sssd-ipa-1.14.0-43.el7_3.11$>`CXƫBt>=?d   ; "@FM    4 { $XLL 3L   ( 89:e=yGyHyIyXyYy\z ]z(^zb{d{e{f{l{t{u|v|0w~tx~y~RCsssd-ipa1.14.043.el7_3.11The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.X~oc1bm.rdu2.centos.org 'zCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKNiA큤AX~oX~oX~oW~X~oX~oX~o4790c7240978db7ebb45b068e719667bc94b918d094d5ee626879a48d3302a0b8282b239202907b347a9a1cc7942ee0a915370f8a25808a40b00dc106fd4dbb28ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903db7ef65c8a57396cc08f8d7b4c82b8de9d7c53397c64cbf120dca001f5198c1cdffdd465621582b79904ea7e77cb96c37396b8d9efff43c35a6cebeab63bce87rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.11.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.113.0.4-14.6.0-14.0-11.14.0-43.el7_3.111.14.0-43.el7_3.111.14.0-43.el7_3.115.2-1sssd1.10.0-8.beta24.11.3XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.111.14.0-43.el7_3.11libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8331f40a84070971d9978cd680a24ba3ac5957aa, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6(]"k%w+p}|,p35muذHZc֧Ĉ`VHaaWXZmZNKLE; i?u)]A&r(1y0+G$ϱ7.-nP]sw%ڟSXrvq]w۬ƍY/Di>WfՒy`'E_]_[Dwb[K%mV6G-,8xM@3bpVi3rIH4ovvE[= QAoʇ 7l&#FvJI$k(I|7^؟$T4(␼NgRADLa%1,Wg:C7+^*_imED  )߳$d 3!hԸyA2OD\7nz|"x$XWoeh=%},<4̍l0oqv Ns`ȝ2 }yH<=Pgq3FHO,WMbyNN%g{M~2+l;=# ٍjov>&̀[6dƭ;xr#¬'ҘP۔31)30tt'C򖚷!h铉rn͌,6vnIO3{.1SC~kpq&;d? /؎"%N{<ݎk}6A/(&sȡb)H 3)dW|s hQEt\zNQYD_ _K{'lu ^ ؈J:>PoRldcya)&lY>x<-Ora8J_u?hEqk g P !t *>QK I3~ɌG*>[ DtP*3~2#$KZW-ȡN+ߑaHzu Z$zwAԄF했-"й-jOo"} ?ȨgL4G¿n:vQ;bJV2e筞{A%Jvbh~8y5Wzt0c c~a{GmńG~d!ьܶ&Q?л^M0x/"R:WdjwN>0ps~"`DqJµرl*AIѾߣCd_mtj=$׻k9@Tfd35/LnL \{[(T'7t.Ns 0mVB9_7YjVIs;Z1D|ݝ9jMJN+eꢭO{ƹ SPw?&_u; :4S.T/'GGNI1Su\(fw*SUJ9\j)UW d'ԧğA&*i\+e<گ?HFu/<"hJpH$Oo&{dLo(dǍv mI`׀rJر:l l aX};n>g'.ZZ^GkA*=/]溵FP!QȢ>3ȋCO~Br?<'9FJh4 2j}K*eJCK}p2zLLR4Vlo@ Ӽ& KxU9bBW}#P?u_Co0Al}T5ϧ;S0:}sIr]xlCއT-:鞅` f=+͔w~wym!6 ̏kՒ'dԋ`ZP64>{j՟)&R~&k7\-hT8ZCJ(fy+ d#'Ѡ3ɤ}eu"T(8ph&'T+8NE(Lx=8sEJV&p<|!?aX 6%C=RרY]p]{pYG16=Cz9u+´kذOQ :8 bE gB4:8}zb #Qo L>qҲ!?vp31Ra&;G$qSY h %t&`Y BPP?VX?Iz8|6?l`qp3zBuX q7xGc~㸅v.l~3heh?!mSe`6׫5ٛ iґ (# 9wev:{- s@&QQ.]doa4iT'k3B*S=_;LweKY^m]kw yŎÝZ☒ /sdP"kEFOPJJq.;D_ 9"4bEu Pܙ4:3q ۅJKC9eDav4F;%Y?r5teB.\2S<i&C#!ս8pt!t' dv[^ <<1{.ӜVPOr9r#\_g@ncrf2)Auj*ئ~M6^Mja(&r_@Zܨ ,$0w"QjE<# */'+jnd| [j&c #?BjLJKa0ˎU$_}/u %\@}ȏ}\XYTr G#ys4W "l}IJ_]ǫ D -Ngr_Ƚ}eIRixE@]fkY@5똅S罳7%I.zs sxz> ʖ l A X$ioS;6Ne#"2JE. ˱)+r=clkGz`cJCk)1K<ݵxjS=}94tY uUb5'6&;HL7.<<8!Zr`*Z{H~ 1%(rmGk/3) E7,~1&.|2)_G#ORT] (JY75PHɥf Z5 $-wNjn.]^;}<݋l]ܨ{ 0wȪjN8}z-f2몯 {U:'.T8 Vh5ڃ.FOmm]1^=TQ(QđDDh  L@Z)Vj>A`Daz7吽G(l1!8=IDީʯ-XtLۅVwv>O2̷UC252>hqY\l6'p x%b3X,7Q.1,M(ү&y&9~.IElAƾ {\4_cgEFoRǹ5N 5O0~q&;Wm} x%^.:(7B3~QwƼG}?RnJ781_Ys [* 6 g9 [H(D9k< =4 mOUQȪ$;i8pzɸ х,T{n&4VJipD!oOl<" Hln9%GŽ QUPOeRA8b?A42R]KX)AdMலb8AD{iv p Z"yuS_Jjjf@{dy[ 5隻B(Wn { OkpR5`Do?qBlQ4 p"ø/'@;j?^pɂh`jS%{qn\ERCOƻkF>*LZRrA/v8m B0&aeW"ޖ ZnfRYYz6jbdʒ~KI'7p n5uy"mIRBD ]%QARVH1 + ̐kVuB~(#W:*_>+_v ?'Q2}Uc܃eh7KVg+yf|-_ pxIum}r *pbG.GJwPll%_ڵ8RJ#2Wb}"} {b>ՙ ửf4B\!Ӹ@SvDDR< w Po#ZeK d\`cg_՞<«:: i2_7!7ݤop6G&+rG$PP/Gϐə/` _`(6 -\.H@U &]9e7?IPeYӠti$rɟNҀ:VGwV@t먐 C;M]|Aύh'xJqZ:OA1f"+K)2`C8YKNEa{*^=wk;?Aa_y% М6+ګ(U.%30q^㖼4YL" ګ{Yh٦ 0;:O [lA]l<\hM5XA۠l:SY@|!%yLN2#z@CErˍ>g)eXqAy33E!ףj㲆Hn#T /Ƥtu]Qݝe\I h6P$ ݉(];iUnN]qh|LQM*D;K yݴ_5"Tqlx?;# [Pb׏' x ?a) xMgZK`&߷Yx87նhG2P?# ^F].c]:@i!¾a([vO4$tJtZ=ʶ,yha{ބ"=8aȼcO)9xvo/p6a~Q]dM٥j-|XX;[fBkdf)SHaww/ jv.%g{3U9}7/D$3 wdӍ?EZA.bOTO` *3$} pGdX |c=Z>Z Q\CS6PṟlSh*yi$]3P.[{/ؽַ:LmvXtTrёU t;> a.dMO>Zb9*5//sXFD@4%H k˖mFN<{%i,@ }Nx/Nd4sJquš[ ѳq-[(A4qc:늿űVty"XWEYԹR xMWGT-1F'[n@kg"0!їXni|RC?]W6GY+!/`| O(TG9}7OOݦUo6կ_@!M-N]0rmETJ#w )\ NEVuG.ڻtkФd3'䲃6XP8ȫKvGŚ{V>I'>^zf֒#*w[2|S w%O1ɒ=Fu3?uX$v gr.= @ Ip£39Zܞ>;bexW2EEH&3:si\{UM9.5H̰^ qvt ώ/s:3c+HRld9_J\?){> GF% 7fMPğ.=T_DhzZ=!eN5o|xx0^=^oWfӍRSTU}}ZtUgԧn& #$Qݕ1ꡫE@NDk\p~{ɢ6bz5VEe[uxs6t![yL=QmpvՇq6.oMcy ]"ъ6D' S-g탰ZxnBJWOI/e}[]j4̗Q~Ld MFx26n =QDmwc<ǚJg D|sbQvʓ4oXK nn+I\u[Cs WºBYiβ=gڷ /DoRG2$3U_*}ʆ@>y>Rdbd`PV}4F:Uy/be7l"u g_(l|tЦjw:Q|Cx㴝 2Ob|`֞{e]Щ1qؘZ|S '罊q9jGWCOJ+Lj:5a9"a_wwW)aӷ6)܅&[;>YلR*~?hҀțuFhi#b]";KeHh9yX 鈭Q6,%Lϵa W^2&=VKW_ ld%F~XqE&Oc8+ o}'2fԙQLZq>B K3 EwiR5t?ŴA/ϿL&?gյ%o.@_v,U *[EzE>L˽_DDF G81_4-EM_#4D^ZfcbWUB/}3`E)%Yb7Fy1&nȢc1^75ȢY?u wV|i9* 9 h:+s*TfVztv )jlMpԤRO1cFq{FLi(lńSLFFl+y"rc(ڴ.kd6Ђ_8Q. Re&{V H{@gl!;ƙj1FbAb#ͫ*}]M^RpۇkB1tr21"[WƝ`q긇5%;pGG;9Y h iB4mOy96nQcjp$X$ˡPmv/Us~(! 4Gd=Bz t0`"KGpעx٭Ьasy"7ӛ*b9#aSb7 )`q hw*ZwuMv碼 ~̿|jVP0miUa/خ1O8Qwcioq h\n,;@|qyGJéY2 7 h%zU^יx"M8Ali417L9+L+ Hz}!vHxlZ tNgi&2c ğ;4_8F>We<'_Q6U${VبOd w")aǎ.F2 VTBAEUIKENOGc쉣.OstFK9T)g2a/ZeUh8)0x,XTP$3pmuD`结PQ2C2%ih<.'W_U fW( 1sx=ҍ6\ϩ}er>'yX :1`C)e- #eC(iu̦5rD;4."!e&톘&" ᧆ V™Qc@tt6ͭcwzPrt5p7TXLnH\tC͕rSO{jWd@$"4Rqꘛiv>5pπav=3<2'CE%haV.ل~ә`i(%Lǥ2+N9Kå ?'+aKAb;'ѻA@ Vui^A^<{p8YQMB8lܥpM%>X6 m3rOOޅm7.]J ;Th`Fwҕ7>wGգ7iw"iڈ)p}4 e# +)\O& o 8"oH:vYȣ(D29;o9#řq)EMt8B,r4$fyeT0NzXov! ߒnt|ψ]#Ê2V. _mCap~cryZ^CbO3)i8eQ%b(*o2Uhfy:2I/Ÿ!$u4VQ/x_Ken /s2; >_Q7-,zeH'^u¯7A҃KpvFr?tdձ= Pͧ43[=ieU:4٢&һbzBJ6n5XC_5K#Gy^L[4?jbGWl1a:CX t.̗J]BōL {;#,7d5Re NsWB*G(P6c}٫ R/p>t#|}dF4bC7W`fSJ[¹6s ;PZ.Y Y'#*GW@(鎕zzxu9+Ztuתm$%dwVxˆ|J\5}v-#G!U1{[Q H_ϣq 0AZu~sX~I9Ɣ"hbށa{*-_#vF*piG \ '? 3 7Hi ?9vƇ-g5]™uhYkNߜ&O!9)_?=h_ iKno) RǎLŰߊ $a)q׈a%9uJۼ1 +U:[ٟۡrc->G:&k=-RQ,&['Tne TN[[+p2L(9&]:8R6o3&F5Z\#j/gdى  Gz"`Զ:VJ F9| oo{ QO>_ҎT1O'/XPY33Mh Dbb^"s)BE[Urܻ5Ұ!"4`?=8ҽ7Itp?J, n$ x0u=#[!+A/թH|Oq)TiYK }Dk<;J!^$Y}_#0C$1Ŗ?Q%[Q%{Y&~@Xp h k$㲽Ta}MQDW?F7 :^D wCKՑ<;'T=8Zf(ڢM7w]~.TQ6ç{23ɲʏBi=.s!{E9* aWkq8e30/^#I]mgr1g>h3en$LVZ:0%K]YղU\ WƖC>IBơ+su3N*YUJBD eDHL E={ (ݞL ,5jՀ,] ؽ4ݪmu ZK~w prgֺLT& ʹE/zܦy˻ :URd&%ʰR3IW՞S)XܘnB"EsC\=fL'a5R,TH̦ie[ܱUTTK*2F{/:.nrUM 98YEIXꦲwE#&s,8'$:rP^8*JxCғ.ۄ(ꇐ=5oy#{Ii*M[-NzZ+"i#AS @/~XQ %xSpf髜Mjf2 'eurXC۶pUP(pP՟MKPiRS=߰Ƭ.bP,:c$g4?qVCkVtMaHjRݩW$i}!Q:,* D4l@Nbr7G=FXCLAfu*؄f@aV.xz *~KFR*7ǨwEJyx|^̖Op߻vO i Xs#+8Z ]STt"J;orvO֪5Y!Y̆4Oy(T#օG2lCu+JVXl c;bT^SD r cEnzRDx;R'żIJ!˚-6 ν+gB\CdIEHq(B-GL[tb^Y+ V .)J̓\jtZ?2XͿZs$g )bu8s~#nk4.$^_p;v4(Slh%/:Il %?Rv#K|_G\%+Q_:`=̛&X`2SR)NkO|Vp}x"!Ff̍?xCemA_rp0](^׳At_/LM^Hwäkͦp Yv5Oʘӧ3'xexUƐ0 QߙxLԻ+X B&Iq4 ˵zf \ȹb,ҥVise8'l$t kǰuy}wd:#d氶^AO7fpGxqa*XײcV?K9(`叕/ HmbFxgU}7fSW0~ЯIMc\WobfsJ+SdkHN+uhh@}| ޜe0d_nP_}䛕ݙ3+,oc>S:Ŝ]!qcIlߨ]:ld5Γx`8 ȱ *py7džnD+#s^zd8˜913՘/UxH㰿)hm~A`..ZL[7e`z&n䨏 MVn'e1w< $D  1o~lNYnq\s`CvzCK "<|HUcRS6YQΛ4vh[EF|go8fJ).߳U:8ѹ w_eoa[X \]L`@%ķO CdBonNfbPB'djJhsa]3 HU9w2  t˟,\f(} V[.Clˇ\Vp06egc=.$N7ek6Qj[ObMxf j {|}#nh% 0 hux_jul+ j<ֵk+heyJ&=1vPbFb"-g^h!ρ?+M-K ՗fKփHG>?oCŢiI'.+1֍G.՝ Nfein4q}쮽 K)pk/S4-^}?QAh}l&DǻnAHn؛CM%L(sKh/L MӍfdro0y*LB GUtKuwT,jɀiX7ۓ+ 35EPo|N:1 `:<E33v'YwQ@ =0,O_@jn.Q-*D\,7{|zeOUb_(K Z7nl[0ʛ|L#*7ۍK66['I;!%g>_UF3\2>V0`ϓقouu/?3ExopTK.J#awXm@B9H4FK1nI{H nsu2a׹{kKSToR)؈a:UNoē ]`嘏ǯ4xxi Ţ <z9>4H>=ַM|N>za~a{W@]|+h\l,""u}v.9A}d`mTx02Z$tfx jХHQdɃ4U$0Ίbv Rr&Y٣/_*(\I[:^1I]>8֕qYpQCY 8NC|4ّx N`2EZP~#F%n[me=܆#kuOiwlڥ ^o\(ِhvԝ@Q쀍_8>b3ГiݶKtFu&+V]!6Oc$-Qޓ8C^\a$XZ5޷AV|HIѺ.#Py?Y6'eΑvgO}|maV{,ziaq"zW:"k[m .'%)62*9['Me_FBrhap^gZsEg'}5-p>'i}.αl(Bަp*+O08ǍwErƐv2hh 03]|iId0" d̨ݰݢz4ܻHo'Nx(n ںc[;lxwSѬIg`ºQԓ#Aw5U@n/F6((a\th:U77-1N*%5_Ķc`u=-Swړ\)dz&ET j"ȶO"mxgG6GB%֮Atk7bl!@&0gi AV`̩V! n`/$jxi`"U:9wjۮ*D%(MYVOsKFSIs3N|t/K_JJF<ɱn{_o4SUdM뻞HY~~$9,|wf\A79h$1 :!q*_U!zoD+G b{Fѝ+!LD4u2eJńcrb_$}j"JIm&FKCVB  ?wƃb+o>_¤%J"Y w6RNU B ه"Ѷ_q h==% ~d؄6U.҉_m4GvGmOPBOO]%:1Yo, }Hw$~RSEXQϞ8I30EuD{ƥD%e'=Bc.k"F[k<f"]\U-Q㚆u܌*PA%32?6)z#S zX[ޢOS)1y4B3DmI;bS("9}~;qukVr) lqZ.JA)˘ ncu!,4tCҞtN iɹ9Cؑ_E~Q 2PޟL/U {ab#/`BFF王4A{;TRP<'nSV޹ȍ')Ꭷ /auioz]?Y/ U}zx\|JafUgo NK&TcMD! 3X\̱Bn?¶ݮʍ*k4L f|*ÌVá=M{FIWH nmvp^u]!ڹT;Lt_0@d]柍=H:10)5$yXuт72 &N9~략nIB]#f38 }3&*PyX0g `肷ҥ9e&B-!a1MB q˫VV24G9 iGٟ Y6RS!Q«,#SA߉T;0KOЂ8,䎩)`Gш@xPzʼc96.}ET!~xٚ\n˚~iYh/r-rc$eOռ0DC 79  UòD8gr<ffWs)z+?dǂ $0tbjhСo'LR_8:째b/7߫%6T}̫^޾Ё5oq]uXӅH~@\EcW^_G I_x!R  L+p4ٯw MQ2d`ˠ E[_VL&Vsףb+]CSJf=̞1|W!BSF|E82-S8R-vN_@y&L=Ի J2+k{* >AhB<)Z>YtB-> }G=('1ͅwz?͕dxyEb@VĹl_Q؜,B6a7\3w)OZ"J2X1@'JyӜkR~:} k/t^^L%GĈ"{]͹PgT쭺[A⍰5ʳ hp? ozh9E DF&{U_z޳4u^aEGYIN)]O'ft:['9Q&L A5VrA;ƅhq 3#c]'yT>S}x܀VL+ZLK!h(R',ʟ783Js/;5MkxݑN9v"/U X\!SAy@BǸq?Y>g n_Pjf2FHÊd|ֻln:96tZY>%A6VRy$KsUa>Ѱ2L |XKp%nco"Ea:ѵ%l9$A/ քh,\a(!Lbx7-G݆n}kI2ir @Y1E0Cca7KB-7ÂHQN= 8Tw5V4}(Td4em犪&_X+1Dc١p8XMn5c1&`TX1΂RV .|moYvt:ռ-gѕW^uN5+*fk*qsc 7zUe;cA$LǛΰsOD@L܂\2z;:;(%=!cޫ;MpD@B݈mٽ/s:JV6݇<=$ G9S ֕YIsU؜ݫ1_<ʵ;Ba$*F>8+N#\)wZHِ?Ҁ¡:x1Pn+}-,5Q%nQATxHxN㝋˫uрB[q78_)!ad2YDQD%֓sɏhp` >E-^ <=ZI-j/1k[LcƗfX 1]שhGΉuATFhVdo0ʮ쮳kIL zaBL) MjAGqCh;+^]O)ט@([ڻ'9䐉|k)4IpP~/gUGb13e7O%pW+ƋXL4?ٚĜ<]C>NXԽO;Ό-?Jnn eىJuoÀXBd354΀ Υpv{L +ϏH%U:VnNRV v'TJ@ 1#|5W'\>7tݺ|($r jRM"m %ן(^WNw; 6$FmsoK RX9p5E(W Gv!o6M8dPkʌl:dLa+м`@tn(rYGQKst{ޚqx9tZ Pts Ѳ-NU|jkr?H( O|N<*f^jU[fM&+rOc)vC3v!p.Q!$9I%_{uj4EdosgA|X@Q L kDB]$22Zl 58u!zeAѬ|WWlMSӓygc]xlj --tǣ4oj橈Rip+4C z+58TW 14OnQC+PebɮWn7ߣKEߴtHyhӌqޭϹ[G^MүENn>?!`!]ѐ-O6j;B&FDnJiw5ID71ʫbto URkS@%֖}Q M\`Su8ldžφ(%9(g O?rPG\{Wp찺7YC%͎:OVZ/Ag}2x8bea~:\S1.5I٩V9Kl:pj\}A˵`8sJy8_NҐ.s|\04=8PxʯjQ"zdH'ɆM7.+< r햇}=FwGr'ݰ7w[)ˈ5P_J^xԭSgԸϒpMMIJGoqKD".@40uNɈ-9~]㱰~=]V*j.e΄jV7c~8.eIZ.c`GBx{@s8ttȗrOPvTEڟDzv lMMo'CxֱלJo(+ɐ33q{k3[f>o9iM~!ԋ>3 xԤ~FeeVYLl"3?/P]ܿ_lT ?o=5~i t9rPFfbZp}i ϓ,Dw/C (MbGKiVu;D~i_A"Ur0MT&b*4KYc TX\L߶l: Bhݹ\wLoS.1ctD&nq,U'[9 Í[}>_+͔énUJ89x_^%m0Tؿa ){y^OzBZ1%΅IM)Ǟe􈀧ꆸ(9rnd3d9 >j촿"sQH (E F%?q#t&w>8@cr{{tVgEsӗ@;!B`_ƈ/at<" 䈊)75 4)X!x=ddZM/어zi.KHؓL ѶS28 L*%UM,j`n0J҄Eec'~"']ӏ:ӹi]JnєfpIZ7#&m ެQdܯPaDWItčw³= }rJcxH!yxw nqcƢbLښԚ9;r2մ, .}-_vk+ ?i%U&6--1R2dD Lmq:#a/v" qqjΥ@N7u~W?\q]&t%ϺbuѨJj4'YBY)vrƦa,n@ӥVI̲MUeVxP̾TM vN)OVngZ`C55k$N:vHӕ9ӱ)kGg̡:y磌-M7N=˳Q.mw-_bN24Jr&ϫzt_و,(sI)v]"ZpaߠUê[tZ2pH[ubgeL[+O3]I4^]ּul$6"d|QZ`q8^f@D}6.D .NKV0V_N[Lߞvj:mGOk&U)׃>fJe[o=/W[B wY9N҆SX{vԦ >>'BZy_tt93+%zϘ?dq7E3?{T.=[8a&o9+:_ý'Еk^D zĀcq̾iLڶ]s$r܉|)*]nxZЁyFUڲ7u`o^r.i}"#/5J)&@K ? Cs#s8agK &eV_-edƥVqX (a@#H{^?g,,%\;ОSaTi6w)v))x#[6D%|\$}j/0[Q5v&؂9fmItI.6_`q!uySS;Wy쮓\ #ֿ_qKZ)NYi2f׏GGr}kxT^U")-{F=!Rg.ooK#Pw+M"UA; 3"ZYvv\rGBarvQA'FH!ږǜњ{GtyghCQi}]T \ Vi9 )=a7*aQӎ$e \6S"JI;} 4ך3qhX1۲ub 5b czwVԖ۷@4-H'fQKL vG".R&KUXNGqCx6͢Ud1]6ƝtC ȵ*o,F=j`w9PCf%X=%8A`hPo,1[Ze@JKn ǐ,ܾGܯ%kKբT0*lx=SS]bqZVӥ)`?\FeO;qk!>6nW@z/urT=5a/y"H]|H}%F-~,bUTA8[wpg}Ls-IܜhkzxWNWaPb[MD2;EKRBa=S7cT$!D׺oW!<[0;e ԖD"z*c&`U= ʪ5Ev{T/~HSKhP%.;LqFXl/Tp*J6)d}5{A9EMjȷKM'%bM>@62OIp1\Ie$1YQGBs5,>4݉ڰ^ޮ(=a]lx4C4(&(w߃`W{0*bK!r.SYՆ ">?byanz/e 2f?Wt^2щCy7fqZ0\C) tPKԈwtȵ 撨OG._wbK} ҡߒ&Ip3>B̖HC &?gRh (')zۦTR`8I(dB3TnA%]fFxewe>kH:dQ13@A9SU$)3kM?$r-6{nv3VU rHMi#079Z/̠`3Θ}RzMS8Ƭ? :HD#y.X@L)vģV';]hO&jK]-cSxѠ/},t!+~>ɰ48Sx:ǦgV /" ~̃>~`粂]atJ'NVL@.n25IdJ2& o@/VS_Dm*d%1K v+/!e  wSB'X\ȿl1Lv[ !A^ )Go\RK!m>xә8ߒ{}^ ]葥8\b=څd-.TIkJJ hu1P'6j0;/ 8X]k4Z=!ؠsq_&urcޅJ1XW;9Pp3Q0-hFb\ KPۦ+׵wZ{_ I8L4~%5%/$dV96+ Ihq(C HUDk̟mC8I_AЫ3``)8`X|Ct"ئ;f 2ש˜_P7R 0i "}݉O֩7D];5ʂ}4C25/-mv:%)rs"-:b;xSz(-}T3N%I %&.'YU}t⒖D';AS'zȮP}bI# QL>aq/nY;%vL"Oj<6q+c{=U khQ4A=wj`ٞO2-nPr.s>=twC9UeakPIAŘYJaqVT܀IR)Z+G?vmCS*S^;hY77Y|VAHHD+))sgмfT A vEP"[oо&UBzՖgbi6E8_'V Xt'jumW7N&5?_mՐG`}2vm!L:DёUgW3UXr!k42^Rnװ>0U(M6 lLRqq@eX|ن0ר#\@F(3U3> 3sʽ2w@#+1{6BIRvdCzy+jb2 5 fcg4>5-z?e63>Sh$kƓ ."x>= ðЯ7"Z~AeNQW}F|~-!Fj'J7yfj=]˜OÈ'E2O|8oj }ۭ 8`Z~Tu7/*J|]-`I(ki b8+qEA5T5@~H'PPY! YV'OCO8g ɀ2KnF767l@Tn xBU(sT%DvlVI5$5w (l!$O0ŅkZ(>ZE,h#m nӆ uTeı#a\àw(C)J bMg=t_;?fQ #EIth3L#J}߻?l&LhihYdh0Pc%́R?nAc?Yr$!?EH7#d&!kz+ jX6ywAQEfrDcxB}ƅ -7T8d2ߕyt3_=dYOІ,Ⱥu h:*[DZ呥{^sVh}Hm'慤.:e%~@qa^IJ+D8 gלB-v~lzNxQ2*JmZ[t9[fd,vKcR.#k!b߮A7W~K!%@7h YnGAdwEzT3oA70`H^]vA{, xI/oOnv*e>6}ӎ 1Y~pFo93Р <lj3긪㲐Lyev-.`-!da-l!+ڰNPO3.B/)gFB12Z(hqp>F*P#rMޗ\2G_y*~|PBH?8 uh{0U;Ui#_?#>9PfI1Ұf?66_1mM6W7陱׍WMw`SSԶz9&jB.-|F)i~-*8F3>vdd30Tq̻RK!sgLa7.cnˠ݊ xĻ5@RMMuZ ]Ux1HǟXA"lrAiJ>dNfzd lhA߀!ʠH nFu_/ ڗg ngg GW .H^ i9lם&9>QcGOqYw`!W6^En%VIo1V Z5^laۻ:[=?O~V,;UŅSYz-qGH+,`}uc 0JT~"bKesLũ[hQ6 AQ/BXMe!b1ML0Ss}|R@f Ut Js9);,IUlJfDmS. &yCwG4V}F~LNUDZvDHt:@qώ0ؔ\ W_d[_%CP:KRkp?0VDXJFBQ듷Μ> $[8$h4ļ̼2H_8' KU"KSFday\C7MNC x@N$ V mhùVodDKr:IŨEllWyBS8 öWWb`U`2`ePﵰzR\2IT.I16OZ3XH]4 ƺr}s[EH9 '}5k 2 }7"Lm8x9ϋ!ːLB0@Lj7>"423>r 頌Kz`ԘӖz>At>ptC?[4(6tkS{R^fAX($-\96OKGҰ`,{SGZ@!p90n`Hpz,rǗ@/}YNN#$  IdQPn[ADn5i 6ՙnO:!c:VԈklJ|ʒSz_Ħ8LJ> ҙ[aBd,LD=7B.Me2¥ܲ?YBUq5`LX{yU1I6[T; 3kւ 'מVV&'1 i?M (=i;S_d A$Ge-*7'ᐜ:QI~㞍ݬlLSqBKAÙ]T }۴k]Xt?= H[4ncDǿV*OR k2WDnIԤrq $JW"&:Ke=dExԼ\˜^i.;Cf %b e ,VT^yospBA .unRϒ@3%|skz굖F\JMGhqlztҞth /o5'I P! ;hd@'/'<"ېxj=~}HS@ jHs!Gr͑6B5n̊Xޘ#`Om6_jY6q`}(oQ yoTK6c4<]ؼjTɓWvbMʲk 5y6…c*hqY'?n{_ JUHKVD>(O"R%+К]: ]jW ( 1_,:Ŕ7}s N KTiFgxq4-ƞh.T }oz4ѣ|,)5( {[ G6;FϪx q۞  U;<5ؔNa(vaX]; D}Nл2՚~ip ,$LL)ۭ{@z0TI3M@H]@ć]p')]|?!LpmZ{dL(ݖ,햹l@ʼӧc'Fu[R(NRm߿;Gm[W5hli:EC;HO]Dl>HL@zvp]e#1K3I$X#xOTG'@?Ee#1pjl݂ of~ib e)4 ^+5Y,098@j$SC_,| czPyIZOPx-{fs";kK@[n 2҄LySF=0SCe@箅qwH>t\r1Ɲ&KyXjaC= pj-FP[6*N&Дx2wŢ;Gd2G |1Y:{C-F&eJbBӉӳZU?pA ̰XBM-VobJHlƧt8CƽL߃j))j'4JW0vbp~ zAY9[UUļįfx61Qb$1FI$hťTHWH5~3ŝLcLnvc:U|hy]r2_ʫNvM?\ّl1=Od\SuARYڴO>h@J{[sK v^ZzLspl viٔ#b|2w̾EAOsEwVgL#Ђ9BYbWwt%;C.MYsМ],Xvgs 8V(?L٣|32w3Ry UNNp:Cqc5cY |H~\5߄#`:$SԄ|U_6uLXj5 P3=*mG|ӆ}O-; uه|{rUOpu#F'was_v9ŎD&IMc-0╶B!w-I-c8bY;=|vB#i:1o" D&!1Zh)R`WCَ4i@mo8|wg0c}y#hƜʉ٣mɘB-b$Lݦ" 6.ƙ:lmu$cD21Z5 $aTBt*`=䠋m eս_ٍ{B;a)%"(ֶdm2ܓ,E't/ TKuY8tJt҉w!;w^PGjxe2_wQxUs6.4]ęX~9fo7qtoNF'O*JCyV]U=gma/H.l]ݮj@𯂑B&VJEAn{+0$/")+KN$i:ڼS#b?uo R*o 5,E5 +Iwߔ^ș7̸P[]~wKBw]$OsG~mŗ{9"qzΒROHyUDtFwi5wmr28z,2wc|tK{wӅxLWNW`U2)&AkmFyoX;JH[Q-zȧ1߉VnjļϝuFpաzŞd`5:RFlN']`VEGMHr-g>R{MC@[bRT9sڔ=A(c_{@lNK}(LlQHJȡf&!];CNrTg,: ]I坬ORw9zy&3?w+ qS6Z6f'>3qABQR, VONA|$]x=I{o ay=M1hsk2a2+}Ӎfڍ]iOs'fz͐|R3u:SO@.ݸ R^A¦@huPPodvAѢ~7f4nggxP=X]wnJG/VQCǸ&%4'#+_v^PRNso0r^aq+},= }`M@)s:D^j>-@~ٲI$چ R8To9låG?pQ99ѯ;|G f5E,v UЛsoH zrGyb;gѝʹ yO3@5"K( /Tu:æ%)DTpXk PgW`YӉ10ʤOtZdJ" =:>X n٪8/Հ,4ڧJ#X0f4fђ-5Ao4G_ᯕ|fYٌ/Gg332QomYoV)Q7Cٰ>]c?%fސhϮoM1B:DHTECPؕn6'dC!ވoq4fr=Eǁ?z- )*#!&e|Mϻ| s벲fxT`0thH"Pa.V!.ԟ(@i΀GܩvNmw>sʏBIY0>Q"Bّr `O9|(?\-gA# (_31n[ĄUn<}זSʙb6\g-H߀օc2v&q2xD*o.7O 9f9["}3Ɔ̭/-P.| ta"WCќzXz yrh=ɸ󬧖@8w@뮩g'§v/<!s0KҾ ޞ>0Ma6e^t>7̼ҭ8ud"2Fiơ( r+KlHL?F @֧Y/* t5Jv0l2'?C w]Rf\|&u3^S%Bmsfx ?Xý?UE&LȼMsG9g_ψk)@δ= M(F eKPN u4(%iŔMGYp3j>e {dMpy1S]dN;D*]]F88U Xߏ*{gcMY"lI8I \†00)x,q%FO$../ZKFӕƮ8Cz;1U89{+t.茩Pmkn?*KDJur&Oq[^/*d,X\Mf-^@Q=L\9UZZW 6ԠYk J^@n!ox,ʕjSE NqQboa\&q*O { K׋pFJO4+weeaG|,n[BXSϞ> s|XԜf-^?K׳tҜ_s͏Q^gkBFͭa=SCsUyy A:.zѤҒډ}F q cШ6r}G_j$WC߭XGpMyGUϝM.üEn]p, HIm/p(Js_Ya!]#oO>n ԑ9MCh齕9XuKǓ@Xz." 8M!X2hKE| 4ɝhOQOXJ>⦋)  j#BR@NN9OiXKf5CSdnf((MrTa_ ֊[xf7PϢn˯wB*GDO;#a=9)%tjV~; P@6֨kfw.D5IǞs].pvarCS)Rbi+8qc֏j0Q;q>g /t]À X8W61ӘI|>0V"4CHZPZ\K6GֿEf:AXk%&`BɔkuDlzո4EbjpEQ L%Ƅr 8IUL#_x\\42j6qעvA5J@u\*ZFBo$~:_5(*y EsyIOl3nim,U̚=L?U1tHbtK3f~MS:t؟8㡺eu;۬Ƭ~7h蔘Iߒ55f~p6& 4 h@m]"ܡxT˽2P[d_}"ٍ0sdmp9[<%4y1T fUVM_J[זʣ;br" <ӯ@Xop`#2Ѡ/S2.p|nWO_gy>e-Je\AOF ڤRހ aacĺ*]~C#tlOvמ[8_bcO"D6桪 ]IQ/O+*~ei߶om_6<` eE= A&'A2ý;4HKaw܉Š: g{ 0ekȗ5-+?HH(4NfjtP53LM ,fv\g!w81ߛ9*tęӉPE$6tAcBvi[%tn#[&?XpbhOb Ւ3ApBȣЅL`.X5o콂ړ55k;TZdYVſ LkP$0;v'/ W+YpY>7e[6B^B&%Y羳_(:0[A`S T\/aÊ#W!6шx$OC]b!g}o:5gI_g-lAWPw0mÿ'$Ր8],Q4?^|Qpf odKG |lު*b+(+>Xъ2d ф=ſ8Jt .>ʼYTMK71D \AY4\2ZE[A@g~ VYpܡ뗍j Kϔ(G= hŷG굖^[,OUTZaaL$O{!=Sv0cf<ȅ [spO }mcu"Bh-5%Aj`wפ"XC ƌ:bH~H?_KYMEIG%q/>;v 8Ѩ T p}Vh^㜇u#((;#m߳6ǘjFc{衲y- p07{gXw& '6&p)YFM?v^sdL20Xp1)&{\ CkdM>6 KQQڰPBݚ?#qiD:G;Զg9%;zh`~G9(0aܻKZ}(1V3)zwcp`?k.7m$Eplm~(Lދ#E`>6?HWh8?t>rP(fn_f'V.c/ߐ6ϏޣM,IY*3`o gOI]FjEOuID|r~"EW l0.i-ϧ/t aBx ZG t6&p(@Jٸښif\rM?LTJ.H@g#im<0% /,`rP@wf Ue9 ۑj+2_liG:WH,c.kiWV)L+jiKNXyVjx(EHb#kAF fqvS4yk6М"w+t.7l=9G :ŸȐ"p/4p86E׳t׍7MGb;kqc\|"Z4XX puRI"tyt\\e_~u|FRhD~nxKRwbCX3Tx7;# [e2E._y?7-ڈS%7~o yN`x:1'xBz]j{G^%ĩdqϗ!;u%krjT727=mO})/ g؄v^׀Gn8ٿ >4މ;[e{|- lmp~ud+- j⦼0 i9KnrrBrea -&2M'D "b }@RlмI@ 횅F3_N/V`CzB+<³:`ÿ)`ߘeB}_ ʴ%L<_s38P{g嶽 " /G.K$f7^xJ)O7lZO*ԸI=B/=ݹNG>ɝ ;7cnt6 lqU Ft-<3@]Am-AND۞d߭>Ly,HC1/@1KXա#-Z$&~=doTBeIa)Z݂ѷhΏafB. ,Y@T/1 2qbr~Bzu8' w Hί29Xhy$"|0E8=755Rqai O_K00jm#9qN.[7md1 'l*}ĝDKH~VmZZ4Z0 $֪/Q@%a6sVF6uhzp  6ӳ9HĀƕe.ʖ`#2ud qEnx=yIHZQYff. y#yI뭤zŪn30:o>+=6v>.tzWq1űUeH3su_TkԒ:YB0|$#{?`ܙySW(`Ũ0 k()00A-<ǮdD.ZKaT]k zE,d`9+~Y"k^<0]I؜ۦeֱWҏouqA\F> 6ءm&,r|ƹ4̖4YD j oofL_o@2.טo̞3;9S;a=V}hlR$F6P%_Q粕Z=L1 0U[llTZ ۗBJ\f %Nڽjv&˲ 4|e=^zV2[?! +itDJ랭3 XTm|L0<92֏3/ ~e`L3Ul_XjxylVp _ ֥n}kD13s*dKBͫ˂{:~a'Dmӽs˽u9ZmX;n>'8۽/o|24>dzZ_|Yi@D3J1] h>S9Z輠OjtJŹh;ʻ&RƇjv&,- PC*º2%v3 pi Q;v(Yԝ>[H@TtI7 RӦu)nO1.ל3G}b/yVyesO98XFpŴ7G.m;86yM*6p|x\~^trrF`_ߨ&*}&O\?*w[iݥKT O"}1ppk0+"O[[%W Y^noš --(<,e*`q,Qt_3z~+֙!Htk M2/qeKz^+v7d-v%hV, W}<'m2_ZRfK{ALx~{볺70X`lк<''VZ,&P1 b2Fv[Ι oWwQM!;TF7ĝIƬ\,E.e!7CW0>x܏PK X_X Lu=3Ւ+?R[IIj >8F,p#|C)4MM e8hQG`bf5ZJ ]L]IJ=$̈ q0BD\>ڙ..t&#_Hs|z8FkDbq+ẇ9<@66}OxXg6t`\ 8yQp.?8@+cXO\ tɱ/؇OYuϛĘF=rbeYv3̧I(Tb ,pXb_WKE.u=RHٳюGx:RX2ŹH-ϛҙAuk :7l"E!$IBt񀋭[XJp|?Ǟ~2Kq7I>*$kIt,o9_O&<- )$X[m隃ge1Oeo.IGbXXSLd^.>M5T*]rM#cuo`}H h_#bz$ō$hnnǟPLV*n $(>AٹxC^YU6JU--S/c83\wqtw(d8LGB8a* {NAktwXZ^Itܰ@gYqF}t /ݏu.~сͦpZ2sRMyi +I[nERZn~/M )Uz`2ٓ!-O? I/+r\`NJђJtXSF}. G8hs7N; 0>9.[0z>19졐{Idbw;X$e+C!ęniF"f o ǣ>H תZH~$*5NQ7Yiʡ(2{[u*{! a0| w(GAh]b^F.t.HTѷdlOdhE4=I##M6vǚU7k+X05O7`ӱ]Ct8[( Mhv KN5Ry V;R Xѐ\2S' ^^9 aA~UDaNxzԪ^C$rJ0$sZCKRe6lXN"`XvnkkKk\8ۑP}u8S c1,CӥtA}.^oDw&C_L >$' >GDdab)0]#v{1Ml[$`k:yꆣtDeq3GnB 2+px]\e=58?#_Rl3sӗCl=|q)! })V0!&ñ!]EfV[>K`?ᦳD.-s>HAX }|`cG{c?;9A?Y/G虥8xøEX1V **뾠ietyWu;[(3S\V|Y_O'7s1'-DZRmgav{6#0DTӧ <ě_E){t"Gw~ V~!:r(fx[֍)3hZG*:w^io h!KO|`.`3GA@Y46axzqM"o"0E"X^@#Vz|cp fZ$"3 qH~RF]i!Y;(",j0jeV6$1, 0,O Oedri`n&im4VO[Zh'n<!\bӟj'v2Zk KD`}dq݂ E(t-`-g_YmĖBGC  UCUր ʯ}OiZptͰ&[T^H$bj=tMc'^;c x~N\=|atT"t=(z"W8oJ)rP CnM҂#8@[ of\3kPN:b#]o_TEC_\~dpbk_g" $0{X2P遛F+qvЃP |lB𗧊HFJI zQƧٷ;5E47zJǓ;'\ISn mbeHBgp3c؎k diLTR&˃-2 etIMr$S#\y ,YYS UZO4tQgDW0vRO3c!/uT <@\U7ƞ3-n; Gr)w52]Fsf6YAY;f_{I?/%cf8N3E7_Q3"Ox*bT#_ݫh>8)xy%WhҾ7VYZ8"-E=Jp s=0׆QnT>}ʔ(Ϣ=~GK73$fkQc݁ztX[I c$S%vfh)gNb Zܺ6g=w|p˿:4kJ`4|AM9#NΩF(chBF&AyEFo|!U Zr8SDj=w.|WP3JX^RJ}pn{-7_X0i#B1h\CaaFlX=/GJ1\K#՛ddH Mڨ[,.ƪ>t]ggH9Mwa`u^ S261Dx>j>;tCF-"|e#w2xV)\.]R|mvM_Aϔ淄ǑJ P&i ./t)JʜvBϋe?b9k цb G2%+1϶t*!BRxa-sYؙtY( U줫B94⡄N 4Wޣ`W4L@H 0|VV_p (]΢FMDcBVёن?ƕQ1컶h_JJƶ1;ng;KxUJ e6Y.,W("[~yFxKGxy ("m][@<˔􉮄 <|]ޡPA}ZCtTtNKUwQgCxQNnS' y!Wa4uR_0Kr *Wҕ4dqܞ a&lJtG U/QHٰ`㞲ҽ]utIeX.@}V&[bcwNXŵ"Ƒ2g|VS° @QHu,KX&ćL_5KTP;ߵW`SqyxkÌOKP!X{03ae rʨ w' *ژ C~"10ЯpT3K~VO.ej[1B]dv+&dž+2d={Ki;dk<=AbTM<݁Aeχ>&Bxp"cq[x6 LJ) YXURA3[q\S%)Q*s *0;ZF'Jn;y9yU݋%X 7X^be \Opu) @![btĒ*$PC=A4.&oR -fd<)Wh Ygg?(|_p=w Џi>fQy&H}jF{ZwTJ0~Wd-R"@6{ wP84PhF\Coľ"B0d|<ZG6&7"Rk—~Fs,{Atө"-JICf=UVC,JK ߷\5ZD6K }"ٴ *w;Dž xj `[<'\}5^W@Qi>zPaAcK#e7NH~FY=/5u*t9qE/{z6ۙHm_0Ƨ`~M ((+NπE?* 5j"hrdI!-Z( 9pCOEz`[In I$lUf5T:=?n1#t4ϰJMQc8|!Buɠ'7LDfG>g:KDc39q&1y6=Zݕ>uFi77=]z|( VU"X]Ȑ~)1yd0^q5nN4Z{~*z"'VSP4YG(YXiQ$)̍V+ffKn> ^y7%J+Ҧa>Gfno|!o#I[fbn1{ MkԨ\;[*J^ZHXp/`ZF8ց Ub HY d@pYzgPAsl#jx|T=Xy}.\JL?Z'/ Hl>;iz&D#xYydzʕv "#@&hF-ч(T |yå(Gmu֫熉WJs{)͙hq_M-vshq|tN' àc.cD 4RHXܱT&Faܢhc  ޾Zm j]ˢFT_c|t bcg>YRD걛<\WV[V~BQ'i]{(Ktvz` oeNFǰ;|1VF%]ťf6+t  ѴcuTs~#6+2 ׄ!/'Z#m#B4q%rt G,l =zÚ&iDCzX7$?"'Xn:ρqNZ\hgM|,/i ;7s1P!4? dh: R8nrD[jJ:am%D{ޮHv $k9c)p%4YNA?_Aa@7}z4/BN|pג9c[8#/x2|*}~Oik"&.f*Bhw Or}4E uߥ[{}O\2-(N+A@BQt?t"P7ڇWf(i}*49 8^k Slg[i+كl&|X$ !іe)mT7(31 nJ5QtjybykuS$JO)OgX1П+~z@GgINL+ԓP" 1>^os cdٚ$EgG۪:bgP=_K}z*zdXo?`@w#bSG:Ӌ!Vw O RwW\BnGG䋌  rH=,ms5VL7>)429( Ea5~1;9lw% k~&fxNεAxq_^4Rwu+Z^СnDp 37wjVNvkIi.$(3.yy5{4@] {Ueع i\KQ>Ԝcd7ӠmR"J6T?+!V%dYˀc9m/Z(Ok}̌'/oi}Evb(I hO^ބ UA2#[glJ?6R~LoXMn3 eld⥟/ה 886eOu_Ť9b41DajPD(8F V xUOz f* DzzR:@`'N"{띈Z(CC73i#|iX0n? ɢkW4MTʫz{E>mgC 噠!Z0 Ń/&m8Ovu2a~FE-e̪m정7"~kk]`y=lV.+*:ng2gdЗQ {]qN(;0B$r9^A (SYuLH袦Hc9 #AףґO~'f& yεP}-5=jJymBpbfRؒǔwPB&3͵tfO,45gZM Caw;~{?%8ѠGA`B;b:b6Oр ֟x$@p;^T~t^g\g*I7<}(A%x',4KAj֑'Fs@\N;rW9d>n~KrZy5ء0~:3=0E#w]"X=RMbt.ZgTA6UâD+e}@ZsNtMըػxф4ߺj[/SDQ)y-]C (e(h|Čd*tB7(nc&O84+򆝁Ke1DVeee&1Gk%M0=L:Q#ަEM P?dP3l\_+yNƿg l kicWٌ4Zv>x24daY/,q7*x(̂1JRkc( a\L1sq7K;7u@=Mܑɞe)fK쐀p]Z cb{ËƄd@QH׮G!wS(mpE[o9Okm r3ُˠj1O[2[IrIt|Mf0oۓNa)qsy^aI)̋ T+]qNBH?!0o ƄSYv7^9{j(NAv,3-GPnNs _ ~?pGnP֘ {ym~0bDOUL# 3nTZ]^rUl87WF6x%ئ$g.rtZEHI36(Q͙xxp3Į%!/}rHÔ2.^/%-OZ,(cm"rN ,]SԹkIaGT7}/##EW϶/t[^MX C\mNOwJLe6BadBfyE h%izJze똒GPk;9G- 'OVۑ#'iKvm ǁ-0vlxľ4iƇ4U=MrnT2טN:$ِojNa&~&C7>G/t`QQO#1]Z됊TbԘyM.\ KyOs nǠVzU1S[iw]~{lZb`/B϶C+Pp;956[F j`f!_B<SaRN Q˝>H/e86~;d`Y*(?i 5ͳI4L.!dٶT\0 K|Y-ɉ7/90WZB ^yYRa ;L0Xl81tm4]ђ*5P ~6/X8B6(A}rHG 6E?mb ]kWu!a(K吕ȨⶾKښwx,BliZ8')oØc +]xxi}'B a C& ٜZ~=O#K$Tč6ۚ=1:}鉚k+1atso.fb TYcwhҁ9`&Z[ZsCSE^  x]ɿ`[A+?d`q B9ꉒbwkUZx3jC 馡$rd{Jrb=* y<]*J f#jy?uo:f<سݠ &] *1FNq.\e4(֯tY,frMH,)Q5o~"w|OdܒR~z#%$sLֽY4"DRDďf埪*>JWtR~AAa6<*`8Um%')1񣷽͉1gT fpׯD:YuߜnpYO5 ȋeܸ.+*en|ָs]쐖t1+*45 {}y hox!xIL`)7hň2vG4#;[oI\0)n ֓t6y} Fq ޗ1,Yz.t30ߍ/d_Lr9Mo[%^f.m2Pv #󷈸@sDXR%Dm"bDDk-܀!RTЃEShέ`6˭yQJL8j˜b1wk,gW|Хd|2g:mN}~hn 5tJ6n\s9v 6*28(RҙZ4-,dd,`u~|&ZՐ!I4C:!j^{+> 30M5VǕNm+˱ 2ǭ`NS;$o$wR'Š^8+sX.@|Pp#cLq,.^^~:&U-OE~ 7(XbhJm 8@(O[D94.&2UGLT?(qo,r5hj E-h$!&QCj{%F-i*\^LO0Ȭ K?po"0 Ɨ?-#R<~Oo3 dlogtBiN}t31yT93(^qd1-3 [Q"fnw+`Z4ua[j٩pNaSUXlh\pcpո"RJ` ?Jگ.\K`o%6_ށ$GHhvrݯއ5 9dro'/`VХGIzoNs Ĥ53Cy![mFFOPrAivq7UEtB4(S 7۵Q`-;-:)Do$%M5c90+NJqގ>wZ` EmoѨl1VHN`%HpAb4d#qR杪* 4`52Ћ [ sCE_ЌYM;˓ȑ X͛$,(ȔeOeS##CIBfC(? "~.Q,"29D @OkȣV:Mp$DREYf ltLwr䧣+u6scNZ/ Qowdxe KҳnD/1+*(ШfN &۱%҄ b]ٔQzb yL(#EcscP@x*B6Ҕ5F |>'~!(mChA5_^CCwtbo'&Sݚ;9 5}_%5d%q\fHjE/\A9u^Hr`sGs p) ae 8 `I6T򊼁Tq9ˤ98/`g+8a' }ľXX*-Zo5]+ƚpܬ,7THͬJFg;M;EkEfk{QqrN/t%)'~|6dZ/`<#_jQ^YЁ X"Du G{8I 05{5VˀLX/k<5H/KH*z oA =6쩨V2 DMT: {+$X,`a=ׁyUYdwD~Q+Y!IύքDayj[+]KC5d)Yj/ylϺY׷%^2tM+ˮ Y||Fޅ-w2av-muɓD^9%%Q1sx;E,/LFsM1u~swC(TQ&%4$帔C xES0чBn)?4cLU>GP)yC?>Ycc͛Hlm}*;{J>MC| `{ S>*e*> z\M\{ b=_Xt7[:+oKhid;xI(a7|byZɎ|ψ!\ -ԌǩWjE{Pf|A稭EV>];l4kT tcƽlV55`'Bw~4(4A Q=v) qG/ډvY8N1C!іaWЁdUl{}oT]t\WN~:VwvqQ<@d lE>w E P WQ5w7]Dv- HXa )s #"ϵ&WT9xlZ6REϫ:g{:F7~\][3:Z׾?E] | e쪐x[nZ, *Yԃb.bI:Fac+;|m ?M+0]D`&^bXp" ڒÈk%qއ&H:6O8چ.5a| meH۷05>!EǂFT YjU~dԴCۦ("WrcFf7ɜ2Auؚk~;p;t?Û<KIaŒ XaK1SUA;Gri?نDS:mu {:1}[pS==֪w m u*ՕeI)d>\Ea\gTJ~_'C_0bǶiĎ(eZB[<˰1޹8ہn 7aR frqd^q,b&: b ;L9H{X!Bj+ѸO<n[5kKwϙ͡>r88ӥb  m@&*lr#'C.~Ȑ 4c ٦FeR20^jD7jZn0 vt/H=_G"b/+I[ +. 6NNuslR֢PNzQ< Cti VҞ$L:WK!1_OVx'zT]#!⒨p1vpu|2SDZ,XI*xy oʾ0YHZ&BΡ, fJ Vf[&\eaK|pN>OO^]_X ʛZ h[س^$Dfhd>RaI `I^kw;5ۆ93^D咠KyY Jd_pu?nnˊA.@7I;X6X`+kEc<[# H6}tC1e&qm~gz̻[< .>TGHu^r~ڕO0wZRO&'~@1,yM[!\̍5)#i']txu9;h[yb@tiJٰػ,%+JlFKg;mci2 c@ `aʝnY''kj uAݺ&C =s0.azRnv<*#= , CN/{(nXʶv*~) ( b+^UhB6R?=^6e|(CD@gDm-y^SgDТ,v_ Η.O *a'#W(Q@]%R 7ŢЄ/E6L%:|+ُ`gċ")G;9_ն"@[('sRՎTkىp{iT'oh7-`*Ցb>c}*Wۓ1rk^yTqmnj66i|g uPFuS "QEȾ ZzR_@VIV?/ \%?wMD=,τۧƳhBF~ŏ0f0|"gD؎,?PlEq@;-e *!X0n*-Ќ1m(b'{Ԍn} 5vӟAW^~ך~bR &ik'ݛ^W:b~W:>sgCʃH̡92/}.>Y{3HK !Y?t# m =G~V@ ^49A<gxO?+;VUy.W|@D;E5EҶ}jD jg:Wedz懪^Aajl)f(gΰ ,}c!*"/7+ X<tEIdMϯ%n{' r'p.V>ub*8A-~аh_(½pDgɝZMx1+^D$r7Y#Z[~1Mڥ WՈ WhluפHH C FIVch/1 5󲣵jdgȐ_0HmT_bw_{/T$Qps-smƽҨ, ,v~j*8>D!\c"Z{$zd?_K{V2 1dZ*3)I*W#J:{]?^/ a//O!3եuކsᮯcRM']B:EO1mӪi) )-uqCDA2BT3 Kl{1QԑJ:J4:†eɮy.SRs3vj AY>LԅC3; *x!k[v1m[e5 <JOe4:Limd"Hkۃ 4)q 5{j9\:;!+Rhf%̔\( d'%Li`g0ox1G{[A$ ػ#Do0ኆfVk}Z(D7<"%h*K4mnzxI=A6+|]X&Rģ%V͡H L|P?А͗ldA^&oIźeu<<.]zL Fmڭ>8UQ|#vatx)Hw횜an_Ń!)k<D&r0UMZК̒F&x&CR.W{=aLͭ,*0gOt[;0d{xmX6h"ptDlLj_d?!r%bw;W\*n Q󡷶6xR O xCGBC4 2*j4#A0e"s+K@hZ/(~!kJ~0|"Tj+~1K`8o%U>4r1^SSfy<;D{rQ!6)]^¼lݺR(Piy!FhRuv]Kng;4׾)uu7խ.ue vUwWJF%FdkcTnr #RQ@Q}s|L!̽C(IdӠ)Ld(ek/)RP'@)"YdB`W eֶ)y2++ z]z-9O؉"`qb! t`ą:1("̾dvluGJ^sPб.Nja ɒ}Djk3/'gZY$1M?-HS5jEp@S|-.NnVO>ZBڶ~EJUխx4mx_5GVWsdq w#V4haP;ΛxX8 OҌ#j(y\uʥCʝ=}+q[u&7\L^nS{' ^-˝)oQHTe9hD;n6LWMxEH:}hTjN+ʏ.P.웧mGe^r}#Jq,]GQo׬d;KSʗr\"C˙*Ӓ1X~6P Ťo-BJyq*|ǁq5;lK(:/sCDʶӹ"tqHد'N/1SԒ)H0?oZ8i)E96S}PBD~kag[1v%7!A>)L&V q+>k@2X:!>O!^b&b{_.WU;}eDʢ˥fgoxqі:Lܙ3Sڔ1}Z&JyEN:ߜ*!umѹy9P`~y \9O%-7 ՜$ӑM0xꪖ(tm-3G'_Pc LcI ~.Vzm ɋ_%Ho,tN8cO (mC븍hBI4^ቨqayt100  1%&m"a=nXpw[<|Р?rv :kx3qZR5'tGnE GP"mY+OY%ƶw(zR;l| jinJ qq4nJ=(QoB6UySo铵dnzPvic?g[Β[ġ>s/[AvLJT9|dkɥ9CsL9Lʞ 6q0m XyqSw1/TZe*ʋ́P)@ZyeA505R\xV0?Uuk/a*jqC~@\ ?:0M?q ̀ oe蒀j٣XھdgY*`n.Ї--W .hg&ߌ{y$;߼nS8lA[ 3~ڮD/}]NZ6̝v6,эw1KKP֢-6Ma0{HɦY*J[LҵpǕ^MfzFYp0J]'6az;DGꈫ -XӭwHQ=H l%~~AQѶ/«z)|l8lICBl09C+w"}! cO>DҬc@(ܭDzހY-.\LD[wbT}Ѵ8UZ~DT$xeݙR$:aBsיCru[P"퇚u X?$r^/SSe.Ţ:`7ƕ߮'YgU6o3h=JWƢʟt,>aQwt-miF0\+dKj$B,=IȻ+=յG@/DXAg7GkO#lvheNX~aeVeڰk/hzͤc[OX &BO&H^BHʄ&aow=56~YlT}#OC 툿KszRݖh}Rx!N~GEY <p;8f7?IHF%ŽlcvE?$;aZS,\&rϖȰև!:L'}lYuS%z8,9bAPƧdQـ> w{f5l3 Md׃љ2y' =s~DntITίtIMc%)O" 7C3Y/xl/CNR%vy!)?cz,|B:+RǯWU↱7B^%&4 6(2G(<ЊI17X *LCM4 wgTF2t7A'G~S;GDvӫ"oôl4—I_Ҝ.Hޞ dѓOkf6r]1Fw'P )N$x&dJH| .%DFXZ+2` Bՠ& 牖c/zLtAc<(Q%^qlt$ Q@uOxZm쫯O⇺xBYFҚW-*l3 [c P-kq:Ta}}48,nK9y@sH3e99ҳz"Y=tgkizbżfv]gͺ06ٹ';+Nky)/:-}*p4*A(MaUԌp&t॒E`U-S hRƲ̲l*H׮W0Ȱʔ]X1陭@,L-ڧKibHįfu{)`_^eI!8讚i%0KXkex[P 3JES 2C؋brn^-wZ"wg R̡4hOTk0H)(<" 8i`I"0dq}je`i@Sm*ZL ڙ $;["G>txZkeE>.Z+!_sLikeҶ)ى@O [EڔԾ.X \>A+q4+Рz,^/ƹզr ȅbSݳPV"jW2 Ěvtu'ʫ?|W3BU턠\ɌG:3P /ix*5H@\K# %dC;Z (SPN :E >@Y29'" r@9/{ Ceݛ&|++J/NtA f$8wnh!`ܔS2(7J/ZԘ.82AO:?ژFj\[6F37A`&8);@ela@]22a-aB QµXW( aC*A[{;zN4ox#=}Vjr-rʞzCiS zI@" ҍ}LzrQwv/Tj^'W|GU'WCe~^Nvq5\A'>y T`"tU ˅6~ꊯVP=P,IoFP=yVa,Kq1 u;+~058O Y-G^a\܁H1sN7}T835 @`- %Hag 6Xdݪ 9X czUVpCc=S1[eS2#zZ-_+}*3 $mbV*N?@>ܡ^N|[u Wc*O4x.$ T FWC%_ 2y(FBK[\"E(Ƙ9+b莰5c%mp};mstc3I`2~?'c{.CJ1"j_Ƒ Z) ʎrqgBdڋPЛ lC7''O)#L6U}a+ »n-2~퉾o9%YGn@OnF!ZI@%VefG-&Õ-"U*@G F]lHjjZɡɻ]:;2ҥd_d<-ޮ[\p1$DY}~|,9fr$^ܯ\`,-"fO[gԛcFL 3+-nq!+*EaK]eyT=X*9HGpm,2%gsuE:0#&sTn+)2P223]i):3u%2FARTb_bi+u;cU9b;:yYm:\z;/5f<`7n/P5C?g/ӑJu[GՄ*^#y{?] -p~ɂ7BޙQInO*=%0T3La/j2`ɂC;C$DXa#dAѰ]{HW#G&2H0";z\J !lWCc+'m,>yMp.#0Yey$ܠG.&q?MleUP%OLep?F'}k)1:b~ myF.?b5|M{ލ/Ilj!/sNW-HB8`tCIp (zL5!gF`Ztdh??G}دJs_=lrƉdeuw0)#gAZ(왗0 A\݁1&A'k)X VUT""#QHl]b?ەҘ M]5%:TkTgQYeo) #A#_gu]۲AwyҠYF]~yVDұ}t$jcg"nx5|A:sjYR;';ɼ &DuYᮧEX43{׋L?kME(^V|h$RwYY)F"w`(hժAb¹iȃ $,= Vpu"s'\Q_4= 7? KG'xx8 8 <ƝMC%z^UH >`c#5/^B*\Rf몲"\ȀJ($@a(IP~Lݨ:ME})c#%6wDo:St"oEU3]b3XoD4+kBn૱@(_ໂvnT]pltLZR&Fh_dNԈ,ZVl{=ŁH O? M&، qMnEXmihZ0Ϫc dOwjvE.-'id: DRu\u9g0ҥi=hwi['ӍK F'k*?DH˜V^։Ъ*:"QRCzU#\G/MR,8CwT {bWN;?ž`Jʄ8VT' }[PUG` WHF"'/w it쟚n誃X r'SK5HXudWtXwXm)YQv=LD]hw_o|3MHҿ WdMЖ ju|bmaÑ.KRoM^3FQJD1}f󨷅@a0V݈̪G X6,Tӝ`HPfKN]QFjxZ0ۇjQ(h;'dt2Uk͐-,($ ,.yY{";BRM]"ð./۴v,^k߲}gGu rW&`Vw>2'b^Ep|d"H $S2H:tmWޮu_2Vl:1PdjО`chM< .괲{5wwШrF|&SO?}SO)$f%6x1~(Zk d>] .ٺO<&:'v>BaLpea/ ESU9 s,sǃpV*PNClBW X"4-8i )gب[DIYm,iRy j0bΣ x.&y"=K[/Џ%L@9*:o\t%. r"I!ƫ@S.V,3NSx\?*T/k'NXkUp4 Y@kGC$!SX bɾ(J%.yVRSX8jyfCN.iVdKO:Nyup7wgd }z.7Ks#q!$fu:LMK,g}?mnTg%"*@? U>dՆdOr@mCp//dA+-E\^I49|9% m }ʩh0+`ݡ8@_Fuσz-lpO!7LCzᢱLڒTK1" {,hTK`k|6q)5H'H0&QE2}:&P5u 0#󾪌A9i g h[0}a}XI_^vz%@duOӋGG5mZrs*h~j}V/[Tx##St”fxtʒsO q1LJI3l o=ƼuJ#!BKIƢ isؖ XX!^TʔԲ_m̹1h@ ξ5/k`[$LMrLJ,`%e]{sxө?bynjP=gXZ_ 儤'9! nx1/6tj?[OMC5(,eiA;$00a^_~LF;,U:_t4U.ӌmSCaqpJP+uAۭ lF*쪼l5sCRL*t⍞oF&ᡏקGqIr3qPkW\1Yɻz:M]"r=KzI”KQLdjSfu#U6=9IjAJkol %6{:0dV"zpvynEpIR4YYv HpkS?I,%]DZm: :?@1n=.[958lnaM?|*,A'N3abҨCdacarݞRL;0jXOONWY6K*.0 fBT!nظ'#JYd!=&'L`%Ւ<1LLv˲#WԎmhNK4^'/szzi SbClNkU. _ kx[0^[ *HS98+1}瓀J Ugҥ4j]J?!E( ð=3|5a4z}X_ucp۩ `OR Fa.ݡf"X9 A_bMbax~-݉q[Y1&aoƘq%|Y:@gs', [vj$&Y&uV(\Άݹn=g@kO6*|v%9yP<.m6 J0+XAC8.N(M}+moɶB%q\ RYRL.]8pٴf`ڨÁhzJƍuYl;SM.a{F;3YkDc,QdX~,Pԏ`` \O8ʙ*g\@ܾ1FN:txRVU le'iЪ-NTxJp_ {"70kk1fYax].riyXa}Uz98ՆA;nw$,Rko=ѻ5?:{`DL/.% ^ߋ䳍:XB^eC#F`~k&,Wi7~犗؎ C֚Y]'S7|IV2FZ.hu ~ȎK UީUEɊՋ=c(fM萨2 ,H71B[@ri'O *`͈to> tP)hδ[nHK ?@y|v!}$=~Ҷ@ІM)Kr 4nҙIU}m=DfQ3ۮxN Ľƹ.-)ZuDy}sLeĒu„Y-~X@Nt֥QiL8p>T!xY}5r"#7Ӽhʁm31[(le?ƁULĀ$/]fsʡmҨ0+r C ay%Vcwjqw 5d&K'tpTL~nϧR7f6; jp&"i 碴\sZi8\HQ ݺ2qbHQp*]@;z,r:`oH:R,ha7/o-Yl4(KLEQy_-b4Qvr@f֍rɌp={ F{cEae`7rm8Y -Ti pbPOܸnot6E8أq0thL"4G Ohu9 {Z@69zP*?nߊq),B%`4*'[F ;ca6$e[fcT)co5ƽ@a_gnP0,*jX|7$!:1OKu %]׌>Pp Վmj-Zu 6ͷVlB)tCMek+O S65zS5w3p%) U[=]S)%/X7S a ),8Z5S~BqHs Vil:bfIQuDFgD%MB40ݱ1fn\#ɖr&0JS"MeBsz,F>1. 33p9=O% <˝·| ok̖SiE["oi#i1K7:`^I53O L&xn ΀%S:=V/&mO %?mn;'81JogШ)w%s3BÛxʗ,*P#`a]PuZ*GqḔND?慻ýV ǠĺeLAu?uǖKÄ?#ѻŠ`jz1o+M. C9ު *ڈ,̞UD;א+y?p(f@q7Ffm~c& qV\NzBrp+0ji԰19TBkNwu\m6wQ>^SB{ X^ 9Tx<0#n´a8s{GX5ñmpg{z g~SFsK2qd4W&9YƨshA32(V_QW!)ܜD+D dܞ->9HP{8;7L M<1:%XrusL}+qdGIz10fr)L>WV Usy[{H(C, 3k fw[ߟذm[)n}vQ`e5Ňf`th%cSP]a¶r nM("DLyW_o.NZyGJ hƘIh)ޱ2?(x.=/$-6wCzCii=g+Cs]CFD7c)f V,*`UF!X5mcv2XXyv lhyNw.8 78fX dhjouyó^H'q` q O r&LC}n+ѷ>IzxT{qaoȯs86ׅ(]1uPcYzuf@AݬydY?QK`f5\-P㉝C>8Ȼ4$*sL#W?u5jgN{|&Ow'4U 3:eUZF}WOGAZl\ wϮXRBRoԴ(vc9eG^䵔7R(>Gy5}yqÈƄI5Mnxp2;SD|->_Xg\+Xu&eT0)P_(R^뾑-Z(]1T)NyFdcaMrI8V%2,:%-6^h Q$v e/@Ⱥ ᔨq@;>s N&쬠8 D$eN^+A%rm' [!ա2ƻaaxKemp@.mxߊofn9pn0׊YG#32348R٫`ق*DSZh cBF-t"@CW Zǎ 戽,h8bm/Y`hs T/)/H@Za@'X<tI"QAƭ%Oj1(-߬bNXdNMD=#P=Dw<Ң+ h1b X(_ m;bO7@L̕1zKO. Q]ˢ ,CoQ( E;+ksOGvf.5=3xF*q?cSzb9mC$)R<>oⷜ3|Ve< vB<8fAl%G/Ձȇ'ULX%/Q8ׅY%ʹKWߌ*͖6נ|P $9lgو@2PK+|pe)MM6g2 fMg s!cYF2wpjx9޴Hgs77)f5^M#T tҬX Xڝ4Ҋ+{"x-|ւJ̭3-w 0VzfTWrm[~L_}!ĥ 밮{{EigІ'rb9Oik0 5}PփqpFf<X4J5n vOj,HkUqA-\O]qV;V~X۽o*D$KІ9o lTH9ԛS+7/McÀ_=PTmT/#ÐxRWJ,5ShN?-a wČŻ$ @/RMmmzQ|m-vPDqMWr̳7 Ԩb:C=Ȇ{ 7KKݭb&vhnm#Tb{:e)+M6/E+p٘6M/tA p: uにF;e#L+liL_ QtH5z>w-!%q%8} S)ͦz4{كƼyZq]TGVsQ }XBejOBӭ$jɝϼ%Uj2B4~- ;Ur1"NIʹ1\c\zkP,*nׂ'J'#^i L@bwْ^qBB`{KR&FQaq,CRc S9wB*+`a#kI<n&Ϣȇi18P2)g%Xjdn|i ֣ԉx2+礠>/dZN/`9/ejq9<莔4}שrkO_+vGpaM路2BS_~s K:9 #È\0"O?@zp% kҗV#2&_Ym#-E'y!a/^?DKxX}S;fi/VBD쥸1,q'ؤF[1ʪ}!?ȗaɛAu+DZ"S7,)<5BH ׷^3o4uF\z68t"*]BN_;Andݝ5P$r] ?kiG*d$ζQx+m'GnNРF{Ow;TI +hW8G. ߭ 74TπyCjR05dkbGi7FP v.ϴP֦fa:`-֤2>52L.] +!U>ht{K`,TU-u{#8s~oB Gfu煹QS<~d$XzkvYSQdNg]Oh4KΞIKJ,*J'WOZ`P#V?3ގl:&FHѼb]x:|}&*A478ZD,@/n'|&ϙBUg>֟H{*`Dmjr)`0Ȫ3޲@D\vxC臵7Nvt)6zNK) SعlTKqhי'SY6Q-RYMgu:_%$aOUjv.Sw|^qE6Z+ kUvm/@會x C_G)IB.UOܕuGC|Ⓙ ҹ|c:[,ߖdfP!* E>Q][ {0mgC/Bh5D,g-7,=/;*| '*r,K;U;x"26[ЃR(3?WmS#C2)NjJdU(L|Djz,܈{ K!^ }NϺ= (u` |{K%QH ~%3"j[:TG@2x-sSBkĻֽ4Zk(北߳ C\ "s6#μQaOid]WpeflI&t+kبNڡq[qfU-QԷsҥ \&ܟAz8C?`c퇙[O4^-ի͎Ȩ$TIPBV&'kU%b m|hl u9P@ę<wOA>ⲞFNxj# C;uk"|%$i:( ힶ\֨:t:_ޝD.6srp !I)}9=BZS qJ|0[VwdqIJz.)D65UlkrK`bJe83lj1 PL60K#=AB#:Zu'kJ&ޜ6Mk1^8i_tNTHww:7K aOVCzCtn(KmxlOҏb}XuKKEQws9I.’ҏ˕[[hH;HOiF]1tMM7;w_1 R>mv7@e(:҃pdIKWsoi"\cy|I reӧS}~$Txs3vJZ5;=m !|#`}"%@%g5_Oa)48(:̼Jul0uka121frGq .|4"Dv#6CY | 2cѷMCJ*BdhD:tH !\9Y!yY!#b $ʹ!/ܳۀ&-imPjy gWq9 Am"oOqfˊI^`91.%-[a/'9xvuP:E_u`<㖥Łvzfȋw+jNf 24;ccOR4woZJQ}̿q,Χ͙?foCs Y+VpQx58BJ (c}`hUE kgjiiP۠kc-$sK^fdIg4|uإmJP`RIL4œgqi7 c cbŬhWEvŒhҫy}\!o qڿTPm:A  , 0+;𳴙pk;z7NH[4 JBM@Wj#뵛Mp^ Md f:nYlиûEJd`,Hau >fPp<:~xOhg)'kq[ݾ<D=wɪ3M;u(Shgi3 챡_ Ognm`&'A/`+2|]r16=dD`j,Gi+`74BԨ Xb̃_1*IqfFj}'͕i5XӗJFbLgkd*t&'nԫ (7FQ,'<;=OU7B Fs'2(-jqHN}Kb0mnQ!$c޺j?B%fo<.r/r(_6Ƃ"g1KQIhaXV CtgXk=|$L.@;kFB)ܷ'>X_AWcf*11L{ϽHCVS8huھ)]NͶ(q-=Z#du~2D0/ e^%Kn7S"+a0W r1d3a˕ψDz5ASoI4MWm UW [aPF1*16 Bh =Fk UTGM)UWp͐t>93N^Ɠ9 Boq^o3:*.:nj W+3Bo99GlyZ ΞM! M_)=7:=RCi0TBb@oiU CӁ^p?\Pd؟EFN/qn}>TCe%$,vϸsnո:0H=UZMS֚$ )s딳h "F101:% V"W,8H%[jk =xgKàrqp8Bl,%Hk[cEbpn!BI e& "UL(Uqlo:_$ali4nR]R˯B;k4R1K4,kx+Dsɞc߹|d]#\BH 㑻f{;HBzr6HUgE=}Vh,ۣw+94s5F=b"v0iēɨdR}@qs*xoG6Y٨1VDёq~[3\/B".B{eѿAԜ1A=BGϥމ\p31WB%SjP}YbѾ𿵃$FF(9x.).QF6QކmV#mMR| uZz}2.X>&4TskkVkz.lr&O{?lAͫޒŰʣi˔aTNn 3Q'hYB7*eVpLGq1}T[^BH ltb# +g);GSDL=~I}yفl+ !Ri~]QD!/&RGK؆QcaHr:AmfOTj1$zQw= 3c"M#.⎪]N<%ׂcvTwpi BkmOWF)ADbxRR?Rm^zF?6k)Ml˜y.SRyo8 tr(SBU AvXI7 ɒ{"r0:'EfK xn! 3-YqU>%M~>5̒Qƴ $L ۂqF *6ŰшGK_"d/2&?n,4"Lu5߄ՊRڢ~v\+j_Yb<MƮC_NGL )Ycp"ԫI;'֭'=g b]3I}g_R2TWM}}oF5 7: A_BBur'4㪉kMjM7P#_Gő4:pG<TФ"Y*ZZ;ĶGz% ,g Xk_ԟȜL}j7I Q+ /ERJ~odI=dVV[ov6䙍8}IB;S|,4-ip\Uz4%Qs æ?Zl=angX\K\=8OzL6yof?XF'} g?DWu& p~Vֆh:p@M@@swP̖q)} u-Cڋ\&TXC3\ʂ`Ad]dW킺QƧ5lܸ**RzOh{JJhآ%?*Z[VT"*Oe$Uʜh#8vԖPz^x}/O#Lu,4-u3#魴-I0?cԢ„xJBl~dy#tq+ W78B ե#z?x8PdmM[<`Ŭ4u-Oq[7+хsN] nm~, e,;n]XcOU7 ZOP-7Ϧ Dwv`g JiY kTP9j~_sy})Y@|!C5ENb2n̫>/9LH+sZ_qԸ|$c!vڳe#LJZǥR&[J_{KەYVF`_~: zW uZAڎ.ԫneHvkiI,@DZ8*]xo*74Gj`n# _Nsn>>"Kv̳Wj@w0j @[ghY ܪio{ X * @ٚ8Mg[ Ùb #H>r牅+9/j;+GJթ~/)0mmP7y%L8ÑfVמ[j+:\+ Oڬ=m%wH[`/%aXC |x,w@zw)@0H ~|xX6P(?ѷMSu4o74v'=u Hc4J>(m>&iȫyWVntE'^(<va~̴oD"OwrZ振8.NQ~4xG֭&u6I)b#) s ٜn@)Ѽ)(g"wd|ebgƷ`'4 ?S&ٖU)E2 ޔ(K7.m 9d\JuuosU˺Aۏ_;amXF"e_hO6zu}>/10g2W G݆0H06I lVc7*J'jsі0ʎA/ ֦7iyS(P:0"p#З^e'Ul5ٶ5}/JQH#KYiA4E1I׻hx6MJR J Sen J=NWlPZ=]v Չ",2{[e,xfyU!Q1uv[ftg|psot̮S=):9S)F7rf9 !~캎Fa!rr{BG93I]~\clv+e Wf |kҲD1la~7=NMg~q\(Uמacf81|C6 ڀRs `xwɐ2%/4'PgHtK 10` 4b%!H Mn"1SPT_5,+^+,0B~vS*=\8TQN*Uєƶ0MdﷁpmܹavL-WdɑwJ7^Kdw5XPؚRc|ϯdjdJ:# YeE˃\R^Iu)z>y99| NZmtM g# Wцb;#|0gb$Hq /} Rs#Ny;k_M8n`j2Ⰶ1\K gb@IV,S쥭\tDt ~JZ#G0V*^2kZLᓛ2o4m?ѐSKw~k6Ѭb 9fJ|joKJ<%l١$?*ʎI#2Zw ] Y2fr˨1ޣ=c5=0uFlNFS'!Rt9včzM9 g qa.S>u) ="p1 L;S}S]aO3)*bE+y1O$=Êưfa7O9;u`o:ǘ{ ^|CXe 7 Jo'+!9T>$N3ۀFZIH?M޹yEx\x5״@{LJR,rUwhfiP /)s떿<=wOo'y}oN܌bВŊ,.$u@ƔT&93en\(\ZG6"zy:7N[<kfed1B+O7dCGV+ ;SL;mkL`B,zuԶ25_-n[i,d^ԽO]th/yټWeM)= \҂ CxRfymZ׭lg4sP8JxUׯѻ>y ἲtxEx7"lh;BX3ɜ%m.`)0pfS7!%`pʂXs̜;1똙?qX$/Dn&E!oWavgҴ}L ۫3}sʯ7Sp\?*ZHʗ_sjLM4\3tG/EDf)%QOjOPtG8@9Cv`ON1;L>פwЏR0``?O^G3Nd?O0[ dGWAA·TdH\C-X gjH"~!va醍U^Lqk3N07!ڄKzs35}1=M< byС 3qJx[P"`҇{#qP=Egb3.E{Dl,?+ uʰgO]᭶YUIƉDlde_$ʿ#oL/Sq>&AQ5gq_0 yK`h8"ݲ6LOp7'M+E8/t!\5mͅlSO!U^$&?T<$_r$$[x@@1ABG[Q,Jl&¬/ޗ{bY"tλPV&Z^U@EK+‘nֹٸ&v <Eb_G\erچ 4,ϑe ΟQfn- Ϗƒ;$)mcip rB5d[+G@^A+)m*x|b'9"t/H4 'КL0*wi"Ib k̝V2-;L1#%؝yt%Es,x.]ZY,$g-iAK=zqj19M>j`mh?z¨lFn(meIKlѷHhߙѵ$Ԝ},3Ng|#\ӵ]pmG09o:FJ!͔@Yl%@ݪ|/`8xʫEile" x_jyc_a 1m%8A,cV1'FvʘUW s+]=;H{ 2Bµͅ!>/T2t$u! 3atcZrV(m7št?!q[cvBwP޶R*ӓ '|xQāRms5#>ed cIV{r (R$ܬIʖrCw6%X,۝쏙vC͊>I7v,25gU!L#C%K)wC'Pj=tFZG`lqOSaP#2ǤF_e y+y((v#`P)Xrg 7/ (7_&Mw4#cPXeEk:F;>ϑBF-V引aبZ|-O>XC4̫j7 ų(dQ~b̠FwPh$ByGOʹa[~ ԏiPE}NȪ053ʏ%mW [zׇO:HAk~;Y?bd͕ֆUqA;lH?㢦"iL@}:@F./Z%B7If|?u=w"bIʄZ/FK᪍"a;λEڀ=ƒg?rAW-YEˠ:v|FNi8β9@o(tDl'}+Tt_LM'|p`G 7r7]xL:h\YHy툻/8pHdwTX0`htaVq:6p rq3H$h*=O/pT8.j4JO ]ƻgȖuGz궺H$,<27~XHIB˨uA ;REL7Fײ(L޷L$p=~b% e${9"m+Q[$ CsK:Ł8.Njv64ECޗ%·+|N Ӕite&06ºZf\Xuꇐz "vNhF2C[ 9j!~_O%H<1#Ńk$ÉVW( ZXаԌ]հ%BGc+Q%;`fw9 L:b`x\SoZjs\<2Ow|v:ʾݷ;KmeĊ:JW=ykDP/zjYWUE:J?ФrPnI#}i@1"``Jb[s <ϲ`%)T7~qHW40JdVG@ѷYKX\2RewP R+a7(b*{ڠ:}a꒥>mk4%ߡy!>AC g\ ?9'؊-yHoɞ\msF膤쬉LڑXEek"/UobV~JĻ[a W9npɵ&ܞ#Ӽfia$CIw-3);Ȧ! Zv*bk;@UA1u*+gAչB0`>-D/6Am\.fk_`;PVEH92<֯?ZN;~m|D^uődIގ,^D{C]ӪRg0,.pqEbk"f"xhPJbOAS^:| `;.fKzU͕j9,M(/`{I/T_0ƴ#) Ew 6wsX2ϝ@&Ūx(/:$ڵB2, 47_MǥɯKDeuv~˚RpY.~f+?$OUBcF EVǠ9V#ay$哟=&g r쁓|'T.LG*V+@(/726ޣٛW{\ֲu> |չRx I ̨Dz.גFnWgC ùiHVߤ6 :rҡ~&[aFUIXϘȓ~}fDFI6k~ZK|'s94jZbJAwHXBӜfH]VW}U,Dh+o'"m +*SuMǩ5}%_*o 3rVbd~8XBfRvVCQj)NhE uo\1+4UK܆{h]qٖBK3J,jyMPyWC|[۸EVR=J+6i,! hЙ$T60E0J5|t,Xs9wTCm2-WQk ّtj? u[ҵKW[ ~$G?U *h ˢKw7l,Cw&GbG9IH>1̦V[*CrJ~$ˌ yOGx\‡ i740?F[U+hs]D(SbXjp3WN[g,ݹdS )9 IVwE /%- 5WT>0wmOǟ/ o2Kv{98գz=Xo LW=k6Kzٍ>w4WO $(zyQjy} Hx5yz ۍ/y[׹P-ض,:_hF/W_-hFXEι=!oΨKK}qFYߝfYJ+z Y{uD߈Xl&*FPBxwЯV[2PIC^6Z7èfgk;e"mI[MvOQ Ixy}AЅcq"/ԕ8i9Y&3 F7p2et_v$SK_^Yٔ.q'ԍq]& 46%h+_a#:*g%\j3@+ %dh=ZvJ +iMIcAn;͗e-S]=[c! f8ʷӕoFXl)Gfg+h,SixUj5g&KN+ jZ]D]5.JK+v:[nH_ca=;O|]ꄠW8mr(=J"$s:{N@{/Ldd첿@eoͭcOk0,Ps uJ2R׷' qM?Vp?S NUI;3qHnL@1j۷@sMyͭĘ5A nm`SV_jZXtk͹}Rv-CKu@ /_2S0t5nHO6zM&~R, }C0Rnr]8WC&/}g<@#4GoCGl cl}K05 펮 51S%ԕwEE/QJXKCã\5-apϋ?^swie] b !'A:EX;r&G_yՙ.*)@+fA8LDC[.ZTb[43wnn>6Nwdz&f ^HY3*hS"5Z3e?pS.:X旣.-i]]J+M8wv*h^gժknNXF?),U69ݛT.6(쇋%T<ȲBf$e\-M9GסV0Em.% /ePaX!\A9|m)^f#ĤН%"-D55*:B`fN }/ pkWl~j-0/ձ;>MTQi>7߱>%H)h8^|(#E3 MLz>m϶ al/'_"+Hs+]" Yϔ|,3Uc15: Q['nF)~ Hy9f1a&eALJ(ۧc znMr0=֗6}ko{:.Mk0D֌)CaQp4#5|Y1Rf$; GTp\sfˏ6Ltt- i"ЊM Y$;lCAp[dpe~meDI[` s HX<'OrBN,c/W^n`Ijtδ!Y( V MӃd .yJʦsG~7cmf;P_X9RqUvSxTr"Oesη*#DQ gqm |xPn)# ޢLɵ\&_̿f SV~^#M6~79a Z;#|qeCӨVᅝ>+@Y"6jDtd >>[1@1bT**,MUP+JH_g~X=@g50l 5o:Vk$~&aJJh ΘJo;Emwke,Y{JpGRTҦ27(ڂ漦z<8D$HD§ӱ A= 艑}E&v†0y{.w`UjR}X{Ύӈ9Oـ2#8YؔrpMR}uSzZƴn8rV D?&$Bd'j HRI!YvY!6)3&<>L {~*1>8GP:`Ue#,&aZ <iݔҥ8|ktPuMa!H0 vnM&fE/ mۅgfΧpxMBmD+3ϐ>waW43rZ_ ^&٬nm `{i \n&V;Fl[Ah:$9 z'!o -DzwQIqen%y^<6)Ocee*G۸E>&]Sx Y! |zt%S%9u>~[[q^sAd- KOZM/k:_X,K#)ld􏑌W@ ;ǥ;S1~-ř_!nyu6;i2R o{Q.$j(Z lē&jy82뉝ej{ǽݎ uXhu- )}V0?!G."B'PD>ZtEA]ҿkN6GrF'~_, gjeYsu葛8lϳK])qv٥Aظ@a} XT]#),h  p~\[Q۪=Ԗ~ey_K54Mx~O#˔GCf?OppBmU[Z4{eOAfWb,}pDw1xN3-Fqϛ^-|a0,zΞ !dݔ 31,0m`J+Dbes'&R\I0U {We"!XWf`rJu]]wmJ:KrM/:Yʍ%39sSDG/Ole :S4eAеKWٺEbQs7,}A_ׄ=Ѭ|pf4 'L uc6?+\EŬrQa:1WkGD0xJ>[1/a}rU7yZuq$'qUH$Y'##l[ kZ+7Ada_Ő96”Y>ם$`\gX`S朝~$3$ytcD 23hQH}І QC\2vǶdxǣm\IcT )U)tLko?*9k=v r͉I4S&/ "(bneT#kׅ͌>Bv1_lvj xTn5KoTgYDҨ:p?:z-q{">82Du&\-MT"b&Nküi*NPBөTZ7*Pz2ضnJX٩! 8]>6*u{K+-5.ɄPnjw< P B% uH_)6i"V]j2^J.>Խh=2[:Z8ӗܟaIA81װg͕,Ϝ^r tB%;uާƎ(M^ZCfF$WAǷCdRc=(P)rD-n>2XYAy,Nԕ ?=FL !(FP3[|NYɤm4׵475n1.KCO%ۼ!/Pt LMynqHmS^\[wqb?}D7~-]185tzlZ3 K`a}l Vn /\K&;O spMsp .w[oUk{ß=잵 g(hPZkh#!EMxr__Ζ /P!#e.Kn n%UL6ˏon5 bE%x e٬+2N% xȏ.x!n/y3t9R ƴ�5YEsrq0EpHllͪr+*A*9bj8JUdG2z:fP@asQ颢Da0&%WUUitQK@\h= kLfU[+*AdT VpB:jYpu$2=$͋jr|.eY Â֮$iKyZoZcـtxqMnS]hݼߞs~}[uƒ"B"|flWAr1}{q|ĞRVV|Bx&IB.#0_?* Cۍş#A2347#eRL]^*M}CިSOLmJB NUR:JkN gC:;7 l( o:̋-,⼉̶^Xgmc;'ay1RgMԼy&dTO^|\tGq+j!6I={\Fg/*E\='D ;.\ ozz@kKf¬Ƞ8E#2̸\=7GӷdcPWB0&ێX.}o=8w\0޹͟Q6dUGb3 >{[Xeg\`i8=rP@X6hm A%Choʩ`٨˶ %x Pɧp h|id gf Rhv>fIc;[1=3I-$޼gY#$:>`(w- ^\z`#0anQ ktc]ebK>F,PR}?w*/E涶c!Xler&i Q!wωPMK߭BmB#̩DzqqS.n$2A'euR@|e;POvZ$3u";ղ}`S?aנ߬9Q"g]F#F?Wڄ@kQ5 v̂kP8-_8a?I)J *PJQ9oV&þꀘ5 zkkav^JcO), '"'癦&~DƖ%k"J$ })  vz7!!ґyRʸ;Oz#;N}̋YE[q ͟v+0Z|3 ]uR樯|wܰ ]0AS. _Xau סp>4&%b%~|1)0C,):3W |e~e|B XeG)dn,BSDԁ.ӹ ;SFBUdT6 k>BlWjhL#D\dQFO}lE `6bC{~wZ |31qmY\J p^9D7?)ލo0nZQ{R5VT&_ `@Oz*/*GS בnӑvM5s}gr+ZofCRs}I^/u ^pQЫ9iPoY:$Rx<|EsAMڣbln oORmK* 6f =lO$끴} Pݓ ǑQ\R$@ {n0fFYXiDJc`^ >'X/ZN>K%2laRr-w^Ց`x=D Sۇ9 {hnc:2l# o|/=bqM8Qp.A7/yaG TGC~+Ax!,&%oAbF*cEjljr!543W})&1 _d\3xm(=qoXfLU1&PvTA AekT̊ *P܋셊D3vE@et7L':z|l7T.pp"Ottp B:(5$/C+wݤ#ֵ &ͱO|\F4^ 7烱󢙃ٞV" RtٙM5dwB~^$B<*ޤk}|Cy[]/lx)d,1`2ݖ#ƢƤnaz?#% Ѳ 3\$hH4+4Y Yu"4kռ~}&בKK_k"ZLʰ>7m=Ȯ : SߺMq*yYGs2|4dky|ϡYynzĊ)9mV sή*,.*,)>_,jRW:DZVڑVl{ˡK>.-ᔯ@^r 9e"Uq-j~0KFb2T bǂrj$:|2M=)в{gtY@xn=d%DY Kb"2z@LqsJ޺E:[ ˙RA -+Ycp)b~EZԼP6VJHJ5jX$ǨrM%!ng]m,ld]Ua[4Ѧ^y.AB~ :ֽlX+@ Θ%BsYu(JD;'e *;ݙ|9H4;ZH4-h`D8?A\6 w&g)W<&@gB4 h7Eʥe1 / `!hOKݙY MouF:MمI"# u*7KC(yem65}ᝓf;c7yk1hX/ W <]{,ꊆu#Rvfc0'9$7|"JH{|,T=:o <2`G=AkIk:3>ip.e .4qp#xGh-L+2y IО 1N& cKtMҤ!QHt}R:2"HWM>?A)8J`R7h$ڤ9ywGdu]ѦO&UH/'5 qK}Kd5PR+7k]l<`qپ?xAˣANfZC\1î5eDց霻~rI۷3YHPvr4#ͣ{S6țoNsvR,:(tkt^Um,脻QԃuIb?p,Mm Q\ԚDl[ӜPKP@&\oS*rp@ E?b`: u˧jYƎ3f~- je0OnlGHu}[O/ oQ{MzxlPr1/#2/6Dj IX _E e(ަD5 9IV?m|7s._&._qClN_ BŰV:vX9D"*58Czch{uIML{S8tjY8@  vG@Ը'ճ$ 2Zgn(~34)KH [xkNa͘0 :tƛG93tMB8ZKR\I鄇jM俵7P}GXnifaX@]ykS:2, B[n $ό`M [ &Z[vdeM@2X"ŅbQɜ,pcPPn[sMi_9 2n!FNA랈^YTE,QВԼgU?U|ZF^^5."`s.GHϯ%}wta+`i{j< 6L-NhW٪1o+g_D2@܎~4!Nx?Q]γn.ؖ'#v|RML #eE`2_"݋)zhG ) N\y+ n.\U9,>"={'BMS:hkb+?ת=FzAXALS%t# .5ii=k0c8UKM{>NOГOԗL2L'30.;ڊvi\$+2AmʚN MVIQC9Қ>؂{Xk!SPѹf=2dnf YOt!`~ொ?xqR"Ӽ!߀ Y+ ]|d\v5xYj/35wo#ZD6ڣ,cՍpyig\7 Y`>!Ǜ. ~wڝT JK4w"rA{֭1c! )NK 8/rEM@H ͖bۉuÇȍRm uj"[kgت*5 ,뒡58NX ȳc< -Z k ?!.uӳ}L_"Ýc Xk(Nt)G1Ʈ/:tZ-#Kx0KȂt)vPGX]B*CV3ri r; ]yM`;"]JR zAϸHh<>3Tb0H3Ðlxt5P } + Cݭ!ʳ5 Rɇ+(- RR>?h(^fF*L/nDܒ *gCWD' y]\M`Ṅ b{R~|¦M,ѴlKh^YQ@JX=`\%Q[QLt2~]f'. ۯ:ϰtKS2q=! w韪rl(t_(qœE'`~G]N2'R~ G=NW:.Ϊ4RSdsAcÏ@DE*9dj4eRt-/}3i:#'\<#zLO1x{}7˅9*εn`[S (R.-Yyg^V|&8gWewU : n[Q E񱿛g?B!)Uy'|"ȣi;wC!'/I-}ΘCcHF1 ˤucѕ۫mNzʹXXUҒ[%r[߾ `Y/Bߪ X) 4/Wi|Z!%N.>{w;5lo'Ŀ#>2fժ 0[9&,8 n5NQ'؄Q"w7 ^B3u~['NMɌnYaHq&H吸xyaQI B$%RZcb[Yت\l&Wv.t\RXs>t!r:zB5ٳ%v;0ʤnN9ᰂZ wsBD E [>wùXZQ lgRʜ{l}o?vcř7۷ud\ʊW*a"%H+ߦ@T(ة#~sLԶ8:ݎ ,#[_)EC4oFb|};/N*%Ly0CBV*>QޟiH\9kmk9&N1ҧEg6i{s8LFh^i-bx P>#6v;  kY6ԃw% ηZGuu92Ҡ*Bj*z`v3dcH֗RqS1⡚khf'`(Q` GidlGӏUtN_Vݴ,Rp!+Ngb_}LC}""\*/TUvYB/Van%{'},y_T:&Xs^/"0~|:R6237%MGLikVccUwxPypR\IhF3 ڑNlOLmJձj|S~A:)0>!KG"[,QୋjI.SgZ0-S׿!,^; [o1a l~L)"NUqXkȶIG$P^6kV{y1*-!`!çOG)8 KG|K y_#q<]&|%@BYxO |7oN^Q5Z |"1K -<՞o1 NϾZݔ>kE,Cg#B#ʹ3@iK*9 DxðP!UEv&U,RH. {~}yxW,ʜ_Zާ[)cwFN tj~l%Lĉ.kxl֔{2RE!^9@$<<*YK,@tjz/K {@X 3BBl.?EsVM>+iސiU!K&)Z8Wbqs1g} 5=|,L1 35 1Gx,Us)ʘ@u1gmѼf>&ª^+ B iV7?ΫFCH(ɚMdh70j(N>D%0Ť_Z[]څ_,|ew)) cFk  ~-pQz9GJ5 B|rb{k0# Ai(&eEJyZ`4,ah@+kN_i"`ZKt;O3WjW){ZZ"^v|JK-67YE.̶ZLJ aͻb< )G_ 1hjx*|VmX HNTER!bӽ8 +h`( mHIu]tW-u|?, rL)!aX^`/̮YanʇM5>4AJ[i$BoZ %+kdw!%;5%ߊ`_F\i18V ɷK~C=3wi ͍XБ~*v<5e#5%||oDleo:wCT+bF󰻒V܍;hs$B9GL!x\C9-qBIDԀԯ i4(i0I2bQ$#J еUN7|9=@53L[L5/9 E2t0NK@ǜ h*B$FMOƎ)نQҘ1)dc'1#юT}ڂb7b,Lܶv8t7 :* kKʤ`Գ4?:L`;q Hvr񤍚ۥL(7kD.Kg(R+4\yd4H[2 WOY/ݯtܲ f[VhFRtC9o nPW,[^MMJ uL 0W8|8QW!43wZf&)W &5ͷZ܅V#}*]]r/b7˟/O&'ZJ n/Arh}iͦٻ?_7pą_9cWS& .E( :qӼZk, Wpfg>#2yLȘtˋfP#}%5$<ݲFsvpטL׎*-i0Ig2|2H!sq^I⚦$쩖"'b´]_Ш?SG#sKx J}~[.5ŘKr R\P!-mǼ:g3iW\pbL&ZwQ>I¢&k ;EZɟk2yVa2>Ɣ'dXj_#tYΒ,LwfTCw?X-V¶*a῁X=,~Fm5?_!)Y#%lqCN%G \V`^:hR \A#OPӥd[}{NeRu*U~L#0\7rԺm/j`2 c W_O=KƎԷqUSew çOhvXK:?Y1Sg I_<0Z FL0?.Ux൴*F$}p9Ej(@Wԭ݅:lBZ_,q֟ϖ'36)4;2UqGFdDxID4$F֚lƇ-k>Qԭ%E gǦ;U$B`/.5"<7PvUC?0T̒`^ 'P C,*&)E_SקQ/#Q˹g>C γyVϷtl\ɌK}j:w̥:ilR5Q\ >V)H1X k G̼:I $t+"+|}) /&u=8,%Zdwy&uyw>,){&[->"K=\d472%ͳpjȅvW =mQ _ <p(ՂrƠIi1!+.ns# }% rJURL=Kaҳ^jq gPtd__*`ߌgVڿl!?A;O$0M\B cXe< tbXF f} Vxߋki9"R}ʮ w(0[/p+:΃Yll=9U4ڢ:O`omc}7xvh1bo\aw'΋,TH|uD kߊ(D."k]^Ax WL\8ͣ8 Rs xνc㞭]dMGGnt;Lr}2Ǧ_$*t-b-~{wjC`W?\tP̩i2(jm"xYHLLedʯʽ@ҸbQv(*Ō`/]CҎ,H)S oq/&M؜Ą\~B:Y>l2̕BȺ KKR#g%ij$v.XbŰ 1ZBM2}LMb6aka6 R\@tc^H@7qTѿ!層^;ͽCjltQ"ޚ9aMHD!IBH d*uk0mw{5oc{ KVȟϩc,%*ȳC;SKCjG괋Y=ւ2*ޓkZX߿I|5\ "uWUTJ@>!Lja"}Ś<߅y3[@>e0B.;M_+Y{՗ܔ})w?vy2 &I}mKUD|t~PU}2pzp0EUtb5I]Hs߾9_7+,E7JjZxJǞ* @m \(]Sjr\0 1B#dkDŽq,oMYR` ž ?J(OA>ގ:9S .K$(k` a)/f/"d`덀N!pgOTv|WV~/\h^ *Y+CрU"1OhA 65x۫^&%r#uP~Eܽ'LhbM)h&G," {4`ڇR^qb( PP*lӣqO?UK=Xh$I֯~BW~#rlW2t !ʼ̣si@$sRUSuۦۛ= 7@-H b:yUԑ7 U|܏Z,F/ȤOm:뻚iWF[9Waj;Uu2\7"|t-m"JBrZLbGk76>hpv60 ]Vx {:gHȜTWJvcLvP7TԿqrz ޞ*]~lQ46@ާLI-2K\rެj rW]&m|w֣ԙfxCYJ&l|\:&j-foJ4^`x |dqPù/oN/t~7[ G 85݋"StxY`Ѩ:ϼr >EHqiRGs{ʔ)*Džc6ÓK-yjtFGf`j!*1Mkz%1M[+r  W.MP*DԠiI->3 %jlSkzl[\(>b5'aPGɮ_5^ Mʮ߀x7ù-!xKĉ]J<2:W ϥFM{zA-Rq:#MoB4$f,WQUB-}}oF([Vo:F#8N,{'f*u 3D Ee8n%Qdm<Ů@B[^3GsxHFH5E.>z^ũ%IGW~fI:^<2Ї>~Db2_y 8G15Q@'-|w$_Du{dz ka.ЉKr:AT)]I*8"ÒsksjUqD୻-qM]hBSъ\Kc3mo8Y6U41H<Xsɸoc{f;jq繘U(#M4?d•X<УWUeCcʣQ%XVWљ:}}ɷ'U/ց})b*BV7 ٚ(bhD2|L }/-E 4-bSƥH .v]}e&&KLv9I:b{|w ڶ@0q R N.5.v SYK˛ߗ #p:esFrj޺N6-09uD٭&N:>=kMqPD&QzoYS.y Fz10ki$+JwxQq7o;H܀JCvUsQL:eʕUGcpҊ@VU>gJ;=G;zڟU\?7Ltw>A -0hk&Z wK8⿜uÿ%;Ĺ#4ӊCTwZҘ29hsh79tǖWV3ߴX7)ۥ:4`*_&BqxMhN ${B5zYUNV>TWL- hmfΑFD|9Ed^i}bFH$w|I#!+cGcCll{ql`=i URD0{v}^մ 67n"ZWNu>TJ6QYf,&pN[ .1Ƚl>4`3>ٸ? zRު_ )tj1'xN`N篕M䏀,ݶ/b@X |~GcUmm&Ng1$f <^qtp-s(tZ?s"lm~yeJ8+3ݴ?0zU#9rܦ%"I8A3A:TQ6;V~BU^wt KI&#HHr*C?M*/l͂ހ>%.:CPmB&uT]GG#,\7*^Bk{?RV&Zû3 1je% m"}_ ;=V@(~KOdr[w =yK.0|]qū\Mx:6nW$*ߍ[z-pvƉO*iMm%W?zo$IW66}*$BP2as FM)e%7YH `pjB"PmG;[zWdN?94ửraDz|kF~ 6!K6WWJ}w˩y}Ls)QIE <{RLx8!jKDQfΩ?Rj7-Vph #J6eV<NՊej%f9ju-fZI H73+!0} 3އb̜qZd & d (N-PZvaFtѨ y¢mk p d&C El E վldrև%qtG2-cNep51r^Bذ Q$'*lquZu2cvȌ%‰/qHU٘&Ē~:@%b;{Wp)HuoBD7rR@"{aV+^@y=)_va̍'wUUɣp)ecc`$&JBhyDE(fꉍQ`|{JsX0~qoJ#w7cUV"J 3nҟ/= ;?cxг3)F_~R_W;woe^!46́H4mmzWźdIe/eՌ/6S$_"H JgY\M>p%Br2D<.rQOk 1 7RbkUnx'(d_'/ĞYn,Omݑ l+vlߦ7wFfdžr,r7=0߀Do2qUN>lP~L.R%MkҺQ\ɵ$nb4W5VPVL?)MT3sMb+ 226lCы/aS{ dOJEl.p{|QmFVL W'R|Q=ƺQꠈ }őO&OД<>pDž*_+gKU]1xra8{2~N4a5|ssmJ;$[Q¹4Ղ24S;k;iBH`LM ,8K{da7T_=-룟H}_YM4: #ɣGf5 I{Ѥav"{'~E=dtey;|#}Na+Ph0PSd)")*EZ[ o)x&!Hϻf"HmC,\.[.iK}.xT8ܣҩHGSUVWԾ_ZejJ@V \EmU02h=RJp2GKa,c4 hs+֎Ǐ?cD?e^&/zjm5Sep?,PR-<7y M(2m:o_g7=P?#y^,84[uW%dnL6d1cUIط9=$*vO XΏq&l XʪE\G& y9RR12=z c8[׌3cs ~)~&Y Č\'U7*3BFDK ;`[;.,Lq'3tnv (#C\MnQb߄[Q&yFsJƋ>Y-Fi爜Ȯc%.AW s 6*~^x/A(^y:#0w@dh=tf*x m4S\ϑ./DfbcG%.ߊEUTJ+fD=^fF.D ; cA-bz(8,hhl Od["Y Q賌[ [Դ8DUF-%!jZ$я哔XfZѹpm9]Ɓ 'ԕt.]?6uμ1L6bޝπke<DžeNJɈFr]Bh6NwN3,6M4˵&Q_yY7b^1K+cf w4iX!Ag(- cuIWYJ6tLU4uƶ2͓W :ď ټ敋 뮞_.0QE3@8 Y-Z{3{9։vˉt5uB~=WN8[ 4y?ylRvWLeZ̓0û P߶٣dHݳoR@u}N2TdC|[LN'D!1^o C@"څ+Tñx>1 .( HQ9}zv*Aò?)UUn?0$j2osMq>1m)}g,qjVN..:N[Z2*u]T^LG jF,nF~ jK<G.4> 9o̴nIqc!G8V*0^ 餆QX;tK`Wp$#7s&΁ zeS"/<6*@S}R')f_.מ.d WwE]&D EsǮFw4e{%D D͞>;tįGˑ70'v11b9{HL \>#Gc[Z"VF>EE4.r(oA/d {;ǧ XЦO C Z?p2|Az0iMS ?~sː c򹅛؃'!a# RK9b_,{/")5=nvj/dzU5%kR'ƀ/>@j@!=sr Mc`V!17tc6C|l7HZ_s˴Jw!Tto E֣wZjSUqhSr]1_7몄{S}KpQggP,YX9FCوWO`grrΌ BƈtkcZ} 3,D v<P)"6 `g >&y*2sgu!:Uoڦ0579UBkZfADG.Z2^F{eXްlO{|} +`9PWHtgfvsIyxS6͒1YAUxkJ|%LT; Ҋ%yo) %Б\eR>d}K'`TxxaHG.A3\cnj:#Mkeᓬ.(UXqVM'4fSqc'&N>Y>$LKVj& +dQFETyGb|^`gػUGzS;`-H!m¢ ЙU`-aZd3L7q%q"+~AjuUMn~iAi-{|cpz+陂F'Uj|mxֱߘq%g|p3hl_>ٜ*%oXF?^43;l:̊*I/G;sz K4 >iEZOԮb T" g7RIR)N)ĥ$c9[5!y7V-Pht0&=OhqSFXl mh,tClT5 X?R3y0 @I~79p'T\KC8L /'Sqd墖FP;r"qCi<(H1l 콉}# ͖ȊⰂ$S NWp`KBV43T՛ LVT9Ѥīb^`MۊSǤA. &5m) 0|:w#3j:K a_B㯱VD)l*I׍!N؅.C~&Xpuz!4%gqN?b_:crK)"C5s h{靫ׄb4[0{n"w!9q_()GVTQkrQSud*Sלm:X9vA^G`vo_5D)o/m @y\Csvg9TWzH2 d}a~1,5Ҋi'oˆ 5@H @uBhb:o~SSQ?>(PeʻC2R=xU hp ҺSw62&/WЊ&&d)m`o/Eo`_㍚xSjUMEp[ɶezzk)Κ⹆$bd-h4rڦ⨏_N 9URF)O0tIS$|vV=it X|ej3RE3^zo%Bϩ\Okэ]IQ `F@ {L|,CEJzپWg $354Yt"%bmdI 8^|p]7}~|/Sbj&e5ڹL lr9c2KZ5}!jn+;;,\ ~.@ܾ3dJ}J#ҥUK4S&fԌQ>" aMu=Z~OZy91c.}n 9J8{>ItMxS=+{Ռ G}o4h"͑t.%lgw f@{ӹa蹄mhsJGaյϋjT_!/[6i [6𑅨.FևnQ" gmK4MO*+L;%!w*Ӣ51@lHN0k F̗  Q[xVf%.Y!e9l@zW6+ Q"S_?h|gcI 4Eְgx'P(.n-В0t2)ZTiC'-DžoLIo)$C~A7]?dj֑Fˋ_Uz{|gekݑSgK>5:DΘk$|vڡ`yI:7jM XJBϩ qtQf`GF kC.k.4ʉsьr(" ]sk|g;̟6$Y?pȒX5(^tZ-&ko@يq֩zJ$"=2*58l8:_eu@ndaS򦮨Zl*  0y4#Xs6ÜҖJ=ނv3o}q|g+>_5Q5ܺbf_Q1-lbfK ꄖxҀbTP(s ]j"TL8%~ɦϝ#fy9Qv)Vk]}RE]'NC< Mxk G`g/?=2*XØݸr~ >RN󧮄9c~[c 8Nhu4z2XS+|ȲG9BzK}\GrT}NAzQh34,xi:ivKS3V?Ņ&L:h1GV.RR0t/[2BUrq >+=xuu rEza00 BE͓%Ly}S1O ddZ={{!4(eP!q54D TWwXJa%#)|cӲLDr||»A+HNszbJl) XQ"DiI$u ²N ba.ǷٳPC'g)UݣI8y[Y>LP? 6 )T p6smI ҞEsؽB7mYȐ7o[THY/rPoSߞ jox"c(od|TVb4&0zZ(Oi܇].nxeT12H5~;jscF;Fȏ`vwGsoލ?933 QHpev4ve5{m'OBNjd`rqy Z{ضwYY'&C~MMe~u%E(z6gKW1E*JBƄvuoѨ{ūoDesā@l22ڥ F)k7gtĤ aSjT'[wzfL x+,ͯϴH&%RLY6mEݶX\_1ֽ7A/S; X ;F "-IQ.*GwO,uYS!RWb3ޓ*6 SajMTpO)๙JLμ,Q"G/߯af(\`.j:pH%({q $cF hA >]%F"Dˑkl\~~J1Jmw]OV2u8OAeHyJ%o{t%I$#OU{f-pԜ`CT0`MyW444ηӰ)c?IUTMITs'׽y,<$:B QE[H\}lI(i!BLYa=DPUCspH}Sضs($z ͐?OB>Ǔ]/BfzS $8H)sPNih@ ']τ QOjxOe`>Z8m=E 8W6v->[L!:$ 3ov zȺIcǒLhjƭyH~pYz.cߦ\#_HPVB?ݷW`C |5KG'x3wAaGH8*5tp4?Ut&2.uGV_)RwnPvMƛaʌslHs0%;;T{/`1-CgVe\K0[Jo2++ǔp1rZI֏aNH"ߜa^+-YDK r֡4ϯ8baS1{'g+FrpETtsņ '/"4U+=@x&X򖙈)@Q>5ԲcUY8^F$`z|+io5V=>Eu-S}2E KY(`BrHU{hmyui# FlѨWD`xoIb6B gb1J]tFjcқR[!v%/R6[y$][!MT}{w ?TY7[8"GaV'ONgqluqNx, Q2$#Rώ@+s :Ρ9o'5gN.&.aBk7s@7ZN'` up[euK']tomVB 2ZgD@ϻ:]>a,YM 59yjeWtfRLWZ/!G !i)Wk]8!h0n77R0^DaIß&wR)_ElLJTBG,6r@1L0v< hiv +7Lڏ'\DKE$h ;#NKYGq? 钮C;\\ohRBѸ̑hN`B`! :ӌm r[_I+}4 -(*@gܱs F'?%P=>$4C(J;3EnN2Ydr k}'GRW. |_%=/dp0=7Bps_,l40|n}/4bF&@:Li kFLq*I@F /E\"$οV8<\mnZzA;o -7<߿Nu l|Ǒq't.㩲e>E^k->(z^?q+/O Ö'0M_񹓒z e\ ċ{m۠"WYuӍGo/G^VlЍOi&gL>X+ \!P5 Q_ [IanJA;̓ ,*@w U|m2p*Y6[q y?U')`6,ncgKM [wpw с$G*a08 \@ET*3a2'18Iz>DyXW{>GYK'diiugGІ|_Y"1GTdCv^U[vZQ.Vl)xnؤi k a_yMv 5E2嬫ZXyws%TW_ r9'}A)pwۨF 5 uFH ` th0钽 ,M2w Q rBR 1"6޹ ,kWP4њQ,aTh6$s^o[9C+!B ^Xte/1|8O ѳJ|A ܚ*HVIu!+]6x]Y]q6t6*zu/am$XPQ6 $z(Pyg]+W!{y##Yv]!)"8Fcrqg#(`a 0 vYe5:c&tC_Sq6bTxR^ \Ȧ8FCwL ESMC+Q}o-Fcbs=iTPJ.Rpgc9b"qhdylȰXd=b弾 Xv2dUd8y07v~eƯ?gRAQrzcP.g'ݳfL  *iҋO
yz7>&sB7?5XEr yV.|zkXbT[HB`%? JlUxk|2ZpvUg6?Lu-Q94vx=I"+>-/Ɂځ!1*F^d*v@A&cp]5)<$!wIb(I*@6adz1I[ V5p4׆S&;7}dggps6jNL֞[PFEz@F'5zTK3B4)_ò>%Ϳl̤O z aoǑi2%m4N\5۹LzOS{ixUizڃhlͿ旻\zO):p`n%`3|>Pzcf4$Wi987d%Td$BVMK$* J]BGU~*M.EIYI(BcA"m ל}y}`LμX+/yѽ36ŗQB9*d\ϾLwBMsdXWIo &mXǴKfSUN0:Iz㖤jW8H>gǶ\.fIF ~ E )|b\ x*=ܵb03DﳑĶU=G)b 6LM}`[qX;rjFm/Jĸ1%I].hw̶ƏYj)Y]8w(-3MBF6G)(i0|v 2-(:&N]G> >;Yrk[~/wF >o22Œj=G`F"\>|N&PmP2䈄;oAwr(|XL, Z!GVXK1WS ctͤaL[$"*D,&?G"N.:̟!M"^ 24͝$~>E|:dKɲyX2E;W*#Si?5BW*iX٩5l4F2ߦY8 6A3$gI">I*l+hw{G +E(*~ߋ){$~z@087֚Mv衊CA)7{IL|Po h,x1uHfh;E4UE\#gt,m}CS%X4 O 'ZX W-/m;?[$RvR-תtOiQ|3$&JL;СߤYu%< IWn@IDNHʉ. ' #zz՛uC>6#ZG&n 3(:͊jtx笻hO)m;ZQH wJ)Wo%6ԏu*MْlPb2LN1-zzοO2+ߡgIF1ǁ${b PPC^̏UU\gH }W`,6_LyU?L'jvPv+]2QIScyȉ ]w*{^r Yz7.x5c2a:G3&"=/ٿݘ xXƦ 81b$߂D*;NU 3C|~4w0E1gcn&r˦>h S+gTKHtE ^='M3K3le-Z G 590Hl+AHj ͨ$" *u`l#JdG,eZ'=DL+ E,Y*dYRpBMU:{f+rtZxyxJ$5z?~P󸕗dZ!l\mR3eP9" \ZL&x7e^%d.>Ez{ޤs:5weK܄̶Jp] AAO|_rB@.o-k(2P` :w1 B1e32[(q%k|bp #)eTbb=6~!56Y3-qeFK,u2NQ*aOAvgΖp7Ψ#95&B2Vlft" :*ӄIIآ/cV%pM~[ i =ݳ{_aVZـ}IR0/<_j0ALי Jpt) 7ؿ䙹y_xuI{6r1U1x;-d"8Oy.޳$3kr zG/%#bhC0:5?Һg"r(' OPnz}7NI$ځTkVr:?0<]< 5 jp!(1I$R, {j#.9~Qќd6jHL$-`6%V]{X3=݈+nb7\i͹SF'Y {)1PZ_<2AIn?K-W'ƞZ(kUЙ*y !H*K<ǧ+|}Obӥ^0HnV0K27kK ׳Zv#&dDXNAIhIaluℸs7G$Q:78또&Q8ZHF)m=ghSD桇;WƮ^ҭ]w2E~Tg5*^da@a}`q&$E8uD,FpEUqA:n +C1{ENt=譵< W_d 2dBGpt}xw9?8[[IJ!M1<0T}6za+jRe#718ghΰ'姮G̒!*Ї 36gm U:h~}*>\։Id;;0LnpuZ!"@}3QI(?0Aj8 {rB}AwowW5 ԩXn4k ^_w?/ZhSe8Le$uYf 5]IEٗM .,lyǼSɀo.IF 1Y|.摁fD~orB<x%UZxtX[c}RK[4U{bց9ꦑvFS 'q)(9C6,J5&c f>fOY-5b}#jZ^NŢ& !%-E-|U}IMwN$4 4l{7W* IJm(lHPd )VS*Wk-8y JL^K%ybd &(% ??oS߲H8s#XSX\y`''gڬwњ=Bpl9N&q.NЦh_W+@oemE]̙h۶AOպqp5T_"+*+|^,-a났) e>JlCUoSwYY(lIdi܎3GB}h޿Sz|oB.&$3Y( 3Zq"D-L_t2xؿRH9[غThڝ~DT!clra40hp8a:ܢ;tckB]OlE礀qsdʕ tnwpLs5=Շ?w*_2*DXlIcс_aH[F4%57(w{0!=+1ul,j P6wbEcB2) vr62&n UN){5)v巓qJl{jDnFy"9.zIW+M"'(`SB m̺ȲwKr.dQ2'Yrޥ?cgz8Ҕr)qRۦX&+^az4넻W͹z:]!&2*Bz,Fp|@&q"`-J2WPJݱtv1G_n:Z!=:elX"Sb ^dv c$wL9ɐ mY cJ?̱`+9}GaX9'xsxXmLʳbA`s1N{ڨ5R[8i-t2E^s|a\G?9U70TU\tas Us[boS"=(^=Q-2 j R7}k\%p)k3R*ejM+7 );VߨNr, :З]HiGj:F>𪻑axYWn0 ߀iܾ- dz@Jxk3:2╉$/10H-ڝ <>kb4$2wgyd,60a~/ynY:_'B͠\Pzp!U^`f7 X}A-׳~`B 2?vDb SD(dx:%}xi,"d-3>>Qs "KȢn g|Gt7O.|\+I,iE;"A{| .r%w8ӥ0@uJ('rIgL'Zwc^ z >`ښ1+{|(YW6n~nƙ-C̤dM$W 0Ԉ= zTM@ub3ۡi]&86] 0/e&֔ΰ:y=z6 o5Ew# G8;RrKC5.ɳ"n;RV?xmGj_8#, b(yN SwWJ/sg-h`Yqà'b>cL[ HW^$ HM2d!]F3l|6~ fGA )h*Ej]oflVrV wNwpn@͓Z?pke3;)WzKXz>gaxEx52ɐ4@?ґ%z]֙AwE!S BRVߐ!PPlNBj3bZ; L&U{̼V3#gLtuւ[vu2fTȣLw?]r?kzww#}:ԑ"[@|P/|6QEQpYdx9TbWaH^F,:,JS}B=S*y|êM.31sPTR؃y{p8Nη= wC+Ψ$ Q@6 ӧZ(EBv=_lbgn}׸KH垌V7g\'m:=1ƹ"#ܘQ<$uI\tqD1qh"&< TzZUg_'H@wKw[aVdI:-x:P-`BfoGS> KuBW}F .}:&]\q*GpH^xkΕE9.}7qGa$l -mNƭoLz8^ ZH p&s%\ 6D(z>ԋ1Ӷ\j&y7fpʱhLʼ,}sNn)n3cb{#j`ѝ$ahLv "od琁?Ϣ4+Jm_*d.4̧RHER!N!ljx*ڨy2'={d,_5tqbc '㭥Xs=6VТPxCOi7#) P)laN~D=/El~H Y4{YNJNqF_|#%gIU ~$`:Y-iϢ4ZFF%--n\"1Ed mxk0fDJD6=+^dFu@*n#*1 ѵ-TYQ{:6K<%Óӏ~E"gSV yQ%^ grmB,FhM`!ȅ%J3{(-Hc5I;nR]O`Br--!ZU-].:WU`%ʓ' x`᬴+XsU -L?4,fbQCF ΘZ.|ћcO~Und{BD9*2ݧU~,kv @gyz1 m|!z8+˧[\괮כ I$rKmp3WLW^Y 0Ǿa !n.\U4?prS( `> \'. 1x}BNЃWv?E>1=پ*@OvWr `+f+HPP3-CT/#ٻTDUI(I"]wtv_ѷP7"uF_ UEлPM<*9)EFVU/2X40z.^m)6Mˇ'?0MIY3Mp&>r<{|N jRHwxܳ'cGzsgɠfヘkUN2I`n~h{Iaju4Fڽ78a XV0> ٠-{9-|LeWÍw3JnD$9#J /pwK+=-^bԟG.UW߹ZW><;@/0a"ز<ήȑ›nsx[ {*`nh .`s[U=3_d|2lR19;ڢƗ} (ETQy@h5g^h>ڨ*)^c%fdz`θM4#y'v$7(7 VC%NjNXG(h0%$˝÷G=H,pqzұ:']B͒7Ƈe5d0W[<Ì)@|ϯ?  Z~&'{!;Y׽gV8>OAӛPN@?&]5; wqCK@ Qq#awi^v;Eqj޹,w̉R{՗RJBIzB?EkOTmQ6Wlȃti5b;N"Pݥ'5'942R@>Lz[>n@jn2S>PU_³"sF L~}8Rr@m55 0@#p1V !CIƄ{K#vؾx# 1ho`XQ\,56a}V@<UD5e}!ec#w!W!{q+!;UYP=e[>1 rr#c}syzG/Q*W7? P.W.BDZIT 3-2j6xoe6 1ZD^~(@[BmP Q"&[nszm.X;eC|%39:@y.<*Oޛz 4zo*Ekfww&ew33l1V Z,b݀}Xq1IZH5hzfW2҄j޴. z^UᒟsMP|4J#s =ٱ1,($ujc]Iͯ bǣ6) PIޖ3suRܞ  tYb|UgJJ ”i9ZO#c"RJRS 7Fs"nW, 3y-J RKf&aM[%z3m*IH+>yq u'_҉9VYs@5*66K߉^5U:ott(C::"i8m_E%̹лC=kIrg?MFNYI&+RyokPx.kbѳiAD _g`ta*at~5bVh;[$=3~w@3Nˣ9Θnrوh\E 4\J1Q!{S6YcHԲ-Q!5;v*X:Bȧ(E0*myٱ)w) @ @$~Uɦ)Pg5yhWEb.)]:]+CE '\ZpOAa> Gnw_xL%2&⿬XA)\?P{8=ͫxfGY$&'#:*!RϻNAƲH"бn's0tɀ =󅩈{l}{1+,>F >%T@Ey. .wؒo;@,r@ezf#|'< m)] m]9a y{a&' xQ},p1R1éߟV&NcaE?[)'Eщ?2>G]!3bh"ܷm1-XcWd i;9NyUbypc&.J2ӑA i6eL g𒼏ll_30٧l7m;]wJɄ2N 0_C!S+y!ԏP$~PyHs'4 矞Ӓ C̋8*0d/9a9Olt{@"l0g L`&SDNT@<#C3kq2LXT4ꆲaNZ!}9HHĻ# %T2%VQ .T0Gh4 ߾専wdQh~&O2,#?K\@n (g6RHԿ!P?DPHS.%4>[' VQïm]3NӖsb"p+r g˫;**iS 0cdOh{oBLzR?$b?.S3pȄ>X0[` o qH-@anoWj?LX8%nn tYCĔ{%vNk>cp/zdƞC__ C-$߲PPxԎsw\n$d n+?dB`Zp}ߊB,[u&/64Ox%Y&L kX M=֕j " BEFJ%l%`-P > m{"b2ym.hA_@tjb-4>L&<,_RM ©8|r;`ehD^pXߺZxāFòPS d4{OO, B+ $f.i]3=NqZQA.ljC)({_y,#/jW3(5Dgrk/?ĞٙSayF6 _TxQV5+#b֢s6Ts@GNQL}VVk7-m6{XҟLhN"mb[ yAB lOV;؀o]w9e,gǪ6јg.Cuw}xn R8=5%߲5^MO6iz{cT4\h-LCA,tC?H4 v?o'Rr[hG30 %Z橸BZ8h?OϦ< N6yfheAx99RV$T"]0;^oU 2Ouvux?6ZKu6RgWu{?0<#l_G&KtBS5@9gDk"N, ] ySdt1 , =X ~/G"`"^*ˁhz[b\i85i,'`v!k-TZѐ7X^ *h-t}4< Z\VUq +hn;X8ߎ'!MoawUY{"]VWH`F)Ab^lA NjtЫ]L>s#d&%I@UI:Pw^׎-ؑX;᜻[Ģ_$Buu7# 'f({'} )6ٱ,6n;)~a|-\oZ xު*Y'3$Y?>b.5&ޱoE-S4;B$oKM֠8jJ * zGnЩ:OC'18g{Wyt;[ WSq~v|\U+ǷpZΦ6cWl7KB>^PRmq4iO޴ rp/'oR^i)!H?7BeGxY4Iu?īkayWMzO0o\RԀ{n*yO|\ĩ8 R*~/szJ1jxD*X `fNhF1>T]CjRFRjT08|\Ͻ@u>Q=KQσmMkG'x3G6@?32bu7A?Ԉn;A2\&iY9b 5?W[ĒF 1%oQ+4\?31?6eMHs ܅;Y7L[T@l~[yy(9+F&R#UT Vi{f;N8kAS$dE`Tif ~vNba-w &"K7$fU/39$eqރZ7Zϳ9\b>B9ek%(qSn_ܮ!8jaz(DD:|keL]T%npН*_\ڰVQ=}LxXR`0;{ဪv  ֗PntBW$xv|u!xf}oWe5UR\<չnзXɨiG4>^v/4N`*w>,#=3%dH6Xs'{Ɩ9[FkFG d,R03't|g26`}Z% K<zV:zZL-X­A(5ڎΐ B08pgvYεu[ZyrK(W$7ΗfYlF|`cx00^O8 QCv0z{~{?7gjqqDVñRCƁ߱EJYƛLRj[%!|jCWJi"1vZ;XNO:`9uGoQ@)`/>!'YkۃwQ3xGzd!éSᲞ&qyxkGu(}{GƗ[xTXM c!YHB̵+;7`%UQ88g3V:X U!q1> (D.xMiS] ZԲ&KXG%]d9Hj`CAH Q 8Val]GTUbRTIs|ggsﻋGGgm|΋}P3 qJTO%VCI(4|!RROAb;lN'm#'U"ܝ_[1FwsJQtVM|4Y=LHɢ Fe:Dw鮋F&t-P2lLةGJ4;Ex.XFuF<*(z];G nWևlp+ ]ia`\2NSڣ{|R"ss. kBƛW%T>I?c-EN(eR>&fl/[ջ}β$G\?[qPɑhK[Z v`ڕ)L+7Ku *@zCOlp>>/׍: ˶wn`eH/~Y|x33s̍FE7B+$YY Bdjf+Paz }G ԰y x5`'؝mc>K(?ˈ<*v#b:8<ʣi{{UQGѬUL*y aWJveg7PʑE[CC>b$f8M~(1 JsF7>bqj)P9ȍ{Vvub^+,_UMUy4xDO0)kpa\d'Imb%1L{N桄/c%LR#8AjM2zؑZp=݈1҇ t\iãnޡgYJ |^isgZExUtUUMM4,G m}6,i-0.u%h&w Y{nE:Kly$Z:xGvs;x: YQ޼-՝(7"cosƢ5ķAd4蓛Yq>i_8l{1gQdmN/E.1=@/jk)J`뜪Љ=rU &uꜞ.('Ɲ>H6r5hv:_$Rg z$Δ(1Ob<`neC>֯B476s J7¼.$񹊒Xw6{u>`M^N6>)xb@HOb'h5f X."rKi~]wpswؓ~д'x\c]BeG鄘l:I-l "SH ؒT]-;3o&{IYDW7bxJSXQ"_X>]σZz?^ÈO(|M7lGJt@*@mj:ԑBeIDz5ǔ׍0KQD[HFg봷̟cN/Y~;ȜEHЂrgձǬr"l`>:같`z65_'t2e"\3^܃*6CacIs e79y a_bϴqAE6a]^J_H-jM*Aӫir8&6Mir7 AqdAR.3ڭ$(2uV[j=x#q} :ɡf$ұOv $T`iu{CW-lPa3Wp/{:[\KKD¼"[j5|gUb+ײN]F_paqIEą'4W_kqL3U^,l=ӂ d&S;6hQ61;|!d3 Y3l^G *HfvrjGm`*,){؁*hNў^T]~\>#O3"QGho8#'fe "늲528#MrBῢ˟AsɏTnk.fDړ4I>ҬΗAU/bcg677H(Q\b6b1]IjR Pa ds)EL F: ӔuۿvuylG̵ܽ}o 1w1^CQ+7|*VOH0fB{qLڌyXfkIg@'<rQA%ҟHQcx#54kƾyj82*=P R˛ȟJW5gvE}ψݯf$(3񮰒d q.Huk Un|[4p)F-y i101RPt")ZSRAxdUpp UBv>?* ^7 Ȋ- $AXwxS[ $VdZRzeޱ wP vl G vUPЮao^ƏK|TAIstҦ{,^[oRp?8>G:apΐ&.~ Dy"'&ҕ}ĂZͺK_^7G#= }l"ȏS=rk7);Tv2SƊVLekǎCRlͬҭEKK;\;#ͷm8v m b0y2x{#RD]Іkg9]DueWUlMZM*BC9uZ o~iwR&IpIZ;sԺHC UJn۳MÊwx{|5/ 9*7QG Zܓ Zh6˒=*:j:6zY9$MDJQs_| k$>|m fi8ƭ%#J~̯GIz{zRȍnnb^mmUEgTu!Hi=;a3Y,q65Ӌfd2dBcxldÙUଽk5>LҨ.{`Dr9{qjrn2J>Cgc̯L&|k_':jj@+1 Ħ&,iPRɌ4n-(zd]!ٿtֺ@? #)E~>CԈ ' X YZ