sssd-ipa-1.14.0-43.el7_3.14$>t^!Mmwϧ>=?d   ; "@FM    4 { $XLL 3L   ( 89:f6=|MG|XH|tI|X|Y|\|]|^}Db}d~e~f~l~t~u~v~w8xTypRCsssd-ipa1.14.043.el7_3.14The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.X%c1bm.rdu2.centos.org '{CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKOiA큤AXXX$W~XXX3a27ddde17489327d64e06fadbd99484914f1c3ee242da22c649828f86c73d76f579a29f3640404a41655c0f8f98c17af6c89cd26738b226a11b1ddb00fcaa218ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90390719415649812e8c94ce606489f7ce48c319ebb1dd2d7700afc2ab2cbcd02b71e041758b946c65099aaea0c1b09192a3ba5637df405f17896a2a5673f3bcb0brootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.14.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.143.0.4-14.6.0-14.0-11.14.0-43.el7_3.141.14.0-43.el7_3.141.14.0-43.el7_3.145.2-1sssd1.10.0-8.beta24.11.3XBXpXv@XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.14Jakub Hrozek - 1.14.0-43.13Jakub Hrozek - 1.14.0-43.12Jakub Hrozek - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1422183 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user.- Resolves: rhbz#1418943 - If a long-running task (e.g. enumeration) blocks the sssd_be process, sssd_be can deadlock - Also Require a new-enough version of selinux-policy so that setpgid() by sssd is allowed- Resolves: rhbz#1405584 - SSH: default_domain_suffix is not being used for users' authorized keys- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.141.14.0-43.el7_3.14libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8331f40a84070971d9978cd680a24ba3ac5957aa, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6']"k%w+p}|,p35muذHZc֧Ĉ`VHaaWX(|%Z>pW!aPC)[ NY؁&TYՄIIoZE}dˬCom2FRx"•O&qOrVx2:~8!ȹ`s@ο?BnLx['ou9 99 {O;=1A\b@*{{,Z`u۵yCH%Qo,5M^%īRq΀Yz"@F6~;ͯuRe %=0ӑ8Ǣtcªd'̶B: cˠNaGMmG= :?3g%A,ס?nz{zP+"S4,o* ,Rz!f#.rTSrl\Pm::ޞZgᢤ{_TS/3'C0W)6ʼp!" POY^/\*&]EO6re# 6A c1|IWJvcק>yբ8j)7֧x$Bʳ{zuk90DtyRwmpĭzI_[GM@݊@X\y<I8DD7ׅobUO{kHY-~X9鑿:H˳)uv,iDQffA홒͹{8{f|nj)D dXD oac:JVȳ5C5y:-1ה❝7!8 PYNVjUOfO<[ovZP1 KjLvcذ@h`ۛQA gD9S *2W_Nw# <_t..pws6ڜf+. Pʋ"@S)SN"WuDN:U08݌2BtP|74Ņ᫻8dZ2?:6Æ?|H\>G 8{JJAT]>V `zNeFY5輁2HS]OM*13y-^{zWJñ(l|Sڹmonr5\v>'GvjAhV# w-W} ׾-y-Ũ/ZKR| g 4 G3^c%]UX{'z>P/@x_x0K>jϜ}RduֽGʶsqtX? 8nwikLQq6~"v+Cɨ D`LnF: #I>s7}/r^rIɻVHDvwDoB]MOYɕ]Cko%{o7IvbU'O*uóB < Rl$űwbwXQU +|_7.P$Pe T.jmLb(c  )}ucQ`zw&k5;j`\eQ܂/J ϸ4Ԅr.n=uAwK$=^V_0"g\wBs݌klxpߙbqC@^<+ƕm jn-!޵`=5*\f\YZuŝ1 EEU[K2ƘK8z.faƑ:}H-Fahd%]px5^sE9CUBoDBRMD|܃!;/c>NkTDd2H&f_Wb<{acfPn򏖎S*Ac?9Q+[$.$p-DPdh+VI@wHS_ay%$6iblkZ/LQ0`O(\ֺb=3nU !V_@;*/r_ճDU#$j΀h d$S6bǒEbvܦ"E֚=|r MLY ѥݷ$ >n: ղFTO˜8d5W~XBJ-OP>C)U {#O@vWwɝ]2S8*,# 츾Ik@5c],hԐKVݏ1FNFcBAI1Pip4! 'J,(kt3ݙ\{ D2ڱ%}?{k C5Rac+cGNpC:vXQ>~ M)9̀L?% p#⟎S}w5R{6)=ujv([|Џ)ٛAO*ds|ުD!Ҥx:YtرKӹY#׈P:ZK^<ê=Z`|̐kV[:&1A`;(I=MT0)a)%([uvUv}QF4l5KP:7E D\,ՆaYj?qS1V:? <}%%0Xn+f)sAYgj#֠# ڽ@h]$+AhdlǪ6\JSDz -ۺ XzV\$6/ch[*V0@W% D fL3z, wg <u2 `v/@ʷ-D.6p~3x .];vDR"!ԁn U޾H@)t9)yxfʰ`*r;zW=K*{O.uD]"Q֐Q_ؘPMjk|Xj2&_)Et=vViG%!%Q aiut)%XAqJhcg{.myOCB0)NmeY9z;bl0q6[M|M2R z BfBD[!0Ӿyۄ.5B>0}].W.771ރXM~ٷ.-mD~Ycas(vLw\/3jh[׻F{3C0%X$m<ĥ*{k?uMIA&!nwJ]dc_us>e0>6ިթg(;ҍlS'B=8ӣ _7B6,ʴ%d|.j2G`(-gW=8҆:wNV2},?8?Fr7 SIx#[1r^~'U@y^xdyJϠ[Ld>#Ps/Nfm-5PnX!zvQT[f&W1&/*ÝAö䛲 2ΟN j^63B6( 06TOÒ6s"Uj\.$f `z⒧{tg:.%=Td /1F ڳx1Z6-Z]u 3i)&ӱ74Aƻ].$ŠfPw-EFf|klQb_b1ta?Xݕئ߫Q=Q:k4كvVWX{e+EV_&= vtTCgaI_n:IHO#}OE#DZ% I:Coϧ>6wGpY b7 tE׭"üRYPȩhKF4eŜ|ur[p|4,_#dNjLnpWtq;[A25ʳM\NQZ59Kҿik'@ۉ\<ӛQ9eԢ*ݟ}ŸgEd &ail>{m[@Ջ5vpv22t@! `\ xRmLkq|#"_ E "EAHai⤪kWjeRA{W Ma(nQ H8vŃd4m*\[MNy+$UVvg(aP xbL΍MʜSO>G*5(yX|k1 dL1#k2᥹{MEqB$~jvŜK r㠋G] OWW\)8ܸCrFCJ:pQkEVk4Qͅ"0Xn͜gF5F (t sL4ނ 6ᤌRO& R-Ӹ)QM YWV#hUP oW%bUk$S}f#MԪ&Ms=օkHkvnU݁UD\j,)8DZOؠjqBrGN"fb`ݵNmVkk7wVx/ISiWggaB²s5 Sbd@-%d50,#Jh#:r/#ζnl {7ݷjC}?Iɪn\{O Ab-3KoXG7!ZCn:{K?ݯG](~$#ca_;4<-(jdThlƸ[,>o"eӵ!IA$]FXDg4<$\VSPrűX)qr q&J,dBq@u˩Fr`?mM`X(Y<Vw bb]~A@JXZ3NpUȥoOrNLKpkD_(Z9ޝ,F|=s|I@cX)c}͒ ha#˥?M칭})[跰ILwS^RfVE^ xX>$\:nfvj3K$J%VC1I>P<^U&obC2b6wO˶LБZ%>o^͕KNNz%N\DRX^E8H tۥ_ $j;ɚ_`02jYږ Gwݒpu7P_ֆq:k$C\ h4l[^t'3=Vډ#Ts0^n1PRv?>RБ&3ŷrj8|+8_K9 fZ'{{a щA fz[ CtP\(- K'zxQUv_Lf_ GǙ^[xznCd|d;L=SF@jwYbF{ nuk'0 )i$pӵ)tVsWǬ:Ya>Y䤦`-UZt`nYŞ=aT8-\R+r|d%aGALL’cy$ su0UdR + :4?'P _dMQ@s sT?UO>~k2zra|j=u@^fX},GߖGׯ={F2j|$ ,F! ]!.=Y5u{&T1$ @V0HFAw'VB4ƢT@ [?Y6If'2S0ْ2ֿi?rwS0!I ,GzRXDJĀ+CoOs- +a>*[ uIgnڔ%dׇ\)Dp6r.fdi, 6 9D1.7U~ݜ2.ƀ(39O,6cfw|B]b ޲Iezس߅ӽBه>/+%jX y⸮y4rE WY5|6K"$ڏyַ*^y͚DmΕR*bҔ0qWb2=`ڀʌ5 k9{1&sE8'*˛J!!|,wCꋭ'9bJYt,t5$DGgh@ilЦe~ 9*pZ35ipC%x\G¯2]ZhhN\-DŽx"la Y'C3L879g)+q9ܒ#uXV݀YyD-bB2k`?<_$F+I#MCr' 6IxZ8ET2w?/$mak%zC+Gk;SUF=нfl#CI%ޛU.֖>t_F0uf=Z;3p_A@g{zچJ- FtN;ڐ4rICį3|{L4:F\AM Ó\F7o4K28 bP[sJJn<wd᨜0B <7.L>؊RDAdj[!z;&%3hIO+$nt|9rލd+8J5d5N^nSIjBϥɭPĒgV#E(l*=$ﻉNœ\k J" YFf,K~ZfB%=\u9EYD$gkAˉBEDܯ,7fPΕ$qa4U AC1Ȩ3lS߆,}C|A%v錡0Vz ޺$VwT 5T S TEaNMgO?W">TGQ1sC麶&: B`g,zO=3qsyBAkg*V"Vi|:H>G8}S__%r݄8qGm__/o(a%|퀎|ve[<'Si˨bˍViH6] t'q(c#zFUL?! (w5\=ݮVa0)6[U/+2ʢf_b"i n kc{^PQ@GĠ I|e)WqQA{pD_ДL%tϴ?)WK|05F-EAl^L<-84t1ـH"HE+vG H`&CQܵ: f{ t ُYx7'_(EEo[)EI Ϸ{d@ d̞퓄M_0,:3RXQ`֬g,-$Sz["e:-t<` @! n0U3&D"Ә_aDSw>˥#@mt\FR/?|[\'Df0wkfLM;LV&]dSCƥ$-xU~\ !UvX nB!MB3h(bvOphӬSnirնr񊌗[erv?drzN;At.tF+k)ٍvR P ҚȇSlFyo,,I[;8">.AUׇIJ5p[u҆k.?N#}0bT¿<5g;L Z-j'P}^2.|Wͦ+Rd@3w`p/ asD< Qm*jo!ﯾõ ȷ Nw,z &xi}A4<'4^IFiY@%g䕮V,ǯW:-%Z]ގ#c T 5'\+ʹb (߫\QnWvcL֘h2~1?ãĻ#BsE{aLyjT:+`HA!x]ۖ5rO'/kSЕ)UA:[\3)s1%//w2O<Ǖ~r"Jm +BDDٝW{_>zt9yཽlKkvvBA!Zw/܏=[ͼH8쵡Y6gaAԶ!fO $sis:2U$3N:Bގ7JTrNBH.W(tyZR$8MiӪC#c9鮸qn=@Lk`D[}<0 `՟#DR*/c]Di!vI M"O}^ͳ_l WW39GCͰT w*" b56qi qJh6.hNEL[$N"K"}b[+pMg԰ȏJ>| -Qx)+Z pU3C#ih/M fӼw'MZZ}!o|EEEC)dw`x  h(KW)n8Q|.Z] _ki(sƀf&0t:҂`5,hr0Gre t*xp#{6\HC^#ĔQi^+!#A-F?LO B}ۏa&E>σAt>ַ>M_^xOȵ3FR{i%ݡFP#1:^k;6Ǫ~#+!00 Jܬv} LE @+Ad/"$VM/2TuCjzUOتL|914~/*E-0`=`^+ֻ06̹SDܼQ&ɒxZV_UTtK8, +UBWd(U[lcJmwу_ B]9 }]AzsHs.or*)m`@D  V{F%PmIcQY7 TLԠ]st3Ȭ" T S:%~ZG09w?&ÜLW<Ɣ*EIN>75d4.pKd/ؕ״ۦ(%Y|FtDȪ^m{N> ʧXTia GsJǵEtgU/-3Kr"LX t^hY}!VҡfL :9Q꧕WBZ'q!1uj0>)VVi^6`U$j}ꤧ@(%1w9Xo 8r^g*7Y? tac0:4㧉߃y}z]w=O{xL?äJ:UBi [uԒ/Pt "o ~i#k^DfqM"ښ:"DXa:,>K=p x?+DsOQ*g`SM9(υ3n.b g [+yIWHx7I?yo³emF0׌@y*]o,蕂b{Uot3-O܍ja˫7V܏R[f7pGcN ;r zۇĆ:`;[k)4 ع ,2Q@ *އ8WC׌FT^ZtK v{fKkhWĒMgcl4[ 08WLuYLm%dK8fT>xV7n14z. s@da_i.kEOҸ ]3mZ@s(/X ,;jp\)d?!>&/F)`,lYzqqn?vu\_8ӪC\;mL2A]rk&_&UA]˔& b& \òV5aV>]0#KG)@k*v::t;h- ذqGJҥ$EMӋQǘ\Gh:Ԋ%Ğ:cIS;p"p {j Z2ؘ ;˷THr1pMmΆoBvtqk5% Γt4oMpt a+ju>|Mna9~a*4S={}f(qqq=~iwo@ E=NRxCg: ~gfbWY`ұiJSq7C _{4. R}k M~g) 5 4i4͉ `BKqtHS!E3PF/džqk5F >H:'^XtwL]- ڗGՠTX*E{_v1}[mD ,=kauxZ?b;*ߍ{olG|j EP|&$?`zcLJUdUdtyxHwA\dY{n$@PT12wvBi bmXl[ <4{Џ֧uqa1ӠOȇT _搛OCp],Jy b?dɥN_yb79 q F/-9 2rdT>*޿"6-JjueG7Ʉ}f2L[Gϧ.yL+fr~( q]ʁ}M&df@::Rm<ٳh7Qf ~2mbsz^a[ ޽2^Wۗ\<2ePd[D-~(덌N ʞw\+}SnUj̣;Հ7zrp|y-|nt6(y_~7eH@6U!?AZ7*B4uċ)@mU^sw[ӏbbd8a|OϪD(7pm[pztX!fdZ< Sc|jY(-NE )%cj^Bv!O\+N#o= Q D7$+'Qd+-[p"Qoaܶ9\6j#8Ҥ~pkC5hjY 7R вؗ$Z?i|]Aa k2KNh?=ӂl~QWkG$vbVjrY~Q-Y */"*ןTUjHwMP"0އ(NRmST%cH3gG{Ʈ'VE,P#*dʔO%ĹzNex\ۤ:.&,V?0i(6Jt` "1v&^SK:̃zBj񥖚\za4_qYәI#EAe8̾-65:vbieZ+ee:0Z{X< H\DJDHb +q.` { Erx Q|i;'ejyITz?.Lϓr}W~tczdT}0,}MXL*F(cpmHfsjZmUYк58 j ;j*VQN{aI*N`$%ܲbev٧ }oWkaU ·b*v T FrL #vG TL.7£%*I\|L ʥjGQ1yx]8ܡP-*į5038S<(DSK,-S<.'ۼHI_ςKëhH=%FrMS҅Zq #X]"G%JskambdniѥZd-|I-R; 2UpJnoڴDvh"I־)aΒ冴u-Ȏe>H SaU<1^"Tcd.xL1v^l(ͧ\XD\ւUjK,\" ᗙL&7 8sU~? k&; gUb7yݝW7Eij[hs | }t]c D!6_of^`k@ꝲ3)+_ cROy-;X g5P?d(7#q^>$[`s| \-ͨg**UMZP={;Fs db.5% q~tHGgfg~mlW?g4$&ҁ1F}"_RSnl?1)/#*sW$#9%$iTRzP>K'3j2\g4;aWΖz&$'DA:V'be89@lͩsXiȨWgU!Ti!,@RP@hLa7BbEXuͽa`:Z}Z1kd5@2Uˤd2m}e41?Eb=g +o.gqf17~+^͍5px9qMTkF \tʄ*:J[iWY$Q`%vo+ a*QЩRmG1YܩEǒsНLkiUWƓ*Dٰ^}8t ⿹hT8mFCS"dބys_z H5Zen ͽ }Zz196\`v0U\bcwN*?mQǯA#Nq_JإD -ks`WWh+# :_92J`3MӝfOv^3fu+p8vyoAoKF ֓FOܟ]29AČhYg歬m]};~/S眅K6:Gi Gv^ ?Grܮ=o.]-kq#X%dBz}PbMncJ? C@]ElUFHJMOmјۋS gee|1%.3"<&ptlY`Q׿r֍PK츽F m?xC\G~C־@ur< BexyC)ሞQyӺLЀnh_bUe/6bp g.QV$V Y7a*D$+Ƽ/@|O2ɧ~Q dlWuFq ?>s =rYY(K)pЅ):g3^*aU⒣Hࢍ(\>/^uhQLAԩ,u{IMjt=NF빤2rE󥘵yilh5o=eON09r|Q K+{AvꄛS+Fa>Y[IԐwa[VZFps'zdPw i}fK1٫םD@?|ŧzTE'p%hAa\7زYwN/Ĉ=NS8ZDk*rSCGmrX'H#t<ȱZ7#Y~bɨ،܌ _44V7joou2n 'Fo|D}"[ܴMÏ~ *XoX[.P@r`e/TM?p& -VOGBlG~w6+_ve3|T<;\B*Kq{*(t*^Dxɂ 2Ҷ"4 BcLt1;E.ZkctɱȄ# b8P`FŇʡ y;Lӝrd\8$jO +ϨU.uo {!ߟc{~03fzn7+uMPy`#(@xxIݧe6; 8=p0hpDHds 8a!¨/zҿ>֙E+nQFiڂ0yH?1c}bf0>`[WR(tc>Oqhu}IamePF0XcǍ /W{:,G\u9=ϊ ؋Fܼ=k3wT|w.wLML}}5zi=(v( .gm m\*Ug{¿i]K=Pm zAd,aEn>OZv෍$)9no2:g9 U_S%qvE֮]i"9G &2oӠ]J&@8C|v 6 h9gS{>E襈R8dIc`sT`į^÷xdbkD#4YN/|]2$Pg*yxw|SXuٷS$R1:m[Y0ku^<3`~[B.I wH|xZ6 lEIE8|a U .qoO풕D vRGe|H#Q`̓%{w ^/mX7@  0~ hbVSGok5$j 1h;'( zYbnfoTZhE,gtμ_!oϬ:y)McY(f Il=50`REHRhrNfK7ֽ>' X R*S3u{7Y)OS$źbg, C \ܙP@Mc1Eҹ5w-kATSUz72+x6N@Tjqi4:8vq%kR6)~y( :> 9z.<^S缛[$0E<];HuBXj-j]. &ҧ:*N rవ8j}Wo'Jnõ0͍(uCѰZЦf=jIԟЉa$fs]ndKq?xVt\.h !=rW Ӣ;^&pYj:1;^>(Mt3Y|Y VZ'ŏ0MVykmri(MPhⵖLrXE ֣@-ڥLFo!d=D5@hg%/0r18C3cpIDDIm9l B~ =S/>I#тyPV}އ MrhW7j!}"+='ht$q;ka*lC<"E*π]p1@M)u:ܛ ~5U,5yPDmwl:]kɗC <Ż2F5D_/_Mz㤹7OZS@|yOQXG+3Q,(" dT`GJ C_aAAFڕKRu;}#Ivd#9VnlI lNDL/u>M'm5H4Qx5䡤^Q&1~"R@pslF:tdnrn$ysXvTQǕpFX/Q6X6Q>(IA9~&^_O -cJL >@Qe&pS[2<<iؑպŪVTZE- 5͍xR шSP^ü5uo ETd5KxzCzPZlu&O血<_ ):fs\}7aNO}@8qBg`v! 3גrזr4%S^YzB4>Ѕ/D@+%T?i-,=*t!1a0't  $Z *~Q?~6 fB6[ Rv2 ==>h1Pk>beQbȵұ4Cffܘ> &eOBF&^3~^JFt7&`#%hñU;fe4j|KpNcVrGt?dnYiٔ??Y B6Jbr[ᴫ cX'h g~}]m `ޕ:)d%t,Lj:> {݊l)^.<>KV7 H@TlsSO,X)"rmZ.Uy#Ebv g03_O"\ ÷G[t70| /ۺ$YFricb\y{ٺcl g;EwKoz&2 'uzk Fl߬+\X^УUۗo5u_3lUhKD}&~dw\itH)|[e7uôQrO C_9Hp?Q^7;Is|CcM v[A6 l ޺QGJι gmQ:Jfa,x.av'^d%*BUoyh/&;dIk႐ c}sw 'xdJZl BLU?ɮ.̻\|gRA~-ŷZڍi-nm?ԏ+x!^8k2u;ױ3Vq*T3>I9fy5s':㕣  zn TЬ>^ ]*ApRY~h;ҟ7DW93\Et.n&>}m#L*J@/{]$L\5? 갳$}챌p.[L5jK07^f2-޿ǠsfUuы C/*i\n ͻ3~޾ &BdA<)0Sfz󏕶ƳNמ>{rOU~njaH?{-Pv ^OPR8FQ;Q )٨$5  wRhEdJ_ *]+l4!%2hҳӾ{씛Z󷻵J%xLB10!$iF=TץD˫i,5L]@A-+yIrNHyZL&e#5vmaT Tp#Z;h]X9@B :xrs"K\ѰAnE*y tFksxA2^7ʖކYJf+Xf` esԁr͚& 9I?ZWt.UӥĚ㫺%d[2нpZ>n`?r d(qju\VlV56}飩kSV5eu~}8M3 z`Q3Df+wxO,ÝτR zc5@ _PpQӑzw^XHSqG*m&ZDAhĖ~>H9q֨$^#euQ/:@%Ä g+vsmFIKsLs[vkXgWoGq.7>WR퍝kqAȵƻm(4"CV&;u %f%i~(S_cJ@J|}cRyp3YX‡o Ȑܵ&LJFHlDWf;Zt6D/f22Z"ۘ!G|s43i)[~^s)17{PDOhw^fwu])aH:7^'WMvkt4n0zz!?S VnMEbs\9ݰAVlwH@žVo? ~M}pq.a.7yAӬ6kK379lc'|uC[ԝ$t Pj󉼺xHه?Р"ƸVr74U3;UzFK$pPyx2xaZEpYlͺP xJO2P'I^ shLLygK`*/c2Y5_ u1B2ɰLy ld~ѷc CE#0 82kQ?i& etiޔԇ83 Aa'a*\ AHYƖIߠTд+?e KAY&jFMf{IgQ )^583(7]du\~X+KDQ b6>M[^LGiGe(N3whrM'P4% ڴE;1V6"<`IFS/#E}`U٧C;\pY#? Qzph(u!DXTz*nu[ q~Q2|ɣEk[T8 lp8[S~‘ /.:|d| W{A 0*cD'$rI%,ew )#}G%{ +hbzbAxOhODeԭA0Uj͵h٧GgV/9Q_H&4B%ʆiKUe (zom*SlAWzqhWH?DLJ虖F =SכtC71f\[G!_&>\{2dsV)4b#Esi>Χ6J,{;>'K<",셫,@Bd'e#*{IBq[kyX($ G0,FW0p|"- v 0d`rWLTrѺa)JDf1Ȍf铠4\N_;"o`.V$S gYt- PWݭ/kax |W)+a9Y3Xez6 ]j3[gɻ+VaUU0B!NiBeN r h肓}hz˲kEx}֎bH ]K ]< 9Kq=;*1^T w AoK6㠪%xYl#l9f.& `t@&+ bu'hLceZov%<Ǎ/so'`!f\3v: JJ:0xt,yr!fZ2jT b7?QWTW'bv1^IEJX OS_6¹k,4P@*SmdcQk̹t"'8R,Hp<ќf-.K8MJd+GIР6گkq";HfTD/;VFrg3xo@Vloh_i_1ɼ^޳,',.Oۘ:Rs:\VyWJ<"5fc—2|1mZoOH{DEqr;n҄"aTÕ՘%9x$4tcܟ;nL~ӓnHUi:ՅYvÑнrl 1V@,H) vߣDqi-\qHcy|O%!5V/6J9 g'ߦ5L={B=IJ(DF/UD& ók ,(U #G~uEˋr&wcy.Ns\8/ImQ;OQ`ΑHBVn˪疭!B!7)Q$vCzB2UN~[{͔!O-p>Mo:\"&&v잭Gk;jr2Ǔ$'dIK yQ;L̾獦Z3ǩO? ̀ QmK"v6@b8u5tX!`gfDrшߦv5Fĕ ׫b73rCB{AIыɌmO.$\\4tjqI6~h툏QOTESF,JJl݊vߕw!B L%! wJ`woEf&I{?sɖsgԒnNйԹ@߂ 8δ)7)؂ v0 AMj`!,R';k/'ͪ;eAH(#HF"]ָvrkZ/"-o#ë 53C+ÞmSGD3=/c4JTAߚ\G6gL c`:; ;J)V y+p=0n]|@׮CtKezwQ|=XwX^j?,"N5lI. |#<)0`_{%jҜ"LK?\T;H!žu41S|pUM>JNv&j6{N1@ į#oa8I#>W6?H;~{3<5CL~xoI[J}_w4S YorNA|Y"W\p%_ 绒A)#*B \]r+@j.|BvQ< p(9gYKEv]`9mCsez` ψkJ -L4tã՞+6ݜd A MHM=ͨ)y^IN֨\r)r۸3{pYBᜆ?[=w8FU("[}1uwE-ZQS]x۽dYۿuHi]C: 'XZՙzMu yiuPߪXM5^.tpdnRc KCTF).,Oj cW}h-ݐnTwJ-K H0JG]_B\8WMZvx֔ «i,`%a'0Ȭ f7F?3p RXwN*(ćlqlTkd-W>[h`<򞃟lsҒ4s94Bװj4Qp}`َ6{ٞU[*’竸bc Y; 9cw^}@nVJDw5~|^6vl1GѺS7;( R8n8v)MLXMR1 qRm0=xpYhl<ֽEPPXSLDDӢWu\$k·9YEz''nmu /| s٣CA'VһMB"]\r5a%FTA~VnD_ޠ/1`k[,+O{]~qB|%gAKZL4i~Wk0P9 __G~ɅHwjA3E;#&@cQm ]f_5TX?5{kQs,o6+P0RMO$ނJ\{y1qA\|t/*Iƙɉs48J巹l˶\tи ž2ZP@8;{!؈@T-`F"{U_pDN/.ڜU CI Z eOzԫI]y(Jq |T׌({#뢇Rx;l6(cK9Z P޿P% |xp&!hu3*&<+A,|lp2.L"glֹ*/r囕 lt\1b/̊8"X+FzG 'd.$nK\Ӊ+f)Q4VyCRu«Z3iJy [x5)%pVHJ#nWAv4m'N|Oso_+N 3 [Fz8$sUN_|‡eN>V߳p;+cR 288God$/8`CjfǾ}(c5XR<ՐɆ*F}[P>g~PDQ{. vd6 , c_Dki֥.{ȰyDRdţcX O| *D kCٛl bʨtD;Bp/4NpX]"ݩ3݅7wዥ'<+w}U]tNfo~Cg|f74G0elwiYĠ$-9?"Kd.:H)ym񉉴s]A>d?mt4^^C+jK싫4n%rVϷmŸkPpKoe'yy 5]~B9EM}BDE%Ѭ}Zeу7(R:)|%>c|#gHEǽ:!)YghQ-aOG!ԃ =UtX̣v"DH~:HەjE6ݔـap\{}9;B`"8VRi\GXd1L6ػJ5v 3\ .phuzygE蘞tctpSo%- `R\zlHk ,?>~+8v$F8DF٢~ؘg ak2\ /&Yc4@&{`v]3& &o8D̆KD(?TPMG~0M'g(V ks G v ~7ǚ!*-hwlw6rmj,ݧ R`6ڶ@tQ#ΐᣲ!sڭ;!!3Q Ծ:6Q]挏b\6x{`=<#_*^7łǍlUT}ǒZ7K{0+>&4OVG6y S_K5c/j*e8~ɪ)ը_juf(_5Q8J0ߛOĈ0*ԩAy_O8Z$^V0E}Dt(L YMWiժ. 6^)}%1J?+ x:*APDJ1wu?CJҡb1B#pEgqGIR{V ޞŋ$U:LMhi$IDB]X w|pT-8= Q4hC.s\fӎH nBDy}401BƌY W . o!Fja.slXy;))VC=|֤vl.9c(IRD>丗ğ\ӂr!# e*.p)|6:}`v dƘG/˃WD9:N]\-$өJ޼3ĩbXD(z6\ASo4PҒM(؏;VqRЛ?j.͗+ K\%[P?9NV?>Ex&)m,"VkIG8ǭ mt{ޜt C'?B.H 8#+Fq1aMA]S9$//o>c@rr)wھPÎ{hQ+L21j-IՆDoRypDcXRih] &"CdWZdtrv[ќyeZ&E0.I ãq,iCnrT@J9.Q?3'xIȨ(HνzPGn8:]J@|\6=A'S O?R0Q5YsF+=q=JE˲1KQ`&"ka 2 &LYd<C:&&dfι#Hzgiˊ-hΆ.k@q7̿J^Zwiʱa)ZѢ6SQYN n`0>FN8F x港 v:&Ŷ,S-m> H1P^1S=)ES-؏I,n/ݺNw*CEU(0bgR@u.٨:La>pAd`N'EA+Ô-L5^km3*f޳p 2<\%rui*prb)Ѻ^O/Xo119lq7pi $ŲRAOɠO1/ʥh1!zA>QP00>.r$޵a0: w_{r&1{$> W; &v7'K-fMUtXCfLsxdw^ >4$ Fo̚H'< 2)}댉t365Fkqek RJ!t\*-Ϩ> 8Х.6'Ycll h w3) zf- Lۉ#7ʩOy J|r%r@L4f"Uc![ B P8M*Jcg=YXSO:2*_{C)MB`[[\n DoU-*@l VNvKhH{ ƴ"kC8 5cIg~DY^;Mn2>C:3b9׊cȅnI@u}/!$ gZ,Ns0_|/eP~1L {[`-Wf*K|s\(WJTP/A{KjWDOdy)&ޭyH )5z6 A߷/G/c|SIjb6`@'lo_Ya<ۈitWUUTcUC{@+csfAўrj#?" aJߔt@?W46{l=,CQ ;& #V^WChcs_x{]Fx M3m 3~0>2ef(cKEO2\Lou3(ZAYKl?8%/*ldo<տ7Mc%u6v[{VE (٤z!$?ɫ˸1ld+Rqd:*rC$^Bɫꑚ`iߕB*=?@9-H#Gi){Ww!|3+g0%ޝ?tjΏ泛v& on䬰ou*ulhIH$ JF4LYjE ~{\"㭭.D}F˝3!#^40hӽZ ޿IpwGsLZ"5#i6gAjVr NΦKEt0zc(fG[ȇt'~| e'sYAi1>"oR>N7FoәJD\r{׹o2Դ:c΄Eh"c!w܍J8|Y/ GEOv:3YPg#Z2UDZúw $_?[}9%H)IvV0JNf 6_ eNZ{)B?D q<+L9lg>>WWgC`.l&Sf,ȱE$|1,Z7O>!!2M9cxs<:B~5#lqPv9vq7&sQ\ZXIO+/q^TK_{X2)A+Z=v*Wb!}2k^W8F( p%r#5Zf+2Lk4 y*:&l5#,sF$6AyǙۅ\yq"3>CkRJ*A7:wMsZ XְKTe+hx 0{nم&|3R>gD UG::3\q;ld镙2Z y8:  .-_nw}I T:9o{o(e4a/`ֱewh|B5wN9IxnuW0hF__+ #﹓ H<.ʼ}(Yx2NEZ0rH抰>Nد |QH&|xdc('@)J E ї@péXH~ 'r47>`I݅ TX͜"(%o_RzoKv߫6]oJ|H6_ۓH&Tjl:b,':G^)TL ,Xا5:ΐrbO~Gz^öG!^^FD/J GV+rLΞڵg'`ZG]$~3x,ZG6RGFQ̓hrL*uқKנJ@NS~U3G<ɍ|7jY%~[]$=qbemނIZy]CCcg9_\,H!UQq#0ʏ:JNzkgjrҗ@78^s(΂u94\qR0Bʹad=~`؇rT(R&a; ۲4F|eڈ3ȡF/gF\64&|p2NFV"uA){zϡ?o.ߡ>A<2/Ypۂ~U^r%  Ml>K2m:/D|iYxYz"He _J-Zbf6lda]2>OvTt,#~\*bw2.%ACF=cU2ʶ2Dʣ6: CQ0^<-1 b -,\I"s#ao~?S5cNYǓ0_Oq!A]\~`ebJfvqS)S̱gΌnH> ќ'Ocș$f3ktDa-E¼`\LEiCflsM YB!k  vam3?z̘}FOJDO_#0 2븫%\PH>4৒P xu^ VLsո/ ٜ^zu9 ‡ޒxpBR#XxVܙHQ*Nx,e,g tE<%z?ҬOwvZ`%p>cb8d`A*aϢ;_FV2>"9Ag!%˃?.ހO1ȇ!)ɂ Tr&:9? )!Ό>zlZbhdd =I]&UVރ^dE?noFlmGw0wݏ:z@- ƈzuɸэN!u>{[Zxkf4WUURvJd>+.OZ>ϵGwhؗhڞ?VKXKtP̝nMԗ,=ݧ囌drK)lH#bW,nZv %pl\ u6z;2/knWSeiLLV9ȫR'N;U͐a hvo0W^x+{ |Vy<#еn_p ͵]?=wIY/As$E[ NE7?u.\M[>::G#z kE椅Pt+Y< ]ݩ9 l[y8#YX:^5jKO t +ue@^FSp7 H!Z7%F$J*?vPsG">@c G%~%됤|v0t1)t%Gs{7aQC*ũ>oѮ-HС,3*YWmfkc|+!].c_nbx4jgӵd{\Y %-R<}xιz^%[RI6zH"/yC<w'2aA]F/ UHb 'g-`f|7a v6 j>h"@%+ غpַ;KΘ~%AM{4*2/^䈉Fze!|_"l^6hxҪJ72س[:]I[Bw>۪=v2:P9ACpϥ+ݙ-}$L|R%ٴ,3e`7du`ۭ_`s_kyA"{bo =p=>F[oЍt+my|vG%/aX^yT闲W.0TgWwvz'Mх`#} ums;@:Wlq(b?J^< vg—䚍틄ZջHp0T;:&٭Cs,b!ez}N#>-0@Օ)-. m:6Sӳ_DeOG}3R 71/č &|"cD/%CR3f-E ^^\"Tf$G 9YT>őfwOXP[ghLuVX*l0o䡿:tfx/Eg]U/n 0oNftqݝ`h@3 ˦6[c9uǪu|mY՞MC |۷IKї)i)ߋE͝a \ո>44 _CYNI3x.֠AՐP0MzmP8ŨC}?q?;tk8'M? 58'RDR;Arg~DIRȶ^2w'!B7;ޚdA% {Yc7뵱<;`87GOΖ57]`4b&f ƶyr>U\ H*8<*_֭X5m3},QFvf>N,-(mJǾVmt"14D.,Y^\3ao=mndW5Bn`#dQ~B5:b_f,3Tp9JE86>A$!Ky^WϔMwHť`  D;P-"U\p3B=d1J',׊ C2g}NJi:&8I1Ѡ,F[آ@}q {DBJHcy@wˏҕڹޖ(K?ɱ63v pFL@S@HG,AIw?mu8eٰ]~ cc+m8si$x<(t4c7@5MVJŢ~Ė{טGg S[[klsUyQWӀZ=/V 9֋5aoDtQrAXK\Xl@'UFKu*Wxfy0NXF&fO-󘸮u_;7D<RHx@4 -DjKg,ΛFђYkI`T2tZxG`=}O77&L\ĝWYl}VQ74UD&߁8`U#;KÔ ss.n:ɝhl^ :vE  6< Aa3!.8< ] =-K# (Ck|KERx2[\O~'L38.,CH5Ġ6/K _A~߹0SsoE'̪^FB &,T=fGfKx(W4nJTT8ܷvq"XѼ'?m'!crF[s:H|pQݖ g}j7Ɏ`ٰFr7稿|'/| w聫fJpAޜuvk6`Sm ŮzāzV)rO60co/  C]rIe+&wkJ u$ڢ Bg)Ξ( NI4Iz|6Fz4lmu>u#!\@X)-Z1;W!b5\+O˛L̬u o^p#!UbQc[p#ݨ Iug-Ԕ3WDk)AulR9Ǻ  ܸӧTz{0%Œ;E"qmпb#2| kcJ&\p!$1>^Gs!f@/ry>4wi(EyAHTy("ZcN %VkqmsU&#K_x>X)(gXOIHj@.^p6p]Ro(躳,{mFi&zzst\ܨb)xObrxrqP hmv9F6 փn/ O4BoEMɌCʏ {Ɖy ZFLF9t$Yz{2*Thrv[I!<|rRbQNB_>DsAei'|QRbY $Bi.EO{sn@ h FH[C:0! C~‡(b}VW(^IYz_٪\7_]__`* Ѿ^?OsJte~\H\#bpˍaw%8 #_R@g'VV%mׇi$E/]G7 #G*WM.uqgsR`iɐQ, 6ZmWm4zb- kA7 lo[8Z4f'`/.^4#/B_!A< VEt~8x[!piԿxQ]]p*Oq9H9 ˍ131rMO?ku}~^j/BAWkRKEgl ~>:A?yeȂUmRWV4=l 3P\0-lD~l'B" ;Uqz=~|(*M;*Ne.!Q(oDTs#]>e(Jamك 7GEjUQdN7v3yxl_QDrtBD:)vX9bb`ʰ#h5S~=|?Z;5j"w5aS}^#x޻ڰ|b}p>`d ^ZahZEb)>'W-{܏0 aWu!mˋxS~x%O]6h2dÄZ֖_]ayb -L`Mu5_ѺR6v&v ,A֩!OtpdV\_c~pVz9h!nRO]VuA?Cݨ!kd^Ѥ\}a4LbuZTnEi:Js*/|1Siy.(CP2[29+.TLϯb7~+c~wӲ9\ qJqp99VC޺qmx4/`E^&W,CI}ԏ ^ȓ΢|i٣XtvHĒlqe JӗJd2$$XP;Rj aįѭAoP0:f{cpo22vѨP>Zr!S(;IVK~8r@+P.bkƨgQ4as7~\HKe}Y*[߬ W]X̬Iz'%=MGU!_T/|S.X Gv3X=z/ n|D4l5OH$)WB ڕD#noiF(|]ȀV0<4A7HH2ܠ)N70 .B}9p鲭fYh '4UwPt?ML:K͉׍ qZZ|L  gN9Q#P1bLTYcpp{QNZo$fspa1 -0WT3ĬG!4H~h@(>اUfQr8 o.@۟!d`yߋBv]&Uӝ$\d9 StVcHar%uV"UӒTꢨ) 2PǴɛ~kNpOΙjد)N78r ٠3`xZK<mU)6zu6 m(룩-{g./Z(PN8<61UCoUw/,w1+z΍}I2Iz"('ݽtrkvώ_*^cUt%q=~) {ף䩲XAV{_I@>!*6" [,ezF𤋮 BD%mx֯cҪ3[[J:~{\5Qj%Wv q؍'^}~|=_n*R?AY5yl8rA!#7$":P,)? {U'!~ʜTUd,aoRlek{Ǒ4-bms+@,-Uy`1ݡVOeC,C}OPSlhcS4,@i P!Iw äh^q?ӊLWLRn"ԙ[󄋛(&e1~/bIj;"i)bL:qL`qGlf6v=uo+VvM,T7oORP[Z}]eW4 _ @]?6Z87uw^1`Ml4K&y"?vS>4FWH=!ΐ" VS,$_3 S^u~@2xB`\j˗QlrVyE)d~<ͯWTwo[F F>a2 *kOqi$2NRtbXH}vcO<ۼ\ķpVIRo; wʞW0]lL&dljwX8:q, ttXIMZom*z,ԴC>XZͼ d)k8pے,\hޘBDt⮈(r#tUdZTrEX4,.uhMq V,ćzn^F?B1[}opm#k< '~ߕB8솓%LL{m^ S~JzbU-\il~ <<,5EU /@yЬMLEg.*zь3vׄ=6_( {$@CԸXMɊ@^; $^8_%l&.K!/[ڢ3b?ۦb,ԘpXQ1#?$S x $ZtЕ~i QV:h6a&7hD)'Cgr6 y(82^ZzY8oaXm|m¸ˀUKuD&>={ iǗ'@' %L •F9R3׈e:ԛ6g 忄-Ís]Ș U A{ZI%jolQʨW4DU:Dl&LcL[Y+1r{cFl3!eJc'Nuڪ*Χ*V=RNB@|8݋J+j֖*=`П(U\0j98yOE?3 86q793.p: [an\goaa-_Cl_[{ܻq&?VV9Ndb+>}s Rjgp䬇eE g!fuxvWK+Rtr9K-ʶ5R[y ;*,k8eUiDF,f{E;WMνw%g Y _A۳jyLK]_-`PDظeiAą(-̩ UYdK?hi~rPzY>GAD+ѠPRÈY)Q؁Ӑ;axh+cܑ'㏰M>ˇė6w}vFQ 5À81XjWHGֲlzspY{%x,˷i C `+AT('}0Rf#F45-8}068'J$Gm#k3( Junqm 2DLe4H`V`NT*v{^!N5pX_W|>RT'™a NV?6ceJ ~6a_Z-SM!Y,L0lr f6"e2Z>πھԿ\V=j7-qzӧYH ZaϢHpw1]jݫ8z\qá~J{BP՟ h! X.4BD&SU* ov]rV><ġEb*D7zF*nc6_Cc҃boT-VЌwzWD6OOv%۬1Kt$VL6|qFMib5[2͌RMhHI\s$r3;>; RV{p98KӠ i%3Lk7yD#Wxr^=T $CN'Պ40"_E;/]#`Ű=-[T'#ڦLG|@iPD,aAeA2oh~NѿxDs C &m%1 !a_X0*MqN sSfK:+BE,xϨ`#1!rg3B{ʀZSm8nE3\lyB'TB *,U7ɧ9s5"̏,pIq!!z"Yhp~ 3Qyk۲djRrG2 zNS4+?|g7ۻ?T Y+/D b~E4濆|ȩ@ %NZ/r,PPn--GE!͑ P_fCBLVsf e8Uq̄hL? B'a +<$"eb!5 ag o`(=s1K5p nrx̘LYڿ,/>kԌDbPq^zP\w(T$;"0rD\1x}p|O _[?zK:0s1ץD&ݲ"1lO{QzyY3iȥ=Gh.̲(PL6I$#Aw ur(Q!Ox̂$,u\g*xK-s2OC1w곝Có`)_krjY͹JXzuT?Zws\e@a g&n'Fݬժ?\7iSgJNE]BT \E*y~t8CѾe@ɜAjS d#ZJI[dI |Ji@R&@}u)}< ġVkv#GtF;{oymdA]} j* *ׅCwtGyV?ahd烩~F{sJ&/wW Dڍp\f;+[Bo~ʘ]Hɨ0ů8;i^~ox/>¨a>i}4`D7D^p{Wma Ǖt 솭. v`tMbAeV*;ͫM쩕~%'_b@g^;Zc:O|$0YhIߒ_K@H owc+rYˊfɳT& vr .0j$ LfgO*ܡyɟo1y-nQaf[[ǼMЦ&v5FjxKqIdzN>ͩ[*B;4"%~%v>n%෍AZsp cP;jÁM~u Wϡ:+=CyՖ*q:aC\0$P2ZD_Lx-SI|By)R:m-*n<|wG[ބ>σ%񽉛K?K3E o.臭BJ|\lvYG>pex&;_3+S I}ؿq^,1|Bn+k*aO- H :`ś MiԌ G)>NH,Pxjt뤧oZxh t*Z4%0/ix1x=QdS[u1Q@*+^̩WLf`ٟQۙLZpwok ϺhTljp==zw=Sa~F/ͨtE}F3 h)o4Q79^0*hEe.85x!zm~h#Z%P8`qIDN`(Dg[#?T@ҖKAb<=c헾/u/`wB,>*3H̑qt$)Lk:RM&[7xJ#Ak|{&V1B9ĵCDL-E W01cWc+#wYKf,r%9QdN ׸4H Q xP >"oo5MMC X2p^D=PX<朱֎ozҤ]4 M  7 / AD䣐%h"7o}rCHgeA(@qo^m>$07^W|ӉF5 vѩAXIT ױOhIӴ{%'&q8fߺ))mѰ(Y>0\z|8⮙uoс'0D8=S [+hh_b7U~P5Ӗ=̂>mVZp]>QWӉnCޜzGG}jЗ =("MLR~˵(ܻ-fί$b<?uwa.;?2\˅ʵ#O>")<ZTN1Čqי~i5USj6j+`𮀪C%L4F# 7^sɊK`m |is$2W21O#kd]&.e 10 M?u7M8$qƛT;(DPWRf,,}}6tށ~׋AWqWazsy#,Dk)57LW5 ԧH(sJ:`weoJöR\Dց% ǞYB7MBJcҩx|5թifp #68Er]J [ysO 3쩐b>;m,nԯ39BUPm4߶h.2SJ}Gj3o\VMycU[k3tD| i? ʯi) Z>wV_b[HRbh$4kBH8:0"H\4I7d6|}8 h 9$x>$0wz}猸~ z:pΑ|[ژ~ϣ\CSDe?/{跩yq0Ekz43MU̴ؘvMu % au` i0 lZp!*wND,s<Q1=.oPeϑ+Э$hzC$Ru}VuO՚5hjDд9Q>="DWsS #pph )!0b#C ;QOwTx(JDɿ臎[rQ5vaYI:-R "2ųU#_%RE;>ḻRYGdWJ% ,ǴjC0HS'aې (qp8' K:nhmi7+oR?6޳;?Q e kqM+ʹY^˂y#u* W\13cOjq,:],(4~o}<<<-B))?ŏ6/hE$C$Wu_MpϒR" 3`B%@`v.7Ǻ0 Bѓԣay(nT0W{/hku&]עKBqHs퀉>s 3jzjKa^|GGgo=|TR֗(Q RL=Aوuo)O']WP{)nL0fFBQlWA [od9UO|IUv{g5x ^TESyV-նA|u&)o;-=ng=y㉀:9}Qv8l6j CsU܎Pd}`S Ҽm$%muP[aST~;K`1kE)4I1l\F!J"hXҍ d<$k#FOs µJ<t~/S4.Pf7&}YP$y7yt\/+*2 ș|[)g/]-fȰze::;GRvmPE"W4 Z{̂:صp;^yZN0bkžgD|5i 26y4ly&פ"Hɨ#]Z"+ßՒF莈Z}+CǛŘfSE;uw*2-K_Dkl cxnZBĠ965L\8Zeh8uXA&̠-3M@  /.x}JD*8Bl/YdQz:G)>#dE?t: Ů@K k%vURv>pZ ezTke>S*E6MFqiiwЍ K4JQ֨,s""e'"zPYVCOM:p$YS4|E=D2]w-*:}ו@" .rۡ"j[0dN\OEER\ / o'nwIj2_g繧 68۹?`R|Z%/Lk=BXLStT3%֡6"A4%uT8$ĪżXM{dOd1k8qNCi#P-a1\ܗ UJD㞀w+~:1qBb`O ?T'bH=י?9$_w?@ _.^_A87 kp*Ab ui휪@ 5 73jXt?H%Rdxu7:n)_6"7R2 `Osz.V:2@!zh#f3 XRY9cϑp[ z_ұSq̖@69 r `ίbG /Y{{HAOT8U7[y(,p8pV-d9m%RZwFA+w•|/Qk 98@d g:74ZKœHQ*L&g\64Қ sN;)^sxRNyZq,w7?8EbǪYA4`6tEixC(&oN)g+{態4b,?7Si1h ^4JH vijaZ#YSy˃ڐW< HQ;"561sޫ,k4+ϧ1%D\rr"ev5x3 ɖNF/_㡈1y1޶/VJ^|`pLaO]7]ƿ &-\srS~\՘ OZHH*Q(]4o'B>1Qb[b1m*t&+<4Z1K\[:5S6~L>:ie',_$JowpҪZLJ2}wT B".хVF7 "J%R[xY\M)=p,0AicαM*V@]Rnڃ:|0XHR7/NK! u33DؾX Ulgo=NuаS<vATR>4w$|c7-PN QO$}TjDvg`S7]|ɕw~Sk9HK 8/Lcln`zW[, r<=/j)= D!G2!0nQӣύ.=rpd+OizԲfffK}RfriQ;zep߈RckrtXc\O4y QjZ{!S}]AF Hٟ_rq/İi@Bm.T I?: %lF`Ġͥ &!讈[ :L(^v#2GM&SF ݤ[Ґk s~ꓑІUz"zM'IDߡmN\Xi'!h@=#Km!0ԮڿivyECk_ ƺ֟=Pe`jP雏o7$1}*v 5RgĚW+dB2ťW=bӡZMp{[IJ9Z bćgRvjˮޣ$gNn YڷR.>c;`,[px]rZtF-7R>c >HQɸKvYg"Z5hWXU9Ӓ7[l$*5Dц(o۟YpEjxVxrXzL -٩_2~i[@ѶB3WxR=efsBǏ6#d́Nk#$Ekc /JmvaG78h+Vqא|00z_G&ńv2չYz [TĻ>ʛ̭b6a:PlxD)N.a# [~ҥVr^|V,F>Paִ /=n'kΩyYH9CkD^1* ӛ@BkA6,SBHm<?\h8%D9n0;D\k|$םoϙ׀;#,>ʮH&L ӵpӁƩIZ !_$Nj53BcҴi![z\wP)^O"9$oHcFJ63ϭdܺV.$ޟuRW~*!OqZPȖV팜M4 ;e?I1,=-s;CG/54&V()g=s/(cdh&N{vuGxuB2oΌd3> *rߴA7Qʘ޵(}% e ZH# (rn~>6gY uM] NήhYBqWrXb N& \ΞhZW 6 ueذu΋$Y4/, uދd[C @g$W%XW<?Ag n*Gs L؝H={\ uamlK=`W9#?J+aMzX-OV>%H|ŧws=Fk 6C_7ar\yU!}@̶rרƇvqrU7aQ ؅Y}vjqw& ut &J8 F# U&BAþ'lܫXD]a9_I.o32˾lb RZ)Q:E,S߃"d9 {Vat+'@%ŜT% ,=. aOs'Cu}ͣW͏76>d/iw=]H۔?VӠ4T䬖Y&:fuޞ3a}1IpCS;"hȰˬ*KЈ2XWc3mO*؃'Lj"mUI9 @DLnx§X)JK5c;QAX ̋rJxVu\woj]]N)5@5& Ve.hMq$}}iSg$JTjn/5gk"ZsZIg|<\͉Ұ-SՔu B_F 2z:WRwͦF?ݰ|ai&-g8g -PMkb["uNd[gyUېRsxx a~ J4wrpX=6L6EfsC_lo Ւ>)*+jS!91qM.SB(nWϫVthR~ޫ)*K.Ҙ߻fK ΋'$ZlȹLnFG>L\In95X~Hv@6MnlM) B̚ cBQl_4Frm0 RaSeusǁF| &{ &U 4RMOw)+ &v[3ꮺ~h}/\0FiЊ.U|8u/:)&FNw4kq[Έ_h\f<)5σx5(|ڿy *!tم:I3kPn ws:>C[^q$ Qપiu6; fj r"L?Up[o٫[)uʕຳt8BuWaV%,@a[ +(`Sl Gҷ4U.9Qe]]~P`:AVWsvD\]}:JHL0b}fz* R(3f<RR Τ6 Uȡ%HJc/'qF;X>jM4"g?DXC떷HnX2;`$#Q/ 5u`I\F7f:Yx(ZZ'e;'1Wwdpmfb1NZ/̓'sNAJ{ \`iV#bCϙ3;;+K@5(*7dS)7@^j!ΐ{y,>QWtHیsG7 ʹ8zEuP15'2C2"SNL9D'1oʘ;)RL`uBNDs>L6Sw)jHKCWbả\ hYg~2&tX3G8nHAr?.A8;Sbv)Ò_q~A$siM;ok?3\K [RwDo8 `Zj-!G'vbL%`CW^}O}eں+58Ӵ6x ZeVw2~ruP7E0Jd"퓌yxoauE9-e6,8}ߙfi0]=>|e]lF|Ί56OKI0ߒ/z  (ctHvBE9]F[~ %|$(%?whV:G&23F7^:荈VYS]>'aNH"yVf(<&lGqqR>_qֽI|<[ omH[j\!' P@+%D{({0g sP2${)Kxz"d6nSl(oD -&xj"(OYF*M㉌c3"41 |ZgNPsamIHh~p4( )3DvT/+2.K$Wsf<ńF?)nD!&و1@Zq38T{1^8)X6"Mh ~B>taTqo,茚t3:<v&X[H\iI,8teɄ/Tʵ}@dEM^o28םtIL2Ry'~awY(~ҹVj .WQW#e1%v" )BsE2rJS:KNȝ$])/ '̒W .Xw2bULE,Pb}]ҠTs2Xt=egi2 ڇɁgb_˘6Fӗ bD`? #Q@5 L֒: ӭz'xu6Cz-xC݁F~j&OV40{`x- J3 RRwR?MB2b^˖ #[ pAu#xiz뇶aX83k>{0dWU1x3feB^)@VS2- ]q7\ഛmrǃ¼ܲ'{vW%ZUxռ:wǛ/9J^;p"Ru::Om:*)Un;D;4"x;5.s> ZDP;VjO @ѴQEAD'^KXaH}CN"x&Wg%<49sB$\߰C`'j;ŀ¡"$J~ > KRe;}+ nFZRXZ,uAozDrnbwN͗7YB&]Ѣ;w/vХf>Oc`O QZ?5_ _2;mC<нt:Q|mw9BXea肍ʵx)p E93s3M^GTo*:[#$'J3%gd5Q' TOI맩zys%\0d1Yx0 &B$72Wcm"[8{5c7[8K V|U xi5Z?9FF_[M1{}o(HKޝw"@ kc8x.n8S5,~lIFjUQ>0i/քr߬CH0`mnn#='BbBz<Nȭ~;υj|VK1u&QXh?LF-3~4k7P!ۮɰi8M"/9t7( ^]@&PY*kE;Ńkŀ3DWL VW@@{LF,ꪞ@/flMaC&0 )M} hoc0sp a>f 9N웥y2Oy~IXPf7,;ҩLΊhhoIk iLw)ŠfmOeL w !RI5ep8)f䣩7,/KĢQ:Yldg򽪲K^^I,tո8(o?2h;8ꩡ[Yzꯄ־(5H2&72aMo@RzU!+-Elb9aJa#kė{n?cix#Ɖ:v$.L6"B]qhi ,qlQS]2t3"JiKS_Ss`aØjq^eͥzC}t4H(ĈY ƒ@DL) NITqw$}Tz'MfZ ͛ƣp*;Nf5ZZ%В'^"?":+SS=C=2N`Pg~&ƃ:Vm`-)7LriDY'Hy+O^E76F9!X: YE8Z2h؏0f \-W*өa}W\rxe.7TmS>܈$ +˔9< 8ҫB+t(,!v 'xjfkC΀ 9m8 ُȼ}~BDDy7-db`9@ 8例ҡXE uйa{ ֤ʾEF2Z3c7Qeh3GS^zNoZ u}A4E3]Crr3T {Z_#JIZ 1n|4U<DAMjvG:->dn{a=A" }^S5WUSpCq%&K֬? |lIf؀P-7*'fvI7Ƿ1-G@>\0\ }p7YA`E}q_݌wF5"/r,c4{x/3b޷c!ȒdCCw32~ja;=URֹi䟙B~&X$F1^|R8y b]inޡdݺ-+ ܚPeOc~dܰ\_5g4G o䀆2r t {{|9A⻀\"\fsi"_D x9rX476g'󫡏Ɛ-/Se3.,a!dKd(+#Lwou] [P4Tx h\s)nXN9@ Pj(7A?~\VI_p1į͵`lV3%[I:B cxCg +g-,*ǝ8W3ZHNF+z [ω"".cb ,6M["c.m>YzSmJh近VHuezM,è-5x|z—O2s2ReT5^Àاc@ xW UrDlacABS.;jLƬOhry}&\}PBLG䦉/I*epzSC}CvßC!?߮\d%oj}hljsl`MF#D9CZZCU,On̬ۼEz{}LᤘC'LK :un.:-k/ު1e%+Ø"]jM̷.\DM+s٢*wHjl<(O=;gs!0fFɾ3>'{\ )(?q_)~_$8}Fp;i%}m'u_pDr<9kBJtAKNXYv]_٘ oKZHalxN't+Baj /w۝0ētL*v,jE˚4)ڀU2wEG#Ylx:>ZǹU*M|eʷV)b> :BAzw>>A<bRʚgPm8< ΢FhV-{(:lOyKa9ǖf^ _SGt&8VILD!SG_q:,0 +pCWm頸'艖'7taץ /S|c >Sn.O?O=D яJ\&h\ҵCTvT vY%p%Vp=i7Z·馲 fP5G*T9y )Ka.U(sB˨4ηZ뛮 ] H;Vi^\VB]{DÐҰ55sU %mz|O]4YW%3 yyhžkUݳL VĒh3\ae8.}|6bmDA\h;ԈWAB=iGXfrQt^%ui])4Ff\ye%pM\< dunyS ajpgfVF6 wK'zOx2p\~,x? j$ ΍*k[*PBrh*ɻ}$-I"\:տʹl΄I㏱Q`&1(/qrIX>~ԗE h毸s"Mܾ-] d^Nj6p鰆]<6YkwxX>#q־<+zJs^sVa^.n:v$L<RFRaǵ6kIs9}̋ÝzA2vA颅wnG:˞AtT]N^}5 ӄb<)~7k,y/)jaYSBxAЖUK6 h{؋r鐼/#F-CXF!yVyf"kKN5\F=!xfaII~2t .Tl0^R6q_V-"x_kHݐHj/RʨH*' (f%":Y]_W:վau~Inrzh/87OhЭ(o%kN67վ/*$] k<^7 6 zq )cf[*3¾=fBĪN/sClV?Zpߢ,`ĝh-W\RX+UrTۮ 8U596 !Mbp:tw- JttX aWu>. O|=3Ef`2NdO|5ڒ נ`a^~CN@Rs9=@}j8 }I`ֹU\Н& 0>!RAOp f9-x0%QZW'é&èsiX«B4@7鯼'xD }v|bQ\"cn^uuXg }]NP<0 Z$#>8]Ye/I.R(AOYpe:EdF "^‡]:))SzJ!QӺ3!BEUsGY,3v~6}ØMxn<+fY.P͒u3O4zͼIm(+DPP]NFwQiE( r!Nw-B om E߫MExʆyHGl.k9i%X'}4Ǚ8h0Vg@ 5C5[#T>mͪѕBUl F 6}x VQA!6rYf4b>\77c'cyVlҮQSF \y-8B/٥ Zq2U>L]Xٖic-MoNf44ϥ%r@$nO858nBx01v.97m,'oh(tkI"wksۂ%^L.`9PwkKkgz.e)k+'9{):;m&̸F")OI2H*:wC K3.v&D٠0ByV8~օ8 "ܸ8-IƼ5G~{ jW WVov¾6u~_ɬ*Z*ndJtǝކ^nMFE"꽉2>cظ{-g4D|+3%8V!}lm3^ӧH}pVn*kI?\bo>29_ /[x.~ek|@ۑ}G"\ )FK5vg঑@V{LTM&L)D#%ge /ԈU,t^PbH]l+{>:K = I5 L^𛑑plU`VUzӬdq>mX-^?HT5;$P .nmt:r;߼*b-˾_*t#×5!r \QXQkUlS",LFe(Bym=<vq.iȨ֮ʼ.uf i3G0ްFuW;@2Ѻo3㘿d^~\R@m 'N,T[*R5Z9}].Goصtz$ru ur1}"=5; S=C|'7%?$*=ida2"L}!u>@4Qu3=JΝ YBvw!c羕=η1:C?--p$O2˖m1w F&6KEӞh?Q^* /ѷnҹLފ9J6ԍA_?˙U<l \<@Ǵ ͉ Ej".×.VBj/t q N]gI"O;BpQv|b0.(p RZ܌u**CDLq͆ -g㭘pG|n Yl sSK*/XwdXյ#"Nt! zFb~qA]8E1= 5L7qXZ4Μ"X$[K?~XW+hNHzQ846KTجsw}]|y6S *ֈ ofB{5v>2Z[[jw#My6Yܯp\ew%)YEojVTu_Y;Gp*]_) n}{tk'nbb/GY4阼X*I:F x ͨftb}KYVG8A{mc£'\4XꔄZzA儂.Dhl0kNU6p,jhnRVzM\BlRSqlB;,.?sP~ɯ!Q o&YcVdm^8c4zU?< ` /9\qO|O݅)g;oUX7{LHUWš@/6]`awPcFv  o l$'W7㒚4 Av\X$9<(V \8>M#%-2oMxg #W/TWOx9TpW,Nz^0ve&4xU¯Icu"r"`q3M!ȚBV5fWM9R(n5 O_#vEvzr蕸9U/\_%-tMJ AI G%{9̥2ZyqsUo2J 20TV.~=rq  (w˻=zVG;/#FrR(v\ `͏w];Px]ңA99]H5TtOH>cZpEqlsd(['/D~N3uﱻk/ލ;mr| 'i$BGqz&n۝T!iCs\u p|۽u빊mhn$[3zP~|nnc;$#Z@ux7DT.bO+˾EQ}gL_pp2K(*_9U|t02~yؔM2i \OAnxӮK.^d@T ^E_kB1p s åK|\u{ nE7POq3[LEC[)π{jaԏ3Dcf-o,pfIqf+AU|^֍59_p"Uy |wQWswZP%ꉹHY?/s[iDQ)hg*PećikhOz$0: ws% $pmn3!',FDtmZ^q3_%U\ jիTofq >]?6J`/E.̷!=ˁߜ_ǤɹiH U$cHaq}s%TurF_TK)]q] WuNXeU bل>rf&W:YahTuw{dPfl#!Hq S9Py\$.QduL5肋t{-Аy4[3p{gfCf?Mi:R1]sRI6bt4sKBCY_U-tNy?-G$gʴC\h%E_9av}(Wi䒂ee<7&&4/sv:i{a.ᩦ%NC'Ͼ.mZ Hb4ߣV ;-pΘE+\!:T: d'z1Ќ2LL_a"tYʂһ,6LGbS8+C&7hhY[ uPݻ/avW](A0j73n"Z\O[q;Dc1)F1XT6 .Y˷90}"`3$px% : }S2_w~ 0Sz}B&奈5KrzY\.-Ȍ`KOV drʂ2Khsti2#qoe: pks D2e|ŀ7D(fC:UYeJi15QauG u:3&[6/R$=?;BI+Y@joz1 d?=vurPe&G|ҳ`5g3Xi4"r}3#: Baœ=Am_$z},2 HZN8 +`"AqQҞyjj>@ +#ҹ2@#NՕW06!4'SpUM0B؂y9WbJ8 8u/W-s3 w=N5O 0ꞿlT] #i~Tх'Hps,_6vEdAK{aɰ _?ՠLcdlDfz~}~ys[rp/\ 6Y v蚹|B7.pb"(E`9W#/!k*[ =<Nsb协&+X/;XKwna.mu'XDTte.f6n7YR]'ɦ4TQU {ޮƺ\>E vÀwzP|bD@ڔNwE}V[p҃`ճWgAżK-v8<$LJ4sPODh3o1ϸP~N[J2yX#xɫگ-%\X?I${ZG5Ʀx5VQ-MtS?8'_i}Rk-78v!6kzaw^ʪ^ˌz9?>vsˣ[7j]i@.إ ,lАcBnH  q+'5q>JwG:lR UGSr]-u\! J]y&ӄԏAWj5)tG&̀ʎ VI|]-=}IA9;vsLxZ=:rlINJ/q]%zFkIky9-$֊2(:LZkŋDT!$ Xt,Ɩ1}ᵖ (fU|P;cAi$o7] kC+#эSθlD|N-#CEŗ1\xUsh*PhjFmLt+kFx\lzuՀVBݎ4׾NMIh%%ㇰ۝zJ|^s s? ]9QTЍ L(32Y@/έ@]=rd:J,AzS5* _d 9-٤7:͹ω&7F輁gx+"AAӤuZZvw묎Wk kABhpDBb˗t3,X,x;ւ7kI ,e践%'f6‹)Nmc!i5,uJ{^|w#O„D\mƁJ{TSsԅZEK/B.H"ܴVEjJHc`H:-'bDh1`'Ja}{hT>"Zͬa=URe*z >€3q 2"1ϕ޺K8]̃)$^E[Y֒Xdq/e*=/)EUJ ,{le"2r0]n'Ƶ #0:;KwPU6>f*);v x!s(!!Re@W'xT@]Q?]^P,U}՗3O&j>Nuv#Tf ^Cϵ =!:}V@aܝ~̀0V56-- ~ }SM#N^f0!@_؉yP\@ tRxIg(4C#LYxp(/FJl o;n\ 5Ke₏ݥBt "ֿ &x٥0h.U eR ei~VTJ?.whNjJ42^_!; lzdl{^AvGl)oWޥTe9 uWėm5PwP&~ƵJBUzR)b >$|JHDH13ʷ]/Tq+4+Q[$V-o<` ɖ>ޟ[%jaI 0* /#oH*IN[ ;a-o~2K 9%ǖjR.pj6lnTiKbQOwʀҚ}EP)9?1 @ R06ͩSɤ->558adN-Y|hH^dАOԇ/Rz= 2%7(3-݆:Hjf8:-[N>uOJvmnK$o~v4~#j JsM~KLus}Sx$()C#рrbwN 2'غ*#&փaTNAu`( ,Joh^Ft ^-`kxZnJ|NS2w~hI ^: #q:qݔpoz&Bm5 ڢ@AƩC [j!9c-eC͖?i(#U(g)DB7zmmKpq"1h]h1U[$=Xfoܺ>n&w9j/]~iVfaI{ njr6:_Y@ .>"K|f̀tcx>S~hlhG6(Ot ͦF/&g)a(ӓ鋖B1{Nkú'QsCfQA>SɋnaXsbtktx[o8DƩ!o2gugY`,J̔u|u%b9K9fy_EbYR519 kޱ< ʑB 21ŝ#XHs(rLjʠDkԅؘT1V`JqT>$$GQ}CW{Jbw~{fcQ*@ cs3=[48.m[ 0jʉr"cj9](Odٌ byȔ Ҳ"݃n>,pC^]b3xyq'ls^ō~QtFͧ>g8eH,SV9=),~1 4Pz! pjC9|`#>S?ꊪ91x ɒRo׊ϲ^y 5V%,ّ)J:4>&Z GA׊!ѓaVEzC6Jpt?]mOZ 3o G5#ӧQD1Dl 6kf,0r2)&TQ (ȉFI#1ûcipx81-_ kHG'ejtZޓϹXM_V;JJp_~Mq^ ҝqrx8(uT:Fp+ZVIy@najr}%1)mh{הt? i:0xbid;T6zE_TB+`PG?rpl%1 >K,h ErJ{@XGhK=Gs PNTJe-A_x]A\ mrQnh]rD0F8u5y{1Y8wsL~O*lexWMn_TLؼxC۫GViϚc6#Wᄗjt WCιgf} nXj>C~Hsy  ^Hqޅg'u[NU 1w:R| 5m3LÇ53 c܀@D1D_pߗC>q -?G_{ S9>T`&v06)( Ōű1r5x}fÁX@hxnw8vows/w\kNM;zݏyN)3&'Ò2dͅ<>EZxCpW(M~*+,\Zħ>S~ԷQg_Q}hܐVK]$\%!n[HdA,w "~!4I :uzā73KmPs`5Q 7c46XD0p%OKepo/[@FoGA2!HGO'ci>vdu+o4)J!6CŇ'g& E_dOvtfsdŊ%<)ڽs'})\ a^VQ:z/ɝK t*p_/_dk.$J4J yh-bFuTʇ!2~R" ƚO$8yC*hK9~ }6* Ko0,p9%֕=dԳP &g+Y.56RueL_z3ƺ.MK0vȪ5H$򳂕TC"#id(T({,}BNk\Yh롏)?gIjD'd\na߹`6iiOQHY=+ 6.# "T*)Τk4E><7׭Ƚ;չZTF3r-LB|n !d^HmhΥYKлUc凷l7o3Mؕ5i$`;XhRIQ=b˨d$顀QI'rFM¼qJb_EiH$H<ޙvc H퇼rFE7˝.>t`J< aLeԂpX/V?\W%#U< ?zdh,h:g HS]+\]\:(̽?vI.Ez 8Lb8isLwTq9d)/P¯\ Ѵ:5۫2FGp结rf 2s-=mh w+j2L֋|,?MZzE :82kCʇt Ds/XJk&Gp}%q]mt{mei L`8'ERqic1Sӧ`8SCoU1( BEK y}ܭ>jGvRnGVm1a(r݀6F±v@*ɰ"bk-ΝL4=Nji)8!.Yu/ Z\9ɔTT7E$hFlr}7Z/=WP5:6 ~3qv(`h}@4fqf0 TA\tW3 ߬?\B98p գ~L-986 PЏ62nCK:Ц&!hx sRP4&c{hdIg?Zhxoqtkj1%DO/VNr9mROgE Pi7=5kA t,( (!?%W y?V3t?k2AribhަC5_Ë g; z oF13AuWP XT?{Zv1ՃNMSTqȜ֚*Kq*UI̝5I^~SOQ +bo2o5"[6vsicXCzJ@wnTX| JaeT6XsGDZ;xpÕi!֤j/Oϕ?r|gb]&2?r#@"Eh44|ӜrX&¿n5Ab3#W4ޡZ &ʙqo9KZ7ioL2s`%;k5*X 6lȽBco"Y٨u)lq{Zg[L]TB΢ɍl9 YUPHI ^f>oaO. 곶4Gݘ3k< |}'EсjC_ъJfVC!7cSFt(o8i3q tY!,ieZmk5jCHXtչ$88ҶXO4ʺv(3ԫD&їi'2x9$kF?)=}"v7pn5V,GBY%|05M Y[Q!-MwQ(?s4qh!@nKm]f/鈘\8?bM>52 㝇0- znd fkU#75O8sS g,Hfr*^EksgcP?ϓsί(ㄯ:@ zd>]`2= Y9w"j2ʘ"XW'VbOP^SxK>5,fW?YAaܯ?O˗ރxGaQ(g /S=F<p7MߡN!v7 xmp4H|iVJS9A ymlDod `\lWRl"S⩣!KK*SP:sXJ%mJPX.&%IE GR; oR  F&&໛=dp\rp*,lw-=#xvpܠ~` 0M3ԗf/P֔?Kap> ٛaI"ݪ~uy߷Z ^#BSҴK]@^wtnh<3!j=j[.va8uKqd1f"tNc[(^Px#Ⱥ*ͅ#%{!ՊTF=B'l|wc9,+p#䕸Q0X6AՇV8yqcĎ6^#_Zɕ(V5;[-zˋod=Qc{dM' ˕AS`a$/cwɜO]!YCpyAԓwF7]Yڃ~vo}d-K4[6Z3WDa%Nr-/3,p- r H[-.z$j}dOhj*a&2NF)ۋ2/ Oͽ*#˜zv>.&n,=:G\E 荘@sA7IF0N"XfovxTe9c 3:gOUX7LD@pddCn(0оW;,y-`nk]QgMdvwa󑜁S7*4Y PҶ7+0~|d%+w+{,ZWWf; :Nb aH4=Ҟm"Ae󑸟+S6W\ .YwbFGQ U/ HG+efnG+WAźUf5rhZz5a#`ۑ(I*QXRw_BGWQ$M.!נK:0Kv'@ɮ?7[L`xAnzǢ[P}4 9ɸsQ^zϲQ/wVRW'i etPj~xdZsѴ0)Xp5}Wڟш>yҫŏäFt2"Ĥ.W5/5N=VTsSRf 6@1'Z {RB~P?ػ&W #]^<L$@qGe~ !尒oě5̖qZ&fL6Aeb*{Ac٨Skv_r˫KoC`^"ѓGd6}`J?JOji&]jH*Ɇw?ZA!Z^ Jw@H!m-+3MORћy&L{m&D_LI޹@'D>z=T1,O-'rNy7h98(x҇} eڇUEgsm7J*0!HE&=U ;޽v&UIEk6\ 1 אЇAqVO GUӻkJdvzr֐QNC3iߧ*Ge#qs2΢SĖ1 o犩JIKa*h\T^<ᗾ' хJMN#<>68rD%H[^ڴK`wl%έT-a:^@R7=u#U;fT:"{UL_ m*gB%? ƏVL@V'Sx9?O5eYw G$em٦{:Kɺ91ⅷ =m izN/Ta|u}韄zõ)q y??H gD G`]6 ҪmTxKCdC0'FIC$, #HlMrD8Zϣ>ǿK+%lF%) BC}eBCX9ɍR\T3oS(uFZ۩PCO R󕰁 MIHycIU:2k( +[#=jr_C?mv̑M2P|y7r[ؔɝ"M@zMI<^g=\BH_~c BCcLN&dlruTTjƈ Շ=>Q"'Y5ÐxZAلk(,/ 盔eD1haj.7j'VkԗT.]S l {d84%JPF駀Pr0ZW=Iz}>$49F~Ԇ6޵F>ұ'\T.%pT6u"S%d42GeMLk&1U8;YP{W( 4tDH H{bq/Bvw4)^ŘXE\1VlՇ6E^B h/3Z03\.$T&[\-VQ?+MpT[߰8`km4B[_NUaݤbꄬWh<:twX0[ |$|k !d%ՓU1pM<kКh Fa+eUWX{{{r[[2/B3xփRN2#}UC2uta9(RG'4U7Oߏ3hl_YvX}NFv.3<1/MniӅY,[X7Pc']&.+? OEfhx7sW[#.0i`XKpZRym7D|Fg 2"C2`&Zִ^7_P<0W_S}s.__r"օ8Auc[hæõ ]^gޘʷ&‘=9 `ӧMx COPs(l5G6dϲy?8j]y#7;rɔKSr#Ҙb KSFlHh:gC6M $XHfdJ[I3}Y \Tshz+MD&& htCevE VUTCpEEFQR|\o{$* }lrjWk ._J r"r첫\%MPy\Y[ "2}D|syR{c .Zen0L엍=!ϰNw'cg?H8g>xTus]}y c 7!8c}>6Di>iM&ul9sr84"RM },M\+%F/?يn}'rZ |'a= 'шH!@ZɣaF6{ dJd崌9 p0‘W/=]CZ JM4Q*s}QhZuOߟ47[Ȥ @@=1}}dk̿ g@dsl %aJ .2VpZSl=8kVͥP$mj>x +ߺv?JKՂ c GPDk?+ω;+@~T֚E"\Hɛ+\#;Wvi ǰS;N,xѷl%O4bj7bo UǒqcaIf~ɕ&r`iޛ6I5IA.yH\1ed`SF/D9](`ۂlJxݨ{ 1ldvdՌ tC]a:e.^(3Rfa C"'ոdZrbVnժ9%XxB"-/|yGHb"Jw2zCѥ_M HyGF[R\KAyT5qNTw1Dx9 "h<)O!m'G\I}:?]EF=snw) arFgWF%Y.o]뭠 h |I;uPJiy jz,opCɶw\3 A[/` xY BPvf{}%g,tZ].㱐U}y7`eCAG+a$.u%8"=/4* $tpV(QKn덻ڱp`bx}8"iUcT3d0Tv[_WIXlfG8BxB6AE|Ɉw`HOO*V:#efj( WzٮNE?H g1?7C80ã8M,?"@VU`M WjUJl<6M U:k0*fuoi)dLیDpof<_%L8'.ZS^A|`TSѲPj'$# Z}g4ҲygR'[Hl87WjZkDB:-7Hd)Ck'5*Ye5}F70md;|HMycVvnOyVdHa?I5'l|)5W%qOi6г `#z'E5y.ZDX)yv߬}K##!Toas)3-z5nT dwo{O 9S ZMASBuI!GCUB\c~oI-Rg*R X sZ%HRT}"C$=NVw)SUR\Tb6T1Jٔ̇܏V]Ҿ盶.5dv"}8qg͘nx^@uYgǬ~~zQS6 (7^풫LG梑L$vqzŇ:M*6KCbhE-D6n%辶O.[0@*_O Q;d09%uf$YTF*d [vjeQ$pO>ĉi\*WI m.$k!i! !+O/fVeYqf @5'2LhD@p^"sH]s[W6str]Unlf|I31{"W5i74Rј$ ;")yТ-slPeȆVj9R!җAy1a'ЦybY̿ZP۩b`ࣩYŒU~VwTmo>_ϟټC#4+(IoR}gf4iHdlt^vPɔ ZI!e*",007dP=$Eo |E{cV9! N(}oOxOu+@&uyIN½<:J',7UQw4J  (e^w›Lm)D6`YKG\kGw&< BaQL [%I>gwg\@\96(dF'Z xt+C(>8F]7nO5 YPEYEIl29J2͑:1brB!i"+M..{ܣ>R u`r=3@n) FL<^~od9#dW(|t)N,gi~MS^Y_qGS{~ިKQ:R(4 +gg% E땶X@3k$9+ћtaټUǧh8םȾUE1 yć_28Φ`/ekcl"]tzZM2fK7 큊Fg+_@uѶ`\{:)HY1?GkF.USwƉb&n yZKwY9A(tZqZ?k~ U$8hY5nKn  v~AoYS@Vw>oT|R@N/goW ܿv|ҲbYq~7"x祿:)2 Ijl@P.qkb šh1!t#֐Vj.-;sTٞ)&u U5gY'_^l!]ܲkFۯ(qZUDڦ61/E8S螒jm(ŒC9ܾeBkV'';I[yƣ|+:LqPj0}g÷S;qoɃ߯x1g҇<ƨ^R] U!Xq^ !vhM${|ɴYDOiƋ4E QYJ^K aSK0@Yq\Z׭:qoUF5avd3*诘'q8w"%SѢVͰ>g]UW$g]&0-z@jePpU0 D,vzZ7"@F%k"RQs*j2?F^.xжC5..#_r&o@+]@fH^0%w،4#o>,G;Oޜ)gb,߃NJ]zmM4%ɳBH-d.kKdHI) b:nƗJ%FJ Nt(1w&ا buF!GÉrt ol׿}ĄM5+>U[UQ밿Zx4,F֑̅nfQoj_ ƿ~]^K6R/V$Zd ͙1t* `#2ĮsC~)N0x xZO)uY{E]Λ~T{'$ׂu0Cy!IG_/*ljNb _7FpXq#q^ңH>9"2Ub#2'+,jfǓ<O~tjƬ2bumLVc!\Sxhn7E9{O;U}|'47 /ddPvZ dHu" A@6g^"Ll(;pr=QT̼?˭LSjDvn| jLK>HwmJڟuVȝƳ}o7Uq/GFMˀX,&N-(UYr|g|\FRw_Q+e{x&M?HmE DbX h8'fI?qYգMmµ+6bC^QD 0R-Z %R 9oTl/ n`%=Q5 z$P9OVЁyi,p-fq#t4AsZ8z`slm@ހ\A(FE-}׵q<]&&2ß62"X6ItQp4NQUFVY}pt02N%#'䞾1%Jq 꼺[N`T| r?)`d;+ҸaEC;OͰ"*TuyV\| '1 4w@8#fKbL膽B"rfbú@ ѝ,[XSPktoծ:4ł` x.hv 5Irز7/ h;2;D^~G:OExΌ4` Ag_H1^6EXuf 67Ci c'cFzt s\-ešfnb uiOiI2`J=H(5JN)KȞ3"ISm^S.5"5!3pu@Y~QWANws,~+:'(5,Vԯle_3I@%wtŝQ([S?~0Oa:6N>pG%t>J AP ZC܏аAe_P x ں؟Wv)K46.^' İ?}5Eb>s&\P>=#n0Fnw;B[>s#QXGRѹ53rc/ Ԕ9@P3-ܦhvA$1%ũxZ"B^؊󖔭Cm 񋬻jt*rg|)m3aڸ6g\65ԮIgM^+"gF}ION [J :x*Ĥ@eHd=5ΩG m@lRb$ܞ9wQ;͎{mc=7*H" rDM f?ݺ!q#_?r:/}F*ABߙ]ĝ!|UuRos". ɱ[<ܯ)v- JmC"w@ i/C]#\ G:MfwG 3ӊm-1S Q_ɿ ~Q;=jBڧApzǶnfs9盃F"wj1(XT+S$piݥBsq&בkT89$J&{/[1dԃ ];[~]lal`Eysۙܦ h^^^ 2l d_B`"'?C=z.QG݇W{G/J6;mZ"`os&ˏRzԳ}y=l<3?0"@pkH"Y\1j.JϨZ#l*0f|;IBꥦYo[z嗳X*]EDe(12Mr JsfZ0[Ǻ.oz&sN1罖ɑ4l5~\[~:"˨$(S"NG:PDԙ%4=뺏D0v(Y!i;F]~0~Ҷbm[^w'56* _hi4Rg VB@ysO5+ȪܿĮ)ݣJ*:l"6qK4:+A% %2LKa}!ѫo7ר6o 6zAJs8OpPtbz0+&XGfxSb8@u=] ,D\{D(&>0vƃnQC8] Mݬ (Æ烈+R>p:F USҽhD v*_`/z+<ɷweWCOp>\:xyӱxd ˓7M+H"6W7vf,b8 SURXe{%b|E`x1 y!.OF耮=Mk}c-Ŋ+ u akgJZl͚2pW `uLMM.ą reUeoAsoyx!ޛ3\($4u<n&`z ɟi+23s yxHEii 2™^`4~^c+POվ(tF6OSqs괖~#]REݜ#ubD3g]R}w HZOҒGs3dIR\&ZaӜ4ǒAQ˄ّ3ނm۪( #)e6s}m"'5@N]@\,I)̎h_PR/ Yij9b^灪vzB$;$ldz61؄:`V "k8P{u'D8~2Iɳ@=,2@|jbZJw;t& <+@طm6 ^&\wiéD{4&}YPFK׿#f\qSȇ_Kp*%јA셨W8PH̓$pY 6@?wXets-!\-^ nc~1)ʸF~\4I*v=fp1?TдO7I2WKݠQH%Qwݽ5xS7vnsWEnϕd7neD_kDj: ]ĝSt4WBn!\%w_: ME#9:M4)VI}ޚ 4Z$ D'K˾2bbĈhdwq8 j<&2UD>9Vft^Gd:vk<'yA&ZnHrlu.Q#>} Cp-ާ[~ Z UPmxz/H޻hl^6e?!jv7/+<2vu=(N(u]E"r\nȔ(,Y\d:xw?΁SnB@dY!8z{uvxTz...4յ X>v+7,UL H{o"آU,ZldNEVv_}6Fױ#<]RB߇^QW\AnО1Bj"Pզ<厙R`GFFr!TrM[X`-%M-H?@q 6Alw@# U"V׺C3xU ;Nd=x~14?tsg ht sAp&!K0s x23DӌZ+~[WUJ;G`L#U1-!6|LwZDb7LO#CO{Ȟe SQ"{_SšX] P/V7бy5~n)9>@#I_WY#1|'Y,uG3X'wRNj"9u>Nj<hz ~Қϐ{ȘƆg ^T0 >'KfE\4R5w4d|I@D7p|RgLg,.%j;-^n5Q rR'ռBg+N,zSd9K7E0K3fV!fp83g=(~{\/05/l⍚Ln[ZT֌9rP2`쨪wlR퉄"8IF)Q.+)@`+[[[g|PELF.REf~lJ,:OB/CUN*$`S&V6sl] ͳmqyPĪxL;b>EIN(@YO@Pw0 ĩF\]PNp]yZi-!ZSq~tNEzi2s8֯WN|[܋:.(kPf JFlOBWV퐁!lvufi|x.Z}uaCT>!u-r MTГX5#*%Yv>Z7Vh~ \5]s.ҧAkA*}ݪj7StZCRR(8IJ&0_0ɽD1-Ę)`ť"]g-+Y#5u ص  &1  4gӒA'&Xwq ,Qîś@'EA5.0Y(Rq4l@SV,:XH( hSƛ0!ހ3հ|{l;1ìL֤lQItrYOqzQiO Ro6y3ՊDa |^j=("kK|CZ$T\#ʂE/H?lI+M,!gepcD31*}gЧErKwd'+|ze5qZ;z#4x r]I58lC=92)jEFyo=[!>pf@gߚaЃP/U;P_6Dh.:+,BܓnCi3rڸc4ᗧ|$ˑg`B?6t%6X(0aRv C;wчI#ݬ q*}F( M㑺hC6E`?QJ&x`eow|ѪC!r2Mp2Z=:gƯB&l$?}L>U@^R>uRZCl͊ bS8N3&myNoً#iim{Fո6fz\~JZb5TAN65r-+0 d+$mt+tnvp>)%"fٴ/At\[FJZSRK}Q}cMq>MŴa76EGQ0IH[LV Qc&ޫ\N׳wˀX<]#%T л7? ,0~{G$ct.P:m2QЈ\r#}/^SsVcYOtJ$/K.5lRGnyPpw\=w1pPO?$cjϊis;a? 5 o Qq<{`?a/3t6^+%r;Zi9Iҙ jacvǪi(/;ՄfnCkHisxrVi;Lߍz&U2N4&Պ*8T: %اd9 cmwm#%8aÍSOhUnakT{V@8?eƸYm@0&Hi*ԏoȊ9ygxole* G,ꠓh'CbϘ1tKMmRT4jޭ#3uxnZ64F\^+Cq:UeM/4nO:l & 1Y)0ה> Ĺhh Snz]_QH^966V*;}UCq7Om?tGbkk&x(zhU[<ҁ@!78=) EpMmle"zkYl;违̄CIu =64.%a_$m=D9֨vclZϩ!eӓ[h/S4[b=p9q |LAg%j>l61.ş7?$̕z"( id/s6gdau\FmGc6yKxo|ЀV v ƯP' g0lTS@v>";H=4BIg|8 ݊ph #ػ}Z!"yo*D꣹48qSsa+lb|f gjk 9~HԵJ,*4 T Rionz"a/\Hrf>n76g h%~(ѐ@#K!\Wǩ,)U'nPAޕ|UWO,8mꗰtѪȟ( e${Q-2-E=7! y?X,v'Ǒ8wu[-\ 8oh_/gB.(tOv롴x}T5W^RsOd'2\ ^hX:DVlY̛rlfL2kY˩T"ޟ^t༮ԻZN'Lz6[g3%u)ljYT,l@ ose?3l6B-J+ Xwcr~4s4 p6[M^EnQvaE& AR{Vб;Y=ΫB- G<:izsLFG`G8]\ ZS t`Ҷas^ź#*s!}`ФV+zݭHӧ\857jߋR-a!;Kd{(D/2{N^Rm Zun t5Fň =kZhU n}A >6 S$U~lӚFva8G@xտu% Jz>\ cL+J1kYmD(;̅Oke{W̎XDP2gzIJM{ "a~~,^aTEcCw]<ߠU:hd*Gw3};ק3\og7 e~yn{z80MLjWt;Ch')X7WmA7!iR &IǩV( )բm܁e[q Q~ &eI&8x`F)AHޚP4%ԇq‰!vKCY #W{/MDbyK.]U%v ŘigzFp95FȰef%j0Xylm"+r/ sor0o Ȁ2ӒE+]JA2a"ACw7.ECS@Yz|~Z|ʦ !B>0EpzeVXF&' 0b Ġ ?ڜLcf"ov|sχ_E'/hJFicOC4%ڬ=od$~4}w  >E72rƥip*UZ,[,YYv Tڦ Yٙ +BAJ,@,zE =7(MR^nB;h V_۾8Ōl\FSn,?kNd<E&W,W}"Y3Yd ߌd`(Йx\lzOdkd53y|Qɱz0qmN_D.'|xnj5:bY)ya@#[k}3PKI6 Js%k8;w~>o}ƴ@Ui vbRQCxia6h^g;ADN 9O>jODgL[# 2 ^jH=!jTLc7Ə\OeAF>ۺx-*$/O??qtN {)hGAG, e5tY}6 d2ɒFԆ 洤FKd󑀳^$i8l^Yhli7.uDn-:, ennmJkX<\_:g!61\e)= ȗԌ^N)w ;;DOEުjx-U/!YE{,8%׵\b^I:PIJ$(-7Tdi&a QA&&Z͠Ƨ!(.K% &~ eСS0ҳ)7]Ƿ'Bx"ZG!#Y\X̢s ;GЂY&ڧMV$L~=|,Ϛ.__wX7eL'oϣ %{hGfŸu*_^?t$ cYʴT[in"x.:뼛"n [XC<݊VXIm+ק>@+/-(iՁ"FAkF|ydK3$5&˸jpPُ#43mB $ ugOGxYq+L5}#Srũ{[u'~l~ׂPȰ^账ydG~@%vfQfW WNsj URa'd' D%*`G2.iY/So$]\ ;sr!87NN1z( [WD%j;[W"scVEf>kSYNo$s[ Dسi0+LYRixW|}^?a\-LxvOp`{R,5JhC:;Gjۓ+ i`h&[Z9rZ) <a-_tyF UЎZ! W7ZmƐ@2zG0MtL|I6;hҡ?WUA$~Oklq*ɷfMz@}HJJ7;>@7Nl1Q\!:MbW`?R' cGG\/;RoTBNRPXOdfnA_ 0'h&<-}yapزZuJ1Yj*@=~Bbئ&q2`c͍M;L*~]$ (}zZ*;,8P#S-nL$MȀo Hپme$ n! \ȽMOyJtoz81c虤@K^q!e>_1"BU&( -̋o߫G'?XhG5KO@*l؈}BT»Ud;Rːk c:NkݑM m&8YuZDi;K×F\BKU zcm'ؽJJݠ;{_🾄X$ib7q<+MaKvޙ',0OL8kic+zC͂HFvФgIB=3USIlyLݔؿҵ;*ܑ73T<)͉I0~@LE B̒WnHFuD^rGg|E^ڃ zw%<g#KhB˾84T@ ^/o2JWρxO@[~Cʿ 9 nm&XYH mȭeTvfbh-Ý`*GҹSQHʸ7Paj)K>ytz Ђ* X*ޡo:kbyVAB#[Ʀdx A#`lfU~*=)iNg! u.JQ ߃,#ߎkY -uz_oFۗ+F7=W7&kW`Y*fB%1rE˾}" N\+I@-EXGH#Pd;CuR"YkO<~eF>}uvI&,,f<N[p*"T, 0V\HEVM?ࡧ]|´x>pc@ywO-@v1ۋ'8ֲx7>b)o,16;*raJc-|f(לS%:,T§![#|nhN-y[sȐMS^N[kSE)hp ޮHgFA8T ϊ i|y2ي+NCj x SV"/pGPPΙXV24%WޞkkHY酌('4>#xn]wc4pn@XA%p A7z_뮪Pc4!.7;IT)Dm-Kb"ݻZ!M̎P5`fB8^wvX'aU}olY wFIkwS>2J=4iB?fZ58D5,CZԋC]R_ibuRDeG@EnYڡ ؍~jD(ܕ/ue ?R}aF=S؞=/ko,2/r,{ }%maSisWq2qK4jΏc;ɞxXGM]KmJwuY2H=UlA ՞XsV@7 [ݘ'y#n K-l&mԞ {a2E܁_/s̶:]L^!V7Ӂ?|I%r2P&Ylޛ!SH,ÐNj<%hLiyfkV[<[7HgX)?[/r 5ѫdfav!i,+B_1m+)pGK* _ &/ 7jxwsU\]ӵV{$LK3)?9w0.8U6C'"9 9na ܛݧф5yIb7 xz?Ǐ&ܿkSLxoŷ=7 \` QǪ/? 2b󔮴96]0=xDɌhwV8lIhsQ.CIMvUSlF|_fA vv~ DF!+OH.*T*u񛢜d?it9W]5RϠ) u|$ {/,ʘ߷`Ha j~NL2Rtgi 378LTJtB%AHQp3vdmm\arP95嗀}W^*q[323~xKǬJʧ h%~3/*nus3O?VϥU &ȯOLu pF,wqX(,M"TO _Re^3дc-@E;x؈p>>8|"tpC}_O-n6|WN:|a5(g=#nye=|ᱴB[ZvM[sda> +0L7\I e~GA1up )/'=޷dXe`m DG*|*Ҙcq]Xp9'_-"]C5_Q"8")/@|Hf%Gʦɒj7uC` Q|b@fVtCJj$?NRn}FT$_RFF! <}+ /^.'wh: ŁEv JVUʦruDUXe,A A2q$5GW-_zz VF5{%t]@(5So' @~C2/_sֺ8;F]ۺRHtlsQJ{y#1ꊏud~\PЖ#ӞB-~ XseVXe xpฑĮv 'J{'g6-, y&RtMV K$")\ Q:vAك3 fy2 Dxhs:Uy\xKg!71P餑׷ '"Ʃ 0  TRw3Dl ɛ"8&Q|^Փ-;Ӭ{J-PdwC؞/ֻ i9Yyt!Y#|hwOz`M˥⬴>^ý ˘ɓ3y"d}#m<ǐ|JWU-X䜊'xΏ#BD & $Iz׿˶`>˕>YdZ^V$YZV7qZA.Xn<]ʥZӝPֆ3|~3?tY<9(8KwɅy ;Nٗwmw!wskp*'+csN۽A"puIzC[.^xBj5(OOռ=(4 nX\Յo-W'(?(WfuL+xNۺ͞<@*c M#B+6 hF %"\Ds&K:މBA>8Rllk,+uw)F}|sJ08-BLpUp;101b7(W7k! uwH7$N'k{掾vE,B:7Ih g)t,(IZ1Ǝ߶㟑V0X_hHʻw:*gP "?ͣh~gz?!AҫdB{jDHJwd}yio=hL7K,JR8"m=an0'̯ެ-Mhs蛋s~AGδ1m{N|FP]\CQuǡin|U)ק%w^J# {dc\ KzVp91UhS@9lXU$i;h0oib\ s#ۜ=sv1L>};cnzԵ.Q;%b0e%/%%6d^Dum{W_ZW֜29{&bkM2EoCfw3pƑl%*1S+۾(^f0>3f^7 |X:O֍ܻٿ#WM+cfܪp<_ގ&ˠ9^qOac;CB6 n`]L JY1 D8|hC~b2㈀_c{VStoQxhI-(Y{wZgT !E/=0|0S BE ɗTGr_\W7j#ݼO G=,i{lRB\t8XC+*T{WDZHFX}v0F]Ŀ>\E\EK %#A3!m|X Bpaq@Kw& pgdi$FGdf. ǹGNa[}]_F"(-휬Hխ[%KBo~ThC`Q(_'5LqJN$I K˴Ge{dp|#E ןᲈn 1-(U}/9%7׿=_6M5'` __*KsЕ 0ZcaY!c:YI?#rgG~E0 \c`V-|UA3G j╠A(%eLMO|7KcBe`PEMvɴ>^-@PpZ˼Xr'?@[$7Yr%N/amƈe.y_A$PU{jAKEͷ8\;4J˄4|<^-y"^r*FaST8 ߽d3*dbDoUx^6 oB=2 RRIw$'7on"Ǻ$l^mWmF=ntr܈Փ[)[H7I}J!h{:HZxZY+#igaQjvB~PGBXB.1rnΚ^$Yw7 ~+ۼ[`X=e/h^Z7YjS1L\s Hu9r+S1v`kc~XOA'{ȿhڂc'`Ua8sM<Ջe[%Ǩg~M>rl5lxdIqi j^H<XK%Cjvv_ CQKTxDslAnrpts&[)%H'm̅0+TD`ʦ0^M; VYfj>U5>;UuYYʨϊ|u>K|LVw^ފϯM"2#g0&݊BpT46'ƺmvkT &9@Hp(f&ė}Z ]m|SܙWe"؋pK*Sinz6Dn(HTP/Ok^of} "pkƅȗDT;e [X}lt5ÓU)`Bw6I^rT]-5I w rnφ/(iӥFYy_['P,)A㭓G< 8isWGJ Ž RT5TZ-5Ci%"25BV$a91#qfd#[E=+<Ǔ\$`H'6HC*ܛ JILKp.x˚ؼM#Џ7A3N5k;*N(, DfBihsu]ʡ$IʂUb̓ŮoXU[Ru {d(e*q&}IN7C^lKަFDO;]_ $Ӭ~[9s`qaB9ԢH=Px:E3EhISYMM.@M^iJ e`c\a旔?8GbofڍԘ=g*VQ0qiG7Iu)Y2<5^+r(0$^iw 0#JS=2IՌ bKMO.'o1Xp(GC^^Iv&%h=-4'%Ҩ#Cї^,7Ɖ1 f(H_wWF78ߍ}W<㉁eA39i('!M:Z8MfV ;Z.կa.S#*Zx0!VxpHyO65PJ‡ӥi6O8C0DŸS){*/)"H*}b[\ɋM#D8cI b\K[*uJ)@T=tvԍc:9Z⧁bZi8 K⮺zWͻŲ?w&zC&( D!:@\BkU GJ y%@zSE;L=$m:6A }ig.u[Z3[BN-lj3dx; H2Ta`mǤ<\ t[҈}88V"y ̡FU-ҪA ,wCr'cAW"oEnkx͌<`uL068tZNn 𰷉T59L΅I"FqRXn@:_:Wf1^ɉL:lRĴ)6ј|8߳n+S8&!囮FW@J2"ʍ^a"Z|ܓZ?++Gz2e+4d> <H?w iHP[Ek6Q '3edk8ZN<ڧL+9]鸽v_mTg]}/ "l j u݅2%ZBb:< wdxƉ'5#"6ma)= PV^-6, fCh}x`|.EW`ޠ[ B fq)O]k +{H3qoP#n~T=;=/qU4 ⑉A Eqo8"XxJA +U<[l( o37~ *@W0㯖!&IT7qXlO9tbu7%..@E@а\YF9gơc7w8I!᫬va A|U$7pp jzpgtͅJ^j0*eV^)].(A ;ԗw b%N8Nii7T[m z0j2(7<2 I ސͮh3a mMbI{O}E˜ 6ob @3ϔ›-xvQ(=~ڙ7uCM[ة#c(\FJ2Ϲ` |o x%{'_Rnv6Y Ь_m) ,+jJӧ`e|PsKFy^7Õ|qbV[Y=rMo2Gv M9z[юĉ^FshP9Pm ~]yڻ%N/N=cfkwAgSm:#nh '\."i f5L23oPU샂`Փ9V&F'ucF9}!22l?H] b/AK6q 1SBFg9cecuẺ b<;6}8;pKڜc |duZ_ҺT0;v޳Ie~k%F6r}Z;2ms2WJ#Rtw\ eg)Au]&E#j|e1R"M?C;tbX8]Ut%' dߨM08tw@l2_4,U׆ykX&=-|:ʎnQK\#e. [}v"ê.@;|Ӓd006S/K?\M(Z*[ Zȇ)OP&f`<< ǣ+VevcE%}o`? w_аa4as_bis{ʼQg]_'^V}+!hvMksBDxY@:UYD6'H_c{n!it5Pgί)xX0AZ5;4*7{-oNdو0Umу#,FqvJ38WY`",kI UlP\XC ebpBYRg,,u0>5-M}*9JaSs6J)RrܶRC`l,Xu?q(#RszIY!BY)$ 3d8^1B#ѠupG`$GD'a;4Ou4X45r*:@q7ij1G&叽9[2]4[?:T8'e{t0h:B 5b=a4vS8悘!/k-.bQK8J0|%l+鷖-ꇖ 4mGtŀO©4n^.1ժrkEg?'JPQHCKlQ%YXko|#&Kc5YIR=XaҤX 78Z,Clacҝpfʫ4dWkRd,ǂ !KeUB`f@eŒUb©MMv` I+Qn~O A<>4[M,\E ~Xt}9n{Pn>fz&bʐxUKL(s($EgO)[6H*oN P.R[ w9tEjojlo^SNqQY|Br(k4c;"eM:`ny^a*ᴻtn(b̻RDv;>zYRMُGcB^[%F"f{V J)tV~ Sq˟qܘ£6P`T#=MGhԆ ]=\-#eΒݽIߓ}<5K w%إsD!ٛ!_{c{QG=F~5woinS㴙Ϸd-FfI SH颜OXj$&vsG V@5?jƘHYX2=DzPi]O weUhW5Й0_'L!](,CmR btHdߙĬGG W8vⴈs9ƓҀQ!KB2B&zmSqCW H': +D`ۨ=sx (vb|.ڢi822~\?esusAذ/e6F_G$hոLj?g4~< u/?#NF1lQ-0w`n\RXM2KftX'|Wl-"Jj%:N(Ur \'B&]"Ol&"xPwb]q.MI\$aӺ~#Hw*SQql}ieޚ_ xr8҉1w.3db]R)Z_Ο`zS ʏhxUQ&C2ϢӀ@}Kuƨ?hƲB:.(A7|Tql(͝!e9R r}' eXc[xwWU^XjqqVH )0/Yf MGY!F(Waɳ+ZzgHg,`b5jK^=y Ide)r@X=+!s읉ڸ B/W‚QGUr@ˇ𡗶~oGa(ݱY}t 0 Q>ykW4U"ݒ60Mp"iX(~@!6qɐx4Is)֮\ ^,jm ~#{.S8X}Bͬ~DExV=a^HGof9̠9hQ_l0`皨):+;V2h){A՗xnbkH{i9|!FMoB"UK1 P)ͭZ"Y<vtQuM©dg'F:}WF옖ؼߪk#Tej-A{̢-y ȆP}SuF7FZ;e;Kʤ%ٽJo CGMo%}40u_㾗(nӊ;iWPp  C],s^)o Zn_+ʍDuL< 8!"V*W0uaĥ CmĿCĮ(YͭsW?6ҟցꮼz*Tx%^Z9]3Jҹ/!F%mb/BCQޕǗƂդQGJ_EdgGQ:,$XZ5X|>{5m AiRX$IX 7I(4*x s!_A>]L]t{8TsWO%ANes15с:FmF9oש>TBeɉApTF#^g] Bn[\0e`]Im· )n.q舩_vixFr^3O, |hR(<l ێfϚ0#ROUѓR'MEb꣔ d*u뭊 c,Miݝˆ'02^7P"Uc<=]~< 8_i yX/aܿI?qV9B;:g3CSKuŒW/ׯ<&O{,I.Va!S542lC#y!߰WMoP>! g_eW&JyRZE,$F .D׬S*%n!]M%=ZDNx" v:gQqUAy|p-۟t(q0F*H `Oy fȾg%h- &1oG͇jӼ+!^r} DyR5br{@oCjcYꝨj[e^5psEra&h%U|5O]OSv7s؊QeS Zm!!)J1EwT'CX^":(ր֮oj\t]T@gƽ͙IcU7¢C6|d$ߍěW*U58XAp :,N 1̋MJZ]0ϼGn`ˇp .R5qWX߸=1T& ˸̕ʕCfiBvm HVQF>_ |W\™NQ魝߹yl-W'cQ@H cMhd /kl(PJpijPtPnݦf#p( Ꟑ $J u GU7c|z4OH%B`1))*"' =%2Nʯ1 -TJMvf35 МFW#eqpo\Tכ5?7V}QCmKtW9=Mz=P[=zf!O41?|ZMm IM4&ǘEa+ rE'ƕX u~*S+wtN+!Sja A`d:up"Junvm?:*"zZdLE}8ѓЙ3ߒ /"#'b|l!AY|Vz?kSQh:ɰ6٪︦To߷D]4os`8 Rk浤|9e?7N|a.#nO =;j ?tqU$t@h>}DX g-{!&%ׂ筆 x@0G ?<DX/|ު&v˧v~bޙ1-?] ; cBϘgk?ʮbƗ,T[V [&?ր.h; @G/߃8 T+ܝpĊ0byTFy#Jŭ,Y.o Xk`;hLHJ͙!MT!}Fߞumphq6WS#\~Pȋ<[DXN@P "TP:,]Y.ۇne3!P2M| RM<6Vgf3>PU}z/SZxuL_+H^R}Ն !xtixzM=u$F %V'r+1ˡ  Mk8Ԣ<mwM>9|S NדL7|@EgCfGC}~aW0S3,Y% dP]AV0uE88%t}k Quog/t V;Wpmfk;0BQm@#6wW#D~V#ޟllph E/DM $eg Nɯߊh)3{ @k"-pA gÜyI;?d>'ύոi,TKOvItBqy~h޲z8d@vO; [ʛQwx~iz[d6i#| -,a Hߧ,i)V֐>SMߔEpwB(EeV'gN'Yl<^Vw|(TXJ0x"C6aKieCuMIh& 0cGE27ԇW;, 4ӌ4QXׇN2BgՓ`:mnE| iR6Q7x$^v Z ;J îV_"O/-|_ һ`#>P}nN\"㎲a:Щ$TDn=%^{JOr6)8 ־Q(%Tَ0~A9q]xBx!E^T[,(H+C޹KT^fd$&—n;C kd5 6l:hz8rq0Js41=v4mr`O2i.*#l}=LuH-%D9G>|է!4DRRE㾾+)37Tᘱ_x8JBt={bxnct1G4HyܤyV1ɦ#99F(T;=J6EUt}Y(.jiFi⤴oh읊4Þ$rRhbDo~)GYf >G\4qI*r^/)TzӲ\nYψl{ay%$g/S(3uP̅US"g`mH|f`iJ~t9hٚ) y@ byRݺD5mqc5u?%:J6<)MZt%[I_AαB*!hBJ"5^P"#RQMC?ua^v!Tj3 Wl=`ۙj>p:]/_299S0O$wa vꐅQcҕ; )|//xD;4/L +\ӿݪkD;+ <9@uSRxQ2Va0`I9$7WJFeRuϲW/;<ɝh}*:Cj` Qv_ZCSPnH+1D09t<7\^ö ^^)A'"g.{,+WQft_\Kl.Q\K9\d'&&'da)ɳ1 I(Tتez]*V\M-w?2< u@{H̄-ЉkA0<'Rf$zV@ U#IVGg!AH[[?*@iq(WXuaJoaM<-" mgBl2Gt,ǣP8w~;7q㤃Dig􏾋!~0NPiV,}ޱ֓%h7S6،"hٝs]قZ1eg |I\O,TZf^v.Sx%ZyrJCbNBc~}rL $k9JD .V"s(|}[^D Ajw+ӳU W:m]#ۋ3 s$4Un!:- Auvi歔sTh˸NWyۚL1bI%/5~,( i%V\*'4YBA)I"T{L8 Q@O<'cG"{DfKK;XkB L2ӭ)Gq򿈣~O$o-$QZmy`'7B\DbgLfRpSX$)%DB?RJ,4 !Pؒnk`Z3s]~rgqHUM nIx@%ʞ*̙ R_H`AQw A 8s%g0>0UH/5H~X|<& ,'l)E+z|i+ͫ*{8;o_^*E13gHZ8wAgY N:j##Y}y0x/r R7hqzdW͘'U2TE{Kqܜ-6a7_m>V  &jWe-'kbw#rn ?%S߮}ʚ lRCAmЁ渎 Ә1= I C3Eu;Ux֒R7 <<+O㸱]i& Sfd?"^5u>ᶆ.*<%FVYj8P0+ϼZAKbƖEˑwy˝b/7X֌Ge|ʪ g_A(LL@<{* 8V iv_X?:>)h$K }=tzۺ|ZRe- Y)p(r!+]:|^ObR%NZ0ORLPG]aQ8GT)Ha=.@7(ڲjtm#@92&U(QA:TgiL[jM數!;/?U()d#{T&Kk+Cݔֶٟ*!om#@(:OÔ`W\YBh %.tGl"DŽ;|h/)F@68jDUC\a>eJ羁KaW˵OMoǭ)>7 n@Fk."NO%>S¶>5e^hf_ɿ:."00'Yc s!Mttf/naK^b=i;z:cq `9}锷}!+9]c,]}t ۱sƝL V~ Pze1,aUIK|lrmjhꤍǾ0y0 K['t'ynF]eӐ^L'Cپ鍕͑#ZpTGq}a5i@1ttPQk]auې˜K1@_z@=,Yx& Erow514Q)Ѫ2|nuS\z(;aq+=zSDa %S]D>}@nY5miQ-LG&''+TPW6=}~_8& !*7*hȆI\gёݽj5+){Q@}>eE`4(cR8Ș)BrO_tx?ϼGtۀ8Aʢ|/ڡy[zdS5ULr  -bl0{@+6u塇~ɞAGbFU_IKǎ7S~ Tg0:7sإڳ"6_N!{zׅV˶g0eÉH#I5avӘ:نP48s❻[J1he#'j30a |Ar^[':~k RP߸˝M&_"FGY109jR| #bviYX8 ]=Mkz2و?"iWϏ-gjs]iZ&bx#-^/IM3[=F|X!@%ctPgNm9'꾤³Wd߂ؿI7):t2;*h_ȕX [>tT]6v8(eRi GJ (}Z1P% 0ʫU5gok/o䭇#ۡ_6 +Ǘp2qLvڡ N>Uhq k)c;'5TU/qdk[)G"G}bO+6ZdPTquq_oB /PBv{%+9XmUtVS9*Md7&._O+`9zM`3 Ssc?÷Txb8IMD !0hjf%R@Pu!kbbpAOCzU5K>圩w^.8;b~2"Xh9)Ju0ڇZ#psG_W͌(Ͽ%chZ 0_'şI3‚}>}G&zFۿmA_$&E#[ZoPr8`S׶v''+a2>P/d:E$NyT,g2@2#,̮Q hj}Jfu@۬7ܼn,"|>{EQsğǒ5~/tCT8E[_S= s/}ɰwOK.0e8W@ֺh^(I.pn#ZN9)4ã꜅RwE W,/s"]4E)V Hu:?~"e9z_d@Y:k6{=N  >qG9PhU:6Φ{Y;. u"]}Ѓ(Ϊ9!sF?LJЯyMv{Nt({=kUZyx5!+JXΞ3Y :sZ͒Q"@Wu|5O7 ,148S6܂#DYA |ea]?NCk^"'#Ÿ-,`~n()/ hUjhTjg/JcϺb`9 vp&!n'*NL{.P1MWKTAhHjVENWrAFȘϽlhʡ9*RDQa]1@5d~<Rt|i\n 0=L$&锍[V~yIcf"#3`\qj'7]y3J/JguGZr|l4ZBQ]LGA5EMJba3o`]w?ÚGm6d/"psU[Ў{n>Y; nD b3hP'#K{ A+Mdzkj!hqgϋ'p:6 ;?Ց }ȵN0ʝt34(La?EyMR0c#@#C]^?Tl)X=r@?D*h^R0hg嫯j#Z&`~~]Ӑղ'.g VmwIP%x~'m Aֽni'2SLF\3yZۡ%oJ) im!*}lhXR I6*t[Cy;.^>_;o 3|82.AWzA-jb|6)B2\@灾CEa7: a6r΍D.OfۗVH"%kP_FqfS/3l]VO `F| 2QbeH;\4(<h ]7V9kҬ!LZ^Vrq,U#ǽ SnL$.318[AρF&"_T|u^CC2et+ Sbe%f,v>=~=i& OuC'Qq a/~Dn=.j&vƂg~م D*v;U=+$ޝI됏AEslj`58;cm Zjo{Dtxm^keWmѝcodQ ;4sOUC; Wý/C jZ p|vRe&\sgi"̈́oTZN_:I+g@?;{Q"wY_5.O Rǯh!Y."cWBu_Ŕb9?,/*xn}ƆL9r:t0O񡑜?ǥe̾3^ڟ1H \j9D&k*[ Z5Qph4˽dn fV+ʿ N$cj~S/ni3㽒-x%~~_VfSّ=5bզ9MYC<ȋSU͇I 쵃H4uBtkg(e2egWEZ 8y v[IOT5.Zcd.a-c ].4v-}esX`IN;??gT;kyp6h_ǽxKED?6!#I4(o{nVج<3rOW}ĩʭIL#N*3+e}ak4ۇb2c{'XD0v vN-;]|U[T[hHڶxCw1\yB>Xkcf9_DnB洢Thv@{N8+[:TF`l$,3KZn|! K>={`)sQhQ.@|(\d#5>&(L1A NP |Re+N\14ՔX8E1׸q46^ X$hnb`;TP9%lrRc>r9D tVs5ӘJ N6 %GVml1Ҫ`)m4T RG} 5#M3KΐTI (siBEI m(iLa{1p.Fp Ԁ۱^X%u]TeTŴ_1g ew(q8EË (eT*}3r Z"&ֿKderzo"Lݙw|6`k&SsJ2's\iemG?/.sp_ތK'9`MbXZkc8!Ceya>2W ,A&]ƖPL-s. ǝ}h&(( %:b i(:_ny% =lӨCV IiOܞn~jܗۊW 1$KAEwAo0tݒ~p$F{50䋱QCbN jK,]-2t|aY,T>0 keAF0he?+}_A*=gqM\װJzHʷ"]攱, :6+' wLqyU^Mg8"HK#ncZha[T ' W\Nz\<9ؑ;{uK7g^OJA6nqP\_'9c78$o,cvtCL@,ƐO[H)D̬S'A Q -sQ +w`-ډ#Tx YDA 5~7/οR'dMUnYi.3tEq_,B兢-H;ll4:”𤋮/V PUYnS6?H򹝥9'1jHk"C\$%p]3Vynsuj0c*lG S I9uN;l"v>A,$ŽWrTaqX u 2ޚw%r>Pǫ=#*OhI;c +N3¡*`g1VJ:Q $VVu{'_k$?+M'z&['5JR֎= Bf/ZSɧ|ʱ'%ײ5nG{+$8\y00x&1|me}+ Tg1 %FI~F]ūI?hAE0֢+%[Ca,lUoJ~HF1O9&Y[^W&)NgC- 8-VG v7akWO#UE(ulw6LB`ٸVt܅7Oe֊^SC!PEl7H=LAY&q 䶩E_i'zrέbQ6Ojt3KIwtS"E `k6u.CPV־]ɯ g*8|rǛ`/hQ B|RR-R I9FmG<}VK\ٷ|=R )t&,La-2/ɮcS=)Lp)bΉ7"ַI4>"'r{Ne#j, ",G;Y+haUP{@!zct:BuiLFíM^AI ;(ܧ m4Z4r?/sx-.rS6K& F-X?`^v3rܑ0Wu= nm5,U:UhKw; 9-5@^(?9k3d]@0qUV}Gl6ٮ@ZCw'V׳@{c\NO !..k7?+c=>n-7aj @f j.ZQ3^,)Ẹ^<%O;"h~o*we T`KG9AlDg FGos5|6"+M)eZV cy&Рa@6QF.sOOX-Pӷܻ}""@t{aO،H|@aS O?Đލe_rLh:qIe7lid$b|xI=Q!9a6Q%V77ZwlLx394&gHOLXt聅uc$*< 2+A2.Ek! d(テ%P )2GѶ`nO_`U 4 3oND| a4;1B!M\̾v %5J.9 " Nm^lhw0B^4 俞|!Ѹ ȍeskmӹ_^`il?ixw* sk84cҔ M 4W[(@drofhjI&u(J(H:I($֪ڢѨKX!oj 6<-ֈq#=Br>XTc_Q"F2kNY]3%? 帱,@< Dd([C,rpkz<]}l(+E~(l$D0%'ɱT I7egLrr9_5gZpI&8D qEN Ѻ#Mğ`ц.4G< .0(1'Z5a =^3'8 rB aRƂuC>N߫''2n*S|fh㶅&S^<ƾ1l~XMρ` }6+!uFl%!D [*.вzoYI)Biv}3o7)mIr!z$qyu:kҜЅI?zf€Xl #]H[ͧӺB+{WHi)LjOPFu׀uzZyI^Mx@ga)geC_7;U  pv!Չk&۬]lFj56oV5\_|? <(UuɍE66 e039Ρim'3}YF(dTgAq1čPV<2/ !FdD$̲B/5IW4xD0ZԫǍJr:mB ,ch֥e4E _D mYM$kg/2vo_Ct o,FE}wgR >yY>sUsE15BfjeB[7C*\E%?/t&c${P[?-O}U'w;@>]Q"BAELYAt gPfv~Sj$+׬>Rw+hv6 &qA.r+_VggTŚwQnQ>\}?1(6 ne;{o=m[رq:U)NN}F+k⩿ȝJ |,h {{qJ]a0u;AJ%L .;8HS~r?ĈrhP7Q9ffXmE}caJ-e.#Ђ >@74ʴ\dC=k6^/fĂH, S`;^~?A 9ܴ: A^r!c `#:jknca7Ⓜ~tA.xI?`b+|^4U)*M/6aq4*JВ{iBQ<d2~,>2hY:Թ7x㣘Sb7C pdee F&<*B?* ;bB .*4-L-f1/s%DldU+ i:ڠ9C#Q Z7zͩƷR+Zt .'%~oi?!*pN+8-SQD® G\%8qO}'ګr0+qstG]dFfYk]GdFTOI8I8#e.`vq|+Hה N7l7qd,-{2@xd[(g%2٠Czm@N\E Q<-Udnjs/~AO5-]/:@5pҨBWŊr.`=2]bzuHΞ͸;|ļddRѕڋ=O+@9>UC߮$_ve//zx c8"D ڂȇ:~L*Rrk ]`$ Zg~4^TP;YѲ;L4fxՑ~LPE@PJ?ðRq̯ z,5䛘u\wj݄j B.|^`~E'Gu-"kC_j踵^Aw)AE\^꒑~[ʮv~,Қ]@~! RE,.K.› % &-pJ()׉t-ӌp֩"AleDE.U&v~e O|s3 /@m:LS -6j+IOy.8>mv@9؏Z8S򯔑 ޵Gq~_]3#aW׳ O/X[2 zw@anNsvRm>9]:YsБUT]DF ecpT[k) Thъ)paS}ls:a,mxc뼈<)0"8xc`^Sc g ț@LƤ<[TIl5 >lTvRݢjZ_owœ~-z<#KwBWY'ӸatHH_Ja&hZ !~'_j‚7I]Y"moPcȰQFp?Tr H:HB Ɖ\>>Qa[żT .6ӈYo#CP"{2bD vs"HP7A&EwLjߤ/H̹5Hܔh~Ig<ᛖ: JD*bzH)?VZ2A{mlvZ;.w‡ 8z ^F˱9A]J(ʅ#nt>PK:m]1s:<pbVQZ:g/YL<=+&Dq))pBm|;^5 J/xɔmDY]"j9"89L;{K*F#WυnвW"T17ew^2 a!Zl?rl`yAQj*\ jAyd|:av2lnYt'h%LBjo(B~*`w|dA2»[5nb}9'-[+͎#JSaI٣#87jKNUeҩ}yr)+V62X0.30J!ckn=a~lBfP·z_~,g<8Ū:P/`' "ݷhBN-P26E~ģSIߌ&j8g[~{/5Uyױt@%y)"0і!73 ̦ }+2Ү,0la ֨KOI9w IE4f5Mzr<.c8~цw\_ܝ}j]/HPqi2Jεŕ~I왁n*+1j-5hdh#f4cRcxF Hyz8V7; qt!~.+,~w /*ODӮ52Y[B_"Ԉ|;{~q&2m T*o`ٯ~aVv{#|i5Aﯥ+HgJ,g__exUIui1g3^v9qځze'Rj`S)= )`yh|l5*V U5 b YH"$fֲ҅Ƨ{/_3_(?N%|H3-"t —yQկ6 Ǧ0J \9ԉ@[rgE4ġfIsiF剻=chUXQ pBwdM(v8u&|G[,}?z#0=oAN=017Em66l_<s ksKa&TEu)%33Yv`^ҼuA]ĘhӰکOn;i> Ѯ(訉9jtlWŘ%3Gq'om[a[ΧsWS#+HS证Q)BrohY㾧ƘTy> lk؅d h]xR. FeO1c^am>>?{/B7(CTt/!旧(zyXi6R[h`;*W=f@WǗk7+G8ox[;d4T߭$}q^G7rkJ[vGҍ<#hs>n`jftK6ڏ"x\"@k)'xjLtM fo ȳJBV/] kN)9'54E[4}ܶ _4KV:lOQ ;[x )_uA 1"6O}l+Ebe]C~(gFc8A`n%?“y/; T_(]l<]J<6~n1AH}O-cN,J C_U!B!UiQm5jDesa@KпR UV~so,QHRi&3y8qV.n-.|vBϿI+ZGok4oxVsʓ4Ϝ bі%;ڂ)4,t"[gkC,sLPNpŋv4'"ffK!K68Χb9Nt[:Ce0po.b8E3CDvF"b |ei|v@`OPk(Uyd҂{S`ZS3bЧ9>x>r H9R"ڋ@Fd#x{zg$9gq( %y]t|tWa ;Tbӹ$q^K6MEI@ViPŃnm@vU Kt`)DcH)"ѪB A+͸#]ݲp ,|rr-I gސ>C2kڄrikn*ꤞء7~X}Bǖ2| ag"@CÓ|'sA Lut|l&4PBeBbܵObysYllPbԼicb}P9O.'1&Bkl ~2cqSN lFĉ%;4vn2=Χ?Xr\%+Ec dfix!md<)L XXJj " }*x/BX>d(zWՆu{_G7XOau XNt D\.4˪sc9*A %3jkQQ=Ǎs4 LF'LH3ɲAb@D!O)!.v'|6 hPQHO"5S=zZarHwl)Ŕ>A ›Ϥ!oRϡ~HZ]ǎV\jt=RN:,V ܽ|B ۨpvQ y*񆴔{˽- =a[G׿+z`kp7jfl_!OXChE̋ I*ߵ w-oec&JU#g^ W|\qX5_.UӡWOyz8:#e[^n=@$-nٚcߒH+nAo>cS2BRPr|hW-YhTq`X/9Q䋜j "^%@ nSu9EUbB*UBуR8fƳxIOjW?T2s6­ʗgO>SfG ӜaO(u ^_' 6m ~6^~0sRu852r(&Qì>Uv6f7hԉ q #}yML9UlG`ū-*a8h&Nj(7˟7?K~e.}X YOFͿ1l(fsb@Ln9;AqvÀtN^wBnM `E $yIJ/Fq&lH-MPZdaqE4kniǼw%kB堬=eJgP= |* ]&LxIxGxzMS@M_7Ƌ{bfhcbX*ZG3D96\LҷkcGP_s(VzUuE#$A m7YݓwүĎ&D6wH0[~0ÄOb7hybiC1>3iyd82dʤ^Hs H2U #s P٪% kVxN5ȶԍET)clXqiJCm=ۗ'݁p/Z=s`go;vf+o6bJq|X1o ?vcCy8}2c(˘5K9c1]ځUy9ƌ#GC~RQdF[븧i|;N ">"FBZ1k*ʀgteЇ N͋V>'vA[_w9]VInC\+سVn/7͎,&-Rg dRa޲F؟ی6b I tX7#:(Wϡ àY/!X OJ.T9Es]XZ寂Z^>Wtp 3(W|@|H@nگ6nKڇ.m,j2mSyΙGaщJ ]޵.^q䇎A?I|`gLO|2wX/E9K,M|R}/~pk3x<^S5$~Yъ18 k)73ᕈoo WaWҿ~MvƺtyjJY HJRz5{^G/ciMec J'MސnDw,BK= on{Atg  0hc1]P5zT#Mq߲Hi2$k@;7b勓#\ Ƿj@+#˞D6c{ [{4( TY"ǿCNy .n? zSUIWrXc<Jc(X]r)3Nʵ;ѓ0=v&tf+'AZwR<<+f8c&]Y@40XFn`Ms Ab DC?)΂ <ӐگYH\ 59_]-sτ!3[-tlIj_'?ebyR&1/=q7"%CkG)fni2:[s>RSOCC} cBm\tecUYTSl0D_Ҭdkd ߗu8# Z2Ɖzt5=O ˰C*{!{,[-H TSp7N.X*3A]6VgGCcbV}p}yS:⸓)8$gGu&*o&F1ɼרW[-AvYT`@moDI(=:RS N *wyz)4# OAO(9[gG({V#a^1@^ȧ x6IaTҿ=19 @+1ܖx|x/1F`s'1gZg엒,PɁj cގ A/ Iӥzt "(&ߚНyx+ߕw53CY}#ڊ^O$xq V8/K姖i'}.F7QFH* [5ܶ:׾0q(r-avWG ؚa)~f)Kz4@ ~U"lh;ŧ}+!%y뮣L3s5}KTCnJx@Z+ 8ږTX]uU}=)avrX]tqw6%|p#d5 qSi2ŘgS>)!Iwb׍"&G^D{9L9gDD`kDB9i}Q2MD)Q&O71)pLj4A8z:li܅/>oNyar`{(|#vJi\0d$•Wt.5xfjdBBaaĠK}~A>N :cLQoVCp 2r$ؾJT>UHfWc}Þ,3 @KOFimЗz.RVAQn ?K@j/qH_ܣ #ޣ݊jYU:]} .+9x0cW!t8?d(?}zp: vM |npg\ Vm3''_ "Ùp;.TJn/mJ`hv I ;/ABZ2uUm h1Wjv{ǵ7-l8pF8##++vc*hMBs4, f0?j$A^p]OWaZwƯ8s0iїaKRt~{zrx1 1-o&E|mgR\tX!Rz }GF B?{hOAzI -CJD ("m騱KjÃ,L6zv~g!3 e;uuvo]]W."KQR``ˆFCU$ - 9jzqz8t Y?hFx'dڱO\f ϥH_o߱bl͊= HYygYF__؇,GΏԅ[@ /cОy6]he=K-t=?QXa[R )-& 'Y2ov?u8f6bIw0glg> )s~nڡ:l96 C!;LIs8@q|SA fȎɔMܗu._;Q@d)k:O?j>u wЩ`>Y)1-ei&s)U\H3B䴻eD/o:lu߫; m\;Wr.i1s3b bz50M[2`*<)u+z4W=)w2̑ lO᠘؅qw_ʎj,&k0z4K{%a0VmD:^FCtЯlV$wJ "M,?{.s>5z^d\R:Tݮ(Yq|>V+')oIdrhHה(^ w :@yMY z?:+tVasn2s.N +Ix h'Hp?rǣ@'I4`^/o'ͭ]Xɷ\_GFfQ`.qɛ.z9f|b\myԍQ ?]:w}pI;yX^y ċQ:w<v_ZY~tu_L4rJUcn]";oCcSVQiܟ`L;&v.MVedrnW567^c':Gn;e6}m+s11eā)I\_<*R-a0y̎hijǬq>x͐0[=h~|G(_RtBw,t"CG rTj<Ims`P1eXxu66 g7!60SCXXI<)ocٖLBCY:dCg~41^YsT_Jc!ϜU&;uY:K%Z{eXSW~Yg/(0"u٫kv߷_y. oGeH%?%L LaݦBGW04J(E\/ӥvKI,aPB9Y. IRe.P5Wy˺Z3$tPU0bҤq0x)Y5O5x޾a2%B ߤbzTuRZ "jy7%P=g=9Az@RW ƙ Wyk"bo[Ju ў~@':K-9(3z8y+QXYnY\m1VS=u\zz/tqĈu^ӛ)*K=FܴXU06SD$žwh΍!iY&z`}4wd/l%@"f3 9n:*n1j=ڙZ؛H?A&`۬ƫjYtVbf˷Nx)g}ԩi @?D}xOPm~EL-J-vaC,t*dv 0 &`<ꤒAwW SSںmfҴ$YLFfǧ )I?0<7} ="s$=xX@=jd/M5SR 1zv޿]V̔iW+(5(J?%WG!JRś!a+:T7IRZ jrYe&e|P 2<B$P=s CE\m$ s? 4@J[|Co3 !ñ?Pf*g"^U,pF>j !nLuՠ$#"`sTV>ʁ]9Qt=w*_X34@&M7>Ֆ|C-gB Ɲ 92r9,(Q~aֆ2P(tcU\fk@qiBO{ǿWSUqg/Ib5seK ty{r; C+yb%Y1.X0rlj^ToS}llec Ce`] pc)5Av,e:? #Am V V& +3tCJ1Gvj@+ӡ &F@MU1 t-Hkj*zR֬d]DV=ه6\j XE$EIῢ> Y?Ow, 3l 2 oK%-CgiUž=cCyʦPFY$̛{ ECz ^RʿB764/=-ցWެkX0_}W<ѢOx/&U{q^iď%h'd q^)Dڌ+6(%_K@eFpĈsl9oɾ׏ƨ\Y7Qs~W+ðպ&_ 9~w\_9kšfƻlpoBxI{I {NƲox5^!_`xM k"A+Tj;/!uA{lEׇ<-vtAD58D7D"L ~5cF}W7%썓; mGn|쯍;4Y][/`ԁH WFB3Ɩ'CfqQ mQ76@r0?(+$9"b/pBkiEj*)`r\6Sq\mknr}jN ԭShˋYN\âCZJʋ=_Xg]}}f;g ;pDүܤ巺rLz~W,Cwd#5!:g;X{ѣ9z"(5X#.&㢡8Z ܮo&gy> !`-2S7CÔlѐJ* -{ Ta,u}StpwHZ4g_@l| 'x1.;FYKst ?UfN^ =nQp   M5u*6-XOw$J0)^O <ڨ_JA|ļ>@葋?SǭH^ I [H&m&Nh5XvcBlE: ʹ|l߃e?Ǚ_կ*Y _JDh8X'ֱ ~(ܓ@lXUЋ |Sa{Voc?J&[CNFy1.w!  ϬbOfD!+^B.y;K" ?Z!6Q%cqu\}M0BCK0h!6gs5+.=01oߐy ,'&&Ʃ"8>apCPw7ipj+z%H^1(k; AxjJ93I1BّNZ3A-ځSb'iuxޑ; mq>c- %Nk3h[)b;G$LBnǞaaD6S[Xby,t P.eryNgT'UvҨ"3C:/.2j*WŏĿ$`su||G%u_aoԃWdZpG|1a1ˍ3Mfr/|JY !":n]Ggl'x+˰%+K"h%jwT4zDZ _92f8}.qC$~q-T2hx̪ ;Wҁ`ˑHJ\scǰ١~r7 )>Cya$zcidp,q^..N>dQzd14F8վ50Uys:,"8}vmE䖓}7#?6ۯ$EN@ )DYk׵KđHbD#̓Tw2ilvw-^بjFFryg^Xz&ɽUI7⦈4|fQ"e"}T&i> 7OvEb 1x8/1;DZ7D,Դ{D 7|/2]ǓXܲiXlx !4HH{dg@d|H%g<5BV-o\i:X v|_z՜^=_3OĴ[;|a~#81ESȅnL_n򣠮뒎f AxFgC9x\k"LC]z mvD$2YGg;JJPQ&^2؈j7<)IQ)dntD F_>wB'oBaF}teg~R]2ܖ" < Edxy7D7Vl `{GTxZ"n=d{yvF5+ix |m{x:}pxqg?r ;էֈJ UBEU7NeEU|ZI%{E 7?No' ph12~{R\)ăGQO2/I>5g?R&qG}A_"q 3@Ds^k_kN+s.[{rTh/'SqXԢX(m7=Qۋxڒ?JX]cv%`<˷S5ױ>jbtuj czuGO?X;pܫ/(`lȔm$Sneqsw*4B6-7"Vٕ&zh1WHdnDoo kL ZJKl? UAm'6Ft`ouc"=txBib= LHװ !ٰ5@jS" 0u<.jb IS$Fa"-(BR'̃H49{-rA<YfS\K7 {L}}`46o զwttx7HlO<&˕8ȐԹ[fq`Һ-l$֫iݾT#HZugϨ4},E|ߤ*,< 05h(ކC?Do2qP;N eOsDLeNj//dML+"jyt:ۛ ͂2*Ɗ)%ozqt:I͡Py欛U r8t"[v&_ј׳MẗvZ9l+}L]y-]]+Zon\!usdؙ2+aCr+ w1QAm?]!WߟTA 礈}4Ҳb~Cf6vq@e-꾵g  g'0&޽6L>>~jpU΢Uzjjizg4B\YDH:'JZA>7$\ /-#.2w sDJ72PhŲi"ꚈWb ܴV[%(ݩρUYLOLg@ <ԞixzQp:l +yKBkZB#3יHe^'\&VDf@ zwM`/|=v{1$7>r2X ;7i[7T]| =|y- d6f Ma22XvЙ/X%idBŒ5$ x6q 'Q%K}i( Q\wk%5yLrj3H/LV-lND$olڮ) yU:HgӒA[ ஍Ԋ߱$7Ti 6Q"cdP"c\"C]pwV{7t[`DZ$0'B &7{7cp-ؕ]r"{ R< ^ SZl It]^rMgc3-3Qm1)nԗ 2v=.#1Qف}C/Bn_M)*1$6IU{Z+A涼(>zz*IQˆ05){ wYؘB20 8Gm)E ^WEJW|#!<+Mh純Qw^wKi~'4f~T ;I3=tbtQ/Y;$|Y0&ksUn:NWd([40bZh VRP/D2L='b* F/1§ cY|Gv>xaϜ%JTq;md`I<{_! j)3&VgFGQWȌXbfe\.%P n38+dg*mo&<բ~ҿ($2|MX)hU/<:ǝ9(~Vv4-xG`nה; p5%Rk=z [,3 p YZ