sssd-ipa-1.14.0-43.el7_3.11$>źۏGg Ee>=?d   ; "@FM    4 { $XLL 3L   ( 89:e=yGyHyIyXyYy\z ]z(^zb{d{e{f{l{t{u|v|0w~tx~y~RCsssd-ipa1.14.043.el7_3.11The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.X~oc1bm.rdu2.centos.org 'zCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKNiA큤AX~oX~oX~oW~X~oX~oX~o4790c7240978db7ebb45b068e719667bc94b918d094d5ee626879a48d3302a0b8282b239202907b347a9a1cc7942ee0a915370f8a25808a40b00dc106fd4dbb28ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903db7ef65c8a57396cc08f8d7b4c82b8de9d7c53397c64cbf120dca001f5198c1cdffdd465621582b79904ea7e77cb96c37396b8d9efff43c35a6cebeab63bce87rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.11.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.113.0.4-14.6.0-14.0-11.14.0-43.el7_3.111.14.0-43.el7_3.111.14.0-43.el7_3.115.2-1sssd1.10.0-8.beta24.11.3XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.111.14.0-43.el7_3.11libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8331f40a84070971d9978cd680a24ba3ac5957aa, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6>]"k%{f}|,p35muذe%'&* I+gX_0o' >xfm[ClYy'mk#lXB@8[|]}5,p , ,Z/~L 'oi#Wұ=sG"RdžӾ7i?Tzw8h{ZAׁhD}|yԸHVuɭyw#EU $yZaaP*Ivֿth+l[M'L'FmٯݻJE X8dU_vF=t ĸml\$$,vyݜJ[Rn9wScA'H2ׅgΣEVu?֋BҸW)%lFr=>vuH .4_ĠK`5nbB:InTs/3+Km"U/Y^c5VQ -oU$b\2¶z z( iJ!ZDÝenEheLYr 2׼vLIe+`p`PSn+*n[RϠ2 &g7eQÉuc͙ZaVP_^תn2&pj!CכߵxI i'T||3'ձT<4EdnJfbY!Q%L3I6c d'^5*ꇒ$A}c!4٤ |銉&>k۞궄ZA9=4j0ўgaT.G |n Rq!F(eXӯ<"h#HdZEQvdo^p(F\sֽOO.cKmO@)pT tUHR gbmԢnD%Ɖr%vpB#hTZDJrZj&/W)  01Q5D`+"z0^}\1X, BhjAb\Sd`+LrCF;b7# h;e {/З4Bɏhw R$u8zuhъ7fNLsݻKyjw9Z'/Iզ|[՘#ϫEyNz_1ߌ"m>΄>cH| 50\c4> MMA?n'DoX"f@4G>X35-&m'dsV,HI<ϡFzu!}%ǴT% &ϗt#ڦge2']=,nYa|Hrڨ>,&7zV-44hREO-$I>[\.2s}"*?b|eVtaͷ?ID߭RXT6y>}s&%{FhۯԌv!?FëMoΟ$ e`@jbl*YVތU![ >!Z !)=,.rd&0% ᆪ}?cGgtg! 6kzU U B'ɚ-ٳD/wR!q, ./sBr<GwPOOd{9jȋ) |!ƹ4~?7=`'`,%N-@I3s-y}VZukt^lN Mt1=vyn1 >|>4_lm7FK^ym5 4*P+\Γs3:3ךhoYp.,yk{hx.>"Re?3Ȳ & 4`!)p~ 1H $ʰ1xvUp{g2$VT˔|ԬPi6k:ZT)hۗc p|nK nB=Щzu5i3K󻑫e+3oډb BۣХx`4Ue1./-Cy]5ކZWIC{sWRoԾGoB1yz}˿[0&H=dH*t`τ-U(zuiD)p4uA`5:ArC8=FI-Xb\;di)>xQg@´DK3 i]lD ϘE!iϪX8yǵy[yߙD#2 ckEzZtD>oa$Dm܋!I\5s2"d. W-k_:CSmycg)o<{xm[W`|Ѿ[.*'sQk rY3./mpTx> n35?.êy}&+'vx#;-AݚW&{mhnp/cb"pF |nVQtϞ@&V ] Bwt3z}΢dkb9 5{1Pn|%nStw(~7٬>>?C [HAie,,# n#߮X_k̠Ư*C!&s.g8)BhŋGxpQ?+xC>,5{\j^xXpYxk9ߋ'+W{[Ve"-N\?J4=Cշ\ @ͿuD (%2i*fJT2^k{}'Yp1+~u/ 3%gkuLC^zӠ?+R3_&9"Yha RT[8–aM@t3ع{* g܋kqam>Bv (x U1#q"Jl$4/Cv&r!eGa 8ȴM͎ 5)~KU&^sEK򘨈h Xc<:CKHGYFL `VǢF~ݶOIj: 44q3O=!Ij<ūS\ GzbFJop"oWF糉[P%z Ʊ\i_717Q>tIҍ7cQKZMYAևqe%0ksZ6(}sb7{nck̒f2a dKԔԾ;C p_+Q2&[4 br MX*.sHܢz|yYu} ޭʃbp;U%7'p Ibw@+q=Vؤm;[N엙$f?PM?=-/X2Id7> *uE }F2~)< ~NI&ˆS!߈?XQ/00"*7. ܍>h|ӘbRd ;D8(iY3#V`fH~=eg3i}1=CJu$CţXpͩf=PfR".%u9E 3ݠëٻk6; P׈#Slc{x5`B [a,yw9Z? vIG:tOEχ_7RgECT)3:37<OhA5HWp4b iYۚel#% % i;U$%$| @UUvֹlcupL pLJMwPu췬B.}M͵7MgZ܍$OGWIm>e_, I j1oLb9VM"Z7hH{>pa^mnW˱]@#<iN=A*/4x;>Uʐx@K;Qఢ͍ |P*<"ࣟ nPk7|ǵ7?{w7*r~Ld݅4QQ7($;<1L!!,;L 9MN)ht PO|c>qLg!o# T]z'qQrBukI4S'b[9Чm ']>p4xh|b_.]VS/0&iu} K{yGL߷74È M568,.#أUf)W2]FT\GTUr^ So@ƾ/؂O䒿BT t ʗBV2uJp, +)EK ˏO].ʾ͂Mf }SӦaƙ(#{K-7xr)v{gt.Pf_L+RɢGyæZ%w"c.2L9ʐJ;k}LgZa ~7-~"D"4;19 G<9\(J<@yqT=)'`LIk\Vv|.8{_`X).RڊD2 ʚͷDѐ /ݴb_x&}|͖}ʤpdeLV{*;>>ۧʆ$41֙G>+cNeFC KU@2/؍6 8M?auw k>0k1QEek!fgK$һw鑍_H*=&Y"ù4XI&Xo A6tI-JS٦5C Fݰzecc rVT5PHRwWhI,i%MP7KFgH>GSMaueŨF?Vې=SiesΒ]ČL),iC'G2CgxM/<ĩ4RoEd;B'seh~AL-,*+8s(ZO,]pC{?4.yگg=HFT,Ѻ2^"ixkT'ؠjC߾IVn褬 6X-mm#cjHvB/K$ )"I,A $>r&N 〕,O?>h6JPݼf>s(q0mN50lS/6J0yVJE7Og=I}+'9s )#65_T3CNp^sf՛0`Xt.Gwg*Q(˶۽W1˴ߐt'Hi~Ph XE35zqkᄱ,A( /H S}îkҔgv)XQ&ʙ'!>4A:z;dr gl6r"dMuչ[ O`Ar}"S1W:NtZri]B,i +vTڥj&҈U19C=K1[f.31B m~|23JlOWN*NrFr PT}"FN#9Xloݟ}3%mGSqdR4)R܎v~/i*KLSB%ҽ8Wa)geA>?y;CꛡkVg@} ݶ}ƑQːnȭBţ*l`s.C5@^ 'Wh5{Qh^ӵ͜Wsj5DVj\vf~9Jy{Q5DT ٥w^ CR |W?u}+.ksˎѿo:)CdM r ]-@(̨-<&7[$~axْ#$P%]C\7q*tSU$tQӹX*$f,z^IN<EFDdxm.Wg>%GΎF'ܪ-(i`/G}RbBiK1ɏGڋߙb?F0 9OZ)g`_`z* ['*7qV0W[Hpc,oC+ԟ~ahd G>]b qR)1!j$.cPB#o0< R{n:ZE(Ȼ#v" >9n">8)ICj7"anOVɓCzamB &wy:]ҾL, >t0"TwhM&J\|Y pJvp?"So-uW9pW46/+^݌t4.lcNGwª}Q gg;]=BCY u&-MsFcS93P~u~W}ypX%&ʜFV}v21c4$hEtw>s?:du㽞 Qs7Đ]E@;J >0ϔ{, nz7ڮzh,REE)p2#eV qgxWco0-;uo+.ANAWPZ .L߳gQgs&h戗u+GI;]~9J!\5eYIZN'g G;TרNDd9Y8JE>C;u}yP^bXbYVbUt81XX(cG ǖM2JDcL0AЌPѳך+IkQD%s44cՌj=D0QMǼ|+{r"v^Xl7Vŝ66Ay㰷y@+.a@/Y~X_ZyCzW]vC)qv۽9m̬&fمS_QW献D.ıXQvj@饘=?$P͔ܓ:UJbag2y37`%\0.ɪ@&16g!Op˚ # `cnUanWpE2d%Y.Ifܪ>fȆr{ۓ \Ck,kD;dH@Z:;K5t%y$ChXT "p&.׶O2pKNs}!!z~7@cd2_u/|aP|S⢎'B\?s*!LetF.u?Dgco4me`T %&beWh3h`"bYGTH jV8pexaV_-.ttoZ]7oe- =/bYY^ztb^Z??Qӫ<<a@N w`XltFZnű/I@lO07n;AeE[:XJ\|v6j&^I@caGM5 פC;\Xtl>͉Z.; Eqb/у:&qՈ7yו\> QVZ!C3:Z8tf{tlV m!o{y&7p i/ VUw&琚xdf4!"%V(xZJC&Yl 6ebv(c"'E]Sʊ6 L<g >Vbq>``y#&+)Pl,&L}fCXA'㊟.iz@$";5tФ ;5YwwʿdHr@Y\/$Ko* Eo|^Qsu+ q"^ƫGCTW7 KP:'6M>tE+yԊ>s=:ˢtl'~FxM>6A L"72#v+{LgY\chN1z=߇j"p1n.8{X MV8_dkr{Jb3{4EU *>"/#q|;q:% RXRIHܱ(Z$nR&c' &}S(p(/HY1ʼl`KbTfڭzC\tgQv=$~T %jT)N0K4?mz~KArL K̂@@T55^Hw\^m܀,Mk~U })YYhq/*)[pU޿=~iryevC r%i U ntP 9gm{ɪ9XykBMGW2י\=}>[ByȳI0L'eXs5U߶ `tסxAnH‹hO4 oI<<r#˦ d4xJ PS=4葆gā _?S cB)\ܣWCMA2̰&)=Y# ԧ6k0[IA<2K_ĦM3ͦWq6I(^?"RiLҒ< /Qfŏt0 1THbe0xl^dJUH.Ir^N ބ_C [-^7:Il o.ޔ CFyWNZv6&SM-+-Bsݵ+trɅCCŖjǫ =8 s%16Cm|(NRl爳}̢smP`48#&A\Z뛈 篌M` EShY:oLpj;ru{$(ÛU/PuX#-3XW5 l?y@Â-+it"bK`5(-k-9ie]!|}Siob&Qz:QSxsj鯊 CZsdyKҼ]5֍dsט0w p9gI 8 p.#ܷ]]^$h6^KJQQ6n*H!,'c(4XioT+dd.'⢂L"cP)h :\un(?6%f_J&Ti*dKbIp{tfJ?M"i4%,&;/s]ud8E$c4 {씭1}:3j]O]%5OQ`DĖ T$DE*Vd jU~EٲlYGw)d!z3}G+O\T*ieqUs86M|R(*N5do592ZscUq,ȉat+;'D?&D6wQܡ繢I $}P.~IJ77}V3фӷw<\ʶp%7;ڴK]˹lz)̜s83Typi2z=9%Ĵ5jL!s\4OlV`#<2Nov$v]scXq w{֢\ޠ!$H"K }4ČE9N<X@9|>Oȶ_Ƅ h2xEN#c_,h Okv1'sj4y?"FYpˣ'm^xAN]mw5逩 GL=~k֎& 5IVle|$+-85(gP$5$'Ւk y5ϖ:G~iSZ .tF1sapeoh1|2v"`mxlGoZgUe(9F>! ,=FAp̒ 7Eٳ.Gn_sMQO@G$ +VQm4?12pYN1 Pƚ~>f>m= -\ sqm:ЋVAss%U<$Tt()RV;jzTzBG"TnP[?׳H="msa*l6u}(}S>2H YF)ɪWF NhNк-5Tjkw?M # ϏVH>L@9ЖϪW]7pQ`v՟`}[ͮ᧟B1>=_(`T`]}SAl;{<ܗk;kk~AHkcմ|~F L2/3FԶi/lֳi?C$ؘ_*Gxse}[<6FbE"EF٘z;w(K1{Gj< 9M|= NF/vЪm@ȟ {EWbi%>xxL3<Jb<) M:W㧕).hQjx.%PֻrS=s0ʡc;\0~|5M;ݖǯFokGemG .s($l}46}w} 69S}r. \P4-1z;mޠ"$ 2!cSVA,FL%)x|691 9d}WjĢb1˒lDjUy:Qe۷Wu T 5 RCRyI̊]H^^0ebTp%8 BE$ #ĝwNV&*laoTﬔ\q!TIH]fDW$vPwheצi4njGga҈,:rrr90 AGt~Tr/DY:kgUa4[Wė->(̝p(C\=J_ iGnS;6r7h`YW4."G)^^;Ŧ :<y@ȲqMSO_L=Lӯn@QWl} }kyz5Gm,,`JsD$sGT>tˑPKy63tVɼ7uD1zqV΅8Ma1:xn%lˬU{W4E"Mګo9x, 8_k"I0(7 41+8hX8ߞf:<2o j1(Tf_93VR ^(j .TTbY{ii~*hӑ5*/{u^l1zy^#!06>^a_| Ük+M g{ODZ,rF 8s(S$#rM@+Ge!=\  j4EƱϬI/kQLj aiBwX);U:y/BO܊s]'/12X>E>uRaIL+ O %Evm>Iw2:5V3_ޟx ^ˊ7Wto= pʭ /㯒exP,'d+UrWeܰ-gWn|ˁC`@YM)f^jjSH#gK 6G\7isE} kѢXH.Ur?zL-5tT0%,$NՉkQC6):ehD(jl1{O|D(,/o]kf?^hsӊ#r5|Y y,]);WU-9&pߟF@l[LI&G5H5ںZ/B˓eG=bHS([u@g}Kv4Nj 9Rgcjpi%/A$VUaM低vOIٕ,U D[h$vUaa2X[LQqB7}LM> GXLCbU#}5/Zp<ϙ:ߝE:]D1I.am9 !%չ(7LlX@jWQªg1څX(c—)(sD|vgbZpۯsRHs ˰d,Mh7nҗzb#>9.TY-o!ʠQs-b::7x3"0J$9^cSş` ķnw>Ժ^p,餯Dզ o/=9$ $rѷbb]:͎$&Mǀ+ ;WkEVTUNcVQIMk7;ȤЗ%CPc6@>d)Ҝϐj_Vy>=aaR ʫtNХ,> =fyG:[En{#E@qUJs:wXv| |̳w?r'FD<>v} ͅ8\CT,a;:v P(Ėq:6XWɡk{7K^u#tSAiq9(咿O`>I wXng ^6o`}TI6c ؽQ;z+ #& Ӧsf̰ | GaqPm uŝ}KAt7n0kΎ+4@$Ȃ1LT#vn@[ *ѥNN~O(t+x`΀Ɓ=#aSzaĠ JWkJ¶&xx{g=PQJO#.odhK8Oƚ;s)}QWER DS(ZT`b25H⡹hN˾*i*vtmVǂ4A\xytc yoϢAR}2?Ҕ:1"Qo5XTK$n29z)W+&#M:P=?&C@3[-^?K\6ba7Vic5}~N|~}D8<<4L{%JBd1tuGLX[Adד,];T(j U@PEZ,d=/ O$2WǕ:g'-tUѾ0dNv]E+3fJ '#M)'D$&z|BNUBDs E5RdnhБ(ww/LV7Cm IٽNsZSTex|6&N )9_gtL~ ,t%Avz2e|}xݴ/&܇ ͈v(7 s?Tk y0w$u^$^{|P/"E-Q̺sIԇiGur jOwJ$0/Q=SJt)ݽ`hcr_Av3`NMQgD! /f_~#hs{ez fɽ&Rd# $2pcy׉]M\.w-EO텏W\V$9zo|Řk$Zya'N̮()(P>S{ׄh8d1rnQR "x\*y+꿧no73؊5W _Pv LV2Am0ܬsP|@ GO K^T63n] O紓 :iawQً-/yFi0_qL)k>J[kAUMgd6AT6< ] sĠ hř)[;^"%Xٙ@IOBrCO^z.Fk~Tه'p ;^ۋНv0DsWjsW |iX}oG.=Ij 3K3ܶ;)p/)%'jMxu&'ӱEhչ4n<1[c%`у љaVUWAʑ>%A p`}FcSI9Ws1ЩIu51{}![bB<|o(z;)6^sG)œx1@k9eI&g*b4Ƹ6 /41OUM:bBDžkX ko[yp @Ki Ȿ柔>;>z˵ݡwͧa[xZO[ I-D~L+/b [9)QNIeSV>[z%qmW9Q☍mhV[BfBȈ!(k7p~oӲY9 *BΆ Ƽ:Zqra;94dJT7N Fl-i4yv 9pd'p74T$]E9EG2;HFPWXV'\fY4j3)Nayly])vFdmT I-\ ]Z2_uڦoy\|Sl%\~_˵xwyZ&ב<آT,1BtD{T%Rz@k:vh~!f{]un̎Um(վJtbT[Z%_6 q:[u G -UFDdKOGf=(A4jҫkC_fI+ϣ>T;$rQP ̖A{w[?q^ԎÁAGN6͸}5R:STyz~k;gb\W Q hOV ;X*i`dy/_\AIL56Qvhֈ^QI+ =V>Nq(w_\y@ ^'Ps23-[wq[J G/Ѳ6ʻ{HoYdtPfLCHHVS[Z$ڛ顰i 崇 N rh{U5D  $> w7`6WsLh9™Dz-Gyap%Mo kQbaEMd[>+5( 11%G샪0e9g~R.ȅu;ZAq A:P@.]Z-#l;B[6 #`vhD7$u2H륁pw,C馶_ +U*hPYjO!b0 #>FqމW5VA`B'fp8&hxhm&kgixC_i(e!ڭQ $9 Gn{c>nmU@ Ča)rij^.KRyi=::vPضWAsD{.['NiﻍW._Ii%2~ie]&a QdOɴ,mA_V-!:ӣ!Lê<✼!pi(nT"ʑ>bOpIiO'c~P6@I_a 26i :PhM`x+й /il*2`EFShrj6cK=C - {>9ƃW>䒯QiB&ѩ{=%rćhׄ_p(Ұv9_/Fh[ci _$X]ѮzF8^8d+lcb&@礖hcY+On:Js?U46՜PC5-d=ΊoׁU}@8h< spAJQㄣO٠{C%L%*.n=!`B?qHR XQ[2~C1DSˎ`A9bȾxgjM$ ;>̔ߵ뽔Q?ELԞyoϪP!PJ>X9_۪MӻCyAS:@dp88r9k^]mu#n@t@׮Њhu#Ӝf GnxԠ{Qł퉚![=ё,s^22ִ3w﷿kOR#_&ɣ%MHX?>%>Ҭ ʢI7EPdDs6;=#z`Tfqhbov@^-h䫖*iEvFS ND;x̅!U W}>ZHIqcϭ|~hj=p,B);(EE~L\2c,ټ7i%$Pmf^ӱcL<&D][nMtp˙񩼎]U{qt89"0&5{aӒYqwYW+Ԯ cG V|T^UNVq<5W_LU^$,;z\/? ݸOwBOZrzZ,~VqW0Ih ?X6+IS.$Z:Wjފ|_Ǩ v7\mBJwrnRI2 br`of*i2I9\ _8q_LLകn/X @sWGփwl>-η)W:Vz{\Ku$AlN)EvUh f[U¹\z;k>i@ ؎`FIr@Wl7ERS+Hqf|,6;c M/| acatHfDt(Tkf8|6ŤTI/7='OBDN3g+8 wHZpҢ7J $:YJCD3D"nG|Xz A ~{uEY(g?|З~!DDO8ӭ(zWq);e6!ҝVʣ,1`t/*gCsKf3V`,2雜,a%JF拲)H\a!^N:1JkzN,ZB]8&_Ҍ5 CPԴXty.6Kί>9fb9]BC =B[jǀp;bOݭ)0g0yng\̡kT\͌1pepG-`x-nzX~_8i_j#W€FN|&ҵإc">D|ph\=ܫ$-.~9"E].gz=_(F]ld-\hTAcTcYM [?IN'?DfO"n L@_>άA"חΝwJ չČV {2Uwo |۠PHqj(1#"{,?pҜ68;jgH~ of^ 5;g'ν|@Q-+Dbev,g,=K^\У~2I|;3j۶Y!_. G}_CAMW"@Zun{"NC+#5<8}Qآ٫}_~6y .R_#;nqydѽ'a54=WĎRYUz)H%uU; "ӿ` ٩?0"8uq"J:IJigZN/KR! Qst##?Lg6HcXܶ"oqxQ,WyB.R0۾tzKǻ=8\aTHGE<-@>$%?<%0 dڱ7(ceڥ78CMf"O5X'Kv: d:儯2&ں #[3ڐ$K1#\^}ߞ46Mu#"$v J8;\5؜H \fU>Srr|{E1_`]220vW:c|" c4jC2\!ð Xb BQ ђKlg/z,׋g@ʩM#'UjҰ%M$N%7 [!r%xw&BBSn5է@^XOeY}m|tHrG.@ꦯM-=[-རqe8u+k4 |]椯wePjvp@Y,PKe)OneXZtF[VGxs*Rd" { df*´7dB\e3pCp$`"*!{vD1t}wM)Cߪ}yth$n^~ZοQ,[bS KHzC KH̾6Xvg'ĞB)ީ+8&/힙wq,O`&>8-z Ϳq: LbBx<4ցA\5^.:ȕDTR쯫̉,D "ĠѪ#^=Bvq2$N.I>^o  V :SEoH,[ XӒnx,Ƶ>ghڰHAJC%N%·ı:e07xMb2Ďt % 9lM: ,ϊv64ވC䥿W U2hDž$Y8e$!U ',Pi+*GJk#"؃mc߾M< ; umŨgKq%\1\[H nG'װ?k Sj]]*3>Y a~%!(@?uB𷕂J&kS@6Naei7Kt(ӰitvK,R|vkauJm}V[@n8r1'|53ԏXt㿒R:ݍ,׼!(-l59؊Rv .U/,GRR\Ul)y(VFwCmn'i{˪R o_b5m$[ QTLqBҡ60tS-ch3%T3jb tVZrdWKq~ "%pa]m*W#.'EZ /ވcdp 0{֌ qCsRx|69QCqO3hz a"[*lUХ"}qirSWi2?tBG7M=PֹTj_e%8Z.2Ay FމcRE5¬c-v4u -gt@ݝmЦ:,+CXhSeh >TM\Oɯb& ֬؟'M1EX&%I:QC.0CҟH cucQOtVhw"ru&h*e\ʅQ j @u :N[.W_vR!ciY7nv"Su.]jt̞۔ J!nDQEoĪZn&YMOd)7Up,l19y6(\٫R#)6TdPBTEr>Bܚ3;7;ey-x0l2nL&1UВ-A!VdD Zc[U6r6\JxKY$RoW3gsx|:LHG#qrC 㣮@q܁sˣ,0CT~vئ"aZ>DZ}_^4J\j~p:.VS09aY^Z1Z]Z_@*ƩX_j+^mQgFYWۍSrT?}pT1C8u͏I&$aU 63)M|~a#]|uᛅiuCiMtG5 ֩$ 30XGjn79uKT{Td+ j}=,BME@ %ƚQնS8lnQIz"vK @uS>sc=$-_ |*Wtz"N$͆1:W* ͣ7]o5k2:3fao.$РAaW=T4a!wL(cn:1ez+vS:SWHO\='9iflhNr z@Y´,AB?C2%T׹7"*II)jƠh8}ϻLT#5ٸ)ZMT9hQh #ʯce*'t{Z s 9!GlM(BlM^yW(AfpH3ԞbԨ_zl'dia @eq[he\$u'%D#Ĭfxbxxpqk^p&Hl`3Ҿ/DŽ5Իh!{e9_ ;mݚVn/ Q2]kn恺'0hN8ei+b*4:7$7|ɜHoTw۲>!zxiֶ!fIH>9Xd_#Y=d6Xs$9d, Mh^fw )_>".E#7+m|/ ~ؘpz$GX9%Vڍw'c%[>3KHHmOh@>#RS6+h7A" jx|CeKp?2XοZ1W,B;:M)G7WeD^1t /{c[_3 RXsHE%@$c.rv|@gm2l˒thQK[yEfCNŻF"Fr >"*O:®0BzhK?yAklY_E T2/C%':K"?Qö (>鯩E5 Aq,g_߮C[mćD@#IIk׿1">6ܭ"Q#^U;Z&9FdlSs=Ԫ8*$Hjt|ct@4'|"ȑhP3Hb.Is2s~o!ia<6\fiF=Q&&4 ߏZHXD}^7nl'P+P窕m7s*JhJkߒC{zL*4V:.b}R8JdcHc/+\_Œjwiv o":d>+M*,^g{*wo' 4{[ydZ^-Ce@^=NH]bg<'SmRVh:\ 8њI,eP8q}wrI>$߈G7eo^x{rkKNъNa /#qWS"[lJtxnAR "2׎@E_šGx Z!t"wοkxx|;&~Q,#R0PQ)Z_YLG *z,3io7}s H7+g>n/fGԳ>Z=i]a=.dzbIKn]SF d#{,tًEZJ>"^TB#=B1RATGveı\תzө&\.Q\ QTiRFȴiȺԕj|eṔ%Ǘ`鬶]W&Ϛpi.3Qj_a"7΂1t :=!EJ؋\\~O}4|M:㬇wlؒ WތDh]*`|w.ƪtGY9|wg(\w$==\ VBoqs 12&3Qǒe|s F _1IƍpXG0Ag9Cyo=7dL@x.Wj~9*]ю(Rׇ̜'1k'EӜZ^l ۊUmt]i+Lqx6YQ<末[f)N.".J?D}uȁhK0$dåv ֠Y]JftcsU3rQģe 7{iϲx.­%jPp^$['EG2Viy<(o2pyoszK::<d "L>4 B僚Ò霎3ZeJ BA{:ⷘ k#'Fx"E'AYJ Q#v{XiV>"]#s|OO jyÁ b9RˡQҫs<9@Z߾7GO2~6$izNQk3\2MʗP_-rɼP*,Nl *E w=$Bj?;!t2뽹uHxr 3AqfYC4{OW)m)wW|*ˬg踺ү/˷Xtˡ,U;OJK٦N9ɺ-":*B]V !~v#͒'IBR'x3_'H_m^Q]$T}'x!:(Rm88N9~uL^4a% <-uQ}1P@w"@*Q*9O8YPB~ {&3xdKaܪ-rxuw/:e9 ƫW勎AщޮwBlη0_,&=_:!U(FRpDCc2z[QH~ DY`8gu@^HT<-$B/>/^=4_}#݃8 1P$9:sUH_jS]C҉ C&@?} 1&%NZng` 5A`f$X~̛6_K:z'a F ~^:4bLִ}ݴf64:&xG=Dm7$J2G7A@c-]=zn=V)wVZe2V$"TF縇;C/҉d: 9:o/-OȊT =kS[q_.C;Rqy`"|TA8=Wqh>`ζ۪%ߞP*\-u@sޔkT<~"%]ařkS2[ ])=MXdg-vHU7g3J\1ҏ:'8QM=LAڹڴD`=fxwV6dۤg e i-w,}vSSP̱l~Rx9:!zH=P9ߦ TpJnt1n&yY016,nfݚT)\l /F:?dLSD̾M3TT5ϕP-@񰯽r#?jNt4/H  _RPLo .2wNvg}9IpT1fDW wѥ<6o_Q:s2]#TrCea ~ ?=Ү&u28Φ"e!F0{T`hE!5=;߽uXf̴ܷeG\gdJ,0{GmB)1;D`/(D-%ЇHNow#Qy= ./6юexoNiz)-4GR.tLQa*!FLOx2?T_̮&v.=Eu ޅ Np8Azɡ Y>49low kqZ=#F&@Ot(_)|kyVn5`йA&-\#@l,?ÑcSlۤiy-vcǚ]gӯuOM& /e .,SI'hGx :#Gg^$CaɂQgK( 79oA%FQ-׃-^zJkPVfaoԲ)k>iS㇄k}5 ]pVR1m0}o_K\r)fUNFwx6vDcL;%Ί26"v8W,bO~zpO.B )J(*X1 h9/NEd%Ȕ ?ErH Zn` 忊}`N[ Zp|{JW[~ȶ<5ha1jTdGmR}pj@ոYeC(4vpUؽ͸&<[UZCL1"F,6YPV3Pb=4 dSyl+`WLex7ŐGhmK0F=*5s(϶ d|`1;@\.߱:-< / [S١hu`ahRsJgIpqRJ$W,%P5e>{E]+y!#2K{z1^q+;i惱1q\gg/#9lpp -\Ǒ ? |vb"&&a9 avqq /(~A5 m27CM_c}X^mj<80fg+WO\F25UM˧\ܣ%Rf=i@^ !T)q) IjwJm79θ8i8\ ZQNJ*/ `"[=;}ym 5Dlv$<TF!jH{.s-F_D..[f-rTΛuInŃ`iHS1KT뼟߼Z@SFjfЙ]@!JAuոi' Xgg:_?>ea!P1ȊuSyGAm gFYLAH$>ƫz#sOf~ۓ XY;?Y?x|p84t5Amd`[;ʣrǞ+l{sgxRFEE_׮nuy7[yj-/?Gl˹'آi8zvf7IȽ7©T_F9=̓ O_MM_3)F7`{® ~UgFʂ ݋걈fz)BxhF7\=DEvfqL^VI4h>;԰ڶfI5A2u- S[mݮɧ۬po~ %pQ۸ C @6?u{IW4yQ:wdTVplUhд4޵L Y)I$.*JIx} W`>lLnZ2By{E((f&.+褶4!>C2uT /&N\hc-PyP; ϒk$ ixTۀ;%yWW`@:Yb ,UX$TFCMt rC0ǧN@ąi#UijsnB[ PqdJ ٺ`cٻt,+A bp<.( o]m}luP[ШR]{},+YXPm`j|! ǼpyBJo" 6I^k<.D~ 3I#gnGr`렵JWW@yߔz<!%ϓՁ:0՜KrO!?iJ0=rfoW @|j+K6qzCw{:D}^_uw{x7t֘X 8ssx0oZq z7p94EZ ;v|)qGRhMWͪ["q gx$n*)>7$}ZݚlQ[ѕKSv%œ%v c<AS[q"JUg\(el(ι>GA/|խCԞ4 EAp> Xo@91mnL;y &oZR>AK``9$͙*pQzYM \^޼kU+,nC}0xW*/+=;9=IMԼxuXK(ƪÿlNcacʩ\K^JtL Ŕ$o'*^VsU߬p QkUUUg Q$6iUڑ_\9aV_NJxD.Nzޡp(S깆JDž2ɿdss#iCt~kZe@lP<IZ2Fk#wp+'YX56fj+!G*C`=D];.T9ZF M,t$%pBhci=+E-IcB݂^P"&yFPb%*{A,үcre9AzSwCqs/Um_i]LW!@v' 'UذhC}RuˡQ1 VQ B{q?±I'p`|un>OCzdgǿNoJQ힒R]Ev F?yC񷐤sgչjB3J-թmo6|3EspQUt5ݵQpLy0*]mvHSju7eB"?2Ǖg ӗKcLT\=xPρ7OrU/et⃦e'0VZ P*fCPj8_"gPT,a\DiNSonfSZюc76ϷWg2ƁvΩ?Jȴn<"UL}Ntεoč=n@HSh&'ɺ#GBbS.eDKS00^0` m_(o:{Q>3D,55M׋hng=QַkPCeꌝZ8jl̖ﺪF"sQ1[7q@>wM-\-ƚ05T-{=l}.Si&BX1Lwy|̞T% {mZʑlَxͪjHlsq>o/LZUDkL:5~(E8]AF,"=#lJr7CM5/tj Ի1UNXbe/<jǫ+u{(BIt/澞%y>NXZOƞ0[),z2HDc5xtٓ[$)mP>QA7OO'b's挥bpjml@ )TTPƿY@eU_U`Uu#:K'Z_Cǧ_؈AqX Luu+.vGZW.cqyS/z ✼J EiL@gwVؑ4u H&@'13E~^*>OE/ 5_ OƊ` Rx&lD/+Vh@o[~ `n^}Smp8$-y9hdqdi F<) +_J㢠 =R%ӉSȘ|z'qEIs!aSH~Q\ߊV9g Oթ_ -$HƊ5LOsHɧ5h;*+9 8_R5"F%FM9T Ohj8q X;J]ȧ jbbHq){xBK4(e%M0X)Fhp"+䢛?qX:a1K|u>Un}S]|6;:C􇍺PcވURQKXZ:kI<0 Sg>IrG~' e Wފ1l. Oot +9O l:1Ś%M#[CGe)[ֆn6L_Z{ !2T:,Y#I|]zlEU71Tfb:.;|)@/a Gps@Nt4DkOfk%۰PR$VʮA(ѥ8@m{ƙ<SL.{'`.&<;k$nt ='m- ֯{.'qІz5BܭӾԲ:OpqUO •WJ9T|̝֩ig9"ꨓ`͑n!nN" =#8x z ҳ#> VUدQE3-j2^)mqrm Tm_X^֮SDu6{C E,L'(5ꭞl`)Dt!+vގoD;\aPr6apwECH89O&`4Int(HPn^L8:t>(|-.$!tx&ٕţgڟ|/0P+R9>YvdKt "u r ɣ#,-2-Wqp1z$.50%ļa6d( HeEsڬ0u ,=%$K@:޳=UWR\Ox O:@qU+>{U1F\5c F;0TnDJ/gLΒPͿuB?gp:Ʈ,rN=',`{@@g|湰^*T-r;ёsU_=$hmLE%K \h<fL/d깳˧EyQt`M\>O2M d}wABAgNλ,t3qoCYQ su<s.]L3- a55TߣQ1ɝAa}lZꗷHа~։8:ܢy ӺrL}v|բ1zL0T >]ףa~vӮA:o|a.Et?ͽC ,<@J;֓kKbA7'v_2! |!8a U8rZ|~{Ck1Ž~xUz_ (."nN5"&T 2qK@/zFWm =i[㮔F] = hˡƃj>b%/,i_RZ7s;vzy @󚾉щ>Ӈ1Sjwn:-vxT4ڈv.c$%NlJLi L%)3 G (,!@~=.|7`􍇮F.6̱i:)y;@]Lʇ`S@r(Wq~k*W[ AL 59qgût$9:m LrX^.L禩UCbY@AsLY#*z?ͥBDqcęO?0Mvojъ[jH֪TH5NSخ:BQ6+~=!MP'\R/oSlž!Z5o]}g[ur]ڣr ;<#'mKs@ŊvH ʢrD._-K%.uOӷ>fn$^I8]' ā{s5sʒ:HSlTs eG^5kEk>qG +)3 |3aitNnQ#o(ߒ $dic[PP8f.a|ILoF#Ea>Y $twE|`eR*tiEw^f'#f|YLH1'Y2w[&øJ%"s +5ṋ^M}q atWW>\0Ws `"_>-RS(3}ZrYiܰŽU!&}/98. tj,,vW䬖 19HB(* "䍬n|P|k )fCOA)Aċ:y/!Gݱʓ)u?>?/3r!R%O/U|5Ɵcϧx]|, X[DJڰϮ2UfSˋuIш\b WkEp%J ;ٗZneBUW8g90A"J.CDչ{7.=yV_zQV}N1_tl &h p"y3k+j^U%oW:nCE?٫XX9b*vQ&/f6Vm>JkQ\@E7D۟n>u%^{0IFFgXƍ~f9i#+[&M|#mU㺖tHύQ@4cvnN6o|%Ѧ]qWa)Aܼ$z;@A-a9C7IoeQC-WEVLթ?Z3"rL/<;Y׎,jsq.§r.'27kKnE(Z pWm`6v]^V}y=Lֿ%\2F:cChŘ+sac _ck}ùΰS)¥}9JtIQwE ߱ٝB#4WH0# _D+p\W@.YFzz:#ܣ-]JJ!qlD;l!khqݦՑ\E]/5N:^ oOwFtu 51uqX`.\ʴCGlJ] wsJA#xt1!zk`FOΓr<Dy3_D!rzdp_낉9(GB7h"4(ֈ'TSNX%`P8Cp|pxSYn}QrjCx{R _Iz^Y[&r8qx=_#_Nz a7[w/X!.eu3J[T)׬NG鲦NDK(w^jt N2^omErfv,CupbO39r^A^B,1_s=ou-a8~='ԗЌ )q>b3.#F!]dbؿVjI=-?7 o9zۏgj6+ꆟFKpb1Dx+oHa' cЧ36 y%0(Gevڹp:*.mڦbĭL9Ҿe^N_ziߟ&=hr A#ЩUK'F&P)6gfFh&q:m}R=]sK#t@ْR+$h/ߝL|<@-^4 zݵqKQ%2!QdUf =6 h(uȏDpX|mM-\#Z$m@>զTS'L8?9{bMrq[kzQ Qi@ёO].VR59 e #LIy3]p"rR_>Xď\4`h_Rͺ4ѐ ؛"eВQ6kf/kQSΏU,oz#n"clc^L7=9i~MC!K*[zGQ69$M}狴;^! ]P}PBatN6˻X.bT:$sm5G]AonJL>vN7V^u;I 9;\ΩRcQ\37ͭK@ښUX,C?"5UF;̳j=<ϸ"p3Դ:#%"a \SyX^|hUalDk'=vp!(j%gC0䬀"by=) KHSv_]%j3e}7s,n ~@nt\λZ&,abiCFԧaZRexJ*sn7k{TγB{Ȁ~YPqȠij66qY9#.j^@o&/NN3,yiM^8THбΌQ˷DYB ?`:r蹘 KL)UGVQ\~ VKJP ;VԆz΄kf`۶Q`xJ/%O)8wFЈ} }S}8SUX5ACKo =jbrOr/x{ 7ЪGDZD?%[Ypޥ|o%uK;FO2$ʺѪSNACV)1mCo󬚟 {mn (qB51w9@*[O%hy1*^<4'M{[|ā%6sA(0(Q:ن&{z'n|f+`S1ӬwjE880zZzz2vkfXmn@cb$oSҢ{a) !)\.S~"S\@O9P\ͅte~(wP7g"! Ng5FqJc'|% >Ը2wtc6FM0“q-mI!]*MN2tIbϔ"!ymS)ˋ3RNw1˩Fu>āK(ե'%d+lL6 %hBKR"G}<*e B?K}uUU^༮{6w^P gDjW`0TJ'?35G hrKŒƚz:Κ+%QKQKۧx yφX[`!yԶz@m\cySQzbUFpw֓ hW NIOh>9Sl^2` ;Ot\J6XpHZOikBkF/xNW:RX>߯f4{;nKټpߧzή.9x~! \(uLEL͚QVʈk)uTLEJuwQ4RE52:/OznǩB9ZU>řܟ{iG8UO/GaRͬ6<V43a=SfS U6fÈz+?F&CKt^=@bAN.vDE]KM*xTOK 2{ ^`!>m#ɒ\}>R7+ ^Y QLW?,,\6M0/]+]YcAb:鮸ȍQF`چ!xbNXǷ3KRJ&cU#-\tk٢eXHiQ ]AAl_KӏZ*eT\x1"8:1&͵7fxɕf|e?( eTrQ,SNT}KbI 6E%.(%h'hd,,9d9hԺciUG: oTE/XL1r?AĠ}cj>El؜ȏ2¨ύY8)@Z_ "$ Jr+cZy[i_EԹ4C߻"FU;nq ُjޔfqgFŒ8nd'C%ֹjw+\dvɟ_ɞ PJ"m bbpV7J]cD6oCPk9>H??ctnk][%elDؠN0Mc? s1/|,9pխߤ\b*.[=""^ߑ X( "ɍ>X'!n#G%ỡTy[Or\W15| Q͒]"fMN`MU -&b\&oom J6 Mqxx^c{aL>|:k|k[! \1ɝ;~d]|jitfzbR8$Xag>"hoL?0z|™!jH@8եš8GE)Nb[U>Gc'`a{}ˈjA<xsqaO Dx̚ Fsx2 }>(DdPv J1wV_D }T8˞cY~rs=&Oꃩ7-o2 |vd㱩:aSpEnX5PuִQFw-wT`pn*-G] m[|6Fxx0`=I1C 7d\!_[SMAw5qGGԞmHZS:DGqo97̠C(ŧIlnި映Ms}d蔂#p'#sN,:{r!]A]{GDz7SGuW˜ˈچJWTJQ\;%8$w0tNQ#Z 9 'm\ in壆޻H!CCd+b`Jo&9oD8Ƕ(҃.$QyFdezp;5ZaZͲk#L( 2+>D#XMegO;r@@k=.1JGJ.uA\Nͧ*7 v r=򠛬t@`1zm_}9I?Zvdm$65wa+J'WAEt$D2[$2l'[-6V 8cUPVG|V 67[ݘ 3֥W/ x('*OsKCB .`\%^uE۸h33 1l޽lH 8@sfȏ F "ݧF 6{?G'M`Fvp.;ˎ$ڂµфI`\q~;t"2(877 "#d;g{չ5V?{Qie[c!BUZc3;R?,%8tT|U}}_wyR;BV >;y6GMꆷ^̌QjoftQvuAl ?.E:!8neKș6)0:!A_ӭkj\{-QxFxBq|jẮۍd }72 kƓO{~|{D~ōQ-?c_/`|\md DN׋cE{y:?8rk>v-CH@H(ZcM{/b40ҔBxD%e_v_U†Ynnm]yqumY3\?9]7 /й6/hf}܂MtOᤉf@ st ?e-w/˂;JKY~‹>i(3zu*VrxE|H mn{`ꌾk7Ax"dMs>yYHk@׳7R"&aܼvmVn| 6}m`eP I]:ʻ/<[@ 4.BH?#Qt R?5̾i¾P,y唓- ϢϴF .3)bku]iw +\< Qw~[nm<-f/ѿ^.s@;:rkXpΜEة?u#umވs@Os qW> j Y\u QjT΍XPOW䬃Q9ԻzL鉥_k ϴ7tbc_&_kbyBuG{^(GB{n)| WN V!NHu\2y5CF}|i<kcs TTKxBJꭠOuzw ~d6Ce!%k9+PRqӷ,oNENLQŬN"u+/8d*ޜr|CL$aE)f ٠ Hԑ݂Bc=V^ C)՞ }/4?EIR)&ԍ4"0>hV}{‰&\/&--<_FU^)!қxU'(%oRJ}W f-(t ԧ%cLw9 /yrfjh#2Ӳ Y!C`䝌P [ezɄ i ɊCYCi A2#V%-70uGԉ"R]4XQEU/mj)`DpȽ&xh8c9Sgݔ߀'x(H5Pxl=;',sd\Ѻ&wi)u-;B捪J$jX v|쭙EcpJ YQ/EȘ$TgZ_L-D8wr>ǻ4hVR( oA(,GI F/k{5{%4ƿyta|􁠔0Pfr\N=ř̋l)`#u*>3BH"ѲE-`{TJVfWeg汕 \(M-0rIR4l.V:jx$ ݗR09Y9̷V,j6scz.ǧũHBmi8;Ynxo\k؇+=DJ;\5n[{ZmBm8."U|H¯$xĆQ?xPw#~ژ:ioéIkg%D#VO\&&GMބf߮6,@2HMgC#Il^ҧ?~>ݤ@瓂%3j+ 6t/4%LӦ 'XUQMmT/:7uDoHRvĭE{LӷcWѹ^hUwY/c< xf%XslwżD2)4y_^hM}b|آ֔bvPOG20pzQ7mަٝW @גs]JqL1"M@wiK9?I/AV~e5UjDK^~\Tȃ4>5"3ob{ne Hg(@iLЅgɵ4w :!]XE!A*&\az76#_ӴD>y'(g*s@> %5=RZHOC4pB+4# N%PW/~$3?w8?@5DeM37@ Lhpz8vYZԼ;X!O1ŀ֚3z<hM"  J-WB uwd΁Hs*1}mc\m9WԉE#oT-/w$ۡLNhfBVsD07H)WW=U>yZfr죌㳙)U+AE`D wIm S Io@g=o-5oֈ' Y%|8QaHdrM 7*\Q~Xo~Acgo0a,)u`͜X'^-ӤjklhW+\!xPO'8Ęxx|4lI,5sb_bNdzBw36ߴ-dC b>/!&(zY Zwj1 245[aFl{ ٨OFʊ2oe79UNf;D _]D":@4{Ů9&;.9x:&0Ö οHrKW f˹ӷCkԦ[(X8R/;(͉S.o.-Jdu |x&P48]p]>)pэ ;i }뙮<1t&EGϽhAM7W"+`ar^12w-f{ Dtݿ5jTad\ ݧNvTxZ݊ ?3 <[IJ{*@߀L7o~o7# u&v8+vz7؛U~K}"4,QUzNp05@Ob )HN~lYF5^2ƽI `C7Ia~L̺Hs%}RH}uGF" cRP+VeǦCJi /2DŽ ]QtU05f5o Eky|#?U =:|][ em)K̟B&]X>&m Ooq WJQňA#K+u;8>"wTlRgxΖV_l[4Eyru8b|:*p=Y'h\DY;e>49n!Mf^GF+TXPVJ#z̧U\!wxyb_C}_Lu}CdpӒ^ͰdLʿ|bǘs2,,[O(ƾd rEWXgX"~_[[>.Un0ow`?h$\M}QwC")ukiVykwRIէ?nT)g_ԅp!ƬrSP7<*SyZμD<:;J6͎ȟMRH}eĨQA DϙwC=nt]Gk|Uҝ?F{w7 _ŞRLC ~NYc q]) :_0Q2R~8e = [rDx.%IoW2/͕%vgDcu&jR>`qĶmp59N ">+s;1+{?ЫV Ѫ}{@Kأ[D oA6cx|&Ginrf7B&ؙP2#ڻ".`6Cն)=M;Kox;n&8`NDIcKc = =Y;VuAIM)ɦ1Lԟmy.s c$44?:)imiպL oF{DӏzS |Lc+cڗr=D*Vw7șlu`fD*7h# "=쟘qG5v F-fOo>`[6$FΟ/aaƙ꽭{))Ҷf?  4'y( ʨH6жю%EvyX=#r ?yǠ {g(khBcb|b;H dMاiκI̸e@MMoǩf'2ݐ0]8{?q[zǚ{ثMћ9IH=_Psꂶ,DFy#Y è6&}[L;C% ifk ٍIphAWm5ˍ n_(bpH*5P8#SH/gJ; &iĸgK$Cwު%=ÉU E\FBxBwȠVp0薙@?^\=fk nKXUqDgnׅ:X|}Qo}ru%~s6ivi-5˿=Vj jW:M+@eNwH.!ܔ`,Nk]'wcwKĺ26/N0t(ʎUtQnLz̒K?#5Tc[q1Eޏs/qPUwzתPKtTr_{ ׻؞A z)˜MZvXФ/\s`Ms0Zar~8%}oٹ7du o~i'1λ:9ӡlqW':e.𷭔ߛ>ʔ?mZ>he3Obߝ:;Vi-ds@%dLSEJ% `JyU#-H^s8Մ_DI=OG_SEp=C-NO7 1dYp >kE)B&Ϫv+:BL9v%D}dt-ծVx_m$S<-n Ú(R2(k?|p{wr!Q\e QEXu+*)/j( cJ-I>t版@{ 6+pІBo0E]rP{96a!O8]sU$ LV؆zBۤKp~q_h*PHҊnV S.[V ;t!J. }D4Fݠ t|DʒѦۼy*lS@I+_/u:Ze%?Z\\хD4YE`c|,⟁rW083la|%ztd k5ڕkxf(/C]g6[ׅ:=m~$9CL<| Ϝ29V8'FhHx2xet  oޜNK^ *_x &D u9{V?2ZNLlףhN3]42oܐu9Qе(Au Da喗:>h/ ))!eBP}{¦S$\Mo7eJ?əFc) de="QHYCK}7э %GdDS)%Zw1ĝösӞmaqg~͑RE: 4e"qBATAXd@{2tU+³e TҼ3CQ@᭞$>AIr3>P?fr.?èKMj%|*R>mhsi7Vv$i@4hTX pjJ).#T'tu']k~N1DFfX=dFL#7ԋXfςL?pf9磰-8hKT?1Գ5~{4C]!km[U o }FwI-Xڌ7i}7rPkL uNzCn n@4P[` zF==kU+"%0#lsƆ+p*QJsiyb=Vnv5I_E-6q(s$F1y?̱OHDRrBv.NH gہ69FLcҠ暛8U4{N|Q"/_=|B , \& |-ӧη~ 'p6K.|\H!3g5W+~HZOc0'`X*AƽOD#Ql?/YHHȤS NfZ<:~am,ȯ'!~1+hVe7>]CZ~YVJyh"[lE$% tb>A@Pw{iucz-J VO;oX6̓1w4Ŕ\ wa+yf+mO[{NTjR J$X}h`k uB"˞R0|! 4H#j_ ƫ?lA gR~?b #|8k*B*peSQNmL9 ΥjCZZcF$N"pln&ұdc ׀ӻ9 u W~Fk 3{Q7dX1 .Y*S.y|eklg1!݁<Ļ`9=ONwxqYY/cc`rj-%\}yEVEYlAӦ%Vc 0R< %%Ÿ IU]mLOW R"%i*ezyfy9eOcIŮyv8ԛnM2~|@ xf -E5 v>(Ln#^ɍ h.S@a X7R b>tid ({ (gELHd轤j^}_{pۓ9:;8r)Yŭ\"ȜQF@V88TT7;7 ;+ ~f/l6BtշJid|3D[?VـK$dTSi;TlojiLːCt_4h]ķb˛> J +lvLЄv Rk$QCx|Y68aS\ 5/M} dc"`/J3YkAoTQ]ss\h]E2{" ʄŗ(P^o$plI9_o{hQ5ZE5ƘmZP*b' 睮3ػ7XjW3suOh [.%r?Vʾ+&#co M%W3.#3C=-_n^1eA@a#K+g>j 0 X[XR)?]12G97\;bSCĂg qgʮb{_f4Z'QdRGܓ9.@o1^O^p:#/9iH$ӘYsgulO*R$,ď І,q.o gΗ|ɷ 8~]&BD[Vq\,< Ӧ26W:!ŋZ!j#'/BxȹVt _8C (5H${L-kJDZɜ)=wND6ݐ3ӣp]"gmس/ϙhN3'kfxw:Ẓy/e{3@/}ḷ`2TzR/E~bKӿnCدfRc)0eҔ\$Vmczm^Ҝ1,&"m K?B-:M wD^`U`J"cwm{ y xd0e\qSO׬Sx:gp)HBIς x$K)jؾqIcGJ iQ"0[w]tG9ua6vlV|Yu?Bƅ^3RY鸠DwoYy !wخ7222ؐaԀ8=M~ A# BV|) վJAejd^Hխ%.ʃfdZ-){J5"nģ*g @4},Jێ_VІjQY <L14"tf^)KeW2ğ-х7NM֓8AHF>%+:y=sO`NGe@&󀭜 "㩰a.8f%cQd/!.3v O}) h`t|+tY`WB震sH!1Nu(hZXpdzI@Y Ҥ0SЧ3zʳvy:Ylk Zlr>O:Ù5.-@ԓr#ZFTt x˴buF‹AFOt2H»b`ʐw$/cű;qi)oE/TH6<j*k2G>`'OE* ё@P)fNZ/;'1[~K}Mr-VR+ ҡ$9˴\17K 웂jokHSS<4E9oaZV#Czk:=d<1H*yTNj!IWKax"]4z-kf]{pSVB_a0nŎjȂ!b+So _lM Fq4acyQZ'lL$$(Pޣt\YRfv O:qOkx 5M7H  O1ib_ 4nO_ a/-$hO'L$LYJ]\m~-zc;1X;WyV~g rDi#A?F@ljpD#Vp.]o*i9﹏Y E_$YȊcNyCٞYb:QJ)"DŽ,e]À"c h`II6ElMlsx786m{\| hD",}9DO|La!6d/ٵ.*aQssX& ͣpBfJ;9LtkRn`P4i,z;YPqzE-<}v*\c޿u~wIӊW7)ǽ H E׍YpqCxWW˜D H4wܛV)HV0ʬ%6nB0+W RpO/(Bp:Zyt:prLa\8&:pmnf Ƒ 5ŭ_.6f{5Mwo p[Hgy!>JjVQWQEjxrT{qHK>rJF^oN?c<,sA#z\s3<3s3L= ,GRfDoDL[(ԗ Ft`[/] N(l5kUx9/QMJvfDd]YFЦ?G\73|!>tt^}Iɑ)T^ړd+>_ቓD-PT5j UMbHTZ׌3=9"4E*ޑ*Y#NCWB_]?:)/!}7α"S\i;7sȀp"ڄ+a/pP23Vz-2ԇ\Q`wJw)`FYrY>fWix,HpAAE?.םe˵wCxu<zE3cCo<ީi~Pk`7TfvЖP6yCB%ƫ|!3hjQ6K= :R{aEl78:YGʹY)g8&VxAæj{[<$H2[> J)ӛA6smQ0k^),p޷GrlDZj:;LHڢ3oDtv"e#,m-.NP%ֱ>J7$/ )o2#ΞFc5Cx7e##LÌ_Ɣ.(ܵ8k\(QkI_8)~ԝ/\O`;mB>e^$7t_~qJ__a. q>Z}m{0@R~̡+@/ m2 P Z h"<:L6TjՔZ#BCA~QmԵm -`=Gybg-:Y7D2:f(.UڣؽbgR 1㤆!~ܦAoLVبp/ܻ8T{BCC!S9!-c ?]$ !0~$-Rv.QI17|m{@n~˺7">#0,Lz8T*򒍅/ yW&ح8J'L"[mv?9\2imp*<o𠁬Νf瓑HU՝D5]IH(/jfr@D9Hh[9L ݡvEJWi*Mѫ-hxQ5c;x!4q@_!~t0o/.vs\4nf2r8cQ.t}>V"p*Dj@|l9V*5Y=/Ꮬi'Qnt,@Bqձ'@1q7_NPJ z| B+7#ίu:$뾍Wuʪ+v/AT 8N'e&dxP,VwLFYМ~t8ۖsj2'js;:+spU.6;K(ī-֕{wr4iIу1 p}5y$#ϰ_&d3ol n@ygAX՗?Q(P($_+o$z6ɯJoP؊~PWo W}fޯPi=ך1n Yhe;uӒZ7P, ;R p%ɪ ^yqM*:31P= *tw^&2FZyKn6F 0yTMpK 25H!U8=qX&!"ddEy;aɘNySDAX՝Ӽ5+YϜ. µzFpjȜB1xCIC6<&4~$VPW !ۭ>?a%QKh&&Ve]D 9yt*Af/Ե.MĽ\4*vCGV28$$[:G#c?#E; 8Ǜߐdc_ӂIJ,~u~.' >7F]^x-S&m˗3 ~Oۭl(hz [K2S>-p} .uI߲u3oa_/eUna_*f"(rf;7ɲH\K rtw"+*@d[kXlE T!K}dKPVc=v>^ a`71SZzZ?9(]Zc YO~fjNẁc7c"a-o-O*8AkQuk1NF:}-mHx-|992 `#u+x0(4y_<ي5Ļqj^Tǿ.w FGv u/B9h܆(֟@lEp!{`%"  {}@@V16Y vNBHph<(Tp$*W2f>0c(|F#)w}xұxq6ͦ+n >dUj)Jl>M_CI? Ma˚ƒO^w) EmlȀ_Qv=ZXH˽~ aӳO?Ąn4˚/| ,rב?qc_؂ض{W4Yb.Hj~F~y*# T潫-_]w=[X}XenNXtit vPPRȵU -Z: 8paɈOFަ]{dנ[fq#:)L "!Y5џv6΂FJЍiSx9B޷WIG|m 7( ֌j.61k+Gx&$26c,f~؜vB\mf`AtVظjݫi> YA:º2{#Xȭ(Dٽ^)2^,e:o*ɒ0F>۰jtJ,?|'7{!*ׂWo\ dM ~eTXjwD Kb#^,&{(6Yr$K=eڥWq@y$dPA<#Q#^^Q_b")gpoPbz! {>M՚N F_.gU?Q0@?L#4P=䓽bLn_ey "¤ꢯJCUGt1:8Z)fI)=$١II&zԇcC/ǭAooHLx9.JjYH缴E=W%aI aǂhyuH&?d (\@tįP;Иz/n -1Mv/~8wW>7Sucܶ'RnPʯ9|sbU{/W4O=ь趧=&䊋:Qe m?$WR@P$Kr[P7`JPzOvBp7͞2b8(c Y7MP8gjNH96.z;*T"*aLjapSYNW>g\ޝ}uN?ǤS(qKZjUWE@A@Q5UvX 9F~lam'5o T6}p 﫤I-@Nw!Q-x zuSroLN0!@MR9v۩a9Z}mWn?8ZA5uGs' k+F/hxtr|]SkǁRubtVќoŜ#sڳʟ#d cr"At{61Q ET[h-.DM-退*]`Q\ z~"X|3/6v? O' [0pͫ@Fc){wpB0q}7Fv]FW`h<{Cz*8dչ$| 8򃶳v4q_t:ZSo_\w gJmyfivn{'mRJEߥ8\% %a z)gqz,y(^|tX,2Gtu!ҍ_ fߝ+ӡS3 !sk4 G3[,;poEYX*n:sD8[S'9;U6B aꭅ{)}NkNc qj1[#S|<6]H?ͥZ]Mq]+d` L=ޤ$tFޖ{Q홏 Ց7eS ,T=)=$9›Gc. `N`՟vkx>b𯿪s;-M*c{v?}zL.0q5Cr̖uB^ɾY Bf@n"yq[&~y6ߎ-ARbvBױIw1\vH됫k}9B] rl^}'Zi ^tB+Ձ7UI8El[3ͧTאG4[^S4U\Gfut8@6UsgB xUjNk-"܂sK*y^oޛbVɈx~DР߼͙GF@ч662{9`Q8g5l!2tsi/"|ͣǼ;(ȅRWW0:dU4n2^䓉A2l($pzVuv\[v T0uC+p׶`}\:!IeBq=1+$26kfB~ם7%w綨ۦ4׏I9E=vя._- 8(kdgtĜ;ߤ,X8K)ey&Ow5]ys4Jկ Rߗ>& WfV0"a2{]"6)Ox\b{ĸYRZ>U^'* XƵ% 3R ͸yTF^MB)hN2ԓ= bP/Y^ 2hclA".7j{aŕQ+l*_=ۏh9Zӂĕ=&H)rf^^: ={6/qy'fU !Vmcx E  rp~əVY61OR+Xw:EU_9'Y;2z42S6qߋ/VO7'[R A!`t»`B ^ϻ6<v6 6{ZJpuVqO%O/Xr+JIn[r8[8C)T SB/W \q_&iH9fw aJPV:#PEO'MAuN@DQ]4qUږd m,NB1lbfQ\(z*v(EL9M<$JS_1Vs/PB$=t#fac0&e# R)hW9έ;f:;vx.)2a`4`e3ty `L fVpUUE㨹2q;[U;ҦT;L2n jF$]C"QWL3[&/Xs,G8* 覮)iOΛ,,p]ThЊOڏwUR$pdg X&~ګswP='d__Ff+>!CRBjܗ#x}vӠ0*ٟiUx9f&^(ο|\܆f%jMB׋4fn^ڿoo;~u54v v'@nN"Aa!2jxF_/$DܵA>r̒d'Hރ{ Zp'ɻv&gcRm0urOn6; %"txɈO9OJ^*Xjq-IGUsaN;ꈝF 1iӬkxe^ٝothEʧ{k׋B>.,|wh:!z0 iopjY/ =GMCHZsxF[?\ҽ pvW_W@\R6',z޵t| \]Sw yɬG[`<MXgY1n#ҵ=j= f:&2}(Gbb9wx!NcS 3OJI9v^$5]h(k(&w&(]XZ g[PʚʿTGE JkG05¸7G+k X$-5*:ة@ctAT"iDTwW\!^F߬Eݸ!a@-87aZ ,sxk)0E@훲9BbG-qJh=^g8( k$$=p0{J{XE[L؟&^+FovoC~&ĠUT)T'nUcϸ(᤮_ fMHU2 pd%rmT*r8/ۿ}?B8yAn ¸ր$i"Z \NɎ4rE}A!%~SHba"hsDT Lu^N0-n}X0dwؕBXG*ųuy6כJJ"UAM?"pyJ-O 1\Jy@c}O?-W;4JksJD?cg83i$}uUvoc|(&E37|C KS>)$3LQ~l>boQ T62,1Uӊ R ͢^˺erWt蘍hN-u'3u)uuo)hH`cb68Mhedzy 8*eJ2􄋇D[_ 74Kzni䶍N'N8-CHd8}B\gd;!{j|kȕe01Ch "@M$J2xyH+.ZSz<@YJa:hC>M3{R$%HE*t-Wݾ۴7/]|$b\m8dZJƃJj_P+_\Y4ں h=ЯŔHl |B\44PwoK"$%<K50۱qv7ЉDc"Sք]:+sK6^OC&eE>ZӦ[CRn[ @we^biHB7~E[LW%xߡDKM@{DLM$@.#ϖ:ѿMqя".Y5_P iCͷNDu5u y+%k gęݑԲ]\ "wNs\øe*R3"y aT gkb,Ϣt9%(15lR([mY)X%ss\ Κg)Fid8K>pH͕#cq&ol]-n\om枣cqIq5;f%V^0Ɣ{:>}!T?:L՛rSdeRQ1m}IDԧep:f֛ՓS4[[WIsJO&ќ3ȍ Zyܒ/V@V[2gU}"F.(SHkfAٿY0KƭU1.ߍ6\NT<{vЩ-n*'_pHe]HhN5M}%u궯ҏfXAùIqw)?J @4IGRbOLf_2L؊!"(hT9u<܆MRFP2BX( ( (6NI³ZdKvFѰ%ը%THtb=|/ߏs-ܜϡs8>^06ujқ$ )Kaa8rTd/t/F\.@$F?.\ Bj&ѤOa&T~'ukM; , wswi#ma{@w)'+)vdqSe" % ټS'ҷ%aba"&#ΥYtV%QF/j" %Chu ĊzJ>I\H%W4$1 jD*]K"?koSfaO)`C}B mH˻ֈkJ pI`w|RJLoks.5Eewg;e~,D"g143#o)SG, YN?"@<ތ;7D!5!yR&0:;0WpG:c  w睘t4g1kGf4IY2lgUGҮ^Šid ʄ QiP]9X; {[D˺(¡M~XUYqR: 03+D "[]z-d.`f3AjxUǃ%HB#ͭ.xeb+tyLBƋ=F|D[RGPË cn#EiPGSm&YYǭ2wS6 ew؞&TS7dM`N0I0h.ou]S߽x:w|XO|"[6P|+Tqex{ލT^Oom41BR3JKuI $a$udF:^AIt6|L ' ZPS[jEBi5ׅ5ϫhTMD.M=C*#^ HsD.7rK'K6ܙc4%׺v Y~q¦t/@RMB}v3xu^`WaswSwi9f`O0(CRTx"8EbGr0~:Hp&`7$H }Id,#)z5Hפm6>$/L?83T &D`9e ae68t% xzۂqB\O#S/kn)1,Zg$V5Bz5i]X bJo쑗RD(2ZفIlx4"ɽBDzRjȚDH-&mgx>ҮCJE e%)p3u3?) WU^AWVL0Za$-ˉs#|ӳ<ZRdmFcz׳zUi(`Rxne cE6ȕ}{_>R?dqސȍ(pJ1އǁ,[n)ț鹵y]%j*d1ɖu>X|*j8pM}H|E4 $~o8@e?T[̽)xD]?8w} J9E_5E>wRL>nߗSlPSQÍ@֭ 6ŅpQ[OXz"ыwr}6geM&;3A1]w+M g#Zjт[W?QIfGAX"P<<_ dy!c)c`kJ21Lh奚lQUSUf#e/h2LC_eqe\ }ڌʞLADGAc ږ אM<% /}7Dc_DaǭB9Wb o3Cy5%#nCd ȸ3stKMI^aD5o )AF"Z^|F(8·tzewÏ4u̯{i+^8>")@t^SV#`_T"e;% fXޮ0{V+\j ۄI{_5CUG$P~G"P?;`}G>)hcY3+ʹzFF\4\,#oFPQذ*[J0&&6]?gb %l:Dk&mX-FGІ˸1 es*QVk&0t:O)6 9vE}Ž/V9Q ^]nguzxa1Muf`0 RvE``–lQLeOU;yu;|{jdїNZ鄜LB u8{i-1o̵,ɘ!5 «LNޭ9`Yns~ʂ M ;4tf`p7.~QP-:H+HB\퐬㊞Ow3mUn{Yj:3xmBɿ\@U(l'@/K\=g)<ڳW:0/-PMK *ZGKr42r'{UWa oY12Šsie$ON˦txݏf@[(%ȁymUT&)d ^KovyӴc aA!9vMW|Z+R?!6[$ p9qm8d NMvR:> &OE;`% C##&+ sF[pA@PB.Kj^1Lvto)@o. ,o%F$5Tpp(L"]_ci@{ja6&{vfM>G9^72}KN EŁϳ,/?+X/+ȅټr>t;h_)`mx/K:W}2ۆ=+#vne4b~+봭i\sY SFA?iq(t;$)BPYm*= N>^-&b:d14Al! qt .kWk` 1+KZ/yxֈMϨ2%OyGK{-;qCqH"(hjX+j$I3D::~> hGh*ҫa4V91ڡփpT%m3Bﶈ n I{?[8WLpm !t0n*B/ƭS gֹD.gKp;&/Mƈn E>-}%9+h=.]+ٗ.\7fI dR /LIv2AR*%Ba_ !͖{VNU5\D*&N"zeM] ULa0:ŕ; e7װv}qGieRE/2I{L3Fe[y8My6D}̕evm![~f< HKLQ4,1x`J<23&3׾TH]Pm)4B]2ɯ:։! g'wx5p_j/KrrlC=(a 5ʡdTQkLgɌLGı?u in]i(鈋Th뭛fm"n<]!0Þn'dSBZ8}Se  ` (_K7ĸǎ3+ \Y0 \݄P^@囹W 3xDÂzO' q 갽S.%+_`|գ;VR^"S`I<'Y*>D-pw2)KӔ2_mEllc?! j/;pX46){~GN$.;jH3>Sg@~LHR9o /5AFцN,f(bA8WuGgA{@.F=p t\7fxʩE7O%RP[mǓыǸD;`04E]b&P Dl戫U=>ݰW_Wl{Ht٫Z׏tssKΉLF؃WEFNce<)Vqh,ҏ]ھ:9wtlfBfRD<UC-yet=g#Qe_x0w%GvGs~^v/SG}#pQ{GڷtL IW38BnI-;#4eW.V)e[>!q<ڀ^5Z!jREoW~hJe'~ XI,_=N0 HӸ],1%13K:¶VP*$UOrNlCmԧ~E6A{k$h6]]Upدj~4?ƶ>ӫ4_ b7:p@.^p%KA_XH0rK5kMN} AaVAж>2mܻA׽7ZJ9vt~ͼ5[;HO *`U%,C(s"D~y6Vm}Ӯ]9ơ{ౡj޷T[Q;IXrzŭ$ T.fp)]iҿgd+;7{*zRG=uZDwͦ:,4SA@Uϧrm9O_w۳s.':p,Ϲ5兲s٦M֛^nj*v5Hhp~䳤 Bl6/aVJW~\֡:K%b&|=U!<RS4Yk9!E9O=F3sEǭ.FyTÊjW܁gh)V˪@pF^"Ko5ѾaAwzMuCZPxW!r;;~*a+0d2W5Z#TCӺOHЖG$3UuN'3< ٚp!×dV1vAe 0^ţ9{[2UHk%7ȀDr4[ | 1f&: k;\;w?9HH"ǥF,+ xuY4r;x}K+Ƭ'ĵ>.LxƷKE@Nw1(tAL)&Zrc|c{\~b0 FM*ϵ.t}Jzf/$ i&Fh:@lesM$ipxr Aʗ6o_5wP`4#SFXLN1fNdt5ՂW #eMՃ-e1;W$Z8=О݂ m;1Z?iX  >3 gjGq@Ŷ3yzй~ĭu<ްqi己Psm%h_m.j-{)2WaS9uީ!a?ߜF\6^F(,|- -t5`z;`(' oWEjDt1'j'movZNeOˀem<~۔8qT[˴U.6 H]ϰKKJO 5I'?r6wQuhY78(k'U4\gs͚_p&gc_NI!ƲJ``WYY+y HQ=))ź&ddOML_z Jg;7R#F6ۃ-Z)Pww3?!gM[%rҠU^mX%7oQYوK2Ӑ+=H/nilË8E+c<:%mZ9=(Ӎ򎡐ecXK,e&4z,>Ըyش8}~^ź&oÔ=h2i;3-$&8j-,S{@c R8|w亻#sO(H܀3'.:ci/5TkE#`LF$4B|54gъwtVNL81)lr=ww@w+SLyph^X1ڽ g ~u?0bGĜN"lkKg*-s&FP&0|WYօ2_O1mAgqs/~ٚ+c[/# paNTCOH cN'hOM.cO{>eʑi cgš;Rd)kg J?{*[0:mj5Ÿ6NN;<>2xg˓Yavʛu?3wۣ|v5>/  ?E5BwNW4`Y5m1wTUށ'b%w#gzxҩJshYԺ,wK!뜿v%#kΫf:SEQ|y7Ov9$stpCsIkN gNSjEMdTDj4[GE_=M:]Q@N/E F yS$|;[+R<Kn`P%X(d8v.3meE8_H5 G6 /2@ ome(p;LXԅ9O|zl!B^fವI=c+N8 LP-ɋ ⢫d1 g+==8%>l|]ws;,rbA:B9mk ҼdmA+ݻ [_u` :L02S͍K!G X!BQ? (\/ 6b[}Rmۆeϭ6!d6m&cSԁ# CZב1N |YWRd!Fk&̋kHru Aۡ@Zo@#ZM Nxȩ׬E9J6 ؖ$ҫ#I7Y`B -㵼2v9U,Wg%b7AaV1gCL^ρD9V)W~AZP7 "T'bpx*G,2L0o~XmϓYɤ =OF8/gL\h4s98 VD>F8ِM07G-CGCNRdrJRb3|p $O%SBj&SPϡ9 )䗦DFz>s7b79JH& ӹfMK զr K~<9T33]lE;KFpBh#i E 0A ôD5˿9v7iG0+s5[6oza+bRXt}̘8+q2 ӜvDI띝3#U@($p$ڽviDp B4tfGE1P> ڢl椡Πo|S jn/T8oyYNdR\uj[Xl8Ƨd@CxRq!tì<U$5g)/tww#~NpYDM=UȿgQ's.5Ń},cn炱b$貙"AVC,{x&o4J1d /xvЦ=hNWXGxsM NPdL{\ lt/ |FMmΰ)m7C@ZW>[?VdsMš~xwk8gsGofRle "e\~ V zV2J<;YmՅ$v^WBKUqc ڲ59q & Qb@tJ@ΙdurW :\VzKYji@]K?" fo aU\{ճc W<|;=:k`j;>?FB|z ֽӋ٘.^&]:Wf127靖:9WC*2LW0*4]ROmoCJ,y)[j/?A$ȹwz~XN|'acȲ%e|Qoù2K:6Ǜ[ΛbR2ܴf8\Hq}i/YosA!Y. 22HDN1Br 'yBE:E+caDmӋFz\cFܳ2B(dL-4<'ݹE8)Zݢ|(.8l G%Ze}Lе?3Y4s^B !U3MB-vb`5,?cooAH{Kչ#nSlg!OraJPj4ߕJ,fj,-wY.z!ӚĮBM􃃦9ҠnW3 a}\Nq!*zʯ ,b^3b"B' Pz3luޤcwWLɋ6V8.7,(^2c7e5mh;,^J>{Z )#T'Xxh`H9Jd76<~k݌g!6#=yѡTǛjWUqT|<+wr~xCXǞ/WMRTvI|cg..2$9#'RV ,pfz5@Gk8(ȃwXmR*8忿/N:Q/GH_|'\'ȿ 7Ui(d{[#o3Fy8wJy֜PơD:/׶X^(|L'1)keH.wG~Zo=г!<(-mU>Qy}ec*bER1:jW JJwK&du H\TF~ÈWfhX5ZBDU$*; (1hZ?T ~ѸuM[jRݭoz7m $n.16Q,,.\Zbv:Sl gVGX>~/AH=j_68xM?%F#E܇`uMdǕ*@>QK(1g=!`0td8VsCrNj큾XG73Lf+j]HW~ AtC#n"Ah<1\ojGWVo+kʜ˶5kmX^Mw?C} tR*!tT8Hhuu;a萵)=I]2'M_j!O{^ _O6^R71I`or{~x^61g ɹ5]B]Q?jwoHpA2`41W)QKD͂]>*K28NEz 0v `|ߦU! -CͿfɂnq?,+smS, <g dr F|UhcHC>u:HZUO\tsXaoS609Bҟ7?P>-vh;7Q#%qanvz#6|4cQ,!g=AGgO#Ϩ:DO{ LJ4m *R[걱+t%:-te{ ;ތDHKOcWͭ !bSx`_ rXޥ@V#䨏`9e 7P /hb_k,B2a\OKtܘg֖Eov,,WP8ݲk_+K|{$WlDH|/i8_Դ$XR"T膮_̌Cs9|Hu<2: 4!] %R̶6sžҷlZ1i#u.WGO-ExsYJ ӂ 20,%]6RVN2C^0y*'. #{R'xZךs4'yJ֛ᅇ<&-K֌>3,=4oSGUY-%kB'0Taqd9cwoo |4[b3!4F$cʦ朥"9˸uL}1ps/Qv-!'>53>eG*Gy= K~ "JZߜ, ,ϙN(5?MtYΉl}7X\i}ղ|!Xr~ 0,`a[qߜ:I2W5@[TX5FhXa!{y]պT56E]l41Zt?*27$MOVG Ŀ* &ti[`ZC&kw/o?dfapϦaWXw̹.5dYA{SshD|x F\}N&CC(=J/nRcw?T]סCъ-ifDzdHiVO%2YnYM5$-h£3E!gP)IpEp.Wfܮ/6#ٹHC>*2&BI\\'⯀w}]?M6H1 NrT+tEDC{^Ҽ'AfQE݁p~JX߸+'7C.xQ`l ȸj$_mHAK$90!^ ]vބIo<z!&`xs_mvEt\es㡧ȭǤX^H#6褠= rCeuuA[i$B~Qd2\e ,Wg &PE=s0/#@vpC*4.HwbڿR%rLY8wyݢ1.kAJE!ynTW*վ"[˔xڄ }꥜ɞ:XRIXIW8tb &C}v /cQyQ}'/٢qgj{nBc{9ıp|d, 0Ic)&!cUQxeU-__|Sq *e@(~xAᕂE-<>,Cvݺ[CIuOHl3\tHq#/Ӈw^:Opi5Jd7~B !hO/hZV>Fq(6|yp(Pzrb'u-\xmJDԵ`שM[`dj%sq[Jtj2+6rjY7^i(BsWX{&kÔl#NtN\0BpZ5Ɖvhv5Sfgd.~Hto/|dKnd"fTF1(:{;ڻ7hcvI9Hp]ϼˆ vqζt,ԟ{wni]Ohͬcnɹ+iHM:W, ޹Qr-zh[Lʔ@垝]PQ{]bԦ!n.^ v17 @U&ͬrմch#,SVN]$]0kAAG`tA G*ݘgNcʃ^[G^ilvIG,SyWlOlQ RJq[Г9#B:_]caeľD?j.$S|{ܒ~-u+ tP<Nُ䔉*(2ItcCsua ?foϏՏ|(a"(+viʄN Uh5k |5㮋UiA2AEd{IU>vyfs.[cq4M?u+7Y;iSݭmwdH8 2ĸsC͜ j3 f`zڏ:*TUVocBM65u&0V a*gc) U(1J=fWtd<`ؚԲ֍g1/+)nޱp"sZs+d|)!RT5ImÅ؄|zsS  b]X4vA<#e=OaZ{v`wS^ONeN%=;;>nq@V-Bu9]˔`o&"S^5O 7x뭾-aݷ? b`@lvj.8U)|IbZF$ŭ Zqg g?$!N;4D>q37WF9_IϼS AƯ9Jb/Ԟ<|)m市-r 3Y< vAV0eH_9<ȴKFYoc+3w斚s"gWK'Z2 &u?emG*YcqF uJExٝOgaGY㼥MIw<.p7QcunnQboL6^ ?Rjc,ñA -T6G;ܮqC快S*10iP8{Ĵt9Xe XAIܽN<|{pi0$1B"uўzn'v KPV;GTIաuc n| p.M}!m-ȟxMeQ@]{2"xHx`K&v }Q+41?t ”|1?bѶ[NiU?8%:.) 쑒:6nZ؝ {uU J ?vW"G @#SAQɧ,QH /hA1lʜ$p➂QQ6?l,q%۹]@ y:^#LRIC/N򉋤8US24vĊbķ kN^%C8(kyy񘅊U`њ4$'Ǵ!.+(+ȢGW{ 5)̏ ōy[5>vhMp:92v #? &57Lqe5ݷt)~tAӳ`RoBٯ)rfh9ueI ~GHp N^➁{_.nnZס}º oP LnlڄipqWTdׯOv) /JpsQ5|<8g+ҺqӴ]vl 4$VN{};3EWwR}6E\G2 |JfN᛫& @C抹b=bW&醿q[ȩa<H=Σ(}޵XxphRJR XޙB4c7ti۫:%CLX@78Kqcu`>q=L6B31l̋|Shv_޷xj䛢č%o,9uaTl>Y-V"'$(sconprgpNzɃ TWw̹mj[!tLMZP/ E0wBmsCmJe ?J[3VET+Fi[JKdfLI&2@N3ֳ.x㼮=4G$q[D!֡X+ [0էɿ5I_|qRj.?%V@'I԰3-y``{i:/Ԭn6_LĻyç'!7 '`h%zRLN|^(tR U:oN2~_=yVHz mԴam|Bx|" 7ϥv,)4cYA4X_ M߳d rȩ ] FS7v?Գ Q0 )zm휏fX#7zMM{tEvg>5? V(Ho<5|7M3|ݟ~LIK6 t{ cqpytYL&~ C7"XtJ{F' Cn.'dvI%q~ސ5$:鍏}mNCOZ{e޶0%FsI?-V2r%kҧ5q@[}bͫ5]$'õ:ryefC4U9A*~#dzBN .C ?^1?r\jG5yPFy[)oڙ 6!rec&X,B*'젚'&6tMw)GKU } ~"M^Sˀ[П-ъ9܉;-κ'w:A9}G!:8 3ד5A'%!j)A"}C E\_m",S{܂QQ٦`LXHGF5PFÎYRˏܟU{Xl s@Vtc>98lP%$vo.zOF֝Wt]͓[!9#ן8nvm䨺tI~ɂu-Q~Twͅ7 &>^ҥt~|?1;ݞ f.:N_ Tu]^kHz"F-e:"P{{2'eK~m$CV@&"Z3NǔK\m@VVA)4֑uӭAH6b/TL#k EN+D0(%=Ɯ9a/.&Hms΃ږi`LC%>~N|"R ̀|Dr%fX dν4=qnR8pOJl @w|N2n !ؓ( Ehϓi{t24S?v͚ނzr<@Hw6}!h=2NeOD`,5YHO^wCY:ctiJYTs#^O~r/c)lI(oBw7W`?&%hk{v.@eN4A-D"ۇ,lcXźy$ܹa\HtY Icfi` Sb  ,c 7.Pu+.d)`ئ b,/gOײRW XL%Gyf c[lDP H91F:իU niFǗ ؈ W~P/:aOFĜ&y x ۢzj &ǘcƓCL]4/%c7 'Oͣiyz})}ݴ˥%_k/ ̳T|ۊ7oENGEn!7i+2"J#8H$RóAX︛ke5Z?15y@ԐɼvޙQ c=`E'^Z]4M7A;KA%TAzfm Z,?XLln=: I^:F(zM0 iE1O\/ 茗[{1 5uzÃ٤'jE-~/R"Tfd?9wc[{2d#S6w_,B+O઎**32ROrPΉTu= Ō\RK毗XhZ?h?^6Tpo}܏qeba ?=]$Vk{{y*(cti#Y7K[&ʦpϏaʻ!Fh' "gu_"WU8Ma%yG mٰVbԮ~+jZ8fEP 'O^A@oc^8K"&;ՂèkU UdwV)jKnfǴ,bœN/ |9ԗM[Ű'C!t9-<[ rjɏ! w$TX?Aκ.89$ Q ~|Hq|p#],Mo41Ol[>'[cr(b:qR-Ջ^њ[@t| -m=2(FMf)Jx6 JBi@2*)ə]>hhÞ5g#5Yl7*6 {E&D3y9- T Hrbᆋr.9~0q9@h\eǦ$;-~UjH> )cAgt_d̀]$#b <W [7>VwT˻լi^4I!du 膍ս5HDڏ tRyoXv Ry'GIN򕞡cPv-)G3&K]#JrK;,2*%"B&  xx PfMU>ܬx3BrJsñbJ N ;l칲\'VI2K"E)˵>O!|ځ%vз́ȩh 5 vzҋxt4ؽ)fԫIowE%ٮ2 و!kHM1Lڶ5k)o]B%'Wf#pBg kekS!gY_%ׅ֨7w_dY̜"gW #n+ &<W+DiiL,֪3TUI9B"IUޜVetQs4N`hH8"*^.FcEqZӺ%H&c[C O w+*I@6,w»:כk@1S\w5P)ؚ5ǕQqL :4/l=;}F#i>]tLOMY9F4;.4xLf2N٢>9(bYAz7 [wony^_73łBSy j`%\aX =_j]2:y3?St1gɁBRmA4#6O } _GЊh _XAdxa@#X 6AF6/Wrt/1۾swQ <( 1m0n$A{m;J\X-ɬ+څ:QL֑/ʧ8B}͑~v灓 ;!aQR:XHB4!A4[S>!xcrC5?޳B15eB{w[ycSff"-f8"g׬{_wM2d5hr 4A(Du AoH'E aUH{4LܳR aų(d[9Z^ 3̛s{2Mt24!Gdy6~wo,=l^5(p9Q I^\`Glr>Qϔ^8]NiwIǫCx r]+]nt$Ud>w!i>Yy3 D~-(c45&=HU-XXT(z DAo%R/VZsV.2' L`eIu&"2Vh3fn |=̣gOnS)-JqNiD˂3 Ŝ 3ӁFwZ T^CNЂwދ^nY9n& &c tIsL6!M$'V~~I,› ?(Q3h1n?7-J@P" ?rWቂO8q;f\ɺ89ۄ,2 Îƨ1h> BEX#@|?f~'*0XR-AYg$/9C#U`c+ Cϰ](n1 x/UEyz2CHBew1n }egiuvjI}}C~YB\duj\%[-o`[~w.`j`LFhmrtD>-QF[\1au$;3{W-95V+q]Bs.(@w06##iVa1rSUA`β;4a=Jyւ9)`EeTĦ,bt9g=OQY܈=&Blf'1A[=jA],l@ ”Wdj5!PxZ/齻To201N52.h=1{BFȾ )G;[\/M6nK8\㤓_ni[G&;} # _, !)AlSMy#INLNVXt![Rr*[O;JF~B\{!ь Xˤtsu%o}mhm@8BhQCo( M SIN7f+Ej oFiTB4 DQʷB︶!ͪ$PW 'GӲ U)8Φ :.0( \БN#MXnљ d36?eyH̆?%Xy0' nLwE1yjO4dž9mϵՀ8g*(Ge;u qۋKyY fWo+nz7Œ_9d[=xBi:y2.n9ރ)CR>wivCL?I dPxnFg1/T'V I"wéYlr8y`bkԍíao^!aM&W `lE.zv+& f;̀E[$e/sg«.C7"7d9] jso\Sq9?/cpgj Ʒ܇I+a>VX@ObF#q'r2W6tՒLlӝ"'vT)Q3~|PA܁j:p֞&u\hzQ'_BSX1'  LdMmQVӓnYU7SB:s}1%PM7*aS]L3 E"S^?Ka@%*(+1փdLKVAH1b]0[\1 ;& b,֩Efqh8okwWxF.PEPP'6PUaLu-P LSHt䭐m}nsnY7歏îs%!>>wpW{Ə#vu՞QnpZJ(|gy/͛zw>cd1Y)X 3Y02לL|2F&Z3]R"{Jt*y~'M~se.'Wj14 :׏{ sJc/^%Zfڬ (F%`nKZCwgIMAVyݍP941ujPyXOa: UrBg0LG~* `Uw?7僈PY Z|@N x"i][~OT]|Id|RDjef[Kܺ{$0YyR&uviҽ=92gR^N>*z{*Y =Gzκ Y&N%S-huTŋ+ MLj(? ogʢB*S1;!YS kpRvag}(~$xK_If&sH\j_;ZlhK $i9DD~g8CNդ4xaaT~D۩@yl!J̫H}Nb#!`|R&Z { w6,vׇțgb'vk @Qb(8CĽzlt&U}0ctCKrYs=`20F|x?<.0 9 j3,Uߎ:'5aA G6W=5g @Y{&uiUbygD$?UO x֭O =r uCkLw+bNH*\ th+X#,,o#xa͎+!D\J &Ѣ#UuQGL_64>t}t."J8G!;q<f7Jvד]#؆?PxbIxU&=Q$yK;OΩ"CV%#M]i#M7l1Ps-;;I*^<6[n وeL$#Lc}U48r/OwPt+Lupb68udó!UF/$P'~[aSD)r~$ DxYL,&OʶW:%^v][d1E,7Q/[>7jjhXeo)i+G;Ҵv^3/Dљi˩DUr?ArYUɁ$Uł_̖ld<ݿHd}_υu*㑿ef+nŬ->6'R#x=AJނ55g$FyeJVas0=9)pg/_iwC7mh~'nfqGp?IzMU#YsA1eF13W ?/o/]^Z >%-#m׶Z&؝WG Q0d-=fpcu rծJCla낗rs,@f@=FQgӭ:5>@XKw[2/&y\N>fCk2`tkU]w| * ="bn[z[Dm *>VCWXKls&;p bi?/׻Vy <6Pbt}L{82S ~i.,v_a+P,ڋ [0Ww[C&uN}׆ZtGXQ2PV/00\ ZiiE9R 4D.\P5|Lx˔’xwءb]r[z?eEƵ'棚"~<|]ک:8#u6PzL8KEU%#lq^vn+}i[PTN8 5gjsڳk3KVQ$EUÚ0w0H؟ YjHr׶pXyX;7<+\[D= T9DԛNEWq#4V-OMg/$k>|h'%'8론aPnm-!:vR7W,k3(RJz-N_ϳJ}Ci7p-.f{@~7e?3 ] ~ô+h@ǂ=_*mľQ1'4-'~C;\InCL,MabH1Є}/BҚz"u2S}_ϗ_>x4x|W^5M]+&V;҅g(ۤ%;kPmE[k#t8USmIx]CO;@֟ C] &P4.k ϕD^Gt-/HVZ"Qu<,-18k>YUZeWӆYXnh^nAcSu8քrof7v#2؂Rt$Hڧ'|_3!5XHm.\| 2 X/NRTdfshGhj9r-;?uL6 ~Ɂd[.8Gm_E83EUsYFKX.rGԋ1lNث@2rNg:w~'+QXz(N.uS 4>v~h +ٞZv^angK1-eBuJhVo0 7o7({" YN`7fdp@}XOzzj/85д()Z[i̶A3q݊V!=w9gLkRDj]kQ-ep>*X<,;XQ~ׇtY A206 %C4e|fG(ڈ1B b }5*宵&FzxUt(.{*Ng4E^K9D"*0upnc!Ϩꨚ8PHP-˷N5U-تb!o^%"8pD06fgUI|GHSrx}9 5Ubܽk0ޒ(pŊ@7!u+!R~QVַ sl{Q`[UwY"\pLI@P뤔p37a뉩K(+C nFC+}f#.r4k 9EOS.y\ɠۄH+4oh.)B/("+rX37;Ͷ9lᇶH̓Чf-y{ ژL>WI&8qm`rv3wV6fhVGQEƼ:y|hiX2YijX,܄y9z =_\;Ftl^J]Zv<[J֣njw1UKRhU^fH /֔2ڇmxsWs.ј)ٙaY1ފ7sݧh%> fG6!.NTȕ߱<{$핾t3*jkT$3]|1H?1y?xQ7X"H9s/k&$k;3AN.-@m i<.::i]lgCU_)pDd\F)tD(Џ'KH8EP@'mfWvn,̯n.☞:.01%B+_&;/6rLcەa9Wyi3NY պ8NG._.% ׾gI=sr"K`p.ׂd;XFk]ҒVxFKoLy4gqʿ\f/) mrl%Y}M5k*;k?bwBH)[ 6F iS>`BΉ܌w/n5{vr`8c+-)l>lbUYl̐ce xsЕ^H>~iOZh!UjҴ[8*${:!4>rǦõ&f#L1$A` #S~CbTEn_O6|q`:T?U;L"RN۞ra r_x=zs8W*Y?A#<6;g e=z)RZ:f6GmM4vcM3<.8[56y~_",$."i#3%4cJ40˸dl~v4ƳxcCBExEq ;ѕ>o+BHMㅾU3->ץ{/;ՖN}çЖ8$D8r?p0$įFgS7/d8W;>((֦fLz0T d,Bc,ͥA|Nr\ݖIoG ijzHՇ|\1ܻٕM9JkpKnr1<5CaG7:B((tIh.( <@D}~1BäM9ܯNgLEt|$ @XT,X8uG0 )cpV Cf_"nc[e\sD/d=4`&*:=y`;Qӿ6պ-?fmtOD#ai:ۤ sFh󮛹ovs±*?<:J֛8Tik,)㳱&V?2rQSӾwiWrȳ~ h 3,F+^0W[p+! 5am>:İMT@y.٧WJEN)``p? ߂ u''pTFj(hED3_< 0Xm3ȼT&~=ť&wrt-<'2 F79ewNk!&fQ"=)<[Rr 1֐Cz7ZD?8*,^sZ>Bk%C(Fէ繾"(ŃkĶXK8]f'Z~2ױ3RO+.E_ P1h٥-x130 / -Qgǻź/]q=T/o]F c!aLG ׹7P~{8 /HHkb7)/mQOr.#EŰ4yNV)ۃzqkA5:WwT.:ʡrM(wƒpW#k:K?$dd0[fۋqmfnFhb*QŴDuI?s%VkeD1&u1 ݸ504Qc- =deIcVH ;y 8 ^Ta8NQV40ZӌwWH1W,8X$9+i|ɷwoZ.dңLgG#ׁ]Q &A:<:ל[wLHŻ V W73fos`?LdUcMaiJ1!#yԮ<4kNDSMM[FdUĕ Ȏ)I^DiUjp}(J" ~H5Z{)e_⓴D筄j{~r?&;L_ЋEMx7B]ꪪ:zP,?Ċ|}{O%<͉g 'WWh#r 3tBx!118yߦ00 e阵VX A\$-rڞSSСubm>pk]P9|WCMt[~Y&m_Kui6s / ln!;?m`Gȸ'+-XsJ;WbvV~M)M(t<+#x}5h7ڎv\zFY2 ;ia*y[6b bE\B^@C@Ð$-ZQ{N&>50 ζwTo0:Lʑ2Lq~/rx (|/0@lXp<.DJ@Obn=@= B]~^Aͭ0Nq<_}Ӷ{]rG!Q/GϻqU B]By A0Kpg'xS&ɗ#8\7l+6"~ yNq@L*~2}:yQ7ʂnh-|WAFAW=;?_xcp5qZۥƁ:靵ok*Uei ~tCu _7#4⩨_0v}(c;p %.ڟf* Wj<(5\CW/16p\s xޜ:(k7X1 ;jIW߇ʝm!f-U`_N?v ;5d;O"^@&)(Tٔf(^cshzpIR =U`T~EZYd.j!)i QVcA:P:GYjf ) ¸ctYX%<mGg_{gH H!}ɸ`l ΰu^8pyϓe]MI!nkiN '#ҥnOA܉QR,<8ZthIAA/o׸{o.=6l)xhMGX)}Pӄ:OPAYe@ 4?0Ys Q6*세U%oqB$e@QxQBo+ur9JDa8ސV15+yeW\m^tkJҳZo|S(kwnu'Dݮ`|# Q,cr:/:&}EY~~_7JKI̢<ܲ2HуG 'ah. (xdQ sn9SQ'JXɔ3V"x0j^c/F",JJ۶i @N+yy ]׷TCt:Eф;W-El6B.ZAZTEKd/F㷣lP7k<*MB"MK䞘`G=="CIh$?XI1ǔjp2Q,x{IaT!b͐=͞7覥K'Un} \ɮufwu@YE>z%r@Q.W<(rA~Gʩsx9z|"gqj]H3Q;Q8UbG{ R?啹HN@`GL OO7S:z! NA /|Mϙb+7ν<*̅7$uGeӍa``Flї|e*'wk:\XgX*tL8Τ4 `&ٖs:]#&6E gZ"QᔔgӨA_ZUB ܘ)}"0pbdWSC[DŹj_hYkd 1Np %P v pQWt(u8cot 0nD zICE3#<'iF*-&^7XJ$5޲+n[zh hkjJ;`:X?>5 @x:'sAԗDh;e2){% 2S>b覺*8?P!f)@oMw1{>mI1"0t`x~ _4ºݕ ev}@]kR?+[ kNB|%4-$#zb{x`o=A[kjQu槷U1R꫟d kS{*^~~ϑ:_] jiYβ6]7^)zd+E(uIw)0Y%D;`FFd3)li{P29כEQ KqjZX49%6& BtBnw/E\cJ~)Rܔϸ@KWq|5B`YYXkl,0(y % $hnj!xŜ s7.s_U `Y w{`Q"Ʊ\e ,xd%Sb#z%v0d>~/^FIeI1d}  X?$TdЊ ' .5lr]Y)x85Y$AcDdgy>IfHsuQDC0xv>ќX+c[u]Z817DHi_+Vϛ #5M,! # 9on~c9)q[m0asG"S͸cdm*1 l򇨳vC ~K WŷCLYK4*5fz,duť^={Rq+1VWd#~F4yb̃=iNX6|@;zu5MXJ]k zviV~c{μը;J8%\˃I ۖY++)l]-Ѳgb4n3D_M_LL' E\cK})|}  &fȫKUTNr7 ľT')y7ˡJ%Y&)am>6;WeʸIG6{+J??EF4cv͌,w(JA\(D^9 G@E*)!e~f_&~OQ +,վaܹe2`#bormZ/GGϳlMCt<q]}Щa@wN:e]̈myuzqƵMHt!l!5)/;Wi@f!2+F|$C|tFBs2n%r~%&{+ãӬB- ȉVɐg jsڮz% B͓WaŰDgfYtQ_(EPL7J yrM ٌC[4QlO V"Q]"Y) CͩQR5rKɕ̢Y0/\_t^+s3>0ID?Qw"&}r '鎡@O烱p̿PhDq4S;x(\żPK~OU zFa8[zepҙ&}{k?^Gsk kS`6 0j[;gUtmw||Nl]&y8 ވ$9̉%>{P]`ru4DX̣"HKo3jAY%AEƲ{u3ǸT<\ۗLT`;Zlr|G2ٳ[è6!g)F8KK{Y]k0.ʪ{7i` Xy< M))4q/O3d˺,0Czom'fYO04oBQLqhJ1}{$PVa e+N,~AR3妮UASYBtpG@IAH{FP(/ۼ$cu(7O[L: 6d6HSE,kk!f^-W!̶A:4 {3!7Y^j,B1,}=DA6zHxu{3e'O,@X \I@ZӑT-Dl`/cO֚ڀv{E%;`U}^L=ΐ֘:\p" G$85:AHB]Z7fϒuk?WCw<a|MRcrn+.baaQn ߤjap{tWQ@B ȹަ:Z&-*uLf]nc|M,!Q (N¿!N mW^6D2n6aݩ`LtTfN_>z,{2$ E}d:̛ri% DZ j?Hc}l{?mZSiSQ|E[$UYjKXY5 A (w?m#/[b,d!T1i y18jv0s !k -6ʩdY=@TKߠ(H߼Q': MR!Zt$`k{K;_ <䟓"!wѯ' tl` .D3ʒu WU#(!P їng4g/BVàG'f^ o,waY!#D~6QG͆)iGkzlI`6"\6D:4tB:1NW`0Êg *P AD2U ׀+߯;.HU+!/:o:3_Ir~Á-@ԍ[FQ"eDjס rd䦞LLN$oARB5Ty@L]F푰&ѭRhLFCH9HWjX.1< ^O++nك ۑC5H >*K7RTJDȡp)Lm:\58}Pz\ g=Gś2vHI4;Kfc tm#N5*H)@Ǿi ؼjq2.]/pz["kr<6RL\xO*uh("uj.HUHy3fIr a}CV<&;0@*9Bsv߄'JE" D :Bnz8=[^`cQX?\9 4 0L+#sLbҭ0M83JIOeCEE0(By.XҦ|f8Lx aK~p9e˷r3L)taxa2RV#+C ~QfN&b4#ja3@ q%V]=oWPqzb eAZ<ܹ,W~^a2>fw9 1.Yc)_ WvA|:_8Y<&2NcdG',ܯL *xxg-l*Ao^ʏ<>ITdE`*#]ZdA1Bih|sN/ ؃h+A25q1˟e_DnPI6b3G/ 2&Mts4âNŁ+ p9w !4: ?*7#2a=ӅUV~m6 ƬNWXAҳH z>-^fu1jxl$%Y>L$C̡H.}owcsn(UQt9hz}K~TGG*kЭ.v:IfRA1oUoEaÚq1 a0O:Z9>R<WU4<t͠hl¶<^&%YVq#Dq椵 `k|D+A,THз 'U(WscKŃ S8È8=NTrxs@Le$9hجSpxywM۸9")Aiܢ?%ڑ6gncD^85s'<_VMz|Ic"(ιڴ5C /lkJϰ\awNqSikI:l[ t-C*=Om^wHh8Iv gE yuxiOz.O>Yf7_$uх]{na6gs 1"O$%] 3[U7ǍSCE`޲H.ȴ3) 5@ѢcV`*$z춇Rn&^A /z.\]JAs&!IC I%onEz>I]alNM;z @r ZDTV7pT|ܖxfkd,oe}Y&o>[fY4P?`h]{,a4 T ѠJn*& Lڭ=jtG'}O CʳXsZTL% 41ͫx1@hKп!J<' !:-PΗ &0xfEA]3gO={o=9 n)m2=hv_9ブx1J`7%[ ExO@?R~Lz62$D!qZ5:7cs'7$oGVV_aSQ.h8:fH`JA+,? WѨh'8Xds# 9*$sĺq|g`MH!+[5-[P ?>rb8ʹc[OˊȀ\͘sFTo0H?uwqNTRdۍҶ*w0ƚw ]ɯL%f>avPj]A'An@6 X ǹİC#l c @֐`˜{J?TlBX4wJ*Ԡԭ̕Ű0Zhrѧ5# ր(;b' 8![Oh=ZJҙXrY.i^_ȅw٫"[ xAq} U5֮B4;!Q&uq7YvQvw Lr=\U4.S 1 kPإu5J}Iu"\>P.t(E>5TƘ^EexcoYn q<̈ċ_t#aJ>?=vJP[e.n V3愯ՍeW3U{W?36OtV&nrmJ=H{_#P)QOYc):=2x2X{EU^'9(*w'8yH9Ԉ.xZ%$'L*e[)Ւ?+3heY'$waO@j^, hL =kic /̪L({tg"ln džQ޵ؐÝz 9 cE!t@xP/Na3LA~Fq.@` weI6l8HMl `QtLСHkX~ܕMLSqGjMF`H50aֿIӐ|r 7n#'z(|Kȓz"!c]OkO@aQ$7M*G~.>_wa6iO%~gA45aG/W{%3C7 G@6Ez2ҧHGOY;܆#A+lq!k9GdWd_Lx!8j2!d뎮퀘Xɻ 0a bwn*5)* BD`ߞ^d%M: PdiJ U0tD;Ok-?"H.ћVMȌxzF~F`Zd+t E%eͰ! u^0̯${WT3c4 kk!FS8藳TXXUj!ݴE| KO%5%hf]ZT_TGÚe 䡏~5[auvVdbRv5<1}E~˸pA؛*]'AϺXm|;@>ܕ6B#pq:k^jl9"V\`Mzd1 Fq8GmGmsZ]1hDCxȩpQBڕYpj$_9EFh?RQD88?]wjQg2r3-*r)`Ռ#HER~)0Vy{ICtP2㇛jh 4SS[ ]Q+ D#v"g@bA`GㅂDv5 ԶvMXrĥeyάk |wtwBZ0 TZU "?é9? |tNhErK1h~{E:WrB6!llYSs`+ȃSǙ.cst*z L6դ-`{IUc'10U& Xy(Qޣ9Ȼ*!,o1]oPi*+ =.WW #7HmtKͲ>01 ҃^6ޕj}%MГU?t?&3g\Je!{ TĮWu"͡,7-z*1i?e: f|d2? UĆ9ަl<~]pȚO׮J9G0-4ܑ-4'GE{載ⶪ/.=eŸD5<󏷮oH-?fֻ Nٲ/أ1|`]c1񐙸~sW$S wjuD-:[AJ_`JPIB~[_ 1rRȷC 4\YTwhM}̷+ 켹q!DLt.fT3"w[S B c]ڵf_Qs5׃-_2^~^/Y@W@3WR bw+w$h:][z [ J쳭 g 2x)&֊9}C,NGuS _Vv1Z͠c4.= l~O`T9i,սWw@;Pud]"$Ր_v[h5`-,d{C]evjSQ\b(p11eq8eqkqGs` bsAF)In3( u:G\GahfiNonqX" Wc5D`Vyۏ. =#c&M ovaYva\ţ_בEi>/]iQf ŐGUp[7)MC4{\׀) *GMqX)Cҵz`x;[Awǖ6ŢVB'^;2L=. /;hnhVsӥ#R^u3˧L˱Tw[ J$B?盟ՉS`C-â;.% ͏U.OFrq)t/LP-!!`'Dr;%?٧0SJe`JQT=W.}s3CNvsSQ<zvHUGh8Iߏ@qO8jr&cj>=j,kF'P$*HH!hLfҀe2lD\bAv$E%)a Ǣ4 9ty$ܠxq*sXca 32N~$nxVSlH1UZ/\E^i,'Cd0J? mmƒ7yl"w5cr:2PyإozsQe4g]_U.UtEL\GW" Pg ~17efՌHZS_j?h67Ci&˿ܡ@Xm*#)8dWs3ԁ%M#^t GRq^iǂM 3>7$,&JŒtoMv4V["$:l( aMZT?\@6H6nw9KRp '8d3 ;Vl2]  ]y}qFĔЛ:*KbZd\$U^,]aDikhi}iJ, 3YGwݞSC~JA֚h_=ե RVμjb\fS#9;=7s_3o >Đrڸ3nBu7&͖=ٽ4fjUwABa5;0)6elJ\O#H Z&L:$ܖRT\6/(X[W~\x%}llEΊ~-PBǂɹ{*\iW\=3091b};#?=p:FXYjrhƵpYHbM ,fm7pcwg\B_.Bڏp.\ pVkKm2+M̭0\ZH  P0nv9.h0H MlD.ekH BD;!c1[qoR; ~!:'*7:6_:dt6R^ظ'Ks\V '`DrhvU> ü@j/w$cebʺ`'%S^3P h.bkCasP 9ؕsZϼo@7 L&1;&6bV.rz &Lnzu*o-]U2Bv.]&Y(3΁Ȯ._Qɼ00:l{7]nT=@zk/)nfMӜx+m[TQ5 >{ncoN%ŒySRg,"]g3蕽gTH vj m+a?JGθ TnԁO:n@!VD")MAXD3½+.(Bo! 7k$5vlϘ!.rSWv8. ;C|,q̓x\UҝmuluŽY1Xd")]]YKLB$Y^۷B < zB-"&#|3<}vCrOa鈚kq+mζٶFqܵJ͂+똹.Րax?ΞP*Dצ p9 F! #n "d_w`a1:( >ܦWI%i%&ɽe¹aAߎybTm_?;}RhZ (󠽰{r̰qXK{Ln;z[wc@P <1MΡɪ ڣ\\¡AT8JPu c*ϫ\.iWga09D48 )Z 'L 1 +9Tݰl[!rGNyUT.C:[6?2}TNjC|iU$Bn Q1ט}%E딁=oj[ZkFRty툝{ZWg->ބw|g:vxם@VÙ4p DFb؍&g}r9J<RXf33d#]pNWkjrcJzq%Iˆ~j8dߪjASDX&dG5(x UkKno XĆ )2;H17s-fXAM)Feis[}YI} 8N x1;XŎnˆ&#O@dy\mx_" ?.(TBkBgX 2J¶^ qU͍jƽk!¾CZ⣝z?3-mltV!`SXI;"10:"J0(fKOY+ rw@@lŃՍ`YkiXP1,Q*x9B7NV6ץd-TkwCd}YShJĚT}­Q&{IfwFNƂ4PdDa \?-&Խܥ Gmӥ盐uL r{#U(k'G{6vtT{ oc *^b:_4$iB*q%FKy J>;jGVcyozh+4|H~L3>a<y3.nxЂ@-XT…s îVĦ W!g%Y # Plķd{\zfZlmCW=K$YZyV$*~/`<}} Ugl_QʂD!sz%$qf *DF CkҠ=ı8A?<LYEtىD Q5so])y]B؁9[VI`]X//[$PYfCo&g 9pgBP-ЏBSi\()a>ˏ$dJ;仞i!ͣ G.&?Cf6;ߴͫnx&X0DpО'3 )s^+^"0c'+t=7(`{]58z@&%O+|d=JeV;e ̚4EleqɍWAtV!לt&CWƒo#P7C$lPiGUL\CmXpyJ[MSnHg>$@g-ؾ7`s\|= +˒@) 0;X"ة 3P6c1C =>Qq dY݆]fMDN CTCBy/_2 itIjg3]ѵ>EB&O8d{oJȌ^I~Sj1:U֍71\/Yכvg/ 7 ];|kfǮJh/*gDKukm)' #Wo@DQ␶ Ӆ+&/B~.*H G=5NՏd`Ouw{Ρ( w*<_V*D0ط ykWmvk,!{Og]S 9ywJYf^ D$)5\/v QƋLMvDl1(yCN6wVhAKuy1a~ L9'W&/lɿG^&uy!o2c!$c-j*4 S+㝦^pŤ(&@4|:>N`Aw \ Tv?S~CЧKxfki[EuJz{E0'Di>\:Q[hVxw%ʰ才&kT2aMSzdb+7T0 ?2vi S -JVr, V>N@R)SlJ*mRcu7h9h%.!CnR^ ̦#~˜A<`L9ʘ#98O2󼪀CkM!+8 x\' $+eDyeUJ иmKV/MUd\жUlal<7ޘA/ຫ)5kZRrP)` ~‘qnk757ŝB'RNtt[Djc2vYw#`Я5'n.{A+Y N6jA0\/-K;`¬qwAܱ P:S}ϼ+T7V`< R낆zmƅb*A8.K4\$4*G 9d_XP4yeKe(ʗB<V !~t|{^f ZAIr !wcЗy+iZbTwC;_Я\T~ny=?Fkz"lr}hDoyέai,g( e4N0dz`q(=9CFPaZ5:Ӱ{ 呛!=__t`zn{,=ݻ-\ߣZ!**ڐOjWn_{8vxh6ͤ3FpRQ֫ E-M jvh-e0<:2Xp:P9d2+0z\JuC;S*~V@Q_:`p2+f[GlI?~Nb1e"׆[r;(,*CwIay#WJH,ӭ7p̰V):}cn^_ȍ;bЄwh_{6lC)<"s S9W)bŇj%P$Z|ӷM3O\I/O1Ta)_9#"QL ki(-.d&%,GSҝƴu ^Ϛ?fg*DIGA_l!*-~zQgvhuʤ{J6*-m5>5wK1+Y?5$~ɘ߬|6ٵ\q4> {4T:ȫOs¶ AVFreKht7z~yhZZ4NDl)4wRf;py=laH'R'fni\(ޗ\>آkTrݺ gga~qVJE E, _E΃X$nm7 7L>t?*7– ßli+X j'"Q6EgǑ a"y__F{q k s(p,~d;#N-g6_<㥦o hkM^h&$_ Aꖾo&21 . -uy~L6SlN`_d@ЕY+&^(`) 'ޒ=zw[A >慆 6Lǭ{*p\3Aԏ c* Q,d^&w2x ր8\[CK-0& zh39{yi ޮ,&L$/O\,!X>lPJEXx z,\x;KsvKҟAj~:|~F?w~6\ؾ']|?7'F%1z"%09Ѓ=;~\A\IϨ"cxaP#)) ]wK'm墨ԕA_p+%'Pxph.p e>ԎMAϐ~Hafb>ݭO4CڻUХȮcbQ4+ kcmZe̕"sL>?3Ens&ۉ!Sv l(yv6U^D?C#׈H>ktN@._*-_>PX=1K]:W‚_YQia֏r)Ar[YD&T6uDvFҹvHiyvBY}lRA/n#*J?MB[Cs$H;ŧ>PS s*42a{3m:/ja$96A G@+̬mOF…?;% b1S"'NJYmyD-Zt%+.+=P:&Cs2&iŢ8b-TfpJ\F]*Gj˘2=چwn'pJv~hӨ $7qf-XRM9-xͼ X]LfmaTțm_" @mȼǝj/^4WF6/@PJ;rBS{7|s7hXϩKzKtV!K{(/Τt==J _"ʕC '*X!.K XI.El@ f !HdZ>J_0@d1买}ȋvNqV1WTw;3H9 J PkWR&9Ճ!v OX,+dX{RGU^T'U0;%*l,6S˺8pd-6#Lj[8x̩ >2E;HK8Zgeϥ )ޔ#y>lC+'.?"G&pȥ$LM5b* 0*`MQc߂.S)R#r'܍VA;&"wKS\9< TYqYLp*aCq7#C*-jLyy%8׽4ĄXbY4fű]pG DoX?voE#gJ}#I+Hz|m,x3B;\FtʠN8!.D.kuϞvf/8R*:/Wrqɰ.<.j&w ș~Ăf"\MoM|hUv3hrs[U̖qiUd}#&\_ JIkn}|^lt޸GZ{M@6}Ť#b!JJϣn7`EƧH~Iw~KvnHQmWq3ṕRA7Γӆy/uLO`c=m;8dBC([ә13Sv+ Xjĥ`NM Gė֏1v\C:}rZ6dd8ݔNYoKA{kIvHiBnNw:14U׻D^7Y#ŖZ̲}[H4b#9h.Rnՙ K$n-RI<>`m8@y¿!ȉ_p.^a]76G;FWnl;`ߢbh8 'c"&vVŸEmށI$jP.CRyjE(GoPåSX"dCq aQJEp!1s+*sao!i<;}OL҅pف+8 ]1_g7|y?=cU {jhw29 tP 3D\!J #u7]㔡h7p6oFK[+ M'kgDr6'blإ]ukcÂѕؠ4- u2 -\ [Xv'zam9.~ʛ:b{7Zg Ί=3"vQ]!ZLRx/}ğπsMLt#*/_~!NNWm!׿I}⁷$"c $$Dž`(eR435oDKe͐?]a/OO i;X{Eծ8D}&SWZZqG_(hBQ]tǜr RCֲ6/Z%SdLZBs`S?%ÞD7%v6xr6^Dܰd8Wgt !w\ P#eD EyZh;6uyr#RA}ʶnN,$>ݜUB}5B1͇*jdoiV9ҡK&n%l 36k0]#PiM^:R,Ob;+lS#NIueNb623A i,~CX!{07Sp?&uy.#.k34dN3¥)!fIo,v=!|wQ`ѥ IqYlHz&V=~F\q쀤_ݎzIKf%§v"9x] - =*fF90".KOL'3]>9w _U&=9*,Ev<%S NE PVye\BaǴ^̡af`0>+!-VWM=H c)D! G92F.c~6 ߴKHY}2uEbq8%n0\ B}Hnζ*s.@8}>ãa}Fu` Cc<&fYV{%:^;)D;u1:jX7X:3wvͧw\DpU5&0:B$Mq2Ӡӏl{Cr =Rh(wGnH<=@^|O4OU?ď?0N=z~FxgLPBfE#>F!PpfTz"_ u3ggo5sP=GS˞ï&ػxuAKBshByEf I}m&~@]l*-9$xz-SuOY{ T0ɕ+raAЅ)"ϥS%5HǽNTW:)n|Cepޱv[58ȮQTJ˟.]Fvz!ΘLXINh*iۦѩI#4S%Xe-h2W*ZN =YݥL[9 DM7b7`0jj{fQMRMvUV C]u;4w*m}O^7=P &`1;dF 1$)ʵ٩>VJ,`r?ZɄf+pàḁkF֢S9 ~|_z8;SZl|pn]uilNEM>QMY|( \ 9NQ_gtYpRr;]NA1Eq ?%t!=758$#vUawKKj`Jn$Q!0<_R!VvYU0ERŹд|úͰ,¡tGp _Nqp,DHqh]XݰXtS((d#M?z,#/j#c q@ڋ?D*2Bf:}d3V2&:8oD-(>_TTȖɸm~#k?a5x lqTc.TET" I&~u7}?$*0Kfo# 5hץJM.h8%?\tQkY; SVݍ>jԨOz55܈e4H¨0\+ہw8i5D^} ∣-$ߎ1N枷m}y!/uFP %7}IE-MTLE d?dToyJ^+6mDѐ6Ky B:͠N%QitcnsBс0=>L;d$8R;*1F|Etˏ.{puY'3*P~,adhчQpjD'UyPI{rM_+a n, `X6]gaN &Y;1L`5EEب/MR%y`Y1la/k Dăo*=c1÷a EgE )l +ex`/$OT[?eG.Fg& }.t6Eo)5ea)w$oMXLkA[Awwܓ`)Datݲ~FTۦ-p~){]QQ "Zf0Js$챔=лfgZ2p .'ߙ^z [ " BLÌcIF~z&LPg=z<=. _5&i ރ$,:^{˫dc4-{J #h6ZS%`;+)g\b_9H%f֪b[0=oe[igx  ]zP Pl ̶M:o ݎ;l |Q&&a-`,8޿jXFfzucSXx Kkb:#{wjte̲0=T/}8D7 &٧jK;aGB݋١ dύ}T+r ka)0s]f&†!}-2N+q!^tl}(>O^""ɍZ$qӱp3c^ v@u(Hdap hRF* *$yH05 :< oehri؞:2bϑ7g\Oٓt24OZs@Gq~sdLyI0#CK5!^L5(r\dVkeE2l;H0ة٢qAL;#Smǐ;Fc;..ZysxZw `^9v ޴%…Ag5:̛ӌ'UyC= Ud.GݪQʐVzH\IL |9_01V>a fQCv$.N 8°ڮU f&2`@u՟9 @IW%,"d w_+>/va 6r6ŚwA KTAsdoKtz5:-XZ80Ie5O;0 ȥ w$lxbJMk\%g[{$oq ?rcRrHaJx,jQhq=8|'9G}VFAY/fUJm=mr%?%bmbHp[WeB \-ݑܤ7_;[ɚ̤M MIiWxr'צqQSLJ  oՉ)0FxN"C m6 5 4c.>^tDp脆at}Y[;pNrm` 3rA-ݭ"@.'HxX̗p:wGE@ra wUqypJf0,H}¤lS~7W:!4S(T M@ e <g3eo_&KFU5~y YbC6Ż&s#b>v9~d .;&ޢJJQCMc1$}4<ڟj'u'Zu&0cǀ/WE|trFTFXJ CHg {'1F q$.q3y38v^|/ۋ 0"4X@yXm^FI4_d B9,W_yNTNcZo"&Yv=IԼdSȪpvgP`ǫJu@gF5* _iB+΂P9p0OvG)Bn!#ނf%n\@ [~>ۇzNdSy9_Qⱻqe>I9fUfN|?-6V_zxؒF']1>N{7UXZ)` Ze2iF>%#yy)ꌵ/^vSkCvͲ. ?͂]zcV"Vg"u:{{"Q\p7Q w-* C㭂S(nG(~yXlo3@C({+W"mSc[x{*J,-ED7U__=఻BX`zI xX?eU%>XH)eV(-m;Z3s"䚄GLMl5?CCi6B]%ŦuʸG WWPVO 洤cs f"RwbPT"}MB/ZHKhͬx=wfԴ"RP66#~՝wE0$/0de{Ƕ?oLmkT*B7v<3R*f YwRGY'b{B5)ls=[u21qOO|ϣz%Ҷ 3~K*[PNW =#ݬյ ѷF o1A1jt %DVFJO7t`NĻMXUmP Y4I3=,Bt]~|%W,Z3\x2P+W1~|owǐ'|Oq5ᇛ+O5 A¦JB1wY]EGVEAXuS3[Q;`i20^}̫Ӽ;R"蹥sﰛ̓'XHW* WE'!wQᇳHQ9EX"Z,ĞOہ8#isBJ Oh&{QHGy{bvu]BӰs4 b)=9;tp>b M E0~;tRg? q2^y%)Ui:Za#*uMcl 䕝m5jOu)ͩ4 #hܲUiYt}!S~PK,F(9m2ziXه A>JSk=3o8W+ -zUVxko.2&c!"1Q>gi1M; slbE~1nafHZZ>U+\Ed`CWV%XBWGmyGe5 ,Я%h&\ jl댮jH&"gp;-=Jd2m_C2rj4('O}Dd 7H"Obp8Э~mbM~ iB2cO p`y㖩 BuNTN=> lQNT_e'8R=玂D55<!=qr5^r) Tx|\uY:raM0 M[7\ Կ('XȄ_;&\vW&X\N[m;s ˠ~sy4p]g\Y#9} ,r, >s~-fx{`M#Měv$sMW-Ȕe$ɝ_{5x;} $Ee.ƂBfBR-^D,,qx\~lz rh'VX,gѵ,s?D P9Ѐg<:PWq6;l `$]ReMs)NC)ȑ ׆1f:=|n@V_͡ 7 V/]r0FvR.#ACA.rW71U6Yv! -KN!?fq!FTr?R "#}T(ہy98m| \xPɬ֮747JCs;VP%$g:x{6Xs;&-G(qH谾s2wx` H#&f"0qHmF9 ´lV8N+mc^x+,c;-0ր]~TZZry#G -h>fM9)]M6S LnnMOT?Km0:% n',JBZݭL2vҲك8nkۆ:7&0s)wC w 3+@~b^dY$C.>2_@N`(vFݎFKJl Uȑ]DdR?׃y'K0}n˞8ua*Hi~Z*l 2QgNxãht<q2a%g\Q FB3?d16VYi9s9bSq+T^}v.ϳ;[~?}m>D)* HiX k?zBoc Nivc&WMKzCe;~s{}}B/Pc\~"k덃wN41f~];B^o73J96SL)QXϹ7jdT7Tі@еJoټYiϗl??K4ÒFn@x#zz">ygO8QL߼/ 'ZSvBfO\flu;|iu;D?aRPK\-mS}GjJz&|ĵfgO l_>+ y81ƌ QF[e\ ,WhxǣGoybP[`0jȦ=kÌ˩pDP0L6"I{D”^}"ɾYHJ@(%ż%W6~Ͳdlϐe6a@C(߮y{ _bG).ck4YU/ KAPԽg(꽥8}dulvxߑZs(;V {CTA<h  HEk3ↇۦ?ҫ\C?[ߪC]Gtw|h^}$F PLS&(I`\|{s_&A ocWP[LLmΎȗ!ndh!A?̱dWxUmtfmiMH(9՚m.1tlB+/cCPgh)4ȝq?J̺8NI%R)u+s &(UoyЛB[] _ ꫃8f)QITN~w|s/>CzI@Ȗ)[\A 1#O_Ir)V4FW_d^X3)9-]Aȱ< d]a_FYjԓZ闤/gm?Xƙ-Vr:3!RXu; tO~ZE#\r{ɽ̋$,C~Ӧ`3ۺ)?v|s$!r&P25&J4":S4"-]DQb<,ڞA,$>{d 28f0V'ĩ|w3R $a&GBN Gh[N""mUE"^2s1d2x,dIKal7lmbBDұg<M^_Hv_=Ziz##9T.y"mDvދ0]ڒqmn}ob. 7xĻ{O)12)(0,,ql% ^+S`fz oT @c(9X+^~cļfE;ՅFHeݦn "i6/$B9)qH0/~@9|e8F'~}gU෎+ KZUC\DXW~ $U<Uj%X8bCt쬺(;PUtB vDԃkDl?Fv,6 Q)cl6IFIR(CV  Ɣ;Ы}XV)F0%wx ."ܵ/~ӀGwƥ/vR6;UR0L8KLI2ۺRGM[!3fz+{3r  ~pɌ17w*b΍p>Ɍ?4`gK+_pb?2Q>ҕA.oЎS:C^6F Mbc!8ZpXZ?)[mAGάzh r1@jlF.+hq\wί?&fI[S;~M' L"{Q[ɿpUWC܃L*ΦXm )~KDR_lS04nxPt+tbY*Cl?ڃ)A$bk'o]u~Nr,Αxn:#^UtK=~R}Ѐ +4{Kf<)/awAjTx w{ap%t|7i_f9A7:~B$?U3d(}XdyE ]ѢEMH_e{s@S+j;{Hf=uyu{_iݤ=>Gv.+i]>x"4փ_ao;nxj4C~ͦF^ IqFfL8TaՍ+^#/)%WzۅGO-d䝳 KUIPS!ˈϿZ%jltb_\— E5%~szf;(L#+>iH&CWeK&lŇ#hwgYh8P2]bg>k] T ")JT)cE;1nЫ[(o_=lOϋ5WձSV #rU?fgs y+ &ьW:!ᨎ(̷CA9ъ2Ew~|pU #<${|̬+0T eA 0Ƀ>n8NB~p)M>h{ 4jQ]-(Ay{&Dw'Պw;^`R^w軔J E9և&Y::cRFo t $6ץ"l%eIMKSg`i (O8w"}8=] ֓i:68[!9T[ՠ7Ebůh)teJ=kăտqcU$؏c~i:F+4CVq=Z}`'-JN<\TF8)gYc]d5{IU\cg\++8u]U9 6((d; 7*#L奛qjU'`=H YJO$D$dž[yޗ _?^QRMĔjY΍#.͛ȋwQߖ#WX~gohPwzcYɪ|++E Z=فt)h8cHYp;zn{zi0K. HfF'2(\Z2OM{=M)=>|J- V '˭}mȹ C-9 3)Ub `:Fc%rD'e:,JP>k(Gu<w=G cu4#_JL/a&[^| !B*俏.UrbwMtޅa e#֍zWs~2[\^aq=꒿'sgxS> [tAMT5Y{(r۵ 7-nw R^1t-Yh)3ӆ'.C3k x `%R4jŎ`IM{UK;i[͡Gpy*szZ7(l**8ɥ7f3.h`+*{ǟH_-atF~/cNR/q?Ux߁xz5"| t Bͪ'+6c[h~ 7DomYLpyh$ӭ9\1o4icqj"5% s~MOl ,/}9͖d^uٻQ- 0eP3-+&PHAVLpۆدJ6uk57g0 SX,𱐯ն{ I֛1hC 9@^6brҭLMlolrֿCb2Asa=%U0As_FY }D&ϓ[8ftY'sdGM!oNJiTVPЗ]qݚF>_A ǡ@8 =>-7{3Z.[P4LJB%@4\S!ZZ ERSmO^D)PFzNNK( Q)n7pJJ$$,KEwlfp肘7q| & 6QȎK uOʞ^r'tv{m.qR'LOc>)!v ˖ć8,RColTC:Ia6o)Ԃ me(F9&(^0nV\^dzt_,:f(^տ=L6+MUwx iMV~cQ FUXbC}*ч,ru6UɎ { 1kRH\e ȭEn/ϥ-K(T"wDud< *ANy ұ4dPf{gdH uiR;R9! ME?ΥB3se;?x{;Y #H@ OUq4Q 5wy/rREga5ZH +e0R a(U_~O ~ٓ^$?,1ȁ!)|z&FWMeSs!<'OǓywWN}O"ݻPVsǧRBqݵwb1$j#-S_<3ڊ^k~cLtW~iJ^H_ȘLy .9|Shq\ G*v'IL1]74L]X6GOf2slQr|UB@=ԆTc,P=OyQyQb u`P Nͭܳ,HM΍V,q-ǫb:]i<l ²+[:&65jyյIRQ] @,lUigQrbyfMA2) cz3TJh .5=MRVQoJ˴EpW | r PGMX̶#$mM',u<Ϛ|n$sTÿΜg!3-^'!\u&cMx .@E`8FU܋NiǮb#K#LRS%iXpV\e:^}} v\2ƌ=r#ּiQ O {BvRNsd*\ڃ^%gAܯ=\T]Uzv@;83z^gmͺJ2S2!IF8IpQa":m mė|!(hM^]y+k;\ L IwgԎ> K ,^k%)!niUSI'Qr`/T?@.GR%8mhmk@oV=D"R/ yT0m}^OWiihqK :lmc.# V[QA@^y gǟk!]5/@@iSA3 n\KV\%lgPdn=PGwxQ!tq0Pl*kO{B] ]hCwvr(4gJ3n-~m1OG<ݱ'i Jz|" \jEʃYMq#.V?/I~zSnB+0:M{z15V.r%ͱJF~⧷L]ζ0((Q| [59Ɖw„M-CڤALDF l}>ؤ-U!J h|UB1i -vttM%ڃbw=_0'0C_舐a0ynV7^jWY6FuЧF5ɦκeVO`,WQs&puY'[Calb* !<a6$3DC _V/W6uX­zo5eN*tE8%x56> #N ]Z;>x>>VzhMT#p2{iyQ~qhXr:y}amVHK`}- ᥚMfqv@^}dq'뭗 BHI9Q{R?>(`(,͋pV^-b)lu'j.S%|Z |M@90Ey `|:i(,tRc9o@;ڤ,@-*}}ȆY3;&|('U"D%(v}mʈ²@czak]ǔ>Y2pDZ"z`v0sX)/S/ʉInrҳw!F\E:%P-tCa [Dz$W Nv/>Q j%i/ aE#PTaPOD^-= FQa4?Lw*YOp뇭9p:k <(u̚I]Ikaafء@kQ7};6fۜrf2ֳu) $SD1]l|"k%<:BBUs,;H, U^ߵ&9\Q◳} _+gM˹/aJx+Yکm& ޢ. ?Q{e>,^ℼGY:u31CIw+s"w&ZH I&ghŒzJD`zVq(YpWjƛY'RU,NT ٬+JϚ1AZ;.B`>/M,S6:}Ng4 0};(Ib^bλTwN+2벌p$ЎwGklé!X/{*2Z3gB5{h[߾@s+omzb!n4)M̗ 7—@j7p{Ler],LUNҿ a7<7o?v8?8n W9` ع>Õ'Z'8MYdj#BKXWa"?á.TN=* WT}GSazM[S﴾#_ ܸЅV`cAWfbwD0 G:WL^V*{,Wh 'hG)jfTL'@o {?1?^nwYtq'9bo~K-(y|z0FK`v`gFWjL$g+1TYeǟp$˖H*4&5E߼k5vI 1tX}c^x;-qܓǡb.zH=R啰 *I|ap4@jF)h[q39ow֡?QKUn{bn96 :4x?uXcbuF#-3xdEeBo }3RNS]Z ]ˎM:7ޑ-]Q4ۛ~ 0ٓ|-"P*AߙiV ;%6`UUQNr 2BaQ: ]@ln`? P(p~L|z"+1~[^0G H8sl x%D\< b~ A$Li0,ޭ_kԹ"QBc'Ɣ%sf ,bUQTȭ0cjA(jJ|#x.3ׯ Y"8ONxz,'zaR,VhL *M#5`ޜ ivJAB:CDts}ۆm_L&jAׁڌ:ޑ3 2mInJ~.GÇW\!xw0zZ% [y)E'ڵ<0TxPyW84#>,% =ᢢ;[ŕ.rY^/ Ns]ŽbMc