sssd-ipa-1.14.0-43.el7_3.11$>r8u l>=?d   ; "@FM    4 { $XLL 3L   ( 89:e=yGyHyIyXyYy\z ]z(^zb{d{e{f{l{t{u|v|0w~tx~y~RCsssd-ipa1.14.043.el7_3.11The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.X~oc1bm.rdu2.centos.org 'zCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKNiA큤AX~oX~oX~oW~X~oX~oX~o4790c7240978db7ebb45b068e719667bc94b918d094d5ee626879a48d3302a0b8282b239202907b347a9a1cc7942ee0a915370f8a25808a40b00dc106fd4dbb28ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903db7ef65c8a57396cc08f8d7b4c82b8de9d7c53397c64cbf120dca001f5198c1cdffdd465621582b79904ea7e77cb96c37396b8d9efff43c35a6cebeab63bce87rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.11.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.113.0.4-14.6.0-14.0-11.14.0-43.el7_3.111.14.0-43.el7_3.111.14.0-43.el7_3.115.2-1sssd1.10.0-8.beta24.11.3XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.111.14.0-43.el7_3.11libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8331f40a84070971d9978cd680a24ba3ac5957aa, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6&h]"k%w+p}|,p35muذe%tWXPĎdߚ %RW P#]B{HR0\nxw&:tU@{Q+&)?njEul%_VV|xb@tVX(dҚ<Ktf3>z":!͇ Tز[msxURp:O`q.S : h7oȆDŽCuz sO~8C2ldquؾo dEDkX1 u'wgbУD !^]@._w2{cn\O!?L$cNYTC +rK٥)+㜗F:QPkB-KrNXFǛ4⌕. 4碞Kĕ0S&`a x*rO_iQ% D^kf.J8pnl-h0)yJQWįtJeTtJ;?>6S['vI5C$<7[NYM~Uz(8Q;м~WXo(?:)F=$G @< ~mA<*FX֢ڼɪӂIMUFݼF>HDtnc1,@=BGgk,[nZ$dEO\yd-̲.5ѪVɖ`K\Uc дdǮՐg+ѕbd}NG6i\߉kQj{`oԼ6/.c G¤wͤ%QME#Qu"+ Z<ȈQbY-nV6NT7P@ x_Bs? IQI/%W҉RB)Ct4]Q (2Z*Y)j<\Cؑzq2oR;KK#8˟ׁ<5t`a,&[ ǜbV5ԕ>Ӧ/?ɰUdy4Ogblf4Ƴ ڌH r JF3(X-+R gަxn+'2?S{186{)xsP0? E DMɩkMOe^Xni~Hjz(n6L̿>K4\@ShbABXse..id-hL0YiiLi}Wy6K]㧰krfv(%]ٯƋl@v43@P=&伙W7yxOHQ㢿}o ^Mj酻}(ೋ18A e xIвyZDWGF.7@wh12tSrrEA^: V*q3Es :R'ۥz`=e\BC\Z 90؍@elxShL < ("YŁ6s ҳΔC{z>!I~ɖ 6olͤ\țuWuf-OoX֝zC ?؅D֕$0:G7˲x 1/fSg O_[/g`;..K)yQ_p6ٕ LG$KpQr0͈zГ~Uu<"xk{୒fED 34D)peoG* [ }RbQ3˹BdZ-Ijq[TaIH7*᣺8O ]fmDJTZMy4T畏sQ߾-J-FW~x"*S%h;/a>cZZ0:8jhj>c*^n".-I3gdP1 ؾ,* t)s P yy,ր|D(oԮqiՀ$bɷm%ađn0G= 7|FЖ鑶LĎz'%JVo~M_ںrL3,T}~Wpb3hҘ߯4p`8bAN\I6*ЄxPn9D,(KCi=ڬK=?<' ~97WMTx]Q7}_G\uug2^S#SǛrNB Mz!n!ܫ8sId}ƍz%H@OW8y/p}JFjy)r%ilԵ@WZ|^kU]K,I/P 4'? +wL)/ߐg.|1f*kZ~Wri~S3)8~[^XlZ1}uϝP##Z!O"?n/хK)1}hd/gZ&*s0HJ0ZR ^1'Uw|jV(mG2geq,Xndw SDvLRKs"ẅ́u ϣp7xVZKlX{B)*-~g(-!)hyLq%c~8?y7ӈvUR]Qo ,Ї63r-E0>jfsNIAEzx ;qXJ_kq辠-zr=&4E0;3rOh?z% ٯCI6{UC{mwˆFNt}WU ILB5\b#b?柲o`X5ꬭFtax,;Ұ,bY+5PA64$b22T+ȅ4zWGRG#Ϸv1Q^^kߺ"i#:Lǚ_1 PD В[W Ew^_dX#gVXdS L7dvÊ`M;8qu1xfz'Zp;a^+ח[G9nH0жirc?ͼHܢxlsV2eY螯-X-R/)/ 3ߡjjG85Bʇr v ,; v= 2 0$ynj~$TNwtҊ.chgui( ?2oU:8inR⨎|*ߚ,Bp]!YMm։ⲄW'bC[T\ ֋$c'{l`}q4Ak` ad):L3cCO =|ކRlޒ',RMk; L!wϾ(Cr{h(rAfyڔ|ق-V7\c땉">g, Ki R;+)R'(zE,V^0òLo<4]?}a.UU;DY3L2rMV؜CT(e=$*XzO47Zӫ9fCѯH/oB-QQeB-b늀ZcWCL,3T Y!Lؓ8xN/͊srKgr z br~v51R[4 EAnƊx c7$͡GF$,˜~3{. dqEB1[ӹl.AH<?Tڣ%^{p9XXaI[ X2]xѸ )fFj7I?%@-.RY(@ )*QaAT w}5zhWmikpϗ_n%> G#*_ڨR66ůUtDN^|݁-KSOn,0("ݐY&/iBOcz v›0E{p;3knj!)s]?J֝\`]md471Guwo%LڷUD 'HϡE,D#[ZunJڐGiw(!uF \`ӏkͶπ#݌ j >:HjH)1qP>YG\kwm5-Q] sSIv R;~Y2ףz = tZv%zjІm1'׼ʷWW:ZHjSM>IM>_hHF~+,(Z||y0 yj3+uWLī dH>W1w96-;BPAXU6 ޼)4ED@i{?5NAg`>3ڛۧ`u.Xw?dxH\@Oc+NHߐ@ǠWdoxKyi @R<߾|7J}ǿn %:qȚ¤|r-vӠF5?J#s$0WŎ/џa ,Ͻ˚\j'Ziamw80dU *uc/{ًzւX)}.եUl͂xl%j(h?EJS, \")tЯ>"޶&!2rZr*9&UAo.ѥ{1?C4^Qr>XT] Z"6d,"΁28gJ?/ߥXhGP$7$˂@G/h9h)YWƮs֥ T?hp%+H6v俷AֻKi]ŧpuUw5Q؃ƨyZRxO͉îVת\Ѯ8ş"$.Y~X>5 'H%mhC@K GY#$c8AgpxOZT/,zM0jͽt>`4*#dVv-K,3蠡KI!'bJΫ̺B: L@6DGWҳ؈Q-:a4T 5 y00MGbɓ!ϭ)k*($"j"5Ay[Ջ-Ӄf jt\ ,-WGoR[ rۧt떆f]tF#6pRM_"h#"]:pHw*:ҲgǛ 9  QPԋ$y _7ءwb\yN-JX:,ï@ voCtq;.a 82ۓPIDo,$SX74AZd}fuL& M?c;p$ϩTP|ya0JB%١Q$fxŠp!ڐ97Pn&4FHron/la聾/l5Wy.+[(zPBi?3e^:RgRuӕٵE;.} aY'IĬm֏GNy~C Jpj g< Ag$m G]|aPHgӀ{ u~#>67YW$}/hHn!z᜸ ?(9 G嘺`meGq$F[e%޳şIMӉ&NNy}8t3ceIJv _ϢM֝htV![n|- [4O{EX.NP!co`ee}_؟ĜDEc(p.e8yX̬; *1Vb{Xֻx%h *z/ `?PB~H ݁VFE_W9lᵾ\h?]\2Co6uto \60u-[p+ yFn4N'i1zVR{ WUq]0NHķ <ĵ;ڹN 2h",⿳Ź@9V)yL:$$NݗvydvzZ&X݀od*fdo*s+x )S E. 5?1| I1QQd/!?EIqⸯqU5TʿF_ϓȽUQu|9J[[q}{vw|"Ύ8^k2klB(@#lq `J]ws; P,hlF'ʼn?abpNU-c棟?wW#3B_L}4+/d Tю=Z55*by^)E o`~@fh ƆD8RGP->&3ndg0~z".7iN=W؇P\ nFjJڠ>@Յ`ʺt&vuaxOlupZ_Ɩ%XodE nt9_t8.y: E .ebjX:H,HW{L#oxaߛL:nU5PrܿTE%xYY5Xĵ"9;#!MgI$T;Dri:BxV!L">~/7,X-4.ݢw:fΆR;NZ`H9 m@('weUg6~LрF % 9zF [FzhB:R m  {/J+5ϥIsKir ؈(>NE/((m~ώMrb5b;!<\J- j f%բ_|U@Sl3.^}i=dZ*e4{I-RbP~I1|ռ~~?4 ^?8[3VʄWIhy !ۙ2Ɠe}q !$C}txAMtDa) gM+aw9bh=Vd gl)8 İ7]!s-IxV~&# o}!hT@e:%Y!`4pMl󅓝e*1au mt{-4'""dtj6XUrw?H} 6, ɳ+zcљ\\l`XФ^fg [cͰrG^j=!63bwI(Dڌ¤f~k'yB^+D!B1 #Ͻ}ݽ6 n̷Lmyş..'rR&VF>rXnlZ oEEŀD6]e~uV:6+Eͫ/}V1ꝥ;;0kq cf-n@QpqpB9{siU$N ֱ30;P'dʉxwTD,[EGfaW5\DCCDĶ!Al%-4UUIǽp]!>;k;]o:j66zmD1$cu hh/b$DӲ|JdF=YEϿnr%'X 8{7;l\P+W;w#nsq4rЍJ!O]uqI_1bvLZErMNb>;雰cMoH$iOIep T끼?AsBKq^|zDX 1\ ia'1F;W̹wi}͉3'$>hWJj3{~jG XܻH 2R4IcJCF^9~Zk}ԆWSQa R8#='Y6wT 7uNWDܐS ynZMJN:A5RmΏGpP!郵1h%2/pV]p8T@4%z(L4mF[=?*9%=;xhO*Sk+RIX[ e^C bR#8q>Rm/݄%-'NmZB|_==8s #(G!9kE /}H(<#ʣ:-2UZ^kRDߺ(ׇV㌵Ey붰^zCo #y=C'mt m{Ōq&gq Sq:3LCCYƶszr4I)@BS{^K,$0[|/h= L AlhzW}}L UL del_,KQ *KzaO~<,o,6ug72k,yiDK6:ݠ=|iNL1 do=CBsS^ u jYtfSY8ɤ݌(g5SzNlQd mC/iWyHk :yBm'YW0=tꥹH&ǚgAIErhuӳءݢ9 mid^caYe["K zntb]qSf"eC_!'  ;UOkM5j"ڃyk*HD;n)8`Qma99\qJzы ;+4>݌cRD1dr@Q ӞquUx|Eumec߀uEᜎ2l.tNqO"B}PQC/^#2*ٲ=Xprw| ZteZaF*nrXךˀ&0- su>_8♧pz k`Ї##ʕ.qAo`m7 ӄ׽X S6j^܋]fKb‹ 4{= l3V!b|imBj`9nzJh(hT.|_ I=l<翰}&$H]q7+"%ta./[⫝Q T_O5TԬ!_Y^pHYח^x΄K 1e渤bTu ӀbSUX-EIz\H4KzZ |. -;jDguuP -Yo>E_w WM00eÌRhSM(v*,0C$6VСeE%I[)M6(YTWʬ''M06U͓x1k~yoǗ#lmc{,1+t@tN+ TR9ZՃ=c~ݓ 3B/86 ˼_Qw@0an`PU%B ɘ*%jFẽM-.$z5޳bA{0~ %l."5D=)*_qnwH1j,Juw)"yZTy¦]_c;]ݣ]W<, a#|zG+ֽo7iqCJ)e27vHwoAoQ1[m{`!u(ܵ5aǟ]}\m$VwD0 t/`.xKs9yM-fv جYFƥ}NkH <>7@ Is?ņX59qeӽ]葬<4?{%?I- o'1h@K&={u@vS5^!.S{~JZd&\% qHEeQ,٣l*!- iQ XnU(Na9mZI:>g* ޝNdM@N QWGu/;P?c{GVQvV^ܳ =h&tݷqD6}aR1ybWdd0]m g 'vF 趼BDW >_!J%HvEz6`Unv`tJ}D=u!l>Su퓚`J%3qu9vG˭Q(^tt6ZL~gv%O*_t3hz^pysf̝Qeh2N~Ɉ6it۴?6jI8Tn cH zqPH`bdqN!̫dO wI 699f;.U?_}A8@K?7\њAik`"3 @Hc]+F$؁[~b&fOU ^^f0M!?L2s̠%3W1L~pN+cf)kJYz@Bp#']Ƣ h]͋Kxd{H9 -^/u[m K2Z{Ս5mL-3hM[uKJ@Vt^O\>O=d/n/Xo황q`%,J%Ņʼn| S/6APۤ1<V'\E~}~zE~qi oW~Ӂڇ>O 4[e/ܖ}PoόOyaO6h#%+GQ7Ѥ.5 Hra}, ;u U}qώ=quWuUܐ|/U+Yg@xm`dcS<}^~ n]إ>ՍחZtOrQQ>bUIL/x(Hr@+la%ͩD)A9gJ-5Vj2S#(;Y% ÝiYxYW'tn#"DS[D%{SDqY`{'KHqVe'V s1$]Թ02?TA ˔!M#˩pT+q~I I4IvqA4z:B QOU k‘0X'hy vƯD"/M߇31#1 +F30Ft ʥ%)RYOUAfy^Vٯq"(RUЎP^1wetAkA.=rI,pYxZS:Wj gZ`,7[.WxTwsIYcF(],Zimozc]ش\^)+˕ݸCҵ0pf!8..^6G}.x J{zA [ZZ{f9yOR?obqV[ˎf >MSJ{*\ݧR}CȜusoqYhB` 7>;J'f@n,]p"@e[DV+?iݿœ![וi%mTcm==!~ّFCMx.=T+1I]+0nCj3qu:W1+M\|iI>!e:z]ZSX : ~Or4{8[ 㭺Xk"DU\cڕV}gW|pa]xƈE ;$%0W0Lz#ck~SĆiy2usg[]O?+CK!(i+*F5%QU,ȴB8nd>3 ߦsV}嗁x;L׏豸e>~)M Dy>B=RQFT+D 2;&f3CtǪL[˻olO(HWq:< R8a+f5b5. |*RVHPPKQQHc1t+c"vѐJu yyqMn-kqlzubs_/6VgM:]v'\a=T(l0.5j wUBƋtqqk+YWK LC%̗QDU# Rym)ä^-.؋9Л ^ r VuaZdDgpX& &;dzjx>t4l@V(.aW+F± 2,ƨ xz'C P38]X9MlNcLGT<$E\sAjpFL?Y쑮 <ȅ`})[WI0rfH+ŚVȟ|8Kn!϶ݫ')N%J]WO)re_q+4H̗C7 I\xخ?~E.xq7tjH zui &`LBxGAaWHTn ppU/VϒJD07A[eƵNQa060NL26HE[WG(I0{~M}e5 VC+)ذ׶iF-7܉IHb̶MGäx2F_Ini||^o$/[UxgE 0,>3:r^bev*VC憶Lr o՟/K_3#t ZQ,RK b[7PE^_h~ g&5zeZZmkaSH*v$chCAί1br? j2W$ZmG%SfUqCX_H_$H,=U_H{`(SlMԶ a`aEc#kU2[ZR(@tvO6e$ ھ!췷+vN X-3ۡ;ùkyuneArr f{ME b[b;=3]ƞ~?mc_cG.;ʋr3s`5OD"RZ=* ˥H~ʥ9sC[M<\0 mJX 墬G*i'qS2-tsGb|جzUA&NqEK!̹/M%lj)5)y"TVX̅0>q4p_*C6lw& -s~&wHJc~gU>UTreGF :sS`Y[nit8 ׏H<;e 'p4o5|X2ڒ2м$5dѮ rp@+Tf֥ģSo1(Io prJh]HSw3[I-9)d92"}E3rG|Mp I. ti]Ǿuo}ӥJcqQ1s,W] ~~~$8$4`뷀)s'ĵ/!c"fnuD| (%e\ @j)D1ugP㆛MN: D.a4($GJSh2#3U"OP*Kg??pġvlǜToP˞| -D/ttƊk. [•ʪ&?h+ {3)k!^r:Do{X>3lVI9Md "57HSW-P Yq 󂅍1zh#j`|A8a8Och.t|7A,y`N@%+0gux8ÉH ayy#xLku}+y g0=̓?EKZD<.Sb/N=u}?&a,㑭ڪzu㭣hHF*Ι5=s&m2 Dq ">Q$a/p~\|=dP9$1_yLAW].AvBq_8QFٌ* =ԧ.5j?#ْ_LsE` Dhh{Dr^2FȆFJ^J4|^I`buOI6d+r";cC&-V'F%!cbرmc&IL-pFDuF*W0B~6$wzaeRĐ@p:{DpqgG>c~TeKK=VG"ny`w05ܝ`Q0R}֑^#8oA6Ldj9|*4nGBjv*?ěڇccEվG}rPP ;jbŹ.=[uk4Q ʩí X+-'!,حry)eL.O̕v ƃ{Qg%k>X.l䴝{IeL'vD=P>y*tS&G!M')FgCDڤ6+s_XN+9'sN :]lEcs Jx@H]BqEW  Q~* Y'Z`qڎ1l)ae*eLG_1Ճ@Cw_v yG;b@D+>CR`-X@^f泹Źob&v񡗜hhX9m3f?~(2糽sCHf1Bh6g HQ/eb;IE޴Yk4.tۺ'IkD>9ȣ2w cA,6=D+uQ#KΟS7ʘ㪼kQw+Ż8%tF8HQDwԲiKN3j+-!I+ү_e_ kG;**NA1 rX|JI8}dslȆI*}uw`](! `+z<Lp|6#ETѱg⋏l7ڔ:r ɪy7 ͢2IyK8Otĥ؁q"X42ffs9sG\8Tcx,o>gN&uٗ%> Z {ۮmcѾ[>gYr]]Gkc1&.T2!+8W;nɔc"a=թ:$n y9Y!֮zj+pb_YYʝchq9h]m ]&4 rPY{U] V@|u֗ sE.ȱ-2 !m!UBxoJ7\nߞ_yY.8ep.E=-eT:e}^-L%ԋ KMʲ7\M# &0(X{k'P:o3k&2t,n_d| ٻB*Ea'Vhu2.EzBBďHukZ|;ro:ATXzOiݝ& ܌\C`DdV#Ƅ}O%v0aȦ3eBۜ w{%wICg2<9zW֙$+ϟsv/XFk)$~i04]BTM \\f݃+XTJ!&xu Q(]KC8_Ο'%\o&lBxCұm2uyJe=z8=A܂%kRFreR]v4a0CM{OOn1$9 h7vG)0W粲jIҡw-`ΣޝY^j6q-1Q_-qm}K{kgOV| шl`}{-gPX`ѰM|I.t≼1p>H4GPmPnڃVUv/fĆ(pv u3 D>o;섷d?{WX-Qal3ɹc8.}KNoNaM'Qpw;&L#:{`U5cȃ1p]E,}%R*@ HR[!eG4~ƸbVӫrMT@:zNqh:E+Ɣ,{ͬZP!~ȋs>S= 7OMIvE;VI"?;` H8f>O igw?/r8eBp/giL3J< *mG-'I]YOAKIJie\sa=`FŸKͅ~GxRv3zc-wqc.|; }Ie5Ȏh !S(BLWPSUy`!)@<AE8J`+Yu]LsB 7^4`;Į0vk#L|Ue.{L$H\ REe6BK^dۡ:`S(m"/H/8B{,!Eʅ*qxOzF^\)0drZo+"QOmPd>Z5.u-vٻ خg4K3Ch<.ciqV;F7[yVhk KG]H%kD*F,pqHbflD&(%|Fi{jۯTݢD-|$LvbN&[>_"B} ޼{hDa*,i1Wf,KTԒ:Te>ok/eccY4'4 {s}b:Z]9{0/¶-YvSǾmW+bBRPݍ2u. ~,jmU'`vV뿪|h$((g4fG ytQx$k#7Hb 5gzMZߡjp|<_~ L41J/Jet1*joeA-;W:s&CE3~vU|A7RVj([M*`$ &brCdW#i;$3 && XgQ-C>殉-\5\R95AkKsJzh-8{\ϳc$BtVOpl1zhN%n_.~>ʳgt~1L7d!a]>M7%՞aAaN~sܤ20& 26mh r 0` c+Sýyp4Ih85B9rnxd4LkqW+.#JQđB2q:0v+ч;qGϝJƸ6Wg/GY RW+bڟ&%Dj*?̜q5~V9rrnrR vWMRoL>ܢwzډ(v}=tD{+jJ#vΆ!vCd뺯J4f_،U6šeg?y ɫ/Ɣ_6ü'>|Ǥ>b}mѝ`g T@ [;7bf8 DELn>)p?Vrʄi,RduUb{nυ3Q(9zd-Yk)f?VqٝdkgY NDY"g_|F.oJ\x],h7`P_Іðx|yaPceP7X'%N>xsۓɱ^>thii/n/)oz u% \~cWVIr A{Kc_\;pcϨ%ENhST"Q4%PQ"|L![Td?,4"[ZMb^Džq9NP E#g=m6W6ſW޶t.L5,âlf?8 (a~޿ SXbG0/e@t.%b.C -9qtB‹bqa5]K (a0PU\KOok[7Y~#HI*![7eYX(QxI=,琕8a;*,hTNi+(-oKRxPLد k,#+F1%qtXzK.>>&raXX*!4#UiDkV#>F, IXs d)*nxB~sF*,Z:#:<1j.|HiNc}9yBDRؓlU= b:0IM,ٹpC>sd(Gd"Id=9g~09X.{wrEK,:qi K%u쨋Ф74+>o/!{Ϥٖekh+.U3)q'rRJݙH C=zژK6?s~}V "2Ĉޖx,ޛEb, 6J WfV+`oH[+%I%(Ą<$X?,gμx7mf9.x)HЇt>-V>1FҴ8u?$L>[d𣨇&ڮ** %~|ksRNi÷uHkm\ ?eX5CCig$EPuKPlR|GcM_Ė:#L6HyX^#G?W z{ه։YȰGK ~,F ވO|kIGb1o^!0%9 dmt )c9~WVNʟ|@Qq+*Tjxx9  Vb"R(^ q϶r=IeޫHX{N $p ʻYDnK%۴l;wjJ6E(J1J ֠:ԋOiO~P8ng>[R89J}zxWҺxnر=qS}cϹ6g @?+gCjX&'o8A)r?¬s;9Thv.'Mԝلx5T>T7O󦠹as%6QJ G@xLjt nPJ5gf[K4!PL UUtURqH?K60mxcR?T "`m :,^Qr _C3u+ƔY?ueDBvlYi_2mq[0uݛ!~;qpGJ*𥀠zaĉ%xlym7\?d@ӄGfϝ`Δ dr8kNs|=tؖ@@t  E@;Q]}/D)CPY)VФ o2$|fSN+l/\\`)~'6;gb=V6z]jbW0:p|~KU[>Kɷ?̄,-:4**صXSF]z$C庚L^ 0Fbij0,V70$}hY:qXHǦ@1u[%IpyF%:>ivo.0iѺƗGDݳr⩕5mVjeL5 xjyBt0 3O&-e uֲlR=P[F3b8GS8FL[cZHxrM>t&}ڜ9pfԑV>F"b:)AF$xo۔8\6P\fp%oFPN!'LAoB! -.ϋ5pG9t[wGH差 JY_+$pk.\&& θy?ttأPi0JjȈwCg "\kiXX}cTN܁Bj}#<OXy,&60oRAzZA$ uجޣb`0 -T/=w644pҧ ( ݾ~ * 8Mm[S7Dʼϵfu)k]黢}f?:onȴFOYO)zb>1`8'".kC;Ɲ5~g&AE>ÚHLiA Xu{M&oi)=Z o(Mȡ}u#[+:i/zC#0w 7_y= $e$N="f ʭ}e-5_6KCxk%Ю Xm*B?:~<ω%W=HDfhd*0Ba3/~&Qۚ++WwF{Zy9óNϥŚH=ZΨ:OJ__2nc^PustiF$]?7[ ]@ ю:Tq|O"[R#@Ĥ |P}9hV?ݐqOF yw끃$|/ae#Ye=2m*d@8+Ykr5O^ Sc蓃VJ3czJ 5%WK#(,fߡ7Vh7WXɧm"C9'es閜k=@Hs"ХW8Q@cgbgfT1r`%F/G}K%4?- ̖57Jz{IgJ)Za ]"Xl 7cqo$Z]QʘX=фJL }ѥō=ڔO- ^~X k$, [-HQ&~7Bz) v;n /&. \*>E'G4J=RFꔡKN5 sefY`I>\(/{6]*,'7H3/ v̬iN^*!bkK[Ͽlˀȟ7;v0}l49xP8-]d w(鵣){W.D# $׻-&Y9c H&ORHZ6BG4zkUÊ52QHʫ"u4er+{,݋#aIYtA,N"W4v|Xn-s Ffɩ\3LlR#, ɎC(AqFKfOSF#;Ħ}mO١Néu +-7fG j'32Zm-X@" 0#He{ TV0$S6΁鎰-t"_F(_V| !3gQ DUx`yfEuM*MN8v|Z/_8TMeE6=Ɔ{pa+pNXri_FT'3 0Dҍ0۩& 煤ɓ-$fG!5GĶ hL8*7 BD;SA\(:/Z JÆ3AVk|rl| \q1_0cWyxh7oqQeؘ^[U|Pc''H39QX>鲹.ȱ@9RYG\{5)rSdoWljAψ 0 n7oU@l`yްSKxN'9C./7yqGHnm!+qҩdSE7+8q܇OAC`}n%3ޑSKZ 䪧*Vm Fw#iiamkV}j:o}EJ.2ys % wI"w<&y9 .Dj"HpkyTbG&T0  :T%WtL.nUnO둍d+TF< xj<Z8q@6k-yaص7TVtT9gHEΉuh]˦Ox -4>Dˆ9E7n'nV)S76EwUd~rprRW#˷#+X?iw3^9QGdk 2lAyBh;1NnuB]3k5v":*M Zw[64 {_jdB:-0X# r;^m|h{ ŌzVOssX0<&T9lwsX]E59FCzZѽK4$#P_Eq!D @6C-qiǩ^FĽpjﴠS8>QBçYyD{mKL:o#¿-+5b>CZh !荾[tT ,kY.K(BHr b W`όOjw]tY2ۨ@2ed ;=W,Ĥ}᭕"8d^{|(F܂߰qЀa#Aq,^U<>;KOEt.9_-b}P Vh a16cPVs-*IzW nW T&0_z_ /dz((ͺUXP7\q2`;02Vy=Y,CpH;g^V`fҩzQEc:Ȍ^սǾB?"R|xk" cpA2PoR\O 5UoJB8:s6?jA'gܨS'lH#׀dkhN WXpá\/*KcE]˰jsQhbETafJzjE];B#_;W$,!0԰.{A7yMvQw[䈝fp' ޲M.z{ AL0:Uv詷 az\kSJ=+)Z{F³9Fs9-5C5f pK|yQΏ%\9A7yW3t b 8{& 2֎uMyy~*@ZdRy_ @v .k2tXӹj]BB/l|\C~c_mG0e +qkYz e2H5at39180m*1n Q GD1+ L$ZwUzͬR|+i34Oي7)knR劯-QxM"4\$\ݹK(S󼵑r~m'Y:%o=ߑQt= a:0:c7 <ǶE+`\FQgyhed,F)l* ǥ !I%\fаje@(yjhÉ5J![W:bjp.zD2p_&!Q@/UpW9*RN |@) [ohC Ŵ}r,fq jwraWE>\v[t+=,Tc#Lh{+r(zK[V!BecD.ϞLP2yDw\´F*>ZbvT21k| %_90=_t&6ثqS.]$cVڿNa4eqX~Zs"x/W\liu>}7]0&(CCB:wu8Oˊ:<@v_P3^*0e$Dވ+,^}Qku (;:|d8#">APt`aovS jJljk:}s*;73.#" 1Îrҝ$-LwDb0^~ĴdY ) k7>!U:hf.f.fМ[&\mmI iIݲ:k7oJh(<_nV_7]Z,7~JM`R,uMj7>Nk@옘#(wX ru}mp|ڠ:+d;no1gh]]:9Oi3 S̟a~a9K-yhlG;(\d0oenKHd %e^Җ߅v7kG~&~D+r4-]unKGPxC_stU"eG"*gיNaV:w\gjQe&4cLtqTt]Xǯrg`V0L)N@~[v$ }kKS- L/0tZճVC[r0rm˭dǭDY`S"RLw1 mX{_8*ȿP˾G>eyWRH-_ 3!+*ׇ! ;D ŎxJRI{e=tT1ml'%[s~`8 S^}* x#Gs .z &>dHwh*gI*?pVG͑vͫA^?{%X_GȐ>.qyGa LxU;YTb/HG]&ST7!Kr2.s6}]xœ VHrm"_[|tFBd皓IaebrO=db(I/eLFv = CEI% KSgFc-,g=)|lfS|:Ŗ-9]Js+7!Z'mAN5Q{ >ڏʈVnX\46T>y:f VC҈6F1r֊o@DQivVߩs޶(e+.6f5ģf[WYKʌ}^J%v!HPC ^Uo'DvnjG7]gzȢ'j>A)@锜h)6ɺ:+꾈KF*)9 J|wlHIb*9J}c_tWJDoU\fJ8᧩,/2ͭ(jY ZԝBEID!!mQَc pCM*7mBE0̓=WFT|b`U}dq]`a"A\CƱx;G +sZR84OF]0#T.aIB V>0Լ4`IsυN@Yd",M5Ѐ߶(d@EJ#~ i}(֊Hv@ttzGaBaaXW3旘F I 36^8jQIhAOR_,Ӫ\M"\z؜ 跨:4fZm E.㦳 Hi4 { #u͐~S޹hFqH>Hͩ۶ok"4SF̺^^ 8mt%h̉1%~XطC:!mdE*& K]/+pRN}v+CZexpxwR˻Dl_]߹ QI-76ҠZ[ؕa{ͧ]lc.'%dZu`uD[dS%үZz9Ur[x&ܭERtS72]ݜvy :%Kֵ5ǀhW~+NQ|UQ8@5Xڴk:mvcm*A@;^jV$nD:?z>j}sY2*:dn]1jT/%qG87阣S4e>`E~pUFn[4Q6V$+I4!Z=Cwpœ,d4W3.Dbn8rb}ӗ)Fn0X$[H^[`K 'BDR)/h_UW\  7q4mjOvvbw>s Tg2G@~CY M'B8WJN7p$DzșLϏx< r`TTk9yU=k6BQ*Eȕ5 bxe,s@  f:2s*wcE~bz$̿ݖΜ>s>d*rim;<|y Oǁ4UGo`jMuAgv5;i߉P]x&qXWdWLʎ6^Etx$7^;/FI[Q*k@ ;5"dž-Wd|h--O`` BDC, ӱtNk̤' !;/ h8lR~ZD%&s*5$0$ʧK˦27l |ƒ^f l} Dŀb h$۪*كID(TƁ.[OjԉH>S5}%FXn}4W;V sj:3?A=KMXxSL~A)eCм[/qG =yqЦBF3Q .(0Dvp8 ]7ZkdRxAHWy?̚)<`])G%=|J;[5h"9_kTW':%xg v{`뎕+90a̵vXjmLg^c*W-bxԿ[ L wg@|A<%Ra.'O+N1B]Z#OUS.G#fN&Og3u,*J|EsJ⃈3)yYn'y|x[tsԼ3%;ˌ)Vӓb8M=P}IF*@PGV񶹒att| yUx^y NT*H5vB߽9,K&lo#1sS,9i)rv-f[6(/K[9Y/*wfәՙ]rAc+CϻBYNLD16|ڜ|oZ^EL 3љ[)n v_-{S[Zzo{y)Ѷ[h'"EG'J(`b0 פf`UXeQ"gnsSV5U>:C7>M;t0,ACčJ\$ipJ+WPs,6"P"ހ;QoW =94מ$` |[@aV]Hʢ|8zBW;ХqДL(Xn(xX teQZ Op=4{v9`xI|fd[߸Rq@_0Դ ?oٻIŲmH(-9(x ;.-$d࠵.ZfA[Rfpʼn:VxaXsc̻&\LA~"%ӀeqQуw9O)gGcɵѫ4CIV#U wZt`(-Bb`|ӂjyj؆VKvY{ޒr*a >'Rw/Ĵ4?^| Z$c^~#4tƬbRmh LRnE^#oEdk6Ӎ ę ŖBڿ_-$&(vӗQGD[s_ X{g+I>c6[yFLtFʧ$vte)B?{ i|`a3W ҀK'ʷd8/?Om:nzzVr: ي'8ڍ~"_ YаRƑپ|oҿ3<[SN/(Zȯԉ&2eo1Y:^`MR1KQL^–[QxۚܮJ3p^G^A$ޞ,'!Lw>XRUfKƼKu'c@=tUzAew'BQ{ցQIʣuQB쑩uB52PbݕohΔPߴa49i 3+i)k55{ηLA)~@ ]bY[A?z`B_:ʧe\O+d4XEiXW3ANm\8"Gټ$hB~[?L{Q2b#ql Z䕅pa)qyM)5(I8L‘9_VOIukR\ xp?ecP}}@@ D:fg]WK|ÿ6?hP̺N9c w)J]Dbdy z![) <35Q\Umz/ n>m4fbƄ^ZN~V0j,wvw6Y%pۆGr2~Rc *K҃W+AΖ$-Yŋ.lM{X旆]oFC64sgܙ|3#nSjU|K&,^ 1O 8oV*|}e(ȢB)t]+懠VNi@[WJm@Ƕʂ?K|X9+8j4 DBY 9yA}\1cv- Xpnt>\f]3llH?5ͺu?!#a=596" H tߑ%I2DV@+&y,_%{4/ÏG7Ji%7nL~0ھAw͆q$K09F7a{"$^FU?D*坩EI0zI-ՕK.O"Y= 'fTʇ$FFcx%,  [{:}յ:nȑ34'I3>GG嶪@!hvoR5{i@_؅(a0c[G\%}O COz|Ygoۘ9jM4KJ$Tw@_a\."QIDD{ db|nJa|2J~?A.S/ݱ\ X^Bqc>eOf~`)#iAWV6d;(}wEEBPxRoq#[!?H$ tc߆5nzLF/0Kfߐ<汒-::]?g`b-ţ-&ƢӸƝn+HxPoQ4g5B|gTK6la,H)FԑO=oLTGŹ=eE)  :(J;ֿdŨd,N&`\˘i.>R*5!q@u'A4ml~.O~8Z֑A-=4rRtfc2^KCqW84M@NnZr 4޲cCݪ6FK]SSQɇݲP͕kq_ZȃKl8R*qcFh~ ;$M [jB}*Û:I2E@1ɂxm8xn6C_ XX9/7 "|j {XH$gyp̹DL$-~}>mK*qFZn1,ʷJGMy_tP'] -KU[aKW.K?NCZ `WͷB0&aB3CB}l& ;\d(ƻ@7Jw6q`nADV"Ѝ@}mᛙdN' 3 4k3[꼴ACD@=6\/҆@|t[r*7y▚zL!cVae6N:^$+AUunLӰ^W,nߖ+r%%]{6Ԋ: 52ǰLoܭϒKCYF_Bn% g;=][ċ;SGz-ƞ1.yyjxę| uLԘY/WWպ$=dl^YUn->􎧐;I}{ɔ[O&z˧\0TjfHNj࡬;s2ZXW1ڱfzț$㕜|qޖEydaq]ϦŨ7}®)_)\)+]3 1l.)w$u—#!QꤣvJCQ:!}E(S'(*LM>/ H+ɒ~n(X^r5GEk=m[~J 7=fV{T)SH]oqfYD%Et,[AoGRrqG[?&np s ~6Y#+ vΊt'<`PQ7Q{4S %-*Ƭҟ󌸂Oٍa Y:4"Yo۞w_}bllvP]ܚ[eP2?d&a] "m6}pk>A%Vpb xS:YCjPtiTXeL&UGM̹@ohaJd% }Gt13"_BဨQgu`=5CJWO\v:~"6Dà;#2bu ^w%@2]RC>I -:OQh+a2\3"SS@y9x5u|TholfAT3z[]y]3K|3p4FGpC*Ry#~VKڰz@f] W^"5cahnG՟"c,QP\݂9P*G#'sx&RZ5WJyS;90Hu$Ԛ}/b1JU 6,uyW~xʺ 4-]qzݜKL70M]wb-"-D; l|W[Zgck {߻m ^SH0d ca2|UYܻ-{Ⲍmx0&u^+\ cnHBjJw2v Wm̻K1O>N 3?z)Zo-ޜ["wW", Sn(:_ ˇX]Zc+mc-ĺ(e<ȇ TO| Q+t,DHmB7JH`~IA;!UjH~fITGL)-J|X״Q &\;EWűzB YwwJXUQTbAa~)Fk$zOu z4lЏZ#z_{반6LmX1{ohi~t7+,WA@N_s(GX7\]UðdKIIG]6U)kz?Qg}h/#-=ⴐh)M:M6bAq^Q4A:a™gX0 d C{RP J \D܃?)~Pc]Rek.fgpy j$ڕD\n{>ݷ쐧DzZ| n+!kސ*Vb?q"{z*Y1 jc a1XC-FRoUm R=qsAn&+!KXd,}*4{03gqW3>xt~ p[ ha ""5[6ǜ@ɸ[Mny^g̛N*Ȃy`=uTkkaHDw@0ͻ׿a(f;_;kkˋmIv]oD岊l vo ~)3'[ŲFXwB Df2n98"YGNw saJ`I̬rg9P54Cz~f9)r/F<V [$&/1iY0-yk˰<ě]fq6thwV4MLcu)SY@l~J/N>e(FArgQӐ ~44х/V9"BC!KDγY&Z@ 7yDPF2YtgG)Aw3ݷlLsXܩM˵r _7m]ƍ8ݷѬEsHBرa[O+5,(^[ Ի`lC|@YT[\$^OJm6B][Y!GNze6/bI"y1X'XzF1DF-}ȑQCѕ[bl m~PlX Vktsgc9,s\-UD<ª(\6F"`%*&4蔏ȊIPj# ~xRc]K57H?LcjGvh[C];5Y9㎽bLee!7@HY >r|Wբ}蜳.@[4?VgbZ`v0$` W (=ny`=p?:D ]l:X8ε<@N c@M}" 3=A{ lqQ p`+c2fz,A$zm1k [D{T-f<\[Wߤ~9+1L* \yGfΫNs_## $ub9 p _svOpOJQTpDG1 [OtW_;tGäıcBrp2[.39{yp;}59'ł%reC0-7'y]ySQ(v0 wĭA' aـCt/5ՔO-,,Ulv[&auO.\gϑB:bl.jQӆ[WKؤɱ['8( K]b0b2UM:Z4շe$"3޴WىiZot ~*<`=v@*KW gHq<ܵm`;}v[N[į6g WT|ƚ4$;#1Jk X 9BZaYžp "I?mR#De;;h%C|JswZFbXqB'_[60b.)o=&cX`g&ѳ2iL%.+׊PL" 4-3xMY-;Yp@%Z`pZn d>m48JcOx)WPu.߰d&y>2یLq/~f+ @`$xU"`=7\iw}DvmQZs> p/=qB;{IꏢۂBE$ySjΛ7^C1 v]6cSM3#~uJ[c߇ՄZ+.*?Z*K:PLrmI!b\Ғ'8`&JD@ )j?TA)xXܬ?nw1k^;~ ' >35snI-DjPXTosL.[+է,{PFbf" (vJ,~Q <^2Yt:8Z#֓$ݧ[t͜)@@1* } 9OF/p9b Hnna^ Mg %+|->Wt600M.cv;.)l[ Lu%p`(Yk(/|ѝ'wdZPY6Kh7؄yw]{$.xf@hZ;ѠIu@ FfKy03bM*84c'O"ON_JL1(ѸmVIQl?>~jiT}f?uDY:] 5/160yS9#Ksi꣑S}zǔL30Q5oV퉟4ƇYsՑ V,WU_#6htU|D-5_/lpPrrF+m~=؈+B|˶ *R瞀zHo aibPt##oITH^Uӭ=L>Bt;tSB3!J'YloZcC9Zt bF.Q@OA]{ ټA˄uhj&'Ƿ=1{V 6!q<'ؠ!z)$UEFƇٕ,D)0}ê!ZJysXs)AX;Ԉ߁r*f\yȘWƵ|}TT9DRڎ[V,: m0-+}7#}7+EۈjaUdTrO5#ז5jRn-aKhEڨG$t}3NQri~9&<q?)pKlAg**Aؙ3@Zi*͠U>/斄P/(=r[w[ 0 >bPp5uu"1WjM78=qu#:m{%U,O?TsԚx(a>] vzs;@o vҰsVOX\ZȢCY(9h2o#b*wu{n(4ftXu?6#ۯ.t hI-B,xϷi"d{.c%1@ ţ[dC.FtFFY 0 C# {ѺjDF@x{GuEN"+PG.77~stFz<}n M׎="Qo4)2Wkmuoe`K03br:p'dOv'w#qI_ŏt=u8 i;VŤ;>;SHWl+o5[ttEwMj^!pIBZ%ݸɭERP/Qn~Hy>_L5[ ׼@IM| <;9zίRB| YF\JI1@*QA`Afd.ʨo&G6iLFKygڤmu&ݱtl_n!jgEuI +bO HNx1Fr)(Zuڇ\:01\s=~(}rdCn {V8^B@$ш>'OjLFEfZq6 *h[/ 4Og|fOMv2Fm25 K$3Ib|9^?-S'nl7u7%iڹ Fۏ]~挹ҽygHNj;4RFSV)ߗKJ rG:~Ob0DF($cR5/{ƫwgN` ˯NJB5ZVBЙ} vՌ+ي 3  [о*ͽ{ڴl(4RzDpFFug-+y{b%N ֔?A54{ kw8%,&@D߁RRN}Ls99%/C6^I䳑J:#$4Q5Cl ?&/b{=Rf+̒и3N%5x"4 x0s6`.giBA`u nMRҷp1 fop,!v"b14}S=F_!̯)#`5 )fo:qx;Iy6hs &ht1Z~5ѻLkO:6-T8:~J5 %ܪ/kx.$KVCR-VM@Vi,ĕ6EyݺhZdm.d׷ZѪU>/'uO R߁Kt]) 4cNZ33JJH >g75| ֋  Du}.q\@4&a13e$>Ξ&<8%;{ps)6a3~GĊe@7J EA5F}%mW]'e!#$9rU96'Lz{A`qXw"M}yڱ\s_!ϥ][L<%a8QT4"HaNֈ=n)8ܴ5R>[է9EVߣyX t'DnԠ,w<㯎N+Kcb_}Oп8pd8jN,{ lk[g_lF_*߬4v_kǩ @qWFԎof!h1?cU_ Ȏ>pee/--k}wFAe`BLcUN׊=6Q- R3,%as*~fSfSs+us{q  kus3Z.#{AHQZ#vhW F[n;P@e8:N;tۉb?0An\Tڨ3rUBo*O<^=)o6kP$H>ڨz67|>պّU6;^$nɃW=f]S hYMebh4HXQo?RKyQpyVƞtg#Oq@М}(d ۈ)>Ӆ.^nN VUe= ?,CpjCJf JF;QÜ*]lE1p 8/b6$w]ß]ykNZ(U1aV$UڒՂ(^@mkߜz&x |/fDnޗzg\O ߆COt31]fft诃pd섺Ԇ@kav%`Fq\Ut@!܈}"v,p0Brdex䫇|0˙m9nSBqd5NV!xQ-VaK"P2ټ'&C3T*2B_Po)HKMʋW5 5ǓEe3fʤćm "S_MMIxd&f ?˸h-"#C6z<~/`ZQzE;v`{o<%7k:џB?G`C_1%?.O+b+^""rF۸ݿaLNT,fw4+&hf5 !3oz1yKor3EGةE>;Tx*2kFzTȿ*62H}%-OF8{i&[ XFmP qIaAG~=%^` rY,[LVntCH{tr)pp={5!u .iJRnNMZ#.~}hoAC`~|:+yvft! cIdhk*`I'ОY0p2kh7l\ꥋ^AT16^|v]A1β.$3UL{=8.2~wLf8^TK'̴*yz!K &`~8y'8Qq^3}F2$QʋdtP%l#h o!@0'H_E<3ڹ b, G sfwQo\GOB62H*jcUԘњ?{ןYWAwj )S"a 7°p`jGtIH<(8Yu4@G= z+N5?FT=H,9D% +Q,4|cBjm3I-f? VAcQٙA('c}.bB*عF:yDf!&n/1vSsR}b֐6$mw]Q7Sƽ fٟI5!4F{'YX4HJ@|M|y RSқ}=/dg' *^/1ՓXʍX|e|w pFZcsڷ^TM&l!Ug֖;}mحNHz8S?Ou77pµySz0,:qeOr.N&48 4?JF.$\c?{Kh@Ah{Ic1 )d")0Hb%߱5@#Eךn;2pG[KЍF ^~_Q02*z(eDOf&Z"96G9r8UUMOobچl NY PHHܮ$)JThF*u9TE^fA?tԸ8ȌLTL#@KǬT Xd"`6LB:!=!S2 o/*կc9"LC}ȏˢNdoĤfgmU9)T`*cݚvl6 G G| *7V-汶f"'I+=u<{cQ-cU1}'jW"їFhȚo[v0Jjqs< HMƃB '$[w鈸IqBŁ (_R7 Ʈ@lfDh ,Rw-]5SEM^9%v$bvwMGK\ȼGR,[<֙,4ʕ!hx"-IyLMĘ0U*F0 c\ "o+^- qU_Ȧdm)A{;o\O'{lb2|A.o4 ?.A?fH$,v5%ԲwvJ >d^J s!_nȔG'}F@P֊X7[Hov ͠ :;-w)Ґ/eWYՀgDyhQp\C,әNc :)|2}&$OQ}V^-AmC{g33R J:f{y]l/97 dߤ>ȯZqD H!2X/|r;WXfQFEa2xbk~!*<:L_"˨x ;mqWL ,DuCc`Bu0 G_Nhz*1tS>XTd=Rֳ#dDlL0:?a'T`ahbQj(tobX"RL ۍPh.Z]ӡ4Y|VgR6qwUq/C}(`}v }v< mףoR'^Vu>sR@ҫP5T.` нrg BwrwbcmX-m(Ӫ:1~yG&KP_1*7&B{|Fe;44xqM*t\dY)B3"I&3Bh[RM^c-UVLVʤ2$@m[$5Q*w Z K W!FoB^)E9}=',<ׇLj_` _o IUvzD+%Cuf0341L~csb k!gQ{',:xx_g{ gb^#2voַAiگ2UYMyH--[%iWai<۸iL1sn8:g|xI:D!APq1j2 IzƳX2m s˝&L%Q?]Y`, (烱*|&`ܼOM`&c9~!?} BO͓~cW0'z8Hd9-[i+#)5/Bjl{>"NWX`o l*)gُC<]3q"qh|w;SR+a'Kdycmt2x_VJ?vU۞[agcm1K7+7)~<잖:)3$ևn[UXHP@!C+BTdўLT\ϯ?g$ia;\cȐ3R OXxȏGHhA Da4OuOY08M옮yF7s,1Dqmܔ-0UZ]3[~Req)=kרa~e *@aکǝ AՐi?}ثUǑ/_f׽%yNQ{ۣgGc}%U2oV'! u}B4&X[񄐄XL/Qp5aYzg+Hfcl@܅8wތR"N:0"o)Pk}lSVeNY+RCM &ߎ'=cq]% NG`Ⴧ!Iy.jlHWlrJ5, )&1GԨ% 1K ids$VnllKV::*\y+H׹@7< ރN'<aDP[:}fƏ #D~4/lmWrXٷ/{&TRV9zzD_,g~yB:KZ*+Σ-NifEG{ϭD+TP]Wc K2QEf!JE0[0ZxMJ`+B#pF)B]ssLh< ۣ*\j11x]&v0U>gkajunvHg‰_ 0-aojCRԞ[uHr"/icY =1pʻ:.uStU5Q3jI'h0qP u^Pt5dn:Fݚe6q" \{,Bjc(2j:n~R @&\$S06vS19KjJOv~F۰Xs.@ÏFĔHI2v.U_Zǚ27/GHOݛ,XPSىz7ܢ"5=:b 3`yz*0@Өa,5Hˠ[KGgAꡂ::][F'Q N? Fe!'}QCT۩ !P!$zl3+\K{:wbHt[5?M-4 uӦMP^AwqmBq}Co-jiH95IUy Dٿ䤓mV0|5+\ZHObrej EXI2VR D^E}GH8xo͑E(QUy=L{o2U߸]uvh#d5a-lL+,/0yuGmH( m2X"jq(H. (p̽A5Q%˓C LA5,.WFI(@aN|kA2P `6G^D:_(=DR0q +ja]-ne- V= Oew535=Lh{pT[! Qj;IuD09^rMyM~xj9Rs !$WZ4EwnIgDw l8H>𬤓 ^q=S}= ڵW8nVFu V h4vPt>/7/V *zV>IvJn{('S]&KOM#~[Ʌ z@) ;4Y:X@4?د"1CV6I~x ww+5v[>F`L812ϙX5ۈ[ e ^&%N!/'hQ<2Ϝ |Ӝ7K[nRI?W4٫g W7W7~&E(!e?+gP#$xkH^BE]p+a2ֺ*Q+U@^.A [ER<؇LM\^;V]5or4=BX&QA2Dث a+;[,DCKVg|zQM'ӥO{BfxOW_cE;d\aDv*שcTםv1F0(l`Q 3C["B*f&ԝHnI@BgVמ]hjGNa~B s7x3\dm$ၸ]D@_5 c A݈ژ^/+sSQxVjkΗ]sW6Q)^˅Q[_ޞd?0L "G:mf> b!pIfSJap3ю1֢js,0}3[at^5'ۻyTj6p>/\13)qЧ5K±+{0a p^0[8 AxEc" XO+|mWavLTa|BԌHWVbי>1ieu9 w}Y&JCV a,ё金*0ގQvUhޥ,ijƴ 2{=$He jrpF8Wܓ.&$L ikΥ-4 B)\^=I\sir<tO=tY CPZ"鵜c +Ү7+$Z(K{V0E)xt K JZ i:蓶5!C@3`S>y؃GT`]63?W>@ITˈ.%_}{ ܲi&%dA겮LO 99m<纭!tYVx~^:[_2 )Aka/,F+iڝ0JH8,t|o?-~\ )VNG2]_R="l>ُ{MY<Üz{z0g _cZO_!VtC%UϠ!dIYaFoU.1c3b!sSdHQʱ5A-`J-{WU?e~ȡ 6 B Ы:B<7H% fp'8ܡ?(vdܣsYcGJ%kLaYiWJ_?0nU27V?j k%ԣc -,׏Gld$h[nZP_ pg1"YzKc(Q'b4r8HZ^?d&F91#:֠JECd{E: ` eC[|jjk*Ō罅Z@ Z?tZV6VŠ[|ש\_dU))Άw^йl^v HAZCm5͖{6,rݜH;qHoj FkSYQK 8BZ o;GN#h>7Y~w~\t.)Ʃn֏pA)2UVSs!&b3ΛE07]$;=gJ<Ιq# ~Y of ) ĂScy2gSdJHPe 8BW4?{s. Nw\y()Ya4o0J-@ЏwDW=08+'iD5`#i,\W\se Lym:b AbgӽHKPU/˵/"\GgN,J c$G·Y{DWޓx~rm]*\"-ݎ8Z,go8BMMNI] J)ަH_~@$g~~qA͋+et5$\O-"~>OΓ ?` E|?9F*c@M5UQT%:ax%Ia]EejS Axe-<û)H6hR^a±M^m1gM ͇jI\ P~4nWmmZ?\2}X.O6'Hl!SEJ|_1wi^q)/d>QI^nNjǩӅ|+1f9%bZv~> Zl$'MI߅Ш-NdK&`>o0Y\3+ׇI4kP`НYH;"hxG7˾Q򗧳V+c$$ \(+7a~`TJjҽO`3!ḙ oPK.CcX]eOW̴_@/9tXt_ɺ˨7A 4BlF6AK@ԎȱZ>6,SP 6zU{H ߯p:5F[]vB8S5 ;7Q\GC>U" `/oA"A<Szu*1oG]bބF$`R8<hbbgpcw@sG6l#B-2T8,;w/N"<=s<1LlЏR/^.sXy][ުa[ kۦ6yR'[=b2(`@|:ʨ]%f4Zkgf>dX"w̖v9=i}xWT3H[꫎ ]Ȍ7oW~%|F\f1Ֆ7І[ >)!qjA{E*XY59! LCʤŒUbBOsȹn2+!y$4"$:j_Eȝ%JcQh~^+Z6k$EEɃoE7G.NL)H aCE[u;f\}zMiJt{ϙ|`gQ8,^6SSÀ#*d=#]jVg\ɎO-VK! &GG9? ՠt+I > o,/49!u;pr<"{d]PK!cR|þ,:i-lZ]kj;J, z'حby6UԑK waQ*}CllM%Wvݷ}|Uf%1c,/:3%΅{ 7wL03(Do3l#u`W9(6+qx_h?v\" =~4zM9n񞷸?b2ENL w5qxx">k1z;0K ុ4w*J=m\bR.XCOEማ5;81hkXR&-*?Ϙ*s>a:c=t]rګ.LWŎ,6tV N]av3VFr0cA&-?J6;VbAp]g82=  >PEC$g. >CZ J[֋h|٭2p0My#6:`^ލjHw']ë14kqޘʁ% mJZ)HQ@&ys/o{Jxh =_.QYd'ڣ-HT|ax9@0E$'B0@+EilhbbT|E ,O a@ڎxC{@lHxAPYݸ q/l ]8۸Y%T|vKPp0^aǢ4ƶsLsPrsz8j\!}kץTMW]!əNFk FKiG@:쀻/I c8V*~u/6@\gt Ńf&$ p8_C/@7OR"_$ՉvQ$8E|)BÓHHZ٬+RHzU+ G?a!~lK@7B_- ]~ |\_c|u _pa gj(SMT7jq$0QJhuK`͏#l_{ lF 6(ZGyŸ뱌gJ -O(QbjyTp-k=g>qAukk aau}FyH">>[BcNӇ@ߙKf ɉ2*N-Uv8:AW[ Ֆ(0/8)T441r~b+#I Cd bN_-&| MK7>žrܲsDp pE|P_J,c@ޗљ",vqwsRGPeYjv';an"/uͣ)䚇y631Ljj9z FdD0QGBZ36gTD/kKyBaG.]Q2SudTZN+eQ8䨜G)?z#,Xyo٬%҃z‹SМfO2G(]KfЮ dx+5Eam7W:7՗6`NFϯIE'3-_6@ RgB.dkwi¢x36]xX LTδLLywN]\q<orS;{~ԓ+3Nc1tEP\jMs% P&z,8t: Aq]S_=MZlךsH|׈yB=:0$<1XXc|Oqe1ԗg}>emnyػ,$fLFM)^+AG占 U)5t{ҋ-4gW{+9q3ҴY;U݈kgوiD{ñxs2Ιv@4J+1Ţ}a5#`KnRqS[K#m?cHTDI1n($1Y1gc0 I GqkP*F**7h/~Me4mIK G *8(SܶR}d R36Ll zYm}p2oR1-n{@y5m`DX^)BZP2]x6C>wR>ȁZ7aW=}mCټ0D:끇.^ :/ Z2/yHԱ%@E7 @$+YIV'PTdB^s-T%ZFyGxZaAAZm?h%5aNB%G>b[ˏoLA(EyV{{۔iFh?`0l,DTf#yP3XilE_M[ `2>H#HՒ `6# ?[X:TwnQ-~ /ĩ;Yо8[~eyd!mg)GP#?]5Pľ[SU9AD[Kk=PzW̓НR,6H^-jQ8Y+a +)j34D4=:lk(|ֵ5*04pV Յ߻=/t/@fţg2D?w}#4x&|^ᷧ7FAG* /7 Ș-Ipaڨ107ipT5kDf8U}e|ů3΀*A##֨l}a3z壇ȼz< `Ǎgϊ,SL}n:Ӥꙝ#0ȗ&"kG=5Br YXl% YތfºzPӱZx(N=$ TJ#;/"wlLk Pb}Ne38f!V>Y^\X2B@h{.o,ΉÍJw0` Yrqaz7S]h[md(>2Pv*t?VX:FW,}۞-|@CNWKZn`c5=Pj#s]!-,#2^dRC bt\P)+}*z7l}~#oaT ΈBj%4sc]8+YumNjA?L`<%A<Ʃ:pI=J5}G?@Ear5/dܴNVRtnSM%}e xajP\[эu@%r)$ g{9 Z\Ά̽<3 9h(TԞ =~yap_fke",`6햪@G2i6xZzk59ed3_,+8qL@哟.R ֝c 3-k5a\n\jUMx^/Md m@YFp/F_OVCfۥI 6 Yo)8 /ouKV&U6Ɏ.m=mm$VnLԇ۸_')!hq@piLaSYGPii4a'f+]X=tC{˙6,Z]|I0B87S㛴;>B9~Q KlGS#YyE͹8cG@? ~-փ ;{E괞;p:R2yc2ٲ WF5S(JJhף ~skp&Dٮpӷ#ݟ3wJl3,z%d(0l>,vwsqwz SA澽d;ӌr:U xvK}@Et|ev|>)xF܄%ȟ1&J2;J"l\v0$q\o9ֲUOZI T8,q%+ U;iBxªz0H?4Ϩ@1qKFcm'd(L1a+ԕ<-ni'V{7yfc-G(X4c{H}S9tZ:9x+(CN\hp _)\ ~ts{:˛| [0"4E~)X L`{9mR2I#@ԣ#PIi Kp5D Ɓ}Uǂ;/tν;1c:4h4Bؤ̷6DVa(F[ܟW #00V:[$@mr PPW"j]^3 8+4*eXiʛj:XOhZppe=VyEdz*gG7hR ŢQL&/uϹ9?'S&ɽ .ldՁF-X 2|⵲4Vac.izSW\w*4PSZQzZO#"`8>t ͬbdSUUP_.BMnث]d. HRDq_4ĎmH>K5]b Al 6~޽Zސɉ0:a.ߐ5K-> *]j8q׺좬h3$9J%hG$!e?HD>0f|UU4.M~켆Sϩ<ޢv~` "o2F+|K3)eOIA+7'V(wx*r]%w 1mXmTD`Q^oB@ՔEdեn@} d?@*:Ep>jQkf9?)z?uC8F7*oVb=Kv^А8avdz/%7493ۓ+8X ό ͙&k*vVe哆iS4z@jK cRWDbls/MӲFArVS6:/jLRB=XU?%/_ϋR-Oa;CI&5ZSΦG4 mwuR'H8#csGܵ x |f! eDPobgJday *gFw + n;6싾X9bPI C7ԎxQ=T֎}//T.?7 1~p7{lYxD+YIhlѽ<#/Z%²a?Wn&{w%D,3. +g\ pWO $ʐVGQhܛ80ׇ@CFxj<9#U3B2PeqWqAoӳtpjAw9'fg_'Q`~栏UXcnPOW!)K]!CP&~>L!|'C#G*@8/@n|Qxԉa)Nܡ!;*hM(wbݑa$Y_BElCD:GnƑ ^5/ADC9lЛ%wƏ5&Ps$sqe1`PG(3S6ƁU_/ظ1J0@CtPuʘ~!= nGzo 4gI6>;~s TP>D\{T&OL=]X;#* >p{Tm 2DBRîb' Mt;N9j J%M+qvӛq/~9[\\iF\2,)[8yH]P@EzYrĬ_|қj6D|A"9~EPޚw</-pلphy/)bQdB: ܘ5gnl^Ak*O'Zm@W]aڣQD"l`e|fE#  tIC&5JI_2TYF  ]"|yTc.nd*a0ِS@2jk̀2ݵJ'r]H \g^~]ݒS:W1EﷱA;zgx)lZA,O=m=- Ey8 0?9{|*}2Kzj}ώv&~3!iq&?f}TȠ9*p;ÍLc3Sl0 !,+!:Vظd8zB /BOGV26#x/꽲?P-;O-Yƽw,$\IWKη퐐g$DYv|1onL=],[Bq~UˀWkuz˷&hxaX;rvߴ+y8{]|1(Y^D.4M tWCC(Q๙* o9`17z ڇbks#_HP 6zdwdY0Qj ܃oZG:nIN•̛NOp C- zB:wi<<l l@#]!+W7!K]g Ԍ`5QmzyJ@2ϫp=Ԛh Kjұ: \Ū볰QbË+i_w6qQ͉'C J_G4v +>Rc{(H7!M .:+},߹{9ߤ@,6fc0cG@뮔dѱ)`ܸKw>o?n>og2J0)2`6&Q i赖jYq5ih^4"m9l'Hؒ|A u eq/NL]V|hr_DZSfOPT3I]{ Eъ~ x0mnl˻N(.n4(o*tY.dv]3ݥ~6A6LY qa\ks_Pn} 5N8khN}U*Ev;2}a)Oߊv4=rDn?}e8S|H䇉/TRWjk֟b]'X]}RZ1:go,$jr)[+GBp׋XݴB$?emѦ5t_AI̦F2q7˳cܬ(șy`g f3(V+ J.&SEcDfjD0+\vIDnp,GL@Wӣ^Oi"_.k0ο]='t 93)TMvUnlK;WΟ1\'G0B$G5!B+ns­W9E@]qCi.~u\qEg']4 i7>w} /3ܑ8)(@'9Wi' Za?L5++wlXj0[#R}^#(,9V֛f> ~Ϧ)〞=lgM4wbϡL'g8ٜ;BNNm>é8cB'S)ULJ'{9ȾYTCvtSqLz:*+^<DcN32m_h~n`\n}5V.Ff3À}m|4m[5޹vtUĭ j4 nx/^E˞^2ƼriS]nGj~S#Cܰ_Ӻ ocb$w8=&1D[vdA1֓#,PBpa5mSbNlًK2`cRk_Hﻥ pcpo= s]T(C("ă:=9Ϲrp擬GUƽJ &_ |B!=0iyEm.l_>_#xYnd@e=aeM('fx<-FM;UژEHy9J02UtQ+6uc :)'EFim$T8>ԞGAqYhJ{ڛ뉩Thg/H[3Np)wDNF+1 $bd~Z-"쾃M =h4Ϋ@;{w qMY9֛oŊnF$ITbەb .3dϳ6ph4\fO[woW3Zۚfk;tkYCA{-㴹G\9VG}&E*_snڊ/ҡQIgDxSLЊa 극 ycbf{ߑ$65 M.E\n7a"MԛF3!1cY='LL@ XNd(Ӝ71&;qѲ5qk0ް(E4 \6 ^%I(u7 7n{76ю*zЂ-`߽Ȇ&ncw Hd"Pȶd;&@=`66Xг&zijg^BEDG j#!؞**5A>?!iIC`g +oMMہw7 u$ C.+I:F Rh%1t*i$Ź,auH,S:8wJ$ p=7諝2O;'qRϬEw#]cqbn+u{ !l{bg-7Z H#e7I:]UlgaE|*T{'4H7fY#NKq}oi g%o2R{ƹ󬷨ʱG[Kxn7b1= 'WZݣ>yTVMqW+g5 QctjNטzOS6Wޅh9:gnBa)a%7N Tc ӦK;T`iCzmEUO:)WcV"{5 666P>V_$ l!еg/a]b9SiPBQt.Xٴp t&%m39*@xc@vlzz hó́y~q,==XW% 1Xg[UfǣI T9`SaPQC$$/V+_s<ąCwqyMjUJU:}_v*sXV2hb7)m4q{T,'aZCa$`HX16]׺*1׏X3TU'qu2bȷ'y&2Lb;Bf)oI[cr|͢ʴ7T# ֫ Ktzz7Nd@a_DZAIz~CCVwxT,^{&l %u#s2Կ֤}|{ IZӆGV,ʄM%u3Us{Q]s)u\ b0x5wjf)DJ}}ĬDYNuޖm4fMajMɟf=qg=ii*QZ :4=I_ w2!;lk{Q$:+n*mJruH\94>"QSVd-OW._v(dE !;dD Šδ)+(=>{mV8m(DQّ79y%&8˘=!j5̃݇۷?T.wKbolY3[K5k^jmz%AW񉴂;+=NOn%+Bwq2Xw4{`#%{g ߟEZ^&bq/5/2qEE/x\a2K.Uhr6(\;>>2K8'm|REzVBͼ>33HT'ryUoYSٍ"Q&I$Xx4)8hmS[kkիaMO\F{XnU6OgnaketN¹ J<܅ Ye mަMBH:ec8\Ogm#2 ɯLP"zYOOfYIc\/iZ 5s˱=ŇWSe }3ΦGZ9fMq7:-:6*m̑¶*[jvmy7v!5m5 )VGB{Y|kHyPz'邭M옷|a)L Y0Y7ֺOc/O'bS(q*.1xɜ hX!XL=(8h>y=ca_lB7 ?%gٙKBzí6Cd`aoIхQ-欪e09;C0 --=vXAAa$-m#o:̫qQi{|a~*cr뻍^c. (,pT?<6 qȐ?Q%RS,Ä%vzeÄl=<*fq6&x\"D9(SGm7z`דPEwl_&ԘmjpϾ6df 8((x58Txq쐿ȌشԠiD9>sMC)jD&b"&Q3z۾Cv8/O'ʸJc mWj8):mK,p52c kIs8; W)HJ5t|;QyP/,9,߄Cr lW8>ku*~SF΀cM;8 jT; Q%Tڤ*P)?Q TK23×&ФG)9-"[X*HHa<?L/gԅ"~:BIvS!/3G |#O5ٲ9'J+COKsc؏+s[:1 T+ζ (eŦ^Џkr+IS<-\HYp#er2բU`2pP5㩢SZ+ᰰgt!m4dTދ{Ca8 9j= #0Eᾒ ~oXd^ztjkRqP[OI)=u7q0,]4!ԸI{? LYv`ݡZi Xtn`3%,J3]GC0eX^RwO= Λ r+9 `e"ٍvte5@ MI3р`6E"ɚ0$k~;Bʪ/D 8B =B p7\la,qW$p9l}aث^>dfUW]o^]8~lp ~azTm`铠f)qΛZH\EJCpݗzr7L:E;zcuG/B e鍫LvK.;ݳ:XGAy/[r9n ʷo$$]܆(׊ ё+)%&`+}Cveș/2״V;s5_w(<[, Ӻ{YvXtyPI/_4Ϋ]%  P~]*ҋ6a'›(/ʜFVcʽH= \:wPZΗrVZcЈp` [BZcAقdFT?iZYWN_N*#M ˑU L=~]znW)B~\xs+ Fb/CI>4>ի Y!\D؅6RE;̼&pn|FW[Vs[.)u%/$5S ɐN }KéC9#o ixZ}ctзioֿ Bܸ0pZdbpN𒞆Bq[m9">uR@6$!3i4Mݪ2L@]3"wstRULXq#c_Fj_.{+qbuAj l;GEJ8C&$M$)SHלʐ( #~( ~jHO!WȒ(.sr; ōxfB$aO3yGƦw^+_ZV gyJ3h4&.}GAr{@s`t fS1([EPbn]J㱅t>Jك5Tj=fԟz*ңI Jw儑m$L8tU׳ql є~xB +w5:q[<@ۘBNݘJSW]2]L*ΒLSi9 qg]#8Qdi3^* _8r*e t ;;F }f6*9AlٱFl@gzY3v?P"3QSFvWVNc' KRH] 0\kV]mtnQZD0%A]:B;@FI.JP>_]ZL*liw˲71mL-1Etdˉ JهL$d8sN4͛ߣUEɡdq0ߒfY5(a0 ̓#ǽ A>Ն{O=# y\0 Oʍ s!Hp$*?$$9 i`ࢬ̖7Jv_ D娎Ha4.ZDiq2kxj97PЬzZN}# ߦ2H* ["*E[i0 ޓOWs3~[NbjBQ.MPzî3pͥ1k301DsYOh}UirMmq~7mO\k[Uѝ"W#?}cPD,b.- i$O$%>#e Ml5yp*er;Dh\Љ"FA+|4;?1-ynʛ \WďFey)zPoko>UpC=4tiSP:,%݁jF NAn/tps +w:%ZMG=\A&%"]$cDDMa '!QF A|?\mV14ܱ'~X05)^5\ȨwU~lQյJ-bGPh ^\IiV_a#MHg~/GKJY?c>asݳ?NqI4r2aR:R5x}81?vUD5e!jg6Npm) +@Fn|19ô}(q.tl< {V˝{bNdahH1;Rs DdQid}0BQ%nD|}r_[Sn `QFFbNRК`l|C0>' !&|y7|5ANkHR&إ$X~EBKEƾ }msyk2Ѥ6Ft{ c>ެV|1Rswf07*xW"EO[͗7$j(onLݝ`aY,-Fѫ` yf٦zfҤ W$wX/|EOz+`;Ocn1ޔP_|$IP2)qB9Éc\"фkHNG/2TD"35kRĩ"oj>W`mSm aD TXWzLx$'n-Y# _7L"NĊI㎆B5s/KΛ{KV Kx̢_i6|':>Bwb^bV4+&5j *z;wQ*{-I%+"L/6F~`6.̫+qY|w(A( xj};\s϶cRT'ݑvz"<`~^}Lt}KG:eDi5%` HC}fZj+NzVC@}hk^kgSg܅Fd\Z'{{ @2MĥZx JF[R BtGzsmϗalsfŶE;QߎY^_,F#d곩攷Pg?ف~q-Fב!/-(դ\ 6:퍲R _1WK0v),[q pJqc{)z\ڶkD4 .wZ5^Ik75V14|uru/FyWؙc@̻uAv2ᙹȐT^?yAkçY~"_*M诺 *C  @fhv;DŰ%=iۆ退>Y$)En<Y p9Ֆģj0Z0N+27s{PT u~ܽo9LNC*A{sE)ず\Y$gcc$mٳ$FmwSjk9mLGz@VVҔJp"Tfb5!! 2^\GˠWw8r}y=Y[<vC#.)d`XZfѧ,Aݳ΁ ƒj!LXWra~c.45w2ۉEP*>$M/i~Ff9қ?L x$=zPt2J䘵MexG4O+[AQ4FC&K>-eeG>ģb8h*DPTxG.^@1[t ÉS$#=.,竼CO(h.=]Y +Vdite}{_Rv6_& ?VS"c݁ι"|J]x TE~3Qʇp*ɸ"lRaـCwcq3fTH޽ B֠9ٮ//vi_ K>sӋ:FF4cڻW9j*r4m_S&ﲕ׏0/IlWFPK֤S־ sxEyn+n:u (r%Yzdƞ5wKYw4}f<%ؓ}~EEٮy)"$W yc(?be~/yn J(SP\M⩄9˧OO?[WNj'['ݗ. px\.~Hr?p[l 6huuQv,s&!\TOy R @UT٫?@cnt~ytDYp&騔g ٓ`[R8 MWn<(R;iV ?˒^)qNY^LNfsvmɪ&"1 e\{s6r+*?I 5z$'g4st?J}聿>h*ɟdg%ܔ 1>.9e/eLU>o8pPt58ߠ'7 [{ edڕ5n g}wx1wƕÍRQ\Uq|X*}"/1}M 5o*x^po;y5BE)hz5=n]DIAKVW^M̦.uw _WMȪ}ӛ>U%g ؾXQDd? VI1Z'o %,}q=]9H>aVё~< _d  v>!Oê /^KY>5^R~Ffr3%Mbk֚r& 9ȡ;fx#.>R4GLhlbWzP:\΋|Yix'P6{'w]DL=5@t CrBNL#tHu:m_F$)+\ߪwnI0v>N2qNZfP;tWS)ȻTk7̉PbR!pв{s[Geɵ]bWe]iȪoH%\xAY$rTbuhvRYfXߓᢟ.X%Mź%/t'A {鵑w(} -fk^E3XT"p Jx2 qyfOrtYI$A˟/{>8eWTz~"21ӏ3Y.롱Ff^(GeP)Ysν,M7 ux . 5_V*֋9BwV2C(!5e pU#z+[8j9AmӿbJZB-Oƈ 0Sk@S&)lbm5KGlp_%UDžg[a O×uY?|DZwу:Ѱߛ]֠OAF0,uњ}lqeJX$ ' Z-)SQX@Ek Y9NؑliA?J=Q-j*[-< N` pܲ8 VLrŢk ~*e;6.^RǼYXh!άjt z-' OeഠP!(\.Lm:Nѝ`%Fky1 6 hHa=aQӚ|[N &z;yh]?b@PvT)jOmD+_+}uYz]M5DSN-5FkՆp jolX.sPUg x:%%Cm3TϨC:2<~祣Q,fuP uܩ>@ 2_h;6ktJpCߐ?e&^;$vJa0?@bɤ#ы [n@9J-h'U/вoRi^W;_% #Ρ`c-l;?CCM;P-7#p=>)t\s׫!KON+ ]+9 u{-p^WFEq#٥I@RlVY pRa9?IWUi0LhDLG,H;JRgG :ziZ*aE?>;+^ɼ-!HX=5W-6d׈YZzg-\^kN&[ .R6 q-Y MsFAcOSf{E p BK1@JJTW]T{ϡdܵ^+z OXq<%% yp4` \4%Ȓ" rBJډo&Xb*(!]7ɴm0^i5"']! 9IP"R tuMh(6f+nqoFkA{gڸeT^ANr"B;\a I]Kd=\ƹ{C DPɽcw /nBRgKK懱^kt״!o'%ȧ=$7_j $u_WmC[ː@cMaj.#S; u;LcIa-fx8Kzjnl4SV06og35\~q7ѓLB)g P4{&,J-f!u r"5/IZR7%ÿBw{'Ke{p<_N|3^ {ɛZcf$_̩湮Y:l}Mn;HdwW%I30$.Vr)7W j|4x@,Tdh%<~F(.,JX2g yPfs8@AE0΋id`:Jy'ԮEհ~| 2g0x>/9=-΃т۽|chNn$Vܒ^SArnʵk&Uև3$;i$Z_Ce<>mM:0CUV\޷O՞1珋e.cTa"5 h+?cKVs#MFK/UZQ0~awf̑I:odV_mѵBP滌#CcqP^mZ\ozUJAfŬ_r=x榃Y`r &1cN< B]Րu>0$T=BqYI[SbxDvp,E z֐]Z|}꣜T@κߦ"Uq\e>d?ι#X}WC% a[DRh+϶4*lӎRۂP1*)YWw#'聺+ESa7ٲp|VXk^[ݧh/K㞽/krv'-Xd5p>hy:.5Y^ ocҫ+yOKA>qxP)#>/٬}&4g98 1zo2l(U;~gY-hM DnԮ>wrSV*q͐p#9`N}6Q4W^-AEqKcP l߷ÆW>3]<spu[m͕ZAAg<:sy+<} s,Fes[!<]g.;{„9uX'Ƨ$>؂hT{C(koV*!ёr$˴ PBKJ͏_x[2Υ $vHD|Xهb2@%nO^W[iDV3W/i~Ȍc~֗yeeh\ F6ʤ?'`˃mW6D{e{VfFqmW#x8W^~4.]"pެ<tEq1-I:"KEcOqN)Пw\guz`pQO"ьW{%ZTQ3Xy>* 0fԿrQ0v^ӯ :*T˟P1c;EQ < qڝ|O2NVOecz)ndZ h 3 qk6?}|* ^P ?&?`۴{êҼo* lE܌KC2Qht,v~H(zTnhVzt{0z*rs 'E-=Iɬ:!qh@ܑB`+d`şy'u_M1P 9vp[&2"q#XxTMalyV-v폽YcM3 ,?agjakm,T YAmѩTހ%@gR I/zNc]̨m{9+u؜t'[~jL zс̠~3mA-j:krHMM @dfF\jʈ@ˢBr5cҘ"GẋtF(X1ɸD.s[jFL]e?Fǝ<M\ ھ=VC)o%=cL*+ˆVH|?ti8B1ي̉O%d%"`8 IdX W\#.;aSS^ L=NU#`),aom;Km< :7d.t;:f Sԯt6 -B].6zH}3C0*;@#.Ov1ؓ 3(`gGC+%_Է;@r^d NӬeV>ָ(s9ĺɡ'L 59(ڎ|S+= O_YpeJUe2(< y PTpi b8ۀ ҵ [2zv=_}@Sy5SZ Dꉳ!򩖯].5ʻWsLOFz& +R1ZQC(TsЩԟO>k,\v71RApWR:tY}Hp5>Aau y?KrjS/7WPlM[kW:xYU7x! e^ x9xnk]-f5FQ> Mt㷈ˢ$8G ŪuO6ɘ|-]fHfWչRӭ~C*|4gZoWjz;+#OLЎV,~jX;3.sS}sK*K/# O%@{^<=4+HWڍN<${ " YI[齙Ŋ Aa>mDay;?*OXl%V=P@\l}>DA`"өmCW7&'~ϰt|*[1{4-v-@:vлB&@k;GPUH ^%=1[}͍ BۍFfrD9#Ư᫉K # $FRm:5حm1&FqSk#'ĠgH><. .[+?IF9Kөcm() @ ue<#Bq(+:[w9&J v5+]Ԧ=!%VqX0gH8*h#Q}su rNJ?ʬq'-IXq^{_jѹK*D &2Ot)P`r'Ma)M`Q?~zR2;:z[On{xNbЖi-zCY9+.n(fqFLihU Iܫ#9@qsշX:s N9;%i+E=dZQ9eZg^9Z4'*ӰW[M_x,p{kh :G ޮW []A7Hzձ̐ ed)'ԽROUߥ7Vn9[ٌ,:NtJ s_ x1^ڦ%UP8' }Ju}CD\OݲGz8HБ+Д` ?:G Zj v^Ԋy*&?jh|d/bu$g AR=QGHѴJ $u҃Tpթ $[)6m=X m?l[6J}gK!w?LK-u=Pv-!ELi!!|-C uk(jHp!vKi@Lb 2QvD֐ʻOC#l:B: gi58B|X.,K8p V%&+Yq qCKnن%hRZs{I("\fG=V&ש}6bUл8?1}}dn>FJqW^F~E'û& [WId]^ժܵ2!G#ƝUlyJ׮1@g&j>ZtW^!Ӕ9Oه3v>|U}t;(;N :3@oUUkO !,=yH 1&$-{N$"+9c17 dvGu'&j}J'7_Z2f=WlEZX] ڷlf657t, !C{2xSP@!-P'9Vd=|1慵h{JAЩc= <Z*,%49ϔpY٢DD6wC |MQ"d?KJ,g= = MEs؁썚џݨ7yRnȘN.\1{+B*`5ܝRO[z!`E:Һ{$&޺=i͉y =nRqw=m PRYޜ޹0ل@3$,1YqPj!\\iLrer=Ńkzi_`*qt!@w&~zp6> oT*ZB#,#tˬb_pUvO԰=0|XvJAMEHTΘgS2ӆCۧ WM)d>d.6r*t+;<<6s/Ή(6Y݉,!X!ӁkoO(J9m- x(i|xAO;gX+Y!?R?J29En Z{U O!h"oNJ LݏR 33X ʦ ^7ҢKKgv5#WLPr؄S M̵B "b}[$eNB0ti *{f x-T\?.k9ed]jAo\ז>~ D y\Y JɪkƐ{Ю!xA4IVpM+>D1!}&̝傫UKlQۯk- Ηb9.4?tK' @ O3vl.j8Z<;;p ^/I%#+bXҠ |‰c d!6hOm}Ũ%$N?Sw|>͔B^On>5h/U }`g2^9Ffo"IÅrkMfZ3.I9 Us4w<rX WM4Bf6v 䁮o\y zn!7v$ |hnL "S;x:& 'N*ղm: UE7X"@{5Q3X\JR;qX=1o9v SLW{t;;( ;j)ey& )jQٱЧ.'D|ڙFCXI.G-TY Ǔyp='U X'iC Vrb#okuKX5^~wߟL8h$ Ftu$U(42ܢ9O+R=5kl=k?R.*g t/`|k9> .ޜjė͞(n.8g+С=H;A4@AoKa_!/5Fgt=(&+IFbG|ga3lpk"N[4F)vFjij'RN lP)66Oa{h!BJt+HZyr(.glHi͉OWN"hKZB#Me[ O4N&X%~'{*p!*S<[1EJncc\Qu)!?&^/vD{XBy+l+&D- />Ϡɝ ~mpQR#KFj=x!Q҈"@m)u-s}8Xi˖.Dd\_|FQj> f_u**%_xxD- )e챥) m8ӢYD+Vԧ!(iit ܼ۬ K?_'+ؾTFu_h:?dĎdVqb\lE[)ƶat09"!izĂ$ue 2C ʖ#Ƚ8a.s׼/0[BF1nD~-ãe khCa MunC a'PK dtO3阮wt]T/;^͛Ecb.BD:X[*L!^GAyx*}&ӝ0}<$*ҏB E}l쭖 ҼGNr "w{~JhLş1Лq/nt b>]Ϻjx_V(өmw')iEЩJֽvpqZ}1lrz˫_^|a`%GQt@$gW\2 CK!5G'5Bq,>3ll_ٞ"^ J#͙j`Ԙ+Ӌ#$Q:_˫ˉ4f$tr /v{}11XC6FNJ]_0(}:yt]gO,S,J|4<~n}(8g3ji瘆 19hsBS] 3ѿܬZωn_Eo[V*jD2eQ}Pvﷂ7rx=RI -eAFԦ[$uVpy">舺kD]6,'^I1m6$]: T__r+X}ltOF0 0g+0kA .^+@w둙l q'oU?S$Ω}F&d= *\ A[8u"I,?=Ǻ4o.wQu0?Gq48ӄic=gx(L8:z*A~7TR>Hއ&4YihSb&ZVR<ΐ֚3N@ *6G.ͬRa 8hD:!&8tIܒ@FIRZ'9azW!pOc;'zʡ] p hrbh855m,y\'fucKc]ˌ~ %jx@ōͶ‘ҿ1BV|'bE3UnO˄f$Tr. S'ZL8ob;so C;aiEZ?D3o7>c +-fp ł>UQNSPӔ_V/[BwiԖIǑ1otaX9"^͌צ}S]xvS:h1l<ѴKl6%IJ&kgOŊ{Q-|ܟYb+=8y{6qګ!V.l y輀?}љMr}Y${馰S' ~M~*)C1 ].y=[ܤkd1&e\K"?~z#c.1(ϐ0=VN_"avw8i' ѡღq>k.+խToy2uٜwyx+'4gNjc1iOfxKvn 7pck@T֍ãEjTl4"}[V~PJԪ5Tdh`#TT흇S#e5-N\PuY;xH'rQȈcM-ޕbM[dl[=v%joyqP~3!:L>:ko)?)jKP;RdI i*ϧEyS]H_ʁ>e0ܸ6ˋkuځQsIA4w#\lN\bf& w m_>!:c豓1rD[96:$br(XhCչ8{_U,<w 8WC 0`GjJH5koGEQ0E ׽Mٻ= D-B7 5aq:/v2b$\xJ푙'-sE"!ؗyTE6Wps78йf8Ԛh$'$!>e.\T-金5i!ćw)ZAЬ[107tFpBm7 Gڀi)db {3pRL؈K^65Α'6R=Uw%5 ۑU .&x@5[pz_6Y㠵kB aT2ػh`[ O~f@J\QA_2Ebar0UjQMlLQ|ơ'VpMU" Ȼ,rt*WdHVlF5 u)&ٍb[`P!t`{wuGJ`Ԏ'O *fX (ν+4!B0TȂA;P P]x|?b CCǃ-uG~FClD(Dr [öjӈ'~n*t$**:.6,VT*_Ʒ1DWwطQeԣybdLꕎ˰㠦6&x_1a~ߒ*1/*NbBQ/ȵ(g{WH/ H&G]^{`}û9ڛK΃HBiTwRWyiO#ㄥ%|["/cmrѨZf;,3s}3#'ULڝv-B0=.0jA9*f WPNy|=EQEg$v/TpSwv)Dˋ5э0Uqw=?73szs{;G70pҔMܚWFyZM*17?-GaI l[q/޺fgc>pVAz&Y5>{X5_FÏq{թʡeP/!Wzћy|NGC~ RHL3 $βN)a ^ iL?6t8(͝1"Y( 䒖UŃ%1I 6YkVܘ| \ȕƒcKPs6Fʘqoglk/~Epab_Pρc^1tcy`P>^c>垺!_NGk)@|1*s Z_v6_fH+SzFuؿ"@V~F*}(/P 2N%o-ԵMt&\aD)r4љR6PߝA~$䧏Q:D.IU@%c!ByhJfƠ?[qs=uH2BS<%6&%s9)VJP`iN}M\}ף[=n63DocDž}! UѦ$>( H]W%o7lT = ǚkcnzo-YpZ*/ފJ@?}Mm1 ڥY<-$9$ݬ\5H_\U*p9tK} țqv6DPWYGl?Ixao[PCk{:`ɩބpqk唧w=hZJSZ'׻ޖގ?m(X6h VSMDnD~Wnf(XG2m| +ZDۈ,od\pU1q`,:VP8:V/0,I)U85šla{H9]KZH V >Gc+_/9~ω``Aʙ1ve(M6rA #Z#bs,Vmؠ. f Nm 6+)EkU1;s<qPag^?!WxY0:u;LJw2—d8+,qثUM9hfJc⾰!s=]xuY,HƸaz4UZbE8r/] CL,,TGiGq7. x_4YrO_߇I7CX Q~ YV?֯~wDZB4gϾ7wvAV8aۜTM !6V*Qڅ~}V0]kqttO鼨Sg LGCk/ɩI+j>!k2SX :ۮb:6l0l^9(o L>mWHԾ l="GlVpe{⯴O jlBB(-pyyk`Z }(/O.Wpuv?QV69&$ԍS9耸䖥Rto %,hYt6Sf9橊G/Qp㖪b0TUNy=pEa_7$:u&w,v -∠OFȮI ly'THe"u?x:&`Z͹!HJ qHDbdrmOUr0,arEP8-^,4qәLG_fc2{frB m:WmsyaO "$ lH <?NQX`^^PI ?I0LmzPzۓd?ήU}zt|G /p\izCJI]%}ϪboўC2owLEN%el Dڒخ.Y}\eA#.*l,m![ʊGT!ei,}[P6˻x!펾@:~#ߒ;U2r/h8mλ4%c]Rx;<3Lh=U ozFba~ʙNKql(}իR5_wh-z B5@a89 ȝz@z8o6Pa|1̢'*ey(]ױ\*Y0q Ѻz=g ʖ-~<84r] [ ӣ0T |K+9*DN%UUhi6HNf+Zdt*prN1u(UO|^qBxe˵hp3yKTw\.BNLҷĕpb;S:8pJ 4VXi/pMVuv8f✰lon e.0,㷅4ʎW{Di4t3XxCd)Mc=t?=PDk `'V l}^~;Ŋd8MScuʚFI;>:tTSt:GQ2O9+ȯ LǮn{vU}Y+T?}hhx{"4Պ3Tڸ|!iW^vJL9m8pc)=|P]+hC[y |xib]2BAr ܘ cA9z2j/yiO9-AZYNpvE3߯&GظHS%k\HY-0K!=N>%sbddJwe aO/:Q9V_ހZt`_0fMW|!q/p_&$IGR=jo\6w<q׌~fƠS!QDWkyEA&1(5GkQdwhʿλ>^kxL{G%M ɩe~#RxJYZRS&\֏_ݒL@Z֨5wy|,N {4 fcj ~cib3Lrᢊ6 H"^²צuÄ)v42waIr$LcܹȐ0nPkyBJ#ο:J9$C9e Pag#S(G4)f,/CL$lMh;Co 2U'>rcOSh^bw+`M9bvT،竿?RVаE˧iO+r9@0[%Ndp?7 [)~C|O!Gevi7Z]j/aZK6xbvJCV_B3w@|)^6'8DY54Ӗ>-n2[OHVi615p(M%z:2VW)o1 t]HT*t䳒>=T++0m`z,|ۣ6xyShޜ<>63IMx( m?;n`J܆\ O'BN*@!I|zz+=A>gάA#ma c"=߆haz7AFwz446J#59?7<]<򵃋+݅Gth bV pnh $깙X9}uM&ΩAW.Ä9 x[@K1ar;r Zv0®PC%X"WNpQ k0!ۑA*խFʶτ }<(;.Ϊ0(PZv00πX(.O@r86$&Tǵ]~,4_zf |>D3-ˎwIY4z>ɻ?=ӸU_Q/,; `kzN8TQ^䝲_]-!F 6 _K JƲ+`r,D,`q;G?gЏ%08hІ dT Da^̑ lSx䋤Et!JEmA-FX9[ho||K 8%iI1Rrk3 "=:&]ieLm>EfP|4??, S9y~,^,}TEJqj sf¸jJ\ԣ}B OλiRhB%[ e}kCfӬX)h-s{qz:>7 D:}Ā7[o~ADJL ŞRiO@ۍحނc'fmKRU5_IB]%l384Óbj3 <@#'l3dVJϿܛjwBd{m w_IlDT(UHIO PN|T385nrs32Tv[) Et_ϛ|UA equ߯CFsF;/8 >!BI/SN*"{z2~g׾ {".'um:_~TD!_{M^J0ws/k,K3}ݞbg-@S6^ԍ0fF*+<{Vi+\"dz\bQDQ`i?*m@M$^옚E39MlET-WM] bx*,[pobp| E^5F ?D5.fۊwrŋ>` ,1DiP@ ;@B3cqf, `d$XU1VO+0r|@›&pnA72lcnni(] Emh=ȁZ7] edg1-w" MN=~Y"KB  ;rI&k7_G**$i,Fo)*)[uC8}%{`Xd_E2sxήTPzhߧ='p5vu)!u7S +UIcj2"i#^1?ǔ L4S тG]F8eA!0$*X@'md qCCJγڻ)7 BBcvspvc. 7;z mtim?3$[[y$@lH4]Kr\4YZꍴ$;MCPyy^~~yN N`N7q zo.7pwVM+w̯9*k։7PTR\HD41zcqQjӸ2d3 XjS~35z9qusɫLGp9G0]ygau&Us0@ 0”vm]xw1{L",e3,5ygvL>IW^EչY8-amBvLe3،tWL2 D.*cO~_7cS}ں/}}%ve8&.4J72Aj9kXYuO*>KE]~äC=}jB^嘵 )Va|i YUaTRO)>(BC#%t, ~#˯+}%L&˘buqgnsWXvbLߏґdȢŪG{ݎ"''f5zgbCN+y iͥV%%LXm|&J)fex @lJ#C9pj!hnLKRohmmm$ N7wgW+32DQO{ZAήu(89TvgtޒTkgHrvB3|7mSZt[8rMTPǕ-˧1zmg4jBlzӡQ\vEXV$yƯ($/SU ^i QAjIڔ+ hka FXp<Ҙ>7VI} dŜZJ'-K"|3N_: lrtS r["=2c0"yӞ&,yie1XE %%wNrc.zmtaaax=g-Dd%Su(PdaO}PUDn\ڗMǯa(p/-/[f״ l;|O|0p9κЯ?4oUl~`#3'c0rׁ>vbx%; ҹzx lk0bµI f sv/4jG' [jQp'Jʬl ;zdI-·9hpڣ{yhpJ%lOE;z{Y@c Yk^XTh+`u[XJ|@$>@NtavE;I(b?*˶ ao_q 9\4 TٲC{}A*:~߄,;=s1V^(Ͻ7~a30/5AP3@u<Z9f/|em oU1rF nOS`4NƠ+"QEc: Ji,<[%ȘL(ꃡTJ6n!က%Fp޻NWKA9RinAN^*.P4sa"ۗnrp>Ҿ\m/J#xZoFv7PGvkA {REP__`CapeebK<GPMy8U6RŝY% iA^B$~c:*JsX`|=z>la~Vs+9f- @Au]<^4"dkzv_g`b3 0gZ*W*[aMP B|bei+9jn^kٌAtv?q#8|:z WGظ@*0.%hjaPFiztFr *5%9Mݖ^m[棵?%^ɨ{uN[θteR5AM|OVbqK7(O:- D0UӺ+a_\#y6 3h{$ÿ9cL nx"w餯“u@mU|fXg4Iemj;5.5kR\ucrqҞ4D6 >ᚕ9?' 1Q/dyQԵNڝZD8zO2X.]V c*$31xko%d+To{UJ#@+V3OQ΄-MU'|e~ڸݷ_P{[ A#=ITphQQH<Q8eohD|H>ƣ*Ycf*gKB/1l7}OqZw(OFEcKE 8)/ˋG24Ct~;w;~PZ\ٶUoVۿ^ @Hz?D<9-ܔt)5ExDn,( d6d&{)э߯ ״f)_#0h۰a0.č\uFo] Gד$ņ8HӞ5y1-_Vun}H5@A'Bj0FNx'fr|Ϛ8B|rTI2GѶ,xVU:ݡ[)H";j[K֝&3ԙEd3["L0}G'APkP75+D?VGu_};Q56z#bg61)I%8{liķ5\;7+M> KmPk[lެS'L\eBTl%w`|rnZxve >kAΣKIZ :8p1o܍Ef@Q{X  /h3h hPp{BS(' |XJc NG0nC65Mc\@S;.JBPʈ0S@5zX*O 9$Xќ#aK.,:j wJ!rX3tWh_hbcWfrGL+=BJbi8|пvDbo02n6v,h<:_.vQMq50j?M%=<.F0!T{:AC).yӛlzNUZdwK8$z, '͆G]FnK?sO{*61ܼ@qQ'&߈՘5ՂI`Zz *{COyWAu+g k>M s [^ h\ÉQ޺bgƟ덉:ou{TQj_@$,~RY!L [̪& țW^sGXPPlA%X=Z ., ˄C5"hk?ƯlE IXӋPȣ!.S7>J&I]I0HF݃/ 9 F LDZ4\*"{[u٣TIƽ?EFڕ;<&3`Օ'eBݵZYKyEbGP_^DA`@3ñ$ G[aAUmvj>жl%aED(5є*UZKv\RJ+U ٿ*_8:*b@)/(|9hpWE8\v `^Xd`q˛UʋG6=#&$[PsC,Ep΋W/ j!@iԉȳ;Y̍z֓1"Պoe;⟱}mlH^Iۣ^?_Y A BgIq 䵰AgEQ1x,UeV-dmGEiR_Ӫݙ~8Q3A| 9ĭCo$Ay}LQʔ'jSPY{,W=vW֦(1ARO/ 6*AhNSѾ:}+3p  T eEglcm6vxwS}ϣqX5_qb`M7TU׆i [RD({n%!gE6 9Ё =˻{F3+ N&z:7,= &a[yp9kDƳHٽ>+i(_P>U6Ќ[@8W>a !j0ϣvI D@07wLbT_7}P:32ii1r׼x(Sųͮ b=G]08#Y6MSO7mɛCqHv4gj*`\BAi I{Hnj% qOS%n SE'zsD_2% 0${*adz?}{xoBBsej|b(Tl|L7y-'hG>.>T Vs_E8w'Ś4hxkW^MzA6  Τb0aIE칎Aj3 u\Wo맮uOXF/$L8a ~7 XGE7PbګB%Kxb{Ī?Ǝq|kUF F5D`^f2[9іDݗZ5oӘ@HGJ!2Г7C,RP>QД&I)ʗN^+5}Ij/zVy7ia~}nN|| ~%4_Zݨ_|[&\(+Gܵ3Wxrx3qamIҚ_%UYfxi9 7 YުR &{ڣ8yWQX9uu9ބ ^qV|l:mc|Cy*^#>!hU 2W{o#0%Y޽n rN.JpQMi2H%yaH%Pn P=${>,*7]2STm* kSm MH"n,pyL>]JxA獖!Pm9ٝh@PnBL5vR|B"~Lه5sؼW@gNG1Л^n銤ΤQ4pNS!D⷟O_S xCxۋS#:. ZӉ!z vj$ d*E}l3e9rv@ OxӔ8Stآ*Eg((OiQ#B ;Y -mv[x\p.ߠ, ǩA!,"vjU%wHWgͦ7Os^R>?t+b{&RYBI- Ou.QU㜝gmIT:׾eUKK,:P*Vdt7s2 N|n&`g:^ފr(c0э;ʉӫkPy#b:$*rf<^iLTTΫ,v$%Npc+&ĭ_ξ֣Df^ʑr`gėط>zMRJs}Nkc{}|Z|WÄ|85 9[ C0K&u6ڴ~خMa11.z;G|4*M;5Ժwu ;9۪,ߌnM&hǽ8=vr[25w ֽNKB![Znqj0Yihp5[ib 66}Ԑ? !UO~DZ3 7p߷!ID C]X+D~Xk)\ }=kCu X!boaݯK v~TʺnƉ﫤3c2F _È.+6vmWK/r7RR7)}ΫKQhVމZʴdqi1p"ܶbI2U>5i?9\>ӂ^c/ݞBìqWΡ6w |KeJf}wD@B,H iA&E% y ܛXټJ%g"|~xϻIFq2qN9ZR>CeoȦlOՕ*ť3嬩 V/H?v>|8KN.Z zg$t[!˅_r.lj)D(jçGXs8)'YKt./L|՛l6"WV;s{qg@79(+$\:g"_-;VNzhй%k_(? 9GAC"P]L>ǒ$SPSHmA׹ l7YGTi!vfdw9P4M~޹2kP L1ޠNO =Q_V='y_~;(9P5TQR9/;/fAHi=r1M<6 N^H`d R=hןBˊE,r,Ep#wA)(?&\YاQd#ã ev {k#ޅF(_{X&?ҔC``c  hL=ΤhۣA!L̙vDZ@;mCqnR"kxypcN4AX^^1N0Nd  L;z|GL`CkS8'x\~EA|FpzvŴۏSAE #|oUfϔ8tRGT2y|GNA2+r}(C rEO"{x]. V8ZuP+X ~T_A𥉉OȎq N:ɭ. xQ\/Æ  &̃\u9''fcT U (lj$ݱ1˿'ӹj %?R8Ðr\V7~Bof})v{7:GW'mGfg &}?q`-_D+'a?)<)t%vH|\3٤໦ý 1Bj^ T連Y=mhp{G:p&lj *2Nڥ$$H|YĎpОTի5dtȲʴ G aKUeetޠX3ND0f``0s?v5v]?ak0ATmb)\mHԉieB{U$znd] +H;̸8/HV!2QYǤ6[ qp{ vW: WQhdA$cFhBjn{J.?|j{ J5R?m4:A3cPyl7G[u> -6 t Ol?gJK'<n;͛q/}77CjDX;G;x'8g9ʼhhS8=ŝT$ZGKZ0;^I?ECWyW%CR靭h`d䳷y eYIҙ̿+<kqFDn;"܃63{Y u G_jK-$}>1JXQ#G ކ+z7yHZfYh.)(5GSΗD,-$7+\H7pЏ,g B$־BRuƽ_\1@u!'ez1'GSqNJNlJ&[|\8S(,"ms%& OL*@7/l[4RǼƱT>;2h `/Be8Zg_yRa6?ޣ|M(D# 7xU2D1hHm$դpt9: -W X9/(~&ݔ:J'Ͽ")rUw.s{\D7Vb 1K|JٜA[b;7;Eg`7LC;k\ܟs렕 9Mٷw\A( Mn% Unq~gK88sE `LHv}xwOaA!y뢪jzI Z}Z'k˅rt:M:c׫shs!QPԤHv0wxT5ti(t4iiwדAʝ#/pg>~,Q'3(2~⮥s 2V Y%xC_5B],{~2T5DYx!N Ly>si*P&d .רxZ0Ÿkޒ@,+fjUHќ=_&ޫlsqm.jNg\_ V]h@fЛ68L d!/ؗFupt֞.dm9Q! a 8LaTV^@SBވhP'h%e%X{QP](% !O6yO1˙N!^Ąݲ%߷ im:̐Nv@]n ];-)8npVAzKVsbgWܾ9b ~8`dZH(+^ݍ4<5zΨP'$5MW u H r[ѧyj~^i<}f4E^eԘE tilc׉RB" 4<_faGfQU \ .Kr~RVW P#>(q?DiX =*Ԋ%Z"z Dj<7g0Iq\/ 3w{>~mWD arKz)ٔLIѐy]Z DuZNȡD{u=w{]y=/Um;89\#(kRvh;xQԓ.[IVz{HC9N]ƩE (uT(F/Js",9|/ mg0f W*[)wM9spn YNeH9|w+DɘǛ#-;~N&Ga7[T>NsI=nvS"S %Ӂ>26tp4D*{r6 j?\ɈɃciqUsq 5nw^F":u O0jڿyyd~ZQbVGB=ٶt {o'(C,D b't a~C$d@2uO ]3u1YPQpYEF•v猴fOHp^1ݣC@O1t2N&¶5ZO䩼 v>ci{N7-x [~& !#ȧGq/h6D񱨲bZw^]Oz鹅xmK̤>tsH?!OQє+WMq?Nv~'aVZJKBgr] 7Aݭy2+c}NWعK+MnLHsiWY ^C>UۢuvO_2QV {bϥ @ƊܷpXVݴ5")dK2= $0), An5f `P%wu2mwg$I!X)~J+(*T N9rzI(.3pyBoƣut7z{EN.3ʬ4hSƧC(),X4n&9SZ7hB,lk*li$O9Gr%lnD"Ef_TO$F}2bT+(0 ^[RHXZrTVW uDְ#OnXB;(Q]3#(So,l83cl>< @d0?u2C\v vM 80i͇XPQo\MLKȇhE qʛsUn3XM#h6l(fp(䥽>ypP} I WVKh`*}I!3ɖr$ @S;+GB0)ĺʲ޾W(Z37sˋ EkF qMzvc̶orBAzզR+(r|[X% VkmPeYKjI+W$L9'Ss.eNH?8|*VerwbbJ̼`s`EM& QҢPg`W#$jeN"@Wü"g@`p&3n q\Gk75Ebwy{i#fmd;!FR ]I G\w> ꘲DWlD[ELja{<rjvg40my ˌ+|rȘuї2QǡwIU'?G$<78J3IOA0;AԈpއoLʦ A]pF:_>!<42wM hd oTD9|*bl$,ld.n,"cK}qAz2臭Ӏ_UQ .#F c GhڢR~l,JF{mMId}(:w [^3"C@"{!';`D^UڀpLծtwu qR9K9V,^Hm6$yt?b寧k=y썏 nFy2yQ1|q"8Ԛ;j8:n|p)ǓVʙ[LRI*N*[, kXu zXFejb&0򛄵KZ e' 9·Uu)s¸aVGtqrAU&;;(* ooP?Ahf cP,+l7ȀTR!11&aڦnj qwmu~i'uՑExʉT faCK;%_(ti8ãŸ+YzEPf2G95ANq&}̴RP9q@nAÉ6;x!2@Ghڼ8jcx-_m%J-@MKJjy41HH<Ph6 1㙖L[,J:H)WaSEY lT=V5;o*h;fmzvzU8TXFiJ1z[Wk'53[bvȜ-G䵯Pl7pڸYw7V?Wbf*6u^ [zhA-rgHOVB4Y3{vl@GbC伊D-%;W/ğb3*zi[ڴW}7~ bH^-Q(t.i͓PPj^g41!VTPW]۸߸yNq#WN_s ykPqrX05> ]ncdb5A>Fˑ%p+<)݃1⃵!؟CC| /`~ӓ]k[YEq@ I>+ šʕ+mzӚFQRUN0c7ÈR%OeNav{u-r X셄d{S=CM 8hhm1Rem׹_v 8XbڻDh>%:Ӡ3O$Ԏ!_by9|Ȝ L .[ׅÁ0*aoi[>^Wa7|2P%amKj0w ~Rì \n)q֭$j,;p^5:pV;3ip`,+a8TmI_Do>oRu˛"q? ᫪r5ZћE EpP~[bx;WH=6"U WdNEpHdk @/Ϟ•+Ob΢a`ΙGNd'\p˒V!^[Fb 4E]Mm 紖2|iS)3%kR,EK3&`WfO׿ҹ|G:y$ocSC2n>$<í 3%gN@f(<2]Rs&mLXY (Itu= S0cԂQy>V 7mKM*觡 ¼ axlL̠ys  $JLGg%H :-2Ħ|^*ʩ(׺{v.ڞUHD3? cN}[A]2 aZ!Mt(l>YgXDpf3}ml,TvEXP\z ϵSPV(،s]A ک*ve4L GUH%`zmZ/"7=8+Kf[fzh/]ʮ$-0u@o糹Ыiγm(;Pec`'$!]qC)&K$)".D9mٷӞO˛ %fW1y1bg" ] ~73DY_nS\cá);VO+m.=̎qVAEFi*m'fwy|2.e34jJ%^Ι ||K%/o$W;$CYmHAtrl$m Fdʡi_E+Ek]%`12'R`-ԟ'؅Hn{shR@{ `mH^e< S;Ϲ'X4f͸ָoĠLUtM~(ȝsSwr[Rgr2:wY5 vTa+6kqKF^J4*< t(>Y4Ӭ %@*߅U0濱e:ӯ_&= j OWpY6e>]_.ij!1;9ȭ$5IVMWӸm1036f ^s 'Y*teEp-Z0p](2GC&|K(51W uˤ%Oڎ/A~Ix+ڔ]#}ܨs|/YūMv\q%#Ϣ;"!G{)̀a 3)ӌCvZZ?]I+675YjXj̩lPws 0v7*M y|0'+#_  IE{/rnl# qpwhK<`gvyH& [ak6Ɩ%^F9 08+wW}4-YTDfiYDD= Z'- a0uaَ@D~jm%=h!&YCpzEf.a;݅J*-M<+ԤJ' \#*W[1)mf$Q.a?2^SF^ǩ8R7黮]*=)'o(]9&AQ-i1Vxt j's6%f!M Ml%GNY_i ^[vدDlZVdYwv-̱0X 5|tt]u`vuWriɪ.uK)Q.Dt=8s~WRiYjñAY5pMdo9Ϙd ŋ?.*/q3ѹv(:#mhSS| !ӒA*L=:{GZZnř Ƣ6,A]V̿Aw/XR01' e.9%Csi=2 RҦByqXyrHrÿܻvw \ݟ$|&~OI a?̜8[y.ƺYG-UkPGWQ;Oҁ ?&NfVoպqNex;}Gϻ DOx>zV}2F`BLl"#~ۻPйZwkoP+}{8AQ4$L;h ̻K+j(E;}?jTKLCMHruv,:_:럄9j7-l.In}7-I/ylmlQk~A:NzI=couU+K/&Lފ%؃Yڎ ~|Ge%p{Zzs"\jX1!|A3(ErgH`?.jYqn%kM7 2XA:LmΑ V"!:)SHz;j HJ'`Ϥ5)?|LC޹MF}WPW߉8]-oJ|b3% eڢۣTLvm VkuЖ/45GI5[?(ǝ;.bMeO1\g#1Eи&-d5Q;tmk8*Oܹ n Ϲ׹9Z = yƳ˳i]zPlZ58@|/L/?9W1(1i(yT{&7h ^mR!XޕYYT_%}4CbMj*=«K %=&vfx O-7cg:k~y%pPcŠ_zʿQ+iV<[gsO"M]B5=3"g؈֛<9?<1l ֈW>(VG.4;*?kXIⅼZ1JP&,[3UOO Bja]H D\?SykX^kHg 5?gp$S ?fmSI7mDtNBh;<g$Ӻ̓wA@a('xjLd1f^irEgey$>$w SnioyV_B48b|aW,k5,ME&aܧ$9h3dzXbfn,jMŵ·m=JN![3%wŬSwjηH%Q Ft%zϢ!U!> ;GcIȥE jSpm:GvdGZ3n:/߿HW) 74駡|pup\G2gj$H/xtKw*N^f^!,Ԁ`b`րX#qkt5K{N}djNRr`ENFyX.YQXX/."wa TZ}Jdo`Q8|:}1Hy7ŗv\,@c`"J)$2Ug=1}/[aPmXvX7~P93 [~jݢ[) Hk"ᙀkSgTouB$2y P hc" hC!3 6HR쏁`*a[c8khJMC:d1/jPե,u 9> [.MI{){5wKV;|:XJc[5vN$L XӛJ[FO~3 V Wt-qd+Y@'dopΩ᚝*usSq/$rK^]Djox#b{<Λ[s]Qz#v`NֲbAeMD !od v&R߁0B'JttaE^ ;(bF1~,c1M<5O*爁O{DNU|;F!sh{O.}'(CLJG5%)^Ѭqwr9\\ _@EĥVCY b/jE/&'vn4S\۟TQPvY,i].-bn$uZrBЫ< OuR@H'SZG0VY-+ejL )S؞YN$C͉]Ռ@MDӭ& LH0]SCDH^ /8opv8 L2G,_ui^[]M/4Fq J0Jy>\ڄ,Md`?E?=32N{hpARh"U:Oq_ 8Kfk@aAdhKxJ1Aݜry[t Gޞo[U̙z"FN$6@ jK|?s(I317uY<_i,Eżvg0~܎Ԓ- \43O3Iȗ5Ա2 UI'nM<c.xYͲ`ruX*;Qe4?Q@~lՖ n2IV>b Uj7)b>jyiW,s.9-ػHXSIp *(ѩ2leյƹZSe]/J kJ. FǨW bӿΫK]ΒdoyG؃ _u2'hi,6 'rn.`L PlYf!lK j!?4?eF{=Paw5hQ0~3gJZhkH9pt{Fw}rZ /U*! #JS1ňzsGs&Xd*#Ba/8/z[\nhz8~t;pmGq526mw$b39X㲉#[&-г[1<|w*}|@eL`4JcPeWRPKf~/fv.{yJw˯` ޥ3,_tØYa(h,|le_/[IJ́d u6?8gfX lSSFQ\#Tl0_n kD=Rm̫ޚc "07e*`|КxndK&^P0f{8v y"g_шm'[(٥ܶRD̼i$2u5tt3J4jhΑ4b Pyݏx(>YQjydȷ/HcBәGI+Q,i?:ܵa#7V~Z<ƴҳ٘*D1HߍQ}Ea9]yKÜI7P GtA ٖ;01>Uf"ZZQͣ hYNӞWk0ݬNYa֓@#hEjO,F%ZJ[:َ;?<0GX5}w+(9 t!EPV潀e:ާ] p:%7 u6;Nf 7}\r~i4naiBZڠp6\ZD;CL?3׻RhX_:KJYůk6r8$s<_lC!fcigR 0h"u0Sfnr*!b/8X /1U*^|tz .xu ׏8@] ,%xQz'&-^rU,wҜLZ(:qTAJ6]!q=6zߜ5oXQ J`g "{4 ZJ0UӹۃRn- ȸ |wFKe_e0c$մv򻌟 ~eePɞHT l|롏-S'˅/{'P9%<)ǹϛT#gm.4ﯓc '(+,>bkqw4[:4}f>hVхsi)!Gf7R:]TlU 'ěp&OyLl}2^`ߺ}8-O2'Iq |l#pU F@|_d(mJ ]Y #{8k5e=:N$4Ŏ[LgX9(M6zJge  ]!:zdc#o [f'}7Cܱ^/:<_Owtx.\io=KꥼÚ.BZ+Eyytp{£}rE" D&x"6y!*"kcl "LNc~;P=ne~qRd\] nNwCq*%$"ϩf27xYOO |ߡ? ]Ί he 9Ѳ\'MRv3&1]f:b'U7C%7-?Ї{zpBs))-Ӡj6ŏ\\J'Ʊ'"3ex 夅\a),|#_}F)޷Q v$#l!d2gg5Gt)m1z_zV&"r.>$6Qb5/˜+B"+.ATzE {$"XŷU1Vr̎sbPIm8 hܼDQ*UfPDz;&Ƴ̥ʴ "_Q"qt<"ݍ[=<&D;>(f_n5G+O`d]Itn^ !a0^'V2M/B#$J[i4UwfKxWuqP*[Sp4  h!qÁi?Mj_1j|%į)buDr Vx8gM0@(_^?0UזB(}t<@/bnphױI% ϐ&U2 E.L٫/XDfy `js9:Ǹ$ *5[GBJ;$77ssw<Wʮ2v :r63B/ڵar/:$p \v3A dLBVr5s7~*'=fۋ L*Tգq3We4\AaPEXꃊ3,{%# $crN.`ɡxz-7߲9[9Ϊ5P!zR5F߶b}5s.y) Jgs%(E(13~44- rd|9m9ŵd,J=%O@;U;H5fB_L ؔw8(g/6Nj TE.Ԙ(>ǭW越~$y &,Yn7}Ւ&O)~#KH<jnEکi6[%A5ߊ'8n?piR!0}*e*<'/HB~'eqXmܷNG)>mt&SFURz_Q`%[d*?lFnUtA{u|/۲IU cBc+\ЦZ]cǵMqigj,ВZYvc׌K hdzsm")k_ ϘL= o/ FAu=CngmXPŎL'V:!;9f)~TC]sZ/o_~0˟c )gVB@fٺ)UJhD`2dp41w3TmPiu hz,~Τ{c-L0N3ms?XFR !. CL8 kW* pg RTf;7.^G;"wYl*{Gyc~ /_zr`+Rgg 7??@Y8}'ЕazzpL/%2fHS~h&% 3}1+{>:D ;z"Ax(Li~Ц'=ថ! }[HEhb)3XWMƚVD0OAvl+i[Z=fy_w7};He!`Gr#rF[b o%lxc-h~8ZQ^uZ) ʼ3ᄏӕ` bċ"޹d`a L3Jw Y~F…~4yٔ[JQHYZ!f5ySjK`̅=Gv2FƽW[(qJYA.%Hů ^twhd ;EU5k<{0q{1#iGW'D6=IUkCpSIYyEbFco*"ը^LBwF _Kp櫪 b㝷U-bh ]H"(;M$[!"?vs@7}QXW*cե m 8\HF;Á -J*+(^ (uJa @xEF䊴hV~%="iLw2 IHmf\0gjCXLzs ϝ:P:W &ɖհ#P'N%]|`"20Pڀ_jK蠦Af=Vh7>mМ_JЅ^wI z6p~X L!F sU0ҔU|(kĆTQu%bZ&}%,0"qTRCZ9RLzyb[aavå( 9{Xp@ݥć(KtXk4kcwښFM끜c "r>o8b3#1螰Ld?c#Ȯ+!bޜ8IxQMB'Y<.D}#(z^S0\x:',Ѽ0$gt& V+%M A:mܰo@Uc}vE/E n&:H}Q+hLw&R~;(!Nl1H69pe݅OE A4zk*4&e˸8w۟Z c!KwCEţT|τ``%*ExZ?IjfߣVD~Hh_%j$I 1!DAP-2xhB x[oX=o$߱JHϏ|u0B#|3R-w:+l;fbpKƢּ!(̺e1j@PS!*"sQG/T`m\~lI96) !EӥⳎaq, n0=::sw\-xQaEe(+ JtSf=л&c=DAМ]&qU΄c!xo;n5_U(:x_DNzV '8i$@yRBV9C_'<~p~$YG5"YH_"&S!Ȇ}e0Rq ˚НOʰ83Q˿e[2P2A7Ѳ`=Eb铜C9IhyiG ST* Iz;b ]]QF#G2oSϨ֘|\4b.@њ`ueUN~(.-dX0-3Jwm?kBVa _^}P~ԙP2.dN6jS3"ML_rS[Brg0>,5 2$mܞY,=э?#DXtDrPNx8}ȏw}|0l;W牒4 r)G{R.u'8ƬhCnMD@O@h+΂;"hz =IG4(~r¡UX,L2YEj&H=ҷ;Nꚦbnlx <`i9V^0[j5B<k.pA>NtPm+wXIo*i5R|H$̽,`FX 6_R1h۟F꺲eUݓSJ::k jZuGC̲U@AtQd(mc!rEX, &U W?3 Jx]x*d4z"A ࡖė+|@D &|4B}:y_SRr  CU6e71vҊ ?K7b9G\*hn=p݋B P:Y76"KE'2`bd+t5~4ڒ)=I,fu='P/2h@ˮ 53ֺE <ؗ[D Fԛg0: .:L#|Ug8&B_SE7%ޘK7w`\; ňQ &0qF pm7EF<_N}ڳ^EpSb{=ЀF3-%Mҽ oW}EQBOcgv E|Cª V:![ iqjX2ִ1V s/yA}ϧ#*%HaOo]smbܚq.{xrBaB'z@HB=Ur@ ڳngGAFs.Ob "dPFΫQIn=]Me z >)5 vcWF:DoH&GpP ,994դ ΐ%}BVc\a)3|'ċC8@^Z7e-A; BLˣI9VkkwajSFd+X*Wm)?%ɰ#@n7lH we2PHb~$Pv)c.Bog +]wUY^'W)1/B$&n zEЯJ 8 1A͔fca_Ͳ7L-JjvWeBH${cBRkc7kMUAwe"7>Z H'q䇄[f\c't78ܠ>l?\#$f}`\mųQ7; rn2GE<ֈd˭%*^{âש{ O- p/:Ljڴ%]w)^yK!Gַv~mL5!zLJyP^ .ߕ: }?VJLuߡ*4{=LNz?@<5I0T)l9̐T%3l#<;GV h6YVw`]&'_X+AU5kKCF2N@xlPlz^XOE!U' CIP'A5~z4ǁUazs?"eQv&. 7.G+Tf 7S ߝ9!`s~7fj[Mo nםKz~2~cS=4_&]a&HcdL~u&A KV G 4SD˙Pn1"udN%Ҏ f9F!B~z;&񧽪+N)ȩ.CM˹\Y IH H2|lD҄`s97/6!ry/HcP$-Fc(sJb"BKjV՛ENhl(-)uZ+ctL!ps*3BkF54!:EubD4&+x9gg3n1} KpF^4LqCzPd|m(^N( WP΂ʩ8dya9S=f 9b`µ1_e-#`[`˜MPrGLқ| TV6|h&r̂+[z3e9E"%v"GxNK`g3,>1,΢QP\quN19).Q_ɴϪʕhD8Tla_}+s;@ϔ'!Ц1F*p>#((`r?RU6MD/۟7l23e GI<nz>G vŵ/Z6\ W@6]Qk5Smsā!A$#l1"VʹEmFQ@ KɃq3,/'*hu2ej|O2GwP˫LRj]iVE}ĚP Mci A,lk[D0Fɨ1^ksUrXTѱض75nÀBya !j>PwJWן;Dd/ VfxXw,`&C3^Bnxb 7,=~BG20(v}K-& P|qg=53knIdGx$9ԧسf%rk".Qj=Vq]dr:c51sR ֝T5a_n;!&~U\.0puE8Md'#?h_|L[J$,,xxNBA(婧\;@ЖzOw ʩ;_,3ͧFsެpʔA%1ừ)o%1D\p'[CbX5JxX6{rc#o&o8^|-F-҄@m4 -S3"ej܊Dl;١{}avPV}}j Zb̜=ۼD뿇".PWsʓ9ӉIخ=u˘ bg*BK2 ~6mMh"']ǬuS@Y(N)%61 nД SbpkEv3zFYOȎ>[2Qj-fs$9-+ZqV+]OR;wȤ(^%A@D4 $Q7+HOyJP~‚upsBRSx>c :KR]3T[ޱӅgۡr@},p)J =WHRPNMq`lw4$mxgJZmzn$ lN ʼnlP7f,X9:v?C?gXhTj~N?{YLl2x@63)wH7)GڧG,ohpC1J*_Q~2n{G>[tQ(qJm'zΩ,p_z+k Df s IT.- ]U?d[_N~b2 loS~t@ 1rr21O|4\&ptPWi2UK-%0|Y5eSƦGoF"!:CȗB0-}IsIj(iEe65hUd ϐ3v itdhޜϞ,A`KTOWݘP[3SL@eE9f y|t¸VKSU~nX[8*zM#Z(>#%"SqT&ϟ{@Z#swY3lGi 絢OvvJ2G]/\زs z3>sF.ਕ۪bW^Y5/BCqEzHn"MȨ(k@9)5q ՇWjiX]d ۱Όt5!-t( cg?=5٪!Seo'K쮓%fez=+l/ߍ*WgfRwm3BwT tf!nLj\|`N{G#|7XKr-;ej3Jgʅ:]!LT2G{1&1 &*a"dI#!<35/(s1L &ˆ Jc=.cĹ(Cn!]B STNivUF/ӳb Fk:F26"<zԵ,ѐ!H춛Q8H/DeN 31OFSz'|:mgJ0cH^U}TڕLc(=MS3 >gk;aQ)|6"8w YpЫv&+.wA48UɁ4՚0<:K̶$5[z%,NS&BoSg HBrl~!ԦaCk% Y?c\ju,=Lt,V|bfR^vajN+hnu?Fts\d峁63ƶn2y?g9nyVL0ok}䔭kH0" oڡwlU/\o;U{^Gyfq*a@rL5`-mgOs=6V.Z#s!)yuEr-TmnG<OZU~} "w ˬjEP<*ڟ+3ljld</ J]-SyP*x!pB' "¹G^jkDW 9q8{; bPhp;>-Q `-vjh'1<.@3 CS:*Hx֧Zi?ͯ Vͫ 8kd'ճ6P/kXFaP:cz_3zoB\/GMJィj.{ቲҘ9Ns@ff O7 oR(!8}Ъ-XMt?vG!_>԰s.܏ÐQmJa3a riGbx15sR*ѥuФT؏Jɗ͖y"ϣ0lZ<{It ⦼81u ܤӦ4 - 5՚C^%V9Fb#EC;D+BJMƆbs@ 4fuP\ϱB/@(,GDdULz(^)Pxr A2~8 pȀ}X 5j8O䓅R/wC偈YeH&!Y* y\yf&:ҝ/3R%TնD>_.M82DbM*-ö";nd$Kb9 S]LRϱʑt h?q}ԺSl,>} xvP\ Ԫ3r$ ټ8QgCV Zkê—)z0V wKTOH&"]M?\Hj/GW V0UZ<˴"|x&rа <[EWIcDDT,|Mu {ߚn9q2/-=QcM\.Vp\aݠQ rY5e(ε'q)ml\xZS8C$ Rwjt~WÙrZsPC!WlD82j=A'櫃&Ίm*\ PM1QY~9䑲nlO m7vZN@+hYbD_by\\!O䭍hL>I*4eJGY@A y,,:#mgj#;7P\ɂf=?l1$61߅2J^*xI⚢ !JcZm.q9+(d;=ѹpNT.< ʀut$4%X@piH~5s2󢝬Pz%[wk7u}62(~\i+;i| P9 `}X\YϞz|lWӗw,shk&€9$LJe;w鮎T2rV_jThM`"Z`/`~R.N7%K;M-th?Q]7 (4'Jd|3&ӓE #x]4 c*gyޫ9࿵)%/USҞPTeKk I~z waJ%`َٜI2?Y :+2BVR ?LL7E6cV!)#}L7DX"} `y?Bx8H#StiĠC ^a?2qN Y' mc ΛRfAS8MwS8@(xd`a$C*P8Rn*GWkGj5{ҘE p/A`)۬4B^(fդ(tp 3"; {ve˚=a<ڷx.ZgHl@ZRPZipԿh.0a8QoRjCmθӜ{ Z,=_T#s5OLhYZӗ1c2 %xǣxZ>TH #|PjifPi#"@ ]2 pKikx~W}ZAK?gJahwl%8s`;4Y֭   4;zzMGK.V-a}¶hdY~D/mlSSAHfn|+U ":dЌGp-RKΈ6N"1<_-%iט%Uoxmt=H9(fJk)3}_4h>ZxҦ^k`*us>Z$m>Bh,)NqVjVβpl$4liH%.%@asUܘ #\L!I|{tR7ךTUv3i ?/1#{q{NW!19 {ܤ7l+Fs5e"c*u-Q4L44ǖ|o'9-<*r|E}׍MîI‡T-qndpPĝ0@Jsj-MjbO/bZq]W-|2 v*pÇ&ixox-Ѥm>"QPo6QQ0ZQ(1/**LKp7^QJ_7sON{|B?ߏl_rsiN"""vr~ B@ + Hߞ$~W1EJesz25w'=fIvƦ7h,&~݉(66Wu&b񵛝'Rh*{3wH>NnJGuUdu[+ &d3`q 'Cu 0# 9Y<%uGPG'9?ѕ[tc2RdKr"$Z}t 9HrY8-ӅspGnj"DqsπT$3ې!ܔȨ+aZ]Ͻ;jiv>;rBrm>T{l`Ea]p"9~Z U]O: *XIm?S2P)FXe#vU |~p#jB/@ g .%?g2ĹUЭ2B ʨ ul <s&J$uک! Op}x=[drs_Bx8uN'DŽGOKQDjWZY&]Xy+_S'K v9;unxۄryv}3R+5} Ů2!|YtFLhҧv֑Clv@ϠQcΐ4 (m.p88KAl=یy 8D  m] VYv?b8;O\zEmߡÆ}/-#*}O7UCH@#zA%kҁr5tb]B\} gAU$6@ލA*utgqs.BiZ5Hʥ%KǠ" {5HGJQ'~$`?'v Oئ25, #L>0 XtXrdTQ'/{""e8[k<ϋBYSʊp?`s&ǏE ?3G63FiU M d/,K/*B*#3ZWy}%{/VQjfhP9ǝCAz)21wփFIYoXp{I%[OkCcIY>)KcVF0t;0fSBЍA+'ZN _UQBxp̛"aGd~n;'>L.M> RH Q"lu:+69VحQ(=a-dIrwCǥ*0f#K<!!xr{| E8J^xF~P{ &&Տ8pUfq)gP* 6fLKdeIǞԢ(ty2gpe4K/ɗ̗3R,6qMhjAdB&dnWCj`};1lYzZ4ɥM\N mn6[F0 BVaݡCuF< V׃y51!La!-aM(d\ 4>{Z]X$9ZmHgi%;5{k:!Ua(H|0^1;fڟAMՄF0 bu:*5Ex8 !#4v*d0kD?SCgxLM'L۰6ÿE\6X9=-=n֯=M0p<#lE!-j_Ye,:iYb`ʾ1(LIͶSx% H^S\L,o0GD P3PsU+HT{ YNN' /^E x*Lo!ĢߢW:VB H=Gfa$оBZb2 sJaxIS|&=t?Y@ . EҶ5_[Z'#*L#k/l/^݉#2|HmTާx+qn ]dhTQ.=ɼ&[^MRt?~I@hMfqReu82l Hi#S&8k)nSdx¿ W7(B0j*nq(I8hz(/3 wq(gN 0Z%/,"x,"Dj>$UQca@IJf\nՑC`)!uG('8?u` 4Ǝ짃xkW|6Ptָw ?y BGTǛ1֟}@Jty9X&q&3Ga| MTF[1] FzC'{?ו}e&̆iI–RX{ދF[:6kϘo\Ma|ׁ!UԾeD1tvPXЃ Gt}oM]kIcz +V5uԫo-O].J%J#UcFa8ĖVa;m*ƈC2*ǝ4'V~1 i`6{nH\5C!DF 9{:R+lJ/–ԙYX,̂ݨ9.h#qj*R+H5a_>7B |ov;0K~E/|1 *#AoȥzAœoFydf+ڡMv UeD':_ Ҍ/&"Ѷ!Ć1Oh%52u6Av8T `Tw1~d7 H f=ѯ ˵- XiI(mHfO=[<&kXRA#4xF/f/mރHQMO9࿪OyNb9:5I>rRԯ̢_$[VSN\y!g2o]j+;OQ4R#, HSւ!9D{7#r.0!f޾t}m39pvvuK,*%:I(G4\bS0e >PԠ­2`wVo]n K8̜o'FeBn9{-J}Y8+܆T4>Mt+8q5-%>nXj\V8!(#iqх5#PCjFwv2CN2F/{@Csbc*9>@8Oai>k$Eb'Ї >:J!4wN~.7sKυA )WW5+RrzY#)iULRbu-lZ:aLJIM#mZHf75e1 )w iFMYgwkKP(7l:ۗDD-w.Li/hL5a;5dvchLWC^_4ˉ{|&賨2V\qG`&I'- TV3P1JR t\ ^>F^wq4w H#xL`< e]އn C˯̶|걽o/ӮIvQ{p3KpgX9uv&I/dĤucU!:*pݳ _ Й^cJTԑ:;s24 /IM=sdO?Mؑ> pGWk@S f#ƌJ9Ms\O%U: :7P赾(mRa|`^e ?Ӂ=Y„~ZWTpP Qd.Zk2wl9 |@fzm( Y3W"ʥE)Iӽ<m` b%5 2jVw;ifz<| {ʍh4 ;sG 3̡UV}g:BVV&f3w 孎 "<,a쯘N[GbsS Ȭ,~mv:+C|:6N \7wM}Eם^L)S=R}(imHl|X}!Ǵ- .57I$|O}%FQzs ށK>{|0N>w uڮ` mQ=<^ Vt_By~0S:',ƠتCڸne,+ƧPKEGF6H&޺HNpB GUN/6XUJl_x>#T`ilwW 1b8 lv{q&PhZ\ (J:Q;P"% c@( 78 j:E4 @~)' =yFN:^ۃQp,wl5?{"O)VJyoȬl.ݨfb+UnUuz=Y9 秢 vdj@+R~n qorIqCmN0mM1yj*]b~U>!7FG$P؊d%yJɢD\XmV2 mčdMUQrؤt>!"H&-}98ƉLs%pmGqBRS9T=&Tͭ8v߹,jYqS9{W>k6sE6W`X+b͐(NB]IяկϝEJ2c2vЛg[/qMC_׊Mtm9MƢ _; \_UMa,*xrdi-pۢjL:nC‡ =|w4 NɊ뗏2j6!춶C,OM( `n&ÆI]}uy0IJj|l\'^羞OA[]//H;zqB-LvOl>%c\ߞHMuB*$W͒SB]܏FX>ܲVZJU)L^p봉 z@Мe凘[4+2NUN5cоwO!Tiae U `{Gg3D\D+3NELΫݵ*XóX lW\$WĖ=u$qح'/#7K6^]y@ǙHa١s_I\iP} 0ԫJG bm:S+sCU NN!3w*Lf|w lKmڊ }G^n ˪5lpGo N(\̑} G# ku,LOkmϕ(WxHiFD VHJCL,ԸCFkxYĚLh}Y]./2%O;=wUw?ܩ&D:6pr|-tK7t,vL?,z5Rs[`HN&,L4%S0[*-[v Lqf9u |`%b!Pqd-m#bh,:'C3tD o-Mt ^1iYq}a̟7P3O(*Rie{ m\BTYA3sdU@"7$ayxXmݡy)$jG] bVKDT\ڬ h Dhǂy˒;ق{+ 3 ̸CyN('řSrhYhs?x2;eLљ.;ʑ?v9Z}yb*f H\]k]Fg>R(%(5¸7gF>>Σʲoc)x Pg3b zr^HCqH-iqz/$u29U}Tf` h垕ESd鱣B.JZ%g? vLo+ yF\6ⴊIXr̊x#|\(,dug$U[-Rh˫ͫ"Vr@m0 Da cR7}%v hvs)+5и cE)]P2 D'OVR dໃ-0)m~W^G펌x]@h%VMvHzbk Dȭ_u+֯Ad{PJdLE~?:T~fž|[V\l3H0BUv˼OؽBI='Y5U‐I Ce=WWi1Ɂ(u5m: 賁mb8Xd^h $TP݊f|k gWj ˳LYnDsɴ\/H!J0N&7GU-uS@fD-b4췌{7W`ީE%%\*;xh ~YF6{Ͱ ;[/{L!c؇7Qx ^;&JF&ъ .J}^x!r@,@ UBߙ;!*E㪊fIJ[E\L"`+,zzpg}Q1m|fC~K#A[XslyMY`'D!&[G+xwI3p`E"Z, w lcq2FYyܛq{p&O*:F&Zz EYnُ2I(At6m%99P{< h>s_N8f>E)D~M'g7ڵ-@,%sFgz3.]5+#˲?iw !liWk-ȧĩFNAZBV8NEehB ^)// !jLA)lʭ+h|@8=n&UAǍm"iHS'NU]|Nm% ݢ|QOZc}SWs.+;օ3?Y6rƫA/]0mve:VLŔ=nEn q0B+Xm:^)n*vxPV ԧMQRbB#\LH@ E[z&F2oBOaʯ ѻPsVұ+ΪW~qPѓp|3f@Db$d(*.K,^&|dFOcj`<$=KF@ȉ(lQĒwVmz 9&w`(~LxN;0nJİhX v -9(&ȮPl U6l])S`/6gF?*!A/FxEfq,'q2MCTCyΰ.4% S|;P@˒ +<` q^Yc' ңaxޒ?5k"usF! l*;*;R%&Y~=Ő1~pѪk0RI_Y-0AP](|]| ꆓp'9Դ`lErL`!S~JdPooW5EqqpqoYL Zj ~6\_bxCxHՠ<}ohPo\",Q$۵\841Y {tLNHsLsFwg©=ɑ9F;L bӒq޽(^ =wЌ6әh=mňܜ-Bl?CL_忩h.e^:jB0Z iѺPۛ /0J~31c<ځ )衯u3U4d 2R-[ mʼnBϸ$0v0bh?Ȃ}G`AihLNN%Kzk}7 W(~!2n0c/$ў־qy\̆%2aC bb.X$n '^Q}UY`_k廁do#[(WcPӮ2ݫ[>`tZbsWf_Ŕ@# ?{%Sc4g w 4P2٘OJ$&|Ⰼ.7|FƠwЩ[s2ƚ̞w sۯ6_O巠,T iHdɐY({2ƞMx*fHzj/>E[+xaMTtºukaGnB޶{!l·gDUKǫ\q}[ttt b!NPbh ⬧۩_ sۛ7ޟ LԨ YZ