sssd-tools-1.13.3-56.el6$>^]JHh>2X?Hd   A *HNTbb b db b b b!xb#bb%L%hb&'9'9+9(,Z8,`93h:RGbHbI bXY \<b]b^bd$e)f,l.DCsssd-tools1.13.356.el6Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP passwordXҿc1bm.rdu2.centos.org vCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxi686*ɤKSA }5q"1EQ :bn3] 11m:+}MHOs x?sH cC A큤XҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿVpnXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿe1ec854f68372bd0e1fb6291a2573776074e921bd39bd69a8d5eb8da2c44dbc38b16a09cd1dc9fac7c51768c27ea19bf1bf0178909122c473d60b317b832c936881b770495b8cea72067643c78870ca9a78a6d1471110d74d39710050bdbda0ce2b77b0cdae21a8dae1bc315ad375eeab66c01151c46a8491e86e483a753062a82fef17872487505c20965039a68b51f18b63afe029b14ac4b0e403703b050f3074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45e21af5f3b90f9ee2037534ee896eb380f28ee4c8287ae079cca647e0c0d110f48686963a818eb925ce8bb0c94f9f14bcedf56014ffa17275455d2879a0fea2fecee8dc6123da04ed246a9e7d1c724ab7dd4d41c33f7923ee72052bc8a4b934763363da7e47f2c3c6df61a7cb83fd33d9eb3ab5c8931126e6aa274c347902583cb57ad3622cb9e17d2bc083e990dbe9c59cf2c0835cfb21210168a04188196c9e18ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90350d84c60491f81ec38582151a779c4e2aee537befbb0bfe275f4af2f4d91a6aca6699600e6c590db54624ae492e7bd5af1db45651ebcb0845e606ee559e903c099c3dd8a113fea8f43eb6155a4354bd4ba2aea406090f3d764f486c3e07556996ab7f4306a908defcace37f1f6c91dc4a2209ba0ef8dd7db7fbce0d4f11aaffa8c15ea2f38ae06aba6778774ec66b34427d8643e9a628e459fca2f53cdd141a70cd03bb230a00adfa378b30947b3c4e4f621421d5598642bf9562af08b264038b2e13af39c3346e820dd25b1cf15cddc65f83e8306b4d14e31d1195d193d3aea0de4f9fadab65b5df315e660634fed1636d3838895735028619c989826cb5cfc92d14b8141c5b61150636295bede5443eef854b35c22858d94d27d2c4cc1809266f7df05620679dee3ef453326967afa37b75389821088071bf478aa26cf13ee8246153513a6490d29df0340aef9b406ecf914d9fd7a8308b0516d609215b4694c32ed1653e72de94bd8799e968a4bbe1b8b2b9b4419c31cc4717c46345219f05981d65f788e6048bc9d1c4c6b217409a3fadc3c5202098a604b69c1049123183ddab8a97d33f0efd00515183d712552a7fb559d420b2382a98bd47a8aeeee7ad17ac5f114eb8c50a94cf87f49ac08f1f6a78c739b1d66a03156b16dacd14df3653c2bd588a3ea18eadb5c1395551ed10740fb86aa2a6e3424550381c92edff47d31c31c18d4e0c2f3420467fa2ff7f54badf57d2e9d03452d0315d4f328bc751516fc4a79bea2e43ff71b134457cfd7ca6f09d9670c757d031ffb545df1350778184cc5c85e2f38cefc1a5fbc5f27546a44f1b906dc11bf7847b6dbfa7347088c3644e8a7bb4fb18fe22400d07409fe8bc6706e9293859f315cc1df71e04a9ef1f4439be013ed636fff2def8917761d7121cb9d135a391457885d341aaf2a349d24a516186ab7287f5a6ab2c03e8afda7442d66c4b6735f7f2b2b644f0901c6555371032147c552448e5bbff22e4dab75d9f0693c61498a6a474cc1da399b24cf6e74b46a9f5b20fbffd2963e906ea123917cfac0a9a145b66952b273068dae0691872ff8b6fc1d5c7eb4a7e96dc9944560779ea8cac92be114f2a615d329b4a010f54b2e1aa82e5fa037daf771988bff39b18e50d73d11e86914487578f0a7d22e14bdde49d0276572df0c93118d7e18851b28e315cd0b690fb3653b48c041c1d18b55521e967929cf5519975d67cc935da4125c3e4031f740ef0691977fa70a7cd8b5fc5c5640e8f39293bf0d0fd2dd002409bb268ee5b7d5c8e9f5a2e4866e6434029b91fbe126e9b533814c2faa0a6eab5b5702367c212a4d67b56ea340dd44345ab427050eac3b66b6369040272b6395539ce39e226e0c922b03d49d6892e97853882c6ba50481d7743d20238c903199c59eadeb3fcefbf87fdedc2ee4ccd8d091076e2949dc5be54449913b808600697856d77d21e8c6b015c713657cce66a0b45917c3984c95ec9dd46b52bbc394c999ee1480a5da334edddaac82b413e6a972b5b871175de92ee547fdf979e6e65996bc3af2f4a47d1389457c87c49d9063684934fa435074f2f345e74b4381acdf58882d46471862ec1f4bb83fbc436f5861d9637216e55a43f3af1f7797aa78e950971e876219bfde4dcdaa55b851b44e3a24f1e6c13aeeb1245750e4a3f529e459b76904c07f2bfe70df8bb00c688dd10766a99d0370dab32750bb1104d0c7ee9490f72aaaa0fd37cafbea446666ab88a65a1350e5bd28bccb7c9652dff2bc19c305118b28ae971fca9a6a1c609bd4ff0118e29c72144475864f3eaf903bbd346374cd618d03aded0b9d85bb22b18ed76d7a520d73a7a98a763f502bc8280d5f025b1ca3d6cd38a1718cc09d1748fc1c2873cefb6307c94a7bdc75d597c98c038251087f2a23619b583a8b546086a0c9f418c4af4c0727e43a693f87c61d7c93860c972436b203a29e6a69f255559306bb17c7f1adafce4335acbd746c86d7eeb69a8f1cd845e74a05226de15ceea5e0bb09516fd684315b32690dcf357948e1648bd97b2a6664bcb857c1e5fc7be27495f3c2e99aa4bdd98a7dc152a75b1135f31dd5ba347cd62cb39bd94bdbcc84c3a6d505dc36e4fc685a81b8b1b79d9807a303bc4a5a9e10c184a1581e77bebc6c6cd32e0a20eae4f4a0e4f4ee90d479a774286ee8dea1851a877114f229cf965f4dd1d49332dc9c066e16edeecbde3014cec0ec6dbc78f271ea0a75012beff5e88701e02fb3e1e4dac8b9420807841bb755e2115c6c6e46b2cdd3c365407be4cfc0d9ba04335d0fd8145b67b045c23d30c8992acd37313ef3a7f7c9b0b703d143f437b5543eba373059805f2e778369398e0af93a55c6c1e962d7a6f476d66d10ff2622f619147e1c39edc58346d17405227e7df1e9f6336c813e618f826ea003f18d714d22e6d3cd717eccc3fc862b25b972d746858157b52105dbf6d37b9b4eb52d2a544e44ce2772184b4746e763ded39ecb4212ae61a05c254b1700fc47890ccaee2d08cb1530610c305cafe9ce2d38267ae622a6b7aa145ef999f128730ee832f3b04f41117e4c0000002c30d2e3b219c4f92c7a3ba309486e1874894b97b9004b2ee16c951aaa1db93c161e54a79d9e5949293b3fb5aca5394007c33971a5ad4b1e0acd537ca6358a3f620ae95b66b058ae3c3ad08e6688a622225d05f16d42013eb4be04c3761a66e93cdf716c743c02f68d39f71441dfdb2686664989e4dc0b629984b2e6aa0cd2008af061a1c3b83a024afe3f6fb073267a63cfec27c8c21fa473980e79371ef2b028e680567692def0429ed9209977bab51786b070bf54f8a69c5ea3aa03efd01f47e44c4d63ebc00dfbde73cb79d56e2d6551404f3f7add230b60c632407d918d3b04644cec57bfcccb0e3b7c5dbb43f8df8167f01ee0e32459dd00c9bad8c021647a6d93c630b21730d9b8d865066d58286fc1ebd25dc5f6119317c9749bb53e25179442acdba94c51e0f07cd3bf74aab44efb6ddb2a9e95cfbd76b4c32854a8c5cbcb7e4b0bac81fd5ff625330e230d3117b78a91c41095fb786fcd6509bad5436f2ea04a06301ceaab2f1490b76e494ab4927e340121a5ac02bbf151ad1fb3ebd42b8f5ec440e2c5a5f00edd5c0efcb19834a87e39d6f3a2a220d64272a18e15d645e576cca2f096d689d03d6898f0afe87ddaca1e905d8c368bb5730f5db2c102b487c47ad0bf8cabba8c91facdd4098f69facf4adf8494ddfb5179a7266accd21f434b602e562d6e11de028ff27abd1bdd4944258d5e246e2c2b056fe6e444ab9e82cfadc4f9b50123f031082ec69b3a844022f9f9b41e8f407d470ab533cd8e2219e5b69d8ecb20c22d514c1e15372e3d1e536a359272218cfa6f9e60ce38eb2539d222c9af9a192a73908ea2cdbf268e9d8fbf457e3eea1a45590ea8f1ad2bee83a70c9ffa0a528bcd61e0eaacb3c85bea64c1c286cdca88c6836a4252c16c48d7a9f2bed2ccdb9d06d4930205b81415331dab055906cae37e1aed485f5673cb60db74eabc239927f99438b7205875343e775d22d65cc198eff590257e709a4921176a33d8c086e1d419acdaa5b60c25afd269427220466f09c759167b9bb3c288d09733d9f372e17df19579ceb4a6852dde577c73c323eab60c92d8a977fdf6e12b1e6e36f9d8cfb1af29b014701d677522bfe6beaaf6739d9f4781c59429b51418e670fd8954e75713bc336838869ce45d31fc9d596cf305654266d0934f3e959c63e179f9ff666b2a79f55a41649897f04fab8e8596269de7f227bada85b84c04bf8214c716b21ed3775ae200rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-56.el6.src.rpmsssd-toolssssd-tools(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0libcollection.so.4libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.6)libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libglib-2.0.so.0libini_config.so.5liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libnspr4.solibnss3.solibnssutil3.solibpcre.so.0libplc4.solibplds4.solibpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.12)libpthread.so.0(GLIBC_2.2)libref_array.so.1librt.so.1libselinux.so.1libsemanage.so.1libsmime3.solibssl3.solibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_semanage.solibsss_util.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-56.el61.13.3-56.el61.13.3-56.el64.6.0-14.0-13.0.4-15.2-14.8.0X6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-56.el61.13.3-56.el6 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnu?7zXZ !PH65]"k%}:w{{.E+wׅMS*#ҎR{l^Jf;=4i njr+ugkj8CsqhZTԥ r,8K1>&/SNNF>wrL 0^̣w=]7w.g(OǩC3Vל$WjյY{:NtFg)]XbWqH/\B xqeKKE'pNn-Ѝi"Ua*t‰{z}teWާZM+DQ~0mrG==W|?9SNc|8EMǘZ6&[+ +":={ʹjy/!}_{g<@Fɮ+L6WyR(Y϶޿ Q)ʴ_T ײUqxᗭC`WmY4}X$P#m;$[u9M:="l 3qGR$*yp6lA7\ /|V)t"tOh1 qMl?6Yԁ}K%nPt&AY hic]+&rQy;[ۗGSE+Z\j3_%|pz./o sDq7&HQ44<=9 1(1ZVT7TJ~,囸ȵFo\\xHR?`>&K2BUs^DJﭳ8xp] qm:{^jYf؊f{TRȺNPw|VXXz׍ OI&l}VnآU}Kh3WFHT/D{KƖ'Clb;fpFi7ڡ.D8rI]8[/GM` e<]'Ap]]~|C -Gȱ*/!hP%DO|&ƭA%_ ])죒Sz/")XyQGIb)MQ ,LV<{mQ,^@']β _C= Vt_;ؕ0،VF~ihщY+>::cT!Sktr뒸eOΙ[' ]eTa]RDwaI@創jQi~&yi[c<;/K+Latњ=.v8 0I&3 M'Obg(qcLt[QgE"6Ud7ʹu5NDI9Ga+:mqg\qRi08]~ps1yw1TYF$'gg&gy>(,40VD$N!ohGOgsp~z{Ĺw=,Lp64 |#qGG4x<<)C/"nfL9d ֢lepGHzWb@FXtTh~]Κ7uHRܭiKcvrmɻCpwF=x"5!pikC*RKVf_G[* *Qze3 cbE,ok Qc;;2kM +':WyXR5͗hμxգ2a‡W@hhXrJ.&K(W[Zr!eje0M*~FS+ot%,IQre0dl_ Wa3I?(G༮g1|q%,;)lAAÅwg|(MrC8_ċqK Mjb^ÏlQY\SB8|dřS ԙ02Cty\%T)WjI:_`A۩8eps?++4OX VrFu,in GQ~ t [)o g;܅4ZC6#=h|Z4y9~MEAUuYW%ߌDm\=*iJYHǨ9(V o c״A[V|c #uEpEK2_Һ"D* ͏4$Y G?y\P[AZ7s8!uiCHpğ.r@8[rN~Gx2*X$axAp5A[uaq]m8cee|"EΗoJ!B-ӏYR][̀طyWW8.)yZ72p*@ GkEN+.}ũ)߮4M=EfY;/pFi|acr}]VѲ: wdk8DU=mR#J+){\K˓&LHZ0xbHoħkt;7^C:$WH {E8F.2di☈^ Ӧ#i=of$x^P3GqV7ܶWʓDzK4}K֨_2^tOՔs!rن0ic0P.8Txqq sy-!Dj`#zf //r gaoʂܮߩ{Oxn +⓮H~vk4/U K$ƤÚ)>ni:|#.qA/ ]  Q=@'Iuh-KsqC؃M! O=f ?@W;y.i%P|IjEH-tIR`R^}(f?j[2RUQ7wM_0]7ļ4S .RCE<ɓd^cWt2Eg+C&7vu\EW7` h`-Lg\miC6ױ2hIō{l. 4+hj/}AdetS8dMFa}aOvISsE"S-L >zլ ]/Ej'lo.:4G<5e!7^P_^Ō2f[Uq#`|ޤa|˗/NVJlDuM@t7/M4yԖKO펁=f>cçaKa͵ڎ7IS\4A5O 4CDjZb#pNQ? p٥-RlXOy\0SuZ_<'*-_x }OVcE mGA!6;}]UjlO ~%g_ODℭ:266X{YJlgE! 'F2REl 7pʳaVRgG ZcwV^8n HMEJ Q9̱zeۄ7okڕ-0() IYV]"Ԃ3ÍJMzW vOVTgF# "z@aբO_iysk~Rx>~T3& 8ßgv{Z)E-v k}QRٜ@[U;U@81Lc]|jRu.#Tap¨H a9Zݱm[qF]%m'J⬊Y]'-8fy@dnW䂾7 BصNb[ R!Lx~rD=dPњ Lq(/ikܧWbcaD1@Td*Bo:wUbhIo#.ݰLv:sqxrE3dEno!IF"S6g{,p̰G;gӻh"jWu[?O!rc*u a{ƨ48No?)p5ʜcuPЂB?Z*+`QSoka뙴 _F@o@[G#z7_L0Xb^c`nH(S1?T62K m3:]DuvLP>e-+Xh # . 0]wÃlo6 +YIYU%(5PAOj4]/wzx8V/[ @TO› 79'8lk)|Piq|3%*MU]PCwuzC`fZKQaw?^ *\~; l,'.)>@! bOAvԋNRxGk/]x'Ɇ<#ܣ6Hx=w(mqUS7GAV88=YG9r!վ͛oqfA?yPErvLZb' "1[HsJ9ad{+ jNh/LA_bW%AK#P$r7'`i-ɥd& 86/y~=$"Yþ^*jyK4;`[-Io5ͽk2wxMxbG$J7o_sg5#_fr&ic{Qk I١ K*S~{v˥W<EcQA Ut9زK$7Lߝ<EϥcF2FlǏSX%|7WBK9%+!Ң|,VizŔLS҉ppNA`uAXG!d-#_ds2NwS`vgt=Aex˔WBS_= f4Z~jJ4 F~uX%Xk3JQ౛kQ*&xD-M{N݇%]ms,K'V$IK ͝+yޥuW4&MS($³:3D1Ah/:P3'.X_g ަ3;<.f=EPL~i*ȕq:=+`AboUdbVxB]YϜ-@{\Z!AN"K_=@/a%V WgPTFUsxģ:$={7>4cs[" N#,t|N[; B ~H3d'C+QU<='^pY b8\>4r ϚIk܁:Q.5z_f)Ȭ8X= =^"=mKG(͙F"1ʹyq1L3#=c NNQEf çt SԠ+E6IY>U[^ioc`e 1*)rWX!6a7Q<;GЎe D(˥puA 9?kUSʊfl\ŦP!dd+|,}aUfi] !<߫ՃJrw*I?K?\ 0[ )W f- esz鱑9c5sI? dO yUt>4H8(!J4{k"l{l$_񮰝&|}xގ`F 9*=j_":3,}5*LsfL.uS."H0*~<_ 51m\$#,%|Jf6B+G69fBl1+,iَcLJ$?OQR7< ]Xp ~ @209'2mm^> Wáar43U 52D[@i{MTrwG㔾2;*3btrM|3ށ]lWICmѽP3R yZ3nNeFy"|/7w6jH><~ _o 1cĀ gW@w]veu㠅Uf?0"B{#R$aEAS)] -:Ϊۇ{;f^sqK$o9uEڠ=Mbmg[f4bUr_Ѕx](5&(+ [Y}v+Z4)e7vu(*>NBZ/'Sv3^m%#Q"eG}昛AviNCI@!(Gw ɝn0zW8rnO 7E\e7LO[D>ۑcRRXZL  Մhѳ M^0M!ڀʼnAD஌5?OvbR hCU f Xz5d9ahyC«LV{%RJG< l%[@nYGrȚ oA.7pzevZIgG8%,F6l5yj}}sXe><*Qjz[ԫPRcL]N̐)EO麣A@7 aK4ϙ 1I= wZv\u% Kr$キjM0 Eàq /vY-Eqy-37WޓcpXGkv4=Wdaf'@f ѩnW0kYz V|[2c$õwIS(&pHMXD/++(rr`\Q$Q"/G4_Y#.g :~'P-jdOrkA)fQEO|RJv2#@eWj0E5xu]vCΑ߂#DBz)3^< ^wHBXs'C+-L!֮48M$߬Uw7.hnٛ; A'+FqoG?3@3r׵PdltL| 9fK_1\{vGr ʽ!O8,_6Ao-Ƣx4e|WZ\}zlW`hARcdrlXfPn ,͖!I:"4_Qq; 6:}ݣp G+:>Swޱe`<Rsh{U\zQKv߽zr䐷 Fj?[,"Ql|7ZM6h S?Tr ;X@~4^1Mi]L}^ѳr$IWoȡhAfejrR:N}LZQoÀA˜śnL'8n¶ F@[φ+.G&g&t @ [? YQ#\Ey7n,I\T+ekKZ9 zGJ@dl;qm$PLy [ :Yt,<- %ч6eo~EESֈSË90q*%:C#\t,Ō3cqN=,QON7ψrQ6&C+TY܀pdC|"Ez^RE*9{$yrBx6D5eJQx.m[ 2w5Yc ulɮe|a#!>8d9l61o 1a\ pL/ԼH;Qp>%u]J?h4`m T-G8=A ݪny!a =7~["*7EBQcD|`t}&'~PHEHjZH4CD<}T l4ٳyrK۟:GbE"U#y(iddz';ՓJruF?.%,-${My,YT'氤ľXX5L{47 9Sq<0)Ѳ[q8GRE %?C,"˱φcȫqؗ_i>IdKһpq7J}g΅JZ0mz<ѵ V,<*2\nHR(M\][qҳ\i@4}GzH2׶M4{Ol)ª$cr` =4Zg_"GA+NY>aZ9 3hj9ZI"װDFKB J$0XU5]lx׶zFʲ6]3f7 &E[ ZG(ps2v[x|~gXk<fI=Ӡh;MV1Ar|Ema& ɝlڶBvðR+!H|Ux @EÑSz@"km^OnIs`zN :qqi?Z<>IK1ξ=9))qN u$h.c֐.Ukd\yQ^[)I{U}WؖlU, 0W:3.UK h٤#ZWT}X@Is[Vi#8F~dGF@9!ͷ.{MgdLtL|~jPĕ ^;Z+} C,_MĦh-f} bKDi._W/MA`g>͖rWDNf @+H5Xaob+ `ǮfB;q4$IBQ-cϻ]\?g F Bn@C_>:y] Kr9- <5ZTL1#GTu) {,'aJ۔ ,WSzBbnNE1ǫ+?_૏́,0;AA*{6WhgHS]atĦ&1׉+<9=hXsv7G =}?4Y X5} ]PTYW _rĂ.65xK95Ik{QVJJ&StQM NFh!>2b/ꁺE2ܽzf:<|%'XJ[鉧Q cahҲG;s {t<^5U~W1X|&sD 'ZJOeK:\L* l}l]p#aG^m_NGUpJ'w~F:5 Lj)$H&y}019eߵi n#C 2{THmVb|&C)`XBotY|0 Z"trymIcV%;u1m]N"x]MR$MTn{C)2%;iDOh+d=$8AfΡ]&_}{htnmS gӄ;_[0R4s|: (2tqz{`sm?''sNgՠ+>i8)0c>hpc}2E8|\}غͷu䘏qc}}uB֯{`ڶgpb~lӚ\ɣPO3j>4 WN]B6꫹Uf4?W뽿L0G$Yྜྷ-eu7 Ԇ8#뢒:iW2RUGU1vp=71R;#7jԈCk}"EUeǥpo'GɎ>6u 2$gW[m8!OYhȜokdZTWpdK> ه3Px9dKX= @I. 'E.a_!{ R왊xgKG;iδ1Kr£YU@(hnn0v,Z_U^ou^7<(, y%ns ;'ސ9fɁj:kiM0FV /ezPrvBhXQtBabL x9aXzB*u{A +~N\$c*>~bv9=d|i #ܨ4y`J9ݧX -g`0\̡ứ=f  & twocu*T%vs yH "'HQt+Gs +^Fi&*{ƙ=6^+{d*d?~qC=.5( k|TqDH̤ukn,s"fd@bL*m ڱ+N&BHQPm3+ޣ HLԁ v"hwFUsZa+˜$C-oL$qsHx!QwV䰜-\!ڣy,z|"*pf, !pn pty%քb+(=OkFZ%pCefTMJw!~vF» BeEظo&aPѩ#ޤe.W+=@{[UyI .+ugUBB<񑶦ar٢RGz_}Y``mlʂﬡ/u|!BovRK.[aI0Ik&OW[f~g\h6I{w~/1 $wڝK69ɼc" ?ښHWyhJ0LQQGm9EcڗHn!4Twam-MTVﯦ:X߂a`ؽm({U:KSʏ!1z -TQ*t#`z5ŭs'pymqÆ٤ODy|<|Z֪dͺșTNʧLEeЖ~K[Uҏ]M~ࠬ҂^UlJT7⧓zw:UBFh3UwNGԤ, ϴ*cEz2G}`Wia<`![Hd}N Qk\LE'O˷ ~h|kwx#@K=i>(8Mi2_>pPzf㔝 zouojZOf)˗b3U9+ i;1.oh;U %Tz4n:M9wO{yKY% ism?eM[9YI4 (bOkg0TR.Gɣ Jv2!.gs; n&uX^/W}'X 9HUϗobagj_C{X +R@X#7d+x_LniSb^mW*SC '%ZV[}.[?xOJ >:i!ƚJq H+'W% lv(2dK?&zI<[FFX0>ER("k2qdUԇfWF#mT/c7؆Lq 剻5HHY d/>L,)|:>䆜jd9Q|Q񫻓3khj=RgGɝթTq<'_&Ä  *\:-'OJHmWX &+o :.ev9]ǩFw7bScEݛNOX[u0B9؀a\.ȁn#:e*0ҌGm[W 2Jws,,bk18/B&g}t7Ixm@FNs .kydEv4@&tI=2q"'Rг8ý%gGhhV nn\nh2j\Flz4`4PФɰK p t!d>j :'N7Ug|BS "{N딢ɿN&[QvâVL-X2`~Bct8tf N4kg&Г ެtc9kHFI&J{ A?6x02f_ \bil? ӯt^^f["z^.'kw2W 77;M_O> uDA7e~2$E  2[qJu;k"~gvlx!26@Nstmm?Du^3+,[AtB^o z$jj].<$.Fdtct2@'8 @]O f@Pڥ^N~_U=ݞ&"O+*Bd-6*ݔe>Hr#:apն ĭEr(3,:ڻs.*buJ_gϺy|@ֈNyXR 5>yo_Sysq ;Ԉt6%T[Em m@jd=1,T[yzdX&"3J. ^Z9yQdKM!P:Ye 2=|:Ss]F-uz YaOqPj~fCKE\X0hKoA83i_j|P{`雀!ޥ o+csGfX!>҆7Քouճ=y:!0W?ޚtss{=&ki͹Bi/cSsp鄍HC\ksҕ=KXI{mJT^?_ʊR&fXcK#ܑ0t]fVOiW8NP5RhQeD J7O@\q61@hh^mxs͒=)ח}|LP%+#AqYS8v,NdPZ{lGAj™g(}\StPn}nuu>"lߥ R,>1E{ L5pdYͧ*) ^c9膾st#Z=]OwD3VM ەFb܃r|(GUXʛ,3CPei[.ȕ%e@fEM:'hq0^**9rҁIa~;u?h+96̱dxjT}{[&1 R;<ե(kTlde-t,{OzrVOe׫r2ތuꋑјnuqR`}{?Hڐ w#ۤӆ孿 9+˚ u2&n﨡 %68ү/:;u=;9Hl7`ݪ ,HAOb?w`f9XDD-`4ٯN>=Kt2fpG BL^yV5}aNcldهZíMbe[N!f#"- >>CbpZgmB^S-I]uY _4,ITZB_Vfd P{yxaOsQ}ٍ[Ie.`Aheu$9)# S_mIs Bg=ajSamd/[V`YetlYog dD URDm4e4tY>9FT\/'Ē{+yøVAaN=Q\f(\H k]֠fR [h MROCBc-q@6jfvVneX* N3p.bY/ R3(}ei_ OD"E|~26M]у~iF**\jtV[ uscC)jߜb:Sl0ǚ̉o''(K 1CD0*6mƇz,KGesAM}Y|gzk֡Nai!t-#<8\|`C|NJObGӡgl\1z_w(/z n(ܢ an7-{V/>mp H:E.ƍliuI\cc}n6ywLc' #.n%gߕ3ǂٍ:@Y/,;0΁Q:2c& HE0 +oBO¿b43g(wG۷[ Ai"}ŝ [)("C:;9ˠ)߫ujqNcR!3&_bv.&pDTErkǙ1V#h}!JQj Kf)j4/xP>j(YmPXw4/J=|q8i>/i9G n7i0@~ɿ ғpaWB0*>$9#U\<6">0@|4ڒ_x:f*$ #tĺ )[w}/p9ą [%dLPԚY$7敇Wd6W;7$"`xrlMb2u\uƷqM 2mQ3Ь#=pln!ݝEjVCb F9I q_q%5ZeKNްG[3sv{72.5 _H I(٫RVT " >|n?AU[k[n %ƶy|LbuÆ=٤)ҷYxy!~1T>fY,iIcƅD#%ˈ3+I!I|~v맺w$ éf;4]j5ٰaW. 3S+X B?Jڬʄaw銣vSK=Ѧceo]Q ]$^!b~XZ JUCИ*k7~lZdA+[6V3i8T?< %lzt hŔmQtP+_JMt)]cw3֡WjKem u09tMdv_5«9k7܍f!YNr>bq0l%=<}(*=?8 E9*@_G4Uu`ϳUysIgb4o<.xL[&P,djyM.jSVlY=bQ*!ƋwY~w÷`Biٓ^sXxɳ4I)@;LQ}=d|ќZSo~J&2@Έ9gw $l~2Ddvla"jDwsq9 0S^̑l`ěl;;UN7C]Nx",∞n2%I92a_sU`/~%0NuБQjGuO{aǩկ14( &\&pB^T:6q<]ZMu K28qg V##myQO솫&Wv!aVρD+%N! Ozm\U5yc^2݊/gL >1+Jχ=fEԑy}a+s;mPx,[X4{8+ͭ>iF'{RDԾPyu.9+{ѢW@1MTdi{kb0ݖu@o,ABe:BrCX`o2OfݜkS 3XUv,-CO1u읐&4gdd$ Ipqmx1T}yUpwAL@Q`%5+T:J5A f%MW5T$FhIOKoOqX X}U0L~W )VVYR¦Fen'z?0ڿCԫV? k]J@lZicE $aEޚFF ω-K6BsZ'4Εo}Nhb&7"L=ϳu%Bf:/:^l6R3oKHsM1yMA3$]u/8d[+bkﯞ_PYETq,g-$[QԦB^X O3(n?R6_i.hY$qAx>ާL3gg+ v[6AŁyuIDWw;/J[Y,Ujƭ <逿d`3e(p]TV/{hwjMG[ǙIXWO-XwdFx]t8}\9O#cXe pg[#*o5ud~EhA.6kewǘBs0v? VsgDU1>j]anx.EhKpE(Aw qd9,~P5,3' d"+Vm%R S1{Y 7mцݕ:& Є_E]h4ȎMo.W*fPJi^J۬;5X%ޡ%~yv?Ax,/c&1:7ܗ0dIJ0A9b7Ê>+?惻!7/,oS?" |Qt5Dzd=s䥻K/ F{( W{kӲi0,26g|U<0 piTle@vvc7Tqcr:1NqrN(ļ|Ԗӟ;t"dÑs~6Hg^_!,rwFTl[ϩĪ%4Һ.4C57:ܐ۽,W_47<:.8#UyuhQur!1g5g7IpҍynIA]zu;Ԅ͕ׅ[̱ioҡCWdylwoces9MȤ'(='[ |@ 9";`L}ɏ6}Fyhqo^ΡxW CoƓN3U;<샼xtm/? 3ŀ!A@._g\T PgKv^,OMnX~\ڐ]UTaă|>6 L#? Yė*dz`aCTCT^;oǰ8gw綏[-V[[BzF9#\]D/@gviHr:b ?AsO5 W5ME8Q? {|A4)N셺&iDM  p9l XEؽK{b|:JOKay6ed"V:h"\!=`!9+v ,ɽA:Z *yYmgmc aް 9}OYai=f5$_XN`k?s'ws״r^U,{T,6g4Ξi#1:C:ӓSsAIfk ?8勝lZzB>!.2ф i?vN Jz_{` ׵VrUP mc/O jh!ȹ)z!1ul烋IN׃u1YnUWr*A T2ܪ5VwA+;dY߼ƽswjDޡFJ3ڐ->6][$#c#5җ%oY^GBXT&]VAb&;bF[^$uTy_'$m0N6G2$ -03O+ٙC ] 7@PtmϽN겾)64òSbDNl0U}ҧ@iU{VlM˳iqE"ߛ/*\W+VSHHh)@DQ}ҜKcßU":ʿ$8`z?7}mlȚOmК!"VNXiʨ3 ?ش7t< ?slAOs~̢i= dr'# MMun>n.2p'w/=d@9Bʘ[ݶܾHǪ΂X]b=tcn}0jj;Be{Eʭ]Yl=uĞO,[܎C&ԍ0 E~qx&Ip (2!3G"0ڨ G'xw:ilO<~](LNQ37'&˾ƕW(bH%ꆮ0xj6wڽ }?@}lV2]Y)M"H}#ũ0_j`e2B]b _ 2Y(S$FSA\z8ɂiI ͅ2,w%sU>6_ShZ%5dH{ĹA>zAU]𻻙e%I7vU%skzU/5UɃ@jtDAJwy [uhʓ7 ]]֩6Q@d_#(xUoZY}ߎtн1+uYX=@A:lYdG& an^H3;o ͂_N\yo0/Ⱍ*9lI5%GYD /d潚& 2^ڂnUI?8>I_1h2L,(¬ѫű~TYT$Z2St p^^I߼0fZֵ\^jq_ғ6^ u-ՎK>L1E8_73p _DPHl?=NvE2U4tQunka#e @Bh9hUN(/K}00r#\BJ W&aHdo]"_h# 72OdIF3Ч[ۀo v6l&q 'pr$\. ;E/iRsaDȂݕTycIg:1*v|"nm mX-'ܙEUM/3ᛣ#@tɾcmEi[_i\f-Z\B"7J*F$lk6!aSG ]bcFB6f 32u}խkVkƅ^[k |fxc_1'A.ҵدm2>z4ױ%VE-s["$HGnާMOPIfy_y|oDV̖uEmwb^>c*[%hLp+Ráq(vIMNu h~0eRT<I9+`5\>&Nn*vt9.s|#~6lh43]A4}aȂ1med@n?s{ dIk|:?MEIbchSᮓCnNʐʖq!r i%_mN܊Y4;\m2P?5?\qݖPdhCxsX\ӝ߹Qe5wh$k6-cNxUxbuH3W$~ '>6 d-.^CvnHSrα8QN":s׾(d= $.P3/itn􆙆s e3-e)F)ƻ͑3pY3U5&Qk\(2ޭ㒁Sl XDfoakG-Q!6eh"pҐqfo?'NV/蹩aefP!Qn6E<2eZ;SB^_`߀ sݶ,ހ%:]I+aڷܲc8qΠ2oU=;? N@'%fbMu՛d3QNX:ʜ0_j^wj] vPA agQhǼvٺKQ=NbsNU5/>kQy͍yȢߋƨĞz;|;RfxSJŽ|/LjHSISR+uαt9h[e::VFJ)py<6/4"%OK.໊k`U3`@k>d3NnbL(kvU؅^:lC ƾFPmE) Qj,v#8F!@蔣T_% S8ӛ}Y# ciAܿrL yM~u$$іf Dk=,{֕0 ӣP=~'g$M)O+8kXN@Bjo݌Ձ<7mHSL'$&;E3Ni}D'q:aHH:N/*זioLs7+߀+-hɭ~eˁӇ^)XȖ?saZ2 T^4$#xps^JJ$#3y_>kx(sE^ <",}\5@t{h̜b. V7_[f6Tl 11:2Kqnr^+oI1B4FثNj1\[/.MejOh]b'ZU =Z"M1ZLOX0=5uܣ68%r^B9pt}|WZ&Kl[>4rr!a %"|>zHt\xk' bR5 }W)N2,iP V 4kߟlq .b).8"]'d@_+h+0QcXW+c0jy| 1`xA*9rJl6fS\cJm3A:K,ABx(R MG]n9@";rsQ,`r715NqX?>:cDOKܑME(IIGO}8Ckz'`l/_BxK5K71hoT|nΤc욈.$m@JvӟWQdOT ,},f:coEs.wp=Q}=FAbk\S֧S^◹5ݷC֞A&b4Sdfr,\6t΁Q3F4sK!oˢ]`Behۂ[@k564R2Ͳc̊okSgp0NrkZշ^Zr;>6j9jBYvPEC/^6`T 3WzN*󆓓q&V:eåWjl2E3\q},/86̠%Ҵ's qG{CC }>èSM`c0gQWYxO܄1>c=*ƾ=?wYk Z펚e]2U*.aE>d fm?Z(a.D]Y4w;|` Ό _DoMK+'*3em=A=TA9}ty{okk>$fk1[Qd/kj 9Ĵ^$: 49kԸ8ȫIոR Z&IК7n9ByA<U>=+-k.R荇pE`}dG]YdY(XD n3v)ΑH]-ߨ7 8Gł%V# hF,(+1QZ&!<__7u)_xW2iAEPpĆ4&c[l߬kD;4ه&3!m_vA=ǡQrL1թ iL giƥHLǟUTFby!FȢ0<{cAHݪTE-֊܃?c3dw@4bQ S.@<@ jvAHc? uUl8:VQr*`IGA3*tv/[ eyE|c vA~  -n)1D:QY .^f0J~#UR\{$!lzF"jk2\.ӝ@[t Mnv8% Y;@Ʋ4fj_}gkc 8( W&5o?$Eأ1R!GQ75S]iه ~Zu;IWkw۴:yJԋ'UHH&Sl_u rA6f~t@p{zm@o ;n(p &p'-8MjC]T#Qm8)T|h/|%LBQG_+?:ۑEJ@'NBF[/)կS25Tэ2g4Gq.]<Ѿ?PlJP*%8ܷ 2 m,`"90`o]YBTeEe?8@A4(,`K'ФHWK1at==TyقqX?7c >"pӔVme0]yk9ӼDKzPo}yXs:R;~#a^ 5d)]d=xsșVZÿcљl(O8kkrQ/>7dyo;{Pou]ɓ<ޡ1yaBEEr{L BJ"Ix6~$|<^ L{~ )O@f꫁Y}naNʗhDHO?(XT'}lϚ]D~byPI7FYDR3^!O]Of{ \kQeo+aֈPUsDJSj0 =#Q}0f˚>w@PiQuڌ'O!{l8M:YVR{)7B3Oᔈ%AKE[BK[޿D6q>Q#"t #>XTj{nNnU E8za>)Ќ+ݩ W1۲JnjM4`mϕOR{n[}Gۖ"+=ځ{11biR#AKTC<[ ysBM/RLjL͛8±8},3'`U>w֝e`>גFz/7Brg%_oeV sG#SXϨZSt^!v y`<g΅ lqg4B#| ~EKtXmR͘QK8>.KdE ,M%ҎЇgBFƘ)ܿNh UvPdžtJ]k_]D=4ZV0ϷV,} \;'l^͹6&sp)aTM|]: LW^$M=ZO5Ң ^Wv^T + I: ykݲ! 8\5^a?(-K4tF2o2qdc3׉˩ mE9QPisySxo>YwPldն*wGt9ǖlcQP"E\`6tEʸP~@jđ\;Y^2|,H YvB4B4ևT-|g2a9չtC RL~2? x3d1+Eț,qzU[[m'sUre;u]rL;p-+j-fkĂuxJ4kJf7ǭ5?GVvjog5ϯfìIdA61 U~wAօF?K ׅ6~|Α{2 #z4K)nuʴvR+2$j̓qH B|h6@?xF†TBnY|ͷFyxLMf(m+nF\!DSULy|me`6qK1[n= ko{Fg'OW7hf:-X9aH53xl9(qKpdR b4!"=?Ì`ȢRsK7V߁)-'j+puإ0or]JOMEMlFdꦛjL FjH$Bx c drLj&vp. Ȫ;n^Ax=?H.,jY3 kEC^?%t t9 Sd7/%ekMYe([Y]?Ň4Bs="]X3 KU4-. )%a]` N؊y߄ɆN{Oo?x^Ki{Jǐ Nc;I5{iN_f(p/pl>ZZN6Z69aqAe 7lt Ni_T8iw4Z,r-paLL)&7Hyx p6xHm=„, G|5e1R*2z4xuacQ!Ne&6[ @HpT!`O7*/,S%Q>]j:/?s7)Mz.zٙϛ0-;p1Ϸk쁷` &#'GiBҋ$ђ@V%O?ԅFv6gC}7k/h\k,Ot_rDfΠq9zzTz6/HМ`5zZ[og2QHQn3a Ȇ؇qniBUu;S< -w%H/LIb4g]`~ թ.iR..J)ЎRnYlE`X|5d\q}F}jMni vgvV٨D%dq&%1\Cë4ar݆4>|%]7mOD կ?p)z-{XyKqiRQIՃJ]ԳS sY%(4PHTEA69׊{}u9W>Y",|l0̭i؈S{rtPnʤ$!IMܓ̄'%1;"ϲߪF3YvšR,?YjM CvJРg\C\j Y'*m9FP!Rz=,3GǬ\Tޕ7r*$|k}}WhG5Aeƴّ'hݵϑ;F)Arr2:KWĥ:z6}V}stYЂk4l; Zm F1kW`/~<|/?=ΚOۨ <殢kmj^p5G_@.\7kyMP@mc7 Cݿf srبsuVbidIoH iQWlV,WJ~<_ .0‡BfyA%fR@CХt{[ݪh_H{IW87PeG@&ԥ]/?I"#-;'2:uQxU+(l5~JW2caYTM1y/U=B2pqg_&kVmμK,^ t !@8RkmJUCvl ps>Yڮ//BϑNBn\= ;$ 97hd;XZ|ϥzbŋrkeUQlrBT̈́u]Iy+䑚= Ȋ]*zmXNO^@֪|6JX0/'$`)y%9hI=[%E}Vʎ $g M<$`7u8qg=8=)Rn| 6lߏ~$㼇ɣ䞑F'9X0<썦ˣ je? [ @^W}ģp[s4.'AKfpo*;ՆK6DMs( "4:4r fTxK6q\bue~ѽm~rcjea2;Ko6&,/StKaZ_Čng WX?[i-*A,.JqtwMh@*"Di  ]x^FәCnTE~,;p}Bm…͚ޝR& !7) U{AHqikgU}e(7+ ېdR \Hfxݟp}5np83sk16q^P! 4$ɟyT_nFܐN_^%8)mN-Ds+/v都?6;Oe&TivI%qq5/ wF2#VDp$ 9MJL 1Z珊=9$#Mx$iAСlm9=׷ _8WߥE0{BlncO QuϱVZ/h9Nca9ȍRl/SSbCv;]Zc'kEA_yL7ۊ en|VSJ6)R'g@+ NIX@p1{SVB$yx{cE{k9us#}m#[ݸYWMϯ_@pt>gk*g&\%WP{%2clm)BuF$WtL4U~NII^$ÏЙNR,됢`D~tZ_QEx,#<Flϗ-.{vFLZq{ s-Bw_+\a0K[dߎbH羬RRqϥdGMiF -Hv(6Y6bTLZSŤrBJ+ O[|m6Ȑ; _ Ө&7׎YkG;mf5`,{[L8s!ĖzIS m_oj$Q-4 rl=§coYHƗ9>(UōT䟠Ph,|:|sMW j'*X-;Y2. *U٫1^,{-o%w[dcTzfUzE }`~!Bۤ~gR+5K7LýʪΦh֡xD8))Kp#K4NR\9T[H~@{;0 MhP1 U$E)@PO"-bn5Id|FYE߶ܴ Ɂ:LIcx?hTV1  \hvaJBFhtZ^1.⡧|vrߐ("$dT[.IslYyj; $_vڰJJ鴲 5/Zٽsa.$%K_||[Me :E}` {W蜩l-Ifئ:6:k{sut6ٵrkMxZ"p1_qP[ fKڄSS?slE?vƉHuQ10Bܙ9|VmQ5}/2;0,6@|X\@fg|]ɵpl Rja-@V]2D]Wmx kW[P/y<(ۂ+?44wMY:Ѵh0C^[ugQ1yӥ7S3['GUha=ќ( "ꮬg(AfrMA6,fuWb4ۊ KwK<-Čln Vi] sQj"xPC[63Rqt`EYb?X}^Ç8WPg\ȪrU\VAX=^A0#F=g\D{W߈aD1(a$Ff'vٱuhNήFgJ{7ΚC<*l:/Lp?Ŷ|yOtW"ҷ/ J(7vyt&ʅDUƢsd=b}*=XoZNg8~b <$ 79y$uhI+5K湦fwn+_-I&X":D!Tzm;@!;={DB9sT>0Gxxuu *zƒ[X}C=Sey-| MZ.ǝ AW͚ ZZx[SQ-ڡ~7/LL:V{0n2u3J U<`fXf9q>v'O9~Y MS@*_AKm[}ʆJw#<ۍ ,w|+*vE6eZ \UEZ?JRbh m;w仮|wJ˽ap`YE;x0z{j^dtCjzgfǨWg[训QvP[=?R6&8)DɋQU^p2 ([bW¼rnPgCo!pWP*h4]\oM2dpMcls٠^5o:^{z0ҶLeGLmt`~,2=n qe1nfբT/zmE|QXkO_c@8ҷt䳑 &By5}3mn$hmpvT\n7 > <\$dP!>I\ 0eo@)gv'f'ٴ$xGL0 Y#. a"yEҧ~L}px @ |>ZOka844>H0Ȇ8f{h[Z>DWU#5Z"۪ uO߾6oT"YȆDÀ Yi3s4g[<ɳw霪MN] ӗc[ %_F: Ulz |8 WK 3w⛣ 3})0~eﮗu9fƅxsaC6yGp7!_)Tw*E%QNEk2F`Cz\*ȇŭmC3h6Xgf"cq/+eۛ?ZmwStO:dqH9|k'la+xm|ބ ,<UVQv! 1Z$f哦-ݰ|P;TYy^Mȋ&mr掺,D,9 N-(Di;y63k84sSmZēBmH;v-a/sxu%clONuitMs<٘Z+<-o%)6;[`u:PAt|Bz>V4ĉOL(q͏[,pl͆簱5jRWUSSvݎh%-ʛ2TQaLDHYQیnp kqv>R&\UAQ6OZ`a j-ܹNU\ո2:QC]@j!Uf) SÓdY> ۠|sG.hn(YW밡Q.U 4q'hK*O.h57~ p?BWxϐ N4"VQZo|c+?8狇&֬wWӐ$&^4L;MpBb?X8#2"u(9 k|RȠs¨Q5` 艢NWD?s?vo ^}uYF5г<ԬLCAޕ[ϡssW'RNa۱<b<[[7yo$$\m҉Y{OʬhXJ\S8"s2,OLbcBKHIO_vwPY`613HJPRTw 55{7T깤8v9`z)LOBGgu("ҭljqvP%-z6BJ~ZcծU_a(#ƄEpxYDH$PF)&OJK٘v݁e=Zژ.DxK#BG,'-m)3nx6uiNsTʱa`/2Ӈ/Dq&6RJD2nySY_G!;׈nWF$r-Kg^܈vBiE͕98.Qq+!t:t)0lXV *yW(.FŘ- ̙j3(Vͽ> buތ=7iG7_MI(gV$6 -R*7c~G5oM3G7p 0}¡ڬ9·"n갫UC4VR+Й=!D0zLuci9R]m8ؗ 5ky"^9U3!źq-} a)\TM2mRfZɗVVa!pZ> ݇zƸtDJ C@,'dA]s2筬Uj8< "∺L93Ƒy/oAM L !;F_sʸy{Bs:Fƪp}bDEzq.7 LuB,OF-цX=VַQ=2*ZL3 ?baסdLh^>? @$C Oc(сy`_5yL{'DvqV_(=)(-=&".vuje6*ZV[zم?C]S(+Y6/[$Y5\QYIeY^'W S$ME0:.tDLUY}O\U^CO^\ 鼰/n٣_xQqt'[uH9l?fg݈=y836-v"Gr_A#ϚH/a*I\h_i남KdI&8X_>jOe 'oPj#X|# Uٞ2)U |{!$<M1Y( d71bSVn-uz(F32r Wy6Ϟf͜ҢO 6@+{~>_uy+qY1 0Jb_(!:L9dfiyf5Kt3պ\k UyU\W\n#Kznl^ӞrL֤Js~zT U9k 9x]1YL,\Tұ:Pcr_`;&G?TFO` (":{3{7 @@庛s, p9߉J*K\& X3`4!LEe5l٘'|u|"U|g!oYk}ǐVD0VW: B_v}2~*q?S^ceI,PesLҋBܳElBV+Vxd}J & } q:vyW)G "uz}$nK)p3PBP[&͠%}'ɔ\=OZ9>8_1+Su $ )w` =@s Cj3\c3yk^%G3d哇${k>jtjER`D_=(P1⬂D:9A+"iZzA!$ݓ\9:~x7|-ڣH/0Wa}z\=3kN-&SG X|aV(QIipRʓ.\Y)5cfjӬe<R0Ĺŋ u̳g?ȿ?Qd^1pkw]/iiG"<Oal aT%LN˓HWZOkyeGśljq6[2 botRċXdDYBG-ʧ.u&vuz%ՀOwHXBrx)46pz2rhXwrqNrI CB Gu*/d[ANgH@`B"ZF̡IXWM_pf[ɷwv؉h&W?jJIhkH{+:Ӆ1I&H*8Ʊi{B5<1.͛y-{?Go=J ȬXrA+ȋ`7^궔E>w. r~:Ea~"rk\ڲ}nq#ڔYyBsOktP|c*iߐSdLA2 ) T ?ƮiӸ>' qKc;q%kaZ$*oQVhy4|BatLiE:rZ>~5b.A)yyOk$~P\SQ\8:h<}lm3@;-Wsq}Z՗7WJ[8E ah <,q8hQPIۑ$f^.;rJqﺳ5\y'y!-q(nLrޕ'Ϛ#UtҕymT{/|HI83(O aPg0É6cuH"o򿒑pZ͛/vϩS߹i+bD_K=5 k^pA,U(t; ?mq;+uHS𝘳wz+hL U:`4xL<=> ,t`(dݷ> /@!h ocۨ.v[LmK<#::UWi,;{$ ;b?+Taܳu79ѹAdT o'ˮWa֬ $׺9Y@ hҁUi 44A7(^,:L*n82L_~nnʌfA; _xQ픺pjR&{ֹzpҒk둝pYBtCk"ڧY]'Յ"Ej.!cگpmN1",Sk'~}xgnŋQg#Wdm:`: &뽰ۮRmQ-*˂bzZ*}(Xߝ܂RQ`c* x8 qlm鶖~".^R.P,?YL bXM:Dv-M[&gkJQ଻8 1aT`o/J2yLя"Ma~[~j)^IaQzB_ X[jm} Fjd ae Y$j} ]7 .}rEa\0/<^KDa$ݭ6u ӿ+fh,JcK@^t-zM8 \zG]!iݮ %?tПZ ?a+hMyȷŪ9 R@K،FsGzdSxp4]FE3[[׏V[G\9jH8WY^ $~~hs3ymaF$04i\f嫱ol[ +Ɗp Z27",G1J"95=)Җ,ا~a1lWkˆė/^{bPDsu cHuL>Ft(  e[hz#ZًjLn҄iYYw/)D #|F3f֫7?H?=;V'&Xq2:nߦ< .&Xm?.|kZ!&jc>ZdԷᠶqO (CS1%v|Uقk˙]C4jؚ+/[@PR# t,ieZF=-h'4odȜj;hGm!i un]H0H^:SpOz1kq¨jya -b6>>1ej۱po~秏0W˴hAgkL[_2zIS3ga )ֽģ$'/o3煁_vUD #"Pz'}If:NJ(\VŐS񎟌8=`Pl{R;qγg̨_J>c:B<f5F "d^0ÀY\zo~4kܽS'#F}Do \40>K-i&И\|ޤ#f. O~A▉کE &BB:ɥĻ&ŚȽ<(oV#=V2&L(#(bUk>댓['Q&59ڝT˽ ptk>.RX!+p!}8B=:  KH=Y8oY$:X ۑ`ڹCLŁkhL3Os}A`K~wm E`9)( _Mew0.* ց)e ȿW񯕭R_kEjH)Ѐ}+9g͂<7aJ0+wSr<Oc_B<ס̯X5h&~?0 spDͰR$Pm\~X"݃LS 'Ea)- !U"dM4ob?Z`*ҝtNPfAfΦ6ayZ"04$JexcGRRI, n+‡%lݎեc(\t h/;3 S.g<T'5A.X] SZ/FfYP\ݍEus_W؍mqƶxNV?N ڄ:2Qb#(*)ɩ. >vc;_Ǯmb:. hwsMY`xވ:Ǩk7ń W_˫ekܲ(`}碇\{\,=I+#甂nJ`]Ѵӷeэ !Ao3>#Pgp0G9fd8|E*V `{F,1%OصΗs1tCQDXoW{JǛы,>dPcu *^qY\=8m'܅q]=2ŚWoKmK*4c`U <;iy&IM koj6990lRYPumx{x>.CDӀ,abjj"6i `-4H|8OKRb %39f^9ͳQ*K91C:V <HYY2t ,s(^ X|ۋ>? /0zi KѷPa&  ֖pkEm mg:W>MդٜG̻B0T [zEI4rFbj8us 3sEC b>$ќsScjq ̯$4krlK3@Wߜ'Eie}'^>*']Ur[,4З29vVۂÌh7[(ks"9 f~rnt'Ĵ:]!V:yDJU۟1IVCa$2Jkᇽ_\ !P j^M 9,z> ;Fn噙aSaNye^yL_,.֝,|o~>\ J0L2ԼNu0Kc9Oj#85s(ℋ.+W'vJ=6'rv }Zi6ϵO71ZP6!!1:ʵ :S' )5#<ȵ(tm64"dR4F >=>ӀhxA>b=HY.hsev>fp--A{.@|盇0F4%v=!2|"sq?LgW;jϾhqJ ^F> L+&aϣ0k45gqwmc]jGRQ^VhTBԕ4-h!O Nk LI=}a[SDΤ lZ|5EVqD\j'q9{|f .Zrz>nVOn{))vi-uqa}JxM٘G8ߋR΢4?3C|W``w3y]7&Zo {9 @ j 9@QK57v)$#"#D5>l/'g> bz:r02반!:nN] Q 0Ap@$WySwV w a.%rp G{PU/ۡa-!˷w.dqLl% >tuMGZtxjtpB`:d{gy_xȉD(t#`KI؞ù(Ltw2r'Z #8nAHtft̯4Cޤ5ުRF^V$an?`4B)ydmŷ[5 ~Ysњ^`n*J(2:˯䐎m1_BeizJ}Mk~7€%Hњ{%niP2yҒ?SgBz5X,58&VYD]/  3ָ;m%NݪVԪp] Uc ^FQ޴jKG?B~H5W d淞Gu>S<dž !{<.ߦh{֖0Q~PXv&Fn^=@ICdԕ4 Q[`vډ0vTAy.y `;S#eFc~Q:F-fw̹m*׆t$w!톨1sj+~M|M]l&+;^eSs졢u GsZlĹN7"?K߇E "gB\ƕP7&࢐v U::jbu(}IzaM5.$XuZLN3A=a;%n"=dP;*)g?|"0t»ܓas-2YpdO֬TO#9㜒'#"XgCUqxÄ= {i]2~c%L%]h_{(uX.Qٸc$]ʡ_\hĦ~5+k<EmKgPE<`d=)ewm \-7OgyG0̥LDҒ9rYo.=Q^zs32Dv0p;b7. lY&wD{ir)$LU7TxG[l-s/jͻ^%sdngha>Uꗯ[;j]$ho; $:EeMkߒ aR5ՏG?&o$g k+ݬ&V;dT^][`I.BLoh] PƜ0o3Bqu*0.w }SNVAȳ~NLg/ ˦ʉbk FEl$u܂ҟt|Cn>XW{Y}Y'HWw,.ep'@i^$ FCE pow~B'z59ג ӆ{PTgKnz`2;by(z1V4S6HF kj7SH: nnUWGũsY:X|ryo̽Sl/ա^TsF 658M[ 2CDGjh Ae c:]qf¸Hs~4)C094?iܵOzm$#,PYnڂiS=5󁓗QL fCNVR|^ov1n0WOrڻ"ϫ0k_OYPf\Y#^I$+F_]dWY;Mgr(5)P6K ^]&&4Ewib b۟K#ZQe,^NDUdD$xdB HE)}*< +:c(ᐆY|6#hBzm:WJy[H"%S?h ˌ9HHs0ϵ\+aL2j!/<3A$~Ξr}"4ߐ4,UZ sv@w^$Y#AM9Я d, XV`mmY x&8N Cx {3s>g8Q!q[,%6Ѯyyd߳q*0jSYYB8q JNzZ~߮-rr5"/#Pr~l)y n0t N44j!is0tDxT@רwJysq5Bڇ)kw rV`ƣsSAf;=ZŦ=h^; _}CκGF ߿ 閝eC+SFsnkN{RO7!1& BVI;?Z06z[K(ɨ΋rIrzpHAl1dڡ`'N|Xz#3{WGzL^q򃥛SeXbWiƳ63Rqw;(7p%q8%@N_kΐjXoh n)ap6Iyz=BzdD6 \o @(=gvk_< L f揍}gz&fC LIxe)J!|ϢuO([<[[91p`muDCwXِDWʣȣVε}â )24 p$^ދ*w~b|)Bx;x>H`Z¹Ry'#]'E6Cڬ6 W3Idj3,U|bC|XPBjXՖzu"n( *dAV5Q, U \_6 }kEgyzxR4@~FR1\©nI@OU>%o@qvT3$կ-5:$Vh &HjNhyjBӪcZ5{V>UZ?mE1YqS}yns"7C.[ 3EkE4}.HzwL(CFF@!L |Ym6&ӠũΦ0o*Ŭ~vAVIFrp'a,JvCۺP v@9n(Gk45a,}KAۂ?&VH$#^D)?. iȫBL &ixw/hv)bd=i F^xm{'/}30NCAҗNeJq'mcΩwM:?,xe0L?/%B;))cd 8K|)j1|B2FDr5 昍(P)4L{ ^r4_U MkG c0OeG;~|]bo{\Dtś.D;EAqlatRRXĞ5;#st, Os0-`ERml +TXZl ,ݜ ӌ̮$w"ㄬ4%;QL[O/q{+[1/_'!ztN P°6g먷f׃Rm*X1qc풛;;|ks %b =4ԍC8FꘃAX;ŗIDzbD` >qe4Ȇ\ܔi)Njc[%)wVgͲX XXHŋq5hϋDUT_~2b26+%B 4YΥbas_!. W݉S)ٓM ﲭK|CkdN7 Rb `KVx\yޅo#7Ғ`2_3?ԓ 5v Y#+ $$ծ_l7۬T(&?;0n$Y['l;=l8Y%P0 lR5ܨ1x3Mv݆土lơ]Iվ7{0CwZ"yNb۫鮙?HK>!R38y 4_QV{q _Ep辈l쇴d iUnlރL"BdZ324!Pm13P>2f6\kV鐵*CΙ`(l|}dQQ USWwʷ'g-7-K V([6h!p~ h+"W{fn\,tvȴĂjNJSS|.UV~G(7`&Uu|3Ԉ~^, o{+p4~.N9#qрC跫@;Rt&Wzq [_Svm8JF +~j}:Ԡ{a7FУ,ZQO%&-5;Xû<~RL$lRz^ g &܅Ə&#"ª2wp!` *ntJTGs=ښu Y8<}Oyg¢=]":ϛTu5ng$iz3+WA7|yŧ{M|nZ@탅 RF m1(^x zkcVl]0ƬWͬr|8@(Skƛ~g5iyty)UkʨaYfo)6LGGa־i:lavQoա}⻑HF3Pq ~7vNVqkMAbGgNP!԰P*h1T>sErJ Pkd{&5EPA^btG}14nS"+^љCN|z֩$WC ] xq._c=2'^ MɌm -4GbB^\pӵ2'Y x 'ySҁ8E.\L!Sg /{/a ;!En؏[N]Ў.;Pc_1g; [l!u%5T8 ɥ^"PO@[.6?d_ iȂ-P1S4#{iԋ(N1VzAa@,5۰dqw&m09蒤U`{ڌ3- R@lx=+ȵҮ,Tk} 3VH*N2NQ'RK;6$=_VqV$ yϨ un3D~| =qmt!{arʈG+9W?;-IJ:%q,J PLH98cI|F_zkaDRS#[Aծ%X^JfCz7C? 8Nh^,αB@*;zr}SNOw`1,zQX!+l[kxIѾͳkӲTyH >4Tu u_I"xH؞>"{}npJb*^t˔a0Ph(/( *#OoGrY#wj!=c6 l3_h2?@`U&M$A^3u>oJKo!kjr1껉0u&z9t ! 'Aty~"f`V7*;dcqfq _=֔nE]^$+p8rd1M.'e)]> # d P:fYg%4+ ڊ7ɡ f\H$E&-g^wx4el/Z1 Xp3ea n%mbdB}E /CQO0[j VЛA.ڃ#X A=F=>ղx@ۄFA6RKX\R@D *,”ph2]Cb9 qRC~3e B OՊwaN/hgDehe J:fs -b_YDS!\{ݼ),"YVr {xÙ;qR_*U1ga`qrWY3 n s9}QW?X3~8ql,V@H6>NЈK˽)Ij1Iw#yC;ƆD&%l K\п5pvt{<F Ӹn7P[fr (b  R<'OybAJY|sҥ ֱq|_}$D((ڜ"T=Nn -G7L @Q,v`;P .rP =i:JP_A SI;޼$Wt?HHxgot֊L m:6TmVMnZ6lc{(k.K#z])0 :}3+h3xF gM|a YA&ddMU[PF(8fz~9#i6砞i{4 f"MEG d2A]fD{.wixH0mx9~Є z0V0MmnHb3164mL O N1g7Җ9sq/UT^cKag% vS5J GLBJ $6D|5A?ZLcCd9o!y>yևG֤h]k?DU4 ӑZoV6͓eR*0oBTaq /F6Tۡ(5U>]vljK#<0!vIXcӑvj,k Ag<$iv¶4Gtד@/䇾2O-A]^CH!kF@P#1SPxb;^vTsDG |ᵔWC`*{F5ۑyȓwWu_~9qQ1ƌ׻(=&C`>7| l% Te24ÿK Js4# [yH|>p(Dǖ8r[S1ZB(g4`S'_V=zdqo" j8]EN%` -N:{Hj0_Rgh0L3Xsk 3K`EВ̂nVbbG4|>!Q)t8> E_Rj,ƥ m!b9 i +CS?3PDm~d{Ni$lX- rJ@@#yة /{4ZHA~YchvLrJi1N)ʶ z`Z{&O6' NTYʇEi^Y3\ 0@pU[T2\+"EdI MIFW{,M9i'/+5l,PeqcvOj=e`K+GzJP=Mq3챽 v>('PIMa'W9[Y{:0(!n|n%pʕ$ 8/!}4!ϕAuaQiGPќ1DQل,NˆI0_#xz$bm{(ym$ځzYL:9l`;+N(!Q?63]uʥ,Cm8*}dw#9PSt˥v". S <,sA=-&X~od&,p3QvzZYw "k[0-"BxPQ'f eH:S9`@*}2K#v~= CN{>{k^"f()QQW=3<;2)"e@).-1JcsN8t˨K?ӈ?T~O8ъdZ,L HLA[SSGE-ciɂ5¹'dn@N ȝiiٯkfq\p,=~-'˂E(K,e3`n`51VP`U~M)>&Kc㘻7s8P>^="1'p֓q+ }s4M+p^8Bfz8]f'gCN}Tz-9H{|Nr2d'&SlN?BPh9k̥XyrQVl!$W ⒤OBqX">Wch+Hru,ԗMY @'o%x~ |ub:fJO=S:+vޤ[|r.f7(_7QI!t=&lnXQSERPɸ3Bw* zrGGisOw`U@uŊ+M(T8[oס I;)0/?$b#|p`ÂcuBr҆WDvE(AxA}w2a_ ҍwlh#T޻yH 2;ޭa;Ҭ #ױ[)9s"4OG?NysRnwn"v{#Է3 5c?bRr1s-FhZAQ:]Ut.ް}^ 'qI(?#%J鬑 Dyq}G Y\r}ҧ 9䏂΀:̹Z7n8i ckzӽ.ޮ㪳j ֣>=1'YF<أSĪi8"`­20K+*ߓ_9Lu""y ~p ƯK/aFsCZ㫖F|צ;B"ՎIgLϻ[Ht4|D*$p.îGmwFӂ9|hh-SGu;eQ*T9AU.:ߣ&_u0:?ؔ_M)V)Ilԯ 1[hx"r:`>jRZ=K0rFtZ\"lH'Q;i.u%\PnY.H3*Csd܄G>c&ʼn!T9GggE1 [7Ni%]XR@qbUsPXĴkz]»o*"Ƈ1t)UIߜ}ڄks_DNvuKLR-To<7HUGh&FA1V)*C [ W V̈eI b@D hmPi7lf%$Kp ۅP2G-p?_%zYߧ m*c=/tNo|G1;[G-h,Xq0pϣwIÁ6[}ުm9jM$᷺JcKpF(՞ՋdT V$!۔4/J.x 4<u-,(~&YYY\v~E/; uUoԄ~c=suwT9\/]|Wa>lsA-+%p؂$t37Ӣ k:AA0^.%}u,/h󨶑 @T‘k]o;tܟ?~qb跄 Oc6+x[*oqe yePpz-ʻmVE|2lR']W3 K6T[Q*6-,ꮵ{'ӧie:E2RX$W(.qEѕ /E/ ,]Ū u5RW".HJK?>Gy:k-!レ6[1k7|zGDs` bE6vA#{ZQ{ޛgLnb3jrE5X*>zz'1f[YU/6x5g/a 8})]/x <ox#4z"'$,}cl-{/_ 8L9!l0`[XU'@|/sy| #N{>cVԀ(B7swprÂu@z~;"lԺ"ܩ_t 4x\G37=gLCĞ7!Cԩ%Joh&OEN)dznx.k3:iºG}y)r8'%-,4_#h' bUEhyPϟ0{ٜ"4=n c d _glA~ ,S'bV]wA*\4K+ra:yŚBEg48:Ohpmfe*JQuJziWb"T IpY(6j3Rf^Z_ߋx<Ii"p1Z1RTd7.m˯SI`ڥé{,[2)M"ev/)c (y2RŻq$Dk4#!; %Co7|Y׻3S@n(0ZB$twTKf$v%zyeuui'Cgq~ݒ̳Cދ]ssS!7!gWշ] @:_/6 ;O&j^Y/uA&k~8t(4+łFЕS藝$YL$GZUrb <_4'5QcO2W/uk Y23unFd\<4=D{`_tmPtdZwC<0 2ʦ<fн_z _3%"C5eD;.Ӛ/`фH7&IDPR8|cY;1Byfy?X9[n'VQO9 ܡi 1>ʥ=mWR#:8Z.Hd FҦE5YUN"ۼNbJskה(]5Po%-iKNm/m:H]i/_ά6r[])*DfΕ&LS[\)Oq[UlN&rGGa^%P# W(_r꽻u:;*هC V:5ВqRrSOP:-Z=t)A)/YMR"v|h{ 9I"i@{.  kOSy6-¶s"IyJmݹg2ݪ !Sr.$dO~\As><\@!IHg)Qpw,{|I@k g bR]Q@,[p_*'xAl|L]MKf[ 3)7&Cn I*_NJ + ^dI׍TQۯ; q#. |1Tcp~ }G}n@gIq Pޒ^N\@3MuŽtȫa r+T'Qia^¸{1榠y\K8R_AJۍQ~3jD1-AVD^S79- cƙz+$ֶ3xe SX- u3aԭR%wKDi\0-g;iSM"BӍ!57*D@ UMt3 \8$K,Q%8I7%Gdq)0Lu]x, 1f i ReOIH;8 ޒU`\;+-c%*D` 6OY>|um ]j\ʤ{nMHJTePN b+p׻XA af}) {b)XмY+PhQ)Xmv˱7/J^Blڇ_[U iWFj]R><>זu/l93nѴģ*ώd{dU׼SBU^lu1H+|f_gL3e<0!XW0Ud N_dɮ|uT=]?m:ӧ8s/w!gEۖ_(S:Io~~; O:o,QNր 2 Te;!*%HL4{Xt8Nr6I'8q3~.p^NQ!u~͒stȊ4Y>C >5 QeoLaKkL載$!Ծ@3ޘTJ3&B]!' Pu6  #9oIҪ+lWVfE(/HzC%'^9Z~MC+RԧϭԶ"%$9͔ kV 6IV`\mlÞ[HB_k2vMױ1r}~%_5@L‰#"ܣ[L9:)ϥ\f2 M/5uhK?眈 KzDc;mXt!NӬ-6=xs{0nLu ^soM%|Xô4[5#vs.e&rf:gb""1_+p^5!gzB(U҂* _Y41xp>qPC7:(-!hrC[{"FcZy: d `HBn㾨iˆ`؃[^ϻpE q\UX&ZzwG߁um)п)3IZǖ N}ג%\h $imAnxIH斔i|JC@+"Vhv(7t8x+Y*~R2tJo7~VC!vѱqDzp $A˟#9! :yUjʲ $}1HOάrM"s޹Tk6g8)x5 )nPvhiܧPƄ32^6L*bб1c!NvMfxPp rX3c2z?zT0ʼHa$P%2W]ܱ7QbvuOFU2y;&Jc;NZ݅IM՛>)foz:X kM?RKBwקdz9츔hnW~e @6Po# .qz;Bo'ڴOB"aaPI"clnj(1\2fXQd3 ~9.c5Ih;m_ŕo+I~օj41`,L IдGf8H`?ws#V;N kxDWv.J?'ˇ-&t\6 W$c4W4Ot$C)Io[2ݟ;CcXfl*fODG'U@iw.D*IxL&V;ے b0NBՖ[:J kY=xNᛌFDxB7GI.SUr:"W"\b p?4ʼnt~Uޜ%K!4Gb);k!x 7P ]UyN!.' C~UvlgfVBzRԶ bLs8„fl !>:]]NtɈhros>Lzx8ut=Na^ _M/m~]͈a3A*hkqW[YFœaSEϣQqVL^Pv6+;vbQab5̤KayP"w+Os_w>I2w- *$ )\Cr+;UuUt4OKR  t!XK> ~JNC>0ByA??T&2nOjItXzǾT-̚UWYe^)TXbwZhxIQpv菛<_~`b;(A.jӰ+ ;yUm!Ѻ,/I`I' D݋TsW]AxejEr}J}PA\v+QPC3HtǭĞv1s&d],P+~.'6uv~0(ׄ;v}?O,Xu^^/Tz}z!OdOr'!K"뚤|dp.2&"|/f6{xy 3/ǽ.'ŎkXnS͝nXnl^whqdsMXNmM[WRw~y|Gp6 '?хF .ՏG)`~]tDSɢ3:UO.)- EQcL fAWS#~Gx'z eC6!溼3} 児fMN%A 0 L^7wvxb38*7Q&8G2xD[ԼƂ^*G죅>d]uvV/ڰdGL81̅!?4Ćn@6~K&,~BH$PSZ\8qEo✐NyBrM_#:2# ~ g[Qǐ5,a6jh˻y,oUf 0MW쉈:]2I%?UCCM 8nuFm5JEIg _mXJ7Q%x\qMKEޜApRXj)9%ϦTQ!JqC|"dug_{H|AolYqƢP0pcb.rs$B(X~Ex[^b߭ҖCk+'hYȂW0y#zY70K7;`8~b/hFx J{G{KKwCT Xݚn= I!|<] qJ#[9;/u0u#|]ux4.ANl)2>+ eڏF+/ʦ!;BdF9cOz7ǚsG*xJ#5xvq)NªTmtGy?IPp4է=1c?Jm{WVG6Y(әb& <q;8:W2+._!SZLa:1sɐq9~ƃ%ۚ4[ϬLr obȟT1ٻ(ǍGJmmS-j qX^9tx_{e9tB%R6H7 kܱ{ixrjB&x[)N̊7C m2"hqиkR]*%m{=.{IypfŔ C4_yQ IYU#EA"A/;TH6˄M4Xqd}j)^؞C3*G>+ypn=1..uƥ̊ Wd}t(",?UA)wYg4ٰ͆j3i_Ђ V>bJWb 'x_S40%dpPO+^@ϋ>WÖ#\:"WS*{DҢ(0~)10L~|W4a+kv2p㥓t@s[/— v$5!I1IoAXT3St;<`Q Fd ^Ȋb,&{1a5{˩iEej 7w@L i<֜ZaV]J)[b||dr{b3}XZ{P'F#!kN1Mĝ켧f8kA^YlEiZq}sLCg=>8Kc91`,:z(wPk_ݘ]͹i[Q[-U'7a-1`ΚZ t-ؗZL{s !T,@n5{#eՎ7\~3YP w~1rj/\$еc9T'k5}K4_mK"ZЎzm:t+WŶ'As^]^q@L`.*,njkx Ucڵ)_[M{eOVpӳ ot`˼zHf3l&LJ?!*HW)Y/m,; 7Vt|omI!}%V6 ٌ5Uy_ Z( nP j(J* `D\q8 BA?%Tm\}jv5_ȑ婀\ Vf1-Q##Uw4:̾N9LI) =!5?'|Q$R=b,3Ջ g(nz02G޹# Ť5k0܏đ$;ކm53k5|زlkULHB@d?i2%}! Κr3V)oxmpֽ:ў*\vWjyEol7E!#mcmjNsq;7aԻY ϗr^,[)H:#;ܭrϻsrXABno r/?\SC)Ox<S"͞\@<|av )H'Vo:aQzۥX:h@9 DE H?/r r G Ǩu*Pef 5>(ȩe4P3{S;{UE& O8gF-|R_gHELԳW@,_9[39u.X\BLdُĩ+GnLoНۜ hBM{ h{!G!SoBeSu\@p;5{һ+dۇil' XmB~mN3cy/ql3NPhAii?r~zȆŵXs-S"Kyz#qB1U/W.:یJgnz,B/D^sH8'gk/=r:*XNRR4k3 $e@ Miw&oDg9ڇ3ar LzE ׃! H?`6>sѴo !#l)y 9Z?P8i2c:n7%~qz%U kܻ-=2"99p(Ddwl壳'nK<ʹG3S(V X:cr?JĮ os 8W6;4? ṵ=S]H|7{2z.M/BaxyEC?D )A@"RGB~՗8;/#ܱv#z(?˯tٕDҎס)B/3ho#F#9*_W#Idȃٔ |0 dwl"[(vj1AI> vA_h \*نG: f:qm@nY'?Lkph@l&K#IO&!v8[,ֈ)bz*|#OY+z@id\"ﱓfP+.{CǍu, o%aMaM3ndW/Q<=0~xg6rQVs1yﴊĮ Zmd#?a&r:XHʯ(iP|+mjz=O,)KU@f"&Q7 `t,H9C76A_;}}n㴫FĪX GnzIJk3iVF1ݶ'S}RP\) ~{f_߄!dQ%18>hN/%z?m!xqp˷ *(/X<8 't<]xwn0HauC*֧( ]x&&|jTâ@c~Ә힠ţAdDpR5yelGUr+"!sQ@Ds;[@+WkdFJxwpY!LQ' ^9{f͵G̚ ܜ0hf Yz~;ſ~ii&->KůxO.A[оϲpBo&&"PN \N&qNhBouP#sU3v<%s<%ByLyrzђG=$qgJ3wKkc{蟊J6XO c)mb!zDԘ$In7vcVEqp_c|bJb;tyJTjaQT鹓Y!ŕ;B4Rxzۗ*0hM0qt)[(iyfn+fOv{{0I4>3'3O"%v/ wl 'X)Q^Tq~KU+TgDv><„Zc4G Zm$b`zgZ\$,UȾ,vS&Zƞ Ɍ$8s" :vH-6QO~ bc'G8RiUGR|dp;Ơ- ]ݕ*x26] &Qs_/D$9 Dx T$,<5ޖv*Q^5LL~~ D>_G wGod6'dѡ6(HRBbթ ̻<Cю@>e: }MXF6n:y_1e,r*<P eDm冐þ:AǨmbecg'eclj &3+hlq֕5 gwIn[rcS#͘.̨D(8dȁf-B; j}ޏStA7@=,pd_hto &#zg1Ta/_5ۘl0<}kEyTb5(Fa:NazDbC4p. , 1k]2j1LCS嶧"YO@n(?$ϯz8; %5&,HFZ VT XGd5~H( EÖfےi# O&?p  _>zzfLJ ewraP4PYZm9ϵ;@k&:xPkC_Đ%@ g| 2Oyӈ^!+15j8Juh,lv$>٘KN00'G:T:IB5x Ggi,qI9oTYaS-HQ|,?}ˤLŅMŠ() cK1}D ɸBZ<ۍrX =eB oJ,#+ynt_-6 \?&@d?ިPS՜C۠w!Us9M@~+,";MRoISNmR2hCN8·g@ W3˴zR`i5=*kph`(Qb(`pF|X+ 7dy&sS x  %u.ٞDZh~^BO8!nP(dwWa!ҚJ釸R˖ +~ŏe("|(읜a(@,/}}Ny5t,2ȝD}FY=cs{ŗJ~?)p{8j@R8G{@ٶ>{p+=GP o ƻy%Α&@>j^|!K/r uEzT-bR[bjZDpMZ/)8~GBhgrzK^ Dir`\2&v?jsF.ЋwOީ0\S­~T'f dDF|p.! KҶ\ךB{Qh5(v<\=n?pw[UA?kE]zCG:h5Rx?nvJVEGkuWLРt~|ΰPx+|UKKzlVɔxKډ·>GYTQ e2rsTVGsUnkM:LrwSMoSg,G "64_W<Srio:nV*+g3lj-.БhD/!G$Gj*$K{mTqj:[Tν ,y:2M J䷢t{ݘIE^yTyukݭ]rG,yunC[o1ܥ'3Kn_y}cq 6cӃ{Q'CA9wNWҥK(<Չu^/8fhѓ><rp^;0Ǿ'v2,>$n^^k|A4eMCy9B(x`ƶ\밅:k&MX6iz@(V9.J-BH 8ƉDb_Fu8xT}kONͬ"_O_xc 6h$#-0(((>V7*9. zcbX}JpށCT#ڍB>腐j -SvfN_GEvJkDƿ7%ihz#/z3'НK}gɍN{& 8c/Cˡ bF7:XAJB:%2_3Ƕ;Ba5bo&PZTfIѰ,9!չ @{3T+)\g-4% <)PK,CY1'yd-{x,U A ,:ޠ֏ҬSG* WwT븯1Ը MxdgQj)sLg6l2щwH ;m d)v5DƆ(1tZl `*,U!VG8Q6< ¹C'Pq;bרņ6!Q{Cs g%Vbh3㶚S[Nƥח }u0slƔC(`wLۖUxy}훨pj-CZ>J*\v[=0Yʗ*M$ RS&AO[҂_DF(%Xa8X'_3$R~xmpUu93TI1L/"JɩCa@x1$1@,rSN2-A;RE&3 ]"f`zix3ԀcRh(\Ut"d$%& f{ ʎS:x{h5pV?3D8fYeUYCYYz EwGHC`(ZAnY YѹQm!;n\ݿ?%~xt%pf-fQPu!3' 0S21Næq{oii5Dv@@;టPd[^+ja $͗X8.yEZrw;7FgrXk9]MP<i]^j*ju k ?O]l:n3Jbd}@r3!mw-e&* P%}RqWi TkQrQVA8&I=gQcYYB4ɄI˜{BIpšmjjyC ~rz#^U 9j~_ `~e1;NF lGxraxWw=7XR,˨1Z.mdB5,ihlRømU 2D=+HF`[!b#FS>?00=Ja/) F^F,XzH?ƴ'D9@|D~\'cc50ny¼iupBRP뉜vrD:!Yi/b} jq]L&oCE&bS[}WY}vx =,$ܦP',Dq6'Ɠդ(|3R5`wJr)vMD>o :[144:OQP " _#bGZF-_õ^*I|wք dۣQ2;{*fW#i.c1QeK owJ'C0S2]\]/t@6myEuDT{,Z6S5 q %hȶU!'C@mG ±0wE=-m<4‚";,c^]ČΎv.KP m?>aYh;X1'fDn[;uȨ0'6 SAH,rܞ}/X'2~tLtlJz@߰;v#@8agi"р';D͢p-.SbE8dw> 7ρrT^}ihdQfܞY'6@[^f2"¬[XC9 ̾ }}vc&|pldAj]mn-޴<Lv]Oh#R٠ ~Z=Syl3;G^Okn"^~So+"ۼ*8ymQG՜.Ê;ɕ :t S^i_1mBv)P J g(k( eTn>ݠq=/MtJhF}4"G" =F6*d%kB`<|2:`[&UW;ZR܈v6,Aďp(<љEjAQmlܒhZa LY)-o| )Epr8d^>H"1q3;J<ɭkWUƲhJ5bj{lCjіꅎ)phn;/[%i3saK^DA!D"rL%RIr6F& ikEi)gU,m⨀n`p_Ht/O!Hk8ɰ$ܷ{B+<3WG4ׂN[|W8Ԗ`e$p.Ju{<ۍϠ,ȂL'`8 hF^mR.1 txoMQC6TW`N{ :efN&Xx A犭pUӏ7til,6G'ꟻ_H 1_EmeHww40#Է%z0DZyQ)fxN U5GW>֘MZ[*а6&a,W0n$Z lZL˶tf@^9&l /W'i&% >s61?I|uդ)XX` !!ok|[PP|PBNUWt2-6I/u1NVN[?VZX wLU2GwTڥE"夲(']*Cێ u[R̩9ts-5brX;bDk7Wp$e -^VIy842i#us7>q= ßPrV_H cϱK2oU@c*"-! ]-pǩFO(<֡6,`X;ʼnDhRa ɾRV=D_E}G=]x_>Eݺ҂NzzBSa|waMCow"٧֩TG߸ C*2J]0h87N)`&YE ^!d˧[S**4;7Eal LЬEϳ~׋QLfx=_?٭ڲbp2^:fs{ \8.{JKd`jCA&ѡ'VK&{s>ѫ'|:=+]5G䤝ZؔPKrN`n`lPFΨ֬v/g,_nOV28*i&ȫoP,{.:)jWbH}Vj|p"ۦ()R}^Œ&_WaZ.#s?*Vc; ׯYKdFLD+c_j֏>V : 6W ǖRCkzMgV#`kFL׿{]Y;}ˢЩhO{S>gvӋNjp.<+ zr-acciBv[KH|Y&D3ZiwoR8U2'ңJNgd`'2~ gno_Gޔ^:`A;.2B|~<nld,>od;+:T1B~ZEf\0!{u'<*Q[(- {SgԮ"7;I u X\~Lƹ+YûI;Ym O;IAl&F2w֟MA|Lq`2;v…"##:ugDHT0N&,/F?U] NgDd.Cs׿sDVjdk#3S~ & ,oqJma,Uj&EPDb x>{N*:ZmS!&| u0Pb\.VmvIeG?uuJ{{]ay(nUԏ䐸^C.E43v_%H\t"r/דuW7\l@T9s |-e;bÃ[h`y#:J@ bjF9H RFzo™%ρdw:񄍮k*I/Lr!x&7> efeT]" E{Y)j[ŢYˬf6H!6?L u4xuiso$>ub]c{[SH80ESB&sAvУI ѹ o`cx_!6X`-i!>Urxzegmp޷|@yQVr ]*ޝ~yVђW0G|͒,;boIa%2t1ן8HM:48G{_];?5220Pv-F7'N:BUC^U*eѧw3F$*CS)ξ݀-.~C[+RڭIuC! Wn2 +j5y2]< rh)zmhҪce9 "u2bSA{i^mN.u 5 kYϑ!rbG3 a{U5g&]]'F%؇` N5HR(%s 6t|1mg 1tkW1OrIP[UVahuq8Gџt%Z~Vɨ>A`G8+iR*S3zbMg*5f Kn0(CL(#]ӝts]ak㷛VK2[(J lϨd"yHT +>#'=һ_'t_pڋd];0O6 9U;knsЙ]Įѐ#NAq0 %xWE4,H %]XDJp(ACr0<VR h7 y,(vJYzfgdܥ藴h8sȃ W[(?ij;`ҡc`d)婍mɃ xWy>Ę(̈旷Np9R&jg'TcS1+`k[V*GR7p:*I3}rѽ9:~[s~ e1fdk1YكB ]րdBhs.gCt3ES0kTkyVшA )@5Q7NBq=^a`1q1ϩK~; XB?hr\x+k+(?!l_rň;2@Å72h(wvBQ" h Wn(tgZĖe!j͕&Dgerָ(Չ4g1Īx2dQϋ[0n1"0NKUe8WlBq]ZBv馼5X#ZWEI/&ȝXҍvS5 c_"бYBr;NWxYrMXyׂH~17RZ2+6NhVe"H&UE0֡.1yK,7/7+Cga*abc,= *\S3Dzˀp|MXU>Z'|Ux_`&݋$bYoԐ*X'++?-e ކFX ^v6M1T#8zZb@OཱྀC8O4ͲszVa#}Uf7=l?3c~=hG k6->^w9~"9RgL0SN]dtU%_+Kℎ! }\S O˪$VVoǞIb{t(G꿋㘮M0si<.Am/ >0MbP';C%nO(jLkbcE+.zg,xl^|M,s*iЕͯfV88P,!s9la.tAlotkXnD,pװsS_TUi|UrF9]O`:sM0!ZIϴO3_ALF %mUiлt]-uUFr#ŝ5 I##R[*U`;n-DByg7WU.Bj@ٯn⠚n` 2ڱ2Ov3yÃ57i'GvN *k:3UGpP`OVq/퇥(Ohx8x]aB?aF> uw-+c(EC^(2orweMN޾|>|픫?8Eŀh$V dЙ$"}NP?B1)bCA_8?Q8d.v0UFL;.sI&OIE8-yhseD-gly?P"~zsGtgnlaU`u';k9BQ}=~Υ$8]EcaOԧ pv:>Qlg$gEȹ޷Ӝda^W'ݐf6} &$~BfXPAU>nNmu]z43|§NR-Uz8;lΪC2ܿa'Pc8KW3T[@s (Ц4 < Iԛt.ؒ*|:^Ġ㾗QvqD {q%v9/^,_1qpgrum Yl`>U3?}˧@(g2<ʜ'AGL95_ =kwUR%(/bY u1J,$C"||}?,]#3 TCiΊ2n _<&L҉84L<ւؽljkC/7NR"f944ɤ;o,tR0W~M"tOZ-%\`6=0fVv5=}fɜb)0faʞTF*Շa7KԼPV)ċD&/HY؊ x:&zmTaB*q# W%ۂm0 1+'ҚQ N<,4WƸS6BxAx?^CϿ$UAxioB8?JVh NOq Jy!( VS%Pbt4K: " Y%Nx{J4')K?-l1S:wuv}ZITwX=_=NاwձF6 ࿏CM5u{ XS:t@ۤ&k_wdGqgd` T+j!oSSN݅^u뀒l0 Ϟ[mk6s E U~3paJ#8۷YCJiRJ-YF&Sc +9ЍN2?p+ 6>;lq zB w}>^^҇oR #T?+7Q0>C>3X{T3_;UYKH7r%1YJ)ſc/@MYQ򣆊~bST%c6T듧lq$.w{6,l4ų^ (C~T-Z6T3%_h|ެ>q ؐ1MZT@mP埂fu88*/ o;?o>vK\׏)6]l| O:>!eSSQ_DI (Z~椋t'%&c/xdcX |Fyv6ـbWosw.fq]!mWJAMAяe;"i-InqQZNwzcDJn J̛J$Cب0$K@H;dZڅD+|giYKmh qs?c򖲄zƳ;-φRWdigdFE!]]fXN#!NAxr6At_M3ɘ'1AW|0Ifϻ،!c[=HI=ʡjʘ@5&𥉶2}~J ྿YKZέ)C|3A7hەTd:۹;γSD#QNluQ>{p]-,_L}bNQ9Z8woT͂5,1#;_|ĆިQzZR&|#$pۇsehSIJ[h׉MO&q#ckěk*R+]LaPKƺ+ ֵk+iy٬ee~d̘F' Du\ƔY4&d\:\f8vya<f Wu2 ]Ed@L_ˀbhD?ݱSlb d^CAZܜ<,.Ѓ(~PKԀlW`Lf>//ܯ_Z{]_! npP/akq$h"D$l,:8ޚ\UK ?_31g~U 8f5$R=h7b6=!Tٝ}@^`X9yeR%WhDBumQ;kB&*G n)D ڽZ{45`4AEݱ uG $dpr~Hj:pXHOuÆDdعuڹ͑uj;Wavl14d*87A@}娲KL2ꍲ81>*Vt׏ Y: ׮!ϐ8*/Vl;!67Va$U3N\I .TA)%jH!$?ZŶv4X(~MS}>sIgq)C?15+a|\G maO`Y{F];:S3v偠2#.Կ]p|iv[!A9B$]OBa@ SIb'~9]1Gps{wFCUsygZ|:L;Bę&BM@J37{]0Ylzve\_uC {u[]%5p_m&C y;~8«SkT8:Nbgl:~qc{#j1c쎮E= Wߴmf"_7_f3G~O'`9|=eo̽;:Qo74#:P?x`JZ,gxkT?mzjڍbnQr9X4c,0"olPp*_Iq/O*_}\ c+Nu(Í9G.mW> ފ:hHV$i7X͐ki ڈh)&3+р:ϹnzqYW*߿<,+7lH`h\JSF7ԘOx`ъ> 7DIV]&y7A@ C7ablJ:4S>{ 8lځqȥCwӹe+᫅vre vNQ%9(NƫE}k;AHc|; #$*pnG`K|> {Է4B @-X6LPL@Xh T{&Zţ&'$Cgfso*W(n*RNo|yT0x7Ha:6gTzUKt?*xO;?̺`Q@!!g5FjT 6.W÷LV83.a.(^e[?Q4gwvvҺOM; lS¨f9v}oHq鱷L/[+1 W(3r>^$eC>cd 50ը+w,7zN.Q߭T۹,% (H#`6ԖI6T !CT]ގr?Vr?,p~hVfv`}{񐃹,;)e'hI+Epv{`ݟF&R۬իr,VC(0Y/Z/fE ]DiIt as2n:hHx"ękhgiyG(b]0]*r0L}2W4O4D&ye,>HBoLot PĭNŔW43-YAТR6e/bY3~."x}_@vs hO=B3eGyzO#~dy3Pշ2V"d+HH>(nj? 7]`OMRҳ <M*pE3o;pD>޴?ПQm-RNW3v/*5q^,5fB=x9k!!;k~dAmOҪeyeXn4ݏ_ M3*T@Fv_KMI9|D ̸~Pob=3/_PG0$Xddt* I#"L/M!m& 4EwڮhTm&f3R{E([7~t; _<ɉYFYAՁ;ȤƼ1ugKw5 yG{ <ϟV{yf[JUE4yrQh):/x ¾PI_MZKP*FZjr~֕¸7U Nfw.*z-6pRSgZEϮNϦOLb\~EpلpWN&Bl XRPa2Ly&q< '׎-@pKHxN]f](q3-{s aH,I} f {})J=i=_.Vymf,5 fS?Rl.gk`|:eګJD*ւ]dok(خ;$3"/9aI_,0s,:b+lݱZ1‚1Ygc:]WcP%qtSJEn:Hqߏ |A9;C4И[cn&@We$҂QЩ+;9Uu0o^~~GPl`µ 48"M׶6T-Cdu&LÐXJjWk~sG4&Pe&Yb[x-$2n=H$Xa;=QtcFwҚÿA.CEI'~6@G8К"q:|%qժ(j 9\S!&N HDTrw&biv9 D~;gdu2.AFlY}7O> )eWDl1eC Өgƈ4V=&!0ST=rg57Cz,}؍e,:Q33!K#9KTŏW묟{P+) 2* ݽwrQipfbG~G)jD20&hM l0*: 8v͟0Hߤ~F =.((b۟Wy R7C3a qpr@Jc47nKm߬m4D_6pG9Bp%=6M*8cQ=$/nkp c$JZR5+@ K@P\ՙz/-??R˨[{>Vn'mn{Zo ̳T;-i|L7NoaJѥ܀5+ 1.s.#!-eo)Tn\qoܨp|#Juxf|X(B/S&GXW.UVKc.BeU(ۭY/Oo2g䤙عVL?EOvJE~jv.H)\iiG8Çsq jp==-9SNkV?y"Yv0}zoy18h1lUÎp <1;~ ]ԭGՕȣڠv,ѣULyڵ4>1pT |Hè ; y, CǴyG)IkoP{ksA@DZ ž|󠈷vPi$v/uAxXLp_rX>.GG>X ,j5]Ee+C7,q5CR^n"%+ӶqofMٙ/ê2|SOx+ ޱ &KvAZQP_H;ueFwwKuHt5TʞDUg,<ڒ#KoZl1Hg̹ܐ`3oBoVՂ[pλ&x?Q_=bD Fx_yѽ==PG2ma5ݯ R[e dWnV#oB 8Pm7]BdCPH@fHغ7Z,[;呖Yp4Nj_J`Z*qWUPi3)# ĐbTu8{s:FM?lľ5G.awfO0aOKd/ |CB>0[}- 4jދRE(ZR{&Ntgc53ԓY0V/c- Ԓqʇ[ӡ]_YY!+pG%ǎuNCuԥ}~B`R(^rDo>K\d;R0 编S6E$ ?pҽpnGql C7j#-[jx*\ +ŃKTcPV/CHƄO텪5/B~qW4 Խm^S}¬6b`¤WupiP67} "c jxn3$_6e|tvCQX.Qj^ҁGJ Vb&7pMP5.Ato6}DK'F4^SpC۰j"5J?QpL&'众FXvlTKVܦPV%4FI4{R{*H8J5#Q섞y<ᜑ?:0+ORqۯ7k4;g!fd?Sui(zљѤ iܑwN!Nff'0-փD()hGzPg%~`۞fS_}Apz#d[Ha@%7_[(=$L9ig՗kl2lтReg>u0ѓ!B4]{meflRqxԚP3ovG Kk䖈t׏K<׊cs[sb09U3Ģu5|>U%X&7k(/$1T+v&,4y0!ZiG RM pOWPF(9#ʶК +PODi,ᆌ%PRϽbbAl*klhë]4G}lK%Kw%!ڎ>#YV6ch=X~wm;Wt6Qm iT}@WvwЭ}מdkΕ ~|7aO1Xj_g`ކxN]$R42 0Iy^0ݯ3}7<C) ;fjk 63YwutNW7! "RGu?bD)bT,5b 1ޜʎe{ab`W&GHU{),Q71d1ĬkOrxW RD718*YOT>XΧdou=ڄ8 fpo<+]Zs[+#q xEq2XR#pxB$ eKYjxˌ6yKz10Մ"HK*ٿ}ydubv|%h`oh% uS:8X^P{!Jt"6$C(pqv'I JMKM~ѫN&!/b5(yNNxd;x.pvv( )aGaL{͊H[<'ya(_ﴝ.a DuK'!JY]d9!kw1xZ^HHC>~I>H5( gq3T;RBO@!V)iyj|;K y|R4k_Nq_cN0<֋raJ`CZs$Wϼ-PK Zsb"LtC?;PmL$3t`T[6grtn4QTܐaN$Ŀ-چl.@5+E# z= >5^CUck]FDaݹqĺALaTCүl%IkhЯs[8ߖȿXij'Z✎gՠ/Arfr\]4];^VjDh!=ZcYz8 Yϕ9:#k hln?ЛҤEX[:W0=V. 0hHhtKZ&O%`tv}׉WH`pnuK?执hXI/L 6qɇ(<Sf3O$\%XY&08JKEzCNV[= L"W]R2OIfW~&_&T% K_mUŁs5pvk_)|F7"iL+:Fwfg3lK0 ~mKA;.5fJ9?[r$,l dfJsm k$Je.qg֌ܚ"j!faR W;=)0o 9_?pi'fvGmhN5=څ@ Y[Npj]i{1톚St'"QDve o6n6/$*+)ʢ1Y Y$lfi)DqJdմJs}HϚ#AO8+LpF:PG0:<Xg0^Lsq=uGnc7 qdr7|[ڽԦo4Х)FHx0:nR4۾jn~9;-MFI0rmܒQx8Uh %\JB POe-XASQ^ų-u%FaDalwB&U3L‰,?_ݫ9g4/9ίz#W ';Gl f?sǹ!BWzO/BfdA͝jO#ѻl6dn)_\8Ub陲Os)Y<=T.8†V2mgZgACǂ\<ae{. 7N߻F$ 劻nPyb5X;@="ӑa&EXԎؾ%d=(б.u3̨ OKaۇFT4,~((|{*ϰHY|ocŴ ؍hݙ,o9A =:Jl9B_Ǘat_0Do**rOG ґO)4d݂dv@/e̊kjAp~Dvv l @'"%@sGCr+}J{γ)]$j}8 @@ZK'LyN붥f+|ˑ0gYY&֫B9k/vH<8"&m/uzbajVrKRP Jռ;δxN*x$DZcĘv%XKaEsO, s^L Q5ifW ^J8ڂKOh}A 4{`eg7 לܻ~-tRmGX 6|f5G_!ګr̓ѡ )K͋z71x(gwBi=Ǹ{2t4vGG $i|Ftgy1=`Dq3'\pCt[By/)%4Y=tM{d!7tKWT2"!J,A]%:o؂51 gHV1F H(?_ڸDVirJ<\`N\-1{4!wG[)v]އ!8vPV j(aHG&_x'$""b>XO<+{ZXV9)t@/LaޡS (ռ'wv/*K+N1ĸlCk{1 ESX؂*@ofj4?61TPպ2 ہDj״G ^uY}"m0p K|vPaƖ>ؕV 1[Ssaϼ)q6ȥ/X̳u~wYxVku1L,jdG`A;#.u0W5 9OĀeZBI#5jgdTcg܇̎yBѥ2x$y[40{J qQ|D@ʒdr1_/9N'T-b:jjUaCBJ3)X A p l''=FA'-A`k(zB%7G'F#@Zڮp4CO/:!M[[~"n4>A<śy„$ŭsuߑ٧Hq%a:%$|H=MY<=ؖ(j "ninWld 蒹.紙n Yvث {W1-6KS{qd H\HQ%kR>`* %Ca?\0dB[:d5A(kR7N]Gh1bKnnzX[4m59j4wmHu6g_݋SЅx`d8Y',Ax+JWP9K `yTC~'^.wa!7mZdEdJ $P :Bs״5{!R kF++zB@?T2wt`y&ZY,T@pDHoP£8O=,nm0qLJ;wN7pJ6{'FB:!#' h鴠u/MM7xWH1W0HD=0sw-U:`c򰩖~矟HFՉϤ$mEx7)anvѷT+(YџIbF !e4OJG i񉝢=ᬇA^L^g"vv|Gv'稛9 i}'Q&kU%'t nlw+XT|,,l[ `=%gXES1/b+$Ɨ#LQVW(2bhJDA'6DvMQ5a/^R Ӗy{F!uh'><ҧNa/T BTwχL? AQɓBu9#zʿhC%pgxhs 䨎] $ BG|lj26)!ثr:T_u)b+=&@"2NuVs.h16_ > w}р\LC9%yW^|JYhU4bV>T  k b9ZXIdž6R0қstc(aa X@ ̋~rpSO&ѥdMNI."YR\[4*S~鶹gv`/ށ$y֣@O`]7:7k mvwO)=:&5=@y6bJR6׌PAdPGszw{s!TgΥŖ'R>ЬDv}5ō_ՆWX35 !x2 H}\ԁ/Cc1<)Cfd#ɍXH~hp cc{;'rH1*Vqa[!k3V[=h}]342-0LUR!ex);˳ > SƊk*' b88# n1X֎VW{yɺ)?D&\ypA`/vaFcʏ}@=  _u$%e#c~f/§k^ycMOel(U9 -R^>o{KwH]3[Q_.7tishHg9ь2:0$ M OfSwb̍emJ*pon8lPVwsLRCK'TOܩm9qKOgu+z+y 'P91PTf|?-*b*uNqz)< Kr"AB1ǖ;=5W$@sZFrfG M;`Tѩ!wI~Ngc`c JimmI3F:2&N-\!_ G6P-Tl[lK䈜FQ[U+iZd: |{Żc}Ca]?|;iF;E>=n+$.;qO ^#!:x-UI9C̰͸([G:+^4% %gTV̺̑̚X;Zc;-W;&JrWi{g'c@}MIعF$}Mw8[br_[U}PٟbE@{X]KQR.鹪J,~RP E fxcxͧ$qG)/<>u V"w҂鼌9/bE֬]m3SQE"J~m)G,/=>̀iQeg0LTbdZ&vW9W҇25}yiD7!ɬsf6 TJnSDDCDB8~b3S#ѳ9$#4f`ZU[9,z_O&E\MJ*g ky+uI9w -&PXPQsȏ|]U!#oJ2a0Y`L?&giNٸZ.ņ*Ǝ* gkV/ qZe^y8,Amٹ?T]o\L0dq@fJK,OxB/q ϶Ӥ]sွGLzJ Ĵފ *Q|,ƥBbI[ C1`g.Ho:-J0g]g-ifE]rDagd5_9o%nbF;?F /у\V7b~Š0'*4d&DM GޘGI;z*r?g5cpyV2F{MdoKVbavdo.s0\.1wWSb.|̖N9;IuvyIrz#DX>3nh]jbsk|xf"tU)?h xEzjՏ}T>q8j"(ƀD'Fxn$.\rQ-}NP3> ۏB@LOiҝlH%S)6nUJX$b_\mbSޝ|nrK,RQXi_&p==`_=A<+5cr=K2Q#Ϸk]a},I4`eRe 8V젷7~oD`Xg[SIߏґ($}I6Yfrdaa"uDS_U.[;K%̿3>R! 4xwڰ|t3RZ/%a"< nS+R/!3d5ֲP]V':%\(|׷`;2߉ fӳBBo|v߀n~jN@%9P 5y]~Lï=ӣuOɌ8a O,]KZFdI'rE(^npH3& vDVA d&4faApަ)4j1 cos2 6Rݐ /plm DOX 5 ^Z."Eں2R3$WiOe|",P430d7󲪖3'c{t2 5.'4)CϷ?f-ƒMNln?OS#O2Bۑewgw!hI-Vb'3}>wbTBx\q}P*3d@' M_sB~42:Ҭ &E6hUk!ܯbK0Ҥ貚 GgAg)XA>+̋s7 | 5D   wM@ }q9wK6PzYzwvJ~b CѦTft]nMx `RG3/\tkq mtup 0y}kBݝ3n6K(rD6 ؟CUeW4ͦ5){Y3مGzw➙[0U\ ]}]dFkm}I;yyAXIUUAY>҃=8n (0u[_lo@·5).PTS >hF!Fik[e@1vJ+@>|7튟SPpyN6y@]H2@j6 &DGjH̙ E%=lL γ'Z ۓ-o,q E0`o -O>tW rfR.4N~4i-i7IQ`ޏp#4|CFn&0Y*8#7̌ZmF62/_.VȢ.-= 2yQo۫:r2b9yWjѐT q4@_!'āOв}B{yn8l$}Mlm%~{>`H2||rz𻮗 wu4b?0K\3kGa`!P VqI՚bsilP罀IrexNXN\"!W1O^M,v6.$)׍@l) ^!fwhJ3o2S\X0̞_2z̍'%[.DƺQyw*QqUL?zPdti}AF ;, $~1ת_T<`F066 RM,ag5c+sJ$pG)NPO`gg,ljҿU=:P|Z'wNfP^v?X{-z0p?~ O{$qQ|F(h3[cΛ+n9K(b Z>6-EnL@5i9i mqdHtfj ZQk$3?@4>`2N72;9W}0Ŏ1>ir'jM06ur.>"NJS31TI[/WEA^Q;DKSB >][OE ^KLr~Co')ǥ.+rBMjXSpL*0t/NZZA 4F*%DȭD3_gV3gqIpSN;==O$Oo׺2=EߨfӱHSte8uf0_@O}eۧx伫n#oOdZ[ƓL A-EIL9J}dX ,^ Jcj~}W jV#`;8&o'3Ԇ, >r=uF2؈ )o8x^7դg8G V~1NhypKީ(>)`hϷPj ,ĩF]hx*-S7YJa,b jli.rfƀ5"/s&qxh+>s"8 qQP±u]f>a: U>WPxnb+V T#Ly]v&jgVnT#p`~"$0 ݶx@:cSȞ& BA$G>Y:-Sw.t>&Z> 介w֬Ib1qHԞG "6iC] xZ:X{pDlĞVb Cr|x_T B-*Cu. 9=c Dm㯛^YzJЫI˷2VrR[Va wKGnB,*&2#dq |$hh%Q-3LFt vKUQj/{h۪id>`Dp>t.m~$6_\HMaM](yY|5[Whdן4s|sn!6Fo2T(bԐd;( }ay`4]ņv04?B͔8b ?9T.T' ,Uv u{AE%]l̞T%&6kDn73 pm%?^ŊZ<Ȋ-'M&)nQeT JncN=x醧<)N ,)Y}#}TWb-騌 wC XWt^wv(uc~bIGj"®qE=tnFV+YE^}g*<e,xgɳ!B߃y KdR{P !YpH\l7?;G@PE/kc$6/+0M1qJKp\ζy;BϿB[.-!,w ϩe MBadBS<{a(ڀgpQ͝y_:J0nlI͗|b d䀐Rz6YPnač*z3nm@_*߷\q䖿PuޔfӨaCQ)U}9TKt_p \<í&j/:+3N5&}$HCuuN{Ɋn^ Yb9Svfc]cKP{d Uuۼ=%cVeP5}t0!` qN8+k_BC@ϣje,c&tuOIxM'.%+WY7t) PO(:cZ9LVL"+!קO(kJ+CWE. qF*uv* ׏hok.v|]ԚT+ `{4|oO 5e\꽍zHaWf'Y5þ*SuM2O77ZN?jm`nPU>(GNy)P̪Yw؜1g>WAYKIy/(T ]8=i"S(-LgRV YG^C>nVu&1#Uj6,65kJ*IϗSMFWBw͵dg6 OWu"O{ץiBiy4RNb*^nA] S/BCJŪ l[K,<[¨::& cm\>Ultn$i8~Pm,ژ[Xpk3GҔ# m#z+Zr 63,à2nuʣ%"U*$B,*SrO*7=&H/Fc҈8?oX;~uz|!&2cwnjK+J#`}]1 ;' 1C+%w)S|W쥲rF 8O/l|c ߯EiCFQW!ZZ %0=ꎦow2{L:1e]oxRn,!_M]Ϟ"rB5%4:=ᚆgٹΕc)6}E3М<4 HW% m_^voa Ě ݹH'gS:ySe`` )!"HCYӡ0U)j+_4܌vюMcё Ua֧űHho)bЮfpmBKEq˪7K Nu^"[f&N|6!9Yh͗9WW]e;)H8u[$6Y3 %TyTM̡-(_qo翑NS H`ο@\9faꭺz|y&twbG`큏^uQc[nJZ5.03" [~欂]):AͲIS.#ޟQu[ n#UQ39ϩBWkL!`Y ̞ՃlF}>/hi")z;Y&e4;`M?"#?Ɉ%5 d5Gp)y6FE̐ ǚLdaZ\D_M߷Y܉كtZD |ZD䭣hsfNUإ=oй*4nl9!]8 % uCa4?LG!"7gFL9uKb{u=`wp:/ {FBJ48_)7{Q# qGJR=!"l]Gm@2>771uNHK#}5O>ǦK[l ~u[ꏯLztQlr~;#<XhE(_ְY8@Dx6}{b0̝(ߖ֊|΂f1ϸNtn7?E"5"4q٩*b z>*Iڵ niԾh{Y=mۊfT^E'X1 w~rzsjrKg?%%Ȩ&sr;6V) :p'p.~r1piji}LX~R?-0Gd\}K{f;S-ͽ2^}[$I.F=uJRo0Ly=d[;6\Dd0LL4J4 фQiFظI}K\یOrhY(EY@F'GREg%T&~Fzg_k@' $xUC th. pi53+auLW?tr)qo&ok;^ю0:hboI5r8l!y}ehڞزt$, ^Q@O볲>Θv9[)V2aѻ{}VحO8rK/T'} Ϲ㮙8:jAI z(bc_N|:c|E Tk+Ios"<9,^h.ao1fG첵Y~15"XL9Զ7s!tU3Tiоi̺|G9Tۓ.\~9J70኿:Tubyw0mљkSz nKvP">3wfB"#QP74Èp}fP{DKlK` |H.Q-UI:]d%#ryR6z,t 'u]g]ĵ>Re&[ `fF@̏i 2fDfk,t[8G!99==[n|`;xAM$QrX$rR63,h 4s#1FGzBϐs]Ry$-k S҉c)E Tẗ́gfa7б$KgaM5'a]1Ь΅1QSH};EoV %^#NL8p,Bb#>e޳b%3BSs-3 U'svbB#YmP\6v/љEz/7(By=9E64$DH )--k{"U}ofS x(##8ٳm_҇#wऑuWvv\#=6lBsF St߅$9v5.ꙉ1? r3@3Nx ;Nc'ޤ?I:/n5*_'TSmA($ȜGWv歗sT͎d%  ڢFi|rW,SYi:uuB\=E '=er~* T >ZXݫ5q{S;e98heCI9wwMQW25,D\ôhy-a%'V?t];@GeR_Ht7'Vpxn5+yʗu9|?Z {3-o2@k p^v%Ѱa93vWfЍ_$ZpthJUX>$>n`wP u6\ 5!zpp1gdǩ4}[y[{qg.5Iyr,yAC^.{2聣P$xr$U0l,x}:XCـSaZ#uޭ_AkGP1ECkAg&Fc*H9w+сƅQJQZ[ W DH:ͰhjlFCDbD tLo;Q&Y!Z?jauL(ttBFRmr\a]*z5/HȞӚ jvKRāBɨZfGFw%ϲFu;'0m[ 35zƥtzeO0&սVK|hl e;׌lKR5bAy hs+uQS7Ī_!e}n|qT l~w3g+t7=s- e3޻(n|q|qقQ0ckW1 垸jWo U.gi6ߏAs;-smZ,$sY7/#gH J9[bS]iT )m\qdŝ)P u5b_wH5r:/Q9'2Ke0-"">I FI$!"QWYڵ"{W[a>SkDx4ʰ07GAA_H)~3_mtݱ.>50_%iֱк"k O*pAFN Fou%/Ӗ 1|GUg4ӅG|sGeɎݍ'S;K=qgD;JN7}"e!%ArS5tQR|ϿRJåXT?NSg7d^.Wd4cԜuX)-(b'F%qL9ӹ\ LNy&q{19# ,xkǍ{qEz(B|Qt[u 1/27ct&Ck§dR// Q=q_Jvܙ:y/8LՔ&/TM;a~JwFfom$Go؟:os}Dx"%|-DTJno:],++ћ(=J Ey,< j\ŁY0s%!@Rs2$N`eaIeC,msg̸ՌQ .[DmGfNJ셭txڥ"kUM?SM78.c빍x/~M+q\˷)p ZEn9U~3۷\u*)sPnܙ-=1>*ͱjU]_D.%6jFXtLi4')'vSF!cAKk%.rrLl";`v1Lo k`Ug)R6@d޿Ovggumc44ju75a (h/2)[+J/tAģNZn+۩dr>9ڿ Q"O &ɤGBP$/4HP ysTz3{qܙk/Mob*Z~J/GhGwȓ74DF3 H0fhZ<1oGG({c봶G4: C,<7*6f :ŵٕʬ]qm@U`rgY5iX5ZO4ٻ0]?|=CSL,:oc7 1P`0`qᩚy?27G' 5;9Ӿp:nf?L?KTORLHŅRV1,({8pZgY!piL瑈e ;Q @l99;mG޼C$O%*Aa.sZqεϲx gIR[bT)acAZ : QB$eAns'ղva&+{⹘_o'a?U7ݏoקۆ;}XqWyCAFc&TQjj3C##LW4IG~=vT*9769q62v(or~xfxI$_BB"ar:;ݻ, yB$Q̐bDأ7ޅQYO! `]~z n-1 :em,[EG' +d/-oO/% F΅\X{ei&!$/C֔R m}!BvXlKF1aE m*˜)mt9?<Ɉ蟀o ~R T+3GPjEZNX_e0vH Afy]&tN&A/6B %b >kmZ;l0.F02wl$0/]iKw90Xnatm@} a+zrһ"{Tzɂ}q)r7\6*X*Z;250i)иȏkj;sH׃ Lt$gG+ .MMyɒ76 ۹EoAwM}P*ccF- w XT͞jş'Rcۙ1S~CXFmBFhP/y Z^z:| ߮GࢫP`qӫ;,yN~Rp&~VF[Y`t+ҙbٝBR[Uj->jWlj@$Vi6eǀh7⡪F(>1\[y0JKDXhv^XYu]%3UYF)jxPrh;l+Z%􌁍-"`U!f1yScpcS*d$Ur_G b~{:&ڭT/8VғxrBGߏjbj$l |B D`:I=mZZ0rn+R ^6d*%3"nYB pVV8aP.Tft7%K ͷ}A5hc6BeKX)56TkJ~\꾈T1o@*_>>!4'a%=!I;xb"nh0225B2YTvU-3/ո3"G/R&~L'%ú{T{fQкZb(BW#dko8F*lxYO/g]= ؙlGΥo1'т2C:D7Љ_az~dd_^p]*ǕB&1Aߗ0QOx& 7j+Rd F3dOVd"u^YA.@E[ ̙vVc}{p!֐ 4Ȑ$2b1Y:x*y7Q"%A`8:D]_e7l/,5[FH s:TIMl $}#uUkt'^K XWSXaa?TFBVV&([^ÝTyƺWY+A†C153x(е3Cr;Ӣn ח?GȤm$M{1%}qD m3a-z6dE:[/U , < AGK#vC~'z,{E_DBVkOvNZTA`n!l\QXW7ohDnm+5ϚdjTg'৤Ju p11rwA `xy+r±>#b⑮Rn tŀbCH~Ot6~#y b|&jCʧ≀9tۙB"D,;~\P] f#JWkBs>֗ZN JmT`RY^`C&ߊܞ^yW﫵KdQ- ںw,+="؎Gϣ3hv_S9r̯qX:/vXג;C68h8i_]Z+Ģ 가0=KNӬ~Ȃea.Za?n)Ivjc0lZ!T``dզl _LLGjM0 S>``IF˃vu0ޗm3Ԟ/'Ҽ-!!==T[X'Y:^ i3px;mIP)(;c5$kqΡolr!~Pc2츹wpcF_]|fa#lm0\>BcBՙM>f({,ߐ|EҺ=.d`6ODϨ$vf}VI]xy4BreHOpiٗ8/ZۀW,}6CAC:9.kDV|`NY82NCIζ E8bb:A+'Չߗu -sǣ7A]F`s0orz7 3<2VXGXk#- $qۑ=6x%$PpɁ*Z8a!,~EmƥFޮ?r+Il f.\*MQg8r5-uP<+VyjUT+[RWBJٿ-F/TT֕/V=4jh*:2m+hN[op%a3r,:UَKzuт/&-iw_z%`ljuXo$fL08G9+@̸:?r4P=wN*|.D?vX61*[Vˉd"KL7'Z;=-OgHLRU(U6%-r>T|Nmu*!WGDqmp J'{@gXJ;Yǚ="7bu4k[x" ߪG.BpR:`P U׸TA]q>IYvK#Vcr=.DǦxӓj"W@mEDz$@J+"Yt%>0봐<1|<!FwUO e/!6<0_k1 ekk-Nd( W-8﫮|m21sNl2gC=#Co<V1kX=x҂uRSsɼ@V @czd(" JTdačwϘ?{Z\砡i;IqՎ-ĩ,eR&tĽFj~S. َE&M)PHdk۹SFj'%B.V8imЁ\\TL%I@A0/@C ;@zf{gG4 t%9i9ypn:庂`)ϩ!AϡT FOlF , 䐼*8|)!wE{`ˡw`X@i ?~F( ܟ뒤FQI*9a˷ /Z*=/qH4[@QͰfQ^#R澧ux-uzןM-R/n.\Q4/^,Hdf͒ξT|m^q^Y/PoY3U8F303`֖M%ٷPjFY*FkfM))r>\T~:x2cYkg2S!8+݃K߁GR։Ǖa6V@@ߚtԸ}}\7뻪$UUC3Oˁ0eWJYE(-5Uu[S$g0NyTbNį `>dSm(aS9Q1>d̴24yڣ0j\< _=SnMHmEv5CI 4Л47$;5ҐFN;H @nu4È1q?sۂsC($[g$;o'@, Sr@W.󔇾BN[ oyTe&!2${T!Jќ^~3&i PV2)fCDkn:ì&io6ˆ/I >j~.j {Pެ(8R+A`'4r'yrp$nl?s۰ LYvodw0ƷnLm A#jk#,zr9g P8΢hKa=*Z)N W.-0GV\_;ޯ!,tL(-]G2S@9He X[Ƹ'Oo޾7L!1 -3;ɂQo54K?|DYRP"B+z1HU%,=ځdj$?-)&Ҽ!3+Q<: vxGZzH84</` K$4y?J k$֑c[4_ }=G.? ?@l7{BJ%wخ5Hq,vcs *LwY0chPj([e6w{XS}巙VUl깹 " F $o˳Uܾ=g\ +搩C4NTT"@_pt9gQYZF@N5/vA轳ύىbaK'Il):V ם}+Oos57BgFxM0d96{;* /S<0LVҦ7nE ̋?41Tg#5H`j)cI*u$=M0B@>kKpJrHFA͑n$:|yaAָQʮ ~FJ@<Ư j+ mԲx栰N^MuOυ\ X6VLl?ɱK2a_F+RR z[ 2i=6eƉ[`.⛤,! %g }6g]=xl2JwƜɝXX~ 0B=HQyNVv W`5"wZtV"m~+=W.~RXF6H<ҽ[lMC~!В6VCU%[1}_2A|ʍVc(`}:·!G}3jzxO_kB0 6vSi+ Oeǣ3:\t;E͝9`]yS)-d^WDQb4y7^ƃh# Rr?HY =Eh@'PnXxjeN TA||4v` +)02*ÚE*yMBvJ3]xE;Cq4+n{{1#e[[Ø+tn4GrXOCɈnFlRc8(Hv)z٪ o|H-do6v)7m#d*7#aa;;M4m%`~L!Q ϝ~gʧ/UUV R4$;>[g-+ѯkez4Ϯz9 PW"1[>qDG^gRU=\"/ |cWp=H8U0وWp :xM>шA-'eoSב2ۥdԪ&oZ%6| u&@CHk< -RVa0JSq]D}ba_7B>}.%&}7bݏxS<\\3b1;P$,:̟.Q,%#ryG ~%F/ rl[:E 62DlI?E2;TlfNP%esՊ8*Ak^gGCOb;}(aj (GXhG"j>);% V&E V+k:?yٍfbxWk\F6+tQ5/tѸ$*( <\`ߣDOvyMnG" J!7H^1Ҵ~Uw_v'E8,:d DC@<7dPH}`Pzt%if-21^1E/B*ۺÛ V(iIbVDXe|3cop$v%bU>kʻknW[vEV/ nSi.W,YEiݽ5g@ټ>ZZ`ňk hLEa~0sCԠhcHJOU6<*o[9 [9wGN/ T@[h>90FP>k9'g"7TO }LI,4-LǕݐ:+X}Z!_G(q9c(q.ImK+莊#nd}ɑE6DZ`ͷ{LG~{uy~MH|ޭo.3鱮V*E Ɩ-Oas)rP⮃u("^ZNX <$A>@m罉mg׌p6lȫXꙋDuCbX%Fjm^ kQJzu,0F*A\ })V2pp^M>E7Y3{ǵd6Ґ\EeIpC]V n'fn]!+SvKay`Wz%VO%*oqՈfYb/ ,Q/ڄ ,[Vm{I6:,V r֎*X@el;xmQj ,K hK.5^ }!?ٗ' ͵ȭj0e`'q^>|C ׎cƁeȻ56{ibv)T理!-,+)\CiqBltuy$xźdAvRx&"NnBh/=]`~=n+m|Ǿ g%/rĉ`k2 ?lds]֋.2[]":f[ A {E9#(9/2Ֆ$ H"vCe֗@l]rf̫o4 r³MQ#PvɷVګ4!υ7}?2=#̇/l=2!|_@-I':4 7`%ނ`%I4elnRLpfVE/OٞƠq7}fGfs:wHe@jDs3صD2!w=iv%^v$.tUzR0F>rcLHY0fЦ1Vk.:W$Z NTj7m03fkz~xm*).' |vpV]},Zw#0Ӫ!HPLng-'~O.ݍA x >4.Ae! WȻ,1ߔ4j+U&^E'/$aQO]p$CАĕSxP^d@2K\_vPjSvv$q}3O'cd}j DeMT(I侀^s#nfRrۚ# VI-dv* 1s}`)B tiҗv}+CN'%+c-I# `%E|pk_J;W3ǔ1cVV>ƅO:I+N 5E4CS8 u@`Gsc\ = K  ɓz?2|v;Ht'2D_~ .+?w L]='VNkW-卵mIU#eBXUa(RMHz+W'ҭ;k+kyb - ]r ::kqw>+m(}~+W9nGgz5,73A JwM ɋV-31iTsuˉ4tFr2lb7sWep;YUc*PăR{1 5OgS3o=S@/kJagA{~ʀV&N9pm,Dnn0íd çVy>UnX '4o"@!);S഑!+ۑO65?:iz0 Q րCCw$QZiS5dkw$j^S͢2Yhe2q ɯ}y1N/&2@5A\cK >f[-0{՟?.ژV^}o Z"M%+?G9C:A?w/ s(<'lG87x7d*Fx<$+L`-'n_ngK?&-m$uŮeHHѺ.rm'bcIn4#i:߸ݾߓE;wT ߖj:#ˉ`(7ELU+ldni- ]_ kUUSdfn6%IԜN1<ܛ}*wj']N]ŞtDASAh@Tf'0y<%z`̈ 0mr[ k,̅'VŞ-*'9 \\bAmSJBV,jP.ͣ^Xt&9A$NC v&tkpwl=s%E؟ HI*D[5E'rH=0kIߝJp\ngֳSSPʧT򀥼 %O&}Ӓ>G &>\&!7-?Qxu'%NbT-`bni Hk}~M@+wA < I_)$MUIr^<\λUH,cIC\&h޶vO:avZp _IAAL˽ZajQG^zVecp*:^M~@"6QpF}Q,u1%} A@j]k*Yb"7( RD3Lěແ3-x5j2-nN&_-t"zP3'W&@:1-lUn:I;ae̖ I*;u߅"fX4Kf{l'a h"(jF> 'P%0x3(tI~ >[zؠ*gK1qAYm7ƂqXa.i]%@=A*:(H4ܹ33xqD5 #nk vqgJ#TT:s4&^a%ܙ8_Am,`nglf\˾-ҮrT!wta]MBԖa/HI't`Kxd$D A =mOmWh.Ȩ9lxˊ'A# _7 wB{POG"Բ399d9#BV:-NDn9ܘj K{T۞`FfğG~vw[ZQf'4P|[r+mx4)*I\9nઌ{mD^9 `ag!#͈G 5?gsKGNǁ0*gViW>KQ VNRFqY$5@ilKlwzסcXPcMH#"P7?wKv g0hBBroFuG 2o9oT> UYSo,TάTAvr )gAw~̂Mb]Ba~/bze;Bk=r²ŴO^Hf8K!n20GrkuE:Si{sM澈ᳲukv|1cN?_" ywIϥsGO5$N$%iSE-#\ǭ"A)X&M+4PNB,5?sdEz1FA% \v rA5{ϙQڸ5 dPy69FKE1D"&[N=D4EH02ZUS2 )o| Pu^|ׄg|O7 ڗS90$|yTk8zżG>b¡Qt 9aQð_6C;xg:v+UN(rQhK *i2)H G0.mV B+7AD"?99#g&"[իdp FYJ1?y2-1bӱ[,SW+|$N"g߳!S=`j-q05)?s+4~5M5_k˷n:QPVF:F~=FrRPw ZP_}݉᢮ BچV>5–DY<&r9fYȉc$?&QI)I8^˚0ZglO\KֲEo_Ek6@Fݎ' k[UAXy"&B&]6'S0"w?)s9Y".{8ym )CPC- mn?}K-!S@lvXQs<e &h* ƚCe 3CsufuA! q -˃yˏ'lwJOn"C10t߲k-½=w4WQ7Xp+pF@#&"dJ>cT}_AӏNR(O P~pz .2I$I`-ygY6与ZXDɝl,Yd{GkW2ن+2[a񶩀?\RrjC%xvҊfLmR?/쫎?w8I|yR?.saCkATR`D_&>Oryagsp 0h0FzgH §\T#x0DDs(oJ.ֿkta=ߌ}M@={>$G|e[N:E6\:nmg++V@{J 7[Jma (K#'qBb4NıW8j(0N Gc>L=qhuP:C1e(S%_ќi q`P)I2ɖ^;S<ة3i©lrHM04@ v?5^#:*sؚz1҄ r2V474$G lG3Lx3A3סmB¡Xl0~2D@6 ZTq ~oۻPް=D=w>,5E^۝qb/^Ӓ:T{Gl,)}%x䟼V YXU>2sw XMe8~i#3b#jF3Tڌx"{2IfDMO:('x!|*XurB̊ux4-3Vu=zGCPcn[t֐`ZYcd`Uaha? KjtmG{8p8HMJ<#>qޱЩqonqUhw"oekqV/AjB}Hr<܍?ȥHUNH>fxNWv?q>nj_;q@=\oJf,h7digp*%ۆ'MeCAZjJF,}k̀JlV507J*}|ٶHtfozx3@5R8ml P[J1WAh=%kU1x\czW2Bh}Sj],EX4.Uw֎yⓤ4ƒc<ԪRjX~l9Io06!$7Nt>!}x qou~,o尳3i``gؠ=):<jS8AlVX6|Sy!$ng4Ӛel00ˆa]r a}#0b?D^ILY\Rd֠a oS7&Ym0B3۝qFNv51b̈,qN%GЃY|laXNd.sExACSrVW0;p[-@`4Ά%EU%7Tq|N @ 3\Y%N #:ej[BVW7.3d _rLh߂TYQX n5v]v!9zkf$3k=^5_o \vYLJ<9W7Pc{Tśۯzݡ;+V>f\V#-Ly]Uo|XQ eryFRX(r-rj +6C]RrR+@֓W!_.$8W&rqw\&TpRQhC^Jc6YkuðKp8zZZD_G:NCn+^ԋ:+Yvff b*˜"0ȢKcҐ"Imvs1ģ3-fXg,$R`kVV?o{ SP크XL5dCYyCmk##şk$ZE\ra[v&F2C-) M1RxW5ˌi'zZgWNK?щ~=_k!B+k̞[+ đ$]&F!fiW *_ZD<_*ot+ƽzH(2?ByncJG54oF|8X&QtHIDss6P[1ĨJe#< e J֎,KbΙ P(rx=}uLOJ& bגgL`/L##G3X,G︻|4$ssu<4Da u0pFL!9vX1#Q%3Ư !>V!WIgvCMRj]a=,[5!ܮ );"\3Q %ӺF S1#6xM!I8p)>*ˆVvde$j-i)+=pEqH!t`+-_8IN"x23n^2c^+~'qOI}7Uڜ|+]mMz~#bnZL9kƽn5_~˸?Gƚ;-`<Ê-_kB} FZHd BsB*ڡnq`N+T*cUi0"Z6L"LLrWoc<4SƀJHh;:o#=klƏ 7c\gTk#R&^ʊ!FΫ}&?%G@WZD%]Rȝ3;̎ ]K_:rVPڂq孔ڙ~ ۭXNy iZcB Ԗ}OQ':Dҙ^ߌ4y ?Xn8{5vgp'I׾![pVdͳ1P >2kwdAQƏkpN<1S8!g+BOLsۀ죴zof6;Mn뵕+8'fo /=kpM{j-Ý.Sϴm ^6$@>oNu͛TK&:ٹ/塚r5%u| \cw44pcºWxtUd})$ y ?k/lz$oKׁ.#'GܖwZ>Uk#8ΰ4غQ3Lɗᙹv21d:QŽCb$]WRU¿:#z*EoҷXLYefVV|t{2-hmh&:Q[XbP3 }-xvS)AcĢ#i S&n+Y 6&*]V``/,䶾|ŰR3_vyYKNv2I A{NV_ˆJwRD^Tϒ|Ķ|سkZXtEwc;Ӑ4Ӆ˖3:Ք:pL]RQdDU^`~Hn%+U+{/kGof2Qr2x/Cgk϶D)A[QNP=@eipгr *&7 %qc,.t>3MpdWl+pv7Imm|V$~DG ൞AZeG\v03_ƢrT /-'wD@R #N֒DNE  7]8oB8m$D;d'Ϻ 2?*&Ew!822T,+pM6#Έ ށL #Ϩ9 :]XO RTs_fxe i^I-2*Q m7"33ΰD _fq(м!ET~2Eʦinu8a6E,m$v]V[&yrN(=l٦bI#qucLB_ފɣLqZHFpm5qOд>\R-h*i5>4_zɂ~ ے\:]^Ƥ`zcS,|/TD%AhPݿz39^ɫVaɨF ( Y*wjP9ЍTV <{:r$ ?k7C/$KQc!(S1Q^ |:wNT\+o Yq=U?s&j19c4wFY q(W,J+݈w;_sshvrPe)ZWd^pB 5u ĴD1 {j!Ds|(]ZFMRrlE0!4l*BB٢bvY#CTRL݁ }\O4 mQ>1P5*CQ`ޅ/+X!U.#J$٧-zۧ~r?+e&:O\[-ay*]5 Hڼlo$Py.9@4tTn8fӐc5(ԕ+ D2a]<̈⬙.~{O7%`,orKl\QJ3a:ieǴ듖= *czQrlԡYҷ7)_h>ƎB=y> LѦ?\~XI|.۟2͙pDY2U*C϶ÑZkK,Bz墛:2䣹ȸmZLQx({ڈ3r}亵4VPsڃ8, Mi2_iF[^X+[s"m,U(`;@j? , =}+Eo*wIJs9zƾTʷ3?P?r?:[+FNup:nyѪNvo*&` [~(Jo w ÖlsӖti<į&7y ߔ߹A͋zǔp{VBaVj]:4mg|6`)%(b14d97 G9FqŴA6;RMĵD+_]GUaefnF2?$(?7&;2x4#;nwV/[J?bC2% BݬOmS4꒰دwQPX0]9A6t ^${);(r)tp gA$kͣ?q%p lL-"`R2=ݹ)6#E풔3͉0YD\˩vQ8@uȎ!Wpꛦa9vD_`FeT%Ǟlܷ*%'L n$\@MqX?xO>19mv]GleP`a'`Z7nU#PW7?` w3Ad%.6{ޥ!+ܛ.z3b iԬ!KeeF[{B4DEtZMXfVz<-Sý%/4VbqM(R* !Xj[ ŃI9dO'/y_6P=f'- % 6/o4Rf@{\ͤ=bhAwsZP3JT97 <}ziP#vA?؇PvFFQBpF' \ ,:?{B}gzbE7`iGV lj1V[r_8;׭tÛd3"#;\ |T&(Ĉw2ÔxֿbZ9Fle'Wk<)ouaV&_ Vqu$ہNH/WBBq(^i ٦8OD.T)UY};#OYSUNk\L] vM%.!;L.Dt+3CYGr!PdGl[s9BE\z*=8i2]7U]^ykMV40#/vWѨJNѸ<$CrNCbGk7 ~A$vDl}\9Q= X{2Ń^/}OKY`kF ,FfՖHBG/b%Ko ~C\~ϸǒ T=]˿ц]&n7 - aɮX䖦 T ,rPvv/L9˨B8Xq;O/mjL \7Ѽ +C牞Q@0t@L,g] Y@NXm]OKc*_5N,űb>D?Ome4I&ԁ5UV'V;Dto-+;fv1jwRVڲ"vdA7weC?MܷCX~ 6(IHU~ Jr&\R{n>YgyAjK,̼bvoڦ2Je~^:O// R[rU]`FPP9xS;˕,*q;-TiK][?bݡƌ{;1RTD*!.JP>XLx?S}tJÅb\^$-;*]##3( )7|Tk<|@2٧]}΍)͂vA# [ }(uG*t{A\ecS dTNe&-X)*65SAm.W#}Bź,&L#y h_h9W4x8/ay_%цB> t$ =[W>3'58X.*ԯ! X%>L&L~DJ.Cm@0rlh6FoU=ॿ}֒UIrMtB<,Js"9̅4}ED3mj l)~:Ty:V%+e<9r)^c7eQ=7 14<MɁv>Ȇ;uJmkS2~8>bkz$zpA>$ o0sC'LmH6';7j2.U3;WB1e5l"x˰?K].Dibn*㗚UÊB6Z 4-G}*=ۭ=E x++D$2v $֯ \{ػd i$;=Pd1][_+:ZOYv(XD ˹.w%4;@朲.FncmOxn:L ()2+&M@UAR{l1jah@E `:h hV3j>8гӑձ~b84# IX;Q|:ՏS7kǠ\qL"ow@\!|NI]1(!g}-bl;B_ ܤ'~J?riӞ#gпí*'EK `$Zh, rGɽ0⋙RyE(r *S7ty fLHY̑S -z6i-7~p i[h*ԔuX8aul,r.&s,cem AJ8l"mk,W3<8L$T;yiwU/q|tp;$FvNzmµ 2!o%p D/ UȈWkp@hgѬV `Z~&|7FqrD٥0Rk2Phh9yv{͚9xv9ʩݴiR2_}r=(?b1~v;Aql@*5nHe]$CrfEqǭd\\BcYhrL MŊlGmVZ0rIWSIf_z[4ʎAV'{qhc܁ V)v)q;.~`:qMumN}-ڗBK۱0(aJo<jn7Zh;ALwQM=A̹%'Ϊ2O'LS 8ƈSbbhIƚyk5SxC6,JBg~ ޼0#^R?y.dmᖝAPфHZ` 0 ˟Gu폄ɋo$l nՁ@0&@|75͇73sԶ!&Lޛ Vl1`mɸ4BVto)Lp446+2<ֳhce,.}l)͜Bw.$ 9sK(S; &*Ţk%oV:[z#7D3(&ufj'㕢y3ECiNszc4XhTNέI׻U\SV#ֵ ' , ;U*>RgWUE9^pg .y5n ф~ 9ӯ\u ˽H-5w so/)ƶ "X.)-Mqa'"2ﬡ"P27b`r%tvP :S=r%tOY PK7.~$?\ue䒓eh?K"qJzuHSGʹ/ŃaA#B#[!gq4u *ce{̦ʠXGΔMb6!/{n#3R8?rᅳ\ޚ1B֮VQx!"9t! oM .~!EF4Ԧʉ;;w AB܈<脇\ց [6KMSCغ%׾7T8$dҏ2!z 6p;D "(&JUBX)*Sk}ղo41H$<ٔ}~Ekރӂ7֡aɜLE$3Yb1Y'4$•5E1H /e*}[M};Cd$ yw>(tRCaXSeQkDH0ڶgy b0R?',Whp-D-!gD;(J03uAsgLXwk>a*ʎ$ RÍ%0^Sg "8:K,h"\A&Cw8^;\α"6Zp167zIP-]'uvb)K6g[3>t+&5o<if YFkJm~迬6Qwroϴ[_>? ̌o`3 "*SS]0 !몘 )-Bގ>Z{ĭr8/{&ۿ`p;z$qOq:h5UN _uLǍ^ہpzN%UB34Ԇ_ՃV[h洢d+)- ,Vg VHȱ }χ4l,fC&~prr& 0 pn":rf:~ɑS ۠v~hW=&C7TNKH#Zr [ZDW|)b4|Alǔd6B`spcځn^X BVfNŴ("n~+@uIm>ggnS3?0a5ܝqLΒ{7r7SV @,kڨ8`&M``W(YMJRttslkppZ+Kl@ר^V OE: 3: @$EwVDJWsUR1٧scQS,#w@LRrԠ%$*^cݘMܶ {ޔrdur_^d 8"'(6#awrb84 N7͔s{1V0{!(~b[TYz:a8oLd K݅57c)^*tي˩olOې pc|.Bjpjd"gߔ˔<3dˋ/RKj>K41oxZ,ĉ0hE1Z_8I2gRdHߋ+ :`^^"Et*LVu)_Pp R/7k+~%.Ui:Fc A-0.!}8t#Cx}-t}BL{nhJVm3E9u6P؜#ˑДDW||,F6=>jxҒN3rV۞?e㭫3iɏzqb8W SKùػsaG`F`qL2e^ݒ!M,oVP.}&f%!aMTaqjvMeY0i~*^8T;PR|8ʲ{2Sy=2tEwii\%Ot98Yҟu^C]LBsi;4u"גP2=)aLe$ãwWAM{w 3JNf^nVb?~m rA,g<&2%KLu'FQSJ(VQ" {q_ެ>oc:zMnfֶV 6uZFT G#Bpʊ⠔WA׺PX6-&~.FPpWnI% mx~hv7~-FWiϴ0"/D]{}u jRȾa6>>J#~>9I\eԂd 2r$-!?LFk݆8ݡaH=HU5zlβ`3SUP nɁ|?PX(kھV@i|9+PKmߨy3*h噴gMIRXeN2JQ".MOy[鼔 pr xu,(I#5׵49|Rv-Xf,>|S&&੊]Ƥq Z> \*Sզ86%2E[Ajj>]B["ӝW)YH]tqg<\): `>b 7hM;u7#&]vvUZ1gAQ,9zCMN3oht!a=(20Г}1K{λzjg`$%enj}촫q *1}Bβ8x'@F{C`)fj.>|1f3ǿF Cr"ԣy/!:Ui>R.͇͜E]|M(,rH$ B|(s6Q7PW "YM2YD0cvgI~oމB'cJp}W b;ۦLu"Y:oQs/T2.a fvWlnA-Xj?1:2n_8ԮSΐBGwV7CcF} ;&H桘U{cr; f~9iw]Т@I5APs嗂 Aۑtϙ_(ѷ:_EyٗȍBco|e;J 34)6aB6Nw@ZԮ)D* Gf)!F_^U嫆}17I|5-t͋Koa?.xg&o_4C`W>8*E^?UVy?#BqkM}P $%& 8jnx'ODf*(@ZmNo6+eW-sGApV=(#ֶ6l;L;]=CͶ34Y8ؑJ.7ُۜ:K/铘 ~ɊaşP)_,mIߧStF,Ah{#+3j`&N܏pQ zASYX'^)ZO>I-#4Q=ib+$ϵmO4 i:N9ENek.] w ;yGD5*spW>Kr IIT4 %wrɅ5#YCRJWVph"㐟'p*/=@[4[K=2w@+"qY>.sp5(-v.FTΜ7caRbBnvާ%%؆C{5E-dZņ;ku[N-TAvGfnzZ*A OE>miU'OkZݦdǂFL9}7dh OރsYw#!bY Ǻ%Q uerzdE<6,(Nܒ.\=wرrt ,{tڻԧ`(O^#oNO( D2._ AťaAPIq=टTL8?e${">i90Zarx|wzJGhb>Qb,>p~#u7 ɻ?X1Io[0 (68qniIyuNFF1'&b&Lۂ$b9E`wٔƝCp}R啫Mg[{Ƕ/):(Ib"qӊG7jnX5@+:/ iiX6j'N}Qbf|mqEER.ޫ5G)QYQW 2kڐ.;ͳ}N,lf7\paԼEL*ʦGBqs(E*o._, U ɓem`>5j^U@\t6!~#}Grv|isӂK ~ Mlȵ48Cr?vy\pD @8 ,念~ER!Z~5K07i[2`=2DpBA{Vf@4̥gF3B)M7jqE z(+7T}Yl;$yUĨveЁ(7MV} lN}2RP  '\p9[^%}QߟwwRRY.? HY/W4TkБJ @m;xJ߽Ri']"O-⭘'ɍAӀLᮁP!ߟdz%Sst官EHƐ! P5ޫITSw+ 3JpA)F{髋3,4p%e zqfaD?+msx|?Zu8=66>0,;lZ$ϵ:]vV2C6LʲHr}1gRQ'轳S;1yȋ/H@JCqAVY\,0A<Hϛ=>К'c>7*a\{ D6 (x(44Hi+QIf2i$%*z=h!ĝ ZHňU[IӓY?6W?Sﰈ9{ۻr.=tᅨBiA P`MONccMT X V4?v0yKZuL~*pK&U**k`2,J`lZ3xwNx7==H^쒷>s`fGd|zP!S>*PUд](󣞻mXnz؊ ̮vFYQg#hhWWfqls}} $c 򤣨C癭^ |>F 2iSO筪|Yc lʙ?ߖU^3aUcH>^aVvH3 dbтsi|+ l>O -7qɹ*2׻cPa-DVO*`qYꓭrf׵FlPjfX^={!eh(x߂&Eb,G?h*8`Pn,) #@.7Q3Ac{{T$ͩuʎut!wYb⳨HL6 l`+䲶V{yj!';b5lr #?6fc>nABM &(3;Dh?V,O|r_TXG[UFή5HwqeyN8_GG,:+DeNYHgOߌqesbHUk`ںܱ-}d'<;ٟQKWYJZR .IDاX`Y9ZͣBI+!4U{6Z~Txr ՎqubqPsطJ#م!Gu(Lr$Oo,*^?IfYXFe` ?-|LYHe !AxG;7{Xv'tcG1@K ZuF/ᄏ3;㺅m] O:lY~Q&ÂNWKK97l)&O瑡/p,: .qlo4nZ VlU-SHX}+>FŶ923%}g-qc|pO+ wїRV!c/WȾ_`7@>+;ě)h/_Bmkp[zޜcŦ8XXQj#%&9'VL:o*M3J0gc}ԋ3ɛ(עQH/7XV(TܩH2-b DM0?x7*ŗ;=JQrߋ%p{ u,-'mM7CuDMt* ޖF*n*ʫk _T5/Wv WݺZ'C)(y6uG9z[{=dYjr ZMM')n\2,x iƳбGJja!ĉUO q{%>^7#fHT#b=;;XUGX E56(X s5AI&rk%Zwq0c$& >=QM@ -s nܾٱgfI*f;~\@X&~@*JzBWǓ5:ULS]s)ӣu m.cy߳m?SXQ 7}t@WU#Bp` pGziߖ k`'D$ݲTOί+ia#%3Qp#4$,E̯|/ѓY<+7Wjx@pnD.%T{-z;[,U-"~@uj<~p_;%02 ݌ʣΎrl'#:ޢ\L ;ɔ__٤7S>s27`iF7vԩⲸ??5/N - jdH8 G7a3`z.Vv)AތƖQ.ȷ4/M6Ӽ\F-aZUݨb} i SDrOIgj+"jIx6gಚ~0^:SC@Z2S᥾J94~0%9h(xG ҌW2ӑN0ǡ / p6fc`pZ:xOY87LC%}Z8ևY $Vg+@ z.HY&8ʠrŒ>Ce&琕 PVucO,Qz(]b>BCXo6mIh$,h= 2 ͛nL]ddPheuR@=¶ǾIT.P{šgk_z ab:ћRh_t~ƶF*:GRē5HBVj=}1 j!qj1uhd8usr8][JRT`2}p8ŴzlCkH/ݧWGZZCA~vNNP[;֪8%gGjj0Ӿ& rxQBu1?1; ebjڵZd9cv{>bze%sіЖ I$tr7yyɋĭZ;Z)׳+@K$R&CP oFN;f6fmkQ^,Z*|O> =j i=+ 4m `(i(/aIkE~9"NKG9 7LN/qmgS=L?i6{X I\C]r.`mD]%c펣?.TA ``0Qz񊐛_|%jjUQm+.aC@D]v}I!ȕ|l{aH<[!t=խHwpemfG4o,,|\ѥ3Rj#u.ЯY(80+$)˴1[r;,0r*gA'M s?w3G%3FͰHpqjFY6`mPU0]{X J`|BXtja2E.F8ڽ<;aـ6 ?e{ld˶ПhiCT9s#6>yEEl$7=a;Й>5 E4މ]C=>KWwk2KjeJ@>lc{X*guOq?)Ļ) (Y\fA] fin;&0-eͻ!҈ZV W~5x ZJ8H lQ+sV;@*[1`']x.*̠̕}?3ASvSs)Kmbr"Gyؗ8列avW_fDƇA<_))0z!ͨyBPKqk-d ۤf; qR:Ϲ(ώ?d,Sr駢*|w(03!3@yco!& )i QH]uBTS*a=@( Y*Uf@vDN 1 :5 :#il}Iw%۷(xT0¬iItClbCwWGC@*[7Oh={n!Pĉany5;V$38T]&5c7p@9y*+.%U/,CG?-='Eeq: m An:~of{-nۭAXۺb>3跘C>G!dVgڂ¢%Q\K% ̀VX}<&vg.TD>!*fǔ3' d"\ {37tcgr jP=A}bV?Ț~C T2|\;`۶J0'O{?ZZVtpN]͠0EiL85tw6o㯤\.]B-_Zy j{cJBWzH6;%iIȺ2Tݝ.w.m~bqĤiGRUSm:󺱊 z6Hz|xT92{GZPSaLgECVqZO]#7%u϶'iMj=ΗC:eď*x&#%b=ܧƸ^޾":-k\T Q <8a $~r:sЀbŵ|L U\U &e'.NqlctG֚X5JP`ڧ\Uِy!+hM 3 ߵX Ϥ"q\ev*E _aa4- `\jD"c{)? +lU=w r_"Y{BѫWyS/2զIpl_˃UjRU "ɣX}MS:/'lyk0 u'/dXbZ]йQꍹ, ~!4>])y6g6=WZ2?ov\P?n5p_K<™H.!…^쇑MJߤC' w9>ZwVb!D@w&Ȫ{S cJ~br*ӣ:gS8dԎo:Mѯ&# 1V4'-k'j$p3s0#SRF10X>֣MS:b'pC)Qx[*Ԉfs~ H̉(.\cJ;ô[IMU8l(9#*$EզylLXM#pO!ҭ!Vw)gt'CI}ufMr= 6BaT1@J=$S YFB&p. lm pQ;r}A_h1GH4:̧!Pki5c, ."yH |‚4nt֧j DF><}\ b$n28˛w*mHn5("jS/7!7azuCp"͚'@.ѲbPnM$n FFof3>I2/^o\-=h|vphkj7?BF0 FrNXY7k⨈3ccyV\ЉKLU[\% ɟv j٬ FbuMOF[RŁ`;kn[$ ^$kA%}5fezsi䪿!j0!DiV|̛cڮ g뇻mnM[e/bմ70a!,qdX_8l+X9cVl wY0\%%nTJ}R75ThMQx'0k{m^!2Sa}Ҵ7q~d5y0 j ۭUB>T |(`hkx.bM(*a9)BwiԚRaRg?kJU JIPN1V/VHxhF$xgO= 7ɠݕ+F?P2c2Cbï?]L%wusXmUX 4Oo#`'H58-gN ?H%myhXB*H7W 5(Ah&s`9v_hQNA#QJ|HR a xCfv6|J~Ӫ&s^飨ZfX"luQ([iurY[Jb'((äm? EM7˔\x~"_djm"oe"U|x'l_[v-w&oY(ڎd`YI6Aj ?e 4'5~D(HcMPp]i 0D/Q.L<Ԭ"iK~ؼD/CүwKZ(U28J5`f*f 9-!g"?omrKi83A!{! Oh%^ՄɧVEd'dys )sdt3OZj&.JX(Mn #ppe.Ŗ, *n-i Ttrٝ hq_O2ZwnO_¾k15A{=տ0bs)+motTA 2WN-]e7:p2npc#}e.gL^K+HK7L0|ZM>וT .cZ$7(cOQy`G&uMl}"*b=8= aL5FBeb]y)ߣ#Wü,OtM! !ȕ-*kHLS9u3reI)- 8+1Sdy`:l*#RU@}/Sϲ~?S]EI,AVvb0dˋB#Še5]5glUb SM?oHsO b`b^"@ Bz3މ2y*}#GԵ/D  ֶr㒦O̭G|V3dMUl7E Cn0c3ǝlsǍKE>W{$k*k^J%kTNzP8gƕcaq٥!3nni,g) ,$ڰV(z/zU!JT8=|:JtgLcMOTM2ЩΌ]HEK Cdh{z!H^+H S sڂ_Jrqt)ckRbDpǦ"n=ŭǤTD=*Kxʤ6]k-Հ~ 5CP5_P>JU].`yfP(m/-,U ʨ#< $ۘʩj;^ 1CoDIq/ʬuD)1w ~&uZ?@j?,8pjwӐ+ qXupwYovǖfj&fL)cfntm=0W,z<ĕ?V:O@]_mI9 & t뛒{ZGOS]Pa~9:" ^ ]7FD[Rn0&~T]LFZal(\E#4L.I0<,@ZM&)@~kxBΠsT~^Iw:PG:gA;Dꏝ$_H)Bc\N𦖾őqb=9cbƁlqWӻ] <ӷX>?Qľ-?Q~n 7v^mmŇ?CsmBĴ;/'r9̛7P^;gr!)2\vl ?,jL#] jnjC1 _:L {O)x`tu]>BWE=UgV|՟;r'G\6 nO mujӂ &YhJ"סekpa\^fw[Wd귱Ǣ3?*֝GYE Msc[7h˾Jsg0I|uRVԒ2e|hfNeBv6.߮Ǵ}ʏ ViGSCl7UdZyrl_iry-q3]2&x80tQN~R&F)Rc BuoUX(%"XY4ŝ,yU QlE`ǩ婨:b4BM 2HO4})/c" ^xc&I+ [sou+9DZxQG41:wD`ɍZUy,3$kY@,^N@r PB(q:A'ۜ?4 8" srJ6ҷ8Ck6UV;YmYr:=!}$%{ ]*oMq%wm՛ w( 6-tm?3C%́vf@q.L˞Q!.jr"|dwph9/v\^GA%9ؿ3z&[s[pK|uʹ1 s3,ۡj]f7 ;Ke5\:1$ZJH$eLw[pESwQ6L LćvE\kW+i]ZYJs2+q’C2G uI[k7eAMh/^kMt0~3.?y;urOxPcU=-}Y~lPU^ Y)q'}J 7$Kq\+rvcO UI'˺Ϛ6MBO@U Mn5k*^˂|9޹^J*. i%ZvN,21'rseI3 \s(haj Y~PÌOB53fIjpx6՝\앫B;T42o< z3Nܗ:W^rE+ BF"kRV<\}l#j+mcLHτF AJjɣ6L9ŢP >k.L?' ;d-Kg P| [[ . sÔk\DX$RxJ|N?ʜ]i'.cr/CS9[3~z Fnl_J[ढzl"^DZ}UZۢ)6ozb)ZnS!gҽ(SRY.g8qze;qQ#â(a}2wCX\=`QxP4Q: H_'0(#a&?QwQz=C!*yĦ, bZFغ>}, hywWBI0,c?eɷ ?#'ɜ6fW}n֕VaY$+8]XK8\D]St O.ĭO&@ bAxA9f'2x$"ʳTa[.8/b|QYI2FCg=g2ID͸ ,X4Q,31 KCXR93Hh#F+0+ /[J9~{SِQ,=+S'誖n6@es 3ο:g*jFVR{P V%!koa%+M (Tt-@{i:vVcRL^x q{9ҝAܕc;Dp Z [c>@8ڕvOK+pS>ɇrOp0ʓnFp9(żLET)@=~Lk U=KFH^6ş m~{< (rGؤ:/Ezyɱ--v hIT"mpؕs_NK.?p$r|$ǐ~ָBr7AOqVv~Z9m߱/$*!{za,v5ȱl)x-=I r|J̬ S`W[hg g6DԚsoGRё}b Pf|Wo}Q}tCg`'>(S'OO,0F?E^[QˎfXh}jPFawRw = |篊s~iͦZ(Qt+Eܡ)qV`|YrP52>y!~#Wz2! )$ST-/qO6'ǝnq<[t\ X[2{j 9S)uUqS6L>.1džaff ;'{=N5oa9.ۖ-Uu87 avcy= FhEOw8edt)pD !Q5Z26x55=1ҤӵZNG~zb3e(ò@Di5իloKZkJ ҏ# / B[Jw2ZcnP#.SS/g6ANak]5XzB~(G"ܕH;}6k6nZ.΋Fυu)>rp$s~g)< m=Bz@:5Y&H2ԈW>e|, AMx $jHJS,VY+)IQ<9*{bM(vT!ELbc0'"}dg3%ZWH4*uH4˯r5W`sL;++&<Owa^rzL;RE(hNzYqw %R䌩 l<+'Xˆ "|WO6 EOog";^/sH,0ХH YR;=٬5R^Չ? C߷%U Ie q^X>,tG!H๠v)%{@rRt/y?;;)uQ`g(UŹik9 d-Egy`N +댩WJ#Dȏ0~㈝]Qs/\=!ι_2|-rrAF84a+&ߒ@l1Ǣ+9Au7\Gt/JO{l\[aI}Yodrhތ:=J?1X_D!ZMHY 5>Cu PXMELܥ1}1_fݾn;x1c:|&[d"-(f7 zXedp}.@AwͭμmTV&[.z[ 'bt}S.)~]-(TKuKm0PvNq$:>̄ ^)IcbgdzG!c$nW7`'"42qvȊzen"`⠨o?µ /wg"iKS_j?EXpzfyڟa41e۝9΢rՂ2 ^&QA|0SH"iXZ̛hqV/5\[~)p_Kkv:prԣqMnNQRjeV3.I q"BW;&jR gSZڶm4a# HQ6.8O˅-r|Q=#FImU/ ˏaLQoa< C xp?ⅉ'@pe,G{Ygeƶ.myk27BR : !v4@|V_ubE>9KQA链+ã&*%5I4EiZwڦCMM[xAFpx<#n}Z0B #Hܥpc7qIReb_-2FXj`#I;(w=bDZh XoDZr$RTH2=ye-ZOT!u#ޭնЙZ'0i ^N[1oW-oU3 zf,?8Ki}*F*O'{džҒ6-ռ lK}%$]]&3˅ [Mk ⩑T"Y)AN9 'N_#ѕ_(;thWg!$O@~Yn-K|c}.)m;o3Q Ls e$gGʭ] zZ%JurqW ]r5`hShWXe31*SuŴfUY `c5zSkRx,u0WURԉ&돇=K9e*ǹsqC N! "sO .2(ZfЅɺ`KxBhWX-R?uET?L~ >o8?/W-D~y&L_ :<>PO_ ͬ/scoTkA䊩"D7;kWY8G{ﰏG&4 !1Ѳ6w.(=ʟllb>Q4/^+dV9H̀3 NxQk*JeBΏ* .j:Zko!7  )H7d{y]S1:!YJOLaf5;G$Z`(I$?8JJni5eAz[YnRϮeD ϔ$h xc_(}JQ ,jmK6i66@ +jf7ޖ 6A\hm %=$vK`l}|oUngY4 p2oO&v>b/6ʨ9&:i෠-}! Jtx7p֑CrHC! rojGV#Ku<z@!y7iI jZ-Opdn#h"`[ nig(Vra8jn}ܘvjσKhƨ:n2xDm{띔]+qNh8:sgV!oCN-o]26`+QbqFCǏ+h7t~"'fX.S5ZZi{ہH0:k {>@yInjE]˔mkI׸aeU##T?%}QHuX[,/{2I].k2NԄfí CJrM t͇>,(Z8}幙+;M<炌S5wWv/~ֺ#C4b:o[iPs'O3O'%606!RM=9zd`84ZЂwnr[2]1.NT=}#1'r)aʠT3)7Ծ6[B]:[mQ(Eq\E-&'+懑~P9'+i_ gE!ZveX2 ŕw̟K6"Jޓ{:i+uĉ~:r ~WT7 T&m:>]YA{eg-ڴxU k$Έ1L*],̟;?=&>eI~pc|.D(#aˊt#QEW=#l'])jˍ\ޫ FN)lH^×/\YD '|]>[psSsfDaaj~ ψcuL07unf,gD(N ]K-Jm7UA#)bN һ>;0[ W+8 I?Y-:G`_FeUSA~RwՆD Oh.\ KUoo?wP55_)3 _p!n0Ia+{>t*h"Q p  ;"}CHceSBM6_{NЫҁ~Cx,hHφo~ NEaMg 7aW#ƒyמ&75έ\iCrpev2q8=]r<+QoWxPۢz3s[o긆:_^2@?Nvh+É2akJF3L}Ic87 ͚^FPv'jty P̴5ٹ kjEh/;:Ef&ql\{RJNI;P&UG(ҕZ=G\`QLDzg0v*j;}K52MsDMAnLҶ凫ӌf`&\ e>Tz  ,->fF65?dvy?Es}[srӳ>26 O8ױ[V:t^ nsEcrnۛ_@ NwЅA;vY\9~hInpv $-\sqcűe!үǃ˹SA0}U"M8]gqWidq2 ls wPiqH\ ˜W=z"_[Μ2TL6:%*hn5{ip|B䏼(΍xQsWleuw}NP2R)Xıި< < YZ