sssd-ipa-1.14.0-43.el7_3.14$>8x#T5j>=?d   ; "@FM    4 { $XLL 3L   ( 89:f6=|MG|XH|tI|X|Y|\|]|^}Db}d~e~f~l~t~u~v~w8xTypRCsssd-ipa1.14.043.el7_3.14The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.X%c1bm.rdu2.centos.org '{CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKOiA큤AXXX$W~XXX3a27ddde17489327d64e06fadbd99484914f1c3ee242da22c649828f86c73d76f579a29f3640404a41655c0f8f98c17af6c89cd26738b226a11b1ddb00fcaa218ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90390719415649812e8c94ce606489f7ce48c319ebb1dd2d7700afc2ab2cbcd02b71e041758b946c65099aaea0c1b09192a3ba5637df405f17896a2a5673f3bcb0brootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.14.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.143.0.4-14.6.0-14.0-11.14.0-43.el7_3.141.14.0-43.el7_3.141.14.0-43.el7_3.145.2-1sssd1.10.0-8.beta24.11.3XBXpXv@XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.14Jakub Hrozek - 1.14.0-43.13Jakub Hrozek - 1.14.0-43.12Jakub Hrozek - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1422183 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user.- Resolves: rhbz#1418943 - If a long-running task (e.g. enumeration) blocks the sssd_be process, sssd_be can deadlock - Also Require a new-enough version of selinux-policy so that setpgid() by sssd is allowed- Resolves: rhbz#1405584 - SSH: default_domain_suffix is not being used for users' authorized keys- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.141.14.0-43.el7_3.14libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8331f40a84070971d9978cd680a24ba3ac5957aa, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6%R]"k%w+p}|,p35muذe%tWXPĎdߚ %RWNPv8ƫǫccNf[9q-I>V^.SuS5`:cy-VĬN79KJMrS +KBda&(y ^qFV76h´*Ӈn{ў}DѤ?wW.TR`I(IF_]ɸg݂TgεacZ)`> )Bb[&/j?ل cj=^fE֩b#P5 GOM5B vjtdu+p geG`l"X7b^UƉ+pƅ~:f3aCce%Gq”R&M^ի30d$R^W[It]uSB8%fCq \{ѰCdhg1㟡܋M_rL 0#hefV}M3i"'g? OZ3DO|dWss Q+u9ۅ= (O&^KI٢L'`a-32k%N%fÇt96@k|KC#r09[ }5qK;O4h+ pզ\z郖bD P@+Eb:C3Mj-7'pjD5V6%ւSvNzIC2~Ӏ317enyZRFlQF*&l˟ 44E學G=ob!L_JmнlQ|~ QRjL$8ӺK4mSYo)g+-,k(= "NDwp%q#BWhOaDԼCM1P\K"weCÆ3(C=I 98䷟ʐ 92xE"%J߽~v)nctq4-ۼR{1ĦRA/bEzO?t{aHIV[hc(ds:g:O~V{w/$,̄lu_gKW8N^Y២<)1Ԯ]hYV[u0 XO0I<ɫ \  KYcfxPV 3O N{4m1Y8h }D(yH7p? qo1Ud~4UO϶s*?s◩kl= -$*IdOuT7w)ޠAS@n`U ~k4qfrN$)̔Y,-'"!S}32%&tn^ϵ$qb*"b+|K ,b}WTο|WjOURV00gj`Wssd1U2߮yĐP›P𘂧4bJbn39烃G\V[L1))dDFo:yIE/i:ҡN.~r6\>,X|}Thx~ciƕˌҠZdH5 q㹯S&.^>sHΠR ^g=?}KKqPJ KJ垂g8KH_+*iKe{^{N1@rGS̈0UԌǐm<+_%TR'\Th2[ln{xPmx﯆DNC殍V?"&*[L/$|e'ۆ!E ,eT ~dW}x[{2 }B^\Zr5+zrP{=4B6QLC0L*3zk.]bDJ{EI^FCHz#?^Vh& KQڶ((眏c}*'Rȼ+5E-9ZV_^a )u!`ѯa!&1ˉ/2 es{nqVC⧵T7Y&GJ7 hN7<^)^X>IZoVDZD ;A'ϚhA[1b^'έGYsN2>&?m1] <#t&:gC&I;RVITd֫3+b~v'2WTm1S(;&RfJC_ӑF)>:XFBNӶ@|Pt0MzhrǬ!8'mjr! d'8uNǎ ]V <]^*\( p`9'S\›yF[&5XW}t(M$^kb&clZ@~׵kQf6 CyfDW E/48$9& 퉽4x]5hF직!o7#fcNxC@R0#um%[8"FO(_ZNBTGQ 2sp*g%tڱz#X{ܞ]|~vl&lbb+!z2[VSWc@3My[ЬfOYR5'Ap :|JW Xa]"~0K8"ɖ3dĵHA{,}Zu).V6Q#9o`pw=| y{^W,O?QhZvXX5-+x?'CVI]Tn6srTCH4WYbӣW+tٔq[_EigozrOT2Ц3z WCKFئ',Sy*eO3q|a?udxL\la'i2 S~ZaOcɄxLG: > {f;i= 2-w;_Fo%]~ABʓG*#q' ss~p-4Th#Bv}c @fc]oT7CpoHoF wr?i6JI&㥪AyN,i}?dTC$~JЮ-2|;ȁA^ՠpYxBag'u6ԫBI:cz9A<.'~tj!QiˑI'& e}JG< :H6ypх2ZdZƕUFe"sIٓmJqhl  }o6l6pIrPZL¶4i9%!#l4|ACǯR y2@pzBXẺommƟw6)"[ئ>X3L/>A&M1)V_93:1#8gTCY0c j;a6ʱuWe۶sW@%'B`Zc"5V(z?Ѥ]6~*?-`-IR~r㛪GP=N4mw64RT#au%liԾ=H(4@,' (榇@Ȳ ,nA܏pB $xzfV5kUkDKOOB \ fݙYƮG|-O%T ű`/iZÎ;)#?yE)+L60btVc1|fʗ{%0@wbOQ4a&:`Z[2;ؾ-A9qSٻȵr62$Z)Kڮ]* y1\'h_oèD6E s#ib^T=&*E!csUeL^y=p^v$c螔nvkIUb.iˢ.Kb/aiy2eIL1~fͳe?xn nj*dX:qS3{~5K)`]+ @DNg18zF.v㣧[UTP_^*l!@(շ݋sT  )kGGc=I01DEps7o*~Dz%A,eߝՙSeh5KK1 &o~kÄ&X$),#Rh1aSĺwfRKjp4x4+KTd:Fͩ s!8LiTuCLs6ƣs~uެ(gs4t4@QtʁD^Ы3% h}nAAwS7̿->D/.7 : OIh"7&qxC6-}wow .Ģ[7VB@!L r7A"&r@P)UtiJ@CkA| -/`֊FR]&B⋐%{m՗Mz!7`6N ?Y(NԬlTGYf \M.`?G-W %% F?b$ғ,@ضw5>BH@n^,ɑEc%lq6ͅSx{Ѭ D!r zz U*OϛKIZWgcqOth` T3pYKy2Mob]#I; O$W13 O?4L{C>#(G2n~kMN =p> Ab+8=_p]f lOU ]3:Mv61\we*4gZ,S4ӯl%P܇r}ĉ ϐt쁒Q-v P ը5gɇy= Úcdibڣf[CwIQ}l,KrW($6HZ<^8^LְO"=k1)u;rL) .vM D'IXnO }S3Ԑ%D/Z@592gT:DO9s3Bk#tm)r_5#usts9$&, /%tmsBuC|o;v(-U'ۧ < v/l?|ʭA"xˌģf>;Է}[9$E3ʕ):f4` |3l&R%!!5ۻOj$Ħp&C?eM x{m+Y}~X^CjJsو/O'WP2V*U91~ :qf A@؂,H")V]8|T]K XgMCbɝto`阜MA+3O˥6&@G #"3 ӖS:9OAuT+p3+;54wYA4n' t|U4r6K by% "ue481> `P^+ TKZCOvA|}sd ɕV`x#si *$9aGH)eFhg ߱v rmBFQv_tPwjFjW,AZOAjpUMw7pުRIJ?&qh YɖT홗 r};gI1 ;VZ^@QYT.cb?H#L $>08]2nD'Et(VmY6S߶,~҉8S YkHo0|0FkuBS]o]6yoJߒ;TUMRCJNPt4@{8q^Oa eLexVWo~o*B[\ :*ęҁ# m I<E/ܳ9B;ȳ*[WYO"i.[)C4-ÌтEZfE(07ACYSlwȇ<>%I{Ʊsʶ8]:EuqN,pK=0^0P;[9HDN<ӥ؅P9nIV_vlLi<`ŗ0NZ!-RXi1@f{ Zܼ )6K.ځ$KA_3'Ȇ%e<Q2qIŔ}Ss'Pԡ`^`c- /q mB+%ĎwpaR,Oc%hgWN[YeL6g"P.ܩ 8a5->Njf'4$V)ٖ'8a2g8}Hr#ҋy$=yVŜO,rMs9G<ɤ,?XRZ *wx:/#O~/R5,dC4Cg:I7 ƒ: 9ٻ>jX94?5p'دvz;* 7_,K9-Qj3ʈm$O@h0hqV%AƉ1`X2` ᙑ_\Ӽd¸{9#u`@V0j-mJ=T5;a*;m9jI [bGz`OFߴnIc0OAS@lI3/?xRSz;~9eZ9~Kkkz3ތб1Q2 _|!oM ]o])B!͵\p0 hYv^@KR-O!#EJq`Gs!0?oT?4)Xad-Qݕf\&"t_BP#&x3J٘g~Ko8ǽ㜨CoFDqZLXv B4+hNjs]wkkIgWwf"yfn`eFǓvXڐ7&I2F\ \]|FY0h;ب{{I>' xq:z(c7Hֱu'3un¢?L vP5.`^ˉ'L&JSGr=du𲽗LZRReȦRX0EƧ0>НMwONsBg ZV%}o@%j;xDPPe1r6sa_j4.ECb&wN,[ˏ,ѝ|(i$B*06KREc܎ʳ{7.\R؞ :+<:?6qǨА+4{/D{XjҫގyToPZgi&Ѓś-,1<)4aUeD06RؕL)auXc}-ǰw O-t2ɝ$е)wx7$:?%m&C^HyMY>o"~y[+/$]2ߺcW+TdjNs)Ia5< VzbNԻa=w6#)lGSen"5@xuyҬ΂$%\I' 0éˠ Lh恓M}sY |9-_](YJQ=mB#vYHKu:) WjL8).tVNf-.Ybk-yz*a^m()*b:zG?clHcg@ {s$i÷ ׌^4gfxfY0[aq}}xA!M9@;h]mQ$@yg4Р/!\B ۽ߺOc6Zi E" }nAT+!z*mx5B Fh .)KLM™)Z(jvoí}[`띦z740hLGyt؈<J*A-9^F{]r3%~Иm,،9*۹̞F|{B%CAQ5ɿ,H֩pCq%&&ܥ%Ü]OchKu;Ҧ>ϓ r.;-H83߉$NuN9 W!QY iѤc截p^D򎺝2Q" 3&d;ݺRn8MLoф6T׭l90AP4 ŞS urQu' \q2ɫ,B*BpX 榿'{,GsA&GذS,6! T)нU*vp]GΛDafH;)*ni#퓯V S->}1p= ǦGTv8+UǫlפqV5^}khzmqTyu*"vW!r2 K7p&y]z3rjX6h,‡<,r ZoHᾃ솖-Wxe&0p.@ѴpGMQ4gCa7 |ǹ1e4lhiuQ|\`vj)L,m'nQ.I.Vׯ_wM09euLJ4Uo.OgDiO/JhVa_!-po0n@5%@ {k$rg-Iki^;K TeF\Vt`d}O=xAxl.\.O GFkbCnrâbcՙ)G.gI:<Na7OgedtCymh0[fFCUс)A*XGP <Bn/|" >BqIJ ʊ!~#hC mo*DuÅĤfQ}vޑ/}+8ѩxacӇOy߷|_./>k>["EsGn0:))//(]M_X ͍쓉HV`Ih3_;ҍ'JMO|:@OС)>QH!`R{ah67LiS\8oy[BɊ;ώ&6#A( &kJinz?˗bM=$t{rf5ZXliBFHt)7!؋c僕2,J6K_oGP%(}I{Jrmd<ΗGo٘MyQV %2m0n-Z~pkƻH_.IfBe)kaa,f?g-ƾlG9:`do`] 5%nesV e=Jň8IIyuF 4`r.A#wQj9$ӊ7i$0QD?0U.eR5%-;b7wvs] n{Hҷ2Xlͧ:-e4nB$c'>INMC ;FF]9$Ϩryn;z*W;> n>ҒsOU&nHbyY(>(1~ ۱Ԏ ;%8ۼ2N>y橵*gK.%x8+4 ?c=n}/+|snĩkZciPS/tsY>͸hG}( D.J aH:%ñT.qk=4?G7s08-.YZdBJ5~otNQ 05 Bs7 mMسyoUL|BReV {O]"V|M-ޝƴ ;'D6#`bUslPG$̏]߉" 7tIZW2DwpK s8cq jvwm*?GAuؙ2F,~uǣYe)ai]ps-GN+"J@z˓;f`^&y. "(p7@˧ uW`[ E‰Ap^~xa;DTKJ\P\3W~}ҁhkkrA+.*G=Ո}J?0mSWpt h$z/."([)pG@doJog bhƖPDӋ1F/R^0Z}>_1mMQKޚ5DSNm h$ٜ:JxQg>0Q  3Sz$C.bh|co x{jzX,'] ^v\@>]C?3{jRFBA2KQ;WeJ ,_S ?2orNW!pU}C+)&;Xuj^NNa+GFZ7;m4ÌRL#\@rIJ|Vֽ~{Cȳz:-ޛ'񃀌ᮯ&0=ȑn< /V{H 0jVmQuS[#5N;C)pnoKw 3+>sXߕO2ίqmLjiMpwlmMiK~ N%v~(=]3m ~2 J v&xߒoJgҴw.*g7fS=ȇ=&P/g ;Y=;#C+"dQDWNLd!`Exg3puq~Fj UC{>!8p19]⼹EoYæ CHj6V%aߟ"Q&  kO!C4T71]8s*ꏉ{GwlW(X}lsԓ4fpOXVIR}*"P6z)~OCݐD[Rש5p6"E}{pwCP|Wxm[cȏ‰TȗmFw ~“Hi|!$rvT;Q,Y#%mfE˄"*8[ɹu+3 5Qqg΂ʷq ݜPYs Ea6N?Jѵ?bE-n7oNbv7 V'tSՐW; =Cnfd\Po:^NLh4Qxlf26)a :nS!r>^'g^:שR0u !oH} w=mpBd@KgR^p5! RsW9mUv ?V!1&p-M' ȉXBvl uN:잨sQg[Ԑ&֥FB sieBX5!yY#Mv*6X U{zםzla<^OL,ũԟca]+Y e~h[u8ϣs&._wB,=:֯$ \eHcCm&#l.DvN_N'({>Os[}bd!erp]P$ԛZaD^IR: E`wŠ [l3c/6Kn.#=(2nd$h͎|ME7@tȢ8W@m6JHwɍD-τ{9īZݵbyմHEaU}CT&!NRsW)rxX:[kWb$vNñ&MVFƈeJ̝O{Nw4C)Ɩ2?5|,( 7tt4Pu}c;4 R=iBҌʇMW ug~yӰZS% pcQ陓[01B[,mBFR?>"舞XV+O&1G#bi jiɷXsbTYjn ZyVPݍh[eizEN VVƍzI7EC,7]uB| j̐jjnXMZtRP|쬠[(ƿyy^7uTˇlAdo$&YK ,2yN\ToDs S<%Dvp2O (X/ȧ]54s~Ds0*2I@y˒n1a z z@00RɱٌP\T@Hh\P&ga?o{\`řlqډP\a\ԐQXP&i#VƮW(.t&hn̕XXHK̫^$R̜i !o&_xP?]ZAn.i_Fo+,2Ys#2]^R8R?5.7:9'ħz_ rjOۅ3eC%w_ぽ2To\tro7vs;#"[i{N -&r?Iך+@o>d$t帲;cy?݊d4r~ujHSj$V WD{7|(am ^~Ljdr9T{ z ;:=mm\2ợ$.+u]#V#{h&&dF",c7'g aQ ?ycz E;Z@SGHnE璚҄:Q"䇡Ezi$vn'ۍ#/ȩKɴID'y"+{ZM ˧^=m+X<5Y\Nb\ڕݲ Bb]M^l響e j>g;YI~Y L,}*N:tEAg> B6I{ZoJ62Z߳ELo\*vjܞHʣ;M^-#>%0gW g]dX!tM˹N*} q`OX0ͦJ7F-4i6t䃉Lt$Eä}H>ϣ*EV[NU<3p}`Fͨ</t3?4r/OFF ,mmlÜpáCP *` p3~ؿ`#'˨0o9$g6!Y =Tw <?VdWG|hӛ6 ;4 ҟsh/GXTQ?ôYfⓡ-1c N؇p3$xhNQ/=Z/6N,܍_o5s 4iv\eo4~lN ;g.nOgLJu'6/?%|R1AnYD~4_OW%!"S ~]'f0Z =Tk>]pJ4*r0 Hm嶓NóĿ/X*7C'e55#0 Bv $.Q8ZYdT>e"of{$YD>Gz)=_\R쭵}Op.bL<>m6'(:AdcV#ic?ڣ.ySA_o&2MցHF`uĥot6$_z{Oŗ󐸾Z+}6qd'TS\<H q9 fv\V>"R~:-?G֥(qc3f杆] .Ljp@MH1rڞ帖q,0iCEt^ĭ}Ю6u qB1>`iƆ׷%VUeoIwQb9Ъ^:A}X>hx%VjYJ8mNAu:8ich /KAHTˡ eZ%4^ʎFq"P׊6WYb~}P-{~$"gFxQVVPeZ@3 K&i\?K>x/rfyb{1-4Q,[k%K:f/ 6NVuqPP_ T73|? y)?MQGLSCr<9ZeKVZnc!y xҒA r lٖ@(IjmhD(Fr.;*HF| QeK֭rOM !f'v@@vvNYgbVNB/sSǶ;¥-kYg1 QX0JP5>3{yl<%;)~ıaE!~]OWpoæbIz"<NpOgdTd$.{3g;>tۛAJ,'RQ рr>ȍ8A#)?^EE, v>qln;PnHYhb"iyKrV⏬\U+巿׃2ss>eנo oՄ,7A Rk3R0U۰.\AˇyMcZ(M|#`eD~Z ¶\z 8JMfE>NplǭLY=}hۿ줻΄kϢ4AU݉;Es>KHlhTQڕ>_tT-dzJaԬ% DB|)8!inF]QrbVx9塂4a]^zޜRwFP_lVѫM~@@~*P!h-gЧ>SEڮ; p\,hQAYSu DN*;TF=z{2te6 :|_I񗗥V9G>Vy*@x]œ ] F?kE|1YeC[D*=kC7/BU1\w-c%6Pmm8A 8 wv`} : \qYlb%5=;Eȣ9dZN wBŚyx<-F"D9ڴ:^èٶԇHuYKRJJF);jr_(_d%Phyoj2z1ۖ/iֺ!ב`j8/V nU^4< W3%~h9B~z@SbXQFy":v|/ЗNhYU% 6bJb~")K=MAnYؽZfEn5q-qhd=óܹwg!+Zcªu9-!sYABҦۄ> YC 2-I\GƼYVA# cF p`ǸY  JC PHyǼʺ|'25e$}"6,կzN#ٺ@O*Lx!yШ`Ҟ$ZC"REsq4,{T⥚r3ˢe,iwܽjFQzр/hjhӹH&r0[`*i'ى0PIrdy4T‚N\qQ43c)d™R8Жo0mc"x9A˯FxBg*GC Mf!iNCPI_S^-C9Ja'1DI%~~PwEFjT|iPBM|ۙ"\TQp->kFfFڂ9X;C2}x뎜/r%֍ {}&ǟMtR%QWD*b<=ny!PyMd_BȯxmpZM;"`F2^TR*ldUqT+ 7ō4H?TSoZNC*/w{-KDT|ʕ-O80Ջ;dd;ҍ-x_bV9i&yqW jT :mC=AJZ˚\cUDϼSUշQ}0 =5GQ.[2`+~rd .mAJh2 JoI[{dNP0u/jy6KSDe|>"[vG{P\b:i(JFn3۩zI"x&btJu-vA܅\{ӳ(aąDVTʮMro^T9txZ/L?OJK$PA,FXWhp-7 D;1nGV;'ڳg>63 _wa C 檆07z|H'7 n$*)â~Y[Lȑ'x4ee׏O0DJnӂ,c0(O5 :c;Dk2䒸K3hh5zPzJ/DLrk+pH*mثAx[YFpE[ ߯ŸUccUu)W{I'~H>XYGKi|tw#>hCrw񣨳6ȲQŶB9 >p_wYUbL/rJ=Wl}Q[~fհ@]R0 =IT\qNō9 I${W=oA40HsYD :yӈhzcd]|ܩ*A=ji!z7.%sA ASMNRxYwA&]Q Tx="IqxC2,+-Cy.6ŲٰEOgY:7qܾC%)rn2ba)ɊxK]5Zgh{`d&mN_ɟ;HJa;gTWs8NpѸ| G9y^A}7/ou"a  xg_$s=@:M&O%5FClޝ|q4^j'Ǎ<݈Hƭ̾L4XRSDݸ(yZ-;c~/7 b,-rnu'pK5P$Cx?<|Qbx{+ĴSR7|\D';Yּ֜EU~n-Biqd1kKgqU q[K0beUT?RYz`+]#&H]_{x~l3CMc8D]Y[=dMN/Brz ݋N)-yoOv)~MmB亲Z++6PEIx'13.%IHxnyNLj D*5Y.Kk) ޤJ}dݛJ3\}9 k|m$"^F?0Wg#dSJlw'3WХ<6vXk98BFZAfIĠ2|PMysQ=lߕ1f]CMvR&%^bT+BASM34tI=96{vE!C@JtRpѬae~</`O_16v?Ѹ* 0퐸)l;9:Y+QoW^^dJ~ۨ&:vǾ^ ܶM_4Z$*RH76ٙbxQ{w{#L+vF 'wDz THjoV6S-aq,>o&IyRv.̛`8зb"&67RyhK #&pRjU7u:> ,;x: ٪ 0&Jg|< ГusIird? M90^*u1&f]N-PSa'ιxA}/vS|zvǴJrUVXvgp^rJxN}"n 9;;vu %)weBE}<Ⱥ3iubOuYP j9eZD&֠K?=7BSuuލ_|flx+X@ـ/xY3)y9%ڤ!~$˒tr;B|ݘi V6к 僉~g/ [;1f.}c8@e^wJt3Ph].!ty@Rlڃ3˺OOvZH?k? Ƀ+>t{it &+ ̅2XZ,aU\ 5*;[DU*?Z4qZo+Qn8Z svmm_< .m֪HuG)QXzAg1/jXZc82ݍ@134կB(bW :w̭_ֺ:"fakJm$Dh9h"9XDKymGЍM)5Ș$xjI[d{#"U憊O}t:Mͤ)6<}>;PDS Saan^Aܣu눮#P!y\W$r`/ c8i_LxV$z-xu&s>9q$PfZz!_1 "&-FW "u &{]ҕ* Svi U/0,Ȩ1z=r?L[2"+y$lr\5^g5ig)ϻDshT~7p&ɡC%]0l6MDWۤ#]*lf7>KT~b_ JadІ( NS!+KMԔڪǵ2ݧNaM+O;",|v삽"rlhUe[^Ux]%R.FVS/ XS, U!/o%YJtN:k yAkì>W*L7& 5"p%3b78y؀]m mO9 ˄n+DZ\Hʆ&0CH$a z8p/C6,p4 Bqάֽ-f>|NO(*pk5<kCKgh@YT./'satlڮˠUDq1ΕF$!ΩwPr;!I*kE`%880K.a~NXb4o+A&d"݁1;9UDž+8mtVLcZEY  -rDAdz.~(Xd}/l{ۣ]x)p=؊~`0T}pxN1ً)IQfW'` rDKW};DG@hb56tX½*UnB#WR# T9rh4#߂63,/K{>^9.SEIǶ]5<O. H^' > ll,:#S; GM#Wj3hA]=m_o͋!1ngpJͪݳqH:[S@|d\ uuWTLT#O+VA)ᇯt9: 0űAb &h4+X+B Z;|b,2!Ru%1II3S{jds>a&囓rNG})AJ' "^QB} iowi0T A psKCo?oRoeU6)|Fi3B1N BR#$Yc" :ܣGlT3i&:Ƣ{v)C^ 0q%$V6|훌tWӚ@E;=]x@)۳ l31_q;s5H`8(R05&𠏯U*P)u0feZ F8C=m 6c2d{Ʋ"@#Ʈ~al2$AŪGTCf1=`4 Ze|Z_=gra"^$5[eGN'X}ΒK}"P Gt4]p^|njPt:E'( wMQ펿+7>o/᣸iɃκaczDI`ӚZ&f0>PLEn1MNzi>seM t܏<a[3e䋷[\:CpmY v;{+v٭t5s:{3D8Qs?I 忦6)q 4FeDE}ۉRFo&`.J{A}gP7$H=x9<c Y Oݐ9w \)%` C_[CCޖmtGG[ڣFu`Դ WTũlCN  F v9z{2[c&9'"X^ =Tk~YɬР$~bm1s9(kWۣgu&&zG\ݼ%8o3Yi,Vlb^|iP%'=OW!Fx]N%܇YA3v7+:U[Š:ۧ ȵ2a+*3D[ F)2.*Ho@_JIDmb!Pڰ[\F(]Mj|FO_ u'ʼt?g]q C{%ȗ)Xkt8{F+fDA\@YѶ1C0¸M&sY33(Q7#C2W3)_Nj~>UR WpVPo=4sM:,px''CgJE:ΝWcq)3x|yk FHZ֛Jͱi#~X8֋,u^,`){o;8 ߴȩq;2YuyUw82{ED@ހq{^Do xL'C &z"!z^5C)!O{vG#dvgb B5h=j%}TtѓU˲ YDo| (/)T S^$KMxa݃ג[lݳ)s1}eO2Óʭ,Pv.TXYUPvv=hp%rYTF*@؊l ^]vXoڴ*n૫pzIz0&r<50Lt7 24^A =\ x% z* T4>TˆtqnoC 9^vr'G`+ !awÐ3ZNoQ @evAgz1g8z.x+& `pmlR13Ӂ>E _-ׯLٮ0:MrՒC]څ.bdԎG$t% A1T̉_kj`V}3ˬ;*;| \c{#ӺjlZQ,_x~Q`%1gIнW|bS _RPrZNVjiY7 h1;1 #pTH8e m?q= UZ/fO,nEEl ܉^! ݯ‘;[f+jٞ5š;TU.EQ|VH2(9RlhmNILoR^W:#sirq18TP7$P4<ҴOV,T6&YhM%! e^mBt4E\9F ͽ c"&yܖVdz '<+ S }zd2vJ}WE H}OVBB ֞=أ X :m(U.8_=qLmj3<:v"Gg$?q\@HP/dI{j#TA/ .pn-#.yl_b5=E±Z@-8fLKFK< kd_+=&/zh2᝾XZCهLbذw+bӺna%ǀy5T(3# $;u>/MRU9bV8_ղU~y~סEO8ni.rXcJGk?&\-|ue(3(z޺@q( :BS$fީ"KQxABF[P,_ BtEi*x0N,ԴT{jYm j7 XȆ =Y5^T{ZLU@ 64Z59{;/,(j<6oWw0gb6u9TvlCo%='ؽ]c ۿ[C+7 Q%_l(TR̳x/yJ>YavLߨD;s]hA_Wst9) ]MM.{#AQ s5| {:H=w'ȌR-hXi>ntYl~(*,LE+D\ml0N%2:uo/SUZaZlD'A#Q E7ˉx.VuXBo y"U L(o?[$cpVE H/.mii  ’5Q1%Q'y>. Bt4IU_h0l!C&(z'A=ˬ@>ohs]qMFkDlmQu; PM=J!.i\\gKEL#D/m愵*-O];}1D iA (dGSq6i^ rZ"Z."įBW\:B0|O>\E%RIBnFAb9{ڑZ*"GzYkU,T!,Ȍ(8V''KF\hfGʈ >G^#kFum.X(Rtc:tWSIp8fD1Im*k)ۗ"VZ-6̸V}R{|P6xɭUe:9P }b|}4 f0IoCHgHj1V袴Fw^=BD"-g^Nx,0@͈,t< U5sʶixBI| u !?6=>PB).4F4@aQYKd-\e|n,Fzj(u 47-Q6@hŐDjIl3-5x. bg@GcHpI,%->}C$XƝ0۴U6!K۱e~'dF&|!צT4a!?YKY zį#yIz;>*LG)%,Kl4N/xw)hx^Z1P\k3̪Cn ?_sI PvNαSa( w9\* oi4;czP]pOOVx 6$`%D|ۇ &Z*dp6ݏĩK.ī6''‹3 _ \6n&hS? 5ŵWɀz!vL^|#L&V^es3#8iXja63򤤲1l[hjxd癤QvʈWeI%i^=3Zۧ 꾰!/i!`SZJ?KX"UB4*냊+}[ME!5agf6%j2+Q7oӄ6]5&1WI@D1vϻMktԴ4g|3 cBٺ{ WS[i&"fџpZzD{6Ss/R1$Y?D^8ur9J[e}2^(OVB+P"W7\sfXd2~B CML$i`+ׯ v[G-E1[e2pjHlQ?&RƸ];IIu-e4O8KVKѮ>a060,>ԕ' ;^GMЕlYv/zC,5\д-ˬ8?)Qh6cyh7!}Q=+JeA.pJ}4!/>O:@c<ܨk=F 4?A~D$d z֏ґz{@ d;K#qzC*gKQYYO%YWJ|khe/9ٌFLin词3Ht NKP'/j&qj6%LXsijw +ݕ,kCF[g7N2.1HdR[@4vUÅ fTJ6rQhB *4kpKteWvAG72R̰P/R63]$ZH^}!QWطԔ#[5Lǥax-ҫb% 8"MYkaFG?=`E%>3bJ IcYn/' }QG;b  ǂ/nGg9ŌbPwgs(t⅑cD4;WZZʦ{ݵ;miV=jó//i23L?ywZu/+ Q" pHKum`J? X5Bu'-<( V@V}F@)vŎu|PI@pٶ; Hu\Mc+;NԷ2k`ĿMEs3Fh@Gg-̽W87[lc!,<[cTvHQF|=[4D53<$')7aM=SdYMuo3q_H73$&]Z.@i}%z"&̽ F-]yUPa4qN£N<%r|NZ QLi5r>~Owt(b e"ek f ,|W@u ,׻\FT£5(=< q9~%@@|A \Eat_?췦(fG)tdx1I5B=A,u[!dR@- EE |t_NnGu=mmsp2Ж֒ &+>`pE1 XSbfÝݱ,蟺Jܡ@(@ul7o̼= HAZoC:ˑn M>3!yMu9w=gWJܫ4KqPaҏW<&]u@>_ϵQm&|3̲BOR^ ))t<+6HƷ e,,Kϕ\*>ue]}58_jf!wu+GN V= º1QQމs "S,ё`BoEڛZNj7L9{)Ve'@pC~|D`sTQ pNWa%O%}PYJb{v35.&䬴 wZ ^Q ` C}B,6G:X/)Tfr_ME5(,!>7A#eij.[j-wJ|Ey]Tbk6jg\`1ZTjn"ݞvS/9 VHZxd _,חʃN/-%C\]JkF[ mЕō- y}:iaҡm3Nz2+dqj~*YU@;56K9<,pi?pz-]S6"s Wr,+c84.LǤ$b'cm%I5X" fdC֧(` 6%\ퟴ; f感H7Wc(^+od pJ-Q`[[m"x*86(Anh7'oD?52i| ir}/a^ߐ})4ey΃"J!Y7} tʄC"T8yex 9z,F1Ujc/"ѐgsT4EܹX͒$Ӄ78b" &"TXqby35,K4EgWT-P8)SD2)?*E{R+ O`s\f!m] +3dqlJHz:H ӼXߒ<(Wʬ gͷ$H8nz^F'I4n!DӠIS.A q$:LU`{U54UT+]L+{{O{NS.ϧ^Vf[Mݎ)P5ڈ0؂WV f0t z#@dv݂ ˨|L*p94/‚o]YCrmrcsE)A6 @N"C.20 r zkn Iv֜!G?ĖID(u?2 u\ ƻ$3;$}[4DhAQXƙ %@.ifmc瞪5_D=7IꁓzoA\U/TzTeM.tK@cQs&i\aL#KpT nR 29bX4N[>;/.}#RF?pUFpq혙a^6FZkT=7_ ?/zj<(Z)U*mgVhy! W]ۘ i+Y!V׿r"@\'c(l8{<SX҄GLr<DAz.r ]?C\Ԑl  ;E@(?mYM±L电S[(m%&[ԅMZHaYpA DPCP_?j9VzMKWZFqqAl$<gtf.SuKmE[n7omN"EW܉G}C֟k ixyy ip6k UoX_4m?rKKxE[+F =`Hpy!I=0>$NuK wjL;:3J"R#AR|5[{h.pE'֚PaJ:"@dkZv!҂d%2”ƥ . ߟd{mn;g;}p97|)B'Z`Vб"#t<lR܆"h=L˪IA@YO_CFN{T[Ӓ!WqT,G=g0*BEjd8TѵlgPp me8#ͿBN;Z6ᖛ #|AZ4s5Dzj?U7.|ŎvRJ|rQ 5DO K;z.aEd?B"(=A'8>R6V(;?E36;vAyw< 5@QB8`syC-T䦓=r `ya VǧΥi?19Q9 38vBU&"X_N֯Wq``?)xR"}?wɹj#wf!b!r}EEخlphfǤ8 XqtV41E,U'#4Dͱ%^9W/'r09#aL0 `1iܿ.Z0IWr 8ߘM4Ywly%7@jVsIɖµM(Wǎ?htE\K%X A!袲Pb:0y\i?> !>Q?H,]4?P42+sq17(\aX V9鵘=8Şrh&Jq,C`9@ N5oM* r! B|͠jj. ] Kh4TW|HĒ3MV<"EY ZAg``77znsic-\Cm01]}Xk#J$y;6oqB•QRrAo\cxgڲE$v ^!a=U!eegӹ'eR4;ke^d'k(Nm=Q> Z ֬>m1f[0EIʄW Ήt9ɰmř^5 ϵJ25r]o0qm缵tz%z,8 igDij6F>g?,]-y⣛ rӼ^q֣7i:B9Ecf9~Ά{2Qy&n)6@/1UFNvrwgtBh$F@f]Կh>*^R/GvPr3Hjf<-yUYyye]OM%h e%&2GY1lt?*.8)j.UK*!Cnti#i>h㯸>A5RD>~Ybr9ri6-va{QLfu)~WɜXCgRUHTb =P> 8Owoc(+kv{3<~[*_Ǚ;3zlSN;VhQ?,6 \h6)pD4ЇM:z DVOp.B';;;aQHM#L4 amͶ&K?/Fy!n. = IlJoU7m` $JaR+9KS~S$Sxt" TM,iJ*{"mW!pOAKM l褬yi(jto*]қ'MW⛣%y[<ǻ(OˀJ9r+ cavkWg&.:]m9$! ,))0լpa{'6#aZbvq y0fv`t"Ǟ= [m۞lcфA $;s#/f31e>O]754l\Qv%j Qtv9Ohp_rsxz3VSd!R[ ^%]6ǁf߲ju̜_|0<*A1am3(qAu87< "i01rZsޒ,oMʲ6Sw$`1?/aD!D#TwV3ѢWi}˲V1&3%_ƉE4M"҈㠰vNCTY.yz#6?`"$_gM$j8ڮI\ ٟvduoF򋳠q`g,(e}@\=$S6l7eN|}[eǧ&bsS@Cn--k6-(,Y}r͛@?;;]LJ 0 y_&zYg NkOnMzee02뙰(eu!;9>V6D)PW URXL`se[6Թ>^Qh腆oUponX6ڸm6aIWKr1ĕ]ol!:M[@@k8>F̌W3S#NK ]kz? o m `#GFk$f[}ed*s-}` $mkXAEF6\3,z.'4ٷ=GvmneI["&IӔ6(L,iTl4uBS.rs%u7AujȽ +KD/IoVQkkDm&x!wlV׿+Ϩr.ɉ_̽0w܁e7|%|TktwAxj[lA vd&ꍠBjc}Q!HaJwT|Kޕ2=@>|΍5{]2˜P_>N: |`QfXH{,%; /Z V {w+qn]\M)kmg|-c4LӁ% PC4KkllC(0[XFq:U;>+6/R|n>|o6x rv7`zsCj])im⦞RԴQ+y. f{e >U~V-jΛm"d0SGBde֞-e'N$7T'`kYZ;y_JQ*ѯ} kT՜+o3N^r~ !C5åV!9(?vyP\LpEӋ`-=4_C2^ fx3b^ShxZqĂua[Aq_d=q!|<]6qp>~ HLx|K9Ey 9(dWZ EBlQmh)Рqu4&vn4|K)%t ԀČ.nIܬ5~tjKpeBe͹@nt^??E+QGqEb%|JMac}%Ͷ"`!K΁2eф 26҂rڧcM"3)ŮGWJX{?׀_'< {p$dukwL]4ڥFVnj|߰ A2E^lR*ٚNؙ ru_ꞑāW/K`.Ė! [_@.^38TNY''W0a;)L.C =p9FYBEv35JOGU* 4LO]) NW"*kW>re 8Vh `W`W4(X!H&ot3#nd(hɡg#fͷuYYN|. {W=#iM?mۗUĄ# Bd]uuH.ܰio۝R_+͍Wܧ'~IUi$t?ߣ=n`%d0Tgo% hp=7@ao8be4t^gYv*s)62`J++ضoQ2hm%~#M\*T=.>+x]!&Ƭ+65$,Dۤ!iں( mP?GgHǙ;/Uϰ}`C$g]8 p:QP(,'Ҫb+x J+~!,3.J]A\o$ǽkNs!]ThCRcnhhc-O*6sj2p4wu=On 8D͕xo.-t AEV)".=q[-ǫJxn˂q @NXKm+D H>;8zNL*v%EWIjo";[aHWc^#btRM_|oBt5HX") Ƅ6Ϲd*EDjp |89i䰝NQ1]ܬ CfB]rrZkJ)v4~vBG|t١`[Z1w'fUr2nMbF<2Zo{uyysٚlkQҡ:هE5XB|020Q^)i eֿI>@5^L=4_+eB^)]AA5oR#F a.ZAp~bwl:J)S>>:p"JmLlbh@5+Bժw"6h^ZDzӖEЯ}g݋N8cv?LΎˍ|=F< kb4=&w77mY0ֱcAmnYS<EDzGS)umuk.H ̯+zn3mK%{ /ɳ&>#ܨxQ6zf26TA3{֋݅`cjxᤓc"50V;oZXqùĝzwym˾؉*HUIpK#T^=`Oےu?q:=as>;?Ej/r(B2[ν?!6l[^.,xsp3gD̥AjM%L2<$fԻ\ ِlՌhFͬKOcz]tJ޷ТE؋_`"O*zR,0΂SĦad\_LEO hS/NҖ~U>6VΏ eVސıŋW?~Ǹc˓ܐvW} ٲղV/0R:-"pF숞lzdpv&f.d<.SЄIH)ZF*-SEˊr>Sɻe,!I_T&zKm=xƕFڄ\tJ5A(ٿNy$o)xNppZM2J纍 *g *Gpr,G{?^BNG6I?e*,iFC}+m<MNkoP[@39=< W@* 5| Eju5]˹nlA42j$|ɽM+Xp$+`LNXw}I9zX=@<k>30Ed1s=L)/jhx $;XP3Xܗ%Xo:1)8kD[FMeJAi̹(vy踶;$J\{zP+[,%,tI7oc niKJ3AϿR3c*Wp]cU)ʲO*HmoE:WCvgU/BK9jrwr ٗjZ$ȳd{~c-Gdv#}d3$iNK}>i/..yEqKpO oh57%Z1yv4/rt>OсaM!͛#AU(uyS[₌E uk3f;P'NwaܫfQsStN:#N&/z.ॿwE@6P&ѱ@\ܤKX݃΋eM6E>)J %U)ţ:yKy;Nƃyl-~.$n7㝯[,_"E_ Ν@춤OݒUUc`3 oɮpG5r$tdMVz_Ou=+ PS볘D qzݮ/ůI< vN7IfM#pf D>CBGԾ#/2>+"ZTQo`_Cb?g[یW^XxfNEc~ 8ۨ:ࠔ\n3依˜dMB0"/\ײ s "o5'DfƓ. 2d6Vʗ4||܏4ttZs֐q_ǴX<+[Gvt+z}E_(&!Yw(ɶ6f!; og.~MIQ<53?ݟl0哧oD[$;M/6I0-@ԴކzisE 0,il,~48xĊ뤹96Nxð;(pN,Yj#M, 6bT_QI?EW`ϏH!/ۜrAvF?-5ٴ]}bx,­Zū,vljRABE[퍸\KjscNhMA-[g>'t՜h&U| J k\C8U-0!eNYȞu)WNvwޖ .]g}WfO Ht/t''S´[)O4̎IBR6w n6OE7Q]c:з?ԆyF[m-uls%Xri"?(2bڐZ2skuޠImPBj(Xú-;%4Z|NGvX/Ê>>z$lÙI9"yr(SUQ~ 7ښUWytw0D0k#QFZ!X3: Bq ZġY&V{+0*UqD9uJ4COD)*LWdu bI ZWXs\Ыn 8`e@NnU~ˈvZn["6Fs8b<;_/}ecMh$ L/< d:PfQ2U#rCHyms*M!"wnl>V7ky$nZX .ٜ|Y6$\M:Qj8m?: TU%RutoU pq 5cKahCŻTÈUձo~xAe>er^=X $!GĊo@ˌPlȐX Uw 7L4oN2=S˿˦(9%4>s*c6XxΠ$-G≪6 NZ-8{gz5% 1_͂kύ\2RTs+=|_սTC{ۊ=C}+A#Xn$hࣆXq5 h`ҟm d+|L)JrԷ,mT2B }<_h̒JA1G|NL(.654Ҙ&?sdd*bw{>a"ݿ|Z#$&#j2(ENxul2o_̇d?uMC%#'}]5ZvԶwWx}Cn?źƷv}e{ˏHѡ3p8تcrRoz k^sWe2X+m?6b ӞXiBV=󨋀;8ATt*q;@/uT צcc :6Kުi7>%t*޷GŹ񂒟RT_)@ڇ%$tMH.w}"C|}l#)i2r6tt f:S؜7a^_*}67a9 `;6~}a6$q߲3:ge[1>\Z^:@{AST|^mkYf}ڜl幙߸ a:&ޔ2&V-gLSaMfU<`#0\n+hvzM8|9ČuPpƪ7pT I®iJW$+TuJ #i8dr OÏсE~ɝDړRL@)/hJP@;;]{0|^ ՔS?߶q1w8l K*`<T9[b49p#F QBjRoh:Lto$&>3*< /=_t }Kt5_jeiHMW"ddOjRp 52v';b1nwϸL\̺ZpHzU\uCG2R8 A5cз S6V.h6yz|OYYPw6?px!Alzv@7ؕ6;ȩ]0\NIO@~Q a:~lV| v v>' 153/ ûzܭ0x 6Д̙8&o(htYX|9?2Hw@\PHZ;thqb^gul/weSmM*vMp4{CEGT_%ew sr2ij8kv0@TԠӏY] 4K v HRb3~G%m ]\{Mo{֣Gfw[YZX+FzK ! &1(0+ϛgIgafZ$cSV7~3 dgFZ>8_Do̒ZVu2S? #Xs2?Z냊f*) 9Db&lиcQ~uII_Q%FDD,4Q^"3JIDppW@)}Dq8.u{ŒD'-O+BxJ'F̆e*n%)⤸r:QpZDD*h-b;ZL\ YI~;pxсB-ҍDVRDpbńR#6 |ʦ/MS)>O=?ͅ_k8taK:|r\A:;Σ"guBF;$/fE&gtT+p̼^9y@]|)؉^ξ768N9jViݼ=֭q97 Q)#D؇9Zxl8ցnT$uw ?bpk]l)Ac*LpQJ-Te'ǖ9=j~W~k]_]uh7ž[Kznd~ Cxy귊H''4V[Gߪkv5팉Fb^!d<:ؔEy8,hyI-JE`GIfu3J}6㻄W(Xc/:T[шMc遬 %^j;%K 𡷟bУLz zf6E"g\3hW9P ߆/=h@X£.O5_F\O-w4T,CTqZv[Ȯx{e<8&A8f/MmN|F/[,R~%ULNHejI0][nϬ)٥x2c=!cӁ^EbZsi% )8^""IQEU!)Ud-?ӽ ; Y~] ծ44H8ӁAœؖ%Wַ@'Wyq>1CNS_ѷ9Eg#O Zv`#i9f.Gs!;aB4%^_z @ g p3l5J}?}=`s4zc` `Թ.pbCQZ6xQ$3,vzҋ ;rQ'|l+OQv,TN`FUSrF z4|@D$@K8.UC*ƒe~k%):>oFُH_Z<~9KSOFTߨ4Cע@5+ދvVWMdصKF 6ic2% \~TJ7܍$0;KrZ*RfX-Oqyz,5n,Gxm$8霔EKtEϢMYk8#܅_e۾K-_n:U2GYoҋNMR_cBAg;&:#oG/eu,;Q9%FqTd<؏t4F Y4<x{?,7^X )3r\iɚ.uw9΢U! qݾע'|vM#D)舑?%'Ƴ'@7iE6wtiIRH 'x,wdɕty3Fni:(mf"u& 쪁 (FjɃ#FߧK53N"BWts }u7F9ᬓ\o:C{uQEjw:J~`2DOGf| 1L+_Dby!a;Ec2a{2)E+-TGUQ q.ʹ"ӘVLyZ~FwfUuJFuD'Q<숡11S)(eSiP$a^ugw 5$bJW͋#Fz;yIfH RUHh~v`FL,$ ;3OS!ffQvI}E؏yKNkrW pʸWo鈷f͆ tY35*KgrާӑcA@ѿr X1v}U٥x;gS͸#Le a=,, dri]31mv.>fդqAmT4>KeJn G71Oޟ̙ hgE6s*[lYÒ[4[uQy?:zy"lǭe&vY%l17i-*?h0QrR~J:&Z3vEXʂ@>*c(2 oطE皵 g, w[]`QC=9pD(&k?"9tvn;QmsN@ϖ qFwr?Oo!;SQM;C_eg)[?*Vs$vy+)[euc$ؤ2*);W2J]n&WRBz9%DWd ZLB*)M_Z "Cg PЍ0C-5s%hwc;+qٽT #ű-[Qfp@(eKx! >ii}7aCXj&S-cix*Rc`Ѳ 9k nMj/zW ^cxuߘ/3_=ΐ dKW>x+ICVk|[ w-zgC,sr4nYܵބ< xݏ=/*X:6X LDh|-Oq]{25f#]?h9B6MY|vruf))%`  fm0 1L?`*H//GZhRb4KRsB /ޗ!MkB?!x9;{O1ye\QZS L+ojvaBix0ZReѳ5~PU<[s4 0;N+{e5[^t<Ѡ.PB#KtD6p3DxE+MAòp!ktO";@ɤ@Ŕ]̶n tՙ w !0]qsh \8B^ n& I# !.h&Fo&=2Hz xؠ9舜n !"C3ػ^8(l kx-ͼ򵑍}78ې[. b$Y"a>ޛ#MSWZW}Ӵ 92n5 "ro1l]V qq=8Z"ƛsVɑm:6EUΓӫaxuaH Ef(WIj`cz505,l_1K[ӵ лbEj?D6WoGSbxmWoREGLGek,ī:KBR%E_WTXS5$>ل4Ov"Wdr/XW{g9F)ͪjeҭ>0]hONW@U~Uo݊]^u MLj *!qHB Ytk"萃V =n}@_K1b7 ^}<\Ҟ)2PuI8A@ "FF6 6ʯCX6~ Ôeq5F4vNN7qhIdɯ(䉞n>7b"gYRHW jz7$VJ؛ј\l2w 26 u {3J .EmrF9B><3snlȯ~u9,~cdV[PfJ L`$=NN@+PqNg>p NX1lՓ G sRPoC'ɎV9Xh!/ɅօFܸ ?kk~C^M Nv-tV{IEm9Ȉȷ|N oaȗ=G2eµ֝I8ٞ1 hNKJڗ]ft;ҥ.?>~M,C Syp{r&aURX-ȯs^ꌮZ䨌\-Svk;2|gBg6˟`հw<ႨQD2$A ׫nɮQJ\Ƞz˨+>Cȏk(OMc=Xh[e=zLs1wyәX dzݪ#"Tfy(iفF$&0C }RNdP@Ac)\0p+HPŝbŴyu5F"P7iH7Єno9>|=C4 h~nGebE[#' @+ߍл\.h O2FǮ~T] 6@+eAE1jB齣hw+izW?%2tQM-ImJ!ڭi5TKhT{B.ܻOu9aR_(c1i"ZwN #E.fsn,mDn R9r #B8.9GO?==I3fV=DK7W8WR@s#u÷i ʠdfXN&8Ap 7ak%n[zqp"?|g6LK:m4=b#^{u\{0:LOXvÍRk6ѱ.%sk`tc4}:X**DqQW6ߘDydgZt:a[roO0TpriI|5٧Yavk.ؽKr?d 㞯 I,𡱆4b:}hvqޅ)zWXe;<{qEapUm !l|]E/ Cɺ09$k$Nə>F}cȡCvƚǚ[҈sءʍ udtΌo^OA9ck-<dVkw!v/8@Ե% zTxiSIa,PՔoj[aJy9c[UnCE1/ت`UFB\VX%racEaLK-/)VYb#^whl7 ;HZGY=P״Uz*ctt[AL^?Yf%mq݃JSQ:]Kgi ÏͨI%mܭhԗWSODƲpQfӷ`BQ5H@pd~UP3&TՂ3߷ K-D-KheHt!~lq7|aOgf'[U';jid(Rn[,mDYHt }XS\fk,)F qt8lyiu$˘ĉ=8-״賥aY 3qZZ/.,wĐ9Z0%RH؏"7l$qqdYIa rccdM! G &2EkU&*.ލ) |?v}-S@c=KC|Ŏښ"߰\q78-u>2Ҕyf"vʙ dV[q~ fސM䨴<ސ m;e9 ͔%_H{'QqZm4d➢=2%Cot,uv|4'q;I_ϸ͓;*T\BPU1hoR&}Z#MY dpC:|]y* } AR~lfO.l#W Lp؁5`_(RLy/i;Џ|rv%0]-?jz~r؟mNFy:3t摉!2_:ICa0Trgق]0Aר@ " 4M#s}7Αm<딖$^ uС{-ۼш'M[~FZ c':` {l!8LjYk_a:jשF/"f0hxHpq-_=-/2d3sfcH۰a1Dy_Bίg'1m7K)r*8Ζdnc@n=BoFQ7K& H=*+݋gqd▪ 5/k Vy;D*u^MXdX#"H,OECbK?389r-E0|\k:'/.֧/B$eU[{n\F3ۖxBNE˼ڭƻfZvZh/%%Ն)s7<MntBQfLx؟'rY@ bԭl>[ 5r :a j$:${@ٲq L;…d]!F]z\dMKҪJ;O n^ uqaۧt92 vxRW@ %[qp158#H'虖r? a҆0^yD4q0בJfU\7 &\^ѥMrG]aVL X Pσ0Q~02pyB^tf-M6ǘ>i՗ӏ% ݌ D5aI3mbiQtd כWS]$wү.;s#_7\§E[tb^̯#cmI:d\ɵiӂ]mD@s]jB5ThR/Dª{ZZ7tGBNe{.^;fyIyTCBgΣnv{:ICQZ,R|!3M6I=:M$}%"7^qa}]GCv Du-j2x51ݵvP _= Zh̓D!Z *5!E&}ALGY*bN#υIֻہܴPecL6zx×o/iͯQEx@a*0r=fuhnL*_[S r)Z-QYۍ.HbJdb4ȋ,z]-~=5mD 5X ?bH¶QMKOT-(``r9eöl> ȨVs{xɨnDɄR!U׳0"`>z(E!*^msMN5Z=vh ~R b0JjK PF.pY9>-׬C'Za݀δKE.p@<; ؟Mb /6 s: IƎs(lUFdh.M'Zjf̆f;tA&mO = _7^5T@^Y#Z,e!p;Eq$ k Pdիŕ֮v( <\2YЕFve?-uoDX5$Rk?[p+>JG}ꃠ 5th` ! aVG/4O'A>R&-Rk^)` HY䟃Ziff<Yx;8Df^-3elhd,"ʱPg9z|'a扯|QFz{5"UJʯ+RLm^6V)n&y*%%%oysqCM7~b 3S !(-g^_I|7 ~5"9vk':stYĎ+d5[%O5$so<:AWeJ)xؐmCY2`7e& -'qrPn.*FmH<ΟIp^q[VCP&:ZRjjNVK5HAb+Nj,T(~Yܹ-Q? DHz tNG*G8 ~g /*ZFa18?☯wӷGef!?*<}'_ScLJCC?9מߠLG k oTfeYZ`iny_/uCm̀ڤnZy$(JƬT2?Nu{P4ZZ3q6[If!e~ƾ]D\oJt1TCj C[-hBjS(<,>nղ,-sO[ZܘUcX|HIwQbleϯ|}K_-ښwW-6A^h#{BYqĈ;}3Qz#MҺ}C=ò`$jQF=x8fndSLԨ}Ҳ{]֞zЋ5:M qO{6XM~ŀ2WD6~wԏ~'RDl MݬޘfL˸鿽[s =Z\t~C_O8'\:_/3֦ŅNJUGSй!'<ZYY[S=Ubad 5xYʁ*!3`A Asm (̢n h|^k Zyh[G^Flf`kdwwe[=0-*>DckhmF.?N491$NlIg>f%c׌`R4}2eknccƄll j>jdLc2)1WBKG Ķ<&ǵ)Kq'.RF!쳠Vlʙ]o<w=!˄4LOh,kh=>t;vcϰ$DJ򵾲 6furGjL[[Ia]Qmh*`&4A}RɆ4Dqk DAQl&7V"( ֎4h#c6 Ao3G*_JtnzTEl5nR3N[Aw0䠦˶'91 :[(,0R:KW닪ڳEXZW[_H{_r> r̩f{JnD6xZ̰#߉O&kݘٵL" m&t'9b^lL;:dqͳB+!ay>7<mLW\ŹN9V)z Ildž$nv]&CC>FR`cF|쌞ۣ*.Vmn&g6GXԊF2}k ;zlO!*ViMJC}cui~yAf78{T4 g&\)ܟش-l% 3]ƷQttZIT\Ώ̆ 9**d:eٖ+Pҿr{\O\)x¸NB6=y8Z!uxзOR8>L=]7 D!z) Gzl[EFЍ Bmȓ%mqz 3@ˌFZlEq҄Z?M=@sY@(QN;эChkK< QFԋdh Gviw{jF$/P۪%"zPf~ !ph}條؃V6k5RKQ> @BY+%g'!tn7g[OﻶҤht| GSKlDhe X/s;c+Cql(i3b `Z`ǰxRk%{I(9 p;] I&L_FJzM s.Bp1z>w1~/`{}9dfq@b3mجȃ8x / T3}YH5xq@eDd$}thV)ի$àȶݓ-!,=̦$*ۑ GӐӬV؍.H# K8,S:mDa |!22R"Q}[AFj r!W1tkNØXY>C=wv\ HTGH)\m>jq;t^A2/S9Il1ѽEp|yw驢YApeEԸThx"̻%?ArbQ8kDxڐ|ic;ɠ4K+?Ʊ} W6 %TIw@{vZ?ǐ놣CiU^um"wN!|emMـm.Ҙ`5xWn{yNd,U-2GYҡ ԌL"!oveA1-!d4yj)9sm%!?Y\q4Z =LƻX='MZ:~<ϖ|F~FUQ?\0 X]܃"*l**ϜS00O:z&}wƤxͩfX[6N[nډHkfAW_y7fwbuf83ۃɴ@NV% .Ҕkr [%"PDk&;xu*eGeV#e$B ^sl?^%K'ymb Ŗo: 8KJqwɴ v={(N?LB!  *PXEN81"#[2 wn-6 Ù4js41{u^g#C^Hc/,/3Kgi> ifs[qq(Օf\,lBܗd%8qN^%QtsBˌ/HuG_+?;#+|A=WCSNbi~W:E+[钍H5]8\;lʍ J_ #5Jo%mb+TS+[n{1x$,F&k)YK<#(Hf<ߺZ)Xk)̑UI*y/?2]V$<~1"g-H@aK^|snت S&)83~J D!mlHՐQ5?ip~{)+hʚK9oX&O5k, ]BBDa{t}%Z-D[R Zqq o O-D@/0 |dT͐2#\1[mu ؘ{hË?v PHPn*m"94T}Rm賘6d{Xԍ'6kTZupO*ޭ\;IQ ጙwٿ"e_&XQ#[ǖR={q00k7KRT# o\h,n4j=Ϥ 8ǗvUMc4B LWsHAElR%G|Or\VtY-o$Ҩ  Z$!nC\á .p6x=rh"ܑ3ȆcZÁIŽuW_-v:9N-uިh[k[T1/q:R^bS`UÙeDbA4*.G[Gw?Ao>2t #=Yn_as3@=htD*`>:r3fDmטhèko^F.t[5|?)&hCths]T^;dk9E<`B̖eIyrP!LDlQ"SA c`$Lf"eDueIT CvG[?ݪZǯm?io-8݁"Z9|$}_<̍LUg8f5|? ^DO$?~nezEj߯=3y0֘a*CRAϱ?vv8*QUO]Eg fr9LF/f؁ow-RrXUab8֘cSfXm{@X >cϭ *fcʳjx3!,eXaUӨ.4z@^@wJ.mn GV0$zia~uz'btx ~"cH\hQ{]v_JV)f&s:pbKc7#')U_a,z? yIsOts^L vݙITiGvXXZ3-FW#nD ?FRxJ,)JgU2g~?f>k3(\tdx)LY!1BeW4lJ/+7oA/Ums{(zXA` Zv/IYT"aeP6"^~;BZ7"oztH9g~]:֮xgm; 5df'Lt|= Qb|E-Cɵq=쇲6%i5afД~c~wP5aO\(G|EMh/[[<(xX< jY<[0;TQB>yCKڊ&kif 5+y kzF%Gh22pF}؉9jpR1Ej)E2ԦA?bI\W0>n4أ{]WAL+V~Iq&j;Ϸ\}O,KľG9H0K-OV!Oo}3e5 P ZFy,$%n+jtDJG _=빌5Xjn!&̇ ]@33xͧ ,=< O֭jG2$ ƪ06E=]GPg-lM^ڴ*D -.P@/R^^xYH:lg+w%[אϾ#Խ<_n6[2\oo !d jW{MtH~ AjtVN ɕ5;9J O(^iem%vC9Lx”n|w#!|:6{L@,^׆ߊKbE5(A`10.i`#FhwM)W|4{$A6F@J,t'qŔN=Im#,?Ӈ]1@tʟV'. )cp@aC@ײOyr*f,[( 7p%&q^+lU /6܄W䖬'5eM~QyDAhػr?d7ܥ4<틺|&ut/%?7Q ΃:GY$qYS! LSQS{9|.0(nݏ&gG쿰ҵ1ڹcn-L B2Z0˒2 -A4a%P+A{ODoEp(ˋ;؍])BaHg @I,f,W܂y'ph+O·aaƝnldnj,TMӃƓUMuYqLs5]EIl0nd;K;NCAI _|ʺ: >)RfQV<=~ z]P3<1yM䢹0?±mF `SbUuG -TX%O;JOoo >0b.p5b{ k5zZfGlÈv1GU@)~׉gdgmb:5[/+BHGG2I;G/ nx%ooo$; \pWd7SP)VꕻW_tNBJz}l>>@> mewK#p7 _ߏ= nj$YlI\ns_Rrc؂E|I]ǂT~Ǯb jj_Y!@T /A=Jȗ4Mh`-bf-ldqZh? Bس ϮI(F"-> jɗ_b{{' ye3 3 s?Q~?+]Ɨcѡ@ S\ ̋SOeSkLϻbq;4q igEۓ.Eժ6ϏWNkWX~0*23=x NNtgG=yq@Kr>T ι&x{osMGouq<2.~Q|rh=$mJ (`|Nb/KkјtP6f a)CںDK2TDʚ%Ӭ;m?YlҎ0Η0<5߄GO3CY-O0.pIź++%yOoXxk3Jn@*eq4)8=1JjuyNn&+=ޮEŀHL+ GӇYA' gCxbT.Jb#adQ1?bf?6/fi5P @ajQ7DCH͖0_I@JB 6|(sDž9&J}OFnkyIQ#TϹY8d4B΂{ 'n>TfcRT궲q-gv Zb~4VיY}E}PvgXI}ۍοi R 7bo9dzᯀ1Sa'CF:1riCPr] DpUNEP?SKRfDfMrwzv-h!үuRwlɴ󡆝)yPnTvJmn9SbgڟR9œZcy6tPb`Y <>4v׿`~L>ZK(WRd 7@F/W5 3?r-sޟ$^&=QW"]N]b}5+Q$ U+Pݡ-Gxّ J[[ a =x4 ֌GV @cwZšԙ]"۹Caq? £|6p /QO9ŜWs1G 1İ?vҖ-1m_'jg,QO^Ҟxe4:!_k!ZMEm)XF25wb&*(o ]ǎx7mܞ^>EYNGHdlu5}m (_K,yCx̓-> vɴil_\g~A&ȹ1R(_ /$ Dr%RL[/҃E\D7#WD5 ~Aa UhZ-}& 5h G82zqKJ8fswċUobY4JQ[8m|@96\UaoՋQm)Bgtc(¶&Zs)\{,mN$kh}|I>o`D Kط<(&>K&Fu)nnjOTTBTѶ!M>Q˱(Gv2Z]%7.W"p)wQ"(yt,7*py/nkM[p!b\22;L%\R7=42uCȿn#=ElI8hNm\Ŋju KzצMJdhY_s7"5H kJ8#Ix(kCGkwiSz;lY#F%.bJ1v< ݛ`@R-18s&/!3J߿;sH#N_ G weNh%_' Phk o ITJ*ܥ#,"d+ FCw1xwS؞+NfoN~ (DXpT]u'sUx?W7cyd7ԃ8dCqY<*Df?sc5]T7f,nIhHydV/E9B/cz#pNG4xQWχ\V}>nق~ ybzkJ13 79v4aR e٨gl|1`P

9"VkHA$k0Jhf ie BHwڿ)ECZUT!(_^u*ǻX=/y P3R9 .+׀ 2{XSD:um\Q/,LUU:^i`40L\$,|3iG֕jH]"G: IbS!C|Hi~]_:z\|rC[L&g,cGAb-Jt0o$'|m<αUsl\`@q.YPj p\i,c=ATbVlPqw 74e ͰJ`q_BU-܏8PeI7{2CNqo?7"HU2'5Ǫ]~Ii[fe ii[]`9!QTIoIix e$˚3<-|1.oeUc3l-2>Vݠ@ě23ڣotlUy $%Wyi}FYL)ģ1_?8 Wzļ]I,*Aɏ)X#kKx~wZR4ԗ؍-Ѣ@i0 qBJmO9QH'SrHGy1Uip Ys45p뼁UEN?~4_?ee_zDRz>fVVWN% 6Vl f/! &t<(W\Ĭɣ:fPeaBTBtـ"1wgrv aE"HAs+QuQΘW^]jfeH]돔ugD4C"m j{i<-oH! ,aѧF13GS6Z:~H"|TUB[, :fF =.E=PcTm-2UJRq(s v7}[rl7(ne) 3x\ұPWB,Iwe ~}_ UQ"R1 |u0)g`&T? zS qSLhGvVĦ拏&a>Y~ :c7[j@”e4Y(\ƙjJ5Gz _♌}НOh/QqNǥvecVe=*Pz$bl5,rc5* Ep;22 c`4}vY %8.JdT-6;۲M#8qϸZxsn) #GfDP#DZbuY.?yَwYKaAǖ೶`Et\Uuh*bUF!aۇrOm)HLrK<=I{Fe  p#d܍8EpM}~쩦oP#.+E>xJ4~~MyVP0=E#3O.o%o cCX.f |˧b]U٥g &L`٩˵0WxKopHH^h  wF=a-\h7*HmȺf{ja#~`gb(-YYD5%BJAES?+BGQiB-R@y"Oݺ)oȲf>ETO[X__ 1qɤ6fH|[WTy:h1X1o {]R"Sq.I8أCļ 8Vz"eOMQDp+у?^ɩm~ɇ%!T6svIsBdt_7h ϼ&0p~ .F8$ಛi??'Nذn{oC5"싰?aN#btokHS12p񵞔Քio`e9_F0n6~DvʹYoU_A;5rDӯu%=ޛ&uX>#chbg5/>lkˆZ.||D_)GÀ*WG۱ (ʇ&r R JL}z_)m@o: j?(ŷ6J/H  O+69FwW(_4a *Q@@ Oji3m lB(}tuHzD.ѷ+VXy!l5dilp/AsQ¡AVx{I{jԕ6R isH^D(gxTPr&{OKRB,s y/6}=-tnz.-bGX֎ V nHHŴ?l[ƺ:H)#l!|'@V~ @S6"^݄- Tn.7G4 ys}_@76vD;v[؂!ޓ0 Th)͗:r.ߌ@sG;-(mKg*QR5)GٶJ<^ITbx5Sߒ'us* d +u}F6C:#y4qah8@s8"7P%v8Pκ7, snW JͶAxR }|A^ Y Di3;SI2Qhi A|b8@c<1[(S+8!8B.%3 <FT⯁CW M$0]ނZ͸G\_B hեtY\7C06\4`s&P4p  ~ffŕ-rS`u"+ۻi P|5TcŔws| 9C m!yE„&Mv\ȣ7 )+'IPfKerP{t$#ԥ /y )yS/*P(whJ=a!%6'O tm'Er6)먶4W27(~%t>A}ef\jiibJ 5D;Kypf=\]vs؏#/Xb7X* jX 5[NDndƣfC WFh?I<-4"72j?rRp.jx7)1g D^U^v2%͝֎\DmӇS$hkB j 1ʿrB^Z`4`D:d#slcE+7JtcFX 3t.+3/6pc:MMj8̀U! &s [t&rUA:4WEʓX762 c=}Þga9VB^ |#0ʑ/". fZ2FaH o3h[q-o#>Y^L?Nu#۫rP6,9.5rc kPPr.x X J*0+(!L`ܧe O0beZJ\ I餷f n$/_7% ;(30E'aS ?}$@xĭ1Rx®|ʧW(:;^%j:ҚTuHqѡb}N]BˍnVf7Tpɧ{\v`^jq'q 2R0YR$Ann9v ?I}v+.ű6 o#Șpt jv$%2׼˺\,ǢZoC\ln$A׈zF;sȈ5)kAyz|ELj|WV]h&;ӯgTy40n XY? j//xYq= <-9JI>Kzeʶ :/w!rƭ{]qK!E)8O<$PhFޝ/B%!-w% ̆L󔤅KEe"W4 LQ D;-=lzM¬`i7FȬ`|M R`}uv9[ƶ ~a1 <SB%2HzW^!dnH P?(ÀI AbXPvK&C3`? J#,a$H(`k*o8R/Hs?&%jhkxzG-#ؙ4iкXkFQ:SLa]̕.| m]{׍]ΰn Π%]ڄޕXOS D%~ "N~^G0l@3Q4|b+}#8}[Ȑd\=7AϹJP:bV xL6R""us?pɡ8~Dpa,[\ !#xxR| s daU}1\t J6 8 ^'O&h|-A;`ye*oR;~Q5([O\RojI&ξMjeԾoLᾧr*m=ЖIi˚w|wS=M SSLŌ8hƑIc\2 Pƽ_|H[Ց,FԸrдo>+Qg:nҊC%"QW+߳uWk bo7g[ vG7-OLhJVe bV4CkzZ0Um94gܧĊ{"Qjn5NPPr6PZm@WF Dt(x/ƻ2l]PfedZkM\0Xw"x)6ݺE &B}g C#8+hŵ*8.LooztW@d_ax@6/O.ӓ'.``\΁l`; tQ*-aAE:`ºn kY#ޕdoX1-8H=o\Y6 KT< 4!cs,{Z%$)H\)L*?%̰H__=s pHOƨ%u\iV(:vש8 <weD 0 WGc3EwJG2HHd"ɧC '_iWiAJ>JOAʩOl fz`\hX(݀4^Sػzٷbhf)?`S.%aE {9_=X~B?걥^K2G ?K9s/Юs+Cee  S圧y3tvK7Xࡧ:KhÅ P¬p%I:XQLd6b᦯<kMJV!PwWxD8Dl(i}B.PТmS-!6&p/MV9ɸfc_f16L%gG5?[\xyKi cwi+S[4bKFgtBu ]$IJ(_4mXc.~pƴr=U<聯uޥ-ZAc:!=rohOYEҿ'oaVn2TuI$G徉s#ګͩ2DR O#Y7lpiQ^.Ȏ(N90an};ˋ=Aƚ\,yL Ǒ>ecNCw|^zSt5|w[S Mzn%?'qLujn>_pqJ/\e8?ɳ|R}H-Prl3Z_nmᵎ~AAaM`r\|^>&kc>.ME@SHݙR @./3h&;RQ^FB$Nd 5Gץة&`Nag;t7+:`׵w}a.aE:~ "FHM!UgdyUT$HDHnPCҜCgfĖLEpǝ0T夬̔IN =:p/@ϕX%R+}#zjT>ox{:R@j!=>~kS<*vB=6XbIq~˕5BE>#„M#ZÒ#:b&l,6Kl*ÝSf ;]7S}*~p=9.F?5ލ-qgʙqjd(,xK[IVS2?}ϹI&}[(=+&YX0_~'΍K`:B~SA 2;zXX=wq76Jx4a&#2 ,Jid]H}IN'e0b̟%^Ζ/;;jP'J"ޢu6V~TG,'?O->ϼ BCː&N*#^t23k8*Ǎ|xb~ IxD42Q1DǷ!]cbg49 :1K)+}w- OXGDRJt؈&t<;U-{-͐`2Z9<#DU)CXQP"Y+:@/H5ifeQdj]jQے[ H$@a?1'w,B$Nx&LJF ,[G *7GϒuJBOwx%bة9u9 pLax#$;N<λnV>ŷ@ൺn.H(U(e:fw:όJ$APDڨR]jd5yy-gpzݾhLugk9RW?pgXY,>^ؖsl>43Y]ŃI!]L@}LF0g?]۽ϠÀh #kQdZwggIH<**6X~i')[B˓6-D>=TqȀԔ}f M ɲdzs@GS&orO1Jg#Bu0 S-Q 0q=j܁&t pSuʩHf+X6lK#목8Dj2n6T<@۩xrurppk1NC+4Rحh4oV!9rmىz͒<0v$N8@֡8 0C`yգ$u;!4+9' P}Hn̂_$b)ip+VcGxn:+`l*G(9"E.tOxL;s |#[.VvEVT@ }N|NP*A΄r^._zlt3?xxQNd%a[Ÿ {xsu!S{zd7LCF{Yt\j"d"amJQa1; [{b N.w Y*0Su}~Ԑ̡l1%D&U+&U.wTmr LEU&E(,!g8S@}+5sV`oQ~wﴺ=X.=mTDCyբX 3߀V8!wtb&ϕ7ȶ. taqw% % 8OsmE3!ؒ0%qWDfApT/.].+*} U |{w{k(¤10VE^l J- ժꐝ,{)r}=;USb d=„Bi>wUJ_Tu}1_K_S[rb!3SG5i뱦z^%Gp&Y:?8X%M*VW(JdkGB))v4n DN[W|Y_|W7,r#9&[رlsտrw7=tx0s:Kp+GTB.PϚY䆝,wm)]AN/ [NJ2Csb1^gѠui&ItJ`Ҕg`E(:lVoJ?JCdO2^-{s|9Hj沘$P5 PS wpe"k&Gژ2( [,$. 'fȾ3_v*8~1!6=hKJ]x)YU 3C*4cدbiX*v I2Ut%ЁSg>Ǵ¥uk0+ވ=w<7UY vەP(D3kh$m5kn4 `3d^vUC0(TN[%C-7F-j@m\om< kӽ`^/7u[Y)qeLWb!>Wu{ߨIDi, y-hn"eKI^%b_' \evSō$|RmH-ɻUKH3>Z?ooR`ߑ(y A'*>d w.^Ǻ1#<,E%DK| MLt4=_x w A@lu.d-;>"xB?% 8VrhMt8ZU;=aN Ǒpm_2(hJˠc4/7%ۥi%? YxNg@Nj _iJ !јF'Vx]ty3KxWQ-eDxnDž &|p,kMpJ(nrb ƌSCr@Q%~>ޘ1|ĝ .sRJYUҮpc-NTs^ÙepHnfPbz9wB9LAs$`I [0|gL =25c nv_88cWrxvOD1!Rhh3 |jW429ZݽbH|ޕ{''<{x3P|?܊n=:o,=eyxlQLHV aL WiOGY[5peɏj; %'+bk"K.7 H{n;n :.Zf&R wR`pj@Jb ,O_>^%JT5ofuB<1^]Z 7Vmuvt |=cSC(Wj Gmc(IJMSU9 HX>#E!KP?VMk|j3XC>{FΖ=p-څi 9QY'Sd ڍG}:))Y#tO5j4X!=@ zqf[ߍ+ _OD"XEgI+4H^Z,% ^Xܶʖnkj9V 2-l4 3:mY=mۂnxuWcN  j$;U/9FH`xDWԯئ8`ҋ eaArwd-8 :}sFeo7z#_AػЮ|;-;I?KyG^?q= ia]DTSzYYbӢėm[3BY?\_Z~[99=Sχcǐ!*]T$1~hNh ~cȺåܥPYn¡w`]#Ođz+\N) W~Y]9/X"41Rdf;$J CfQraa U%2a|A'w^X#V;MyԞ:냲/ D; {Bccb.Jg e6GɦbpߚRY볱mV"jԫƤ)ҭJ) 8ـFkjf`.ѩlğ^6#/ m 1f<s YgO vPH' -+QF~Ԡ]EH}"Em/&T"xJg#u5'-?;dMDWʟaa'6ج*Pe9yg:]hgoo'icaId+1V t-jW6̈o ̟ ]L]?}Ҋ[0ɕjƪ6,[ 34%᫃5z?r芟vrfaGO?DY&4+_O\(x0~_Ń>sA6I'6~LU%/Y.N\uvD][k2Jw7L~mK6 lceq~xيqd 2Ipb?oBa!"ZD,uGRDp^+)se-Fv([bvC{gc]D L@g*՛B\! yI)h,VZ{ce7 =[PQͯ{ڌ:bsӖ$ȏŬ"F|FñK>oʢ!*E9.cȟ&S`QK9c-  ONoP"q97Z~- jn,¢DemB@ -Qo|}~3hY Ɛ i%D_K~d$nȃ{I a"F/ xgl)(xA]m# wN v$HBzH';lSGa{P 4q'dj`e rDK {Jr*8Yf*A 7%W1ucrH]A_ '-49JΗS_b .PbaY{D;bqO*<\VuzoZA.)#/{P2UNIk޻>o8~.[b];svCȄBkݱzk$P7{R%;c}g_ ņeX N\s3џ'0hG8Sc/,;T;-z[ht4)?1˟RУ鯠/:5d|Z ߿N\Q՗=(LQ29"IL5f79~w)8xtyp5ZECH]g?gk#"OAwh Q V?d&*)gB_N7eV#V<+x}Y[8p;eLWvm:kk>5A߈y3+fD#fV Jp,Q:׆VX`PFq0$]Cl^RQPjY@W+" MzHMS^O1` _KaB?}mj3 8JYM@|l0w~WT@ s *ɔ#1_R<[mրȓ<#U)Mz%FUR>98zKB|2 mn~= :o6@:7eu׬NՅPn718s :g!;Q(ch Z؍豽 :wtK4Y<΁WUm_꧟A6ә]ﭓgXÍٳXƎ[awQeX#T Mxzā,W]X"v%ܹ՟@[U-;P;]h'21ޑ&U,QcGAd>Dkso|Na8nOJeUOg; bA'%mwA|L>*gV-K "1.Tb,ȁ|+ o!n8=i=Fp8ۮ*U:FGx 2~6  ,$E& *v7 P 4Tk\W`VqN"+zNXBI q-:VLYBeqfՒG=}is*B li>2qttRLt 7|wi<vͿR9!fa)mEA,ېB~mULdj@օMvbEYwe!q!ApЕAxZE0 TbE<1ݤKz* !D.\G|)C| JcGU}kyŮL]2j3(1wnk;7- u.? mo8OSgx5=M_'ꢼB>{]3);(C(t`33 mX9-'2q=ZRfR7/J)[+ڟӭ}I6z0=KBO ł ^2 N +J)tn+Z}Pt4 Xf1nysyb >Hao3!&Z;:UW'[RpN&gg2ZC?nK)4Bdi _O]1wrR _4i !Q˂.L߅wsY[O5 V]"=BllZ{B$b@7|{N)HRbkƝ7z5{o\2ɵ5or. ~\E_[(TTd7M؃E[V6 rxҵyNvk9װV%wX @ ;8ŝHJ;Er1d-m 08S|YKP[:Tq&q EHX)(Sr=09yegjVj]P~(l`gY-Jjdh>}ΡY EI~A,R չ]Rq?dYٖ-?-ElXa BnNT'aXlr>j2<~{ha2y1| 7 $'`*o,8Mp{ߕ5 |!{/gA{ʈ|DtE,$ (B3޵Y7tsT-2#?p<ŭ<g(yaUAnA-|z4y~f`F&e?:ht:+ I>GyIk=3hq9N,EThŴnBPF/i~|łIb3D8Ɵy-ILS_}8j%?q}kҩ7U6fGGpV-y "E{? YLNGEv"uJ ͩ:PʍBi-c6?> 7CƾXx9ykK j%<^IAp_7QONt6 &e8\ZpUOnvjjBC7-r< JGbY@[EuopXr0Fz gDx@[—"aY|KȽ9s;[i|z$/װQOaJZtvq 7=w[ݩ!ĒbCTJq>Yڂ#3c9EٞNW:XҤRz8HΞL6exћ s?t̳Q;!3R;.Y0exaduERA^f4aPHP)?sGYu3+xI]Z1_iO5vW0Px+y%Hhw4vVo\;+̦NK$tD#m#ҷhjLRjo8j s[bvǷ^g07U)^ ?ݒ֍'}?XbҗBN>T^Nݚ@"g ζc p1s#oϐRdTS9 s lYpG^x9Mg,Գnn̞ X(⥋GYHdsǫ*aXF/eD:87z&۳{b@e7OPV0sZv_@ː8Udң SŲe5@ţ܏u?Keڱ0hBtrL%oisۜrMl$Zl%Iq#v S ,+!|*rm/dwcڈ$Nߐ嫚v/ST֦e4>P(thɁ-֎ ^`.eq2H330Lb3qQR} ;zf$(aD7lהPqo1Z"&p 8tԋmH3hM=N_%-(s.o#i\*zAIȉrZ mlokG9~8ZAk4w, \:volf_::I} 9 06ePLSTp:g\QP垞ʄK3Ph;'ŭLVᰍNuȦN'uTԙO !N=oTѕ3/;tsC9}Ln_X*Tr0\F+ӨK^ ?(>-'<6 y]dRҲ\hDFZc?- @e;25PzF=cDh?GZ?19-$Ө:rPG52iF@؁tSL)/|X Ȑ޸z97yQC띧{4^+PI-ܗ:rDX#Zű1b:D:\LCV\ʻTE{&m֚t<1QCJ>gӒ:OKCs?SY%}}jC g;qA$n!ґ^LR  𔹏*ju:JN}~=7&u?Ms+WK5F[}޺J7xMHAO"G;HͯY)tEZCA =*nTd C.̜j҃(DY꥝)J,dy&=O/Jla0s:} 8 8 Xp@:x.Xd5"ߺԻڬ h>gb]ԕd=gbmRyw}Dָ|wua4~/Y?@e}j%[{7CB-6KMBŊP%ԑdz :BC +ò瞓 4fBi`OɌ;!Xe6қfOe$Ed`/QdЫQ0ef[H{xxWKG&@N)Ǻ 0ޔ3앱(B=Xrx"6u/g:-OG9a |pBx͒MTf`uOcbB%gRiQۓq[ٺ+CL4Guk6,=f׻>KnחK 9@d3_I1ܹQ>S I/J0qbyouTV},YKoջc<NλLhi"V:PvMa/$[V;i{)#q'{ nts@CHyL+1С؞DSKftq%PcS "'Vf*Z@}p.rHU,s VBdYF:0P*!K.z>%y0`a/' iW`.Hqrwk}ɠ7DKu4ڟx ҥ4] {8J>m=x?V|&NT$7V! Cn  /պk_;)m tCv#Ik>.}4*4M5x `t:QG pxUYBY~b1E9؜AXAFcYQ;wܴQIYͳ Vui}@ÉYֲ$VzI>TQə!:k,5ƹ,WAY=Ȋ`tbN.6Ƒ3YU &aI손;(> x:7bɿM,9:K {Q~UnFqp6D]<ī BZCCIPuMyRpSO6hnwe. [Lɽie9WؔDĤLC]|Tr>|H[^0ބf |h6[JUC'b&L0|UblwҝÒܵ#be|~'{bmijt^F<3HhZ徯Z~SZ5Sء5'_Fw=Pj'7?#>}o}W<^ Bsu,N4ҿRxI4iA2rrX=]d6HQF̭9NQd=$CNYq].(d(6n W$g;N5b" ytelROL72Q q[.B(_D"c F'P(Zn)2ӹEOz+)pq|X C#${ .nyoSjq [}[MkߨZdz9 vݟ>wܢS!-ŭ ׋n%f\ 7EGH G)9lM˞ }XBn5x!Vӛ7$"d AHj:ܬ!,gDA?_oXUQQB#YPx*Wc? VgJ]Zްp  reZ[3s39-Otc䲋"HGݠoa³1"u`jos;Ϙa=>:'QF3鈀v}fam=K"L778^p`m@YD{K8Y Es.W c4*%$7xډ?M̓'L=w.UC _f69=D?N`~5/R=- px鸞 7=E]##aUI 7Oυ)O؈U>J6MvKUS]`QZoQ1!mRμeWy2cShƜkDT芨x9fU5 2ƙJWQ>LGCIe@nL^C7 k{f!ѕ%^qm@VF(HnrV3hNF9vٵRzLΤ}ab* emZgJ4h8!{LHcѪ78]"n>UM^y^cP@a-*#ӸphQ!^,lx͆ܣYZȚzaxr}9}4_HKP Bna^#3~2q[saq/N^ A~CI Ys"" >τׇxQ' ϥgTI|U%kA|˴=-[DB3S&;Ħ$cH i̶wjJ}Rvd#x7 PdrxjS( L";8ߤ)l_RȆN1qGf ӑ:/k㆓gH*4\V'xEG@L?κB-!v+Г+=%7<x{V˱Y)TmJo S!JG^tO}lV Lz#/-*Y O#EZ`sBj<ɾ ?0GqdqwY?5%?z#Y'E"f& m2 r_ 3- ΠmHFv6!3`Slh yaCzw@\hB1ǛWDg onɊR&qa'5+fW<ힴ ^[-*<ʬ)KL}F `tA7{?k@yls){B*֧bN=avӧ5髆%wYyX$|9Z)B+R)r{8wp,* ѝj1Dh>`۬.~r)=^,"! )ӸURX_U-_^T(lʴxhOT-;O0Xxv6FMp4qӇ!T>g0l5X; !vhֻ?I+DtUp6Jo? kY+kBe):6M˜eZO2j/+U 4 \+~aK _GMT:ٗH$W@Mձ3V:EBv7qg߶Ϸ5I0,QB30W3iXu̍_RO>úǂl6hK_sB;e>Cц{_:G:8q+o 9sI)KPZxKPYߖ~}o_;;NA=_e9DKUdYiҶ8]^Ow.wt9m=u:8ϷH;żPZ^)E*{R+iL=ȳG֕S1purrN{ UlY6GG^l]*'mr kMM;vc+^-F&r&Kya9Ga>ʶO%IMn,#.⤉)c7(69U@ʞ {+FXgTkvi¼W S|A;9QvgFF|sSwtA6 d̄ gaSӛ.{6Xe(8ctRSd?-j;]dKh3ӫ\W7E=PLHhsU?~քI8^tM"YEo~;PTVn49}.P7KޓU!tȉ2эV\^@x=ΤǥYdެt4.Ny16t6>TӶFrDzF,\^'}2>W}kQUjSv\_>.Қ \&B_u#V۾N+Ǩ)$.'#QC#zhk\tz |?ahtB'c%ΡgV=$``j-W6ܭG=(iU㸳XFX$??D_ 8S.o-h+n2tEwN< KA6!pd8RkvG]*@K@\46o̬ 27VmhFu"z 8{Ve6[$o)#D "d*P8Cb-Qti ]%7S!WAsRn+ v\U:ŐHo  ;D0Н.?i1b-Bו8A/KC pSEIBAHGٟVtg!2]=b^Qy'Ao>BV4ǵispZ}y@S1v[U:Y{_D@FxW^Ff% YM9HtJY|sۗfkt\pg=&orцUPPыة\d.lOǡX9p#w~U-È0Fx7 2d(ݳu\eN[ (cXVs5Α]']eZ3wXHIYn6t sđ5H%>cDB̷g41Ibm6* .NNK%Bg&/ ΗOښĕT.lzdzs8l19}bm5AX%}F{#[I-#IrX{$S=jЊđ)ag.Opߺ7!0YDH_J=W vO!~)6 81.A4\~w kKãA?Do+=賂4J)>]拓Y`kgtR%X|2tXm.C c23 -Vn$P2ZٱK"QcNXؼj:X%|R'[aul X~uXRBl!;W]D? Sۅa$]=vBq9 NWj3ۂyht9%OP1)c)- wǨ(M~Io^`u`~|8N9a9(f]4Ĝ-h= k 16H[B {⾫k /OFO)HLVaȇixthMLfZ;jMDc44QA xg\ܑQ`*gΝ|Kg88QE@G.q9'ԪکQ[̚6`elHyA=rz7=$,P-N18lzlYxM;\0ɶ36„=r*6;bptE-XH.CB(OfqWiOxğ:1b2q$}X^ 9FBI0KlYX!QxtTg9CΖ O_\x#Dkly 4ؿk/: iSxMɴ0*m_Pfvgik9NLJyD= .f+׌b{id.V@P1:ZYD+y#x" *5Nԩ#+VQPG~ǧ\ηԗ}.M}4i#wDε>ȋc[|KMw6iZ>R:Vd?Ii_ދUdApݡVE).L/0Ы &P߆c,ˇ:Re_<I1Z2o|bkx@(o-hs% -kksxFR NK󌐋9ɺ2-ry Yj$"r :Ls٥cpT1 XqHb0zKG5Mzi2oe^ԶQ #lI=W.L..Nt1#ͱ&^8849MA]0"N2)^;)A_a  u1A3SBiҰHʗU]IJDY?"FlFV7Ko;_;G$"jzyQrHܛ-rd֬DIzuq.>C*_tJY ,Lʞ?Fn0؇F#BXVr8*nG7@eQ#,Kk|m]Kg@b"߳1vܣ2 YeD*-z/n}o*٣PdHnS6sjS `SI?Uŝx9%NQ۫^01jfA;3eHd_frivgöVؒ3kڤ6Z@qncya-5 }*^z40H0o6%02ZJδuJ.XNPd uڐ"v-/X.R_cdލQTܹA/d# A!Z^ޙ6IBRX7CM }DTɵi QP<=#3N0PJ9_} S23,ԎXBpM5d؂O5?5c0؀:N~ypB/W/gQ3kBڬ9/&7w>47F:5-V%moL oǭXM[$׌!D[m9_ A~#)lE&Jr*XL,YCL&z>h~,CZb^r>j.W+c[ x?3:_jOtòPׂn螵?? PՇ~T-;Ņ{CX GM\R_@+~Ɗu}Yx 8!2iꙻX~ Kh/H޾E4/Rx=k?8Ԋ+lew1KaRQ a?d#=R;OOY +lek#$[gש-ޒ-tbKjSwoKNh2 2 NV!Ǫ,9r0l6DP-br]3ui\Ntcy!88ZGZ{a>mf(;" ho:?ZAeycF9\X"|:dDFخ# ҂<8Q$rVApH+w| a uک=vX؍^_Br XG]0oO9:Rى{mR4SNhGb[XLɶF(ͳr%dSX;v#H੯5~DȪ`+[6D](q 3> !/̽TZsٹ%;y}L[ĺX R Xu?:;LeA:8&N^h`lkR } gMGTLDaRE4It2eXo-*^מyk Dd&SNH ?gXl6 ϼl튲vUWvSK{$6mJ{C;⥞oe;ksԓ9hH5ߝ`1ǯ2dKF\ae8F 1]M% +}`-c(cd+RzjzI ݗ"rHGtD+!84=VNβh`G|}٧FvޝO{"C`]퓺d 4ƋM4D if8 1P_W8M2.qM^#Oi|)̒ry/Ax `>&֡cje'?X @hJᰋ҂̼WDalPnaҀFu\hUbO uU9}N#3/#fόBܝފ8X$mޑUCXDK-|YX-`JS 9E]ri~ѢhECbt`"'l6R95YJ 3= ~1n,qj}>Ͻ0O&UҺ]ϣaaLHT0/:8whd?I\ N8!vG`DzOғ'+Fc=AɶO9o(Nht٦DmuO&q׾GVmeNM^V+B=8e#kơs܃6Z5b܏j85;`D3;K1{=%=v}" jg0Kܶ EnNVeR;؊@$]kn"idpjB琍L+NVi^}K=R`%F[&Փh_l Ʊw|쥅4}ݩ@H[d4z6\MF*. jDz!MY&p7Χ@UJ9k!Jb9/G'_'[=\kS\~: NQ5B8-dwc =]qU<zx)70#W &ՙ`B¥ +M\1}+$ߤnZ?K<+vۑ)N mIͮ| WHоos*Cn92f8y]'Xq]kn})a:.4Bȁ[9f4=+<0wC:"8eNe/6z#QsQ}@Ÿ++ C=DnY90A&e,i@h%< |k規miGRk=6ӪefЗ#sה_&Kr'ܚs ijꐸK aaJSR3w&p/Օ*9冋}AI~$8D_[_pH9mdY \B>QWH_z 7\gtfꄪwCR%HU$ً̐> CR6(nK+Uw_Kh[Oj>w Ux|e4F{)ou@]ڹ "#~y+FTs ic?Q^Lf}Q8eg97.!RGl{< fm eQJ 3?q]~1. S`Mw "ig[#AXa5d\zFUϙnq6J|ϭLx4 XI"C?F?.'d@֓0rsMJ6ePP,koY79HNS|}jor{zvph:>`>$zdz7 [2h:lyXcZ c6`"< MerRS㊆{ |d<-fVآoviW4pܴEɵ:1\.t1rQ6MUluQޔh_’jH6@o; P/t6RL5%wVy qy ZFqb@7b>;1\ygj@)Es<#1t]b;l5E҉ : ,c*m܈3fLë&x8TGkܸQfĪ\*qܺ?3KбO+ndΚ)t8)ĊcZ&E<!1zd%@=[2lY|"+Ȋ$ Sڴ`<PXr?o={!;y˗oH3:i{&Mw;il3l<ʧT?m9x#ywUD] 'o7M/hm}P"%T:* ˆ/!d%F 0(K9߉M`vd7! m_|^,F@E4^l%|"~]0( x,_}A~PfNS):@@[8{+*ו.-I`Lԍ(D}XB?6a4u:RDUA >kv*gYGH`N㠛vxq)Ƥ6$*뮮20ͶS|;l5A˟`M];A *h 5{#zeS9G9?܆T[ c~t'P@& NfM>x`u57vjmֈ)^n*U _oi^iLq.5ZUK~$LZ1HfաzJg'L;^̔F<)O-Qa"VϑJlb '[ÆC2m8 KL ?"MGͪG=t J鼡iPclzAb%ە=񱎻CU!ýo7mTXz@ yIV?$P% Vl^Ѧfc/p )xXf!%ϧoSFڋ_@è4:FIA<8BK:DVȒnJZk'өMQvj8?;pd )W%r SJ'ti<}yv@h;kYUJjCbn4? 7-0F%z JS>FٯߞO+B2ڶW'̣`((DyQsu 瑹`xdP%6ӫR.RJC 5J1%/MJ):c} Iam?,+obrɽQV.hx,-U8o]tXЁ-Ga ^:w3 p)($'AonS2Jwн.dTOMG HgsR,wDP$j:_wMGxhΐ˼v9o fX|JWOygj錙\%ˍ "gM|ge %WFqA[G7^"#QsS\+ȜX]F㐨?M|ԫMb޻BeF >T-yq?xkM]A Ra 71 !gߦDYE>ѓMda@EjmЌUt7Z*þdu!I72ڊUp}x$z`yGp~ ߪEwzF]͉kBw`Pp00%h: Ezhf:ᘙ p}b%3a+NSq괽dhgS4ދg煗nX QB~-XA16OOMkgM2eK nFHmyM]b)e ,4PYMv ZCv(x;PPB>*ZF^>U\a"Jj)Ho` #Ty߽N'UzɃ'73숏(COQw%%8XOưaX.PHCTOqbipj@ )'2K0(e8Z@X<\  j/BDoS1yh|Gfi(09i46RPf}?L`r_Cz'-9o[b{=J5$!6^f=]߽J>BEl'`0\i}JәPQ !}Et2qտ*t ΋rCdY?VY-ߖ8zK;C'B'c*|q%Vԓp)WVo%%{F3p y-2m{b ->aM(YG0YV2l'"Vkk[ \A,]-^oyi1on#cC9c @I$;~9fHZ2\u(LpC2G"Y8eB5R80!w"k9"9']sb-F5DYZK!.JJ=\6@: U(θ" "r95Pa s¯5;Lwc=lި] ~9ks) Ak98U j1_,TϦT\@zXbjW[:g7RƸA Zl]|;Sfq~܇WRc(3,w7n[hq"IlI#=j^$QݘQ7=0̼=5y171&gI/T  {}_(Y|*?YEduy-m#( ?{Te:}6.y"nuV\(>qU`+RBZ]SZ7u.І(%15sp0zLqC7;zG:5v9sI)Bh [_>n )ufboXPE͖rP5@_8R|Q\|\I%006¯jAL: ,*iQN]3_/eH>,-pGԡth<~]]WTHѬ%j#? 9htdS;/=$^ܸ{>3(F b (^w}|==*}O>]IfR^_}ίY( J4Æ hQLyX#skF/#?(r" ڷE3Õ Q~ޏ(Xqk3IUrKOF5+WK]j<Wrz6+D3}χ珎t9BAqil HofttiܭL)Y{x(s~('%|/1eX܅Y1=;x"ePw-<`I9Ro nX@8z|qr"KKlVb#kMI$ھᖦ&VJGhy[?=$փqsvzIʫ8HpD.f|,0g: 1@[J=Y^TSNF!mU!dlGĔUL4#C*ԶApO`mZ ݷŇ9 owfJ7p Ӊ^7pvSN"8}qVUf]Bg㨇̺)CZMu䛖po=IX0u⯥"/zq-#=e Vbu!ڃ|8}{ղM{"} ,rfһ>"pHzrH\N@E2@>W'o1v*=.*wЪSM(S@,$*I[{Yg ,}*hBBprz~%VmduhzK'0-]Nqd@3EMV[jje.CE bj.IQv:}2) :yq `Ȃ ǿCգ_9'ܴ׫ yOpXsOYB|*~q́AaY)<'Z*괻3s*ہjޙG6TCJzt"EŒ#`QoG]e6"\, a*LE3㪡 =LsqMp;9?„T"Xk,a␿ {Zt6j*ą!`#Z}Rr(ޣqu'15.*,,G]ҷӏ vn> T`t,Vg.3uYtqDCs;5DEl& V5."ayʱb>PA89X!t?xkL17 a"5ouZ2/L'^`aX` hK\od<I"v:Ok'"ͧ5R:}^)CXq6:3ήAi>h(O~7,6+]Թ~ $.U5>d؍P>t|Un ^tm{@\eB$:wejM.!Q`NN$wM3 [a_/VQ1sFQcp,׫._S1YE49`"tFk.1Vb׿ l2€=0f?w1$Y2pAoDu8Wqvj0?}}@5 E$ cm9ّS}rkԡ ew| aU,xj y% p._EW^S/i;4 n<>u=H&,L4Q~%n}GW rH#?̣fyf ;A4Ǎ x5t5ttll_y&+CaBtۍu*}=W4!XDv3/mpڡ:w8}gN)BEӹFŁpCn\.Akx3/o_2 HPm7u.*kjNEBUMbi+^״M!m?\gP'L׹}ybM{D8E]`զL81Ѱqvf3*6g[rZYN$Wo*_V Hr"s"2uy>q-SniuxL'D{S DK_m@G: Nj[e%cӰo{r.Sw$܅:@jW:juzT/Ǒ整gqɂCXUCPnNgN~}~ySQ{(2Zd}jG5]rlG60.b"qvVKM@ڸsZ6K+@JEH6s5薩\ozX>kQDlu8Wx~7CȈ s'%^]\1^)/47k(F¦Y+kևȞc䗆cm= l"Ƃ ؞ReZBdR UԍsD$psQ!~oX7#ĺF &)&OgDܙiq.[G)ܘs •ح?7 XPUV =xCXEz+6DRӬ+n9thOuwvNۃBC'LBh%|Px_xq>ƒT#R6"G)'DKTgp2r)*K.J|>y;U](~f^=KDSnUirCT`9U*P_X=5Frְ+c6,|U79Iҝ `Y4&M;s1x.k=pR?WE^AaNRIgn]@C&#b89 }Mv6lU' o5(lPyՔaw3z;X+9/uKT-QdKexso/4 *njwñ}aB d\۩ąUAIВURg:X4$ƹ4#Fwâw,wOEe"Bɬ9x:okyx Ns.)86]+a>b1S+eJKHBxݵ244 ;('a.}oJu2Sy~3ࣵZg9G-pKSIާ[ΝǺqGŝi p_FU{/Y` U(C .*.4㹝5=ߛ]t1R>jJx\OԟNbߤ ء]%0\KἊY97!BPz( u: 2Vb SdG%K fA>{my L$ٶ0b/*A?U)/ tq?Ĺo2 V<îÜsqS,^22=?qdJO^{ (;=6O  |+̉M TRs W?d{6)2}@fl-%Pw Smgi0`}jCbbEaɰr7SjǢ e&FƭJ+2 I]PmN|Tܐ&Z'JX/4IƼ:LDG/N+{JY8Ra(&a X+i[~vz k  i)ByhW sKX繋3TG7dr21`{zU_Z*0S5U )ir'ռ=XK6Y}d~˶ld $ȏJ2f g[1kcR*g7* t=242*[ޔhq :~(kWm-q4죖 IbԌP^"`I}PPhl(":ҖkZ<#rS5 wI!HFXtʯY4X϶]K-01qAR[z}N묫+vjEpj7&e聃+d# `L֘tKĥhʓO Xe ޽雈Y)~C*hjdc1(6K;=FmZWwkp~ ? ]8a$rW` }Ǹ` !"Ƶko7H'M:lu%cOf==>\er`$#<>Dd6SO:Q|7J[K%{4{H7( e}]|֕Q.Hk4M~O$8Ixk01Ӣu1<\vYy"B5=A.I%ۮ݉,4Of=)N@`ȃ+9jTZm #/ϑlYI5iaAyFO7S#Тjbn9oe/y55?jA°RjIEd{XoPZPZc!"Wyl1郠iU%kEKC'b~p<3N|G:EN_pW{ga@Ji$a˽W?@#콓)\4\/6LGI,#<$)nЎ*U߰m=f I+J Wx N[TN(rڱ]Q9m<MpS.g#Xx쪹⚎XԒҽaV^ͻNY[WQk  xe&7xq^ nYϭKFФ{s~SKtK!RU(n M/LddF͕p}hL=gf(ܽ{@ zi?r33GѾ퇃? (N9a8ed>Pŷ*lS~4ﳭ쿌` o^x0=IAD",̵#MKȆ6mjM)A!~ 2S:7W\xo\`h|š6kD@ Lwg &ja-Ƿiڏrg/lXo;@^:|(Á)Mcߤ K_enЊ1qҡ~h2,hSF 㖹T_Fz<&uWV3}3 ,R\vOxڲS՝oQZ #IT^%:7{E1KVW eA01 vХSiMs~{CN*ç pv fTԗZ# @?ǓU_ FqRCnM cʴʀlC f-1 Ŏ Laѥ"Y qɋDugX)$T)Ve K\b*.>B*OBͦ'׮HUeV/>U䙭OmLQCtDk_'ñm! k)aiՌCJ{xS]1ZvXgX,DyLJumԓ؝c۔L4oA'a9'vj#&h2䑛d }ؐjZϔ腔"۞͕-=xM 1X2&ټ_TΈV} hebMn?*.DA#~97ܸ= z\]oX.;+XkRjBubLXؐiK4;VV> G(U <8Ma c<+2BO+@J_ z, *Q``gQ:دX(ǝ?KWG$|̢KAYZVMP:K%+W3*ZUnwsz4/2 @DN`߭gN"JD 㕢?vPԵ ^-m G} >abVw =ძ>(4Biݥ"@]ubmx(R>-ڀZuHyP{/>q`G=1^"A 39Ǯعz,5r+R]/0w*W'V[z"%?m?xQ}tZKPY Wjȹ@mwE_j@+S0K)hcNcL4Í^ObXU~5hZԗ'h1_S' :fz+Lzؤt݈]KgM,sFX Mkw/yXV=|2_G\ZSL'f3{#NqM\)7dEroLY8`hk}WLڨqŪ%]Te3xOL4@(F0AH|̛]zFstVK~eY ʸ_Ȍ.W O|y5u͓!LUS tԸ]B *YsuެS["NrDV`cL뽐Rb%+XlLV(beOӷʤZYfhG3@/Jf[/Q_]iPs ʻ (/6 &"/[(,NF ^-zϥ4hd-y9n7,ܛjUASϟy~)moa LM2q-ںdbw#ٿhr(3Rk7`fZ 4޼jW'~q(T 3Ь8bfOf{9L#kpɉU&8 ,6wk %6xJX*Nz˳bw`~ѷO62w= 62gCx↰J9aɄZMA.6U=sɶKrq΢#y\p<-~n9S1R@ʊaFGuטJ}y0wsD= \>ٍj- ,0硥_ߒő & O F5[ RGw%iwYu/Їo{ ݿ@Ur xHrQk6Iev99yzNUw{2OtjpsFTviEeQuazިҼ L[ /WRR&RC&K(eSqF=)Pml|c_̂Sj3 en㰣/Ĥ^xdo.>吇\Xʁ<]&aneB]wc7X]#ҵnrڰO,,nVG9gBTMDND xzaU' v+e6XޕW6 HeZDۆY6 hZSPMH_Y<׎_eF% ї=B_u)vs7eq^^޻th7KGCu'(ǵɖ3%(J)ǰa>"(Oc#$F,%dV{IJUDB^b|=bEX3snܷXsS;bUlw`"w7XF*&3ƛ=g u&.{Ŧ}3?,H(a>S=d gMZ9, +(Uq :=@أ 8ڴ>v72Ty_'{^$ś wK7atS٦t&:Wo \2߼1ۜ E۔,|ǭGNлIqDeұVݳB_}$fRP8^CI\I0).} KČ,v1>$B:Uh҈kj \U%`e,vQ~tLxȻ2S'j?c2"ǭF$uQcCkkpr0Y!Hj#uG!P[t z7lyCϛAeK&q "6RZ<ԐC༖4Qw J>.KP-9wc._%wRvbbp>S[eCpNSnJ^igQ/>!d0T? ^ؑ_pϾ/AYI DL1 E Pit4'}&T{,Ăz׿Y#WL>lGjsȵ8Cav˅;]/QI8 U n1W 1)V `cuxѷU|^9NBԷ(h'Gy 0GO.6ƱAjlz\u 5|w%)q*6ޚԦ&Ě%}qQ#X 6(J`':H+ڗyHd3N槌_?cUطs"ԆwA:ݦ΢| ~sk3_߽Ți9J:p(WeWe `sa^SϔX@jk9[㕭 ]HREC:IZ QG5QfCy~'U`4+Ԝb"0J>6֦9\>!DJ*A/oFwu$<\QZW9TLNz`y$\ՠF9 ކ)N}m!؏o(lS**1/ׯ_VgT&H=,x&cN[oԄ-vEkq ϯTYna*6pcJN_5c(޴02[zn*-ēvgF~6ʔH:QXBA5Rk(rP`t!#Ni ➓a4DLUg3UǸQXUsοU,y9dHiq=SM 6T0 &(ȍ]h 4 ) *c-Hr#T+ͭpl> y4J`P$47"A g>XNIԨϿISِ )2?PSPD䡬nQz7ݫ{8djPpڅMU1I'ew5aMcwbga;LDfj _scCy:M-I+24ə๬^)oMYdkȊwU cRNvDbNl !Lۤ2XS6KsbNK,+ .T- ff!JeoTGA*5'e_\ۭ^6niaEޯ컂l_æSeZT|ߖĠ돏սJ֩2,_@򳙰{lu*mi^oŅw8e?ZsO|~i#<qtO{:c#uGʄ& B*hRBu溟4f0iJGZHϣrNNhd/j˽&N rcj߫A7fKu@Dl,Jb:i*2r^>ZZsiG@p^apA4;`oKH$׍K@?ѢG̔%~ׅ C̣)rMk})ŻJ'1hZmyGY՞wL @c9u Czӄe1.-kn*B3m"׏zm#U8Ȕ;7f\(SL=[@u=d!a]?3"?(Az-\|*u ncž-wfA,Wtq_O(\OYJB+5ʷ6<I{a%w9'>y%<<}sÞKĹK2`dyຠӬ/ޠ(#L%<|DYvl_nu,~ |TKfQq{Wjp kb/9WbŐhmys1Ѽ'̥"St9ņyca[_wgԼms+v$K:,{rk ͋jΒh(J82 Bu;r2hNjԔZ{l ڀUEJ݉|_?&(wA B;6ͤ n"{AcE[iC_G'Q껙MJLaoc Ask>h=.&ODN"GxLJrӷ<ŮuJ )U P{%60ɗseCA:#?^jS蘶c[M0R% Mq.]IkRӤe te)\!dZ-\"*acf/PKur(2wGwRjeD\?qBk~]e\PfuۯⱭa/s_~ }1/k#hd51X6K/H\$U3$jV@=PeE/ݜ<_7 7_Vkx1!L444 )5/OJ `Z2ji6W|Yкm<#9M[P5/6GՂMgӪW#_=h=H{`BoV4-@zJ{?e<2Mq-}5 lb3.z Z; 57۳:62 ay,f .54CѽJE; zdh r/(:*Q*WAB2pY䢒o˞6q;p}P-~ɷ%wj{2V"yw,xݩ>@q\)] +h VL/;J88rf߱Yd%&MR˭r.WlU}ŌTTSV?>`uO8*7QZoԒ&N#pxg/OrE$z0"Sq~t 7\#r7ٳjK @`8-?l}M$8<00Ԇ"=,9Ui$(ZD lLhhPOvo%mR߫  E6yJw *\YBpFqXN®97:` 46Z2:cdftQi߄C7oP}>n )*!u-3ZU\to) u]5h~Kxr]b٢+I,a{ :"= [|6uӲƠ}j/hܵ؂Y%#ػɂdɺjCJ~; /ȳ pjT{-lrԭ:ΦLWHwGwXvJrБ6:QA4AFNAkwV^e^4.0,i!i 5g/q)E?'Sxm̉C m(k% ՏZpTqE՜$ kz#9:ƌpvӯTJMYY`'7dz8z_ۀ7Tv2e Ln-Af3Idc M+'^V!umUp3`bg KJ*~&jh`QT0 lavŚcf9|ю>:R߷ّ?M,Bf w;钳eNϔU_Uܪ%eqwV ܢqXX57"%ޱ_wXΦ*Sp>?uXم =_M>:C'彆Q|u WpEk.!gW2.ˇLD`|d'/z7<QʲMpQpsvǐB!E8t-tm\1^^dĮV'[V:"y`ƅj+G(qz,fk:oi"~~6[Iȡm_ 2+~uWcuJ,+;1wElw\&/†: s7%[B,Gnٖ;_X߾,zu8[m O͂/M$3wR uG"aJg2 E:(OT ppj,K}~b C2B;PzQ5wQ^VŢ0YkP97Vj0z,W?8_݌p`!xR f/)Ժ@itV {P Q^@րXAiFVBο6\;~hLkbuGr$J~B{EB ΰ\8LFԍNQCe Wu㧶-% 50fRI+Y - FسsM4 foɐSF9|-U& .ڒflIvRb)\UsqFU.#nlITDQSXF|vv"3Z2b@Us<[EMX)fvA%I`Mju4|9GתDQQ- {9!!.g$c5.y8ixX{y;SE3מE @k-6SwcAAzfӻ*#j#bT D.H_iYٔ~:osvp Zh p{>޻[Qۥ05=xBjNċ77DKiәc+Č8d]X)1W2O^rIJU= ]DƟJwV5e0F$ XO¬/&9r-C@>g X(JqY-3f vDz& ?Yk0Tr:ҵ\F+7_X{н8v}XL,kH1O'qM3١#iYܶ3|ɚJ?/<1gA !KV |  STO~1Lxf3ry]x+Ǻ6 |څT N̽`_'?#<%ԑ5Z}gQ]3? pp+`%*ʊRSVt|А}H\Oz2~}`5hHyQUysWZ_rR3ͬ78@D w79R7,/+@(ۻ8nmaE>&"bܩh.y, 4qm>#$ w|=~)Ql6]d{:u7r+gDL,H-m{F`ι?ɟ/J  + ud)@7ƺ9%/V#wsGn`K^pTCtY!{[N^oWEik|*j=%ITð5.?xgH{$/+jIifc_)O|!YZv >%OEAQ*ܛN)nR\s#}l}1ï^zi=2eR@ibcy%ľ8Y)Ċ^rf)gk%3jH_52Iyl?&%L1=_fz }ȴ?ޑV׼=AʙelrQpYؤO"3<4o.?cDt1HI/[J:g7g *P38SI:>^r:uYs/6 ]5s ݺ'ѵ"u?Fcb(nKs'BybTH ^g0rRH5MY҂jﷹ _p7=Vv+ 3AkNfl|=\:hH@hA3F"C0\FNZo> MQxRJlXUǜ0:]I]͓jh0䮥A!#pf[ܝH|9\jv!y)n#ffEQ^ }XWO<'f;%պy\PP] *tqiY@Hʬ we iecEGgVOTk>;IN+a fH%!6 H,9ZmkZ^"Jbq &8& ]ܔل.i^< h?N>Fm.Z׫s ~x1_YJtOԂ>R.̍IX읫+'"|s9]ÇQB;\KX"7rp\=}"UsDS,>u8M,=ǿUЪ ()r=*ٞFC0T-]e`/ǟ,kN m*Qu [lcȦn&t(=giݹ-zG`OV3#C#&]xm7HpF8ı;^"4,eb#s'o3͢h,}GHH6豔fΖ$Gr}!ģP?Ja]tmJ:tS r4\^BbGdwfg{Uܧh嶚W@Px\;dail0d5$^7El{utx!])?P๱1N# ~39vl%vrΡtą@2KE'蚇BuOMi'Nn"P>K; ՞(z0#4>,k1}2*_ ;Uݗ(SD`[*lH\ú^ưl3䨧ܷZldlʂkEp&-4bw+FdbܜOjb>;v)|ڭ<| {>Ap` XV~MhZQ >kW> 8B 'ⶴ LP Ъ<+U!\\!Dyd뤘\HZH2(2w'=T:!j$Mi,q9CokL(&LJ2q`E\ͭM<R=#=nAOfgtYmT8.C)$0.;Vgն3E2n_M94ʈ@WQ½Ɍ?Xܔ1\PKWeBNf5ԅaӲ|KG|1oG_nĭ) 2jZ\<sywob@|}-Ct-sUOMV6!|QUAڔհ)AE!= IPR?:fG\3T1~CeAM.=ZMi4GyĂLwVYh*,xC3CMMdY:BL 4_<^s(>_g.!\OH9&~`9J&i"_ً!#@]KyB75lf0킽rFV'pV:ؔZ-!rCL!13/A*ד rQFbFX/,*t`bDk1 0)[fW@)%ژOf+igSqrn{_G, sXjHAD;ֲP yǟ9h7*[!FT42uSPz~ǿI ] B2'*j'wH*շȸf@"ak%Dr;ܗ8E'7D)*=nD{?qW5eaXHrWd2h67ԙA߂*AMCx {yBvFgo!IEf Hm-* GRZwaM[̣WG:]`͔n? Jl=N]Ƽ# b ;t{k򜁖VRj|/NSrd a:n}YciEҞ[ጱ>fez潑pBcr&3*Q@>ɎuYIIƣb`ƅ {+*QT@31RX"5NCgl([0G){lA@RCa9ź& m=9 r )7Q92Ha 7W1/z(ʄ_Óz~$Vo^&X4`X|B&8%e;IцK\[KY S@ܯh/=)i p&61inQ8&SNQ ,#gӦlGL@LPٷQMrVʤcɎO-ѩG/{?9|bO RPd)dEMq&DK#rnF0'S]6BRoƑaGb=۱'|( 8&Gf&Cy@j'x9HXEQ] ./"íN/BGMubz<*NXn!}f Vc<,8U(r#Jttނs@bD>G,Q"DĪGb "W߫yZ 2&tzSNBFCxh &)1X .U}4` o5p"sRgWrTKI$NVttZ:bs_6 X*ݖS8 #zvſ6\L{Kz5mEJ@1ǙloeŶ: "_M"LOۇjO\roAc-SCo.Q-t߄-D2IlՇuAT -`GFn~+}GzY$Jl#g,'H?j%S 4O}ʼ~ہtA[g0ޞ`/dbGSj i`:Eu,u?,]e)AM -ЏyoCpVct݀Vk#v%uƒ!\6~ Jʶ\9Z~WXUh}l"Q4*vߤȠiHL* >*ٞ 4jOMmL0+k_/*z_ Dˣc{r *z5t] ?GʕV_d2d ˒pxO$>{l)³ፈV^^ڥ[dzdFv+$5 B,>ILf,/}~ dOR0%ʤ< oʫ =/N:ˢ^y3_k5)LD=.d[P^C:B͙rw:ejw6U"3P vlcqQ?|9nBTFE7,&3F wGJ6ɛv(P "d5jR enKqGp- 8KOd!;),q:FVv5ۤs@ m[zeh5sT4Q3gdɌ~!۪p&ijiM22 Q9 ~#YN՜itMMz`eց^"(o0XUPYd;21(:r:ܼI\c UaNRX.2Vr6T gIQM bj5Cti;4*z4u@k챤8 f]O,9lÝp]=x;~LNiǤwhABt'!^=bm"XͼVL\r+0U ߷~^H,^I E+ ei-&ŏ-6\V1}Ѥ+H4.xA~D4^3TvL.{4Թ!`+_.a ƓZf`zHcp.P ̊cR˦xt~ Pˆ>V_ܶ:YM]uήw3~hEF:$b#m~wDisG)`Zzȿi0T*ݘɄ,/sSP{$Ynj%9BsDt_x9A6sbg@YG {6b DuzL?D>MLԐД/"/`h2`ML>/kYN%uªZ|{j5B\eLgU7dQr*2ȜJs§TyO6b\]1YHryhiqRE_H㝗(w}ݯ(d2u{a[n $Hu`v! -!~GC`\=DNj#ظѦf#hMr3OrfxmKw рd$ WA3ZAbq6=7jzdz%:h9ҧ6>)fY>Nd)E`Sդ8D'XZ꺉˜ js@}QЫ*^;Vpq5Kyt_jTgAYǐـϖ:编ڽΔT9϶]2+cÏlң  mK^E9Jc1V1ABd{"]5rAm=[aՄ:\HC!Qs5Q+ .GC2N=M!#esex8BDHl}#GI7 Jld'E;"sDM/TOBHtHw o'wq.Ș,cں,8)X}>[ltP{ +}?4HR~29N\"sfyڗ[R:.$ւ/|OV_(f_5 r]1XYD sdh̛C{O?+%9p ҒL&c[cb'AΉrݞ$i_=sMQAI!g&(V?oJ  ^3%T+AfRmk *5y\k妕7O4ƫ-1 9qJC谛rȽ?\331 -7fbfWFqKhᤌǸZȫo\S\iJf҄V=}e&k6+Ww5x]S0* 3Aby"dXKǎ5Q(n Xi%3D{ 9^/?=yJܓݻ8Fc^Vf F35>"ΙU{{*ܗ#<кN!rE~ ;îI |M۔L_x\|gsxhN~P sP216⋣k^j`kq1haz!Xt~xn S\(cmί&i8~I/|BJwfsảM->Qiy|6yEV u;%uI-/Wdѽxvj]Y,^Lpj=ܼM뚄gLrS#ՐA /2or!jq'գS8:u_]S^c9 mlhkA}w23pEHv Su*\z[ka徊sSzkѧ#F5'rn+Q?[7[l'P\s;EF1P~z8MO^{&#}"/خi'wM [+8/38pJeJQaE~_W/2+tlZ"Z`)'xRבaog\@TtoKa8;&Lױ: BeS3R1ṵ,e]A0g^ڭ%ᥝ /  Sצ-,h{apB4{3 j09d!9@0/`=@|b<|>nrRΕB\:@9JKռPmtVdr^lʨ3͓D2)f/V@}^iimUUtNHmޒd*kySaîXjn 8TKRa0^_~- j8G|N8ſ%Y$&H SIK4pg_GʽĞbѻtfXL5.^oϝlmC "Cn/sv,l⤾[_:V7I0ݲ(8Dݱ2"T? ƀ{LrҶ \`*. )(S< PD$OO8"^Qd0kQNNLҠE8 sޡ\ gԛ_WSm;\Q@ц]'Y Kx30P/+j4qŝ;Su2@lG?=)0x3.Z?7a0j󻡚"xtq~~J;$ln>ao+~~>"9oFc\Lhw>_#x'(Ye >Ӗ-t0 bU~2Y]*r8< $olpurɿDfe9Iu :sD#eCSvUnܶZd؉Pb~?G3Z4mz䧆-_CNd>4X^D' J\i5[T2 A9~'H;ٵ<պ1fQLVfiur\.΀gel;.B8XKFȈzh Aj& CHSI!v1Qދ,$y/a P64eM~QMڛzsG[_%}h *DjvW6'rRl^Ͽ)l 8(qٞո?r]# fKĢgGt{ v`]J jꨲ 3OJ~**/id\1!|ى-Awђ'0I?p RAn)Ei:X#FGi(#VZ^ PRA9fk|bęxop꟰(]b(pd,k~u/-xoTjtv)@=G5PͮGgުᓈSsIٚ|EG- i1%=QeȯEZ}KvPzD5JtQ+%SehJS5<Ƀ[RۘNժK*u܎-|Dl*+-7abֱm^̪? @ }DtpM/g8 SpKIyWcp_r Ȉߊ0~ͦíU'rtk"k•sC,eסx')"ν5ʵ֠~O sezb<"20|&TuW_τacyY5$\䫳GSp 8j=fHHܦ't֗$D .yJ\sbTM jس ޻vpgrV9\܊f*DOnB}GXNUm LaRRI_G7$ WoO Ц },vu\ȳɞQlK|PeJa\ļLG.nswd+@J۩Z7ihIBacSjզ*Y r E']“ށ`@p:(9aó̙# L6N)dy `/[ϘF\#h`ax*RM1|zҢA`U`Z{uEU߄2UY%\6)tpM"M3!EN1eph! o8)O1^e"ф^7Q<5jbuȨgQ IR'ԝ[+W8+ZN$8]Em}P|FHZZ]YyAdPYB !GDM KJ E`.B4,x7l 4v`\3n'n1!R[8MJ`*X'Is|IꭩP,ݶ쫗 ěrM>* Tw_dNZ6{Ў4<# ǞoT 'iZsnb;BSC\q2&Frq4)[}~<VK k^ YxQ5t *_?#Y9Wshgkvg)C.dq9$7!Ăy J-^^J]LGy/A{:ӧ) blrd17퓞1Ոm;|(҈5!W%-^sFxݧ!qÍ}(OgА-0ꅱDJ6bhRDPB 9 y⩌AYy-pHd}apXa}{̉9fYdJ\~# ϵ}tMܔs|%1%Qd,oL?9̡˒pd\"&‹ٖرD1 {H>$o|39Q29vϹJxk~~w}[k$րd>F8^:!Mg(,ۼ| ,NѨ!"ݨ6p3C/1D4zچD?Q',Q7I:BܟsJ*! )iiZ`;u#j]%f󱊯VS(迱%YCLQ@CR > J# il,Bgw=^KC!33R7ΔSjZSI*KgBp<*1Y,Yճi6"|ë xs:TC`e^T?o(a))bٕHle8<[fGݮ"O!\v4m=Vn1mD4R Yb|jK~oJ$Fd$`uH OmBqy<`cSxi #V~u0{ͫY_[OL6 F<%fS>or8^P"b54],܈Xwi &sN%v-;"[C'Vi@.w:.$į NKW̌DYة=brhذq^51s%FMy^{jXW`}lͩ?Ƚ}9=p=.҇!E޴I|Dg^ _3;0PbȐTV`6&Ӳjqyo?1T;^m|۵=h28/9';T25pdեb\]q?c3m_|o]1`QsR0cwl52>ʻ* Z9 ;)#gH o IbMhwYʄ بnp?yWOϟ'Hژ21J`>+ ) ww ' l ߍh8sG/1!\M*i^OO\]2vCUţx w ~57K&L$bhB@i4snIoi֝|cJ^h|U X][`el@ dw&QN 0n4>o ?_a9=hʔp;Op[# (#G R<8>TNhTKFmg}h Q+%an Y%^+kyB2=҆.Cp)zl%Ĩ\: cM@b1Q3/T#+3}eşqf%M zڞg[ K8L)%!.D $QK}r@㿧c#8uw bkB ->~/ʭ7o9 VW06PdKI+5l$q~0? >ƲgZ&/Mn lΏ?*SUsA(oP<D <*!ܮiQ+;؟1mPEΔxA:Uo85oӲ͙bK-ڱR5 ǭvH.jbi)5C1~k8oJܸ Yc0U|"Y#?|ic7SבA~k 6z^cÔH9tv+-{A،RjMqelLs^-! I=XzI=}id~j,٘&U}XԅgߟQ &^oNRFzPALKmAbsʢ*iG?a"JW-rgiK`RE7l8{DxK8{20qd\y>iHFZ;^ w(Ӗ2 T'UQ$1¨ %b\[sJSP@[1}kE-PGFQ7N~GqV# 6Pp0#o1v$ypA6Ҳ1~ 00/(鮯 Bh̡KuFP7 5  ao*u=uNW`~kr00 ?6â"fʟF#d $?|~tk܍)g,URK1JB~OBG&aR@i̔X푤%wq"sI7!y @Urb>3^R޶pb`0+jʺAFF󌠢, RDf;q2<W;jI{ I Tqq']A?*U&'I8k˚W#n  fN9D6^n&tLY#ï*r^U$b2I&eoѡ` Q1Χ,p ./T/tku8uB"g'emJ DHtu+VxgvXn8պ_ǔ0u_DE'}1CYv,V\y46)Y}I|:FD- y^OJf1t'v Tpp?Zwo1:z7?+F&}sCQ_LRaj5ܒ-1IB`[x]S}{"޵x3`22Nd~>pb<q\HɍYiu+K&u>IV<G0*ԦchhШ3v*[V>pLZRҖw7[ C6=Vz9: v1Q0ty *2Έ9 vV怨bTS)>K Xwa:vGkJ *SVPgzp?qV/@I$Zԁq*Y/_(eL4L탴 Sagl`Bⓠ:> {ClYaK% 3g04<\js˯lkBqi2Dܞџ5VrUk0L&3k e$گyZ (?@ե ,͒_wpXٌ3Iq$ d<⽜rSR⛜gWH8h!3 `$x^FbXZ t(͓sUl j\;x.hF/3I "x8[ TʛhfFh͝!S3`# 3&=#i )0>UXGB@s!Y k-b0@QƠXU.XԆoHw0_${-0n7_Q~@oiN,7ℛ8rOɠB-Pr# ?Ht2Hˏgo]qu_5iUb=vhi%81H\Z>Bד໢|OwU/$AQ%+?:Pׂ\ݠNޘ^'Њt/qKRHiw?CPŒ<# @fЬ:&NYuVbr3P!TIRROޣ9 ,&wg 4 *-]lѿWoլ5LL* D5lFv}`J^s_;S?ir 2?e~Ќ/g<\gg3ϧҵ)Z2lQ\_EnUD G[2t;DySS݈f18O|_R0:Dz;\7ʅ1hk^ ueLЄytB[=`JI|,2^O5:S%ΙCf Ť+`M\դ'KQEySMwAxX?ICNT@v9"?"*" Xm%6MLoCP'?AqF@A@[bm>i8ZK|˵i7roW5T\tչkՃcBi*XuL, ;sPI6{ C㢈 }{dz}Į/oinrva 7)]Si2at}{|)jrV?ؙ|-:>H<,ĉ6v3uItw5) x(XR1~*W5="n6'%m&}6c;0J CX1#Fg=@s.mrTta(= c<6_og3L@M}`ZzqqV^$m7$, Kߒ(>|vH:֨c6Rm%kLGH`A6~[tNxKƾUU}+!T4iGhxm⟷WƤ3]6޾1XƄ=~76(E+%sM6pߐrNL6/r/;EW}vd?8dv#U̚kfc47ӹ,tnx#Op.nx~e嬤=E +ٷc? uŚ0YpU@4^No.ݵhP+孋)FrxǕN@kCL& 0] R>$UF~dqL*/0JG d 0r*~h9Q1bBY[>3xB+[5ةou6^CUW]@aZ/Ѕp>\64`gP~n҇oNu./LĮ&ӏ OܝN-9!}"]$K~IHn9(bp3٧!1x>dYL@ 3RMbQD龷O/1qʔiX2{XW۩/:FGkkm,(:" 3m7{yvWrw)aʨS7l6J̇q]jog k^o;^"JAE'^>0whf̀_Je }9i!>zuûD@63RkKjIs)q-gz̺ &xlg(r Įlwg/yݼtd]aL%MY/daশx#=Bz͚15Ϸu RO>N =O^ +RF8pa~0_ j!x5owOE^Ї纄dqD1ُNvA! gfcWه%[:[*5գ]-tt" !]۝_A}Fڟ1/}6,83 (pD8XZ4EݝOL([Ҝ1B}̪)ucaE65e݁A[0ECJVD#7% aPXYӹ:Zfg,'8 '8 DQ-s_RB5:Shq =="Ƈx8IZ\DEoEbh>( ޳ 蹘[,NucP)J)x_皁?ccAySG\+ y/OBW$ěWgY_g!3sd /=wHX ǸEAQ]~j]0#[6ڜ\sOsFf4D**'Q%d~M-bӾ$v?P!7\F.yN6,rƠF,3utĩPF jzM^SpӅċDY9L.ju伟_z$;z7 UգG(.P@ 3Nn*jY_^Խ W^a#M'f V;IV=E#H X ]^Op mZXt#mm4p })ob 0i0 /'|:WDv7KUBIT>ɽrhq 7Zv}+bJ"]ڤERqѕ7L`H>yST `=xROp(F*wtle[]UHǂ1 eW!Y)38pL98$rshwPJhTԗPɘpxšC pi$ИR(.KRŖUYcY8ONc-ՠhc#7|[ylP4>LƼrTm=Af3?y ۝Ӫy3Ewu`]ܯJʪ"r}Sœ@Ԓ(32M"vG')/X{n6兵_J(Il J X^0~NH 6lù!V%."a$8Wm2* @#<$$/o}6auV CN)Kbtx$g[n4Nٹ^-uMw`rk7vŪU&{ڻMV xT<}\ß4ߥFh} d 0,闅ȟcI;o{][>6/X}3 ڢ.M-f'u=o ɲ/)I)#'}9׸`Ȉm?ŮtH=Fg=8JU&Wּ4#('xAzZenх5&-\SnzQWOUm% fIZbr-wm\:{vV5GX~[zlW$m>>,e}>&~&T#}^45Ta[7W_ut:5qv׺ŦĜNJp|Jkr۔!S̪17y/v6C^" Z% p Z_{eXty\qȳ4'GNyْCZÔ@؜I} 7[v{TGҏ}h‡YWXK3Nsu'}?),Gi!K\ӭGT7vSGd%_s7հ,f0kPBe?^ ޾ܕe֠s1-  6s,D|pRkk_-vɉ5*z)1zӹ tP<$U3/±-B ,ҚgJKM <6?44ejcc%W bQ3Ky⇣-'.fF^W"8;tz,u/\0Yi]%9*AfǼ"<AV)t!ngk'vyX`ǼKH`DuS"yr$ߗbea5wQ^%p㚄ṁo_z25/ux3Ѡ 47&b{I8O 1#FĮ3;-bvD2LscW?N6 KcRL4c^n^pU ٬ ,O酈@LR +``6YC[s(^L r|0'sp)<=$ }^*[ m7Bp-Ro KoAMGtIF)$/!/f TR@b䠢i0 L|zXG& 1GnmZ)`뿸X,H 13v>Q8drCbxT x+ 7inP% 4f'ϔ/8az(3]<;{=,I]=,/wncy TJ%Jf<~6s>R/gGN3[b_!dvA\@L;9ߕbumr#o%j4`-a+2{LJebSgpfzz#L6)\2=omI&h-{)ކl"+゜Թ?5U_0)@іIMh_0z%N!ǫ붸 w0g#ć۰ &]@wP;VрtR C)'cUuAgog=@UF\<`~PH 1d8"'JU&̉?wQp #HkuZBj7;Oso5=s=E0oS`߷l,Dآ6Ȱ8Ϥ(P 5%~*[#7".я/ )nUdq (yvKwiXS5'зsʒq$ˇcІS<Լ=;w@*Ƥ[:,81QE@xr<}>w!+(w)Op/=vMXB!|g5/q녟M"`.x4Sq脾:8xPẆR_b? i \oQѕzif#$oZV{" ؃sF??ZhZCy"LzljRr, q+D{~.ڣS֪Z[nfsl2LgV"(tQ,FY܃sr,SI~Oiƃ%POq7))-[Po6|zɬv^UEs`fw lTgm|O`Hr%,z4N @3?:K?תzi 9jk[G_ZmY`wW<39PҮʶK ǎA[GiE}7Br¦y.3 yʺ𨣇A"LLb&I/(S 0oMՀFmZAD^z+`G_J, ?ѭ_":7o~Xc'׬2|k {(,P"o%s!:!D2dz$G:UkєM"6@X&B I@0[T6JFګv ʥԾ%0ͮdB zkK-"mQ5-b7L6pFoqk-T,,!"k>.u36[zO*,*p~/]mutRE"dQXLb=S5Kr^rQʇNA4IErpuL};Z ۭRuKKmp6dǙU*,wM2!MĹqCn8 S}lY=2]L;MEdDþE]^oLݧ̄oڪ^sSltqURVj_y>$,ۙ ۅI2#s]P ɂNoq$Rz6zTw͙}B=)A'QpKP#JlL+Dt[}>sEgoX$g6TE}Au@l ^?\CxxT4r(Apa.xv6GϤ\mҥ B ?|i=Azy+ςM[fP9(9 E]I(gųDWɷֱ0Q[Yg?C8G*B. H/HY^BT\.p[RZrXtcU!3HǩHO ϭqfQKu4n6g#]<}# qn|6s9x X (3Y#k%Eߪ+Z xa9<9_ +U^F(.G7$۽7a[+Nħ7֘#O5^l{ =_Mw$8o둪Gߕ3]Q忳s5jg)9+ F[eaZZEuڮ#\ϧ}4UH[F<ita3_G Szfk.]s,:2ލ*XLvٯmA4Ѹ t#PcT~QCkæ?(hzM+륉qUӎ>_z ]xqJ:d7'o4MQ& -vB P2TL0fw:2hQySaZ d"t&]Nx׫tµ>/=IW@Rne]ɪO䠯LDa1>kKeb&0$K506v4A~tBxwA nSm`Ҥy6rq- l b3^r8JK*, Gh?zx5Vl a'GߜXg]Cp輣 E\;#T2nh2m #T' L/܍Ƞe. ݺ.n_ yׇt(5VI:&CJ5Jt_=rA,ViepZi:i^ wxA)wD<[r+`I.Ll-f`U z-98H9c+n~J,,+&UtRH}w88hkTSIp8+R <rpYcf? ;A[՟I0hy`JpCfe"q,-_-OJ̮#h|n σOCa;_Ygiɍ1:[cuO2Rù=NGd/-{Fsgag"\nܮKvǙ23L+)0ߛ!Z;G;nA(CaTm|vu+=:E"Nb-±s9fðCP syLB,噔, y#$>R74|}b,'K&W|"mف='쏵& VC >VWCfΧy^\pϏ1f )~ña! Bk>rxK4Z(b-]m4}/lv.QS+/kNvOzH_x;DBdȌ/H9)JnكZfc [<6GgW8hK$yJĕp6s)VOVz= lާ{6#? Iɱ@gk~TƲ{%N@z2 c=<,14O'%O<<䱩O,=qcaZ}+8rQlu 5LGK0  u) 243@R0{D皰Ex{ 7QgQ&Lƴ7TqXN-iEm#\@)7m[{Ki<ĩ']xA2,@tbn?f~kiLVkj%bJCG&l׷;PH"ޟP{4` `?>Ð$ڋDBٿ*{*|L&Gۆ>*~.:"=”џ*%J˰O 8{D0z d>XV2I B!E&6DI??Wh :]ә9{{ځ.AE~%{WwoD9We3Q:# 2*fJH7*u.N?RkfKjN~1~>"Fn %/S:$`Yׇs~ױ&tȇjQ'V5P|(Etʾlk+4\cB Xy*wZ^8s{)64rOC.Jl.@jQYnm~IWw dI WZKNeԑ?k:g҅ ajnT^OkwE}H", ;2 ˢ5?Ag[7P^"6rݽ]>v5!у;LO:Pߠ7LЂ7;̻%ZY 2؎@$7wqwd=&EOtZ jJ.b[uuB`9Ԍ6SU9o3u@ z7%1E.{4ȥp҅ޝL'Z٦K5.4 wiZa :>@@dUgg`4ːZS|/};{aLhfَY*6:\nLUt|5