sssd-ipa-1.14.0-43.el7_3.18$> jS jЅhY@I>=?d   ; "@FM    4 { $XLL 3L   ( 89:g =9GDH`I|XY\]^0bdefltuvw$x@y\RCsssd-ipa1.14.043.el7_3.18The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.YTEpc1bm.rdu2.centos.org 'CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKOjA큤AYTE_YTE_YTEoW~YTEMYTELYTEOb81dff727b2c5f2e041d79953f1631a428ba87ab85847b3bdc991af78e8f669694d30cbaba62288876ee7e92f0ba8b5e69aaebca8c190f9060a3670d91a193ba8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90371ce67dead6a25db630c6b71465c06b2ed9bdfad044db73aaabefec0bdd0cd740a17ad4e3be94abb12e67598d0e01f60f4419f9887368b81d29b7d0fb4f3b8d1rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.18.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.183.0.4-14.6.0-14.0-11.14.0-43.el7_3.181.14.0-43.el7_3.181.14.0-43.el7_3.185.2-1sssd1.10.0-8.beta24.11.3Y(YYtYXBXpXv@XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.18Jakub Hrozek - 1.14.0-43.17Jakub Hrozek - 1.14.0-43.16Jakub Hrozek - 1.14.0-43.15Jakub Hrozek - 1.14.0-43.14Jakub Hrozek - 1.14.0-43.13Jakub Hrozek - 1.14.0-43.12Jakub Hrozek - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1456013 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1450125 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1446085 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1445821 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1422183 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user.- Resolves: rhbz#1418943 - If a long-running task (e.g. enumeration) blocks the sssd_be process, sssd_be can deadlock - Also Require a new-enough version of selinux-policy so that setpgid() by sssd is allowed- Resolves: rhbz#1405584 - SSH: default_domain_suffix is not being used for users' authorized keys- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.181.14.0-43.el7_3.18libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=21eef38c65d50e5eb1c3f51f72c108a65d626955, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6?]"k%w+p}|,p35muذH[zhg#(#-d75QbpnGKnʙXZG =DblϷ5E! Iԃy,"yWQUm5jtτ΍fM? hG.D(.n- Buu 2@QgA x4.8 FF;gy:eOBZtr*N፠)DU#[LX-<" 0 ' N*DSAjߘx!5@xds8M`<$ʔyz^5Ìby7{>7)&&WgMBrIW!Z<=9 Bf=w$Ͳ@s>y8˿ ~M|rlsYgN=uqv\j6EFp&_23.H*Ku8RZ7lN ͔UrtvKYs=2q0lK^FFbN sUE1;_[G|{-ڱvc ì l=ڄ}K kC ,P3bFvI7 dB"WƲ]5pOl(vTβX_S+mýI=}U6j$e9/_DL;vEs-Lp\j鹾 -3b[rU;^ Rg-xm#i$&}w&z \Pmr2~L!r$F@~1.`rKւgE[Ŝt~W\m6;T&-yqNM,H` AsP)%SF;vl>>A b!1P<JC 9 gňnO|[0@"?~)iZ \)Xzz 4& gTG#.*៪+cat3 ClVTz"Ifxptu5;H _g<{?~cXչ<yFκk^ {xotSK627kRyY8)>t1D*X2fۻΦlX 4-G*4W\r{,T*Nb3nc@v1XJu[XR4Z%]=`WgJN\%5q:zoM9Xr@U$/9[jgV끑!_}} FU1 ŧe!jQ2dIXj7kBGW|t!쪊}o 0*A3pΈ{|twq/^ J kK##[y8dQZ6.ƽ)ph%BT-;jDJzQEGfU)qJ't@mӊܶcsaboOyX؃ڝw8jŽ^S=7 @saəkŐzS Em陦m0 &-,葼e0ћ}S:/wr RKMmP@[ YMQb5ƗyL"DAy[s\B`r18{ FT腔at?d? ŵI}ӂQ8kiBq׳B/!'đ$`|B`(֠?ħD7Z9%bT[Ϧ뺴603(޼9#|:SQ7VJqn^}ihAbP6İg4AHk1ˤ ɼeor2[MÿڲgkthegU!d'rrx@Qk= r|^H]?Pks-bGk=vAˇ5p8kB;sM2hYu0ZLq1n{eі2 7Q?h}. }?b.@Vm MZHn84xC'wD@k̭Vgc+H'L.5MM u|m>^%='0M Ag?DQ2K3(J]eLU\r̖}Iy2H1~ 4]U\.ą[9yq{k>8KzQrbC)J2!ZBǨWGw=Dqp dXtUIVC "f@f(ov] k0L؉hA\ʹ:@0 {9+ÔbMݷ_bA+ΣYr{}=O33}')FrQAv4\L{$7~ru}x9gYGyZj7K q,@_rAiȉ<$esE|{4qYrT{{v{2\q2OK{acS孡}4tP6aӳ,X 矞ӊ!Lc_,jhq3JPy&%w1Ue~9'[XZMskA}sBAH᫿8 >(|,GDɒMmhY-n܄0OY  l]uq;(Q&jrqk\1"?u |+cCwÊeTvN{l`pkV׶kԉ2v-o<V>%2R [5#SsͰs}]2}gXLva`[rô >˓8˙,ԏL VTej^_ fQO2 "fǠBhگ@6DCBD~"!CM1 8MZ8K)wrE ec6❡@%Ԁ䱉|~tq( |_دnGwRM l`BC?6 h1ə;f>`Kluȇu$>h3P>}&Mɷj}ir<4N{|k&6+V} , ~Նxc}9^/J'b"o0NG s_f(blk]hx:0*$uASO*;9}! FxNѽH!0l} )JjBD*1T2f9agq֤L& #TѸ Ki k5 LdYd2~rgLoe|TYt![F `x3icZ gkuSr6P]܅>ڔq&2)ɭwhߗf3/A(WUvR mwzmn/0\6[\mM ,ʹ,mY5ı!j/\DZ+L21X)Au?۲xXkt!2neç\ ru9+F2ejE߆W-&fFWWcvMr+z2O!!<ѐڐD m !(Hj>oTJYUؽt9spMoc͓'*ٓ1YͽTeDc!NG*c Zc`W Œ@5yyp1)':\. (|$GgvJ 5Zʠ,] }(%Чt̠^[ptjRMEEQGtX<%P TJ.+B/\Q{-a`zE Xv n~qƳbSo;([`]UBgh|-֧֤344<xӢ>dyЉ< L>g:T†gf1"j|nmX$Lcm] OgpE&jT(&UZn1s|@kB>~VƁ3JwȒƖmB+:P@޵̪/"}H':"v:jyېk +B`0w}#fA3tQśT:#B|6(.vv,Y{gEO>~}4w6 eQ%3Ri睌{dKt^*Zs͙ a$_frF2Z1*5O=Jq\wLp)]~Rgrx`oT`12vLQ]dRKI'0氊9W\S g ISVрuhւ ?j>V^x'uWZ$IpcXVDe^> CBt(m cbUm%HKBuqձDZ=Z#< G^ .M.Y$t|OƎS{BQK(8nL i,Z$$q0 gzDY(AՄ([\=6M[ _Axr<f+z{:s<5hcDv=OQ :s ;tܫ],^.:ݒ7EFr 6]x'VFBaxkҶ=nIho "dג_?>2Y*aFF*8߻Y*U^1g5 P+@l2lNi75p>?q.nEP_I^EzUǚei^]rB wIz<&b^$HNKr+)4E܊kg})cl[Ո4Q'4X:3'.Q]u*݊e l'u dͬe/<ߥN\ jh#}boNgS&%+AXzqp\ Yl-ԜwGޒj㴁pn9`ֻ{|ihUy΃\uj@+Y8p( tK= lUy5[ У +=бRZ5 R{v|BBR'@ںvh8 |Aܕdo9A!޾nޱ6x}Zgݽ#Y~͊,-oJg|CB[B<8ag07/xNu?GNүaf܆xT]#8[|y5ee=f!N,Jx볶g%jӌu 轸5&ub${rtuh !SyF'ʾaDv2_˻L.uX}_oF؊ZWho=O!1[hD;=LAhehqRN"!lb:8GHB ؄1Ժ#rgI[*0K̝f%JWy.|ou= +.` -?/ aun_+y'=-Y{Z Nwtwe̘_u W(@ Dad)J{Թ L:*D PjM"" sI Z%Ŵ$ DZn- G;G}eG[۰ K̪K+SI!שaC*Ciq"6N3g \hl}p\~t9vƋgFwNV7g xZ`j&jp `uHU]M6 EFɼbz#l }~x닿Z& |frdVnEXj!ZDnlSlϓ'gM+@f!>*Mwq˦7|ujmmY^p^`7=6*~oy'cx,V`xٹGF M=xSq?5TSf\~PojaȫTMB3H>T3N tIвqR)-!xCp +ƾWL>P |ӯ[ɊѰ0W5KKr}'[L"fn]>W?C3n7jf|+emlaL;21/OA0#j־9Dk P퇫. p R&֑IzzVMj8zFjsKF˓ĸM Dn$REJ!vΘuPKYQ# #)o/qov_XH )|A} Y> 0I~utS:5.8, `8771:# iߪ=\6,o"r(tv;_5sX&04*׀G %+=5$"mML0Xi>QS\U.`G c_i7R%YÙiW|(f?4vD@0~ ǖmnYssJVJIZSbڙ M_@h!*ǵ&kVeV"6|,瀓"A3\^1?k3+Լ@&P4RpjT]($cxl3ryGPR 15oZ/94#l肵Jg2[BxTJ'a.ߧ/D +=]r3j7;bOa5*Brklv+ / <:v`Լ%цD^CyzqM CN,`ڏU|O89)5TJk*EOilA ˯ 6ILt"jqOǮN^&?2؁ b!Rgb$# INDM0T&eӂHL "O=&(?6O4V8ϋЀCؑ]rt r*1|08u e>u*os,1JZ99Shbf Ž8'.\T(UۈL\GF6`(8W^z10hK3bbq!6"hGAd#U-N'5R7G&ef[ՙy ԫ }Ogc3P1:E4 Z5O.>ҫ |$#/BtSOZ+]G Ӄ\9u"治E萛Qi)ׯTƻOhexQ1VOt>V{H4ǎ~„Wf(_; PeC=~3D6e%rj ]U[x9ã'-J0jp‡{a睷7Ƹ 兡E1GM1.kg*%I }Z\kӀN7Zdtzv?hP@oR'GEl1P"7I]5='TKT_5^2SجOZwއJTh ykQ,LxKiSΛG(P{4 שV?< H"*=O^Sb,yԟr8($^Bܢ1v Uؽ;]CΌ, <QǒwlVwITܲ3LbqEJ<ͱ pӒ1y~; JRAEFWY x;ev /x2j?pxפC/6G\Шs1 =31'm7{|[yIc>*H ,q#-\ (Y0k$w/1RPJKathk}WhXv6aQwM\ҒsR SÅ""/w +f1MVb6BtWě{?tތi cm(űƱӱi^,-GrF2n*n{}.%omq[ $9ݽL۴y);P="G9E\nOS! n2؉:;pFRo'KR;ac($/܍Ui"h%KR?5D| )>@!7%%8-W5SN1QCZ4AATGAZ$3qM#Tk 5Ո 2~:v1Y%b,Lm9arwBmuO{Z&'۲-\$>&=Jz4%EП@) +}ur0fL BOmz4C`DcM36N<* /1ڛ5qZ*8pGieߍ.ΛG5ti:Gf![b+ZS?Ӧ 9A(`k=J.0e#$A]b\Lێ5nb3ɁSl]+Ik"*lJA؟#A,- EK&DЅnlQ]Ew {8aMȷrpdk83.13t""Ї'\GO~Owpޯ;PVxJ9&ВY@_FtƳۭZ~*[ ODfKKo}Y>Fdg]vhHth K&̏$+η'7$ ^ !_pyE$4[% E u1`a]rptd̈@,>~sz|u%$z0 X6Ny{R? )P 3xˬWg՚GrUM#H6OH`+7|7@JDB8g~΅ j7j剅_o~i)wz WST!ie؉`f4twE8]('Q'b6|MMzyTRMs$5Ѝ/[)Z"D!OTtD2xp83L`,GHzPp_غ`b)<]=RY.IP| +@0j`=lzwƷ{OJ EyW!b:i"@p_:g,& >}춒ç6og=W-}2o=ZhqE v"e׋3&8%9j|N6,P(/+N jthF-]X_%8& Ù5m\' "H7>\Oi/_!oi W@ϖXq6.֙'hk#Ƌ0vgc\{JP׭$;<!cr1д2MrW-&fiS ~'KPCљy0' Q 宫WDJA{|q"I9r݇ݿ,Ϣ_evib!>!]{.[%m8-GkṼ$~7=}w6)܇!Hj匿0=V "i!u!==?tPWl'(ŝAW;L9H!wȩ ӯn)hY@0H^q~Lj߳zl4R7pkgLJv7bӏ0;eKsyca460Dc9{TҺBރmCy^]x;AZ6o4à.į ]5lh3)z41SXS&nZbQO Uh6XkXΒ<\f+}wEqFЮ;lu9i0‹sHT݀K9H8*FܔِwI0~M !Y6k/+ᤶ(R͗tN ,^ޥ1/ԒwuD9/A/5`쮺aZIʎc-t*h5JM*dM DwoX3k?'o4-:EPYAT`Sޣp6nJ.83HUO^Np?"E|H,!-BwL8=".]'ײ~ ţGpTtcZP%*LLu!{m9ˆ"WgHIWկ #}sdngSyY6c(B $.M޸"3 XSl]iJ߽ԃ/]WI-:0#WɃ ֵ]ek/CrQĆ+ UP2d=Tɱok:C|Ey{ |ʷt>4~X,Se4LoӇsfF4&h&^ĖK b)K`R)D2!^J|(4idOd8-pΑ(gX!iMd'}-֥i6|$g0SQ}eWתJ`Y 3t1VmeؗHVb)-|SuFftmSye0xI=lI heΗVe s޵69 {t2@yJȠ6ڍgʉf<ݱS>\&}#x%*1lݪx?TfJJ4nSZa U J D&I0`?S׸bDPGx+rǔH?LJUٲ ƨ H9jwg~ $f.NGiYSAw-!cZiq~t+C[R?!a@kԔ4Vf?_M1T1}R'fuf?|@+׹4*[Q,oyƣo.A!~y 0?{yj9Km3zdη.~\U/jt`jKGd g"jL?zM꽥='v| |~@ a?w!GhP@e7QMeb8}=hZ=L R"55G+=cKqY*p)CoD7A 4DlXTw}3ʃ3K&ڨF>jKƎTXaa\}^MX3N$u! w̄(>xD!U7HTyQĵb^u!Mm*_gW*_.A*^et0%W `~dm= .f^W!`"- .zOxx2.Y.c^["saՓN.ҞÔtiĚF.&AD2!{Gy,C% iFĖS )&ވ2R+Fى3mwࣾ=`jjHćy6*!qhܕMXt;xX\rdP-{/„~9ij!.~ 4 rL| KAX&w|9l!o1 t?ڿ Ox] ҤZ}q8Ku}Fym.C,mdx¥[%4}_5(2Э g¬2`$;Ĝo*Fi/5Tr*~EͻHjzXq|OArCY^׎7>zhMYWT8Off<,/ԋ8B0j#\e_p3"s&1OR r k5̠odL ,0Yr)Q&`"N:Eh9MI_*0NZ6y}Qz#뛈/䕴=v+ X(s'sI閸=Bos8V)d5Pn (h&m%C  ߽I_* [P 1f%9hK >@e{Měm,*(n>:@1YQwgP%SPOZk2 QlDD]UD  1U`XM!ܤoƶQakc VpzORYT" L9Y>F0 oD_SuBa𚲆+YUqE/nFOAON–9ƵC3Dej[KCLw~`RsmCExV{d{iP9..FBAQqm<#bm`Hh(΃`4+K/~$R8|v_%$t#[4pi|9ih'r\`ɞl3a-j0Q [qxDk{R ׏JBmJn£R0 -^9;91K[.}ٝ;,A8utKJ'0Ϥ%ba\%OU1uzayO(h,DscD+ JkNb9P#^S,QDss+,xs6^U (pUD]7+Z+~޳HT5߇k=t6t'ss6`a@^7 Ȍ&>,wd$J"qJ?w'n[A}UR&TWBuY{DJ%KQ3Ի>eѡz)Xδ$-X^"| y~а>V ˯u+1̮ƖVp>Ds5>W(-;@oƑq73祙Jd'^>'Ko*Yt8x-n4J}t"yGr*<ūsPD'1͌Œ)X6G[ l4lJ(eVR|؍^y/ÐmB-d03ΟdwB(l$^EҐV"Xh1q'bSwAX y,DoP5Ԭ|\Mh6]\*jU@<ف}E:2ФګCS.OADQ0C!Ћ,xLUș9цN,Jei61Ֆ^5+WvG8.60?DیO6tyz7P9.**?,`⩖Ցfœ` F5e݄EKL{OpwYTϕˈ?򎴭ԛL:QI15mWk<"Rѭ{uSTڹ~7Ia`v/]\u,% om5sF<;Vx Pyҹ<ͼh p۸0f-ЍV/wPjO xz:,L Pr;]gy_XdQiUˁ!W<Pa޻JLX &;%)j 3ѕQ^mi?58C 3%2/R[Ԛ9C-*bT׍Mw/en0qx/Ҿ.hcq`+$GG0 pqrn2.R4HM%vZ?`2NU O5S}a3o5Ԡʖ_%?A{s6; hgL?+D9( 1 \yg6U~?R~އ4=ァфQ!2-HL8gdzq/vWi2 6 K}sF|Ny 11`vXjA]{WmDX1??b4dp:{(M x%deql8+Ieٞ AֲYWmDTQ]Vt،'c/~LCf pު$#*2^ 'ilj͈P%cF^pK7qVꥥ ړxѻ\^<:"o0BWCK&Up!wB $^M>"#֓Jcj㋼F7S7ٙ`.1 "p|?_G]RudTⰼp!@:oVNj邋F`go@MB T52IsCGj M,c,*wU靣7 8]S jТJl$Fyn^i" @[k)"҈?zڙ _YZCpJ@^.a!oL2Yz8z L}8\ܶ#'1Վ030)I?Kf)ipD2(GS1u&8ݫGKd f!#H4;XERX4K-Cz$xdC4x!CӋ Ր컊dUf;$TR8GkZ}S1,$qp<ۡ}6E:UG <(Rh …結vy ׾а`1扴Ib75-g@h5kΏ/P@6pi7~I6v/8ܿ[4خBp}'M.g'_Bj? RQxiFt!CD8i~:IQneeǞx s 7<#Hܟg@%漀LYDdZU8nG;=>׏>T_Nqx͋@I8-j؞])-kARp՜s'G±J9%YW˔#t=i/g!TCD?3|[QbǐT t&oylo\u "SV1AwJ|юp˞7bU-VVmvYmbC%]Ð]c\n&4+4w\!qZ& ;:; 3!9X`""8sd!HZ,k!%|, S ZA:U.F,ԩ(jLq":{SZgbLX>D\H42/T>Y-a>|.g}G7>/egSO)uJN@O #HVW]$&(vv_!8l*n%H} cFMtGw(<̐G9 NA<^)*AD?Av[Dqe[V4?_}xXYEg;T8l $(ROx|u74ny@`)s2Sjf-CBJZM C XnjTKBu4ߖ%j|虄|}35,j߉ >7__yoL`=QBДqrzsþAER]$ym _-^f=M *ўJT*YF]&A_@bT`N!Il0Ÿh+hGԓL㗏%V<*9U굺]#?uj!(PMq+bTPɀ/(Ȥ w _{ 5A9Ѝ[ T*:.E!S< qG|^,zP0>gP _FV, .DkCQc@Nv#O. %7ڠN~} w',N{^ô{3y'#EҋO{b; =QĤD`סB]Qw3b8~f2\;>YTD!pZPLC9_g|k$0b LsiЏϲvL Dƻυ-l(ue?b\n+Gh[P5W +೗cҞOt@xgZk:#fMs||֟MXVxcIT<4.;[0GƬgP%?) m`mR?l*ыNάHA!Ta0,gKR}qe_$ViPd`K};N󚙄}X˦kNC8}6{E^}_fn5K@MSr/iZ{MpռL|[)Ų>uՏ\w7B8+&[`Vy9 =yýСG~o3@ *Zdpyn`Eb35xǻ~-msW?Rؿ,b|)0jg#3U&ڱ:z0}Rl[~)1e>E4uq53K H ]<ݔUr# I[Iz@w*S9XS:5g;\TRmcM=; j>cZλctǔyTQ9Vˌ=Ĺ'r`5n2ૻ-4 i6%wqf={lG>9}6f芧Sb|,,)?5`r^wn!I/FnSmSZWN+ܟ=ĺwEpM0XϕžΰeÁW{4%6-p}kb5@ Db{RK8qNHSC=ȧ[_~ގiE*)Ks%v*۹t0"S5!eX#bJ1JhV=~4~ފke'oihlvw hn?rQq_&'yON@Q~qG`$%2 ݈tٌLlJK7t4q WYFo8xY@]N, 2MYUҾ!5hM1=#F(WP6|XPOM*1@dV_`W9 ;6u),|U]C tDED_*'fC)' nTt [:4N%:>d%Imºf76!"loWny/8A;.}fڒ:wL ]Pr.*!}I4} (@I;k`N-Qn~ތsѮ8Ҿչ_{'WYρ=yE!4,|wz PS^./?y;)%RCJhȯgi_k;Cm'h!M03C0`WlCCmٷ!Ë_՞&>JRi>K?2cI!tJoUsw5j _YhVרh5-Y< ._*.#npF#2g&)[f*r rX+N+fzr~\ ՟ P7oVg}9c !2SuHA~XEHI3?:R\Ks8î3 ۋ)D& l[3+cKNk^(mp7b">S6卑rފ=M:K! 1 \04 %m-0HI2Ȱh|Go_fBe;upT&kzU{~AYnms;)Dsk!0ɋ_&xڲ}_u"R=m&=;^'s` =5P_{9^ #1x'SI36d1sH>b9I/`|%D} &^ h-*Hr6ܜd1O*IPoq =H%S3Xۍc*vIѵ,]xTF ЯL-UA_j)QEXĆ M2D0OURk'C"SV=f~`O~׊͕vGPJyJ |FG{&>!bM]/lb0 V)m;iF G1T;⚭)Bjgk,+ l/1]sOX ٣DIˡ/ EUݍ1Z UiuÂ1eJGux=ZE9 !yJDqahI `tXW 2KC1э1j !KB|d7Dp}.cjy_!NI5hPg1%Mڜ`ߝKHjU' 6_4>et}%&n q0RCzj%>ꅿ*Y]0sf'^>cj{}Q (Dߨ 2/zZ`.f}MH2$ +cJdKQ_Ǵ to@Z gkTTxa~{J()D!_U'5gL+t_c[6M|%#jXƜupPpyfvy_ ڳq"UXn+:dwCGdRsԳsjQtȧ]t`<4F@Cdžf?=#݃Gˎj@6xKkkҺZ_ -.f16ͦXXڏ0/wrg&#Y, B>OdlK)Zv4 '_ .|]Q&1K-Z%/$=w6 *uw}3w>VD)\%;g&Yf9"ϓܵ,TM+dz_BܫP)j7*0TjdJAgzesq`R%`8#Zgƞh"3rcMO˔ @+8KXh>U : c([l(6 4P-Glӎ%M6-w8WDqtbXknfMkkZ0 4'_nQ⣉?+6 qi3|ntSWqV"4S,1ܻ ېRfFOH1nU?;1Lq"AL6ekG~yFtLWB]f/(QIW 3vn2yJPrccs 1QdOFGlI!X̥ѹ PНx4?-ϼ;I⃍7$Ok!zuTWPNWÊm{.d j)8WR~1T12I1w;M 2V@0X^=ʉS1 Plc؇opQof:u$iIco%29kfm9ݪJ\ o#%jX^/tM؎α6W4"#Gn͎-\Ir|ܑZ,Vu2Wѿ *D{5\W!*`rOtuJ['XB/lu_~ߢZՄ|K59'ɛ>KWCSfٔھ9†?QEyOvwu^Vy:#cSN[SoWD;"=cZg#&f''6iڇ. gW>dN^]yk7ǜ8 C_oat!n(=hTf4w[FdM=r bDaFChz/S/Lݶąho = 1/jb| 20k+6e吥NٞKn >KUF{0WfFye OP;۩Fu n=\t4'=%Z Zz[ol_ NBs73yOd? M-j~3׮\ls-,rJmћO3&7Bg֐;]0S*tN/oZ? z 7&pvJS_p!c̡̃ d`솼'yC˒fYNh:6=j#Bb|-RT?7;B]Nc%UJl'Lð%<=~M?d9 ]*8οpzC,*j\jJ 4~Elʠ[M ^JNYVz|uvPcgckPʲ9ׁt1/ .Vմ٢[Am?@> XI7?h~z|X*w>=5`Y'4Hb) /] 6~ l_vֵzŒvY])m#,(g%!^hk'Nv^BSmu/{H<4\GZzLgKO-jJ+?i)wX:hkAѫh>BLëN|CdQ(.78'>XbwJv ς7m-ix `vGu|W9'Qdԛ*n1}r wΥLm>VFcKړOX')Y ¤0acDl{w^20 >bO?(Mǡ0pI:*["#I@U`h{۬NDl휦A bCq#K M$nfߺag% %6` 5źN$E]V%LZpgTm2` 1%^uq03*MبuN q eiKtqbL]3+WY Dy辵-YiuLfצi{wE߄E<<:im˘,DZrƨ ;)"o"ƶ9At#c2^)ЪkU "$EOjC roݍXjyDkI s3o]h5Eu \=rUGpj HY[KO) wٜ_-5߆3.ݹj)wPef@EϞ2>.긴%\jopKJ$Y-|q{Xvȸ)z v L'z0.81_0}#! ğ>Cy> ЂD{^]88A"ZLLb΢<6ֳDk!=n8s'2ku5:szyt gj"wA9\W  f.W,}*B+Q p/e@zH ocl?x*f[8 U@1QqXmDf\g o%ε ҫClImبDJOgn-O?'g^hKNKK>ٜ{FCEwrV}K::'i9rQʵ} iPVNmcMC{ n)L*΢V}'%J %#!ܮiIOW-[aG\yFs+?aTlTM?ה >EQ)c3 Jo󤰚~ARo y3_M‘f? (a /زHD8)uޚָ6||E) K-IsƑ><3fJ@&y؜V.FF3j:(nm+f(xJ '8t2 r-+ɋpHD5잊'\H;tFk|K6+Α0IYe3Sy*aS>1SO2osQÍxb0٢!O1mFە9o=I/%!ҽhAp?(_)w&6TC@pY, t{HGjs9f7^k+|wuNمF"N `D0Q7?@] m*MK?Ū7lmQ3Fg4,IeGYB%k2K$sJCuP_SX0 @B}ߌwsv߁1Uؽ#+7J̓Y$4|0h1q:rzF@oKsP k`}~dS3H?}ul'IS/59+YjKv@w 臰if0G {BHōR+|=*BfJmUi@^*D\eB%y8xUw!L΃N0yTzPs)6Hpq[ǔ1aP ߩjJBw&Xvhewx*|Y,A&*T̬fZ*:MSL(v4lQT:Jܛ(jЗlJNIS`]?;rDFg%jیQ~8"/,캸2wv)Ro/33vMzv eX3">kH;=WKlJy;-vNdgY*ddb Gt2)әVL0dHdMdKÄC^cV7ItZG> h|G{,.*Tk*I#2JfNqJA&ueSlwRGT04m}e, NFpHv0QũG؎lSZ[0AZ!:̭].TViw)#]MjQ]c&/M]Vӌc-ЖyFG 6z͒ZT6QsZ@[]i8)=}R=C?8\Y7/)&w['|~<< D Vh zS'mIIFHJw{bGz#*o>oMϴ!_͝^\ߺ RD @q7"$=җI^D`r^sOÃjuN£^*-1TiՕVk2fV-nSˇKD. 3ft=o^&eCNйV^Jw4RڍI\8,\IRG1*. q3HeZ@Ht$WuNHOΎ( `aSaxC -l/ ^#NДz2}2ҪյT+ b"0]ɐ!"kQv4dEHS+w+g; Z7LaQ9{V #;(GTn%N ۄBؘ|]Rn&(%,u@p;ָHݵQ)K52 `[MRwq-j]oN`#,D,l"!tv.. E)~~tX"%0;rbMNʝ}``u,/E41A>I"e7˓ , n.,zQ K6\G)rxLMafgiZF1^-u+B*de5*z [ԄH ۜ@%`baAªOY[ޠ.exuySxcdr U zt/URajb& ohL*!=W HWwn?_XVʌt6aN cpUAY8,ˣO~~˥*51Xte!!YAҒѩSR #a<1pT ̻;4byIx®0P@-3/8\u|8& BHnS>o(ӎ;z =R1Ijn'fy^Ft"4YTPGkUBe9h֢'yܢ˴sIX?.$`t& 4*[HqG~0H-)RqV{9%HaY}!\WDa(Rqb1j9ل__Eeti|`hRMUd#bLPJ^7ڤ GvBY()eC)+8;¸aH*]qL"[-QP ѬCթ)R{wY: hzqp~' 6'm½EzfdTۺ"Thϼ5("pvRNMcu9SS 4"Wxxm3}*>,wU/Qjy_Ihq߶g49e1ZmJ=tT5^lvӁFTҰ?TpwhTR2)gYw@fQZY7ei!4"ޮlUuM `6n0(AwԮbd.*+rwqhoyCT32=Rh "&\KdWze<`GX'Q☎-+#a_[S")-Ua걼X宕-xG/%+2DfY,F^P)-BĨE(L1T`/MB -W Rf1ie{ Y_baF`OĤ'x^cOh>glp<]jŋgs 2Mb mjt'BXt zo0ec}IF&9bt?D!?"6BP7e8#Lb< 1UMO#;4hk3_5{DO.7r'm E:q``N㯶ʝTnJ}%T>~EMG'45SW+Bst-g?w.aPUvߏdUC^L:A B` .$RtP\hg)7 mUkP㝉@â/DB%4A42>閪>Eqv  Tj.@8}^~< KV(}נ@CQTTuuj9*j2L &Na,.;8fk5 \{(# m.+ fNweLʐS22ǛnљG`WK3 ^2` ;ȥyrRfk!TLN%Bk}Jh{B9u:`E3 `KPY/o6{1z\nVՆ~mʌS1 S@A]@ */s~BB/˜^Vmi8%53bŶΩ Wp2C2n7)܀h1u#nj\1eD $f}ۇ}0ѳ5t}חkA! e[S=U;UjKB`xng}hR+,bZR<[%cT{1ڐ d4IKuM-Puя76_P4&5p?Zlr@S8_DCLvRj3Զ؋bNC]_+X,O( SA m괁KCC_ʀFN6i騑8l2s ߮9B+!u}PDTwڡ>-ą䷷[YUXY7IZ Ḷ L B!90,3DUCB u -4(ىZL=+3h@}vG]R몲АxYYv 24^~v _b}NٷJW޵p `]4 8:85*X}/QREQ ~8G ]Exq8z+4Zk'I&F;gLdžyH7hp3h%w:d8 =y6h\`.UO" ERSFӄB9{3;y:Ʈo${l:wANh]TaFf=ICϗ>y[|ED$(#!S(r *cSTX/,c+b8W(RkIg|,ikzPM.+etӷ}pГCHjhx3l*'E| Cen/8PWOC3iKŐn+?w'V&]IU`$dl;\Y ArmSۊw+ >8đq[M±)6s?W9{#"WpAUY Yǔ#af%؆Bw xv\ ⇁2~jD=y;w- !@>[ʌnn?#W Ѡ#"x#w]&]Up*Q R3o5b5]8%F}cw .P~ `iG*$FޖAa ps2b 9BOۍ]czhkT2{-TY16ݓތwtr[fL+Zr4VǡsfjG.[ш'9Mn5BjFW4ږJ]peoow'xGM[:qF:\xoTj~8ȼ24riHM}.P4 ($N>ff T.b`Uue\8]B xl<3y5iZp^83CY:jdPK V $I\}NPs˽|I6kz4IIsl̝}[3xC$tyQWx_E!W:l0j/:lR-W;^M)J02 Gc߻Lb~o7L Inlѵ:k,hN|z\v_ +:˓ o H:Wcħe'reyCW*Ōa_9yb,yXeUsr*j+Z5aG^-.L hHa=Y+bR:q0y8j}FNaq3$uGM3@Lr.NF@PL7j){U+_ xH1@GHڔ6\۠/#X[FǙI<|cе܄IRhԛM%Y'7u? ډt/[δ%Ix] SCȌ#5s3`5^GʒgW)i-֑ב.Z˜ F`14O{c3~ai- )w^g ?Di$nK1va8vօ-DRjS7)W,&X+ w JyjZÓe#8;oڍl_ly/EץwSD:Y;H73D/aw~>R~ͷ ޏo5M] М?5K4ִ%J#d’âN/ѷNR9f_H /6o*mGJB+sEBA|f%J!.#C av4}coJnˮKhv;[v W m @ Rw^3MB9e%ڵ؛51)GGGxz[?(WR?r4BlXVT08u;!zWVV}C +G:7_)C7 W2!~eiXK ae|4fw+PHrkq [js˿PI kLNBA A%%MrG ޭaS>RE**JG 8] isTjN `*4e x(:ľnӥ4ւ'!/D |YإgWݤ^_CZZ*Pu9 abhhr 2\-N&n՟Kw]0eOVERm&@MBa;ȀL!=:|P.[B E#}ƍN=OlF=_/mӝ WR+`p+Yko01m4dу~%!"pB"#=1F 觢)* ڣP`I۴u|PLZ}3}ur'o]Zբ& } eSf{GS̶Fן@r㛣?e@*.uSϖHJ 8u&M )Ҍ›An<|OjC +p_{CN'K 4A4Λ|쎕YM?}CUCKEs/TOj ݇"}PFU; Rz9&Rwo /΀E_NIaJqtF @}Nd << Z$nFAmK6si-U7G\OD2~cpD1[Y2B< ?r6 dYCTpfW!cƶm3$ƞk3yg!( R v3exqp: -֕vUt.[ Ϸ;4q070 vhŶӯQ,W:A]"?'7 hD~PqY9 F&+D yC_2 ',7tj'mf!V!c`Uڢ3].Le'Q-yЮez 2$?bwR!FvD::dj_n6R|@a; ,{:[n(_zgVT41.|vF84z`#4S~%\ eI'?()r{I{ǯbSf.[ yO+qvmԘP~URCdFwXFާ \P[4bZes.!^gEtC2NCIhb;+-G\B;K%7ˋ'>52Ǫ+i1L[Sw%?ϋFȳ2oxLӑ{'Z4v V'ճgL9&*rU+˟@S3uʘFS5\L wS)dxJAq_4r`&9XѹH,6. O*᪁,&O;j'rj;je>bSU?Z`YR94(ЃoNGi1#I ]^Wۋ`尶#kbX9tiG?*lM(:TBC# fRv*]RZ@#G[ߕ5/-([sAcD70.wG("6u eʨh..4qԏti*eK,PzX Jz u`(0%8[܇- $'`.vrjt?-b}KNjAө-X]d|AfP-Z`̌ 9<)|t ]Ȗa韾AS{ u%K|Y\ZuJ8۵^zfPFPvp 2!xmXjC(1-̐ IG'mNo)R5u^]w'8N+dn6h?&Qz[zaV7sr̵jAn{uZ@YXzHF 2s>:9 :cNE1AqۦKƅMύXAsZ3$J@4Ųi |]*^2"AEL8a$ =rcܳǼdt_c+(>؜ˇRL+)ԘHȈ1N:Tիa cc8nX;.|aDD3kKqV(CDc9XNt Q$,]뎔zM坑BM9 6VC[a;-x#8dͮLAm:48# b̪o+Џ/U^CKw_]9oCphf/PE&.9= s]KTn}o':m]EϹyݔ 7X%?ލ\8\WIeQPb۞˷$ZJa˫먿JWD#;~@Kt:ߡ5!;U+h^^k*Z{h4_sY3"%Ii=OV)u?ͣ!^;4Fk]%iu`&t_cģnjee@fnUE z0N+gNNi]|ϿSm"K@Z2f6"1N O)TK$j4^}$Y(:lW B}>1A\c*\H!a,fZe4T:FPX寳e5}US-=-Wg+m"*9/~Տ!ÏTyuCDt]0P{_e=eV_gZԂ/2T -pz+O X/ā,w| VYokȆ~8'Fٕ6 $ogo{S0QJwOGjO[eӁ- 8pc7,n?֪#Bv#RntmB8Jyqɴ-<鮢a'=eVѨigTd%e8QKI%5\f61Ij%5K*f4AA uÅ!G-Kl : i3Whf=:8f$f\ Fbܕz-+$U-Zڤ uLB#,gs|[0٠z101%inU[GcSBBdY!yopx$HFQ[5`dX*n,rHwwRr\p :F2z;j ]$$:MR wIBB+Sʮi[얭>"zsЖ[#|FqLZX<0.M1yX11~b+3+dbkxC؄җQY!D7D^gf1RNEQ՝o" u??g0gon/^Q#w}2pk#r?ʥ+?p<=wx5ah-߹7Ez&&ޡ'҇NMN4P}T|]Nز ̬$b鬑o %q,K@[ޮwt[7f5x=-1ܑR]l:%o ,6&F) ӟ$z4塴bͮ5n6]A1~u9W9STt&VߑȖg~0Ev92|t5~(߃i}p>9H'ҰG xa)drp)$;L |fRZlFC/uH`﫧.TΙΘo" ## ] jHsluKAuڃw<ULy>S8M,O+$޿>~\,j*=9l}Fޅ!)NZh:w3:_rK[ˑIFA.qAWDџd(ioKLJz}R Փr []YD1X ʶvU(8E9 O>eaWeu=!{0`T&챼d9`Pb'ic_:R41Bj= F@|D)8 ƥ ɗ}h6T2U꫷]]qod͌\LJlI7 ŻHR쨂Bv^#KRlQhK^Kb}BN/Oh:Z8_xğػWo3LįM J_q^~b|g W{w2UB襛 ]qJ<uhbv`<U=C$_ED%v TWʤ%aD( -#ĦEZz!9\yȰ(>|X{?KK`_A|l[ViF ڭ+pweuUg`굡Vwg%<xM1([LU.F1Ω!~U++kByЗ=bpCt7,8u7I DcqY ߯D[2"(;3Nc=Tzzl(7Y(#T`WѷS+,S#fO~5$ṛ½ūgAH@d6dSP+ڼN_q}@n. y,ZG{tQeW͏#sE6jNjD7%ƍB+lԑ=fS茂JT.DHvB&{ޚejuTExpg` #Z|ozה:W72f[;\Y*ް]xӢ٪Pm7`G\u # MvZ\$ 5-/z,8vUF CBGRXO6k!.љ|Ӄ?27Go-+j܊kކ.dS#aҔ $9 ӆɑ!Gfȡտuz{RWzS>ocH`)]K'`!&8q%G͵F _R)ǘ}gl>֘ Cu282ia{𜊃'毧Ll +Zz{Z9{@<3]?0H(cQB XqٟH?`\V,";>3i%d,PTxL߰({s=wJLןGw$moʼ2@zߎ`~5-A/< 6 GсNOVhg`K2Sv ޭ ^/؂ghm[1Ŏ32ڰ^ey\5\j;;;ۈj, 驺ퟂ+cnfgL+tp%" Ŵ+qiu^Z,?bR%8/(d~"r2}`C22\6,_z\ jX9+q[;mW f ~-35Oxh1?b*^L !䏓0㭙k ie+Ihq?|jy 7Qm,DŽ?jQAy2{8X[B &c Zo_U5*2Usn&}jm]N'JXg[b6ș3fC oM&+BHh״Ceu0D8qa$Li$i819H+QVN>%5f%:B]>Su6e4 HNOХ"Pb|;f,?A%QRdPKIP$#Q JhRuGI&қcp]\+8e"-_#A%vMjk?;dQF}T=áVK;*ġc[d3'@s&VL6+OWdy䝧/8B)/W^RLiFj&Mo=O\)k lSEvVϚ7{?qY "F ,L`׶~+GȺ`VTd,+_ fGHY]Xx $<> od`rTpvv^^k :\4Kh%fm$g-;!, *ߊ6PFэZ~r]+aj:T7)ͩjǨF Xۮ/͚UȠ܍ǧD'MBB먰x>;WNF%uFGLu`FJؚؑstw}7{8[M(QztlRP'&Q29԰~&$G}ϻd dC:N*IK!c,\-F~&XEAvvrW Gv: EU[9fZ8/eݠO<~y8.M|eP:X&bAO >(u#,Tcvܨ#cƞIhNA+I.&A`}!ETRÔld 3絿 >_zېͧݿWHϝj"XU eB; /~sHߖ8XD*i@+~q_=CNyJߠbj<<O& WʷĴ=tgq~d6ʹvՃH˭A\QR,"n\P7f`'w$YZ0) &TX"!xElgz&A- }%bY' 02bL.W4N{`6!y|)ā ]'E\V'ڻȪ |l.- 6"a=^u공M7nv][&^̌+WCUg 1}/(9&XzLSfyu1Qpl`7v~@&lTB~VTpHqn./o ]18W[̺BbGyѸQ|jV.M\wՈo2K> J*ab& }Gf:a£R3$y<qTR>|358.m=Ub)w!41 b-y:Aَb:&0jF.͇Fg3Ce_vRkٗ #K]ụ!_p2 782cO0>nY8{ߦ;†G9is`1~~-x;kB9i}O(iDoK'{E;P)y戣[ BV]usۂ:T.KWY&u\~sB";$|a|!^vz'p,Cz_Ҋ̡\`"&W(*z9.OyUEBmPCѭpG'fQ[rY{M{'!^L, H=Cf%)yKa/<*A\VTb}ry"iY#Z_)5ՑZOj I1t .zd:PP><8GUk†hL+;%\cF; X[߆ @?(rϝ 2M?un,MvlƳ(HKr`6RiC+ V7(E?eB8Ql,H@}c 2b:r=i+<(s7,wƶ MrqHk>@50qlɉ@ MtXU!cdacA8"pWkrwnp|ǻk˲C Kxr:<e54]7'4dlgK+%^:otk uV׎*K+lYKkاtHwQGU\nQVu ̺W,&RH$tʲ`ɇ#PRT*o{a~$.Xx[d;(:sqBIt\I^9@H`|G6@ො0:"Hx>Pq⼢O(U!Lg73Jv\TnC hՌD 7bMZ2+yǏ3d|Ff~tș~{<̣ZO[0 q +fJ%ɏ1o lCZ, /0&YK?vuqE }Q8Y]y6sv "(76#X8䏣Z`R.o0霨jQ W|) TC! 5:]~J`Qv?񥅅4}-vd2nd"$o7W.&xm3zv tŭfOЎlsŏ) 9xhieBۤET]W< m=m[!i2ƣ͒7{UF=ށԣ5< E)Xa(7ؖ#@?hz`1} yό92 mpI!MA":C| 3|qn]-(MbUO|mjM-ǒүr.HNG~ɎFWIor< ĐJ.虢BC«65DeEFb?TUS1q!:.f.1 YEB=/D*&4ET^:Ol6EXj- B1 ]US̳ XHK7 dG(knr~Y:Qhpjc."x՜l%wş㻖d-DF<86,}CO b5pq<e: \]$A~ "(_L AmHj b6`Lqm^ͮT ܎>[+Dkts"hS4nB*X3v}=oh +RQ2]QrPXv[J,#a/z |ѥMT:-X!0̄$[}*QcE-H-Rlo{;&_IX ߞ 6 +S+\-3#%ker^CMy)4ʫK{B\ذ:[=m`Z 匊wvy`&Sh ] $g"]Onw.d!5l k@W O@1 IuiXqwUfZi>e|F_pibM]38-v8=|)IƮ`!I Huk/^k=6( `3p1X]&W7֦]'%- RM֮)M%.K'@Z!/TR- X9ԕn!bH4NؑFG|5aSĜt#nQ$ru/A!\sqӵlsX)<@"𳀹'+XI$z]W_(7[8tl6%D+;A@Zie##7ļ:ׁ At3,eQnDuȰztkSIyn: xtHǛZ`Z* UvNQPAΑĴE+,J! .ߤy$--9#]r4z`Q0a(ȷ [ll.oI@z<ב Gvt_@w]:V %c;~w?D". 8U=+˩Ezi"zE|1ƱAI9|!MAs+4fIMZ~CXn߅f4osT\_ހZ "`|V8~bfߡV~ZY_e6)gBAtkT>f[$޿*pSZ/4S SkѥA"̉Kc"1V[C`rL>!0NoyC% ~ـ> BLT]xX 7r>c iq~CH.𹟍XΎ{I6jncc{WWGd[B,}fﺱ@Dy҄6T؋R%y}GAqp2Br@|& o!,No$V߭?&X*H^wiz160Sj]K]{)\rZ2Y͹dA&X*f{tJ +goS<`&\Xq]SS@ }FC#D@٪1!?5%YP}"Gw"4]^^xQdʭON?u+jȅ֭%WDe 'RTVɟguP1yblGAJ/E"7LraUc]kN}kH߽9_;6w+dN$9"#=}fueX,?_4* _q/vB$%Ѽ.޻ cr6X\1GTGGssV*xȉ1eQ'}7XUS;^vy[rɅ FuLs 1oo%A؄Ma/xT)\Y^X#D:.9D~4=opJ$J6mE%% dEIȀy~EK{.Eoi/wajŽc@&46oros%_sk\XTW:ʾb B+7:F2]7FKl|Y\|UG(r;^Z5vm*a&%ft8Lro/FX]BOM'v<-|2YD.׳<(<,foe/a GlkRM`]C>U4,8{<^!C×Ɗ9gS3Q:T4迴#w{n)^+iNMi6KLT[|Y*ʘ! rk 6} F-TΑGUq(z/4-FH|ԦFwMM{C>n<6 p%8 XqP"gu>ً&mS/Yd{ɞrlG&[e#nu?qtjl8?ÙCwr-h4Yw.J%`D## Ǟ.'gmߧ Mk ,x+< 76b\(t_ٱ8{?ZAG|LeJjԺz4bߖ8{l27dtjG'li&Qz}}?],G#"K YhsR|--uT(Jd3|2*WEPEWX3ͬ| !Gn]{G(wC+#wжMvY/fh31z쨹WeA{3PEx$Xg ШNM|, .M<}K}pńf%o,BXGfQ+O8 G`{! ;cCy=fOsa0\>Շ4R,"(dkcÚݣf{_Bջewp䳧*mtЧv" f}uɗ`1gŢ,dK2Y0G=<:a" Vg|PC54Lۜ&1LHސx7ilT &'\v< Ҹrf3щA0m#~Ƒ?hdžJTAQێ{ 9Y>} 0oޝkдgY[{P,Ǔe`l ohNYeN zTw ÷7+IOEe8ʱR[.W#rc椆I3&c$0+}Jk' P֧)[iNׇ~^&PLqgpֶʇ Ȕ"NڟYӮq H!ΘzZ1RRYѺBI_{c?>~ZG}h$إ[(T Flg/O[H4[EqF.3 q'1O,GU^v! huGxyBwN@Z)}`@փ)xCv  :B_]BD5ղLQg]*j鹤`h 9M+UVˣ[*kUt/2 $ATD7(̲c"Y7bNENW#aC'M/6s!i&y/+j@% uyW̪U_s@3WAЗQ4^(DwP^ '؆=݁ܚ$7եX-[f?m"dK+c~3*~JKu[y%\›-rT͝ [ ]UO-8 ӝ#LF.nt'G?˶XG0twDz{ן)1ȷO,0YE _22KUb7uT %+". "ZrАFNNh#2ՈבiP%X% Rl wP5 W/& V+Y)U9DDc?SCŪ#6:VR4u"TǮ1ΦlmeqX)/jkwEq[*\,hJWuI%m28,vu2S5Š\ιq5ay_8t_˝}g'[#)RԔG0] F"ϰR&m JqQF΃*]AIltzF,߁Yat1>50J]4Ԗ3tOι]wwZ tM+ʁ3N~qrzֲ_ Ƣ1^MwxlT[$?{Æ "-q9^(0j1˰}(*:m=u+IIuJN9LkPnxnB׋$ I1ywTI)y4w@,3aY<#_^o$.mjΈtݚwIr$x|(G!Pޭs爊XŷoJ:ȹ$ ) a}m}C<;C"BxA( 3Nϔq+ދ7ݦL8pT|A& u1)4(:ǩE>LȰ%EQ [NE`!y` A-14c*&NoFX2Ŭ ʈûXMn: f- ڂPuj!j*X|g~;zaQ9\ *Wx\SU(55DXH AbM^)HD Ѵ]PˢU 7 ELnw;e* 8|fCi(!0'7\t&V@SéCK.Ҁo&ʳ611'tzz@Zb@=v>{a= =Ixٻ0B8 j)_ןoDڋt8|)0آX SHV95?[qZj*@ptP-d#8ZZWKنk}S`TIA;IJZ\sc醐4ÒM>;c˦Нsz˝5'd%BM{>$ ""0]`LyZIANP}cy/> f1[uZq3}Κ؛fW\3r\V&PńFeyȕD~]Xڴ9|x%Ul;#÷lç,GՏqvAd'9AZxnW^[r')w3 ؇;p-i3r&y1wfpJ#+5!@H.ĹE>rs9y:}^@muP?k Wn.[ynEBgNPnϲb˜mX)Mn2i"mQ<(/$c(C 3N_7^bTDhrIDK P&PTR05L.).O+r&$u( ّ8Hj|2!cqOIgln;,sU*\,6̚}CISjm|WVDwҐ3ɐL%tCX{G ᕖٵ >ɾ<(SxZ*JXG4lR \~/-W(j6-nj3sIXk!oLULK 8=:xKMjY-yڭ`ɨyY5@QS@,Ev`mlxoaĻÙY"q՗keADo<#[+XFdYNZ!GBzD<:nwZMb٧<ڽf0Dvpl3aVDA6`rA Wnr9A+ jퟔ]4ֹn6"Dבt_E .\LBG}Gd(0g̘Bz?,1Ks1D5a0%Nekӗ%1c> = 8Xr@Q8 pi&{[LK)Y1Q>s>ǗSs0eָ{OmWoJaf*fA?#G5{5 _"3T}2& ՝iydrZE 'pNDfy "~rȔfZ(2L8.񴼪cHVpuCXZclS7K`f l^))5AS+n\aT&YM:VX3V^xb_'43bF1K铑L{]r/**!Y5̓ &Gy9AGX{gQ _KCN@&{YR'OqW(v=23߰~5 kfle E_АT_6E{,< Lnn`xq<pN?7MjJ5eE1kU|mDTG,H$ / [&huΠ-PWi5*Y ~z6:Hvev0o5r{ߺ]ł0ůa3RĶl3wAo.^f7oȝ$1,{miqQBa)!g>7ֱt2_ΚXCրi*R`"i\DsѲ;,3nKTh;0FӿqbFiyUB hocqA<!a0EpR n)y՚ y‹-mv'T?TRTzXhzw6|"9ƥ˶^f7If0r \GxY.#A/'>t}z玌=+W1ge&e3f}2v*oҘ7=B6ԭ G8%NT -YP\""ct3\5nš_ Ͼ)xԤN0{EB? xn"O%NZЂ3W=oLT ]tL7 `_,AjX[Za ~/`KG#{k6,k8->>PTP4 X;X /\Nݏv&˂Dkxko(8v @[Rt.T{6Vȃ]V8c1N@vt<|x$7,jIF9^MaYQ0߼a4)ѺRR21E| KYAvHR.1{WY%N@J XjoكB.MLAyBVHF)cװcGu7 (>F;ONV`e0vUKwg!JrA0{|vx3= q]C⯋Qixdn=ߢ\l=O: HK8pb1M{ӑP5~rb:emIrѱƓZDtmڭPl_󓂑<'򀇥WB{a KLKz Ft [4EdMBZ69}L:v6Ԯ%;6 pKVǙ>'eqҕЫʖuZMptDžJgvIlB;j~vYkW^$:TpZklJhgO\C4E$n@i9^ؑtRGxWa0|mܞ*Q t;L BKM\jt 5ʭҠMzߊ #j99?_5qMVL͕α=UłStH u~jripw91!i!0nb!VMgGhol̀UT!f%A xa%V EX1HVZ9|9y I(XE/w+ؗvu vmN]&ߔL:@,܂=6w"heGY]iQT;bm~[Ԓܣ\~)YB]r)~LHzGbѨ*+JU!RjztUw,+˛JzS+|T >ߢkq'K$-,>YFWqJ g8 %|{[R, ѵo?۝W/Cx|= U&G<৺hʤmd9HOAa?|M%K/ҳXTF٪Hqblۤ=}bm< 2(՗: )DmDkEҷY}Օb}kSDC\}o.*%*L|D{)$6Ǹ{!Z)#q@dnj=Ǎ8AxwrV+EN y$VR 9)B",/Tf ~Mʪ[n)`DqQ]E_ ,ۚhP$aZq3su pҞut[tt#)4{d=%=ީɞ=gg}fME~n(ƟZb-d bCW+ ~!g?Q kR6d$ Tp-4Q0s?=}6V|S:дΙj/UuCWZ%A eyHF4?>g0  {\эGe^=N8h@K z+}}Gt_rѩr.nfhqTUq!nTnN$NDpתwfH;"#&TvI@w@yKۃfDĵ%8]^O%W*E[?~2kem)K'x;k9Յ7g2IV>(|!tg@TBY1@i|Xǐ[.3,rχғcr6e U[&60A)IxsL~5_sȿ./Kmmf_y|w:J9-7YG槈zQQ +_@X> yZiv=jb~F`TaQ*0&jO#xbےJ{6*ߢBDٴ(I4qo '%=[Њ?$»h58WQeRɨ@DƠVj9tJm66G?+,c47Pg fǘ_bl~ء ]ךʯ{.F w/)t .t34$߄Sv ]ђrS9V&,Dnq!eگ ~/'w.ZA:6WI['K*dfyiz @vNEooX53hqB`BM gAnCv=ųg #4wB`BL;W[Z7i V9?aI3_ ~~()] q8/G{++0u;cHʭ8WuUҟT$ද]0tZ}4`d?пZZE(Jy&{?OŒ2jzÌ QVTؕP7^fcG*Ip] hܽ"me?^7wlPB;R)bb;{,I-Y~w^C@#6~}%BC0s+KVkvKU}B"jHl'E:/U&PgE+К[6:BsHaޣ uR~ϣNB9| D$ j}+i>~ZoOFiiur*ˎkVjjR=FR& udIW0qC3V[Mc ]hQx6UW]˱`buCZ<Hy:IPJuÆ PsLq?oxyӔi 鰅 hl,S}%3~5E1d,WC##3^ xA~ـnT_#ӛL[ԍ?` 7~1ާoJ$/{?(Sq]nV=CbD`~u8ZIEF~†pio!S6.5_[?Uޚ7e"|n(]ٻyq]b nXL˨ku҄_ԝxVԐT`n>֕x |,j mdl{s+)U]Fkh?z#2L^Mə=ArnD]vM-q~ĞrC>BO0/ؽ!G{ 72k;MH>f|#:"W|rQ-A5U 9boT1Oa,Hג8`\(6:-Pm.pvD/z)&ruAJ^ViH[(1X:ÑJ Z('^|ǷӏB\`B57۾C^J 2lEkDaA TiWW?34/c"c`뒰Rߪ8_:$z.KW~s541E=\&} )` 6PuASڄ<.^ O,޿K׆3j8%ran)eLi2WO'tz]=Oӵb7D􇤙``8:ПiT)s,5W 8f}kb _n6Z[V*dur*2=w*aqɹF FRmSLv4a:S  "B㑹 枧<4.Y+Ch!͛ȀS"1ygW(5(SZf~- q߾etw76X. 1uiZ+_%gx FRRywF~ZIQߦu__Ϣ1j#^sΡ+*W6 TI.JnTԡ:LL[ii'o @85Ef7rWeȼ>m4w<ӏL힜Zd 1"G\Gr:^ kjP9Gn\.x#8 L?=cm#r7hwR`͇fN^67C yvZܓMhZްe dgH"X=lZ*CA>&tyLYY\#55:$&@?NZu5{V;GL;^2^Չ?3ˀNJ1n]&(,PgMU+*تϾϚ-okiҩ=nrsmN>1[QmmNO71 pK a[gkCسbxo"YaGF4!th ۩ӔPJ}tnuuAB*w#a7{_ݰ[R^U`N E W/賮gmMʿi_'M Q6<9};ѮE}wG4oKf%1Q( pˍB6)^1a\٦ NX7/);5?O QPn:$y#x ;E |4|Pͮd`Yf=.l9 K#SM^ lG am2Lk!"Q:ɦ_TBm8"r?WCg(<~{*ڍw0bAhIqQwGe`o{?BApkg8`b>_|2j6hIc]'b:1cBlR}aD[ 0I[:xStZ"d7Ŋ:'F5 {EQû˞8;hQypܤ {5S*{O[)"Dj9.7=E jdSLۂPJ6n>w3iF}dv}W$4!|T/:wjeD "~B{&$N1ۘ"Wsl&Im _8r: yw&x_teFO>6F"+]6ɑWqrGP7]`QF/,}mJ't? *],C6& Ph6!Rn(k_2eX ; 3Qc;ci/-kE\S։ Sz!c2ao{c)U@1ʼnMt~^⑕FrB2Fv]ؿ 5)}s~AtLKI"8p˸iCEPՍm*b0ljӍN@%zZﮟh؃Ɲm3eGF2k㵆7n(0O-Mp{:n}T^Zr+j *TA {V=jȊ|g V8_To]$HdF%1 !._&y{<b9Wp)FR/24Yk*$JwwxBnf4Mk*Ij]LwQƾ2xDS8dI$ym@:U^6Ǯ݅NIvP\G&}:LLVScv&G#;֙G- cTm<|\3.}c Y;P4],ۥv_^5k#=w4F#|FA#3=.K[Z(swNp,w z\ '39bƑp (,zoE}  -[n6(lAU%0ƺ}E w24ɐԄ/_tc͑u@Yh=|+Y>iK]1( {:|_%qLj~`7lƅ ՅųgakRn?'˚ (U +1]}{I'bt=͙`Mb*| ]~ע-;q Iެtgm;]utp~1*8LXpZ0d'-Q)Y]',L!\ VFuk&?%% r&ޮ<Ȳmè518m\s cHg'AaJYsr^T+9&).ʿ5Ym߻&KI!@.q,: 왠&MFjՕ{+ȣ(Xj$} Kf>a/XW9|G 1(r;>l=l< k$L6 gLoa -mi )}&Hz ~B=z3×ĥkHji<0sI]#U$6Nz(p5(`ᇨ\:ʑ6wEb-φk X=OM1֯Ct#XjtXIq3oR<2aAý$e cm-9TDgY_eE0vBZ3*ɢo(GBtNatb؟*cP33VֆIA?>D3#oYD|Wǡ ߫\\ Ė;h=[urt@0)ۂcݕ[RP/ft=E!NGZAzn02Z#'!UZ>h=a;oC<YHbB.*9;!I~Q~ާ`Ӵspli#^e!mJM]Vcc*%xa˸2z䉣UdؔMɺ.(#l^&m2^ 5AND(R4:{d`m?L'kaj̏]_[역/?-U wY"#dү Vi y;EA͢(L)4k-zH׶yiTkeXm @E }]h}+JtMwv@#GA>G"uZh1om.-L]I Ty vexSY?7/ȟD&Vk,bolvSs֡ `KV/7zᲡ`'Ψ)|S? ͂ژ|I#KΡ4a Sh@=)MRJ2,hIIXߖmK3v$ub'.;bH|u󕒑=ut8΍;o}1x?߶ې+"wpH"j[ cXWf"I<~DzYs~z*'E2mP#6fuJ&X] #0p(,M^QKiUQ;OyuX ~^NS봌0؁LF WEq2kP0bS`T4:#hLaDar"("aQ]Rr᪞nj*Iղ5jfk'EX^6H(-:'M0ߔl ŏ!lD8$"nc32ϔ5[^'PQ1h\ը%K< .$92q,?/r)Etn0a&QlȮ s[ Z QF)r# #qӦT U6 ; m(Bv|x.s y^d B!]ɩ!l*dARy;_3lt6[)yj_<iThqӖUƁ#VKf7~vqZ6ѦojF_rH>f,gp@LH QIiЮ(\gʗfsM:y,u+iQoI*rhpo':$?U,H^<_qlY00w'2<"16đ,۰yh/,2v-7M ΅1> ? rH^zP ADAt!i={0ɦzA| 7֝ gc9K(/ޒ[V*3[,+/&OcW'} |g3-qKKkt% ͛bA/rʓx9V44`^ vz rٻI<֟O(?ݵs@ρ/|c  Lg^>"e)PNB E)"POm&G8s.7g)wy@bVDzCB7wW {>{eŘƓίP+ ⽮j%gm@xƆDR3HO>o~u "ܾ0eltr^KM[RB6N݃& 2Ε˜ce[wj3}cYG:)8[ŤHǰbi̩3UA9M%N҈\w3Bp2ŒկCPXTE]"ۿc돫eڼ< fx@ŜKmj)+ áL}N]笖^z9`sn<ݵTKys*\VA9Њ @ڏQ93K\ҏ,F=@Do]?|J`eYw2ß{+Lj I+徒w2.V[ ;9Jv˖ >86^YpإBg ,{pdՌb{;]yՎ6dxXr8iaow{cS`kc=N LPAH>H+ŗ͙XH8&qcMQZҳnm;˧yQgmF'Fi6~7tZ)^cE]8g\& +>N!< 876ǝ!-:R>p}fL[+`x8zb| _! ܫ`d r*"45JTsJ [gb^_*H%: ~@zî3=ia]CKj&X7R9dl!ӹjL in8@ v9Ȁ!eR&{;B9ު~e]ghO5?#`p!LlW +YOp~e̬gvëA]^3Hݮ=\_3G|T*Jtܿ,aK (~49ׂMl'Q8‘ygy)| tNڄx_6MU׾g&by#"}.L#'yixuBf,xA#9<@ZrOj[b*RU x d6S)FOX *.f?)l`juLUA4UFv/zovT[exL, M2i)3'YyQmO{*k14o2a6RGFvZ6_TLa§[0%ZcIQj9?3t2љT:MQ?<| }N3wK|4ڰO/:L'Pef(YLb=}Qup9+;d,ȆS~|zއF;LӑqlppRNӪnnmf3]KPpEm;$Q0~D /h{Ȃݿ=, >:i] 8ȝ%1)u޲3  >aAbwRD# %k9קZh՘*nsd |#!)M<p"N{5T5&*_ yc%D 6JQ׋E1u*t @Q< lgW6'fa(ʜ3~tdY`]kA Qe`p?^W*ڈ-iL)6=Fă;nRRzwM졌e(XNH'3HN!IU:_[+;z͒,͍.{NN!֓\-Q].۰nU1'}ay='mg3 /OI^} ^@$( ˆ( p6K0WeE mT*}[V.,e2Iab*TOyDpm(\ ]M)^=P1!$7+|yO+e:6mtXmse@ͦqGCuzP","]ޤ7:x I-Y,w8>5P| MEfSkj4{maejth *\ed-o4ɛ)oꅜteOh[3s"wVř"NM.Ѭm{mjj(N.z{d} e 5)(EEa?drk'xDDct=*?V Σb3 n{^q#IC%w&=dQ+~G; jZ@Y*ATU{'ϴV*{y*],s8]Y1'vEOexԏ4WR@QlQ,džӨlؚ^qʹYVL3R̴@:9]3s06u`Ys x &Nx_S_^qn~g8}lﯞ$S5A>兂ːVOqmh[j |6hA(Cz#ptC]G{!k sk)x,JU8Ixp4-.nOSzty;3{-c1)YM",h@"զXAu-4p/,w9+:ԎBA$Gp+<G\*u݄ >@DVGH3J}<%CO&증 $Sg*`eYKPÞq1F,DolNL3f! DKzt؅*֜5ۑC<ҁ&#47im1>aC$z}8>cCGB҉q|;1#4_C\oN W{@'h'd"Ş? oyg`2~bys],.bR><##ܡPb"W^82#Α!,-sv(fa ='xTwYVu,aswߥe;Abαe |[[-@wh~R"6 K6gJק*H [P^~.|f9$N~MUU JQ(PM5ҳc]w.V=zWBX b K4I%Ro" a:QL 0m:eV"\8L'춅Rf#A0#%iX9ezx*UE8W yE^qY2b8 |l”7_ق }Ki\IVkT ٚiϧt}̍2<3D,Ibh,ə0q;QF/%B4Cu:YCeO9G>/v ,=En)*,J}1Oi8.Y `ԫP=동s?>1I/*ʝWUjdyDw:tLǍM\:\h>gB; gBSM}ݡ>>l,{|8bKw=rD4Cb?^2H'1+/H\dŜЋNϋT"{ $F.74E1+S M$ϭ;(DR#9oRjtܵKH o*..ڂĜmU$6Le.X(u*B׾ɅT7ƌ!'q<σSs2~2hSkʞ}F~~%'5܊Zl>w-؟nD.8{fRkZ0V76 x N]c}墆e-*ya52E&XQGjyG^,ߡA"u\zv2-צPyl!s[fҗ1` o]5Ƞrd4ۢK]E[+Z3/G+/tu zn9}Q|I#jJ~ͼ@~HNrЯ+OlMEݫZu'̥BsV=EVQEJ'aU@cj㷈n ltgKٹX6ztF]_S{ZnLcV]-"8%e6 k̓ WLwՖ95`I*yLJG$C}v P|O2 n@E,eYTkc'`XW#U+f'ܚրE=5Ey )}"],~SHq1F/a.tݾAȜ!q]Gou.B;rpNdׄ"&׸UBfQr@IaVZ3smi7a=m:v%^[9ba}SO4s5(!OVzV˳ } }ǂVc¶PnƲ 8C^mN*xY= 4 _7ك~6O<1mv1/ZHTF]@^э*#WܠU{' K&j1ٸWK\ƱU@e&GpHޏM]6{jcX(>FSEN-IPwՃ;Gf;V6]tTd'ƻvL )/lW5P Q6)c^6O?.e _&g77E3MQS.Л ]HtH~q vF:/Xs.te/ZZ6hO2Zmz/4@NlI.1M-HkB4ZNڊLTWJPoJ[y̅*$Z$ELvpa#!;n [26eqʮ "Aп$v)K PBKV'r=+A,yw@ϻںw"PNUi[oF!/cQ@9.7()6p 4R+B(A1\}x72uGUwnh馊n6E_H酸>)CEFnspVS`FD_gJ/`f6 &9 L/:CZ^lF춶b>7*;x.»'H|) ~-2m<=Lܔ1!t]B*aĴٙ@qhk+ 'rоAEj[fUȵa%> SS))"3\'zFj,rLEJŸO.@C,z!2Ƭ9Bz0˱p " ,Laxqpnb驕Ԅ;$]pL= wrާxVEС@; #GH>2s[],?4P3iZ,zte 6p+ L1&kv?VHjp8}=E \ 9ۀgL/sZ8@vǩ|vWp^hbtm ,#R)gKCZvCFd[EW,E%6C^6>]_t$}/#Bi jd/(V|g@anaE125#+GKtQEӐuR4^N-_.J.!ЉؘP`}ןY#̛e8sHxFdoו(m'P]H;2c:|qpZ-aPݦ?BՂ4AO ng {#~HƲq#h`]n8(!#*ѡCr ? Y>)HzS&=nޯ oɔ5t\)8GL;Q<0`D(ԫ4iukMJ].d2=1s ==zV3 |BtAW,go ;g;q#-h:Z|eLd7^q5mR];Z rjI (-uӵxGqCÿ7(KsIQ;fW6cu`Nꈺo)貟m!$}gt$+قRsc{u֚WB Yr8cа*R뽪p (ν֦6H T5qn{lۭم\NP N ,b2C!"?1F!fԒ2ތ(i)cʮsCJ ;;CÛ^V_Bv<;>1+}bEC9=Z/uE5q>RB^q{r6W(^ѹROu>H,fOF R:Dͱf\Z3¼9`k{aiAMHc(Lٽ6g!?(qV@>cQ V l N6 Cšu5cѫ(2++4(8lt'іp}8NtE/< E[ 2EUn(f{(]9({9>L}:C# +uL+} %˟j"(oL?We4Q5!z5/){&*b0wˈ0B|6Z=Q \eDTbvP?:O?س?鋉F~;ppuP>;%~}LNLUšx4oouђZ"|W(u mےI6Iدr~Awk$.ҰN =m7Cdw z}T^;'n{Lgcw`0?7ңޏrl'ps!)Pve=ç[wًiP0FSĊF"t x z¸D,K>bkϏ@ OR &u?KgI=)IA 0X" Ə4%!=/c78ό@Uxa ;v+2;1zm?vσȋa+*E.^X$ݟ+:hHQJp*$$4U+X(Uꁺwr 91\ -Q 4_}ݿ^|N2kQI ᨲZ&.C RvmʧApVYZ.(7pZ5x"|ym\A6->PtO,*ﳅ =}6HwϪbgZn/t+B6uf2x24l#qZ&b1 Yy \:?ȸx&zOr3$03Do֣*rh~+Tzz%$:,s&\P\;MOlvjγ#ٙ۸7!KX}1R/@D?p9+AX RL wUφ;ؚ J_}z'L ~d"0hKe i}wҀގkb\UJZ'Հrdd8}:]9C>@bvtwꩩ$ $~jO~LڍqЧx^\QQ'SdigyxGsVǤKIv]Y_na1q_B# [Y!J}gwZ9#1BKrsYo"u{loQ\WS}tEOJ6/<Z 7 [m#R Qk6C0m&&Q"b.}4kP ףH^e^\f[MizZ7T)iC2j7̦oVG9KBW1UrA#{+:7Q̥ & '/hJ^귶u3t>b|< ;&͂J"ؐԶ3BDsU[Q#6r?޺g'F@]ψCG~D+J6@B9f2MK `~hE2*p>sd{ #>юQӽym|&%q9!F82ɲ5:VvW9\KS R4"*5!@h=GVlD(lM̉USjy; 2ۯtǨeEdtG~^~ 4Iv~G:5%yϩO wM eWxK3.~zs Bxn7QIqs7t@r~Ɣhpz)]-0mݣ{/ #Px1~.D|$VlOE 0,YV*R7-"f|B$J(MɝSh@ K0T M5.k:t?j Ο6Ep"DOS0]י%ea'<5?)%e/E5׺x8Y2 ɞ^j8Rm ĈaPr-pȻю/@Ź؂<1'I%43QDکT_Ӟ9RT&n ~.!vG}SB|pu>'d@@";4 Zť4'W%NC80"}<e}_dZ4n;n+"vdytv_,k9]%Hf`⮃oQB*6@9_lz|B|q-%qRDX3ho-M0q˗Zf jdfo+uv#t~aƴ^{e`oo+UtrǿXHWUpJ5Pk:% `nyU/n}1ŏs4_L>A>jj](ZM:r)j3:H6D,,GMҩ ОQJpebnf +#޾ @Y^Hlf1S }E.W֗{pܮ? a7Wi%JQt#ፍOa,P9Di8Pm`4553b9⵭QSptNN Y@l^]l'GGDBK -)*v٥U96TmSm64) jg)Koq}Ş'OD3sT )ʍ¼d#ދj&\901pVЧp§Z]#+qW <5|3d? 4Lw Y꒥_`ttOPRNxcku ѰGP, K%yb>`(0(g;`C , a@wAsSo٧"^I: ;~:VrpgPP|wb/Z@fOz@{iY?ɬ'"crPU]8hwvͨ҂?/PJkQZٸ_O|Qֺd/T%C?WqWh0eۯq^Dq~:akAs@jR}לpȚD< RMG?JIYpSm'kC.QӞ9 *@*̘}{̦Ƹyj 5\2{^~X7نWds1dvfM )T󎌗z6''z0q vCPl @6{%I6+'{Q gh {m*{Z~4O7 DfXBâ ] ]k&i]u**C48b8}v^{ Ag,w^ xUxY5FbLz7O6gQWejs 7 i!#gi`wX;Q~$ TS'iJjC j8ziITZ(ΗHcN)&@{/nn3 Qo:қ{+7(ejW޹L~.ߊL.m< NΪ+Ȼ\N(M zJIv^'VUYs*hnfA9ޙsXޑcv:pR ʶ2c6 mc갇ܖYfc=6`[SZ>X<$ 3֫uuN3:G$|9<2w6pK\[ffW@ys}q(@8todcљ*Gzl/t[x:n<c?EHY. \xzƅA]ѧ.Z-Xo;la/U 4vN"ޝByvhpn{<Ћd1m.fO1;qxPSd7~Y( sYNj}Knj/7pAa3t.Qr>CDvnr#Ȋ DTI>*e*$RO~r#Q p:'/@e{\";WF9_HDPguל9@&Nr6J:`?QF*(anTOP(EnW"ᨪi"ӲX{[ʗdNFx@Ҹ+.=d,0 7͘kc`ˌG7"ʥfb|T_6H5k8G{%N1)(Eڇ@r.qwöb,.1Nv9)w&m~r=e_2#jk~W}<|Tzb?I7Ƃ"og ?F`my}H;z15,cuqKSloyf)JJf}Bd&7}|CX$=/;е>n 7ꍌF=BZrfZ߽.y`~dY4;ҋʿ:.$b}9k~Ⱦz :vȽo#e5t8`xPrFäy"]0AC*S{q, 2mMS) />mL8vmJ*W@ )E A=76s/cFf@)𯫝;Dslφ>iFϢy8:Z>M@0x?EB]X1X2i oC٭m1 ڌ67P$@$>-_X`xzWJe6>Q]Y4Duff۱(zԺAAU\|\,C8! FiL|IL3h1DM̦"-# Zw`-rRQNѼp.Μeep%K0ٶL7Og Vs S 4@5OIfH֢&鵥ĩB%R7Vɻ"CH}yR~)֤qwܥLVb1ՓT) ʯ`LAuvу[(N|@#\A)}H"$zߓɀ6-ޖ!ZMX-vU//h?h r}&)0[T[1dZzO(Pɉ?/jf8y2邸#U7L/7B0)n!M4&)Jnؚp1XuU2S)ݏѐ`~k)r+6ޯAS?)ҕgHv~KVSxlˇ7Hi>AIFc.8`Qh%Oϗ]{F t,/.c)Gi|g|gr: +"fǺϽ''Oq?΢d>v9'.~L4]>at)fkjh EJ,jOhSY0h.Cj9H@ NB-}2^JYC-)Q[Q |>94@. (g75^icu> :筮a*9Xc[}*o ֓}A eixhiɏo4/o&sDF= 8|nʪ?c\NC*`kN܀9/P9,uݣzϋtKW:F4TtpW)4jzN%ne-Aї.gtXG: )??}f^?'1ݏ~md#zS##=To~.-;,ϖ@bcn&H sWɴ'-L鮐يl/Z*(6 R&^䬺CK|FZE:^nz_ }3rY&23:Baa0 s"@i3L|X/0,0H I~KIOt0Wj>gqk d VkR.[!m <,䋅/:T>H /7~!p2; B.ڐez ˜T':c*7gT*ueX]㦤P$z9?q[\mUX|_2(MwCB1U 1[rɪ4a͓NoCfͻeΪ]@]+0d!9X(8FPI83`P!i%]%c5E%>@ǹ~IezC;b'a7N@%&\j&q&k ˩_w~}1;&K8(-?jJB@U&PHEW&vQG1q[_,Pu&LHplT#ysg"7:1]F*"{߉߸9rs mk6!v^w(jҥ#Z6/կhcY7s aa{ 9%1"^$^9Y',.v䴟1A]͉ ]s[ )9QB}#>F>@ai <ǫ#:jm-g>HK E~bYH\"~]pϝVov-08 LvǩBOsf40fM_j]ǘVKǠi<6aT۫I]RdfkgP]$]e 33=<MYbұ{hh3C$zQWwqςѻ`%|Ԉb8`PVW%]oQσQ>+kWTQ2V:I#&{tGBbt*Y > }_]L[hPYI#/U[:~HLְ^ ~]9LT[Gt`NR%Ux3xiUղ̻;+M7\A%#Wպp괈Fr&,OAlvTZH8i.^'SJLQ*~]$8mPz_dj0N:KfI+nY5[zon116ɿ%R44]R Oi~ . +nnf=m]G⩹V@jRi* tlr7ϱPT@\KUn N(-ݜWmdr1m?KCI Ǽ3Fym:v( ?>}5]:p(;qHnjsMqLrcv镁rNL4" So6y~upc8q@(QղQY24RO&L`CdֿҨi{5цMzJ'=ae'\jp3$rAPNWR>ܜLh9d*fEtjȕʏNӚ`<= #Ff Pz ayexb̗I="d/zٖ8Hן~!uOyH$zj *qwWYswr[F@M_#6zڥ-$}ȰXݐDlI0JrTc8% VnjfDXp̾VPFVdNËJhۦ%_lHS_lNc𶄔"F3!l=sL_YÏ_ ~\eٴ EGI` *HaeUs`˶߻j NtzTͽ&oHq "y]Gː[PbvyM2̶,=%BrIC<`Q|^0i:[R.tj9jĥXJ!1 Ü{+!e"3SYP CgK#j( 01~Ы f<8Q 컺fz(ĭd] $cGVʸu(X}[›e`-`FȜ uC R{6!Wp"H̅+$濟'g&:>eva~t{!!9OBُᤱdJ(Ha&dupYTO3|eL舽g7.GH?1&jvk̊Ǿt\Ͳ3iSjH[Z#̿8rݯZG@5|`UoXTԾ׋6 w46t}9AMhٵo} hCs@2q} \?8YrٯTl+e%<>e}gq LeNUtR(mDYޑϪfi ’u\h ]4=1cΑ>-B?v^sKLB+͑#a#jM3ȝ#(`i< y $ +`TY:RLs2 g8?B\b1uB{,pA5.`59b.Pp.5OOH%+r6@N,qHƗW{ao 4Ri.,֟V:[bUM:!/yՋ҄l(7;&E`A-NWE َk(>ydV2< M4)  &Kv}!B))T+`C̊s~ӡ:N5t L 7ko'NT%;8m69T!W2!)%k*!C79Bm9Rn6p::{rm([T+8c *AdqHn" .iSLi{?_% 4~11+ŮFS] &6K "lᥕ] 5}GU;=xb7 8~ #l4.ec\LcDW=od<%4u SsDW&-P{ϊچ[j_nA=dmx*I#[+uV_B<^p3|+eRʴpuA% LqbƵ]] b{MOBKq?8VtA*⒬B;#|x ,Sk|񪣂&rrfx:EEm.rEx=yJlT̂t+UKY> 3&NԞf2&g 3aWkP#H11Jgnsd,cGBM6\Fvdz(.Q3W+a !Jj!6aJ L.@7m\(d (+Asi~ fށ")`4LJFQ5.2^OlDLWh"ф( ݕ5U׮YݑL'AnGÜfM{2C~qfu2~] arKRD% X)M(I&XI`R)߸NT=S0Ӣp{^_f4!P(ZGڍnf[b|?UPUV 5G.77JR:\>}A2QJ- G 8yC+Zm@Vx0 咰 ]}Nn֬DKpsE{|Ad^ʻ]YaOM)~..|󕠀4۠_+?;ҐtW> Cin^i 9H%=^pS-b)t KR¥qRlt"~۔om-8$c|&(Tt ,^1{%Ga9bIV v&|0wO  1w65}g6kM( a:ҍ@_P:zm4(c;_LWhp9-*,~@.nj_#ɓ͔7"YWF4BB5J4Be{z#-8ߨboGҰW36SDӀ5{Y%\92$R%hLhq=7 ǜGSD>@M?t $:H"?jd"_ESU*4Nli_~otR"kB?Cl\JfχDeGVyFk"T= 14,L`H핐yrlVJ> Cg#AҔ̠Z#egrgsD5k3 VNX {s}reC:w*=xK>3/KyW JOc[LhsY6`BFGaI%:F+xM|Te'G!Rt댣GGJάSj~s Ӄ#.-;t`7̡(`:#7Yj#ќQj0@]Z֨@M8N@6:~ELo'A_B ɢX>]d:h>z6IҞ0Aa#iL+.;l$y]KȓߢI PD>mfӛ*qu;44yzf&?y U*^M{$a\0S_IWyU &7R /EK9=,A5$T>ߗBCmUŏeڻˑR0aR{_by"E;f#kcJ}Rښ]xEv0.7aZhgݲW>@Ur?po94@a"<|euj:Rjh4j\90n>"Ny xA)!h cà NYZ׽ۼ^VjZ$ C ʞD!z!>fʦk-fRaDMdmi+Ru:62#n{F'VomXQY_GөmWT7b\*}\xP})尋gH]޼GC[hbsU&޹4h.tpɜL˃3Y Žnp9$%⠗B&f(T0^1Sn"7jJXfcBfFrqrs_/4V$~a9'z,?Z83wҪ;N-ϰ6^>rcr B|zplV@ш~('|^hAP7 CLȳ0meh1'fl;|LG%Ef(lF^opP񣙆O!t]]m`;Cp-2PO;dgQ"-Te:5zf1-–D,Uv89QrA+(~"A#{+HM"t 5_,K>Źv^N ]kh僣%t1d|Ȼ}ûҌ%"fypcnxhR[Zs[<(p P _c?|c?Gd)NZo8}q+]Pɏ7?ZN:'h<݌`csE6mRk׼Z ;)SApLtNͽ)`pgޡedDU~/ЫEQg㗋5S"ls9 . 6Ћ ET߬Mzn\>x\8CQ=%Liq;2b熖7\Ic Mmwot٫8U@\YGqٳ60ƎcX D7o`R;N'rlŷ[D&:,j Ny HTuSR0JU<5OΨl“bU"i;%ڮ%! ʃ,E1C9> eo r+N0w+(.7Úkf aEOt XQwsBj{g=1Ed]r\'Hj(ͣS XSH4}ӕSC%(IGA+pm B5JqyL՞ N19o1O`<ķE ʧ!kY0{^Zoڱn,a>KCQk7Dm*vzkX-njYC< Le@Ir {O-~'".Pp%aZ^,2@BgɟX,N(,}Khu>/yȴ=Lwê,ǣDa4sY ˀ$Eõ{?Y&hZ^_ط v$czM,`ZdI,2֭*c??#B̦eX2yG1>GkTrUt} 9KOhS%dW,ae6g{Ihy^udOD}m0oD}L07-?aـ&)(UggƙBK"{'?8DGO* wn Á7P.8W!2=ͨ|rz'\n[q=`HԶ4_ZkkYtUF̞S0Ɵz_BD6HAzx8{2`` 1X parᅼ$Mݨd(39vBɣy1mLY+1DOXPf7}pb)L+, 4 cMIBœs8 mFԽ zÕZ6| $ѯ|@_`3Ӛ]`t٦2R;#yy{Řnc! wZH}-P3Ds#Eu"vzwY_'r^Ad`DZ)GAo $&j-rhJdIƟAe|tuT:LYT8Ŝ!`b':5Utioؔ1@/TP\Ǫ׍blYcsi&ŝkE ;Rb6Ga#GU*JΝ<\V^!AZTB lo q ;w$3wa;4VDGZ+ES]:g-N^ɸ&7+b ˥c7sHo} Goe-{ [;&?Wϐ]Ia#]VCpJ^Lz˲cО۝-(b f&>p# I@Զ!=6_+9RP* R#.qz_p\ا>@n*˶iX&BhS˅m w+sq+`mp0&pwulEf33rco/G:f`tl+pZ|ORcXIx7D?A]0Еܥ,(©':Zcq+nBqؿ vXﶋ=H*Z}Xch}|?d1>s1_r1hN +n&/EH|H?Bf.T('ݼRTߖ]kQ3_%V)[QbFԓtզ4|WyL!wȿ "L# GXU6im"vef!Y8J ް%16MFr[=`L?G m͂voog`+'PS\Cnf-?W-J(^nR=WC%'A]~&}]y{F26P(/cѳuS{a22@=ҒP%ÃhȖ"ރ$v~J/giuI{cbYxS\5IN"mތ1QzoC^#v4PQ˾.U GsrQl$kj;P-Y\7Z`6 "?}!Tq?^1[!ekw&EqD-@RtPV᠆݊I$`F8pxG.,CΌ:_[%EJr đΏ }Xe)T_6 ,xA* Q 9`7px8W ncTAAD7JU9~(z1Fd{0oV ǓRFە-vu\=r31# f Pu}w{1,x_ŬLm@NiUKGν܉/u濂D[r|݉:=1Y ϵ9OAlo f6)`+X(q\#|{xjoޚܿI_n >ֽ Ga^ZWnsO;PEnIx'L\?Q)ɵ`U*>|-S|̟1KF' TVERI0!}s 떼1WLPU Xw;'m]aX%jJ OeY7D b>(zr %e8Ԡ3db馢7:~2cWAx!Z:$/=ABS.9;269kT%AȄ2[$( }2rMgfc}8KݐLz]  )닾-{ 9ݼC+G|kGdy6濺>zdv]z W׷x<I"T8@!A#)A7!N.%_\ݩSA),.VGڭ'9lؠP/r{f?Ys!ChjM+p2X(N}($Z~[MMR~1eqN0 dۘ`6z6+)9(4ׄ ׂ,Ȇ~4a- J,_^M=qۼÁ:p?+r7b62UfA%c ǟhw ge'pqkGAY vSJLl}Ǎ[yyw;+u&6]E>}=2ʼnPCHLֺ#ef09ĵCVQl yU~`S=&Jq` &ueڕ$D&qP|>X놇Ljg;ٞC|7na(X-x..؏ėOȔ\8Cs( O9w+e$ڲS:>)QQͿZxbd$mna갦t뺚\$Pp)fZ #PҲ;߶={=_H^92ٗK>ȆcZ.M!?(g9LoÊ#q^-ſɧ}NM:0 `M^,z{$t;`T9)#$Zh ԏe0l7O_ld9 |9v,G"ĵ#]Zt#6lP0(,C*apS/{\wae˹#]'?p gBk}x"4*XUO*& T[?}\w<2x!3LR*Dm N c&R8w3 wm tNBd\!oT-.|Qv"A'Qtz B*JI;,\Ƶzf\OZ RE.u16PFJįl؆&f'Qwq L݂,j(F&>Miј.j;xptĭH2I|_h\ Su*T,L3CMÀ܊DQwE<>ySC !xao[7DW" W*@𣱾u?*0/V{3tmt DPJWœYY*smUu%2އTudB8s69Bܩe$gcncTDTl. 'OK3WZ2钇҄)R-iNDI!i*zf19=e=3]-,%S^}g`302L^jӳ5܄"<0̲FLj,A{c,M9bRSΨEF!ucl8& zƝ.D3 %?_puhDnk3Ɂ6*?=!M`Ǹ 7(1 Eרùx"Mؓ_3V~rm3,iDPtJ/q1R7.F jo!,ӹ k*rlV;-m+jgY J )uRϖȔE w-.Q //HYvQz5JW7I9Xp*b%$]kGыPZpIEsDW O/$|DS>ä01kiK d?L)=l٫ճ_ ī<++-;l{DfLyNPAz !! C/,ҤLiRliW8WlGe%#2O DR%0^\|ퟙ &]{@o_G&qjNM\;^FH+d)G!FHS_nI+]P7_]ekOg&s5ՆΡ̭௴Cڍ]}K-2n\]?NLf43a8Ån%5gnl9UN4c\;=Ň$M{D0ʣ7ㅻC=5>|wZyթԪEVXa?/7SAڀC(^N ˉ* d/,UVf6E }oX;2rT9;YBk^o^ŠOU]+аkl:W3ܯvs[B9 Ym[<_ߞWqETvV&=A乷Nrlw_hG{Knmh~sHv[[Lu2V^wTtɋXB T5S7XPr 9&%jL6sZ o kd0-b/Bb'^WjZ݊>G Щ1wk=c51 leZ4rJrRW# \Ri `b4VY86 HpoUSKZlzH8]jb6*X=Qߴ`PovQze=Bш#:A|4?njdkwq/=lqwQk7Ş91/tF7`%\:3BI糾xV1n5|WlAhk] >p\=?3E8)y'yݏn@6Q}s\4X/cF2fʃ]z(&H`f"I7p-Ca"ym,>⯐r5RU1{] EE xajfl;ԥe{wkk&J nAmeb#1N8fO?}K~ ȳCY%oF*  oh9]nc$+pyA$ g`ES3ʔk̗I8tW$SFxeph_9ʇ71[}*ReHdkvGK2p AJI)@TW1ȎiL%SÑEԠa KugRAEgšgiڹHqW1np5MH$>[ln)AmMm)Jh| K(BNRc3oO<9U{L'koQrUH+ K\d&.$*)#]GHҔLoe+6bN<6\@N)X9;ưzJ(J.n̙3dzO<ė*:ib:APO[/r~Rʯv& ]zpws$4I)+y#x.0q#G`6׺HZܩ1N^pZn[l&Iggz}[23n 8(C68fC#nZp77q‚$`HRZ-"\zNd XϡdB 9Gi8;-5"t Vɗc?i('ߖ[I{$4ޏeklHr]OlTUՆS ;؂~#"0EWb!)wUX2G zR` }14m7[B+v=* f95 KњRHGrlq5T>ѩQW\0U0 J[|[~^M* :sDdRSV,oz 8釯 >b`?iv h+X$  [5kqdWw_pN.'vKECx|NL6\} Pgh#igtxuƨ1mф1'$t0́;Fue!g?b͎(?2N7DI5"XG9rpX%kASJKxەN:(Lh?] *V'ٶe3bY[Jwi-nh 9Vh{ m„vDMnjÓWbR;/vU3f}df{b"ԛ!d%xPN xt9@gT>môה _ YxwmįS?4 u3'&ٌn!-?#G8a*]+&ys39lߒ2r>$|efQcܸ=>ɀcB|B<_ 0LNu $_ j\R+ ,ĺg!ebz%W ۼI1^rGl Tb-Ek*8b`t ` U'czH*m3xngP}7eсI#t .07}9/e(DaTR2A_i2"|iIJboU+q:9Oǟ wn%1+\1Vk &9m3 w'yսW9ΗKuιNMĶN i}&))Nyܾ"J>ѼjR lۤ^r $kRwr_{QLBl*.^*\nvX:K1A/q]1! JIG" @߷M<1 6"թ?|mj^Z{(t%),8=z:I)%o +"{9 ߾C(&N^vhs;ߐzՓ?UyU/PR9N[r=AA^sF%fx1X˃`4gY5 J޾GXB:Z^+x@Rsef*Humgb=@<}sQxکmKBg+]R{ 8=+s.>n6pF 6ݣ=W]]E,> $}wNIV$]M0J`c(I` Vg>6D9+j/̶䱨ѫN&' V=\0C,u1PO DZZWjpc02TRCmY V3<;OAvHT+zr4IX Qdk㷼w3tAh-jyA w-k$b)O[2})P(%]`k@X4Mnlg.}sҰtSս8Vq/'E"9%‡m';4b^m#줃;;x&!6܀@|:eMqs.nhlt^,mo r tR!~C5VAn%[uʯc -8AY 52:E4N1O+G3yO,8[ H k'BxZ߻C\A} ag ,d ՀRk3'7ڊ':Ȥꜳ6M {||9x_}J7DpBM7;R>RNZ 0R`Sg eSY|* XӖOzˬvI9(bׁE _c&w*JQ#*_Ebj63kL>1_+S^(;=UaNxO( 5+EXלFjDZ.窋euM?Ui 8?:[bIiJĴ)k{NKpq(^i|NV@l-3q}-}{.cSdf|:\Hm\j ^#F,Fv9[6$C{'PrRMS N Vޢ$e@np@f-64`us\Db։( ]g"؝u*|k)谙%}=[B@hKlNx$lМ_gќF@ʈWP_B!H-4nཊ|*On;WL!]7~ҳ Icӿ-uŁЃ^N/]Ql/Uh˖.i R >(ȋ|[Xu9S &s|*:D.,Mf9(&X:Kܔx4|7:NV=\7ÊB+Ggp"k㊻k!ޘ}SWAt&t:Ĺ/&8ЇQηFJs2{e;$yŃ6+^y4q~Ma1li۰Bpor zBhYV@X.\ֵJ\i/2衚Ѵ늙XfsQg Y))6uV{p1A}:ķVwe$v` x1..˚ѰVڻg;Na('u`.~sh_Zfqs&1ΪD~TR1 >W:Wsj=ܸa a=`08i4Vr'zIZW9'U k0Z1Z ^q05N V# S*qP+ Q\#F=3[O.AqK }16Zq۹$jvaOd= hFK(8ٖi!ȷSD9 a3*LSWBUM ۦ {Y) [Dr;ٱW!bgg~JJPT7f G s-on`p28K){#3rKB󼹠)Mp"hn)9pLbsW֨S| 9F:cжv -+;t''@R_A[qqA-Ub1ert!K1u 4nyKMM0?U&.PA])™N|9!ݦ> \ό`{`1kNAr$`|ȶ3X?E8yo#8j"fZVoѺ:: IиQmȣ@h+k4.tˁR/&#)TM;1l.rV&"3-~`dM:z(z$JiFۄÆAtRH)3 dWy%5_IwtЌa5n6SIݴ?J˯|sk.Zc f;MQYtUV~Ǘ0_X-&+BhC!yYXpiH$d{|'N_9fQיDٞ᱾"7K(T3f&9v(,_}dTHH ]&ȗJ]N0K e;疺ǔ^`yhS}ЕŖ(ǪNaAp, 9"-+V~G"W`I,y4ťL8'cZ6qs3f|RU_eCA L!;O5aODo| 6`IqNy1i4Πr^>]udث\:VJ,CaGP?gRC`&jf<~d?wy[00v. *q4EC-LxsgXບ85\Fv '൧w9WiO*Dd yÍ3J/YX{*(j|2&=8xfY]؍\Sz܍AӞ`=ev$+6+>&́_.hP 6OQ~NEbbAh7#z.ЋcKZ!in00Mӻ_݆pA8=i!*GP7ԛV@I[ߺZ?nm<S)Xz${O oPm!Hvz!i8~&89lxwbl ʓlka~χV ń|ıQYGJc[e|*|q9I1lbIut(B~m rX"1vFϫuOY*&dP/+Z,z:k>+nV7gfA*<O"i"-`? Rg0qMeE%br"۷Y,s2,VVe*xL#9 EY;2@ C|< R s`K-F1mx _˲4 vxL87E顚 Y(Y v*?ZK8${t `&#u(h(ޛ ԇ5H,d;'4>N KRXőt˵^*_[/ 4咕h>AY`: trq\h}ف'M܍, *XJ70 d^c'I}O T٪0GmԓIu7KqWK~[:?SR ft<):]9dž/yBDOiÉ#C 26+cc7dX,v^?۝NwGPbg`rrBd0XU LB#f}L7*︴RJBp?䲃U;d'xm#ӡlZgpb4O5o!00+A'b8I_s6QqJU[FQ-'/ 4³!d%2Qbuo%A[<_v <ϿgBV2xM%JJWk9kx|3~vil@Uu9\=ø'M1BYC.h @|ĬlYmB+^tKcn [Ut\-/`< kH.ZiC#/6(Kzg&ХQS'cKZp-')s}-hwqn{2PixAmQq[< ;rq+_%pzFC~UQ<,M5]{5{pH^:qcR%f-Il;bC hk1Ru3Z`Qcߑ1rF6![J`M2 4> i;"a ŗC㝋q)598Bw%dH;*}=jt"\d+V]\!oKh.7~vf9qN wqF`n&sa.Dr4?_6Y@O1gQV0p1EgBm-8Ʌ| M# lh`JNk[^B`/i5ǿj`vFLikh;x[;w3w*g% EvbYlmg4fh U]?=/al=."Tɯ+\X*7,k-WCg ?qcetTEgs 'kĎOy)J#@pY`Ġ﷊}ZDKfx]Ds vS!ʖ'9Z@˹4]ܯt&|rK5 Tsln2d4ϾoTЫ"CG^&V_`ErǔD(Xy@x&c5yQ$aA\genOf>osv e B&Og0p"ɌK2ZwIrbً \Ks[|*;}Y -}8]? I5- ƕY0!ɡ! (]O8N` F7+E w,#qa޽]nI?7sKz|C.PHVJk\DAm}?p@GKEaY$fR($3U*:nzBIKWރY,&̉d(fVR 6:FQ]3)*#&KQ}F9h!, Gu֌t96MϷ<#3AܼF!R=t8k= Lx_L;|ہ%_yxꊆoT}6k*{&Zonhq,'+Ka;БOH #xhvKK*T2G I˨R+2Df>T,فD @(xb\vGTdomPډx"]T ȏ y=bW<-},4y! :vs2,2iy|~"&A ^'-Ulc :}Mx qƧ)@Y-:'ֵ&RE1U$osPU `e4E'c+eNn/}b[7[ș.Vtߢ첮hH;iC{0r[kV y:Y[\ٺE@fK@ '۶(LD,FR^Q!)E1ƏK_=֐ g `>)' plO޼qǬP5+ I.I:vI֔poM=X+RB_ 1`>VAiP6 T}K[V[gamhJqd”//ʱ **Z"{1a #,r_x擺l4b9"(d_ `C ow[^!Q1. KV9 9 kAG%XcJF^zg: 1A:?J2!z:?R.r!nD5E('ь(AgǤ pʔ0 m-r^e톋{z[n}=ŕ(R%~0y4r IĮ4*˂ 5LzId)@o+|;C/ۜ8jH9z; d~Pf\ο9û-Ԁb\TrƢڊi FJ8- ݽ &C|{QZn!f5~#;pxHRqS.0;Szo~TLf:q(->I+= *ѯyϕnDe NE~DcgװJ!W{GtT)VTjg2'3c xil)N|x{нs`ʕgM=J%DžkKiQqO`оKĄg:1>e0aZb\,㬗N6R$-Pb}Y=ZBUY[w>g^]6UdOr F,owז(Jrof"4 PY5fԢh73q"VO4PxT8rJ 6^ZG"с37N3?GrcɖP&ɇL7ޮmUN`ΟĎ(7w n Э;5K;g@- 6f,b$*䀄&16ewV, eXZ0YOmm{V[z&-=9T$T'gj\󢛛U&ΥF>"M0W>35as(.5#{ iJ%iE$3h.1{honn{X)z( 6@Aiz%k}Z[rG} ǖL>WP H rz-6-Êo >u7cښ(}>k`v: `q+mKa2@ǕaΊe aO,\϶ﺴ)%'B+Ā5jҿT)F$v(UsF4$7Xw9/< Γ#cpHymۈ.TE&H82kwzHrxgTZp֌ͣnB{14i^cWv4jU$aSez8 ^2mcC]tg-G;ٵy!V>jaYʰ7 T_u@s|PJ{xw$Ew t tI&emp2mlD GQVͬ2/|\(\"p^` :A.ԚV?B?cA> uV>gɡf~=H_sV5~H러ݠ |>C nVǠsm<Ҷ~ `mu9=ew}YڈMrFD)6So9^MOمӭ=U5$tzT߫~$|oʮ<#oʄ-P"鶖܁ a99aPQw.{- |"U)h! 8xm@Ƃ>Oac!̀8'S.DtE5 >}gS/L8Ư5bȍKm`ZP`-l9`TTr WޠWGi;^Ċ$#VѢ!]-i($Y *մ~bΡ V\ɉԄ?YjV~zvPs5BrGҼ. $$.CX %0%>Q~0۴A:أ!ywU_%_ꓡŴvd̚rq[M_e9th~Y6JMO:;n.427xpQ֚.oЋ=+a? !qmKxm ᵜT 3yB@@Q#=Ch̡-@Zş#ɎD5үWu't.$ke'a@n?%RNs;JީکQio R?%'MdD;;>l:P=c4I1"ӽG-X fm㱇pLd " ysaѽ0O>7qz v1C-5XjCuo@d?]أ8AAog̈y :λ@R ]}nx`[8*d LOA!"NqTW"ԓsp; &,pre/)wT,"hJ\XJG;w!yQ#@KQ{\ݬt[N?3!w *@Cӗ̔K>}iɠICnԟ4 D\jӹZ^˕ +|&q )5a*~UCE \q&sg ب1MsC&tP 2F9B[ȃ2NjZ9F@} {ѦaN^tL l-PBԮ}_-$El˰е4ev{-!?=}N~ J-,bJ H~0V..n`H&R-.L?"Ҽ5 W&./c(|^hQzJ? k9$A,&4D [~rB<{쮕q4HWgxwj#BI[$['ބ:toos,c!uda]g'֔,j$uNT,]7f0eBae·ŎHWs"ѰS&%UI;WT4b 6:95EuBuh.yǹ:-+Wz$׆9ЍJyE"cxWt ~T+.'9C)Dmb9q&bEvˬ`q;'wljyHNgg@y &{ ЮŬݮ l% 1)g &WicZ z@n25rxrba}KVrȚҠoi%DuH=/ Ű] mdLȡx9+'9u L:xM5(~<{$p51K qHLe&j6 JQ?.G0Ϛ9,pCJ+< A좻N5fl&8*nƞ> ! 1̭-.0Cl>^^6)IJ4(DT4$]٥Jl$U0o<[pҴׯ6pk݈ D*+`0u 6c…;VQOjjرulx|/[׸ij?}%!3.ʅq^MRgb>AwF"-z/8Zիſ*垐۱'9f#+E/뻰nxs>?l64zo\&FVYJ4h;#MMaK+zߧ[T5k/Гg/5ߝ c4;6Ya± Ǎ`E1ҾQcӍlL@Ɔ$7> /T8˔CƩvn\ +_AaP~\Ю?0rC]MG1Ðu6ɽ|nY*΃M7*|p[ +pG>0[釿ⓑ7T ߥDΉ?juty'qZ)/zЉ2*5r7o|muWKM7#Aa>4R*ݾ`02$C90qP:X:V&#y A~?}lWohY\3H9f> s9^iK7I)@mðUke_ DN)mVJ'yq۱xhsϻ%(\;tȟHBL,2`m-DR^D}ͤ) "kfkM#xO[!ۼtzht#'c./`ya<6Ե ]A>'-MpGSUP6 h[k"];GIT"8VMBk}fF#.(U7|lծGx7*&qQPS|) EСOЛi唕HIUk9#f6lPI jUls({!D +W܋/~ ,s81^ R%Z,\JzAu@\]1<6ޡsDAplYFKϦQʭsrp{W'BI~|338Oj4PmֳʥretXU76jth{*a0OݺPMuA(1 j֔oKp۷_/2M''2Jf| W#ed(>E-* ͬ(@Z]V+Q ´IYu}3lHA2Y@}ŪcQo_Z]G-7$nQH(w}V?Y{Fue͒mDl$:\.#՝[S8g K)$ɪR0PUe`qLvug!pK]3ZXJS6@1 N ކo~^_g5ěvD%T$c!_jY5cz;t徰DyE1gMT]}?b\$&#LQiӽ3OJ^MR_}>QLޝFԙ1jjAV8mZΣsڶk P>'j_e ט/hi_ibn_t *3pGNg]z1YeU{T{Ўæ`w0C$ q%N83+Ehʦ]<:H~i B8QNK4מp!1X*395M/'jN8}^B7P$ٲIc_^d#fU: DwRy`u ΃CC5+_L;%+/:§#f2u{`/ Nv Yo~Oj}mI:>A7Ipa6S뤻"Ac^t'Yk-P/ӝ=;X')G}LV[0Bi~fhkzhsrgW<%OJ|NOK qia !U]Y,! g=~C~߃^)ؾTuh+8?ǽ8#r*. C$qKqd."S@쳖z {R3FჀ[@ARt++AM 1͹ ϰOAI'iշ.~7Z sJ\t< 7rd^ *fuFnI^eXKkK"E[g:R=tu?( E{t́)\0~H'+?Gnh~vֽ7nw;p^(X`׽P.`1՞;*A/+)ںRX2h8ۯ'鏨:3kg)Qy{3nTR7-𞡗n E؇lj~58RCcq5U HC_汑<!80 /ij1Pe֌0r )FJK,'ٽUރ'c@Z__yuAoŰ;E3tU]sI\Sy~ P*bBS#<+Y  6ڀOg:򬄥rEon N!|>}n.*NA7$="$P⳨/M8 T'ÏǷTզNQ= +5[9k$6O=Ns[;qt$vB `s**KG0}P^,|4 gԬwFN>e1ToۿYqw@-! g"8S]C1jHKl|EBZ!  8dC^njj`Cfzrd Vqnkp K]CK฾B"NE{KZO-jW.' $' j!H8(EӁXZ/)z"2/[g\DQ/#õM!DK.B{#gU xJZɕF/p3&!Y|QDՠ>%ĺ"p%+!|dHxOR;*UIgp9ĹĐ57%a"t&f*)Yx3y> }"y2ʭD$C7(BOH[:K=#LR0K$1_~T{_os\-eT@ AA~jjY :$ÐuV)\@HY-*Q_uw}ɌZhod+kզRj뱘A"Ӵ7zVl&H: 8ӘLCM4(Sy!8D65D x)-AJ֣I%x3T#Oїox (վ,SuxP'CT#YDTe JV ^Hj}%c' 0MY DJ 5'V4$AzGZnciV`O}8 qHQEܙ_R3 {-wd7?R-a\1$ۂ͔j|DW"b>A/;׀Szg?kc̗ Y [ <K&A^!pd>(i͡$m}zA6ELCXnmL=ojgK4E'uclD*w& sh\y9g De~:ŗQXxGt Ǣ$ySJJiM6~-*X'w=AmdW$Su_Ⱦds?5cّDw+#j !d•<}"Ö7b = !MW01Z/}TBw!LߖwwP T7k8Cpi91xM ÎW]LݲpAQ ba@7\v JLKtɚșS\u1f%3=sAf;xKC\9{!}KZ)d0cG+qي6T(1L } r4Pn7V̮,7ҐXmad)%+ %2cK?Ҫx;4ƨ5^AWB_HI6zЀቕ`:|kc)c2wa+& o.^QZN牊A2\{FN04(3ue5z|T$|?X9(S>VEѹmz:N9~^6`T58™JgUba92$~ 勷W Ў\*-g~B:9*=U GH5|0H;OYpd,%2fC C^{ vƠ;teYGU{afͺ`T9* φVpLU^ Hd1d#6CSfTƀc2D2IYsX.Q,PM펅Hy,4[Ę.zI}=3~P"[Uh|,&z\D`ƃ@rs6͝]KGI}E۫t)Ves9<1䟆muz& GA{4u+Se;~@W9ȃYV:ޫ 8=5$Q5MLtq_.ɂnƒCAh*6?UE\v2>#Rw| AY̫}(ҪdvϊbL|- (/? g4Opצ0,ӝ *]O8!A4N}UYI”IE;yZ>+jģbk^v6ḷf`4)mv_퍼-a%\PV+0K!CO.;z_o EFsDZ8˚쀒ŕSBkzPv(.Jx%|<馞erILȸdz5GK:Ř=5 5L=a[ec>El("  \I!m: inĩ`%#UBcft5}[6\%jg@Ӕ~d%sfu4+(YF̉\xfw3ə<6P*i8&ÿ,g65x`cJX_ |X#'kcW@<hj!Jg/ٕO]0#0՘sn=V#J ˣ$W#JD38Ր]w-2] ݡrRekCQ=] |gU&T cQJ"uA写ZN /_>ڧamjRSXR)gJ,+ EXq@ *;9 ,hJJ=2rd^f1>)F%{tߠ>či+v޿JrG392O|He#0a]"?뮗s8A} +[&PŐ}@ hG_#ZfJ+FXH\efG+ƅ3!ڝ*' 1~U{ʟ nvB Ъ)ԳrsyժC/=K?yJM=Yw,JxYK.IY.%rF =0%hQc*{t9sµrc9e-goXRJ=w2:sEb ML$+09)ď[Ĕ,4$ Aqdt}G0UQ8^ꯢvzTj|E<ݰi?fgI q+])9}Uû@ߖ< 8ύrEDAE_ ,2AeWѻqf uio@e'j-Y'n2̩a`V,ÂK n%s$G=0R)Ykg(G)7|~R5JwM+2ѧZp ZB/e82i/\''Veɭx>& w&44}Nla\mڐGSJ jr65;)؝}nƍyb-ub_p >_hiosDo*nbQ@avC|AhDfw-:T~p OFA8|Ќt,Zbkf.Qd\N,2uTƭqI/w X"4.)̂`L`'=H]2+Ƃ-W ړOQTS~}R_2[؀*96I#HY^ 2 wt䨯>R /U}pJ'iG%YʔPJBKj0IUu oxزfaQш,L, `GO±S\@m &7#7^DxLEΓ_N|^LxJdx-Ym$5&uм S[a&x?K #,U4`&ԁm1#gwVmHFz tF&_kQ g^QE4IgF22B$ֺ٣("q..=HjSp%$i|q{Dj-ʷ  IUf 2 fR O1~׿gsߗ7WV\L?>k $U1"ma=x؃>iLr zġ2EmNvw B~ᔓz2^LDEQ0Ӽ} 3R u!:ibʕ5@ -9CiC`m05FiTm:|{iMjmzyR5=>lL;{|&DpHӄ\*4 1_3BAҞjAt3-g+Nىdy#3vm1{۷&_ji>o~ՉoGR(4':ivFMap5hR 7|U)5k>Wfu1L َk*AvnOغ@T O ki%jԥYK- ][EM^-wDU?Bm0:$`r=a))`z5Li^T]P"Mc#^ȫyӚ&((f rı%ǍM;M_gmVb{␘酪:9߇I6.DHq[ZpkP{m[‰2)O1 5?<@K"<DLK8]@ű..bj*̴ÔU*[VF%b %hK@/,ȱ:ؖAK?r;3+spKШ Uc}d~{#uzV}'0ןR>͎)Ω4Hu@;l(/Z++vu^>P)ò^0w)S_VtJ>./ Uqwte  j$/φ{FLzLFK]UP1'zw[(xb-/tC D,-vmhsc#>"c72h_ZEr i-߾NVG2`j@5v&| 9u=WۡgG4pGQB-Zڟ= OMg(oK -7Gou*~pt,X;M_6v_yJnn&U IT?̵@H&iboKRj&_57?t ̯ؕOO`:hʭjxe ڠm5=R{&Z&)Ih֪#AQ hh1E~׌IE?'MJEMp,X咬As]~BPy^p5~h ,? T!c,?cUw/I-8yOO{ؔWrYP1c1ݰ[+h4. 7^So1A?Q *" *ӻՂKC~"C stٔ텎De'ko Nd_SKVIe12q=2seNdU/R;xS *66=WfDa ÷R((5cT\|ڃV"+,V/vdi`|B WrMEd1YY@نϕO++۟9SPV3MA6C.z,5ߒiM#!n]q Rh"Sh@ry/GxLY\@ȼ>ed;UR W^bpK l4lvxGHCvV54Z,8ŗsp}˾Hu/ţhIq,5V/Ͱw$%:Z)+8E{YmE&cNGQ TB-Nԃ{Hd`Fh80mް1C HOYLGi/'# U@Җ1ct^Be݌u%ކwOP,VF99$DSJΐVgx1FX{.h/ RWiǧ0Rdd&"(%nS'oQr@Q=?lO0xJK| Mx'hQ ^p9N@dƏxީC$`C. {&!:,55O:BSi[%w.rdEæύH0TG{Ȇ' s)IP'JSR-3FӠU!>YQ͍C }>WIxZWÈu|FRW^&ڈn$P3&7m '<.ڷ˰iIv URϽMo_"Q߄^^D#Xv,%@IhgCuFY[RsC\F9H8 ,)lݬyJak=;ྼ`wWm:6UwXnح |6 ђ_3|x,K=ͷLV#u4_F&IpXo(GB\ǣHEqJǥ(Rͩk;CC73D>%Hb{%, C]ЩniOtR:)h,20;Rgk!6X>Ϩ.-^*Azڊ/o}x!}m@8 !RYC22OTǑk Z6PX -CAxV\1u[2kف:/ǃ<ʚޢgrSJc@t/1~E6p*~͆lf~Z'jV[Qp5XN>E~=_)'ɏP+(Ռ>VD)LqNt۟e<$emp|`D6Ru[9?DM.QD(CjrĝQ~'J~qTQEQDկF2kqf)߶vP~&OG3-3`5].?Rvc)ron*Ml)>żc𘊎'W;}~0a.'H*_a4E*4v*O% `r7晃a'@lPlYq粡ɫ ʨc 灃M Tu*(5$ "s Ҫv\"_Ϥ‘$9 ϡw#M sI=*Կ_QO^nt!#Ne-)25Z>\ PͥB\MD!3*ݻAEH=V.D~A?9@ճ>xԞ A!O,Z#&'?cV'{9xk(RE*pCW7g{`Tk;tOJ"3+jzFfH6wduH)(/~&ߞ0;bLY.7V}*`w` .cV{2DgF͏Mtbd yVY?M_IUqo8{ȭ0`qϣaM(N7kG;v'gD$VuU-w+tYҠ1 u#"8GC$TS4Ҷ<{|1weF~Yp،P-f172^h07Md⠳竮\ԦȠQj|S{h 6gr>'$R C4\-T>\=-dDȯ;Gab"6}{yJ͢Mo e_ةO3QڞGcKtu2XjE>br^:QrSsQ_ p @Z_n 0T;vl웬mq`C f)|dרf@FmLmD9g9'"-ܳv!kz=ڌ`q XMr8X/kXӽs 5;@[EFS/tNļgRBVf79(u |Щu(Ͼc 3(9`FA==X9jefa$ڬd& ẂC(:*-OԀs"x3HUG"EXRT7uh6ÃwE֗3n")j:Y;$tKP)\3( F۹[tbKQ`DG%yZ"ʨWQ\D@-29]%382 j,l6ش-!:46_nc39h3|azŚu}qK؆0UEOa7c] %ӣ}Z i(%JcmQDXn$^bbMl AM/:چL[ +n4P n߅A?>bnK|օphp:b ŧ8Jlb8 +_k*srv޺!Mfyr!KcĆE ǒxO ^tmyD-)'[(Ȅv4a {TS8V/*bY9-$QU^ɲَ1 Oq6[*0u㉏UcdPG8;.0;n:Rij` n?Yk5"J:j&a1Kp)zة $с}3AHiY O,8} DZC5zMVWO{O9"Y.u Fc]oI3#p{LLlZU͗1RUVJhIW$yqzɰss42ܻWpNK;l 5x+ i=N,SϚO1?~ YMCdf7eB_$KP">|a+@ g4\lhmPw Gpsjm+'7(Z Wxپά$wuhjK]i %"X 6䅼WZ.RUM bS!Lն+C,Ǵ{1u#3CXC|+KRGBf. eerMd\r C8h?Or7=k:(ÙxgEH-وG+4{RåL{RޠwA;$W eIX$Q.&QWIl2L;17q,r aO$&j )__S ƈLyşĦ2'ClNkڄjD0&%}&+ܡA:xP r[&]'_ ꎺĖs2 A`–\=8ia/gᲜާ 76iXWɜHK?NDL#$Kj ޮ9?VvEz_J˹ G,WLjۥ0-(,nP-^v2?L8)t#:s'>EW65R rO: ڲ߹y0C?}qJ{c|}m&Ԉ5NVJ[IR[ld86Hϋ{Ivf!?v-FcN=龀f.{'2q<WMeV΁b\6+?>n.]i5m.|FII<d4 + "£+3-G4"0ˈB'iRXіkj/-l|u#kA I^=J"sQc (VҌ bA6ˠQP "ofJlȐƐ1j*.u@-`zSfduGz>HS  DO7WfִnEWлZd UP~Qm淜X&@uABDRqHQGBS7mF&C' P>,ISLCDCtv14Lz̓{Ӄj4`ۧjpO{,KQxs…@:k_ ][wb0%-t*8+$Ifl,z,'5P+^ oxlVWx0}?c[ pd-͉1"ɆcV;s)bL˱!ceE)kQzUw)Q`h󖟰tO1>Yt`ccø 'Q|qk'8I:d-~Ea<3e;Lƙf=u1pRΒX0 ?f&1EW$4!2D-%$4ͰHOPZB7hey+#<xL{{Ut5EF*x/mXۉZ%nTڢO's":boDZV|AѼ- x^PGC#A+b9-I㢒R)"[:.<}Z[cҀez _KKG)YJ~ӵw@;3k[e҂E8 x ZO2,:Y}3_+R>OS((=nAI s){d4˻W ;e$\t1"f7;സ;v21wdUbu~Ў?N /˴~ژly #c ǭyn=C' ?loW20,);L<1|3!<ެ~(X.m⇓հhvޚJ`i3y^iغ`‰ISwfԼ;4@GI~ck,7yscyg m 1©b'vˉSb=$6@VdrNr}>4}RpJW=!8~\\mqX 9g4X1zy-MVZ31$,2cD'r~d,6 JdC``( VO ٶNX? c{~2js`$W#ShpWw|'V n̞ĨqWoD\fج.EbFgc28t6[ƛJ/+PefC уkl幗t7,M];;+;Zu D 򰞑^uQ ڒ52{F8ڻiq:)")T1J҉`Ű=T ^zZWJ ޓtVͅ11FvH{kk4,"5mL/Ga^gB1MWx\ /{PͫMTOGDِ]e: $je cTmIŵbn zCǥ[_ߏ5-G/DuItA||nBcSj:* ڍЎlHN[-?yZКR"/A#EijWjUqϺ#(t@=+J _-(ivEfBȕc)XcБts EfÚLⴿh9EVe(yl&A@7jr{0LPe~ F^XDuc-D],,;ϭ DOg#]E"f74-I 0yOݸ[dEVDxj` ]GdtّV_'B;; ƓeQ0v T(] a u^"YmVrx\^dy Fأb)qW>3@1vQ i51"kmsk.ow4?EJ"$I8uNL\p Pel t]i3 AJ>YEuOMV% ab5h]>ҹM {0νBtN?o6)V2*u3xA'ܑ"k`a*1Dx}e֬n>@BhE nJ8!Rm>I6|c>A Z; ph¦iڞAjq:@˜76tx79 cd Ǎ95mWUu:paהS.w{>'!\uq&X:^8'n÷ȯ+;'!-XA.sށ Y3u}.bu>D%B J Bfչ 'd65gCzG8BX .cN5iԩGLtuD'C*P$& /qY% Htyd.-75]B4'*+:pPlNʫ}w b] YY$^>%]b< aX:/ e/!flH)9 _ԥQ\Y Rh G<9·^_VQ6 ȅIR+˱BJ2*z?l hEF2mtkD2z-9'*M%( ( zW̡^bV%? ?%Rf9ݶMReM=(9TBS a;EDډ~f1mxgVR4Z뉰 嵮gtR@bKhwt. _80#[n sܶfjvմbE{iLEk68oHrHIJ*8\BiW/7_rI.|xc׈P܄+_*joQ* zJ:z:f'"~6-x.}8A~Q@!BԷ*0B@ i]ˊfJ05$cYkbFgh>ƅT RgOj, 'X;n:` 4n+BS6P=!ԅ_: E㿏@o8\:,'LTbOjp6*& P"Cȟ ^[m\^h1f{ &#)4ћjo%~m& ;Cґ7^|}0bY@iv%jP0 u@l5FS") #cLn{tzP3j)FU;5]fWh[4 ;SpI "ۜE.A,'[[-詆i7~{s;E rLĈR|u`9NTrs\? >Yu'煑P#`nKn\AKYa\# @pؠ<!4W+Üu!QL*;*ZI/cz24C+xNZp"pL~ l;KD= =]t .J -fSgn˖>hcH+# }jF6JGk&cI$z\u+9Ce] giE4t q4:$톻=r GQOFN bĒ0(E.]qmeFTfm x<dP}u}mϾ2:m J;`WG<167}!45]S~O"ޫdRL~ҘÆc@Pv9mV5!o +4زp$#mc&7& c8xJτY{UćprB\ǦCF}@.*t[24m#G(ՆMA{#kʰhE>-Ԯ}|ҋ˒C "ɶՓ-% TR}n@EU 7P Ժ$0 20 b$[9E{Nz"ތexoO0{~emUy)(i |M _2߫(ψ!xⅎf8 m,81Rwrs R,sԷPL*judۣDmQWk,8й}P/鈋+LQ{_] Qrk36̚Ɖ},0nBG%J3nKK8]/sdo+g61ń"~QW۰Kۆ03 wFwz@tk9:;0Oapൎ"PzmpJj:@*oqPR:L]zK$fzʱF7k & _mSF y˵O&4VX{B"V̠hTr0H_N &}%N+YF6oϯ`m^9%#Ɲz\m66{K?D3w"4+­s_䋾B k!A hp lZIqwR|qcҸ'NIo4Pp>, ŽQ&{Wr+<ʄH#o 7?oHfF8xUq^ՠ>~};z-{!7NS"8DS-ė1wM '( ?2ȭ7lEɃbP! QJw ?YDY"bɿ$JH^2j4{ėڑBhʠۮ4vM$䶓ܰ[U W~][^U"(uU!6󁛕lem13ÂXLq1o@;ɚ(lGczf,fq霗o,1oN#B?NV8G^E+ v[[mCg\3XVL V`{<"30JhG;ln6j2zO~L_`j ^Y_WV̾ljIh|CrOy-#!E~Ey`b4}MtEjZzɮ_jX(fy3oiv )q;{bewDnjFd6 Yr' H+eC4a  NyrhGcAL԰,&Bpð1^I@U]* : rjڨvc' }:~ a^?oix?ϖrPagH?Qٌߪ.R=cA:L5ڃTE.ncNɊ|!5]޲I+?B(0_B:P<0 Z4jLl)d|34f]_)E%SхXŝ4)NmtRS=6uVQ:Lvd$Mi#x|U3Ba8VV [ILX=ɞWp =I0bIzFUh} YeDTl]`ԑ.HIA`NtMLM0hOXPI}0xW u4}*x)#+;hsP$>SXBT-'/ORZTd]8RLt.p.<Z`y}%f lTi؄$pi-tj =;}[p_q пe(z(&^bztWN}{WK *0/V՝JFjNZgSphV[o=>q4BFYW~Ü3#BcxGoͪwP?=CE9KiԨ] ږ$ UA> V>oٮ\%0枌hgX2gr+8D =Nf3ѥn.6@w_V,>b)l U-›kOՈ"_ K% 2CR\j-r*$:"BTO%cQ?1ɟLg%>Ҩ\:izX=Q^Dt4Ξxۘ?RyTc,J `n^%ETwaOX LKh~3I> xE"CL|T&̅/wLY6T:aX\6/y_Zr 䈻Xja|(Scd cjZ1Q6Lrt(bBǾC!8Pj"<=_"x,4L1 1P-'O[z;xtAT6pl"-eڛ \XObqd@> j4@KQFme_N<VD)-Vʻ}D[:;[]%ţBxdelV?A?C?~ \7GwHcihYp -7o>^ Wu#3?>hqt"%БB޼e`}̀tes 3ᢛ`eZEIvJfց v\uJHDbHW/{m\(È!^tV.§_Ë`ұq*Iw.17yw=e=5疗WH v'/&GߝvJɏ}v36qVhʯ:A}[MoY@<^ȧ8Kvp'T/jŏ+:n%#ܫL=dA4>緲?쎺K>ҙBynB$W {oV2WmazV QC#dRz[#lzi ?bURcnƬ z"y֌!:JҩYƫhDi"T󆓄dP7V;vi)ݩFݥQ !2fXb#~4ZvE8uWʵb%K} lb&_ ?tD]:4{1}wr>E\aH6k_D=a#ʾjBεX\sjl:5Y5D:fBnioؑ h|i͖e>smpdeqeEjFA:Qm7Fe& uvnz`ף]1i|`vı☓^Ot[1':ӅN { IG#0ҷYy Z*cuBm1&z4`%CndLTD wiVR!+@옭s]: u2?UG$6XCRAgх17Tr/SD6RIIz5×EcbR1(T /SǟYQ쑹w)m2`:i|{ r?3iG Re/GC\4c\ ǔe&Ꭺ?G\\]n Wp|pMћGw&[@2ri;. D^j|v[38]8I5 RY*AI*xB mb" }4sl;S :A/_LV25#Z2zS"ո{[+3gFf%w~r-9FVNwط9 rHPH jb*; v-kT.6JJ=teꮸF!>Qf  F+GGP1P$ٙ-.0!ڂKdpRLէc[>zJ|FHx{S&sl_S:WJ57Zh~ZI+&<'Zv=c!;c;סi9d$>6 @|{ݯcnt̎ 3!r ɸfdaղ V>b2۷<͌Y89\.6(ͱ%<$Ab#Mit5 WJLnVjի0~ if,R5%^bxkG8[_1x4i!ǖݸtie>lo66? \HFT#O8OKo*I2nI㴓_X4CUHm~-{^WTDDn8<ԍt ?R /LdYE+Yt$PK <$ ҝz}uKP"iqٯNO"ؤnyU% /Vj]0JYBSb`ɨQ,:zB*C4ۯoy9MJ.ؐ^wyVNk9a#:%熃*C1'M,̓+JtPWj-2msy x!L@ c,IlbA!n'); eKr!--B:{9ؾ.Tlwq!8E -o+uVZJga848/JX0i\ N='YRL١qR{rqB WÙ*BQD=gn~ ȬdMpX}"YNgl "\-PkE QԖdA$ARL"IEOeܶΦ@DWmUVs,#-Ʉ$nvA>V VaP ̾Y~ffq&*J 5#\%^$*{gR|u!{JD 6)~Pq 댇х_KS~c1[Q}aqIɧqiGT] e r5( )QJC9[. ԲLuC{F0~SadvmU7(޳Wb3HKSO0Y)$6Il1(Z֛R|Bib~*UIK:vD+ڌXe˄#\뫱HJPiW:b3FnԧyR^5Hhy@ <O ujtȗ[>YwF;"1S"L" E)қI#*[w]7UH ay.Ώs,\p*K BcSdb1 biL9p8/bݤf#vfҏeIiҀ42r\ԞcPp 웟IxuX+2rrR|bNo;bCx a@3'5bVU3wjKhv1Gy"^4y;.vsQ-xal0Ey OF5aWn BYH\g<^:E1uU>ח+WvjguZ$ntXr9=_Ohċ}UBѦiKW6njڣ !ܛ\aG15*h0o P6!Ucr({zzՁqW2P]ofHÆnU2|TޭbtɈwH!ە锩\aumBxc(pӶ AR#qrK|}}Dr):4QƂb;n&!"$]GIn,5O"mjo3IdwT6¶cԾz܆4&^T*<ȑ3R 3~rIHB?1=M}`k&>(4蜷y ViS01p!(n w)2>#Wqb;E@N"2&Cr@wpoޙoԬL{T l#+OSkI,h;fumOoވRpq N~Xz7G,\g½R y 8wg^3Fr<º9,,  ܌5Uo*U0R /S(y[P^MeGf WX aҷCɜv9bu۸]~,^)`8WZatxDe01׾HL(kDgVq֬tImGQɇrXbL}f+v }')[$$ˀmn o Z$K~ ػ721\bv*<0ݠ'cK0z>Euewoiӿu^'(Rxp"ȃ=򷱨(ʇZK{8*vzP<ئ+H+[CjrN7a -bw/V9?{; 7}P[jK}X BOwӭ{Lq4p(w=gkmcI8%IM8-cs&DA'i ΌPdh$!o$A|9؞F1ʱQOKp}M"&e5!O^3r\`-G>.l38n\S1hgt3NW!έB=鵻vps ]8x*>DAR:Ep'Ϡt,6F_㮥`ZvJ2,FԵjw6"w'MQl  O:6(9ZVel=tDDb+1ߥD'`b].d6ymyl"w\Q`9ljܯ6G 5'Cu08n|iTA|CQvr//&G >FwF, 9O=Ka;ME+02k{9g1>jfIKXBlKP W~nL0pn\S#$=> `26L66B 4H?]2O]91v盇/&aSi%,Jgރ@^%Fם66E#"S1Z2UРfYߜ{Jʖz>~I԰ĭaY}P1foЫOlunnFqʍT `xy{5pQh]4$ƭ-"}k?΂k'5Khٺ-D9vf` _6eۜd_-p}J"F.|"2 3_Ck~W5|$=umö%pvMK @w#0u0'Rf!9/_@qto\Š#kPvȈpR#v R21AfO *gGr-=ʆ ⭤ږ$T&,?ahA,]E=>d/$$I]-=]P=mjX Jg{>2^q.ɝ}f1qj5-㘚byqc/!>s$\Uz{Py>,ԡQ vbYK[M lq3jACiQf4TgV nх=JZZ<=Gj葶94ފH'UpX^U]y 2-Te Md+6YqDC 8LvOٯ(kN.a$,} 96S˞[B""{ H.qdJ /|7@[&_tM<\g'0(\o\6z}ȣ[n(p,$uk hi+xlYf2k8Q|`ZVnڶ$LIz4yIwJ3Y&V@l\jX.ǬPfc$ .߫+03_7NrƭX".5Tu(Nec ( YZ