sssd-ipa-1.13.3-56.el6$>6*>+rK(->5?d   6  <BHd r    +NlJJ 3J   ( 8 9:dGHIXY\ ](^b deflCsssd-ipa1.13.356.el6The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.Xҿc1bm.rdu2.centos.orgCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxi686KA큤AXҿXҿXҿVpnXҿXҿXҿ0320eb32e3e72bc4bc69afd1a010199a1c9b2176bf88ceff8ea56bc0b348fe73c1aed92a7c88b149fd3a955697f81efc195e82ae90fd7e3db91f9d81a3659d428ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903ff38b7e34d3b9ba462874bb7046122ce5fa8727b398213f7a8851779e749b02ff118723639c2d6a96917f174add580bf133e4c24dbd15a792ba1b1c4fd6f1293rootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-56.el6.src.rpmlibsss_ipa.sosssd-ipasssd-ipa(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonsssd-krb5-commonlibipa_hbac(x86-32)bind-utilssssd-common-pacrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0libcollection.so.4libcom_err.so.2libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.8)libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libglib-2.0.so.0libini_config.so.5libipa_hbac.so.0libipa_hbac.so.0(IPA_HBAC_0.0.1)libk5crypto.so.3libkeyutils.so.1libkrb5.so.3liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libndr-nbt.so.0libndr-nbt.so.0(NDR_NBT_0.0.1)libndr.so.0libndr.so.0(NDR_0.0.1)libnspr4.solibnss3.solibnssutil3.solibpcre.so.0libplc4.solibplds4.solibpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.2)libref_array.so.1librt.so.1libsamba-util.so.0libselinux.so.1libsemanage.so.1libsemanage.so.1(LIBSEMANAGE_1.0)libsmime3.solibssl3.solibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_idmap.so.0libsss_idmap.so.0(SSS_IDMAP_0.4)libsss_krb5_common.solibsss_ldap_common.solibsss_semanage.solibsss_util.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0libtevent.so.0(TEVENT_0.9.9)rtld(GNU_HASH)rpmlib(PayloadIsXz)1.13.3-56.el61.13.3-56.el61.13.3-56.el61.13.3-56.el64.6.0-14.0-13.0.4-15.2-1sssd1.10.0-8.beta24.8.0X6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)uk1.13.3-56.el61.13.3-56.el6libsss_ipa.soselinux_childsssd-ipa-1.13.3COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.13.3//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnu?7zXZ !PH6]"k%w+p}|,p37o÷G~"D-%d$#Fk=@[~GT G8dj\BhaEK^fpM27I UpIZBeztNG{WǟeDx/N(Zvv.xh Rľ;wruU.9i,ɑR'ZAWŚ{r+T[ݳ;qw<'#7?V %Ee*5JԖ/,q5BU>_dž$:ddE&"g^8vy1|P[ED?SV1 N}{q߈ .+m3XRz<\!K=Qjv4D1<Խo];nPs8sb- vU!Me z8]|h;m(ی ,uyA،&M΃!d4{-?}Őf -)1Ÿyl˞(0= c}R_6)_f*}qtP6 O$XɊtsB/=kmZBV ڊ-uq);ST[S߶=y 5ֹ&]jgdb ΩxS۞ג`N%gʝǃay\. ݟ||a^Y"|2`&9Gx 8BYuc4PV2l&ȝu5%wb1tG}RD ď4L!ɦt ( VӋ/TG2J3+FÇpZBh1}*1_:u{Qo*^S\h}E؛BȁAGj!i!oXiF P4#5S![&fG`oF7Ab8.pgj*`~ɤZ2gwf[X+rToQu&JFo-Q{OUf"˼+}ULqS.Uk;PLG}h&fJP8= n3[gu&ڔ|N&vA?>^b^۵oKO/@!Q7MH~F?7Z5gr 3weDo><7?,*PpJ );(]= ; c8΄{7Z2=rie<g}l\gdAI7 O~ @bv&xoX/l &v> "λW&݋#sJG~VR)52ҕUe[uʌoDK>_f8*5E[n`^);ck0s ԝ"(ŨE} n@ {@(uEiͭ :Ӥ,|cA Hlօc^jSWb,[&iLG!=R}|1-=57^ӡ,IS:B#/ܯ?r8ID߉@V3n9T=-^1vϴ&kӴln@ -)^G (ّ~dqiN GìzA{!t~W痞M a:X 6N@{HTQ<܌coza9џ7]䟴\=znߤA9zy--ޫOgT1[~yQbrXTy ̤! Ճ./c?#[E$@b),a1$I<" ʩ1 hPn л̬ԳT _Lc;sA3vlj[Иr+ձm*<ҪeҀƫʝ/^DJV(&it/YXv9d ALiF>A]`F᪎{=}F<%ۦbS-G'c*'~Γ|9jOSQrUȞ!KIm*p > 1lo _.=k7ǩ?!A8 Hu$Hg~% @zxݐ(X&*U V.h-G4Ԣx&Aa&Ghi3GEu@␙Y@ ,zi 'LGUmDLɹgUHf3?ش`{˨Z^=pWjYZDTz!r dxtr=^7p|8*0l.rj!uVYf^QqLz?7*,R#(Zk3LXwC{N$ ILKYR"1k KŰčf0QA P Zŝm"a\j8ox1L,oRIPFxJyAdjqu\+$$wѢ%(j:D^~})-|R@+VZ1:&{D9v~~+*EXj(Gq~@Zl{3[&چ۝cG~Hc1<7 ﱄ|W?.W:N!.Zy/ץdm5>ᄦseOJ5Cç1a8GAN9ۆ#q`3E;dՊsSJɬW{S-K>1nO<\7v b͡O: |]xP7x H]7*{,.J[1:}۟z\Id"U4dtP`;ӓlQ*e.WYLWDŽ`nxS8XBiߨ3 C%4hP a)qML: +$HI( T7Kewɀ4딟( 溜VCQ-0QSqme^'cIY oSS(]F|'רBHJ?}3>\7´.ҩf9U#u .Nr9u]`e 8U< 9ɵF6oQ%iqMN* uL9C =i 3XQE8~@( hض1<񀑛j٠8aDf 'x*Ӈ9FQ'}%E,5vґE3$Rz2|'`7Gvz.{%#J?tCv`Sx^mH~*,Gq&X$bh#!6OIN sF4*IAЩkrN ެ7Uc+L كX=/2жH?fEkCh+6zL׉:΍ç:36N ʒ,:srE÷]Hv%< f vEyxYÄ\7?b\0/v=. կwRl_ )N[hQx%5eEƍz(.J!1w$R:E; j)nc^j,߱ld]۟O-w[^V 1ߪTËd=8"]v*Kȴy|soh~$M%%7 BQc%n1/7MvC@"bOqXZG4>ݸ*6t?u?zy3\}imMm~6<Є b~WtѽL O{ĀMΤs`L^8 %|:n, ͡1.0QN.c6\<^!j7*n\Nl tBwz,}^Y0f2hԴI$"/#Рf9iYozTc _5͜ G8C[֊GuևL$hC(46~K= m*zU1FS NmDVVzN*OD\0->^~ˏz>&y$JEG3(*ͳᏕbe[>l$b2I;M*p0Ke\LJT6ofzHH*B_w 1T45'7x(/sMuViXC*fknjz]J0<ɞf0sVL`| OỸORJ(x{H_wIK=|2%GS, x0F~#X`vNwpXԝ(G4LEƕh0R˫SlE60 3W60{x-}A$h ;[C;$\xv Df)IPBkOe{,fFj#v,qPb١b፶[CR2XC$<Ȯ|jYRߏ;J-&pSi)GA:\j!YwК_ۖXa9@brиNG7|t]P/,ɫB<O}H))[w%$*)&'hIcw-g]Vk=]\AHEL:2 Fr6k}Y[T#CqOkq)t_~7%$Lrt|h# 䕄@1d!~?|֌5I U$O(Cz`MF9}}@g۷McĘQi*/ɝUgGݳ   d?~~w,.{U'd!qTf 0sAƤҧu%1뗨Yl]){d)b^+DY!5OU*D%q1UTt%E+3+T[* ; =vG()tUKV"y,o^'K>if2>Ul-uu<<8E8ee2^Ѕ4Ҧ,EBOrޅ-LX)q d޽I:, c:2~\T&QP_W4n5xw\=4 khV츉VmJS ()C&,XvGo4]5 `3T˂3'͂lW!/@qb7TS,l!Ex-Edՠys v]Ph퍰H$[60pK-񤋥?;4YWx3`xRO""n.Qx-CWn2P7t>&6lyV?dܺA:!}5-vϼz.YK`1jy}×ǚ1vݶiyzr:K*`VO79dSм mSzjEl_*:rpPΒ$jvwׇoO^n,B,5x븭Ɍ)ֈ?gRd(c^3?6RQKk'] iV B0dF,H{v|'< >U1N\ƚC?!@b)ӭOURhyv\%\gwg kZBrcČzK/:Q%}~"2JϐVݥ$񻩝pu\G"܎3m=t@x1=u(h. ߣȋd "ky-:u8ϼ{/&eqnpsq|}nj2orGPԈ9se>J7vLGxHV]Hq&,FA?tǥYjgb)E֝f(*lyXxw_ yh'21v5ei>MCX &:(խEofNVf");z/~ "n~6KhyR %u_PFIQ?47C(Oţ . )NO~-lErI!}eDdM% ׾-W5E0yTgv t3'h!\w/FER!!]ׁ9NBOTY8ǂZgޭ`pJiQT_.Fҧ'|ybAGIjb'+仓ѥv8R묊9^%; q7 k&sop?Tpik^2$K֨gdzIfvGeg3>D"1]GWA1y Rfh ykV]NcÇDOu H9vnH.7<ˤ(S6hTjNj\/QA@c3r{y;^5OebPw,%~kK:-x#c* WNmO:biU>=A&aX%gny_C:;Ħ-#XyZ;K?,cP|liwq+]Nr!ni>ϲe)8hJ1C ^+@G2t/]gE[ƞ2Le 5q}T. eJOڙ gh<]P&ugCFp̸L ,.)X/`uO4|.*G| ]5C<.bʈf)T w-Y/3rr;K͕/ f XYѮTj sE矄i2"d2|>ÌC;f*sMUEKQZ4x T1b0!2ȟ9VbH-ǎr!4" k<)+ `^N$tg^p #xojv?X-t! 祥TY=w 8.cK($xICY"w*r':/Fbo=q-7ڌ5tX25բ2"lG̣<|3bAQ:3[}B3FbZDnUko1FK 7ڕya>#AI5J$8Z2eV.7"=ŏ -#1.KM -+Ck**xyC4 !T_Xm`LU$LWwe olHK4߅ nf`ڼ=S/m_w[1",Y_Kg|UNnք6#&BzIjFmz5Ga!;M͕<wj{qƃx[AYY!rI3Kf˧r'U!V,#Hߝvc *H\PWcc87nE!ٻщ⿖ k8C*‰ 0nK\l>ay}nY;R[-ͨlb/9oo}*|w $_x}%BLw/X񯾦d;#:x6Ak%X%-uut]*`W #B4?K3PGp3l ̩ET7t4ֺ#@,gfDrN:?$q^? Jxf TN ;(@gDn̝c1Kuctyr:53NXu\y'X}.@A#'U˞]gVWvLaaQ+/ϗI\^R?FQ5}S0kYY cV'@RrɊ"9qG˭6<r {:Wȇul?Kn"ڭX:盙ګxt"aÃ5ʂ:/+;,^;Pu4SNkެT7l+*Wh0jŀ?98(:>ȼ\۝ u;a*fuOk%BmcoBTow;fOuS^Y4` \ y Ƹ'lvf-FL bRS9wy6L,@o `SN 6(hRQhЌ3B,ko@(`*}w;VMQGhAap癁{E+!\iQwXs6P6?@K}Ir?a gd^C7nFqk3V'r*drЪZ5vYqm^P4guW>u%ͯGm(`\?%`勊\߬4%›k Hb5dU1m_UUlOʾ~*Zu]j|Aox$6yMd\aJn.yH TGnLǬ6H"UR(5c #12Ub:LA(b-ggז,x,!&/G"ٞD8[)QĶFGRj/0z,JJ6Ýjd+Yk 0^DÛ5X|QT}k(10^CmB\i6 fpjaL,gJ4&i Q⍳6! 00h_oF)-@: %Kj.|1LPqhDx.Td#METޕAńC ]QQԁOKyEŎP)*O&FTiSR!6"Jy׸wrI yA6PYr}?.%:3)Mk#.S0YHOD_"n,j<ޏ_:-c=ںg BcNJ 3T:qN`ɛl- */kroKvaT4~2O߉m@!U#C#JZ@FsU`ރ 93]G}tB wr li'75L3npjRr>_`;vxP'C1XTc`t&c!)2䠋,&39q^Q }7 58޵Ͼ%%Q(Cp''-%҇_`vckݮb=. 8s _ܱFz,H~[8&8ue16ъfI1TW3k u}Oڔ TvUI%;4ȿ{(g`%ǹ":jFNqF.mF3n2+̩~X 0̽IOa̢A%8Q.4C˾"JDO1UMjdM,_z[^&5>FH1xC:S_M-]o2>[ʭÃNB z]cwYKtmФWFJĮi PgqAV&,+@"rXuu_ݔ/!#GPF%7Wt {c:AmzrHԡOwildc5^T񒯇ldMmN*cGk/L4>8#+ PgD"Ý_?0ܹYL%qH;7ˈ[֕B:di/]Qm9eh`#ir?i)IЕՁӧ{&2ynՑie~~uX4$k{I1E՝0hҗ)B@e'jI9}9bdߵ"¹3,Ӫ%:6GagN-]8G9EiٔR& n @&Cy8f%[l5ΰ[l}T2 ZmOLj:O 5r:(*P\ss PsB'ad~xGvAj_?[@<< 8~y9P]o4jB,hVD,0dfR9PpLr':׀/.dŌN(aY\FǮRcE\"K-;UFd<}='.VtspJT4؍mK0?1aL SP\C$u?gG4ىkٔNDp6;܅(q!aa[%;> (;wȋmFM>{mW\[&fLH0/|i&* %c c!}\~@DiL`(jI"J+ɂ'E3(faa %v0]Y~Hd5fdjGU!édl@&J5]Y) wg!N=^׃l@cܻ2T460v=α??u3hugdBwj=$q8#c>rZ)Jnz@(/屮=+ֈAka?5UͼgC Ǻ^;oDҷpܞv P3?A:V<{ZѲ"x( \XʘO6JkF'O1ycrdA&Et{Kf"l|Z 2&Rzj(D4 E85V˼_:è5,Fnj 8a0@ɋ)]g4X v_3(\A5yG̹ P;H%33?%An?Z޾HDH-ءL^E 3IVF8},f<Յp׼eL, @Lk6gOL fAQ}Uxhk.EP}Sɼ'^wM`l>//6[S)ILxnyau~*o(?CW)Qj"1`YAWF6VyI#>"h+-ir?&ZJx.v(1upJy;B͸ YGY%k]pPi:U)_?З1K9n;DαviX;Fcѝ89Um w4h"ϫ(Lĝy1!r anPy }0֨d Ck#MQ_l֞ tY5lS(Uqz6mLGbr$l:pK/:]:Ά!V$Pnq۔s}$ 4LtX# >j!Uzc޷g}K@wZRs3&Lo2qk0Vm sznZ +| %E A7"'٭k6|Y\ځdUdӪmQ$b2J5-WaX&H/A9r[[ VD fӱyW>jVxLg I:qif=# ;nXU.}$~3˻I򹂚+DWGNLZ܎Js8bWB I]XR|k4J|L'Z q8l-TL")1q$\Xu@4̈8U|m+0at<>gЁʃ&1?8']ȝ(ؔA+6U9n5Q2d45Sfr&=, l8eZYnyy}dl͖1Tcӻ{QOv4zEnlk旼Ruq։2RdX3*>5hMB]Wa)m"\aK&x6՟#roTP;|\=Bh>Gvg%H޼(qN/mh都cv4 YMkyOFPǿ!T.]$`(`7l@a sn,pp7^x#,~NIB<`6)^0ldVӤ:s+ϾEvZ\נ\HXwj9 ^4f&+,k!xCIx2Reu͟%>"#c~=")GJv`ྐྵSH~bi= nآ@W'|6(Zsy\11ƁS֐a1jT=%胣oa]U υe!] w-8KUnQlf9طBrF [,iGSMv=ɏ1fIq_dmZh3E"_X,h2inLK11J|Edȳ` ,A/026Gx\$^}fNGM|.zaXyA{)A&-:`) +38$yqRiSH-UƜ)3^ɩꑧ@IU%:2@AyȝfOH:Z.ȸ6NZ~ՒYhZ!a3k`MHd |ލD,quJd KxkN0v 䐬Z@ ݤ E!4"|n.c^c-v…6<4=o: x+K(;fa{Y*]*fA^o`p xv>_4Ͼ3&2,%if`$]IP hf^p#qg`ep5bice(ՠYg4sqX jpW AfMfRrW0КC[ё}.0MmeQpn&[PTې}[a =uUA^M'tmcKѴ$_-G 7Kjh Z o0arcX]-N9ao`sq>˕ڮKY+ԒTė:eu{5 D{&Y |R\S}uFhB[2sī%=s,pе[AM`Ym"n+0 ?@}qb}zbGNȺx 2[x|M@ }~(w>,3HIA6^9ǻ58T2C*' W[grK,Xe`f|=uqt{ndvLٖMx9$8jf&=-Zj8yCfiʑ6G^zf!'tͮBy`]KsVaWF݄ ]Ef>Ewo6!U|U!EC5K6ROpDF:pl""D]+Wj.-6tEs";6 TҀ4T_?i"xWakJPvP ǧoM LUO.D B%>4)aΠ=[ AM{Lqư:>0MHjql+頔xhP)ـ)uPCbmTRv]ˇI" s}Y*/~THl@c#192fϨ3_-9}>WCk/Pd+Z1bd}^]v|e:d 6}?] qFfH+6]]27U^vSÎ#1kTܝ-KˉrAu$i_[ÀNh '-@_25IƈCu}e=xu7⟞eVf{4!ep s|LLK؝D7S Hu#Q[($KYJ@F9yʎq!+[4apz(zY`hmmg*I`758rP:D~z-݈!$hVnlRMG -^"jcV" qQ 9݈5̷j j^Ԩ(MY]IiVq\au/Uɒt#*"?\Ξs*{v\؟fQ(S.$ZF[H.mRr&6 )}ՙ{xWg)6V=P"a˒rݧ=J$ 2aB_yRN5<$W;4&Y2f To_tc-X}v{NM1=2zb'Br+w*(OYǤ]ĢPd^_,gPYa -oFN׊Ω)mF׋:D*< 9QjY,|a4B^Z:l[SgH1$m@9pޚwJp1T*0qlN~tJԘ7U@+ ";=0YxA*-i [kc̷jA9[[iS,[JW \M ΍FNwc |t"5z=JpgKmA OIōM"dyG<])YX쯺cpvi o&Ն@a <݊-(|Bnz;S&3"."R"IA[l|c穔H/ʁfc&}y(2s0U,*@uL[Y/Ck -5;/:νhŒrF:j#D"B\z=?&/A3?{[1W|5o'O2 4>MbZfձoritYKFLN~yU^-Bj,XJ nӰAZ]K&lN's ^,dQuGo+p{aWet؏rxV զ #)w_g,Xؖo2nޝ|o>\x_xv(W"әP.|^df <_ChD2cӱaAu'd"b@E"3ߘFQ:Lx?$^2S .M\2/ (.&Dɞ0CYSY| TkHۓw}!8ox]XV2ɡw*͹,O[n&k~P{|xыCӈ^xN qXm:"7bZ̍40@t`VʢbM bCWo7)KAOtcv5ٲ`yHC;P1'yqкl({R_L䒻PcNr_ADd##T^y&9+z66!ދ:q1tN>S뎶z)4ZUN;O85*Q_hW>vYpϻ٪r2YlD1YqY逎bؕj_KLA >ѻN*"dN'`deĄ{OĞ{޶vy[K@dLFT=w2i+YQ4!uǓ+OíG?4J`ovQ73S`Vh09cquLk]%4=PH5Cѥ\&`>&fA1u zʺ$rjJu+ݖNdхj2~iO 1`GIsk ) k}$CBOK&liL}o"?-uoh,=`3 KjGl=K[nY?[7LA;փ_0UE!ķ2;Slb-<}2RiSiҕe(?[`_%'t("50rGDjDAY92)?};Y U&>8 ]VZuwq+ɻѦXo)kC?=6}j!N!v %p?0O*>Ƅa ! R+WCkI8Ćz|Z2:1Np| UvjqggW"IT^o&PiUxZF 0}bEV mq mg'1A3 `os;f_8Q=F'o/$57Qa3/kDykyyFNv@55>v^=61: UuH=&FDi)L'6,f02V(̰;*xi!ԌIg)uwAIX&dp]p|dV!ڟ!t@$ƿV pJ^na)_8Plc/}=}RUyf}6pN #}ˏ=Se3CȇMyMw)0)yQT:m*)G|8ۗuPdr  shXg ҟ/rx.-m97/]yƯp5fC.d%h%tN 'Px彉;Ug9nj+8.EVϟze".㩄 t 13ov觸#lz .հZecu=:ށk_nJ (Oܢ6/ƤN|,lzi p@qs4LJLUX{0FK8sGB-ުy"]`ynm=GUB)nvPin= t |T J@Ơ&iݶ>Ѵ.Z#`ʻpH\Ssvy8o"/jX> $C%G?%s_ԫbxF2#: myd05i¦>'8GvXl}0Qy}T"$s-̿DŽ ]+spe{R!0x iVHL CTr"`k*-hSQ`,e#^xlybuuɌNݝyI JEzh.Q O*6QjhgcQ(KFzgH^ VLv}:YE=S{ݢ܌;*Ι\gFފ`wmO9as%hi ( :Tx?̆Rq2KKE(&pԩ..?G4L[%2aUMopU/|>%m|z<_JOLm{"62&ݜ?ڔt.h2VZYlIT:o]FF`ja蒅F2`uϢiCvz6G "7)r/h9'j\ j'Iuc=EcT[^ӛ&Գ]z״jLp1QQtX5F3oYW u>svuEzܙ/]D~YU }K' ;iQ"A9r7:XU "v(m'7:zyJ99q^YLX[ <¢} bsnxXFl쨏wle.:#'OJ jW7Zr|aAa< %cT^&oj#ɥyh']E\҉גSCH;`Q}<[ƱQch Q;M5hӃx-{ dL8U]\D սoSLPˠZ :дE1ey͘VBY;P \;5~PlD!cw#m0J @Q#Ha% ٽ;kS.uې`l:Q:ΡfZ+q}JtbxtdyzXGP<#"Av@Gۺ{x^cv \bRpr5Kg'..K* z։eka\J%⟯IK'C/-tx# tq(B)>[%@d]}aNV#9uM`3 *~V_b9s#)Tc@Pv&g ,hKRjXu!m&}_I䢑`{&7d2. su)QbL'ˮ|Oh)p׽;yIUf|o}X#{( {H9+Gϧ,Tz "p߸VѱV#ُr0 8&i4A3qTdk8f}ZFr!ۓkA{13p)֎*+1%9)W j{&©C(NbMw+eԶ+mwc1DPuуU .UYg6c[0pZb2$~a[Aŋ]g8RI-z *WA F J@yX/k+,F6Ā^=ہ|^A&paw6G157&hMwvis-}iz1ͦӭң޾(êNgd?:TQ&T3ƸENV :gT@l"Oqj0wAq W:<>`Ղ& %y]iG2]gIѮ3ia%Iʓh8[瓋Ď0DQmh:Yo| H>k`-}ĘQ mG~'`^^ҬouM~t'B;]#/)28A# 聾#F2~ `uFc*RޟP=,O۲u*{d#YcpaQLFZ꘮ub8tVVnIF7Pb ,ucN(!$`ӳCw7wS bsI ??Hi]@v{os [geI)]}ǂu461!fXygC?iP g7KB( :҈Ut6[U]»ٞ4 ZesL`1C#2 5OfUg'qx/Wրu%|r ة"MŎU `U܋&n)d1  WW7hTf[|d<6^ݮ O|v0E{{ 6HvIZèkCeۆ Ut"EꝦ:\iONH@ "C(R!4 PطMrTw*פS$V#Z rԩx |_ahCr0_AvT80nek{b0b<.I:Pˏo.O %C@A!GoUoSh>^>o!|إ>W4 g|Zy[Kw/Sۛގ:+ˣ)^-ɫy7GaXc 'K}͠`j)yâ ɺDD+rjUb'v C6l[j#Yc6U!@7Pu,o@73v9Hu G+$af@2=Dtu@nZ|u$,c2c'so**% "}+:CU曀YP%teE┽{CxUj} 'X2쎽9UwQwDF_Q.C?Y _ 5Q}~ResSBLS8o+yvOb¯)sHyBVR`4Zܐ4bRdv]1| [M.OcP4 A+ԉSeksGV6K>#MXprqQpI{Wة\4:M,`۸Ѭ~bt{FtI* F +KfFk߼xNT7M+}T{\0Co\W8]eU`n4U\,C A"\<۩h* A-}Vr ,Օo,+7^_'Kh9:`$^4ҢW| `8 G̞/zPk&w٦;6ZP|}9ퟚD]޾4B38B&gFg)2$υ+;~@.{WH&xe1^'>}q3$NU {F_3F{+Q#ҥ[AAh~Iw.7 ]ReD,X@kMm7D@0T9fLA/`8idlK[9%zGYϘ¨6sŹ>1g>hP4&XS#ZEoaY98}Kq9MމAO?V' C+>< &"|\NνQmniJ;; `sM T2}u[׌=JʗAi·Aa46@hZfY;%%I ֳLMpb(L[PjSsLp ŕPĐM;[{]NArr䨨\nϜ!25t6~U|Z{deh0M >? 2l$zK1XgX5XW*'ҝ,'`N Me17:SpIT `2 iWGʹ=nIaK໅]DB$^aD?+1qv7GSn399/D5"_u T} )׏T=wȻ*H$u^Bz#,̽9~쑮Ƹk4j*%9ONJa!cH*U*!,T5/ڝ[alQ2N#,O_OGnHOp$Ϩkq$`y'3+;zQCQFkzsU] 4(z!$&d/`N4UHzF DtvH+pAXE7$ۼxh59]CA7h?$i@_)YWE\):D_"gx}:Ql7NζQjnXD*LD|\/ M>C /5Tne.seʰ ԏ'~ ͊|L%rǝǷ ԂUݜ:WCqmrڹ#iVTf̜+3>^/CaǘYASަXQ9FIw#rˢv!9Qρjj sP}o)WDxL <MgF$Zk : Tp^V$|Njf7~A"?\JR<^خ(TR舋ؑHWgH C`ay6 F¡n/1 E9qb9YN9G O_뻡 Ajdj5^@@q\ W}"e(|׾)AaV*FS`nq'M~RX^ux݌`EG*֐a7tG b<,}%:`}ԥ; 3UwNҾHOpIu x׊Kךin bFw:`ci2y ķPiB3j DE/[}?ՋT fT٠fjJhMB:X^LFpaRH$!cZQy6*ΜUYb*4\]z XRQoZ]g>M`*K`zQ#Z4ԟ)EY똑r0ߨ.L1VC wiWp4۞ G}D{0ڇވO8zVùaeѱ"N7?DHW;C6#gQIo]g(@p%. I>vspv|'暼CmU{axD %L ߯|gXwtn23c -J/$Px@;K{$ϲ[̿$pbό y{I5M6M7ʀcY&pmbF3a.C4&ɻbϒJ+\{KDnAÚ# |W%z*0bNЊk]lYbܸ 6GZbhz|;IĽN$XtC9u4nmE˪ f#Qag clg2Yp1`'EXڷ)ÞVvr%`^IđDyq9gS">wn=&V>U>,щR*ޅB&4j|K Q>-рm[]x_ cHMFXrkTnstLzS,EUgj(z;&B9W$V[ytF+-eoHP 'l?F w 9(&8'Ci`[p̌}t e9H3 hw.0n Fy[.?(!vUTF %ַ,Wy #9LS2هb1 4wsP,3,:SHvP`|e//Rp/Ċ`KG_\{ [fB.g6`h8͐m#rƫzJ@hXK_XͺV3*ZclJI=N,_w/ i"vvPސle .օP"trR'E% >{^X0׵C|=P#1pm6nNF 3Ne"^ٟ}/񉻣uP8ɘSbbj.n譙J@="gv9f>x˕ LиWV$B~++O{qӣ4HJ*\nf~>˧9tB뒦#ҌJBRԿɀVqђ&uX&K#yɳ$J5w8=dmz0MQv\t V :Mi^^:f,% B$GC93S穠y>`D<`PyJhD,1B<4ZQ +5iUqo"iTԹxs̘ n+U7Aaot&}ل~ͭ;T+/TRU}V#ֶwҬz(65F"z@8-LQPR& ::85LΦ4)M(,iT,er?418Pd q+q0!<_oD>LE=MKVs11S5sfYo32oTo4CH0e =bX b@*5?DArj@|Ք0KDC#>Щӿ )|džуѧD~"ˣ?MEt77uxJ>wYas6䜧BNLamm>)E6a\jכ:0 ȟ(,,k-[g+3E?rJlUߛ+#N4ҿܢdO% @|xN>gͷu~sO\Öޛ<%fhw^>!bDVOϊ0g~͔M诊)O`Y[KN1y2P@1Q2v!s/Ôd؅޸&b|k#@9L‘U_ \ $^ m}N eZٍNSہ HasWpMy.P< ~K$uoWEُrzґqzjڅ;THn5r .^,6OMC?e3CVA޻-)tf4>%_?< 0ojz^AH@Wݖ4XKĢMwʇPQ!nfcAZ6=\Jt.z`4mnS㔝ŝqr2˸eռ=3#3sʮj03iIW30% ̷H7s'N-$0@dm|}G4 UZ}cUKM1֌#u-fj~ru  6\Q!~ecdwU,U/Ref}Ȏ"52gE<(ؙᄻOka'H D"QOdjc[oI e1^Ш5XŌzor?M8[OpO)}w8A6LC06yjkz LNJ-+24qu t{7Ls ` 0(8R.l*-76`BO qDW dV^e&U#.r۲'+S <:K+2=hҥF] u4ڢ !|P*2 & Sq* 5R`irR8vWt䢏[*N9zPs쪡o'z1ї ˴ȿ ?΁ yC+C䧴VWo,OU3P{`s)IwجW0\3!Gej$:¬L͛GޣY*vda_%~]ٶ3eBC5]j0S?ѕcU-zi{#ى gS|S%lQ9CoY]/Fe\ՕtNwn=M,-Ȁl5LWroR\cyد\$A]D(W$R@1ql?{.ɥM96y߹$ߌ}H0+ܡwչ6%wnR9>He7a.';$9#Lq`s N$jUBM-1vLrqZ~Ŝ61Y`EQl 2 ZxTtO1ǤAϗ{ɋ稾w"q26zrmDY?c)!vlks8p>"3m^b4T [ S(zV ~m;9~PD1?M0$ ׽ kY0UGqv|䯧29 Bݯҟ"[|_BU0F9(3)gwwH|ƃb竽_= I3KrPEԎ4N0x"Gco־CDq n))tCOe[0Urk`Ad"qp""i@gu![vu |BbY18#&ʐb8Jrq)`ŕVn+iԈSBun"[І/fޜu?`h1L)](|flԝ`wNX][WmJ%TY} >eXG]` ma}HMrV=Z#% 互L쎦IoJz&Pz ;/;T9Axaft zۗn:ɨ`XGQ0t09kj/pс>#Օw22:i+L"0g7kΪ1 %A{ɔ%vAd\,I 9e]5O@H0D yewϏʴvE 6 C=+zo\}%8 {}N B\0>s Rz|)uY8!~02wբQ*!K^7sKJ^ QR1rz q"V-Om(}ퟕw{>>0P>O//8ѹy_ 'k~jVsF6Th>\XS7je;y$} V<,̍F6[b'~+K׫@wQ[ ]WDZZs-8i9VJdJb%nl_s0H+_!my9$sVH5L䖃eEsdpZ^Tċs\kS}UwcyG!ѢmT[:x;n vqVDǟn^sK(8O:r}ؽѲ4>b6Ű}KR~k<#҆%wHxE.xaO~5agV#1GP@˘ׅTڍEZRGKuMedEMP4淡`؄lFS9;!`!͗#ыH\ ;1e3qf@*:$W5ۜhj _+\QOP\  ޿eG^ʇOdw9Z੊} @+UeLaN~܇vSZ@> x CKOm;MFȌ.ʲyS٭ b~!y AMxɃ)3z]R>#n=>s_űt֭ ЛYrhX??K)mn, /r` 2jнZ2[2-M̍%]f]}}^0zfg"r0hJuI9wj2 y!p5<}|3r!KKX%z\XI lwW j+He4q H[κ{+iS8Uu;Asیf'J(?olgGcތ=PS4G|>$.2rx\oAFݹHq!,>lsǻV$] b^O@Au|G@op2,y7-UؠvK\}Ų=hQF y} Ǎ,93GZVaV*AhwߙF#˟fDQb$ֻ8Bs(o=L^ߓ8@&;O{1~*lo?! d!*Ю :^/#4)h7 ž|>%tϢ:^إKt|6 ⡗9EK|Puƕ7~-{چ؃:BjH / }?v\/+ YK+1-f{xB0M,M)@a]'"egWEPW/ kKPr~n؞wlvAtZ2A‹tJç;;l&Sӻ=?lҍP ,ir$C2Arei>hw05ŬM22/aW ^? ~܇?|m|K;2M>L/ gjlt٣?0BhMEt*{%IS(g3FB 9Ӈ[)cbh_-XAbϝ cXsWѮr]83x&!`.k\ }F2bf}%^ 1/ mIမgxR׾l􈆭 m-daGy} PvOi/$mcmq- 9缐r@,5:K/H؊YGkdju0,im$wuB.LJ#'ڠMԖ\꼌 rf8OCDgꡃag̨ϵ;"ĵt@G zy ) f^ iM.]|5[z.(dV")n\G[Of#}%ـD:۱ Ht:_ 'Gf"ETίiۗs!M{pW{0ዱCCO-..^"d "`$ч?['PVK³;coNo^Sxg|3(S{ EQ:}Iunݷ  &m+2o$,¥a{ЖgD i"fWL8 sOt?$U4< u۫B=(k.1dU0 UY> wH=vÚYċל&6t%[OPWcΝ9`zZr?AxU]3Z$dR0vVIm&At8NY<6pڅhRC+`o7A*Oțr $v01#, _s3QI Cț`JMƧK`[ +Ľ٣^MB9 s=p _hZv aIZ Y^֐,XjϼСҌSuQa^x2mdbvj/Tx(ALc'5LTj[3##. $}1TΝ&'PtPx( Ŝ6& oBeIhPj6޽D`CΊT@D4qGE+IE_|U͘<+ܨ)l$ژy,_ H0Vhb n?!9}Ӆ$~n!M i!-o6ԊkX-QvNkiքxsC0o-34ކ735blT3ik,wMQeZەێ1cl[iLQ0>-q#/tuTlA/sElkbkBeQʈR:*/jN{~ P`ݦkZdT@XLt5@+">+H$R&oq_5wtp׍xBUs[yFכW5N^e<r"d5LWYYGᜨp)Yb"3Ppl$$gQ  34}T3uH/Sm;N([[6Z|u.] )zCY K&4Қ}t{7 on4;0/cD%N$~ycx$fcV񛑙1tg+f6DZf, cqc\ wsyv)9iTU{$DtLa'^ d]eDз/O>k?~zLּtش {Y!e@xdZVtJ<@>˨.}Gdsdh,7"*i޿0-n#>=*pZ}%eSgza.7R<! !jCwC^ JFhDA#@Ʋ) Nh5G`]^Tz 2U!TہLer̳\ڪp֭V(A0U\́ yLGe-C ߴPrT.Z Oᇜ\jw>^(nl`hۭ*M^ Rٛ9otV]h,2 _hk״ USu Z҃g'knXR=Y TeҴp烠ގ]+e9kPƶlOGӃ%VcXձ<3F¹Nz7-XP$< ੝cکVb-AT1Y=pd&+I\n-x:FN*+:-+,GK_.Wr_b;BʹQ8fڧI]{G`N* z]m6&DҦBfUE=r嗫>T6jSF3HDgrQS bC[QoGC<ך< m ÏOހJjqxϣ#ۡةx J:?T*aN;B֠j!mYg13Rblj$MͅZGC 7Q4I b8> jg/-&P^%fU=; wF>M*B Ű: W'@pl?n!;)a՚=<A" |t)ѝ?P ƪ5]:ql| (fm*3m}xV$?R#/ Ym^ͯo],W:wmZxqG:+GHWn&hD6#'%&Z4̀m/ZP\WuPmTNQX>ŘLzdTr}fUCjUIDKA zsb~S=wh%>ro@4&C!YRV-I8}MR. x%pgM zEJj^0#,݀MiM+:Ɣ- :u+|=N60[8n㕋,:PXѿߋ *P X* MhvOR.wx'k|3#+y IZ! WwГ V̢KQM0h; "Gr^L IUQl!Oƥ5eGF6<t[nIj ݢSȧ0 I}ܫgѼ.OK.igQY`d Qg &j @ZFQQt!} AK^H5MGt9mǝʙE'yauƒfwgMNΔO ؖɐl90~^])+_1Kk+bz@@80[B\tM#SF~IC>k3<2v!zJ5+l-jcĮc?mt1!NHZ./dbq ,VecƲq 6B%.lb"js,3qN3NRm׾J `d(Cʹ@L1kߣC@CP"2b]P~N+s멒 {ehKy.@CQV/ EM~.95ϐC}q0[i.!'4>ҢsmI;V'=oc?-LbYRT J]H\bȑҵLhJyAG~>AW6NW9#9J֐xv%i 6}qүvhyzsɣL/(Џ9؛FPa= +'z'3/p,ﰧdg _kB4BS NFLFFll͙7?/jjr' -4m]پ}꤯]&uV`%_ X ،U hLSǟ[1-瞽cU2z;޵6!*Js/j.s$s(!Gm?PF:vSx\I]Ηo~(z%|a8rz,]5:AM@YdfZEc1!uC)6®O7%9G G_IP(D/qN@Os׳3<.0O(Ak:(Y+Ή [x4-uQ駋+b^PZɢZs]8G&Zv3hHʩ`̨ttpF PC`2b</И Mwwq`fᖳH}>$j݄j/jP~n&BL1pɫl8ޏo!hj\Td}- !`۬fH& YGa4Pp@P̽.=|7}'0g!:L$hu@y;=0P#-j(ΚgV#EH''QGu>{x}\ү ~.tqf^) "29Tim~u@+=2%ޚ;͏@thf, l?EH$BFك }k.)aA\3&$4dOiK`8l5*0&n9.S^MC-i<\-i+<أGTlEpXI?<=w .jG_uR!+\<'Luʇ)wOs&Mp%QAlNAmU $v)jmQ5e0|keT>ݒ.:ح$rR: ɝ1Mf) N܂9Jn;?8ECAWT{TI`>Hw>sjy!B?)p ]OmCVgI K:iW(IvW¹KVok fNsS(x՚rtxԳ} (c1b7hNU$=[dMY_@ nt4݊X6kx;}=E4aTW2(bشI?(Y}f) iPN Bu4 ( +C{lFMk7 (D$SO1Đnjij>>:Ɉ7dsQ㼻ޱV* -a俏 _Ij 4O ł~R`AOh-zkkXI+,'goym-%TrEC0R]2!\!{:!sQne~ܷ`h1c~_l1.ŚlVڍ,YRNWV N:gmc \gZ84_c\V˴ ~zrD96qH^-3]Mjk:XeXSFAtkp!IWaFc-8Б^=;S` 2!<wXllLWfRj;YG:Gx vB98 l>L`_gһ~)h%+=Ke *7JQ`QoL<=$\SE}f2A4[%b|r'_m$.MkIt{j ,tKӜ4<ػ_B,.?#r NCgfT$)FsUp75&ڝPh(<޽g%C4Tm!j2mFNVlʺ337jЀZm<-Z=-0ٜ\p%qӉn{K(k;)2C=s$\7bQ%Ҡ5$M\_NjuK[LF45M? AO39Jf5g9Z@ nr o-rkzL o5k @G`r9-T86MɃo 0G#}o^cD#-Gdx +F$ $n<'cŀP0qVٚēq M0"4A"cf '* F8fZA@Lq(7;Б<8[t'1}]6^Lчl y(j)EړU܍w Oyv?l$䔶\L|.NW n@L\4͆W=)!pُ5 B ﲒ6[᭫Mys<߷ b/Gk`4txI˖:$]aE5wxDc&ϋ-eQضdlOgO՚8&Q"Wp*dcOn E^$$NW r,5 pȒ L'7)J*2X%oY: AF\6߉d1k(BKҊG}R$6~gHb;b; -bg{#UCI6)5 \vj=DjNQMQB"mk;vjwHgxཉፑɂnD$'_pg $ҢhZ ؘg{ _ZRVy~ՀWHWO1ڳ$-kh5d~7R: UQobh=jd _ Is9<N>qJ:!oeެCDygW|HT 잓rvimd!߀eYL!S_F\!;cKNf-@X2+GnZ^ՉBJz3oՒUO66wb&^j5;ڽ, [tޱGTܓS2`ftMsPÏ;*Ep:/ՌƣZ^5+8)>jX] y`'zTOM׿y u3cC9#J(R۟C1ZU)H^*P11֜w@?~5}C7ɺYh,suݖ&BE٫|sȜw,\ngY:`A7nS(_CWO֑Y:WRl*Dr(΂6'hю_Ϩ&>`+!UF#^yn|Ced,bpcu8;vS`I FJ``k֊Tox4?b㞥r"ыpV35' 8 -kLۭ %ȫ[N]AbYIr]^ āWq`TXƥ@aӐU vlRB%t)m7VƆasDhr5)`1؅ }AmirPj yhp$vb,; ]%Z$(?H<䯢aC6:RaQ2h"V'cE৯Ծ8"[$TID̫ؠAvY|Kܹjo-#QJy]7|d;/_-C*n v4[SAQ7مq𞔅Eu|2x,KPIT9!³Bԁg $JGB̈́Js4 Q{A']>V]d=4enOG5l⻁k8jWvcc6g?#_ި-rosy@PL}yqh5 lSrj % m,>H^5\4u&=)_b&gE@ܤ.~1V`nǯ\bF?aC<#!j%Q ms9ziiϜ];>j-MS|Ok8;[JT]'r}˜G;czYi]1=8H3m/vf1yoP(ibjf8&^0/X?KY#+4Y3MX90(&y)哿ۍ~Wu,aW-5kGԍ\yd\nmA*;$!H23GmXTц He#1){MQi7\5JC9BuΉ[cε*e!" J!SjŖ5RL=a_[ͤ c lgM*#i O~Qvش9 !/X=x*>\vkg<ܹ#?LQqqCZtfA4M0GAUhWDa0Cb d"؏#6 `a΅ͯweb :F<.~iA[*yF#8Ū!1wz Ѡ4r#J vHISN o6L xg__D#h43mcT(Ld-:hx,"~aǵnmS]<#nN3fКC2?A4+՟шP['p/d.E~PG1:9qjLUxWkiN#$%o?G}Huj7DN `^:#w5y^??۠yqg ڑuՒNHSKhS]復Oi']!5JbN]&T^x}X f#,B&#&mھ.Qgk:~GCYP"5t!~ ٿ4bF3O%8~-M>REes.k 3QXfrLSVdԘ] ebƲ J=^uc E/)cBoH 7{3:H#C2oY` 1IpAX;[U]'+9ۧ'7ݡjkW]V6_Fo̞Q 1T*&j$֞]w#ee;u#u-AG3u%d`hm9$fuAV&|OVo@wjq% B_fRY{1MQD^Z'9n)Zčp U%_Ũ+**CC2 ϔh#Wj;?GӜw,/i ow\}k7+PkW3l)%ƽҎ=qۢS"͘61SO=0K{"TqӼK;`~f4$ks =nС˚w)9nȌv/%ZDlmm$M mI3x`$fMHJywŸY}U\t2AC/?kyZ8D/Bc-` o?x+(wE%xӢnLX>!J{@"3TԴ\|ESH_I9)=i'0wGKi q ' ܬi+p1G>N)}Ao˫\~^u8 x^;=ázF*i-ɱ;{b3_lZ|H#ē~6i7GOBXk#I_,2O%-4+!;Z]`ONFFUK# gFq,`tecRр.x{;zlbќpF_k*>mҨUnHB(i\v@O>9ԵXLy!Oa)HjhHVMt?;3dytv۸}eXMo3AcR\(& On7cKڒmNJ,inL$TI+9^j~Zd%QBRy} hi8F MiF|0/%Cdnq=R6!`xaiq (v!/k-:CវW;Mԥ(863s;Bu#5>BfC}.W֋'kMGlyu02*=-x H@A;F{lYfd#xq }y%P2kCs]Vz>tB%aWtWX\4uKl+wಿŗhFLO72-n iJQ & k^OH&Q6!nTm]Ö\_n#xs"$n஭׳CSG1@ 1+J&W"(6:[ S󖋫-{D6XX󃙱h7TFx"B[]@B83,? Kkh)X^Ca?5|Pe޶-'9c[19fz>J/z= N>YvVކ9pHh@cA[PSJjLq4s7?3!2Ȕ0aAQ8)ڨHGP"~籊S9v(9, fk1UXGڔ`kA$"t&jH#59NWClxA^_lGg]JL2>%qSQ 'o\V@Ή1%st03Km!Vcv+i+m vw`]zʡ+y(޿!86w dK5ٸ 5ך &'D%sW)Xw) &jxq"{O?{G5,A yexwAD- ; b]Ml/ $9TVlzX;v A~mjaE{S؅g&MɅS]AqX߈)ḙ"qę"- ;V/Ǚg߅lE% k)^X=Tw =^EKqq5H86);YpO^$8Z wu_Gx'o`NX`+i11V~9 \Ycsg2EK6Tl339?e`G} dBG#UrhXIWypF\]Uf]A$#B>/e( |`*CKݭ]4N:QbHzʐ69G1L ;SJ"UEgT5X9zhrB*4 7Dޫ[?@(L!R0?iIF̡_.`0}Nr)njrx+a6pE23+0:_iӃ o#n bCJnQb47%P/r 8bbu^%yELf{8 8Tj)E6?iFEm_Rй#8co &%Ñ׻9FL[uB_$[o;?՘7c}/]]r[Wx]8g`ߩV{qe/먟T"mA0sܣ ,`PRxxqIajmPMRG:X쎛mHUT-o,[C,!wÿ&`yn>?u@9!gLviDrci](f!5". VoI]JNx0$.@z7X#NE?(qʹHbU9tK=+b͸5ƞJq7 oCM[qb1 B&$G.E_صg-Z:>Qא r5to\bmm_.9u0'$v{gnvO:, M@Nyǹ gx6#*@YK2q{W>HAٵLzZ :4<MPR}+C\֘A+g2$M buW ϔ.-E{JǕw 'PgB!l75#CSgSo9ӲS=ؚ։oADEޔOo}oR̠o ,ơo,!iT,%1 Ž2U* ;qD>}[b9l eu@K; ;an^p,p- ie*m ̜0S n+Ԫs{x+rvr,y^Y5h5Yp=]ɫFPH"h8>q;=% IS>2ԽޱDteL.E+}ХQՓEI 9 JV|I.*7Z^9sxWHYd{k ~-GRҸ\!n@0_%#ާƧZo^7 Q+ݦ%bDt*3oDLw!3/eh\D<\%2?fbJt,!gur筄706+TxvQ(TEL@PF0 k&ՙÍ/16F\Ueٌrw{{gV5㭨KֱA ЏV iyVm.d7h7} i,MVXL`>y Ё6BTAa(Dg->V- ص*x٪3|8x 6*!+{:ʅGw1 #?G<HMTX% &XjpBo>]i &qp_ڔf1cZ\g}lzp#yeÊOj@CsWb˒vi=^!Y0 K@ J'+oɞYRz_\G&@r^BxXH5ܷU?ys`paM!.FzxSu60NS% ctI[g%+<|pYd.0ƒqVJBE(l$֗)ÄI9"8H`@Ae5y26-f0y湈˯^ҹzPƐMw Ddv3Ǹ WJ1LGNr f^*$gNeG€-R|>LҙDumV62HY)կ'^ +^P#̠fE3a?. z3V3z$yqN<$S9+ @]I53Ovg̈O+NVhmgp9R5NJsn x>=  8HZ%+ؐǓ@4( ȵ{_U2;Œ70x/թmPb34GoM.JD KRn|?I-{!@y|>6ַ2ASt"U_kO|~pƣ@eGu L' L 6.hG6$`hϟ,p&yo|JGѾQJ҃dAlԪݶćlKY\َD5oL5' Ih\A$_ S#b#7}S9A|aS.aͫF@A]/J^K~GF_EK{'d3%BJ6Y][f]++P>13?Uxㅗ.xH%` 49gbU+Ж(:"K,g"4<.+vQDz:PZaNdjBM_VWJ;j8{muGP̍,.4@. g*?ê}}13?gh;ƯYϙ8"KG GkTs^i>ķA.(CmKP :Q4y~h2X_Fl2ݍƽ_[d3@^B#fnVgE? 67FA"[ݧ'6)x}Y0fn|tȠ6ΒQ4qĻ8/&W%CbZ`.qPQ>$_t,֎^MOs:h7zLO%M8;Œ\/נTx,b{?YCHԼqK2Ch^Lx ܳSϴx\zEUR:CS֍E: 2_/_[U.( > Ri̵40;[#cidm꬟W,d/h+7,XD6 ا&h ,#v- < q k633Ѥ N@XUċ2 :׉YE)viy|7zHh|MKhN c5󣦱1%\DAD:};5/#d3ܐ8uu!xQZӱ.h?;( 4Nhepu~ۀcXώLu?q)tkf$iVHD\\]0Q&&xhl& {[10GaLkOۅ#yTur5 13N9LJmێO/\J\bBjbNj[ht4aYo%\q0:xfSpPxgLAm U)i0VÞ'jb@(?>cꖘτ]ת Ugj7s۔;"r{^1Όhbf` \®ذۨZ`ztg@ o-*J[|=w]HT79^\8gI$# vo?S&NgķF*-BԖ>CM|8qD zӗǪMLO- yFz9J*zϓ"|JokҢv[Ry-ˌ;ϭ*5P3w^|Q'uP1 mbmvH'}G@nCNx-0JZat ],]!M:lSywaeSP ?fi{q%bdЃD%Ű6;9>nڪm,uk(WN7;sDI} vӏl7eFVZ8!+(o^F:ٚ[!:־ )c~JQD2g7aVjwֽ)tꈵTWuP͸ VC£ DnW*:is[^%1qch'_:*CUԥ4iI2l0qljp h%yUQ΋t#-iBL2b;1?A{ 6Op h}b103\JSNp}#\1a-_RWђ%ib9hmc7 ȍY!P'v~[ %I[[`&/=D  <ÛcVD`U|[WAɽwS_i4A(;zl19t;M8z{RߒHʼn)1ԔtY(Z`{$r9ouBx=8aL{MPČo,ItB \htTCDpH tTs<}mK WUܔ9}&*̿ 7JS"Nڭ|SؚKZuvO5p>SŊ7k ?~J]q+\g5\>*8eoցAJ4+ZL+FiȮ"[,E Gm`)iW\-h泐8p-eu6܌qWzuD|~Xjr[%K2\<RpdhrƙSzVc2 " o9m]ig}w,8 $,aȟmz8m<\^)|w4JIq\6D!W6%i@ wPqh)Κ*/$?)u^q )%:VqHT1o7GVTOBSA0$NԠ5M\N-> "]bV ZFcچ̑}1#YKu{\b[HG _r 3D3Emq 6]jcxy kbBY?Oq7;TKE\SIFzp{7Y)ڏ6B(@DcaYs/=[uN7N0}۰v-h Eq!F+kcW/ӛ^7+4J&iɨSVRs_WeD)F$NU_ ޜc*(ZX`kOeI\:=jMrM҄39Zб 02S{5h!qeumD20c,ĄgؾqEwG8u믓š[- yJ Oq}7Z%q˃Q։V{[GVe˩54Pձ؇+|e IƇJ8Y@DvATc0롲A h٘Ք鶸PtVe"[smL;u? XK cg/YBf)*&34#y 60$N,LѰ$ Ǐ4Wu M͕!vAIۆ}6g&f2BĶhu W]kOޑq[Ayei"[C 0(/I9fEf.b{PV p~jN rNDD,VRVj)HX+J5^)^ y(h S{In%9GTHoqzOKȶj MTJus}ڎI&M&*X2G3x>Q=X>k]9F ѶȠa?gH mY֙KCsmr!ۆ "O^F^y'jVv|b SVs*h,Cp_GkwxP%Nm,plhroB5*xdDX{$K>A1 #iÆC3@?,!1E&1­jpaܟtl8x+ Ï'@{W2M,JF3؀)!s%s*N_1b`[>^#G iu&CXP6lRp2?񳨉n*Q > !#ҳvf$J9BS$>QPVA@k2Kऑ#t94x|];v,SX~w.KY!Aa/@cIN1x3m)~쏚~$B}-)\FE&| Rw{`'x5Ը wI!kTߟ{WH HVja<C+v@us 0N+aOд7 \rrQOAI\sʑCZq`ywvg9㸾?rCtl)9 $n37i; ~3iI&B:,+aH^b8mC+r~`lO&|Fiz\͊eq`+},9ɣjR.:WPY ?p hN;-B)J%&z;yJ ,k[h˭/.o:EZnXB~S ״bj|ԆMnQ9Jr/}ذ_%\I`$隹'3%{eYm`u7]@ [߭xcJ3A|>}Dz%ȟ:a'bJ(\TJNBY}uҴ\,LEK&!q ՕC 1 L #K|w$drkf4LSRN5!Ŕ-jtۈz XT) /Uj2w6%A9F[~a Sm$O&cqG/:m-Hex;/kj9A [Is.=@!]GԂ4Qٯ㷡+3bZ5{ ̹O+2qF cY=rA:FYsv:3Q;V.'`uF{<v uSȝxŘ(  jxUC[?ǫk\vjaʲ}Y*3=iܟ~&3m)5 C*s*!Hw̓}xR%ZK:/oޑ;ӾfDFs@k)>1ŚLK}= SA0j.b1m pJq~23jm*rZM`\٤3cfb:zoUB5@=V1IF2 7}^@KjIdcJZr#=cI-UxP1dso.4V%>mGE7A(,:N~\8=olYJ0N Nl'Q`#[(10Hy0By9ýE\xTMݐWgDz_Fت!ioI@3XR؏Mo*N,cyp1wyu('Y۸̪yԦwճsA.&uw$t_5+HxҭP WMF{5(ˮ; Giy fU<@sjLz1OX"] |JN>](ՀCBfs^Ƭy"֒[@G~SC<N1j }ɄdmpAArMbDi.%QJL5E$;r.ԯsnocFqSrDէ?qr 长;mŖpWW%8(:Խ Jb/6>@[2AvǾkx%RJ2+w%Xf')gZe}dIYr眣q+炜|8}\<Q_+-BVܣLʛU$5Te]=|ʦ uJ16e6V5: R6SEth_c&,mg<ZQ~Ly6q2=[<,\09+)lm .)'k[;!/q*{](J<$>py4hOɨ?zJg-6.VP2V`<= 299m _ O7CFQܿh鶨()ўAkA;s[%EĽ(pPԺ]UpJ<֔ 9~ObSHcxIمm{G5ߐt^IB&Pv׃ )yB c-OWy[*ytHX&ch#wݎ b E[ HGeVy0 GaׅemFe*! h]Q:VD(ܹ'R#H2|'ٽJlE%~ 9XLkHSu39CLIZ]hx,2!NTZCp͇St1_/.sHD0N%Ȫz JDU׸dqoWhpTy|{^)=eS|ѻ ], ѿx= H3j(KE !T5i"~7Yaf*PNE!\bv uW{c=oBj*SM£rgbL@ebk7Bts*Q؎{Y3C:|[6(qIBw/7KL~|MqFVIYټ$A@bnF"7VChƼbZ{y./Vw\%lsa׋ Oy:r5B?kNX?)u y gbz[qC:1{Zq^]"jDQp >r'q;̳&8Oۈvib^KrPa )$HffoX![;^G{[j~w柧CHNM]䗅%T9m<*Cv0p;ˋoqƌcYx46 PAn#lx,Нgg:p&8{Uڛ';#d/3_ZXG5˾XKRN?3G8 !b~ö\Z[2-| BDC$ $Sw?‘xH8C }|} <AhܮnGUR,عQMvkM5ϥk|8ӳVRT 8,Sy)s|s𠰀qp颈i"{ ch*jNϑ❠jӫ2 ƕD\4Q*aNKVDSsS p#2b~ϮG޾ yvAFԫtkS0"I<˸YRcRZo%#evu~=VXZ7 Y7BM-[hW*\]7Ai1.,JzpYd 3y m +]hVcoV@,a(DE?c~bkM%X_>:.Ygh:Be}5+5;5ؒxjEPzѢH]%*0&*-i۔L[(c:!69R2\ts38y쭦-xBޚm:?) V}1M.\4lˠ+2a<<4_A8l~csU!vFr%P#~~pf^֐kwv w.`%)S}.TW@FUc_㪑1S+gò@CMO)+WaӗI4F(?|7P 4TF4<+}S]5,# rTJǃuę 6;NFU]auZ9qa;KBўvDu!Mq<\h^PhOQ"([B>6d+KHP&'!VfE7Se)u%bY^0 `i^Qf88u#1B WrmN!$v'ejV8 q O&\Qy$;2#RʬDKw(j`nC]"KϪ̻g֯#G5eBThŻqn]-G{}h+C]H9Cm1}x@ŝQkq2Rw9ŅoZMQs4lzF҃g߷z`Ҁ_Ε/qwXRWc<'pB0~4ە7[@Zk!v(ݮH$L/2 Q;K, %f Yn &&ڌnJǂ{`"-U8Qԑ*>ȝ߯uː0! '$]NA6P<4?8Vvj}.̈́wvoۖ6F:!u- gXyCfQr>Dp31y:b> ȑW , QS]škE*+dLNOd2<*AѸ+ZmL:KI tv?w[~@F~$x? } Jg+ NmRxVQtpL]Քd +31H|։f2[fؾ WǑqeEc tf!.'3&uIjaN2q/49jvj)PK4<[?wŠ3gP'o] AVo }'ӣaɴܒ\h[LX@zzag/-ZNii1\]'rŬۢO}ڻ0ҸQŋg\hFT@S4p? iN,%&jeWEtWKٔf-"#oDU8Ǫ´BP#L'vqn⻰*ec֤gzA+Y8n6]LU4>Iȗ#ͽW_d$Nb/TIhԈ#Gp)!z9h1OiqO?O.ԊKMeotAΤv00 oAKcX˞=+:QM@;D> 9b]~U[ĝޡj\'h_qvTD_}{ A0Nߣ$1p )f <1U^5NInH25׼؏=|iRA^Wa ~5D * G#ǘnCTD"nQTX(ʔ$6S+ii.kHG|h`пVR:po9co1w0Ol5BϥN' W#I/FtwY|/m&)'E2_QVr?i! z|6AJn@ø) X5e -&Y5׈'8on?NF2⣨p{h9l5Eߝ\ꅗ2 dB>B7 (^/7a,{jcc5 1{g5w-j wx(jT<ջZi7Ott\z醍t[Q֣J)"wš:rȽ*<+[ww{~̈́/d<%8)Q=4ܹ_KC0רɘsyaq1"GgL-L MV\eUg{:Gb Vl+D)̝>=XuA/ TI#ݩ=/?MVjs0 ?G GVR筛3>ZY?z*Bwiw(S(4 m !l9#*I<^yg$ |W֖|:C?Lz.k{+u(*V άr2[X t'ՎܦC-j/NF{0yOIQ!a' WT[ Q#OgJ`)RTtAY7nxٶm I|w_2Èp3 GE**)јHRh= ڥR\ eiSV q+ q)@JN3UG2 ݋:H}ptCDoΟX K@kS lt|2˴`>3!< zYoUKڅ+Ck(-JkSydћ3(-r:{NDy|6|k3)ܣҟ(t!{9ܜN26EYl=el/tH4/)I;~mLOtlY`{@ܷ݌.0%fZ/X0SZ[^qy@ˈ!LLA\6f%+"8@v{e/Zס\:Pl}\[|`{3  $HSukW6@{wERc_7uezaTndmg?/y^b ;?E|N#JƁ ;vǭx8I8΁e oq) {7 /ΠyΏq cuwŽ\GwmݤnrU0[5bI[Hv StKR!mnjfiu$vj_ QѸ ȧً-ςw'n=p?k%:yjݸF.=liԄC@18YRn]ř-gllB 56R;[ڔ%ft  }:rVA>y ^5߂yK֐d0F`a7-H>T@iBIޱPtܚ^ьYLOfEr: EHTـ[*_\M%y%QhXrKd#0ݰl%ВTf9)bfbskV`gi'V# 6v;&w_i< $$RCy"fDp[Xg9r/,_Uǫ^'-n[eƭ=9{)!B\Oɫ\h"3w'nצDtME|ê &*[%$[?ʋ&mWD%[ b1^wZ(gjK#haDl[C<^-f$ 5ꋘ:WM">&UqpdܣԡސhZ 9᧠:25 'JM4> Lo2OV=]8`ZxUcY R҇ӣ2rC/Fz6%NZ[2 nOzM+> \{[c}* BɇO\x`_<4 ,j O …Xx#QM:H)Ӏ_ *.X(lT@!sl΄FFʪVū|I-bo`N]米Ct j&zR9$i#r NLҽh:bTj#ڔ9U\dӔg Pj6J02˷F; qz^,_%BRCA?yٳhمj׌n^es$0^0h#9< }[*Higĕ%\m>2PE\NBlonԁk#_rgk|<vB-&hm{f*VՑEA1}hv$J*;A)EZ=2.(2"oN,yvT5&{VZjrE42{M^ 8rd@k"0TZBN#AEft%f 0;Ň# !{``fE..׵ݯPQ5JD"nϿϸBU;R𱈜h7gJ _1> B4X,gyk+ՠDžC,N4H~>z遜1?H D΁#&2lԘ; ">5ZgZL&hq4! @7֜3p@Bd:2;VR'=} ]F<+پM \Bd*dZ_q^ 0v8<#:Q"uI|)(luk.G0TRu`Dg|¶_r-&E^Zrਕo~9tpvhr03->m $Z5I5lOj(E%~oi!d q8`.sSγ\ɒ)}ܟhU 4Q;N #--FՓcyOIS;.tF&1Wǝʵ0UJt۶p|wk.aLFj#JflyP=˛g[\z ;*|`]Z0+"ېF[\Uv ?q^8s|v]ظ9qm7DUkbÊPr.YoU!7a׏#ǧ7$x _޳o2/ilq %9)䄼pWl&t,OOf篨n~݉4WܲFg֞v˭?+EsCP)A!L/QQ?+2b˷hCt!6ϋ-}5ǰKY>*Oœpg*WAVh1fbPӌW䰧gAFzerr[8DD5.^46eʆ{Ň1+y4t U4wW}CdknD93&,;nt2J0=e_@ff-A fk#֙auZ{_-=bD*iD"_euH֙OaP_e+s5=btQNOIM/s|"~o|% -Q \nNinzpj!eՁd5p5xL-7C= qc;< 4U؉[|*]($r8<45G٤Հ[q_ -GuqZiv$6΄0vt qشv-Hsæ4=w=塄CO{rˏ`lSy1ƚ>Ƹ#w䶸 BjHT'6vi2Afk%C6Jjzq.xǽ0]7 gS`ڻf@3!Z)s7qNyY9F*̭-0_Gnu[ o4Xoc3W]Tz:zws+Vv2[|}KE.܉eaJ)s@s5o͚D|DD `+n-6~Jrp9D?%};E?+V.0pkfb$P@gV]ma.p֣ӌD iD JX2mа?$R!@y}6~f9_~jb V 8uuvYssƺ7V.\02ӺS"UD4b\ PHL}B cs JWsP20o^wiOAЛjb6r&!A`ƣJM=X1= (c3pЩmLSGF*Lj3]{, NEv;fvEa3m6>"'O5ՈYu$iTeu%z8K C`Qr@iNuE\Y _'jX}FI&GY*V2Μg1&HNj4ׅTD* eN4=QYLAnꝀ ,zZ"=t7//wH3KQeYD`Ltg;҄FDPi0tw7MlH)\Tȧn[2}F3zu+듿h/)Q Xt0 9G%5M%t(p|EjlR 3M$1%Ee0V/{R[ ;~,m\i#}l<䃹Ҏ-yH?K0ɗw3iyT'-:|cQ*HS u& ]sdEouiQ2ms]1ebHHYh,Q9ؤ'A{cZ@!:'1n:KW)˘' &Ev_f{<+KGMԖ-xhۂ1YCëU C8nN]*d<ݚߟs>ߞ!XZTU ϡOKVBWa19=? Vgv}aȴGM0rAId$Łd j1)Kx)"pkf4 $~ E+LH\6{}~?D9Uf*~/(ZunD6!OXql ,m|l1`Y^LK`׽ 3!DNѠs9L1\d.eиDrٕ^i1 L2{kq|lCcO7;W2\إ!94:\a͵¹DV L&5de9~s0 _k,_&$aЈgԣO4$Gc|::Q|s)',C dCQpeJdNZgZ>5Ƅ|y8UօػBfԮ1 W DN)=Jk&؇Těcc & AȏplTpõLD]Z}aMUukks{mW+ k$#_xߺ2#ggXnF<3܂lGIw[ŖԦGS"*MJ Mڻ/ͭ,ebURfQԾy iq?GNΔϷ칶QEP5S<Ц!p["lI & L AoJdEѪ#ƫ:ޭߠl.AͨOF}ed 錎nҮ\fӣ.ud)vjevL~r~U;ia-Mp&8r!67.V#RP~2巡p]eJ9f][^z;f?&H5p&եfO"b[WޕX*/րT L\qN/[py-Pȅd榥PG ǚUV IiLqo)c]Ha3_3̆kTޘgk]/xj t5[Jd}tuZ#6K9'wO8pB6\5 `Vi.HS` "qKb:A Qt MC؛{V=˳8ǯB0zZjci*(.sZG%AG84!}s;v-}d[d(% egTs[4f@J>9 |MkUl48vhMg* Zœ8X&xhc JvH Jp {kxdt0T 5%3baP:R#nzQjRE533xIZ~8h]M&X$nj5fK0<v>&7l ,Jdt[վ-V *>rؖ`ͯSo,)Ƨ AgF5J8:1G#M1:4ytl&D$Lng~Τ=UbH2XV v:׀joCB_*n[T}BZ6ɋGk̿1րBh*ݙjW#/ ܕHBWǟazqyƱZ^C]PNL`hj< 'kbB6 Uө i .4ܴ .WТळ!_ߜI.YE9 5"ʀiW ]Ga1]Y>v0$i'>дQXzL%uQ B :у#8J1vq;/> yI"c-%[JOff=?Dk+b~:yN朳@/R+}Gvdtm+ۊ'1v4H4y%~ގQ<O^0$uܟޣm7<8a(0seT<7""dʋ.`9ZhĒvu~[g3]%jEc՝<#%ryF |A鶥a5s2r,HZz2nVs*: Hr+q$>0GJ~mg?DؼJ| rMco͒#hn`J"=+G \lfH`i tOc_rSO#B-a>I2 =2a0[Hų1X]VJOhYJQ$|R3 WjtnjWԵfGN EH~+ɧi I:lt)^@b"YSf~e9w$~pݴ- }k(`V6ք|I辈? 42kc]Ƀx XuHouUl]m<?gk61 gkN_^±ކ4 W2K :(,Y^"FtPЭxL=@U[-^, ST}e %]ɖ"Tp 8v5 G+R[gH _E y3IW5U>*\;ȏ7KT3/N`1Cw{ꙫI%'rAm8oʋbƪJJsg>2L)AOx_?R]̭Q3p@:Qr$5NX,kP?Ms*?ԃ/r` t:oP "}Eat a0ƨV1BۢBgS2cZ"5~<82talcÀqLƘ혌Z 0sJc3H6X-| (%3cgB4p*?hZpsxӶiۺ# -ǫ׌ 7`rQy[QٺSMҖc׍;kA>{F+FkvU2{J5R'juCJH/رlгR~;56{v![:Ub<$V˴چ:޾VC^MɌSZɻܓ ~~EeyL,דUxHZ5VS7X邜C]hC. :0 fo XGB=Gh!ԋ,j.}p e}F`:B/+e[lO GRo~UUy% a펩l I1.bhxįL{+phV6|\֛H ,p8/-7r*:$zCsH }%{G MW$(%Pghɲ"1Oe{*F3z_!Ոm95fcc*7$g_*ѡ,b{DC>$ ;4`mJ]C;ع$kݧu7ѝ4Y4 hgk&X}Ue=E_ 1NU'|X8@gʆ="Kʹ5EUHUՑœl^z.ņzOʲg/E΅Xf{LcUSת$R~Ἴ#i¿ w<چUβQ%r7 {^@IaFD32:L3(8);HH˔iIZh{mߵΉTb~ʬh }v.#L>fIY1JyՃ[w(5r=ԫB(q< 6/YisI^\'2Kl_oN޽X?g4_؏+i+ ? ;~ۻ v]ʗzRloT*kҝz|"OBeQ 5 c^Z{ɵ?86-ة^JOmDH:LM߭׭f9%6yXyemW{@&14n:wƧsuvʜ6jO]yM75*̹drӬVV|f}ѢQB$%; VpP-JAt.5&["2d"aPZIf&.%/1yO׎ 7TMM/P.)sv &Z#m2}MoO~d)"]p _hyx@n}ap`bZRQCd*H_ O5N&/[#da;]2Et4%bR[FW{م"w'a|d#&Yt>)pG_'(-qBIHYZAq9j0lkK0 zMBaȂx"_qގ1]0mXj ܧ$;_2i2ekVɣ00Pl |$[tW~j"B| 4Q 5Q6^|hĉJEhKQJx3Ċq8߽]̰]aT`h"?z3@*s̙7'HFvuTN Iu~oĸo=;k Sxz'2$d[wCSV ܽjhMl1 HfcʵH܍UԴx(- oV·DJ)59J)SSt@Nhvi:23b`y~~ {$k^YeLktFMϓ䢡a\ff}~Jtoq`~3 Y] 4t'2j'6 EwN qۉuxI-uē0-16g$KL a'#[lE%W]˝оGC3bIlJOuiξ?lw.Z`s@=SN%t VkF\'|+R*E*ˌRr^FGd Jʱ(#"@+% @ЇYBN_y<˳2{@z5 $z- )o"?ibG\e7Qlt7_bj+I6h\z˧x|皋 w1{ yYQu@԰"ԤL[T2L#{6h^YߑgdO3$r<]q ;ĻUoi8 x1;&;Bb0'8l)G=hS3tձ5tz)f%G^0"t&aN!v KfKC@ST"H*l<-m!>,S~1?|8+ <6:Ŏ5<6X+2lk|Vm*x1^z+#jjQ&yils[j 558x$vi$d( ))pAJ?y\NDq-u.X{I'43]:_}_-JGl /CԳ݅K|TʸqpqqeQtV)^L19Db:]nP;W(Ue;C97*T K~ǽtR`A˅ͥ"r;a=iog  j νS3 ǟ&~pt--ce2UTaugϲ1diZKi |r)9мZeO'(Z [w.\Dm-@Lf۴:~lR?G,ܸ3|KE X` x#N{ǰm*_"% ˞&p f ~0HexW 3nOV L %Qi}rJd>W{͖ WF"m""+s+}F\- +Ӵ 3%j@'n75O S 4QUbfY S2YG`z"u}=Ý#fl_>aE1Rz4m`Rm1 cm= rI8*a JԲ}/ #bcv*N{qnopɮoAeGM4Ju #fpRS\᧚Ld)ΕΡTuL\֠% \=jpgѰhR1Q$Nq|~ xrFsxG3X@+=2pZefJZʣMz M@K.]iy&*#rj6p{[aZIaB9Cxa.zi Bši9~^тƳߒ%Ln,[JdQ†[B,!햊ʧCIt֍ ͪϷ?!ΛP@wV}%9-^Х!5G1h#& LW v;!{,$_Q'q0g8]Eo z,\Ŋ:ҿ ~>3BAM(LmE\FB9CA k( uסɌ0Uxu 9IPkMۖPFA2̈́qcՓp"UurAD<+VwlL4"\ywMpیta(ih3V 5ҋSNUcHVH[L;g[X79jnYQ~`FR/?'n q{o/TTIq2UTp%H$ţFxƅF > WJi/9=RFey"~ZNX:ӿ-K =2u`DHd]cDք Zpbd-^lK`"bjq*M~N`ߥwӇoԒ.i'@8|nb^|ߵ)q.$18S]T /ZK[XC&3Q#k3][i"GME#lwѦHv+:%Oel/U5 ZVbO=: Seo@quFOFng&e) b]G$_a [foW&ICC=hmF0N=$Hi5FEf ڐG}<'398ы#-sU .=Nl͋7z)n sm^AV7x4VO#SW(%jQ? BG6c {q&u f}lg&zևDŽoȋ  888]x8"г qN8|F'qƒhigy R8$HH wP?^tWʦ .+f|~FSw` k cƱr 1y}MNI%f_Eӹai>J)዇SRYBov17i_„ԢrB{/CguӖ֥ _]yf}c.tfYݔ;g(u,~{ژDHVRYxܢ_4SnL^yP2Row$r _E :)1^a/yrXm$,X?kq )"@We_O,W~{"Չ O{XO_aHt%i^CZ&uU Vi1Y&gH|w ٮԺ 9)'ÒS_LsCߙ&b80e]1Q]8ԆZ&Ky<5'% $ $iP,zgPذ R`oV8 KOjU1Hj12$)0h]6ʏDWRj@}\Š,?gz@:JV*J՗G3w( F( M!_e;?تjAOX]5f&UDѰ.=|u64Pgx37w6P l)ժ(̅2[hHp@- hh a#E"N %Nd홼biyh xT "PQvr>]|J" =mH}1 @6&nx:|t/o:Ma+P^=;S|eǗiu94zZV&l $R;c;N|޾+UC'ԣOi~;= l&VS1KBz]p$؉=`XB IP`4Q~7B:d|?xȧ V)u,ڹAt'f6ݤes9L\{I=Ԑ%J5y.t)Bs\9G[l/5 h1ԛ窔HM c"B __ȊLwV߳1wB# $GN䙶1 jH+v6R qAb+U-+7s-O4H%[Z(9?pcOT [Nt@c0PԧEP+nrWbhlI\/q1\^75zۺ@9ïZCϷ~i6LHtNɁU]ZT{6!oBu*o^='`@: wٟ:g >)gr=21b2ԛy7^hfnߢ?X*. z| J\ƃb\}x*>g8 1EԺ"mH}^X4o;Txx؂J -SU&26O &JEĞU"ꔥuZA1vYL@Ƭ#BBgOMW\w :+]sZ*h. +iK :zjRg *&HOƢ`*;K\cq.΁u4,.^?3 &!}:k}>ueH6+o5A[ N {yV*%S廛_LC]Lue5rKk>q‡ 8V<խ|c ;T18_<ߺ ESBXp˚8>e<tIf{+nSNx'Vt@1XVs%DA7`4LkWdA].6jeo:?`6RKLR\9))YvbOCЍ}*7^ҍLWtϜU[Qo0En:Nd) grfF j4]$$ZsurO#_qf/`_Ьl֠DO7 %op|fg^wjC9v5PEmC 3f*e!#3fG\<r}0 FKlq_>k @x9YD˭ͨ-L<&7/wϱ@,[SA~8ldU^yk&(33v˶)io%"dqȍF5š=Z՚@|SL냦;,I? +0c ug2d{9tG.W Պ:% j6f:f) BNT2/P3)~id 2m %VH'=|:mSuE53dۭude`qyzѸ1r߲-F'|u(/A͹TSã_IINZ>a3kEVt2E`_L-wtdA}->t+ԿڒJh) Uި<[e҇"(Ec679e_zdɎ7L0b["DU#"J\Ga`J(9nQʤNV $G|Է7'%5],riR]|( #mV]bɄ [o.HZZ}-+]DiUI,V;B*um2{ߍӡrBv6wVg%L56W75RtYVE᪳&Nfz{; NaF^ 9&+%ڔ^Hď݋4͂=$DQ*>+Nm22L;YgK;aʧ2x['l$*]gH1{<@rW끿é6y{LZ͇L͐Ho<; X0{tTL2| ZVOR}ia|kνHY[_^IXg)H%t8C >=ɤTjAC`\pƪ&f{6 \)@컇 iZM F91kmo7mH:#GΚ쮠, X(἗ SK\~cL h\6%; z6v! ekl O+0 BR#r`>rE4KH\Z17ZUH;KyCe#܌@晝y/),_7~L&q,Hi9TK"Íew(&GUh4eԕQ~;aW|J* 9фEJm٤0v1p>g._EDSV;OʠE[:]LF s2qCЩ=K:32ðJV]y[ȓk!L1R 1ˎ3V{Os&Pᖵ8Gf-h=ͳ-Eg,l5g\ 8D&kxq% v+NVdl;d3eiA2$Pkaxq&:,ke~~ ׏>b4cFO;q?˲4cWc@[- #oI"-d#G *o4X&^>LzO*tqG.ZݮВۻ[_S,JX0R N=K72iׇ2>'t%ꑿ!1'1 <Y@Ubq;$N^ES&'G6t<$'ܽwHb gb.'XD}}qʭJJ3j鲲ʛŎKVl)ezkRens&xlwK[pPV"7K(d,}$SKM\n!^h}~Yu.+c2̖+d0A>bđ;&#xz72g?<2% g0_Pzk775ՖSU"*=#5o#WGR& ֥- dslL]qџB;lo]\'Y9۬)j/aF3o,M`N|{ٝYLHel}a@_Oʋl͸;z5Fǘ1å RxjQd-9nTc$_ \w/z9KA ?,˦seXGA vB=`FCCT]!b-GI@Q^")^nYy'Z6եVky/sJ /g$9ֽ:+nRm3 ZeR֣c* ^YJ-a{r,34Ic@kgv"\;m G7zsP[Jgz,T.Q]:=ǝF^qN9x?3ȐS7k#' ]D.<~I/“y[RR5nfܒrM]1u POn(js0B˚YTDH{VmOj~ySF-4L {=/d|ne[{Hx'Tٞ /B䏯>01 u( G'AP ;g<^깐xwL* +n/qɄP>Fg;sIԹsacԭC IzE8u0siMy@?=pe@T(].g:20EIxk>ι n%u]-!:G$j~DssAҺ{-}b2 1Ӟ`:=L,\\ G)Rg7Nwsc:vvcC=8D G_:wnoD|H]EU5e>Du\$_ȮQ~=$DoGS-\<`HAx O2<Ŷmönt"trf;Tʠ%5i$13F#E ?9Z ob-5%'2<6ȗnx=V ڋN I?!^K9򬦕NXOV ,zY+q2" f A=0Q!tk,BY8C[y:Ԋ8([>E1`_w @XIT35"g=n7hn G 7s >~X|z- g;Qa}frsbqaI*$[8 J ۇ{HCt`vo.[ˆۃ#VAk%,!. c&>QEň~_[JȎ{B@1wj*8%kSPwHR&uQs2hp/`Ň\) 'DϿ5ˆ{jM{C`+ kf0Ua"מs@;/5G̉?~s!mR;O=p,:΄vjMi; wBz/bX9YoSflʆaq48~o$d)5圁> upeFoYj du紑SغN.%roX'6%Q/G Kglo3(TF 3jR)dǾh^n43(I4:ȆDQHo& /t`\>_]'ҖBHmN0U~)eZd}]lВPژ{0$ԝCjW IWPK͇ͣK8[IA_9;#nj 9[ )Q!R̄"隭k.R˹q*@{/h'8۷r Gw-)\*iAd!ז/kj⑤V58vt e-Hcr7LV2)$>3v[Joz !EzV[R cn)kFZk5Y4ϧ'f"hHH4)|odtoR]>ԥQn[CHwx`Dvľ6k i`@ kFeio"5O7 @kE^:([UWƵ6ԩʽfybOz I{J<}A5L;Aj[-A g  ,f7r{q"y}m`+E2p3ϳ.uX3mcR愠OEt1Gy4qEsQ|yGP&E)\}`b}7+w)2R.S"Os/ӒKJ1kr8-_S۪ EgQcPs^@纴]N[衽UH&>**=6hwC|Pq ,kbWOPHhT@.Bw}w թy؄½<ϵwZ/F:!,Y>%]9l Ą$ -b=R} *&Ȃ~\!ʶ'a׆c3b~|#rEͶ@xe`8 g(z[1s7-< E3.4A`(qY:wF$"3` }xM{ ?Qf9fs#YV-4 #YKW&PL*ObV}DjC>ﺃ,W_ӴUt*Rx`A*l#!P[n\R]6\-A_%Lo&7`Ω!jM V f{ug9[US]Q0.:]pnl:>yunuAK=)oslF3 [ sIn2֋F92>py,i݆Ec֖L[ׂMp KRݲ6a! *^wcf$a3Aa-Lzq~޺#{]XQ73Մ"yꗞ# lJX]9,nu_D*D땃6ƴ,pI(M+/o+29Mә٧4`@S?W{V@ҩ )ZeP `C>Fb3g@i!:p17RmaOwWbBǫBWf8 ,%商|rHwm}$}ޘ䈙 ђ[j_~9҆zEfM58XFaZv1,~y,f2\J@O]21jmV& 6oUgûGXFHy(}kw>NF8[. 9'_n(h"UX.IrW~~P82# 5YA1bT x"SbpenHN\.3Ɏ,z7b;czDHU*_]i|E@cgk]td:6ÿ́wݛ]K*F~aa %}A,d.ަ~k1>Vrx&HK|so$蠢6ܙyz}l:^={.[ü_>qj")3G=:{9 GM8}`5p& هg+KkJ0$(ޥTv25Ӌ̣г 5(/›HB{=,!TInD1@19+5Y(l5%FѵD] &r y_ܥ=0k*m0"adKl wLҮ~4YoθPSMwZ$OF6#p/=gaŜsEt"UU]ntVϷ+, ?&P| ҼiW{;Q]pRhI *ucSf[< <%`8.ݲcP 7b ˞Ӳ>&y_4yDcB٢ZƏFxj] UzzjP} [(Q!PÝO<8׬P6c8xo% h4,&SaA y[/.2QP9,f\W*Hq#+t6n5,CPI$QT֞a0FU.PHWUipNwo@i+=TdJSߑG*>YjR(5WO%!܈-=^tk"v<({W)y0:v3§?,+l~G9ĬnCj1/o{#gZB uUl~; S,pVIƌ<*2;.N~no =TH_d痚\: G=W'ۋ@pΥx VH?E0 V+0u<9x{3NQGX.ࡗZ9RRm+G%9ONpQ]QLkIdϑGu2@(QBg0G}Ѳ{ ϞK l32јڏlS4WSߴnH4Q~  9GSU!7a3o !@V'ze)Fmz3 $_]^v']iD?gw+d` ;$4k~֟c {7IkQc 1&uay'IUI VO>t6'81 ,p8 RpiN[)*W fK—#NYL|5qGxڈ\))7OLƨǎfÓb67#_W{B5- ԭg)5Ĝs/LjzjpH?Y$繵&Fo`O͕M2зqKfꂏBak*8"h|, wǓUy@fI_^}gþSSsC1j2s6D>l69Fc};)=?D,[$GY_DʪƕWKeVGۉ[QRk<> %a;.D'dvK{|Ø{  S` # 74+gYoeJA.t&P54V#QTM#ezcjUO@hw55i0԰5 &<8R,K D%g:ɀn``#h\-J9(\Ip>N&SŁs2P_5mv 7SpC\9H2'k )ZnIL^I1Z|xkuN~bnvvV[g&ɕ#_J2UZC]$зR¡OV:X!6 }"։zImJ/z(\qRȎ(syuyibT'2b8Db[.بyF&> CكѻCq᳠Se"+r™-L9ARä> N\7hGT z:< X!NIWǧ!+pL48,%d'@g3ZN#iR)X1Jnqۨ3q]>lב UZi+͓֔AaBRsܙmqS8Gwe*u29klJjQ{;x2dZD]g) ϰQו":-wL]JPQOiC1!UcbYxTNzgr 5V|+k,R?2L׉PX>/l]I ( ܊j+4ӚܗtkHe'aaռ3qA,-grOWu*~ܨ"o[Su-;I/vS_X#|9LYS ]Tw`l*hSL|+\4&SF(nB,Cʼ$kL\oi1'[}jHsy1!ڴ:UT?B<)%˦fp$swnz~,t}vܫ]wCMgN!Xm?iCbėFgDVO`([ըJ 7-8h?MWt%Uo"C;nϛC_3%!*Qu>QњynwT۳Ii3pvo8*Xmp6[ Ceb .Y]9JBuAeTeVY  h=SbՠN֕HA$O[;VHh |^ͿrC HF^K׭\J]ϵkf DG% 8䬡w `r[$'F>I6K4MZhD)1Y~!z6 dNf$uR?TfceFQ?>Z.d:N7ڔ _MI=ȣDbjꩧO?- f&+L`*Τ6BY}zGG@6zǫZFʆѓj0⺒ }9ebK 9 =ZJۀ 3=8FӈޠJؗDA%L+KsEu$\aɩaj=?|@}u0^/X+8J*(ӘRa{IAVB`uBLFtKN,\QvgZ8=T `6^?u\mdҵFD^)k)mP)EQz;ۈ nG`İ L$r&|%9ͫ0/MD$v(]A;+j_斊DZπ1!žD-U*{H;˟bL$IIV0 .jghU8 ru97 NzR~B^mlDŶYu4 h6#DW3@jD4ЀM7GDK8F_#Z# OZռ{J7ob Ӫ=J)q/?d#qyK~%kV II vUsi s5&U4j5$fhvRE@V-L_f+Y;3O7kTGRhg 7v=kݓ= <6ݏ )* T10<$L?I-ϧv׏^$Fb`̪b^ ,I`ʇsr!%~GoyXC(ף.Z1rnʟ BTEf",,@WJ$HpiDDU t CA|'nQúPW5’W,Ϛ_<@/dr%ƁcﴰwWpI//Mp"˿ބ--^Ռ!o=|j Jo' L,>YVٹQZE0PRbaYi}0l촱ԓ@^ 'ڢ62Ȇ"1~(]tuwͧ @>wGyh}QpU} 7S)aMц{-1@Alǿr cd;00T,ӜܝH@4$YQM Mk v;b0KFeRw7Z4.}E:48#70Nl͔6Ld5 pAFM{C-V :/e5"{P6އ +Glt:;/:L:H "Jh]_ x 0/#Qc^䕢{_)nUL3#DrP -ϱ3JaWˈ"$rPR']oZ2Tc@x%_ X ΆQH9Ǘl|h `7tg ]@,fd"KHߠٸQzD1k@),#<ͱk5VXXoVo ™Mq8zK`5o{w z1E4*Ť;]o|` v~tI:MBn1'LԏWґZiUOեl|Kk)њ,tIc3-e/ ϥrڝ_6V1H9\Uy^y[ctrl¤u.Jj}SL1?m?_ܲ@z+*0A)˒ϙIk ݢU!4Go+թvޡ#ſD~.UĨ<=}YwhW=>$->3mb 'lB?:\%o,@#&\F{7c-kPA$rT{3VAN"'}Tdz7O?# T]ITFsShAߘC˲,fVپZR;8?^UXV5%{~~Tqy?C7tа>I6t , _ݦQP@D+|9[0ȣԓee< W|1bK{=x`4-Zka_'y yP;p kFt3]WNh(횓a^yh\{Yjs;cW`z듓%Z x%~*o۾Dm !tu@_Tgqէr GGINXwd5ޮ W08`q_\(0R{΢u4\=Sq@!3P@OUe C+IE<85E"SV-Px%B`>JGML1~q*dJh#7k~Er: $,{*4K7 `Mv:\W~_CW]!$EHTV/[MK  Ӄł<:O^{Q^E֞b}}؀z1e^a(#D3{,-h,J6HqoX9ݽqi*庐yr0\W?F0/ s֡>ӻI_N_ gK|tEĥ}ߌShj"&H?#q]L60LnN87Xr'Nz(̤ݥOAl Z>AB+CaUklj6z/F4:4ҝ\]J}!ŚAZP@R42U{- mI\^Ŷs[C"ܳԆ1dW#{:Z< |x?E HFJnIb!6^gϕ6e:9 Ҋp# zS$+e4msfA:s!p?Zj@?&<4$+# D`F+ٛuuM-m 8O;hUvLqzI? swKy.7^Иmj R.>uf|ᇯok[ҏ٥JlЙ>xr`2:t3ILUM%x+4$mmDzJ-BKv`F1(FW[h+VZ~t:<7 6OKZh@t茔ɢsR^0"?+lF r@U`̟јe$y AMSU*Yt6*ɌH߆?+:5:pwğ#GDpںdlW1WDm"; ٲ2c_< B]SsRbZĄ>ɛRAr9k"ӯ`cl2qi:#ejzz,w.8Ơޥ$6B2Cng^fvf %^)V(E!X_Y(gfb#D951׫L1C#f9[Z`Gi i].(ApDU^eB9ycޱeN 4 g47j/>3P@"U˿S}fx| ;%#T6"pEcC5,y.×\3OJKD1f!bUe,lN/X2f$dlQ-ÉۀtKZ`)'rK4i > ufɋ()%ThSJq*ŇYW98N t{":F;]@'wFW,!Z{%9t6b7y"DG7qyX ! VCL9/e&|e uG^Pk $ǡ Lr,]v8.+Wd{`Z~Qb2a'kZ{iꬷe`SӧEfR9C]ZyXGpR+ﻗ幢 4am[itoA%54ΗJE;rZeӟu4)Xt؛JW0WLJS(}MnݏhoE.juz (zj1.AhpG#vSJfٙ}@ Hrf/wa[<(G#l㭬b !)ƐaC1l4MmMcRғC)WwϫaM= J@} ްh(rDCZٽqiUz@ORΎqO'ro\ʟ`f;"?(6w6sxݸald&ЛY'-xOq [C8-;4t9}#dH`_/#}Ĩh2"K39p0*"zH_3-wOgNCp>=iɬĜ@j%;)`{j 6J3v!I0 ?n{",h~`(krkYgzK$"&嚳 d:%#e;daelȰS&yp! +4@SujzCʷ;SwI|fFB0NRw-G$"H+>.=ó8ЫP[3.T_h%d`ʯ%ϜpA! 8bl; bL_Lxaoe}㘐()O8]2\eZ#6{y7nץ?J1eΆ_~r(QA!Ǎן,砪J>/&S sZdPiު9]u~ #RM 'w:}dc1ts{]@ 4v+^SB}>y,yV[ƣ֨d7$/?+ٺ}]؇˨u)cK\ ep`E"zU)v"m~1ꁜƚKsϷ,}QZ$9qFN7a;kz'Q mUpw0"UenЉs5qiz5@ JѨ E|]Lj%IE֥^~~'K꺢G)G~")8Qb8NۘwA m/ҁ9Kq>Mk=)zC#֟m@<{Qnrؤr&O7kyK}92)#jr˫F؎qY\OErBw=s8ks@]1=6RcP^#^*3uAHc29QKd6tgߔ[;H;T Al -p43Qcu_bkP~I7KK, v |7¥*Lԓ2BTDeqF; 涂~dgC4~Lm=6,xrg:v;D +E4:zɝom!uPqULT[tF%{ھb/#$ )KkCk8nH u*БKG+aZذJ?%_Nc"bApMaC|] ,@Ր줐&rӋ :E}Z6ۄ+J8홃T8 SՎ:)-wؼD| |8Dv)ZAoj?_l<b&]LuR?oZf #2}M+MWlDt^glgObTi.v|z^G$ڸ&LJpګ}eELY[]Y' 8e-8 wu:A!aOvH .ٌe-Ϣ(vƉW3Y$y)jB $d ţe$8K4uU ]l J:ˈy4m2  6~^vP9c^y5UP?y zǀ8.;ɑv1?H@{qՠs wR31ҥjtMx=9v~YTa%29 7JX!յ&1/nS !:#Qg~gG?+;n:4 3+n{5k)JzJ,ho mB~Kօ5;_;iǫWxe6Ҽæ3F%Z/?Agc9Ye)Dt`~dPnЌ mś"do،F~(_GOOS^WCGև䇆3ԋMac(§EM6\VEXZ tBEx%QY;/7>QbP^YLA4Z5>9@J)2B+rҴkΆ+Lv7y(sEqra tjV-På`j'+*] TZVFwizɴ{I̘Ej!S^Z,_hMn{OQx؁ʇN8(<4=nkocfp,-#dYuzz@gă*6>EXPUZBQ nZ7G=>Y9u7Ԋ:\ബl."̀Eݺ=G+h0BtZ B[6?;S*:&Tz;ҟ%cHq~~9^YVֶ+-!kҗLu&e gHAL+jak:H]/wl5Fo%vqxf~kxRގ$_Z7:RZ[uC>sNJ)gE*c|Ӯҵy1I*6Q$_n강6tp&ۇTle)Nuu*ӡEH&H}.Q wѶǝ(M~5tkyHq]rs%5^D='Ou4:"$. t389lZZ0si\24$]Wj=iہ=鍏i;' }"7sl&ȩQ*VѭxV;B ؤiF=Ii߇z)91XHm;>1GDTIL%[e#-ZnǰT3\_cO,f@j2&/!P oҷE:!<&g V9< HZͮ0'_]LZ$1RK7w~~4A'0z{'i?˲,B7hӳ ٬rJ'E 2})y=^onՙ6u{'O Ȝoz2tGKUcL | IL\&v[(lלw6{￵Ux}1x:I\TFHZ~d/Ϭl"p\DD⬪D;4B=NʰP "F;cGsu_ H_?1R\MKskn;$GI"C_2דh ٷ_$W3?:^ TCm *ʼs'x4 L3(  xoEwJ"sBA c^)i8Z눠l8t~sk?YM۪eI - J<4`ĘDa3][ZSLUsN)n( w*`.'Vĕ?4Xݓ=QC[f=Rgbymv`\$оYRݟ#b0ߧ! Oo7/I u(4u&gfȌaah>*ʼc>X ,'jGA2 ބ5nᮞs!տ9΂ 1y/`ٝPïzK&cY 딫"2$RU †*O$28yф `dҖ QΫ- JG ? qR蓝|GՁ 3DVdG/oyHoʣ6^'[#6oqM GHj\glt8xْ-(no^K?{*1T CRCI4.]@kιٍ2=9;Nw$ROI3Bu{xs<7g:)g*n?0d}v3TDи*j#26fSL *^.uNBT|p f l۲~ت`V~N|Y}iPryiR&n4dd7ݻq ->#{<~^an g3C;4DYPUtЗo%}/(g7fn2gـ$zjfķ_W0\C[VҘS(LG:I>W1*>8s_NOi型W7}ߦFo6 }7bFXc'K wzu@/0Ä  -oΏb:X9d*@݉wDnbjrn̛n@u>o2?Vcm鳬 C!Vy~^2op pg˪ml`R"(:@bA~Jk$]ǟQz*.p< r>fr(Qv2~M_!Brlo1v#m#ڊ\t8ӆY8" ˻0*lW<}3 zP1UBhx\ሗvfV%$:ESIP!FXKR$2~#;A]=/쉶L$896/Uf%|_u PZ9K9^n`4` pL"O\G>SB۪ p׋_h tZePzKKm5 (цX$-f!Yۑg 'R|94 pBF[RB`Jbj J9#߅'0}$ypwy7 뜦70uP?yKuwŬ2+Njy2#K/bU(kddny}cmOD[x55ȸtQ8CXQ IL1~ަK/9k% ̈5ʿg|ZMɭ o5sDZ"$T̎/xeW .㪙aat +`Ûy₳3ar9fC񕥋a\HN ]vI؛SսFꌗ_obǽ5@MXeAZC8,wa1;f&̝'D-dj aAO'Fg ^:צA]t\) /[`&:OO/Kb2+bIK&QeMKFiIt! ۨO, @sω6Psfuy~_zy-("-zEVaɐD̂5W2TX D惙K1H֟5v~ [mP|ퟔ~ vãܿ7{kNfğ},?Esi] u)'O_0։Ti7In[AY%Y'۫ 0:rgf{n3譚dעFX VN㥰2C4E ͥ|\Ef1Qd3'Ti:H]6%t&-X>&Y;&i{G:`TʭļNsClFv5 \'J YJ* !^oen+1Y1G#o8gv.O+dGeGpb3:imllQ"Z`\A jEy1ClN,lIsRPK= 40sy/σϯf>-#"%ǁQ | gI`XO9o[Pg@&D[u)_He( lj0IҺB{us+ѯvRN9E{tDxxG]1+[VzB7?w ΋*$["NzMs`()P8:On ~ &8AȵnJo%@19I$HhU`G*'-  /&f[!]-ΧsЊW&en9?`\lo ͝IXIsuAUiDnB:N0lJ7k o2$+.mɀi.[,  0&]…Oja۰O.VǞt F[Ѷ0rh'Ǝ6\oHf]~J3XpT'gTICQ}h5J~%ru vލ'M&ך`Z b*is&~F|Pœ{nֺ߽@Q\`}O ~p>2 w!-(^h|B6j,dt?0y$׏gJ6ȹܦK㧿s`Ro}Ij=_>dYsV Mc?*QUg$ರCS6>m$e,l YXoΈlvɂT1/l{ʋSZ?F ϰ'X׽gDk#w8FRHlQv<@$Z#tO]pu|YPx2ÔGv!>%&d7o<ϫB `)/ф/$`I=Xu>RO3p0VhIC9[}Wo X,WłCod'd`p-bz14nhgEa@Z[E@tBxڦ! rZ~hg̡h&)027OOO-}E겒Aq{,Yg(LL_TM(dS>V;UR,85Rh 3*zgfir9;w=VX3']WMl5зC]s/Ux,8tt>NėC/%dxl",%:D'vp:Ǖ{IW*׬f|Nחw n`ʉm9?& ?{&@_5FB@)M"aD'I(6P<D݌{R]ճzXRpe%Cm' o&jWWɼ\-'M袼qF$wSk/]Xq䧃ߘuA؋POʍ/D:\SԾX`%y!¸ƤtفOd1BbrdMt7(w 0sb|؇2&jU ĴJM̋sp r=1)KeD/h.`?Im6ǿ6W =GoDq8⼡<i^qWy BC_z|{kԈRBS X7E"O=(.jn#kE(ovEHfEl|_9dR'wN_.oߤeeܻ6[ЯNěPbu)|z3s۠&j\]l}S?{AmQN3SV r3E>FKemi+z{ =x|SKl!źF䃴C78W‹De0]7|)-ߨ^Go_;ǽ AU . ֍usJ"*JADE+-i!l}mZSnN0l*q"$8BY)?XRgJE@ooއk8, I[al92>]jb`/wz>AFJDaxIP~Lm~ewmlh|s >#.$M06(M)2<՝ 8S<DGCUg Pw z:_j3>pw ix/d՟ (dj)[Dq~*J4m?#%s@Vܺ)L+x,!Nz(Iuowa{`/lv4yUGehv_pjϦTFy,) "ie *'%,sPD,Ki 8Gj!Au0{P6J+"@vB]+ ʣڵ#iz!`ʖqYvq)|w;t;"4+x9Ph ~  i8OA׏b$ 3뚧QbXD_XH6 rQ9Zh l'Dd*>8ϟ4A0%"K. s-q{xѮFB5_-4[j)i jc0aW*V"Mv`nð߆jVuS[.kZ }}ݷbgwqn3AǦgM0:_V-?Rt1ǛnΓȰ;8 Ϛ}׆4;-,qfI8_#;=5ptgvͤy#Xy\owW$4R&~@5ҿYx]{k{lzzloJ_6ٹ~^ZpZ!Nol{ee&K<(ڿiSԣ ڠvA"MG/n|\hC#/u Nf`GC$pGde0$EFT`gLLJ/TkvMUKM/Į׺l>Z%9Eяo2 "~|s?DZǴ%a&n: #:||o%($AUEw.8(a.嘐ׂ]ꦭs-rRDQ9ŕVUf?k7b=oTn]ă{f=<ާc#/b.}@{ ${=xT%u3frQ,ɝ3i9ش:K(#cd^p6pG|̞ѧBo{g2*pKD)l L{`NN@%T"}7ƴ gQOC kipq^h.[v.HoHNƦ5ǟ;EQ\,\UwC9ڀɢMc P i|0KaMC؇m[qC=_2g'krT`,RU^q #6*x+*P0pdj.=C1Nċ?$'p#O2|#901Q8fsP-o{2p@=qG1R!xT};v%RҠwNūܹX 4*֎MJ7fbX8SNRź1O\ rKF!O'1/=20$Q PӝPd5Mk]c9TH7B C<*J=lm ZˣKSmnv3ï.ڇUJDŋa_x}vC%SjweWDD,_#1+}ޚ_hH:%僦A8uG/2?͗uv]87rɑdd5kt L\aJTQQ\UF;_o[8'G#2+>a>=Ra \=xR##Vá/ѽY{,5R?POӓ^"3]G?m^_>Rى͈FTr¿ii7P.1ZԨ%4oA*2, S !d-\|y="+<)C(qwp=1OMeܝ=(/PbNIefppt`'wg%{qiٲ&N;mrdnY,g])%}\]SuʼKfk煜v|v z?+pscK>H}E6>R:WIɍ*ztmY螙9v6Fh%W7mP F.ze$Fn;MuNB.+J[apg00.<*,a[+m=2vl2qQ*H_Esx-vqf؈y]:|%ʨ4gp BVI7ԽR=Bͭ,o% O6M7{[{RGpuOnn/D2fRtY@l]3ZI:4ؓeKϸ00FCN8{AT%ׁJ, }XJ:[s_f/L0+ǭZ`^3*9Q@蚤~Df% (!%0i1gVT$UXr Wx l)t@p7 `^Lh )J{ ݫ(I1e`@9]msc[&h pSm~Az^,wjnj S1wbt>]#I(u9Y S. r uNi_ZL&~xkI{WhaVn4$@ us!\PѷhiWVb-50Sa[,>F,UL2%~A^;f#0 @{u] 4?)ݒ901MU 0zϸA$=b7+~(hC3`SPэ{!Qɟ/GO; ҡBZFi8sKS-MC;*ܱr%jѪA}q>M6Cw\@D=.LJ5{F&հ<bGC~`K\ԏQ7 OA y9gD?#C毛76l7|76g,|Xg'cDl4K\,BqѸsZKXlkZ9B 5##j)d }1c2x EHxajq8}JeqkՀb+\VmיZ`Gr0ÏO5>:*qW)ExqK[^UP8%>w !'d=Kz5"i7ϑuGZiwrĈٿC#OtťłS#*Nu]J9?_ yR 6GiwFָ1q*?UC;OH:Ns䶱fy?\?=%>^"fԹװ^{G _:;"`htN\صQƜq&fX5xۅT vlj),F~{SЃuU}QSLZ`6ϟ#ᙾ>DAYhVuW/D-п\2 }W Y3~C0H@ĕ\›.PZqU`#:ezx E8#u #;R>Nl+z%c`mlFAcX󦟌vdc+mc~̧W_q#5t MoK9Dq>sˬ ~GӂTFTz:rl#9ѿ㐑!AuP8rPÀgFheqU"D-K}\3tڎb1a=]ꈁ9u3ťNC#7^xΩ[L|Y'i'(S,9%SlеvV#a9_υatfūF 68K[%gx(_. 0UQ&J1';u׻-hk36t'/"17wqXY*; }qӈǤP[4(VJ?/}3hX|95e$f!D /CeYZ@4U}\I,FmZKd'Zkt,zGJPL{Tc=iI̡e3ïYkF m(zN֏0uf(-;E}+bl$3 É.%_:fI'4`nN;i =F8z=e ',J(] I]0`O-hfF铥]I #,(P5WPnYݡeYe4+uӤm(BxYZ;_Ԟs!y6 _D'Iªa0= 4c?:AVV["AӼ փCgA)+kCHmrӟn$x0U*VƆ7K[VҰ0u9fv7pVH=ǵdr@j̗7 {_4F v&x-v;NϹ㺠ݼ,rkпdpHsE;NQUoɟ0ǐP.{|f]׵4%H"uplᘏ'.ֽw1 <O)Fc@d ɧs8ˡl)q=I,/&r &Y8F-MzUhZlPˣ @8aR,[@oڶ?.WRi/cH~3>rHhőf7jvk啨z/vr,1h7q.㣸t+o )?un1Ïlh@Xj׊aRU`i]j@]d*k#Q /EڣZ*Dh=,i}M'Ğ HVO^PF [q07P3`0K/Ps~ -)--oHZϱ6O3ƒ&zJޫX n<`َ6v-1Ǵ{Nuxތ 2Ds_ϴD l]rY:ɅJGܝS:/N.H[m =#%,/NE?JY)Y.Qw`G9?0g돔Hi:?uk^JTsʵ~q3잻*,. JEL\yO)_gAH0֩VM:i 4}B,> `^H&Z!8Ӥ3U҃f2 RCn:g>;9 nqЏwVysCF g~ ve4d-2|GI/VKr}DCg_D>Uf/%ًQg*2xorE\OolO R6\<Νj?78Ar\..c"ߟRP&]Pۖi1_[;wwMsD7dऀC`j;J[s ?*eT;c6F]ݿMEq;݀FVJ2W Ha"8vJ5os?rZn׶e!qP.ex[;m)`7ۧgJoXqj@ΨQ_oظY ~88ʳ]UL{_TqB)Q jgġ,U1\$݄: C %y1ja9HZ(m;Q[9DhY>4+I7uC?yJǩf#d]"IESqEGyq^& /6?F0{,Z\ի#l0|/NgnExvZWj޼gÝ"ʁYPNl 1pS|%S4. $ 0Ɩf{i1R;b'}j^,k ٥FYR&)ϻ=ӰDZ\`-{t5IJ#.Ϭ'U`b5 OQ8h Q}Iir7'H ƶu\JÐqC2}Q+)&)F>ǠApYoVdXݎƁIB=`7 xz^Mi+]vy°R4눎oxvi]yI*R<4?E0Ug'H ZӇ$I^+hRpTLrI[`&6c.nJT"OLtv4 ^ua4"Z,FEN~!Aυa0By,렡(L-ho|'F YWU%+ *@CV]~|^Xj~*!Z뀣RAm?T?K \|Tx.Tj )3+"/*9 o<'} ڀz-`1  k4?N6kjQjܨt~w4/>JB=uHw:`%]M]&˾h\B4*dd;7< ǣsF >[/e ,Os g0HLFjAeq෺\]x7#m"/_ؚք.SR)ų~0ZGa~enq#IJͲ@hʍ}'C> 1|A r$[I2Q6 e5Ϣ4'CB= Z] t#,iC1XE'RI[@y~np{"Bx;l$rQ[>W1Tn0mgEz6> Ö|ԀpOZKgX^lu#}TL*i/{alp]K0_ÞF0lT5I;.>ePA {aZ&=4\c9t$ԨEQNK,[ &?Xr2t d;<ϱe7N؍QEнr4q%' P3vފ3UZ,Œnw^z\By*?), Wgz)z#&#tK6yBy"Wi XF,^R=D|5)ŮCeW{H[U:qA s"GN'{c#n{1=i|c+#ρjl`ŌL<DbB(N3yFr?C8Ԉyܱ.t]_|X dOF@axiW kOjnD w95/uF8YbG@rIm.EkiVD֣C =30W1e! %Oۀ&;x?8&FgRz皕#6bĻBLt"fJbpj+'K,~j$mH7fZ鍜j3=|O ň@3.ȱIʷnpl-7c1G{uuG+'SƱ1GZPX`*!glسĭ5sz"XO̒Aܒ-WKO>OD/$|ƍ1at?Y7sxldA !qcd0D>TY߫;~;-YǚU6SGɵ_Ȍ-I( L34 qIa9'~ܞ6&ێ7){gVy^IWB%̦]b5v'U; 3|5A@W{N~ UcɇDCl_[ Soa ÷C:'2/ -Z&q=HqҰ0+wJ9utL+֤`Vx;=DQ{ة? FTBe0'>9] WcWm.Zw|kwcV%nCe3>rRqP?pŀ*Z=,^X 4YHJH\ğh\phc,D3Qt bu v8e.[cR`;gyVY sbJuo9%M6؜y!7-zuwC3"kD1k\y<~o`]pIw * (U%\.~l"[0[,  GiYgayLϤof -@}Oy?"XMCU .|e&e9=7۾=Z]0MV`Q`ʰd, !.HS$62D]k["#^e F"gґeBr?WXWpoazBL5DEѩL2ML. ހF3FK%/TSŇ, `G9IbSw޷參ْg?9cw9nĽçh|CEo,(h%EDQx!:UX6NfOvK;\9i4SRV_~mf`|p*:,Uv:H ~O ?$8Dm,t^2 +Y9'Iac]G"47$VEf; +J:ZúO;K҈{5&uҙЉܰ.ͭ>ᥤu'q єǃ=w=BQ((\Sa:ZiߔH4O3KA(F ƁmgemFP `fR'rY2Wyz?Ԭ#MHJ/@ |BE `Y@i[e?KEt~[SPi qfS~Jk&qCl8-WƖ hDT=_3BK{H{4ghaCgh)6' VM0Z=/9tdrH~1:0GSLw8j2,OZ鳥"`ͷ?Nv,r0o9.D<6/ғ>ЍA?Q+KbႚT2 OTsVWk:ˊ<168TR5 Pm%plRck?j zB1QS,.q6ADP#߉x.:ev9-Qj9lU/ 8KጽS 줍z<A;rfʗ fEvtލK XMFΉ1/&^d ޻}@c= ^ eFxU^a:,Ę^ 6aUⴚ@ *>(s/,m!rҴWupwٳ{$)\./i67 [QD\qآʯSN|$+='inТF(I <ΞgƧZ?2t fعOT;nfN;gǟ^9)ϜqшbZ^C)s! s>BG`s *!Gp+*  lp (r1$7TݘR} ?Sf|VGah%cEΣ*4 ikb8j#$)(KfsW.2Gpu{]^i4pALЅZ`h`Xt? Vh0gdoOHM:$9GK,n?la!v߂ǿ1FJlضyqs<|V;+=L'GצO>pg.@ h_ Lدϟ z)@/lY/Fc&T^S'7EZmiQ-rR +1ې)=0vhndeJ*cYqs‰%m{Ŗq*$9o)<]leo2deKl@I;QuS4maSa`<'Gw1,C3A\"F:1#6chcAK) 1':TqP c ]2GHREBo6t2|]\+*zPOxI= ' /zDj'X ќ/+$N&V)0xLhz0VBm&9ߕu@q7וޚhFYB )H6Ojca- /oW$#{p3i$~S}3 +@W,X!AR*LK^BēZg*-9EPil|N J,vZ ;]=CIyۗ~YL8Q⷟g i<,"afA<J4OJwVa!P H_w )]Ԑ)k6K/JP9[[}iKY#P2DwGC'h8>MRDU}V=@qYjY2`u֋CSx:?ɽߓt< L]Cr\СV%jZh;^}PrE5~,[Gq^Y]'wyl&3!_p`- Fr+_ T *yq+6MTTs%e7ȋ%Q䕳%bXb|xV<^*02AX(Z8릮3ԁl)49z zVKȈ NQDj& h0)ŴڱnQ5iu[yޗ\8cʭ[ <} 2ɞ ]dףEF!7F*-6W%quX}Nқ`@?t~`yfty&C82 z?IAFڏUR`~1߂(qߧ"=$ASw [yq59K 5Ƕ<)By`L \uBdx$<~%ڋ>]7Ԣ |DXDuwC 2<ap#b GN'TeEe3$ɐ&4[mV~TLA dRmB»':Em  T[FgC#[L)RgM9y4-QHϸnx{$7+kSʈZp4_& R/^{ʔ֪k;UaZ\r~WI_-r8U+2jX FX?P|b+ 8\m{$fsN4;b̄菫Xa xxn^BQЧ| ~+*:8罌n2XFnAs PAECn)d jk6͡L ͆rNXj?@`l] ĂqyDh]b6!tK&(psOM lqf^"kh I, @s ҅w obpچ[mx>ȟ4|6v%)w:]F̑pS^8 A-n(nu0m~qBL!4@衹|Y?TvRtHsu=9v 2`|/W' a)J@2gae{xfN+؞x{9CӦf k) 8AV yY𖒛#V&U=g#J!NbWG3?hi4N<17{fFJ›uYO Q b3` |4SH/5\{lYكnfV|J}?Sd k'Fâ9yL &KfI\CF0eOϒԟlD>mN=9.8'8r!,Ťnj %u+t(z:k8y8 ⿀4~&m2BsE0qO ["ʥM~5qCMIku^2ą|_8D`Y[{|B}(Mj fB4 bda {3Q#pX7%kOx@0 ʝ~YkGrw[y%VӨRؽ͞ fs( \ [q [UeL%ubE%\BUpof]ϴufd-W6GW{,BWV_Dz놇K&HCS}c,xE64w&=by4K,iWKu(4͒}":ZEK3ueY~k`W΢xdAOWt!+Jw^ D1(vj螤:WUh#Y(hE 9DRrE9=xU)9!_ѻ"G%/6?1]FszWmp o-_3,r[V]@5-Sg{*V %v><1#]B0W~  Whܨ;+}D*L[3rHV~>ȴ4G2?H80:ѥnq1WEl Ab]ft!+qt9_4pgj xYs= Zp=6,. ~fÖf} Iih2H E+v7Hi;hRqy^*;1)'G_bT bCh1-6!.vP} O5S)KfRшO_.lZoTU122dQJ5CvSCLm6@0͋4cse܈ 7QRx.JSE? } V:S,}RLK-6yx-; D7xL.ջ݈!(Ћ2G7\dN Jh-RM 1+jٕ{3)7p*M崌Q Zbi.R.o@Z>3t졬3L$O9@2vQUcJLd  MW_֞S"< !k}%}x{"ȨG>7_ fH6U} U-NFn/J(e<x)/O^mJ]RqLr8{RgiC2-T;=e٩m2n93Lu[oiOUUؓMx.)`s6@A0Ew>Vи-`ķZC5P\i+66۸6i"A-,x7MKQA&V4rz8R\H0uWC{l8Ҫe>ό[9W$8Fr|kBx\Rfv@[ȀsK65gM9Wx-cBMZ(h$-GB j r-@uYbY>{`3ί4VUBFպ"w6ˍ.&rV`>.Q"!9C/Wc9l)>esD(m> L 9Bwb0x {*0h#PA5B^B0^Q) ?jYVΜY`>ȣ +d]ݞRh1-!q<`^'$\n $a~l~C-+`9nLxCex6EQ#u(h:uAB.G9c5'F: ڛH';(XPY+g6M0gjD; h!&Vi쥬 㱊> nb} ![ ߍ]u4R ۇDz9!ۉbH4+y\Wzw}Xp".li5M= ߜ=dоsE?6ݒߘ\t6Y9dz JuyJ)cK^r AИ0 u|a9G>V [:'lSJ\D3A4O ; o_U!q降U%8ow7UR/{t露yj! .8PjUESr89=UD:.9V/fi"xf0d&x؀POm嶅QY n R[ GwqWKk5{2#$QFo%,oL܃XֹkgG*BCC]*<ĵ, Դ3!Py}c==p.wψߠvW#mioIPMωC} SV)/)F["JeeNC j7$^jV_eF$9aoXⳫ\(6N?A9Jא%=M>UN9?' { nҽCU;#{ :v| 5w܍Ւ!Kq,a.g_G0zMiZmB~=^0p?B/)IVE6ۀ*jb]zﺾ ^P {߈=$Չb}>2ʃ4վ_,dkG *y͛#K0@A=L׽=R8W 9,'i"3l+$ʙ p!7 VJōvpjk n>9pN{3QNOaS)9A2C ~Fqcdț s ͒<ݧ3*hQ\Yļ+,"0'I3f))!l+f8R?8# C} ]扔@c~-pv}uT7JBß\ ( i2+Qՠ Z-xfU۫z//Q([XZhV16}q긷6ل<4H DIXs Fn2n~Ax!ax\LLՃW]*Thh>ZM$ a/9 ZbO .uTzԿ])jKx9Z*@I̵l@pN _Oڕ⽝`o%'W8pEuَxdQSCW{u6TvPĦ:GsaqM {U3_ 51x ɒ g/ YZ