sssd-ipa-1.14.0-43.el7_3.14$>nbdyr@RgAWa>=?d   ; "@FM    4 { $XLL 3L   ( 89:f6=|MG|XH|tI|X|Y|\|]|^}Db}d~e~f~l~t~u~v~w8xTypRCsssd-ipa1.14.043.el7_3.14The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.X%c1bm.rdu2.centos.org '{CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKOiA큤AXXX$W~XXX3a27ddde17489327d64e06fadbd99484914f1c3ee242da22c649828f86c73d76f579a29f3640404a41655c0f8f98c17af6c89cd26738b226a11b1ddb00fcaa218ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90390719415649812e8c94ce606489f7ce48c319ebb1dd2d7700afc2ab2cbcd02b71e041758b946c65099aaea0c1b09192a3ba5637df405f17896a2a5673f3bcb0brootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.14.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.143.0.4-14.6.0-14.0-11.14.0-43.el7_3.141.14.0-43.el7_3.141.14.0-43.el7_3.145.2-1sssd1.10.0-8.beta24.11.3XBXpXv@XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.14Jakub Hrozek - 1.14.0-43.13Jakub Hrozek - 1.14.0-43.12Jakub Hrozek - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1422183 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user.- Resolves: rhbz#1418943 - If a long-running task (e.g. enumeration) blocks the sssd_be process, sssd_be can deadlock - Also Require a new-enough version of selinux-policy so that setpgid() by sssd is allowed- Resolves: rhbz#1405584 - SSH: default_domain_suffix is not being used for users' authorized keys- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.141.14.0-43.el7_3.14libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8331f40a84070971d9978cd680a24ba3ac5957aa, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6;]"k%f@}|,p35muذpE /^!P Ӯ^C SDeam"عZ(6bX(LǰWNv7M#8Ek76Y "<6 Ԁ R^b9VMrՈXw-64@^_R\fE?UtL l5N&n:(T ?'3fΑw.ʄOcD;AdBd\c--,,C e9z{oׂQ_/cg j e)^ s~x(o5 |#alqBu[ E?Ea} '9Njl5&OIDzKVC2޹$1SZafӏRs=}0\˝EϲFOOI|8nmnyȈXv TI9k= }ːħ WY IȁL1+]ѪNvMg&*yq7_yn)6du=@Үy,<s. h ?.;}EnAI6ΪSҞޜKqX5}8ǪIo}s Vǝ4Y`SFGlwwLN`bY*/|8NBKeiC1z/f`jUG W!}4wipzPR_܏ M̻x#>! mQqmVv-4$Y6WJ2bMa0okF΀Jm]X@Gߞ+)1J- -WUݤEH+RiX$Y]4 J|]; *Nz/e;/<=+0saf12TsܣN8et )6 ;1sN5m0Ĵ>d3E ,P(O1RVkpx ;hӖ @ʷKep `h~5lđ v3/R. "b]{KxmQ4*C :,Ʊj!J˱ԭ7noeIjx R5Q_9/,5RʔnH5XjϨj%WUO0¨> fQ@#y)Ec@\^\"4ܝI̦[D"rA+q(#vmO6qSTT*iezQ*7^HKca!9!@!|THNf]`tkqo4?Rr"椌 k֮ȁ3KɷM 37MJkQ R6(ċelޡ j:7 HjBwЗж_ݙ.u6ao}fqu{B餮?y -yT _K{3&iJ:?VQ\F@BԱ`ᾈLF]wIYh؞f0icbGS}W eݦ "^gHA/ȡ)ĞN& ^BL=Oioj'cCw&,l*k7/8\{XB)7 /N{1^w".-Tf/# 'z[)/{C"ϖGj,xsR .˘ӝet0ȾGF?b pzT)~:6|wDg Uj m칟wlzZ-0["Bw9 VNǜ%mi]@n<#>JI/sب&+ h:nsѯ{HzĚ3SKAt=a^u𴍼ŭ uM7CcWZ ࿌ȷml,,ɘşRjjZV%L=V֯m}'V/.yԙ p=tD{ʚGQ3'!ёBf ,">pCu]Pvs7ٝ* hʔn@_8P,QE [356ӡ2^x;gl'Wd RϻԾAen7ɘ[SyyHb}N[f5,SQݚ ?Zr  wfDlE|V0( aysϰbM۟/4cTYc.V8۝d0eP*1OiyvE*թ4V:LCI _+2"@eAuBJio9n6%2Ky*$XM<5M|>5LJtrMT~D)#no#̌s_@H:ѱY4S {P]#ؙKALWP2tto9pv.(P'SdB/0BLX/ *BnA ^vxGB!1$SSmv\*?3s=V,mul~C!^5)^TE\H;6WwT.2 wöq?9FB}Y<GǏAqn+M_b߽`\vk zIW7G]}@:Ա!ņNP>GdZr!U|6BT ) IHxfA[ύ003..U _ 7+Cj\XMNjEovOF_z0Un.ls˜=%^*`x TД:ϧRzębdlYXWDril\Ɣ |$c\f$ثhJ>6c]8~[BdC"\ւڲ!%t< @i79 K§ڲpD*WV3wfC~aFsOra'$$N'j(rc `t֦q gEqP̙os7tWV'D9v7&B<6V#zLU(c*^V+c&?6@Tz[4ooŵP昶5O)L.WQp/S|{PJR%^RؤsT-d=$)5+*9"Fj!,?[=QXѽ %w9m-QXZr@|ʕ naKh|pd提xÁ?NDjў :LC&H~p@*[;3\*We*,rq|]54jk2abI*A_S%n? M_8&1ѢkTlc߹ssE2VOG,;Iʉ[rWOh /%RTwCsRB "K>D2Č Aj&0 bד*n#&a҅ >J\*p渘g_n{?^W/6Ĵz@ueJXWẗ&m[C,MjtEE2.b *CMqT #&}l,%6s/KXjzGCMf9)2@4TUw2C: @z/ (0J&j?99~N `(W*Ydl?cYBSۛIftGpX2X+9VBs?; J_Ϝ.T[>Ρ1]hsP:eNdLc9gc=$mD8"ugtX$!M|?*g־?Ե0Jɭbf ~dBDJCǽFfߚ }`[ۜJ!˯<~ eL=?רIp,VBEZ^6Atcf$*tl[ZyADiVASL-޷"<$Иwͥ83*b.hyHTYĂx(% Cԑ&qbSv6x"1/y45?]uw6^_>BL@p)]_F4*JGʎBtMxaqE+. ˉ-Oڨl +@0ڶG,0bwn`z5]{iI"W28$Ⴅ[ U>%o|R$AG6f&l,n}A+JE6H֋SBTIXgW|~T_RK!;**Ͼ>gD@ڕh|<2 3_(99 [痯c,^Dd UX1k԰"׽Y`ɉهJ\ޙ~p" sPTJhXM5殚&gK3vzײ`lMCy?<(c jzD))'< Y?vbDR_*4f*V%![? CA<5Riʰrߺ26;BMAVU4(JoďDgPps*"=B-B\MD7l;)gm 9[(Nu0V u=Wh8ν(#3R)g7ߪÅ%2n\p}^ ! <ɫy{~^#Ra& @U-d1Hv?DI aRJ8CMJߧv6SbΎHQߡ[@ oT7C39{QI|c,,jɩHE܋HL? 5+M( M[@SƝRTM-;6 m{q|řa$hr牅ڈјyAS1)<* P/ ldv0M@*Bb('1b+a;16UV)b nnMNsr6owIVOH >vᢪX-dF񷲤X4rfw֠(VdT>NJwƿȄ79m]Ji"Bi3(~t _|0l&W_M}6'Zm{d D 5! yl>#=$QԖ c,٩߽9}]iy3%[v -MZt!p~ѰͨK{LQ׻}A]0SQ*d,NPY( (WqW4]ABF=&=i*{/+k`/ Ih{X^^`uwًHς_i9v)?$XB?WIop"DZUAD)0To#rg銳'w<噩Ng=І@Ʀş9l%TeE=/`%<0HS޳f>PJ*%HZU1㎥PUF{F}..6b\,\[W)dx P\Xv 4s,[mSɡ%#|];N`gFj SfL'[|H]j,m64wi sWdAdE#w`>kb#/m/˶+@| :BnAI.D FW6̓ʥbz+DwGy>!Qjsmɢ?Q]4=f8=zצF'NHj⿺[t!dUw+S>TbC*!3T`IAUW vp6'%gJ{{ִWuh2~{×9gZ S 䊷eoBVՇ8ٔ /4] k9&/|kZ:=ד V pUVk*pΟёiu(o)F t')%9p85!#aTRzƨYevGJlޔPV8L8W <63"Y>}gRR:>ZsI.RhB2bF2YFxx-E2FI* qz]h zN!i㣚ЬDT { }M K7d|fh O~˦F(u)~j/_?g&RmX>qr0fxa{geQDV8{i e>%/c L?'X<0nY5k ڕ*-̷u4)T==d*|}iDny_J^t.ܶTF>tP~wGk@4i!Cow@**>? VE!7ƾ{u`j6ۭ7ru<LkΘxzvgycJUMsA!7 n{fqQb4P;s,!4$ @YS6C)-t6xVﳁ)I?O0"RkO!:4#u7g x&+p$Џ0=3 yڷsIdM_at ? ۝XQ}}VoZ~n+q>Ur(TEbUƋLJF(h-Dh(+t2("瓆Y=mOMb$08v 2"vIF8\=|Hxp0i^AE\NNȈ`,_KOmr[~0m\$8WNYJv-]]q-ĶM&Zm В3:2W3gM@,rpRn VUN԰(eFd;J0ǀ6f | J#^nb@QȃO,zu d:?@|`"&Ydpi \}1AI&SiUMp:ț"Q"LJi*X D"b۲;iӸ)Z 0SRXfE)r*ߜϿ'+_I ĪspA (# 94Af! gNɻ@F/b>5QMƄ^!?߮'Xԩ="ا#i3l($]Ff.bl;^5cRY4,3b+ /6L€PoߧmW N.pUP}K <̢^u J_C%5U$76dC-EWdkfhtzK P؟{naC2B[:8h~\z#,Oߝ6ޮ|Ë#gU:)Q8uk[o_<#-{#Ya~.E_3`_<\{G_{ Lx_#JXvXe_X*zndsAV+4~J `8m\^ faUR`-EQ+9MLr.je@ XjKsaDQ +)ah\+{=rI \NZx^VKqP>y:tJW%W>\!ywJBo7u :Y>NcdzPf!~}nZ).?[>P[5" 6Y| JVW^F)p"D:5W2)h4^ >:dcydDh'.l,)\;mkfwa50X \BD񾖣>qHiVl(x90:r-@ My'nxo'muί5>O/Y0 ]@*{i*ZWr#=<vxj&pc# te 2SpXF8wh{ ozfG4N\qZ07M;0ת~աwLȋ$UEfIiJP h@RX=u7AS.f;UJ<$\@gĂx12!Ua{zNpس<.ڭ`Ðjb[b]oWͩ`VT&%(õg̓)[Ef@4 /x/ :4l+;E\|V~(~vxW!SO0q!nģ>i2u 9A1|A; MRٚEg\uzUs2ee[ l;ap+)fũ pwhIm%;01ApV]*5E*" FxѿQ8?n3 cJVD#nq/Ӆ5bK︦D>Ӂј~vo|յ4H/ѪU XWi1?̐CB)-odusƙ -XsgңY,#,vMkHQnsyywYC!(Ϙ-'ץQrO3fl9wptD9^vyQg;Sm<(uEe >';^¼DQAįYih3VҡO +7L^Ei !YoQrj=zcz niQz`ɾ[oМq;bMֲSy_"=_DsPqCž@̾yZsEfx::a5A5qV7z}tX@Knz5 =o p@Rjү{$ڣ cƢQM (/HQA L>\"h咯&3;\0Zm.o`xL *OOS)ݶf SS 1K^DUCk{O/qD4aZe6U3<툆]g#H.ϕВj#ɇ&ۦf(r e#87tNe+pk-RdDLJă= kl "g/f[l["(>CӴs@i$dž(9 #Ԭ;@9_eFWlcB*>4:ItV6Q@"ĶF, d.5Ra0|vx4d;/OӸӏ"@J;Şh{;JDZh g:VHJڗh̺̆כzqa4:81Xq%ElFBCJ: 9Hdi!1 ᯛI2tcw+4ESB)pviQ6c/ԋJ=G--Hgk;,DBg%luC 9 ZGZ\WtAJ~Q+O,oNz7TNԘneT"bhF*׫mNdO*>g?D@ t?HXfœ%5{sF)3(B3j4/:$^  %=i_ 8gO6?ALȐ!lH2>5Ty5¨:aF!$AzT,.2 cAcZӅLqyH~ ҬCj8RFXt}iGfޫMe@X_ QtEkۿ,O2UD`Lf~+<8mUa p`XaϜ#e =w-wxV^.L 0b3'QΉcA/ĽW U}WH0mY#YN܍'H.<$ $)QV\M$R@S }|WZBUA0ݞ x@m? \h~^JVH8+w_C$(|ŤӼq̘gWIMHP%>r7->U SChA.[ՅC#Ði Tg,H$&s r. i , uw~Dhޟ NQdS1 *XFYV Šw7#n_57 =pyR9N|vw:ap@WibJwZ8jNY濙^Ѕ'JaiffPD=c~dt<5Cem8SD&}&P&Ѡ^F޿vV-c e[4zcR}5;!P@;xWMŶ7 )åx5~Rz/B ljN{Ht0M,*t?JԳR7mL _ot}(3a&ŗp} 0ޘ,%[:RLe5~yvթ hߓ z2kaq?o;؜ k&^qGh}  l;("` |#)6Eˉr˹صNʞ ]n+<*cfMQE,gndx O7x1yF>b*KԞY_99@0ȟ#GiFaD({.+AƈͳP@P/c>H׊}Bami,43<D eD%xx&dH2-q'npRJk~6?lzSJ3NdkHxdh )\.Y}FˠbK7;MlWi23j":֐r3~%-,[aSO!< ъT25qs$ѥmPiDe_8x?4x#GBH3И0^e&T`0i:QMx!7J O$cҖ$ZX/4X tA&t>^T%3vpIӇs.Pn;ؽ;v-_#jUP:Ku(u+2h|Wn: N9Per,vĒ,/1l=="k(!fn`0V'|aVf&ygeCiݐkݨT @'6_PG,/?DeHyE,7S15e|g* ' Ub(7#(x&GK\\EgnyജΟ7~f 46=-Zf~'F`!}Am J(^`rT"GrÛs0B:0BE\4A4ms|"lc]^ۂDyYB "܆޼?2D_RWj]e!X: dLND9qMrBK¯}AdvFHJ $gݎ^N I"3G+(kѴr]$^_~GYn-JNEŹ"#(A ig]JǕ|**5"eKD/_Gka]FK6'n큾Qp{: ɚ[N$z ="=Ϸ0[mQ]gxZwVuHJDh5lĚ{ ~:YM)ǯi;f)^(wۆ.Chuʫ͠FFwg &x̓6@MQ-`MykJikg">G;){H)xO{9[w-?g*Q A]ɃP&Z dųb&õYb1O6;rs]xOЋ-6za<봜 Cr:bo4{5^z>80!x ŷRBت/R/qi} fZH< :?)Oʳw&eXrjM؊Dj$foUZ26Ȣ :1*3ǧn|chz#{~W"eM@r~p.JG =ɐdTj*qnơYhrִ f*(9#*w!ښ(Z/lArA Xީfv4v aIsׇOJzǤ8Vtftj>l؟VvJ=ݖwr.Uo?(HBΑ(@i yqH@m]Kdk\84* 4A)z-js/*zv>X#;\׎:;TpqgP-n|nm~_eޱQJ'a {NJyow,4;V';PikWԋ)9Av^!ݘ,uL 9 Zhq'dթa{JO{2A/ zU:gF%np b_&5rt}bIh:t͏QhZ5QUO*Jts†+{rZ)Ad[4ڐ-O]qZ~};XRROg^cT^2qc9ᄒ)C wW ᾈEDq6xO9 bfɀaW8j2-֦$O:UQ=KG OlaYݸ v=wCOgTAъa: 9}BC O#4x*-,gh8nt"^?B.UcȞFm$[uU׀ЁEapȐQ!ŌH'͏~7sc6LF^K33 U Bb㠙`ŭ aA2qZbaO̭5c˧>#x~kaBi/ q: ڑ{v8";<,KQdY-Һxc8{!PvS>{?y;!tǿ "uq,,BƵo.|t`~C w,8K( ) Z͔NF!RJ!g؃V}`IZO_$N>E5o6ցFV %iq*#cgwL㵘~VG|Rwtթ>*|_]RHh?NkWM;[u[_ٙ[bUm42ijEo_*#}/rtU@7xO.J";4}0џc k }TC-7{08pt;}_zm9b۪bRa@zvY[C';r-YĘq'VxhZeZ+.hn{*u4 J\zL(EIYI )g y^߇:9܈.$繘۱egL$ɱkTjdX{z]n  &f4sѣ#.c>Hc?@[B}A5$zg4JvG%xNL}#L^.t W xeX ٳ^jqvpΞb_iPմ}P=Dq>;U3b>F"@@&mH9,V*V0 T޸/KS:[5.-׶<<[noUr"/T|5>? 5_r=;T,;7N|4gx iIkr&1!DQfL^Ry 3DrjuێIrY[3c@cd$Un_W\޻v^[:KZjPTC~Hf'lR}u IYFFfӋy#sS5fRθ3ͫPE%O-:Б 喦Q'x xCu(۶♨l̶ot9g=+rX("'ly"sE !ӫʮǸdn ;!=Z?AZʫ^lVr$pY/|-cdHϮ-k5qJ`x jKS -2RXXbOHHvM̠ YYpOzhȥvcfUW6a[G 2K\ǷAJ@gq8QnW0KąPQo[Wak\[R`3U{d8 K65qMIy6ÌuJ}dDʌ%iзa ֡x) wHaӓKȃ/Љ,.!<4Pš< 3t[`6c7Vއn "fW)Y~ozȽh&Z.aT7KKCpCiDY +|h/fu*P~ƏB@9 %;2Mz,ohl9QqpQcT@} 0IX8;S$0?C:^x| ㈕U]/A%'8IR FYY!ph*AV030ȗ]t|,]u*1}PoWY$_MƀlzMJ1"J/--NJO^r( d6҆'ilG]ts0-.P '`,?BFjO+CALny%=tUb0W}y|l\y9 bVTo;{nʷ*r<p7\t? lb;eԸX z|߲f!D8>eN9Q my(ԺnC*S:xov[T{|Ys4NIӡ럁B7:\uNyid'85VEcƲ_= MuP*7< Oq5 <6Z1a`sF+!GWY\SױBU(|Ҵ%1v+'  F/Mn-T4&}5MzJSY)2U7 !o?dw$ٗ>ܧҪIRwe@t! f` j]1wfl*7e<~u$5nˆWU<k+*@T{K[f>3=d1$fnZsb-` 1n)Dͳ6X#BtC(u}h5_xBXwXGRQݷC>ٞ_p*hEl:HۄMN<"`nx $/ؘk(ME!U^ t20p;_<cY5G1ònk4̭Xet``yGtgSǩ›$MH\QI 8&-|^ `M|:}+;Bν3坄Ko2d|kFcyfciX(@ꕉ3T'ܥLuKNPT&)RxFFuU.ߨ2U>*d%جI62UWl'og7E㒵CJXݱމ9N PgsZ[ uRwv > j|4S 3Um{%Q1tDR쏷Nݧ< ^nCQ)7!ϠuܫjPU<;*Hh t c=MwRf2\A @b7PIj>< @{R?' .őֹs^T)C@~|gq`%9.OzNĝq)g(4X?yCN.z:؞ b 7kйnbR ݹmMbϯ.ڴ[86cq.Mf oz7V,SW||g!u`/":|KYMnR^^1KEE$Mi7RmA=Mdgfb "@I9v-U覕%0o4 u$];u7,w!OQ%((z agTW㙗ٰ7" ns=cnsB1BJ.HpBTMk:ڎ4=NF-QE8C_o4w T"c¡ m_K4D 40XgtzQeWʤ.ja>3[)vtjakK2:&Α6k6 (\%?)\1͝_zsTͽC \D7[j1Z-D;f~iۡ.u@?6eYԵHSlsS DßS†6%(`&p-٢_!贼!]:m_YGDM65N漿yb{\ 6jtEεjV EcA wVѐ(]{=nzXJһdᒐd7rXD]HZ{R/FA!*->BIU _sA苑[aSmȟA2m ^< ΒcS3I0ړʑam@QC݈I]I!1nl , :*޹4V縄E??<ĸ\76 mvG{:#~f`~j-@a h>cc+p3N-'ȏ-!<zP!8 G*&Y-~Ռ,bc$æ @j@-* iki`,iy'g*JUqkׁDg3Q+C;3C7J!3u"3on`t᣻;8/c]H@aː,;㳜9RCcp^Iז0//Gn%aГ/mb]RK>qл$&|wF-:3XFzkƂbkskٺfD6MT1tD$Mb).aZ-j%+yt $1SO4i "f/{wU5p3w*,苬L3ȫU%v%cr9AnO̬wo-GpId~Pj>v8&k<24QSnP86D9iŚ.~2uюv$[VȥWYpб>}HO= \#z)"Kh(/vLHO~-?N$l8jlӅx`i O)#$Р'>oKܒK.{,$VEtUA9JD(rs/;4m %#2Ya\+h|D  Վl҄ (yKXEh|}`sa0]D!|.ӜcuJ! >7"9%V8g[~ o+Nh+V3ɝ"j=vQ zWgp7>_/AXِL&O/j/VGiUIh<5:b>Ns臔MQ3T9?(gUԟ$O?l\kpiL2j#wO)gsqNɆ!&1'%+Nziy+~(*!Uڜ<8A-wVֵ\,E8ؘB/JČZ \[(kEðW{|fy>p5 JUKtҹQL j sTShUr(M*95}-=**j8C+Um58SշCg-uP[ PL- ik?x\h_ykaŷO}[qzÍ#I%v 591Yi4v$mp /+ΰ9%C@ȱ$ųi e0eVVxkoMރ';ȿlBpx(>I"tS[Y8 %I?? َ2ÐWyJt46[zG3u.?nPkeK(\} R91E - b?qzhG?/qz5i4l JnBYĉ+L*SY39D6<ww2aΛegB{_& kwe_W,ag\ir _kmw}g]N7&ݰgS}^;Q]֥yw_.A qb_(lQF{&\5;0.Pk) +sL]a%fwZ?磆~RV2 %4hk:`X * !KM@p/dw.?L0\1B0;wKv*šmt뙔-רk-r!'8JQQe;9Got=Ly1D`0oPH]XG^x_ e~N̸)mN֌V1f?|^ oEn.#}٭(YtІC/w0lMX1O|ߦP:¯3BBfEy?d8 S_\Of\!W EE00SMl𢨝q;@O6B].)TI1j:UV]Q_xQ8bmX7 \I@pϓ7dm:-]_,.{C5d8i2_#Pw=wC_A|̀x9d0)x~P6,~1F|JJPBaItQ3zr͖J6xDZ_sx;=cpԨT!چhb|C~<$WTMVA6N.Ħ/1;o>>GF߀vPS0D^CtA҇DEhf?vްNw)(A:,wceATdX6<O;nLh&U B:=,F$U> Nr5z#8оC}̢7~LVFE_-`1EVJOL56ewaq9-Ax CPNO*`c?ZNPZÎZK&"eKTV9 Y@=9|1 tE+o/v*PC#ʵ7Ϟ'q-H&~k @= /C N5^WV'`ͮʚYYk6?4ߪ+Q%b-t K]'`HYڣIpʡcόr{_\0/PvPMHG,uGs/*ZFs7xe#}H;9S 6eFnxj'yW$fWI>$%m%ER:D{lQon(VyǭT&ʇ 1LJ :Ɍr;1EZZI gJF6b(Z32}5LJg6>7Iƙk4A#4acRo#EM=&ھ-u2vWhrI@z/oUIki QFXn5/"WWcK.rhk׆ho\h8u rHiʪa`[%9@Mc+ՠ5afQ[=@({"KvGn3֠N."瓰B[7Fweju? ltihƏ{TRD|n7YH4#&vh? (./%7l4@e'+NLS﨣[3(M@=)oidSBH g?)^eΣ9rx?~N4R+V\*i}Q@T})[(| nC{QQ kmPfS ƃ<$n)hsJ\s潣hr-ƒl Yw+*|]b]ٙ4>,~A$П$mf&^ \zg" ennkY'^8>{{eުBגA˙ tXb|r pzT]dUʅd)s!l 6OFŬzOȣq"w\C/ÀP^/U`#|9BBsXyX}Uj`|+aD5c|aIm&5$z-odԒ:'/RZG~|6\fS)!7lÄ\%3)T V<\"1 @!r3ƒ*< {'JcSO{9 q()$^,7n#3g|.uv2Ye/Xw#=U;N"i2+Zo~(<>XG_T?:Bo @*칱2Cv*RjG9É՝:!a?DyjH.w3 ?y%桷|}SEm=A# FrD@ :,1_3CޖȀ蒀)Ox-pi] ~ͭ|;gPi5Ƅ7}73򠐪7~bRvĈǗn U:wR?G=ѱ\\3icb]xZ&7n QmyUT20XM DHU&?a;ɓ;b7[%i/l!ˑ8Pxà 졌@4 ;KM{2m ipj|*0K!/.ϛpE4rrJST^^aXPXPSO4BV~ŅP$!:Kێ ok<(~Xm8.L攤0omvZ/A@zC)Iì%[b |ҙnVH]eBlnb-sXH-P;b{xZ r$/tJ,L&Ve9w<"(!:F)'/Ku&.Om6 ꌓmѼQQP>Yx*%W~t"V|8E=Xs"pwR!)u*.4&HkIF6;*V%TSr^ }2ħX gUXc߷ Q9)7Wq^EU$w|j'MXp8+FLDqG\r,  '(kxGhn?(i c9qiqOݏvیy)|87M:2|OS@6Nt*C*W,wV/)Kbug9tITM~ޙu bF;hP=op;,bfp6|vq,mVZ?J5 llb sGf[AmuZTY/9?x^Rc5ؾxXfHW -֫W;Nl&bիIdXX=X)9#T2e$ON;uK[?.Ry#2}0th)ۧ KPu -G B^2{T$!y99LXsUi7Ug‘~PEX1Tü@xȂ֨>?9(5@y j@.׫u{rQ9b](-da'@*!Wi 0W滧Cƍu/&J8\F~OHx/b˾u_kI2sN`B$LjIsTwr,ܡbD5kh: 䵕eر/`'R`>W; z~ uQ-SũT2Ŷ.T`~ͧ"ӱ2,ҌyG!3p5 YΒm7ݜ>B’F 5 /㿢`WDG& fɞlW&"edLmeJ^`l)&;E_-@2ibE}y J@u>3+'O5 7G9r٢ǠD\~7*gE P(AP[0.F"G9Ȯxk!:CFur?xG ~ k#C5Hk!p%ƌhb&|fl$-QUeݚ2|WĮ F48A5AE yzOT0.V]EOH # =qRCίZ#~\Xc9w# B2R4HߌmI4' %gi` fg=K 3P'bC`L&C!T~Kݩp3xzFΩCATr^q 77-"pK.wVQg7ű)PZv1餇-B{za`+U4l ︟ݻ{S_?_TbRR)zܮF/,Qg` -Ǎg Ӟby%Ry 6R' Op;1qkm>=Ow0Zit 4iR\ԅ;zՍY44G5R?67vxq E>GSA`͗c~M ;,5gkR/*,4E0ymϮ U촛⻋`)f%2 i)ۛ \;|3t,r*/gl3 mvlc[~ŗ5J_# ?y`~FAaJ8 zCqR'/N_dHƨ L PG`vhafk`ol:"Hpa^ ѲZKz5]GgQ髦0j3‹%5W)4‰iNb~UwtCs`0E(+75ϱCǖb %g2s@= O%gv:Z#5W}jNJ*UZ*cwR9wU'c]VhAouyf(JFhc4 Cz[らH$$#<9EA>C}) ;|2%TP;͔d: >cyG`Dohk I8t$7@th*L&܄iY%}'j ekN;aSyO):хqMuu%f 4 #YVN)pJ_oOac@ڟ}…)ɪwGP> /j{P)p*zaV>3:Һx:BxV˧3[o;])I+ R>)˄~ 1[gZ; dSSx LL@L%#Gy=T`zQZ($~$0±cd$tJv9 ?Hrچ3:ؓbUH! MR1"'$!nRƬ8V^,Ji^dB9w)*(["/] ,i#ynkסUi͍nYH~ֳ,a t>Gz](@AFaZRhF{BŽyX:xa+ˣgͅG6U! ËF}GjKO EUgE`c2wOk(έ=}ہ7R$"t],𡞚5 T'농jrݲ=XuS:"75JX3^pĀF/=ԝaҊ;xp١36 p'oZG`d Iaa6ꋊ fFƸ @MwOC^i'` ^gS {(]q1t~Lig_5&jj]t@Ff)_\ A Wb]7Haǻ)fVc|"SlJޜJ_BIǒX(kY31}5;<h,Lʙ-sTց3 a {ĽؔiOe't[*p^y*S,mw;ݚߐE&Z~%F:u5l{v,ǝ/ tc[8kUs:m.sBc>'!i1-pu-3~m 4#)DrDHrB7vh|h^yc%|֒+;Gtsc/3 4)rbjed3{BqDՄ_]0O+媍}wV)tYX?⺜)zڐɪ4Tv $'%;[)Tђ~8͵շVeu;2q?G-{"B{Z't-$ÄMlHtJZP[&vS(|Ofg@b;^NHgB',IW$>7K i*CL1hH$y?>jcD rPH\gL"QNaݩn3aDSGWP4x≰~He7WaEIJa;h[",b8`iQ,SH5!+v6(Foڱx3^UkcVG N7~K"=^ND~U@Ocw} R.vLzgaˇO|95ިiaBVE6>睌ts$x:ew(AZ(Iarס-`recaas@dhDjـ2wM$))ϸԪPD o@#S)@`] JI, L"K3غhX̀O$}{f*8ί<>)nVd,OEtU/Mzv(JK2X~Gݹ3~)xɦZɽkD3gw믑:1j|_zzU}F4, [T_Nly5 ߺwf^6O < e7ƺ%rfBBQ'Vq78lNFSM'65hD(`QvɃk L褸B5Iī`p:wr ">8ڤ:rEb8 8jj,:-WLdĉ%fx[zC,YyGBxg\L}( WopɤJtk,䁝2*5QհW full uEH|-뫌V[#˦Z:EwoKOΰazuk@ҒT^gj aRd]k0SbvAUp6cvT\Tt?"9ď֞JaҸ9'㽢1犸7fׅ*ėcش:( Ylqkό/v:GW]" =7qf{}ZM/TB ; 3iw))(",fkdSSu_s5 ׁO; a1ĸO #Ui%. &A$HAc'1T]mgz-y,AUr/r#q֐8"8rwy͸L]fY`K8 )\5uX*wjRԮ8YVćwaRK]>auvyIqJRD5fmΔ]_/x+VRVXYg1R‡%gsKrץM! RV d|eY?HPvfJux&uc''=pߜ@Z# P^䈦nJOUhMEoaTl gRǡ1v­ęB%fZo*~jt3-F&glnN|Qk }#t}$ܴ͘&Ill60\Tg<#SiFhh5sF(>JJ}xoC'nvV]6#agZt yx` !lU+M$r#~H˱(Ǻa&+9Z.6aU5}x57y6h2 Uybnuhks[ M,bT߇ v=m2y$,TYQ/# N Qjmx}vyF"j] N|T2FAC4)Y(wքDi F&^qdР#RDgT淃 <}=n6 d^Ѥo$$ܩI?˺DBl?o52wv]WYu3+ Lu.fF2+hMvr^]Ԧ>x 0x2Tff|v |MQ0$ Gc(^+GEfvF.g=e G]rK Ԇ/<؜<\MҟfEB>ffGvA8?@gS}ZOL)hV`&m"2uL^(OHY5 EV~t,nNuDW ֟sQ_K\A P)Eox;f;F,*D4xJ] _jej@yU Qpu; :)iu+S܋J' Y㕖&տQ/Ἢ.#Ѐq9JR %R_ggۺ,9OGHE .0v٣C}4uҥF&JP 1|;%ݿGZ|ެ*t*IlYwG@C~J遥 kvTҝ'$q4hl~۪,ne}҇X%BIGeMi$: ಂ?z[7dSբHVЭ1Us -r''䅏w OZ Xf (v<4]@8턎Ʌ4@ZAGe{[]$c0[X K^SCW|ۺv`R3.3*;Cc f&}7lk:s/0ͳcW:u߾R1eb,c2ё6 Uvt,lnSH]8kyJv5d:Qqs^=C\ސ-wYf}:],-A7D "rQ$b$-Q Gdptr$x0vƣ˘Dy3B$W`$2..XrW#6F".N:@4 5{i(E+EڠuI&/zgi2'x&ml&}R*6= ;;y?Yu?clEޠuW|-,g׷q-$G[Bph,MW,`ty։/+%\`x:ŐRjkN\_v@5 s҃PK{$REX/;Lɰ:RdkƛQ6#KV{6Im`Xd$stcKNoEBG:V$Q'BmG3v0cj!amdɑMډKab4tîr.zK>I+5w 8бl Hx ^ogI´#YLU*mG mHyR+>$~d&Xk~Y!tzQpw,}lt|ש>֦uօ{|:i'89_]|yƑUӸ{iX%2;1!Yq#ơBiGDHHxJ q=<;WTkP/$j";xU @L}s["t ifI8p!ُ!?S,vyB@ |y1|-r^!NXK*q}6;SyPL(Z͈ wG=y-sF0'fX9J9GBFwP_>9qPܞ4u~{dD=u&=,2- ܔĄXIvrpkH:N#^7iS@kRaVy Q䌆A={x%RJ~gZ 1bmQH0k Յ+l܉#pZP evؚWcyżA=޷}′㘱 ;W8H _A1m< Wۜ1g-9w)(">e&pޓ;qJW\r~Z3=%VvUe(YZzG@Qo{{h[]+iX֖AGI 0{ S1yD nߕ9ޘ95½YXY+ZU6mⴑ4]ɜvU2;p7+ # E~Pn];0'h UIٻnY:X+>}WVP)y]{C1}Y8 zy Vq{8ʸOu~OlǦvAq:y$hB՗';m4W{| %׼ՒIGciP/#z'R-~aǠb$ 3Lwno9~w*G-WuHB5Ufո00F#F31ԠȐ^w~ypՠRxs=w硺ʫljMm!Q)Ҫ.bN"݂ +G-}UE UVF͚J"8B`rVTHi2xusU ` }zao\ZI@SSyPL9ـ~G>P:CKޏ}Vq–5*fgӌpKfX9lqwn8)/ $2jNP=jC~ !'k+IO(z=7 Eu5z[Uf$ 5gHuT p]GjQ-&jKHxM5]vM/CBdq>D)Z9 Q|Pg7 5|aVD)j@r|S4S}1Ane64j{!?vB6 zv />Y Y+SdSKyv38 Nxٔ̓kf2-Z/i$qpqz}Fk7llc ;N#!_x>@F7t-m: W)$mjbob|fF@-7MڵYy>}#,mkv-LtPrA߮%XI#f.gNK +5p>[3͆e#(NxXפ6=$뚈UX5ηaG"DF4Y'~gp+5CqN%;ƹl@7.lԡe6Q֓`5@I !,8 N<z3I<+ꞡ4w o~ˍqA\O&˵dֶL;WfHqx7eG't8`l NP,ʔkXG=m픿x&?yWF쾘{4IKK G\cMM)Kj^JkݢWncU %g 6M*b[3PQ6;%G4\:8lU'tە}$~2GnBsLͼjkÁ9QMLa]W#Hcr wP@VeI PuD4ZT^kL:tGws7 bffvo r(|)ba!zđQ`;S05Xp'@g/썴Y"Kbžp (0cis fLH̸Jɺ$ b}., %at.7@:? W{C9H3}MyWvO6EL7zA-8 B@ԫk鯵2 dcQVK" ƊC%&g& DOr+C?TP\4<"zTckل~IPxr+\{CUBA$% qt*ǂ9ciAT+|4V~FsH&d6&d"=O_,#~ Al@z$I!6e;+55,NUV4AF|j/~M ]5KG!đ#JXv%/=YN@ V4>vu/us8Df9~ZG,Ax6pFv0.GťmJ,p( ӁtMLT+/S4UUhk6r C8'鰾f[qWW=,YtLlWwҜ4F@e]'nW֩Pvr˔^tŷL }:(_CRlc;Z҈1kJJC Okq뵓Vtkpb_~PڡrQyrG_ ϖSw5lEr8M0?7*q# hfStۗX3H6ZW7eͮ{.ڗޫbHm4&x]®2HzED˕+ gfe{Xa;cD=mUJu6q(|^r(bSi>gsM i,&_pq*ܟnѮI!\0{gu(4UhQ9muN˚E%}G9l4QI6= #u'$&.T!7v2&u橀54@RtAO޽Gh)YЊ~HϙMZ%P1ͤU͔xv)]oj܌Jy9b~Rq.om3TMex8~yO]AeOEJr-#'#@ܘ bs&CzK#*Ҩ&AL¹ʙ yZ1 U{kꞖ{Y%1@b}MM^t:boVs ri:-VH0 Naq -N ]0#4|F2tlvTkY S O3(,p) ]Ǯd.+` e(K$ DEa8A(q нjtÄR 3z32\odZ\[ﶹI?Z4RL0]ւFx·,J`,w kI3c i9*Ui?ȷ,KE)}5{Іb-Dnb'g%W5}"@T!7tfc-S/W[ƛMS"' *E\BnHޡӣv\ENy:<HaG% %7MܢOu=uA }-SٿzsБn7]8(_41Z=\=8GM%z ۴oX߫~xW@&uOiU}bO 4S[ׯ/Y_^C/[t ;cFgjuGI~՜trXajVSVSdдӏ|JYcxێH$r=; x$]2ԁԂhxCȪ}T{ @%#qDњУ~Th_m3i)f#j',#1m㽳\GX@6`|^s()Vaz^:9$^Q)i;2TS_M!Dn.[SQnŖy l 'sa]n# #10yml?̼D(kԣYZ0qKxlӊq7'ia1a>ŁBY+ Bkb ݰo/Pw*/KcZ+GntHdHW(uvɘ#l‚XZ>TMp\MnٶMl+=aV8 qT>{wI<|֦nS%4&|̆ح.~|q)ƌM  yPaǶwWW#[/sşk~uQ=gMy3?jD*Ȋӝb2WdbE1>&gGIR ټQW}˚OS+z^CxlՄj cJ$ŦO}Z{dd΀5XW:->wE+S2qz9`[S.=bU1-,J = gqPN5RgΠY̅].Wcaa)*11޴f?GuG/)k5>`֋QLɸy?!5*&\b˗m-GtyvF7-ݱ~YHQXnhY~yta,}0BVvZZD2k.bDG~uE[ !ȒW䭈P*"yCd5DJȹ hCxH~QN*0 W z3Ku;v~e0ݸbʑ>XޘM&D}{VU.-WeiЭ0_Ob)f(?-j:WŸ<M ;y^{0CYug]7V7-tb>41(Ŀf0(s\h-P $!"|73}Ni.eeQZ%'7G,?I'ԙ{?M}bFBnOK'–{`qי4wm/ i?Uψҧ)1Ep8s9˷ʿUi`O?_vnG&N|,J>{;8Ԟd;DTbkru}sXvTWLm ^z4|n2K\#:^UVG UX|"lg#U_?']d->sF!+lN3|(_˃!3$S<>'::b6|s"N@Pc*SUSƨdNjS}QHZ,c)Z%rR a=sI) iRahɜ͈j3C!"\1Ƌ;q1xdhnHl.':B DxV)6W!dӭ/:yk'7o0aׯE. d|KWٳjS'a9v'PtV J#& #"GýfOى+\xMJUʬRGncH nI$4HId3Ynu_zm.dbM'2KE<Ѩg9d2[(`MZy fn RfhR~GqoBM'a yD1bCTP6Q$1@(_[Pj9HO<.4Cp@PwM0p)lWm`p{gsՔ*#wȬYޒ;pDsr5Dso3ˈӥAa`'׋7qf*wr#W }Ͻ?ڶk3\Gwf'Xjc\b} $ᒜwIrFej'.CТ X{FcNޯAoptU0Botf9bq -So9璢%%Rڶ8D2{]}iqF6c-e3 @e/9d4gb_tYS_9JoN ewHhQE~v!fyx'D$uMݷXkTSgɑ:7?{eC3dhX穛^ Ys02%LyW0 G7v0:@"} )Kh c穷<;,@'NrR=|tbkifP B[E:7+M؜1i.|Qr B_=(%'R H)h j)% NV-\0L%n;Ocg Ⱦ2@>F%8TX |18d}N}=vYNUẁgǒeDF 'P'-#L(d]T4DTh^P|j'bϳb8zc^` ʫl$pq㵑>YĠ'c5Njm >me*ooW0ab]LQ 5SQ {癪 GmzS;e;-鐨uL;̫FlPfđ62bEr,}/Z*B,D`V tYzZ/'rFj<.$KSްv7SoedYs"6a/ãThMIpMle?hX$Xf_6RZg vW(_ !䩷cEnxX&U=v7:No?a0Nv-Ue1\b41Ҷ+ُoYkփ"[k8gJ\lOGBB4_ q5Ⴤ-YnwEOTLzsBLz6ð:j_@}!Q$(~)'-2s0Z5H'gUoiTPVwP5Cb**]0+ֺ^G,.,v9iX-@#ʠfگjR2y2kPB:*ѯzoEpTWUp^6WڶíHJ"s*m٬zCWAApK% MR>eba_XZ/CE:Y-F;ɑf{yNi!ϫ-[O]e2C#.j3 ]S[l'A|m: +Z?ny{(y#3M(Ys7Dp:dMlsU!Cvτ`< ".Nd5br҂M? W} Dɠ\>$t6T)M(]yT/H cO r7 \]"?090f;[ kvwVJi|m)%C5lOLo n U.ɧ_̽zݔ.)s--Ekk(6D@\si46(Py?j|ɐ/S*~@KՌ, n[r~\qQ7&WP#hH 8Ȇ -quY%=}\"ԳXO?CE.9 pKMUZ(0Vm?='WmcRQRG@d@z=ilgOҫŠG~*yΝW ܠal鵩felZ~:T>lʈ/I:ż#͑6%5%O*\1g_ avFoS.\X|cz}hJ~Ea%J@^LnjUSHWD2%TP)@᭒hO^B!Pb'Yq[ѝzjTWĬ=eKEXPhۣrC$ˁTkx}χ:)[,=Zt7R-*&d7z\ꁋZ1W صU  *0U +LbތXmز0z\aGw<)'7Vw]^KE*w!Άȑ{Xr߮qĖýr5{g @e5 wNqOW{pf(O-w4PkaTdzcbBi)A~QV_7!CXMtMK|p׹: *z*eUg2]`?. \$I 3:+9}Gi%2 $92?}~K)Q>0D8mq7e Pw X: N~Blt-q#35P)zu O/]&49U;|)Q ޵+4r]^(\ĝt_ "GRL:Dyt!HS6棁! #55d,?S^L̀GH^PHn]D W=br~2M*pF-.있{9A#":vw|k vt/E}^/#ȗlH+pbw:{t  ;Pt5c:BZB 3ӫHZSk 9x~H…43y@,41 PȓXI^(|sA`Jghk[%0/Љ5 γt*Ss эM==+=OG._A ֒;;wsq zX0~|_cj~J{O3Y-HtK샇\~Kw1 k^a g;!QQmCJWKr@(3 [ڭaqz "v|"v?`R.yX%a[ dܨyg]yhPQ8zp+w .a 9ߴ?W}8.G.j\D35Dx]˹!Xt 6D`\jJSnfu _ GGzXHoL(puK(B VPXFOUKO-_8ca fCS{R"3Sw{#Ɩ_Fi ])gkmlD|;ߩ iN̔ng0tGֳM>ԋZdPD!QGE A^| 2!c(лE^ɥįT< u0OkڳU!t׳jf `%0}I zPJ +};M^9Ny;Bbz@J.紥GmeӂyZýGC6~Fe(|=WL'BK} ^JrΓHzuVgB>DyM^6q8қՇ#݇:8`}>IqV0 w`k.#6' uXە}qjP1]G?j%]ItBN9>e,DVΌ|-]@_!gt9UqAK%^@emԹ4Wh<n^u&v S2'Kuk\GcW05;yzr|`f;?ѩdX. KF.Tlwֽܷh5MMUţ [h2+rJ7QLyV}eM p,W@M$'=r놱MN*[(i (Ň0[VY 9.ۣz0UU|L+¡kʭ_+ћ'L'YYHQ)nsk}T -XC̟< =H7UlZ#)~vbxKǼ'/?ܧHkw~@d0>^0;ȵn`2ʐ8'̯:Ff` ְ(LJQ@ !ă Q5huȓH.L;&f->* XOaK&֟^F52%I5H"LަFgy7czF&. J!Lj+P#=xQ89abf@^cA3h>!ufUx>ݞ)CO7'bI iA bńeja򝘼۵P{5O1ʛD2f+RZ'IZN/k%xrn=橢{LTpv*~`C%AAϥ3F%ZlYX2mL(МqԩST}&(@|fp#Ts|/܃YSw6\k׽l /LknzI[}B7Gw>K^\mKb_`a@ 6x|sCj_^@iepqb+]zYj&/= 9(E"P(V̍~J!p)BWb(ol8Hbkyw@"huhW+Xl,O0BeTs;^Q." Ux[J6O1 $@793#wC6_I-Uo: 37׭ s qꘝndZU8Z@wLF618<& ==d+oˤK&^_>޿}@-}淹#ߦcu.<+lrB>ll p)f?Z$^Il$r؄tH锡ط7 נݣH2x<LvC`=3ES Ϭ1vao/xYNۿTLjm71Cz;4i.ڰʣйDdX)Eˆm.a$q#^|EZ@8rd?[K{f8懳?*ȄRW9&&&ΜUK[҆>C`GVcm)_ ح=.| aɇec u᏷kph昪>|LSJ>T|@)_/rs Na.ud,A@î.x58:%g )\ >》ѫS P:Uгbi*2QR%lmģDn8V7 {A^c K.Fu=0kc*?%x\2Yk-֥6w^=٘}&b1Bh7lκK|+нA%m{Xʾ.}Hv`ʷ;3GENuUF#|x4$"OO]EMv^< ECmtqL"!p/;ˍ'UsCHq{  ylpI!BP>% KXذY9AKGzeKV j2r(+ ̡TK= %.'&] r7thH`Z}k'2b)ltܩy`i`ƟIaYnBzL#dT-Z/_;u)mon60 S nXMI? ~´5?(,5x^4U]Q; g?߃}mb(-w@f>*[mZ 8lft2ك6/%VDz -^#!*(|cPY^lB .yiA! t^Ogt^hěɞP,Ir)oؓw'S}GªF55$@3N&yiQfԠNN:eo-/=`q(n]4x^ (!뮙Yk_ٻP-\,b@EJ`VZz8awۮ0LUDH{UIc#7u e`ԭm{O]%3B5+ϲ iLZřn2py}s]gI\ȁ΃g`@ X)2L=5sCeY {b%| .H(H.+?&!Y(}‚@˥_@[aK*G75g[4{{0Weyj_oMuۈܬ{hKZhZ htZwUF,8w\ TװAoCx\K!}wK4]ML{PDIKn&%>x91vd.<~!<˫mHyLB bܙGSsm4@)&ܱvyIV`UPSnR] nCX\`٘y67`OQ^<Bs}6v溬X^6B OIBu,f[\ YKU9l/rIj3 a'JT歍g߆SGB3B|rڣ*_@`+ou2K4oK Q$[+{aT/G۲7=h̖Y[3<5hc-[HQL $>i翣Qxq8H& -C:[M3"5I`xVIA5#jC/2 1# )y@V]jJ: \ۂ27Ӄ&@zak =iy7ȑ-2UkcN8qwEm}0a,\yO Aw3v͑b"6PlԎ@,mRX`Ąvd]Jdn`Iޞmуsw>7 " `>2~ g,I&̋%zۡ %e=ކF Q*彂9_djnZȯ97XƋŗ򧓭1"PֹG9j>cw'tt1>F!;r,fe)z+sdKlG=ýv!>BzT+hc;ZB ?3Ypl0>6U|$y'?aP jg1uU'ZZLqZ5F;S}=o{TX莎p\ 9p^d!G)e/Gո3ڶ36Pl4*-QG{V≨'sl>O?Uܳw(ߜk`ی6¤\FҨ ^uсPlxAq2R%2Vt ܠ3;?ۙԥu#!Wϐ oJ T~iCHup-[ _au7kMwtJwJvɵr I*QcՔT q! dY\|!G8fiSP9TaWV5lt){xCb'] `QHY÷رJL9@;#Dy#zq`j]₽1I~q 6ﰼӝA d7*2ʓ(Kio ddh@soPw:ҲSuo*5$EԎi1Amb;D,yÅ Pv3ÍYn= bė/^ 4N fBSf%o.z5VsU\">4"f;~5Au~9KрsF# 4 7ǚdgٯeZju?A,&]rյ$g\ےQ4JO 7tH#RS vsEZ 4e2zl9_Ο!aU!C<h|SFy;`[K}91~AYͣ9 :u{1j@ߖHWe.#ua֫c l@QtdDFAA5O&/пBK܆s^I&W_G윺tq xruj\z!6@D#@t%u+Ñ'pGI̊ u)xX[huJW2WYI&,Kv&zX4ePP۩Ǐn  _6$'#HD/ aWzE]349)|rZ6r!\Ի;]c. ULqn\p{VsJ:`kO }{|c{HnaWBG%Iȶׂ֚:ph ь N_%XO<>=JN(uC+K-ԃ^nڢon\a~MWCuDXG+HoF 8M79c|rЕvy֫@o1 J&Hj61L!{MFVH7~+(h:䳽ǫ F%}*hIgGV*ӸkU>}^$݈i3Ih29*2uܚo<^#⯳ŞlgT|  fWq-[w.oVbY/'({(.VL ƺ'UX5?Nrr MüM/|Mj̒ 1wV^_sʹ20SصTN$z%hd'q\loq>9rɨVTdT9>s0)[t2/ӱ7nyMI!pZ0c4H l 2q/Tnsޥg86mί@<%_v7Gc)8N=_R^eDL|Q$OKAEs8Xv!: ̻x.M{. LrynEoLzض7Gf]lWiv@pf mUf>~%; Ts:}gѥ9rhYu8;*UZ |9-'PaՎN'&#@[[%렗~nv+'#Ҭ A}} bʘ)^_2o \Գz zq\ݼR/!R&p CpBiWk!-Jsn"{eƉ!tzӔ%]_l =Eio¨dfQGlk2^7j|/yL_Ɖk`tg\KINp~@S9Oy E꽊NlYwuO#_zb4oǍ&)e4E9QO&> sm>ӹQ_v0rִh4yhg"8he䱬 1$ =-V[SOcjaeE#Py~X4rp0 ub-Py!p⵵J ʨzUK?mD+#mp%@C4`@\N)0Z# h65H&[*v";%cd&Q? c隤@;3y[D_)t L^q,MƑv@*0TŽVTY,ˌ!?NUS3itx}yF`܉yTyJhgC6%F=(ԅ sjvVR8s&A&Tp$x<8ɖMCaaI~;3!2&|K}ٟ+I!mUFW/'BfM±#e,G 4:IG"Zô@@QCSάB0TqI&~<}[0^d.ǍDB0 e,ݩB<o5Mͽgc%9!G2B̠#ӍY2YNP#n.ݾ4ekĊ fg%62׭3KB F 캫md 2AHo &QvkpC؆ݺMn͇˜_]$F uqgZVLK@,~1V-m repD ji{cecc3@EB枀yKOucl0E"cѿNOlٻHKwQ.a]L=N+Ym xLڧ0@kQ(+.gX<[g/ŏWQ"M+Ξ(#4`bi"x`ɳ{Rh|"+צЗ2ϫBnm\1uIt!_Ռ+!#36-E V֋{ dG9gqËk}/jVpMtŕi~ʿ+?CF+ZFk}޼{ ~w.ur\xJKODm@o:2a`?Rl:53|?k7#w"l'a$|<+errHf8iMEU*|Se(݁pxG~Q0rCi683)*Ӷ{mhBM%`ѡdABFX,{;cUe!Pf2Xh_:Z 6\.^`1ÖwP<^7vܨf3;ҪDR d7" FC_!csΒyb=%kmh%OLؗ  Q]nV&uEd%t9B?h2yfrW#knjK<݁4*?Ѿu@5f UR(D8 ;?mW3?,9Nj74 $;1_4ѧOĨs ؝t0Wj9fϲTݚ/1 G8n[#rL[m{Dz߃ UA-^BrzᏃ< u*</I!PQuv2?LvegT8m scfJXN@ S4TJͻVe^(A/aM2yn bp$Qe?8 Ԫs_]VGWǟCc,UW)x BQ E_AaFX7+}f3U9  ~HA*Nvv8DAbyUwN<ݤŠ <<&VeNrOeUuJvN |7_ HD +.x OE3>8 KF $Ҧ,a{!R{:6Ii\~gDJhɪ@ ;?a(iSz ݃5fsE۾'{֩%ju<^} GJA:hΡ5)^} ^!#8djB,h)أTaN C6?=n*_}4"LD Kfn Vq Ї5KNccW(]^F! .*6_zv 74u8u "Ix` Fj1O<*tuHCQ=бUv SSE5.5X@״I1^s2Btլ{K}.Kt&PuA!IYsԣwklyw[}4 @DU~wxEY2zP>ǦhzCַoI_LSq.|YP'[̂=Ch_z~7c*l9+6_ϛB$i ȌS re1V"f8 a>rRϞ:x[٭y-u1upOQɭZ࡛Sacr|dZ3lcoy︦hL,{0^Ec8&DRfͰ,׸8!cD`& ,zGpsfp"6H)=Τ,+QxoxD%gڒC}' Ƞ7אɋ9?Jm%bHRo9 f(Fn#9A; ~]۟%[qQnbbOfpńR쪸tπ$N[B׊hC0ìCE./ZK߸8yY'H-]LcUjH4+n@/RqU QZ3uN *Gv(jSOy(3?G84:St=!Z/*G(vtu`6n<;xdá:v Y rkCq"OO7'8M~fA?mr{T}f;f/nԝ㋏.Y sfOR\|;T_9{Č=@رt'ף)"Zq`\kEcG x1Á+kaTL+e惤me?n.(ۻqXS4_r:b\5F* ~ ["_%9= S7u7fG0'cP{#%z2Ā_ M3Oh|㺡W_Ⓘ$8yL{&M{˕<>/RF"0SU+,a|B7_¢d_aqj\W++ Pd(൵%t4wip:źX%NZ(^5غ. 5ix!$?~to ;z/+ '13qa0RIo}"^ZkLaA?lAۤ=rGis&VXVm |WzVPδ9>l.wW|q>)9 |V H VZ]jb)#R\m0,IJ.17SI+*{ʁ"^ ]R0Kz3\!.rZuh'W7i¤Wx WK萃JE S`M/Bi(b-FMqMPgSg[]N;ġI1x;SY?S~.۱6bUCB[Ϲ6^p93)P n<9CΒq`w1o 7.R'vY-;0+-+q"p/s q?҈EZ1Ot5͠w OAK\C@f =Hv8QaVC|Bd%ѧNrPbP5}RŸVx?Yl Kr| ͊CX6 b/j̀@5״ rJLDoc\@[B:2QBc3D)7n*!9V<v˙!m鬉ZJN#(B)Ywvא 3jN$.ԽdeC|.csZaPKJ]LCpӎL2`&-$ NSyj\Tt!Ky0hak,H-ԺR]udas.ͳc> Nif'07`#'RfJt77fdvs`]Fy‹~n0GΤtAr5pP8|CvXL.mC@eA|+U4y Ϡ4֤inhdK x53^V {[+j. w`DX  &T_&`F}#ye690-tҖ#e$L8۔Ҥ<@N}3F_%.hzX]"`Q"c[X(@^[,HBR3Ն)7 j#8.sD\&/I0dn[s`ZxSf h3k5#O@5 V\Jm,J\Q&/w B1C7[W[ޛ =m36gŒ&1EL#,`&kX8^D5I"_m_-#cj㑂6ԎPT`Rp`Q >ruc@V}bj\>xhZ;(NGPQVғp: 4m>IS־H;D>+nZv -mB> tC#Y}be|y؍( h7cm Jc}XKb!z R;x{߽u.M66W[Ioz@6g^&Up Ќ`|LяՉyܝ>)oT5Q{0` eц@0UHX%@qfvXG)$ fh'9{o=_P[BjY&8(U<\?JTޮuYl9)rq|l~ۼO8$]0FD֨(؆#b`/?@>K/ձHkCι }Q P1PngQKDUdo5unU\hMt/GB$]Ti F Ɇ0) Ow}c[+WЗL4#O9i-N9&'*ZsW~x"C2vd ޚ7XX܍Zji"jif)P=o QԢgAeUHZ "i[.R=!!/[_=3/*n|xV?D>}}4u;c`G?inO1dž0.dGڢ7#obEIK&t+6e|8isr\-z尙Pޟ601cQh I_"3DNX-ldw!VI^FȺaBWδI/?U- frN%jy/U^̍Ro!J҂֌HGG=_zo@Mr99zKyZ!P~u3B 8OFhPos nRhns#Wi$~kޛڼu[dǟQk.P:^ޔ4c M ltX"; / JchѬL$Okpd<`F=Sp#ձWkANѢ#Zc{ʫ| %u^Vr|lcGQaD~7+-rG0#J >~k Q>—FÉ4)HI %/-FdLW1M;q:'J5`rgmk,Ptrt? #gRy KEZ5M6¶Ӳ} cqt}gYǛP%NB7D.E50әV<Ċ[AX)P (:Yq /{yd ?&aO)n0#u7vZK*MBpPsdL3U.\.̈́ZQbIJ)|3"ዑCBnP+wt-)} {fZ406MuJ䔾"!qB'Wf'icbg" /tfsK A52z[%)*\g{lEFfJPBRz$sMA 羓h+)UM_l5.uG\SR7ə4a: \Rݗ~)C^:'0s>D;DtX Lۈyi)Θ!)鬣t1Ms_a.6M@ÄΛ"RM0m'vGt|zì쪍̛QDՅ،-9pSlԂ4ۚ(^@jȈ]@Q1x]?F:4zB׸̚)Нoo>R~Q\N0ay~eOK 7Zao}+-N):"zTPϺ1s4kN Ш|4vϖm(s87O͎tA5Z&D .%O@82)KX,]7RgeeC[L|3$Kz%HumƊSs'`@B[ ~4܆732 tq 8{UtGĐa%Nn0W,u+sf'aRn]qa^?n{qȡQ\NIxbT8p-i&׳{w%_TҬP}\ԫja"|t.X) U4DANT)r/IItسN%'l ĊɹP~`8C Z⟦bZ0@tJo ^,"Je}V¯ZΏ D7F6SY s/FAl/mIe ŁP>sEݟ'I< X ܫHĊrn|JNp6E2hE 1? KMo@O J@NY;b`lE,d5Q*('TVu=Kysr] t j]nt&U/5[#-lnنf^ < `n7X0ṜCkzW&+xW%mͩLK!P{:T[_Ȳ7);hLR*mިεdK,W%$KH]e']-y;n@֨$ 1`qe{X<\`C6,5&ժtJ5cAhz`PMmS=EQ۞{%; 릊Ò`NgEӸ%< ¹ L0ct&4< `_V25N8AwfࡧatJR鑂ӫBS{i73>ִWH;q%29yY{=sȑȴQ"{~Rzx@%tg^JGt%W7V@oi@ VPLƄ)n&x2pn+Sk(R}=GjM1+ M*+ϽwY_D\Jz9̇y:2 Q)߲%ɼXplOL'ZRs:-> eʏXrQYMFuyfm+-uzjx؀@';0׀ɯ1q*Z7`\P/3t[M1IV5b%2goF误ݺSKI8B7Y儱VGTU20-^.+۹OĀ6Oy1R Ż\'zv2_jȒIExJa:W ?0aq=zda}"Rp1၅0L6~ '`IoA!4U^(,Fc&^9,4#(2S =,2'.ԽNH{eM Ze(hNe?]=685 5,6Z&@%H8AmH ѰFG'샆W585X3>xdZ]pq'n]PN&bM$h3 !BQ1dWgT%QQZ%cEo'x(5njpNf%%U 3sٳՇԪK§iW}K+41i6 d=x!zbq#<4yMu\PCRf]3yO+(hsm)B]m­"]?}I2 *f*Kq萵Y\|R"}y{7`3 /|9 q"K@ mR1I Uph]0d$ߏze 6BħMv<ެǪv(ĮzK @ΑÆYqw"J16@NTZqy: }>v!=,- 8jqrY;yָr9Oqj3&zN9bS;_F]}۸ZH 5k21weJ/98بMI˝MD"v@BG2};g_Nd0 ,2#O|!'|IR*`ec 6]WwE<>,{&.ҘxM :MMH//V#`A%b=cܔlar[t> #dqhMj'DĀ.툧[,vR$ ϤD7DBlJɛ~mjBVmn]zAq}oƮ=IeۍmڄZcgjP!JO u5S?`v~cޯhJZ빰ƷsGM!dn?ڰobe%wЧo5%A_|w@(HMߙy;:XBxmmHmtZ<\fA%0inx Q0>ڍɳ5"j9M9gSy%P__H6ơ*͛T!ؒlb9\N7 [ʨ̫PNv%4^.`B$lr ߌ̿~TG>> :cvH7JAsJBȟj~zVKfwNu"xMe8mЏl) 5IlaPY.9GѾ\Kڷ3RXSn *8s%=ui/r5M\|h}̑IyԿ~.kP'!kFh;ȡ_$d@|с4T(gW?LpQ頜mF? g <]iDtw3{YMDL),( [w{onrxdl'͑HyX+@H6vM%x)\dr &ȥHҧAM>zu2bm$>DP ݫ*wOYhrQBDTJ,Tūo"nNQrL7s7Q(]g5!Ϩ8` [6@`.kwxUʜrcDy8E58GeTqE <~45ޠ9y+5`cRɜ iJlR6iRMӰ ^,D *dЌf/.$H,P0xVuHrpy~ #%JųSp#G.Mq.%@#'q#!+J61.I[>#>~V0U3il:mҶnx""frխn_5kTC=o:jD'ersD+㨉*պQB%KLTWοOS49?[.Cit,?BM%; ܿ+tmKMxa jsFE0n:PP!Xz'@빐ue mI1DmbПٹgޠs_J vZ@"NxbQ tBSS/i'-mo S`68e\<2!%#4Ei(&%\y {}nf>yWHiJGcrB'7ŋnL$2L'xӆŻN!Bwȣ!|HkW~I4r7~ZP?.Ioܤ3L q]I!Lɡ[Q&vE$يNİU؍e!q$S7cE/4o{sBW5f\"! f05ڗ$ Y"*D2B!o3q̝P`M^#tr+/կ?l4t^Wy|&2s0F9}9 ԋ9wm_G+cE^$ޞ~Bӯ-/;ㇾz݅L3 N%νOG=ډ.5Pi^ZU`&R f<I=!EoS2L8ۦ@)x蠉cT㪸"obք>h/#JԺ<bJPQ!D:AV= eͻxhfBm!*5Z`dOԘ@aSaVu n;:"+¼[^\ >uPsb7*e랡w@hIıFh%!$d ږmBS& o+Cv8К{]ދz)U}Fva]3ֈHٽcKߺXr+G#u6_B_6l8?;WWZd運~rU 塯|mu"qK+YP?--+_CDŹfR39ffGQZ / G(G)N#V[t]DTѣ|(r2m|2h;pE.78# u@Ϫ7E.,%G 7Ds"}SVyMk8HzJ.NaÈ l-P$\[/3 T.k:j[gza;a)ub{^I+mr}7u90r_Nl\ 7~e 5=0:RE1M6/]8p9 r/6̻W*_aAd3LU$0t+/%PG'L5q4.VX(7ja.Ln$n8)O23K߱GǞk@K6SBPwCl !P#Y{'/UHEp]!d3@лbO[H`; lrO‹hm\nΟ{:v{/&CxGrIIe5owm SJ*[WA:]r5.T0L":;d]jZ8 [e| ,[GdLcEF8۬*~e]q#{S;.2ue%ɂYjq|iz)q.`}fk5ccΘsĮQHTaБU-(*#mKՁ ZQJFG6e(<&ECqܻ -g[! ?tWh/"6/{&/eD((>?j|fr*^fHs7aռ[RK/a<10IeKYyjeɗ?'p;¥HTF C|=8hIǼtIַȰOŞr@U~teưQ?i#<7;[D䳋D-QEa}'UG.4{-y1#id#9o9>ZɳA/@sj VOV}vwUI-GyUBo3H"5xa_SHؿلb?Irgw<5.=$Jq}\Uђ'jZIj:U4+T2ƎSAӋ2C5RF [zª0Z>yٰwG"9J&}ŸaSmSA &Yқ0?bCM?1binYsfu0Q$q\"y9 =n~0;< U.LJ!sk][4,cϖyFk 〈dIⴘ展nkS̮`8EZ2+$W^"g?2bgXOP#ޱlm>\8n`ư *1}dވ%Rvk=eL;(c$&@cVe6gXn8BؐIlZ%ښmÆwv20^)"Fy(m(%杸Fcz[=3%ļ؍n- vVZT)lJVk#}aO`Y~>-<7U!|=:1@9D-(i_:I{o~/eN8[>@7OPsK*tNh/fO"[ebqh b(5%EZJxW,wİnMplr&69٢U\44I+RU.jf.3v=|)3ʦQF6bTW{7px-,%Qݨ%F]KN^. 3SowN""'7K7$1}p_pN\PVOpʇ)5XZWt|e M{۝H\H93O2]Ҋ *(.0j,҈fP<f;MȖ*Mfg҄ \ܼ<.G_P:zHRs C: w&|Q,zۚ'' 髈4R;RvJh]_br +:=J~|Ui#,wi"4Js3l%a+ Š)4Vh9LBj޷ Glug4fªE肦Az@Ze^~& r@4#;7\~4;թs?%(֤ .P6 a|/{KA+f4`TthXY"=iZ3 B4z6RDz3-(` حL!~h8w!(x6K'ţC?(Ë"AoBvB]w[6]tzt%(i,5Zԛ8?dJ^J$I}3V*kDW ;Xh</Y KR 2a~@w3}L\AD1"`Y%E^tٹ3Ƙ\LmbJpvE<هuES6BC P8G3˹+|"͚VN47wG$&d@gW(T)Sg0(`x L$4'} VJ#Yp=O*7_,V#[s;qn l6&> mz &BP97L ed˘ffGaQq;i׮/0?[ 7-I~Ԥ;9>w#$ zWP~в80Uj,(>a{'~NOz4sP ?rRqU9is ^<%|3y!g,FOTKU^7 h}49~_vd~"*{I'^:?eYBxt$EA%b#0 K[OCi r~L;\nʱ)BlPRGo28,Ģu6aڤヮ BGǴ/earB1}BWZ t5Ű*A;&7;mVc1CG;JZh8ݝFA&%L r 8^ UYb^0׃"pIa\Ovh@]r@`^}ak}=RD*vs+( q2l#AP(IM2v1d%,<6(FO5ZK%1ޥDqwekch+6H,2^~'溰ˢҝkW[Yxd~h=|@q|˚9 &VއgM.#0 4Mi?=NGV2}6+v'ɫ(9ҙ3Ne|I}.RAp+$I}u{bZVP]#C9{box2T̏$kuP7c"ELd9\ UC1Hf<$FSπ&[8s o Zn|?jJRA|}'wې%ۜIʻP*zS ϲ[Sn &0"'Qcycɢ-E ؕ`wamJN%ח?} 7Z9ۥJ歓 rɢdlޝG7>U&:, ׆ʭ=Ѿ)e2X]ܕ7-w荜W:>9䑙 Զ<瑒 e\v83: M=k ;r FB:,U%&G]GuuZ`U4vQo|M7g`dn?j)Iq}gvެP)F02G%Htܦ@ДȖt3 7!tSݔc *C gD[!u㬜c14FhW:[7S#{)t!H1(vڳZ sRIw붶AD V8H9"()6Vd 1W/ DOu\"(|+]Bּ/wU0uܽї"42ez,ޮ#UQi_mP8]U5C4 n߄!HBqn]s js]vq 9TԈkcr,wWOwjf$b%?c9GBD[WR 4. *x1&H`'A9%ݙ6 ƴY{O2t3^Y"tT9iG\"vn@mҟ]SJJ^;*Fq9X*S*ռ~ (gڵ9]ԺwVJT8&^Y,ȍ*V~U?z_wgK#b%X:bhWh0OTKK,~"N\+vMb 46 fW [`\6dA(iXpuX6UV^ p4_+5$s)hWEPH}5I*VEiq?wt@}XЌ^98$T|HMN}ohm&&ON]çd#c~\3jl$ d˜'eb?`R"<||4'G*R8fIR|Oyޫo\ܞc~;yt$/7ʀ56nS=U3QHm*hP<⿳lb6Uς#^dWnw4"0T`UYMhCw<$ҔE ^p'#eRZ`/_y&0Qάg#=||"UAq촀/HW˅lN":ǻj'ʘzk,_,Bew24f /WvMAeB浦P u[Az-4 #+J4uNly[d(-Ȃ Lb,A}:¼S\(XElwg;p@/95*DJީUy) C\ &{tyYKv~~Gn˃okYRC'ϪA. Lчi;/)gJpD)ʓi,NmӚz qET 7H5;egzۻbmƺ(T8`ւpDAѭpyvÝi<ׯgqlԻ?iIlP/~T8gTrb +fNjLKFBKR={Ws>*?Ԉ7WFBz>}&x@n\m*ȼs4c}g\R TY1CMMueR'~gl :I*wXeuУu%pp-&߭"=v:pqOF-#6rDM̈́%O5)H9&:rIdf6Z78km.EP?~>hr O-pRQݺ:>?{)uϠ0!ʛ|f-9^|_,p(;" v35(u|m]u&RfS/) ;(s@% m7|uR:.QVB w s:Dq3H Ҫbi38:t:ד?Նэ 3Si%tFˇ4+'cXۯ)%}4 0rY0*9& HX:O΄7Yw<Xp $yȁp0Ykn5E._ԏ-?1&SI2 '̩g@kb{h˨k#OEDa_3è5CM,7->;k7xF):x ž2fFƖEE,FzjU#D *7vDjb愈|hE|Bp^ZeqE-1ɳ ko߂.b$yi ѳ'z#=i%~ǰ*\ER-jԺU<3kg $YÆCJa (>}XKէ;IϞ[Lh20S?JH/"wo\@{<oS[6wlۑrc?*Lm5\ӄ7#ҷk>QB%#+#iIzXA_B/=[0<̋Gg0TMW]4qU.=Y@psU'(cxDs+MXUItu}:q6DvUB0ȜJ@#GJ  -Ac? o_"9$'UuC`9G{v#̅ JY5G*˦9X*,I0˸ "/r6egA.90k?CS3B캭0t\ВxDĪ980b&32׆B+_.z /+w!q(&90jk=䗶l$`ƩM&@v ǔ?=M_W^W_,gz4Ν=[5k'x0n5-,w(*m; ۗz[SՀ2^ϗ٭yvywv4L@݋MҿrI78ZP_p2"vF0`7, *QbZTh=0f*D3D %.ZC!:N\ozu߿yVT")T~_cy,B>ʹ Ѳo7zWhU0h`F1>ۜP+{{ƍiʼn&G"-l& C8NQČG)hh{l8'S &́%y{Ƿh6o\g g 5a#{ɁpM xWҼDTd`uL4)&tk\Qer>DOYfb!1(ܯB`]5rAwqh$U|!Ag+=JYP+KRv(ZÈB]U{͇jRKHnO*Kv'%Vfn3}45QC6cmP~O{,D dd]33vX4"("7P?.t[*^m$& :ԏ@J?5b?˵kk$ q@;Un! f}4+J @@n]ߡ˪_rv|6Pi=q:/̨۱9THqH Bz%m28*P`^PF['E$ ٍ^AO>M g_K;jthgS_GNsە`,ARZ":jCiPu|#A-[bvΔ-W?xl{Uy]X,9]D)Vk*q(v1/*sqDv}`tТ-ބ.+Jv̙\q%VqŢx2o$_:J^q$"FU%nLܞOS 9"qt%(|{":3cUflaV TMylY~el}mVLwBB3WPꤡB[Eا9v9Lz`corw`o7 ry;!t:Yi»,xUi'݂j(boٛqqy>喚L?M(]^0Rg[Oml6m_A &Wh( =wmԫ}~&Be3(|b lW |3t;D>bzYITr,qy?:e%m ;>3"$ 82t(|Ԋ7׊&fU:^$y:haZ\!=E` Nr}0SdxyJ YN"~*[Gx w i!{R|e|P뿩V ʻ"L@_-NݲAKgUNsoM5>NmtD܋Sg EBcThfJW66k,%pJ6ORCrDlՈMc(/?L:G' 'UqWqu|{٦TUj`wG~ڲYZz4t7Dh3 ڌ;tCvXPt< @ tSt\U:a@0qN.Yeoa"< F_Sqz ?'dL% pƦi)yU[B0Ks2KKwVWC8MV]jS)ӬN7o1DA F oPhe\]GRhO.eo9ҹN,m4rDTcLT"8%iA]S,n/}%f o3Zۺ6]Rddb2'Vbq: dm'i#=U7ǶW 3X`q9Ռ~zS;Fݯ9n;(U7f @ "tɂTM!4AfDaw-K׭hu9Cw0$ػM=?@Sԍ xݳA'"2FD[8~!~c ]:OalW{l,ChzyB%SRC Tb ؿͮ_γ@EN; Rn4ĉ1=CJX.o}?#o/ l朗:5}.bnh5۫ukXQMLZB59BOm~59` /&4R[Od^9)bDX> @`O^%FO0֖?.5uTn K$h(|f_j:3Ij?}xۂIRD{^Pjs qM~c~3w&@k:Dv0lM&89? 䎋m,\N;q"6pAOTRr?"C ̕;-sT`T ?0)C:1W/;,ve# U6hQc@yŪsۨ, - /tJAM}袉q5,67#t'̅*C304*JR"b/6aqaey'zˎpSkE,.Q#}lNdƧg2Q-aAR(F)8 A3Pr y,ⰳοr,$qҊCa\ef0qpݸQC=(daE̔ zcclRj3ߓʺS)2ϋ%x*v;-mCKg{p|5!:o&9KUR{ڭݿN]G)/-rI~ݪn\h 3F$&ٔ3Ovc~( I^/9d2UrF/lUB K]QXurkفHK߽GץJVCOqe,TXXVnիy ^G0h}GX}6jߑEȢwOkyMh E摰CC lo JInJQhp(ԋ^7_Ķߒog i9=}*Hi׉A)to KDWHȾ |R[ݠaK]M1bs^es!Něn50BQbvݖ3*Qs4l:dD/>Y*rjn'hВQߓkѢKqI8&t3%thy~gɃlNv!BdCO*l"kY˜P1/-"X_:=&pآRbN~..YL[R*1K2X1p;)xӰ'_=}a"猍\ƈ>L] ]zsYEգ._L߮n}So*}N 9LU^cX#e־Xсʜ2HwSi`r{I~DO 8AgQ^&^5LeXcwc_2+]7k!TuKZw£Y¤M]c`} a`"'>WjF_gVaAa=W)E"`vPDۿʐpq%2-'\eHӉK@`:!ׯ,*3Ցu!O# |nj`mpkv~e; ޓe+4 ts.02^eoP9V͐Ԛ/69?Lւva_(sרEۡe,mv;:ŕYT}j&)mÔ''>zF:$}U5:DCaǠNd\Ijޭ<7.lEнJxY8򦀬+Sp:XEvSpXt;AA].F@9/j{7*o?s^61`1uFё4ڂG%i騫eX,::IbIW~7hBH+@j9סˇ[a ŽRbL -xŧ0LP\,: Ǯ3GB UJ,ނE-'߂O?{ECM  *P Z sH(|&MqV ݺɇ1ZnP7ARLVjJz:v%~ӋJ _Ĝn y*T"G:m^=aw3F.˯ s6&3&~A|s,9&#id&C KIqs2C'TxJtAGQŶ֪},!gW4">/$O15E>F< ۻV*|bjMн{5 x!(Nl=յ"msFrXËG*?\(?/ `ap--.T)2qE#Cx(R?xQANJ9S(d(h|Gb(Avrx[[Ӝ`]|("%8՟VN/MX\g`]A8K# ancǫFDƣHЄ=OSB$|VD_T#`L2(Tb@||4:k^;=WJ\iB/|S:_J3)!bMdB)asңߥ] |\=uCXfk e v^b_ kJA:9Gx݃%A#U8P Lu=b~3B!>lG5v:_S] ;3in.0N^b;9i{|r$_NtmWg+3ԃ;Wpe|$r@.9VDXq:e`6]|4 +:B87ұ's3=TۡޭAoz/$}K@T2Fs;ءR4]Oml#zQJ}iȐW;H"fɕr R"Koq|o͒pZP>"(QZ}k oJo c0W8 9%z Zx>ih}>ik颓lڈZXH?ق yb Պ:8b?ަQjSس( l{ZJ#`QUä4m_H8矵w]*~k9*(w;FܚR1H_eL w]FYmU6uC3MSGOg"$I5#H0R[f9ܷ}1V8:'q*L3\lwq ,OŪـo!·jOI?UP*@<]mE@ ;/*X}) 弢2PkGѹHr\/ɝJ U)~E(qR`>E$Q vMH+%;UR`YVfAZl˻ί YԄ[P| +85KZ͈LJ{t a]$H1c Gtl3̣Kz|VV uQ"B kbPvRT4+j}ga$̉XB4;8h(Q-wC"4!/E !q\p evCV#w϶ܽ5߾թP ̮xTm&>(^?,d!{U+/ cQnCJ_.fOl߳XX]> XdTH+! HLɊT$"R0yεl҆N&Цvn۳41]sãt]Rh˞|^48QRK*~Ŧ M5cD16̆}k jL8$Vb jAv6Zi7՟_L1p€"4mE:ٞX]hNd\Os̄D\\0V X'GfG#VE?̃ 6u5NO TMضQ.ZЌ9H881jxe11jnpx ߄yMEr/ pwZ.e*ͳf: NA0Z~T*T73f,'N,oyemKѠ$fb6@5O6^NyFA9Af_2P]Bm _{'rOU6ҌYZ4xK(RI7UC?d :zOqi,J) 2z␎ frlvFtj4E&kHpE @V3.2Fs HwOԖQ?r]Qk,`GD7yJ:Z]sb,x yeYK buDv-^J̷W*k>@x6=͞~#^?NȻ`i q2Uci+磀t۳t.A(.} ^VYY!p#eXfiМy:zQ)@DgPl`&L#IE饊Ua~MU.9vGұ<򠂄s;["{$9= (5%ɛRp|c=C ٩0ϪCi&_RJQCΨx?J-pX./[%#N^`u7ԭ̷&c#C}2el ljnzFקڽބtKq ׾ "iO'iUcGtĜp6FdUSl>uD~k{Pbn^)„$FW絴+A6US~V[>ga9@瀣q)VoBީ8.~ i#i;<~{9K6/]Nc=jm=\=\P%u'f8tMgE.h.裵c6J؉~N4G >P!jhQzޔOʜzB{tIN9X@:R~ϡ)Gz{ש6Mľo'z*,mESmmG"N uo"MyI5k4txۖbRI69EƶDXWRG~DQ%1KnӉյ?DMrwQ Jbx,A 鏕bⴡ>vpdAdL<"Bjz{f >볰Ic @g(iw`74"t-wݤs~ndb@fg5u4D1t+?Iɷ1V5Q#,%R_NJ_Pif=^Y $Q@QG-uO7։t;jF#88|O׭n^_Ve`_|U) IedRIVlfK}8(/ߔ&#+L{gmu2y&Zb^6:,Zmڰ~]PTE=PZ BsC!&48˱eb4њQx 7I\jTeΈǁG lmUZ9l.CB^"ZdEM)]+'tM `V;[k BD# ևYyL bdfWXuH]BZ溶#K7&9V=rUk>hROʼ3Q~:=EPȌ6kz R/^_f5?!~`HdXËh6R*t;4>P*~zߴǾم9:)D$TX9/PvÉH&aN},²loIl2TIY{4r9 SI˻ Ԭ #*"Zwịz}(fX㧮(vz\#=b@9s6y"pK2b&#ov"9N<^{)5'sװVtQr>fP?+i|P{/u r"2TD ozO 4đhxrR:3vbT%!dS &bi`2~v0njMxsiFQZ.~QA7ѷgGq@ʶ"5+/4ÍSj]'eWX2b^iTI-ˤs~:}*aZ,*p7l_';F/p $ nnlWJl)C u|05V`uFZ3֧˸^ĭdwB% o҆FmƇM @?n4Ix1(ӁOrPjbwʍۋy:x|/luQzҭCu=U-G]/8$/,q";I~>yI f-c3-ܪ "vd[-uR[O@>CSO̡EC(nƮeF d5=\ M↴şY">{nLAs&WAa4/q#mY""[d+ec"LH#z4<8" d geKI5!',4]B:UʳmxA9)W㠙$8*v{0@;м $4d3*]^]!e&z 3t5|P?6sz3:t_B.cdHnd"ln/FݕńMk bIC^Ox8`8ѸsD&neΥ|FyW'8HA 5$sXu@d[ UGᠥyMN(³EFkn =9"#U}M-L &LzL]zM3pCL&,lr? 7$R*o)4pɗ[~F)j4@,Dpypj;*5D/ }- YfHǡ|8ҵ-!t{P1n0K1UW4f=YйSU8S}=b}޿V96matC6 bDWǒJg9UO|UBZrbG?I:Qe))~-GUʑYi@r'&m`U7(s['˾I/oEǭqKz8i` XcU46=p3n/,4==P֋ui[9ph#-!tw'9[sДү K@ڛmz[4^`x35Y$_mH1[, 4i'}aaqaa& ljC7[\8È8tPt?#:EM\_g7.1oFҎrx$BH)vEyp]v =1Ɂ#Z2 BYzn 6Pp{q{2T7ec܋a j.g (W^qw2G%])S%}G2 -j޲gʹ#~"d6ƒ7~늈bh1/v0t'ܱo"_!WLQJKcרC!Vlދ$gx"Ч` & PD*}9(&j B!EI `F4#|F?D?v=I= fI! wdsԅDlGfyR#~|Jg>V>S}ٽĒҕ}b׶>jhnXxD:1qE`PwX$ZoȵE$`b]ΌC"PY4A -$K^lPcMw3՗mʣ"\|6%=WǥQƿTyqXsa ~a]CTסYQ TPh;tpuu=%/aIҤodgʭ1aH0YU/= `ffxvwasRFl?-)wSIxK?_ldڝa=F 65' >7F+# 1SSW(U\|ηdxx:xY{n;1 %M pf܉fDal)҄]~xf{egO):>謆x&.Y-p}6Ou:kwTD g%@0&f;8y7ZLbW(A^~9"c_M%U91syF,&|SR:>gI!PF3JA;eZ1pp:w۔pc˹IML0U`vEm&Y܌*_ ]ޓQhgRnJ,MK81dzmI^+u nVrtfosUv[Qtp&bڅNg;eE"aaL 2j&k>ahT0D^ x){.-R/X5M)r Dz ].i}6`DSlQ$[&K I2dBRd~~,TB0pf@8M*o{ʏ") QWDA/r!`Լn(`xf)-+5r\utreZkl6bbP$yD #&p3Qn,{ee1A0jVH9@{@-km|{c-qpuԺ\UKtT0A9>tw=k"e@a+Jv65I\|9ҮD9XT+NM[z2Dp{ZIoZj8DXPڟL]n3Wҷn,Y&}X/Zz BrӖOl_~24fHA[+7{!!X?u OQhmgUA{ۍbëTc7sbXam6^Bn?MgAa,grViY?n:@;H̕ޤ|"n˗]{h*wR'sXVw :?ez;6'w ~Я@L Nɼַ/|k9ΚH #W=W5TaK+?ko9:`]f76YwM׻U/2"AfcULj47>nM|8f!4jx.p߫f=G])4v_л*Zv@v6=t~ipnU 2NIymCO֚(0**davU˥F)`D7c@^rS Gѫq1|Wq"O4fmg'HTPІ؏CĎ.pG7M`v Ph4opy x<&Lxen.eVa_3&Yeqfs wyb;ni#FmQyO8XdM &Cs44gho!,疋ruEyn6(4F`xvlެFnw-Α~mLF]-67?=菶G q5 ` żI02 O[nU?NV.)|Uݬ&#u'b$'tXs!Oƻ a~գB܁i- dk `e<Ղۤ0T\y55 Oe51$^ wpdi?N<=)4ťoNOL՜ ^4 =RtY7݁[W )mPu0q|ԲKC0%X/^ o({-T)7DPp/PUZ#}յ4֚U+UCh!N;ݯ_ID9rPđ#,$8%`xTY)EﭓHWٞ&G0.sEYbb8Em p]Y#sxXElnR+4oEH`ܫP\ #(T y*TP[<016> q}y12zU-l8#;;KŞ+Gg8,OG ל|4C~! ; ~[uoP4z~ Qǯ[D&"Tc)I2_`2$us-.ˣhU7V:|-Ztj-5?/i3+K-i\A(0m&/]Yh IT^[ ʅRѮJEt.Mԫ_Mql9Ha57 NIJ#B|~%@QA, r2&}x^%N9 ʝG\x\Jx) qӠqbmo#oӻX!B^Whw@OB[OCq` */bef2Sdo[hXⲽ;J%h~IH ?f 8tt˄Hr,Cyw7 m\1ARy4@-ر54HIE.s} H\7=9lߕ$ uW6f0wO]37 =ɝO%>HX^9%|:7+>oo9F-19bPZ{V*:S@ m8rw iԛ IoiJ-7ŬqE36m[?JwXBf 5A$B& k:.CCHvWy; OB{ +^ Guw6o5$IRa `v6oM |ko:&IկDѴV19NJq4ԺiMDyHl6;ʠ0,HE66dgygqE/n;V39=ޠ9b7P>ׁ[6`yie:ubSQX :1ݵԼ:l.jnߖdFHP7sudf\v J)2im}źj> CV@lMks} Uxj{9o,?ir9 =>MfX Cyt Mu`+^b$~ިuLpu*\XafNsEo>ZXPP>02D>E_ WTt?r "F߸k/#) _<<)/kSC HIxh@n#(XD21U//7*>L\(K;80n\^SB`cՖC -Rw#qF퉩:[m1/km.qP,P;!-$j<֋r|(u4V?Ptx\c0Ff0l1U~Ѫjd%6oB>"a#2C>V͙ ͰE ww`>5vcc9~t +TJf'a ,FcYk Id ޷W{rҺ}eӝ"b]tY}tֱE!x\ +. ycIcx{x#7r _ogR!N"0\@K[zmB0ZveG6LZK,5mJxf/5 jCw7U{s:_w*$ JYȻ8Eַ[ ,yD }) L.ۀ_[Vt-rr.HeO)KD_#f64N3V`ʣrM @%3IBpA\_57}T}4,㬝mjo :xCT6M) h:'yҁsU5[8ƣg@\UAHJ0;x@b KuOgfrnRc¶OI#G#߅%_t(zU<1\K\ =To2cfN"4nր\ۨC*\.' nq+SXJtET?#qwZ;vxJفO [ג]AcRLm;s%!dZWxj{lFZJZ7gIg2 dh2}l5`]FJ|DA<K>KDچ- .pH\,Βz"C*tx\n˺HM k$Z=N "v%ZYn{L󻱓\Rx+ Ȩa6Ӻ -e=Q1-4Q\y.lД1r̺IRextЛ-#2a 0<8Pp B/ /q~ 8ݷ)M}=pUuм*[ddW&g[oS0n)^A-Co|Tmvi矿X|h\Ƙ1KdY=hyNm"8`e:n^\{(GCbn,2G40^%p1ʒIW;nX;BTC.M/@;OݗVߗo ). \3 ^J^4!0Oměd|YU\Ḱ+bVEQ!׊ ҃I!S&#R3beF|NY3vʰWT[xX4UUSjPOS(Q6!'uK |<^2$j$(eqG5`Aa4+qЇk6>oedډHk -ZIID_'l2=FTp7nЕɩ!,!~7iKniCޒ!aͷC0bL`dؗ3mhغL-RL>jnHP<=(؅17ؚL{b7Y-`B / ݡivcB p+tk1@AЗ |5X"'[~Ve}{@R' Dd8t3D9HsMrF1lJŔGQ|Z{ ("&j(Zϗ "y12Y?3YU?_?S~~75O۷*x|2Ʊ1t[{23Ŧdah479N4\}b6eޫ}ߦkUd0UVÁRq3{$a9CEAkdŭo;ځ;.[r뽛5gP=SϢIB|߹fOw)JC\6; >yq%,SG5~51N-A&3k(mK:it.4wJ1SoH)-ߠ;9x ջq^i$n)˔\:T_Ԁ<)ڙbZ"*mfVxw2`e]5A-"S O_D(AΧgxgDף?un$z[QQoS7(aWIH/*ehKMqdW5WE-ۥN4ثˌoOJtP" ^ 0 R0WY-oQpO*>ɯ;F;fp/f0Kf0L@=sPKcM%< ?l=nzsc:*xٮe@>cVkYp\vn yD"4$ }m,gbU yFj*" c2~N؍{r`\{(fs%9r9pn)wHE©v{j&&74iD;NI6fB/q7Em .yv![(K iWt\YOAƮ6zxmxUq*C!+ {eH5]љp@:쒃6P[D m1Wd`P[K|$-[P&QI-" ˨)? Uguj^'2jUSb8ϥD.aRTA P@5>i]X7_ғ;RݤJ TgDZY tNM/]w ь8UWc\e3M M=8FU_O&`1EɃ@5~ ]gyq'߳i0=]b6?fOSd |FP~v)ⶅ=qLxsit ͧngRNt8a.P;|s&/cY%iȺvRDA{kg vdlnaLWuZ_%ْ¸\L=[R~+ºi.H=hHK@oT]cu=ܢ:\C/HΜI|ICTHW56.X07 9.%QGWc;Aٓ{^G@(<KZ6AhLl>}*h 9mC0q ABJW1n폨/3rWK-EWGT wNSCe_?(-nUfkm&os R4ʜ,8S<ޕG8:,IU24Y2STF.rtv,N⥍7K% !h2y\ЖGΪ2C ErC hע21e`$][0Gw>ًU=WOW w¤0ˣOHTOLkd8e⑻ݒ " GZŗ[#- Z[ B!)qwDxjiJ78E%W߄JKl:7&R65TJaJz3c)9R#{4LW0xװ׺#w%HGPrReEqGhD* 樨Cly ,=;A^>BvKӃ%򪛇煚K3گC-_dys<]Wg)Uv&;fAp %Q/ 4ըODt/,)@ĆRWảC7NJfiƫmz>B r+c^GAP Ic IFGicFY +j |"Br18SХ/ٿ\ 9]%!c_)[Eeٶfo5eZb&SإF۪h^e\k[\8Umny:goǪux&&333XBsWebDkSOGQHa`B|@?x;OmxEET?KHC0 qp9>VtI%lQs mz ;n|bupz se˜ͺqACf5b I(xm8|2,_) G%8/nxG\_^*[[+]O/5$>KJfJ>"j(8J*=YTmavw ;#C7;Q1tӴi)[DC77ew]{Ӻ = ߅f3P9yƒ*1QG4N)VkaCEVr։kBOafz$2$Pk6%[e̋(!*& >qAdEv1AjEs_=L-uv,np ٮL dvrq~v'vSnfPAΐ!= Kݞ&f3{zcmQֽ3W*>8kBO<^:m)@7bk͹jJ*9ɤ:RcAR|;ℴ)7 ,n1꺔ǽqaZ ܍8M#՞x {= tAO?Vb8$SYj? k :Ĭō^ĢrajKuNy2 -G`͝CCX"w\#aU)]cnJYǐbOg 8iبQ/@hvp/cG& Y?q&1 `>!ql X:tđ_r^6<[z66- gݝf[9 $Rqg~U-`YnX T^_odOrDD'+nW>JjtaA^ Q\ DQ<qg[% w+(U}v.Sˋj,`YhJZwhaoKy'SuNKkI,\9 2MiȦ};]0Çn8iEJQJ9F;8$; {Ɛʲ*NǨ^/ ]}xJxĐ@'8_LXd }PV2˜ !{O+ҭuuޢ7iw%$S30fM}[Fc _IC㤄]_mven.w-Ei󞢁%+)ޥ"N\qI Λ!dՋ,N<ѭ3a]#n{'\X»Q  |]* mR9G?3:ƪ-Mk: M@ozov\>Ӂ}qt߮Ӂf8JKW2{2!$-pzܿRRgMȥ~j2(IW5^Z[5]H<x}/l3<5iPC&SGw|nSuB(ω¦aX#>Fw,l~WKXQyeXrt}2gsرӶ%hEf/YPD+&vaKPR?]=(V9{:.˂m[n06ҋٰ;Ԧ+bbh:wi.IzP%CDKm3/xC@б ,cgz> zW&lPjCBBsou$bÖDi繵`z4Ur7HW$oe% 9- R }LꮴMw맨 Gcj";`auSUqLf6ߧЖiڒD"V)xMg,bȧ޽dX'"wwDҴsbq#7^啇 h2ӓRjezO9_ Ok;)/37'nonZFIqhƸrrH IW%[͹M#SC:Kbǁya/.,cݢ c nD{ڦWֱ) G|wUwLLJI-'q{WZ  Ρ; w]pn Cˆ#$ j0%߀?CEf(XdXоuU=Wv~ܷ|T}\,03bu㫨Q`6<½ɸh ũ,P'To߱w?ܒF>hK"r"fRcg.ŋ@17 &ɥ#e'cF&z\ AĞ^hFk% N(Ҕgi@_p,S21,b[#Ui&f`q&>1n8˨V:q@nNsyS&oF`vש?2 Kc3K x8j5a^ 8wkً{0S ̡v- tJLx*7<q)D*zKغF"&Zݛ\Zd#*rBRz2oPc ZK}!$i a=3r FX6MVxQ d87:a-#@&J073FN%m.Gu_ᶦTl0ix,'sGoU։1_[ ]GU\:2RꭱM<ƙL[e2*ٽ D~[IJ=];/~CZILG+ԯXr&մM) C8. ˋ"פ4N5ф@,gHC^-5NcTMPL<^07ީ1%>5:!էG={&1A*J#8~I60Q[՚]'!sWA  G+a_Z$ ,QI=yBz@`>>gOo0ά@[A5JqFimwP c,ұ8PP21xdx@N4 S{bwE̴xT?>gG >z4 Oo]f#t(q`0EW[6 irU<p\mbrh\G[VotM3Ao"T`_ kJW|$]0M?4_oׁa!>"j3bem @K^NQ]$/X\;U L6@d-UޛZj$<7)4ytRZa_y4@8%iZEmö3BDj?}-mNC79>EJ&T-ƶ< ur,X|xqR M@$fȍwB)t/H=]4D/vY_ܠ 40fA^*wsu]xV_!EIFAzȯK!+=(uqd@ N g4-,_3]I[; K~i "|Jg4GA|`YwklZɖwmk陨|]Ct;^qEGHK})QpiEs튝OiR~8RTpުuҘTR 2`*"ONMqyVZa~[09{L:7ykzƍF`hrfN۾X.3h/? +R׃_?Nq(abI^jOG`VU͜?o dd Px^p&T tPk&4vz<p:9Si{$(672<=<7D=&<lǭ]!Q }=l@׾IYG)88wntZ: /`MWDwsOAyiAVCu;c`n+#퇓T,i~FVT=Ltl`E%I%8@?Z v[Jۛ-B"5}1cWa, z\(^a\&o6KUTA~ p 6>-z/)QUBY vLjh!]-(uS+) `ti¶NOi$nS(|{/vU2HB7tf@`>}E*h+ VwBN&?Қ4 @,)1% ִθv~Cm9EN.v}ѕ^b c ;U[w9Y\gJK]͆Sv[vZݽ)9,2bL';;Ҋ惰̤)R.0 ɨROv#X9ZD>Z#CVҧX5նTkeV~V#q( mbM!Gu/ov4Erǎ'"=5[$EΦ>6uUJqwJ[_! AnZ-FA w̚渋,iX31ً. n~NQ-_Tڽ.Ie&vglgPEϮZ?sHCkbPﶁ0I,}]hx(ۥ90nxxv΂B ӳZps f!U"m]#L {;9w<Fn70 1\:e}|WԂh:\dI@pA4NѬ$7+~k'_W -*1[֟D4Ju4 Q=Y Qޭ"Y&+υqApjob  %J͂ǐNf;5Wx|ugPީ%z80~'d.,XNWLdTfI\N jM%5yup_x]4 L6GaE0$)*$!d|ΒɄ^fۨ".GC-3qa|*΄SrQτ.`X!\gB.dZ^RYK90ݓ ks:r4EMX[svtQz]{篓׵ytT> T_uVm޹.`d*OU e-1\AtwdI{_T.OڔE>O:g=/"5};3~soWxݠ(|J2D^,Udl9{JW7huGS} E{DB$wq>›>;05QO-o+ψ(1w9[vЗ@$C=X,2Z(CY=+"!,+FLBۭ|#LKR[ٳ{u*<)2/|jZ=&M_@\Qٖ2풣%;2پ-}BdX<桂D!EkMi%BRѺʆVwlKﶁy_t+YuF \ޟ;qFwg(&;cib'Y6D j#]*-ViF~/B^c8:u2Ёg:w &8aV"|&<}--Iת|,޻MHP N3w;Խo|7ek 6Hŕeɩ;1/#jbtCsGWVH_N;߁E>oNSTTFf|Awt@I|"D-tidO?1ۗbzu=ټC.REo] @_F9H8#mu_j<@I˖2?VtnwZxc&8|ͫdb֑PC"JY/e.^d&jcQ6ZE57&z?ε6W hy݃7(;]HOG\&]z_M #:ϯђJ=X{pfi.aa,%-W]~NKhAR^< ,19gN'oM` cbVFl=!5"9|.-_g4;`:}k)zq!HA8 ^$}\p3gm钭LK! ]J XhIE-CgӐq:!#-Օv?z]?DuqB\*VT&̒ɑrj^ݲ",^KaթEG'{caәևgU! TKoE$OTJÆ$aK"uT./LL,kjh0^zcx5<΁dy$0/VYÏgZ~vb/G}w}[Mb$*5 uLRأM׻cY|69c@>0v(@cW ;ر4(? 61+Y2_Ƙm!FNO*pL*S@En9h< ]1MtCuGming)tݠ^65/:.\93yS2>ƭe ]*ls]\[29o:v'L WN%IxyXDc0}։+'Q&V喓¯.-xBא7 19藼{xUȥW |'|ý.Ӭ'W`sF^4f)MUʩ36wLZ-FMjE;z$7b8 a{ݕi6Y2/3~Kb4rEoOq*lgI$l?6hh1\f-%O.8؉" V7@ꤸT7w_ouxrJXoం ٖi 6]ol$mw@֬M}4XM$VčHN&g e()lB3oӸSE1*~6e ;?rOD̉} z/,HQL]`!z *z?!-a |GSC\QllnI,K&>F/6ȤnnHӗMg]h41WClI WCGfeidd0HxSgjOKMQDΗ۔^]-!⠉t!/0I5a<{Pw+%}ϋ Wd$&ξ9܆u_!]wq3&~ c5[ή9,f&T񰪠u=f(xx5TW'LD}|[@S#_ h=}WH['O(OXf܄ڌ%[c'^{sf#a]y&ln>H /ތVIy05+_ь6w 8pU"ĕ1w>"[ٜl(_@թH@0kG6>&rT=b|@N}ݡMC%~ <#@NԨE.ؾTWa2Us2< SZxy*Gl #8&oD󪣽:D{O% xc6<<[ѨCn'-}3oPI8.e YAlcrl5!Qdmdp$.=gXtp rbr-1؄~*Z Gw~mmwR" 2 ˍ!nf^ mhv{~hD̹JԞ쥚襽wɮt;H@ /R7mUuC6J,:::8˹u_1]g3[ۭ+{< 'xi?H:>^jtV)0w*Wt^*7G H싡@9KyL"Đ-`2JdTkb\13s?gurzX\ŬRJ.l_7F;+4a5YbiD˥7V79$/;b &P p^a nP&s*P_oq5޺>|+7Ybل{ !p SR86+8`7|kM&Xy%2 lJz]%gL6+1QP~#,;(Û3 !9e%~d$xYr,ƃ+Կ95.tÁuI:3j$qpD(xl.8bMܽNRrL(E? YLw4T$6. b_K$޸jN0GPrֵɫt0%Ԭ??[1aڪ>-FBi/r;f8IhA;Aڗ&>۲Ub;q6*\LZCTVBoه|Zg| S0uvZ~Τب!M ikDnӅ٭Z(- (1zL2G0{Xy/-TdYs`2[O8)RVBCUze6n1ĭ3ل\!UP,$ ,@|`aܚF~EI!ۨJJ ̨#o-ƻv"no&vGnh뜐kpg  %J8C&WN *)9#fUHZNVg%QmsCJU[oYitx;u7;Lh]'&5RIC/9G7teo"[ޯ +KBQT)p̄.>CfB/U2?Ue>$+ a&].hTl{J4/xG"Nji^V֮{s fSY_kՙ)w$9AחMuSϺj* EGP$lAO(ƫJ&Ц"gWt'Uc7攐_]m gaX\U8QTLYjM "]HW0AJS .BIzp (Z Y2zȐA9s8ՋRp{ORa\V`j=⌵Sbtھ=̬m;czC:{UkԢE}xR xQUVzOtc_]/BhgrdRlMPwک"VݵUaކl!$tOt+i)>;^Z`I4'"rK3kyӄƬ8 Րiaf`ArnLf Ck ]~v2#Wqnܲ RM&7{OL_j4j[@b:J+po[Tq medSV!G~]3-Gc=o?&̢ǒ0BÉ )PA[7[}Sܭm5~Cfvqo, D`St_&|{uIL!X7N}ۈ)׈WmX]hIkBDxW~ .1ZPֽaDZ֓![Pďk aw$w΂ꍽvadXZb}fJw D:sEyi CQqd^"H8OZM:#Űz6Ơns4fkpEJdnXePwAH/%GRy&D:e+e8 }ƾ$l_Ν9|/u\x-y?P5IJWbۄpK1H.x n[l8OLj`x`֒t3hnmVΞV2z%_*@foى 5]@G qi { k1/l(p¯aPk,jk v uo.@D^w~Ymv@^`ƫ_uiuAQ׆x*p+*Jq51#qTB2Sߙa%ȰHlVUemt{7DF!B}Na pZ-@ta&8Sf׆M 3^U(r&8N;O{tpK2!{V{#v wnK֭)O1Q\Tɼs4E*愶tۻzOcG+=t|` WΤM{lv-BSa5)Pap[شӨۑ"eQ,tgobc}d fg>&پc5?Ԓa"a.<ق{ՋnDx'o[DObTcVG$0>c M%#x쟲9V9iى0UER[k0PC|]@t)%Puou4 = ]i&]pFF LU<[֪_I6mLXQ0 jz|¢[mUQeN~)La$|cn! m c.lDUp.v ~\AFIp8j: ;W1|i|$.Mp(Rԟm%$h[] /bRdҁx4yV5Ui̙,# P ]1?|8G#.oq`` X},<ɫ(ZEzQ Ώ#{^R'8rGpRdfQ3,>j˭>X.?%W2bخ'm#)DOwvxvfߜޕݛԯ 3) LMی|bn}0"h?3V #h!đcG{ ¼ `Rw +b)RD!`Nk1(vDb^v.ZLV'cojWy=-aPـk²%NiE+s iڐS?`VDV4 HjsT0^U/ec]oT`c~5#۠n(*((/1C ;5X+;xaN22$FA*S3 /EԅvFքϦHcW7="`RSW1u<潊,?f7T+@ULFyor &.UR"s&LTEK\#| A#=ʾ+Ri瀽29;((RAR|xkhwJH;:`қ1u46uoĿK Tz{&+G(gL;7G v"3eNusym ARbUf1,MQ?}0?|C{󯾅~T?_|Ϋ9tzĖ2j&l]o((n+h'SMCa:\(>fsA1ySei2hpiJs SdR|<2!,6}fwZSy2I:'VUUܾA-=Q CrFڴ4f:BG1am0#%Fzpg9>FrZE\㾘>Eq8pdC'QUhrB`SM#`z[ /ՓDB;OQiOr1 @@*ytKG;a6ir ~ΦX[߷mF*ǝ;M0/:llj߰WaHŸQg~H}Y@fzAd>b4ɔV;Fj03$d1Q_:c߮h7pE͉?_8t/0z#c'իVeFmJRC%!Xg8; zъ # 8sudTJ3?m#SfӐOYh%P0?ɢWkFu%Cup(IZƹյ\ DUȿN\]<<զy1S ȘM̫?Jf/&hK)^oM{o#æ %\Sk OC9H.DWcrP,¼FgHJVc# q%@g齙E`$dM/grƹ@0dDT];oX1 /oReK"vT$3 o I}C#ށ1ϷHgƍ8*Lʱ#!GHXwjkL/FG 2MO&yb4C ?TLrJ`5Ytg[<tm ZHRY+OSRns9ڇg}: V"Hk>)P0'qx/jFBhOYFFmi 쨈+9\DPDxgʓX!NS <) oJޅqG&¨ Z!z9AShYSP.zc_q Td_^sORKBXgږQz9ZQz%Σt@ < E^. /UjGeR$iu>=|p! KcG#K }G6U֣b$X 1ʳ vsɺc$ 7lvPH ݻi#\`tm L:;]qYۊ M4G524 ؾPJzT+afhzE\$D(͟~PSbÐ/<5~X܌VY$=L]DRFȣV"u?y:¥A#p&cyN\Y۷12R_" W j9i,m60壅ځ* B}Չ-'wLXeφE"dB F/>? HVEdϡR3Y4_h}6H^* @ ' Y^>PJLXMKai4KBT`湷@ ŗhNFP{)ݺsYrS~1Z:4b9^:*zGIT6Cdx Aծ=; f1(%8cUܪ:o M. :=.2Af_tB£5^~3$F &Of6,3XtFtM,OȒv?Q< . >Q HαZ͒o@0FK,vMme+|iқͣb5V 3~4`NVwI1T& H Y;и^žQY2QY9+s0D0:'-틬)e}<Mp{Z\f31voW-RZ@"`ǟO:[p'N9S=vLfD ۤC $yiwwA V;N{*o0d&5vlK}3siPNZ^Gd;xWiflUM4Kh:,{[jDCEx/fvd!4Uu׶i9 AhB>z|UcXmcmzk,kA 7fEćeVZYW5TzmWh~-|s SK޴"bYwkXet|qJ*EOn2R6?~U=1|hg} Ӱ93nBgVOYyϰe!㯅9I(wă, A4)u2B"c`ݸrg׊TF.> 8>$p _iNԛl M WkrM,fnnic G Wmb` olV_so%@|' N5ɏe KWUx-aA&b'͈- o>j3.UQGkY7leՔdsW%bA5az=7& wt"3l@Z`GuKJ2dL3X{}2S&`L|89 i*qgRmbd > _ ,M2ŇڶJĻD*.*zisuJ[0JXO~\_G]$?>ubND.^[ݟE(NrN3~{e_-vq*Fv@o{^)}XӅrmV&2tJ&{=0=<[$]q{/ɤ@c@ӵQ|k馗iڅ@[,Bm60IAai"f5x+Ź)5~D7GMJ}-#֓Nf,"k]FTf)fmPDXa86\V?,,q %4_"eDJ( O89HUf̭>韬e;-rzoH DlqԵ8e`Cȱ5i⏭G^ݝyp3<; #=_4,(SBBDJ~C(+A]z[61н@!*s>tA#&P}7")T&9%'Y뜘PN5=z[0&;$e(ԡ`ݍL'iY xᯢŁ`Cv;$k;]};ыhvԟ}eC<8 hC,O:W}3|"rii qɡ :K.뜾l3ȽߡbS\樬֯U'̻oOTW\k#U5E /&/yvUor'%$.D|Ae1\a7'6Q-Z`tnE`V Eђ*9|ĭB-T@\(K|2+;hBܽt `\a*6.5A<J,mT{KmlÍ BHC53+=D ķ Uۯ"ߪ8a^N=j30I|r.ShZ"k'Wzu7*,)um܄7hs“N`%ǰ?v9ЁAj}4iDGE+%fO!dfpVZ"+%-伺~R@㎔}Y-I)̝@\moO͔b5zlD4!V(oA˽;4?RC]6n<`H ΨK9VDNZ//gxz#c=T,3M 2Cp~x]g,We6IL~nn*5Kk&`_+=񖑠;fXY} Z~ĪZWqDUQq4޻>ccO2yV;p@{`q&~|,k oE/Q}K,;L Mٜe9rTD,y?Bl?Zs`Ɖ1D.U1Ug=լ.(=RMMȍ`bjL lƮe{ 6 ^@|X4ۅC_2:dM7 ֪*Y R25ۋv'~[+YPf"(tqq*%5 Ml)Y^vW[)QsLa0/SGҵeԯWq@H>ϐ_vz$k7k 4m~ |ֽ77W)C 8fĭ9W=.ʶ%56#IKϴU):pfG6y7/h|yL\ob9esq[4̰P~q m2i2z8RSWXRʕSK+&rG,aY|АyWhX"Bο y,Ʈ%?zyTMm>9)3[ͷ,k9U{&<'8j) dBI;YKOd/xĪսµφl&j(L&YYquO,;Z`Hwʥ{w?R /f{1[=X6 *nQ*{i`ح Rg{% U};AblyhH)s %rUr wm["5pZ=ef^)Yİ qk)j^IYE3lU0;4HKyA\r8L +OxAZosbBC ?NQ^MYhNGnPo0o󎪽#_p#UA>o{+2lAgb'j-4Q_C&Ⱬ0&>87&x`xޤwP>)MuQnfںp=yƿï,=˂Q eԂ Dy}Piw NjK|ZhP9k2XXjs|HͲ||X5hfz,+wTpS`ܰ2w>x61/\*p-vyxf5ePүOm教5 NOU1.-}3%*jzl <5O{틺Eǯ$*gQ7 oBbICIfsX0MIXXÿ3VEƘXAWJ ,Ŋ'@fPO(K\U$b3rFe/Y~i~Z*LZ,pT2Y0#R{a7Rl[rX{B]aW#!R 8&)KbgrYt[X׬Ǜt%(m bEs])Fδ-DZT4KL'w5 Ѻ;UKiU'FG dG JmBϚr9Vb(+YR^,$p`ps0 Zs%n= X#D`y~nt8;l !&QO T}{dϦ`$T8\&sj&VmRך %RAjZJ}31D3I +)8~id4%/+c>Ii |Z`LoRgIgzIaGýÞ#)UiidM-Xc|vqC]b $K-uG R!<*>fm;v<HX-jW|w+)k?9CM 4etWy]^n;g~:$a{NݳHh=-$dƝmM'"lCvBWę?%Iu Ve8hQn=JՠAc)"PV8P"Pe:$OWoRF^_>GasEAIٚad;0'Ɲ8]AtrGM)5'uF3’1:yHA|J7%`=#1rWv|((h QQ srP ~C=a>qG^I]Jj@E)j_w.jNv}DO7>eQwhAWM6-uN,@]'_|bl @kVOiŸܿ25@Es[/d0(Ts 8IfƠԁR.RgeH4nW,nbВUbOJ,82Yyt~!$']ݎ=u9Rm[VYգ@+Qy'as|}3N}F8u]aPG=֌S 9a1i1iZg9јn"%n7,|wH Twޘs1+n:ICє[MrLƠOҺ}d7[fiCp?$G7u b 7 +"_,.C '}#Y®\VݛB)uqT!;tKde23%NzArцknQ_^'¡|}6T'n_' Tx (8ChbF#k2xd5 (v0jPDXR30 >AJrsT$Xؓ4FR]o \._QJa0_/U:f$Y'hege좋 L ⚆U]$,VPwXE@߿! }W9fNA[ =HuۊW?[19 m^[fFQ9@N25 2QpZկzSR.vT@'3};F:h1LqL\0Ez:a/(8}njՀLkI^iٳYKb/]-td˪N]IV }`6F&s=/1:Ovu6tl7 HU@bQ[n.t=4=ocXXjT >6Ʋ4R+H~J >œOu7@3hsW EOW*LkYkZ0炬A471'_1ty_p>Mnn\;Pls BW $7-9BH a;{P8vDB#`6J,NJW6f;*>.͝g2mTݣVJ)Kpi>4g H"X|F%`a\=2iuR {dF9D  IoܿQAeyDf5ז"bBM)m Q<`VpJ [nƷ2,^WaH:'7ץ:]Z%kSځ6{Ukd"N yͩ74H#a:hVծo>x]!?S,tt jMh/fAptBWS$WNn[vp 'k6u0\`j o!,xWcu.+1TS[ )E|lNǾqP'd"33i62XɌ9U,DŒu`L(HՓyd $9F_}i.q7j\t{..z֥uDoZ7R.`lMsk`+}**q{q|5nqb6W b$&Jyz*ƙ5Xq I*)13ȃLhIX\l2w7{|-GqS{]5eZmXziCL̸:T{ ;TliA$ClN\wZo+} wttIh\T9iB̠݅BA*[;HLTsY$rq2kGq *S}HT,\'`QeY B8;y6&/{4>ċa'Mt^_vd]R!./9܋0& ux7R\Ҭ@U"ׂb4;Q58T[f]&=}|P(җ bf!!{8;!g?CW8)Mo.S(z`N \[֪{~c*A`2όjhɾ6Wg$:̚yt?ˆ\W1qmuǾه+LQ,ܬNn jsdU0-l2pvWA}۴c+Е23CL`O%_ IpQtmp.7gJ*+u _M7yE-ܫ,:Xg%WwmPW(S\:lЍSY+*Uf2kqm{B*Jdޕ$#BGS'#~t&i  !LXz,Wg+.* "ܘ DP{cK~[38\XG:ќyw u|6 ;7 IC)ץ9>H"[Ta}TJ# {^'(iEJ"; ޡIJnϵɭoc sA=χ;|6`F@H9D%*աsNA ^c4l^C@4s0,\^Ƙՠ]0L{E;?7_k+ehZ\''lLaT # Vm,x-+d/PB\ڪbSjܬ 5-z,{Qύ#>#iXd㍏9W/,P62\M9KՄn/WJͼ-t&(Q. PA![;v}~ .bDFD`٣ P/kcpnGD8. 9(Z I["lQ^vbym;6fH鉁qPXMWWB'H yၦъ5g4y,iŻȔ]vm ֋Թoc;(4`o# T9gZg{u۟ڣ`8p\kqU-$į$V0r 1wѾ~tmC :aB.y^䄕V1O2 %xai+D 8`miF6ZjGS0IJU{#F(5,x361ȀZtYdo <8J7?'S;Ufp=T%"KJrV+]l_='r1ΝG,%HrQ48H< ra̮(‰R]vQRGO}? %A Hcѕb3 l2XcMd8f2#Ĩ$Qy5.T<"|?m6RH"yج8{N?A%ȌI|4EfV$Ύս]rXj\%Є:~XS:b+N|oFjh' 3~X_]X$l[HC@W*)c@ťw,y @|:W$^Mo掭"JèNu*{=hDa:Qk;75Է"n6"8;g ?V).m0;ly-uO縶F1;UM7åzm0璭{5a&0QJ_zW9[J )ҒWGY|8y @Wos=טHGic9bC*#l_0p.βߔD?4Wd\(jV4/:J}z3=ӆ&Ŵl,%ڡ1!R[|&QmշP}[ÎQ( 礖ͩw'ۖjB4]ךHd%:lʌwgmL e+U&||U#n\|W!e{&*̐ń+@(XvÙaa8!Q1w3D'&~NIP~̇nu7I-3d鋍QR 7.k2Uoh?rosZ& V%S#X/,YK*ɨ,|ñ$#@" xП+p ˩ >,^Kj @8/B[ 9E=zI։?>E0ZZz:WjY'Ir޾ z 'h J^^M)cKJgk5Q|je/ҿ݅⚈$z!#_-_oV0 x +v($W:mBI2")IԪLj@ݕvNC=k@Q{lBMoR砛62{.IK,nzڲsgrpIݬn# B !E,>s3rLiя_,%`P2hFع6u"RLbϋvcź'kn譀Bp~ٮ\WA YfX)",K'y21c#791Fhb<'KHdipS.s;k+ЍZ U1m'k&c(*>[ڸ>77з @B W,QD|8\Af3]@^Qoĭ5,Լ /0~wd?&~a! Ԍ<<f4,.7jNh0Y=*gzYyd3Z *FiW_p@, 56)J.`p._]%ZT;eŌ rG7ob$ 3aY4'04o ;"S]u,e9$5EV-KeĚG֯ 1Ku<,Mۅd5QCNMxCTOG|8_6[N+q]G&GhcOلLޫooy Ic}\N'qG8sT=rNK|p kE_!#~ԮbOjf;d[hįnZy~:(~K/K~Rup) RQ/TxAAV- 9I">#߈RmQ9YshegR0goxdCh"jB3D8S>0#m7.eP?\^. Jb30I+QnGn c2Qfa``gzU,r5܂AON*SrʛbaX)a# YtOHID:[ &w,;? #SpdaPr85%Ąjt.kx#q=  ]ÅU>?^fA V| |L.,6UK{'X0.%g ?W.g]nª)]?쎞p[暂1dʻÆ+*˭6&szd W _?0xTJ90ހzJ#;g#ܖs?(y#SC8kdM N t(ͣ+bDIHg̲XI7~; Czk[ҷ M;2-uB:4a b!oEZ"j>kCj 4v Y^Q kWw%n*^YT@N=1to]Ji!nJ6lG*ktM(lہ(QJ,oh1ME[>{:a9Gf11sjfıv8zg^~XLU0:d,?׳9 BVgMK0ۤQ?[gVbAri;^дX٠ݰȖ"ZRl*k|<et=fFnk,,P?sG:|]M\SP:+?t#}@8g! ',M?#o%<]򬬘Ai@%M,C]'Az'Y?~NϮn D+{P;|ђvzU?&Ҳ_,JбC7N49,~hh+y}Pw `d^6mJyy˩uJ?-i ڹgr3dMԶW`i nԔ|Y,ӬʇT"ۈo6N6f ӡzB}p^ʸsrCv ui3uͬ|.DP<$P hnGXg%vhܰvpei72O37Uw2l) |Cs"]` /fn:èf h8d,>tQ>ClF_⁸ <{  񦻁R:s3 >eBkk"4J5VlO9Vc]=w:N r]gj&njm3(1`p˿u3wV'Ťo+b }ٔ1,n]+}фd[_T=%B9 D2|.fC̍@ZP;.bW[S2.s5'* M{n[-1kҝ̕9DxjRO@n۫NU 2Q؍8FWwAvI$(F=I%);|ǷqTxDap,Ģx(("xy3@!?=&uhg-F!ΎKlbLX\=WQ"}&3{);yMaڅ)O(%s=j BN#jL3Njx5ݰ1Z'rF˸Th #7-[OUcicߪ@}ȷV6ı[p>URƛj=P*v9m!L.W? |!g}iq |R,H{Z3`A.QOfnoN|P+mc8 zXa:ٲ*A*9@.ORvxD/V3).mQM}ȫ0/kuWP-cuI q Jm-/r+ȗ,x1Yz ġiUR%WBX+sRpHaJwN Y[; 6ҵ(767}*\hz8‹RY!?oj*REPOwδ(d$ZHJ; ^,ͤ0&Y/[&n96#ZN/ =}q|v4 [BmB!SGCVԗu|9L6;IZ$ A4S޹XtbxFêߙF 2ʼnFCcxyP0roF&\HCZ9g 5mznȽe. At-i~҂M8oDX%A:+s]6B<+vY^nK~8KfYd= ;Ll*oJГScOWzWJ]mM,JQ,H1_ҔD ; -#5)<:Imr ڃsZ&#)ws#K^/÷%%oY 0VװlJPEؘEi"Q 1ẓCHV@B7&a_C[?˽Tl|·j 9#Vtr/iQ|Y[ڏ4=^X?b)J2ݨ|)ݞee[v)W(XvJbЀ AXbo+> } ȣZLImt5@EQnW6 ^?}|45nv.T5_(|@R`ulmE\ 7 &_^`޹iWw|2e^TX.5v([q>l[ڠIXN8 o+%AJ7)Q-7‘'V@ i9bN.b7L%,hʹ/PEO; Ù9 #Wq"V]ދj&;AbB" R5ohϦM8igw(1DdYy-L 8|J;e'}6U<*Nz ʈԤ$5|V/rKkߋ"Bb5vT8Z(Z6&qbn}ΒEW[[oi]8yVq@Y٢竭3K5 ʠajBZhT=_Z,YDF[]¨sjHpog5wtif'3toOb4?*=%Ǹ=WQ8s$:eq"I~\\nC]y OZG%i :{2!5uʇHVE*a@AN.JqH)vhRBPtM,W ` R8(|ą8 eoDwFyB|GXRPi䨔LT_a6cG* (3ۗ e׹uLB?J1J;sdlTHl 6%HRj/V#e{5G ri!])-J-}oS-i-_q;UO4?8ocԞmO*sS"q%'Nc934`ZJF9E3#P5 v}8A&ŬƑshC(MʁB݊ j:yCAy `*z.YP =\bm֭]~O=}?AkYUa|O2/8H@ Qj2~:!q9K|V{`E+ѰQNOvQj {FX&dL?م8Z +ԍظOL P587a9ߑ /%\}x`>RLg1ݮ $VSNI[|A_9 _1RU-@|ی쉜f!AWrLEdfYō;XJ&]沛^Hlt=HB9%ju3I^;/_t>ş=m+kŗWDAW d=q(LtHZpP؉f ]eL Yf59Dn†h(Tsyr>Բ Vk9uˀ͚͆ ovo% 3`׾NKN':'̟Y|.k69@A)+B;LLhԣsMӞl5Z;Sy EH{D7+! HĎul-i (=ge\5Dsԏs/g4m&:8gfW|e%I^ թz, ^싡?51Gt\kVB^ep߰5ª_HyYdo{?#V?m5jycE{&9j,|OVKs;8er7v'g^/5eNz'e=E],BmI +VQ8پ30 8#u4\s^ͧvh3'yb/>L1ظͦ*Azoa ֌DjX:yym 7!; EДc>97ҖՕBpEu$UkʾJC-:ܩxM7q 49/~aS2ED'TN~'uKmzUzɆQ+.7/~6ׁăޮɉ],9 KH`9#e `B]B0h' i4x{!I|cc#3ikBWԓ\Tj GbV۝$ ɞ(ΊNh ,=Q{ ZY4_AZ/"D霌u2j>n(3?P}dtB6cklB Yx_Q^RBS#-@Dٖ$9>V m|*(2S-U [ZsJ+{‘#?~Tk:N'5^g@ IEFqbш}ʜ)xӫKJy$sW7ET;BlUu xG<F~r4ci9yiw@fˮF+4yqPu%\{Eo<=) :WRDZb+T@ :y}7%.0NTz xiKSEUrG u {]꺞GrYirM@+:V.]HL0[e{]AQie$l@w/Ka4 iH0#ב{6H"bإhe|W=9z"7 h(d`D]9bL̥QON@=Ԡ% _/,dWaKIj}H<3NǤi>$0HZXL?3-Kds|_g.~ʕenvxiF>FJ]J{FYb}/l%2.6[o9f~?yD"vCi)6MiR\=D7TFkNglk9䝣4Nr1_PBw`,9h)Y kZ..$s(bfg}S;r`[6 :%[,ߜbXT`_i4z-|Ce5*N6!g:'D<^F5@X\&Rߒwse7Oa_W% ~Q4RYsQ fqa\t+ ƚC/%cX>"3 ܜznN>J`3U6Tj s%-vJX%{؍MW4̢M~D P/r3azPC*@ņ`A f"G$b Z)Ku1iNԓ鴶 x^70C6@[%qo*y߿zNvɉ'_"#/+d?NJ5N+>YĒ.2VTεWBKM*{@ɩ}[Η3*|0PLV͙X1E Ƽ7#20_y|~bljp4!ijo`KA+Nk 53(P:Vnl}|3ǥMtzfj^wL=3a_vÆ4ߜ`'Px5u ,Az%6GS͟O<zC%RzWB UN|3)QXKFk3>Na]Y.No61<иP"މI,t_"rj װ|>]m_'ף f1>hB SW4 @S1$,8C@*lT`ъ5C yDٙM<sMzœ4-n6LvBsOu< eHѦ0s/XCE %t}-8fm |Mק[P4K6mmdT l+J5.p']4(|5FLs6BI7S Fu%E6?ZyOMo tz] ԎLt# `18Ꙏok:0Y [4_Q sxpPώ ]NK* g6TSX2 X_,P\/1Tb S /}jv0y djZ+jVeyk $W=Uenٶ-E.[+:wA9vkSw%@88>K+* Ho9c{ w(?-G>W 4#0Z ㄃D&y[!o*^7قhl .JʵKt*j|o^jz>s 0M?V5dmg{C=B*&#.!HKьr4<-ã6D[xmfV`Ohv 7рU>ɾqLJة՛NvM0t >Ś[Հ]ߩ'H9}sYNZ(KYXݰ;mGtb'FS?_#o7k!^D9Pϟ̣ db)Gl=s~Ngn&DkaUV}&A/c& @QpÛq"$:BԮ7q9R(}dN#L*5Ae$_ ?E@3fQVRfxLd!N;DîF8IGMcر;aao.φvx`#͢pB9mRuSX-~m{y %NvKqfMǬ7I QhuY<{ޫ]`uƮ=+BljBӭ;$9}>^PR Sx0Tw5uNr.#| z0/r Uğ\W Vy&s$뉦@ -&P{0cxWndi+pAUN]76/fof"uy]|:|,Zg\3HijO1OEX o|^ںXi`>xyX46yl=p.5qM:DyZ'8M:D Pi\jBNlBfqz?ӈ{)‰f>.R@ΑNxʟMH*>:"q*6v#m zlAᓩ ϱ{T'MmHyRy'%m  [=9w˒z% -zMHʚJ]ai :KO}7;ǁg~bj Bߚ΄~Gb0Ċ g0Uۂ G[ӝ˲ـoz9p _^,8VTjtHJx@[z!9rq3so ȁp!3>;a sZ3n6c3P4F@櫟δptbJ51p }SyX\vI=Wiim[2#F͑qBzBڒo QN E_MRBؖ ؋/$ZZwRUDIJ^-T-Tl,Q3,\hc,YEHr0rb=c$lR c,%[@^8gԡ"W}- #x~OhPᰙn%|z̘׼REZ%x/ULcmڻyM/x+΢ȋ y@ j(Lˇb,$E[kVA !n>c?bՈ;u}3*=#uzezb j,S/4돥8\x@UnG8VU +Sq6Z,̹l ?|:,`gέύ7)>f&Gűϗ`p8G7.%"]J0iimI55i9򼿤QbN1+wϞ?Vb}/k# {[3ۤ<OACƢHs`@# S3trU2sMLcJ/6l> |##@>^-Iq|g(Dy~t Rߨh, ]<'yd*T ؎w7(0~MNV7r>`nW44-A .)^a#B %)Ʊ7 WBha7.Ȯ U(r6F  %/h廈Wt4RPx75pNTFz[.߭㦾?Drﲇ`d*\ )ҭƯ#?G~j %wO!S`)_xT_UXǭe ϵ(0:u.vZ`.:>X]8"4`&S$α35"~ϡS p𗦣w X!.v (Iޠ M&0 u3S 4mn- /o=&m:Ӕ* uO 2 ;+痍:ɊM!eD(v i"EQc.(j \mNN<l%)q'ܰRHD/m:n4n袿Οj9[B"~֊dk;=4$(Fm|Uq 16oY5:HmkQsV?Rv?i̕  Uy;]f'&t|L5O\.d )~M["iCO#|NaX_J?0H⡠f8|sٍl9N*N"r-lZbJ.p7oD.{2EjHÙxr(Ij.moM&Jz_wK~^jmhY*67G17F69׍%m͒bHE=Teҧ27xmP޺ʣ6RGZٵL Y_TWVu|2cO&NsS<'xtvGf%ۜgutF,P-c, + NkXk8K!AD-C94qeR?d*%gaUs&ƽ/c6 w#!s 4cin ek]Y|'q {P4U؉EWH};+GD{{O"FcEGRYrjE޵p-;Ҟ}L{*VCF9+*_w hq#xF/=HٗyO*wƷdiK|8MP_r0tO3Z_+ ~ P5p%SXʝ~p([IEżGuxSJ\RgkK_WYeJ1.f'KsI n J$a)^t%.X"Q=t`}Ajr/_eF)ߚ&\]s1/$CId ^&FkC,VϤz92 ÝZ`J=f絆$f^cr'#>~"gmӗDn_9u឵d|w&hDv>oy7#?Y|arH}aY)Z⢴VQ#7i|BثVІ'"=ySU@#rDOc ba L΃ɠ;#`)L*\cmpg?ouՇ jw}Ep} k%f\'&y|eyU-n|H]H_P_pcȪÛ{ MYރNj#SKd.*,JyAI0+$Dr?O=m)M z l gdzlے90Dt?~bP#c'*kʹ\1/@rUMm"dfS|O?7`3wLwUZ(S!kʱf&e)eaY,Ak?h{֑)H\YD<8Jgœ]#.J$OrPHU~[2vg:÷8j.*v~e7~t L?0+a〷};et(T{/)1/-" n.?v_OM^Z$Lj9c8GӲrooBͼʖh2{ݢa,#KxdÉ)QlĜLl$|*3Rm_E?^OFupJ!q\ڌضŧ80<-~G 2yV{4Uֵ]䶀G> R"pr ( 7⫃QC.?#8Hx$I"'VCd+C LX%gtQR {rEG7h@[7;: %Ax斝#- m3ju7 Ld2_Q|W.ipg9 0(e`ǒʜ\sPz_LxE 2rPdԳ!.迲րQF DD|1ŕ*nK-ῄNk4') Lc:ar+5eBzd2@T.DtO; x;Z^8^I ?Dͥ|^M0Ai)ԒVYULMU}nuMhI)2P6 T^t}("NJ}G1U>'P`kUQ gF_#'KTJ3Ӎ^*ջGHa6䬺d'(pA#Oy6#^sC! gID3 fEgڼ3}J92oDqL(iy^H _HѴWdQyR8w/VjcCeM)59D;^@ H9Y/ _">2q%U]> ZK~&^Cy[es*}jE)sCI(O/ІvS+ v(齹M?SHNj9D hj@6c,YA3UvQa-e4ɖlBJQɫ[hEJmc PT5ʗ(-NZ;rPz`تz%<Ҹ3bB3t:"-h7TH QI)bDϯu*r+BI^X0ɳ2f1.-j_ Ա5Ӌ" 2A@-j ?>>2EȀ4lIT8  L~zbn!Q`t;~8> YskKmmqXǏwIZA'x~TI`W߄&QلufysH͇V`r{5WIy<Ӯ5QMwkLѱLj=SHωbFRxsnsQbi hjgnWTt>D-mY"LGK|jfogɐ;c}Yi^rs!s_ { $+3Bg;VxtV gHFv. M C\ ??=RƯ ;3ѪtbVÏ<I:sl6G4 yTCArkǩҕ:J\[GZ0:NXWn D$ n =쮎 8} H=)VW>$#vZH@L.8'Ap \RLg?cUR|~YEg6,iȎ)RT8R}mJcX]6 w)z{.4aʪOWFKeH/1^b^ˤ!H@U:Ugy̞osW7Ӷe&E-h<ǂWfkVsX"Xr@rXǢ,&cb1|Y"ZԒg I乆=tìd[MH,U[$Y^D19`~ufc&a۸Ƹ_)&|gxz2OO~N(v)X'W +p0+޺RqeЈ$l3ET lO~UžCcě4-J\۟A>i ! eM ,Tړu>ڋMWdB"݅B{ V1E SMIN\F:d wG]Ix0z<F쯂1y`V&0GfJِN~wK`򙌇fHZn}HjiZYnr7$/s6TcN(o8salLw5DS!yu3н2u6kU~Ɓ4י:婔Sxq#07hV iU3 ~`hhB~E(˦}8 ,,{O!d ,OW?QJB" كvZ~:|gGih29 @$^O YZ