sssd-tools-1.13.3-56.el6$>1C]co>2h?Xd   A *HNXbb b hb b b b!|b#fb%P%lb&'6'6-6(-8-94:GDbHbITbXLYT\pb]b^bd2e7f:l<TCsssd-tools1.13.356.el6Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP passwordXc1bm.rdu2.centos.org fCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_640H0KSA }5q"1EQ :bn3] 11m:+}MHOs x?sH cC A큤XXXXXXXXXXXXVpnXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX37400738f8cef2d1783c63c8365dc982441e978114ff575a73f2ec3e1d855268b7d8ed25c10f3f96949c3b06bae485e1a8bd3a9256ffcfd83398fea2d2a4fbf506f7c06b8d4c421d9c8fcd580af633e3aee19682fa86e18f02bafe0010e9370ddd05c09b220c2c09300036dbcd7be67f441693d13442bd8f9cd23abdff722b00d024a636f665f3c205803ab952d6a7d67fc6f9880f2a28fd29366104aadb3b2a074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45e31c78f14e9e5e8916dec1155eed908e41983829beb1b4e67230b61da9b84b6217048e1180f9857e4e4cc360177e8a16323b3caff65cfa88c9855e6dc58081793435563d311ebff2595244bb14d38a3f2e835da62f4acf2d5c1be9a9ec1af8ae51fd6440b604ce140da2805f918d80f4273fc16c0c3912cb52b9049a447b55e1662167d9c67bebf0efe19289cb3855d420538049ebcaec5c773f14f7a4d45f5b98ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90350d84c60491f81ec38582151a779c4e2aee537befbb0bfe275f4af2f4d91a6aca6699600e6c590db54624ae492e7bd5af1db45651ebcb0845e606ee559e903c099c3dd8a113fea8f43eb6155a4354bd4ba2aea406090f3d764f486c3e07556996ab7f4306a908defcace37f1f6c91dc4a2209ba0ef8dd7db7fbce0d4f11aaffa8c15ea2f38ae06aba6778774ec66b34427d8643e9a628e459fca2f53cdd141a70cd03bb230a00adfa378b30947b3c4e4f621421d5598642bf9562af08b264038b2e13af39c3346e820dd25b1cf15cddc65f83e8306b4d14e31d1195d193d3aea0de4f9fadab65b5df315e660634fed1636d3838895735028619c989826cb5cfc92d14b8141c5b61150636295bede5443eef854b35c22858d94d27d2c4cc1809266f7df05620679dee3ef453326967afa37b75389821088071bf478aa26cf13ee8246153513a6490d29df0340aef9b406ecf914d9fd7a8308b0516d609215b4694c32ed1653e72de94bd8799e968a4bbe1b8b2b9b4419c31cc4717c46345219f05981d65f788e6048bc9d1c4c6b217409a3fadc3c5202098a604b69c1049123183ddab8a97d33f0efd00515183d712552a7fb559d420b2382a98bd47a8aeeee7ad17ac5f114eb8c50a94cf87f49ac08f1f6a78c739b1d66a03156b16dacd14df3653c2bd588a3ea18eadb5c1395551ed10740fb86aa2a6e3424550381c92edff47d31c31c18d4e0c2f3420467fa2ff7f54badf57d2e9d03452d0315d4f328bc751516fc4a79bea2e43ff71b134457cfd7ca6f09d9670c757d031ffb545df1350778184cc5c85e2f38cefc1a5fbc5f27546a44f1b906dc11bf7847b6dbfa7347088c3644e8a7bb4fb18fe22400d07409fe8bc6706e9293859f315cc1df71e04a9ef1f4439be013ed636fff2def8917761d7121cb9d135a391457885d341aaf2a349d24a516186ab7287f5a6ab2c03e8afda7442d66c4b6735f7f2b2b644f0901c6555371032147c552448e5bbff22e4dab75d9f0693c61498a6a474cc1da399b24cf6e74b46a9f5b20fbffd2963e906ea123917cfac0a9a145b66952b273068dae0691872ff8b6fc1d5c7eb4a7e96dc9944560779ea8cac92be114f2a615d329b4a010f54b2e1aa82e5fa037daf771988bff39b18e50d73d11e86914487578f0a7d22e14bdde49d0276572df0c93118d7e18851b28e315cd0b690fb3653b48c041c1d18b55521e967929cf5519975d67cc935da4125c3e4031f740ef0691977fa70a7cd8b5fc5c5640e8f39293bf0d0fd2dd002409bb268ee5b7d5c8e9f5a2e4866e6434029b91fbe126e9b533814c2faa0a6eab5b5702367c212a4d67b56ea340dd44345ab427050eac3b66b6369040272b6395539ce39e226e0c922b03d49d6892e97853882c6ba50481d7743d20238c903199c59eadeb3fcefbf87fdedc2ee4ccd8d091076e2949dc5be54449913b808600697856d77d21e8c6b015c713657cce66a0b45917c3984c95ec9dd46b52bbc394c999ee1480a5da334edddaac82b413e6a972b5b871175de92ee547fdf979e6e65996bc3af2f4a47d1389457c87c49d9063684934fa435074f2f345e74b4381acdf58882d46471862ec1f4bb83fbc436f5861d9637216e55a43f3af1f7797aa78e950971e876219bfde4dcdaa55b851b44e3a24f1e6c13aeeb1245750e4a3f529e459b76904c07f2bfe70df8bb00c688dd10766a99d0370dab32750bb1104d0c7ee9490f72aaaa0fd37cafbea446666ab88a65a1350e5bd28bccb7c9652dff2bc19c305118b28ae971fca9a6a1c609bd4ff0118e29c72144475864f3eaf903bbd346374cd618d03aded0b9d85bb22b18ed76d7a520d73a7a98a763f502bc8280d5f025b1ca3d6cd38a1718cc09d1748fc1c2873cefb6307c94a7bdc75d597c98c038251087f2a23619b583a8b546086a0c9f418c4af4c0727e43a693f87c61d7c93860c972436b203a29e6a69f255559306bb17c7f1adafce4335acbd746c86d7eeb69a8f1cd845e74a05226de15ceea5e0bb09516fd684315b32690dcf357948e1648bd97b2a6664bcb857c1e5fc7be27495f3c2e99aa4bdd98a7dc152a75b1135f31dd5ba347cd62cb39bd94bdbcc84c3a6d505dc36e4fc685a81b8b1b79d9807a303bc4a5a9e10c184a1581e77bebc6c6cd32e0a20eae4f4a0e4f4ee90d479a774286ee8dea1851a877114f229cf965f4dd1d49332dc9c066e16edeecbde3014cec0ec6dbc78f271ea0a75012beff5e88701e02fb3e1e4dac8b9420807841bb755e2115c6c6e46b2cdd3c365407be4cfc0d9ba04335d0fd8145b67b045c23d30c8992acd37313ef3a7f7c9b0b703d143f437b5543eba373059805f2e778369398e0af93a55c6c1e962d7a6f476d66d10ff2622f619147e1c39edc58346d17405227e7df1e9f6336c813e618f826ea003f18d714d22e6d3cd717eccc3fc862b25b972d746858157b52105dbf6d37b9b4eb52d2a544e44ce2772184b4746e763ded39ecb4212ae61a05c254b1700fc47890ccaee2d08cb1530610c305cafe9ce2d38267ae622a6b7aa145ef999f128730ee832f3b04f41117e4c0000002c30d2e3b219c4f92c7a3ba309486e1874894b97b9004b2ee16c951aaa1db93c161e54a79d9e5949293b3fb5aca5394007c33971a5ad4b1e0acd537ca6358a3f620ae95b66b058ae3c3ad08e6688a622225d05f16d42013eb4be04c3761a66e93cdf716c743c02f68d39f71441dfdb2686664989e4dc0b629984b2e6aa0cd2008af061a1c3b83a024afe3f6fb073267a63cfec27c8c21fa473980e79371ef2b028e680567692def0429ed9209977bab51786b070bf54f8a69c5ea3aa03efd01f47e44c4d63ebc00dfbde73cb79d56e2d6551404f3f7add230b60c632407d918d3b04644cec57bfcccb0e3b7c5dbb43f8df8167f01ee0e32459dd00c9bad8c021647a6d93c630b21730d9b8d865066d58286fc1ebd25dc5f6119317c9749bb53e25179442acdba94c51e0f07cd3bf74aab44efb6ddb2a9e95cfbd76b4c32854a8c5cbcb7e4b0bac81fd5ff625330e230d3117b78a91c41095fb786fcd6509bad5436f2ea04a06301ceaab2f1490b76e494ab4927e340121a5ac02bbf151ad1fb3ebd42b8f5ec440e2c5a5f00edd5c0efcb19834a87e39d6f3a2a220d64272a18e15d645e576cca2f096d689d03d6898f0afe87ddaca1e905d8c368bb5730f5db2c102b487c47ad0bf8cabba8c91facdd4098f69facf4adf8494ddfb5179a7266accd21f434b602e562d6e11de028ff27abd1bdd4944258d5e246e2c2b056fe6e444ab9e82cfadc4f9b50123f031082ec69b3a844022f9f9b41e8f407d470ab533cd8e2219e5b69d8ecb20c22d514c1e15372e3d1e536a359272218cfa6f9e60ce38eb2539d222c9af9a192a73908ea2cdbf268e9d8fbf457e3eea1a45590ea8f1ad2bee83a70c9ffa0a528bcd61e0eaacb3c85bea64c1c286cdca88c6836a4252c16c48d7a9f2bed2ccdb9d06d4930205b81415331dab055906cae37e1aed485f5673cb60db74eabc239927f99438b7205875343e775d22d65cc198eff590257e709a4921176a33d8c086e1d419acdaa5b60c25afd269427220466f09c759167b9bb3c288d09733d9f372e17df19579ceb4a6852dde577c73c323eab60c92d8a977fdf6e12b1e6e36f9d8cfb1af29b014701d677522bfe6beaaf6739d9f4781c59429b51418e670fd8954e75713bc336838869ce45d31fc9d596cf305654266d0934f3e959c63e179f9ff666b2a79f55a41649897f04fab8e8596269de7f227bada85b84c04bf8214c716b21ed3775ae200rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-56.el6.src.rpmsssd-toolssssd-tools(x86-64)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0()(64bit)libcollection.so.4()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.6)(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.0()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.12)(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-56.el61.13.3-56.el61.13.3-56.el64.6.0-14.0-13.0.4-15.2-14.8.0X6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-56.el61.13.3-56.el6 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnu?7zXZ !PH6F]"k%n0}:w{{.E+Ǯ(vT*l’ȏ«\sE+P-3ηUp Tri0~T1maǢg|ahVxdDk3 9|˔9:$th[eso~?^ A{fKeDbz4脨1%QՆ\ӣEli`*~OrᶉYMZ=thVHM hD1i$(4TLx6ْMSpvw b1ԅުُ_0Cwe`3WW ŋGRx>~a DRrp."~tIIEQy*!P~\Wc')n"6R%4R}ITE !+f!߆!s_iPH>ڮ,`rMnlHQNoip3xvg Ig]/5gJK7=ùNC'.!uSl'G u9x4Tt (=~ssX +eRgkI=k1ǹ)t/ s]v,ڢog3og2ցym5Iz? UdkYGQPӀF% }qYtCO38 \{EA9A?18--}Fch'Gf8μ+1b~ĕhخ}D‘p 7_gڒ`WηF}`5\"XMs!,5Аp'tE0`@n}vJ[T>{hbyG:-iT8^EtR.g-p/<ZCK~lt(6hbp)_E,=1-}7.XUk`t1z\ep7~V52|1wO w^6c=kyC"lTԭ-|3CvcMa lپxrjKtl^[ob8r*v4RـJ'?Ec<(:aO_P٬yhw##谇㕰 # cC'Sp9AZaËA=c8iA=/`W{:ޅ)v V }9|mhp/\{lY:sW󛞄(ebT,۾q|SA驋QX&Z{|:sE8OOfޓ"ZpSrD.]Bꣷg'j~[jkUN7 W)NR-e F6+ J3T2 +ۚ(ʶ !WVy4[uM{-b8䖵"q5Ndͯʩ#L'!`pB8I9C`-gS aj 󒦅QiTK[`r?-n93q{k.L{Ź:ң=r6r5>.eg T[Fб1@2ijGd%o+QI:&FTZ৘|Rz'4c*C{P<2sJ[78(@:b")Ќdo^<]yVb4J@Gn]C nEfv]ޓ;qC'hj8ӚɩLT>Q/VT}~ϙ"=BL:('eB=+Ҁ꓎Ń !N6n*Qu,*at7~%4C qs9@VlϢݣbY_٬$) \,)TY5mgf]j ivW\ձ5s>q> V/MC]x0[ 45!&=LG.U+mhƞZLJ+NJo`ō@ kM3$@ƂfCV.aFjϩ8qb#ٲi > -h(_iI?ފ/lFc#gh' Q %{~XҍQ];sċP2җg~G fe7Q ݫD֚V2enF+EA#'xG(\Ϟ-JjY}Yf>C-]FՊfvzkG9J(Qa 8Pӓ4WKŖ|;a>!KOrj-·juJ$yd:n =}Sy%`^ zEYu?㱪#HTd6RبLd틀y-pAy 8ڦ?v?"2pD?@ "qmfBUXCvLO:bEՍ34OZ?5N)Teƭ&r* .ӂ_0]f I)F&MB\9RC@:,AH.vJ&-dz Oo A+b&1BaJ2w~:>+=,Y"ԓ GvPdI3 .pj =$yUoQjHMB=\oqUhvȀ )]`$FQh׹\E2D5V ғ;S*c)xJNƝQAy#$ܞ#S;!ƗhxEe:^̈ blnuRQ&uaCdIXC[,d-w%~^ MFZ&7"۰)}N?ևAa3ʔsSVo;hQhfߩKL\dY5]9@1QkcPZm5B%F.w ~[H$E{T;6i .R*}\2Rƌ_j)C"2 2&_q'!TB RDcwLHGQcɼ}Q0Σ@N̦50h̀h |6FD[+:[Xߐ ;< #AJ71=Dr}#6j>{q}VvB띿ٮ(ɳ31ڱsF0`E^֬jrQEWԺ;ʜ1c`+3!W%RODŦ_sh<)II <)4n46"1M-i\$pR9I) ^^6_fNKB /&3ϴ*!w3X%:%a).LcO)⫱!pL%Р 9ʖ||Q rd @ lF0Y+/׊T*Z?%}vr_f&IX#BrĽ.32tDd稁mx%,hgn?~ՐsD,ҟ*z$7Ǥmw/XW䫆Q,kHIĒNlʬy׼^z/`Y?k;kJ 8'%iߩϔ`aŜF?A]vR>ZF6A x]$ikx)&pWCґB+k۱9nc&95!Ȼ҈tѧ]3/\0vpsШȞF[NH;pbɽkCA}i_\B nazI3Θ;JH|h[! tBx-K,p$DV!S-W){J:mGA-N#۸MR iΕlӹͯ/40~:77a74qq,"Vjm4>ݡq xRF3Zpk6Ehz=Y\zkz`7n?g~C6ǩr fҋ (4\1G)4D" ,P9NZkc歺-{]B,έ˅xV 1ŏ۝"(@kK5y{h T܋.4yrzD6`[Wń!P|f0jMm̡p2u?FFҳ( 6- |-%ϪraY\t$Ϊ`;cϘkAE҄oPȹw0bM ܻpZBzsZsX@Ң݄bzܸ|}}Ϊ E)Wmr(gToҦٍdCU2A Ѕr[[n$! Jz#,3-/f}q\ha:EhVl.L'b.2t%7_mPSY-bhp}쒫YGP,ݯ^A7zkrF}e.EcI1Q>?uDp;Σg M'9-<9 'c^ *%+G{@`rK/TXͥ& -x]ȺGl[zM[\\kM5 x khjm M ThҸ ;hzϋZ%^^oү+KZ?LKDknHꦭǀ1pA:,'&)-"i55p EƅW G)H^izmH <-\5 .UTȡ\>۫ Q}4jZI@B;zbz8m'g%(B?KQ1*:a|iIF[$<dp桅=!uѼg62<%Zo-әҘt ]K:=YrV[C \}zfH$@0/1Eݐ ]%{UH-ꃢtqOd`8D7?wq33՟?o[h2Ђ7kpN)by٫"gSX#Z#qU~ư%HvWX5xtו:c=&p/"\nAѤ9b z2>ڊ2U@JC] `sRPƘE= 77n40|%E-C EI6JQadݡUqUy&AoKn" &{4~4),4f-jsJ /|ZЃޱO<7k=hxKI2m[x‰LU,@"Det"UM VTґ Scu{beRH??@aݠi(R>=+ Rw5Й3)BNdN91'fRm} =_/aFK4h)&*=v%xpշ'HeI&UO2* IԻ s1csր)wt;8yO; >:Q'Ԗth:{2BI{Z[v;|"$+F>Bsw1 k SAz'7tOk?WƮwRxEsM`Y Bi "X:>XRҁ̯JFaXL+BΧS9a>3B~d=ٝm3`tt('$'NE;TT ̝DDyڡYP?'\q]pFy˻F*^0Sb MwHIq+`|Ϭ>~wHYUmarlv콈oXx%-vŠJOI <o7Y7\+Qg!lΛz/>@ |Z!FmYԛkUaMWуw"&QmE*ks.$Wd;4<%K:uCCwH:viB O q2l9X *$(9 /Ǡ;VuםRLeF<9+jgˤ𽗶w=KѮ?8rU4޳5]2!\̓fX[Ԍ#Nih-T05J1:a,0qہyz,"ݥAyLRW7{ZWӭ|)]*$6EU ˸r_sw=YaFZC '4|;p_܀Хf`3/q+GHh qyNS񛭅 T3. 6״ē7[]+7,ֿj]d~SE-ʊL#:qߺ(٢9<\]9o̤u@!ʎ|Tp+#j<ڙ@#0YQOfwHsxc"RTFf߫UyEycPO2nr9vSo m" c+u|ǀEJaZ`bт2.{;cwᣎ g-~YV#IC*UJɖ'@l}2LB[yJhC_Z%g  {m+L6g/Iq|-ktQv7d9 %A91^~Q;#gH"0S ]f`?}psTbs}Ƕ1)Y>ʅ"2&kUVo3* ?/H/noQ1 8o|r (?X /=%%TLklӅ規#q3gn$[Ɓ6b?-N#F+4/[A#c7c`&\8?Yiu;㈬pht4Î"ѩ IsU@|HfkU*70W1ts=>p*.ڥYFk| SkXp6m೶:Ǒ"`@#8Rf(mM`fׇ/1a#P7%?Q ژMQړ'^8pzqB3"Ta0տ˜ ,ElT?^%ݟ<شW'oUv~A%L0 N33LGd ïM`.t1ϐB)7.u_X^ͱ |hI"r~+cqgU&<7A%;|A'#QJ:׹[;v~P:#WP.eA7 OdOG35e4L|Ιq&:q֢wyB_+аVgzqsWz |VA9(L)tc܅ /# /;Ec}?ogu"XBfcYy;߬I_Dm ;-wiZl Z}Vt%%j''AȖ =9ѶQl3;`~a-81! RqA6!ڲ2[ +4RE JT>- 6B\,m&8T?5b0:MRH°}LQsxhP 삑7"0'p0s(W"{CUܺ,u 4"~FBg D,!~{/Rv Mf813%0ŕ-[a[P҄ӡF$]鴪yOgI\#%v0zvVNWcgkq2 ߕԷ7^f _a3S&rg @Ԑ.xl M=o{ )u$۬LOfC0zGXj)R#ěB-Y_8ZA$C0leBs+/ΪhDn*!B-G0]?1AX<+s}:>((N )n8$t d;fQM$ŗd W Ɂwy0=]Ng#⣞ǩbdkc.[kiC:b)?G6ώIw4>}fyL ƪs#|@ rk TMSISӊ|>iR{xCd0MFZ"%AxwuLc&xpxӓ!$.>U=bZ"*=He}ގĠ Fb_q ֳc>Ur6ot9 04.ɠoeht0֘UW#l,4wQ\'E95 8'$̤̩q۞%Q֙4ؑYD6/*Ӟ%!ȉȮfnyܬkzeO UE(zzu:Hm790`r%pD>Ȳ$Nya!/>2, d Ǭ2YQ.5M_*t707O}@h#5iwk 9 ˟ wqߘ" B8)5x(IZoʟ8$.kC_EƷCl;K>KQhaզibg(/W q2&809 z'de5NE3?a5ha>Æ@y 8/EP[%>Y!ng6ڰ@ Xp+WxuaQN'74[4mt Tc]"a+/{@VI(-w&0S ~>!#Y&bF5؛O Ɯ, E#Vb3qfː" 5J.}R(Gⷞf:A 4 ϛp1Tx%[' :r5iv/'W$ZΈs y0,<W|tdƔPjhN>!?h(Man%G\鼧'P"\1p]<[Q)j@ p VDKHܛe`ULB}l6s.q].Eɞ+`5Ӗ5*OHXkh"/<ѓ!T/6ږ}- *Cmss S{쌑x,rl>蝟wfe׿J55h\юgcUCk@eש\iEXL}G P=؏2lVufҘC݌PG?`4qú_DZɺc!ܔT"C#5m,VsKgǿwzoc$-Tg>fߩ.oa*(v61ZNξk6'vw'aKUaaRmG%AyU՛O֏c;-eM,90ĻsdÇnpqV6>!d[Xߌh ]m$0e+8"Hupu\:*49+kr7&yb1x`g0w  wC젳U Q}sfTֺVϠQyBI97\?C8TqdmR49.NMQ#t჏ۿS$̈|t9^uf'Y\ydx1;<~=J','LNrP^\:ta쬢'8_Ɋ F^~t,HAC4nH_>?izfAprIdOxc-+Nf^2B'ݙ6cdSX`3M?)|}O+WaAbubE7mI4O]L ]Oc[,?\ogɑ(ϴ}6k_<a&ׂϨA$j HrK@&P#4ϥ$NH<sI4 S2zx:ǘ0dKݗ>ŋZQ'sm [}3=/-dNMS[jFZ| IǸVbFh]THDJXH2o$vFIѠ(|ɨ9YT axG\SL] k\0R\e?A\$i/o ],%t WFn1 ԑœV&6(c1|MMno³LiuvQ.:B3y70v#{ѲaSD;^wMK@p`\#2˳UZ'⤌ۺ1)". SIU Ȭק6ZlkYq*\< 0s߬!}X•tI0>`dt> Fhn;Nggɹ| ʸeNUZ*Ϥ 4V؜_{ 7 oyE/ѩtNG}q`v{r0>Z6a8zZg%@lxVk&,3]/^+fԜ%AsJBN {iY2u6$5|n!D +e'; UR RxXVՎ5MD:# Js/<R3-jmԊ%p /ҏȽycn^B1fx<c`en\S Dl`0^q_a5iq߱!i&A"rP7Lƀ4Dd V̮vʹ,(P޷x⺎*.ixH&%qRZBbtNdS`Q{Xz5YOVKIއE[aT ,]8gdg80ۗ'TzEO_81aqayo hd_;~ϧsHI#R i253gwLꎮU\p{u+"1k )6ۂ@`EQ®W.\̄# ZH#0GP?@6xOȓgiGZ(|>TޗWu#&4&TiS?7|>bak|FD-A볞2T+kSZqc~G*U5MuՋ;Y9Xm>qMHՓ_>SZVZMI3sIlî)$>jAU7$MZ2eA3ء"b[`tq$/Tqc&oS>opK%O`K;wmy0$Жj_pƬ%ӳF?)8XH)1S!a[;azƌ뎂bs5tiGH@R9$*$))m”fƾa&En(dsyrᏃجW[shYP^g+$9t\k^4 Oɕ$I5T7Æ xe*0+xsDg=ZH*^EpOQv|> U}Yw2-Mb~eTcQ3E ;-ĵLoe1s> %*Ԏ:n$}< _VDLG \Kb攓Q3iz)ܐizkS(p9T|U HadP$E QH2i_ï(\&(5>[D 'ċG e13T.7>a]9z=ע)_1 ;??3{S]Ż!r%ybrP0ucXl\Wdzx?Cہ AjRՁͳI4AQ8JHH Ƈ֒H$D0{ڗEld4YDHKM _:Z ̙.C7mPQMM$`]4%)7GΌe[/aew/ދqp}wrj"iIrVOڸCLM_79jV/l- &P+4MʋpgŪaurұ3G=-I_UXVWj weVq˫?â|Usf:oyg[2囁w %.'o"pa*舣*4+3BJ:e<2<_/_$dKSK17 _J)Q9X('^: wzb#1/s$hlβG ~yJ.Ns20*g6OЊ:~ׇ}pKwo0Q~tb{,sYi8zUNSIv=O*p!?Y "n",HK~57_*#!3gź#@HMD%@D3u8C-ޟDkdq6k] -\eѷM|f cFj2}oaGNbt 4Lh;bvS}x^ڛJϹx+R W ЈԞzxdPލUJ>2WVMsp`,B7zT /Qxt&:ul >BVX3(6zW\jgdOI kT!hx[.`n=p&` =@I/DeVwW:Ax^fȅ'8zfZp!).i3=8H°}@8&\6bFTL΢& z6Wa ؁~=n|:VZ!\0Ƹ0PTFHwQcyr} p-y6U}FKc=l'v+]D3}y64'LJ5(ahS T'6!4FP bȒ>uDjcM;O-?7_ITRDbZ^vP )KCtis8osDH Ngqp^!^տȴ3эx "@\,SէWK? ѯvKnV0 cR6в6EqvSš@mbEyz2")\G\@[ի_2`)6) TQOo$F50 ށGc$ɩjrn˾'(6[D~pGI{̣yR-j-S?U' n.% vs–y 0rݬ 2 ,K&t`-B$Islώ`|σ x>&dzmoB/0$6"DhMLdpU[\{dDRLcXkTLDz`Cs0:_bbFnJ~"M]6uUM?(aT'ɥ1 /f -1ui@Eޥau5ux*JNC`-k[Tj.1sܡ?72R^˷)@J`uO/ u ؅H B![oWsEͱP5d<Οzzo(NJ !q@S 6:=|QM*rGV$nG2v;hm i8WPNàcװGRXg-.KᙃR :"K xY0}tSuBۺ`7>ٜ_b{N$m7h 'f'VN\+r1TE&)(+CH j]&LBVHY(gɶH1!" Nfly?z3ۣ~UG?5d0zaX~,OSjw7B2-ZxgFmez/Wt(-Mv0HgG '}"TJK 8,62qukv$ &L&y.&.& FUa-g\*ɟHw鶮Oa7EjR %"q(ZhivQ CzlwlV޵gr +zcTLtw+蘲M.V Uģ"(#"^1#;Հ\'?'LkV@)mhQ޻(oCͨl!T/Ibe(|ygߑ>tmjzvJ]3+oڮiM2P};lVŕet MG2IB)6?eA+Jx&kޣRVRUl2z_ߋ`xw hIJ NWAQ(q4%?N!+QKd{ۛ7ޤI=Gg#R՝R\!E.y* ]Tt@x_/ D]V_q,=Rzyxc>eؖgmY-_q-EDoJamM> $K ol;-ӥM}Jxҙ';C~jt¬7m Q#=-ch(wJt6 xf3ElAdEDQ݄w6PF53ݚD)rZ9td8؀(¢K~b +=GăɃf&o2;Hg`WܡΓ\Z yĝߏ!*p~\w)>⃴B!S(K`|ȫ 3[pIXF ;6j(d4)pes,tko0 $]de=|sWyu!`7o- SSdXw`m wH^|*t&ѣcI lz^- X\}0CLZwDws+IR|hmmYD hثxk) Wl¬(X)ߔ NiE#^Ů0_f- 嵡| S)T{lDk\Un ̙ACpAw4xj#gTaz9}-gd0cװܖӐtp.pSl%~ tT,(R[FEVu>&FK,o~|*Vǂ~A}V:R&&$zFU*! 1]'E $UI9a<{-J&NJ`R T9O0S[!L~?"%eG(gCxѡW\n U9LHA/ SV YXɎ ȆZ{e".3&,/} xnA~^_r?4sC͛*Sf?VWa6}Kl-`QѪf@:C$EЎMnu]C1AV ^)w$D&pT\JrEۊM'a4~ZO1fpffٕ2uv;R}/L|%:Hm5$Y鲛Im3hԮZe7~2F_ EDU['ԩ!t_Z}b݆!YR\Q}g2?!~""_D/v&AqLABҹ$ZUxژr`YrbP/q yetb8[BXw6Bit̶=>p)k*mq,ݵ}eH]) XTZomɎyIxo -Hp-8Y;Kbå.b],F's{Wo 1NGG iܭTǼc?S SNy0.ï 2u.dzMY%zMm+vH9Kw7dϠa/+7|`/7e4;pn~v-Ðu-t.@'ZQ8HՐNp+ :s& u?;Wy2IN0FKWQL؅ #+G UagҔO0Rм5䧛AZ.YNw E_U9tYV0C3W6Z<]=jtHEpM{?[ 1ŏ4T, Tch4''4\ߒd j݂7 7| S:X ] e׉5lg0l '}ψ5ߕ]dPZH<ߏ'P3^ngd=LR]=2W NE̵ ;/GڽMb#P?s^S;!^dLs9&oO!L 6jbQn+ЉXkSBuA6F)Gp"6:lJa%q`Mer(l Ux gs5*1@hdmM`\ruڐqRxwa\V/CKU)Q M2̚a1s:.ȹYǵ%A$1:%̞ Z$GOqa{n礂!m׺~EekƜCV1&ud5y*df<@IVQL.—xx蛉R׆v?!׊?3.Ul_{YD=?q:Veeao݀5ģtE㢋y3/x{j@ W$!ߊAp>a_d=^v1s8N"&gu (;F.shpd"y(-`lQ `L3Ћ )K)\pgkvK 6?er9~Į&Z9i >}MfQ "n7#Cx*nHvy.񏌉ubzMA1"InMPz?{X4A!"}P h٨s, ,w嬓ANo~}mGD#a'Ş耜cZy: ʭ h*J3>_Ll9ݵ]>JD3ܦ w~0*%"ꃾw7<00{߬g ܝ>?FX%Ad<1|rM2Z*kV4~uYxZ8V2VI%zS;6Y.[PIk$҈ mr0Go1:_@U 7 Lb=[Ddc`>+!ׂgE*_' ,O JϠ\pi 28}c~xLJ"cԦڏucU(`DۇY6ʋޅ(;dr׀f)7V'\8|06X8[j(U!,[m6D^}ʂޓH8:";WJ o]ad*6B7 fML읅p/˗!: ao_Z)i!1:i1:b|V>hۘ4IXnFA +Ip JS\ƥ [%KH8/ X>VBK1V/i m?ih0)uW1ƒ'8-HV~dxdf6hly6' 0֡ 0)vU&XVJ:2)4d_Kb"~==)CGOS9h9gOw=^"v3Yؐi64r>n.XđHI2bGZX]B+"xp0uunR!E#pG9SlOOp xHj'iL}讌H߻Oi_*$CfvEQK0KZ9WOb7ç`J+Vд/Zz`{)ȢjS0;_ҚC~>uB~) cYKdzWc"'.bMOO‡\ k8)ux2 ƒ7Rm?!8`e0#Eٕ7|񻱨go`$E(x}Mfhxfpz.1 =Gꦷ`t7?p3.WgƎpgFh<sI7c9qVeK1c+6 UFrR NM.}p,/t [ ^s*Ԁ،SsrV8JhQ8&RjH&؜J&RJ:$既o3B4<_qy-#`wZ&cK2/+u6fjX<i}/h۬3aIasFfCh;vD|{V9 W$e8^^uiu3k\ rRB m&U##FMaqrg8N|&#&^tIj:c!rO> w.W)_6FdGM06w"̸x@P_Vy2dȕls+g&0*&OBA!#T,!W׾.:bԉt<+ᓒD%nmy^Y'L>j"#'rpDE OV@'gM:Y6¿__ |g e=ɪc$,7S&v)u㣘&v5Xp}n`mJU&z90.rfw{")Կ mfR.*:M&T{\x}@БAbF]ѣX$ '@_>8{5r6sF5)8potN 6WJ+ QJ|1/_ SE-3pZtPˈǝnbjoysW"!Y{v--2a{X;1 ?}wZE% #Sz=+Xڃ`O[ tɑ)]{U8?|Z~\;V9&<i3t,OWW n?osՒQ϶_~? }MiaWbiB7V9qc Y{ HXIJ۟|E F!ôXN9B%{ofCzjsl9ڼ<x''P; [6{4_ʛSE.)3AeW1 찫@(0CHcug=?~PD!"dj!9jw6i3, >%/g>h#dv`4OiZ;US!<w',KŔe S Fmp*lRN㬩Ƭb,B/vGMKɿxo|jsi~´Ns]6;¿t@d _q"xaҚ ,!`b7&Ys▂2mt' A[J_Fys*>c!๽]zH^\:/*&DIzcsq AWHٻ_2R "v_@v qH<[>}$(q/a'b8FSd|M*~L1LLy-PGha7[4YzݶJ ƀ2Xe S8x/ZF3^1}]Mj"7$V u>G}7s0oj7UV5֓Vpns4+?'coo2Q>}ew,m4m=ujg .$Q)XGs?x.#W_{my؋!(Й&ŭ`}܌/Wz=I=^ѰW0BeVET&~T{s@&q||7  p0Uv.Q'XH*Fc4ܙ7U/ih=Y!(qKxǩ ;+E9kjYi_HNDrިZ?Am#5*eZ߰G* "O(_O/ 9su;r$ǟcMi15$}e a]«%6)ɐ-6qkg[Em{0A>-BH@L`<' ñMz^e/Z8gՌA?^I*A {fMvw’7۫RhF6}LYcDnי־,wG͗7ƭiqLDA\M zt ?"yxe#3)iW,6ş9F&X^tGF`CE>(]!ASPamON'ZlaՖ{0m}K:N^ /P9a9t; Yx Ǘ/`Wڇbb>X^jhU/-c\[owRސLy dG:+Er|f <'v{Ny93hg}{"pVc g30ྙX$Cu` J@e*#`Nq;M~rk֬ӇS kw/"cI5q/Bh,wQۚSGjD+j v;g#M ip¬^{,OF4$x f [80:ls y)D{&>Y##3mZtÿ?E%P~j8<L*{L bf˸#]*a_ݬn>sDu50 M4#j\" nېIz[~Tj1@~@oT ثYHl2wΐD)SGE> wT w_İW\\3?j|u~q9VFқ #fB-lph?bR,\b̾}{X'3yF !}Z]^)< k>ސ@i'L>XS 6G >/NI9xCoCLz6ㆼA]) _he4u,Yx`k Lن&(wp'BSAƎ)YGL>3gP100adr肄:x {e&lc~bftU*ǂ*5)?ڻ^&[әj@4ejЪ4Qfz plWK|yKQ{l̄yW^н8*M>EԆ^6ԓy(:m_doͺ:EZWT{{ſzXL_ji&1 giyv҆L*P0|  \*6 bQ%7 #f P r8$4Q:ɤx)Ƚ r=Wm MӑU͠F6Ouĥy¬}#|q}B'hg㸰IZ3*7'Ei':ѲdA;0 '7RZ]Vڮ1a{0z!Vɲ H6@j0@Ů('yv& F@|HQPDyԅk~hUeٜ:$YMpL-ӝ;8Óɶ*-^0wl fdH%;z(5$d} co-Uށٹ q_oG bn>:tJTYIdP-`lM0=6',ݻE|X-vG͸)=GZEs%& P-;XW.9.'˗mΉ7-j0,[v#KjtvX#.w%Ekla asn\L~YEOմtkȐbsXSTMD|vT}B]y =kUndV ĕX(y]d>]'YI0Xh#O'⅀;Zn:hJδYtO{>V]=ZC#.xy M|O(\tFrF#&޻.߮eN `KJ˄]23X_԰d=qAz‡ܺdY97IRbY6I ̡'Z;Q' O^N=h2˦:n0 kCV7~|'g=nS"aɬ)~k!}n4XX聨*mפ:f\RP|uY.m1{,KH;|(ע%&ºUos!˂ cKA`u{a^ T%@sEވIUǡ[/uM~Gu5i'T.jbG?詍H4-ݺ\*7t]¿/JFEpfb¶/wʮ.U"zAd.p Ou=VQ:C1Onht36I]5iB\L`l Z|6nsB/ܿ畷k+9s(ˏƒnjdrߋX<)ċo(J-9ARؕuȩsۥ)K(6!@ \8kз1k'lK?IE0BUgnWIvg/tHVPV_!N"хgہ3Hc\lSh1s7Jo!edII O(q^l*]xox3DžQ=5?DmK1шzrH@',p.6Rx9pA?+%|0{624qMB=ᩔE6RQm^5{@jZ}s EgGn;xD$gAt<'E~: r)|B'Gez۹sPɶ,+K-77j2q.V"'8Z Ng߉ ;CtM vHC'(0P>_<|;ܯ+H  ‹nFF_ބܽ(ۻ3"Ü oϥ; "7S"W`s.5Ap8b"(3fCy`l+csve$%ﳍQ@n{'(>JPxƵ)k`r4`(ڈ0 ԧJMP<6]w@uiY)帥(Q2 }L'$ BqoQ淅.QWep;9_u/B4ޚ~|uj'+V7ױ-}!NLθ^nd(ׇѕ0BLw-ORP⬈qy|y4*R+< ﵠCdGYGA3gr#&1NU49xE\$YHv 1PÙ`uYWnG-&N%9*BٝD?L.}o]*OD[Uw2BSkg&-Rz@?mUו>1:0=kE#{^Q`Jyǡ)Z meF؀sp՟YDKJa1"5R}{ 7C2I@JU DX kъL78℃B3L?)匊?J9pm2U GF4 Tp@)RGcJ# A0dn`mGN]0/Ϣ1rH@rٽLO\"ɖ}vRl VL+*Y"h,7B";BMb⽕;kCԇFA7Y kYˁZʗ [4AypesSEp$Mk%?s1_htЈϮO7X|_-xTL[&DAvkr w"B,n3 " tJ3c&I~ 0A5%&Ƶ?_GL%2OޙM ~ᮝm(e]=T H=|ƒnD`֐sdFwu_Eneu jz!;~C>K phbY`Mi ڦ1<$NU8taE3pOQNt'ZJK=kyUVȓ\Ej?H BOɝH}c>C!Yq U6;33(_'{^\76򩯉?b׹T3xS1I]Xn$dL,Wq)c݈< }.Ưs9l/ٛGڴYLgUYEҧ/@El44 9$,E 1ˌ~k-Blcr8DYv(+aīud;_D 6*aKhQ4L4xJ-P$flEn=L:9[20◹j&C4d;9T^e14|%Si748|+3M Wu v6FaʬicDY,A_s)Z{}6PZ/wS _&1Qd>"΢,>z"e!VЉ=E#胷zf"* sɱ^x[w-srq Vx*eӉ(Q-SORNwYsT:޵x؎C~V_WZFh7ǽHpK0IRt^5n&O<4;DGt}aYyt)BGt؉2hR埉Exg瀯8^(p;3NFO3EJE |kx[Y JQkX{﷮p1_ Po 6~XW3j `bm&*qz*wA;1PY{n( 4s5gUOzZXWca 4ZQ *܏m<6rN-!aߦb|<є5徜}^D6m4aLa9 >96?S&W9QÇ }B0eC}9 Tݳ}4ne1{ 73g -q\^ )+e0o9בjnJ%1x9~wʡ/{/0XHKG~ Y ܲyV3}}t孮?-q.JJ|WYv;֑X-`%; g]WUFG<V!LFZ5kia'i捇?e#j0,3U*LC([~fp܆91ñ#Oa5:&G̹/h^S"P'q^b@ˤb/(yZO^Vr2bScD69pk "j34&򾟊ň̛ZOMBGLڼ]NmWIe 89f^l=Y(h#ȜN>{_U&*/[z%(_,Դ&ݟe&~u1e'`J5\C}h̳8ԃ'8E{^Bxt1\>`wtU{h}TfqhhGՋ:3NcpP^gfQ\5iE H|+-x(EX"+VQ?yJ^LRs/uŋDיkw_WP`D2I0i]pd h5IYZ=qv0tXS|:.m3)I|e(0p BU)Zمl6m]ŕe&8-1V~4(35l`rm,}q/ҞGయK!>w5 w;R?u{(rr24IA쐂 ̲Ģ+UJÛZ a`0QKR?^:1[ݕ,ˈkjCcEVo ]G86ayeS1|p8'7ä;%]|WM ]jFQbwG 9{IYwFݑi^>qPϋ1|{J혟o6F4:Rm6.E3txٷav 8eZdԃ_Kg ua=B 4F ţޗ =~xRFSƔLZkdttOy4!ґTkh5a9#{y`a`#e3`y<=aS $IfE}.91d.T6?6i.`Yrէ%קقdo Ep, qKAb΁tuA INZK Eu'S m뭱d&Rf $Q]*jGՆw_B`fNI8vL3#h2KpOP4Hc^ 1Ule yҁeV9k,e-` ~BX\3:&5%p<ALaJ ىRDxLzTB$*j|[u@`,H( g ;1A{[$8_AsTmzȼvAc6 f_1+kuF @Z_s6f W%6qnJQE~s[!V-ux(Ki1b3]|g]CqlZ) 1@ʲp@o?::)~j ?{v|;AZZVkWiտX<⫑Bu6.]yKaL՟<|_="fQdlyB+lö# 2<$T,NSV3}֡]"朾ʹNH;[ka>IY.(p!Ӝ7k.K\SbCj\Q]9)#@B1 2֑^k}cr`~NtXp=f`wFbGƓrBƲ<-OyT!qvS|JΛS!e䤿`J\ *3אxTl}eaTSzK=0yMdQL^D= q6",l$?~ky33۳t|q!Vb2tl[h5Jď~!Z%2qJTzX6Klx}kQ/$&u5\&WeIp(ӢjS[尛SR: n*xuE^* $cS܇ѩVH-_ ϖE!WHk=Xuk˪7$a#-]B]Y`~?޳7 !--cKcTa˱F]ܘV]!/QQ_#:/Ө}:|=JN4d+7am$Tp="pMSu[~D43C-Wn1V|e$@xBsv61sHO"4cjQ?ї`>:Z5 "_;}FY*,!=]1k{rp 짛{/L㣃}5oFUYwgo>b%:?9x9i2Ҳu^CYƲO$>'!d~9A)lt6T&``A3@ ڼ?Izݰ4ָ r$ 8H2[ņC\Zc\?}/ FyR0O#Zh6:  tD5 Zw,~gV̔d4T'+>ğsdoe_U>aOg(9]nL}##`^ 9KPXz&E:s%^zNכ߄PcЫ(|[{G|jtA/왔e}؎6}Y[_-p2LJn_(# &-0tL7] IқVu|oW,D nfԗ!s)>ι K`q,l۴fF5Xa8ӉuŌl5*uKH^ (p7T XU)#1O.JÐp `Ʌ^DO 3dz*%13Q2`RzF9~*`WY߷X6!B~GPN68VY7a)ҡ>'(yP #L|FozZ^7@K('RuA[ơ-)]&$StFƋMZ >EXn3I\җ^~#}:k w5O]BdT6u epn'*KR:h<挓f{cd%7:AyōW\"סJ@1{4v#u})mi;6ekfF`+Ê3oM#\!O*Ȑq&OtT]!c=B4:Yde45 1lImBI:8䞖-?zqs?# Fƻ  A\P/Bx?\d:'ac҃:XVDaCFA֨P8 V:ˊ+Ztd#P׵WnT 68١,)LC+FjN+MR[;۫jK:_i'YE ҩ)Yݦs z};ׂـ'NnfɋK@'І䄐ќL9}pj +kW.${&7"&\_=*çL;0H#D_T|C!:)}0joR%V09 Bƥ׼ QZIr>d&%*AXu5BuiU{j ~*3BϠLc+HrۢDP63[h bxMe0xs zE^o MDH'5H"ƒMQYH km?^qϯh#kH58Y.Rt>3SFV gg͞tB xiw^BBF#9ZƭϹ/K@SaZACAR}J ȩMP'= y(t R`I*k3y zf`B>G^HB3=9qLԮkf:H@YJa"1:ӷ+7`4sXQ`"= L\)=Q5x*)S{gǴU(ta\B(1dB3*}7Smj&.}@C_X]cPTӄlzH6SQQQ4 x0:A-#}J+t1>\`J靉3`e5xYHob_̺ȱJBh 7JhLǻ;F|T hcҌw,A5 ] FX#Wz)rTީ"ڬZ=WahELYQd_:+IAC(sr0`u&&8þ@vF:c}`ԑd|M}IJf")fYK^v-SK> Z3`cYi*y`ׇC0ъb_\Y9q|~1VB֣ŖjGJ;3W#qsU)1sy6]>?R+ʙ6\[Ms"A͐q+3jdfbT=,RyTxOhEVh16ڑv~~::;qW>3\OyTKמ[1M8+?F%{U4# Ԥ#Rl0! ^[P$b:BqDHrb@d]uH1%,q6+̚-Qwvy} "ֿČWgƸwQF%[ %rP=I D7=g^kMK49Mǚ'yDжJRnc) &,ɀ2'T(͊jmKՂaW=I仪EhN /\ ֮O"Hn0Z BUq:v+(:r&z%CqxIT<5\6VRCVWh'‹ _=Zakiy M l/ox@o~̊Pnhjwhbg)5[cX?<[(3#,UÑn:r꿑D %$dGV?[ܚDl| 퇏bcPiHzN}cn&W!@50 hyo&;Plg %CiV-rL{{j_8JȗKlnUT>k|f3K#m5_Z~|X1ϼ4Lc]ï( ߙЇ{R+٥$M`epXc% W p qZ1UÅDU+ <!ڄ9&wv2wHskjOS,,:H?ָ |mF'vh(E PK?T)F&2ڈzEChҽ)9ib Q2Cr'A\ BE$nOQmD"3Gk2Y&Pn6ò/Dt.@( iQc=|< u3$MHas..oWE`v e9{ 6n5z4##W˨ `xyw¿9YS; x?Y+YȻRPm$^'󀷛 )Lnk"V69b,vC&0t@G?jwRq$1ѬeNh}#1_(Lr0h\ h2EV*qW^V6%bZJ zVR I0#; }6wb)LiNSX=%m~ |IVǬ7uoz]}QQ$SNn/Oo$Y%9#2 PrTpo+WVk{@_DōuM",3_{$z6b1sږ$g<$,I#N'Qh0V'݂}0}MF FJvnvo/e g7hݔsDuQ_n2&y2T]n WQuA}}0_v8QƴEL`4M:u]aR&{ߐs b&֡Ps4-[ 7@F\2H7rcݜ~N>/e6ǫ(Wz[H1ڴuvߏ6&k' dir@>GP[fuBkM1g_Ǹ5NDbD5URy#.)m:f`T.49 K*JE$eMx$,[.~~$7U7c 8K&c娕i S.W|۬*i6|V;^;?>hVǍaaMQEꟽ̉jLV}sŽ-$ȳ9D5k2!G6MC.%^%4 ESлcu㶸6$1 iMP)Sƾ% F|  p:q.n;0DLoͣ9-M =Pu6'ˇX[$],%^'H"([]ez?X/9;\d٥+NLIף{Ŷ9]N4 r#HZBO~b,ǨϮR2Y4&rz+ + wY-l6 L2~J+,w>yk6:A2"6.ܭDmHk$&gb\ v]3)>+8ћha *4p]9= _x(P[H R}C4ZU68_jD[G$&#eZoE>6,k 䚯y {_01g;7a`\ JP?p|e~RpΊKHl:d;+mSp!Շ{>䠉ms=H]0>`YL7HP )>I >W|!l{FKm]:Hcܘp:~OF͈xjrK{5+}7Pݴ+o6{Qe=ު{՜.-ыn-bi i<"u>j3@cF~#J͜ sщ8wtv4kObp}6IuRb8RqbGzi"ELT"TVc֚ISB1rF3|4p6=cn-z跰3܃A:pGul1Y?oo+Z:bTZukT儯rQ`栃(6v%9@I4Qcb $.$>XhaȔ]uӈٯYs^6YD68. >c)o>$D;bNHM-IQd}t8!18u)Msq宰if(Glu-+ؓ$QӝhȺ%QRx虚H :ݮP@90J7_Gej̉)R}$_ Md'4QH7a`ܮ[:yI:6 AE09o=ٜ) W_wS+X Eeqn9MXcY wʛWz 3ssBԍ2qf qx`ގ|.jp5BYZHJ]x#aO\q]۬|pN-Vݺc**:[֫dnz+Bkn@U3(ӺIh`pl%y#?rCbGpvQSXlcEZ?bog3 z0QS^Je'JʎL3KO<2 A4q 0{T9u)Ls*.x!}BجDfHD?g#PNgkrOq6ǖcvIp6Y`+mIes.Wy~*Y- 0!:e|=j188wp?d5`Q ʞ'o0j5䁋嬦r`QU|))jG;=}4Tc=v#I;BsU* 9jlp&萻>GEBI6%{Ja!1eH cU2] 6-PUK|op - ]LԘ 9u5at'[^@~q TU'Y) @/VvH栚bRw^Ýu:XE;m"bvڵqBy.O!s<e}Yi'ֈɅ=|cJaeH$Igd|Amڦm{AB!rϥVi~ڠJa& 編DzLmS0ռgJF񧶕/!.4lJ f4t?DH=Yk+'DJeH֡ yO׼a'5 8"O@k@'Lo"?- c)s(sDھ3F_iA&HdΕpju)<ޗ fQ̹,ZG3$m1ԧ[T9z{_E@p V@q='!QUR%k{T6F|UL<:mqSN}a+i8Aw=hOf$}(5t.8!1bN*A:ìKEB;-|>*e7SK#X(C|.)eNU /D0N`?۫鼮ȝG|?4x.'Pּ16Vr9fN|!1Ew?NҏξhK*z㞖D$VdXd}vqўb}k@wr~L!zoyGGJ$RB{Jnô7@^DKk#O H_)o$@ތSԞ`u,0h3 tt+5DiN~ޥ{qCi E]Ι, ZdԔ"鰽@{\)O,PlJb.qN1~B(i"}$,nXk,ʠ]SoIgBL7Hr6CRhUJ}O3@mCzp O@?N tX3dNbžc3ZHh8J_˯ouƥOrq%bjXHyYŽ{bm@w jeqƻ݃ Jq-֕rGP*!MmѸTz;p膴]Jwϒ 1ET@ZQ$3zoBaɅZ>=ГI%Ś)s&Jލ&C[v)pWO^Sl7Z}i`ȍ|q =yDK@s6NU%cH^[K4:H6(GfQ1@jWc\jO7>2 m-[}н6٤u6wz#&*0^d0`t@K6S:r9S(Ü6\'դóns)8ݑ;Dh3eɐ #^1 59ruu!54Ib${~6<P0?!J[w d H)4v 0_C A<9z[=V{ޯ#F'o~~zQө+J{l*R7b mݒ .TK.IeKꧪ h|ă #&Zfu_ u,b~]lchz8ݿ?'-u篦LVT:=.ow{ik Nx#VU8ćJc@O5)exak2Ѳdȋ8s8(x<6@28qAlZzv^|b|Y.`~rk8K7o6W̄>s0UfNaK3핊^}nwC;[)vM{ jguBt!G2z]dd|وD)3Ջ*Mwm7fc&:}ŤLyG- Fяhl#P'ăRq C.-|ձѢG]"4)Y|;Ϧr2isJѶ&:v`ו:M4g0}HdkZ= >iØG юDmp$ iq @m(&{fn+-1*8^ †+X>zFpI:1 ]л0:-0ݴVqSI("Jb9ZFn%ۋ|\[NxVsCп'&3V qѢtbtu1+D WgjX=.Jj/-Sf`.6lρeaY;6/Di {MkB~E99) k:ٝEotV-ȕy׮;M[xiD"Ci|<ް}S|.֏'t5//ͶN@{~7UIs~fm6NN=d$uot͇+%(LH7b1m=g€P!ĉdФy;xuf"J}<~$R+aߗھJ[*řۯb7M$Mu 䲨șqT8(p͖V<#ǀ7ݮ.Áh3b`.YWn)MbKJZtrDmAdό(8 ~mI{`P^r56 yʅKq~6pW&BSH(p*V_*wID9 pÌw3/]3i_X7 /T6)]xI1C|,w KMd)Ujr;NP,ᚳKx4'G&[OJx5%u>^Bi!T-M7;ze\֪WCSd"UMqdCAښCwPP=`>0dɒx`ݲyD1 bIZ3pV"L,V$74Vy(ƔP=&BUQyǢTF a8|g5n_aw8az`7n_АcH|Ljy>cBZwXJ7n̉mW{)ϟ(7ƢZ!C4n@i[Y26\hZܛhHl<ڀ'~^I1oʡL|"0TM,ԥ'}0?1w"t|_q 2T%ܮ\t!"LLegikkLHYiuyȈcW?(ee_oOLYX;ҸTG"flc3aJ?qq _M1V=lm/ue<'M@98i A2FYy0鏿Ē P@͂ʼ'3_PA,hU'+ =ZFNPhO\[[PjSI-_)]5+J5Y6P1FE03o=k͓tڜg{%h*0D;U/TrB?)Ca7ft[t-BL_K=q].ݍٸ}| €z]WH9TmjYny}/V 60y[M.'n|Bҳ{uΓ 7/\.9- `ٲ[FC%**jsAwv_R/D zLia!Ã"iVT!kD{_F2A݌$V>MMD^$U4養F1EKt4hjYIs {;  wҝ٦:Q؈I6,ą:Fo`mτ5oup:9gidBb6D bD6n)플_`Q!PS.%8[ ^*.5]eje:|y4xœa-řXlJ> ?U jL (xeMҜat[6DzWO*vE/ 5"L̈́Ȱ.tj4@%Bޠ @VEʋD /_Jyw>p P DwH!S<eU(DT˧a=4cRi8Dpsr /6Gt6թqw]UfV0AZe˿f)|BU $Sb#Lh A;ņ"z,(V6H,nc~'Q7 ]a!2$Ⴑ-~+.=1H;N*sb={M$abIeWy]rB_-AQ֦F<@~$\ʌߖDi5f2s<2;S;Ԝ/~B+9td9(ED  sN4]K.,%Aaiɝ5_J i_eqQИ eRJU%|NqH \QrNںfWëK Q`##Ef)t.]KWJ49*>zan?I~2BCM-y=Teߘ2 J?pMqx̸#ofb7Riql ̧+|)tL#̏:By-hcG!t*) g|Z/+zqFhC& < 4S.lg}OtZ~A*W+"lݓWl_ni4GĒlt4̢KlM"(_,I[9B+!qhC ?&LWHJ:f:фg0\5KA>vڗ@}O3z&4[y<~ # 1{h_S2Cl9wp/17'>ZwrV-ת#~5X[t'?*vEx/L΍feӌ(w0lV?(zyh~yf~M;:a:`͗uPc*6g)`5{G+T#M lLާ/G؆nVb8`W{E?&oyЏUh3~4e@%D0L8Og R*#zD c ۑOΨ?6A^ 䒃i. xP"!jlglB~`I>(3Fh[#.lY A0 p:)rXߴ0"Nwj]ƹ|bk 7׸nMˆw J%t@EWJf7&*)J&?j/rXμ}G4"󢌦{,,l:7>i #ߨU5uzQۋ@dyY+>Oufr׆6$螘k /i.;Zk;6\DST怘@_ %7ߌF S5]ZaKUDT N&vq&n{YᵍmAUe'!pE'꯱\"yoWua R}++g/R;&],ۘ{n{0bӹW'NFWokR_"B\2}N(vLʅ(B:~NJ z~e&0A c:^[檕uW-N3lF4G1(0`9˗4KW /絽7!;R NuV (t7큒hk ]ۀT@Kʿ̹)#j}NvfbDټǨ_ftA)$9 v܁6oy |;ˌ0^([N@%9hR( 2Ifّ])X]@Ǻɲ~30rԓ1v3@̆Iy K)zA"^#@jt+ 8x`Ө_ ݙBZs=j%sGBstv}#70-`OBRɺ 蕣iX .Aх={;-q:YZ/Yp[{DV6UUuJp d\CV,!.QÍjqo`='%Lqed\yG3ML˫%(*~>\*l@tY>"kuҩ7^r]~1jT A,8Cp /8MCQr6yX \Z NSϽ‚@p0 %HaLko5L2Kd5S5ǰbmf[? 3I0<12G!Sj81[>#4L$XnW[{W{YuEKG2 -B#cQl+WJ;aUEc 8]ys@H)l':#:wȩ cr)`w*HKw2%l%x>ZvCnNq8Lxl7g g͓\FKMZQDi1][(ug8e+*. Hi2w 7%Tz.k'DR%6aUf20VqryI'͊ >P6iP. ,=07XR߬13QL=uUha^\qާ.aJB╴ fqE&bQnHֿI pH/ Xv1=DZ t#Yt(~\:'{08'j$.{LڭBіMoFϑZ=G\nޫEH t$b.ݦn[bX<5F)"Cn޿; )z@lPp n6ٷ?tbSl˪9.E>sӏ†QS5tI˴|_#YDCe G(BO *!@ڷQ_Uu㿂 0DdBlU?*?77 s @m-cr 3}&WcGޘDTpɸոɁrkz9z(8ϢB&ξD C~=E6*{eU6Mm@|9z7-ϭH9슍u/iP9ӜUTy";6=0AA4z9LAhAw cўť\z|Y _tR7]OlWmm8~=2Z'`^OCGژ܌{z tKE#]h94!ERˁƎGkvrϜ^(Q AMC}ccd9_w O!72g2Mwx?L:'QH|}B00 h)Bm^ ea-[P4 M' ҩaR!I!#Q@ ~[lPC_ %F64)4Z߭5yGdnl [d +ϩy0@0xRE/h7b>A),| ?ix][Ǎ '<2˟n1M9s.%NY Z3 /#&Dq[|`l_SZO5/aHBfJ)>u6٩l˝ȘmCاf!='놭OXh 8xcyvʂcH-9zUL=Py[O**Oal-spcإkZf@9i=t̓(8³[Mw.g_\ԧu KeM4Рz\kH^M/P ?EhZ/'DP"4hg:wؼ7,?110BZkrӡ;2_%1U0 \i8ɩ|۔ˤɄ{_+Qlp?uANژvMf>o<]SUsDq"KmZW \fPܭSx@~XnY P ,Be3WeO 憞[a KwZ|ΈQr5m^IsK߼LaBvG)ܚ^" }/gC-GtV<*H^WكoLP\ˀܖ lCá=^o`CjGsei̓aȁ|Kz߈P諃ɬcrN,b1`3JNWl7'TtbIw0;3E\ <̎h8AeEIo֣,5T}|g1ߌuTWNO3i9H'zۭQ{(*Vt$)>b=^p򩹺>" 7 ]KcZPu3FmKOdFwa|1Վx'pIɱo쾿I @|LA h0gxM#]P]" Yq p)J˻<}1Lc݉S***hO`l9tG_p Z#_.KٹNX;&7Abk! ɅmcACdU[+v%^^JD璷]\neT]iNG *rܵQ[Ũ3$FV?~؂+QKp5l\Ӊs3z|Y AiAU_=ݿZ!fu1+OvK78; h!&%hED9XJ"3hcXS < 4墣kSC1 =󱷶Oz}VPr!h}.P>e iMVڨ] 򽺏'>;]Sq /dWҰ`ꦤEЮgz ~$3 ӢUmM?R1s딺b$q٤#êѥWy QOP]8_Tv`*=4ry*% {p,GGsSx;T*Yx'uq|3lw^6ҭ Ʀ߽_Y5 V-Xn}lJ22xY[ġXHSt[7DE Zm pRY~O߇tXTA=6oBV ǀڍ8G|hИ&|5/c{uFZ!1G AX7#{'Ϥm1b>^a\[֐1̤Ʒɤ mjjy%WL R5#p.miˁٵ&]/4Q"TE8}r'oe *mJk?sX 9#ӄT\:z8V0]Xbv>dz D6,NEo}Hkh=ƕPW<~uz yMJQc\!Ӹ풧BʡHӭ{%\եjZcPs7԰՗2\erĒVSL,y5L7vTˊmZa6)]A &x>k}*EC AsquavL.| 0GS|)KeCJ]!pwE<5ݜhl*2K5#|i*ug|vI#M+i֞ Sm1vP=5CCiO%&qfm< m4G8X]ZX&{3߹\1YY~4#MWYk^o Is|[:_8%iW~`Xd%Kj =bgT_Co"6=B"OzW!3t649F\^uh=GEJP7_Qm|e? I^[ռ{RI~W;\_^W*Ur;<T׋/#fu_kB&. +\yȥK4}1ݵN4I.OrQ%sd68liBLns^.rI*E'.6^MW|$?!%T 4]~:v]Tn GٮarpKE(2Lڍz3[_A/F ׵gNA`pM柉JFm+`[9i8~k fө鄐o.8O F)xJQw)i 2RU߬*8Xrb~%/K1jF ,$|XE#4HR?p\6\:v"o=+fl̆vVfcjrބshE.U&n(U*J':&J- O k/'v-+ǙN˖=8' 斿 WZ 9M9]*be7@E/}K2[OG%֒aj.:VKEᡭ#8ta Ln#F:I86Gs cݽ Ky$m"*K~]Hv!r/,]T%X:_leܦUQӄ;׎f"[l_ܶ_xq5ZB\vc;o: &Sk,z)޵c=AZT 3<̊@l2'mBH1]MT, 0]5^_&5DͯªnQ5 jxk C|I8L2%ӾP-P*Y&ʠdw\e f|ɾn ᛜ&~LSPxL^BPwNzScR\:Җ՞W6DPқwIw<')IGwJ}ճ {!(}9h}c [F|^uC*NڱPHmv1}0T\YyNT`͢pRH mt\AVqR-$TT*?hWrE(IQ<ɸXPLeP*]" XGROLtnĘHRs(mK֏E6c? ,aO<BS_{qt?{QMw/ИUn Jsh؀cu&SQh 9`+fh_<Mޭ@@.+&kN]WYF2ik;``tf@ygS,t8!:mvbdw6**θ*l]D_qr&2)Wq}ZV6*L*NxAGB6 e(ZMc?_I|廩vİ zrP?4@,ev"˒10e3@rzCŌX" #y&&!Ij}OLuZ,Ū#gd"j6/:.DĨy`F g"r g_ValOA t $q;}]OWyezpv4Д+OfNz6>=\27`˅$+QtQ&eʾڎ9{ # yzKOU (q*`(I}A#(HW)u)1jjJg=lk13aK0ܾy b -)#H= 엀5.;=-K(#CX$0-0kJg̞#эœ(kS ˯;!¡V> 8܆}x,z2Ca?Y E_jsYA#.V;(' ; LȮYZո﷨aif ^ nJ=1v@]ϡyoTy*`V> Ur-b#XNr XSB<6#%K62$>Q@Ò&V(,9V„Ĕ^֕C<4*4Bq)o)1W0fNIP*,mY׸7 t`Z ǍҠ7դdB/SivbK-ߦjp+D?!3_~wuE(S_Nb^jBi6aIv9vw- r!%=;J*O]w{((8Set5fۘ7~2])U5SqKH1wz"C&$+hi8@[ ,fUZsz0Fۊ iP;E!ԋ>~tǥ`E0ϫcteGa e.zR3bbB) I—B xwIZ,>Ha^|ZTA\O3)6 A4Z͸GCf䊗K UatUٞKҩHI|k&R=$!ڀl0<-sX&]gR)Fo&>ߵXz!&\K[ɟ+ QSCw2s\҃,zԤ@L,U|ʛWfPSfzFɨnkد8}<|QH\G- .MF~'2WE(1=Q %@'YfbYa8rO"쓶eobh+ dW2;ut冃Ejt&:y8f՚񮠝M3i~~TWvj0^5|]YyӕGů)K=#lwnBPYS0DQ$_I/NR!î/KZqbwʹ9O!q8ղUAOA!+8Y<{\O!;ya3:82:{bRgR =)DB?ǃdᅚp"-hY|بz].ony! (IoxeB`xCWave;Y#A3:kCfyO$/eenQe 0 7 vjFqF=0_҉\34ዱc S<@VpLD /5D5_Av6fދZ`c@B%<h&Am̿+pk?9t:J7*20!rY\ en7,!wz2m"yt \8cm+y5/xd/DII 󗒤/ W9o!ht¨)T0cEZoOc0k\c`EecfK,VhI_áC Y 0:U8dmdwj"bλVCԖ2k4 WlpTGDٹSO{yBԯk sbhQNFS}{aN;}Q*}k?9g.X9vYU;jRĿRØL"mVSPAະ4OJǘI&t-w|W浧V8EfmN^cL3F%JDDŽC`5Z+fb[g%I;Z}ӂwHqR0537#h vNg @Fc^_D/2lP~*.ha>Kk'~F\Qm0,wC_Q]])_U~-| .+ e9^ihӻQ[=`(S"cǍ&yoPE љ CLMW'V!-b;qr>3xt_;@ӠmU|? @i}j=dEړ.H 8}FpS hRq~qqS!et,eʺors7, '؜:%qeHjt%7+> ~}不#D|_H/%욼9wߏdsoԲ@;v";]l+}r ɝsEF%ezjK^&B„ysh}Ts[ŠڛRv[K< X!Cn^--@jkBU?|B`S vG]*mF&{ "sG?z{͎4Ηkj yzFpخu4n۪9TډOD%~ K$'Y仲nMDW3d[%( euµtά:LM'UR}Y~sC+t;ix?:a tr~(Ѧ!&5\ycL6ahB=nPXj7z5dC'geeԧrg?1堭%X:ӌ4k~{Șhr*ǖE.0d^lP"SRfE ӽ2VK[E'axyX޻S7ܶS Cѩ6ݧp$8O6;+(Ϟ?.pKIP&MpQ/\6}˜Ǐ< AIiݙz$j$ⳡydB%KB܊Z]:h!dp|8`%.QJ43~Xls)dtbQ#'D۶l%R_kgڟBvg黱f RӎHJ mst9] mjIJU0T02 X(v_k{_s$hY_z`epqJ59`H_7#wlb@._g 4,E "N7jVD@|W--+>qG^2t4TV% two@XSnP0H}ZyFDJxU|1Mk<7JE(1,/KFx(&^[fXȱ\[LPǍv&/G@&c%w- yu?*O䲵`kcՠZALޒ<%IHXpfC+CvZ]ޔ8 Vϊ`}4ן q2G QӃ $\(扰calwaI055}_} mPNDvX& X͵qs\ziα#@o=N^NZCW5UX6TErcR[@'eZSunFKۧw;& ۨbomjץ5BrB7~0hfn  yIHe  DY}ddj=3a[;DeC%/f#z9ԂFޏ;,IvuZoⅸϕuLauri~GKb 7jg/<4 ƭoy=~YsL_o/:&O\d2X"}1=humdS[v${!U1862uBD#hr8☂v<8k#_V[t$`?Քnٚ9wKeGo6vM%0* *Ltrx/2 K[ǽG66lD&nd16Οntܕ?ôU[Y+_.VCKD0 kel}H4ov}%[aZp p2& mp0qžAW 9'TJN0)(giKr#'  N+ΕhTo@/yυCS1{@*э ow! IIW+䌢~LwZ$l?/*suhZz v G}੗2ĮK䂕~+,]V9JHcAIR2ҹ͚~@",yœv $[d? lwڮv)kO_8q9=U{AWYnǪʽؐ\ J1jh \qeKlnQJ_'ys߂Mj{UoKjU lniNA|HSБ3B)&+K/VFn7}$`(J78Znu\) { (Q_M<]ȹ$q/3{jKsAЈTo|Ky@c"km+R> Fd\IJMWED%ek]+VN#(Oj\5j$O ^{6?lL ˪+TG0+"$]s $`ل_b4~?I 3/|nmԓ +vI.ʨzF'Bvsg$h+"]SBld?~aY)E8$lpPeA߹},] !`6 K 8Cy F$܅ ]CPq 3|z 11, 7%*;ga٩tA}m#zQkg8*mUg>`beuqǨ1ߡ/,/D-)S̈́\zf졏=l34Pv˟kF50 Iǃћg9isZ }J9kGIM`0I8aؼ]Krp }| `Qq.X+^C J,KH?aKjqƳ]( SF~72r#ȮMn=SA'ۗ2z,8<4h57 R"J{a^SE{ltʶq `nsI*Lj"ak缶m~Z:] | 'w%9eգز朻$ Sv-DvV?q|\s3<"yzfHgH,7G` S$8K){60Y v36- zQ)؞b=b*57smaqq"NuvmFr$C;1r/l[GXd|1؟X:Ua;hZJ y9A[^@8LVB*O1s/փH޻B>sL[,.2WWPX6*RXQ&uiHZVH7#srQȸӪ.4JxD49EȸD$X-DPE=[ 7"g񫶙"ø)OG"(D)G-aBQ7 ޲?^v%E(W~RLй悼=T0,zJd%Q0* M*mo<'G)h ޴>z\x P|/:w>Hh$Zf$]HXXy!WVVmŧ1.Bpyؐt=w7+h0|HԢ0chɑ*CŘ[ذ(lϰ`׃h|FA:S>e΋ۯL3Fgb߾'4.i`v==i/|1e)DB2?nRZI \ /5\+q =zHm^6<QΚA @q_js4)[c.oy)'g Fki9fE3l@lWq:0ӷhNMr_qWǿ~՝{JO6PTL3Ld`v^F_mgΨLIE"5nۧ&N*4~TF 22EO̻71誘dK&b{)GCB)id.NuYǣ ECZIk#]' j34]csXZlF)nHW"\?RO,~+~Ͷ BISRNԅe# a8qq Iڈ3mi?sOP̴Su@ }b}$ӥC=6ǜJ-0Yt1keTlqafSj$IW ]Zbi|+*]\KZ"bRm%@{ٍH[넫9Y?y3;θ/ZY)Gw@ia~CUJl%9c?h_, 6;lC`ݝE#8qZ,+c&Ҥ5twJ139{"KE$. ha5,@jo70``Cm7/LԛuE8LOhʑl zR_T禂R*.ߦPȃً^9 ФtE"Py6X@\̛np䜆@@ w+]Ez~O Ikk&H[kO_X_x.c=be"C- ۪4|.ZYGrp$ui–4B\ޕ~hű4C`kϚT=<0[\BhzI8z}|J6HXN 9:^>HAgR})R|BnEw,%&rlɈ/4`NB4کl} 9]𛽡>IOQm(; Vv큢#tre*%0@]>)@?9QEslG#?,5%WvRUV,T쥿31v]q)7[ikpO{XgmQ-jك5B|EU;Tň񯼔?ofZG] 錝f6Zww*EmVm4 c{3:KMoh:i|ܶ1~nY[3F: s( %Kxv1N7$[#_zo R٦q`F ٝwC Pk^sHeIa ELlwv`O$33_ `1ZDKIOs(4h*fzԲCMQnՄ:8]RċwJ6?}&:jϝjfh*X]!F7z\g_6)B]{ p%ݬ$F\Qb /|tn朢ㇴy|n+؃]K:]fCFCzv"4blYs JZu/bc{ޭ.CҲ\J*o f"9k>>?bYVT/uX/1f@-}߱놈 x_Y,IČgۓ,Hl՟:K2q`jg֍х  02zRiL߾T^='6NY6(t>ΰw6: t% mh֦ v*xz6{|/Tt]H aAzoElH܍6RC6H)vy {dOe1gCT W?em1RguZ j ;ƪi"ԜʙrlH(ȱhx<(E_F䗧V^6v5kPj_W3p ^da|.sWѪSӖz$GΥF'X[I9nu W7 ?  5t`ŗD_C(B\K'{~oln,壧 `\ىúΌht=cW<"=~VlV5o&8sa'Ñ[(ut*圣zmyp9KϤ8a0txx#Li jZƗ&yqpG ̍wuد<#(/ĜّǫB!$n>3[xpVn-{A=|Kܢ(bow9i#;)Ds$cQHQB0l\1aΞ$ DhNJA`%40#FbcV`Rniː4 /ƹ-2&lͿJcM/#?7>T2Y*T &MPٹ:_Y}D7AI"g$-=Dǻ%jwF8VӘuKw\XIi0r%n]mwPNdY2$7o44G0-X*)ϧ)$>~uIWaBݵ  J:1ݿQq0( qbJᩔY@__jbݞ R41 "ě chR>m0 ( |RWR{`+F?5ͼZ~{b Pt5h7"Mf8 mI3$vqsx }Ӏ{:a6۴Iy&N*9s4jl VH 80cPXu'`W0fGcVrbȝP~~D_r1ʮ!fY}0i*uOV*n'^4Էu4r]/E;>$q0@3{K`HqxC+]Y*0Yr]THVb(-ץF<GPI%tX&׷(\ZxG,6A z/̀Pq< G|PձzF6 Vht$3+j'hmB{ &9_'\-ч~8zp@17y-QBTR8̬.[KPխkϬ;;B mQyz&*4EzZgwޗD+Ob {(&cg6y`MսOq ˝]W^w/r\bI%䜢B]P䮏&1ɱetBKg>;_YVw{u+] WXnyn8WjM(bX(@(p|DxWAܤ4zXe")m`bI,qKZyD|K! y# 6Aɰ}CXlW.~(z  PrERO8E>4 ǎLv?KyrU=BB8S;ȳ\J//,(rd 8EjT$䭏tU,Qq%4ڐr:NqQVVf%2(הzϾw6ޝy j ܯEqqxn |N`p2 o6m5uFM W\8liZs'K e-Vab3w`1VbvqG1lؽU)7FKanSsW a.2A%~iRD$aV 9=Ή@۽/g+[D.|f,zm[=SXs l`3rKSs R'r,eo+?x२[G@˩_أe_68n\N=3{u)07z{JXf);k[vORٴad&rQ{$zIPa,GyR Ȣ t:t{VVUQmm2Pt~DV(םXs4/̜+Us(oJޗ4̥}Kobf.1g#-ofQ ycR'dӼW08ܔ .>2 [WIpAYHK;+jT~X.dsA%v]D_m37r<4JDb6rwE3cI]sAC^'`h) ݍ(=}q&i:K78x{Xq'ܓhr ˒2'f#]{XSc0T4aVm*)d/\ߩ#-Dfϵg*4Zx%f1I" u}E\'Y}]VV/R QU&% 0Q%s.nh]pY['t?]Hd8,) Qj[Σ`O])sԎ‹Gs"JիvDDv`~*?m^|mc$6] {]X: !w|=K6w{MTZjVH5\1 XL"DuFRǔPh$g-DY٥*3Jτ`yaXϙL7Kgøܟ)- ]_'p/n-?QYݡA U섺W !a o!hFi_5%S;VR9G#QYF)o 2GEU?O3;-tc hu. eI~aUQwlr0o~j]3c2sбS!rh#ȞÄܵfR4?4ެ?E$Q`uq~5guVp'Gt;'U!tOk},K.x3+:x{# Ȏ&Lsi iҶP wdZ6`7W-:+2+T[bS$kv#ws:W$=߇a? |Qe!Ag ɳ~IJo>bK?xXظԀ؛oLl8CE֨l\63 Ԏ K]`+ 5bI[ ZyE9>skڢN?er`'&Dz%-E5[77{x2;FL$aQ+M^ԽO(z?,Lo#, }0 Vy0UxvK7._Ԍ9+h 5%sbEd' 7#"Aş>3Rv@_2hĉ+yih55G<3+]?.-)#ЙznmxO 鸕v_j!CI |9;O9Y'E| .vDᑿ)ݡC[wMiZF2Ԗ;I?"v;6!(0lNɆӷԯ^#" E^4ktTe2ޤeUvbGO[DheN.Zk+`f"-D[wB_gc%hOAҨU+!Bߩ'1{MqvJ83f:RS2Ny$!φ 'f4TA^ŚCǛȌ[ \.RSS4IGVV֐΍ć[&ym9O8MM r1[50E멆ZVfXf!ScX릝z׀.ѵ&+ǭd<)ڝ,zyn@"?j7C3?R~0\ɉiKK@U4Kw"ɄW{N*5|,&GDMo>v5ͯ!_1l'&ܟOΩ0N!ꨕIQ{ IQf)L,]AנOat aoz(ߩqc7Pk|rEp9 6X4%jZ.}CL\D& $j4aE4RIVw.(ߌfF Rw`><1E0s=C”wCj46v`U!FV'?m`nXbCzXuK 1ϛӔ+LmGa@rq=Q'it@PK78^_s 39m+! n=>?TIEt]i=oO @]gŮ, 6沋28 5Ԣ(NZ~hmMg|Rys)^*d =?KiȸkPԓ9Ji Ʈߌ:w58e /t<)HDniÌ@"個$Ln< ̧v܌;"9Ѓ$|6­w32r ŠժȟVO_h7/663tŝ c8 &Ca5Jd42^)1 nձAS#JK #^ŒtO@fv:gEJi,M_@zk(d\ȯ 'Ҡ߳{&w<,αl7f2bH?soPnxPݞk8߱p9DiUUˤŌ0摆izS?T>Oґ7R9 à}$ w_JU-U-Vs-y~i`eـ1]"pڛѩcRH.7 ]zuL3!?b5>^pX&5vT8L9H/]m]P/Ϯ@zc*No,"3Dl{P mY9 PReIwIcp]n @"x|u Fr'&ah{3uUcKCn \5neXRyHawG%mHaiDzn|6.&? 0-jdpy:j9۔|}fڅ'-{m 07 )൅oUiÞG#k­\@JմëMr%kL f%ޛl) O@ngmjV2c]=lva`#fmN #PH8%| ?g\i,I遺>ޛbm$1ߝkɶ%rll /EwG "fNzRufsD5NcE:$K^"ћ2 Ҍ>_5u!-HPdEO'u2a! B>\KeUt6" 1/€ugjii-7n/~ i=&X;%~5FWCqŵB>7lGhIO-eDU2),>vhΪQFYGwXzUi{w9v]s$DFlYHޫ98'Ya.RڿmnxB +REd[r1ZzH? ߫ |b3*ٔ)EL<| ~jxeJƂ3%ys$a8DsRaU·>Hq}}@J]͉ɼ>dl#aqֵj7xLu6i)3 BR-.+Vmc}H"ڐ1ʻ>c/"s=9LU!(1XgfI%7^'Cpս?k (*18L"]؜&_K:W3u݉obs8SoΪρA˓X`u:y4w5Ѵ]sRtw' ?\;R~;yO]=t_ڻY]%m/bMk m\h[j}J̷JΗ-AxYv\G mA֩m*%]T$_М{{]Ή2E+n0;@5~@R'[7fLѯ,B*A7!gdoʉD-Pߊ_7>t 1lXJ νO;VGpٴ틑mwf,hZWaV|U ޠ&k мMEC@Ue|8>}Hݛq"guo' mq޿$سTCaQ, 3ZCHPdm~PVD4/8I;F%qkj?mRWһNP20|tM%Ռ>I]@:vC|Vv;68k-!\ =}5]$Rݴ''`hl?VU {m^ u'['(r;(#,cn6LAaGTRughEG*!iO9 ϖÐwJpa6ylLbMNx~]U8DYtmzK̓'#@|  L\$?km<+?Y@oU3"5鿝 z|?e G NҠxhz Pz^C`kY0S_@ C5֔dڅ2FCh[unU fbej#7KsziVu5K/p1V{C- z<|2f)@ތ;8ś.1J1C˥*eóE_#$|i!_wG`( XitN= C7crp-eٴUPJW7s b ?Xӧ}@v֋hzܷx;?"߅A|oΤ>Zs JYAOLEVdynGVEWML΍v )ߨcjlAg^H[Q}W"lQ,?|(Y$_q)HyRCBŐp-n~!.GB:OEewbU>| b:%0Vs\`>g^C:0:@{݉H:T:%5n9k2J%g'Hϸ38`;qv9'CcS}v\qUddX5M$[d1E=e)i:Xֿ ,%[f &)aFLhe$IvLx3zOG=:ƅ D.ky:hF@Vb"bP!v./ i omT QqS)yB6k2[^^Pce0Qw@qXĿ_ 1K8BMΘIHKQlE2\fCE붒eoF jU|xO<7Qx6$CӬnaa{ A+iq :B*&e3uް+˰'k{klg?5cRGk65!T@LSbS Ʋi ڧrW--,.}HS lR"  Q0695oK._aR6w}1" ( B(^/Ee=z,:MuI.WPEKeE#ƲH:[pW4 *IX ?o 瓞}BfU s ,_zj_N\\fyᒀa~t9FYLlLqi?g^kG25⛸M6+F{~<-q TJsN#4 MLJǍr_Xz7+E2a+ ɩPT!k@7#wLH#d홇!XM|%^p𶷕"Hem> kFČ==Y0_/ {]Ek۾pnD}֡1 +Triĸ󲗫e;Ss<DfxҖյ?/9CCBԉ]4QuS\H%(~|]Uee$]xe%<~JdHd^PJ 85 f"U{GJa.aaKT[JΫK܊WvƷڄGƑ8(8 -US7}µ&o<~YTUp֦2EIC 飚 (ϸ "$L>+Ykjp֞LۛxS!!aF3rRog&Ò"- l)\5o *kBub$2U)e>_ G=< RZ+` [~!yyE'K%Z*8v5X)cmA|J<ܩQmǯþ5bey+Q}(Hye%#Y r٦da!ŢFʢ:nt}u8KLž5<{"IF5kD}ݨڇRVy)X \ƃ CǕG}zt]%Zd|ǣ5}lwyY͚*+)*D$_KGitg^dt*jQD:=e`cH* vHUIԻY̴ RV%ň\^VF$O3fy-i.iZ z;JA‰1d7Dق4&R{'?9Z"cDn2WO*9 7젌2fk "m_r.h-$5h?m}y'n@lNtb!f+i9:7L4&I  k!3[{x1myͨ??ћhPΤ{?Ye *$4m<!%  d-1>`@(ݻɱhZi?ʹ\T2:-*vXrlZa[Q7h Hݧ/k̾'u/;oexn|(.qrGTt[vJ~`֤D}MCY L_ g yOwQe]hjU:1T[{ǂ2dg06F} Zˌ sUibfق0 Py)yHl'&\5EVJ^&6;sAcaŽ6d9=3fuzgC͓*07g suK"W *u%FH52݃9#f I-l[Oo^&сdnVoB OŸᇸJ 9:b_=wR=b`1=(Z@p667uA\ЀGv; sjLcVj? +ԊjP\q<&(%֪o敳rʵr5wjtA'9ֿD]:({*ЭHdz┨+$1 8r:RE4>x_2mmBDކO  E?tW(9c9&"(MUum01[c&1,"PkPsc&Lqo A̅TtEHS^u #no:4S ͬ*Sr<9q6h7j\(tef,bq3#w(ia9ѩp]:#Vm:2 (/[D9j 3pNj\O1Y,Rxյy~\CQ^I6wE ?M<n낺md|6gPl 0Fa#QrMJ zb6le?BͯO0[IOzi+\7ke5r3= v{ d=vAC<5!l'~!{ȳmfL+zaa܂,0v:ĥ؛r)ڣN46ԝF#$[r93{Jx}} /++YH< ~Nך+TPɔcEU1{=|;.:Z5@nr^p4pog̵bp44.}{%9`WQ_Sj=oA@ 2| $ E_θk0'AΤ=VnGe7)ҵ@ ^)W*ؕk=-ϴY114:cj/+ʲGFсu/cQM2zB"~\ =PdU|'B 5|]G$fPAT`1ŤvdBInh~&K0F>ECf'[ŗ9 ,h78ӯ?9&DH1,L[nTkGufQc%]-IGx/DA.|9%.0[C+ |OkD1Z+.fA5X+GC%b>Өv#7|=q E?Lr>2˗E}&jaT3Nv巇F=LsѰt0"䧓V/Uׇ_QMX yj"QNTe,۸ѶY_֮F@Y<>uG<k;‹ЍJ;ߏyT F}G/)1^2}y ڱ0|oe>%>&,܌RvƹWm9M}mcf'H³$t a|s&nR) BFSeI6$ȣmyL5 i:9w%Q6cys0ʹ=KwK/vjHvP&TG#{J"td\.5QM|Z 8ǽ[BgٻW>TL%Y0ڹF v@gX9;s%4Cj]I ?rdWjc\TNE+'7r1\jtʉH*^mza t'?a]G )AYX[M5 Q5%^y5fn}3, Z{_-aIO93J8)"Zm{s$\~[s67QG7#2#O{+r ?"/s~`%?@wfJ[GRu~o{(7~3nw7=!Lk7pmy' 0zxD{]A9{S8@Tt_4J)8U[cTtYtUMZ jHMdA-S%ـ()ꪹx_@0E!N))\ь<^poz(:FG?Lgs 학9;&|[~\iA 1.J{&-W R= )J/eŇqi!x9C+T.|@I¢2;X- J% G>>MW57ַCWɹcur;ǿc[F"EK@Vؠ:eJ)¦lI~w k*E/޿tA]u ^6 rhA!cܔ`X"]A$}E&1>Ab59r,uvЁ&r*[Ayz˙_,ϭfnu ;"g BdkRK $hj^R @uEт.>C7C%Ђ*:} rz ƳY: MX(rbVԻλ \6OdUGfɨnں+i֍b#͖ƙb[19uwY%+#Cuv? >nKDvN48R5?ӜqׂI hP,%g,,DZFSiH]NriӺ_w[*4 R&2AU?^j y;6 yyYb'`tB-ώV!p|/1UH A=ZiusZPBs=\Om\+WZ4 l"-L=jې3wl9lD *##\;V)VP+B ,jpæ SF-S<FV<ӫTт~roIHe H9('wEHm Ke~9 m:3sc+yd!짴yڂ hYAz2*QyIy$z1aV^r0%": ~Q'Ϋe9- CC#B9MטY0X酛pwT2m]iS4Dܽ͐+$ne;0?:sSp "iG!Muo- [WRs4/؏v|N-ok(x[O!>DSYA|(G<쭗IJka$4"Lp<,|FAfj}^9O],zBq5;96їwe4UsG۩ {Ddh H:mj?~b ELF@pl0Ey+32JAEq#66?2$daTkwPְ"#p97h-ewҌ)G Jr ǘ} lkX(FO{i\/s]R1I M7"`6M*YlK q/]U>5瓛s!HT֐qAً&#. {tb/8삓CWң]PR?w?,W pBX܇BhGY ]ӱ.^KpC6/m{,ȣ,)Mk9p)dj%s^Îk-58Lk%ɣGs| e*Tr} 9+pj5Ϻ(؀7mY'zL z)J#Ɏ̺GhTG@/ߌ|YЄk ĕ4X,u%]xn}%yxuJpEdŊ-58yBpQZ1|`{Zh: % uy76(rhv~-ָN3[}JFn4wV4 j;@ncWd8eHo*;F2@j i_ˬs|fVzˡ s4ջ$ADӊPHPiS"R^C\U22b5T={ak6|&~@Ay/{4>iV+yQ/𤄝b{ySMP>e.LM G|z^+S^2v1NPBKwli?rfW%jDB?ZzÄo:%)V3Y\zG[)?#{Q]jx]T- 9} ])H %Ss^6lٟ Gձź2VB*n<"DZUHKlko5! q)!Q{>fݣgɌdžI.n+ϣVZe F h7ʿ`V"յMJo.Wf5bnNWkDu* =M6=rՐzwЛkXџb/e ʘe{(^ OQ^Ɋj2Ae#'Sm$,!YQZGǭceoUF=3VKE>"T~b:Cbw#'-@[U&?0b_dM[Zʻ (-nkeDV=$5zeKF:+%Zoq[Bq؜btCo#o-ZV "ѳs;zdPףc6lAn9 XaٶRKePj]3ZM=*김4~f$R. - E~Zxy9hO[~y%S{+p"N_y~HhۅX[.N`[dBڈߍ69{e _@5猪<>@Bt_mn92 oW2P^qK&6Em1|kxl -omRHyo |>}]M}7Y<@ oV%;ONŒ #nY|򕚗(4?Z;W"tĘXfX֥Z zD8| =<<{^Is$='cЀ@3zۇFX'x rXIsE1CNC#=-@30fIhqh ; BE۴oi Ϻb2;03P@}|Nۀ2k skЯQѺQfوaRs[&tF{w`,=m-Z[Aw%?4u?RfRc5mmBg,]tכb_% 4|S*TY^%Q},Lƙ_tО3S&\2/1;j=Ȳض]L)[%n`2[Tݖ}饚iH +` ~s ;#UΞgTpg X_ŐW3?Q=v˩.vyUBlFlEDc?Yx( IT0|/Y^g,h*q# SNu 6~jˇ <&=ā ҟ_P D u<+d.Mu *yWZj7k9qХ5遖~ dTw&fqt]ŗ a  S|-?fzxXxqv^VZo;;գxCO~I-Se*'{pѫ\[g/`tHGX^ôME6*9{^&is`G:ƙbo1cGRńyɸ)Y؋2,Ҧ7EE="0f-^X8q<].1d=|x8c0zf>-URҬӲ] tR/?֑NfNm[`IpFʗa1Z`m[:Tk`+F&TKVzFqL7+xV:2)M"Im.4Iѩ:u`i>^ o70:B2RqK&F e uU /*bgI)qxO~ۻH3#3z׹n]6j9RIm; q p)oGP"43wҜgd7->u4d1 u{ `:>S-v5Yl2 ]ZN]pR[3^'(1 ~)™Xa8$!п0;juc/ajW>˜ # OV^[p@7SvDL_ wFfK1Uԣ6vwE?ŃO1d aQWQHƘ1,QslX'(PYBIn8ni:BȆT% |Vsxg |FG*;lA8Z)/ j::,¼H aϷ/r 'fm"r9K7;T լ-\85fEw;R4[Ӝ$'vA[!Jf'a$D䱻 oG?1EO*3A3?aǿ((Z(|%6-퓢 U?Za$ʞH~łw[kiŊVTH[*g"3+]F{¿}]_R%Q=A^ySw7lBBub7T_I礤l2K{1۳ f5eOZP@1L_GT{T}q j%/V;ʎ= itUh[Xv$)ܵ[q txT5Gu1 6RZߎ0n߄bLExtR]B㡖A2B("^z7JOݟ#7/Bj֕T/\{2?9(q7|v}7SԼ?c!SxUk5n'q2QfsS9~ 쳛 cRG WXkjYCENP0x: OUz-X lWqy`c".td #T0%:;M>߫dnM( KE-3_ %!x&mB5N,~Ɣ2zaNxcQqF{ϥۚHVYK,幯ٙ5`P[%ꅙ%nCY Jj`ÊL/V;=Yt;HÚznN~[Pxڐ!uŏ[b@i\ÀH |XK70HXcBK}ׂ_..y?}w0U,ixnbFp%!Q/@=c`<ށt^t][6;1\TY ^ogk0Q:}Stb3^ߨuR3fc2]n{DCy-Ћn'bv.'-V|hސvzgZԵ hsrSHיw]jAqQF셢䇓 A?ʖ\ {O}AX_sV}IJAi wd%b`wwNt$&s,mF=j%v~93%C\c|ޡ&(ۊFC.i֌G3Ĺh ^ q84\jcn0]lz4ܰX^1EL gr*=~EZ->0_J'nnWKO-7Swl 5w=zbp_;rrZ%R~ŢleW+ą@f70кֵ{x=w$Hp *;`K6($3{kGbf+0&ܒ;T#&)sX\;bŒ?젒U1bEЮBL^D }ݤ38>IxM"$MhWJ%"Ujﱡޅ>u)E:P߸^{-0q¯Pm44jf.3Ԯ G{\P)jR]fzXDJ$w7($u?:q8[\XU]7kQ 97`nNH% aF[$Bwsj5,Li+rPVa5vn&&(RÀw0l?&b6$M 6!V!<,rJ`΅{&6m;oX3Ž rs}[.j7hbphH1;VSƾ_9N$Dlk9G=䩹b5ޤ:\X.Q+t+wJGyc478VT+ZM m:*~GƐQDDtukCd/,% Mq×or5""ﻯ tN&9eW}}`f[>ȴpoM#Dw(S”.#{Uhm=)ٚ<8d,]AirdF3S#S(c7&iKǙn8^v͗%IZ%?PVvvr$4EbYW I 43"lFB&$mc)ɶ $}!D~2hRR.m1l`}d*^FA+0%# /ZOi 90uL(P.%o!"ɘc'q|eq=OM'c L8 p_L/뀂#?v2 yD'8g+Y9 o^mSPS:4R:#Am~ְ]Wف{-7|Y?V$AiA'MsX/TmpJ ź@BiSՈޒ[xD|6>IOx: ~r%vnQǟ87*$)b8p9A>x$XU4yRiɮ.d{3IӤFh#s/2&JX09|:7(Y% w0 P <~.Mɑ'SMG U*mV %WWxղ1߽փ?cL#ax.,ғni ?Kphg41\ *Ef(FP`vR6)M'MMIH43t^(usQmK*$zJO@9A(yB@Y7ӊTM]]CU+aVv=~8zSFyՁָt?dڿ \_XS9UwITgUg"SJP 3J`ڕ9&|R RT8Og4OU'^TO_w6l*'!5,fqd2"ÂSo L>i㇋x3?ȥ1~ 7>1 A?e[X!kF,TmHݒ=vȚ  7ϵ̓JbMTRӁn~r%zи2iq$U,N>b[l\U䐌Z5՜TNH8|v'>$fcԎmWJ2󨖅86x а[v*OmMз>kNC8#o]FJ8^Jt4^}T|%wַ!s=#``Mp"^4/(-=pӌq7>!18xܗ(Z&@eľY7ZcTY -n4eu~!Ak*:`o=ش I%XR[L;Ռ*Lܮ+nRsv&^|AQ)dH2EH )ET `s,O 4A;lccp!gBRJӓx%FˣC͇dʨ$ >^ұ8?ruǹ~qf.uK5u04wczo# zPSɬ%d g\6-'s\E ;kY>ڏ0!: (F(_iiB4 &Q sI\vuJP`aɦ^#4Wj4hwh[fWd؍~&z=!~H ?:>2{e&a1 [uL,qK*csz` { c\}B}r>Oь X}c!zd+bfv^"ȡ~qb||}E@_p.ʉ 5Զ֮L{fާj]Ȅĥتp1BD۸m@Rx2+TiY—a5>jZ)KP/7&h I0S/?2|#=LS4r^q 0ĸq r!Ӹ,BS ڀC*9k0IR7jf!Nqd~2:TJI] 1JG3ԘBV[h碇ptWv qrQoAYPf;6Rgp :91)჊w4% 3YL@|i 7}=*w竐*2SO󃩭5ҨHKL7gfʀs9DRsCJ1oUBOSCiy=? #Ҏ²U s|2.;&̮ +1OՂg>΢,|$+qq+^lg <& ads`}$"*\A|*u*0 H$DXvdU`f]y/j3*CsiOv*\(y p虢E"t' P#?v`v!\ZAH.y,O77ČLz*0#!㷲lEUһD3sG3kj\ Pt?D;ZVwdOۯ\LoZyK]k_;a=bYel;*%FU+`xM,tcq]2EL:[FQ ٻga IbX 4ٳm$m9{j禜[O">&b'W} 9~$⸟ e}oگoE\{؋maiK%qPg[ҵrKh:yI{r~#@Õ唲ɧvao'f<+ԉg`>Lge5𐆿W96?W3ֱ]E#'ZH#0Apu92G!uoIqkUsFBwT<_׻ 1KFn䃠Ru6rDcDFɖ^6D:K7;uY w j]x7-0t3AǟPoImor}O0C _#9ϩ ]0+( 䔬K\JKz2ħNt6MV|0|SMiދK4-}2>񚚯b0o0ԽVϷpXl dvFC F4bDY|ZCbq(j)VIB\AQn3Dp뭿rYͫրhA>ϋåhhySC~q f/1J Rx ӒvHs^yd7U[DФp+1 -?jY{ -|VgVN 7 y_\̹ٕX3\̈́ V[َyz x`.k zʵCs~3وMfHgmwcXeED ?)1ĽAºpN=ɓ&MС6ޚ7F=Yk>`dꡞ?^`E@i,nʾvlU]_BC|c=O{vn?roѹs 3hxPO+ރ J~;0/2lN2a2p_KLgN9Nӏi#$)>;EV,(D2Akz' )>" oXo˕[,5Z> |1{m݁v}?gNY-n`=(AZ԰dd?W2ZXd 5qJ'N'F>MCaS˂Znm-+^UꨆK.'\dl>l#+ 25 g2d^ SU?FR M=S$^i+FsLJV9ҍI~!99滅ӸK̬18vCH;v-'LP4~LHHP@>(;d( >X.*5hҎi">ZLij|률}Z.&^P0gJ O0UAo-#aCo-BgeT|f^ DFE3'fP8´$>fY,MqY5L0'qC YJ*1gw˺ٕzvvbt^*.{TD G~SݧjX4WݩU,R>A߈Bt։%-)ˤC%H89pLzv?A3]TrDZ֍^zYcXI`OL߸=tZ+C٥͔a!.*;Jrw| 8v9P .7MbA8<~nnajMc3R6cv; k/ 3AdD^bWH`b]JI܂yM1ENŊ筃e~ 8|[3/iUZupU!aWA'cAZ8?v aQB `W6HZn`؍)({dHs/Lէms{dVվo % 4mGS:Rc=5r;wP}-zaCfCݣ2= yN %bx6FJ= f7A%9|Yh`xHLA\Z΁[S[) YhVdGtb"k~edKuSm2ܩo%`Ki ,nK[[͓̃ -~ޜ1d1y]?De|D ap78jz 3K^HFH7[k=*u~Fk9ss_y1ʹ:Ʌ*UK4لP/*`@c#'JҔ_Mxr2[-gUzdܟIjσY4ȋ hgut5jPKCR)'˱Fg ~8~}>Eg$q3N\,窂%Gh޵QỒħQH^f"ij iRKBDP _6DTwRIl65cI ! פ83Bhi4jDo -C=8v`=?&gmGWAKxDV ifTM4^c5\5]ޕ1IWblG.BB(ˍ/`Ti=a ,r [iw!߅ _g.?]מ$Ķ1l)/<ʏ[桛s!"#/rb[@@)赒}`#O:!vwm,baH ϒNЃ_HZ`F>ㄏBbG G=l[0;20ʆ- a;=-ujgO ["?m"ߦz1`ق0&T6C>%ԞQ jKGDH RnU*(lxeL,xQa^8wp=۬hz0TfXILQ/f=M_ѳb h)jd"0^#GV"38-nṋ܎VŪӲ^K@+dߨqkD$OaN㙵?$.*g r9 \:%g--S۝+y {)|``uwzy W2 J1sRWO3~ Sk pRal_z>DR[`J}0L e)4#'}^wx||uxy6M3ȾKJ|CSYTvvs"{ ^4s i,c+o^F|?9]H_WmIDbpG|4|V+*^SMt^YtKQX=Iyl|_F^7 F$k5+ *Ia34!ІM<2iX\14wЃ&nkʼsM߮G{p܆#uʄ~Che}el7h$:@Pi)DT<́a *ms@8&/``Vb(Z#,.ѐ)jqM<+2}n{qじ;.*IC'a "jE *ޖ俑nx%ÚL3^)'8^⏢.@+svZV}mogji(|*W74­̊}zߢۭx{k-Zr=  ba:t`l!\' mr!#7Rizi(9o|>fdwl*,2@e>r1K-u'dc:tl ;Y> W]kpڴgěQ}ٯ<\l"UɈhn pE~i*9tѦyAB;u2&7|tѦW?ེD`_IJST˽. T$hA $uU鱯T"a]zwX.AY7LrPya(x'ץbZ.Iͤq{ֈTw/|MoAHbлH^su3?&0Ͻ ɻ !Hh )q͟^Y,~i zeO;lOğ˵3[KBG!-8ȓU_Oy>GX0ـ V~x'q3Yg y"ʥ0 Oy {ǘ1Umg+.LX #̻YOڮEkaN+Th` [JZ"jJyָyGɘngsz0fܓS^.>C1ĞV5C~b~""CFGx-U.DxEM}N xN̽TA .`G|ByIFnIlpߏ[Yl " /TݾR}lNݧ< b^ùI,,shv:d\Idu%6̞ʙgtn˅ؕDBNS[F6#QSg%.0CQTxؾh Gf+d0 e+JM!]yM߉)t#?tiz91;^b+)ү ձ";E%,?PșG6S3kJ"}-x֗vzQ"qW=ZP׏oi O=q!~:3rwaJERwJfkE358A& ul[ >fb? yI%C &T0LK:GZ'z1z̘t]A5طq$= X$XYX=[YS꫎YJ@@ %I_5$L'@;0]kQ+%"1$}ɚCsНnVôwf&L«[W691%f0xXa6V/&1Sm)Q]%y-"3{:PY,G;.ES#iИ'r>V2tQ6dk\sxeS_YhssC׼d\Ux2{gn%^̡-y_gaռlKRzo7Q0tCϡܘm0wfՙM!5!t)*Tʒc8I짻}}Q &@=r a Vs)IV1 T1藅=]f֥Pcaݬ/pQA*׹YYF&z}VrREC)O#kΊj}8C3H?DNG@ksn@`ZL^/ߡ؝Fi+4)5Vc#?dQ_18$8Ƣ.Bһeŵ jJf cslfs8(>įeִzl^q|H;G:0w_ a׭b} :-cu5ȯ/[E|r%~Rߢݬ3;}z՘t*jtĵX"ytͥKΚ_Ԟ:T}Kcvfoh]ҌzQU;2HB%Y":'C!PA1C #_Wr{5j _˩QA(l=/x c)~t>tGuR>a($6^9Z:TQc/X,?&%tnEAGjS+E|)I1>FC@1O>')*` ؛}ps6EgC~.eZ/leNz(k+ OpTFFglx"EKk9ޤK7C.:Jtwr@ʉkƗ#J*pvF*1?xŷKw_FwܼBzQ̤ɋM>`>ޔ)8ҀàHsxt,e0@6YhR'ЬZ25˩# T?N.Ph;#d g5v ¹.i! ƐRvX}o6\R?*ysTM/%h`>mY:%MU3mN8?}qv rW,snN0m7i ;emsm+ZUqB@Hy?Qc,SP1%,؉G|iIW~^g UZU'Dع[FGmTFxi(o B 7MyrV;\gKA3U3XǀAA4ͷZ#ȍmcQWt_>d*Hs @U1M̄RIVD[ 5vD`񐔸i!И65̏$t&Wy6(FLBhקOزˆʤ=u<*pr4\2n%A5mo"ѫ,7 sL {=w ߸a%Z$bL :`䀙'ׂ3Psҝn{-|3,HȑLѺL|d{69F"*hy2^P;xHkZ z$ |aaHSIhߧ"]cT~U-7@v{}( ՔjI%JFs9~ڠ8Yލ."lJflp=t HoQE ;P'?WftopvL:A($dϜOv͵0ǤZ$߱Q 1qNlupi'YahY$J &_4>AZ$6%M OF˥A1)$7E>!tUXpj. g4F"@g|ΕZ蒚t=Ij/C*/v1P:`vQk`ǁ du+/>2k\SELg=RZūE}|g\K@k}†c2M T_ND(,49%RHݴA(y*#OT0'5lb2$u]Ur V/]pgs)5|18ʟ2I<:bծYmiʠ83hq:4?h/b4nߤ}~9K&a8:gw ,AAm&};}\.X.)匒A*5r6Wϭs6@ >1? aPz?Œ-MF T K Okgm}K7*Q1Q DJht4(QNFddAAST&z*ix*13(\oTyY]8Caآļ4EBJ%T V])H;Xz fyE49LZFI6(4DIcHԛLFU[R. nA!ŗBUT^E=fqڱ  '8AT4ξ#&n kQ`(~i!y[_sR'}:bNhZgdy,-ߎU7T`E&=q4kX4dg=vKj$>QrgU==b{z e1g(Xdwn ̍i+nr@;H-Y*O݌ Q꘬ Jn 1Xm0*v<t9ols;8ȷKϋ{|YPb]:''1b&扏9I&&W#Τ?ˆTnw^6PH,.ZVa0T ]&MH3btNEoBҞHWoɒ`zɑ1Fb{[![{ Ǐ\'!_O=%8e)9߆,Tp<k/FT!: *L !~D8l(R7'`b*$g獯Mv=%Ac`btVef(߇Lj0n:t|^_OX( Vp*}V{RAoydEU.%D0#*l:nNpwKZ* 0(!fz$Xń9''$lf=puL0>e6MC;Sr" =@gR1 >x2XSsWkkسhѲs KXKDx _*-7-v~6djւwX&I'=2*$#G,N`#:(EDwbU"B&.'JҚm,I%<.4uBǏ)/lGDAjsxo7v Pgr3MΔK8++_c#a8VY.ю| PHK,\/JŴ%m{x@;ij`\y xCVU }T{,Vv͵! %_20iɟ845rwwF> &P8Dà# ^"baÔ #J'=E+yg!)p%QeQ j]}G rb*׍qدdg2# ~ ^ *y@uizM:Z`v9#9ᆕ-m4Ӧk þ/\LCkL R0DzWTy۾BI0TF**e|f4*hZS&;@wT>:*oo\  0- zEs6d]sΎH1s7F= `176 rISJ뚖fTӃ7Q^;h5IOy%w= j|mD"3h"u+[EʎM\_ ]!B2|) &F> Ee)[p*c]6BToBEbfmcD,|^]ExHPzu,zCPfS%9. BiXW2|9^uA@p;h5Bb'I6(9B ˡ-0i%Ff3^1-x"].44CWf0dzk _[lCnwNUhit}!y{&wa|_D^!FM9[E^v$ohk{kC7]Y(QM o,NU 0oׁyUaK+=P8-N/7ʯ=Z!F}hMЬ3[thyg>Ӡ qEE>yq dui𦶋h/bugP6a@qz ؏ ɨlIr4)6/AC3Jk36|ʦI5,)ulˡBd{! *]oV<&18.jwE a) RÉ0Gk!7G>ZFwg BqOs  0ًlP~7'νU&2}&>SY= ul@NPƳt]A;6qhN1 /)owB`,؁D!~)HyAiF"UiGN*ZX4 ˜v,sF7pJS:6eI$1ͯ3 ܩA/<:"O^]#?}]n0uJ o'Xak2!jg8lGhhs]$q"^M {@ɊVp|[YoIXېb?(&s]#;uctnqkn1n05]2WZYZ "n2M*^Cl #&`LI. i@u"HkBcϽt-`9:dTPu^XNWf%4lٙ$.-#->Fᄢ R (&zAzcL O@Gm"F*13B.#/>m///B61*bǞ=|V? ȑv HO0_St۱eq̬nݬ؎Y J& J"Z`Mʌ7 p` A[<ƛ<])вTݭ8 ` 槼}rsa 8\8bFܘye Fc XD=aH>(uqz}]CJ8h`Ʒ1σ@떮vGcV hszxDkbu(B|U G?_n 6bodض{CZRŚd {C_^yD9tճ0OUg:^i4z:ьpaqw;1*?"0du$. O\ҽm4/|L>ۿ|cbh3VYh]tpf^+[O2=D*/;G[;bBgoz ;*$K^#0Ԭ3:~ jj p)qjN, TЦjSv3="bpSpn5>vBLj1X$qou 藒1bH# r(o'Q ]ja=`2jC .^/gxHHha1Hei*nu\IR[>%[ثdv { W+ˢs% T|ӝl^g_h=S.97P;$qnH;v(/UU@TpF*2ljw'vp]P9GSxD'0WtTf^Rȷ=`D0OoV2!4Uicz2!O'Irجٵ s R#Auj{3h Lzv;Em]OlyanN#ʆؐo6HH\I.XDž kУ&yMI}mhhaD_Й0 o*r6~Yb@^Z5qmAֺP$BkIQKgNڝqrU!JR[ 9%Xq^/22_O{p_谯r4o3ujۥ̽b-T!G;Nvs|]#^/ؽtmhe=сljels6j`D)5R”iEAsRON嘩Ӊ: (B$)oT0誊B $2]0TsFʇ6edj̵%-zwn?Z>&Z#Vc##STo48x@gbJǥO26z>2}t47?0nRw Ñaٔ boCt[Px7 7=r\̫21\dsDž QЇ9-'yIH,Y1ȸgpIuEAg$ wE#LV‡;SZ&WUDcWgVZD/EPg#͞ #`aYz6S9WeZT'# B2hUHw U=s o0>@%J_O{v%o)ꌭX!+I4j{HX1f'*Gֻk:: :ERAe!b7lȣ? f;U9W2[ Σ <X:{ס$wC#FMuve2ofMB89kk9E2.]S3($ 9AxJTn yQŎJnk,H?R"KW@ m4UVeݏ!xW%(;G,Q8gH CH/zN,6r#XB 2o 4b)ݣ͛ kn¿v*?K UjD*9 ( E\s!hj.L׆N!| ~1ɚS{s0F 420E&A]7=f]IE t) 4abEZ+AJ1:%&X ,pag!%d/p4 ii;02QiMmW/QHsw(~^PF=RF8=w$JQшEQ]o@~ZkAFF 1#8וFKE:]@12kkjWv}iJ36]×HTaa.aqv@|*_%k N1Kh]K=Κ13Ch ؖK@=$pg'QUnBB%x5~IPIFh[RƟ |wͣm[oȿH|I`X;@X ^`9AүI?c`2fkwͽEf Ա(lf"vͅ/I:3M+"/50H%Q xaQi6EK;%μo#㝠-L MnE 39|][0k_ A-[xx0QKP:oRr`!SڡRl 90ܺjjE,HcSO6w"sZ~1gJяv S)NVDiŤiY_4抹W43)p."Uw"W!Wqn1ͣxwG5q]O /aO my0j4jIHUC,"U~XQMwN-[q -T7sN+M{|nPS=oĒ WRf a!Ye*hIM]'Y q"{}_*o͐j>5԰Rp˹߶'yn? ~V`6Й!bםπ$rsr5C5@'F>Y6o\!lw+ jV7g]Q .4&Y+R@ bRk]9oC8$&kd:]-hz@ LFGq5QL8ox3>>zh;ٶYm{q"g/sj`LRXWUa0{c:'8CrVx\7`H{΀91N]B+V 1ƭXز ]:8-*E9 ~w"fyD,E->sH4-[UXdDe_s~󅸽`K$:nr[bMd?BH C EUUN>)s=ц)Bp4 `ӹ= XвOgLZ&(@q/b/Xc-|tZAYhTf5—Mה-a^w#Hwѕ\FfEQ#j?kWAcDi}:7$#?Ϳu-"aNZ!*gX Kh9{DJ؎&a%}0`_ԋ[BTRhva!ɩdKy$ j*V%Y'"'x=C3~yʭ$҆2Y\6HbA$:%no,}ԿB ^cX_BqK]lkB4D |X=MyEr VKz% W/񟾡UGWQڜkB/jmXR"WI@ޜިvYmT^ <^O@7$,vc{`8(N ˃-9=#4JR@ (`LiYIV}EB?Js Yg;މ9|U\T"?]Ŝ`Yރ}3i䌭_EE_.w_UlY>hѺwGw^hLKҎb5 Iv[΋㞬fU܇M.`r HV x>0V՚c{:AXi:{9MLl$N,-N郥H7q+u)_FE,Ro 5aE7)V8s-&ɳhs>KE[u?4W ($h9j{{6 2CH[4@cɈK^_λV3|eAAX_?m^Tlq+"7Q(6EUl#hSOA S6OZe  G*A-TTK8Ifxƹ93+d˕ل Kl &}X3,wG/eK+aFS Dphݡ^dxG1Q0jw.`i">ݴUaR1gZKF`vS*IƐgZcWsyR q2J:$KA?97r8͒Ԟ^lNKq/Ԥxd m:/{hᙩ"UMbwB>19(F|gߧ3aD׀G]iϳ)w tH"cv!,\>l|tALƮ%Up<3Ε. hy44hU-5a?yo)EPY+q|ǜI,@Jݮ3^:c^ՐST%XM$4I٭>V8Z;FE.ՙ+I"F.2gϙS^xwۨm. Rm7~pAG*sK7j{}f%ΩAt tP?&q}:;&I!;Cߪh\2{~gh3"Ȓ }τHPΏN| Om:%S4^VHa=,X }'V$cןO_Ls/AQڪkJ5ѥNyW!7pq.x)UW%h?dowKygJ pNV{N)M^҇ly[(D2<ܪ1 5̨47 k^dY_@H}HxɱRmO"H#-`\w aim) 8E`TC| i0XVud5-|PhI\5F%ihOcsJZ*PGlU8&/`}+FikV,_M+#w.<(ż@Y$ 'n_q?$ee4ݕ6H7 ~Xn|0 A&ƍPhjY39v\xs:| mjLKΚVЄ\r@ԪKAoXd5$.+֜tX@L,jP do`M! cOk1 پoe Ԋ_s鎛]xҺSoQxޒVN$Ef'ǟ<_f;.,^_‰Ȃ.5QޒgIp<ݣHFP0ٸndLWw׶6pݥILݎ{y/;t$3-"~Iyn%ᕡo6%ꁁD^ӆg&WB+錉,&'1Q&. Pjd :$ɲ2u|KeTMYWGmCn\~3O{P]l\p4IWbx ߳uYG$[Zm"㖎4}"HRӨ3%K0 9DY:jK@^xsyY7)Ri|{M=,UaE@`2!Ψ1=bjji *Z'6^p}wCWÉ!F T;O0B~uhgVV+Kyx";bAbΰnQq{Q7-CӼ y ͏yuuFMkGF\pJf! k@u. V.ZJy6b[f]p(8I)5zk;14[&>#D:кv\k_< '@_0 C#.]ZW$㒈ѦJ[A:@aCZ`E4@}[4X,>P+Ɣ-쨾YVZ1P@{>,۾VSLskHop?{l-č-x;(!ԍ EZt؅.O~L:">ktۨDLh*yle \Fۤ\yj9ص|;"S_>;8gA\ 3r+  G4 Rpx۶qdRd7xr bRaGe uHilmdTE<*0&y'iu442nا&ǧg;qC`7i4a:ڰ_#Uo)F~#KeVˇ\Mz9Z!'u[(P=Gs=)Zn,vM&L>3WZ)q4,eZRܘGPd6\6.GۻOVߝJ)6ڦ;c5矛N3{mR~&P[R#ZOcEȹḕc65]j4(irZJ*]3ν }Ȍ>\S#HTvCz7 dٰukM#jOܹ;{:Fo\8f4'H_$,DO,+?$>DB#cp~MXRy.Opƾƥ ފJ[ѤYQu8QdmЦ]|CaPedFY-'j[GXpfbW Ҧ j9p5ʞzcޡ[x4V,",wL.ŤcHAƴ>{HE,:dOΩ5`W)Gؓi Aò 'wvG@g;9pR? eESe, %:Je v}O5FyOh3k!e=Nu:QRe_g&ME mR KXd["Izc)1koc4@ +zg }>jXB~3?0j NK‘q,r94- @WSK B\ra)^$瓉xI?q5n}EBqDiT!(A?] }Sz>ъL^07a준8uV^olk7Z󩇤kRq鵁L)_S T,6iK8x>b_ 헿Wm8+ $Ǩ♹ݞȝ2ra=s_"DqoJ$OVDŽx$'<&?O|?Mvo6[;1R`aO%!_8쀶U=b32̅gSd&h53,y ;POgpĵ_sHw,DQ.B$ٴ;NoBC>om*Ƞy #wIVq_8ͬ &Ώ2z _fsZ魇JHѩ?Go.EB#ziᙦ^'0(qzL%y$y.`˯h%Q3R}#6RMstMv܀<8T1(T@4SULxL9%ӪudyZ<7BˉJdaWߊȆ1a/03?R dfMt} eLDSlu)qx )JFTrd2}2ޫZɬ$g~X`" eRŹ:$)~k.cזӮT,m#6'xAIk#QS(d̒SMd ru~i2֙佣#hhW?OUaO;W;$4-FBȼ-iȜ*$:Ny8=ݢ/oR6oj\RS51ͬҎ:3Ф^p9eab̉A9`04*\{lcvm ʅU5W Z%>Ͷ 00L67lAtw-PK5[3 x;Dns@Hc,Ne+B}]] KסEg]-w17/$ lU'cԇvJS/WQC"yNfK<1C*Èw`8÷'ec5qn՞>]D"?vj_(oU<ժٚ6Ū^ 0`PCTx~Nn#9h6!w%H]L/4󒱣}ϩ钟׀*.*PEs_/_?cМئ󫟆JUx_8Ұ^ vqpSs=@' ekK$jBgOZ^ yRSvbx/2;y7; Pv]gkwlq*.MfZ#ދ2sIX_סqC0"6E|U/v|RUD%I1#./6jTMB-E FDͼMaPe~vR&J~xA:eKԱX hۘ2*aoko7E]eSYSU[ז#53OKdoj&I[c V4wh`3ʙ"+u %Uq`FEZ;;Ҳ$$H֡i2p=i\Tp;vͬUIMMrf%xw bIM%Iđ}rShW2uniHX E(b/3.^Mb@am1bY~#&Pw e>ACkldv[5AB@'\ phxӰe;KG|s8 lt?uwpNufPCQF5X&ηŁ=D`ҿW g*?>%j,O{֋Ue/it4ʳwˋ.u %H 5UbC=:ޕ?lE!LP+爟d H^xJR.rXzaW$T` fGxF =Vi\w~h9)Tl3_`4yuxZc}Pd+k4үT?_@bWۋǭW{/"k6~y,$B9lr"]r]n.{E -YC{C(Pr<;IPCkZ_Eb8j7Γ7T:Ɗ%~UK0d)U#V2*Z`vr(m=d C@+Z],/!Q1wmZ~+p*vڟMN}8S2*}N%C\1nә?\76K{;gVe|SࡈK<-Ay~9}w9&'y;M,*X{$2E&e-'nߵ"5X F{L̷IqHj!D#~"ـm_|cfʝLb&5*WEb:*s6K?9CpY' %j-!iinr^egz4M{Oj|=x-cK^}ߟ+XS$*,Y'' x0" rKZTuY:\/<,6ݷ \oB}cR84'8O!7Њ.CtoS1; }6KtR=DƉVo7^Ԉ 8|%+T6#@ڑ[ 0#OGsk;*0ߦpSD->Нg>UV@ФkTF%xLӁ#|nfM>C)OIMF ^?<g3MbQ^ f'\n[.7 %$'Cݶ5z{=dH<zލn TARR]6F%Z ѪXirF:Sl@C8<N 91,xQ-˜S Ol+*wM޿-o%'+ЀoȚz>D@T1<'~V6[&%9ED{0o([D│/6,+޿O^o BtV͖C.1|'y6d1|*dBˁwJD_ $SFx $#t:۴^-.C9@b0:BG@iTwإ STf*47S7w5~ >$ys~iyd ˗v"+ hZ.21uAERL8GPhƢyHM wVW30 ӵ᜔}x,L,z豷?JMApc0G!/| Pju9.&*Ky5\No"r447Q'Ul8hJFsAh^/ϒEp7.]`3D0,"\9=Cf$ȴ@p-0eU.g%BZag.H^(5]6Z|m/luU!D.u SEj67wmc$>LX؄x:}mX^^@ 9s `6"(iB\kY3qE3AY6 $sDZ!ڎ9ɨH(Bz_JkJ[HDfn zgf#u,1J !x5X%F+v?>cq=:)k`:m.n"+IȄ2SM?@ 1a99r_-tJ%Dq/8_M@yJ`/")1?U.^C}pWXǶŵlN$$"6ۀ}ǨU2G9?G D\>JE|S'i蠁r2Ď@ _YTfݖf/# pdoxƉ^ V.S4O Cs=X @اFXܝ ԲȞք6!'(1?I}}ogГ$XPuͬ#B.&!nr6? U|nP7Ȇd}h7#zb pG QT*+gL`I' @B)=Q3u('g}H4[ZbwXesX{hvzEa!>g3$vGmdE[)H(|V|bP~n,H; d#njs/Igtk^cJuMm+Fथa[s4_E,U)gDMN4ѵ~]ټER^]?[\`j^FS"k)U2粈l-7adq6Dm^3.uܨ2ICkHinlxa{̜ LUH 'JifF۸#RVO>˵rftR}jz3Zx2f&yTPΞdN6IaU+EjB= &x(n9txFD98 BQ~lf(_ٽ,Ja ĺuc"܃bE;ϊR%8ukGh_b7;Wz$5iԁX՛FiY>Γd9=OY%`7fJ`ؼ%JKMd'#bisR $<^ǀ#uKҶb 0LWp``"i6$xq&0?W| ̷ϭzTqt AIS_y=!_$쟴BU9F$kxD+3ːXΚ줷&ppp| U{А e= oat2wѬHp !K|r}ۘ|;8 `ʷAg#7Y)ɰ}Sݷ@ "sc[OZSm0K^=˝>yqR_j@ JD(iZu(2=t'N'l8@qeV^!aH 0zX E觪>rU<\B٫s F*s2X):U0EŨQ)bH.#ꭄ 9nG|&4n >Ob{o|~G1Y3}c5U& 14o<0푺8,POM~ tX)=M9TRM㷠=4$oT#E$d b &MW9qd9RF!Q^ZwۤJDФ]N;j̗TR-$96G\WɨQ"yNNnu~_iٳjS~ >.!~V:ҙjpZ|@SOH?)rX4N0C꽽tm`%AV}_W ]{( 0iu %%!2N xYl@^>}o`z τ|YZy7y1OF_A/jʖRQ7 O;g9j9ݹ/QcsҨ m>އ?fpt&L}E{PB'Uny<3~N}cn6`24Aj KvĘC@Ah > $& Yuxƅ\N+KHiɌY*p %?`ϰk) ۴t#fW(ChI,Me(:!A#u\VnE% 1sCRT¾_F1T.1&F^ug|0Oߒ쯓Uʌrs@ʓ& gdQ'>(BRj~.L]J;{̵Io0T4Wt%MfGY)jDʘ3(^n5`8-uYPZ( ػ@&Sͨ \ %*`0Sq]vTALʀ_E?6W^E/iZZ06 GBM,Mi۴ىb?) ]mU54M,WfAtUP殸x$S,+L=+Ǫ+&O0 >8@L<٥U>LЫM}0]4@(A_V oX+v׺#(o9r:gkf>SL:=]q!OΓ7>7[ S$A|%!4NjGQSfg+Յt)~/يT^/NsE0 i :q%6jׄb/c7U}Z36UZ9o?1C`MrA av*BXE>6Z>ވUf dxbMZ}u >ِ/]:nOnj }/eT]T.b)hѰy䐇:$x6M RYBfwP<`sw7w2!qB[S.8'$08,EB{vsݪcG& :ǶÿԚ(i|tiȸsQI^9eCeϲvفX< N42!#nCrZ>%aX#53Zujc,o8/ xԟ*k4r՛64=uhS=hE܏Dj!J@QffgIz@g:&;Ca#].f+zՏW6(+ͺ1LTGPz# Ao|'/m oҪZȇ?2q!C"ܨRmOoncUB;~H9X*OHppGړ@u`ag|rvJ`mt1Ͱ |b&8:WWM!c)%Q hub7#Htb?]ƣ3>?Wn;/x{4PgSŠ⽉|U9N@Oʉg,$6A*Ή!(E|nyLta$';I s$E/aUSu:eٳ[?|d+ցjp2GItnkIIq֨z~8E m Ute&/x{Sn\Ѥ0Ԍԋ&^!89_I~Q5}02[l{bs|N⫨-PE8OxFMwļcZ$sqQ[Sˆ ڐr@\첬YxV*nؑС*sVʖkSPCULX8$E{_ "Q\. C.ޔ]@XTe o*]`h#87eI, 0U4LN^)JOz&&E=ywix籿X` 緕]S W[m  y"'6z06w[䃵ܛP?W grډYi$|}x$^Žu4Y[5L9IQwFsMb%_ɗMW ;RMįoQ?z}Th6"[n 톮Ѯ})T"3ԒXL lψ@Y$jJW4G.3sgi|Rs?1~pvhI-:ԋ2;vȠUt'y)l䇖JºzĭV'o6u+R[s1\s*d EBs;-)(ϒ1꯸cTCli02]AQWJ߭HJBj*A9bF$-9|6Hxc9h2ۇ-"Z>sz6i ֡HJQդGk WezzEl+LԽ]<:V.pZ (TLSPa";R {$$j-8!_ړ@82^Q4f3Z@wCarcUU O'X5CrrA SԜ.b ]*Pc "9q\}=C) +<;'wi3y@iLF֒rwvHK%1572[hFAɂUא$#Gf^}je [>I9yc?h$L ,74 Jy*-f{3OqYѻH@1NL?IYMu!SoܛG? 6`! ,8A6'~8?)CkMTLorڔ TG Z&/kgp1k FFǕL}%78T;Q^)V4^`x^ CZOW/hK4@ŲBj1mS F7Caqǭkk~q(Ślf("(B@:^{;lxsA4,L>4^%:Ћg*&_ h=Aǎ*fBاu~r|&.'ޮW 3+:bmRBq=8~q)*E6Pj`0htڔ]=Q~-n.O50 xI?~*@VlB+ ͼyccyETҪsm0!UDT.)҈lZa ]LSP% =WmWt5sQ.m3(빹r)aisHdž̦LVB:+P)9%9|TDE{)k_~p`zqxHx@"R\KPrM"S8>G~HnQ Z 5劢?ИH:|R.,پF W?lDЬ6\ӍΩPeyz A-z7CSu V ܙtl/x頖9ڢά]*^ѩ]jc,Se脅8>ZSG@{'.pz4,Y`*콼2朣H{ r{G27ތ,.nI~lFCD >۸Dz?Fc .>8r.ORvN\>MXcR[Op'!Ov9LR(su\] ETP+b /1q>(4 1e,u܍8S.dY&+zDԚP,/:*=]B&cPX[ FѼIϷƿ6hgua޼M4Mj^踆lN3gDdtA0}6 uZ;)UfT<%ɕ&d+*}Ľ"ג7)㕹%GYHy0Ւ_φH yA\(%A8*4mY_O2 M 8 zTM:@G fBcxyfmcaި&qQB:ߦ6ׁn^tJtçE7c@":퀓J,]-jcɦ\4iΤ}LF9;+SiFo̱_ v[ZuP\;ZIa :ئuZ'ynuZh1[ AMl)q Z7%T} Tq7TqӏIm7bc1^2}qy aQK]*&*UzfpΪ: aܧib^+xh~>XyuIޑD;<v[mͽGl>b-s|G`G3Z|f6̷喺^~[)B9ܝ!_iriko7-Q-%#L89GʓXٍH>zc7  s+l+D-4$jQyI}` W_j/bS1\5R=;`vHt;&.QokOှK`3u|GY%5wxý(knv}Cě+@l %&\C¦ BS! UroV5zmRAЉ÷?@ ӓ'R)#6kSp28.' :gm{:?ՉkG Ϛ},ڒ :b4H Z"t.@(*l~`ޗn%Ѫ$"^k#7t5Y3?[EcC4 ρ›=4/MKQ/8pxs X\ xA܉JF)"ږfN- @WV"6~F  j GmWurB%n> zWIaJzt`t%Q}yF1eM:_2m }wԖkb %V)FǸH#tQƛ^{Ө;A1Uzx:&¯F qןݝm$7 e'=wJ^WCk wj_EGZnt|G-Wƒq7|t>K{n;ezEû==ZٻNcB2ȏ'yD>dXG\C$%T ݝIYs C,+K Fcj$2,(Wv gH޽lT ][W5c6W=F[o.?5iU ûGY )CKԦh:d}&JΒpRD c~شٞ+e(5)h+%\W=S\pSx :2]VE먛GK>FjZ}h `,JbW,<-nBRHpFrZyvOT-A[l.Kכ{FqU`'3׫ӠTAO:$"ST>MF %B}hT+tm>R9^5meNBV_{s۱lSo2֔nRo_n? uw%dEsLf 4ZIN6e:,is nWRg{2ٌ8YBM&Zъ_z}Qw^6 e8|ݨrLPZCEJl j2.yJP@,M/?ɢGc8j `n:CsəSĉ݁ 퓸 T4%5}jaLY0'ⳕs#L睾4#6 #87UBo7{Di~kSnJ(Y~ ř.z4B˂R͟ug?@C7#h[=?Cr;=ZfbPxGsWல7r9?!$bGZ#@eo265N2`”1i>⺎Mc7!{!GgB]K"e]Lv`VRZ#h%&$ .'E_1\{\-2!C C[ц49 FL1tRs:\Y@8 < p(\:X89}\J-fR$UQ%0~juݬޒk;P~F,k/Qd_͟t{+K Lݴa ^IJ,x-tGb"Q"DkDsߞDt$mv +'AoO6Ez}+%Bwx3uFf="шh-B"Cq\};U'Tf89G{%+2w9pZ$!aLncX d< 'mWADKwr}AVRUem=ocpO9"~B"SRqR1ηo*Cuc.3)"ԨyQ; F7lZΒQ(`jx~*&ڍV%bBWN0BY@l?vtfvKc^(ꟺtk ])ŒkbbufZua!SE~ c87u#ޖ%LYJOҸƈSwWhŘiGhb FŁJYp1<$FiWp>V\,  XuTy=;h֞Egŗ)X^E]Q>3bPG֧l|-aE{ó$ƷQMܓf.\S_ ^aW֟ )Cs`Xczp6襵: C$|'"/T/h~kH'HM9` juvteHI'}n*B;lfwaʳoV)rmonaVI:FrT0hַ=%lEz$qZ))V)oee9geRn9! *!(jZX"Rt8}VV->YhT R8)' Q,4 Xw D"w䠌, Aѩ{dlRN`C'.U|cS pcR嘙Ҭ|:C[54G;'|YVs}AkUZ$U-dDQt þMwjliYβ=M.Oe/35~#ڑ9E ||#;ÌћI@s9,',8t0$; v^8ډL¨Svݎ"w8"\EzA<9RhWt2rIpvjĺ) ,I=p/\_K>C!Y̓7_ztr)EK)TG%Q4$dE"Z̓yiNI,Le8tU"T[<%Dgޅ*kR`T9f=azWbރt,3B ;ia < L7w B&2zv8LR+Im ŃRM.%j*u(Pq zwVhӮ@_o TgpN$P\O8=K`LC9 jVޔK9s +܎:bz%Vە,$hI<;_x#͠1..AcG VKH: c IE]\!*M"R cs-*%>ؤ-KS7yXjjiKO*X><0y Bd,֪'V(8^^H@P(d0ɱhxYY x%^?(L[K"q[QVZ4z,yt#7 .Y7Uwч\?-Ve

K7jov۬뺢i㕮y=u6y/583Wii·F Uwq'TzohJd?o 06d߯#֕7x]Ea-;ZĤF1ڶ [:n^>ϳiٟkq2+),d)ȩ2$y :CW(X܆}Ωwษ%, X⯊ӨrJqm. u+~Q,y<Uc'N)rХ-'{bFpL'h@n&SD+sj'Czp=-mts5/!sGەbv0@q;1}>2 VpRb?Oa.oE5_fSj? ۶|85u(rzlb C} g IͧH `UF]< S#ˏ[w,3Qd칋,5kk]D9^Af5Z~xZ'![(%zՖ!@&Z+lmY25=3RSfgs@"Y8O3ttR'YB)u*dBbB6ZZFj+[f z4:7T/)۟z N=Is!w*''H *z۽WS]1{׻̷CGlb!ZGAR QA%=s!9|"CZa2<-M XKIpzcZY69fQF~? fTQ$4WU6>M"CCbc&1?6Yh'|n]")M=Y&Zx/av"D9,,c̙у,hr]о,cԁH:҂C^ERcM&av =^S;jU`YAFA &7CόjUR~2feQ_ijB;2ʣ:VW^ n$뙍O L j>@5f;-\\hTCu:َCWJY(-5E񖸇hS(oKL<βPqUSBt|L৴0&J'B Fv!P9B˘chRl/:t#篊,Y^2֋C AB h 4W|JgX8Y:6:1vէ5o'ZuRxM+Ox#z :jA 0B׊'EASTy]Kc W[@0!A.8@$.[j2g NUM',~Yh3^cz_ A3LJI6-_n^7hWf~:+ݗU+/hjYO $_ȾƦ>)#5gS@EY[p$5q) S;k\vC&3 {?s@{W.$[ ^Ca))QA߸59?mK b;r(3'vbO7@ H ّF~( xyv I0y Lezw4DOaĴ3@gQB[j=;)L |QϤUucjF۔ڂ( e:/SW <>FG*wz2ۧ<_>fu[҂SHԗhua*e$x'/ @JEtՋMꓡ& /T=U[z!HO@aY{;%lʧ4-@3C i:&c& ?`,JG .[{(>VY؎cЛ.y@ B=u\@1WjzLlF:@!$d g|?Ɓ-ZbkVEwtaxl'S'A§t‚1/*CA֥Jܑ`#'m W2#T=x_ZEd| n`Cڟ]v4M 8zKy.;]h@X,eRa2YnMPe<5pz~!,(0!c M"|NϜ0rM](i.\c?A>C @GJ渶!tVM]p*N7"п0_ւ` P=ؙ\ ͮ$Q'FDS@f&{o6*o}2҂MFmeY7bB͈Teitqs+a-vsM#92O_3*<ԑЌ֭_ [Ss.N]4'ݦb[Emw\nj;Bd4wOr$ݐ< mĐgwj!ƺeK613 "F-J1ٛWFXd$$z8~jї<' n: 1VKbVR0 PcLjZVGZ\}aT@vH2b%/e8.,vt^%#C"iNPs'_KxT0elڽ7RY,.mKX2NJbHπ'W3BQ"op^VWh:*0,8e`AOQ&;݃+H_tkϼ/зJ2lM,c,5@nkH. GqaP'P@ #q |o[r!cNx ~Cs[pBQ 'c-/,|N+}!%'a3 '[5X_:f6wM 7_~ .E=ǟ2R/38Qph ? ;ւn4ek\D]܆*8F۞Bslv|bRU~Ƶ4eaM7:b6ӽ![: #G9Id6K(BVfz6ɳ͉l>"_ߩZ"mh~Y2sr)ڡ?&^Ils]s':]GQo9eݽ}g]j@_~ ›ipoG A=2nYHX6Bhݒ<Ƕ iolͪ_AVß}v(]A,?uL׆Kyez+'z<>8ufgє:5gŔϽN^_N0?`ZU&-llV gXG=$/C+_5f\ʰAf+ KQQ=qh㗲~x;סstIM4,Jf|5;+4v<ҢyB v Vm%)[L2YYZXDXU0|BW,Q IT.z(YV|JmRH7`f1>pnfwl`ϴeuzUt,_]O,P֎KS!CcA'5RN _3f,b$+[}[k0DHqk'x4SvC[08umL|sX"MGh;Ew( #fű:jj ί|c ?>V7ܒhb2s[Ӝ,b-(j,7l9 a7@HIl`g2q5_VvܻbE>yET2M{X_:QM 4bkwn)mjADYI#,fo㌝r0J}Vʃ a>?W0ڜyLX;ʒ)Zf[.x,hV&(r!ĥ|nT5ȉp.?N{>4]N[Kh! Gղ3GzײۼJ(.rVJ: .u,K> { cƘkW"t!I_8 ޑ#H|TS9AN"zP 3"(ZsF9A iDv΄;U%_6&xQW^@TKh)5()M ֈ?!T@'U]8OR o0Y$&̻opg0p 5>_m(/d`2l3NH\Z}ܴZ^(pf^w6roɫogI+i[ 6. yBXwZcڍV%v;TcN\% ay;MtC刹L ̙etK y$y^Л$~`5eVhCl\g-^`4CڛŢFg&YO{"mxTG(+؎t3pTl>Mt0`E| Ȣ9%nj^2ol/M4PY о"/u;C⯁E8ٙh ߟII\oKcW^]T덨ˊqýp]_<WFLsPbnlCDpsa#6f%EA7e]PLK:j ` c ]YQP2,d*Fg6Z>E Y,tUkYӯgj^7AT6)\6W"+k܇yhz3\_ʋ? E(0 &LӦ/4Nb WAӢSKäplDtƴcܴR66^ j,?uB=z"|>#|k fK]1^-y J&Dߓys+Pڜb4Xi2;-,85 Ter16"7fӴ'oT1bƘWwAV^`[Agns[.Fl\Z1 # jܐm!yE@,iNab/bh~x-|Of('^KizZ3d:е،}W,0ypeZ]=8Rb闻w9Sq(\0ĥS|XA*Ef\η3>tx02fIԆ?c}?bfROHo Chn|JzğbHk! ?(E95&e]=nRїP$.l="̛aqz#M3>b\nsG/isOܙ F.Z#`c0ZlhZ{,Ɵ v,Kgt)(҂4bp/4n L7EcLxvQmҘiaViـJخ?G?\+#m[f258Z'+`݅.[!GNSWn)Gj: t;Lu W2x׵p c_,wæoC Za( = b>a@DeK2cN&))l݈zv B >$Ww/"VF\8{ТO&&@ԟ~łXE754պ0'V_6՜#8[{xYA$ =`#t=j8ӻiEF짫9bEJ' J@UxLƒP." mp_vgh3Ot;><`kP5r0V+rRz\)(-`eV1Piz3!)ʥɩ9ɪCG:]CЊ}fc;9}J#hL ;/M1G(2u^?u.ZAHV ͒-j1InJ+$P( \[ f9AVJ$Cay_K`9b9tELopː߁*?RA/q]J u,{p(M7b($G }*:!̥I;Y-_7QߢUSpu#?_;^C:2gZOuMYZb+WY )I"Ol -,.*ց䏝/!S4FY5, <i8E*ADM:zcEw @'x:Yp>q)d@S1ӎV}+GQdj{;7 }Ogԅ7\w j4DfP̛8E=j%t )*92UͅߵֵF.YAʓ޷NCbL3'ht|fjo@HCԞzy*Cqgu`Ǎv-J%9ctd F#͹5m;Ci@K |Ғ+?iA]3N6 "~NF耥D'*$-.b\qر<ҶسGV _$?aghh_">_50D)#!*}~sؽ(dk#=2[d89,De<] W`eM֕>Fi°#Kj'l*TNgBE:"LN!isIBsh:w= Xūzػ̒T?Q0jOD:RHuz&{H1Zm!@ufKL4Cr\q5͋!:wIU И.ZեBL\6>o0Y9=G\$^{\1Б獼F X8\Pd)uo0p)^]q Z'smπ Q{(#GP#d{Uڥl@CbVEo̱+Z!}\DmK۾f曉=w fmJM!件2Cڊ3ls4ҧ,P;g(Ai]. O.I+n 9\ڍW71~lrǢRxWE7 )y,-gp7F_ڨ:[v\/[?@uǃ+ta6s/edAzoُv;h6t](hҵ7X-Ӹފ`Vke^1Àv4~;ƎMm) ă0hLďث1ٖǿ#IFUa O!B@eۼcĄI_–0wd*u%7tĤyy1%+Y>VJi40*=x#u!'S'N,Jl#[AV$K:wjSk-xE<|P]QGV!*FZǃ8F qC:SbwD@(\9"3Hvh,܉ HG" W^ކZä%fKr X XWkzqW{_O!;d=W5Xs{bMOEPҀ~2 pM轐bZ_DeyceZVwʏ@2~&ij;<.;ЖCbc8gT">'Uo׼ Z=FPv!ٕ`r H k^A' Š<{މL|%p\$eBLJKUp𚳯]EY*͆ɈE݂Hvo3n d{hv"χ9 -N?'VZu>3Ypm}g9&1;G׾Wu=; Eg*fW"dA#&CA:&1%l*K񦊁 XpCq'\ba$/i@Cr5jo}/H(nCr_3sBwŝoΆ#dX:H5a._*Q)\_ϴ=ơ7FO|I0EP]5>*8IAy,kӌKۑJxjo>1N"r c#HGxGiϡ*o 9w$ezK;yB̮sswb%H DOA_$jI1AhQC˯B@:ٸH)['V?C[^VRMSɁ7DT*Ngie 1S0$f[ܱՒWbC݋fĵ/1&#5AH;ঌߖ LLņ+5D9g[CZK17Hni&D8}C`Gɢ8bf@8~L\٣J uFz2V딼wC 5yCXJW!0w71RnGFkSt  0_{ܝw9.Q{Аó}N(hg7 )Ѫ@U#b TT8tAaR0N!#_<oqjӯUZiEI-Z*+~(*'A-Pxa|o47l>@Hg'Wxҹmt`P>H*ryD/DKTkڀ'tS$Eln \nQ*Xv-xï܃fKn+Pj?d^p&#@3'Ns`}Mw좵kIQ^=5o\'̟ߓE3.N]3gс1[y?JNYe!զA!עJf=UoT.>դmW-}b~f6"^_k-{Rf! N+y:wcTꇝ]DfGy'YJph@4Mn]#K~_żU'-p&&%(*!!Mke~ Ɇm0.Y[y l= @;O<@(I _jqϐ0Bϗ)@7.&o>nU6πG|Ej-S?,$/m&zV`Uj3p{v ^bĥ b';GqgQ/^zvI폠.OLτMoyk޾Zȇs7K tZP*(.쒎$Hv?Y_-aCcǧOޅ(DNcCJK>J9mRC䕆& w5bNExi{N֓P,t$ L辬ۚR[-e4pёl|R=I1-^N5o_vesd00F Zpx؅##mߡ--ƾDշW9!>2Xm<ߺf!8z2n!2e [yգ@*ғxCԭ UM:qi"[2yRQ薒VحM|{R hSӖ;i ;Yk11Dӈʀ6PnZQGD䧖hI4qfu}#T'E_⼌݁z|A` z@W?;)`cMۍ@&>^r6z>an+/O]$Y`)TL@e#M2Ŭf& Hya1MA@ܥj?M@IDb5u؛nd겢`PFrg5ijq#=W*Uw6^#|BeX[3E~u?/+8&4%1. Q6  3sG9÷nz``Ī% .'=Pĸzn) ,2_G_x4pPc}Ѡ&𚨋yu(Mٍٚxf\<3sTjt3:T*֏_`7lc 53kI3A8H^LVyxn0K'Z_t)C;.S/N\f;noGw+Y)qfޘ ] @ibZLH,KJxWmrlfdV/SV%/8OO| V='EHZߚ^&_b~wTC\x-&EE\$ ~/h.\:~,/==kDYC:Twg|xRl{C0|ΨEDPqG *i?TCQK(97b|I# j?WUU$EDnm󧘌L,$ŗ $PMxB-iׁL\ɁvG'tX˧L7sƺ4uzCSxw2E^;=8:`i+A"EgeXoe;0~k76v{˿h ԓ:~we!Hp]8rOh<:琽 :ǥ=+nytנ$NM$mn)Qj:B}}w0܉gS,YfJOkbZu.q>ٜ#P뢰 ,Rc@{tQkD S-ſ*[Dਙ^j# 8mqsƑq9"gۏ@g٠-~ITto~An4KkpsCi |K;`CK 3({ LL{-/!}b)ڙOs+pUа4-`]f[E1KCZ0v,7g}/Jُ;^&BTI~ >.LX4x8n\T,h/1nXI)K~ڒ * Ou[,ǵŴi@eKQ> $G`8?jDOG!DE`~,{+v'Y/zicO^P1x/ |mį@^w'UBUqqKa$B[M:~N/81% E SR'Ќh9 57*EqQbc=d7Խ7TFt uTl֬y`I1ur`fu c*]}6aT姣~C/B BΣI9Bp/5z(g`_UTx3iy)DD"%t֥.-YlT8=RSfPІ*ёt 6a[I_7j7{ZgY5WWKaw<с*ppP'x'IPE.b|yU4m9.蠕!:9 P?ٳ m <D-n5Y0師H :̏*QSɰBا(q#'w6E^Xɽ/=!«jʯE {D5w/2-$<0# q›m,< FߚS8㖈OQ*ۨ-çf^597 szoaACkZ]q0lbuw^ ,52/٪_^y!v  y9ԫ&qLogv$V0?XocS=3M:^Nj^X~d ϧ>}" K #5rQt*Y*vpgq:j# P]O`2eCzL &D^yThXM.q~cR<~+,ҠQ _}9Yjk=h3q!)f=ɭ~l:G;bA.}C޻Ґp~څd@ D2x~cpC $ELENڅ=F9D۠$_\NB !fgž@pOZ6u음)ʪ`YO|цXŮj'й$̘C`Ds[CϽbNVq4V>B֕B] U.ղqW#`G>_&d,*`&o5Ш(ĴZ(:k:-;Òv]y?Zu68^a5 |q0+̆>ΟM0څD:-GSǼ@m<!JNjPVc#po+ЛȀ\PLً#UK 7  T,],)}F:IPzN2ٔAP7 3t/~O87a\ MP}خ#&A"&W"h֢T&^/keA h8332}&P|v>"QcbۅOKW\.z*G[kdl֌n־UXtkcJiڀ?"Bll;ȵl"J-&b(sT6VNb=hEs#f0ozݵSE$l1~:bstYn ;9…MFDo>Z\o]Wh=  `=O/LQf`^rO! !~A..6 } BR𺁊נNIFq)s'hVoGpA췫Qp-E]>tCΫsgk弅ryQqδe2' F} t %<`K=lB)$-aU,*0lrs128RSíMuKLȞw8}LÉ"JViN:\kM̴T2T>mt@ TaU??{^kqZԁVML'\-,} osދ_3vf8?/ ]HN>C6 \ 4 seҦi⪆<0QP I2f;P2~Gٹ{ueXګ/ꘐFKq&N>V]sШ6 WoS/"8-[RaL5K$, )a`hfߵ\?ԫjrJ[HGn9GOG+#xP B[ /.xꡇADGtLL 1,@Ꝧ=W_ aIҒ vw~Fxj)7/4q5QWIkU;SDZ0J%ڴL5)@ AG]gYHjA=_1x~& È-=d_LWkUbݍ_jGUM<% <%ǿMŖ }su Z/Ԗqp:ubV&ˇA>cEa^e;Z,c8,gI|n;ap{}$ ȰĈ1:9{Ha6+?gnz#@0jmظ庭P^/ 1$ 0}/yNUߚ$wzBP=0D8AM9 c?Vgu|yliZ `yY[[EWtzY'h˻g)&[hy NQ05I+(=lNB=bO*j5}h 5>+»T:<5.}Z$݂1/ vaSIKG5ڮo]@Mɶu/eYl> i1yBy̒`,c+.N(|rLaQPwLXOڊ;A9x$sBzCyX,ԌUmAo~1ج|g[ĕG~ѱ9aމbovk o)/_)Pɓ.^k;$EP 5ێPj%*~(*1abФiF+YHw+kt?[6Zd|jةYl\#FTlIhFpA!O<]NH)2 qIfG&lm0uV\f"I[P釮@E*˱0-xEl_4j hG"mqaUT_fk.J9c-FjUIS=WOHytog NpM4 SST5%|*> gM<8Fd-Nh/v i+e]pNB F`Ž?]$s*Tj}>ײAMK*1eX1>EvcXVE =D5E nJŰى;/.rHc_뿟tPY9RW}%=#S vN^w[K@Zl]FR=*:|:]Vx"@X|ɐ( 5};_O圙/ ^OƨTLZUym=,vCzT|q? %y~,q̀MϦ͆Y@g€azQ[mKc>5̜O->MP; @R2 k:ܿGED$@tbՙBtH>(j`c7{ Zr<>d<;8JlDw7ߘx|ZIqEN|T1hfsG1fMO2Rx(VVb:GXXKƼs ; Ñ2b<~X=aDh(xM}?ZXghV>SN`k Gz4NZ lA!Ƙz>cYЬt%jjr沗 ds4^-.nw'|nE_vS`h]3Gd"|Է:h$HJV8B):ks_͚gW 2VHZf/'w fsT(fJ-*&^xbDISIa~nxb&Ŗ>1H ;-aD0OIg*}*P-={|3DqS:ivBi0JD@Q`ZQE;DPM2i6Vt vw 89|äLI/5FΧ (5'u7)3_TIoOѿVE~ ߯":hpO CMG.nJQkVPH|Sjm \,OmҞU R5 xS= F8:jcZw1өzbɾ zE޷p ȉg S n$(`2PȯGQFo"C?fI ClE+ ^eP@=-]=$Tm^lĤ6ys3UDĥ{(5K*:G*oy73}ubNU,v*"ȴ0piCi_ܛe7-sWR.6~tC MzHv݇X}d7'KꮲB_NDg[K-숨 /W-|~6KpLM12Y&ÖjW`$: ѭ~4x2۸@{[7-FM?b^tӂz|rf/+8-='Gnbӊga ͌[S-؆O?s@ϓhΝ#:*>rYMA#/$^WR~Kҍ4R ꟔DVt(_8 v$@mMZ ^rm;BQ)~ {PoT,,}b¾“k ?p2Ӟ_-SB,=H[NYC_/-L* nַU"fCy.$NWk >Ε\P' _/+Ơ}f уc0wip \4/CHfbtVtE.ZWxp#>y?Fw5B 3dA;g1T. B[[$渘h- >s@fF8_03tѼA7hG4=ÖݷxREǔO#!!]02/¶|t)X _]y iQ4i1{˦SN_Իus;xj*bU> PM2QEZ)s.EåvS3^%'lbH$EOejE)KbEoWo RHVs"QLu>QcLp"tE), w |agcw4z7Up:}fūnt˜0| ;EzYHfVX}X`b4g2^мH2?٘d,0TAf +pkjE@EM}3xرV<Xر ԿR_@~d F s*BB*FWnF)9W-T«ǟWɥ gnHeC~CQc`UF5b\ ]'6#I-8Coǭ? 7 fژPsq-J2;LNTeyMPol\$q7gu=j47K iygkZjex{ДyX-2bBT{?INI.:V}M9f9ꝟm2L4 9m=׆>o;OX7&Y73KGQ"C)'DC7ohtp-i3 ,,>QCfsjj vlw,vp51(sel 'U*1]siRՌg\f=,S]oOg}ri8t #{k[;VZH,lD>srX&F:ׁ~&_ z@#jFx! ~r@\meZM_A X@髑ӺEƁԐH&1'QGg5ϾjZ[5#d5'-X [glGV2? `*URO؎ mQe:qf:|,,us*~v7: NӊB0t| $/*<<##JGMpRK|kG|6CD %OӽOx4ďF'>otЛ<0-]Plӷsh d05CBdpA af;30W茣dv -vf'Hn ]7+)c=c%GL T4,?kƷ*I:1q\Cfqq$ INvB+ʉ9N(Y]L(2Fڏ./[t\ch~0ŮߖSnoeS2~]X $b/v hR>\Rze 3&55g|@9ׁMhiW8 me8 C,/?:ƒD t0'pZ(JM(#<+)HK!nt<*#TK<+/8FA Oxso_.Ey@#p++;wY拰f#8OV& lrtٞ\ c 辢(\X= Mg'1I4cg+3"2&rđs-;7Fi59hqPqEZ\qMOv rgD DeL+LW~B)*^p ³#V Udv^U\]ո%>O'3a-lhC6or7Y񍕰α!/@ak\D08C2FƂAG}Lt@wjiKVQ<5Q]Y~Od%_~UJhį[!>Ϧ|wn|cKPWJN݂Et-G&HRHohgoMAS$~Bt;ƢTT<=<6<UH z|C1{R[)DvPO'SiPIBsƛ:"3Lj\C[ig5v/I,"~Zメgh/f\d=9^p*3-K?`U; Sjf#rCp[vUemR&4XT}n!6B=22]1=t|AL\,XiK.|ҽN0OB`%*~ऄ)5`2xK}&";4n~# -)Ne}~J4GſQP ?_NK) =.ox]r*;A!iNr'N@f4I(Ҧfn}PFk]|jNuYa9` !)?+^ U֞DIE|77ࠪcۊ,4۟}~Ι.Y 1ͱ=-o ' P@rv5!@,nhLSŀ+"yzUԗ7{/YNY , +z5^0\@RڰpR>%&ȁJZ_-2^:Ed<8Q&'bvS(%L |?Fy)qyqx]dkpͩ-őwfY Y+629C; *K!rYպ@PabJ Ysu"zGzP@S1Rn_iÐ΄ʀiyoW;=yv.8mNbmNP`EWAip Lp̊/>Ag!3-9^%{hN1/@ٲڮEkߏ;*h (>o! µ f@qГS~>]=S!cQ8:(fx/{8<OK_u |Bک,kH&0 >$֕86+YKwjElPĦ'Fmj-&eQvZ(Q<{|z R2jE JVP1Au@9E|e #1e+=b3~zWx^G*or'ŏغ/xA kzUއqxЉh]tŹtwג֧5\8q&'gP1| \n6{Biuvz33$% p LS|{oѲ~iFsǹn ]dd?&}+G*W+uW٤mT(`f)Kd0чױG}E"[9,wp}9FO9}{YJtԘ(d0f5;a1M0 M L"g=P%# jBLx0.oR)byʊ 7,Q-9TT }GU;t0!\ifDYy": ,(3D[R6]܌I,Y2IZar%`NnDE-!:,FU0ǡ)ʙk\A EcX~/0' p*yEN ,=0%' '!fɃ+Y#ş5: aRATEq HX#03"><ËTJnЂD':X=#e,2d^}{U8oB$o `8.,Kƒg$a:*:o--۟ЮVaDA [\NYa/~ EC3|O׍9/O>+,d}t߁HG1= ?1^EguX:2 D vbT}z\db$_ >J9B=\XS̕G ".D6eݯ`Ln h &XlP)"1-bh XTc=da[ Y#g'&mj]g0v$8"#x쒚 5rtb T@:>G5fSe3e[ƧTA^fDqO12XB83I-&7zq:-IPn8鑭E<Ġ>N^MˣսBF11 3wiKrſ_ _? c5ck{nEEsYW1Y \Fb-*2%hÎ>MA nBq;X3)cۏs7w3ç@^zn'brYs,7&r1r;|h$8M/~(3,!ڤqlsӛꄆ9;\tzfQ.tE1X4Z}6N RTNBK 8_QMލ[8A&l{Xpfsmqx~Fw zᵦ݅$͸ô 9Kf<QlS HV*(N'vN*&p cl{σH<&^w>V?5 6 (Jd15uUF* j7 &b[$>Y+IW;JZ>r%5\ˆZw5G /.0S4g ΒO65HQd8"݃+@fq kAc݇ h-IP@!Rq6c_B7|y'$t?},Aܻ 2jyɥÀ[W(Jjvq$|OjT.# %:(3RՅIiۚuVBou`uHZqӔwإ .'gK ecR:dzD?i4n׌kN?G{WO2ptzg ӴCrސ=R'Z*AIyjKAy,臏2YQ>Y 'gΫgZ0g'~X@ g?5& _!"A]cGHfݢq|Z^"ʼ3'D;K- XmC`NjoQex- C>0ɮ0!θ'zվ xocmcm|K)&E yfbܡG@%Ոf$8i N選7=G[ wNN~JTD[arΆOu#f:r*7f2+$7:")ZeDШZ`e]sیfÝ%K!\]:/wd C}Z20 eew/L2eG8:XnCAM\ {a?C; 4/EAk@s͈iaz*'\5,U0ciRV?L:  7~}^xZUF4SIDFC]ț `fhJz_&~<8zV` /Y$ 2>?~JLA1_GE&oB]2M%|[6qO+꧟F+{JummaMRIE m[b9Uj\[BCut- ahgt&FpzX OSot(hը/ >vߘ&-+51z@[o `t@ 7 GI9\pN}d{끊/cg!,C֢ Yjv:ã#u]+ø]0@X#<"ψ*x >]Z*fm ȣV1#ɳh( i݀Rו͚pOk$̿ֆG^%TbP/no9*1nD[y>E"BbAڏMֿLz<7Tv^Kܚ _}35[sM9<"yPuhOQT}׾G>VbQ$9:/D9WN/iIB禩kP3}(>@ 5żAWK 0QVSK=yD%f~&d45EQ@+Q5L8]na}nxQ0WB*`;<EHGoe-lRtڿL+0=(dհ"Rɯ[ڷ5OGD2^nuCI\rL)цɻožAg B$KNOZ5tjS9m`bQ+7UrcQut[ !۫>N=nOvy 3#U:X9GxMЂBt6%;FY `El P~-xs:Řv7h`d)¯`+Iņ R$0/$ffZrmb@XpPX|ť>KolbiR؈oDjdS_{^3O.a`S)}{+DPgH!zUb7wIObl>L\`yz8m7]zV1u{0=]OK9{[ 0nbzsnjf WjOvBd>!B~-xyC! ZAI,ih&|Ms.h'(LL>mNHiӅ,O u -Y]4O2V8P^Aս&BX @nqeSK =m:Rۏjdhs+XbP$\m:*cS_w=H+~\_%RK#shOʘHDaCT۪;Aj@ HSL`-:,^fG0G}_cXI]rXՀix6p%CjWjүa^Vbe,dUe ,>H-z(=Ԃ{0;q"ħz/ue9?N.pd3 ?嗣wW 7BsC@ 2mwwA[W =~ע fAsz|øs҉+>`5/ٶl3omdЈjs5x`XZ(Tic__Kj5mnh#wtzY.[IyN\ZNL٧FZqU5L 0d*+o$؊C$8dGL|mbc^j(7G>)ۣ_kr- Y%qHhcӋHV.97r֚_HJݼ֩}yJa Ufh:n+THtyck&YmO~E,kk60#\| gUŊ(iXXrǾ<6n8g/lL7|&O"u0uhlUFI1b^#w7\$ZTQXK)z)nҩw*{_,ꒂ&֗Aע(Xfs Ua כM½O#r߽oxwOk4hV!U(1ƻIg~tC9[ UJ 1 Tp@ $>w%+`8n[RQԫFw@)Hk4y>MQ tj H#$r<eBEW!B F " G v0yZ8Vp6ts 1q6hl \#ZT9]8Ɲ };8ef7=›9[_z /`?""{.Sߌ$h G?'\+Qkf_2v Ƞ~psrxx@Vlg;i24r0̳(NX[?@n/ K-'L1 MX*z8ޘ)*l*挕02 y?ә84SW2|\ZY\GR!$*fM!VQ} 7OjL8Ժu6JEGj^:nIVQgwNOO )XB> h% gVV5lKy5]Pp7}"%!keOC A]Ua-@X;1 H&T~/YMrf8$"j}rAzSCCG?8ngsǍ~ }TIH* Qte F]31p O6o-b8~ƆcT}͟X$N{أoZ!2{y BfЙ_࠮ɵI8[}SlSJWz{!qO8F sQ)ɜ)YW~HGAX800b)1}Q@YorX[\|B-&oy:%2 u{}@yE!4vUX*H3PImce! TÝTܬl Thi0w d4ca)`o<^Oׇ,\X3&*JT$I_kd߿>aѰ)p@g柎 ߊb\Y }2 Y^Ef5l DqYFqN${syڏey/zziʡ.tM({v}{ǻXe@Rv[.~MJݢ )߶ YZ