋK?愷Ԅ+"oT.5穣\@C7uR([ۓ O|Vhra$^)$O'U}e+$$_&hL' A2[NmK|AGQBZ*IϯiK=(Q?4G4vm-\mRSLabw;3/ (ڀ[ 6u"`l0lӆSt/xhk)8-5?nУ@@EjJUjC{;ASlЊ 9ዤZ퇣5S/㎅|X EHSI_C&˃5bD9qO*ݶw]eX_-la,/rDP)[*6s8N565.kj:!uY9iOO*|lvmD qBzųަx,>A$fFx\/+@} ?,#s pUH5欂w=ibP5UP[eD,_%ddC *T#0\OtVüYpAdBЬb%ZYx/12$h{")5<@2ljY EA'Okh /YFqlr&ICp LS=VL7Ѣy + \(O]S5$wR)U8cUME_5? C&NjY*Ӭd{%cȍ& }qWqZI0QB{.4qtP J9q+O7x1t'>/pu{7js4Lس29!5*Oc>l>$/GAyz$I鍕=%zn7w]^ّQDU=Z-?m}e\?@m n N)H\`[ il-ߙUh;bYB--C"UOd0cpoobeg]{#.Eܢ!`RE2+Mi?|^!O,aoC\ph:+#RK`,c-%L(iF9Ey#mbLܤR>SqǶѥ6q,YG0Ԁp'\S`u&%<<>q+$Azvld69Vpϭvꝝncpoe+V X8+߾G8gخήudju2fse@,'e $-V\$`I|1HT@L/rhz t(W۵rnT 'lQ+ԬϮ4v6k*iCWKhPَt 4/fn͘rsЮW0bVRuNz▄b(STpꅠWf>JkahBu+KS=g%,* QÅ1HFl3q.6dK (jvONGVd󾵀]ݒ%%WZ49f@>ʫNw߁y%*vޱڨ ؠw-ևޒ䅊ѽz3>L"oFw-mj{| o[oYH FRr&q=5*] vv/eScn4_"=6{؉HD-@ڪJO6_޶{WQ>>lXk#WG&{od3N.|$4z*GG"z/ iBwۊ3Z9Sp|x6+w1(-Jc-#cfLlBkvIifV@  g❴Y#t{ ?ƤlrcTu~gZ@R 6s!i~hDXTpgI4zN5RwYKgA_$ 9,Hl4>(08iO;eg:'qhza4Unfbn4Q xVl,"3Mi9Ǽ//*,Ofo/)3_]}Em@3BX&,ӣM] !)>d@>3ƣ>Z~SljNIn@"fy8,)#oV"N>[-N\+s4\'.&َ|̰JTh_&C!IpkA>V]4͹xv %^DŽOZ9sPT hF'{!hTٵ=(eE#|)I3 Jwjp_R}V|NC_WP0 [UTYTy 'iPs`w>Űl%pWvUbT%+!Yz[ےn2Cռl?10@O$ȀwfMG6 WYIXȁbwp{_#5h@/]d" *;u?g&Np7|\z-"{.^9BТ`g`Mn6P T"<Sc9rhXo)?džѓyߪ3M\U5!/bԥY9ar @Tɂ.k'Hx =&y!Lgt߼cOxaQSy3(֫U\sxbZRLpج%Oyx w}ǿƧNj|2fFC[ 3?3%QtwMH84Iͺ嵘ޝQpą.Y^>20~WÙCA{Z-1BZNj[YKs;e0D|'[xs`+ۗ`0V%++CJsMd)%Nb;_qK4t⋳jůØ@C&'=G"3;)XvH`b\ q(GP:5&?Ml@fZG>$kO􏮖*f4&yo$ }cL;kWz# 3qdayɢ$7;c[Bt1?/A]`$\DDA2CsAzzc A[6JØԔ`>K=Kk=S?ՙ/r@١=7.}~ gȱIlfW~&/uEPk @Im +֥Ǝ=D8^׀&`i]}&4K` Sל MB"w`_Rd=r a rɑ|AAaqTWK  yU׹29LJU@.ԯR>'=:`>"؆.Vb3JqK\Df^t6ZX(4W$׭MY8\Z2kvdCnjfuѭQR,hFx3"*RVDRN4ikc r-vn-;aN(Qt,y%m'qyLl܎9|H9u]5Hf7X꤫+wekO^}V2blnpa$ǩ鳵5{Ef ~u#Il8ʲ4}JZ P@%%hHF1jSUwrq-! sw3,W>o3/%ݣ0 ֙iYN;b'*হTȍ)zQAZd \'RqrsR;]PUtQ_ t9fXtI]~fֲ!jO?n% 8zQs}8ev$>oSQJ\f[ثEYߪ+BB'shds<cbiBTmrc6M.V-ZB!x9<^x9<^;^iZu9uA6x/bD<߈Auvgm/0Bͨ3(/Q]i7;nQ^u<4"<3y4ަjJ;0OmqV`1~pSnu.,(o{T@駟/(#0"ʙ`X"c>ud 6$¶p^Ck@ Dv5EYh "` Jܨ nMkFڼڢ] :3\B?4x c]Kd9k8\ #rMw5WID(` &2CsfvC~>1;㕶 5d”^O{d03!7\f+gnXUPq!@/Ϧ?MH!GOU]& yC,gxr,x]%+vHl8hPpGG=\ 3"l¯`yXZchԗ.b4tjǨ?^@b@KTzlY`ApْkwCNȂeM)!- 87x*H?%%arxQɇ idSfwS-冎4w Tpd][*8HtWAεrJ(kO@1 y${GG69Y3{;9Xm`]hք5JBgs!d,i駯4D4M+[:&7HL2 PQ,J31\(fVN* =FšU=c NEaF?3a ^bⷒ#b1tDrW6ay-X$Xs8D…QibՂ6MwJf65Hg%r:eŖ&mUφ# `{]nקkv{2wB'0Ò6Lf:f)GW;ʌ^B4̛ు.R,Ggp$i.31y(Cĸ}( Vi+Az^졳Nl-3wظ3dD,I/D!-^Qj7 A)ErG<Ъ8P{uFL$G9pܕiIÙe'[Ptz$GhI[|d2׉k NO=řwrf\a FPz EDJxyhN@;8£Yg: ԉkg`FC]6&#H䕙z'q gҰPfGLkGIXw_R`v;aD!W5q6WO.7sFl+-(.Y`b380SGyuvd%Q:EJ饡nfSsgJf} &Kk-4;B9^@ĩJ$lPv\9vLk8tmVI[b܎Z$@>0EB̸=&_x2TyKTA7&5Rep7ҫ zC\κə3^2W!ϣ፧Z1`|5 qEB~W㾧&y~42)+O.ui`Hy2dǕ^Rk1`-P[>7PVr5&E4's:صoZ+7ȡ J{l/˖#X!eȝb\"϶zmT"\lCPKGNe><."Y P޲,.ax-0"KG/А W`wόzZў)ngeP@!hQ']&biW+CőI!N/29%qҲC+"lgrjՄ Phv}8+aE:<i0ۋNA*w E&3I JjM7/iתe杒)Y .m,BŒT"JԨ}og41 SoCS1ylb !ah15avTDGI@`ԃJgnw)#7*~ZLKA1vpv= 8ąQ2 ,'~p"hK6jYebun5g ےl-QP0M_u[:vEū(VH`场me9rNHkpߧ&?/? HChR yv'6O0yGnӉdv32:x1dwhQ0(ThGlh؍XSJS9*;3Do 76+DPrzl FpKԣɁ#h3W*s3/bw%lP'Lڜb_ _Hp MA/K#]RDmRJ!5? ">jlQrc]`l5@#P߾g>ԵJ7鸉Q3x0WFjB[2L B+'Dde[iV%~$q'ƕr٨Uu+ gMzķMFCs>+$ܻy!B$1j .lNl ɘL^2TcO҅H))&%չ^/m}G+ uyJWlP` ňo>b0v4iJ+d6E$?jcFRTIF4Y p iñݨ^$t}LK~EaFS\I;L CrSbn]gkQXbJ^Q~ (>Nzm/>\\Y\׊m\GSc1cY7HJ!̚aw8(d>h,oFQ+="~nAuhُŇsC&(HMTJ3§+xWG"7K [ 'Z&!>2 SѨ {VSj kQ8l7fA5[ʠOAD~Y{rbLB9f;+QJ,l,dNv Tr¤Wm2yOp֕ݟL/VM1g-n3ݩ,xmd#<\|SVVׁY< 9Qy⮑f4LtA.ƪVj f#Nq}gnPo1 CE@i04JҕM+J>!{c`݅c=2S*>kqas,dh"YZ0~?QhhuȘ*qX}heZ|#4iEڦ3%+"s:N۷O"ttcy@kDFњ.VPcU9Vn &  lޏ3: ;ET\tClX*2C=YF e ˼oѠ|1ԛrٚ^/]|KQȰBjrEZzqh3@X7Xߊd9nttҗB. 0Rk[ l W1֛z>a!75>$'f~xɍ y{\Zz~</n0]IG$ipޙF؈ 8Ýu͞78 ZMԄ2&mZA@3ܼ:3`>45.."γZLxɖ+ƥw8\}M b'S:$In3iU~t] 8A8VȐbN:Uzltb.(/,4ܻzΣ!PqٻVc" ~'Zq$az1qobm&]IH|Ԁz[ںQ!{oɰj5%I!8ǨE`{,z.i|.<@M^p]46b@Ԟ9}ԇ (Ԫn)P6ڦ(_aw(gm-2QM0,p+Y*.X`0%MtmmP)A0oɪ۬!%@4<;`܊`ò0Um,.*`3VNHM:_4JTNBRS4.HKZt _Y2KKjW\:ԤjE\T\m+[>qLYoi`?:V7x{[Ln3]p=k:g ̐cB=B.q.3bd$Uj^OK|1zd?XΟms~N/Sk6KWS S@>~fN6 - -bqw+#l<ڎشlpOuaJvg6$H&bzGO}A%{Dܡv=*Wٺ)$=JH)t橓KPud=`IRLJe/0.y`44G(793wxS`jITuAYfmU5)1v9o=b@c$>lB[n6佱ALbToxz3P4].RXC_u"Ԫ4R1ȨrzU*;ltZz(t9%J(- d04;uI&uOqo$=dA^A.|?BG^j[sUHBYz:l(zeTmfXC߿  4{W[HVꗢ{' EYdM {P/Zv dN`4)AgiQc]H\n![PI|B շQfu ;SG_jXf?@Kb 82$&.0h5A,/6vR=gwL6M+<)QȋF;D=A%cD& NGۊ2g.n5+5$C%Kn&_zWS84`li#rKA70$BE3ky[p@:`^C;;l2W!r^Ga#yAۆC)ȫ;ZT eU}J7OE~i7R Х s"_d.[޷'̔S/+!rFXkK tF%JoxU:jkD*rVVʭt6_ ǻlQa'c{`ݟ7IȰt!G&0Mtx/2}+qL#Q3kCsGpb4} M7L?h8zrܺܥˋueI,Ot&vZ -::myВe<4SꕌFқJJM<^CeM$ʄ[h^jd\$-Nzh\1/a(qQ; 宷_ˢ6W>L~|PqGh,j!& shI ۲d}g@>JsӵF'm]-JЂx'%mS\ۼ-, ^ؾCF!2fĥ.&j%S֓87sPaXSqMǺauVIwj oYC4ƺk'l(0 `. 2!ܪ$6k/Y-8-&N#>rFV# ߬IJ^l1OVP?&jo e_R24wL8 Vg}}W6DT7; :g1aCowSIcޓc'6MXEVfVa#PA(p8>{x$vʍjs~93N ʲ1a8OiLnl`Nl%B+~[JˬE}>&qXA>ڸ$޺;v~$mEɱGcak7$蠬~#9!E٬-o7қ{2pT%C(=3 }s݌5¡P"1!4^ u R_@C8q٭@ h4l&.Q,H։rˢR m^=VԶ6,؛)GW}`Ok D7\kwt۴6Uï8a;g]yrV3L;w`0*nd^RDjM߲]+bSǠbp78WmMa, H 9s1$M >PWG0X=ȵ٥_xI%,Cb5nwǙyAi[igل'$1_uyx_/p3GtVy|K,.#w [MKdd@F4dNr,)7:-ZmFsPc3lrL|.UAB= 1z3R"eؖ,CC%%UNv IAr^Ig*zg9AߥsjO&jV՚G.k ɸIUwp90=QFр˖˖-hd޽1 !4AxvErIZ} Иk c"FCa"3a}ky-S?\}~' 1<$Oe`mXB<| &tQɌׯ>#5.e!>xk NH-I< LǁYORk@ g/ng\*xL^A,&~̍pBn붐 Z'+ͅOOTmO M{0/_ȿdP=b^ QpgHXxH -0Q-"[A'O]`[˝V5֤7ZFf}>Eu+CRa\+46O5;>י卓ǎ*=nsxXj! P0~?cv;r5h9~$<~NVSqqK4o(P`WkipD_3!|r"x J5V XriU81d)M\tخdվycrVà|d-mZrn"K4ieQ]^ r"vZTA;!.rx..rx.rp˿9,tB؂@{Wӝ整A%jH`E+kmeb9ר,7^Y>ԧ ,Z'xݲ >+;4FCc94Ftu9}~x/rx/q WG&ֈP<8.g7JtK%8 Y T@j\0 Tk0͡4@hu00nW7">V: 4Ӥ]OrӋN/SYܟ1Q8vv5{t*%E`1+QÕn' :ߦw`u%_lj:wZ~˥ѲPŅ!n6GQHa;`7p6kif 5rWT0}T¤y!FԀ %jy' "\ABi][AY*Xv%6srVQv*[,:C>1[Dgݓo^*%Ue.IL/W6weQb፮cMuTW#6W.q2M72tk L"x?Wgot61<%Լ+#6flkl:ewܾ/.vvT$ܘ9UGdW,VUd {a[b{MX &6E#ЦܿȲD`* '91Q[q?'ꐅGdfL0v'J֊cHsڤBdV6izn|/f0$h# 5Dž2nu>ybT-=YZ,}& 3ȫ0.%yS݌?}vb r6s6 d,{;FsA"K>* Ɉ,(b C^ wi&u#'+"H" ^9Y~K Y5OBWX2Ⱗ8[(< }ES%knx/Bq@3hzv,gu٫t+m7W$0N_>MTHrNdA$@_\$L\$ HLs;)1NvHF7C0bg Ne>Ck$zKE$7cS[:*2#^Q.C'/h >N<)yN[oIȦD2UuɬS62Zp f Q;كۂ츺~l/)dF >wvOb/_{Je4, w)yK@X!x{xQ0ҽOTpf@MlYm17WMS8{9Q6p)(v3=lG0_ ,k7rb+,y. "q;-|se5%>whdDdnyy-,_(u OI:vU'zhݺ:mTm4O8Lfu$'o=Fdݫ1P,E't 0k`.s?idE>,ip KܮQj,'2\6rSqXV:`rŠ'=U84":%gpLT pNUkJSPקr(H_rqd3*3⳺|198x=IA c/ &ӝ5 }!ZR@HTgZ)4*f"nxG8 *YCw2779ǭm2I~?T2 Q~G;jIJIO܏Y5N}^}˶ QOZ.;¸&nkpt=C.Xa) BxY۪ߍ)W.ѽAm#ч*&.عDbTZ¹[U/,BhHW8Z{yvem!'Cݯd0 ^Q-Rb_ṳԍf1cQf=v@| FwmK (aXW;ō8 G:H!nq0 TdpsnR/!Q| K 98l4a涙cŒ,a 0[aΏ9)u-M<ѢRe&hUCM xA-3rkfTJH%5 7l``dz>7#Taj3&Bw!*2i*3ЙVC~J2u#oD>o:#71MS\W)AMll⍟M\^TĉMU.*:x,U?QJ=+v %@k5UꚮŅ'p-0Cy8 𥑥.bͫxt˾jP:|gOAZږ\K mB "\o..[pwCbX ^&1":Y̑ a UYfnZwϽSXB 8#sghHSlA*n|t{7EF+1+i`|j1e/R2rQox1OjXOQr>/7v-DF||l" kKr"ta W/ek,ON5;P$aTqL:ܴTq6 ĬaۤhdMbƜ] {AÌrT9ɑ@Xxz4Wm: o٨/Sk\즅mG*_=z3QqmT!Љ]{p3n> 6)ZMyj"9߇bKoܞ;Y!E’_QtqLq#:*k"3K?^ ̕ 7x8o=wuc':UQ]/!<o=lUS'?3AFT7D_h?2=#i яGbE5Y>z7}&_&:rJwqrήj ,4sڙpo 1 Wo]kF0L"HLSz\<0WπX8] -\ tv{YOZn6+%_iuIsJs02#؆Yݘ46T?pdTb\[[Kl9`p/b\$ AMiry/–lvbH̪ACôC)39zCQ %0FA^L>? Ƃ`O(o7nP/7S@HZ:_-y$~\:_V/Y."Z2⯢sl9ᨁ.`!%\ۨnhK^hpTrq\Txj +Ag۳h90*\Vq;ӂE68 f; fDH19&MTB_]LJhHtFd/}"lGy~$7BU*0zꯩ *J|$XƮMJAiJ7F2V% BٙBkY<~/)F[Q<(AF#rKLCwցALuz[T 8zuB40D(dSMJWgk{i t;piGnj7sj4Lar@ډ*Ej:Ur$XYlfː㔦<8 vSsi}*O˗Eo"vbUsFg$Z6=qI\]l5vFn$Ub5%n eb-CQA{X{$`{ůIHrhҐ3BΓ'KaEH eNo=Di!XnmG!8Ly7^FZc_**KW4%Hծ$sթ-gՁOFV$NWZi5mtjʕWou}K- -}a@ eI}'?=${푻XTv{Rrެ\W| Q4zoZ6ԛ酅fV^j.ji%ɭ}f=90lOν Lҧ,.@j i`!~f~6P}5V5j.V _jQMl¯h+#81\+'ڵzZ[(/+3zXm)5c֘u?QתYѼ<خ;iO4