ipa-hcc-client-0.17-2.el8 > 6 6_6 3!y덏%!E/֡f? !E/֡28܎^$>rȆ-v2q+V>Uᛰl6#;`XS.ڏL/$}t^3X%(D 9=`IE64 8ِR-b5wD|d7pt*f[ʧ0qc2'\P1N3WC ?+^7<-C4k޿LCp#;ؽs\90J&W7AWbNKCuM`XVV_~r^`HnͪHd86s,O&3ԋ 4|Ut;r+#UCѲYkjLn8s8 0om t~"ا'<@(K;Q=\̛=?IR|3hAZ@6~Y&2}tſ3.KMF^|Q<~`bcZ޴Q/AԼJm)Z<+ ][z½JZ.[XFѐc l)=V[1FP]лCŲudž>pF7?7d  U &2]cjh    P Xx,hS(89: 8>3?3@3!G3,H3LI3lX3tY3|\3]3^4Eb4d63e68f6;l6=t6Xu6xv6w6x7y7$7(7,7S7|7777Cipa-hcc-client0.172.el8Automatic IPA client enrollment for Hybrid Cloud ConsoleThis package contains the automatic enrollment service for IPA clients (domain join on launch).f7buildvm-s390x-03.s390.fedoraproject.org2Fedora ProjectFedora ProjectGPL-3.0-or-laterFedora ProjectUnspecifiedhttps://github.com/podengo-project/ipa-hcclinuxnoarch if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset ipa-hcc-auto-enrollment.service &>/dev/null || : fi /bin/systemctl daemon-reload if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now ipa-hcc-auto-enrollment.service &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart ipa-hcc-auto-enrollment.service &>/dev/null || : fi # with clientR'_KA큤A큤fff7f7fff7f1c846cf0265ccb49de8b9ae65a2ae81ce91e616cc31208592c496b8530a12c4a277ebff350e0c0cc72b5c488147e52c2ecbd572bbb9f780b3695498ee515fd13b889e74859d63dc045aa3874384b870b74df350abb657dac1c6ed938fa44b6f894fc60c37a254bedf2a580831e8e8f11a9a3558f533c3fbbdfa7a415f4031fda1ccd7df80136f26c5df5a81921dfbcb597d4ad4ae8792a8421cdb0b8e9d3272e8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootipa-hcc-0.17-2.el8.src.rpmconfig(ipa-hcc-client)ipa-hcc-client @     /bin/sh/bin/sh/bin/sh/usr/bin/python3.6config(ipa-hcc-client)ipa-clientkrb5-pkinit-opensslpython3-ipahccrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)systemdsystemdsystemd0.17-2.el84.9.110.17-2.el83.0.4-14.6.0-14.0-15.2-14.14.3ff9@f[f @ee~@eod@d@ddd?d$(@d@c@ccۥcccChristian Heimes 0.17-2Christian Heimes 0.17-1Christian Heimes - 0.16-2Christian Heimes 0.16-1Christian Heimes 0.15-1Christian Heimes 0.14-1Christian Heimes 0.13-1Christian Heimes 0.12-1Christian Heimes 0.11-1Christian Heimes 0.10-1Christian Heimes 0.9-1Christian Heimes 0.8-1Christian Heimes 0.7-1Christian Heimes 0.6-1Christian Heimes 0.5-1Christian Heimes 0.4-1Christian Heimes 0.3-1Christian Heimes 0.2-1Christian Heimes 0.1-1- ipa-hcc-client depends on ipa-client again- Don't install /etc/ipa/hcc.conf by default - Refactor: Client scripts now use hccplatform - refactor: Move all server code to ipahcc.server - Feat: Server features detect Console from rhsm.conf - feat: SELinux policy for ipa-hcc-server - Fix EPEL 8 build- Allow build without idm:DL1 module- HMS-3840 feat: Detect configuration from rhsm.conf - ipahcc-stage-console now configures proxy - HMS-3821 feat: auto enrollment can set DNS resolver - More Fedora packaging fixes - Implement testing with Stage Console APIs - Implement console proxy settings- add CONTRIBUTING.md guidelines - Fedora packaging fixes- Prepare ipa-hcc for Fedora packaging - infra: Add helper for stage console testing - Fix: pylint warning R1737 - Fix: Typo in ipa-hcc-auto-enrollment sysconfig - Fix various infra issues - fix HMS-2066: Add timeout to confirmation prompt - test: Test on RHEL 9.3 / 8.9- feat: Enhance reporting and logging - feat: Check remote status with HCC - refactor: Use context="hcc" in IPA API - infra: Log JSON error information - infra: Refresh cache and config file - fix: Use LDAP for public JWKs - refactor: Run ipa-client-automount - fix: Replace legacy with modern Insights API - fix: Limit hostname to 63 characters - fix: Use UEP CA to access prod cert-api - fix: Don't create global DNSResolver - feat: Add ipahcc-client-prepare - fix: Fake headers can use org_id/cn from RHSM cert - refactor: Change to --idmsvc-api-url - HMS-2348 feat: Add ephemeral fake header to auto-enrollment - test: Run CI on Fedora 39, drop 37 - fix: Better error reporting for missing RHSM cert - fix: Fix typo fdqn -> fqdn - Fix: Keycloak SSO provider requires openid scope - doc: Add test instructions and hcc.conf info - HMS-2814 feat: IPA client installer and automount - test: idm-ci now requires local cloud auth - feat: Add sso.rh.c IdP provider definitions - HMS-2694 fix: Update JWST issuer and docs - HMS-2595 feat: Extend ipa-hcc to retrieve+store JWKs - test: Fix and improve coverage - fix: Update spec file URL - fix: Update git repo URL - HMS-2594: IPA plugin for HCC JWKs - test: Do not install KRA - HMS-2532 fix: attach to api commit - HMS-2491 test: Enable backend tests again - HMS-2491 test: Allow backend test to fail - HMS-2491 refactor: Separate GET signing keys - HMS-2491 test: Update test infra for DRT - HMS-2491 feat: Remove old domain registration - HMS-2491 feat: Update for domain token workflow - refactor: Remove env patching - HMS-2446 feat: New domain reg token - fix: Use gssproxy client keytab - HMS-2446 refactor: Move IPA API to WSGI framework - tests: Add test for deserialize() - tests: Check that serializing compact form gives a ValueError - feat: Add additional check json deserialization and update docs - feat: Rename deserialize_json to deserialize - feat: Do not allow compact serialization for MultiJWST - test: Enable mypy checker for tests - feat: Add domain token to mockapi - test: Run CI with Fedora 37 and 38 - HMS-2070 feat: Remove D-Bus service- fix: use new Quay org for CI images - HMS-1789 tests: use @podengo/ipa-hcc COPR - fix: Support latest tox on Fedora 38 - fix: Allow non-compact JWT serialization - fix: use OpenAPI from public GitHub repo - test: Build SRPM and RPMs on GHA - test: update packages in containers - fix: Don't hard-code inventory url - doc: Add documentation for developers - HMS-2195: fix: Use idmsvc as API slug - feat: update locations - fix: Fix typo in automember rule - HMS-2147 fix: use HostConfIpa schema in HostConfResponse - refactor: Use setuptools to install Python code - fix: store public JWK in separate file - HMS-1857 feat: signed assertion for host registration - HMS-1857 feat: Add multi-sig and host token - HMS-1289 fix: Remove inventory_id from HostConfResponse - HMS-1857 feat: Add JWK abstraction and helpers - feat: Update JSON schema from latest OpenAPI - HMS-2038 test: Smoke tests with idm-domains-backend - HMS-2068: Drop support for RHEL without PKINIT- HMS-2052 build: Use OpenAPI schema from idm-domains-api - HMS-2038 test: catch metadata misconfiguration early - fix: Move rpkg output out of .tox directory - HMS-2041 fix: Represent org id as string, not int - HMS-2038 test: Improve testing with backend compose - HMS-1991 fix: Tighten OpenAPI schema - HMS-2008 feat: Adopt JSON API error objects - Add definitions for missing JSON schemas - HMS-1991 feat: Generate schema JSON files from OpenAPI - HMS-1991: Refactor JSON schema - Add project and build definitions to pyproject.toml - HMS-1898: Fix and validate error response - HMS-1975: Remove check-host API endpoint - Improve CI and test with Python 3.9 (RHEL 9) - register: prompt for confirmation - HMS-1926: Friendly D-Bus error message - ipa-hcc CLI: print human-readable messages - Document how to configure for ephemeral - logging: pretty print API response - Reconcile JSON schema with idm-domains-backend OpenAPI - Add verbose logging to ipa-hcc - Prepare release 0.11 - Ephemeral env support with fake headers - Improve Makefile and tox runner - yamllint: don't apply truthy test to map keys - Rename field 'cacerts' to 'ca_certs' - Reconcile domain response schema - Reconcile register/update domain schema - Document how to install build and test deps - HMS-1898 Reconcile error result schema - Ruff: silence F811 redefined-while-unused- [HMS-1788] Add simple GH CI workflow - [HMS-1779] Move secrets and settings to CI/CD variables - [HMS-1645] Replace bandit/flake8 with ruff linter - Add infrastructure for mypy type checks - [HMS-1645] Drop IPA 4.6 compatibility workarounds - [HMS-1645] Drop Python 2 compatibility - Run integration tests in FIPS mode - [HMS-1645] Drop support for RHEL 7- Last version with RHEL 7 / Python 2.7 support - [HMS-1607] Use inventory_id in API routes - [HMS-1607] Move common WSGI code into module - Include os-release id and version in HTTP header - [HMS-1479] Implement status check - Drop bundle file, add more ipaserver tests - Detect and block auto-enrollment with FQDN localhost - [HMS-1472] Switch from admintool to D-Bus CLI - Add tests for dbus service, fix hccapi - Move cert parsing into common function - Validate insights registration state- Fold common and registration-service into ipa-hcc-server - Default to stage - Add title and description to JSON schema - Use D-Bus service and simplify config - Download PKINIT chain from registration service - Add mock tests for mockapi service, refactor code - [HMS-1485] Add --location to auto-enrollment script - Verify with pylint and fix violations - Use server role to indicate presence of ipa-hcc plugin - [HMS-1485] Add IPA location information to domain - Add D-Bus service for checking host in HBI - [HMS-1475] Add tests for registration WSGI server - [HMS-1475] Refactor and test auto enrollment client - Test with RHEL 7.9 server - Remove dependency on requests - Rename smid -> rhsm_id, drop redundant rhsm_id from body - Move API handler in separate module, add JSON schema- Fix config_mod(hcc_update_server_server) API call - Improve idm-ci - Refactor project structure - Add timeout option - Remove unused cert info and detect_environment - Split ipa_hcc_cli into CLI interface and logic - Add systemd timer service - Add global hccDomainId, use domain_id in PUT request - Add HCC update role and register/update subcommands - Add ipa-hcc to register/update domain with HCC - Update rhsm_id in server's host entry - - Add server role for HCC enrollment service - Fix deployment and rhc connect in stage environment - Test on RHEL 9.2, 8.8 - Add mockapi with test API endpoints- Add metadata to deploy with local builds - build and deploy RPMs from current checkout - Add QEW test and metadata file - Add idm-ci playbook and metadata - Add tox CI with custom image - Fix stage env support - Add 1minutetip and virt-builder scripts - More validation of PKINIT options - Write custom krb5.conf, handle missing domain better, more arg checks - Drop 'not krbprincipalkey' check for testing - Mention SHA-1 PKINIT issue on old RHEL 7 and 8.6 servers- Fallback to kinit with PKINIT + ipa-getkeytab on systems without PKINIT support ipa-client-install - Add support for IPA 4.6 on RHEL 7 with Python 2.7 and mod_nss - Handle platform-python on RHEL 8 - Sleep longer - Relax dependency on SELinux - Move keytab installation into auto enrollment - Basic tests for WSGI - Move /etc/ipa/hcc dir to registration-service RPM - Move scripts into ipaclient.hcc package- Detect stage/prod from rhsm.conf - Move refresh_token to /etc/ipa/hcc/refresh_token - Move more configuration into hccplatform - Remove keytab file on error - Add service with force=True option - Update permissions before adding privileges - Use ipa-ldap-updater instead of slow ipa-server-upgrade - Split server plugin and registration service updates- Rename package to ipa-hcc - Replace term 'consoleDot' with 'Hybrid Cloud Console'- Update CA chain to official RH certs with new SHA-256 Candlepin cert - Wait until host appears in ConsoleDot inventory - Always disconnect to get a fresh Kerberos ticket and connection - Add ipa-consoledot-consoledot.service - Remove old test data- Handle outdated keytab, autoconfig org id - Remove pkinit_anchors line on uninstall - Workaround for missing IdM features - Fix spec file dependencies - Automate ipa-getkeytab with update plugin - Move some files around, automate service and keytab - Update spec, add KRB5 snippet with anchors - Use more persistent connections - Add caching and logging to WSGI app - Add link from search facet to consoleDot inventory - Lookup host in consoleDot inventory - Regenerate certs with C=US instead of CN=US - Return shell script with certs - Add cross-signed certs - Add script to generate cross-signed Candlepin CA - Update README with more instructions - Require known CA issuer - Add WSGI service, roles, and cert mapping - Add test scripts - Add notes about cache and certmap-match - Add test data and instructions - Fix error reporting when global org id is missing - Use lower number for updates/schema so we can use 89 for test data - explain unique index - Add write permission - Add enrolled hosts to a hostgroup/bin/sh/bin/sh/bin/sh0.17-2.el80.17-2.el8ipa-hcc-auto-enrollmentipa-hcc-auto-enrollment.serviceipa-hcc-auto-enrollmentipa-hcc-clientCONTRIBUTORS.txtREADME.mdipa-hcc-clientCOPYING/etc/sysconfig//usr/lib/systemd/system//usr/libexec/ipa-hcc//usr/share/doc//usr/share/doc/ipa-hcc-client//usr/share/licenses//usr/share/licenses/ipa-hcc-client/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=z13 -mtune=z14 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2noarch-redhat-linux-gnuASCII texta /usr/bin/python3.6 -s script, ASCII text executabledirectoryRhttps://bugz.fedoraproject.org/ipa-hccinsights-clientrhcsubscription-managerutf-8447180db576ff79004869a574c30c14e6389aa415947b3e564e4ce215b278182?7zXZ !#,໇?M] b2u Q{LYn,lYyݕFpyQhVCA‡Kרnx}Oy> !v_ř+J_ϻI}Av1MpK W,M>:uR)?3cŕ{UyLJ.HZ{]wž0̊ȯXs6(y )8w_Г󂭞X-(1_7ŀ7`ZA!$}L+lb <"7<[/nEC#͕}8?綆|<3WyId[LcW,-c~"rb^ NiW (,2oBN⇔"iNR䦄gj:D,OTso4 =ЗIOF;upnU{U &h=3JFNFsΚz!-ac ;) \isY4E(<(o5-&^ۤ֬@IY>.QtFd ÂTÃ)k#fhBC>Pk"BXY}T&y)d6eQxŚ ? JyI t}lׂPKgs%w۔ޓ# VwHAMqR&rN ԇř9{Z稷L[g֑DZL*EŰ%REOP3O4m G"$sIn#dqoC [t~J꿃5Hx |Ծ[I>ĺ0{066h<`|}5kpfטd@饽»w^z^iGIScu/j"p)Dc;q__YT޹Rx(k$֟"_mH64|̜7iK5nn̽0{F|4Д4_XTAtK7|>+9uI=vUi^XA]4Kɸ+eOWfxvndc-#& t% ?55Byņ̲誢cC h[=("5#T.h:N!FK ,JPh\\5_÷.fA oR(s %%ljAe&zmF3ED;e4'D"2Ȭ4˰gzCMҒQNkZf)O)߭џů?Us0m"[[OFھ'd0'eF[N}B|:Gfua%jam'}O$?Oϩꑟ=e0 YT@' Yբ +!N3slEf1{wsDkPX>'/т>7΅*C&亥tvl){{wh 6${ίtJ+E^yx)jO2Yk;B5|AQ.Tǻ/s.'NEW;g 6HME>!Hj̼y<}s1yΟ0z XARwn/yP?m# s=/郉GPFopЄ %q8m{rPPՆ}f[̸Vu)~,gΜ֟^'t|zP->?;eg+_X)w\Dh*-.OKW+ Wgÿ[ס'_o@PRGk~݂J3*x)iLh6;so-z&ܬm*߸oy[/MLPd#iû1F7!f_' c]P̈eN{W{lå3!-Q e-ObĀ">r=7 \3ۙ2o=ddh6Q j|_[s2J7$  MO7ábIcG)蠋FiQ7р1GI{iJ+" 8n}LnOlG߀\j[˿jGI8V 7KQ<5JJ3iՓfOs#%I^BKj >kN,A7/ W>hpߦ|fdI's6 VƲ\F5¥fDcD=|54Gu:et)dQO|a2<$uG.e]$,kHꗜf%wEH&\p-ب`;4CKxrƁi!_f,^niv)VމJd*[ۄ*1Z utfy pkGM*QT-[D RFaA‚( "&x53JU)5MLPuн;|*YuZKM!4yiOJmImo?^!0R[0':]@d;QJW|YRȜ+yeQ~b=? 'lG0x&FE /x}&afE)nM0 ]=7WJS!TGum 3rwqXqr6L C<=wQ./p3Wl F2Hp<{RxF;Le"&W#jw IroKS=Yx3LL&I KwB~In,Fg<ɃjC4poKd+HK/'/nC p0:e4[AR|HnYyF.s8cPvZ$cU}#׵-O *8Uңt9CqHϠ3 C'ȽzU5{JpFo֐6rg첸N48c XrgD*n#>knD뇅|kUwq4(,:$oX%Y;й7aK Ձg!x 1z"W8>͢#ybS!opa@Wux|7"5eK;hV"ր>T}X3)ru<"/|,.C `,G,V!^z#;y2˿m2+)!E!u`q!> o>O$ +"2iUaE("[YӺDw6WW`pc! SmġW[@'hG.A-vs9V1S$ %hf*2 Gު0~@5"[3m}%aq:G -/ l(!vVZ'*PEˋMpƒ ޣ(;.&ǴE-ii=[W WʻuFjUĞ0{Ml&UyE]de}ٹfӝ*AÄ to T~:OʛZ浅GJJھĆXjk+$ۿ ZmWI!+*x= ixA{NPwF: !_EȜ-4{-$ؙxē\Qęx H8PbAqap[(}L`M Xlw˸XC*ž%[vۣ&7F.A!""PcTU=ew=#IRy -Y|V#{;f{xw},e`3f3AK ) ]._.@k&:)"=odQ:%Iд:^Nd=zWa UH֋bTMԎ }[Zt>%HHc8<{3K?eϟ݂.+(ͥ.˨ؚJOz zz{V7UX~eV; Dc?)nzP(om6hYlWBNd҅-v*KâQ_\z Բ\YH}T\i8a]ҡj73CflK77p_FkӱXGMCxn)=眮/c?.QLda`Gq3hAu~*twL$V'nsjT5ϭ`$7McOۯ[p/cv?/G.og$le tٹB6"\>eh$"VdvÜ!d_{KyKoHC[$# G3"r"?x5I܎J]t~rz ˂sGlL m3)ti\ a}%;ETODAJJV 7{>x;&[H14w ~=u"}0?j@iT?Oj% øX\єtr}]m] 1G uI:NLWоYE؛[I3m<<}¡H/b^)ŏn{bVB|[01UXf/~3O_P\ꎓ5v(.]枲[{pFJv| dHg@k 8CK~Uq9-IBGG* tL!Iȭ_Į Y6Xj 1?Xm *6QDkJU6U&DX"!1wF -$nl.4&t7,Uv 8If '~IߋH&w wXdq({)&:#,p FZa#/%9Å%2*< e0n~5eڙ+ݟ灇E[sͣFg [-f˜"k\KaK$0\biJBdIˀp;#Uk97t8X2zېF E/ˤ`ҁ5A:A?[aLLLw'MNЕRAʾ3K9c(ɉ '%|=| %BXܓ|7^`\D׋fw'봀6nE(J1ixIiI"h.I5@mBR]Ő A7̯ăaÁ2{nM5o84x4[}!$--2ԺhNv\pR)t:Ah/ pLkTdbNwHĪLy,UO'eV˹wsvsFX$7pO)]f. gEp}x4+!>rӥ`N#‚KBf'W+a ƎxfT敕 G`7J+vnM(C^G[Ɗ^S":B t33Kuʔ*@r#t6h+o#+C=J!Y4] 4T}&)# -;b0LϛW)6mFԖE gXSئ`Q4mGߕ_XYpQmċ{ڲ&y7b1Y-0:AmmB;%C c(+˹ض؄C\4t~=u= _G=vb$5e'v/n|z>!A)RMs `J|v ` / 8p }{i궇5kct.v:'ᦔ1%q]ę3oO9l?ޯ{e=V#c$#ALbO/=A/-iRG $0jHWNSmqQ4sSj-kP"L XEí[~psB7pӑE0K /IOr-&Pm~f>)5G4fgxZXH7xuɊw~e,4 1mylNɶ:GB!Wzee,r'n;MeçI6c]5"|nD/KvB c4qI77QpZ$ۥзo?μ,:y, ܀8==w$(pY&(,G$5덲$cX[gl€mעdh(}IdH,mZ-}80 jZ6Qw+^Ea@U6.`ltn4'P]c0sk|Hg>g2"aD:LHm /gs|^>lQy;qp wǗ1upYlxջ*x~slNJW ׬ d#ׄ/E)@Z6ȁX 4'M!˦ȈѬ/FKaarѳ6-/d&ErZ:6o:yŸC--蚤*Ŭ*>ډZ9 𞇿s]ZGG\1Tof oIjt*غŢ (Ji>a) t mNPٕWɔt6Rsf*n 4 |94}Gr`EV#M=&ׂ9R̟xp&FtIql~I',P}ό8*yʚշѠ;}Tf;{cri u_b@qhŔ$nXeu5h>8p`LC>$%Ԥz c !V16Ugnόb.OH/-h}0#7׼ZWW[pCTXSB̨s2=VLҝ l9ګY˚:)yJe*YdJXd7_R!1Šn.4-"D 9@6q6| Rë@Ԫ'fq?/⠭;WEϫB@<-㣏wSFՏG=\<(%%U]skhx_`~9+?(oY'Bza^Etrep cA)^"s il' bVIxhaBc4+ۑF܅ߨg)g062([<sCL^ᕢ1@^{UhǑ=8O Wztdڦ -Dvztu`_(ԀKjlZ wn&@OHriCiDLgq 8V)o|;1 㥏{ ̞4P5:>ekz&Ee|"(й._Yc-uסUG;6kD3B"i<&(9.˷N`l?hDn .'hvg?`--32 3!#/&4# qڊoۏdyf3-c52G8"F^˜VĖo;$H1=},H .V1}"&"Fb7Dؠ׮[i)ۥaNզp)lQ?mE}Տ4k8,p4-"Bt|;&h]@S2ph ⒨xl< $ BLhCcxZ Wfhqek)nx8&Nj1t^ 0Ӌ o4Cjk{G3&jIVx"2'4CAϲqP迸u0drțҎqA(ѿ3pƚ{i+GS~9_$hGW)FV(,D 79}ug,źLV|LxR7fMP?d`tK߃F |֋uԻd)ԸӹLP-:OV<;%-)\N\Dzvx,~iҤ^e+ϥegboQB1%hrAT([r2ӓΒGxˆU㔸'zn{I[dcb As୥ }-rE%/b4=}hGtƃ.!~Zڭ}yn,`m.:/YucUk.0^| ȭB:ɔpg;bf,Uڟ/4hLvhRR5 1ie4MY&|n얇z?3=D#MʅYk/7Vd^eF ]`VlawWy{ 0\R@~AexaC=q35raO`n_+灍oqZ~)l v-i+)veAKJ ֽh=C UU'HûbX l1ݟOAe0Lz/N@#iw 6u9 wTo{ ib{ޒ_g@rH5򚏲O~ǯ[7ܭ!ZSB_Y5H/*=]QΧmR_wGc\\ԗ6Hc$4E3M!L =ゃ \1o`'s)Y9[}(,fF(5~Qp t#xVxogx ?sǍOcyȞ? l` snA0+]j}_: ӄt8^|/URelȏGⲟ>e`lye)z,pI)0^wۆZl_4rCc1ML1sЅG醞o%f_.PU-![<@ Gzµz`a7)31xܩT Y'C>c$E1}Fs@MKkXI}ғvڂތ>ey1euYGNwiT7Ⱦ۽!8,iV v:ukƲ9K.rV5uʷ<#yAmSdnÒ*?cJKg)ƫΡx:|b|1$>ET6c~鎼"q Hb^Tv$` xw7C9kSKӁ9=ٹG&5 .41 (U+:ѻ+L "ɲ`m=b9l:k 1_ |-3O1a|IPufB$ 9"0Q`f52=kIoV] m:dYY [Bw 9 .R 7a3on1C|~+=d JR%08+KE[yq,[,`-OJL4"0 WZ)8Sm6fUF۝"%|)gcr~/pеR+|,X"/=5vYlba!f6$!A?&1oV(X6XˊhN;chtX,MO#\hpЉCv=2C F!1-o4O2 vx!G[n (1ԅ2-;$l=qsoWm#>䞗rz\J;>KԦP2lXrHOųbNzWJ۠ؔay.7bػ]F@F\; b5p{h(Gf@`(t_Ǥg^A~࿡ 2{ho7u0(Ol3t́}8?`x}lkU`bk&(:Ym 㜨ǜ@+$f},w2Jy\ iD䔇HfD u+B Ͻ'Wl J :$6K>} L5{b-CV"TȺ*/}\U-ŖlH6\dnC"(D+.tcpgC6rL[TvϦdtГa 1}5ܗpյ7tSxV? 10N n^@u Ξʵ2=[^/VlO <;5lu1VԀo<.r'_ EboPa6{I/x<#$YO_iJ1ˡ$28mh¿Mnȵ6!\9mE'27)% jRuL %f*%z9yNmP hixR4+n9ubAy72bG|loM,2tLuxP?,ѝWW0Ѐ| 賓o k3j217`ƫ)X!y Qz8f&\!D)',Aib$Q_fW[Ar\^ 2R%!N(@j!޻HC#.Nj7 WtuB1jВ=fq;w(-9c'wkD,#uJ);Zv||c-?Ӿciw5HS%.NXĥ?*46I}([(+MT)jہG V, jE{d)ՏQy@bݨ*oq֤;w#{aWb@-c:faS&a߬-N|/8ob4Շ0{BrBs=YI S{q)sRsIR{*H|\E^mJ'< K~fgNJ, AjL8-a-ZS60V e7,k%*J|\!"-Z8.%lt~c=[WcsJQbSEfj4lHC@PrGwTtEeyw@h81=pY`O*hF˱I Z7' FlGmLE,Z$I=$&OㄢQ{J }Q5ɼN:P6dL50/QFM%/eL[͢=\3gRoJS@ bЧs!,T-`$/*E s} 5+D =ݧFK2 >2cWyJ:) ;99 O<~BxO73&?w"Z_EgL8.%wm  &ivw 8m!;/Ȏ!W$BP4cq=Fp6_8_<A ra-+o`v u\oJTƪ3DZ] vn