sssd-ldap-2.7.3-1.el8 >  A bU]k6|i٢C<"JP"%<~V nxONjkFn[y0 }6ҪYoRU zTa/~IqY# XЕTIχȧ*oA\K#m䐒ԚP+DZr vl6/y(cW= } d܌s#JB k߽ DEN|}E.pDÏ$H0*DG߄;Ώ|tT 3Yn x3Y]E)k٫#$%2 uw~\NTCwosZX( n,+ Ɔ~3L ]m瑂JI Me6^?}---oxƼ0>ҧH"? MÞ|tq)I&6q B #N vqʔA]N!c")ur>64a4e1eb56ca63f62483d26c3128f82923451b0c19346b0b0fcd39cbc7ea9dafe9ff12abe79f25d58d93770ae13bbfdffc4a63dfbU]$2Mأ)(=KC Hp+dm<g^ 겹R/s'+h= *rYD~TɍHX$j4m36mtBO8l8,Ob W01icT uoy3} BTnEdӥ>a9 > BE!Pf &%&ċFge-&(YAO!.0 Uq"U0RnDz=, wB4&S1P@Qɗ2vI~-$leU{˂%6ԳWy~RNMt %U072`C>?3鶌7߆13uVJy uՇdwu ,BQ yH@]mvĀ螿1 ݯIzJݨ8A, Qzp?4?$d   6 8>H      D0l.X. . 8 < A( P8 X9:c"G|PH|I|X|Y|\}]}L^~k bFdefltuv0wxy8' Csssd-ldap2.7.31.el8The LDAP back end of the SSSDProvides the LDAP back end that the SSSD can utilize to fetch identity data from and authenticate against an LDAP server.bچx86-02.mbox.centos.orgȩCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxx86_64)oKF\=T4Ar W@AA큤bچ bچ bڅbچ bºbڅbڅbڅbڅbڅbڅbڅbڅbڅbڅ15ef8e50ef13f8d181f26d37de2c1dee96291bd707b817d3b6445984f92b157f8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903f42d4d1d3c8546007e0c3e47152590cbd5f38231e9d7bb73942485766814e919c862ea7a03c25e6e6aeca4574fdb095ee4458e00e3c9d286ec04b9e542d94ad7dc42f525e6b5cddec89fd63791db0d5778a926a02c25f5c5c8f5985a76ffaed17e4f3129a227990d55b01650064623d916d838cc334cbc9a929a027ad07f393bc9c8c5d53ec524b7f7125c9a39b93e992623736414f05c88580c0a00faa771a53c87c3a9c3b343f639a4b59e07c1c8e8509bf231b8a0c7c196bb73272dc080170008655a24a2a21eb1dbafa4be26b752848c98329506e023a8cd1258b97a273834c228602c88bf05d5f7108f6b79cdad8e2325febbfa1aff54ca8a5e21818605fdcb9c0b88c86edeac08a3dc0b4a5bcca1df2e7d06d76ba3da5adf07747687c04525cb3cde2cab6386dd727f210e1929eb1c3649693247870143470fba927bbd../../../../usr/lib64/sssd/libsss_ldap.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.3-1.el8.src.rpmlibsss_ldap.so()(64bit)sssd-ldapsssd-ldap(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsssd-krb5-common2.7.3-1.el82.7.3-1.el83.0.4-14.6.0-14.0-15.2-12.7.3-1.el82.7.3-1.el8sssd1.10.0-8.beta24.14.3bγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) esesrurusvsvukuk2.7.3-1.el82.7.3-1.el8 .build-id0989d474aaaf7c2dffa98fd56e247b0a7df1d3libsss_ldap.sosssd-ldapCOPYINGsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gz/usr/lib//usr/lib/.build-id/13//usr/lib64/sssd//usr/share/licenses//usr/share/licenses/sssd-ldap//usr/share/man/es/man5//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=130989d474aaaf7c2dffa98fd56e247b0a7df1d3, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)'PR"R%RRRR RRRRR R R RRRRRRRR#R&RR RRRRRRRR$R!RRR RR*utf-8f7df2dbea56b63d406b1577a1c1597924a880a2278ca8e15dfa4adab21014463?7zXZ !#,] b2u jӫ`(y-lG t'U(%[=׼{ 2-=)\!9fň&z/\dS~7k [JJogj^R jL)kY;KJ3yc-lKs}abPШ1S >N ]m<{r bj ;r+٥yW;NB@h"^?jI B#ҝխ/ƛ}n҄ߍj{LΟ j8Գ=JjEI)r1`EɨG {Lu140pp(-PG>o'c %ZXIpmQ7]ؒWz9,+{ ,z D腸eZ6(ai]6ms`}gA~hV̑ǥaygLOg )r=d/}𿉿zNFv;F.x< -KDsb0=q!>яV3\tBH_aVTXfވ 7+rԔ#k isKQaT.qR3/OŃ  w]먢v1'.|ۑk&|&o`Ir@;Oܺ41Y@ˀoSڧgP_^9]qaZ^/X$ҥt{;UoxeA)kNLy&+H5N 8&MsOG2NЌu!n4~q*vou+ܲ'A%60jJ7q jjH u5|sP×[[ˎ~O$ʱ~5@zL&.PoBꢤX5?^>vfAkxc+L 6da /4k,B S-:ݪ.:Kc9>w r/{bx%ݱ9p9.ޅQ7',?e[q\7o?ȸ]p`6n*f^0! 9s%pj#K6Vq[1Sp4]);6hM34`?3!3d!I<&9׋{!rԁ7֒'~-νZvscvz,qAH JJg ~7LϏ?$as悐1,kxҨ+\ŹQ L&jۗ\Ixa` jO,ZړDl5+׌#6*VvM3&xcm44kd&fVb&R2oL ,ܪCд3BO^(H`ZwkMS 4j.kXV]|aw9P AT'1g*1݋) (g;tøR9G^茷v:]Q}Z޼-9|{PnOi١M1QHe(%+"z)DfSW%CcD}5B[Uuk[zHQ43bK<1}Q lsudGm{ ˏq7>Nhg*5@ NAb, {:LBۤS4)ǃ]_ >ѹ?A웣)R.u:#BȮzNX[SS ̷rګW<2}o^X"1=YE ΜФ4Ere$FWpr%P(q3Px=A ŧe ZN%4O\}fir;<܎ƒSܛRȜ~|r\XOʘO7e<78-cZ{UY|шk_SS|T^ݡl,͜ %XIu)kVm[|D}3c<& { u X8f~=^C\6M1pƈ۸}Ei4& 5cyb}ƚ~ ?<r}Ou5sP<,B9~@۷* WQr ^gI3>2μ'gŗ=M0#mg}XWp"<_Ys`'j¬$/75FFW.OXbש"VF j~TOv}R 0q&d X*t3ghq26FId6rZ$Qz#O-;Hl)L{!b2j븙 opǚd-o&[|օْh7O^ }參!GB0]%PFDv,tonY䂹+Ȫ˭DSpo$$!Y:JˆB /evnx.%P,$׺?UUVX pIXX',f;-U+M: )LI:]< 둣ez]_O ("*N>^RgWȻ7ՓٛM aW-~+|3@ ~5ˈVN}+u"wV"52,M1 '[2 s}m*f1;4i6&D'NGS[`dEQL3xJL2D+z;ppe}HBMssE%NOkhωݑQ5>lX( .ӚE>{?6(]/+M{v. + _\JKeM(Y,ȎrΈ|m?ț7Dj5s$t8!3)8eYU+0Ro@ԝñ2<ҎAY'SIĸZ#N,U O^&mo?a>zV6c[G)u,K>gnlѦ@?fl* ['h 0v;v Ħ%} BphxPB?4G)}"K CHpe0ۤ `sdpk_Dl>n.B !(өBF>Sgc[yni莥9!S>Ƥfv:%sP _Ɂh) Ft81'4׍&DaQ&ziSKR&xFsFPt- cl?Nŕ\1)mMr_yo^'A&ˎ,`]pCh}TCyZi2\"|@xTRX32q{㩢ia~.*Ꞓ-tĘg]eBJ}45Pڥ)AL``=nS0ݳ޺l1[+v4dr5Й~wmdHsilZJ1ӝzo֕*{yUh,1pl880.9 jkM(ATrF+SɆ?I2_L>vl$籕׽l UR> vi?'ʮ;Yn^Ī\?/p9Rwy;̰S΅t>IYqA EC>b2d}RyiG'y}S1ɉ12IkꛔCV愺?.)Ӡ9%Sa,) GSl: Щ>]CXc 9{d[L0@QnOWmL0D8sASJ\YZY Ph5IPM7"(!]z\v/n(~`"RCmjV)Q6f ϡ}..ߤce{5_]_}A^[wt vw\V-hs]}X`P5䑼|cޤ kc ‰FtQVNjï%@4GveBvJd")+]NC54q ¿+`8BUejL?pAR?l<RJŗ׾1;9A-?Բ(8 gƱgXpO:Hq3jt7 h1< -H}"xtyX!aGvO v%ʄ{qVݘMhѨ+Ý\-n9e̔~W ʆŶf]L$ \oVHtd"86OJtB\5vLvFNi[:^Ay𾂥'< 9e$i`h*7Eo跠"3>"qyvŢ*?!V 7s9;ֲE4j:)#QCy`>PuH-l1{#I+M@^m B-И ~D(anM`qWf\xcvnR=ܣY7?jᙥ4 z\d*DCUЂmhP# e+/̬B]4JApeȾ2\ nwq*D=G>O Ḓ*$? &gKDE 󀾯tL`|^lX5Glb?fwl 1[m2/ Kz$}٭Q Q{,>/1*9S23y]Eer wII6t E@; WĪf*IQL?g2"xoP\ 0I>.$KǎZ @oDccCVUFf,uE#c` U`p!Ԕ '"4NX+|x2 4Nua'c;FY$12&L?@nNgS.yb <6PQY8x?^bR K]p;kuymScDA\y%Zn3s&gGO)&.nnI8X1 5xE%!DCu=O&p_Vx{vW.pPl>cͷsn~L|3sfqXOZ zzS9)jlbG޽]6ſsH;Dcb>f 8Egct .뺕RLon)~]~̋%13%r6?CJ|ş6`fs}OzR u |ݕ#F횪/E=V)LxhPySֵqe5bojYyA1-I9/a!Y 1I!TNr]E ZFЅo0W'[c׌$%fS<3'%$@RD;ArGz̍bhz|jgf݄qlQec/(}E]iF=cw+0B# ԉ+S#9&*Yh,ٓ Ï wY'Gȧ.RK30^At* >]ZDZdp|c2]1_Qv (nd ~oBn1$#'a6'rg=QEUOOv,pXwG<<6)P ~pCSѸaaCX̙Ӏ;J:eEI3_MEkG3듢ގ-{]9)W|0|c~\B`7SpmхacX_9lsZ@Ȅ+;#mk(?n\J +#NRN8~L FDs@l JxQB6H8kQsiK汚q@C7ӫ%4_0Z;cϾ̑wNd$lF u (b4SorB"m|0HjVF҈@/fMk/>}\ I3j h9βKd#^*!.$c Z V#`"i*G/ afZYU~u&h1)},lՉi+0,WLE#SOIFH%Tu7%Tߴ[+d zQCbao?zǦUoqVEeL:3pdx~Ɖ5<4njX 0KB ̈BpG@-Ȑ}|d";TXF<\CJ̱j5iPS@{YZ=ՃʘŁTV{<)E4=%q!]|deko:G2-Ϭ(mA1v޶aTlg~BEUy)@fĎ؜ 릃3S^;s$r3J|m3-ȓ }o0؞Humt` o#p}+P?Cѧ#E Mf[.5Զ rJ'JaNB=uPbx@hܒv:׶2;w?b@vk? ω/񱇴N' L+VS?eX,ccY8R>AUNENs~t1~ƌqQ-Rb/c(Y%N AJb! 4V2p_^c\cKI$ҏQJ4 t6J#=K}Uf%T[*qA;O`Iz:ߏx;hi%%d^t$tL#p/9gfu- ]nzhU7`Փ* 8-jo=8Hehi՘ 0`Ω *”!j-u4'IB廯`.8aOetޯrïO$G$=[:"Aj1)=Qf*Vm)b1`&l{EmkM/o`\nԉ3xW\"(2rPVK\;Vx&c6<-j,BNBVUe,(諫XNHN*mmJQsQf?Vf/B[>{sv7,/4TZuB\:) YAjqݥβrCc_ c5.?lGȩrxgGO@D20-]xXB,DQ+yX4AkHEh w;Bsڍ z ɶ6mAƍ1;xqYdׅatQHA;0U_iTnNᡔv,,ΩW^"AQJTy9{q91s[~His-ʮ\h ?WI; ݔ}wANXteJ52Q_hPZ5|Zlz}&pdRfSJIA[^6 TnA {Ql.GX ?4 aӆ(bSj𴍅[~rmH.n*ui|M.Ug4??_:dHt (tW4"?O㐲" GK@% X#Ѱ)~qasV)d)A_dv53޸z tXn_N[/eKE׶`lf^;/ZU@}]ˤ-kVK yqmU֞>t̗6T)VrfbX&2ptxiŪ'/s49Mj̰At">~d¨X3Gi[i/=BYs~)s fn3'R+9;޼v.Q3I {%ѸH1|D!J# 㯴Y[ڱCR` Be;#ma?RPr.3 o!'{g^gI&dE R h$~7JPxqjm>{7O@ iP0(nn7}yiv]OQ dBB[dO°$+)LXe@L-"k!K0 y~V֚l.(}WfW Nqa𡊋\ )5'Cm>a6P#iǴ/.dِN4~LV nZ(Z](J׮*V7M`uS-fװwkI픹1+TKq3~,.֌3:fv87Yt NRSSU?Wj.GG2v|\'V5t,Fa3$ >{W]֦rQa>Vp_|>sԝWؔ€O zM%6 KZIZF > yo y>8V` &{O3D`mD{9dy F9%'gc.pK@δ1`tU4" F{){.lb_1 }bs=R\/ql/JvFF+V才,3iE?\ag [>gn d:1д/јz_yM]Dk&cs6r z-ϭxF+K9|H@mGz+L*)G /qrY<?""Yъ y)f \kp0\4{J@CUkA,O$+:Nͷ8@Q@%֋h5J 6}{bg fkmm~wrkXy#K1R vzH+v)g̬:A%ZVt%G3IJXegn+_1;atnHmrL=7ٖ2}r` '}&H2D I(;IGԂq2ye5W<CDo4Kn /ӨU MoU#I*2CZT.֌Yff μJ70[C0f)+R9̺|$Vs a/cweBBicZ5 :8yMVC8QU"S5|c4P{#Hu hh3ב_r|&*Sxɳll6?sXQG.Ȱl₋= .%h=*~ana]m &Ψ/.ĵ"{vYgtMo4䛂 .Cp4HZs XOGI<-_eJ m?LJDSm<0 Kȼt I 91%Cųe\K}3Z0''45Z,C[Y?U;)'!*j{EX_2?I!f悝1Nl- @S]ٺ&9'=DwhqWP87rK}C )&@]OObսB6Y:0ٺ?r)*O ϫ+zV O.>{dRc(+E|Xn S}k16ZXxĝH}зWd8ֻuJHXLkL(yZyiM4vl:};rNvbm٭S5mH>EvVdv9YM7Qx|Y8jOr<r`|/O^U8],+_ƠvxUg bFΡS,R G#z+Pϝ@ӇViЊ+4 zrdƊ]x*u O۱K\f4v$^4z7>&m I!#m2k'f+l+ ďI %hλQja6"Z[gږɎp("J6CJ8gƆ f51~uأl:YA$Qzi'1P:ud! .U) h -wIa M=iE$k'Cue{A/DV$7LA:Kv>$P$v7Ğv @Ư/i7ŰncN)k%S;v?ab]-4?xW%e3<&ttцUcGoP#6S.s}Fm{#UGKc+4L tX0~-jjC+}|yrQJ jE{'Zz _u&8PwZp-DvA1KK RWZku|*y_3))HujDXIh_Bl~3GK- b5|x8N5®f6/."3'NgOkt3.?$%RgKPO?JL!X) ?I #: ~ŘrBW{z FALsqw[.l\?SMĔq/щwhŀBru vHL >Rk=-:yO ˵,C>]L~=t?ДStjxP%FD/+%F5BR:@]S^Χy {tËf !fȿd&_^vjT:7Ikik\/x.Κ1'6Dq̘Q1&29?a2: iaajߜT ا A32k4U3V}FSܖjNWA_PbfꈯoVu J/3^u${ GF?p̶~ -K`|ۡ/;%pFR<ڲ )êwEV%^+W!XJoKgןoD0 9.pjf ~PpɿP/BmNNZ"DPU|4 GdL0ٸ1k8Ϝ'x`=]e )# 孅lL'Dk_v3AxX waA+2!]ӭTƆu6PlP99Oj=x'ŕyFD~ZHXHJ>'9 Jr?D4:~꯹3WIQ` A efj=R#w1~hm2̈(+l]fͣj6Lkӽ%_ل!iAu [Iks+GvM ltBwUobat']+?rH#4:|Eeqls_g?.Wes_ ɘz@jR&C$,$H]D#Oy=^,,[cKhm6@_}"=xŢ1Ghxw@`#h#g!0ǐ*Ib޴׉DvxTU-7M#"jEbSq#A_!gye;R\Z(r_4T1## O#GkF}ȏx|&,nEP=*a+CΟ;ρY@)Ѵ#lM4UD_x.} XFty— g`W}Ȫ^9$ Dc;h9^I4htYϳ~5CJŲ|Z^0!{sO{^>C?Ppξ8uuc*E\S$t#P Mv(4kZ PvMaoq#24߄~vYtVU[-.m;ۑ'ݛL/=' b}=K3R̟&b,\t ,= Mt<1uUMCt?a_˨ ܑo ŮMDi j;zdі h"z9=Yݩ5HU {p^BukdHj/=Qfkf7Ugj*Lg!-Y]*I@p8`(^œ_/HV`!TˠU*MbB7hv*QK_A@w;͑z]+ieyl Twz>z\wzBxpGW 3S z#5:j,i$0 nv킳v1q^/zC[i5(< 6 6-y33C=\ꄄӉ֟pދc}ʑz' Z8"@#MUH:E fڔ |mps:oqa֗_ZnI!l{h,Hze5.-MtGâq6{d6ih|_92W-<{#ЉEaے8ayRKdzJTһ$D*9Z'{?Ln FB96n9fSwE[RIF=&LX5P]&Ȣ%V hjY,7=~Mh;>"w˽͞;&"av @bADC]tȵ4ad?eJpk+|4b蛺Fx\Bz!,ث5}ɞ*v9A:>_b?< T7G(1>+dg*$TiO3NJ{WD=6AtXwUf.Э~-xp} ERbcw#` nr1DW@8waNQh'?Aw\Kq/.奝9Z<H~yx% U=yRf -EwY)v sGys ύM"|~=J9Ha~\cɣTTc=Hdvi\p}kS7yEӑcy(lTg=b}rf\0bb«?TJ%|Z2 9ʕ]o%bԅ\?eˇ5g7 :nVAdQ)@3lP<~5G2ɯw.):]DEy"fBC79vӼް} \+>|!K*a0mV7Ӣzt>;y3v&>@{*FSA y̟ |"3LHcs 2"Kv!>}֪~L(lNfRhuP~VY|G,`z7 D6S~w#ۺwg}rt"h)ey{ۍm_|ulJNy ([ C*{Mle%^_/*=n_KN6)E{w]/}/G,0d^lf کIaѧ@g3ss=BT!#[stwwsTK^\baI: cl]TVX0k(?X'N+ $W\n_BV(U푷jiL f) }z=iz=u==jrkȣeHK\}Ǎg6̟s@.^5^ҏȅDs>rEkd2BVUVrMŵ%o9U&L־A#MuD'x;5$",i$xMẎ ~qhuvhJaeWPjhmv ~5sE_%A#%2 UN6+s*r1Hx~+f1p[:uhOn)$QPgmkY5]96}PdnPBSHp(͹l:_FyI[L/^+Vb?E#t#=ž.Zzb~(i>+ 1x<`~F ^ 9>Y@T$7=jAND*5Wi'>ޑiVr (VSb 35ܣаgU*$ hИ-sSAToVx ;,d@Oyqi:7ߢƳ'WY5 9P&Y6mΦ? =~7^]6 (lL@ ֬9y0$oC8&Jri.kE~ Ž\(/1:%8Ah^|<r3R(=tu%<ި lM  (7}ujgi}r fNf;KHk:-3\*/ejGCh!ۺ۶E\m\HӮh-܋ui(kyw5R˿0"!ܤn?PWο/qM{LmKJ壅CTl<V`0Fqh lȼGȋ$3j3 ."cɁYS@ kfM )mc! cB(sJB>Axͷjw[=U\ːΦUXؙeɲf/R'vڗT0aH!`Y= 4܍BL9kj4h2~4[aQ?t V,mz%vIJ~`cٲTv&1ps$XjYC!B:ֽ$ AM~jkd>#? @\uWyK2^OrbXg(^%wSgV: /LaQIA~I"n#DM'$ژ$`**LXt|KQYahAYt\QR@&j("9YOKn6ș;le3jElm_#UcQ `ECQլN cT]=4JyHt[7&YhyUfh$r':Pa} H&J[]yq#;n 0hb"'.mL!6=ޒF`kܨ- :+Vr_NNwQªI9`j&i N9$ͻіoZq2cenIl P+9@dݰY,'nD(>,cJum[paz_e$ Fjg?a21}V'BMXqQ}PP%oѺ瀄D!W_m9w$mٿt T[s`m|4X(We|br$Caƾp~CWJ颠¥´*NPކpcUzOx; s_.S 6n15#>'fz1(젃A. JLb&6tKs A}[nvR# I:R4k!M&<֙ yT$A 3{O)|D ]1hK' mAds %{D+]Fl,7h)R5zdi؝i{DrHdzSⰤUK@-u tz5jƛ5=Gfr@?=ڹJW!YO"H%e,γ%80Hif4@AoyHR^6*ad,gs$BQ`ϒOXG!Dʸkrzbp@& A|b4! o~Firv8ʩKߗE|JHREҏv|r#OGG[h׎LˇkdTCm/ܟ4<0@ >(-Γ@iG} -t31[{jCs}ŗ"NIlA(G&JQJaRJF#XÀ&/6 M~$/vNȮn.) .=7UV$t%ϫiyʷ*͛CoLё<쐾j:9#cd{@% FdgG{bԊc#K\ӫu̪mcCU`ĥ9f #I lV$1.V!Ri:Z_Ex 0jBDcXj*ǟ>fyWCw˸Ef DA/*׺z?b}Dn[uNK(-=EUx,>2%wл͍.GBTZ˘J$pq$u0fF|#o(=w\$PN'1"ލy.a!m)@ ,|U_J:Or n7 aJJ9d_ Ce٩g}p+q"LJ-^dkVD:?_ !B޳ 51 -7YFd:𒩇k.J6ZPaX)U]ab] PO"%W l^2^wZYF/F14ܕRZXf>>NK5G)2i͐g0k=ѬfӖ(tD+Z7,A{r<hH$]; mu1gi)T_] S'4%@ݸ,~/)3d8.`xHc٨0ZCC4AAכTd'KKhr?0qt20>2̛YD-)ՙQV>]vvuF^d*GNÚs$wCzIY6&*9:L`AR6q$uVf%n s?ik? d|uYx ݂؀l{X7sUX4cB5LY%V~6CQM:s4pC /A׃sP*hU2 C[fT Bw2owƔ^VpA')~_x|& X[/2aGP7y$5i/0zJ5?bCps~S/$O]X$ͤtd7^qX/#~Fg}vXSWjn1>7; ;r|^oI$ ,Й7h;o"9@|,` {GU:&Bi j6On N8ܘ*yޣo`3nmU-КraA"4gۭ_]^E\z<[4'j:Aˌі1r PuR/j5 :?<` 5F^k*0nMfg| VE]PT`YH6{󤭑g -b:,0O[EŰcˤ#xV?sJ}ljaHhmd]l_gΘہ"*JeeI:t{)rf=1-a&2[;mX{S{&Ƀt isQXB7D:(+酌 L: Eiַ\ՔL[aƱqoMr[;U=sJִCV[ 3+HD*7X[2FϼOhLꐮXH/hL~1DG/{=̏r([RS2 m)/} q- 8Ax/ywJN*損!VXϥj$ըR]Z\oL;_km abWz"^6p0}lț57PNw4ԸNU]Yx&`?_E{e$\^u =508^4f*m%,ܜ~R3Sq32C̰eC@Z>ʍَEGbӰadq5Boݗ[NRt9~]+sA?~D/5,\-󕲉Z`i11dJ /hzlXAFװ*ílj(Ax{0#v9Q!>Y3Yec8$T⼕ e+NVoM<3b\l/ڼkjVǃӨI5WmLY%m ØWMhhhߐMͺ|I}M#^LThwp<-%[߳Xxgȿ+ Q0k|abr"XÎUÈYx2:ՔP^wIP pX%(97$},E'᧘XDaVWWuaLHtp78ƕF[+!JS)7?۫9dx8PZ2(JoY4|`@+ IJ& E[] B-ˀxRD}Jo՚\2``r9EzcXU|kL̥e/#67]`-\b™]'m\ˊRrW,7og_m'7V[8F!Rظ qw2T;g'qK) (//orX6vOp(u8yDѳ"EZV=)$TӰ\,V9 WTіE`ot,L.vbfOB \}̇a۝;G rٕ,^]#=n *׮i&ג+ReΜhR;^Iq4OVJ_ ;3|H0k6MAU5}~e!b0!E #=goїu:0'\fb"40c䑍 im4 m[C^@V,>F>z?Ae5$yWuCe|RB{yDUXy9׺ܡ~i{Lfk lvU>׷w6XC2˴.\9~/h#g )JBL^-q =n493ʼnգgR淪uY d8"e]| 5χ^r /xjgR_t]%UtZ6(ɟF-=Yk91IfŔ^<>ٞBn$k)L^Oc-rRLX'a#[RFXiM:bNRև~&԰'=J1=9,O22wڝeJ'˕4|K'8 ]WICwgx߳A]Bg7^h"iRWܹ$ cb4!AѤF^IA_JjNg(|J!DVt6#韒Hjd^ȵ 6u!߁e6`uB(X"95^܋cv)6>*-1v I`/;;XoܾE^ hO=o ;9nM0p%9hI[VPGюn(;q@Xa9Xfu0+]䓱$23 V̬(.r#?s(77KĬ9rD[s!<"׎އ+qyşIs(h̗ :ij4qx!֞}2%Aj3M1CC3j{EOVΊ9ζM,y%@fz'axS?Z'8Ee"Nde<(k! |2#r{7QzBK8"~3][YQ;J̟y N +-[vmY]Ǯ. {9d5]`[I1+7BMTW uG5N,:fBӱc{J.G;9Ka&Pj_H@ ׽xVj&P& Ns&y;u{Wڒf a sp pB^L ֆL?M.>lvj~/2iCG OIpdD#9=B[ߜh0cɚW)NgR=P_cDZpRF9R].|@[5y0/(F1ʎ_nC+#W\ٵc'py(W O^%QvS[kRi"ċIѦ҈eoY s L$5.8+{DwΑϪ%zݕX< TVZ:86W| iO. Qysn1d/m4k2ɰG},m]Re(=UF!XM˄_ Ǯ>&PfsDLRNӲ*&3N<߯T—xq/^;D 0|0ѫT2;К&ľAdoήǜ9e0Ds5^f<0;#-%NU;rN;egvlQk]$gq#*UsLH!}{YsR\g~P-Dg _gV +"ÃB=t_\";L$i9ں/k}m 5yYۈǪSc0~wtnh-eƱe=|!vf! [o lv 0ߥ4@Vث Q`k4/B@\}u0[^!k 8݉J|AK.l$qAvZ=) <7Y҉1 oQS˚Zׂ$VQkB!#IA;1;3y))h:cR|vbn!Lwf̨zYs8 SfyCC= re'|AJ ^Ρ¾&zM+n8 j\G, ['z|A030Uz,VфC^Z;"1<'FoU_Ŗ"R] Ae/-*`j-}'ESd +Y3H2ECUKaХwhCȴl-1mq.a3fU 0C@z5!Lycy0ݮd`fFW6,koϕɌ9?{=uir _[ᢥj-_wt%ڻP'$ g?~,+dJ҂ik>k摚23Sg%!}U7Ŵ rW(^S38r$jkX&#>kam=}~,dj8A),Lso7p:_X $jύE7fi :  P`<31t.,Ү񒓮فc+NyA]eV۷lu^8>& xE!H$V|n@oI|AS 1]Dȡ JLôp 6M haAHaG#)%$/MJJ&ˍ|mS9QHL\-\ܷT)l-g\ M=Dp~C!v'1G-3N/ 6"JZ4F1Y+9wB/NjmԲEW/,+wJc3Vz":iwI,Ws⭐leDd:m1Q_lO1ģ-iذK)`<0>em~c“W5^B,XAdkzG3Phz)TBFB8jd& [^E]OI#m#mN-DcB מ[>BA Rߢ݌=ay"bgR_ wZ~~pPGCF UoӼl^D zc1m1dH#qB`d8\]~096"ol;$f)ȆA>%z(cQ~vjY>E8ob9'>!*tjs"Y )Zx[>~L#Ɉ2TzLwii5#h4X+L?$u ;a+H\FI3-*K_^b8oJ&s鲜 R`h1y* #!NApf;`tdWq$>CwxQ;LjuKS`hQ| T1˜nBtvw(W i0wa(֍^ʪ9`wZn0Ú`?'dNV3W@qc%ThA}3K0'ūmlЮ!C]+ kB19䨨*(JXzp)4 I}uQjwd>f6=ʆa!jq0]8L蠶şW9R{osӴ'oBH^Je奸ʦ8*t{x%ONA f˼/ꅗ'eJ6JO$U (]iBD3v*mf"<O(|*2>A!=QʏI{al?([Q]#i:3Ӳ΃xc; K͊UGt1H`iSi\JKobAgF͉Tr27Q7RS!XhLbDDNUW,+ -׊_ ۄ7p~wŸE39N0/4`?v<Œo5DmcA^?\LV$݉"t0bDKj:c^t{cJN٬&J&iӶʓ,QmΊxʿ?Ww5d7ƑkE,`Տknm?*VT)~>a2Α/~n6&i3VM@Wۼ(oqHKX .s^7aaR;XC.̴Rez*pZD=9HԂ;< OcS@bFj&RDCfts2Z<rCQy(C,vj=kt¡#R &:$\+SfgVْw!:Ff.e9,QoEa`P|8ti5 F- y. #p=UYGo޺~@ԥr ~7A:#5S΁{AЌUBβyL,|Vz!VsٿcҰʨUlG4vb_4FCm.C_Or)gsa%qnkx}'l9T"Y٤OGڕ }dwKR(A RM*S8S-ݢKa~*MG(EO1ӳ#]}uÿ B?oIkؐ:ȥAhބfpAnq-4Ζķf fl\lHWz)㏅}\EQG@֕(h= oPFy B^~K00vZhNn qEֲȞD+~'qw[~4{$W$MN2;"wsZJgPI}BDhc-Z"Frq huTAxrEwSx.IG-a ߸tE:\hmVZ Y;CL)N[Y-K;뭊 [*xGc2Ga)bu趋H o1|OD@NstHܿu{]}6mg'SGeT(?I;EЎ?ѱ8.~<_#w,ԟ !=bP:(&^}KjVx-M~AeWL kvBElގ.\0BdPVZ hQ˛` +4%1F†~E<18oӭQ[0g+Tea<Q=e[fZ$Mt-.ZDʼnDzC6#ƱxDk{6T!S nԕ<3x-]m 3P} j<]n,8nD$yH[6]ϕEC|򦺯ɑS$kz@([ cEH(ó@iN$:y#J@*dP&sUngd%`Q/WVI6J{W=6b$)>X 0)R?e]+pao#3 LG[D˺9Z.$^Fh| |zFS)uu+L?8Ȩm d9+ЃW`bh@E l8 R\BTI30A-Q{a.矊u'z[bnJlj܎!ǩ'( R\h(Okna؜~505&|_c0'P=ә[o%L=1 o! ͘Lr<[S!x7kvf:ag4[`(}5lG; y1V#-1 n͵sWX*:rX@H|8@z;;;k#F>C3h*(|^LzW٬!L'Og9Ll㖼=ݿ;~UN( ef7L+\k<Ȫ%A,⮆s]Wv6:22< }|u}!̟ü>$:xiܚZ PmUp>z)T`VE$$s5"AC@ v$T B\hTט.4|pRuA @[X;t`7ZPrqqx"7d*V/$_ZFKR @}=^Mw_J 򠚟 //cCg3Hܦ&jUm%zz蟛9hસƟyldꮎ>W%?ZKgEzG$ɰ _q`'kh`;~]RkcQg`$ښY~=ξdHt]LS7?ch2[avStj1Xnh''{m*Gk-Ms&!UUfT- šHX3Qܞ:FBeqVk\yac$t *6Fr}04$UOZ#z+#p g*svY^W3VZ="4u\YqF뾅ABIUD8-.-GG#l![Zx/jJV5KQo2)ŀdͯۻY.妡k7苽B]6Л "5۲ 膨'%JDZI,em /^C.]c>dޣyGPLjB[4( v{M)ZnE%;JCU%2kԓ p\U}R"> fgzsdx b=ԱY =z&igyu% 3ByB1̙SwW pa쎤6Bily֗e HH6wcY/xGӉr@O6ʾhz gFGBJ1%VBrk͈^6h|]=fi>gIt`ALLdgN@S<~)13_n,nnvdl)-h$! b|cl[e=lyp FSRC)[U擱I($|6+z;M{{ ̹ Oeq=}=$P֚70NyZ~ZЬi-q'"̜KwyݓEb?noZP8zW4-TE0ƲWqn8KfΦȽ?/sx#5Y՝]k8 s(i5΍=sɥDHU`_Tå1=\*CG -gM$#D-+ʐ٥0WIkNLiEvVtrIfn-PȐV_CN!McIe:ÅjJ΅No\g ПvE.,B&@@iSWאwtM Ugg,\`ȶpx/|$0Y*pD208} 5:׷,3xį~=-kL;XgѦ8ḵ͗q·R7 )Y* qҷ\33DysWd)4s Qᵵ=`RxXRoޥN^Lko~ڃԵ';\^oy*=pImw9#sfڐpl%cn]%0= c7&Zɿ! EU%}%~(G aݾ7AQaEx 6 גx6XOXw }o‡%mDssm0(s@H`y2n>ߜI-r\2'Cnj XG9P1翕G۬22H%f=c-KZh)ɏvAcpCtgl֛BSZ4om|LEQ0OQ ,8 `O#GM^qʯp5BJXqlc̗NIYC)(stA'lcpj)&5m^| yg[c Á%˯W8Jc&qX{Ѽt_RYDVr%@.\Oi]>p!V$`yWyȌ`DT?mXt-=U|t|Lt|;jɣ̚/p.˾{FW 0!XZ+یk:f7J#g^ۚ:Oj)/pmaIz]/K,IjJ4%R=3yP:s"تEd16##,['h&;!sKkXDQ27qj\4'K?BD2kD'37[gK(KFXCE1.ozi2ShnbG 0tqx,gD'?!a`SC&l;y!g_%^ OV$<`.E_ݞ݉N9KۤDٱ  >$m;À7^R8]M@6 eٴ:l!RhBjX[& To& OPAk;"#`b3ʵ#5jnhsO4y琺yHߘRgPT(Ac}'b_ V6xz1$wc:. UcqfsO ț5/1&qq4yߘIX4MZ۵Coeje3ou tg zm|Ш5+(@J!j@Ł w(6ir(vUhH5ζ%$,r27F>'7YݿOSAxLFDNI,1vWFtY[2S9\ ۿhaY7LHsrǚ"M P!b띐Ҏ ęz;hꭑۃFHmSs0֏ۄ<{(!b1e)3>7BTTnSN)w326ܙ,] Ⱦfk^~׎RsnLyJbQ Fܼtzz4P߮ KǤq}:o,axwM9҈ jHE'P)Y1AUL^$ʙ}S\kc|/'Pաpq1'3:qb S{RV|DL/eZYVg-L]k8UCcΨAhkXlE{u,NHi=D!"D_q;();JjPLs`Z.@R 8~˟6!ock3Z ͱM&)Q~.$niNP@ =O~8+4K@̃ذ& c/Eu6[~vyBGFH^Bh چڶ^c'4,4`"*/_tOq`q8j<*p& VuhYg'0UX.k=lH?eYU&sD Iy2Z*KF,aFz2s*_ 뿱 OչoEA]?JUcADh`D= pRK0*AXL*pt)ߪFS"m(3jnjbw,]S /hQj%L=R"QkUNqel祲R C 36"CI0 (=ʅ~U/n9dQxy"KWdŒ"yhA d8(qR?>qW +nD0 ; VƘsjYklX|" 2otKmH j[ {yc-,1Q$m?Y2ũ5f'`*΅"_DNoKk%wG2A3ḐA AZ+oس[+@GO1J.H`Anp˹RuRQ7OK_( =)ʼw :{X #ZC6FLfݫa@+fkfHX-L)6;`bt4a`5ܚHo]0\sM6/e)F\O-=\hAo~QT-Ѻqm|3*t*vUԩ^P/5}hPJǢ iC؄凱 ,j!NL=ds[ ]):2*S7fćʖ5;]p5y2h!SF_UB$=5 ^*<5|`1]s%x+u,QU? *;u4.~A'QK3-΂V?#﫝 շ~۾ 7Q`,b0([v9f(QjB=5OkWS1a ).6OƄ@c>k͔\SL { {!NNjd>kdr 5mk;؃X^\FQցhBa 8:\ZQ[#@ѳի$zPfM_ڜ伽50;7f/VY1By&%{bG\. " F'(=PC ,Cv 8gʡ.gy0t#U_ȗʋmql{#Pf%%}t*@`w 99΃/g^n-Bݩ eκBL5ҭ+&K ࢫ Fqݹ+5ŅQW(97ď,YIep,1J"O"&a̋-O '&A/3rUwɊHqt Ch[2T1Ͼh:&{~I$ 2,kt &u/|vΤ&fjrj'Ե&sއ\\ʿ؊'F)ySSUJ?ú\!AvR 0Ym#9ݝ*j "ii^qOWpUiY(ߗz=7Q 8Vtyj&`q:M hzz|\}3%^'1Bzjzx0fZ?H0zu44m'.v챩u5l0 ZLS,}R`a,S\I6YK9#5%&?@#@~)0 ǻd4~򱄔%ࡒ4K,AJ5s!j}<WN9`Cp=&`QR -_W#zC1%扂(uGOѹ|(nwe7n=x*ZF&)W+s7O~5{A;~(e|pKSf:-B') c>3fCM ^^hiWo0nui:d|ѭb/mvأ Q|ethO}32RLճF0J~|E`t7j~jb֭ٱ_}+"&K>H32<w(So [J9 .*GOZBXZǫŹpF>6e~zOw8c4MirB%sPSNC2gB*aZsÄph X%!3Nqe  qY.4"r|jݺG Txr3:qE}}n3mzQn@NZa7[f{:@Ub.Q^꧱dZdbiMFQ:1&A]<̉!XϠ|ŪHpx>2p@ yHiuRЛͱZ7 {gD2:2;bPKR[O3dC\asOx ;?MD3?C-xXzc!}7 EЛ&CF8_ò?Ϝ(zwO#*4Q.B _1]'^қWG19m@pJ_%epJ~\Ψ.j^A{/qZ_XkzˊhS||l[CMT>~HvwS/J=)׿^e ?Ju+HX3qE^P9UEUڎ-V6=M>@RT 56>ݡϩHkYLj]B  TlZ>-h^H펈B Ҁx;-kTpRSTcZ Q~օt7, MU# :Jmy_lApgS$ơΫ+.ȣq̌V?g4ARp Ң-HX=[R>ZVj )eAOuc%3ܽDu,QS*yIM7g rTG"(^n໰.Mi^x݈=YbEn:s٧CT. Ԋ%1&c Mj2Я|O$Xx FpQ}xAr !'gӒeJ_J.*F([a Ô ǤDCkb0 C}g/|)&A+\b@tUք I=kSt>k'!K\gQ$>ȶ ױedƑ6$@u.:!@ݜPՃr┫b3RJ|Ce0HC庹J`3NH,teϫ՛Nʿ#R|\gV }KamŖFK 20JI{2"`Y\ ms˻WHr?]*[~Ψk8OLM yxL^;$%mm:?S9"m% _zNM-䱿ۚUmSΩoLGj3I`NΆ=͵rۋ͸ٶ Ӕ\a( MpNbkŨkfp n.t0"vuC:t]|mə ‡=3v%m2֗M;#UvmuBKF5zMeǭ:n?oa5ik@n]"<ԴqnHx \&4yt,ع?6́Z51jom,׀ Gt[a. GH9uyivs)+ |5Q2sL_YPx/VMjLCP??U차OX6>.>}1ejM&pΰ?@NE4܇Sֻi33 T-JU\u[~7/*]#ju+Ћ㲭,XU5߶*!bS $)z_g9^ 0lO`S$WlDuLUL8IƎCB$PF'mmUri5w˨.pi4MYPAӕ:=pӷ(ȷ) )ˉL a/w!nrʵ .6Sw8X:W -E-0p/:GJm-O[RtYC*J4pЊ>͊cMUh=鯔 rj W+(-[!|ڛ#m3>g'@f`ϓɁN(YP69ʴjL%[ޮSiyb:CzgL>FBߐz %7;k*^8TUؙ{c,#@&Y&\pSG2ϰlƸNJ'*S)Dߧ3U~r<KvX9,L'c'*dPGZyek]!hLk8)Q6qӞقUA$&Dt1Apb gu²7[ b"᠐8?C6 FJ8誣:% sS+qLx#cbq6;tTV {<R&g׵)`ij-줶<(1>mJ<ƔڲU)ѧQ7JC=sMnp]Ry#Œ(˲&~HqE 9G>K)(MfшJzCby@7UBc#1! ; m5b\ed闢)kR >n'c~ @YZRY<]9O7bBFJa ߊ&u)w5^}`+ױ`:g۠k9 q,lP+CԙO=BQ:q8#wܖ*cq,0**^fg#075CzHs68aˇIS1zM&$sF^c _q]o$%ܴ ϟJ&<(ŐF9EKka"[,߫  $#dN&oƽqׁ֨H]U{9\d~<>]$,,O9ؕVtEittAl' P Z t=D{5FqʅUo=äy8Km+ذTQTE jm, 'ZU414'\Х::.[}N?HP"N1]R\TS.fêL6Q_ #yH<< ͨނޙ[*5|ƍeK?^:>+L7@]6@!I=ӘM* @恿7y&P it ; FpvGu,U%BV,2[pfXnPd5d +|u`~BZmw Pufy> mcf1_\!(wP> hyzꇆQqH CT5C*vSB̫od /3ԋ{tv!fŢ(=إ[K uDQ qK9f0oeZ:[`[PMLx,,4\Y/#D7 Ybu]4޷=9W"Ce@%xi#lK2N%}5}ET+tB=j!-e)0;/qu& |Y"l6v' tlD3aˢ nEy:cQ2gS7A,i}S Q~'hu aBm`qLZ,aKw٠"3g^d8|NI(x|o]v+@mDp&_@W#{.KLSvOV : t!Nd AfAzxQCS:A4w+ȭjoC<s'\S$椽,yѰe8*>EG(0$fA† P$L5g+I"\Cug?L G",g5mw\ͺe\ @~e*1/L{y0Tȝd-w"ϓߔ#_qވ*})ݦ|Eۡ.wʁbSc vG9T].6^-1FY?Nʍ]RViwQ_6|(Øjq5~|^a?'vwԾ{#U `)Тα_ % 3@ f$\G=%V\Afwҿ~Sa/KIW{1BS^<#ZbqmMozM8bʹOj{’+i -#Ǟ| 6&׽lOh\2(0IP-u{royt㕮\ %u`ʩ145{!.%Ofvї8ܞ4ϴ>9/w>o:Eȹb+i_i^"ЊB9C&GJwlQwB'lF 'xVpB VfhM̒NR9U 6,nfh~kd.l7+4޷(<2o40u HJ)1~Xi̹\_ \H'N8#:jD9kgPlq4 XRcRAGQ|E ]MRM?FuJ[kb"&)H I*-I;c:NҒ|bMXZa} ݻseլ@dEzBD~ (M}H>d\C\\A C̽(C+<8|f[!J*B( cVaQ6 åkПYb l/D$PئU賑ŖcS24j*uz?nҋ}wVBvI)B\н ?4h{){)?(F{w~OqR2wFZ4Mh2)ej'C' (&Xb|={"QHQqeCotj;A(:"j`B*&lobju2+XAYLbg`Pz56{أrvlLZ MF mkY%( ٜƤVsg0 ~e}`WaG\7&J ⦈iAX|}-&*y~9Q+`jU+e\Qhcwaؔ)h1hV<z*1hDb$_ 5|szYEϓ|H F`|^nY.f)Cc͑%{gcB[o@K1Ö5ZT^+1wPfȜwpnqb .@bQ%F WGR=bW唾Ƅ67;XEuGgD/J)~2 F$vsӐuhfc6cyһk bnqi $*c-!j{m&K iےŲgaW//۠h)5^UրqALۭ7Bya@(+>ɬ˭$zH˺H>BZ ٟp_CF4~Q.I0HWH譞T%㰍cU2X&j;x?* d㻮L+-eTd0 4lTЦ=Fg&L ;C K@tĶ ;,A3.E .˸مTILmW6`w^#&r}Nvv~o>TpPW1SCR!sV@oDlTH k2E -n B9UXt!%e}1ɁAkeTۯ[ ^UG<stYle@l# w"B9VZg w&1nK$!>r^Tѥ );CGz fS _~6j*׀B0q^/?=X=<ɴyˁ=%: ?+lӀ Z% 06oǼF촊T<+oC_PsN[<ԁ}#<O2=T-&Z @1ڲ;#KvnR59e+lmNN;>nykxYSTs6_S)ܼEY:pnӓ>,;1/#[U+*XKznqQz(&f*m\4,i`Wʻ*cݧ:V"0yCHi]:onD*ȠyMARVM=Sz|M CSc&p,oE=aq5Bm<$TLzG[5.?OpfN(1Z'fuGTIbbcN$S1%'6c)tai'&\󭣊Kp)A!mP3a>;^RM%s}Ҙ%DSdݎT rm.gʑ~#tD/e0??^>1vIHm:2ty*%m{}^ MbxsGTӪf8>*wn:eλ3oFo"WTnNFTBůxߠm 5D!@vewm/1nmu.8Y9שZd\*84Al!j{;)sn7sv R)|UJ)N'5>[ ;f ! ݸŒӑ+Һ:DԺMjOgs`ی"ZrY;LYZ=ȹΊ *PZJ@8?) 9Y(ǥ=bt4s@7<;~ -UL42OrhYŚ.̇(zIyC+283}R^툦G V_=E3{ 0!)w}'؟Du}\˺f⫬>`OjOH\N%^þWZ?4|B~yHq@ 0k3d7%|tC)A!:F3=FW*5Ȓ|VC_(#FHmet[iЊ`N:b{IBCtH\hhXtEVXX΅z!UſȸkR.e,Tȸ.2A58wA5 !Rbg ʣM`]2=HHJg BkVe(NIF-iiqDgT}"=R:l6NN f<H57YNGu3͞M6kSEJcqPϵV |t\h6=.\Op0WKB͖0x.):٩lՌHܓʏn9qGG~RaN0/竛e {QRxh{@(ܮ)gftFvrڛ|0fHNH0۟̈́;ⳮO*ݼ8MA+-/m˒D*fP5nپ7"J%0&xxpZߨKZhb;tD`Zk{޳dO ВH26ftO|$rЍ~0.?3qf)f,=GE|gFߺ{J#iî5ť%$iEnX 6[BX}9?FwY7ҁqc4 @t)uLN~_X\,N860|!&+ȷU9m$:҆* d3nHlUKq[ ٪gV{w]=UN pEkz+hIS` pUYksl.Ի,;7\!VyD-I+( Z|gR嚖PcE# Rg.01Ϯ=LO6[0)=bQ-4Sޱip2Á=-1 OT[ >NZ/7Cnv',ފlkR@26HN5{t8IC;NˈO% 4E=zbs)~|B8wSP,WxK;L~FUG!o+F@E t84 !65WŸLF]z]^q`LMf6SwYdIgg9i,eI[}qL 杗'5}*ztjgU6c?`]д;|P|[&k?w ŧ"b9qQ.m^ţg ̐Oቱ6BK9gv;3?"d%0jXʯ/lQ i6~dHOlL;1QHבT8{d:wЋ9zsbG̊ɧc5w,RrXҤ'!/wrvTK "9fbQ?yl"LK2; l !/ 5Tem fwd}{E'Tb?I1庋`yTRIA77 uuy #:ђ76)Ļ6=%PAjD?Ä :'U.qiJFnRKsAs]%q'@ gisךL4Ho "rhM&8{71l2<iˡDFl2 PkbZn=&u _=̳RSP4beSN$tm-<>g!]-ڎjYvq}ןRi♴OJ'L{w_$m-]~4m:d(xF@4|Et,M7xgHrR.4.$#=`o Z47Uq+Xc} [` \Xos"IڟY_h܉lT )itqދ0n],iM_2:/S >|lgӃKVJ[_՚aay5=0EB?H>;G5-\L?PM؇|J뉉K3p+IWkح}&Cpb"*% =*aDvڡ9ZҰ@NoƷަ]<2aSmz@='@;\`+![c}6Ռq xwΛ4F7*j:dd? fdc6b)l-ZC.7S$>Z>c@=Fp9cFΰɃYuH.ڱM˜~Ej3N^-᾿ZܺеP/3oY,o1o9/#E#ϒ  &YEt%UtZwĖgU|4&9X/{r&O}$slz" +ןYNRhljGI(]iؾuDlqʼn3λ|XAY_%Aض%3Z͸bύ8 {ybŌܵmn (UE!Nf]IdVp4nJ)ؓ* @f pq#2E??E&ڨ\PfoDb;䶂2MBI}͑Qϋvb:eQ{tя{>#Z1DPGEA?V4o?+ceެf-^%Ag( h3[3[)7kT9n>%@YHцKkز;2SY\ ͚Z }=UD:I̗Wy0iMtQ]X-Gs$Ȫ1wi ~jOs.pMS\ؐ+"T14/iq஬o|ٷ :k8Grp%[PUBtOr..yUOXH{) x 4O\L& ־m)Y5rXt-]Q&T,^gIJk`Moms  R h1E)7:F PYh*+fKK~MLc|RMj5!3up0"mU˪A#龳ZLny1+d"'hb9sߩ$a{aqrO< [4ᅫfκ׸KM/rJnы9fk 1\ndK }chߏR6P3"zbV, _&o+Zl'=9T/Qx] b#,҃`m1;bu0^3Α05K .! ᎱvTU6DQ]WdMT!ZiPnv(as=}]\}6qdO$D@}e~˧kex * xP;>zȔ^6ݷz6őv4,Ϙ˜Jg2ў z)כ_^dklQ׾}.R( a嫟ɒT*%Y;W/lA% Yf"}|!2ofUb/*ׂX${+|a W e$0@!q eWBS3\h1(xs7FGT#uSt7̢,w[f]`e7 D1 7hp*93 ʘy# &>nkO)\UNLrEЧ"rfe1p`KJOAӥ̠+n|EgEm TuWLDBmW^(*?GdɤD(D<ݘ[)qL oJnBP(GῂO). QdʠY92RUl7-h:h6;.!_xpt|yG$Mܸ9(㈕Iǝ>' 5 kRD)yPNb]ʗ(_|y]p KSpcz)^1^J5A{Jm X#AeY!+:gW"LXd%1c[mܝgL#V[W&OZnsQ aU- p\-Oc٬ N/K$T%eB@DN9+mzG+%] u9g{~St`4TxcB?Ըi#Z?Vroq(+ aF+(<1ҜdjM.|wIR2h|C|U5@|i\%5*,uRm U^zp|$:/&MR.]>_Q:fTp=Dg͓J޲9tۿZ}PU+TĪ4#R6G FXfA>sVM9'{؍BuOɲ7X.(p!ڃl޹;$* Oݞ|Dcg*2 YP܏z/R_N1wmqC{xEAB"/+]6~Oى.nJaC*4)st Yww#`C6s]RG?Ue\/"0|AT-F(RFtQ %P#r`GUE^vj}ZP4HPꑡJt>9K c͑ N``0^wX)i[g(߼5l#7d0؀ǔz #W#)xFmWpL.!/Gz MyZ(ƵM.;B4@;EpwV(ZcPxYwwlW(o0S(2݁쮫Ԣdu;`l2JGKf[kTc]:{L !Y6ZՉ`{u.K3,INr x:/2: qWFq/>18gsD%9eQ -U{DgokGˊ_a_ӸSǍS܄7xLР)=`՝Ϊ!=Dw]UV[m `%lULs~|$ƏvQ'Cfb|dvtO-+^sU\=5x-&vzO{MNb E4>2`Y=m9YzZ,b)Dr҂h<'Xϖq'̸|V@D#@>J ' &Q<$#HNfwLEo칁@4@㼩s8fD0>}2DGqSwU)i8;LWp +8J;Vjŀe탑-0j#B0Ԍ3r|h25q/#d"fOkƓU#_Pa;b謨`}a)}^>3!ŠWɁ~U։O'OV{4*q*'[a@B|@'|A/0COwg߼>eh^NF!;_]%R#.v츊]%P7jyz|1V#4gejyĥ6&tk쌵u3_3fuT],i9;co1eߕHNk~*2xuq>hNQV1:i_D݁2j!&Kv]WaDZzrcbj}3VZxGhua䆗J諒Y pZ_Iabhe4Ɨ=eq?l"+8kp-a;. kcL]d܉Ń֨Qqx]ҍ"@}DU4e/KV'7l[3iHO>2MRw~MŤ)^}q(js_}uj̙5+a,H*XSU"mff!u"9'#j~1ГZ{ٺՕHi@WԇmۨrrO$>кɩaa{X5GCCL%IOmc2T"Vt(zMNVfe6F6Zlk7}'%QEPdFFWl˻-],MNυ[oaٕ "D #hڶi輩-. ݾi/!{&l.I~qV"!fDUlnٚO|djBz\*qߟ_j7=k'WoAfͬ?XUB4a`ulםr!M^jHTN7L{Ŕ2W@ߔk6`yh[J ϳ,nX\cRN |Cx'[wg??r߲VPPI8*\F3GPi;H *? طZZNv]K0"Adŋoߌn[[Β_LkvTNѤf}xW Z6t# ̺L$0TwqAuRV1 n d&ܭ| pD9oJ.-cVY5nofAȴ ^C0w <78}MDABxa,C^-M+> 8"3[3.`bBsq5ђSTӥڥŸ@1x8%Kƶ~𝎯AvN=V"3>(Ʒ4IUu , 5~1P6-}y9SauR߉}zn-ۓ| AJhѵĨ2;1oN1@D_`^(%x H(n }t =dz̤ص%]LMI)SR=O{elƷѭ4[`ƬtYf<֫7`ֆ3ܐN2"V=Ay&rXFm"n=c:]"6 Xʚ5n]AR~O 3< _'{I OQ?};/͊Z#1j>Z]O)V˘I\/M@S%Cuʳ>'.7RS: !n΄J~ܽ1EE"fxs>+>y}N `Nsl=ކ6)nc^apw?^@RU~ 6=Dv#qjgP`exζEmX |݆ Zֆ熅 |vɺ:~IA7fp^U$R2$~]s2p;31NAT+p6^2=L(H{bܡm`Z>Ù=?~FTt6pQ{åBnmu/an ڂn8Rh¥9}OKWʒq$t9R(ϙKvm;e6GnHŽ.hŕA܃ONՐ);?+r_誋w}-m|7XvDtmVa=L@h!^HYzPw!H y>h+6|$ϤU$7a< C32hS}Φ|tm(IQ-8Wlj7]g~4S*a:7!6h}Ao|+C/'TI<_p D;mXGЏ]3a5k; V G v5-E.+^`CF4P K,ƛQ+Z@I.[͔<N/m_(/p-Q/H)@7(_._XV"Lhm;y(]tHs Exq|*f!9ȣs;}X|!F}ߋ;m Z](_~-Q _eNcQUaɃF73Ӝ"2k.^=h͠R%"cQ:}\ H ʱNҼ\@[Ao;6Jn։`m.j*#)O=O,!GOlh aWT*e h>7IY?7F´O$(Ի^YPu DRj߇;i-G^A 7d΍[ n X]'wCNM٨͓LOR㢉c(!'*$Z@UY'R|h\ od~xߣ.{YVX/'{Ua]|guwͷU/ ׼)Ţ眠ZQ_ˍjkiT8ꤚ ҈95Mtfe|0P:i.82kl`SunjJzO`e& U(0^(Dm R ʵV؜|P4lUdW$4 fnfpN1"t]O{z@V'TIh\Ơc7H0zSsX)O5% (O22''FJgSv8,to0 Br[g^a49Տ? UEnjcRwE[>lα]y^;6IlOzhEniɤ @'ȧo?w"QJahkZeNfWG$$1DAH/K>NI\:Xk$JZ.A - =lo@RC J~.ݬD+mR;U Sg0YAm?ᒭ>nJ4i#YQY8*\jTC\RPJ֔UQf a~M*;/\D΀YN:ϲ&3b=U[H~)1ڸ2NKpX,HMnKJ3(w[0E<%똑M0r]SZEʬpeJ<.bat. `[hF VY5(xgQUK[BԪ>&\!eS`۬ 6.'[&ߜp 3mGDf/DA;Q9,~wg0Z4b3HP%7`|5kebp``  hzUnq)|v DH2>CԶ%@(d A O#<àCTLR'j]$_&Ny[tb{DLb<˝HχnKe4oQ˴vxN.;NiIr~OR3/C03*D}3~/Y@o$P7~C=゘3zb V^YHtKܥX~ n>Ss2=du0JU˛vk[1as$okh7<ȱf}+:}NaX\dҭd*W{{ZyuǗ0]wu+ 86})%y#91t0;-ҿ})#A<nfVJ ZHb aMZ5^ֿJU!!2BqP HJ'40Ĉv $2LQgxHھ26LBI%,;.`eʴtgDx1x2 jNh l˜m x5 'oFkGC~cT .G~lqi($䢴k~Fegwl2g%e@'ta` ViF O۞cyFw ܧٰjw@j٠Zu| W$'OCƖf#O&нq.ͳ k:h a#McA;KhҚS9%O'gCw`y](0Z7 WnI"yb:A`*>N7r EiuWw<| iLHG5yF/EQ4fs_@T0bzqxɏ$^ + JY^Oz"NYH?Gi{6t,Oٵn3A)\\.a[?r >S]}x'V 2ރ ZB3 ?Ư;l7j1r>>LaS;{>g@mn*r`R2a}|ln32}. A?)x%2f% Ffk.QȲNo}T.]d_3i=J2,Sڈy7=aܻoPy$€M*s'5hh,;Wb%7u&5R!^SwaEʬ(6ا3Xe* \I+̀Tsڟq䮑S/g/3vl ͐ [Psᵻb+_`աtulc99`Ř>9BĽ]Y|JWrrvgΔ Hxvi-Gu=?!gF %S ץz_z!q]|fIҗB0 rL$c_Ex Nӷ{}g/! +%v{Q`l޷uBfNpf.[6ނ_z  D^ pjz37`}!( I(̂yCJZl&#y'^S躯3Mwϛ a:pw&'ňd v[8s.wx~Ŀwfsvhb2/2^cy4@H7H/FWud &ԉb6Y}5*㤻}D.ƺ{עc!Yop Քڣ@= LP+]V~kB,eҔo߆䤠OCk qo쩇 o~ T?DswJzEUJ ͭ> @.=1DEcw٤D* 1'FAf=3o\5~ o{^֩ ep$A+©7v.zݢ~ z% \MWT*,iFN[-ˍ(G2/&v;fek78o?<*[Zg&S=vg\w^u6U>Ek+u)vOJ/}  Qci_}*2 1f`M*MM 3 HPCYIQlraΊ(F㡾-QBTE$^.PCaf%( O!5*vQs8g:lj^5C@Mf w+7NB0jK1ߛn4NuQ?Dl-jRbJN]77 (5ՊtF̔v6j* أ֤A1Ijx@ yء㠜Q/%Cws ]@1cgy;*(bf9ZBSG@wm:FrECLSK0`cJ 6]SXy ^_OR4p|w&o.7vҬi],/7P*Ϧ: 5Fn;kx-kn 7 <5r߂y<Ҧe1*S2!z+ P=S0&zxexҗ? ߣ|e<=sdV1@d/ F9z둢ʖ!e&=t-F0NapS ʱplEF@HTPB.t"&7n%A~'*D&;q4vs,ӷ4JQ5Z0q{$|Mȗa1 Zq#QU@I@]Dn<> lףk4qV !X½4Su+ }gbz]->DkzXgT:|Q7=Y7p%QrU`?}2#ІV@Z6eX*b@,00m_/GrS)o|_3_=rYW!Nq:#17J΢>mfNH}O1Υm l>%`_leA(8-È4ml'a#VTIzGk* l$W*lZ]m.0\jY̾!|\) .H_zDFJOb\&i $[6IY:أg_J/d "78eY=]-֍1ZkIG{ߊP* O<-1>Ԛt@f(Lb# !_%`5{|:;Vax)Ӯ2a=rEB2gOR:^KHS &W)geƹI۾'10u4ΟR720lzRcZU-tvbG #a޷Py@C$lsHYV өMtF1E  w*x߁g~րS1>ϡhK HYmYPxi# #K2;iPBnRo8om>퐁L$dg l 2\m0*>&Ӝ u ȗMk~bKzK O: ~lq "_3 ü?d3uz9#2P"Es < JtPhy2PD_ Dk'/,.>YJ۔q3(vAq&q[w\eBb'f#r%̿2),|)q]YN,voخwaSX6TE UZԮ|鲘Z^?D*gNϙN 5{E_ן MTtX%mO,=Hmƈ *HJȟ\\/wn˽IKQv ΏI=?v˰D%AriQv҄srm 39\nX g4{ޥm?'( gQp/?K@ʌCgk3~noP4]J{O3I o ʗ &1YZe bγSD4 (nӔJaJgۘre$KSt:EG׳,ZB wP rZ}k[l˺+N))"yL|) [W[F\2N].$$XP/v]dJRI11u.1%^Lhq|׹%i΢YtHBJD}qT 񿦓c+xTi=*weĥS6 KesT7O=yG{#2B)tj˺i>pŀ{Gev髝v(*4hrc`2;IfpKњ i'x›"#wiT J'yC 2v ٬inX eUr3?iւNOi4;{02 /w3Qby b)(nGޣ(rWyzAH҇ lyė1,@!1ⲉ_gW6I*ݑN\G,sZ51[K5c:c=v7OCmɍϨ.ڃlqT܈B^q3aCdHfWfN53TZw|G*~Պ@J#HVcߢa[L^hgl|nӶn:ϖ+W*q&]gc.`Qgُ]dϝ-@C}p)7~BPH%6Hc2xtq1{-G"*,5TWn#2\$ߍioz \ (Z{]w(jkH84>.Knrʷ/P+͘e$O;ȅwЏ,M#U={(MI| X\ e$+[Wj$}]nG<4nkŒ)I84`[fj ^ET'$Zy]PWJF݋bJ_mf')i$mjr6Pi\i c{SQa cWccU $=]!7zvu=d׋uZ~U'GIy2@C~/Ϡ(#xy+V 8ob>վU`ʫRH> pu]/mx̱}|n-q"RcZe#M+,cb_COٱ/w؁D9켻-*dT`3JQ9 ('2-K Fqر(/r8D|gd2&,61>/l\Z͌3ak'Zo7S~o^zW만Xb6\)":Ezsr/P;q +8 Hylw8a'@sޮ %X\.7GJU2tIS¼l-I@]F}UnĪ|mDv6Xqom,JF+'= Q|tGֺܰ#bYB:xZ<О rU>R-i0 pa&Nհңl 81w{ܮfeݝj hVPSUu!mBf'p}( - t }`EzJp>Lb,.G'Y^G1,P_H*v4T[ a u}|wDڟ_O}HQt'.%ȋ+k o5Ej+ߖa?JOAH0j8o| )F8F3:ЮRn ⿲TwNm:_%,#-5 gFcSҩOAZ!{xnLa´PW2+ryt7C_|'΂8UH6I6}}5O_8/iZ/|L46k Cb',>PZ !zm 5 ;TkLt<: |%pqA1nً={f9x>`>nljlKpI z||,$K8Iޔq(*ʐk.Fs "Y w~~^nU3|-*ylFK4ǰ} ـXz?dOcZr b b{=#GޝH"#rSBw4PW0]v* P^ Ԉ$q:(/+1Z^/bq퐄ݕ-㜜e 9VDRV}x_eTB~.4 C7z,hk>1i}=qP2U2sɸy/A[ ,Y bA9)TK BnUS?;w8W"!:XQrVBaiQ\(CLg1 k좦#,hA­ m7 Q Nט!V^8i"$ Nu̫׉ L)d>IP:qyۓ]|+KȌt 8󸍧 ;ZSt1gI r=KcN0\8n9o.#i5ey=ЌeƔTNd1I:LƤ3JzF>{" ׷8ĪP`:ĠՏsԐE]k |GB#h ; =rxq0iuV?VLݷX*ԘrceI.٦l7FͶ#Eh{%KD kJ\a'yL0 bd=$_{AB>Wl vw\Cբe@wu88gÑ8 JI `7Y/(;v"ʹrYvվ1s+^>9(oҠ n/ ZrWR'LyC=SkY9J+E2k\ڽ@ +\ ą<9d=cV-5ZAU0漎C, NgX3A^MLu>P)<byH V Q02ҍTi>юٚ%UQG2z.*Ē jFOa,y͏P d>?˅TFS2}!FKQ:9&dbLz7uA& YSf頋"L!gD0< 96p~hȏ C21k3 0mjF@˜<'=3䊁m(ߪKtDɋ:00ʞ-U$*[щH:},IB *Ao"+B~I΍wv;S\F {,L>7W"DD%b.TTu(j֧"j$ky桗$`26Vަ/)an>X.tKņpzbS `Lhx^|YN}}*ۗ?vF"8~&K ;=&, 6/)Іhg6SS'ΝS!]T>hel1q,x[n Cu["{'T)d6׸ZCJ:ϖiɡOu{D1B:wO ,`(cQgkDH:T|\PV  pVGsWA_†Aig[ze}([r,A{[DiӀ5@0n?Օ2{5V' "EjT֙FB$/)<#7 n3NDȐ6B|U;˸KevUa""@wnsՋU{KWH{V dz֐ KJ4߉ jKdM%>[Dj,iK.2 [Y PIi /a$bgE"RGD$:դxR>`\QDG=TO᝵2m$銷~iɸtg>,YeMג8&θz}aS Ye9:wv>113Rm?9YװǑHbH5 5/vu_|&ڌxSDC5(&gu;׃h2V?qU*ƼvȞg|"#3u󾆛k Fۃu1/&#*jg_bX=|9wӨA38wGC1p^3x'Z"q&ke M`yx6?T:*w/ QyeEߟUg41ptxeq:=T(Vr {Y4&)[:p,ߟjD6}5`Dʭ R$,hsza+ddžzΐA긂0= s\HגEAU< U34Ox9|l/cSuhHX Un`04ĝL6Vd6U \y;៦`G"i_E?EnQ7գF&:/4:pmcW`]WUp ǠOLTYИ,s r*CYb8~οj%KZ ( % c{eeg-#NTͿXφx\RJQVovҧĉU{tc_lC͝aJHu qpNEX#$'с_^(k-F_Y/j$ m͔M26# q+09xd27>e!6H~h K "{(P3q򣪍g!xn6K"eḡIV*'abdLpqqr*b`l@n=+bD|˫%n"~MS%E)k>M:GS\FIdNTs?M >IG\_lPr#]LgI =o΂ŕ4ZVA[<<*` y&1fTVAg.fpMPyE+_}њ|}:n {Yi05wOݨ[~ڸ f fxk36_<_ˋ4&ͧzg9ODVzJW0Ww1E(2GRĀ$G>d4)jSKOIM~g_!7!n ݸd5v:/穤% Ҧ,ɲIIrucw֋O,0ؼMUđRLC:7Dž-J>PO:s1Y'AϭsrվHud*WAVՀ?9t5VPp{EDfE)ye dvߨZw#\\m񉬫?*3̪!ljP22]GS_>lwͅ*7ӷU ~ANUKz?1pe嶁!J$ !Ie:y=9˶\]H ` FO~>jv&&Virp4v(L9` )Ta .|Ʉr6nP~% =9^UIYO)shʃl,/eIJnrOo4B5)_AUܣU{;PV {Wv W.|~Mr]}_u>%^,%+b NsjgA\˪{w_7&*YoAa'G rAmemmb[ @ ]zƗ97<7=s m>_i?7)y#N;zڽi{ }GTؐ/bŠ+KCU7J1= b~,c""C.k]T?lK 0}bj;SQ*0f:3F ֈ^qP/2MO/ӉžaL9rzл~rhJ(Ҟ TeGZ`&Y(kB!/7hHlb%IIvEJ8|O_pH r%SɁF(2k"ѳkIUt)8> 3"P2w2hymMĿt`*es;dļwKcenhKq/:Dui+mZA('b @G![Z0,Q+/NDx[ ?vbH'ל9Dqʸw!z|s`jz/dkAz%!$UPaUHPjw\oɤ7q߇+%+dcT2AHw'pE|/'B?7S+lL8yӇ"L:%+Oj@di'IʅxN]%$m,X=,5@=2ZA$uZu@XKZ<<4s4xh\V5"CF4_7*8Ѩ+Q`7F{, '1,4b_EssD*JazevI !TDE!o_1R]RQ%I -/@q(0䗧e\XԂ8U 1ָcz9\"fc $ƐlUv umcՠ|}8Q몮F onq/Qqh>*HpbC;wE+~jTOstli< @$Y(e4_.A RZ}>Դ+nlV4/9Wù޽IbămQy&5 =$a~{jͲ1HYh4z4pxLX &e"_{’9St5)o_pe)%3ؼL\x=[f G *0KPsy(Q*@[[n_38OF<"tBE'9G`ɔT>b I|unZp 0.*F"2d`&*J Zpm͈8 fƥjqjgQ%1&!twBc n0b;y}' wN -Ȏ-R̐(*2gm6Ij^zR}zJi EUP= lȂzNLrYLC$y䕦ږcAh j}ޞZelw|/չ)VBDP e ~Ku 𿆈Aa ]oKfySUrΕDcSvTz6Ɛ2H2Tv%bϥNxD.*-qRDhs1n?5Ҡt$I?ɵL{=W}<Ҙpތ i+q3H@[`Vc!6I~M ws'?2ْ͑+` >{a0D.7퍰 R\ΊEwZc[Ɓ.͛:MȨ^2";"n{%C~J) >D3A+ z oJַ3X2)ʕuxdQdLw'䠰y"_Vd` 6AZ*(d ;@4wM' `8_I\O:?zc>G"n TaeiyLD^Tw~?O{ˇ؋^4ɡQAH$W7(Un_BH26zlE -J6c䪌 \k qQ=춊1u#=}E>vmƲ>5 Wj&&*":"7L 1-}ۑ>/8Yɒ} QF)rZB Cj&VKױT8B³z,Il%L;_sqT[4i˷;Ti:p0tJ(vz_\lV.wxv *#]ckCx81@hP͐ Y *P$6>zA49{ZV틻{a=ç;Y9gnd8WёGU;Q$b/xI% `jOqM{Jw=|]'+ p=)] B=&X8-I wCzb[53ҁu "@iSplf6/;iO>&`+8Vx*hN!*~PM&5E4Gwɤ^geE1OaL e\BR9L4N_Mcqϛ><2V{dyȅjddWPj"7yBi|VS|0.*]4}ةg}MwaA|Rx-R9Uz$RzE_8N bqbH*={cfeweIs▓c:_ғ_AZ>cm"*]\W_J dn'@mɑZ14Qb=;mO{|*,=P D\c\S.B'~S:BnMdݗNyN | :cDsB=Lt Y ( _-DŽ$0uwՖG2}"g1gQ\wH< N*SU^̺?h,dBM %= J> `Nԅ/KBnde0=2d8Z"$ѿtXo~hB@.-h@ȹ̑b (M]aM]|Βdž_Ix3$vW< ?}bpZkS.,1 <eIϐ-e15i>啃g*Hh|G.q>̽LqN/N lW7}ki]1Cco^d$wόVMћ򣘬ȭ2ec5R)ansyDJ%on׹,LX1n O@DƋ [8Zv!b\TSX=|v4f% 1|˄j.}0{]RrB=50W-/T 5ke4CףWkҸ0-,&׺>]Pۉnʠ<-ujWUa?Hq>X%YTbdA6d%۔Y\Qs#^YR\i1TG}%QB|"{J\Pǹ :홎[4;$-L%}3vLPWƆ_U`N,qt`"8ž}.S3ȎNHh SI[[UՁж6#0Sry%d@Vic*!|׷ ^6gJ;w uoV5d /b.).HeGeާ`w7LK3HUi zbs`(4FF`JdRvB.=!$U4*<#Ys"UؚS\:9񗦢qj}ᛤ1k\ @b9dlw97e7dhYB c  Z-^ Gc@|kK,^r/A07g`Q֟no?L Q{PPSyNn ݌dMAY9uaf(h- ǹeYI^yTӉmpbs.vj_  "JH[ LIǯrvK&}jVb5`W8mbk{X3ܘUZVyjҞ{4,ӓ\Eď+h7MO(gOWo( ^Z Ό>3fmM|T<ꗑG @tߘOW8Fxz>ÙsmȤ1?/R7bhD(Q3@˹F¡ᛎ:m3Vd1B5@_"A_*SVYu>5R}V^ؕƸyq=q tx ĔRO].WكKx!R3+pP+]* F#v#}|'߯zvS^&KI1,nos& QOC?M% ) 7B j&raiڌ][`]-&`lu"0s*%B<&0~(sb-<Ҕ$ oe-&]$R:w9NN4&el_8@Vy1d?@ٷw'V*[1mT2m d./8g-]Zr:j#27P @)w|<" !)xߡ\y|aGBhfN̢+T'Erz`fSYH6+ihV-8:x*kԔ"B8 twlvwa~ES޷f9vU"cr<=n'9B6G 3NVs<ҁFcHR-\G?<9Nf#U$i% 7  0#yy~|g2hŬl#ɋ"yZ_Mtyt Jt۹SiéYZ(PzPwC|RZhփK$үvU'* k|أ‰+e}&q) > 4ClU7 p= <^/^-^Dؘj?p<RVߨvH_?z K1 W<(2:g#/ymg @0,*LZ?!{9%o[ ?F/};s<ٟfTn b I_dm]3xt^1)*>j}& Rj ʃGhl)CP8yshuoiB>tm:=[M ;&jlXl(֡;Ts'30*)gIJ-wZSy_OP/1RPuB pmdLedh}@'!?bjL|>LSkP2<"ޠKU"zb[@c:%b 8eE ]nk{TOAmeܘlPZbڷuqsqB} ]鼮>n{/o:l&5$3g͆R? D,P pwA!#뿠Vy*FZq㟆fr,P'-^ͮpsuEujpEhZVF0dvp0DQWOkVDIցŷ'!3*ކ>\ϰG J Aw!} *$]B) du_ߩ05V)P&ɍzK C(-BıkG?)SSbTxz8%hV@0@Z=CÃ/ŌȔ"`EBp29c\&XԦઆ؞~$z .#n@B{ɝM!o擌V OٵCkFɚq (,20aQ91"RX-t_+}hڸgi?"̪-  =@Cbؘ| Qáe [H4^ ~p7OC>|[ʸ{)3՚B37n`C ԡ6B͓T/~-=~~@e ٧_21:chc߶" MKnP%g.S<5s1%4$ȠsŹ9z>9-]ma.fV 3|h3I:־'*AC3Dc4h0A3gT]sl2e‚∪kB3 =r{)O#l8mh"~v`0)64RZ' ӿi EP֘MVREteT?4: ՞1;,Y8:xqPM# R~cUm~3:D-}Ȗ'JsCd$: B= @SğùRt^XupCVus9%Cs{r+FX8E"o=)CYXv, U DG-k5~Ik>`I.dзȴ(K~DX%f1gK=V~*DVsͻ PUFy @J;cRWzw}`m'_xX^Ů =tU7{c"/aH$+saowH\͇B[!VD=1$=ޣ}[cPyE;O YmC.\W9ibt*a>BErJaO6XBDBkt(#׾ƾM$/ܷG8|8jAC;!v2S7][iZ={]~py4d:~f~b _k*i{OofrNǓԶ9|/x{+ <&t?4sx&t]}XdCxqu@]u~~KW\@&a{>7O\TJ&aHyDI&Tb=ҽhE{>Hs~!J_uJR#fOZ@I:IBSq9݄̣fF >1+Ke*>:EykrTڹ&1Б${%=Z2S_v5IʂnjhU"1x/OKGUf!/RY;B߱f>LDo6/t$9z! 8O$ L"P/B]{ta\MӼSUMQ_D#M, w2Qax6jgP@Nd";vRYi`zٛVR2p_TAL>Ƣ;ߨa` DT@7!Q{8͏Li,tDDi<м*Q@ gR[jܣtVM+x *JgCϖan./,c#K3+pjy!T%4"Du)=90X"5H,} A#H$#ŹM/>ٜb_T)SEi"_i~[42&SI&eN#Ĵh{|ԝþ$Vˣ !wƤ>vrY|N6 uG77׫`@̅->X^ٌY@:ne A8G],j̠~|BU+ ?;2]aŝCG󜖙̊ Q/^jK#ӓnյhem(]I,FGU46>G@(iWޣߜG+GUO+mqh8l0|3 `\m{h7Pi}u?dA0 =ҜvQUN?E>>+KFHOq>80 69c_J51 lG;kw܉.]آur!WKSO׎:+q?-n!\6P۵Ώ%ď~4tigQqK%2u9'V~ ֳBy)>y3=araZ"0&E6h0ZR{FK{ VSFhI=+@Q:7ϲ7y&ǘCʥ|mOE>0lj?Q2{ 8PMeUYrF98E&dŃD9PnZ;%˰n"*ſy߈y4Zc8i MpG'v ͐B)E(יG㧕6lHoĞaM)BM" Jjܟp) }^qC#0BN| y isCmdY|ωc^N]d<ݗsqCR7P(S!-Mo] dzZfA?[4#3j6L"n5)yfʧ@1(:v Ujаi]NfúKjI ҉r`V ޙW1`1rdOSʊEe#l!bi,/`|`%%=ǜp&Xg}DJ `&:}kSҎ k W::qRRUOl&$d;-Z_׵s ).Dauщ ߴ.rpQ 7]z/ImECӽ f] l^+M~(=I@)|4~>=:'\&zm(HADYz:>Vs ]MtGpi)Owu$zmc▧dl5"In-x[I`?ZMiDyy'Ii x,g~n\ B~՜쟬&,=A\eM??^5fKJY/&s|gU7'( = 1N_2hp,=@)$ɗ&^REr<"n ep''5X*N:׹F!/܉X3O-q#[~b?ښG >6ٛ\|fƉ>3W ˜)q OAurXHmn#BzCj]]CLjlnS[_UtwE3uHD )[ŶU.NuGŢ&?f=Ðצ?pnwN@}w@ ,@+>BQepGzNd?d)uE2sB X;{3;4  +K@V4W@,R$)MF&eEJ哝Y2&앖PlSeV|j'D$H=w#l<ԝ3;I4 7D{ȎU'3IF seXjiKf MG{;J'ڶC)8}AI~d@3}<}{ΆA/"DZ$ęOm$?}(au蝹>r wGs ]ɗAmzaK* iS; yVvHjhNgƇ?c`jA6r",6EFI#!o MN:EBOI޺%*ܽ361ֽMqr~M%{6PqWi)9A2Lv <ہUa K&nSfk[VqV(^w0H9hQ:]%G :5t>v'D81Um{&{Z ,=oO%Ov]z[f@ ?")s#/N 2[ŵ)͜e}JGv+q&Jl#\逤\7uw v@,2ݬ R"te΁Zl&1Ih{8{ Ƿ(Io,Z&u#3I9R+X+_o>?1bV5m2|?bkE)9J A,!0`t%+jAkNʫSQHX]~Kڗ 0V}ylvhf$[)5 }j)/i'3T%dmdE5bgHTq_D'Iݠp{p410m&1n,Tho\vfʟ{i:Tu/P@DjsPTpgIț? UМ$N-KݝҨjBa-Bb#PmZ1V)EN *cQc- {ig|X+ݷ첍N'FiE:lCҒTBI;of àv&i&6M,+LU4\Cj?d+璱+D4I$|RT>}Cc 3/1*|`Pҹ$4e ᢄYf9@[-/tCd$Bs%`)_M+FYd;)?W$0[OZ`@|!&&$͜1zob`sSbS?98s>{Kb9igVb/%KT=TE ;knHzd`x`dK.[4Hv+m]T=Ad\W~_X&l\9<=߸yM0V1r+$!Z=LC 6P*n:Tp3lmO2n!gyPu!؞iuOƣ'VIPWf#:q&/=šݪ $QHd1Ba}Ԩ{U97~B j .om 8]C5#㊟{_įAi9%|lR׀s 3#n/f:%{*V=²5hݪqH [UP ʩa.%GG]~Ab'+.V@i+|Nt3$ .ʮ7pܬ;|~tFOsoz/LgOj2߾B1Ópkݪh2bNE*PTV)r7+ٓڷ.YbƈyKaͨ(aU;:#"`܍odqM,,9w?QWq-ٝTWdA h4YїJ.ZPNk\&Q: eO=TiZ(rf#&o~'C@B(0wp{jg6k~%\;,9MжRopV |Xl|8drpbΰЕ0`TSXJPtٍ6f*ѩj9?-y@}$QՔ& d~>w"i$ޓofh ܂M4<hpMjHis] +QJ_oR2!iYk\T/p4xI9흙ߔ #Tf/3b>E,.as43wa$?)8x8ą7ٶkiI$qW#L%AB Ae6+ jrkټm2nn!\"ÔnHIܤ jǺjs[_=m'+o|@,+HI#kiHQuҖ:-`^"`|䰯[:5ҨCmRyhF@--[t[v28=KU vXIjs;"Y1&!sSH DY7#qLl8nռsЇM `Lg4R$F2t;ZpH;9S˦< HP)kft#$'b'ra Q|Ozl` ="mP69E6wU1ݫUyyvjB?يqŧ7eIŭ0eeZ^n?:4~cPl4ͦR~%g;ѓ@^$cz,ƛDsEp/v衴ϻ/|<앞ˑsިMRn:>\D4%$ %u[3][ȠnJ˱/b\ߵc}/}D])B%4fW#فoc!al(YnDY`8֫[IdϿF ME%:0! `7pǹD! CPnGd.iiPi@}+Q&xdODbsyk9C$Sԓ Be\&l`R%_?S5KW: BoogR"Ft4} Ȣ\A \VbJ1VPC NWWP?{uZ~/@w.gH" HcrkAjg$Rzeh SlST>Jijb5{oEG$XN,E`F93fhƬߋe"2הKECױ ^cf\%KxLGB;6BކD5U\J:_mLԏjTgq/ֽ w }C1nnB$G4ג;2QuL$ oz/|X2X`vU[z]C >HS_i^pOlJODTpH \J^71[ijMo^4$MMPa|CVc}(? K+dZMח'i)p&B4c]MEθsс\]p3UfIoAB 0gaLUM[~K*dfMbx >eӈ9%3>)e*'Ƶ(a/_>{.Gغt̅(ySlw~no6DW:(fs7 4bsԆs]K/tZ@VFXgbF;:@ݡ!)pZF~ᄜp!~ouk}rSXV m1OBF{VHvxo)0Yr[̯WI֭z3+쥥A7FK-Nc#!}"ڥ'MY**1MxW~5fI!K͌T6Uѡ['2S09`` 0ƫ(qJLG8V؜FX/įT + /l}ztk'HɵVZX tZ NzGTn{1`jY[m0?P*|x( x#Y?ݯ`oĖv${ J,g2 3̱A)`g*trhRrĹcW[FHV]⾡"6fEZia/r_ 76.9%3M6eNR FYyq>7~Wpc\UAA;~?{-Hbrh5ex7N8 =AC3ŒSh(ps>L:[3̹ZY Ï+}BMRlIJ4M~谤l2[(i8pzg/P52"8 Kg;hX5V> l0!\=NT'z t:|O mczQJ&,yy"1a s59ͩ!6 .yʪ_w/C̠n2NO eK)[fn&z^R=k\gȰDocl!.<מ+Œ̲7 WOEL81U!jp˨3q[ 3nKf7_YcŸ,kϣvy7VnNIyU'<ץK?rx]gd`I2jNOWP_'^ x{ }f l :Пa#Xf`zn|( .06mN$ā gD_gNB$H^kY|ך>^3zHh6cܟJ` >j^hA"#EPYNkTsɹ G;M߄?'- &m_%T@aJAb׋4FRt)0F%{KqXuy䅰<0)}*ŴShV|ff p"HΥ{${R$V!BgXMg rQݣ'rr ;D@ fܛb9f@BL? 89C>aBkwZ˰=EҒzbÀYz?9FoNNWt`AOHZjq -&$W"6ud ʂY-$qFғ[֊4jz{ 4 Aﻪ`ٞ$fnI"y5k2 nިZ[BC~Hhcz XO[_,D i]GN%%iRR=<{6 SGQ* Ճ"R(à smݜ؞ǵ>Yz[u{|Z@zڽG69PcEKh]Wd,A8ֵ4ptEBMi\Zh(}:b~r gs~ӄh{DmY5֞g$(7:u-s.{@'%լZq]WH6(6qA hƈ.kRBe+zA*I H4iERT)d?Vh'BϟTZ)SΜ-ߜn 5˙,kH},\y[m~۝*ej$AŎWhzQepa5C谾' 8re{1H! o[)Qx5Frxm %N[bzV ;1w[s*E]iOw? gWb| 㖨Cb=,s{q`2Z{Yu0;Xp6s軐kptL2ODp>j/ؒƯLal@"Ue||*I8MW4궖BQ'2Q|+G.6AD)~HpTYxOeI( M@iT{?ՃOMv4M!B.s7E'Y;Y#Vp1=@|!ow=! wSY]d-yDb¹9CY̳a4ȸmp脲ghdȿ wI2W53 .=ţ=On4Whx^`y2?AEFf"rg9-F4UaO nphu \GX /IزZxxw64cF +c`":!o]^ -m\ =tȶT/H>˫CboZo +ͮ-Ml|oPֺ@1-Ysն佅 ,bw"}*?N@X4ΐjYhЀ wZ>HsC"Ҿb߁$T;l3~\7o@sF=m`[Y P?kO f&GCYY&: ]-&s/blvATe|':3s˨kT)4z['8 WHb?ᜅs(.pA1e)9!E% s0A4?EiȅX w/Zc3etS\#Eq\4l4@ˡeȤ$t{Wy ~)-i?d5lO4JX\ ȱɉtf]o ~6tyTZ=b87?ɸgkBQE]X/’ Ck3Q]th5 unr:HjsoA&١hOœV{ziIEo{:;,/-g4Dwg6۫6%L <;ގD>enϊ5i?~֩Rx  *f&Fc Rm4D"J?&R7a ;qrwV$a;`1SyIưo9u{rayֵ0f sD.v!I8Q&"D½8"/@¯1.;_HbC'G_ۃu4,pG"x S!. cj"Bd>ើ5mܟ$ųޗKkdXw,0B!WXd{c[(;@D4oxA.HvpC?O^ iR߸Fex5du_?A{fX(_I)?-&j6xd'9Nu7+эH(G \0gA%PA4b$&7D%Jvח_[2VLp],=v+r:9RBQݑybV]S i]dg4,T`- ӮHFưc7:-~$+<f9ox ipҶÃzC oQ~)8W"xjM\i jYoX=X\Ƿ}`^vFoƉ "9J}J˹mjDK:BOtGq^^-^]^>m |~^SV~f; !*i}c5U-+TJ2kQ(T9 Im$^[/5ηƀcK)_NY ck5?˛Uw)1^2~]:ylag B隞? Ar-ᾼR!m[V~~0eP3܀ D<32>dKYu6UY/'}'䓫lP$fh8/frv_SߚDFlg'j˷ツdl:|"o 7w=wEuzz*"c 謉 j۩9|-rY%7//6Tݍ# Cms_ u' dtJT$⥺h+߉%K.8SkI4?HxrD] WI/QZfxw6 -eޛ{hs#nj15(x+@Ank{8u. i'ɟ.ޥf (oMzeǒpDV}#1, ɸ# Oo_T7VFQkie &v?z:5sF:!QK}9"|G FO4y4C}ܝkj0OZo5URR8LApL?z5`^:S/.=[ط5.K,Y&iK%ʣ~W!d›NCɼp\~\| ^Zd]"?M\n39^,Ԋ m^rw1 ka^+6}Ts70̀ ˀ= }COJލ41baz |V8.w5rP-z3f{<]u}k"U]6+% b$ƍnQz0JP)Etΐ-q&[r :ؘQh><TBF=c~_Ch :~V7AԹIn2Ÿ 2r;s/я_omFcVb2K!2.BT}>&&SAfpA6~FS'JKqKްoKz.gXPR,/9>jnh1UwK"sf8pΟ4ˠ~2kPMh*.tqNG|^ܧ3RAk"c8BN]5ˆDwÑ|!?>昚ɯ\mlUl~pWVY*'3:lF 3,eܡ?<ΛDd -sb$gx$ᝈ<[x%#9'KFCο0̓~ DF=V\=•焞T4j}Hb"+_;*#1{|#eߍUȖ(bP--b>,4.FusEmqUS)o"BNJ(|fge)+ P Rcɞq!͵AHfÉ,_] [H?C^)"G_T jvC-]?5UnP?Kj̔cO_)j+|gk zjSX {V%2՛I2@{=S7evz}~OH_D`|C#oBQYhNj#dP嵼x—vLG,Ƞ;.(9HsXY ZSW ,3 ¹Mh<:] Vf"V""SzǥZ(\(>ai>CLwrF  (.q b m|̝FZf{AoXppĔ$1M?tk&w,| >m!8r381*|ӆ+eBrr 0Ėi9aP3,Dpܻ"m]͹u:0PVJ duȡǂ`OE@p$5L[^>1IP r9XIt+YҙTMmڤ+%]~6A]%hȊ$1΁uZ%JpH>9X(_ٍ\u>p:1Ǝ W/52msުK8ގpu#bYA;*H\ (,yu6qmW \+LXMܾBٝl,+_ש7W8EX.df~Ȇa4򆰹mn4 ˜~Y?uZdW/^Y?+SeASrgwpBq@ĠGةpǐ規 #W3 h -M"] AloB tXԡ1*e2*̧ ߓ!uX..>N;Q"U2pcN$逸QbG4s5|S(aT:uմQe Lpg9QK9$_HKФ1OEIUFܕClS4eh'Ǭ"ԉ2訠-o*RUr/1f%~L6phBVVFړC̦K}Ŕߎ|SdHEKS:r %┱bS[[&_˲ 0wLc ԁcS?W C a4qsQ?@c$+oJb] )|j(v@)HӳOo(*zGώ{0H 6Xvy}&@5T m xu԰&?j_TGa Ġ7 s]ܝ30ցecIN %%X`RlRl3yt)-_[L;6&ROp,d!ك،\={^k0K=DC x+&Q ]H G#WMRr3P$vD2JB]0͘e{Ǵ9#ww/ &4O/Ff)dl nivl2jl1ՑlН8cW_i/7.-rp^B,];[E Fwy/ki"],"V.,%DsZ:wx$g&b! T58͒jVqh} 7fDϡ3=0U1:aϧmJ&س^^qBrd^yZ p> N﮷D0YmlfKyºxR<ҨƼ_klxn[ݏI.{x5ɚ #M4nc+,$r# XS_Ҕ7vDVp{̋&jI&R}US~w%GF/dҿ71<%b߮> q=k}+Qp|_g5y Rb̗U)kbMA BX]0X0Q/)J&Ks(E7X{K ^T&AX$._⪣BیCأjfT2MJT2 ݍJy"_hu`-»[RZK ͛!,aw %,@ >-#C G/)-ap _*Eit_^*9yfF/5h9w⢀ S/3]<9;]kh+k.kZ%Xf 0rCQV0R~MoC{56422;n(#&i`}0?˥ 5>oѧɊu/w9ф{n2LQ(g_AGg;ӫRϽ+=/Ǥ[#|ƾ1@Y;pH3H7mj8κ~unMc[/I_ @ɟQ[Y C vulݯH:≗8־r8QřMY&Yί=Ϭk9k%\-j8OoTM]OښnO<xԽt@:a嬅ޱ,L6$[.Tu . B 1X0 ڴ5pcE& G,VQQbX5vҍf_EC܇t*)|;_iA1z"k4* 5X[Y>rxIkt=.xb|>ة Mh(_12+dz;\nIc3 ?\i ziXiݐ28uxÕ{K 3y5F1AyQӵa*Ao07}OSos\-dg"-vVȧ H/)iY5A$Մ l^s{?Jk, 9\-D_٣zb.$nԃd(+|6$5]¬B'hdhLi8Z @^RQ[QW<yVTN n|V}JFlZb Շ(Bn$9/+&aZ~h4 `b?}#R"ENb@U8#/uN AϠ;d~D,"fF:s1 &^FYwL"xyŽ嬺% yLP;ꙙm:N' MP  yT]ete`<$o֢NhfKX{c8iW@KzUjhV99o/z]EgP̐hhb١̊L$GV|F޸>k+g<7&N wV!L_@/tzd:b8ɨ@.mz `X<[U&Ljɨ"ʅ: ?_}|r*RwmYϲ#Ёwn ј#>7oGţ?Nk@7pS=&@_JZ1 jWrc+g!,:+mRld؎>ϱqOuIvpwV.XfAp>UN 0UO]T#7\u/e$"Ҏ_7}sL&b9N7fW ۉlZSh$4G\C2E ?Ng\A}ΝeN~MWh7CS, GBt}zYJyWQBqEݶȦBCBƺ|hP]xp-Ų >tߔi e6c9+3DVcd =&z&:8Hl,d8$<66g *ZyݱAr*\[Cg [()v@|x'CY<_4vuS] tI+ G.Q\* ʲzg㬙G㊔#u m>6tcd<)<ó1˔ɶlewgWf> MX8(ڞ-|IXKNZܞ4 %M}0(B|3zDi-jbQiB n.H|[16(~3(OrVRZrݡj6^1mɊ!ϊ%Hk=5z̖^./aǘZr&uՁBLvɢ{R95j7ߓJ\\6 ]InJb~М]HFXG3BDi[izߣSRHӍG^*еJMoA@2hW뵌j4%{'OVť\bhMSMKWE+>j? .).ۏCűh.C#p dƦpsy@#X\؝qz0'ˇOA8!\Eؘ`UV[V}|]wsر)F˭V,ۂ~t؛ByK֯u;nH8l13m,6Mܽ-MQG)le,,stB*v3nu,͜(N%^!޴ mgUgCX5Fv3 7fDfK}lMcoؿ@#E!erZ)s|k^9D0%ĔB Cy^|}-C1H_/ޯ? ;B[ׯz{+:^o.F7 bpPw4GZoEBeܳ7awvM'N΍f.e'Lp|,۩"lmD-к0IXIlMUQui;E;5m SQ\J]Vt}@\Oz漦ǯ*n6-euÓ"1.X&ǔJXx8޵N!aÜH+ >ٺx9(W98E8[[@W\Z3 \IapQήaQ %+PJ "33Iv*Rd ɪD"# >5 =Bu IM pJu~3zTh9R2M0?3UkCX3H>J7+"f #=R{U)q# ݧT7hH+c:tx|ex/X7/ctI G^t&1No.v4It5/fghF hIjpRj2~xetH+F3{RiuMJZQTIq;}CM:[>s›}fAB&ṵUdRqM ]4l`fyvzPe=3 }N<YS^8JD 1 }1rTW$3iZv޹jİhxtYp]VؚU=;w ۾.u'zvE^7B^|Y}# {Wp{ـZC0$ȤN"*S<tvH淖ѐ7=ڣfk7hM.fYDd FcK.'aNl-tԪ"MR8Fa63^ipLJP1q8!XLJ"o_. ޞuQ$rؐJC3ъXzҡشHru"If#b}1,QKYEOY=pp#EDvu"r(A^6nܽvD ;Pl'eZ3!ʤ]M hHzk>'BL0s NibN; f\AC&̓-JU ŦRVf,PauGHmWQcwtT7Ӆڛeí0/;s8:(tgU6UbYj\tYs=䕍XQ&kʝ{ՆKj #fUԎ%kMNKJtHUU&0J첩W^Ys$5a5ȯtP鯽bO J&I"53x;يRĻ4DQUީB9S b0\V=*s-Wx^8աXK\Nw֢i(H nG&[["KAnhwJ0X-SD?W}@22-'yov]߈tRa& /0C deoj(FY/kLoKDڞI/ΦWwTZo@ t4EFi]֑\KO8Yru^].U.jT5BNM[|A['ǩJNp>!Hr V(>J+|RUasv\?l)ݿ8ҞTG>VCme󱄄0%x(tOYKec{C T0YU:1e];LbVjҘ5fcsLH~N>v}3iM_D&skKPJ9X~הeͷ__Nlka~ 䞟So{Ֆ't%cZ& Udt?5_5ELհG[5LaM/gmhO}_G˚&--]$ߢroH^fDqH=6NACJǗ-j3"9pwa Q9%kLtR 2Nj"b\ddx{xA'j^Z-UwŁ]2x/f[7~`HUЋ eホv#K@ΘhIl2 ǣmAnkʣG`~(t 9OهN0OI)d&jmNig! u߾.nJ`0)i~sBn^"#~M/^;(C8bߝH`G\Q kVWˑG5_W>zOPo?^N5eZ\oAHbyJ h@:=xIC MJ5\c0(5.1,# uYy?ܛ;ݼ `m'=4u_Cj2^~`[ۖYl}U4-֧{]%nUA܄R~ulʽ @f ?j>Ijs//w:Jߵ`X<xWcʠy;s>w"(zۄ1=@D_EY%cx TM'pԂs1EِO߂<')[^rp#ُ1 i`'ѓ S>pxa(G:Z)nCXw^aD0H1XsO!\}\ݣ|ZTL-xDRw@yZңXk%E QFu q^Kkw %G.uiWq&ނ~[K\Ã*َlc6 H Q.q&nOZ:Ŏ-<&zC4u<_(O)En+IY狔l9C®7_( \y6cawScn!*\)qQ{9 |!ZH&ԟcq2ܒl.U|2`5Ēsr~?!_Ϟ[&c\ d$lo9)OS%3}PU_[~@|!wN@-l 7jU̳/酉Rie _.h9fĢ@ ^KW;Iߠ֨j%zy*(=4\:ñ9FL(A:/> `ٖSR|`S44ԨoԱFZ:ŵeCok3uXLZ f7Ai礭plb/!BTxgNTgʹᤑ"WqKb u09~q6K wn?q4t3[toe%)F6gH⏫|BD>8Ѩf38{0u!]ҍG:9ӿyL[2jb4PZz^8gO~kRΊYȦWMm(-CwKu.OiR?v[2ή-=]C:;B T†e!% ZwFԚGﲦK=1pDQt_VkYzv%.sdܥqss_:p;.[}\F4y&ؚg#[\ۆo0nneSR, B'("D)ʟQ/*s8sMHZȺ\WD⯐:M>IOq툐dw@n8/EإS;`p%r2ST i>Db,_{("2OdDتvJ3bxx"%rJY9,A%VMYX8qGC|Hǝpq kA(7`ܯBQB/,;ՐgdIwɰ t<uF>2N]ĔJ@8nRcLI̥g+kmo;o%gt`qpQ38H-묙i" o&!mΘ d58*_S . %w\z1WR nHg+6V7)[faa=JcU12;nYވ930-%'`j"g^85zŠ)9ny+0}Q\Lo!~EbtOkCml3OrɃ@R??^I6xy;afT/j)EC\INeU4>K u|0{P^9i;GxXm"1 4냁Yǚ 2 !X*gڐBefJ#qpǛ;kЈ`C+֢Ȳc?=VcU1./i睯B1ӌH03")#oFQx(E3+? dg_U <gSemjqMyrڞ 9+X͎1tF[+si=9jprкÊ!xTL?iG)Xd3>8Ľ6C0I\c(ݨBvr-7^Mޯa, z-Rs;x[?!z-JD)¬-ⓟ7QHT`QW˳zI &4ӒKp#]PIB.ea'>, 2!T߳/704s]ZHְ 2vL!~ot'Gd̯\ŎwV <Ȓx QRw((矎{5/9iwNgCLOSgf.8ݰI.K[p|g?߆伎t7֒Be9j"Hʖ"o!LN1:u2P Hޣ ɨ+s"Ⱦ Hs%q+-mZAXOn}vd?f5 28 ) C\4Ns_jo(` `~=Nel,e1&_7ĖrkimAK,P1AJ؊yw1mX*!z|d+HeFưw@n-zM E x Eƫ XT]b ,o7},;}+wNa_" R 4(q1er_󥣈o49}oV!)4&0K }|7)4>uE4nr.k^Zj!97^%1QqS!vq-tc֍ åz\ԃ8y )XQfVϳ(!\4 FT=L+Hza8hv= aVXs}.+dWxxj΋TpΗ|qy]:)39.}Zڍ9]$I~L_|>ge=#j'HYg XX9 Qb46!\g>V|gx΀=Uj}4*ntZyΓT9n@yY9#&ZL0o*KX n01rstD32Q %84 #Ks SeJ4$Ŵ@'sO{SrdIW&o钌Y|J\3 '9[Q tm궇jF'~_[Y>m C*5'޸W.d#ހ*_DReyeOm94?; aRH2m5Q\Y 'IǫtX|~Ҩ䱘H.5wA}opeA˒u0nr/?E|`x%-w08xa/*^t+N;K1 6,Ĥe/5z?CeG\ e=Q)nlé9NrJ\K(}0ajZ Ӫʋ7hNYе6 DҎ)KϑJWk1U BhS6jeк 4AdBTE?vE{&z}Κ\٣<0O?p)V {Ӏ햑6-@].#QHŨ 1"QK.%_.btwZ^2y~p(f* 6󀥐)ԇJ; pR?- D>Xn]e-?h0͙k&+zבvL|~R' %&Fs ?ΘEZ2#F_3kjzh.FB&~&)ZEbO-7y5$)TbnYS\pڋNUh.OP4;H4 D]ɸù?ffp|QS>Ɨ!nG\kfGaՄ?+ܯ7jm|p.PgS lוP>dx~4 EƯ8dzJBHwlF7zԋuY(vLL_Y&H*݃jb/^v%@¹V#TLs ڤ+3ZC=z9bhWǦb]ͿK'1jav cÊ[ +AtGюe$] [@jmOWh\FJG%Za{ăoަBOGlMlC& x4-Keض,CmD#Pjb9˃9ƠeF7{h?nYv+Y7)  A[ ?hj$M$&v=Bixb%xdJ7Bۏ;~\Zimk.fgpԁ8e+(yP>յ%ݔ(89Ey=(MHֱaj@AłeWjo/nqjg]윣;uPSc$,p5 VC1(0@#<֮ xNn8<[wǤ_.El@A`0{?_@zsZFh Xhh Əse7F͸\ͪ%CmE&7:/8_wȊI;[nMnF;۶FDr2"$C%' 8i~ {hRʼnNcFFYL.UZcͭ+)=_s(WS8"*6*̊m5=fSiJ 2:ځB@ֹ4yFqA+jAo5Ԫit :V"r朲Xӌ%-N賭@G1=KXh|VaQdߒw;p1\vx*XWM2//Ttto~x m-"i5"ku^#5j|*N~+ɕn#bk)9s֦V Ã!@ @2%#n/2.zJJͧ(_k} Zі=`>UeD,1Z:GZS/ZU@p+.^8{KzЖU(kdJǵӔ!|BWX7˙,8y11ݮ4ӷ?*OM=ę֜˾KGFjRx5<u4oUwf!sR942fbo_65r!*d^ rB1&N^)Pmpt/Grt//sٺ|t0G' st0z*ăHn*P<…_<0/y">d$XðnjDW[*2B94F(#!P0fruwyXl9Ro!Uy!tXۄFq'6UYdF@(iby;ZHQg v[4*Ƣ0[.AEF6BY2Jlɺ-a|]F36b *^l%2*̸Y!9;J3gNJGVn`E ŸMq?IuL T´Aif{ 5X=c!;,cP=vY Pjh3Lg&KTylĭξh~h>(HL_|oS5EFw'hixs+c?8):ߟ*(oyT@駟/*#0"ʙ`X"c>ud 6$¶p^Ck@ Dv5EYh "` Jܨ n-kFڼڢ] :˩3\\?4x c]΋h9k8\ #1x=Q<+m;:h#jsɄ)06 `Bn̈WܰB^_KgڵJB$6 M@pYt `Y p~KV)p!ٚqhnt-*ԎQفTw#% 1ŇБUg+-&RBZ{cq:of=Z=BSUBFKp=A%tyMɖ 9'.őۚ7 i?6ȺܳTLq<*>kM1>d P|){e=vcE~mqϳ Qg.=s8 t5 Uaq=CXO_zih{aVN-ʹtLn8-%Pd㡢X8 fcʟ}NQN,(W]Seg|w,;*[uԄU&4 \iJ 1j!aۄUb`9BE, GiV N;4=)T -J&U[MT=,Xv]Y5"{ԏy E s +sKK>:2U蘥_+3G{Q AG0o|KÑTl̎+Z",\Ytv3zu:q@F i=dcexG'S'e{F]Q0ɶ H@^P@ .KeOW3sWrR% g~@nͦlAY鹓غ9%m ’B'_\'f?, j;=e2gʙ;p6A9,)%䕣9}f9"˟4¦S'5Rjy  uRD DzF0 CWfcֶ1JAy{1%-rcw}JnySj\:\ir?X6(ZdL}_٩`F%2‚*M͝yJ([.`/H E${*%BQ-Cr1sl3KVZR( UDKf] $IiڀA;1_&FU d&޹ܓrvw\[n$il%Wkzr)U7,FU}9M̖kuuvG /ib®1tH~Ktv\Ow} be3Jsaq YTK v8+TF̗^mVFѩU 1Q^4=KhfԂvFNeV+Y%muq{j'3]AZ@$ #S{D5xBDC :@FS h+rSZ5+ {C\g; pmxB] >7S5r޼dI(=<[oxkt!55<:Q2]FgյcI؅ƾ:,i3OzX#իh-x~M/Sܤ{8<= o]!9q1S3Lh kUj$e3`T|fMWSC:&6sg?8ByqqHV)l\#`Qjv˩ v$i5Hf[ZkU :NhTD60_qμU1*D"o5⬠&'aTqmh*ΝM %ij - .Q\ChRd(ARzP .0Tzf[4uZKi)n">!ո0Ja%dONw{ mfO-LYm,a[ Šb< ƙZμLٞx/Wr7EZ I6̲S,ǹCXY@GzKfv oRYdJ^싇X$;d2^}udkٽ-` TMC8OD*ieЕB/Ke,ݕ{$Қ$鱩οX4%~ LǑ;t-L!{M!'NBKqÂ(z$죃65wf)KϝI"L?"(L`6b3Eu\kx%Q@R +AK.`w(bp%lP'Tڜb_ _Lpb%^F̉fKݓCnF礋E } j$ƺkF3F$t }|xF-dY_2XM6ྣ CzN>fϒU:dB0Fy! ycsl+/y{yUcIy DfQK/t(IMu$AB2)a")V h~o}AutĪYY V "5aM&qac~֥Dde[qV'~$r'ƕr٨Uu, gM~ķMFNxc 塇 g}< WHw-skCIBycF-]JO ٝ0qlƞ+R~S&=L?Ks9)_*j{V"sqe9@} 8la.h6"<3VZ}Xm,,ISA'te`e"p9D džv{ cG]O+ {6ZrڙfS(R8[SAkN;)ヷUBr"Vlʶ> qTHȺA"T AdA"CACn|3M~p]M4QSwMr3F݀X|87uR 9QG&r}G e[}6I2Qx+!ҁJΞ-3[1 κb)7mf:EmtGuʊ؊:p'r`a7/e(МtWk ڢ,k'Ll3ש]DTCE@i04JՒM+J>1wc`݅c=2S,>kqas0d&YZ0 QhhqȘ*qX}heZ|+4iEڦ3[E+"s:N7O"ttcyHkDFѺ.VPcU9Vn &  ދ3: ;E9T\t/DlX*2C=YF e +oѠB1ԛrٚY/]~[QȰBjrEZZqh3X6MJqȒpѱF_ !v($zHnTm5H\XohAsU,[NY9[O`H@kuɮsq;N'#WZ^.WjcrF+uzZԸ'b𡝤Ӧ4Yh`h[IdӦvĦew}g'{SӉ Wk =`ZSP_~;o}ܞ.g70YzCh)Ȓ9mmӨ0<1E= m#qlC%A aSTߺN-=M KL~au6[-ۧsK-XZsˌÒv@,VdSƢu`5v[hp )d[O/DeƋكg*j` 4 ~hyL^h̨w` %^BWZ/ 91f?Ea!aū3$\難NA!tUGwbMWˍI-(Se]k#nk/Lb_pTtqZug.ˋsK2I=hDP#1M>ϡc+BAkC-d w75Y=ۿfib}InmDcI3!Zr}O9F4m.plLLO s_㿒HYC"ll;±tFw4UӾOΈnV˖6" ts C"T4W\g)  54ζ+˞ , ~1B,g^~ezXjv^MxŽlhp0/BhƫUV l$|jՈJSo%]c%~f튓ݠ )اd?-!UĜ c@)gJ2gi\!` WKI.hm(dy$od*'Lg(a0&8 p*B3e8j\oEE Rv[~uTjw3GcqKVrW&x]P3 ,H2-T;PV7D}5!ps:9FWA&Q.òKfOiUƆE {s}C;)!o'. mLz۳Ri6i1LCKpKי4kO73փdequZB?6tD%A* u~A4T^}P %he??aut {  M<6䶕]se1QL妀u LkN1k b&4y 䔡VѦ{tt>tW#T[8a旮|BVOC]%$D8.9A4Ӷ*7-ٶVsJ4\:vZ9~^Zi.ٛ+bJ˭̥r'^ᚬn/;{Xz7ޚN"87;wC6=&n=Nq|чE8ϵ%wR&]G@gTX7=nÄ$S/-߂ Cyy9R_-_k2ǒge[I<'!%=R>ZnFPK.uCevzoWnX5[<9l^ڨN>.\-|W3 jsc|m)ΈD}C JRGmC@RJUjxy ]u1J"Q:d,w# €.(\]o0Iq$jfvbs({1X tGVQ]j[הtiin, qݳNQפ.Y EQ75Z윧&`CCH|r_I `Vpm+^LP9=I; %>=jzZAҶKcYԦ~^|J~ :|HMTm:ĽфsvvM\\8a[lRg[i{~褭+[ZijD-|[rźSy w8D`L$^Mdzp*k*X7.1A"-#Xw~D FY4 ED&[5Af:e]9-bWGj^A52I KYM3F *oX%,ÿNsda`pS煟m%@f%gNMϓ߱)jÌŴsQX8-xJY^ZS^X1e)ʰ&˞&|Lc!9BktT uT<{< FŐnaKwk \1ͣdrjcv|[Fͼt#x52"QG|QI=sܨ [zSͽPJxzkT)%YdQi6i>6x#PGoMbHܨ6f,.& y8ޛv6^ Vm dP'cAEcAmxc!TM@]RT;Q:HqWPJ9(4R*\WST!$1IgcHh D]] ̈/j i [("FX\}+mcMed||LNlYr5 XJ#M.a%*w΍nA«iζE;q@n+ 9S2b悩H4|᪏P=b $KP6SqkB{Cȑ\6ը?(Ӆ4(WG gH~M)SpwhNE贮 )(d62tZ,^xAD_|?ħ>YΙ鵬YXO,8yZT^)חҿ$.u HxTLҜR+ȂOsݜ_q^9v ɟ{i5)s/ lT-!J#b o6)%&*M$pk9|tJUsѳƚF lϧneH*=+!/NYo+`ڙU4[s:X^{ BmqNo˓V::`C ЯzW^uG ?w>Dj55Wm\#q{D3"ũ~|vA|@5'.w \ho%6\C6͝N+MEIV^:V h5 GRئ(.DV>Pn G.` iUKq;Trt.Grtr.Grt.w0iI(}/-w5i^NYVPV&y-ƈsZâqX C}l QsgQw{@L2!2t&S~ܞ~!-3b#c92F#c9DWGrt/Gr o~(ob Ń}DXL\҉B $ BNO YyLސ[C_>tS.cEB3M! y(7j[ B9p.uYqoh']Grz[XKQ$j a5\.*}mz_ OqVm^ϦFQsw'\- %P\fs$E$jILANp#xg6FhPSn-w%AH G%LbD AZ[w ¥( 6BmXb8lqo,a;)g i"rSo=hyOp! EtF=iU2NPbX[{ehsW)?FOۄ_kJ94AU+x5#J$hcoSs|~p־]x.b6u*NM9ho'&"y9~v\K+0+×뻥94YeZˀcwKeUkOmo':NXDW[x)6/=[Dpѻ,fv^?O_ >kۥ4q#$C͂+ukcs.Ct3/QL$+r̜q]NZh<ó[R@ͻ";BjaoŶƖSz+\nogG\L (z!QuD8{b]E6`ݴv %W+Mnqܟlryn:iiCg:YOmjh`[Mt{\ 栲pqYxtJ6hO>?n=Ou#Kaw*Ha:v;M*D+*A ϛkElb J6s _q\)V'Fh2bl99{~0øzsR򛷄8#GmwQ+ R*G{ns8gSKB7{ycTx1$cGnUWEwTgb~[VhY )VOXYF G2Ôo5'.GAYNd7+$%+ͯܿm^Dh&AMX`ͮ͂"Vpnn ::pgpnR1rbѺ!to-ڐ՚'@}a1e\${(+{:cb͓ȝW5Uإ"u0grVhϴv~KBZ%LL$::DKFrT; m@RIE44Өx`[ddt9D (v&9ZS?ʱF[n\dMr<652/*Z é=u>m^qߏ[No0#dMϓw> (d|lJI-30^Ug:)a#ǰmf +U͓ւXPl¯fvEB&.ڴǭ9&hOe8@HLݸba7,oXc8 5'3m}qOhF6$$ܿTeYQK9-sfm.v Hcϛ=(-ȎǶ!pInts/~a$KJ5WN[Fxrb JZUL:"[ΈG #DgԄf6;x}4>swsOxl Qr3;X\3=ܽ`2ө,Rc_ܧ".m/44N%; N}Bb+&w_5tM-s:yw7ߚɗ$@$PFao>"&)|>z;?s?gH:]{{-6&G?i,T TBѮ1o8ecGᎺ`7(=ugdn~7x\D*YGNGc Fc.5:Rmwk] nV==isOk ^\hum"'YN>x 9wF0`r{FH-ތyF۳~~P7ŌEUlu%-ya]8 Vn74 PEy[IxF6d~-*7фfKF¢B`ۗ6L6llI;?&mDNHp5[zv\F#l61r9+IQ)!V"Nx4rAuo˓JߘsXS[Ό߃Xx _JȤ@gZ Am6>g*[lc*-'q8% K#K]]ꛗ}١xu7 Ϟn-NxD9X!*?Ex\]80ŰcM c4Dtc#&]E?8,PEu&h{{@qFS{Y/Tȝ3X+nVcDA Ws|Tlvc^d¹ތc{*X }\9so̝h[D.~זvu3XE ^օ%qLq3:k"3?^ ̕ 7x8o=tc:UQ]/!<o=lUS?3IFT7D_h?2=#i яGbE5Y>z7}&_&:rJprήj 44sڙpo 1 Wo]kF0L"HLS粈z\7WπX8] m\ tv{YOkZn6+%_iuIsIs02#ۆYݘ46T?tdTb\[[Kl;`s/b\$ NMi]ry/–lvbH̪ACôC)39zCQ %0FA^L>? Ƃ`O(o7n@/f7S@HZ:_-s"y$~|PV/Y."Z2⯢sl9ᨁ.`!%\ۨnhKdr/48*K8.*C5剄O ΠߵY4H~. +` i"F3O^ &HU/Z .fj %tn&K#u2Gt>6<@MM3GfO9` M"s`\x.Ewle|4x.:guW?H%]gӮaẸd }Ԓi:vxg8D#9C? qs =UsG$cqsU`V鹿~V@1^PMo `eIliΥʟ (#u˨#pg݃kWkͼ,``L(֞qWD ?UV<[T21RQfχQfZO- D&4/ yQEp!anap8qlNJHik+5ŦFlfDh?MUB&=g8ǀ84 Nbv &ĞϦglI8uCWǐt[:>=FspU(+ěd-Cx[5u C/dtV==5=vbzɓo78ɓo5=v&Nxk'yUcu(cOQ ֨dI[M2d*^|E89X`7!UFٷ!ƛLǒ䯓f9qk{KJ]Ca[?s2a7%< ZyTmhrgyB=d(U6SGp^)&V(.\zj7T%%2iud":𨁂A־ɤ5U ٫x0.Ù0bR\RANN;9cį/84nժ3b7W2}U0:-:~$XƮMJIJ'G2-*BٙBjY<~/)FQ/A=F#K쵱L.C!GK6k%#1v3/Xzsl6^dvqzO7 HQEnIZ 辰\:йMnixZЉT9EXf"UeM{L\\(Dͼ%j!L> HZ|\o18|^k&b'Ʃy5'({aCZ'ޥ([[~|JZz`go]\.U< >__Pb^̮]mVFՉDu7N€._$W,Ƙ( 9#|*](7ǰtJiSSz^yuON\DxOs?F&or3͖Zf2𣽔;Ee@ޠq{WLެ4N/.6ʵRs4VKۥ,SHn%;6CAрa{.qmK ,Z{Ȃ$p&N`vV臋iP߼f.P|b2_a6D&&9