sssd-ipa-1.14.0-43.el7_3.18$>t~5;j>=?d   ; "@FM    4 { $XLL 3L   ( 89:g =9GDH`I|XY\]^0bdefltuvw$x@y\RCsssd-ipa1.14.043.el7_3.18The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.YTEpc1bm.rdu2.centos.org 'CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKOjA큤AYTE_YTE_YTEoW~YTEMYTELYTEOb81dff727b2c5f2e041d79953f1631a428ba87ab85847b3bdc991af78e8f669694d30cbaba62288876ee7e92f0ba8b5e69aaebca8c190f9060a3670d91a193ba8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90371ce67dead6a25db630c6b71465c06b2ed9bdfad044db73aaabefec0bdd0cd740a17ad4e3be94abb12e67598d0e01f60f4419f9887368b81d29b7d0fb4f3b8d1rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.18.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.183.0.4-14.6.0-14.0-11.14.0-43.el7_3.181.14.0-43.el7_3.181.14.0-43.el7_3.185.2-1sssd1.10.0-8.beta24.11.3Y(YYtYXBXpXv@XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.18Jakub Hrozek - 1.14.0-43.17Jakub Hrozek - 1.14.0-43.16Jakub Hrozek - 1.14.0-43.15Jakub Hrozek - 1.14.0-43.14Jakub Hrozek - 1.14.0-43.13Jakub Hrozek - 1.14.0-43.12Jakub Hrozek - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1456013 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1450125 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1446085 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1445821 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1422183 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user.- Resolves: rhbz#1418943 - If a long-running task (e.g. enumeration) blocks the sssd_be process, sssd_be can deadlock - Also Require a new-enough version of selinux-policy so that setpgid() by sssd is allowed- Resolves: rhbz#1405584 - SSH: default_domain_suffix is not being used for users' authorized keys- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.181.14.0-43.el7_3.18libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=21eef38c65d50e5eb1c3f51f72c108a65d626955, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6S.]"k%w+p}|,p35muذe%tWXPĎdߚ %RWK']~?-L#tS1,a9#ęe=ӛ@;Mށש |K'=7hnJ.gb{-U+հ'-/Oc~:X *E, 6J)VTRP>^sfmhzp\?E""<M}(n8 f&Tm glplF>.DY(x89%pޤwwz4b]WW~G-76%1VcMʟct\ҧؠQXȩ$1;R0%j^i AsV\p6.f,D ; ,&'̿,׬d^;:>j8A6h\k0UX(m[r@K*>A(JoBi9sqnrfzpB."筓 j *}u A7‹p:݌V۷ =ޚ>j~\|)xyfAWp 0Bxڸ`Yf۪c9Ùl8=slmLL~ù,)Myˆ:_+Y)bp1V9x#OEfG52߶V)ڥJ^ahyl1X^o.dF |L+0 '(8#>@ލADۺ'NR Ybȣ-Di+ű*fe!#'x&Ĕ܅n/, sS/3

mw ;m< ܃,^sKbbsQ F -@Y:; @c3;R؎UQc͇ Km*7PY&YRQ< 7>vA"XӴa4j_gx9{AUnPۄqun\﫯l[cXO8̭HAt= W2gt^JI2͠za1g5=╚ VRIFDjVXX[M᧫ܱoJ ZP*>/ti[X%:ّE&AFML' iLRQāfX4X[`V W>J M~'a6|ErHǿ.F^RJ;q{-O%^ϸY(Fcq9iR_gne!b yF۶_"9~OOցVpJ8+U2EةZ_r̔SF@E%HR2(XK'+`~*@QCՃgx -uk*f 7W(+l:ݯ%\˱ь=k㹷ڷf\`xS)ot̠K}J,YL)t2KpsG)1vkI n XQBn{nzg8U%+c-ekٺBgp.$u8;y"+O>R5z50ˣ,cǞ*k.['mߧ.('iO{}CpMWϙUr*~Gs?keOU QB9GQΒ?\=03 a2ͱMu-E{"zvl^߃ "$9&ϰF;xRjQw[]ˎrX7gs~6Byd;@r.ʺEoFp!4,Gqjۋ8F<}dg,.;J2U,.:k.r7kg&ʖA-Bd$4YwT4"6Z]ۓ_C0Ƃ1Vzf-O! $DɊa5r2w$fc&i;wS3BJ ]z}*j*{-!} \;n)B7~FS6hFVw2)@.zs˒v:N`{)ť~Aa < (%&Y`R≮4jNc^0-\x A3K>JewDܩȠG6LV/I`c LJT+vy>p`G5[F;֛5JZ@(^ł{`1w?Uĝ::z €e=WLj$kz<3UTHI eIb_Ǟ|)#sv1v:֥qìC8).!y0-W.\n+^zMsDtz˨ߩ`r5%; qz9BeI2~^%szfqY҅HٕzWv_0xsSSG[9 HHc,3Ybra&٪]lLI_2 'mP>>lIQC"wT@Q9lX6Hp뺎~LWT^r$0$]]7laLG-`oD4Ŀ~GNl(!(#XCUQ**} RE"? ʡc6#O+7SZ)XyH `Spw ڊ^hZ{eP:O]ofaqsza@B3#!AxQ .cnmFSW6X\GиYܘTbGf=n%y/s;ݕI_%@M(4yٵ3Vju=۲Gݢ*[:b&2ؕj(\ԝ.|+Y$SבQGW'`5>"WEjdٺ ɹͭS}XoFl%#Vh >A:/߉DG"W1(+pNT"!Aܐ2}YhiG-1t֫ȶؖWER|$ؑB(5-F@7+ҽB1B%SD (y)5ӮY6sދ5=.f۔htz5Qr2Iv^iS4pt ?NbM)x "<@;%ɮxT߯͑"-j_שTM ļ]Egp4Vqñ]r^ɇQԮo6E{py;]cߡa;Hי!x|eգ+ǜψxdN3S aQ5j@ j͵}@(QߘO궐{F[ c# <}p8y301!6[)މ_؜}<ɛdY9bPDsqk<&cvN/qM3EdӁHIb`,Sl->eM>H:38B &w_!]#4xPxߏZYX,\Wsn>'XoEK|oHZpbmf Gq7&.χ(ӕK9'V, {|86vöjj/A;v%/?ml?KToH,ܒq HD3Ҭzfc , oI i Togl!'ɗJ޳bS>ܟD,s%<ᢉslJ?HhPȔ`bjG".Ƥ2 ԫ+Yrz(q1vwm;c(Tqw[A<-4fcN?1sp.9 vMP'˒72|GS7$db+cD8 eM,frz``tF\`D|w$*]G1X/_@1Q1d]wN|<ƸhR>0٫IpbqVٱW?R.ZpF%X >y*aP^F.?Vlx3F  tvu&á7g8eo(k ;'1Y;KyA{9[ԓÙ=l*s¼L9P.];D=Fcg:/!0Ԋ>2] <'}p9LD? g;CGvX##Dj,#@^O􂘭{>c!RXv0FS!T$Xz p *߳l 9Ao6jQ@1/P1dgYmpyOmE t0/ IR'0Wͅ> 5Z_`vv938*uMlYxPeK5Nߓ 9|+M*PuQӾBܢPޓݼXa;D?J4 X~ Ęy(,q[S|} aX!)U,ݥ.DI? !g^rSd>7CS (I^o;?,Yx#4w],d&"n`P$p; qƲDZ윉`=-Ed͵D!RIfLJRM]VTMrq3eaTx/~?}S2 ?3Y )O"SxhTW uvȕ!ZA9J~4N12ܯ2ﯝJŊa/ƳN9A:#b%oYZ|Mw5 ^0Ń #~Un:-zL]kÁJZ1W+bV؇G_@G{TV(y]O-}r#{%; Wg"X 4eO$ HK-=â[r93LSbh .A\(LBZ$?cesL1HkλVmArtdTPE-?#W[4o7:T( k:D_BT`Xُh[2e4zM:7{~ϖ),g1q`4݋jJG"G+VYE 3I[!`#6wf͋~s}۷ ǚOVY1e}m.uO|[~S2DiRqƼP*;-n8 ʉWUdmV&~|D`~*>tPsvO&l-`U$C1cɧ# .ɓ}~8qu 1Tii4JR xl2Dۓ珛wfpn^\%%$V:'K:gb0u:,$}=NP>dՍ JP]lgZ UW[|XdP0INfonoym -I$k扂A:Iv ^bxH<1%$|`-|sYݵz"r*Ox1S~Kᳲ+Po9aAinEK={EWza!kBRvcBD0aB|7ڗr3LnBvaxvRD$fwP垒c3dUmQ?=+DkQR) KK3;'-imt.Pj5#uH]yT4sPdƔ5*YCR;ORt4|ZW{4m:+Tv@EG5 w /$/TIPg /zi´Cl_VhxX?k;ON@I0ӧUn1PS> dw.hL:Wkj 9 ⲹ ځGpBN8.VT)Jpw/F#?^q(Dn9HR{7W=oY(jyxd 7V$594KjGZv8?[NI 3f2 .el3krxX@̠+.`ŗ66ռ_{\Ė׬'E#;yZ'.8*D7HE/HvEA o?S'hخ 2nIZ-w8/݉n|P@)_ԵE$;ݛ+w.ěm(n+,f k`zY H.jY%okF;o˜ǔk$tؼWx#q҉5*̂$XTqb&]EMݖe:.uGU< [$I[6bh,xuF(z[/`}S }QqHְ%fC=XÛB=dZx 0f%NPtN6j0=4W+ԋuz8juAssM3^Ttm3)">;IZ'OYVso_Kl?Lj('<}ݮ\lA ebÁNG)ϵ`%KN6Ums=:ݪ5kebp`Xm3/m|TJ4>: b#HA H0dlaV[@URѥĽ3)K6{1w~ʄKTVs8)Uht`v-YW6HsUfGF2ͽX7PP4 k!| ԙ֙D@<^-ejN䉇1lb!'R=tXէ-JGXNV_^۰jިfS$nVH1zd#bAe)aC9#vV;ͨ$`|#Qy` !Ǜiٿp[1CqgYrvhReU_{QyI0RDX8tM+Gse춷DxLpΊE%QENS q7G - E[ 9&~,{wK#k3HYԐ ?"SelBij{;J=47wsgRG ȭKm,66en$\&dZuG&f4ɞHK86x56wxʰwa7D,:8ɓNf>\-F؋t̯W:%Z/l\ fN@{򡥐*ciNa?R`\\,t>`b}MzZr3~'j{PD" 0Zpwg J?6N`CԨ-.BIZ{J2/R擢\\[o8ʕta2)O:us|iRSr勒Kݶ,~j kA 5%#J}aOGD }V(rٰLjb7 H-fJO]khgj}͊(J)v ht6z,`žC~D: kח;nWI5ն2pDH:EHNL,),w \-2vuv͢CBxkXr3c'ai<%6;نl]^Z?|;oqq{-p?.ɪOVB4oh[80E[q[ӽrֻ(IL6[Ti \Lo;z2>m~I yS[pgԾ!d(&NfPw|y ○ N ;"H=+hSCavY>,S",n'Xn圁>}2C;ާLk'F? |y?N:ݩSHIhx?<(r( b,Czj&W2K̪mRS Pqn%7`XL#e5nFXX)pXT Fej5>;G>nXc6ɘǚDl ^ 6^41x"N!0G2KvR"GHX'މf}#@ƫU@/h}?pAF]զA)@ӂ;#, wN g>ŀ͎x\D@ :gS魜{@N#*ETvkQ c9a GMܡ7r9qM$7?)H򈽄Q;n|QT_gl5**_Bi24?T=ʛpy_mc?%]ϻ9۸ٸ%Ek\A=K>b)?bw(u#Kj/;K yz0&Rx8>%;*Rλ6|,WS6ܷj8ZU<>nXέo?̓@*=SӤÖ l) E-6Z9ץň HOUEӋzy$O`!1j)X.٩28R`ocدR%_ZJv^*F0Ԗ0[✗L71*m6zJunrϋo#[li*,Q}?mFG`,xd;aG[jg\47~zu:bv) 7kr#EŸ$ACzcc>Omװ2eiq@ꧡhlAg+ -X^'PƖ"}e#ԇ]BD v\>㏐r]9,.H_T=~P&_4IEvߛ[9z9qx nbOR,wvKQU5PyhJ037Я9 "ql?H^fПJ|NzM Wa\Ĥ6]F" p'R `lul^(~.>9*i6>e[Vh'/&OH1 bQ]`X1_g x"#v߲*-KqfQg<+Rhz:NW/n fDMŞwQ˱CQ25iuĜuJGvj?RSј<#,t̗^!ycwͮ WJsD!h_kݲtdq1.> >h^):c+hvop!6yRv(qRXC`}~8 (l덞wGbңNO%!+}њ1ד5] Y,55i#JA5.'zE9z{U,wҬ`۟"ы.nxO+bT1ƻ@y19cVQkeBN'WZZnҵ2L>olCf }fPBh;ܧnoGh{([ ;֣ 7Vkp0ɀen˻BDXP#2#֤ V]ǎ1nwLcSh%Ufdę-E`(o%d̀RWA:a$Z ЏF=w s:e;^]m;U3VT*x9񗥑B*8mJi7\Œ #%Zku6OztvNgסpcDbi鶴%ʍEFkSgTCl~ͩo ^㵢CQm&igb9t]V0Z-ɦĉCSn7պigcC(zCjj͂Aރ$l~ŎltayD$BZNKWC[J=̚Ўh֊b\$"sF7s֒mY]o#kG]Ҳݣ1MYRm(2ˊZ]=Y 6]\o 0iJ#pm*PϭGKFufsS8ϯP.oWV!Ō e?9I Y[YNU=PrI7;fk/|yvD8WIG 4SPYGee7+_xKK5fF"˨, Ɖ9{I#Ww `'q7&+iB T%hPk$5=3ܕ<^ w̗PĽF:fW1eEckfs!?s'Fi4È!u^yޙlw gcsG|&$5 0e ʖ8C{%pb?EFZ]R'P a Q|҅n%o}φ"QQV]^p2S&="0s%V@5 ʰٗdj$ߚ*)=1$aRjKƩlqa%T 1|lbWS_=}9w\j}q vɨ#XY|eʖn6_) /"$6IڣH9Qܭqb:7lWa| %}r-: - O!vkp΢R 8Ne(|tě0*{LW] I|<&L5+t!{g4-< !Ǣ 5\凮˿s1 qa9`g5 =hV#8STw_%.53=ݝS[ɌrDXy\#ʌWFXd# AG]o;cg̓զcpnĭ!\aA"#z=c Lme Xz!6 gqUȌ|$XVmsAI0 =g 'Ve/ϼp>Mw սp{-*T-=-WkC 3.i(wN=׶8, Οi@0$w=-bW|j'妴^ ("lq682"Pb̋mWTS?@B^+3gn%&Τ"C#P1|fȫ5[j&8g>uv1|"C0@zU a\^f(0y Aar)y](yM ^p\ H.D"b@dpUl~Aa)^ ?xiq %!\,-ܔ ~qZ~!v[ʗFx{ rA3 Z9ɧHKNMϼ@t4tJlz Żo$ +R/(8.yZ/W? 9ܥLhNj/?å䉅C#[T*M-%|o_ yb9WWYZE\P@lG'\)fx ,΃TCh5* G欛1|UFՊ׶.v3;1sS T2`jf;A^CFLacv,jVnl ~&tx, oeN 6k>3O΃%*;R_gui*a 6|aW]s2bF/Hzb2r&iJ6$lU#heNw!evHÖ irwQ.Vw8Aؘ orBRFۄ~R {wRGu<$?pu{gUgj~$?PҔIV? {hǬP7Ʀ+_'?mԤ M-Q ig@ Oi#j'f̬ӯghL1{o(F{7۹#?_]߻m* jmLĘlXVQ2VNlPմX*E! eˆ>Zf%-ݼNQ~-g޾>)RPaMsP +/AP ,M)kB/{cԇ+s2}6 TV3hrEk򶝩8O{jviF]\{seRγf_']hʈvW+7(f-`(=k%?laV؎} l 4gYRghEr"eӃs g&+"ZqwHNC^l=0+ڜY=}}[\ &ɠ0Mv'!'[G$<`2,?q\dzbF{N/^9׍7/rS<ɬzt1Gu9d58eDՉ|p ]]|Mg!8h8O2Ƭ؄ԛ+D-OjȰ˖4Ufl0i6NH~HIP3ݦ{MS=Q8@yS 0fϕ\o*Ѹ)TArXKv\eZ_gs;)p1Kf?ݟP:7U(VѬy`~ M'e5. g)fUP41xzsЃM[n+R?-vQbm}[6=kZ`)s ZOΟm,t_J+]>:TPCQYvv(6Cin5UZgm0Pk9QͶyΗ`s0:OD~[szhAU&o4)durQn9fXV_ӝeTwYPn΁ɛWz7.[o7h9b\w]WaK|E:%6 Ci }-9|guv>T;T},ٞ~AϣRfnބ#b:_8dd*4>1|zBChCsc\\9`g01eڲW8VǢ0 [bY97zB,q{f4m ԕP^\T0}4CIQ|uGݖ1Vǡ0@*/bua&گUU*FPȽ 5{RMgPX;pI8Fbx8mW:ڬJQdh Ws*&~~~"P-sz=\/ 2fA9{pL$<3ъ#ի0sÃ:si|(HJʸmUj1cs_Op깞Xj%l`qwU2h*,qY\>/O(-Ѭ&:BtctǑktc,nlekyC)T-?_FannRg {|14L ljCڀm@S$տ qF97w3ك֖܀< IbvM;K^j~2*M4!G͎zkJ;5ԋBNlTiA晉 J5$/s?S1jyLr9 j^CQkH%d)[4ߎ% ?@^ײq;+̹0[p8f`j#kU`QaccÚ: yˉ}8w;  ,%?J7aʞB0Uϩd‡\"T|I;P&EK+ dOG[@Ki-<#rlP_=`On8Me&&SwM϶ :D`y7%`q)]|SJ-ȭ0i4vUHRܟW>Æ.OM҄3ݙ;' ILjEyl؃1IA!FBV_B'2]f$u0;9C\L:"PVѠ:r{UcA ;}*o ,Kyj RKqlrg9j.F\W?yh,\w@Cflg(qL䜐roqT;1Z7.Uj&4^ 1݀wͽ&fKK_'!&WDMG leĊA7Ρ034'2i^BתCCQUrij,oU2Z);fYr"U0d^f#]҆ПV0X4[NP)ځ9XTlk7bjρnN6$k ֯`X:Q|Zd[@ڿ5ńK^Cv -rCO+AG9(tJ2zZ8sMaҏ]rbdS ?:j@Um7zc_ٕl50IEA=mO~_˹#͟$}`Mb&SfI7DPV7~ XcW6U;!Ε]ˆ6R6u6/Cg:~\R=/ܨ Qn-RU;:ɊR "6eo6sֺtlSkh܈] W|i t퇃OFMc +iT}ߤ˜ 'JQl~dg8^osx+[n}R ansđ F>ү}A|0J~jܤ0ѵidѱluj! 8mӈjzdE-p\:s;|e"(qӞ0_l`||\e6n-Kb3a`GJO76C?hb+Ѻ"̸"o`2yŽި,41k^550!cÆRҙzE'Iw-"L3ˆ%,ٺ..=)Oզ.~8ש[W!BsfhV ICݾɕ$>khB?XMUw}BK]fnCzcI+ kGj' 4dJ.sӝέ`*zÇ-S)G1I_P|]Ws|@3 `WXk#.4 ?30u^GCS¢,沌r1?f 7BB(tRi(\qKp1KO ]6e)jb4 -F=@W? .|ByDj?m~YL)f?S_Q y$1F@LS? K呜#-a蛛TgsBBlȶ^*7frڋ!`wOX-.#q=^A^;rd|eMj[0u4գn_/K6R W {)G}s\y~b{ jQ]x>YjZc0[[M\V~xVR݃؇rWcjkz"?ssS&\ֆ5+by0/i.4ƽu\(68sVM׳wzԋ Vcɛ!%|X!05L-‹bNXF$3nƁAls&-ON'jKan!K[u:HBT=It ױfS9۶dva^"> N6t}ݒD_d.$JOvd sE{OٟM9L\}03τ~뾤ݲo8,a/cKo긐Ge*,#Kt"iC})F ٰn)_*"U2_MyJ̮9dӢCK+} եPyَz+^WsC\Z32iXW.h*ImVF?D? n~ Ci|״AeKL4(Q=^w3Z19v+P8w zD=d!|YT: ɖ RCO}6ybr(6{仚}k;24'otSlXf'e8;bk7YsÚ(:bXtE᧢;~"LjMatU\S[,t;b?(?P%.MjŲb'+Ӌt4hw7򓋅p:"Kețti@XBwMZ9{V"/],%(#2n2f5k1{cg^MeR.W8o<;WaE*"断WV6KP0yL~q\7'sr2h.rO^ZVCwT2]y,-Zt^lV/XHwqkkvjs؝:.Ćc5,mM~s|kGxBP.SU| n$ݜFӒ %ڮx~jƄP2DKڬbOC9[񟻦 SXܨػ:coH6Z&,W-&6 =xBzyF_U'sTqX%pf$"|ؤn&x&Q$bf7^SSӗdV"teˡƙcuKofO礆T.b i)bĮt3rLZ~(Sq9TAbׅZ8{yvk$'mJRI`$Dg3v(]q-qh/tߓs'{j_sKib#`j_6C'#p9^nIGh@S¿[|6'ס΋(7PAXv:듭*(0y`6Ofq9T=<޴ Ĺ==d4mApݙXkpQV6𦾗Pta=/ `*TNc9v[ u#Ul|kůFno]AvgSO>H R&$2ܧRse?m30Z>J^ڪUa}X ʮK#.GŻ0KWͭNˇ|ŦY/9I~|m9yhVx2V{% Ӡ"HE0MCw,Dme!{LhOWpԦ!69?O R)>S"aPSqZD2l9bfTmwcl< JDV]A,.ҦH"m.aRײIv3gg-Zm+cZ~(3v0En3Ocp|c:Ma_e6ɱ)o0b,xjܠ{i74H|Ib #Jx#3;f[hE we_}i(큁;`Ȕa9= |0>ofGy Tl9:-T1!B_F*83Y0VJ\} +%̿! 6u=IC"ri25>^{cHmAI ^_bqP|.+QWOW1`Jg:;R%b.; &r{r|sJ$={v,'?y)3W@[3ezBR?~<&'!nڤV;IYN:D-c|Ј TG|P*Su)%Wf@f勤d}HxՌz]a W̿ )Dt!Zu\5My !+0;)Uױd-f,湎/DYU}!~{RlKIfPccb,5r,m\zؾw#bR=!5ɴ.9җh6 xh/YBۈL*4i#(]"ìBMw>unQ9HA,_s#}@V>lvY$"!0+!q& ٔES{=A1.0FJ**MhrD/`Ys4?an([C'Ys&i-ۍ7]}|UT?}d`cOT,؈̌λg;OaJ9Fl#CܞA?s"E=ѐO5]?s:v䛁˼6~AsۙNʁ\I9DGf *b\#p)l*b͉!mHä|T%|R+};RAKVi}<'S`]:.j/g]5N6?cbBv/iWɴ :?>1GEo  E*Cb=QYψ4J)<>\`-Zz 'MATcktW4ihp H[oV 7Sͱ|`eLD*݄! hzJcH*\K7*林YGypK)a7(*v~TS:uCQKR`R7z"e(lzr3^AGf](jCUHkH!ͮ>#*W|@΁nX] :#K' Tb7EWʗ*Vۉ\2L*,ؠl\_t}Ib V- _+?L}-EJMMN -Oj S{j`p6;qVޢm`w~o%qy [d;r֯K& ]<"/*ʉhPruW!㵺|ya, Ƙ̣ ' \HgBΖ(>k3eC,Z~a|0qaF}giFxFKH/fE 쪈l6\k(/(b4ʇwɻeTxP~*Ǽxa`:EKۗ=uߵ7ėay-IGUQ!7 üo]+%M!۞8&Zj89uAvw4n/R+6q+ xeqkӡ8՟/}fkh bs #v$9,s`*g#zqyv`za}b%-n2+NF$. J |3Ne ]Pۺ39W T96Iz,URսQOb%>dnUpLEVAma?yN`]+N>m&y}DӁBi*U#Ɂj]~)#JU3d2yJP.mqLvDzѬ mB E0̈2 'h1N@=#R 5BBOiyZoM+PJx`o&9߁X2u]3j̥ƜHG,ESK()܁6Kw!|Ht\ԟ4+jfۿvC3_p_kA] 5]Pc3T:%q`IL53.&b$ji(=|a:%|y/>x`AWG4IǓ~v>]W"muׯL-%WvGp]_zӮk?W3ʹ}7:}l]6ŕ4;l#Dj7m̯K{`n" %tev;jcG۬q?rjSFRoM9DFO.'@R(~Ń! `ɛBꡘ.~Y]} &_%Z Jg|9EZFtR"sd털x(Zs-ԟsA'5jMyqZ*0{%jHȤ1 *KW%Ks zcr87lP$^H,'obDu5zXF҄c؟@4$p=0zDw tTULOUn5?za(Ɲ[鉵v}x#|$?q Y@LD^DseAO[MfiJ V*bG}DnTXC݅m+:jٵ3?%AqkW9co࿳9?և@4jmj\Gln gEӆG,=BQUk`K_,zC pZyuTϙ[VoGL_ʒO0L[q;=+o{b5I<0^m[FޖAk0L& Ʉ5sS۵ė#lN^V'IxV+`U%quƍdaD$6Œ-LGy0ɭt~l|ysa~>'Jz"ٲMTU̟+t'=6*uxޥg=ȪW`s}̨̏Dh ?Gr.#~aDq$>gh͏Hx񍔏!K})9vP@>ݯ<|f1LnS;+ 45$J%lAd~!w"fm܂U}#&/EmBn=x!$72 +tgl߼hs$Ag{+ T6~ 8.1RlfEW0b Z 쮌4N$N^CaiK:~M{ z4.o7LFP]mjhZE1N%$ݨMv֠T>W}Hzʖ FD4܈RWH!3’ 4I(Bfwa$>%$[n8pn~,La[j'Gx(Ř|3pgJI<|oo .0\ƪ5%wC>cKsƾ`86b"&Yd/{X8CdiVPL.r*qvktl @(nhjs"?b3I%B=sm;"LjI^<c r~ k\o$MڬZP~iwzܽ?蔡wEhz;-l\|֍_}a$~L m/*?ASW9[c\SLr k' {C[D^[i'ϫR2ԽAkSjp}d@kX_ֿ(8B[1eq)ACyS)noq/Ω2~0A~*3{<VTrZj=CD_ 9kҁ-'Ziv쯾BЧ^$]0 T9Pt+*jX&l% 2g=LFv4BqH)qEK&lFب+L].i)br1@YH_ }G lmvFnoFIW/ KhN"+))B>Z2^V ֦($ƪq?e9oVEJ2ls鞀U'_VwIqyF]QV 7jiŵ_FI1U$)C\G (hg7yB7|;"AH./QnjWvcNu{f6@[z`b`|Ċ1BRᠢNV ֍IQHn-/l|>}Lc8'Pn5o#mhm" %BM#UZbϾ`S{D C>(ַ>z.) ׁ*{ǍX6䨬U:$ƀLD'{9(?$#L#nj ;q@mdM[ɏaq!)C^l8W)Ndp]f<5C/SY+9ŵ*/ =w͵xt͕ɓT %w[(,xݝD;)[aF7rja~kGG''24!@|n GqxB!2V#͍X V]xA٤)ah[~O'6OG=%xE, ;)P 2LQC𪚉uM6R'6;Qڥi7ۿd&j'97 v>3/2 GbI3u=i/?mI Gmc42NP"9͑Lm@LzXT$@''ʽ1#35YUCaDa؀6 Ȋn"bӂw54f08Њdw `"l{K#As5PtaŊKre[ZӣBh'&"Fe)É,Dg[Ege^͍4CQI[j𻋕˂- trz_vRk[J([8iR+#6t%@,`FSKVtlPiQAOJ๭g#@} 7_H$O1lP>߷RuIo#` ^khV, Ra@ArP3( uߊձCɛbPihІȞPzz@_MI،(sW,~-8 86ZNDBYW6a3*IEdF6&ewd֍zP-( ;C9H+iO֯P N $ЄqV4r٠Ghp>`!VnC$H>k5<([VOͫ<CV$~ҌK=/.XBɱG~>3+.Z"X${}Y/GpG;: Uq ϊz`[ 5:K: >ߤ`sc &0迅*\2rl&kI |Hg8=4"Kߚ:&Y$3ʂcidӫF b|'(PM$fM`0g§qUk77\}*OB-_^OK3 K:g 1&iFZ'U^Y|T:X? *kwΉ5ǵ,n?2G=خtiݹ0],Mu:Szzk{ ceči0a0wB v,lUAݒvI&_'{n٨HH V`4D qI~) 0M8T/ ~Ҧ ')CbTҤ*G #^l)* 3dBٞU dlqX0Y[X{tMBr1V؞bk'HpH}!D·ٕC=[7VdSZ̹T^t<0戬h&uJ^n?n9p̵&dDM1]w/JsdZa^`T]`qetb'K&a7bBB4]J >QD~ogdf`fle{2- *υ>.KEpJڿkJ7q542"3Yx4Jpu$GH·խC&hG+pݡWuh{w/aCAҼ-W즪w5)P˸!ߊmdc;⮁ul'"ŋy M{0.=3uB0@OhbJ~j- Q?8E[6y4P2xƒb Ap7:#mt˱Vm>!O/[۫yE9'DBPCbڰ6鮔r A񗽅c ZDNfԏU/mqW+i8$kEZ2iN.VY{LoТ2\;Wvk,|֪Rub +H]N97]Ao4'ה2Š[ 0]ifvQ]Ql$Xd[qNq:RQ\[_jAnUrnOtY$_f^]+ l2DHl`$:iwZ~D1 Kc?8|ڇiѥ0z&>EG}sˊi yU y>}"A='Σq3ؖl؀\} L܍AnMD%$g[C+@3Vۨ>%>cҎbb@a: Ƒ98&J[ zݗAN oS0Hk> _ʶ1X;zX B3&ypgg..$k|~4|(#"d% K]zOӄ,`!7[4v"x3B8Lp 3z uݜ__[30 4I%z7 OO"h7*8zR'l337g" 75 Gܐ, 2ݝ4`s߯uŔ$-@.ռCI^ەv ڏDecThRD\TVeDR7cCOɿ2!cڃR|> /qh‹s1?aˡh9 ;,>F[-`^J+Xg՛(b :4jrXa,c?eX _ G*D+D7DatE(*!y) .q3+ 8vT FӕN:3W"qAf1A+oaeNn>.$L $ L,hSJ 58<y ֥|zlkhݛB'?, T3dTGkŜiW9}eQ -ը$*XKDB'T0?e+ [L l藽|T$~SUPQ0T~yʍs1;NUqN\}b,[Vt{4T21'WFՃ?,2Use`b kTG뙥J\˿&C7fY]B UL+Ge73~i7r N@{IXe^m PHv:(3o)  3UhR>.谯PL08ZDiϤG^NL.O6s-%.leA!.ƱN^?o)FKwoܿ^*ARj AťoM|Zǻfyُ%7!ۊ}f#WR+g\Ndr wk5B>sze: V%Vit{Uz?H0S0arnoeefYKS(MaV!j^Իd3 6jC C>b$k T;uq*;tTLA0zr|b1><:(u{xX^ۦy&zhl_R}JV j)9w7OTtM2{E =#CR'Ė!WMb|w qP7|<0m{UK:FӀ9n-ENB;қk{wQXuCd%ޱ>2.fl'x|1(9 XW KjMM` +@:GW&wj@Yv9oՑsQh'C8'(iUd5>ף㣒hu24읫=(0 M~$ k!nՂo#B̹Q&mܪw' G} 2'xH+^  BR;̘R/ N=\7OcMqߞ]oN31 )eQ,*p"χKNe{LkV%VH(2?U%e7 PFqױ̂R'%.1dc=vWKu )pmK0e'J@/cjGCЧhJ=O}d%}4_9u&}š>R0Hr0G2Sb1X9Hî/Wg-bՋdRDT_/GFǾ^NY-ھYGH@oxkάqx?>"rFsOxf*𨉪#"4"(.֯wʝȐ(P` *w:,Bü4Ia&Kk-k U_rК aB&av5~|ŗ .SxoAӞڳyZI /(F:\MƧF.QJ v"9^]MDp?GL#19{TȌȟ'FBDWL%;+j^{`?꼮;*qW^@S*܁u@A` ~icR4$$O$ődAV5rIҗj{9pՌP851StָEmrP+LTzkiZO'yx{1BL< ;F?5q>>vpNf]`U|Q G>BxxEܐzOc[qAwNW#6%܋2L:ATf-Hܖc  S˚g!_Rf:Bv¤a;s,Ej{,X4IK6%%+j&sĘ g|,H fnq&5M$^S}c@=(Ц*h̭`fE[SadT{0*-I#{+c?3<׌1;-xZ\o:X#nec} MvjulIe[F"Gj6Φ#csOqStlA].P'D$ѹko XC@ljLʣPYashA?'jEKz~Z uX-|s1px_Y.t0[ok, OXE8cHHQl$wdzD%:1F)j64>! mkζvR2jP@(G+.{gb&g9_z?bIߵ5"G ʡ Um+9LO]@ ]fj]'^ k 65\r&`Y֝5LvmCѹrAkq#3-7CٞL |&Xfr !A3tlODgZD}!P4v`W<7@,WF/tKwX@}!ue>㭩PsYK3uH:`ൈͤypd1ؓ43lG]lGMpѭifNcͫI*+|r$SƄO^KԂLk~;rLU&7*5wv 1I9k zKQ0b9sǧnΕNԭ] Xeצ7=u`piB\ڛZ84׌ p}g .&eh P @d n1hk!@@}Km劚R1yH[+sX><!JXR ngr>7 >Zۻ5hRӫ\:}\h?i?U :3~)EW}l*K?e>:*Q R(9Mͷɯ/l 4n G8:PݕH j sFJApz%ʔ\n2U3 fHj0t:쥒.%q#wy>1zʱ ĖLǺ#=Y)A͒Yd'ڹ ?e 塞!]*KYD% 9TB)r3_\VS_)ʔy8d`mW3gY7:Rj>͇-p :!|qOFj\xX!cz|7tP4rڿz"E}׊7R 'a 0 šΣ!x 9 Q8 v[eJbNmf;XRH 6}budp)'Q`jӋZlːPXl r3SʾjKa:*^m%JOR>pNM!]44dNZw\}Nc[Fui`$C;4ޛ& `=sbݯBN+(q}쯺bI|4kJ^e1-`w0hk8+%pTw#?gK2NMUч8JEaeӀ!#gCMnU$Tb~XLɝ>іx2~0.;i( /,-|'5jcT0*&\{1/^9dE,B:X7a"g+G6'cH#[Sw3@oR9=ΐא[M'h vQcuqp]%(l\ǹh1GFl-U{YS"[=q2lŮ?(]}دU7!f',*AFqyu3~Yπ5B0fo0`XuMG)_PxF,Zכ-$g[a pLm{:T1#0ѫx @d$EUu ߂aJ)r3 !b"T7b4I`%|co6c: [q k7TLi>y!ϫbGwQvѓ_b#JiHxFIXB3F Q&UQdبؼ^;K٦X8q(J5:nynw.yIJFsۦ Q$AS2ĉd:aFtp=3<  ϖC:tuVKsWHȡo7̮IUp(xW}t]q-1޳~[ͭpoA8*TQDzwp_.sпI-߱-[nj()Gd"=Σ],. z%x=m.% ?99_Ąȋa*+O|V gdX>֍Da5o"3D)%IQGUe I2o ;ӔMWi}InNcH8;WZF>OͅZl/K*:cm-/^m{qIxA=-`uSD`]˕F,ՕXŁTwߐ0;xA xt䠛+UCq34jte#uOm9Ӷ;Q4l`YIC9 uА1pZzLנ Hb7Oދ_+z9D4РJ1ok&/}fCh=-yJ0G{j\̨kXJv޿Bx7[T9s/$5dw QSW~%*L=D@uqTkv:ׁ^X˨ -9WN;2 qGQ!~bF$ŠvS=$!Z5cO\KűgI5jz#=~>iYyYE@m I&KMwFTJÜ2Dxznr^8tk3yl̝{Eb5ABގXHG`ml駞?SE1/_IQ0S#v~iو(6@,{﮶=.hiy>κ P u@§1kΔS7iT2k7/!@֮鰼_k 9v/9-H TRa'{<@ijB0'_#Y6W05`]pK4F!s)Jՠn-a+d3Q3S[RLe&Ch{#|@ H_&mR,v!VH0q&F~95e"ݶQy`vyWSW4+BK!5F\m\-ytb L8̕dFR1(Ǝ^ŕUyO~# ̐V;|~9Q0a2 Q**djdU KntW=X wWҜY |R;w>[^81 y䵌f}k(|/DaI!MF[5l2a5}u|{keT:f'NVM'83 Q67E7eJ; eWPuM-` ^:OJDq q_ȟ,Pj0uUXz X{a@Ĕ u.E 2|zuF_0 uZA7|nA/SЯd}:ԙ.RlHqM#*[kosolXFOݝ;\9W7q0o:; 1E4؈M,f a4/vLw%f0к ax>ߨV'8~kmgFȸʇ rr&IRk< *وa'k[% cOg>pb`ch1”&s؝xĩ\j{-gRv"88z_X,T,dz z\gFӆPء 1]"eRX`V -_*>=8g٤asgIM. hwÏ1GHkJ=qNT!0jX/ybqJ[aqc&  _klMrox'`C|sAVNu %Ȝge!!)ړЌJYN/C|%stSf/9&w4@i{oG rV.ʿ3X6 bCDtDדWCE toA|r(Y_N=npějǀї-qZlALWOdj?2>(}.?vPN+VYyXlϪXm6' 6y k͕:m% |ŚAevpÚ=6|Ю{5OȔ}鍼WLR#[-:>!`}!ik"PCT嬼gP 4'I͙|d1W-$ 侨8K)2 %/q/6c k8\=#ly]@lCnuƒ2Cx@xFjw\F/`k>iCnjÁDI"BocZkw`0diޗmw@iZcSd[I!>$wBFFVD?/ñtY-JDKmn@Wdۘ}}xp昿Dģ),i$O+Q`yr7OxG|wo ~ןЖkƸ> }DڗbV.0[ɝ~]Y<=e.?dbg;1^X\ɦ_S[ HLhj.;GނzӗE 6)pz"lYrc/N:5uuq <5L@KoV;I"@:-?xwhRsK6& BU[z`:8!KP8ON<*wnFi2h߈/2Grq 1Zh" ~kg(b.ShäB[SB uBº: 3q}@\r${\Ƭs c2|8Qԫ.+sZ1\Q= WkVh\lQ{|E|wmy*] -ICL* gF" %N[ϟB~"џ*=f tS`Be3ȿ;rv7mg۩}ktl?Ѝ2̷9zp9i]Bc6 v];X9TRޒUip=nO_..rꋤɷe[7-s2 p{; _g ^ϬzKd !^6=)&e+:JA0;wH-#QF5;T?Ae>HL(䅘T- w™#><_nϬV(]e PϡSA򛡤_`n v[eO;ZRRQFgVIt[lz?!_/6[ݯFئ|Q c@yN@j(_0ɤ $  :~|L䗨vfbpčS!F\)~98WC5]yw^<;\YmCylD,3;9;M<&vYo* =TF "pt8Ys E4o߆I{:*t:ӊݞ0v,oVȫ +Tczϱ{cց⠑$)vZ5" UC% Uz3_iV _r" uDN*SH<G318ݽcB !b3dJ[xK NWi\Yv U p}l45smB/AcV;$E,@ЀGfv*ZGg b>&`?RU yǷ<Ӂ`c}q(WSһAq̼aբ6Ɏ4e. n 0eZqZj VH͹qC#]6󯚙݃BsUБyZaJ6/~(hі)-:l}G?:hB+1LU==vV/yEij[h&B송n7«Ƈ*-|e˴4k.E"ҳbYB;?NV Y@+KBC-㘩Q ,9~W!llqOAD]kG#&*vYo o?$!u~(F-Hn?|$Oʷg@ê v #:q{\Rx=dP̳wZ8WQ9q~"7 :^ W;ZԔER`ЍG~ɢ@b(b%&q.ʍObb<:(e"2*Ew4h+9;Sџ=pw>IaD| "|T1Q]U !:J؃8D|K'\7=zU_L'0u \H&y Ȣ[pˋD/tjRRy3`7IDq'"z6OI _jhK*nySR$?Nށ%6I%a'А#jR&~b1hδУ BxASJ.2Sg׳\[T}Ht]&9]#\*, pfǷț.^+;SYgѸm= N.0 4nճr BpaM%+.EㄸN)OozyHd f!^'}&ƪQRHT[uk5AjkOp ݃vˍ̄}[qhs⽅WN4`]\j@<`jKi}++± 2?>Yϗ*zXwCnh(Np҄lu"`m#ud!2S1(UD(daא9Iȥv[Y99,P-:ϸVN~cY}dXSRXwsX^''6W0}Yh.I#ЌRXAc'}}x/X"Q;9R PD^9? ^%# 'ST b&bMLju3~$(紑XN9Ԕ*aGy_S#g\xpA_Մo=y[yeMdQzH=$khuSȌ wdcBF6p8Be@ Mن34Yx zHZS96A}Г03?,uQ6y8oEp[oV0hv}1i4ӎ&9?oْό`Tsupa0CIN/F~GҚ']0CfΦv(XB*~g8[ y▶pnjs 'Re<#*m_kyzV\ig~,Q;ZiTfʣ4xSJ#R*g.b]I$*;gQqc)>JqzdČ#]3̮>A?kC_,1U?:£Og(A\pHW2QR"uMfpd&v&]HOpkFؽTjgdDDNDC}|3^ofòKZ񒛿.kTtQ6soc{+ء0ë}e@$ kh[Q=i%%U)fkp k :(f2]8](JRܚnMφM. .QRѳ+dV~Nͦ:5v -ymI"߿ ']Tf#w=EG|pd Pu{/{O7މ2P~ 2V9N]k>.ga*kU i!fyzIvp mne ~z&LG#>bNg4̀M`s7vj l=ui'uma,1*oM(/PfDxHF6LEȍ_\{႓LޒU]6/BoRZf*_|wdֈ``n^?fin\K 0t|AE2@FuOA)'W^B*ɚTxdӧb}O@W3VP`(w*="_ʀa3@rdmGhe{2js3AQ3wB=cAk9,iZ/ª{t lxҬX=0ZwykE,G1qjYGIf. b@XcO3U}7أ1Xf wp"W W}PHU8 ?׈@9D4e(t-ee2?.}bq.^~7@H^egSмa̡q9ՊX%9/Bڊ"R9ik0&=땛m%^)}tgϚNt\f{f r ݜLŨ8;tHEҨړ h@H)#+29ۺmQ#JֈNNf_|ATM4$-aߖG:Vl9jM *g.am,9Z?$%tHvWgޞ*D+G:&|5)!f~4 #%>8BgNI"}yTeEE$ ]-,k[^p%|Ŧ~jRfa$@6;pҘ?ll7LZh(,:<17*A_\zUW\`'ڛ^5ΖQVyC%aHgqdʾ=JZ+8~*ܾ~ݩk*rEJ o#&:eRQԕjUBeg<3=&o?=wVrQ&֞j\6"#s.Uy``O.saC]j˕q"b;|LPWXOgun,|=8 [o$!`b ! 7pa9ϫq>՚0-x(ܼ#gG=7)/p-) ˊ3(fOT}!7oSվvqJBbXi,K"ޣ!h\ Yn%6oiX]#QXͣK/C+~' %E8C50ZOAi&%h}FZc T# !aP dA((R-}9L:#j? >05dC}$1u\`~Nؼu'wi]ċзG],mɠIPq}WmQmVhZ)@}S": \o ZTbτJQTCQkGfBLk'BcTc,f }}g@Y2e]Oyѽ Be +IIdF}Zp t:¶A$a҅lL}Q ,|$,Yh%G;c v̈xPMu\]ξD6~A+O lV]=PB#[/`8,(< mgBLC2̦0]ͪ,fGUjRulǧi1;Y4BFVםx3̀n bɓ x@ C.U"#He*2|a9eBc%5,Vt2럤Ti'Gr}fPg]3BY-m"#CH (h m@$4[L)K맠~.uiYUh7z;ZVSPEn:\Z]Q]yNBLF%U)c ALMݓalWg Q(7vLcT͡[P¸1]TT"Sg{1^ՆϋȤqk*>k1/74L~1=Tmpg9@uo!m dpNֱ!f'i(Jh=e0nzAһ/5Xx,}.auC'C8r7x gmpFa(gQ%lwi: Τ4"%r1g5 GGsnJV'rgIźRi*Q!EMM_?`W>bkb,ͽ_i!%#'o#G[^Vԝjҧb~ 7Ox!/DNBz?$WsIdqA:6]< 9/l ǚ:4 A nԘXk4)+=56Qp'|A ȼ ĐS?#UR(B~$(/׀nb)#◇N|gV2Т7jc_DH9Ī;|xhs,` z J(i S陃eq;Uijt5̦J%n&ܝ] ^f+Π`K _lxGy pT-`4tUtz4 5JF_X;hJ F^VayY2"_ 7♽-c#C LdFy 5/z8ChƎΨiN9bY*xɽ K)]]KenʚN9u7,L6L|`- !:A:?nbnj#*݃ITePsDAl*Dz/paծжsSqsrY2u(%-{ ~F*Ql#>Mŋ3sSZ=^B8QS4:k#HK3ĩY?(w8H[rO-#0hVЌ7Qm"B}$hIVYNJW*_F֚}@Я8G82*˖<5"%$N:{bY"&as,0yVOGlF{l. VN`vrYUdzG/ $[ոw^^II"`^e(wtvBV#P-QPqDx2"Iʞvks1N@s}Ekl"jC=hioGl3 |Ԗ SăPhvRFSS7-sjn2K\xκ/vzO$d{pI0ŵETp@@&^/IK <{_>~HKR=Y/ʱrf8;we,k^-HSl.Ʋ W\}-|&iPf{<d9}A?# Rj3fՎ[x%YDJMdrT10g ౩X˂͘ui9*V ZhNxצ4 kŚj'CUiZ%!"0ag^&ȽHsO'=l=+9w hS΃ tsвI"ĈAdET>Ek=ΚD'?tw3<$_mvGk`ȓl.efNLʆQbwN'.3F %!(L`8n. e`6g7 Rr'iPd'۴2ӉH -@L-ZU7L[7P ar.d"^k ~/Py#yDC;nANbNf&x(1aD n%!)E:b/jDW %zhB7\&0e;,$&^p{/** _L(D2(e^fmh돢//9ػ:sMe* >Y)xAsPn3u;g_y0o$s5r3HjO{]Y5Is(H9^ij԰$:յY!sY5 ; ~^^Dh7S'TRxܶGnшbm}P΂깮g3ül(:&'<}6#ʽr[RZ|+Q h eϫfyw+'?!b<-<[۪ $Yh`\Q3XO'z1cqp2*ě9eTgN o؆y06Ԍ)OKUɗAe0DntDSY[rw5IgP-O l~7u U Qd8>St_ͪTZ($mzC;FhZ6BS/ tͶaidoJ@s"K)4EO NOwW=ぢf:1!/. ="ynv+^ (eɎN[0|lv@Utbe}Ֆ>p%yW'ğ tci}E @z)WQ]LVylA1:74{XMPh X4RP$u1 QӚk\^GAaUK!{HA @P)m~ zZ60*5Eyu#1f h14/:O6jnHn,lt}7= qO:_/0%joT7uJ0<[\): Ы ^82p}pl4|u#>gQb$;*Q$ N $K?)FBdIws@GȆސ[9Q8+9P%vݏR?^3ޅ/0=&z+ͽԧbF?qp+qDGzE#@m܉ !y0vm4/mԔH!ƥ̈́ީ Vn1 &ˤk|o//0>QXctE#d+|1fz*M;= P %+>kaRgM>).6QO f_mI>դH +Kgp1+tsfԕ' %|y~ I1 KY40 P6W2LkI%s~Jtp͔uRԻz€MStDuis$.K\h14,o{iiU礫sUwPT aӢSWUgjh߲Yۇ'vm;EB KT*N₼qJ$ήvihN&Psr.L P#ٖ)WS)X۷UC|S9S)Nqf~>ߎ<97LVj?6  :9Nc+B^n7ěm,qOxo8y=xVŠ|oy\ZzA4 }MkCZ ժ/ܞ*phq8X ~Wh˓CE dՠAX>=v)nva>B8UOQn~^9elZA!ق/"ZϿ˕"9;\-B?2D#j|}?ڢ_s@A;g>iY;p`ꎚycNO4+L!!k vMpK}R B2k srȦJ4D 8Wbr41p>LC:>mufj7vgeNLĄkKLȋsqGT6va;_t{Ғ $012\J\!aKG)&sפLfF y$Y`D(z H9[uQ?.vBaI`d~(445jgiMBnA-~V$QA^Z%>RI=up. E$ 9*n;{,0Bi!0oX@6W:3\I5MSXf`/P6J&Rd8ϱqITqnl?iD.#.)NzdJA2`wk)&YhoBUkp{4:GPCf‰F"ri.Y6,/$Cx{ԚP~gX}S!(`;lmêVHM5rvr8 >> O63.c4HH>f b+sP}-P-JM{~EvídOcpNKqSeǽ,ܩ>%}@+x-B@f?owTU%*m5&GHV,n%NbĎmX]TM=[xȞ]ޏ߇ZӵQ[&k W3C VOk6RڛdqcsO59?@@FUT@ DVu Ωt͕ي"꽲EN.F[tԯJ:#!_Npg8C&\ƞoOTĭ78ҋsBqqDGMqDP/֡|C^e:ƐBXk4r]Bֳ]#$܄N\|*ҥ LnKM3Qgi`<HBYz>ےntXJ;E Gek)̮ɭ19W5{2D(/ef6~>i&? 4)D>*(ç NJO|ژȟVItnpsoHj J^֔nzk y,yU>UJ<^BF,w"PPq'e}/0oIE46TF:6T[yHvQl %>0XǔT*Dv_a^h -!:=*O8#9VNH<.Tʲ\y~JWGLu| (ݓ-:Gu?LIZ5o]TVIu1K_1ܜ7h|h[tҸ<䧙BeH PK zvґ;F }~'*450$Ia 6oH dLל`or`>΁V6YG0;oβ}xǗ8S3.CdM®\ jjV#ɚ%:$ch!8vnX=Z*' 'fh[1\PT$Z҈0ȊsZKˀaEhOH2M僤~^Б_/X ?5K=/Hb)C9D,VSe`4m1 fUL<"*ѱ8ؼ*/-/]ME8,p@G s{y`Gb !jñ jWBPg:Ђ|Xᧈ[U-&Cw*7Ɗ,^ce9Jz\6վa/ajzy$a$OhaEzJ[e(a=bExt_.+4 SE%U9l L)0c{+UᱪcӰg8m/Ikog8ppUZoR^?cw`n'5tX4 07fLGxM'N|PZvx"7FEf&Oh\$ |D P=zdnL]r%LE@KJ>./n.͗`Rlg7UQx *÷ye!C,׳Xhk_Us@BsS vci9T$ƄchϦJCёh 1j,0ҬmqR ӈLd+DuUI@]zCu3iZP?PxkiR2NqS>cDG~9Dm"SX1' PY=ɴ`3,e~u.DM;FyO?~&(iT凖^JZ-Ika/!oOPo{q Gbc$Nߖw5k}{KGŘWmnKWd%>R۲ ~Y cXIG5fғ$T( hTru6X{b1=%5M/~/l85IOhoBJ|"咣AJ3D, 4Ϡȕy %9Iyd<[ƁA5^G$/J0YgF +rd_L֊4|Ͼ#}[ndP#0"&LH l/]9+ƯSE|]g6vpx3z}^~?iO?p4xGơ+79L43"r R«^]W^:Tv욇Ȫӗ~缗hm!s 60v }KJ}z{9SݻH?+6~^!]NSH~g 2;xe!SΐADq`eGJZVOtTK0zj| 9f -Dڽ\4_72:ʅeT7zvȹS.  4v›H\ėفK>`۸Iu8[5 \hNIȱq~0V57=sܯnl ;0!|Pqr//0&_*x-:2ϛOdM${}G'"|٫izjweCCWs3RU g#`c t.njL>[ʽ|ҧ,k!q#8t =8pB@RSVƑk|<%b''#P6t.6ą8vD1>&je WRzىͼႂֶpDKݡv_b>R{8N+¿h1e&tr}3&y܎BpWMlV E($ ^-RhE6k@֓Q4C6g8Ȫ2c"`KCcsN(`q<~`LN4c'@>0OW,8)$F[~Ug+n[;G`aDOBuLR3#4ː#@(^賺# ǀ^J<r5<). c}JJs8qb \,%1,"φ:S)\VV)JQWVIBl5ƢN7=b 0zgӭYxծ |W:c>*,K `OҨJ=5.@/<;p+)i zOrԂl^\c}2[h0&I)enօ{{Qn.4 cEn3B䐪0U(뺂 nhmexl1DH0? n < jRżLSs-U5v$R:K=HZE}mz";ξ?%G${f4!_FpnA|w HFQTBǭ=HՕ= G=⩔^בi喪^&o{6֕N/;^Z}&]N-_Y$I*<^RcnAP|A%'L;!s6ŹYn0ꨮ/ L 35"T1E_s{ # 'z@N)~b.!wkIzaWqvS1PI^`Bxl>snOZ#K1au LjȏN1usm;dVvZs` kJDLPȋvЪaOZq<Wuɦ$&FȠ(vȢSRjE.]0^.²ImZ=cUډ ӿ_Gi;? J Ћz/͝'݅đsS/r˻ۚQ4Z- [1䧊E<_dn8J=Og1iд sd4 S&e8%}?dJ=E#Aaԁw5D̥?IJI><~+Ӳ"e!38(?~"&afq%-nFlvYBM/_II7 JS`|,O:% AY;z.Eg1(E% eH#An Du}\G]"JTHT \')jM6 m}|F['tW3C^WP2 5!CM/ #fvKOm8cn~e:/tB cʿ_.],%+2_ay:`=kgG*ux(r=mB#O hN$t[5_1sE{gwsiMY=Ҁxc "2%oVDq /Ieb,?b7GOT1)"Eެ(@=R+2xsːe~7YߍArcJ"|VƚKF%1FfF!m-%}k%j7Μuc͞f2,]\Jh/SU> ɖaΙH"˷bp[Vb'X2 'r])δsBocWEWA>%Wܲ\yYвQN9MZ>ޔLmɲYx!~_c,T}fSFXR\ rE*Gnq~dSb6!bu^3-Ǜظ^ gyIoRclA~ERFCKidK*&¢ݭ%G86pxQƥ#pǍ0]w"*bԮe Yu~t" rlIw>: }rX'Z]qigFz*ZYԞר>K[Uuq&vN;(y]'*;[7U-'6 DxKsFv@@B*&'O*͆|/H[O$ypyYbd<3-C.bz }:f$C}$;,ot[r 8d >w {{c{7S\&Jx_30]%j΁zGfVP XgAV Qpό rreMIQXkO=X2"c6Fjp}4+wOb4~CyO3?zp.E6ƥTjAǘ~9 ܼ =Dz)1:@ظQ *6umusf'E`<㭹_:XiMeL-Ҥ{O`k?_+*r2\/ў6 BQ jɃ{q;DV;-Iz[S]=;*¬CraRy\~PCUEoD[lO}vOcOs3վJsKFNpW!']TnZ#ASD @VwiHUd(HU ^uXygy T: >hJ5_W_8Q_v5e^YOn*h֋# )rosܴMBf8_QU%/X\Owl'ni8$E? 4#"M!5 y$w]&aɸ`-w#P xN{kѢ ^.;N#BLu~R; 8iґC33YE(*-5 Bh$3 F_wz76ov*,};s0+Z_rc )OHN4ou̢<1*/ Ů"zQcV/ GɀW}Ek@sʏ~h(>׆7 G3; uyҋcRi%:=q٠ J'LzS~%i:* *x:bBce@ʹxx5ZU\㞷͆ atHǺn֢K1!̥S[S-l D9M3gk5 AvxP1O ?P`KPlW'z31;z~FFY,VҰvoaswQS6Mi9"M|NX@[A1MԈWLV.647ҏ8Y3p(f ZcQQ!yHqN%ԭмt2O3i@j$iwkcVȲWm*ɬeiJR<>`l:Zr]RB\==[l?Xv8G"-"dfD=*B 'Pf?JALIADƘOW 6{?X4lo$)ikN$|t1 [%B̭pl_Τn=!Wu:n+')3'2@$vyLpp4KC7_plfS9);4 oߺX8V|@J/*^]&E W.52c,,AUWYp".|вb=It%79|t Tqv #ϭ$`S>uY8͘1OM29ӻm3%;֧Z/ *EP l/$FäS(Lb@g53g! 2NV~؃ɓ;ʊ:asRuM=?LuG,zj?ٝNtaJB#l @U QLOO~f\>d,'*y0O_S(G0qU+v9\fz"l+M~NgtǁyWM}1 _N[\S>SUѨwW po6CƐlD`}bz;oo.o#Oϼ0뉄&`ˤQZWu :Fqާk>0]^VшZ旔M |%lZT *êD=v"4H-D4<17 I׉O%V[Viaq4Ĕ*xŲ(ܐM9uM$?Bo/ Pe^Dݐ c @ݥ={.)iu*&C-hE}3XXClp*r8u*ʝ#%5i~GUYA>ս(@: uF9hj]C J}A XK/PIڱm{8TDuRK?O$PNI|=Z8{(,$猬7rHA8"e3(M2+H)#^V61U=T`$;H8]%1K1Y @ xw"CBTWkZR 65UbP OdFO/+^oQ3׀!z!z}ҩ;i*IVW=:v,(lwHNEwZXjfT@ZLqxOC1LyoJ) }HYpHyRjӲOczR;ZK3h0F`E>|g ߀p)uJCS[QP8+;L Ds=v\Ӧg( L..,=;iw#՞$?@ldO.A*ձdS}a/Pe h:Ìz2#9|'i 9}YśNRNuTMmRε.gpw?M:#0q8~fQĈGcl8LCP <5.-sBi o{)]Ug<v ,dW\M傀eb)+(G+†˷jv1#6/T_ь}B4w:;*ޗ+}̥Otf¢sEaStΫD߰Y }&Q! S"?µau]W]z^|_!$w.(_-fRT#U6d瘬}$ :&S 30;6ڞ:E9MDl.ö<$!6!S-Fh@߆A TrjɛCM'q]1I [#5g:wc)A (H`o, 9ƣ9Kmmt꺯{G]Ӫ$x UhoB% r/Ga-TXr"G{S^ydZ󭬞/)R#_ ),PUO|:Ɲ"`!՗+M!$mY6U3 {g]Z#bRDqY7OpXiSV⪔ߩܱO{N!r&y`H*ef:S5#qg" !5I20AKz (o$8 \ﵰu--ԕo`P 0GR^["/n h(CdǧpCgy%U˙q e{8W}Y %,H3jYEԔ(Z0U^ wn=5;\1RO)J̺xCt†AԹXƸBPcqhl3Ӧ7Ljt'>JY2?YWb*KKcE4{ cV"E-$W^Ff]چ, U'ȅ< :n)-!Էlo 2c}-Am'* s\8>RwevZґ|YG(s]9VH'fb$O'QYbFTPUk爿_LJ?c / E 6 @ ʏ1dHf K̜*>|M3CDҿig*qvɐ^GӿY5վ|C~ifK/XI%2]>NyܪВYˇ#˟ȫ:m#*QHu.ؕmYIDvuOlRoJ'5=^ExcS2{wxf/yo}_W%m8 Ӡh2ݟ=qܬ!Be?@⇅V26U:T4ږ2k<.LVNG1.OFְnXp5ooXڪuox[VWpTɓ &lKmVrC sDۥ:կ\걈W$wAx#QnUZ 0F۔,7QAR-稄+\Tc79WQ &=XRDQ1IRot`_Fa]cIy5@:Dˋ5سll-;aD0m܆j[2}`Z!^;;8m'\ !C@=btz)eE|c,2V .4z|Md:W~ Qm'mܩ% ?2 !)7sQHt_D'i|;OQh8]p t~x'M@drDj.-ATZJl$<[\N@!X>o٘Jlwpr>Ɲ+ul=bH}nW CsBsd%uSA(w2nSN_5l'60v 5@P-n=6`ܳF1e!\bx#BN 4[Iz)NDU\;OEPn 4VNoZ3Q &hZnΟBn,F/;TF BI H0Oxncpoš0> .|:? 5*aO͝Ǭ il}lB?[tޕ4e`h~/ݵ#! c9{ "ڳ9œ 'M"-8x/9!:s ld>&N`mn^( ⬳G@룮jb~J'5*'4a HelT.*!qH_dj7X"A`{jKR$4R10vG>"0-LqEgT[\\'(%Y6€ `='wǙ)Q%5Ad$LJbV58uz kpv&g͋}`!y!pTk u3xu`uͬ0=(u[&_=Yvë#@U\_~ QIqҲ tPG=XC\Z{Փ5|RY<>D%ӵpSgء eS6W2H1˂n:;NFMztC-V@gH$OO7eNb37a*]^fͰ\zC돡3o]A\yԤ`3@, ܎,F_N$6%`mb.9|PQQFe(h`sW$?& jNg-# C ^PMtW_k}]7ƸGwBXFT R?ZyXb4֓4mic /?5w)I^ti PfҒ@u}!VcӍʈl˙/C6r-PݡmTSX6kCEeYiiW6`Fmhi׾{+];>ZyE 2@Y#=2T$Du}5:p ͳ6LR*Rb@ MCޜ<ʤD-hg&{Axx.L!$tdif H8Xf!#6v6onUu3wl^jY^;GDzbW?CCzU$2ڂ4B4t1c.԰/ | &=Qwkܘ`oqA)CXԻMI"dA ᫆y^ĊҊ|ov z>ZWKَ9qW8\K3v`ީKȬbs_ L?1;`|*+K8R $1YD!6WK=>=Ӕ cGvZC}-8{3Mv|H#9[;!O\v,' M!^BP7)|DAtBub 4v|Ϋ0Ē&oB8HOi:xBʼqAf /C^n͉3C ^Rs9KK]noa|+@e5WiATƧ)ŷP}=l]Ec7"̄4_sTL TdN> ѽ QZjFeq)Am`GLy }\5 `i5dʒ/wʗnr?Wbۤ /xyu9ªd[O<.b3U':`MR*Kda򿷧1a RޜO;D%1-.4z}͟xz5dTr]h*J;1b̦6 pvpޢ9"eCp|ײs/XPLT7pvsYב=%oH~vAr 5=k: #klI'Og%Imbczj~P~)=?5`(~DB- " /bemvs<6c9>Bïّ?Z^^\myʟHbӛD*JgaFý`FrfeSSX͖`E4qhY-_ 00>BwgO6$IZ^ꙜiLQ‚ qE0~b(;=;p2Q.L _ xY]ѷıw2N9W2ʊ`>oa.m2{n6(~Q8XX<̍Fc!b_%A)gq%ddͷº Ǻp[>I$u"a\|y(҄ӏO--JJ:dsbSf:DJJR '$*(뼵ux v(/URWw64R 5uc{)VDdӥ.4S YL=É])4j4Aa*3,yoml(ѵk|΃7=vw}.FmZ#"r8CU|!nAU(p[`㢔$|F|k9ueIALE0+^M>.*'OZƇIOTFdVlLp+ pKJ4b?G 4ěYzwlƷ*xl}vYzZ>l@pF=S$"kMm*c)̻4([ #hԤ,=plɮe*EnD~Wuof$EL GQc6F ~mdfD& 4Tr'CIps/DǕ:(mUJgKxq7+zwH eQW4A P7 Ir m\>I,V1'q^Ob1Wr.=w @u7S2A%eAS.Cs0|f!խ]nUb # b -LOvMF5xާψrs[}^3 G7 PUlƥQ!eqf"^1fQ;M=OJes=\3IK͡~'B(rl FP2u4A%r. #a\wM LBbi[T0eҍh.g21ۤbsðޫ7\b "K*oXkj͵AM. wn#x[(38Eԭ歍۠ݼC=0Ws3v6Zy-ʳ NlԨAvD.[!|+EQb?9"-x۝ft4Ww}L:iմsfmA+_ "dVݳ?t:ScKC/AQnKy6Gݣ/F[`m鏺9No 򴾅jp?ov };|c!{]+[pHY C2 Ryұ`;KZpaTF`mJ$?q{)KP4')u&?x G?bhLHD -;!i\vҥG_Aa4`e֓yi)Q++*8卑v֔dIYQsQ_MΕDhEBw:,;Fc3DILXě^kS$+}K9k Ti,dE#sGs=D.O1C&?qZNe0٭s.9"SS+`D\rd:rS>əOѪ>QrA;t4fac{J? 4rRBbFimW<Ǿڦ.Փ CBq`f;l}U]uM;P0i6/VZ=#[F?̢W_O# NE2dkڀWm~Aˇ!|u ɑl%qGG fKG[w=$C3~:i,Ԕʨ%ղ*-OkA#zq,0f O`>N*´Ic}z,3E$RO;◙ѓnʱEŲ^be )Krɩǀz'DQ1OJODlfpݫ,]-BH3CiǓI9 1IȡXEa'iVK8{t%+S>5$?`kx%2mfmŭpΦ ~\^b~ [k~_/e߉u}9\w-=F$dǜa71lmGd Ŧn)|I$ڍƼMw u5&ZV1=9K2gIkXozهC49(id~āE^O?+Q+SSù@ |L1m;{S2銓 9y&Z|;mJRW [^&I0 "1- AV_sek[pي9*W[1j]ԫfSٷbFbN`ZA4=0P=¥joY`F@ "B%wC+} 3 fcSXeVsUKO0Iv7,Qjjl??>2t`h PRFR uᦗ5l2qЗb8g)O@ݬ*2S  SNl,qTf{gd=CO|\7HC:V={y+]KPrH#PG(,ri8E0ٵF[{K+,OiOЍ.T\ y _nGZO\<2zӝ+i{KzZidu5ˊř~DijtuHIk/cǨ(M<S±[6ci2r6w#%2 A[_(3%OSsSlūX`y+7Ya/HD֡!9DMhobh3 !BE)V%ýSXZtb  igBivXcǷ= jA3n.-R p'Om|-rjp_W_Ѱ6۱-]Sp&$)enuAtVh2-g[ʑ3ZkB˩>w"64*+$ߨxnMLbW2cS Y ⵦcBi?,xA7E, @qRyU v*+EаYe?sE޴}B–w@6[b"X*koF1hEROoM`(*A}4%u}rHx.N?xr)ZL@:j{2.xiOA%Mǯn""l(&EHI3 /I$X,|!С7ˬs}1Ir@b\OOy0a8 {*:V5u+Y3 H߿"]wrE!{#U:[U-%ˍ֪5Zj{o!/fV@L4g  /8/f. Dhr`D6/H7?4/lHr@+;Lj^vW=Hfi I h<]4u/vP)4[n:hVlu>!+BOJ$yj#sOLg ZN`yu3hRա/O_|.7KNџ%rzb2]JzL[5[mS6 b_rO:A".4f@oЕq\+>10{(ۆoD#MȄ~9kƀZOQw$J:b}r<˸-D/k}U# f` wIHv .5W Aq \Ei/.ӶJ9J UUdaVbM};+OSȽlMoj=3"D|LCB&-T[s1OSrpkݴD!h_nXqĘvqM%"Z>(=tQ,$CEћx|M_eOWVk(hEڍ}=zZ +~ssb 3jōQe9{mfReQyhЙb AC I8` L)Kl A ]%.ʟ4507|f7'i(K4Ԓͺ̨Z:VJ ]݃ȗӦe2@VcP/ sB"1z-kUX "H56-ԃ޳X)S+g( MUєe47?/?frCQݔsI[Qq WTW- ǹUl@~["|>+m,潁[ve=328f!"}~`FTHgesk~9Lu=nxÎ zːlݯpv +ahmj\+s Ћz谙ݶ0u-'^R":+GE6sDopW߅tJȵs0x;9%!Fd<s8vi>zeKMAJ} p›Y^0Qxp"YeuihD]tcH3$Z~zθ/Okdi?5?r#onɞ :p7C} @o\5G[lKIG%D`]]djK#T dBĤ165`a*ONhѕŁqgeQ!eJ{Nްkm;ϧנ2D4N:54VHTǚ+="ne~ :ʯ)+hPZ"}n&آb.Hƃ@Hᐼݟ.3{. ߥͽm)7lQ' vuq|Y!g5EhnvjEfgfP0&>P=yN^:41?HYA=[i p}f:SUG;SLk8baOǯ.m2; YAR9~Nɶ4jPdߘET_ ҅v䮤Degcv j$tۨRԨ+T|D.D1 @s$ô޺YsC8D;Xqyݓ+Se 5oBdsdZ; +"?߾d%mٵr6;'xEMўΉC8#bu1{4͏?` wc3\LfT,vZ+ IvY񰿬J~ [ȃYE1WGo*?{ %S)-oC7{Z)=؈/y+ f-yyFHٟPog3nB|l QΜP9in8tz)ClqÂ]hnJ;LdoU fl^ҟڧ0F-H}Vowm GSZ|X6ᰎNQ>Q]f`k XR3b_\bV[զ͚!}O7۴/H.¿ͽ!Kvc6Z^^(Igc#0fSӋUj+7~,нcX\MWud|'ٟ-gHK⼰SDa#72e} 5xғjra"fh]?@/)F`krd5 ثʑ-Vxz"?ǪT@&[^洈$mB ^R*i6xζ}) f(Y-'(xs.XPJ^Ѵ`QAT: RvxO{jRU0s!1'ӳe]Xy'UG1 \f8yޕv w1t`>(:)a0D Nmæ菢(kepSY0iΉ~PcGlkc&'I) fmĦo{VL}&SYq]e=Q0_qDFG;tSi.Ԭ@CnPD{fmU%Jo`M: 8o~ >^T;,xC q؅~|sy] ?}-ӉnC* MYs:r2}b$7`i B'UmDW 2bvpRd>?ǍterǑo=P<8eWM8 ҝr> =j:C8Z98Ib6KBוБfil~!V/g5(ڪ[xaLnDT?.v$͊X!͏kכ; ޿_H_41 4*cyITVj92r37t7F8i}\'@LÔsgN5[aIйQ^BoGM*Ul&?bfQ~FUx>A3xHX *6 h[؞+d4/FͱZ0tC:=JxkX vGp^;M(,rc3 NC@旇a" h>-{/{hWa g+p82W<&r+yF(Ј2~.ʆuDPF jF03$ƻmʶl~WQaw,-#lq0+ɳF7}&Эgnw2G9TBBxHliGc`zX<^dӴm-rRG}JH˲mMB" !|TG$?-)nkYr:S&hح ;p] {Q4rC|cWWƦsAĦyR`hM& <Q.ܤSWA]f=1dmrs6*xLYs&\ 4J"{9k;Nʧ}=3D|nJ sՑMiUM >.F/Ҭ[%z, ҀIЊ;%&w. =AQH)$ihqNʒ< ΌykI]{[d{iJ ' o8cX[ KN{f7E1B5_=NBf#5לZG6)~ mp(&=<!b#>M 6HڥFp c2fo2`5>@Q/u$O~A$y`_ی,s sg7-8 Jǵۙ@~Fܪ;*3!M򽽍1zݴfũhj.HVaR#".0^+kpCT<94kgWn8mỈu> yѧsc2OڢmWAA &}^wiţdiF3OU&ӈBR>C^VJ/sp]'cX O]= ¡^,P\(1 >́@ |Yа {;*e٠ cјd0K J S}֘ms*xuW4\CTuR~ud[WYP)vM ށj/ z  %.p(In - |\teyТ7N&~_sj7y# Ǎkqo-3w:C&wY] Np2%KRةl)//Y5G+pBi,4"+9}wرŧ`VDh/%_G\utHz+v#*`:1b]l0Xh:cM OAyNP7"ePqes Z.](ч4-vz]H. A) ,S^EI./:oAk = ;3Ro9`%hSO13 mě}!D^3xX bU8P]))bk"ww; U;\ZL$h6Fw4dU a W{H:={sMP_$9N=yXhSegIqwT9c/erd|3--[+zQ׌\Үe|)EBIxf&zÌH{jy$z];C(*1hTfrT uV2yY^fL !goJ*G9WVGt9JRy/'cujT t\Rm< Tq"tYyE.Fe4rŽ۲ro_?0qrΒ#.qe cr'eF9_+I@:: ̆U6Կ'64dOM0O|yLxO!$ٽە?-m,v)3SfKFVFOcR6qM3Mb߸0tqo)&8I#G5Wݘd-5PG51l?_MnMI!* Kw1tfD./}oץWGek&HZYdc{qCdX#Wgmp^{Xy؈"-o2JukU*f*{#&+ya P͙P=uAԃ 8)ꕝiQ_dSB pYC,n>5)ArD䷣N LX(6qI?m? ^^)_7n,v~9.`LY̧X3DL5! s:"p^˿Q!}QHHmqWu4$F0eZUFG>jw?㨟IaH@{:`ho(0T)Y3]vejTHg3;o~/EdE֮,7xrg1_8@G|LIQNy?a K3Z;VҤ.TP{,E@eS-~<::SF *iJΞk|)j$ 5K;BlG K8@)\n6׽v%oCbn(]pLXђnDM}`ɭ&S a=ezv [zW˪OcY#譡-ٌZy~q>W6{-w׮kLzF\3uq0e[N&:"16{#VɗVJ20ݻG|1NW_HPv~VI ua=vJ9 W Hgpp~ksqs}V}z>Vl 8=n>M`^?f&\11UQ8* OG [XWfՏ}߶IX#Z|2h=~oZ \0cu [Uck@̃#bNMSqK [bÄ} 4'),"w;QޖBMLb!M~`g 7 rC,6ƴ"SUN- vcK yżeI!)Tx{PԋnFO>9)*O굷( XU{g D98GAŐfʂ>BssT{OOb&Fp]vꯌm'0I kF g\VED7Ŗe3ծ:1T[.X??V)Q8yd[IX1Kj1 ϘzZLjdt(p@>1Hp *PuI}8Rk`3҂Zj:/=)qjLTۂgv6m{}kF <͊o 8 Ϯn/*WQ']R GE9"hR>\1跘t*Ƨr,hȡ̒:=1=2LC'vf,CpƗХ Aa9JfoԬC^\z>e&,v%q3|tĜ\ 'Bui:4>Y0 L_jΟ,9GGš`ٖ !i@fvI_y}A*:Yӻ~ 1jNW  c2ڊ vNu)m/Z^+oZ&9>A J7=簣kp##;^ϯ^w5b澙rSsǑ(o%40,\c6qA$((%ĠadPF}RWrڳy]x\iSB (N',6GЗB/4!^Ȓ7䓴Rl) y݇e BaZDM\y xf8Y9"GH ' s8( ?<勖o_cfW "x%"o`Ѕ9YcSwV O }m$6iM7fȊOB+GV; a$\9MPMxQ]6(8r[L߮bb;\f }KAAPW};F}s8Gɓř.mD}R؊׹3to m_aau ҥǦvɡGs?.nM}لGX|W@{wln'q ߄'A0µ=zE!"𘖉J"BŷJ!&1HBˇ*+CrHa4G7F<쳎+cXW{A Me& ш(A7cWNhYYqYJp9v$WvjVήqѹ3=`O-CpfTc) K ۬ڗ#4ßWnTJk4'E*~a" &ItWx,uᖦWr )=;g#'c;9B?˔$)sDd~6pQij0T3|yy+:x)rӂw]0l GMŗ/^uLF"-MV+l9$^Ix>gj냊+]DڭjWGeDRW#2|p9ܣv2?RM&65_ o,J _פ${SY1>i*ʻ9Đk r1)Ph"O٘rفpB+HGļrd_Rՙ]N$΍.1ZJjXĎ{1ǐof41+ES2:dz[ }j8Nh$;t>o;BF]DZWHѹx.: {|CF;)frَIgX`(h#ԣ/F, [Q-y3d_~jWx<+"dy\G*W8XX}-**\B͍ 5[;G"Q9n&&9wܻ\Sdc\7P2Mi*hl[F]X,Ыټ(Ji LBRsLUCz%TwGl@aeZ֬zQLJ罡5:,!={(Wy3S ޺(U b>MzzZA*} Rn"'!U8TmשQPTmN=Aғs\\+4㦒N52FXZ,. ,P_?WkF[W]eAF{hٽ㈺Bڳ%^ES"Pu&+:C+EL90QR9]z7]^4F!P PLեI],uSXUL'UR8tuŕ7){}9ZRTx;`t ~PˑS gMW#w L }:q/LlMV@G+1{0a򻟝 R^ːڊi.Ƞm)ftԷ2_7MzāY:I(k ibDH4gƁuiKNFyŅIB6j\@g6*iPa śn$[OW![2*C=; Wŭ< I :nza~r=>BaMJiT[(w1Oz3p;{LEtg O/e+ݱLP,,dK/q݈߄hꁠBV)ޫkL+hRwmw.:g#iEK_xZ. 81O D#Pآֈ6:.%<p1-L:Q~,xCnIwX6lo( p7=yy~ M9:WwXvSB+j/4g7<iz x5`_-N4JƆG 41u@djm\|b%^@ܙ(&}!o>~H`,+CsfK3Ô-;;ŶAI$e5Uy#gp}j-N-CUtS}j97i~iou y|.ğjü;]LJURx] ICfbuGgpg>W9N`mq}f4&I]1qoՑpk-=պlDlNQY3jT5- "04~v ɅOe1ޖKH^'3RNwt`T /&B[uW^~ n+|w N׮s,3Ir$e,Բ,o$6zK_cT zQG)%F3L]̍,OnGy.=@ߑE}s+^z^wJ,) %VQw:p78+?}c.Wשg*'wg?V5B{خ2)r$$/PJo00&3Z)1+Զ·Ͽ r}D$P,`mLR6wi^%qY[D<ߕ}(ɬ;ϩ:7v+c 1ƲMLUKkt ^mY/vz*E!AIQ#BUlQw`~I2.#w`< Db + wY{.7eom/%q},D+T @S9Z?2]_ݨP┃S(G?|a:D`LKB "V|>(B,}-# &MTk>OE]DK=J=l_Gy ҇+exld bu,r !|8Ui{+1R-vt~'}hߐHyi{(pB EXuҥLF#fLax Գmx󢣟z>3}9'7%4^!] eh)F/c5W|D߀0p7eă-l}nu4xF/ 'ީRv EЅcᅲ5j34 W*C/#<u_ԮKn@"PaK))i^H=4[U W(CAÁqA:q$&|@nIPZ_KB1F޶q䳖l\#CLO:(9=F#8ǩg`䧉o{sCt6/&M*,͒,a\+QD!,k@{JzmrZ2,2ށnz2^jsI!tЋ@ eGDG#[9F rI!>я82Ĵt[cٷ'lUdZ֓tT$sW\4Eߥ;8Ar9vgH.y.^PH(>>.Iv iunL^yNϥ|=?Ps?ñMܷ Ù 3xYin?S&T+,E4m,Bœ7}e񹉑4@s-p4E-zDB?X,P^:cH<@"v qޤ Slduwpݚ/dΓo]VȷYʁf,@ۨDat^ ϯ}l!~QNR]Mեcf>~&]WeXg)#nD&g|RpP?CPf#B3&}}CjQ^Fv?B'-uk#t7k \2Np2X&Ry?Y`ZEoߥYu7Pa/z`w;)Iς,vg82Db+x t<e9i[ c]OFU7DPPZMP.쟶ױxVu8\Ǜ 'K&$bMSBcQhYBGFl2;对}r+ZOD!=tTS*纎RPgFydǘ0'>DZa2z|;m^8B?oSkAMEI1Ewc(^oy63\HS#C9 $鉄{ᯉ:IN7Н;nͫI.S6Hz ȤPѵMZx^S )T܁UƮ; h-x?@vlj +uxYx۫wuY(֝o>4{t_RmV*?!|@k-00T?nwn(ŸFv4coFobq<#(LF?~uAXP8U6^$8o'}JW\gGqhvI̾K Yӷ Iƒpߋ2*,k/X;dY0eO+v#20x34 s 6!^(.TݼsS۵OGe-fW%nsTX/0dMGm$Gh&1Dd't !6.)qAѨ ๻'ި~|aXa)?X\(rdHV$RPwEtVFs/}E׳U[y`OK35nGIPf@QbV f3,^?rN'_܍'X7s^2s'/wv;{U(F>[-){niמѫ5z/ Gv ?W~0mZp$^vf APC?efDmYrbaG[ T>gŐvKF D ?b0wu@ϫ蜊?=eA $(JL*3w-X#?]FJva7)t).o?ןqubț{$l;8iM.C˒' ͘D9>(M ngrD-C ՋWĮ : .ko}}z%e *"A܈D$Ԕ(+IiUByJٿW|[c8&& SY+JZг $$U|$cr*oT ~JH@{r*4oj>'y'1k7B8qpZU+@Fn&7"M qѧ]I#2&S ycMe>Xϡ2ڃJEm}#&Y\>@Sa^JeN?1Z6zteZą>O9Tgv7x|wUlU&Z]g},aSh`*$XKww'ƉUGr\gXc_P#ƇC%zY$^NmVԿ^kHC+i'ZZj9c f)TRT Dx (a_c ޏRn MOdQ2ٲǃJjZU$|od!o Cٍ^+B,Ѣ{89 &6dإ~GV&#u?K^q6 {сZ_) (,d$vw܆x *k_;ll-HdDhepe.Q u ]l' o(C6Ğb&b @VvG)Z7?nYԞh=ƕp'ߵ-#k]}!Le GN=$_弈+LXYdY+li J)]6@$'<^}̌^q1=gt6Nn Al2&O5GU Y#]FP:H.JԐbѹ0q #}i#`3?'ŒՍ:6%Pmxwy% Ou"%6~'H.p<@kEGCCCyhém ,Ln7 )#Fqf}ŃVS^b˸*>.(1BV;1=iIt6Z͜o76BtGr#֪!,v S^ݜ0pق~\(~IV0,3FXDt؋@#t٩YhQxsH! (c19 oXMnw@Vk˛vgdrvd_4ƕ^6, $?ϠC gV8>[wԶ.,р6/2iSyiڲ 9EI3N(Oijn=ahKAa`d\bI-n.]"ZRm&gA\+/Tyrѕ/Flʏ<=Nz?PZ[ޜ-bIix1kuh?.臂LctS #fo#)j1׵{( 0Tc/ {O? Uxl}aY$Z:|5 #_o rl!iF?ʿ_()78 05պN|0)\USqx?a hƀS2w&'xcc&ٓ;Rn *UJOzSfCL0SMafd?#!mg.m/;DJnӓgWTX3"kQCB~:W x+#2vڳ2Ep1d+ؘ+8kk:$/,X c%a#xA5zT(W>@|0 z>u\[7[LiYJ6OTtQOVqFhk]0:d֞4=F} 0n7jt^u-~6+,DC7+ftPҠٲ0ޜ>!T$ f^IhGIJ@nV MEqGQKI)8-^5 5Wxw*VGg7:Pt"7IP52 e!%}k@ou,4oȫE6_7[ f*]kw*@f V$geBԤs馛<.6}Fd>6 5#J`4:U9y9Iuk8/Iϸ4~ v g )@TʞE3AZsP\G RM AzV dw37K6%#}6vnb$"u@?,^[aZGe QJD0F˵ 0Zr0Y( U"}2R达оlT24Em>`ݢ_5=~Qp`VU3 ܾ VcQݐ:Q+m\ ă펫Yљ؍o x3M^:)-^¾̉ 3Y7ȱ}%>hOQͼO'XR q2.m\δ͑-!W:$ lFa39nUo{fJ5"v Ej48Čn? t!p BQ)0SK^RYk24rW߼a6dg6!TNIO6+gDvYEq9 XE2^amWGJ P%FUCmYJIn5jws|!W,6b^Wƕ?g<}T3u8&'P c#Fx!;>hŬBՀm;[w= ֮GwJzGIO#O.;vne&c$phmPXéԃӨ,Y7 B|8uKs%?؜ D' akU.'8#lO c;iyi>U}ku=idH 1[T(?>vwdmE+6 ʏdc5_^7[eH6AW2yG;7k9U0*ji6* %d+8L-EEU RvHRGFM%ն_9jEVC#YSx싆^r:~N,%sw|q-J[4[؂U%e,"7"'e-,ޕF,2(@0&>/'+Ͻ4M2D 4J@mF)լQ{ßwKdC~["; >[P8m '䦳+WL }o͑\zœQL̰|t\?D}>"[RRe~AIl`?/lŜG^ }c7 y}{SORh?3*mgc}s Jv +7Ex)Aም1%sLSNo#WǪ䋁o3!Ӯ^`'g vvs۵#_nyChe(Û{y0R .2g@MV WD%7yEJ@@ OA5&Y&sѠROv^oڦ q|p&)jf!hE qn3D j<,9$\L嶥dч- -/̝ȕ7VL鬐$}i m~Ks9p[Adʪ:6"wxhxEb~Hbe`SװqY(w__$1bJw$Ug;Bb$OS-6_^ 9H]K5[sZ41wky)nc:Ն*͆3E: =bu-ؖ]Ш?!06{ q, ցzzu1RK|2ي.xkkwCd:EX L ӛ"Zc"Bl X!DMUiX u/#䳖B)f.kzXsiG%L\-P~/?*e1sx;v1ŀ+=%m#ٰ?wX~|$ԏwdz5B&g״,沣pVZT()$*RZVHOb2d|c3b7oABC1*r0%0<[ʮ i r隦nAđPwet$Sc^2eF*JJ~ks ^Av; P':P\1,ʏ>4TӁiϖZ#^9DG ;Xbe>ҊmfSФJ V QX%hsZc;04YCK7Kz;%hߖ Yr<$\,!A7nje[5_d/TXc4Tf.gpN.A$tz;y[߃GF ̖;$9n! CSES@)9>X1jĻWhMoĎJP¼z.J*v_^o(3yZB3ȿ=!2xM2v>)X"j{7M$J-_ۉp66icy +T@}-H+ E^+-[x Pȹ#ddzB{HW,bjRww/`EY=52 W*Hh ?-]Yzrb+tIXzi΢b;='pE{UVjK8.5ޡp=·sVa WDk/JIs[p~ulAs]H Cy>1ᜐ 1~wrm=4a36eqwv"@-&9?:{R4RОl ?@[2gӝ@w W|Ep臛Ӕ(toIh)EU,310qi%m([}9hcK6jsi)`t: v@)EO\hS,ĥe',ˡ(w!LekrCO]4R02 ]lZ˽.ʊ3kتیHK0e>h@m(( I`01Te9PȴpVglAZi= ۛL]h]v.ɗ GV4Ks yCm;#q:in>㥴z 3agOR1'sknXԷ(a4rYwn|؜jtN(as~(+T &`Y= \۰rT|üŰ̢)᝙;i4l0yXΉ9G~o8 l[V9 FMߓ1L}Jw3҄0d`SCVI'=)50 & Gң^fK!"FhпMd+8u tv9B3C+Lᆡ=':ӧGz@&k ܽM8k$j+ƁwsPPa+ySs UN7[5m?XX_A4C׶pa#C}Ŗ٘v;t3X~9oKƔ_QOV+&A{nL~enpډ?2> wu жL ïuaVn_( dx[-[]%P?%s̺8B=zYCy=M fq钆" oS)Xn"tƇv3uJw;3Ll\;i1VͫQy] [ /vdNx8&;l*mC"&ɅI4,zR*PgrdAq2W I%wNzi+!Ut Kͭ+lJ2V_`2 uTeH9ul(Oܘujƾ|O4WQ@ *T"Zʂ$RU`mW8* 2z.-։%c9|hԮLk沩@(~gjk9TX (!ȧo3+M+gJé.TY R:Ԡ)#%6tRP0 i*[pbd8Xme醍^U3|,s~I{#E鉞Q0dkWaX NܽUW7\Vx[Ji]3}#9AZK]qX69J!dׁSnդ#aDp^IlEt^b`>x_~/ɮam z.vhn< 'he IEh2yC3F' x!a|%iQ%~rٔO_Jl}z5`L<4ڢ>4M!9k +Ax/ `*ۼD76Mwf+~1Kk ¹n^ZƩMxZ%IOWg tҟɷ#oa;F=~'9zm؝y5w`=dZ,34fƞR/{XAuGQռqfn9&"f֖CiszeTbO dٽx_-ւ9_jʵqʗJF&,Q(|LNNd.(d^Sel9hZ)Z b36rN_-HwJ{a />NN&9IkɺI;k81hr;mhϣLY5sbA;Z o8?䯹u Swy _%鱞'QaLg "/=*[obQ詬y7$m=/8S髻cx}"Uф+c!/YR,ockX;y ɜ=mβa~3x˧5;t۵vz.N=7 {^la:c?#N|"8muȍ`ma4+ƹ!u+W)ӑcnRAb~:!mbv Sdv87x VP(ZʦK8MyDW{L:d4 cg˗\16M[xvu[|06쁀:j(5FA1p+xu/ށx+<ΊD_;hO`Hz#:iVEo2>~Ŧ&8p{69В`=#2an8Op:~;}haF34hgG\z?gcchGS[k5M5p QL|YM5ҏ)斩ئ7u37rroԾ.+9+Ddˣ~p+QUޢya̯jU%,-p!.ܽotd<+&.[e Y5Zpռݔzr!:hN%žvWM<+%{ewe[b(|ZgZ%w$~-bE-zL ȇ٦neF[~9ZH3gD:Nn bR_m+8QjЬ>*~X0SVlLt2YB{(Ʒq\=pv{/hշx Z ..ڧj}9;A ?'.[ʍwziuMy%4]9Wˁ68Fu O\Nd:osPAmW)js :^_+Wsm&cGL#*ᐙ2 ySa:FI4uXW R-#)Τ4'z$d0fc9R|{DՏHvU6H ,mf锯Ga9J>'9hSm3TmҊfu\7сv&O&^/蠍t)/^K H XCOIIkTt3[BN_I'0l2pnLcӻD\WȠ*`Y"͜ү=bP-EԽԫ׎jFZYC/&GR:A=]RU!+9R'u"j )l\K[θ։qI [u%f". ĚPu&}iؚWPb矿Yvbe0B (BJUCT&ZFhX :̏{QGZOhMk(86(}/ϕ3E93Mn:  _7+cW޲*nW3T/xX3ե0{6vؐ=[:Pby# (z{R̢RG1;CV¥ęf)cݯCDH^}V@LT^g밑OAݮ'qT;GvzwW2X);_"Y#42H<c^Yt!zt-v`֩&rL;.r'"D>Q%5mA)SժWPeľE&OxTAp"MpHu]:D>FM zf=ZӞyY?Dg't?r,T{+̚[P ;܋<@7f3;vlɊiSq Øy5dM-rc--աWj~HZd's?r]OEK%rFеfA#k1I^~}R:jX֭Hx .61k!7m!U s=J903}ZTl)} dDgn%(.b94m#T̪,h⋺3ԫMixrWL)yF#$7v%.GSW ;\e4T+ድnLg1ekue7/3%)döз,NvtBeBRo|a6ГF vJNGng %hܞm_M9 ^iPmS3X:#rxgBB0p])2NN @Ib FfFaxGI^iՏXs$As YrʗI28eva6)LZ}~vnHQVlqOUG_ Q"ƖY3iR.fc R <[hmZur/+c ιDp^^~[^ 5tԿp +5»ƇIl,Б%56rxEɅ'^"mr[~jXD&9eHԛY Ӌ)PӍ2v^$2Q?/+CaA4V;?$J5#'G"$$i!X9;1])Xӿ~>oA K/ʢZut|7m\%'X EzjhE#9 %5K۷~>pWqJ6؁U6\,6'DP Nz5:´aGZ=Pă;SJN17 "7S06~ htMW19!Y&SUws] Gd mۃyWݿg ҃tSZmsLyŲ`6Qd \3H`̣ѱH=0POO)jYp-z%uĔ@ko!Hw}3J_ 2M0aNT];Tؤ mfHɶM7ЫӇ(&IW6e2<|{O^諑qD<^ɅG p>;6- ;'"=37s?Lmք/4/Õ|FPl%V3$ XFH9vb+f+}+K.RvbBQ^Q`K]dcHCQNQ>YS #1N %((B]̝ʭںثIJ?tʉZ٢4 Ej^XA! (@MBj`UN& R^ˆ t0=i&Zx9 /ށ6ȰHςQaRiHqY9XP')J;0cJbF[1 gs3}lASmgh c6aQW[lu`; Aeu?KQdZQl T0"S:Uqǣ\) ]mAqҐށHjuLP8I'9˷Y[Y}^ E /L2{7kzE/O5qTKY<-iPrS!DWcsnêVQMC{=VyІm oĠvٔRjY>GU}-iUmث%KGn}C8E N`mP@- ?Xv]1ӣk;xE~Laj,.JW9-z4Q|3;XpemWHN,xK|(5>95δ jcY_ni+S4@>j0l8X1f,NHB^L`ªZ)$b^]>}%OдߒgMwsAo,q|oo<к(Fa'IKna1C㞫sx$%ӀR&g%Åc)Ho"羾"El`Uc#@96G1ť eKړN =Mkh 1#^#K~MMdخ3g{t"uvdt&2j=v $&v)YC$9arM'_aa4ڟ!/c3:(J\9B]aj7w$3,gu3U]3 W^]SOb6 Khy_rc뚄QbIU {|Tba)@t^l^-'`Y(p˜t [IN)ND>FkrbAO_eJRTE+|7 #^Z,/= =m 9|ݿ6UO붫,+B\}+]#Dr KȻm7lĈ21\ׅGmoc|vϨG4 a >y\e`%Dh6 _XXQ; $KAO]a\\Cylm㚿S^CM:98?NWrޖx]'-b.FTr6npf*C"鎄 ".dzX͐*x}`BF/W]兽,iRv;.t [3:M2:CxjjhYȖOGmdP0_QޅD[ ogXEy`NV5sBl2Skw4-jbJJ3.FՆӕ+@z߾I9ps0o37Mej%X'7юڲ]jKlepMuX}X@`Qcp YG 죴Kj)l[ݔf._&r78GJ;xޜO"f'aPf͎^DVz~?e&7>egG~N>]۝ÎB\1y(F+xBxQ"ۋ0[UxSbא"-ķ!n$ɰ1tC_2sʩ{Ld8uy<D"uX6t4(9קƯz쒫i3acx|mbQeܙ4;o >Oa nnב囯݁;z y|\rfdr+6J-@ 0iM6mVA="pÞlNf#/ZJ܉vY3Dq9HooZsb 2c{軾&{K2=IvO~BU 3pm.+~}LidH)-^cv+x#oW!nto*?!+Wկ|qu 7~m%B#Ƈ:B6~qT{nIۘvIk*fNwʻo y|X `9ˬ.4拗Bv䉜'#؎9B<|hBt#Pg,_~cߔ(Ö>%rZw,@-q}}Y=,w%7x+nRd__ՓWs-(uFiذdC0{:e]Ps7>$!e>*X]xiA:0օV j} HxOclʛPY4U{Ze e*z%8TR i'~%4JnK@3MWxn2ĦE ɂC&XB*1hIg?o4R[#> ǭdAa |*X 5dnGJvN~}kv64Lvb*^`Q(:R܆_Ђ*g{SP*!6h1F 5̼,Z]O.Qm 䊊w߷V(" tQ(^~Dzt+ŸRVQ]H'20-y s5d,+#ua /"*;^FTmgգ5O*ʤ:PO.v.PP݈#qa9ʻxӅʡYvZmxɪ:@<ʢIT6$m`›{l$ȋ]:>דT0ͺ1s~ RꢷF-Ӡϰy\82"VwGB(so׈[ۍ(jPI}3VO5' +"sk;+|!c"ϋidըLg[xȓ&S4j$њvR,\ H 0_6թU~+4wWu-q3͕BvT6Ol-Y4Q=πumEVa{?t=C<ȍwOr`Ǻ3;_`>8^Z<3"lb/ǿfj7;oTrOi>ceOcqvI^,Wn{bPʾEWi dʳAh; 3qp,C!VrVyNt=`TĦ ^FBZ3w g\f*Zbt?i ݇vJ0rL쥼Vi£&xVlű{i;ZAf %4[GHݣW4[!@/ܛ8EoBk+M7?A MGilOLEl{qU#}^:3ȕ!Շ~,heS^$4+R+͈iԭ; %?A^Y `}I}_;ֳt,0k=L Zs(M3Y'(ݾ@"oaMkIʿ}Ux \,SB,I\;mma~a`JU;x"iI:xߤ7s`Ɣ9`9^r?2zr2TSK1lcO"\_E̟hh0"m{zrxp Gs^CkŚ;mYiP0"YH@s !Pco[x9ldgs-E:cO Td~MCԒ3 J[}P)Ь9W~7%ZrQv"r~>^OQ|@߬!z^i%b؉u;xz\cAQLffd&a^~êM''5zֳN!]ѷʗ"]l2ܑG i::%+nZ N 2jA676v;·t[έ]Q_;.BkQD,h&~\?Zo)hpir01Te:4.p(Rg>Ga)xU~ea| "墌2/QB$y8gyn1Zyx< l븀|\EQwuc.Ԇ2zD}W*co~[6"N}{uky?lw~@tom;&ebp bZ@Z* [g@WJ F-dܓ:Pn -7291lS®p$h@[HZ`ki܏cbDШ{|9's{qyzɱsr%ƥD調s \dxOS]@NCtܪ<&cϻ%K=';r93ESaw83&#'(Y\>%S=-G;"Ђ(6d `/\}E:?Ixd3>A$TOk4;+? 3֒LP]< HO,!-6:cOP5>8$*.FWCł=9aAǮ_;CGs]L}mE(* ك iU WJ?F8з<85>*)N5$)H$QeN%aʡy5)9 V)_<\9At'-YIOfh˝Ե8oA8. |֦,]HtrZf- QSF_)%=EϜl>/G(i_w=F/db@67=BZ2-Щ@al~Șj0t%F#p^ZV\W tTq1Nˋ6.xw8_@ <$08iυ }Dy=e'T$ESrCM% 3==}T(Sm:oams$xMV5BG9%T?ګ-̽ҒyG7%'bX F(2d( JjFw0"ƚn?ݩI<mҾk&|ПtlGic^ZwJS``E)erbMA̬0Cp:phtl8B{ B7I-y6`=y ֩Br].eGT%]:Up~ۨ-MBBǯyf(YHB~vl&覦_>DJ>g_%a/)K>1nSl̔S0h\jwʽgPH4zb8du WNk(>57G7)> oߐHW. MO6.Vb}"m)ظ-FO[4ٖ;y6!8cfjqY1q婯2\wWc/8z2K`t#E fGE7GOY m'DQo + D߰A]*FB54Ltb=xoF3:oq%d\ ӯnhſ̰.ݬm:ǗЂQ]hC_ՍSe M bw'_b!"t4\x.U2uԾ*~q87 c/lEPm\M"<2.4`)~_ /E!ab&0HZڙp]zXCfW0ņ)M#JaF%g4.%1-,:ǏS{یu#̦5?'24 '~^E܉/{SFq4͏=#i\CLb+<I|p 4~H|_6z ,1wLOj 2D)W==/uH*Mjl$Pv&TUNْ4qMŋpkKb{^-7hG#e֊!5q,\M)bє.!$:T5L:=nd) #*om<qz\3@`>ril e`' >Ȇ[4qx+e3cNP\Do;td}J+ 96D&t HX'7Ċ•VhǭYXZ+:*_PkUtD 2Ԩ|1-i6Js#a`RD޼vLAib\&@єVnڤ`eMڦvY"1<6ٔvw jH ]qIL2|> !&8PrFHrCX/"w2_0`ηue wE55mCRJ궐qKvP5|YCȻPcx7E&,U^̈́Cf`- {ψh) ,VƵKjG],Ae̱NaX:ƻ2y݆ xf4qys (Fȥ~Xmq׹.A6y9 cj_8S.uSU C>9Liq}; 7R:/+*Jۦ%qkj~-pC`%Mw8Bi:!q@l+X4l }B&C21+ðEY(I[H`Xb$sp**rcxV@5B~ӈ~Oo̐bqV*+fEB1 D@LWWY0#XllLF%s S:4PܸL8A{HhY &Τ.;\\9b3l:,㝛)*(fB[@8B7D z7fKz5MWKQum)7jRנqtYhi|DBL_^Ctφ옾Jiu.@nyv`K&7p+AuYƥIc,w4YղeVmKpjC2$.7d ~9~ι ?وl, ѳ %BC Z7jV V9ϟv+҈yl"5K^Wy{M3c_ 7P|l)?Hu ٍ@GFOgWPV#$0c{1sMdk{8}329f4C8ξY\qNf $;THclBG%=;VKC[ɜBn֘lo)%RoΟMY1Q􈡶}LPeb}SFFeXΜ`l:4oes3,4E\:@l8lހ+")i@kOB@m$XANPJ Z:c|p]l *w[ !s ].A@kG0u®,7οeN0) i[SQi8(Ӌ]VCgHfBI<_o3"ac|/BH1 IfgU#:B!G6߲a`Uƶ3q⻤{'lFfsBH@Kx;T[T& w׃.'zj/@:6RPrc86VMj[Hxt7kSp k ^,Yezw>Oa&ugWP8hKˁ$q$ \X~ͽGI ;z܄ނ,q`E2dVқ5\Hzo)牙*. O8'{DuqIT M'i^eX:Gž{n?+]T:$3`r!l>72$R6EFܘ<=gIs0KY |D+ZM}߇B(}XgSoV:$UNe  '?k~ FَdкE֟8;_̜-8)Ж,(j<5EH_l?DM@ 'B8Ed_sf0u]gs0V6) ]OO>6y}i| R87`o9!T`ևxT&'=U1 yر &q]d`&ZQ@6 "zn R=2li%Pj;[t`q^7̌G83J].ܰSkCWְVjKd)Ml?A{KEIQY_N;J0R(M?qE:A>T Ϭ4;i~Q؛ީrym/{:fvn [XcW`-z $G` "ij U٨pɋMemN1^D0Q[L&47-4;tV ^ in}*5T,?Iv{V/=56ҥP &k' S kuο>t Ӕw#C;=M!_G\lmqM2{)[]Ȱp5 gh!1E*Ge"Va *6-tüNN*-DTN_}ֲ}:0Q5zW @J+L;[Q)\tvQ"SJ~Xc!!˹DhTիmcU [0ָdwL 幏g 1aj*WN$lj9 zϐZKxn} I5,-A}"̸Jan8XZ0nuDOy3,>D@$ D% Ö>|e^+7& +6Qc6gNa:&:}.*SAKظ)*m#m'j^f!E"w@<'I9"VY71q!ioz< /R5pU5=@:ƌ>[`@1d25i/"ơ9mF ڮwLeihUmA QTM%Z)V:,Ƥ&LD1YpsNTg |ca[j,ճ g>#*a$ l\a1ԌZ*?qJh:$.Q2[߮9K#mh_,Q+Poc\K`\v%ƕP(M~&z 3OXwDrډy$#? v6We)FW"&2БKA;fyR.&||E*j7Lptް,ȼ+'3҈T8Uaሥڈx2+rnDhO )ir_V#}/(}-AT&c|$ΛjkjV /6 fN%8Wx.QP!CF%R&E`" $P /~<TuR*A?!ω2`R =&ȱ\[Y{4["u~1մ:1p Y8Dv۫4F<> VVFDNK=/mujTg`Gz=mujp@/cgMu!Q$]I$I,*q&9ܪu0iNohh im8 03K &?(SWsEU- F.3=ild!J̶8C?毝 Q*]%6 !+sxVQ x. 'KZgx(9 o+煴L+h;0$5x>gO'>xD‰x^ h1$ E`B;Us;i7T]o+:h) )"1*?*YLdX.|'*mt=.b,`DQ[ Wwa]SyD@L&:q- s:} ȉay Ǟʾ7ʺauy}e|Kp L9)VY[oϪ<;I'Gr^snb)W.#[%ݑȷ'`sP6ʀ}8^0`nzOb;*yqU+#'JSU EI6.8;k)#OEɕbZM vA(Dԫ:̿Av̅-Z/78oM5U_2moYVb7 >BBQM8u ]{7o=>b}GHyDY6 ȯ>?Rq(ck7d aeLvjx"\BN|z[yn%\) \El_ /|E3QB&J>R0Ȁ:*ZU^ > E>^8&~fPj:].df{L6xH=21>FT@ڂ=/|_qJ$4h>W\:"S>3tFQ9*[9(=sYꀭ)rk, .]Q#NGih=쒰_{z`W+$#m&"XSbmL#b}2fcA96-H Y2eyZ- `ߛؽ."#V~Q_~>bDAF:ܷ-1Zް2 +el0x/b/6 ,x@pӭX%VԽp@IꍴPVDkB.܅C NZB~x5cU䤋C6+П`z@PCJӹ>ApM9/hYb{5X YHr"ƒe݆e,ls6`ezL+Gk ƈ 18i( !bS,I6jlWn7`W0,!7u R4HƅjFcx\MzDj@EzcyvgU-[z} h egt(c-4oI&!kq(D6g0i=7[P3\_1?`/pdy_"'iaZ`)y⻰jt8Mw.EedDB>91ФLJs'sX.Ma/m93z9aNml3$<̋z'ea^"gQq-:v8'2p}w06U7ql7/^\ v ^UMӫ}t˪tV=B8xVF2ڳb$CiyXt=&S$#ՂmQ^±N)V RVwsr>E~9{qZ>$\agro?)^'+Ӳ;Wf 栔s[2 /UE~)ƹL|f6J0X56M S;FJ]l+*1y;ߘj'1C"崡C.l:Ӂ$\ >9w>cz-Z-GŤ7C1|?bCSǼmD.>s\ק<#=&㱩nZ ys ;wX8.{WkdMK7Z ' Sq 8Q+/ /g tYB[% ;u`oPLcbKu4^r~G/8P[V";ңqch ğb6#iqtf(#wM9=0 FRѯ&=z]Ib! ]H}హ5-b$!Q EE+:1;vDJ`lhGc TGؼ5 }m S^ßodс$/ yfvj5\[*҉ŗ|?p" ,[Mc2tfg2`AW XRqkFgHj_}g9uvr23XƫRޞ{g=Kڸ.xQSx@^yI ^z/ы(%~B6oz(ɂKd%Apd,g+#3&z{pQ7Ң~`8ϊhvu`§WTܼ *,!28&bb 0XkE%/=RG%W֘ˣ  z:!M{->5n{J3`WIsl,EIм6afi>3d9/%>~M.m@+˹STji>nRdCOR۞ń1B+;$^$CmT\V#Yh7+pX{ 2 -u)b{,mڏRNu@ؿz`[aFCF3I+MyBX 'үY8Ap`d,hc?wp{lF+ا,)8=ȣR=|~ K |n`L% Nu?8gz˵ډOe:%%t!MZ{&k/7T; ds\#4ߖ~IBMV jvP4C]5hU0Y(V4',%| R,c:u-L#ڃTX_pxL9tZA]6;O[DmrPgxWۏ*;cețB'h#Ӿ= H FMßm#}/aQ WGlR$VKEGJ)H Α:_XF.y$Ulno RHlL{!ԅCMɻx/:7ކs XrUOjL D Qњ@?6WINeI|⑰J p͜9fP>^LMrLQTՌ:Q⒌\QN #dL;Y2F7h eCME0@YWh󫤗Գ27X,jtzbX[fKs}DzجAejj0CMo'R AơxM4 M F݋a,Y̮VǷHtqjͨFIf#$8I",N_ヮs`-LqpmF#XCDqċyPtk)]l_)(`wdG\hF7: ?0G hѿ'/_(}y| \ɶ 6cBmw'УuITƸM_ϣi&gkwuP4MZLG G0˦`!#+6SI~SJ؈+ ϟw!gdb\Z3BFK %z3٩h' & @1q>-.~=*贺00T ߎ5sLEach̃_o^PbSAG|k޹ч%v~DՋK?e~Y0Dؾs HhrAb;]c~XӐ^"; l':HvXkP)@?,Ks[zcV߯d,Z K " )&!ScD(&V3TJvҢ )򓽙BAxTz̟/`-W )d./uIT0N(h]YQ9%@w#kΈ81mfO3#?Lc,U5MlMX)[/)f N yIݥ<}u`FScQ^Ezfpo\7F3/07ڵs69/B3mh#1)Am9kG/ ᲆ >"jvM39S@*3A!%Jğ]}8ϨOYV )IQ3((qvɃ_W|swZʦKWkFcI[&87V2e&%*O]n,&9:{5P43KII-ðDo'q3R8{uHeݸMz o[ g>|aw[?9\J7N2@-!a!K^FhsH,MpК>KΆ 4A`9Mf(Ha]I,̶M)fuJ<=ARTqܹ!^AbSE&̈ v1̑kުR[N}݀M2"D)xőWΉ𳧚*~"Ez~ +*<~[gp-B6 I喢m3\>Odk7^nzC!`gb;`B_d1óL-Lnh`( 8MOc.@W()@LW $et cohYd=JM]޲[fZ1xd H+Q= Z$O2$nH/;6q4mkGa~Ady)!0.Gm ƴw0Ic*aNj$9f9 ^/ 6!_8uI) +4@v9F`c;s >2v}x7O%|M ^fU4S !*|'Y8K==z6kLC9B"WFqसH'$Dn~ȊhX1_ Cl34z8N29B w5~ +qnE12#WeP|jH1eVmg3h@mC0q e[(u.d2&5k_Ӑw5>~pl`Rt]zjaAd Ѱ5]zt(2&ڌrn(߾Oi2)j;PGQ Eb)Yf'"sK-7ii,T+ Ө WR=?ežl\[!h0_}MYs6St9^pIQC4vn|bƛY V/u0*ܼ'>ТJȠk}n, p'I7!gj-L+d%BY [ғtRѡ"+aѣƶs$ Io78懷fhDB/%឴Ʈe$ 8Pq6_h>+$E&[@A R">i! JB%833܈ѣ8Z98N Yq3m ^a'J,3RxP7#c?{ΦuN{:i|e f S"( 3X&^i闹\ݒK|ƝFs!hI46ĵ,l lS;@ѹei7Hs B粒eInJ `B!#0tT寣rơn,$d jU\*I|Pu-^V4VǤ2a1Y7y i3 w!2q. MuWͶ0Ux[XDF=jHd{] jXK֯,KJpEV-ai{7R?lR //gKYk(.H3ZԂdᜱFO(;> -Q^2\-dOonhBj"BpƛY(W̃I MTI,H8HGNyS3 ,ơC26joΣ@3!WK 빈N{ɄǝF(u{N's2Vȭ_)>z~Qm@},Or<ꋥ!+/1"b$klJ_HJ ?$M=3FGw-9#i0ErexWm$#m)oQ5bY6n <v`sSMN~Q?} l bft1{A_  ?HV1mֵ} 3rp RMMErùf_*}1v?#'J3Zx=Ӎ olz T'W=YvSHv2?.Mw`-ι%ض`\ZP,[4 ܳD%:mĖNFtrX @QWT\}1hkf*OĦ(I9zE_^.dOpܰ(͏hG,]d Y/jJ̎ZrWeX  ,JT-{yC!aS5!AZ1 MV:3f% 'C}Al͍ lQ[}61Y?r/frڴ->m.cz571ZbX>҂2}-H׳Hbܵl-&U* ZY+@"twM`\ <qSp JZt-vƮǸPL mQnAuٓ'7t;xAӛ ;3FP2/۳x"5&846fauolp6CVm/>*iyV l0+ !?^ O`Ms 4%y2=dfK(^⡦" Xd?6FixDa(E7Xk&^΍aj A#!8xELժ&O Bk9V?82|GQAbNM4p !~_CeI`J9hw/:"n2v,Y}JH7$<ޯ\ifWŗ29tZA\ rXEJ( ?͋qx@[xohR qC+)k4G/[li=-\ys=V"0GR'j{[E^1RY`pGPH e4UYp-({w}+WjWD|vVL_{"i/Ԥ$#cð!c\G;#n\ĎMAƒ1=+]YiN.z{KE/Q<$m̲3Uݙ-s![S27h ,}|mGTo$f~r` Dtj! tl^%j{ԗwRG"ف{EmYȥگW{jy,Y[p9W)Lաj!g7yCNوX9~Zϛ}#w1X_ Q0aKm~ehi2"Z~QV>rR ̃2c6 ”%;M/W?ܓwC!y7C!%jnڦ_T1_$C5j LñZH~#Y'vFz[^iaAOċwMG/(IsO6{CE}m&]\6&F䧌WkRn?8N+e:dhD>[m5ªoغxCv~_9|$.xƷ廭~]z"{+,5̵y"Ģ yuzjkOho茮AG *SNunP `Pj4cXkYܻHɌ2 ֦R !dİ`heyQ+$' FIMIEe6#w,m(?kW;۳j {s?1>HJwʴ t)Xy63άUvg_|58SN6XYߐ@?KT&JgRT ЊLᝫd]{)~˥Obǣ/8犀~SY0:k}s}7]&"0ǫe4 6(pxG:F> f:aFBN1ML ze=?,{XHMk|)iYEFuQB: 'b-=i!S"w~B57`R8 5@6(Mj'^Ğ#% < UVGJ|ޣgFGU,5o.H8mڝcbD.sm||3$u:њI(,:TF52JWa89MT٣>WmQwjRF"VAfE?^%Aݠٵ}#BhNBFk),lUIjlT/ޮQ̸gXƿڅ'J1@vIڤQ#D{9PȨo?a0Q`^Il2S*Ld lcDDpֲ;k:{H`#%ZjHkKdY<1Ke+vdc cE F6M%;˯-YJ[W.*DY\48!s>F Gn=sLYec8_L4K8C&Ml{3fPwE-MWN=TXT νĞLGZ== ~&N㜧_%"̛dz̹%v,uW!P"ŗ~!X솶VQC>pw־oF|6Yb:0r8l?[`y(k3/LҮ )ә_{rxN GI:d2vHアX%6m=hxMr8"W%Rň'de4Km<*FIPz, (3Μnp#Q\ܸTx{n7?@ }0QB`uu8ήȑJljQgER"XGd |  (eV\>x*o8:R ._ZS'lFeBvJ F]v0]x%n=Oy %%e 8d&ngmp?T1}&r 5Љ9I.xZKbӠ/0՚fq81CG%EW5r5}T{-%|&'xtL-[,yRn[na`Xl.+}X[ ߺruԫug*S&*obrho?.q8U$k#Ec2F1k5" 5BksLs"~w>:=4ZkV6e)J5*!Hh嵙lӍR  M)57;2h~{^+􂏫F`yp Z5ւ15$ ]1b5 FIږ;<9Hbl7LZY|-Km`Lϱ(_?R(;?>yIU]`AUyl~{7}ǧ hشS[A+wq 8G^&0HEO,ιX}Zi_A,˒bb5myT(MF-)9UuPOuCgtBLH/YlH*03ۗJߣ-{X5%6Ou!?g߱?t5CAXG|o$MgcP$iO2s "~?l .nT 3KiP9˜Z;Gפg5iS4s`3:WI]I6H0Z_ŏA&VmSRˬ6գg  ѷ0<+6Ȗ #k<2%z<@/#j1=w>ΒԠC[I/FX"1d8&IOۘ .:6E@+I~&*IUTlU}]?WdIZ R ^ޗu5(̸kV/1\с`]ޥE g)?J%5L68 \ 1*&Ռt,9sWSN'3VNF'&R1z-b)sg@'4gO{Մt1?t}̓]JCR/j%6,q_ (8'>I:]XFK/Ҹ'p!y]x?ItdRUw} kvky".^t5 z̪Ak%V`NZCM}&׆k47zZ6$¡VPw=u#&CY`Rpo炢E2먾>j'l􏒩xH`.G>^E+H1m^f :Y'oI)8,֘h&+x:Z|sʓ#z0L %zQtA0f, s0yeD񦺾{y鯗aѺ7vq ! k9ITƗE1biGq89j@#u&A(o NW1 WRd@-G`g>k 397!2pYe㭾}5V /YgnC5+Llc,Zlp9 $vK ,Cm/#2leeKB]&!)?VlU?EF_dTƵl{ʻ"CN-IƗ0yKqhǩ+'i Zɕ6FRT;É&Bw.\F3_ !@ԬDŇJEPIaUQKWJS"d[ִ/o %kAf\yJdtEȳURoJx<φ0HϐWDd3 sd3"fD' Gգ JζuXY giSK`֬3o `V Ƴya,p!zl TB .i"I81Gb~ EQx4{[Z>f,5T4|CK!]y$ TyS^!8P#i? LS]D'bLlb ْ/xoٚ _+Ρq SgjF!FT s_#U G[nE-:g56&mmE:\YF44+|ķ=bfWih haVFQzR 9$otW+#ia1ơ}ct{:̖XwQVڷݭ,Օ)VjSB{hn 0 ,fe7QWfS Ϟ٣QJma9'ab?bO▕<ٲrZ.Ta+PHB-_6<X剀;T;-OmQ-H=wABhowf>N?˹MjqLG.[3춚>wpq%:?oiԠϸh$YooMDJ&<+Ӥzy\r9|Y$FXm3U#'F%&UW[L0q0PTQ%S}!Űu0Q 0ttL̛E@!Uu[6eZZ yE*_Hi3(ZM#%Ub E:<*&2㑾X|n?,E&[B孺6%? -ᒻi3sGt2?<,Y7x9ckTD" hGuEB#Rc4mf;g.V}z>JPL(B\i`9esFZ?1j?l/HvFL90fya2gI,pղ;L VV_P7 g }/Q'EYbM)%H Xhw'IL6Y ]7!w"8 `Dp™QH <qA@cw}-'B)_dlRefi@K*i3A8Kl@>^s)CND72CE)!f%n_bݤo<ȄMs~C$7K*A3Vcz.1o n}^Yr.9賩͠)D(Ek޻D84zr0wa=en9^~r}?^޲5n a#ycstmSz BQODĈC o̪tθR$ G:SiNF4f$xςIa1%[1Yjuܕ)SUdDeP 2{fVA*-cJ7 ]O_w{K  aNy=>ept]Oڣ˸ PPz|E 8[$M>BΡ2}vƅ@܄PRoTgnd:Zq" (Wz~ĴnUBb`j.!I*KYF; "'ٍ7k@n|m/3iB$' o'6!: E S=e46Ke^ "1(::MF]CDu QhWB,N#|Cz$?J5i-ެ,`iߋsZ2Չvk&n<@VNbY5v)5}i~P41%8̒؝lPkP qyp#2rV.Z Խ‰EZelE5A|/UeEcG3Rc5sO$M@ۧ\Zd)x\`1Dc(h.$g:- [Ĕ;\_^%=m窨_d(݇ܓѩ@ܺ\gy\.a`ZbF sLz6Ê1ZTMDU?#07+!:r0 }gʳs92a]JIC+M㬫}=qZTLɂ][m/aK&mʓC^%J66/RtU:=ۀ?GrraDz |UrA͈SzJ4*+;l ㉢PS_nFrRvrT0Ҭ{2wh&D^Qΐdv.eqfieH(HGo8ۥ~\O,E2^܁|xyvqK0h)kj%1ױdZ6k-3a WrTdݗ5v< d 栰YaL6qx8A? }RF-TIX(N$'3sm@kHX]ŕ߆:Q0cp|3AnuoXO{xg\yWxE/-ּ/Jv1"ܢr VKAdȂ|J$UB>51"z֦Q S쩖XT#r*Q\+^P!HT JaaJOy;vx7.N+`bEeVEh,rHOkS8ipRao}NS$+&yDIVt}}4g.d(6P `C5UBqW A}z G| i&u-y2BpH:9K<꜇w14-$S\udQNX7hNOC>'Ha>Y6%ΐ5" (.NTvX|,-Eɻ^+F;Ǫ xx>Suh5e_ԠC6Vn"*̧[_|H~Jr^5?Mꦝz.&[UT0g,mԱQ |'-IEJcn+vcS7)YKsJzwTng"z1Ru򝺫(xXADk? Jוz"6-1;׊2B-[#P2S_ mJhlһOd]%7zo0~i鰈qO(_/\0X+4^M; $}|0#WJi yCTMD_!~@mOPYmSZ&ޛqIO06wB. "z"oHZ{1FsDXق>I䒧e0̨ 9LUj{sWA >k[.Km'tHu{vey:ZݹS~4=sV7vJͱ,lᆠrFoP1|+[>dfeŭo]KQ :l]H-,G-KM8E_AH9[h`JTR+i#AVrO>2;LL S s@ՅO\VXLYF^HN In '[z,@Yp B=#w<[Nϙ?8G"F;ʈiRQ]ch@%ȇd#8(Mm>UcfXA~ebυ8Mi.&qs*uhnv'|S7'ꈔ֡X ׭|i2{cBPlfJr}3XD-H-,%iC.9:eD,v*S?2)hEϮTL+'ZJP> d{-{+^iK8f +^^_xnL%gz>1gqrf~D"/WZu&LQKlJ:o> Bñ.0ѥe+u}iш;sL)%t!4I֧19vbl6sdAbMgAZ=MˬJ@|^%9~.vp"AW 5b?O3fKd5wN;*6 1=MPgB`ܪ%@V ( ϛUsgՍ1[H=^{'',np]-U:dpzW)ώ/5Y i5r[E8oHPu^L/`7dw\`N!#eqvet^(de=e8ʔPhQwi鄈s3N6.yb@9tJuΕ8rNaJRh̤ɳ{dx_8#UbZ~d*hXY1WygE4jweM30 +ssnۖ6Qe<ҬkjU !: 0XY]F:Xega^#F !>R~ZL-RS.̌~ RR=חD4e,lANN͓~HPkeh3a 1bFmǺ \R4𼪃&DF@!`c!Ş `TnKDYI^>UXӿq>Us.#=Dt/,Sy&kb֊7'%(L>FĢ>QK;U" 454S(&V ~Fdb\fHnb5zr"mJy/ I/Sev~I:'ʫM}s|ƌ(KqQsbح)LS'icl10pQhRcC.w"1}fG`*wWU17k[d@mV$9@-яBY?"8N]x K;DWbbw;U;y \:7 s"sgD(:I]4znD Ὶ+gy^2D?zћ?߬FTιuROu&@w@,TEOyրD쏽}YPͼ^#oƂn4sL8(ξR2SD$Q5,laC(ԾSqp|&_ktKIDOйx,巅W61}ҙrؠҿתDf>f4QlP j 7/i15{Eag / u*XdY?0/ pEmg\~CڃȱU^P=PD(+M矤b/ weo{WF.pյ㞯rHߴƖKp7u{KI/3YY1R%.0 35E m\Ȅg64B4z\ q 8sQ 6NHDRLظ*+nh-־4-ȪAM8.y\)&yՆ ;^'(f&&:EDhU^FŘ cF TcbٮBWq7/ NC(#/"UgѮ픝 S2vmnxmȢ6.h궅CUZYyz,#@H}RmYbH"(~YD Й/s0/Åe?u+먊z >%KFVhƨ$:2}Y*jؖ&J~DaPNJ]c30s =ny &X^8g\{B$XQ4<̂s x0Ց:M_S<:엀[KpydEQS\A1;Xr_)_4 L"4zg--2n{J )Mqx}{y)2J{ <{}/U8Pl!"7Ϧ)wYwٶFxbq:N}녘{-FP_Z%Qf=ykfφ'3OwH+9ݞKݞ8WR6h]Ɂ3k~kÙ7 Q* 2ˤ3WF#)':iN?٦HKC*&)MG1IMG4'T|7D#)7Z6Oi񦻮0ElM8xС!46Wf.T_p\KJ-|Q2mj29K:+ڰ{5i Z~1Xh4׶.>88X3\{?ÂShĶiE6BVRj{<'VVA705 M ,Qn2.!cF5YƬ*yX^cxaL&n9P'?92}q/ Sw,oq׼ho8FLT0o1]%э0`eKKpMI;VA7gg[~gL6ιZJtM ְ|ҟ,ub <%cGqK^6SOM^KqxMDDmHo3 *Nwb:d6RH/n 56I p *Υ43ߝ>$Ku|{ ڜI#iKaܜXn}}63J U*g2ňxsXC1f?!jay!e W] YZ