sssd-tools-1.13.3-56.el6$>XmuiYK>2X?Hd   A *HNTbb b db b b b!xb#bb%L%hb&'9'9+9(,Z8,`93h:RGbHbI bXY \<b]b^bd$e)f,l.DCsssd-tools1.13.356.el6Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP passwordXҿc1bm.rdu2.centos.org vCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxi686*ɤKSA }5q"1EQ :bn3] 11m:+}MHOs x?sH cC A큤XҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿVpnXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿe1ec854f68372bd0e1fb6291a2573776074e921bd39bd69a8d5eb8da2c44dbc38b16a09cd1dc9fac7c51768c27ea19bf1bf0178909122c473d60b317b832c936881b770495b8cea72067643c78870ca9a78a6d1471110d74d39710050bdbda0ce2b77b0cdae21a8dae1bc315ad375eeab66c01151c46a8491e86e483a753062a82fef17872487505c20965039a68b51f18b63afe029b14ac4b0e403703b050f3074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45e21af5f3b90f9ee2037534ee896eb380f28ee4c8287ae079cca647e0c0d110f48686963a818eb925ce8bb0c94f9f14bcedf56014ffa17275455d2879a0fea2fecee8dc6123da04ed246a9e7d1c724ab7dd4d41c33f7923ee72052bc8a4b934763363da7e47f2c3c6df61a7cb83fd33d9eb3ab5c8931126e6aa274c347902583cb57ad3622cb9e17d2bc083e990dbe9c59cf2c0835cfb21210168a04188196c9e18ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90350d84c60491f81ec38582151a779c4e2aee537befbb0bfe275f4af2f4d91a6aca6699600e6c590db54624ae492e7bd5af1db45651ebcb0845e606ee559e903c099c3dd8a113fea8f43eb6155a4354bd4ba2aea406090f3d764f486c3e07556996ab7f4306a908defcace37f1f6c91dc4a2209ba0ef8dd7db7fbce0d4f11aaffa8c15ea2f38ae06aba6778774ec66b34427d8643e9a628e459fca2f53cdd141a70cd03bb230a00adfa378b30947b3c4e4f621421d5598642bf9562af08b264038b2e13af39c3346e820dd25b1cf15cddc65f83e8306b4d14e31d1195d193d3aea0de4f9fadab65b5df315e660634fed1636d3838895735028619c989826cb5cfc92d14b8141c5b61150636295bede5443eef854b35c22858d94d27d2c4cc1809266f7df05620679dee3ef453326967afa37b75389821088071bf478aa26cf13ee8246153513a6490d29df0340aef9b406ecf914d9fd7a8308b0516d609215b4694c32ed1653e72de94bd8799e968a4bbe1b8b2b9b4419c31cc4717c46345219f05981d65f788e6048bc9d1c4c6b217409a3fadc3c5202098a604b69c1049123183ddab8a97d33f0efd00515183d712552a7fb559d420b2382a98bd47a8aeeee7ad17ac5f114eb8c50a94cf87f49ac08f1f6a78c739b1d66a03156b16dacd14df3653c2bd588a3ea18eadb5c1395551ed10740fb86aa2a6e3424550381c92edff47d31c31c18d4e0c2f3420467fa2ff7f54badf57d2e9d03452d0315d4f328bc751516fc4a79bea2e43ff71b134457cfd7ca6f09d9670c757d031ffb545df1350778184cc5c85e2f38cefc1a5fbc5f27546a44f1b906dc11bf7847b6dbfa7347088c3644e8a7bb4fb18fe22400d07409fe8bc6706e9293859f315cc1df71e04a9ef1f4439be013ed636fff2def8917761d7121cb9d135a391457885d341aaf2a349d24a516186ab7287f5a6ab2c03e8afda7442d66c4b6735f7f2b2b644f0901c6555371032147c552448e5bbff22e4dab75d9f0693c61498a6a474cc1da399b24cf6e74b46a9f5b20fbffd2963e906ea123917cfac0a9a145b66952b273068dae0691872ff8b6fc1d5c7eb4a7e96dc9944560779ea8cac92be114f2a615d329b4a010f54b2e1aa82e5fa037daf771988bff39b18e50d73d11e86914487578f0a7d22e14bdde49d0276572df0c93118d7e18851b28e315cd0b690fb3653b48c041c1d18b55521e967929cf5519975d67cc935da4125c3e4031f740ef0691977fa70a7cd8b5fc5c5640e8f39293bf0d0fd2dd002409bb268ee5b7d5c8e9f5a2e4866e6434029b91fbe126e9b533814c2faa0a6eab5b5702367c212a4d67b56ea340dd44345ab427050eac3b66b6369040272b6395539ce39e226e0c922b03d49d6892e97853882c6ba50481d7743d20238c903199c59eadeb3fcefbf87fdedc2ee4ccd8d091076e2949dc5be54449913b808600697856d77d21e8c6b015c713657cce66a0b45917c3984c95ec9dd46b52bbc394c999ee1480a5da334edddaac82b413e6a972b5b871175de92ee547fdf979e6e65996bc3af2f4a47d1389457c87c49d9063684934fa435074f2f345e74b4381acdf58882d46471862ec1f4bb83fbc436f5861d9637216e55a43f3af1f7797aa78e950971e876219bfde4dcdaa55b851b44e3a24f1e6c13aeeb1245750e4a3f529e459b76904c07f2bfe70df8bb00c688dd10766a99d0370dab32750bb1104d0c7ee9490f72aaaa0fd37cafbea446666ab88a65a1350e5bd28bccb7c9652dff2bc19c305118b28ae971fca9a6a1c609bd4ff0118e29c72144475864f3eaf903bbd346374cd618d03aded0b9d85bb22b18ed76d7a520d73a7a98a763f502bc8280d5f025b1ca3d6cd38a1718cc09d1748fc1c2873cefb6307c94a7bdc75d597c98c038251087f2a23619b583a8b546086a0c9f418c4af4c0727e43a693f87c61d7c93860c972436b203a29e6a69f255559306bb17c7f1adafce4335acbd746c86d7eeb69a8f1cd845e74a05226de15ceea5e0bb09516fd684315b32690dcf357948e1648bd97b2a6664bcb857c1e5fc7be27495f3c2e99aa4bdd98a7dc152a75b1135f31dd5ba347cd62cb39bd94bdbcc84c3a6d505dc36e4fc685a81b8b1b79d9807a303bc4a5a9e10c184a1581e77bebc6c6cd32e0a20eae4f4a0e4f4ee90d479a774286ee8dea1851a877114f229cf965f4dd1d49332dc9c066e16edeecbde3014cec0ec6dbc78f271ea0a75012beff5e88701e02fb3e1e4dac8b9420807841bb755e2115c6c6e46b2cdd3c365407be4cfc0d9ba04335d0fd8145b67b045c23d30c8992acd37313ef3a7f7c9b0b703d143f437b5543eba373059805f2e778369398e0af93a55c6c1e962d7a6f476d66d10ff2622f619147e1c39edc58346d17405227e7df1e9f6336c813e618f826ea003f18d714d22e6d3cd717eccc3fc862b25b972d746858157b52105dbf6d37b9b4eb52d2a544e44ce2772184b4746e763ded39ecb4212ae61a05c254b1700fc47890ccaee2d08cb1530610c305cafe9ce2d38267ae622a6b7aa145ef999f128730ee832f3b04f41117e4c0000002c30d2e3b219c4f92c7a3ba309486e1874894b97b9004b2ee16c951aaa1db93c161e54a79d9e5949293b3fb5aca5394007c33971a5ad4b1e0acd537ca6358a3f620ae95b66b058ae3c3ad08e6688a622225d05f16d42013eb4be04c3761a66e93cdf716c743c02f68d39f71441dfdb2686664989e4dc0b629984b2e6aa0cd2008af061a1c3b83a024afe3f6fb073267a63cfec27c8c21fa473980e79371ef2b028e680567692def0429ed9209977bab51786b070bf54f8a69c5ea3aa03efd01f47e44c4d63ebc00dfbde73cb79d56e2d6551404f3f7add230b60c632407d918d3b04644cec57bfcccb0e3b7c5dbb43f8df8167f01ee0e32459dd00c9bad8c021647a6d93c630b21730d9b8d865066d58286fc1ebd25dc5f6119317c9749bb53e25179442acdba94c51e0f07cd3bf74aab44efb6ddb2a9e95cfbd76b4c32854a8c5cbcb7e4b0bac81fd5ff625330e230d3117b78a91c41095fb786fcd6509bad5436f2ea04a06301ceaab2f1490b76e494ab4927e340121a5ac02bbf151ad1fb3ebd42b8f5ec440e2c5a5f00edd5c0efcb19834a87e39d6f3a2a220d64272a18e15d645e576cca2f096d689d03d6898f0afe87ddaca1e905d8c368bb5730f5db2c102b487c47ad0bf8cabba8c91facdd4098f69facf4adf8494ddfb5179a7266accd21f434b602e562d6e11de028ff27abd1bdd4944258d5e246e2c2b056fe6e444ab9e82cfadc4f9b50123f031082ec69b3a844022f9f9b41e8f407d470ab533cd8e2219e5b69d8ecb20c22d514c1e15372e3d1e536a359272218cfa6f9e60ce38eb2539d222c9af9a192a73908ea2cdbf268e9d8fbf457e3eea1a45590ea8f1ad2bee83a70c9ffa0a528bcd61e0eaacb3c85bea64c1c286cdca88c6836a4252c16c48d7a9f2bed2ccdb9d06d4930205b81415331dab055906cae37e1aed485f5673cb60db74eabc239927f99438b7205875343e775d22d65cc198eff590257e709a4921176a33d8c086e1d419acdaa5b60c25afd269427220466f09c759167b9bb3c288d09733d9f372e17df19579ceb4a6852dde577c73c323eab60c92d8a977fdf6e12b1e6e36f9d8cfb1af29b014701d677522bfe6beaaf6739d9f4781c59429b51418e670fd8954e75713bc336838869ce45d31fc9d596cf305654266d0934f3e959c63e179f9ff666b2a79f55a41649897f04fab8e8596269de7f227bada85b84c04bf8214c716b21ed3775ae200rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-56.el6.src.rpmsssd-toolssssd-tools(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0libcollection.so.4libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.6)libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libglib-2.0.so.0libini_config.so.5liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libnspr4.solibnss3.solibnssutil3.solibpcre.so.0libplc4.solibplds4.solibpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.12)libpthread.so.0(GLIBC_2.2)libref_array.so.1librt.so.1libselinux.so.1libsemanage.so.1libsmime3.solibssl3.solibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_semanage.solibsss_util.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-56.el61.13.3-56.el61.13.3-56.el64.6.0-14.0-13.0.4-15.2-14.8.0X6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-56.el61.13.3-56.el6 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnu?7zXZ !PH6>]"k%n0}:w{{.E+Ǯd_A CC`_uwa`guo?vdžs_zlz4p_±C Z}ʰ+u "xB-vJ/SsyRm2F#`Bxzl碌K :{{nZ_*S@6e. [ŶznX'~[Ydnz-` Cb& qn䆖  pAny$y_(vD=ʹ-{q2_U"蚃 siOh_狻u{NNt$u|zkրQ4G!M"!8N}sJu8Nhj}2 p;i"EtEЉ 4*CzMzV0<(蜗s 1iz]qi"vG \Wχl7g5;1|rh)ڬ_fcVSK$CtKүHt&v4l$JMa];.ޅЀ/YPs|R;(z`}+1HTPŴc'g|Qp/VtJ޻5NҨ?KԽj1x>'fg Iw(sA"G_{4q*0 ̹Y^^Edke=vJAȩڬQx* oS/)$i>^e5P[Vu2 I ʸL#z gћ8Bz .| ^S}w*ZIJm.5q_GAGyư J rig@ UP0_AJzd\X`km:wָ[e%}Ot  Ru%2$L_/ߕ *tIR;=գ|%I,ڤv} hix̭^`2(!4Bxq1R7S*6l^&/Z24?:`|yN:_3b_ ,d[}'Mzi>$8bD[^jD9QM}5+/[*|;pݛ!oVQn60ո!Xx!!)R+I=BP[ahR )q%B X',gAtc&Nl$A؂6،J^CApOk k?0T!J^I- 6-BUvH,_3uTgq+`ψs+Le:$b0N 1 p.8N,/[ROC &7=8EV]$h$w &NBk/x"#W00]x' ?\LYu|yiXȣB7ps [C**}'A4eӤGB5c|W?rF*]-' ,WU ;MYԽ:A@rëj+åp`raGѥZ?Y7%֢ `یygfjβ(sy<}ulYT6\FfFtiG'2wCb93ad#;P}./^ZEZfߦa)ft.1w88Zqm6 c5.s9 AOտ F_s >4 k=B͗$©ouLX6* xAyz}=ȺL1A; ǴZ+~`θ)гcUsw37aYy->֡*1k &>F\TtCB}6Ap-L|`{̲zy| AkbJsVz(e $d| <p (&eWPAhr4\;#kLLV4es GUlv5s[sqSx>ndCUrbl>& *h"v)I ΌdX>Jk!LJ ^%-7-h2DEhoWo?i ` .o1ujlXG\s1<_+]3s]sDܘdbcV76Sp`4 '(Pip(*>KfmKGI/[\MK)C6Aۗ|fniU8Kr?gZ gR+kHIMZ\RoQi pmKB j41DRѻBAN^x *^E+c "mhK?AGNnEfn[D1{IK3GΦ,:MY|ΜǛ0RCLo 02 ij6?ƒSB y2aհwGmѕ:$8V7T3axg9b#[*ܔLOrfWMKo\_c֧K7X7ՇSÑh_Rļ)|,Py"G@;Rvfl[@m11*Ww|\Y[Fvm{@dAwy/ .- w{TME[PDKdbS}v?u^;Cⲻ;&E_~y|rE9Z`^{-I@*g^3$1Gpg/ )D5VGٝUțmj~[׀>2{YX)K:-\jAM, }B82 8GDӖ_¨5GޠB؀JO],b׶~ΜpF@LV#6F}яF!6y7o)ʏTd&痉wG$q6w'r+&ӂrI!14s e*߶(ydb<7ff.jWߡvR1H8{Q\HdPq֐H}RR]UtYm"E`\z;0_?TpUmr? U ҭuX fI=C.=9"yM|Ed`B6]X0}岺z-YWOŽLG1dIVR^(p|FG+T;dxK,pR?4?T+2L˴9~~4I᠀Q`_\0'ݨVFB@@;:HUtuUsw֌Ӷl*F,e b;Q gⒽmҔz9gZ]K'F_z+h݀' ;X]vD8"BDK_VȎ5Kt"ok-x0K^6?0_s94>F.?)D׺mKג8r.4 )uĎU;DE,r@L B81P3x*mK%z<S'fGօi1aH-bW驲n!?3ݮjvm;`F0,/-'N qw+P/3y  sHhԇ;FJcpW9,)s-@3e"R'w=g'H!pd@L3ZFmUH^2CtM.Ч܀`|YҸnPu wQ{#UuTgԹֺex͋.5ٵGtui"8)\1%Sqg_W2EzLyϙ@RO\yׇO|l>[ #(t2她pj~]%XD,ixj;:ZRh[bF\V5|8𱚙FFUE'CAHޗ˳u SeŇX6o?2V5S@}y^cRTX<; O2 @}<~y3i7X]4F }R4P}Wd2c. ^áh5sƵ+ј~9~DƇ׌ L1aܟ?:{.qe;A ia<1-ԁq2<{gڅM=k˴!Gk[fwBBR62ײptw0aHdڤ)ţiqS&h_w];SF?jcʃ.{0kA#0Ñ'ҁM3+s*A)aBÔ$1Z9`6ؑ ѹ}NT9h@8Mcڋ/Ki?~,$B~a*02r:6BC= `4;~}Sm~_v[s;U%蕝]7-.xiBB>#B jWeZjsW*BpNiD4QS?EW!XsV8 r+Kuh;gqWԂf97PVD$Lu ϭ!*%]&;şhd6lS(3ˤq>OhQT {#E7m :$7{#ra=CأK($|?j#4RM!s5ŐECJQ^9oz 0=/34\`Ծ:yM?I?S*BBjUdPADB4>V#QC|†E!yAӧ1uP(\$&aUYX?6 K(vQ{Ub1]y6ж~4]\ 8KٳJp/bY}6yHBJ?=dC(O`*J|cɉ\vWLepN(u@KlW2ѝS -@3)jo>fhXӿ:,6LQ/auhggh7ȾPQAsp/KԠq$܆껮LfF-d=-؉I-MO砘*r\?gn¿BU'IMhc&t#bl3OoW쓜YMS{Gp*MNU6g,zK-yE?TYe~dBܥ!#! k`  "ړ^&AwLy]jp&ihM[m,i=Ԙ $Qm 6mlf)Y5wKyOT'S*.];J.o (bXzre}ISZz:[nӆ \ԤCvhTn'(2 ,jT*C\Y\v kVb}8ڈsowVHWZ̧T@XGh%x(2i[#;#q<,;^fSR*Rwڏ! }:CmUXhP` :;]]˒$+/%f߲2.lnؑ?H/|"P`RgL{gUwikA0*ו*յgs8IF޵T斯PީYwʤP'aih%ESq0H7>zpŎ͑83lɦAiEŰ\EU6)_ ;Uy(+EŶj@3v8IbVj~"j9BY|@]dZ@m$LWӒ㔯$B^o5$n5FXNqж KV:h.L:#w}eIAkhj"Q M\cM[GB10 INk.aAkKɲ(8ܣmcـCUr%UqXgd$DO8)"{[+-x}4ލ/:MKM$l #R P)¹^vYt$#fcsJ؊%->Z'ʢAv逢7$U5Nuh3Z7s=]d; Si2kˤҳygNpvUk :l i^<(m>(<4=Q,)wg":>jJiT fUiLeqF9%M [`P ya;/xB"dhw WGP9k{)PKJ9"X,W2ӴNc~9M/H3ᠾ&}.~KL[l%µAE@qS}-_J#n7rre]®XOͬ^+1sѠ<,吣E⓹; n= HL֩? =")zd>$ B[Dgx~$ݽ2+!1`3|kCCJ+'/-JPЋhD*Zft=nDRWKjhSKvL`:xir4-V0>UF4b5*&VJ]|>*ck :SINx{d68+xJ*&deWqDMFG w89Y|e3ad{ʴZہw,MYqۘ\GWTXퟅha,f|lb{t;KOVuq?\o; aϔ\I6 "8᱐ Oo;s}#'8}CeyA`ZIT\FO1ѳ{?Ө r9x\QX ]Dbʀ䷢þ7n5RFĉ yBYi8Huj ]'թwvI,;ā -4<֔ cf*/F12RL5Fr%dkrT!|Dښ#vUeaи,ad8bي|Cb |TЄ#A|dNa nAC#DP_e`[&FhO$ZGkxFqsKhr@#ӾDD4p[s۳nav=@o|`8.06U}ޝ_Q`eY.٪8xuTST r4·gqgqx";j_P2ݶv6u/g!G2Y&ʤ FdO"3ȴ7-G%1U0BI Br$ R[\Im4 Q $ .ŘKLG+ \Q։u :cRRbaum>Pm޻7mOi)D?qp ೮ז=Ίk ,W9&`oZɸ_.L;/$*[>' R6,F>γ=|@"rg` y+-5z78Kp2 w.06]at_Ts.Hvז5"ZҾDq{Vt!}9JeC#&݌@/ <(|-_g.m-r2't1)=αZA}R=ƒE6DX%4QJ]rP4gModKA .eJ2,sf^i)WO /[hg(?S=LG Oz(;5Bcc832RM4\F>]@&Mw- \yDžj(V! L[\vNYUK( Kz-oBC+gÕh*_&(MilCh7g՗zKVsLc>\øvj"Rʁ1Ec;XϢF:AC0`hD:a֗RB`3$[kjqi_t7H~=e Nf{b$Ȉ&$5 W9?NQIK#+l1 +>][3H/)Dy,Lurn|c0`$̗.A?}D@'+*xU0a%5'@fq,'̀IH.#?!&؝oOa~-]w6f6 : #>|g^??NkExBߜ^!˞`S`OG ]ʭ a,"AR(&jp B+˿=L/#e;qYcӝ-9;D?؄@2J pG>{&ox}Ķ =$ ̋)Bh_w3m|%<Ժy@PV)UQrߠb bt4x;%$xUUZ4wP KSx:s5o2֬,(5ӁQz" smyB=r_)v`?3sgZ]C3Ka ?tAr$zXkmVu<$/UKj]!=jw1ߎYԸz,G}?ťWX?ɶ@7;FxCC/&taUGq^"d~ q삒G;x'2wH5 z!U'h85vj{Pٷ}ك5N?Փ@og* 9ʑ=d1"fu2}vт*Vi asr6[$p4TlLj5Y>JsFf8J'j-jEq]QZsjZ8񰄯$ \Ͻ ~1'S蟖\*py|-bhdtHBG=f,9leċ0z( Tfp'+9fkj7 F9X-!Pł:k"߄Iӂ#_00GQ\M9 }XOxM{ A&WZ4*.f>Mc#B7-olG|(=S{?R;_רyc Ys 0f%/*> wӋu 1$к kB6I#: wQ^u(jium?VK`)>ٺ2@ ->bimh!,8e.rm|}C̴Qԗ"t.y C.}^u,Ed( \lF{$>qwu"S A+Jե=/x: -Ykqm"xmR|1CZLm}]7 ʳ$A]BJ<+{BɶP9B{$BO KM*)M'>>ną`/[鲔 ,3|W:]>zA.o iՉC_YӀs :9Cs oA!p8EK!T&F엛̻|A|]C6% s8}w? 'J sA5*b&#c2\zu>,aR!EW~N) ͒bj;+`SXz!{DijtN-:>!P2*\d 5 hK?0qțQ0v{,̼'عiJ_=Eތv=c]FإA{_~F-b`f u -t{Oahwׂ‡[xR~0ZzGqn_k^; ,a ؄F콂"_gJ}MDvږȄV3nQ4_׎1_k *~ B}aLKBr*K"~7!:@*SF,,}鞏"0Նl;z&fZݬNV>5CQpwLRB=ބL84qK0uv~4Y(=LDa;AZm;dki?5EVƢkrR4)"]5rŨZV ~JBh$;4!$Rx g(*pt*h%B XoHB.~٧>ܦrO_h~!{6HW'ʎ0RΆDY3LiDnT-MKqYO>5Y@I k3+rBf /"hR3h_YjGs}1&dЍ->"ODDky #NR粓¬OEd0gٞB#IO/\қ@;(9GoAY$A~Y9)3[qn6u8/ /4b5`)O266i!BjO-wc,$P<$rӠÃ*N&]TH=.㌰0&]XU*-(ފUgK~;u,AᄔE$6 W` Ag@ƢFjﶚW$VI*blmM1w[W&u%A1%_eK(b`P:W)|倄QRV9V1qӃPMHhw0*S :36\X:c; N~H{Rz'bඟby :S\;*RtY5vZiDZgE>p.eI&Cg%ď$mF$;2='dBb1K*2U"0ri}mH oP-8n(w+HMb[_pMQLBR&R"W ' A G{M-/‚vBJ&.+XΪ Yr!Y'bJΙG9I$V.d.pP|]Mw)x91 1\!8o5yOUa)dJt@9|IgIJFGS?E_]pw?`z09B~p _wBī<(e,cʀkPd~"isbHpc I,GM3I7 aqyS fSq|vAd,cRee zeI .wW5c3Pr p2H$*7 J}jFOB`ץZ#7.|H#;9yi!tnjWa/#z3>U$ }pq\~~h*} [TȒ>[PӤR ѺY`(k\uq9zÓѫ:85LX CYu|CVCdqӟP&9$NF}AmԆ/qEs pڍ㤩dMTBg9<ɓy@Wpc=O 9FQ禉+GWƭ !ytB¾c.4`-aߍJ*SDLgV?0/!+bq ȦٛAxU2ԶJ+1qIc~iS.)9ydcQWg9, }7=MqgXy-CMG#0!9Q/6j0pKmeە< i۟\vXTͧcxVy 3"qhFhb͐GRQ|O~1ɕn{aigWPh@Y/'0ҚhRΒ1Kd^ˠ@ί1YCCr%WOIdj굃CĚJw G؄ hM=!]xV"s۹f;Ȍ)oTgKLI<]{@Iğ!G#er97mT&AdP辋cIs}R3暃CDkzځ3u .(<NE!!cs6(-AT:az Ɉ#a€}t8w;C2y|b{ tLsH(AR%` |7E%-^HuqoS$T J$[ !E6!Rp.4 򃓸$'x3-J)ըMu^ []= ec$=j}pVf@9kjCm$H&4=J+ط!QW?Zy- !00X3Y[T%ˢu.en)co?ugL7vU[޵PƱݍ_c3F ,iֱ'ƦwuJ*"+(4m&8A]"NxŔ7wN#2iN=-@Յ^IAL~=zp,֩7lMs:9*G`sOnbQe`yP(0 qP;FCcƷDv751;(e m2&@*}\'0T`4>3_׊Rh(h{Fޅ2P`gZ2"h)mjCǭؕn*#!9/EYNW^@dZs]_(c  >]إo Z,a}˕)?L ؛\^^|J>HY"yKUs.ݜKn:|tSְg9*ԟ.g?&+F0$0V&9ͯO f-n먺|]%cs`tE`>ȡ.45r[Ò;ͮ^ zٖ:7y6u1Te#FnWWOeR{nZJ:xɾ8;%^m,uYH~}h!oW+[6e;l32&A_a{qJRE+ azUO)@UݬTP 4.Ǐ){59|tZaZ`xr->:Ꟑ-mK_yH#׈k C`㑂F#5`ALCb@r8ն]!ڴArQ̵|ʉ+8܊Qoxb  a7W{;69{l\r;k?IhBr'u@JX@^> VHTrsf?m8VwlYx!~Tu†ߖնo%"` %iYm@xRsIh Ae-} `E~`tm\ >SYcb_-cRO l3[@1RY|.}7͛  (S{>Iu* 䙤/=fSTc ݾ޿jo"e^0[b ?}:?/l5g3OBX4Y o*T9$.Mj;=Zc9 Ir&qvlBJ"fkG 謣}u(8hv}BFml >n<$vG "*6Zů$D;ɽ M#:[zLjPdRGLgGtu}zGf_՝yFhCGU.,q7|C2.E;jwI#kOS6joW0bbW0U< W| /0vd G4·)]L1@f>Qm1+[yUq(BR>qސdVroX hՊOڈSDM&ȭs%:${H;" Brn8De AF9n<[6<vb@q+~S=7E>33!M{1K`zHPc",ϡ#Op  ΉiG2]ባ,˞n_r-D|3XAKs6,Vp+ )] D! +sғMRl7zq1<[>kգCVIPqbnt"W*-Yyv 򙡡)"8dxMqZybbT"Zy4  z6~.:w%KCdБ*=4>|(l} ,pn_3Ce]S°'5{װ2YkQBVw1eY'% f`<VoN[Dg HhO8\Rd[,:\qenwLx#dYЮz+d>z`s⛔{UT ҃E[(vfKAEc&\ң>4ziN&9_?T䩱Bg{o,!2+')8$Y*(O{+~#RxMO|fDG:uYs$A+wAs Dw5+cNSro[}^ugF:`5/iD&J'qTJV<6{/5fd! %s_]D>L2ڵ^jY eHK%6l8G}Gh0Z "eg%?QHe Vpp&ȊOa,,N)^xt a0U'{ˠȔY;W sn/B> h#ҸcvUt@n$MeI^_@;v{+Jz*Y$a4ŋ01M-1t1Y8M̵l8IZ$eZQTOWšfW;wzKP.Q{K$eFq7qd6Zd*#p+xAd=rܐM57$ *^k847s1÷6Cyoݷ7LC{6teǦ==_чPjZmt@(pTMt\Ev-Kjf^kN(Շ9)/.ad2SxKܲ@V%HJp "A[Ɯ.S8t.#xtP܆ \ܢϜx/,oT>3XL+(ϻSpꉙl[ M16A1>Y:/Dp꣮`DEjܤ< )f-=}X0H&}+=ׄaOdH̲hj>c7-T/ZﮱI~iu}EH"j]!|*՚<).^0?BF[DIu,QhWy2a~6_]M5 |eٵ &ۖ6G [D qnM[Ú |I&\Ի%X ۖ|}$~|t#!I=~RDCoeg@SޏՍWl۹`+p#K hI̭,X2 ӷdXmz 1V\pX$CV>}f-As9i߲ԣ\۔9{$uRBky`oMyFK{@ ]^!,xJ׃K"0_B3) `)mswKͼL<{lN&ȏ Os(Q` \L]?Hc`d"$ךK7s9 &sA/CAX-Z#KNHĪ]C-<9h }D ƐJE*$i^L2^t[?2 MμD`7r_mzq͓tɷBJrة+Vz7[?zpJxFGLLq.5I=-|1c3;+:xT[e&AC:~Uy$ODQBs^p<}Z4㺥h/iPKps0R%i(ɣP2,T]uW]O#䲋֕s˦a<<2tUU%b?5ԃC'JL,ہyAW&;2rY-广$43!pC`)Zبs ){9gh!k^I@Մ5Z PI )Z z\ǧ(DC>j- p<ĬccۜJt:L9moSatI?yp9@Mm q|b3-G0+:d|(Gb"%5(tf*6bJx$4>EXAf qcX_N^ve1p (W]s-y:ID|)>:z\#c(^\5G獐esފ <K^:@~WT'i6R*r!ɂ,j5 #x uG8Xůh%~z?b+R=lP&hCaʶ;0hYF5| ϧ%\=Tͥz4OxsOxx5tMeA:/yQ PsIXqĜ3+Ix[C$9\X+$_r!;yzӼ2WۡѥYuM'/vk%?yfӕ?×{_~vX_9okJEHǿHY2s >xF<7b m]Yocv+otoKmOP%vO "x(f_ {|Jag㤔nעM}jQp )fM YOѠ3FHC)DjeAOyx_ :Qo Yl4`:*`qjay$[<+U/lR.e;*L~p+Sf 72F]o-rbOdF帜#ψ~/px0qARa]HL"s&"5-jW]yFӔĞȺX-6krwf嬤jc, OcEu& }u/>+#'Y鎖x [?;j2^Ehn}] L#U՗})H>Oi}̋M |W+*IS”|z`y%0F.qԄ<ؒ0PhOieKB&]u"nCIFtP?5hK7K4,QZ2şz+z&Ť1li4r|bUkHozT_<wfU-(I#k\=? HkJ XO>ٿ` M mt Nࡦ:X~GE3QhC ăOdIchjqa[/d05~{eы .WA DM|bvy6/s!RDh00-zּO#3&:oooRɺu!]ňXTz;za,ǥ`;J89|BTVnfQce]'dFi /l{"ame2? Co}6 +Ƶ6nӥ-aqTXt9m yTKļeLmܥK`2W {(bhIٳv\YJTJ~NI^D 2*l oX4f7NK{h5’9MrPN݈R0ڂv*4򣉌ip׻Ǎ[zQjKZ@)EA2Q]9.+@AϩclSߤ% ˻߀@+mh1igZq݀t(FЯm=}b?2kls8Y&>^uagJ_* 9҄?gGtGHۢu${*/kq$sIVLcw8C!)tKIYPb]S ~kIN%V;)LR8=ICahQ㉪Ri/＀覶G;ဘZz+4v:eK B +%.2_R Dr+ 4IWQ׮ʅVVi8WD¡qAc0+]ux ٰiS VgE9g] Ra]ՅP :-/%3^bM~lEU坿*} 2{$鐬eH~\-#Emp-Č’ΉX&D^<7tQE7;a `Yi: zvCLܵrPOߛεnnLQuƥP"uO:r;, w7yݛE%|]p0|(0n rKS]s2׈S fdO4RKkG/9A1<ټ R8h6ѼJzPދ7ȓ n%V"#AL( rK==)aDEq%v/ Rq _ة酪m]2E^i4[1R`йMЕ 6FTw ivaG Me "uKi}M^IvU%Wʃצg}ցD#8aymмcMb0<ᗕݞ{hZ⒩LSpitYjvDnxj=)tTN/ìXg5Z+vWě4͍'myLD\^__xB%y[zgj&3*xuz0?Pm?G?Lo|FPmn*J.lf㆏fIԯ147t=T[VPR5\] uGӸ}O-0kn@^*RuJ9z$x8lN{y̽vu,%[$2aa)iOϺ{BT'u@YrynFq]5v#n6$ڟB`ϭY0@ړxantKwȈ)F5d@+7(` "nJd\@d>l$] hPx3fa_Rro|e]V͏\`&=LL\j~0B;aV4Ig>6Ѳx7U$ʈkx.D辌'AL{ g̈4|ɣ_-u;`kQm^@ÚNӥB1`뎥ʈ<5e9`T&V}\J0HF|t| k`jNI()}]bOv(/I04MWpCruhAXQ+>>/(9vm-ŌwGӸ5@1T%܊bㄪ 2O^( cQɔ: mAap )MCC7Y4@q&BX\9+5UB kY弣Z8f˨ P%+wŸ#}d6RBp 0 9.mg p#ʹ^Um %@mB^?˷~ۇjOFzZ*QRx =ŒpK_MT;P^ ]| :R4*I0H,/!O{$q|bρArVCo^4[$(UBNs}75+1LX*S~ fTnL;]bLĘ>ѴaD~&ڂ ck ˫R Ei%>(ݲ|m[PE@.@)+s5>~[ʵAaCtKQoy̗t1=i^o6k^rNDm?9ByX~pB_um Y i=nYRִb^ond,[l7DŠ Չ$>+̇~]a$zȬu/)u{)Gn3#ݾW*q-I?)!^ =ѱ؈*4@L}= D%bsAwG qW8{kdyc +/@sGN7!pP/t"}?!S;]6XDF3vCIݦ27D|,5UAiv_gRHNBpia%4OVe;VT>}"puF&6`ҏgƒѐk PUl}à8NnsbV =>iEj}5TXYd:;<|Fj4 epjdOjD1S4?zܦqj"TuqkE$Gww(.Wn,4!wjW%mF G ¾୆48⟠f`a{ɬ=60V@Ds)Ctɭ/;U\Uó.Ȏh_uJ;sB8dwZbwlAnc`|*'KA^wOVE}/ŊjLÜItw=m5iW_JVn|p{{"l+ov"'> 8Z͢Roj̛Yl^>do> I190SG6:t?R/rr^mg7KDTWTaJ `M3T2Y&,3GT4Zjdל@ҹ)r(6n5?Tpי{_ܳ7ӁɎqQŽ\\H6%Paݧbƌ 0[;9dj =ߥ"<ٚp8fRT|c.iFb@"Ud'5e @c+o#s~ZIxmŕ⍚EMF\E畂%3xqKFݐ1r^Ka?Oab(hP3FA⊬pg? }(GCIV=w:CW($xpdw8p"J=1iV։k2B{^o?A?}q8(aal.R nb5_]Np< 7 O=E>n$BRpD%7 ͧ,Vy %8>ſAh`s-7wVĠ4_X^>ζ='tI:Ci$bx!y7y\kj|y{"j}MpFy"KA悂zmcg2̫@&(϶DbT 0]cclLL%N&Waj"\`b!\輆fgl'=y i{FF/nJK~{=EB}nMQ(D21]1w33ݽV(ndъ"& F"ϣkpD}n0hmFv*O b\WB`N0Qpz'qz&(rĹ4݂:Mo'bH;O.Me??t{D\)^j~U|emEhB!f޴f\'d(c4}㖑ɏW~xTe 2߿yD Xu^KG0ڱ@ `/c;sjqYe~0*eE mmD &gxw0IXiZ4È#,gZxT96h + oar;3я8s),No߁Ru3p%xpC"1,Rz;15]eߠb;6kc!YfZi( Ɩ%nɿ؅-(ޏ2F`HaCъb怖%Ϫà;6 s9YQF1jwː -p[Ir_6y][bB#B/Fc:?1ҳj&8@gR$EEE>Y%6Qp֔6޷-͘g߳@Ӕ{+ǢNQ뉐͋Nnv ; ^>ezRR<̀Y=gBS)34#\bJ2oNM9sOu[6٩oXd tX ~-n~ NwnI˙,2z/3T7gB-D:4o_6 W4۹VI,ݖcG?c CQ+|lt #&uM*k乷GP&P[2;]2CfZs%8h磧7 rlpj>w8KNq=56(3ɎV?ύMk-TQAѬ񣧌}FSi!ұ H1UEFOBSe' g{CrDA 4Y$PȁoWF `*P H;6̢ĕzTnKN @x"8;)D沩i> zQ{:;O7IܔY7r>W0vXL J:$''XesC:-Sŵ=45 K..yW,B]^`SBh0X=R67` sUMJ$I5N0 <.ћ_̍qdd?.e]bGWDigհ'\qj%q+hW}ɰQó9:e_Pf uꫧ &?fƕjci3|fNj=Vo8e6=/+C}Qr{(ywv.Y6@d/ acU1 \ܱ<;tïh8ooε&ȏĨ Y!.pQu>}EN"I5e#qD1s5lξ*0RveL&pI7p4p\gRoz@ė/FPwVLAQzyGx|&/i'DqH!wD*YaRN%~>k@J)I}F_SZraَBv#dLfԄQcAv Ԙn#r]Nw$ʃIјJħK뙍yWֻwmc87t\1dZe! gDcWG7׻(g5uKA:F@Mnuj밝wCB?Qy_&o eث#s?5+[RhP-؞4آVA@GRIWoA-$)/HH:f1tx&C4\$ ܐUyd0I|C4NP -7sUGۋ2~K?-X*(yv(޼ z' ۣ:HK郃J l b&K4ְm=b8 sSewa+QU׋ow\z̸~PHFj lg` 8 I-Jg%$%0@Wd?Z]^al^%zDc֝l@ P'VU*"iqǬj9|V=f¢RG6A IY>F$&ur@ҜpIp1K+&F{ap{pD `SAGcG4l%A(*"S w@gZ^ ^7@n06Lj!d[ma@)ܮe0Mw.>?CgEj,sФqIlTt̠WYCF{VFlkPxA9"/$4DW*1H]bj,i`97lۅ:al]_'!}V6x|TkId4~`˰]Ӊvcl`C.4g`@鸟x5y}u/^(AfYc+fk/ sΓ ^)MW*'0K$JG3W3v]Ĩ4+P}fW@ |aZ,Jeգ /Dƶ]jAWbxw1'Pd chzC[b%X*(޻~Ma1Кu(DA2do~UAA~ rJ˲INYl@*;aJگFjw\ZԒZ>sb4,tpcy B6u5(0~ |?z$t]drml͜_Fٰ)% C<Ϧu3i`(11G-ώ$ ]GuHoJI2d™Eſ'cVNdzK?vbq9-l򋻤`iM۾7[+F9Eton߳Uӫفk])RUe$ܧq O}E7.M MR+˦WxG63]f4e;;-ϒrmBs39(i> yrܥІ*8 O|D*o`f _?.?gTg۵A*[f*d B`KC&FG[\"܉ǻ:L$1Z$lY-yvijaJ Zռxbse\&Evm~ RbRDv)~i[=~d@蟅rc%*UAA޲ۼ.n !b#:YY=Q^@2s(%A> Sϲ@#5s 0l+9R@S3cRkB;l_6h5w0]7W+ _y)Ou}ӯ ?WWR<7 u~cPլZH fԂ[}-i+a+@bd42P;_%"WUΣD{+AE*~^5Ei~^2$iz@@?$DebZ6ra;HR*i[ko /9nA.Y6Os>SKV)EX;켙r~2X: 5m֮(jNVM$ 2_ٝLJ(Gl$)CiymJQinT.K Ly&z*I룬IvC +K%8DV4P* YϝLqO cLȴ$w *pMb0pdVL"([l]'eq[iP+]d\3)hDHp#RzX>u:k8=$&X8 M&|mcd 6/Ѥiqo\5X8b=Emdr?W!^sVy4u!抹r._/aLY@aCItRnFVDؽ}}p{,^h m ϴ+Έ)>eVl:ojv\3Y Kxc/UԸ!K7ٜԧ 5&LXEepg.XCE8$fOQq89 ST:ԃ!FΘh'HJ0J΀TbwTc4ݣ=w`G7kYKUx*RM"=#PР%)vnog` :bs"h/x~oAxe^ž6dAh`"k+ :@ymYhLI&2ƣB=d[5uz)}K Oxx#S)vu0Oإ&I0^sj'Yu~ ZCq#9>TOY6˕IZ9QZIK ('r/1E]} *7Wn a# mкrz[/C /\tf)" >+sC!e\Z)JhM ʶWD8$$Ip>ޖc\m"dS&؈%'jlV\x@!d^+Й5fY?9>o(}npx!aΟNO $vpXw@C; z/+:ƀlⓖwPk["x&WeovϔH$;An\*ῦgbq#A{@‹{pQA9oT~HSiҧ|W[:7nn[3E͙ [.$a^f8`z%³4+G\%N;v8uCϗgT;,3ү{|o+Wsס-VM*Sw)JI$;Z82MuKC~!k9Ěxsy}ѷtʄcDžd}BBk={[P%ϯԼ$Rk68AOtSaqz٭"sGSܠ3CT@'5~w=N7iSx}^y6l-De"Wתj*|^6* ݛ]`$q ġH3!+f/f/󪐫`pq|10ILދGyRe6?@"|qUyklw -f=ɺS%_,D{wLݠ k7v8Od7r E>r$DWqw^(#62~;H6^r[.ХƋiۇkKSeELQB/ΞZ1!>Hލ4Gh^5VTY>ʉiW! gՔҹS^0?XYJhR*%࿦ Ɣ^ZxScMrb*Zh~D-XHb9YQ݀yIB{ /W񜈿,mgZF]I7P<[!jmNg%q2gjIoGg'plA%-ib 3i>hgF-hNկpF󔢊6;pl\?1`OV߯utz(֛|n;WC\d\=>]{\EYktdɫ|{ GEy_lsJK”[׺,>Zn&kS50LN q}L3տOg̢ȣiQ@u^d*Ά!Vx}g砾0q>.X_2=+עo.Bdxϐ3 a񌪸ahFA-WG2"=s#}]&WslsiA x#D8x. M,\I䶛>ďApтԜ%qgex ȠkF҉1ipf]IISD15RM~iq'_ 8*UEav%w+!-S62e㡪le8!s;?0޽Z~eۚ+E9j2ҖRm߃l 4Ig*s5~OP"6ZQ%6`O:&,V4iE#p - CPMōQS*hSXؘwɢ C@Wa+#d!ITRXr=:HCۭB8mT$k 7_ Aƽ'=W!%3s(ƔX.ul1;V<F?d9;RUbtJ|oWӢ/NeXn͔ ^TB8*@iha] VlH?niQ0ڭ &Jͤ'k{l`linb, 4XTD>?bsV=ֻݓbO 6TaúQ85e9at1Ϫ oO&_S12tN$IzyK3H*&Ғ4zFzh:$oݲb+ suĘ %[k1rrc!ubY`Jנ%]g٫CYo#./互t]M[l %˛Xd#nObŋ&}밥j^!2Vx;txe|VH[ 3`8gNQ3ѓ<=XJ)4VؽM rײ,(xB.Z-B$ J*SOU%3)GkD7(|2-#Ç"XA=>ڳ!*M?+8fF=vM1LV5k s8~}ñҟZ-=xxhk1N%p]ʤ8u7celSzƩxMc֟=7FW7J?^t;;A+G"W20@8A;A!A".`՚N sv,*|CYHnc L;LmXq044Jg{cYY#q]WnP0 2 #aAJ/G IWu*OU6*q ٽnY^tzZ6:n3?/n}TwlN"^gkv|qrd;"$tЦJqٞ4&7_qYj>W:RL{9xs3,kN׌MfrY^{0qP6=Ϥwo q5La:kKL[KI@-EzcT}fH~zDAtt{ 6jI;6/άA;аL7"Tm%"LsF q5ef#YQM+2Xg%c8C· DcgM LT2Tj@OB"*t&= 'Y(@*R6wb>dԕWfIKE]b* 4)2!,ƇS3Y{IS*C2"oGtq3]}閐ݘ+i+ݷp{4-BvK^u[ Y|AȪ렧JyI˚XLs/;m1nbn֩3͟$Rf;U#Ox7SN9qx~^M "{e!Ry*<+'%EoUC9 OX,[fLk: 7|2e/D-$;Iy"yU j<$C&'Չvא$\W$!/`Aڽ87Kty2o_bcv[7]5қfBXœ3|N PVj B ?MVY|%mc(H(&du)h#Qr w"u 8,c _x>|B@hsߤޤ:,:e jasm,|>WS?oDz~z%ujG?1b|`ˠ8.v΂Oa ; *Bпe/jЈYQ'KcgL@0kaUs;0T;j(\$_jYV%ǥZE}Ŋ_ix#BaUEDR:%QµÀAئo(s Ϩce‰oNzC5T)HȰetV4Qk6ftxbSռk<"M뗵T,5]m ^zYkX pǷuvD]O4UE® %^>:a}ց7ѿJ#U&BnJ0gpPSVD~AC*7va2iaJ7J`d[;H:&QX}1PD!u\cc xG&a1Qf!6i0%{C*|Xܩ !zql_2PP475HN. Tz2MKG²&q#=;S%A^'6eQ_^.Yh -̈́fyb R,Fd Ww ]X^lJa_]ӧ65aLrW73Nk }NkRs)L_ sN34Tq#!s߱#ѢO}J!baRq4Z}:n}zw6!`}DqD/G -ð)v0d 3|!ܖJP5.6o ؞* mX!\DD!h'wL`R;wS)j[26r6 "ч}vTjAh<=pkP9/Wgtx ?)_`v7GGdwDF46xU2ُ\Y`?}rwZ҆ %;L?ӶQ gj{H)%Lbp]}uxmn5Q1r'LQsv.|Ha ROn^ YO3bđb.y ~äem."D.{ple[7d?M)E(nKti@v=m^pK&.>-=y#pS7:C>}J ibc6EcCHœ]I"sÂ^J3lY4r: (Vch?=Q}e#EN'w\vc9$< zZV]p6?r>3rǝ!l3?}T迕зy,VDc= gq(pwF0>7X3*)ɦ򧽊&nRzUK?RYt zJ$Di4ŽDݲOpUl>M5DžW;U)}oYw͸tE=J׾h$T(k iNZ$:7^NJ ÓmPu۽8<3\DN{ Y@wt`ځ[/ gEK%}%ifaP$DO{V"Йδb9y3rW_||*$I${U/2[;f}# p`Ee>. ǤW!MZ1P}n kC:ו&Fd#1`5nP;Mt1hd4N=uvW:̌uoLkJؤR5 ӿY-p L!KKJF{>3N*'ng&&'`dB ,2Ն=И S#:j Ra꼄i2S8M~k%lH(V\kw9~$7̰$AΞdOsFNEAc2>-reΞH C7'`yke3LB'(Z`fGSu\eWjP?\5i:nV"R O^\XͭQʷibH{>mJ]9~>3TQYN)8#'7A & >t+x?Z'(#ڲmcNHClȂS#%6y< TLvn== p^R= A8{HXyyۆT>qlB/p2S7WK[|6Ԕo #F::AƳ!y%"_/PA8ύ%ҝWA%fANeIq@Tzjw8W-T}.op_bo|#hx]zP?@ &f[SD>dՅJc^\MuRjR Tp݋8F?s??!qEl"!SASwGtFlV[# 4o#u-])finCAU3goR3B 1ϙ{|+^ƬLEx c uA_3sDdA@i2Ce<="k~ `D}*MPEF'7hF̾i6!":veeA/%s(G3%!xWMor>ώ;LoP"##BzvAoY>*Q0Z)֤@րˌ6^ġ"XG 4~]@^xB;eq MIkQk.oث!;XMHl ~qL!onH9`zw ?gMMн'D(㦱f.D|TU5ݳ=ҧot\`ƨfJ)]ZV"EPbw,r(nk AǺW9F !3;2_8#BUN^]-[lXElA}d!,JxpWd'q(mj@xzjLSs?LRr+SXG7z WfgNhwYAJP8flR-5-"C)'Û0QOvk$궓c̴ |8z$pP4L[2 XVPdť@cHDat+f 8{v9P K cL3R7Kp>h7OV1r@h wvĿ Ok>Z10_K[hgʦweیJuFl)E#Cu hV[7^\x?'#*胢z&%v.͸JB'Q;z悋"trfU bj!|#7nUyP}tW⹟$dX_AS 0NgQqoa,N=M[T/~֊ & sBbdl? r,u_ldTJ]g {&2Sܲ lbU }4dB;tapW /`t{G|")}L6u@rV0铛Ӝ!6"3ꐩ[`zXK'-*\%dQ1ߟ"חQ{ĕʼPaj:}ۘzmȭr|B74[0Sm"Z@_dZUEg 7.օ}ٓA H4/`<]>L۽\vH`(qgZ(Ld(6LH=?圍 cz%o35VۦdyaA1v-x! -x~FSkIgJ;LR#G.41<ϴDr3X6\.eHKVB'QSf~u;iԺztbw H;7 ipPסy+'DL%FJ,I,zifKOA.%HS=tb#- x`!>SCCvZ2F1 By̅C0ǎ ߗ P22!9{Eo+'֨8~)UXWx/x%u,Y@UEn( ~3nzJkEԏem ^CLV1=T6*Ze]#Gg^~xGyGwHō 5nqsx,o#8~<c٭C@%@-Sf{bWdHôäߏPo_o2n^ _„D3ڵ9C癹d¥(K^U#4D`ʿ.cRMb3? kY ϥni?d At+OXDr'41_|o:hdzO=K7S'{;eNjNdu-mɵY#bP; h6zx%UOM5X\[ HACT",ǁ#ws2b:$=.ߥ稙 ?D<[nof1Eh"8PbP1RE\:GSIϿIkz='T> +nƍ#KɟI2f-e[A(4y_S!`߇CGW7w;4͆QK_a˱Ɋ]gq"{D=?+e-4klB&/G[2֭b33,`[\hEz8Z̔Tް ٍ'V e$D fVYum"uyKf2y=MXY<ޑ}<͙aBp27ft&`y@R# obǃ^mi^+e>Zen&`jK֬ȑ栾v@P;lxzc: v<5_Y X)@LJaz||;[UJW!঎.ŷ^f>2<;9/yV: 1'zu#7X$=&69  Y[ݥm4P gopQ=S_}T r_>d^VXDkJ5~/aF$e&5AD8ة@ͬ$ԢyGFv<6Ĥ\ҌkdA>1n#TQ:_BGr+b9r'$:,!$JϚ!w0=Z%&/򠢾PPS2PmdZ!/fB_{q lf M`7p29Kƚȏ9`ln6 R( &e}i;"VaRH'4i똤/˒[aC!L3+[t"=|ĘR^^3:@ۢU<"29U͌:Mk{[E>_SR&QNN?WܙgM=0ph 9;O&_^~J0#I,6F,O%W`@.;Fda#`9M6[Anۋ +:/5XzCɔؒ?ͪ~[H ya._NYo'cR澫A:I\ dW3RZ!IA>5YSw=]i3%Q"$A}mzd]nؘHuv[FC=j&uZ3 )s7Vp @gԐRN2mr~AEN!j)='w5&]P{*[tT֘I8rٜS]v4=^wƬ;=[ropĜSV#\g9)YpD&@-hǝm^ P|Qar?lv`9H(0=Z0#*б昝Wh-=}1fSK7. }o]YRB׼ ,O-Ξ b VW5k#]^,i3ifAZQg#Wvaᬹao7@_+2Z`Bd5tA"֫k BA* _>3Q1liw9EcT@1.ng"}bX:cR3ϟm|A˪ hTA Έe I$jdϢZԡ u_}YyJ# %S 3,TpP_J}WT>Urj2UD9\Yw̱T:=i^7ӢznφzujȘiaǔr3$<2?YX;SF~^)ts!S/ȷj4ewy]rsrj0qwjٰ|}AQk)pxfŐJwPX1ub+#X "9ܜW"+m< - ^3l>, n z/߲dg Έt%t4R׊ H6 p\zCc a1?=Vxg)u0Xt]tvtev-ܵ5"יK{hxW}淖z>گhvC&"}jUMm(&Ϯ-gY:EzVnp*A̰~ށDg 魇I{ -qlDt6eͺt){H"(aHiVy ir8[ *Qr\Z wu׷B;zO牄ڦy~Z G}Pb`fp,i!$/II+̌Sx ۊv c_;yh2I01Cjn,^$e}.AW2Nd IVH~ɪ Oz7qfs2s 3sGI97mh¾=l Uew"!b(nqަCo.R|fW8q @xrD,u+.ڒ X$s'7ś0pM[CJJT_ez;Ft=]x ˟PG_e) 9k㔏E{N(b2Z]WވHnaz%fhKLG >RقY3$>;xU.Co\vO u*v:%$q8DKUj/6rin,O?owVrJ!'xqٍŵOHⶇoApI?Sp&72.Z4o Mt6!J&n?G_:pNx?&v5pũޠ#To{<zp;{(EKT';%빮V5$K. \b{⇴m5 -# +Ut]"z@q0Sp!,ɹ`> Wvvehǰ6Hav#nj:{uvՏ4H8z=]},A'a5 K,M)Hl $XHΉ7WelV,<3(I$?vFdߞ{RRېT!}7j'M5ۡE V)oda!c'iוON %>@2[zn睒:"K>+i+.%o=IS&\>o'| Ax,`gM(N{eyC2ޑ[+)p#8 xJB\UƺMޮ$iG(U0pwGflp踻\z%η#B*K:6ӣ>4둄L<%` ZDZ(j]@.ЙQDϖ,7\wD ͛sLi5:E qByR?l3BD&/3AIT`#RT4qm"k ^*WCvaNk,Fm?KU.bd\kyL{`aS7a8ŐV@Iq<֜B.o Gq@R-gq)* _̴8{2f?__WͼW *(_rf^ȥ CӚk &501xB&날&*O a%%ÿ% ]Kz8u:g0RQI&wXڳi6ϴJ^4g}6џ f PW{tcZc غ"Zi>{H9߶Xx N&{^p^>:(6;*LRu 09|^[htv4S%*qV`=JN%Cvm7PY߸ET|?Uv yty, ryv*3-j1Oz,]lfo &']t%z4u`xބ"VGٺ/֕-iaCkS>6ZF l 4+Ԣ-R0E-R ֌$MR:z]ڻ]nJxGPMe3 LYfK U}p^MnO|B6La"+T/ ̰njy5^A~m78p -ttWcuPb>⹜C"s,H5MpU g:4{s2~т<'VDI5PT 2ŰE -D!.bÎeT.L~R5l!ˤ"QQfERdBœN 2_}NqyguRx`[,IA1Vv4QnP an"!.&0omTcViBt#Wìxz="^1\b*RWW՘5FXzCYbuR;oa)Ooyv0_ڈt ς}dλAA\uTS.5xNv>RJvʜm DdeЕ Hx1y WjpxsfSqXF"vgn!MX|*r) *_Bp;Mxkcsw&ObBey2R {knq(kkaB/^jk2S,{OD_s'XXWM4S[X2E8c|Mixq16h՞Q!9 a&.8}x64~CD[Á7i>F-^1|֛${<,9ɣ%.Qc*y%:8VtKMRoJwH+-8A ϟn 3y6([X3@'."+\d췭uTm*8X/+m-$rӯ^{xGOEڦUADU}&+5K$Pn^=yskQGM'{T6L (ҿUh':JH/(h[W";T_:S>?X "29+-VL+W_K o9X< 4&_8&',\ iP!󻛾,JUThY:|.cRd;a7MtxB*$4vjۂ.\\AE ]/^*I+;7o*ZJU{fVۯ8=\NV bߔúp9NI|Ecd85$]LQfIYrdb1v;jh< {^±:z'8=(QUcp*&Aey-sv'[uWX#|uzټP*JON2Ԧ 髍y̲9t/l+h5\ty„n8 oSR= _=J?BY %`8Si)|yZ$8pu1Kf0@Jֽ٘[3B:CoQ%RtF2촥PAS~>y c1(lWmِ6 +b=/ kv4 (_WaoЇa#6!׷}E)ƒ;?#H+{O**H *dm]~{EcA&NI-xoN{_M 6qt@;a!`)Ё` ג՗^Op"hO%tu#CTC&ɋ*=dڈ$E z(Bч@?r!y3sB'_MI(WkKWWQ) >aKs%YL c{-XHMLC7fbRv;PHCĔ[~0nZhWt Gkզ1EņG *fy~7Q_ [XuA;p vF|0Ѽ+KIkG]`璃QQL#Xz1{'bE̬VPX oP1I*Xk^3 ~_:*04հ\\ gךАV"[7^bwwwSSsYn,Pm붅&Lܱ*lsǷoA=C™egq N{Bt0e\t&,l߷Ԝs[֜\菥(ʥfr4bdIWfA*AjFY\Ј*ʎҰʂy vw@9 bX襚x8<:@r.P?f%oK&?Lv9{rٹ(~)6+<sd}JKW,2n *7oLupP*(]bE~GF``U=2;["#8R./#o1!fW9H/m2VO8ԑ2j)Q  :+\hKnZ"G׳d@͕Bom&tNS?N[M{2W{Iu6$QqL5æ$ +l vR^`i(i.js?Y2=|~xw?G^JXUH 'H,~Ś/)ਸ਼[ћ)F+ܿȓȣj]MekjDPq?ltk y#!gBɆT+}U? \N^gdbI7Ȃ 71̖ȸJ4bo7QKi< H3pg7[0ND!RZ zB`]$,.|t^)0_W b3V{xc=~ʻuqfy1谏hv%=3O3 ?K ]%oB .r忚u' _cf,Ʌ ͗rer]UNRBZ߻\Ec(Jz)ܱ9~zu|@uT4SVR:U|WaѸLxmWF9B"V=x$*̆t2}1<~O|?q=v;},& ;[x F?VW3z%"/,Ȳϴ=|k?N.&mx=UJ#.d]r%76EldzSH0wq# U-Fyή'H ]}no <"M{v_ TM-`¹\5(ټ.0 y= :TQӚiS("P$>k\sOyC=/KulXʋ=q?Znzy\ XJru%(xoJqPaT<1>;֠ܭbU.©PO(౅(="S6r,|HjBuT->zG)/ iZeM 5k4^^9@|y%~7D[cȄMvJOٴ!,;Fgo0ԧVF,egʁM͇ra#pas_GmN$'.Šo E\sS6/L!\b~޼6#cC': >% &2T=:loZrI J NWp+.sO +UT7$'AP qh,]E%Y׫=aS,t…:YQ o3uYQ.bcNc mL`,sY1Pi9 x~ɋ'&? q'Z=:LF {'q]'ȪN?muǘqbat$MEiD"woMu 62^̂Cin^f{ծbJO\|8F+4O)FJoYd$4&)5,M>P5xAɛrsYMLCPڈh  +# RuL4Py$q\Gcni.-2HdVsRIVXS7#pB;B\,?u4nV/0+O:r]$n i=. Ov.Ȧ&+}7 p܅Kcw^g aO_M0ă 2}R~[_Y䬎tơaib 8`'O* ґé*Ը[Kl`٫}ж>M#% Ӎ~D2O)߅Mwh3Rԃ@}GOXźOuA`^YI٧GQ;7EPӕR})s/E?@W3OS)*~kX\SIjy2i"`2;HF24}OnX."05yh.ny&o0#lIdZDJ[_: O˅2~K!dS.!!)\~nNJYi_O߀}>!x<~.xclonHA\5z`E)z0Om\T+3$7}Z|YbD0}JgUf7q@xКtTws%qb?w?(X #Y`3aJ[WZEZTj <[D=cDҐY{#AGF$Z:]3I.ZWC,fF"2|#@N. 8AAҒ`5PفfۥP+۹Wgd|Da.Q ,UkG&i+y4乽ğ \{UA3>`°0 TSj% ~.!d ?+?kOj DpR9E:0^sڟ$9r]~+ dOw)-*[*]>A )9܏cP.bRYJehҁ0LG6G12Lߦ2dv55c|g)z܂ݐy譻tP{Ņuqi!i@JN4?^dMx_f`k9/H؀WmG 0#A*!g n !(Zeqt`{Ą2I5,wrHgWʤ\ {@v27%=u{}S8|We.CDfհ\2"$jdTFN8 @}0=>O4\2]7<.y4Wj,зY-|w'J_|8QlAI_:;әي@ި#a(ËkNq[J4ԫVڥ!M>Bi2-@OSc(稫W'{ p({U.C7r#X&(+I,JsV 8WOs ީQC).,PZfjhv.ER;| z_&x`y]*~ ntandKk.DՐNY z\ I'M-y̐e}i~v#Jxv`H0\"z~ kakJDW }A1i8jn قjP1fg{--`*KK?9>J7k!M0RCx/4K_?~A@ #wy.9/]cbmRf[[?vkԳ.]ezvSu 0m#"&Qd(;Z$U >K8(+{}| CL z )J p:*NB XUAܧGs\'P0bxa$E4kքN G;MpXUc70.& yQ[o庫.1ѕP<~_^HTKSP+M!8iZ}$}\Kء p4JbY9~[{1(ag8`- ~Ya>Rq~틈>e$+mZr\btͱXiE=ifH{:kS^rL4 u @ZzM;5?s vk_ǂiDbo{7=X" @'!.,P@LH)G_l7 5pL!52-3eU1Slӌ )0 joYxCG\$\<' .d`cP% a}|f(+҈ϴTjqֽg!\s-65b}{ szw^?QcIߟJ 8+jui2!R*a2mY3DOem:# o҈MY)n3 0EhR@uuk[ՙXyKcMVD>=y~2T6T^ ˅Giyd@=J/2,X^}U|!@8@M)Bឍ(|7E|,LJbپU(DPI3CX"A+'A"1^[L`UKLdR9CCd"sR  E ݬ&JyXrZDt$DOR{@P,=X`t,Zj3N4gni%$}Em 7V)&dD$#ݷ&QW>OQ3 N9]!ξfCqF0nI }Z?`[:gB;-<).G'H#P-V3h>"VF>9KVN{zCI>⛿.mN8ҹ`]aIa@Ds!xץ_ɩQMԈ=Zkrup-fKw+|nO,%Z>+?v迳D%V6_]8QsFs^+;-eе?Dg>R"ph:tIQHtB 5*"֊n8 g TsLT?p_\ooZtBCU۰022`6L^gUhCțkƼ"rP(_>/؃5rŪ#>)G-A!Be}i`~Y ~qZR3da(WVуrCj6b>qTF(mmv{Q &-o1f.wk_@ {߭kF );-%H횘}Y[: I] )NScI:>! J^uLKRxfTv ~b_zv8n:D;W> ^IQ))@'q)> v\͠="APhr7Ovyn+d{{WQG3At*fv ZYq9plӦuKR.IJ>,+hٙM7o|;.u?a ! pG36ֽab8 fu0^BJ'hEx1y gϹ2ӾG''?< .?8Mbⰺ_\ Xx h$~uRa6cZp3:(ĸ{e6pXTZjueh>ԁ4X ԽWD5]o@.ֆSX?Y\jXNy=Mcc2> o!ˆ跰y==@3?kW[3L H̹q6Uu=Wc8` mY@ZwQ#w| .✺[J :dyH=_:]{yNOZ4^m{?NJWZڵPS, ػ _2ğw1\d_mzFx802i\s>) - \3ygHYdqI5KER!3O4~8X26>ud;qVrFy!4`lY96>=d6id,PsJܗR Q@` w!ikF`!7_\^hTvN7]lPKOfOuIt8,§޸>/2pUyOQ7Ʀ!1pI;mEC:xgsI晴Н>W`υ|=5Ne' Pw9hQq>ӊ?8dQ16|G]B;Mq`/U9yh,%" ʗLXl387>íYeDBq^9itK^_+_6q> =Gt9m Z3R-L>-`3'+A|ۢtܿd6 !(F_d6p/ޕ4] ʋŸ)T? /Q^0tC4'mwF9U|ReXnAM u՞2Ш D$c)HBʅmwEjK^DtfthGɜi0{؝ Od] 8 S5=}ACxsRSIP8= |:z9˜/FiHS\x̾҈C;=zIko\ y=ՒJ 1LlKE"aa''JVis֝|l{ɾƷ06o$DqIxSK)RoCe<#%v߽tZ^XD?b2a:1G&9qW;EHuVNΤ-,tq-%n6񤿊:4ѵ&,GdHGLC8s \WA뀨 emf* ez* ɭ&|qfqz>ܛ)73bØ3bv\#i]; NkߌޱaR -"ϤnpRXu 8@mSw͠,Bv^0[N-g10/^}d8^eiA6,'*"ů}LNRY2(xB<Ղb)?3]p exוaqU_Y+ld`ƷӤgː@]VৌNF..VjC/)oO "huԸ-KXTGD . OݢE0wnidXAv-IUt`?Dˁ&jCi`ux.z=?vq&Wl>N9}L`D.tY]l lXG#ٳO0nVPzYDHH%Iʡk2 h$!ΐ{Ι{w ix:mn#Q( hr9MXVl^v?P'*'#շW:2֪B2G3,9АN I:>? dR/xYw%v9!2gRzge8# [*U$GSOEɕHoZ$ XD%b;u!(?7QKhr;SXNg}1aSM'U/_S|D@2+Y!n*ᅢ(QC &Gu=~~3(poWi|Oth#amԤ -z5왓?=3C/8=s2Dt O' Uo %b!Ql]U kO=,c ۪2l|>T$>Tfe 9'&YlnK Q&=T}3:z!L!cTߌ|imP&E0U}N`Ξ?69.k* ..bk8inC]/+v#>jeUUxxNM5ߝNAJZFgEN xmׯsAW({l(>T0 ?y9~|ZR´:M◚j ;ʹ e\K6pA^ύFO?izLA.۬wFc<5̽ob&!e6Ftz涠ƒh?EWEOQ)X*2b|{I[^\sɬfa%G^A8og/g+fg:b!KT3S Q|7HE !H鿧+Tmը;emqjm2*rVCdhlf4`7y?qZ-{xٓ1@aFӠ@rݪa_ ?ڀ9d4HOImF/{)49@_{R_Y:0v*jǠxb8J(bh$DYoB- _"4$!Ί02οH\c|;z"E'5?MQ  ^2u#Y6}Hj+. N͚P3a;8yU9t Wm %FDN̂K>A謪Rl_%W/5g/ lէ#R?arAd\c^`znP{k׭QqC=h+:НL.< u:Tņ@s*8I v^ej*E60xpT5i@ZyFwl"I܃r"b=2ԿJ~{_ }ZX<|=*ΤKIh=DGA4~ZqjEG%rqӭZRv\ 9 IqyΏl?ul^㽁ӕ"W#urV\)8Bnp+Ѭ<7mI]rWBQm@? ]I1 >iϤO4{+-ikj;4|3*[ə!牤1뽼9N܋3 JJ!&sTe ݖs{Q܏?gWg8=iVބ$E"R:*YDI(*]C gx#roO,j?幈ܐ!֊}Xy<9JC"m}iurM,5"XfR2Ī)9Sw#S7c3tr-T&86@30S++-sQk6|G%[_%UnDd-0Cy.:?ǸFWﺁTIP <܌.Fm?A>5;*^2BIFoJn R2_ri 2 Q(:PS ̪n+rTzb5%{t^ҿ{ }fiy'0W`}dy0kHl?Wwhv9`gQ\H"W{̊тwuvMF9˯ry,Gsڏ LHF7wC@lh6m.v+5:13HZyV%q½`=$09q6DSSwdwE6Y x,vײSs8esMNePt6[XC[bI&,YKcoRCpB`4ఎy!)Dޝ Xs&A* =۟oaޭqRp6[F y %$}6a 3r\8!j/ fxBX F=^x(ܫ^pvyBp]W}(T2G)t*,TM R?9X{dayۻ$$9D{Zͩ!Ft@ iu[Bչ|>X*P Yb=u̍r/`%`:SEJ:iԔRe; 2@mp_)}.8@Z1XX 1UGȠ37hW{>|f3l"J>>ݠG'G>VCOQCWVwhp=%^m=E$zpEÃi#L_RƢVsBVݗ6 feUNHVl(Op1}  KY$"(w8K%&Ğչ]vXrΨzoC&&?j-HaK W# ^ 1y*PΕ״MdnjUa_3TUL>h2QWt>X5D$xf:Q,Jz*jGoA0dGY45czXQ(*q9yKde@ u,nccyRlg8yڝG|4Ld ؤ@14֥qˠ\ϻ\(s}?x['~l~i#]o3~ *;iC,I18Tc~gYS 9Ӭ Y-H *?w-ο}]$K3ژ-G߬CNEsͬXSH\Sbm3$y*N0uBEИpKtbD%uৼ2o:=?ztNUza8|cqYux͛,[RJhWB 9RI8ؑtx*uomHJ <`N<_́}lܒpt|qA_vZ| P9X{ k"] q Stm@bD3A]u-F6;I-aI7-A{!LCX-z5XQ# (Bu7P\lfAP1 A(JB/T@>UZ`>y{R\Mwy?6bY:Zlo1GM3,`?CYkHyG w؟b`D[;}`ƃ_A Xyi;v_Œ"RZ1!ng6#dA;U$ɘuos)'N< PX(aݵo0wP Bئ-Uv&}*t(2])/t*o? ó qČہ;03Mz-}zr3O/sng_J9=(x,T9=c{&}߀DHӨ!qEw03zckTRY]]T }c[fp#DJqdL96+:!ZGmzMݶud9: K֯ AI42 ΄˂66eʘǘ.n#MCLŎZPʣɪ)S496,ĎqzM]-Opni+7F<N1B5CYOPn5`qxZ${Dmb:l ̡76I aȒB/G8cZ("ỀǹNYS+p+M&e)߽}:Xb`冮WΫnEA2aCuUݬ֭j(jG_UVuJ\.pVHL1ΗߑP=ΓM#kƐ[QQ6ŘNOԘ^Uw "9٫ >x.l(~('~3bcQd—^+RvWI0v}4ܹ %7J2QeCn{yb#0-Xâ{#J, I5c.€ "b:P;z v!=RNT\ed7bCUyl.;:ry(1N4Z*<@?MgBpB]=ְK64Ln&RqzG}00q\5Gc!-r_َ ݸFR:z'nA'jlV#>QPxi+%$M3ƜC7pr ?TPv"BgwG[7&?"R@#,?Ac- 贰S';}륀ޞ+"<%0,pNA'Ш޳3l{ aeZt@汚hSzjT#b-\s?9TL]M/jod$" 3cYmꚔ],36Y/{zv~׏8GfiU㘈г,QgΩ1ʆ+6:39N>2m-cRHdڍ"\Ua(r:zRi]w҉58UF\E%4UG _oK.&u\E+3?(Im$j:kJyJM+73[ W{aeW#6uYSLr^!Sk)V0`"Pq脞G-bN*"x`l_Ej@3c;igyC:jz˞ަV9?bBDod-4sWJ2p7j92Y'2܍9E0t7YŸB6j *>GBkE'۬6HZ:h>6joz`孥2ޑZev"%rMH t.s( Ψ9}vv W-9پO` K>Cuc[^KeAL+c@8{b|Cگu3DTk'zK;\ſawOizj5/\_P[p&|:,$0U5s) ֙]f~LgN]ʡKj4-3xb6ʹժ-N)bx+YALfrOۀU6=73`Cu#3rtPI>Bحhv=Q-gpe;/Щ%f+ycm #UNF] }YykboE)( Y^}#I?P 1D/OH>ؽvKш㥋ֽxļ>Cz?s߉8WQաb<􎊲 5Ǜ-},h8 iɱE-LC8vjjq*s\˵MzZP< jF8Ѯ-b vL> mkn ,$EatI:6d2BGU&5IoR 7G)GɢTH:_4| X hB39,2sVP+!"yNS^k@؈Og < s,n:Ě9zr<% e(. \.h)&=Fh蠚@ɴl(lQ^eJ]DlMnL[0h>O34;ͲNѹ5VWƝza*T%7}x H+^ G*?tz CTC~ #͙ .S[h7IOsz0I8>gcS4K-nYxm8gB泤~P7W הXx :OwyDō<:m}cU"&R=fp0dbq☹` iCpKfΟ)|$&\ly;r Y2{&- N:A !Io~J5DB!a gfVh7YہPx#'y\’6Xc׼VtABoiˀa- 3e53IL:tArj%m2<DWE7 U^+LέT R|>%1x?GDn \c{h_#P'۰0rC;ߟ{/Weyc$r+:ʔF ~,&rAWwP!I|  Ti}{ׂ-RpeFHS]@a&2 NuarAp'A5W ]78rNfqF4;-J} $l8'" BnwSOI>梘Mk1ȳLq:ZwL2i6E2p| g?RJ%c4'/U<8`Y)Zvɓh Ӥ~0? G(" }scQXHq}< E=]r ?5e狇Ig\y}`ݻD?;B +wc΂\fl; `< IEUոWb&rN{=RxS$[MiTJ !z/7;_x{2aQ+vFʴjy_<+l4uhG=͒@ 8nx&$6wʋ+Ϯ7)?¸J0"N]hw9H&O}<̚Y6# frĀ27&{5E&F nሐ1p MtXhg?MKȱ(HC>L 5!D۟W#ЎL46S"${F+.Y*JDYOm྽Ab|=[`({g{|,$G^uh>; Ň8P >\C\RHmީ_ϰ_i{M6ND /5QXu)e *壦L+/@ qS{;Bft1V0<4 SPfpvKDAQbgT>TְG[QHY]]gy7S8 4c)m`^z0.X R8W̞ X{EzO\ƜY mG|R@!l5E7dI 7rTG;9I+ ܩHuJG%-ŊV,|0BFŦgPI G_xquW" IwxM(FC94T^FV!W1qJ ])n :\k/ec^r6"ɵft+DB.$6'Zcy8 [0bٌ=F ΄<+ xt'mn'g6\.᳴f3 ,a ay=ਭ]"m|Xt!]1e(T#mC~,d<*EQKKF&ȼ5N$m^ie?4DQYLH1#L S,]{`xa^$a־zA`m|"f.02 c۠ e bhR ktbE/Fiz$L \>]ŭ4THX/#TwFB2Cƀ4j#餱.ւ2=42@c=cpݗl<n@\/][cnn\_[ ,Cu"N6S@"z1 Ij85"D-2 ,7QQ8XSjND!n>20&hin8] Eh`,+8f^Y١`("M/N8`_yŽ-;R _>E6r@jLrjF*4WrR=:SV.%Agc,33ڣ|wq `2O.k#7X{&vke=fL:0RHy4JTtz΂#L{2o##u;|^!w=䐝l滦 bRmsyfm}©mdOW J}GD2 fxcpѹ68%v;~'P?Z<Ƒp*\ηm1 \Ժ#AH Iy&F^;}R|_O!NЕ+k49S_JaL^8(K3~ڤeIuy JDjsA' S~4Y$ꨁMmx^|l(U*.eЕl_Udwʝk K簸@?{kPtpQ()&LP+gT1ɯhm\ $-_Pكqza.PӚ2j)3'P=z'=)3.AC&R]= >ƷE 6PNI& gJė; )$a`ҹ9 g6UeUulmBto{&GE44E&O6g3@A{I UK4fy(k Zڠ# LPRrbE J&xuA7LG9 Ekso<+(7f M^EG꿣j\U$W*8($,(\uN.8% aŜ**]uy>h4S*C^- yhQdk' ?:Y9M',ʵp 3otJo[&Fܞ" A?~~3u'uٶQ]~W,qi IΗfoxY>z@k\<)k撻Q0;g!ܛ-}'=y4 >UOxoCt>;dGjϧ΍a d4 pk`,[Nl ="P &  ?ah՟syڤf:S-9-;9{G9f>RY-xG,4 FxgJE3q^`Q&뀯9/& XQ ((rYr2wrsѝF`FWCf1]^E~1Fc;*@d-~q|1슋蟱}iaA Br)FB HIHۆZyt{x6]ކPMAVn.yebO3QҨYOuɰ"^ȬfLuP4ߢ]\"S֔vt0s!|c6 ;F,r/A WkAٱMbVsGl/Ȕڞ( ?CK֝4Dϒb˵˶vo%;'INh\#|hꈺv uLVrc:r}N3VSX>Xr7c]#}iи27~cBل10|@$\ƘX 3m7O=&n.JΔ-tuIxpQV'h.Koxh \qK>lr011#io,zM{Ji0V]AJR Pǁs+8ٴnenYgɹ֐n4_%rUBF`hCѳ5g/o+w}.pU#XF'j[#C?ȅhd\'{"&Dg3gf 3ηKcv/=#!?=#; cҮSc;j͘Ƙ*L]vzV9{Rr5,6gؐ+kyRpV*ky@TY<,LlŨOpdYlsSoZX!#A,1HzE;$L'/C ]f-ъ1u_a߭WTܥ9 EW!XNL5oǻhnL8aTˑZ b>ZSҩt蔸)C%&gӨw8nkPĊ7^O͎T 8 :ZY lA.I+)=0?N5 *ذgS.l`+*\sfxUt=cJj.% mmg 3{nˌ$\(eu 4=~Z(΢(8!y}ވ#8 iodSԓi_r댡V`q5^^3 sADC7ϲ[j~gx롈鴆07d_UR<aN9U{ꕞIz %!oY? S=i}/ Y(u-rd=kr:Y)X}FZ~{Ӝ@,38KVJ' Mzs <jcg~1H3".Ȼx(CobvF%n/v}0_(k6Ha"cim|AeSwR06}UdeB NeJWՄ0>ȷ#OC^p q+3$տPy"djYg~*IJ(1xe aE)ix̄ -K)bE>HpaL v2cCD$Sp/ϒv;I}qCT:o> 77C̛-<|eIWPP+lb,֡"@M$ixMPLpKmx7E:\˨U'mcWdaol>bI @F2Xhz"=Oc'4ՐeNH()쟐Ś_Fv]?-ԃYL4jy(Ij\]ia"B=fWw7P/ ǡ724(k1:?O ¼ ̃Vb(QX`8]45@n7zTIX=%X:&9[ ',E8AG8x{S! :>"/T/oıTwe>ߪ=@K)#}zb7J.q\ IJu|%DWuCp[KZKdڊ Jiq|I"q}RS7Ϸi|ʽ76fƎ(:_S!RHFG5[B^}ܲ\ F`8u̪^I] 2޸+h@a uRn[äRwC 8t qy4KzRbܦ!.x=grU;Hăqf!&AdE@j;¼VIbp,KvBx'$T 0.l)T 'mJꢛ=&QQrIRZd!\Qp t\ܭDOK/n\q3\^xVSȵC eYAm}\dD"gpc+oQsasE橦 U:>}+K䃯 Fi8`(/&.m] ¿Cxx\_ Y uiT3]5}/I5MDgTm`Y5AAv'$Wgʮoأd+<$Lpaa?D͟xv הVD- LÈWobVx[tIq%_s2u9[R<# Z,^Bf;J:^+̾;E]) mX|"'Hi|y^l{rS!/F`n(>%Vx''an7\|mΣ Rs/؈)B8տe ?)gxE-/KtL6)Hy8=Cי{QMş i‘)[K#g$wFɴlZ͝scX-C\4۱"ewr |]K+F$d%'*ボL/~@Ɂ5U*p;tǘd )D-$]2zTKc@ŐyjJLn؄$Th,M` N@tsZMN08h|WM"̸F;ڳZ[( ~`Oo=ƿDS|T֙MS 5%EzZ2>8FW^">Apucʯф$q/%o'\]*g7 M4}aܣ*^~XDX\ ,)E8Ǘ~s_ҿ*7d=t@=iuE4I7d||^S&*H,L'>SCEX02x̻Av+c~pHҒ.J48Sq L% Ƿ &-I6vTgEax1(H T t/r1CGW$crTj"_wkH=u-↊SC>#?]E @yQ _I{ P),CP#Uy^S> O@Ok;5I"8HESiV\.Vq=tк6 ~&˹r8LCBQ1$ۥ2 Ѽ/ٙ[Qc`NB~Bb%ٛxHe^crrVAIlcDr [v4"X[ll ^o>@'b ^%q+z䜔H!|wh8H%\ppYL/U6E$flu9D-69*'PV@(Gnj`۸圖==d@"FaH8yr3"0*'V3g^xQ3u+OjZ(/ `cp̄F!:\Mj d}JL>%c[j+ @ܢ)}~U0L\S+o1<ưƣksz|q>9Kf=W}s|g+e'_p 4qyа ~:dUZ4$FVGu;FGcko{\`MVj~F_=l,6E`CQ"Bϖ84j;L<06D,OCޜQP!-)sr~oiDhbf,i=虆 )#쁎0j AC6*8F<0ecbސ+ 0U5($m2{cs|J2ūzLf=,aO;l-мtxx>z.pݼw236-_zSi0 ?\%zKI,k{x`]iR3$|93Uuif>g4]K+vpN۶IiV&XL/ix;k GkfqP\3r_a|A b>:Ƭ2 lFGKÝZ?t]GvlӨ*;9Ov=2G%k5>LͿi JZ̎hZc7e<0],^SK9=I!Ꜵ!F+0{Yd2ߠB|".e" 6.֞},&-3c^;c^CyQJ.vF07ftLζk,ug\Yi>^瑟 NG 7vKͦZimS_q/|DX5oOh8}k ɥ_VsֱLocIiQytH:$JL?%!߭ \$bPOaŔyLu_x`ƶw!)Px1]V=g>f  @ ArpyS on!1dTG1tb摞ʹ-_1jHKjC)X46r:/R,V}$x_KT\"&XX&x( H1?֋?f55f?BM$Lqo]tg"Oq1c8C@2!wCi]bfI,w`-;q/ErXdPWU`M+FתfvE~ࡷYR%A49Ə5"@ b'rs yX8#XuE4%RPsZ$-DҪymECIpɈ[,_Z 隷h=4q\0݃㭺,! 9b1ECn9YrYJ0>%H@"%mx#c'F'S!W/@?o|- OD]i7doh[+&jLQJ@lSvnANv}RvJ^'<07)ӗH}dO̓a\g`bW"wVM\1ԥk I?&P݄f-CPJe5i\.apaABLdPsen'a0V3JG?Ci5` ZQgdl9cāzu w+\舻g"=|._ԝ4%RfGd.kLe"NAJ%FHьԮ >q^m} WUF>9ƚO=,?KK1Z^WEZAcl-Rߛ0MfSd%cdelT8Ae9A jE]"NڌPŽ5HKw+ka l|y MuS)x N ΞƸ_#3R=.g3 M-DfDVM!Qj4>[D8Y%9-7ԣ;ej!?&wd?u׹Zq ck%nY :~sg)EG5 wPFAg#S)g1g_yj D}3UU='\GxgM1B֔Xbfr)у|\x\wGt%m^ \K`*ړ]%7, $;_t[x:K7|HV˝+tZ ]T>/AK$Z3D`>*jձgz> { {cA`Jٰ:{E E& a%ѫyYǦ+ ~@ǎiaKTx,kl X~=LD[:kPZ DCۚ>2nzwWܪPo6b0CfqsO> "PGکq*{MzR!L^a:0%$ne_cuc,\@rijmNB2OmsТ:Եd7h'R7(=-x:(tm[9O[ qU<8-l1j$Mկ2LHS9/n+J^Aqz2dE(, do%2=x4'?،r*d?$Qa}i jY_A=̄cjn;RF[ofM"+"nih`? 5E_(p\5oK&8B)QW@g(Wť7?*+os9-CeMbS2(Vetwu7-=|1&*4N 2Ya)wɏ1,dO< M() Y5|E8R?oГ.>.v!LyffJDJ?ABCl<Z@%]11B/QxO7-uW@qoSWjR bXH)DZ~O6O,/DlFīJ1Ӂg@/ו@G_^nb#%A%^}2 w$9-{cj'ňh^1:o)jsNx?`bie{6QgZ"#ҍa\=z0in%N֤3S$j_졼[[+. J 3n+7W2hv(=P$CTw?r(S!8`n4uz\7^I@|3s xltB gd;CHHk 6(j"u[w e@ftP1DD]!gLoL<f0< )`nP`Yyvd ^U̥u1oJ)y$ɽ=oۍ I7#2É糫m(Cʕb' zc7ϷBOoS/#hqGAKq ,&J(tvz5Pl{$dq$(ޢ:wG$:ZH6!ﵜĠp]o 6Fuu 'olst"dӖUܽצ_3R:-Xmz#2D@T~IH`IbppZ!BYpgXX~Mn.c&5ShmʯSxҴ>ƕ=X@PaIRrRм=%*L3h}>¶@,XHܳ0{΅tdi|FĶ?vs'FQB͌36a1CN⾥ƲӄJS n6HFZ-y`6"JO>iF&DgQDҞ(T]gq 'c<(AhRTDʫ;͖OXT_6N3f_ 师tUHVӽo<o/0D(2WNr6AFO)&_q#w c#؇ƍVO{`)>vy(`Lָ\ALZGuB˂O/n m?:0P`\IѪibz!h4DZðOWKnxRsi'G̢|U9 fsL!'Dݍ@SP[O%$~Lxt@l.U/N<}2TvF_ F*{YnkdQOn'<  16W74/w|R1(>| yF2n}cp=CŽr#Xb+JceVS"s`o_=#f8ƼJa|w<~?~B%wЉ5!OOo^ɢ^- IIuE#˧n[f χ2StiͰIs;*E3rm/AtxMpfŝ;[p tQ\ZlGVhn{um"V5q!,̗:#>L`Mco^4]Zmm,~u0CxHΚЖzU헅ъTXU!#sc,_'J(NTx#nM' (3z.ͯ߇L=Ke)ylPXTvuVRnHb)p Fщ)lw?8,rDs$|,;ǪQGf"`;B@kr5O:.mB.G57+:W8,cݥj[\g85`q`uvFC#3!qt~zY[!|fa b#?4 Wkư4HM `+EjBr8/GQto3~0Y{av5- Rjp ;4I1OxnN8J_Ţ\.+na-?wf1>QW;3E.&юʾftˢKjؼD>%,BZhn(u ':R*@voLDiGpFԵ1w6`_T4ߤ}bNV$&A5Y1S:,Zl5vk։fluC>v a. e]0(v=_ZA#ǤV{lюؑU]k4Sxjeh27O/8i\ @^ ܮì$ҡoaw4RۮœI).=2܈=Fr2Fx>Hy* DwTe4ʙTnCGK{@?c~03x,V R}Hf cc#-OS9d₠2%2z7G7 (joRrON#,b!BƓԹzh9FC,)rV7/ 6d2EYa-&[3[$e8vռ+-69)X8߼O C~3b'gsS74x{)$#7 @_O?i.qܺ KBuS{*K0]S%KR~7,~Sq{˯ rI88pǛ1=R4cɩNz|J& k70Q:fcuW U{wEƂBd7bbH6IIbLUoB`o;DcNEiU-,/ZWr=gk[07m>oK1jO9EۮfF8mַOl4׀*GbhB*SkV Au '}{YLLp1F5GApTiPyK+ n,}:g?7tir|`ju0X= ^zQB[J^9 5S#mz|Xt<]o#PĖ'B#)hi=M8Fṱ,)?VP$gD< ܲPwUa4 TYn`jCKd5cwB'ciyē[Tk^N:IGJd2Bΐb 1p\Z}U9ʷEؙsbyvPeXo8Dfc[LXrsL?OI !Ju6c!Ӛ68tx=: t') 2Vm+u={(B_r?{ TEnbJt{ 81EgChA JKڔJ뜩qHy߁S0!/Mɀʵ1~DrWw$dwJjǷ]ˤK1' ҙ莳?)`P" i,;-Pl7y'.Vr ֕GO >;>0 @mށH")|Նq͍T주<״P$WRU㸶-hN%4TBw wInLzSTŀ+qH'"!vThB^YEkx6/8OĜ]I"z`tx ]&EjFZ _Vo,=BNԮ~;V'7_53O%N% ( kJT1đ n;G%/鱵FcwK?O| *8ܲR=BKdgh,lK=j*B=Zb47V8f'\[gjQDFu|;Tf #]7[['ɱk4۷`s>@B; 0T阥š%QZ9-3K lESFC/#;@L>ɤ!JHߓ= M pBZ9p A 0iϨB_oFτ^\>aS2a݌w.M!k>:h86v^I xeM8lcWzn˜v2wr?_G=6օeX:@m\Uőś15K}>VUb;`ejV(RBDpmSkDnZDw7}WlL9Ġs~-`̀OC Ы L[7/8rٴVBYMb[PLW@Xj'X͉a{5:PSBJ+:?ڿfϟ׀u,fs61_yI=8b{?l'/̳\TQap|Ѧq{^B0Q1nv,ZS!AEͽO4Ь @tqAnɠUX?$Qf|oGtvj9V%gR2*ƦGT\sjؤ(1<T4Cb6ܔ"V'~(Ŗ7Y&*)i%֩WtN[ kC5V )u}P[pT8Oܛ!YՉ@LeVH4j2"%db@< Ժ|_ou7?no L l:Nx%xZg*^xRBH { :O*I %*TJh$2E"=+q;(6)?Ҏ期dӤiH+㏿ml؁Oio1k'-gwԂ*K1+~YnJ?h}eAya' ؁Fֽn6e"wbk iwE9qK(я(KWv)u\pгYXR״hha>+VfX̸K p{pg8i6)'[K~Ƴ)5܆\өKT4BOƤ2`.c.tq&o63b[gVsm5W%Sr $~ \( rdV SR7t;,JUh[O/,d]'6ZAr.:X@'@ iH<F4J0sUD%YCwŶG1\Y|IL>tD&+oP MޔK2yJ?!~ɋ…1;ՇϠ '(H $xL1P j;,c{,,URfoPH۹&YY]n Ĉ Lv莩!{>(@6ęVEEZb [Er ettc-/$A ;F&N9h U-d&`=@1V-X0 1z^+mfx^J1E pd(~*je"`J:őp[OԜqb%/ø (!>dX[%Mq1~C =+D]k"|)/:52D26A#FU_5eu8 E?~+.OԦa+3}|!3V.ڈ=#4!rQ@}$f˹(,H߉)ObRCuQzd- wh xTQ4d']5 f̧&ڥI-oa^U9~N/"%`j*!oI:رCrձMIIV-֭ū6*CmMq&z F"p:$?|#l7t]9wG{n-/TcP>tMrJZV3D>EJ+J;yBU4 疺` *V{Ԗ K\cnF^KO3!~(mV5VぉX,5&k($ֶO XNVm ȏIlZkFX 9Yuxɳೊ$G,GI;A䍧RV! 1$ pdU>#Y5BIJ-JD`gZi}=ۭ#4c&5}Mjvn1WipfaeE$`|Bj*&gr@]6ֲdwݲ[̜+R[qYG\9qlmX Cʪ)O--$pܓ q&WS|C'(k6$!C:.+kF?EuUv5zc͐ X!jjA.+ʰx}8-tJ/f&ӏW`u` 'cXXڟJPK:S!=6kHt,6gIzs"3icYϪԼBJ2IJ}@#M$J,T,MV%f 0U/heԳ4ɻp+瘗п& Ι:3"Y/?yLH݊y酮a.,7![W} F>@ Q"'z| bbZɤ/Mak0d(RIه|g_(2G,w[Zio)P^ɭ_ZFѐ.G˭֐-eͫ>;$󬒑L%+^v{fEq$=,ExPYc0mIX'cq)]ԲI`bbIXg3*R1'5#PK+l3>/OП`OyxR;v+59֓k[ʹX}ݽ+k4Jҋc(L:g&ncOƛ8axZTuB(5j j>pa!QTMi7xg1OO !nd8\:~^oy{%[P>_3ϓOQ,wQڨ+;޵Yp}Tl2 b7x4KuX;W ˗ ͑.D4;&p.:6FT4&[n`*soh=[IqgގԒ8IroQz付lfuf ao3~Q=[c)OEK0lj鏅t#7Du1NP Ixlu|ic϶ڭO Y0 ڢyC|T+j#ZR"sZGi*U*/-u]ub6+&vN9\$)V~Xo["q(l:i\^TV.]Rgž#26F'7ʭgLb{Hǁd2in]]4W+Ti4, XCc6i9^uuqwX=%$F?-R3-5'{ ڐ8xl0)E 1 ҼԆ+gO ';`^${cndD-nеY\$)Vn{GDxGYjG (k`<"w!¹WO:1GƁR`,qwldm31k'Є;J%pi.ݎ!R +tCy,7rٳJyE& $IB)3&MشM:Q9! QZ%B{{}  0q?%ڬ1D,ͅ-6ى{>xMR Xܕ8" }܅8~vX|q)eoWWAԪBMbJ׵ GA,K? }CPCRMFO8(lRJ`)ґ;2yAx׽4zO%yXdvGhCKQ+Bo^tPGY`#P[q=MF[M5PT&為Vĩgڝn7i mh5_Ð̴US_Q^txJYhNAB;H'e b]<]훭C o&| csAo/4kI5q5]$3]P>9U3URp=hPсWFj(zk+< U<jʑ!XJNfh v]?]y|u8f5*5aҨp7Tj[/ 'C?AΖ']'tosk mgW,fu>L;Y3+Ɇ}sv(ϛNkɷd܏5=l|I8 ChG%-!a|fu#w}.~4)b3FP"Ч<]$(̀ lǭTvV0 {{oݸs `>d~vskN,-yC6Y̭.qElxXpܜ=5oR4H58p@' rɎ;I#gF;R`1s<]\`L9#!BNJ +CǢl"81Q[(EW[is2r-C>U$ǝi%]Pr2_^eSVy9 8ԃ :*9J7Ow%gV~\fq[gNf&7) n̔`iy?ԑ*=jU~8Q,?Q!ץ$dɆ)r < \our̫vQs_E\(15rAD$n,Y$#ԞV'!FpvA\BW.pf5+q|g;>f&G'X~"J#)Zgt+fDm\1WoKGNj`'AY?{S}-B啅( twgpJyr=ɻ2͎8//i¶=[ eԂ.n (?+BDG0c&\]SajS j )9jO!p)|̡3bdϊ䪷guӧ^`›/ЎoԲldN~**?=sQ J#1FVs/$"1L$Uălj~h[B?'"Zi ]X)w 1.n&([};ΚQX^W^ku960ZJ^R"fxRTT橙BYdTFUFM4UB Mш/-d %O%EgdS|rn{}޷LNU@hDDzSar:_&ܻ8IS$t&ˬAd >y$OW- dŞꎢ Y%Q?BoDE2 W_1bw5 vẙE1FjMD30z&SVk3=: +hqd%thk㖽 X%MKr-%.%EKa%2c7iwRQdKam9fF\vwL?$ [,j|Ie%e7qY%3c-MNDddDO9;CKq&}URr؋RW%5tZj@ui2ex$Qu\ue 0Lu%/4AyH$l>xV""贚{D*0w4k48 .d!f 4<Ԙ"8Y Pt ZiB؝h֛z tb⳨4!&͠MԊx|۝|Q兛qBn#!dXb7 }ɸ*&/}iu-\AJ;c@Ej}~lekMX1]S+Muuzl_鮯Z*_gϪo%ZQQLADWWDt!˰$J(nSjz0ց,?mԛ K+ĎQz^jm-4>^hhG[>깝,A)Ê ~dX],"d|:<AElko!G{cBe,&H~R.HFlJ ^Ik꠱Kxit`&yk}P=0 3幔ӭ=z >3gu5G܉Hmdy-#V숊nW*m}S9o[|64 iXxNż;IžĤ p81TIPz滟cER䵪 ,jh+RkVm> j؝2z@=98Q8a`x'aԕ2ZCQzޒ9ˡ!Б+r~f2?fw$xd@F6ճo5RpF''NQ87˙&kU7~0ն5-~X?k aXb$4F榤pF@GRݚQ#Љ'{ gjrVYφiiPhʔ);!e.EchtCos~Dp@8m)^9.o?-]p*>ynWwlNˬhG.&)2CGI~s&6Vˠ&%y`Q%vLFQ6~D*I+?~vggWE&Oh_R_u:aY ߧ[tj-FR&X"y7џ%2e9EBVwV!' @x\zՊoa!9w?z8 3$>z[E;g4O2t aFCM*Q4tper <s8ϟI4YȗZk^ rh5 ?M [ScRD;ǙC~E1ӘӪJ\n ,z৪c8I֓@x0陬< i<7]pNBt94!l6`..\U&1RFE&/ Jј}W&)ٻ; ޭЁawjE}$T H oA>sn^,U]`7r9`{&:qTz$+)Wb>si?\r*-_iӝ Q-61ƣk`0ᡛYđZ#\43,{lczy9EU B8΁g[rl;j َIHIB5|/s 1δ}'6ir^N:Oރs+gE0 abAS#)^ҊY6cKsA%%.RV2Q$;67ܮtK+9fϲvduxi.6Q¼f.)dQMǎԊ=mK%ɥ)_fl ܛgDjkpן( Fd9|"k̯潼iM _s"d)#VĕX#KC ( N wfFրi˒3 6GzCD/|+Wfmę3Axֲoքl;}LTBb%t݇q0F#YmusYVA%)}l N8OJĈMkV1QP pl0shNXCT_^BK7t`d\w3[*o~CH$sBqȰ!̼QͿUG܁ivӓkc vGe\"gG#9WG_%ɏ~] 0\Ne$²s7η5kx#`]{B9ȫT2VjF`렺&&<>jܚvjjWÔ! ڵ2{- 0q!&o@G/%mTiVՅݣw36L i?sv^f@sS-W2H>G lߋ}\ )dC'>XNђU-5J/$sq2{lvkڶGs>PC}ηJ5:Y|w]] _0<u% ~&Lr$̨a-p꣢))+Gx ߺ ־J xLjo-x6  g&-Iz+aYTUhKV+r{YFʾPijxƔab֣_bpnrXW񚎤 =i$u-w\CTU>2Uk\t%e4,2md4z-ɀsOD~OrMNtȒ&Cy.̦SSrgFp-V"%wV<>;( >;LT\T@i^YtѢX(cQmuddCO^+2atbj`aݽI|ahB>!uQ2ٲ3 H.n҆A\a"Z a,Ku„xlN*`F!F>^r+/1@fMcՆ%gq MS?Y/q igs[P&p:F9m Py np=)twL&k54{j>0ZV +\h*\_龖&g,ĆX?1}aOzH-$ƻk«&{ Y8hs+_sNxc-%ƺſoai8qAsHmqYL'-U0Q^xW>3UBX~6gXqμ+,ϬIԝif@g=ڒ`yjXN#LTׂqF{s:;/eՋF[0>bVYM܇~Q;`}lJħѤ4~j~Y 2;0=Zg/󳪴B]r,T|TQ@73GԕxH(9SgMl: l? @(_/"iȳ”AN `!>ޖ7=:J[ͤ_A #uԛvy&x"9|ˇR1gU<މyT0e~-\$?RYX얛Uضhٴ.(-v4-͜R;7]}3U+p}ӊݐ" aCpmC^f>&skpE:V,|{wH uUk5 hR.TΣ#Iw cя}1^Vq3+|)gMn*тB^S$9wl8\k9'N't-jVfR=>twBm6Bo>KfurGV;8b >I˱༺zD!Б&?Y'-PZζ?)^á5#uFʟ[a<]GY_4J8@eo,!zXT4-Ux4w홗"U/cZ{G"TͦyԥPE>:9 ) v8`nRxGJ8]MMq`gu$e~EϠە@.X7hs m!&,NsѯIA};ɚzEfJ.ަ0rP9@mrh%g%˹o$$}F>k62)C'*u ?JGnn;o0Qyʒ];ъ/H,?b?;eʢ>٩$(lT5}_<i8g7Q\|M]G(L5z|_"1V%auSгevs9ZRp8@z`{v;l [N_#U Z/){m`5䒉De ָ,sf3$q!9>\+䖅y!5R!9j; 붵(#(|U n._Qm"Tx*%!OD AJ}) f-|T zxHg c>Eq}1`43uZƟ&5KBɠ n|àE{mynY:kzfaA8SQG F\(x&8ΨyPX` ;Zsf.ٮĬOtoY%\vVyub6ԍ+RBz/`R(?/ܳ]'UO&8eQv{}gYeM+qA"t%X]QR &I]\_ &"|.a׾ FB YHsP !f͖w e}Aib'_{1F+M9?Wp7uf& 3GKtZ"VJM/ڹ"8 i F&Fg; )I*hU- By\{F?-ˉt5Li*,ڱ4:Éet TpjSȝcA" zU4La2`̨Hq p5n7#)̃c+3$4>kkK1xӀgesNUd׏:)~zAl\*uHGlkmP Ƿ3/ٲ̜%<BA?e;ƹȰ fcBe暤+&ۖaU6r-==ܗ N:) k 7mhGA/wƹvE6hYРa[>]*‹ ;BQ^X ^G!#_*hDUMq|PI|RP4H_?hhJ`1XAHtfDT"M g*,{ 8 (&e.YIgRp/=*EPZ-9?')kO05v#~6Fg/naQ5$bɍHFUxcZԗ?j= ,D?0ݒEZaʗ,,jS/@" SE X0aomCpIh H^ʘV%c|µ rꊦ:\#말}-tݔN ,/=xD/9?E.V9DEt)cV:H162rB[Oja㰱J%eX͞P 5ḥ[H}^>7c8&HE&]nk3k>ǟW,dۨxʪ-dw_{; ݫd0* lr 2BR/ kZnZ1x}b ΢A$ j& iC]$_{6i?`|<\|ci]FXA!}gcOq}Oo6HBe56*'j.80vq),::1%[ɈUIt"E-Mʰ,fܑN%F2Qyl)t[_L㊙:M]yG]wû( WO25KwZ>7`ٿq4*K+ve ,+MGf\!ttqyU%$j^ҧޕ-#N[ .F%|d1VB~S$xhW.2cI^a,D;J[-!. k-Cb%w/qs&/oEJ9kqtO$nx#D6c RKvPVbdmi4δsJn29l#|VrO1{^:MY!,}kv4ߢ0.Ij0,+ ]naϓVA&hr-(+94)kΜ(ӯ[\K$'~: "l0f.}!+ZUbcY.Kz=͈DD1e:>5 r ءqx6Y&Ad0)|j|Mi*fhZ7ɴ}W9x~Qn3̭S,ދ%2_yXSgZkݓ⩺gs@muvs]^piMݴ]mdKO¥~2BƜIoP%xR.u-jڑGϪ{LFBN2/v|2d3Bj u9\@RL!kb̫W3;3K(߫qsˑ'DGXpdf1'XrMV n?+=f.L`+tC|EJ8;u uaWK5o8* MP*G\n H\4+EΧrJ bR[E$)ʊd#YݵG픵d &Pd@ASZ$Wo;bN:EÀXS"If!W]t1Oo\dJB݈Ꝁd^JvH7YrOcD~TWL:KCH\'~ʧvMN\o alXBڞ) JXJ Hj%Ѹ*e"g+|lPEH5M2n.=\3!LPM=)rjR =[WfyѮ2k(/R:vE?E[wvzOz|i־vh7䂨Y&^^sUao3sGRY1h媀V$M3nEuSME=:RYolj_c1PiCv})}oVn/!Ily)m}=A"|X=:ƋDdIeB&bG$Hr /3eH̭]8lml\& 8SNcltfMIL}rUţlm>X~E7Ymd'᪝jM[`xgȸs/PpWݘŵ;]9AX ?F/4 N὎š2;=ZRso9t+O?)^աo`[ui?xJNeqzoߠ[js U;L9"fEn%v|N;K6:j7G'p^B_n f:ä`1Rl+ߖUSMo`=#^RK6N(PvdJŪw9>k/~{BjB/ܰ1VGQ=@ 2Jӿ| jy uȘe0^4b_Lil;m?N 꾜5ʆ!\d].݌{ E \oYLC"^Q|\pu Q3/tj 3gs%^Eó>u%7%r"|ᇙlf"/m2nyM"fWI 8LPn\*#Z$9fg{t2q$L B|#)@Q,o:i[)BiJltˌ۬MTU4X7t_O {ib, Yk7p*\oe/N$^u}&٭|D >CW.oEI%C./bFsjsj4,{  YpER\^x"r"U9D^ A3EzQwcZ>9 mДM}H#v(ٿƔ/:XPG랟~J5 [I"A.<-}D֫8JAxkZ#d9".ZkhDtqx87N'lv&viRSZhf+w#Hm(iG+ӛa/HpPC$TtQHNrWWUvHh9c! ~`$qܟbvT)iW ؜=IVi,OؽH/!E2MEAg}'7EӜ..RtH 58djD/&bLzX_D\#)2Y`fk\ΦRˈтhjGȴqqv, "Y9J2$9V4Ef)=uǬL XE0wE mt_u~Ra!/(vA-2HвA>HiA[L4bXWf>g8/ӐcLE零]mߍ[,Vw5REHkڭn'<.ScdO8F5c_qu^&8/w$,>ݗ컠8H;7ѿ[َh$\/()%<;.OvG!"/9=Qc_9ʉts)&?##縅ƝlhPvɝ)r~TG#jpF2^&H~+`%Y8Wn@UM(B[LRy*qSݼnT'շ}(הLJ\j" !dV?åcp8#䠫dý+@ &wR5}uPs1ϼAto}`Ў롣-wA@Q<|>^aYmR6қAP |y>(?1~6y{?@Ys2'N @OKt5xױF7 nh\ѓb?S0|j x9 )5T=NBzFLϲ)s31; Z=׌*<ګH7_ͻ02ҔnL/U*+f7'5{I_ -^_Sۭ=>[JGnMm@iD1JjyYO^a>.]9)A:$DoH>~)p+y9L:Z:5g㨲:Ǒ[#;%Ҭ)Zi3\W57oƳ`T ]VWv p݃ u`0ME*>qdOμoDpPj嫝5hX a{TJX?A[{:OAYYtpܶ$Ey!JR!/%wl¢2L"XĢW.;lUmq]H=ZJ(.Jzzrx[_ݪt|Sش ZBؐ) 64Qߓ ~'H]|~u""Mʹ +-U(psiu]K"ģY0lOnZV7b Ee9=Y^ Kc+[yxؿ|@:@2]l]L/Řtp op+KVh!B-Ϳ7CsFV>>g*#nZ}MlYVB"Zv?,xJo2dV!;OJc\17?%wНF2zdy~F tlaVg ]Ib*ܭ@k֦`g#pەe<3"*4fH* |VN97)y >wYKnedpK+P8:Wrj p^AmY-*VE,&u5 C=̤\4%ё3?1pFRAH[ig sK켧(`+gG@N#ïkjF i/z*hM n1* 2R8뤹l{Q L)#{,M[MûZД c`Z D.`cv:X"XY|IV/Hƶ"ď]L!(]܇$ިlAkMVBOPpD1_Hds)'4X y0hY#6gHegӬ_.qNJ1kuCƫ(dH&+wK/C n}|Gbe\/)l&m.| …S&`~nEӇIYF~_.١׶RJfwׁ:fZA3.,"E%?'!#ĝBXױyN0N+LNpqw>tRqnw$'!D?u]Z#(zRƤ/bJt%yztoKHh,$1ml:dE[1='sD,8$Ȱ]}{%cZD/tW@i *`4tPж 9QR/gܺ=OSg~u06ER m4LU:7ow>,~iD L ,= G\n=s^T#Q/]eu(tOS̴?;!.ѣkюVT~x5KzɢfI;N#|$dgo߹HfqT)Ar%CPKo579rDhemAuĐtGMe:DCxQjתuem#Ezg,n5=锒zZg<֙ʍcFG+aR>&1w. !{B=}V'Cnܱɤj C޷׺_f|xAɝgYDũzCF=N5mY,(Hٸ"6zecw0U-!چ`; 2*FeZ32ul0 D 1d2n8/oW0WdmdK!a@{|KfLȞiلr/yߺO2TY7\ Zoԝ蠐[5DC83ŕYnX| À,Hj4Icܘ_w7CQ誶c@x|&8>2ڂBݟc6I%wee9ӈ5^^RҔ4/&\Lx1DTM {]LWFȪ9Yc+IIN/EEۥUl^m+)ӻ4R?kKA8Ȣ"o0w&ܿ2CC\k2 (6[vhtC|Tj #N`[ OU%A$@_cO&КNs, X!?vZD|iTX '4CpS<YMQRru!&@w!([ɼ)U'qU'@N17)P/3ؖ>55YC֮3J8{1Pg~YtqH=-^o Zʍx"G=I/5 x_>gMd0 9>^@fnԎrupDe);@ JtdsaIԱQT6.F.Gwɡ󕒬k[Z IJVAS0 Ƅ&TIw&mOBoyYO``vϫW- bƃ?OͅE 29Ę0[S |$c =ι;*:6*0Yd( v2;_Ү-&jAvWo>I{Ln..uzCgZx1пb oH6dAN8G\υn! ʴle8#{@V^ ='um}&M ȑg96UT8AَHɅqKPm2v$N} =5:<w ?(=|h/ C _ߎs,;>nOL3TIrׄ,\8wؕ"uy+‡66E)}o鶱ؤ+T G𴰔5&%E𿟁Ԧ$0=ΞHH p<3tzKM>j&+AMp֊kdlٛq^F ] '/\Ά_}]#[瑁~> }ɔ*y|pwb[=+J'V1,%J!=})} K$(EL5^ʑ(asBL=ԯЎVii'VRq>*rPl4]Na.[xgMjl)Ks.3ֻ6Pn; +ёp+bÔ(Ĵ__N<I&+N<#7HG礫OF2![`\?"֜zJ݈Pϩ +" GPJvm܆Bt\|N\Rl_&G0G/>x5s Hɛ` mt X hVf}7m 6C ixO ԰q/? }P:~0W FOp˦z"wt*#\*ᐂ)c`4x5\$IA!,ܳ5臿i۱61*HP.:CN!PB Wʂ@J'Ά۫j az1D흑'[CzLĤi}C*pwd1RAr5EqԢm[2KR`En4 Y\%}ٜug4XVR(qȝ?"P\cG;Ot ܽtr B=DE'v] mķ/jK+b EgI|ŅC962 3g:`3mA Hc'-$V,5p * s9 ?~"0cFQlɠB.uUd"V|$g@I7 Uۀ+L7H9O |xtW7,=E(O*#DFk \eh?W'EKrp5]np6ӖJ52Q/Om#![t$6 "[=ݴM#ȺֱaVg0ALj`.G W,I֚+g\d螎j=s`kpU.Ծ֗=c&W៧TrqiFTB0rN=!,fșbI@3AN(wV`Ζ{耹cUՒ)7WH)B*Ylƺۜh#1HHUK X4(Z(^[9XAآ.1}ߌyڽKI+e9נ#yze1r  SNf`YyMV`aկ}n*<7"|PfoQZ3MxPTj×Sý:SsnwzTslD)n)t+pfJq8(gm+U4&o;HsVq_͑g<WkW9t%]9e"1܀Jb%|1/UY-C硍z7XZFL ,9s,-: Qk s*u45*,j4̔#m*zFeU-v8:447 .=b0(#+6틅ZQYL?t|lӫnJlM2Gf|Y$f}=Zϳs=w$M#Z] 鉍ӆ"Ͽ%c;f됎^r(xͭ`c-Lx=MC {}}e8mZ z9nzyА>2p-J!::aJhV(z{{7icR5ZEJȊ¾[ faS.D~ VXm'1yV|sG!b'hfz(k씃0%OgP(e,S(9m?EGEgx?C簐 X[Rk3Q;ٰ\N]oٕ$s I!cFg=U;wmK¬?: r 6կvDr8jc4EjyO=)zXeK;"hz:\h|&rf̘#7'wV%FepA4Ыi'A(_shCvH4'j^,]b4иW<e8Pv+1cϊnLl5aDH Npzĺ_+;9x bHZU2&blYSРImC2ĕY{0E$D51v5]8Km&x)='-Qk{\Š/M޿2DdBS&/%_?2$ 0kX?p8.:lb\HjWfPs֫wrU"-l [+1n4.+ O0+2({&pIdEb[D>I2 :Z{p_4 NgSP< &=D]~fZ8Js1|w"v99ɇ1D%4k hU<~,7umaf:wYX|U.f7npiM%3 X M^ rDXdIЊBl:)w"(/:40}O[՘Yw${ʞqZ*J߫rargdS9q,]~ _D̞~p]^\ /.pvW8Ԫ' |Or6׀8ZW5\ugr[mN|0Ocs֛tV޾;q,YzoN,qYkٳH'1`J`mdRrR <x]H˗K/Ae2ѫɃhO?t+|_'w}=Uޏ0טCJƫZ!69n ?QWLaXjM 1sTUt[ctqLl"m gH벉矩N7bhʠz&e~J9~lo}Pxxh* txhР~a"#8#ӂs zb$Ul;75gr@y$͹\4HȦyu*/Zū`&֮U)T2 Ar ∼p[m$7{ ]xn12ó!+ }TVaF`8*Z{wH$sل; iS²},ˡUӴ=`є>1j kbgk|I}_ 2K  of;'A-]nfG.t+0xl5^7eJp<$~2xaMT.rgPd(M*+8zǐԚwS"k2MsW4!8O+asY?Q[g8l :4HjFO/'xDךN!o4$OS-xr^DUkmF)B2[&?V`48ai}v{b\k,6] *>fU7l#OJ 0%(IXsoH_YW=!E ӇMq%Qt렗7w& > _){ClhԥnDɯK d3P޷0ER4M,gF  /*ekkrXz> 31)PkMSHouG U9QDuzc(U"&=$e8'c P~l+ 2oe|7=TbkP޼b౎ӐjRfiA y:xQTns9 e8`h - p8}u |>.[$@QY>&𞓎(FȢ0[,4ZCneɴ0NBЪHmJ^`ɞ#ޠQʆWK17%0DzUk;L>I 9o)D⫵x۽Ѥƭ,F,џ BIQ޶0B;{v  ~K9P/%Mf@؁bY 5hmǎ{8?Q{OĆ~U9<XM`%;+&td1 "8xgᄀP{3ufJb{ȓCBpVFz}xd< AuIjmqDtBr*-#׬۬vOsd;ӫᜬdF8[=shs@|3%EB)Ƹ 6; YFtԭ d}E3P*JքsҴX7Y8Ȥl(gjVɕ*A% z̐Ю8q4(e{WlߩQoM1ْ%RIOH:|k'XzE@;cN5.8 0ɴ1]APg^4jx5Xw\]Ql3q>yf>p/ Xݴ%?4~C<ss2itu*8A&AZ>^{##x0Kr"Ѭ/’};h,^n C(/kc"DSO Kv+}7k(#3޻>za| 4K>CMFҭK`,MdkcSD~%4xͰ=Hn0X߅{uQ(Po/{rwz#*-z)]#f:VieX:[^BT(2(=U*hx s*~눵3^B5,JK:c+hBɶj<ڰQmصt&@C![Ծonߐ\-o6do9{v2Y# +@hVKQ7/ {f/:3ذr9O!7` |LJئ  oGN6om=-aBYIiFZ^rB!@Bz ;!za2k 9np LnKP e"'H+~,/͊B%/XTgC2#Q/.ih2uжdn: u,5}UNRNֳ'oң)АoYQFo{|guOgj*Q1MH>+c1>h PcMeשݚjrhC*ʊFZVfv+a563éipPΖI(#"ꂤ>•QeÐNOC&1'Dq3nNԂ1xʇ=l(VgM(0=<u7 Gт6iƌ TY J? m-V srx{Xo!H\GI%:Ga| X=ӰKCjœ΢7+/kV<5W`[oG'Ǜ'|׸c _3!ՃxgWT3:+`tS=Uɩ5Icak\TP?^ԱiT@dS9ܥ;5UJS=WߘX"N^߲8[6Y`ͬV/='L3{C4SS˛ ([/ˎypQXjqTXz\O)RC`Cf9 vXw\KEB7p˷mg0H ƻzQM21V+r;sZևq(hUډ; psI&ʹg#2"Qkz2V3ۚQ͌ %YPq逦 ;Jpϥ]^F ^HC8}D0w])öMEʌ23/~ĤqF Fa_1=\v>')jQ4C<ӡdŢ>!NLq˟R3RBJmOȬR~~yTfЛdkOԾ}CНXSU_i*U elfv8# o9C\9" J-/#*i쀞JƷ %wPœ. ns Ĩ(ڡWo9oGH9hK~_R 4 Y6P@|vӞgB}cH,=MBpB= f5lb" _!{G$=Rρ =I\^d3dl'6em-뤡O̫6\;|)foSmN+o2s9=^$k,&Cz1`'SǦAŜP"ϙ9bWXa\0nO4FEXi?; ]sx*Uξ95>QUBs_ƴgMI{t |D˧ƤA&mK qY{*=5~GFXE1&qoJsa$C&}ySx{DtI5#e6}%jxm fk k/ v14M6"0}$d*d:͖w:K 1 G܇sww'ZŠ#?1-Iٔ3>$pnPK*D'c)HFZIiQ5l/rvHuCT+E)Ҍh}DoTyߖZ,77ekvwB¯vw:Х==* 5Fib j;Ӈ,;`|'M4 u,M9c(;`sM C>A4T~.nՒC~mqn.!2tNĒuc$ m{X|HDgo/1@' $(2%c1:˧3O4â&6\vh;"GuMb'Žc"uBhsU;Ix7:ou7+dUH&IPN iKOcF^aW%Dަ@(MX F?z͢BMt17SԬfRV@МVJJ#!\|:O_7;]XI(E d8DUcLeo qȳ75^5!&:-wb֜#X0Vv| XiPݐ3Ani)NJU&.ֵ%aqxh&FOGM?5 <$fo1I[wX@>{|v ;.Fi\ò1^rƁW#駭, n ҁ=/1MyFIc)߹ˡ_:^I@F_DˏFI 7aޫ=a(UI>3g© z,_Eoռm's:R~'˓&q8 fhɳ2ipҚ6씉iAR"AmB.tEhIuXS8pB{Y=TϗJ`.-Sm_“ :t+U(*:zV<m[%6c$7FU~6X߹]FEt|}+!w@h>M&HklSaKpɟ@뵴GP]uqd-Γі+eҡ(8-Rt+쑄"JsJ1awT}fw0YXcZHői]8EgG J+RwqC&:8K::-Gp%oG9 h(VPكx){;ULL 'nd[dlNlBQz;qFARF18`޶ll,[V] gCt[%C@ pOdc?:k}IL7$w-X-8LwfAaܾ,PtN$RjRUPMזUIsk7]eù8]U zxrGhUn`.49iS !a|XWԩD1%%wZ.rͦjuEe_Qo5y͠-(ru#fLCW@PgwdZɾń;ДAB N:*!,Ȫ%-cjY #q43GihpΧ; „ԘE1U 1Lua9ETt6gTd8y`:D&{{ N ,Xd<j$44)uN hKa С&}D+|K4w#:<("Z.0O _vky8)5͊,ө 0Φ<#(YMfpKxn h{ͲR y"8L;qyyWk M!_{"8M;V1L vB*J(l]2R*Kx#$~ ;tN\~c6-uz.O^J5?QԽ[zmL˩g QwswFmW"埁m$ݛMY2l`"y5L0ׄJ~; Jԅ|?3LzRA K2C>Āw;N `"*u2=mաH^ef F!ZnqПiN^vԤۻ窙z&@_t !qו3O*C2&FօiKӇLHTi;l չ\cb~;%]F3(X4Q":}i3QRjh)"RVf"Tݾ%MV&lV?3 O< uS4EGknszXG< VhVsVnR`[3_#HaV_yeM ъ.,Lc/țBzճ="fhƙjtX| ['N-zO8V7\sXEJ/1Qt':ѝͨg71&CЁLH=p$'|`ɴT^suju[3nZdq?3!/П9+,\J-M5,3P4-ʡ}ל-3GͳIR:_ A:M)OuI19.10bB̤PS4R^vvVgСXreN#@ 'eD%+Ư#zJoW:Ap(!"JZ|62` }Y6eץm%h,]'(x(~N֯i™S fjG/jwIyq ˬ3F95>}C[7M||pETV(GY̬E!jw )!QB!ׂ}wK|Vj}TLCd56FX3 }K|:'-G:03 &CxzG22{sH SF%f{/4a##F G~a#]1\-XG 4p;4^F#k+A8K^|©`Lׯ6)Q}+ޤ1dZkgGb.K0U(Gش{#9,g^EF6M67-D㌁20cKmf`,¤;tLQeNjfu# !yɪ iH]7@\C1`|s[V>kkR;k=)U۴ۈaqK*2_{ 'A,O_#qF}8SOmkuGSiW$v,a|r G|>Wc'9UwԘO 3@>3q\I!<>3!RY.8 mƢl 7)8 䁻~/9Ȝ P?}i/.VVn6Fig]+2ք7+MDÉiF v Cf& Hz{GMV+dfݩը蒜0((Ha$, ilL& ja CNWڢIY?/&$m0_(ltH>MJ,}9@sCP<9f9]# FfU^bmkTcVJg{.N7ljޢB-2P~L/p5Y6U?z"+`32%[ 5[?RžcIJykxG~tF >}| OZQyU6s۲I$\kc6 zg&~ w-Ei檊7rġxB  Q5n ʝ0mhŁm"|dR{e/;w fxݔpL,/ޅMoS$X8COP)J`}2us:)j wVlZR[ւeU8 Uh[ƱxrjwԔp+ 6h: Aj9UL[ClWwAןf=x$dBJ3{UjG.޶1MD¼]q| y ZƩLs9`vۏ:U,:nOR1ЧaUG-~YRPW_/J/0rxi[3 p"6bsEnuI3P7C!x[qM V$.?O_uW=P+6Ep׏oP A3^iEh)EcՀ> M*]r(}x+O^/v͖Yy犯D̚*b@2n{-luKNhj\q|d}񔂓mT@k0"a$z&:PE5J㶸}92 sT7u˵eÀG1zxT18Wb ?BG!7CO/\Έ:$>Mۀ .vOƈzF}EZ'JS c2|茅t3{DxB(R@\MdvntI N$,31 I<.7RbWRa9~kQZ53)qH䘓(7LB扨 L K8-*觛g&fHo@Dr> TЩshfO ӊ-Z)a,`!N/:vW|yѽ~up:@C@Ea0 ~֡wXEqu 4Ωa(LB%otѠ]n!8VGWaYE  5DI~Y?8m*_ W3DɸF`FAv#X*q(D~;)zbPωD]~1 Jٱ=8m`ʹSڿMRX^9"_&!6[-J@yE(_nōiooNZu=3l=nfa\M]F H2V?1I?]s;4RQYȮe󝧗0eQVz:D L`dx O`5!LPgb?#5kgb'y&mq>:w-cĤWΑh`1V=suMp!V& -Z.*uaypeAۑ$Q)%h5ԫ,[/'ď_I %ܬQEvv5Jm+Kb)SUے$6)gyAt>R AGy/V\gӸNQSh,MÓ$]C@/KZ5M_݁ |HZbfCDd? ZȦU %Ǣ&5`,@ZF 2ͦM5)vm{Xa9:^ ^FEP}fy)khD]*[S2(ſ9|I<)h~:X(!>vL;N4tl U2cg ' IRq.y폲*-é H,rɝxͳǙE"KmFkH~lw\x}1+@05e5 LN fPRٔ]NKU f HGp@IͲPWO;tTOVA:d|uɨ)DMi@- ]BXqv )y'`Cهޔe!#bG<˺ ;CA_Pha iUըF#a0S_/E" 1Ԝ:8jZ`(,p l $<=:lI8%n|&XcO&'mD _7]7# տ!_m5?hCYZݺ>Enaڄ7[F= g Rwc$| s6>T* a6T85iRnо4B22 m_e A"6J҇qo[CӀFJ\qf95+Xv N% _z?O!O}oLhCd*_0^GbG,}..?a tyD˯gFԷutw;€!Βl ke}nRqj٨y5Z9r/dO+էhA]1sSy3i2Ɩ=_J9*bk@S^dVSxxy%u{*%"624;EBP⵺?Ҏx=bBj+vH;8۲̑?X\u ಆ5H e9O˯m@Ťsl}aGq"GLM>(ĉy oػBqR; O!t;j\=i>8%LyJX~ۇdrEAIjrB_-·o!Ixa_(okQY*!L 6 l ܱBOt>c0ԤkFI驟akmȶR$b& 3 n׻-Q1eN V^_P!Vyb?b@F _Zb}1%SŢڰ- =Fu=*J2a,OIxd o?4D+n; :EỜ!D7b8jC1Y|fQ1 m Kݱ\уr+`or 1eLe'c׺tk􏳳y^!zTcVgl  hSʈS.K_[U 6**lɄx>;9Ϋ3 L#`;XX=u9CBVҪb^ϡ빦r?DУxLj1˰N]XN?@6s؎xb n;RihXnʆvw%=Uy̢ǥ!L*X$Bܱ=$KU}e-rC4m(dܪXRq͇#ߏܷA 4n3W{יB/F}1' E=*I#z~فS*H ,]Ǖt23Qy*վQ&3;.+,VAOሱU P1%R&▬2V` Qң?~Q9b8\R8aUΑM]RBޱO+9Z02jJf!?Zs/QWE2J*|y1r)w?U9닆/"EB:kQ eKﴓWd&Iu}AgH<{~X=9?wqf fSљj6!{j{w3gV;¸aV7GJ ٝqRɺܟe>1!C8;Y(%,⒁9Ehle~eI''|1}WX}I_zsYuMFEDvE{'X=@ c- }e g<*}cʼn$֎t>&C.됏Jτ _>A2;xqEs)zP6Z_ SLΪ{ajqb8v Y |Nn*-lꁋ`% ~Z۶jh9&\P5܎[3Xֶp): -,bm˔6]8 b1KD0o+OITsm?LH", SݬWkU, e9Boԃj.P!NߎQbRx"KWv)erN%\gYrz>퓻w9g@Jm*(7n@55eUϩşNX)'|E43zQ‚Ht_u-MD3&#T3Cu{8 v.ܚɺ,7B<<*8܈=(oZRp"x n)/aY+-'hdq~e Mpk 31fV ^^46d]'B% xխ{(![q57:`b,٫ xyH -Ba),;Ef,t,[Q{cdeqdO0|`qm12$L0@ WFEF5`H#IF0u 7T=^CQP9fp/tB};Jj7Dstf=AD'%:v RP5sl1`aȐ0HP$PcDc\yeN5IHyK )Lb{UK|{GH܌hj]P !j l]~{-9O'UjaҨ>kVTOSbƞ1Ϝ3@У"/W"XN^ {FV ۆUF:0^ 5wTT!1qcK)̌I'ӃA7U_O$K |ԥ[d}} )gѧ({JV [ёaA X>F%kOە4̟Q&ZqoH93ܫ CAE Wy LDr'i"Tq IW| gPik4A: 5:sb_FjcwGJzz׈QW^~X:?8[i#vv-S4"^c75ۭV6EϢw‚ٟw#)eW/{>0M1dNgSR)7o+d(eB&z-?[\P*YuxG[|-P&\gWVSsqB?^"'. `d|Eo陕횘;rܣk ñj_##yi?]fYGSDΚy`!n鷑F.˹th^S/NY,0PzؤS%=/0J"5hS8 UcjAy{*s@-¯9v"~ AɍxaFc ?˙:knjt]9ƈ{f @aTm80~_v8?l>ܳK,R&3RյUUu?0׹¥@3pdûXźE 3{ ss[q5~Ok34o4ǧ  &SPrTTrlZ:/ɀ44*g8(~ҨS3fd!j|!`dx}Vmb酫vO'UTo(ob4\@MN 9aʰ}{$$e9E~[gZ;E \" 0^F8v{^mo?M Z3bģ`^R$0T!-g^i ܓR&Pp:i _@e$Q^%Z EXwN- D_l~pq9<|sQcCǴΙI2tVܟ!ܳ8&rf۟":Xc#b+.?L\q՗b 4OXS /}0v@FVt`APOV02ų1*(<vy 25%90| -&/TT m"dAC+a@IOblT_ڗcՖ 9 xg(S:Ƴ%Zb2SҰO )E7rPS1mXeIEcH?d!^Ȟ.TbGI]E˭y^ 3/F@GpMʧ_ Sx;& ௜ :>65R ~G;~qȓ0Zr{FG.*`MrZM̭,J~@AkW5WBsL;gq+-+g-+CI^i>]*ڒxlUkf\Nl]x4)P}P_pur)V2f[u s)xiuIq Ũ=ʿo-՟tD-v"ϓh܊lJ es_hC-7ωxN7aHqpn>)b[uw5d 1{pĖIxŜqjhEHպd*Dkx 1bF]2絙}"Pb$UƂvOq~֢u`aDW9sP W͍V)ztNTsL(euʏ':` uX-&hH\/u l:jHᐨ> Qyd;.7cP%)%*/6"Bc!cɓi"@`~ьIV>ÎԞn-GD)$AJXt*K_9x Z.S,f$enqĒܽp1(5PUIE4Ae' +$!%37܍R[bs̘'vμVKgC'[ΧH6vkK,NCKK~9D3jb oN!ֶ0S&w P|:7M\~d<_ST8w8VSeF>g|q[)Ӥ`kE; 9ȧ1!:vAh@fpE$%_>)pd"hd5rsxɾ|`&cWf-BEaRjm&(b3 ~:oS^Гedi8n W_jO_DoM#!PR^5 w>W;Q3Q»[VM^1-nQ() Sٟ.;"]Y$ʷ7oi^ᒺc|+xcWX#wPw(LeSL=x]qFP.Ar2˴D|Y˜" W .WNSaTE^7_0ZVW?~0BcTї}[RhRٝ[IMP\НjWUyERF\t5 ̘4._N.* ۾zy,9ƈ_N5%4\htS=UIĵmx+eKv*I8i[$y O@c*w-S5f@جREG+dp:PE"7Ů^  ("쀀=%3mĹ58 tYn] Ph쟿jʆZyh۷1ACoSq ߰?Ń&;" Ok,Y {[?H&U)+ @oO ߗŧ&&MZ/LPΤzX!08mȩڽ7 "$7T(^Ђ x0 Z&0G@ۿ7C~; f.UeUq! ħIκў#!b 7c-n*,2QT_M6/`#:D(UV:B:7Gm/mC"UO*^L3U5_W/rOG5uWN,s`Aip~ZLF!fU{#>>]=5_ J2zM~?e C'%]fIP&T~A-X&@!.-gaȩM0equ7?Cdkq_9Xt@s.e:N9m$0= (n x&[E&,_PyH'cTEeq fL3T ̟Cp,^- 3';T&N Řb W~TZ͠[0~?CuLvxs~"VBiR{|\rl; &6.ظ~'6YlvX2w,Rc${]Odĩ"q?u}M.&Y9~$3nCP8c<#+JÄy7oW(`Cl}W Н3j nMlQ.۔"67pU9x" Rb"[ ˈH,M!'6U ln$) "]'Ni{W @e#Dco"{ub*gHmn 8KןS/uڊߪਏs[M<* :%hp6+~w(jD8JMHۨ[&w`9'1}ꐎz S]Jͤvk  hh:wՌQk+N̔ ++]53EHWo+@P8!57?Oϝھ=DW5 "t3i?8GPގj*lüWIŅ6[xO>IbZVu->IV~m9!Ty~ϳP];v(8d)rصx M"m^co PV%`!Ҫ6/DYVCrȀXs'[\—7TA%x ~R݂ŧ?XJTix[cce.۶u۫@`j-;z~Fּ늄.2{bk:B.XNEEڍKa9X#.} 3"4ۑNj;BQQbe:f'YIULf:õ.MWo$rli{26/16'؂E؀<MlUFq]."&$ 0k[MTiL#NJh?Ĩ-yags)$E  ^xwԖY({11^(YtWa9EK̦Jul* ȓP:_ϫ]|+"3eC` ɛPYc2T1x6 jUH1ojC(ep\p1 p|[H・>įÑJo۞Rh%RE,֚^"P)]{\vu+:iiЯ>a54M{ӗ9AR"%V?2'{X"܌/.X2n^Z =i!c̆pǕs. !ʈ@YGv;.:zqz?141%0lY ,6ɗg$Չ/ݫ\"\ϔ9g#,>bPYp`H1!}ʇg6g2WvHv,ȜdS};y՗` ti ;ذ\nU>݄ :0ƥ~΢6gDPqo%6RdWf=OҤ棟xQ.vĽ2Y~1Eduok;4PKʣoZd ŝ|\<}1=Ηبe*Op%PQIKfqw Ymd_!hbwE.27[Ũ{#Bwx*pQ\~ea*PN2m"䲙[e`8νH]Ln]G*&Y&ek5$)Q34@i̢Zi@m]-ɖ8ɥlWJoQ1aBkR릀y60PQ4eg2܏91V5h0 + Rt-3D<3!w_R,)tᓱ74t ]VA.52ySX@-#emPFd! "OHwv֞~Zx7!MsȄ4NJo$:eqҥw~t,thH'T~Wr8>5pn}?h}h*Bwk.׬<\*ҎlK2p/ؠ5%o#lq |Gɂ hFiO0S5l ,g DjS_֫ZS[~|"X6MV%q]3@e78`~ ev?BC|mA U"c~4&$|mXZC ocObY|" FnڥV<}X/j\3MCw9 zNR샌hWe/*¡0]%Z"w<_z[H3^Fr̎)]Q=ACkhFZkx-LBaگ>9niA5H1NG Xr !rT ~VIPW(ub<5_`1K됱 ')QЦ0m%o԰=¹E`kÁ?6͝Cfx{5m7lw k<)>늹_7բ Bw@ xtcdZL{R|Hadn7UbѨ>{nyԢcf!. z~mzFqAV&FXLppgfLp/k䟾#>,9R埵QG }najyo7t FKpўp^ccbc~a-ݭQwTB;YHdť89+gɟś >{Y`(8)A87LtY%^;xpc9we7௫Cm6krqq (Qf (#` Ϋsqv&Ϗavxy|Hf8S"8CHVN&0N[)1xQvQWDsd!lZ9V 7agU3|@stY6P`"b3p;Qټ`Hh T>R#|o_k`rNt3"&Fy'mב:-9p!7"Sq!@G<;Mp{n0x\6@]4GXe*ƫLٸ>^_ /L1 ޅVw@5p1A30qS]dn'Rj'UjYsiCu&[0Quv m3/QqZ&^Y =Ǥ#Yŷx3Zf.NʼnGJ!YᲪ7z>(ecp.9[rNf[8 brAEoVNy%XSKm5aΪ8Q#az>TAl;h"nI;u?Gy t$-mgz xsEtҡϓp@uꥷ = c8HmG|!S9Ԉxe!c{ ɄX nZBEL|}\YQ #Xw. Ț ]> 5Rs0b1/I@n⿖mblEK+ྜ֓1O{|팖s8[/ggڳPmYez1IwQ%%Y$q'|G.ҥ:%>[WK3 4fCm!z{۰ԣ LJPRS"w8[Hڝ,(ٯm *^jbm?`]O`~-PoZ6߸om ˆqcس~?O9B+N,Id(A#D7"nx哔׆*BXvd#ըM$7$ˀiƣiqvκCV1wRƖd%S,5!BP7)KK?%,RGB"3S\x|S&DO "u %И=Z{#Ob x^i)xS1[ (BKTGoJ*ia=+^r[Aj2E>B#^3=z U6wr0T1]̈́o3[v-LU&qR`ܟR/²NB?xQn{Svw4aad|vm[kL:8Npyd+'[ecd3|@g/!mճh~ӛ#AM ϒ {.yWM6JkkMVcuM ]pϚ:"%]vEΆDȁDǎNF"עq] 5A߿ݴOd@b4Q`\K/1LG9i B`?|5VXnIƻ`7C(i6=ooo} )Bow]XXJu{w]6cpfeCc1Yjg4^/;`]'|!߇"~̆pP͡ Ϸ5}y߳&W57·,(<01= K{RFamۡ7 5ˣym7+!)ْK B[m_ΣS(h@,(ٽ~K#1f#6F) 5Nh.2~÷!`; ԧ੻k kl6}̯̌jc'{>]3o#|EߖWc/J WXx/x"_lےV9BO*2h7SOצZ=^RRSCaFxD/P}xI-ԎJ)$uuhxvO_Rs;,@ޞugy,yadګ(I8[cnm-b>r<4M?=$V]}qgZ4VŠagb=ePms:3h2Gcz]W.H67َ"(Y*,p$>4dBDp_սʙp_'\p9ڣī.6j#3/[&oAT{+3ʔԛuUjc7 &1gqKM{n%+)[x"K֣魏g.(.k#{zt (4U)8/ lW6JvzK .Gki7p+W^rDoOpi]䊺/1 *qTġ3r9h3 J"%8-[hg‡"ۭ獊qU-ˮKnDҔ:W?] nu,A]@N%Vi4 TH}UꁬXV}Ô.d= )pt6o4Wo^q*-jt:Q 5y2g$+yE ǒ埶 ?TUYB3,6s4`=(m\IM nGճR)+}D뛈c:H#M3'6/RLf8l T@iH g s \:JӶ;\ߨ9Ris<+KլKL1 N !ȫ̰~%RDv~ѱBPOXTJWҸ,mVSgݿrU>ttxYܪ'q0B8vZw(uDd ݃^9L{A?Eh4WA9)zȥ(S1{ xP Lr(ݵ54[(>ө4 e8+p͒gKLؐB?zؽk+<\&-Ɣs?gDBvs(ZgIȬi*9U[BM,) Q3{[RmNOYGr6*p|ZQޘvnC;a)9?Rgp>)~ܳ x)2o3WU$2w2A-zN^8"LYbᢉ34ob,$82=`M|M$H #hyim6dyV3Ra';jP•g9m]wIŶ&k%hT#zĚ4=3M1sc72ȸucT@#dKhQrN3.;g5CQY&b\ᛙ{z(Pֺ@Mbܰ5gq%G'bhԑ웋}!ͤy GICckUܹ1YB@һv.4$ZULS{#K gaeB1Yb/ Bh&!⴯/Qm:1t 1Qo_2[pp^ƆUSz@~%Id A?q{KL:Z D^ޫRi% `O3>]6J;(8&7%%#c8T^hOIm$Ӂ)txg(W$#L"BSn{"] tp܀kײҽ {I-_.:exmj[yIǢ+p2Ӣz4J\w]m-"vs<@!87Y!4mghp%ǶP{\3_e@Ĥ|A0PQCΗ?s<86}Qgrk]@z ~rMoqBE]Cq҅Tes4@k=qY2 ., xCv+IH,2$ B XN- b )'OrXlm?L(E`>q0y+= P\C7O+@loR2M>ٯᚶ\s̓G0XYqpOxJ;<岔_3J W]|_T-AYTirNWd:F:D,V~p;cReck{z4؎ ꔻsPiOr_b _.)8H(%e"*,M"NTntGJO6OR4FFO[QeS%`G4B!Sj{.{qxOd7ۼu*DGW|e uì`'!nx7¼|bEC_4@FntH^C 7Jyq tѺ@ }l@pݬԱY(`| ! @ лmN!-Я8;ygPѴ||(kS~%2`xapVIT^[vZ*DcL4!&pڄ_Ofr$c1jjjo*Ū8:á:X抠}nBdq`.^ n I@YSnH^O1 P ƽ9'Ƅ\5rV r,$kO>.D*ڋah`3^oӃsN:E휉ycIv!dLAxhszx&uNjb jV\ڱͤO>ƷP3y(6H^_0|Y4렯eY[TK"nFwSh ؁ςA ΥH%AsNq3.gk\uf%iJ3gtDmOS,"Ay\g@=s}!LC6"@[-B9p XH681vUu\ߪ$;n%%Ljf4jUvCv^lPM8Y`yWoXN4JHkk'R |{Ud Nίklޅi)&d{+}b:I+3+=.;N'.Z. eg?+YPc0+da(g凖|m-SB߭:1.OE4Ծg|q? D*YoHZۚsnw~s R:zri :iJǒDA ǯ`72^QU6"f*.4:|L@%1vKiLE.e=&dgYYjM$H]?v[){1.YS{]3bߏg0zC&"vQ 8ːYV :'S^,U8_}ͽ5Ejiϭs+/bmR G2m‡[1;Xw\m1FuB >4"Y{th{ɰZ!gB3]+"sWg5J $y 0{;eVx{#F TG<ԣ̓~SɼIlލK)zՄ~ %] ĕmk}²Tq|U.vYڶنܕq_A'D+\h ޴ѣI;ތYFЗT!!K&Iux {pq:bzrH["݌ sa9\cLBsGhJ#m-R>sWmf\cX,2-6q,Ec4Akf'LGCxdHS0F勎yJ~ЋF !O+B6@#ҐdO #pp6w56^R!MRLqdԜxͱCwǤ. _(%^yIS>m:`ΈietʴDT'8Lu  dpyaOu4t5N= W콇:M"T"uqGA? /ߺYV ˨ gzی9`Pҷn+j 9^@[ˣDd,|5prEwtcj=%ͶibWVFX@1Q`Tb:~_%%x'P!tѤZ|E(s\ړ<70Y9@X{;hGbFUxVsuX/}#lw8??؃[3P\A F܅^(lt'=IUHS&$gbuT7^B*;=!igI[WlCw?nH&TK0ձ٩1Ԝf@:%`wKzIH ÂK]4yD,~ k ?*vϳ៾=b{ӧ@beCl&qЂ*pɶOݝQʗ'~`?J3oєZ:T/fKBjZmT&>I]+pxWhHvI:swO9A?bGk- n~ ռZH!Oz#S($9B 1~BT7Y'CA''|`MB@w"; ԁb=y-/wR6a\DɪpKٯs$AlIJ-Z; e\A-?Z$}jsiK5\Mf`vp\;GXHiVIg(eYL^"_YipqqW3; GXlq&|n*"#p%|aF&k3h=_A T :?r:ĐRg͢Va?>ZEI'oɅ , ={(SMY@؋!b/@%,)(!%a&sDj e|OYу_@=GOþ !9tJWڰ% ̧ifqU*c\6nH|ldң?lE亹3Ŀ";+ <|Z@a_JjRwH>G0$^OZׅ%b@7#%7TtΓRU_1 k`b;@os=-\crU?\JLw\.hI }Ӥe"5[vl~{H"+NyCrBcǦLz%!۸(K)l.$7WDRL>y0@J0HC}7}>~ߊCcNe^ 4=(_nX+*;l/KqKOjHWZ_|NaKԽH:8?l"Y@Dm]ykO X,K4X$;h %&Zg~c92\8^@"P*`󻂥 qbiwh8OӨsn+9畇Ǿe]B.Ff0BmSc?Sȗ&V)[)jYm7#6Պd(L7i?{|̵ccήڌ4׉jJ_q+3;A5}lӎui[Gр zbcY@kea/-t>n9n:ZmrTJ% 8%i[}QG-{@5dW EDjGlCP .qg%2̅O.SxBT,sj#Y%J~6VDko{{c^1ѯO<''b7n= m+9M O7|5NJTFo)v5N]Ks#,G'&e[}SDbڣjE<+O^_-JwR%n*Mn"OFSi4 AB+]citL^y$X#PO>Sw`@dɪJ}j5e;w &Mͪ%U -- 'W-: E,jX& ]Eɺ˅@PܶQٕTAC>tlIĭkHA x [amF߄c}PV9pzwE/]<3ɤaZfs1\"s^͝ ,lJ.{ .+ !Zt$;աq =IڐA+(@8u?rd8pr43-{O3A9PjъJS~S& T|Q#4 /P.̋;{dSvkff֡~q Gfp߾fJI9^qKdi6WNkVE ,6V)eӵIk8JkZ7C c:Qл4W=/kϲkI6K] 5V)ge7WrAMaWK[F1jag҆eL(:oPuE{&E}& 'O*ۥ )"W0ֶEh\PA#&@^@́Ρl$Cy }usQ8/4-wRN.yL%WUʐFkt'uwtͱ f.TuJ$c9NiD(t">Pi.k*MDWO0B_fe=Qi$Zm>)KQp"KtFcQ.k$r,"YGLpFlOP5Nn,87 cڙ%c49_CiH=B$6'ICPNR݈:k*fMATosJ}lt9G5ƹ}T6:8t Gcȥ)'ՈV9ߋjP C6:OK#(.rʨﺩWc» :z p=~Jx}$w$JbE00 ڕT!5}3f?8Pr{8{+3[!u}x8s!^~(Z왗б3d%iLzG ?c†[{F%ukevR(Yx?jqkfU U5b?b3nQpuO PD5e *cnKi5Uם Em:rM N>37E_CXgSsҜAx:82/_ WzX0$$#2/ԝuZ &'JHOZ Hަ_gυ$ƿh[By è2كeCQd P,hN z@o&<\ԘYsTㆁaqJL]F9Eղ%h˖ϵUt/| yIO1j m~YO–I.ij~c.( oj<l?ФW/@UW㩨h [ 6e)ȟ*+}|5֧Q5fׁ-=ª˳%eRS*R"-6AwRސ 1XWqfX>D8C80<^ PY;ZEfm_CM@r/X$Y!oBIZCBQ<wsBB[|uUtƾ+惚ڧM+o]6X #fbP[h'$-/Ȏ8anb}wkY.#x<'ח+yKƛ LS걋XKnl[1\t%32QrUchFn"ov4ƌ5".u2Qk͒7xP6JEоu,ܑḞ_i̋:Bb~'fL\zy `jI>$gJp f| b%hKRQE-Yvl [O&:vJ[aM7N ,}:5\Uq|gMQLRdRjWU?vs!a7}n3x|>p.z1O/v76̪8m0}2o.ȉhv|#T*7Gn V^XJzEfPUf*Ņ4pSm[bڏh&C1ơ,:?6nzJ {zY uʴZ32nP9 jlLͰ?u콹W=Y01H\jK!r *|;8/Lؾ~@<^?S}cmm`O-+Ŧx6)! 39j쪈ms[DGsb\4tv}t]SYsإ#5!3;.uz}S ϽTޜDT&9g7c> u3ŷLlsG#Dg3qT֤^S5 "xOtQ'"ݮË\GNa O *U*8, :HpD ڱ+U`?id/ƬJf9 W+)Z֛hR\̧!޼Yr37شXA`cϰ*d(r**ѣT!Bfz,U$Ł:xXs~*;1GʰJ\pbXwNaA݈vC$p =vO.Co{:Pv+52TQնK,<Ŕ;܌iqjadY`3Dtqe".n~3/Nіk6YrYD}t"/R[q~p̤zR)!g@<%((;NZH<ʌl%n XyxͫF7?n{.2s>`Hv+b*5[>#}{1H `> 5A7T9)Z j/.qorOr5euOj.NFUJ@E*߲C{m^ o0+df:Xw(^l#4xVԦE2c=,Z pTbU"[AX' OnhM>?ѬΣ+0 9ω}{/*Qi4%Lj[+"Z5rŋU~ YUǮnBA+IO_]5,N8:D 7 D$!LpIҋD )20^[B6)PU^Ҙ(jeﮊ{۟{t;~ɯZT` ll,RnۀYr@RksC?BgAػ90]anJ[q*)nK4GEeqB(*IEF_Z_z_1@ZFy kþ 젚`pcgܿ1OB:~TH5o˹cU,܊';?/,qXgmY6e޲-?bc]誱쵯l40&Qlt?9APJ{> d9RI n'w #w< f~eQn.kiSH)MyOo9JE﫰UhKUArftr]S5tS6S[o:i V>G`BTH}3"h|46sC!p-H6Ab_2e׃Ka‡k& 8 iRJ{iNkm4j;, `t| ɋ_lN&{H6;Mtk EgP^lP{']w~Tn]JWܢ"3zѡN.pXqƶ`xt?7Qʇ&23~e>>̚KгF{ZFOsIg낆™`!ˋv2ZJƒ:jѯ5`z6y^, qhK >0C29g6gAPq0_2cFFy?pV>Aq6&\4vͫ&81ie&}nM9Q_')wG C8ņ6Aveq 4-̽r|֗:'Lᚖn7ـk}'N!@9H1yVO1H[:sbj~!s(6DzHһmM(:A;wI.ijBwIį7mv (Bw$D8ZoXV8v 8Y38Bnym'7F{r8Vtƃ- %$4̸q X4cL> 4e'+C&>j,dQɷF; t9!}gm2h}H((\+yᵦ2o?b0PWSy 9r,s FhTGkEahe8"mC<1DV~XC8fRM)xQ.f+3g@ luۼr%675n*3~$-K-؉3w ,_ 若%}'o/H'#g85 \ܺo9քBGDJڢ</z%C> G;a?42Wcuu _hU}~Hxx u*9ò莐sD@%LkN!Y]c*;~Ah'¤,;DTLƢDb0ؿL9 Ⱦ+.ÊkU%!Tq~嫄7n{G`OE$fl&;R U4~-O9%.B$Hgߩ~)ll< #!b.{ρvǒ#EV#("m(YB͑s*X[{Mlw]yG:Kdλ p,})\ ۱fUȓӚ1ٞ{}N1ƧŶΈq؂8/ G/#v2,#5ToW28gh(tĆ`l{Z}TIe\"eҾxhDd[(;62-%lhx9xZ~ؘ(z?QG#%ŰSkա,1}|BqX^U]~CB[Rwg ^_2iCvC8qІy 8浢@ QCygZ\є:myGXm!F_~q?]9Vw[9W&$)|]*㧶k 7r ~ dzv#3̓CXWv rvqq'^= 䏟n.q>H&W-k3`֬k.`@OJPNm{(Nt HAz5V57 p{NxJYcVT#3"8n~p&8+vJ6'bLrЭxԪ<&掴wE2qK`҅j]~TgF)f_jcI:ەA1ʂ4񉸓]Nކ%mw AW= Amr*nB;J"ȇ_lf N+eI'Dq}{&ALqx8!BzpPMچ>:au2(Q0s7=b/t&v$;' tRoĭXK y 9%,M(\33NŤ='+50K_6J;Qd⑇9Q&pÅҲ;.И3;ZN^Y9*۾40R&-T{gwdLPS*6I-Aj/ 9[y@]LwuJw/.os?eGSF}Ϛ1Pq&yaAgUFT<೮0|Zt^4YĮN:vQ-MƇݫ |3TQ&?{Fb:-,w|Ԋ"vf~Z u >bgC[+VბInÖ?Q()ͳ@FQ LX݅[@>.rdĸWӘa;EQqEe'gU*8e*_Y&:_py~| X ڬ"\%ǹy .QOy]Jd$6J~1Klr9|7K ]Yy}ELf۷l;:"R܎ъ3)10ӏqYa9ve$.QܰF9jѩtLAF?D$p8yG}z8zAx>`jrv͊(j?Ql=cW> ͷa&jP94z$Ǥ-'>y+b3К3JKKFڍ(1;=n`p0hWJKcfDr߆fԏt♀s-:j0ڪjU;'5RUNUühiŶ:j hqM|.,yv]& MQS y 8CTF``1̷*4"AhP$P 7V;Ils'3VSGNKLpvEmYyK_wJOXk3?:=ߠ;2Bm] a-#Wm"Wv"8@Vz48_6ޞTO{"QPx-.s #yDl6 |=ٸ#Mt|dC}A̹eb4 3"3׶q+ld&mF\'@36?NE#^ f )~5B[L?,rBVBlDf9KP'~G&G}w`4 +$M檤I%7;̆0sF ^TܧB'5w8 #rYYRk]Q[מ>!JFG()N\"v:bW 8{!l!y!),dVqmw㐨 yl6bGH3{$yKgoΏ=p|v8M1 sg!u?#b,vr\jޱzkȧ4ffzâwF6(-NkxZo7&`VhNQN=@ܳeSaHs>D_#0Ho}fl IibDeԮ.M Ut ͌Ԋ"xJ,8Z}q! ƶHl:a0E&,els A){ ]"3v)v5} ƹfwC"j DR 28>p oz;X$g`nNJ ,)4lmKrg bH@r,x BvhJ=)]khsHU+'Od5)32F*С& |l]9? nK<$c'N:( 'O;; %⧝N0$bN+ئWKnN#rlHI ܅XPi1V(Ƽ=R=6%{Z]ϻ1`x:*ZLS|o-t0B$od# ۬[7R鍧L܂?M'*K7usMe`Hc:%']I}cB |o/6JoHВ{hޚبN1 '@Rɂ{%IqY ?~88PWQ%{N|%G`*)W9ꌊ3+i2y&t15Cmj6lgÓ 6Q.HpgQD[`0˫Ay̖J<óM!RPJ&$Z[D"CYX[1 ^>DcvtTew"=l{ ̂l1b%HZ#k|AټBw*ӋfHRul ?Pr%s{s\:iv癈?>-z\>5w°&๴^OJOPߢԡCUmcl nN &B`KIu0l\FI[doe`/M\SwJWϕn40}wC7Dޮg~:$R'x3c; ](:Wb(HmyOҶCq)洇cOJgtN0#~D>ăWcG5JiIJP9vQt[d#WƯw CAD 1]f(9hP;lnx6!hB"7ȖޫTz}fu&꾢8*O>oo<{CVi,:nW,NIٮXןj쏓l?644 kqFXT$*=^93~ Y׃#|xօ2f}P؏_C Egk|1Ig2\Gb+K`FAҋ}JsdaESókw6qgti0 50^H "/&דng( qqbI;-jmԫEX }N1 }zjQ2;93 w)J`5oNʿ3+:nV`>eʱ0x<#?r}Ac)&_/Sm> 0ۄnO929%&ƹyK6ht4v殾_!4b > ~+j\ ֯米U<= `ɑ潇OǪɎ: A5s\vmT@Xm[Ç2BDzgyH}.y@( rg BYkwNAwy5:wtv@n!ƾY7poHD#4I 8qOZ_=SY?G4޴`, toNU͹a&Nuc`[gтxamQ7dt[Ϡo_;=2!{_V{hoE53A2l$^Y:qFC>4 Y\vQ/kf"SA ;> z'G5!19A,va~fH?ƛ;k#; (?\+gSCoswTZ]%, xE4ӈJO0 H')qM>\IAP%MF{{ۂ:8¢HySM1,IJ8\dP'7{A'8m)*:;C(N|G͓h%L}f\N4~ !(q% fZ Oe4*ey3ڏ?ߊ9jJ2CG=pjڸۭ 9a4lnaVuX8`5-{KtRD8%^PTyU? ^[׀P5~m*Xu}_W^f0Md*Qs PC:If,{de'GΊjpq3iޔv%-q+Œ2 =_2:\MD< @ּ'J\OЌ0, P>zTHn;%Э74uX[ ?-/0W8{E`EOp.q]orFӢJanIn$w#Py׏>nͪ1K!Џ=<*b+@u)MUPj7" ,œ#xgRR'bN3嶋Ęzq"¼& ql PE<ڳr@)xt4AO0leO]V>k'yE&ɘvOen1(7_ LuiaX!uPzюž=] nRҰƣQ jBtF-J2a1rg9)»17*Qc^.4`^F\{KGC0`>7RLcۖ3`=vEd-qCUTb FFČb8&i1RAsvz{IuNKT9Ea-Хsg+xQtpHT̀MfJAA+ fxa=^k'rbhna \qs h.oEsppTL}, 4MH aW]cbO}v}W^=!wd"?B}(6 Sw zJa7eUDnW.~=VKkaw-b^+X'f1S0q>D c0Iȵbb* nh7܆БE d>F.7`q,E g1!.'N8奓SaR 1!癪] 2rK4 oۼmBE`>}mlVK59+]9Tc@3Nep%J>C )L}p|Kk0&{?=C8#/Qyj9n.v2#pJO'68޻뾊Fl5&Ӥ+/%J(rԬ`3la;cߩ(HۢFŵȻk$b8rTѵM 8bV Wǵ }goA;i#|@''UJLN+*H{'2ꆭ(;glQ( bl*UU]+?#X5;RV*p1g.R nD qbCNw1Mm6(Qm jK7?V Alfny w(7{w.'s/ؽ6*q-F~j~CicS$ ya{׿ƌ03aߨH:MoWMVh?#avˌ'<ٳ5AfExG-A [}꣍Wj#a Εș0xfSck(^A3ٻŇ$TZ?8}qZa*Bb^MEb`Å /V󅻴-Mi!j-- &}5w}cy[7CQ[cg2CI\DZҾω +K#h5SgSJ 9ql/ 2!}*DLG?i B|kV8ʹVH$Vn>NW\&q)4͘g#BMGc"n\ɵN`y3xqcK_+b'mޤ$>*I7[i'(>eJ |֒4~8 l-Su~& DaGSp򭢀 Cl8RP:g~5= Pc8 봅ܑ"nzn@ի7']L Uag3_x;P?{"#*\咑֞oX7(HJ,$7lNVPɰhJL6nb8f}jvv69]+RZTJRCxY.#XW]奀Sŵ>O f)].rٺlf#Kb?uHFWjӹZB /Bʝ58Wubݏ4x"mNe/{V!Y1^(܈2hl|/iؾ/]:slyL5 gуOÐXF\sr5%# XB1œyTGmUWy֌nwܴQW!ׂ;557⟂iXJ$Ye lv7:j;xʱr(:+ Lq T;^Bt&r *aAxaCdbC/Fe2T+"Hyݺd8TQ9uGQ-:~@/2,X #oQyi~ak][jv$9\n]DX6c4E q1lpH؋U裁7ԑ3ij+6d Ĭ|0ୃ"Uүq@As5}tp8sBpXwd W9Lf{*J&ǎfAhN>X]0R=!p'5,o TTAE.Ӎ̄9榕>+%|ta d.x<]ZjddN-R"! N4"K{nٻ~u,f ~%zq^ϟknhkhcLv.'ώ')%:()_+zRֵEfdj|FMiOR|?+IuR ur)+ @8C,;[֌fu,Ջ{i/'lwxOn}Wxkc6Ikt5g : M' f'#ڈ[:G(;K[nb5:om^3,o#ORGwʑh,*l@>ܰs _j}1x'2%$P\#%h11o0<6ZKF&-\tM3fm3&$tShA?GkfԹ 3)x&pcE6/uí_tpđl3{N#twۏPd b=Z#"Ͽ~(-+x@ADTLJ&.X5Be%*bzըCXl'myU~^Ԗ!@ hj^Q#U^(t U;37ܼ 4LT Ęגih扭 `C+sN*; CE*  W%HbaH&W[q,=$=qmՠ`xb_*^^c`Yu[Mڂjl}gʁ2 v uJgk@^sHGL[5ٷVR!'.Ԃcsa>11sKJHf,f /f|Z Ig,!<*mxz ^T(jQ/&f>KjnF_sۑCO(W* Xm>d7Qu;S:g@YD␒O060%,k'`'@ZyѺf5& T8^Gրs3\9G !eמP@[ťc0Z H9`j\rbw' NYt-nX;ڲ˲ΙFG&uw۞T֢u;-PS*MjwU"D #8\Y^\CybK1]bY;WҲ-1(LVĭi($SyZp5{0sΧtCr&Wۨj祯MƴlF-D'/2 -Xc׎Ya}yY )cyf`^Ӈ ;^ xGV$[ę]C& ['@/s-nh8g"`cY&@UnJu@zJʼRIs/cYZ:'|C30eD;'.r<$A.,ba<˾>ues+[0p*gOAs%ջ6+Vs*?49g¸fKnaT$$?*&HG@wvKٰg ^x@zWa'<KAx`b`ͦs24ɝ'ج@kduyFO L^5!cFpn9D6O%~F퓘ү*[-Ywqf{C'xo#,Bל+.ztyi4a"zp]nе|hql][\YJh5ÓrM i. OWr(;݊i=;F6G.2wn1b]~a6ik Z[Wv$oۧgiIyᵑMxo>_3qӘ ,9Kɫ^؁k߅_oj0,BfYDC;Ǧ" ,EHmA|fp3; 3=jV58\#y %]AVfvZKL5Ij#kn&2heƿ/8q[S yh7-9?kc1<+^O?Qadv0k0=akuҡtIJA1g|'K:0+(8Cv׫IA|NvGq" tYсdꚉCN᱃Xwd;'Zu G[L1uMw}- W#Bc|(᪹׶"R{C/\-ʰ1(*ldpC a쎯Gj1>z-/;E{vr p0ƈ{l3T52f~~d[ZYn3| /a3lлЂC[D{ , gAz 4T Ǫw) FhQxJ+͒3\9&𣢲Dg2"Jap$<{:Y=rC3zž܃\EmCЁS<[ "vcw V0u/Q*Cq|*,I~cMp۠rƟ fkfvº oRQ_}Lw6Q7n!R.:َRBRSR|Ʈ 5{|!%$#Y$aIiEW[wEJRV?΍ ~QS,'\GHz j$Vm`d"L1Br$)z=1݁bT;jNwFe8B̿Sx|:%!l?Bu'KP UmUm6Kw adzHyRڡ׽zx+ sDE#zy#F!;KH@z&Ѵbh܀dIij_? )J;d|/*vTt7zڷ#($ay;)66Ѿ4i<7n?]-YZbn{uۂL\TVH<,mWZ๎7L}oC-@yI%mPis޺A \>NҨ8xaↅK~Ors5vA*˦7=[8o4QRq_"bíU!:%[rB1L]@#Mt8|/3vKǼȱ6:f93=YUrJI5m 8`5 U YZ