sssd-ipa-1.14.0-43.el7_3.11$>d>(fo=F >=?d   ; "@FM    4 { $XLL 3L   ( 89:e=yGyHyIyXyYy\z ]z(^zb{d{e{f{l{t{u|v|0w~tx~y~RCsssd-ipa1.14.043.el7_3.11The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.X~oc1bm.rdu2.centos.org 'zCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKNiA큤AX~oX~oX~oW~X~oX~oX~o4790c7240978db7ebb45b068e719667bc94b918d094d5ee626879a48d3302a0b8282b239202907b347a9a1cc7942ee0a915370f8a25808a40b00dc106fd4dbb28ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903db7ef65c8a57396cc08f8d7b4c82b8de9d7c53397c64cbf120dca001f5198c1cdffdd465621582b79904ea7e77cb96c37396b8d9efff43c35a6cebeab63bce87rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.11.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.113.0.4-14.6.0-14.0-11.14.0-43.el7_3.111.14.0-43.el7_3.111.14.0-43.el7_3.115.2-1sssd1.10.0-8.beta24.11.3XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.111.14.0-43.el7_3.11libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8331f40a84070971d9978cd680a24ba3ac5957aa, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6(]"k%w+p}|,p35muذH[zhg#(#-d75Qۃ`%hch"zAϔ89,W\[LuխGrSSp7iow⒕{ B3*3PRƌH?ሁӝMZw:cfhF)J8hn/+R QNh?xRH.eK&f0~o,hb5㗢*RkFܿ>]<|esS]a"+A޾kLWuxnscSD5VwEӿߜ.#Z>0[ohb[LrWm2ϥWE#HP)*sf+.@QXx#[a)z 7$t0,IĴ5QA__.U"&o՗+l=Rk!҇BM&{ǣ$!_X-Cp=u63D/KRrҬhr@-z"N&fH%%SnSij-ov=g<ʗk? yˮh%g(CUr!KjO+Z bx(3ȄRs7MWBܷ#BT^QS ^prKMے'V8(ot[u6\ " zB'L7DI&;ThND|ZGbCtL6\ 4=ʭ&^1WQPOB OR<_O fA45WcGa8HMi:皍l|w45~B^r|U:Z=k͒ʟ (%܊g1Na3ڌ K'j`$9gOVʔc5%+CłO1{3K W:ۓJ.ÔnP{DZ@U71{Xܝᵹm@lsaAG'_:M;B=wA/F "iUr4#vz K,V/@0Zx3#N=J(dl̍<ڷ*1~ȅegT%ySKݥؒ~?jLB%K0=h{|cƚ8|e#3Iq^.`;Zʵ1|ybQ Gg ߈$!ìۍ\tPZT Py܋|;H!{a.7uQ.ֹ`͒Q 0GWGJsb(g < YdBo27oS7E4QͽzY4>Γ5*-5h\&rbύʓU"R=WCn;q>LpzP5IE?\iIVK%)O^e`"µZ6`VM $d$t (( ]G_3qB~^>=z˹NCբX#p -6#Ε2j{z\?t?ml47ފQS'E187)'p-NctS::)9hyoĔ^r?(7l24U»@ 24{)~qC%KJ7 y9gkj\,=_te-61ߤ12W%Fb P:WEG/OJ9vy}Lv#S_]emt҉5/*sGF.:jRg̘Rc2>wqҬ , zY_ br Naw0 WW.[-@f,STvKMTPٿ9KYdSS0i{y9:s+QE ˃;j>] h1L>ۚ[748JJ>֪1a19IqO63^ؘ6V0EvAoyBr.s "Q"nq,J5Z?d- $+Y׏]? ;Wz_?+z|Vٻl.:7R('73vlL#8ZeiSkOڐRƞ>Dq̀tVģJp޼8hT1TWʘ# G(dj!*[ Nk x_g6 7g^'34BQY$>?Vr\ԫꢦUJy^Owth:0fL牉#g[-?dK&t9WKx '@#ß O8@eO+hZ g`*jj~`!j1Qi߬G6vZ@W7-EtOl,]twzǒ,{K/1!k̒vׇZn7r9yY" hx9H^a'ŲX+xFcJ ?mLSU3PyU [ҺL$ݵwxP b$^/PsGvhkKl`Xb4dμ;\Im䄧5^ 6C"d \va`#M3qɄ-5%IA ˜uY1.$@(W_ ̉(A[$\(bOfR=5jݜ0#{~SIG]5JI0=>^YpOWߟO;bxO [KK?'ҫ_Xa6Mlr0 TzyZΚ{}'`vfX+*Rd:x8^hpt.RB^$Q_esgO0KrMwK~A՞&u߉RV:Ǚ|Ѿ3-Ut.EDvŃ4e-p[ekQ@ōȞ\A>Us2\>^-X_]N,`8V"UL􂯔iG`NM5S þQ]j!{ Εivv4(^*Ӷ JX_E_N{lmqZkwՓ=a n^:TJ:5Z\BIBtEIG{…h[?&^KCDY0IZzb9;snݤX-gwKR3ԇ\ӤJD(X񆚄 )IDTΛu\CW0Q:ʪݜ n4׎9TB{,Mh'9@"^r $6yE~ogY=[76R d/GȲifv80"Li=iYO,!W[I[ש%)86 T{ItrGq(Oz 8[lS7C Yw?cbPRfBq hq0o#ZSe|Vm%tCbcDUQ2G VS3y70XNb9v>*퐲1 ]I&k'g )Gd HJ[Pp˞ֺN˓e0t&ѬG7 'iټKtwY3pmXʏPF,s46YFev<HNpI|U_e&9=;e谐3%wi0>C8\vQf!/Gm#P"śwAc Ut#*2 F4<7~tݶnNocSD7f[FLK Ni ƚ#ľ5DJlxb)WRHhKvc`g'zxM/`4`4Fco ؔZGlW(Yw?eˍDIG^r~Lu8$ހpyq9pei1NPI/_Z^&ұB8B< VrGvJ** 6SYMe5|8 hJ^D93.#(l^ތbg7YyyYEW=?&F%]=D3 3*fҀ2PtGˏK,h4QacxVdhƖLqJtu n ab6^TuR(^M 7EV;n8Q2F {aYڿ#/T{'=FDbaE-?_ z$blzcRUAw}̹7*f*j[$ r7(3sO2g*+֬Z*R~6 "l*{20Ғ6o +>hxf\Z-)w[qrcI'QN6I$jq`"iL}J|5u7z%}ڶ?igx +sh;1VAyMy Ή{-pcۆ2ޥtX6æĎJkOR]sx="~A]R_>Pv.n ٴk{"ލ>{G OW_7z'laNi6TV0pPGkk+T15!tѐd0"b8#yV=ҀV4 jvta?<mz"E'+PMCǯ=ok"j_7[EZ_}gqD$Z5szq&DE!i#W-XU:P2񫳳z'.ז2W0nxd|\/p c׉J9(;TxAѼ\_5)Z6ݕ6w9O0Hq' (d\NXo:޴"=GYY%wr쯍6pBP+F8|1|KZE*iB4 V1pfIt ZMv#)܇R{.p] 2YeƘɢ@*|p b)F]6LdJbNkYr (^^x`pJr)xS ?G8QmѭIR-hhR3mG&ݰ?Hs]V*mA'G8(=7lxPܽMۻ!C_`BoqxҴ @Pb0\E຺vjS~' a./Qvm%ni.5hF@k, znHI`\ bN:dC#d)->P螭;7*Jұդ+J:N Mrq:|pOpw=/&aO!P&]v7'o&DF7ύE*V/ &;A#kă؅4[/̏-~#U뷀!Phe/Dâ"G4.Q/QVN:@~jVmnwC0fØXnBu_%KG⃃ױDbfCM!$uhyEpIl__cۦ`# '6ƵD(&@+벘p~̻j?2{Zr4i:(;bmAF^c2 ;ًbk aÝ%z:QFO=L3lסtH+Lb4\Q%aj'or8)5t=Bt΃]>ぱ[n!ّnGI^XT=%J.KءąiC/_^]3@A5H 8 7ƀ|%Orğ[V9n `%,KĚTBN稤ʋFZ7l$LX(nW;͙;n)>Lnd.BMC9C/qbc&0s| bso?{e?-38DO'*re_ l+Y\ء#{hf߰p/6;MsKߤ?A ,Q&^lohn*R@YO|*[5FTc~(W<>59aLUq7{On\m/jR ( (]lijzrX0{ =W;xufw7q\[dCu ਧbHvnhl)5l$7:W"nE6YE/' s'|b |P?b*^Ϳ1,YaYX4&̧{{%: JBzW&IIU` a* Y:qyc߮EUڔ.&Řx պ 9?)ԀY$8v=b䪵z+/bdxM%kdɚ]w$@["sJL ^ WeSGW"6gcrȫ CR}+VY@앳aTJU߄Rx{{*8ɽmf ;8NbŲ;m:i(Yjq5l _a5~v2CO)N|O;F2NjO*d.*PWy_RI%+g;_Ǜc57ϐ"V=@bP52( =㒬99~*GO[=ȉOJ]#L #tFbNr5~D.= gevAL%5H,o.2s]VdK#%(#̹!UCϾ7=q08ANxed&@%P6Sdd 8帖&8xT{_Z_C_oP;-l M[.tDDP%>wf=O0)a \[ܣ}3]?R4HC,A ##eV9r/>/|zVNOn @o|cP24v{9a1#|c"e!sy=CKeǩUуk0.W\QW.I# S?cDXsZ}ז KS>2-P=7aadt1&YnipUYH)ngM/ualBɉ '>ooA Y? м 1r ٤FGLS3gPP3kec^4m/YLՃQn'ߊ, κF}yքzw 3'u4e`Ȇ,#5S[<ayewdT>4( 0.V!qO0"}k ʭk)6ٝW2l+@SWAf ^+G[1lF5Cx[/xGK@fE%-,]~7Ɠm׊<1OEȕ#3nlR t W6[ PU =KxGYcJNeoW]Y )@#[;|Q 0$2MJSI:dvh}tHx}6(inD<`GR5RUAumL-jb7f%~)'|*869Ze$ Tm;] |NEN2?.oi>")rLjy"oWTM&T G͟y/*X:>HHHFٹ4ӳ`1=JVg@򘃔&s+,CuBb5jd ({:r4Ε.hz?ImN;H-5"@G<hئ1. ?5.cr2mO\(v؂50Kan?ՓqĦ{INt2ؘ<[sfY9Ԣ9&є8^GAc+h%Ma)GmL(b~_QŷvwwهuO%9yJ!QJ:=Na5\~\XKiݥ@LjSREtxyyv0 W%tt f02ENQō!@t]97v&{Dv⥉u uq8)7qHsJ@[ \?^"^f%Mh^B^Zr 8?iNr`20%.fzr95KӻcLљKqUAHx'vx{NƘcNFܩzx6?Se$f7Wyq;p%|DtqG >/~@_GUY1˜6Rqyy^Jd {"d7.c͔Gcy0G'VX6 OL_ғ/xk-n,bBT$ݤ$pky3Ipr[ubI*(5M;,ϩҗ_Y`XL v{qGO0\UݢXԒ͠2}ܐȷH̽x |+ D%1y"_ڰdKA?3iH5cSuh-AB%J&1C:c h8Ն5b_ IêD_Yz\ϩɸHDܒ{tuBAcNVcJ&6)gn>>T7::vs0Dcz_2xv|x,Κ\V}q@sNZQDC T@jehf(s30bOXyzFc2OX]N?&2 D%ZL[ ȣmjr/b֜s\@O$]#DӜd^P>KqF &8i=d{M34 cXrS1x(fTOx*ĝ1L%" UҀܨl iteٲ`^cm2ԝ.!qH[TBKJD{%ʓWSKM D*K-y",`oV!TSu"Bgb]S>=}3_N %/xGc̮jTϨJ_D%ݫ*UBCX| ^uY壮{?I"w=uݴOVӡ,e;f4h*rG~Ff^uYzm.o+T]q=Y9.PdΤ)J}i9nYQC4%M< .Ҵ#αBZtO#i|[n1k2bR%uX>Լ`*~#{|J im剟fr7iAS %୯y.JrH0`nc?%LzR)B1wr;:Nl 0+YC!Z]3LT3@a;-ܻ,DYo!9+PH(\E''F!uE\қUdT<Ÿ e7tHua`~Y E>k8_T^ƾٟX\^3 ; oݑMωT󱄶!M<9AD'^bkn}RFLUԣp@G)D<*UU¡ u'4 Wip"X=2&6uDwUmk5/{ȺJOklF*nx ʰԂ'֏-O[t;u HtiFrod$uvĭF<;T]?މ#M<#bBk)!(=1fh\C{F;̓S@0$"n3Òmz B9$Ivn0@׾F3zɆĥAܻ)a(B]d<;D^L1d\)n '#~ݳ3n@dg==u^$_lb)yp8_K+n 9G9*Jy"#h q65Fߧ5'x̓3H1\nl#UBL$iiCzYGzI~(&;YZt #7j}z}f<N8|n5'ϩ8ӐK%4bhjU8L-cR|ˁh] ΡK3n~Oωk}^͇YRڡ y`nY ^lpK?ʣ!Ӑx?pG:`1UFkt;&G`JƑ ZvilYk-Z~T>tG* 8BFgJ"U#kUVod!j`EŅ)}QUG+Y,kP; qn@DSyRvVP9C`8跸|[ VyݝӭZ%cqFdDTqZo'5ϋT1i[wlFtݜ@Qnr,IЋ iWX&,N-Ã(9at_(Q%aar F|TtlrV0KI$q0vOnNOH[`rl5fsS[0,O0op8Z'tH#/b/ y"tgZ*?^@WfV5=4 ̏V}턶Λp4C!kā\Y%r2ONt2|K%q62f0;sxtdҁ/O{:aZ$hxϧ, ^`Ñoߠ[E_~iQgY>m?D'tmMBpɞ1s`2Gh|+,.⯸<g~!~͋'yMW#:> ^] #ۂWE“Pc(30OAragSP^g;WtZ+?NIƮ:.a<ًb @R`?g (%Ke՜=>d~wt]mcO5vSKRz_4 +S-Bq-:d Uum/E ajv!,\>[Ow $C!ܾE:/XM%o<ʛTmmI`ʛG5MտouC F[\R`ۏzT?]M m~ (ɢdZg6БL~88(1!ߺFLzۧ<P#qXDm.@9=/e6Yx=ԃ単#If&8 TLnYutSԏTct_ 6z)r Lϐ- P|k!dYkil=/䢛nLB" V]9qqߍ*$>:f*T$ݿUKDOOE۰x1~c<.F9uf'0?p<۽BkW3?ѷ\OTF.|Z &F 06NY U0pk([3ҥp3jD}/jq0;`ހ^9gRjʘ:zZ|bM(?q!Ug7Ϟ?:-Uj<8O%6zŨ* w:nwLxSI=M8s1w:{#*- Aڻ ֊IRޖjN[ig!:i79X+~,Ldxi t7T8oIWs4TSǪ$MLzmy-*k4:G-@AQ{5LD&mW㹱k#/_$mRĬnRz*wOAoQP6{<-Al$L;v+1:3a: ߏrj{sp;*/lr/e櫸τ-pH Lŧgt^Ynu @97A=sD``'(E\4'mnr #s[A.A<6@ld&s PnAћ\Nm%7Fwq݅En[,ؘkb$J4DdF0t^pw9|c𔠊=II}PI,䊌HEsΒыb"2M|z,% _Ƅ4op] S1/߱1Jp7"N&kBW|Xfܲ X\p=3ox:Lpx^&c.`j)Ǵm`~Txay6 g '}*"*jwme2-#4qko\ t+d%j჊Թ* Ф}(cu2+1` $i_-e! 6zN {Y\`!`+p.*'B+E [,^',3FcR\w a\Df|@(y1Iooݳs | a`5S $ HF6S\F \0Ø Ϥ/X?fu{1VIţnjߎ呢C P;e؋ǵ>.X0Na)v#вq6}FrIKclrMuWև7^ujk]da2c/$w&tW=5% Syl/~K~Qe1;OGێ KaI :!_ݑ݁p/ 'BxT\ ԑ{W!!hfEYJD 1We#v__3:yo +̔0 |Gfʝk,qQ2',R~ *n.z}xΦf7U'sfJuU6>,@;* ^>yy8ag=|7S|Ԩ)?8-#lR+dw,#~A؅uXGr6i(7:H^D#'IEClH;g{*mWk(64$ܙr`f 5yUUcaIʨ,(f^O}CΓz D\ɨǤ>ӚCH%HM:^ }3 6T2VOHysn 2\2?Dyg>Nyޛv~rI՗:E I|C`NuJ.OuzT_M[3_tzB@d$Vn@w7X,\u')? L?OHmXDh[]˚%迃/+!E'-׌  xa:'Uϼ!c NL;[$j61[_$U&I>leyJ(G%P%vgyxO/(u3⾗u|aDA޿Ϩ)f$*CywX0#9AGsPOjt`7/.=IFĸpJRwxux$)A#zg!_s#h&Ru 8%CnE{n>y*ĺ4#5LSD Ii47֙1f|fIgYuPZBcnUbWM(x▰ JT/@ ftn.oyU_ MsL)8Ox_bp.sUztYql@%lLy\GIS[߯=ޛb, S-r9p1 ޅ>@`v2oxs 0 S$"]Tuy1CZ}Rv0^<$P '" @i/yCn|jB3o:7R҅?@ pi!Io@Vd@oPW 9m #D,f:nM״,fz*(l>wEG!ZZ8#g ˩41vVSԻ4,@RKK,>ښQ9Iv5'm/Ydk<a~,.(w?Ө^?7rC @O -!F~TW- >Ϊ=d9Yy NɲGCS@uA/fB6чu59@FҸ!*̓#]iI) Hޏ8Le[Elxn4-ۗrMR!Z۬ 6j}J[ݔ9wՋZEؼ+u24@Gq eͧ hi^PԽh@A0%t=4/m`vN͇vM$is`%m"[5\`$Z<3!]wum 'Tb(S q~,J|~`2a0njkЩV@iw7)unL&pOAZh=~7h2goJ7@Nbx>;f.يpH Ksdtk -y_3EnE"8 я iPҁG٠` 72&:xP`jIT7AH>p|{'_G)8vVI{`ֶz`vs+u.K5pٮFhD#X(1L(9BKPc]7+g(თ552Z89JG ItJ%z),3"br__ԣu N /?xWJHfbh7c87# ^aJ,'Y͏^u_&83$:w}b5DQ_W<< I2֐Ͻ'~ݽYugo57vl09c1[Fuj0X ԴWO'chކ=Z7B3V&Tt\aW)Jy1bcpcsL~=k% Gx%Yz*˶M՞8=N .e9艫O5^h7=q8&iaP3az RL|(tW| M`VS@  tyQf:Fj'ȧrV )fd¼D,g BVDz]FgNxPMLE/ڄ[_r |p,c;5ڭ S4VfE%= YĪ&V ̸sBvC]1js}&wMvtD,oފ(nIV T'xNQdsZv̱[}p$~v rfZ8;-{HcZ ۮRjƸUhRXEw JL裶#")rwVC%sJe2Z(~<. #Z0WabM(Fn \WX ; K5MZY~=Z aR~kVd뛎@f{/[]pC뾾<50k`kܞEF҅{qҙl~2{J#4BdHתRP6|,A[f#&ҹ4/jY:#xNNA﬩ucJaJ&Q1$1 M 5"ҷ{Ai꨼j>oS[ SL>/ i10̗ڶ[[ .d,SZ{g1;n40*STch_یth!Z֔:: ^Op찤ď̖ѝyu{@zi =.TfIH@4\2T*V;ů_ORǟK3'QӮoJ*I > e$^r3/m]J䭃 5ƽ6.ǹ_C3so ͦvF:2Az7GMνPF 4m^X=݇,9mY飡@ g,aPJkeaPWn\p\ 2BXcEArZ|$rO",~_d*Aˑ_Ug4Q婩ُWaph*P X =Ppԋ⬒*rGvx$7G Un[4]1Ti~m5n;_q=ՄoqH˱/VYPEXk[ṢהreSE> \|p. Mkt{P/2ҐF]?Ð>SlJ 9u{ְxSj!WdS^!鰺γDXz-Zio#[H-+ .:BL<O]At05ȍb_W&k(ةwu>|:RD`{.[\J)1v.- D0tJ;'2 б<+:t D~՟Q >8:A}P1AϬAit4.f*,Z'?BaXFtф%ҏX_lᖗx$ixHA gx- l5wnae|9su$Ĵ/NżzZwl4UBjPlYƩ1|؉KebCy*$@5 " nd `#~ w;Wav$:]{쭐%DpoK @0p"-e e@ "??E>Eɡi)l?uK\~3!pat 3 YTLR<#tg杳Y5^0*?PC|!QӋ+߮Vwp3>mT4ۮ{ϒ;N'>Jʋot+W#kҞ?Skf;Da~v+|ȹ*KNVGii6J@b0`:g{"*t@^.fJhz#kCv#8, rb %n)Ch,iŕ/R@qB+Jc/ $>!Ew5P9żqzn6`FV[qEvB"gtJZjy/bmF8p9}|8WhNĦ4hQ=!ƗɦQu;B#C c3]P2L0xDy,MҴXy<6^mއ9Ɵ&GopN:^s'i:'G!Ծ`ܑwq%X1LQF[^(4"h;l\e?x7,ANTU$]mLwz~H2sW@y EvfsQ0@Ijp~ۥ; 숌5MgFńI>^ <8(}6yB7 Ǡy2&+% ӟ/V؟)1Zwߞb[S,.,+!Nj OAcw(h]v?[p򹊤.Nu:Gf[w0zhY<ψ."!~2S]+5)Dnwvw *uI~CO_S!xx_Npr{**҆nEuT}#"]ЉZ@lzB_6Fvi!3yΚ>2vtŷ|t DoےX۰ K窮K (.V8V$&7CD|TD2`n'Y"stJFŽCB9@f #/CW5˙p/Jeu{1,y9b8G"ng"T=JxJ AG`}q8+GT#Qsv8!9^;> lr2SZ`õ zNY*DEBvD}*M_iԶlG}oJ\aQ -0p(~% >,V?ݶfo_b$62 :Cd#cymZJb#hȲ4J35gd@BIM~ϛ?|p(GIMu<OD-*b *l(&:/6`hx V5>Hqu{$c/b-(1+-M!&-T*4Q ^_ߒu}J _sl\2^{d!"q eG^cM^* ׂڊް~S0ĠKWKB"4(P/LzAȱ"Z?|̟[mft1E؂}|˖tyXLUh0VEyKэOzuǃ a;G$ƺ'|k/\\+,*#EtQ¦CLtͱ #fx5әZJ[R9Tu{ǰ_mE/ƶ^+0xYk7fX~YP<=j0ؚ$ҪH.4\R|AR%M@r3 j-6Z$+(m|4{0Grᐋد2/I,WhyHi@\vދR;D]{ʀn-5(rk?ULy;&`\{Ve _p@]He&%`\Z60t@ FAT-ʦ-/&',KUT}-][W dDdIZX ~D4Lfe3.\#]h=XM:S}4OgEz}2cbe aL#qxP\k7燐>w },&6B_#"S)#yXxȃDXdI>t?>&fX-3h@':7b%uO}Yڈѯ䊭 ͪiz nXY)pf^Lf Z+J 2{|#K0>>>/`gO"jS/"IBT1-|h񀱮 VK^b6z\x#XQd lT bD*m:2UoUp~h6ؠq*bn B6n1 7C-\.UnKɫBlF! :_=}?y.}d@Xm9}7 dxj1ڇ+|~ Mt7-xU ;fmQ,O,N56U55Q<IGJo9o%I,iơVJp=e/v&0*,>қ0<npQ PsH")#rz)_`u2W.r\<Wz@߉W8YCŔ,XCnѶ=%~½v6oGVjO?ϧ9bZqvR'$~Iz kP ,ӝO$u[; diյ׵KZ3jCIPbKoY0DPn3#t$+pO%3(9zq &7r٣¡:a_nnJu|v&lp*RMi@$:| $oՅ;.Qu`{r+]9Q?@b=+DV5$W2'bV?7BW$Ȧ봝HJ`Cy ²3Ӊ H[spy9 5zI5@4}1[<2=%r3W&NgdW'E~hA<L t%j N(9z7G_+Qz ,vt5||j^zs vvYsّ rG5Q*J`o* K y3Hi0%Pl ^wRN&>&jG Ŝ^a%&D72%I9JPr֞;bxesVË]Dƙ(r2kŷ;rM0J(z^xSX$WjMaR.@Ԗbƿ}݄E /t_N 05^H$bkGc *f+K֔IÌC G]~HA3v6'} ś|1$>89k!0)$;< -y"X6u_5mSPMmsk׉giWabox׎Ip0/waV:⅂hԔK~wR\Bڞ0}s,pX>pĪx)/($+5cO>uP4o61:nDVL )Zz.;xbjP4SKBg/e+d vX6[lef Lמ{<8%Kt'Faܠȇ׹(e: 9p.zǞCѹ2j<$h[9wޟ]I%8C"kH"˩\*"p@$rjܼ㽑B&\uzvޢ*c:ĜEEwޡ y.X~2jŒ|Z"3jH/-H-ZFH@WvyuC pYm׼loz'~K jIdzq/y )T}q%~U5;CkxaAڿH̓C2%L*VcYiG E[6W( # (En7!a8Cq<_쭘\6hW;ѱ+).+X%m"pAu'-S~Qw 6OwQWElV9~3C r]7 #ylA Nv"q-A`r &=/J>kH}N#u:oXQDEnȁaE}v&p_\-~)K[/,2~itX͓uވ2tMkbG sKZP:eYSCU) N0(@P\_2=,/g'0:t<&RD1$*0D)%q|ְܧ:)<6y.'ϑ/Qކ=6֬U .9WM@;B o/WlzJ^Mo%>D_VfF Va2x1z)XKhS_&aІd$k4qa-* {^%LJkъ6}N.Dc9n& liQtƹ{9N@f*;PovY~YKM+~jwQgb_#M>>+YIqvqHPh_Kf.F< `lM We}Q`*w/S 3X(.=r@ݾL Nm,q JJN]o Hloc飑[~H5!GHҌgn(r]'ǚm4DpUh.H? {[B0j˷[kdע'a5uW|%"IWRk'g4ގA=IWI:ϻ?L%*g\ݥ侤B;&֨>Y]JC6egpN97T)f1vcs0]ekdi͌p2?뢘qt=et ESq ;=!T`}@G%PۑDuuiC5Ū(^5#E:B `Pbjh*Ru%9Iz>Y{~,'E$ v3;R\PAkW%y=nݾj!aXTC_{{WIVắ^:gn}3>t 2YڞqzDCHyM)Ĕ;@ }Ha~T!L(9.MuHb Y$X ckvTY%: \6Ww2Jz5sG?LE$4@N al|-[XSi<S^X Ba_DhN{mevJw0"+oOLv ͣ˂҉';g2/Kث+"VYuڝ롅0! cnlHę0l|z|-HHB tkkL ҇rxIrz ݤh45GH<\`OԊm4աKf4O҆O3jb]ݓեQRW@kȔAw9 HTYͫ<psΞnʿ/us]UX9Iw6yaDFo;Ts3liBh62 }DgO 0K1˶ZD1c糹eME]ǧ!j9hՎ)3Vޘ?NQKM&8t,29D:{CjE<<9tږ -Ȩoe ǬlʄalUU/x0Ͽa_sQ8V谥ωLZUPA"_2LB4NpnoF lm__Y>εa$X2H /AF,wf~UHA\iŭ%ȫK<*͔A䦩_E12ʮ$Dۼ+{Y;3.ʸL'ЧNoyG6驿2sN &FSqp?uP9i'P -v֡'H$ fqr0|p+tT35qر W2qƢ"QVYDY #ILbC:f&H\HN&vJwMH f>j8SQ Р[ۊcl/Bh}L4i׶ ESu  X3j+p(!zHΒ-@$!J - Yn=FDti!fʇ37W -ᰬ wGNגr?Sv1$hp=آI9{k D+T( Jr6l)۳hT*Z,㦘_Uk36mmPK۾rf̥_Q^s|*/^܆GHq3As*7;Y!4?Ngp])]4<$mQ̗¤^qZ )@>]x{Ħr64DzPuqk$+I\_m)\hCc,MK.)*C0#`hr֢8t2(OߏvmB,xxw1oW $qtt(&dJ?0qeQJ$LL[& =j<,hC Ey*Sݍ%Q/atzo#1gaMԸv&*J0gѺ &RׂeKvf ,wc~s_@:4K#4IE·+ ͅ| ⥑>T7 {u ϡtoUoڣjv_ ;rp5@J\ OEe>J{@M#?6,G9yxէraʫ+ٽ16wq6Z K,S.]O Kܱj?y&XWF51 3J"~47) !Cc]^WkJWz ~&t?d&O=*겂m(Q&( j]:ĬasTwjW̔A@eZHÆ[yBթ@2gY .2h(dc}i;b.w%?K5In6Fs [0 k +Z1M(.$K^/"*,߱cly"1 fag gi+m\@h:@ eT޿7dAZyįkۈУ·jZDG]D/dy=4mIB C' a{ȭf}x$&l>!be PD:l+)lφߴJ+K4mܺ8$b!\{{УdS!@DNNoɞL@DT|QXRLGlـ!8jENmdB<` x)IM+X8Ǯ&[BMVm=iKCABG9903Jv3 PDEx_$ڇ{u\o: ibCy{/BV2#9dF*csgFl^{ b/|/ܢߥ_kUTyV}l0z͛? ,>/-w6a 9䚗 ڛ⽂_E!+_wdz |hieG/^Rjjݨ_107k}gh]>S/`y8 n. !_U;@7󬨹vO+gI j WI'k+:X]}'{\%>>G(."d\Κ(k9&ϝ?kw$`#N|8_6bwWROZ%k+?wS7yB}mMwwD.TyА,r%;3E-iԣ4хYle F{(8$@@/~oY ! * ;FQ{< )}ZdlM0h0py2YTb࿠|\Z6z z\&-4#'?[168h{. \])>61W剫଀:7McA.+{Q >xݺٴu2Z*`^lv/0[ZghSe'|ݹ'@_9|Bӷa{Cp >rd_4Owɼ$ # iãJtEgMIY@Z<]dz&ʶ /4sY4m|ꮦj4xçP9j]L6;$7/ 9SyBj9K}—4eMl=R`^ e#a\̷ͺ #}j0.GFT2,i8t 풉"{R ?\.hϳ9[t-6s*|HwdgĦf^!FY׸/~P_u`(ț0m'¼T <(-Lh?-G 5<,N#H U;fjqms}N+'3 @e@GB5U Y}Xp&̔w6h/Rc9[#Mo1YCLns =" Z[d6Rt:Լ vj?Ax3r#mH6*םR[ Ws]ew' pL4 T8uXɏ6퟈2T$AWsZ}̸pk}^C %iTڹMi@.0ΡkgR>n"4u)`۞J $23HqK4y,ꃋ vuBsEʷcג(B@Vzu[ лB_XQ՗:v1$ʵO\WN֢Τm4VQ]cd栺Eu'mQqmo;,ǟw%6LDר IQwF,n+T. ؃Cio ;/ j5n@4pʴAA0NiM5Ρ[zDD=fQNJ+hDG3ô5~@IKtPeTqc +/Aoϙ9='2uLagٮj[jt\]|7"ORȐA@81ff>=Xċ4O8lF|yT-ܭ B{ܽfqͥڬ)LZgSd]weȊ@]Cjrh+7EEGm _vHVUiTæ^dChR9)Nyqij0xq`vc6G0qxp !/aaGՕO ]J7 Z?\fǒ .$.jX@_J} -{L(Rpi<" BAjHKppWe2Rjun:RNˎ;ɒBˉsIP"P~WXMæ25GgY[c.Gs[}fF9n0wj*8VR]YSu[݋jԒJROq7ـ&# K5.yo{lɼy~[ ن<ݿ }O onYSfL lܣbo`s3^nZuB?;.I'9@knL|[^8?=сP0+S gQ0{һqFyB/GHf=JCrݴb@J!эo[Հŷ;[PН#S[Dv/g IR棈eq>o'yYȎꈉ+m֌rZE}%ylYU3xͨ/]L2C X$86Y gi wQCr]!^{oM~Nv K$D3>[&WPi,]&I&b9ABa#Y*ZLўqZ`&ykl* F(,Wn$8P~"9E;脍aA;֮2EelOgRf:I0T?0&l՛H3/i#8"Pԇ&-ئLx%녊= e!d嚂 &5FNS5Zc,IxrZ]J``#ȵ.@1ZZ %#5]7D<^Im g#o!qZ(Im\PըV1j EtHH&Y~!>/enDJK:_^ Ȳ 0ơe"啘(M'@n;jrmKI?Be"c4D\E 8$^*zs SOݫTSx)J%ik#+H&-|rE݀Qa7W?s+4 hw=db?I_W3[I^BgPմӞYFa]Wˍ$ݏ|u?3vbp;TL#<6؂M`#Y8bI߮};rs2v*;P:7Wru/h֔u;frq-GUW=9_h"?*/)X4CSqA.V÷w?I?4b-d;WZ!t 8gIYFa'h\ފ@Eej !Ptp;\XXWء6cEF UvטH5@ :3t0W[O|/22&cÙ'9-%4FFߥ"8FHqFKP?c2jH +r;2玎8Jh4@4 ~-$J|ZV߸$g;SV-r[=|"fJ}Tlў78jKN:(YJ6] zPFyMzľrk/8+xKm VgI^0OMwnaf!­  (H c m]ށ;n.-]xo-lg,\Xs*H];/:T=P]v0ad) Aww'F9sSJaOre3O~KM=;u .5њs|C % /lryԲ\(A@ua;t s>*]2ɸEufdQUxo'ns=$As .)Zk5hb):-luT"bjzgVUK–@`tڤ, db@n7؎C t) 6yHڔ`qlv-]'`?5eV0AcAg0bE)i>Z{9oovh$2k("0StJAڬ;3=УPx Tuf#ot.&zCbb|dWNMtHZe Q>GE<pm1P6a9J U XGYdsБڑ60hk:IBozge/a\@4]yo!<{|mT4lم0yohStjo32wtb=~_ⰲ{iP֏֫hS͟w ,ѫqۘA!ZhL,Ev Ypȍi4!'VNI2tփX(nB JYJb64#?mrn<<3}r&Bt䭲 >B;R ͳM59+E2"i_"R,uOk'̱.);`,ׄ>Xy:Z78MW1YNz\g^c~R(ğ~u"x3ĘNBڀ<;-y* tnϖh*fW~F} JĜ_N|vSЄw+";F { .^[<5Et`>f{36BO x)V+ˠe,vO0<7s#&g^P9'QA7H]:k=ڒ8(UMQ9e"EpM1.OZ0Y<P΁s04Xg7wbiUwp#P$OVÚ}8;7Kխk/{Kѿ4ե>9nL {sc*_}s_3*/p{ mkHGO,HL\  !Yé٥Idm P ?!×2V15]jxx?r&nY?xPqZgDNxzc8`z?5 ѐd$x*n/V@4lF4>?/O7ccpZDP\ eBkR@MO v|P4gBbBcm5v;O`ǐ!{}BJ~?R~ʐaADBCڋ OAig]U&|}bz{(CxLH\%t#U%'gk)'>GE-=šoWRZ*;hY~pF-!،ڰ-Ͻ\3y]Ev< ̷t:SP;ßMN(=i 9jj$j,ko#St>\W%w݀ŔKPe~x:[#f&ӼL+W)ˀu5_N{nYjr2w(/֐b^VT8D]HaD<BsekoeCX3j`e/D_b0WF=+Ը2a$_؉];rS{-"MnA&P+!!:>8 ז* V>l+j1m7Gי|7ثL˶ٓ;f5)-,"/is{ϪMevyzA+#;r䩈yG(,c)9ܬl2PԳx$Ӑ4<#)<> OqmDp@8l^-V&I>N"T4acGƃ9)5i x[Ӱp1B147m`fGsKe=Y+\dZw 6◷+>hS@7א&bhmїuj0h^mw=fTd&qlqzY0l[q l0F nX]_nv=(NG:~%1ͮW[J-[㻍 I%-2h_=jojxnĞnO(Wp=弱L+3G..YM7.@!vB>$[c96:g9qsg {6Ly}-U͢}Ci|toxwVK079HmBtTCS Sjs{_rWmvQC/vEN >mhg*iQziM7Nb~[Bw(@G cUaL:3Ǒ&ayJyQyTcEzc}\cLS =9t(CHv`㖕ͥ- nkU/`섰TX*}ăPsDI?SD0bq1xJGB-]^rytKLh3B؆3al2Y@nߒo~O *>ar>(,}yRF8Pqe pQ90xLRe~'b֬_C"NA\~uŌx|}_8i>jЖeoymeoeUs#>aq^>KվMھ܋OS ~p {\mnbG\U4mrGtsAvHj185sכĕw :Ԏvt^&d@#S b/sZ:G7I!ɔԮܴb8buSD&O2`5;Q-CsJ:27GB7[F 4.8YKE8q|*(gc`pcZhMҷ,ܞ&^~C7Bl<%'FnM`͢WăcքI8B)}J%?(Wa3n/ GC ӀYW]{pu1\Q La3mߣs%G0 ؂\,fγ+"tiͺlEhJh<۞?ImqP'AwZ dq#xqW@p$Gj{4#8 \ ,UQpU{R^`$"iShr$O@vEP *=D^`km+ݬ(KkU'$QS۳Wb&̘X2 VO49`́r8%?  jAƃE6Yqh&S;g>HKd%&<`:OaAeGju3~XR&Rxז* ۑro泰FlURˁneݦi;}HJVXެ=\M+'iK )Lg ) :3QB Dbrfa'w7tғFwU>[ <#8#GQ@u^_pYأ뀳kfxF[s607ōC҄>>[x} MM1.(^8ܜEa7KR 1io~kG'lA[ك 4S^0\%"K#cr c4>=k]P2 N;ÈȷochpHzIg4by 5 TT_<4(u$;Oe)hC]ayxwj̠vd>*vUǺ_L9HSJ<cd4ΛA Vsk|c>.݃Am aev~; PuƳ\{ꈔzp-3+U[S%bWҧӹׇ/ګT}w-Ys 86ۙ}{wJ HˋhsB3k[_thh|gP('fhm\dİ W izw9ڏPnH#&G.\ kA4z##G fF^/x~YZ T[-8#Iܰ*$ L/KjĠaGA6UME7 r \|rC>EgPF>f5bj Dpɮ(1zO+Ye{;qo:Kjby޻R[2Vw1w--| y*W/Y!MF"s/OP-N`:m/Wuy2S'RHhdAI$>P2̫ c`f1H4!EFsv5 Yb4[‹+Ǟn n=뤤*rjF_G)Ob"iژxP|696\EC8MXu=IaI% cViueaU6gC+l3ZL6._xś47; l_#VSulu(2ͪ"ÇF n,h< vX3Q$dz5TySoŤ,MXN6s'{9p4<OUDpkM kRb~ಆ[Y+3p$aSM+҅(LW *4%-A7Nt'͆/fD+c3;ܭlzHkJX&8]53ΤANK&ȷdOXejt]߈92gYWݲKY)ϜC/;?ƨ?S O޴2cB ^b9M 䂿 h$B[^ɍkk>Wm%s{@ROQuETX3q|TµrKlVbȖ9Ұ]ůxPP򧴗r_VziJ\]aꍰ5Ә+ojdN9#w`sր#ϒvp~FKNg>7B|Zt>?i*E% BO+_pHΪL!(B"}r,~T`Hw?L0fRn4k{R4#kgeƸfC蠱n21-deeO'a%!sH^e!F[Iu(v"3+ "$[p"}%bc9eeO,0d` 1nL_uƌyNw̧.Ӥ&;؎w;cV v}~)/Pz#-ZIDM 3؆8ls։{ѰN7xØs{_5Ro5DT1}d 61-3MKS\&AL<ʶŠER'=!5n/4MO\ن3q*5sB溧Hݷ^- r /2gd#)5*Xʽpb0)>oWQ׼#_.(D3T1Ц'U+s|)q.خ "0ie sa-Bf;[K_n9q[R!WRp^EN_f fLRxIRF0F2G ;q ׯDBPJYy.8p9lu/;{F%C./ipO;҆eyz rcV_jp jHpzP͒V!&Rڇ!l1˸ql5+t+ɧI\y@=I#Hy%0[ ˙S9*aKڸ9(E@HlXB0^>8T!r29G8̏X=^9Z $R[sdl~IsCm-ajMETM§KL" ;F#%_<:>>a>Sjz9ގh"mP D^`&/KF*r] vD:7Gоa<$LeZeg֐ oPǏ%bFoԴiٚ#?L#Zx]Ϣ*.i˷@~D0e]+mW?vZod8ZL4qvQtCe{r+X÷dòhROφsDkƘv'|EFԧְ%мSƜ lQcbm?_JRg3nE֨:oo jd="s`\89e 49G:41')]x5:Uz ^U=|-e^;xDyi>^HQ}"i/Z@*L!$・`$2##ȓs lcAu#x+_M|0g(?|\ޯ0Ɗ`j*sML9 tfWṒdFU;%h<=[B/O5Bh~&W&̃};7'4KG3'"pL5)U| [;N6XT&3BvS&z5 ObβŁ&BHJQТDoOp.NEZ-gƍc̰tyXmӓ<O퀡ν-F]eF8(7EF>A `I=ڃH#+b+jN"sQ 6X5*">W 5mV7Y$AU&]i@dCi;yo8^K5J B yaoVbaq(eDwÊ$upv J& )\9g=w3[_ 9&/\mf\<6{.xrzgp˾)&:Z=0Qpo<]TP?R)9kpTd8Uz/"b:L@*PR0BJCj#28OwN>4}8ІoI%81B-YKj߽`{ x[IAQE8e̖kLOfZsyX=xrYüV[B08U4Sn5߭bdL!]ѨaFIǹ(bp!&(=S3,ِi0-=җ%񸺖opIuFA0\O ZjS )Vz2Ŵ2s#i(wsSX{Yl7}$J67`:bѠ[ٰ-0S\sK =F\0ìˍLgLdPjH">nַ`I>5LS#2Ik!lMa36ac"4NWm~I2G E: G'qe%$0M}`UH3YIGAhw :cy3^@Kb= o;A^/wdJ!8e,Ӗ@gCkV#a qx_rEZGuvxaΙShßI8dZ,0AdRcKn*zkL$c=.yM=B(?C`1 ޭ  0É@۔--ݹ81t;fMih $}Yp$v(%K !/)>3B!V_E$uK!V`K'dfXy'MGم5AؗҠ #ۉCPww}rX{̹+o >H[s!UKX.<&QN{- TABu˯*SF(1] kY)S7PD(j'ft T+MšJZ]ýiDDM-8PC$GE4`wXSD=)&T7hX[WdԿC=X|Rc"vio~Яs{dTnMpT+zp9x+G|Lɕ ~e3D&G^moSEׄim n{9謴$o܎} $Gjg\ թh<S FPco\5rx!:sPe`Y =2W /žїu:08hN(VLs1_ԎFDȻ )C*%tb5 :^Je<" lh0ub޲6X(?w=eWqcAu|!Q ^@6 PqdSh8ak$αw4桎$ pcxfoI3sd" w@ܶ- wQTӚ|Ф9D.?Xԉd(0y K_v_Zp>H]$IlbkX᡽pI 8D^$mpPX\6U5fKMOEIʢc!Y}(cww#ꑨDi M}@@"鬯.pHz*A0S#%%F8G%vXo%˦t%@xP4rzƴCQaR VCqG3By6ulESU=yjZȪq g6 yJb#@|]5a܏f&VCqx3ESg%_yGܪdk7Au{(->gG:!'RƵusC׋^*C503өŃ71 WC[sNiiztA}sf/YTG%í8 (xKe54 2/OdSP<‡{~KJm!ZN%7gCBT_$͉g)GJIg7 *<4wͰNۓ:?QaXPBa |?$ Ph㷉`t^;H j <P")+L2@c|'ejfPt >}k92Er,pu X9-OgX]RNXD;@-~4|*X\7}@$pO`Y*/O G Tْ!FߑͲ@4~]5ƚ[L:cI `zpv ױ$$+S%N8kҤ`$^KA??%M3Σ<JRjQ$D(r#{vM}qC+QZE{nIah3=dPq"5"R4N{\b󂷵h qc:^&i"$RH7uQ]XJk 4+N$5%b".;<m`ZZƜo6_-98o?'n( .VR4/ *(c=sTU#k 3NY/@CgmvB/FS52bNտR Eƽ_)g}Z.|RefwGcU&ң4]ULG1ҡs?arx /&aEiր~0XIFQ9Ih5ИIjx!Ճ&4n|4tq;6פoC3rͨUChQ3.hg%ڭ DyeNz?j^JX`ґt&aΑrqYIT3@-8tUU$^Wv,RMF (AO?6HO3pb,'$D_Ɋݒ8 .IT\඾K#e:f %_L ]_?x"$ٸLv- Ҩ!t(l;X䔕5e+H<<Cv攝L|8sNag[KNEKI[8'hlD WuVc,[|LYC :E=!KvZI+F5w ښU)!~z Eu2!  ꖘm3S;K4igTO3bV ?]*,ǜ*T&-=5L "b*3?YA!z'ȫSQnki'R%QPQ\#~w~{ޱBF>[dҙ vt df\6z!p$!; V hfUFӹ.'iS)/92(8K8:8S?z%Z+.d&/yʱkp+oz>EZ h3>"C 1iG'V ꟙ:ohdžϘh7Yõ/NO\;7 TO EnҘ5S "(l&)d\·t6bhxyLpXN=,b\4; Y`4 k:B8q[}&e{3Ip\VQX bWs#FhڗuV fďӈ=By~ޫ}QV۬l(/YGK[CapR??|2Z9[PcelH-]^6%L4ᯞ?Bl1w.wmǩIS;& ,!@Yp:uXE1k*(,Hp oM)r^ dLK%SûL0W$~ A$mzytn0,7K i&whڌ1d2xHZ>HE$0D˦*9)b`ٶtL/ .낙BLʽw5~IEђ\!ƪ4O*3PT?*y[Q,枩\T;gߘÙSg\ƴ4-_Z?w1-![y@f/˅6"2zul46>t|+/tJ #@ ;}S ]qm㟠߷ըfu7>Dʄo=I 2j.0n4 ΥHMKmc7z&Ei-IokhzhX ]ҽe Sl(0z.boGR 73[={g:zz>MWjiɾ169/-)Pk><# LOywޣl6QrmT.T-8.୭b3d}1]i  [JdkyDtm2н6~k ) 6ve!Cyr;e4~Y&)4pP('UӒd'@ZZ?嚤!CsA=z iw@7z_ ɝkD+dӈ|iLL:>`ٕ GAy\ `I=~Lj-mD6bn ,%N'ا! J7mQ;~ !X'ȃ/[ EDZ|Ohz]X[n V "{Rv~.h;*cVlaIRF Fms%0agz;"(Q 3V}(Szm8K^:&+Ñq۴Rc{&z|@b BN<7FK E2ph5Qlr;1r2˖.λoa%|?ko0ltXEOLQZTH?;RN0=X?eia_gț+$z#R|Ak҄ͨcP]#21`IєDV -лCg|$3KjD`/! N $e`P}˸:נƴlRE2urf~`e+eeY( г]eg0]|,?VK8J/;P 6!Q*9=sxJhqFh Bj]"B&nvtA4hípEd[8:y㫃pmq9Y;&ܾkh~tK)}Z_ow_JbȐYRmzk"?,wvn=&|)C9ciE/=iJ%}o;j=vi}'Q}\dY.4hqWчYЌQw! 5H'V*ob{1#mG$t,@DI`b{U3'x]FTjvi. ƸSYDUl/`>)HKi-`yҪ&ڛ;A>#m}WA^1{4զN)¯i(R޷r"uj!衾7W|N#h+V Q,A5l߲7QBCiȝz1,n1P{kI[rH0iBӽ%Lg TtoC7+_1bo d` .72"TNDK\_ 6f ~ WD: LPuUۻȃB^Ebmj;iBu{dD4]( 5751Lc-}n N)d!|; R$uEVCe#YJQ ,!{3k\e>5 R#C}H] T{bSJA<\e޳Ӓr)Lf㤭 : ZOt6%=>ދKr / i  !zxF(iZ!4Y>atZVN‰k}P-! gD8xÎ0!WbHN 3 H#S;fϾjЙ6s8\\Hk6ٝY*7"Ah00-X<5!?iɷ 4]̇qFt~:V7M.R2ҏ)1/rAR /_ׅP3 u3 /-z4nq7Dxix/Y =}-l1~L++#,$ & Iͅ~5evbo8R?K@wfN*3 ?-zt!9A1"z]Xy63{bM"N!-=Oս(W-$޷>^{k#<2` V/H7 ktl?Ko=2/mOm@]) c=\Mp)J$(dy |o<-@m 󺸩o6 b*`/ՙR"B6|}`>_Ja#eVqɒAkIrHS64R9@ʅ=QU&AZ,0 2q&X!iح /<lo83͎ǔߏ ;.pCʓs&Uj=*%mz08HCzJ\s9`2I;2/lebdVt A֟yN/ n0ҩ8&#A}&ILA㳋h6Ny X _8  -8bRZ C vaN)zq80V9e7WPSf ˪ h87?.6߰&ЄK-?Zi55έҷj(7$Z]9`2e 162t M59OѾ= 6Pv3|m̙Ds\_V] #QV^yC\&-ˈLC0.V;V1B Ė#Pf{8301qgG/WhdKisTbK]~<B8HК]5CJovDL͠Q<#u+/70bDI6sȢa_! N)!!4ʩ\;;-v!wtIMȂ. ]"Z+Iӄ&KVe<Δ,KW?ZOHFh"V<炆vfRH7!Uo>!G8_T. չ񶦈8@D~m E8Va:̾QٶaƆ)ER4oRļF(fWId)`\rqc{&<&>q[ #\j6'vzv}k["C# Uvospm.4V@Aw'Cz3y 1b9cXcSbt)$$lvD\ū=4,aкO!S(u?a1f˧z% HHQ Ź]VIN^ Jֺg 됒Zm0g"-'[2Aɧ_`ZhflF2l`Ql7srP5uVt ⒍`SIj9CʑF bU&/ ! w [1P׌7Oas0glsM`!:>b^eN4jVGrԩcSBnZ4Ym# B#UM wls-fW\4ORl?ꕂ X8{/']i=̞{tmt%0bۤcD-5 <[_kHk`8Aw :g'B?IAQXT8hӿfQ=9%: tl^gZa}B!W6tܥEBN-yv5LXekUˊk|6Bg L4nU d0~?N5p ˯TeCWVu=YS}xHY]ӯE39Swm۲/j!HO; *97GCB!ƙ(f5 !;P _ފ 9^}SJMmGO>4J9visTʹ9<+ns2abc8$^jerCǿ(Anc B.LAnvEMŦrdפI~CR&}h: 9 -~|[9Cq;Yml{wtt)Yf-aHh6!*Ů)ʡ SIB`=B1@2>d!Kia+KU BcƷz.&AQHTCv -3Vxx26'x"̭o%H/9L(ⶃxqt䯄c@ X_Ym]0{W ySb^!.ʩZ;ڬR$6av:DAfb՗܃8z!(,d@gj^ V?uȌE3pGdomf%}}2CEٗU_b7 HR$!1]D#ca蛐 [ݾ") ݻkp@# kiESAV"n@xteԽ- 5|>rmeQQ QS*xa8n" D ڭ< OSxGq\P|ϑà imd.mWm&(c8TWOmFo`nz'\4JUXehޚzd:{ȜZ:u]Bݕ7{ps<旵*M (g82BF14VeeלOHTG+SFt`~hCzz#d+V'G ؐ ;/GnAC*Ʈ;i9*F~X ^erڿ7n4^8hPR#ҵqJ) }[cL|5m7WzO[RR'X xw"Ђ8n+ 5q>#=dͰM6R2Bqdz-x9xN*S+{O*샤{HZn?.>]y0֕H,?ܔ] y\_ 7r_PTZ[l=b/迳K˨lFZl GV.)b-QF')PP" _2[w. + Y:UTs~%kxk??!PD-oTJ30M ʍhk{#ǁ{w]3Nd \FM C0+0 θo3,`5WN2>Th2;g@i#n' G-"Ʉ'5&UsN !48nʍs ?C@*4=xK.Gh{{YteV \4͗͌&4EzU|m4@%lo 3W_Î ,{UùC? Oqb*ů, ͽt8}0<~+qj`-zJB> h/ P0 fs0-衛e/7neBg'l7A71RtOm`]1g/.YZml߃E:iZ_o9wUN])WFJ*}b)(y]4"߷nU9Qq$ҨIP$d=@-h2'C@q cBr\&$jUE6gh+4ΑH/[^;H=TNtgK0~Ostb2&]e+so7*xz*[4{ҷJ VilK7'PN|LUy8;k.⼮Wx@w=(_|F}2sE%$m|@n3Y&Z _( H!} 9p*ZHu[?ːC KHO IYAiFKDjf&]ߑ,I2i9#S ~@e9Qa;T$ z\)Uuk_ޔ6L:>=j)MX"~'ywNos2 >C͸ ~B[ZO$5. Z~nSӗ{\P3`>{ ʔ O-4!0RF{K*& "?'ܰB= Ƴ#:Ys :Sx.>RlC"(!} k${w.cFԯ\J0wD%WCMQl:@:ye_nw*|XepՄ*cLJ/;/f"bS j(<˗8G?݄\(CdL7Ehz}g|@ccCƎ+xNO09p{PgT`1{\?(kh-Fm ZN5o(UQ'Uie]d4.%O}dUgc]C6'\&T΀q iUY%qH eKMFEsgw;je`+mF߈]i%MMUz-.:?rlҺ kqf xp1v'_L18z B_ "zvRPf9$6Se%a  mZH",Vڻ9e' ہ̍Rߎ@[3w`5%رw'YRAl%U# uDdԝBexC^pycDDlt{DO"(. Xʍtnv{!G]Q;{uNeg8ͰjDžU٠܋;Q):k>S N*j(np.Asg-2ZAnQ`) pSK ,Pt>[u0W1 wy?OcJE\6ASWyz{e`Y4^R-V5#0k!qGX9b3$b_ߛ[V`)1gio+@ q6U)[*QSKs)Q8POg4@7 o4K,\X4VuKg@T#g:{tf\`HvbGxocx,rvfM")!3ԇs{kE<{}Md6C͗k]?Ed 7RCYU jd=<;O`psC֌=7VaJ44d;tɭQ6B9#w? ~?䫹9I˹#v觨rEgkk1F!VSTQt!XN*sZSW/Y棃—a"MkqS0VqDb : ;"4T} G['Y/>1vE{NK|>dV8SALE, VuNVy#IpH:b^*€zkgE^l_/2g/L- Yq_ߟ&½C֒"gRp- Pd"}aaN ʬ5+fCbLyΊ7-zY/csWpݝԵ*i.E̸.*PvAl᭜_bʞ+HaչS%E| yy@x[da 4@7;@ćkmh3J\Xs+39g5NYMulP:?HF:N+en_ PNnp$y W5fXdž*\!a'9#r }\"b1k":TݜǐujqT;GZ9EYCOTD{AhO,)R2*M$oCĽ: m u`*jܹi:+lQ78aRYmԢ㔼AA츠d0L1EcCm̀a\{ȅÚ75Xf@#*L3N 2ԫ+>þ;Ra;]2{C1> cƇrvБrK 7j;Ԕ`ɹ\n1j9`D%0EHu+")fkI#RFM;^c?(ꈢy$ZNscEcSG风8ϑA\(qSKNi":O'=a\Zփz)$Lɿp:@'vE-Qk4g\:FN oZ͉~% l8 :߀1,k%Sx4:"[~$`9]M^\e-$rlvϙ0Xt3FB$r  !]=$z㘲)4>]W "W6K3Im/)L4QM{toQQ?sֱ6fEp.'AkϞ|NWtgjt{2J }T<0"3Q鵭:)rlU[Ot=F[vW1m;?Ke̦WBh .o]< B #܁R)V|\n ;jf-> w_L2+i }T/߿2 /bpA1FFI&%)KKM! SU- `Jf &B{-F6̒cMҺhrg $jDGXKG;Q;q&}(IBa 5(<*2~@S-ImX+obkm :R?8_JqY;͝GR3C-swQK>%q=Ek~>?{ٻN22 / W979 1"?'NsSW ɓO45f 96\]_d$1лF6cqkZϩJ>>IVt(~k˭RCvT)N.rBJ ,laMB֞@2d'~U|>CGkO6U500=U 4 S%n+KAAO#$ ^au0a6_G sL>c {jg!.ƚ{Ó9BPg⇒.XJImc0!hu+F1،D=f/fZqX6:^?ZzA%>dK4r*VS{ii%봻&ĠlBvBąN0#rZr&αJ{'_x?|TSsWCG5&pG#NƓAlrPo r/ᰑc#:!v2Iڋ̹c(?ǭ)q6ѹ+] 贖t Dh:4olnqN)dB:VTe]*پNr9J,q8(Fd תsfjKI (9EC*$dD3q;;L@[qyy`AV}!fj762\nݰBR[A[}p?11$‘'#"G|Eܼ@X>RYcY qӺi[sq#qHr-gd&=*;Qe6  )型s{weY͒Jz+ѣd=hUoKJn7?Xk)a&s(Gt_lz@FR:ɡo LS[ `<)P4;î܋C~3v"ASFH,h~DSbqEm>@b2#fNK֢yUOyOMK0Bx}ML˗FaՐ,Gwb7đz ݮBG(=8g.~{3oI0ЖXE)ͣ?Y.@-$j2[NHpLq,j8gI#Cgت"pka7Z@@U`c&ܹ>~frg2W-A޹΋+ 'Ge8z!gRf[HD~` 3Ӯ~KUS $߻'zzI'7)OV4lw<8*;%U&5q(P"z/ xx_;<6İ*`hI+0gՀ{XHN{njN]B*aAΡ]v耕~=q1Gn+l}'r5l?ݬFCXM+[0A %d9/ 'ɒNV(d<;v*;=TցM${wH0(BI63੹'WI$ OrƦLhUsa[2z6G6 ܀)zAC F8C;??cM+~[tb~dG gASB#ĴUAt 8{y&m=‘E*3ӈu$ /:L{XSw.paR ^'9KkvBj$ _IR&*8; pbG[Fka:.ӌ De\ɕd-J J#g&Ph*xz!#-0&zZ~YRamΗ@s1|>E=Cc 8mwAtH.zm3xs72.BeaeN5ƖvVzP L"q{Fo^<n %ϿŦdJIdڝ8q+qSŷkZoZ<#-[;.^;Y'r $x&\ݰZq=5~n`!n$4SO$d +!"ܠ{ NF' y@I0F&7w:I'ZW?M5\ rgaEVI4L @dÝ8v;F]Q)׃&'IK49˯}ۊ$8eQ1 UQzv_Xł#a-ʭ4O]iȳcOݩmm 81{ E)_z(GOW^7I ߯ +I'ddk"z8ɃdoOX VyUV,oc5 ۻ^glՅ†&Y+w2(9gp#ڟK ]?w\ᎫwG >ug;GȜ7 ם(=%(OWtQd"lcB{J=Bh os2\ 0`=XWN:qZ9kJ1cq/zZc|wz c o]\f ~_'fP(νk697rQ穐3\sH#۠cIti6fA [ Nrn.ZBY`-sX94"UTQ]vE|_I,b.V؟- z:D7G<}[rЃt!O:ynb-3d$}##evq-^d-kucЏlnA0a&f='#fj6Rf#R;W>B͘ڝmY1IV6ijY>*}V/r^vg]4'%N&P3(V= F3*n؂sd__tA+=[zθc#җO7hj2r& UBظnFqy)r&tfuxɣ9`'[=fdM9D̖7ÌKjgla@Z5_UJ@0B0)߆BQӊXfR*^N<8Ų|.-E{ٖ`鄮 JtJAE8f&1q|?>c{FB:mc oWYU1GKzn22zU#J,ؽ :oqŬk#HZfn:DwKrI%~y?3_엵'Tyf>׀ ]DAv8wF2`x=z!s+DoQ&VF(~5&-SW{-}ϸ$w>B ORlc*NIZx whh?DeRQ°s^ Ձ4oс?(j]Zct;=J鳧 kV0/BeB Y!_oLs#=T}4؄$K]x,SZcDN|P]u= E(mS qNJA&f7*.]]*EKvc8 鐘Z2L`mj\y.m$$kuO\;&5jC;9;PȦ&ĶA;W; éOC{AkhΟfҙo|4'P^U_`X0rqk_U+zF<p~\#;FUb>MGm{p3@IоEeG!=$w&L^H`[UMB17q(yؠ7=C{k䠒%44SP;eXm_+)P@dkhqj|LJn!߫iGV7n`up9bSXoTkaJ ۫2!Om@sVjsFArY-cj? 8B́A{~-$i顥Ũڡ~s }\xޗkC /jV#z*ţMw\a؄u4)[R9V_wTTS l8N[ M9CD1"FM'j$1NM&܁=3xÄ{Q VZA|P͘"_d8)3Q n+ГeI@iY9mt=A6[\J`tw qmDץpLtW__TfYáwbۜqe:I7 jE' <~^ 瑔L .fɩ& i†~R_^r7;I'`+7yc_Q}}A~cvmH#Vf,0P"[n><$7>}`j*x4d3mY,ht(A>N:oþh>LJr|l;P%ZSXE5&^DgEӳ`4UK!̂k?Ȅj2hi{k[?_^P{=y >a$I~NA]ிI6yDZIN&YuIԳmvƨ8]*rfShhбrQ̀VD 2N!*уm: 1k2gAh$LKܛqs r@o~/O;\)H~ΜIw >l{w<h ^P$> M4 n<^k[€1t鹺y(6י4b( } xW26E8Vxҥq.x4 /ԲJDQZ9z>5MzjSэ7h/4$?A9o fc-P1kB(HsvG{$/RSc46<#5KhۦɑV ŁeWdHMC=dS4BH1wp"ԙ(1;^XD`yp|[5&[i"ܳOzcDOI|pg{bLD* Dה?j]lu`[\8]"?,_ֹG@ X <'&֩VBTw` D>E>݂*95 WBy ҤDKDuX$JlFK9J.ۭC%+춌(ի]o=%jn㦳t}1sЇVNj)϶ڼX}Ae;+;T~)اTC!^!wd a}Mc EoyOqFMpjG ߲pI *+q^YDÚ~tAX(GyQUouF_5(؃mȞq^Ř}M. TjV7'(#C)b23zz)f8o!iNi"UO?K;'6^1nfm8Ix9,(kǪ%9 ~|jAZ-0x)CmFK- Ѡj4-6$B1R ~}NB튇P\ѱ bsp%#sV6@eVm}0_oM@#/?EZOҒ}6v4q\2S>btCZYn]]4#[aLNB'W0.iGdۙ?@)],uY%ojܯIhBpXj[kl6wY$JŌ(nH7\U-^6H+H ;̹Snp#e*l٧Qncג[Q#]ajC^ P8kN;=mpz^vYfUv{}׋'8W M>ME eYI&7f Pc8DM,D?vBSцT:!3x!ܑO;~YתR3eysј=Lcm?~$ TdX e_ZIWkW?N0w0L j!:11*$jao.(p҈yZ8B!`v\P+@)Bͼw6& }UY7v3NU;n'Gm^_C+&b$0sN9 !_6D_zP 1M=o[:xh"9:'gx_Ý}U霷ڕotgc/' 0%|\fuT=|XNaZW{HWVr>/LJpo~qhkZw' 2'Ų58<€ x=yiN*6N#~}VQ=''%G퓤- CiИ1pM]tmtBɨoLd/# %!c~ME;lBώ8RmO$O}h;ʄ~qO6l'N_,ܽCzwPF ǐl@<ln)M XHJm{l2zmKc$#PHsm'+ $ן胧zn9!s[ ǯ$9[kwno~"EMn `VYGl,wGcD~92ѵ>U镾s I_ȹX.U)"O o4 h^R"8)%uQM 2@n"'~;aIw0ڝ•nL yYsHX}w?t#Ƥ1ߝ$ۈO&dWjZtR@e +񽄴߫"% E c,i35Prh PO^-P:rn J W'̏worzw8ۭ`+p[entv[+R5p$y/'gV3[A2m/3F0Y| 2sq:b ՘hy|0 Iݾ`lnp_\@Pr "3ƐI 7s{a :\BdR9PK9Q5]lDŽ1pIڷ> JdTD6OoNG4Ĩr34"[ $J}D H5+sjhU~.S#z y@#%CW=w; %m{a~G1嫼2UxHT9pC` wNGW.&rDOAΈ2 MOmL_b_©v(|U`5Se )Hq*^ׇlKOi7AK@1[e 6(fI^&s:<Rآק!`q#ڀW }| yd.i~=DDDHnc oEEʥƢx,)ه6vB}!P _2]Sl)C}C<VNWÆuN8ĥ@v/f.NZ߷+=uSXeʶw]4bЃ]>M]y5jG]#4nS&ǾE6'~5Ft-Pu~e.{+ɞ؁Y3tqns6@O`#a]L{o+06ODoY|e )K[V8lj@L: `.qj~'8FܲCCh {\mc˜]Cl W?kEsr{tU=V-;9s_GJclhӣJ(\M'oJޱO dSc({U@ 缭˗V_@LƠr阢1-Xf9a6oϾ_APRA_6ssl[< G_!qR>!vS.6ydiycQ [ 0 Z *'2;.RKNa͵c&%hZ" vbhZ֍<w ?z; }m7S|IzĈčrI+N5,_ 0}'y;ziaRkO I󡌞.J;Q{#7V^SWY.bVQR . !Kk)UH4%YEfCQqDz;4huQļ&j/ƒ'\QF/Sy3YurRQssp4/BlA4*k ZhUGI#};>Y+\X!>VnROF@E%~'{ G TQ 8d`1p/eD4!RagF"RMҶ 5WMCxմjqJ[]22mLJ$RJ5(\8;mXŢ mʎ "M2ׇo[%OPwEۯt,=v}P) jWٲA)qo 3$j;c U&{l)nQfFʌ7k! uc[j>ɔ̿Z m#~9VT\{kTWnxqQ#6$R^9цDV¡x_lĂ7gES1ID !x<$D[Vzzd?m CltË8,q_#*/$G$KBI$\hbY?^X-EE1c|I c>f2t9[$z_yU! l>x#m:yjaåk"89gճ,O7˚L/09 hRAڒL: _kIiY3u=V"ʕq՘}R2))w?h>OYpq-g&V3>BJ}`+>Imgc|j@G@}HSR;K4݅⦁?Md mDاpxz~ S} `ڂWYFs1=f:W(" p:͕T2"itcn[.?p>)'fJ˒s"ګU C'w͔FZ+[xE)5y,&n-S;4:YNVx EH0M1"jTJ3Iky L V5S7DAu_8*fSjV:rǃ谹e9vzlm$1 ;?Ӷ,,>~}PsJG Y0$&pB>&} 'QHu6&l0Ⱥ&gT,?uNJfp~w)xMj l 9^|O$cvЎg ѣ9Re_:Z&W T![P4ـX`͹oa,= !3uc/hچVP%TYN}4!vn) F$%x\($9ޘll極\{M\!S9Z.x#6%c$H%as>DaL/_!"$>Z7W\yѺ+ ;6Q7hQ]-,r3[ou;xĘs ; طӒ^ue4ȿ;~!;x7Wf?9dn!o'¶V܎,555lh8i^3=`p|uZdۣ"yӔ^=Ho(p^/K|+H9ZwXcW VKvRŐ/Ik6n!ݾYZiP0E=i>1@(l7]x H녀kv 5[: IoJ[A͙g )T<< /|hSqkk+vÙ-.fs#O8*^fE%bygQw江؊w?:Pm30^m?񖦩3{ FI ;%Y (y3OWyJG{Y>y%9/PMߒ `N:$хyDӤQ):Bu!5 ZT̨T"ⴄ:18ma^1>Dq|蕾_Ɂw+ \h ]oGqH ;,>aV51DV8X:u{D=-ˍ~D<]eTir0VHzѹd[kc"m[2 ꀳMޭ92z8vR'`,ul?1_b&P4c`1gC?,dE_GsHYA!ζd 5^}E.;Kʞ6jNW_'K~32(Hsx}QzuC|F[ȗe}ؤ}IVjT33ib+6`VQr +n81up$kDl &> xvMpg:I.F:_"{Ȓ8&a8CXf[*ީ肙qfXJZ"/ ZH?TWyjԁ2dGA9x~w%+댄bj҆[iN#t%ǵ4 6"WdTA˨ 5 ˤ&IQ6ltUǎQ{@c8D b{CX^7M-5װh"|A(&@&Ɲ}6 /0`Cw^>6ӾpN}-YAc^<)@I⽏BEW6`),5zH<%S[xt.M[եuoQp\k% 󛅆ѱg7y]LLXxPc-KoV aŘ@3/*ܔuIt&z%˙xߨHELHMlwh\|nŚ4'4 İ5隻 7nDy$ۑ,0cs\lU1c½nx:m|TbA.0᭎ 6r^0kYYDmmӯ~Yj H ;dN%"o pM32T٪| @ю?qœ)17w(ہs6Gm|51A]Y[T?5a\rI! iOhukORW|`ݷYPTV} nY,Y鶸"[=]ÚOl(}xsw(;=ޞWI {!L#X9D#PցSҿ^=@-r _J#r\⻲@l*޹_s3i#/ Syx2=%Yz s&2_f wD\9'⢒ ;B_ @9oԁZm~zEi&p IGL?BjL]duo׋&N|GLFC?\(lXOb{=l*ĵ7%2^ MvI% p(f o8gᬃM`ֹEo~K>?/7'uM2Kb |$L(0B dBЅG\s*|^MN|ϬDD)k` d!@R#A?Ahh1}ݪRm5R؃P<~uys0{Μ| Iתp/0ho 4+vzvl&NU i=[ֺ2DPw%AFK$zb`{22V+`6B9 \ZiVd0]R1 * DNi9fj˷RIe{cH?%]3'QM7X&#ϑMoai<`e(}&fzj!;M]%KRL8,YXgyl?m&2ƒ1/9xGǎb5,gh)lt~<@kS#ԙ=t+$ Rk?+6a.Nx?igL4QNroBng*'`QO))hm^)Sށ<=,qo?w)׺6+`2lYW׮g#I h\*MԽCGî!G0r^jJq[l1> UUeZul%E\L<*AJ rޘR f_"]ZTrQ j.>[椋{QjQ1i.FݶFZe*ߚEOx)w"^; G"E5<p9_mxE-ypyu)>N-+4⪔_KP&Ał:=LezYG?uF>ߘƌҦ9+nVFoO׺ ɇNXm' +a[0F ;؇NPN_JP9mtpW6"yl,;kvf8Ķ>Ó%kǤsV:,S0P'a@dKٛ?f1</DC˞]e ea܆RSX/4E#سcT!_~oVyI&- 65P>x;]p:fdUe5&%n= 6㎳q^C:&85BQUԽRÞ7+-5x,͐l -}3P}{Dw0 Rl|H"(tZ_L*Św8&\* e?kt- >..2Sr2vyY{@¶'"`1 tp +Cdm[ޤئ쌳gÉY|# \GlIYAbn<hNBҫ>&r6/p̨yyI|!~`yE{ )H:2=dE!6r/qnZ9FBmIF~I13DP&RÒ! ˋ 6.oEg'6.55A]ˇ"'hjV62!foIح& ǬK¹{y^A?[$0bLn(}|s[C29ӽZEQxٲQC42gN#_KA&0 ۛ9vfWyM@McL ȸD/+4mX%%'5\ 3X__T3\IXNwX>×\f!W]ksRZ6΂jT1_d*iSI5Y|(zd%Q` mug/ӵx5w:8 ykwrANe'Sݴ^=Rє8.^˜m:,1fCa=|3qD{L1-oKu"sQzQ&hY#&v8SY#s!E&Xr\fl,(۲`yH-!nmܛN)gEEgaD-?CPI".A>Hm9'"j@qmL?P`I3n z&uzN]m>H 0VP4pP(3UP6<p7Z[h-l{mаj4^s]/E<4rq g1@:5-˙>-ӥҒEy+ buETC.m@ YݎDK&EArq fK٨<9bJޢ4#0Fy88(ԩZT|5%΁|M(0D ]Q9j#(˰qI 7Tr#n$ z`h|dU##{X/!Tf0g;buE!u} uXRf(*.cGu;>ݾkF<$iO!Uy/6FЩȱjU[CMmZ~M4q01g6i8\^Pl _Ei;mҏu~s//Eo M) u/EcX<2k]Fj9߄hkBwCBڮ3ZxnI#$y_ Z7 Ŗ=?n=q(MI^rı8qﵶx}Q`e!{tRc#[~ e$XF/-|$QK!PWw4b$M!uCR1yLx4K^5wky. Un[8|( 3O$%lB0`cs"("rgPP:R*!-e0 ,Myxr ג?'Lu@s^m$_O&g8}#׊!aK}1 QtFh[WS?4^3r/Q-Î-6 kPb22NuН'nPm:?RVʥ3WDQڤ̂~>[jҕЭف ur082BFe:̠wطJ ~o M+ުLLPZI( TOЧd=.{HHy+WS.My˩3 vq6^ ƶ̾'O1L>ڼ9{DD'LoU+xJvK?) sME;ul^z~m.V6>T#ygP \mL.0u~L^=:a:&I&.@@ jr¯ս o?"w6w}HF0[0l&dڝByy:Bk٨! mFk+e錸h$W^&Xh5j]㪖i> Cܟ0HUK p@E_Q:.>{4qT[}p+0+sFM潴62WaX[ea@6V |-fz(c8iFĽđ7nNǦnemK) %wћMzBR\~ c1%ps6@w؊xv3%$7UÖԶas_B>=ԹWEA$omo"p7ڱJi{?A#i#D#>GkagSk(( FQj!OG|6`[I&–J|XM׵ {fEe+M*32BdZ )pq7֘%oV|p/\.AOd㭳 m2tޏ|.؄FytU qN*&<%". rNũ{Bgft8)A/IL}\Ұ.4/Eh|fbT>C82@E5oͽI]O&a(Y(4U'ҋ(z}`ϖ #(]S4fEAXsp;ʾ[:$`f&Rh2?xFG)YVogm5ξ& @ 7duJ>y "Grt=_orL@|bFqO˗Hʺp!O儽i2u63ǔ{E*^Lvdž,B, sIWyCgǟ'a^hG4UE 6,~L܊j3ՀmdOQ rX%=\v"%!k3x1JE+~b P”Dʙ^ʘ fi,)_|1eVAolSIACcô_!ugLy3,tsMN/䖥iyX?Uޓ?zWvm7d)59t‡;= id A8nKa 'v8Y1]v`%3xi奄Ũ$a$@UT#!w _TAg (m5ͪ 4)oH~yxrYlo#vKMdiV<B'qŕ/E;p9q h J>xk9j.p Ү)^NU&Qqt8bڂ8}/εZU[pgJf1ƓA>\šUNYAЂx %1Br~X%Jv tG(OT#9~*[ ah邦|>b &.#x v-BOXms']) eDnz.P>4W Y9>)[}Xpr~Vv_vFV澁Hyvb(Ԥqu`SpG^@~@eّ; Yѩ&SI[YG2[}v[/(:3_>H['$tKzDYa7iGWv`Ȋ֢QtޥB& lL|9 K,PAFrč7""P#jWUuE .T$ݔ[,lԨPhR;= xw/SԮ+񦇴[DY8(z㖻^KޞcBNUKS'4tE`-JHfLd@]5 娽Q7%+C1 >)ZwT&r-''<Xt E#ueeXdK#Ʋ*'w478ŁFً: B-X[;AN~?M(x\ oQ^qe7%Fhu%Xh$R:b=Y)nOD f(& ūEohHllP΂SlؘVe Ig\a?\ +v ﯠ$ zYC0!.Şg0)AX6Tv)f?l4; ʨtpL+A G\]&*hcZ)o4shSS' xpU)ppy{mfgҘq ts J:=XgkRϝ :͕@VP*LAGmobV' /Gߚ^Ҝ 5 ^'x",YLsHʾh;xeKey ]l%@-;g2(wu:\xN }{ f&ل ʤ# #lVB:z^4CG@EgWh`o,Dy ME4sꭇ XLh,#8[ܞh h%ls[? ;i&A!J}BX٧@7 ".}\@ ._nZBW[YW]:6aX/i~kzo*~YALn{a?ɸs/󤦾p9=!E߰bx$0flc)ۊGcYk>03:C5[k;$%AKfOvl(b4an":q9IhXo!F,A9YC~ހN"bsSSۚGUHZڞ"b3!ܰt;-<~qGb!K"2 Hs-oaPmQ ֦Q=3fg.pAWmrrPDjtfܣԁ4v#H}|IH* KL`N\:mSs5s~0+5~+<] %7p%瘑} /A$ЯvhM(f8O*H!pm~ /rj MM?I.h2*qIUh=sIt+~'lW+nLmiuv:LV]؎g/xKZt`[SU\7&ZD9Y>6TR*jͲl?z5Un1"K$خ?JYޱM{n#"m1mc8L7:X9w#mr^T{AEYMniMzRŏC~ʷ2yTNs(x%?4`<& J<vhlr>l~sZx{)GjC)Q.ƫdG29yKAe;y0{865/Q¬:2M)o B.WvBjjv_Oaw9J|FSJ oERckjnݿb'% N>zǹHx} #' i_p&*;Y0p66?mU+ώg/ I(zS鈋!"%* Nzŵ͌urR;b cۜmPqrA΍ Lg骊5\uR]) L[q@ g?MTÅ.ANX n~&I{zyT3| >!y{1~hp, W8Wm,HoOI%-{kmDd/+RߔzEՍv 辳4(z[zƒc8nDe0 i#0`~P.v(~8hMf~\)Dn# uPiT0), -)A+W[ Roߑ9m\قEn#ڽ lJWCQ+WQG^βuJ5g ؓYLZNrk57Bhc-ECd=$ɽ#Qx!  [c"m`ДLL"[({.#[T4m!`oTXDT~Ygyډ?/' WL7{RG\I/^*p%C$pC'+L%@@dKr4Wֆ0ϓ'ɞŗ͞ Inֳr`0nǎF!faw~'[J y"C֤ D(u#G|G.:atT1Ȉ  ,ghxml=oq [ x}uǶ]ZJi)!k,sG0R*}F(dՒEHdOq*.Zd'a@?]j:ǺF Ȧ ɖ|}EH4첩[^S)8[67e=?a.jlA_*`FG@9sX "F`9Q޻/DODI()mYt{Ӛ=<훽 _j: x6~-R2& tR(}́g^O puӮ96ICTbM=5 <6ɪ;!wv ;Iq`˸d!ܳcZ%VBߧEs@?Z@Yapǝ}M&yco(dJ'C@MZ_,VlO$w_ @i$m73/ /Am +)|/auD"Eьd~O$bsҏ@ivֆc9s1y/)1tlYG ۿ0,H)̾ c`#HbAK@&j')qm?39S98-=`|_YӞڛF7qL11KP?q)Mq!gJ$ێ[k%dfAI-bP:㢊 rFzGZ{]nL")Ӈ%\(;bp[UYcj11 Boe5ңxAmH?:?v%e;c@UwrJ:Uڑˑ`-oC|Й:0Xˡ˼DrzfWưIo2Af'UdmCvgpWGi{o# UgϜ8XbohRt`Dha~pDN5\yʁͿvgGfѺБi%iբo^缽F )f4Q5.+8ajW]mIi>E,7Tg;`UFs]7)84^7jLl@mOc@Y~ 8*AC(Qd#:jjރ-JDn8 [`f|X? T?&:?6Gޫ(.CQzri9>!r| sܺHI8@p߱uwd%ŔpQ2o}nA %Ժ>\ձaI]0WN_st.ixܿϠdFVI8}H`Khj0=V@V1e.T#7qFMSE3:oHLbZ7'q~$*q_=c=V 5"!}VH4B#6BCS:>ݞN4?E8[30O͙1Pjk LX1v\lN%:BiZd8=Phu->-OoM2)Lk.T=ib^zk'5FVR@D'(QLnA<ա;x'4᪈_٠Era9a14Gu(wov U^ٖJtR?1>޹u\n12 CJkDqBWiQ~o{20 ݍp5 +hVU&mWThB~&[N|OCz-d3ȷ (.SOmkPSpĐT8l)GN_RVM0"A( zwW,5山Ki,V1G?z Dy ГR.Dx Sc0v}X&/MK)* n?!܅5A>3f^H#l[Vm|6/2B#1_$|;Cn.Bg $Ynٯyt#?"fsd[X:t7ZnBK5nIJh#f|>%w̅5h>A2+x;X?rA g Cvq P<0)]=SVuoVt@f(L-d1ЏatNq*dƽȎq;|0O՚f 6B b=< pի6 s>=Ŷ/2ŅWse}#u{H#b 8S&O༉IUI#iϬL㞙\*ґL;^.KKZ/ Pޛ|?)*oJ`*bS}:YFJ^R~~dj`:nr@lW y$pɧFf5^c4^` %(Ψt /nSgaoK\܈7dMFFYя V!Zs}!>k^"b 6?bĜǛS!?tܳ%M'ɱo&/e6 kn]qN ~)b0*a.pIpA-w]V^U,=b%a0]Ea0沐pPivag"lF}wQJX).SKTA-wy~%wb(#8l}[E_Pc&Gm6<Ŀr1]T}(FkgTP!׻8w(}2He$J/^&+CG仫H`MTR[D!,qwɷG6ұ(i&Fם.x#lAzqÕ}1ߚrT 4fEo6WUݭW{J[$oKEϰe+f+[ȲŊyHy+wj!H#&S+7z.7|[_&>/tNp➣p5va\ѧqW $YdipՇ{ f#/-%pX/ǨZ݊D*B1_5ϲ 6GΤug7{6rQgo[S$IJ<_TS=z%,S9xTFo2&mֶǣzLÓ7 )/"Rڡ귉ZNNG-(B&åǢ^V}FZ}.;IEuAfNǣEp9[nBfVGӢ!ۑgs8.Q8$AMp4j&ym."KF􉕪Ǘn FU'w j>fSf͆ԁ4X]MƅR 2.VθnKԪܱO{m2 LQez"{71b$g\kXr]ά#:Sؙ~[oK۫[i!{NIcQBcC|qc0{ ebBygNpET*w . Ͽj: /P!_=#*}A2qB; fE)Uz:a4sc ._{C\(0[PLΩ|s̰I"{tTK.Z=3B7C2l74ӸtԻu)BՉ8sY"f•g.՟ڇmOp^ zUꔀHel\#! tSzD.cuLt$sxiyaǔw] |P!ﴽd>rX^;ev/.OȲȂ_ڶFd; cƄK2e70) բoގBf)JસL߷(V{:O_ØsT~TT!h)os":&#F $bGuT\%l A1>ΑmWKKL)xrDk[%Gm92btYn]#ɚxKnuQBm7""m4.`G -£Kipn{N*IAl/\JJG$\w1rۛWȝΝR{A[$@xs,E{zhc] 8ͽYjadҪ9 f~GnMͣR b/?'d>app?,TOBaݳc2Β`/βm[BDú B 8vxp~W:EE+q|Īy"CN4 ?ï4A#4&A^>v{㻥Ϡ,OF_f/YNON,қW C|Ib$ PG+7b=|@ 6.Y=%LxܖFJ]rb"JHyB<M{YR kgV\ƔaBs Î8ʅ/}8{潈O3oDQb>A S'+rp/8 Gn2jC3Uq1j;;ck&lAʴo]57 (O?Dv?pcwv><8oKwS$[ hݖѴAՄWBh.<3Pz$4ApK)7ap: BJƖxʄ7:TxO(]}Oj -I@>bXok/[I-ꀄj>~Dn] 90Œ"iwpDqϛ(9 r I㾫$49Ӑ4Ye|HzH3dh1) 5 = Ԗ@o}θ_OezAz.A 8&؎7aª8t0^`:rҖmLp`͠R6]Ex[0/tۏN=߫") s=h r0OP %@qY\}&2a,SJA>.T\ q[u(|˺GЮi%] _jAw/"VDIAø.raaN'd܁VCڦXEEm,y\N3m.Jw7_[GЍܡiǮLJ]H|[G̏Ei)hۏ1oVU1jtE#}I1J~|e3!i697Bz-e3з'd0xOnVRKݘ\0p=rK,t޷F屈wcȬf ;J< -#.Wo<i U/9–kZ_Z m܏)% kM(/ؽbnlu&nk^/N)bvMS/W?3dZ1fts/!aQb1H$Ofzor_T؈63FMf$&"źߊVpwp=le,If.nS~d9lˤu poF5kf~-q$FnA(GY"(^Ņj*"Kmcl{zpZ%8[:=yoC}wԫx?Pɴor6wäd6BOq6x;d=Umalha Dme}s$U)('bM5G^Hu3ZM1 y6OJ(cV[:.5PwDTkk_Il~IYsew;ݑSaCV,0 k^U ZX DVd:šf ?BER31~>1Œu?Ġ/mz)y7Q~hmYh Q( F#X4—J69&W╘P8 <⭸Wc ^M8"gb^g}as%NʼnFq,Wm<0$7GMx?]Uth+X«3 ; m*#2&:?fU ]̕-G#c9] k ^]L@˚@`~bLщ\ d1ͫNBi4ݥ)Ik(n40_Th3heaCRЊK!SNLGJfds{=UYGD+!f&O`< fKZiɷmD٢P/ZhJb,8(b>(3$ڌHuӔj6_*TVj0"J2΅'?jL9岀fbCw' T* qm_Ư Yѕ@$0j`U { 3GpaKw=ءqLje3ha j3edslz>Gnt"@|lU7_6? ӟKSؒ?ߋɊI%)HMNi~͸l.e ]ϽO=3c| P{huۻލz*z m=Os61]:," 2s1ch`(͈C*mXraFG{ѝD >ESc]ޫ*EemGIb|/ T]H? Hw5S  AGKueF"5{9 IBh7Xw9b=ž9Z(N/OXj5>WY+ƨFHHNҌ*(dD]hZl~KC$MdȒbܵ1 wpc ޭ庹zNؘ#Q^"_zE= 1{uCr to-x#Tҁ\2WTJ8, a`T:/@=`%$.тm貓uݬ &4""d|2)[ rqЋ[p*Oql9p2UmŦ}ښ8ǵ^K$tVNLG^Y>[L$p^8szB"!$G[=Cem2߳rI`l{wt$vF)\\>}0_XS Gpr0x ߾ 0"bq5й.+p5vK?ZuC* -!¬ےGOC\_wKpPm`SD(iMv:=}fU7~5f X`UR1bW2P|w譀Q<$x>Wu 9JEJS, ÔaBtdl8zhޜȌl{nGvAlɂÕ- q&YXdTnr@ï~*d$mψPO\5j+A0 :40u;A:fKWI3snG@QR:EvU/M&.Jj(Ƈ:wc\;gb;6c0!J~uֹy-ùFGUZu iA;!Ci>UF(@lY(4xnkVZO>B2S/x+/$Elѕ'zZaXs[t*1WС{fa{$w̫`Z-zGGcI/ 7k8WbDhqaZQZrnP0;fT.F5g#?-"`\ BbT$b1Z`Zğ9)>%8MvLoca] m@72 " uGL"?{Ffx?q >(+JO*!'K^?|nih>Ƣԣ*xvcHK^ձ*VUGbMsUc-tk4M ?)9["cv Ry3`# 7?Ouݎdߢp(oE m,{Uj 'ӬI|,09S%avNWQ)y@LV}MX m`z\Rhm` S`Kޖë%-oNaOVVӻLf QQ|q窚[d%Xfg.G?=Er/)vg K5Ȳ)`/h{'~r < 4gZܘ F}G* vH`wbOp!Z4g},/?U٘yU?c~mh[Q;>>o, '̕O`Sw7cF"I(UiݨGѭ?;s# A%kIȫe,ɼ~TgJ?j٭%–&7ihKeQ{ȀqW&_yoݏ+>>o# USkF#ȭ.V7X?Gםx `n@(y-\wC5? K4gh-O3o*X_oXJ!U@J֢E%= ];=ѥ=πmij1KLOO?^kB_ 8wMnsT-]I7G>F8uexfa1Amf.uxS8n%iE`UϾpCR[Hk_wȀJE= )6jK) BE)3p#/0_R '[&甆[{smSlmhNCsȽT&2*ߟH1H }1 8=tp0|`J6]/lN2.̐q YlRC'^ 5 vrntHJ3t#ّ%mPe?I*c5EO:PЧ;?7"nۡ40vkaفssm IIf5ٲ(L&"78C'ǚW,;@jXLIesb[ صnmeiasG0WGpvkЯdil_4`Ω}<hJ7ZVmq8;eI~D<;;"𰏅8ZvNV%rMq_CjM*LG*YZz|qKnG٥\&uh}@Ut[o$U%mOSh/#"͐Q5w$z_J&ΘBPK6ɪq2INO]\y a\Dʖ}56#iЮlґdVUt.qɂz2v`x&1aw<65&Xx:9/TFwor"R%rjy"$D|}:/^>1ar߂ 8HS=F32\ sͷ2콍yv24 #'-O"̞ >*1WX9\'1w;~r9xedy.>C)znizT? =TlAb9O FS >汹raJm dx.n$itDْĒ?ɱNPej*[aE-%O gtUi Z7\h(60P x"igxXr8Vw`[XIv~Dr/4#ܰB6a!UQ[#UU< yjIYhÍsG$O+9'8\t83N9(ZB&_dqmI" (X!~oiғR'AD œ%Ya` uW5ՈKc'",c MS>ɜCJ1aBJO!1]\aILC05a'!0bCطCN4Sz*C69JYd~EmrR,Q` gk: a*85Sw:fפ]W88σ{dS Ug'Ĵm1"}ƊƄp$]i[yj";?;S# qkMʭ8w-zhJ֦:0v(iδu .ӂhۏ)IjgL1F?)EF:c[+vt +{ U%#i*s\\&?43!҃I)']&p^.ydZf/y "\ ӻT)S٘Oc=]϶qHnA=ptEkC5/5'Yn')XI `UWm'y%كB{&+ wH39G|N K?{#} = FC W[MwlPΘeez7hEm$1oD(i EҘ|`sv&"NkFJJޜ y+QdґБ㱤P:qL`)pIiܺd:TT0G>jy&m?q'PVD'j3x ]R ].҈C`u/޾v)_+w*3 5oz>mW5FJ90FkGjoKbb8< +}XE㓰^k-Ky{I1M>GLĥ g,k n#W4oo~Uc\:4};3fgTg29cA?kߥhPn' >ƒclҀ'JGgPFp۫ &4t}MR.BĦJwcMg5[Ze:'m=9;iBOʦ9q]?$o ʬ<[sik  \ $)<T|KwTsfgaL\`h=NQ>2ڔϭ}-,fVb2(n)yIUvW=4'[6_Vg\`ސA9'Q2٤87/k 9++ΊSn]bO;10ރ=Y\T:Ub8xpgLm k$jt.2Σ'+<{lRrN v;LmQg/摤?t5{EO|wc 4ᣌd BB^et !fICht YA7Q62]ᦊO(76]<%G&}O fqBB"c d¿, {d:m;l;r.+6kڞ 6ax'kȘ(5jEp5Ve[V֐#֦*={ f2A)oWHj5;6q%fhNC\5EVޣG,PЛa < {Ľ.<>ҵcܟ#1@M ,]ݟ0;e6a]gS4vqFB~;떀FJ6'?vYYiq,7^4?I֔E_ gͶm6SVG: ĩT:;g{l*E-" zGcԕ6}nGXYcIRE8Ԝx˸+Ovѡ㲹؆MX80``1{JSW.9>MǼt^4,k*;94/ Kø}H8;(x@RqiM⭵=Bi4("{U *dK0[i;*\XGnשD;ް,f hƲM X7#uj'yszcZka%gmTFKƴvdr8X#  Wҥ96ȈɈ4FG3Mo )Qj'm =^Q%tEdb)fo?5Y?)eTL+>OǗBsǚA)f$X|ȽE K>F=QDjp[d(*M0-С8X&GD=,'e蒄 :i{Wu0q:RU, @8y阺*4;qڇ ƽUg hgFݾ&FZ.Uo FSqv5_>QN%Bhdu E >Qd+kRU\mVO?\`A@Jkj`MX֗ վQBդ 2Tt;ޏҨNH*(ӖL5T=BA>h?PY=y1VLJ?FqW)298Y]CYci#fK3B^&MȻL/4R4ǜs]*G#PA9'K<(( =}5uGvEsdC2HVKtVCzv3{Snux[4lpsblLg^U&jʗ^Ѐ/ vT%9鶲iP+mRq |G hj6zѺ%3M. F z)$"TU#4y@5Vٱ]Ȏo^ f }꩖ҽ/#hQ ܟ;?W s2]r\_D_,U%&^.>Yۏ |?jRth?Lp>o=4KOO!K ?Q刡,)XϾ첸Q+UK] SꩨU(RYZ[%:XFf^5WnB& ]0@;Pd,Io飐} "r4hIF3Ϋ&aIgW_Ƈ;rw$A},%rv 9 _CxY:%L<:ps'Vmz.O37/+Ю*{-'< Ɇ&!gC2<1`1KcjX ~ul VƻA`Y`(Q[2`) Ş豀.۰ ޡ4%G6͉f2bnfx֤Hp YP&vY0v9jS"#g\nv" 7MsIdccߡ,.nҌ>l)=j]",vR59-N:_~au=j.eއ̿9zQ AV> 8O%PTmDv2j%1$Ĭ*!u{-DDPAv>J<: xHUBpx,8#W+ HDZ){ޗƘD ; 76Ld{5K:iPv7ᓓc=Y1/c#(Lݖr蒲!C y}L\ a¹!!8Wo>;T>wy@ɞR Mn¡ MYmCFњTBsqVvOҟq[t*YY#4мEMVgz\cϰB# oV,1\<(Dbr-ܤ#m_b3gl%i!͂OR}  wxúP.UyQxr8&P*}|6`>uYղ k?jjTEӢ,\m@@wDO8?0I6m++k)1rʣ@,.7MW'UjE~X SCDƧ⪍L>Ülזd4Ƅ壻-{Ow K)4a`V_>ilj5W@@HF:To3%kJoGEl8+@c(gF|,:?NiP*7-SOXUja 6=eΟˈ(9c߻1x#1׻nnB1c5l D9/a+J29AK~1kWe1k;X2fz\SWnj_ T33|ꌐz[o[Tgv%_;/[RMcMʠ)c#m̐hViXzpynYsTys2)c>VT2E_;vGkX=|xX78Y5IT DlA\g2/ߘ tiXp""BJ~Bv%35vFGy Eb=e ׎=y! h*Y8%j**g Y??~7DV W&/pb?)p:Lu pt/#QJrion&]KwVwZŃho._qT&9ݰx&17ə+Na6]rxCT։|+?EwMwI9a\@/X1H;D#2![uC\`m^sʊQpԹ@ XhӝL uJq;k6ONJfaml+^j,LQ<@E/T`-"|$^^e*2en`'<˅nHd1X]EMj$ĝ/0!\N+^5}e]ĺ/`!ۓ"&CNq{U b.i X×Kv!.qx>+x<ݻkO$HU1}cyFRh8.!zZ6x3~7S)Bz4 8 `ڞf9՛>C2o Haqry]5v vZؔ3`L +BasQO5}E9+C_.[H/ ԁlqn-.ʫ_"&,핧)Vy0 Ms"EpȞݚm>P (Cjڞ0h*5mipXw/FH IrUPGc|(R LX¹h>g~ty`3;!,-j~AR?6tDUG[հJ}8pkMOv`Tam6dyn #2G8eD@`<;^* B,^.~{%瀸QeHgXUZvh줹VjԁpDZR05mwaJڥe3?yTYbj#'_pke٪37lRs{gឫnYJ%<.ݙ{GmA4,a[$E]ю9(*aY͂xtY!Րm__ǒh.wtߧg+JANםKMwZ-փ_zj[oRTtX

xOO ^$ 'ZT Tf Yغs`sƼ9P``)W^Cأ'kTVp~ҥ| f—;H. `,zrkAH~*%y2lQR,Qݙ{Ukѕhwh_G7 utyj!AڥMcS2U_Mb*n+^W-R7ٽ̏zOJ5:@S8"O;LŸU2a$FF! B(Jn!mTA;-oEf\\66R.}:8! Ŏ3_F0;}`Zn蔫<`dGj9c˟!zAL:jlv? $Jz钮|4)]\_ xB,?46fτ4~^) [x;h 'ͤz۷mtZo.g Xq= ?wOrU/1\!VÿOEۙt96q.BgT3zZ5̖0@bnpzhgpB2]yV5c-blAS75z%FH- KvtN!KƈNTtfI^-Z+v4Te3ΕC"8SHnG=%oKz]T ݜsW": D z*ٔ.{3icWq-trxu ;n*ey2cF<ٵusb74KGd)PKX,XP+I(QF0]J"a/|SͳuCM.i1*\N|eyOME*$߆(DQOu?,r 6vcN-]v~dhTn3 ] a"(S`^ )^[i?Fx}`mYs`6P|IC堉E<V?0RozNv1wYŠ4X+Ҥ;šV:Úh?Yo.0kbe1襥OPSEDWn4Y ̎7MO߇"? Ԝ'@"ϫsxN&@-4\5\2CSg"H9 Rẅ3 ÆgzcVIj18-VD~3r:{ڬ4BU!=@SkEoK*Ä,<ft^l.0mv){.o9ROg]cU8?ۋH v}5{3.ض-=Eu(oakf¹[xCT Jp<4{ [\[3 `&{jF:Ot8ޫ1 Xbyp=նef"x8]SȗazLT>.(6{)J\$e2s('8 #ԩp}!]pY=ƒQ,L ^ a!&~҄+3gAIU\{L|bU'=ܼz2ӳΌ_ZG;fC?s,q\ɮ9 vJ' l5\T[1ȇi,Z&Nz K$`ׂ*{WWL>%BpsA"=9X򠊠7N\/yǪjg0Bhdȟ-#B (WRѤ,f;w:wP KI{is/(|WnКJx_o9@e9DpG!959Y ~eVo¥ٗ aI s /_t"nj8~V WfG.yh` d"& ew44ygPl|[+ku**/8 =ѿP\Ŏ+N8-KHC xIs$j(`˲ԇL5.K=6>! 9MFaXO*)b]zweT m"YC 8hk̲Pim#haPpxL/y>}@XP})x5!C w . X&S^I$y;w77YZ44q_kX#sɊ𵅾4d(MGP2V]dmV]?Ů Z.\ߡ @%Se;_NJc<ԉZ̧A "u>z]|I +S!sbuKg{: *)[Oz7 m-ډfDUhWON"mey}2.Y-JOA(SFpohw$'tRgr0u+^s^֬Kzp6$5=.*˛Y|k$Mx7&G\19\و2:x~5jBWVcʌc!fRY~#SqӇtuq_{:bN_ )vkߣMGBR Qɘٺւ _G$΋iYgԛĞ I)͡Eg.yhʱˈy[Tpƨ<`xQR(U;0.aBcqR\w6CPo~:'8(耈l j"yi{0ԦãGapHpppSbUZiFBzO[<.ъ\$gf@>ĖcZ2גeo׺4ܷ=`W;rDHIv4;ih)upab0vut1k4R2DK<1){`&ga6Cxr6Y|:U>Q_]Mg{LS\4%d2MϽTؗ"_wH#==.؈]m1gqݪ!4\KCxFhҌVj\k%ZlT, v>μy"մogy%K ˆRA *>[Ľqȓ14=W W1q}zۉV{8yiPH}ϒ ZxJR>d~#veh t/,Y/yRvҾ[f6tGUE`Vέ&~\}LQrѷ@MG%f/}z gH4iOD%; ^_`x'ă,݅Y>Ru p6ņ(G" /=x{Cʺ | !;?ViS[O8p9=Hw*L:1K[ Lzp/A͈^YՐ6Rr6" S|ȼ;W"3}. L3,}͞%Ȧmb>S۞4s ퟖ킔u4Stv9q| d H@d) qCbKT"|s͋`K:}}UI)}9:@D\@ljǘ GD^( BkE8BYwE_!ߟ{|}+(G,qOxXaȨKn?VW:g76| P R%αcmw7+.gc6-Xt %5YdgoZYV5'mȭB!u[kaI{B_B,; 5l叅ҕvZu|]8@aFؐsY/!# W/RQF&/ ?8&p8E_qqfHHSt~)@#.^e،q`nA< W#t-R%CO}ZB\Ȅ`ÅU>HA}f2efzeF> @M79 %I;Xgʼn)cˉydqN}υp:ι8G/oeF[ʡ,o!NWV b~7l\2T:/rHvKeM SLIF%µxjbGؘ\ضoBmʝ*]88ΤM[ii9'􂍛vBfRt ^]]r ' TԚoq+C]0$3JC!eg4+[.0@1ޠ?ykbSDTS5KzШ ֫jϮ^ [zjN9إw՜2Y"jo@*9/;dڢl6t&Ӝr|M$[a~<~N 1 JP {YK\Ѻ7~IJc)[5H[xvCo ɠ_SZ?Y $\w+_ Bs(|&^+y'QMT4*K崗Jٙed2 |KuURW#"cTN7sITKMT}[#7I\-?NɾAbQyHWcy.:fy>ZrծaBܯbܛy;VwvctA^ѷ{/tЍĆyOZvylPSհKja_Ϩw-if]Li+Bq: 50lvӕaR(muiphU R[5 PdJtšǻ[쥸L/dZy Ʈ o6Sl;ء6'/6EA+'ѽ"xCfaN⁧`ri7v;Ip_,QHE&4 p,D>OѪ]ԧ fu| gaK*Tɴߊ=(Z"5EgN$m5x)ԁ~Y{/r-):6=Cl8:0|δ@{`nk]Fsxn7ʿ8TTPC7D/ 6؄iS{=W?J)M)vqEAYAc_ LOz{'jDd"<-NwqabYb*An,/…<3V"i~ëLn" tj6= ѣYk'I ڈɷ#K'TyXpbPh&|r >=rC ۨ49vO6AHM{n]wp_)pD7ھ[w/=gCMX^?P/?#XpL>,ubl4hz Vo:q1&x8Dިth0Ky~fzCd*pc29i}Svע'*#"-$,>C$pfgw؊_U``ĴﭣlI#]O6u"cqW< =A5n;ݴhKRN&P }d >֍8a0,$)fRگV`tRճ)9[ Pe1M.eybQV1WVJAH9"Q@$@`ulS%Y~qegؽe28=^n/vACA>jnƯ:SqoQ~;iÏdWwZ^zr7}֕Ozғ(DC7s誔|62@4ñGT~)ö8n=hau<㻼6.V_b)Xg%aQ#OjTf9JJ.k>^eV)6(Qi#q!4lQ8i vImQf1Z}c^o\~\ռ? ;kwøn"Qrp,̻m4#6sߞS;b D VloUea;5!0_l=wS)0׹w'L Ӊ>{܁^fĐ i5`nL(J?FY va.x>VXBxF|klU= 㢷Equbb`-ar)yUhwKoGh:{YC<)-Pdã`8C\dE\_gY{`!LO#:LC⹓H.زoCt)ݶT:!$/dN$B"ߓt &n?܎oJo[FxYA F.-b [%mJ441~@b&1'73h^I^829 Z؛~JKTZ0W`ET27M`]d]]{k؎[J<_ `~(K/G8"VneB94aq'Ŷ ! ֓L?f=fϼh>eUى8 Qs^gg5:LC$v_SEH׬}Ѓ5Jr孋E^ x]3ŔyGg嶧$dTf@YbSK~nꜯ峕iy DFR=$I>˽>D4h T>`hOs}%A9n?b.6%1BDC1ͻ,Bw3\rU0}6do?wU#8#(9ʃV~xģffh Tu.eg#{ GnKt̹\1L}O k8Z~b&_Tg2v_OX$_!Tv0sZ V$+ﱻ4q&{&;+lc+@=rD䠑0}-S կmcu"WdUZ44y>3Y%Ô_^s`|}>]L*!ɀ?Fl3_zs#tpd~T&G;CQT~ףUahLGZۗj- WY(lLlp}>8O6ĈgY?";.|EaPIH@ɁelgӟA5y݌1>,{DK2#;9^UGrwЮ(PIK@G ϋjBN2*~-BJv>~,U/ئK,Ouw`pB$<"$`g7Ggʕ-x>ff MybUJ1\[`-vt$D h1˗+=d|VfT}'naDA]+h`S`V^tmkp){d4 6щUSR6T5q:qߎR8_P{͗&@g?.epto"덅uq b"O|9ljT~>PqtVd[u,!mIΙQA4T.Q':D!9l4Oj *\ퟫT+Qmh ]z%XXWm<3x߼ YBRCWA9s$p}=y$VqoBO$ gڝ{/@]v8 ~2nI"[Ww8[&lݨ~]l =9# G A*01)Hc7wBb5I 73w])]ѕ{fI<fH#o2RGuC"?gFed l{NsF KQ* ~tKpbT"|Sp7v`+9@IRߪ f,hgAXHxQJۅ:;Neie,jiX46[ Ҏmq+Wu\2' K1AХ`)B1>et'ھ9uYKs^l5__"~5vwn+2BTńYЍzgzQU||`BC>(_œK2@}܌+PGd?_zSQ,[1{NP |IT\N'gt@^5F<5 d|gwlS 5/(N1T Y6-*j:" \`d#!EH&DD=;_1McjqE$r sAH 7+`UcҒ&L6T$"`w19D2ڌ u~G>$dZA|GxEg['6GN$/A)vԨ&VYULx,Lt"aC8%I^6PnDbh;8e?»>!V2u{p'G 㒩^3Z$d5FhTںU!: ĿP >j9CT$d9.&K|k p%ܔtlXc5% IЅ~ Dntfg&* D# HeAF6<=Mp5Cq {wg󝜢$Z``,%׃f%"4A>Gw1r8@⭄edkGaxڮN1@kPAIowNL0̟Fᱡ * 1t]͖)jAe$ŔA-';,?qmyO!U=1gafeﲞ+0dMQ@F1v[UD E-T%g=ΚP2eS%lɱIƃ<~L_=@ i'pϏWuʒn=9B0ԧ?6u ִ MCݠZY\=Q Yuۓ uV)hp-=W "a>sCB +hgILDQ?"1qn. Q:P7nhOv /s`߮8 ZnM$p 굨wٹ1LoBj6'~^m .|4Yb+U2MRʲ9e}Y!/TIiOEg>|S.z}GyhVqY3ƖaoĮq.C8oER.aV`Yf! _Fُ\O"FOuWe}FM f(WqQ)2frc97s =hkG0M3D40SOLtK(`ifiM~懈Wo_x_ :2}58 U^ץɭ/j]R B=q";;9/Yl_KADgNGh/F܍BV0b45V ']/ɧtgA vCV9mrG`/Ͳ.wO-Gv*gTJR5V,FHi9Ҹ*t Ǝ3Mi5#b߻Yw.vc)S D<0(.`"C}e[xRW\eSY=^MA0߇im֡adj58zUL1WK.Q+1p>ͩYA3ϤpS_.F!/%)GNa{d֮3:x[;>O%7`c338݀xQϷ[{]~ӌڧΐ;`= ,'7ߋ'']YUQWt˘za|tI9>s'LfoOU /߼Qz hhKFKr(unq$٭o?gtv.-s2f#=m-r ;8֩Z> YGDLh}N3.\FX s{2\y(Mi Y"U) BUPzǽUo+xs|fŲO?Cpߵ!i`.]:ʁ:rF4H%l@`2nȧs\1'WW"'li@e]Jenc^^)v&7-69a(OA3\gC/lB= 眛6tFNh6XdfuQhtZ{xˢ49H< Kk %r],j$֋-Sp{].=x(w^.(FjE$!=Yj/jqjE'4~{gy1G1FN\*L4u'EN>i`맚)|Tu ?dU7Bgzj7ri2 h5OT0kT-n̩eO-n`}wOV8`,pzkW֛ï.YZr;Xuo01laEoPuf2HⶣEd|h-d0a /r S3=~2`.p0D19p"+U7˵dSX|CqoI (Tjr˭i0yC4x?L~EW*(ޫvߒS ;QDI*`F ";Z9D[lp%/YjGRB$* M?Vϣsklyxxe/߫ :cxDza:٘믙\d.ԻU{Qu!{9-NWsdk,Dd4{u(p4X_I-wkʅ%\W(id$L<ۗtٷ8#N9 *,B*,o+i6:kJü-Dx"E!(8K͟˔U\dqun'OyRFA9 13 8Ө|8*{ RwѢ鏖FPYza!/o~i*^d$0bI2"I;TzQFG3 GV86OLY=F׈0n/QCdVg+] yhأru˃7a`yNujp`”< @lHM;ꓶ$cc34 w؅ԉv`[%M4R;¥UH|S.W# AK2fC2_^9I;ϖ,̀:j>56'KkYR7*X:&|b.sGF%_lwIkd\-4(*C^/|z`LfXViJR̉.p~`[N@gvOatrA߲D% n'PքKn!?X[uH] ҕGz+) ^ģEQ/KG} W-Y/"? C .*$H _BW>]G,H0aԗP]fvAMzfiEӇ&l9h!H_`o1lsz;"L{qd)VXHG'n+Kƒ"Oذw3aW _p/o#xY86P2nE360 Js;2[e(נ9$ SIq,\Q8Jpb<U| D"N= "plxQ}Ӻ~.;FsusSY^^ikycb ÿ /uDߓlY0em6aŽm>bUNW"dzWA nϨŞborP0X!}(7GpCcÇ"ZQ׶puͦEʿM!/ǼDH?lv?8G>) G 2pC[Sq.$W>VTÃh:v|(jVu)adOc <_O?m\WSێaaڬ?̀WL&ӯ.W@mRs}$0b9Z96MEOH9E?F vrd'ajF)khH1R%鎸U#"mubJmW^cY"^̬Rկhb D5ߐA8kR_ps>'gCȈ8cHTp!a)^M~Giۙrd=v`|Xm O6|b'poؠc>~4*A=D_:éѪdxʰAl#կ, %^`76:.w5ߧ),vjű wdzִ =!j?I޳;tE kJk;襎(n ӞnLV~ڐTp] qZ[^^$eQJCo[o,*|ԱN)I=~l7Z$ʧ`s" :M7Շ5='kf$J%8S3=pYO2~[;ŠӜĚ| (7lR}[^ᇌ w ^wfap B幣pTkF0RKY;k]_w{ uz)9s@$+(M f naisV?,-,8Z$b"tͅ)ۓ şFjۜސ'`e=/mlTLqHh٩4-ǯTH9 8%N4^Ue=9lnR+ >9рSއr>(Z j.O`*B룽3֌57m kT-[KV&I_E|E,$`eH~9:/ܒg)7< AZY&{ K3>S[{a"! _ov ^9 DT0I7 +( 0w5^ .\:G NZ#Dž3Dat70  *agS` Wc-BHGiFΊ!h ?0°i(ڼ XFeBk&vi@ٱl2E ^:@ BlfD[ÔZuHzoHbdA\ZĠ*<䜁yGyqD# K+W)D{~{^͂jE^6Zu;&1/:%E"M,?Zt5_h»1du8 )5N')*ikEQ՘Z6zQ3++cﻴw/-3~. DIrY#ew-htWۅogqmp@e( r Ţ^e$/?tS`D~Q@Ch5i\!ptAQxwbcjpGN#"u-T2\yAgjթ_A/8G_eॴsҭar F_/U6DW$y!tH{Fn,AgZreV!a?G2ON0zG\4iA}HH!e'XmV ׍ܡM}f$%Қ#W؂=:rMnlaƛZyo'!U$>2>xD#äBb/+ o,apv?y᧳ʼqnEښd6+2?[R9L^wcJtY!֩?6@8hM^$| ]mp@0>0wb!d5TW^zcZЏ}m%5gG %9 9 aCL3(x`RJ Pb:U!yʬE8s`sj(<nځ<'.]Ogp<3H7rm陮,L "nc,o,%"A))&:9$w}[vzm?.$$C>'{ίO' wp B## 45vܳN Rٺ=ŏc}z |#aVDv )) CA! d P"YP|皁Z@Ȩ1%\E6G3,~4MԦu#~ "[y:с ze/N!8vBrUt#xkԦ ݊  O[JyΠ-y;aSKjN戀'zQ&}Ģ'lIk7JŦsSk*7wO[O]M7$)NMrpOhfR +o[N8XCzrjU6!/ ripHA'~0%!оdϥ)*V7#MeIQj!5ÏKeY+^4dnW{N0 ߑO t=F\/,xOQY08XEjlr]z* )D;),#شg 鉐jz:ׄ,!:0}x.LP/ 5k*𢚀!Aė:eqT Gr./z>dF+V̲kEՐGW"Y fFp4t4S4',=M6Χo  ݡ1:9f(|(s= QE@iO G;RL$(|M9N ~Nx|^C̙ z`'(D vVr*VN1aV]\G E] 6G n($'IJ6(Mx?p$Q=dO삦`fU&90K%۳nt!} z;ΥZ\K|<%J@c- [\wh=&(EKIp/D/3 r4PYǺ+$wh*sZKu UԾK\MxO]q3_.oIL-@+$vxxIWx1Xf,)w//َ.NK>5SC#L/w7D>eGgG%u8zsL%#/ 1zr|l zk2V\r'`_|Fݸ;a/ )&u1/O$NBS8AtHG&4 PQX6"ovot7WWq4|B Ď2T0bUkƢ;9&pxomׅ+:~_ؽ DyJ5Ω$))dsKxq 803KFCAȔvc8xT>\mK^R"tt8+i̭;la5 T43y3G&WcNL'Я/#fe.e,`}){hQ0,|r (~b\-YS||Mn$07kη2 F=/T2+s0$SQ& q٠Fu$tK _#zDb$fˇ^"*%1l(aA #< v  SGSNkLaǫ՚Qy pT ,gCȇ:.4U'vnũS (Yjl,;ez17CH0cYkzۨ{Ba&{!&j+spo_j Lxpqmv~(s8`Yс0N*bfuV=;Vґ֨GN } ǧӵby^*`I jį:Gj}>'׫  vcfd";~AΥvJ"|O5Rw4z2xbV$"%CF;Ǿۗ[, -W`sB3r??J4eź|-ϊJ')SdD>PU7ҵRV;r7}F P `,z%c^+MB54뚬t?bf ،,fӭ6ASjnoĪHneL3gE noڄ8`X W9,&=n3CȖ5rY*冖#O 0ϝC;/۷.+\VZF4DHM{ҩdk?qe4xFB [wV%8kE6+:(LǞШwVzK]lf6;.Afu/>N7 xCK8OjNa&ެ2- ^3C\G U?y|0O ,[&@y±j,D,Y1>7&D7l2*ְ mvmFWz`bcfFzF|UV~ImAo! lЁPf,f3Wa˻i^gJ0@u۫L2ҴŵLjTnYII ќa!U֊> _}ϢT{1'1N@&3 ֺȢݶ PQD\v ĚPzEs؊4>MQOuQ GxN=y=Ę2fievx7pvAJOnhFׅٚk3 WN2 ˱$(@{أ5|ո^vA/2ۏS ROӇ,S^*T!:87џlFG/[=c,X]$]q*zawdF[퍗+8g%ZH-Fmr_5y`荁AU[s DZ~ ޶ɓ8'jtQTV;R7VM)U'LIn7#[IKZgQQ8rdg]%X?3ܮ̫,n kZ[OI YC9'䐎a5,v :X3 b}c0ipC醼qHșFYIVL"ӤKKW+ٶYy2(hOm; r)-9o Jظԙ iHK"+; =Xv=s-z 5{Ioܗ r`Aj*7Hg f]1/ţdkUb8 [ڽ3qM4Hg/d߳-F~]b=BIq9WWpx3Ӗrm#ٴ ryS (TiF 2- Ȱގ.[M|1LXk3?L\g/|919Wd%#8 7iHMLߘv6 OyXc#HSq?2`0RWx֘t}OB&8|N㫖txhEV{buG ;Nhzٵj uB)dT'6d%ج ª <(cM͟<=|#RcO z;Q|}QUm֫;'`EIt[̪&,4%0uˏC^pWT!la[FXljW92ՐҒou0zECtbyg6 +h ]Ժ"O}Y1z"<-S})sAī74Psu"B_pk@ \>^S"pgi$5Ò=4 Y[( $CkFv@6,G~xVhJӕĩOd,duW(9 oC7tu;1B2CƍeW;Z;5?+ #kaaxf,څX;9m,iM%ru$Hf1>z#R?dij|3$w6МIiv(žMI+-.\\ԈHׇB]U qoWAdx-`v+B챜y,ޓNȺ3jvD6//UQCt|0e7ߍq|dvwW6"v~Q*JS@&ZM>k j !8o"{C :oG$mW7)'{ OU4wO~hR8.>a:BiH rnESIϪ.o:C2}X\y 9^~V?zXɜ"<!|< jfDn5Ís/tUȣ$A4 h0'2qFa0A0D5tO?}vB'3Qu2|2蚒y09!,LfKL7ħv,MeY8rv"Z}+E%) Hz,._GZ":=w0J!{Ky7oi kV[ķ> &3K׶Bf } KQڹ9AOTYAP4?'-BVG5I~HwNRV79^ o?&?D~LyVRip*oɱjtMʻ> d\& 19myVdT%9HRu+7^ϸ[Q[6p .T(P3|^K|G@&j; XQ?y2oE3+-L~۷%`3cgji|yXe:ɉo#O!/ǫ kH?|[ŕ-Z޺ˌOeEf]eY .7[-@^":ȥL^;("env(%kz[Dw M@w7U=eIiaw_B#ԥ9!:}6\)@-תqv$Wr]ӓqN@Pr% ܫLHUf9ּ=pTW|r6Q6zwiY;m4߁ 4p`K?4~гIqƼd@qY*QdT6D|Dn Ȼ(X6VTv& 'hچ=M)d:!D;"Kڸ6.\/50%͈GOχI[n ~3C䨢f{`MNlZqjSq<}L8Gg;(E-[^oo+ 15,@u!A*!;|q.DC+%N$"ԏ〭M;CépTƬ7iX|r_܊P?z"oV;=0X2|uC #^VUM꫊Za ]"2f:2'^ L [$KU=!Ѐ%s.6び?vadW!2Hrnr8!y gͷkIj-aF/oC+MAORǍ: 4-Ƌ B5dXJ,*,KmHСbI9*jșfe1u KY+|yJBGDrF|!(|h BH{WD‘݀Ͼ7^a vX?sNЬ9CPB}TYĖxeRRgB?XE WZZ M@TкK J][N N%!Vl7'C{+hO'wbc4y{R74YZ;˓w|/GFRIsT+V5AwNiz 璛:gJu(`3I\d8tQ1s-;̛~*iV~?rJV>?w&(򏠒E?htk㌚ Mf=nŽ; i vW\$q趏0o!R{5CjtGΘCl FxOK)]mOaP=?Xq7.5_4R]VR0Q#_T"6f˗EqBǒ̐J(|{/>M\N 60$/v㓆 BUpf\m2SNV$یҗX4Kay;J+c sGsqkYHJ7c/0 Pykd"U3P=o X k6pMDEbj+ڌA?w!A/Q`_L}I ~n5O F`JkⱵO,b.G2%LPVz ّ6%kVceGY{Lަr7ΥFZy4o!#@BSޯ<歷3J=UXInKb_ơ-AVVyY[ao4'N*K,Cf~H̆|XUqɓGJn uɉo j{)*a?Guv[;r8[};U9APV Pe*c{EkCA"]&(%}| 0@D[UA.k $ٵc S Tfˮo "]t0t?0{WA$EHz֥\#qHEŨ-48Ze{/3#{U Q3KDTIWߑ1m@OH %3io)` O$ڷNVg?dm>E;9ikjZQo va.NjVݕ/}͜}π#J'&5 {ZaԹF1DqMφeJs-_fH+K|m&>|Nv672xux=ʾ f[ ڢg6U`AՎ7-'sEۢHP&(8UY1IKs8zm%>i؊qD3O˫>\UX_%Vp嬚0MkmQW9pmik)PaTtMt>*%rf$ dX6 Zݵ|Fux{ \9rZ|K "YP*oFb9?})FZSḢcSћsPX!^2蝽HTfHBn[a&V > iϽa>r!Ch* g`+%߅_PL҄0@t% W`ID}[@9'[5Ze{v;a 2g}D+ʅPAa8wO2iڷA к[rea7  ?3U! N=QE3:'q`!ȽZptgp`x/RDp[߇ʓ:]E  wX; ̈~{2{w3fA,92Ǭ"y E)\RuM4 e@R^ܤnEV,3$ _&C22Hke=s3MODY^6d1g7/K7..CwGAwQ[rG9vl[v @ Pw@Ņlv&c2 C1V5{?R1j,mW :/!_j^~LO-QeҁǒH>3 [Xjr?@U~RӀ+#PM$9 rvgH,+HY4㧙)|}CV;4I̾lJ:OyNG @H$[$yhİ!ۙ^".Zz{ .)>Ԭoo]@i0:US~Kv64-M{B31\Zz%lGJnm5"Rڜ9Xی(+l`a8.V'Gwf::ˍf߮tIB;OT%.8CRe!XJĒӲc!(x+G sLT'9?y~ $[`h`a A"7{6Ji&4,]|%j,ڰYxDEV$Q+-I s^gcE4oĞ=A\il\-Ŭ%҅KG v4[*@.T3 3RW^~x!9J^QA%y2eMdk" M:gBpsq\bs6[#HP܈jtuaxőNmv$?wf G@,2:ds"y"Ҳ>4}%2J¨2F:4-0Qu[1)mY{{8z|7mQsȖ(&yq.j6$rjr 8l2)"RN! `R9ZynTebnw4+!Q8 ]Z)y[wͦFPߌBْ1ܹH K;Z0z Zi⋎YgY?8ZB1b|$`R R1޼2e[mިzn!IpY?DlF #5#ms I:M'û(7>Dգ z!/3bnbFd;*}$է֕z,yrNzCq՗ۘkdSL\Ss:5-kDDyWl3@ؔ+4 ~sy8n b*~'=261?ls M5W)8 G=WVpO ȃ:#w)DƑa|>t9,'Pr2'?#t6wuNbƕKh9P5`QYWo5Q_0mS)wCs i{Bl:Zs3;u'޺ˁ䬪)IGNr s!gj95k!\heY@,[8A)pyJҳ-޳ PRR> omΘYeKFna 1N'TJ&|Y V+iqKw-Qw]ZBЊ GױAw stz";k&i+B醃z1i V_ 㶕a;c+ʆ^[~#T=t~! Ӓ D _gR<T+,-=τ23,Q6X!nY(RK嘗y/ -kԑKS{QK`:HnPrk-Pn075{N%ԼZ$^v{?Cxw?`(4u-=ޣɊ? ] ;P9Rl7*qdpAc涗1Q?ucG,=(J!Qp?&# °i[$qla{'O󦖢Ң[gY|A[pGQgu a~P2 I `')Ly2Gpƅ:*be(CԷQy-1T \nr F?8@P5M@6(boD-" 7~mM/셋Kyj3e3ϐD~Pȝ;wzc镹B <xh \J"rܻٚ}6$ZZ"z$ۻ4W;7ϴ8 zO;V'<^O1N_%>[shTP6nTր*Y 拮t,ʫނd> [f 4:Oze~EyyI<%F{6uO8o#7u% B6!*֏GJSGfc8w u8SLm\>@WDc$~Y Cx-lE ŋ]rF#8;{*Gg>s?ܰ)]`P78/08 $D`RcF@YeAVK$7R@͂ ;`k ?& rERU}dDnNfp>vh}GK[<*!~rD0VهT00fkL"6C7FNBJXÇk*5wLώaƿc ncj6#S3Jy3/Ͱ3u{wTwsurD~UpԹ- EZہC bbNY6l_&V7rYuON'(&n5uYG_2R x3X A;B纣h8"B.ÇT xP1E,$ Lmm )t F~3raYq [Jog{oY |%bhP6٭[bX. z7ɣ҃Ф)A;bj"$ؤy篐xOU0ȟ[jzO $rwBusPIčHES㩙m lHY-Nْj7w|Ι"gRΐyt~-eT'@Y:6Db;J͞-6&#lWtjQ ?+#hNc'O] Ti݈yk0$7{>P<_ڧ"#H,u93 ն/_M%Xqh@NZZ+^085hv190u˕]Q G0?if*B) h!1C2VxZ|`'_6?fT'<DVq^ G:ax >=QWj,9e߰_?͂:nZ>w/RVW(;]:J; Fȸ*\tt .6UA(F泖;4l^uJKT)\ xJ*2e- {4|dJFԓRPT-`2CI?s].xKyXOÔLs˶G ?7 <TQF&v=Kgx%l9ø5>At&k_XV)kyL;4 ;9%iCB #,(˴g'qf4tALq׏f>½}*yts=&,^oŝ!F:r^6YC29~e&ɥrՐTU?T.xAjp20Nf!,/WOV+;Igj*phrjH͡O{D+tT|dC dVR+8Ig_E˵mIԵ͓wQqkKXb94k|%~Żb|Riؙ/-4k3& ci ?՛%-'gO+ꊊ`דZ\TJ +g['ȇAbTy?[@:5.9(4ģcv0xM:x@DʨAN1U{@a2D{'VR܉|lA"hpVp H?tmfz? 2zO"w|oGj[b [*SY')HD('-Kjvf^ڼ4W<򉿁V{G4kF.:Qzۣ8UwѴHM(PEYw"XqsF.~a)$aHRВtlz)֘^H#I(z u%5\?w~ȽeX\{DbvNZ.G,\2&x? @?CZ5f/ ̈7î!`xuQJF~|?V:mD*Kk(sſbedDv<}q ε ,*nJ؃h$qo \DYm\-c VWbk7}i\.텹[x n+ꐚRٝBֳOOk|4[P;I4i噇bɈIPӐSD_؁Xu_Z`6bgCS+8ЪKI}" :-aѱ4Ź>#-=9Q#FO k~m8bauC~Ԩ>VndC~do%l)5nWIjZP+>c%:Plf&^d y'*5=Zom݌(D0 fa#`Jd-dF%he?X)Ƭ+Jf<8_|C@v- `{t18˜wu,MP N< GhSXꄶ4J9d2Q6euzQ PNq\A!WcVaJ`b"ΕXACGH= i>ˇNDVI>)\: -rXU;pBFݴ3TQx c}KxDOS-Cz2z2#PNf+*(8OZ٭/Cf77"]&kqLU ;,>ɇ{+1&YQ-Y1$P=JKU}MjɋC9py>,TV:ZRoleKj>{MX@_IU-%jړn80z<.bɄD S|76iwДX)×8{me-v\1rVJ&!:$[鉜@)_Q!$:,=f׏UmZlv Ir 82<^+LFY* IRR< +`պN^@P_PmE G`n.\*"ilԘGƕmæW9N!|_UP?;?c/Kx ֕1AFGi ¬$KbO0]jp} G z4"g$b_=)>Nx?V}qpߠ2P2{SW8 FXϺt z$9zS X.b$)o%-Z{e l*=? snC5:vPS7Dj\wyXA zPvkiK}N}RMYg"὎=&S$nC*} FVc!‹CGŢ3hdDuB0:XQ%:BYǛmpoŵ_3Is4Fe/%R\erk64cZxLxջdD+7M͓[ihE yj!菲!K݇,Jj =Xx3ZԆ9\"J[m^A@hcz'XYC]SDV~2Foɨ>?'C^8Kcz[uδC:=#5N 2 "/{~9y8Wg4;ⲕP ^tCQ-O%O/=+&L&ؐVދ"%=AK+%2&,Uk1Hj"2e/R+Fr(1 "|'Z!iL>ԆAi\3$>adJRP+Ʉ*g$g.^J 6:Ӊږ7 :t` :%Eޞ$&̎:CwG娋Nȍ<¾a(mB=:̚;85{m8 Z[, sĄ:Z9W!5eCBmmp UOՒ2]NQFӔ# +_R܁mY%v-v04ZeRdUT<*ũϤrkl ezD1ۨfb$Ks9v = [57(ϵwц%/NgI |{֭:@P0ڨŭt*p$!rx  =_a+ZL821I]-H'ߊkxz=Qv 柲dvmsTh%8оd;G4ݶ#OS܀a y!L6nC. DƉ B¬O!j SHHr:C_WO*7`}*JQђT7nF5 _Jğ= /94|[R,xc/hIyo,Z&yhm_dgG!U΀Uҁ%/ ys8u꥙Ё43WvjNlubb|n [/>̼i (3LSǪʠ|EԴ9 jeMSe MpwFIx a;}cNl:Q@҅v #sK+*mk IafUKGBu$PVvj(j3Myb5nnp". }GI@JѾsAp (jJ% .Qhۜ&#/"<`pgigOIW:CJ+h^Q~ӝۦn:s\,)jc0o ^/ڈX wͬZiiGyVG .+g*XϊT_ a?qї=NGf͸_o|z~RҪ+UMX!f[bMjvo#l9lK@г%Jt+զB'{z>*ZR+?Oesxɮ VP"b.&:&,ܹimє%:(0`'2 2%kU8 yX qn}oy4>I*x$'8E/K-)o0dyA%W)ʛ˖13JkDs^>^Bd, uJ9|8 3U秣 ,]/u{ Sl1C IF%oR.F7CոB0诖Uox%CT! ?ԟ^8d]1S>TJ rqM[;b| mN9J?K@^$ŲĤXmrt #}#&Vb-8"S2Sw%U`:_j6}J'8|UC, \y>65k-vy'XyG"Yoa䀖"s:_֩d7Bϡh BHg>io3͵+b.2t gD)(M7|+!rEMq^@N ]_P)X47XVt>'(꼓p5NiԸIIm(]_ Y@But7VSj0Kt3[B]x6EG!Izt.4JΕW6qG5'vsEι&ˢEPC#>Hnq>?o-lN.Y ZWZ[}88 "H ?i%w1Ӿ{_^y)j9r<)]T! o:}ۆf\.󥀶#wHKGۛ`Z?@_jLY4y?|Gm恛%FFf\Y z(Hڦ~FS SsT_ʡCQKnvt=A96 \.uc[^K`pu9:|V){5{%AgExf$Cfj~M 0xO1U*E n=>a.a4ND[7u/hUqAfR^ނzF@ ˦URa, {{D]0T}HTh(HKkz$eH\n9XLuMw