sssd-tools-1.13.3-56.el6$>.[3\k >2X?Hd   A *HNTbb b db b b b!xb#bb%L%hb&'9'9+9(,Z8,`93h:RGbHbI bXY \<b]b^bd$e)f,l.DCsssd-tools1.13.356.el6Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP passwordXҿc1bm.rdu2.centos.org vCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxi686*ɤKSA }5q"1EQ :bn3] 11m:+}MHOs x?sH cC A큤XҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿVpnXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿe1ec854f68372bd0e1fb6291a2573776074e921bd39bd69a8d5eb8da2c44dbc38b16a09cd1dc9fac7c51768c27ea19bf1bf0178909122c473d60b317b832c936881b770495b8cea72067643c78870ca9a78a6d1471110d74d39710050bdbda0ce2b77b0cdae21a8dae1bc315ad375eeab66c01151c46a8491e86e483a753062a82fef17872487505c20965039a68b51f18b63afe029b14ac4b0e403703b050f3074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45e21af5f3b90f9ee2037534ee896eb380f28ee4c8287ae079cca647e0c0d110f48686963a818eb925ce8bb0c94f9f14bcedf56014ffa17275455d2879a0fea2fecee8dc6123da04ed246a9e7d1c724ab7dd4d41c33f7923ee72052bc8a4b934763363da7e47f2c3c6df61a7cb83fd33d9eb3ab5c8931126e6aa274c347902583cb57ad3622cb9e17d2bc083e990dbe9c59cf2c0835cfb21210168a04188196c9e18ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90350d84c60491f81ec38582151a779c4e2aee537befbb0bfe275f4af2f4d91a6aca6699600e6c590db54624ae492e7bd5af1db45651ebcb0845e606ee559e903c099c3dd8a113fea8f43eb6155a4354bd4ba2aea406090f3d764f486c3e07556996ab7f4306a908defcace37f1f6c91dc4a2209ba0ef8dd7db7fbce0d4f11aaffa8c15ea2f38ae06aba6778774ec66b34427d8643e9a628e459fca2f53cdd141a70cd03bb230a00adfa378b30947b3c4e4f621421d5598642bf9562af08b264038b2e13af39c3346e820dd25b1cf15cddc65f83e8306b4d14e31d1195d193d3aea0de4f9fadab65b5df315e660634fed1636d3838895735028619c989826cb5cfc92d14b8141c5b61150636295bede5443eef854b35c22858d94d27d2c4cc1809266f7df05620679dee3ef453326967afa37b75389821088071bf478aa26cf13ee8246153513a6490d29df0340aef9b406ecf914d9fd7a8308b0516d609215b4694c32ed1653e72de94bd8799e968a4bbe1b8b2b9b4419c31cc4717c46345219f05981d65f788e6048bc9d1c4c6b217409a3fadc3c5202098a604b69c1049123183ddab8a97d33f0efd00515183d712552a7fb559d420b2382a98bd47a8aeeee7ad17ac5f114eb8c50a94cf87f49ac08f1f6a78c739b1d66a03156b16dacd14df3653c2bd588a3ea18eadb5c1395551ed10740fb86aa2a6e3424550381c92edff47d31c31c18d4e0c2f3420467fa2ff7f54badf57d2e9d03452d0315d4f328bc751516fc4a79bea2e43ff71b134457cfd7ca6f09d9670c757d031ffb545df1350778184cc5c85e2f38cefc1a5fbc5f27546a44f1b906dc11bf7847b6dbfa7347088c3644e8a7bb4fb18fe22400d07409fe8bc6706e9293859f315cc1df71e04a9ef1f4439be013ed636fff2def8917761d7121cb9d135a391457885d341aaf2a349d24a516186ab7287f5a6ab2c03e8afda7442d66c4b6735f7f2b2b644f0901c6555371032147c552448e5bbff22e4dab75d9f0693c61498a6a474cc1da399b24cf6e74b46a9f5b20fbffd2963e906ea123917cfac0a9a145b66952b273068dae0691872ff8b6fc1d5c7eb4a7e96dc9944560779ea8cac92be114f2a615d329b4a010f54b2e1aa82e5fa037daf771988bff39b18e50d73d11e86914487578f0a7d22e14bdde49d0276572df0c93118d7e18851b28e315cd0b690fb3653b48c041c1d18b55521e967929cf5519975d67cc935da4125c3e4031f740ef0691977fa70a7cd8b5fc5c5640e8f39293bf0d0fd2dd002409bb268ee5b7d5c8e9f5a2e4866e6434029b91fbe126e9b533814c2faa0a6eab5b5702367c212a4d67b56ea340dd44345ab427050eac3b66b6369040272b6395539ce39e226e0c922b03d49d6892e97853882c6ba50481d7743d20238c903199c59eadeb3fcefbf87fdedc2ee4ccd8d091076e2949dc5be54449913b808600697856d77d21e8c6b015c713657cce66a0b45917c3984c95ec9dd46b52bbc394c999ee1480a5da334edddaac82b413e6a972b5b871175de92ee547fdf979e6e65996bc3af2f4a47d1389457c87c49d9063684934fa435074f2f345e74b4381acdf58882d46471862ec1f4bb83fbc436f5861d9637216e55a43f3af1f7797aa78e950971e876219bfde4dcdaa55b851b44e3a24f1e6c13aeeb1245750e4a3f529e459b76904c07f2bfe70df8bb00c688dd10766a99d0370dab32750bb1104d0c7ee9490f72aaaa0fd37cafbea446666ab88a65a1350e5bd28bccb7c9652dff2bc19c305118b28ae971fca9a6a1c609bd4ff0118e29c72144475864f3eaf903bbd346374cd618d03aded0b9d85bb22b18ed76d7a520d73a7a98a763f502bc8280d5f025b1ca3d6cd38a1718cc09d1748fc1c2873cefb6307c94a7bdc75d597c98c038251087f2a23619b583a8b546086a0c9f418c4af4c0727e43a693f87c61d7c93860c972436b203a29e6a69f255559306bb17c7f1adafce4335acbd746c86d7eeb69a8f1cd845e74a05226de15ceea5e0bb09516fd684315b32690dcf357948e1648bd97b2a6664bcb857c1e5fc7be27495f3c2e99aa4bdd98a7dc152a75b1135f31dd5ba347cd62cb39bd94bdbcc84c3a6d505dc36e4fc685a81b8b1b79d9807a303bc4a5a9e10c184a1581e77bebc6c6cd32e0a20eae4f4a0e4f4ee90d479a774286ee8dea1851a877114f229cf965f4dd1d49332dc9c066e16edeecbde3014cec0ec6dbc78f271ea0a75012beff5e88701e02fb3e1e4dac8b9420807841bb755e2115c6c6e46b2cdd3c365407be4cfc0d9ba04335d0fd8145b67b045c23d30c8992acd37313ef3a7f7c9b0b703d143f437b5543eba373059805f2e778369398e0af93a55c6c1e962d7a6f476d66d10ff2622f619147e1c39edc58346d17405227e7df1e9f6336c813e618f826ea003f18d714d22e6d3cd717eccc3fc862b25b972d746858157b52105dbf6d37b9b4eb52d2a544e44ce2772184b4746e763ded39ecb4212ae61a05c254b1700fc47890ccaee2d08cb1530610c305cafe9ce2d38267ae622a6b7aa145ef999f128730ee832f3b04f41117e4c0000002c30d2e3b219c4f92c7a3ba309486e1874894b97b9004b2ee16c951aaa1db93c161e54a79d9e5949293b3fb5aca5394007c33971a5ad4b1e0acd537ca6358a3f620ae95b66b058ae3c3ad08e6688a622225d05f16d42013eb4be04c3761a66e93cdf716c743c02f68d39f71441dfdb2686664989e4dc0b629984b2e6aa0cd2008af061a1c3b83a024afe3f6fb073267a63cfec27c8c21fa473980e79371ef2b028e680567692def0429ed9209977bab51786b070bf54f8a69c5ea3aa03efd01f47e44c4d63ebc00dfbde73cb79d56e2d6551404f3f7add230b60c632407d918d3b04644cec57bfcccb0e3b7c5dbb43f8df8167f01ee0e32459dd00c9bad8c021647a6d93c630b21730d9b8d865066d58286fc1ebd25dc5f6119317c9749bb53e25179442acdba94c51e0f07cd3bf74aab44efb6ddb2a9e95cfbd76b4c32854a8c5cbcb7e4b0bac81fd5ff625330e230d3117b78a91c41095fb786fcd6509bad5436f2ea04a06301ceaab2f1490b76e494ab4927e340121a5ac02bbf151ad1fb3ebd42b8f5ec440e2c5a5f00edd5c0efcb19834a87e39d6f3a2a220d64272a18e15d645e576cca2f096d689d03d6898f0afe87ddaca1e905d8c368bb5730f5db2c102b487c47ad0bf8cabba8c91facdd4098f69facf4adf8494ddfb5179a7266accd21f434b602e562d6e11de028ff27abd1bdd4944258d5e246e2c2b056fe6e444ab9e82cfadc4f9b50123f031082ec69b3a844022f9f9b41e8f407d470ab533cd8e2219e5b69d8ecb20c22d514c1e15372e3d1e536a359272218cfa6f9e60ce38eb2539d222c9af9a192a73908ea2cdbf268e9d8fbf457e3eea1a45590ea8f1ad2bee83a70c9ffa0a528bcd61e0eaacb3c85bea64c1c286cdca88c6836a4252c16c48d7a9f2bed2ccdb9d06d4930205b81415331dab055906cae37e1aed485f5673cb60db74eabc239927f99438b7205875343e775d22d65cc198eff590257e709a4921176a33d8c086e1d419acdaa5b60c25afd269427220466f09c759167b9bb3c288d09733d9f372e17df19579ceb4a6852dde577c73c323eab60c92d8a977fdf6e12b1e6e36f9d8cfb1af29b014701d677522bfe6beaaf6739d9f4781c59429b51418e670fd8954e75713bc336838869ce45d31fc9d596cf305654266d0934f3e959c63e179f9ff666b2a79f55a41649897f04fab8e8596269de7f227bada85b84c04bf8214c716b21ed3775ae200rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-56.el6.src.rpmsssd-toolssssd-tools(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0libcollection.so.4libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.6)libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libglib-2.0.so.0libini_config.so.5liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libnspr4.solibnss3.solibnssutil3.solibpcre.so.0libplc4.solibplds4.solibpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.12)libpthread.so.0(GLIBC_2.2)libref_array.so.1librt.so.1libselinux.so.1libsemanage.so.1libsmime3.solibssl3.solibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_semanage.solibsss_util.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-56.el61.13.3-56.el61.13.3-56.el64.6.0-14.0-13.0.4-15.2-14.8.0X6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-56.el61.13.3-56.el6 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnu?7zXZ !PH6Ec]"k%}:w{{.E+wY'S?eGTZzBXj4`/O:wCdV$3},w-51Rp4j,5#-/%0K!lzde"lHOۨ uv9q*? f`ʮH=~,DO; JJr{Mag2qi@[f/`FwUYЕj 06Pǡ _Zք?3skS7-+`+eh:Fu|j OG dF>ޚ܎4٩#]wiۭ*Q㜩 2G -]Љ!Xj`)K.i{6#`9kd(ЮVGeKG6 ~ͫ )ʠ@R8aCRzqa5+;Te 5;kZ啍q` vĶOTe$˹`z~WrF2ji9]9@Ŕ`sICl7Ĵc(4v.9ojW0D~icI%2 r~bG㮠 G_"}2nUz$PBVYC Uٸggf,X^#Sz wPBY|w$;!؋C *P}ؤU=V$e1#æ龖.Nw˫\/Zcyp̌X*9p|@HqÜjSvHq;SokaD?]tpuSz+eK(~IWa *m Ihөr z>\[h@wNn?/ÃR09jCC<C;`7L6Z\[Hor|t- ,+*Dc|h^,g=ڵ&jQ麛7$u-{kP賓2 WVMqFSUgVQa1 ŘFh13E(H%g!3E.$w Ott,O4#."i6 5_:.L-\뉟:䁐"_͊իl` q!A6!vj " 6ccBA唀XCO;u;+B.0^&MeޢDg:AN gWv-s 35~GK@<,8U3ZI5rA_+iƟj=EP`(y@~yt-0͆d#ܭyHIqG0YjJψ?zf`RLtEP,>cy#._ja(uKbYVJ#=.l^"e;qzއOjfTZp)%= pR`\ ~k 4BK~,9A*i|~Y% R?wL^nD;8ln-bܕopB2kfZ`?&Ōv- TA255ũbW`k[x ΘXõco`|ޛEpSk+0j:z^-3{\H!viFůf cB5zr`41^3jgh(Enֲ`L6'A qlح{jF^8vs'i8"[RJAQ1goN##/0LwC[B T>Y%g 0 xKbz+%Ńgr{R߰(x/;J':ꎽqTsFPN({szxC(ØkvQwE%Ƭ ~y6pb.bǿM5ٔM&53c0ZtAV+ZKyF?bÉu4x|wllޭcUym}99<xWCu|tS~ʼ ?vA9|m@FcgZios+z|8uEJOr8^"Ҁ@ǀ ݪ!rH-Y~i_s7dS[)ɜS.qm g.Rՠ:~04spx]NJŮ?$)K?I?Q8.^]1Ax&v؉j-dtJ$*m@2t a sR\jnLz^w @*`M= RIRF-QueJDi:W%gɀiC pC- .*7C%:b.gU^ uPcUP (rR$7EyM>Cwd#ڜGP7ڱ! 'J&GLJ`mz78ԅ۞lAe_urLLb\6SaxC*֬{X=`= NBJ.*"mv\&ULyOa;:" .Cp-uvaQ~ _LC+(V?#S>]V۠phV-gZ"⬁n\' Y4k5S[ܙq–CxB_1=? {!S8%pLD] [NQ$P%;>U޷PxoRɡHx՝ nzUYAtte=(lҁg6ZwlBNeluqՒ'{nhZ ?,bgdfV(A&)5N4O?i%vߒ_3l7b- V "kYG.s Tqഄ/I~hf\Iί$YF%{a W+*̒kّ&V y0j^,},#!;ʕؿ~V(R4!"hط9KHRH>8Fޗ-'!1ʨJ5tJ{.G">=ҟx"ラeȯH<̰(؎gK7F ݼ>"":wO@c~xjIXo):HQJ.< `HRfU*AGǴjog\6+ I5ZÛ?^-ŋK4E& ?~Q"Ow?k97,KIY}7SpѠ5/Lq$J(Y#v8U.f. &OM;IlЀ[ YH Aj!AB|:j|4wS'=8$Q+E@I{H3A gyM!U*.a.y X QU&GUg4諘]!wU,{6/O*|q;X(dl>kA?F*J\oR̵c327xN{ YQl57WԴnm0b/m%N3!'V?XR&2a!.X@9 r v {_c(hDv6lQ^/:hةȽfpĒb8iC iL;j6|a6׺̱4A GgOIt?@{)"AJW|q -iq{h\P󍙶$Pps)pǍ$Ph*ڛrkwQs=D(yd蟾Y "R<:Opj `?=8N KZ$1dyn3;#@:}ƶZql(^g+$0[cU}+ DZ'd+]vP: :e]T̒lAޓIChYo*82߿/3P9M:T򠈰LÅэ~n}R`rA2A xAJBJgtGU=OYWSaN#ߒZUP.<%L! ug)/~C]n(,K_G31[eԣwxëRxz{Բ4l|3`1:-I-N8JSJ..x%eID: P#wl@Xh )?Yz`#p]P\bImǝz­O\s-HYDwY`! -> Xp &rs7C1ZsxTwF\B$3d7_V0@L0յk3֌,|bbz&3%\L~N0n|+ZQ`MNwf:3ՀN[H-kN6R,3Ε=:^HVTaˮJwEFЄY}Bu@Ir;Y"tZn#ѽsʈ(^"y`ʠq^tD ȊJ򯌞s&<& "7ؘB~hDbcClDl 91zXֈV <:UJNC*FǧhZʡG'e.-c[4҅C-/|7Hu%7Yv~W?OayͰ=ˏ'C/ClK %# 5qU^e4ԕWGpZi7Q1B#=8eP7UU>g l&Yx_]3775WRd5O:]ߤF8L gMf׼U ٪qk>RsO]C3~C?x'61y;$O¶q|[K&YW\>i]‰=VMLubcoCtw㰑BWB\#@(bPL9#Ցadb*柱ىO҅¢e*WF뤺J z{©}BtQeZHwy!?M_7Kr >|HTL~qY6=A(m$TJuY t-oC4]ahCŐ\lF<䉃ECNHgad]6x4!}Дi@ dݿv)&Mc~kR)-OبkejK꨻R!&i.IbMt m9h$9B|6R ~c8i{2s3ң(6;ٳhD;O* 9-_ԗpS.=?26R"a(1[#? GTfCqI ja>Kg{Q\w&iy3YArPggt L{6Q6BH}Ǜ@|-?}NWb!_#! cRQMs{_*G[-y5@i3w`"> )عS]" @2:F(TQu]?}Ї 3ac@~uEqW/]_Q4B=̚`'tf^>U$n5 .3aaɀ#-m\Ѳi<}1fuw(jpƅ-p~k >4Q3U%F䡟| .ɧB!Oag| EXz'?ܲ@]b/tqoꟘC͊+ ʛ{AJEg^ @hD8~@SnthBGَGK6PA'fpxbBA.A#g9힃73#Nm҈Cc``3d]rX}>(LVtax9 懻A$nm*`~P2E/K&p^kup:%zfA 5lXTA nKܬ 1OYjڢó9C-C*?E[ZRC~aZDOR䆥^Dt#Ch&`n]C Q}D!aXڴ EܒCxĵ En=E^`r ig_6*o#⽭3\Yp;NH[zPEؗ󯩃S4 øZnú6m~\$fMc-o<m#xꞲj$ 1n Y"CdIW8|{!YX dn/h4􃠒2fC;8MPkb4a=8Фxq7nn,pJ-f.(\{|u {g}TzWdx[QYKn!@ 16)aڭۡ >b쟺A ʺ74F%1)d- ;1okwP "(BDު+s(A&3o/ȣ=Ƅg\Ds_k߲D\Z e5ʦc(Y1& ~GKH`J4 lJc4q2?$_KKE:]u}+1 )NFdH}~eh162&SWBmT= Ba2@xy̓G 2t&՞P<fֈԵ pv~c7BGI=Ɍ5rY H.0lvjo{`d v!Qn|\BdiApU=k>@n$fO$lPϕV)@ҰXn˭U2FVEǵO\=(%_߹ψɡRlrX|Eӛ PδŞ(V$%S5[{gKD40X~sdD9Oi',"9vU`r|wɮ݃Ì?4Jpj$g|n?fP39"2,[9ExkQ\nKs2w腬__l\߃_aRz\8Q;zC{er7f*y[(c bF^y -ȥo%]?E?  ƋGIZx _' _{ښKL &ԀrZ__1ʗb8qy 5ZIQcÍi وo"#_w$VEDyh!<}MN)OZոC]A : R=f[!( IbPtuk84 ]}\hTyG<~zϿ<;o 2C6D?,JS~wy 5ջC H(ӗ(jBfA {mPn pY$ W;|sYO/4DCQ ̀~ G N٧ $ɫm >uMe)y1tt%۝@YddDrheWhtSg"Z/lʐV[j,9R l.iP\W1ZGGk8ɛȇ $7Wn?e+1 N ĝ-N_ 2SR:ry>-(LgqHWn0?dG0BiDSks0+Y"PyՈP;W RZ紕Oy5SHɂ%H2trij!)yxK> {%?B.]s{ y?%#i_?@ ]@P -j`{v<(_mA3N4KrJ Ug? #6;mch<#b.#C#:½#`-ɖOJ|D I%թBg>屇䧹ndS0]IS2.. ʘ$1t9ů]'Yƅ|dA 4aU`y-;{`P8l2_!ȝl;T]5j\JC#!$a;k6,7Rh,p,b_MchGsD0|1kN-BTGHJ4}rL-4IPp{&8*L~q7,cЃn-Pɤj-3!Ypf@Ki|slYfU| Xiךҟ~ !'9tvf.kG^} . ّ `˛2 :S ulWn<=aYotf8ޯ5( ,CO3Ԭ,UA6^Cg~ D ]`=~i b-abrGB;{Dd̄C%o c7m57}43y #4 5;$*ܵ0SKyo&8v:Õ1L0q]G Sh =lWgHl&X)S+1ƑR(/ [߭9vٽs-Y8 Iބ6$yP fw 4M @ p-h^ɴWX)~Ce?\z8p-PkdCމ,1m~,gm)@Y`3AOFf,8H-z߳ۦU; xֆWVnJf'bn0YXÇ,xf꠷u- ˳-V-b5K D HnFˣ(Gfoj~J0!m_'O@574 _>"9@L;ݵkaQ!?ãje$I(L/'cg9Ciag $T /'pܧ-تN<|(/E@vjK*r5>pgj(de T!0rknD_5l+aq'C\ YcU+k''zi{n#?TxH% W' ‹jWvb<i/~jߥBOPh.ʁЏOWmaK GG|fo *ɑes%stF*ИG<_=:rM`LED%)͸k{'dQʼnq< Ebٻkyԁ{;)H#?WZڹ-Q1̷9Gq}>_Son#J{#%fv@+5fYb0m}>ڬǎ6YWs?._AG)V.FP}L)^ܳz!kn[}v+2'`5=[<y1| a=1x[go-\ 1#퇥ihn( eXmB2!&TνJ:N+IG_j]Ϙpy>b1սŮ^sD4UJVXlxBw}s!/8+|6%gtnˋʑttbċ#IDn\4_)U=xn.a 5gx} S^/(tj1E8!Бh@?+}YK4]$<]eH$ J!/̬Qd!LՠX.u:L5,BB}Os{уt{od`]Z>!(a6)L< x7tŎ*Յy܇ց 9_WEFvnB%hJer7+@!ܠHKƮfZ[ &rI?I@rpRz9;Y015\QMlu;n}@?J߀{\J&lٻ6ômg1cY-g$8>_c$e} O|Cΰ3R>[H>E6fmtoDBrrEe6e"h=[PGyE x^u 'ж}!:=s) d\cjW /,VJGӳBK,dA=5(8/{,O-?1*nng䞖TALC7-Y-)A!qȳ_k?V~q!BN~&lǼ$.v_xě߅ M+2jk zW_oC3$i9VMȅ-#s G0ȶސ9V~a*ZKVw 9'Ifĵ٬e[ fIlO $(>WGuObOb/Of!{ *&8ofF⼌ E+%JC2B.ǁq7^)\`,Eȇ98ҤN dednk\` \*ïSC2mJϧ.|aZ(zg;!|AV5,{ !uYG,>ZǴDݗ^b6zi#k=~͟K3cT>IWgR_'O]kzUvZWYԊ.9 N% ^Pn}]Jd^6F%Z̐O UYo- `E8jà GeݿNq-zba\mt]UTe# ;§3OOrҡHph/ahPP0W v7@ȁ& fr#rKU-Yq˳z@MH1 HUJB6v '?5~.qjڋUGvT0)`yX.2+ 02;}nS22*L.e #VSǧ,WBÀ*D@(.Iz\>ӗdϧ,J*f ep∵zcv~B$&j~ q 'ep${+aXƚmSCP2[T-Ԉğ"^,2I"S;Bʸé3SL#P&8KR\\2TR.5( uqW~oHֶ;ER3d/>&ݥ=*|@ޛ8L"NRtu2T$11,{ڂMvN ~3f3v[oE~b.)")!\ @)u}T#[\8r@k֊%R|h74Q_\VU~-Qs =xc&p=1SUPs_bf읟kP>״op4:q"v^!Ϣ va9q)r:%qTJ]Qׯm.Mŕ $?hfgtUGRn{Ho-=4MR#+*Daq0=R2#a%A(Qy[dWe)+qFGʃ"Zk դߺ7}D8{[ӲЕ cak_-ܑbyqԥ"R,bO|AH0l_Ob,w/&eV"Rm3vr3||uPs?<֯Y ?+,*엏\zKi9iTd x!!i8zs0vEPWRk/8җUK=!z;h+EhK+>lY1zw!~l$1pВOt#s<\|v:ik;^6vR{Fpg:] ipcG7ZS?oSb.}x-}Uk !"VUZ`ykYN;ƀ)d ˃o4d9 VO {%a)2WY]bAצvF2v3g7?Mx ^>#Z΂:|=IKub9'HTgIf #YaRP; APFEʵY='~`bJZuO5~I<.jBvm`]B쌐 xsrX戾MQLW"/Ϗ>etaeE_ZK Z,N?,}β}l\GNRWB`;BԮ"N۱٪Q^ȥ5 (<U ?NeN3ىe0$-u%a͚߂;,E0 \Dm%HNJ\?w@WEb@loɠQuy+x(16'wsGJL.}P9ݹQnݖDXČ#ˇXYȋڃz>zh>BYu\98LLH$ lPYՖ IGi.CD9[*Z'WEI"Xb<@yeToZ!djHdڰJk E},n8[sr ̺Y_ϊ8^aoW^VY1G"Rj΃Qe'|J|Mc_eM#]c Y4E&ǖ)!d}q"y2 OrNޡˀZܻ:rQ8: ]D:uvϯtY LwMWc,*)"p-!o;qB;B{<sO8R ){8ё.e.%)»FE{s͎~~,]'TW,qņ&2-q;ir:[>=3Thd=VT$yT"<1QdQe/w]K/^`.>[j+ܟ4Սq( ~Y^ғU;MCVw.iZ_l!zx#)f|kևgQ Tp@&Ñb&%Ņn#fF*JPV` }Ŵ)AP䬧 $Rd#u* +uͦjNBCOz6qSÅij@ihe\ І}#8ճ#[e鿄~# uasH6N-_N&1oe{q1KK!P2hP3eo(j5l!:>C\iǖ.'),"m@XNT^G E[ Ģ#\Ϡ%IVrNbћζgQC#߆4UTf+{$2 g,${ٞ(uXtcQfW>DW;‰ȁTk?5oZ!C-:f"_qra̿W[&kx^TvdbY{ˀyN7wϯVH+"Wv\R3dlx:W.p*ԓT1eyS@P_PGKtbvקsKke.)ow'FH D!Z/i'a&oJ@41-=Bʥcd~M%WG*2 m%F>9OU胸.=~dD6k8nO\PqM|we:bwrدN< ,*Hm^nL2vJ+.o"`È#GA+p<HN%Cv/` Pj#0d`I GvޟEKk?ە84!|ZO?>5Bt QflZ:yS"Ъčm&/z vϐ0 ܸ1lu7BeOKWMP "^:>l[&QtԹ#=3)#eɈz 'z}{}L8Yڅ"\ߴnKlVz0Bj|("tb0rѫH<$FϪ e-& +K֏4tajHMO㲶~k ~ PQq =\^MJ@J'M(I*_ Z5|GOC@#&XHۼu@ &!Vm1ZFV4Ǎ e X;$"H쾟WRU '<tg.C@KW{tQRŎѓ{]v{0T_}㗍>է^3socdc;0-p &qP~qH:+Å+gdBՒ05;?SؼMA*%ӀCu!cƣIDiw?T`Ѯ\>%mŎ[)%S^cVx<7_a8 NH&FLF)Do}@u.llL{6KRF%WKUZx:CYr$M~vz҂#cYXUSzTDVկ|ti %š9B3Hx*@:ͤ.{&Uc†4 P2 t bdM*ML\k F , ;Sgh i'*f3d7u88}̒&ҩe0MD1ݟ#Ko-jYlFh|<FUe{t* 'Bv$+Tx?pRl͕p$.F ?x F{AKԏkغ8! ~W[a^KR(V@tGp4dxeIHD#\c7o)< Gt9oB$zgץ1M"4*R5/Q?%)Wu=>i4ٺt' H0 swkey>,z$5 ax̊׺ey87&1p"]adYr d% zB/ aACueS`A h}Z3N< SSxISXDho2諶`ʰp3(=cbfn7aA2`hMEUY(K"3%ikq &j.syn3.;SyY*C!L6J/tY5ugxa%uhT?șI56!\9|O1N:Aj Y UT=ܪQ )p̅o: .m/Q(=³脆1vO=7Aԛ^R?Ҟ^d %SC Zf+0>>46",]y0 w#1He&dsq'r~rA7>|#VQ%jao v >潖gZYR[%& `PBfWR|~ݧru{n3h"zc.wR!Yu&G6&3J&|O"ϯ7Ū*)a/O4DOoO)xuȬi$^Wb!gY"fLYY//Mqr;>[!{EHm .fF嘂(> /xh'tP7oi}$ޕT1zGPJA|hǧ1q9ݠ] N,=DyG u ;l7qf<+Geߕ)HmdMO#.L=F+}3S@/ͮ\tًRD?Ya38'߃BѕPR@-ٍ+RPy]ML)uvX}IʞzB1TT0e6!W4G&#"fr '${D`cl'Pdyc"v QGeQD:B k&V\ߪZUֈ=!]jʏ "ҹ<`/W!eLVZ3ur9 3O a 70JyoY;+倚 DzT:B66꿋VzfќlJZ>_䧧MtF+߳jv+fheiu sBlL㙻ҵXO:2Ŀmɏ$mP%4ԝ!OVq9{hJYzVkv XA=Jn(|PkOJ0.n9ik1סAn"0'΋=X8YX ?Z0#UJ9b>[FQԷ+#QĩdRk'|[ͻSOW#FRf>R&]j#meZp=|O>V~>?TcMʯCE]{=K<2L@!6rD֞⶟:Oi LwU" 6$w:% ZU]t6G5"+N!y ޵OA Řz* ޮm¦'*˻.NC+dl4Me"pP慤4DBE!a4=9 w4?gV8ʆ%z$;W8]/pD΄vVcD7/d:[_O㘍3Fz"č#yTIZ>S&uBZ{@ Q'Ġ3h`dBoDqjMȜ֌]qz N>fŏT=mW4$zj*kԬ~A$lP04Ш۠ik̹FlDYf,-t)h:ͰE&#vuZC~f?`De}ý\9hCEQ6cYJfR(+7A!X_$Ak,pR Qj}q>;q ;rKW,7HlP `~5pC-^ru5Ml ӡgU.D)iyuR)YjRwOB/K:F)~eiAFl}m\HSO^8,jydlWVm$[j](^(BͦBuZjW)FaG]ڮ;"΢LTO~1C?& 1Qb볪*+Yrea!A9r/~^#Q_i4~XHՋLqnJD,yH"C@y+Gs q"КLi4*-2Z1B~շ6kTDnk FӓWG~?GQl@B!LdžvG|>0;tc̞+%7]fmmv|>[/J7y:uE߉:t&lrg6lX.k~H`{*>b^<'3 S}-L6;4c`(ӑdEˈt/ 8zVJ&+R 0֠90r?KvG# B r{+ns€(>rW6""P,a4w*I٤ROgOL&3pڙ3,>6I[̖ၫػzEe^U^J!URp B8 \W"TО:X)uL |B\\(4wrݳYn˔>;y39B#ڄkv*ZWe!^a.ћǡgcHW@eQ祴 9vo֯h$㇪jοl%݀o`=> ]}MS_^e6Ԃ4׬$EgH :a)WQe!Y$gm= ?2=w&f lbα召&Tis\L y"RC}%xsVQ=, x6W@R/ д5k|ro"΢1gL}}uJč gƴdR'~प<;X?eVEř% ?Q?#Z aq`<+3ݨS\ӯRyӁ=w_,;^!` 690(#5y[a˹3DC'XSet7YR~P dM9-x腚ShrV]nq51n.U*ED7.i:A/v$ ‰adym3—6VGy+?nD/Lo~`j Ka 1=)EUp"=>To:^3 ψ|h^k@ sWu _РA >ymH\+.^fYV:.m0`mz}P663}8G:|7iɄTR%]:^W5u;Q}1R\l .0Q3}>{߼(+ya[ފsrP@ 1Mt1FAةqmY,x1/+?$0!_tcl#|vF%EXy%9kEZ QA&p5boK%\Lm,|9/&6n2tf΂jab8ȎRf=滲h`C?ʴcr&-%0^ l'Ui$+f^ιTDŽ:V$~Ms>Td!2Du~ebbkSdV[iqi{qČrIqlG Gk{/Dir{W?RnMg}au9wxɟ~j,f=n`åEO_򐼺=B \D z*oK.E@Ŧ ;ArxG0"%a`<ޤgu`^'J(FLa[eȷN6ir>Q!)h^0²fM"2v;Fbj]^^|`gQ2_jwx:c;iZ*? KlOi'[^tGժG@ XkNP" >z^5ѥJ3TձY.`[QD).Z@?'$SF OV(fޝSc<ѰW_55s$5Y˽ث~;emMK1~H;IbN'K[!|k =4xw18v< mZ&tVkLV阑Ҙq+X{xyOoJא~ kh4Y*͘+T#[LȚPmhC=N}#P[m77vݣ~$߽uRM28?B\tBf+f&Li"C" C7;!<=%;g(v(]^"L$ܸvJ[T_p#bf,IyňD2ѥ5)mf,#^~q7|jtwzkF_.=lc#j)HNaMm4i읛ު#sr0R^pB|奷t4қ^Tfxp;/Ұ[%9}Az*UeƶT",8u)!|ۼT/o0N"jHuXH9L̰o qj5doڛ;_#) 6Fz'1O}-Ͼ[a}7_倹|0Jm׀Pz8N7O\0$N!9,{  iqפ s]06[:cPZ#F T¾{+7%}:_p ڔh> o_1:H@;¥oy8.E]:^pF=|Sk֍Bgg5X97xer-&J3 ]5Y^&%C.S+ \]LUmK![ fkߟ$.N$KxS@@i/4F!sz=įײh#7fH|SSaP ,]6jKW6[j$ІC+RsR"U<**何HHZfoފCpgNodn_j>'^ޗL ~u-=QE'%u-G-_ Yq깺bT.sȠr棪?O7/6նu‘HmҝnH}{x8K`Kqb ͆+[# 9鶋^_2B+eԵ^k`WgDΞ97xa ?׊l8.͑P迨iuNkf*<|8Pgwluua-9f>R%]ׅ({/7!g1 \jR+m;WlK؄ۏнEM(sJ6#`$Gi,Pj!\Xlhv3#ަ{啐Ȃ]+B'qY%+$qR'hMx"9@"_o8 q %߇ ?k JKvG1lAaBEPSDmz?N$D#~W#tr􀰁8WTG~cn#Tq~aȯ?tşGAu$*<ĕ9Қ81ۿΘWF%J%_F &Dd*l=du O ,1;iJuc]l,%h!~hۣCw\F$ϔ]Dž{TRfHМK 1.ߊ\utʄ$OeO=jɁA\wkOrG_-cŃ~ 0=9st;aMEUx]e VREF^obD[!+ae!{z<] @',Fw  |;/W= Ez9c_O]rv.GO _\+u1%:|dFFufZpV8q -spRC6, N(F Ф`5QIPA^Jmb&ˠNp>UҌE4>ChoAw9("?'h֑lgO?<~={6Ïw裡əQaN~gkKslŗ!I 3tE:| KL4ȟbP=IΌ2S!Xn[&5pp)Ͷk6mX@qw>/B;)5c\W, ;]KB( 0悆7Z5tữd):cKC{.@SAUC9;v X>]"Y1J"LHyi8;gwgq{{l:? FlxF4|Zٸ$8` P I/Ӌ&s~M @ U Ih66Z"fYݫսߞ2OԌɿ!2jU ŋ.iZj< 3P| /d>^SBDk[:ǘKKAan.a4Ĥ\15FqO-5V^ʧ*Gr/` O/@+~qt|FZMm|D!tx)BJVՎpSRc?D:FupN/+c)DWh`OܵFY[gy5yb83jgܹ0jT=-:vzb $,bw!&]NGXaA xN)H˰- v@h6JKSMD"]: iX7& .=Q0@r 9AiLLs:U! *xuxv߅'GЊHϯT=11!1wAhV/֢(vb®""1 K y5<78p{S(%5B92DžTfW#+$0-#(*? 2%o0_7KN\RWFu5l_r"64X_ |"L9#|B˛//uL!~KiІu2wnL/S PxSmf{٠4s3EGc(!؝\/" XBWâVwM,z8 3՝e(ldt!ܧ9M,_ՂE,uv9T DŸXƬ 婾_{u (䍴>%:8JG|Nz*ƎG6x ,ȘR-˂ Œ Qj9dHan/v"4|\L GƸB~ʭK9MMMJ(;\>B>k_:H # ^U\`lv&>\Cn] U܃Yql9Y:PU]:wq¥Q x m-QqFOݡ}i2 4(Y1y-E'У *R qUlC˩VM.;Ijlʁ>(I8.ل57IꞋ\AށUٮB3 Mۍ-N8nR)uG#t6DtjyoPл?z8=dt6e_) iDʇ9a^V`IĬ 9d~XVMP@ncm_OB#QD|j;r=`ibL[u G_B[;;*4]Ev|fw7H+aHzcӡ@ҦkвpO"w_?#|$+$]4BRX?9LW=Lޞ(<'hRM3/GQ%LG;Q'r3O0z)EA rʟc*1| 6-$c`4" ע) ]C_ր|bsv]GKL1u26;7$zڒȚGZMKڽKӽ s=pP7+Thn˫o12F2qWNVx*=Ad#2W_c 1ٝ d-L-BIq&-A犘+O v@BhR=K Gپ);hY>sU -f BEESU'* /C#tƈŃM-!z*-93>s>a*v4,r̷_4>FjkboF!D@-KEd><ՍzL*7Fj(Ӣa6MrsD/p악;}hC=I뺛 ww[p%P2LAɵo>M;yvLa.͟ڲM!dn̕e>CQ)c Tc=!{,*S;=A&{jޘz6d&۸Ha'y!TSEPsL8I2+`IF1\^!k^]ڊ7|mq [L? ai\P9{G2 @IUԉ@='y?(f: ^:T?ԜxG$Jz \)\>v1H + h})|73,Mc5dm^ ^•8ƝD,5j-59Ӹ/a%Y65lF}VTu/^W4|p5zZR;k"H#J\y>tjqmGdhHqORb[6!JeG/AN9\x 9 4-\I~V>b %߲}⚇s>9Y|+H WQ'< aSkñ}RF4cmTu]HMeޅGvdzW#7DZH) "},q$aCM6q񹤠r3E^5vt )iA7p&YM¸Ϊ( cM b9f !BYEџbbn}HBkZ{V-T5A&GMJ Bwr)8/֚@N)Pdm]a&5 [.&| ZQL0{YQYd:8vPa F)CLKއ-~6}rdG0 *׈TLJna/P$=pl`pGDLvG[fnʺ?"˟pfA_O Wtzƫ.moO9Xo0]9f^$[ [7GԥWO2uZti nV|-`Gh^-x-:)`aLl*/JpO!\|"e~Ϭ N#Uhʯj-Kz=hIB7=qD2F`cUuO*j B#2< *1΄ȿ`mM`f!\@ ]ZTN?xҲZ&rOl5ܦ`HF7CMٻMdÒblUѣĬRCQ5!:$Nf+j^UPacbr~e9)nܴJfDC i&ck]',;a,@w82.̦&ipFni,|xVI_G~sw[ӄ&%Ԟ QX|@H%vdbeU~MEiS%B( |T:9Goz]xx7z‰6q 9Hꔃ',_@jjHƻَ,dĪ*b ϗ,gΉbj0vϿǓ Z07n 5#ToXu-G##ZyTB<NlH˳/ 'Iǚ_Gc鉱2=lZQ&ШOa LӪ[U;W×*vmFL8 QrJ*uaע,.BەعTUla3?wm6ٺ䌚!4Y2zUMM[6G-Vdf{@|8 ?e3x'26)~E2lXb!Z[K Eűn< n_x٢e!eKؒ@*<4ͼ3x'g Ѽ=+lYɗLBs7t}oZWYa/Tg&;2|]sxS͸Rt™[PN I4 o'CDM2. ۛ1剐w3[x lTo0$w(vEȯU4 dGuc&c 6$s$ "h7 9CI>4`=^B]iݽכ2˖9fd.>%鼜bşs:per]pEۧy4B ]YJݨ2%ƩFqz\ի-.A#LF)|::esMBjխ0 }ؚo O)Dii$qy9:"Rfcs}OC@E#!y;Oi콌Mrp?V[/Fx\ TrV =~z{$#q+MԺ RRG/0Cm"KKw ]b&)Y2ḰRcUN!zҏA[MVR=*/ gjɅҧKhf;8޼z]ih%:"- ;ydCŒ@H(DdM<:'_ϱD#k'_ۙ >M;~]Ote$9/Fp%)PlcKkQjh\j67YKUp˻B?LT5vyJSEVGM=V,"K})`wd@F A9K'6c89$W\tʄ ]}"ft"'dT3H})1HL <`i2z~ FEZǗg /"~[""W(^&$J8B5{5Q|5ճ 'Ag 5eݞ<#!4/b`)ـɺЎv8.2l OXM*AO4Й?0?N] ͫL/lpF,Yȉ Xq+|p`# Czh{.jf}+R(eY'S_re1ԙfR~sڛ}L@m*i Hqû|1h MB,!rc)c5=nHr@\wXs3oӈ}BdsuG ;7xjn DU", Ƶb`ƀɘr(5ϡ.uJNxN>-ޖ g2h|O F7l> 5@☜;yIP=:$-#FP-+Na$, >`oiZdL %2Mrd@M*$RKB Q"jyNJ@NRXrzz^*:7ΩkW+Gτɖ}d'B|9_bILcn L> YDcT+ڜ`&Δ8a! cJ@w/p52#-y=[HTzg3*|5!Gg}7#{~xOSw KےΆ]Fԭ|zA~=X݂_柎Cx=Sw(w',S[r'{J!%m|[ (چT9$*6J;#6艈0c(ì"LtX򆥲 XVM±n68(*=h?Epd=ǷQyxT2GGmҝ"F1v@߀kaK6K$]W!Y 7rOFmfG2T@ks+!|e_4+!fG[9y]3z;͞. _ ۵roվ?%˨/QfSG\ Aka;z-ɷ9@|:>l[W˔ucjE[]T+}zLJd**W ga⑕w's% '漕2NR)F|i{z[ٵVr3(}n8\#,d{^لTY؍ea,*b|Hw L&)WzwPK&idk'({{ԅ;\ed V*?)Qz^kovmȓM4u(U0 "{hԋgCO֠W)͒\y>pz, _]7ֲG'hD!mj{YZWGd^fc:Ljsq.4dlb?+ ,ͦ;[H'C%o^ɔ5[qn - JSďV0S din 9_pB-I^;jDcUg.T^@Z( ȸ;0Tb;-Mq=+l)r?~C2pe^Y]D$ed8k 8oW{]1It:-$97UWYls^6gl+'ո`4zkϙ^y%7%ۍ`BvSY.O%K8HYU8pT.0n>o2{y3[Ag1|'A9e5zSURê[bkޒ T%z _Z#VZH{J3EĺWx_Qpj7QDN[x~->o2}J$GGew7g+)֟kk|8ZP)d5WzY=HU#@N{z4L"D{,gGqq.@s_HkZ(j[ O9ܯKq$K !W!呣ժf/l=kB&B7`'xZq*jRM% ͍S.oէE12ظI],Dp/0{ f?':4T9!LD9h9$E5z~œ_әDKcmCf SoYcs!R%a3/? 9&|@fqGROvm5ħRIMZcw+0)?)&~̠ԤthG.= a 89A|b׬gY (+܇]ݏ4pQi= NzB :De*C%0sa`UM 7%ΤC_jnruGj1)sJBR+ؐpDpn5ٞ㭐uVmĐ: vX; v5:MCa}U ZV<6 1<m*ץ7h$:B5SJ\G?AXԣ \eĴRi&n-W7;Q\m0ɱ<<*G(؛Y;RbK #g3;YinҴ@ K"Ԍ\AbHKP jU ZSڶy"|z)KM45異-j#s_ԓvw4ӣ7F(Yө%[0ja+)UXosT+!c Ϟm??\sJL~]'Atk"M*.1!WjB;g\pJb&ȫV?X 棫T<8)^{#]#..L-a¦se&q_7 `U6q0= 홏xfʜΣAfY&Q/3N_\S&;6ָ&߉D*%2~FjM̖5푔X? B{ղt[cqq P( ; Zug>yFFK*04+J OA5[w5:ucY"\Vpwg< c| .0g^聪+ \R-L|12/~oK8B E/>2(@XKT,uv]QyOjY۬vqqTwr$Fjxġ.#ef"WC_i"_Ԟe^P`=% }r฾0mG<8aэ4?]R-P~(K`dq޵HNdmp9û&.r͝1Ǝ1!]\;q 'R܃P%;mMhLl#UĀxgMeehiI@X)ybvPtvaO!MI>kCǔ=D Ȭf^NwRFO.&!^"r9hf33ڈ^o=Og.t;8ەZF@ʭOdzK/RY@ZS.VA`O-B(s X|%= 젪3BsnpCWFc+!ly/xbP5c# "g}NW'zF1oN*'!ך)Y^ | )ATRsoߋ-STa-5-eڌ^5<Y:Eu^ kD Y鍑Tmұr@R@RlwTEZo؇ٶhu S[͹`: 4ak|<;oO7p 9TFH1eGF?{qBNOP r!Hd)'Ifݎu䯦!JN\_ZrpgYkJT 1>B+XyNJkh#s1 C9zVz 3ZE08qƓ?H+hsp9H[rG!P [tC!|nwN?e0X+3 )D;Kn\/A]ӭnwlNr(%{qA 5Q4Ai*jPN͇-dcXtiߙM] /G:|?Fɤ|dzg[d7v"[v/g?(R&nzȰ۩$NZ(W3L$qWIlH,ؚo-W*?Kdژhd2-tTwv|.. IH+/B"[h4j@\QP82EQ.Oդ,lnr[5KJ ?Nv|Wo=lf+?挙xli*a8|e)S&'#\_ $DӖ A528 `mUտ049Bmn}UBTTۯeB852:jxLuTNj'$&f x+̺iJQEU})b/VΦ/AU6]Il|Q .o)pZoyA{ն].jV y ƒ?Q>bF]Y{a iT#Xٴ$0X+ ٷ4L/oZ_cjh1).-AhPhh)l-0}RVÙ%JaEzp!P!Ş4mv 6|pE QĢj@?fD0hcy_UOQm p;E8;zs/UoD^/ m\HҊ>l3&?V(h[/U*P !t;B:<)c h,!{WTyܛI9s͋m+1q5lA̬s/?/b$…1Ԋ`τ-Px~-5 .uZ sM@x>䝥lNF' vio}+ZI߮3灱|Jg|AuO!@Aa!V9z ^ l I=7Mm\8ģkK*q=)ܕ͏p \|h 4\Vp'J5F)yKHױo(8kuF $"y\2{Ux0fm*Cl_% ,Վ.~VmmM%j?k% @5ʳu(Β""x <ݳ,h5 |98WaERiw`俳z0_83eO`E3 S;Io.ü86 >e@OI 9d^ӎξeFUHߴ0} wgw|: Ma,oУڠ9m.2\}NV┆ݭֈRUN? 4V,K3|<\EJۇ)8+҈mlA[N 7oi#_kzk lom~᪚F^Ym?5[L$ V54pPR z2u."Bt&6l>qbxJqř0z_Bl"QmK*j[Tpp'7^0 ZS9laj4d0|%{cj޴N@39n{it;7>eD1oi*d$ePC>}Yzdۚ[M7v]-K&j2(Pwxv2Scɟau\׳WJ[hPVV_>$A|Cr១DYi.. Jdv uPme2M&; ٘Ckv Ԯ Ɲv޽%VVZSH]R4Ӱ{F)iO,KvEu|Kh,[5XFU9Z¸.R-D7ܣL1OPEm/:⢾87F8?LσB&z20f47a#Ao5hv/'",KXi]N$&#ˏƱĕl,ۢ-d]*s{ˆ VoSB;9(P#|vER_uAQ9<p?% e7Z"aNJdؾ xp´ {VNu/C19KgA1{xZ"{Blddw} vX(~.?"v >:;e:kvcgkFj ##e @wzP)gN䞓~I 3`P"]Z93of ϓAOU4 1X]#n}#wZFԖU]4p8D9ö>\q6c5캈LWم_A[-.Gs[i;+?kؾ:<u0)/I>Wi;{7ʁ`C"0 C[5e}pDmͲol-d>,:5PǔoS*ԡv-"9/&V'Mď]߱mm)6Ǝ3q }S[UCSCDڕYs=0eLe.K ?$BK+^po/25Em!TV̕g$@qis/>;Z߸p>:p`Ru>JȺ.l0HRqix. _z7-> x_6Đl t^OqLۛC.;>@{ !JtVY9Tfb?.'W;p< Ln"cOr_*xd]/ +jeg_.*"3ݵp^s{~쓩TOd- XР Fbid%!s 98=!f^[ŠAf"ۤx}׋,hS[ڽa꒽i0za}'l~G:Ԧz${H01yH.PAgҐ]ôF1 Ҵk0-P}(ͺͩGo}}NlgE=O{0[ߌckťڏai8 ͮ^M}7b3ޠ.Wg]^w qB{рtMSl=l32W3Էr+ <8J~,PS_Pdt3Ѳgmm4 VӚ󘉂>L1C^ιO3|&\c~?*Jclg뫏Vƻ7 M>p%XϜvNVi3?vP'&4,_#I<MR 4(/Τ:/qD @8qĿ%E뀔l 5$^E qfa7?gxR߭`RR^*,_>8bWNHԆ.&n6zt? *6s=^ztsR bE(r(q.gh1OU`dž͸R9vsxm+x0ˢD;u9F3T]L[GG+p]m֩XM1%[?q݇*׭Yb()53@;+dɀI"j$ZYK jC@;q[z˥ȃaӮfӬ z/xa19]4Mc&~hlÙe L~d]1x'ʹ7%_ $%A/| Pb2֠D,@|r`J'|EP.QGX\( 4lg {JYT+3!8 ~U0Qv8ڼqgg,:2_Wi"GG1O1GB. N!8%%lԥpxܨVmh)RyVPI&x(5ÆOD Q5cZv@b"Z0Jz7UĦxBhD\M0pW'Ef4—nE&g?yt SCR Ó WD4.l;BY&-ۥե+r*˂&1QV7Un5Lq,Z?Lč,Ԝ+G轅s=nLaй(!S7pcC@ ӌҶW'U`[+(l:=j53^А=xys,@A `w7nL8=QKߡdפY0Dp=\~|R<7I霎z0Y F ~ p-2:c \RYCH9zTjh4*uS\dMջ~p)(XVpt`s!ӥ]p!)[LJ cU.A<ڑ31Px >q,D P-_]eMeۇ}σz>G`# !!̱JG)T&U d?aT*厜tc6PǖsJ L3@M*5$ąt@\UJ_Mg8,s Je BTK]wYæ58 Oy^CnK loӇ-5 KZIbh|ߩE~P\=EƃMz9@ɥE&Xl|`휾L\|'"ˤaq_A8~Ъ&2"5Wdk Rn5"m@ N/m$=Sw{}rIh}s0=|/֭1Ĵk+8kgR جtc&WpnLe5yL!xuVn:Lgڬj!i.PCv]rQi) $4:_WfaG|&H^p~^y6#8I=CQ2}_F80#x7[d^?mLIFIV3uM!0I$u(n]Šo`-:'JU2UeT+9'}8#(B~N+}T8GYs: (Lʉ%'2u`A|櫒SfU;4"Dm'Vh3?>Sm5psfClĚX@ !9Q^BLTƢIqb&sFRrM>]Ey9&@ ޾O;Q\1 4JTrbI*‡ƛyE~:"nwt I)}8I怉ĒA+8n1$-1y|3vUXG'F>: $Mr CW^vE5HQ' ,aJbTdmw);MTƵJ66%vY>I>uL灃 qDy )_Ej K,EFf`UPuzQ۹9 c>J=̝u:=$w.c7^6Q">!fACe-XI,,26Ӎ >M__aWW5o࿎MR ;,m$u!AL9`n/~.Kd'IB, `)XIVUW;rik?BfsDem9د>-`dQd 3Л߻87$t肥b^߾QTŞfsqs 4U}? 8Vnʀ8uV l2f5O16Zp}i5?9-8EPuRfMrPsvBtCqUʇ '}exJfQI/HYⶵd]2>5{ \>o(5f%ȝE3E{-./\Nn`y%y`h[}|=+'FJfv+FTZ ;aAi LX~i1B` uá8e<ޭBrtg\FL'n$<m`R<GH=t74hGiՐmӬSsgȵ!3mV1͘f 5ŜF&|8Αȷ?fCUfPQ(>q+fB1l_(I(ll&l/Ss04Gtxad RsiyqvP7{hL^vNTSO5 e;Rޅκp$R-uǥBv/.x@tC%DӜCBRH|YK>T*[L2@F}J&{rɉNSbǡi*G|/&Qsw]T o4DDSч4yL_ۻ:z q0X Q$:6"Zr|atp:?(KS~&ssʱoGWRBW:EY:uN'i1b :u=g s; xEȩL=Egz1$0ծo=@Wڑxzgy_u+SRpu(}>ijK t+aFP~6h.g"#e0~.+IċcXn+*ֆ2;ٸ׀Fh!S7#5DFܯ(zheNBܢ,1zjM92F.-B^՝r׀ PQ.}M ]O0ޱ3YU{?9㛨ʬօK'z&o[sb1 !ߎRrX2!h21n6 G|>茔, 28褤K:it=VwmG >vi[K3oRd-+M.0+X-IMqɯyy mp9ΚT|n'tեgLP tx%Z\f;Ɵ hFaTtr`0TCj32J2:Oq[v(3E8OkyQYruGtcNw37@y?PTn/": 35?+X:u\Xj0 W⵹j,$\BMszj͋ϚG3-?"EأZ]Y㚖OB4 W =PQ펟W~FR>e"`EJl `:5RaYol[vX}IYS98_b0?j 5fާ@AE幏5KVЭ}# tLNYVUե'\r>%1~&Sx?K@D.pr"ˆ4ġ{2j> Ƹ-NTJ-)d;lDAi>},]ʐԸammn̍C ?D!/d/,ؕ@y93/KRZY+R-sP$12xtlIźztǎ8Rm/yF!ĢmB=x6uEfz̐s9/Y?6sѴTJEvLJL=o+#d?Dz& !rN)HzLΘS,!hi:68AjKeRWQQS,OO5wƶ d5p쥣OKJeB[&&KIM>tUB| m"u I>̵Aםs/"3gc*D<--%2kZI8SVMeM_BJ#u^Wt WN:[ aKv?Ӻ4:.zHo2?aG[ScOfkgX9Ԛ bLnG|a4l>}ȂF*`-Cn##pKeD #u|8\RI2eQK/6 KӀ݆#?q;~%].gfW+, ꁢ2~ejoO,O\m.Xkg,s&BvPV Ax5[_E$(Y%iü&E~6PCo%D/" !/PCjW]tU"Ujar()wI6Q+ Ńu~wap_ciTJҏ2gG\G3RdTu*mܢӦ$H#[HQ֣HO֮9"j6Vgx(~t,UaU ̣+@5kxG>&PVY&ŽIT .Ü@# #kGW+.>6xqr7X&VӅQ-隸EΑO 䟣o^"[`H\IG;>o,D캶d6e #:Yk G|BO"}e9⍅xtY ?jVuhM`Z sowX끦 ԺD С % 3#ϻz^MZ_1]f?ZSoȡŶpEB;1.MԹr WZivo-mᆪACx'D׀R|FDo]MOh!,zDLŐz6I:3&hX3G5~3?L  3B|[݇5NA&l{܀AђfL".ŠoG02?ުzMFv}y \] l_]3])>;ږ_X!Sba[2YӖ jF? :sQ lNĽތI`-96w.eGeDYw~/gxjF4ayU02~~=Cō+R护fs@WC:B O+Yx/%cI%udt=n4qcJFV:B42z.]]]J-Kl+6Qo!m R`.%N4ޔQD 3 PIdRHWGiTI NaLT!0U%(6{EkBE0 =gfDrϷEn#P7}SW;2vYd.dR)$q0F ~\Ŭ.-˙BEHm3%bԹPҀv-7Q-j(B/;,ZCaϥ>i1Lβ92R} 1ҹI[ Lk'-/Jc "oBo* J _MzAhlÉBE0֋ lC)Z^m`TE嚋}%1Ax6ߢ~ _wZ4ڲ$9a7L`_ 6-57& X [Vl㬷%&{o)Y(ίiЕ&d+.GwsR;8LV2(Y(@b2\;k{lAI#֢ǕOyJ nJV3n{w(mISǬLf`JKUZ&k"GR\ĵExf:VyFEAWD,!pA2 ݑouxX^WNu:E7ʊAöfnc΅H9' ~}T#M9Aosr^*?oҚeG 7aMowlxA $Y xhxf0-EvD8XSo{mWv3dd}͹E1#MUPτir86.+۰7M0">Kx,ILz}qޤ.>[/t:C[@"E~wB'\i%bXzq߀#;{V |B$Qřy0kqwrUVgFtulkb)\@D<*_}–oPuIwTbgI-Т/ >s` X`lkY+}`o'!LkXn(?7X3D2$ZI.VDЙ"Iuǰ ~Wɥդְ hvWs M ݛkUˡj2; a=W\jrPI2|ne\6tiBFMzmbmzʷJmYFDA\ˎw7ZNfD[E7(wVn3.3lJUF ~M#?m(ŗ?.}*i:Ųst _ڂ{ʤx蛹8eZnRmmAfr4W*` ̝^4kigQu7inm׭8};qgY/*/i߭X`떛g xM_5RL\ Â]>k 49F{ s *Iۉ,aW=0,6v8n زɝþJ^vj}rUa},`]jhuX8 Fsp0>o8z.7|=w\Rx7//bk๻{ `U)694$bu HIΡ݁At:] [sFXӆТh#f֎QS} { r(T$&S'7ㆠ̵F +6G8??$fZ\Q$o7jPtql 'N0Q rΝX6ѧ?e$9cw Bԣr&h 9_wQiOu]/B]֧4}-r #M-jr N X qy=ܐg%v4~ Aa4hNe3.H̯Q& KU(7d8{6cj RN iTzl98t^_dg{j@"|3ך]-`k#:"G,B@Vy~|k0lc{](F #ڼ o[Si ,%[%makXٕh uÛ2"ǰb?@{檓_!pz$Cį«wrW" H'Gkm7j;#\c)'ty(f*pt0X6d4~;>:ⰨNDk: 8Y;.d#Cm2E)C`@2=!iɎU(;wZ^k}Y&E".!H}l:2{ZNuǽg ҒKy}1s .7i`b*üWbwһkhznL ,C#rWXZ3zdY6.#(hۉ+ 2 Uz0؄LM;Ҁ'.YgQ Zɢ V] Ymii.]̎ XFY=IM_dy/9z=k\] /C؉BVJP1,;uWZdwXA"T|\&,6ϟr`"kA8WOɍ%&iWo6Q7K"αP qP{kjnL^M9G/ʷ&1=uXXvc+ +߽N'E_ $az[B{+IŮ Ss}M0Nx8`BGS7:\=*ԐpͿч~Wۊ{ aUHF{^P)o:Lzmjsv@H`zS@޿Rf+:Gq;'<)NE9`(@XFN¨r:bEwLq!-kK֏I|F(c! g@&o Ʃ|5HzH9@ :kx]էN!BA##٪3ї>53Bҫpm8qzޓhl059YU?\?B(߳keJn 09Գ'W%)Rxb[$Sr9y6^Ԗ[J{g5}[yrqkx!fAkt*zٕ ˠNn}AޫqcBzc? AapmXႇdƵyG8TQBiFK1SPK"I"T~\va·n%KvcTWOK}52D,(D7CR/z#xo{*dvh?+q DyeD0deO`~Gl@a^Ybct)0>DMvoVG^q_Y V02w9BՊZ9U( Ƹ -prhs^hup>#dMz :w~v$o̕eI.t[M嵲:HfEau,Cj1\ՓUZt1ۛk<&2ʴ{V `dS%*ض1N|b]o@ [!l~,lua>ulx#S&| \|_{ij1Fd V8@(P ttqk&::>KV+G Ӂ]"dX R<~]p\tgCԙ{G@bfxi X%=ﰳvs8X8|?O|D.~>xhB{\<&Xh{!}K7GG qמjҧWf*j?LORoUΊwUƘ3b(*㐊ۏ}쉳JY}[c c3,pI.iDhVrr0C,2|O?G9Vc$0FOFUk)1lR@+lp$`ۙ"hBS΃} 2T FF"'  *+NS`̣NkpN5Z; ~˗).lxvTW P3u^*`oYg|Hc4䧈@eNY-lwY,*4ɔ)]\Nש!s~a׫ALAkǦ|$e8z'sIS~0ԛ-ئ=K9%vVZb([0.ju ~útVEe<^*vkhR?B\%YY zfm\ܹޏ8Rz=@ k} Hӈ|Dc͍o6 tZf!Nu_ {޻uő;+T8mf1U%:xlr}s^v(Lf82br w:w@!Yk裧pU;9F}~´'4.|(JO!XcJ*$,$drE]h`&Ψ4!@]?-h^HXfҞg`ѕ/kJ,^}뿓*`d63 HJxg8gFhkr"{F(M* VYg2CXmKxeQZ #ڶoٗ> uwj)W {8KuԉU睁GW㿔("AW䆼tKs&V ۾=HSj 3XOr:M':dP nal&5t{~X/ٟ8I!#`g<:s_䮁xr~py?hEڝq! l  0^OZTd%JdQaδZKXs:j;C,"Xsn0bD˓XG1+ҔOCZWI܂!Cx|~Y!umyHpyt|MkO-|fBC;R-VP_i$P̚m\ Im[>n59;j!ei hFXa"h|ۓbls7HsràhSH١aX̧ξI"A`nҬx$\׊fq"1 d7B疵iDKevR xjw/:HCQˠ*7=РbA8:^ *ίn~Sg&3![Є»}TI̾Ȝ/x)tPQV~'}aDR= z_<ʺhdYܻO/7{ ʩ^Ba{=KJ?8IGtG-^ D]CT`ek>z_;Nߛ{$ؐ.nX Yb_hq,ٽM }є>=a}LF6J9Gf4b Iv)[d Y:3A՟3m' H kw8~)rYnx9bn;nvC<}e: q$F:Á}Gn6ajgv*r>ARzڌzDb8hcF ZfK˕a8Eu ;z|.AxѩwC_H;}hˏX! k0sX)D^Hn'pǢ>d|G%pCq*ȒƁ ؅7=y׉M|GZXyeNl+TOy܌T\7bVs/V'S4bwS4+CLp})uߛ`o&΢C";eX|y8!,l:]0Li =.T ! \[ʝ)Ğ( |ǢJYgɐ,$~KXztUhAmXSKQم88V$˛s;Js|#Yx5μ1]wBx+_pFhOl vDYؿO4mk|rݥet0%M4 fã(͹;f.s/&[9!A+AQl1KJ$wKBL؜2j+CJVFsʋZrkBv6|:1ln*NX<։; P/l3gؠgސVQy_ذ7!åeMsG{q6(xS̾KN|$꤮Ճ;d.Mcum+}zd)L*Q#j] > w57}zV5&(c((#=]v60Űj`.RyTA&ּ a.eͿZ1*l񆫢 &00Q7c9%tP;6- eAh:eFp1OkV6RO> Rm ^QtM!g2' 8Qx~0iH}:Q: 0 PL%6>*`/-Q]yqq|D+rE9~VA-Wr5^D>e똆MAystuU ט,|P~k"ܶ`<7T O6Ḫ1H'9س#cNG-qh{p_Z77 !\^MFꊡ{ Pg;p;jncEDK7x>Q=um|X? K,PyʉAf(x6\'J2 (P~.6aWtbOx|֖@~վa5x;y^MrxY7eV0h$oDy@i.xҐBވN<Q%5En"O.+)c(x.).0,z' zOS^76⨬nbo5]W֍g1-L4qgA1G6a] ζPѨQH"0~`Ǘ/b8glmmH!^@ϙ=M|bu1XQ^ k)GBuO@؜%^wN1p&/\ ^"wC'1(>m })$A}^甎1NC9+zSi b;SEP(.N yTosr4`"u2'i ~J3Hlx:=7X5UrW+i7OAUf5{g}ؖ")u5Ƅ?nA |4Bt$g$_!ʰ!aaf{DNj+#ͨ"$EIRe5@]+gF"SQ0-7\C:V FjDdh-U(p 7y=;v? > #%*Pe[zZ!5tM/ WG61k*M*"wOus:# 0S#ViIY"zr!R; Rn7/͈ʊFD<o~o|!۱Nҝʂac[Rh-'/L`:K5D@*yz:Z[\YEA~ >kG7bAcj"nҍÙ ͜ }| /&'uU\n3qhaײd ňDttl54< U@ϕm_g$Wi\3bp3ZxR*}fj!e1^#v.&?!7t[ #:q~M6V!%ȩD&>ٹ")Nr;d%">{É ` /:Kj N^'k7 /d G:!lTںu7F_-H_p*0yEN{Vɡ8Pe$5 W_P!1@[:W/z֓w|S#sk=%Kߢ(h@_8(B'h>o0G7~ڨJOpεګkLlH YM:a8-āP&ӵR&./mz2< _[OF%U̺6BmCq@,7KFg ~ dImW@>vtVɖc]3WW_[k0#8Z;>C>ˈn`K©wx[һE}g)fU-w^Fca{3MHA,„O3uF_ )D0Y 9jGPHIakxע@^_DS/cCoXdLf@SNC lF9T!6r;R*fd7's&Cό> p8#2\ϝ!_|ۀu$ ׻[uݪD@;5e+ޖkx%N[:kb!xV0XwQfh!s=-Nj4KwhƦ]fty4Q"_IV(T5OB:FVUh ]KiC"b.tټ$\@J!-88%ը_ZY,$B^t^!d 0k5!IP2ShQ Gc6^A|VyS4-tgf3%3o[B.{L;Y|ۆ}(?;_Z}:\ŋ܊V|#x-G+]l*Y=E!]AL9뱹ط S~z(7+fWVFK9.> %IcO%^v24 .FzO\\AW5bxԕk}q&.H!TW+b\m#ֲUxUF"JG}4_EA张MY.(1Zru1As׀ %HĂIIxwʲ8պq$iD˥Z :QrdNH' WJ^LMk^eҫ {o44z ZV)7Vn=|V&]s>#U 3=8_f Şx:zUc'Pb-dfDL/(XSԸbv%#H`HXbxʋ ~3MeI/ru6'-q6 8t[*Gϻs}Urv89P_(f"{wC*W *xҪ k,OU_y{*͠%[%1ÿωGR-H,fa" z8B>%iȬ2(JDpd?0qPD1Z(s㮪ډ 3c 68iXq GNB D|ߑFjKuCЍcI/*6[<*Q `d p]ra~8x䬛O BJU098WV5 Po S3(!oif&D9XtB1+Qhkriy,IN݋N;i~~{5^8'R(ca2V2J shPSy|p/ g>1ѱNR"Z)ICBt(,$ҙݐ0I#v] p HE:'_SvT,T|eZ;eq,x̔"$k5¿,@/addW&Q`=Cp`gG v7V'-5G4("t=|C.]%w[i9R/\Sﲾ~rN` HE-*1hu+W|mͱyH}dLfO-A<\tg(%m3@IAysit\3Q&0G jZ?$F|)y3~ Z&uC |yT#*A HUi/%|o}oL5@:sd~VM!: Ϙ̈́Ș@Hy4dV m#`r inzͳdXՇR;`5d_aO"wVBz0\sZ<h M릫"t;w = kxe> k%`NԇPL8̣P`oj/L_-R~ vj[T٪,Fڞi`]9xy{>İӁ5{yDK<2.ӡ8XXg7 "}}"? ^|tHAiqt1a8|&H67 @5.Q2@׳%?/ qe6}+ݪ)N2*ST-EgGA)s32 %.5}C`6^Zhᡸ@"VaHBПQ>jy6(U_ % },'b09#ƛVC_E;^[y"Ox 3mء!V`W-)3Hϒ\z4neRd!@|OU}?([&f&V❵Z]W>IRi_j1(7m7  Z0Ogvt JtQ ]uVlr"vxN_WA=pXQ10\ibsV9+1` l(0%9XZ GO֬{}xͤA\4WqpŎiUzEאټ/vHscG+;Ay埗Jl0JO.vѴ™zu %1 iZCAJ ;X7W_ O`d4OjwIX:cmD,wMrn A+ʇJ}\.>wǧ/hݮ/XV l%| YvL ](+W=3v6 vGjol%Yqt?G}Jb=&_9T"Ra4n_Vpfk' cYZSxԷ\#p?zRIܐ #,6@1!|Xl+V6 ! x!^:}H&mF?~p2M4V07 VԤ_$6zNR6NG񟝻 >0oCI"aE P5B;icԒȜi[!CKAkd Ui0htm_{Y:SEูzJV.D')1 N5 #3EO7?(:0"\D )AM9k'aH -T߼&O擱?ԫpBMf)a7kMo)V(77&yo{F0@CVEȠm8paۛ/&1y™QjscYyV _OlZ~y<\(k5`"p);?l7J bo V* 1,6Ȧ3A%z-g5^t2&Ų:VݰA>uvy#.7Z/J:yAbr'Pέy6Lq߸z@&qxȅUP~~Mg|dP#o!SAN#s3D2*}y":yٿoMe8Á9Q R"1z؞Sjr670-e $Rv0WM{i*_3!@ze9> CBB7͖ c96-X>I:pzhmg-G#)瑇9v# GZU+6tѻn&\|<7ozSn~C`HH$֥d_mk 'dyj~XZ95e{PRVS/>\QWM?95C!Y?3\>iن/n)G-{իDw%/;,˩ mb%F=f\PW$ 1m-ɚ0a0%+~FYCoX*7Ran@=\ɺ,`e_-oArh|gyT=Eǹfl>g]0], Խ|I*59hZܮ .a L0qa4Qby&?#Ǒ)'U*478 Kp=ڪ%BQ6kHv|=H΢0庢@NkPKtL!p(rW b_r ^9#=zfV_$N.<ѡI¬?#bMZMeCBgߚWNA3"KK =94kIOR00vLPA&d2T c0\X~WP$ .Q0.'뷫*AU˦ejPͯht{М%(P,n&ZG00Bȏ_dVʼnLl'_]d0 +Nj l:SlS=gzPF?Sd LR(XQчmT : Z.K"Œ{QH5yAQ1mpZIϦ0"[ 7#_tX ~{ p2ڦ`R0[iEQ5&! xеhhGsVC1D-nW-gR/FAysXAIxg0;CQ_bƽkGU5d$- + Qbk޳̻ =n娜iG1PA<1tG+RGuřewznm>03 (qi}xO;{ԢPHԁ'}_RD{zC?,X4$3w=|:x[`78"ɸDž>Go_gsu8T?5|R`Z'=wYsPA"s"">;` o7|a-"^Ӌg$V^&bһ[{*tθ,Eӗ,NώKZ.w2 O0/'` i>M#Ь^Jޔgq]^~jM?w"mGUǠ8t w@rC*61B &,%8OϛE-6ɿLV@7pq&Hj$MJRIa @m/ǥH@Wߔ-$7|@ eڅz~U/pXd{c$ӑAR$ PB20u'o4˄V]CJF7s$c݌d <L/FNWϣbG)MmDFAS펪^HqM]{,'ftL-ػ4n}Q ]zen\&BOXqGlHܫZS`h=_J|^ypijIŗ'qKŜvn$v;ܢ©JtG2f2+!`riC Iv/"YH}<'ѻ&U1v#؇po(6Rpi2xdZFF(:7mû 2|ãez #ܿ\SI:WlսH-g1<׾$WE/^&'bE/MxL"R"yq PvYxPN_h1[%=@kY)'˂<:]ix-gVn?ѩ"fA\4Io[_R>H7k+:[zq甊 ΀#p_>hM,p#'vp,N;|2EHh0%9rn4!ؤ|=qvF;f iFD/,\Lcfz) ٺE"ɸ$<(Oʧyk0 3[B-9 P;/m OBKsaH6<ȁhvI>biGs3YMaor?a)6n )M1å3b]qnl? ]iT n0@.v(c O[nO,Nҳր0s1C@n1g<%8ĈMGVБT%5 WPT#RН%a\.!6tS9~5IڍV!u1.j)]i8DzP7 (eȂNF~Ta/T;':Z3v1(+⍲ppƦu9b uT&X[GwTՓi|T jsh:3 wuo#W@֡_NfFVr=]zaE/>dEu'pK+:/Հ0 X#c>W٨(R,W'Oxg/?%B %wK/5e=;Ȯ&OJHk n(z^]ϋ#$1(VvSbV0-ɚ*:(j{$XSAz^%{J r{gPi)G~#gʖw])ƯH/O \^U՞1F 5r=0[CHFkՉ(;:wJq df= <# S2(#cV20dfRmvRcTeCl8Ѹvm91BH6])wLe!Otp:dZ&6t֘媙h5-db&YL%cZ:0MX_4KFZ+#nn!mB|&2F \K#~e4.O_voM%ܜ_ONI!ƸOgbL)4$Pq3dꞺ& m{F9 ͢FpL~'$1zza-LtNg\8Ohl]єjoNp?D툱Y[Μ}3#p -}z0H~ t"" xIGPّ_:'-`v~B FÛH 63/dw'ުrhO vBR*^W[HPi|CQW~~ Z ZY!BAxS=)MhQdL߿ g̲6 y8}QBc+dt}ʾPNVGQ|!3<;L;4Z ns)e^~Z-=#Z)j=[0 B$lK' C2xw 1VRzG vͷ{;B톞Ӕ&|+;Ag;ThkL<@T 7KLV5YΡE/imWePn~<''|5 #NCyol9਒ړ㍭/ЎuRq`~݊3UhE 4^Ue_$YUQl2AѸs,U'$]O=h@7 1=Hv}ZUi! ZM1:yNڰBUT?続:O;| #}a?nѫըސG!Luvdw%- &:IPL"†  {BJ~J_  'T<5{ĘP4ܧ` /s/šzd#;(rTLEApttʞ^5C@x&f>`ZF ]kY( K5_ V :呇fU0uYnˮV'HCARa\lZ+ibVʦEXe+B)<-Z,5״9'VR,\ (M ʤD<ا!u Ϸ+jXv\iBP宏~hWܦ]}-rV.Qgά+"!VliQ%b84cak{ 9m~?u !J@XsavL? _@q ?[Qz\ͮce8E!lcFӶJkZm8tQ`PAn6 jʙCm/RqBJ_>(9Sd!^K*wȢFO_.ӎQ9bHnT5:"lܷj~;WR7@MYa2 u4ZxJ |WB@gi 2OV ݢGGp}Z$N֐הdn ޒm+:Ba%5O$/ծU\>q"'Y~ˤw,GB6'gE;`)I vYHw!Yy<+\Ӆ)`VˮwMfrL$o`RLNj$))%Gr{ɓ:nB,} &}E6_gr CX,Y޶9BH@H א9DB{xҿ!I~2#1-첉p0 ө(F:t 0 G[ѧ$;'SV`4)0#s XܑЎl#d_g~D=־z@'q :AB̢(4 GG }˩͌W*9uy޺?~bm}{ eE|IB|"r5leS)JI k Kw:ڸ`k[!<SSwyw]jm$n{'f@շ,|CaGZC!A {}*Vx 6qnhu n u◱|qy+zwZɈmI-8vXmCtB5o z[jx[t-oAaˈ7TGK,]%*s7v핆C+%y֞U]iЧݔۦfi}Q1(PPQPc,w#w7ߗjh;'<`ޝ#)(/\U "MڴjYh/VQ3` Cac ~4Q5m;$<4 6hLY4-*{h4M KGy7Bb0MO0|;rH Fj [¤H]T~'M BuՆ!XQWhR`7ͭi>5Xh ~7;CH[j.oB)2|ԨNQq.P" eUyy"!J'|EYPV~pJ FT]Vv.p}(:39%vɦ5.w"y Iy&&V0nKNإnK3[HN\FaZ T" XMv:P O_PY7PTOR  !9 90* :0>葹1e`{eʰлFj/֪/;xuX<g1| ~bpJh !Evq9Aڪ^%V1KE[qԸXY;;Rȫ``W\q|s6Tcx".FY.rch&,D:lHw 7'ՙsñިV)B詵Ҽ)p{]OV/1^R|6ˢ |uV\)\iJJ|(lq`kj-˃_mV>P!jty{2"<y%`44ǸqoqmmxGsYQrxj&jia)4Fa'CcX6baeN D-Ο+`Aέv4W ʚBחZ:yu&5P(Թգp.cUoѨK$;{O7hrU#NQj!: bI}H Nx&_vhӆXCcZ9"dnb O͚$_k_]Tlo'DCk>ybHPm '_r F7 {Ib7dAigCy5M6m VMQE&:OBzC?0-,rVQC&㭒qDymc\.u7"FDupG%8.>G\V2[^u*QKK֪Uo{^-P\R^^#/q;,rÓ6+]rq]/zFZO XTfP έC.k+o_DAC$MhPĮwi:QG ߢʚA2-aHn:j)ڛsˁᑩ=vNAyRDcO#\5`qX kJ,[RGkCyx+]ίR#Udb֨ 1!8ۿ@̲լ41٦բۿs@Q:e-4K7lY1(!.xg-6Ae:K5M"/JWol /dXl1FI.=gAf=ۤ^5S-G[r[gXU,݆ }S o##=#GaF)L\b?&{3$Zo/)vH1`gc/]]9CɦOa!?:PTh* Rc퀻1\5z|&{|@eƋ3-k'0v q7 p$%Yt,Ń*!<^ҲVFyVc}ebU57^cf>iZa%TYYQ,F,=l-=ȤG[LO+mD9Nj-;[VfcRVr kl\g;( gah H{)hAv&`1CܽDpW'!w{~~Ttq1 X ,(?"Q.*!rGv !t d*+{@g&{{ ܿ(S G#J}z<y^km8@\/1D18CStJ2È~hiDATΏc+XX*lfA528Tʲ4e_Ca,HYd4+?'V=r!;9_L "`Ј}!oEf9VB^Ļ50˜`ץ UuuB^L(Fp؁lzU{ZCX7J@Z.S:nhn(goQJ/r:&:#'B#xU6KޮaGnв,E {Uv1 tweEucKhۯ%in |,Ⱦ<4oɪ:W| s#T <isJTuj^Gt?[ʯ>ʆRVH>6OPJĖu&’q$| Q ,s:1#r|M;,Қ@ѧPm<>GwN=Fm53ըΆf(r2:D!)jJs_! \*7K#/\;K7KJGxOe;6\FqFn&'7`O"ʒUH!jэwBż;T[ _˜ගZ9Pa)^$:fK^R^֨EHBlSNkͦGɩ dnnPzNY,{/. x=k%]d[U :AH}y瑭C컃 V&@_哆W|T k)qD*Oi}(!]q*SWɳp/>EL4Bx <-"ڝ&K`jLDvd,^qzSzj MS2pZ ꉗ`T&v- xs;Q{-Ϣ9װe/JC\5Y`NL"&ߢV˟Љ2sU!iP>F<~Xխ ]&̓YW+'&o dBCmT pg\$3ug# 2ۤNYy!oγfSL5g`7MF=7"Zʣ[SsGd>Hc(6Q9@v5l+Aq{9uQE9j(y(1yeS7vNanZCT=Y[@ԮvyMx}`gaҌe6#\JeŭZ_7DoeRj"@mOjt aM hWJT&T*DuB^sd

* o4v9/Y\E<7VO@éZ6jOb+b^py)޹VsMdE[mqZB]EGLLa8O3<I ե2-;NSvrH7mŻ1+S)Fa]EC/n +O+\O(02a֛Ggsjf(mo$<@Ӓ_h"WP >ulld?w焾W* >6ѵ,Aa)'Q^7 $%(  ߦ),C@niIwhk^;!PVw75h4 RDh wgR!K5\,wgُ$IЄ&Bxm CgEHbcn/Q=` yVy*mtƆ;H- 9fZ!e uz&c9c-8֟zGτP紈gS&qM8×X:s瞤Ntd0;NX(lDsGmFLo%KDY;Ck'RYnq6I%`<ȓԧ $6R<&ܜٶ9WlPy>`ji:+wRl-wg>{C?aSDؘWj2,6 v/Rq^,ݚTc4yC]~:zgQF{vv:DmW58cFC# ޹O*;/*` cE&72Y:pUJG}MPh֌!!&A/ܵbD{H2Nj-]ȟ@+Aj@[%4JJĈImA@ h 3@Dv}an@(rGXʇ6G+`>%#ibhdZ#!;s߀M; a$L:z G`=1-g lI'V tz.h{wl8O5Cx<Qx9μžF!x-=iY&xz"]ֈ^aEԼo39p)R}EP%UڜSymKw=7&#zim,r~x.XGK)X`,4MKnRГ1\+w )0Y_6w͓ӻ~pWXy_Op;j4▵Buި:Flxr4Kx }s8 ;qE+]E5 "r@/h5 ;yVAjS-J3T%a*kKS˃dm!z^}!zFpNGv/v"[z229+3nXyYKd~zHF9p1-P@0=x>90Y{ѥU$ ń@@+ 1A:-+@J:^krw< ~bi-ʕ_fKeXKDja$a0фn(ߘDCQ˒aR/vwzi522vݲg LSYgOdQE ʨJP1è.4YY'ZD5d2 *f,/gmR229 ּ@,' hMVD v 8T^+ 瓬L,$Rq I+'ncS4FT=T@(ؑ{"($6&lLH Q:_o>/J*F~LDWɑqEkslSl2 M*.%sd4tw˼#[x_ 2ZUqВlOQwr #oL1$ ЖإDRH]RJ+3iE~2"'@s.`1OH%K-T Y8δ?13ݨ4b'@oZs\O=BS4aш%>*lG ռnW A@ ͢4:ሞ~˟] N Ί|`VVq[){66^d#<%Cn|ׅAmQD E›>YPzUrzb7>O5Gm܈+,F`q5FM.M:-G&HTEifY&.e;Aj&՘pj\\証‹ˉ& O'm_NjWD tK X$o /ҭ~لҋ,uIx'RCBJh[H vF+-掽:䌿؋ݠ&\lhs#-7fjлteAm{YoNm2pd Ȅ$%#vwsefգv8MMZ: 1bad/ %=zf?wF.Fmr/ÍLB!;NMeyKjWeLz23i]eEzUW3ht8FYM< 1/dn5ZՋ/7psn dQ_e#wn^\i(H|.;Zu"fLF;f"P2=)H4 +"3TfTl^"wj 煖/Q\Sϱ?Wn1h s3v+~{=+G<6oUip>o ުa+"gtc[u)݌yD&~ְbfvTa7H{/|;8yiQ"WC:3m$(ceSi h7.Nڳ@nu']qEy]ѩ߃gV޴5uQ5:P&n D;=#eަsUِy76LԜ *Z0SZ5д׃ jRVs_#0wGyIyzN>`F9'Z23OU~OUe^8NXpQAQrY8Hk r4`s!vE1 vp_ƝyتsO&ӣ{r]i%!1E\20>kB#=M9U‡YזOzL'\<,ܣe-]%rY=7\\#J:{bBQ0l{ȎɁ)49ċA7ϡGʟp&2awC,L w7MqϜayJ&_i3TQ}yGN&BUzo Bw|nL6pU9X' /nΏOuÛ^+a١&TZ>.ӝus}{7tľ-ndt? 6(FAYH7rBѣl(cqzz`AXd)"FN!{Ƴ#Hؒuژj!e?)9Q6÷+ A;~"XXBaƼ]8G.Dt\ATiu| 7\ͦO=Z~ܳ?rv*EMRiJ6 &lR[6qngp$gGV?Jv!/Rn_ŏ;9i + :-1i0y]C2Ah,X~tKK< \ȷ$l,w0]]c-E "n Е@|+?#Il"K6Fx#ɠ#f*5AHE#KY|PnP N$PecC'*cQS p޻LVNlǕ)'aȹbH"7LW_P6VgU|rrαNBHRne@pnE!e`Ғ=L+]Bnf8;(:)BV̯R:H;r$RFhP m^&Vw0~T8t6a[ 2xh?2'@Dᲂt6U>.6d lqk{q'=ȁ״sF;H Po"l0¡sJ<ʉE䅵"ȟ՝Kư:&`|39$*;^7聺tv&.ЁwaDGܞMnfR] R*4gC2YN* {vmNai2=6ͿW2EKT;&Yb}>)lphqTO$Vd.Bկ;8)Yu!ʳ0G|(DAB٠ skay);u :@A7X J`E-3JM?(G-[+#ĬzL+P%D3ԗUav{B xq>cZl?U=Pwx/2ZϥTHi99EZ/ksNfrd-\;By7G}1)la4un˵ i<2<ƀa4z]%+M?E5eUZQ:ӗWNbNL 90z}rmU˝5Dyhe2~ V›fqV6.Z a" 0?Yu1^ wAiO PDed ]qq̚}ePozOrrk:)IQ~q@ao1RT cvazgj4,c CH`=ͣ>,53Z\C>/GW@)r_[X<~Z3Xa݋Yie2M -!Hf@VH/ ^yjw#-B娒@@4p(\IҲ 5n,5iȦ!zy'+Q>(Û QyD7$ҴzuRv#7;cD&=gng6kX. 1L3I]xHB\tuDX .ǐF$nl%#K w`!>*w=X y7|q[Pwr7Vb| < J2QWzr%u#t[})F\xVa # mvkox+L<=.%D r4(n@7C`)F`tbh; Zl jٌ L|P0ft6[?ͷg\jO3Q fnW-cPm/6R"w :9-zEoHOV$ފQ/-o %:6~ۖ/ ڲg0mVIszcEQ YjՌIS2h Bt(᳏=*yiEK`pH,#EXG̗F܂wOzk*,93!Y$qE囒 Sr|u=\Q\|}UL)^l)Qg(a5ABtxKO𰙣!>fgC9:EGS0]}m#%-h^-ISwH$2O-.kb=[qx JO8zNBNP中b#B»rAm1dpՀ+wm#yOn?I3OlrZp3qSQ S6=ؘRaȱo#+EP3)ˁՔfVQŴ#iY|{/Z>IZe -g+)K~L< =ynI+@jf5eUL03d% 1и+5 @ƫ$< we%up+&ME+>g*?V!-O ڑKwmDַb?rQ276/pYd z (/]ÐEI+'-Xˏ}/w{?(YoґlȚĴg;!b(ӚWa*|,c+%9V|Y9\b k [b)!wdűu>$i%*)vŽ;MiLbF`܍тɮw#T w"=TWA L=d&ڿrKΨ4WgʥO1/m]1 *E xL`.u:k*f-'45vkߩ9$\dL*OaeW,d/ m?:*-(~lW_[~:*6j*a({ʽ aO4|Ov9,DY0\P!d5Yޒ٫n2pldE`Բ 6o^| ߼AUShu~oa1tTZ釮10 mHmX?O$K# ɸ`~%MN"W_:>L⬐ -S s~ëWgIϐz2b80sBDuL:pg$H}Iwh}[#~*&ӵ_/I^e+! ]/4WU3O(MmbAJĘ>R:",F9Dkr<46)L ʂ^ޡekU}+e*%joN(3|'.]nƸÏ2Џ' 2;V4RFW7) xg03تT> CO"Z~mnO3n]pFCEBx#.oWA"\)DXgMބd?)d**)Q ?"dSAT9Bt [n;U6+'s{yPsuyeeYM~6=w :GmgVI[Iwa3>@_"ՙ'˪kt]Fg@柗B ŊQ>MC*AsgeXCErJM;v]菼 Gcq}WKL_e9 F8gZs!_Eį&%G/䅮;ޓ ;i;@]5{}ͱo PF[ɬj86X-Vu9\F2b kE`kF<αTR"[) nKGk"OY/'Tb/ bW^`wȵm| .w9Sblo IAIV.6&#)WMbH)R",0*.A_tMaOWrq撛kvX,Su<)Fw~"SP1HlR4eAƨi;oY!5D !),eь9!|SBZA A0CJg1_)֛\T>;8L@4ptkau/a-$&zTs=ؕ|iP{w"tE! cFןmu@_m,GZ?Nv}CXOqEoOnAmNmC7OD up؊ص{yX4w3)T/]ER ]Q~]C|Z (g A͐cr?G\M ypdD>il6/;nX( W!5h&եEQ% csQ?7=fHK^g7s}p%LOK56Xu:{b?& 3^``fV%}+Rwőio858vX c~VpKINx5F,Ek!z'6YlQUOWN'FWILZ.7cނIɠK?uqn.w8}4LEy ]n .&yǴwl֡}ޛf8Mr2i0@u[ ZJj.=a>eHԂPs=* c])Ջj >{ \؏6h/PVO 줾Cl_("]}ةÜ@=H_ftH1Z2Z`%bhj}5c 6>0_Ba];jxs}KNuTt[\+1vfIjk9V$KN!^OV ',ެ8ʶ̜i'Σ(G&0=dpZ &opF`NeCG{ S?aise,VqN #be:^q0,԰mdBXx|&z"gݯ }b??K :7 ?VqAf9d.%ȗ^cb*OT=͟/X!qLҝK wp@wðB}F "Im}N719eO0i={)KڔEnwq_ xX.Мr&n]H,בJ*bހf:0o҄*Hq*g03\T5DNK"WwL<Klc5ă4q?UޥzKV,2w坃TC3cy ]fKtvv n1 *1}e)l圻07@}T ERmANM6K7~iK -3Z^GL[R}OZ b 5ؠd, 4E>S: j<\R7Ҡ ;/5 !vJ"Ӻ CEh(.RDxt <Kc!HS3pQj*pm:^B#Xck yj-|)=(B:Ր򔥒D᱖  ʚ j~f69%(6'9Xט!;8tz F+2K;mE\BeȩQ)*aRĄm$e͐+0$e ?^g69* 6GhcaK8K,ڽH :> 4T2+2xoyhX ~oѐhY-ZOl+Γ7|e(n-~LN0@כӒI-8`YAȹ2VIy<ƕa'pCYq?ڲM_g)ms5) w5<\(y~fjcKۮ쩬AOaNΊ{R(1;`ކz[ ]T8-z}GJ%&A[I<>p5 hsb6J^Ș`ҿm9y`^iW3Y[DXY{[p[a]#gG舛3j10+ cB ^e9k+atORg 84 c"_̇Tli^":}ձZ+7PF(B_f&\;^Q:yB0'*o"y$=OѰ+l r-ri]Vڀs̴A}ÿY/r#QlnLv%F|HޟySJyJ1{Tԭ2148#7DPdI65r'_VTW^}G4kB'@O`(B:(5hSao{' æYQN  d5П>m81nP5gGs=d'=CiժP fLsFc2q=,^W $q!Bo&of<"T UA_j5@;iWy @ a|]fˋZj3N`v edj!Ԫ Sf]mIQ6ax NI:===Vȿ{GPcЉ+e2AC4b BJ<ܐ$h@"ViRfB +w m؜ dqxтE{\DTHoTCmGKp˗L%a꣬GM5dɃ]!Œ-KK9 ?߯j%1(bQe`p^+~aLy ‰!\$6n jimRn Oxdlͷ& B8lYwDa5𢧜2iuܻfC[qeY& zfFhTp]m" Kނ%A/vg"] 2;'D0𨡑ݺlFUEϹk;3 w4=ۍ// MO AοX=yf|MOh fЏ[0-o5 ~re/}h$*]dXíQ©3/5y⊤%FATsDlqߛң3J+z,qdTM${lnmW9 @@ Q⏩oُdh6[83 #8C#؁E J7}`BFp+en ^j(lCe⾽եx澜ͯRd\+]';SZr ϟDrF#gχ\֍f>a*7#B)[;/$߰mIݏtԛS-8iFtxkL#n>2\ m# )5{Bɮ鮚|t?!#`@ 3kdJX{t]:<#$)W`dbTY% r1щt+"69i,y[ >4!ߔpdsK1Rk\5.uBIjItA4/{;;I hRퟯr~^OP|H?0SVO,Mإ0lXo00]ҨcXD xt8k1*;x aALpR !@{< `12lO+dв9| ]{79XN5 @|Ҍ,W80laoѳ/Cp%q(D)NWG?CinT|ȧ Y|Hk(7o1Wy?\؂vD]!ݽ{u *dk57e[V z]۟nY$5_ zQѶB xB9mnռȐZ&r] 8qV#N4p#3V8XwzAbxULŭmq,]ԒB`~m\A׀X 2ڟ$X8nݿA؁GjkCAc˿'/kDhJZ-{$T;($$'yĒ%7%pԄEsAv/R7FWWXɆ:?ݙ$?e)-ٌ_^zsx"2hU @@2$=xS*Ķ(޶A{88-c-h]糏 q '^Y AcW{#e;R`T12/'S jR^D"tJJ&Fe:nоbZ}?ٜJp}%YRYG1+S:􎴿b^s"_n->76اP { M3՞9Tlu<2?FL`؇6X@+927kǠq;q6pH@hѴ˫oXMc 4E ,jUKc'm֤s3Ejw>c? kE&;+sǻqr{.IA;@L9]Z3?aBN'oCi(cz˿F[,@2J~6`Q``.f&i2={L_=>2N/NTӐ+b:,xo"_TBx_Yi้aƦ5H) [Id?[ߪBќrQ,R*w| G}]БfJ'-JޏFR2-nC-Qsp8 hs-dgt+_T8Z_Y>OYꓹ,y Fx=$7]`k3y,U&"J}@%^<\: rZqpcʮ:A o'a B) 仪AV [anv:#qp+T~(-8Y#)<<" sGB9PM(_ԵtcB-dT)? p4QvSȂNsM Pa kA'O֑͆e.,̿`kJ>XS`wT_v`>ɦ%>N\Պ1L$:aT|z^}8$_󃘋l~7H ˋؚk>ǡ`A0 |*7z -F, UkyD!|6&ndf1S^ 1գƥhG%Fа١ǦZ ` rHŧS~7t>Ut쨧˰=MKAF-&F5V hk_"-tgX{X>H(_ Zz}y%lXn?-@~<#f `gǁO~yJnWJ|)ؽL%x%*9[.s/%J<(bprtpzU (Ynᑞ<ẠlDh„u9/ '1>Tb*n~RHu("zoT',ĭ%>6ܠb!6y0x݌@z|/ okRڕ ~?C&LUq1겍L1hC'!GDA[捶]uC}jy,UJ9,/o;T4SG!t bBy .ȡ*ݰW)Afj0rh%"d|EߖԳ4=(|]A A`X8`7iWL*=Z̕Zm @ a~ΝA*i(bFQʚR )| ׋yH`;\7A =x#ig2##hXdexmԌ4 L}hmSqinҫjJjui"NIɛ:Dv}x\'9y;8eQO4jtռ7'v&@]KdejT:W c{=H$y$Hg amb7Uܺ(6{pפص/XfA}iCb Ԟ]h3 J9_9YIǑD)-ˮvOWuwk Q +ڪ$ ?5 / 8(糡m>2ܶގ}tz)WyK^8rT0me؍ ukq3c0lapo_~25åna3n=c gNu\ y A]$48F!: ͩL柾ns?51畆AXԫ0.Iՙ>Ÿ &6s15(7)^wiNLgw2/86a^>>EEjR#}ckGO"bd1̬KY(!>qy RHOإF!埠Y/1ddZB uJ4[YA#iԴEa\ЭbU۩~/A7Tz V`MNB&:U!URhv OU&밙 *Y~DN$DDH.,t!ygcX_\G<]5t$»h\]=(6^$`|Tۅ ,o1sޗUxYȔ}"I,XwKI&TҔwiJx^pMɗ5x_CvΊ4fSy{MXgֆ6xtF|/ٓa-lf 3/PF9χ%eC"@q'S>}x%'SY@=M|*+c\oUw'Y)@H\O%gἰ0=@̸zS%vR}' YO.[ ܊bg?f>Y =L::2J %xB;ME0nOl56cQMe7-,3;d"`cCc-o`Fk޷IB1F)#iF0j݃N_c62k/>R h0!niiOD[l^Tб`$a"'چy6Vd-6*d}3n  x`sK3|x{5?VF//+Iygq[R,bM,_0@de< ?JnJ_OAQ`|rKQ#؋FiYYt+(yElOZ'b{}, H|}D")68G^>y#as%ʁ5VZ^}QJ^(9H?MvY[U{u OwbG[.QK@@X0rd&NG0٫xde`Ɋh`W{ls 22L_dxGM$4#5״Ͳj{S,4Q M򔌤 NF[x\(0͇ڍ?p.]F?<HWT԰}H<3NDGWv@%G.2?";H^OC]&N/u~vt/uꕼV9^|Av."CK ;ASٶ n\[J?zJ!qL=1 +kF0jHqM ȥ̥J`6OTsauюX&&CY;lqwv?C݋#w ANTS7vWEZzP+"cĸbڹazŌ<-%C8ye0g5 ~T!Qn%FG@V

}Y_|w0\e<*1߉eJV^>1);*XNJK >zBi&-X$ZfW8VdyQe:0?5HZ87J*,Y}EmAl TgP11z7~)o:C zO˵gϓɤ/aimhK,I,9ŌYٯ4ɴ_R)Es%@?ɂ6`XGrtzK`eIa Xq>^y֊ i?@rJ/-3Dx&Zi"v}dF\8@NoҠc0ᶛ;!nt^=^ieNY $1Vws4&nm>NGYVa/kEZt-a-u)¤ԡr3ЬÎ\f6a B_;QoMwBIe@K)J 0/p &Nu$A49Ur;~Ą/1-G "w\0})omg'uI9^U[Ɍ\4&1M26mT7DdX2xHVqܠ]8&]/eR,J(s $tc! *kfjUKoTLiDx+kI {~^Q"W0 Snqi^.4{?*JO:^cƪ8!8J-36PcDzG= V[Vv|| j^LLN0n9gĹ+lCyu]|~>'݈)ŊL@r/Gݎ:>] lt\(S}۴IcnFgH{ZDTЦo{iv:YejPp^A P0zGwshK7Fhͱlt\~)o)jDQoiu_fiv?.Zj#[g;ex@Ӿ r32GEH-d֮ż7E9v &,Ke\v;ghivZ,I펑Z.r&V7N VKwXϚs *}-|@q#.'JיJ%-2vk-#Ҵd ut7Mҷlch=@ȮkWoq3щiQ{:VNBddgmqaPy3Z; OF9>9pJj Y# %>IG~ҏ[ ³7P&)rQ,UIY K~\/-\>ejIyy~&DzdfYJa=~=~b@F|o]/G#gT@l '} x[|7)gfLoo(2!u i{O8(K+``*IJAb6D i RY7x)~`7?Y})qխ5&qr kAq?^obP,!{bd#d5fN-bi+ȑ ` w.%bQڔ(/l;LS+1ϼLY9aB#}"E$Iv6'kѦ $qjymG">AUzG ,xsB? ىHg@_RzG[}a !׮L#ՄϺڏjYȻ՚Һz݄aLt~;4oE +l0u_/nQzz'`Il[Wܳ,^h=Q5x8cP ?OIp%}xX",Eh\@S7SغԆ}"a=K]̮9X:z5ݖ5W-2~`o6 S:9 ұ~x0;."8pvCY5-/nSog ]J Z$0 k99:B0:@+r@@ ? Bɢ˙iV‚r4rR8cShy6+ux#A ߩ8Uch#H*yQ1})7F.FwU~htiR\ fzSتυ"+ՋC6U>enMWe`9rFd+ÎcJ Z<%`Qd6mAFk' 8 6Zb% " ﵝtyTN6Frz_~7D-Ո+,B8TdREiSO#u[DŽX\v DLJ,3Ȝ'+{XS$˹)PwhEاBͅco'}V!’m.,rLɥHDq) 7XB ҥBPK'E5DLл,ѺV<8#}^iA4Jnۈm\@q#oW{Jbv]~^Xo; >"㤀lb4b\'&TMO*傂qCޅTZ`̤;A3[eȱ8wuEQ}?bFn77/Wrl*YI/U/ߏNREQ\ẽ-~=K@ ͦ[<ɬ@ޞXb/9TP!Ae*tj*u[?{eKwySWwge+N+reɇ:ti:Z(. P|N!cbl@0Iuׯh`1>ZuN-|F?1S=&{>VD'D@A= D ~BD䈟7Pi_m~y[dX] 33$wyFW(&9Dt}cȂʄ ny- O`B?_P̰wrmB;-c!nc|pf.008F]n %UDrTUfU^v }ĚEn8a5il`,l4^E*c/2&F:1Ů 1lbB̨k9UCJC^NXuWbyc<5\K3@}GUATFYz³_n2;}% Y-;}$v!D2#>$A4 f{)a1`pѯV| A);QWRImգ5UnYn% ewnyC d^wm؊i&]q#p բ0Pޫ׳- X:sf3[~MڠL1|lM@mż$ٵgsc +TQC<.VykȀN< 焄w KZZm$G`-ރR Z-r͎lz\,Wƽ mmED|9gbިiˠ$ $ m {YأT@v̨H Ι5'_NTӯp5cX=<.V%zy'7,om`uCWY}kb~*(}HlWr4k:AY/%4z|4_-_^`y=#NڿCXv c-Rſ5v ;UX8j: C]_J VpdBgL,tڙrB"偑.>#n3ykƽSbN,\ݫTB;[榐@o ;dH:ʒلg˧2Mnrzv~"YX9פ1weXeC} FÜ]dOb>y3Ѷ mF!"R4}gzq{=asN y S2o$|[Ttkz񮓕rKA#=g[r*z僁ʯ@e/x+F _sL84Ys UKq\{^ 7 ) X9l ႚ.:՘c>6I.:Xq6lp2 ϋ_W&#&jY)Pl"T귕mHA2-Ǹ5ei/c͸p&Ng@!7͞-=ƈ>tt8TlᐦB;c$$]ui>wv&Xe4r# q#k>Mo k yҺn %H>@9hWFiײ&4U׭[o?S[2 I}#8xѐG3^;|k[DfXJ.ßުvO&uM4I$ ڱgS Ყբ=*c+ו07EvT0]NEbq߬`U9?4Nkl7򺎫ޥyBMN L) ,96L[(/y!^yOǽ) < ; wzn]/oL-6šu^E ̌~N zĤQ IFOgk;y~?A]j@N>ʃD@XT8T X*(5nE)Caucƴl* ";}\BM$t+Abkr&҃-~ [ P^\+iY|>I")1#o7S(*4.g=6*: X,h8SޏQN|^sqyr8/:6z×Z*{#\E_2aJ2Ա*b̄xCUVYAn!LUTR Z1 F&BSJ*lzLyPrwLΉt,H&{{sn0E}HBt{C-@QW޶tp F桧)9&2S@6e &S } 0hӅvt*o pQϾ۳APVHTdF}=ڝ'l83@1ʨ%o;T)[nU?ޗ?er4[i ֧kz8I!.jTQ` W8oos|w1(fkOve4l] eJy(`+mkm{K1DbG^x2{'{f@y[jolSq|DY#g\K_B [)F$K~w3TG ՗H?U =68 -f8kEXo$j5P>vbXA*Jǻck۰i~/8,҄#I-ƉU_tb)Or^];c#evH("7'55{/Dȍ緦l6BGیAh4DaUI &{rr &š2\(E6մE||<ҍypwF|i_4F8%)$?ߦBm&< X5 JZq'3V`43t>62W>䁁|V0_.#{K~&f[O=qDו',fH=y  cc˂eb \PWZO!-zJ>Sč31'cǒ脠؅(D/t%C|HbM xWX X:*nr(qr(~sTK@[jRIFtf5=z^?-Iid/S˧|qbey1|G }x 0`v)B]cbG Ρz5C6~:v03ٴlEŦGfoأ.K:^[k|!#8V'y&u,Mα>u!1:A'Zbk\oND*A},F [")+;DZbSL.*LW$1`y8.=Tټ SCdspPlZ*<֍3?t_e)PҝlX-y!Y%&XYv@bT<:GXXy - 1ھ6?Bd: ~J爪nLٕIQPj{WDj6V-Nתּ4Tjt"d{0:Ol8+& Ͷ+v$/ze$*lh PEƚRϛEo52{tY_=E-s80J2(["Hm*94I)xl|C\qAYdu8HVUgo5 fxX_4~uE4;(+s18f' SUa|BJ²o"xmԛV0k;;dC`߿z&rU +Hf5Q8ҫM ܑie<#Al @GcUM{ 4^86SM(Pqzp4]V2@#uy; !QH{֤7^m6sc |1jk'pQ7ˇG_h! S+U+)%ņ !+w Ti<+L1YY Uđ86+0ZúVȨ*\yH[qໞձr0A~EeZ x,YU WĬ''/g6kzha9ǧ,%_GBԽ?j,Ebߨa .*).X?5X::n#~)E3R ?t51ߥ\JWRB]^c :$)g0ۼfI.:˔9~|~A6-M#F~.2Wo`| -ސ-o 3J';Ze?W !2RD jlA LxX~0Y$?CdP"lZ.ӧՈƒ0kB@ZnWl߲!^~A4BPV]:jݧd(-e2G[7H5vMUgWytf 64z@7yT_ˉJ ױԼ*lKK$ͽH6-?nrc%DI?VXW-; 5VjJ tOZ! sb*r3ޫYE4@)yMkc"S ]f L͠j>De`oAfWݳ<}A/THN0U0 ".Obm]-:W/%tA*T8{vMkM_ [fQfs@Y1")0n%(uK@bɳLaP9b׿TP8^1VſkޟFϭ's1ii֥;-gs"V)N: + ~zp&Zz$dǟr0]^Uz{Zs rI]{ev8Z!J{NWZER3{c&'p<$r:cT~θ0ֲdp\u[ζ5`($ x0lz;Bֹ%cU3G5eH[-pեC10Vl lk i.4 H;=EPJ`}p0Ѣ"I򊸤4LF`j[N,Ej9[_+3zF?X}P0'Yk֐+q[2ܩ Fi\idžۦ JÙCN }X}^YwDl@xB f&E-WuڽTᔐ#JM|j_ 8^C(//@Ps&^]HC|77@ OҜ p ^9AE>\ )TY gfV4%؜%w#m84Ąĵ۱>B`E9)Sx#SdZˋÕoG?_PވpD.u$мI1;U,oo.0u=+tEɩD.ρ&bnMl뷯fzIn^M^∨Td:Ly1}D¯H2Ӹ5y]nZH4' R}Wp'Jid\b"4V)H \P+_H.]WC|7 #䧩,n0L̹r2;*Jxw4BS()pg18iͺ-be#e) ˊ/"^!T WR$U<슇êƂ]YR}Jwk2(;}K{2QfP(Y hq0sXn@;Jx̦35Gm؉–.&Hf-*LCG蛌v[FwVLjBIl`cǔQ4Sy}W} `Ӓ>R= 1-n;cc7f8]:H|^rXwhvz6B|^iYb?꧲grYv<=zJQ@rxF 3O΅pX&1Ct:Ow| 1)WU~(^^+z3YOcE"ncL^F7}z0lhTNӻv0sº bOM ]q[)1/!;\cL ](= ش92\^M ۺDW ޫ?!c,Q,J\OS >BSP e_ \`7v)uP`L] D QnXD-=ǵ<YKۢF|,QR-\ppSY<$)`'F:h4,A2ʘSx[Ecಆ RS] RwSMG\[(toC-vCT̯͈觰d4'iq3\8=*Z>N[E-q5UЊVfV)o#.&;\EРT86Q7غ @=4t'w)[ =p^tS%FIQ XߞFmSɜa Ά˲{{ԖDQJ{B6){2jfyHL z=v :|(inCYp 7$ögsfX=  kgk$Z\~8̉9%Z,J o}4hbJ%)> ݥfzm3t7Sȴ+Ɨz-z&?hж^|M5__2 ^n ^p={b_*^'BuӜ ]`Z}~ LjpDg窕@ l|*A Y*C2!X ս|s%q)b7`PdjrꇒfLFP}|jMM/(!rL׺p{0ZK4yQ9hC 3x_|D&8FKeZk"11۶p=**݊LfACB3Leo8eD9)xְ_;}3{o. aVW$Ge~V7[A|sy1\Bw21eI.Olu OD퉱xsS!aӴ+Ql!͵U$/m>\IݞaܻQRk^$1~rG'a7>!i6f5/&iu8%U%곀`EfmQDi=;&9) [RDh[oІ*TAh]Oq>8)D"``(Id13cC}7ss!E Ng _#uSs>֗TN4<A\'8LNJzm@JRҥ0/q'';L82s?Lz> ɆMr\Mj|#q H9R 5gGDGbD$`RӅ䟪iMt罯!}h 7tU%U|k52b BLq\"iGq\cGNI&>"KWJښ2SnX"Grst:}.]fֿ4*!ZEmeVR$tΈv|[S.V!l,* `;ߍ m{I-g_ )PQjnS? Zڜ>g:DJlT:k~ I= ]Pp$ZU'QsRZ=/Wu`vb`t(LRiT K{K:EEW ;{0ZRU/dw!f14ʆM65`1`'w7ӭ L$PX ݮӇ5䟹?XCAUUC(v{9}GMe_iuszY({Ժ-*pvHPdr)!Me +RgI+WFp o9_P1N~ 㨣$rزs#<&*GXN/E=Oٟo8Au/F?/3ıYӿYs"d?8XQp]DFG;Yx]xޘև16q,¼,r-:mJ^n]Ξ>4350sܮ<4HEqfQ-f\~ l^ۇgX^]{/0RERþG}#ìCBsY3$N]H+%prr4vhOiJ0O (ʼRq | f~`4(Oyff]8 hʜ6)3`\\4 o~S* 5U6J֍9(RR6Iva>L5jүӭ bp0ۂ/̴7syzJV}Mw3hҲȟP94dWN |U@ܓPW%G t~MrTs 5VhC'Nv2Z]CogeK):E1ASȑkB+ճdÜsFk.+ W/uZzOǢ}V[H Խ4 zUw8uPFJ ‡>d!'NSLLd_Pmzkpb ؋X@ꃙ5[K0Op >ўFXi!npſ9gi꺷~l9g]zѼ.LĚ*s,]a]Clu$ U/x90 l뱛6 >s]tv1໾z;Y + ׳Mf1b=Q ٲqWjYAͳenJ⡃EW4~Tm|1wR_n~|]o搲gYi%]L 7I+h2.D|XI6{OY &=:jtf͗cf9Qq"Ӗ-=vnS(%嬱^"BDǓyI{ůNo=*[e>u[RZTh՚x,a)myǼ҉q`8rBA~l?SS=p +&üSܔP8 d!vzmj: a#fB ^aA7ߜil,+P^@mF2AU&pGAhGYBմ%w4gQ*pt&ާ[KT:OX኶Iɪhs- Zdh IkaIFU7NT8zDX{MRf6B[V4ujPa_׎* 9?ۙC~ҝ(g2C!@kNB͆_#sC{3?o|`/YJ foIFSW2@.HZ;V?S`aܦrH"(b" Lt)7`7?aimz[:xF xGM1d @{4%POYt3}VF4c(ClL@etIW?ɱ|Hݼ)-j?@RU>.⯱9;np.ȕޮl;ɅVkÍ%7$F.>VgFAfWXaPTQ N!(Q#Г`aJXc) 3rzw$ͫRc jUu;yxyf%ErXs|O*C =n8}3#ScޖVA6c O@.?=ҧytV_ʂhm+.MBaK#Rc ,H:) Ű9E+HRDPb eUM(>N9S8'H0b8h|b;al $Cgv#RDo %#ac?e CzuЧ] II% IݕPl,,v9rLM@yAk'fcĉ83a;惡ݏxݭgM-lNW<!`'U4xk+>!QN$jKb+e_S )N; nH n:,_`B+?4Տ/Y %kikhB!B늮m.>V5~ Jd`ĶǴϵ{銣¸kaV4|V2t"S' C߂ pD[J{]L#JIcp>dܕc;2ջZ]6/gǫlJ:{"vqE8G?4=C9dUPӽ2t3|K+`9 o J;o1O^JCGAӜh 6&nÖxZD|OZd9Bo)@v 8 $z<B}RH>MVZΤ+rV0dE?,nn+f @ՁA_ :_39n[&,ONZ\KAiQNW%L~*"5H>y̤h2: 5`}'|DGf3:й7]ue m@9(asPF'iGwww17uR J+L ui&\5&YPx3ztr@7_wVm ;gFmB:R&kf$KBh񞸒7ņ*gqR&f(4DVų?VQX# 9F8[{ן$=o80\8dP h_U(yJy`=XS;M0d? ^MgIZ{:aY>͓ou>٬Y)m3x$o]Zi#\4kST/<8=Zų{槑z.'{2 V')Xu 4{ Sz2csxN˞NF@a 'fA6p]^Q^Z"a-bq7W=BUa-v `k"0^'r;b;;U}o]E*0wougmb GXdRIEd1if!nN:hkUߜ7bsDsoقx8ٺ-̬ /An owJ.& ݒmC&LUn";V D V=aõdIR8 82l*\+1Rez`PQN.B+uAc5B*K7Փ遟ujNNb@`jHuP h p[zaKcr*ʀpŊPe$D2-T8>&mN 0ņ@%vV$'%ڍ?hjvIBOrERN(Z @ tѳ CnTW0|c^:I9&VsȦj)vڤƔ迄 79E,|axu?҄ц[^r1~ u.ϔ!fusH^ܣl0Ct.Nf% PTO2f6^I})D 4Sd"zؔpzߍdPfJg+nvihZ1.#)9bOew@5d*iQ٩Iq QCAywb€ѧ?3xAq%z0 vhbٸ%k']C-).Rbތ׋B@S;zso@>ڹڧ0?'cMk9q:+DDWC$:Tec{"jBM+BfxK*GKf׈gl@uOJGK[&mՆۑ:׊sG)i_jK#|N۾6:]PY霒/Z'( ^x8ZA(R N Wf #hE Q. >Կӊี>D6џ.57#Bvyu;zjMڡ~}|ⴆ_;iƞ1_>ƈa80naUu|d z29bZ* _AR[k-|Y^1 _Za%rd`8˘GQlnH ɜƁH/}f] B=`oŒͬkbGh ]}41='G+FOTS4T͙p?@ CAGd#xu,5P♋| fyҜu}|4#|E2GO,YlƠM(IE}=]KBl.dyxh4ϕn0w\8Nmfq9M9>ƒڲ`UdZd?-tB vÔo]e{ZvoGujYun}p>| ع$w<S <h&y[qC2nc/q!NHڝL;v w"C=Z;jMp=[L3rX:2}zx NK3℥nJdZ"K_|dD6 o~&(_=" &AYKIW_VQ E?IL[+n U@o[ؽKޤrZwײ}yQ!&bV`=Hք;*2;Ky80BHYnB*B9po^#4@XHIx*A#0o&Ol wT!=jI' vUdøA̜:E=k/ SFȁ-AVbFt6y t d196axLXVy7[J3ĦT\imqhI4%EŎL2E1eP"dehI[jm-[[`,MKvF$|MR$όVK[,=Ss¯ DJ9BR[p->9H(, "EMN iPd /80JZ&ޣ̘61OZ5G%qEt㟥s ^D7مQ1r㐂\Ye+< lQ\ڌgVZ&J,}gIUğ/|[Co^P&JC/+*$R16,a:psO9銰mjTQȯIٔxpzcҁ-=qebdRo{6,8;jT׷,lA73-?iyPjݲ)w"fbneʓKd%5˦'A`X HdWE+eZn+0`״-T#rc~ō1&f@}Vu0;N KYQQ^_$#j[6A5E{k= a\nJ@)o_1]Witҟ茼ΩC3j=;0BzpyGF (迡qh"xo[C7&ilBô ?Fp*fHcFUWZΪH)b =#WK՘ [/*9OP~֒oyhT{h: |{ kS^a_mLXE7.g)j!!L x~<`5x21LZ7U{Z >[X, ⪅g}e+mfYB˱C,yIkRqaZhhB(2G||5VZ.-{"^Q!WBv :M>l5^'[;'|'0O.d081ni102MI\0:5bn:94@Pb𩉟ah%˵|8gV޿曐=o;WN%ACs_p %瑶Eܗ" R8u藀 i\"Ąup(x^?UAi[z|D9>Aݿ k NtOOz89k{ߚFR- 1ζ_Pܥ֪$KJ𣁰m +"6 4Jآ,3=}XJb:Dvt8T%nWrrnC#!pn a.R.O#|]/Bgg~AتW D<ˇ6t 7](^ܗI@ 58=GQַ7Ŕ4dcT+h1f\+u[2>kN\ѲDl> ƝWVU]\Mcs1/NR: `*<&|SE;:a,/Q0#S\I3RIj)we&ۡ׶r&/:+zt>(mie,"Va$Rh'`, Y:".}$]Jnӓ`g#7R\lڕ{ɴFuY,oy'm߬ņwư:3mTeXmV8`Nm)-O$ޑEL볣T k U(2&bOxzfАQHnڶ_m|@Bs%,:ϢQ$]K홞fzIdVyUe 33kKԺܲ.+~LUߘ8gf[ \Ml+g GRq9Ok$wz--$ cIlø\Mǫpiy?RC xl2vX1fHo)ѩI~9K MNEBܛ4ƵP-u;kf1bKhm-c. v}x&QGW@|;l`_u~R,>۠ms^=Td-(ޟd3oGI%H۠n`>Y|cD]OQXGZE byDf۷evqxUk1\Edw 17iEv,j֒krb̗wĩK&*BQRFC$б # 2bPCQ`+Iw-~)SkƄr6(\1wyS,pkx,`y,X$ӧ'z?-MV4*0w&8i^,T˔S< wD%S}h0AT~Ҟz+Y9J0%VGLj<#I0Jngxe/Sc /AknPQ7h'0hkҼ-vqWÒGE|m=YNYS+ P,6q:xZiPj G4{Seqmg|WPpA͵F !ތTnN8QɜdT.;V@dz1a ZK0Ž)`q[@H}_ 4T> ˈֵۀ $g|'ɚ ,bFN duzg$ Q]WKk9R\PǴYb+f}@JSeV-tO Z%#=r7ⓦ bdxסp ["q.hE%Gzxh&{}|3I*0d{b ;qDx|hy?S߲%)ͣU@됋)jhqVf?<#NYK>]VTr '$(jh1osԓy`Qt/ǟ^|IoAOl3EUT`@aTZEb^[R8Om.؇bliY{ZݭcZ7GW@l)0<U{]]703|Ɗm^DM"mɼq{pɡwJr fQ"X#KfG 8|YLI.%/z/W\TV@@5tþe0 -?:+D1~qhgi=;%jn\:2!춣,Bo+PV1UސRGj!>1umggWX`Y:^`;m%H% hTgHۓ739wr 6Hv^.(Z\㘞K=TehP^y8\?Ϫ~.Ny,^]I"zmNG !<^nI)ę @Dwƅ¿Eyu Q!.%`Lu,bzlA! YRڮgd[ĭM_i$vآ${;E$*d[]tص@y>o,t!.l@2_d ý%%@~-ǵ:HBH=8[G4E Eɓu{tkWG«xI-c "::F^ VHJU.lTo.fH`ejݰ9M0*TR>Gt?fq =zo"U$8P}(J>We?{}wy8BVxX/ C2P+z8jBʙÃ8*b)grs!${ |Mb}0N1*JWֱRvN;${ ]iV@jϖ%anCֹb)Ab]{Ee;ϲw')L%wa )8@ Շ_޾$6?xjh@zv-bi14:Ӛ)ѿZﻲY`;G g߻a4z_(w\5Gԏ;)ri?_A_šF}lF$fQ-{!0U!mbgK$5ig P)#iº@Ig+de\sߚ⥏h =PMjQRVAٍtܭ3 ůp  H LęYB1Vy kcqCq):NiC{#Td2ܖK6y*iR (<'+oN!JPRmy^+_k8ӎfZw6: oc^_Έyːfz ۳@&,C $?Lm%kQ&z4=(jm^œ?bK/7Ht\]$lQ8NzH+34:.lلE: yHcY+. Ƕ)q2X*%!ܤ+U ӢҤRr%[3cp\j,^@[!w(JDP..r%͚.S} AW2\풶n: _( ү$}%pjbFu@ ~A#hFv{B' }HO"H?ʾt:p)uJ^ݠP̤~I9/*52̤T-e}uN(dRbS?瀵u.X6k|*d$LnJ{a$RxFk$HL'KԳhŒzb\x٤!x|m(P+ =4ܣW3mL tE O5*T1DI6:ڣD)v`_qwN,L-;sV@Ri_cv/|ZW$l]f KJ#1)BF㓯XK.~ Jo*1{H'g1KnE~xW$F48)=CITaY |@CxJp jOz\vt,$N[J67n,3;Yz\OAL`{J@p9Eۀ7yNC/E][3FNYw@a@VCeضWơ6/W pϠ5$kY7`Nԝ].(+- &raî0IK~sOR.:Xe;! 4k+Gzz7lٚeؓ"m~YIGH9/ej}eWl pK1/KF2 ε.}_I[ҭBq'pbC:38<DǐwЊgWDG}{`]c|=h's|$3( Ԋx_iRwV'O՘kyj!Ʌ-% 5gB $ڝ['olNKCZz)7+~ q->bV `;7rې@͠'׋]nGTߘ^s&Aaz)B@ӁXK;"2D2V,{Ej.=';uKYWP'y0q}YJem"[?Ôr[DMH8^(۶ևA ܈'!WLߤ6Vk%]ؼJfIa"~35Dro)?ꢦ7х\bm*7l1j/Ej!ucҘ-q!ݑjw2z=ط;l3Z\KqϨ/C&7Q _e=p,H \LZu/WѱaX7\dTe} YS4|DW՜^ĥncR,mzh4oԼ|Jnj1x(gB;[^]H}ܑ\&~ b)b1w(OPt@c@K`3|w-6|M?M؈7EG,qF'ά4A diщ Ѫ IۥiruGD/GIW WΰwwGCk#:+|ax rў`ݞڮZMRnS9.kiK9(epte>Iq9\AdwW$u0ABbDG :S:Dz}W9!1B"&W/z_w|!))7"z<ϢԀp?? 4ѝDGk"T,6H6B imyVy>*zZ+2 |etVtp7ݎd3[3˾"Q^@Ԅ6e< ?Vtנ4P'5uH&[~UxhF D2ltj3ղ) yyUG9?G.JB5'WPn^̝5s68t&ſ/Aa7R28ou%={Ul@U*$z3w&gގ&~$c듌 dܴ`f@Eg]SRQv_{c;仭Jw %ӒއVawoJ!QGZnvq",$ܪ'&hgNHLOߺX.v3}"r6Yrz%E zO=^'P!0@>i8QT ۍ0s|P-X|$g.KG7\2W'Mn89U%H zů4 [ gewt"!jv½F.MĐ>eL0&^)ihEɅ("ʎ (W!7~7Xg}%l *h-)>=ozh51=]!hx듂=OZ%  _#>]04ĵUu庘PJSߖ^4\IۇX}w~=P)J־e I9Ek'piP=}ZlM2SC?'꒲.(gzJFʁo#N dFYfo.@q.Wfj;Zbيi*ˬH*nCa# \=z7,~=vn.bY] 2k.Ry#10D#8F\O=p39Fm+VzVSJ|pɬB+P`%s65_%NFXW枅gޝ-:}!6=͏BuB~=ZN2Bk4#U!l7ڞтZB?uzRZˠMBx$Pz()|0KFע̚蠹H9tcCw^׹=djS&̓]ɀ{LLaN; fఆ)Az';檎Rj;'H 7Ƽ@Ɛ:adq0aBpe|} W<- xX6'2rKQf(bJzq[D[c0B< f@^^x48÷Bǟ/BI ݖf b4͢n~P[k< 8X/NrlBHp"h_`b>Qw 7]Z- (>$gi`5S|ѯ,P>t~H^=Hy"xC-MQPT|6A><ؗj[84A Q>yA"^gɽ"^Č>sI*s ]b!sxOb-;D =*r5 ݤʌ!B%2F eeh&r%h\iMj*jBmr<[>q }tRRh/iFVQ8pR%q3'Ij@?; LځrV>G{(H&ͳTwX18%9Dc4Z._'j[O8Pb1Q..#_왿~v#d0*] XmזBRF]PUU %;N^[ʧ^jw\W&W<p=<6 ց3pWmz~P%sz(r^'bh?K:4'Ơ`/XxXȝ?n(Q!C}擲PBi65ݒpOFa}x"޷KNtMP{_i0]0 }6!"'[,y0㛽Qv&L/{P 7U<ь" R:ԦK -Ռxjn6IU@M9KsB,TZ_8!qӲC2@#U+ Zᒯͮ"pA[6Rv_aeS MwkqvˀY2 @#IͥA9"ߑsa'#z`"m|<IHRsv>1AvL'ı* F9tQqԍvBjafæZiQr8%*ކ sDI"Fj*֣vVXHqP\_8ꍠ}x =* xKHiUEruL{N e跣%G($#jCIƨ&pȫ$ԘDxW.S~J"1  j1ۯ%ͷ-{%5B\W)>>yB)_a0 7n`DKzIKP:{wԌtoK ~ˤSIih5uazs$#w.n?e7dk0ӎg0)絫D6JX@Y8/9xlyb8mu?Ⱦ:c3y,aQsY)GI0G8W„BQEWC 1`m<7u 6Mt2rR;0A\sϰ/># {cWHPy}(7!C7+8וOǹ~LY&;iu:YFuzWa Վ~frV:E!lm/z.=cKs`lޫta]:5?ӓ\ޡ4ÚxO*oEfIAXDm H*IC^^ אh>{8֖j|le f48i8Zڶd!oCZ,5%œPg\\3`ծ}{`n6rxf&24-VTMP 5ŒeJ;&5 KJ#Ŧ<]55EW|ޚZpoe*+w1-/)i'h]}mFxV%~93OgM,͎J ERG') |+˂$U"B{m24_+_(!P7H죊1siZÇa6- Um/>)$_Zu $I%\oi@3kjd)# i[8\RƨəkFfk#$ˣ?/Zcյ3*(O9Ułm:ղ*qb+z7ϗK栳k=;SXra*sq#iR^h!' _!㟬9ٽ״ ya+ko<2T\z]a|:DyP3&+ž<~1 zZ%`֤uJ*`qMX^0Zz]KMebviyd\ Xsהd!4\#lvtC8 V߷cZ ^ׇZ1;~U k9܊=ożN~Rt)aGl0UHXbJK ޗ!E^!W4HVFy[!@~mص2dq1"铉xWYNͯGU*\3e91CxNJpH@vUiv fT-4c֙zB/|y 1t}K\5Qj|4g%/ʖ ܨ&d {"B{t𽺭tJk qffiQLDq(Cfyj)SޘzFke1_N#l 25b`*F6xpV]Qک]ޔ ^畺'Y}ĖÇ&raE6vJE-Cޫvhh8{X6?ueFq@ph'\׸24s3vu`BA]HxNݱ ؑj/RbTt6YݓN'q0$'Œ ekXtѮen+FJ}U*SW^*HNH4۵Ț8G)*nx3I%-/ڼ$>⌏'ejNqЭ}Fw(jsB/ 豛CbWOw.2&=&_)jJH0r&)1֝7vw̋MVl\5;g b\HA˲ob \?mHd5T*zPf%9l`[&=BoVd$A^!VEeWfw!GY.Ɗ I(ZUX*iM\<}gu=Z`ɥF[3r.f-EH})$fܙ}~?6?%Jks(Z&µ-nFQ_\I(+6huc+y$,Ԇeq7H;Ve0ryy492CzX$*is>Ԙ|mj{lU~ɴqXfM?ڗ?~:BE)&Z\k` %h쀗" + r}Dٗd5/#2B#FteO$p ~ˡ%1jAtj>bT@ ȡ[Nj?:E>ȒV2a}6w'i "X•ĴqgwRn ㊠5MI=B?}d\Uc9o7;xYU-TuLο+"hƘ@nwcgc켑M(yh?oxHܜK\$HU]ߒw !v_4l6% 97;. 7#/3Zg1JÒB0̽zD$&Fj{b! bڹ~=GK)٫![`ߞAmu?tAo+w;M~<0X˾8!"f BY" v&sH\H>X#*D^,<\&S§óPAM/0he娇hjjRIYy&Oپ^j9./#ΐ+lS'@?G-g]u6Ւ̇+Ef38PT&NOH Ifښ} != FV) \9yR0íA&,V [dޜ5cOׁ SeiR =w7Vw6GK 6A+1j8\އџq;&XܨʺW;fsA9U16Q@܋)Wg&k8V5HXK"dy+Q.A\v+ly-xjf"wl _w n";-kH.gɷaR~I0(/3M5zyG4uOpc|/nNM7 /Mnog\\EBx^E$7E SW:'٩<{&7=s]|7*GW? I$mW\P&A$f~>_5&/8K62Mj- nRF39RWs`mB`|</ }V}0oV/-p iA f0V )b8Ǟ !=j^[{6`75#qR/Y  I*H7yZ5WS"dÞ&7NĐ3xtp=%pF2/tK\ohk Xg=PXD=V$xi,KraT }!{| Xo[$IqSa*ldqg]@o1zKd8 ph@ZWvj3mae7d:i;0?W})++Fb*IPJ'eߋ`qRj[>)1%S\8N,Nh= cӚ<㵪Zz5 4hW~kw~D3P]^eg`ۇ.dztywNBLj+n Stٲaze9`ld$12^dWrvA`|A[>Wu5 h],< jzetX駌Z*ydz\0?e2A?OzԵkK#b.V) ^H𼥃0c> C .Â_,6N'LQѠJ4)֗5н őcx4Gԁ$qnI%?džNdԣ˥;û샞gA x~4͈>/¯@l~bh͒:htTXĎ͟X+YKBO #6s6[W;#Ӓ N,ŷJMg͓͉@vMB$iB#Ev<H C~&Z 1$ & S,ʆU:Wk"f\-:)[~IDz-*^1x񾓒 (*n,҃>sGXW@ s'pk_9&Qh[ƅ$zKkyp‡rF]c6WW{ŌW6*3zTpƹPZN{2*EXZf[Qp ڑEpr'N?$ ܇63,/eEʸ0i0%trmр5XnOdKV6GĶ3ִ- {C\ލt(KcT{[I8 #TkJ+?y}yi֯}7"dk\!~֭-"!m2k>Q QvWlUx?4kT/a ԝCՂT>ugYȕI#D,!_<0'L6 ~]6,gZi$2e[G6󢫶Φ64+G-0t[:6W,gem'-Kk+e!vCQDQ*#"m _q,Wm4 >}oan+p`^ '|0qH~*Ei~Jls)ȍYCXJ'DnLb/T^^Ng:NUW^+K)UeXh mHYpNŽmH7 lneǒO̊qlC, _.LF;>l8Lƭ&#Jʰ,]ZD'' "La.?)=:3Іt7*~xc @՞;g 0Q]8x.]d)XǼ1{S*՝%,b8f;?v۞i풀t-?G4awRe,hgUJ4Ӈ5nA2Y *)li ġzxJ|rE0}I4 j E)04 Ȋ;xM%hfO MBͳKNUO KsF5%MQ25ո6%x$`t6]Kң(7҅>i#x놑h/^'[yE5kq!9wTQEk9R^/ҽ:( vueK>\D*Z3T( 1 121,O?-޺,zN:$V[427}١7}ᕾ3I?z2s9a0,l-POQ_fc8w|$֖ZψJA)J <{./g0DFg"6YjlB7=L Nʽ],7ow]i ı.[ ƜpElck|UTPd6z%yt_^RgLlaH5 )`Q5^6v=s$:VlȘ!tn#GԲ@>ވߛe|Ǵ뙤\j6{oOdY890+o3e}]qax-],XeAz &w8x{nfj4$\7^E1*LdqO~CNx3f+N(w hE*&uԊ76@#}$4l$"ka[5'NZR#ӷP;'H.eQH9WWpI!{>myTזN 3C>Y Uغv>ۨ퐷9 ]Ќ['4hWkŪ066W XiF`B` "[ l$Q k4Fa `J¸C-k`E%F@T8 }|0P)d)ˈg&еX~$lޫռ1Ǻ2EYD\pK,Ƅ|S ,N9ucBG,3j~?UH[Vobt2s 2&\j**Q T pM<4p Jhg=~uv1Fg\<1!HbE7f`z1+^_Qek+BIsM;+:lW&KL!OSz l*AbQTYfppZzd|tl7_X2}: kڔR]D__.mctj-y!J,$J 䘢;v|%ضI悍R4(+H{DmgF!>ƒ\F:ڹS'PjAk c7>R-. ժPtZ%{r. Ŷ|eܭh`( !j!#!q8D6=\rwyq!#oB|YB1);ڤ&8Agq N59֍StHNK`?SO}-a.fRZϾϒ١D<{Gx鲱u7 2Bc>n(Iq?~M^vyW#Omyi(lic= y8i 19bF8J9mɲŸo``Y1a^}r=6uaHX1/0Ns\a3AtkTni7ѣW?@.dC4 yؐ./ٙ1,T+}!ֺEUFQ'w >cǣŎRgzx㒉l>%Â2SEk^UVx3  pR-  \\-fR ;cf5y"tw㡓- {GIvww*F٫ao1n@m->#xO+?#%"!Ihx0 4FT-j)2#{9af42uﷷEU_Mq1RzonJeQ͐r]]aUIRE-Ա_eﺡe%4->w&<8fs AÏXngbf .d*T9,V߳{&L@&ړ+7^ q 0a nq Dp?4@1r t'60C%Wµe]⶗ OM`  kn& `5lmz<fMaSrPAz1 #2UQJEҥ_akUpѥ;E۟A`hiCETʌMp?Th_li\x~_lM:Z?O^;3Mn$h蚗ߋEQ-+kʹdcxvZN:Aՙҙen\ٙBT+]{Li5u\*y9f^vxYcaI2Hu_&{!mrosu B]GݶV{zFP)yCkLUP"dVѵd v]5|WIotHF!PVK,dq[]&R44>q5ThA.oAxϖAd%']@ma]n!W{/c]L(;=_b!@2QwĻfUY|S,)[drg\;^%r>0Ĵz‡9@*`|Ff甌DESxwa:D@eOx`fw6huY , x5=N SIEi`]*T}a|=anpFo O]\HF@ǔ"~4i>~ χ~sA" Ktk悻!6QޛSG,yeagsVy|C| Jy#{⶷^TX31AɉXTPw(xEϻ"`1=ȮytH'{j]Eҏ~9:Iqm] $ݎ Iz)'d{@:ʀ_uOn4V ¼+ݶ=]_ʦqŋi' nF#\z{xKv##y}qDm^( >~i銼̷r -GZڊBտ .vR s+Og Dg8kHxr$G͏>yl<[D5fT5;J͢WҐSqgn }ݜXQh*CiE+zd΅d(FoҚU^o1? +d6ՐiYcxA]nJD?ޗՎF( /y GVygc#ܶRc}ᙥ_^<0-k؜s0`SMR€ _=#-tWzf/_Ł@Za=~|jX֖DĽwӬo+a%񡴯\R yuhQXQ]a-{}лͺ< >vU`ClI")e¸}""\sǻa5()gёO|t7 "KC >0c%&i&7%~h iiA|Y”{?&BeG&4eyZݓH{mwx"󀡀/&pm*DF8I򐨦+?فcCUڗ up,ܤ.v]>9Zg'}}d/;gLuOUok8>ڰJaS鬼է;%z4Q|c?*WQ}<^sVVvz2G\M.[[1|re)yꡢzo6V٪u)- 7T{H!/HKWR2ȟ p1!L8D[kC`i7À{g,JH0g/N+5Lf뎇S*/tܶD:K4KP̉ +꧁F8`œ\F"wjҁ3y/.U#0#dVkٜjt_JNȄyTz" SU_5H±j\ f]F N6BO 2 oUZ/!ЏʩY{4ui g9g ״z'\K$4ZD/z[YAT `!(YR6l%yu_E ,!>djGUœ1(.hbmNwI>FopY'yQ>|z㵖 zю.? m$Ay*Zm!G<Ȱq~Tr`K֊oAH9yfD ׉Vho) gr lK«|`G'}݂>d *􆪞8LJh!M%+ PgWc430&8UM\UDBz|Yht~dZMx lXŲ6!%8L?ٵ`cZZŲ_r7wa+aRm`y7ƁgCm_ؽ& KO~YL^f 9zq{M$] iM^/f:ERu;AhqpiS0@na^ B4u=mҧ,_"P݅%Ov[ k9!UI) LڬF0? 3# !P>{Zuj~y_| gYk-wLdJb8P2Ceټ]2 @94bm2S!|{K ;=7l7*@-C's[xm*Y"9)ָN1 Nn|S4urd/=8/_91"LءGJJcx5_Bu<㖧rT\_%=F0B@K˯f%MKOS\Gw씞/ cwLc.PCl4L(!u׳Q$WI44;: 1խ, U\@SHzC!gǹl"?pl ߣ]oze j`F]QqWDc@?i<ֽO/]CRܛiK&oMILE+iz(&9 NY&_?w{Gp3;ƾIN@j su=kz^<4KCkD(!kZ^Bwưl ] (oT(Ffd'g<"RqQwQZdFHհ2rGn3S`&j"i㪹iGqlUƦXhZ܊o=bՍ c A-^@lϟ.y &՝_QWgLi]4%jVHAdtTwt_͔#T/qWE*Lͺ$  S=\4Thh('$%klb9&:Nk t0w]H=Xq@CWznsh albp“9Wlons>y+ 6k!K ~xYyO^ n"S{i9Nf]KW{mԬ֎)rGɬ>c JgT6M}Ģ>vۥ`}c7s!D8LM7eJ5 ;2 6o׼UbP'„Pd1Iv({|غV@ `4~" M8[\@snz<6'AlUi 31\`dZ`7҇*a}tΊF~Uv~~tx׊6]iE5PB*ğA1=+3;rɽNQ-'ȶߞЬ ׿bיfPBȥAsas/nф#\>cR4<#np2gPWk-<'Fgj~9uwi!~XrK0zc6F;|ǹ,5C}MٯPʄz"~0p9=$x _M8f{([j8#ۓ.OG_}CX[$#I8~>XΟb%~ "a[(FaRBq6J8ș|*X$%udɞm76`#p%GSU)5v'c}Jk"K=rSC`qZ/'[?Of7EP<˿Cb1= gtUli~i8팊׉6ZhhkD۔~qwZzdM>2[x.y,?se#d7#f!;=^Wqu fna(j~<+@'vCT|w^_Hc4-j{ _bRj;OJeBg p -ʹzvd2XpA'oCG{txN܅)u!YWJ> ]-uiV6J?ѥt1@Mpkn0=â:FҽD{$ԱC;KVk!|3K[\փ |8nĢ/2L[9`TVfj><$-k mPRf1,"aј ҋ&߮G*[3IEk]22Brh"#A<U1{dc#ק5"p{b`SqF@>:@%+ٶ.~#."Ryo*7_"b,">4& py z 9Eh85`GO!Aj0jjr B#<՝ `)"q_~ic؋{Uf̲4}gzf:f@AG@Tq:b|+PﭮUc*&1ru= rQo MAk=/v2|;M#cNq]_j]k̶h?Sg wDd%x?mMJ<_:3@y#O2J5!X*֥P)كjWD8Q:$yůvl*e)r;c;a8E~~1nWh֒ȥ:*![6G]}P+aQX!`p_S1 F\gR^8-]It㈝K`'AN,B6|F(h64[aPuﴻ$w_G5TjvuM5A{Gt_Vh"Ue!k McfpDGd@ٸzb~ZMo UBS;nm6F=_(tn(n=4Sc[kr$m="'r#~ToV6[2*D$(srrÞ' ޳a/H}oUo menIϬC'KTQ{YwU:j˙~k'NVt Uɤdy\ԌT8sQttGQ iNzZc3kIorBIi1rY~jJQt[Øe@]gޖ[Re&&tz)}6٠ ;"zSČ9K' Ӏܝ:B-rq`\ܓjUlG=eq?vg^C')@ӄ"' 2)_G/k-:MüÆ'M3bf,TskޙGD+=#0xLw?UE>33wET6)pE@] FS&=iq=%b`o ǔPb zQayv̭x?ӣ$857*d;iTQU&dͱH'`4CHq#UB*-ofr Au+ vS'sEiT~;i+PgCJVܰӰ>Ot+7'Y_c+-C:}sEca`@,Yy\'-4%,YSY?4L1ǛnZ;{ł[X f:g*}k%I?hT^S1܆e%#Ҝ1} ](۟hNPɌ $*,xڢrt(pl'vʕOFM&,Xc: `}lڢ"ţ*#@Y dQ~^ibTԄm*H8WHYՓ씨Irg@s b6L%RJy2n90OY-G1S$vs s/IBm(wdBW7ݿѡpdԌNlڵ}igILZKh73+Q,G^HznC1@J 0~hNJq>>{rִtUǼL.'.e4 &d(/DJ+"oBZ1&@!9EW3Q-[bkXt]k:R$qynoY=fz1r#3f'gQ p$@_E]5tџYeXNJHcsȓ&$s >KwZdh͚r[1M\kmsy{Zŧ+V̊`?`h۱Ц?@VmG!zTGZ0FkRc^Hm| +5y5+R >,n 5.5 qh]G ][n1x"%7؊*iHoeX%[m:@-̉+4~LN}hJe*Eh3blfsGKDNgM=~(:h/E99Cr%-)rS6ηyaSkY5*-J5tr2f'bC5 >trB!i7 *iIJͽ9[/3Юyq@ւDM7Xm|9 ]wױG5ۧ jI8)D$ #ցCeƕ~>}`q$#=T:<~y?3I֔f(qdGuGE?#mdejcCj ҳ X)dl ZH:7F-,~̙RiCGKIaU浤s2q5ޅYWf;fsIh,::9>B!oN=M>w:tQJ-(uXo<#61VI3}} a.c} Z0lRa8JZG'de}F@UQjKJ I\/SQϋy3۽nKȐZfmFOzڕy 3Ac~.7ALUKm" BNS+*R5"f1N ͐7VE"p]m{~rE['QF G7:8 #['Az7.}r ԧx8"9xҘNq'PQ&`W(3.X=0; S="  0(LXH#˗%1<2ys䎾҄p}'Ml0?njV=`Y`w\3˕'rwu|RIKؖ=nJIQ_d@p? 3ۋ,f1,/ s1 Pֈ%nes[ M|p BefPjuG Va';l6FnW(KW}aqP iAl$3CA,_ykKHژ;C'׃On[_Hk1k5l{착^k~d20cD1pDb|R`xZT0b=%(Fu3 H1& OJJ Li++IK*+[*RkfD,2;T[|+ 5XwВP򙈗8h'GC[T&Idޞ m,|&r?Z;9,)֊ o|Վ89sMZU=G=ky> Ukט|=m)b B7J'<s99f"h5 :s@^}Vo4OLM3S.ba0Nc9`gKF\V>`sŘ@9ax %!A| Q pf;EMBԓn @&C1r$J짶s ̪ޣ0.3& wW3ۜO5]2! ɞ67-iUX~ΰ:V"C/ёD1RcֲE$bIйO^K3760ҖfYr:isJm[P(!`ޝ&QNkY6oД3,ZwB-n{ݯ[a5Qls\"9-}pCnBk@JPѮ|v?*%XPqhP[EPtg3fLєwfjC~.TLl;9’ OD.k[ ?y}FkZ=.X >Ȉ.xHXd;$b>tܬQN.NԲ5T ~gf/5nyk|`ս!0tZ~ r[VHnjC$͖ZM\ )6n )Y1#yE5 TȊZ٨p6'LQyC:EQs z`*?QGٸ@#rb ,M H5g;?e>߹ }Ht`^u{ÿ'G̏d>>kWutf~V W`i~տ% ~,icwxZL/L87,Х{yo{,?"P;.GlҞOClf,\5S۬`d9.8z!j& Sc)cdԸ|kbsOF*ב@_ɡ1Qjv3ǜ#G/{=JZѫ߷EZf@EX3'#xv䕰ю߃5anJLZ!n0~Ń&O{IFzsMOg(_n 3rcU<e8ToA۾\@xD(m >TڞX7DF } }gj;w05/tb&ӮE~zD85g~gv7eμlӞKp5_&}bJ_⋆+A$ȝ yZ2ϛ} !d"`)=Rjr!}c, 3aڔO}>蔁Z2 <>*"FjB9#AWۏ`ȯB[po-CzxJ:vxtJ:?vfbH9 PvJpǸqXw "l%P|pj8z-._,3㇅m(C<l٩ .Β)9PKw?tO!ݽa>U{N5tiLqR;7Q;?tS 놈z[:UˈM„=LX_7.j20m6@|'Z}Sl?م){b~t9ru5*/S'[ndyBMs 4ktPfv*wAxyRYVuHaS[(#>-$Ӑ|t!?.O6Mڈk8])}4UItS|֌>+Ӿ{0~ȔŻcO[a2%]x[EH0+{`-ńZ&`_~8[[ȥgckcɍfȹa'7 5pvgZ]D7O,.\)d.":f Kv&&ZvFsғg.֜ JYY B!Kr\)}_\Ъ賤h 0y%%K1S 8 bGn-Xv#Z@x$-qǞNK 62R)GѮ '6Jmxu#)?MG!(Nnq(|kflɳ(wK*+s8@zDMQ<ؚˍ\fe,z "ۈ uߌgFWC#*12\o:5s$S%W %5qtKRH%pwԚ7 ;ǫ:s ZZ!&#.(ȇWVĔ>Ӿbñ}($̫' YJ4jBIzk -귒P?Uϊ "eހl| y@M(_K@G՞Gazb.*ĝWgH1Y̘p=u$5!iɯe8%*=$;x:]m1'@K<>@PMov=^ *q>v!9Ytgxs.gbĕ[*uzʈ%JѿGo WE4Mc1nsaG2ɻtrb 1G祸( jHĊ+'6R]t-~%xhz`'@}!j2we<6PZ=a->gз$6 ʏB>hA( 3D֣_.SZVPZ|Aaz$7l7 S{.0ԩ7Mڥ{ߨ;dOUjS0kn liO4k/Q!?OUm>,Qg{ou '9^~A u`̈٩aBP6+Cmswzc^*?I$t h -djv( fn>5Z%=!X(jGL2,[|vB|E *XfgOŒ\z- KmN|U/PҷChocT^Ѻb AaK83שj<Ӭ'_eaLY9ËC ?a5_JwErtfH mfXҕ6w~됌' 2y<>V$hߗ7SsLlR_f~uS¥jTk[ Xӛu[l-X+HpsHʱ5slh%:9G2k!U.6ES 1!⢝sGjEɈ{P6w5 IٮO\DI,Q+QO_/ؤ|$iVr#5,an_4Ka# L '9_.ēW6Z(Barh64Hnm&,(u5.*X%ଐ963'([1݃Ug.u[ +gr!%TQsAhzh% 8hNu=K,Qk@v47|jTx*/}]L1ڬ/|&_! _B-D4rFk:+s"qF>_-lE7 oTFO#xȅtd,iNFMRj h$ɤ$a~>EXUaAdvKb[d`tG 6{+|#Cy n q.SMD^JFU'y[]k=$,u[ C'h d[uADVy$2{hq pi,vFqmQI&yCˆJ67k\(W \%'"L9tmf`mc{s<pxV+~bDDa=eU|(T LkR0XUrMcLFY=OCiNX 4+"ЙST mA˰ ,"oLx={2DyW;::H btzsGKso3aL` 6dl8uɊOX,8 ;dE^g8盏(/MO3/ &fK!`eeZu DzAxg| /,"T&S1XOO@|ffMvF>Ɋ·%<kU^L-CD7 xۨYU¸+uZYSvko3tOG Sg"Q69_9cjwхf/tê"5H?RSS%J,U=]<R x{_;4QԮxr!K\ETu=Fz[F>UmRkJcjs@ 5=~a_|3TC{NE+W81 grWPfÓ)~ׇ^'~'*;t* Jl r?tm}%a5#DF81L:20-g O]! r96W_=en2m|~\ 4g(zeة^qbfNMOag@բѫ gGQYl8oRQ#˝N9?#;w=BT &"|(|)s/GWy)U ’z^&'[WL߿8Is30y$E[-+f&Z](y*V_y.xW•+(~)>BR>%P"lvF,ԘmQ×o)Hi:<7[=t_vŞb}@bxSixrͱHɔ؜yC)!oPgmӐ qhz66\91ԋ'YпNpl7E~#S~ j(9gPńi Tj W;/·h zҪyYgnxB`ekpvHQ>jlv^0{ )%зϑԃvAߐT9EHZ^,{񯛬ERZ_IͲ(ͬ)DP~}]]?^ĭֶ]}ԇT5a?ϝv p/_BUyeݯ?7wANM/u(8HB;QdKKQJ6\vJ$Y `:~y ɽ&jF>Lki)VX8vP8DgҌ*ej[ 1&DS[1V\/0@6DF#M-]JI:yw]'Uc=t:;VW r1Q?=3:l< *)WZHa/ioRhhdg+}߇s=K?=T]@6LG]|RP~T%Η)Cg‹aL\Gڑ)]uǿtXڠdڮ?~ۄ@"*NaC6KCq5CL0&zlS/f)gRBձB?Åz$ `r 'o>|X(귾`IEh?XJXwUe[&Fʦwq`਽ӈޛF:H M2g],hȹ BhKp`s+o0V,d"l $Ze1jM.[&np7NbK``2dDžv=FU0%>ȯ ܮf$?u&VS,}矓9'jtGdRIhE/PiWG뿦^TJ`94gV _tŮ1X\>'7Rnj]6#0FHa .݂woY3M b9}@CZ(L@Nҝv>9[4o|:.D9Na\e|,#1E=?Pq!v5a Z2b}LӁ$A][ʛxC@YzI~ω bCAﴇZJ`_!¿?QC3jhDzP]6eËҠ/Ak'۹LW@w oSܨfF^0~c%!]&d}7֬xAK|XLJ=YK7!qlG ɱeOE!i}c'LKty&-Z-¦Ot|d~ a)]^H$k >A%om iϞ4=fT)A^L)_5 %vL㙓N0 *`ggsOS[wwBȍ(F,F\C [PS~A{>|'*VsW\ nX)a[tv~lAe\UwR7D +>{)-'Aq(TTF[R(ް G%{勐 9}EF/37 5԰c4[ta|g3eRq2kfPCLU4]ּX}soS ?m\m=CV3QG[ee %N"1 ;UȁD8 zRA`')L *k (GF4ppq̾_lKwj`;6gܠ1rP6]wR`wO6r*bۋ=@?ب[Ew½uP_Y H=,+u^g<)vgĩ6\3Y*0QNȊY&l2x*lkۮqo;{f5>-"9z^.2X =V4~oQ :CnLKݽMk%0xÙ`pz˜ Wn ƚaPLS~J(l.SƴK <),mURͧ{ 1 ->ݵv; RS{r3. IʘmuSw=`6EmSsu?7Kc1 ?9]J Nh?2 m 9H֒vZ/3y.un-j[WDUl4ߎR~ˌ-@JFٮb랂4ʈ V4hYTvXG$n2dEԂCkIGCN A$]SSiQPKGFo"t]ߥ*]2_#JRb%`Tmy"1o"MFm+(c}7Z9XB@UU3e*藭}%s, vfI`xoXA5`֭-sR#.C63Ge٠fZFJTr\LQgD2~m1S}-mҐg8tG}ӣ] ~7}A?<TD PzZ[䑓fv,:,Ǿq-HX$=!f!uAx.қ{d;e "Q̡1zh Gcݳk.bxftBьaLK S/޷RvyژT1?^5POGt`GD ˜yKfr֜>L|3Ի G=`AWnz[@qeԼ6P&x~Du[7t<9VKA9bTDkҙ 4BGRy&9e "|ȩ+*CNC_A&&u:ktY8;hWT+0h㯎1ns9іH I8ʹͣ)b{{`BYN$( !hNZE %:O<_`3,:Fq|efboJ .n -!c6mkyM)aog5T2p#:G"<5@I(IgUo@љ{O~J[}L,j6)̭i:@5qR _ T0ve ߋ;$50H"@OMhj㐻шyAS czpsbKn )(n DLW( ݿD'Del 5 "@:tҳJ5^>r~Bǽ=_c8~F|D9uG,z6Ěv#ʼ6]R]$Ox]tUVK_cfPG勭!羖tu;y|_&וW,gP슚: E״H'"!ؘxQr\MLD #8Oł $ހ19PQD|<NT0hѫg|5Ohg݀} &DneG@L}PiHӉopR <6cB@gvjxT[:\תS!?cCQ4$_aZG2%#?[74_#ӎ!plz^,u4r )IF'aSȼХ|3@ &\B9p?H!L(AmQ̄tI |t2%PuőHsϑk=(t& cVla0 opyly Ixӂӗ4U} "UgR<}!ljm.}-f1^PNiD1ZB8%]geKL~[_lP o`i^t2C3DF'ì*S{u`d0sEҌBf쁣u659pS>>*,@Mo?XŽȜf́Nx Hbݩq,''Lo %Zj>Ԝu@ g,EXDwL<[~s'%V@{m4dPij3H.c  ]Q%d[nmy]=pFzCX\cYЏ*-똢Y6Qi|r0`l/>ATdf%=pwv@7z_NهfR/dk͘g˲E"Owǽc ~y^VHr c: m[Ik<"` h8,+C Q"KE3ʤ:5[2TSw٩a=S|s^ܫG()f`&$}-عK_rwɜUStSij`"DȢq)6d`?췛E(kON? 9ָ!U (3 +ta)D0KɈuq*&tZh@iatp^ wgٝ}Eh6)l JhݾM/ԇDG/ zOky2pk!?9zA&t1VyW/c$-&]Al>PpTj; Tz5U`%H/AFPw$zVl[>S雙@6&Tè){MgI=|0~PnO '+7Ztu(/mdn@ɓG<s?WUj2>hqTK%A.freI]'_-īD"݄I y,z_D+?ɷM6bRb:RuW⊨f9Y> ^يp4'/=YRxZ̅8dR( S.[5؃h=%6xw5ςQl1)8 q*Z )]JkTD*v"+i={V% e$w?WB&J6'`q/q' _ 9"e;B`Јo !t~jUzn4)FHhZ9/k <'CPΕwAŘ̔|zuN EpK|Q pv^})al :YfyYܜh} .$A5RO볉GbC(M#Hu QB6ǷW0x3_m"DoBɕ R9~|$Cy&n7 *2Z~`?3E Eh:rZG> ΰVlH EtDhƯL4G#b؂NPg(qGTf4z6] [P\H!lX wnrs 󭽞Lu4AXoMVCABʝ =N-&NǙu6iy,S kzp-Gi|X4Dkѷ"xAbbpri"efB)FsѯMZUϣ6-!:"g%{?Qi;C7 |eb2ŮMՇ$~ǭ0 @Ӹ@Z4oYesgp5CYbiiRz;0+>Q.r9.T /3+[AMKy{JVt@>y@ I+!?f(s9 Z*m ].;Z(q+ X֊SVv> 2)D7SԤ2$eyem;`;pIܖF,S:Ŗs9 7o-S-O(sQ&[X"q%`^w+bӅBGlndv@nQWyD@L\عcGAKy +yG݉BfY ۀܚAҴ{^}` XEdlq. x%JT/byf7,%`]=s#h fRQ)'|j~EaL;imG\&f.P@9>tSo9-Lsr3-U_W<<'ٮ7%E!l>#^1NY##2 i}4R`+fBuKyn޷|NP9^ +P+,IcgsڃН8֟Xg)Q^`ę moz{Ee2ۻTu(a~,fr B>zʘdD {>o`!ɪDJ/c{)(vPM~_yAܐW&5-[ =x' 1P7soFNU 81>. YXGQȺ J,׼5Bi1"@# f5C~[KOec%Oz2ŝch+BVePd+"  5KDexZ-&zh5jomQn}#BHa"XPTS|l&c)Ra1ՔW&lB|>q",QC%h!,K*΁ kNYҸ١!Ujw4/9('}+^?ͽgvwWG]gb0d\@!Tsa^rgǥ6 ?13[7xAQwLk ^j1pW@n.)l fIx+Lد1+@}Dp@k6{y]aI}AǧeC1n}4\)P 8ܸ>D+Ipw *Bny ôʞ H6_+ɋp4.=^*(z604#-Dp\/Pw"3bZZ00d{2UwB'$PmyᷥmO>]FԳ31'ϴ>sy1k/V-!t/okXŵβ^hJۼ/ cpBjWY ;j>4ܼ !:`eۭ-%n=+q YYTK8[v g[7]7v;T^p7hy%DP0D܁uV++Gʌ6;?۞ " sm% >]\&6 t&%z:FGh9p!_[dW9)JxpXD=+b9gĺNb30=e< 2>;s jr;(͢ԴXv_ҵhqP(>}z I@53{9G}5qb@!F-Bo8,ThYI='x:xPZ#\"g[T)g,u&E좃~7}XBIm,MZ3p8JC3)xэJP{`񢽋:9ɤ@iw3zB{t+rxygM6 GG=Ʒsc'N'W;/x}Š"qf@? s/oY3ĽkZMNgx C3>Nc>zͤ؍40Ct-Vo&/y>-@^+7-WHNJ"*|HfSMY2(5]A yn9hb7~!nT+bwUEM!HtTzw^ty=A WGu˸JDW|Bp@{_"[mk'ǀf lcl?ÖUD4 pJUUuD0EMų-#is  *D퀐X1f==夹EO-R+5&FY{(_ ravW6jAb3 "B[C&X!i7 {HP's']Y8p9K߾#GxZi{s]s]RgFodV&0V"ZP$k૝;̏\0ߚ,a2M]ozL L?iŠDخ;2ǫhLL3ڶya@mR"Ud[G}>}h|廿S?7'LgOHfto5([vb6i؁| 8B+(T;Sܔგ5SqJ[ yC7JeTY[i 2 0%3ժM̿!o{FC1l1wZw鯔wprW:]>+‘Lfu/5eZf d'ԃFqႈGaHpgbp"jO5!!~? R 98టo@RKǻ832-D~\Tpu'7ɳښDw'ga3}p%`#"#/i/q hmNkvL<-^Tz؃3&gUk*8$%2IDp0;Op4fdKO2#:Ł6@\B7k}fO{U)"ɴM%*THe<e,Խ' ˝ UM¡ -vj k'b_'OXE,`ømm[;SdkGċ< E_$;lz^097;[Pz@~ѲG:fd;Q츀TY}Ut|ɫ ZԳkY^4A)bQKKFN3~wEGgf?JRRO,+ WnJ1F [yqR]i2 R/f|A H5A aᗖ&9?Y8Q)*1ىV`OWCZ;*rs|%1EԪh:Ϯ{LQ>#0i.Tt]@-H%|nF[]ѾBZs8\A<Ӆ"r.0iNA9V ̼n%tݮEx:\izF~/$4vM'ɲ!nC՝Y\8f5_MiF>u8k}HOSg/fGo4F.qa 7hfߴ- û؃rSPf,ùuR/pKEoႥg57E%˺ :_{;3t*m#:; 1s8ᶼn#""Η?\M?GFTdn)@|MAt84 xHn@*0mH1M#Z3)9m nY,?"o G"_r#k+Z /q)hn9|2FO1&NlN-%ت%%mi ʂWS2^ЎKm HG0$oƕuۛBؑGQ]i߯g2K՘b-3Â#܊ c˞TLcVͨ޹@๫ٱ@CA5Ͱ&WOίN@ /D<7GVɠq%MB\de,+4d@.v& T"c5Z{ `)8bJ-J=+k32fp[LмɏNǛ<oKo:"pxW ,JrzI\hiQ=`s#,,/'i%#~9jVlFj`9)2RhB}:jJ#+EV4zߪ^] 7m)?sPmM*ݱn C]3z0pڤ#?<㥣}AoISr cV(h^=Df^ݤ8_3HByϻPGw鮂ŧm2$9 ?ۮSm afz<ݛѴy8m2n{"/s4aBŅIk8`i /uTH3}^sGqRY"NB~Dp9C:*!1U_W{KEy'S<ZqH72k m 9xW{9xhzI HleYݐ:wt?GO`A3c75?q6\B.j6; "=f~wÇkBfL.#W(:VȐlVsh\1;˷]}:Q>s3P<1۠Voj 0D@NИj&b9FL{i5bU\n]ZB61=>k y1VH@{Ty`eiWܬ{YX~gPK&}D|R{e*GP=gDxLS+yE.DmaL.\Tejh/!=cݰmȇ=&]=4Y!|KS Zt B{Q1b'Kߦg4DT\ҸBV%= ?tOhv +FZrEF *jlU_pFQ*ݲ֣~lWr\ N0Q?!T9ݹ8 r *#FyۖHzZRV"I )֣cQ .P(Z4V%:8˸n)s}E~TQQ]Jq?>ӏ55?j/(m1VRw`K P8J~ݣ4V.0ۊʑ\f/='YBYE(sst\IsRH:1\aYL"z3.g\T*G_[h0X &1Y9K2j@{>%&fhpq<ʁ^d;E h8Lg$ˠr'fs8|ϟ(_ z\dzssgNyganGV Wdonc'Lۜ_Pp*xQR/ S'ؙ4%ȅVG}?=}) ϧ8 ǧi?Zb{2f? MauhY;UIXRo"Mp| 赱Cͱ /9Kl0sc y=8Go xlʷn͝xEXݦGdT>?q8#KG}_=ΤIX<2r$4m^ {|*\ō7tܵǜ6LiΗu޳:,9& F)Kt&3\ћ5 QG ,FuS0dI$?VA+ _?i @3胉;k.˃vW.o_=|U \+ Qf0cMsHwt ޓM/ȼf6Ox/'߀+YW!*E(AT|<;֩!瘋qBLa g4]LjeEG3[*kXsπR@ŭ1D D Dو31Z)#Ic0 vm/χK3 %DIq3hm!4 J=AHvY ]{ŗsSU(BFȼT[S|fK ke¨s :a2IvBDS'N}}-6Ld!wVfbk7-NB!@S&5QZL6n1H0L " ĥ\5ltF]hn/aT,M:3FV-^ m/sV$yiME>'d@SIij\쀮X%f.ͬ{;h &vk8HaT,cX][@uϒSQDv|,R\޷]3ύy\Uq5x53++EI !ʌ7z[;fģAЩ}?b^חȍZrF #G JɹF)#-4KG+\fEuN3v(3mmѝ{ $6-X/S$͇@-nzm+=);AMg!~iSbZ*xU\yĔxMy~ Y$_7 ҹ BkR:{ظ7Fc1|pK=oO2xHL6%s;!Z'[rϲZ0e1Bn.OSw!25$2l*X8We .$+ g;1TPBŇ0Z0|ΠŸ[Z*N؅5$Ő!M"Sevuh;*`8$Ϧ C Q)G'ȓk'b"Ld%#ʯ<:*D0':Ƌ BW RH|H ;%IG4 EKY^kLLg(lV>T CM[ Acp]GIG/E0JutƧ/4|VA?E@k<2Wy0 Vo} f,GR&Q3 rl0rg3k'@1;p/X I{vڐ UbzZ;b]~hCaE,|w46(AyV^,s1;E4jt|Dla_˰x1>+ԃWt;dJ__D/4ɭTҚ:|Io lCAJ)[bt0Lp׻5I:aX3mgJgc Y6j#%Ҟ)dX#ǜ`߬~[A8G")TΖB(,cFL; O~VϬ hBZG, ֏I@= Gu3,*:NU q%& Te (jN ~~w 퓯ڹITarm)y~*!Xmc6'aWL˞$j2Q{vK*.DlSeɘÞaڈlad|x& %.yӯ=Hc9\ vAcO`C@͋ۨLt9 si( ^RmJl{\ȳFyRH,0/VέD'Zx~5/w6$TZPieuZtJ6䴘P[;>hyz_@,5aBFvԬ@۽Ee69e"tkސ8NU3;9ʇ })}iH/;B›%̅AM1 /,3:7kq03Ҥ*^[ˮkv@@/j~b* _ޟsA5,W& Vxw9'r②XBu!EL5޵55ּ; kǑ;2\@C06Y[O@|{+s2 VglJxf48*tyLyQ<a3/bt"'gux#o0 Mھdw||5%-ME&@!}Q>-}7C &/Җ\=ʖ]g_ƍ#W?1+,iH1<'yD=yR 7wq00$NdspM'~IEat?gɃf?7{Er|7` ˵NDzp,- ܳԷA٣[* ftx]Eq1+,xv&đZCS3b +Ode_|sǀ )zM)Fqq^0,- |iwDbX)Lzg3.\^[i{zLG(cI0C?ZCL嚈|1Rig8KNa1c&O.Ċ$0.;"nh)n)eu2K?DL9~{)vFJYi%\vkfU/t _U,WfL[f@mL`l4ۨPHnE USv,b/hYϏACi3K>û=iijp ,{zq1rv 5 nf\S s Å YZ