sssd-tools-1.13.3-56.el6$>X4{ Anݑ;>2X?Hd   A *HNTbb b db b b b!xb#bb%L%hb&'9'9+9(,Z8,`93h:RGbHbI bXY \<b]b^bd$e)f,l.DCsssd-tools1.13.356.el6Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP passwordXҿc1bm.rdu2.centos.org vCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxi686*ɤKSA }5q"1EQ :bn3] 11m:+}MHOs x?sH cC A큤XҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿVpnXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿXҿe1ec854f68372bd0e1fb6291a2573776074e921bd39bd69a8d5eb8da2c44dbc38b16a09cd1dc9fac7c51768c27ea19bf1bf0178909122c473d60b317b832c936881b770495b8cea72067643c78870ca9a78a6d1471110d74d39710050bdbda0ce2b77b0cdae21a8dae1bc315ad375eeab66c01151c46a8491e86e483a753062a82fef17872487505c20965039a68b51f18b63afe029b14ac4b0e403703b050f3074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45e21af5f3b90f9ee2037534ee896eb380f28ee4c8287ae079cca647e0c0d110f48686963a818eb925ce8bb0c94f9f14bcedf56014ffa17275455d2879a0fea2fecee8dc6123da04ed246a9e7d1c724ab7dd4d41c33f7923ee72052bc8a4b934763363da7e47f2c3c6df61a7cb83fd33d9eb3ab5c8931126e6aa274c347902583cb57ad3622cb9e17d2bc083e990dbe9c59cf2c0835cfb21210168a04188196c9e18ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90350d84c60491f81ec38582151a779c4e2aee537befbb0bfe275f4af2f4d91a6aca6699600e6c590db54624ae492e7bd5af1db45651ebcb0845e606ee559e903c099c3dd8a113fea8f43eb6155a4354bd4ba2aea406090f3d764f486c3e07556996ab7f4306a908defcace37f1f6c91dc4a2209ba0ef8dd7db7fbce0d4f11aaffa8c15ea2f38ae06aba6778774ec66b34427d8643e9a628e459fca2f53cdd141a70cd03bb230a00adfa378b30947b3c4e4f621421d5598642bf9562af08b264038b2e13af39c3346e820dd25b1cf15cddc65f83e8306b4d14e31d1195d193d3aea0de4f9fadab65b5df315e660634fed1636d3838895735028619c989826cb5cfc92d14b8141c5b61150636295bede5443eef854b35c22858d94d27d2c4cc1809266f7df05620679dee3ef453326967afa37b75389821088071bf478aa26cf13ee8246153513a6490d29df0340aef9b406ecf914d9fd7a8308b0516d609215b4694c32ed1653e72de94bd8799e968a4bbe1b8b2b9b4419c31cc4717c46345219f05981d65f788e6048bc9d1c4c6b217409a3fadc3c5202098a604b69c1049123183ddab8a97d33f0efd00515183d712552a7fb559d420b2382a98bd47a8aeeee7ad17ac5f114eb8c50a94cf87f49ac08f1f6a78c739b1d66a03156b16dacd14df3653c2bd588a3ea18eadb5c1395551ed10740fb86aa2a6e3424550381c92edff47d31c31c18d4e0c2f3420467fa2ff7f54badf57d2e9d03452d0315d4f328bc751516fc4a79bea2e43ff71b134457cfd7ca6f09d9670c757d031ffb545df1350778184cc5c85e2f38cefc1a5fbc5f27546a44f1b906dc11bf7847b6dbfa7347088c3644e8a7bb4fb18fe22400d07409fe8bc6706e9293859f315cc1df71e04a9ef1f4439be013ed636fff2def8917761d7121cb9d135a391457885d341aaf2a349d24a516186ab7287f5a6ab2c03e8afda7442d66c4b6735f7f2b2b644f0901c6555371032147c552448e5bbff22e4dab75d9f0693c61498a6a474cc1da399b24cf6e74b46a9f5b20fbffd2963e906ea123917cfac0a9a145b66952b273068dae0691872ff8b6fc1d5c7eb4a7e96dc9944560779ea8cac92be114f2a615d329b4a010f54b2e1aa82e5fa037daf771988bff39b18e50d73d11e86914487578f0a7d22e14bdde49d0276572df0c93118d7e18851b28e315cd0b690fb3653b48c041c1d18b55521e967929cf5519975d67cc935da4125c3e4031f740ef0691977fa70a7cd8b5fc5c5640e8f39293bf0d0fd2dd002409bb268ee5b7d5c8e9f5a2e4866e6434029b91fbe126e9b533814c2faa0a6eab5b5702367c212a4d67b56ea340dd44345ab427050eac3b66b6369040272b6395539ce39e226e0c922b03d49d6892e97853882c6ba50481d7743d20238c903199c59eadeb3fcefbf87fdedc2ee4ccd8d091076e2949dc5be54449913b808600697856d77d21e8c6b015c713657cce66a0b45917c3984c95ec9dd46b52bbc394c999ee1480a5da334edddaac82b413e6a972b5b871175de92ee547fdf979e6e65996bc3af2f4a47d1389457c87c49d9063684934fa435074f2f345e74b4381acdf58882d46471862ec1f4bb83fbc436f5861d9637216e55a43f3af1f7797aa78e950971e876219bfde4dcdaa55b851b44e3a24f1e6c13aeeb1245750e4a3f529e459b76904c07f2bfe70df8bb00c688dd10766a99d0370dab32750bb1104d0c7ee9490f72aaaa0fd37cafbea446666ab88a65a1350e5bd28bccb7c9652dff2bc19c305118b28ae971fca9a6a1c609bd4ff0118e29c72144475864f3eaf903bbd346374cd618d03aded0b9d85bb22b18ed76d7a520d73a7a98a763f502bc8280d5f025b1ca3d6cd38a1718cc09d1748fc1c2873cefb6307c94a7bdc75d597c98c038251087f2a23619b583a8b546086a0c9f418c4af4c0727e43a693f87c61d7c93860c972436b203a29e6a69f255559306bb17c7f1adafce4335acbd746c86d7eeb69a8f1cd845e74a05226de15ceea5e0bb09516fd684315b32690dcf357948e1648bd97b2a6664bcb857c1e5fc7be27495f3c2e99aa4bdd98a7dc152a75b1135f31dd5ba347cd62cb39bd94bdbcc84c3a6d505dc36e4fc685a81b8b1b79d9807a303bc4a5a9e10c184a1581e77bebc6c6cd32e0a20eae4f4a0e4f4ee90d479a774286ee8dea1851a877114f229cf965f4dd1d49332dc9c066e16edeecbde3014cec0ec6dbc78f271ea0a75012beff5e88701e02fb3e1e4dac8b9420807841bb755e2115c6c6e46b2cdd3c365407be4cfc0d9ba04335d0fd8145b67b045c23d30c8992acd37313ef3a7f7c9b0b703d143f437b5543eba373059805f2e778369398e0af93a55c6c1e962d7a6f476d66d10ff2622f619147e1c39edc58346d17405227e7df1e9f6336c813e618f826ea003f18d714d22e6d3cd717eccc3fc862b25b972d746858157b52105dbf6d37b9b4eb52d2a544e44ce2772184b4746e763ded39ecb4212ae61a05c254b1700fc47890ccaee2d08cb1530610c305cafe9ce2d38267ae622a6b7aa145ef999f128730ee832f3b04f41117e4c0000002c30d2e3b219c4f92c7a3ba309486e1874894b97b9004b2ee16c951aaa1db93c161e54a79d9e5949293b3fb5aca5394007c33971a5ad4b1e0acd537ca6358a3f620ae95b66b058ae3c3ad08e6688a622225d05f16d42013eb4be04c3761a66e93cdf716c743c02f68d39f71441dfdb2686664989e4dc0b629984b2e6aa0cd2008af061a1c3b83a024afe3f6fb073267a63cfec27c8c21fa473980e79371ef2b028e680567692def0429ed9209977bab51786b070bf54f8a69c5ea3aa03efd01f47e44c4d63ebc00dfbde73cb79d56e2d6551404f3f7add230b60c632407d918d3b04644cec57bfcccb0e3b7c5dbb43f8df8167f01ee0e32459dd00c9bad8c021647a6d93c630b21730d9b8d865066d58286fc1ebd25dc5f6119317c9749bb53e25179442acdba94c51e0f07cd3bf74aab44efb6ddb2a9e95cfbd76b4c32854a8c5cbcb7e4b0bac81fd5ff625330e230d3117b78a91c41095fb786fcd6509bad5436f2ea04a06301ceaab2f1490b76e494ab4927e340121a5ac02bbf151ad1fb3ebd42b8f5ec440e2c5a5f00edd5c0efcb19834a87e39d6f3a2a220d64272a18e15d645e576cca2f096d689d03d6898f0afe87ddaca1e905d8c368bb5730f5db2c102b487c47ad0bf8cabba8c91facdd4098f69facf4adf8494ddfb5179a7266accd21f434b602e562d6e11de028ff27abd1bdd4944258d5e246e2c2b056fe6e444ab9e82cfadc4f9b50123f031082ec69b3a844022f9f9b41e8f407d470ab533cd8e2219e5b69d8ecb20c22d514c1e15372e3d1e536a359272218cfa6f9e60ce38eb2539d222c9af9a192a73908ea2cdbf268e9d8fbf457e3eea1a45590ea8f1ad2bee83a70c9ffa0a528bcd61e0eaacb3c85bea64c1c286cdca88c6836a4252c16c48d7a9f2bed2ccdb9d06d4930205b81415331dab055906cae37e1aed485f5673cb60db74eabc239927f99438b7205875343e775d22d65cc198eff590257e709a4921176a33d8c086e1d419acdaa5b60c25afd269427220466f09c759167b9bb3c288d09733d9f372e17df19579ceb4a6852dde577c73c323eab60c92d8a977fdf6e12b1e6e36f9d8cfb1af29b014701d677522bfe6beaaf6739d9f4781c59429b51418e670fd8954e75713bc336838869ce45d31fc9d596cf305654266d0934f3e959c63e179f9ff666b2a79f55a41649897f04fab8e8596269de7f227bada85b84c04bf8214c716b21ed3775ae200rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-56.el6.src.rpmsssd-toolssssd-tools(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0libcollection.so.4libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.6)libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libglib-2.0.so.0libini_config.so.5liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libnspr4.solibnss3.solibnssutil3.solibpcre.so.0libplc4.solibplds4.solibpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.12)libpthread.so.0(GLIBC_2.2)libref_array.so.1librt.so.1libselinux.so.1libsemanage.so.1libsmime3.solibssl3.solibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_semanage.solibsss_util.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-56.el61.13.3-56.el61.13.3-56.el64.6.0-14.0-13.0.4-15.2-14.8.0X6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-56.el61.13.3-56.el6 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnu?7zXZ !PH6I]"k%}:w{{.E+w&jhʔm!r;cj$M52Qe#~蟕½|4@"N6"}eЇ&)1zkMd]k*An ;Hw%YXߴx|9rKiǠx*2}OLbHmF}ܗ>G[lNk58ns=D{ieQ-cɡ}lkQ/=w6>Xվ*áCP+5 |;WٺLx Yѧɯ-uTXϘVJ~WV2F1(cxr#F}ȅ?.ٕ-HI[ʃE pu fo/[}SU{a7 .Ӎi{5_Uho9G#qAB46{7@M⤜U㱙,<&HbTQm <מyڛay+"+(ЬY6"$MYҎRl0;7 \Iphӧw,L[R.L#-ʘ)^R93-XRbnFb><@; tqL.79xjBe~ydX՛b'?^` +W!C|C/Ƨ_?!˛@zּsHS[pIZI}6`q~$@Vf[ Edi#7ϴώ8}ظ ^7buzDqPV=C y%8p]!?uxd{M@k93/.fǭEO' ўԥ4~Ϲ/CE cvŽ/P{jbt : y+{8>EsNPsA@$2R@Y H 'LO]=}(z.&$a5W 8eio8gq a㋓حlį/gOrfr@((_Vsr.7}RX2KO|G% wyB5F>P8daFY( ab3X!Vj+(ɽBT&BZppbȋR|M+'xy"Igiu*P DQ_7p+|P4' .3KONްWH[1qPnq1 ަfNR +S ssRT&ީ63vr5Yx蔳z }܉&v> B|_m]+V؎HلiT~IRh[nT *GږVEyi;bWXO2(ԏ V[-yJМ4 xWgH6_.ƸʼnN TLU\q^} X[U@=1 f\]l?Ϭq8SО]<iK@ΓĄ, {xh.TPuSXjI*r2lF0֣"TY\k>re^ѤwZ=_, lO-vIM1 "k!fXooԹfHGc[Q\\:OJь ~MNz췮vIIJon5c]ܤcMph4٘ DzTMZn6gj.jtÍ,[:G;B>LEB6e ; qUV杒UCEL3 ЯJY/槙;ѩ;4=N@ ר%1`fxQ`!@!D)_~!{HҔoϑ7pZ[ija}A= U\Eo䒊2i 6I]Jx!oMop UY+#R3i (#$Ϻ\3F]C DDv? iv˥zԅC{=/"By)Onhy(/^Y);ևSj~)N1B.gݪ|`t -\ 7خX. Je:yt- 09AL@gNgц@wt3>6oN;o[_vٸ*S5z$j ]&W-r'c;P^Z^/h#@_^CsiV0,I)5^U`Z%2.. ]5lWbvf5g4?HB+:ִdDƖƛ&xܑ|>އw/..y1j  xAJ[70 @,l/Q 6*S)!x8c {] /I,ĦԵ1\fg^JK>Й}k'L\Ġ.xWӨa::'Z^4ONr <ˤU,ii5'P{?rvL(R?p֠U>GgOYVk2|c-#M^ NSv콸ug^?(tͼqa߳b rZtWw^KU HrruXEz`Z/WH -=tz$ 0/ŀY+z_# {F+Bܜ;t/䒝il~ ?b/WtVg?oGi~")_ҁMhX6,>1ǩb0hDK++"Ud|/_Y9mxjcyU$18[ vPd :祎R[L FvՓT?&7';(L 1El 0wȎR ᬮח"|q! ߳*&pes?P])/mP7|:#ÆJ7)O1)7#e8ƓlPAm: ?|R:x"Ђ3ep]͗*eoJ)kFi Ʀ,ot6%OQ2/|]wU_K(,V1\^zʂ:ZChdFv zD*]Vww\Q(؆WNIjTѮÛT7g偍јsx\0w a] +z;&\]Afłf&\쫆ɓ)iiSV,AĊ4Sh^ /Uh?WԈ^qZ0`Qy179P찑*bGy,Eՠbcd3*Ӻ,ZiERacKP iy^jR|y[H>9a\&y6w8*G`o:\ ,"feɘ17 %jZ$yY2-[3A̺8d)?m;g '7Q{EH=K1NBREbN+;Z"٭)"9{,@57.j-M\wzl?Sj,T3^[՟3Y>*c?a.cc dEm#wԒG$)^ W&v@1p<0ւ\IAi:|Vv*©\>ȟvM`M]Ed;x i.nm\e)<行M͍x,B WiePnlv8EPr~λvO(y vډDC ͚z/tHȜ>uj*i.٥7j( .e"áܕqICHQD;3f8'<7n1o z{&X>\`?ckL9z|:c٥[9Hd\GC;̵z6!'>`SO'cMa2 n F}ɰ-did;2 1 QY"1˿`kzuI՞PjDcn/čz@etz#j!5.BfzL^jʷeaY\eg0,ڄD#V$Ia ! tybC'7="*PA>$|{@*4T0D/tt12Ro:O~S0lpWL,Keϼ[?G.epͱ43ӑ iUJ/Rs7]l/Uꨍ=d^:( JvX<{\]HD$x~ yv:1rZrT|ayjzD(q˽vtJu啾bS&!6 ՟M[*Ðl9zLjcaAxH6G?doaxqẲr9Vt3h>/rҧÆQTE|("NAg@Drj8b";eDxEqIW~Kwن638v VdZY3bE񺧥6:̏S0 3K' S#|H X 6t+Gd {"q @ D,,,Y!pfy-t5\p G^OucRx[́TcHť+4$!`e2y,4ۉWfhğ[u h8Kljҝ>_:K2-rn-јa mn~ ORk3|G6^tJ[q;0 &PTx@\5ZDf#4"2;O/8${eUUjY_#MRv)BIp+ ýV϶WGҸA_^zLF2WtԥEUFu;uH~8^vFS^>o5;SlA sEKu ?i8ָf|(EK@-1k4V4ȜDRuJb Vn_fr{96#) ~55D9Q{4J*Jf*Iι;"~YKEV聐36G}y!i.ղ>BpT& cf*Dy+B^QB'9DOy$hdS"sJ-;/z-o6}I+E[޾qXڿ-?|<q0V;bko c @ĝ Xo)ly"&0ڀwoAi}au}QwħI@b%My3+KS*Uvkf!w@7¤ֆb( IZ*ʰx3XWԢ6X _U?G(=F%TTՖ}~BD뉌-!X]YƑ.n5nlhnj[^yu[pZK2d~Α#s^>L"rjE$.frRx9Qh>kM7mdvwk*(ND%&-J1s.?xSNTH^I FyH˻mcuvIZҘ@w߭3 L,+h{T Yp"r׺*5QJm4НXǹGww}y39{BxP+=ejʀ=Iwԍ؟,;s_.+d拗s $VsE|fP¥$gwg*\IF,rvٵF]5Un/)|:8å[ @ &vz1/3{3S KSBvJJh4kبf>ޒ2ȇ8xfI,EBsmV9C36@rP#FFY_\BA1q(Y(X(u2üŖr y.N0~zlOCcFsdӠs>YfiVz%15YzP(rwb iCJM^úVBz=B|!ތ`/gvI<av6NL 2eP,ALuQkJ;}~ӡ6F {8$y c>*V",oGQɆk xWv=|CAgt na~AkdTiBB I%н]Fj9oO2w2^iT{ O?Xkrf M(4q]$}k*lT2ꮳ,Xf,'Wi$_c<UyZ0^"Qfx6)EΥh~q,*Fz^SNqdiT~q ]H_'q\=Pſ݁Lz#Gr#Rc>CL_FIriDuE 5z1;H:-#Q&x@(ۓ@|\OJeD[lFcted7z%PV+ΫLZ_k{;瘂5Lu >icbiLq@RWV^YQ)Re hp9?Fv{d7>"/ק?JtB3*ݾ]ks# dSB&|6յqo> ]K(0ܾ.hhSOoic\4F媄K#7ҙuqaDžN,wVd?QCCI$]S|c}̯ gQ:蒭}+1P4kVҦinqQ#g dKW_ThJU@h2$yք‚9z"sk=h! k#z5@yQn[y|tXx5D켻ĕ#2|R4hFmY,gBGƕ&6ܗRk+l5}*v9x4sQ M-`|9KA獖KoSؼ {FT3X }"7Y-2NYG>3NX ثҖ>Ki~יH2dM;P左蜝}dnsT4ef# teΡ{!xa}\sBikMo D=MOSXȤ2ћ )[g~z C>NŻ-#^VVQ,)TײVߘ樉 /icvI .l$zsIi[XXlt\#&2hÏ͙!4X)PqP|+L"wso e|:|jP1UtE@V u?<v i\Ĉk\p.ܰLBTWLAKBTU,K ԴjH9N7JA&!^3-,ӳr5 iaGBP-@R8*cB>0MWP_BW?r-,0>ڝ$Q,b'ߠ?|C+ɠ;Ȑ9@\T | 5D+љ.̮qRRfiQzh?Awr%'7+?\1ϡvfۛIj!Yʰ%sMM2,. bM<{lC_7f-lX /wtqR9{YJXRAƧ K6eeyTEHىbF2'H&\dy__|pH- ΅EݜsUk9[Τn--7 w^ LajtCnFX KWkA 8#NA70#1ey5NN=]^z9 Ѣ ,59Ā=s}y?xYSoDmÓwNmK,&e [q,]Pu9 ) q";dO4ENg6*'&xAxѯΥJ's!òto b2RW9a{X뗗OjD_I_g?}bcD5eT c}Tfw7Y iG@>>HziKfs11SW2/wKRS}UwsdD+'XJ5t@Q¤lgYm-qiuaPDYjsG e^HfCұ!ܖ*G$]0T 2SZ:'9)9k+Yd#RFʧEV;,gPպ /2fR}x&{'_cv<Mew)6Vr*^=2 ⣍ nպ &~9]F`=.~#eO>^6W'J<~Ø1oefEa*? Ӛ4d{@O:QK̭@I8HpL VԒHf&IlS|xed 8>o]r }RXӣ;Ĕk5ȰH`sgՁiF q-C^ *`7ML'"ΐYNCBllV;CmQ6 @쀋 OSקosg,.y7FJ5\ѕTc%sn0[k&[cA{g," &wRK}12d60Q K^enVf_7 g>&@I m40ž7~M,﹋%ƺMɦsD' /Yٰۛ 'n)4 ^q9d$: sX[?+U:"*.rP̂~'}-=xim((Y Cܑ=X iDPoyv'o>ֆl|iFƍhn1w0^^{r1ZB\۪l藗W[ .v -XDK~mnSS%1l*\o yb8!g<67CmC/ϟkͲ_ C\vh- Qv@,gmʖѡ4R, ++s~\7olgv~^?ŮN $NRx&dx=& !‹t,ɝ)IلޏK.O-{'/zQj0)y ?mBA,/¹ӳosV6P5<*"}tOBWR 7k؅'U>SS/e) #mШXJ_'f-j FUOJ^ 5_lEe"^ ]b s?z օZ^ۼ>fcebThNe0@x; Oq:N"/y'Nm 0 y#JߡxIU@Ǎh!}GYDlf 6͙lNPEmV'&`,_H ʍ&M9^!6r.8ڡn鶢kwFD!:孷( ZeL k:1vˊm%)|Gr e[a)n˿(j3F4?5P}t聍SERZ?#43do.zDzLKv4$JX9`+'kQbnE7g Rt$vvq!8JjO2c)}4z 9A,3fz/3(v&{XQaiFAݣ3+E[ȭ2dmi;7 j]߀_uo ~ܐڻ %"T7iN%s| B}߼au vN%O|2GҰVa 7W(FEPW |8U+;j㥞[)w̆4Zy0mرJIy~P7$=:tИU{7qqQWnUak0}%8G;Ƭ3ʕBcw-#g1ugQM '@@` pt썷Q1 W0JJ*0 2Kr-a:~ux+{m\cV:*0݋jm uQnRdjr %n$?/pZc(%O٭MP|,krDh&E@e7Bkb5+/*5 v)M%vDUƓ/xSQ(aGd δnA\xQ6ǥ i ,q؞eSݙ.nأLO0K6cٹ[Ơb]{pF{Ua\"8_Bi@`t!-l9Dmw<2)SI+}(S{@"r %.DD+E'Φ&3ބ5}dfZ[v#!g6N@(GY[;]:hFnڷ,>9NZyeU!K^U25BQ$QjۏÏ64Қ (L>Fl[f.6w!iCY&mHuLUp5W5 ˍ#b- c9W:#R yc:WC xdfaO tH76d=AX6 75({5XOȢf["S`mHu7Zd_i'H.^0T\9w LF9iå!|se`%[(뼕]^&B|]*h>ag1)D]SqΑwkF5/A2 F\\cW=2DY1fqE,R%Al_ʨpڮvKGc!"ZN FiѠUrr-%Lr ߓI|Y8/bX( gTX =[HWܤh v}|ȘhwQOAvc+^>rvJb2@D{lu#VfWR|eq$&ʺ^&jf@=.,;!i9ֈQKPUl_-7l>e1(]#~]b-}lamtV*݋H_CZTH/~Ya5QL/{㓡%E`tZA |"70Vch0#>}W;1|)5HK lS&q*-|SǙfQg=FU/32 {)UoT%;GGZǷku6+DUrSr?sV4lb\ Lmq^IB2Drl,,vi>@`s|(d"Kng#>)0y3<3ȐpgnpA3I6*2mg89TG\;#a%] X)R#Q` }%1VX:47sPo l1tR³oBJ jvmcȁy[Rl5l \t4T$3ˣԏ{zw:Ml%p̸{+%-5sO{f2p%>F o7CU.C3:(Ŀ@#v|_LPp #0: ҪZK# &✿ >fj ?K[`/- 5j[=C`OP1OtL?[JL d|*kᴓ(bkۄ/nl>76^6wg=n_.t;!}= ׳gM. \f2e<crW{gx:a3Wh*O h#U!XUP1*.gFd붌WXǪX̞ʭ1T6 fa3B^a&.AJK,iyAєu~͏ʚM+-aKyҶ4dl㉈J0> zKo*{HdN&TG&Zny+7SR07q"ģL?:9We׫@rc|%DoQ?щ] \5_8ŗ# M, 66&- l_b5鬴09b`z8U\ p2lK{0 B3 ݢ>:vZgs7}lY^a˻ v^4w g"u! A(VoWzSSaOS:4^ ]W`emi!3wųY&(tPcw{}-\IG񷯨vi3H=x1-Wy:7 " Esm p]\.@R|t2%Xa, qx+]#gw >1}3ݷ#45DvO͍>F*^  rv#ߜLm^qc=KC8G6Gf!BӄToga#epwιzXp w"pV;sO;C1]Z9VƜ!ܧ,4Gi=j~DԞYkNMmjKL0R#D?1դ[~IvHubVjSPEhhf>oOa1iKZd[z dufbׅ{VϱQ cR8MЪw6| ԰8!cFi1N؈⁰&.Y6?bLw#JDQn X<aIrҙm#B?q ڂN*"c}Q~:/]xm`3 ll^Q@:e^ bʯ.}b\[> y)ݭ0+{. ?&L H ʌPs84}PRgwz)Baj?5~`66PJ"DnLZs5hy$2rUwxm0%PچFg|.)D],qXA `&JV7!ksݨfw~=?]O<۬Yޛv`kZRj$ۻZ49xkg$  Z;{da@Q3p-nxB!COC(ouŵIRTP]uaÚ͋"ݯ탉&6O`Eik8M>/->7B 3*-^A^r BL+:\$XD%o+ R?PE<$mSvͻOӣA*=3-¡2NDA1QRb̼TrgA|aFYq%߅;=c}&ZrpUL_p-t2}K7Î-ϱ%w 'јm3xkgfrn1Z$24H6Wk`j](~~A2TPI&[ԡ<Jc(c`)$^@\yQ{uQ١,>zA2G gFi2M,{F7tTRcZt{oԟXѐ! |-9j^0 [tx*]YLV6ͱaZ-v*yˎF9}ã;lf%UՄ~E<)@^G7h7TETB!J{oS)z!!?WBNi0Hv6 C4Ə:,$LLS0 4\'i8Rrç80"̾o0A-1ߞvgA£g:F^M'[<7q pj9Oucl}RMc"WӀ+?pK4ÙI`$/h.IUOR)~Xѝ+6@ ܄So{rP3hN4fjksnخ.(^G#q9#QƓYגAu)\}K@cLu״g'?y`Bt^N%AB~z7(F7@R3.qӢ xj?,C7վG-%_d+N K_$8Cpl .GC|AE_p|$<ȥ9/6;VzȤ-sGwedɜ3Aˉ*\PN"/oV==HwL W6@ac1D30Xˍ4Iu~Vo,fi[,_[H3!b@̫tN 3E!(U37РTvMvvrthmӵ67/1}]>C-2أR0b%{jLf2HF]ga5wjxG aXxkAF!6)s!z LQE~Y/V߀#OsM!OO}E0Ck^բnZOj9A}mb#{y_\7O#5=z ] E A0m¸/Hy'*Š0}{.^+=gt3+rl70.x)ӫl?ٛՒ$ > 2º z:Eٙmۛc짛?(>A=:oQ׍ڸ P>0a9t+w67qJ+BCY_0B iO+ ʧr&(J+yy&}#> ͝'Pc)ˉr\, ۡd͆puv}rQ@xk,*3{nvF䶓Q8+13y Rchl7ITʵV<3zz/gMlǟk|};}lfl۽>Q/L sQiʞwpR0Y|.* T:Y}'GM;nڙlv.|qanΈok-bLyRAsf)RCeTDZ#e}!K{4on(pzm/1wV84[:%K}+:C0<*aPSy<xTZqk[g}PtB)0yrz]xͧb RIx;ųzuQY1LlMr3^\r/ĉ-=HQnCg@[:fW_89Vp~K> ǪjU6)b&b5!^_ t~4@!Pbzx۞qkTVVâMQi}#ϕE,(G㫃(qE@-IyrGQߵ`Hl"kæ@ |jk5an+h1V<'l<(,_&@8"$6J[N5nczźK_ X+H 5-)h'Jo1/%]X:Am@,'ly12iW$ˎpfv̗e -Th<}~?,8K'D=5Ώ0=1x{Ďlxtr`SjYmc,fW{fh"orB4)5/\ عDb(p{ߺw]P2惥ࣤ 1܊)z"ЎZYc}uC(4t44'sȔ@u)mi͠C_23}}*YZtiU_ˊf[Ao~u+D.M>)\N@F-[c6Gt:OS4 .gx1O5hJ&P*waimtS}&vf)yjz˴,-}6M߲),bD'a`D#4 a^t ԘcSHZjG³YP@錷jy +\ t2~ ,j+P?4*ZoȐ7Z&5"BCR೺ E¹Z/_WBy|J1atj" ϞEN9Ho>z ^v1> ] l},ܘ[.e,LLaZ!zY캘T/lҒc<¾K{B8V!la wNM&(=YS_D2g}RC{x S {drdH0ԙj2Z\T紫}ѩ1z= HLY@n "А,<@d[8=ԙ3jm PEAL^^t6mҺ sdtNoKÛ!L#1Nt&b.U=.t7MDsX6`O׮n"k@xb=Imű)Q1rO~ _ &C-c`/:rIorZM3}*Ŀ1s[xSBYJϪ,ʁw*c 4E|(j>(9E^%i~^|+iZ԰L*Ut\8lQ/D?9  Jz"rINUFIǝdP"e -/V%ȥR2,S~]֭@@Àd kkq? U=\!,署q6$ҬB7Kq Mi&o\ajϾt{/K# LJqyŘh<id7Bp.V)!-+>R[r5l#l؍q+[Ϗ/Lm-SxKuo<A ^pzR툭Y,:J,`]É5|ZiUxi̊_s8t_O*fJS>T}am/ \U:-PYcM˸"%w.:;c *>n 88v(qvlw9e2+9b0k9x'R ÂvZ|g/H 0Xbiؠ a%K-mPvmҲw?̂drGoF&软m$ w)JX/'BX=tFa/Nd*KC7v~*vX` S/˸y\ImҘ1JϻsePrru /a DH(/ƏeGD t:W@c8nb鍺!Ds+xUR)} 4 Ԑ0f2"E!Р!exKWxIu<6W6ؘn_:`J_YI g\Rt aTwBzܘxw)eP9z(jѳQ}(ǣf"l4g^{Jv=C1-2LϷO'5>`y9mr3C`cCdj%1Jm1D+1س+Λ5x5n% A2 =e͔n9$:xj^=(@k ߪ)S;fpӱZ+wGv한.^u]^fqHG;BՍa/uR֥hC|'eApvB°$7[w#Wy&lb2*,BnK{a ?7F¢LKA'9 <7Jw7(Bn'Oh3{1t([]u(9Lƛ15[yB%Br.gT,y.p@Psm]1~nƃ>b\'FK 8қ2$#T1[wrޘ_+߅v$4$>l:x43|oL^2\lE0P!d6 /`A@I *~z=Ī}|͘crA,1X8&;qZ^S꥞g . b8dؽl-Sf6߯_ F)ɉ&->,ecB~pcGHmyN"튧*=m zK:Z}eD[ 7"#rOMN6[9>Mp#4>5VzO x4 K g\l>D:SpqYbz _X,O [ҶU3:&9TW[_+ֻ u(jSq&لlNti1ੇii|/UJJH=WI{Z}U-v%X@4.gV*Z.\H6(!AѨN.:*pjtf,q>-̖<"~p۾uVqBu2B1 %8)hfڗ Ipڏe 4~ nms+LߡBn/nf#m< 9OOc@+k&FB &w5,DBۿB";|xray$Ap^{vN)@Tm78U;6 n224J>>EWHH&1@ C:sKV%;O` rs5N#aʟ% ֩2~J6dE7XϬ_k#q墫.>㠔),V41nGC ó5"`-g ]Cag<{/FmL$ fa`kK7fO'3ږ 0P ^@Me]`-?*O'a-p9?ţAb=^ ˏU],GqM ?jHE6$/Y>}yOkjܙvHo]YN$l ۩Ns_)yKw-JD(bqXƒ`X6ݨxثܛ]3K8YYk6GCITG6'\X'ۙh)~٪ XmX`Hs$f +*Pբ7ol* 6otm0L#V4I9AF~znpF턛7A ^1ӧ=9h/L0PB`0k=V$+h w0y 2-!ԋ$4-ܯilADr u|ױ~?IS)2ػ$ߏIZI}͏0RG,G&5GNh(%\Lכ"㒼5m1 ]Cuz4{EKOB#h>F!|Z LQޑ)&ɉicazk/g]ݒ8cjXëۂbo>oy </jtKTg7r|`+ǴOڏj={}\ª%-w55Ԓ`~xw/Z`M d|͹=|7 pTZV JW&tefmDP-b6[\8pJ7c(5._q/zE0AXib#;-XXg' lQZT|4&SL)nЯ^~8QWF|+cPtccGF_7z+ 6H$~!"tBAzqz 6{/quSV062ləRB]8PuoM0(,E08nLhuڎzՅ] Oż|hLy+ske80ru2|&?D-~to6?[Aq\Sz%KʗKQ-j-H`r "*K*f;C$$>p>LyS^$L{؍\З|VYt@yerkX2zB!#/gCYhs+Iaça+rH3) 5WBHpˋO\gB [ otƛh/職Jy Z=z 8֜5aW ';֏_vMM rDr&|PGaѡY>ͻ[~T[yq8S+ܧ x8@4xإSf @]K = -iBWCx+D90dq` %&t+Bղ3w14j5V2" 2%!AJ!E#"#~mG&T.xe.'%6Pf\ʫ͛OEgV]d#/u9 j1!c{. pH NNY"-0ރI /%M8};Ђ_xa ";(OHd0 ч~sÜ@2ENW,:)H6A(g:ɮnmZ!f9F(0V[x{XvpWk(HTI<Ә !̗ x܏#];`"((X~cYlu ]Cn^xwE$o8z,Fr~9cn.eB9jd!\(tT Lw{d7" _4ѩ O( 9L)B"Ю26%k b_jώ"w'<_%UԬ(-7T7ԅ8 c(:qs/?7EG9b< &s}~G?t}!98 h^Ә.ܺT9.ONI<5TZxoaN̓ ƪ.Gky^ :nh-/N7?(<,Ye^E\ٹDcea ca``Jp^f!AϞG,}Wr-п$mEwK5TNI{н0&+6h5= 9o ?swNď @9ho$[|[=BylX݌1Ԃ#_ vl..Ȱtgwp-սHSum#s![s3 Ӭh]ͱ ؂*Z|"#H_RLA7ȜC0 Bܡq9"ӟ2Xb'[bHA~m>KPXG!&ke5'Hg(;|\eķ+@2:&{ָC,١d8 |qVV΄ @"N评=}k"B1X)(})r]`6fI%|+*P$#]yg4o:"=ÜZ#I^<&?)]vg- ,"#NpsNo\ET +Wz!=zYH#ԑdـa!k?,[Ec~C<>ޞSle-מ6fiߎx}P5"~;,=OL}. @#)f.qbJю1 ] W [-02$lHd&ZA G:O4X=XuvSA w1C:6 *ǿڒ)R; _90O /Vhb'άߧ 8hj`%@nPFrt:[P6N3e0{,?sEu]nǢIV2j"B{wA;UݢīI NM}XBfM$Bq0m9XV@^[xa%.9򩋻!S zRs"5I[Q|Z,X9?B`Iah8$%7haΊb$ֻYh#x3vV F. ӖFɅ4!.wD>ilJ~_|WV.fNqtGVVW{' ׄ}Z9~?tH~t%ű<;*eG:T}Z\ n:|f;8x2$!xS ++Uqƥn4q~)]rQڜ 1xcܣS+ 191ڧ RpO($&ɌW? vw܉ɂ4;a Q`Kk V ߎC#[ zƢN*\fnZ'xy>f.b9aCZM 9>-@gVqj´j5ʾ|9tLi٭sEG~ꂖgEDRX' FD(P^ J: aʐ6{ 8W 6D {۠G_V1굯STs)e*s5{Wsnܡ5]8@A{|/XCJ]C$gZpGqa8#aDCg%(̇_+-w0qxP%̒m  =l_a;GNWsdJտ9!:u̽aBOZZ.*jU:9=~n˕"Hݲ~\Dݙ6^Uqjja]8yNyDm#ƛ*jz>a~ө'ֈZ{j\Vt 0騜E3*awvkE؈ڷ,w很B W"i{$ ߭9!a\Ol]_@V]؆Z1#kTTrN 4x~s<>+wQd1fRktq%a, r, )_Od}z6Ȏxyax[W1jE$X)x{m\8=i:1:DHЙzw9dO]Cz;2&oj aNpęB o6tYnv$tr|y;~O!3TOOh0sI;~[ˡZh3wFt+%55*@e9GZ_tUXyj}&RZAgY(>6-}c履7PKGo*{UQa)bHrjUx(ddQ\4NþF ?>I+'HvG@,v'bKwui2 ZT3DΙ&5E#o:S֛<6Hz~H?\XMAդz%r|U u>Òh#s6E-{R7vRXȓ#(N}>TM˫ #(a .mgE۩Co_\ozwK΃0\!.Q. @f{3ђ~&]s{id8WS)uait#(ۯo Y|sӰŸVӅF 4o@`x˞Դ`a,Ѵ\(D GM. ٖυ{:W䒺c(1 iLv"m+RoLE^y dSh(0+ XD*HrzsdbҕjQ18Lv59GvAYgtg},Tv.9:Z|Z0B7dzGb(8(Kbg|fC4)룉QǰYSbqVkCS (#8/,;_}Qo(, 1MS3ZhQpAֶq 6,c pI*\W^F'/nh \ 9kCA-os@^?ĩqd/ٜ9w`F7@6)搉ؙ=j>IGo#s6\qN~h|$dPcb?qv0.C`doz=YIPV@xR] qWER{R9I bcd4q3B7bc.ABV gXc"EL J+:z].dfhiGzIISc̍.U'Mmb.|jl=e~sS#R bլ-hxx>KAk7,,fG]KrwJL8N"滣K+lBiu鎨2A gX|rJ_HH-ɇGTjF_ /Ƕ4&݋ko+Axt* y{#}SA7$SlXDּ-i aWe[m䗸m-灍cF n|{iiT61W'8BEPA 4xn(lC2v<[LR2䜐.֬W.nzC- <(:2_eGaȋī )CDAE#෗)՞xdW6\Jװ8S )n:?i |_mԎ6 [R!b*4~$O=%]0r4ک%6=ׅא6aHx*i:)C&2]v05ˉunA CS/Lh 5ȿTn3e΀͘Syk0DЃ "V͛%S(*'cNfyqSk2<[',5]# [#֦~ן"g]oI{w-#5|0 y-,Mr Px|)B9#蚦6)B}՚WӞ%|-o TKb ;2`W_s[j*hюs*FcGbEPDzF}i= |㑨!|O-GmFϬGUe"+d4_VRDcQCڛqEŽasJ iNAz;罠a >Ѽu8Y{Pw]|+O HyBe^lʝ}P ׍ luv/jo|1DڱxUEҊ#EG!cEr8cM;q͝:Ϛ{ V`q94)2>4 I{y )/PV$aDfD1"RYYd(H."t=VsU}v%mX>PQ Skq1&ؑd Xє0'gzKFp XJgiD+]#2y}&$?vGD-Ns&V1CΒȯqo/sg8o% yR3)拲g&)'\V'1Lθs5 f^H܄*%e4C;z폓ccYmmyi`}^{ nVdxgCuTFNΝ/^ bߨ)q(GUb#?.$*)(}~B|j{ˍzQVmB1s_\qt읅rOzsi`^x<=#.Kj! /soiWSx2s *BW*RKv@=^Mh${G<|g0gzg`X̕,r ~Qd\7ld*=k£"y>!8ٵѯ@)쌌<-_; tNKҶ9OP,XGܠ{cP}҄ZcT^U`ܢ Cгߢ0'⑅nKhv躑Ou= 36DG 1y3͂_=+,_W6Ζ}e`1zBQ5ji3^ՋMѐa{2e͘y+3pOc$m$Z1MaIMIx85v49} +)ۡWdza N!Oz頜֑5CNƶz"V& n}褈ДAI:^d=ɬ i}lWz\p\[e3UytY5>hzZX mpo)LCѤd"ϙUX)VyQӆALDf mǫ#tNԊ 2œh rUٮh@WCF,Wd;Eၻ` x1;~&x*3'EZ@+fA|+nrqEᥙ.Կ lx2E^@% 6٘"iY_'w&,DHNM`|0j`$qAFܶ;exHΤ[Ƀ#xl JVp_8Inz5Ee]_fމ{%#i9fJQջ_2?0c #ѿ最{ai"kO]pmn.֋p/rOW^g,꓄`͆iX=Jg:hi_hߒO- 8S2ˬ_೛yz1y](2HD*oU{P涛|.>mbQZSRxQ7&!scs6鬌-$5[;ko?T,OX7\e7`Je5MC”Sš' Ph] Q8مdSvpnRDJF1\}`Xb͹ʇ~ mcB4l!zUQڶ~R>)8[ZFAV}?T ̚X5hF:Qӈ#¢fQșd%dK N#F=\d'fLIO}0ʟvrixpd˳cwZ;|q;0CQc +I)[7VMzb DߤP>0yHZXJ"3./8TӠ7LksD<Ҟc0z6ӓ͓J(6\9pZذ9<tA偫>Mjm39ӆ/ ݑ?3 {'Dq,|̄c)eR2Z`>A '1rpanȅR}:B?SꝒ]eQ4N(Z.l8ؑT1?W+^鳠矘꾹lLyc$bV3XtNDe}V&׋[񓇮/%J+ ǬCCX9-5ܧŐx#c1&?bsG !H*I 6M7T:L$0Q!L LGVP>E@-af>0KZ׊rot5U@YDtoG̼S$͆-R_x6ofCa5Hwm G8u%$s $Fh\6^K˨w~~wY1[Lmjܳ31|#4|qrLZL ٗ QSOL~p!緪F3{nqciԪa!I200fCʆgp,7hpgiUh7 3ehGJ4lunj++p* EQ,Wm2vɊs'Nڲ>I㓏k2y I|KflI8<-ζ_2MxA${¹E=Fmmq?{! yqG>9]D|~.&_B!z3@trHosnf%it_Ch3ɌC2ޙJ%(-n#EYR=TO ,Shʻq+b j)*\P2\IqT1@\+zuKGuw 781=FzUI \-zw`8.ۯеI*"R m0XMO{vT&:N[o/̓(f(&Bz!OwaAfēPt^:-dܲ hy_^1SY)h?0O+SL~ٝ!ZAJZauxU U OtfQ'-EJ~|eXq}}uJ]AcŲkdF,bg7 XdR'} G˂m8HϞ Ky^L@mK.NWE(,e^xgc3׼rц:E>cԏH SbK8['.lz} Y>™ Z:A5)>(y8] KNilI_ #oiqg!RqrHצѱE>h(*0/H~(?nɩ p[mU[^foYooqE^ U~Qa>Z$fצww|a(gḮ_Q~^{ľJh31B˘V8GݐĤ=sw-U?uB?́#S Dg|X1W!p<}?-"W Ѹ7L'C3) 8Ѣvjc 4佛goeAAu\IH:zh亊ևѤz!JKm{Z`4-9h-}Y P6AHRpL2 8! B I) OmA.7'$AT"?w8+ط'|X|vCtMR]i^ݢ)DF`Qn/t3EJm#j/W|8d/;SYcm]V 7|pځi3RxM(ŐwmO3+dё誦 ..\Godt4m[}{ `1CIp!=-9VVkjlT'?]f|[C ƋfbNt Z"-A_ BuRlVB^ \bP?P&NqeSv+U Jv.ހӱ d5}4ox/elGeTϳ䮕j\N?v,ZvY/Un˃Ed \ݎt}㫼לw)g4+tˡA1 =y(7&cLWܐ 㑔˶Ҍ4[&~ь[#[LM\ģyے{ =)`y T *'_QȟzHHL Kq%WbASɶ,l='Q>h]˝!ۊ5o~4+q/'Uȡ~$4иdL%067d2OYp RAF;@n;䝲VO#.jt78l^- _oI:W \m vIΰYY#+ MQl͌e\]P꛸"zT6s1\ԛt\B" G˔=Nz(mSE+8J~Y܄61gGB- ߳sYů([bYcrQ /HґmgD *-6 >وK/5 U()c9w24ʒ:%v !M̃Lgkg]P)<#|{6\u1STJ8T;9Ocg)[Ey_Y2y>PZsBes=. @a[,Z,~SM}5ú/BJ:g9HwZcx[ nI(;:/%!GHzr3Fk RՌZ|Eg6 4lsltD=DrA4Z xA}}EHlQ;7Ywr?J}uk_ Ga!kh"qx /98ާU=/ݨExMSv dEǩC`4VeVr}ăI=3s1Xw7Z@1!dH_,_SyUw3KlB+7W"(u'Aj-qS.L(üoKl50D(]U'aJ,| } v&v=p!֍7<28;,oS utyE}<{cJ[5p{0.>AСG?{;*IjKZkOxF@wMZt\B-I<♑[u'$P{)NٿYכcPOşO?ˍoԖʵQnpe'o%%Ҍˈ/ʚcfSjFyĬML_sH(^vRp4̍qJO?Fߨ:dH=g*qRvlN,"{gyY-YʈtV-s*t7ǗtZ8oV ![ E<\*~SF36HZ__iFW^)MmPTL {Vz`01ӐM 2Dj *Rɯꏄ#C'S:ծ|]_[2=)Zk:+)No/KJ?25ږHGqNFv[!ƶ}sD<{dK[umoWL3VTgQDI]8q}4Y/"O"19_ZDV*`yH,ht2))e0&DW_$Ch YJ~ҦRq)6[ZM ֱX%uLO?Rt44`Yb0fIff:#:oB1pWr!0) X8dVzlyp7ش"DüͰiY4 0k-rAX0\GE}pJp=Ywf'~BŪ5L<3=?07rܾ&"M"@Wf`ֲי, pwR({O*pPTѢ*)(K}R :& o %FƏ1x7! >$UXh8ڧ}Wfs> ߲+L 'zp(z|K4p`=0 v4$'-.8D*} 1m}{cRȌ|֐\3*e]˛P;@ tFʄgJ^e?Rø(Ii/h ~,}|eFܖT HP|5U.ElD͊3R~)wC6DDDэrJ{.0{V6QI)i(9]'57)pγM J>6=z<  OV.#xSJS:02ڔk6u5Eț* ScQuzTեֹL-3 l`a1bJG,0I!q @-%0tI(\( EQ E@~eX?|`UZ{SCuJFʛv(iO_!t~C?TzLi= iAPsbm␸.mGYFV,{3*X^tŬN Xp>MMt)/)iv@T~:v~K T${'I7ڜUUMQbG&9)鉧8֭wO3wld@GR2FE`P~}U#wn(Gcȳ3:+a )HaouD@Vn{`%sx;P-&ki!w,ihT<ĵ\/:5l l/h}9U"i ½oB5 iV>9IGB]R~I8 `PL|' :n C d7g.}m9Z)6\S)U?n%q6cv tSLіӸQ \ώĭlΣ7T26xE~_WHdF;'Bb1qyZ*^0%)(wd(o Kf8,mE,׎vH p$ڙGD.Uä(R{h;a3S肴=y407Pl"=d~(NsʴSnY3M/ݚ_.ʼMn1WݠYFFߟO 5F gL:W,ޯ4E;(u`kLq(utW=  R4 g)?gOnymvϩ UMkN /[!w x p~SsW ]qg$zrdlZ|//.zoAˠgdܙFV+E!|D~+̵^RlDb?lϚD5F"6G63 s\`X yb끓$,lweXQL܋ O1lē5Fb'7pwD;;ٌC'F Z7: C?H:~^y9pwI_ti-զX]'o(.;!%|:牄|+}'i'7`<̹#37tQM3h1v˚㲲l`:X9Hq+үj Q[)kKR(=9? 1-,DT24K-:{̱xyJAgX9  aΪChՈh.Uf`K4xOd8@oNq;$n s!_Jn E/;4Zۋ<] åNV>1C$ i9<8N>K<~]Y'*Z8Wxd,UMT%RPD"#fErJob^]\Zk}tQdseA|1a~"C2 toaW1k)3#"RrK MF _)7%F %ϴחtl޻ =g DI?EK!c~ǚ12m1p:seHd(VXEڭ2o`BN%E;.0,7rǠѿ׼IaDϮ @Zz|SHE?"3J^5؜΍X|z|EZC|RP#Vg!;ȳMg;P޴V{pZgFܗb(n94$&Ee&זoiz XDDޘ#?3ʏ}7[~ruMݷI 'CvSwg@xqCf*f]aT21jz_":-9 t"^l7bGm^u=+yE." <H"DgV+SgX$ Q?/%f*SC`49,W} >ٙ#!dٻiW*?كTdYRƴBI~r6ƂC6v]%.ud2e6ċk3vbPd=MNeB)c,ie;ڢ2$[?D%M䖧K{ PΒMCD輦ϥ3,lFЄxr{ƀ۫ |I+g<νJ':XED" S(d'#x, ܏<#Qڍr1ԵhU;0ցޅ0KbמV+?PE]EWB+q"iސ{ֳ*9CyR$AUEKmr+`>k'm RX"" I 3]5>?uYv @&[~8?m;%2w08=H_b#~zʤ*f tݜ2#NZf~(cTCg< heh@ЮMTuRUч+j3W`sd`fk#i¼j('%i=ϖ \a-0%U߾num4u|Kc44rSpX^=l"0b̆6Iw7#%VF[>bI^ZbqͲ=RzKo$i;bS؆ϵ^9D |uV^Nm:+MG9}6tˏJ%Qr&,ߍMMB}V [0Nd@m2˴`AѩͪU`y %m.39Yk0[Bh|X왐WdyY*!i][TkМ!b~PKOfRR=3x%3V)D5>ݙj9cDjQIh@;%] s,{c"mC%*PVz]*癲%IaUc*p#b1݋CIZ{%Nd? D_|> E"Q@Y֍-\bVu`W F Ijst]ՐM2Bc9z5?QVT׮8`T.b"I}#dPx.mTzL&.߸iA&%=>63[&Ÿl= /6#Եb7\4:3FLtM&Izi*-UOE|?ԖJMiVpPb,Z)L`YQS72u T2:?5Iu#PG|q -}3lzƹl^?%Olkx `^H8sH6 [#؊?JJ ɥ-M:U4~R^B;OuPJr`ꑧߧ:<~/y鋿2 Bs9A8^) jةO#INpNs=羻9@w. h`/{-?HNg_qư_D)4}R>b"=%y}J/Q-CŏPMLt?TIK!W[Д  CUS]Ke쬅#xX@$+8wd©1Ac*/YBpO3*!eX%ƘVˁ\̛c»d+&<} O="4CryPrurŶ!Ȗ 4~T Єtj_TnH@'|bu8:r6_c^7"'ۡ~Cc]0pr$Po8A᝾XAq>fͬS1_ e)?69FL/ne-@XREEO =ҿ֟]tF3Itj{~ d ZD)Bo\X ѨDdf(GBY\oRf tc>0~)72f x}ڄ/Cڲ%6J%7X\0l5,=;"Z4F3Q_EkҜF*$ A4xaC!ȂFӱvB$ N搇` ʢ8`P"}V?Bd닾٧׃/҉L`OSBy] n2 >%9OyZCPY쌱o] o) Tbw_멗7,-h|!kYt z|5^frS*Nfj=Iʆ,Q(Jْ=|c>Gc;if#,Yl=yWJQ%+b/:jp|QFcFp j{hcNyJh,~~ghϊ\.aȡen,J%'on@DZ-2!^(T =B/s0c`V`,B$0?Կp:\Yjπ*ˈע}+U*]nFՇ>>NԚ[.e). hSіƑ Q+1{Om*&B%2QXu0(Vږx6nkbA"o`W=q79ބߓvX#غ\,|eX!v@/ ʫ W4I3~~gӗ I(>?"ܴٺx `{!:rS']rMZS3?lΜɤ;neb^F~kq Y{u{\ɽXVaG{^Bj43(SP{auxM0h\m\`s2[c'sv6Qe,%%Cd*fC Оl֘e7| >3DsS2 F9Hwj6AVgTΧiE ~wQtq,}4@I\{]JvF k?)G˓oxck¢ʦ1C(YW2u<厍?#HL@Ɋ;|؁j>]iy~Խ4* 95sWA=ڈ=vV)ZJu v:.;#Z +r O󟲯Fm`:҂I)y+QC:Yǩ:{Cl)OO #հ@4Iڹ'p`5FoK_?}J oMN=sor ' 2`U ^NQfQN;yWrRY---*c@\^(v y8?$VHĆH17J iD1a]L67xI*u1 }䣹|HQݼfa%{M+\xOS6v6ș=ǐ@soVB\]Z6 8H~`-q+?8Мˇ]֐Lˋ^&"b0[uom+/I3g)l%E Q :8.[֪P(C[t'TX[nt*'GG=WhZ{Ab:7^!ڛ >/z?][R{3yuP'C{qqc!tM GYN90+.iG8vx&|T6qX%pl0E,^K.(EΉsX1Y}d"ȵn8z揖 [NY9Ca#!"ejꈰ]&?-XqFFpBoɡi!èwG?X/~# @ovfobeO$xk:%Og aBɆc*4դL{4V^#Wd?YX&ϼG*~)= G* ::;sc%a<9B$XF󪖶~KN݋!˱F[LIAkE0nX>"&J ̆>v 3NQBnk uȺR v bq" vϐH)Z=Gtt'6<%lqa N"l2Xky{\=XvpiUƮDwcȽ2wub'C~RATIod^_l1ƵkzSӘHl{ vo'>nW&,?ϐ&k0n;ۃwyUR̕T&268D  c_)JRr%gR ¢ z Pb=jf5<꓿ jhNoâOr k̈р+bL#ވ-_W/4b w'T!^c@ad`Hf6yf"zSYLӪxFu7-Y GVK7 λDlWӿoJ#+~jE[Bvڄ b\s*ƶ`` tȚ:¢%b[:Rm!PG5*[4to%;u9b_V;dwy d9Td1 Or+ +@Q?e][_Ǩ)"7<,,_Fi?;kGFepTw')}P$d˘𬀣6WZ-,*y9l8ȩ_)/&U:N4߸m8VET#qN3@ %G JI~2 Դ8aV͋>KY4`Yb= lB 'a3&+cΟT\*!G`b-dt\}[Б\#0%koTUNk"uLZu_'̇o͜ jUsuuUjT+oD"p:}"3%x]ΒFnL蔬DkT,=cZ#Ɖ{}77 "sWAz$cAZ2:#^mP-'!"H5ԊX9M~k_8SB= ڙk(xN0blX9S 6*2A<8 Z]N˛HVѐ8c=U &DJ=R'*; _ȥjgrW{|[Ӽ.[ܘ^7 O|$ũ߃/Q3X?4REe?sfnH@M~3"p-mF@gow/foM^x1f}13o"3oPN*O|QblE-C qOPODcz3"юb@f.w*HTF2.=O$|NF4< uh? N ]quakZ2дtKb6^;Vo :plMwӔ/ϜhWft<QĊ!q9WtMAOv σ frhZ%%n&If4 }*5D~NlR椤j+5YFnyo(Bl4e O1ƣ+PԸtȀp>RB&)JC3?^(ou+s ߗ(T~ԓet2HJOANYI`bf$X.` sCO?@ܶY`dE"wUx:j%]2 w'\W2u5 ޭb2{~d_D_N iPEzNHd<~d?df)Vb:ӊ3aԉvxrd\D\k%3FyM'|*B!lJ$UIrbLgإL#aǒ7+ a(ӛ 2Sډ!{t~e`/.kF9P֍ j'1S7HC ' ;)d5C:d}=CeЦ7󌆟2SS/ iC|4\uC{ȃa[e p}"OϢԙ*J<]!ا/\R|9+^SXQ%s @Ldk٠{RK\rF:f]xIF$wq71&K]'QVm^.ќe昞1t"Im(J_yZ_As{wZoZݺW/W(9$8|mBx /9P,NJ!)t08濉[e@f__I/ɟܪ"tiQo䳄ﰦ<C|?]"2m wyM;Q@닼cP:%F*#t 25<<=vS""oAb7hi07wס|| (R|v=nffyc:GmV>峮85JLu`rig{(kO[򼆑pM՗0{ޡq%HQ [N n)IZkY7m~iIc2p9I;ģW:,eMhYVn0X _gѦygƑ3HT/V˩lʹjd)ipcJf""[C.sn_]!.}N&Ìfa\BJӯNV:\ Ŝ'PV-37.zDhB\tںal-0LeL_u(PD6 qwb %e<1W̲է2fAvѡ}H♪@8Sx CTَSWSz;(^H~(c(:W#RJfBeyI:ZN%P$D'y 7i9!$UlOsNPl{3tbD鼢ds]Tjwlfl_ p9 +y}f>{[&vQ7S}ރ,1cKXZ/1eV;qiPl[]PׅUM 2$ 4/U9l$W\nhض=酩mt{J3meE.Ζ Vd18Ϟxg#WtR[;kJD=)3rCbj*6hMp!ns>6#Xnؒ ybf5kiTNJuxΨњCڗ*EEjɠ],Ͷ@u$Oc  `MD{ ‚ J)nZ%)NRU2+.iR06D9GҸkrdDS+18x)qXCJGH b$bdk5^Uv7掦u] Ue BǺ3!M̔Wf~q)*^g Bf5"Nux1Q3 @rʕ$KxUz섇2͍/Y!^\v:Hetb%#= ޯIDf;Bu~˿G*hovIa"I3,)zITB@C3$%5d]VvPOUUW-QSja&MygsȦo&7r&k7$ԤstFSFw-fwSo$#c:;(_.Yǎp@ikd{kel/7E,W+w v8`sRF $ ^T1M2-`O}qd/1p5$eRՏ Y@O(THgWpk''Ω1>~l PnnhS}lalT`]T1 d2ZJb\@"ό4s^ysfK (h_ []&GК$'&1Ճ12ӳ|tV AlC wWxT43de o7n_P3?vaňMu>8ԇ߾Bq>r6 .y$C>}M>= #.}7pUj0WrhzoѬ_uJW"Bw8# R0'C 0"R ;>⣗׷HL !6t:+'v47D%$H5H/E;2 լ'2[j]d3"SnV EoV{ ZS\7T'3w9s_vKqR"I/ 4G]Oc:&Gū al6˖~U)=\ *($@7 %puKe&T,BNyp௾razOǫ{InҎ$1~M{Bl"ӈfJh1ϔ;W#Jw5[~ԯhPB>/@cEءNشBNնځSi{6;M7WJ1?lɂe>MGR,VT("b=*P!!T\ww ƀmb aAĜ%ec\b|ﰷU ݪ1V@;@vҁ'M-fk"&&-`'.RhzOޢIHgTzQa 8ff:zӓ|&{1iBa4rJW:}z~Ő8&Kxy@kG@0 2/.l_O~|}ZL#6aߍ`Ȼ eVcv6M{췽z|i]S+w۱v$ɸ%J*l9݂ۃw Vs!k"&I&7T =1Z & dv.E*U]5DEMZ0::oZ %ZOXFjg}]YyR [Au8s2 b 萲; ܶ5z:JmQv6yׇ`WG&,EI/\Kx1FlZo i;bHdDvGmI 7Ib-ZljOe^uWtwO¥6k;Rq|lX|3 ^%hN޽ιdwW%2~e#βM,<3 'xt[rO yڕ>ŒԚFd}zA 9ǞLy޷iƕ8zrJ)fQ?rU8W#-75z 6a}$^? \'U[淒Ώ*-swS?[F/]a.f{p\)K df\h{ lXCF{R@IiA`'=_>[gᰡIt.+ !nA> Ww?ď F7ōܦѧ4^=;Y'>< + Gi-5~} Nڳ0q';Drw*V53+& ^6ÉC6RfسKK2X^$X$7.:V s& L'@@9 4ƺ[f_ PR~QG[A2v eQW()X 5v1&a,ʮX_( ِSgB#hfPP:;FkV$mrߓ1VƳӔ0g(C0׶[SrmuĖlISj-:/:6)QucïF-y!Xď ^82kd+!I|SXRn(D[mY*z9Q\xV_34 t:"B fb6wNj" ߑTOJC؄ j v$9g7 *FH#o@< yhFh,@)jp ,q!/"INXY? #_Vʚ?]{~Xx@;|uu:bN/\jy[n"~Hޙ٨M ǁX%S8:1~gйj+DIs{s9Zq$.򜞦gf5nD`va0 :en!II_h6M=osIx &.*bOWr<:߭ƽdA/:xv-KX'.RNO!n*Zey{~M篃AU~DP, 4F<%>_gd%6Z` BA1-n҅*'d|-y:?>;R3΍R 'wC[p4*\8Kl _SY=x/"Tmwch d币QۗZѧ°kCzf_t#zFM+(oDaPKkY;)n`rnؽUާ8ĩ̇2³=4T3RF4gmq^+DG9|SW &iXVdk V;t?NXH*NFգSc9o ;N["jKNDYQ~04O"6v-5;eG, nGc3sy}9}gx& [hH2x&/U"mdCϕ4"d'~[:> iE'~]B:+8OQ/U^unVZlC]I"2FbOOٕ0"%u Ҵ0)eQ.'̵ٗD6#Z管-+. l1IDvr+3vtsecwpF;i0l-#B\.+u.7pc ߖYcWhe}&Ϲ\XRDJ4cH pf]e4G`gCxI J>5AH9 k/aN.-X>@+ ]ABHq%4{rǒh3s~HKXtVWs*Q^ۚqGE } 䧞JyǔmRJG5|_}vs$#itP/mwy/Pd{k0b \u,M̰@sX ak()n~K~$cwSNvNv\BǠPY X̱ګӝtv,r=buD <& ->inDsP+~q֪eQV@ G;nth"o&S?k8_Ӣ=ⷪϟُk9f$0)Ϡ ,Ўwwú:L'5!<*%M 2 *ڤ'B0e[Plt;D,1,!P,0}x^ h'A1Y =u[zto,(Lb;'<xʰ: G_d\8U-~ c!@)b |ِMV +BpSWŒ-v3m)p=*Nq/ce)#Rs^m+?_۵EWHXGCq;<(Z>KxTM`욝f4ʄ=Ք받 J6ۂh,ܘBŞD^+x7L$=\,13CyXSG tu<'4;?sVD9y#MUΟ3^#SrÐS\͵479)e #z08JN]ܗYQSuXI@KL~a6bx ^7NfPX8ۨ#VD7\kwuZ;A e]hɉIFwIy>lJ4ʝVqu_pmw|,&栨mj\FHVGEmSPtiJ)7 82M/eȗz,ky3|7lXMVFNSmL\⵶ȂBX=0vT>ES[|-:· ,fND+8NC3Z\8By+J6 A )O*1 H@xU:p(k'XqW_Y_[U5]W0Xu!tCv0_#X`X[6|L`5HRv6&2 қRR'~[~02 nq DWzdi)mИdh`^ɮڿ/q6YP[{`Sd Gm5\4'z|=Z"򊥰!Q^KxKXL!S¬±1䤐kpIGh\A-ٿ;v@5s;3?uo %.n,hXvF Gٺ$ca׎^eQP6mWo /v*ͷװ2C0;v)~1kκK %Z>*h k= ӱ'.+-h@šn]šHЮy=Wwۿ3jڼWejC&= ЃkBW%fY?p"n vtE,ҠMpl?GlvڗR!љWEf",#Ԧ`6qGk>O"cߴn Gd,F]C qvI}>fH]wM1fQgv B_"VHzhM>2"JPDm5/PsPnf]5`ӓ]3:)NQ&݄]m.%Q 7uHPn8`tFdc4OWޛUgEUz/ҵVLz$5P8xA8{k|UN k!>v/ڸg^TsvgҤj:ȯU\KDKEYhuKΒ;]BTR`$hH9 q|In.GRUD>K,n4ϿRܖ?Omf/7/ZwYe:xS‡:( ԊX }\ rOn׊|8Emge%v7L0qM{xO(%7J콤Siyz:4O^Vy機;LG*I&d(`:aT 0A6 N.+{ 42<و5MnX|:}>퐸 mJIx! B+@56 }|Ip*Յlxn%5Tw)i,qF^b P4c̓3n?b2@{:e74?+]*7ăˋӻZ>vv=҉64ۘ8sX6b5'\v:ByU}ǟ}2l+>Qѿ: 9s*"Cl5~sPBop6|{d}_P3h rnt+H#Nr>o~j)9A_W{Y5l+Ϋ$PU_y >$ Kuͭ0 ɠF O*=n\=bnߕ!rCy2ns Inl'o̻h>o 384c?EtSJ5N Ј"h;'ÖcPҘ>{u)UϵM9?f+x \Nx+͵&EqFyc_=UĒ}"&,F_+OvnpAR6Ǘl',pZLɈ,PʖUrRzEF0h}:Z޸[(Βmiyz8]-Ѓ649\XB-Ev]佣~n3&G4:(u)2|TuC :#צ(3WbNS _.4tNNNp(Mj$A85g D 2܍hhڭ (W;7$#jEٍFTTs瓒1IRV_S~|3=91E/Ίvx'Y0=1\AG9qI;((LAx5z2|P4 ;BZ\H^ k XjRʟBp0 srPK-19\'H\[=)'bn9x6:A ee^Ů73s0gvNk?M*(Dp}Gg;=9ൻmAv*g*:xVHEJy*L|Ju E-ڳ,D+  eAK!K4yUzhTx6\(acY[ _NoaDK[_g"X:-EC^gX,+>wkKTh*~>s.8g$/#y8]PK+x AF'LOg┽xr=߹ϺY犂 PWo Dd|W r7DM V'3u}[s8<|j) {:_vm;9'R~3#|i˄_⢕pL饵hF 'V76?˗$UDjD Kr)+U2rYgS& WQ%ë(f+ZX֌zsA~xVnq^W[:2y!O:칬;q?y 42n~Cmq͘/lXl!خF=ͪF|=>{FlWsWy7eŠ-$8]bYx4+xF[1m'xc=XR8-x@䊬Q,Ő _,Wi5`W*1lk,qZŷջ󟰭ӔCkn5 :|o|f-cEIlN)d}bU5ng3H9b&.)Zb4:)Tr86LnͭTwgjE%9zFO@ :ٛF2nhrEaD˛V rq(sJ?}֣mn %Q:X̛= <^"#tS~=jՍ"H| hEFޒ$L aT݂MZOKnGQ="W>R=4KWSE,ۣ4^h+zؐ֔d^ӸcF=OjjȡuMkGqCJEX|nL>枊Xtۀ ICN=|YlstSCq1 =d"_~/ HvX">{ʮʈCti4cZ{ ̢z 7^lXroY)ΧRe5> }qC$k;IciO Ɛe`mg{sh"hX q*8ݴ9|T Y.= ʰ/ ~t~᳧ZZL8|%x\)\`؆7BW*\7"´73Bd%;{}50 DK`ЎЯeOo[y98xPWHa 7|$m [RwplGmi/:5߆͖@/TAϡXZ@@@cJMV\ *"kb{ eB29?`V`PTL*˹Zbn6;$$CxF$ Hfۼ,jo>sC_{[#<2K:>[v6cezu mD^F-qf5DV ?QyQlOkh9_nf_D"^zx1kN)`]3:"i{*f:o]%|]G]koi$c)b.{'l*!ύ=,%qX`TnJiK-%~:PUmewS2 gc-<b,QX5l_s%FHAc0 ^}dV鐺q 7NST54PG =j\=ip+eȃ 0{J ӣ7?@OA](̷h "WԜ) 9byi[~N Ɵ_ PB ѷg ",6O{ m3O-`y&#:6]fKC4X沊}UPwrdWcx_,{x\F i?(l@GMڷ1FKO)6&ijӨBRe3F1R&{ x+\N(*?,^/SLj0Uzz7/ǝy#fZ7;^'>Q[zsc&YP#$lp&BP6HNb!; py K,L{ۋ1Ť-PF9aLAEzORR5¹\G($NX E3CTSTqU޿$`zee/ =3YBPkp"Sp~y԰Yp}dL\0*Ltu<|1$dbYkkQ "}%n󔟑3Sz?&;3 .84E [x*h  شuf܋}2$O=}瓚x!_vUq, 0&#OtjKA# k8ƥdeg5>N<سlrz:vR+ܤh2y|bcD#н"N_8ƨwsݸfq-i't-Eq_ם¶ÐJ)Ț!V+.0_@L|cu</O֚QgBNװGQ [mwRwڕ=qM}%;Wu!9 @Aheu3 FpK[2/UN9 X)rp !t'r(,@U ,+PO|fwgA~Rp {waWG'd)0oD*[T=6 @[׼IqþŸTC+ז(3h80<\e%5s]g@>.(\9TЅ+XuPJI8fOT/&TaJ~xҲx$I0Wl_z vd C\J?P)碕ng϶0vz )ͼR2&@\RSUܧOJч7WkSL-;}SPW,;|x4aasl^Dw%mYwWn`R̃nu8I鿾,N6J7\ô*y[@pj:+Cʾ5lw>%M dO/u;W`1,'ԢamxPowWqQ:ftb,DV̢DiBƃ(h;AOq<kcQ4|TP`WGSzzȖ< q󺧬4-\6!md\|ϊ#5^\mcvFf3Ko~V!AԠT-i̩i\!1 `K-[ceV PK8B*J'k)UrI_L8+1E|Dt@-`Fc{a=;6\<2RN- y̽hm?[p&,䜫i` O7ܒ@b#cB9hyR:PmJɯ M.sM"(u ͤq%<N^qB +[EM%y?( |/ՐK^nᛝY#lծ; oTh.LO0ɎYO[.+J/0 B}!Q)Ҵ2Y2%#wL(K'4%nM>C+a8CsIrmۣ([5kvn+G1;a@]lydb:9md^'X u91bkF)B:|yi$@82zq{퀽5p{iSV'F }r:~:Hk@TԵ`M{\#zL+[xIΩ0%9OilhnY #ŷ?n=)0bH*X>(j\I_|-wAǸ_T8b.tԷ<>|'aLY'W0W_7EKY#AAH[}H?#UFYKl$ǚF+z`aDP!}m雔[峩`c?}QY+[˒e`nA)dT ,iH %Y tgɗgKhnM<5УX/4,n9 D'Ȁ1˜͚Zw)/jA[-xTewe1Jb]nRR EEKV[rw1Jg3,ur08z=q^*?=lLsٳk_ӨQWȶF/4o/ )}xgY~v凮0x{3邏4S@,5!LBϴ|dM^K7A9@eT=P=wmjIkr,oc pف .6jtAU켏#E'@wok$ILt6B {*;C_DL;x8aiD:_ TG NBu-p7**e@^R,QWQ0ed|ٽ 'A^y /c\NW-._\iizۤW#3r 0F蔌w4h 0y:"{;6.4*PA ICĩTNא^L;v޳Ȱ\zh.$n`8kr51 nO6ϡ' xt9v1$o;|?x]d/(tT*#4oUb,ht )#/!dAόPm&}/xTŸ[ {8nXL=['rPShL='#J44d~xIN]s0NTM1vTtm6h=mI tO $tvG! oZv ]ɳY5>Hil§;Y1iE2[l&q( _?Jcw ugnғN.5y #Mqf3}vt5^TM xTR>>eh}N ˆ!)4Y6sGr n#=)QCuRg`D ]އ<=dP!EN ދ<7E%եl{[;"ǥ`QGq BGg8vT1 ʜ.4ϻw-2pH(h~5lnfpvUpK&"1loP>84ZNвɻRQs GXFNRcK,߭Pɖt|߳#W0VTMԟ=},aj挽-fXyu!TK K?By# r؂n$Dtj6 1ͩL:nR8Zxdyv7٫7fR6,krzទ05tSڐ?׼(}2] YOAE=kTCM{u*1 :p3&f?ӥJCމДUkw^:Đ}'RQnPIl Z*;:SN_ϼXs` _ dCcp:&3˛WĊ!ܡ\HBH/kS~nC XA/_zamk^QS-KcyoUyS\fTVrlIRǾ %?`!x^5rŶfi2TP^*µ\3ć(Đ7n-/V=5lGo]diT5E7_|0 ޠ7<ǟҠmjw58Fj 79 EW5&6`v9o/ᙊnҹ m{RdHw<_Rܐi{4}h} ÜWF@" _I;7qVo5f2TQ3/Y~=x&'HL(DU<[z{_i9Ձ"QcU\N-L O KhcR;ί>2;2w¥~hLAFM=/;@f4,΍@ZV'fuՍdcmO{O Pp!i ᴽ)#S|T#޼~m;6`i#F.ph>}מ͔;?]T+l`^Q‘{H z4dG<ڵ2GTt9##&0sI\RtPP׸2bs^[}J$/|~_uC1z2H3|u&qwx@h k s!ymWw oT1]_0;%2BMYjn˚+6G{b1Qv)cyM;d|$4"m"54ݜb[rt(דtQI5F=ZhBo_8=5?X2 Gbߴu j%e0E۴&wƹZưLj! VXD ʒdⶇrG6ߢY I,BLvUYF):]>Z("VexBbD#~7GNJ7JyTq١L$ز3dpxƍd8At25)`_~O5 AIlUČAqZ@DvP#ξ'!4H1Uvm6۷8n[.Z4t?'>Z/I@t)c|eEhvRH_Zt~T a?DhPL>d0pn\"5-' ϑb!tc",Q\N7kFOeZ2k@\\zǬdqk^yKe v#qIQ*\5Xj.~\z@4W)gOiDJCؤ_m;=yg^>0/M)2~tTJ5ueֈݳDԣkb ģz1[fWXӶ s#DHn !w5Xނ-F^j;ǘ'K ݯOxeH":#YJ?#:3@z 2ewxwN@|' }7㈁3%ZJdz*X#x9Et}\BukEMRwwۼƕb ?c'c?yz)6jFO޸vÞp  4f-xtGԖ5{mv웞C bF'GV$jc{# uQ>򰒲$ېڬ$ۭ_: 0J83# ͋Ckɺ%(:G5$e4)8i<7T9P^> t?UgxLm2H6Y<ޥ/=SKRl!C}>s G0\E$&48e-ۗ`a`U!Nf@B!G>d=Uf :י9J\{U[iުخ-)܂5]ŻCٍFTGxWbrq;FsAj+xu7v9 ^djc$_0 E8ANOG?8  t1#>Bq_~рz["sh6/|3a)2-P/_Ŧd՞Km5[Jߧ8YDcqMYuׯhI^txg^jDN3RI9!1 D2iFiq1iEMmG&H1nH5]Q^S{ds+X P=S}[#)zg%dC\ps")sF) qu,bKϒ0xW!g̍Y:kseTFwYO_&7I:08Vư ΁A-׮Aa=bNٕR]^9DVHK@[Y i.!hAlN6R@Th6/ն)"` U|s| 0 àH^]6u)ƖCBTu-I^_+Ar(> +{-0;bY7c 6d΅ax353|Mr2@qv.q[;Mn!0q+lh1/9E֌Հr+ռ#2q[E.g >y3)liʒVXl$Sh+;+>g.Fr JFCxu1РWL弳фF4uj+*L N Fӽ†c:KIeiY~ʹ)g11L*zO>@ݰT$-F:9ZS%Θ= c7k\Q=w5 5 U&D)~M1+b$`N=|u>u\wIX!&1><:;uEٕ| H/t|zD, <%9 nMZ૙Z Czpm朱q_qa:0076m֧$Zf-=zJtkmM忏#*9KOQg$9l .tԳTu? C ;}8콄#UU6,n<UIGBF]kğZqx,y b_!=q=q#6)ng`8f"!W-RrUqx yQo/LHbOISm@KwY#!3 q7VϜXt貑:e]N}U Dj%=RKPb>P :ٷjO3AW>u dQp `]u]u. HZEJrV}]o<Ł~f!+^X$,Ӟds/tlц;|lno O%MVaAgِ XdUӣ؋/B3J#!E]YhzTGc4QTMQf4F*z&pGikxn鎚Em< )EY $PVHjLvxvcҾ@JI6Č\JhuΖbby3t]o_)ylX dScTk*(ck,d :ݨxn4Yu6S93#x^{F<ϤRVQZR3vBԃ_dA"m0BݙfXFK<n,W<[`Rk5uvr#B#&U#FoT)#/VTNUti‚gHo*A Jc;U'Ґ)ف>DX*-۝ &˪L8JΕ&d)K{^E 8Y@/ k/s= d,?ЫȴZd{~nkT9`h8"ck)hALU;o6!ԛR+rLSjd;.ރfL祪v`(\Kj^hr2K-†#qi\a9#\ /u,7H/|7z!;Rcn60zY;,Ϗsij@к0H1dzid+<Eu+C$?rWHaH.8OCxb2WF{T\ߝ˪+@XG֧k~d \a;ړb&K#&oW',Ixv~Z !mU!ǫ9ۉi`23|A@#$z||'*ZMOR_9 EbADxp% /L$K6,ol`߄U1Һc#e9׹7ۋ'DW{2( {XZ##.fsx9ٽ US:C$Lr[j{:gg?j2bʱy`r neL Q4(cKu8ZQ.t CWx@rJt^PvU E_zz"NFno%`ݯnWLihLLwAlF5ӕ6&# ^ƮAXLF⎈`_8x@ZwE።Bͷlw YrU~&8c"3=ubm:ixQzh&syꅕ{0j)|Ww{mxLbg DFPtiž*-đܵŎ;^"Y{HYȦ~8݊URL'ٿYR+hP:έK7GETĐCQ)iŔn7jm)J_0|! 2ѳ47*tw[{Sg w [|QH cfPĆy.2"w'IS<19hs$ٿtj`D_y{ מ?JY%lc0e_gutL2O2`7 P%xrh"E? ˨/C՛^=\ L/\\#1/D ua7Qh >" wOBTϤ,|Q5yHVN8f tcdy-֧wWgH۾stYl+ x,X?#Zi3I?BWhӖfu'SeZF/G*0NRY}btJ_b6 :>#EtUAz{狡^h~*YT]030%$Մv,+OW4N,fU  G[9GHںY /)Ʌ"prNJdM[=Ywt)&xhjOK`[ U,&g& X1Pڐ$1bT8Ӄ$HaEbMψoɡu3)okiKiIa"tLt gH%:8UhSZp~z&U$n,6H-{7jEAv\Ay3+wD#Q3yʥHw ;Ɇ~$"D vZMw=z K/7%f6^E מSk`rU& e~jJBl8ᰒB(c3;+#EǛQr[;_j(/M˳+>}]4aƳ\P&t8 qXϥ( ۳ 4=Bd DMZ l"6 mǪ_]J'"u$C⿘"<{2J asd򇐅cq-v`*JulìצfuϮȢkO̸D6LBgyzŗM:W/DB?b3xKwjէt9]>JCrxug_pRWG2grqRJ s ;7UBCؔQJB{8aͲFYQ-j<-5f?> Vཆ3p?tXFhՋnjQ,* Yu0Mw \˥@##lբoY:&}Ѻuw.(Y炢]m)D gP,GD$Vj,^ Z8Lϸфg }* @Gޙ]=xD9{҃?v6wUbF {Y4FAgnik6M\B="wr  \ ؈!Bݥui:KVr ǘ^ВR;K m|wgHeƼ !|1gk(Bpr$(Ur8' '=ߢUgd:ֹ1n @u+pX)*dmۉ?y I`^K$ YbGcʃ,6 sѭFH_+t7e Y_#ﰫr.-9(RytΪ0Qآ +WKG>A҉>[l{y#99;ݡ}1L yf0a)8,">܅8sBP_}L_';>|l'd{aKFvi ``!6 /OwKR*Fi]F;y3#0+a~E%cr`~5`")b,T biM񳸮l_! T, cEZieL}ѳW+4)'C U> >  ]1nTwCjT@Sÿ9oH[r Lc7o]!y|BuXFwʁ:T |jd`;@œBB=~bךs:PI-V{z; !(dO ^݂ a C}# L"S䬟?jO~gl^ePsO4׳"5(ѽ׹ k~ # SXg^l6boZT%M"A\2ϛ}Hǐ mn+`֫~C5?`KPQD^0k8w *S-*M,Zn;ͽUx֮t|0I^Uj3- ?{JM\Ҁ9A ۘD马RD@afrt_#ȫ*q6oϽ3q7%Edz9Jn~@5Gc^*)hr2ʸ/G#/?̙6T))zb4O)|h`[/86 _ϹG[=_jI|5ߺ0?@FZ>~gjr0m2lG ^3T7jb%|y;MJdbg@mTZloQG0o*i37,xޛ@yL±]B*AG$qOT)oqƕ),C^ƿ3c3\`8a;gۂ2vq$=XR$1nʢN4mfCuG۪>{ ~mO}+)u^䢗& 7Z~UV~a+=EaGҦ,9Q,ɁffC畲/T} #0BpqÿƏK<c>ߦIWec!Qkf&B񪤟}smܤhk:ɯʅz2u,ae"_D{WMـ@091"yEZ#(ߦC~J}?Ɔ[tIW\o?߲GzuTC!ۡㇷa׺phGׅ堚G?EPnQ)v/ GX&clJ97̺UNF=y a.")UuKB |+mv|7#(ja&4WVO+133ҟz[[LPʣ#Tcؑk},LK QUQrM 뇢9{$M%eϬs]r>[e~/>vډxh^aP+2u/Ԃs^XI6agT4'fz$tcsk#M'`N) K@ruQvETbC7usTy^XZZ9%S1Z-3+.9<-"”16)|wPYD{y go1wmOf L? ǜ[}9\ l- gK*h6-4B8B5#Nqy#_@xEAbn4lL;Ebߓ]l9:M|X<-׷V~sTlir]JIReuRt@'^:w?>U{/ ſȻ7@p8CĊ$2:BJ׈n[pߗZu]A/>GpGq l%zɻPn73~E;3.="uM:UI.+F/N>*8gs$ՉEz['UjɃ,kV1 N)*b}o[Y&ۥ { .DϢ2 h15~sBI-{Rf]3j݂7,!Bx~ UWeAY6nz(2s{JߒNf&ի<'p\!|~]A5_Ȝɓ_8c{(Yw T%igd4"JTVX4d@yq(gkI./mgic3vf}1L֦`ky{ D{&渽 DN ^>G(gߋDf0; *G]6iĿCOx}NhnG I[@Q˨ڊw~=uz{o(v&Th`mћV0*GkZ(!Leɮ/Ќ"_f&Eu~8eM^%t"U. @~F\JJGSkkw>ΎM͠_3~AsWz&ڽ=O qT?JWl^"$fpC5W ݏnc2ovI1%0ƴD<]䴳Ži|' hoP((B LB~$TL-;|AL3QGA흢_faQ֋._/ᆖZA ,Q芭C,a}pe0hwωq_ׯÛ"ycՒ |-3:#grxՖ_s=9*ara"< 8N&bLOuۅ1\;%Sㄠ_nO`_70^Oٗl V~d\Jl7 W, ɺѵ q*7iLM",}G$^MJ`!C-:{AJ߀g.e]w}5ʼnX\\Sx`z_$f5&#VY+nL*+P5$)/F_8TsdeGv+ ݕbKvH:&vO"F5!1Fkn}n %'62Eg& n"*#D SGBf+&M^tʯI?%CNU貫G%~d**t.)?AHRqjx`1[8ղv6<8.PY07ҝ879V0)n!p? r s)QM2[%`گ-/Vfvs2y*AY!},$Ur"IC q@_uJ~5U2.Y?F?䜅/nI*'bvSXX[׼Ɖ\;+2i4yٖY\ j'$-˜==l qyȵNVg#T+qE x"g)P BƓ'HM'O\6LKVێ[KwVrSu(*k$jp_"&+b dqkiJĎďO e RR"-Zu`] ^"䡕gX q#ZčR} ͆^aX UeAvXb,n%RE=w|vnC)uSM#τ@Xl4ތ'tntüRi+')3Pgd?EyRіsVc'8Y3IټmqХЭ֪Gn2~ʥ]Uā6oDS,Q8'Z<7l/%1b5< EZ+qU|QWl m JR*E@^5KP zxNZvf@ Z^Ka6WI@MjHer ڵspBW8z)䘕F ,w/ZlIeGƄy &_WH"=`-{X)pt4pԻ;Dsx +Do'Gdc43Ӝ\@8[*XsY8e5)iAOTFGsBXe͎$[X)'}骛\F` Ly :G`먡+`KJzJ_KF4^Mmh4K2|ý:] 2ŵ{v5d. shϜ6+;a8?_䌷&DX#Ga[Dd6w$jeamQ}>Nьȸo%wX4"j=41 hNk\ oH 86#/[0o DfBygC4Ltדq!S+հgkAI) M<Ҋ տΌz^)C_~);5գ, EN7m IpW>Zi*:a3+d^ChoA!#oQou l_@tȃUg9@ !")0fB ZJ26/_gks%bZV`< 7knZF_!u\ga-RpwA,C#ժñ푴VG;CtA?)klRhop>:.Tn@OH xIC鿛~OEhʹi- ]ȇ×0|XadȤf'}x+O^*g+ӡ1E^k_C)R"2hOm&eJqv@|'T`e479ڲBz .-c+EH\o+t&1XAs. N1C&(oKڽϩN`S*hfC'whYWcsh101@f.xuß[cDmqD+.ސ~ 랿&X[}=ٓ:QoK 7\v~8 E&>Vv G$> ~Fq; 9v?3oRT#Yƾ`],mHR|Y B"k)R5jp7JBa WaE=)bL Pf)b郼N1#V=Ϝ zt԰B,_~{z{l 5>4[_4Nm+l#599T]vܡNฤ5rN;|0DVߔcӂH\ gbb8e&Jg]`BsqxXuBgbn._@#e<">!NuhhGr@9`5:.OA9*0VlRz `Yxds.W| `Kz>Ż,%y!2<ՖЩ  J[C+zk@He,ɡ^K%BKl( Ji#L ƚs  O/{0D /f[ȕ/[&x]>KƓ I+og't S]N+gfU*R2&UEFFK:kWo2Dw"xKqYu@rl뫈pEdc5{txbxta W|BpHr`0q[5/9͖ef0S H|TOB2嗊k6{؎[J;\m)%dFIyc$́#}j;)g;سzuޠ(Eb Mg>Ó/jMeN4=pZC'rX zshARULAc9Tx8T@1qN}ucx,c4V3wՙscyS{T䖭 5H _ʤQ4|L+.AČҦn:7!4^iO*cĀ5L-' ۺpqO[#-/:Am i3 !ۢ;,^AҢh #~)aZKl:m_(y rWp5X ߚKna0J6Roҿ/iR^\-9MvSUh?{Wsנ&۬#nHIvC M\NIxzW`։87) lSRUZ5ΑR{Zܑ|'WH(7aZz%>m3Ժ(K?-Jf83`P@tыU8PBM1aJHfkn&"W|Rq *{8%HBb͉ mFוCm8uSUT'{ާ:0NL wm^C&ť *;;+Ro_2F Ujq=_Z&,)|lRn`zF[G @X{wN$4 p_6&XY8ʶێKP>畝㶆Tjhqʸv?;BP \oFY;g j]]TG Jh-sAx걄#.>Pk1P^Ch?B=JJQ*:uCeC&PژV7KM~"~Q,9[n[C}U[l揂Z2/W᭟w g(,Hgz "tEhS*G(r^i._]\(¸FMzZj*D¬F ᅛcDF.Nf`KZ?;&PcP)-N%?BEvӥBm]ki%&C5!021Dx Q߸]gպijρ-nﰈb z0ՙx* ibB|.G̞֬7*W/^fL(5JX"_<lJ2ͥݢPsh{<~[}6wEʯ5q684p:6K@r;I <]WGҽ]-/L 䦕~ͨ-tҖGi*tHS~BCkԧ6 8bO k>AٽfI  GeO)KJȼIo:oeaFMs|찧P[rv)q_7x M'hFC4x95/)Ӡ^CI]+"ǡophI,cTZ!` wDd uz-Ӷ( 86QͧjRwy"I-s -洱?*@9*,AH5)5D&OA"8Oɥ舭4"!6#W8>h(ħoQȕ4s*bEv Cđ"vn/hCR:Uj)ihAHfj #Մ]Kl5 Q `$Kan>hk3S*/৛t 6z.lrrz;7U[h8 AY<>|h ^ÿ#ۣ>m q!sbA岀B0rI; -/yZDmK ÓqhfTΜ!Ts=TyķFW5e =Sl`Ȫy[N,GR >}_B*Z5E:Rΐ9s@BAN$R:{}m6M6 OV\.bHi^E=E7, b &\."4=^Bֲjx3+wA0!_]f`ᰝg?!_ x]7ѦًcMw^مx4;!#kFX|7 /X)XOb9j|q[g@MKÂj։͡kH!ՃЗgڲ1_R.|_؃<@#=|h,PX/6h2 稰/50Z~UV p X.JUg2-Aym .+3Ǒ顾?FK+L8%^2s03KKv{;{?4~^) іYF@CBTŝ]XgacRl貫݆s]Ќj&DK9' j|(ܢ3VV1-uw\ǭDF81ny-J}ͨ,hMm ËX@%JC[Ԓhf6!ޖga0AC_W \1V?\b 8 f!GN C8UEX a)a b7'{ ^ ,Ja-8h(IFxLygwйX{5Ruo``p)?%=-Œ(?.o'xṂh 6Oc}È*.@h; ͗xRTS2&9[;4avۉ=GQTҒb|ƧqaG')`; &kA4 'xV=oFӎV'ly6P4ق\;2h(z [O]nnGM5Plk'ԑ+!SNQ0l0mִBa˧Shbj\QB#!yN'twjIB@h$>̜MFma ;.KbZ?C&u-(Py$X@QE31bpdM'KFvZKW$k?H$TX @ E94AaP %ƛ 'q2_0CɌ7!8vu'a| n?lDCYh2^[Ŧ87ӌ6m57KMS* u][{x꘽zl \k(TbԊ+_94=!Glhc>\knT4sH1o痺88󏡟<wr‹R! wXtws%=<`${\f{xCЙ Y߮y›Tl?`D7vkX\ټTb|MҺEg>ѡ2\ǏLctTqK][ܢWqٽО\8 `a⭥`ν^Qf,V4j+g<0  DbgJYL94#k>&SZa,O.R3ag'/Ch;GɀOF_0ƨ.>Zd9؜QS{[mHLXր6A+#6U2I٨D)ۆ©7d z,r/y4; @׌ TPQ^tm"CvK>kD#:>vq&ذc6{%K+}m\`_.O9DIm[_6w&v/˵ #JVmNT6*0Csv#IXu7R),<2jB,#~&tCS )Iˀ6AV?_ *lš*So 7#h]R6A5:\ƍ&n.?OO -KQ:+f[ A{g@ iY'ur$y` 6'*N\`󘎢ۻ|_~$P a?e'iZ&oIzù:k&G i#5B|n@WBo:;h n|Jh2\FAM 6c%^mja.F_:=m|ܯY$ ~r(Rn>mݐqe:jf3A`SbRp}j>4:{s4{A6CbP^c0Z.T2[BSBW L6Vw#(xO)Ki6a|Fe_,ߙݒ|t>͘TvMaRQ96{qlj]6ëY[Z#3':SM&nAK:<у3X tRz,Iy9\^qp%y۴oL3Xc&\$H'U&oߵK v\$KɼW\6iv-WVPTX[ ,;k|>|qS , &QN)P/o0IV<"`|Xh`ުzR2ܧjW0S=}G ҧfV׆#a]^d8dr}/MvkHQ)1J7_7[|>N SZSopQe oqUWd;3^Tȷ`P& ѧ Tկ/By²+#=l=ͤ«׉ "}JTCf k&B?䆼^BBP]MÊ}{eY1_2\ rFKVlvcYDBPS1c@xAk)J3?LzNcg|#W"֏ݚ alUq I|Rv5 bտ𾅅DƏF?>r k e0NL5ǂ^m㯿߂$ݛaRb˼t_B@SZۥÖ|R?JGA Dr vOؐgG4՛{7I&[x,X7MNK*/WI5W0f+ goJ|EqӸ_tw,<贎Ɓ@ncj"ƆnZEp0drJ(?Ws d`Z|ޅQ|?p]?`9b240¬kbJw5YrX`}i/(=heϚ!D.WH ,MJ&y'M U瞂$޾\/?aE 5(wJ`Tu~LwA1v=Z,Dcz̯}>+D3OPlV=M] U⯛GAGʩC3 (dtKFq"V \-cam30y;4]4NcRVM`ԕe AgeLEqnƘj @hZTR3YB Śo^9 S5s=N0𝝧rwiª dlF \*i<8j"emGЧ͕(Үunbq#ĂL]2Blf =dS-|wr*',|(J Bi]L7$#t6 J%<'UnI?|!PGAw@O睟uc.X%B X8eL(t^fW.~ѿBunĥ ;?63N3׿8X:((UIXaߜn!'ctZ<~ɢ1ޏuW e\z{zX)cG_}W"*tϖ Tk%q-Ҁ616ZnE&{3Wot #hшt&-3nY66m"J3wW][)+&9VxiGd[Xj,M4^QϜA4Ar""|¤DJth吓3UG)S-1׈QE]mPRuIK5ȀeI!zm=1YǟT,8sxy(_/%vn2,@PP?6?J۬ã\LT5IڌpZļſN鎭9`0$b<,!XkS H*0#X3aO5s+(MZ7L7SM5_ ךw `G=7źy,Kc̺9SI6R!j z4X ׮pfGIWe? ZUc=Ixuo,)L٨g5/r$)Ey.tl}z4HG?pWcBptwoFa6=~|G10T~ɚ`2W9$|PyE ~EO^;1n,yv}h8M3dԴs?붴 0 U#jV,C0wag{"^ɾ1i+ 6ڽ0sP-ԠgN!}9nXJ"D)`p rS$,OX#bQk9 rهEz9[!lWE3³֜3j5o'=SlGb_ q<8QTs@Gb %ֈo+$Er`9ԩ*Q~jq22!_Ţo.kܗddx%v]ţhb `~ysl;_)6߾lmql0P;Bi|dl dIm~KjBc?J$l-X@QzbaJQ?pzfQE-'K ~TQhInչ8N)ʨL??u=X_v{#xO~ r-l@`ϝ~2*O`=q 3n$N[N!2;;oY5ٹ&q2"o{ʔ'5쟼IV7\P4L^&FN.LF(n? b<O'Oup^~m45U.IbA,iF4M"kw|{1&7gù.sqAԶnWQXj1un4L c%)bߑ>w~xwȍ?}ܐ=@ұ2I?̀OQA€(?zd#FӷG´_Dn!<2rr4Qs; 2OVsFP̆6H`udyf]G 6ȳvU\N~9OIPv7fBG9H2[A-c2ϧvkjd˲>Awc0_?zAЃB0kZר213W6K=XeҋͶiܗ}x(( *@)_#ξ9Ws/X2H+aj[y{o $~VnmW&:A)KUfCok.C ^/k \(-$. w7l ˹=T Hootlk׸C+ 3 RATa TVޓO(;)ПmU;]]SUryt)iQU~ L᪑ԓFD=|:)Jҍґg:SF:-w#'=v3xUV!-G'#3'sh%҂2x*'s &Ź< jK!Xg(೉u?NݾI. G WsTc~I*M[,a?ᅩNُMxD:quڮN4.Q'CVaY;pZCb3"8!(Ϻ=:B5ޛ^ 5rXYѸ˴y$ȭUn ,.1g-9WH+xY"x#Uk<uUu$߀`[^ۂˇi!amm3۱>n>9|O2]z)R0H0GP,"Uψq}u;,& 5 d VhOhufK^2Ets;MAn53"+tHW(0m0,9bbFbnt4}5;em[j8,~ !\ګ* \K2@dˮAEpgİ_Jn@DF2Vh,0?HkT)G˧UڇY-37bl˂ӯ *^# 8S>u Oo'ԸTT Ǵ!oyHm+06rF 2` $<d*'K9Nf~Pc[(9rL/1spĪ$|qσ⇚`j%!bb~n ZN ic+s<ԟ 톥A{B{%hzM%\ BZ RkKaޅFpCd e=I']edN6}(/VVysLY LNgZL)psju?m־+<<[ڮ*tWExŸg"JNsZ! G@}c Q a~vrZMc(`.eX6FSm([MD_\x{dt5tLtFۡ]:UAL1?&Q_GL#YOd9e(~% ]U& %&CTR R +^^ ?8Ga$Jzø}\.8R.wdW!xMPߚe^1A^H fQiڦ:DaTJj e S#WF~"h=gV;il3}myb@GL0WfFoRy6­<ϣ~}i9cT ʏk|TlW*4LL*K%yYl四'yuABVw]:8+ ^[5N9*iZCkzÌxk c%8Ԉx?-%B5M(/³z ,bT :!Eˏ;b# ڂ oU,YC1~ˀFGYx:)63 łV,9 8VI1]SF$d? RĘD{ p:QpVY4f,FoevPE<_;%R72Bq$7Ⓟu  ?CG~_jui\^@tEH;Ks*xJ!Z~P8I ?>LBbH$VbɄo~ 5/bI8S+=,^9yI1h"qksZ0+,ɂ~`4OAT;RXl AG+X"{.b!Ԫ(X c13^YB}JHN[$gn5 d 2vwA,\iA5`jgֿ*nq,X1%lm5#K2A-RN_6>Pg&0lB{Vus,RB۞ԍE 弬DuB91:)#qz1I|MӺ,pFe.sH("xB@(ImbS-KGT,|7G0MLWSu]oTHHSf{'>9Odj#HU$Cgԟ 7ݑ&R[:.|{vuSyݐ6@f'IO%-bT۷a7N,<{~+~)s=xdT<lUN 45 x߾0L]DO^Cҍw\uF~pY>ڹ\04D0ɖeBދ$ ]tѤ׽TcOIas{Gu8Ig7]"A=OAb.p fu(bQ#piňuwkDo22BlȠҎՊ-[8Wn՜!H#rq0땥TO"zɿӲ&O#wDQPlZjDV=NΑw&_)8 nOkǘz|zA[dXeGH7w3I[ byr 8J?]lEfƞz]2PIQNN%ϑ p #YPr҇ ˇ^hת$lKR8Q5jz^I{7{]4?Ƌ kS |kwci+> 3sG4PgtLb|Avd-S9#QiQ$L?EA|h<Ȁr!\~MΗ׋1{he׺?Њ[$]z!qP8}85y8|OLegj}R55[›9̷ذ0b˒q[ۗܟ͖ۈ<Ч@&C!HX3;ϱNu{SnoC3 t?JzNKb R%< 6Na`jE@3LN;̐ ST5CD% g5sBմ{isxӊk|_e1[|h ԋ&ВQ!w>7E1Dy n.<{娄0#HUL:KNߣFQfvOINZWcE5 # /Uiy-t'5icJ滾%hK{\XO&B2Tm#U F&5~'>%Ze2'+:NYY5pWj9NZM9'53v?)ԱDe?J}Wߪ,qi?֟X✢6N,k;rXp1$-E_?8෬+]]& P>=  2cށȈM2uye||.)dó*8q4-4ӴWRxSnE֐y()Ȝ+wINQR-OȿyiiVtD[UE΃԰ `Đ}4h/APSπ)?(`_]?nRJ3sc W9\n nٮ0IBKG1뒚rS︧KU_{v^7x5TKK΢[^ٵS~Lfcu}*^ 7|4S|̒XU3ŠaWH(PQk Fvj3ٹh6U* kG~QEZA-OX2 ZQxԶ> x!d<2 с$b ՠK.R>V/uQnV1ius[x?G&4&⦿0Dh#|Y o\2i=\}~]n քݮ0tHawշe`0u*)7m%K6ŨM޸(ӧ-˼F}\}I>%igs2ׁ;?so@(UgF5h-JY4O8Oo4RzUIj:daBx&-"N.NU/k`Av\!||[T 5loyOPtjP;.@DA~R{E3m&X%&fw>?U#Yc/^1Y8-Z A=u&[`(&"GK~ǒ0qPAu6-0{ y]^aȣ0bDjlyؤw]/\%ڃ#̘v,uFҨ!4mz3ݿ|J>ܜ^E;DT9!vWC[ de:U$洡%Zs,LGH,G}3o,H+C5ᚱo@ظYz C۪b%^ٲ+ŷ↮EVLRקz2s{nMhӬ:5_*g0:9&e>|u]<2 y'W4 )4LD{jb y뱉h8/W&c_ỵ`(WuNQl7n.{Y 'Wf`hy >\[$MФ,9wۮ-1W((8i.H{P=`ٰD Yqg B; @z?xU=rzFŽ7Q@BZob?ݸnjso1Y!=hgV^ݶAj5h);=P%J I%kF3챇i,EoCj]+^Sp-q䍣1zD bX9BOFPP4w;TvZ2$QfJ/HP88߆TʰlٽRZr`|CXz.aԒ Sgo5; ٷquA:,m×%7]dzGPkN$@e'I$ZlĘksڕj {OpVD`|4 >6GQ*Bu[ju#7 e?\c*l>,lrg%> (%nMQ@ cy~˸D8D?XPNg {o4GlX4nu(PG'"od;Z!^/.qm|ܤTUׁX YٔRu0P JF0p1$8Ƒ:ؤ#Ie ɑICS(RÂ~˼9oa\@Mc'np >*L~8C)jx*ɚy~oqX1>lt)re ܀.vo -C<@ DJ+ydj1nvsV Rp&WnftwVbyZOѲD1 %RP9g,7: 9`>J`+Jт[4`:H`jr#N54 R^3%yOLރLg'IsI$|?nJG:hbزI˰[B +1¨9COV)T/=Ͱeja28_Ϫ;dgov`!6#a٧/629ɗʏQ bYf4ߑ"웧|[[8B*/g''VhQJjݾX;K8M'Û.QFh;pQ e%{3+~π܃58x7hESX[=mbzb2!U~,b,FN;Thv1~Dl;,!}5K7*&Cr|+ fgo8)$$8H _q*'.F$V c8\0kOdl5e *kjpژ IyQ>n\ÑTL3}Qz#!XrZ+FLgD!{&2(`'z0E TbGQmCE c1Zݸ8Up {?X$Fʼ b5H1YpcNEYCIf|FigUĸ@@iɧeͮƹzZ-f({~k&}o (;| 6FۄJ, .,w.uf;^=aozJmݑI]bJ*pp#$p9e|7maݺ#.L!ٹbݛ',S31K>ܙ]X$({ALS {p-VI_OEYv^~^q.::øu".훁 U>#5'e),5ǻf731HHnk^,$DH_i+? d "|Νj A yUыQ!Tc5@織> a5(oJl)*7G7} ԏ='Ao?u1춏rf(l"e{с6Xtߐ8_WD@:Kctqc\(BrX`'j=Ð<,%I>>w"!VBX83łU$P4k&DU ^wL&jm uN?B9L}?L<4މOL5@ًO}-Qg7#m?Kj]/$v莖E~3݆9ˊr)@:k&62xn>f|pғ TSAucZij !^8櫷1] v z+ʗ.Ciz km:mx wB=ëE,$ՊF )|DIǓ`smk2ʣc01Ҽc' ?Hg܅3Q)]Z*r1.LMN+ENS)1Gчq{ev8k7ƛWzf5n(Xh1iש3<+2X%5z-ŭ $Vz pΕeV@e~4DjvHтO~Zzne-ԡca1('ͳXyTRW)7HȂ}ϵA&ȗM(բyuzQI8Ȅ!Sxb(1k#͜$=HJ&̶ٸ eV|N F`K⻞c~W@a+ʵ׏P|{f%3 wGyg@s-m,Q!3;)qwr$Gvgzm&̜MPbOva-2|(Ŵ%؉*Ϟz| PnfƟ~.ǐ)R$ _E2GS5XvfVKsTvUt"N75o\&2r٠ȳ6l(³eB4ZkY}>Y9#gG׳)V5%=E_eYzԯ6A5c.j)ެ\5y"f6 e&!}qrL-̝@S 1Ь= ?P_Tm{#'CHїafCmJVLu?5O,`&7v^rCC\@:KT%Sdd6h"JUH*gE`߷J>wFHV>8EUe!$u_X c FtMhbSeU?J,=z1R,?#pV4L[ՠꮚ9O[L ͘K,6Wi1 Q;V)7J_:"G?GA\Aa"E,M9{}pmzy$8tO,!_n y?oveyTy4H_Ɣ|R`lFY$/ ^RԤ<#PhX?Q]mƖ-$%{Uh- `k(83{` Fdz/:UfAYs Ӡ fg$cDP',Ꞹxm8Qʔt9/ Snp@y'ߑld/`)8a-iJorܿ8 QJm{0! HZ5Gaf{ Kr0ArK66կE:L1ohkDfsʀgfڃY'Ǫ<0UsK=_k:K켝 1e+ `I%#}+@h'=%jQFc>[9 zw{Ӧ釻(U k!ٿB']ހSsOTu_B'ۀώ7!As5&lay;?&t(+?`l=±ۮr%&"–tSO<i *@N} (e**S/AR9 #u5So'#6$?B{öѩlW:mzS|S't*o;+ÍW@?D}ds~S3 vͭ\z?<Lܔcx;s'0\o!kh?=LvG{xϵԓCL!~bX(j]i6ʐl2t76cu]_ $$XbVtqț+若w%r^U1 #B d.+q)06mMXi[cZ ҥ}_ 6U{KLXFܼD86:_4^~vͥHvˌ5\Ҩ>2ӝ3˩B3)8qY  ˲aKPgu21^:-#HMY>2#=W$nK {Vre]u{5.A#iҴN#]"aɒu1P7!9x"}4hd[ GWm^1[v*DYtveO+oDIѰj^{YfؠI8hTA_bhFͼʶ`l2BXb S7->'*saBu\=0# >TIJ`|  Xa8By$˂ЂdbaaM`tW4A`t+]l,k;o{'0YO وtu %Ya9$ǰ%gD>l2l$v>b~hT7pcԍFVkx'"\. $'9xy9һ"aDNz[A8{w¥ rY@ v g= d쯁:xPx3svGV2\_Cp@/#-}{Mb@й7mQl7)9R"y奿"^aF9#_TDQ)2Qxl_ѽ&h( giC~`&˕V7j1 Fk:^ϝI2d5dԣ3Or%$ہ.$#A xq 6MO6}خ9/G\Nw++Hgygkw._ `[(H*OpnǠN >+ ڶa-&N&Z?pU"wo^8@&CYu X IoÏxEԒ"qpm*a;si"=PDw#SloHM>й{q&D qXW4cKzkpV;ͳ签ݒBduHOyN4|W(f7@͉|CIB68p h:̋-XANpC|C< lўY=ءLSYRKǫ* Ưǐe9|IW{f aW2=B e^2x^B[E}XNPln gDKǓBB`T"Ҷ[HyWn $h^F^wFTQl]ni1YvIz]Y5, Q$T,gGyش 4eإ-~Oqk׽lP+䧓^Y=Iڔd,$t蓼|^x ;Ĕ?c+wmz3-?GjߤX]ъ%я#OZ'jG$b0&NHt85Խd^_$0Q0i 徤lO͘Dn$"QWJtߎPklerKO4>X ~#%γV3U+R*QɔA*Xao{пcG?{h3O GUK<ک/k΀&(Y,+4ϝagN?-UÚd{gaxO+Lm&ñBgjfSR~ GIKͧvX6OWyǛ@0W ƿF$@<ʄw =Sی [" ΡSk2$^0]ᆎͣI 0%;ɸPuqe/րoT١`:-~[#'؞ ڡ$2ڂX0q;1VaW^OL׫`hbjkr-OXzElj>[EpE[e4%L`AEթYw`x/CfGc8+ެ,HP@5JHTrbm"+ѷZ wX~s(NQ>A }n's 9sa lzibw ȉ2R]uiz74dN6<\`$t g^YQG 5VG{/3d-7?M㌋'&W#xGf&:y<,qD?> (/n&ê׃Yδ_\V{Ьk)K+ &y\$0 2IGGGIXNM*2;ɪtH!^I>Wo'b'n߂j5.b8Ry#`%%ؙExoVGXH=d_ Dy;L5=H Rkqj&]H>͑,+z|yn+Ҩ Jɛ+l\j@l1W9R h/ԲΨѬm_K5wRYcF'qt9ɤþLnC0Yw6&bzUk ض/ErD Ҥ <)Z/ǐs?_ >BZ:A RZ 6! /pf]A]eݎf7pwREC"D)z E&}yuFC+Nf՛Uu7Au%Le"XSPfx`8#ŸL[H.ŔJȍVgoUݱÔT zMGݛ/H$uߤd _r8|§'+,W_1BqA3>m7-lq{`DT)˾@iȜ=0O2K E hYF/$C/.zeIbi6sq 9IYELRB0mnubWwt|u*$Hv:羰r "$*vNVR?-Ԯu !/˿F-~ڷBU$_io'ސe)o ~(3W+ZjjSIeZ%$R)17%`:[O%N4u{M<(cF-)^mU(Sl-v'Rr31 [S5O.Ռ)rz4lpH@dwӸ-`>B, #bNk>AާY49w:Tn:g+24hZ0BX4>gH7xSuVͬloOǒ)'^a9Un? 9ZPSLUxV>V~fCdCJX!7,xDmlYjjs<_l3op%]{nz"um5C* E)JǍ^p˚j}!62}υq"/l-n6@<4BX`pG(`gjI~@Z8*'BJ]ڳՀ4őp놛^?F(@0UsD*WhqgrvtJZorXawŬ.wb>T8&bZB cO#l̍@wG*CBl3ĤlT܊.&6d|%5BC;V/1Cu `V6OHC\O1e~ȴjʺxI!8Z6kZ ^h 4 p莺^.D7 lRp=]:lge]JJ3Dӯ?%ay#uPSyrOB"et*VjuיMImw\OՑ 6$8d?&B!10նE h^U׻ ,Zcߪ:yfc#CPkIm,1x$,NYG5ʴFȱyX6.CSkzGЩL_04#_g-SgyϜKkya.t2!@A#- =l6g*48SsX!Rf'T-T?4mkqtU1OyK><'GDNQanMF2hfd't8 +>c߯pEE s]K|ޔScNj23EWFpZS r5#*Pl5O߶~eu谸{MšrҌ&+.jNĂp NeĆoGQsoCDS2ǡ ΐA4?N1 E -2M<;p'oVGePE5-[8YRE) p(NQƻbI3OqM\q9.~Nu>+rK#90 !N jzLP jڼX=d֦'LF >qPXbٝR8_xg]%@"CptCxllgZMw\wE4UXzlgx {@8F minΜZ ]9 +dȶ X:͇6ErR4M[KM!⸰cd5؟iOjyvb+IG(Q.ru?'J!=Qfae k5DNTɔ,-X|(+˧\p"-9)檹4 kY$V~t%̎}¨%+)696 /yA֋K]q&SAr/kqeZ>a.[hM3^'2ʁ*)wbd~O{;$: `^6tЍ6y&@já27,bSr{ I(@qZv ѦdkTBK(#Y~Ά ٩7kz-I[vkEF>%:&W= :|R)C<sao*˄MZ0x T.a8}q&MI* >IeT@N{/*qPpsHϥ2/eNxkdugkX;֒"vt\=bu?fA$:.HMƱ :9SƒѿG78u-$>}{s_DoKY16zQӿ}:pVEe;i7ǯPiiez^٘](S[%T-HjQbcͯ;x8bvR9Qf?430DTV=zC"NC^ 'mZЖ/*m8A%GKkAQ(FEt0N>PJd4r]{^ Պi.*smV6 o6'4ph333<8D`i?)8RjT'"8ߢ_U6ͤTVߩ/chNhsqtDfAU8HJWfDCɒGfz:=8P"I2* YcLBvA(H|)@AFp7dsFvK #JJ{ل EV24ZPOK=ǚJ ة0:?#WWULofZ? =qT~r|HE3Jmj=/ToE{s-b4oTp`V%u]6|Dsn7bALd&d tAKi#S7#B,t/ks*qD߄XMah|y1HnVf/s6deQ;>P;};k D#u q2$[ڥ"ACgEI).FPAB栲}9dݑp1/%4?Aўԟh*kV7|܃0}rǥxtŴ]7w 5j^^^D*[giHIa6|fcA#+ z\rY1 `'Y1sE E`3yOq'S !5@7?H)Lb.e\mr6sw 'N@%^y1HM欢}P|w5ٺ%o$b{Ea|?rb)Qڧ[[QpȝU`QJ7#s$UnY;%gJPȩh՛fՈ C!N}Т Α$Znǜ!!Ȩ O+ 3U:2Ƥ."\<}BGKkoVbHuqC[Ziت?rNpY \.DY.n}!..g}*i?$cj2l;#,'ܲǀ>p2? I$r~Kzʳ\qdqېNQ)T~ =]a&͛WmZ]ןuwD-\N7c WZQ%/(KLVSȞ/; 6ݑMGE_X;8ˎc~$fa%#_`%%MZgjxXKKDV%@G㦿ÞQvu90oRq#t[ ;*+a3HuJ=,-bbtDaLrB,<-]XP\ .:x$l'QhKJ#p|$Oȷr8Vs)ͳJŞnHqSqbÑb3= v@B^ކ%_";yw3d+<7ԿE52/rvozeF=g,1gO`5-+hA]Z|t\#_\י.աrO|LvNM%d1 YCJUBbc,wz뭁gr71l1ӄo5diٛYN $]-.+ѝ͡KpTF?޷LƋ'GrXnZېPU-}~L|H_޲#pa^R7W`I1ryƑFMy*٧r -5auY/B7\gЅ~=#B d]:@:`\~ba Ss{tX zZ«=\~qƵ!5FJϕm,~Q6& >ŶSČd{8L5T]n?=t`hs@B?8L*IAp$U& pޯv˸-֜BC%#ؙ]X@S4tl*2NEb]濧4+X-#i ?yn@ś&L4@[Kӵn#3 ކK#w ʈ/))BE (6Hg Dׇ9Hx6Em.m *iJY?^lv0)2dFc`ɨa.ѼA2vaIR/M03g'#x!n\}ySjO^mppLO,PlG44[qqGl_ "k9YU\q$JIPmm [vmMQY)U-L rI4jT@g ##8)1b)/wHj”Mc 90Ru?~ W+pV)j̞K0EPb{ãc;+lb8I(-꒕Hw3> $Q#M _+pႶ˙BEE$Nr 2_#r#> ! }3j8ހ}%TNѲVzTQv1"F&s_I "}VsϲT[ ~ɕxU£IJO7QEL*̍!d$[R63`l;#E\THL] [f@J~KeV Z2t 2GJ>% Km̬O(ܼM2yyDAoxܲAZow~:X-jimyl+]V@?SXrѯJG,*5̔.kZ{c;=_HFV xmx BHfFt Q Kˑ0kYZ6x)h|1z0:,1l{9/w!KMj+>s첶 !p_L{5R!G>Fg"mζ I Gq-jcsAނ'zw_%)(Kicf3)*bHg*TlZyz쟖 c6>gQ 1)Ah_,TG~`:p|wCSt#wBWyɽTЛ947!dZ\2z?V./Md".hE$%G15 ,G+Il f8v1HyQy=`f eo';o`F#0 RݘuynW4ƪlkM- 6ӏ9Dc~:IjYa$qP ZGIbdF,m!"$y%|`:w(ϛOqAdbހs+<3e$irp~e2 hE%m 0yw+s]x xc;L[c%s"_J 5APc NNkj`U1At|{ySd9j1&HY-S\ﺗA~LRȫ$I:!򬆠cEȲgpNBr^_\&w9ttMN<(bFZoAՓ5U?| .z{A?XZj0!]tq2¡F;Fo s4%M`mi,")v)  MUSXqtF?#gyÙM^h.(s†-~䌆ݨw}_nL< b:ZdJqIYW;osi(uCMfs/4| /X" +n؛0e#cWyY0T־&I}^LnCg buЫ}n*>bW 'u)fWyCrv(}#ּS9E[ 7A3IfX0<^{彆rޏ hK/=[Tȇytϼĝn02ʴ%K7 Gݮ+w6Iu8e3 (INE/gZI ѣ[mw*vAHjϴfeuвn}ibߖO|W8yjA $6Z24 ]`x:wdl=z3ov'Xv٨(2Tm-c;Tncw+˲0ZU*Gz LAJVe&Bɚh֒p_EK;@|,;?ys4۔ z|oB\Vj\'h j32^Itl;qƻN>JXjzbdgds-( <Ϧ{6$r׻rVr76:.Qoo)wFTdrkr8ïEJn0`r][7)ՠ? G"Im.1P¥%GZkm ^iLl2R T6ܟNzx\#gDLKiI}w>ʻOo^:rz1"wۥ)- L˸_I*kY`@ )%O_gC+U<=QQhϝSrnwvr2ǫbOhX$#ڊ]vUxR`2] CDzYeV~>Y63jE˥ eu:` A!$3phͿm^i(4-xOBF`.n_/d73K5-<E1nܡc+Wm-1٢7mDZr8 dɣ0kb:,@<N?t?U')F9#@>阙 _ i|DM  ~0!'$LYMTS ^:a6z,ĉIȈ?5[$dF兞 @t3,cH<=olQ-jΛy;Bg pt tF~tc03oV DoA[mq*0j:iT!WϪM~q`*eS_FKfyP[kL111QqPp$zD&P]9P <3ùF5tg!\ifCM|@iV3fvc=!CtX6SQj'X_̰̍[BilHڶZ6lPF |7\{Em,n'!e~?tė6 %$}&"7Onꨝ]j@CY'1_lj0Wi~678+bE2^VWh(<` O._623܇OPڐG?HqY@n_%I!I_E=ő poȦ]v[؎M_<ţpD;OSk|a؄s"4uYlڔJ`E) }7Tf%`֕'wܨ Cd^ULYś4ѭdӉXfwz'qobtT ~ ΐ;||Htr:x+gObYwT*,|[bBG$A:nmΌAūrz;Mi֌T8ǹ8=LZ273)BJx{xCu,3ru:AE^Ύ{s j %oS|k8JJA'JtxO l6߃faj%C7I(he:Yl~r/4{!qnV=m%Lp+y\ᠨB܏xʶ^c/2_pY&?;*7k*l4, Ip,:<)3jhmy5 wPrnN痴PF"Ny$x7W{!/]/5l͉u5s| b͒?(nxknRx19x`w͆%rkEH/y֕O#"MӤP=\=2yHz4cP\9^`" ;]l=h#‰:i>U#ReesxHقqɐ⽄f1cI-rW/j̬9ػ-s4DOp lXT" _dzh 8[laFo$2c'])ڀ.*U[8m_# j` "= NsLu,RNm oB18'\gE]#и z34ek@)M-]{2," lx^]j=ЊK}[[Xd ;d >XJ0xԃ0o\(QC| u.BQ75֘}im^vuKYT)_u rˏ`g0Np˜C78G,SZw[ Rr|-!W|5i>2w~>bx74L/!J8vgsI!EyC_hWwx;'}~ؠg+KHB̶fgv9H-׿^׊ Ʀ53YUA\#pJHZBaUŴ1ޕ|`Y_$x\ 7[KdpZx 攏hy ;fxhYh!H'*~Tѽɋ/)>[ql+Rit?AQ-x.N$^WSPLT-"*T_CQtl7iٴ3OF'~mDDmO ϚԘ-u)VҌ؃d'ެوyë' JMA1`9 łnal(lo4f9(w*vW 9wgY"i>cHcNZ(g$7VJXCĬڃu$;b$Ѕ)b*j6UZfG#hD~Jmd*s/ᲰB _63--7 ޮܵ8!X̮;bY{ĀfӦ>{5xW"/q3 Yb_JWYײM$cyɧKdQ9ݥc\Y#:e!^%lDUDY$h~:+j4<gJ(֎Qg&o0}^9I5H2'gkH,/JCimCbՋ1{}X3lQ jXrɑRMﬕKVc&샂R |b ߤ ?""ʶsjgָ[)A8RIM) [Teĥ蘅M;ẅW2Qd@@ܳ!֗Trd(/2 tzU=EU@p '="R Y$e9bv?7x`3,2~6+YA-7"yRa$g*^KUrj,s9œC^nwh=vzl]jͿ\v]|Dyf.F[1U/B#Ky;9Og-O Ib>'?W#z3Zf+]REǨrC!`lt]88¯|H7fx@4"}nPf7jyٶ]f|jtd8*B4- 6Z6.x:5Q9pM#ߧ5Շ2Qg5bL=[V@n}l A*zVz9shtΚAÀԈ\,Ęj~|d;H͒ږm`ʴm(nzsϜ X K~a2rUxɁۼr8]뷚K~_3[i<>)4R!lzؠ64=%v5D]|+?o]En5*cS5bl,MC7^ ՚_ 9_I4 JЇ"KDyak_8q)!v^dTjI6R-||Z$(`#(,5kW9+Hqnp7ڝ=b;¥x D^ޖV"z ʤ kԷz\D׵r~Y1="PClRe]NqgU.d0qR11Z5CD&'r[FoijVރ$C>бLGXPI!>F;0"lT(u^H:g[9+!a ;V|'X8I݂T%F_1@kJ0:ӶQ@Ծ]z>0ءCz'T ɤ@ b&tPjD7F?m,\g"~ faN6V<*$IxYb!)eq  [>XLi(.Z"AF9E cY-.¾Y\9h*I&Iu FD7Wz-U١޶} V~aGhU;0n]&v?zϻƑOQB k[ٶnU #A]TG^m[VH@a@Rd>҆.?WֈքYtOgM|t@<Wb mũ}*Q )En1fAv=[dXBGb( 1JiNMbmi)ϡc[fAR3H zs%CVB9z&fC0qfj R< F8 z6cug mN/NQk rz< /$Fqb? `fXco(oS`Nrd{옟cC.z+rX33>0Rțf{jh EqıR g>p-GU0])ڔ`=%ڄ`D? m [+ 9дf[}Ku[ & nɵԳ dVu5H hJX+i?*=P/,],{mq!qX"Eŀ"P@ڥZw b:T[`m8t8h+,GMvWSE2wP*Hxs8%e85nG˂O/Mvbma䯗mGf՝~5Kkg*%HV@ILRQmƙ쯜[ŠQ{\5/WNɸ!G gʺn8쬭8?Tj0w#12 qlDٴ]x@X4P)e3vL%Ha@ԭ*$z]s7[ns#{C?<*zD@gB/Hj |K9w!lF/6Jo؍3n9ū <c8cqS/JS 27 .DxfaYѼ?nm{.{.bM>0ɸB}L 0tHUFL9`zӎx?1E|h7ޟMo ɢΈbGs#]I V}ΏzHG"*79蘜 ks㴴Mh9b߭A,p@n<`-KōkE)sH }<%6m辭mXφev>7ĭ"Ӱ{7݃o197]fa&`3ya|S.DX+e9R5KFxPs E]ݔk?pqϒu&~oJC 2싻b76+mX<Wu2Ih6JGS bL/6Rq..>&F~Rm~BFG"h@/EK$TżqP>ą}M5V~t 5lJvZhzcvI"}v1üRĘ g ?}fy6jbivJ, "8e+OVcS CQ-csSR+{RxaK쐾8ݟ'xEX$**ZQۣXMT >HRR0dnl5jr46-&dBG׷~=vnL\ʖʹ2: s􂉛|m˥r8PH#֙|(T> GL4B|r7eI}aGӳͳ S,'T&PЦrܤ7˒{1UQJ\7_[@ AuxqW AX?!8r#~SamٶH# ;[zPɧFnXsF>6NS4~/ׄ+AcrĂܮ~PK _ r/fwSubE;ZF^O%A }JBz:Ʉ&qӐ㽮w,f]?h#V\aU󷊾H UFL|׉ap Кt>V'~J~a\x ڔN ,`Xsi֏T~$"ذPaZeT׿Q`籎lր̛Prt\?VSDue\mu¿D+O+jWe?kS"i$  X8+{_2S`5ـ41Teȟ6)]1,yAFGnJNƵy"y5+a\%<XZ cfxP{e@]aצ7ݜNs Sc(5"{p4e=xa3/+\Qo{6BPM,qF+]G 4zSg_ɝ2 s3FH \ ;!v̴ ==\c\KLa) B-9:5 'ƗI&v5±,)8k#"jPy'M\ՅkgۤۖtCԼ{9R )qmF7y}RH!rǮtb ޼8.|j! l:I*ERvҤZfF` .V.ۭؖB,Mz3['!׻`{~E+\IQr5U-9ݟ7>لz?FA>Zсwf² L39KE%ZX<4Żm~h#^@mUa|}P`"/@8\'NoP%u NЁS E.<ا#E$.ƶUq8r;& ec1,;Оe']) (J{Bz䱻OX S m<&~6\oqgf58[B^/V \CgG!RSݳ#rZnq8*X4"Ӕ[Qpպ4=j󨄿-PePdm2=SJWUJ=iuGS$> }aiÇGuR=B^k@K"[UIF][E&)6G}ۺq)œ,2ew/Op}Rj,m;Պ b \9l`ӨfB(}x֜iˌ=r5!Q%>E PGBˋ}'tNF/Jx4chPɻ%/Jc5n V~ ;׎_Fw&d6iSd ;N^Ͻ߇qz8qtuh F coZ0qlGҗDq<-_nh7f v'8tX:wlobR@N{oǙn'ttQ:I!׉-+%OH#Qo̢. X!,_~YM98`SG|޽vZS7_6ɰ"awFua *=&@OSz:Ƒ,}4$4YTz[417 %S*/6S5 ڞZ fVagw_ 'SQ?hA25i')斮lΎc#foїSݮ*Q^Ӛ.2Y#&ES`L[M"O 7 +Q2;w++o%3PNK B{-TLvOTkj3p!׼QuqN׆DoT[D2*l=߷tkUGb*]2b*z@1:>$@9?{7,GH˗OTaMNv[Ffsw\kPޤ>ZFӶm)T`z@ܳ eFY9go9 p٤+]q>ܱ'\F!TÎ#]0$ N*f:,yl-4[Ɲ,t{Q?po^e2E8T#E/CyM?D*$\.%p(ϩu8q^IՒeڸ63*~(繜yx:+y /[Ei2E& >%col@Ue*2t% ǟ_?6:e,Jn;4l}/D4#}Ge49#tҩ^æ`ѱG ޔDa[r4JMEɂpHa6!sCL&pu lu)`@6jZ6&&>T[n3fLAliMʯҌ}I"a-rALcabTHeuTQԋ)rTDl YVƻ4*85("]2>Ŕ|P1B^T<_{ez=zJΖ^=~\{L`.%~yD3`Yn6!P= JJ ;l ^˦f٣eT䥒G.:^{)aLp.8d~Ǡ4=FUeueeRL#Z="Vp^\[-dS)Yr|6[Q-,==|n B>| h&JDѳ| [O{_D@vT=kʛt  W&Ľ|K}f~=yPW& Asu͉b(szSQ CL{V:XŤzaQÜ^ݴ FˢO R}3^M",)Z_i3w,2~m`i_+D~YS\`T4mܐ&WC|ٲgMf< b4Wn-X;?dFX*{{VswMׅIOm~ v$=T%34gin#"D|$!X )@Y1:~7ۤMaSgZMƒ: EXES7`z~ 0dGS7r^ϱzu> *[S  sj:ӉZ]/`'xN͸7#%!aYöH=%ch |ey\B<>co܈- ݖ^F<7kU`T2g9docxj )Rԁ2~i<[zXͿP*bT< CH'תp^X5y;^F-] :a0Bny"-&2g)/)48O\f \pX]=`}6eŽiA[6}n+f(&!h$ĺ$-n y\_b2plM䛅C]W81WdWѕ2\ m.9׃o,q-C-+:g&Sjb<_\tx1|H#2),::A+>iDtgbP&n\!0NM풺) +<wG'}7vcfD쭌[jn΍Ձ6ܸ^H\J8c+xi.ttd?(^cp|HVr{QZ."W-4o@>swxyblOĺUҷ\i188ſ޵4E&e>ֆɰ^{}T`L.vDQޓq[:"d4S;W׺̯ZÉbv̩L :/mgZyMZ\p9C4з-x$W,DIf/_#(?*{mX]r?ҹ7p h讈u={,TK8>F>nh' _hH w:%lu<2ANL}ta?ʷp_rUYc{ŎFQנjs\rW<Εsշؖϡ.ޡ`+.DXݬUoD?'ↆ4Y,9qIמq\9Kph];`9%_]ٕ]ZN;1OeV!]yMu}>lXq"nHEʧ+R FBiucDws8T:Dh2XO4p|nj `Ia~x}xo0'GQL8`5<3ʬ?Wa1,_vLB2ۓ@ Ijoc,_2"C՜.]H|VlZ>lmO!B3(ldeح{e E͊OƬ3}B3s:]8m2ٍ1Q,h El[a6IxL/%T| <גjFo .NUئT\t z8·dZq V.6z@߿{n E!))"H%18we g}FwcjWH]\yLl `E HIzzǤ58(G&4_cK&Yuh| hPo)LBj}{d9s/zPv\dUY jm,r# T0qE[)naxi|NlW4ŵ)2>EQU<5UM0)b7A[v HT޻ݎ'ϢCdXe)8,Ҏ!CuxxP],ϖUkL Q qA˳Wx!{{^/PQJmbJ7?xb{t.F@KNw`np3kU2Q2M!JQlCL4^ۖ+GX@2~x)tAQ#!0yGY9P3pJu=E$㯇}5Yg"ͺYB#jԚ[*j9\a++UoJGf1xcnB~0mw#\/hT:^H'V:m6=ؽ] bi`01c3qq?Z򤴜NZnҲT4O;{將'V,)H1j:>X8M#8/Ds̅U䇫mnr&~0x2̠,}ll.Ht/\DM;k--EQwJ-ސSLP,vgX "&!{{1#)$[u$xsr5B_dM|UBPv+ wj7 `Q/?>548BB) QuBz Ϲ L4 LjؔrIdC;[yUM7nKy"('.(̻ooVŅyҨ%BJ3zP⊃묭vky7tXf{j)rfowOH3c=>6z߫]l3Ol60" J9Zd-A~m?]'@A{wgNfpIoծ!bIۙΕ}lVEn1^S~ZND_nC3m.$4U=-׆'")z\?]l ]cdp 0e^jK7RQ،dP ]yL30&d»;X*n@^s~|mRB6(D?@"ϹHn_Y`x2?!j];yXm<_jWv*W2ϟ1:JNvng~.h`g &n}iF8f;(Y8Y׹%{?k%a n2_;%IoQvB*kǓ(LV~slL}saq~&SJ}9օNBf7j€x,^_TJMڦ> tl38zhf0吷ڬwʕ681' 5~g; q ~\5- 9B~kOE3ȝh$"{5mU#g3OdQr|nGtCZa#jI$7{2tuw|Dzv3髭+{w38)6y F:{iZZ{/M1)θѧ5yS1,hìϱ nZMK"]~eUDZFfv40ՅtΪX=},5U&EnZR+@6J+-po#IlgbBO Fpm);$#ԩYUJ#,QqH(霄d<|/ˢ-{t25wcO$\%f9{fϗKY# bgI36cFm|Gd4E&-BiQp۹ۋbi$9nɻޏ'`|g7(HxU v=#kwcI51 2)YCJJFo2t5 _-<0;z)PHcxp]hS $5 Mhc mV?y-\͗Hjpwby1؉ y[B}(tyY5.!K/dLi"+cݜ _ZW PQ|DjXs3;B&wkr떢q w#mBhU!$*$A ^S7-~&6҃#| e-||쳪a:Tv^h'Io^dU&gmZAhyʼw֛i8#@I8|گeU}n:nyѼ[mx"@-`3 LpLƗa5*841V*)HN"JUv ~.|Hjy,zp$:qCo.'5Uwn/`D?{Hnŋ/{8L0^H G D1(v7X^vbNܶn0#ܣ, :ʟz(_sLBoE›2z!k lWXaMAA/@E}y)_ E)v;"2a݀ 1A$ohQRf:.}^93 ȣțE0Ź2/ԟÝwVj]Gp5ęu.F%sE'NS5I{[@n ]~̈́R{95#2SRއՃRwz luٌ I~g)m)$&faRvx7=z@Pcf:'$"چ[s2Oh}MɊrg~)c?Te"!ُa~qG a鴃Q-YdU vqYl' V aהwA)<2}(.a/6㧬VW5 2,J2+,9z݀S RxܕX6/ο0+sz{\'@xi7?`aLi~86:|P/by4kPAu)&Z@n>2C"Qk3u7QXTأ7@?JH= C6W-kK a.sN(|&-=왨eS3"SǴͲ,&&(0ZnTx_2gs:Ҽ5SAbU1 "rX S/P Mgv9 V+Nq%$,F)(QB ܙWB7ӈ[)s~ƿ xLWO ^g}6^&!0hc~.ƹXF.P|mAǝW]KsL'ĵŻ)s1ِEj9+fydDVg h$m3z R<c*C~E#܈ L"P>d(nO5#rH#Mm#"߲ddʫ:wE7TTA>T|[m+WZr0sL+(hw WꍃLtk'A.Sv4$d~x>d݁#xz]@&4"HփpKwGABxcV3 wΟ/y.q Shׄbg_ a/'7TQ Gph-SynoB1{hRaemAc~P{ @b絬L^β/ۘ99~J<ņ^m'맶ae>r^JUp}vҒ5 :7$/R\9gF K;)U8#ǪASۭiuE[4Tx.fθ ^3ϩIVl!ލmzeqo-GYo+/t7N9߇w{?˯%ȁ0;V* ~1hŋD_ϫ@vROXS'fJ:1m)X8v;%ωnaAҁjra9f/sme2h0ܕddҠ =Լ{*$  J:y?BG\JM31h76Aï EKx hP픆\& kٙ7<Ǭ1Xv lfyUr˾yN<6$=rpyx0ń!щȟMc ,h zo A 3f{'1c^ԪGgSfXeqǿ!D{%$Z>~:\ ws 6O=~&d,n */uW(FݯW+4v(&kGOE};Y$I[3%z./OM:ɦLԮoZXo` F"xNՃ̔z>^ޚ\LYDFcbZ(ZRMW}m^}WqMs<_+\˷j 6UBU(ףgM ,̸݁˻):@fPԥ>Ql X0je2syTq]] ' oƄ@"xj"Y9Ze.kȓ@d(_u:_-ǐ sq$3#"2ϯ2S±߅zV[ _-QVۃiov1D&"&9`'zG[7zhY^׈+_mS Gpm\++'#՘dyGxwأcg&WA_llF-Ɯ\l2ɕUa6} 'hŝH_ԕT:r[itY( q1衳qxغaPm:cneXTn:F\\ }. *7zMD "8BEEprE4˾.!8NUoa &uP=VjHmA*T hWޟN}WըR;%m*[b of3DLer6h6%RNF~لڔY )WdJz)X9JO_ R4ײ4%ŗσ?QPnݶNXמޖ&MH̖ҭ_Qg"֝g'_HLҚKofļClP{S ~vAKR\۽s1=U0e_*Ak&ҌuFJ)\:!W-׽;[ Yj'vm j ](q 5y\xg_yxɗʟDa]6>o@.j83HKq*nEdJ6aOyAxX#g*$h`QQGAh1v0u<4œہL`_U,R[9>cOOZI -' <6 /@hS,6 >xcԟ8:W*'#C zoo Xem{l0U$ɺ{u[z} kX41Nr6Ui{Vh`viLaWt鍒@tm3\l VCҔ' s]h9 G(zu79U8Ƽ6.TaHM|5L۪ޫR1Z`H0L!٩ZbږT3!RγP@VYƳѓx_v(bt+8Z.? xΆ'P,c+ 'a7s%thp',8rR.Eto61 L&81Ԭ(qg< tP@YZ?$h@Ҟ>Nd\OC3FWo\Y/({¼ÃxZn׽}%tВ[ZhF&\2j·8͢lEx}u# kSsa%h5f|TƜrhKɅB=a4S|1TJh.MϩUzzT5[Mbv:l1|s`lعke#B(MOg9ߔȩ+dڳfR9XGƝZ/,#NUd˯F^o Hz9@b]lu~\38+yIQR~6+0QP*dGn { E)#zX0C|[dy{;To,lv B-7@DG鶉&%5Wl$^Sn+o/VߌXR6ASʄ//Mm.`x am͛WEsa``}=&(1צ\7xN~Ǝx='iAIDZΒb@uC&7ʱ* uj׀d!]Zqϊk 8P m\t*X1VԌ@婏gni}Hp4bE>GʽiYZ$LScCɩ%dJT c}r}㢙~\ZsL\|pAVt8jFNh2=~7Fqlj QLh>/0U Ql툇i ;>hL[H9l5j(OPNDy(ӥVTCM)lK@s~2j1FEtW޸iɸaǛC~ʛ~I\6`.J"c)Bv-vSR`Ψر`e?v*e?Jtf%&Ӝ B)hFiݨyZ=^]^#ˏS>|77,PW&zO%KnLޒO J c}mE.%ϰv^$r)tHKC)X =mj\ *"L'hOT%c9O'LbB w9)R:Yɾ()Åցi'N,Rt>vȔE$:6S QȌ#}"zfP`#0qcYa$h9/a꒽ ]Tq ]֦6qݭK^MD K%F:?zc P0@(HXMBI6fd,u}6.J @:?RA"UF'q.U +4 DBO+vL+ޣN#k=ٖIj5_\<ӮV0x`;zyTg}.¯ U~?>Y fpȂvmF}<Ov9\׋ AP{NVgѱT$QPȕK A':i1ESh \svQ`mXћ*LH( lb9%LpDFd" NHtgK0aKާcxbWjCC2H8%H.o+qbzݺ >vԽ+E |V˱o DIh( |:H|m&F::n_OlJEkqZxzfwTHɳB*uv"QȔaљŊ"r%F l/T3ܲ)#K ! "^V$YNuQ _Yz68i՜+2maB|OG_RwJЋj ĎQ-䫛bӻ>¼`vV9ob* V_GcpX hj"%"nm7L?Ӫ4{hoq֪b _UO! r iC`lgٿ@Ys U:L@狜4DDtUS$v.JM_n_o.9rb m%]4G*Q8ޖ+^ veG25/ʰX枲dL?]qkxMՓW9a42c W.rpUӢܣdD+({x"Nf)Yh)|/+P8hsӞt~W:zw[U*ȓ a㚄*9~4Š3E8p~`O[V?6lc"_${KyqTQcՎT֏0BQL9-a|D!JvUrRrJ Hu&W[~AVgW![U} btߛ G/tTsA HTڿlII o1VVձ^`:Vi6w=H~`:L ߗQAqT:2A x(A QzEE1-ě" ꨒ N&G1cjr--: U?$_R(0h,qr6%KZGUV)8}l" gYkYN =* sw8tM=' &PPҦ@P@,In!aP8jJzO=߮.k۩rÆQDʄJfuaT[0a 0{G>7)Dݔ uL'[uN,'W'掻m5m!.^rAhjIƥqzx#W*Oaa6kEA-\x qQ Wg=Lcy2rDZBx:EoU=FH_Tu.ˣhuTK=nNjW]g? r AsTpVz@>! bmT v_U7q.oF gvrjW dx~i?lYhWb;V ϒX(U8+tP{w4mx,k{4CEGh cN3vTHSr(MK82iځ<=81zGU|E[H6׾(X/ E֕asȋG#_PR:|{HEL"θ$Sv'Qx:X=MU< 'xw6Aɡgniuԩˏf Dkv#<>"\ߏ̹Up5 ;Ӽ@hW @3myoʍ7t0 e\f2W(YwPRz f*WsGNOp_[\Gw 63ST}*M4*&7IueND>8ԔH0ssN?L)Tm7Pjm/Ч݈D'ͩM{`P'~ 0xi e9~lZe* c͸|+{OIz|B%۰3C`SHI1]s\v.wľҡ $4OXݝ^%Axu.}g.+KEm^G;v&ڪgzi;izǤ/.6V;)+Cr`Um.R( n췵.ǤWxd*#;b1 dt;x0<ݼh,09<]*Qqo 韭|9fH17Ud6z5|4uU;*c< EFKW6YWoovZs=sS \چUYw_ѥH$whXikbe+679QS-l>цuCӒGmPm~۩Zfk;rl+Hf /Ok7] {(~B';V-"])jyqu_JP"43 z]z֊GNǵ1q1 Eu "gi-G5q[ t kĥ"7+)A8!Ľ6 o?@> h-}x-Ճ B/* V0J0D;E޲h._2iy!\q14܌U#%c݅тu>IE!epQ"@{xu sd.>T!\FTMM5*Oc,8J3F LZ{D4oppz;oĞ!ۊnyh{8uu wn5mIq4dnlCUxƏC8` `87AU@ [Sؕ@U- |0@9 Ea}ӊ.xLVZRd imAC 4n8t5Pn/!gûhwA-kT_~7w#M 0̙[*7Ż^nɕuc?)Ըf Oh|+1DR_7FxVn !Z2PWfk}kd<&Ͷ2ܩl_L€iFvT 5N XMԺQ2ȶ%yPB{Tϑ?'iY5#)h`uyV?Xmr4D_6N =a\L a=՝TUh>2l'^v7wz0$.3n \Kecm!_ݝ+f jAɥ6{+{0߉r/E dѾi'@8SEH]`@JJu{"YF1&aog|{WS 5@$ǎH(s'5.?d@HVMwe]>G5YQ٨$w)R _vV$wGhKE^ n}n %r<# D݁!6"j.+6&y2=i  @[*헰$^: ̚ i˃wO  Co?%h G+/5kZL o58] XRJRI /A>I7|{M\z/X2/6ԅ^;\Pi9Jd(0m9z\;Guni6U\\Wzo=:$=v ҍpqN6=_1bmב0Ϸ6{VMMZ8>BQb8r5J-,{Zкh5ƞk6@d|b$]5bĬqg6lt4H2*$fpyh`0ktHr#QN:hE;(ib?7k*aTK^z0D6pyʮ0JMbcB"{/ʾ.w#6\#JFnUEq4 s&Hw:Cx=dc\hѾs(ޕ(]U+XZ4Z %D b8~ˮWy8*CpK,z9ĸ|b,)ZI9.龾urus+yOdJx|qf!XV0h&֝@L.JΦJ=%KUNȻnQxwy'v3>VuȲf!IJ[2i{ =H5h~'kh0|jv.jeULD˰p̻x./Lʉ%}](AZNl"~|ΎC*ۥf#aR (rX\klt@;we;iGItن:AyH8mT;H6dH V=ϴu9jw>Q!yǝj!g uxPVUH8gcXngb0Jz̕o6R G[Tg|ػ+ &h8بt+177R6PJ]*u^ 釹/X2`"Ԓ7et8ѵ 2/ZH=rv~Jhb"s=PfG*4Q27X:k3%S0Ty]zDWk(ف @&`x:t^9Y'-I|%QR.0K}MzQT2e6O;$@R$6/]]<߮ ~ʠhdգW NA/rjWbYs~O!(`I;~V48z+i`  C8` Gv=ؒW?0wJJWaҀ"32@]ĮIS9M^>,w ElܯȣKW6* B(>mK~H/̐?GGڹ \^q)#__TS"N(Y:3]y܉p_R z 50X g3ó}ݔg۪'SB ;gqto)Oh=˘5s8(e 1@`?!T:gh J*y[wtRO^ma/˞n:jQ+Բڞ`eބ qsԅԤZ~Ǫksy4x-;WQ;{oUHH9Jt呂9h? G2*yD!KCҨ*pB{<#2#0?!Є}z9gtȡ9ͣԌ0\xy=&xD !}2'j5~CIAN}] -i17^ Y2Rv`4.< tmyahzlɩKGKƢaɋeb>ԝViނVA䓛o2ng|Öa/&q#4g;; {*!ec̆nZcVZhpĐ-V MsXh )UƸ<`倽iG{5 6wxM*ccVyȇ]t]Yl~weV.bm.kRTg87IYt4Br A?aiڔPLiߑm! ڟ6kQ{"/gy5)I B~`O|xٷ]o5WRR3uRĂ&s |͢?L@q'm(T_!#' +D9QzB[&'LTI(GK@BqOv`+_km"H)@7F` g gX.hٜeVeyT⬛)l a|\bIcF;"}? F]K5Lv6{14|I X*MV2?-Xm~%6Asb('EK + LN&.rB3Xґf')"m;t$g2%x!|92fTcL(oT's|Tf(o<.^CAo@ʤ ) @ k+_=6٠ _\Տ${Vl̆1φqΊn|8[gx@TѢJ*p4JL"`Q0%(}9Qrc8&Gur!Q 6ty3'VӉW@^E" 'SxP9Kc}aLRkA` !ruaZ<$@v=3`Áxfl9 ja{)+W +Q^ oX@+`Y\%_뢂2 Z'4Qtȁx`}CnЙA !{ˬ6'jG 0؂-gup'!Zl(Yw{0oIx ehGUR/K<4]ȩ!ls\RS|a[%kdi6wsםŻ3{:AAҳ}bGF-f !'q{0Q]Z63\ȡ-ؚgü|*r4"in1B-}ym4X@(HT8ԧ=Zs2c3aGE71$ui~0U֐{['C!`{1Kjnq9n2RC Xvv]5UhU C\E `BY(4LA'nfV5Wl%hp|ܗ~N5.T&Hʶ?|r,yui!a/ ]'.A0 w%)L*wDaqsygAA\or`}zڷgh$ Vo4:-oibv(LUWATq 1)0@ԩ!$k٢%::Nk>j)|RV=>0nCbT3g1JW6r.o%x(0L(?+1cꣶ%E`QnkGͯݔe5dij֣F^݊u*ٯV#}GRӮԗU;A&DR! %gsdi/Ͳx- 3<N ʄLL/"` 'Y[r:\KM0o6k0%#~el!l$yarк,A{}Ii[)Q8z8WzZdPjk9Bs_Ye96q@SR Dwv©!k&knQgފu Ģ2+w8[+lYug&/V=愦N6{ %WL*fhyRLW3V H|{ߏ3(-V0.ٖg|}t3 gamP4kaƵ=Rs~ܽm]폾\e{)x%#dbt{H`@U],: TNvrFU=w]Y΋1&!ُHR,ժŗ'?sF1jO l1i@ G_r @Y'(:_$qٹdI ")Ʈ'fhi :z#7911$PoA_<,fڡ,C[~Z="Y;P`;j_[&kSGO }ai*Wz^R<%=CAuҍRى0w%^L F?<=}Uv8zcRxQ237}Mr) tO'g~qHfc'f O+ȷ3=#,|cW\=Rl7S# ^ο{+F[tc;'Ud{5TbE; ;a7tM KTyr' i;!28V4Jjt6Y}SBY[c;?V`_(9%'|.vSC"ȏ__(c ,%2[uY2d,BGsxGЌMe\jm'(74뒈8ĮZX,m .*Qk/ts#V[UV;HYٟۧj" TeզzdSnzw8gCi1j^Vϐ(xNGnBVQ\Ѓ*15BnY;dY6;aզ,_4_&ڒ|u6F.]{jǷ.z>kNj%k9jW-EW#{b QqEШU~G*r6:z* )fk9$c,;TN S}d<P)'SZ7c9gviX su{kIV3ʶhx( lմQF1қFn!C$zO.i2 (lER{]"U3W(Ks^8( KȪy9k͎W#2Evf֧wX~1ZDQo^"zjyA@-iS8Q=3hٴNZ:%7c[ |xu]—++ hfw%rQV뙚LMV ^:<~|}86^dx3]qeMkӖJÊ[Y,.k[>;}9Q|6+ÌBcl@b/ M_?)J}g'1/Ho / ~>MH%2Y#H2뤡ވp/G/m>ÇJ\M/4/4H_Ԧ,m&ŽjկM/ 6P|MRw;]cºKQZ\WJ~묝Z>=)%~mϡ|P4[*y_ 2f٘fA~eC48s9ݹ*yj̶9$ rW^x8# 1AFn~iu~5i$!>Y{85y~/$[yɏv2rU pu!N{y9I᢫H vJ: b20bPnFWN@&ml@{v'ҹI= Yxٞ w{~ETIڣJ7ȳnZ~uu R"l8 S9%kgujjޒ?*Fqhļ!\[]$ՃXb}ȵ;Uk^g緅ɣ\JK45(&a3_3cq#cϛWDh\cV /Բ[{)h$l[g ^G1! Is p8A $# DSc2~waW7("d1e=XVoLz#5&U<0H byd3]Q{V>g*E.$4D ,m*#}䟡 RjKJj3-ʐMiZPܯEyB)ȫnEUA ]1ɑPm;1n}ؗhN%X*}P*QQt l`Ghk4%x v…b)5`N:9LÌXBeN唱αqFl𯏀3|~(RM;55䝈CxMj!]5}H hXίNӿlvuH0xeX7(D2=N.pB6ǀ &#Bb Us* • hRl iCNC~.\لo}0)HsS|i2Z XqFS,y0o*zy{t2Gmf-*AAņE? |#X?ɇϣD{Nkp(NSЪ֞.vH2UhKDi(؉[ܸ}qmr)22hWӗaOLr2z^V\x"1/g+r 0p%¥r ZɓβMiuT$HDxjWN35Y[XX4%ԏycbaKֳ ^lp3O' t}sK"ey(aKbJ۝~(ʣ\dy ve0l`2$ pXFɎYsTM*J k'4jt_OGoNu4.N.7ܫٷm`(Ғo("DTvFARbq{L;eT N큶Jキ4MZzugCvbk:Ӛm13U<uCCb.CZE ["~nXi!T <qn `?|YA~91 iXTڙB{ y}µDHz.hh&qj]+._h]$EFwN>Ka-'.D<*6|l&q--zVEqN|2ƿ֢NDLwBZ6|nG'xr%YO}P_Z VصlcH <֓HAl&1=#^̃"{0`Ɠba$AI R,O0Xjɵ`gc3!&]ggZPDTRz}sD]>E_ BHI8ןUc>F4/r?XW1J^v~kSͰR~jx-37̊q2)Agp>ΊsaiGFbM{>mEDjGj``e(+}oPޖy0OwՓ<--4E,-d#˖ϐaSc#HL=KaP\ Oܫjɝ ?÷c|x+^c"}8wn C|/ߙ:lĜ GG}b5_<(9]i kK-^:h":,̬L!gŝґٿ͟Mg$S `Sr7gl _U6a%~}-Uˑ,QZ[.:̱/DFal݄}|H@C8֦J%d8:0c)<_5hm1=' H;vRDLqɟ/+"}&jfgӋ{(`I޹! Ll.@$GA*BtiX{c)&oa2#[/ xc?0XJ3lg5`Qc'(&T(d{C@X7wnPwR=B8_Xo C$x[c 6S>$&9qĉ>Ghi ]V+4-c b%UtQQ}WٵZӸjD;%ŝJ < /gAzi B/*gC^F.qqWk'q>t8%V_**+c 2X;F[xe?Rf xP|"@drݶ]=.q1B]# #PcU/ͩ J]N ˖l͑NxȐBԘ[^-l*"!of (k0?jh:w&` b&~!\Ş5(ȡȌڙXR \q!/o1IUc`0b1*Gd$*bЭh.Ѝpc<jTK`_ku>ҴTsx+ś,ϛ*ӱ+D]aVa@A~2v #ג0mV-M_3,]u'7XadQYVSXƶ]qr\6Lϰ bO7cF"|Y8z=3mQ줠LF`q'& q>ʺiL-OU@<+L䎧~^} 6?dD0_~q5 ^3#x"/fC>.ZhB*jz_}[[!s^`Wtș$)Hܣds+@cz%5KҷWb >+t:1+dr>Z[!DBB!)C`4Bai3ױcJ6WGe}Dv+i :\5(r<nY툭XCIK-+@doFtBF? 9Q_WC_F H 0W Qj-.!ڗzT Y :n1@H>(D.Ҩ ~10L c`ҶMZ?yVO'ZJ|X֫H&KgD9dLd{"Gc_)%e2#>-R+\:Ypl=XiO@DK_xaDuH$D̠%D~ԁtr"8N(M\,6\dO/fk?`lQR&ߠ"ۯMʰʁ"D'ee[P}`7FRdzf?BU>%ŀ[. \'c;,ayT,q`[utT㇆.x, _qk:r޸;|qLF4̘DxҘ3gXРdWCD_$H@Yd  c}n@yuG`*THO.$Rg;W`\"UGSgb\yKa-AiF`r(B.N{ ~4PPۘHtYG!?݅9׽cHҒCIh΄0D$կ1Vs)Ⱥ>%'B5c:>4\ RCUOT!"fͬ5lTtH|[1 63mH.c})֟2xSIqDlpd|0Ud$@b*LbzB .Ac ZJqnCaxQ!6yh03;Tga+ekj 2|!cwiG$a&|ru6y b gxO]F&5#!ğ5/p-O`svẊ:)ÉKȽV9Ə׷gee9ݧYs1q3$_gr*Ouܦ/W3rd|?4`0)ε:!l#!7k~SnѤ4K@ |tr Bfu,Y짟N'kWo<Jj}.|Ȋvj+=~ց t.vdd`"{JM3o֋ "9ԡ~揄ڿYaiԥ~҃yiFL$?G^ )w' H3%Rίqfɨ'&_uu"88DG] E,1,7nX@Қs)EO=jX j\[KА`{ore)rO>+W 5N{5bN@ʼ%fGdo 8TI c)b o=QJTx5M'ǛP!3lLF!)Dk1_1r سFQ8|y9.}M!Ο{|3M'r?l98}jH4%øwH[-918P  u(5r="my4q"Pս#)0*dw"o*ft7nAM% dX`m-}So6oK ؑbiHM@Svw^IyZR i:KL r#(^ަ_FXl{= ^%|kfؚA$LRr{yKa9Sx`ѹ/fs_tg)Na6Sڷ⁣|ЏG%O<}!ZԽ6EӾVk12~[d]n`f9/ړMI2pgsPh.N7aTjt 6[ 7 2r:j/m-ι=(O0 ^c:.b2>_n}vpe.rnT8>Xx29B$e9+Yx1?pBDz$ AMWQPyx1뀊D)T!>aA~)=M|ErH(5y,ik _"5t gJliKoyг˽G/pzSsr/T6w#dS,4|@h 6\)+kH؄g33bAnh|{ᨴVc1@.9KUU6.bw5Bs \ HN$WuNb!<8{J*v⊷ F1f:Yj, =T2UD<94k[|sfv:a=ndg_ӂS=wgy㞐5o{p^)Ǐ`tc4H#֞yX7Y` Fv?aapU.t~*_qR0և7cyU f7? ]l NjԲGsDHuQRelE\`~y]0ڸطҧ`euU8LΎ&!V,HH헺V~jLmha 0 t_~M%j5, fqWMS/)]hG&6qU 7_648Z'n5<Spf ]d_ 4f>g{i;uRI ƒ,O%䑻s6Zv>Sޘ}:e)*w~C볡/QKiDA0`; .;Uuy[_$oiFV3<`RP0O( 49#T rfOinHQ#iQMgU4BP*z<1;E2| '8&oxx&֪YI$݊gx :*v1]O*U LBE4Բk5SY8reG FxHQ;^=+QF12Vuw~Ė6\ܧG05* gE)(b8'|=68$iG6m7Im<\@٠F :c8zI()NݞZ1 p@(+yKKǟ.!t'?T#D&mO _KkhDwFWļ ~ʶP;6wS`Q-]DC$gb:{ϚX!i +2^IS!X$槯Xiv[?!G] u~ooB i@.p OrñR}4!قr]aCˆ {/9}{֎46.B6IS ٨S '&vL9} eOP1\tuhꞷ7I"տ I Ԛ0)b&*~sYtXTx+^Tٺ(!&@1O+D ӛԝxSvMJ=S-XjP6 L<VizxZW! onǹX.EV1g'e qs=ɒo*DU-TјJoMd!࿦gW؈+cE܀XCo|~-{wgZ^ov-9\. @N7u@۞w |,6.-u^<8=BH,\dɔݭվTCD\RcxZEOVO7D5$HŊЖ,-JCȆUކ^axl`a.=_X24o_|`?[aZk5mg(LbRcdYXi!_"+Ch}Qt>8_0f$Q:,E KHÛY  3mKjL~%t-(lU}6lzH-f_v*BƤFFslŠBR`?fW )3_B VKkWrb\{Qi-b2?|Q/ YsYҎDlr9({0W>tntb)`vrfoL6bY""tA3/86Փ:Q.%IR~5ޚf;c^xj@N0u <,})~fɠd佨>g]6T~S.sԭ:GcSbP=.ĠP]q%@Tش/It)e xq,@iFȗOw5. i7gh,+gY3)x`"Զ޺"APVes AJrWO4ȱP֒rUY/F$XOPnE1% O6#rl:-7o2$B7Wm&~+,64xtpm72ۿWS*/DÔw7 Oxv/t/L|N|Q1Cε.~>BXb 㤋4 DHh sm {T8yQd|R{P/u'F6spMӰϹP`lXlAfiaG۝ZӽOˆTL܉pGTrǂcm U0 =f0~N/}%U{jg uBH , 0 +g@\9ّt N[eI~QǞzhH3Dc$x,0w$KW n#['KcOcS2甿!j{<޺q8$.-kf@X e&]̈́( XH8>ïCD-Ơv"iImk("ՠvg1D޾"ds XI%`hYH(4FPh\ pIc)b&AL4?1~iϦ/yӂ=gD"SnU??0O Б;dЊQc262(! *n8 oF$V3eAL sI~<Jz?9_6[Y5UgQ=ʼnXSҥ{0< uCfnѫl:Q4 ЛBddk;2ȘS@v[S:ڠmf_[vw:ERsMωY YCHP&}G R9+/)F'ٱ$nd)SWI  qIQ\ 3OF`0m^'ÿ}`:Fp}JȥH@@ā0L JI$[*yY p(_V:>8; KTZ.UKyܰs7jMZf715Iխp`!wL`ih#K F=m~^}/omuzG {D6Vs"BSB^g#{ݑn9z\)OZ}83E;p>ޢ3g!,ݮC{Nj-tm!vNPPCU@Bk*G`-?E@C0(j*lJgz3`qB+mGK/fRҐ|[xVx5S,%dJfmƢ\#xpа:ѐ2N7f,Lm9("włmeFq3N+jO,a̩\%>OJ dq~9;lB M@>G5+cKbS ͠b)VA]K Izk&zdV;&)c盩R&iEd!ftJe|\j\Y;)Gro ^KX,)5 fr96h\?mL^D)3˄Wֈ^[55=*=ac"e/AVk2̛O&x^z@(3tsC اF)t1e+,kWzTⵏ&9q(O&%*Vf2ud^l!|nAis U/M& YP׆GnLVajg#EoJUOju w;Y /W~TXMl$Y-|^ 9^/e!673QZ:h֗hGvJyTNo))A~<} ;DR6|ע`6&#5X1nBdYt4&!Rx[P8=[/j,c&2_&rw-Oɑpӊ0W0+֑ٓ!t½ܗ齫e{7SXAѰ+T9P>APg6a.* D;B%-OS3ct2*+mIaO&sqfJ>h!y걣S81^8 TOؗoLdDXL,6K-vpbɥPLM:6HaL+2뷈xMMNu]p F_!p7xDLUkꙖ_CEdD{7tg]usWxK:o _d! 즶 YZ