sssd-ldap-2.8.2-1.el8 >  A cPU]aC#)%zPF>`^N5w|2 bL<'s0p>ʣ| hipPos8*MO%m熢LR")Kȳ Fm d>!0Ł0ԗ {$޼eX%g䓹뉉{ r;Dd 8N}?hný AxsBȿ:"ёsbeIrec`3xsoGjţ]ۮo7[#Ɩbv&،vGySs t@ U NQ%3.ߟnV3$ D]0#& ;.J|UB:?~h8yHјkBO0c4)[ZDͶ#OsW$ A08vQjDF&Nόm*w8N=i~Q Di0ᲁdoL7 Set0U?s3\Ap,>p??d   6 8>H     T4P.|. . \ ` e( t8 |9 :d~GH@IXY\]^* bdienfqlstuv wxy'Csssd-ldap2.8.21.el8The LDAP back end of the SSSDProvides the LDAP back end that the SSSD can utilize to fetch identity data from and authenticate against an LDAP server.cx86-01.mbox.centos.orgӸCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxx86_64)oKI\?kV5C YmAAA큤cccc^cc,cJcJcKcKcJcJcJcJcKcK1e52f729c86eac332459e06e4f415610eb8cbf23b2e95ada99cec4dd8b29eff98ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903ee2d3da08419faf394c028546be3e589e1dd14bc55325c3b9f2e7892c05502dd86e688846862b9cebfba681fc9fdd6cb4f3109badb0d99d31c97cd7e213152ac08da4aeedb9a6c6c9a14734201ae7747837d890ff9364faf8af9810e6c0bdb09b1a463b171b9a882de6b9cd27210132798f8c941ac904db651bf5ed32124492c25de999af4580f08f949e8613b34a23cc2cf4c832e310731db3aa869ae5531f0e1c67015796aa7a9cb807b7753ba2cf28a04b8f57cce48a0a954886ecc897f0c1821424a22e152c76535f8aa00898e93c73c57c947783379d420eef4b3c1e389214bea42d5984c69f8aff5df346cc89789a5a3cc24031270d75388617907f0630a67bbb0c859506c9cc73ce14008762f55a69287bef667c04120bd03bd66b3e2554091c38565e28c2e1dba6d140372179c1f9ca869147dd880e0962e56a90246../../../../usr/lib64/sssd/libsss_ldap.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.8.2-1.el8.src.rpmlibsss_ldap.so()(64bit)sssd-ldapsssd-ldap(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsssd-krb5-common2.8.2-1.el82.8.2-1.el83.0.4-14.6.0-14.0-15.2-12.8.2-1.el82.8.2-1.el8sssd1.10.0-8.beta24.14.3cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) esesrurusvsvukuk2.8.2-1.el82.8.2-1.el8 .build-id2739c60d5cf32678cdf4dce5db0b2248a4390aeclibsss_ldap.sosssd-ldapCOPYINGsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/27//usr/lib64/sssd//usr/share/licenses//usr/share/licenses/sssd-ldap//usr/share/man/es/man5//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2739c60d5cf32678cdf4dce5db0b2248a4390aec, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)'PR"R%RRRR RRRRR R R RRRRRRRR#R&RR RRRRRRRR$R!RRR RR*utf-83abb94be03c1f6338f84a3d5bca681dbff82074ff0eb6f0f9a71f2aa809c34e4?7zXZ !#,ᚊ] b2u jӫ`(y.bwoc}u. 6%'>rϒrZ]02X&:J9SEj(FYr8XELKcb \ﴑj,8&r56lav njɵVGϲnC:j\΢fe#EВH-9O ΁3I(>voSf >m#XFK=xqab9j*Lr?skGY-ۤ vVpd8$91J oKF`)IB24>gF!igΓ[ѱ QMzK d-]}$_%-CDZq[_B*AcVh%RuMEh 2| ꢥ`WY~?Hw X8VRx~jgf٤^7l9P{tOƱ`V_#.7JiދLX .|վ+̍{ީ8ĞL jm]vHK\$N݈K>SLW`إxlš ڇ&–H7=ɼ.DdPr;k&S_Rp2 Ę2Caw⻝2kO5kKPlb7+j)KdP`Xj簯JօeI~9dwj}9/y=Ϊxԕ"OO=q]5SGH~95_h W-/e}t+jŞd*>Kʾ|&h]u*Z=# 75 %r  3+vQVL(qh>#ȥ!& +KI.PnOM{rNCBw1Щm|xc nN)n!)46poӦe78 @M +[>ϰ'tA.ޭ ?YL؞UH2lH2uz3 aE'\>4l8 5xlc'ԃq .?)==T01֘͹C7sSnAxA,,V@8xO' <]mt)l@3}|G>IOPH1?ccKwu>D`"8n+tk+ (qkf g}:N6+tmcSҎK$Q0@3K9X+M6Mg%!,Aqar`@tԣz~m%[& km.u6~AW7ވ_J; XEW}B;~h EAo8鞢ʡ;x؀^So9WL%=L(ɿi!H^O9>ӝ~ d2;|%вI_/ "B!%di#9qoH4; AuFG_#Y*~aA+]ê.ʅD}ܜyl~b3fpoKf8SI+L{uZBĝO}}2*O:9'L]'yJ[SYSꄘB'pSaߚG7/<{yq4 =kajhр|aХ=1F߲zcdX$|vکݎqO$ŊIIܿ8S"d4K;܊{u3hm^BntTi]AM; *L݌aŦ=>`O)VE4<I"bJIA#rs8~,bM?8ǽwOb N}ﭚBhQe?urKJ \`I\0D7KTN!X@Ypp%7q2!6ռPùoO&2Os\*{PY@ʤQhF:T`>6qEDG͸ vo sݪ|軘-[‘`tLI78{[ѢJ"Å(xlB>F;Bn#Yk,-0O,m/G{;طp ;4#y^P JY46V1!k4"Zw[ .!UdzmT{ǻzne((Iw.ߟ}[:vNrD'f{2>Ixy-+ %xz Lݩ*;‘ᐩ!tsWӁÂ3b | 5b:g.c>j .֬cNe3 N@4 p6ǾG+Ej&ӷ&G=H pP89X~bEN eg.m\W1!1땪TaCVSovYܠb.8wIxi5۫NfNhhvRf?7US-'d,2yh՘ $ѰcrAP#YCMD)n5RBW6E{6!*}n Hz-,!dԸ+F88F\τ0B1|s# c$Ee+mjz*_t4gK460$,2f]\؂b6#l1xu!X*&}=d/b卑DZ.몋5S(l53n/Ry_z4Iwilun"׊J׭vMSm^tTur{C  >} "~ .$^R֬nM}OW. W#]Ki&%2B3yk5^t^(2$gj'{4aEWjB~1 Y|-x?n 2+b[%epM3peRoLA|1uխL.H<%<R9g>rCBANaATq3>z|:j>^m{vә3^!fsy$mmWW="\<1>P)\ D|6./:XA㓪ܧ(N9a1 4;z5ukշx5W] MeŪjz@Y/8c0:mtZAeR 7 ޴w~ŸqCVİ>&,uAe=AHVq`&J J8Ϛ_sBebmk5v.;jk1wCPs%SOr[7)"b[D҉5:~:+>n⭾k!#' 6sTO8dPrI>$94%Tp&ӻ ҳWS3ZOz=qpԚSkfQЃ S7b˹]O lAvPe*:69BɂHA{N/ӯ˄19O;,czKnV@6DFɎpsQt'?!Ջtr@xev!U\ hz ~P(6eDLȯPo5.*dV(Ao,չ׈Oq,k*2]Ra:b=(?U8 5gRa]1:\H"z9Q15EC3!HHw9Q4u__*y=Δ 'ԍ3,ՔdʕNiћWT?S/f yK_OG qrZ㨌|m}zᔥ@i>E-s~ADeRyvlڈqIS>[t+{7dzܷAHS`'(jt[qrb60a5E͑5LroUJ,;GHp\;'<&OSNNVg,hP/ >1d=tVa wv?;>cA߽9P})+iA^EgBML2ɂeGf{y,鯸C4$ǎESׂU",ײןR)XiRP<{/ IJa 74F$(.KD;ΆnAR60aKC)!e UO{Y9 27;aea{ϋΛ}nD~\1 1Ħ%{t>] v;`3gA֋,ɸw61,h]g!ؐj@`G׋4y4LĐQBt˘fI%q⍷мb~@G9)a"JXbG)m㌈MRT2v]6Cx[9 d~~W v04Lj:faN9u{-IH*,Blws#tVĩ6%H P.6XDqӳA5b̚e Ը'ŤLY.妿USm?5!Hz(bey?0M Jy0u{RѼnkr+vP'c? /p{Uޜuqt\/AH?968s{ fnPUgojw-?gM]<-"@  ӷA ZseklUTXh3v)u1st$Lf wu,bgR!m yA>Nwc3vOz@/ {0!atCPH0y6D}p-Lؕ) .wHJfۼT1$T@ѴҀ$L\8ԦZ &:/Qaݔ Ӫg^b+&]X@^`XM|M=E1FĄ6"GL8IGJ*Q~yxz5"WƐ$@twl"cJoCFa溋=ې Rb6ŬjNXliM2,o%(:JTaYP5'n'e}^KRe!ꘊ.CA*Miϱ.@qX;)dݡfCQtIh8A*SowAFI$Q¯ĭ rĆpTf _|o,Ƭ#[G^1;Ůd8⸡MǘIb-=MjV$+19Ϊ qP͂pi(x$@qƣ#0]a F*mguj`uW.jKQ[bGr\ F;`:*'ܻb\椤 d42q `xO4Ri|1)j*tcN Q=oc':`SRNli`\J<&.*B-DKxJ=5Uize≷4|"7gI_§GȠH]+/H&n\y+~oު)A]T[2ܶ(dsָH;￿^ \ݶc>ślZ5gJR!iAQTϤً+8yhx?;P gciv?!J:RG'AfxY ;(A^[YP1QC;)WEl7yhR`&VAGXǰw+$<-$1Kx]IQ]G</m+ᑅhUGv}KEZ::wE0.a-G {vꝱ";H?_ _!ij *?4'*B*n,TKt%ODdd tOxXJZDa y#G>#;z#8_hޘ[S&qmtHMllhuP9;ƒBWÊ*ʔ".*+OF.:Ȟ}-7Vi((DJXg5JkRD[U& BPI*+vwآ䮽~1lZb#봂ZH)AH:CbTt[QɾHmjwr/Ve uHON-YX;,̤2<YDa] u矐mSU׊N1S1[N1clޯO 7+qfK@7H>D~}QfQ={;CraRhur݂݉]a dM (P$6FsM g"' Y!nEa" :4F >}$67Dkq2{XأtQ*}?@H̀vϑ R߃W 3x>h*^I0XRpG%H; 3wGj$4^0v# HfePD!jAFI6.Gbd,+cO䷐o8Yq=|ԏ>Q}vZ 8|7ti!uJ+d6<0F?..[{}+8sp]"(5r"#LծbG !$])| J{j? ]Fc'B1nDٔtB#`1nw噩O [щF0fhǠC8V-H_?29/| :rMpB]f![M7h:,kH /S6k5.k qw;O*l+RiOC,;p*BT o:d _-vB/ҕV1 ;钜sR-Fչn戹پi-2q'F} &nK `(?sD$NVfȍo[6kuf9+;jѴ8IN{fpH\ș;[~vU7tgRZ_\5h[WCk'I2觧 vZ(׆|KY\Nt?ǵjQ)PيM57MƩntVbrΒ._攛F &/BNT4h?+>*|50+X0}cE)-se||&PUOl '^ j+ R!˃7/ݑNIUa˟x1.v9u *g|G]"խ2[9,tOH߆}#-&SO?ym8RaէI\A 3e@S&r` [9ve,2GA:HdQ,,n b!\BvdJjԿ؟ Ye(iYXF#auLS#>X4Rn}m 6'w$K܍maL\K,VdZ xf8'X`hAЮH{Թi؊j3?`)v)_Ý@^S\#t5KY̛C<{>(r/v!鰥Yݹx~#Y:ؘQ}I*\Qy[\3wnrQ Zu; i-K繞+ȸ=!T_hqAwD_wę&.+/kQ_G;$y-UB0> rsZ , e&Kf ܍Jh}^vΜ^}|X!]Bǿՙz)xCPu tlr-HYi20W5\lvD\\mm+{!ªy6kS3"xQRBxbZR`SG3Y"3Q\/NxB\=غoLo#Mq|ls|[ ]IlC6$ "z.C6''Nj˓}a?/9 )0y(/Iw1W ly#ݨe{ Dpj>b99;am؝i `ĥRU~k:Վtx ;Ûh==}DwQ\!]T!֏`#deF8ZfR`g߱ړWB@3Ot|@ ^2IǬC;@4wN^ߐǎ IlY0#HyD_L9>#D霈Gz<禄TDIr|'v]{< 9%Y,aj[ :"n }UWll3@>;)k#*^/KOFT~udU99oaM ܊|#K,+[ć_¿6b#.1*4ca)b' >y8#ڨVv| Pؽ2AE?^h/(5ÃBZjRu䍄XK;#N!Pqm@!iW#((f48g 'ư*ECRp¶zگ==wGY:cZcvP^kh /sޭ#|m޻{DI@S^7*͓jKx.s$vzjdWvsddqT3!hJ̗*a,fdk}EG"Nx;ٝvkZa뗦]+V& o;G.m7Oox2:a6}rGT\1U;", +W m/_L<#>d~\xOEKm&yiC ej(4h>H~01&moå'BeVI+Έ-*Apd:oBR8?[i8GRoKfa{."PqAi< Q46!)_hDI亠ډ'2I#O$_-Nƨ9HA5x37$h4K MT7~sl_|ń|3̿񈩒æg) X쓟Pr7^%ِ g"ww5mA-0]8JLƮdl{r_)5DBݾ-$J#lg~PeIJKdP஀\ܠTsoqg !l(諒]tc<59>T`q4`s}4}z`tQ޾N>8?6vt9tGOjK$Ree]0f<>r`>}mt2Cv?=!i"V>b\'&9DnUv:ਓ, cUj`n{c5- Vhf qKpGAa[H P+#se#&s=5$ΰ (TW?`k鷅H<܃+F&ău$/€p1k,J^p駌;]*>nliԧ@'Ζ@p)93D88@C̦p eLQg!@ce:'q%։穁{`ֿ3<:NwuxĥAKjw"e"M !S^BvRށ Jh'U)ԥx[{~JuxJeݥ(/|-pa=|qYGS]7(΄&* L'MexH"0,D)'xyeP |l!b1v.#"qлk5̺?j8PXb]W}~p2l{HIFNR(rǞi>0S(sçwa&dfe_& 2 NLr Ek3r<ƄJ[XAv8>i:j0?J\w;lM: AxYD b$ss[h.F)Oӄ=`FA={77$2X5rzWCӛX  \B7Y^d/{y3uh5$${K|8VpZ>" u 4jDhߛW 90/ [m43H~nZ-x>^kN/yDk ɒJq챵ô OE1ʨ- 6,7T|C!LB]r/ Ɔ΀P3>MTA,>%Z:[doAtKhdl wG.4iKʟӓ;t50ٙ&8dh%ꎝ3foã<."]4?s}fKqV|\ϴ4 ֪Lhn)RC}S(QYeP'`<v@5 {>XLelIz(gˈδG(fC",]2~lt:zwkx3ęfr8V6酔W=җ[[3,A3?ʫ3rL澺=4qq8w+gyIG'"lEU,ĝʃ7opJRݥM,\PD)`+WƳtɇU;Db*f:ODmF',rӓ|oSϞj@W_3>Fl@{*X((Dn[{QYgofji,/D5Aab%W !N' CPc65,\2U>8YIC ,ׇHIZ E {Ը;\75P4  M6Go +Ǘ(kXfX:}ZD֣Nw϶|sP}nۊ :A4Hw&6|b9tñh9gQ*F8ۍgg˱*crmPtQyY^i, FS9ekftm[A3G&^MrFF{29䐣m2/˒TQ _%Y2lwF)/Dz RBZpu[xfhPt0ӽ'd}"W:3q?c.,^+_iiNjE ZC=]?Q)j*Ȗq3Q+ހci<oXdlv ;ٞY(&LV-'Obf"M~uN u‚gzQ"ۍcp.Fu Jzu?>#MwDEpml,\nؕiyDU1n_xxЇ(v<_d2!$)@C`F}Pb.Q}m .buʟf@-Y_lMi}I^l­/r""w%b|a*-1ڀjJ6<E'U[23͞e"5b7=YC3۾fS?7͍n[^)n( Rppv\A n0t ߏF?F.E.c)#UBP+*@ڰVkY])WnhD=p9 ?j~LmZ ӕ{/r*4:Lr zc粡~,yW=G1lga5*\zlU rCNasG?wU}co^yT63ԓKO~o>OSCTBiSeK% D&ǔw>Fue(E;T]v޷WAC#ӓȰR5[3`͍:I"u?Y}#dzsDe/Rǡ%2.;p3K2'pٯv˄cчdAXRksHJ VسW_nYڥzP;!2Iٙwq$JaD}>i]^QKk=*1El J¡@,oA^^VdֵU(} HfEQ7wܗK9bUSD=Em[uSmwiRYz[uS9ZAVrٕIOO¿Œpc<xNnĕ4W`p9DB5֛&r*͛Jyk%]a-"7Jr,3-kʈK8ȓ %a rD~L0RO+{F䨈C!#,aGncMyZx ulrKLMg?aV> &\sFXQ6/[Ba)zK_,Sϝ`˧ohE*?֙Fz]bm=#Yp:iR{ ah(\)}/븙5s!LvQznx'"4&k*rڽ k:}=$^y<|X#^n z||t)i~RD'0}Q A\'|AB]tH-D\(IvGQ1jYSCk:'7cE~c^ u@æe얐a۞DOC[FXup|eE )Zy:&\)H7QWhQqN:..}ŹfDvC_[WF64N[x|XZtܶ*V4\BxKbN\$'[\~ icC#@a |^ʌa̰2=N~Y .= jEط/BYKgx+kq% eÛhCI<1K1BFZ 5lByB8GPg":abE3uRyGzI~Il+gG{Qivn?uMS/l3L,'iSo˥2q> i `h oMp:)q) ^ؿPe)aH XeAw NwB n1mpJfՏwCܛ5~};aDz֖Q Y;Zm x RU!a^_ Vz./QlKb,>;jJ d؀YPuL7nI2&Li稒FI{Gk#jc\ڍO#hj _G_WWJX+V'KK!p& el,_$G QTz,:R*۞HuYBwy0Rg.7BSQD~ǂ]$-0VF[#~m~c0]Њq{ Fa8> Гh\IYlwt{sЭAGˋ-al; tf3ns8m +4ܙ$~ 6\QTҪ0'=Mm) cȒh[dFUyM_?/)(x!ӗhž0aw8Tg5 qB F % ~ry-NSyiWK~~2EIԐTqڢaFq a.9 &'xbbrxM);>p7O#OS`1ڿ*g^c5 u߫d w$[ w TbiWmC@ꉙ˖~HǞ0VΓHdQƍCi=_ޑ@51ƽ( EPLZx~2 kD@ZSQ5ЧLAsezm8CgP+V{4nߒ"1+Y>ORR|4VHc_:zNfYO-lRBϮQUK@l bg`%Tc;=ƐLH4Aʼn2b@;EZF[D@HgWjuwe O&afgW5rYeH@k[5yP%' )c?~^pdV]l{cQjbm3B^-6tw7Wn@[,^*Y{k㵭f\5ͭ4mAgp:7o&tлv*yFFtSo-m<]0K"hvݧ TzG ee t Hds6D} H:ۦ?5rsPJfƳ`+5\玍ίA!v+wL$gܗbVy )Tg(-y7Ysl-τGv-S}ɾ0N pj#!n86wOըfhoRVS5L"A]D)ni5 t|[{'k^ :0ۥM2 \3 [zͪl { aq Ha. IĒ ^%jܤzj=~8ɖʯxy؏yB(Gzs(h +3nю8mEGXKB 9ԱM.5=MWhMn E9}(mw1$ [wAgQ'Ra56b.o!3nd#Ý!f+M⠶TĘ%"dFgH_7\UWا*` 0-)ͤ6ʧ0!qERƂ 7F5{u/TEE:RΪr3n~$R{nI(Q{43}wN$LhD ‡?yp;4t+MI Ak9c';6aXr HIaiԙ|Wレo@:Ĝcww@Eڪa( Ăہ(!8i"՟XH$AN/ѨA1zP6NHxt-y1P,EYˊqhqܗ\\rYGWC`܄%n)%P\RϾ&(+2ʕ}P65l܁VfɖNJ%s8Q}4Ūz3ӂ>J&sr,Yص}0+h#9 pCQJ]~MK2JTjPwd3ǘR SEV)֓W\Ό47G*br^@$*̺a"Q9wR4Z GG}ö[ԻLM˿藟Na,Q !LDgΨbf0urlemm6:9W1o Lc jkS%Fr^Ie}il1Gy"c$Xh IFP]m"j&ǧo_ڪFZ YB;=ObQãB }D,PKwL \܊2AT^}( yמ2'Iq`RRMv]Lz +N0MI ҍƶb}?C K ?dCSeH/2j_m-I'HqޤO1V/ |Լp't0FJELQmӦ/g$5gIV^6؁FS[V2eAQ2ϱXte"kX*g5ƣztdހ}@!:^+XvC8Tm]܀B*[/;(֠񓄸$|Ŀd' { 3&~?F-@G;-U=i[k@}D %-a[u+? 7E>|:r ۡd%rr ħ'BR$t4lNXCMY<,m(%$hsCK/p|/k9%5 V"OXsDl%u9K׭&8]'·͘n sjɽ\̳׆[|rAajY@[,MF3GՍ ,rB*uOע^`Dj(oL=ja$ o7")>n#Gs-M0܍uysr[Y*g4zv׆n~Gjvx9QOgAuԅ RZ cmdHK>y*䀣1Z.B| APN+$9[6+.oє3$p8D3Cd;Seu+DnVW([>Kn n!BN6|K>\YcI~"Sm8%L:k"S)=&ED6J/d,nh}zyZZܶPE"m ^dNCbFЈY?6yt>#kӜ4@*w"{N4MI_EJc[^U^9i+-5т_9 !+kNJSL+H>/(a7~;ShL@p=S#Aʞx8B7 Ppxֳ~tM@a[}lI:aa!"d7kÛ:g{й(yk`"i}̴ௌ%َ?"+ɫmy17l?NlJCL;StZ[Y B̐# PKi$u⎕ J]bGXh#K{Iu!$Rf@'tltz8ȠC0|KB]<4wnv&)qfPڗ;dW:bR\ 9+FT3Tvj=+Ln"_ eZ@@N k~ۚw2b]˜r8sC ƺ<8jT^a1}7Tm8!Q'D&gidWy]MPFؔa ;>4 hND! xE(ƽG8q3*LH}Y.1#x~c3 &AEM3L&x#>㘶Wh5HgokKeUcD"_c<:v{7 Q@yLD%r B,,ȞSw6dwi-n=ᶳ.2{M(p {Gz@qk^˃/ ѵ'\/""k5X_ڣ=ߒ/|RY>k%n, ƿX14^͠kWs! p֝p41ߐj@-;~{gTl.: F=aZ 9ajG|xl̛Um*BO(|yqL,#0DB <+ p`h$g-XryrtEhd s#A9e5Htsd:Nk_LI74qpr Iѫq\bq%K:51_ãͿU,Lh^W瓐ߐh>4`=l?$G3F Esx.2a6U,Y)U-+(߿E۽pk )k(fp9o˘X-gFڡHY^8뗠[KYP\\1\z9U\+tcMR5Ɠ!7gy0=o}U=>^ro9T3_CZuz\ZW Sv 26(жiN {7|cOfk8 rn׆Kt7^g⨩}y"Tshl-!Iq;+]R®{-i">RCc`\WV%?] g+UUً>}j`pKrj##&egRJv> @(k/E0!pS&|nFfL3:? t{Mɹ+r߇c MS)pwܚ R(rȌֻ&%|OŃ͇? ; sjoNt"~ x %_B$t7/e/رw!9^r` 1?񣶫 Fv\`ܛj=tAla+WhB W0"J՟oغV%L}: (x!VSC7A>W VXzdf_">yqHA KDuUiA xN!!9W(X^A#V^J:?#z]Խ39A]vlxppqà A'gF^C= [s_pΩ!RuLUu76kc_tR#"]7j^ td ęw̢dM Wc{/VJ *φX6G-"A\Bg9gbpְb)ybֲ`79aib@Ѫ^dg"_&􀋅.[\(и5{J>e7Rb"꾉^=Fbs N__2m8YȦRӥ'iŤ Rz5Py zsnŕeAPYZt(RÈ9NM&O>RA PTrtÄ^ SV0Fˍc1Tb܍/1V.lLC0s=a(8Od'RDǣf*'`KAeZ1{%Bs>f#^W gJJ/}/6=<}??3ё ͥ deQ#"HVq#MU0p|w3n_!5 #>z7>HiV@>"% iPK>NO26Db M2܈WX5}Q Gw '÷ݐҕ$m4}j)#xo} )՛5XQUPS`Lmc k np!닜Mi^ jCLjIZ@ुİWϋ5ĺ|Xc@ eM|kD8jWeMp [#Kj3*bDeЎ@ J@IBN >9gOt V$=f y ac%L':, _IvNQ6'm Dr^l aM$e+O;`-!SSH]6]1G3vu]|B3XB`VIK5|:V8b 甭yX>V4a3Q=gƦʦf4ʭaT(hY]w9;L |f$1P>05[%!pcj39gLܦr?,vKD!x%ѻ ũLkdzZrBM9rA r]g f?V+骑M1 N3Pyi bO^~~?{z͙pztj\JAy*C1C Ybg_ Bf(Bz#SMXCSϛtlLI:F"Qn#E~K" f5CIV~9[ |s7&@+rh^8>TVV\,L00**"`5Ue jbf'fZlYMCEƲ~㣯i~¡C yTD2PQQ"{xx9˼/c.LlqFLaDpXtRq2y6Tz9LU[*j I9ߎ36 =2`=)e5\pa@]wD7);yQ++I 2"yE~5MUd|::y";|AapTGqJPQCmN37,1/4kUz)a8m* |pg S4Q@\utU3vZZ>O6y@>;"_?U2XZJB-Ɂ&>2wEEY+nO=Yt80"&eܠ'b!pYP^p=K 7E[(9C`0=*iHM}jc_I['LW[؀$n^8LZ>Tٗ/ErhU . WگJبsY3пgjU*c#[e9<([Ǡ\vM"`.g j)-Mu9O,xdpK] C< u V5 NSq^%Rҽ;tOdT-uiBL_`<ج9GzVܛid8D A# w4X<$qkjAĆS߳+t(mcSb(hh{t*>8ϞtǵN m0+}R aeEQ|-ALlQC;VbC؜玒П⒏$9 Ԣ||5Š i v 3ZL6$言yn%7Ӏ'8TgPLvvXK.Bz<ՇSЪAm yiR'PCQ7n&ϱ=*Lh#V')F5i"b<6xHKLIA%ɨk_h8pGMڇZ5SM\F)(BOH$CTD1 $ݛ2֣,cGubs2ǕQK6!gB{*R*uJi\ ʞ;/2ܛq.A|ۙntFK OKKӲGYZc8 ȟK߉~$c9!OBe7wVɳn:0'+Sn؇Gk[u2ѧwMEۋm"n;;e:匯/7B7Ou$ڕ2K =@}%4)F[@M!m5e׼" I[,tx6g?Bmmpl Oټy6C%MbY+}pu\w L?6xdOu!IAnwvmW 7xN3{*'i 5b&YZbXp[HğI-w|gё_~mIA5eIHRa[)Ӧjwakk;c~ k\\M/@PezQDaE^3̨ypX9ԟfPS|6|&֒Jb|FFp=I3{eH E*ZkO l+"2)/HgI1D}NT:kuרr>E>B}`YS+<'~jt\ےu6v%\U=mz"Nu\d+ϧ, @r7e Y"q;ǐj3'ߝ jޢrH&, [Vb00/ [@>oNz:L{edvߔxowAi&0J)1H7MQCp1.kH:nI;Iz {_tu~dВlN?lq3emU HuۂzͥD MqAsĨqBg_ā)x2ƍ5BmWC˒c>jyyyT.-%JAfa9ȿsI !>z6uC\l02*i{zs-k/8GIڶj&yCk._ d+Qlv2 M6}W=!{Xü,hx1N,^Hij)JdhkH@k@1!Mq*|Vul"ɆRA oPDw켨H`Mԓ9 lP(ޔj \즓W>ݹr.(OIy6*]/V-tu Ŭ] ްݕ>45 Pzssiٵ$7&*Mi ]e|Mض<^PuOyG7@&h#,'R. t0yNz=lr n]nůC¤ugO }z¼2f؝Y8C@J5WW>O@ˆKl;iSz78:Lfteo;6QlgRx'bp'tC.B RT+:a[^4,W=;JʈMHM4fF6bjK^xR""#οˎRַ0(8ۭ&zgʶpVszfP_ g||%tM] ]:c7aV8'D2BB{|X`$sx> DdA`Z\؏xv)@@']5<#jAR98ʲ1,y& )JqTGqyx}nǝ[Ac_^̖T~.ƁYM!.>; Jyo5ɶRc)͔V?}`%nK56S ~Whzr;,mY# A p]>7 m*YRS8\]'9MiYH\Q&%a٘=ȯ;s'yul_3.{;YOuq8ұ.fRK%شI]8w QH͸Q)+Wj!,ab ſ@~iA-hշ0Xޒ\<`Mw0^GĹh7wA̩<\LC7;RxR0~*GV2#n>PΠqhV~hM;IDVּZfz\b#m!?&ŀoCfH`4D}~cXU+#QHNPʀ뻧S8|J,̀we/|Ѽ"H X| &jCkQSV*;3PM!xhXՋghR+ۖ&8PTfv]J}L[uMv׎LLZkhtB V`me]~&qf13Yμ&ڴ{p[ %1^S.ػ{15\ dT1e%(b;ttL4iSOEjGLӎOߐJɇ_k[d$5 tRllVow 5suۣ`;roJ._tp)xE!5j)M9 !5RE/{ ٣9Rv֨6sst6pR,Z7?`JUaME#yC= $ zyVZ\m_ j=ֻ`k2pI/=E``KV!2TqQ=@ Đ6׹+.]MHjqe0?}F7UoxOt}!m.C!7Ȓ*bVeG֙)¿sռg^D\ͨ2 1ƕ(Ԫ_qYYmD+Z^c8J,_eV]NtSwr"*c I]9#<{WWF1ϹEPYkgLf ˞)!/? ;ze@*p넞-#RЄP7gF[ L>ĮEBܲ6kpGHrnkF?)X7V+d 0GsuEIFs\sIk$\[ /#gb獷As6ѡC,EmS.-~`- ^ܾ-k\"2sp.7ɟP%|rzXqq3%Z>T2pv'-? ]AEuE*8I$ B!Wϭ}@ds8-JoTZf(&a·=_Ƥ6X_t; Kwt)$ _sR w}*OQ] %L'.Dnή|)n'o "(yD5ŭ o\ "fW,i- -У擓6*F9AG]H&O$\* Cu?cT]ӚBuCX# ~f>8,#gD^nהbdOt$q'͐V{+<Vs=(iGQ_O"-9&9O_{ mY$Bz n fG,91tiN+K #ocAb`'z8?sC%&]-FF甌fw:GdS᳓ | CWakwC. !O63Tߵ#U@jp[cv_6S+ 屪=Q\6K9Mͩ:?l S^JгDtfIrMccS*C9jTpY7`c+1Ö́R^zM&fVqa{ìCW &0O,T/ևvΩ檮/O 8ƒo%[r>k /qs͵~.?aYƃgap>* "Iϐ;Uf^/;c`4\y{Ixx'{8*>!&3J+S6R-ס"ܟ|&8 8G@iO coq"rȈ9ЭIkwWߊn!r Zu0tXy_uLjoM{8KHru=+KUO/Ɔ Ųc`sfUx#7A'5z?3yx3\?rrbE'b[<*ɿlPNM~̌㑓~_ɸ-`]EweFTGKV zBza( ~( Ko]BLPYEǓN|ٮEfM^Y]/ibwU/w8?:'.UY}$3NdV.:hnL+=H^gW5е8I=jLz<[ml%xs"ʬCSKJ:;=~L N2~?5=Dh֜mHh$76 l/z?x O6NO4?^{U.HΡ@h\N? BR$~f<^l dk1-m`Az@mde1 ocٲ!sJce1N8eBU_wnL]fCg('G]UX;sGQ-vurT<=dL3}fQ>3i!5x]V5`E ǽH)^˵ =Q"@ m;Ƀ 2Q_N"́T>mP? P%K#:A8r>epHRm,kwkI5EBD9iÊ^",ӗ_j2K쓋 !Qr?,[ZDQ 4u.q)>?d|>ώS e}Rq?ML td7=|yx]\HdO۴4:! Vi47xZ{ vUC(7ՠ_拝Ӝ{\U-xC"uB<$ƴb{*hK:ʳt˟Zoruj^l8 H%ew# =hNlx3 xmg9l==wi^QqK*VzNt 8R-C j*qszd2yOB(,\*ϒw'l=#)ge x׃?Ѝ+hfSpNd݈[v V35#3kB_ұ4$`r!"H|R]k8W#|& qUs>!;maaFD5$D8$eGO#jJ6^#c$%ʖgFGXd+*hA+D̨r``/hThu< G1SFj~"I.WкgNW=ā\|rŶZsoH:Wjtdq"prQO)&`@iD`2$vIr} GM3f-&}0,NcH Aqlm:o܂Rxf%k 5wd;ALu m05kVeAEN.T Ikh}Wz+t/0|OßJqS|_ (nXe jd1eaϳf "` ӞHXXrcU3CH7(uN'8ykH3<Z,`Rֲz 񆧍P8y6wKX4αWuD׎yF\s?‘q!LՑ7HG0W[/,S;CU4pCD7Syҹ&m|~>w>762JFZ۲Tzm]iFov(g4~lDxдq"0w#0pY/JLhjT| ]Y᫩>PC7oc̞XIYBHLvWc@Z<% kg]_CI\i24?H{yϦ,h;.9K]bqT# K8zu@ C탍ȽD BRU~=@~Jd~Gg#SPfL8fa}>-+>L$ !UZ(`O#f,PAP㝳ؤpI5 ~*ya/H%K,w}f?C*S|[dB4q){pqh9ĆNSmJnROF݄h(%4Pm}|ekeUiv_ \S MIO(ri K)o}ֲR:]ox\hkp`S Cxݦ^_%hÚ)oI_hEdT(̋*}dIp:;O:QYiMfngsd4?Cǫr0x\k ?Xx`cHi6$9J88lxQm-}o+8CUM PeHReӟo=%$KWCf;VWK k.e T'ss-r:0?2eN.riSXS6uJ/ub'Uw$l!7Ήn+`^ux)=8 l Pߘ|5@2v[*+58h!'捰5=$j{V05^šoH au0' ݠh6vpEm1Xc}+4o֖ludK6wJaFٵH!beUW3)ʛ,Fg. &VP9UJ _ɼ,3bE\Y07<N Tci Z~W# vC,P< pqӬ1a;a0Bϩl{VJzлg Kkr6G R2W@OHJLJYE[gJ6n/3.ϸ/~atÒꆑMV{!-o A+G1<cevuX:ʡ:%0"-0|QcJt/$;zᐩl]h Г$e=rYnVTD_I Z|?L44S-(*Nkq@6O';d}r{r qJLWa\n4;1ӣ&Kh䌀EN";B3>Non65?yTmB%].:.o )GܒDqd 19ޝXݻ8,eDGAF. vVdږyq@̕`@"|.HX~+:l[G_ٔGJdg&n;TF%Nb3̼hF L)w۱Ap޶+u[}[w)!7oh Ұ Dz@BO& D+ uB,k;PFX;l/ғ,ӿ-n%,Gr@_#<$ 7g-&|eA+ !3&R V%EOၑV>h3ȓqXwlvʸJ/;_/4ztG+E/O5Npv67O ǣ2n02j 5pF2ϑVEwhͭŵγx Lu(W-LC\ڭizn VņD;! ]aȀm?I*X>gaO0\r9޴H&$JC͸d)%ֿ9yznj A5kLNY J{2pԇ[vJnr܋6ib=uiҽo9UR;م^Y^`@ؽˆD|‚]b 蕲qv;by, f#6O߮zRITZNB+MkrKrc/ֶy+3Q~Ή]=۵>t=TOb~XՎ 041KHċJ-nmY{kΏ> Ș܎gVh2;69jk0 @p*3BwQ$ά3_vJd֮4LXw1~k=/ n";ºKuD|F]4:fQ8(OQn6OZw $@j\:Hqe%_bo'gaxh}2?a{.80lWB+gmR+|_"o 1"?;q-rCG9mتusrd"h̛S"374VSEP{)":v谊]FppH-m} MU7NO;J (6HeDSf[e Mt+3=A%8R$9$]nExWQLQg]k=z,p Rt-UbHOL uw̍2K&>>8DS8@t҈8Oehg Z9\ j\/LL5C2\o`_e1.Nsr[4w_gLD@N]1^7+>0 ܩ f+LZ "l ?MXJӭ*39SZtBka/6S|Zo1^ ~E/dRTLކi[z'e2c" baB\O0DF0gʚ+6Eeҭ#׽`Hʒ x) Lt5Cya8XַɁ"u\Q0d gnI}KjuO= }^T}"ou$xA#jS%l`H Tm5xYE K& =Cɟ="=qORV*φEeНϮ3*8(؊H]i>n`?> ZyΪc"UˑS1kWF>zn<$ﹰ]Y7xIUŹZߨs`f$"M%;ůz{MsԈ`ƱVꌈf<ڋQ'M6?z)k sM+b'`!Uc(]]z>T?i۔ >CƟ?5V XMZM@6HCXd)Y{jYR{RՅyk,Ӑh;ٕYT@%`41S"~5d4ֱ2+8[2ҭSa ޯ!n">K'*{~qU_,- |šMj<[ %4UDX`/']ziH;- ҳљ {ܬ2ZX-.ʢm6\-nӨO,ȟ/Fڪ5\kgʹ.{rvi杏 !DG{[|1 H\9$[/lV1X@s=bu:2ť,b%Fck`+C+xCσI 5]G`tmsP'[֚>߿B*6e {@a qd$-bNْPVjV̰tZV5Ɏ()eI9vRx tuY#le:|M^hUr?fduA MΪzIة ) ^h&hWX). ֡ n6-^%]eC4߇|sMp3Ñt u>`^%n+ YFBH ff8B*xĝ˝ *Xz%B›Y] W|ԅ}g<ro\й=7쮝o@))oc3A4!仛.6nAI#3حTsC0uo Lb E3ƙvm>|K@|Dw>0zP!>6=ctjuC6 "p0ߞ}Ed *04wJE} Mf+f6y9| _9uKV5p\]]Om[Q~Z s֩+8$>jK<7ʊBfQpDdz~G/N?ْ >?(4P XYVi\1 ? |C^l.PcEgkvUgD0CfwvOe Btu2 jgp8IoR7?/L}8o{Iˍc#A'4=H@*z,Q };tG-Rβ誒{ԩiF4<%hoA>5De߸+{ ;eBmd }^aK:!.$Ki(ةBp̀k-Zb X"hh(<,Ef=vT6Q՝%ow7J@g(6 O,yUy\:ɟм7^POamS"W?5Zm5!9<^C;} <ɮ'p-2er* g2QEN4Wk#WHaGGX"&\žpzY.[/6愸C3V˖hNaXx2oWhk݆[ c:hC#,hX5I.~il|M4'>8Q5zQ.yV1~GBRy<9#>Pqbe%==0E5?U\; B3*1sgyk`S۰DCxhz,w>|ڔ-Ҝppmt6Z E 5-z3L[@QSP4/trMRP3HtP$Àzh[?F:Xa&wnLfޝBc?&IR9,m[EM4.yD ]hih|0~˾A=lTeT|65v[Itz|d:(&p{7@y2xyklC$\fO0^5ІU~\^33t!WO)lqJmNߦBϐl;o[ ݼp;wמ՚YKp(_)MQS:tMkwTP_Q ݲ@qW?yqdzQ~+36H >ϪI6@=AO_V[ƹiK1fYyRY /i30ڙ)Bnm2#ҷ {zm޻ R˼V^^`"@ q1Јii05HTW5@+r֌aWOs9ttgցM,ֿmGkͩ܀  $BNQ}z0]UZ &1k:A:*r`I%AKickDA(cxn ]֐H:;g)-xO'!֐WZ%ш"D끣xmo#k(Zw2]澧)KG,xx12lSCJ% :w$VzdNXn7.MRE410Md]|"p>L0R,yQUl^ܜ=#zo-M[MW( 2ұnF~UՃzaHSsӌGWkSň6չ8$RSU3Kk@cIirgFtii!sGDef?aen_~,||U91R^#̚KzGꬺg+{Y׀XIQ),x iTnb>'G}8Fb¯ k\C]$HHAp PZLﺽy6LOj>W-C]j2lpVTWocg̪BCT5a$<5m=ܠi>iN AajA2,'R4[Hv@Vx+/ u^ݲ OӭΟ w/|Ƥ8$n#' *65GP5s򽆙՚x`6"hQ(٨:"y0w;(wVF7{ԕ׍jo@t+>cłmUո|VḬU>sgIkB`Un;x!6ХuX1]hJRѐ@9c>nrhu9Q)J@ rzξ}*(lUa=c>ʥt- F9iv^5׭Ag ![ÁN3ߦ 0+`=1L'ŬOJ2E&6D޽$m59h||20.1:_?eį(Aq$v"^Jyķ=E, %Qlnf$L}) YDcC [>ɸiYG[c)p"4J~r3)95FxƳ\բXOai<3f=b1i9ıdĉTq -3]oF0yF_`"k}J_z0gތ:Fg\0L9ְn8Ƥx)Bz]P"\crI@9߭D8ݲ#2ן0:|zi.u\/44Q, З`|?;!K&&2;z-K=,Վէ*{y l ~x뇤Sj<6})z)? K) Ryv%*r &FNaW&<2ߪk/6cC;8O/pGě99sZ["sY)/(!}_&2|)yCvqu&XkRp*p)54 AL=zߥj`' "D'QU_Rp`7"@rnU}G+YW>,P < : Zfl&Kq6c[du a,hn~<얡Mu \uVZɝ&+DUQȲ] 5O$ $ p!!p;!Bj,HT(UРi3\l681˿Kfc7.uԴ9l2$`/+YU' ys1;B;Ћm-c$xiz! k>6 Z6ӋǹA'h/S@˯2v-\w,;$Р4_ο:Mfi+Įq0W+if?+PC_[puPE&$XbY & 6kEm5JӒ_Y-PyE>xuxi!WO~ŋeo\y@Ey櫾#x!0 S 9v.o5zL3l0J.Pz阅,f5lCq7 !Ճ `HΛI>zqL8۾0.H2__7DIB4r>b 25OӬ)SCJ[q*M-jQKI.G4P9 EmfȳDR#V԰"X/5:sZ8%i=4g.&Fw6NR%NsjWt"%L& >iC \NטSop`E~F+:~sKKKݟ,E["7qUgS!軼So5`uQYStQ<=QvTd/uGU@y4G$c418b4/c/ڥ  g;fW]bCXGaӖflWXR-.`Oc$%M te"pxj.%>qLWN1ԗbo+oJ1`ƈG5c`3c9J\KiFn07),p>.5-eҽ92n,^`@#8-> 6W)|e(ܖd5^tQ"VQ Op84sQbJ~4$?E!Kh.Zp"^U;=T>XH+P`ꋜG(a[;/\M(Qvk z{_{x8XJAy;7dY 5xڌ3Ҧ?Fkn/6Կ$ݡ)"q)Wok&*E s'[#qj !BТ|s:3O3ڃICɑl2d^f-\ [S3~߀vu̧7 'XCVLβ+q1n |u!5@Ƽ vɴ(" >gjJV`%QALnCNl%!kfvnU5ރLamL˛)f@ å (fe oWB7A\ƽ@*{Ծ_JV^P=蟛D^'Č>=6N7%Ū,U6Ż4M¸8Nᾡ GC FP0&Jc2Y k g7H8--'JE0Õ]{ O +B9?8^hSNYr}?=iv Vq@K*f ׌WMs6,,[W15K.X̝*zffT6@#-D*Í j=z|1| [߬4(B\2 t_K݅{R?ğH^{&y3; 3kOq 8qG1jt17%nN gCW$g|#5Ge?CnVWw&Or{ȳ!Nuuc[ysIT]o`֐zQߥ!@x0O'|ZWD/{P;%xWr2L4.aPJ-Z:yu#Qm]Q(wϫ]T<<0ẇyXk;ݚsB|)Ćv' B:Wh|ew!QKŌ5*8Qjg*Dn^k=5_3^syvVx֠;smksY6;Bhtq_4VLJ iGsP dSoA8LEՒFn3iy|È\vͥPDWLbt={J2ïa8hyߞeTJq% U}˙2j5V%15ɯF/d{m-J\$UN;c7sX`LRk'=|NѦ({Xw?E{zO$֛&wՕƽ?נ([ NƯpr5?p:ρme! h#hfy+%QܩJ?7 =J4]ZN-PxL|4ѳ4va>}]5UhfюhB݊zqYv'vTD<$&b\fI94\s;qޑX1hIL.0ɉL7LDG(4ɭւ+(Hił8!Q@{tj QT}먭GBg,,C:frKI7.SgԂŘ~NmJe2Jq|~W"g+oo5:3j&d̘!,mc "G}|R {xaXE_r޳@%7C\3Zqy~JyuN bmN}8:i{lh#yyᦵwꚿ!>Y!.3%g:*'ռvh-aHH3|1HiKSzNφIyt>~L( HpZ+j=yx uÓ1v#Ma8 P;+ < '0Am:w~%6lDhR[.F2qplA?K$p* RxWׇ4"Vt/L  ^6 }9m{Sg˶X}uӚ7Z2qƼbJ/ecй,$r1Sg6GW۹doHW+J_HԤ K|yx8Qo vÌ#G)%Ofl, љm꣭;V-)999G9~̙y4Y[8"[מ;7F|44˹@gJhٚE^`Fn^?7GrRC'@) !+@ӵA򎏛i B( ܋*?B< ¥AY;u@wd)g*Zlc:X6;jWӚxcR2R.qN+$Vr$!ca">bmXg0BL"b4RD~1cBuslG)s}Um,ĹND4P#B*¡LסD죃"1| SIQLg)~7-]EI@PEXKK5ĨjlLO\xR@S֒o48\p ىadqTyk\?zsfK*&oh~B6i)XBKha: loJ-3X ҀWF dž']q@CLNJ=) 7G2O{;!^_)SžfBC&BDy(s.{=vU F}YJZZu#R=Ņ8Ma)/(3Fy8j_Tg{}|1瘺gbWd0(ǽ{ -Hn jRc@j yPT`_sЎ3Pk&n(f ~])`5ujp k b\iG᝙Ko9\]x Q+qhZ+dnURӑ"c֒zrܔwqgJ.6 ve<;])Wkܚ\Q eHNȆ{)"!낣eE*Va2}>1xcQ>[Kv8Ķ4sX+A ؖy?d,g](+}VrP_D|u{5 QiK wa!ʂwDEWonvr%qOڼgL#wA\t) iݣcKx p=ُ\j߽'&I(<UҩOkwa4įq-Ҽ#>?7)S P: ZE@<9Rįƫ$\uşTd玸|D-Qӡ]8RnL??ȅ"^7k/y7&_arl>,$Iߘ>jQM?==ِ|*5pի{Vi}:40ڛ G_8Rېԧ=:(`(f'ytg1X`C9:BA[=Z^@Bv80Қ&sH fbҿJ"IFwRvCfkx+\6ӭ ԙ>@T0/˸7 7`hSnbw`@N}(JBп%%[!}= B *џ. bĽk>7E4~Ш&'b#| ?(y^V4UeK7j#J ` xaF gڥR5sܙztQ]]>?%$֚y,LOW eTԢyak[Y|I>Nu }oFt LwdmL1&r]ʟʢ2ZFSvs&s )̟rjωkCw4%[^{6F-0xNH{BߧIO$Ȯ) u?Z*6rn ,cJ Ou/}. R9a~nY ԕKu?9VM~5% #h '1Ri4_TL | s ZL˘N@5%%;];Δ&{"\;I9="x3)ND óTY yWZ~dltwRc?q5Q`r"s7Yͩv#sp<^i L68Ŋd$at\ȻJz+I~PZyfC{=oQz?uc!u h 40*¸&&{|F(GNȇ0e=9]9jTGڿRE)A2qݑ+\=2-m9SkSX^%  q5<ՙi8kAh4&m-).ٓ-KE&ז>FŘfm "MZՠzфn O:F}$PA7D;ӮhQ_~ -rϜvdkUFrAiDވ.6VCiɄNVr1 . {A+Wn(#avm2 9H7;SL.@ޞ #sIUK/m,cBGs !UImyZqaWf 譝l}؏-xzxW7.zǖhT\^9?w)Gx̢8K\`MBKҠ Lo!z>†8G^>nR] k"@}-?N c9X%yeAJ.k8vt RgpwP ̋PtE<?qIUx{KC_,hdҝQ(nJh/JHKSC4ۣYᘤlKO 6\K@{8MPu/b\ 9[[d|f0>~ T48ak{+AM-I-SpS4U 8B\6v>qe&TPk7_%b-njzj&` 0S?)ǭx 7C2wxcGsOiJj9?%'650 ^b.gAr`1^'x*1![=!kt’杆rN|])!s,^`xL8O;68Ce! p0D3Gjqt)%U;֥t Be~$hߧ[HHn0Pk}\|SS!; U0*˨x) djKqﬠǯP\yn<~5ҠfX&ŁƟxfW†͂ 'Fv%4[EVc2pFKY&:9|bfZ kV97?y}vTk6ا$2!FJw84jٞNh`CoDnm+$sjt&O2^;wHfg*Q 4IJ5rK$̲p=\oWΆL}lXGXaiW1‡>s FhF x9 brA"!Q9 M4 {72hbQ͇ilhTaߑ+ya켿ֱ:)y{$\ |j1 U9\a!/?j컦Ogcr k'{tJC BW~|VѬ * wfڡ(Wؕi/E.$fM󒿗6Yݾa#Q|+NJiiM;틍݋!A |wLՠCT(Vl_<(Ixz.:Ofb1ې'=g|D>I !0lY 5Cg>r]dO] WYFRBRV7zM;| =Äu5*wh7bVn0WKjgC^/+{S7Ҷ`ɖol ҬƶI N<砡(߉WULrbt2>[$r]8[P|3Qw{3"6ɍWI2  L;GS[Ă}*l=*ЙZ."~LHٮ[cB^ZJgTT+j5]imO'صQ* H<^ U4ɐҌ&# 8t%>k^(+e 3 qltoL`YѡMϋ-cpdj\u^'NqmJnL쿕NǛ G>Oe0S=Ze. P溉- i?43]${'1z_;!PHv4ƼkXN `7&P}2n :t1O\=6y|[0 618#=wGJI=1P V "Ϯk89biM.[W& :ZM# Y,N5l,ž# _Ba [Kdd ;v&uaryV"G^7lԪ`Gʣ.7XOQ*Ji- D.֑UkX[n~^mXGy"63>|q`ב1qS1[_‚J$:N;#XFٌCeҬ 0IMnԆIu/M`$',NZ u.amn lRz#S/U_R=ZYhؿ@Cr>FH۸(7&&SXvnf$Ԇ u}Wu3—"Qg)#Kh\*!|xD1V.,t op3JȒU;!`}E}Ldt3~r9z`hd y|"qn5)e +yl~j3ì&;W:?W/R |ƶo|X2dO?KЊ(¯ ,kNŰˑG9\a,&{tDqkmDBKǫfPwLĆR9A FIIԶ}e$̻o]zb(N.Oq5$ڒ'9< /qF:'WE|H>8Me0D(ݸ?#F#Z$-Phy6imǏ4~'ծXbK\5ۘ0w{a݂©c m]n¿hxk B$#ß%+Q FzvR1'9udEd!ԒF^x>noAiCCt`* %. ܏Htdi\ގ|{#N_-t:X?X8uj[=?8`}'ȢvO_MTdyH`?On2|W,p9[eCyKf]GխEB֗O3u/͸A/3dmpe1)II0g:8ο,_~j4JUx `uF˒xE.^jh|/&*\VxLx`%+΁n1Oe+HL,1Ks`ӯsbߗ̇XjIRo!LP,=rtGǛQ#1t%VNyodr]=?!/LN1hgy#Zh:_%TT, a~3̟Znɯ%yqrs&}]eJO@|ZV?}^0U]uH}L[2̛.4+K%O}F,/UJ YQ;XB8ӬYsl -Rl&jq8@B,ݼudT}׊Ns^3fT+ЊD v>c f9q=(OZϫ "d[8C2EЬ`pKH{gG;7 xͲ:Ͽ٘p/҄i|+1A(v-e{SMr)CLУ8|]l gPbnE?&At k=EOT.!E8 ߽DD`*I\M~&~Հ(@bHw&)>Z̔~/`VY7*kkDs-X6d"߭}?%9o Aqp&e{c_^8ɤִY떂d>z+/8$ќx Mh q3QA~s Øh\ƅX&P-~6J&OBHtѨY W%iHQ]\XdI͝ϔhJMVP60Dvg1~K4EN1^hSX%^@3\ׅT+#g0q"HkT4/P9.lBa#V;QYoSN@ ^?Yϣ6qwɲȒ5gsEP om).}izf Vrȗ-Ҵ}Uu8\O80fq?ț9-GJ2C^ VU @4 !4C\od;X3Qmu2j?iks")=;:m7汚Q$ qN*2t8xJ$b(b@i(|T#5=m8ŵ!LZݑǹqs^%P)IzcceckQ;֘!7 fTQۚso ()Xu O3" &6O rY=nHN4[3̀a~> Y?k#~pUDDq<#X0|x z.OPcGUc#Q*%d'[u_)` $QڷKVƧ/\B^N7A$3Y.ԭc~@\:nJvd[0 FLD ;n_lq9 t>I2HϱF}'s &5hdf%Yϴ 镴wnM'kOW ?`x.]9$8aŢpxz!߄XF'%㶂G#SER mƊGp" + !QГDs6q"#R dJ :Zv7A/qҁ V;\'d156ѻ9UOy+:)ԏ?yg-^sw55:+6-n`p}g?ypϑޜo|:1/{j*L έ{:g? <<dgUG ޘw*%xս 1̞9`2^׹MI*f}32o'Vk)h?CgO#MDd /CS› #`cQa;򦋒ҺY!<|;3K҃TU}f- :=B\Hc<)Vz.St,Q9MWpqs!j,,MH2;{Ǡ}m>ؠA.q#F3ÈĜ]9AL?9 "D.Q.珓ԭ sۭL f />8\ qӉ>;T]L4Qp!FQq4m]_7"(DAo9C,!  { ;{=8o7rwBh+[,-?:l=U&K:q-&DE6=Y_aw>]wj;XThZR81WZGTTZl=:U5ԈcDDx0 XhPa;:xDfX(QW 5 1m\+!<~$)h8&L]'̳QШЀa~c}*$s9 Hcmzu*Rj@P](c3:g/6^l4y:De@nWfN% J2 c4kR67 IS|>`73p!l%ud'SeYљ{FYwgQ 9{fu6Fv(I(Y 2mȷO͘dC66=E_jYXɍ#sիY!>l_(oyU.g#ũumA\>T\eJs<+ǜgřG?.[L9C?,L_3B9ѸYR^`%*RT^uC&!K"(%B~v/6y{Ưsy56|v,]qn1=Ǝ;x45"n3Ӫ󢌷 loI0r+ 尐V˚ XVok9Pz ؠ7'!ɓ`t"9? ,=m.c_^u%%Qa,ǶD5Ҁ(rmeckgmk1}rK~z}كhY() ଴,f䙀ז[Un`qs*—њTfyEOeLAnj[j$Zf̭h߫N5 U]XH-Onk { a],A Rs{)0%wzRMrLIv<[U< zw\|]'3yzgx; #$| -ڤ4w92*[.։8Okx~aKǐN|K^\?1PJQ`Fc:>nl~;,֤ $Ǚ^'PX>1)Zy(gǦ˖!@eaМu]jor")^]ƃ' gSHAk+* jR%Q5MIvӹlAV'@Gk.EH.aIeOFy`d0-fL$r @dN$SMK*7r]}h/ZkVL|R ̔5v&ۮhۣ,x6|tq/<^jۡ /;07P2m׌`:9p/`7Ai5wԑnKvͣv$tb7=篳>?;KNxOBbܮi/ / p}.wԕAoz @'68p]; VrHA_':)A>>gH[\K|1IÈqOgK8؍]b)t,ҎjcV]9F2d@ǖ;+1OO"nb}`T>wm$ Q M d$˗\Dyux ӝ\ShWq;C~%)n :~4НTɘ ^(婀+8~OO@>ʀ?iȔ < u-utn51uQ}}F-w^= nuU@8ȵZ+Ĥ0za.R \]Raԧv'1f4 3w*&  û}uLEpRDW#߻K~ 'hke g7JÆܙ(#H_dSK3hm36]D!N:mhs)+ 60ƍ yP[%Q\ V'.D (@7!MTL^F("`R-&)qME}_/;ڎeռJw܉(H|٨<](aԏt| u_SnH7o%fw#F@2E<*$Lm[ 渫X TtJ2{H")9sf|5g|-%sXԤQ^~Nm b7],1jwE}L]Cw{79 o&yL鞙.UCϮ뮸Pp0N73L&"MybRx&^v)xQ3?KUИ)Z9.tV4 7[N`!t B숑`-UBes"uxtEfFXx%YrnxxCtKz#o~',(p6k60/Cg-=ĴzGMꢄ!41=5ނI`҇dOZ|JyAS'l=KD*|Œ>j0$rtɏדtsum&6\)cj~";0ɵebߌx\b,ǯR?,-qu@~?~WT.ߌʷ= AUT 9Xݻ ztwiJ x##SsR{rIx*I;$'wY?Ѯxf N7B.G[*C +`qx9P.7UlGEadNqŝ&4t2vM qc{&Bvm%o8<@3YXi7ߋEY4R5ˠ:E!6 jTדp[k,Zi'&}+R{7gHs΋H[@Բ~EzI ]5:׏W)>`3>8kyЯR40b:a畬J Dakk^DWurHG?5bo{v[YqFs6\E_7fI5X% mT^sl:k|Hb.am\,JnD$ޞ@pnWeű+&wqUK s;Y_&|cJ9b7IW=:'V~U[, E^, nܗC7[i XMDx.7d"bdc31R0<./J 3j"F5GJlр({H>viIFAЦftd޼uISeO{!4[l\= 9dŠ`x"hڏЏ! #v{ٟ5$k[t;N܉Cœ"~;w+}Jѓ 4זNHд~DB&k$Wp#|>=#Reҳ&SI{SoLRZyg"ޖ#},"M 0&noQ۽j+EkONMpW>Y 6£1%c|B@SKDNyϝoPًhxoT[3D@!{w_Ot󫛳?:\o5{N'y  W/$ ]0sEP)jdQڿYF'cQn#B#7o1yR\p8CU>s 0W7ƧzƧPInw%'p94\ѭ{.ix?[`Olk-7ل1GS{Ǖ= <Ě烙n I<)P=H텢݇Fq皂T3I35ZYgjxa6YXǛmF. p=6<-hxhedqPyNJ2"n;V!wn.jq{3bˋ65( |L ,@I&]UD d"]]I3V=\LYm2ǡ -ǐH&x~5<9u~ l| ~"殭t8N\9N6dYh?&x&"%,L5s1U8Zع N$ $׫g" 0T3!fJÖLnyY(1{y^t#$6 q־owzBb}E1H_ Kօ 8>hG.af&!LC5{ JKziҴ MDP{OdV<%}ZîR:egu.rdM2,.* Pk44p$6$|eEB$ΝY+tZ0EPSezo{^D2T϶gt~VQ_X>TǔlmPYguB=d;ʫ\bS-V~·롍ZݒBL,11b,l|);fƀʫNz/k̓/"0"c#rbxY6LhGFCn.AZ4'V>杂t)MR0'd p 2dg2e󠙿iM!lؽ`Y: C].K*az{;+e3q?ηyoY-DK(aj,G;da):R҇ ƦY="w4%֐-}.wWyԔOM=ios'|E붟@kJ=i`Td)!YC}C4㼴KB5%k̺hF*m9+1$*7 :qMxVsH+"/\hZ3#p9W^=Eڟ:\+EkVY(/ݘ$] Ȁ\x H}:pFwJ&Y;yӒYH0a2*;pkto~Sx:{C/>̲OdpA&srfQ$4 kzch IµL2S<-2shpI׵\kAV8%Pjqs6I֔.νz)ĸ5!rf'u)=WR QrZ~tMᒆ75 `4G'i41z ca„ I&^5H[BBJ7E&h'2*>;M9ޣ%%[d~zS5*p0o@?DlQY:taȾ>gha[V2T~SvRf(.]s yA('UQjf&!3}mb禎`ʍ v@Qd k`Vqb.0VoTl6޹0i _Vx$,q^O(wVC-  Z tՍkxb>~'xďz~e-C@ `KٵŀKlUهݭWwԻ34.2gȳ3+H+!=Ĉrnez/.|.`bs`75|- (nBs!6Qv0O ؈~H3{`FbB[wVYk$6z٫^F/tʪa=;yKJ 6$;oetr5l飄 }oT{[Qԟe*iW'~{}bT'yb蟦t-7s)L hh%L'ZV_-&\'5gԚH@^gy'!B\;ÈlL\4JIK_J=kDrW~ j[Y1eȾOfϼ/x7@e5G#{ > ]M׵%\`)e]QKhAl$p1P+%hW/OR wP=5]8&RR9F;cާ&^q4,R_~o0 :d˅tb|R2YBi&ghDsYG9ӌuђtk܍.d߼ W}p"|ӓՁ3f1NO; ֝㎅5tIH/]VԔ\ͮ^~VkD',J3IFeMCi,A>poyT~* FK!Z*68 ҥQG9V@76D KOpf OK%}n8#pǎI%tkHq|Yb!CX:w:c.|MܦYw#Đxz?uT8e~8P :K-;x6!dJ~LE' {ϝDg1p'7{' gqn,? Yxzljz?)sL>\B닄l[&>gh(^IA`Q_J?TxX4pLm NJ$6yjH?vWM%D!JKa5q]ʥC VKM~+ȢU`l6JJ >c=h% R-ǓA#Q<]k(g2'B\$UK9VȱEL-;9ˆ<{횾H1$L5kbáS^JX}g7(Nl0s("e ާQ/YIzlw¬3J!x{nXAmf< D5` ̩NAǕHsHB%l?L4d4/(2uS-cGe *Q,m6)0ML"[k1l tVpJ[<3_B~!50]f*{ѮW3VBHVX1%N을Ld?|{(w=0t95;Qpkkn${>sfxCi I d~J~N2VfOcZ"cI:6g@Sk1unґPD;N <.8F؛l8WHB*̰J]iӥIɮUx8PޑJ$hA?;.UhpJToX7X\Hi9Jjk|0<Q=!Q/.#h=:79M1]l D(Kʙ*#qkR2"JB~,rj+]Fg:Y5ꟕ~{]vtwQo 'p؅|Gב3ZFZy UP!@1]Ҷq0W9rNi+#k2C a1k Jp:RL'9D,)wjP<m" 4nx# F ϝtsg9 2\UDL[㘋s$IT}/jNыi1Wj,"Dw?˼?ѽyXWe+j*EۺꂆZnjځG?cwtV9gB,&dϜosaٯSOve6·2uL%;D# \ÆzECָ68B}aݏd07@g56knMM:7d ߆3$fb 0~Ʃ7YVH^r*K3BeTܤ1aIGAg "Rw|0T> ͟s;0xDŢL3[vI":p;$y`S&v4NeoM UP]ii_q<,@큻68w7&OPdݍ!iF>Y%w& #EԸ 5TZn.ekORu)M&x߈AfqJ%)_XUfuan,}@7} @h_Ӭq %gP hHQCڤTb8C+Ҥy!q]:*@<Y/嫣%]ظoa(tР;My&.mwnaf=䶒W *&#eW"ǂ] ܜOd4,Giȹ+H DoAª{݁GܸaUr2 %6<41>$êf8ؾ=}ϭˉY^7NΦ5kqVho;ľ^UKyvBwL /Y9 NzՃnZMA?+l#3nsl:QI?Ƅj5}7d _C Yv'jFuX)w|8ePm&RT4X5P`d5]`rjAo^{:'ƟR.0 y5xnWA:1@_L'q˵{yKc}tKQ_S]bnQ+D7Kx*j:0/O"0z̴,]Tys\Y-jxmmdeEξ ʙUO*9w F}'qE"?-2gYHj6pn.#-KdrJ0Gmc8lOr16;^g/=k%,\ȱD @CR塞xΕJ0 z_$bK 4T~@}}Ћ1%7vMy> G"|1̱S"Rͤ7_|)G|:HZz(lqWF?wéf볌Ϫxڭ]=4`JV:woSGm.ce1Ehm ' rQM-?*61)_h̃!‰iڕdqubS706S b8E{@D9US )E׾XrF$eGT3$+]lk _%]x_e&k{pyO/}1v 9Xl84pq{;\ 9R=§IُsswZF,u:ikeC;khJGpP"*vT4a }1!C5L2 t̓1 ĕ,/2 XA@=OT.CNXr#4(~Wӻew(9yIa:Ҙ*6ez/)9ݜ~~b3{.{푪ޖߜ؛L"[Ut $_ hb")VW{_"gg'{ yijug%ޑ.7Si+l4&rY^iNn ^O[A4)t;Z}<f ή=v|`6؈Vp=h`Q[+Qs9 (&V&؈w[2Ĩ55y&&͘-gjxCXazHgh]CKLHH)˽7 8 G'.wRgy<;~}%Ҏ}&&:Ϋioo* gS>IvZi~nøo_6@m3G V2"?tƤA kط *Ox`EʦO0<F%G&[ggӼ?r *"ԗu jt'dJ<C>Ƹ7o+.x`Cst7Y^|ہܨ21 $}@ihSp9IOsPHM}!\05#CVBbӚZQ3w㤏|C]GAAV|G uqMo&{:BfqDž$WyPc@kCh-^TRd ݷMhM.0?6 x'Z{0 I'/ I~+Mg'|IFxY", C`Ȩj+C]}~aM#V[ '8rH킬0[0n>& 8\%)f^s4X[/mY[h vޜf nNf k]VCOf<;i0#J4IB.+gNFgR,VrOڒzCLH$r&ro,>:;ᤵA]ܸi{[Nw.0P{KؠI3>7 LΈ່$bD΍(IB"ȯxE71{ȇunrRcJ̛B#oTb;9sAk\f5IM[)P`ZQγL0xZmZh~]3bH樼&L2j7=K ,|p|V.eCGP&m\yJmѴ2'dV4 '0S^`JuHx(kNߙ;Pgm`,Cwwh~>业3eu2!wt2g)y=۝g߷JBRs{TحV䎞-_ܥKNHvtLdCQ  h49x# "8W/"gBțHɢI̒؈hÞiM ~hJ[XZz /QXNOn{Eyy<"T}Ȼ Ɠ/'%QIxAϦYf~%8rτ#7|FSc\:Y~˾`UJ~İM`[#0||!Z8 ́c3d -H ksp,,>6$%*~1.Y hhx=WVjSW[%F&)P:gGeG{}`=);X檣ʚYuyR7UB5`XW:KFC跸9ߖMuk`Eb OɄߖkb]l$R<1_.CT)vb(8~J4Nl⫦m+!\L@3VWe/ɡpOxz T|L1;Dد[C%^T x+~ՇܾG F'TQ^k.<njSb Nϴk 1I=G8ۗZ iSCIAT_=Z#zc͗&}"RM2#bs/̜Ph~(JKτ;{=GYwߍ$vSW7ھ7KyLL4TGQm/u;?ב{5SDam IJ!nNch;g2ix~:pP;ȒrFJ"`*=3$fJem#Z".QRm7]8e4.~vg 3Kh#s#p?)y?3#R>ټi7J@?3ȭeޚo_QB&(.b-kS~nGb\qKk\RxUqSNzJ?n@rX& I|QN2XoЄyi sqX ƀJE56X-ӅJԾ?Rt)쀫le)տ&8tb#^[b8yء!/5tVE }/CCVn9 l;^Ol" 5}i4͕3M^ K >ʞ\ Ϝ, 86ɣF>op+MԐfRSFS͏}xF3Z,8*g84lZbݴ]/pe(bвMR,*Ml˳@+E J~ NH dn{ӠbuQw-9)kPNg+6zt#qG/Ӝ`MQy~1",V2\N*Pv2]b0ˇ\r-)SS?Αu5| ;}ʟp뿶uW23+#v,*[?wBI@tc*Gc_Bf_k$sZԨnp{PĕQX)M7#vPw}M>Jvܻh'p!5ϻ!-5 ,ѣL{%[F-kI[x j 8{PԴнmj^-Y^TYݏ' Nڄ&&شvqJyD ~y&߾/| p( 7]<:F!otB{U 5GT/#W`o@㳠[z: -#+$_+%6Y醰9bLCmJx\E})RUjeR9N #A3* 1|>M+c&*5JnQǽ^`kB]+j{`yi R ǝ,\F|h}bGSbKh"KA(O0+AU G IhWy52(O'V%{67k\o X H*$J ƛ0n8>Gs{PjjFg3P]5nз]LCePh/U O.H͹e>P$?e+\a-g "v cAL"q<Cvci|GZHC\3/V(Ic:.y3dd{,K1巴`t*tMdByfPjMգ_SH~-p燢qҙ1}%2ʳ_~0bey)=% k5nRPWQ좸*>֜<7LZ[Kg䍨qt+Zc S 3ccw>אNfi (lL\WU؏bHx ޅI}pQ$ߔ=@X20(+kYZ a;Q`\MV-[c,n˿b߬,2Ɂq(R?ީ85:OxAQ#rzC0k߼_ Ε!MIJ7ylࡌ&a}2SnLj Zۤ?;$C1Uk<Ɵ *Y aё[]~\tdd}AlHU O&T)jp5m(kDU2_;]x ;̸NDmyz}^1l/9ЙzeHfe-`X_$c2/oALMQn~{T~3֡;`p p52#/ 2jUlG[ 6ֱaLa&Qqtl8TE0ZyHAAPcH=5Q-ҸUFJDp8仭{`S^@+a}4@g>[q8WNq?Uj̫r."+)b:q3l[6oyQ>H^Ȣ?I15$6pxvH Ɖ` }M*GȴSSce7m#'Na-WX)h/rpg`DP\Lv^|f#*?b̰ 3 JԐ+hm!B""f#_5pp?uśN$`&ɽvh#9ZhJ줿~Ƴ4[Qkt3^J9Ԧd0x}Rd_tp;~ ,7$b )][htȨZ. {Z#;E }PeQe$Y60E'QpzDdZ8Oӵ]S\r!A 9h@[GyN1i=;l]QQI (yjS,tLSù\/xܬo\էY~^c>73rAq(m; ρ12uaV4R"ֆ͡X=Xަg݄Wl!ZР+ hnav65̋D J ti{ֶ=t.yg?u s;E!&:>Vh?EL[zDq 6ƂUR]Pb{&_cʯ1VB1đؙ ,WKzxUi;b_@C6&A83/5z26cċkJ?:G?˲ޞo0 ``݉,@'Y߬ΐ;p0*v."Xl<"'}AI xRf7*K]jŁ(~=&T)%P GcR=;4N"y3K!JiK@*JҨ髲h/F@S$d{Y>C:R/pVwL346t$ vsDxW0bps@~jxSjJQkʣɒRSTmILS0)td aA6<DOXw Z("zR\YwչmQVیVyw8ݷR(}d=B,e}XoX*<_>3Ebk݅hS>"T'Sv4U@Ju0Il'Ǘfjݹ$}-K8ǁYu }{XXYZc7Zθf&sE2G#wxxTZWymp*ފ1T515 &H>OZ/xvnֲD"~Oq Mcj5 ׻Np,|+pe% A򝸠 _gŤ-4V]͈Rq_ofl7fNjKeT~*/Lmdg[J|{g:!gd H |n~z6 z 6;q H'f9@$`Xf.q#Bxw4h}͇x#\MoV"5̪slҺ<Rl}N%e r䔏nlKgM_ c,5",9J&G) RNNOݱd3X:t?Gqn@ʙ~3=6RBKe) |dz ;o~yc,!:ܑLw,Mv=SwIf@@$ p4*6l*iElȔ::fQ7dk?YM~~YLw)G{ 0 ꒏C%צKͰ9|Tw a# Ƚi~9Tv QNtP =~RmInHXyEV͑70`'CS:Zo ^WYZeBzႬ[KV"rev\b=zhJ _dQf8Q=7q$rѢb9f;@\V.'ux<Ͽ }Dgo,C_LAYa+fݑ)PFe~R:! /ъ,׳PR\[ u FuN'޳4|\[2 `$գƫ|8{s]|ƊXYG{;-,ONO+}@EbjujG3m+}6]3[l43:~I#Jt5ۈ"Bs=k h ҀuZf9_ D.CZc@X`$$~ʤL.۾A9+HQ7}tUWqr#?@ s!þ t$K$r),~CGʳerw[Ym hp( 3dOwXA{S&2ܔKQI^,u| Lґ4c=<7^0̑u(6üijƀށ *X C?(  {% gPuӸ@8btV Y#yxX3ܗ}H7,]4&uLFQˎ=TN%uM]DPyKAZIW;Ѭσv[%M42(2F XcgBCgv@fD7r":ii͒rݯEa 9Dgz"wKfk cQPHs%qs J ^xADR(k?BxEJlo&Oo^"&Wa2\nِƝu%9 KA}Wxo4hϟJc&CvoX[Jh~œ N>)Vq] x+L+R-:0t~ il#vKsJZLXZ 3uƑH wE*4lO*3>,=?q** CpsԶd  )vnq H.F|-46zm]J֟ X6< 0,P̙q\G7gXLIyZoHgXuu!zwHS:?_4>*:'dJ"zmz m:fFBqپoB^}ŷ) !c,)ci  2FqssN.UYv]T8_iF3͗iPJt+WzI -x~g͜~&EvZ<ɑsY+|KM]Ca=&}uuu ؊+|6'EQycHԭpcϚ)<w@ Y/n r3)Q]SW E @(C |o7}5 LbdubO[v?᜽5BYީJI$`JnEz򿲪g-աMYS$ax s+ӫMR~ B)QѼb䥥xc\py,l GĬS3+:JԐ= 6HN##o q:'xlJ@aeGV{~hy޳ʯ{KOX  sz- >ݞ-=|m}V#R9۹?r8k-cy_7&=D˃ׁMc 3\gr5h4ί+wx*Oss_KgGmo5Fhni. Y(U݌]"EJhLpе|!Kһl̑SkDW 3{hA`v ,2KL!=H~5T&Y`$qߛѬ:4ieͅ 9>Xg\nDw%$!?*bv L@l {_Sv\fݩԯ1}ڬ2}[ aުTɳ)@ġGC3B/3 Bbd~$=|h|7hM0E3.I'{_Ƈ+Bt-QxDJtG9U~RUg#n.ns{+4sH)8:q iYdžf{z1 >c7E^@iMihBBE %g,Ï[H'b@~ֈ!-]䈅]\xh(rj{y'':EJi#eyOAlnfy(2$\5D00)xs+gc-B i6Aomcf8YR>6pҎՇ(GADqn1~~6nj=/!GsXg2 '#?7`}Szqv>ɰZ<)yo)O) .V~,yn5^( 0R6C"u[iq`4N!jaF*@z<]$S}Ӷ6#QD$NRS77hA>$q#y$ 劸-w<±9]ő:y8)#_Yhm@ :un%!0)Ru붏h5-T1-ƻM1Pcgǡ%j1-m#_ѤH7l_ځklHWKv~\D:aSi? SQuMS\j@01.:zRwO,Zoiu yқ{';ݎ]x2fJeENp7S\@&"XI8L|P@t-Й*M7!"DA:Sm CizM+E 亏[cQ+}cDcOVI|f7Q_iY(0^tU͎KS 34#Z FzmRӲB wy'~gm~94wG6֓[f/#^S0wX0Tifӄʊ"@Gԙ!(/ބjHV0̓'@5|69oRjCJe OUMU~DsՀM*{ )xIH4)e^SfNL.k(휪QGZS_N2l@ $1@cd4TLe j#'źƉ 8oKn5I~\z!*VƓioV젹 agr8_*yC܂w]Iy { ZW5CcS"X<+Z!B29(;ɧ|3UCAv)i!q삍0zmjچ϶({}Qib7d-KcJy=C:iSnRO^ē^\ vE7F6eaɩ._aQr;p6 r|_Jah#FYL *b4>k 5k]'Z+N Vc;'Cy~&٦mepB\ay6[̞u4Y$͝xYu.-k"+[WP>#O}ݡ˖n?7SeC bZϾ^ Ls $)?t+:S̷4OGb;sq= B ATTЋҏ W~ ph V\Gr` tD1K$ABUZgD ].RĻ5nSSklRw HyeS=G=Ai+6>Ή͞UmP~r"r~JR+(0`"kL'^xZboZ=<ݖՆqpt!c &@oy'`.j}KɷQf6<}܈%g&̔|'"EOQG?Z8DG&$[RɎK; Mm,Ѯ{SByXpBN9Y9ǏuAFS*ӯ|i.xB`ZW]YX 5K6#RM$|6&~[nӎ dJjK)9W80\^:dGrÙT,ApS[7 qkƍwĜn^`JOeuF>3tQDIϳ_[sܪ ^Kc/}20Ws,?(lRLAjLj]!<R^H& x\FdHM ɭb-}sו\g¦to{zty0$0vS&3, )_cxa|Pd ]na/rG=cUt){7x/\xaa,( sp-( бĤQ̬9¡j-GC!ԖU,io%|o7@F:ZTja)@{CDĵ\}sY# _o`[|nŬ_yy)^VRAF!JI@ +#钗~O},UɒBN ѝ^KS{*zgE%F$ͧǃԏVK6HRm>,'Rq Һ7'/ wWZV7ʳuLL EXGNK}8p{XLqL`#[_f|MML}.'f@h94}6.И&2oDq8֧~4;M3PW˚FMszʬ( Lkh!e2!ñ j1^6ߎq7gHoz}/ ]l/t0Sx2S(68i#霆M{w6:$aDDr -&*wy"? P$G]ص_ÓȂy0'M3S^bzG*.D,Tjp!6%!\Hf̬v+uTc>ByDU)jwhdg32{RcC:ln ۺyZ;}R(NS0}A%x5C E@-VPՠzJ J;(5䬠؂fj"}~-S!۵^͒d>3d#$wOwYS`/ů*m@}C/J>,"YF7 1i?F=h˛ijh/T Sa)'I[|8Ѕ5͵$n J9!ًf7`YcJ1Kb( [oגGz?mS)hD\@A>RpϒN>ۢ~q~鉶:ۮ=mn3i5`T= ѹ{"oO`5IzW ~Wq& 3[fE4Y ݃h[omLX`z#X^U@MX83:z&r.>T<:9oƞ~aPU tG- xxWAtO>*+`9D)=n;`|^Wd.Gjg3`ݩ"h3GxoӔTCz|8v%`F{ȯm|E"jiA tR0ie Y$Yq2Rg9rL&ń0eu*{m8qN ]c^SoJbu KODCT>L>W1L9Z/ħBwݹ{ y$u,Z!s] Mlɠr-2J=eY,s(VOH'.)^W 5q eT MOndI[hD) \V6Lw 77|RN[B^ud);dAG"Bp "ztKth εI |n1E%qwWB=DK1vQkC(3iGyHNFL`v.8՗?u6"(N=$ \AS: ;6YQXۤPj0w4_'5d:D|67^?~)ԏ,kѺ`9zR8 ?Y -= 2ySB@ ] )QpV5ZD$ V5p !tufL-| \m,uZwwTsQ -Ϟ/@uĀj|[ClOqN7ٷ'19yIN|/M ./C~=e ,@\]$ʯADNnÍxkjipC'b ,p4aġʼ?4镈 }?= 9$V*%3>0egE-J@ꏾ>̍6o;&fg@>xxDoc){w;>rt@ls :pN~h-Wgwi_+EKԛ'/.[k[˹Dla&aU'0Z4S<0) ,5BkT.izRu?z;uk2)[P O+bgtEx}T5]>R}.x!m1 $SNe \+͖ w(^!l`L$Q_;ƣ[<Ъ=Fω.4TaJB7U;hM1‚2+6TɈzrfAף6UzȎ=]` %MńYc47:hM%°jŶ?I# X̎lU?\(s7{U9W\23bߐH Kq FiW̋:^mǒE^pA>wwLrG ';?YF'~gnD>Q*$LUs^ӜZD~PԵWjh5o/9ńבt"W4v.H!Rϗ Ns~"ADV.zV"zm|' ƈy?pO&3+2Dy`SBXЬB)ʁ7`FE|unSW#CP便&\1m YЊ++! B`?ֵ5--QRz&nje#mϲOaZ؛}׹c#b,׫>S5,RBH$kg뷞yp ;+0s -J8|j懍3 ى[/ѢwIҘr/x*H\꘧ I}]rV*QY> Elf Y_R ܠ" |{=jxç/j XBVʝMYW9u\ IJ^y`thRȼ @;I%۾xВ u+'O-5:}_SK!B}i43ƒ=/ۇ%@lO ,c7DXLHw$ 0%P)DW>_oD6 V@*k5Hv#_<* H %dJ;kltWx6FOҧg&@'X$ a}CS1g)%ADw6Ԝ=o2Pזy=shmxХʺA(FWy`1 ٰL| DOchׄvė^IFr$?O645a/vsf$̛x-JrKGL8?BL-"]ū=rk=Z C9J5 kϵF<|$V[GK4qx}yW;LK`ៅ~[0mB\LYVۦD3jܧNJ-`L/VרɨbO+'w|li=#Rj&]t,&i,pAaTU˶0Ύw.3y`r^G:Jc ؋Es0i!vpКyF iOX35 NX3ӨU$$n_L;&U A|\ ]UsSf U"zSRV!7GYHEmG| Ocsr^f4 c&bzb0K98͙:AXSEÒ2ƘVIJv BA (c 1mgzZSjb,yI{>'xFʃ 2JG8vi vxf %v/U_ H@"/_KpMBA2n:ysFܹ]B@cNF3Je='`eĩ,ϐnDWQS )4 2 N@܍Zkw($%Lb|ɀiX!(ڒGQ,UalRgAFkSrѽ^vh>o۱-xCHz@zUf1JU֥wؤzgXEZ°jO/*_w$gKkG(WIU‰f ̈"^.Kd$IsBz?=z7-t dz9ѽ7;D(C2ebuwUz-u^C.h#"r$ 0>'{6gp Zhh9=-d-Ĩbj!PVDG"&KYW:~ K@Fbdw<7uZyjI=6k,Z^3#I_^"ι ʧ9cyK^_ېJDe ܀g]f -@dȋ9j_0d则SFWZ1kBhT6nT =H4@eIFnW7 ZL0B'>^`zOa#wB x%qА\(eD-Dv +_WCY}Y4f?׿:N!I{@(~)ַBSHxrl6dP=%<!^B^AqGEܸwRwu^_݅Ld`K)[0c{($ DvFX-\zw| u+Hs+sk%R.л n]F?&  7hʩ.oC9)T`Yb)&S%C Ų,*zÝews8π 5W`?{uiYv>kՠS| ,i_j[Cg6e&.F cj豣=tJ>/U# }hVC}X鏢qOU3Wx(QJc'O!amE y ci՚ Q$m `w ;yC~Bͼb8Zg5kʉ<9Uɧ*Xh/ɑY!cB FO|vEݐ-" ӐZRt'zqS[fC.2Ꮌ?ՀYM/~HP?Mr)2&^6õ,"E |c@0WͽH=!d빈WpjR}pi3Uv qͦQGS"*,ȗ4|#VjRz d`"@NJg>vJX'e;4^ _Ctl x_44MK~ek-4{ר]L"2ڤǢIbz@fw7iD p8&! fJ>(2/Fn쒺FD<"ꫮA`,$OSqk$=ַ+ZWsnOfL5q\/WY8Ko' G,lZYs ٯ5X5#L_E![m L|噴͖+pLk/.U;ع>Iم]|kţpde#O /e讔Z}xbШǎ&#>JCP%A!u "BB;}R <=sb̹pQ$\q!c/h 0}h5 b Db gA('I_薏- fZ=uruuMƍyԙ,T&%53s'Vs:(@D \uU+{+(D+FlηNV"%.N?u:=bhl  ʢM=@U$ִc:>_2-.}윔X̝V|P%M;8U7/"]wB7ʟ\K n92mcRfX~ (QQI)iqf3kvp۽e/+n[p2r@{ j<8wYN`8a|8#Qu ب 9M1ڇFWsHcΊaZ,\SN{\|k]Wr;m5yk .'.k.}z$5-c,oPDB<1GT%D,˩|gf6!V\S8X ]=#O'4&΂&U(V*u&/Xd%#A>u-IG}^9ka|HW FLai8 c9_sXʷKԻFgɻG~ɧ/4*0 n$n9X(d' Bxnes^#%i I/tKI1cD|G 9ctRa%YM `9\5ENCN)-Q]6'(*JNzvP:+b5̚k'Ig1,r珦.\q]~ķl1as-rZ|I LؤnA\r 4P 7i?a!9E`$o]mAV<^DD߈Ao!A3i,fmAR.̫ħ+['ɝw_I2yha`! GR4ҭ;FvՐjS(0ɩnjx~Df(d >?ѻP 2= SLtÜU?/|o*G3^9cZl}?Rb"OЫ)^p漫) OG` 1e>6FfRv is;8D?Rc!;VWkn.,,2ugavA>K5F'ƅ=<aغxRgB>sVpEIYCwpDFܬ\x 3,!Y6ef4wdS^t!Ycgң%"s^G/\Uk[cvYUOcey;jZ+-3r_Q/@4U8\Ka:a.75c2oI{IhPm +;P݆PX(uݣU񛋎G]By +Cuj#1v򛯻\)AhԍRԯ4`ujPhk^3Gm T'Yund,Fg-48Q?cAE@d۲iPb1J|ZP : l!U2Խ{/i_̓/N m90xxrIEYk!-B?Cb UU ǚϓ[YOM>$JQRL O> z61bV5X*'kq%]q[O\&+:&*-}B^Ԛm/Kk=FblIyj3k9dFoJ)>]/HHxa of3mW!ٺgijb+/k`G7)"˰ hh0za:v'跠4V%.`oFl zr*p]lD:^!(aw 8wNqi)F1VO8A :#[u;#I~ؠ0 EގGTәP#D#U[&40@17띫4 /BrJ;4`:כbq~&c![B(A:&D fDFÈۧ9b3-|sIZdx5u!$moSLF`up;ذ?S%`v}$ a"7%G:koZ!$tTaW;Ÿηlʢv,,dP3(0'i&OӴèb\;e>=>Ed KK2&H@jF!fV~WID1fVtR6?rMeo~1#*j@l^d~TD^rFYc`mvSc6^Eʟcd"E糤qbd,$_ӿyʹv-U:۫ҧORCL)_E$C[CrRAџ/"u8}0mg'.'µ& AAM[ cg) L4QbwnfP ?0W]{ Z)F)]?i?Hx| z:o#$Q11W0g5ud"_R( $q1꫰_%ioQp37 nL 1A9̆ËJwtGøhqƨXEWr!fP`.ԽE8 mv$0&3댝h%!~< D٦cTigC и6.ќ(@O|7TbvaInƺw/=pdr(ǀt\1&7AW>5P*3dS6ǟ;o-""KnCc1M @v7RwȈ|_@.vP̵mP67lPzyVfX\l@ObMtL$7h|h8oa-ګE4vD8`jst+Jxx -s \vu9̴9!Y(nR}~py%,Z/:AwRԀ\Jwm~;tiŧͮU[c M'@4 M~  -~(*Ye1 /lTtQYQeƇ]0:Kk8e FomwQDt[e> SyInjK3y tܳ,~ M\~M?-}ѧ3jC[xA?D-5;#/T*I̓46پ&>^Zp" ijp?6K6,-.N\IJN”(&WvS bmF5SvG&Zn<>a^xuk1afY/?izj㝢Qlhli+AO-Is&O/9}wL\JR~A&(Y\"$@;sSJj弋&g=0 5̱( EϥاWhy a7%"hdGSA!xPGۙkzŨN 6fp\lϢbSI@ lz^f٥JF,U%S'Ui# } Նb<ˌՂx KλRb,nӡuE9bS'~5fCe'']htOQ*]Q"պ~._zE}s厸ۤ4gu|9a9vWObx?(k`]#j4/"c x B32Lf\咁xOn%/%Aa|Vr~x6m.Q}DVrLK)iX|ܼfk]ySO?*U.S`O<6<3҉Ӟl6™v-q.%4::N(#MQ{`b)U1KK p RW/ˈ맹jL#%_:W8Ҝ kX 5'# &a3 F5ao^ 7+zbj;*.Qg{ęC2tsKC؄,>'wJ]a+y-wO=. IC|}0z!ۆ }3%="mBݕ損~ôE%omM :WDͼ<䊯&ʀɓŬ -…8NhWƺ>([t?K*cR, ]L@))/G}KsRilܫ}XgcGy'Ha*S6ϓd2Rm_YԩP&^֊_j#VZdS䥱 uƩp-Ab܍Xw/Ep[t1a`~~;ۭ9@H 8vO-)?} ؒUlp1+qtb͐urGXQ^es ^=AKEn|} 1$[= ȶ%by2eWa)(UYPZa |Y=AS7T7K:1O>FT8͆߆>iyt6Mꉟ'B"xYd^_ӒbHI^JgdVL՛A4U]ARp)~3Nuyvc/ 6tEsفCn|1s8jb.X[6ۆPvur#QYۧrsxf`"z$ټDQdg/Vc8ılnM&å _[)Ţ@4[W'0cdwrUdǠgtaP\K\K 9%!.*"IݒjGu8}m$V&4;"#)jr}p# vm? 5f*{2od]14KN?Si5@d"$~B$*?kL#Fw!K>)RƩ%mzЙ<{ XO|S %ߓ+<9fKAkۺຣ'd<!Um²Vyt{;pb) }X݆V| On%a$d<]EM ?d74u!\ul%*/5 IUXzfjzE9/tѝLǻW qMSe ZDch虠Jц>(g'FC_v?F?Xp~!]rOیXL(<2u'(Ap<5i~)IaV(eO|LQ KC8˒0#5Å.8$J[,-)&z3'aSЧ [ :@5~w2--pWZ'Ph9#e<;Nh 7b+ .96c+:ƹEV eUMoVLHp0YGhF]U(۲TXtL 8.E0dI M]8FW >ŻN ]o'.ZE\̍B6L ?P/uǍZ^f:\QqB@6mviF\!BL[yC-,0y~-$d<#{@ װ?F'!p_d2R8cp]x*ۊLL:Kayh0c2soM\;S86_{4uGɢt$?\T:Xq^j,\ݟy~.@n34 1OjAזB ߕ>`%-`xS b0 *4Pϸ؞-CL#q,3X />dmRś\)}ɘZ<I7u ̩;  5Kێ6!MHgg&kVzYɬ[MNG;@ֽty4јJkw11zWi3~U%/;ndV܆Vl)2ݘM ua<Pr$. (2m 8O3|=r`Z>o"׹&SL!WN!c\~]G˾s K H=0|Og3M`D2{[&+B>IZ `Ҭ)sy jjNcOopJ%;ӶGޖUS=y rjG̞mjlDR,PͪU2k=,4gv]'jVtf1iHfW2V _b:j{(uVwIH5KA ̩:k~M Iu6~Xb)d.^PȵbAoȀ5Jk?)Z{v 6ÖLGLmBm lIk侼fXTm s@hU#XB>ovV5o~d!^ J!#'!vJkԙLܙS$c/aaH%S<'M>cF!BZ$b%Ccr֑5-XΓOz[; |"騵 ])jR$44jGEq;oC7M/@ےW}];dVt6-~ 6sA[?(}=K˕Q :E~W5*K \(BYh:H ve͠Š.b;Х0*vLr8C]r]{.ymNrbQy͜w"Z57XM, L ca8(p  ȘR5ZsqGkvh]XY<i f:U7&<ɫCiYK$6% F7o/.pdwS-gZ=YLv $ud䡦Jig_b41aa3C1Y:3M~#zvMZfDŽ}¡ `%Vud_%DXd[UscDp_rzm?SI>yP `&~9`ԇ9Iצ4_}hr ?Prѳ)s1AdS6UWE(VW6 Yq-U  -Gi>_CHxnV%:)>~!'ʋru<{/ShUʶع@īmo%džXTu-ˌ ^/2q %/@_eTo/?NcM#4a2G J7bJqxy h\W[Fs̐iGZҲQksIN[Ϧ5,01d2mhoZuz֝O L5nxH'ыM$ /߯":'w (cpغODu@n^lO.y._Y`Rl&t0, "슫y JW4_Q(gD g"U}jӑ HCDGI_ix+aB0[T NDU7?fx9] 3˖ܚfر?YSxWyQ6I\NŇYr=ѐ6dKV]hLs nC Bl]Vaz(Zt=> 33#GǸ;e>fAv"ULs㤚@l^EG^f⇸ xIQ3j6U9WdGP\7bxP狓%ҵ xB"չ,/.ht0g |Uio `m'#(F&+M毠qCp:S/0iJC}듻.Eш(B{wmyLa4wi>ı9?'Fy'Tf%LmQW*&REsw\E'B٨%gqq+3u; P2{Bxق6yDNQMD6ҙi2FVgU"dmt›5N;[Ȗ"ĺ:DEFC='W G@͵Z` hMcx$c`r7pWHNoeaUZ2 a/S{_65T80Cqy+ BMs ؚVB 2G ȝQD@#vk|i@ccĉ{eQ9XW . y4BtU.翟uo)M.,47S rH @շ%m#_@)ݐrJ\ `P] xW^N$߽x7k8D ij;:x Fͱ_WVxr -׸J.n?ESVT;ܽ` I"1ީ,A99ujvK"t{Ɂ#Z>{J*:N8R''1sN3Nlۨ] \ yvDvg>Ivj7SmYI)Ə0@ )U`RmKLEEa\#YISVA@Khg1%h&ha/ KRMO&N[ZHZt8bH^BH$[JØfg~h ɜXJh 5fOfy=lOdů^/.bX2RLx͌Qoa3n;*>Gоm\}pVw?; p?D H3 xa;bw9k QCx{lu~HK{ȫ[ǔ{& _b%V*&+%yH2 jRֶX* I'ƠɰJ2뻞ePcӛу3gtPóqG}{ F'8~K4N|ul|*9єh 7֖: 3haCTXLŵds|*jFL tnP:(\@V,\X"4fX^LSm?&24R}6C /=kȾ-ip?>","CmWZehw@'$ZU|X}UeW֪D[{j_c e.YFSz~$-Z7U?HHfT۳/P{5+^0[ VSɧpe؇MXPȚ!^'d xpB.X.C jF'B2v̕~}ъ(cĔZ~ qPݡXtuKg`٧IXޱ1F]8ߊ%_am<4y2k)FP'Tۡ.u/Mdu?H߽{M$.!<pYM@'(ROv`/K72)ȳnDa ,f0.ΰO9,v$f24_'qa7Kۗ;w5 7o}ۚۉսesLqeڪ?JS@@\VB6Mr8M4KZ^IX9;ac1V^W[!e6[LxxF/)đgH7ccJ}\4hVeFxRʺ{C[`-Se3p Q@2I ]-C6GSwCk8[gɍI q ‘M4jZ^b5@ }u@y_$tb^XӁh7^jZX5F@͗2UB[? >"2CM:…- q!DV1V[М>nqٓw7azy%"*C|0cni|Y!b Z}mJ 06mrvBڑ%罣9 0o{MֵPSWw> [J%]Ҵ&IǤ\te1GLqax r<`$U T[  s4%֣pJ(Zq%V}CIb 3> G?E{l?+`D4~OEQ}B϶朢F Mw{΍oG3w/.@й;HGo_qx_&~ʪP>_G_`{rI@>/V@;XuZyPHS+/8Q}MYm d<6d,FhÞX2M+ 2!~CWo^"p-sմo<Y,l 3Q!q˱LZGDe'cQ29An 9~sj:Y3JMy8%.;UH1){Ѿv]a]VWkc/U✚ŷ$_C2bIp$if>XdG.xaV@A߬ Ѩeqez_1AJ!9]LJ7OG&T--l{Aqh5=Z8GKnj`ΟfQELKD|cPTErd|̾ƌ̉xI)Js|"]6 MᾩP7Yy\; jD1@Ѕ=qaVj8n~=\T.FCX^ /PӐZ*#VǕf mnpph-v y(8'l*êXq.. Tn7uZNpݕDzT3kt:sy]RjrHQ@w|uЁEP2Eut}'֊Vwn|[丆z^ěnQ\#R԰Yn,ܻlm1R oQ:WIKNhKa>/X($TKStU_tE@h#7PHj]yE) o\qYHI! MRL7@Hg*(Ei/ d%-{Tv%ƿZ8-f7Z91xB [{%{1g:k1dFP-uS!JI/)UJ[Kaü7L%\/I ѽPlE;&|;憿= GCUIKt%A$-4Kk`1E9դ#,eA6L7*.&ÄpM ItEܭ;E\4&늿I^6%h{o<~Io <&#K}6,IbWyR?v7-dbԩ+;rr% sz|{m"R<\ݶjTK巢/0 Q7dD`GLMпu孥^X (+ ! u},VMaMu{dM85wL/X6<=G2"cEL P!"XCR g {)AF*!Xq9}bvp%҄s&SyX9u!5nD+FN67w$oeү2҅o"@39XN,~O J{M&ФJ'E= -B*` ST&Xu3z6taG& Ҧp3 ͊N O_ہ:$&Yݥ8m|ㄮR3=ِ )w `sSm LƳ~MuɜNp0!&D}kB?9]lٕWMǶ HjoCIcm"$S΄95mpw޶\gz [  @؝And 1T+C`d\ڋ5p'Š^RÉ^n[oB+"Ms5|q2OcI<bT[q3 eKqOAd1;oK,N22yՄ I @{)"[AJ"`\y YpqX+JՂ#L{Z & gڗA"b`iIS^}*@J*7'-52X}<ppOgV r=UN]?K GҐ\6# n$Y.H |LxL:ij#rM V~7Y<6؂Z`r7/'0ԐΠl|/!#:.oWhqDmw:֊uPw&PZ%wcL*dW(슚g/ "~u~"JQ<يw5V8)P#^z\YnaZ0#5'W2})pvv>~bǧ` 햋\[Jv(J.,ூ p`t2gM}Bu*Uf]n%NЗTϒEn)ԿʷR0\\X$:@ōW1FcX{᎛N +bNg{ͿDSJRM?'pJŻ:R$:}Q^fiCO\$qjMk`xܽ]v.6yj}ys&@E=EZd2x!/h נ+C/_i x?e03 ؛&~@'v%xwS i2„{=`2?fRd!$,2;.7!H6{38M7a#4“>?l Ebe*#TNrTVDmͥ38ePfY԰0WtNzT_ndApa&x+ݏ3UT]^[D4u'cX](ߠ?4ɟ%gkj'ڌ^pt}FYn"6PL8h <"P+p̄b^F%*D$Y#{~MDHk(b݋alA" wkf,f1y#ixz[{]%3s=+lo X<-5-߷D521Z>Z#]7_-MM$;E97,CEo}>90<<`bJ+Dp>I )d3!^;UVgZ|L%_+,TOȘ-{BmVb#ή ]'~ Q^`cpr[Y)rIGP&:ns t&%svYo2%L ՒOAI?GW [u/w .A5;`ݿ; !Űx_mP޳-4Nw.PH8 1ZF[ᘫl |Z'')2+yx FAA rR*p[vdnuGpxvJݑT>)&m)p>E7d3C"laD]8(̶%?yȰ /chJ:O՛WN%"VgUȻݲl "DF}Nx{䃀U}<<]ۀY)ijy$atn9_%Gi0I:h yGɃkrBUa+VyS2L&XJ{?\!ޠd/>WV :߳ۗzBw⡀D8K&/ۼ\?P}=kiӣQdȯo`}R_DÀ2& ҕu\-. g[7 M.1 퓨%xS0ϔ𦪯ȲcNOGm/` |^|v=iN:m n4$_R+vB5 '%U5\CE;5t1˭ 2A9>((2F/_K8s0ߜp̿橪jHL0$RCm&ojpfڂXN݌PldG8I%$m6ѹI9TG ]v!=>ROH%a;&?. m3>Q8I%kߏi]ig{琞:񖍬EŃhX;ifQn}aO"7KVϿ<+/JQe`Ǿ# j}#YcUfnWB&b K<x#u/H8uS<m9ʷfb˽e7Jd8HUwheJDF~txx k -"/1u,*ky7nW#P\t铵b=orL[|)*a $ p8QGZQs׻iAx[t%R%lġksh)AĄ܎'|QA6&wx*"!F9e$pH'8FZͣ;.c2S\b?e" ЉDOaJ-ORNGp xtb10RWbZčIK& +{ǏɾT*nbm, hӂ^[֩lװK. .!=ml.p{  JۼO앻9ɣF> ]얚ʁ0f{=B.XX@XP k+,ނIR}l] 2T/G~Z) ,TJJIEX }TPs+'}#}DӺQ,J@6FTZzxP5PZ|GCS_^Wi'ekcFv_F5TLt{@D@h㏦2mt?+쵠ߜ0pto1^}%L71t%@~$1Yy:B۝=H6C3WصW^^{_I6XwP"w=⫟f;i7B4b#T @!ӿWSS{yq O2vTp4cMҡ d7HЭ$}$}i&kZFJc\oS<>S/S6MN7q.ɠq&S6N[4y% (.{恾̶ ^<;01JS]WaAJ^]hkڮ#iwhƿQߔ`"QkNn/؋dց!0qWpwW>Lqj E7Qw-wC Nt;{7^Opp-!Mgnv|&Yëq3gNN~fgNsu߲,2!x0PԆ}æNBjS%tmm砟MťzZRVjVzq 'E. _dݶ8lwfKiBKvjmey{IFJ q\/O(*9kܰqB-"r  (6PoliY!C쓌'y"0 Cѳ1exP@N;ZQ r) nIS DMڇY.?`c+DQ;<uFQ ]θ\^5o60!_lÊ_i6;r=>EDⷀRx3H25=WviIX aB[}izt dsOk<3EcFy.ke=YSeˆ/ ,b.]jG'ܰiF_ q2>RXxu4rkJQ9㹫 -l̵nySčVV֙I:>Bq,e/4TՍt*{ldA}]ܔTQP_}HgœI6$b=slfg'_ܲo&OlrYYRrKCԉS> &ߠ.+B2&." 9C0tV:irJ+fV259fkEn.6[ꟴZ'qq@g===U8 |:‡,]ӏKc$o4="F| B&_?|JkJcĴ2z9ߞpi[/{vfUEǥGs\,*lW{ZF=4(웨%🰯(;FKm}{59f7VWQ'~?<`d>쩆!%[`ۥ\ovMˋЯ5jηl6;T"pD\g&dLu<|J|1T juAa%ԜwuĤę AD+5=VFա13?eⲉS8"%Wj͆Pc91sb֘5VCW?59y6˭kP`mF6&kt gES-1Ê{Gꃜ2{mЊ@X,;[<&pG.(~h>! h$1 R^|f 1sϭKke_=6 qLZ$~|4)T{yP}:6ZF]$qb9FSƻ&{rGǤztԘOgM㤘!.bBdi^PxÙ2^"xlB:g,:ss[AȔ X 4{ fߚn;m?:\dzAnS qoыXá À=@yrbx_[f"_j XrRP1p&|>U*?eddR%5&Kܺ;Eg+XJ gʧ=3m:mH[gM;vh](SlqW] =Xe)/pr =SkUaGk Jaл6yNrrcb>E\JUJ~oz!y\-_>9Rk!ۖaokD ȧ@.YaQ̝fvqbњvɿFvnڈ8j\2KTKY+4wŒ N jg9)Q;zJ: ɸ1 P\qӑ '&,JlcWʍkir%jr=L>֖ GH#r^hꥑvn6[׏4̑90GHiC0?$Bx]hiq >d3ȴ)N딉D0[4F@7SvE젺0y[Ik;s𥂉r 40=>Bw۝73J IFQ@p0<ѽZ?w׳υ*S\2ЕڪT;,A[k( HB =2 ((XjPG05>(tc{ᅪ/CGU!TH*RăvWW#XI. 1uI喙GW@^ǃ gB%AC >oԕ2Sy$Zq7{6~kkN_=g*ԣ9A\CW;WS<:㯰bq׍OP!.t(>\n3Mgs"iQ{C+xתd=ߞM#Jlph^͘Ҩ0 }\v?OA5|r2;y:Q. Qw|nĺg􋁼'F>†`rʊ2׵VA2™IphS'Ԕo";rAg* ݐ*YO`Kkliqם߰/4*4E5}(WBwzIa?u3nEndNwQY~6ゕ5̭&[.;]~<fBA:ȢذBUˋIC~rBB&x"!tUٸP^qQ%!)6 Ũ eބ0R!%gشzDrt[U 7O_i/vhz*YA$T1jhͲ liO3;Kp.볋F=_p dd<`F k |tOgK>i6::ių%NcЪ(#i#V "xJ YhIvИ~;!bl텗i+, X^ađ##ٌU2Fqg:e@c搝Ec>7i/БֽflC5"VP.[ʣ2Ÿf02V_LwOxUȌ2P^8GeOdsb,QNœ}Ps@|R*9:A1H8ǡݻ65̄\94UZ"eƞHHAp"ME$QzH;BA S'937^i؊5 {Fb}"7iŧ/_(0ahLBɐ+YFﵻnV,[}-Sjfqh |SO\钍 #ӻkԧ dw9TbƥA@}R KenI2"NU"'aK[WcOzEKV:h*yeL4*ihྦsQ{,(xǝ0wF@-Ay~hV :0UK+eC #OB-d]~NTe龒};oIp%6b9KûuV$#^fO084Sܡ0V[2L-͙8 1l Pa %'o<6e,)헑uxx-zȁNG):C \ yTiJx#E`\+1\4-wu󷰓BdVp2LLPt hHo`˕cgpGNK9v dwedm]Yb4ZXכ7yƮS8rώrrJ7|u:n6ۺ:yf _s>0e9l)4^2bZxP2 Om5],7^kМ,[<#d TԊHz#Ԗl{))gp]سv?U(̄hCf5bZK5A6AުO:x˜/AI;k" HVcNAnSOZ}P;ePHt D f hΜcjHDfC`vKK#'wE1,ZI$f@9ܰ]myCfk/[͹V:Zܼ.f H+^3onFd eO xs' Dl64/$bFކ VK?VwlзśvUaԃ*N/R6}Txk8 blTޛ0$6q-e/bwSƱ)u}L}ȸSjlz||GA8Cc78~j2\dE';L02eud:@?yKltO!QUD\oLNVykmcG0@{£6OmQc/apdVٝ^ M]JG|SIŊ$Ο WW~[z7(EO@#ݞ>ϳ±+tzaO'ޒäYW샠Й0DL4Eg(Rp"zL/R|g+}sgZ wELF8 3X;dV<:5(qr+Z)L pO~w UpNsY2Tå Ռ.10]?-eN4V-HL 2͸i"?+|V1c}Ѐ{boӹw޻Н3.2&o-f4߉Nw<%09zc, C>*Q^L[.svj6%|8c:oq,/| J5b9Vb=B)`„m<uԳ)QϢ >][ݿ|=OTW?I=X/.`śRl/BVߕaX+|,Lޚ;M (N Q49Pu'ƕr٨Uu- |dx zGs(ڧtmȾ HLX3x~|&0 1*n0'.z]&%>N 8&vrP2a+ S|^_| EM%"Lo'5[oo_em;-7F!`$V TnoVq- ?M:y)2J/\*3;r3κǒROPT2_wId,yਊqP43/]/VjK d''tOf)mE/SS6xwޏ-yTJA| ".(6e5 qƭIW  ?PpH)eM1 i9; |8k)c݄-=Q<Q%ϟlꝋW yct>.@jH7曇FdmnkE" jV Ḵ1\zXee(d tw S:%fF *2C=Y,+2DO`acU>.h2F`lrJl.՗p7Gl>9n*YUn 2[HD.*pRu &@uV4> k ƪ n>f>l{Xԍԋ"BJ5@CAwq~ w`@b}=u$n$2 6ccrU.:xЎdcQVigFt^& _Y܄΂TQ _7rv9FW&r9$\)A<[γZ~@K 'qйT$|D sUԭA>3^.(s}UOlT-_[E=0a"t s:v2)5VhwfJv8_9L-qv[F OB$(FҘqtD|1cd/>h"wj%{K\ h,iI#RKP?_< t׋I5X$|Mr>FPK4˩3xHaix"҆앯\ %@JSqOFZyۄoV6xqKe+1Ħ%>Bg۷ƾK@0xE0ءa,cN(CzlJuvå{pg~|ޥ_Zd"/td u7(L8[\nttԏiAˏFa |։8u+$(aC%#5[5QlÓU57YNa^=,CݚKBRlۙѦ },7uIC;N5nmnC@2Տ`w=ͰJ Vix2SS3!y !ꗫ/Ji5fdFK*]q̼[p?5Hi}!\IjPqo$(riEM^AC?B2Y-ﵥԛ?ׇRب\$31T܂%5' 5,i;&]2ԁv?pcс|:/ڰ@-4Ѝ`N2s*g*j` ( 0}L^h ̨p U^j:@/{!BV@͉QǸ(CH?:K7hs]RVCxd8I$Ԝ=y ZPrp+f1y^jCinY.u}ng&HdeAxf9tlE`hY~)Gsj F;XkG/ųzf}4ЄIzzRȋ N9FRK3c C\Sb]Ԇ:FT4d LhVȩ+,HM( }"'FM^q/]@Vͳr}K)lH|tMTB\3>IqQj.jiTM?.\~4͌kg"iK˭\هbS7}\mi zJۙׯg1nat;h+wdzFBև<(;298{ |c.K5\K 2-icSaBnᗏaQ} o~y9R,j2>re;~NBKzznʚ\ ܱB4XBA<zk2ujr ]&1}\+jg)%e'横H1Aª9 Er@.4}D@T}Jܧ4Ҭ8LkELV O͘>&y͘DkU9W[6Zօ;9bD2Edmr1H Є뷒 8285k%pe(s\7bE4SFvwd53;RؘoW[J .<$x?e;:ym9}HQ͵ʭ[][6[WJ}qUݶNQפ.Y EQ{Bӿ-YvS_M0aj[lQ+ 5z DvxXen3&ôQ@N82Y.NBB'=4oI/a2hu{oSj$宷_[m+oU?_>Wvd ツOP>=gi/Ws4\u..j԰-QdCgV0%6pg VyШ'qXYF2E =vKձs_hhLRBR֧7>YA3uuj :keX2;4wB8 眽?}Y\~dVRnKFpVg~Ӳ 6 3Ea) f6 jNyqIbhg(Ò,{#FG)LqGijm6}7pQ6djjcv|[Fͼt#x-2"G|q)=sܫ [$&YMsJ>< iĒZ{TFZ@#^@}HJB5iVQm.6i_Yt cP& y4ޞɴw6\ ᷍=/BQa Vbmc<@oP/\޼(9h,lo0 (!U5)J Q =n?(u?]C4F8z)x;HU~NTƽFo6U Ш6FF"Y'VD[z.+cQnulKIr 8ԩѣ.w5׹HipItzxO}Km_Aj~;V_ȓd}eعC{Uq%Z'VxG [:_\ {xszѤB}0 WrJt@(q:` 򾲸?kKwuxF}mN3װYlx$G;,c5*j:H9t>@L鮝ď*3fl?Oȯ<<WWQn+$ނ>Y4Vk3"㢮'U=`UGaz'-y-v%N e[8335/5%ղCcmrPr3a}kyV?}$4 C`uaM *O'hnqMݙgDؕL2wM7) _iX8P ˶i5@>s Hx߿mҜR+ȂOsܻ9Ы-ds/ڕROPm M0/_ȿdP=ba QpgHXxH -0Qm"[C'O]`[N+W}Ek/D#>n캕! ƹнu* g&&:f ig^l]X,'byɓ4b7_<']qtt9 `yOo޼\ ~Nw>Dj55Wm܍@Tf ESj- 18k&O\@!@)Z&њK.:m'lhA)Vqۓ7 V h5 GRи]S-d&,+|=+A]5WN*v<|'2#r\ˑr9R.Gˑr]ˑv9.G˿;,owB؂@{WA%jH`nuI^1bܠV.s`x-gap:P>?H/ .,cOgBl1 >'m?ݲ >+;2F#c92FCtu9}~^ˑz9R/GHzAͷOϷee!xp]^rkWK:q<@vո`AvaCw3+i›wa(#0nO7">V: 4Ӵ?!3&M/և;PNKfrGD-I@eF>Ro^Tv>I^ 6Z܁ap|QTJKãe5 ?ClN F|#IIhRR3:޸PkmcxvK yWDHi;rQV}_SB쨔pc~Q8" bR̮"nܷj -# M.M{6E#ЦܿȪD`* '95Q[q?'ꐅGdaL0$> 5ttH֊ ˄M"WHGs{1ӆyF`%XG\W*jʸZĨM[&{@õY $.OfWa]J~?}v /r6s6 d,1{;FsA"ȰH2x|Op}Em͓ȝ4Uإ"m0grVh϶v~KBZ%)&h}|^Fڷ::DKNvڀ>[44ziTl<-qC2eI;\ʜpR-bX#ح`7])&aIV-AkzuGx+N_Ŗ[&L8Yx$䝮O7J;_oo"9 RiS Wՙ'NbJDj,d%yZK"MNH(7D4='V{PmɗP,.X_ ۀurj&dp cJ9dv %x痍W+A%vmWqW^A 0#+BHh ki蜼 =̃0/ee"Jݬ°k-IjXfۭvqOF߄ڬTLjϹ{u2Wj AE8.ZDXrK%?_voD|K\;nϋ(pt5ÓE .F)k8W~pBeG5=84":%gpLTȰ#AOUkJS)[b@ۯEx8ρYb 98xՁ$leNe{sA-vi{)q*Qp}g3^7Q#UnjU+oOxs&)jOe߾ f7$~G''|I|~þe'-ŝ͸!nkpt=C.Xa) BxY۪ߍ)W.ѽAl#޻*C&.عDbTZ¹[U//Ch55,q=6uǁ,'Cpkk'p-1Cy8K]]ʛ}١xu7 jaRږ\K cB "\o..[pwwCbX)^&1":Y#&]E?8,PEާrOMf "O)Vc% \8ڧ/^У1"L5^-;3Yt{7EFk1G+i`|j1e/J2vqox1ObXo}\9_po̝h[xD.~זvu3XE ^S!~dztm3F=*4j|,o MLtL)儝S7ܷYi00n3cD ֌5` E"/d+xlpʣceۈ@Ο֨zs!(m:VJ!Z3aeVG< cb1#h,l~6ȸbq((_>^ĸH {ě/– G1$fUˠСa:!!( /&̟cAPTbÏ/18'HZ:_-גUhHt^*W]4\Ee_EGl9鈁. C8Jт$^hxTrq\Tj˓ ~W78жg s`T$5$u'ӂEzF3O^>&" Vh- ]5n$KtFd|"lƇy1&T?끛2Ag $͞sE爯(ڹ@śx.Ewle|4x.guW?Hm=GRdMB1+#%1 Ҏu*Й }T ϣ/C{z@lj֎S{3z}R rqxW _s' N<(*zxd2Yzab\ڞERPGI cN 3즄"CY+:m C|1O@"ݣVwTv>W j,֋t\0B\jWd$UF50nAP5P0 t6ԕ67Dߣ6A#{%3r8BlZJK0(/=Iig2g,1G [lT(^JfOX=JF'R}=YOS"V㩱kһ:vDҁ0El `v-囵\Q5bg %y;1h5pi6I24[rDdV2o97dž>iIu7 jn1NMRi[{i,t.`jӃ[njV8tb#iN3*G&E{Ynv  5W!-fޒE5 &\$z`((.iL(.%,.Ջx_F85%3w82 aqHkĻeKVu/SIK޿˥J~ǁKJ̋˴- 9:xv9:IE_snK#1&K#9Ovjd.t R; 꾢!vn7"8L7Ǵ^98 ̢)wműv%) KCaB`pL()<1mCҐAIN5/JsOS@~b\ k+)/GnwXxNdP~Q>viR[ťYʬM#wƆ, 0mdW/kn~ir1i\hQ|=Be2N_.e|r[,( sk% Xp`lի/wdpGvY)9Ԑhac;Jy{ܨ1Zx<8[FV)wj˼<{:1W_:]Kn2Z3sְ8XAlܵ^.B7L{59c]/'awqtQIvs1M;zSKI^oL:dYB IRIltZzRk7[n: ` UIs>)'l*|X8y.奥fӆ֛-/Wn'7YJL7N^kAfNWVr^×ˍdN=*<!4JΩyHZi[mxA6uнKɹ+7dc+.޸soֹ^ι\:˷߆޺|sW/{9 8dcJ|⥫/k3Z>Zcf1=ԷP*1I}K \! Ly~Aԧِ C5:zH"h $nx %0ժKZ5m%g#9VV20xZj Gks`c~.jPIn>թGՁOtJ2M^dd( ;o{qF&oR@7Y 7_X$ؾSOj~NtF\La72^ޚ;֮-.SR\_vpj3xMxя+A{e7p*ktn5th/Ϫ#FR}:޷ V[W\cbՑwy9KE% ,0_TXO[ʦZբ@*~ڬ:Mt{ CmPzBc DRr+v xw;x۰07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!1/iZ5Br.3]&VK Ut YZ