sssd-ipa-1.14.0-43.el7_3.11$><3}GA̧2X>=?d   ; "@FM    4 { $XLL 3L   ( 89:e=yGyHyIyXyYy\z ]z(^zb{d{e{f{l{t{u|v|0w~tx~y~RCsssd-ipa1.14.043.el7_3.11The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.X~oc1bm.rdu2.centos.org 'zCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKNiA큤AX~oX~oX~oW~X~oX~oX~o4790c7240978db7ebb45b068e719667bc94b918d094d5ee626879a48d3302a0b8282b239202907b347a9a1cc7942ee0a915370f8a25808a40b00dc106fd4dbb28ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903db7ef65c8a57396cc08f8d7b4c82b8de9d7c53397c64cbf120dca001f5198c1cdffdd465621582b79904ea7e77cb96c37396b8d9efff43c35a6cebeab63bce87rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.11.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.113.0.4-14.6.0-14.0-11.14.0-43.el7_3.111.14.0-43.el7_3.111.14.0-43.el7_3.115.2-1sssd1.10.0-8.beta24.11.3XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.111.14.0-43.el7_3.11libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8331f40a84070971d9978cd680a24ba3ac5957aa, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6;{]"k%f@}|,p35muذpE /^!P Ӯ^C "ْ_#!"+/$JG b(EWŕ92sw2KcpBF%_a]ֆX4qV)]8iђQ4(®t_r===䠞k#ݻEמ%9`Ʌ2XTwq[ D^]qe׶MÍiPI;vl5$HjD'w(wr0jf)ϱ0otҬHRNA*G_Đ|iT183 &Y9oOGc40>VZfs/ާvG"t†T*SbA kכ8(NyFFƈ;6h֞vO\jhS2 .`~CUewghF-!4O0 VfWں?rMX n \ŝ}}9 u s&5.[=Z^ڻu( dϓjLIZη6iu2h1c c\}׀~ZIV9PȀ "NJxw%ףĠ]:gbPgIr_6QMschE= fE>5N˱MaY`{,@v^ʈCI;Z2LIa=҆V诰+4fFdC3H#D3bcjяuT.dB-o$#f,A)RŜ3Mu-) 5#<q[ӬPPBU$cFt KZ5{.55| xHdѩ2yBf|Iнdq;Mˁ|nÇo0Mr%\E|o @Qxy[o%G=p>(Uo dRiBOոCŵ]d5l9>;fTfxN6%rC-VTU1귲EROm\A.YOk#R+%mQ{50QżQ>G?K(ϱO]R#]*y0=_̪&ϒ>j }c?GƝ".yCun9mQP[h܆ )O@4. Uc<64dSQhlll\=Bd qup[G`@ B<`d֠XÕ2]bZ2ogR5\ƃe=KQ ?(^±̽D*fM{uCǬrts Eb5\ -ka4{{_Z)1Kٟǃi&)ݫ-)=Q>b']*v+# n"Ɏ:ܗB]rZI)9Qvu3>_50,i'3(}x6p)9q50O;} hG?ͦsK{vY7= [u2>6JJt+JCp~!2XkjOdJ׃ED 4gv"8mu,? >A/F" ܯ3L$ߣGóeшUmx'`vgd QWz4jͣ#DwNd :i.|UX8v;܏@sf hI.6meъߔ>Uh iFl0T()xŏ`M,BfjMe#-ao.Gwgi+^Hj;aRa!tt)SmD<xm"#׍(ESA#׎(عeԀר)Ǫ 5GV ;>ԈI3C\ H~4[9{e:ŗ 1c<+44kIܷM[^3?ߺcIM:%¸n&qN ʚq@If"q:HR6fYpyz Ƚ[ݩ+t>׍Ĺbz54E V#نвP&wX&|A_1(Ʉ,K+yJQ2?TI]8$S'Y\Qpij:z%kuʬ|픦l_4?$0ٔde;KE6_>h̖DcDf >"б" Ԋ4M80Q䊡 zYKEiGWl2UJEVuE9YwZ>81 J$2bD-=XF;\hTnHQ*kxig.8f]*oM ߙȫ<`:+YꣁDI*K`7-#`ݵm I.>5bnli4`tZ:1I~d5N_5W6smE^IJԔ-,1\4uWH2Wwkp"ןRitهe\2u">V}2DF1=ԙ~7 B4,p@\CG| \Ê@V5{u*TOh96RoAn|0I ܤp a6(y_Smr.K(?fVXݪCN%e{-|h kGߵ6="!FjdSg2\:4f,8 7YŠ|Mrݬ9xfL NOֈĶu$5]̷OS@t3Vy3[Q&kwNon'^lrP3'C젫x4Ovgv0pyS̾+\d~' 7]Ʉ2Ǡ⦡Y¼?[M ;o3'Aa"9~JDGWTCXG `9]|]NXdp$US#\0na-(=SwhEm[)s@=ӃRRB5J{rWK~^nv3Oa:1ilBSeg /#0$P$}cE}7:2ZdEwDNaRL>ӋM 'RVסҝFHOD ʀF:$9Mƿ+b1ztѹ K^{AO v7K}# $`%QU>6Rna>τ}06%y]=(n?mV$oS 8x^mDJgSV:$ȜlיG8*\2Q3AKDɣަ-FooP=G˳ڻmX9\Ŕ%FRklkTn&#ԩ7L/7"2uV]7q`:ťd84hIs3Sߎh41H#bKq1.13^xgeG$|гZaxv'&qמ": ՑM:(%fV +$噇uyHvTtvSJfLނ1O\ R ' @^ DɹCw,.{uhğ:pQd~a`P7c w۫vpزlhq}@ƭL]glt ;LA8,_qlNZnռu=wLVc|đāWB0tCr{ەWpE2&zW1|:s#κkآDzkB ͅj ..#X_KDd8C.f*XO!܇pa bqZ1/ϟXR+'Pʷ3~E73ih;yd%K! masP4 }]9.;/tѭbT';3/`NBll*i%068̀-dD97_3I%: Rr xkpWNU T7RfQ9y[_G%Wو\y8s皯Q\k_TPM}Ar R >tP d _]넋`g/E` FZ&zF's̮`x44hHhԴ[wнx|ڇGnB,&MۄmϽ~q͆Q 15Мp* 05#hZ1dxDh_=7 ;0N@$#*8pO '4Dv/Tȥ@_pcnr.'*~}ȯC UTfq=†eNJVޱY5++C"22lK1#?1NtN\%5(%v b,!_hWV~'T ,F` me9AH3Bz(F}7Q_th*j7FCc3,e\`zY3uVRC\lrڙ( nXVoszuܖr5@s u y%]*Z+FۊqaJ`I9D$r oRҦ+"53YQ7u|$!Au{|KXtɮ< 4~B@*KirkeDk_"_bN)㓱#; w«1iȪLwW`H@;O՟ߑO]nRd2/O* fҽ@QxΤ<#2Bz{ݭ zj ޛ>{n7=# %ݒ {q:&Cg:ϛtfEv 53< E\m7yMy_ʾ۷J$mTX q bÃ3.G. t&ː7]LZ˃;.c6Dt/q״#Y-ǂ?qA9wtc&r"cdɮs"?8ғ ֦CbƕJc6BX  p(ֿ4$J#䒄ЈuJcI/cIqKruZ3{ EXYK½,GшrST/M|A {GS̎!`m7F.puYҔ /"řU"jkɥ6 v?}<j"  mcFo T.  $غbZoE]v6t0\ iAAg ClQ+A贫#vR160㽣R=Xf51XQ=FvFGͮw3{ٷ|rRǖT}|RAHq6+@+2gW36ژ8m/ {E%V=D;|X$bX&}!Ξ:Tl`'qa(M&G>CUAm6b=3?:>Rp + 1KhN aci۾k΢a7lLĪ9Jg1>۪ʋɻZJU+ 1]֣ /gJfc|ᔤ[)F dc*KOj(/IaN?c ep<\q/̊U J_7盦ePd6̐ߟXQ]+~e*~ 7{RjsIy0%t*fdzQ~rCkEԥۡ1t̊^Kܞ (llS<ƙ*TZ;S:0ڭʤR^mL53v-i6^!$]WpBuUkӛP2 x(%_J~rˎYЍk DdrQS.'-P-]quvoe řK>W-E1vgn ?})pV*;=34봗;//Jr4;.4 $Z M_(GSh'#Ҏ cF]Id'д\oy"@9O D ;5\E=EЩtS@Ί>+{W$K2&`R+6b4+%KjeQb,w gI6#7M}BS5,~98iL"{jpjxf g6aफ`+M7sCT$bWhM-oVVbu*V=Y$%Kr )Z S8A )8 r˛p4YpzgeVޤYˣkQ,T|.êߒ 먂i&D)0Gߺ_E՘\D^]Ϡ1`1XeFA}lh( '\gB.rߍ$4Fޜ0]bftvy ;ߜER"{"}:A V>gN<묕 ySNtZtg.<1DEsJ#9$i`cLp ,=%F@[Y@hR'&1"|4m.։-On8ݍ IySO߀*W@'8π̪#SXf <+~Q-aHRχ̓JZȧGtf֙]1g0u/SzdlDIJM2-+ecE2w4WrY焱n,.|qٷKzb7^ Y󜀜{ͩa H/HÇ6*9'a3Z'&5zv7*6kD_cAԎ`g3$dac;~̜ fƱfp4=}) 7!lʢќ_}F:,hdK@^uA"'{y'UUze $i)-,=Ҥ\{Z9͛mbA!, Ŏ;^ R7{jڮ"BJAwQ#S1%ZT,lr#@.Eik;ՙ9[F0> &k`A?2^rϸsĝ(%b'@ uQs^͹%^BUc&w.R/Z;XL|JփVJTׄF" |9o歨1̆(r_|I'섴".CjT>93̩`%?={t U(A.@W(byyn-~(*Y@9kl|$S|OA[\d82vѡs</I]WdlbL/̲$L~\=(v9d:fW+ p1n@#۟S42jm=Xz"XPмXeڷkARyR0ip ez{Br|e$ Mq$1x"cX zƎl)20Q4Ğ@IX @c7¾Fٗ\]cwaiWR;itPRTD)Qq3]S rD?\ 82ɑU y=ѬW OTO称Cj. CÎ17 0 ѫ9+jv78 \{ bb$o_=ϴvB{;dDĹ h ;f{[ fi{l˞oX"q%;S&=Ϋ"JjB׽5u+r{>P# Y$6OӈcϷ:[݉`)stK^5-)wr_f1m د]ї$ݱr XiGOllR9&/\#kO_OUV=;m#h()u   ;T/-]YB'ǎUl0j}Ӡ 㶖ƚ bSXz9&TJ/'O<}r?ǩ^ YR h.6$A*gFAYvٝRkG1]Lt4yF& WqV"vr{`+,|1Lu򜹤޺0k34+!u̕m!Wʤلv0qTVI'Qg;6h2>S} .ef~̢d(9E`"L%Gӿqrj#*[&|B].^"7ȉ?id`g>!Pm`ڭ%;[l oF, jVBlCR+Rj R+t 1{ߞz;7u4RلetY1n0+*^}`U&MƔw_H#h.iny#-A$}Fk;)Fu/#^}1XtI 󗎁aSl* ڢC5U` Xs~^*@T!GNLܳ-Pʡ[U-φ-( "n Z3x<*' q,s7;x| sIimwV&g@'XG +d7,u[t_Z`ϞV L1\.@h0L\8gBaMV3 l]$W`>T[RDf쩆lB, gcY̹Dt;$fhK{X}EdEJIX4uP-hp30eYƙA8MN5]yڛ6xWa]9T`y8mfH1vpJ r:OuWz:UQ:کvê&92ġ1%bIIˊ~6$略toR YXk6c|q`FsqA(:R>c{mBD v D]zCl*ی}o٭~(݋$ō! ģf%rE4KK惸")SW>H_@C67DVSs¶VysŶ6cOԂ+CF(EiRt2M3(Gu/t8SjXwh7p<2 ݎ,_o7CN4*mTU+gmqFX. yePAbzi-_VFߥL3Цcn)x%JJzAҬY0yZ$Q,XKy<\wz'i㒊\{.ֽA_ȣec[| 4 Ig&Z+BKݴ2KE2)^S@o2bs[{JɆ墔},yio =o] 1/̣8@'U_ǚJg`]Ȇ jr 'haM,. H.G31UA.!-K8=ξ/{6m# aAojQ #X y RI KܗLשlLJ7B2v- uY({,rz@'d#ӊ59,d[~#u4hCY \fGQe;%*+T4r*u=OBز"Kzg҆qv9)E"}!ɀY%S0}P1:2e~Yԏ|Q<ƾ87 Rk/ysW "3uլ^x߅PKO[ Ia3"`tip %)WuB0 ;9@vP;ؓ4I\̃UMut7c׶_:Xh1D jWe85M 'fEn6(3h-; L@ y7JXܲ9 ݨI]a CmDACϞOְQqrلxAAh%McKRa 푨'W5|%Ug *>E xF3B'%Kq|9\_oe]7rBQTD{O,7G +ܺ<㟞Yhq-k(X-埯=MvhA|w> m_9&o NndF"DY98JcQ8o 9Ά_J윝kh58Bi|F'LɿfY)r z"r!v%Ʊv=DYߙ7?!ɶՙ__~I 8@r(*bCJ=L^DO12']SQRF魀``?%9WFͺ+(:yQt4{޵SG+A}BPA[m}ɓ gX%|/n>v_kEu2!VF))nO[`ReTL-)TqxrH9{ 'B;Zٝm_We-f1JOEo?y WZGirq' 16x?$1<=]:E%'hWKD4⼷ZT'4w< DBo,LhIa #qNx/7.T>ϵd!"sЛ, 3gGgN5bw Ymht8u 1؁Ֆ|y'5hf]Qܠ=2̯^E@υ z0!x%>  Jݛ ac&q\݌ g${ӹcS{33R$M f^36p/| 3ǩ ?u(ȣ$ 0=a<.ra--=T:Qr2lH;OH]nHqǩƼ{#AhQj'DJ!2±H>S)eCg "u3A/f3,(Š":I 7S]Gc7`# o|fJƆz._hwC RQcJe/S0%MYP957R9 ꟳo+ ݞD m@ K]AlΡKzV7zIde/tUo R?C2jwJT,s+9{66N0Nͱ..mn@Iּ#WƊe}@uY[1;ks0A3wxG(8.JNP>vnލ'-SkW62an[8k QEq&&FNtorյ}/DC:H.HozLF0V9=_!oEI8 =(`#;os7Μ.Y}{&)9%Iӛ}:.2'gaRII{HĨ(ab3#vfFzVBbzr? B7b́ &R ET|{{(/wV=\lwc,ou1FKc0;0>ÿ" 'K JlaB&kmwLz[sűŃ +Ew#qH#Z^cG?t$T  5󫥥b_IBrtA<ꢍ| Hn y" ~|>FF93 6K)ꦂ RPTfW\5K`WQ4Af1 M2eH^U`Apo5c=aUDxLq|=|13>6y2.x+sXrEl3%8VL3)7_u mCbg"p}BEkb [:>}sBo_ZG;05 vߖ'f`c2 Y0a+y9ijTUNk;&4F&UTE,>iwb^a[ >M4oQ`1L1Xq)(rg{aڠŧHWA[}"{B at  YkdK_ΠAqErn"L"\BA]G8h02l&cƍ7]{X=C&0y#prN=zjoc,Rݑ[UQH)LE&;9aX k*x&DW. g_(:WoU1٫y)_a%30T=' | Oʈy x00&SS[$^ hi2Ύ/YlЫuhM=^Pe r Sk묯l"9o|; ܥE@e{uMp闁QUA/`0eOlRV La8[@ѶH, $XMP G%;qp;Ezj{ڢn K}µi,!dLPbW2C/&7G1ſsp mP[-4x eô2Mv3"sl^^sskoYȓu+Ӯc\|'"J `R#p$<1"rI,sozP[K :νwqn1-`:]7#N~[*!}ڰ~aRAbI1z) C %as|ƒ{K`P}4F&lŚ5Vit1+]:;iKO21+vOhzu-\;5KvPDQ#4|yramբwY{*K-)]risn0'.RP}{y,8v$8g=}SӦyٌ&<ҭBV6%%G_<` Er6V*h!IͽvX5>>NQ@-=n 9-K&܃89֨ATQf|*퉸|*Xu ("0p&~BtTQ+tNGcG2*E~ M6\ p_/D:RէK2ԯhX iUS(GkkNxaYo3hq͜~OO]E-; {w*8 DEs>Hc_wVx+! 5<fe]6 ͕;ϮL+'- &z rK;*y[U5u ,5⌀ (tLQh2pt+)ϜBʇ9!iۇQ'_< 5WƬ<~M?pʤ ,h"| &q]ռKgڕZyȤ!>Mtsĝ5Ux _mϥi=vXj8DvM> \ )u1Qo\PiPV# sOW5\gH~_?&%({ӕG2 /SIM_;UK& FШac}9]4`v[ǎ̘j{_:N_c,zTƒіN&|@Dtz":ht:]ɹN/);u'3D{4xsf#2  Ӕll9!t`wn/{=<;Y3S‘+Z*B_D|aAGmm1G?NgOfS]+;()xP4`C eia҉Jz]љxdhXmGV2-ŝZAfm)I5~4coZ(TjߝOe7@iZu/qzė]G;%^ /sy)G`@)9SYJ8qGI=kp(ٴB0 8{dʭC$zȼ(P{#sP=J\gAԣ #)IF .f!.m^GCE:E* в;u(98MMlv^m }b7W?ˬFKӳ@!'˃  KUE)'z16~ yWė^3A]/"zZǔ%M,@i1Y5NyFӶ1$(;r!!IIh9 QEYZQ704H%We#cmEB4Ct ; H nrl!V ?YW3Qy7 -ʗp* 2}%vJ>OǨǼQ2ϖ[E4qb.pqg!Nu-)Wpذ_雤2/D!pzPYiƆ"kE:X ș5P*\X-ܹ_f+7!{v Oc2V&)HmUQmk-~?-br/yZ߹t.Xd=tQcCv=@گe-rZ|/]2p)ᄞEi' V!1޵v(9qsPqV<]i] rQfP n*2n7'4TѶql͖#-D>Q0u`<NwOUNe!iZg 6zm=l2 wʱQՊ)]epI26>ڳ,?:!';T~a/F}X&4JOEHM|hµR2;Ca#}V rPd%h}8ksp-\%\M .rRODfI)?FgYz/:xws~z;txj}o|) u*xwE C"n)=u~ïH->B|:e K:⾮󦑳F1h9 Zzy M+TQs|YQjģ:^|/tB<~(Q s)ߞ|'L|ؗSPf{aԢXbSCIA}C _LqA=X.nUj>k-2a'%/#XjmjifT1>4̖+G=ڵuQb9Ih=KYhF=Ĉx{hD{eX;9lxbhfw’&\+^3haq3 5기ԛ5MW[d䲂;+Y,h_((|3q.Z͢ rEy`>sN]9nJ) fx8e7RV HŠ@k6ȫOaO~SIo\Alj}QVc>vAA9YSՅ&{o |Ʊ\6>.%V>qLjp‚jb=w~p#U)5QcnYa!k|lXk]'Xj6.4§|#~=q ^x:^|$clAt-sNEfu\ 6BJQ 92Ǡw7K7tK!XFņ`'~ZIĪ_A_8cg^nFt٥UFy+^#`Z@9P&Ŗ|6W`o#D^z*9~ 3X_2tU&j᧪k/51%x.}1sm.73̾)#dA}ʋ p4)L!ò܃~Ǒ F,*7"d+8 -M+N[qO%1A!R u$cz9W<bth/=)N:PJaLlwMñHRㆲ ._𔭸;Te #JRLc:ZWPx{G]9ٖ]y&WJp"yT[!,D+~R ,Qzſ8QA 03V5uFe7^T>+MH/kjaf1mip`y:IcpZD߄ި~+Q5JjH6_Im.-=AB$ĕk|H]ynE_g9agLҩkXYU|y&-J㰚j\av Ϸo?Ū=6P i/PCrTl1 O~ddTa.'-K; T6(cb@nN+gZ CQE8^Ԭ@Ȁɠc8ޥ@u V Tܬ{ ܠKWfIgyJqGv쁲/G~sh#ő 'w͐vEzOW{f+F 61.9C~I#[zOݽ~b5Ť`?@!#JBRMG F`4_^p4,6>JI ܙߧ|_ګz?sX+v xn[ʏ& po~ @5fiA%&muA wj _s:hF}ڮk;lInlj-Ǖ.@ &ur85Ft|ըbTF\8d腥H养c1"=$J ř|zڲ.(| 59`ٙv+c e=q3`-˅ ga\Ϗe3W8ڴ}fGa4*u1R޴oW-qhzsUwj'ןHRzPۦh5 GQnu:9%0W*IZ?ZCʤ Cit3%ģP b&F4C "쬛 F?*6DT #dG"LE)0g#LX7zGo=S,?Kj/Z{YM%s8k5z,ׄٽ;wknk1Ǵ@?C =Q."ͨSpŃ lǵbߎ^;{}C т@ 6 mKlWHj$EN{wf]Ћd!̈27Fkk9&L2I'4Tt:)T2+ɏi lu43+*͈Ba|#,BIp@'M5bGb>R.ciЛT 7i+XK4sɭ~)FSkHfu &j_Veia ˖8ÕΞB&_c [o3*sP!0_tEIޜCsz&Ы֎%9nNO|بuabYk';)P.q ;X40'=><;Ex"E^J/ž0Ov%\-'^4pQN룢RqQW5Jg_w;lFơ pZ)-SKzh.lRa=s,`[tO8#R¢-ƛ9en%M@K`y.oa/_s$͌9}jFFVq.KzijEUBLvfX_$qq&{9CȌy!N>& y y~OMbMvR!-W<#GΓ`tx : FH!TS^ ou仇A.q7<0 IDMyQ^j D70#F Pf$MJnlVt2>mr'0=՝Q״JkҵE!qc4qi3ZKAo^ Lpp/Orq2@tMG#?bpcW-̾`+tx}63?qw+ H K8oJmHWe ُrn{tG"-)|* V@Y}GWFA.]-[N9ɼP>M kOgW_5dۘۗB͔o-_ؒm5R̜zv_On\%ƹ&@!4x_*,;8G1ozkҖ.n,t:\3E OKc ӹ_"P oFrsPXb_- z#`E#/Ik@l(o*s AchDiH:D/dOKk4vD. J+{sk10 OfAHG|*tdB䍟ڵ%0Ce!},2334f>q%jBHᠷb$/Cv|F4Rkϋ >򪽕o_e* =7./)oڌ$3#3`A)KsK'tj)ӤP&,֦7- biI4p,OI!h28?!4nDYm܄ŤF= X ϰ0ϋNoL{rw)XJ+o/&ɔ*c}pgNV髓᧷@YUyqҷ©hIbkF?;^j "-lO֗ۤdcx8c,]ښl642?HʽSV0^y*9՗Ri{Ti#6 0ero mqߧ7 bYh心)v3$P_ Ih5ܨ!Ȫ{KQ+aeɴod.:^Le/Ԣ^fh_IA4+xy]Cr[y,?D$Ľ)Y@lQaK$8o+TBP++ܬO;+;^H7Ĕ= gXQEeU 1RKT0uxRoD~f †Q8URxoW5t1|9,MĞJy&[,mFodE:B|Zw)do3mqtBCZ#Gk ݥY 1@4{kdP@7?:f(eL"̼>$dž_X#{Qz]YG0g3$1sSJ7J5߿H!]ń$Sj"Cw™b0 zRE9a?T|΃jA@߮r4̏rV*O.W\S[ui$l#]@rыc){ |d?yېtHp6)vRM2'3;]Z}2)3no^L@@,W~.Y ]́DUW!}B Aێj,/ֈlg= Rţ֥VwjB@kQCMhG"(U"eߟ䊍bUovNIWr*%KؙG{ WQʚCuwoHrV Z9 DAVs `MA`Q+䜤^nP{I{7 s?1X =K@, -ؾǚts' 9f_hrw 23;Cu&*1h<{yLGs b̈_8ޟПyOo0&r #6-'kHP`B q0"D׼f9X媥#S h[Ȯol F+ XgG=y)ɗPrX}D{ x!slj٨fsOD(, 8l,mr/ l80MqaH!! 6_eULZ ۉ10 &`of߶ޚIƚS"\4(llƭZ^{&,hd]~vJoy`~6<=]y?/ІY6l?>3+uՕyajLsSj Zt*սFڀmg@*`[74LH=6fz~_XtR/Qs=z-NsCGb+sypNmDFb?q-9+g}Lr_LD0ϰ= AoPۄ { ޗu@qm,'>HwD<cgzdt]!FX Ab7^M>J.g?Ϻ$C#մ qkk&)Y0^۳cX C{I^ I_!զ䠲k@}&up'h(0T^8ҘWgvd4ɂ MJn!s͉b/|[1*lDmP.8IwOD0n6֫. b s%rX'LO,#}VEyǁ)h} {h ިRo%H POD+SXPjPW:cehG֝4jt.JU5מ͖:  @kfk0j2k(>kLE+!Gp+d&?!x0[HW;51|xK Jؖwb%,w 'Ac\(9^\k41Ё-59I0{cf={4,L"5xzK*-aMC'ksB)^ @_K7oֲzU p7߷2,\XS~V.f랚;?B=5$V5( ޒȲ kʕ7},P92=vdJ=})2\Sx2+9 n&E\;OdUՂ:s!~)`#?DHHsM_{S̩i/lD|)5<( )QB2(0t'ȅ ;F[r>%0Q F{V,1b9=~RLW5,)*(NPud JǺ8{p-r>=c}J'Jp#͸w3Ӄ4`y^,Y[,M-3bZOZLzdC7ίa+0q57(7 {3|سr+Yad='ZӦ݀:ZM ^kcg7QE!Uh8O F t(6$4)7j|8rK})]Fa@ &} ܶ/3(B/ʷ^hA_QMRz>3C&c- fAIfvt&ց|g+`m'˰G+!@s Xcx1DH/\>,5AC|C dR1\ 9{"VkjEog:tǩv׽8ȹf5z4ՏsfTi 0S;AB7io{FJi-whtIcsaM&T5Au:R͊)JovB.QA@2e"gNRƃy`k+m4GBE[sֻA[<.D`DG>!3렜(ik"x^#cͪcbk2/TYP7VHޕv#[ )#-h^L e7PBza&N27eQ?FZU ~L.+_E Wyv*vX(*8c?cĺmrwtJd q"."IYu-}2ft$w۱:2B n%uʾ)W'츃Reΰz v\əJdxP ~bH`PO7g[]l%i6[J!wv_%dk[DM|Myz[V@eK3rcsa@յ&oڌ{i\j[Y㜪OdvOHM#f[ysYokݔ+[Ygg- rSXj0]i@;$ۣ[*zaE}#ZKc=/QP├ ۆ©d02oZ@K+, (vwE#s%Nw /&/v!{,ɷ{V4mIIX!ؙS+J !)C+W %1gD*tH;녂x}0cb&pQb _oj(*DC^%ôלGf*˺AkxZ^]DX# ۭI+=nq&k&'kYTTd ?3adKZp;S,D+ z_^|QK|%@ޕ Q%‹[]?D0[њgcf#)nSEe|{Yѹ 7pќ ]&#\N9VCd^ 'uI@({ݰ[ݖeCsȳ҂tvum;ñȢ>njt*^=* wnsO׆} u5n|=,#QZt+Cqf(>?h"`RI-9}*$x8Z>OsU\Gp E~?`7ƽp vgmῌ-[d<,4-'[ ɩ*!4,ZS"T0Fܵ&[m"<9b2SZ>nNf R{'UGWUa6>%?XgNfu7lUxM@]|x&΢ٕx)@w*F\0 Lu>i,SK=- @@;E07<]xJ9 ÑrkVO>R>Mm@[\&ᘩ Fh3'JF[16jU2aWg#dv#Iƙ@=Pגw<ŸΗ:|=#'*Kf8%fVڼ9h͙k+23VZ30z2ZPgJynl 7)ُΆ^H4SnuG*47YUmq*l E ya W ֫:N E,fzSb0 Y א~3R#'ZՓdQWRІnlWZC.EJ $_U( &^>??!5K^e.v,\۽fF/BOAB{-S j^w흁v.z/Ra !pAcq8|[X0o 17ZbS 2k :nʵ<@o' ncZ&D0 #C:PTNxk;W+]뒖?ЫBw07W0eE kQ)r<_'חc#qޢg<%ƈ[J:OBWt5uU~=6U:>Bw rWsHv~sqw4+0 ܫTMNJ>>( 1-,kɊ;i; 5 vC I 8O? 3ӦI~RZSy #iݳ.w'N^XT 󦷜J>PFLO8f~ Z`s7Y1H w H5'kjCz_~{媸`$57n&Wb_qjqPQybXH3cTDHE|,zrzֲ˞jgN^Tw(Hr5ӕ &ufD`튗aĒ0+QתV^˭B9wl!Pg-y%vu } ]?b~:6,zWT|&F6H`m >K(B~sZ D=n{HTEls]ʟGmZ[S dU( ߊߘ<_L >;W{/]~b˝Iʋu% PR|8riDnp}cʷBvY!$?7oQIl!QJgV#=ˍA9gזe^lt6Xtskb('dy6юM5{"CQ(=ȴENtXHZӿ"i0VÔ'\E3P=rࣀE+(ɸb8p =Opb _Ʃgi8ҐCJ.׆4gƆ՗ !iZ-N8z>|:lf}h丠QV$z`UADzB>FX.](W|5ׇ:OԵ]-}rM^\~\5;>6+K@FoVuJn.c'w|8ýŌva:I$34WC5$zvQd{#b\_knIl~WԵU.N$%imG(1&H ̿Wy.L3k9ѣ{v%KYI v^_Z\:{Z'{a :K\&!N.dh/6ߵm|)%I5(17n68ѭo?^e@Sa&N-J}/AtˊeJ<\f^ gɿ[jF[p8qmN2`;c,"`GOp|u699i,jLԸa5A^fA{N;I"#qaEw_kOsUMnAD˔p)fdM>g\ V%u` ;WApW {Z_>G_'UX@K*Wdgsے0Nj .0>7<LrHaA\1s<0eXK1" 8nXs,5S.am-aUg |0Qe\;i]j 9z"A i=ڔE<%j4 C<*Yt޲|SK,Y:ZbO (n|Mb,5^ 3{< ud0"IbN*%o<VpЛ֗,ycZfT,_Zs!; R=u{3s}0gvJ{(Y$>;u%Vn4?EjfJ.Y*0aiB!8j|!'}͝hH,ťa_՛ l@Y4dc,RzјOTI$csdVKR-`Z" Cm{/L2uōo7(Yj?WrEժ9Mٺf, k ئ(q>A6ߍJ=I7O>ފ;Ѷ_E N+Y%C3'_QNjk\AWvVhvqg"5I$qxmJ_3cC@.-]w[  =(=#׆Zc:1XD)ʉ>riC6 p|:;D쓛6\LƬfo$E[DWWVs[e/E gdmv+QZ/EI«3WOg4|gS ]ɋќm(e(>k_jy}F Ě6mh<~uc8QmSY]U#6 lH\&f  ?JС•zϼ| RIlZBZN]1j/nU G,hRDw)$g4ɖf.oo=ybpiůP~73`yF3r>*=ph^W˘~8p"lL78uP [c|en"MyyL3 cǪ'Û% "¢30{ K-t| ]Z=YLW^?sy΋\y#c V!Dݾx#g( ' g뉔dr_q;rޣqq .ņU0R)-\`E҂D29Ș1#y+ b޸#8s97DLڴ0K#f:p-Axjti7T&@Ά}ę7r_2\7RhPy6,70B5Dd>4EU"L)84=%-_xDdm.8gj ,'L"8R!rExʧ8;M|.L|Ui9ُMeh"V.;ʀuUo&4oKPd8GSp ZX&u^)ɻGX!iCO.6ɖLo<kf7LgaŒs䄎>MC^fl~cd9Uw( 0H8Qә>Yǃy8`$k.Mj)D%Ek7iڭ0"02b$0z:(ebAſ1+BpkT+੪aoE2BCւ$ײF x(55JUgrb2 N٪c},t+CKո"V 6tp‹66O`$nW %i(0 ޹ =l;W.j`OXpR5Q Ӊ;69d5JibTVВgۄW~r\JHTřFiC rjf/auF />~(7CHJ&LXTFK%l(@&%nʹ'X9Ituw𜩛N Y\{~rK+|+;,xty{ߛE\ 2%Q;4"_9vFwT刍'}j'z KxfՌ<GcO:јHi>/Q[tgI2ȣ.R_g8oTYL(s}%-;h@=ZX?l %.b'v2Ko q0pJvVP֘_v#tq%{i(NgcV&ʆ+ObMm}&:`xpƝ.Oeyl|VspyUdMxGPY,x"{…70[7*XuچVS\i|fL>ZYU(\Td@*lw0$ X|JwTYʡ$N"^o8& Bo^FM9*\2C.$@#[Y)F`R+>sBT+P Яh*Efa58\-c8֤1*Q'9|)t6 D`azFnnb*]6>nt1Kgf6x6+:ŵvzxPE0fσ40t-տSB !rSbG'RD H%ů+ =skȯz^Doy$ OiN7&Xd Ӎ,m;C,TnClX7EnYP8)HR͋Z.V~zA?*h@w[:p~v<<טDc)og$Hpnuo"UgI\x`!04wi|w:rXV˧V旜B30O9` *<4 j0J7}|0mDh23>')ifVĂ,: q; ^Uè+(ULTdENG"8*~'QY>bFN $C~@ O ED^o/>#>#<4dFQp^Z:qThcQm䙎B7ePNyomAu Y(pv^z"j$.h90В=+eBH]KX7- 渃.3+h xU:qiܗ;~#DM & )'W|hɲ!k&_?§JdKd'$]^a` "/淜J}1|QDqSzIdqXTvpȻ 6oۭ=a5Pĭr>Iui  oѦ`Wݨ^16UiT%&69g9Pc) b@nDpa*þ DHM3/Qs~Tԫ&{]"J3aW6#Z0_D9lTS{_zD6@ڹ[{bB7 _ 濦'^max^-UUV|X7 7ē^NO&H1<-lqz4 TyPkwlBKca59ňpXX\IꃜbY! q\YdU΂@[{|6VdzfĐ4ct*ܽXj,JK՟i9Aw q\_Ynjlh E[W"1!GJT+`:>b2BA!"QT;\؉ueeU1a}~%ohۻ/nljfKݸLAiX\kjR| O!4541Ѹj>$G_'7b25 uu_R 9-9ZQ'dB ݌Z4^X[]a2enBġ VutRJpE#;3 f"+ ZTlSqZ.9j7-G6L7|ARJu"s[qܻLREnˑ5wZ4`uuL7<'15g |*joC/cwV%acvmiu0:_F )V ;KpASNζ/`nN%ӵw:v@ qYfCڀ3bϸ@7b %EDcb%4@zQsy)Ver E_B mP15`&njAr"4 M[W鞨+j_yxS~WGRXBvŸ#&*֞x_#&Vyx(xz.'Sb&vQ1D D/ S3#ADK:[L',定]gFd@_>WS'ў"h ] X"nN8qwjGIg*;k){$%tF1tX[8=Wu,Rp lNc HZo'"0wTWN$5ov&Ve8EvW>*䣈PiU_7\"!uXQ#Vv=Rw4EE n)|[%>l(@94.a~EJ6~7ގ<>Y fʅ*F.OsRl&w:>l}UܤģOfo8ˤZ]UT2 >T-=C;C3%㋭.F_M~%@vţb8;gX*qNgVʸ }d^u(nV|z8E?*h0HJT4,gϜ}t4bZSJBG` xJ+ ӕv˜!Tojb5ku1;f͟?83xuBqH"L677(("& |OF١lrB(Ud;fL } 뿅@wR-ӵ/l[5~b$kw?vLୄZ6Xpe!5!piU[#yXѳ"kDu:҅[> 9V(=I$;B> }~5 tB&CI.֖p<n+] 3q rhj^אhbHlGK^ .+jc~Yv[d awo?b(aRS23^"lOcD!%~MoYjm2 W4&&\# ^z2l+e lR#܊LXxVA;thn53 2FI*cqU`FS8P/B(@ka񩗧8e '%>q:2O?%o|S ǷgK&zhsT6TQЇf2&@Kg@h5忠m?%^7z'8W|~Hw$B~]`+?~V5F\3 JXGȵy)~/ [Y-^iCބ8Yp~'gV`];ILǣVPcY; k)Oh;V9'^:j͔y,; (g7Qjq5yr.Y,~FM5V-JWۓCh&-O72sxC _c ,6e5px!6ֶjr(."?!ƙ[yU&;O== çN3 tf !*n3\jNo8=gkzvя șMpo怎Rs;osgcP?>\uy_")u*:j \8.VtͽzּdRPG} 6A{O F9x(5^^r .&hxCIi1}Bi婗j%rU= ~!aI$#[h+T!2^"c*ٿo[0<_+f)Ø-Г _z+@g;4#jI v`EPB ]ǒM9szDŽ.Tcʽɵw'QT[ 8VVa# ;MmHW=oX3$1/.A °cIau?RA53U`C5yy+`?VƊlұNrzt\Jol̙7CFГZV!;DiSMRsa m;cUYC.]4c]-h}Pq6%!} `䕗.&ϊ;;*tq#B:V_bkނzXa6H*~ g+ҵq!_Pg/ڛ‰wmISva#=* 78yǞ5&;wT/}|u7UP+to5wG^Af~/%؟M[!h%lM2.ԩzձ )T5*%Ik5s3sÑϹ [%uosw"ˈ ;mhw#_׮v9kjudpK#Ҏܹzhw w\D?-\"ƞ'W^׳yҿ;׽ YWk/>DHCY鐤֋M0lٰc\jfh)B(IO:nV{lh=>tKS =0['Hz4O~9پ<”#l]>( v\8olZ&k嫐G'&g>=$$U֝V;rpO0aEJ{iF^',߹A$*Bt]Iy4f4%b.$3V>P]Ot~VBH0K/1K{ rA(Rd1qӦ`,Z?^S~GHjZ0*7"ЀH 3Js2Q"\gaml`HkcG /C>Hn6<]TtQx`>`u=+s3q"B%:Y 쐂`gqfl߈# n@ԠW{BOBAΉl'\bTԘqo5')l_{] e(|Gπu}D8⁾NE--(rO)c9 ƕGMBZ͑VJ[qqXh 3QOc.P鐺xd$!˝@9v v~Lb;ۯȾT-`ʇ?b)vHAR,"*A0 m$QNlPqX>єR܊Jj7 HesЏ ~Q-a2`{¹xLv*Tz:p˿':w=wʭp_hxBf!ސL28:ze[!8w$ /4wKėb&=7{Q6(_ F8$F2.6Mޠ~ DWwʜ^2Nb>Sf](3<\@0.k:Q20=qwUv4u[&99͙S|@،/maG(o&h̻J^{I&),-uq<9:4f`x +j~pr iGVqqU;pb8EgR+Br,1 Sp>f-K2{& g2cM[ڎdAO?ѥMi 6Hl?upaֲ#w2\l80. ('FRTV3صinW|wHh@c. ^;LOHէeF@AErX!sZx6d'k:3X4=[_DSl4v6|OҪ3d-fxư!"fʭޚ P ]'L3 `~ۈ2d[Sc8y|q&7"&ƻ*u:6wO4 k9N!£"kH%Qw]CQ H]OY".1Qk\Ϝ=4`'hVik+b4FQ?}~I,SH*kZ~'VYglF=9z!HrK۞h9feC'!Weu]*Wsi\՞qlE773 _'=ƎwkVJ`L*lj1oÁ4`Y fu!O }Дo<"\5Ճ%88}Rb/VJ~_~|QƸN[Sa+nxV_<yz'C@ gVRԉd&Ǚ ЪD{ZU9- 7Yǫ;hs%vi~Y[Sc-̙PE&P׸4 p:֚Un#e⾄ǨoKFcn\Ae?OڞR2>Zҿg|LpplEN`J5o"O`qpɧpȥ;t LƖxy"w%<~=Ŋ~bZP앳d`][=s9> r98m{P_8d6f jM:{NKq.o^᧍woJC;0..1&Iή|US&B1rBSéD␗cf*}^ٿJFeJq>O x06;sQIJSva)m̷m)3Q:y"6S;7{ɪG*NF;ɫ杒\%fԺ<6DgQ~>B J<IbxlL(Dm0q*;dV!(oI0ŚYNЈ>X,zzy0eAFf/`ms$d^4ԘJӾ^jy~^UcEFf48es{l8hO&tQ~E;IVo:@]/2gk9DX_lfTfF,Wc3ZӰtT>dNoL>;|g!: h7 -$5oJ;(^u9FɗtUѣdpC`fB#aԦf#9c p&.GDl޲ӭQLHR5FP`!*LM7&l6Ϧ+Rm_L Q28cܳc$D'xW#!jѶ{<"pXurw*ScQS񾉩p6[LH{wn" hVhg*\X3ڋ{sw[5R #]8 ?Ůx6w]EŹm@`y&?P?iFt6\uk:oW lKSPFozos+bZV٥}+#:olp7y}9NUȣ=W@u 7U<'FBNjUg/;"&iP#emn*{{tr(aRMAac[I&iůeT$>r 7Iym% ^^GlRU&ޮU `[F4fS =G @*& I(tVsBZZ,ةiB'֛[{C4PzQ!}atYePؓbq8l:v/IFS؀I7{}z$,MqWc[lPLط3.r[r^)Ԏ=Gt#7Dah ĚT=hoL8B xxW{YdGn]-G ]Pq(=/@n9!! zr'QPcH$_o2o( kSCxUYџZ^qY$cyQUYz08_zm&Z|-Omrg֙=O瓇*X(͍q& q~۹4b2a:^DR{,b%+Mza]:h\ԛnNCnҮ} 16"Ʉs*UUXe]#ᵔ hwi셭<{<2: ͣw|>*qC/:ۯQ_?{E0;$??' ?#g XGb܋jجqm@ /;GGUܶSRB"3 _EsLJtm#rJ\ɞGnQw&m};)џ*PaWk09[GpTyI5qJJek5/DF'8o '>(TBy}ߤ|^p_!#-^C[oR4胉I7B,; 閛vOua%11^q‹!o骪{N|.qe7,zص/c{M=iO~CR4wlvDqPphɊDH陎72 }kgLw i,.hI8'0d꾲Sa9j{j֦E&B'ϰq_a,/2ˍEXw}{ wV x$.0jP45Fu\OK*X 2+R5 $}qwge R>|=~w*l6cLoY!}&b8SH@}\~oa_-$EX 8>zdg-.>ϝ@ԯnLQ/Z Z4m YN.>IJP3y;T(lq pJ7/YT*(+Td&QM F2y!1λ'aYLK.HPob8li]q}&Dw^M|mqe7hmN:F[&! zyݺY-Q]+퉐ؔ_ 8I<*ɀ޼#~`.hn{#é5L@>o=R"[O 9`T~ު,2f;S.k"RY`Q >g^Thw!|I UDeVQY/ܤ$"M&:N uW[_'Mx3g00'ewPAYcł[wEw'ZRy~Y4|Ggc?|1]}QA4ȦB"4E\Vr|~mpmdY@nB/+V#,z οaE4}[8?$|E( =inWs;@B]*|IC"(CX 3K3* Mţi3Me3S-觉[rJ KZt F6}rGt(8y/Z PhИ+LOh)<] (2@-y focdkp<?b;Hܵ?- xƟQ'wVJ ف͔9@mRxeM[1ApJd-6 "bMȏ>!V8UE~MҠ I:_5mB1:CJ7d& xNf!0MAmD.q葟)9x F~BnKl7>`h`OW%tہ%KʄO/jׁ7#0D;L/ADr6_7Z-JoǦ )K(B gBUXKMv}Ȫ.!)y͒ #=K]6AڑNKkwH1Z\*!jh7mZ8; *;Bnߊx@NW`O/]īu!*%a:2ߪ^Z-{[9PHSC;@"Մ90<'7X8c%0UbG(610/5ǧV񤉘5yyhpֿԈZٖxՆg W@Ef7CsGj1񹗇(>_\iQAkoltmD@$jN~ȞHh1,ѢiwЃm{ӊmfX{L%*d T-(<)Y묢S/}-xH:zf^PR9թDAV# ɭxo͟UY+q~E&t O= }H)s탮r °GJU{SdEc z s9*;&^Ur=l`K}=p,^KڦB"tJXjRH#jH֏?D#}?Uj h{n:p@x+kN29΢b>8ocwIOf8g x5Of֔Fy_u;A.|3Ɯe;蠞ԫPNM PrmI ta6SǍ~ BG/YYSL~<,5 dRxmzZ$s=?@.dlJɣd kā8tjYu2PsJH jhB 鋼-Si+ 7I4{%0Zv֭^aG D߯cT!ll&Ctr֞˽ܾ2n>ɽ@=dYrZR5cf5aJX8IdƳH:ͩ &= iZ]'DUd:1JG}?Ѯ}<&x{gצ@S/ W ϭ!]( }ZW`:WRkfͨDҐ]M:wMLyBκ܁xwE> B|Ak^ :7"TyNDCRw끿_)sUe ^ 1WLkZa3޽VN g({|їg)v+Ϩn $[-?l7 7̨ZVCM.|>V{A e5HFA 0-&RZsU°7a~qk.13Cu ԝd|4[Ƹ?QսoCar/`3׌4+Pf ?=ps6u8D}!;|cBzDX !,=EQ%LMK=f/J"yn1Ezoj81b&pnB,UXw#|-ם_p}ޓY5LMIEMʝ <.__R,ڍ>9E鯏3u\m OuH'ɶa6[ ɖ?W9'S_2KlzP'#1X)v[KBGr@l6`t8 sͿz{cR2}qc )̷Qv*c5L{Gb Ý%D]P3@3l ĩkXia\ф.) ,z4dZl 7mڴ?qPX=O/yNQisHEŚ7b@ŶdLi@aQVEll&7&hD ڴ| h&Nǡ k?C#}cR_Uk@FFb7z2`d'F^=g/ =@Līrx*6k{cIhzd+2ZGYWew2HHJj _^XNҹ^{+z 1MiŜ.cWyVC@Q%8 WV$^H"C~F^F dQ0 eƌvK ʖ)a} [w]peeIk05o3!U /5@n1k8`_kLaVqǾ1V{M.ڰe# =gXYA?cKҫUju[TfG9,o(h~khL4WgLV=! /i,rgq xwv7jPʤkgMVQ B#¢dC1Gі6z'h ~Uc~ пnvr1a!7d?$H|MScRDwV)_jl(% I%s5N7p&n` t}ܔxvQ9w um;\iP.ékL6W,.2mENB֯/|a g<`gc, 3 0lCLt~Up9,پP6Jb{OAʇSqM-&Ā̗(8$YDMvZZfy  mEP \[{h{ +U,6|&_'PWw: dAR*㔁 A */jN><\}QϯhkF l\E ֘F,& pJzUX`J ?z=H#S5{J*|)x&A,I&>T6><8 d OZ^T5J\wb猁]J]3Q(ToiB' CCHҥsGwM0@d՟fJ ԎťL_.n-f]~s(;6d-~w5 r{:,{+}Z " iȑுOm[3GN!%S.Z4%k-3vgŝw!۰24abS"gAs"|?) o渫/Z2:&RAZ:@O)( |lc%ܵ5z4~cFiʼn 2,02'/3=ULHѯof@<%+"l%'n_kOYPs2p'~/g6<ѓh*[-1GK$A\![zZðK{fh]؂s/8 TXH"xq&tlmmкl/N7|Xq^ld*i)d^cr "V=AJ%$'z> ɒ%s@N`Z9ZSH C~W9ͪ6=2-/Hc<TwQd^%2A2_}*@yذ9{y>P>2#}]gZ{6MkM`Pc|`1^? {sߛgQ`v]٘kkvO۫8U`h.T! g+St\lIpm`?]ZbU.bA;&m\KBsD 4uI2 ("nv#)XK&僎W|šŨ{ia{8k+tlJ`=WʔpOY㺰VcY+'ksk\DFmkg6'~B o)7H ZRTNeW3[xjX U=J7rdG1eoS=exc&=LcL~FE( lZV~AC.!Ȼۭd PG7pC3Cue6qK6{)zbO`hܲ<= 5]9,@͆(zllyjN x8K8iE;Ku8I8/h}xl i`/kzef>0c bF[21@ &xەV. 7xeOk\`fyI4PZ-vDm 68r3Z, :|ߋR,<ׅ`? gHpFRj2ebkU=1RKx[ٮ=ji>({!f]uqUrbTWRT5jGțxbZ'@AmʜA `zu<0:Ah;qAx.C*Hz vAzvtert;hc(fV*k)=^ ,:uC_4u_?1K= `k_iAC~D X5ºTGN մC5|֩q9L/qBb @(!<ߙ.Hl1qrܗTh )$O_$ @򆲡I r}AT2c✩Rc'%śͯ\q,''"nXF>f ap!KCQ7nmp vkY}/XT͌7yOq"3I:%i\w5#/D2oK4/3ю^񍢢*ӟٰ TD25\]Hr{=VN3%<`WoGCg~>xrƪ8n#lίYRn%J턤\S;IP;:ܙ62.jbV`°$ٕfo Ԭ &"Z%K?Cjj@PWvqǤƨ b 益xxM+B28 Y,(:ͅ\$hf(|^ΠF) ?-W0a׶km; $hn$䡟Ny&gK5C%0Q#{#_8)CRޫ nJ*CYư;ZȦ<[;qCGH5ָyT-h4,;? ؘ>-I`n4kymnoL#.5dH ٗmA\06qhr__ʦ=BGYǪxp͊ߡ*^y#Efk'2qJf])(l"HLa`_/sgFx"~Ӏ3z[s𧳳t"K9hXԾUH,e';3[EW 2El[X^K7,'!’䣺"jy4Sm2<cP!-uDC!&LTj6ͽk9oAϊIQrNuFY͐IųuL/ uP-c0=ūa%~}ɗN//┉~a1:N 3Jt:#2Y!; z`b~L-╄KFrm^WI#rӐ+%Ism lPi;LL ,LVymͬ4+dP>{l$|e+JO#m n5GV|5IJi"kkP%.X̔.*@-lOVg댫&_$' ySP_;8>gp-PpH\3@no y9rG5D(~!IT#暢7Ru X:B_) /oSp0#~÷o- S|QX^x1[\~h)- \0QRSP;p̂j_͑ΧPn UB~N>6 }!%Pc^[XIFphFJי pႛ&j##M;#rNpԤRS2hcL;08R/;z4 R'yaMiS].M*Iy"Gˏ5:I@ҏRHE.GˈwQG6e Hʕ.~IZҙڏ0fi-:?L7~1ɏ:A fi;e l& ~~u,A¿U`0gp:!*[,D_,?-L1q7k}bpAv:p] T{T/YuFTNu4 XkzrB `` 8$$o'ÎGN9y!c,b,j]j=1n`E"\ؾЕ=&9&,XTF i[Gw; ފIr&5xs .x,N-bw^>]MLI)2"7o'V7=V%jCGh'!(S; in#gu ='; c%yD#2˱vz {HyB s <f$  |O F|Ui^3GyYZ.."O*݆]QkIcYyXݓR3(o,iI x7Q'YT-Gsf uZii=6y'!υ8>\,j]dė2_o1y!7, "ZӾZlzY1TlCs@EεRIKTeS].OzFd1)#")M two@ e 9=XN/Ksy!X qZĆ]Zai"d.Vc=(h eʖʵRv@"ZQ={w_VʖDiq_seϵFj9=b+q7mk@&wE$dD 2;MSJe41t]Yx.mw'e&Ӣa=w AK\*.'"U;TC;™h!@d7~X!k FAb~bѥPDEYTf (zsdɿ;Bz_Dzj&70%\Wq]}e8ad7BBCtR⌱Xeuxȵlõ2r=WsäBV˚Qy}kY̛qbIKx}.cAηyMkej0/MP߭aLz aQnfxD Mv(8sTK3%~bZGa!cNv?bu绱FvR4N۽Ll/uc\0TkX1q~uku)f ; 2RBϬ:BBE' hmnth%aUye= unFY=3Kzk"ѬW)]'0d#}9>luЈ@)P!y ^H%LDM$]J>;C,' vʗ=b*:+YE՚c{֗zy3@G 8sڤ:T[kIMͻ&mzL KW7Д~ i@Y~08Cj>CN7QJ,Ӎp +v;8T|-L"͇h A Wn}zmiٕJ@9K^ZMMT1?#ZSon[{MJbO :NG75*t:݌_JP' zMG9pCrBtm/#eOA8h[GX@$ xg2hSNtoHtRKo}}sxaA{ۗǎ4(v~O2x%)3O 'ޫQA]L4Hl'N,N|M+tǤjMuflBzLf7o(.YfkbhZRC\Nq@Z[KlЌ˼7 u%ed-ĨF7MjrF-_4(*rĈ'_XV : L5=K߲h@*udoM:PM*1ڷYҦ"\},I,%Q13,^ ,+/{;Gd9[̮MF"*UNuˡ3'llpEZDKmBI IHʣUش sMIs>GK/IMi0@3OGiTαFY&K wPPIJzzEVsHk]]&# V .oz)Eֲ݉huXbdʻ[aںEQ* 22cr܉1i˂@Ա!)S i֒CLx+іR+v*HƔә.%1<QaE/h("g羒F {/YAJ#V Dr$'h7T6 r]XP /XT.% t|o-u ! p'i9whsfopD`ϴ=QjR qzvd1.[tZ5nM; @RI1X!G0DU#Iǫ0">/IMVs8w҈fk#ќ)$@ܴy4).6j]\&]f pV+CҽJa x8-jChGE {b;C`  GU]_MDYaOS0JɟUs}2Ǒc,Ym,`?۳_۞KȲWzL!l=vB 9#ǟ?Wkmަ8zaOiw?G"u_⻊ {.zQAJ59émr:пGrʯܢx[eiz㽗Kزh~liJB%a$h6Et /QN5 KKn?_-5l|HXa~L|wّZ/}uW, 8M1#6Rk곾+~A<xeOQE*b/tO q磉 Cd(9R̘XMLJEoLFZ:tХ|Ox^n;‡ 9DXYPAg 1!rԔXOMzp' ~_gnLQhv[+dWk(s$aZlCy0 vƤ3 hoDSПLTL<$ce`{_ybY.23T1u12d76pvgoOy$pUw$hŌN0FTXǎKo^<<B<%5:hheWƸZi mˤ /((XLބw3]P]Рg֖^v{wץʬo!+@u+\5Z zhj\kɻؕQos_McTCg# #WpeD,#ර{] ͽ,tŖX^359a;)JN⇦xalO4}<4jF fPbY!d^EuB!t?GA ˉz,m ~Lfw ]3cptkپթEC<@w/حTzniHC}[':5A&#o='BJ>ܖoHZLNR(x,HD9;\?&ذ]=Oz#C tƳ "^^+!K]bׅ3.- | ?&H1so}'m}poُ~sI={cw%btWz:Am`?W{,;B. &;t>T~L F"ν2x^@.~:h !zYeWNQ7R%G2-VٞᵜgTPL )=3(v0F? ?~)58;hB~Rw.!l zTC mM?I(Ҝ % GOĕB !qbyOluILQUx|FK#cT4Ѹacav *I;o<$Q`ɾ50z7NL[+-9JJs{װ<@ ͫ^.`BӰy'&w2:W&BˏTudw. eP8*07 ӷ3CMPz<g(Ygn ϸT[_}#n[> v<8r /mʱG`i] :&fkꙈ=$r/1Z7*Jl[ߑ]E@ׄW" 51fnEr;2y*WlFH8v1!R, DGcȨce9'J*gr7,G)J-lr\\+Z&4F{d .sfm4r6**h er)RPćLg_\ r"I.R7GGNsѝÃNr)XJ!G.5'4roTхrn}N0QwV\zQ*]&.n t'Fq)ϕujYffD# |qz,w0K'6 6Tʂ~Ll3> +sr7d ]Α;G ڴܺ4ʗ-ZhM3Q 8@|BH;P/j&v:BJ8w!  -4\)\h Z2@Qܗ6K:GtkDyxpI6,FX٣*[uLK]{封*ZcWKZ7ߦbszxf.@!]HS/-ƙ90s5idǵoH^Ld\Sp1I~Iﻻ\?2>hS8*8g -Jրw>A 1@M%~؝\!hjy^A59Da^xlhuWH$fvcd0 j3p{c=lg(>XӜO: L8㣌rwb8nWXQ'{j&`,f5O 99m@BĤ-!`JNfne@`G>'Fyl齛V{J#]HDжJ>ERҙsJⷦp-/~vp2DWkEQ"1FhCk4y}BDc$>ogT'sO$Y`2<>Ɇki=+o؃+,lex|F\9{z=R=nd8C|R4u)!~,7sG&AHϬh D R}Y;|/ r$E]q})YɿQ¶G+Xf㔑)xk疠F@~fcew8;MR F. gc/yrdT3)cZ^oH&aAc@3S뮦q@,"X]eZ@cIe몷JƨN bQ\֌B {3" |us=w,e~rHgY 5]]օO@hyl@ b ٵRȋKr%eVq^ T)sS(1 w 'ҵ0 teP{͓;5&Ku}Y$avI֟/@VEi'4ٿը\(w'25,:Kw`$zYZQjb6J2%"97\fuvt7fb U吽}XoOG bS-ṷ>Uû(ΡA6NZy{5ᘅfSna/OYɩ|yl]}p.O#|6d5bb,XOo$ 64OƟs/\0L3(}<:9$K}q@Ηth y Aۣ:>KDV˹tD#_@C+X$b)vsl!&i(Rdڋ,mp`L!c3qѿm `Od!Լal6o:ӟ3h?DWUT,GɍU1YE3ęx$V'-h7A8,<8to֑?f}-7Cr骤!E7[7-Ӆdzdgsג$6: r[XN .1<q;{m !0fS|xXC3:>\Zw KTl%o.uAoB}F:50Pv"GVFQ8!DwHU#[(6'e$% A6Ӂ|,r10s;Z[n˃fv1 *!CHg[{O;ykUb"fGO݈_MB1ꆊ:o׉$<DYE%é(%xgҫ!?DlCLFD8m\/r885N P!JBL;G'1u-3dFZi\pߖ_<|C:dϖ2Q #fkJ͹N% ݑ(4i^jꑊ遚!*EB*'Kcf'JT0TPbLzڠ!=#LP]M5W@O DYV pB<7.h_qMad\jU0 SIDg'j-0׋6h,s;KD9By z~ `N`&sK'0sSuQ,.mGIH,؃f~Աk 9xkb$k&QOضSۉOU* 2=|i4VwtdA^StY)),6PX(Z89skB7;8lLlm'LL5\3 z|>e{ϙc".r_\ Q%혋e^]I=}E")/q=mZ i G [oSZWH{tVzӿ_ S%Kd-%[Lޭz,?:鸉}ަM`SV@펫yQ(^ @P)[NBD r0ymUgBE5CQ- `PD  v. zqhg3w_^(SmҤt*r`;c*狭hK&qLDmiJn~peG49w/m V;#xqu}=|ૐ_w g@x) f7ш.`><ܛQlFa^̾|(#տwni{ISOw[a>4G!,rjH}KVyy/3zG/8ji!Iu֧Νl-q̇JkuH8ܧ=]<\<Ā'z8|˴#/-,7ƶ)#"GI]ralpk`_9,V>\_F4S{X!S Q/N{s uԿ!*Ɂ!r"bD2: Moꈛ,,du^+/85F#Tó(vI6sRZc3\ż"tdY=\S!?*ȸa 2d8"K=ͯM--SqٜC j"_6Ht5 ABSvDVARM*U]쐪()ylEiEU˲&E۷,ȽT7*NM`axOv`[QS3עb*G϶K7; 4>~:Br87ώԉjl|4uaiQ-"_+hHvڏ䟴zH2]i7FulYur~#$ ٹ60ܪܜ"o4}د!-ܳG" += YQ¨`;K Ð[ v H#u (S0gjoA ˖ 8%*,mY\%+`xqe&&u-KrRG(HG9 [ \Q&"ػ-orrH D NC(>Bf#GYbt78ȘrwUnJcc϶Kɹ+Cy>i@n6\\ |L[d}Y&n { ιzAo1XtveCh~K}Ӱǐ*ddD x{B5&Yw+CZtO ~?Â.!*saw&*{H[ i3ÊV7(PZnD=m3 +6a#8 Z@?vbR BO&*d7Q*!͇͟ ?a3n'Q{\.!`,@nw,| LG]ՙ YtμfY'HDzn|bV+^*NJŠggqˊߤSZ>d6(+J{}qW3ԭ{/a^0@{*fC}; Î Uts&HkaN>}=P jQ(FN g:$qx&,^V>aF~75omo1{_ݗOi6V$_c`W(C52~d!Y:Re}GLXgZׯEmY A\BGUE̘ԩ BD\L\!*Y9C~)*41v|Ca м4`L2!w gyNٔ+QO|=څ8ezȥa/R@WӸZ^a{o% TX_64fi&u3pR z sol=4$)< EF׳Z:~V$4u8넜&u5ߔ?{F{o w='h5vҝ\I5(An:ߡQdi?ѽo 'VPڃnijKoCD旅'Sf^:UI/Q"&V@bo&Us;]uEҡz[ij=n ݻ:9M*yJ:9 ;4P7x:}/NYPz .u[V{p=ШDiM ]:,#מuIxx+:=2/j#N}i :lXx y[7xsr{3 ^&ŷ0+ϳM܉$V(~9TVG\u*t(&L;z d[z,i+kyrA} X}^gXTC- tovrK{R1?iؕO86?5֡i]f=1֍kޛCEX_d:i#,-LA2*f)hoS1,L@'?Y^vG~c؉ӷ$mQQFqrV|pͧkVtNkP |j pUY:t䙙]cs_CqsE g&g;[TVsqNw>ђ &+Ft7.TF5obI'!*]>I h^W犛_S0'w5~Vw{{GM"Cq䘽ўӁj6%ѽH|iⰩp^;QE('*= ^JWhhO,o9ݶ7Q>J| $$G -G,&ۼ/4Dm{ 7ub+!&PڋK++%Pyq Y2Y_T e6 BCȭ眣M=TvH0<4{Ԥʾ} ±k0ؤS˶#V Bl'ǙJMz<~{O.pLT b㕎bi —\^ގuّ`MU~֯~D6Q3I҃"opIĻ8t#m?# >@Y횒?9H!hhe#;eғdD4ۂ Rf/tl5jkA X^E\0&4)PQai&hоET>WngIR݊`BjJZaڷЇP/i|.3?af_ˍC6B}ġ5I)FZ{X54T/1rVϿ*y< ѷ]0},C,t?lLҼ`U9  _=M4ɪB?;so; c̾ow92e?DjmԠ 蕤ׁJD*\@Ŕ;xjP0Xb\H] GNLO8,0-DpcSFL.Dbm!);Uȥl}m+we Q؎!E#?'" &`R?N~unZ+Wu:.ڴX1&tg:y*eƤG?o=HT=6Glr ۤc[GʸB@7,*F vAuƋ~s_/1lDc E#0|$ީ]4*MOz&pUV}.\}(7KVNݠ8EqlEVֽ#P(s'qzB(͑ԫyYQ\PE}<> |qdVUŮd ^8gAЗ2 *.H6ŵi~{jLz_U JCˎ~e "IQ c&yxS6~%> WxT*Z§Ti'o;@p>Bk[A}VQi3(JEF,إ.nكQtRWVObu+ G)8dO25ik%8+̖RjqG=nE;d>lXJPYЉ5'*qκb*o*B_=KH6E#YzV$訹iFgAx(PPTOZNnkn<=i9WZ>Kj+1hRzth[aǰ*ѷd[ 4VVV^:D $Ez֔s=g&0fA-|Ƀ4_Ӿ9T> ']Ex;KA6aޣB.\pY7,:@6=2`p܄8r7/JdHlLآ$q/:czVF[)l>H`@u-~,B-dSI9槁^ƾ=~|cV|(aD9,ٗc6ՙ3Sf3b4 {,[VdeUp'YQggB;4 pt醴W1n jqq^av}V]LyQ'ZS9^B|/ս5M4`%)d8VC79o;?eDϔyP8"fA4Py,n;ohpB|l½@A#V5W+`%"FrQPQN,|$m}*b-~Ŝ kTs/E`J$Q m04R/q0*}i }Z>х꤉5I|,+pĖ9`-8ؗj ?VoڮDfdd@pABvCbӥ:+UL>VUU8.$BWv DmQ@)xV5}= @;N, ig&ZE46Nt7#"*ſ\Gz~FG !IyZؗjMHr)mBf~ܽ plOU fAL4o̬A$t0|qOMhՎwx(,4g['dvȭ$Q~ G=OO3 ;%sļ`dʲXB^Uy2ŵ?M YV+lY{~*Ԧn%R  2`'tHPϳ n b>} ʎ`-G6(䇧zJ࠹N_Y9[T_$Ems/_x4=Rn  ˈٯ/-)V;֑Cz !F,i%0HT+o:uj)=A-kuy~G ?&O,Ĉk~T+nA+Ȗl՘ #}-ZWEDp)?W.DIoQr >M7̯o ,1(aEAu>/_7~SXDq]LY* =) U&{Fj c4X?O{[L\~Vs }:< ݨNk&1C4oExe?I8^ێj0SL1 2_+EDz97Ry=VksoC(z6s.Fʺ #ٯe(}.ݳĒ鉃7ͳXDܔXkk fI&-jcO:4IUPpCoS@3&}ΏGyI|,f֣~܏1@8KɼWGP fFb)mJGNc] PUhtKJҲp*l>eF4\_GB``]@ukIk1]׶tok@Ud Qs/3jeȷ|E߅aSRLM˗>RBܮuBd#e2WՀ٘%~}(Rp&ϓ=yf(ŀIA2 Q;س/jHA؍5E#Ϟ}ä́bnPJ#Mˤs+s=Pb+BTѠ":P&π aBɗڍFƞF`w{grH[u# 0ũ(>wяh[9lYu%ͳ1+'aia)4/^K%GMsvp*.^JN;]4Hu2F ͰWPSD+Γ);wvjE՞Qϸ1(h]Czxjk}Yco!Eǭp߰'x?V(H. zn40SghPRp}U#D~Ɋyyz jFAZEv3UqoŸ?p8Mi"*֋3 =e3(lV؆[/g)frQ[1Â~g7"X uc& ¬f{iWaѫE`^%Yݺ>RkR~SN6qWow/MgzO# hg oN~mdQe _cGA7bZC*'Jg2"*bMǬz%ëw𲽴/* 8D:{.Ο^TbA;0 k/MڷL?)3M>*'Ll؎z&ЦI'/؄0ś*tLft@wV1ے7 T-^| {@%vۉ;f@)WY?Af/tm X srN,Ϛ+7f0чe?x䗖MZB'/ xa.b뭯}N;pCA;MŞC`~^3e:\ms>^{[6>xuc(flh:|aD~:μ U$t](5$X&5FTJ!|Xu4zZQ``+i@aΥ,$U"F e6qTAe1=!=u >6^VX>`ry#lEWGghRݚ̿ΙW[Sj# mx<<ՂiS#F\íg<ڦ4_k6ZI^o}kf-GVwhWЁX%TSr#;/CFu]5 EJ7~X/e⟱ c]ѯ25s{ t(¥#l8ZƃV/_aYAz[$2Od+SI ȕ.W>\{MRLxt#qA;h|I'j'{g$[PͷJ2݉뒳pNQRՆ+W"o>=(т=K~B *P;eK =0#2YxV_rqWԧHouU b Ŏv @^ _,8kzjeC9 ǶF C׋ w 0v@&JD#%K!W~"3l7JyAɼ$b#F+_oWV.Iͦ4cE8ś5Q¡G&gVX;|ſupi7U+bv[fh'Lp0{RwEQˏ?aK8Rꁼ{/ׇCp6Ww$"$x5ι~rJRPnu+ॕ^QXhK_ > †STq; &@Ʊ.(ܒ(F;+]D Z&/-EХpU 5{QU ?V{8^-w9tWMb0~XwU'WjbI.B-rwK ~l>܍@J|5b "k=o ڿS$%@d\ONɳ9U ڼyFF@)|b/c;"K{%~@9MF}3[=aj.HQ;@+רi-`0v#ۈ jPi YsKU-{]PtO4iZpΠF(xZ!L3뉟k:`ɳ.4I'8-%JGûz&s2w ;=`R,P9?Ga)cTLn+=JvPh+]^6!?s-ϙ?~.fbNcnG'ތ1}wvwMxA`0v"ccSE*=Poұ&>]R %[*%d`jkmWJLId+hPxR ZKW@'x31Kc7Cvͥ4S#pZ͹iBUx(hEpד'$&IUOB}ȏ[d:Zϳ=)vPJQ%@ҦAV(AA[ t5u#)p6C3Gy/j,Bk7ɞ& {ƒNc>Y {(7xv e˽&k3o"ʵJ6V;2[M^'ry3Fo5LafS)nW=k6Hz_L,Tn,EG_~)VȤʹpŰ w OP4u3^CwzϧRt2ӑ!d(9g !ugQQ_Ot}ep>~kܾ1M|ݫߑ2pjM NKҏX-`# l.Ğ- L)V"KuDޒ@t1'-;B*}z/3~ʹ?"-|~Y 㞼*n˾LUvV<`pdE}ބ*)OC?<#GhttPPE/9vmǀ`mļQ.VW/\ja,c}&uk&\k"l|Nddo\OGZg۩_쪠&WWKD#Û]ggL7 < ҝweJ { ;.>I֘e{MM(K/mKTnro( Xˆ[ :uD]$: G?ݱks"{Sg=АR2CiF @tԹjǑlWGb Q z::C6ffѠbVXa X!CDU1.,0?<}X6=Yxտ P]q梁*&[Q )(LHRA-0H]mgD쀚9!W-bQ(,Zڜ=g s;6LFT"G+k;m4 \.Gq2wK5CX*ݍPfH*IlARJ8ŧi.WqtMjJ4'5 lA1k g^w5!"]luO/E~p/J(HS0p0llyB2wx@E,}5D<]( o%q)QGzs~*n]$³F.h&ҭW>d+ TRlfoHQ y <{78O`]_啙\ 벰 uv1P+:_:Lx(%[R46ZziGpW4|5=71Jh#b6G-]6P+ɮ|.X>]@ZCBi`c0'Wd%9悐$J`J*w뚪 ;7fzbIH/$G nuٲ6~\Qč`͇7*T'=(㇮C~PE3+^ϧb<Vn,}r[+7:\r`zm|~?lj Lm]o'7ˇ/ W6G[_zfg0)!! 6dxn*ՕL.I ^`}f)@r:AWMnFq#f C(&&c1t :08}OL[v94۪çIAdYH|9`bT9sO7n?&d \} ffͿȩqQ܎$ 8; g#?.{? WN7eU1>[c:#*KmB LEKTʯ~~&BP>ˮpG8 䕯)=Tg&PQo)GuOeӝ*4Jc`"0z7;/OHCo^>]w:bEm%^u {=ذd#2#R]D@58VGbhiu/RΨĺπ|Lz LqSւiLWNv,`Bsj 䌰\Hmet̓k}Yw޳!ȿڇG]y7 ӧ*'ClLcLf%i׿fF .=<B4r:qM X=N}l $4K1N$+zZ+ + a>hy  @!g HsMt1Ol7ۨA Z&m|쑴ޏ@ n|>GRl~7'̪WLj76aC EOPX祐Zw|U{=-(JHOtdSNy#Dw"pRvV|]A8]9{f\?L%"0W%8*p>ILBDjFk^΁}}ru0 !jT˫qoV!-%ZRIh⣂碭L$m"TΏ Iţ~,@sueВi[zJ4g+IEϿc}cъ%c5c^:!hs Cn%@G2sN(9Í`ƙ4'^A *1yV .(9B ~1$"|Tu9%K֣pu+(i=r> kmCt椭 "؞ՑB|ބ,G l{M/BiکT iMNI->5s5|{KO,$!Ma[*F 8Eܓ\ ʖ ?F ~-:E9YF۰%t i*/Ds:;l2vщ&,*}-!r"E$LĀ.%j~qBpx)rHqdfZv.rs4q%6Q78W^ ,9JΌ HFLo'{缐RE7# (4OFg gF_V$$ЍTH;<ʸR6[Qh4'[oopY$'VUSv\UJN(!MUs/Ȉ1)n)N2c`2!u=en4.&>Bc5=J!yDV56G>/)<C-TхG^YDAD8 so= 8&[&E?_ź(Qs ˗\1MK&}\s>ih%Ƨn8V=́Xpc+ohؿ*` hmåO;m 2Al+ 48θ*hêOd*_|\QJ7B/3NW{a"&… ~$~ 4UM!eMN7)7lo uVGgO vZk/Bp)Zy_w0y~%~?Z숐abM%cx&M0s1urV-8gS`xnvs9HD )Buffjǰ2mu"GدWn3PuCX%?F~Z]Z̔1fGkKG~o.D6!F)5%tٔSdoM؏Q&Z,t7>O)hvH^1ʭNjm>y $hJNR4"MtVϥ$nXo<,홅$tRJO)( |ңwX6"+TVpa8Sz%4}6dݜ W|i34Rj,2oz&*U~F2#bld3 dQ(Ƒtkn>;|q`gko_:<ƜݞRJ{3N9V^z1xg|"R_,Ĩk`LVE6ߞKsö=[E#_Y^WOqg adӯk{5]=.AV<(Ɗ@Wh~Mv["e$#d&sGFٛ9,#L-+ɡ W)^_tf9@$C@5̔D Qsy=9.7b#9章6DTT舕6!IץDm2aN&({v֬*\:^+>^BJ~a&1-;5S,>5SO8ڃ~ZDtV: إgxN%sjlٰ!/,!7|{r&${\=Ӑt:(F: UyRNgyM\6q1 ۶)8X<]YGLsDG!+wxo)ƾ>'}F9U>uwM)}bđ3.`8AsKmz`(*k(ʢ }!wk9z(|l-*M1I òLl9bO`e㆐Hvq46>ȫwP#d==J !NkV 2߆8D,yWzjMmHXC`SNE[ÎB^~&l)סdaW`Q8G&Y}TUsaI/L{[^:tje~O3P[Ԇd~'ߔzC4c{]aZƸjeDw|62ECa'ڌ&JMͽUO֩>,[W"qTBf|93E=/Rq-@?Rpu 8(KŶ!b0%ė'{: ڛJP˥[)TW!l4H' NE':g~:5Iǰ^' #˟jѧ灠p:$kJ8PbFn]!tZaO} d+3aC&uQ@Uซ!cyܡ: iensx}I1 !"k\%%ģ_0\S]+ŧ>Q"ݚedicbid29z,@]6[TE4P8@K׼lk*E_wk 2·d6YbzU'Ӑ+Yy悩/`1ӟ˛X)r 1+g; {#v.fk!- طӹPfRH+_;2?Cj$g=ێbٵ;QƖ6Y73Q eWw2mĢbMgw2,u4bq |?D@M9$V"2H!| LqKaox) k_DĮTsqؒ6e~B6ijKM(Xz{ψwCg%{($նq‹ y=T=ayݤ >Q9Q;^,y28lp|E.k-1M&sx`{8?8 Hdw"ccQV&hUWۉF zo3{їTslSo`:@,R&JD:KoI rxI[nD\:Y!=V`r\pͳ+ ;'XXo4'ZI0ŭ51)R'Ll38c}vqaUn61}?5_m{s,edCy g1y$i~#[^ 6'j:M#FHY(N,_ 1{ ̣`$TݜXyaǖ !Њ^QO"g8'piJM/ϼ2^s#} ^N^z^)(ӓƖgSlOVK_h^ V8wMrRl*)L.6Ss `fG2ZAM[u1 XAօXbM/53d 0x:݄Y 3ǻn\Slg:<'4>4ܘ貳wU?yE#Y$kcPD! ¤vږLރE!$Rdt&5U^j-5u FɘO@ͤ}sٛE; q|er)+-{eOlaT^r%!qpI&<9>?ujr/b%I%McX`kE$sL*h\Bphd [ 5/7QP &GYpᔇ^7(fđ[FPJؕf pq5g4|+e,wf U{wQEWJ ET}$4-莪X yT"M"mc>BG-;]֟8mACy^K;|2=Ż-4v]Yگ&zXmU2q0$i<* Py4Lt/OL|Hͤ+@4;5-"l4˾6M_-HukЎtO~%; [y<T&m@ж]rќ,oܶ0jD^msO(_W*&S_Aqz,F$-r2OW!r:8196N%*Wp3ހ@2q_.7ԡ9O_ڨT Uz+42ꨭdX iv]tWGbSCl|BpRZrQRoE9Zd.r{iEBﭔTCL.9'[MpZ#hxri[L϶fgC,){&'Q {!˯lP _}eq Ź@b\,I%n[hc-q hnmR9?j.c1ڋ[5˷ɩ|՞M^S6Yp̯|( V)eHL.qU㕘麅vg wA{ i/Ka`PM|"fO0K~ vr@Υsj> (f,cKd`>}y@4C%5 {]Z@-#yɣT.Q mR4 C'i*t.K)~tƍQۗYw 5ZE Twd G|OܘZv@]Skb͋BD Jron;x'nnj't^s{<ƠR2:~Z-ޔ of ԏ0 .C |S9( |ȻEdC[7Uq7 ;!uyUK/nĬ)|VMPϿ?$=4o"wBoAPw *x\Uݪ&(d6:9m-FQ,`_UoU4jh qk(jm&(ᄐ݈w)owozeC/{nfU+ F s wcPI>Ai7DUCfKU q^CIZ\+%tOAA=01iX-Uq{-_ &RMkU' 2R*_FwTu+.1$Zqw.f܅UM@O3@e,T x3_0Thl==D -aR []Ip(lwp(Ҙé0ĻŽ9{a'0;&wGMBq&.*?=Jc@.1XVT%GSI' HiA ]o5-vX\NѺ zC&01~vTz`9-XUJɊ/)~s:q>6I죠't˅u%B5D^L 8<pyi{݄BJJ|66/~`0ȳO)CA"%(O&Xu_NzàcM1-b.CL-g5q?HcmnҎQc'!uz֗SBb&AvV nZI*gj^|>:f燎?Mq!aBJ*n5A-CKx8~EłqI[8`$-aҹ߇b?d˒ut=aH_=RX|n*>-K,d>l jofwpT&s}JH'39<Au*=@4&ޚ9գzL+L9I inP1~g~uO ZEPr!J{bܼ8*FVGzvz&AT'iT@l6SCuQ WKZa/d9hX`E]ٴOP} ^e B[YD9sYyۿľ=5NTڇ/Ry?11Uң^ugu_W缼*|fv;:AJ"Wy5p3 <}.SWrB3;r=̒Lad_a5E}*m)r4!gs\T''"eUD `bYD@2h8I~&}MK PCQƬW½-CXAZ)!27`\"R@O){9|u5 4q?siVqj_UJ"8JFv88zp1fd\Ub˂m>)%帵&#w4#b2-+zuzI͏CmN ϖ+5-}) \i.K.%8K=zAe*iPEqV>FVuj1|Dah!9`;~5(+)-3v4*7o;E[)hG:K9%WMM'̄+m4d|0Qm!8U ?6W5%TnCW>>./DfpĥbTio{tES8 R|U%͡*gm9/뀝G "#x^Qgz@SbNQΜ7K ̴5֐L;n ~K#k)e +2ICy7u=q񠜆~c+5iۇm;Ln{V}qNF*%‡ t$, eoW9m!Gva#4%֑g^nnŒT_'%۩YlWt45HX.?L@wGV [A:tJ[WoT௮`vo8NGtyEܠ|z7rpM鋪']y1?㢓CڛTtLT~'ڰtEY$BZRø#EJ^&K6oUH0z^X잴`G:,MgF M*<S*(ƌoI=̤$tx?/@%aJMi=Yɛm_NYJ ]:o3C~M8~f.\ Kq1r<$QD}ߧ }2:-tl'\'5 /GV'ByLr,BX亁x(f"A#@#%/q 〠Dm|Ϫ +g7WUJRU\חeǷg>BgxજK P9f Et;ů,[x ?;_7E{}[(u/2EF ڒOlN϶^vYԡDkCi$~W^vyYDUʁCBk<5Ҍ0Y||?'CKsQ)AI+/I_kZ4KrAɆKwLdkΓ˷nT ҆k6ai G1SUtĹY|a^d~i R.@OÒKȤ8©([YR (\ "ߙZ G S(t$x3H_Hfճ5,< MКh]#*:k>~" zNj"ăLtt:aY}`H*Ooz tͅ&t|Jv􁓥T@֐Ɔ=k/CK%%^;uo`jd飠Tt[FfRj^CYm^aJNxRܗFs t(wx=ʷI-PO8vu#0Bõ۝3^><ȴSIJr:G2 RXoG׭/g %o3lJURZvg#m,x {NJs0 TO#& Bۀ[g@{,$QXin0g~.8gig8?@Dl@Ȫ&UF\>NBczGUDžg8 c֭S姪0eP! OvhMY%Kw ?=rQߢSn!Z:%f𴁀!}FKsB?˳5yML]u5\d%j?^`g{dr}QD1*;#lDz\D{Ъ_$]tԊSu4rSCk&/<4lJqF4eeBHpu՝@ie}_1>4ֽ&;,:&LÌ)w!Iiec4b.>38~Z\-OP1:skf4.f W0D@=HbYjR\,+c!qXp_QLLg D5_A`'xn >1.EQ0H>o YHc4JfMEU}A![7b#r{c{T R>ާ#xhZ -HvN*߿EpOٜ&{Q-|µ1\č9|~h\qk||oOO0!ʇdj.jŰ8A dRѐO0pbh8d-ԣ .!G\.Jtr uVx_2ּ ( +(d}8P?iq`6K|ܑAHnч.*t~vr `4\֝/u##u ֐YpW*u2 xBp=~:bA0żًK-x7m,@CkɷKc#teFF9* cۀ˹@ :̛'1wŕD.@\:aeX&NTrxCt L? Gui Wh)(c[W4szvE yF{=[~_ιgHް;MwP"h@W ɾWr(.9xUy}E,!9|/KuLObXܫ[/Ȱ_0͗\TRU8?_&FɁV+QdJj:jB){Rxkkdx}(D<TAO헮p/lp!П)R+Fi #r/v}h 9?+-1%?C6&Eؒʄ=e7A"RRf6lY& ˏt㗨/V13viq,Bs xz?kyI$˟t)Z]D%8IPK&1\&}׽zˮzJ:^F!NIF0*v_tGbe*lY4QZ3O(Ng».'=,vP?"On;%u֪4!O{&Eɯg7Ti~OU45ضezB[OըC)$yТ %zN)nN?ܯKyjb\ W w~h+pI}-5B92 *_RǀIR.`?"U-JJ *cFZ=[Iԯq#cUPJ()_,Pi퍺C3V.ո J zˁCglI)(Wa&ЛNk9%+"Rmd+Iƽ1u^+0͔RO!F&8oA-{ @h¡K<[ Zʏe3"}6E'CLUabN` cIZҎ(b~1yHW5U@CZu<Qx-MQ6P)0+m&̘ǁu:›LM^ <oq+w~լR} GLr&y*1/ ""PFwXYϧ+Z~:Uv`1FeU? oӵ]bF 휻%`RS5 7` {W0q6Jp>!LTadn^ډr?yHy}}sqU8-@UiVDe+app?ނ!|̉៦V8f\Uh{u5aE܀Ȝ:.GߪBD-р"!4ぱ3kdɝ@ǻNVHeA(pM=e~/_|f RM{`K:24KNoQM[̬s>Uv)/?}敂I_`EWDgd ڞԣEݨUX܀HLtSSg*^ ʹ._^ e8$7RmO=AL` XQQUzHűz o{Iܫ~6'$톅Isrn(—NtA ǀ|8Z]Ouݚuv @"z:4KVF@*u4 ȣՊ5)HUBL+fTy?U4 BcyU@Fe]BQk([for4aY>^)=u ډbV~EN$e;A29)FHZeBrm]{ k A:``dCzxkjwYl:+$|ZT4hO3W6>.ă?I3Fz+Vf) V\nȺFKɄa \jq26w1 q!\ >O{rQzNlr%c^wԜy6;|>(ïXmb=8_s۟-ɭ x0*9A!T 1ǝyOrOAooLs/`J%.BR3U9C'8G=Bܺ'h"˶coM҉ZZ ~o5lBj]MqC28|j72vY)Sn MԘHAB:DQ#|PoQY$ct`jd(p&FjMӏcʽm&dk;*4bC{-$%!RIBUs}l48ؔ.ʳ#!=)#^¶w Y>1JӨZà tAa;('}o0>]:k y)%TnFh_JFկVNVm#C`@Yn^=qBiiV@8X_,x 붜+.qSK51|-pZ:SPiFeSHS΄[3le2!R5aoFZsIvP388ZiY-]gb _)_I_-TW@s$y}M]KLQ9,o S/f,mq[q7of>|MIߌnP @E0(;қ^e:.tX+Jiֳy)AZ??[3jɫ?*/?SiJ CQM^mOpЛcU ?C;vt-B;"츀c57 iZV;toEQΤ4t-b%rdE4n%̯~Ie`Y,/CRwQd!K\no;C~m[/jc彅s*QէirchЦ;y:#Oҍi;q~4g9)'=ѹ+LO!=--k٬]PH-3pi,_ha䃙\]Dݟ%nZm0qV4H2ٜY`3jbDۛۑq&7s"_zԝr7h/Z}>?k;/˜+PWjEhǸN [Pʩdo48.ޡb'S/nQÂkBqVG9'47 X|{̟NTͭ#C mWg2yV28q;QJ4&[ ̦oԍҲe&=~3U=<\r<.e 93#/˘ 2y@uvd]7H==d kpL`f dB mC4?k1Ԭ[xjݨ?K cSԢ<;;3+iu~!Fy=kbHwv!׊m%f$?ԩꟓA_: ɠVbXS&} _; 'ABm& vJOW0ouXW _YTJ0UuWx3Q.uu~f1kx Tq#ŖEт6HKi39&aR 3dh=el_wc5iw{n^E-!Ҥ*kK>_e 7% 3VmSg3Nk&͹$!)Z0$^yY[f VS.;&־ Tͅ|nLj?'wT^3x"h54 xVH}2ڇ 'Ӧg<6 vdϋ𻰄wE!Fj0kJx/䯤?>PA cNWfbe4pO,|ϿѤ$m6wp!Љs<^ kԷ)i.5):8M/6̬dITI,;/@ڢNI}Rv] uP o?;F2`=Q_3w.栫*v+zSvBV0Zr-/N*_1Մ;18dݬK) tYK$HۛjO[[d^t^ >)Aũ\`ֳR![螫~WyB{Zc''<ۤt"oj'IetOwm0ؖqU#CQ̼HJ٪9{<lBF_ix&>{o`<׳wOeO05l}ގi d~~xA;z6\2 zKzR9w74,-%Y94=)QJ?vdZ'/jz5̝r~#( E؎7_4O@fzi{ oeG^p$eQM8#8hDezjm^ouZ "*}pVr=qz!֟ :6K->4{|{xls0`h"!'wd;cV('ms45)cct_rO,;+nxd*"$QrBEWeX]L'=/O6K'JA<7`/^!}:w/O0qp`ZJ7%@q+ M'Ծ2!:S:x^9WuxP6Thh'yg:u=;xwwt9J|o@EJbsOL7qHS y,?n 4QT%seZopEʤ.~5!+tbY%n*U$dqBh)8G9@2p.?xOD9Nk>VzG_]{r/xk~=WtxtO9j:罷VVU6 mЅ%t q'׻H ZCJ':J~bd!'J*`Ň\bxs1g߷T z墫Tk1>Ě:x]|+(LUא; u|=YkEm,xYrK' C|];\RSMP .mrڕCFR& m0*MN2sM" pmkD򢹡 Bg{ ״ rJq3gjLRĚ=#\'F 4O&gz%Adžap.,a߀z9޴ii\/Q.=G^7?PFrΒx+ꗣ?X7_ X.*S6g`M29khyw2p:ēۤAyfi^~x6WY:l5!N:}d%-R^iÐaGz3!urJrs\j4x]q(U_ Mз:K Q~T ؉HFa ^nHu9xRBQjT.|,B!e_^ QW/k -OkF,V<ҌgiOٷs:p0MxCPxTżJC_ Bd F?94œzhnZ3nMUsS㶦wON)K"0;칩e`Oep|L+'nR2,* Y;U}O[*9y0X℥ 6z>ͧ5}8u&_tv[s[N|΃Rb4?!̌2_Q=%͏;"u##Rwu{aՍv !;Ŵշ4ӪM\͆Av r.ktLY-> ZgdIlu,(f)'@*a((})-X9T:x\=kkPaOXse3q(Bbo9R^pW=P) ֊3t$@OI#@˹b| yz>a?"&MSt *}9 4drM3Nb?q8iNtv` a t&a3AwR}?q YBmaN; O~%W(#{4ˏSeِX(*ȩtcŅWɽb${pڕEz;䉥ڥaaڛj̑!kʮ(u$&(4F%(כڗӊhŃu/J+^xf܂?. x(\ohpsȎ"cdnqyЙ2<雝aӾ,Cҁ<U::Sr^+ Q yfoJV@`余/6#Ek'xO0w_JVAv|Eiӟ1I\~~טaGfviN܁F#eNx+J̊,NR p3j1Y*;ubBDI#W:6BMQ{vkQM郰%>VTqSJqnٸ%ZfR~]'9> 0^уq3BQr/8-N t_ ԰oZ\ i\Ek?pGج [Wߖògcqp/Ќy~[:R.ػkV(]4T-(_RtBR 53,{@9f31j9Ha/%$Q;C@0k췾p=}9|) R;iw2X G{g\ [ɑ$EÌd'}JYƜmqg>wXXH l.U_8`8Gr,$X4Hgu? ; a Q㇨MM*$**r7D9"]u{TiNv>a?ٶx*?.|\̀Pܺ|۾.qAԜVJc */b}JJ>YI^J;:B+YQmcQhh_W8VO*fI|'+enꦛUm~G lpn4 X?m?xG @ͫ q'`QԮVaŰ!1>8:^e2ؐ`+߃ λfkrJ>h=1*v6fd1{h)u.W.FʧcKZ6flADOgxԺ ^˖bHfP-oL9IWuHulLaYm(fHt[t_ # 洭)Q$_IP ӢtC,Bx};s3*i 0iHp!*]&*gH'ٯ)9 1q˲DO1rJh P"uPm& ЅP1Gmӡ㖹\11 (4ifObE)6$LO3/`6YWF!^Kx ǁAnp3G&,4@y入JfL,;Z Q%fI mDPq3$$m+mȽIC D:&nF,V/~ $Vc~K0rK$7Q,D3: &A]Kt2" (H^ԃH^շi@q@ev?{9;޴9n%kȃ㧁־zPc0̬}{hz**9n!(D L{`H~ ,{PZ# b0~Ima@ "5dXee%:R9&tDN9zj*3Y#,n49/ls]Q@Gg&Ni>xMf)¢$eV%a hL#?r%s#X 5Kx#tSؕ} Z_*}ݺ CT_'[T<8WECgD_tD hj‰'j2uu4^,s:aWrAtR)|A^f( H?(\a|]I[%!$W˕%Uy*aduImP<.c E>ߤBD%W9\ڕq>B\y#35"BUmJ7~i›sӾ+E vg*Gw;i29(vIKVnRwk.Q0f:g- סV?I4fSΛ}gTV-$r^NWI9m%lD7H/GF;7 9#G\R y"uw ,*s62I JIO/o]ۉb"L7*]X=vWvq=! υ񆜢ӟYB@T4,[z* y Ն˅yd]W~.s窃Ë?1tRh]ȅ[֗tK:C3CwHNe,̛Y BaQf/L+gam1ҋfA$q? Ġ SQ2W7 }S|=t4p3>&noC~|N5ƿm̂ J-?⽏&KqI,e ClNNqn_bn(ZҞ 7Fl5`Eo4ĪSbitneudMH/QT5QZgld6j[FKl7*IJ-bEH&=HF$êf ]}'yDw^`&:r±yN1COytjB0@ȏfQ8ejq(v2luh cKwYjyLBߘALj.W%.D/֧e!d!34Z߾,'vjrX+oy L.̲$<d?%t?6R Ϩ`R0Ul*%}EUTͮK(1Wpno5G Şp  ^eT&mٝ _AuTnʭ]C"P!1`!+ԋ^];ddPb L0I?Zk@T)V²J=ܝV|qz}i4ZvN2 q$ 4oþaFC[A':|yv-sm$N^49p:CԬ˿OJb;p"YS/3D9# O!p"]ktXRj<)õabWoo*d-o8vΜpł[8OCݢI-CMmߞ;хd*Ō#5M[g#a,E΅W,a 5k3T*4@[fpZ5iK0=#'6qϮ:oGQ `;yM3[n9 "0 C^0aF=sb ^t{9-.IKܖӤ(5"S00KhcHƲI.\Yr:4Q⨼V2O25]U0pNX}x7#Ұx\n4uBgt)3|59&y̐^6PICZ$|N?S1|ƹVEG#oa:4.G& Zt>׸?C(mgO!Z!lRq1^9[7caKc>ט#Rt7Km&q|Vl5y_ \wR26둇,\2^X褓3 4 [[68_16/-U0yzĨZ=7uAZcSCbk+/c-yÓ6 WBhY\cO =|L35l^F9SepߊU2p6UY~zQ:nO;Vza о۩}]7}d[k38S׆>a}V\|+ Aw#muLsո{PD-/yCj߼$e?gԣbQMj`@ &jҡ$bDž}PptTWUT~7BiL~Gf"*xT=]>nA8\eyC(D&Ңq}ћzߤvr1>I7\Vk>:P8D?(?Jv@'~:AÖ+a92Tŵ@z3XlFkυ0$0jOCؘGɅUJ*t$ _0⥟8.ADoc[Ҥ?!XTD,@ Qcͨ#L;VOz*wl—9c`NEZe2*[CXkemxLK@h&cJEһqC^;Ju j,bc<<*HMڟ7.2J|TgUJd(a Uҙ,oX*-z>|M m֮P,Yy@Mx썂kE.߄I=r|fzEo ?܇{PaOlj=J̩{PrfϚ_OgTmc B>D"LMFW[-up^`I誱Iqx&%wBDej@!XovR4Y KfcF%J$#۸txߥ noaA!ဂRTͯu/5\3fTۆsN=!!d> SƚbʳykO :M\z,Y { iCw"Jw)9 ޗ`~\Jm `-mRpTwUb)jBO:f/!w=keMNIYia,V(l +3[%[4 7XRoTBA!GE8Lom'9u[(}ݶCCU?q-9-G52j8/+nG&T?S9#ԈoBGAy1rK>P3v3W>Cqݵ!Kh_ԵkѸBV_3[ _gCTL8 27^%:P|;F~Єs&N !{!9 @8Qr3h|BtXҩۑB_܉VV' ed) t=e \A(啅_5ŚWYwdu)F3k/h< SCY#=wMћOPn@4d-ɬe" 2 X+C,{8 T'C ;3lqLП = PѴe,: D!|πC22|6hL:6!r=CEiMl{ߞ̕#L*CF2<3$OIW-Vϻ֢dʣզ  Ŝ>2ʎ-Uy%TvtO!f09seگ4V4}56 *(u-|emm(qcX)R#!]Js5nwcS/ytѳpH j{>nr/n Bp35N[o޴ ٤Nӡ-GyU V1>9nbLv5ݢY$Ľ;]|>^M |bgLİET.K9EXnUDԫt+ַȑОg\ɮW2OhT))AN!^)) >-܆L!Mdh7)?SxfM"Mwbn3ۏrfpCP7?m쿥ʇ  j&T]>P7{E|]U,Ëbt?s߲ -[f)mRى߉q]Mf&IKϞ]5+hLMUTО-B?\EW:5~I<\QO{!ۥQ1F6K ⿙ QlM@X?Ze}yOufUE2*spVdhܥf3BQ)Sӆ:5B1"!&xF2?ŸW/:-<-ڜ x_5X ߨ X%$rR^6Ld΁"%h[ZJ(߉e-)\WdvJ%uv_v BTI % &.J1\&T]]vf~C*9?HԵ wЖLūNe(%P8(5" Q![F>okfVlr*e"AWř ,t0K]6.kP\_aU^("U BQw;×r}tqb+(QpkJwSzt"{\}pz *JlJ,qAr'ITDpq|B}Ǡ I2|~ ?nenȬjB?h[ O7a֬G?EjL?8n []]Z˓p/V{K;9 AP+5=ƉA,ya WoQkEcVKAJ >6)[{OuDA/gA ytj*u}WE8kFv=eG?9ЦvJOVqiLc =W<q ^y%6'&+paYқd +JXNF9 3vW.{$(=A]ǣ7nA@AlG.]qAѻ9~GnAJlСHhC6+u'۸YlǻtQ~JGX`JňlEk%7XNb+mi?hkz`=ZRY#8r[6dO{n/vґSZn"^Qą夐55*+7VYE6Y u,).; ު7[uȃ֗tB3ϵѨ.pSӋ7go+fu'`2iW 5,tlGFQ,nAvd1 7žY'#2ŀlX"69l͞;kU-Im툎3-toc 5%*itT:ՍEJ+0zTkV8bAY7C٧"ah^7wFm0rIX V;ҥ˧)[arڍ2\Z!"PRCU]G\B(9V>e%YѷA/K *'X@JԾkva$9B"5XgS]AYVՁqi;'2[5ft.>.5܆Kln;S/ 30?S[,'?P ?CJ :0Wc9 B-Gzc<2\?HE*ʢr0kaw'7L*K(҇/B#}1Y۬ 3Ķ}Wl'ϳ`)t0x3*LJHۈlrr)lI7dm gMh#)O#5C@Oqv>BYld"-5]]![QGt4/=PA:wHWeMzkWrQsn whnahﱸh1E AZ`5+^Ak|PlSI[nO@ v,ʔWGNNU^}ؑԀg-RSY53HB9GDlR勂xf!UkEQ=qӘOi۶V wH#UpTƗ֡W2qOעy%Ovyb:- a|̖m%8AV{%^k2fD~=f+KS޾籵dZL3ȫxMao57ڊh*%.~sZPJCJdhA~-+Rr:1ypKOInVd~*g 8H\I6'vD a^>U'tِ>I2(XO>OvE; iHnQ,X)pb8"z$ADd,7/d _P{et.fD7;x1¡c>>g0˩Øҿ "q9FJpj޹%&xbZgn7ZV\0OnU-A%Z %ƹ @~욟 ͯߏd)γ:E3JhgYě #/fE1VN(H4<,Xg$x/x-\R>?C+ %@*jgyeBL#OJ|oIoei#7}vYpB;/V\HϣWdv$HInwɓuNuh6],?Vt6$kDMژʁ.w r?!WyVdm+z'S{cn(e-Y:fԬf8+ j&oKr *5lԿ-:tK1@ {A/e6$D4'~' bu (&ˑ}RH NקmJm+Qf7X*{3W6>_ciñPAN睹@9_9)qRA7 ,PhB6wPƢӌRMp UO[14j)hK3f:ƜTR"FD8>6f_?O^eSߖV'Ҫ7?X.?3s1Us'EpNց2/&L\7汈Jp;m|[3Q޼B2NGI lŠ%&ҮMZt~~Of*|Qr<{چ[eC&]bU'I<WUV\<]#lc#l߮%Z%GX'm%*Ne-04䫷EF/cֆҙ:eU4d TWū i!rqȍ Ly[M63n+AI5{*O_wɷ8NRrq^OC41n^eP\(^ɱokNe(7hsk {4IFtIo:n磌"§%yҜfk]݂Sɻ_)V4^xfrCVPƾ!Kfö_GχH-qoe:J`t#ʑ͐;+ Gz\Fb 0S,-ٍfLEbQ$( }X n%:B6|Ԕwr9â|f3J FпuA0|_ !M?EΒѷ207Wէ\{0ߓd3#!'G&Jr1JK"]jGz]}J=ܻc`#ڊ1~<"Ra;%Mj5DHc3S"ܨPXm|ٻ{}ω/]@m.&2$ęͨ%9U6X_Qxi}x泎/9^Q7*뭦\Ɂ0V+䓥 }*ϱBupEP 0>fs5@y[**Oʚ;QOXvPV=  &IѬt-TyQ8YJ5-گVd[`ppd:CS(|=6_;&f,xo;~ .뤾zs_7?Rf`.:l52#.bcGnj;6 >%nX @Bx$R6ؽ^SĔzq:ՆU1OlNB"   N|qRv߰'k2{#x=76ܷT hO.bf34SmEZ|^$i26|eyӧ5=vdܯ5Y+ި>N8(>Eܡ׊_+2Iՙl1Ŕ;$)St[wsۗt`7#='vr6 Z>+8|'K'-\UN<1|hb=|6&rڕ?4i. ~ |7/npDOsS~k2OPF4+9-ӏ&?41X:r⦺gѧMa'#:Dpxz~D*kx4J5N;[K= C/ &Z W}ϸVu'8(aE:ݑRga(-v쮔&q2ztWC=2a>a&4حP'w|ux/ΟU8%&rh$gI0?wBA\Rps ޼a]ZNSKAOJ-Vo+K0mp mI}6E7w\i7&jgc25wɈ@l2HɿBTDߐSSbrԢZhz&%q6g1R60ϥz@ֈ3B{_l%;J1XrҁZAW-E+𝧕 n>rI+XsM1?2L}'S nOaZxg6žG0 Byg5в)iфګt!-ui @\c]EҝM^KJ]4?=/KJMf-$l.k"k47(^0.f(k9)*ۘןѢBEȻ67Gκ|&npiU_${F4| W2(T1ǯűyۡ#Me{얧o& ­׋E УMN)F@V߮VN$F?~B'sd 8PhEʈH&y}3FπS@Rkk ހ2 2{&Tf̼[,\!q AlKӱ?%iWH^n Fٸ 0 l Y_FT'ʮ_9f4SSi;Dl{CW^)etm;3䵺y%;Ԙ!pxۺ}Lm^j9]N41wZp-Ut|j4M67j*gR`EwB![,#cs(;5"r-0ڂK jlyqE`E;uYSMG^c$OfOOJ&iOxC4 UA{5 s0 no¤ [ϓ.1H׆NUUlES+S\Qu U[aV47,ķC\,t[o! $j {đr!z6hveƬLܔ]o>Ϻ`?>C*6@XZ L?gB~nD_^qNw|/{(t7paYnz;Vڡ HίGKױHƫr5ӓwyM0YLȯT[rf1|g]iz-,Pjqdi}F0@8h'5Yb[xFoY }r1`5s.8: T^v9_7 9q۽`YkAcͨ 8T|pKIo~q FgnKzl0/-0N&\*hlqaSfjL{Mڥ'CYOaŴC=1 [UGB0 wujyɾm1_#bcLQ"PMi<y&. $C-Dl{YN!GBpDB%H2vC,`Q,y)n%HwWqlyh υݔ P6A]&D^/ƷpOc;ĺש+]ɈM9;wx fVBPD4cBeލKvTvex,;W> 3-A{rN:-2 _-_M?envҼOeS]jEej ѻSDd?p1gqj;*kNa$q$w*жCNJM5v-IGIcè1ז7Շl⣇{<0xhq9wt}qV7gA>;?BpkEz߹In0 j=flsOl¦]7yJ zXej|%Cb.ITk: -cK8͛(rP@g9O=lx4xT^s>j/炡ꛑA-~rꃉ@^Tb/PG,ݞ1~r [Q.%q8 Ungp=4kMֹ_ b2j.( ʮo+i=3&ʄT1sY!F8m>B ݇gUcq/ fAHY^k/hT}uT!{O}Z嬇x$wxMlj#cu"W) q$r4 D6B-)虥P‚C%@67M[`Em9*:lRPj=g\e{WR4{blF@a\%|ʉ|VM.tR[>gUG TÙ*"ET!--|l4Jx:Lt xg%v{>" S2yaVTLu@ZXUQRx A-^1^BWs|#T2IW*fS&b7N!!V3ʳ9x@(x7o*7ŽaRW䟬ƝS3s,JHyU^VY1^^閦ْ=ZP66%^8R۲/R$OS*C"E 4$k4?輳5@~ZYo?V%mn, $4E-n& (Wm#j/Rh{ʹ?$pFm0SB >+i-kbt:4+zibge8 Cuut2Q$E\#GiG)'+CaV{ĉߝ3JaJYU|&0TirײaM"v"XG,F|pݚ)C{׈>EB^6ģevƝU!-Pչklzϣ WIIIJeܒd5qd8[-鷧}+ ^xQ-ղPņ* @ԅH"Ѻ)E,U ;f*g^';,no ]l"ZzZ׶*(fC';\{5Vn#NB)!jnoPĂ;؆E}[OF]|qj3ZhX Z|Ԗ9REz W; 4CI߇jPRD9yjʉ4' 5I񮿉F{ˤQywb,>#[u%y3D> 8Gxr<7$r*5ˣ#s_G"uу9|ȬEІ!?ٓ`=Zt5;)U=z wt%I^<:BUMу/:΃ \v܇fd_?=zy r[z1D^F Sdzeֈxvv4[JG l$oUw ץjsUFuuEU,]e)q ͬs$ʼnb亣R0w6[<֒tn}ҒXg~4җ~"ﲶvu e[.(V.ir n ڱ܎B=XDVNyd|n$~utz ٢c1֚fPf9ݦPݾ{YuGw{T\5 6+w(5H" |*Zz#0"_)>6SN nŀ<64/J;=>;(㱦glֺ'\_6vԨh9>,[B 2q_Yy~TOݶ"(T,vDBb\\cS@+ÄII>~<5>=3~_-kvU@7Kv _I֋<|}m=9rr<<`@tTa/3'=F?ցdBjH`[QY$}<7EhP ҰE}[}@׈xtg2UҦ=4@5V/&@M6ypS8;,%q}ąf8J2Hg#Ab˜S x?oZ1v0U%!k >F1Go Q*jQDs`-ɪ_SDѬ*~[pbC o'nFn&$=6VrN9$Pǯi*8yOO.GdWbǞ^kS@57@T{;?bXݽ0F jXj23]y$J+^k[eӻ͵Ҡ[[&zjtqg6uB&`Cub1vڏ$ZYzp=|_3CPX- *hwccv"4D}P&oruE:w9{X1c̙KB%ge T:]`CMcz;@AɄNšSlpف .\#fWarBr+;;߾mحvW&g@ `葘B=V:t;(0ްb{gTJhTrt)j({ZIn6^q!|3ySi]k%nč^oҞ[.p<[tṴoFezVFt"\5ELy7!&]vé1Gf5Ҩ.6\u $7bVeg/3PXvy.|cs]s ZB+dAQ@'dK9?O,I/}"fC@o'BW|_3z{ǕyFP?b0zGoh/4cL;Ũg U,ͅCX%S JdI_$?mb_X#ڹY4={`>1q>hW'׶p)[pŻf3IE<ѣV6[~33ǁ^; ?Y-DvלfޜC=ąppjr)L̢{A l꺢a_ۗ˼M \%/mǛhȀSG_l6@w`Z d7_SGvUDZ-5_*OXIu4,Ge%N[&jşҷoaI49j1 kaAlP!Sή%7BluXG邩Pէ1?,D80{n0k[;q8Z#}t c{̛@K!";@qlkugK251&C;@a$AUvy4Ensz@;Ut/ lI5QwvXa'`9o } `G ](fE~a; 2镇` JeNՕzݐ~xm 80kXx) pI گ_E_|RSD^܁ܥ>|4˞V,u75TN,ǯYV:+EA*}j n rG?H:N[-z^ (5=940QcԔo`ob91-NJah! MuI\r=\eLM,~VXsv0zU e З۲xw((rU Wj1nuT]Ohz~Z-+cCrĆmڨQr'tcqTp,6ZrvKo׋0<oy*0$ NN_q Ӝis+M = ]"Rʸ/& uGН*nݗbv֕!xl㋞x9+vIdHǹ>v i6`,裘 p`KГÄO$ e2~4ׄ-^sMg 9r^^䁸) E}Za? 4k*bng$}? -~Eز3|:]X23YV krxpVSH8%nH' frʩBL$rAT0VBQђE0%Γ{g:yqڹo7бv UJ<ҡ'g$qѺmvKHSC6A66!LrTol3I(i47>b !t3CXrgoA1qN3[d0}3a`# ĝ'ՈjQ vdǦZVTd ?X)4W C4o nHoTGJճrA?^Xh~&[uL!qƩlb|"}]} r)6+PLt$)oQT_;XmvIWQ+/0 ky O R+!TXɩ4 43g5#Y/Ŧ=3`,A;!W@$Yƫ ]#_>3 tZ"+Q,kI88MLB='gmSc-`˄@Sօ;"e&{*$șgU ?VvkB<Y {xwʊdorm.*_mpJdb!ͯL#Ϡ R5{/ H,EW E&?*.ٙ>>%[ F^l$2gTa^663g 9yk?_79!TCd~17V6r&]ϖi(- w0ȳK_5Q m).;!#} 7T)Q[rbCc# _\=S=p6^Y_*g ~xP u1n(W6J\9V@[:\3: T z7M D< h,3w4%ie߹ƗnKgk LZ~P곂D.gx[H!Kvsy;/DvK|$.?q'NrTD0Ią1T[g(o+l 8L(^fT;&|Ӧ\6FVgU -K5(镠-I!- ʰFh /gx^:wlRKg͉MU<[4(])HVr)#є2_1|Q) ptvTOhXO:J' w}Vn5awiD_hMm&UQ([oʬ}GR.ou)` %'S?jK Be8F)zYX6d.H'2c[T- ?@~@`GjVN 98mWFxL W3(% ָMS8EXp:Hu9KFv@A5p\ŕpOFltXڎ7LqmFLt7 iB40E+34;clW[ 0|(!p8Y/ phLdYzyhzX5(w+9˜w'BN{I-f@!Bi%[w2XqSt弋zZs!!ZN;ԃݿP &)4Otc]b$6{?,=)b ]O=>!0K3["bV$_YNk27:MM$dF(⏾ xӤ$J7Iw-$uQuvV~Nv9Ay 'GtjN%p='bU6z'I[ie/j흨? *V 5O $C0j{8j:D]A}^ bbtV׸cJzi:3FOɰb};mI(@)c F:ɴQ6u>p0)R@X BdQsiRSvλqss.j0Ō/%{"_jF7`KI]%,0bb']CS[p^*L`bI{Kᕐ"0Ǭ/**]o60jM$M7aqߙ6܈_>62PY쩛Ӈ2!81U×Eܧ ܠ}GuGw4-QՎNWWBTcr/pR; mߐ[&Nkپ!Cφݰ9 uڈ0tvkW~|f3RÌ i S+RmVh3Q&Fܺp1Qcgѻk7lݸP5è&,!TQƻ]A1K7Ɖ:: {?1b8A`9Cm 1]rKRqA,b(Xd> nmވh0h$4i9 )e=(XG3WāE]߀$%ڿx#N{=au pAG $Rݳ r>RR% Att 93f-&ǪR/ao^]1 mю--~W"amj/ʀd2.us1`&(,+մ1Sɒ_~r%V^?/GAe."'TA `DF T#9fIK3~}Rѱ|B33|/wZX/ f"jZXG5Z6߰ٙ;6J'4ka5@bvB2JQz~'q o_) {]\u8}qa Ɣux[LGx8O|wV'MajSq)OdPP P=|q-o@d9KW+8 y`#zޝsnh)cL D$[sG5kl%j1h^_rl✮q99>oJ3ugDよP' ~؞ `TS7ǗMZt4œ3(euL ?w| 4j;U$A缓x{1EK% ]a„JR|an H8-)qJNձΟbDu ]矜OlQvA43R] Q~>=+Fl iTYfc'cp'gf,{^hL#FY F}.S -Nߌj[YH:7ZNJDf0Ly?},NN.0s-Sb RvWBuCD|Ix!M+ӜL~|4bkon# T) >|&(yḵX Ӱ2Y܁H(ks0ftm[cqGN0lZOͧFߊ]%` >r=#ⱾkދzI(Űn7:n4;CT>syjR x (Ѡ]X"+^tq$CRo4 0`ئo?NjU(몀 6([4vupbo%9H{L`Q1lqJԔM+9q EqTV@7=Tibr:{i5Z]#>P.@œ _ xtI?y>55hȢ[7(,;whT΃.(TE%4t-e%bb ~#L)u02bݓS%{b65 <, v@nUpDn[&hS=T-K&g#m|t{"=0Xj/Yd2JzmԈݟeZ3(pFj%pĮ >Hh|#fU.Xn{lV|bᎽm5闣c ).!Bl1^y){Z K{Q;MTm%`.2r`5HùEտ;NOIG~,8Z5XT(Ԡݡ7'6R1MQNnl+{pO.QS @ ("['!c$gԩ١ Qsxk:dT c)G}…&oi=Mrچ&_pknY5g>YR%pѬVeH WuRsOi7|-`5V*-͂Քʉ6AH8u3x܀{`~=c=7ZÜt zҨ XH7G^:X j O쒻C@ da5g7ͦ3l"$x ғ؄Fz}2b[]G7\*3oΤ+`uVt]|U @7MUZU'+'#ȆTil2ۇj̟ Eϼႍ’ӭ<3r"ɂ/.-eϕlyth:l5S^[IO 2PZة'?f>)\xeGW|u)1zV =c1dO,? nϿT56TJ_66zzPȓzGkd+I[H[o܊X[*!9^kSBg&юU>g^Ķ|lPV5 XP~yT(.~gZxD=fTbϙk#5-ӟL-|ܷ `;+~U%<.R]Qf,^3Sv$ݜ~[mN@c;_2iV4 o2 -oQSTrV1/ZњXTGAn՝c椕y}؛EH kLܴkL¬=R|_cQ؝M3N-E%o2QO&h)v`{P$ y" EkGs=ǝN=/|_B3lVzT2*YCDM_)|&\R8!0qZlLgCa^{ 2dw>Wcn FMY@^ vGá( &Pba*!kSXցKQ$_6AxB,7<䡵HxߎzeFNh ~DPS]h'b9w}95[ 3nA荍pY>H_mL+җYMFhk&D ,"PR2Euޥ 5s8ΔJ!;u. /Oٳz-qJ\ jE( (#-GPdzlXsS|;"' U##EzyA)G 5S<~Ɍ)4CТ"& [ƹxg0u8@7D҄J | O,@eF'ҺǢY֟fgLsw +If4C +KOy x t,a8͏t5I(U7t`ƕ&WTIP <a4/*δ%q/GAe@6L^`\OL<v+{׉3XʒE[ģ͘c5x{}KXKdޤ(ݵhq&;O="_J[  zKBA  8Cܨ,(7 ڦ`Ey5־E.avs0<q'q(BDLo-K+)\]xr]Ůt޻Xix{cH YR D\x&5>ѢYI+pM%Z]E>{So r:qXI9kK#TK~M@ c ܚ;:z@|Wu1[NsO,#I|ʹy@Hk-a?fO"x 17:FE4f_YEJ_p8I4zq]L12)5(Bn20V"ۛ9 g!tŷeP;&*Or.,Le TGC?Ù:>g 1D5?HAE"dc:3M9xh;"vzCRU2r2[/h4nj/w[9| 7k0& =L4M,f+GAnsX膾rv 7/9YȒ)T͢ԓ߿ÅH_-rrx>npWPz UpMTB!/eX0nl׿nPڊqZ KnE$1hCz؝$c0h2œޕ3OWL&|a&4% ?3?4o}[a0,ƩWS :JPM0q77n2p3b jd`.TA}8k!#3kxBQ3Mmֽfl9R^^Y6T%P& =jx:ײ1inRysTGu"[D*ul4ٝ>9gv\l^R[rSL+@˫nz/x裗o*k\AWƋӥ볉P~RͻZPBV- Һ+CJ]{;儣,<ȕ#:ԐFYuZvOmk.vfh6WXśe XY kjv4_߉NF-)==;Ph]km>Ѭ0m:L";N. eȊk`EVP7B/<0줞1 -U//lc<."A/t į>QP F=& /)z^ pUWF 35Nu >ϚQlg{j dF'P(LpY> ?ohZAKv_Z\Φ0 XL=^`WDV{ɛ:"&c88'$(į P(׳pֳ^GZ ,]{[?풰Cx~!CENW(7/[wBH>ʑ`S| +otp@ъ4?vrLwV1H如IN7gvO{Yoԭ^ZB{>ѣPׂ-RU5dqnﱦ5:ԱTTj-[jO!T<&b^ ƌ aళ@#hD Fkk24[gn/zÃ0?@@i7 upBX .BELG7LARB, RKs ]|Qm"d`PU I˘Lc]怳寬?$~ru).{Q;+"|fԍqC n& jaohv_ӕdRJ:0NSDHod߸8,}8Z^,2-Wc?.n"'n4C2jއ<_Ҥt-L} r47$9#B0UlD/3,68a l9ۜM%m o{"`CfPrsXT>(~2vmN?ɽ_V"1EVD)~' 4"/io®PFMdJgX1E=ʵ0:8GŤmXMO+UFm ^)Pb˜m29bz+m%9I4h)A!XLHmܰ,Q{b @өV6 JfUϑ*='?&xYM56S ݦ[M;Yͦ6컾gS}΢dU$+#W{e9# xQ۲Zdad=zfjZps*̼BLvmL 4`THxz; 6 =]FڎJ>>0udy%|eQΑkfE18l1c#9O!ĂE7y*QTlG:f#YEݶÆ|PBHB_`RYO-c4J*積FDޡg$KQӾ{c*p; *h:eRt5H&bvo3_CSgCs L.sED(!#v0{鴯}, D5kM]Q ÉGIņnH~yʍKRwU_{ь@&0A'241dp}O^unR*~{fFSŕ (k(-Yf*MprʵHUepdf-&6Z)L0cm7:0n] oݒ"* v*Enl;KAzHV!蠸М*q+|Rͼ"{5!aj88S6~ As{u:O/Oh@G [L#l0 HĒs>Æ'0Ìr9H>$Fo!ǡOynbf)g-Lua?(mCܞ~E ˸Ʒ|m. ݦj0QI1E:175YeqoB@id!aj/'[/r\;\ H\mƙg}U ޹߅(!u׋K: {d= Nʛ$*y 5Z`o\1Dvq Z-Y͆m9wI+%ɀ~j[Fz3M(ְfv9lب=3"ЛKK`B7<|GP]@=M{ (Hmq![埧ΖowϣVxo۪LLFsJܸ;d8Qo "tjUTuBj6HF {uBPW& =ͅ; 4Ck 2ۀm%U8tS9}ພXH^`Jl-ZR[v͹tgvzmI={<[g}+2dV9^?9I@D?jw$ 蕨ݫ9?iK\]{ r;_p%9VaGOC v]' ǴFnCKYRf Ɋm\.4ZHHr2QD}'Fo&>o&~E.nnmQR.o;}o]}XcKvtb#g!3=cvՎP*r}4'~B|kJc. UMc|;TG}5L1q< E~PY!ŜR95֛a99@vb46܊3Vi`ׁV z m;07.1_bS* nֲT#Hf駐duub%FUfe"}V&I囸E|M `D(b JY 7OA4:[M_f5"l9I܉+Dx:y|$"Z՟ul?89Smkx); 瞦$?:sP M+"`fꤍI>?]xIwH0h/MI<6H)x6Mt>k ЗQ!Cz Z0p@YQè?PZN%cE5CAj4YWYQ kϫӞFf un0ɓQrC뿽#Eՠ³!%#n[y:>je[y3 6{GA!qoa|t CsQJ]ӳE3W:SULn[/д?<" $r=l#jaX*9x'|mYkyI7x端>[rnVV<@$LEα]%ȯD!6 Ͳ灹4me"c ' /IB4NW湋BDgRܱԋ0,9V&rjN"zn3R䲹^;~%݌3H=;`X1{J`!qd1$XŅݫ'q#x3 ++G7ok4y&x)vq{BTDro懗Rj,LLvrӘ #ׁ%NUSbFm{in!FѴ~;i5OʋnyX 6riG )VWk82]6j{^UI豨f4M ÌOt$@ |[ |7ґulog b@tGVt$Bc](J)/w$m9)v/J%loӷ# Q2y:-ir-=Hem q?ՕLTB] czƓKM^|l}l`u[zBGׂf1Ç'< }"MNWW׆~XiyQD6+.Qݡ@uIȈ.I DL:~r,M."ب0ٷ5qIBQ3TWy;̓48U^O3=i.3 [=rPhptFoJ*:v%cHlV&;B %i&o.0̪`hCHi2b9jw[]B5qnq%,6zk {GwG}&Ed6_ :8B06+@539͎XXZ6I b h&>+Oﴱ#ᧄ]YM~ɖt-WV=9dY&Ιv3ʼHMW/Ѳsx@ An>shY׌~,w ݡGdԸ/L㵴kKpS̫޻Dldm3-iaMϪu 9"^VMC;-K֔L2go(^f=-as '.A9򉵤3w:y1,`PX5$g`FfM<ZY_fpBcՌ.[`Kqwü= /βHLa" S኶l._x'3BNK峴P~J5~Kٯ oO(rVKR+J`>COa[T%,ɽ; % Q5wßlREcy{\|O=ɞZQД E KoБjy*X@;[i%4-};.Y"M 0/⿗2l}-V9RMp|ky|jYmEw,QC5 M0'X$8nHڋNޚP'S2=VC^Mθ*.niSǭɉ+r,A"jc L3BI[mtWf#]<M p^X[$g9S1@Subi4&#9|+=ۭ4`4Hg Y)%opתo4-7[B%"^`P;omw>uz׬p6]E!IWWh775NL4Q pkpdՒv*6-H=7HGpVdKyh㉲O6UQ Z/X`X)~b73 +b<zr"D2of`&+&כCq 0@XƖز[) ׍fHpc՗2=뀴C6oBS_vl{?U:ƞ(όtO,(UE"X0'W_OJ![r#+j#xZĝoɁeP@VR~d"/u/D{"\ƳS+T2"h(W/kI6K7!9vOXjV"'8%xAPXf|t"07ȅ( gӝ΄*KGW.$//ń:"i Hz*a+Ţ^ .(thr>IoĂTd#Е3@o¿AO>pt&BE9$l5&xkKb.~/C!wHJyuIܽwS{D;6U42ro0Xצ۫AR!FEHbHl^ ܓ+Xe,u5y+IV'AĎ+κ$)1C\+lζTnsnL;I9®Ť[-0'GwֻaZ?ؤX t-Ҽ;u$LR+-[C!T!k[YU`/1[mѢZ'\3P =4ub nVjݿII裤QA^U@qEvbX;%SD:IEӌ F]O6by@2/;2 ,#H(o:Rl,07 2h yre;3t.t,JQ" $Ӕu.՚4AbjG]]!0;.Q+ngOpV,a vl:z^p.ay;+pWϟS$ːR^` yq_* >髓,@Gcx%p--*UmQ5DӤw11Gt^A%Մ ͲV%mn )ig9r5jQ24,:â z_UUA>JIb0Son$LʢΙ"ݮ0ط̺|]~8m#P^8@c.5o Wu'ce1%HU^}t9թN s 9 je QQȦ@P]|8 Wk~!2oH(z2]4-^ hm&+nJƪ~mCx wcXdא% $'zL|"Ђ@3 0l?[;$uCucrۺ↎3MH;n/E|I'&!e#"yaI1J]dBTVl`zǐ'9f8\ D FE~S=ݟۦ`2ImL¬Kעum8X _1e6#X.HH[j).IEUbLOz"zn?3r;(bjh=.FαU+tgT:7@7dhSAyZZ),aHwb|]RI8+2062V1o6__F\>=/ a;:̜/徫'u( i5OEh ̼;_/AljqLSDfOſw'+Jsj"M'0EwIP9 Vk;vE:>F)P_Sh]" zrcZx"=YÒ2kbס"]B@`qs :&!LODj)+Mz>.l)@5mS%_i4$SFiť8-q9ز/6ڧ ϳvNJīnC E<(<4{pKzֱ`lWHx͇Ң98&BjbO^cb᪃^Q4ФaO-Tޝ*!]&ta1GlUڶA=#4 3WHt%L=@αEjֲe[6^12%lC^Th;FW0sfT zymX ('}%ExR$Pg"gdzWds&Q.Io<}>)GtAM? CJ1 ـ Dd|剒~!Ջ?C';oq"0NVN:P/(#ʯƄQn *;XyaQ_Y*ŵ隲R~ڰ]?ēH3m}M'B36\sx1&)܍AжNhd-y3`jr#ֲZ|<2\ѯ|LAR+W+y-J)Q_lFˤUcʢ9(Y#qkz`cP~mQ?IQ7hh@fo%@;N/[N:&`++W_zH0G3|%7H$C{TWy݇S;%ԝi4܏pZ? EN3+єDbʐ}EtViSlSu'*7CeZ[)kP }3C0JTV\ɩ߳9d%KU"@n|~f]1 $CoMO7I oo͐o?o!Iy @T&STe8WxC*Rt:8{f'|\p+sut%jG.Xę|=^QZ`04)(E+yȊ'<5tI1Rk uS!QĜ ϙekB5FEW'l4:X W*(Ϯ}|'򃾈CaPRiV m .(em4ycmf;%Ō?nƟG7]-ffzC|.a. lhUGxGUuMEXU'r {#mB;U uu__aqjO &V Kԍ?z@vzm9JK$ťe%"QZF6cfט [gg輶i+~ ZzR't6`CsQP5Ҁsr52zCWW8>tTpMw[ MZ@S?,N؂نBC`<8a2ojC Ն䎗5IW?Ɗ& gqX̰Qo9N/Ġ67nnG}0'f6xgSϕu/D ?(g:+w]{,h3Igb},{Pf)B. $~.$(z[u9t{~uA]3G=}~6ڮr=i#/ZM#`:ֻ$45Z`V)GgX ׵uYڴ #Mpkeoi<  7+ FCC"Bh>&U^)$WS ÔtsEӳ ?]L=si5xj4Pg??lQ<,EJv::Q[D{m7,;ͪ uaCyZ3KM~* kCvkK \G%ܩvA݉9SN_J꾠rU{Y@IAoBZIw5"&\7=YD͍ Yu)Da"đ͖UlMWdp%o#"zV'd HJP#}};xfn>BͿhMط-,KtG& DʫUwc+%F<$ay8I ~z?#~{<2+k 2}rx"F \ pjtJ~nsG91s6KEA/༨7CI؛Qo7|ݴn+Tz*m!OL[V}ݶ璦>:6"9g 5X`R`IA9YH$P1 )ܰ|ұuޢ-vDwȵl|Q>{2-]x/NVez[3 *<'\QtHCdozmH L\c4ȱ2gRA1m7M$x<DxuIm]mamg9t˦ C4Զ8=F |oJaWBVѮ$ CgÔMKukLw7;$,@3V3r"iB5ZM*byи$+)Μ $<,u;ľm &Sk'eҰ"W{j8ƖΕO1!6k e*mOLkRR]\Q'ӆa_< :~1Fto]h` G]4"l۩ 7nftVUU^0 uңM0gS”4)mk2Gٮ•Af$'s$I!U/SG nO7ï xn_鸩XХځ)#(tu͚QVm$\]02 B`xRzRLFJ,Vz7^#K%]6 dbE\h`A7%b 68V[k]ǵA2<ə <[4T})gsE˜H ǰ>#CxSh`x<=.2X#>rbg^~{4gL1M^`g/$!3ix:nz{& `qEb&.6v5&RGTwDg<)fˌF4o+"P]pk߸g<µ8VuĤW} KM5S/2-0t(xHmnMww6d@th)N{8ssÃ$(V!Ud5dxz؋4w$F!]t{&5VלU<7Iwo;zj[t%wЄ;(U+y< r}/W9-.ISq*(|iNrgqZD VYFdesxGkn ˑrL\p)+0yU2NcuS*:(Sf1].~(oFԝ%H;vImyɊ**fRkpx*_R-ܐ퇾rI;=]3Hc{dKo|O>;lM=A:/x)4;YLMXO4=no%,T@Y [={3[d3p$HgetjO.#-G5Q'=y_܀e& tW=b/9y "Xtž%G' ظ3ɛqE'8FI~~woTCӎac7qO4u` ; y3h eu[ bJ5=oz8$oO Ae @NA5Zkruf(g !ͷg2"A `:f.Dqp'; EDnɐ?XkqCD)CYH@52^jQCwfV?NחrV#UCȨեx% gT?Kj4EVPs6@0umVٿcZzc78Jv tͮCy9q/Sk)ǏQ3ꫝe\վ%#7|l8n(D--|ټ[M\\ `V~Rmh):uԿ=FDynE֒lk/~ʪpR]Aqo^?B#,d:wC~R.BXkκ3nXւI"0DHj'C9&O8y͒^"~D;ۢt3gHԭlHJo&[^ ­9yuC17",: dnl7Or0۱{˓cHt,F>1K`Bg6.؉R|z-RجrqFIp73|hΧ(TN>I\RycPh ަk~W,E3UamvC8e$&+rBg!xuJ*+❙S'Jc-eTeO@mڈ#K(Y*#jb[F8kܘNOMlp~î`i+ex_Wd7htG4oc`X8[O'~~UIhz+3ZzS iop0k@~Es}ʆF,a1v͵#@_n-FVEi[<+{PB )߰<2ԮVWECStM%]ӛw,l q-Z: FP U2=PPNNH]Cx~IWYI'T /HT*D7:vgUSb|C">@߹vc»8-9Y6RU| R8j0,T˨$AOFjvȉJOǾ,֔o%SM*2܃j%"[_ĢpSd@]V(Ѩ`X 5SB<*~YM_o!Vv첺l!bs*]?3u+ `kv`G8`WJˉ-֪L;Ov`(j[de$nJ3?fc{kvAH+('oRldugl>)'2Aa?8 gBd {&!uu:=bP%Q_fddJp! (G;Fib#w/ن/oQH+ CNp]5~źMHc-aeb+Tw"xy6HQ QشRD6zu57('3ו2V~p]&Q+w Ze'1g衄uN~v a{u`Jdg4Q*([vZCZ__JԺeU'0U귍˼};NaH~p,(B8C $FdtƇC<9 Œ ƣze=ka_ UX$ m?GD;mWq*y7?1z~G]=XhpQ䃗Yx~Fxef=^snm̞Ѫ-rZ4T4-Ҁ'أeCUc_-@kƓ{2OShXSZ(P$X%՜G QVG7bzߡ(x32UѬw3NLXYS/Y97.cL]LCfE\F>M<.ܲ|ɛ& sg-Ezhکi׬8Lb1{VwOGSӚ3pzذJe6Gily>x `V3{E9%uMz Lj/imD>4pR~Q6_4ˑPWBc|fK7+EM gxz/-'u$]|d 9N*Tq=#u@P:>{t-U('PiN)\Ƒ{>(wCH撏mĦXB MF$[% }"nܿ":m*;dys&x!YܝXwfWA6-cFŸt"L2`ޔAmHX*/%— & Sb.N"f/C Ǟ. ƅ@'Oԛ i;b"K7 |[.pZ=4(e[0;ߎ= nK_;(“VdG Ծxhɀv-=&2m.y3m\Q.1t$gu7BXd"n5Z f|^NMdOd >?9ʢ/@OtShNlǭJc'+ 5?y)  i, tuD*^fg8SIT6Y>֍QWoz=)5We ’ *DQz [gb$w 2Ԍo‚(8W[ܳ>gQz:!?=X\zOF`ysv ,\4}p;wTZᲓ42l6G/b[sW#q0'˿`0&:>@cx-t}7A 䣓: =i׷^"D6O}|<| P9Să!,`[d]/v gq8^ݯ#`rٛ<7O!$~lghQz@_bR$ qW =TDEoyx?)"StΔYt:r1nU67 ޷l:Gn&zrCHՁנB:kW>M!SPNdX 3Va&WnQCe@~X?1ex^0pm6r;poïPKٙ=.x!2p,ūڭ|LZDIv⳾)bV PjAZ†( 7;QEVGB |$Iz\㉂N\;̠^1E 9CJ#o~952G *砆ɆA"g}kٳݺ|s"@Qz.=-këL >:GKx 4>Nfs *AÈMLP?"|?oΐaW\Ѡp%RI&hF)=}Pҝ!yH.!u+ûj1w`0n&rA'@ʅC 9-1ҥ 'M3TWŻ]Sz}x“({,YguRA5`c(QɵBAVFkshEQ=MAxzeBG?>=!RplWrVkLG1'{H>eimd#˓BbizܵhB:\k j3CK2m[N72+[.Ђľ!~QkKA2Svt5 b $<<˨GSx&JH!sߥs MPUF?VZx7 Z[  YZ