sssd-ipa-1.14.0-43.el7_3.18$> |3v ~`/>=?d   ; "@FM    4 { $XLL 3L   ( 89:g =9GDH`I|XY\]^0bdefltuvw$x@y\RCsssd-ipa1.14.043.el7_3.18The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.YTEpc1bm.rdu2.centos.org 'CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKOjA큤AYTE_YTE_YTEoW~YTEMYTELYTEOb81dff727b2c5f2e041d79953f1631a428ba87ab85847b3bdc991af78e8f669694d30cbaba62288876ee7e92f0ba8b5e69aaebca8c190f9060a3670d91a193ba8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90371ce67dead6a25db630c6b71465c06b2ed9bdfad044db73aaabefec0bdd0cd740a17ad4e3be94abb12e67598d0e01f60f4419f9887368b81d29b7d0fb4f3b8d1rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.18.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.183.0.4-14.6.0-14.0-11.14.0-43.el7_3.181.14.0-43.el7_3.181.14.0-43.el7_3.185.2-1sssd1.10.0-8.beta24.11.3Y(YYtYXBXpXv@XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.18Jakub Hrozek - 1.14.0-43.17Jakub Hrozek - 1.14.0-43.16Jakub Hrozek - 1.14.0-43.15Jakub Hrozek - 1.14.0-43.14Jakub Hrozek - 1.14.0-43.13Jakub Hrozek - 1.14.0-43.12Jakub Hrozek - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1456013 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1450125 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1446085 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1445821 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1422183 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user.- Resolves: rhbz#1418943 - If a long-running task (e.g. enumeration) blocks the sssd_be process, sssd_be can deadlock - Also Require a new-enough version of selinux-policy so that setpgid() by sssd is allowed- Resolves: rhbz#1405584 - SSH: default_domain_suffix is not being used for users' authorized keys- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.181.14.0-43.el7_3.18libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=21eef38c65d50e5eb1c3f51f72c108a65d626955, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6>]"k%w+p}|,p35muذHZc֧Ĉ`VHaaWX"g"$A :~?YN$`pƌ,) i8Obd}ȔWd.ԐC`*hsy"P-x A5QEƝaZ+Eay)$n \9s& \6HU R;g ow ֟WV$mOvt^sL#aO!qc Z}֣?e,d|OwO1ro -ן=$w Kyh S3¯sܻfk4 Y[<#UM*x̥Slj4,]T6dH4br//`}Aеu"Vfiuth| 2.A:ì|5#9׹Eؔ Dt$FYp 9^E󆷼%%4kVe)'bQn OK9!졖נ:kؕP7F֖o#G>!cDX9FYbҭDѮeVato 7VPbg8324*[?-wzfRFEF+WLh{("ю>Q"2ȐpE=cBqE9$ֹ] Gly+#Cbv~Skzԯ2N&V|Izl]k^0%C߭\h&ҕ9̹ &ڼ(@b9K S1;tBc,oy7J&NWiK=\NuFENe+bYr .Lװta6*mD$lmʮum6tz]Bt#?h%4 &x"J%5>ȉT>~ń$Mp"Hf]T=[4y֖C9}\p92v} ;)quH@LdV),I>FPA*,t]qV=':52?ƯgLuLZ1͒ءg=bw9YǤuo@(Clxw<,X>AP;i j!؅8jLG( jmT,?L"ph/o;"۾ruj* k{kߏ~`vɎl{#=?FaC5=G,f4LݍjPck pr{S y\=}q",捠PbtaL)x3H`lʉjHY©Rvjg-ñJ%HOlKkݷuHi>BׄgL)#Ȯaݍ}:>uj1Yqv|j! eJEA5 BG00u$neMZPl;Hɪ/벡Px|518ƣ@沛r,gxi1.ʘ6OM)MY3u`vЮ݂rG-GÒm^E4NʋyYq=/Q^h5u$P4yuhe1 o 4U=~FѠn }*xP%C@#חuWsxݵ/.6~pO?hż{t~ p0)c|%^84g^4wgd /:i+bo9})`b*ߥy+*dmcLf: Yf!aF}޺ü88e;Qka9t75DLBrj?^YE"id#w"|c;y_50A:.p6\>z=fG -6PeD^b3+=4bs;&SlP{dOJc7s8TL&@`wǠ v.NظX->1|+z\ ѝc{ųC*RtnGFk)i(z_ݽƗފ+Mh| @"R'p *]Fl;SZ9a:N~LEnY4 =~ףh{lża5|@àIkxfD> X-Pݫ!]A=՟ ]=1ϭx=,݄\fmG8ɺdG8EvK.T7kژC~!P,z$Be݉%X>p~;;,@O5/'c%6?-ZZ)rSlRzSKX)0QuX9P1d+!pDh7"0 x/}& l+d?K SCBW;)jz왁\y&;_] 8! cEcҫM?(b4UolC9lA$.]sC=m=ci_`ؓoI>P 3[)c `'7<;~!y9]ϿWI΁Dqh+hgw?k26!q N^+QȎk6'}qZz֕nϱj)/}CK6ya\+jCT'N!dYHyn$5Jڏ;2`3HF%hOUlȐ:\g,4{R<^Q+{ e7"8^kݭr# rF"}H PvZJUV8Am8Z9uZpy<L?Dț9| /ň J.y8˓ry zt {Z%Lu/-f2cZOctpZ/<TG/G qk33CNP3̼4⻈ޕ5LSC!]f;$R{|МRă&/"\uez6p4ӽ,Tܲm/=RW*~ 5ncY`s/{/4 F`GE\o Epgg-/_m=~OmG%;yDߞһ._ME^ B뙖h‘{o%f ;ȩi[q$jmhpAu N;t_`hyf Ly8R1|bc(5JBzƐE{vh/(x9o@t;bܴ{ WJvH`E_&\ζy̚WNN%:d_-q=7X|q%PtC|ڧA=h[rߓkc{%}l}O\EYVy-dʅWDTOԛ0s'#wRܺv.#Ud)) u A%hT;G{'WbUL+`/מaD˘]S.HFפ-~'(Otz©q/ PA~rO|cNzzLy=Cl ›S8.rq ?3:r=3?^T\rFAP3%> 6UαxC_JNc^W}eK`:tlvl/@r`>b 4:NV,vit:v "3jv>`zf4Z2춪4<"P)nސ 6CFpL݆j >a-6]aA,^=efN&N-%n^m\cQie/kBpR*d,;-sh%'ΩMkW2260)ɬcr8"OwH+zZJ955_d?TUܬݺ%R5ЕGxȭL=Vg/fqIZ3yCX< ykE^λ +ͣkwPne\EXG T}MI9.Gƃ4ܥdBVpimA6?ES(\s!Dr_o4WG΃2 eu?"ypmw sb>@U=V>>#hkss{/  b8/Th}M_g`86XZ^__?s v dC߇ܜ) UKT4rGoay_w:̛@adbZwQyw`kq,;pr,5x j!RWhf"R 9M3:ѻ?`Ri+wn #oJ-p쥅!8)Qz+Ĭ;OfhkСDuʾԪOOK9/]),k)TS<0b^mM+sU#+s㯆K"cS׮t+k#=<rq8ߓjġޞlZk;+8B,NDiOɻ/'x;zTЪr OHuIRY߾ӐS ͇ "-WlDyqgVrMjƈQ(bU9e̶.23Mz Ε5^e#Jxj6ֲOyw[b4> ]DCd.'7BP_ҁ!T- ]-k~f#n@ta&֗,Bn_67m}9FS(l}*2g'uMBCyr(őԳN}E's֘:AY=V8X*ɜW6e]{Me" ׇZ-T8$=%I ?pRߋf+ԃ mVq$9͛KLTb` St,ql!3N3B@TyCI:P*Ӡt BpR|õ}dVqUcy~CR8ب+ kY3%6/ rIǡdda/zAԍɡ ONDkpVyJsY3ל CC, `{ n]]7vy-G;R|*S3L9țp zIw1&^N#8"`%SܞM=~[,T@M׍dKEZ_)*}KXD)6U%/31d8&b_OoΟ ut5rY&Oz԰Jw#hfOh &5ESavv=~%I?P(u Z2Яth I>f %|,D#FRPUWp,cwyTPN =N~cc-Abm!A gVT Ņs xM۫ r`h3T Qnl5pHItfD t \)2] yyolqz)B(_BƑAL/1uaSr)ߢ 8$X1Ci@U~C+ @{&fX .a4^~i!q>^,54=\Eps.wפESX h ( Mq]eir~![n{7FqH>I` gDQ#2|JR"JFDg}@RקKӎhx]c{m C!aT%"0^?Vnm^z]TU#^#d $͐O|34SJ 183YD 4TSz$^cMM%F-`9 gOJ Xm?g\hVsCG{ [E.҃oh~ҷDG J,3tSSa3 ܜ8ٹE}]512Ū:u2` =X>{/ݯ*Z`Ҩb=]l b\|YA_Fy#Cv~đ Z5$#~CfK!'%75V}u*Mu>.bzV3ЕĤl*Jf#a]aabˋ_[y LUJece}vdg+ =s{`oe2]T51%IЦvwI-(MeH~^"l^J~.@ ڛ)g do ;IQhIv6T+IFn)\zP*Uo+?5T7.}@x;&]1 g[\KH4kR^ n Of㗁VJc%HyCL`^ۯ: '[{8R|G;fu'dַY.!AByC3߳丁di3(* X" (tA 1ah y>|w[z3)/"2n2&m؃fkO5UJ(q'3O2 U%?eb4D;IQ8\&%J+ki@+}s-`iLD:J1ڸ/´}+̄7m")o:,zLMs9ibvd)"@a):xc.1ZTf&MsOR.` N6>&Z4FYd w,"a" Η~`IJNA޳nJcU?KrˣX\+_ ֒z:=MV uE4ڎh< _ ܠB' _Ż#õfQc᎓aV"IP{xvrhr>@?s$quýO+/`ʳiO瀃 2F w^;8lwcv-[ū~(勌nXI$^(퐠[/%.r,8N[n#&ʪ5he,:d28''D{V}kHFJ(㔇Y%9&pZK<a)xHդ/FP ?^Vb@D4dςħ+}n9;PiH`ڌi:=N)CׄHAh#B~Z׋\mޑ\Iy#6!|0-*Vs7O4Aj6KWJ\m۶̘kzQIk>|ö l?}gn-L(/mH[Ŭ`m0HXZ8kΞmm`,5Ԩj_=H.;CB͵m 9|})=DUֽ#Ԋ/SmlZ`Ḿ$% Շ戺A[-*ڍw9$}=ڻQ2a]xqQﯽՌ ~r}&"zX1u2iRJlЀV@):v_ (8Qq5kjE)u#Sq%;s-Afi(f%i rǵ :dJZp6 \~`7(`yw>wlRus3sR!$;1ZސźL 1#|jʎi j":JxhA.%xJ۬xen@> .o8"{#mIM4s s(HdzC kN \@Z]q2=p!:Ck7ص_~Sv20/t5ga(^Lx̹~>L^~ќTM]Z+,72Xz A$zVwַ5{J3bRܨ[Y 2ہMw;edsoQc>Tc&N!0:aۻjwn'p=$ ,bAʺDb#/: 2B/riu0 K }%j7ýDz~,;O;jܲIme:~}ʈ#{x[tB1]ykYt$x]c6 eGc*x /8ܵ}y./PPh\cĔ(AۉSW1&TYTށ[7 * lӾΣCхxn fYz>훝" gn%%,b{RxYĥ+| wVy]P3I˕kif!LI1Y{=#ARw 'Ԣti*:^ը;xaŅ5'?؁!lb#а;6 ߓB,h~4:xپ|Wk6=@!;a]*pY<_3 >TG,/B@rg~y nbU qN( !k8fZͰiWGUzO_7Z2 a^=ºXzxA6p0r?.ڭmȟ*{G/6BTH4e/@DAU߫N}DiQhm}Z4ʏqdB`0- \r}], ħpr{?,CkvD'B#ELz&ַ#rJϰ$AU{Nj`ߣPzRcO΋ƙv\@TGx~XbCӖWhxMW5X K@ ¢Iyxȁb9c]hBb[q:Wmc׶<&WD@UBv3#&c~l+;p`.g<}]}.D) j> 8:O_&͘އdiA,YDƅjeOH90i#wV7{:p饫1p8@2 c- AYN7略:L-GfJoo@OnR8WBv7z >vu=rs4`uB-V4Q$Sf_HNgjXђngꍭۛ ߃ XD-]%?c㎮f/!4_˘2-SZC5!'l\q$:ԫ^6Q -T@&: >6`P(VdN?>jPRy!E/(LnuDh^;2uŞwOxP.|oWu=l>lay*KM^R0ϟژ~w+j`ڃM i!ANֽAD61)m-f au~ em`luSAج6'_Tj|V?_^53-N^"`oΎ\^]T?ocY.s+E/"5BNT۷5N1ĝ'Fel'O ~µ<3դtb1SzMw<~Qt|qR64ftd$;%P;;*+ : ^[4\ O-UHb.Q)ۤ谽Y/+8wUusJWҦCK;ɉ) y\1NA=<] &/_MV&s7J4;ey#;I&'W_5,8F}TwE(nA_fEP58 u|+{4OٹM|7^yE>iз$=Io| X sRAsoSX*e%+|2#& HV>1Kʧg>'gkPRC6?(tB='sM$6 ̔ɽby}ʗ8d{AbLƅqeY jΞAԈXN^OP 77sVYRٞ64x=4Ԕ3BH%2^(\o;)4YqXB Qy-xƸm w7J)z!(qT˴#ܛ*}{.mB-RRXɜBj1*ML x /.!)?*yF[j""ӝG}a ^cЉ߄[ӲQ$FI6>c l\p|;bB?3wE?dbraFݤK顏4NN'觊h nVʅ>Y,΅al8z-YW ' u4QEE+ 2cO/=дM^Z\*C!⥌MA②je_ڭsY B'E̓L F;*=_Ѳ83'FB!H1VDK/1xy/R5d$`PI0"~=Q)ʢ e8m}`dii[JJFv'ENDw ~ꍠfsUN>":aQJJ#7ns)a;/ puf 9˧#hS3^)g(b3q$)0nթت{tʣÃ, kw2daZק1᛹'ݭU_[lteO >$ZUuj qșۚ%QN0'Ve?܊/5Idf*3w귖RB;K?ReWԐ H>ş#QH!:>:j[C{ ,J{ΪuWrPWyL4 Z94H^%R']7\{g/Gdzƌ ; gzȜ!fC/90KF=K=H4[$,xhc[j) LדDBDx3; ?$F\gWߋ*WL9[]5CThP$:hȬ1%8y{m.` 3NUW[C@ǣ1S)s;g;w9uql0FQCL3>.}|^"ofGWŢC_ D.XgMCPRpV%e\ZI0N)30;PD^ +[h+ߓQ֯˷h }gOV1!?Fe/EvB:6ty,,je A13x(EOw ׏4N<"?x݊/C|P7.+je0Z鱮H$r?}L1򐪈"1 p=f柫80/!i7;qz-\rН! ]]n1ªMzkF)Q p`D ^_hڞ,9e 9{-~9SCOGݰ$=W|B6+9Ydɘ%I6iurȦ]UcHhTNl+"=A"Ğ为 ķ4\9?V8Czwmi^ w;L]d"p 6^{Oml_7,VI^i p초_,繐+sQG"\l{qk9Wr)D<|?N#\1Nazw}{s+,:"-tV)aZ7w cҎVk> ?jXu?0ž,faHg[j'm˭Ѷb-;`M$Dg_o'԰e< 7xtwz f{d؝)]G%CUj]ZIx$C{KGqE{ޭ]d5Lbm J,/t3;ihkEp W NIM@$$7O|r"̹;:[Z pƶ(oѬ, #"p;=w+|T!kh =5U2 0t` (Y|D`XKYds03{d&$t_wEyl [qFί,S!>ێ<j5,m}&{ucxBw¿!$$=`&o#)_Y,)i%wpQKc@i8#͜ sLԀa QVՓS4:u6B4h1঑| T{w&[8^gIXI$6l6~Ry0렰]W.^ ٝqiU}ۯ{uVEPa9C )Cdr LΆYOa !8bX).FL%(VaP!PIW4 F\4&D4V%\^a{9azmtpǴ6E[ d+ĔskpKXLQc;υЇ f]nkpdZEdCr7sJ64e >{frkN^4`QuR*_:P/:5fz65f4Rh_a뜙d9a!0]ds7D#M j )/R(nqr6;ޛV4 f5qb GI[=_Y}i*~Ϸ/BҍIV@o<J=WN}BFE,:h!Ku\~szjyY^q C?HXI0O9PYZ:ALGuy.'Bi6b%]FU>h Vx>:J({~|y%Qcl .F$icJvᜤqm돾H5p;Y~*Ⳝ$DsiQ5΄?$CuT&ephzFӝzP~ Dh@p`u?00Ⲍ-t3lA8:e6i4q78$D@{Q7"0Syn?Z7 xkPc~njTIG6.*Du"Q"2(N@`w+On7򌡥,"]+8cUwl񽄢^ d^P ^_X@쪺.>%y: On_qz ᖖujUEm:~ a+ajrKfAZ͈e,pl:"ݖ:&gOC^SnA+ƫ^8AX < DBfE $Iv*F>4g_"8vwe>,;Dl$܊;nؑsź)_dx$|u؀e п|xV#2%WtwgU K,ݘA+V 4aFVhAt7((ZH킕YJ $"NYZ\=KA,3^_,+ A)t9ZYg"T6Q3N!lob jZomb?(sHxp7Y2F@VQeq6vE`M=aQ.@U_lq#"O[`v½9^=WAO}M_-*K!ge?m{!h~3vEY` Y8W}u,LWݟZskkMg6tLԧc`UV[XxgC}`X4p+:bfs R;chHcy rBa8F@=1F<\\'6?wWh9*١êM?Opkah')5Qh\otEUFJi]Tv UXvG<^6M33܄* D[-t\95/ѲNC˭S^\2Io[^K2=>d$<l\S?@PlXbD_WhnGeFO" ٺjF͛5a1g +k?:t%-/[ ~"s̮s&ʑJ|cΫ iiE,= [{RT#A Ԥz#wjٷ$kT t4O5~5 /ߍ/C'cq,3|13Nw 1 !->kGL[c;+>H)ҟʄ|/9\3a` e^y <>>AgYF) kf08@H؂Bxn%}+❻2dy` -u5ƹHO)n -gf0v&N폒X#/{h_h(䂌 8GиTݴ]GvF7a˂A Ka 6kQ^ҎR bܤE:,~tw*oqUw@qۀ{œaBRIJ'Hיh FES)x%5oMnbrgpwr .bh?6yzJH*}T.M.l7b b=ky_]tvB,~B=p|4xJu=L ׆ #e1OgL)Ǯf͕ sB;Il(,eYbç4C0l|wYK vKt8ȫx/_9"!OR?3b/U^2REJ3=/SV m% qKx&_ 9` Z v*-CB7Gs?%HKC4\qBQPQ\+ J+%$DvWjtY9:joN^HH*%xSͦPs*h & /f=wX,0ߩͦcvA?svv%Z:aƒ˨fͶlPz;FIB\.fgv6!l̐e蔶$Gj ^eae uɨh2{ m?#C&  }OM2㈸Šaݐpg0yG 7*Ŏ2h(lkSA:oT9.y"&O_~کǪy6_?ql845 ZT gm Yx.n6 V\V0tW,JxEr[Βct~SHrm %ɝa9r K:(9(ڋ}LM:MPWlNka(0# u|КSؚ( ovG/WB"zD+(5 J?Hq,#Un;;&jEI  cF+$~@\) Xw@!FO :ZbU,5grQ\ *%{dH5rjAwN"٠MO^G?h$2j@ t)Aʦn|$&.cS=-"\ڌԏ?Iºu`ޭha۫ZrxHO[MYB˝ <ɾR8`C P4mHa#/YNx7I,Q`Bn\._[D_wO߀P3mSt6)x"!u}Elxj9Ÿ0*/R _Loa ">+@ twQd_qua5U/ p*\%$+5ws&SoX0ͥ3Y2~ \=hJ >4ώo,U=yƧl߼<Ӗ[0NC&ع얚i@B WKى9[\ʼn" m,Zd'&J-Bk稖%M_+$go7 FXcBa3Sf*K0K;r mM^ptX4Xlo(ǞaY4I1$¨vm $Vd#t\9%q1$+T'V0Xg3QWWtb LD|4~\OC hav4WŚ0/CwYΫ_#0T,J뮞D`]$xkƎ  kWPԶ}q_D&3W{nbkSo>+%ldUۂOj-؎oirM!o9,|2l&pܕ`%G90Puf )9k% ݲ<"KtK@NS==iǏƜEF̓@埾!suNHJ@Hâ 9XqEYú1ʟ Nk@Ƌ?{ilݍMGDxdvU{L_Vsc#i[rm4gGઊ"ՀܤHY{sc($s$%DE0'AɖEHWѻQ1UL5A*AX!r\fc2e9gi\%q9.U-7(\0$i:N|\!DV`yn8#6?Aj#{ҫ$9P]eH6XD6 ub Xq/Wtz}3T::| nlH)C')_R']3IߨK`a,5H/{ύ>pnJ!{EA,b bn_ ^!'T 6BUT }B6M.@ 8썿j^mǹW@cFKM-B$z" qejRLV:R87]=}RvgI,(s[UwJe.;^ݛt}mdmijk.9̗fیD>uEz,wZ)/74"P솣fBrڡ%ED::/J6zGE Y#vެfWg8. =$j,fw7]T%vQ%/&Hl&(NN{pP{MC /dq9Ɲ~oĒ $\W3$e3וxIF<'a4;j¢?W.n :A\^3+b?69D!eSCD7IT: [7=9N|V;ZZXNDA FFor9*,*qP,^7d PLsl7;'&ug,5:xoʃ`H96z]80%Tڪ*jta2|XE JBe<jդLvڪNŶFe(N \%gjRALh]}U$2 Q8[Iw)v'(*6F' {R4:ZP]tWҧ y$6WL\l|ޗlb(`+p)֙o +J \h/c̆r0M}s~+[iiErOur;g)ځp=D7$Dd#]̦:WNA[( e-YB}dҧV=(apl)L(c__pvZsng٦GX4`T|T d \S Vo;[/nk,Aآ$JUl@9QN}{Ѫ DJZWZaS¬K}zrF&SJE;U9QX6&cO ) .蹨cj"( w 8PYx䈒D Q[3'uVlTM>`*|+duե܍UH#{'D>r6wYEgP3%O}K J[ŹhTWkGZx)v1+\^.RO͸fme0AGh `O]خFͽFzi$HdݳFE/>RJp~JYpD)?"8\ e1tx NvQTM (66RRե}`Di;M7ZA,oqjp6-9OGs J1.9I^._ qtʰ*Q*f @ØBg>C>& Sqk9hm:#H,!F*D%8up8%6כj|4K_Ok'DѵIwZhMGS%?|~_~H(\Oj QǮR2ujGQbh.^9)Z$RjBahN9NȃVB~ g>5; #^Ӎ,9Q8s^l_1v2EhWGA$M)uPOfVTٽQBUv @ ]۪ħP oY[TGC/ˁau9s 1LGYi4ŠDF̫N6.7o@JpO.^ fZ!Rʔaio*U:Ub˺GiJMM Dz?z޸^$6 0 w0= @h,Gp|siW;7E=x|^(JH76*b􇨻$mf2 3S++ν?_k x7ZwIPHƊ^Tҷ` kiu/N"31՛8H ;he0a.*ˁKGvfSKxe̗%e,ņ'Lejzբ{Öja\2&C eRI;HR|%SF R0i mvv/E'KQ ]cB p> w&z6ѐn' DE#;U7N~o&V{vdY0 A\6ߜc1ť GI' ~^_4#zO]"!hÉT ?BtһOtAk>Y<2e w_ Q$2`/ZY㏱N]_;|@м&S|P[E_61</:t&G,`TQ1@'PEY1NӅۄq,bI]Zto`԰ kF'>F"7bIHlMvg%؞'Q![@<4 ?+z"Fg:rr3GqcPxվU 3(8h4^%tsW&D (˛ yL54)dn&*؋KB])qkPDDt܊m!vj5h()ԉ"prˮd祍U!GBM(JDa7NS8e]+7Cf)nDYv-FwD၏nF-x9o%6.LjؾT6aBx.G4;1ʞ M}vF7$v򱉗##@ikRrVtj!D*;IQ:rarق-0&i!YJ)w;jGy Ӈ-2d`I;1J;qJ:/f@-.y.dH4#RuG0PGXxЈ->j]٥k82:uz=XEB4V:!ڲQ䍈|h3z܏wumDgHKxҳ .Va>CT*<5uki/{#7\b`J qA"N%:5_~l3˲kq~]$bU2MC GݎpG'q!8h.WP5! PQ3?l7}Z?ec-}Gu%/CW:Z(mHI.59İB>G'!ێ&F4Juzmrz7A/Mwa=,L^rJ,.|"?`k9Mj5j nGE k˫BTYuB֤cc{ f!)>Xv8-s *65̩TRН2,/Ђldꮩemkoq,1WR"S _JX)|e W(?b:jQ]8Eqc4)}>;h"&З^w2˒X:?@N}ae,IT~U?6bEvY٨<|\R8Nr*c%qQ e3q_,P.!p`07ZVC-Ht2^B '+ӝ٢!fnp}c;8MEhWDP2l竷aIP5k܊=gw0k+`^ a)Q9&rm6_eD:r܇LqwgZi8}JF`=2R]~=Ț) v;'h}F_AXo%o؝<>CT&"_a)Ŏ6Yl=)/XK44]XX͏Fxpdh&DopCSFqD|)@H/}=|m0} ܂Vze7ӭRޑž^FYYų7۠U" 1T"~̇ '|/0^ܲNps>; § $1V|v%*Kв3(i#z$+v+nC!Xb__J*|74ulFE%F֙D "s,~_FPD .KSc t 7o/dUEߢ&C]x=CDV%y ện#EkIںD=Q9^=lJ3f'm?7X"nuo{Bkƭ1v(? z%vq,`_^x\DV4}H ` DB7Xu(f`HW&k QctѓN@Kˡz'-l BJ=p<4\Ȝ DZj1,XoJ{zh(পwW*o)%Hh[X":F2pabF #WzcZa~:Soe=<7/X{wa *#iV }F` 2-/-N ӯ5K%K3O(Ջ]E^|f(é!MU[؅' I تu 'ߎ'fQQ@Bl *<"89¬A w(cp{mCw3"7?F,tY}<ۘܩ_lbNe/RM31D\@j@`V*R-~OWQ*WFJ%bI0nK;ݹ°rbа0AoU Ve7_l`uč!īo)ӨI'n#|ڝ8gc73~PC 5Tˠ#d^ۻ3 AH\ L6.9e!C "&j; 泂ÙCgt^TGd] 6E JlZӇ1DOYw+Bp[u#N,TY@B>kVS@틆YYũ,dӬi.(.:E4uA2WMp[9%?Hhm]Qb[I55HXTud}9x-Սvr&ide*ڨZ:T~zb,/y))sPG n#xil:00UjkcLBwF#`oHsxD4|s_*Zؠ(Sd-OwdA7E(؟/9\ub-u̪[wT6Ʊ,X"W⨾| (5)W5T++ %Ѽ/u8ogZ$.IC]IJZdibN'DܚmgE*/&QW&@t|2{+csjH6JNceԇAJ1s+(%|Aaf&;t CA~f1RM/^r2ttëĽT%>o2 vD4!W\e-vAaO'b@xaW6!7J(()Dz EL4ME )x(r'_ 0aC6{Z ;tvG[^2f/ep=1@e |<+G>:㠔c0ࣽ\Ͼ۶ߖ 4ޔ^f s]|a6PRO,fIŵo(Ja6/`mY)c۶z^)7ܧ-v~:G ^688}KȖkn< T`|K Rs=xN)ץىf)~YJ5;QgG; wR^u]E~ߴI&bBe~Bs'8*>kAEl5#+ⴔ6)6fT[9q';7@lkqaa`NJ%q˕+S vG/tEp8h~( yEUYXפԷmhoUz(wŰ]K3;,( Тaؤ]a~kTv(6ݭ*V Pڵߜ.`{5zcB/+X90–F"i|ut5]vw<&,AVw%F ;fӠ(6lMn=>ruC%HVS5&C߷|UJٟ믾7VEͭNhq ԜHcZeV PaWihx~E?I|Ogim4)EM (f-)nn0$btG۽^T})a+Hr~/)^Q}ń#0]>@}Ҝ 8Z$zžz |1jŏI[kH˻} @2)_G j0uê{ ,^9wYskz>C.jۇ٬68<٫9+O=`OеFlҶ8F@l!AA;"uA+n@w%}"c@g9-64y޸ڄ6˹.A(#m<Q u@P;=<|a8 @͐l\E* sҭgX?yo]pUaS  ɽ՚*>ZK[z8p JUV *>kr(s@'%Է]b G,/]=+8G¢ۏ>dUzUgBjFe|f#-Z'lrN+T )IPRQ@^ ZEx5& |Բ @KxBƭ+|o [YC߫~hiِ|)+dj, WL5t| z>֛7mv%EUA斒4p'2UIiaKNqm.5K|%·6 F 5% L |Tx"EڗQ-e瑩%ְ;6[*V|0 @E: :yA, NuEhj1y-uCNn .#/2p wGv.C94# 7"/N/+g>ӖNTNkҘR9ӽ卍L٩C([>Q5,W?W v⺭?HS2k)p艝ˢ;uvwϒF!S%v:W'E{-Qaɢ|8ĒFru2UgP-՘9C)^ka8HP/g5L> ENJYz{{fMySgo,|>oMVq%!:M{x "ќ3E;@B=pQ !Kժ>DϘjX`Ab;:57Q#*(4d<"Ǔ-ޗk`U-rХo.Õf0;Nsd.-I*8(tux(r|ywv;d$[ٓu$j&y@>S38 }C̿^Le*j`zNJX_#COd|!A 2&eB_3`wPtkiǨOCկ{m4doڴ[ [`#"m:Iwz^@֝^<y.Ieʓy"դweLL~x{]$/m.[MdS2uk U3l*xGgL2|DqxN%l}qg:qL\5Xy‘|aPSQ7R(,#Ϙ$`J(E MlCgy\|w1~~?dT> \,Fֽ]faw"}!Ik$~ 5[7I)!mPN'x&Cɔsy%?Y2RKwq54'KMaa1_{¯ZCbF]5}7(l6e'-7C:@/A g aVifv3^r`R5w^VReX^ZZ~XZ֜(%Otq4ȿ# CQu%Mn)_MA y rQQN~1ճ߄4Ni>JBk|%]E*N b˖v-d@ ]OÞJܚyve;ku炕HJ'(Ϛ9E2Tx ;mr<, Rn*_SfⒿҌ#aHE)*.PlhV֪|A4+.NYKX6QBIx>r:I 0+ԄƦ=42e/9~%D8/(tJɸ9ٺZt$u$3TэIy²v 2@u4Y6]ŷÕL)d=[a2AཌQQM^<"dGXRUf+yLwANF;5|Bde lK3617[} O6k %ăe&d H?v '`sEdhnþ7ϯ'EøGf}GtF.+f;ν5 B&!|$BlƜ_C=kA ΐ&SyӦvݣ|o¿\'6TCGAӆgOA d X}o D)]}n=~X&բk $`RgV_AP*^l= l4yU{e"6匘JC@ysV/J RmB_bMȗ{ާKGRVLRbyKNǠ^gdhD 7}Jc"Ŷ$#I oʻaL5 [0]H;~50z|@ +B*ICxщbdo{'wp,v4:sDK_gk=:UvOXÈ8G#Ll_=VH eZF-2Pg6"3B= ~'Ԫ niiWv-2^Q4ﶀ\}6L}WC;k1'Z$K3E"Ko| hw. co̜$O/bvgekJa~'gi=%6k4) } 0@¢\/}IxApCH"F"l‡݂susd^֠㸾ڽ"*Q:Sȸ[B vfH:߱щ28z<{fv [Ex$D7!%.Fψd;7>se4ugI|ѷsqi<#N4ix|ԞZ9m*5eo_qIr͎lq 6: "_MAòO0483 VeR@IMd D(!qtiBޡ \kW$Qj I hZk@#s`I8 2*u~vM4`lujlze`ӊ2i/[Z*|j%~T\kv $|9MaK} p2^B(pQkRi5vWjjRb ^) TL,AxAq'2<)h22ՆS3B P\y.ظysjtI l4SH7b-G{$v7] HyU7D-|&1W88hTGZ!Q1RDu,ZlT>q o3lȞŦ3?\g8UٝƹS$ S掶c<6p܌o=SA \gE* +?Y _?~|@= iJ9`Еs164k+1.Z&y514'ںfWZAnN N}qI-Iy&BsI,r~J%okd*uH/ ]"'BV)MDD U|ژ:L1.cl.Wh\(=`0z@BsWuXnR78eYcKr=|N6[˙qahV ǷWey=ջHzbj~L Shڒ|2k7 @ 9 roNEdSd6x?ڼ}[n=h7Oe>jń pK6=DžJY*OgԞs6NF u)1k(,N=D} }ȋyٛs::eՇVkT'X vD^@~ƇdyW-!/9]{Sq̃-93ح,~B*Mn{ Knnꧢu+N+; f\uQ[z Yb P?"DBx]~cgq-Z {O3-#XysKaRm Nf- &p'ו$wf]u=MR/>gc|&F-9 2)Dwwr Uʄh}^t,?Wy$lIp~=4!x/E}{ۙNq~ 2/W%+e1{H!eWP %i@v>5e1$X^)DD٬6n+6T:ٹCj,!_ ^2#R>$ZiL ԩ ݩws1xQ*l!-I~*sܷp3rg6UKWMXs^Z!p ! (X\״zu-V>[3ueb% +8߭7?a~ N q@SYg\ T D'ICIdQ7hS˨wIEnY/]?ċ*KDKPit t[JQ0į̜g*|#nUmZܺ;k`a(cfh+G'I4us]Q8VP̆I61Ij8`&A-<^PIPS-aR@ C*5q_ԌH>bddo㩴2n/5!],fěC1ٛL__ lS2v=m P˜`o[z FBF;.~a QC [lqeQhx,I\ ,%RĒq󦙨CA0ZZ#vP@ZCCtK(CRWPHО_Fm\El8En STnX.nGDH!FrGE*] gC.d7Z=ȫ n P=z^~5B"B*eQ SCg΢"UYbpb_Wi6uGj4WDGBv| >Qz iND:]ZsU7h0kl#qXD Qar*!Y~_'[Tk 7@p\#i Hc ^CT4V·!%i\}II<{+_OTbBRb)f;b s+(O=7]?xMBm$P'FgM+"[F*dmbIbR ?ɪ)I[>/?p\NQ49*̵ۈv#>FBғ?A~i`rʶr_r Fi]܎eF/mR !1R,CO]ȠhZQfLn'CBcDKH* eJյJ _#GNpCHǞ KGd0NdǺZn;Oa~t@E9p mߖ8ďy=.(~i)4GcaL[bD6eD!lKK`qup$a1󈄹7[xc.|5P$;'zvXl%sZZ9x'H(!<\D0C6@he#N`oWEx8yCϢ"]N҆cQX)Ha4 myKFbHS?lK`inŧ" ^╇5ot7 Xk@ԓd5)-{p4)1wXGTjif` @3J0= ~v+uI3zIrjݬghQ7%|1@Jcz>Ce/睚>rmP#9jo0j!S\莌)1"}(Xj=r_¬'cKO2$ٱ4J)<|YhM1\sUCD+6ɮk?ab'==6b;Ms /bǦ8=d-fPSC QHsb]T^zc45>讥y*ZQ6s%5(H5͖2r+3/+ m R';.cn1i}(|nOt<&y6AzTNn%W}R:ս3=gKi%~ 7l8>`S "i-jѫ;:Wuw? }+ۋ9$7azt>+<8%/88"0sw;p6Ɲgi7Hd1`>[;)U,h6ܾ+(Yq.1+v;D*E d'rv#}t9YeCi'0;IMkC霈$SCݵhVZȓ,gGrGϓؘ"D*uYnFz28z:mA@71qLm clyq|ţύm7y~m@\u8 ȴqQ Z1=:+.䫕/ڊv&Kh[GpoOcW!bYǠr6MuPa;-Qr}xNs6hcC@~+8Q5Cy݊l.=؁7d6)K^"S{;%2"dߎ=(}0?#\"$S7W"D1ve(OjZuJ},EÆJ~Tְ7ދkѫB`sT H! *U2d@Lptsdd@fӓx ~+A|l[> Z$o[;O#>y͝" 7 Qab2+~M? zL0Y'V8٥a.7SbݮРr2ng_2 i+F1DйjΆNͼRM7]1ltz_ {mlxNE}AXDƃvV ٝ'8"7AnMâ􀳲JKc U\)#ZYII#]A`kVhSnjw lwk's>cW%TPQDV ϔ 7PM_[p¥;6cc],-y_ zyUu30Hl kl.ЍNupvir7#e;wzrdirhd Kpg[ _:XE#~e{Gh˫Y=I#%dqbko$cI+˪KRkKS!m.[#'_+~,vݱ+qMV+ܤ&!6혤uOS#)[FdG>V3QdD}%|fw imhMjH8X%0Ț8ej9ܱ~~#fe@1'|#a,L hˊz4 A/ٺO}rw^,/2$M[J+X]A.QL.α^枮및&G;rJ^7N0BKsoLS o7c1R_'Ak/d6ځo(#e̽4YPj"Yqz.A W UZEa+[B~2"YSz]ت|t_f1D:)dAjE·qvȒ +=Nl&Xm&LH282X㭉ɟ p5K<͊@p=R-Є9umfBNE5F2^Ƅ4pY6px=~EOϺ^8 ʍ? ,2Xх>wCDjZ^.= 'a oՎ|ek ґ5=C>M{sEÉai10L@- A{Kd&bhH5c c{]cF>Ǎʠj? (0˝ј'Ii] t AvB,л`@Uh%[*#䌼6bT n_ ʉJL+#@%gB);f=Hq\>.t0v4c_׏!m@ʲGW&?3ӆYz:m _w>>=Y/9Iga}(N´#ˀTQXhR~eLsS"ǺsjvjQ0uU! 8bEpҸψpQ FG 4[H"*XM{`*?V%?FI3ؽT"lEfܝ@\DhBYY3`]E?#{|TĆtY!Agvل9-Mс5[ab>Y(z÷ٞDSr%Xԕ&0%f,P=} 8w3dCpۅ4ɅXAlجglr%jyիF9( CFL3>/cuy):O|sK]ߐ5@d8I#jI6"7JD}>li~Ty MG8aGN Z@޳0v8ÇU# Xv!N!;aJIa0, f ؐ~@T&| ];K!?3$W?DXx.hBAH Kک Fg긇Զ|8#HérK9!}Tk%tkt),jWv]-[G?(yhvh4[ú]2DYqŻp4b"+C JE}Gxp/Ji `Eپ )a.*WeҔo ǚfxV[թhxk[[2ڮbGȣ/}K⊩ ^9o hؽaLahq#q|z>D#vft% 9z3J=ԩu+"*?M\P$IJUJ_ExSjdE7^n(`kgfs푩2'X ^HdƜl)IvV[RۼvEW(8(y#l":]|zfB[ʞ/|vPd ;Nc>SA0{]ct"ك5@k7۰%cJrt8Xy0Oi)#uמ!`bI(mR<MJf2-(O<ޡP~!i XV8ϠKLItgmFj}J!ՙRWi3R; -<|RcbB& "CvdbKES8ZE@mBvjImGv d^2(=!@WTsZ½DCpO#ypMsn$HYJ+f8$mXηI 6_W3u|^:H*?}W/rU3JpE#8w%A+{אAVʡ=?&a>´kNM60ҳ/}OҐ ca5.,EB= +bET1eCEIt?J:.+U'/#nFQqd2j_rp.+v/MV3`ŋ dN$W⵹|%K?ra3NO;A=9^:7uK$U g:MB.˅鋁|4zeXd4t#G*l*hocȭzc8_p =!{[Uv}ƫ&caƕhI^nIUx3)Ya(:8LH>5VJ |B́aXGD7Oq%o-at7 =(:jj 9A4\c9Nc΄cfMt:wlJyRFwZ1]:  ݀`eQFg;F $8A{5Y9br~`^lPHgbb mi3T+эe(%TrNU;z>*Q=!D°'+^趜u̜(V  Rɶ7؏,#bkθY;3kR%꥘#x^}4L(Cq}F:'mxd7} >j©ق2@aŪU|m61@q('rDͼ !2sɚ u$ mY".9LF+7 Csc[m 4-0@RagZ!hЬBD-laW$5ӚN@>?f;qw@% h/Px_ª!9mUpjPvAS Vа9b:p&q} cDuuғ[}{Jvtb(Vb88!i0R}:ׅctEr1 1Ḧޒ:i|Y&P69IC4g*7clQޒlζ1?eR'~)Ѩ ~i"] Hixp;rM ~ӌ7D(=Vd:Z0~x!:5W |QYz[*qώÿ1rƳM~vpy}|Q)ңWE \d%<x.b͔d4bSAu*6b櫕p!"K\ޚHTZ&Utvu pt߅ >#5J˂#)Sǝ\d`{ݔ?{fz 23r tV`r$dpeC=?$BlAs>rCSk J:Szݚ9 & /Yʼ}3l( ؀'l.`@m޴:M:۝jMFƬ1<%lGu{q^!+;6=NL 5v .TЙte%zO ?ܾA:myj8A$ T-v-WRAat 'e"mk[PV O,sIՃ{lWTbXC1lj+C<=g  Z5lq|93sD{e$Kiܩ-ȉ+A&,] ;lA^$swwK2U8aZ'Qs9vL˩C7%͋d)ܥWGPnYxw {1G0 |N S٤ãc9dv2q]h`^>shڊ=|k$-41aCDՊuIJN_mZ0/)qHXyr`UG/D&KtaoaEC~$JqLOfte]z/8p7o>b7/j;dNSKlL#4nUk\E°즬mؿQDJV+j<ץ+MEѳ8]|I6͉V7KpmYQ[q-:9㼏P+͎s6D|**Ud^cR|<x{aG}<9dr4:N4E*5*mo ^@aa05 Lƽњڦ[U!X0@ϦHK>E!0XFUI<s 2;qĘ*r2|{eӗW%lNzf?g>"s$`}%¼T$׭aԸ7m#?Ȏ(ԋZvRa]#Yو*wrTkm'? /6+Hxk;ǡyK^4O`]/#n})ZsHBu(Ц:^\$ս#JpKbGl2P{t:2 OJ ͇TO)-LtLI',\& l>Grg /<8VZf`ˀ܅H r*ݙ8lA56+ӳj(Jy=T7+tivQBHd`@1͂:"&V }eʦP4$p{ <(Ex޵ϟZ|,է幤'YbzIx{m"m uR\}XqcR{Fma6%19?x;  )MD}muG×[z߻ ڮMO,R y"5/m}_f_)˓[[.. ߉ M|s5 fKToWx$k U=8[p,t" @oa+#jWtf}g0Ӑ̝@983}AjT/.Z,jbnku³Ufռ rln[zIvu.NJJ@A4Pqx<-Y4|c? qCYohkSnZT¸K>mcJSC N,P#+XY-4djd 8(  i˛1lAw ?Wއ(^NSg1y~nz1RΒ8Ć",Ч nw{hxxHjKbU'ʀelծ.+6Ƿ"3~AF0yv /WDI7+=tkwބ5^.̭IRxQ\<^濆YO.Kν$nm^.;Ƕ4CIEzFḰĝ䞎k*Jy1N0^V7t788"z 0ۀ+JSq%~~qHrJtՠ]uQ\G!Re ֟)O/bE3I,`r<HX(x=&CG(Ob+m՗~zgA3l@,y%/RISĻG͉IDۭ?d)cP-ŲpҊ;w6hm_S(bA(sQu34<"bij#vAv{S0) T\pRdMvk@XS5)VcSx#c>E\j&^K֟Q̨ló<9Ѥ\TYM}u)1FR-&VynfbgB,Њ?Eؼ!nW—huQRTOtYv%Ğxʆ${ ")멙`fQ ߿k!լ:cEǖ&} [9^yw'LpƦ}Qt8u|En1ޝV^?=lnrm[6G{zBML%IJɓW~VV&=5( a0}yh8+lR8dLX0TX#sbی8BDʉ/xE1~JFAp`am\ {\!V LqeI!Nqgh8|rHhB# !pp-G9F-kmM}pzNam&a?x3dFjI 2JfQ0B (zMBiTݞ~O/&m?b,=v$Vj_~x( Pja[ZY`S5e=k!*dGg/U/7Thqv5tJ t+L?~,EH3ʟr#ߟV**LZDiO'M>czia?NO/w:i+lEW9R?F ؄j|*K4 Cdab:|D~knŊU/KАed'7`(HϷ*q}ĨsJ-cb'Woe;ɨmm|Oxc8z 6Rz;B^"meҫnta KU-%TNqB>JiOЂ.ѝ+@~{, ${~z`{$6Mg;ᯕ%e_j%14{I#fBj\?*!r+LzIl X;͈+>:r:+C5a?w{uqApBCgh/Hf%u;l}t#t`QpZ2ns˄2I>&KΛV?zPrv:3B^f dt v yiWJsQ155@Fx5uRX"0kxLQOSyo2N;2) ->3jϏQGdQ5jl RO _oWade0mCl>/w6j;F9Kbe7J> ?> S3k&74mBfd?GbF@nah -802kbR7"Zh$q#tr|% e: pOd\+ WK 6H^JZD$K N2?>eoijL7ni%{ "?+>D^N7䂨 kG{*\l{\ٳ kuP<& $Ym)êGA_4 SU,wm&pK .*`K_>gIW8A}FGj_rԛ [fLc6 X~o1:' I%>ZP#]LF} Hr8=a(G;AOA4^Ф[ɴL~~=fz5'PB(PˠԤ zlF#eJKB"__aY~a_{U|}:C6tSD1ckV l<9B~}zLvֺRvKfE8"FR4 4& g*K;Wt4rbW3/Eo`=A(p˶fRq{ђ>)Aߞ kJPhZ&Tf`ldٿ5bXef_73ه8a 8 A(Xia {d~?xH!+z1vHSf}. sD RsY ߋ#(c'vn'bD…6FY]6Dӗق\c^vpTS$:jʁWVEx$Z>pbmzXSIoXn@(EkoLշJtBٓ*-h1ub̔ F\d2T]U?W|ަ6I6M]"Cd ܻK40Im3r_>}fs*[i MP(@LIKOarhSG\,X;D>'bZqqKsG) ig]e? x<?v]˾)M ׶wHX~ܨ&g~J3 GdFƈ+Ow8wcPk^*6\ ν'>4QSiٽPmҙhIryPQ'KxQ+ 0ܘЊp(2/t\!6@K?iIkL"{Xq͇%l |Lb rOq`Ӽ/(bW˦^ O|`FL]dK5zP~~4-j{eO?<þItI7Lbw'|ް j/a`>%QhȪ*JPM@y'JBy07gm=(>nFۢد)v ;T*mulu߼%kbe2Ã'E%]^MC2;KwdT3{04.MRB)g\Es d&OWfe0U--xL FW|ݳՇ$w\lǟ[vU+ aFI[DB6oQYG&E[(gEו%]ƃυtA%HwΡAROXwP! N67)̩p,fWx<=ֳׅ;jL_R0a4jHAsZ!O4-d>Bv%D }Z?&[|sug%SV@^]ZEBy繲满%X[ KXb(Lqü{WQOѱSbAjqDF?etл<߬,#vHƜ{AlOU*D_ar)OH-" DvTjmpY{dDO2bw%bϿI+fO.v֌qϚTo oh7iSePr6Bp J*y#HO'@&lrjGU}93Jәt.)v% ݮKg8fn:Z +'γ*x1hes2!>EJzZBr¿|o8v{ T]T 9m#M]O\kb3ۉ_;QF$f >3R7#) dM,M=Dku˾XmQ1}v5idk 'n~6mņN7Cɨei5 Rg[wxrXZ \{V Lѝ[M 2A2} h~,FeڜDznVz(DM{{PJ."i>klhS%tNFOt[Qd:ȽP֎p_w_H5E48=IQURtbr[sfVlIF`],KSv[Zd"Cqt6aEz9bE3r+$%H( ܴ/9bs8^nU`Oyjk#܂k [ ?)(׃k9t?}u&)5*Rk}.#X).I}r!jYK QS[yօV,w"Y2Wr5P1B<" $'kXWh5n_A oT*cGłIAηT*fZMG33&޳ Hrg%Ft5xX%Pp\_8 >`eK0 D53-oGI$Cev<Џ1t)w!/`ώ4g)*]xj'[5w6ѹ^?|ߴg>p컷{iuD~` 'KfX샯.#6Doi#F~Mw8` yBC.V5oMǽ_6:SY4fTCGo:)[[,kEf0D".JB|@U򄎚M1Ýz71?Ԧ奡)fyxQĴ*Z,F`o&#Aлe1ף!R  PުC3j+"'pF(栳Xӈ IABl'?8sɓ*&zO#/E %@xؖ'o/d ֥Ozg|Yc|gI`afu|V.I۔{ ^kGwlT* O筱"ԀgX`ʲ=iMH@I"q M/.)uG n7$DHɐ20aٰ'NT ]tuT?y+ChJX|FVU޹|#sB4?CE+if̯!8[/q~wKOs Cڪ2&6چے7VGLK+_-qShF=y!K'ۥg8B?u+T`HPe*fq|ƘCl ,?:5OGOb39L09L}w1jlτzkS KͿ t5|^D$hwXkP.s/2])LX!Ll2xfsMzDb@6UW<rW"3]ҩ*Z0 "Ɇt;w}x&ClK_hjkSNe+ @~1,N!Ng.bƀWi1Y`EBj._M"M+ xPR* <3%#>̈́>æ2k1j3CdBĻ~KISC(.qe*ĝ^յYݎ曊Eގsn`݃+EL )R7{`xy9I&vE >_'LF~h h]>b1t:}K벏h,Й`bCCUUXTH 9*P ];2eO"ˁ6!'% ƭ|q/)/A@nQ.A3:TEr`R̺אYE3ӏC_`ivݔըyݡ]AMɻmj(yN#6K1*@ai<Ke-P6tHgj(qnZAb8IC'P"s,(kU87A f=D/41C]7m*42TJ,]J" d+S3>-aAmRՊwNs|HMgqøFLLaH ؄\E%]xXQz3,zWuMX$ܕpFC0Y 4t}Yq '@Z7)6]eIK[ː/f:C~ʑ'󘄶-y(l?H0rZntjBğy|%0z_hB)ڭbs)ϕZ+q sZ/NFOL|{5*}ޔ,_ l `!7" 4.4j%YGF ls\{Jo 2gO)? }y'Pƒmfv|ks ~ o0U_f풀3L2le&nȩIAv0Ui%3=a o4c RɽH zl'#Q̓{Z(D=ڸRʾA]=0|eȏ)P)iXlLlDsjbWcQtk7Ŵ#϶GѯOU72 ̚x[ۚ:=/_ch46\ӱ;c!6|cuWnh|'PmB& ~o&nnE5Cthv$*q}?2c}ʾ3Ѹ-/?o U]sKm􊢗 2wML֧OƆH"2g>z#!T(v#xR=M- Z/|Dzu;6n-,d&N-G"<Ξڻ` @$\ƕU\2qsZhHjJ"2[7PM~}3ЍQڙWr-h%DmܓRN] }Ff-+\GR6PEKb#_7|źb!Pp3GʾV#NM{ ⌓;.Sw*`ׂ6Ml0 Hd, (l]REG.1n}_v:FxHK>i"ۄ [;C֘yjrSG3vmEp+D55TۜqD?:3J2 "UEd9MsL(i0uiGAl2'GPns^踤fy={WM$W+VTȰD s@侬:fd>H7W 䘽Сd<S}Q@?)6@3uAn|#n 8pF?NQ=\*kRWa,;KN V.]_y]{} Z?E&AV8y8yC~ДR:¥c:ƿ4;y$(7{a&ƶP4LcJ ||b-lLHu.c@2QHW |8"I0"ӸPAU{h za+[TZ]˂l­垅%V~b\,_.hdwиG(Jr*~Lzɗ4=)eً84E<[NnDH䬀U`j ɫBPݭяò Odp&5W)hz?"B#. Q]*zfi7[ 3[sNK]/&hiM 3fAQdD借Q~Ҁ9Z6*3o% CuNߑ?k)o])P淪#'2?I*wd_Զ+!%5""s ʣY-8Ev!E\Zo.+8eK>OZma}] { M@KԮG8s qHi8ʙ0YK)F)Pjx ځ/ucR21'79Q1*׬2,2f )DɄX@FPR'J<7˻M{^˰7)M"jҭ?䢹C[9}$d3pT (.nwZA"戌OSGVgp2w~DHQ0L܌֧3SWw&Mxp,(ǛfנgDWG8=TKG; XG%s, %`&lzJoœmn8~깑:sԒ ^-}d+*An1ۑ%C<>ȿq-D AL]KpGԺ?j[ûBowdБ_U پ9ݫE1ZMVRsu RA0/Xљ*U9_ua>%P1G4 XZm 範5s0{f=56#iz@hxijc5sQW>%+Ƅ]3=0*a5Z;bX At. t%фf}hy!F>>L/ H\k}]HUmQQm@' v&Aд'Zbw@Q܏5y=?=+:C/B c] ~~x@sx[1΀$הb:;r8VVI| R1.BHd \=,D# `#5] bܻr(?=$(EGyI:y4G况栏*B/|2ZoKK5j׶tS[6$cQlMFTg4g38(gy ߅X7, e{Q[|GyT'up>lkڽ LIX!r59ZܐMU2YfF?. Ol'{á)Vhz)pu;9a*;J-lόmA S2ikues:n&I1mi' %m-b\!˗痭Q{Zؘbn †}:v"Z-D O-0PY"]yBwy٘ӉSؙ~wqAz;ԦGŶ A-I4pZp1B)~|ysb1Рk8R0z,m r!q_6${HQu"BS>΁ևv;:wynSd[LO 6A|K|Tj6?|7>a=TւqúN!gVtg42&?Yn&gw5y^U<qn}օIvS]|ߔl˄.5P":6NdX87|fRWUZI83EE'+6df*@0aV~lo^VB!iɦ-|>D8Sܚr![H+2QFb .,:Agl}2i o̰) ,djk?uα՗)bkY>@{Eˉ\|Ff|G5mP֨7#* 5]~9|Ѳ3;L7UY߿R@o1\TO{gZ,;uoHO$mYku00;^|Y`7A9u'Ξf/R,kƈMZZ75 ~Q "uvپosTl]BPpkXEx<08]ğ`m RӛR3hH]wF ,y72x*xaޅe ߅4sBx{gK; >}~X?]+ʔm8  Ƹ ij$a|9s|Tq>/}=T;劉Ob(''fۜ4k$4<ќϬ2y*RL4I)}вq1=WlUVEܺ]7=S+\e/R]DZá0T KU? L 'aiSƨ~q ʖOuvDE FPAS;fo#eezcDt5|䱱SHQ:+ ]YkyAž芸 ۝Z ]m~(zM?DڰM[sHu$T1H kuյ(CMu ̭!٢)K 8~-4 +F^#/ \-,Tbi?nWn{Ãt?v$ NgZϲTξw 3T&Z{\#6qa?Z:s96?Ԍ%ރe]N@_ޗDKO[4G p9 5a<:΀dO:qCD;eaםy_v_s?_+Lua=$x,:c _B9DHCh (¼Ԭ.FxfU{ưMALBfL)y&Wä iiɻ{36*ΝSJ!B X#0~Iq{}u4CQ!/3R8L Xd.қwYycH<)26T/ʨ$TXEWΫ< BBDMo*C ;-4dƊ86s%]W( զ@xpybX^M!\]= >",V;`b`-(^_0Ν]+"iPKNR|"䑈wWɨjӄ#jnL4h/'Iv٥t`s{ 81f;g ,&DɤU8`vފH P`?!5TtI"3ʈD r}lB,NPl2QuaߝvVy6OĦF$80^EOK߄)'nX!}[@f'f c[oӠVnWb))K zoA.V,}K+{ 1icgtp$|obU gv`|N}^B nT+E,gֳkq F˷qVcaz&cM #ϔ @gG#o--|VuBV* h!a+&v5cۇᰎA%2f ҇j>J s MӘ= hĭ!/egK*8܃HzqIƝsmѳJp/)Ҿ6I<*@ ~܍.>e 4CNKn}i ,B؉}Z2l w.S5J|pGm>PflAL3Hܖ-Eo-렸6%ҢJz؃КyMď4L%r<-4@8oWد6ʤiEß&`^Vn7Njp ؛rU~ECl$s0z %*E8s(fo*~RvA=OTCTԵa18F6]t_oۺJr89-d[URSCE FTAқI'Ӂvqº."&"غjς^0ՑU>JaV4=1'g|$V, ﺝ{yr3bjQ b%BXFimlvL`o@jZꦬ3A7* rOC?t:+\ ݱV& c*݁J޳ RЛvRZz&LUǸؚ2RYHwykMq$i!E> +ŒM{jʿO)AOrI INiUϽ%}䭆fOݹj_юMN#Iy/ JC 9B8 c3<x^8* BiHٻBQc=PV@JJknΜxo_IyF]DrքIqьB,WeA#UGtrcTgA50v|˂ ?|^@L&c&y|;>l4! kiGqV`"j|:QCFt/C]ya&ad͑ߔƝa>'WIl19*69m+m8Në5F*D lSRȮȷio L}U2J@'H2G J?ݥ,~ ! fE 2uIL>r`H[`FT w2`-ϛ-D4I^ށp_E 7n^Gg!֤!_J?hD- &0B!q v/Ϸ `\aڎMO BlQgLM1 ˮj_Xjʹ F0O61&Ig_pPX \ADF:(ǚ M:aP 'E&SK=< Qئ5&6J!Mr:j}~"e6`t"D2`XI"1="ʼlzg_%33/rJOVy?6 X)F*e7G!FxDOkJ& z(z5d>hgQo#Xڙڥj k #-" 9BM Y N0/lrq6U V%;]km;XN5SڼU>!Hc^g2h=Nܝ0a *21|q:|sӼn8L7nA \;ѣRm_,v~E*zC|=fE]\Œ8͕ʀ^qV!PMzP9ΰ/EcOV  ?]F=ɾF 9!0[y5g؋}XdY*WXX)1b44z+tb] )UP 2saCfz@I] `1wXD $5iD[ 2QOOąj/h%m4QNh1hDSkAki8ea>qG@Qk7EDA/1.)15LogAU@2:{rSJ&Ǹֺc)d r]+cs)~`8" 40XFJ1' oeݾ1.a*7ҙ8Z j"3VJϻQMҢP?@lELNN^`q ,mߜKY-]MS/& 'd 67kLJȳv?(nUdebs?JʋeH!wk(K(CMc謁!+<.} Տqx 8?o_+O;RM:rlj|ׄmKtف϶ѩ>ɃJ _Հ )+BU4{NkW@['p:{b؏ނ,KON]d:{4|c@:WU2O^Sbuֻ]CŴH67)7R5rz 鋙 X``'2_%b@:<"BTh.V?`(vuFrFVnX׃g&.h>0W-z(ǶlvزR۵(>^lrjicѰʭÎu|cVC{5}$W?am):&Yonojڊ5v;f'2H1+1 at('\{wy~+pXt W+ 쮐?`$,uVP(9l)tp_áU4dDU]MlO6S b!d1Ͼ`6Wep8'/0x[bރ#TrwC'h8pU4 PA\<$?X5Jj&҉ĖEJ;fgk~%~h%.~1v<!羅/ݽR^s|p.:`&iX_apDa1}vY)Zo{45t&W83 RrR5 )P fbx9Aü6yi\%üf/bj +P;ryҖL6Đ_G'L*ob>ob90xB|A߆%csr=3Bh,.e5\Y])T5_Yܴ!lZTs멳~G)W|~N5ulyO`01mNI[>dyL?A-k]uflg!xD`'?pe֖0: ׸6rq]R~xs}6Hy=fxIh2W6SeB7;Cn=^ #JAu}dQīƟi`^hWB0ucysHœ( M#?f,zBXNG-Z-f/&!I|N.[*m/D3_ Jۗh*vT 뎛E3\46RGR"-c%y''-*@c9/{WCmD^U1oc=tf/oX-CA839sU']=C_[zqxd"rHH%~Hvt!O#G7:Ġ)CCQF^++?o&֡2~D:c#?kIEAN9I, vPk%m a$B3OnjN4A ?0 $oMu9"-SjV睖Lf+wZ (jz2䃏e]) \+2D¤&UrP5T? {H`%M @gte"rǿ4*hYډ3yF7B; y؎j34{ЉRoߠdw 9' @)({j}[hoʛPRm ݡg9{n O \x?6;f .2;=h r=O %ݼ8!!KP Q)ęzL&7hE7W< .EuH4iRSw1ˠFΌ|3MCMb Vg[Mw\~샇;+x{`Lqmꌟ:CF< 'y-SMtBah%_h*j,z\o,5e燡nڦr왞6<d541C:.nońY?:ÁpY Nn(CW| {S:# `mdOK9+ă@Z䛺 11꼕GXV7/D2Ur =1ԾƠ-&v1ԁ7 /E;.0R('_ߊ;A4(gESwqtXJ YcC~Hɵ9HӔCpWY摬wQ>GeB7(Q`/1f-&\mvFSl6 ' *n`L+>_+Hxizn7C7֘t\9MJ 23ߡ\ٮE[R:1[z?', %sO!bXol8-1דy27c KD}ࣴ_ِT`~NO|D%%LZ=ym~W:X%= ~bK!+6(1hxmu@:+/o ekhN_С.[}b̕S+6)?녝Sِ#m^yk|ɷ6p.dkKʙ fDBݘ\X ziK{-SЇe/(TeGBwaL h l3i֨:UBdj0ݱ|Pز obQKіZ3bYj%=挬QM^,\J pg0`GqU)W2۽Fp<(~`bWx3cCEQ[ex VDmbڎHZ:\L.mtWSvӃPFpVoT(IMl:ᎾILWPFF1 iRȽ5SR{c,w]o%fxܨvkm{,emӐ=7L*̙WǁnV/&M]KTpĪow4DeZUw:Jg SqLKɰ W%BTTÃ4\Ab=핑5 DkaI-WҰ?:u*'BHD+> f{Mb3-)^x{pV<6L: yAA97ʧ(qc2bhz59SIJ.vaTTYʮqpxiFٍ& rZO)N=.{(.;OSHq.Pe}ϱ%=>~.YWKjM WdJ fΓp:IW/3Cu[X4A}pXhͨF`o54%Sm:sg>2`N0 짴5gGlVXI'JIBawIf;V"ccČOz;Xxdhd*sAm-id'c W[ꀄV/_,@V#(m;`,y' HU~4BtQFscT 9STiB呀B JK+P ͭ Ec5Q}}Kv;$Û\\)%dGXmѬʧT S(+gWD={ #>|ԇbR:A@.63w6J5», f!&x4lB",Qs:Aj G2*sycl.F((Z΢.CojЄq*X@霓Vx#ڨZ h%)n' gS찴|̕&;2,X*]SIrzpbq$niq3 4jif#`/E<3MauGܠ~gtl+SX"φ{CAtOkY7KD]48[p\Od9vT1,C)'$ (uJ.=oU!\V,GYnN w.Pהpǂ@YIV$p|S.EP°EcpOZKT!k'2{J]U`ׄa롯,Eq3[ks4G~ o2PK'2(ptO,C|Z*V]=Y@ $2t|K6u RB,1SVͬZ㵱 8KXl\͊Z50emlO~KI*OVWZ1qWsz!鑆sZҞBHˆZ!۞_̠/ě{݆ +;Gе)[_N 5ָT 9w }a}p͹+`bbs39<9 .i!0{? |[cBbf|~Q?7.SSC7XDړi_(IN  v}vo7,;hlx^g?b5O_ÿt9WRnix<vJ.n)K3grGZOh83INKοG^ޏELv ?GL4`D%NL/˯43,oGLR!ӝ>kB=ts/qꊕa='T,`랤.V ŋ)!dza',H!yԋ? nnbZjr)?~3Rٽ΍^_|b?/(HW|pZ=͔Kzt^ްx%>k_mEKD>z2Fh(c1?i{+g$k$Z=Xӷq4>KjA#n󑩿 _UE=ߗ$Z= W5?F+#F06IcE^p :V޸s.(V,u:y*lwp #@2?Z>qՓl&a-G q.l;^jCxг:f,J snoHo}] ǥ^<3q,9o6wtJ;9\ mbbW@ ¼x[Uv0!}I zS͐3E9_xhU!p?I(M U"+7#3`|e=R PNk;Ly} H]#DےRVQ"LR> :&ǽw$*hqr;@p@~ጥr&lm=159p;>ctPtۭEEُx_+&1U(HENCˮ" 51HXcR}$DtN24@sm{ lDld*dkj~KT#P:%t6قoȥ_E(uK04wj'"tvRu w 'C!ꡍxq=&!Pț u䫸( &¥Pˤם3X;vIvu BDK̝|*#%eB~إH~{u|j*e(rn\Ƕ#^pGޞfT>WOlΞ 2 4VagWLv kKt]|φr)$ˉK~[F I>Z\ /ĭ1¸N|:Q[BO_ȤTB S'ce2]AM'<-}{o AnH |fYARN`dd2'u3(n]~Ϭ$rUS s}Fn`Z4?yV.k] I[X;qoY9]Q>/ۃw#q:\7iDzL3"+v$`|~~;ZZT&^jQ`gU7cP@F^:ԅ.thIX)h}|uT>%wqbU@sgIIk6,jPt/{=eBy+F/Vl U-΀R/*EUL$'!r Lv)z1I0>}m ^윣[d2;,Ck{gHMhi(El'K_)db?FtyLEo?Dlﶼ-Kw^Q`mqsAJr-ET?ѠNW"=g9RFe5a?(Œ <4&]TTlwP&IB#jwVUBY9UlZynj/~sdfV{Qd[-s8VKA۱Du4rl# sb͞NKׁT #"4n!?0zldŠѩA%||St#J2 WW$~j63Jܳ]KRk5(-Z.ZQJ))m 'dx"MUO7{m%zqօ'oʂnbwcz8+4Lwf]1ހЯ)]R-K"1 "x3/aɚS̖}]## ʞX;̒XГBtnVxyd.]0Lp/5mZ|OߨU. <9<֬:sȴw]诓ca_#, Jwd[ud,V:R/Y$"}5^$Q\`e9oP&Ye R<<-DP&=&a;m:zuVDm 1v*W5-z;ބ& $U k~aS߮8wBx7)Ux6q'8'@+_|v%W3;ܳw>JL9aG9Y-@Qe`7VS >ϝu旦QW 'zq?ꇬ OF/.o8_jX݄iP yq[%mw ^ia,Q)PDm5YCDuuBf W D{vН_k 7pNz']x5z|3> X  zT bz>eB /2 E⌃ v)1SK.0(0cڼ<Β&IJ11{*OAZMJ@KZ!G5pFx)h+_X`JvY|릐:4`-CQWZVH"6r^RGJFSfɀƢ/ruCi䝾Q8 Ŗ ')sY1/+Y3_¢ʛYw#zE'qV%,CU*bPK`Jm:>i*Ot2mb݀o{[,,Y>sZɩBRn M&96I| % HB TЕHT]ʥ̭_,ȣpQClE$HvEp۴pG+ v-@GLj 7YOv04|g'oӟP(Hߕs"ё%*r *.q@bיx w]+zՏ.|Ei$XX$v$5ʺΆYPKFk{4OvEUdm ^͟1JiOG*Gb }}¤`=kPc&Ix Arj&Ө~1{St6i#*ʏ{x\TGgqrI,y$d9\des ?sU`if+K#%HѸ̊: /VxxdP+5- >n"#g:<[RDBk#l-]9|RSMM}An&śLൊʨPZ'$IV焕 y33-eȓI唇V.JP9T+6]J~jJ {3NjML_hMcT!*B*KU3*|}ŹxFddDYb =ֽdz 8)l؋\3rK )%756)FYWOL}UC*K93`S@$RFbtQ72 ! 5.;x/C^W7c~9,$C*HuE\,͙}?@^MLy12e@hRGlMZ U\NJT# d+!c2C54CM91}o-'#.ƩW11>@Nښ;or\l9B |]oG9;PUs>, =甋z=Au=EҪŪUpIqҮ@TNT<)0i޳.jYLVh`љ~JspqW'(/D A|eAeܦ Litv1,.Y5>Հ)˂pJ~hrf%6y(CS4ĬH[6Gu O&wgYON/n왭5A;|:M] 3?eddY̅Ff H U, 07OJII 8PY䰆/{hTgE*H%?ߢ o9XXdQ6Ehvcɂ`4M5v|mu(l%acwm L1.y.C: eE Gr4J,ۘ_&BZ+kV\ҷncZ _>mEt*]ѹeWrf1ktuq\ddH ^V&L+ Gatnl"\b$HngSجI:\rtf"\ qбߑ}!.{Ya"Bo]ups5:J[ M U" X-[{«+!k4 63&X0!qO ?Vw27#iz C0R, *ڭ^*JË^Y^YH5U<%"A{ Xqpaשu=zS]ՙ謝A4/jv.D7awB~B[9:W) G'\[#wW Ȑ}M{M>WR }yS Tp (1,%9rC(BJ yi~۱,k5{ND(~s%}R&M.X |N+s|p >iq} ($VuPg-`VԴ Dz.hc U~gNWKe{SÈiX5x mK: +-O|ăD?ňetZ.X?Ny1a640W0lۄoGpZ~Ӎ_Y/4#8lcNx:8oEfswMti%6ǝԸ >:Zeƈg+F j*})6>5 q A) 1!A>!l;yqgDJJaݒܠAL:u;ZBa@6S.9 L)`]@I]s4:9,e,SP1,ѳ"u :'?4IHfE YThPtBI,H3&$=sj> +Տ.]:7k;=!;kV]>Aa5|usrl) 0$ пZFP+52v|0-xZ$l ;^?jrqu&ȡb+l荴0펙4a!}|-.#CClӵ6*W\2 "&aFf?7*~nbtm>wfƥݍ}o5wau9!&8>d ZryqwIdY ~C|R” bW> /%GEU}NGHHWSl,˰Nh)P?+~*3Vz%|aJqPՖԯ5ɏs޷:0+) snNnl7O Цnuak% \ZYz9tl&c~3s$YöH0:X9y#VhCeZ(5=|N|? wNn?xds,WFQq+u2ؼym,1{e<& $]96\x5s[/_ͤ8\Lsݭ]ƟQfZlZJ<41PdLUI);eӭ?C2ڳڼm=fYR޷CXoخc'Ua|AbS0,)hP*!VMZ9SRL5͕bRz&t5õg vW8,n`[h1 Y PW;9fodSl&D܋,~loV)N>;1ZQ9 RA˧_ 9Fm6%4=IkĭerUK&Ws4A)O~G3{Q0(wb"@ҏ"|Q|a2 ؤKcݶ/p-0yf)< D;VH}շb_{4Bf<.\yq3L<MW+<򉣬$ec)_Uk{C aGW'NtWBĝDQ_q`œiG(J)AVCN9n|/x2qWMbYi /9pC+΀; Nrw AiLd`~hpcEVFmP{C$ zCu<;ap W;gRvp Xwҩ͢قTlCA-J4S:`qs Q cԻ \ip9¦3X؀Y縻k7`}V+FUdzW&ŝ]ӵZhcҜX{)n6\FĺoIkn< fIR` du"8VO=A3{ɴ$YVLMP$4zi{^jNǙ oe֐)^p@^'ݭ" o|h.fq`f̄ѭF9g_ww݉1O7ج8K<[Ն6/SnU8%g^Fd4;ejlv?a8l o4%}!lچ@l9WT42ڗBaqKid^\]:B;lgb{`m%LߩBK޷* l0v % UW|Adގ+- peTN=Tf桞1_; wS FaMj$wЌe-ǏL$}W6D~7̘0*˖?=qxSznm^zJld\ KcSIildJ[הD!v̶ q4ޫ;Ա۷G"L@= ZK-]N-E27ĉg(Ɣ8"d曣яG~,{0 bs$MP%"Qa"`Q&wOy95MLk!*.H'šʚXX%bBkHz~wK9uћH: .ky~^[|Wl ع *ZpBbVE>ՌJ/eP3?#'b1A8V@(}mxu\[ڧOB fg.s6RCjD*}0T⪢P+&Pl/Zշ2&@݊.ؑ#%>CO>o97j({~^%c>@,F.ھ+U@uG55Fܨz^!8IMY2ou:-s_^Fmx2)"U)~=~J4W);e6}j"BNbƓ ;leYs>/x eRrEh6i!dvt:/@PG1Z!K:Tֻhſ(ã3ł~rLUbIEFA)7ޚx"/ZlW`ŏBly30`6фG$ɪo{6|o?c^b.*\s.0J5mQ&AL1 ЮWKzđa3و) Z>zT1OtK{%I@rgiʈ1Lk\j,nHԻMa JL3 [Hg2p=u )DPp<Ex3*Ӿcp˛q|C@B[*m ? d-PqGMg_H-@NH}\7)IL7AQk҄鐯lO UqǠ(ZRM[ v!IW=Mm=#M1zYTwwڐaF26(ψjx؅1/&qG 5( #5P'r6Ogw† RT8JB] c jvIɧs֜}Pdy(A6Tuw0U "\ZCi)8 351Ni6أ(9MeJY,Yg6}CxQs Q6pg#-ҟ}x4D["Rm' #b^wp.+< *F 3/ָ{eNE< aǣQӨpTْ܈jGE2 .Ցk:x UC\ġ+Qj]*yDקfC?Xq 5e뫃 5?Ira蒎br.Fyw!&k#hp}sX4X@핏}e.COZmEqu$}šfРכ}}htyH03d/%|=գoY|NWs],Kvî=ȗDAKFԂbdU-TiShP~6ش;n}TX|SKa-9);]FH-z22aa ue%1ק2!sč0х}FTr?)/_՗\,ELM]oC~J(?Yst!1qSՙi"Y-oъFu7 vLVZy1Yiz{) MvGNq!0M&cdw0`Urw"^#@cMAyÏ``YVx؟R A+()-PfYX_,wV~3_ MːC-V_TMVLۣx MB:k#U6-gYRe{S/ =ى9| <-:`5]JG|K(tYC5KX}r ?{|@@EGk螵wȠ?a/H6R)Sx:dQ~>K@J!8ޜuCD?)B[eZ^aQLޑ0τ3b% '=!#v_A =^$粖KJDϕ@l!ey69qB7/P. V1dvAM@c{sJzn>* P O! Os8Ip'P NrfC n?`6&z/:ݝ%R2Ti@cE83(ͣ z+1#U4^ j3`U90!~.>p(>h!'^Tuϐ謥Y`úx3lD/6ZOc_ ;5i-_eh0$fzZ#@I$84됈C' X}ݲ$NH7۲$+^) X;%W-#~KQ] {!, JPI.L{ Ժ,wl_vCH9AvMb!!}=%ac"$w[Jȝ[kX$rzkBRcH+3U[l?hk3&,Gn!/;a5.2mOàPmt ZÝn@A@6Ԋmm_qv\;J)%q`Z[G޸u!Y:1-Ki6ji{ȦwGqفʼn{P B&&s&"+{onKiټ@wz.˙BA_<{HvNlg=}{I:L!ye5^5bs\Z`犞(Nޙ_x&K6f42nȕCZ)rAzPcPLഘL}RW0wgNBӜf e>#᳥U4paݏ~æOģ.QQ:_$utm87{{Kï'q {V!ީnsC/ Vj_0:*)_"ldT ?4+OGMRޏ\4۾πnWKˈe= +=Rf4.{"=cq{ rY;]7~8U:p.S_$g{ʼ+!* %bu% 6v'\%2sq˛:(x,Qd:Țᚩ(Z"2DZx ckB`< geSE a~`To&n+ۺF{* /4,u1 PQן O1' &]rG>PɒzDQeEz'7 {m3J!s=O\򉷑?߰JIӪ Z|T~25v5``/̫DgK渀% qur&:4 X+NxbGl!%9>-E8Lkb 9G?1yxxgHx?xt,7vJ=-!K!ZFL9g[ ja!M_RZL|݂Ufq~\/L$ tZ!;?J8PD 㱻C1͇@hF;i22B :mz-$^s#4@$^y)iXLqu Xsn&4Q({\~e-SjKJM`?l Dc I [K 3n̡}D^ {Sfp T[tZEgVZݜ{PmDa|E,kg7H8kZ:6=Ϯ×-kNUzf[U~^Wcb=^}N`3J5%/YEbp*j\KA ,DEͮW:P ܽNy]|iLA5^b0+q\*slD<%2toA?Ҵ|k]ZWcQ=qJilռ鑻]V+/ܞFEONQ=cl6  _9s@1D4xe\Duѕw(}=U~G~PgWjs˃^LҚqwL|15sv"ndە]?]~)QI @i(}H~|*D3;¥ED;&`nHiK(g( *{T"y\fq  :4Fa%H+?icQI MKNb7gSof5=qPSF99¸>V Td'YDOw o@sZ&}A {VLC!O:Ґ7//'[Tz33k꽞9ﻄYgMJaun.|f׍y'.)B]Glkeo}ŷF-KVcf`lYM4o*7_s#|,|!cg[y**%y$Ӂ\~1oS|:HՎ<`Vيd#hVe$$fdAA E-DΡ_̶tF+RXB 40f Ra[2a G#e>T6e,<}Dڅn(Oܕ~Z_OS1H}v ;ALpfZo.5 $Pk kpoCąT^O<,sk|rr!’uAÊ!}C&``0lx:@p%Od'Jȅ;W6.t_ccVXg'cdݜ@D"\vH.="}0hI/ql؆jn<{}ft@:AH%m q#z"ZGc;DQ!8#2wKOu0>8 t1%#',*x/Ĺj04Yp*E7`EDioog3./C6 /W+Xa? `Z^2_(w!I*li㗬l.h͗ =Z)O>sx=!]:Eg_cIUJ,. 1Dz T>e]jЄVmj#Ha>Gce$/dyג:Ǩx{z`^6We-)ڽ܆%Mj*E_(-e&Z}m:qD yp8{P@0'k}cF%bw<)aF;D Fx)OL$Y0y3 p{\:[V^g }'ȬH]`n' @/ Cf=|86WLטuNߠaiښD38%ʽaov_?c$N%bQXGInWcFK:aZ՚ozM i#[MwwHũlG:ڙN0鍴/,0ox4QUj7Gy|;VZ \"ߘh%!oAf/ow%ԐT`"dd<$Z~g&R!ή:4D>TW:,RpDr]rY{=Xa/,Me^?WFipe|]Pp(Kʗ a6nlnMǛ(  g4Mo[1w\9udd^w25Pl?[d&1k@S[.KLPk9 G8?mQ@ŕʭ|]OdDnJ[byu^wW:0gvR ~GpmkDֆqXkETJH{rl1 U`Zlؒ@XmXMs/r:WMӋ 񴊑lsq JۋS~a0k 0R"*>pސ] "1 5N81vM63MLZ5< ;֨:;JPUH1\hc;a+ sN*3ߵ iR8+,G O iGG &r<(6^ 6UbIpͽEw }'I݉+}!Ctѱ&mnҤ\a}'VvD1}Tm6!WRhڭԍT|ʷyx/5R%O7Ǝ ` "|yT3^~,mV r[/\.٦%pn)u2k"xjydd}$ӻ,Qͧwa$*CGRBIPCrҮT 6[c3TKyW!ӘZ) gԺZx欜]ui,Ǫm&Rbn6r yK:ĕ! EAMF hvԈ-^L|EV]|}޺ uQ{E o"GL/+lCn -leF.dhYjJV̵ÐX߭"Zήqꘕ#<>PmL 7YDǛ:)lA-|w3}x!J{G/tX S: n@ z2L2&=?W뇍7hzf?_.#{ݳ(K3 ^keNG){,^}8˅;` \7$Q,R{ui.4p } oÒ6.EpA aBA~=.,',p|WgUbzD`i5cB =ø/\ j._-s,9hHxC*g!W.',ѕE=bBX0S02 q ޮJ/#l~4A|֐gH!)O|Ϝx9bݻVjJc~7.gr ;wG$iq{<,64Ä4:ˬ,X;^rq$Hhb6@I1Ww(<(ܻke_9|FT J|2"IrZWwz1+v:>N=2hC"^[0É&b~T'=Vi5%NqoKtIҋJZR}TK{2:XЭ؝+g~O2~} {c<[6/V4ȆmG|k~%ۂK9P5X_ݑ7"/F^-0G) ~_${HsoIVE ZyMu{M(DͧM C-(FW0zv|\!O'5xAƵx`$.ٓu{c_RL->9)ÆC+˹Gy6" VBu9?ܜ9AL6ȾOrBb2gUAEc LσN}κˌ ֜U't^ :>p6ƀ pIvlϚыxT៙ftG˜Xt}p~Z{6`CN WC(ol]:fyܜ L >XM0RIg>$7C-翏uvHMvogbty@saQR-òS 0"Vs hX@o>X>֎.`AUIJ 8 }/C&Xb~ig,`զVP<}#EAp)AE"1~gbEQum{M*CQo&R-us&e)V^l4F tWSF@~dRԷ\3NR 1.l,JǠ  $׋ JRVW[lFXYK.X_F+fm48Jc <@S/Ƀ_N܌3A T/]/2mmM/ ݰٺ@ĀNZө7՜šCG+~%BÕ+f2;FJf.ۗ$Q!:!lLqlE" gek(' \t 1DҜKhb.SxdpxjO-4}DF__fޡI?d@94m,}SM1Zg3XkTR̡La[_f1 U-B+o1É_ipX!xB'bTǕgϥ:C]',oX{ ~ %ќ<ppIO2͜oH9.7FǝEK܉r C\Q?ӝBΘ^?rY|ď5 !RgG0~t !Nj=~ l!lJ2Id!G^dSk;R"j~>&A}sQc!{+bzFZ4? GWD)f{}yTzlr8 A_i7'l@#t ī 6miKn! DB;!s%cs\% ^'BmRb*Hq;JK< U'T8sfk9`ޅ &*S@ChtìU& DAS48ޠ,<To\Y&V-{-;o 8s ZP(Շ0fNxəN_.SE6E(F'3c [D*fkeT,-Fpƀ| =lH+ j?pn~ncS$fg↋bG\u8}U6pԙLD~6wܳD\yT Fҋ$A扵]& -٠H QzK, @Ifiz^ /L5> +fܠy*j3t_׵O y;i,E1\Nh^^zGњTC+c!gEfkTf TY1%ZrI6ǁˋN[Ou:= K⩋/v%eBIZ߅-: ຂC*8[߯ueWbyD&r'hEDĭT`^Bq2.h#1MW>:#;>SM+ܛ4 NQo[HؒӲ0LoyyX?}ra`ޙaq=n8j S @BuAxQ|lywW9er)nU`%==w$f*k6SweRm֯H,Tzd/ŭZ= y[ ŨUmB g8hjIBfYwنqQe7ln %۝7Wh~Q-JP|`s'8"&Pb["lquJ>6A&B]IsSߊ/Ӟ2D#C#DB fa‘G:+鮾@Bpoqеӷ p =s\d96I^^jdh0>4 h媍[f }ix>RT^dubxJCj2>MfSM^=TX4X oDڃoULA2 k^ &s b0;Kp()/˒h_۬hy5eL۶GDnERX6ڴA:]XZ&Q; \Q8 y*H! aSxI#q>$(z}!yQ &={-9 aӗrI nNjnD'@f!X+K(XяgQPPZ};Ib wg!qO<̈$ )I!?_]'JQvD@L!.[wc:5(\CvWt\ZɎ]H) $j(@hK1V{G la&*%aHY+ M+b@7RNceh%R {kyT\\uv:YBv[YX{J~QH Ru^e6usZ`㓟-PгK+N~ @ c娻H^{)=U#Lx[pB׺plA@yklv* L X E~?:aŷ4h2En^n#C~He=%4;6Y $k6~B:y/9žB-PTnj߫~Җ7yQK~&G |\}8*r?<8֔e<ǽT/'vȕM gU>1AfЖR9qxu:}+c1|𚥤I4Q=h2\˷h-*QS#Aڑ/P4/yVAo MRT0!?*Ip&QLp_L̝SZyď6g}*66(*U95O%n/JMšmo3Re~An"Vpw)E 1Ing 9Bʡ, 7}-pbXxp'"qn|-Zn-Aܖ"IyH|)NqU l8G/ƿY nO %':bQ%"I$ nEAYbTV$3-#->@ަ٢C7V4L1Jf[N+pF$Tw5u81Qp2&Ƶ _d/$BnJJ+Ah ? Q0ЄmUiwdDb=4T/N f&/ly{ V&`i]WÃTSJK->=P_?mvdKlgM,ZX`41o5ӑDuT9dF gsĜpk,J*_ UV(y3/~*pg hk:XR,.z]sc&g# B*A6?U+߲RsRv>!\kxwFv!?j:kmsDs&GKQ%. '2"~$| !biY"UYqc,U ~܅kJ@\Nqix5 F~1SO#cOkIXһӀ®8A#kG8<`EH&릒F!%JL]o DiT]d1m } k>?nC~Vt3]ӵjwc<Juoyrx<_ >F61!Ĥ62 5kq˛,՞_o8UKO"A " R}VRO¶VDZf&-[yXjcQNdJv w!s䐵;(vcah9U{7Z}nWe̱5;[uIƄWWq}׹?O;w8ȇ f20fGIѸ`%K?^YK4zFxI*^:)C;'B˫s9Km0!1͉~E9R4;DbyoLcP*Rt)8wxqͿIε~e=SQ#"l<"~׈ Χv\@~Y\O#?`-zxq REeQ}Kxu}oZM!- [Ept"+RgG&[6q$y#M?OSW-n"D 0-1PGME`+A|IsbΞi0$/zhk[1Zs"Uϓ1bώv-|>RU/ُʎR&8p3aX)>"m]#ܤWiWn\B˼Gai bM6L$G~ȔHU}I!W-\7Ʉ[}'Ղn`:"+c ~|G~/]Y<50O_$rIvMo=0>J+ (דw^zY8&c(7qdpa6vݳ<ݵj)gx(3|s7@ø*\ _ W>>ŘǎB`R`~%&V= Ϟ'ŀ=M: 2[A3kb$=~ _Lj[ޑ?.BɛԫI'ԡ@/O[R0.|#_QքXЋ!\Qx+HʧڱF_ ֫ NXÜ9JkD%x SJK""(F-kL"<ՖC3vp&H$'$RUůmS0÷x\p$2- Y/b3jtP'Iy!|ܛ.BB0GeDxhGRf *:.益,+h)J#I@Sx/xʆfn(x~VU^Xr)jNˀ[nAFآճVF.ECRNhdʽrǑßtM[C (Srt)$bٕgɽ6fqMnzuNatNBo:)'eJTB?^l#] Hn㈑⎎ PEky n&\<v31I\[ni#Am5xgcTcW۶ab$v#3c]$ 00tȟMfCϧ@tъ$`G|ԇnR` ܻ|t:?O[ Ȏ0 Zjs:=@]DJehXwu{ 6q*qjT&rn-0,4]Mugʸi/}9%;n{u)v3(oH'7q Ok֐ri&BonHܽ՜BFS(DZt"cc70}rpnsWʜƿ `~k9g0$$sDV&C$x+nxzlhʣZ{(xϓURaa),ypjʊ!qDE4]hz8ٓ\**"m6H\V5T5Y|RJ|BLf,Xڼΐ.1\Ie#e")#9҉NMmG)[>žYRg{YI)&I 5j_zL> G4n$Y叱"pj97;osre7_P[l1ॊ(.No =q5X4N=?OA veψY*):οZp7k3ehJ, DbtU+SA$8 e7GGˇ!7_ [+iCXGaT"UH FlnDh/!Uf̓I:@&RB9fMPlj4yyc/k-d4U"#sITݓ.>ǒIjїTEЩ/IX.Dg&iO cq lq`onA5V bX\c%^˃][s+RqaߊKp0+mtg dݟ z[x#d2(gRV+a62kq|bs8GF.mX9NMMx},)/ZE0h/4}-W$ ?\xNSJ{#e;yN`0qXMlI.^g}5]z6Z-Lu*R&SeB",H&ǫcbKlL*Orj sW Ytϩh&^oF6g݈FZ&݅[/5&B_wm|{q DCR;3OyՈ=Pżq u^'W$/0.}n {v2I w *G (% L/%.%c23i=k&e|?Iu>>(]->Y[Hn64PK[#C^QچrDz6*az+:6:Y .ѳ[შÒO?A5ʣI; z;X)Mw-r,o4 A6+LzmS_O#Kƞ+clʔڊ_מNﵶ~?2_m>3໱OZ*-|83? 4r⩽e7Ԏz[$DS-3(*V 9 F?bfޏec )ZyK)<^j43P\ў5 m^$C6>l)`7t"NB*,̷fާT: =wo-!&W„Ԡp vsJK|h AvВNa/jS/2!|<`wnMo3t1zw7օLW]&s[CA*N<ူXDCztGK7OM Go+ʿqʾ-űG^Se_qGrCy>5`m.uˬFnI@^(0(Q:d D>p\'h:i $L✱Bwޗ)㺨=y BcC4`ߟ*?LEk$xy:oYU?52̆82}:*Q.=] c,bycR/y.PkGXzT U"V/m\UVQaRK_GFmm{gF:jŒ!ʕuJzxcÛ/6:k673(L;6%CtJ9l_tSڼA A5N1b"6db.stIVocN)h>rJ|t@ևp`yޝ=`!*gyL'x]C*B=ӄ}m2q!1)i ė'%1~CS 1Z77bs|'JM_{fYa2M헳' J.c Tj]~rIXqF` oǭ꜉%ȱT6iɅjUohYLz?$6,*N ϶GSޣ` "hk;] J˔ٴb{ee|/ qeYM(~z"' gnܧ^zIJ9oMխ&HGήlm鑢I'4VC3y [y5x]ԟ_ JܻՀ Lxۡ&?22lX2Ũ:Bi WQ㝴׊cv|쁄ALQ?WWXej9x)'5Vy'TR5 Vpk,ҡ#Zp̣!0ϠEFv̎bhyG눒XsBZ>D>Z@GHAJfl(ͳ!L2DW2D,J*}0v 2e-(G[n\I[]\ g%f7JAVsBt-H|GiGW %*3yt] OF?Y\e3JL̽e|FZtKZEqc^r}^+vxma-iwIYnchL9ʝ)ɳbu`$a WA0Qa^$u-ya+usTY &DBvghHw݂p,'.i_99M90S{~<CWh߰/Y8x\xrs2mzQ2hUCicFHҞ?~@:c=gS)(+w$SZ+"w;Cb'LeW\"׃1y2Ǚ6f^ò6tqtHeoVlJ5RjiR_?5|?1zO~fP{dz B%bjX mh<?i^)ouTi&=Ljyk0neAaK}tI``=+<3"3BR\ ] 6_B 4dרJ: }#eG³B@xًOez'$':Q68w'"J90g_diQ|WŽ(GܗT d"H1nf<},\r!weU9]"x!Bm:ƽ2Jo Ss;As6h9{ʁGe~+<S TF}tj AҦA2!rOBz!ro{1L__q\(2{Bόc(F8fW0:Iв-V6["2f/I ,8(Itk `_^. x/f u&Sjm*ضP~BrBF:'5/ ;A ;OkN}*plc=D@lW,+ߎ;GqZI~O EsYff߉nGBރwT88mhcM$M8"y瓱iy;|: {?NM5(- 0K̹PzF'rصuזa, ?8>sФMXC,LDK V /?Ռ+WSpŠ#xL5+Z4JpJm uֳIbWLQU6~ˁ$ScoR3M{.;fg[r-ew1 ;[VK7XL'EY,_TO g|Z"bҴX8G*"zmTCpe'}j0u΃ /7pk 2\{f6 MìF}Bzt_Z=[(jrZ;uɽD$hFe}U@7].myn_{qYU_+mO`"7Ue/3~fcX1LNunE w-n5\^wֈT7 ҷd$`_wd=b_bBrX"|`Mpf0 nN4C᧷^|"jNl2m~ɰptL h>G1e:{G]';{%boX&П=2*rw*z4ޝ3Ht.fQM=ū!<^5M91*f +Qӈ Q|}r01< O02["Дaevw<ݐ%k}",}7[/ΛWM JU'eh&!RYsD<\9'%6G,Ѳv}%L=Qz}}$z^c+fxș'ʢY?_~ Z@(oH:z7~U:b\#{&bPHaL7o;@KEΕ_9eb,.n4\{l[k"fpǍ-ݻOJ%ᲝCR!]8tusG=jY,Bk,7ֿ,%|}fvK8A{g쮎mjEE]~/c2nDZ&e[!]IA:ٝ38 H|?4>է*^建Q+wlD|2 :IRRۯ*[rLb\VyK?cVJvj'D0jӽt#X 0XYsWY4bڨʥStxl^۾S!}Gk:_O$]s-oi'AF!0PueA*p~akWv_T } YMwB daLd WQuR:LV~+c}u4zZ[oijI[911?)1q'v7 ~~#H]2mmͅ@wa^h#_8NܠJ39 a>hߜ3.X\eB&§gOb^̥Ǩ4tMWFQDJa1Rr1ޝcX IhͻJ޹8p4}Ժ_wse+oī\!&Wo##}EAݼOLIE^I(iyLDx'*Ԫ dU$qvz"JLm%lt2]/>:w2i4&se`԰HRqw&W#v&l Tۆ렿Gh%l!IۖwFOi4%1T+\GHX'a=˖\J# ?؜3[kFf4eq"[oL~2VJd4愩 OW.C, ǯʯђw9ڢ3r͹3*Z+,'Yd#OhˑG~g3fW8d;&S`ٛ>,u{h :ZXuĸZj-TjnΪ?Lguʹu]`>df 7& Qzf^\|.\v3˶O%KO^LOIəY/gʴQh򌔛wv 6yZ"P7F 7 swaplY/GDn!PLO+n0} Ch|Sb'pguI Z*&أ#׆!&C^F*Hnr,{C.uPG15|2*B12W\DͼZY=fz 0$dbcKTM±AyTXR:PA{XڠB2w{j?Ż TTKhR݀J;Ӭ~t w[0պBqTe)ݶd}SwYCǖ9FN Lq=y6ZVInhyx!lZWA7dK9z+ apˍ"(f]OFȜ />4r7]UGtD'4ybr"nTHȄ]{\¨jL[2Uf!Ġ a>kwӛ?~CNTr#5iT,~lNӽI8z p0l{Uv5Dߴ+슨J"3#svX$4~{4Xgk9B9)یb}h` AE}S1}4DQZ_ÃF\Ov1{#FK}k`: 47 v6NO:o=}V@W^jR zGh,&E%,.3fP! C"gqhK6DÙd3:A n~+H$fԝY-j1}UXow0\HA Q OÓ& ģ0j4P#!Z "n`#ĩ+.9J)6N:Ka"J*@8N,lV\sEm>3ٖ^#r}}(.NnlrR@5Gsrˋ(ܦ(E%QN{zqB"zi"U]m6;@6`0[Ɓg%䝝W)a-++BU/qcTLg7Y4- B2ۇf8 Xr&Ǔn޻] b{)^cT e2.g hY" ]cuDN9ͨP>ٲ `> yt n)ɤ:+;f7$gLKl&$=oGA,;p lceU+*m4h` Y^qwFc74VUD"EEAzMkmBFXoߚbG2ΥfnP}g*݅dI7Α`+g^Ba+qvm)VzC,L˷h $\jͥ+σ4y>Ӑ_J~/=ӓzh]#S`2j:څsn|T: R{f=Y5}Ɨ = iM駥"TsJTEj;tst>8-WwyeMH0kuLlu׿-o~ղ ķnorl9hr &DbK^Jt=aQ<@ $ᯏ["0;UMVcvHy;}boܔ?Юux^hT+~uyf&:yq~TأEs톚7cV=ʐI9g.Z jށ|ݩP60ܖSͽXviJ6P^s,:CQ3 Uj0P.' /M㈍:TKFP.JUPg>I]CwԱH_7H숲l%h\+^%沉DL*}cDӀIػDu36\1mmRLUm4 DD 3%*ڒRF&?-.Cd]Q?D bK"@2{EH4KTe`|k9A[K[3 Ԉm\IL~QƧ YcTPFpD@_~_+aA+I7b.r%2cF;4#كuU%ՠFOtwu"uabKGJƤC_x>aǰ'['T?]qM=_@``_3"'C]c\Kqs2xY/ 3tRvG(1Hpd!ctlHԅ̽G'1\[{j q1yhHu/q5O9Atܵ\w /v\Ba*: MYo7(,BMo.(vK6xJB6t0|,a-d33%̸#:(JMDAFEęt7XQg}upùMіݲ-IZڰ+Y@iXOe WQI2r;F+!ЬB$*pya*N0fvbiv8@:ʈb׈; aKyFez_T/:E[.Z ShP8 .{k:y AνrځǢ=ȣ}\)&b>Rj+d31zC cc ɶ ԝKx}2'V|/H;duB#x̕'̞ \#%uᇃ<|]3z-"*ۦaEP>yxm+c9sTm b<"OԬ; hGZuT:$sĽ9&n>߁14dtR8L:E|G~R`d;]Pb4H>VxEK;WA}m?sP]8XvY~$Hw*ї:~d}n,d'>),ˬ7m* `!leȔ5iI&a h/xC$bsȊWc; )E 14p**/@_GMnCn \!6*>\4lZ3~T#ڒ@;|{=?ij}q:{r1rR 4.5ir^^(6N.:}!@ AMn1VDD-`q:,Ôը϶ *}Bosд7 OzVϻũ^b~!oK5vbd2#5GSK(8KM2.ArBo8| fa)&b- ^ݒJ% 3Zg$j*S S79.ce w^RƗ~a4~*v%U]\i3N4!45䦮+WrU4?\u%+bsirQ%x!}hqL j$X*0χPQYO>;H#P5fg[D 37@,;rX`U˻KHþ7XiwF{;Gg4T.ĕJ[#Gf>ղQwM6rpʩBĦ.&euh0j\B5' epch5s#.&su c >zve;jtT#n H;4r1S塅(JM>T?lW(xs/n`H?=:-^u*ҕ|A ) 1i,70q i'=U9WJCclȓ$0粥EBvaV-C`_(߂D4G)ڞۜ05hޡގBT 98XRi9rYq>1B&=2 zEaqh;K|k 4uL͈ #]E7ٝR+D\ M(zBucA2elKb*WGӯaMtEJ|MK )#"ߎNe 5ͧ|h*?$rZ.mU }b{ e08o޸o%D&2pz'Y7j'\7_ yp2)w9hDq1 ԕC{ NrH43={NίȜETX(n9RHov^]'){O6`j Jy#6ktb#l< v8{匞^$ilA \:{>Žxc$#` ſZ,l\K[plO`&<S)9>\~hee&$cr;k(iy5>cB671YwQUF-Ikc#fV"K-} ƄFݷ{r{lD<3\r)ÍJv~ZKh,TܯeJkk =fIwzهuHfa hWߐtqr,$Y?::=C_wXgDNObd)c6F;voHfIM*ND@̼3w/2jTYU#Vw|}{d`(V@D36HFb 4 - DnY5o:V5]Ccΐ(iɛCvSң ӕfru_T{@EWy{\ $1uϙ hbCena6>  B}69*Yrו-snvxwȫ}@s*$݇ /W!SK_ӯ& lQeo|oXg\̜ڐ#%*??® sjgYFr6WD򨄄Bk* .f̳'ḽ+?Ɖ|յfn" <,2Gd`# V&J&I?jI?)x?,'{޿Dↇ@JX`Kp̞2%*N.*p⭾s#Ƒ$IC!FOEIl#pa=RR?’-T?;O ȎbcstP>LAhd%Rv4dp蟿KPpd}vm#!?Y#i#VݤLW晘po?[wR"a{ _H,ڶكHy_;q9jΎ&ժ"{}.9nL jƱL6$-|+_.ï?zMtր}jkM:evD?dm[_&QP󒩬?˂q5(|66u*_,i y8)$aNC@tro8[.3әMޤ˧k%~DofӋ6Vd ԠQn{y$Ap,ēGru7.=}JJ˨"ԷZSo `4FFrHO.|0u0`X+a' A~(u?<~W_&Nb!>Js˾ |wJ5B'pɇYvM5Sճ2JRK yB)Ce6!uKI-A5⨢Wyר ⏅L꾓î,KDȷncsg2+=:v&Dŷd*V |rL+&^ri\uO@y"Pwy 潚pm"ո;"eJܕ,t0ӛ4Jjdop{Mqkʍ د:Vfu~dR{  dئnUrCρN/1o!vkK/{{V 2sVXW"጑[{zykyvo:L#{ h{?)N[ Fk S֒յ䩕 #=),*qd:88܏Y37qB+RڑCX)4$a0k=qNbF?;.]ִT~%p7_Nh΄ 8u ںAh\pSoH}8!5P9W( 64pT>->gwcʜ{]0C ,B^W ۤ]1Yѵ ˙n\w2_~`<gM%NH8 RЖ5~0_RPUNnP5PF "[9c'vfoE.Qut̨N Ֆ`1!m8SU)ZS' d-M.*XۨOKcj׀4ɊX5w;攉!<gPKSM`-UñibNOD$P!zXDm0^mgVs"[ }̢e۴+ `k@oᛅ͈*;g ,?^pTA9t2mgs-!"Nqf&ʹO s8Nﰷ0"|j*gjD*_MrBQ_hy聁v6u2pꛪ7Pl(%fBV( F t{Ϩ]mt*e7é bSf &{в)=lL <|RPblg+.A~qq§d28?h6H{`w6DI];A#:i'ī{ 0!R.&R/xI1QO"*&e\&eZofס])^/7q 7IHwCݛ J w)d #v.w?&,ӉMR~.ZX+ˉG=%c EŋEsjKrLKgɘCDwTZQۓPZFYd yE+W1u&UJi/w\VGC#>ǿ"pщ"vkTR:s|>xCObK@j7Ve BޠeDO׺v7 bdbVrYO#'-'Pwل4:د9MN-;V~<NwsxM>wPG-{rCfRk$6ʃ`jBљZ [E" =k-kW1jX2:F*%?lr1*ZW8wЧُXbLEZ\haWBZ+=uVܳiCZ|KF|}mo B^XV hswd=5) X Ԙ |`8lnIw\1ðKӳЎf"A(#NY-[z=X7uS-Rر8#NFZ z7QGOn{'%u-`l2YIiUAa W9K8 *U!a`7NmjJ c R(|VܘBrVܴ ,woы䮒gsi'o}3 &`r|rP|6?7`AtX Ґp믡4fǎŮ.nXpX?dR'c5'&yusnou& xO(=kT6[Z=ߖ"t|kMlG{~.S/@E;;2]qzZ7"J R+]wi8Mlcb 㻗U¬][\U eqM4379m+/v2|>Ɍң?llZGSwWD*.Y!9*xoV /P Jw݉ؓI˝ 6.d"O%xYr, L0A>}-L"țd[:JWO=}FOq|X (_W'Ƶ;^[ތ'.b#̠u+ wi3ĒY*{&v91)(7"^@k&n '9E!\;wA]obNl /PAWvBeU(zgžE&3 MJh.ohX 7oPޟiuObGI.%YdKf9)`ץj.Z$uhr5M9pa1ghΏ8Cl%:2ylbALch$Zl7Rjv39:/ЌLU?!d2 Jv#VJ`#Z⢬"w-IOe K:Q Q ߫^]ol\4='ɧ70 l O s6HxH0@ G_ n/y=(,v{!n"PeF-)Ʃd ?G(j/_i#2Hy?O* ̪"Bi`t1P5eɯUW~7}PVP0H=_Oi ʁл/?I#,#Fz=SWTՊ Ŷxͺ }xhX#*jJqFa^yCe H[˧R[O;CRr$g^ cJ[ JCsuw"tBRy'(O=1b XHV-X傹R~N$ Qj5lHzQ/{1mX8>cI 5,"בNY%nnw ^yo4O7VAa!KЈ!5hi/9 + EDy~D ڏgŜI1c@i-ҸV<Q\W/oZH$3&@Ӓ{r6QJ'i{)}뽾0"W]ʸ}GS)I_{)jpb9ȸ U#.΋ 0ȔD~B۸`(F\&H㑄\h9K =鷦%J/"x@+-5܉Ĺx֔b޵Q R2QݽrGAA?.t>p0Dؽ]r{t{}6 /-; gRFBo !KÛTFCZ |m\کRAdeNW Wfnf>!q^Qzc\4 OZ e>zhت?t$:*M 3%yzz g=GOKqbėnh2,{Iuی_I pBVHx= oRfvB\1$BrK"PjH%\)W鎡x"x Z)xig9q^hS\~0@]re:j H= $+ՕP3$ $ \q}aQw1$?xr@CQ6洱vjԄOL~ݩѲrIݾ{0SbsdzD79  D^k7ZaOg"jn|Wb5WίߌEG-;ZRC4v ;}U܏>pGlqrWw }A!GynѾT^:k =.V_hGVB@+,@|Þ R"Vc}oDza \ozĚF D~^'pK#j9h [KO d;$c-pEΠLޟ'P}n*7Rݚ%ɯ}/)ri=8n]b2J^;|K+ޔt,%jGA#`'Iފ*mqC;Er[*A=e09N_*Wۺ?Su9DXKHTH|Ǎ"i:nxgDdAvHӨ:AO=v +9V!M˝|N; G?m Uy͵]8$i^B MfGA8c,C Z@ pnU*)ӊo2/3bN7I NR^w},ܱ6=N2t|CioX\!ܹPi[&7Sd׫QB 4U*P^fՎ(Gsw69I!K TuYKƋ㙕Om~&YP9 dQW MȂ/s71$*$&#gB69{Һ`NiyGMyBW)rϲnZGBF$48a,g]nA+M /:*71M41'o3wL[́ar d{Fh.ᕦt }>r\VMҬaf^ڢ/;'+P߾HÿћH.‰t\~0"f0ڵ 苒[sҦKBi{||ܮ3k_ =@zli{/kq#vN>SL 5bs<[I6 pwp>(cZD {mւ:HAo); nib?p- 9l sff)s|9"x5`z KrxB  4oO*HZ쓎`XQ|gmŒZ$jGEMṕVfBj>0ز`S&Tt-FIScS1 PԎcZ2wMOm{Yp5w2e53SRP]q.^<X ,a9Hi&T˜M+~@sGŊr1hRHkH\ڎ AfQ[f5$2b&iY;OM֥Y?iICS?à;8*d؉RsZlcVD=',H*Ws3l࿇ v{;AZ0lд<e]T3-偱V7 T:ugGO+wzBwn .U\qنeqsVF7/Ͻwxe.%';]%RuXP>U{-?)tpU5a +<2E9=ؖW`O4X!/`'> _.*W7KsQ€1x_g"ʕvz76g6v74\dI_EX! j´SqA5ibsl=z#-K62-FL?PJg˛ꈐYwȭakbM I|&6^FSB:V}ؙ% -/Pz"$Z29crHH,+Kv"}14G'c^"mЄՎ3e 0b [͟1{si $<c<{ɗO@) @F`xv=1G զWO4B׬zzqO9EUC3ݵ!M}hL?p9k߉ U*b7K>nu ,}7G yT;=PXz=[#2`k ^$l#[8ßHD /"1.La57טhۜ- u7{n p;c }6)%KӗtCInyF;?r(OS+;P59L6"6,)SD*0HLgB2A@)լ`윹'N)VėS_\%dƗˬfD>c p`M n3KœH7.hb|Ũj H_ .;z=oN%h}HEqM7>w`[{x_4qE(sQ4<`@ C6-0_hrIHw1!6Z7&:kc x-`|<~_k{7T -K@!?]їumdzL*'R#5sX4D6,X۬yX V( a yP3 2d4se̓onwK;6RrK)t՘䨔f+!;46Djml7* (U -m$'m$vؕokN_"m=(`sX!BGCLzm%IOK¸CcZ-`#D(e_ ѭJB>wY`KnSP\SrmGAr}WLpQn~#üb(3Iy8םU~eҢ ،~:#2Qف)ȭ?m;vq㮁X Ocx"l^ /BM V ~qvbF&= ^}&Ƴ)M (Cu&t_MR;Yp..v螌: C,cghj3trQ6$R*0~rc Pqm^Rd>?aT ʲ=M!'oxHy;_왅_EuWz\kZ<~,;5~fem*yF_T,0$ۄ)>O+Vk [t$Ϧomƴc۫σ qlEtCp xPKzBpr(J 0ج봋엮 h-Rl?xA*uFHG Ƅ C,ůP€FĄ2.FP' AsJ]*3$-$`׀ڏޫ.rPP`Ψ'*@D.t~X|Oc"N4lV2q1 {oG8ݗ41YdޘdvVڎ|TGG ._+k֕U$D51J X n-W=,`se,<:#*w`Way6!/d ԗ\~Ɇ7˲diA;aCvh{SN?XӖiZwG9&Br68EH\"2-b`8Ib<*-)7ҫ>l<&^ iVG)y6Nꨚ-귳$`AABHSTѳ3c ,Uex|.RC<}hp2E% ?m0ڄ+_tXt2V-h2@PD1|k,()؏Q݊]Lq늏 SM1ר<>\Б!Gp)>ڷڿ6'=4Jl곥+h?6?S;G%gʭ@Ut9bÇJ³٧.zߏ 43{oy|NT3V\%{h!{4=m}xmuN8.Ɩ(vU}-HݪB++xNAR=ԷYOȹ>ki`oUt^ɘ30Sy;(@y 4>y-xF#G!INy O`0%z+|4BHƖ9hF:pZ2AҽyXZ*sKK a[+?11oi_BhLښN_lFʊi$(;3d&MOrA1LPe 9 ЀJH4Q.ul F i8kg+ITYЭ aZ>ц1pym  4ByVYvn&_8Wo!IؔI蛌'έdKF} CYs^iߐ&ӋQΐB1sqfͨXhmIҕ߾yaVS%6 bR˅St*:]b Jk:}oSantRn)GpZ|MJy俉A vr}7KYf"D3&P˾8;g{:0M0 ld!!TQ,٢="b[5l8$z't撗v|(*aG?Ѧhbt^wAYӱ8@[١5 /űjD;KjKY# \{<1^.fJ-/|C8 y`?^+ך=dě)Yi&:Ȑ/:j"\@f%@թ8 ƱFܞ=)1BcȖt4[qqo;ЃuY)˄($/!Z0XV:#dG3Bݐ*9Gҽz9 ՒJy4bKȵ 2ƇAnU7*&g7CzqCgʏ |J [ﴻx)HdD'wR6ngC3MYxQVBq8J-kLyu ]K;RŊ)R΂"7G/nکNcrk:)hP8qWU{̽yƚ&]odAnު<U zɽs=G{.>4'ዶV[q=E/9eUBEM͡K+@1Sg+,H@ KKxCY1ᚗ9"{)uQ/ϸ(81FKzG3J_)E‰dЬB8Bٺ;Bmsh`a+Qڈۤ!u [0ۃx:,@醑 V }+h!UHMJq3:ag7xCE]V;8įV,uL>("SK 5 6Pi)n^=OMz}u`3;28qqU^qqSp-xɲꄌo<ϷY#a^[U,ByW+֯AՍ}/>u*>J Բˬ-6>(n4JCcHێ=Ÿgw0xIkL$3YA (tT]v /xwuβ4N g wghӤT(HԧٛTΙĎ֭FfQba k>Co侕٩XaÜ|FiT2k搀2/:RĔ1Ou3 }{ɘ +k##N%2)Z3"xW/39xt#f ;|L1Al'h-KXH"ڔ*_~v\lqPRcbb+^c2D%!(MCOoS,l\ݾюpTzϗ%qaupKJ~^{c]b}DGgy˔4=g˜5[g"MfhYvlE`R%&G%tt;6ݰAw^o ”SښIgM5+Eo`jrj|iNυ:Ov)L?+~1!;ޡ5|zM [$%hO 0{z۰D&r.祱Nux#;F>}db%rvT`f)7o_ŴJ̱`J&owUg9)xH^W, g͌:db(IS5ٿ~YxC 9BkO߂7=un= ipWOEO6ܚ{d3jiHOTpɅ|k|h(:aL#UwtKn>fzX]Kj}\t(&J SiPL}9lF WjS/"Hs^@̀ދ(&>Sr=uWp{톏M.أ>osxf{{:'y $200# oڈp= '])Y{{H7l; *4FBn:HR x,\ʩ&i9*Eu}i4F\[h=).sWT% z~^MTŗڧ5'̚da6C@SUVogE{y2Wb[> ?s`yya4SAtMMYU~^%n|Xt5r Wݍ֜S^Ѓ4WTpT|4곒E%h+l_Z.jDBmlY! 79Ϗ\] g56"͠YMR% B*n)%aҡ澹* ˻Z#q611ld:-zkP ri,|VޟC)U3@E/KSŽ#VUQ5 'k+9U>i3) ɛ_F.dzJ6i.Im{i ߿.5_!<=H>Lۢ]0jO@ƏnLg.r7w":^fiEOW.=a!r_r|3y-,sY'\J`MN6˻?UhʸPaY*-wȔnG"~".ICOock/d ?q k&zmik$Mrō P+vWb0ҫY v(k^+mcbYib@5@lI-hl+=ŵ-KΊE@/!;"otBvϟd(C5~3v Ń4KX1yy'Zuk8;E&YFŃU&ӓ+oNIIjqX7ƞBٗ6ZhafZ8^1m';ѯWR7F=e.W|z̮%*FKcyIHxФavkѫ9Ӥ1J:@lXtTQDzh5M-6 [Ȅ'4(u[Bu:i}XK=N#Ԝ󟵓I)GV=aeE*>E QI@lFKƋG]U~t㞪*& ByY㡤c`':oŀ[ǕF~e/>ݸg-O-'OE4^p:#*Fۗ/gpo"K 1. \z\M ws{Uy И:sWv7M+??y~; @[fn-wg1gf}Z^nئCrJt"O/_2aFp0V7%GW%B`-?Eݛ4r7UZQ4F2dllը45 N~KR]l1Q!0AI&'&;"6-nѢ F [1/5Pxu}OQD41M 橈\rC|n qAȢG?KPȟt2#h97 kAXT/9 N.4q_t~OeƮ#LaXݢz_Dv-6 KRqɈͤkI+*kLv̼SrG#]Zݣ W{,I{~x{?yPI+5p9SDixC/,JToM7_Z}Oh2Kf:II5d;+s0#\g9IozKoxFndHT`r,!JZ _Mv}U .8|$oLɺjf;!,mRbr-n i >W@ACL5XEY{w.!*.QRr^ 0% C!?RP6+YA9bÔÿQSE8>وaaQ3mU- ="#OqoiC#mrU4Det6iQ%=;h+9p}-Mz.~sԈ7Z]N:W6 p^!#!7cfu운l*%hAgP`LswJU@3;C>2M"vs9'g=! yJ|_Ztqf|1/JP~QPJh;B6kaRTOD)Fdm"9їy !RIAPў"[@ji5ShJ 9/-{Lr,ac#GlWX, ۨrA$܅g!ku:M.ɠQj=3RGr*-Fy] 4(<~q} T̂򴍚"By;*ZXot?ū'N*̺Í9y65y99c{V+wWA6f~|,Yj v2Lf]͸230\u緩ܲ`A ȷIe^,=|/ xx쫬ܶ^J;+4g@% +l'xX:vVRSd"XB!4}%]Q?56^T5l^N`ډ_ Xd!aU6[FY>%S;&JU!PdXu7E WR{ W̢I2+C`-c>EsQ$8b-~xV<ܯқE쉁c6~ף ʓ/K?~aNWZ9A4`r91jN[|~֝ 3WATxl"Pw[m?{dGt);Z+0?ʘ%tGdvj8y$C) ^͎+`[JX;.=huƄ<>̇ޥ\E18/ח|~WYw{ȂnA~"(qp캛lVKy]ɼqQuJ>O22+&YI;&_ , ^uƎ8oc'CjA.b.m`,m}>xuz֒H%/]e8=+Ucrz>xF4nzUl'6Tb!kDTB8 0>H"D~j8EV@DC6ZU&Bg~}惰:ek⯤=cA|c`.7%s':!&Q'͹ᘣP”^z-2#Ս{(/:?$ͮXĞح8}}-cI\çY)!E':ߔוvIW+)FT6XU~"[t1,r03`mYC#CHg&DnXa=INdCKԨݰ `t TCWūI5$p|zţ.jbZ][ hd4Fӷ ǘݤ@:c!LTJ4ǘ_e&1%\ԭ+C )$Hur/.I&N~k_Fwä<z-WV$3^1|׍v9fQ}<ߙ$<&瓶#QG~EnpQOR=vkqB?נ=[?~@N+"3R9xTV dNr޷â-*1~n^} |Q&Rښ?}wFV8-Pʲ~֥[" k.mLM 6U=ߚ+_Ҵ^U+3?G0(~7 Oг!ii5NL%9կ5|NkN.H`ow.+ɚU){}nv2όA53S) 溶7M+$Nb'esoJGNNQ(΃,ZCVtfxߦZ3z~Ӫ3zE8 n\yԛv{>aĎUȸ,s@⟤l4'xR,;R8(|R% 3 GYMse?hzH}sKjm_> $FNmH=bXV=aDnZ&' c._KvokD|0TCY4 X_4"]ES0Zsy=|KM6qk|6oO򁷒oB>+8 _`!C45d$~2QGƮ]= 쭏r Px>t\(p4jC|1Ylw }u8YxYo'[k!jGa Ut,Un˅0[*Uɹ^LV9e 4ߜ#$Sw--k+~Qld.ụB T.Q_Fdʷ8[H&2DC:|{!Ķ'ooN/mlwvLY]YaESt@Boޥ}52oҿQb ?kikId |lI$C>q8l[JG yRzKmb);m4#7- ц=ۇ2Ta!yjȌ C6ڵ罹=ʳ1FEwyN!~?Q`Χ0s\9҂֩|%qGħً08r<0c3Q8ְ@S %RVKԮFBIl"T+/UD.RMn"1N̅ i?≮*}mnP᧿qꅚ,G͡~hlW+(kWI>3@YIYS4բ5ȆBd-r8ѢwB2 d{^kWR2`օ!ַ`Qhlo}%B; ^l!J6s(YkcFTti+ ~)Aٚ /ATjz`^E5&`鬛J ^KCz^d#Dӟ0 .M4Jè@f!SD)r򝎉 L3Ac&ԽyBpv|"wl[3%wa0= pl ,ckl_"Vrܼ &~t6hYEu/Ԁ12S־|^-$d,QwK+0pl2xN'r;58\Z@.'\5E)Cg)G]~肵'QK!lĿ;< \S9N>x0A4@wC\dz{>IT3dއlb-?eF#+f۰RCrCvpC4@L66#ָ/"v۲0}ﷱF;96>2K/ꌷ4I#W a0J1QK۰qPZ{t8??cFa9r9/[`(=fX-Eϭ&ؕSuvc>pF!my2DUOvQpҬBfr@jU(zwcyA3\%ybtOg=ɤ:DaB_I>h,!^!rb̨wZG'i7R6! BE*(W M ໽~!}daeg|>Ag(UB).="(c4fcai2s1Z|Ф Vzk%XińnU,/ؤ?Eob<WNnu6 dbh쯔GCB!`$Gf]L][7F>rA;xPȠpP2`鮴׷l51T/D?皓Y}lbAWrV7Nj|浵M`-v@'0kϯB_+ n0Yְ"ɴY3RL4e$,́\s(%@T:Be6c{nN\gͥ<+me2mi.#ɕe )Tw(3RC9M٣;z*rBGlYMpP3 Կ֕Z3\*#k[j m0ѵP FeWӪЏW=öKhGqGәYD{tP !;} j0>giG$H#EA G UB]PC}S%#0xWv;L]'pT]^4 :R^*{CKvmlex"~tEЊNe͕øR_x'7· j@ﻭ ;CzBT.*Pz Z׍0 7\?=MdުdG%q[N[#M&zjՏFStP9?súF{Z;aAnOg@hC^uEЍtL4Mep@?EY LZXVr٪dA5VM|ҴIXV^b>/$vƔ' < ѵB+{ILn/[e%EfM3,TL?c(؍w.s5zp)(NOU۪Y/I4R+qyߋ@Ұ4+%b,*i$-=>t x&L9# KǡxJ!@ j9NՉTݢw`j4*o.$'?`UB5L\!Ht[gA(b6@>)RӣBzB˱C0|M|^gߔ Cuf2jԕVL`Bi]K3F3nme~&6ҰoNJ[O"<| R^8wu+9C{bT^iMYqW+y.^{6XJplrWI@$i`XPJwd5hYrԽH/4؋EA D: ɴ,?ǩɠ׭ߺcz*@q E0cLfu8l TʬHE.RS1Pn }q鴰 Oiq߁ᖯ^XO7;`Gǻlod(jGHN! ~#EyukvpXod t(Рs2xSo\"mL 7a=lmf#r=Vn)L^<<>5+Z\)]#)S[,(s6$؄KKff6+ 4,n=+7x(Ā-X'Khن1^]ɲ.ԮNzv{ W+*@{˟v)Fb ʻF!I }y!o綨mjr#ΛQz.vՍ!hp 6{Pc _[A'lZ@OS*gmkDF{K[&Ӑ0׀O 0WjН{UQEmUC)v"F4%jbNzGabS7b71l 1 )Q i8⎶D<zD6#4&5B%tNIaZk W_YE̔H[l1_k7tglkʼn$F}ˆB'7I9hY:"ſ7ob/(IFEP$2rՁ H 陚YJj75*A.Bd wNzո%×j>jAWҳMIEä1fI׽H ^xmy10P6;ȱH+)l~C ,+>ZttPfsNM4(9=ѡJQb̅nVFe4[uPpNs|;#TV[)ח*DHb$9Ǒ}7j3^UrW$}}VS |Et:܂#QnJ&>b n+ծ:03Գ䭯:@"*(6Yd+M2e6l9ybJA5' ]K+:/n&FkKM?@~ Hs^a\,pʫ[~FczHw$>TژsF0 LܐmirWrO:%*֖1j+Z˂ՏvfD 'e吘E_&=S?f*R.G/BOHgљ_A}:+" Ӿu$H1Fif|`~?Nll$-Q}¤KۤR<*hx#1br|n F^FJD S/b!`KyדAXa`w_U R/xKKj׺}})j/htv6 sLO}qSJݕSl\Z QϽ.Ű8:ɗrҺ+q`uZWl+-F<5Y/s\dM(mxyRxT,Ep 'Z[R8cn<oTN&qf7 ~*Q0i?lBz >`{`XKXe\2өˁ17o~udLe),^L@~HS#xr85'{d4^$zɑZ%U w:{;$o CM+>*fU.o`F^',;baw~j*r!~Dp i\9RŴ6b(3ʪ ̶ހS,ɴsq|]w x .|PҬ.{==;!))9<], (;@b#Igb$[+$I٫ݽa]CR?;؅T<VmAg|U(CUAQuչkb@ј"Gv|Ȭɯ͉s`=ITF5]BU3u8 ?hx@òJj5O% 1{ݍ%d`Tx")#qޟKF] EsLqv8hxSBXa=#,7Tט%ֳ9lv ŧh/b<-ؘoh(h0V0`._hzǞa 7R{[~F<1˿bCB47/T\:,+i[ F/I Nk N TZKMv͐g)mnop]ӶffΜ,&j66 frJI$?]Us # G[^W96j:\`ɬy_mjjpbd@MU{ˢ)$7r(:̧p+xKlZWVN53NS“,RcAAA^phUEש$73^Y!:#jrI;f3 R;qey=BJJzd鮨kbd.NLF >ysk/앧]M К` & 0C<-1:7W9߰p۸dR!ײBlD{\dA=˘@KG۩KŪ9U"+fFwo5gU's}9k{dn4Ot/=*f`"ܙAz`Bڪ|25F&Z^0 $>So:{EdM/ fmXٜvG2ҩmO1qv&М~O_2NSs]jI{qVw idQgƼV P >.ĕ>8rK]870EH D X-08+0;C0>?1WHaj{,@ϛ'IZߒHg}qV IV>Fkqn!lH́3x"8_ϯ:K5AK.rxp嶂2sD~{y<"RCs$\6}(Ue S`@7gX!j/ǐplքDX|G4Bky kYc=e~޲]Ndj̡OLGƗs.:g֙g즸1~г'lfQݏ ⠸%dG+F}绖ϣUG뗫3βŴv*汳*%?diB0M.`chtai{R7lkJ/]*,Թ-|ΨIxpc֓,׍w9>O;b iaMe P?aKrT ΌD0we7>{]}z/ 'Ln`xީ@oS>`;'wIi:Y1yسQ6GzV7|b-Z0mkq5M$7y*j mྯy]re[rFX C>2Ԫܓ49Rs)Ƒ~+x5}GXc>X z1lpՂ#M֔5sI1Rhݲ[TvNftXV_t<~V9Ѵv3d&goiS8np8muEۖYOY|@7J*ZcQTÔJ님M6(}-akɰi;| .~յbr`6`6s`7]T _!j+W9zcibś߾VO׮bkG_6"O'ӉW6ֹ@Z禄wQ٣eII'I|+@b-Y(jaǡp:'T5#lWB;Z˴BEQ Q ^I?aFD4P΃+ic`t`Љi@s܃~ZlU4賤!ث(RЕj[Gd|hCotw!E{/qoFL{STdZ諨6ǸU r7؁)=cFY!nWvf.R*3}{6Np D0ݣȏ) !8T㕭KHXT)f]٣ TT>bJh ~VoCmc1lgׯOqPݢ7Ր~1WФRN&A+SndվŅlNQodARncs>Q ~f c紛3K OIe=d䶐_k2B5T~k~溹\jda NåDW{ ԣ`FU԰$a vPg0;e2G.V+̕\+< YnGS: ؼ;wZ,n]N`7Pv!@"MO q%l$2w[:d*'(Xogm欥Qڛ.Ӄg|yYY`^շvSyGivC &!.bF!w,6|pڡ[C9ϗGrZŔ;Ӻ$63ʣj |VSI(|UX\L<,i Qh)$<*;4#TյO')c(%RO?\A@!THpF< #lqvugz%oiRFvH*ufqY:\agִѮ2 +Gu7I7fE3T~S7 ,v/NJd`uJvIyK45(sK@<5>_|ߠ8re:웲4ϿPl}p:H?jT5C)Ϭdk~:r4bXtQia9Dϝ;NfɎî}j8t2 - wC+Hj@ a;a};cgz_o #{ePy1oɐAziW l=2.!%O<=JPQ Pmw0rLMsEf*B˕7J;~ВGUѭ`LzEN6 ;##.N:G!Oiե*aN ڶgO q@d6@d-Yrv֥9:g#O0R8V읓BŢwYrf;9jVlͭ!9̽$؄6&f&UW|)^Zѽhg!xJ4mLq(y+R@l_  ~ef GY#dKC0`5:{I7*!\dN0Pp5t^uʖb}nޗ 5蓬?I݁懀.r %ݪ3"T'&FeTy2xβ g:jQ+:JoS ~2(]4):N裝Q(e~CBEp+8IKD(cV3ܜqRA攠Xބ堄EC)L"L^7,!{X%nXj?d}dTxk? Tۻ}%Hxm(\:i!b꺡rc\HRex_m{@yToYOL:D3.0,:dEQJlKz@(W# N)DZo)>ٌ'[HYuI#xn J*v0XXj|65T򬫣uHbP@Dzs h-QNX}_\BUEL7ǜ,vɵGm̙keYN=sanrVsӊuf}~ztr%~Et1{4ےx"!QҢX0v X=5'9;\)HB?N[n/ϯemXw,\cSIڹ73kJYղRGf~Wmo9ܳ[ܢ(`a˽Vn,2TCʂ$j2@˰7m^M-O,VRV ^T; J*܏"R1ZL/Vb7^:9=}Z ngbU#R vl{b G)uA zCԆF#4ZSDQX8mlxβoP(*~8Mf O6͝WdNբ W#3Sx.69W`zxDwQib'dCi:|LC\ԛxB+.N_T~;hscS>4gDbOkMٙp.gΰ7{Wt>d&AxD.n\"18)tRP»JlpW e!;ő.s)ya4^гH̄Yz@vW;9VPH`XE6 潁g6\\G;$cPr|YY^ڤ: d|6cmof(C>" e]'&~8'@b#bhy>ܷ2XLtdUue+|`F HC bXEhЖ>{(Sn4.F9J`) 4@E<B3"u26wȩ6j a1?,aݼt( .ɗOYxk|<~!|Հ`¢v̚=T,,DkT6vn|~k 4TqzCFz֢YOv'8!D@lѽ!3%fm0_zT->[.+Ns#8?o\Kc.U) A)gt1B}ڣ8kV\6gi ՜>|N$@=fލ̉.Mq@m NW;)2& Dc:^~V%W}LZVF4dnXZ]ULiUJ9>Ʃ8U6+B0<_ e`Rp@ RfuPd9&5m虐}72՞KvQ~f^I/&H[|I@0ސfSS TsGfꑗC\/fKl@Owslz h'[>K_vgHf{${Lsa=_$'~ݷP=)Y|lI--;wtߦv Ԝ\"/I '><c JXeReosh":gםowo9/]֢Er@Pf~B me~ȏUT,a9ـf'ڇªnBe>+l.3=~RuP\ >=dMԮԒ4ewZ#3TߎL'V@_U#vBYq#::Bڄ.V-n VBd69[NoL <ڼ%i!%apYzkPB-JiAY0`-@KFʉDXt N#ҟKs eip缸I)d4A"u98 ,RE$].0]a[E~KøVďݦ>﵏0>>IlLK__N< :D9g_* p0Pm#kAiZj9NsgJFޱMWY&WH QHV_0x쯉,=cdH5\X3'.zĵ߉3sElK%:;ϢC~tN1pB]nM+J<m+!9S3[,,T*Zi'%Z8zy! =qxXWH@1z+Ʃe۳IlT҃bRŀ xFbsd|)ח[!{ \l!`z35e}$!}1x'S};YT<ٶ.jE]zD:+6jGׁ^nUrJeZs&3h)m484ky^hug]h`yZ k'Ya1  ^֏#!9jbrXEh'FsqvOq@MJ"r;wIk1'c3q+DGm7˪I'$;޲-3Z4_z,zʩsO8*]*JuC0Twa)Ԛ>d)bZMhJ1|\Z1~qI4@rm[yf9KTkH`] 8D+[X9?x释tʞA׼OH+I-7욭+ƹ7ϳLK{0cmAc2n?9f6pTnp (dAϬqJdAP~PQyz$6L rXfnzQdf`ϧ^ | K+b#`&-I7 ϱ "1)܄Wd/m">.oP]WgY˗ddܗC17d}څl%3'&욅nsl@)LYB@5 5 *!kh,:Y2Xc&~0`;)Xw1 %j+sHB Bꮡj-2s unl.#S6*o*DignlYʰf\q .^YG4tOdޯ-:9 !u%zDT8:&sq#ՉT'w\Ogtq$T6RTNms*r#T՝kK c(x[ൡ&hPJ:~N? @6-7gw!\' NZCu">8JyqsRT8\jw E%&C;=@av̇i*5 d@T0(45~vT9,*kZXgE!@D0 e\NH3eMQU:W6!4:PcXlX5[L]5.fZR;|6t-k -qV P,܌Cp0.Z 'c's;QItjdh?nz^*eTݽ~Xy4to8^1߄iwBu#٢s+6F{؁IbVp `ۚ8׆1Ġpܰ5e YQ![W d7׳6:H7/G)7TdB3|&_ωaq*N)`IväZ |׍e1-/τ^@p' }Tj~","L L'%.oero}S 4t&4UEk-4I/P 2w0{UnfZWM=yϪaA(śVC‚EImyՋ) 1cS/.V4w,rp!:ʺ,E)RY/Hw&?ٴc+ok~) 찣^ąSQjp63읢<^(Yx"#Q/7f_/ж KͼϮUHnU, .zb(ɚS+<iKU{R$妉 F]z\[@sdVp]OcKV˕B nw~r§!$8r2Z^-,!8u7&f0Z1TiDSqU4Qmw+O{\[4"{!+,;C9p+' nLk핈._@LDZR;2mű¢ODL<a?[,:[~*{PB#C-cXI$^{@dh&\aF67[NVKvPY\O\&l 89 ECB-&4 M݄(0gXD}b в!Nu:T k[=]dѿŸB==L!e4+/0?pZ_sFhaeMv<)'[J3) FdSA6@- |Fl6$b SzjyFȄ(u49 ;cK_V*Og`/{ڜ '>L:]ĘΞbZXþբU 0 6kЎZ*y %km*öSF)m]{$mTÛFHqu#arZsb0 bWVWkJ-UKP<α!i2H.9Q#%T!H3 '#ı9X$'[ na- ^%)LU"b~]vJ@ %ƩiX@  oIDZ)d~ mXcb=/澝Gv-ŧ6jرRwhS8b8ϔ?":rO36N@Q,q" $K rs<<龔.A2RM$PuiA$\$,ȋ vSga 1GWe.s"ƛlx/"-CX PJ_9ְE Npx%!GςSzyQ '_-49L`~aA (o9ۘeX->KmjuNG$K H5jf+{:~B_C$(z}|_-'a H&/a=i;yG$b.OQB$ [ ـ b\!" #UzfPwvY@?)bT-=9}?U93hRѐT ;H+B~qo%T6]- q+!%wM1-_wاHZaWje'}%U)0nxF&SB>1gV)ˣ<[9g r){"Pqf#WC՚'q=^>$T6u(0ݞȪYZY#cȺQ-bYCkF$68p~Yꙅ8Oi\Չ?l,\@Z/ͳ?y6W,4čGn7'z`roյ_}M yݝ V?%XgR 8[ ɘuOy\ȏK֨%{cܳB Ӡ-ޯۍDxR e ns>ex)Z2*WvqkKF'܄ D h@7dGk^GTT;V)gMUs[!UuzLh^]r$Z'X ³*y#!y)d#=cm&Ga~dOp]ܓKq^t8,.榹ݯV;`da!!Cȧr%N:l=Y/1N L=}9Inv_eIzL!>A+-mcdlѬ|Tg&`U,e):NI鏾 1(0SXm_\U%R*$qVȻA[=FrY0,Le!6J|*_%ው4jG^\{}S0Wܮ)#6vo0hr/,Pk 1)˰/ngh?H#G(. ]&EKNY=+vefdˇ`\ޗ/I7Q87ElCNPvd1` g=|lEsk9{4G1 O="F壃tdq{ @O6M~hVi˅8V^Y?e@9W]Q`C咿&oBP _bw7-Z^+RG_[H  <6yX}a;C6*!>5Fulc Cq;\] I:$4'mmS2u65gkE~M yRҔPw>I׉#5p{CSsҰ`W4WN%~=<64c]%ˌD;+3 :׆j4kESe0lw#t,m6.Ld?w:-Pײf ;bW"A]3 c`N451?ů<]sjz몎 *2٫ۿŊ P8- Bł#޼@sK'GzYEBb?tK|]qy2Aj;){oX*u`9ލ!UgcN R]V\桾W6N3e>AXؓ7'+ƽk z80|.OLksa):Ct ԮagLHw(9UC=?LZǟdOEZjdeŹI!,e0cCd)ZbTpX eǍ Ti@P7vw[|'3\ֱ}]|Xc'.Ud5 B&3w^>KȔӲS fɋD SȮhWƗg2ʞ ߽=V,O-QH%Yl8 1^ $N L;r׊H/AvQ<ףaȒC4 ^5HջFwW{'7@;@?@ w3 JgB([!ܨ=Xs!a Pʓlu:@+D>œE. ͽlSG{9\-p;mru& SR"Ӷ?8U*WS{% 9G^){rHvprBj.nz*ơz<Ε\n`"#"¿Z=9FY~jI҂G&avO0@*v@ Bq | }1eιrhS(BצWD)-[A$_[h[DzI*w ahϥP>DtXkbXAN([P?߼3N,҉¦$ Ō=!cxaQ۬p(ImwpYӲWj fME܉b%5B返o LʋAR#Mg"T1*YnqkS;8{ "BF|E!Go>p#Zoܹ jV1B@-2L3t#u>2[7iiﴰk=EnJuB/VI;Xi&ls ӟxPs+CpPk"6oãiRPr7m(+$)ć#,[:,ZF& ?5cIkSEfDCvڐgDLu/IWqVȠYgIX/2936g+*ٺ!H/kcHf1Haھ"#,8m+$gN@D Q? Q$$t\W!}3DW»e*|~zW[AHtYTUx:n`  B% YZ