sssd-ipa-1.14.0-43.el7_3.18$> TZ57g'\>=?d   ; "@FM    4 { $XLL 3L   ( 89:g =9GDH`I|XY\]^0bdefltuvw$x@y\RCsssd-ipa1.14.043.el7_3.18The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.YTEpc1bm.rdu2.centos.org 'CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKOjA큤AYTE_YTE_YTEoW~YTEMYTELYTEOb81dff727b2c5f2e041d79953f1631a428ba87ab85847b3bdc991af78e8f669694d30cbaba62288876ee7e92f0ba8b5e69aaebca8c190f9060a3670d91a193ba8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90371ce67dead6a25db630c6b71465c06b2ed9bdfad044db73aaabefec0bdd0cd740a17ad4e3be94abb12e67598d0e01f60f4419f9887368b81d29b7d0fb4f3b8d1rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.18.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.183.0.4-14.6.0-14.0-11.14.0-43.el7_3.181.14.0-43.el7_3.181.14.0-43.el7_3.185.2-1sssd1.10.0-8.beta24.11.3Y(YYtYXBXpXv@XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.18Jakub Hrozek - 1.14.0-43.17Jakub Hrozek - 1.14.0-43.16Jakub Hrozek - 1.14.0-43.15Jakub Hrozek - 1.14.0-43.14Jakub Hrozek - 1.14.0-43.13Jakub Hrozek - 1.14.0-43.12Jakub Hrozek - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1456013 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1450125 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1446085 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1445821 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1422183 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user.- Resolves: rhbz#1418943 - If a long-running task (e.g. enumeration) blocks the sssd_be process, sssd_be can deadlock - Also Require a new-enough version of selinux-policy so that setpgid() by sssd is allowed- Resolves: rhbz#1405584 - SSH: default_domain_suffix is not being used for users' authorized keys- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.181.14.0-43.el7_3.18libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=21eef38c65d50e5eb1c3f51f72c108a65d626955, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6@]"k%{f}|,p35muذe%'&* I+gXjI*%U-$28 KgVNs>#fwO\-<))}+l=o[;J5BTxkje%B%RP=GObw~j\K2U;lQ|9̳Sr1Dɿ8$''w)̿A0 nO$諟`|-M$YTr,F: lRg{Wα&ƣ >áeϱ3< $ +EUQ:Z!ޏH%־lwϵrUFcoo\|txл Mu_aŇ/I0 <7ws;:]?@ )&L\ %7b/o'l*W&ZʷpV@H"MȔ#̋]6*WM})"!4^ԟxnZYn28 |ʎ.2Y^_WF$\l ?e;D%aws,C"r-XiYFMW]]1WWReXI snC< *) rM3};՜r#9YNۥZ[\;W%*Rc $-%> *&;(6?+M.2C`IX5Rh˨,:teR\X&)w k2v3V9' ѝdATt8b&2%;BgazmӖ2mk^ŧ΄:sDUk48U@U$B[v@Wx w%VqgDB% 0nqU磗ݨJn]MoܑLvF2^6-ؠţ*/^`J*2vV ~u?dFTf b?4v'")_RAN JEcοW4=K®mU4&ПOsz!YO3~X8l[(@sȮ*ykTyv2oB#&m"+n$_?%chY@VLK^4cvCy0ωd~s"bjt&vhdfF-l 72s::^.s)a m݆{]>hI2~/ < U݉ o%ee"iHzmr_6=Rl8}7#1my$=YԒ k L}ME]JGp8HlxYA.zP7RO7Xra"x'K}}E!X;M9 3tWQa׋+u4uZb{AL+~y(_>=*f ɱ:^P+ ܹp:Ř`6AAU5pIU3NA+oy/fIA[. kcop'qDR%"<}$ >K@𫜬X|ϢpY 7fhacן ML~CK&ݑ iA۸Ú@V>[v4k~YOR-~APTLL*[#;\cH^7cx($dcԳֿ%s9E~FB#5B[<&%蹦H:KUQT5*_p0>(m{ywjNfKO ֚4\f%%W'/~bkP仙 z xa./<, M"?T_*W5Q hը3R;q wFZ dev|vWc_U" ͤG-?2y2xt2cpk Z% 2HU!ؼaw)d0& 'UPP~ւs4]ZFzP 'r?|pME6y 2d̬0#?PU#IRFaH&$l \T㋷Y,Ym]/[ioqr965շi l> qbDk+rˑY$̉X[x`G- GɀLrjy*Px "J}xKe9^O:(sz_#12r%ΏS(Bi&4m6b.Ž{nJ(eWw/3JBK1XB'ż|?:oOt~ӢqtoD7D@KMoo "ע⟼礴QA-\x{خ]BatVC[}R|> nQl=ᯡzs UzlO11挳%;xW_MMhiM*|xCY|dw^^ͭ!*gd [1kcnVjͨmի\- v o]^ 3."yuxT֙ W5o*ݶwMA:7KKf0i<"ԅ&V40?S@*_}J!;Pq D,TE Fpi=U Uhs0kѺXETafV*>f%'4:OKZ ];" "]cTFdPH*dRd@(TyR'DߠI=B bƭʀ5vm떵n#JlUNw]xB "b{f { _bNԳoy2xklQ5FD)i?Z8Ydc*oT+ZD%"p U;N#>y3huͼRNh{|oz%=t/2ً[|^(v$+-xWE6R?Ik捡@\]42:ǝ&m\翔6% ]c^?-nmE搉?%_xocP7V&y鲹%PݝpM+u$+֏_6fQ&ce!ۯt`-B0q]ąN;7֘r<b,䙫e虎YTW)榚 ʐ-\9%@ue>()z/ pX_6-M\IX]1yhVg}4"gvmV ;x$в2J* \CK@P۱1 vGDI~b؆tB6(!29Ƕ^FS7vr6$mq,:"T~zv4D҂6[a+6s^1|"wu=*a tT@z襑NCUC $j4?Y5:m WGB?BoQ0YOmqTU:5'f͚'p._zÿAj J{j]J@o oeUP"M{SW/]Z&98J'v Z"'lF[?03ÑkX~._q+J}|ak4{AÞD?_j BjZ$n4Qɧv1 xc-̀Hyl+³-&ch~Ǿ)k2 V/7Fyp"E8v%}+/xe;G 8yxqP֬M/ǀ~cQS|CӅg^^&/dAMmyAOHU]ᩫ#0N]"H_C?2X [)y(Eorb\~F?1=/OO>nu:޵Ĥd2h- f:GQ(&u0p5<7XH_)-ОlGt~o$0 2AR,c 0Qmw;| w"fNȸf8gcn(oHcmv}4SA)R/h1Ԓd:T7`7bWhOM8gfǩJ _+ϟ(6cF ԗJ&>ʂ^0Ooq^6)]th=.7,(xB ג=ٯt "wY<W`2΢lGWr Q{ hjo{Na|"߹l)ϱ_Q׆ʸ9W 5@>;yBJ{ƶc VkMXvoc1 ^Gŏ1]bBߵ3el R0h~aQUx KݖOmQf1Ҕ?pO܀h}Cy%ڇܪ\//($18b^em!aR,:P9>Ku>U)IG 3 V:ƴq/|쵕k}D81LH~`&j]Z#"|OnHVWO]q2fqyƭRžwI&d⸫%=s{l&ٕ@nXN$8lj%"rǒWD(,$󢧑V`UZuA\xS]/=R)bM#<ͫ-ΦQX}.Lr".t\_lɽhIMنA _vMeNx?|ďC38#փF D[(@ESv RENܣ (Dd|#w@jnwuIc/\hPsL+IKj)v 74'ǺM} Nv>_-2a< Mpݡ 7|g"tC`y%#Lo𥓕sTLf]n_ mn0?/t\- (JDNaF ӳ]D VQU1(L\hyW%,M 7W'N`0\%{+wzDqx;y.;R_J0y}AO=j?UL t~Xӝ" ,yTFFZEf!j@+qO.(?iE VTVg Z L w UQ1KF`O{c7rA:8*09a<^7[]Ӟ񳔭XGV-99-Ny*x.*u](D~4w^ɪB޹23~gJ8m>E_!8 gIGSm/bf}'|f##HDQb*+-!e\G0!|DcŇ"jD5$O ~ qҊ&}pi B>SECOJݘu)*Vƽ` UtoGYY\Y&1m77CĠ:XՉYE0̏wZ5tŠOoQufzߦUȱL2gr>ӓr[BeNEYXbԴ3gt)l D[ݪPE4RX6y"]=Z|o3zMoNBTZY뉜42K]c\F{&lA+YC&G|Nyai%H [`Ϟu޼dª:{1@@5ۆx,tB-Vךd m_<@jG-pQ(ԿGT\H:_kx$39ԏw>mW5н1 IgsꩽHIȕiW`Ý" ZėxLYخ,L~|嘯EJБ‹qt{~lR$ÖAfmȿ: 7S^ qSH.Fv55}kl? @I : Bm[/}BT`?2zz򭊌 HnhBoS197[:LZUVHQ#=쨨rނDZ̞Mڔ<"k\Yu.TT % k_2 ӲΧvcC!?+ F##33lhhb| ;9KO$1|dDZ[ԻYfFMGCɀ~ rJ{`V.X";'b"tS_ *c5'"kF @i9&^+XXKoH؇_2(}¸~Klb9`k@Sqt.ʔʙUhKoU MK(&Aɉ & p \P=56*} 쥕;aaдR0y@GIx3TȆYtCS޻zګy&ݳ&K\.ˏ=6ˬaDC d9H4/a3EϖtӝKh VaJRE9~A1u֡ٯBq op7@!fCZ/ ^#t=1bS":BPwaҜuuMlZ`a&"-sv,E{ėqK/6w#iǘ*rTXknYtЫ5-) Q`sz xt,1V갃]I.TKHz74aM>·Ӥ a{-V,!daz`&la/cx '"[@vWi vhҐ -F<r?#/SP=$erpoQ>>d:I./+ʉPg;ES!؂B{8x+j̷-KǾ0Xi/}?B6}{`R{iY :A50kI@D;ԯpŒ biHzgn9Pk.lJJR-`1}eVyp[f2K%-k.ybwN$TS蝙C<%JT$LE*W|.hS0~c<|{(Z.'m19B%cR<M/uhs>Ce.OUڄxx7-h:n ,["UȒHdl,Bw z8נx->.XPj(Y7p:STBqOu 0s5]زR'm կ؇8C8BW(_Qk8 1=n$ĮD@,p. GYBRU˜CE@!OVS}31s,ҩlzlAˡpdpD>)n28t2~ ͋|-X %J䶾d~g\iB@{7_TN~p̋u[X g x4U'aسRH$ L=](oeb7JDDsO^̖ΏF6C%ܼunj[XyC7Wu,|ɆlBA UZDdQl!SҀw0̀S-vl '&/ғ7Y;z#+l貧IO6t0 &IR!pb09[ jY=U\`X0 .cc7(jtb; x*,pygLdK ;PIӦ;7)HiNl"WАp~[TǸN{5pwSLeL)^@~QBH!' f.Qc]0@FrMhd3MZGNpQ EY.'&F^a8d2EDv`q. U{%$-\U2Qƾ E =odKF~&_<|d. ;s@5`{@ H:w8?⧆bGBHy."Q]2QC ?m =rcZIq4JS0iU ț/gəG,u;l_VCLAY&P!j _F ׭:R]|Th0 Cq Ȍ"K*?W}uCsFt +GԜ~} ZA0GE 7tKu,fcb,0\EE1ї^fnwx+0siNՎ;EIٕ2*pm O. 8♠!坙:aa |2ڵB )&rhV1m[9z9tY^2Ej8T@mNŻy!^R$5黰~-~ŮGZ)t$np<;LF6w+ (MtC½&ꮤKkBsZcG}S)ĥbrɭþ##2uEKz7:UCZ" lRo ^_QS]g@ia1(}6Q_Nޓr=VpHf*SSJP-#/.>f:!Nd%27`FS%Ո-B ZQ*eT#2K9y$6uز! _[ I$܋2񌴂 fi}"BWkXן4?V֓}o_krw!~l% ̿%wN@Zj}7-C!z8BEbs6 /45F$VT$dl3P0zě&݈#U jnTrT L!o(yt|7 AUĬ̯vn;t:UZH X\嚷- LWo\x6`L\Zi[͖?ʉ|yni9im펾OnBU`0qnr5 5*e qPcΫ fʫ{ )Y!ǀ/ rVBiy,՗`[厅.̏g!>nQp])fHABoǡW/ -xes~,L͘J#y/օWs2ծ/*)a} ޔx*bF!rW_ BLI[޹`u[ܮy2ۨleZIċ GՈ (& O" *v?M2=zKJVn $sth={+!&g9ҰG*hh&w=|TkI=Y"3'AKE ;U#p؎\}zRD<nE@U:FϕoMn8!P|AM㐒L_!f1RRϷO4PW_,<#}hszBT)N˾`Q$grzqyS(e%>^;p:sTi oBUha-t TV>.4]^@9z}HtG69^R|p.&xYܡ$ ͌ 5ԕgaF kmt͆ ZB!_ea r}u%2} 8d6g]㊤S;4] od={fVQICxOv @%>|3.՗;/^-k:=d quc99`!͚z_#"8vOaN43 f 7g*!KD\ukgxT\<R ^DzqvT-qKuqS`\FҔo%fs*V{t=Q\`W<`cr;9KzP8Lv1\Z҅ +v̟4ʴ\tQچ0GLDž%-}?6#ڷm <ȈPf.hFݛə(׏;͵u0v=g[ _/W+\OZņ{[ 4!j4RΝ* ׍2$MV&q|AGiRpm\͉/Ma#YR&mlA-CLN[NOIQNEĬ~M2T=mӍ:%56 N:PŊ B2't0[B9tv ؐ|.[]k'O3_שHM{&,+_1`0"Ҙ 5LT@~{):d-0ID[ cWO'+4mvJ1 Q9':sg`QqV;S5:aK\@. kuTJpܲ=&.jI X(r1CzD.6IKA'tgt'Hy0@8G)t>zUZxv\]p4*SRQ۳1`SShԑTLP.n>4bkT攀^ -RUjzyU>V&*s-5޼I{sђI[O{טcin %;f Ḳ0/[EQ; Re0K}*DDLz4T%mUJv#OXoVkͨk#Xxs"g3R;)Y \Kf /`ETNo6߅xi됙ǩE% Ԫz^zp3L *t}'z*g~&ȷi^ F}=4E)QbdՆ {5PMz#Zd0_4(p6IDJ|džO␕("0wI)W1HW`e6 ,!+[EقMI Aouky棺6{EKQt7f.&V|S\HJ䩾K47$Z[@Tؕcy d,:[%I݁$ƹqȍ//e1Cف% L| )=؆ r:Mx),D'BPEþ N'O^?_&^U1"FW’bċxaăM<{U!Nї157U!(Ar!>~Ҵldeٿ$+F:pt>SveV2v'y+Yü܃%&e1=3k "9&IC0jQJπ12 :&O|-WmΧow3䳡riz-[ *"3zQ+eSV> sD{1ufAu,^v0}<>\(N %w< 'V]O2;q[0%YX;)y ;&?axRS#8o.L|0UmP6X0:zG9aj:z{ TE51`.4.o8vIpc/܋雵ՒZ ("x8[%: {WjnO<>XB Yj]a3%hEyAKڐIݏi]3JwM ^{b)K|h:azH,j`5ɲo&m8˪O;9ښ(+՟B$3 oLi}cTnbD\/ce뛜.F/ċ32*i[LJ&XxvϟMw'*0;t0t*fQel: ]%^Υ wN^7e(;{ ϖBhigܤ/$d]˰rH(Uས|jsVkFL.?ť4 U-Ï-+QxX]_N2ĝo7Ũ6%-ΡKSt\zLďCi;}+,d qVkoV.V~3(GSċϺg5څ^!96kH4 R$2݅pI5k,"y_elYDUא;" b,{TTX酢PVk/zq+7 KVb-\քM~Q^=o&̵=J=49?^iN» Y-=h^[:/4Jy`- %aTzNQ`4uhK'mH:-{rIԯ|2yF2[`*8oq/Pt _ l *Gc_AizhS ^xrZ& ŵ(|~ә1z3,`%Y8Ė&63jk ~dk)6V6"Amf51p.B<29mc0[W~!lf 1 9wۓe9$,ed"4Fd-g_> Zq]* ِG$i04BȥSv}Wain;&dltPlO >~ 'F* THq3ݮ s=4꣤Tˋppz4Dm7@]?cǨJ rf`i H<]k.9%B%;}%'Ց:ܟ8]1|2@0,Z, o <KK%Y)Ywul4 %'u%:@&*.=pt]7Jgu(oj1 z5f@\7ŋ9Eh/Y x58U;mCUutr*7sGfocLW[GkqŔ)=zeD3*$ 7v0Tb'[0Tư}9Olۤft.Z1{OBVfp 4;WVk[Xea` %a*wtRPޞ] >bv  8"v,faT!Dgu8:ݘ |Y:S9T6}|q4`_v}Q!"-RNP2!Jc;ijVjStsk_M}[@Y*8kVN|Ϩ^kwWҫa؇oopB)1Nm5L;5ќ`~V +I˻' 3YظX" TizHFWز[\_بN6kplyq韵G!`=P3u/ӏ'XKծǺ o S/N'i+=M@&dk',i|V/H̯:JD *>hew?12Y>Bay րIoexZ Loc~[Q޼ wozd>n MP8;Eon3eu[GuNn!W겿%MN EOieK=@w7DnmhAxG m+}nOX@"ǷZ, s t P.PÑa_ ͓CT,*h*:u?M2C%%La}Z<}c.N[)l!$%B3WX5h I"1Y Xi}uT:q1 }ԙ^]ѷryQsV֯{"3m70W Wz^FQpS e$M$Vx?93GcU5w輳8g|?I$7k m=3J 8mu-SR0s`1@{:Y/C[;i,|t/YyJܪ5,'1~`;IC+9 3Ёd 4Fٰ}v}3!lL@oͪN90N ;9V5s\s MÙ<5|.)OjVucٗȨ{?f$Ja;TyHe IJߵcDr[NWTazh;U-J "u;M&T$9oAҨ5'ϚYU67x]*=-xAQF3#W{V 3b2 S"x}N;;C^\% [0p2H*EH\e]OKW䟔_:,:|\]2an>Sa&p,߉֚l.J9~V-TP#90&[!1ӳ'W{;ڑL1< L+.bThgr #IWݨ*w}_f?@O2Wi7J=!l( rnnjǒf}s$`[kL5$QjM?6%=!~sE"B?˶+/98?d #܁ALAhˑA[],ʂ~6ئMEG_m|L RsnrhlKQR[lǤ Dĥ4G1:@Ű'qNL'<.d 5Z[ |Z Ncy RgVԄ**%Ei-t)H$MEX`Yϭ̑I i811YkN:1RA 8L| *CUCzABcmH(V_3ߊ>,uj϶kP=k@NV]Q^W6LBX!p?j CKk0x 2rFMgHٓ>zw*G&EтÃ%+ %P3+Wdq׸iX4ܑ"ʊ+焎y4;;7t:}U[F]ǦaObDq5&ouQ@wm~i|7 f*~5 MQ䦌h80gI5H >5Dr Y:w>{PDu ٲAg)2fgw78ߩ${g跚N53g,yxߴWpF}L'}6TP>Ye.;L}"EƥW:taE+ɨP63w aXabb5{gM7&tDQ>wrmaUS#Qy'M*tiV2FQjU, lG26\I!ဲKR)4HsR A` *ieSzodF֒zdܛݣGiYSgᝐj&oBA - 2a98Y]+)Ȋ[ 3 ͗P]NT JLD "t,Ï! XƙIyTUQ0p-~4#PI0`F(`웏D*ԟM~Q WޓDR h(*DmLrE C)a^IH qLEɈ*IqVoLWs {ȲFڤW6QT( N$J+tQʱZE˖!ʅT$Y55 ×2%xnnF^oXX9˲*^$㺦W}uj\`Cٖ_8]rԁ_b~*Bkx+O"Qq)i1Ƙ>GY=gd?HW[5]@!fmZQ:u?ޔΩB,=_+4B0j~x%FqRTL8-g+}8D@~ Lj@wI EV9/Y \cqi8Sc<9* aO*ºǣ)oWG*KwuLޯ3n#@ |ؒ\_A %nd*tvrk C^~hM=Mbkڅ.,Z71\RwN.Zg Xo(rĩk=͝&jvG\$9*H! TߟD[Vk T:L,n-Fb7 *ă+ aHԲB<}i$wsSZ#ۭls)Ϫ-ϒEҌ) ])-_7wyCc) Խfꑼ^Xi$]DOgy[F؎%'n$~٣#.6i%kEoS%Ug(+|.C##Ra,̌Oz0Bj yOXrv4se<JslueO[N cE Tl@4oh0\To&fΤ$%%V+\s%a#cK ZX'ϠIDA݋lZ 3#Ζŵ+R}}5uǥі;VP)(u}ZC!#4rєt.Jߧ}fΨ UoJNF奷_x@ {[yek߆cs;ӕdюɖ^h|CѱkTg= raH)[a>#v3ҬJadI) Ģi<{K vPk__V(0A9A&\/5Ж06$ ]$Xˁ/]*UEh6er4ê jSw־zἁڕ&#HuWgÆѶQe8〄Cs :yOU/FvZh¶Cr:eð8H_w;oϠĒ),4k72B~m>qҽh -ch_812 -7g;=cqzÓ;%Ld'eСj:Zix5ہߡ $ޗX;hX I0psAHT,Wd{Pu6Mύ$/n_TFW4Ud-t &z&hJXхko7AQ*Ċ+KuȕZ@dn_~6?Wϓ7J[ }eqHzܾCĥ#QtܱWl47Mk$,B+Y PSiD%11پ.ijI>Mn3r={털?Qbf ז@RpgB(psP_i@p~QDiuc7jн.1&-eC _Υt ?21Z6LYD3B ;䥁W>*gD: Bw&gx]_&O}C1;# mK/E "*k%Ǻ^shYR3`oRGoa΃H,/3 Q"pSR涒gڡ[dܵ7URyWGl7u3a[Oj"W[T9Zj~{4I^7J6jc}/fh@VolZh^G bH3gdsx|g Eaa {Sq_*'<=[W3fMA\ j7{kMp TĚ*~,49zL|Sm#N![nKXWRD9>T,*O+c!:^Z$Exdɂ7`V}x]@ۚ0 S 0+:ryfx{w;3fGGg;EK98}!5kvhcEA<-]KSd~ze2ԨSn%Q_Q#}^6T:G#8IbfsadvPx:R``G {9igG{.λYarV܊Ҵ"~iyi9SGwل"M;\hqoFNE-6(0Cл[ vPqjג&@UDLX!珝84]@qcZh Vqj6ٺ},9M6'Nc$0O$/R+l~k3KԤb+6sX|h8H KMٞvNyN[Q8Me?߯{Av;`ֿF pmӈL/ՄWߒl۞yvc?$Jհ#y[~ +m.MDk!;<pm7㖔a[E.Z̃+'%kZH>uUVew2ݺYݵvTVҍ p?{v Wo~u)[3ڰ}A_69xˉiNI`@3'b,mvbڵ-f:)m? /",S .yv:mf2ȝ٩9tu@Cy"A' 4D@} ,-s ӴH•zV-# -?{Yŋ9?_\E?3rx08lXs! Ξr,JCWeak_Lrp ZurYU 2QD t`@lu{=$ we4 !ճ3>~0ɵ i]NZ'"%6i):u(gxWh",B?ff ](_)v@leܹ-APVyaJN]j閂 Wj? HQ6€G2E: '[VX޴NLWb)~gh|#n3'G_"q [a\}`[[.MVʖ'{i==SUf2=dy >,.ILᵳh0Oǔ%5zܥύ'{%ۚX-m5,$&jf7$Z6d%ks+,ΫN9bziʹxߗfGHtu_nRd&Z+HKO*MukSVd% 2|YԾ߃1Wm !:G$|¬s{ p.$`JG.dP"&]\ [ @'`K~ --{*"*H|=#FP#ΆPOJ}iJ;)X,ӏkG?GذH^)rPX _S6^^ }Z,=:uO, }im%i /P 3yZa4mEt.eCUN,+Wmꏁ樂A"4U* Bܽtdہu 5kY,5BE:er Ne0^0^N0-X)ʞZNDp}ozcTWclxQ 7 ;!QYdkꝸn]s=zR#) p p6=5 iǙ](w `6j(|:R-م"咬K L@9ؾc [ʬɣ]V",.V$6\?gql.5*V)&BTiku}›i"$Gr& 'BrI|Р,Cp I:C""U,\iiXs|d6yiZ|ѱ$w鼫+HC 2l x&Nc׍76IR;d"f;x.p<RA'hh.Zߩ;KA gj!izHvVJU"afPXEv-0"ć5zށ<џ+-G?d}E糌S k3͠0i[#fGJP)"!<ÅIK| Խ \_}a%>@u%OGɐg,F5@玨 k>LF炍1zUu?rNrùgj KDZ:9S>ރ g:8ESQ3Le3эO0AQ;"QP' ]CHgF Cxd79{`[E׮"1"nۖs9ڢM|K- {7~vm6D^Pb)ҋu >a2JzqlD3AŒ^N]G-?TRރ_G e"vg a܏񚾴G`}I?;g4|j1G:ÕBT>B=Lwǎ`C /͙ܛfwf7}$s8SJW=fz#zoDed?U2X8?b@;+KdHC85ǩ<XyPh58!s0GY7UjzBN?Z`Vp|4 l`vg9 ʋz 6X,KW3z*Io z2rsQ^[UD )FyMG3HKԸz t(Ø̉ؐ  5%Z$4*>YqG!qݼK|0FBE3/] ˧MYR*(sX<2A T'V>,TY_{p[ M=e)7.԰Kc&^`Mji^ݵz{ebː8 U:d>4W@.u ~9!{Bqaj3CLd]ЁY{.IKM n͌ga!4W|ف.['Q-`^肁t2mU5v;5JiHܤ|;_h7 s_Yʝ)P2kc^[LU%~9*n~fNj1fv.BUCH]nyݭv$lik/*Rh y7"EO~Aãڞ3%@@iAVP1s$@цPtt6cYM#D7Hc2Ӏq{]&X4{bh RľW?a%yAcF5*iW}ب,X`AXBG솹WM -# Yp;F GxlXwLD4LD6''\H9.sϤ';R$Ǣ/>ĺ3-U=OsdU5d,]J-qLndf/6I8]S/ d7j[ψI5s:B<ĢRj=,k^wM)~8k' I`!=ʛ=CArJxDǏ=fDx,=_5=V,_Ƶ$qUs섔ghw?Aalm Ү4IՆ6%긣 aX#^zV>t'۪vzf5Qbcx[$V/~"$nqU ybb3cZXAZuH=s ? Z?8!?⴬%1#&0îUAL⋍Kz7d,0@6801#|JCܔ*Hس%MjXiFZt1*3X[g$*5 0 1b'xNT@%F‚==!fʁܳ''8kjZ6V'<@n:+N`ynj Z>0 @(r"w["ώLr E '\Uuΰ$QX祁+9=M *mNdlrtSz9v@EGāgB͵J-KN<yY1n*7_^t!x,wd.srf=HY>9 9wX713l{C)?\41IJ!2ӂE< GaJ^:u'ǥNu?pU.y&=V4^te}Y4z7c=o! ELSPY=tfD A2@uC_˃Vv:~O|"X ί[xb+o[ 'Gtŋ ߿0AMEfc[k!0ӯ+7{\Xo֔NyGOz2]1GZ#GXIUvf(B 0+=uܳ=a> ٲBe*<`Dn4B5\BFm$JavîZZӑ KIa蕼&qZ }z|OTHk?WP3%0{Os\mM6&;OAr8"Zr:Q#+̤m1ӐxKw]KÍp^f,:~>5kaʉRASY-3jjwFWNJ:IATRW0t-BA6XkX Q2Q+eFh4C^. 3._/Q3.`ߖIܮD & 쭈ʎ(]1HB! =t^E"F\F;13~J#&m9}?QTL܆`ǷaLrL2N$ATdjw, G(೷Z- {H4E.]W .ia{ll k0>'ً3$3~npƈ$#.E8Բ@y7D%|M2`͐GTV§Ijo\>AAD4{.P_d*;R0B6J7L uAx+K2~l$FQ"H;vDE< )hyq)]r?-#g28.w&urB 07҃ B8p0b˗4 ۪V^}P79Y2 e(Ԉr#f:r FSCh<Կ@ ]L|zci j1(Bl%V"Q G8L=*(%|! 5x9_]6]+UߺWI [aq"랬\<{n2u1c2`IdML}: R7T_DnTϳOfk5/y~vvKw:OKRa/|ޢ1bcm2s^p''9G0z7Tuo/9WE<Ɇ0]NI ¤Wоq#M&G|cy2"įW%7 RgEb@N ]|UF6`drTZ;dvٟe S TZ2L;"2M0f-6\=Nx,|]-=\ 㐊H;2{K6|kyR\U V]M]}"(Ήə!Td-t *kS)y^L4@e1CcTqW- l!{J(j}$ ByStnʯcus'ĺ"Cb[1,#w-]]8WB{{oc"5rx^6xB_ОIDv9͔ڪGA2qa2jt_QX?y[:|unWnQ,Aj4y9\>!9Q/dl,3 :$نPKsNqxr:^¢bӺZqYÊr58%o: (є^5$&02`jݯaӹxeTb!2.Re =L"*s0 *3wx /[\25IjD&L1M6VUs||܍Ww}ZwA/3 I\ ܫߤ:y .%H)$wZzY]ۥ^EwӘ\l(YqQ 0lp*֩-9Ex81|2L. QZt~Lr!0fv{83jVfKpjuP9[^S.TK)P*q`򜨚ȢZ0mkH;/[꿗Ե|w[7Hj/\\4FԴP[D$ \sg1h%0,iv>PE;jK.66Sp&SV<}ݤc7=w.oJ VDWx B cD2o}4mxҞ;d$BA;\XW/뢘4 HsAI>iqjB u (ը!3/L Xys#7~n8[d9yCito?A_-s\]܈Wr?OPxӎ"kHQ/O ʊajrkՆi+pk O{XD5uճ^yε}.t8=@wC?G'鋴hE{?j`;4F+ :QsL4)Laޝ_I!}Jmuamd+ʕ'$V|QpL o֑@Uo6/r 沛 | b9e5 Sq~ymRam^`0hAL;|ku)!Tx׉&B O|2`kIuen|34(#^j~b"¡wLC?L "y`9:ݥ ̤`O`lOVMEͣ%ׇ0<u~}=}?MRNǃk9I6Y \?ૻ1mʠZ7o4꡶H[o{~1NE M?IaSG  ش A4="v%߯y;Z(Iw=R=+.R ioG?,MKkXAQ5g`l|ID-ksF [.K.2(EC.=;6ug5?]jȅ0U2<"MXoӣ6_/0Ϡ%84G+QwAs\/׼g\Oo}JBaz|~ALlTlc"lԶ[OkD`Lȳb+l[;\(FdzI3oz* ~]ov亼M}u=+˪:.tXr2qiGz!(X?lPtzLsPR k,NBk*x A/n􃦽Nu4m]TX+E"ݓcG~\ۥS%QR& Bc &p~J|I6WNn!*Ԑa+YWlz #/!Z ;t :#Mq]ekyic/D!b5X7`aGσ\KғC hu5*-Tk%J(%"Ko^歋;]1Zʒ%r$(~2JpXy&y͈r[hGjӚ=mK8T w̿)?H F\"#YtrI:\O5lJy;7;Dy' O[ uÿ,u+__WɈ R븀nXobje*hJIn1Vq՝Pʭ?]I3rs|BJ>AGθIy]J +U+%YjHZĩ^pzHb拙T) yr=/,jG-\hs("  Nx23G.*62/jz|E—GR54pak@jC &;on?r=vQ"?*l3\&:0`j;u *GFApw_0*)AQGEh DM]ۀq ȗyLh?h0#3oduɭzUDt.ҲlBR5M#U±=UXS`- 2òP,@[+\aroSkFF*L&}x>CBNѽA!pE@Z|.wHSM.U6L F (Xocb CBN`a'h䚃.nѴj7>Z,'ޣu(rݒ#^zڏ8R>% )^|$I r3k_ HVϤЙ5/ҘrueV=ҩF).X<ueqkYhK7ڱK d*bG/qz%`B&iEU^e k/{7^?փ턺wz27 iTrxZh unrqd6oeT.iB\>WE]lKf~C>:\'njłH5ˠ7S\#ok].4k3JHQ򀚊[TXC:mGif=`X*f;WQL$eO}__ԑyt0$'${Lh k(J8 vb'b@vhl-8Ӿ -IAΚLRSwJabkio0&O=]饦 jr8&u%KƮʿ{5Gowt>HCRm[Lf.{ 8=jFm% 7d0JJ=S(d?w%Tq&&Y.0QHǁVPܲIڅ{C):˓H1 7 B}x&36KP>8q/nБ!od80=Мږ}mB. {ȭGa~)tM tǖ{pt(7L{_;sP*®њ`/fh< i{pd07ŇV`j@`$9.uQ> #Bq/&ⱕ3 vXҁ\Ɯq?~sxf#}01\_*FPc,6m1Ȟ`+s% jg33f_In) _,(/ 5s۵Q?j #ƒixz` +p+ryߏ{/iAއ6Q$t3b> ?-ki)l0Bf Idbt*AwGNfo,|ŏF<$~4nF6iG"۝ C1osm#nnj>r3"߄Tw:u@IũNP!i[CUI,e ɍo{M?:_ Ԭ@eU,j&$m̉kC`Һ27%4#W ºDms0vl< ;RIgB9䬌[@3CxOihƧANiɈ6bڗwh->M:s>O"1tg]% _,SO:Oxt :8Coh>$Dc_)2"ܼ#7zXncM'C#~?  Ԕ~9GӬaV܃lR3J7WٖD$`_x=E NN܃XlK1&< 'Ǖ'Lp* /ZMcIw@k+( <ތR*W'\nIPB. 7#ū@'?̉RV](']t懏Z32%yBu+' ~s{aW N 'S@K Ruz6iQSD$3cV:_]QG81_R"̅0xv c<[ Ȳ9\b3vDࢁ ItfpPwmޭ"$r@SKn4Ub0W)0l_O-xl3{DpץVme,n.q,5F^H%bG!J2 /鯻>y0U5#slz Rx3KҳĠy>mN6MLG7KPJ!jċY.W]A 7[LQ x#Z2r[r+ pAu*3染D!OL;BS9չ1PUGM`v=o :3{c a?&EqC<"u`$ dm/҃/>?XOF4,4`uZB] s+QQs2.gz/< YN31 E.R?o>wܸoKW{9\vБԞ[ma+jhlccmb ox MH.- W#o8VM we7Q_TٻVBN9'e1T1+;g<AlhOǟ8'o꺂MrofE]j]4WXW)7-x6=A6/@ 5%}߷L2C/M:Qf! 5;M'e)5;C'MR# >"ѳsp١E-%fdL(݅gȻls{Y6K/_Wڅi׽Ǻ_iƟ>Z¤)gz3K8|)J`W~plغ|%Z5eܾ؝RЂ30FƉ-:msƋ?a 3^Ne=o5_ +_ -,yv)IXe 4[Q'={[Lo+ ljKv=K_ Hjsy8,1JH˴ ˎ! %U"uKAD.Uɷ:v] (Ī:&SL]&`֐-|֚hi(z]0~,ݸ÷@vRܞs]NxڄxU,qA!1pKM@Pp ݚo"&o]|֟1kLG`d&=.ڗ.[KxaIKʨ1S*?r1vmK뗷:( 7]&l:&oLJQ:91 VGzBYv xۜ-lFȔC}PԒnHu)CA/RJ=T&gɥ(I=t8_3G)Q+{bzkQDR?Q$,˩" 4\ޏBp*rhoLoZ%%u,R)MQkdl:/-fD6`(xu] E&UY Fdkh7o\hً0,:2s#"_ AM(OQC˜S<vZq?.=0H_7g?>l"uwGtS1KpV1жܜ( ņ_(ZySD89sBu^SaDˆ ng.X0k8LhZZ8-|F}Ym l$Gu جQpogeOwg:*wֶبs !ϊcټC\m'CHUp}^V~@[8Rط{yg fWo"B2 AuХs`hlhw]:*UWSCʇ =r(zLЋю- &C3qctb$:_:_F뫏 $7*첒LE hj\+Ivysˇ]1YaVzv6{QXC̜_0QI񿱛劭PE4 Ci_+xuMt9#z*WE͒v̰OJB{izt>urz2#NDu E.YOLR QlmY8>\b*#;0%eN'c,{_69(W?Kf5P9 G7735ՕbSDq7SZ 2{ \CǨ rK0AI,΄s 3ҝ9}(O F@(pUB-̥=Q~4qUZUqCg͉ ,)T^^Gbʲd!ܬ=Ia ː+bpOlL+bم>Jٌth.O #Rɭ/ڪ+?I/d$Tָ8 ʃ$~;8߯H R8W젗C:㠶WbB[%OA殮 hW*tIލ*" G>Rٽ)|#g E&g]/U:qdœmUK ]?DDRGQ57Oii햕[&pb/(ndMx,&+U)71|8 0xj8=vavJ[wOly{-xĜ<_/ {=$hith/E$c DfզǠx;P|T |VT \tgq0 `A_ucUBCGu֯{>;|Bi>˟%g_ #rc[t1$+HztYorRBm_<;gsHh?N,a Pj%9 ٝ^N0`6SEX"%8[ u SpɛlMxм<-91Ft !b`h wM̜Q"P'oérsŧoXuToNqVƣ0"Fe`<_gƠ~?'M5uݴVԺ@AZ7%\G`ެ$HݗppX#]AƗZbSBZn6P#}tZn+я'D*ڠ}^ŐS^V0)7SO 'ohG{7cC)2FByCCsa btef$Yۆnae[*U-IFJӲVP`<f/n?@*0%IZp#K>ʓЗ|_e%c Cl"@wQQqIMnDl,[ 3fkR^J,4/ e`dXMU@MPSaGbjZg>07@U6p `NTT>A`<"9PU|aPfPpY4׃b~jH1&g]LgznF9eT䮫|M% 7LcTNbMjW@S`wapcۣ'Kd~O[!Z2%~+ =U/xOY‰@9>'E"~M?iqr1*(B̍Z} |H_\d Sv3ۑGq3E!J#'كTr &C>Ls/':A?}%Ԭ h um\_dӜ=Ne|'v MyD2ݻ/] ܢm3 ?rÊkA|vL;/j.;<9]Dl <|5y&¡OKӒ,!O1L/*8DmWqJnY}P"VkdD H٪Rp^|2B]Z~H[{|w`5Z(,˝M_?pkR7xS:h2NKwzٯT㫁Nġ_m :e2Fc"wuBsL'@wkaYb->v^D(]d :t؞w*4_ctI_~_WЍB={,Ba*h` lM.Wǐl"Yj) ƳG!yxr·'K*Zy^~<ö%S7˦Ecà' Sv򃰎CF evk0}畉/<| ОMwaJ@e'Ҋ^cޟt^bR[BqS֤@jE7q{XvQmo|L'H92L7鲫rgz?,B_zX6L4-(5JI b 1}si4Ab&uVs a~=V{u@~{S<ٍɮŜBؾJykp疪f.a”y :O{?9SSADy#m6sl7R1~'^I䛬8iGC,}IIs~3nr3=j] K1Ih.uuR=cf$;'_S2KP?N=˻Rb90Dx{em}URO*E0I@deB.ou,pH![7? 0g3ֲƞAPdaL]mTr> q ;ʰs؁w;s%.C[7L'ePu4l\rs•'"M).(0'XP's+1se"˃Ss5\dx齝`Kx#GzՑ_vm;u " o)`w:~U޸wIYMF1cy sڥsEs֗G>yl;|@1xRϭ^wE5W)ou!@pN8C:suaؔ4Zj߿O>:f%PL' jPs&AŜ7/E]>iݒHwr-hϚ\E䧩sѬ+Fe== Ӵy@R?;dv eE65%R.{ލvᱥ8{ U;ҭ WNT2V%Ij8۰z G "P+iG$ DaZVKF>rՉt@@J;{ hŴZ6; i >cҧM,,RijiK5>,zi`*,02_垬L %**0!3Gdeq[;-lG bYJ)zы/){Vͥ^Edr|=Z'PbەE SG2f3y:<_gyp`$pA'W#􉩝Y3ۓҿP%yTcLw 5UA$h Q5taA|J|øfUcSSwUmF&&i,` McX"N<5(b൰Ŷ %%b,(5?lo&Tާnu-Mil9&Y_)'ԷgD @'9hr4ieј jT 0Sw1Irz^/ 7)S.bx{d],XR3, ^L׺ ]~a|ėѴuOpڤ6Je-vl6ZzV!]n N0V|B1~ΝTCh!ϭ fv@/.#O|S>Kż1!ٵi>FqW)悂s'ʽFޮ'O2{Fksd8GC' 3GV/i!$QT%:qF{33mnrтGM]R9Kd!uo2TT}N")9-ۂf2!''"'rR BiU YiUCw2^vp*?`Y\ȶR DR_wJ^;O Q$3zƕO)W;,^oW8јl>G@DcZ 2M>W{<jAK$[L:`GRxŲ%;|r#X*M|V{4mZJ!"i6Θ{oaPd9vTI.Rlfޙٽp=G*(2s8֑)_W2ݭxJFg+'!2hP?zF8Mi{"W1` ͵[I\1cR3Z a cPַE \qRKw%MDҔ&^z3\Tf1q8\Y?0غ 9!@bj&!wQMɱ\_UOs pE3i8Df V:hK"9m]|o.RaʼlJ1B|SNkj֤ \9 \NeH 65ZO_ 1wvEE?@pވyGºfYHY;wH˘V.x/ .l-~a([Qς6)Ogka,?}p: 83X][s0"fratb*͒y E <2;Sbߪ|{7jIK|y֠/ʯѸ )e)"m/l ۱dR󖇶)Rb0LJCG6BY8WI^"\R= wnЪzEU̾~M+@EW&/:d.~'%l}:eYD?>lWv?Zr N{"@K& rCU{eT`3Z/u$m9gۻhY8~*: @{Va]86y8.5w@L)3W&\-]P6Ec(iCѥ.S2M({w|oH\޷_lY\ u4O ۗjOmm-az!{tYn!Y{J"oSJB7WA*`:IJ%Z)|3k{N50%y!!qfkLܮ5ީdO|n!`o)ݖDyԺ%o^h(9% uBG#M%N27R~Ԣ*b 2Q܆6IeP3TpD<[?/b#l"ڇ@w :|چbBgd2yF;*@,rHdweq8,`*ǧ]#CNβ NW-pu2ht HҒcSTAhV@9I=[+b'p>7|fHi~!\M2L^<+"ؘhd'*.[fB;RG 4P/[UifxG i2 1Vvg'7ՅӨ=TeQ_ݐNR2]uuQxmUgYcZGZŒיi |;iuRAj $ CLTciË7K )MUgmEpo;~ EopW0`8 dzA7*#6^3MQCqY4+:oNozX*Mϻz*+Xts)^&R~/br>8M0ErkT$^^bKY3?-rJF./PepĀagU%1p!'ǵy(!N١: )ϋ7 nH*]qg3PnRO6 UMύ:6/hQ?g} ;OP Jv,1E]/a1GxwgSkcO-t34^,w;8QWu7MA~'.[>CXHľeQzV/굄$sN=JΚckv-&EI8ht!Ad{T|\b{vP C< aQב[RSf[V l蚎d.aL@, Llkӝkxsw<]ųiA$d37q`5l_r~_kUnn)1?kce5UHEi3Q:Ϩzb}=Ŧ!L)_q}+l$?B$hb;tY5|hJ3x2j0| 2?Z.&8E0BץabMBjÃ'Ѭt'16=`1%3>Ǔ u'K.%\I_s@Q]Xʶl9:IJWN.|~Yx{wpg#BiI1#w^ݕ.LBt'Y*Ҧl:rb.QHsy+7q$ LLE)ʍvw¼{ö;fEx1%; о Zڢz(R b1P>rb Wra..O0gk2m9l!3/VHdv} Ҟ;ȸ|@$P@.NX`^QIKhI4մ;qmX4";j0z#Q,CE7kӜEu̥> {D/j I!s]+ zlhJ-&ֲؘ'y,X#RF NV-p͟Тk6mPxlwJMFGґm.0gz(<Jsъ[VNDބ1 iF*)J]#:e'0UY̳'nb Z#Hx13E*IZ0A#Q*^?ʏ 6xpx%_nH8bv rt3:Nk7ɚ1nQHS:HCfBJRai ȞqER4juc*r 4^j{7\ S|ăؓ\ŻѻK8̋bE#SZ @۞+$~C?~×E:yL`+ Af8v}7t6B@/z^ *Mv WIZ ^Leܛ\[T J^w$^0S\~sПpDfaiA !U &"8| .՗hըbb!=yF|TJ\ў@A`@m-㋞[{Bi0摝ZG9dF[h inჾój988{~bP13nh%*`S #zDt@*D8 {c*NPdC:kA)?-@#?btvD!#5SgfT,JÇ /P2doA5W@Bi[\d.<T* _~; =5_Zܼ(Q"GVC#d~X qߜ7OQ5#r'Z EqY *8+zo)|zǽ!_8t4$ Wћc?׿%Tv,9J*-C:;?&bXSPƓBْQÊTie"e%'h^Dk>ȃr6˵V_y}8Eby}Oɲ,);J&j }߱ˢrF^43K4FF|{>"^]оl+UPKoס,=z"'w@BEι&.v)Y(\g4ОBe'v^T*ϱg}CL"$EN}96wj+!uj3Tf_8ҶpqD!6;[ .7y9VkIφ;><5h~FT8o֦d zt-ak_W,QU`hS-G@.<-bO<W'˴;0R@to}bn2Jcv׹.s@KutyPK[!Ng+=ެgV#OoӷXWw<\C Shs<9<}1MgDwMA1KR5Q1Qbs=ʟ ApX﷥1.lR/I"2CȟVLe4:+|:ږd}l5H"~}IJ[_eMr_t-%3Kpg8G@6BT9ל_]7ߡ;"L䘰9S!6A3!I4JeR<\lfwG k/TY#OQ κ>B>"_Fv!\.,6ڹ[.zt~R7 kA53*8dIyOdsn $۵rDx~Wq+YzIYC8̨CPݼbpV  -޼kƋ:%7B,xlqԥhONCysQq.WG?_oa"SвTͪ uk٩dzC7&I,+;/aC ^*\-eGGEq2'Ca-uHY! ZC.\t|n`[?k'4F1菡%(*$6"Q[~7+ES$_8BPL@AYJB +r Ti#ƴbR{5-SCtebz*x3TڵDDM6T TSsޝ?=*&:<[&!YvHe{G;5%"ۜd@sFUG aa}߾@yEv8͹x5~Sx^Ӥ@K`SƖ3+6+[ٰ^Lz9sui{Wf,I#mlw}`bio7mӀ!_g-N⿗I7C7xBE.}1 sM! 8ȵqlN X""|hǴm}wE5mzx!DG{$5z2y}(@)CO}R3 eo"YO;Ε2:^u9;ӭ}֯) &4Ȏxh:()AL[m>ۊ!_)]%Z@`*b/\xH%jz\{¦E88[ӳHaܘ9bzL[5tg|S-E% GX"o1Ȼ+CsTD7N85o_!V騫 tlʊXVc]7rΝVIpz.W&w7 ^b|讒Hd"sj+Qmmy+&92mL,Kܝ ]B6;!]#%"Çkl{27Xb#/)0XP6?K&OʾD 6YޏC->fc*{èWQ`%\oK\S|e oo]̈́,pS}YG^ˢKO7vۚŠU={>=Q @Tp{-1̢W'[zIUݭ6u N03pǚql6P-~@ rUnAgIo3p1fN7 xYzMl|Y:ԟӯC\cv&Jm+ Ŋk7[oxyɿE6N҇0cϩe-S^HpU8G>QqhZ4o|iCfl,)dYt C.ʬmdv`E;@ڏ^D&'* 5^t B| *_Tӂ*^XwlŭG早}'5GD$pB3"E_ G?X4|6v]5? K&/9 7./QZRG740WM73 s;Bm9Qzk\N_poC:h ThXJڦabpkBN PRn񂻸Ž2,Μ A-Ԭn]hie7-0Zě+0d[)#WXw"KE[#P'pdUPOieDeRg6(ib UWzf/ чއd&>m?NWJUaR}P4xl ?u4/`"n)$E R0{GAEu)tͳl@CqgϾP?6yJS2N60 +=15}Jz쩎Ȣ5woL5|GrBG=q|:ӔUAKq!5PPGߐef_jP Y>>K ZH:~AhP!~< X_|d=f9e3"OF&m%XfrhOCW6K`.5r%{%_u U{Kn5Z)3DU2^;sǧd5&BOTͼE ~ ٣_l>Ff>iDBӨa4եz1\`gӸW܊i>Q1\y&Oº%3Tj~8jQvo<d8ONnǡbbX8$YFD ]WMXz1ʊfYe*$ x>ْ"'@W j^ۛK _ \YMwEFyg手R\^SKՏO/r(y#d[ۆmBoI!Ƽ97^s@?#-OTu.DZI)a6=o@fc,^Ӯd+8A<=o ?$ {u#LJ fAQnw `PJrm&Gl?j>sEs0F  1>UKW\nBj%Gu>j>*⮸15$ڎ.qDt-C eϙr[W=8@LɞHIyy13Q d8w=#DPF06NYHD\'i/=BbXA{*nsc~8KC[b1 =v\XȣhM^B]We3K[H@Mhg +<ζsU^1zmep[h7LXw_P<9vV4}_dc7ƅ5S8]p@rmnrh8 EE#Q/Ry՝A#aVṕͣ?~ y%x|d=%?W~i.hZ2ԡ8<֗<ħ Cʥ0XBeb9>Rw0瞩}h~fCMAj=EeiBV\\Nk,5#fQngy+҄W4BpIgN1_W̞iЊZwm'zeI<A<5]䱸sRP?PRfMVfwGsB{,UB,|}/?j3K1yu^\uM(ӵsX:U1<!ߨO;.)8vzuok5j"ALkG}|!dыZNnDu%krY3ntD:\h/z-TEQ[LyF &B' W p9Ff n~V悷[ 0k:2O-'T7Etj>*yu/"M<qyf%9?A&lPatymEpxu@>V줌ne:fhFFNw똦ȭC >x䅡|=#Ә~-䆠q5YE-qCʞDR]hGCY㍞-uI ;= dق tOL s7T*8m@[GG\OD4K[>Q;>ȽX+"D)Y6?,YϏ%O-Zϼ 6Y>ݿ#U›vUZzu?>C(vffO)Q*Dyq: %"Q0Vk,{`|Vb>Xh J9J6u {sW?=`qV K1S9gBPnsYD)9"C RtqN-l/̅#q gk0:avs8\M}t"$*>6jʍ,"( RLt*l2 I2q 1(9BXS 2mbk97vL+S\:%N)pTXczWZK|]oq7l`^wuҌhk l0DNahIxeAFDY ȼ"@|2($I-X/,#¤pPZ/~a076h:BwTZCu CD!º]q?37g2F0@Y`5i_|+VwN4Ju+PlpĐozD I`i=lG/ۄuVL}5u#N!U uN IdIA$niYVkA[Jm Ik/>ne cgSP6_Z] I_@&a<Un՚Pm=37yԎ F.3 =b [q5h-OyڋgF̃PAsbd<9Iɑ-]i+-/ 8 LZ̰J ۻ%unCgߕPcRfKNꨊXJ ^hiKQΎ]&eZ`?RD.@nxp7<;+ hew~Oli*L"3=S^ԳKEfl-S!PΖ̛)F/ܼHÕBRRfSoG$#"ob9ey\BMuoZ!U?U VZcY HfPiqy&Y$]U{U։-ZH%ç<} B r>Xգc0tF##=4fj2{TJiqBzC$gpasAY֝f>dY[Nn?63G{]sPp11Hf)S%16h?T~&ÚM8en$BZsViv*/ #/[7UHC0A h[HݛSSߙaFFo_fa8bEG~Q 歪Ak,DTP*!n\/\،aG9M8u V{xSrcuo0;~Mw/ə@)N(ƪBͭ.wt% 7BP̏z<&/Ç#ڕJ#u%fQW.Lti"vV᪔/~xoxj.# ߻www.D$k冰>?vá ^sAl,uw麤"ꅽo$0¯Ki޻nҵ{%+2N϶ k>5e)UP- 2?2Anf!ksSEI*nTA(2r+fXN4GNgQ1-P2 i] g'0\tzY"o4lIkIMALMkwc6>DvD7Sp[3AnJE2hVm& pr<'y!^x K3f^%iX[(%gz`9ghDx"ޙ_Ƙ0Ҁ"r\+MakY*p6/3vL`vW}I2מjzb5MZhTWh 󨿷L_*;xKly TʵsuICl"iU2ks.v$P_@T(}_Ǫ9I%:mUGLU)DŊߢҎ XMUS2|-l7߂d/6j/feNyDaҜ-h9ё5Cy%E=K<$--v>D^#BdUpޤ-_&^V vjTL]J5d:B J9[0A#dZ3dWc.U[gi uW9c)!%u-Qfb#Y R\8!UT}b em5ቍ]DGo"Y@Z0ZcFL4~ Juȧ*kAGO48½W$Z vbǍ W3&NׄoŰ_:ēw +Sg1~cOǕdC+;WO {^>NEf_&&gle}HܽR,7u]H*Բulawj?%$>2.VD 0ϕc\U֜Xfidžx:t-IavKv>`g nj4fqxSkYKīRi5y~8Sl&:<%ֻa+!Φ n8zpp!ښqδo/֭XMD)u'kN0nAsfNE>A-<koEB/ѥ`3T 3hs*Ơ "}Caҏ)*.-͂ߘ1pN2Ɋ\W4c@Kz@J-RS2[`p48`W|.GPHCOt FbX f~ͩi2?k.RWYL$^(2hJd||Qm"I=mEqu0@x o7q+l IC8IpS3B&ճvΔX;c1W0Ar3FϿ_5ʝ&uNhots٪df{6#3/{2dCBĢ;EOpW'yG"Jke Bi?ëiz?GA7]왞nK'3y:raJ0Tu\gsb?#ɟ LNaHT~fHjjכqg)t9کc 54W~kĠ=9K>-Uj8Qs'jxP`ݡsLmmWic&Ņx's)7HvwVZW>E&C9VFGԚQ  +WaAzxg$G!M* 9Q|Ȟtvz\Jh;+ ym65$&D)QQXJ|RɿbR˞<>3'=?=?dc>7-NCsX<+@OݐR h\$PwKڹ̷//gl&r^Κ\MѴ/!{.<#l Ȣ4OwmkTҝ ucth:Aremh-`|8\έ݋o`n_[Dw.dSzɨW(`7ziG߃wnIQ&e_5ӂ_$E@y57h4*;挚_CKl6UAg%_tvv .Z ) uv-0dk>'[ um=n2Q"z?r9ctBTvtl@5pjlhۦ4況׷(Wa3)OԹJc'600oPixᦴW'ԝ EM Ǥ:0#٪D7 hάw/۰3>SC8+nUu*aVF3jB .o_0+,C g`}Jčt+*.Y)}@8S?!o8/yC'~<@'ԐѨ~xO){^eJr7΋H(,o qHZ\FK.'wuADryIWC WQK)M"m0nׄSG`f;K X`5= Zxk;2hHCRSkՑ ;xMIi6RLQ|MMme~Mh3_/Ni^Br2!>ׇ/PܓȐuU.g^Lcp]{]'w脳)&Dn|z&x'<Lӿ>D]d@Uyة)܇Gܝ)@Uܲ"'8-[O7hyMW݁x>Ӵ_úd~t'"` .y(}Z B@c(8qr4`O2/~/5(u_hȄ}x-[ei~9~j%Ó_7@ᖚ8.*i`VJ!8 mgQotM0`NK}-ރ2k<*Gkp(s8?D7b*0 2&H3'¡IH=  zwdh#&f T':\}H|fOw&|A^v[˵0b0c!j:8tR˛/|D~beEHw>XO.; A2aXCQu i3+8(ͫrh~1.q}]!N@Im .r;ſ1CsZ _3K괬7u"vԿ hV0+1^?ӅEbQJ;5rZ{+yY/67+ yci?ϛP + K-?.WbHfM:Rgr~]z75c,{H"z6M䯠F.ˑ9=sw 9E@zomMz* LF&WA -}Io}\K!KLdhiΌb&QYm`P [<7CvZS]yeA0w$MUfh;)! 9ЩswH.3^5[(1/ze5yMX33HzZ_}˭~ULx茹u2H(s1ム/AfrYA5%:lK`I56wlXU% 9d܃vB@+4!X{C: T^GÖI5:) ;?- H|@|Fޱ> waLM<юO&rEaӽ}X5{7[jS[B_v"eɦuK=deJ70^5'5bv һӜ, /?g, ko`~ùQJ#?Ƿ7鑼lS,W|UV4,Al^Z7ʦB\{ľgF!d]u.q@3*'K-Xvvf'Õ,՜^^ׄ]Cy($ݲ J[R14Bt!?f>y+sBicJ_c`bc^7M$:M3aL+VN>Wk^䡦Ginc$. ϲ!z!H1ͳE޸qn04-9H+w򈰙ݨ$.HEy@qWvޛG=aSL<:S_ɯeS#^ ƯYPX;\+&j0=sM&&[_ےtwj37z($I٤[U=_&^a?G?puTC(Ԑ6Bdz `Xnl"uvAʎE<6L $~Re~0YF jIZe*p׏/VA0|UT 莀Kr7M_ox) 0i5:U gm;ƴ8y&zȍh+]McՍM 걧#Vy)SVP *CFGqC)qk"M JʽMۺͺ dۜ9ZQ(ho:6c WVy H崣Ilޕ#E^.'f0YBIIHĺInUPp`~Em-nVoN7w^|~'+%x!ͤxek+4=Qz^x;["\:zcGmag ‘=xy}t_8-QD3(\4NJmnW#7P~ZJ"$ p>T_t>Ð"'_QߞCkަ4QI=ߠj Ln=/hYe-۱P;eG%X'l >%N"x g ^Knz=/SʪOHA?/I'6w_؁$+ f X/yU 7hkD+("]$m舖U{~Cq3Ć$؝JD^Ncy=.]GlQ#8FJyviK; DB:0N|c ,!t\<U%£7KWag O4Pjf( pJQ \_PccX2C,x3\ GAVSC2G-zT9.;e~>[NufmnBMLLI)CqHˮ= yUZQAx?0e?B ??O5|.,4նj< 9P#YJYuH&r3̬1u(cds /7 ׻ "ͭxKzt =,CMR f3LE?kvƵǶmL mvPs7ېPDZ-bzz|8̚`@NY▀d Fӝ! ~2Y#wPhd:a4/`&^;RlrVVhN fa Z{IGd-M/(4Ë-9;o/c;8L%Ŭ:a (,6SйmݸyQ>K^JX ?O7{$bʖL ,yat@CMۧIUb]#t[&St^D0BޠLNx Ee^,aFT\72N/_qE,ł,㈢Bpؾ tS)l <(4IyqPd&FGqf|>axO `yy'XԊr?B dhw=89f|p"ǰ!gOiiTRs"vݎʨ>7q!aQ!$v A?T0.}j^?scO: ClaRtS'ܠI[y ̓Nv E#&Lȗ|`iЭJ0#UtH_TͿ2V6FqID灃o xdҩ2)zEBw<+7JKhq+^Ȝt~VcZ߹lJ4B zLS1/Ŧ3JVq:rz'^C`lbhJbq,Ȟ;҇iԝA>3 M zI9 XV>k{1޲y]6r-8IRx aC,`f- ׈Ne(hw9RT iIëtp3[ 'sJ`q)4V62Ne&̫yZ+wY+J5 | ČE, صQrr9Ke'bA_M!' :3%`t[y3hgp{w"ѽNkcJ14?rR@J5`4tK7B0y,ӪpڔǞlTm{xJ?g*|S 98U"Ra=Byԧ}5Vq; o%pմ)@͘[ YAl!]?DjG+t kz9; o}n1\{[AcbU՝s:AlϠ{DkK7m8m 3U)b}R Z``!Vm%|sqIpaq~oHγIpEٟvAKu@2G&q輈~C:z ;*ٻ>YP9$^"$SN1's$AxȶIh;5ce4y3V\9E-6-pw: QGh|KդGS5{hEwR(Dv?)dci1c[}} w=媜̞q\zc7c۞8݂J{2<262),?h|]/<P;77b浕!sbT$1v&ՓwugKذ!9'u+-䝅5L"kd e/yڶtt4gh85mU? 1&,X^ױ%` Og׫@ւsJmB#k 3+JƉTE QF\s\eؑo5]uˢ9 e@ϕSWn?pX߿՗_j'\]˧q%åXld Lx[)S}NΌMBc'RL]ivKue.{1XMeA2$i9C gjӲZ--Ǽ }12Ez"ή2P{S`=W* RnlRZgs)Ô󉜞dXUۻھxZViX2Ad\B eOOo߰z)qfbWqUQoᓖ|d S#,$ao ƗgT _' ?^\}X4*Ώttqg>YHq6ml "b7bGDA?@Nr \N c*mâלA}=8@^\aGD۔͋Eڐ\u>1ph hRdܿ7B|;2dnشuOiv6-B6aί4bl4:e,61+*\4qܱMHtieJfuԥ3ܩY[w|NxYPti(\׭Յo59 I`+42`7+\c.JR1V^v (Cx#8C7k ix"8*oٽfjNJ႑ (= m$5VAJM {[,1<:ֻVdB{?rdRwVe \N=VocWOt͞d|jq\)^/eh x \Dշe2pa! Qpzv4^"j,O>~0$7#ۡWk* aZ{y)3SW^<\pH'>ڏdu{O#Q8℈-KIc|{ۥGf].(o ( ,z[<]du:,D 4~ODֳ]tۏC/r$=q~Ti_6\z' w;2XG<#i?kQs:Vn69}W ¨as`79ʟMC^?|`Weد(G-ʑpt 4 \@N `pGM&j;2h#A#r/ӧv ZGyT'l2 |0N S .*9+Yy^ 'ؘL4j'!)-X|f%Dep .TqkF0cpsK215g:Ja :~K>KPsb;O~f4\y)az c7P Bx+nU| g zEPwΙ`ܗGɘMV ^EXɻU\[x6K|ri&NM!~`< т_';O b촃i\Jj\\qGnG#f20\a ؍]f%/q؈~ G= r>ٰ@'acZcnf{z9p6֖&ɁOsmF$rT쳋qrؿEp LkipAA?o5LdE|3S%fH?Kuo( #/hpcdsճl7Xz" VIFԻV!U01X̴Ťw>]l?F sI K,Mwc.CiupP2N6v0]K:?X6 ˔y.]w#3GwhX /B) ql:\$Bi.>щG)=/ϷRKHFrM\R0)#'ڳ6_Ŏ *bL!ler[t8{m{iIZw,d"xžpWR#֒,9 WP ['L` oh },glAdqn_&` Gи<\+lcp"38Tۃª=Y?_T!5ϬIp#xp$9.>b" ";m\ֶU,h(ʝ{ś, <  _7!I+)S( ZB9U>Eto!* ;t"+tDhT])ƫX9Rl*k qmiB5ЯWM? Km1{Tԙ" Q6o3 <%*I Z@kМYyuIpNjt΄jEfAcaVY40iB#5 -dݴ@֜{nCLb"zǚݶ 7ju qr|vc>~;^*I]Nޣ\S^-;@L*sEk\YxzX JeQ[ }dDjބ !noԗh4٫T9ۉͱ"M] p=ie,<>WR{.)~5*zjAO`$lxfυ%@DFq>Дw@]8X8" :t֦:KD <)1M ǒd6͆{8Mw&#R*!|\B̼.>E?r&jLS A,%-Wa&m {cKer{SL96brϤԦ+^ !6[] Z-V<h@<+a`qߡ^{/[uk+gOU`Ŝ PEiC2kՄt^ 'Qq=`LJWI1?34.d œ,6,Qׄ&Fk~x _]bE qc1F`4[yrpvJMY8ާ:]nRFve7K'ÝE_:];J{O?aS0-L~ilu-8R.A%1*هŘI#0oRpr$Ą)!T9Łڄȥ_~hNLbrzeǣҡ"8lp#X-kzɏ&0'/P$>ԭ?K.$3f2P>j?\Z}^}W#'pBJ&XX؋b}+>%x@(8_+ȯu`N 햧g`wZl3zMjhri^@*0(A*;-ή"q߅1Kn}n<^փ$sBQʧ E SpL}ьG͍ks|c2x/LX%JtKǏw"h٬ .R 37#[tq5Y Aݥ s];Υg 8h? jn@y%m脵c>I8*V\+Ko䤼4::zbVZ ؊Y;P y)EQnM^I72ϐ@Q,՞"JHps'J0|JcO66օ93gRW9ҧnoW#sM 6F{au1w=|ܯAn]0]n hϾ{XQ|$x3bt>nԳH/mʓ#?TD.%;IeNE}'s- bt?h\qbܕ!vM>~&YX~۴Jw-='H H¦3P kŽJ$B`'4<ĄR#ciz4e X{ Bf`5kؾYVLۺ>{MD̑kbJqd f)3AJ|_lD-r+JhO roW nً3l'#eUȚ>5RP Af&{J`Qi$Q4*912kzb:$f(U{ºOSG'jRFa]i:%4Z^DۣzM7: å0}Ƣ?x? 27ΣddZ)lזj5i{[*Q9az%,Ժ8IԄs4WjLf -f1z砹,tܝTtd=yLNk3`8܎]egz;%됫%FԺ"*4FNj]ٯ:m;cOM4AlxYHePAAct9 `E(Ne5jGVU q2ks?V~ @'HۊG,w"فrJA0D2ktrm6B9 Q bڹa#fB\驏$k f*;B@ley H+yk+57$zh%raig5dO,u¸Zqq$P"~AI6sPZ 9y_(P7[P(qU(kQ l~Dĭ7?ue1D0r!afw[sm_ ufM[_Z0߉R⬥bݷ_fL|p(TUȟc)懴3P~1"f̸iNNk{.  NX,VV%;~gyXpG!QG+ѭ#quAէw,$)$dq?PJpCw#;NNE x!Ƣ4hMBmS"; Ct#n*i QA3c'*K_nt?~!g2|`j-g{b].1NW6 k1掭YQNRz;& 䈞#9 mr: .FFZy2aKMxfL?8.n"h!#T/2^q[i. RZc$9ȭܛnBA3&:ɩ_9&; ;]^VTlORydgq໼⺮uZޙՌ~_9֣d\] *~XKcS3Ѿhvgyu/q\` eM%Um(r,&+]w˘1ڶře 656ۏ}hy_~A?)y0!D\(!4R|菍;I7ԤzjNC =u>0O1aY Aے'uN&75׵[*dK{WU](TFnXXCG}d?Ao5c;ncgj:xgop_-FbG+*.xBzxŦ&/j zYX.i9=o?P{U/D8DžN; W(-]ۜ(BêU g-TbtU\2C>-7">^MB&Ƣ_+dɺLn0UO tCE5Yy!H 8/KS-JOH1շ}ݔoBkAԊHm Q̡h; UEom_Ypk󸡵,JY ;7$+未v&R2k0Jw<݁,/_S"gXm7U:QnX֑ xJKHWbY[6ol"FɝAPH<-&Wj$,WI;6뜎 a_bmwcz32I,MNK?1:[lb!xY#;RإD9%"-E5˜zRfJQW[9ubb괁esNx%$5ޑ5P=8S&$Plt^0*MU2op}H粀!B6z֝IΟ=,WAy༆B[:1rﯱWrm (z}OH()dM=wT~k8ޤB&m%(sʕb:hK YsgU9k sR &uhS~/Vn.4|veƼh. T z{_p.;,Ӓ *f/,wf{;_EUjbQ@' SG#]GF A4ֶ;w0o;,g5nq5xH^3wA+~{RE2#k6kłO44vbЯUBRph&I!侕LMy_})8WH%ցHxo/ *<)+~Wb~IlV2J ?}ѾY(+$0eM6eT>0?x$} hT']-e-6eo_6UVz iurF5Vx7\-MyM QK=hc#i`+N{?3+iP5Vp*hρu~b: A0g"S-Z⋖|>ab qjWIԢ?D xhf$~Jow/)>^#LoUA3r'9]'X)rղ`MWm>ҍ^k"]0jO Aus }[gź!'ݜDØcShoAW ^aD-Kk74RT'"S)fjQ@hw#JW=bJ,"6C09A^֍ӂe 106. 6:[Xƃg࿙V~ h"Zs[*`UńBL;|3%Ĩtbs<ŨT k+DgJg+o'[󬵃i-uWڧINz<m]M܌rcȧPДޒ:`BkƺBSnHc>Y8V /ҏ;>&wEM_({I6'|Az->X>kjCye "UŪRB"Zl-+ڎR̦Y~cI%2n2?..5{7 0cbO<9r5_A6qTCAf/J[r Ȑg3n6!4]rlJ:te`8kN8}[\ ї*ѢEx,O͹D@'O`Lsʴ lWv5/S3;ƁW^#Vu<"M Q l,\U\V{.!E)Q 2}oFM%Loߝ[Z<8}X./ĂCo_b1Ic| uIE;M~ =UZqr5Oc<SF^\nVnܐ`NRK)2[`- ϝmţٻ2V)A_A\ *h|_`U5~GKLV-) nh7::4$˷c\.s>sz%b8_˔v]Ikg[RZE7HbTbG%h I5APl@BI2'/HgdjV}hE1|Չk'j<=u\ĭI v# `2 /U\Y`MT;K2 *Lp+J9&"QcϡG8*:!,4uq%'1kp#(K$^,C2nhW?moY`t)l3DZ1~a Bp[[B}+fg.N#ƍEv[3!OXq@"){(uv|}St]#tB=r I20^If|M 賤ǏJ{IAK|t PݱGj$iy)$"X,oMG5)0Xjon8C6aط=5QzXކVԥ x/s}7l+v ;jl8OjȊyR$vL/#n,1١sX{z.j3[lIS?meGn]p822A|bC>)U~ADNX$ČI f˵C/B+ JA蹏5 L෍e{- M-!FَJiZXDkK(>/gC(ZW(= !^usFb`Purm繯b{N*Bi__pf&blu! ]6UX,Uur 2c.Ȳ/d!~%:V{(2F*Bs+a ~[7PCP@ c6&o8znCRw>B;6 餜ksV~a2A>be[ |R$?BiT2݄o ҃Ʃ3%">rv5Sɥ vB8f#;MK|ւbngkŋ=u ŗ8w<i=Ah?#rZ)M,Yr!C/iX=;'?2HB؋V&`G<1c ll5-rQ E; +> { yLTro|A1?eoTo5 эЯgr%@uH 1 B%; .zlC2˄9+S4l4J d;=xӹkKwXl.*j~HEgsr;b kyNxg٫Hf2|΄Zkya*ڤƟ:c{D"3^ؕ_!\aUMGzL e&%݋+U zN'm!-%Z߶uV$fҟʥKgƙŗO$ZqO8*qcB Jxka饵 9tXd` ϑDR#Gvc#X$%,y V'#woZ%!ʩq"b )o +HMܖ*[&Ijb+;ڐƩU?S_F`pI#< #h|-1N`j)FF C$2A S?{'Z"ǚ?K+e_fK^H*yYsY{&6pɢJrzZuI:G"lbIRȲ#"v s*Eg~&\ W{V3Yvnq6Cr #pbcUz:]L8=$KI#%Yč}wZ^D#LWj) c~ށj֡:I }xlm|&%A^ 1.~4D)f D"Dm$0 ;ߑa7p;CP̫][|UNX'&TY,mҀ[uan]Ɵ^ڒ*DFT^`\OF_.vbdl>牙5['yRpR76 g5pRcJ7Zzaa=ί2ߑmai(TKA# ,\ 6eC vcf"a)Q5Sνe C{[2>?WJc BCZBvxGiWLt΢c8}Otp>fߣ+zmCu :i9dbEZRRQ]ыQvzv赺(Dx7>k@/UOL$'1tWM~U/)"m9+hBpղ8,T;J׏%qvA v+`^aHh8M ] с^鿴IX6<ւIczH⢄|ӥV2D1wL6b!L4WYo'wJɢt]O4ݺr9['eFl0}~+ӭ<0^${R3USUk zJEEwUK0Y֘sbGt;L`hBav[1e< )]Ni+Y(s4]lțJGA)[i}}lI65l̸EyD% /=WKJ]c1iّQ1$<*Ԁ8Bl9)ز-dL疬Jْ/ 1gUoiƏmsPң4tΥbL͠50,1XlIk@ڏd?6(O!QD0rAeYIe\22oYNu#+T*}hzec -zg썤6qJS-,7[͆Fe]ފ(f7ZA6+_\\)td3 (KjSI{g\P\[̶KP[fRo; ,{4o1ƂfR*xg0yaY_scҁuCg wB>ÆL?7gp<;$4 _\0F8 Yx@EyH 6ڄ$YWZYL`LśjJ]9/ʋUw啙lʑKFY핣nSՆԧ[ ;۰_}C9C h 3sVJi:\ НY|3cuT_Nh0e=b$[$MyyB $痪Z{۵%粿^d6ZvI !_qH7J=sQT;#--[OE2% a+KK͜.cUa8W?"ļkcd0 9Z(5ydio 1>>OR#W49dC ,0ds\J74is[{],ml횿ZmXNLe&lA *c$xBI5Fk 5H#mM}QIڊMoV$ 9{6€QސtR:P0Q/'i*uE _>Rp'Ʋq1! ^j$,6j}2nM^iCGΓ*h#_qȻ bOm:} d8EYV ?Hꔊ=UEbW2C{4XH&A ou ,(P|`mҳDdn9N :"AN oGY?2:qfZc;V m.z&V(OIIpjDIg Ck(v;;8TMZQDB* k54*g:7`>cf] -bDHx$!]/?b Tؓ/ Ys:?/~MFbFr>I :@!.wa &% y&́v@2T LG dO*\Id[[]'5"8ݷcpeC~=,|b1f/$`1 +Ht.5I~cs بiٳ7[6 BZ#wzLbI}K7=ӫ%`ed+y|ܬXgOeN켔LNBIVJ Xu[8|\.CEW!R620Z>`@o% ;Vli7hZv[5ͬFƽ-1Pۗ5X oϢޮ,!ӫj7R2YV GYiU}/v8nP=,;}U"}&yVܷO[*J~ή8CaZgbs`wU3玸֎cqi8AI ln'oyz54=d4e)hv76 We؝ڗÿF2';Wo[*+7QQEzPfkM]5_>K "CDg3Ԡog@i3=;rN%y'fw(dL \i9(qg[7E7gwz+nT1Pox!>y1J.ͽG smȪ\ʐT `^/^PS/QS,KR<0gGu(`Zb\l(]HTSCQ\H N_`ʮiOQi(WߦJHa;׏f%J6w"Iv6,fQ]@m5p0c~r6>qii@ Ӕ&UvP$!OfNmsNqVaR" WNVk*ҁq@i)+E70IOlxI37q@htf! :d`0r%JZѸ[n'Ȭ#_;}'ѿٻC$\%($~S2Bm+9Vh0w'5"d;*|qc V =u-hN~kA3I5> H. ohp+Օޕy"_3D?Y}v>L? y(ތpE&(-ՠ)MgSL~Ājj`RG"S+?MbGukJt| 􅧔Q&[;Bjm<86Bi'eg/o&sD;ؠ6+?R>~Mz"Vh*~I_ boQvf6BtYC@ByF'oIў$FZjF4 zzZQ=[ë^uZ]rE{JS57٪J&Ȗ+˴w`sst&VP 6A|}A G'*3a*#VSPkݼ1TDeIՉ…0JIJ n6V")}?-i(OT6~--~ǘd ,ۼlݩj qug\Ns_iQN">RqL U X蔬`E?Ǣɳ70;2P\m4܊U>l;P(<r)Ik2#ӫ 1#C Y661s(޺p[fK-WkD#k]$*˿\ؽX0nFuD@}pu/vrAz.udE5 SX{\UN\ڪ6؝}IA{ eĩΑ%'Cep6*+ϫzw9{+̿Lܒ/Ag0> R`ɪ :DNfEUvbPPHEGT$d;MI$v9 o*]Nm|FOON 5g5"7'C@oI.ZfH.Os/#Pﭯ&9CJ] qUjegǻ!\B;a!$`k?D ˽ `m4{ s(龭T|#J=D* M6E?=[,V>.ٷg iӚ :eS%Abl{y͝.n]' g^gϲb2[.+{*6~'֩!|{gAm0q?aHz{M'c[:-RL҆En-[;C7i#&ɨSpD*^r{/]7h$.ChkԵOߑ[q骅R)!m֧9CSe#&aF@u񿘛T AQ-Du\C̊#V)-c |tBzVיNQg)\?Ha[Rٿ4<$Vβ7QLiږa /s֋bFr$$G38=d7.Fz[P|!T>[Fy<'C5ζri- Z"8[ؔͣ/C MPOhȈÔ"Eck ۹Rde$"?eWFHa9ϛvj՚ji~Z{/aRb9ăv;M{ݙ*;2+CD]oV ^Wz2+)B{;^jb84]￙^Ui#[!~V}t=\gtwfTq 1Ӂz EEf!9|GÜB)`xHrQ3g&3_,J*l_Po"/1c=a@ }Yi<t.nmɿJUiކJdRM@,Х3-QuNIJi5ʇڃ=܅mc2Rq?1˵:!=am"oRpQ{ZMBNUD,u&E 0h&;~۟4iKxŧ7\ UfH5CT; $`߱ǵh=: ^+V+dXͽхqe ayZ+:x ;TZܸwJmѕݙLJ9&}yYwǗxD[es [ԕ7W}fbeJsͥ0;0~̣x$v(n$4j#2q]IۅEL\p_KM2Ƹ_$];g*>fG^pMHt@/yIo{wKQF1'{]SHH NўZ[c <6"~QEq{ 弄bLkmbF1zè̤j>VI@EXӭ] p,HxU~DKoI`Q?N{wU%6&]|/"?N/fT Ӽ(l[ߓٵ:]Y@R&hS/bmUڂ]w`ǽUvQrkZ ?QdK  J#ڒ]S,^bcO!0ta5+︍wn`,2cݬgfO3lVJ T=vJ/>T$!w G);˻:b]a\ց )3thV>2 a!+w앆EE}rΔH][`Eo%v'ar*D? .~LD6e:+c.m>m p;i\jM)_݈`3a6vwB7rBT ר_e'@&N8Tc&h,`|m ^Q6z`lŢJ!\ F!5tߙ>f& .vyή36SrtYV-zKɷ[bNTOB&=:J$c&ۤCU&hwa~r~zOa|UINxQ#_ k k;EW(݌KYT\zCs. /O^dI\{upjqL9Pjm8 OfEQg,D@1Y;ᙫ?of{ID(eI8+ZOl_Q `cu >"QôT)s= ce0 o2SʕCE KHCʶdѦs a@J M$Ompk!WiN_!Ρ%R (^SPu0'0Y9P;+XAЙ^[{NӦUM%is{ti`Eƴ"ȻH&!@[ B¿ ԯg&1VvR>ɠKMzc<^11K0d7D)'Sz/P\ 0O5\x4!Ym6B}\N.kg2Fy;.Er-2杖 }ʯJh9I@J<b ?~}xi(69CWB~i&<21}ǐKpչV_ bg=_r&"n#I@N4 MpX[l9K^}2F'{w6ߖ^l@4[El ڦ⌇g|rP@£՘UW5 zY)HuA1dJ#3k=C^SUX^{Z}|.wuMnӁ+/v˶ŹlE/^U`YnJ8~5ڃ,zB_/}Oo|bAX4DV%dQ{\|l];A3;3pw4DID)FP" Jo5d#V3߁n"9,L!ps.l3)U逋O~)a^Ms77RE?m#~x=(5q"Е¾ s!^J͋_=a/C~N|xn0 MۿlAH[5Dڛ&\0A]H0ڄ3OOf*!p_ж׈ǜrZW+իQ E0 hK,D&c1zE W"UFn4͍FS胻qߝؾbCqe_HG-2@l+CMEY9wu )ebB=K8,Ph6JrjRBu z0_v1WO7AXbi@wɨXyܴczf7"0Lj`H i;銅M_ܔY5*ɼ昈,n=p] 3[2Xk×Z z; D.M+A AMئlJ.˟vyjy75oWG>q䃨Q3ܠѲEqnUBđ.H.Zc"vC[nz LmhK0~h5,+-,U$>v~dc& tlv(uLt h1Qӈae| PM Kw7W!}Gphe</18PḯUT۫>MQѼ>h&m(=Lt~є"\]J֦uĒSq؎s0YU6-/+֠ܨG!?Tn1)٫HghGM JeNbhHĖx=ZJ^vWiplcr l@[ 9[2R)~辪T@9byk3ăj9`/hY,-֔v.\3O3Bn"ul+ `MVW[G.;e1Fѯo7w&Eeݹ.8h31ῚVlFb͏k4q 8fG?@ri<|K/nB92lUoK͖ai&[1{tQx_gq {bs'2e"դԹ~䗔eR3'+(!STum3ñ`<7]+ǀb# Z~B{֣@<.WM<~.*3]jP+8TʭGF喞(ewۈȪ|a5ǻ\ W%?C`c|>?'4oQi "_4EJpQȟS'kL-z'ȍҖ xK 6*fdxm|M6/\j_ډndc#h09)s`\M9k~%6.&}+,o%Pli/TA6=`GR1a V=ڋ90#LpyѸC@Ϭ1twz#}p;;9Ng >A$|x3Xu̪q=eqS!%4nvF"u sR2woC^lr(u|Jr(B+MШ!{V״疓Km`1|⋩`NK]͓}Iةx #.-Uz⬠1qdwWram@Lm.Re4nnr,FAJW7oIJ|(٫@rQ0cKWT-&:μm-#JC bnEVK )𲍄u'yO>fJk H.8WD=G Ͱ7}A]Bb&l+JJM&dG)o(f҆WhZYR0* L]*f1K+|;/d ɪք$%N"g˵1M!9(8{9?"Y*;zzK Sߟ3w(SP03\nzUP YN_{(l-sߥF5.Al.PCa3K8l_KZu+Y_ NYI?+kAf4D~>Mbۮ72z4&F/N U ɓO{ڽ),-X )&a@QcŘIdhc s.6"En0>޿8gZ-w9GU'mq1m^96F z`d^4_.myV2^a牶m}(w&]sIXl /#ײ+?tRE!9O" 4[H0Thڽ|Rg\ko)0җvkZ}'~Dl?* WtW%sI"暬14uIS:454+۱c_fVI|o|^4""PM0i3]UzD6ޔ}2N o訏فS%lj[LФmQ79z@yW·?=;Ĺtcؙ+"MxQ]oY!a8eK9y%\"=l#Wd,+=$_2QE]bY0L{+T'VZFtgLO`gtЎihѻJKE~ @DK2 Clw˹1n#^S*BKheKOrl Q#8%`Mχrv8c)<̈V Wh&7qԗHVvtd|Xٴ߆_C$q3 ^6LLf:4&SlVMȦ ?] f3KCr6_p'ԢRVu5,ʐFC4973;oB\@dY?CKcOE@RrAmpXX8 ܃LYE"' hI%290W̎ #˽~:UpwaHDHȖ'r4$Ñ΅̅5TUPrC4]Y[g~O=`a_^}l3*B3T迒%Cưors?g޵fD@=_x4iTevRs6De9 ]\=qT!k_!"5z$޺CU9f8S]%/UpAd׃^۸;_n˃i$4S⧇K-lnTO#T?<ߦTe TNh{Ql&9y2/N9i VI1E[Eٙzюa i,Fs߰"-}>| VW!7\!~JUUb?q6S`@''gO=%r|gU_HtWEH&µ X] ̂g1؉&)9m˝Dyp wF>#q`B?n>0.׀cIfI.hQȽ#>͢I~ vȭXrs F |B@|`~CEqAyv7D@%Z{i6R;"&9Sd8yw$ Ct ^H㪱ho-,w8L<O*i9Jq{'Nl=JjꆳXh?覛F Q6+*^×( m6,&7$龕ڐkYqPϼO3KGOhmRjPP t #aPg7z DCZ K{'ůueY2.gN ϑox8XqJ5O9N׽cSP+'#iM|7"&S9okMh=Lg?MC;5^#1ըN-(zU <8sq1ۄTeoR4Jf@ڳw8c.[4$ݻa'}gb (ubLpkz_RWJ\7#v!>,uS%rUOjA*<2WhGQ0Ԉ$rNU!~ҤDrduVLcz3~];M7lT֙2@O5+{vۚ 4@= $ X[9u*" 'PR =ҸtƘ\J$w.0nPfa, m>pD ho\]m6+U?ŞHgu7 |Yͯ6n+ AR^%@&,I_\ߡ@*3%wrчw%=ܭPc;///N/\$MF-i^a-&虵ASv%j4Bt.F7hL)/Z wŽtN/ @݆Ro]Xtrlo ލr 2sǿ%6<>l$DL`|]Cg<짿 z loM#]|T,¢PyϨ8cn \]t%T7o!04DBDz jMђQwT P &!SHhZ̞xYLðYL3+ VZug @]J[ Fyc_s|:zkyAzפ,mB[p7dsK+xWyHA+ga-p4-tؙC0hyp£}Ca ڐmvtFN('BCq\+ "=!+}-׆LpD}ƪ0~El؝$'20\){n''`IGprK4:aAr tBDdK:!&_3Fd|dq?`Ϋ1=zwk$:vsVoDOn)60rhOXQtMsD5OE!M!kN!?ق-(eB9W&̷w7Q܈4 5LN%K`iԳސb~I0ޥ!kwMxg 0"ssFh#RgW ,CITA͆AOہ[t59`´CGc/Ai(OC0NA"OՐD>2OZqAøjqT~W &;Qev#먛C\ePCT2cf<]c!X-}urgdx mgߢJ_mq@n4~//xYt*aӝ4ߒ^D =X P;d=f0>;}n|o&NDpyNeco%%MT#WeT7rr䎆,bwgjl8P(4ze;ܙm T3$Y+yH䍣)AIBAG FJnռx]_49Iꋠ8Tجr vѱqKښ͇w`)=jF0x]xag$6 \vWsZv^Ub p/@TN(J-e) QTRd>)uf[d+}0E@F<f^xjaUm|$"Oaj ǔ^xc\W&3v0ߕ7*AV`g]y dW%N]:kz]RxaEABRa'Z5«<:`{]ḳTO: 36y'oE.̎gwN<xcp['-s ;$&0uUU0D_`*$t<}Mvb/198 (83kjԥ ] /w,iY /a[ZAK&\|I7ɥe´\!KWDw*&t}Xxd:1 G]fuTJE}T7J }?;Hvl^:BJLn{0NDK"=2-9)c7!`)$F w.^,=J@OKnMeRO3ɤ QaOGw3 r1 {Wo٪޻P=u..+m f3N~T,P94(}"`n6+Mi,tpC=/A*8k()O Nubv8 {rykp񡎾S&+tm,F -5AUgi$D)HR9~qqX6V}q=Nh1N%̻NBqJEھ3]TʍuhP]#y$N4ԩj^w?+­w=.#fSBŔH T,oI7]݂[Q-HI0f.Y1J0pg^ڶec`Nzi,*`1Yy'@4*YF"v Ƹ&cقվjiG"kh'OW? 1S\/])V}vV~wqn8\rl>PIYXӄ=ng:kGk] }chLkEߖ4\O :B bKʅwKr#o^fWEaڭPIᛚEY[0fG-=Ώ-59HǀZ|<Q"#U5)Y􊡭9u W[[] Xp[Oz;X)fZRvfs jތV'RPj 2PEkVI4P@=hRanNM=IkM#䉬|ƞ]2iܿԥF| &DQe].=`tl`̓xoRlW5^[nnmr|,yj ʧـ]4ܶR:SuNaKp{ki#]p}ǭuW|.E鷺RD=׭fҩ 1X&"Xb/'1p<{!5k 'ܿ#æj?/ !9,|{$i Qf F\1wm.`у*n Lme1DqV.ؼ9VE,=77B \;&ڂ=z|nƣk΍30ŗm Sx; 괛46Dns;ё$8sciBB)I~Obb80j$7]֩DMЀk>\:vE4˹2bjﺑ/K; aChI~}u*c`_hlџ͑6 ʁ%v5l@ c&]2-#م'2PRBwWp!Ox"N:ՙfؘYOZM!$+Pru+@~7E-@)5꬈b )+dfUiv.@[*^ M~|8BO$UdPBcF_~l9.A"?O=V٧p&?@0jTgƊO%)Yl.RrAǓ~ kwgmwuM%rґv3'Wf]i]3|8ŌŚ Qhc|H8kb| ;xtdqs—)e>W}|odd࢞6cy ]//̫r1YlnJ?,G~T DE%9)yD2R'1$o[@bJ6>)1N&0g9ܵ; K7hk(E֡Xs8SʣTד;]#aޓlԶĤ d::ec획A g\^ ŰRä+; ./^6#~Sx3XZϟWc ?Rlid\X[tlDѩr8 ȼј hC af̉Sh}\jٌoG9r p:M'<]E+aTƊK,xWOnКVE v}1xQ 5.Jh+qTd[q"o>& i/ \2_8VQ`ks QM =LiP1è#7 ԲI\*ESx?'+o*L8dpR ;9!?qvsm$jXIdy ?\yc?chٛ5!m&KЈ!wvAFQ2Wc<4A @8<[vN;j} e8]`xt( ˦n$]oFx IXRa]oi(=/Ѥl7:b2=u Nڰ% ] Hٚ2އim!a@aa} wTKg~nt ɑoj>jQW1`ǤIZ>"!8適2ӫc?Ef;/QP /E<+GkrS"Ih[ͅcvjIO>8J F$<.}OiV: B9!t?D eєĝWf909|FBf{1(Ykd! ڡ(.Sm?X}װf"9>˫O6Mެk 5m+k^)ϗ7]cxU"ivFMݴڶS D1fbrWlj \Y:P?a Te +5T ZwdY/a4$2UqXI0L9c3/mA ,eK';ZҋFu2j Hhnb5wriwR&{"c%EUcFC/w$ž^?}ibQme1jz|DMF\ R ^=ҏujf7geLr#3qI ˸q%T;&T#MP- *{/SS]v,cy@,)k! lC_иѦB@̉V)W_ %O9=>'ows./'SDe#,2/wwK"'AŭeAVI֑l* ָ)r-ǍpUb)蟯 WvºH~t#Hu!)VzYB<_a1HR1F€ 6?a!:bD`d? D :t͓ @7чhX QFc:;|*ƘZ#v>Lzb#|xcty~T?ɮx[vڦF3>rqn-tIYUD9%7OF lh̠N/fЧ=,YO0[[n?aȺ} wHK5n+Tk澸q6''-v4Sx~7|Ap.v]^,0Eܖ1*.\:Ѷ4$:ߖCC92̝? &z,\֣%X=(UpY\=Km6b+җdRuY.ZF˚}=WrMNf>sh'F*8ɍY7|mwE[X1Y(8K.t !{GA6ͭ3X Cُk8)\8,]4/1":.әcM:0#(OfH}d(AO~S,>YP&p+)L\g|m[5Jd+;&)'wP]XmC`8'5\5)R3%'5x0)+j46`宑 Sx[5zP2~ݹU d 3|UEH6|ꪉ0vϾ Gxcղ{^ w@9kd(Q0: ȹC5 2-˺^|w_1El$X|\%ϟ;%iY~kC/oR< p:rM Vwċ:7yLeOQkթ#_WV4b_E6o=_3 1C4Ԅ][[:p|͌+4;2g1Vly_:^[;^Zm!qwI7'h2j)f.јa{},21Eʮj&m~)߈b i_@]{+94 )(1qOJ*''EmՏ)q#ȅ? hy :IqAst˶ }fDR7;ΰ7hRS6≃ G fwp\$:BH]ԓfE,^'1xS$ڻ`AȋuVxuqo MI[B8%Q$Z)3-F7\23WEڝoʔ+ɶUxhiY?6kLpC[toJQ뼜NaL,ca$ZTPfh8]?ždD5A|,d;}ZjY"bCD˫0 x>`~R6d: |Y!;k(_H~[0s^֭CpHx W$hG/ 3t 1{DW&uFf ђZTTEMz*Hߟ++ltA?匹 V䕝5=GA 0BKڃx)>2~e0`ULOj]0_eip#ޚl*=lQO'49`;{J :Yh =5k97}nH\OkM!3&Rv?Ԩ&U_(mTڤ@!|7υ%1%4Xd!ășm+{ʣ@CYb{3l5vi%VX oM 6(he: {,w UQ ^hd ېH|^ǧ~Ht񃈰,`ȺƟvP(F$X"_RWg0 {C'XLi fam- lqQnK@3;jec`οP[{et2e sO)%dmsr'GlwTypOLk@]d F>2%MËͅMo/:3+^fo 혪xsؔ-7 k K=cx1kє^ZtL@#%F˪+] Pz8j55ַɫ)/-i|%Zi rIẊ2G1]nJ'lsrzTEx2+7G},BS#GrR/*?뢬߳45Yn91i#Tjt I}lR~Me֟n Ad#%>⿬QSȇK?PA_*[3(N?ah\k2/ #v;IUc5IalS,[W՗*`a  0hBdkKbx~Bкp%W\+_J=; MDxnjQ ׈ƙ9)7!+ʇ2Lq噭ͺ g{cVȝf DuJSulX @}_ e+Mi>8ZCO>bE$nSHǣpQ/ple&P6فn_#q"o'9WmHU|ZqF 2f3DI~]GSgo+Ҧ v ބP2ΰH&r)VaSJ w/5QB6~s"}4;S Ug>SgJ,Uv9 R?G[^WW<#{&{!͙E̮c3W@ H.ZSLNW0e `Y_(3/>.BK cUиڼȩ{->QUĉ*`ڑP>Hz|UCԭҽwF+HF+C*R_RqZWH.tmHR+ t Sqݏ8ihѷ?^L'2赊,օ,x8t %;&z.~,u.r:7vB:rtI(֕5]ۦݏV̾(NUsdL(tJ @vQӆ}bp@P`V`LLl2?Y7IBGeiEMүzG6AlH;p(2eG1;Y?bpbhhJOvz@̐J zGjYkoh1eJhXio`l 7̧|fn FSf!Y㣰r94[bg80A`EbV8PVj6noF)^;*-UlЁCbe.ym1k]-HBo'-,+b%e u+iUnH#' TMK0OE;:~+ /#yyq띁|\r, iUR:?o {kLPiqǻc2Uf 5ZZ H" ^XH}i,, 1Vn&VKK^(2+]jq8:$`xUKjȩlewZ5W}~7r}ϳ"xrT-:Wa:ٳN&K!B "?=abtR'\s!7%m=EMW5"Em!!/D- "q<?@/ %?c m2&Ma#Egm]=@ @ahc'q_ j+"^#<]=:ɐcQxqlgU SYٯ@7'obM|vuT+؋41C_rl ( ѓr"ɺ1&7Ҋ'c~\\djr@woUMn\!~3&n!^tD>KF̄dGqJeZSJCM){2~FD {X}w>7a\GU.аϽWZrdWMN)dnO) QG|GV;1N+CSx:U&JP'\ER!߅(y cژQ&lA?V7LNӾS;Ky30ih51a6ͱ};`rzLwdﰮFך@O7Dz7x>J?:51W* )kš m6 :r0r3t=a5D1l"RJNⁱ4\b݋C 84I~=6їtcB}u )Xm #M/XH.X,&~;m-JΡ"''[{ K | 0Y޳}liRhN$vk79vh:OF@|trM+:yQ+`kޱv^׬N5gosˋ}x !.G ?e5zhq5e'̽7{<~`n* "+$ޒhNVuu͂r 4{U>T7zc%+HFJO8V:N !+v%2JfMzܓi_ܣˉu$..;b'Ķ0̹K^4kA<܌W/"B%#oy+# C E3TmB83;V+w{u(f ˹ϟh1湺ą2:`,ZwnLBe`/Leű{b-nbj6^qP;OB`6,d \OFQ"(i#rN~<BR8)i9 .4 V"8|= ܤ[\NI'=9WkҀ~prjWr˷]!50R$ f*ᬻ:2wS,#1N6avfP`;C@:2P|8m'3 j O , CUc O/[FS. ;,Uɫ9 㛖Mt29*n\"|Fw.=4(bbO筴4@ñGn:}4M}VZ]B`pЎ 팕n ˎ$PNcZ-$ 'hK %(8w$zW݀so] N@tЦ UHؗ*b] aE"*6z&upA:b eZm#1Cy(ot?ᨥ:_K}}%$#2 c@:>X3{)=^NH2 46E䙂>@hRo\ ri'^^nbOCvE=q1XI:Z.jb:wcPLIѪզ VrY^ѸLlʼn?a0gDR0VLCa(!$O|6p82Y$t@tuC> #U9a0p|6O|춊vԓN`! ŐZAw Н 6uUb6zijLʦ*۫aؠC喖 u0+'?Bm L͏JC$Póv&k6'PFZe*H3۬-JTZAHRJڮpXlFM{/EZǚ:UkJ.4뭷YeΖE0^y|QKrRE0<gUD 4ruSgRlքGBS> ķH&2(^=KSgѥVwX `Pk,'.F]\*óbhB#BS%nYCM$,]7r0SZd\uC49OiP9* w" 9UŬ1__ 1hѳ XT'SA}RiweH/1-*;' f}(yID ռZ>-.X#Kk.co{p]{? e`̅xUVƴ%6fMkw7QrMc֭A9a]`. =ՅNpn1t+r‹Q0J3!/kgڝ32fԤ|2&l:?gTB5cI+d =1^&r[{L #tPR8;5 1)5|!\^B7z$pT}0s~K`'uhrw6}UD68xlRO)RC&`Ť.65x*pS#yӺo0,Fx)ù%< p紃EW5z@] Ҕ0RF͸;)*nq" O' jDXj.WT: :yT3;vAwBl7+P -(ԮE'os_?aD3dߟ(v9V~u$8iN# Fu MGE;Q|!깡á1W<U_ h8`IY,@{ .jl#F3=,-d**L$߈cvKӾ|x ќ_]*G'vօQgCҺ"PjGl Ji@B+܀u3a Yp$cqH WhRD˙*ׂV@Zs\dOi#^FoHzַsF)쫴2BfLHchpr-@ӎSX/n cµxDK "/-50/5U*_vǞ4;xF㫼jF &'ฯ'WDŽ䋚ccD gQ C"ʄ 7iOL;. UpPkGJpz\zGM#<#\$"]0JXs?\xg’2ӭSMR4_]&=_ ohq9w̗v9JF%S%W2F1Y# ǞhoŋnXJ~- q%-,djR\rYcE-.TX+*>Ip;^*Ä'X{"K[磖+@=/;RA2sM?f'"@F?M;`Ր1L=3ZwZU)2|tLP~XkH"3@iT=MV}FJ6X|8]S"'=MhdXrd5KR+"K^a=Nʌ _?pX&Wno )Uwg`R!Z-#՝dTR^ >1`1i=yuǓLw"N*4ɫJ|:I'N?o*^%C. ǻ:ѭ'{[ٯ׬Ca7j61>M/ ZhIK#3uTC/ R-9y`Zny['^o6(=[F{od ^]MKIЭ6zTQEU?o7!&MXf#m|u=e) OW݊вƂ{߃F_M[:s$5E:I|Wԝ.3 u:Xf9 @xX\fdzYЯE9ߤ\3xEv]1++8~$ 6nH i5]YF1VG!nQ^q#4νwos\9m>Q6u7\+preJ#Ysxx)R3 }dZoDt^nQEi=lF\6R/+mLzE]]|q*g\6֦hdIIYuy\d YlDL!߄]VLc3k ,9i`]xP`T]nr}\X=sH~z J [}3l{3L:چKc3R!z]nV9نCQ?$ayrf XC 6Az`xU!wUpz+4PRJ؂8'ƿ7qb bt\]@(Ie[]tBMɁ_ɿzIv䪪%}2|$@DjPf@4%Ƣrʖ!d}9Zc;ȅ7,kC1Aex.">/%jQ۶V#Z;FG}$>mIZha{gC25:6**xËGirtj{'`Q ]t0ߥ\7{"@ȶYjvqLnPǢ'G۵0LFF⯎,yJA)4pD tOwiNh!a]䥈&vՏ[_Ae} l6rd_T2Ql=p>jݕf5jrx1 Vjv`6sw>x 1ޑ{U.~GiFrjrΓP5 §aF뷳_a;pYY+ESz^#nPZE!X3?//.c*V6" 0,In ٺ [YK,?&K67WFe4z~,V2^"[=0 lį|js vzt#VE*%ڤJ؛>ȟڝQrFLl"bõnO~MY.yէs-i;|?17843cLiuФz v7RtlYڭ=DPe4K:Vm%XA4e/?j0pm:@S9x2XSdgaŷa 'd>BݵJƛ`RB adU\P] wl$ޢ(a91 >tDےXHizv98+D-כ(?ǮWБ=;m;@=1Ftx^j#nFGTl5K J.b0#+{ ; ~u6BfӾO@.[EZ6 VF =ɼBZJ~;Tu:@[8 O,<|3U _c4*dl“@;rFX/FE-W+j7JAMtgO/#sk<:lHBLcp7,\Y<䯢K+^2áKLJW,oD>]`ƎsuϞF4dN91 y}Y/aXLnbh;+p)H-C}8= "ZqC!<|(eۍeUd[&# \\e. ''5Ygh:puFĤ]Gye+71niվ7S_Ot/FgNlm`<#۷ϣp>q0ۛqsb35 hS{ڙGKœDlϱwI]75Lތ;﷙O0̀|icL\H@b׳%&'iqusH@ :$ Z{L4H?4/u]$\!)Qr'eK}~3䎝Í75#dF? eZM +`)<85dz8#}W1O~#kʬ !w;yVsa|yB /N%P<RWwn%l,PT6C;0%t.b9Xtk;7tт(nZ1\COVt3slweS҈0gZ^%`=!wǗFĵ5]3%H)L/*>̾ɠu.-Ѣ{%*PBw6Mk^V,'kSVBM˔r׫ք,Fh zaj˷&f;.ЅrR-%ueY WObaPh0Ϗ]OHۈ˱jo23儐 W7;=s'Y:%O"A>Y7UDuM"Z(dƖWgJiem˪ߙ]yq;+^eÎM-rXzʩ+]gk}@ Cgb\.rl_-'`~Bؘ0 )Lov ;e]~r'Hɸ^DTpc}UHGE ϋܛy7Ii&X-rwwZQP~~Jߤy8*_fu(oPVe[Z_ -z[e,zNob5*=D|pCq c{Jz9_ L-] ԇס0b~vT$m4*C72+/}-x!@bSTTMB%zHr7i؏o߬$!Y˶2Z ut>(¹Ĝ%4v3"'Ye)sINnȍbuq~LEW=ѡf`6" ,% m $YJ 4N ^cnA#g!Wrᛥ0bf~)"JfB+};hnf JL;~FZ$Snqጐ]5$Ӟ[%ȏogN'oӴ#=fmyV7`!&2xtټOֺ :05.fř( Sx=V)A~m׍pj1}P9 y,-v CߛrΚ`^ۊB.DաDiU@}Dp4:;ͮ4F_ݲ5+d>B ꕪs領Ø(޽_e1'M$=aSD [=&O?CԳraM&1coП|ZiPT$,W餥frvUоwӽw]!(˝_$cwU⥞?%a(5SJ;l;wi ٵ.ҁJVcwjJR;-߮yÿ~@lb߳&WRl` D|QROof&9G)zKwM*ޞiln_`fP$ U&t6K<|@7-Sol5)/2C+0>vntS$cA WaT/Gf~5*ΔۈDq D,xgiяi$A4鄕=B[c)CVçie༯5a9`C ^k@ͮ?ٴ9 a>?/8<^̤}&H=9'74."K$S<8wH@<ڰM?O$l/U GRHVs18dIЯ݁};(>)=}~;' UD<d5X^K+%HQ{(ޛ_TIÏ|),uQQǑhcۀrbCo#ƣ.p4K Z5 ʪ:_#=-8Û6ll^BASuq?[j񔪴$e)"uMZ㔻&T#U7))0s5}(AYс$xGEDaヤ|`u#+ID*5-ُbCI2*\|yKYYCuC M?b>4+FhҦ~zo~XpÈ fw_F||TH Τ.Ɨ:Th9!'.=QCUcˎMY*׎aF:Pw育O(Kuty]'=wo;Fk%EYE;,r-aƊbFz btރ@A$& { pX0HM/ui*ܟ.eB7y|"^ MV C~3pxkeB>O`2< /+Ð^v6:~;j)7_*voLaB/8i腴i` 1eZZ CN!gu%,㠐V+BxQZ-.~2YרC<'Vihf/5yO!RX e%ߐԗyxpH^hBhY(\WE 8U2q{HXU|J=k??y neVC9b}p\L{+kB|,Äo¨-Qv _c:ݺ44LDOCbu 0;-ߩڽ8AWރrc!pVO7 p@UI-#$ې9/C-uXKL'7 윭{X몹c@O }PCzaMk}J*Q4O>p1_\գIkMo=?1&W# g_ꂢPB2#o[@WCy6g>[bvNGah}])o~0Z}FGLok"˷Ko~/mp;u,k wj~D`2{BesIY2A,wŲb$w409d X٩CnI'e`@ o#4KKņɃzoTnsp 5:WOX@"o([boGrHXX3phz_^Ԫ6!yK7tDy&G`ܑ[;4BibG+BWU]`|.⬏.$ B+ (W@|9zh9epu1hjya* zz?1= M|@k&Ն)ޗ va  jD'^!RCyN-,isc{v5<'F>K[}KM/y>~tmE9[G֝EV*li-+Ln_Oi1'XdO]dHTŬ͔La$!$ ΓZo( "6I0^*r OW maΖ֎{dܬ|0hd^\x.qAxeˊMT0g\E'P&j*FP=0'kƍADŽ6^etAyεv8[Q1UOW,P "5c؊yMt 2N`HhB_%u~Ȟyb LTDVרI\H": $آGN #v9z҂ZH_-AKfrp!-0c=xޏ]e:kTn#:;0~yR GO`PTm$}zc 1~rpiXXDNGò<5`4{ l!_8 *tit;b57 uϩ=ix;\p+VJ'Sip;J[w 5s*LP}Nmq* 6=3xCaQ%viu VR~p4(Q,`~ DlB Y/lJ/e3aV-I00ܦ=AJC͂ηkX-( ƟIok/7wIZϲЅb4J/ ݣp/0P6[sXâ$H5.Pi}_f{.wz("$[[zÜ {B=p' ۘ^ I&5H?EV"gRK6;U7pԦinIcޫl_}Fŋm\ZKC-d 01_&Z]@K'1/U":z U,m|Q "Qpi"Ars#Vb70I%Sd!E^z%ddbW/Qyq56?BJZ ,HB$o-/RoHgW|oA)I /Q/۵|pPXj35*~sGΰrgO#'tj8۽\LBDؐrh& i'V_VaMA,цK2ՏVbnF>dݴ ^2˃\=uP'Q^b5&8cX'm?WQ:kRVɱzl,6dKAJtŐחdCn5Ԥ,!۲!ǏT2DW-B߰-(^Yp7]h $R\߮Mu-[T{WA'[?l]!5wt$-eq-] ӘU( U2$,651KM'w!8SgvF Ip(Q}1;XpIN>D_r5aw4~<@dƯ'ƪh8sØ~wNgZ:^$jLLj .6^´4 09L6*$MV*AK0/>G6pvd"8 p0: 2'eDZLsaFU 25baTs\,ZV`-_G*7u[SX6P\^iIVrp^JDczc(M|S:ay 7)MUS<[s&-{(L0fz r@t2 +< fN]KVj0D=yz^p@C;έ|Hil{ԺTUFM/JlNMi =oj'?NJ_4D- YRse ;NH6g:_/ E:HK_&VZ!.O<6Իf4̞ޯnr|oض~Ы[g!q"!7AoOe,oJ$=28z.iX/D$<~B94gZ7jX>_A˫mRp F CaM?͔xSYQ:7A;rP 1$- \"i^d>kN_Ž6+$Z8A-{/Cl3PD kt<\ =k bx"%b&Du>1vlY7Gj4u#Mm\HSge^iD@p( Gzjރ9J* `Dc=ZXuyYՏTn) [575Gok5/AR29(pQ[?C]TqYd0rV~;K"4 Mӌv >u^-Tԁ@$u,TU%|$P2)]vPc W`]#9fxՍ C:t1BI>U4 Th>26d?Z?5a`o|F-HzYM /8N50HS3 n칁EVP K:@R; tV,-?ܭ4dja 4 jaVr^"$# Z(oXTkyg1&uniҔn2 rz$葄\ jg@W \EL~~;yz}~9ggwzss|ЍF:Ȧ426+w /&P8">-q8Ч3hqnP }]pW,tx2^[Sv ,H}B~ֳ'] xตca#XTAFbOc7mˀFIXD!}"c{`:,#;WO=%ǻQ5?|ۓs؟EbC7rFzN?\uFX/-Q5ȩM00-JkmUJh65k`tm8&.fdC>`N :X*\RS=)lE[K-\ ^0A#s.#۠Y17]涎wXW܍siX$%E +^̸R@0-8[mBk㺙(ɵl1E9lI!#2< 5[J9k,a?_(_ p 8#>V1m.~bs¤j6gGL1g#2HZSTF6~kԁhi tL\es&;'sM,[:4yڽ~t>$CBVL\q XkFrDk LK]ԃ #0L[_ x *T^eٹJyQrku( dnfL L=aI.+TrX7,,1S"(>3,͍jwВHs{Y6y\0gGC%mҚ+XD;VYyDo;R}-J6SQ7lr*uU 5p @-x< 77^yP78ۦv2Y=ɂM4 4KV}&>oCc7!Vzڌv8JtjitO|0"hN"TxM-+~uy/Yd&{릾|b>Zw-  k,-oh?* اpnnhnvu .TMEZ4YpBS뫦bLgh%r44/ ɓ~pv_ jս( H)Jpwyio64Ύ!`60 nףftߔL TT/\7=0P.uiaa<|a_@ ԉr8T#gsM< 6o!9℔tdF%Fǁo#P;[(m؄VЕ-Gr;1N]@'e(tԎ ܃/Y*<%8ŒecuMzͻpC}-BEa c%zE A:+=$NX񶘝<0nB:dD2ϛe/;#$Lƣ)Љ|ǔwH03I. S˙ >~EAȢAR{IS Z}%kOaߎOs$bba ^J$`+ 4<,0--G=^K^aXct SFfx=J ,i.ڷSIyF d.B7bd3HF?)S**uHRe+aH#RFZoIf}k66 ְԤ(է:u7yRظYea7X&cy15.dQJ\IONnN/EBn=gHMC{n17_+j d׉TsoŤnPeg~b?7$X.;NE`\f&0uo_|kk59WֲòkᑔOl˶ՈYO 04yzYJ8%$/3/?uZݖNJ0ݳFVk}!Њ@rPRKF@%I<I+0~3፷d:)z;eyYHOK xJӪ"̺9Q~n}cnZpbרkNnꅶbHG3LOޯ"hy"Qh?J)rEM H@xw_\*_IӵpPa̎<~n,*цg~y Tg4eS:mnaۥI=K˻Ǵ?Rҵv- s5f"=O#7%a"q|`9Ҿ%eQ`Svaڴ#VгXXTƋyXunIoM'h} Da?lѽs!Ѭiyq -^}̃zZl[ ګBw?$Cx䝘Ϧ4~ro FY{!] 0j"\|.@9c5_Tu-I)]]܈f&F b".[:@=M}[eVhk@4Cs?X -0ݨ`ے^L^{V]^Dm 'p"?Tp(y~DR sͭ\_\0Y~,yD8K[oE8И?$#œo{c-GЪJN@6oYW—Vw>/MŨCQ0;Rzvɤ񽟧na HLʖM.F -fPf"ltya邛;"f.26SkYk qemttId5'P_8R#pO d?8V6(ܮ/}z͖Ƣ^gO ]l0iߢRȒz&9>`8gUN'k@T !K!u {)٩3svV]yIR {HQ_ElDEEו{ Bh2da/+ֶ 5(9s?&r(a~2#DjX<AWモ$<} M0|Toqk̭;Ȍ1^-n P^(oF`,I02wmI,_D{o\J$'#ĒhdFWSvY2$x59-K.Et e&;Hإ׸(u+FD\s,8 m\_n\&q Yg򎷠Ahr)-cBx|"J' o0LX'N)7$\언ܝ֢Z|'WWav$..HHȷbJDLvgFkPLBLXSEKu<>F 39V3f540 SJ?Q]rB3 bcʥ[{ƮyS uv`snW\W4kK/L7mb0ᄸ]}`3`s?'8X]G:m(9A1]%]%x{ͧgFr2/НnK'{ZjuoQa U{*9R{c}P>CRM;}JRr~ktG^-^}J-q(%:Oog4<7^x~g"ڃ5y4C[lҞpyZ*im蓆l*Jҥ $?ٷzHQґgY2OspBZY~22baw!:\֓cϬ9P2]J\!kW-+c6J?",/~u^aT 6HLT>2I0u ΆooR8)gi(កSTT5wG 6~^!ƹQZ$)K9=foJHƯ]q TX\k٠ܺ]M1 (E dM]ОNP~/#/{9| M:~4:ˡrDp+ub'+^j*{.vXK|N Z࡬q Z604W:_R*!?[[~FjRvh&BFN!̘C8 oöY ܲh"/i<7Tb-HfC55`46l49j(Ed9~;_ۉv=d҂|DF' {P6KaxzX}̄EH:&:(F*bθy}Fo.è.)BOYel⣖Y|G]{Q %Τd)ybvp8zNՄ.qӧF(=2(cŴt˕(c3TQ6`G*. IXmR?mHPWD(Rʇ>ȃf'Jɺ60S7ZU{% %[,r]܁S$%*v׾]朡zWwwr#<c$Zy|UIҘ]G\| e鄍j@T]뇚]uU}8T!G[hw܅ 1l(O[؟gz̩ Sh4'z^9u34ш)732EӴlm6MUˮ@)qC<7z4I]?M ; h^2.i5f:[cdtjJ_#J] ^[%9ۻA (Q;Ϳ6w)k2d܍N$Fj57W:#//jB7~ښ9dזR/3D@i{vH(.c/ Oxw{E?l sqߦeQ&;|ȶנCߋyd.N!$}4j, {>7f5"TJ~#7i]<z03})&4r 0M]x_vDcHY=y_8e E_T]IvǞ#d/%#eg].B$x"w,7|ȩK·ٺ!38?Cz^95 }016f`1zq5/JR>(6?q5V&+6l)> =16 ;Fh-Qgkw5,j\bPQWJl}.$+p[pNa#a# u2Z9Va>8"S@QByw(@ g.a )wXT 7 z`Ȋĸ bؐD0Ƿ'/%s|zi}y`9KZ/"gm![v ˢΓ5tumuE֗&7$H0x = ^3U7܄~ӌTU-jV�IsRiG:0³j?.J!i9L( Ӡ Z)n ڥҡץ|cXqU)qPmVz Gq|MgYEk(TT|L~ R=OE/wL]q}TQb&Ͻ P]"7|PtYGz/l5r:a-ZL7ic/XɅܤz~th Ci  SD_sY&7x %,/gGL1扷p%J!x*n=$|yR=[x| "=/oW#q;}S#0bWeаu'Tܤ[KC.ax -%^1UsudԆ/H9X}x;+ bjLC<_"r4ʬy+!8{ 9d3wu뮲5mRf)xwf<5S:O@ 4<,X# X%*6䠚9gkm *TJ۾Uh8S(r<5F #6?eU"jdHǿnH5<0ՊaA]< BZnzq9lawe7-xNgWP~/Ôtm#,ɟ`,A}l-XJ\)6ZP:F,GFRb|2+*ep =HO͝W"۹C|&lj4Lc7(Vfy`ot xGΕm^CmA#3 ռi͎\ [|8zQ^.M),=g} 2_cU%P!j;hZ%IdJ<}Nu2Xq>`&hU#;,v-Gd)IˆǍ5kxqqG'CcRdIVVpAP&ᐣG\$x0_bAuMaZ`>ŖM&~1"6Y!$;' 4pڽaAVlfM,8 t/; )sh‡l V>KSeq4a1NZ0v5%6SV̓M/anD%^(4C?{ŷ2"bPU֎ kN?ǜ-J:N\vgo&ATR*ߘ{' R#89\wlt˲@_̢#:29]Vj-Fw'Ĥ\ b"(bfw,{i_`-~`{X5$7V!}`~V!#kTZy~_ הZ)_r ䷐rE@sqD!*}g;G ꠓ1c`9*z^,,laByZ_Xl=u`I= {ԭ/#3 @&z6G+- ǐNT6dt'aQq8Et}G4?:MFbAa^SM_Q4ѷm%+|Y71 SWp]Kν4wL6O%q"Z u4g\\چi&^Iۆ{Ow|jK ` ^>l" 6!VQlF9SvT"-XSP3~(]  3‐N~ꥉD%*Tӫl ۠96_nEw.iGsypPYfD}X~u7̮>v;q35P*7LtYuKXR&^OᢊR+'a@+LiƓK J_g}|XIsOkԟEXw (]TS=aXeڡa+CrcfvِUp\uo.L=/gi'cEjq{C<*oJT/Uz^2iǁGY$eOG`"l6#]3͊u9:UgU[؁ڦrRzeQe5ӓL,r. +FGoSỾ ]<94HѩjLp,(hYǑ:2XׄWM9 =5d r4.h/ D'dbȳjJ#E^VRr/25#s@G4sBS;v5 bVsr ,gUԝ,~&o΢e/K?:)O*c/A =:{ uEV?wxhk?Z%6PY )`,مn*TN"y=Yi!thh4?r}7Qx<*G@G0!^SiI=K`3?Ε~A/ĊQ2Hurx5LNBvPm#(3^EWpC[ bŞ ûoUЙm\11t~WCf ͎ލO&i-q~VX[l;a]G@]qu5%םldwyFjWcc6n/IA=-3?ȼr+(9Pr$ ڢjDt-~Z!*%H=L%k689RHrg^&PJ"%$zZA -B {1V%cxӧ6ּQ[*/S+Hg "M.ֳJ7 T>Og@*}4M 1du%%Ot*HJj_EtPiyeh-%ϗjBoTDav,d䏔|qM]_k[Z eӚ `浥YLA=[6v'_ Rqa>k_,t,՛D: ,Y+ubn(>~DV 'r)\9bc9zG] ©R}^lcK׵jvPKg`6Safkײtk>yѠ^?i!s&jwBߟX%. VWVv0AWQJͱL9!$Myc@D6>5\Tw`7Mæ>s\Ȏ8GoIx mo|x&xnR!^Kj d%P{ eMwO0;,xr p%B+ Ekҷc3K`9TxY|Lf\[QjP$rY?H6Tg{Z Aưa2v#܆ jz{ehp$}4T){o 0?k{N'e uMEb}锇+fO!cC&I!"d|(&)6lg ۶|K׀x\O>?+,l2B0pQT-X Iՠa ]i#bxE5:4Y1m~շ0tl{4^3d>5MnP?qѱdbv U5q_\+n/f|!OV~597s!i[A?PG2WK s{%kw`FM%Zg>~!u0);%e%OBq%p: N ¦=,FF {#bjO~l_kxחO$0i)hTyaNޫs6IQ<@&"֡x}L uBjzW L)TY/I·۵gQ7؟E^-{ĉGJFaV e6PU/IOV#|K#~(bҧ#{pq A0^XwiEA1{@bCu)<ҳ%Ob ,hrc `h|S#T﹵[d^1sكǣcf,Z{6f AY2fPkɃu? 5dDB{|kF!nc3 i>?ו앭-v{p,%k鮶!s)fMmQ\딟2:8Qxc)Mc.̄Ȧ/| a¼LMg)1劷iY[ 38Rb#mK[ Z^jGNΐEd?RPZoYt"~MSVM5^ f7&#wx,}CN9ͱ g:N[]3źд='| D+z;Qhh puyER&N}lO<2-H>Ǯbn)ҕo+wJeŔQM6h*6-*8ɴ)&c.ahW9<,h;#bXw;!C `c׍E}hDZ\n)9\G:霘s'#;>zybWRWT9v|ӷ)EcÌJw>?Ylʧ'2T/Y`ZoON F=qْMA3=HٜP545h0@hG3A؂brtEd܉Yլ uІ` Dҟ3}Cϱ__ĮiՆ~c0R*``8t)oU7.IcOktMG]P%>ejgxVyXҷs6=ehul3[i2% $7p.7ZW:@>tWyĕuWOURMFHZf0%b`<ʄF]v]XHā6{fW%(xUZԇ4.&0:mnGSCTQvP#?_3Ҝqһ/709NpR Qʇ{R7]0?WV&Y`:|gnQH1i-/b3PKY":DHʄx`r?]޵k4VWkեv1qRC}G;̅$b Z,a!*1M*e%$hHvg6ⴧE~~Sܰ#nxc>|.:8a -}kN^ #.YF4͑^J^N;~^UYZp剌Dżڋ5\pA5 ]Hq;RNBWXSFmw}tjs3_{pi"%$ Tޏt)!mn)O}_`ӷ9cf`S)&Q+_(OLAvL1Q;Yigro̝ðՀ!gCSWx2eEI1/ۃ>4l-PWKY|= ' e3|1YD%̡Sq5NC/`+UXzW{5t<а@SwVkIWT$*,uҎ7u¦CK]*=ӘϬy&e`$/y";}2OBf^Z!I=GЦGF&JK"[,ܚ!Sc~ S"ڀ~0m3VT%gPvsL \ovNJP9HPiQ pŚďzMs$u@|6\Q+C1_j=g_ML[g\3!xFaO VDxě)k &O؟o+ %E%2} E=sȐ*eMO!qjntGB&́zkX#淽u= ,vF[u˅3`Dw>_m0f/) %p\\)-WkG`I}S+µe͍OQ~7E#=,qÁGY@H7V7<(\X|/+gtܲ#_vR .pgN1("[=V.uV% x~ZH9[g}sD2I=l;א=Pllo S9 NZL$%a0MkGɒ`M Q0#\KɤTԽY @.z/雿 1 s~~O4-l7_ABWШ3SptL"Wרo|z en +) L2+T /Ǿ^LߦFWyKP\Fo=;¿yRl%Gp|ӏ88 0GʚMRmDDCu{x<3[ͅ{cnYĀ{Da5\ɪ[<#;{ 265v2!ԫ0Z`D:s=όDE_kI5-"nxx6l>}`&wƮ׍탯IDXZ.o/]x( ` H7-M嘑a'wׅK{(zԼPI{??g#k4O]2~|%$u.BTu->f9.BAU< x"$tYE+H]o0:~0l͇1[V4N0{+\ ؋6SW6x5N`mcR! uZId4SS9@G^'5[Rd9\(& 78JkAEP1dz"I{']ís:$8XEW$N=1G߀}^:83a2R-r* 7nžJߡáGӨ]'83P!' ~ֲs,6 Ah҈ C%4 (- le6r!_znjŸ;NM]MAzbs LD2ٯd{.ЌH~>}|kTŵ8umwZ ts { Pkv5{#`-C[6Ԧ66̖5y;oōg= *}DڧmT5ږq# ZẆqdmƘuq(c#yF)wj9~lm\!lh2 {@ʎś)CNÞwd"pi\Z7+bXHUñJ,tfG Ic FU$tɉK(8m7oRI_X7AsJ]Nf g#,Z8&~#HVmbO0pxGrVŕpb$f0rtPT$}Nal4d!/hOSALAF7/PѨfBnC?FSH(tZ]l}n W cfA͔F dDD;`g_NwF«tbQKXX!qbߒoR<'ꄯF7`Hy-/ ,wN^pZd` '"Q +0;*.D*6N>U5%|P=KkL[tRk/9!?UkY8_~͎/R{I~n/X)G]ϯ-g Bh:-r8]*iא{; -Tesn_H @-vE Xa>md5pQk]V@nB3tA/ࡩDVPۏ= ŘuJ}ڭ/v*{[vwJ)x{&sCji?Jl͏HQϒ5+ڑq-m*nC7-RCl;%Q0b ccͷrGE _ƇX;5$Xc v&̻-ؤ2j˜,^^%Kt/hܙ87-w:xL%mh`TRqCS0űЧa/^ YL-Tv_6Z~ 8Z1uw)4[̳=e3 39:&~΀YL}uzT=ąvQ#mw Y<򴩆y!jڴ54q#ϙ/#.ūGf!Ԯ(4 &)$U@7D!TmOktN#3,mh+" hF9jL+1 ]0sئ ߠw u/h7-|G~HKͺ(&&›|p7߆Vr{\iauv! XNbtN̅gMRH|.fi&I@xlXQbjhZSC @l3iEߧytT4JݖwC0|.14R(7>tҢYMm9|o&w zֻuݮguW֨3i\VO07(偈T QGrpǒBF<^c1kN::Jvt#7D@,aѧ}WOnzR0p9RXoLᕨӺVrR;1ZHJ^Ѡz/oC} M"A?[Xp3Pr*'}w ŔFV8#$ɋYX\Vf~oCRr]f,Mj9K25lkAVczMȿ5@s?OR !8R8Lr!'݊40 *p:y)D3=lA(m1n93Tg8RDBl z{"H{R'0Pu;'*Zniz!Ye+OW_z'Cx܅RĿZdOD/PtģT$*n(1ɫUHrVeNBzG}9k=ln[Zv7|mj~s"&y0΀Qo gEi!z^xf8T /e~YgwcL] ȢeVNZB~5zމɭI ᎉBٹ<9د+ց|{^7<8&ӗCi66tkq[}mg؉4rK'b ˜,%sʝT~| F5q~631m@ѳZ ZJ}Bo`a^3ʤ)X!C./ HKb6YrUw-! V- .Or蠏O6pMaN@kKbă㱕9v&{Cc@t'y!-c]qWvcj$ӻ| iW_FmW錈&}ȷ⽸i΅Xb1ሻ}$u[`Է4 <ܭJ2tR37߃.ܦ5t#U eI] yDVhb|i6yu\M')L=S3P* 9I)B'\ K<ΔWzҘJ$ȺFl53$l+^b\tqN4DY)(ۘkd#K-#ݣy jo1k͈3e."v%wN)@ Sv;h-sLXq^3N=0X.&wc˷Y\.ɫ^c+Ǻ&"{(2iE5]X`?g=ԯp̀0OUhj0g$lo:nd~ޖaTK)#!I HNPjqI?D 68P ML0c(ЙX41R/q0bⶕfbTM Nmh1 '1`t;p6&KjRCvssFcϹKd#l!O2YDIbKGZ@WWS[]U ߶߬c% hf"!mjۗL¢/AK<&}9)p YO!j:Kq Xϧy{vD4dnWKחH@m_GcJIDzH-T^y(#<ˢ:1EEd`NrJRٚRUZJ̱,扺=HrFpa宓(btQ $0Z@fʈ9qhH\^\rA,jIwGHR6ˠ]e4<@ {zIo7-wܐgP.hh"ꪯ$m|$3z$ ػ%KxYkd{gtPv@i9&xF٩߆Yh ._@JGpqɊlT!)Xd=e/?&X&Q@&т QCY_WcxZ':Gvn&4}4@ p Ɏ) -w` ~1m*3mZ81znU]{-j$ד\a_?!#Q&= 1P@xY#!֗(R|xh`p/؅t e5].YK,w0; tec᷾q}EPcxx-lh_5進|\NY{Z T(C..,"nu7ثȤi?*  YZ