sssd-ipa-1.14.0-43.el7_3.18$> 2юI;p!}7>=?d   ; "@FM    4 { $XLL 3L   ( 89:g =9GDH`I|XY\]^0bdefltuvw$x@y\RCsssd-ipa1.14.043.el7_3.18The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.YTEpc1bm.rdu2.centos.org 'CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKOjA큤AYTE_YTE_YTEoW~YTEMYTELYTEOb81dff727b2c5f2e041d79953f1631a428ba87ab85847b3bdc991af78e8f669694d30cbaba62288876ee7e92f0ba8b5e69aaebca8c190f9060a3670d91a193ba8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90371ce67dead6a25db630c6b71465c06b2ed9bdfad044db73aaabefec0bdd0cd740a17ad4e3be94abb12e67598d0e01f60f4419f9887368b81d29b7d0fb4f3b8d1rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.18.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.183.0.4-14.6.0-14.0-11.14.0-43.el7_3.181.14.0-43.el7_3.181.14.0-43.el7_3.185.2-1sssd1.10.0-8.beta24.11.3Y(YYtYXBXpXv@XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.18Jakub Hrozek - 1.14.0-43.17Jakub Hrozek - 1.14.0-43.16Jakub Hrozek - 1.14.0-43.15Jakub Hrozek - 1.14.0-43.14Jakub Hrozek - 1.14.0-43.13Jakub Hrozek - 1.14.0-43.12Jakub Hrozek - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1456013 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1450125 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1446085 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1445821 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1422183 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user.- Resolves: rhbz#1418943 - If a long-running task (e.g. enumeration) blocks the sssd_be process, sssd_be can deadlock - Also Require a new-enough version of selinux-policy so that setpgid() by sssd is allowed- Resolves: rhbz#1405584 - SSH: default_domain_suffix is not being used for users' authorized keys- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.181.14.0-43.el7_3.18libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=21eef38c65d50e5eb1c3f51f72c108a65d626955, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6:]"k%f@}|,p35muذpE /^!P Ӯ^C 68|o) څsWmkkl໸Ž⸋[!oM:tV+2r~~XusNk|\|G; Fd+)l`eg'?ph2DQS5`#¡I69Og\~o{LsxV4,Y Ȅï&EEXEmV$B]d+F9 $K$qڅKg `7P)NQ S[zP.$`d]PoR.uOWS;'tVzg(ά?fzG$ w(%9cYrn3o%ʰkwBbDE2MYpP?߃%(x*>}pUVF+"57{4^o1B`Ҭ_XK?n\Em*H6t;, gl* @,6)gjN5;B>z_A<5y< u3쾌;&#؅_^q<6?5~⧴ 9?kC<*0Tc2q?IRCJil2`;aBΗou)q@]ۢRx |q~`>z,Uyk2ҵWKAzaġ-*`Si.4dJȄBjEOO[coq UdߞXdv'GoQ2wۖ#>(ch~L ̐\EQ^5V4CO XǺ_~WVrr6LTHًGi$C b 59tqOw><q̒gF@Z7$f̫w{=G +Y60Զ M5>cV vSsBl:L<-,M/ @6TU2M+@]"\b*vWjH(x.7 8ԏ+/R9BklBmR-)Q{$Nq}8—+o8Q! ?r^1LxJl"+GL(_m+_!uYzGW )e5uX))k[D*7eNl Ηsen~%@Fv…Y)x'E&l_2q5[ٿ-,kѱ/;Vߤd7x$ Ċ/h">Abɴ㾕e!@hRNv]>4Q5Cg7G|?ܞ5[h-M,::2 VAcCyȗk>;elaJ ݖWX<^aH@' (@,L!psC Pdv=C o#W֭GBmK,hC`4,QsV'#qJFh]ѫ LJ`#ucm_&Vf*?S`}tX^]T|j؞vYT/ڵ;;~" [m 6^W}׃'nۇ8/&@5D HёohpY1T:+;6<շs0 iBjdu1r{.qoua@vT&io_bKT.f`Y!d|աZ՘ QKL3{xcG`ڻ.>OR],9e[>S1VA\ylΎ4w_,Yiv%FwU+|A)Ѱ ;nrji5O ٚ 2h AhJ2^+s GLЋx*@t hg>fRov鋍T^! H52lxI黗⤲ݿC&K xxs)S8o)2xq򸕞%=5p%qN\3vU{}{ި{hꗤBf;]L綐bSƘ&9P뫄Cg qR|g2ڋm (ڑ.^8HU _=zmy_/!y ॲ}J_hh͠Ptr-pmA~ q9ƻ NU+FcJmS`፲6UD͔jY/ @!K;K"LqHxwp}S3y|MM;tOR9&m^/f5#Ϟ:&|;GA|AsgL.31gkW  d+3>fq5l+x/\u3D8ݾ\Prp'ߘK0G,'؁I3/T2w[:`n~Ǭ]SJ}9N\wBX Llf9AhR71-賹Z([Н0X'4v=!ӫ +lƫp+a?S㎗^ < cy΄4ˬ\^d~ӽGqE+z0_iWצ.6r$mxVmee(kB8 3:uM* ~@=Td: @p5%4#!l=ʿמ ] Ⱦb ~礝ĩ{G55E!Md:6 7(X#<57.I>.[TEԂq1q˲>jGԍ 긫5@Rg6|C@HX6pu38GnCNH ZMĄڐ#ziJ@&Sp):i@øpJh5;#Uu|njHۏg_"|%C˒?u1) "vA{O2y$u%*wvaN'NX 5VY;gb1!ȏ@ZbDI8 e@dQ?!QA?ZYc5+M`rowBgA=Tζv0KCq?E~M6HÃ]C|rothِkHtS/F2n_]nWL$|<um̯V^shU~!t )})+YOB} ]\l3jPn&xQL`lF7ARCexFG3{gGsA :X5$xEJIHŏ4M(5a-F\: )+P-Y#xm}65F?B f# ccz:rltХ$1v%Z"_oC|-d*ܯ֐ ^Tc"# \;tkheYoO1#a [d[)D\] q < vl "&W *w'xi:}QE7ʃӰƘ/8x7j(|ѺI6+nAVboF% 6!j` p,&>AЧ) .Ok*۽9(zlZ ![{Jg.kndVJ ,Ul!\Aꨯ/S{ 5PHYXH)]I. "֔+;p.,+3;y@07e, Z~CvKb.a(*w1,oXUϷliG&1tQ͑r[=X O=zтܢm^leCww|5Ig,M+/dFYbP7r"̮32fR(bYKEuc^0=ԧ+cJIo a̠ m^^65Bd{~.!9Z4u$DŽ@ZSV=BL=ЬZK$^asxOj]ƷmJj3#l2|ZF;>8K`EH@2ү.ލ߃XXvLR3XJ< ;JkA;  Wa~5. *5(nPAccKyY>a AQ{jXFgn=D'+9M2=V bhO9!wvE@: xxtK x>ӹ+`$H>zB%c!Q=y~7j[JW~T(6y++:^O [#-Ua˿)|Wʻ=H){htat1Z :M-?$EsD s3ΏlPÜz*OyhRXc6>*<T#}%7PgbB@f/[GCM`ToLTάhcv j05%jأ~1Q7-<&V䁦9{S 'B4qlFl0p[龎1wXjҬWB0N01دflU.Ec{%+1'Z4bJN;]ťeqVMMP.?bbUԋoy\7κ_[hOhgP㸗V =9bzvҲ< GNŒ,3Ǽ*3O}0C^4ܬ.tzPV4 o6Yx+QwdGFԄZE r)+b#$ 0O@ )#P0A@ Ì`W9Ү:7s޵H ܥNFȌ2?:MW 6dn80J[GG>vﳌkvx+CE ̗4OX;˘#Wx<·e)}vO(r /e;rd:pgK4$'V Րl[RCh搑H`#Z4r%Epwv6ye]P*gK? >聾d‘m99zx ^yh,A /CN幤tmtyo}%j:>\2AlYCGtA]&ޅO)xo:O,59QE'35NkXO&[]V(Ɣ*ƍs-p.F1E_+`9j_ܵUQV7$.8G:zbUv?&E#$X[֯Y\}):([Zy(s״.9éܼQ2 ;tPc֨ ׼KʖBEx%QdSo Od5L?^q{ - X>=b] I|l,v]<_U3WRSq E;9-j9EURey\ٵG/1edlɑLvY[:IfYpBm8bzZWVͮ /, 5MѧU!n@(OV(\oy!HoY[Hm6J:۱8 oSz5$* 0 ]QC %B , л%w^cF#(0\SҴ~.`#p>{:9J_j܂D !c@ jPR$t~8K+IFa/Px&+ 24J";I!*g>+PF")#iM̆6N;tWU{$LԦܿiKQuv‡z>+o"EmI- _zvrP9vtQHa)GN0 s_d'ҁ~D9קstW$--O/8Chk>PjIU2Fjx&_#8' L-ƽ/Ƃ;jUIM?UXQ7k"it*p(r!%f:bA ]Pv6{ cY-ΟC.cEX'=J oNTwCi!Yu,o{7\8ErLiAI)DEB5Cɖle; v 8X^)9uD8au*tWNت?֯M^co@&T^ЌNQA!2Y#^%jr *e&)$W ,>fs4%ĝl7' iJ(~Cg[1 W3 aL0qa5M¶>A'ףX&KZW$ ,z;P_$`P`gv)g6B;e3N_8d'5G7Ω!JQ>5==y)K!sC 5@JJD{Ɓ;S^NIl7 nqLn) w/ MOm_FUaVV}| XKeh#tbz?V[|ppT6IKPYا%>Y]i!/i$xiBheF0Btg_U^=Ina3# ԿaM(5{QbP~tb>{*󡨨ܙY jV Nζ Dd!=ePه᦭fxȭV81!ۣZ&z]b ]ō>DAڔ\ދܐꎾ:^mpIwgЅ+Ky~HoRHĄe;r>ô~ dqjQ5VB[|x+LJ=G " 1wf,藵4O@ZH[1z9Y~0"pk Fz?;5[ᩘ gA\OP.z ,܊:pܷQQ?+Xԩ![_zDo!9>>k;7 CkN);GFJg집;e{v 儈%FvlcD @cK~ ǔR*2F\q63,ΘG#0lbIr[ vXy,oC[Tg ?T|9E1/YݼwZk;#ҬߑmqoZ^*(g%$@M)eyV-~!QQ%m )CVZH?P߸Sl-lB+\Zȉs57 iHf0~%6.UpAˇ|Ҥ 'hZ$/U%AXKR},#4 (h]ޑ9 Ao!B5MMR2>p5|-քU>\+?Ҏ2E~nyJDXC Q(oK}aw'N ie@gJ=Ѿh \goٍPbHB(yQsgU 9W"I8CQm+C+*ߐ.JUt>7W)IӅ?LXn"\T}7HAu;wF m(ä\ͣ㐺@j0M7nu"`mqU@ zkW%+E+gw- kP$t'EE{%KRE@0N9.EG$XLL 뽹h5Paqd  9Bz|NK$cı4/otż}UVV}%m`Vi\5ߜm);ѷ4i pWLYl| bzs"di :r*W<0onz941!1Hl4Ww_? :W:?LE;bԋ\s eXkvNtMgb A=Q&Xtk8=Nm [! @LE=?QyDupz`Y/CI,>:["W1"~= ?tlװF^i|/u'` d6eNVr(2i?̀oSknN7|TpƟ0tc?L<_pAr=)w# k%[ ČlTڥ0귒飩l@-,JpkLL&`Ehd^LZ&Iuڠi.&K gҺc jpTmGksX `KeZ"Fq`=?FliVfDU4$`ì6)7I8aOjGk"ZA6"y ]v+Tz ݏ=u^:vWX!B:qUi"E7칵I{Ab5Ip~38n?Ejdӱh`g|@ut2W#Dyv"a{Bض8O |!k"Ne1džL1Ouo%VQuڏfѦDTLUҥd޹J7Owܼ[%?Kt ~psYNN 90@;6ز8ڤ]Y3]!=j-_wz=x^s$Mxyi2{j+`җ|V"<@'bkB^r1G@HdȿtoH UF\,˳1OiX89c~@ $-"KQ~ߠx\E[#P3WuEHOO\E?sۧ`H4u'|/ҋ5Pto6(qE@\?f*mj\slSmxc BDzT,hVdh$tN"#Zl]pآk lz=BP>~Bpum%xPAwޏf(]@R)Uv|dŒ!z[[''k*/FR&yyb8ɾ#R:~?EIkDqp*E00XC䜃J 415(iK- bA]_!c;oR^61su|ѕ怼)/ɖ?pWmhͯZ%ҧL%eUn3(dI/N3yY EqKIzn`gR T^aY֘`EIYcբk,>VQG 9.ye#(*yIuvj~ z.I>7v;~+" s8A~ƴ\Vq'TBF L+c{? @ xvR6WI?T!1]K>騍+k4J@bosN ^\vHmJmAę}S7v:_6Dža. cP<:_&e6G$z7S-oX|M9|B*ctt10=Cͭ3<6$Ⱦm"AM*k )U&k9"I9c7PQޫvQOz[.%U p/'@[I51Cf  fHw+%G\  D Xr@Z$iĩGh)QGlaWnFdrmh._b2!F\|CZO@f3-Ϛz͜EM^q*`3;Uʹ@ݞFD!fV*Ƅc(IF(1hX6#y=?PTnR` NBS:c^*1N6rQGD%@Xd;I {R&kqc!~B~AAhֆ|la(;rfj2z8#N]P?R{;p閭Bd|w QO(]-Buwʳ.3*w8cAͺJ.ozC7fl2ܞQUSm%5( c ۖ!q|8]K{yrTl\SnQmTW9VڇazfDg/]({.eN,2&þ% dyu-'n<{ceTu\ð]@."B/[Jx[0e{c `*FG?YU s}~ePg5H@[NZJ~ B&MIԏy9h_WC}oKQ_Jze6X6E٤@p/ ؤĽ~uYG E6rGg7,3:g!A8M&pȯ5c)^ |ў u=,)'_m24TB8S2z|E;X1eX[E5 Kӑ5 .Ysg| u5V 0w +-2yaþ|s#8*[pvc GgW~d=}~ ġ䳾aVX63 y%uh@#I9)ѡ~ iHil j|jsd9,opQck)tΏ@lt}Z!Qۨg`}%a3@XY6ЩOg; " . U;bާxK|nXz͹[ZgFA[SVx:,|]Tv` |vot$=K*.Da%IZ1R4QhJצvawȉfNˌc<5!1_.V460LvR(%u~Ycʝn G&D q aa䰳kWɤ3۽a}=*ε~ߞWGOr*ocS4\勵9nҿTS, ,fH!z  hRE'}3uNRLmj73","mq *R§՝N(JKg-pէ"!B.Y$m .:򢋂3ȣsqaÔMSWśi'R|##pxg >f `}U R峫6DxQh yqCEɛWp *#^i57bR NG ӏ8A0 rGU D'^79P ^a5Qvn^ٰ- Qz r#'eLZo!O)0>/^vpڕY=QD^/wAߩ3LB8GE*$ʃDD25CH frCOqLۜ;0JRļm`=@Yͮ Ox/\HbaZjZ* ].eRRVU:Ӡ3҂<1#,=8-67yaKu2 YUt&[+u3-AuJTrh;F8ڞ zf |> @E6Y(NqaP B<+D_Bw5s[(7,sDX+p0t*ݮ+`M%e5J4h3Ea\.eYA41I٭Pb` [KU-IlH]kǙ$&jUJ* Sg8M,pévUx6\h㠳BLVU% ;!XE9߷G1!v&.QX%3cm*&ĭ%гBE̺Zư]O ȇ==+>3 j#VF[?.$b ?TF=XfXƤ+:H$9^f;qJO3p׈,*$M';lIP={a!G daD㪻x.`/2/DǏcWΘpnf~h7A0Y3-Ix]f5-ϢȧI%wD3uuS>H]d_22H<;ZBHP1F\I݆U:7/ph{xi'X6EkiQDsHlڎV$Fr&$ueE*W}-<T6Uf×T|N5Lԓ:F30cLd.tEFCxze|yFY u<upF ?J!`[]96x2B$b8 y*Gn_gbf1Cb. +2ɨ:Eܣ4P&(u>9rF%Go^F:űxr*UYNߧ?KXѾDسK޳Rf`k#p2 YP@#q]ECŁet08{! +0_e01bJu[ɹkz(y\4, +;}(/6 6c'7fԕVd*ރǢ,wRѨ"[Kb6\G6D^:ҦX6 h*QNpwH{7ll*յq܏t(}I+EA%SW|e?/&1cx+طhB_(%֣Cr;ɑzv~7)` 5Z=& h?BvP4\x0Ō)f9씱.C&u: |u)W +E\IB60CW#=41M vhx$ ཨNJ{F/y}ިlA |] 5)+=O3IM0@xAdQ,ZTE{VaJ ZiS"Tdkͼ ~PX "vZ2dBpJ3L{}%s!W^qӭ֐ QWpbiӻViP ͭzUNlŖ"$vލ/z'zG}#ݨ1\ 湤Tz2^tMaNhSRK1ʎ}}Qnj YTyVhE;tegi9nD,.B_FF?QLF7"ԙ3@˸Hҝ]]~R=` 8J#lR/; #NMUڄI8f{į"&γvK.kW+ < G.G)^X v<תɹu`gي'TdYo7QkUpL#eܶS]N YpuכOϑ ,Ȟ^[CxGVsvO"F6Т|yUgMlE -)ѯ+ЛKG h ³t u(ԿVG8rb9@6lqI2J[9\QP 'Ǹ~Nnq-gT-k>iP&bE( gJܹ;O<`QGo"[,9`>h jeLykgpHQ@zjld$AP4DUFq_ ALWD+Ǫނ>>߅Geg̟ޤêGG!& S)M@n7Se\z> )jm5qo[f;{Hte4 _Ӥ 'm3?}HE:: 5ŬGlw@̽؀m12Y9_9An[{lN|gǑL?O׸b[`YM5Pp.6Mڜ0Hz6C{Td:ȋNm#ԫАO= ("%Q=\1:F @P'^w:V}&>M R3()l.>29@[M㪄9 rr`aH}0afu ^\_גcܐC%"M?ói-QSm 65 fϻ;ޞVr_d搥z3-ȷu*K~3(u}⁩=Fܺ\zth(]=O/tTԟS΀ 3s[3HC>`@OgloZhuBCXo-W?sWEhDd<^|9ܜ#2*ˮ26 رFYX"Yi-ˌh,a2ZPWY= A)eZvZuH$AY 7W85C);oj@]wUu5rX8V=%ucs S16Pz05OTMڽ XbyV3KxI 6l]̀}~V[YT]:$&C N b~R;2*TG 2ˋ;-_^Z8lcN]ڭ^sRmXd>gm޲̛ĬEJΒA 4U $8Zԅ]0m1oŽgS& з.9b'wPRWXYV85z*U˂w[JZƏN://8SmI)4vbZoN3X*vGa;F=cotE!.s&NN@ a / <m?k?k.j2&ײVrJJ9IY4U};TQ "&x9,$0W Kˀo1dsS}nG,{]}>sH#pTY^CEnZe޻a'`J&W@ 8P:6N #H0hzKS(8.X{I;nAo7鏏-m@ɏ>2_k wC}U[8TI0 Y57ցV1d麼)2A`lV[" 6\Hg~WO>~(\~I wlq e[:$6ai=z(bFD `IxW:E?('t w!{DrOECI5t6"l~/k俓Cx 7e焈 ɗĦv=Lg{;f I_h{՝7xO1L5MAℏf(ʕs¼Q ~bHW|kNDpqI24Uj,k-J?&d)ڛAe}xPPoճcC߫žzs5 Y3 .v':@蜻3x|pfYLi\/hg~" ^Nk㓐1j\4R k}d'kdontנ8ȃb8M"!!(m~۴/'హS (wno@UUZdafT6{3jc7 `@A!۬ς Ī#?W5EW;V 6(YnIK-#5 o/Ct3LpreI%n˄͜us֗чPiţkm'1?a)ІW0uwɶNS-7|S"P:ػט>֋ױhW({l/jQtW|'z4eVY!|}vc,*,qPzsl4cQF D_: z3CarV􋗅mY\F'j_1ݶe_zDR)ԫkHb95r^wV)|;rfy1THQq8~*Chc07j&~O+Md [XVː![R8Q3F [ sg̖bC-X Xr$216$GMe FXEc.Vx0a`bK/KQF읱yi>6b/J[nsvD)-{SryO$g@ jN^|V. !.WYkIU8RF"wzHG¥1: HFbEbτ:փ*1t.S e7Rszc d9UG>  o/q${)%=2ħ"/6vRϳ8}I5f⣇7e=vÓzNS>k >_:7C C39#r"l{Č$oRmbYE"bT`x5ob]Gs+2T¸3t) t?tT Xd3=t^cBgqw O)SvN{j i |_&]A穧yc6- ܪ*QT't:Ixz1z&%0U#>o@,ۺCqY kpj+׿/24Z]f*=2b?JKT s`K-XY*-UԊLk]&5$$>^ ߜq~ESbv`R' yqǪѻ۵n3(XI@I27-J&(Rgfdb(b=k.I^}?,Sq69D,~;CUa u!P|R' 0%bԷk([PcRhQ?G8h>*pKij7t;DT~]Թ̺Gqb}=f9 tz)X R1y{a^ݫy4(A8 f(8nq&yxZPbvsL_?Noc brhV,sn)=B &M@T:ּĩx>tv%TLc+`!>7Sw.nBWN2\J[Uxh3A8w:Dxzm0V[!> RGXQQXO2/7괭Cawe(rXMKÒk!j~)nmkN{;rΟ_LcNPj Q53t Xh2:G<8%W ^/R`܀T=KǎҳK7ֆ>U:RM4U .4T:342iN`J' Gs< huqJ$_Wʬ=wХrDI]<~P^b l4|+~%ۣ%mW=J{5B@$bIdʥŗ)5ԙV;qZ,xPPčZH0ukȱtr3ߢW|~=[`=OC9p͑6_>ϧanqQ' ¾PSf}X+,3;l҃NX\_ MB;t?j (Ȋ.uZUpiԐd1V`|) gdS+j@J?^˴jQLS!(s2\jCmlN|4b`Km93ϰ:DRޣ8lL}*T?)SAGFd;tKoGΐ>g0RI9U+?E ~QB{R{-G٦u(wB?ޛv/VuDՈP$2izhdHnvFB퉅7FZ6k6Jt/<* ?kg2Ski=mF,rr)niӻA`z1_c`!79 p:vC Uj\TW#p-fGgUx^ TAʰ˿p:ã[&oAYjP ~Y Yd89ìywclBsWMy$2ӫ5u "}vQҿIY5HS;:ŤL=OO>/LsΔJSƥw\wu^ oV$ Uog.?}4z,#p;\_K[UԸ"vGаsA2jPH2mʡծ!UmJ[`484Oh8lX&'1ib!(\$!?ϰY5ګNxt ɻ EXSu/0=DǜN@u*-Nwb(rP;]f|u/< e(L%?M޷iz[yv!}rMXz 93DOl!jOzk8ZK]@XÍ8'NU wݺ` G> Pj*{pI &rTؾ u#u~؍FBe1u)Fݶ!&FNz+g5Qº8ri<$qԊ ԉa e ҾAZ$n9[7hlh3T7a6k{JX3DZ7bAv@\L溻BWiL^?j?S`2ʤpjU&"?mivk}wwLPNHH @v6MA]hIJ i&hj;XD\ab}3a]®ֱ 1^@n4FKqOLX8+b CPCfIBMRP#ŗ1O&GĞ*& ТxHPa<8BGfG!5|"UG.`p{"ŎF{,~5{l_E0ҘjtgÈOXxLf̧[T|AKޡSFr]HuM-V,S+<:Jn󐑔])2I: 86S=eHe#?-,V'CD-Zcp⡬=.J2_~w $[}?tu(aP:rPϢ" op<*rjlYo[l4mZb8OöI 8\79ڰSk_Hjd\v. }mIXPO~-NO0$ kt#8P8٨d5NuLދ8#Sh'l S+ %.K8^0:SЖbjtgV0UM⟨Cv^g>ss0Hp w[+#ך~~7凵 ۸>x(Eym6~7wERA#vVjS('z& ƕF# XuّlP-aj ʡz8l:8Bצx#cRr+L-A$m 凪f@z)#)Q YneI!JAI ~!u\O 﫦QB()k5)}@ ?)5|^J&*3up8< k 򓂩{}v(KbRQ(R2'vRFL&fM]JilR"'Bs%Lv)l3%~:  JZN\2ݿυ>8y۶e>֑0$kaO &mfyeM!Nֺ?_i:ش&inGe<2Zy)kgaXzbL$12uh(Z:xH3vCc*xxn ”%8qq5Ng j]YD)!THyΐ?AbTl8AY Dj$5EZ%*Am)FVPSRk 9ån?Dhd+>fڧ`bR4%uhOZ $r3BϾn-GLj7E|,# <>b\DH٤Wd.z @vWɍtCA5r"&K0+KlǏT1#o&_^ \j <@Z$Rs}z^-x}q=A-)A$i3ؼ}6y~ p%4k'M=ΖV[M烷nAN=b!/|)4!)ϕBb\'Gn&#>i.q.[ХOP;õWE%;z^Qf]Fpd3~,+^x:5a=W5 D-r={7r}0E; ?(DZD>O u< y:wHR"G gYD~~k}oBa'A w g*[v/7tyYi*ګf|ɺo*uFUzuÈ7OB82a>ïp^񷲳VƳ Љ7-oyj' EdUWq| w6v" C[$ʫPs\C:81E)~xnОY-GH{H(䍛4Y}R!/&p#E/t(iE5(lB%#p8 +_.4\1kd] P%Haoկg1fAȜȖ K2͔p??kY;(psIcItp\eIM2 _c 0l@첶ZOIS{VUgyZbSFmkGl[*+ԹX&̉>/V|*ԊlmuM&QnoE'7 ܹ&m +(kln,m}XWFKvoIcTr3VJ6~WhV544CP +_>e|Isi37yţCbuBDl9ڼ0]I/Z! P"T^+244d[&+Vdy[PKĨ/Glwˌyp]I^ =7`7ߢfnW4!Q@{A:1phGQHk#%~:b:i(Y7U'_l͈֮b6Z.~Y;nmzۅ^~rVu,ZQq4lIN2[ߏ\P=˄ WIaVdVN[k/6g#9B}(zrl9[E-Uh3v/--'j9^1^=K<#;Piuyoל~ SP@5J2pg˸ո/Ų%moq[v i(umFH&fq$<5ݴS5zO+sl';2:tZ9C4BԲ Qo~JF˨ ē911CFvy\Ddd^%la+R^ f. 3Y4e=S@eN kKj7'ۏ> B)J uDa螀>G2!!l.0#4AV")΃;I?ĥsg h! -p llֈe=߀\u^ qv%~REwl~-_,檺?*.DnGlYC.(_(aO?elFqSӠڽYo@(EK0̘L0d2D Qz'5iH)lO픙o'dz JL3QR}()ů2/ޘk:ťgj>4dsXSl]t3$n@;&2Qz.ꞃ3P}0='3!`Mc> y|`ǒߵZ~ >"HNLS$;O\7VpFiBFMtp' ?*ag`V)IДf5T\g#޴q^-$j{TJ&#J#Q@U_v̞\"4F?Dk&NٰwEUn5E $ˎ EH,JMf%fOa -:oDAhj ,lލﴇ\XuAW|# ,$O1QJ/,>M>I#0h]ҠW9&ro]=XևF'DH{e4pӭ&b '),3r'?3l^VUZ__(c@UIm⊩%4wmp 9|c.TԚpwo2 MaSl/5qTC Qb[w=."75vQ:n\/s\M`JBC 7{@+@v"Ƌtfu"x=ex;ɛ㦜@!`3!d$9/ӇEJPSc7 /"әV>duFG)àBSfm 0:`&[uyM˃q\99w_"5vQ 56[c*`BN/hǒCi'Xwd[ <BޣZB2w}pFlл| Wufvx>_9PkJCc&L#++gHtK { :uE=źԝX+4{["#RϤ2#ًp7OS8kWZ p4|֗VpD7ʝk0ͲPyM{ϲ˃Yb3kOh_Z1e$Ddk: R"9 |F%,~^V?/A f Tt]KwSs|HkfS2Dl^`i b{Hg^-%?ݏ=F kp3S5?m 4&_:_ 4i! aZpf5:9vl37%ȝ"p ?.ч٢}MP֓t6{7xk_I*~43WEO eQڌdbqٸg2$k`NQ䔿:.w() Pq% nŰ:&gHJ;@TN~%ұ7G FpSYX!v7@^AF;_$ùof+J0pNݴ&kO_QG Cn4NRV{/tF:`&>41u4ck@0Kx}XkSB(m0_l`w%$5:\&lj=ÅiRаW0TALF+RڤoyB&uxgjQ|U]2GvMQ?խ [%(0̉ 1gOIPұIּv{iGHϖBS}hM%vnu3 6K=׈ rf/Ⱦc}+nx(j!2?\!m f|_5);09Wߡl`I+]ʄU+]}I|{q6/3{G\gGu\Iھ7 J 2 .L$cmCLNBX@2G26>`M :Ҟo)|m5  u[[~8%g\Nt#DgcLvoEnVĵzᴾn?F>R OXLdd{eIJ;t"GsG R]'Ɛ_,Aѿx!n?:ۻ|֩.zZz+i@-Lq)Fzj:jEL(Z"t:YMTW%rL"(zcؔQrb#a? g5F@t D}92gB %%'V@u8$TBp&J`N<Ş8)*p3U ^P;zB^UJ+T# {W< ) M( 1b2KNi3s)Eѻ?BG@'$KJ83eS^ L8Yg+g0"?lY>oW:7H  NuR*H/Ș7ņ2_W&=M87>5-G⎐} %T]am Jvxy)2 $jrXw:<USjH "x{eG#\?3 ۔M)cT ]GT1X:gY#P+bL5ȣƫG>Jּǧ/"7$IQ1/pJɛO.^׳U?2۪B`nmvhv]~ rw> mTZ޿MC<ՌI.)eeM;TYHWxFu c w}:l.Q;/o9*A9 r\ۭ_^ "Ԣ ͒:*ZHMkH8%}`>>A8Jst Mp u%4: &VG.ڻ\mG AO `>L~UP6| r.an]E tF[ IlLSE;vC6L!Yj[\m-*A6ӊŨ(/-Q1(ӎ1ASBX;fFxJmdfP_('LΡS+0՗`}wa,%d{@G WPϸ-G ]+q"klec !51.%Sg% O7^[C'a&AtG \.cQ+Ba/M;clj_폙q{ vxS۞ D)NA.E뷝C&{5ba!@zRKs<Ϙ⅖ 3]k~ p&=&8^>ݽ]/mr֤ϝ"LZ0D0t?* zC:2XT_cp˘  Ao?̷u@fҸ/[y#$Zme^UW صI!=$ !tm zor"SwB.}Gɲh 2Y2npAY8FIa+/Ō2 Ԋ44i˕c`G*3ÍgcYV <-d 5vi;d%XcSٌty,ief8v޿A" \%"@9d{UM* g , Zm2/-ca c"+@zm'\Jjt.IOEEXqZRdLoSJ( oB|F.qdܡA S*,Y ʹF ]<[T@W'pie( TjXyP')0_mjX]炄lz]rLIHQf*TT!Z\#4&t)<\!LTCոsabw! 8X&W+ Co] (1-m Xjk;vS7K+2GƚۼpK e۰)kYAF~|5>zB< ԛPBWg.g{Eّo5[dP;ۚkȪ[lس{=o/&*f%Ƭ?<( YEˬq;mOy%k꽦wI^ %%MU/0oKt V>?3zonmKḲVaA/=lZ25ZPNX4]$ laJ]E4RyM޹#7;@K׏PL\6GIو% 8_r?\@>V!C)keZzh赣JMgp㟞ݺTZudu"9rMi!cRYIXYZǧMPH089 )]E&u+'iC-S;h-dI4%<"% @ųƋ*|.·u}[)ڋqXa΢f`9[sj.:NK\ ;Tnp4DOtTwZv|tեe{r[]z Sxxw`5nal>y+b4Sw!:k-8rz+I"߽# ڻo@Z\uѩX1|5@Lx'mO QcUsZE 8.X. ^` Zi~oCiCWc5t prÅkj] aw)P搇,qdBgNqA b"W>)cw6҈/Av1 ,nb Wx7<3X*n$m_R^32GKop5LiaE`@x?AꞱ.ddTtNdGSx⋪q\r9}/^DKg2Aety,aU b0F1Z?oT ZB "::̕fDUh:aY,;b4;|Sx$^\tue=uSkٯV@x vztn,%]S.%DհFNW \&zF;ĕ.-1/$%J xdw ȗEbd4o4l%PQOQ+;qתR;5ún>vd7I55a˕G#}ѓ'I$e\,CwPc1ͦGK( I+lCY*joү.Z搊xk(Gd1NF~"]V |nK}NϪ~4^R6g1RiqmL%E9&_魍kiMKPJϤ, m|' M1d7w=l]=>Ƕ;J o>S^;$tvIrW0 $jXqWo^}@OX5So7Ywsv :"Sks=ןm#;)Q^3"82Kj (fMZfA@]AGuQb N6,<\C */ܟpӈ\#t u%q&> 7/eiD~Fz2^gB+ ?<5vLZ,64@r߉–r(v/ǍHg!st29a8u` i;V{'\:1uLjNz_ C +'ΌXf$)Wn'ƙ:],]O[яs@V; x@ȟ i-I_I ^!6:7Ks 8dOv*C6 $oeݧ&Dr/==/ v}fKTh*>?dbH 4U+4έLd4KY-z]^ROec7oX)헍MTUȂ;*-bGp[m#WA댓uX.@MFZЅD.QL'qu5*#Voۇ*2\# ?g&r4G}DY@p{7Gv)wwMl+֓J`i r[~>[.ݹ1P?xtqIIܤ$!|ƺx9: we2i"+^):uLTԑM R|>n/(AK{g6;tԗ@Vי¼ٺS|]Ycڣleɔ%[rmuw)>zaB^!61PI=.wV"):D}v ߈y 401#L.PeBrs_/ .9FA|QJHb+JQr?nU?8[|X\%}ae$VBi 9GԔaʒ!a-&Ob' ^,\p^,&d]]@ 25}dAK.ô8\|/ dY]ZiHM1ؗp#XGKH {"x]ڔ|\X&kZ0i0@X¤IP3E *&\*,<8w2[wwpst0{/W 18`VJ@*@7Cvk^K>`RP5><|s}isNF]C Ζq"{YUs0VPZE+?H# "*T t-uO2(;+Ahz( 3QVSkk2^_bΜpp:K g;3ؔųn&9Y jWyN*13/H>Č3"c7#3AX:{~-+8@Ӂ'!D1(E9&L6§sqd:5x2L纮X:}|CGtP#bmlqz]|<سZŌ$#3 2JZR}ad:囍Cӊ7N7J_ =V-lhYNб427O_˴ h"UJ|ȹvi]|+p^^"Yta6nޱ NlbYTmgi^85% kT;.,r~Jc gpLjg8a=MDdcfI~CrسIx;?\˸p't Kk>Æv!PCl{&pvѬ8ojꜿ :D"&P% 6-DR"b ΙYW$%fewbu\y bA9Rn^!+_5$oU4XMvC^_f QXL=܇ sԁ2.8{h^q86ϳVh~J#hңiM׋`R H8BRo!W&P v́T호<mgU& C_v)w#a$X.l?7"Nv %iwLqZcIÊ6?ZfX#cQ7#|GD0$-I7F̹ڌ^a.Gr2E{#`ïKӝR5;`l#f4 l#daXssGWf*$0SP+2Xsy s* dOoKPĚ!(kzH=n6vu,ٮrV|LfvI@lf;%t[ 5bt_j)YK{`|C(kv\Xm-FA?͊ɽ (H:GW^xO]5vC"Yrӕ޼?znXc믻.(il ],Ýk"N,N8O"`^gr6u O>hKv;UhrGSz<n+׭F5Ш}Zp/ǡ<+QE Jxx+;^ ͸ꁉmdU mc[̙=,a7aC{`#gSShB[4HԎ>BK<5 r"y63i"ξ eÿ% QT3ӐAŽ6q$d׋R)OEg랿;y@,\LC2pZ'D4h% &GDr# \.#xM/Uz\e&ug1nd oMIg^-bMKF5FΞ~Fd EQ[\.1t: V#6Օ=@^՛/\({t3}ڪ`yI9?x*ףsKsI֎&$h6|\AƄΠ7wjcp]\y~7Y[ >7a2K u8LK¾Q7uIDs;1@HC5Ys8ʋ,eu㹱FzSf^i~.Jl#SѼԈvT FgP [C01g2^əQ&yEߝ13bj?#\%9n͈v#mX' b6S) ZB>Tb[khx+*ێWރLnN^b鞆 bνoICˤ@"BӖo"aH(Nc[)d/#;Ή'_TQiTZ"IWY5*BA!LzviY2l`ꬖEo)-_R lT51h2L+;h)DXtx+ﵴ݋VU4+pCq|i p"ճFQΟ$deTn]yBj5" g*~]1!$xτ(yqYd0)#q$\,W<,) A2r>[_0~zhydDkEum_/a$݁L?񇨰 zo8SzϨB7G4K\`ѸD5rZt@s޳q566ӌ'S6p!Ԋ&5pZU|w(_Ս]~ħ]п K.PNzij`5d> g.-[a`^)\^byaj -א.iZ 1, P5ȵn8 D*,KyMRc~1glvdTv0H#Oǫ(4[6CtrW]4=X_/ʨ>~76 DǏ_p:4iyəgO\rhsFz0!ƒwfT4Y<Em34L.=ydunKtlmδ@~VkD1"Ÿ93 qT ({X&;A ÝQT?m6`?8|Sפڑntd#dq5`ѲlY<^TUstppҮh TV@bdB|%R3 _jI%`qHM|񂟁/VrDnJ%QG|D/CaLfP~NfVAsYՁ$b m:rԸ} 2A3d8{Pmvz}Vꣲ[eWmÇq˕2EyNn(?jvd`)):f(vdU{os4IaQ69瘭0 #ӶN_ 3"\Ӥ<@qi{ή,aO[\1=$kc -(ϩ/ۑ~8$ 0nsŒFӐe,șhǷ|#rO`Vz'q;Y4}nMggiZMwK!cJF6+GA%8,yN|vbX(a+x\1 EtsAe6b U7ߦ]Jpljz~dn>]=vQF,&'4[.ҙT: ARp`qsTpzlwȶF2#w8KN'z^krQg˂X:Db]MR։aPE] K[,07L։)M Cojqj0|4<~땊m !S,)ʯB9Xoo6'("*g H&;9#}%! C:fz=- K9Ƃ"Fk}i>CJ%_7aB9ΔGf[ܲwhAFT-KjMR΂d&P:z0P(N)k4t{pbA7itR9.7kޣl)|3 No asugd,YH,,pKEu휯Z!'HN7:XCQo! ǙlĘgcPqoi  ,"11&u>=yDԭ~\Ӏyw7`^3kk]ne`jeA}]w1R6ÈEAe:ؙHisصFm<<aϽx51dOllş(oҔ7x)salLiVr Ugl |mI_:u-SZV[|,+oV2dG]NyXnW@yty6$z+4>(hQԇPB7al1咓e'HH@ Dj0Yòvt!;ed>(I-$0<g_VaԽBT#g7cu& :WJc>2#H<{$phM0HuV\ܹdhVvj˨*&L/U_@;(6ה@T^`e>/"Y"GlT,:}:Q7NFR^D/X9ꉇw֕6{/Y;\s8N$lK]y@qVVhVL{K<9Tc;߹lI14L$%E^8;gIՓqr@Xhr5C;;D#X>%rWҳuL۠4PĀhY#GlfQTݻJ3:Dr|"ᱠr\L̰6tQ٥@,Q\YMAC)5^s}"=M7ڞ\.:`ad!n -Q܍_ M;6eAԸ*I?{<܎Η&42ݝ?@J:*ށH+K,LV\!*/g{a l1;h+#z2쓴d<2;E<А~ lSk)o,'($inn 寋DÍjN2DٯM=6=@)x@AL{ěn(|'B!L7JDzJ&n(0!1,kH p ">yMK悌yVCCǦmCQ'nåF=^Zc "4-JUҗ_Y._{%uvw^@vMDEzn@>YN6q\$9M/$-Aݪ\c!b%t5[ԕRjP)LxۦYP/N~8^9ǃ݅?mmOG~KcF8Xl5.o.9PZhb CP9WP5`G@ОrUume)5yKR9FS ZU{ު]'WAfVzpwMV{e|J;L/ZzfԧOO ^S}S抛Ge `"V-їq Yf AIˡz;N%kٺAR 4q%/:2n !+ u/H`zm3ѳ`^ u,Rm>72Ty@8fy=״UB('G8_.(*M؁'ƟT?4 -+-r 'eP+|m~\S"Fs)@bN~= zȬNY`܌rKVspVCWo҈/,]l6lTQ,%Uldd3oDYj@d#JA֥>jo:*߯׻Y2؄jڅ31!Liڐ\dZ{'[w'&$fk蒶ů'y4٬Sok>ˌTj*P]XOa5 [ 9wЫ7p@5~r[+du: ii.b#.NdKz훓W[9xD xGǴ`EΣ"P`'JjG3ΰ0IovV_pt_ {K"&&jM!LQ'm9iB7*_:.1}H2^3ݦ}Z܁ HC-EGh{E$^~ 0j;)K$/c-~Fvsۆd* fp†c= o]Ǜ%n@A:4ګ=UQG $t3}l #HZ+1hANzBdC8 XS\48yzMʨ鲮) 9{A#@#i e |c{,lÇ#- ~7xN}Y~h6u*2"b~ טutZOȩ *}"h_")ɔ i*=c#:ΔԘ)_ ҡ'|*ʁ)E3ƭ&i 90sQ9E7lySu6!A,EYmߋYBu˜ *13 ӸhUN326-OC< CnF.H#/_H?䵌X 1UvPYL\6dEi  &q꾬2:hB5_4nzb͡apA'|j m+̂t7ԛMR-@W{Nj %LR}ߢ+O P pXZV%.ӓ=(ߒŇkPU; wNwj̺wUѰ"b^,C:TfpFA纀9Sn YA!AD0tOY /yVk} HsH7lJp40W|6kFfB<"( k6mO_OIƅjB\fX<qoo-<[%v(IŎDOslԚmTƉt֙܌PJqXSek(g3C¿8^< Fy2iAbi;#:zS=?FK`Ӷy$mjz}mQOmTKxo$~2>d^4pi8 KO^Tbr3 us|bӀAIc9PCoށ31J0:>t=w3L׹>R ɞ3XLv~5n-61\V!-p>itv՝PI(Ge9W2h_ g߲W? 쐎0K 6)y9yGbe_glN li>Zԣ4\ul޼]AҒ 8C&R+Z6bKʢϟi zaKU v9Qε*6?ᾆv֐bnkO3B[k͜$7KijNu:)7yZֹ/AMC8'_'y_w0-UA=طGFj8OQ;.CzdȆ69S5 Y;RӸok&{UsH3l0Й6Dmfyq^-1>1"u#Xë8L!g%q*#js7 &;|v6گH Rs6\2W+f^42ޓ)?/\-70 ,ZG Gx_]aZR})PNY{^z.\kP41|:a!SK({PcɯQOl_ l3 4[p"R)ֺ*Fd`o/Z`ȇJ:J/= Y'mW ̢OngsV&uHurllWyB$ 0q2Z@zd кqF6C1 ׍! Mi|Wǯ8HNI_g_Xb3x&W^f%+) 0I5>W+hptu+qsJ-3 1 ]HL·%t Љo9W0\,8 䬬M}<Ӵx \'wQc@,i`pY0dX'zXPN3MESzMI2%iy=O f#' [t`=aZ[V9Wk'$O:fE/KR:;Ɋf/(ʥj{d% )OFLAK$i4f>of頮5W~Uv>)os9vdؘ* 7+m22ԕXHM;{iiv* hBP%av ~ @$Fc)!j$Ԛj[]GR68Ii#q`OUT\[,@zVz@LɯrCpO ${xkI\e\sqp p:*ZnMq;. K֏,6D[dxDzGY,;bY^Ѧ Rx<S x&iidUݱfE0L,-W$D%4sQf'- N5Wi-qVr$bF% dU_Et:gH+V(W:cBD "7I4}ff>)?xÉ/ s:!˟~$x ntt"y4p}"ban)^sLI $QVBG+ G>*AZTXwO c0 ֜`iIn?5l_ C QF@rVZ1j[$+B#Mc ?=hQoy:U-xj*V̾ }7Ut>p†z2b'we,bY5jϒ6/}/? >]R0Ci*G)7飍%6K"ZG^G8RG|/9iCҡ>Zh{|H ,ڿ}#4iߚ G .InuiZqЁuq>QP^;KmᝯK}ZDll UPG7ڡ)!4dF-TlR/)kMU(;ޗD]egf?rq\w5M]]r(=̶983@>/+ĥH0SMjEbhdg7ȘG8wkps!'ٌENˆAvwMp·r" b [Iq QGm/I^,(au寧RvWRpj$Q@~g>iჰRJk0Y!V?,jvΝ q(Z awnjʉ͓hVݿF#SɝT9J,gˠr^#+O)YɃ {epj ?S2jV vGաW DؙS{T/9C#G_Hl7o7*╧G?D;&pxc klN/Y22{IT&[t6&N-;ƃ5.J$#` mRaR$ʷ"]О0Д^I-qo1ZqlCKBO (ܬ-ViDM(FT0œލ0?Cų}i!0k4ñ3gP#?nB~%9~`VVWSq(P- aB*xgsʕ%ai`f^Uxܒ0V 9hVIk@D4IϔZi7B6a_*-)5,S!~VQp=0ĒK̊c>?-cB4vڀfJL\v2ӃYq)>޼3ɂ5_2q!zh֡@_Ih)=>5aVeVJ[2>DJz߅sa6:,@"^B Z⏵3s?^-ĩh/]\.dʨ6u&3{ IA,/-}nhP/Em.9/Ȑ-ϏN ;إЋ.: Mu,ㅆs*B Tk'8BcW%ɲ}1UCYwߐyP5Ma}vكɊo Vyn b8XL3?o۠[)7W5 C{o9`XEf|EVI]CkP߱9Oi{3er2I %1*;?z +u"9$$8y&3"Y&LS( 5/f'2?T{+V`-S#G=Ie$e rHrWʲZײ4N9w! ܹ%xcxvv2FYrZPbBN[VZRJѨJEMT zEi}ZFvkOتDʤtm#t؄m0c$1WS0#|Z0AoK]DvP^3}%4eSY>B`2LIK$ ?C0uޣG!|0aRWm!frMeT@#+5T9ґ$DOv ֽoE[25%|zaN)b ݜ':K&1XNN0WߟQm|#GQI1{(-fKƝ~8x>uJؐ[ߥT` Tpj'mh1ş#\auFFvbW]fs;:껪fM! YKPߣ` nH{+n`IY5:hg2+[M$ɬ %WoTg:U_{aTl~|a! +&+)ևyЛ)$s_<_<C ][ӖNLu V.H(4] ]1 &P=ST20e3Heǎ乢Az|w??}/d5L~=M_̒s F(e'~ -4bNo׼2G,E=  &UsC•Z66dŒf6|d֯8$E]}Uj Xd ÀP. %jrsn1.Z 4wռj&D9o[dvΙ-dH1*Ʈ-lq/ҙ Dro"pkpV7ks@9o_xܭWyRӛo# cRA=:&2ߜ%etoQ"Ul!ȯ D L"Ur>x;,58N.>ͷ`ߞ ?U¢'kF #%!:\83Ufh`U@h=#C过V5a"SiLPLՁvYME$lK] ÆBe{.v_|c?ly,pRl~rTp+t:rdBX N,=sJ|Yީz1q\#•Z[G~Z}T9/lE4:X"HOH⽾2k`SL!@5^ͣyR]749|:t=LBL-O0N}֒U.R:f.>V3 92\ 3dj\S.7z\m+3 >Vߛ$qqLݡG9lYՕ~c]92ȣ6NLl1JK<ۓp :\R9_˶H$d`@Zg 6ueUrT{BIP/ ç];p)wf|ZvjMGc@|Wg9H@מu9/Jַ5,  ){RQ M$iRg303FT:Aqd@qp_(7NJo Ap'`G\yq6}(9;l˟0=H߹UndW=:h_ZɈuCuRWT{groDgL : :e <ԩU+i .~E^""~ha߸F #( =9Ӽ;-mL,: d<[Qv`U_}% 

lOPgK|{ޯW RT%'I¸!?a-XicI?,Gқ}su4gBGlxH_XRk(>6 y~O:' -~Uۀ'17?ݽ#wz.nAw[bݷF7EV!}5]t1Mo^SW`)1n%$~{n{#b5GLM*/BBiȊmve.L|#m^o@}BIґGt3l+V]xv}{ID|MbsZB~=EඈfL1b*Mi9}m}J!{1ktMlFEXI! +%udڥ҆QCYiKcY0$PuO/tN"҃=@Фco$WoT~H.@ `$\?*>~%5!O,y"o2$m~vBݙ[5@V"tIGԙ.8Wұp_ 같Fc6[ .՚9ܙV?FMЊmG5ku"F 6|r r<ixߙfns5 @PwrdYiPA]@& a P|E,9o\D~QZ3byk/9M^4Ȅ='frlN1kcXwJǺv1{̔!~WȴD40l &_NI4bħenTXCXBL-( 2UZ( CැP)CcI#9~K㱑CVzVE0 }X4IYϾ|C \|/ܜ:%W{/g$u=3B6(khUΐ mg0L[5dl:bw@vdLZDj# 16m9p2О"UiM8,IHA{-7Y[.hi_ H9qk&t3;2 9#%ioRta+Zd'[ˠpZvCPKaIKE 9QB'GͿt#HaNK߉M;W+қIyӺ5\Q6knC+ZݦJ#[[]|{0?!Þ@#m20R0LGMWV_d U(d4ðfXV&M=n6fL7c*BO{} *nb&W|J?v|!U緵jÊf[PE)?dGMR@Н)7:67[ը? (yдi6VփO1~SxIPc}S>o &UK*}2_hɀ*b߁fȫ[ JьϤbptkx nkʧSv-W~̎@浚 :?(4{4]{ SV!ѫ(ը)0&L+]Rх߸}wRYسBo{4cDo/b>~-(;i(453#27n*<: _$8q$4GWNFv)c]w?|}D$\m{^+ qAl]3}HΊ;tkQ65g你Ͱr-f9x EՏĦrxOߤ)H=TN`9b,<"ocb2iԄT}v0;L̽&s#qx9ioN_?O)X!K8Tu᷷`YbrRv0(؄)߭t;4$(p9Љ\%- 5;edj'wy z{9$o mr,wqGAҮMHB/,FpG|joqԲ|+iP9>K[i$;p\G2T^d[W5alnѢEd@JfˡeN!8Ƀu6VlP%xD.:*b (λ_,!`3a.*fF4:`LV\v,] wOv,KaLAf֡T+|5NTWM_)+aI5҈"-[`rv  XFMpF*᪶݅<ݓZ Ttjô71&b[QG 2C ]@<"7 e5lg [&{T>Brytj^JMd5bZ#i}SlRnzrdIؽ^GS= Xg|#B~Dx 93XϫX-nvn|D̗MVH"xIub)ّT.-ihʔ跔g3G (6T A> YM1 ЖjT(q}VLǎ@Xl:1Nx'5zs.mj9=˨En%o:VO6F'hԉ~B~YXpo_0P2xq:+W8y)D m;Jߴpuz 1kLr?2zzݚsr&kRdOÿ!%K"ó$) \R{ Pᆘ4:VSБÖ_#= wG9yc;X ~h 3NUid0r'Mfi 1!4/`܀_UWf]Za=jO!&\ӧC6̭I>t|"IM'"i0mCV-k]ܦQS\IV"O ^䦳ސ#0dtYGJv{>sE'5tpK[")z{M /hl@b?8 [KI tve @/]Ho:oCk>;4R)gDXY[+=^ bZݡ 7]@E+>llxވI9nKdfbe9?6^3ѧ#C@b(^8փ*}߬ьo*Ip %l0g QZKNoaa9I#ӡ u3Jy 08$N?=}o{d`r5Go0曯d/XI+|/G+Uݜn1r'𣆭3MlBճCB3 ؂W v7OFola$ל D*"]пj7l}_]bxMd8;8\Lߜ^=O00|Y)- @&@  ӳ5aj)ApCco)y%YJ{/촹fĄв1rM\1bé# a UCy5ʻɇ _Ts vع0r/O@i>, cs7#Pncpm'P6~xP)chG2B)#C+q|2MFޔ qiZ !II:tˆsp%2">q U4*G8_tNذ JlkJp/Wrqّܻンiy^!y e@whW{p :]qPcXgn{>B8$pd]_bJe*A'\t V vw2p?U-ѳV@0حwuWʰzUBӋټ_5KzFԶjt!uŠ 9 72-oOjy4&XT):56P$= 򻙕B 73v\-S>ց@Ě` _XV3=^2Ķv9Da2QwAuWTc].\|*H_q)љEbTOpu!\(#.Xx7ص _}:ʠu˼%~$"Ňۻ  BFcԱd Gat,jn oP1[dfۑNOўw:WC6fч6+X#Mx ?GEΔsO [|No^J=F3y/YOo6i ֳwyMM*E4`-̗^3o:gT_7N:RpuER쎨oJN^T3^Z<0dnA+pT-gUMp\gDzSٙn4${]k镔ZhPm '|>t_|Me^JyXypMptV׭-~g2{rEɋ܊}CMex^(})Spns?yHklpZ "XOok%:t_RN-3c シPLDƤ&F*M;`SBr/bNٵN8/D?P 7MH$))\̹~2/C>:M;y*<#&!POػo/[W}28 lY!ƘbLhvi{f7NA)]%BN"-e\pGT3 (Sr?˛fȷ(Ͷ-d}͘BHZ EMae٘ާINcIYĬc,@c #QہU~yc]%4rKe! }`LK_# i ^YTsT~. E2=rMfdw8 ຝ`( d#(C[-a/`y}'6+{4R@UsFB-n;]8E+M}uH*./Ȅe 6A +!G| Q..:1VR?i^Ek+yΥ2xzMT556480LktBsv$vODqD-z-l7m `(]ȝMHQ. }n9#+mz#IE ރE0x^E@sS~kbs[nd+b=Wgb+kLtE9 1h9Yh;~dB@p2;PXFDXs8׽pthC-l D&C(&ؓ'`_ ZT{wx`[AAtF]Ѱf+fYC O抽 #,Ij?I, 8C7zF1B&YK⨵<6&+†(r.BMf$R!,YZy'iӄSAtF*6;UO9 ?T} 3n^UwX$CΫnnV>VK¢np# >'HqԜkn`_j xw͌e.3yRX 8 -p4-vg\b[!,(i=-V*Y)OC*IhH= /MEO7e;u̇M @g؈W @9ُ ZFUs/yaR'`sQrY@ HoCrcl; ;,YNgR(g"*匆/e,9{*&iŁ xp/' 9oLKQQf=)_4 _ô KJu, T%Ѯ~mp~%aO}D*m,E@c#)bZr ɴ|_ +T3r]RMOwۡ_a/*uK|QlK& ~(U&B [WY[ jbyV!ܶ0]1i=;ҺNAQ+WYH'Q4Y74 LɡQ MRF+>3eaPYX 8Z aYGV>0 d#W9S= 9I6l.c@*:6(U4 K 7{RA%% p"5}?R*$,g8(IYr2K8qR*)+ RUځS^ru7ѵ`vIVW'2fW mMrH7/c}4cJQfTIsA"xbɌPϖK&{_X1% )qy~STHAґ\ 9ܘlM+Q.D.}oѸvsNK>G5> sԁՉo6=*ׇ{8{dAvk9+>M $=YWU͸WZ^}K@2 s|`d%x: 3(XOPlo HJL3s.;"5NaJ>;olv551ut tjY]N HpD:W$2G:FuHuϔYjɒ6Ŋ+T ϕ"lo[d1iKQlO wm 7[uՊa*z :UbI: >u`d2YwAP-Cu+ZaQ5 +t.k/ەTW}+>tj%Emo8zDN^c12rlMmlg/<:ڑ+$L5w곺8B:p9xְ5\M#D̊'m}#֨g& ^uoW6{w!(.ޚV [  { gqa41aD1d|[bը7 f̆{-y=csA9߱/u:S[>0dYdI/K JnhŊ%$Q%KI8c KXv6b,RJi?O'i)}C]Or|iMadV]T7ݒ#abe)8%OO>@ALkcyU-9:@%ULlUG< W4Jb[x E8a4 >[=v΢cIreg+:D:kZ`%ֶVxC|VnCnzֱ+&RC{Sn2/Rs (eY4ۄ04t˅ou@"bUM_AwIDr*; ;bheAD^"|y6q),@Bqq0Yf:Ȇ`XKdoCT]0KH9?đ&kqnؿQG;Ε=U['7۱? Ea'GkL<;vRe1R?ׇcrU:a?7-t6?(dsaf-F|Njڏfk!8 5*JKqa|ЍL{%K+|&,uФcS𮶊L4L1CV\Ad޹zq[cG<%D(0J2wQbN2˴݅p.:Od3Nzc^{V})!Am`B+AguMVtS牚3^3 )2 $ t}QAGm*'5\_2oL0q~ 9XޯMM>ܧkwF QB'8;+wml=XASv*H>4BBpAK[A8b6U+MزV97縡i9g7iHP_B^"s8} 8LkbjeRY3UX%^FKƙѪ>S6hvEAϔv.)(iP(g3u ?Y[:8 pw3C N >I~_V&yz{}ė>-D+I`A,B/ V I%=n 9cL,Ȱn"nlK^sgSJ'q~j?r.J k0Vِ~fibڲj-Jj{ \+ZK/sǕfяI!Bn=P#a=}Xٲ|,gG\Љ3uOqbc ;d ~~\ %&ؿ`VfO輚/o?;|[6L`a LQ|0$UPrʘjUd7J6:S5hZ#'X cR\h)٨r<'P]t7)%f4f{H$r"ߛ@:ξðg д ΄c/=c81ð?A98Sƽ;<u(wn N%[^B*:\ {>CM+᳇+3u(e|:tL296{BFJ'IS&X&7"#zA{aGK0g.JwGocKr :/= IBť H1;*(|R]|ƟE3iM? =Ĺ oϑRDU|Q 4CMs*h_zV:";VϚyɀ+V,dM& &z3-cUUXvڛ!־dxmxrU GIP~iÃX#IZO}P4@a7-N #/i^+ˊXBDЊ4Ce-s_g~.^6M;ՉMΨ`hP=|&mʛ%*չ\B 0{BXap"`DM_5V;ߢS޵2M&_+oFN$S'">pl)fe'0sІf`BTz,C^,M٘WmfC_g/mr拥pp̨Ybϱn3*wkXv*:OsFSؙwwOf%n\eK02(F=ϕ 1|E(l(aŁ;Ӣ XSk$ HCׄ0Fv-=5kI_:cn ># zuٹw_͝WĖgsg9LkmǾRfP_-Y:pxgu3$:1VCmQ3`L, ,#LJNnl}ݐYL=#y@,5wk`+@-cL4)'4nsYQYo(#.bi1E; ?r-sY8G9(|-MvhgOQ?d Nn8ZJj!D5Tqdt`<-9ծv;QŨ@.v?¢A>8%j5 _uO,aŎ2,FT| ҈1F+ e2ϔ9RMP^9X{6J/a$JLYjjslQ?y ,e ;m;C"*r"T{\))(R_hqIU-ZKx8ϟkػK7pH "qi8_"B$:&i%b#@6N 9!p pLGsMɥHq{VD*fE\ Į  9D[XdVJ99Hℇ*x EZڹc^͔@X?^ 3j@D1*R9փ qj[u0Ü9ʨ;Vl*LSI!6)7a=KL1O_C,^Ȳ& NJ}W'BMI$| f0V_QYbUABw2E2߄azzK:m6уeהr*a Gss0;~ U~6[yCq{g[ cM/>*ĽǜiwӮi,Z$N-azWNCSLj!<=רK*l4VX8'ֶ;1ID/%=I,Z| -"J}%bqf>&%'d%Lu*v5j9g5ogv}ڭ #9=/b]c%ʪ X-tޙԆEWEu}Ǜk@498(所q hQ6&rUE#T[g\7/|N).E@6^]q7G8+px95?gQ?RYj~2 ۋTKA&57T!ewS[xmV@ڂʖ9 %7Gr+ZJ;CUn@$+|[XPL<~]J~i(ԺzKWWȞ7HH7S3 F<&-2ʀ/ #cؿͼ'X}?$ytILY~ږ,Qp|rJ8(o5m3&c]p0[MFs6 bT"Xa~8sn8\ z:@PÃD]N195ϩ'G5b`Pm:lVj4S .u]6uK-0y]a-0jvd^g/(ufRdgwDŰIK? '+=g#QdǷ|7/ڝ1]󀌐en.XX]΢QQ2Tv`ɚbu0\)l6dgb4{T ]ccs녫^PW7SMq DP sΗx{NP֝C鞼5sMD`Cu1f0CdPxLkz*2wj`KxG𐌓>FhL]]ȧtM41/J f1Dw&҃绮d{3Y(- ɕn5Ro2(eSX Z,?Gr6ƻկKu@$Sn Iη=OSPqj5E8Lҡꠠ`/LcMd5 @gʁ6Yjq(X6c:6XRSgbkDIbel`g͂F-yOrs{9Cpv֫Ej` bkK'h ,AQ, O4NxzC0\1<I,ϓ:: 6HN*%k>emm-7Ƿ%څ"MI:R}:P43 B>=vv;O~LOR:Qlw#[buiYݤ8e6TM`sN5~֍xXfضFPbSv&WD̘#"s-ÁN Pqѡ lnwm)PsmA^yM-C4:PwAV>46jc䀠j/#Gn%a>·{O4[z7b7a32E57s&߭b n^n#Bի1K. N VAk<"ߗ^@'EeȾ65+ AbKŤ]y~BȘ0$UI-l[=y)pByvbT<9\ndK 0b' 1].޼P$'5?`bw&XZn?.޹y(k"hLY3p~z$4e+="H^pUě$^aC=,RTcϞBg_ឫ!ZCyWKCK>5ʍՐm9D_Cpuz"$sH:1R=P-a_2 xV |PW=&ધ<|H 7jO֣LayaZl235Щp/\vkpI^%*r̨;rtEw{)p Oz2Y:VU{Itu(n,(  [MV@SHOo3QV7Uœ!ӫzX:3Up=%Q银e"'zq`3HF1S]'UQ#FMsܘ+ԓ}.#+P /">y5eCaeg:Y 84r.;:fYAhG"4WY4'WUָ0[mŅ@b]B%3S@63x+R}),{c0t`GNF'Ĕd#82r !G%wPo;8cЋ:Z!b Zz$uL✤)dR=2,6kh 9AP!~]%"TQon@|dg"L'^-(^ޞ gpF*7_#"GEpjxof:u#88pӛRܢvI_}3 BأuȚov͑l"<6H`_E. het"a$3іfRlWFj-\?8*BmUYVP5C{ ^EcqӜ*8u+r:1,P˃IH7=ZΣ*P]NC0 t ܴ]3 wzP'אמVK%NnăܣkW: wϡp詾?O_MGtGLNi"NrzPQnJҏVK K*RiM"jv7OoIfpQ+`G 5yiy 1Yp΅,(-|Wd%F mv6߯4Ѽkpf-!Gܫ1<.W8ɲ¶U-F` 3h [2^$lrI靛d*gYV :JpNk`I6df"S%ǚjJlDïL_uC" ,J=oZc긁LV!S8WxK:L-GEod SɄwOGqJZg[:ojУiv/&jOU@G@!&| =9v"H%fVߘ([ ͚5 nƔia= -3yVq?W|#Df/N2]a:qe +-`݇`NH=[_ ׿Luu3_awzWYhTE{&00$/`,د@?Lw*"EZTԘ]eO)Sްwtٴtv&ը^5տhNjcS_2z}UMIgbUit-/l oDkzz*Ffʤ5:rUr #e*g<,1<0 ‘2ƑU_D}jydk7x4?26p%x$os=Id9sf`O#w3Ub2$ֹ]P0o& ]%'/$KM ȽibĴzŨa9Yr³7 lO qr+"vŔ'@]lDdz43N廦=UF%jw:x4r~zFçZ8Ut+0k1BȂǹ{LFYˋώU0 1e?TwBxz"AEHP^4E`М^"3lښp@) $d$N?T]S#r2}-_ |Tiag򯴏FMb8 p$m{]܅4 wH6Mh۳ڐި{q5pH*J 0譒|xl+&rl$F_.W!V-@h%ulXƦ4R#v-4і3GN`&wrՕ̺U[{zE`x ŎMƒ,P gmYCVDPI%3@ ]UuN+AdѾYc{.ؠ>)G,2i@'p+rtvoD{ )LaZ=gvF7` Mސ&eQ1^ @ ı +``8tW5/3fo}D׻X!^O̎+k)\؂:ߜPx6̭WU [f2}%C<(~#hpUR&:K )O,zRg69݈[`Z/GLNuO94/)jsIhM_8̆8݈V2dO-&(WE&i}.Lg9>D=@{\]g&\M\hR穐xthbμ\Md QNE4Lp;G~<2e6ǹQoY \IUK TaeQGWqV~+:[SP0dPTuplWv|@>ɓדC3X /G3,iK/4#D+[d8հ}቉ōDA¾ƬiNG ~.9&N<0al_qv0v[U/7{ɮ5JolKGaҟV0ilֲA>Rс%Nt߸}}D-tO" L8[z[cJsm#±&x-d68`Kn}QPor@s v[_,Ї9 ex)Fjuk얍&Y7,3!y\Cٝ D`dÙQΎuA]nh *O=֖Dls\#V,Upd^n{/4LYs`pco [D;hV:""ndlxxJn(,lTK}eΒNNi.\$m/ I),4>m-m%c̘PiP 4#@.2"Lէol#qA4ŠNd]W6l-`>M?%]/RU{NNGf*5%_}t E`}8QD eY #VcLvߣnFaLJ$5]S-nYy\L`O0mEC:\FPDs6OO<ӱͷ֡X>)<5nuK2b$owky9x=Jm5o":-wFi守N,&J%1q66=|Y IRO@"CzcQ^(5,YAWCC%RY0dýsOYκmeݨ:ZȬg#Lye直(eYJ.oӽBI"5UTMt]V.^fd -(o-PxS9Yyrc`Z+Ϫ"]!)ѨQ_F{$}? :9WL+FrKi6eYeh` JϠ"A6Y( Q۾ zu,Raw?ƨbRY~W)3tp=Cy}"n:SfGƤef>uV*bv񱂓/e-k*}o:h98KjLU}4GzY 缈h3&.)X6cCt܏ KD\ZcMN?W $[H]d׋(p!dFu]"퀐f#}_ hMCd)k]ZIV<,\Zֆqta6Z +•nl?Ua-PF++\,p=jqG37 wY|FBդrsz.F \IZΎA>n桌+ }ɿ' jC~|Ԙ#N$R/dkgdeȠNÃ&4$rihm}BgK1M YK֏NB RKR7DW0Rw~7F ޺6rPk00}+З/r+DąR-Lh!ShKr%wؓ !(1WgXx_a-SlR K4 ;%&+Ks.u Znf6Ӗ~썜[. pni6.ld7̝ұڝ&]akm`Sw-\quUn/M{q}!'%xg2;AOrrK修_Qv ZbͤUJBfimGmߤQ :.ym{6k+N k{$v( 6<ٺLz<`ͨx$:U܂ռL"U@G6lĠ&p1=ɾKܾRY3Bx8]IVNCD݇̀ L2qD7K]'lbKJ aeut$k4kP@48siVoT&P3/7N.и3F wgA8 ( ٘pNJN"◝{% N+i܍riR)U4܄^BUxKvXy☯T2_@۽8Vܕa[e.qqb5SY r xojΝ:%.hg)k< U*jASFA:tRϰ&]'Iȇ0~`EGY|diؠ4j{]8sT IީA+\ApGw$hEʠc`mkq?]}OO4{"4|S=$9N=) (GOWglKe*'#(h`#3RJ`B++lݷf`& =zS̑yQS>92{o5-B ߸([|{垰ԭ[ 7`tq`>Ϫng+g}HN67:ŴH8)@qPnw٨ګ/'jpmџ)O +Hc)[y3?23(B!ԀnۼG\Td \ōeT.f Pm)Fkڣ,]=Fq=ʋKC1C gbᣓFDGFQ`v2u)hpM k=]7} Ya,$h*n^5'͈O4ʉD;Չ7B"%CNQ展1O^A?MWzߧLz Zi'!=5}N>6S%mdд:[2W'*#3}|&ԡoH#I`nۖOL;/aQc-3yQD]zVm#"v>fi ]ҥsYÌMG):%3ozRpK)\/CEe[_#2: T[lշX,cL\Pl^+o4{ٶ8|6XR `lj3SB\^|јkI ŭcn{˻ &%Sy${W 5)IgѼ$ZN_Jt5,^̜u7yV.H繜WJPR|'vEmv^ǣwN=j|# \KeL`I23rOaf̎$݇i P6x^Yt[m/‡j(Q:X|FDA|m\h8to1e[HD g=(,p԰~f]4'3BL)$^'/D(OX̉kq . #Er pH1M.x\ v.U(ca^r؁nNڛqob@hCPQa^;8xp^\V۷t.ئ}JDƸF,kj'iϥ}5]1N)ᔝM;J;Sbް(N'a*$ia X'_#EQ!]˸s'Pb "*cIGT9ꒆ=Ԟ߉ԃbVSoNxVytp<*XSge=?WˎTWP+.])HW =v-V3o߷d5-#P5D+m{;;y*j)? K {CM%jMV k(^BNЉ9^ wW% 'gO~}|yO1AS}i3  1ٕEz}1kz;F+/&,hAHUo^kj1?U`M^)Fgԕa1eX:¤{ӑB6hZڹvl)ϣ[eA5kfA\-!OR]#gɵ]5P_]]͈hO[vFU_b&r/uنwϿ%3DU>6 >WV;2`G5KpJjz }l=h"DNTJ Y泿89R9dRl ׋-}09DzAޡK9C`LJ vc9LOoVV=E{SjVqfu(܋|{w8bxcayNu!kX>4w߭Vf+!rQzzZovDwi*D 5:LSt_I}F!AD`a{0,r6[C"Q5ټ>HRזyQwN<NZT0|DW=W:}<;OR'͌xEF _~#二hXUq{AEhkmvķnT$hi RoZ=~o{:"e+^UeWG>Xa9@PPAun$ރ7%srfxN.S\5b?f T=< dD͡xX1'LdAw+xS՛sx]EFݵ8#ُdvMVyEY2zU 1pxH^K.X;}k |}k_UF($&ewwW\:"I䦃a8^}e3ʥM?>42O&@U |:kOקL~#uwp:#ȶUwBxBf" bܵ\,.^9a ٢!f5uE$J@ e jvŜSp n_lPNw}Al]W=j^$3Qmfo52$"F$/ksFV/~ɳzpY6LJk4ef1ٓ)(]U~|%Z v)tEzY eS_)5f- k3N@:WPDIEp}TqnDT9#86^Q"7R2Zng6ܰ˵#*УLCxi gwlSɚS~vgy` WuGGQXj΁~'~]FeDL#z )E8!̙Mŝ-zj-!=UOCQ.ڵK+(p˟XF@úՓ# 2/iTWΫ&]c ȗ],?ҕ*4\uGwN{Mj*dW Hڷ{Nw6~e tD ĜyW}YkJ|Ay޼d2X1L('}3sMF:2qaHi9_%^W}?֡<$ea# (alrɷzGi /ц,g5xX1 4VfJA+1}[* ]7 <7΢fĪYME-J"X )YRwSgړ4>߮U\QNQS-Tg⡍auSvS zoX&5+A2.yʼn7IiRn$FP6FSI9r?b4hC&rY{bFMH{ =u^ 4[,Jusٳ bjkP@UAα lHF{([x C K(k n d Ui}Az)3)y~)~V1}2: ՝QF:QDD} H4Rjۢ'Fթl dkL`cohsѭdPdR,0؁U&`!PK9[.3ML!9vBig;~ Hx eQ:C ?6 D2Iޠk"iX_HrS=!hjL>4laC0 4ޮ@$žj[gEk4N|q.=Vw@u]|j.?uѭon;ֵW:ѪCwFDi\#'h*]u tk2Y8Uh4b#a's~kp=9#4)HzobvthgH֨ܳ?($Q)*@ćk> 7o}; Hyx2o# !JR]ilHythHeR#֚p`RhO瘁8.Tp\aɆ*P{T#Vf LWrsCUl[Jĵ9rmӄlW dKz-SMQ5i?*~P-"kQhTRH=OwW.b<޲ PK2w" *2 APZ.-sGZ~C.{2qV GE ޒFEǯe9\:" ֛(!Tbpc-mJTBHLt<شjI9y7m[6y|E4:9zd+گU5tTZp^17I#Y CˤrwА4"O谲$Ԫ<,쾞^9MѷR%q~h'Eu* :., #X{M2%pY U:V4cg$r4[Bm8l6bT̞.N  A]1n(i$1B[5>0J,Sj- ~]'_a͟\}opV&5E|#mtwE(Cs^QW@:Ҕ1gȱZ&%U!#Uؑ6YXNo_+4K>I, `^K]ܷR˰̋2:(ƄeEf\}^v[5#O,F#v*?9~~OHTeQ~1Uv%a`/.Lx`{rUNb3# 6j\F2],# U<=ݴ8;s>@m!C~RC>Zk4>4G(0/f2|.b:Īǔ,kr+Z <3tתYFIHN};KC#7Na}xHv./Ş~ _G)B@#i#"oE[f{<'nwȚC&̂ޖQB@,!KtS8`L!AfTh*¦}b|y9hQXGV۠clh"3ZF7JΌ9MUp**+v^n9YvRQ_cCZ#kpb`@Qz'R ⮑BǖIpVОlvW_yhK=QRyir0va#:>4שǨ[ Aw,.\:V[ڑB>P^ }wy3Z#bQG37Hl̎Z~7dpORee-HSk2G[ OeDӧP5V>۽) om5'& %GB@tqo9Vw\.Y ?m܇i|d7W+<R-g@%~l:v4w>oJ8kEקsr Ѐ?L.=}1Z-S4GqfCL_*xQd w=[/i ɬ;cиzWW! "TU O+15ĤKL%.Pr@u1ܸ~Oiyl3Q&p_4۴ pxjX; *?eӛy&u_z A Brc_S-}|0 ō͔ac0vAµWMHV>}.#J"#e}a rK 9?Q-+a2J/|9&`OXquυ#S,$" DgeVQKEꥸs۴ebjyy68E ؘ/[5j/lNFDE1$&yɸ@ vo4C{-!> pDʱc$ߔ6Hݣdаzwvh4Ŀ ix/&ъ.BE~A^WG0AqX#~.FStkM} E&8OI<؈N/}cO=b: Vk{28=ҕ;P `[ޖnX "Mjz^_ u}FEp+'Azp)Ey^Oe7f Y"45?b>^#IGy~luه((?וfK84+dKB?}CLNtxm^mn-[rmb4HSDb<_G|ա1ɕ[%@"-L3kd)\^Չ_G蠲Q"Ή,zSnycj⏤fQ`:]xIh,grzF ar8' K~dyՑAuUݶ1P#~^V鴄+(PA h3ґU/KV/=u@(h @%uM8{|Kx!&xaP-SR>X\,6=P:y'CWbO[M.7͗xcjODY `kDYh'QV8˜L$89D9p|}9ŵlVGm7qE-L|*ـl_|,LVzW,x}h!etx8rmXcU륌>&1ЮMl]u#!2vgƚ6m꤃#\5gNf.Joz5okq'cVdg}F;ZªɞHM7&5PIjM@71VeV@R"8ԛSL3~ Gك٢ Pdw&qu>9O e3>`f ޠY[xm$$uel_}{-{6{̾LE1F&YB^4^!T˵(]L,"7@b} u_4xnyzuy"zs9.nS'"W GR;^XWS!Jr2XIu:w\>οHk@ZC+,l|0?-t9jN!?ڙLZN@7%SL d@~Kcz{li0o|-e3sNGL݊R0w̧qaQ#] ЂLH%鴹2( s.)M6aRsؽqkU mAFP˝qɈ;G(g~IC8Pe oJR0P Tٜ^f(9[Q7@~am 2YW-G!=Bd^32<!A4Nw‰h,C%OD:+YCpm C40"}lE^Xj݈;W u+a^$S>ilX>=Ș k%‚Md!N [}/׺٘yn`JwitXyQd3{{\hmxСwSEFho?.)*hYV+Hqt[";Ew@I%6HC"W6>Hr~1+5"j xD%ARVDH@_|\rS,a`IǕY{[`]$[V(ZAu?wA'P1P)4 cu /H=`j4-_gօ{G!ÏMm:S8#b+qΙӎS$ !'5Ha#ݙdl<9[<]|iNQcS̠n9_ A/-#sj CJ93c[]!TYq/]"7,6(, m)Z%|"+ah8jR#oUp҈,:?}7֒R"6SAJ|WIPOa!O8& ш! w9E>Y<6@aX{ pwr񄃳V7!CWÌ<&SN.Sd:T4W [T8+m#AC4XUnUg mBE`Wт=Џ8%ZEXڱ1[Hbt|Oc;(0kM|0R(o{Ezђ4'qAj5uϫ7qS:&WE #%EҾD5.ğFP3Ip~~;yǾ)aWf SbX IRQ#ʛשn1I,EMKQ rcnrYXnaV&SԞ#c 9ȭ׊(̱h}\{fN`@3sa"_ ~.!߮¸9s8>4"iZe׌/Wݵɑ'ہ !Qb}&&cF%} a'!I#x~چgl1xc]ݵ qPxF1Q2J'IJsd@ux5eث,(̥X3.*2E{*Q}؊ksT`"3OЄy92hte-K<$VǏҹTf7P=gf Iy,!Zn[܏.Zϳʮf3gJ#\z#t }b3TiE eҝkL0l:pc`WH+މT݋M lb%mp[_<>hIb6{f ?_l+y~: k]H Jugv$K-H=iPYLU$zDoR;qѼbw1$zdHF}Qycqj]-~gI$bg ]K#?[63u3{2ƌ?&4jX 0CFƸt7ѻȦBc3Ä$Jו`8(B(C&ҋW{BjNG'$覴SbT<|HQ$!轋ȃ&Yi_Jz@gj aҽ6dO_ī7++S [XF.L6@C$]91%$Puuq .)ADD˅u:(_jCieeйkyJ;жuJiH䤺- VYwT_=y -kj$@q uSxpf&3?OZ(ブ^P+Lv-jN8T@PXprT=j-P =!nķnDnPkk  ڡncCEg)W0fm'XT]$K(3*tU]\Bn,]Ļucdֽ>NA5P=;*{h~'1FF)hP0KԄ^<Еⳳ|M`_6r&R*AG.GJ6&6QfKj!Qeyi kV}0\QK޵EmW 7Z}LߕS,$"7vPMr %ws|iHLӆ-"f%)2߄ Cf^&oڧ}}ifw"|D?CP޼;*51 u | }o|0Ҿ[)e<}F=[0P(VLN8aq ~:# yU9>+!fȒ!(Hu~Kqg({tܨ_̪n?lX9[O"e5Y˳ٌY2$aؠp>>S;?ԳU7ҫde&)Rn% 㶗N +C[p-ЕU?4+ʕV $^R_4[΁S{[(µՍ\{A% ,o+k4U'wDֶ=ջs21,E̝pqd|Q{zץ^%d c#ӐSk Q\`Yaua5v,t@ aﭘSo`n(Ҩl_+^+41l:G{UI kq'P~>j{R`cE(.DXPF.R>TQ˭(n?tNȀ-3OXD (B*,ij/s"%[a s=1xt :߭ al,p=._d$.ajnq[MD Sx+ z鮑>[;tn\=^{$H-x3;N}tWxnqآէDi&3dzuں<}ZfsOOc 6L.nldPY*7 H`?PC BZ"ӒvE8 $ʬВtm1pxD~)E%8PK% C*?mg$\ 8O[-:2H"xt:B RqB)_Y":?W9 zcL 4FxYT x)VtsOx+Rdw04HX[[o_s'G>v,|qX|C&H(Ű6er"t]n qjᰇ7N-#iԫ(w {}.*ԎmaI`r?c0eIDpULr.w']m"F.ɻOe[,jv^o(zn]~TGx=]qZlXs#3)nJ֫rFDyHK=tRn+o+]{ 1fqǑsC2gC;$28 Y\[s> ^6=NX30wF?po{& ׁ >I;'aTkѯ" .t5'ݷBĊEC^[(I,:+#"Ams nQ_8̿鱛|إe|䎢"`ENXB~N !#&IwRd=/Ÿ Ĝ-g^/KF@iH?! @ WxDGӫ8App>IA-{ ͿxbVm'#!w@͸'4A%̭ouD#_|<ǫZBq$M]]{[))iA=x)q/C IDXmtf- Fu[MgiNRl82gBCNbgR8<8KX(UT۳W@n[+U3EtVّF~] 0񴲲L0N\HA}#ʨY@&/- ս1bf3IdUH.nphڛdVW:2sj?{oߵ"8厇?ǬPZ-.%z`Uz׿W 3uVO&|,=p& @fRro ,^f~3{@"3N ti]Q`S)K];I0#Y*$dRܼIv 2lVB+kK=@p;%ηwI[q]LJ7:0m# ydALPYS#@kt/dиւ-/N/P0w׮{%^ҩI0_tց>:zceƯ#ְ VCuƆ%#2H@yg$$?93.@ cbH$IRjok[}PKH@fL }0t܎4ND#Aχ̣\ 6<˵c P{@NSDUG07 A:FKE^x۫"kpMGf haŒY.WmMj|Sxq>А;/ :8MJ0q%8(q HJ* IFpӌ=vG4&f!tY:\d!UݲjW/CH̋q{ #W(i  PVbkU̚߃vyn֓-=!s6+@蒈eِxB.砢|o^ܱCKZ7 NL?p:|.}\ lcF+\eSC8 r^o%ipjeЃ36͊fHV?Q0 mp܊#tuEZbCSWv \R]ҮՒ65omQ-4pz^"ɔ 7P+HGh_Ĥ<;8!5`+ ˑ06}@zC$l6[_^ksn^Zゥ)ut^޼K:CbH=- tlu X^"Cþbi%K5$uzipce;x)Xމf#"\$QRj"~^0Y*׃qzOН3Sn@^҅`%n*dNYVar)qʛ`kdؽ;sSy^inOp%PEauhH P%>^so 4EzJ3ύQ#yؽznwxOJf\/٭Yt؏}W]@@Ȍm?jbIq[16o<5{t/`-L7#Ȍ볺4<:{anp!xŜ ciDgvS;IU]-C ´ꅺ > ֧c5ZCVJ&p0Jm\ /v,HY2?a^}H% X+"&,Ÿa)paqgfmQK+♭_TX5Y f%<)];ȍrH)2 z[#Rፏ 1Q Ӻ&.m &̺(U?r37jsr.=2{^dEi!^lQζQ* K0g0?v|V #7[}z]-sM8=lFEkm/*LuG-f8- +NW, M"|yb `ҟFVңzo¿(Pc+d4ɷJH?C\хWUe׵臮\Rdz2 y4I e1^*b^6PҜIHl,x!N;m.4RgjPRʨzui3+`$fj"3f5ӆ~#n-C.H@Ne|%<^m6Ǿ!ג|wJ(T d0ne_laJ5Mx릮_W('WL/la6UaxSUP+g;c w ]$oϼ0MM7JlӉwa{c|bc3?7pN` ΛTŰB7 jV27xP{ Jl+٪R?ݱanE)4PRY ׇ(eZ,O`{ eXk@ u㠡a I3M^J,Eu @>2J{#gwX XNx\8DE>n#)Zv:p-5_E% bS(VkՄsjvxd.D%_>o#j9өbA˶OCb[Ýa}:t{7ly@ZRL^YzoBch_1 Ѿё­{"HN!ߟ FȆ@&`)fU׫/QI۫|6Lܞ7ԇ![u9+㥷sâF0S*2+hdc}m3=kvx.ՐQ1NU*n&|(>5C&I=MIAsS+~Ú%+vqX?C*6Id+2V^lF롴+tˁpۦV$|6+L{-kbLwx\ǩ~5A$lIc_WPM?}6Jf-@'dS$MȥU4 &b{Zb\St"$Uw dԀ@|Fo:Bħ& lp۠Hm_K,1f0]1G1Z \Tt ;5"Ո[|&XDžz]au%Ld;Wq|HKL /SWqj|_i&6b8$Ak|~΋nɇ([(6,QA=W5 B2fI`mlOK T`O` dWNٸK+FbK8柶RϞr~ բkc#-Mv ƹ`,yNl%ӡ5PXl8rҫ+3Ud6VPVDGx+ CAkY;@0MI)+`|8FIb#5䬌ȸcߝʙmAgL}v=HS^pOCvU`r;\ۚg7dA .VR]ㆇcΓ o~s`""3j[Sb94/x|JJplk|Xԋ\F+D;enJ}X$dPΐ.;t$пכTrF*ɊN[,N˚ʠ[z_|R.k"kkC|,(CbϿraLnt= . *+s&sMko{1IFxƳt$= ~bTH,w\a9ÉHϔ`6u}ˏ€vr}%&{J&F^E<~c'7I[I;Ֆ- J|H?LElFp}Me HJ(d?<:150,tVuWay[c@M3Rl\ ZP{ncOJ;DZzkX\WZ7~ C4% ZECSq>{Ii|)p T7 ѶIugY)]tiFn^&!VørZ#2Y= % sL TU::Nf* r J,9ܛ@}z(R&sδ*DwI'>qvYpFz }/{=+ -N =fջ®W7#e)ۄA4d3br+:0:^ݴ^^Xo8Vr RCzq~yk` B^=9V7U6!gՏXPN7F$miG?٩p(*a[ E'5gl%n._EDzj`0=-z _29/J5.y ZY-^=exƳp&O;DW5\p8ޠ¥ ~r@m*/ݷ=t#QV(2+X.:TfB,V{Go< Ebl"yq?uf us,Ge:s_/!f*ҔSTqgXn%6pųZy@ˁRVb >:FM3 _ t: J6r 8 3rA*K,F׉sP:u2Zl,3vl,L`u]iE#Ө:wkʊa[5#Xfk vjLR>]@t5(hs>0}-9iK̆-cUsXr.@ˆ &m#azD,@`I3a=QU%^)?8jkpĞ&*k(X i\;kJ(w{ #ζ?oǡsѭ40q t,V>_<(:.ڕ5d-}Rj^"f6oX2,4Ϛ|4l^k U<̐5.ۃD5R^i82໚Ke7#}X&jMg*'@s}T-;K_ZF P#G职h救7{˨|fVanwkL'DEd9^}!#'[n ⯝앏n$VP#v55yr{k]/vϪFϭ([J!/-9 ^6Q$n`zv'Yam0{5yr yIצwwARf8iPR摒S6R|T|XF}3'ѲL&W7|w{}[vO ] M9Ԇ|[գf:+ evS42LL 0&;-^< .kld)Z}'jA_Syq.\g6n=Vd bm 7PDKgeK_/lUG´ˉWZoP튒-%5)%Ka TU<_fHѹ׫~ ^ku,0ǯLx`o1%Nٳ^okf,$3Br hk ذnjVV2~9j; :MTWT։}'mvB42#̈>XbtYΰOMg`[?ogX~9˿ AӨX>\CQnQzS6&d2x˫x$pChF(!S*n;(G6LFr +0KǼɘ[';kgU|3(xHm,e80BXMg=!CPGX_c78[rr.@5_Cbg5J $ # L R{VDaRWƒr}:Dd/຿#1lط_ʬՓeX>MP%. .ĺ]N١"?YH~.j[]Y:d-&hk!Eﶻ&c~[mͫ &OMtA%؂dj7R}T߿); ˭H3! 7V;rLm*KCW8)i[* ϥpmC"{̊? C0msB(2~'2X.e:ŧ?!ۍ, e=}^.r-dF/NKsѱ-E%KP8'w(~? GkпfN*owMD%LՊ@ehQsTJ;;4d-D:ߐVEփ]דG:PFF܃/P%x;!oC׬ [<(B\|s++=b<8 LTD Y)b*\߉}7Goq=fZVH8#ÕL%fq?Rm,LB=&.De S{Pdb߆0ND7\4 E4#W']!'c߂3sps:܂I Tu[tR=.d >Rq13\θ!3e!_9%rk7>*/ggXH$*-G޵hSF~-ն0sƉYa4?~/Pu?0O >,0}ϵ7l]:Ұ/c1{cf)SOUm^}֭my >zfw67!V*z#Z -_ siɀe>J$ nQ^.#wS-;3\k ͒QXUEqpgICQlV#fxCrhj*h7|@Z:Xl,2bL-Wv nFRXrV螔+Jw;{dyћ/.{Gś~6Б`B/_fj¤v{K+5 9,}7]w5wِ̹|.tQy?u'D1RS)s$+Đ6eE=bߣLwN5@ nIȊM\'dql9gXkzxu <҃jz>"O̶W-m+2]OtX0k)ڷ [6҂k(.҆v o?p<~9T#ʦ)M{pŅ&␗ @QfˈCK{Lk)HlCpFѿ hjrOX- dq8> K÷\JS Km=#E=jl8l(H J"@Kp~ yc +f1*ݽUasȷ./DڄbNF8ms*L>qU8ss<^DQVr7 s4g3 PmnD,aokd@%ScSS j3^ s7$ cp`NtgWOڮY@ iNwP& fՖpKsК}`AƞWT>Ws4KGp*䅋FQeݨv)obF~.S_Kf_ 2`oo (,UWHkS&Ï`F7e\"Cs)iPcQZ \ v% IZ';RCE iQ1hؖ{'UMlU$߂/1_oLXɅgCܿI,]Ctu ֈ!D_nSPwƫcO%62& ^?A4`djЈRy44{1 !@r'dL 8V ERS͖fܵR^b_XW$q@ pyi%~m2]bUOlԒCb7``PLQ}1|GF-ꚬ&0v39MU]~A|<]rynL1 =BGm^֢28ԑ 3̣8ysunοH??M$ ֤C&7KDŗpbFZѼ=U]AZ4zҹrm\d(b0ȭ3a\|}sW~lٓ\H>* j$:ZN+UĔ*/3q^$\UoHcG`Ee͇4ʝ(٥gOvWB0#y4=3" 3@/; gʃf&/ t|8SA+l2A"rҵ`L ] o5~Y|Ǝ!W h+`4~lGwt ݦ3c Ia^x}?0d3Txhf|2U={uH:ُQ, m1#K/Xဃ9?CWqj5GsRX1,/v0&Ai1mV<eK#@t?eEu342$MNvukcȘN55g %ŨD/Twba|gV:*: 8FjvPlo_kpx۵+m]g^?Cj]8R kKϳ "FU- ,Aq@sv}iDxWA@jK! I]08luOEg)Ya&DiQڥ@%Ysa0b@P0G{e*b$w9PFF⃨wOft@eKx}n|-١eev :'A$l:(Td(D}ҖJ7/M?S[G$˝W"dom aKS㓯@iZ*H[nkJewÀeآGDEl5;\܆Uv1u]u7V-"t0h#O#\77"-#6? HrASaWsv=)WpiE1I XV:}&i!MW 1mfz G{7AdFi ;ŃzuN^=EgWjzyMSWꆖΖ/SZ~.Н {9TT $.;AףOnVnB(\?9RDed>eTZx3g R%ӑ' 9Y'헵~/fZd$>t0E}W#53/TPCZjp#O"UDg kJ}$0McNwÞlkI{+7I'B9S [Q[-)ku~GT~۵|'7@%[.gWd76<|mb=M7G)xhdX*@G`3*Zx%}m=SҒ<@v w=]D( ;L\:4~i_J Ċt;bh؇'̀ʂ XԜaYzxʟ@w=\h4U%1`ʧqeA2wqQT{07e. M~L3Uྉyd!?H&ӆ[wz? O=A~`{NV1X:ɬ$D;CoAWG}~g5ciejJdN$nJ`^s7MKWbTu Lj%#UnwAr ܪrd~#@ "lkbR߭H`l}!Y%C:+KC[҅s<-@,UW*S[D^p~Z\Э*I)bdNĥUMč7`.H.9K,`Pg/KWm84M õA8ۚ?}9Qoo0THMU4p[˭Ch68U 4Ag3eH־J7^|?e氃>.}3x l̀m\<,pBVJN%;W(kmĄcJl$ȶ{і+JcLQPN6bM hUx8?hSy1-\->6eg7ߙ OI_.S[[ܽ$LNj Q1f(q \=<9^V' g4fTVI0¯ c5I4ΆǔvBi<^(4!@/+ϑ52м&aq9[w:H8gQ={\.]p<,-g*-Kz %$AwSGc<8hՕ@50Z?-djljg߈ Tņ.+[~,d񭣔^EB5'D.rJSDؓl@2F'K^22$֬]rÙ"ISw q^- t4߆|=IjWgyh˗,։hء.qw:X2*5(p+ܹ)lflG[2i?h)EÏW,(thU3d\onS'")Y, $NWB~GDS+k {2X<|:k67U^#/&=8MّWHTsEL\^ hU,JZ>Y2{5'$_OދVOHr02G45&N_Ƹ n_~g~U`*|^jגkơD wSmh{e\.1ĢM>rT&C8Q)Vd-(RBŲ!V>S/pjWai7LTSr04We?~ fxϢFv玗_HYb8u;J'oJ-8pi6tP>6EsYQy[Eb$`EqfT3t+oy *Ի Cl٥؅(1;82Ve' 2~ }dc K/'ZԖ0r,dn $uYuUo FzEN f$JGcXz&j&;"ǬK]( /6PGoB^ H]::\~iV:z# ı|FPwu!r[7LѓUȃ0MX8c܊q5P$LL Wqvğy9֞tը&섨PcuS,V+8 WQ oǽII/Dҡ,MdxN^Q[Ōtj J#ӢT;^"`jrh̔K;S򯏏Rt yK*$x UAsLoNj*hD90\SuWw;<z<@3"5 ۲$b5OysӪ-*xK>w.z4 *0Z---hX7L2m3grawt Dʼn￑c%7u މ.ʏ|^G*6) vqmlꪳ^a|:@`Lo=Tu'}"c6lY^ڢLh„.. 93jz!*aMToog.nxn[R-CLYwo&fֻEVO  ~7}Z%Q=%@b>R!'i ;Mw6FgM?wq%E[Th M"{u}c2屻 q_8BP?ͫLuQM>צ{m>G\ 9\إ6H+}8b@Ll͑pU'EH")KO$dg^w T YM?W-{8LG`YL!WbQjuOQ !.TFr'dZ-'Gf[0 {3C.ȊIlCmr7PoJc/d21Hٯ ?o-)"PX)gId+$@AJHkOqES WUI[`띜A;QdVd4Fb$H^6y}xΡRalp~<&ǼHs \K6R2]i2aa M K§4t$F`ޒse;Ke~W%'1Fh% -}pKGs7Q_E)W⹑(!24J˟b|"-4*9*Ie5,R̬«k9q puHvPn竚=6Nȷ%?Xj96-Ќwܼ*@V&;/t8]b>QiL*2ɜGa'GWiYތKu"{iZ:n73 Nj$|EP{„")nhiI$Ncqΐh5 <\|,H2_{%K|`#D79NevRѶ6oPFV wQehJ:{jb7=mab Ji@9K,19'מI=801^b73mTf̻sYU}2ǭ5@] 2_& |g0DԲdPkWaKønؤ6|:Z ֨kI?SU|èf=F NxQ!ag}HceM_c7>Хx f-uJ=}я;( <_M9/N>r؆vlL h㖯x5ݺ_ZN,&PoUjG!=GXAv 9rZ3&NѤ(̌!aPvQ1IVc6g*edpJs# JAz=iC5 ψprN $*~Hda^s4qcF|"Xk :D{%E΄|&6b8;xG:.fP}שy&<2YƜ/(f-) ]=ؾ\vZx]j ځPeFM[Ċ>O*8} 8 Tӟ(NиM~tu =Q~45MΣjVazh>|yTzo%p#HZn^8){U4[vTe9Yg]n^-+oۄb{&=y[3rjrvL ӄ5sO0mg5q#[b\ԫ h9@('Ydݚ(tud AQc|kɨ-TvC}戥/8coNNQ8Y1)U߫njJe)63 =!>7= #hMoD8-u,ycx~<,Ө7/ܕ-eECʦzFє٠EGڼp |6%E3U.슅Wo{)Fmw;^cpJFAۛ;*`TE@%16[M/g!Ϡ˛TŻkhT ;=o ˪$R<o3PW,ݼ_f@Xv<=SFeq >^lT 24.Qެ*k`|:dt.)]WdR7:&g]Q ;Ow\mΘZ?y9nLK›w{ѩSK rc ٗBEA)4ˋ*4o!xN4s /jsl w.7otn1Q[\J2|iZZ, /{'3`uCSxR&fz-<} NV.B;[w/!+@)U]a2c7@ډ})H퍎 .TWt?'K0׹L!%yWR?@JQ7(B)TSb.gނ?WPJA4tWIgEY2۠{oc+pi1LbVEWC('dDz~cP({vSqȊ ᣐE2tECzVgLx$x!voBݦb \"+m^+W+&hR"eesF# =vuaʳtpŖ{Pjr'bB=:6{ymB'i4o7Kes_,ݞ$F~d"hHϜqG:1'$7m݊3fP.:c},zX0ߊ<f)Y)ff|ФvB `^#B|ayLM2Rht$tC)8o 5HKޠ L[]=Qq|#w0D$h? %h:5|dcwU1 ϫ";{s>+AGC| RVV Y+ZW.>!**"?Uˑ3%x1שl^g~BZԍbv.GC˹>f$-<Ұ<NFeW1TSHvV vmW{ZHɠ洟MoQ㻿$מaj D񾍫'i2%sL Z2;3BC Scx ,_(ǺL;3wVg%I}r΅poab20x ?B4ifub2? v" Ȏrd56 (rrU~`᜼_=*JKd22i{ ZfYrui~,[`f1 bsmOL_?;r K3>ӳg4A'ot|nxF0€8l:pybq)Bo͘\3}N4}P<#=F0THu<8K J4Ё`I R%*%RQ) {$EAǣUoʪ938@^89zO6j2H|ܠoD.gIy}u*GVYa(2D@Ƀ e!f`Bk'g)@!=^b]tE"o:^d]m~x3~رUU $nK&vM{sMg4fُ{S]8NijӜ[K<7P=_P_DTCZ/w`rqa[HdC CVֹ-hC U5] ȝ .'Ë4UI CjMI1ťh Jf < لc# B*Ayr@PmDB>-]б|COAܢܑ'ɲX%>I ({kjw6X},ӭt: d5n iq~dfmnߒ ѭ> V S/],"y۽ i79vVb-9#繩ŎN ǁ^)S7F^H_{Qqx#JWth\ћW5I_BL k-oy:fEѿ{:>BɺnMy,W',&ju$loE1 L"Taz٘ C4 ~K-9TjM4'yK\/[ckw7٥"ы1=rʽSB7ڈ)\_LLD*2[4jN=n- wzA)V}\qNV4R‹TkyUC`]wK ]RS5Y56s@C$b.b nJʼb36ۣCBPvs_FCYH?1&"hɥ{@\1(.q/ )zxЀnF@4NHX5#b2X-_\t!'lRP&`*E<4V49׎PqeYAЊdI. \j<9-ԪVV4rl2Ll܂EV?i!vTtKpl0'r")ϭ$z2PΗf1GdMrtw3a9)g$=!h q0ۅH7ьM`TE|Tbwݳ+|c]x" G^}gv{\agmÐ^ RVDѰV '6l5ȣS5QTfo4POcx_<ywi&xH쿧L*CŏQܴq Pbt!eQV+ 6kk9Ӎ!$kωy=G׭]5a l]cl]SY{=`2Wb,oZ2sǏ[ed r-'Ilu> [)J}"mwCs.0ɚfO'_d 1yEU6ۋ;~5] ~)Vhh82#Q%d2\*R&N4h4ΰ=rIqĬ^?Nf389hL8Bp֛ݧn-{MbX2ݕ,D0.{> ,EY}3"Tc 9}40m;H1C}H}{=L2ŮN|KFRWb1⍲SLz) ]Xs!XBEln*n[^0w0p~W:ȇ˺ aOv4N۽&(;܈wf L)ZY *y`퇋]\K{%אڭ3=)"]Fgn0TW?7)uĶɐ_]+ Mn ]E>".L-ls)k=Řa+ˋTv<s_5ŦV5v3bzV>l#RH?xU pq B+hʣW\z3mn  ۡW 7Bu *K]@d9XG6furpm )ܚO&_Wn>NƱVY1qkJT%oBS&@[T?Bٍ8&_ұ&JBoMQPXbZrS*T#//-SNE>[cjS 4mٚM翨 ;NC;jo׳Kz ." .>?zY*GUT;I?g0{%u>v" 7kpjo\wڗLWf0DCE _`d@j_B [)3!XlC3rLPD-YΗ'2ITnb/FۯdJɷ&T*7SsPɑ 6qTFZķLlS<D)Q~mQ%J2eonfBS.!ˈz.9LJH",ub"EaİDc$лnZrK6.VwS_Aʑ_Wz0H? TzK[{c1@ٷ+U"Y5%E2s WT횾\9#qq""ex0J4wo!rcqApDZ89M2eHІ#0i4w_[jݡ5\*#rEt"Y%.*gi0xY,xvA's,,BB[w/Rt:q^8ɳJkmw9Uϲlj`-kfњ"SNa H,ciΉv  *ԭәgwX?>yTړU89c 4E&u mGsQtU?LJǏbo^Qiܛ4ʟ]B;V\ 0#lhx ɰD=۶8XE譕xvy fT_F RX*Be:; 6{kFk+,.`Ϭ$4=cwûSDZXfS>JAUr.E˰!Y}_>uPܔ﯂la[z ]ߍj>p0E38f4T ~ ;hæxp-!wD'2;(ͭODGqwXMpۂCQTHp3u64TC=H9ekd׷~#ږ N]`Ϗvg]Q*sv[j(7t bƶW(.^Qa\Sf1RыƪylDkzP߽X'~hTpr6 JѩAT=inz+#X `գ|e |#Ή['faEэD^忏>XOl+ɪ{b"9qfgn[!*ΊĒf_Or v*;x3]>zKAU06mA;q-O>ڍNsL |A?]ǁx,ˠ W!uM#V`ʊqRl_ J>$vo3"-WP ;)ᣠbUea Kh/}: S~# v:SOV'ng, [Z%˕c$M G[2]F鼮$uyA/jBXyP˙$a<@&@yc՝ =$42"D>+EӖxnq#^fMBghjRUx!$L֧ۧk^AbQ 2qa5rob3SkHo"Ýwzt(N<%tNbObֲ5iAA"XYߞmi҆c"bsxFr|ḤԨIpAPS/Í+>LS-XSe.u8`{LvSھȹHڥָ|,m`CD?&"fnE2 2)_$%lP$|{\r 7Okf+o(XjZncQ awjI Z|x03yGЌS91\8ʲt{ L1uSN֌<>۷%8q/ScSM Ӕ FZ3[LȍnJTQ)}5l|<= N 50>7 …A0ʚmAtnp30*$ѭ? æ,(LPߙyPzM S}A^f/p(jW:Kyt$23|$59ٌ~ wu.XnA(0})(ftׁ(5Mxk̗|3-xs naIX,٩(O 8ao)Sŵt:ٻSjڏ=SGhz2}!pW; ŋڭhnYP̱;hk@}CƪJ]݋voFF0pr@<bwVUT\VJC= "7n\:uiD7pMuq'm#qvO|%B),k`GuR J .5 Z[;#ёSGTu"[/.!iؔpDeq(Nk$Ʃ:c9^A 7(;JM.MBv9MhLWS2B_(Pda>FlN!pr<bXBx>֋1zv(?c7Fh'G C=xҋ6EFתЩ;nw58v XU Q&3;S dϿw𷚬N3U*&H(|Aak\=N*26Y%0Z c^w`qXgtyv8 +p㴮WPQw3rP5;d;pweɨ&(Hɡ!r8߼3\+s-hf$*ݭOmWs!grS-a Oe ,u0"Gg㡡z(~~o񿳥1$ q9hQszR; W@M+rfQ ؈(z>;>#:~\E_)M -|(>%Hv2:4F#4)PY34 PvMaӊ{)mc z W=^Z.s'h6C Y i.qo<0h`wA%8o1jJj?P @[en@ڛ>FG@Nެ^:iR(9",řYII 4OK A{5'^;MTH,#kKy~R~ڶ`aM>xx-WVi' M ^3jCQGju_\d` -ifBG{`s6 (^_E䖘Ƌ}tP,m;ݗ+U<vn;b Zf?QNZ ӽOJJ {1V(\J}@dvv#09Ы+voֻYJ]iL3-ܘY9Bj2JX&+gc*uhx/Q0I]P PSqԺC<`G~yHVZJi)/aԵSVΆ1f #?Ga?\yOc8ՓUqѠ2LBx\c=b[6 phjlEv%EA?W ]aNE0U_kBd#ϴE^Iezh\<)v]aGDK'$opЪZSX g84?.ֳELø_:ycjyKߍ\Bφ|m`SIіE,,a Yq1 *} 1ɷ?`3z֑•X3q=1"U,DJYDz9TB3gӜs6s7adw{Z Тżl`vo-KpravBA&P6j,VG¸Pe9' =ksSlҿ@f%b\> $xځŐXV@ÁU;FQltUf߂sWAٿ>s8|"dx=lzUX(ۧT2j鰝XHBn~}csP~MHt i30ȵi]>zݝ>"7[xR|7FPp] )u 7g4x2'@u(vf~H| 5f8ڻ Iې֕iKpۋGsB@Bpq^%G)lMt+UJ6FY8N_,ZDzfiXop:,Ӱ|"!--דeSkwjHЫrM"j_&S&GK6Ohy [綌hiwg:|R),Qf)8xY\ #5oOuʺ,D&9[Fa}s[][#!W̝__QhlMqDogt.l/ELt>}ɮJF/0EschM]  ztnt~j?s.ĝj2EjC3́,pKw5ca&2N7 (aq2ORͯRF8?*ъBYl!GFBšot8n}{n6S(8U$]c ʬI_jޭ|A(7pf.mi*R^2Tdsvyin4 _4_ï&/~^gb/+\-ҘR*PhÌ2RڗԜm4[^}g R: q~ء^3pLPȟAnn{m )³y1^S ZCQfwJ“Y80kzi"{gsЛo WlTt(pdDy\4$o#ʷ؝╽Ë0V~l5?* +%;2)ʯV51kM5{m] U)aI752tM`ϑ%y0% 9 k5D@p> B}fq#kTuen㎫*,Bg"1ՈӳME Ζ1!qZVU4~\!/h𚸪#ֈRskZugp@V^] QA1HP hވrfjAh(=7k8,H7bR!?q V)T>p4uqp-7fw|o 9;Or6b|T$3k8q3A- A6Gu}+ ?*:&GcX0:nkhOޭNnv䷝pL:IX od6j&foSJ4q3>nkV. NJ[l 7{GmjVX"񣏒) AWm3jzĤෘw;s D )][P͗\;Rl%{QZ]/^2𧖺i+J0usDz+moNldTѲ*)GRj3VV5!qP %d*DpjuK{ENrc 8҇7z{Db5IzCEg.tqb eC6 -ۭ=vRERnf2?e4kl4!g`4Q%q t+TFG]?]r(vi| giQ7U SMz^ln=Ubh\2~nb;24XPO6c:]E3'F>'eb|Pe=SZV<iCfҨ}ЗUb_lNN&fDtjyžrӓPwH8KpVOɏo=8q`*ތ{/ѪQ dvFx "QhV,͸UB2DNAY:LgX68v߇1,2S^2N`ÙEAm/6p ^v3_#ztOZKՎD|p- Pp{|aq&l;0$Ʀ/ *z]q"6iWGF2Zw*>;~7JuuVW*^ eS*.k 45/5 nQ H soㄽ\OQ"꿅5s(]O~'Rz,O`0 |5:!Є\\VS$H3/Ye:_rxW/= ;L8I;ͼC,LYVƗ ;t'mHgo U p7.,assM&gzx$ R@>i$*g[d\Мm!M..w{‫5'<>œmsSAƥ|0rq"e`]̏aHc=s rZĚSl4]FE24:tԎAPq|j5yeWK@kܝP^ شBc'p9Uf&{OG]Dq#,j}*˳X:U̫X }RY"[e)6M@Vfv[hI#胦18JO|*7Ƙ"cfzFNAݰ*=l:Rd{GO wsyҢH"{hP8E9)Kl0J9@95#c5: CxhRd=Vo{*?Yx"q#/_(,FooqZ3 /^ZO^^X*Ty驳b-t"e04࣭d yub~-14/!Ht`X$(OhSZPNkg5 G7F`y:sT'-4 r-T1ߌߟȥ3v Dlߗ3GLk4o􇗖P2JY6(gs3BZAaMw+[L $Q'Po> (OA vT*KIpd8yqǶA!Yxfs&~neQr~.m0jAt='9h0͛~ |6q~$z UZay3FcXuJ.+MgiJ?vϏWWX~dCyʩ{:UMB^QLm9u3ݑm!Gmbj}v2#1mg"ff " ,/'&LOEZǸ\7O(]oZLB}'SŹ3\Ncu7j kwFD+@5&<3i3d1酲\^Qt: \|d@~0YxFX\E禪7,6 BG=v-D'2W&iuo\ Q""id^$N["'He}bv#hhe$,  *(3Ci[6"OE$''D8qedkǼʜB ӝg7frskt "S`2jjP!2:BÛCҪE8HtS"HJ7/Lo+&3?pUkýM-9Z=njimtN4`N?!dR%J ;I-Nj-Iߍ}K:nK @ؕa ƳO[߈v'$= $go!Q`nv/~2ǻqX3Hȳ͗s)jP*7ҟ7!Q1u>X9=lhc:?5EE=ujQx7 Ir0i`E"hv@/XR(`( :֘|Vf(JAһq _Րv_^⾴8[y$x2.jH5̨"cC="AVjC 4Z 24g4XD񈝤Q1e`z }H[5-?@M] yc[{OzDphO``.vb `6l>l`A+wPI7p):_kH;0 g'\Nc6;9ԌѰ6 2qPճŘ;DZv϶v0Z@C%(zFd t1˾9]N)k@HJ])yi?2r&_g{\KzoIf՚8]BRvxeⰯ(ѷuNBeہOxO uEG҃T Qλ04TlJ\SJI_~g|'ҝsǢWw F&թB-$'wk2k 6uf8*D 5ٖw,tP{fL~T:.}jHPe.K1,=X`74@4A ۳2Jq(4È |ߘ[-Ggv30E;>1itICRIa0̃8\LɥkLֹv\RU#z^, k?*O!r*!@v=jH268^Ёga"t׆|+S*BqAq}f?&:dB9[;TkAx ,=zSb21A1gFUD{iH4]9t!_Wq5*3U+uB]5K&} q ;(UbY]f'i*Qm?M=t{a)~vk<{"h.V =|$1ifaムtkm>%QzԦN Ȇ \<4#qAQw-lTn#;VFe u48ɫjϷ٣Cn-45OBzj; ΐ p/;(P_[EANL^2 0"sV1h@٫//$ˣ$ڤD4Pt<6t^~/lrUcO@xbi$nV~Հ[bB<@M"f/X@ഥs_b+ং7s_ݦZp>=8f4vFblT_t U(#aBGK"(ds:YuWa%^~ͽ|㼾E+`9Hz !83lJǾ*Z|f҄7ܔHMgGI_W.'u Te WBbK4Tw^ kkbZ|Kk5y'q|DJ(30C:jri~MFJJdLZOIdJTY@C}A%u~O?C2<@k-CX@ZiSK!If& 電aDE 6}HƖ녌(plr@w֒0a5݊ʃZGܠÀHa'2s0+a~tqo,ق{ÈQ{*3`qw";_>nzk0cza큹y`O05{2sD[M:B>DƏ55+ #fCCb=c[A~1@J;BTP7Q`_Å*a ә/խV~3̖X< &9~$f{` ،%?lwWXen7͐B(0)mi&G)JW.i?K_T2ύ׼H<̥OįTVF("%\lR}}v4tvOYET#\t)~ к<0ƿĻ[g,p_ߥw{oQ%Y,7>:K*wW-nk4Aq|O\LIwo_'G.G'i\3 tC]q7U9v!A[RWzܒk۴ltf5Ok7-"}*v2 b^²l.>JP k ') tx0+l[|*vdQn UD$/t1nI;E JXtzC `uO_IKeKuuu.0<X c%| 8-(֠J#=TQCy`Lb;i1~ҭ-n?% +76>{i9e톨F?K5^JDuWˮM| |ńt[<33wDzhʜ_,xϿmFG"`҃DػL|֏.7(.ZuES]k -uz  ?f#7icjW ǍB_b4cQ@r(Wdzp胠[ixGܗe*rH2ޘ"xWzC]E\pGZYU..%30B_ |Y=J-v5B>Gr|"X$gf2gF;4h(n %sC48JlW8ķ:az.$')E 02+jYj"|} [2/58og&¼0~lĂ8{;b}jy=p;px&68ܖH&IMe#19[ztҤ*%r Yw86";*Ð*uS)BYPcp.)CHEld2hŏp&rxXbk(YFFaN !_)iVmUB8\Mov\_MEgwB[$/L wP^:QӤ1Ir?ķ1O<[}Hu96v&F!A)q$vBq> Xj'Қ#"]O!*a;?dJh/(#fESJK&]]b*aD)3p l+T v\_ZSWVn.;VV3bn41b"Xu# KE0;*`Kl^tzjkFh6&*ml kYLp-ZA.`}Kv)6' %(:_ r%eeK^-%-W!Xxfd|LyQX'r]u&%۠&lWeUl,#T엏mY' /MY"]έ/͘ Q,l\M *\6aLh@0@(&1Ȳ Y>U:u>aPiZڑ)QJg mjq4]5/ἴÛ2]8u8ttKzf1_&U3d-^-]O*MؓNAnEZ$5R4Keȟzʝ,$%*A)B?"XH?L(b=Ѵ-X14wl5\f7QE-@)jpB57lZė eJttLb!-4Wyʽ͇A9zf`A+ilv|?]ަ`yWeԯf@B^ڝʭ|?7>d& `hYL(}ѹVėzUc5SoTrs$qaD vO=3KA0~` YƶQG[q?Q%+}{OK_סfB5C p}(`qD I BM0jA1@@E=Eͦ>B[1ӘAnӌ=BqZk4fڱ \q:U>% Dt@έ;z18S״AڍQ{ru 3.ڰ٩#oe',`# c*t8%%^yv½"euhvtw OX5jޞ1į1oQV'In/aY4D~2]/|Uoku/R"H[]Y}y%hg0ͅ骗<>9qxY>ow& Ij>JxTʐDU Etp)ک0@VPq!CQ=emNlSJ h K ao5^S "**4XkZ+qԃ RZ 5 {(\`2Ӏ˥@K&ĕjBLSW3\W/fvCK(+Epɵ͏ DCU bniL􉜹X%T#a=i1,]D500$.&z]t6ܝ?rEfpWI Ke#BqdQϦcQ !\HZ:MT(b=W"e[2qxҨCv2N7gFe\QdFr{ !0>LJX`qaIr^⊦ڕ |^tQi.OG|¡9 R{=`+dz,M2i,5Y#ba˺P'?]jeS65u|q(}VՂi.>ٌM LtQmZ:fCSsMtjR<.ߞ:T$%).ł?NoQE C,d5@]:HըS~%uXrP?VUH)PKSFUe} $FݚC qTB6p[y:q4Ε |?Ex6pdMrB~ f3C{p Â_@ #ѷԎ婝6j{< UjeQ zcF^9-"Ty*t2;iέ}R')RWs (Ã˷'G8SA|R!q %?dI/d~TςG4ߗfbx 6;5EBm<ʗ{hAí}` P1l#,J=n}ڙ/ g Stw׃ҕyjϾ d#iQs'h8/b|wH&kXIX>sÃ:ADH*5d{daHa p=HazwB-۵@"(>wd?rf2̸Jޗt̃me:Кؼq]VR\ Iy{1uK';_0*pדcb]mIsGԄb ɯ\17bASdu@kY-Ȟ+1"2& F)i7ugVW,$ݠG}g@?v_Aj Ecd'Xy;AZ;^2ʡo@7>7oCɵקA6ŧ*X8"ճmJABd3nrŴ)!Ic#]){h 3-Kn\GOKC'=Ld]Kϰl/eKI/! ̎ Ve؜7bF$w bgHr:]f"hD1dh^4jq WM6ds<Ľ{d/EU)P{ÞDv8 Kjw;3ĵ?u $K|m/\@G+RP yLm=۱OM O#K b ѝNrn ۴_US82j<4KfxP}oȴFp4`AMWUb>ds;B1l௅C%DxwL>Yz7ª/0ɤijhlTt1)Vf7 AxLjmamH)844G;Rq]kwIR{D{#!Joi%B;)/QBbY.9/ל sYOyLOH}JqysA SjvfRy.wV}Ȉx_5lsw8veGMxwqJwDz$4[[O$-/Id=].Ie o̓_ؾYCln&OYmgD΢.oְX>QL{l=1^LJI!5K_2Wo,UmCNB8QgX7*.UWeDy4 7่Z!g1FK9.IΎuaj&z@]3 ?\^| q\R{Vh`x ,lCDW?nLE7}!= 1)Q93PU*S|mW QNrR:\>(=/L:нbFT r=CspRK/#xXT TP7@GGF+a_yg mavz&ЙU^ |OGE$h/`\rZBO0#N#Jś-+=(F˓a=ZMD+]%|-llkĮX YcQ6أLO78Av_ upM#rvH aі,,7y(N0DpxK`YsP}-E l[+xdJِN-5s'ΔBn&$&iWp`>+Iu˫4 &\h sڏ|tQG?e=*[ 0m'9-&38 5^+LpFdPKb! !X :bk} n|Ynqx-a7Ep"J|97X>PWw/sLG8k*ЕIe` "L@@7Y!Ye&to2qgn>XN Űr=$bKzo"_I` XRy 9. QOO#~B8tTpc]g[;eklGI U_ ~>I!3ZP\B N:p|Ǧ*ueЮ>G[QEF >~$,ǣC$[N{xhF7˲'H{%vMIi(C` uar|`cٿڀec <}#$fcX܁w W֔C<<j@OW#x\c0@9vpasYqZhX[3<[r{3zr,~PIp Hqhg=E0\:b_ܾmYFk4[lu&54O#}C|!4~ԯVF[AT늎+le 0ET¢JY'E)|ⓃHzŦ[MbnƝYcPL00^s)23 bsѝ:bwy_Cn6_]N 73Tlj!Ի1NwK|A4DtEwz/XM,E>O]v)h7jwEFao ^ߥ>Ǡo wH8QWhT򯑴 *iP{[{#H22J!FNek۔dV+yC[Iear۲@;^t6$*3f,x&>NiiCmD["p{|0dFɢ^W;ʡb@}vhQhI+5} F8N\KWm!Yu 5e­k>o6`jjE߫,tBY%k|^Qͩ YWSE衎gG0ACk ]R[ WעSS,}$7ЈZ98X`8l25L]Z9Sk5assG6:f͓bi_֩\TMbLz GFVw6Px5Q]MwcÒ<Ǧ6=ـ b_Y3<1.sI}rxljS L{%rVLO([H?=B:Vϛ>Kƅ IV q0"h4:&,wstwTJ!l”HmEt^t .՝_BE9Ja UtR$k C3!A`)E=89𽌇1{ʝ|wp'tW)'ΦW#,Zh KRP%I2JC_)YfNJ\?*l'sGaC39]BMrhΆP#W-WUHBj> I^aPwN bMؼ22sy,"*Y1 a‡d98DbbWJz8pf>Ѱ,Z aaBZ&fUQx%;^/fY}yBAS%@HX b<2oGV?qr̓Dd+eK 8#f6"n9\=m aDH. Ǜ1ψ,RBD8C,{7Vt"F=O/1Jvu`g;K75F%!4fe#(’zUPi$d)ي)qNQXdp: [/~EYt €>ۨs xxn*;.qMؐT#áfyڳ+M .4 zgR}y֊;Kݱp]-J+J;@VCrG[:` 60T> Қ?#GG6ӧ~(z8۠%)˘Jj}ܝ6,iaA8v+L aL6jM5_[РOa^hKu&kCTBS^bkkVǠ }I=7~ }'XX3܋?~:rj{HCrۆBA^ٓS~I|l kH,$kᯒI$*no'A$ÙFC0iރr0.;dCL®:r4'#TAlȿ%X >q%Uh.(]Fh㋴"$IYZLQ"揔RyxݵWAՙGa&A LpYmzUg)Jr+! v 1,'Z;_\B/X{ݷp>"ȗ)I9 .,pb  yD~91WQn)ddUTKM`[G\O n rxFYDag0.𧀼r<'^"!7$>A`m"#P G1,gcהɼﵑ9^P/+-ػn"8Ĩۈ`Éznn"~O.р?T\$mnDQ!cxlquM"2P̚(oJS !J*@Tqc+`:W}iĝ%m<)`l)E AAϦa|VBC?7,ńu<6a6f}'m{A҉픠ͧcdANAb`ĩWZ'V(E7 kQ3p8}Y BZ.c:Oel%%<~:g=,a *Ma / YZ