sssd-ipa-1.14.0-43.el7_3.11$> ` nl{<3y>=?d   ; "@FM    4 { $XLL 3L   ( 89:e=yGyHyIyXyYy\z ]z(^zb{d{e{f{l{t{u|v|0w~tx~y~RCsssd-ipa1.14.043.el7_3.11The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.X~oc1bm.rdu2.centos.org 'zCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKNiA큤AX~oX~oX~oW~X~oX~oX~o4790c7240978db7ebb45b068e719667bc94b918d094d5ee626879a48d3302a0b8282b239202907b347a9a1cc7942ee0a915370f8a25808a40b00dc106fd4dbb28ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903db7ef65c8a57396cc08f8d7b4c82b8de9d7c53397c64cbf120dca001f5198c1cdffdd465621582b79904ea7e77cb96c37396b8d9efff43c35a6cebeab63bce87rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.11.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.113.0.4-14.6.0-14.0-11.14.0-43.el7_3.111.14.0-43.el7_3.111.14.0-43.el7_3.115.2-1sssd1.10.0-8.beta24.11.3XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.111.14.0-43.el7_3.11libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8331f40a84070971d9978cd680a24ba3ac5957aa, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6(]"k%w+p}|,p35muذH^WҀe:>Ў /8߉5U5 DF%aˡq^rΚ3;=?0 d{0>1E[Q'6 h4^JFUÄKWO[% l2NRɊ%^ϻ9 4;g%ݬ\9JEᚒKFJ f{bW9V4vjTvj௺ِɈiUJ%bFxyo' xDPi@0j"b%?! V@mj%rzO28VW^> >܎RF~d!f[Hn7~iQ] 3槮`aG/aY?+ :tŲ!|WzKٞLNk~^N}%Q.nȡwCyB-z-RI `Mx'c晀ǿ"Z7 iK|)flިFڠW6[Ьh4Lab O~oH_⍋ⶥP>I6BK"eYT,ɡ>Hʫu<8vZ9d [R]c2xe=,@N=*NXoK~2lV2O-șF/ɳ_W|$ooc&h{TrVϬKw8y#3أ֭k/??'1fB^X܅v6/< NjLZM1BRF{[AdA$ OAЦb:zycm`G!ygFDQJ`euoRJ?#^\ڄloj"}[1ՅL['XE:때OVgO vaq: ѝXVSe#-KHt\f2!I[sI1nnn|sd2)whO:x8Uw#`%9Ŕ_brN5%?)ZAl34=rkSL u`5)iRNk0eEG%`d_;^Ey 1 D 1U$ID6.M@ߓ7d/మr^e֊ `ORXP) ʐ|J8ul jtbR@-%5s:HJ=Ԉx_Xyx?d[3ZI 諥&.Gn n\<12|yH0:TJt LN7./n{_m KNUU!M 5I"ȦÆ5`=-~n*Dʥ6Q^.DA_CݞH nj:9޿EjPS\R)E!Qi16e _"0몯I6aTq@j#`o86f*C8P@OvN*lh1I^W[A 5Fv ؄\ӊòJ(ua偲v<;8HR_ԏeIrqϜ ԊڃFjaU ~< H[β:VQvpy\Id^1'CZVED`qELBmKN6'. L/x]t Izaq2©aڏX[$pFmhlՇRWB]ϫXyB 評av4a(f~(հ.2 ul&Zsxݧu2*y;Fq'DmnRX jޫ2Lfw!;f2q!! N'H A[hտS$ӿÔM[۾ ?Q1t'=̓wE)s-uUpx&!gi`:1XU!; ¤ y) NLF Rz^iګ!ka&m8vf'!ÐʏZ`{su"U6mnV J\m s|p>0B_,;IX)/ݳ] N :;Z V-dZ"ؚQ>:P1>ƿdl[a t` $wy2>Td6tVl %r}ۇI_q'To$(W٧N) ܆Jr&LT#H=]ZPk]^C[NGjG% rGBSdQqJ$J{%|ch;eSyo KCNwl+SɅrt m!~a=4.#S'toƕ%h¢[ʒnĒY|ecHP}4Zq'f5̟T޴hﯬtE: hY6 ~@lE.aA.ֽ9Cm= So |w GÚ))k?zZ@siu*n8zQEw=d3)AFS{<*pt_S[* ֤K!F퓳_Eb-}Pދ!4g9̱o8#'g}J}IGAٜ]9A4O b z׃zDbi+ (qUwV` ]~% \0^q_M]Qj`NO$@hk7N{?1"@I*6pj+&Ji։eӽ~';8*fEDO\(ܣ"v8OpOk9V9}-Z4xmԓt?a oKU?4YdelkLݡ<48,>fuꨠ}:4CD6vFZFS&b͗w\'zv|jTlq*yr^ MU!}sXt./Zo+;iSX T)_Q .GʞC汄4-v/{ZϷv!θbsXv?%>Nx@1̇z r%v_:=Y=+Rvw #+:PÇ.v#+ R v|B&>6wQB^ߧm"wq+x2mO65+iM K^z0YG2.,ݾs)ӸZ8da( C@rZoH|~ZD rYMn &>If !{M65Lߖb)o{".*6:$Ԓx rnN/АAhV/SΊ2Zl.ѮUUe c6}g =>a )aο ;ձ1N9P0jA)Rfɦyk$?X/HɚKq0"=H[ئ,JdOu<_3ZLȼ+.nD4&|`n;MQ kn$;7rixGս\*.-50,l!+_(),EUTU`pvMA^Yw(5ui3]B4d 122oADz8UYa%5VC}T9-g$x5j!*. @kDߤ%5\ =^?bHc~}>N1Bڢ6%xr;R>K!B] -p 5<adHS;Ϣ~Mk,>6 QG9E".k7z  _K~6,T@rJE'cwd 4J5ՁbduZbVdya_Lex{WAYnЍRZh ژh4CTaSæf15EXI@#Lg$xSs&:zp/),Nd,k0Q$PP):r TexrZ1ueō1esfY (>H.TsBZzx盙tbB_PYAy.6&Vt QOJ(İԯ[{F.2卉P w3J)Ja#8G&cjX} ݻoݗ_N<H,'yӠ&.Č74lhYOQnAG+fZpH'.p');y+&xD [cFd'_tfȦr1\f-BlY>w>-].')iY,7zn{W9cn NoJ<1 僆A*$Bh8)>Hf9<V Vr%y.У+m?8X|!?~2~$ƌ;k sӟ͑GiqܣF9inytZޖ&ZqS{d7m,t;Z %fǭ_R,g&x67.`:q~>&e%:oej׬e94s 횊A|5kou{[0!3fgG<6MfSmlN:pb==A'}ihQ'ɋ  Ίc3e 6{ŷ")PZJF!~qcth-+A7.烎b#Hn^HX__yѨ^KTDA_$jWP!\Tr'궓֥H.>á-"Lal>H"ʼnnĶ*qQ4`uH:MGoT ,mlfR"|c9a ]c_b$ypaA{ 8Pza ՜mN|t{\ 4%Z92dG*]4k)i;6ZDiշ  jx XSsxzyu a}>_0OqB|v{1[[Gm5 BsYU}YA -J؉UYDo+9-/38ON!K*%Kcmy}`to;LeLg.>D !pV<:<9Y` z>!e R؅O]q.%PDz'[TilCp{ej4~K**ee{ ޸=m{Up5:-⇬)&kBKV; 8D;㰴v; 3;iQرvM%@V{\ /^ΛCee)y;L Lfd*aU@wZA~7Wf'C+&9M~Aގ{ujOK40b N~yJ:TXᓲk[Y:Qx3֯% IaB dlA\}Z4s2]/桡 nH{k`sWFa*mEln4\N;BBzoqBlV?%:5sG*9[XrGu/RLuRmza>IVgگK`T~l sb1P'>"l}_T+=)2."uҞߘVEPS/s;=8hbPޡiI&˛BVǦbf>x˜:Ѓ}3hWmAj3":Uq٪b%O'H15<m z$h#%K5lyuu`WE8q,}<:9 d\͵;+F{ R*p B-KjG9ʩmHl? ƎZ1 mn4JZcET-/_&6{2-K67}gT]3K,5vNQ'85%R0)`7b[A6vͱ׆ۼ iuJOiXQ!T* v݀B_t{Gz|a{# k'<2 / AnJ8n!!ֺ4 )lzOqJȽ]v?%C}C/p=rc#pK2h)gE)xDeWlrڽHt%z7SttX,f9-hc|J[b*JrX8];7/%ū" O/!NPfb9ᒨJˍ86a2ro1FrqɊGt3[6FU7+V68hސTyQ`%1)9vB<DxK! lY?A5+Kѳ$ZnyϿ&cϔV+;xrEmcLw "`m99s^Z}r?Q!xU=Y}y&:R'5ڶq~ȑ8Q *!<);F0;C,'ɛkE;6:SU . ^ Έk6>|1nW C3Ѝ*6QqU;ZV2ft(f+w Tjs|d 3~Fגk[GO5 ZtfmlͫQיbl#@yom91JijzS:a(`TH#s~ bUcV]u8J %'@,mƌ J+Ρ"fn,(AAUl! %u- *%s8C2:7hf%aZUD,_v C kGYvX{xD*&ѪF?xe@lX9Y'r&e1T`z5s{$gծt~ϧS2ݳϵ dg1qVKELN؜|nQx1#)zʏ kKrrOj*j~ Orii e5*it2P⁺`77\NԑyjcS(;q7ѨAIj`Z,i2^FJlZd>գvaa\\*U@j!'X킩s[h*N+pP|fNȾY@ev;r0)Ù3%-Y@vlf_>sv&Ic[/?r bs)Wh>:Ws^s !r.w8&Gԇ_Lq^q򽖐! |yR-ʕ'2b<ע0x+QPsQE6qsJZ23ԵUa +Uhy-6whr\(ۙf l󪼫Q;2%S:sv'`9tKToʾĺ,ސ QX [6k8-vIimr\+5!Ԇ8nJ(q/[\[}9g?=Tt8^ZtBq?h,E*Mʺ+}^(W6v|5Hm5^ݨZSsҭtRE \ \9"]wA6sS!,F\i? ; vx`G.b=L'|l[Π,,:Vy_SfST t~N1z' 咉vlSЍ<2^CZ}_~DUVp>߅ȅ*H7­ENOkd_eh ~z*0rQZ;SK77;'k #wi I*HGZɭ74EMZF|YҨc@umJ/<)_/3pC. 4"3<7v4mLȿ70L,Qn#PЍv*Gbic}jA}h0869kzޔF >|&ξ='zqTPLzT iؓA կ|k8D\" 9 Zn6GMPB7T>DkcC#I&J'/#}_Bc-m|m1%-iúޖnAUv?}j, f@f<li\;Xރ5/r6|pHc/gp!U&Gbݢ!b8JlNN*#w?9CË_]Mrs "0qF*GIaDz|K* r(}_z]fz/&E:Cl+boXBG#IR4,`]z[rX0EDw<>lљ6W2 obOhSS;8x1Q%̜x"l{k@?c!oZ,ػaHU}I  _dRmD1ŝgA]rlG2g5?{/j1 6 3IupWq &$d4ؖ({2*!nx&h!-Fbhh??wfy ',']!Abax A[%cSdlIT@O؛9It{}L9áH{8XeOd3:"P{,{!_e~HCqn }#ΓMI #^ ~qtEZxCUY?&7hah{>HAn@hHTw%& J6Lgw"aʋ MRF(!FZZpCq8+ g"o e)JiH'zǭ,ZL|Q^.ۥ>]? "j1΋Qkqph3W7QBXPc⼃[Q;y u\ O$PvHῤmD~&Z>6scg-r[&:KE${nWUehi4%ο$V}xqm6D[':\f% 6aʀtOl?)*ak.s3kam|Sig>thǕN3;%{ePc9GcSoZU9q)~2^瓏uB?:oh@X} aœxGsϨNct?D%-#-C)Vuk"<q3 o(0ZX?t;?îyt0u:dž\Wf[ >y[DOpҹ vP_ί]#G?y=\J cTR@g.8|{T3J>Xl !9+*Ku=Qkb?ybЫ?Yvno*u~1.ðHh[@#ieb+ǫzi*)ptFi&]0Fq+AD"'?h--Enp"k}ƌ7NÌe|%YXU=jwsow6qly5$MƳ( #AUO| }{sØ84#wd%99/bH9җgr rt&r7@ *0aXP9nK,ZNn~;Fzhn9]+;L"\Nj#esl+ߝ“:כNx[yzt4(deZ5'{@&XOlLXo٥k7%LAfP׿6`ʓ<:8Č+BӿgJfmVd?85i%tۿ]{;;훈I]LA~5yxAW\m`2) RrqqQ:9xbuUIr?̀\J-=gStWrp.O@z>7 e_mJ:0kco,v8~rD*쪗Gm6' K6.I81׋骍UrT״h┅gm۫ %s,h%󴆐cIԗJvި0t5R'%2!˓'_Ï] 5QgQDOb )_ ᣦJmd>Ab'͆aDkƒdCSo!}9sFAiM&'Pg70Lur_ RêfeRlyܷbDJXy}[r^Of$}[V /:Pvi.sCBBm?n3=DB\5L87М&ִ?^8WA;#p# E\cEN,b`sP3^7!˰:z#8e,:ǕD*^"{4U7,Rk"1n.0" G{Z,Snxwͣqx$u+/cu. fxrs*y.s:>O._"<<ՄVT;>hzfe:`k(C3Y=fO,x@vʉS%hל')Q,tl{[Y$϶CD-rC7$>B{͌ŐӨێJ-B9>xhM']<:rKWYHJSlc1LKhMr̠4˖+Z}Gi&AQT`׵:9_S>Tk ӧ'ru$] wGC7WM {LK (j [V6-4N~N*%.H zMGDZX]TVB ^) Z$=G^Gon4:%4y%IӇ4Gdp >U퐬\>n E3ON` vg-,8'wX#BvRI + \;pȩM:x^ɟ[$qtAKW5Cϒ0*yWE'+[\TFx 䊓N(Uؐ4pHAcuE٥hFcs6T:los,tWE;X-%o%_G' ho>I p+Tw B[?YXEлY*۩he?S*:&A8jjc~D^f+é+ cboQ 8Op-t^3t1g)^H)^A$~ϟE Ihu(GrdҚSu7j9zy➤?ʾG)t(t` Rym6S2JiZ9ChB#nYwF,K[QteG~%f.|\)cc6 q1ēLъdB^5T-}ctBѣBao"l E2\.M*C(Pnyt$2ȋfՁYd*yDՖfTH^"b4€ \]5B1nHU[wYf00Oc V^NrӁuvɱkFGjX"Z!|с` _]@޶u+o#Oxݒ#6)jI_jWdj0vȏUdsn&!:zeVUG;U[4%Z4K}iCq*;2"q}vxbtjkbYЃDy&*O9AfS)F2g!hn'ZcLE^_ۖQ09̀P~m H绫v|o jl*%8iIвc9V5Ljo14=* x1h@z%EFSt6-`D4$(zfS6 CS|t+Iћ_x_]ϝѮ;}ßNT;H2iJ(L؝tyK.JCг ^=,ry#&ҨOh4T$ "Z@%Qh]J_MV K/=jU`A T/ f0:4ΦROŰD:ۯŠ za4kc1ώ7J+ %sqEy' Q4wT0/WC酅r$p{eҍ(tYB V|'jx_U^B~/#zH>6޼u.ُO&#~E 霕AJ'F{8gl4?ZEnUőYm*"7 (6k3oW{4y3:̪)g(ZAYh%ՀBH83n$I+ꭸ~R|m9loXzنC0vPxAr zE*h 5aϵ'SSr,`7U4¾脪C71<^`0vt㢡"<9~|g#SAَк!HjH$uYb2153)WЩW"{jnG*+ dƑKYC٢uƩkAIgxI9D `",ƳbpդAL8xj y߲hY4؊}TyL=kP6Ym7Yu= 2sKJu{;v:dժH'"_8/eAnc8FgFکS;W!Rǀ&gQ g1<GZ@ݘP!+A2bnՂŮN%,fVȐ8v8:u!܋@;N/wt:[:G7 *麊PMLrf j:om4- <*?~׼W4fX%=%Mlq,cLjS{p~(WM!$0/R╝CIyOj= U4+r$&}r̚}H+0MGKO跏36"j eG41ź)NDb@*]YxGCI:sZ^yKbfQjmmf1رnJ` ,e9Zbr_UoɏpOγD@u|#6fiGYOX5`ėK(/TWH D"ts]#R["4/oY1$Y죟gKBج[bcz!vIY̎Q4" eƑgldUwn}Ɏi%j׭ۇąϠm3߁w(Rnr-EGyg_fT!<^'lF1{IZI/.rTcn/ y3Ljip>H~{ 3 7a|79Wxζ38q+29SX^Ȯ eRcIJch#.%@ywopBejd1ԩXΝx:SVbt.bMBLif&t"Ëjϝזq2b_8xOkpÞ ~p]}#R!L+ ?APplɇb}DSb|M>yL6iEawJ]U~J޲I"/5ѹ} E_D oWx/u(R句tO/^9=/W0D'=nf3F,\k”]N $Ѣ~ aK ‡N7k05̽\WC_z2g'­›ٺC/˖Ey,|ďO)CܩUc W C`QԌnD۸F&/5 u>D\$-V0WT` # SRИY(A!r{uK!"KC+Yϧ3J; ^zv@ c,*+x}zl<,\Cu|@踂-:'tHԼQ]ӂu(#φ Xx@OۂLM%!B;*9,ڲ\[vD+BQ/a zxJ8OGIXAWM# }9^KQ՞iw>ڴ~_B5 Uȏ݂rA[hVQd4k[Lb$իV2́]?vF 1[> ؐ4Cqw;weFGuɞ&)y/hz$_mPޑY Xqbejz3?ۓx9 TpzhFf؁r s"Y6Sj^%Z& r6S9d#ee$ZDR~6$[ayVuNvj~e*$ߐ`4_ǔzdù(p};PW KϭL] %a%+W?3s%[{P˯u!, <7~lh69:8Ut\bGb Q6:HZ@jb#<$h/b (A_qyr78㜅MFw,+G3H3zg7>-rd\ Ga^"I%9CWܔ"Ix@ "U9dq#Ɍb]]Jyz$W&˶P|o~cui~E!W5(TMR.jdl"zs/ZMIMrmR Po8rI#EJ'z. x9)׭5ԝAWaI*Ń{7s]|wiv$8}K< 'p<!HE`%lO =?"u [ ZEf!vHҭ~A+ ]\qcOm,j opڿ[2qvϿOMRp.HFv!+3Pw!B*PqvZ@fԣ ƄRn-֥! v1(pDC7/hԑ"AxwQmx\8D.҈/+R1:<<[ :kXVUnufj>*G W ȋXR4О= %M%[) __k{{^] l4wg]]LK0O7cȅ%#JDqPY}@eG庅º ̍ڳY@v)!9aLlѹ]"]Z4XJ_VJGưN`e%&;a X!)g|9E7W Fdw]S/M5}.K^ﰅsߺ;j:QM6˧W"$wmh܁N&$+aۊta ,(Jr?Q+G-;F]"R˹Kars=lP.|Ҋ g\%&Vce)B$Oq:\lr8ڳK%+.I;bBiad@3}OMtΥ]W&>w66=&w: 6#B5Bk;{ZaS^Jea :FγzzdO̎BGܰ-MGLR"N;i3Q>oҫ/Od /qA&[j%^yΗq2u {`-R>V'm"LLNXbYq=Ȋy]Euq&O!Bl+W Jdú\l'#2#oIpkCcุ9J}+%<D\L:x}'hz!$^z2aqwLp e&j7_+1NBYxKqfI1VH7? cI҄?Xb*OPfxIUO)1ƣ0n#[tRfý`6ϑ5=8Buw8FJ ~ۅ!P&'|}:n˗UNl``Na$m(Z2YśIJ9f V"7/ 6?|(,U`5/|}{E_° %NA}ꙻ<m{AT~ Wͧvx vP(%blY%{WcZDTe1{r>==i$5uU.+ +O%eݯ0|]*Ko8;u Ro{o2>5xce(N797"N-O5ڌ IFp$˒aA('ca+L*k .d(hTQGjܗ4A(4!WlAF?M`mTf9r}gɖVߧ" И!L@`u<7+i0(L]Z?.zfa~Q"hN~FX9ʶ`pPVv5%&`zEF &8*wxꮎjHoE>Df<4$ s{vzv&xil<6Zfӭ5A): 2R){*px@9uyiB_?9.i(9pGX',Z 7jR.w"NzuoW \Z&jNjK2o*5|xUǁHd7e˶zvǺdȾdxD?Ӄy7,a9QL)91zC&KX#u?nh~I ]5Aݨ\Z:5ZQK t3ѓ l?7lssoyvPKeAQhʄZ Or9k}n7^0g;uy~}f?(jo@AdIdb$S_pXHl#ӡ:&\yˎURFo R%Vwc"4qˤDZFC<j+}>3Ыԩqd"A5 g%&yܳ@ ^T 漌$Et@>׺V _ :[pm28})_`}eYUAGv0C1^S:/p(%+4#{X-c:di^ԹȔ87 y.@:+J/ԡ6ʞq$~TÅdгx,n|6' xk1 gPg2uRc/x zl*wK=kϒCKޥN_șEEՌA9ƗĥLb nfx U1VP ?͝.Tr,J^=`_kfW jyI!x3шX;3(̹FbMrRU{h[LX^J:Ǚ<]ggEF3f=֬]#иLii>{K& t6NX:}*7)I`:gZx1b΅Ro ,g$K|__Y]eluWn_46 3b1YwTQ>$Y$ >CIەPϞMp{QKGQi"Abs;X*7–yBF 9HLJcsiz=m wnH? ,9.wΈ++v4tK܇I)ãs?KMs28cm9*OIbew1ȍtH^jbIM{ZcD}X@9Jާp~duGg< @KA{4TP:dnVi%0LZÿaFT_Vŭy#eѐ!$* 4<^7%S& >da`p>\o wX72;7B_Kl56H`5mPѳ ['H߬p }=g{_#镉TK ?GDX+R3H3P52}H%K1]XVYc+ey/=!#&j=j2-}E ٱ))sɩ9Mp?l Y0w4+̫;TNy d A p-g{[T/xem3bkLƓK浻ѿX*,Z0@,Q`Ȍ3aaTu@ 2~p,4 &+Zϔ[~ ECuFc|A`էl4%-ɤDOܿ 1>Α!ZJv 'xUD Uc&XsH]~NU;MJHA`IǽaZ`&A1/rhρ s:q۾sb/[*"b5E5֙]z&r2TmI g0nn t&'>.e$J=gh qpP`)?9z1_7bԈ5Et)z}laeʿdziHGDfL8h?q3hLIVT]':xQ0[-="9@Ub]O[VNQAy.Dӌ1]eS\7~Vy.P%i &6O5_>uMV(@}-"4+ğ@OeEK}渴&x mbz sXQB@" bd:Qn 0r7W:*S'A^>@gp\,yׂ5Yf}ӵ'9桜Tw 2ֈUBYA;8F^ǭR( UI1ݟyV9 WG7[t!'b!wj(P 51RY2Z8/YrԏL)`3R0/Î#.4>m[8>\L9K+D8 N&7Q:Uϖ0zFD3dLC?tSۈp8# -b 'zƊ~&@<-Cׄ3(3%"YQUg_G0 gNUZuԉ&y,<֡RT1qʶzVT?4oJ sdx6Prmaӭɇ7w7 d$^&[ljdSAB1Τfo 'b-\|N6a*H&HfN=b9Lk#Ȇ0\V#jFsA.ԭ<޹Ν7E?O_e\X(E \-} ze &[!=Ė((e'2 g\||W %5L{gnF6׿dFDzkx~L@w.Fay&d*)qDQb]MdDzq.Y3rbrKzIpsvZ"hn z: !,}En\EQDT/GI*d# PXz*@r_~}Hf;W.?Z;AP|6".4d30Os@9Kb+WbYTߠVcxRǗP[!ʘߝ-Vj6A1.JpZ[7&!&O]KNy|0AHN,_TfϙlI2pZBTioGQ 󸷾a"h(<;ߨx)EлOb$W D*o\G³ޑx$|/Dfq߯[Ugq #Gi\ SRfSK& F{6*x@шW7 ;V`pĶɿ8J ~y@? -Ō1 VCf@llO2062f MH@E$[`|+ \w[cPժm=rY{\ROZ,X%- -hayȪ3Tkeq )kyZ`)"F\aekZ!s璴3L/TjɷH@ND=H;ӟ ^d,zpHte/U(0N8A0~_yȽDBb* n<6zzQ>;WXAл 󲘾N=PzØ$U"L/T1 'FQMjz=(f2[|KZEUL=:WѝLg ㅋsrz@3;J/Nו`> 9e̠lz40X¡gc>LG9Z#sG#<[ف@h98C!9+ذ=S IoP"V:,K?7$ 7ل5& # zH ͂0 ^)cZͱLj&x6OA`빌F/+5hv47J], M&2;1poCx39:Rzb>fׁXs\mc$>tXw^W:uyt hI|z\x-0&xӑ+[Ὺl_%(2LN^wKqkؤ$4"8EIIebZ^Jp{Ƥk\`jp#,ZAɿ`WYH)*qlz)#~-G%͆ FJ :rN]H[ S /gC>#oK<誒|V;igi sߟP!<sa6L%oݾAik-n(3V0PM~l9"y;#^q j>޾^\G!ּ[ǐ%@IqHO]7k^Әۑ-Һf'I dN`(p-vqV0aY3Ogb~cc׾xF Q10ϖ$l;0p8eO%xfdWWD^xٴpkgJE3KeD 4O~ Xea`@b^s#+aBLC3ow -ު\fX!jv_ u*4ɅZ]$V)FCXn2hi wMxNTSOZ֭ww{ur3)qBp >RYilUuad Sfx|7if8FpbZDi~"?=k Xɬ vO}z"n]jZE-~ʁ(qlh''# #s7-JbQ[T&,͖6->0$xeOd $@?Y/"vB' 4ܴ(@cc8=%Ȱ  ?[cWQSah@)B;(IKuv06و素U Z?!G#RSBp>6Q΋jA7I{Ƽ?90l T^)E*ꬼT}=;Dƺҷ9VږSgjQOrS똓&'kMAdK3}sXI7zbEPHݾǕb.kv=t<ǷV}&&ePNJ@U(bʃ1Is` -8p`uCz4(ɽG]F#-.mz[P ~Is4&k|Vr%7d&Yw πZ>+?t`6pf=U cSN-IZ%FcX[0g&_„b0AC1)S*t& m{ޛfӆQS)OH=-q)so>@ dt&۸.$  ʄWЉ~?99r+K=:UZ3AqG"f\%h؎uʡ0?o)i$%wEsŹ++ &j95QTtϐ嫱;=si #;$H 1ǥIq$|yzC8q܇'`-]gӋ@szKrT}kand<ƞ9-zE+M9$I\LaRg 4 1#J`kE +/g[`kZr_9ܔyxT}\]JӤ%t;Š+$ٱ0oAeE})D [P4MwLFV5l1 S'9@ai_k;K%fiA1c H si6ʭpI 5lHܯGIphL)~fD y'|:#Dō+ڼ)5E1S)JXsmqDηp&BAUpF'8 vfkYW*wď/\,*"C7^N4ͫȋ-9m\yNO0FJrGqSC| ;].eƗ+EXBCt{dͮôxܓ0LmQHtD  }:m:&B̄iQ%40rמJtoAݡgCҳ}x% PYEob&(TF"aYu ] Akm``_ xYofax+/ԝ3B(!<+uG?UP`p$$B"n@ߺ7.Jl҉1-|J#g=XtpW:+vƤH'H<3+ C,[lǝb'6RZ عh-@=?F!]<w{DyKh1QU Իlx>546_PB>R'ݼqPz{P݆؀뵃_}R%rƝ𫼾dg,wwZ% ܡgg8Dڗ'Y 25Gc[78k䇤n8V Qg Fn FDe_Y:6Qe=Hz_gQ~aO`<;/CDE)yi`+uw~eM9g/=+Բ:].0>0iqzs eǚ_j]8 o;|陃 sAYbT!<>rGLVi/1jR})Ս {*y$_;U- 4o IU@d%6P\Rh$CdH;oֳ5 .oS1-hݛHEϩt@dto$>44 \gi'jpjbıg^}crA2tcq wȍT92i,YRϨlٜ)li$V]- Xr[ Gu]P_h̙i5o.`y OG~X]m(lyޜ0#ޡ&7s˰=uNo^L]:~in%|h-o%FLnqgï=oMG=>^X;eA?݄tDbU p OUQ?+0no/^ƃVf/SҨ4\m2CU:`f_xЊt|G8QRG}j z`lpJ0vq"rCo/SYC?{"$٬d¨Z4}ewF K?}p東e[8Ximr4U柤ٮ+sT?6^-TLr#O X''*`]ZXy.ffT6D6ª] <#'?ZYEےV^srC'D x?1 1A x/{Ds(I!N~y'B(u] yq*xIt*VTZFZ'ºZ˯!v̐ 0ewQ˲:!1Ǽiu<[S vݹnlH摰=4Fry(؊D==P_Jҥȶ%@4}ٕN]-/= ႻWyeG Kaa|C!!b TLm1!NIPqWFqG!vvH${(Zw C;lQ(Z}jYp:nz915J+uzwsc[ ?$a+@n`"ZZUbzzKcSH QT5y\éa X֣q} qwI*!yƍT<8!zwLqIdG̈TvI+l*A?Mڤרuo`*+"أM}XTO-[$F{p$xM1z\o6^i=$ZGY'0Q\3?25po\OKm+>SRSL}3kMJ^o=xߐs*IDz9bu#ѩSC5~{-QvMZ8 @\MV~ D}JE1AmmӨ 1]R*kIw(`JxjW/.um=VS@zBI7*GOD0]idxr] NIͪ'+yE*\Lb1'!<ȿ uPl[h|y掋_r!o<20=deqytre;vKίc@"@9T]xhl: n oN̝?T@U./j1<(c&hЅmlFe&-;>lX3hR0..\0E{ .'}TN?fQvGezjPٻ uf_ N,(w}DgxMT3~bR&s茝gHk`UT߼5X\(x$;o Vd[>P'eQ`g&B3u! xX͵[w ݍUrM, x}SWe*u/QC;ZEvWHNh$*,dzp FB#J(o=fYj1 ;4@:#UURS^)Rf "k 3is@i, R4=Ԧ DV1Џ8 ӧLDNgOkC[Rn &0Bͬ[S))w+go@R_ҽ5'ߪE\>!ཛྷҎ}Ԧvʤd Fk g׉Dv&Xe T:m|-m*ѧ{B&( [rwv%8ޤ"=~)ƤlVM߬[H5vg<2t" )~{\.d`Hآ ~vǒ5ftdq -ó@>$}R>͢bp֒š!B|8j>ܐ9N9E  @sȰeo|?!y:}#xq.V5D+JJ?27R|J2Udod{AMu% fҖN7<GC(4N1-p-Mz&Ùܠ0܋>Oi\MB}T9i~z.ֺIP$a(<ڼdn/T*%hXߴGcJpJ j2؋G2N&bOyԺCs2 8}Dmn6Xq4U-MhMU$ s!]3qޮڵtF"ݚCT,}y /C9VQ^ՃA3XR'^&Crޜֹ'LF^s)5Z0IuE z?}g*X|[>qdNw֗ Ľ Q`mrjBi,v5tX=ah¢#pfxS'%G_ebwu\;]2>ˠsjMC#ݱ(Czjq򝡬lKQS3"QA|ƪTM"L#Y{Q X/ltXjłcK >‹+?nHhtAL&}3OxVBy\%:\yV6 'w[2g?=&ZtpſXpe0>drgzSyWONoa*Wc79L8bt.~RR-G2Onbl*O0vX1x!dŦ ˍ c^>h7~=}zb<:$ ٓ9MtLљ)]2SIe}tNpKL-!>R3ySo)|m4D?oA(ĩ>5^H ξĮ5fjul"\f!=&Ǩ~Ց=cS~;b TuZ1D* ?iv%jM #+,W6E;QlL:qi!;"ZYp[=?C i$o M9{Oyy [c~tfS7Gz:ǹO>HeCg؀􈚜rZZқ{I|Cba?As.ާ:+o:1g9*ӨF?6c=`75U;b{NppQ28cE6jFJUQ>M7~9QM +v")9ob`y)/O &8l^H TSͥc5M'cP:n+?;dz9&z2;UW)6^v3[Lc<cėnIeEo} DV׫ }u6}#ly ~v&eǡy1dbobcզJiXnؠId{=)i\Deam4<<@-(MRsTMמ1{x+(Xxw p 9jtF}i<'&X1`_Rwv5W϶Eә A2t,3 |Ne+JQ?drrUQ8ḮOeq"rL0\/*Vi<\6BwQ"W׏d'kmK0`{kNMTwzsD؎"LlTO3u< 5*SJ6KO1 K]8nïۄXp Ӷ! iJh3IwSfO?"0hqI"k_j n}fW6^`k+ ;jGMt\'.^PlEZGac#=`wN"P&Tmid.cLedbd,=bW$JsA72iA3 TR~aL ֽ|T;lw;  FQs;N/ moTBI,~YZFtCW\RB1y_q-( ~=5w.N%rDhHgS*GWil$M hRPelV7ݸbbHH+|ZK, + Jݨߧom%U?COx!vզy`||BǴ ի 8TZӦܞ [79 5q6 ٠?D}|SW%}vT6!I~[[.2{.*@8w]0g]e.twDC@"h&"rx Fv ιpDUhU|%+!"},tc_32OR~{Lv\ɭQ^ijsRD|\o%B5x,UcMmc&ĥO_.#9ǷbhЎ ģӥ UQv@IGk[!^t%,Ϻ.xog7:p? (֌GBWNvh}t-؟*T}Pa_^xI&zC*܎!l[MVoj/zkxωuR iv[$FВn|D Yv Q䎼}rM# +]E7G0u #'zk% yMaDfEW$Im3 r!4T>=~Po;8ID tMBU,#Z/f զ!!t;WiLUÌo0CuSRtlk0k \mZw|bdD@B?KhWsy0 q=׳L&pJ {0Q`U hcѯE .[)O4fIQp=a{x0ޫp'Þd;42xeuVc;cRGݞGR$KftFtR!M7YHD[Pw*[D)R-7ԭn`e.:>EPI· M_@gZA%Cwa{VXZtd-g@ꍺVU#i,Ycrɬ&eE@ $jd#7~Z] g*OpXyޒ;F߲-J3EqlM" 44zkc-c_1h9`.2f28@M7B u]S1p }#~U `ևҬzW5y_,v(5P=8o>k|;IDq!B*]|NS 4(@'|_Ӂ?jc _)@N<7f%yofuq; 8ݳCJ12ѤFK~Cྦ=]X'V~E}4˵ s1t c~,6- /ii~Y,s@D)7Nh5;wPˊVֈz?9 uJU!1Io-m0$>qv^^a~yXt/GdB U)ZcOO3] /4Pn _ ynZ{H4;$U卵.@ u2d<.9$܄_۾XVߑ\.bY084 upĀs9 mw^ɞtf~lͽsxZ U^'U6J=z?;iIZwkk]{{be$Ft:O 征b;/hhE%$jv'`q{Q]9CNTE759޳< RTK˟ ev;19\c3kOUp'386r+y= ]uP!uam^.11E+)MԶTlGZ{*)Ha;U`^9 e6=hs 6pM)Em18D2Ϥ:=CJ|282'O|9|ܨ7hP]-ѦۜU6B(vqWilq4k.G5!)vӓ֓x)}ѵ3u߭'E.=WPWZO'+8vѡfC-F5MdA`׆X6&Dý\r'F>,%w ጃ4IF\vy6"9YL]u b y\I4T. 'BRXtY3 ?̠h+mxk08|IwAQßAv`:%lp|ú*`h oͱxyEe,&4D Y[eCX ukh791 ^;ƳZe$n)9^Qv?J}ה\_PcDKs!% }j#Ԛ $pfrafp'bҾ"Ny<[kH<{*GmR<40u8_,Bܫ?yī̙/|bOZ j^'81:GljƬt7_nKLϽPL[2X J|LRt/+U^˥ gvюIg|dl2ɻ n&PU;RcQ;@<6C63Y"P pwR[{,½17Ou?ŲsO-U,W6Ku?W"RkXlFH_[\,D%4$_8 R>c엷zt0Pc[^Z073(_j_8LK קPXc&q\FːO^X>ӱ q1C/j() }.̀=wŪ16{)3I ,bZJGն-Z?:ѕ UH,o(_gl˖1'pp"#: )Ӛ<;Pj=D5b!!&9]ς:8 ILsQp t1V0F,u_:~lVj4<ڹ[Tk?,F [܊d Lv)꭫`k\lf=Rԍ d Eǹ$\ VMR~v)1"|PqyV 㟾8#G[_(0}am!+QzXXb lNe{^ A2 u s{RD@jF60P8>tS}c[(g3U*Xd|&I- .K$􆶴pfm#'k~/W@L?\; yϫ%yvX&`LBtp1jJsݽ;v>R8-R9Թ#cc&f-VA/bѽ+eF%OC06?@!`+X8Bec ŕỽ7?Q:uwΊ]0TVC Zie90Wie`dP Sq t\=0fsNO3H`pwh^ABROViI·O9V(GwImk &s885`=DXX1v5r[EΥTN·=>-њ3d@@@<̷MD[u#T(h }yEK]>+Οp9tR? awBFh{E'H=z 6"y6N~6a&Ε2㧄ue˗tӼ}~ڻA>٨b[Tk>{~Q%e/aED+_xbD.oR __F 90F Dt_Z$U?ՁBvXm0Rm=$TeEԈȂhMnȺy9!M B$@%?qg!} @fN^YR3j-QEwif(ZHJ"VG'Aaס%W2fhgH`|XSakf bCiF۟fs%#¼Ơ`&YV;(@H7:ԟjt` SC C3QnϺ<-W3 gA|EccȬ,sta&4B2vO{c-t+Ifˠ1|oV |c(Բ5u=Jn%:b hBfr/M->Vi5t:kΔs=8IKtxd1x,[ ?yh[R^ }JaKTߏ-\)bp&9Mw|mzq]}×QBi[[4eRsVEcSdG]*_:z:;h']z!p{<\zP𖹪5Ju؆C\?,Pvl5Nd"_AvVaG@_'ً>a3({Dѐ;?3YU^G8Ĭ&S۷{~"gK~s`4+dŰA)|uxjӆ1JNa1k)oSȣAda$_$7J˰P\aIcϾBLEk3<,tB9$l#@JD_s/J>'J) j@ϣ(!_^Ο|V0AN׆ )@[|h3ϸ(v&&91-i1u!>]Q&XXy̆s_-6ED?8`Bo.eкPwiճ؋?J DpO*^LwnMk7Y8ͯ}֊$H"cKZ1=zƽ8/!SEgh^Ϭ=#˓/Fi>BG'_A^'Ԫ.i|3\6'I`<$NJ uq@KșHSzBЋd\A{մàYZ {X &Ŭ*׼Q3"ֱ};YV0ʄ]Ng(N5CzVq0q$ClQL"&\US0N /NX~NLA:LүJiepc>i/ւ[̈*=1L|BqM["osorWeT>&v_]lbԚQyhʃa,w΋4ډyľ#8[J{MXK*oN]d ږwu('*Q +ުH豙NO(BT=Lt?zfW[)YZ$ţ> R]J*!=Ɇܓ/?WB *LW kH..=?@k?x@/Gբe6ZP_!dEq#oP%i_iBG/^/N[s "{w-Owس_.TAu|džU]2_`w=TĺPx9ж*5}ך=*ݵXckʿ'y/?b;d Ƨ>Lhy5Ix}2pCH!ݲ H8Sm" ovLT֙ M j5A8,a#ڋH_U2iPҟY5oeaJߜX 2me;c/΅5N ږ| }iCb6F7}O8FCLPe!Wex9ڠ(FtYo™i, ]~!x)0 MbĜ,2o{i /JF,l@#a@t~D̝|PIDa$}G{`Fc_݊Y`$^eei~;圖 8ic2& ZCpP]`%R(z&e:3b S(dblU ·kFv:t,D:E/VnKVh`G 0Pfcҏ Q@`%.0$OYYӴ% K>~|ss9bYWn_SbjE1JQ 762:eh-ʯ;;ifO[mU6usjN w#d*JU°s6PrGr`)TQoWMC*rH p)'ٺ&>*oL2PIyZZyyʋu ]2;IKvO*ԎO<`'4W>8aR#\$y5 5mLҪOU]dr %#JeQ rrjv5o8cb|eO9uB7¼PkF6XW>dl8BxʒzNxsd]T? 'hrVD -axkoƽg~JئI͢oaIcր)+4Zsupd2wG3MM}>|+Qr#2qR)IjX j*bB+:6&gJEp×]?nbC_0jg|ZVtFTz.;8q~C4Mq0!D x0A o+E/yմu qTt6ގ:8/{A9]nhƓU6|@$ :o[Iptud&A i^rDcʱWYHGʋgϷS0JCfIa=EjT%SI7Xd=:FyH-H弰%>|&A𩋝cAnx]LkTnQP>"gv$.AgqY-Uݦh^h먜6cA41l$-i151T h_]QH.}O,$"\,"?ꪉrg6 CUWHB쪃sGKc) |@ǻabp3¤҄L5 .IU>y] rh]xl )(AKtat7[Tu,žgY5~PsPq}v@#ʽK9n2tE(fྥǮpM0>o!lތacO4g튠83q I{"un bl ~) 鉗{E&QbW 6z闋l3S- Ny^ [qDG@*m0*e^ls/8E%nU%rLcBu7&a !lI|:*x+iNJOeE"‰.E[΀ʼnז a@yBjҭxܰ-26P,j0mx6bYctĵ,uʼnJZ+ L҄Zʼnc?S+/N~m(Qښ Y2%B<~qU)ڔ:yy}9B=]Y6_>ܚ/wSR P-^W(B%Z zO2z;LwHJ$'Q?1,gܺ=39m 9 ̹=5˴,~EHdwBo.ej!u$/eVICU ӑG=8 D5zU#f=` paX6*]G(D4i}%|: |Hٷ{Ux#5חrlA˪ckOM3"b9na [%9AzgAAM$N)o2X?@<k?Wtw451?C t,S1}8PId#+v^}Zl~ HÈҮj7$+jZvv"SFx"2bp[o1n/^Y_l&)Q;< ~z}"{g>F]biU7~b/R;Pu{/;? #gd lS`DHnb_m'6G8)UbQB b; iMyinezcЮ9/VN.NWUЏg}D61@-=K LØWq]^SrtU?P4fOX#zObk'pX涔{gNt9-6׻+ܮ+ySy&Ċ5ʣ#+qu` L@9͑mH IIR2oKAiZp&]Q` Hum{4Oxa$I* lF6?RT?p`ĸ(8xƉcD-ϔS2 N'{G^f٢1ӠXڧRlք7x{EƣrTvV},ti>L007c2Fn6TC\$H EN;=-ڷi|QWbŃuX\m-@8 !=0g:_*ۓ~%D }s 6+|ˋNR&(9}<(I8w/esisZƊO!g~!F7 yx^'5\]g9iu2o}C_ yXL}jK\TDj<~n"#2U͠.sC&>/*MiWqSQ'R< 8)dvA023e'U%* CZ7`:DcuZ ҢyQ.rxljCƄz,Ѯ~Ԉ ѓd(Um\qiHU&C?D:s}{a4t{h5o@φf_Ģ4E5f[t Vt$LYwnq~{8y,2.c`H{ܕZwLjv T%Z7o{ 9x)uZTh z=t )2DZ#x5}ݝlCE>o~5Z?aNca{U\ E0dSQ| :8";(8v|%"^x:qCcᠩeABPMb NamOoݺkso=[~sjg,4w-*> dbtF׷X9)fG {I4"Z"L"9[I uve$nS axWFM/ ɜ tlE+S_ac++A_:0d?d929vCӔ ,SZcI1eT@F3Xeq% FPV UνVM!bUܶU>ER⾆+6Kݹn/(C[#SKfIF57~\*$hd$~7{#EeXٷd0[t]%zįi;BP0T!΀'J)-s$,eC!>Ej#hnq\Hg zH\b@F7 Yd\rr-s5jj;m@t5u{Fp9B>6HZ_AOzjh o`ɝjc^fQ"o dִmL-s$f ӎ-,a ݢJK|K8DR}o@1A]뎀HʋHsow{s:i_>/|g VfT=4S Dp-/%X7gsm3<{5n1&T\WӠ& y@omҧ' L;3ܬ-zBZ>I앟og5Z!S&ݴx{|J_,d®i9t=SLF>C#Mۙ A؁hZ-ƫ;Se8QrEHL5X$Yh-Ŝz6N{؇.-@ ܐ`@U l0x!TpnRo'lt{4vb#s~Xᖊ&l4ݲ w{Bڳ+*8gu^zD|79ɅOo>UPL%zמ-plLWO|XVfµ;8EZCWڡ}_$p _5imB#?IF GA(+Zpf}dKێi' ^kK3!ۉMveocK PcU쥺9q$GLD僰cEuސ\g|O#c[n!!r^nz WKJzAgb ]gb Om!e\P?4 yL&ydѢ>0 =(kk SX;K Pʽ;4en5٪BD9iK'䬧j I:XkeK(FWص%WpD !I2YygM)Iòdd|L=yQ_ΚX^NJ̃&^`0| NWmeTcqR+X@٧*)U*+'G+ؽL}d|V D*$>D0<BuRHLsJ[=Xκ8w%}!?DZ>FAߎ*c"*֡@&fVppQJ&È|$Bܟc(cgA9UagBGX8%A?:-\8i}?Ass|2[ r_50NuܕșnvVX/X}d/ܘ @hHQOY(} ]UTLO%(<6)-2(CfS%'e @DsRs 3Lސ~87nDt(h01S:wFOA"qkF < Vl}Rz8~S`2CcԠ~6NO/1 pˈ."(a,$MPgHa?\׿*[>_ D"H #;#P~an*wyҩu<0~Qp;ICh!u,D> W܁ĩU4ePlbqg/f.gcz=xH]f+P&:Ъ·>` rÔUDj~0ACOYބVAs},I _3Ѣr n?X:;ۭΡ}8 U[#mŁʼfe՗+yd<eOAM9MOr8ud.%ء[qٝ64 .M*t3Vd_F$<PP|5RZıd6d$'(*Hk cOX4}WUiF8s zAR XLNAde]?Ҳ I*TSNp7i:Z׊џBF& +l7I&+h{l:,i(/" s:N_I>6t9`A:CC֛h Esr(/-쩳ǔ|=ᯚHK H +4ƐQ)H'awo_|noCکKa1_m>,)D>@ |Q=~]3$`ԋ'tQ5Jަ:^25OeMݝ}vĺXL _Uviʸ~sw*Lg enDh㻕| Fa*T*YcRr]ٓkǓ [yE hWy2m,M^=~j'{ rL;(كz52t=jhzB2O/"9A<)DB]hh)IXBr>Xf7E`s9Prx֜MkT !R#jOhwF˵>:bx%LL<vb~K&uԛ#Ys+4q F4l; $JV 'ZyoFC*qz</IQ׈b΍m$0v.rHUGM޴Ʒ.hqV]̀oo7ZGaIؚK1NV<|ߦ}W؆|/X$l 90"T ^Jcql ?bnL:j5u#HYUaR1S]3Q/z$z0s/C1+sQrym;lYkf -$@!w%V^iy&_:tN*ϤºD ;Ҳ#}u_S h&r`CiYf|Bɝ7qE >57 . o"#]ph:3F^w4KN{Cĉ'ac*i\z$D;][f +J EԂƎ>SŹZ#ii{ZVŊ[$iP%9Ժ7WiRfHP.Qr҃_Uw4`)kO6܅vοoteB%o ܥ8j6P"W/%8%|₷J ' {Ҕi꽡u[h'9Bˬav{Iϛ 6imࠦ2o\O3|v|˚f>JB^[uq ^w?>$^Fmzpoz+BSO!qg?GvIwx6f? ,)vM!-ό14>y)gQ 4ZYL@]_ eǝ EC:6'ʬCyh-S.5A-׉`gyY()0gA+neɤk[wgގc~*&j/|o-0 %NĝUGI }V5! x=䰿B}j)AIZl@;nj~="x:k"NGJ:ع.G5^ՕIb9\|h>>.GʋRB"5DYnR"!Y:єxm^ʆĠ4v/)^pܤY}֑c%5i0QF̶A“6 1VȞdʱ9;pL2]k)PD KgvHT8,=,sfv@T^ 5G9%-SSx@, s{B\4l4}S!Ul˕t{¦Ȇ<tRzKMKIZFQxߴѹR2z,ei,vS6oǚZlF5:0^ VKrR3J_ՠ!/l-dȦI0/ _/IvVZI=pMVz21o;aiJ}|*e4Dj'I=8h A" 盼/*#14[J}CY#APFi4_n`>-Za(.^[U3|k /2!ZCsOVt&WT"-MTAh`(lt)(lf)NGbW @ w+CQȗ#/ /@R}Vwُ.9Z#Af{xww3;UG`E)MvH(zSnm `rGt wIzhM8#(E)9.xiXO&t2䉿8yF9p8@4?ݙfj3pojdݯ_g>!PyQWb T9=JzI]<[dЖ^@IÛ ĂA>g` Oqabl̓:@5NuVRZh+Mff9?J3ڥP=)bjN|,jYL=&HCED !f P$9Xو.!*lT{%$ܗ.򌸀?Bu؊@5 JfLMdx;vo+S7' q0! NG ;!clxRDȼے*&E[j7pީŢl.<v1=#.0.Y*-կ]Z wzkZY ͑3% Rvc2񩕬 rL^n[m䋕rpAw|b-ͥYΡ$]mP +g5YQ E M3W r5'.ӣܑb"Xfp ̆FGWlJi&~SoaR8k/E@ǁʖD J%,P~ … ys@|Dž|(#r.\bulD9Ͼ,c2 ;5.\ "`t]TE&!\9x.hH {N'bW*d)UwйGRO m K_k‰1RSZ#b" rX?3Ndom;SØ6TȅF 2*dMWrA47yMႄZuPGWϚ-2oUNLZʍU.]0wLJ(x#yIuԚi\p U+0/l)7 8 WM:5m@Y{мTAtw%'33O}Z#K~f1Puo'0ĩu󵸕~G ӬmϾݻmC5DhL"V,N̼,Z,t%nyц2 q򌙁f0 ?I#o%0X;҅>\^]r<S QE)KPKi4.OEe؟&ݻw4XB0ϴ]³S SI=Ag*v􏼂n=)xmoBh8bu{XL~eJhr}ﶟwp˃Ab\ɠ@Fd le `t.%6p,j =yo>+YpB2Ie燞IIYhӻ?ʣfQʻxrE~?47*1 @WEg -X"6:0JA#ECSrc[&FOct>9: e2M3Acʽp#GW6d'ztF f ?\Tn1:!#]ppL:Uq}NGɔ(;$$d ن]ڒzRƓ{QLr ި%\q2 }v]ŕWfVH}[0c(I!נMUs}{ 0MIw 4BՑyƊ@N)Ď)'&82XPI774cD;~$$̴˄ jdO#Йg%!ȣW/~A 49).}B)?~ ÄuF-wȰ!XLףtXцWy(9Ka4WmZ{N^YLT|ࣁNE]9 o ׾55Iu~%{||W=4ۏTZ^˜T2eZu^*ʯyˍ%@mt2s##~g>xaeXK)mFω?Ol+Ҹ?xO{0^Qár\AA0㥌僲2r%hQt^`/&ζg䩂R]4!DN{~ )0eH [DN'ʴmݴ3OsC1ꀀ0*q[lo:?MW.qd~`>$uPR\ U "G17Zd'"}8a渮 T6'l~L`EqFt \q5QۡPi4EYLѨٲWc6 4VLdL0=U[ȠͮЈߜ.7?FY ȴ,"Z\)ӛ:]X?M #CcŎ1 qsBd;sQV3aꅂMl쓠ѐMG"l<ç(L5 w)aUXAy=}8hqA/,sZd؂<Ù!}ч7{G͎3s[HώNJ𘡸a&{S] ))PD$$>w% ZSpx <gfnMج:UB3Dʝiɱ'=A#?CFm;ZEC|SN1.}Ob D0}OhH'~MqFtH) hxy +YUM%p+⅋4_kejSZ7!¾Ăm1MbuWә ?/S B]pf4%KxRʬx ScYM{l!Z6kC^GT`N]4=dNV5$Sb!|qRmJ˭95Q0*.(/dj1|wJ{]կ-jbGӄ^V%$2qew I;# \;J S(׌ y*沐~0xuy 7j ÂِHĴ? ҃q Ft5mfEhÀ@&?@*d#X<8.Ϛ Ά}g;đ0ڄЭ"n`pCk;aKDO]{GLf/es%ir4P76TXLJ Ć#̵L7VZK&1l({wZ# M5D֡Vd!F. <#PSYi o绸Y4}/'髁c`riȬkiiߤk%Zsp^>7cdD+n]ُ-=)zi ڗS ,~4C޿%o5P)oO,C=@R4N*cI.!0BmG8"jğ? gߤMߘ"ƻ 9ĩ7{ҵtϨ 5]8AjN>!N¡1lC+vGQRr0,xЊXyp|KGɓ,hhKq(ڦ)*\-2_h8+m}_+&Atr9Kk~=σZj>f٢Bڱz^aj9ˍ LKzb֣;$!+(p 7jxxCqN@7 Cɴ|,Ai㑸<$\;LO-rfO&S&4 {"t-eYH*[y?mj8љW/>0"*%yT )JKi4^Avi"Le'.j=TWz@j){è,ۉHb֡pF߱K)<@-FM"q(t(-'CIuK D#Ko;fqioA71Vz MG.Zic!ɞϨR{\?~omEK/&CzT(0YK=NuVgڡߓ"AG-quj\5R$ȋ UlM$1)hGa[r@J9#}&Y}/8񗛎=dj)EAͤ6+6g89~gX͖OeJC(>Xs[gS`}(g5QXlpȆ)iڕdhٮ4)MyKlXŠ Ȋ:4V헴 ,uhi"־$pxKH)F%e=)R/;Ϩ2n )ZK!dOqse OGB)6 powFC ͭ|fS0}:bN¼:,w@ @QGI㑣\I1ԶEovV)H/:DU84(.W]oϼ}ҷ&- G>peşp Z0);K\ide܃9 TݓTeLKs3'@Js/* |+DV~3k9@uߟ͐{%^3BS=KŘ `(WZ, rBDAm$jАLmF*>UjYN)mLgpٯ3JeKy@dgua03*LT`B(^#^>&Q)vr}҅z>^Mɴ?BPO`Ć1pVOIN`9ߘϮ)߂ Y6>NWJM%E[##r000OSyA8j^(t7sMOC2"mdSiCQwRBWF>- @[(x536n`cdx g%+mBJ0aALɤS?unʹrևXek}}#iX5;mL2& 6^?q+%1Mf|fyɪKe20'xz@4DS HEDhKnD@f4\2G0BL:',H ,8RYu*ƚo @,#+d蔟@ %.@ 5$ދ=O2(!~Ʊ;ran*#6 !Ɨ&Eb2v>$g$ɔ';j_'Sg/ːmͰRaalXei(8>@sC < 43`S긣 .UK͟B Ug%~?C2Ho/|?'&9+Ok *.}g+8b%ŴUzR"W m2~]|PmBKwp(wmOIeDGFІDX0Cm49,`d.6лUc~x"m9?Pc6ےf9/BQ1IOd$+R#d¹}7h0nᶺ+WUoO?Wq A%5G.)fxuoTzݪͲ,΁f\5[d_3/OfC!+IqMǮ@=߄wu#/@&Fd'~op ^D kO&D.'5&$"1&+UGU~`-t,J#&bX>AšO vr.c/6,/:Q>>Khw 铬B:-Ah)`3)OiGI}՝x1vӲ}>iϤ{cDzl/1N%!l?#h# Lra +StWP8E WRj^~*y]ȿ{q}CrrjIݬlTUIǙx:nF1S=clfxTy.5n׽>{kF!;V~$B؆p -"%`y8AVcYRmEg[zph4Wv=9 Z)?U }ut3yl[m΁s=PP|' ո{Ƨ?tyh}Vsg%R:ȥ{M;[X߆>NH[5M*~ 103Chug)}w֑vRLriˎPjbvwZ%0{ӵ|y(Q5[d5I,6tȥKlЯBDX׃)CAc~K kd~.km"qC#tN I RBScoqke25I#~tH4;\L#OnfEY"|p-iׂ;[(BdHƷ>LOɩI0*fO02Ju;@R%-EMZmK U 383ϝv*G]'lF.wlwEvPSY2+d]jsA9TQZX•=AO^ktĆ$Ţ!HhhLMB-4wE-rdi!<,ǮNXs8Nģ膭M"KY/x5/R"zj*f tWYt/`{+,[ PlMm\׭a`76׹I¼][rbGuDo5P4rLHZ\?^Cc/v?39T'oF3f)ab0QՕ)UֈwhnI_Xk_=fOe/\طr?Ҙe4ޤtYi=>W,"lɪ\ưt ^@8i7k@2r|)D"ܭvd.YԾ!͒Pl5D**qo_xs\)YWOMjUy|";,FyWƇg"rEhr<oגZnz:$$6|B".C"P%yҿ4e&)s n36NoVF$s_#֑x ^?,G_1TTP~͞'Vo&uvK}$\+ȓ3mƵW͏@qS%<AKF|(<2 zfn^? Vob}t}_Y~t.N)9"{'#D !lPh*޴"'>,gzb>@dne ib #e _;p0Z`FSO )V5 ?M9My.VliY N|غ&t3b  = D,- L ^)9SI[gg,4ud| OΤtdۨSiNf^xDa~:Tɉ\.- v}!*b(gr48P"ؠgPU=t,@g:=ZaQ_;'4˝9M'@JwhkF+gka;PjCIR1G`ޱ㋂_Y&K s[>0Rm|kw%9ϻ;s/J6`RMז 2 LOlMR\)2`7 '{{^S+Xҹ<ǏdNǣ؋Uz@ ŇrrZ9;7g.Q޾B+\H`iH; WFh`lNҪu`v,@cV Ԧ4r\ʪU:}i'HЧEh VA 9^\cJ'ʯ;yMђB6x5s.iO]:L!J6eKujg%=9^.Ǧ;w 0zkzpy0MfUyv癫W̢[T—y!ˠ}WXͮg}j0]ʗ4G\OPsqr5*5L}N~w.TE`+ (ݲQjBߞ¹ xc"VC "J&i3MʢOa#q,b$V+M0g9TM *pD+y5Q:s,MweOKUxnV,X*_Eg! Ɵ=1j [u>+ Z-fL05 %Oӕ7ؽ!4 xcZinѠٔ)ӫhzw]~,狀r bB̌@GvnU|ƱUҁЧ^2%"*FW;:'V$k#Cs+t@@ IV6- D V ˼GxzwKr0:6Eyw ?%T8>~)̉I}}x䰙Yw\~-{!{Rc{GYtb:D a 3رBcA8n7֞hL@ 1k|?D 1&\x|ieMfjgNq"u tؾyOLI_0Dsz2ZmuEnGBB+Ɇ~mz qǷrz7sSkiC xe_9x(D]٥ex?\o'hey5$-f*rn)xO IԤul򛈑A%Q"rI@1l I~>"w5 `0 ht8b/u68}u.PRft/PlTi0SQq_ LL5wz8=&`kʓhiyZqi3:ޗU[3,P^"ʻ)"ƴk"16Ă cg5#JP1vXӓd^s̓7b"ʷ}Œ _4!WTum qDDt]@3Ecw۱U4kRn\OzI"FL/wO ,E#1Ψw el~4]IK:Y)ƚNX؆Wm`֝񭛭1HN6m2yGdEۉ$ nUh\X[!ՊX1ȽQxVque9"]U2iTH`+oj&qnއO#`BӃqQVƱM&AH HӀŵnX^ E0[S| ~ u zoktذ}:yd2xzI30 \}*~LvsV{}.%B;_(dz >q[qFn,S\p`nsO&aaaV̓WqVQ͌hί=`v8yXz,۫:Wn3pV昂9Us"%Bgz~2D\ٚ]Èvd'g 9/zcG5q8ф)hH^an5+I}%I7g RC\D_m:5d“QZL_U v}l{82)5L*LRr;&nMcr ^o+Ƨ/o/^MI(7mA[A&>1i Pɟ7 gX*&g~%s}yN&%DԛFO$S7Na@-# 5gll:fO Og,=io1雵հc|}@QbYcc!Hٌyp s+R'>d|Ѭ%,X;;($~#\8Xp[P ec'Ȉm$@`3_J< {D:KA{t}ڙz Nq-G _m* \<Xķ{vt=,iL +.QY6>ky=Ekٱo6O@IM^+p=6?Pg)+ǡ٣!82}GB<8B7\(\Yɮ ﴖ "kS#@^ERY%x՗= F錝ׄ{5'dS!Hw2Et6yX|mAq#- M%8x$4YDk|7O{aGLdWlzaqҴ)%x9z-g~19N_uNˁz=sC=td__Z˦Go.'j*gW33op GW ~aBgm$y%VUv)_," ,tRt7S IZN`bi:KCSaҟ$:Fг`y8>zШğE]sVPq2Y͐>Ԧ]1Gfm Q[pyMYﶬte3"Q<(wE$F~҇Op;Ȃ@b@q16+" ߲m,sx'7똪dUɬZoiK.) 8~j.Tq^"h,<2hd T{cm(Jl| ZăXE>{%@BFfj*H^4يR}{Ғ/¢aq =)m`_2<tZo_d Le8P'>Aauތ BRf1Eh]f:/"(vJmqI $kf঻ӯW ܿhSӛ0`ʠ %vNMq5U (GcW$SHoֻE(YW_Q>H8_C_셨srJu9 193;X3{6_|ܔ^x YCC=g Ǣ*D"ϴ ʧǨ""*KvAcT*oiŞsӢudi= ㉘b2/;VF{:RE2TLҮSL*1+ͬ(2<;:-uo6aQ4|`?CՃ4R{j,GBj,'t1K Ts 嗄 ڻ=mT̓Ε}89(0/nUR\rYgcr:# u?cn&) wѦUE\>94AԔ!; zm `l#} B  )*I77$wiulcvPO&&jfSAYjVTr2 82mE1G,_F4"C1!,*-Q:렷І6_PV+-(@SE{֢P`Tp=|)N"yt¼8A{X\QTl]gOP`ΠIR+0 8(|ȈmbGsCe)_>;vņ֩ߙ\*RŬ氢Q& #\t;rn^\)rɆ/hvEe5}BAϘ&KڟLێR3[SV.,WB:-¿mkK#kػ?ͩ7̐&~Z$1ABsw ]NJu<~ESqr5n¼G%ŵI|TG o^窿*Z/wj0[k>ɊX Tlˀ;lw,>PL{^d:͈i!WP8gīe,|.mu QW](9%D bA_;!Xv]Ϩy' iת^pyQ k"a^$h ?ަWaSsrg Ni~L]vk~5#O` [Z@a`)cl CE=xkk},vEiH>|,U <±&+Q zA6kaQC}Lvj/& Xt[NeKbłF0r[/8a_Pȱ/ #(}MPmLOS3eyd bIsHS}ylfپxɉIUxtv+cʓbGهEae_רDU.HWfIV˽_Lsʿ)eb-9 YRѯ1/ ٴ-^\[Z*5mjnBme~5tŬP|0&!n-)Behf~$DiŽ(v>$^==E[8YAL N1U`Jg?G>} a ~`'z;)E.w6Fy2) ezia TbXjc(u {Rve.+{Q/3вbVdvy }q%FmqgmX"E wJ=@0fS_քhYЌ e$dH"0؉ 34ecR$Q_LuOj%nsT@Pf^fg+-cor0?Á2W#r $|fGMl{?҉c#QHe *Iș.a.~[UYfCQaͣO`1z2cA6R7od7Ժ6N4-sj:^gq/񎠺^oA oF @EN,ѽDg~#-(5~xru:SpQ//R1ˍ?(jƯQO%jBqv}'y%`EW~C'\EpP`,,*׉i q6 ;ZmL:| ,$"W$ iَ^D>\ђ.6e P8p ~̉;݌>_5^l1ȭLHrP%=<.JwЧg+ۡJ$=qY9 VC 500[ 2-q8w-A1*Ɂlnq >$,T#Uq5CbX#O^N:"q؜%xG>wyN$cp݉Rs@> jءԺ)q4^\r9吳V≝M r%$/^'qq,[=iӺڇ}Дtkgεccc೛ЎJ:d ԗZHls 6{wpQ˻SyzDH:mXGF MdMްwO̢9 TwOڢE㯡O(4̘֍\N0_)b;Io'5LNLR7*2!6) 6CVAF|YDޟ`(V0Yi2bH!ƅu@ٜ+N]oNn,e562z0YBO!#dR⥐ ߫I6>@)pqQ8 "qgM.n6R;>ҩi58]Tjx4m`\Ej>@IdGpC(턔$z{[#gisߘ,K_o|apwInj{G<6i9$5/Yu^e=kw%T4, 88 y(^))˵΅QW4/u&&{?e5DVe^x97ϑJ|C[3{%G4xC%F=F;*-#dUh\,t_2zQR z@vnt3o%: =J0f[u/"CB^'䦶Vy o?|*_4YlXG8ёKk &e[f`-\R0>gB7smW)hgD3x Ӯ簢}AJʭ+t4A"*Ǯ(>;vKOJEi.D[so0P5&1_E-,χ 贗5nI<_;/-Q[aaPgYEZ72(!@+ކX+FkSZFNiTAuc;Ba=qL=*#Q%(o啐!%ߑ\m~arqjL}JDwPoto.ֶj9{Ttʡx)!I_$l5RQyը1PԺDrֆ_Ҕt-ktjc]94~mrXv >cGr>}SYMkM1{1)U`_ͣJ*k'txW*6o5+\w7Vљ3kܛJ~1CkBWQ/;H?Wo#yf|E\1XU%yHq !DϓJInn[p6ޛ6ac${Ѿqy|A|rG"nR%T'l֨)?JFC8LBc⚫ߥ55V P~!Lnw3Id:K<>#/xמ Oy=M(+Q1Kmbى:YOr .E@8;+=,`D/s T\8tn(K{xPXU`Ka&<;/iwNo?t80Y{QОcSӨqN3_J(cu\}N9 ?M=BξMۮOLf>ėn YMkC"m;"d6?}Ӊ._f/|}@?ֽY)txv$`CGKYAbBT_eha>|ĩ1[A+*L^)Ժ?1qT =jo65jǸP,po} #"bo ;B qAAnce2(=˭W%|$fFf`&ʜ8#X\\DcxoCDsJ3\#D4ZUvy!j9:%}1clӑ.4V_^kW V4HR])>|Yba!86Lߏ҈[}p#fĚRA L7i,#5I|0}ҷ }Wv%DڒԤUѯ7v 4WW=u܀f(εX6:BrdϠs6geD֩Kəc?r_M1@#q.Dv)1;D FmlMMS5IdoFVDQ/pI>pM;ӭL zZv7ryJg2tU#3=QV!>3L|nnݩU7zd8:H&M!`D]0c/Q23wjxlaB g3bTԪr2"f\@{E`3(&x␽8;$>$#zNR΢fDp/9/&r!3dz ႖^&t'l}Ff,G}z;V+lh. Ѣ3iMi;A6knE =;ckRVv _\yX8'dFHDC@`A"k OZ~{-th_b]CMYa8֙ϖ e|}*%a)CPY*!DeB *N{xSy*m nYoYCTIacMҍ^ >[D?N$Kgtiy`no(Q[]w-vOdDbj V34; z\r5c|=C)7g ygOBR=ꠎhJ DO<°.hR87mJ4!ժ"\"# ,=gF(u) -Y`/) t)UYW/ɿL\kT/@ͅB9RET T18A",BY9,"i5\ɝ< =ZA71ʝaK8"EV[QI{B:3"a>7JxJ>Df5QQ 7W@=Yoy`Mթ.6K4|*HoV!rCͬ9C~}9!U56b}9lKm#7D 'z]KWs{^(*ЋtMGJGX6{D$-H]Xq ' R=]bf`[cf n@OT3tf}SSd< 4\$9)Dr EY:]Ŭ9vnB54Wsxs 7ʤ(!oeFnwP"oP#yyív(B@qvpR& 4X|JDq!mOAe.`Q ВLe@g0)TnS럟.[Z[z_WȄB#1[0C$EFJMN}b/9x=hFկ]$Rwz<3WL;\_[BɿMEg3_ޛsqQhZiX؈HZ-گ?(2@3䃪U`+p1lM7MߜCvY.%7E[9y pMUnI$K꠿jXrT[:7LPdI~{dZpi}-P[[@. XD ;c<5FjK3LdۡY8lvZ*T-r9b~:4޲}񻔲0 _>K >=y7 J|!6|w*uP zg)SyR PfmlVR᲼[7z^qw jx]5Y Yle)9嚍!"/#7YjVgZ~"y`WB|CdS5iAA,/f~ 2uk/CPa-ӻ$! =J}mg.j o-<~!U; ^^.kLK|!B4NJW{R! e=*A[nF3?Dmb4s?^ka ga#BA>+aQ^Zp.K9҅-ޮIG%XMyt Tx4{΋S(7Q@~ϊ1gWj+yѬ] zb50(@'qRΧ2QI h8) j7"tlgep7ؕzx=F͝HVٜ1աQ~!ԊJST_ ;&4b7<}Ax'Đ|b;i[W+ I@Gȫdb֍nv[ 2IFffG/7Qv+5@ooſHuv98׿Ju =vqZYval<69y͌79o{ pKK~ohz̀|G!+^HbU&=1Q%<]+Ϟ=gaǃp%lb5+!᎐p7{zMH2Cwᨽ*uJ-vؖJG+W{Gsm?7LF]\W*ի:#^bz{0A 24?c0<~p4QgdEQi&lF(qlʔpˍBϋ|eZN,sviqS)g@-'GBz}x_'VxQ?dCmlRݓﲀ$A6KI&N ۽4}yÙlNif%cزNIqʖu7F\qۃt N*iϯKT<`8OЛӨ"/[#_ f?Ap&"1^g㄂4 |u7b*ҧm;",CET 8B8m*mB1kn0ׂt-~_D(&Ű|17=dal ,ѡ5e7N+F%{P-9V$dc8?o⣎/4dmH#2Yxb4|'aA]A*43`*ǣ{H$4wF *w{W:W(F8#mB„q\>jVus}-3TC6(Œ.OeDhܣ|7,3U$:\1b&THspPۼ`}\_WyVJ}DUTOuСJtt|O8۟d 67jjC;hNtT)w4wdZ0OSW*>sC*︁BX)%*9/ыu.NMBeHZj )xط\]j~mB*P*[ZM3:&#* c(Gde.:(W021i:G1S?2 [ H;U{f~e$}*ۧ_wP[G< 9%|$.THHL|ynޭvn V=cM~4\# oT|}c R_hOPwK$mG@?AnI#KNUUel'æPY:dAU[2( $O 2qJ(2{D,zybkZ=#41 {9cy3V=z Nс@{N aL%$Y%4W{bnA?r_PqUR@? نy4ʃVS'UՌ'MgBL(~@kXVmpf(7`9?i+ WxŤb +vlֈ(k?=1]yjLmޱ r:sߧr`j]J.D)"L'4'rƅRhK PޒV!<Mwt.ܯrɊXMY&oBNk;dSn#1ČH]Xm4ƺ''eCH,a}KF ԙ) #C' p4oLI4U7,k zyjd$Hn+{)H۫_PaH3@ͽa Oh@" ]ջj9uJJ3^c2tIôd%oQ% (wf.Q4f4JvՌ<`lӕZτu2/b - ׹U m|.eTy_Uw3G$>% 2ƍ6t88lW։z$XB1uy QP$t4AaNvC9S],?YgzE,"i ]OEOcl ,V'Q>*I}| r6$eY!n̺`D ٜ!V;\5?Mgu#UQV?nF?JlP9{ #ZK!9IŨ}E6VӴUѧ֘l[79՚.TǞ&4V$nwe؞Sޯ~8;B\vBDjbBo>n+W~b.wqEg?C>Fγ _G^VOą{DT1xet|տ%Z;ҡ+lU{斫˙>_w|{!NO_4"lؓ.G<{ H:$5˷(0yFCiX Ud:ަ,=dfwMY1c:W^ᩬed8c!j/)5|{"_<%" Q'U^7jox7¹7T>;V9C4OZ=gFD:Kbkt2@'YskaaSVj`&(Sx*m 磿Y3h4 Ucu>]pŁaGN*_ Rlْ~$.F>NԙLiI0AW|nJ:T!pz*+x8[ϐnPF]/N_1X:i{>يv@;(H0L؊T`@F"x4M1q)ՓȊxĖCX`4-S^FV z3˔!LX Md,UQڶ e[Sؘ6,|"njڷ;@ρ(euU&*;}ei)u `fc=wy/ )AJ=+|yQmnom!=8oY,@cQm7Q-54=] A\C51͚2LO(YG8>/ξ`kF_#!wީ&(bزEZ]{Mexpl`n d[2!4$40:՘SӷH{y}J Ws`Gflf7xO ;KyMV %*%[zfI(+MjA˘/¸K9IP #`PuipZfLd1  -Y,GWQ%Bb:2Ek{…&(]O;xr%KN'9== JybOX00 =@][@s70e=4G}g[mnnannSxO $IS#eKwV^>mK齕G=<eOz;MM6Q/=oMaStˢf)7@cX Hgi Q1ϪB ޤtUS*NOPhYc5rιs2oUNDS H$yU6M՜[ }3Ųyl7Ac^,R2R5\ֺvKҰ~*aBi9]\PQZ:/aKO1׵0(o5ɊO2 ͧeHܑ|v`-&B (S'GD[oG6EZ1QPG-|UQPq:܌_آHo<h,n7!=sު~_ˤN\NyN.P#R ׿>$+\vZ'GlO$`\>FӮo<!}>u8ѝt @OVK6<cAMY).mmQKZYx}Us|hy83z_/%>%L|ІE.ODBh"׭!MA`]aV.Ӣe"Ќ!.Z蓵'B̃d0b|TeSqNojy- uhr[ě؃tQrfna~F2 ,}# HF!aOuAR~wn,sve݀N/Dbewuir4%aC$]ˬWkh0R\6PMLToZpi墂 w5/y 2=W[jeuD-56hE-H}M j+QG8' QDdTG=(fYК%`HPb%a{wyfa gE ǚ!_+Q8-TU cAK'>&_ΒdH" AlN:b$ŶkG(49v8s.-YmscԚG#![uRxDll$1rfp32u- p8]P6*&G.[VYvL_F 5g8 ÍjcU-tT>؀2>!qEehS%g/ SB/=*Qq++!>|Y $҃'Մ.'wQ<3uQ`%@ *alA ŞL-_~hcYBSaܦDC|[8v2>n~Om *+.Du_j1CL/K[?lrT W /pl.ٲ MQvņjI:<8+amj!`znjvhe8࢜|2}h>))!E)߬ n)9/0 Be7E`caδ3H#2tRQBJP dڵ߉08)"ŹjWEȤ?;/ͣtvY&V ~<z7[LzC7'߅,Di|@5c<'S"i \3fM`Z\@|&s-]4*8eK&sE8Bru {ipx*("W-Gٸpp鍑BL#P|?jèEDʼnK;\3y'H Wy@p%Mcq8˝<')0;pVcbX7ϏϒX'PK}I y5,L'5?. ǒxݨ[K/"\t *{o|1Ce߷8,Y9RhZ;xF'gVT,=])xS!}: DzԜ$RiXcр[T~; %UPiǃ9WTF_-i %%vc!mξؒhỢhs{8ZjB:_cVye,2p踘( b/]pd;vڊs3X& d,-n06~|+'׌Wey|:S~y׭$wf[EXnf Ҭ˹Sʟ B*zw4|5 nIaFuD4zS`ZGR`_!'lĺ5^ nҀ2Б3ч-vP9n|l;rTٚZg%8%hy;|[0=tDɒx2J)@ %\qKQ*s6Q?-$/u ؾٸd*$ t=+=k/s`)7rz@@R ĵUog+ `"=J_ Mwd`2@؁}=d/kT4-GK08r3`k WK<HDQdQqv6BW+J}VmfeǼױ|bI~^1סuԜ 34jH%e"m #^vBu$0jx @ ]"Q'yd2;ԔZ?dR V{r|9VrḳN<>%H躃3LdraLahu z3T1;S9LjX RC0PΛG>Ajzm[^F#LXV`jan4Uqp;l4=NtgyS%7q9%;J1AYp_gGK_ۺj˕_h?Е:m ݝ.5],[IUO}-;-,ki;XDOrU 18򿤔oyjkK.#|W#tADI1t:q56R\2F[sYs,T{>-Kk[5 \b4f{o3udƼeDA{TkٖO%޺ˎ&6U{~)pUc9X "!4#E6H4P}1R )59(گYW~mr[~+1qt+(L R |IJ2[ Tٲ%.H 1q\JA1X禩rLJ#{b~9Q]&k|c6d*쓰zo$d%t-WX@U=!SĔdVcqcѩt4 6ߺ>9֊oSvZ|źB*-ZT 54Gv~yq9y7]vagt6/~M }PeOra>oKCwF{/vBU,(|"8#Q` J٤Wwn|֠%cC:?"ւf@/5=g=a@*&*|CᾷíݔVkogC#%#m3i@,Gtr[C3f O]ΑmnI!\k*= !]On'>3K Yq[Ɲ=}b(&9=:!dUP;\7նfrud7S3>s[*❩oUVLUS xbxMv1 tdc?®STF*gS\!'=ˆεiEuw#w.,Ѿ93Z/O`,M'J1n~^JUJ]Z3!oK:Gb4TF^IuY͝¶\! l0G({Troa&T#MqN{P^+AXPG=oS?yہ02u{;Ʊ~7nۚ.g&XEߌK\ G[9`/D]'az;H(fBNU"N!GmѽFvAt-e]%%n0J/ )\z:TV: |:}Gїe]P2M\@q,X<cs۾7>p`ӷ.L+VBrO| P?jC(2~Δ∡*=F5UW_(1dL>ne+G+o(B-MRPY~ΐ.Աo%:bئj :L\? C`ZPD\$.Sg1yHu^Qqݛr\LH ڥ^5߫8&U h-yOl(ʃ E nA%6v![5&&$E.=Iyl`>2ct~DtO4&p3Rg|:V0 XatNbki$N1H3%fO/EbX$0wc ;rm5f{Ԉ4;J4@n_誡3W$ =ea+;Qj7RV$.Y/s]дhş01Lӣm_9 V)(r;/)xG`@2]46ؘ6e! ! {E^S+^,ȗw! 9 tR#o8(`N;xHNwDhE 1XMJh9dT}X'6~042M]gTlBo6r: Hep.Fdqp\7bj#҃!VkTk/u 0.m:24 kmգ<}p2b@?/82a([[TQ#ڄ,)rى`\QmAE %BK xB>ʄ ָK Y1:cAŴ Z$(z8={mEuS/A+(enQ> ۜi[_˿1—}s?U*O:RnF8?=qRSfw!SK5%ݽCj鿐Fx$2$i17M}AݾͫcGc3` u@|n,52X"u:>MMk:bw(E+&5)7uŽj ',؈ҍ^ǟt^I/Y n} uD;km:]k^B'ߟ5F [o]@Ie!/?i)Xj5Q\a;ya dDZ4Reֺ7i7\V1Dm>RlH~p dYb_tRq-Q{ubD3駈f-܉Rӫ2OH5rm?r'[ؽ/ Q/v(߄ ZX߁Si } =Ĺ]xw.d2#152ʴ .2}Lǔ̵0<Ɇ. %u=~j𑺧ch,'~r8#Kqk}ƴ0 U˜Dsb) }ȹr'YJNw|qKZJ'n_?W~- ;9c\#Ҧ.Y}9Z},BzXĔP4PusʵlG>ycpg>S?6F6ly=$Цy&gh<2ࡾP!<<*R?&2gBvӷ=1B (SW#7y@!%9VuW]25qE&%/oL苍U?7]E*rWHeV&5,Nو*儅"k!=' \sٳ}@Z1Qݲ쁂JV^D8*>|o}pU悥!ԅd_{ 6Mz0Km@)Eqwø?>, JC،pߵɱ@m}$OϩՄ~TJ҇4sRz`k9 C:c.V((DRzm¬>'l;y4O?,'CcI8~T[V#dJ (n&L9QJIBdP{{Bz\2)g{qAܧ"*Mݝ06 Ӎ|1!LTe+mT@)Y'(sEcXv!Ȳs^クVb5 lQN EKAꦘB$VnMkM݀IQ[/4t2w@1$_ŤGOfx54b`K]hIf s vŠ=D^aE(ƶԣeNE.fqaa[B 0w `ФP [t]) #&&;lyn'~[[>0/D]XN:2f'(BDB؛Ǵ"O,P`a=V(^T햟-P<4/Ikld6$yӕTXWhX-eϛm :^G.:I{eBl#E9)`_mujx:3mOڇy)f_#/q #]Qr9O!t#ݗҾt|#vp|SjF#G Bx_Fd[❫\6Ef@1( :|ZR)Pbi +iJ_EzvgM ET ڨbğ-3Jl.9ETA1 厌}[vRi0#Q$3/N1F̫𱨪p=1H(!- ?LR3qjaF(:VE>KGͬY׿o뚧t4YO_j4K2Gg:Sɒ,{-pGV e)=ΐ.}&L)GmjJTH0*SMKԆy1`ڀt+;6H<"M<F/sL6 wK ˔J.wՙU\>8i-%R4z -C45*Csy+wJB 2xKkRmb@6j:N9}9Bjh2q3Ez4go13εm]QKdL)EC&":D8\ 7汬:9BTL1<ƣtYB=sK[ΗΠV rF.CQa//'!I "G!ݸ&emwީ! !ШX@  U /9Lܯ޽TEz~A7 /-z#$|)L}]b7* +r] of&T`j[~ ̴ב ?ZsNZB :1P:7+ Y"o{(ѽ|7>)o(7.G-E'(ҽ<.AfB@hlg Ȩ sk!rMH:1#2po;Uf]oгG5[m\K>&(-&]EJs̓5b7VYNl7퀽3ͪ՚^d8޷˦D5̺>O"2N vW4GOu~OYE{r~Cw]In`äH0|>m,۽!*z,'a (cK_@-619!D˳w)"0s53 F&P%]IGaYov\yfN) RP Y{斬pj?XS;Ǥ.FZ%rxyeרnM9i $"/eʔ+`mnqc\5JR8˦(Q2?1}܉ψ3s//NǠ:y+mڅ6fpN8EEP=&ʀ;!V^}d K,̑AUNV $N[acҏؘ62)=8WX1M0>S}-s% d9U mY-UFcDn_?X(31;S{uN/ܤES";3CnRd͍@s$ȈH$J i*%[iDe-^ckFe7k- wCՁMg >SM1ٞd|_]UP4w2I75 >Ix٨,Ϙd : t9vAg%_?BCZ b|=oc}~j2'IqOD|]?lVJONfZa2 b6DR@sMvۮĦ!,DP. 2੒ &C),,sk^ǭF$0-;/^n=%5cwiMElGdKXNJ 1^ʎ~54 /GgDYQJc?x SQ*Z?"Q3]rk +ԈYy`X+gϚv?ӫ :caSE 0kJ Tlm ͎&tGofpIpDMbТ廘,L}aZ#Ë827M|rLւM on5:}1nqa0RASEDMP7$^0ZIR.o DžvJ ushxO%O,lQf/!YPlXJ0o'!ɱ}vCwI*? CQ&$!EY 忨ƞt8{xQ%`sB5YM Zj,?=&rI6 FM7cXlS(RFo[|%P kb3Rn,٠3U^+-la\)T{]5gуXEr\7TˆWD~r5:,$o1Rx'<4Ƶ h]16Baֳh\s.zBa[g5 d$NǑt7GDn3a(qf.r|âdWlVjp!8` *Sv;wJ)bMc( w~an 9x3Z-tt ?3n %`}բ9vBXށȵz_dW >\>Zo#xF3$y2t-ԃ3 ;q y=aE_1[L?R5O:j]j>W2פUSMg5/S:^4]~[wVdQ-ӽ)mɇ//̕WUo,0 !n#? u pwgJz@Ii]~hea| 6m7XI4z@O.3:s=|?%ެ~k]7{y8m)("Z/lj{C8KwFr::aF( A}S _z\D>YT3 Wa= +0ܶ+8V]IyC'f?* 1՚k'Z)J}N7tn<B<'p!n]"RWZX3<8RV$XԒ ~М(՟6$w4P&U@r^c1QЯ 㹥aG|ٺsctɋ%bijn}hfB4|&Fkk1H0#93["}8WaݦoSI'-[\o52ɵ< gL=W\5_Ň8a1p *iud[bL9_3J x8SsKt8\Hn p9Rq߉Q=y8RR]"V7(\jژ_Ĵ QO0 ?WTbּ%{@3/rjsv䅞 :|=10X;R+"-⫆\EMjk-C WZs>ͤP[tJ(xWC//ѧ,:p*AGZ}r&2t Mg j6U+%o=qo'MvŶX lZLp'K R?y凡-mՊ : M.cF#s|~en,@$bjM+Kco͚ a OsyP`SsWQޏ ̶h$cS`N*[!A%Evfh7Z[zi7O A vhZ~s)ڜ69"OM@Y%}@TpmEBZ3x}I&>ғ3˻t\ʬ徒z(ǁf%ӊ14='4QwW6qq\譵^"lW:޷KztWLxͫ]<tQa%x5#*%?s3*vO|)!f0VI/'ƈXwU- ֽb/i859HRwXnVنzP`[.Ѯφɼ܊PJm 9~ eL[̊ݶպZ%piaOQ_ax$Ъ >>1GQ&`IeRYDxkmGxb|kR]zw hƮp gcs`npQ +܁`IMO$xJR=}as>%NQ. 90hm.Į0NArHhfO _H`%݂|M 0v=4D/6pSh4^:_A';Ge Mds3_do5Oz )؂ir- %|w$-Y1;GaT0#f O gkm%T!drÙk:v>b Я/5NGjPrC(B>TU4ksEH?P 4ժ@՗s/LXMU.S yb#ؿzT+c֔=8xW M4둱B : ϠCH?Sw'3V)#嚆̳ϋ+2QHϚ'P/$ۆ}>l80y3iD kqzPg#M$!ըj* ~ ut-CUMZR]_X{w>[ `/ZvWC mIi2 4907 |ܽI^~ 7H]B? ˛ =3 5a"d'? R^6P@ nWIrӒK|iGӇFG*WGJPIǏf")tE*'gF䋁ͽĆep$H ;^n8R‹u埊+Xrݰ(\NS@*"1DZ jAwmi*iH K(»^הUUZ U@;@:nhwsuiv@O4 ^Co\ոP),%LYb&`qމs\b&?7nRugIп"$J#xK%s޶'lXl@+z36 \|%Z0$s~&77KR8!ޜES92u::?#4r(EȘ-F,PI^Zy4~AڹtXmu]ZX%xC^Z6dL I,9 U TxyYS#*IdK2Ҝ'#H{&Bu FW2xV fiߨN.ҷudopƔھ.â,bq 9# %#sƛhX6U`å0f#XQ; G8]fl ~vdf&5-(+Ie8-#9G*j=pR@5&SPYu |-]1q  0bpGUNCn»8;؛#C:}r瘊-*fg۫i,;ig tNV[.:5?b\+jyZ!?CجRa}{\K=$䞇V `ƽM0%AɃhX!XbLĽj'-:͌ M7GkVom%bG(,t*h:.y8:Eۆ:1&2R/0 v ĺKAҲC'2? T$RoN(BpQ Ί[' |_A\&P?kjN,0dM9b$.ffNR/1y;qLۓMidt9c#_7;Im0f5=zS m4@OV=@!{}U_1xz-%-էHz KJg=/WUym1@1V*g5&\úaSZ/zK ̐ޣM^ oBS7eRn0Oؤf!J(` ަ~f _IJ22a5E;w17&֋DKZ.nsUjlCĐR}ocY;\ TY8c!Fݼ[rOb>M2ôiMzN Fa$q46~k,Byx= pvWSU`TzQp5!gR >)*\U7_Oar780ů'Dj4>7q/y8{)StbdV1}kg/ujj&a/8}PDan\j ^/^ݯrv][ i@$ (T긜/G LNrda Zϗw&,I-z6sbʰ`FiךζU$ĺH"CO UI1{eUgS_eYE-R1>'t#S?@qcF\8);vEE֖vGv) ͯIz}nN3[c4D_fakC/4%x>w|M0*@$‰u15 # {a&lalfvT溺e0BI#ڝ=+.5G)mJ)e/$R뉣fBbVGcD?ioPH>:u5Q5 -pԪ>sn }Y sˢgf,Ǧy)C_:R >B)@|7u3R Kw٥#\\ijc_~&hux2quA*[՝Z4X k]0rG< ƚ '9[ܳdX]〪ZIV UR,Jwkd ^ߊF8 d3P.61,3Dzx+}ذt-|ᡙnCGv- %?uˆw5]ţ_ ,ޡ4zs鴰F@+'NvDqzjzMwFmͽPDH{AnVi;酀ej:*@'"$0K4 ɰum0lKXuM, u>E"+ =qNyÎA u _?%с HnUcۄnPHق}1"5X A.%4rӽƅyW&q 1F [byö(u*uΚn )B_$:| bFC~۳RYJ&%W ~.{F|r,gT_u\H'| "j4)eIQsM.pVVsrf8Qyŵ* 0z,{L3@N;][XnH@ͳ2H3~T5 ~XViIa x %2JJ}i:2{bZճv?ia;cfvBYs;?FuBI0F̗*|SIQ `޿2|B`_PO FrOȖ#C*ٲ(),fðʟP8[`CuI˵YJ)!BqnO"E2Y7N 8w݊-t0 kK`%w;aܮ{ATݺ:48t]R}DB$=0<"e }xjC(gܝcn28}qi_W`>$uS]r8EL`:Q&у6mшj7Ǧ3|I]-2b_~ono.YRW,渃l>"L1"k =""&q4jR{.±(w'tʂyu"8 ,ޠ4t@YEo߇s,}6" J0>kvmBR,~A&V o`@|$x5zeFv%) wI  hƝ+YxXM7a6CJd#NQJ bVgyo.!t=sr!pj3H!'oklX?`EaD,Ӯ?6&*ہRӻ gSh>yR1XEؓr4 #Zr‘pSD7<Ń#$iTZI3l HC"| t^mJN˴h*:*vSzAwoe#o}9s"ՋzPH7hۇ6%(9!B? uM_z[BZ](丳"9uf}M"tM  2Ε)p\g'LŁ jn.J㍞r"!~PWI?wE/ZmVȬږ5=g}}ؙ* \A\bW˒an/\,(s(76y}i0i&j]|Dtߐ%ց8@]ߜ۸x>ة[.[Z c{'W8'4 01ʬ23E!颂 ?"woؒ~dyAK# jӚ}l.Ir2 H/Xd^Doυu!{EݡpӋ>>)5 ĔfAPg׀!,1k çٝ<4 tJ}> kRh W';z"weuAO3D\8m5P @kXXHXrJ,G;`93yT9t닍fa/X!0%%L}ǑQ(5 G[ksn3f! m|EatzT7?$-P9d82IjbFmnOw d T윉T,ey9IƉseu[y %QТӚ _]6G}ߦw6yRZ$A>#FuO䌅.>#PEY-a}ކ]"ZN;MYܻRiLxȫC4~AcR_4_@}e"["ޮAeY̰TS*U ւL(nYDT2u*k9BWJ-g@sP$jzcA9>[oG +b۞fhxMltİsť~w]b_f3q=`ƯvSY4QO]~T)mf)jN%" 9tjn4Z!TiQ߷WN&%9{T\w|-=C7<uřnr-t`aGsK|rТl&KRjqx1X?[=dFR!u͔Q.L[+ʼ!oTRC0sCI ;Ll&}-sRMYą7n< Z<@'–ŠQOzXZ7\ O7/Êa= 9x CS aB,}Y3 .o۳9:h]@=dL,ϮEXd=9R|JZ9u:j<7rpȿ={:(,*GC)ߛ HC'Iu4xpt`og9<&)SH,˷_mܐZԻ}](DфxlhXnqR(K-?!Xg]9ƕdsޛƇ^^颞ӱ2iaYV$-T!%}} Lcv "a+:+d#Q\ђ%q ̀aC&Df6mŠASmzuy)j9<ؤJ78ڤϲj!+4:RbӧF}&cV2iHEF^IGob}-?v'rۄަ*6+WK=le1=:3ti7z7(+=xI cfEi>L笏+ /]ٙe S 5F+KVa\ 2A{[>OHW_69\ɗbn[3*.v1/ tfi=aGq,<)I ?m$P+*rHKG(B'.-RP:-sh I8NG7|J R6s#H/L{5>a\}~"9 yvx:fy@0Z;S=T+X>lnG) 5np&2Tm}t)rWGΉN8P2v) či1/p=ByC˵'%>nut@=R fpRS (hȤE紀̧9ʓ>\[%b=)6 j.Q|<~vA mqI,{QG1ɮbu,RÕY9dֆB?TSx]W}Y l6&T LSrf]|Py, Z' |A!:sm 6aU#nTn[-cDk5ҧM@MLeULQhKǫۅ\r*t_[S_@:^i@.J^vE)Y{ECa5q7T}97kJc]Rԙ "4pN֌k4육}dd̩CL8`Kձ6‚lŤ/Ϝ`亓3«*ҽnyd§QM.Te oJyKWŧ:&zRTF [jN47}> #^ҷjCUH#׷kJiAxWOwV``>\SκJ;4~R \@%~6 `cMqT*rzrmV?r8{!_*׏eo>3 wnQ>BNAł-S}|t[ra#tV~;-f3nF_y އl-%Vm>@^P#`sZNˎ7"/1 E@/mp0g'}^^>a!!e_LYi%~kj~r B-1MpQtÀ<`'%o0Q}ButLCq~( HEm1 rOvkNfWHJl*`&o)tf0}+$9\J@: Z "V"K 9^ zO>o]NsK00J kcNSw<d qJ3a-&jjە\" NWY4aȳz\)2:Ⱦ+#~B.,@f~A^Ә/!' 0wnߚ?Ve;0k Q^ҽTֱLOI j*+%33Cbyb{vh9*vx?7|>[Q Vǫ`Ӵ\C<&XlB/]ITogVDSURS5 AUKY̼mMZ,FiZ RI U6] Gˣ D{m]"!UjX†B ~!3e(;~E߯-:EJ/ TJ/g-$9gvdZ) -T>ujfTP~"R.W( XBSL`zٟDk%_jݲ`nh]SZDNRmg W3J4Law*V6m /Sȓ u{|#v,Kd(XhR2i,Hm#1$*[g)OrKZw/UNnW׼rZ /?GFx6Y$8/GND%}})$6t$kwɏƶ1̂"n! 0Vb5 G ftB[GW(\i2 qr͝ 2U)6ݠ*,  ?&nϥ TXkDg6ڢ'̜&c7POc‰kve.U(2쩈'Ck Ox .u'%~96˒t"7A'WUr~*sVS ]U2uZ2W-pJj)F-i!8KHx.C%džw?ׇSz}#`OxomVjbޝs*5ȋ2мVת|S RJNh"uONHO\Ôj}O}dWM$>RgoVՐ54ݑsKB:0oѴqxvė@jNu4&P@.g*A}I z5kTl(4v|=pt5ūMk]]\>÷w/!ć(꤇^luA;a< (_MS TX!=Eܑ+hFY@{חIR;x%/OŏM]z=TWxc 1 K'wb=?ИŒC-e^%bydeBn5p?|A~új|khq4.rq$/ʱll%ng7v:&s=s2T )PC,:r@.L)貈9fv`<#c|A@;92 [[kn0 zRe HlAw,gXmu|0K/M 77k"#lQ*ycm&0<^(6 gk9ܑV>򪅂XMHFO Sc&McE"VXԢerdjs\Y Q_})-uRo?pBMd󏳵Tk*ut/ OI `w6=1C!(A1tۘt̗XYҀ\3`:rRs=$mcN)\FlɉWGNcNQPe78]Ix,K>F?RbBØLL̵d pOӕޮ<& 44oWNjl|Ѻas*,[vx\luc:'3k6Da%9&7,"&HWV$V1pAۚWvڡZNǰ﷐hiH!f eOoJ6EtUCW鷘`3:nSBY,oY\dxl7`+xzrD˗YyAc^6Ć'Lk7awxr5/%&[ Æ7DC%^VG/jSxˆ,sCQv=jt^N6j4 6,?.јɥli@?v@1)¢QjJ[?} ag{h Z's]lVY)ԐoilhLhscN0xQpP$3O_0PANVC;Ȗ`!j*BǰztgR%zWM)l˱;snOd{7ra]C%O C*~\ AM5UWw8IepԊAͺ uqD.GaF__df,OC ,FLТOϗĦQW)VI<(ގ3z?$S:\UJl;` \atqIępRKeoRYt1>VÙ44ZөSc=a }yw ̍,8)mmjfv%ϐU2|3#Kʙ [40ծ!}Ǵū`M6mx(NF -wS3>KAOR!R_rD1 0)TH۶Jq}v,/|%5^^Ad|+T)T1gN3\!A1k~b`6SHt\{N%(%HTswP4/F,6ASbpʃ&uψȡ{{3qe%5 h|㲽Py< d-+ʁrN gyRl9/{˥(xX5+aVҕ_t++\Τ~Lm-*ηhuI*kU|:L</eTàӇxyu9xAcs?TԂ:ȫ uy 4_ }kB?iqyQ3eO:tU@*(u @6Uk=!@IWq#цvdS WwH,!=n:2r~V;WSCK-}3@lx~ F\ ;bu1(uA*#ĥYq֠$ŌZe  Cߠ:CPX0 *\LS_lߒuV}xK& ˲*a)*sI}oxGG(?˨Ma ӑٹI ;H搙rfS<5۪ U*q2L*]yx=LQ噋S#\YxВQՉcՉ*\`-Zzk~o$x3){PM [";9`ш(҆X~̹Yj6gB\ O?aTHMZC\5hȞ.€U)g2d I+VOV浙0a{Op陞a*ir3޷{`|^a8gg.DDg7620G_.̪cM0V[ 1 h7x4Zf- }zit[ ISgnfq=窷! `sBG:*0%:*iNt5j Ch*Hyq8FDݸ,^3esUqY1 h7ҟ$`ײ!C6Z}ȯlƟe[B&(?/=C0cnJGr>Y'2"HMӠ1ytvdz>8c>qޒp z iIqRFog^cӹP!{o.{68!ffTuG`juNYCžDgLDܬ CQW @"]{q:و 1{  8_G  CO?c|*u?`gL<]uv"k`ᵍwjh%q׶R ֪j-FM?ĖD1 O-EAZƒ+5#PBkC,͞VQ<*D΃XW?U4aQhXDtn/euK_ރB[3blD OS,,Oh"PS:ӼϮ5uz0>Rhv<&C;?)kꈊMлFшo !.G>0Vn]!`sX4;^/[3@>CQӏ_9^^" X,-?>}$/Ρ[j.LTϽ iXEDyAIW"y3'طM(²xiխEDI4-~㏒kRZcádq0Re_C dRSFj({;Y0.I΋ :ʉ0X!" ҂ޤZy m,3+1?+ȧZ%.. }Պ 2zWZX20tm_ngVoN ^N; 5@H|F+V Ę]b6ez cP;4^^Kwjʉ9[ ?_:Q<6̒}mfvB)3b [}ՏAdeԤE24h,Wj3bt3"ʆɺoc*('vӦ1mp0. }P0萜,# }]qd?+(_P8 z_F%r(ˬ ~mLL Z(GĒO8WtT(AD'ORRgdA<b ҁbʧ 2l{{8rYFÛ1r.6xSc40rC MarX霵[Q,V /i8,x{F߉LE )|gsȻѲu9p<nŎ~t$J+ !?Ə;cO>ۀw1f6Iz74w]Am \pg ϋl d #9{)X w% R '(.B|#VwYD3D!B.ޟMO_?Y?,{ڸUd~]ì.~SU`+. [_tab?C*Mpk"UGP ZjS\pn do>04u}c 2\W>#ʱ>X07C )`o{`x$.&#+pw S0bbMq:Gs mtgkWzP5kNnMr>h}Sh=S(v ]jhՇ/A{<TzxNؒUQڶ:l9_|?]*2^ O@^#Y>!3N7${ ,;f$XEdV̥N: U0/*Y✨pWt0%^h!t&>/##`eKDm?p1i=2tR^Ѧ/ {1BA+'12Ìw :7Db@ƅlF"*wiS7 `Z%Ih9 G|7Q!bn;@MZcGZ'jV=(Iq:NHVQ (pFй $͞+T>i٫{D+\nd.nM?-d Vr#znʔ;-L&`CiZ#ر")C{Oqf_Th^҉%`sc8!$59:+՜blj ],v!. HYrйL*-yV6% 7bG"|swQfg;XXaq>ĮgDڙ7x}2%.X%/Z&7)/ Qun{t($h[jʩTSIk6aIo3}. 7`$쩥YxR@=>ɘ;7|]=!|嵰(їPKQZ>Xg5qkzJiq9I W!Q^"3&-usIbO C7G=n:y.|ffgCtWv19 t m6Ĉ~Zw** UMoSg5{~a Z0YQ ݬlu Gae71Ys$^聛&U`a90WUB[ IQ>oi|!9%wbu[B޳\St@ǝ@ܩw eɦ`lW-:!fF1K7Gy%^qmAz:ΗLw*|NmIw[8}٢ܯU\oWM`lLmƨI9ULNFV=E OYC:]g5T~{5處\09Nڵ49[ l59_˱Say 漊b5)^'}]*9Xzf>PN6#d41w1_v~Hʶ G4:U>Y4")R c9&S![(HxXK̥:SË詮ȼD7k!K}aK6XBϥRyഭgQA/h5(M+I>!:649f/ f̉"efYV2Ȉh{l1,*$i[Ld\޲oԄʝ8Ql۹"cuħ;|+Ռ aP]T{S@H'SU{EF%Y}@fUb" O!IG⣁XRHxU覵.ZA/kl$ޣ&` knΈ ^5U_xb dƥϜ֛NnvMo\k r%Jnƃ@4F.tR`aچ#u1ED2J^ NhCNG{A"%ɱaޘ"s}2"m! [ZgfaTj(V)Mщm^BJBVI 5 }IhcVQZ2ź3cwQZ4p{$MZf$?¶m?R){t\/?l5"Y㙚s swC""5]/eo ӄNldh@Yut$[- LH;Cߍ]$K #L^sFAv}"ra|Do_G͹T܊q7HT敊Hќ&8 @uQq_f'nC{U'a$" [8{j)R!^TIH$yT`HJWyJ"TBx,e /`Wʛ56gW+J^u -c뽯Z ֢6J(=jq -d< ļ 0r-3V(+'`Zvy9h *hwBY `cůxe\ݱ6dap.Hd;'.O0}dy ~GU쀼9ri uJꆺ fpܿ#-Ѻ)bIN]9F9dx9-?ˤڰX|݁rG >kFާ]qR%J4 VHSvu4y|Ǡㇶa*Y=Z"j)SS|L ;9ܑcptފFA#E~6IyBC#IŠݕ}nZ<.`Lt=tݦI:N%Dȸeg},[6˜˼nDFru7NE:Is!4uGƎ= S!Pn䓽3KIA(YN.JRSFқH"q`Ut(mno`2 fܒ=/-cq?PyQ2Bwϛ"1?H6kQD"Ֆ z$5Ąf"850hE3'w|y(Iv95jYQZa\VRjy-߰J|V~pYqUݣLnLyUV~D/2AQjr0VԷ,Q~bì- wLU(h>`*"u̎$GU >[t( j 1Ws hT߅&'K-i F@R6<':,̵:glFV qeD_$Ipƪugy^Śi8@΃":tQ*tR]so[ G/Z`ay4RĿ$;>2>B!mQ Ƞ%jI8^r޵N18ݱeM]噄p ' C{Vn!+u9 yŸy7(_fS|Iϩ6V;QCzAvJg*JyXh#G9o&̘ߠz5}h!UY`FDHB)<ܣ|2.( &gA(.a]0'3|NNЩKk>IMØ+ vŌEHH;}LmcJn+ѣ]Lyz,nx2*o.eaE9XPUx9ܴŻ68ܑЀfIR F4/[$x)f| P4!iT@.nz sbW.X3\gSێ xR&%bun^u!NNV'ЊrL~V`^#<8ZoSpL}ǐ'|dj'Be#Hj~H;؀z"!]-ԭ,ߥ⪿3.;,9GiJYR/8t^ zH]9@#TeA]".OŮ!X6Vk)o4g{$_^B kzr!wTe_hz"(TJt}iϼ'>iAiM>6U0ӈ]z5"u2kiT;e*q@sx&L+rUñaUMY#%VU`}G呧OE\Өo4b 6AbFdAY!, hm}Q _L/Bp)<޶ Jr~jxM= 1Zg^~eiSfL^%S!t8a^(Tu P1iiI$(l!3L.M}IK Pt{l"4D}X0Ȥs؋Wȇ53lW*z;Ps8.ĔeQRJ1 QCT~yhf@Om݂ zxc1  jQH*3K|3EUX/72Q8w Ο{olz]>&!7rԲT':+L>W cdžr]2iU0m Zy']j_ f_SMMu2&dNY9)-W&ڼtCg#PA n숼pɂ̱X:s(&Wڸ#7_-sd Rr$%U9By6"LgsFKz4z'kDu`ө S_e[4ȀE(;>*E%tKLmj/W0BOv|DvOHׁ*MZJ^vᖮ31r)K q8Gpwgݛ#/(Fh|*Kŧ*!`PKZŞږX7 .Oƭ 7_Nl.)VF-Dd sf sg'2.g|)qKˉ3J:G$3 JJ4oh9 :m+{S9c;g5UH n* *iJbo)&knYfU@# $w#֗ˎ9=JN` nzq(-qPC8Iq@`\ih;̦`9hI@qao/fRݶX8yn߫e1Z '\YNMK`Y(sh욛qx_|]vUh|2 *AVz2J*XQQ5S5RđVl_3ZIlN?;ҼEcZ1}w0*F, e$dwQE=z-ӏtě_0'Y>`P[AypWcI_3[뉖qJ,$Ȑ-Rd61b : brG(&o5-u=*X1 \Y^&ef(;ъ52Ă`^yA8;=Q !&Wb)v;'Tz̴M W\L#?t͹ʴvGlPɤf>sބj  !vt(5kR#!׏Ui#`2Yf:YG1t+d N`Jf%COX೤5r+( U3(%;hm3]EG7~] TLYTa\{=)Z4(+ p.s B;Q\PAj%ND@^|e#1H/y` l!˲=fo+ĆV𔹃 }WqWaԑLgzmum:&mm/ᶀ$"mWc+<OL-HH[Zj'F+4<%Ze#)`bFwP?Uڀ+S!M(ު2`dh~o ph7cԃU =V-}.6CCm$͠VI5!џTsD@ Uy LOJx= K_>Qy1¶+ѧp2XW+.ƔaЇc "r?苼 44_mhOJ]10I^@wņ?u`\饴_Z!jT}Ge4ruUTb$\3%mr5/ͤёH 0v=@ޙrB71f~gf:YʷMFr M[ OZA ˺+-'# W6 (-@x^#K3;LRGd (9 : ~y[8qâKQsvcPPCm!gJ̝G/>7.LB署-萕]S;[e j$ok%LJp©ղzNz޺/1hEnEv*bj@r.F\ 52U1!Z?&¥ߐ_|+!h 04xoo?_37MZ0ntAq G뗹ѝ_q]uY]QUsM<ʎZ>,'щ c 8$->ӪDYAs[]v9 䔺]xdsvp[&{*֪3~M.D_#–l3'tt1~sK!zPaٓ;q4d c:W6W%t3/] MWѨ{ȯypys7q0wSLP KA+)i5ϐ@?۔?RLF|HdabO?+ޠnLΊI즈wԩSΩXe]Igo8ڛ5s,BkN`=pYr<#t ?fͨ3 Y\M ژ!'Ź1mX>lApma$'B7RS,!QD6>\0yaNTZ©aT:M>u֛WqG ?Ⱦ ēj]k췱= LItCCм&ߢH.?.3 wSgw5AT=3[X=T8E$@M nv4aԃd>GUrj(p[*lh/5RQAO@hɞ"KUbTh%~z0D2%?AaxcQWRYQ["_TW/ ,`Ngd:1\%3̭"_s*I/pțw }vG/WsTjB 4hn+R4#Y{7HQ(;qt*13Uo;w.۽5AM>nFkOdZ͏o1\0CrwdC٭G T7zAr8As2˻Y`4uND8?grc@P4Q5#qϕDjDZ]PE4HhYKn?P`,5Wؔ(Q=$j=.~aUәˏhcf>dMCa3v%Ioz#  3=#KEu*r,b$K4-p!F' ,İ)l[Tl2\NjƔbjڇ؝4fel۰5 y#x$;ҟeq_Id`b yRU߃rY=F0W WZec TX8%B8& Qu3G]l-U'JQ؅$MW)6&WwZlnqYVLy):||T;I&'0 HͶ⷗(g3X'0y ;蘞ӈ`ްcoK!4 P̮lX fIx(AC 'iR.Yjq &`ɂ8ѳbPk z[ǾeWP:FGyUyx~iEN.%+zSu՜۷<1Vǫ@oC ?Ѭ;[ݼ;k#kwcAm#0HEV#$v!˜?_*chS^&]p"k"쬞1Lv\hʌЪȜ3.%9&(7'fcvU'}uxqY^B]+nɸ6=rCGD2[2=A%KGN4t-'%2cxqj~%UQȒ8ֺǻ IY>˴z2@=*'?O--☓7!`I ؊ou1@hG_]B,jDS:# ွ:UH!UVJD~|~IyS*ߣk+U^oT[)>@ ]a:*rxIԵ43ۉsous|,q))崑K<3ai=|+ųoŽL puEQ _)5nD^ tN/,uѱyfn/с Fb!́).փR҅l~$i)x]Z ޟR(CBKr爝Hm|..[עtF [l()4Yb GR٪<eÁou:0$3dƯ0XyX)2EK$,b}#Kt N$.z% ]QCK455@%\mStF;!sYf!Мk^~kE'O ߎuzV" uc߱nƯ̽.Y K>.oYF~) ]A%cGz,S\qeM1!CO'(9g?OϜU0$YdZL(:%q]BCbm2%Fmy,/ gAV.b Xd*Zų6,J鼄X@a6F`X%[++ 5.2G6T8Ӡ/ANc]1w(ߧAbca! BvN1;b  1m5e .s …qGYl9ہz<g8 TB .v|6V`){!C LgRI o*F!=qcPi!q7% ibքQ("($ۼ=Г2]B5؄yڕ 4o^ABoeJwEvCɠ=$9[sRD ɽXׄ$J?FV&)'ϱ›}(Y@Im[8kMFORĺMv9ܑ<4>nK =ŗ=|tqm[&J/ &.WT0awKUm(Vۈ |gxb pL]% `%}L0GGȏʤd٢G(V&ܡdێ %jM~+'ֿ["֔8?Ϟϖ0S[p8"w*bh[2NɳjoVS )iȔTFi/P*@N<1u[ʦ'ƬrdڱyMJܯoY0s8;ϡQTT߲?:Rt{Kޯc!K k Osx ѭw+ɇ!hJzXrqsy>eIiv<#b2v*nП / b"*bre4V9*ԑ{%l.&Á9_Q%Vշ6oR' J|o`.7MWzgmsV^=~*rj(NMl@ A 7x'Õ ~IO(%mdrhjK:FHda'g7D .-KN(,N m寝Щon;Pmm.P9T m*BRh]}!/ROgSWBXjЀE7kO)V'z.<w'[o5eFZ=6N6(pRfM&-N c6ɫaX }2X?:bB"}*SE&N5hNu` }8#v iä⍒ۧf+52AtK3"]gNIl &^lЗ(}dAʯ={Q Fwto 7dR¦i) pZ âAV[lkx1̄/,k,gs\U]$[h 篽ޯ5]^hi3 >v#|&x:+fovZšB=氝(sTr9k\mn.hKX]b;nHaG^ 58ʼnTk XZ"*媓۝$}_@x\^r}+vp[DLY,,r'ҵ'u "8ȩTR A6}֍H!MƇZW'#dpw֪P[dg5?#Ԍ̾"{$S>5;0`]yn.+GK7vxǚV#]j=1XA9`6.##'0D0ڛYempHX z]}0T3rz5sm"R#nA4n[*- $Sؼ? : ];Y*+ 7q5C;ќ(b/qJ("V;Du {wD$@dG5:v#ٴ1U̔YJ9FǚqoŃ aݺXֈXCVԤ…Iމr9'sE*7'Ѡ >O&q⅞ `cP>=P< J "M]sX=Ĉb,! 9ح?e2~7X~ߐ~&[ZxqN[{Z&]Wh4 =S1 ApӰWRun XBv;(@fRG{ 33]UWhwJKgpߓOCdP(s!j !mK367[#?)wR~gnx+?59%o $\Z=Iz|z4T-,| ;e #H<M'Tk*]S D*"jDoMG'FY`+O%D7Dbm8ɅՕ0(Ysuq h#ֺ[_N% '̸==ˢ*l3n48]`J}rD]f^sZ>#kFQJlt\*EiCzW_}RJgmiߜF79tzHH 5{8xs LЂC;2;ܻbO=y~N%zlTmdpk~tDD _=b#~LA}o87w6Q\}𫛖AͨQwF84hB EFi}22zaҚ1p%5#cGjj1~Ay0[KDzdy+Qհ:SعEw/ VŒ*ze񪺎sS˺:T:92߅;\`X/qat+4F-QU1qȚ?7eˠ9C!+(FևU{},DH%HI#9>SrB~YMj%'C9®^fFbzo ӵ<%g\U(fB!~b|ډDŝ"}&҃5͵w8n}kg_e4&6U$h:9?)hSY2TOw$k(?1o#wu*#ZLʼn'`Us 0`=~[XŠߒI4Ejn"c=-oHKhRǘnLy ݐ2otsu͸fzl Ӿ7 l.76[Ug2<JOgJⳣp=)F?懭 "Ħd{6Д0bpHxcP:/C($!b 5 @&d?{g 7ؒ|R+Ǒ[(]MSHG$C_lU*rm }r 9_XS X木BjPmϿ~!a,) |"9qxEk䓋hY@ї| 1*}"Ir-`ۋO'(k^r%ƨ-NC=]nS8$$`L 8e`hS^J(y78S_!SbIpqT]SMsփlq[4Șr~-%Ȕ!&Ńd;f% : moѲ7Bwb]i!{^"S4sB.-3o)L,ʏwly^ ;U{>[NKehtbi-1!U - MqGf?MA8-ok˩!$cV~7G%X]Ug>R]AED{@` ם㍈wr_~f3Rȓ_]g^ aǼ+;IwGM'[yJ?m0ob$i$ 0:j_>%P0J)(]CF po)nPv~Q+@dԳ6/5QieG`vCBRXgv-?=>̹P{5¥8=h((VBadžfxF;e/?]7(zFJ1.ric~F4<%6 2Ep%s*6;x( @ruiǁ@IL=9]*\<T:ȈpG12S <@VHё@YuvAPi薜Nd me=e]5!m_@oBy I%"z[E.YļvA" ^&84{<%Xz4Px$ϳ'hn?4~C~# eVxmö71vݥs,^ͯEU@_ ԧ!z;j wP8/jdޕe,/"wMP*3YAhWtz<̅zE k_ $X@-~e`0yrrgDc!#, ?A ,dbsX,Tn3 RzAŮ93%<AL+Bn;3Ncvs3MDWcz0enwDn uf|BX?i]h@ÀH3UXekzD21&Sr]WZHt]aR>+h  ԓ$h'/Du8UF(|`yaH3kmKpP*M syG/c:ٟȩGUi ==SȚ`o,.|#q?|-%-`hq1Tmv _9AUXYd$BjlMLC"CmmR "Sז)cP\ /~ p>w{1}E}:A7O2Jr-q~-/ !%.<}}ߠ 8Zl5e% 5A HD$:ɤ{:Ԉ &kL_Tj|OlZm+^"<*?JP=AKBA\jܲ.D2̱E+Z3qbSeg"~nɟl- W bD8 D1l)LW@0~i<;?^ް0o&$IQesԱm1`Qjpjn]3"s-FV15?hcB.*o!){d\vC }B 3_K} )`xASéLSpi3̸w,FGwH f@dAy4(/ w6Mu N]tq.egm=?w57%]j]9" Tϟ>#8Nod6ҷ̈́x\9M1)3o쬠 62uoBFl{e&̂΁Tj9wrUZ]jJL_r>%]?XiD)a 7,\Ӽ<3j'@&di)\tb*pּB579?2!Dd;[\bV6pKd]8A aCҜpζ*,ԝNC$D]m> Ze,c>+MSvJqmBfRO;2/oC[K_G\\  ݸ@-1232ѫHdḌA*[F1EZ([0I0CһIL {l&\u*g$D8Oؼ;G+I{~\p,.B}Vf P|m>3AKq X@knxp:o8g[X)`H{U-^+ڮ C"ˆ6xq_1L%@ (/8}F .~pZώi{@do-E!B'e5x/Xe50 e wFg˹'.,"$WGe4dqN&uZ@&}mύ/7/}'yʱ7XxXѳfQvs#kLZK㶮gM4Lg/y̸/W8uwS8Ӥ dӱm˴dNSs;4 A 爘) yQc 6}46!- 7.i${%xI ,8WB=)|wyy!>$E&hcG 'k"y!L7Gҕ}34pRS9/.1Ɖ^Z(6j?_>Sy~p#Be] oVD&؜ iI~6 y~U1G"8z|Q3gHL{OS&{ecGuׁ!uF3b(Kj+Fɳk|ՉGgp˥OQgn[D(2UCt#LHGY!U7]lR/8Zw+쮌dο3~a: xU/] }w>YC5b5X 'PEꄈ9Xe zk p&| a7+,bjIř1= q TنUf z!y!JF~>g F n@ *S? *󑖟lp82a~z2?7[LݣQ8<!w 6[C+ iXq t ve6WlKL1OhkJ ^ b~RjvneCo-eǻx#)0'7&Hwib˱)wa;BWrI _FIy,$E/hgE |WU Z;+50ZZ&P ,Υ6(0i1wc9_ng~3HP I]rp%")a= 8~GX@y(!6~P܆ $?/nS h?) |Tr[v$ͤZ{m1w Y nܓ|@_[Wta?nUͷٗ`w[]D*N4A&5[ <S'Uб\NNYOQ@ VZٱatcۭ1`MLM omf}EG{W$4^8{rI֏QᖺLO6$$P@QтCH"mح+m hWQ)':6zɑ*7Kݾ lJ(S^jpȻ onkȴc-PlWHI^#n͸ŬA髱=$TC%lcsXe`Gu7L jPk3O HǮdɹ Cfw8`mgpWP̆.B f Ve#U?|`:yzdaR썞P-Isj<]e̘)WzT(6: (Y*$;ƶ^8L(a2="oFA?v a+k .E7J<݂G4pP.*{VIba_ WGiuȳ剐RU0[ god~v֢,0'5Ou_pʡ |\XY,`lv# N¡pbu $rw1o3뷽?ȯO( r;2PBjͯ[47߬4#Z+Qs=/[$oPg- 2FPbU8 TH2^i zU^cÚr>˃@J!W!m5N")nB~*(ލBssn@Fé=3c$Xpd[cvpN|jX/(az¶a˄u/7ƞXm<.<);ÿ́aJ rlM[<7N.٣@eA}(" P\lg䅘=6vT{Bچ_N%y9ZRZoF yηźӌ~7bbLL9uYB=7ӿ#=vZ؀aء;QŞq6HK"])ܦL~`=(S5+;eo1zPT@G`T QZ[7Z +R~8q:J"8/BxipSY0ߡkh=Py;E ʖIK924ZO=\Оx \#*O)9I<35udԤ]_ö7~^r]zitg_PӡF-^= 2~qoyVYY6*rj(f-ZSju]Ǐe2Lgrm)$uY#`+2S/lz1[K#ב<%sXLEaH`b`Y R8=wu/*RC[s=-EJNM2GBa3=U՜n80E|m~WU(l.`ͬ!p9(Bfb*HuϮuHS}Z&{9A=-fw''a"pvL&#K6=㬷zŮTQ5׽> Qݭ˔Gf`vZ:eR[”{8hDpQNȨkhji #/\Β.8\o ֫b%nfuE~F, Q4|pzՃ Y *Cyz_${@ks%_[n_YT.E]}~-|9 y0Q3:|ac-QIst@#F}#LzC~ )p%a&("kf!"qEi#Di# ay S_'egZT~!] [(d@Ķ_#Fp7:FK7#CLK>ii[|*t|E<È:wCz 7MP'@fxu+xƨ;ֵᓛ3G̨l^Y%)iV1о)SʃJ%dDK>"च 4U! b[ KUgMԻ{b}]>*oQ{c@5dzxo ܿX#&k!j;ԺYx0ZT<<uI%̺Rس_םTSM#0vdmIީoρ#ϒrn'sӰNNԡ\#|QAeJ.}Cxg(8 2o]rkI}c'+Wz!D5Đ'q횺l W2(K%߸%VV'3?<=>,#=0Y2xͺ#"qD ,[r_7ڗ˭s\h_Nz}:RB'sZ;хKt0߮\_')$̱h,`-Y& pMCr>l}*6ncz>d:tg3]anൾ2s(o!.Ym(E% :@&+R̺k2ŇTַ $'rF2ZGhbt\gveK.otYo0 aS}!> g~7̪k З I$0'yz'de-}4#C 68N?v,xüt[ NaC+kABfo2M頹ߒZ> p,5v|,5 5>LN:M[cjyֺ(!k24Z/1s\ vABsaRwiqCͬŮoĂt%7q l~eޕG2{ȫ3/{_QV7rN9iG6!^Ǻ@];:x%*!;IRO  <@6V7}K40 (`OH,Sy7enW{  sn":8*\ !1Ã@Ҏ4B Tpe3IMrU1 :|Pz*rja+>0d l{ECh5%^,R~4=b"(%XM᪄Y B@:u[/ s=ҋ|=]#lE7 AX1ۦf }qjةφ Տ=xM 73_\0롹kd'*)U3ꌬ=da^W"v^KWN{eeWk300O P_;b jj9q^ <beU z;\ CImB˔WymC,\ Bc:Wqs%R nbF׸c'ϝ ~,>у/Z^¯t0 ntM3MtB-}wT&1htY `wi-O!Í<8!^ORb]& s@=E<*@Q%:<'k>iGVXgSY8_/kL澂O\k)6[/@e)U*rND ^"5g鍊} /1d"DVȻ_ȹb@%9T?awQbΠԒXZy I6} bY1&}kvN2IXk0 L2!))lI~z: C7ƾ_hhVj>jD~%j줷E' C$ Y7[da0 G/}if_+&sfH<_ w| JVZuĻA0dY-X S`^cTeOpr!KO8g@~=O$A %"9,< r_[8L5g E;r--FcBz%:LQQoRjA$RJ q *ًz uHMО<ԭ{ q^t/G{D%e^%mHӏo`QeZuXb];M [uEpHfSb" bOxueH I0[@ |+S3N(ٝD#FmЎ9U \?ϱdY`!n_xx5݄HJ}O Ƽa^\z7VLݺiXgJE0Bm:"9w]JDvƉy0 oNM^prsIIRC֖P@=CePg#VqI*s7L]yRK<,,xcf‘`|c5 la7Oƙҡh&xش)4:s^S⿇1!jR gt: &S$!HxD.3b P9 Se_:%t5XY 4;V:Uvfc*,Sp [Zv-*au@ ,[u g0Rl[27jI-WKpjX?G2<4LJ,7 M ~&6Kg,9U4kwT8+rҊnRH o|49`VR9Z(OrKFNO|Al {%{QA 1Y{&'`-2aJVDT`" w#6bW|*]et$Wϙ-@qnd6_l3kSU.P}zeqDkM_eaNj]G~zdo^5&%G- 0D[Z:kSxp6U!X 0q@ |GBQ4$ϓ){c,=t6¼\*ٳ3Iَ՝vFW9_X5Yd_RKm+&8!vcPRFHyo.5Ky"wy]ɏ5R4F98wr{F;f*e 4\MM3N]7`v&Jgpva5لEYȼd Da"Mc_Z4/D!KDش; JQ ,ғ jaGU enh2ssF3HlbB>Z~ 6j (=x. #DK 7Dk(]RXRR 03IxegzYC$6&T1QfusD.͜}܁5PΈf8l92}3ڜp3F X40Б?Û0'+c\iSvG by:B ø=N]9:~p TnNk'eE>iq0 0Zg …$Zx~ޚœަMW8k!93x秕jfa5,YQ[Ѕȭl5* M[Bg8*C Ʊ1zg<ՀJÃWߙ5-} lm cku5VwCt(3КoĺA{VG{V ' R&ԠC͗XւXHS'lzwpoIHw9= Hyۢu!!z@h5l\Lґ*fY_S)$ gɌ\m]^xK|up@!.Koy!;M#eƾ[莕1OPaYG W&de#@3'<@_VF{G|B4N#9wA6w} xwiGuEnFl2J:l? 8PSqXJZn~ 88V72@] u]Nydo* 9yVLMG5vFTe,5E_-]떖`B1bvlc۬]kqxWl.֨nZ:dt3'~~N!&ޛ}DJџw<00Z{4ӭ?eR2 |k?<@G^Wݏr#G,[cLq"V=$<w<vnZG솗w[ `2M}yhH&cǟ)uu8FCղ̈G m0WRx!̗r`WXoShEa^T(3] GdR>WRijd?ĵ)hGtqK֜HQlq94C".9~fŃMPIkHX'@ Ui"a m,l@SrP{R3x0=#ثr)4ÕΝg SJa?³+-wEFǎp땳.8My!gƆs, ò%Q3.c1 k{2yryEW!TOPyS|ek~׭eI(x6d2Ad(c //M MʻfAIܤdTю [E;r W/Uwe{а6聸,&ǀJx,Pk[>׽?y ZAUFd˱ 0L`r38"C{Y>~d|E7$B[kfHrښ p3Cg3!#s`#)#xXR߅/Ͱso%^i" G0JZ3f~HU0t9HonOEb18a8*~W^#`(@qP"A>.MqA^XK,^{ e #' )msWPܒf="9o8;EYC2ԋ˧W.א`SQ7 Aۘl47Z?q&OlOY.bjX }!`7RqQ5\LxkmXE,c_K 2Rл sQçu:3!0 !)7 W_o%( b)HIiu| UΊ﹡RR$jSkR*/^jP)K[@-,{"bΦlS,x`u=J>(MY%هLqA.#ds`N9LP)f;[7Y)@UY 0{DxB^fX ][\_֏eH"/;~.1's!gMv|?h$ce%%xACS4HK5 up(}ƃ_aq:S@Bn-kkbn%b%!+ {rGA T?Ƌ DŸU@Z~ܕTkXu[1# : fe ";d PbEf8z'% /Cɴd^?mJbV+t"q8hܭ3A2X6b ƀ5F|.rȻBka$As$oͭ.y-hwZO X <ϧs20,]VΣup䪉IoVф8yG'kUĹѨ CH?}qC[b\WJLCT`gE;+nc{^~pvqdI3q(J)äƃ{!yZo'ɓ:y8D +ź > U|GL !F3"8YlxM (D2vc#@bp&p|A]Lqbת.MOP̊^2e'5"2K8S Jodrۍ~ҥ% q>gAT1k~7"Ċ~X90,Re)c1D_6p%@2QŊ7:#w۝5V $)HX Tϗ"QH>lq#/͜ "Bi%|y<^3\nS 'PLYƴ4*9`]⨥؇&LorophUajE[Jeb`?E*vP5Jo"2Έ#xy/Bی~%fW|yIMkY7Le& RsQ֡G+ZH+8^ӲQ0N6 Q81J?NܔNOB\]cFr^\ufx4$زsg$Щ6 $ :M ws߶8ZIRc3X_yX$Vc<* ˢ`_G S稾^jBOH5F5yBn{G".^֠f羲pMȢiڙE )/><@'yL 0tbLHx |K*|ai =mf^Lhǰo@oz1bnݬNO=ŷ !/sOL}vY@.'$Kk2E=J_:wfuN? 8D46|0Z=:t %#aYaOۼ hO~j,*@VܨowDn~G=ɦywY5d8]xd;5[ Y%ZD}|=&3D|$tDsrYJ0wg-}hABr?7]͉Ul^e_ _)J6A5EՔ߻cc(2l|hb70+ˊ*Uřr`L:"U3(uu2:,U/-dLQSKW3`_Y ul-x| :AiKьG[#?Â(SBc{(Rtڛ.0j|N!'ztPR~RElզ\:Fq wZ3fsIUݜ.;>abJZL*W@{#[U c9Wbۇ6ہ+ b%Pͧ72ϝ{!X[{xewFhM*"yMimZ\f nQ0bItEr,K7' ӫu)nh+OXoPjL1ն9A}7WĔf Eq1ϭBބ~?J/|_[>~u05gL!Vߦt ?܃Ƒ@H2Aߨ蹖b}X 7F)ԂySV-WH4 %ŕ2׀q6( ~Bgy65CC5.9oLR8t\VoX'&Kw(JzёQ}^9"⼸|(Oh:u),TH5vdS?"ЗqM@ҌlKGb!3aw $ӝkY&I=IRO|s˙<%WBqH6i1ś0k,),>rgcj3&L>n$Tc_)]Zmʆfl+a0`7 Cbkݾ$E5{>6YFsʔ9TeX40M-/M(vR5ҥhmhDd~ܢ!&j1z@vٵ˽]C'ĊfUDj='ҷ'spi%}K ڇ7P0xx `r9;)D ϿV ( 6'oyS:'N_Xϫ #|׬123ctT;s9;lh (.UsDMHpa1 w0bz-`ܾ }6 ;]q:TcG~ޡ}ien)*<%zKXQT~:}vh?v<%hy}^O6f%*xSh!A k6kr[M%|y0E:r}jH-~mю/^S:o\\i6_{G}]\KÃТ gRzz`;9*Nyx2qV҇0U Outί@;jFЎWHڌ6*+Ӻ9Qr{{I2~t ?TUF#;׈ HRf~Lj'a!AXӨÝUlQ7 *[ NXG;XG,ܪՋPP1Ѹ1-ogYj~ '8iDgDaB:M"jR)I""CR5ǍR)#Ѭi.rًm Y+Y xN/HGTȗQD 3]YSLk+ <;Qӟ*-< t8PRF ;N}8+$&lnW74?Ɓ(8+t7F mi5C+O} ƅ|" WKW-* |7'2t3F9&-=Q񐜴An?;Gr~Cv bSU|Ɯ|Og+ܱ7l5o6ՁYm~K:_TL޸X!1.Oy} aT/ز zA㟡Ud+WrXcy3jh$p F0tM]U`z0%r& _ذM7w Y"J \ DfrRx0&a;o ihp& ={5z;0c:g%f3 cyOJ{̎*~N&p4*kxV@إ!m-$X%A-7=&+m(߷b*ĊwjTNvpQG=3P0 Ӱ׊k[6K «&|hhdӑ^ s,;);B?ӮU'p-\h $WF\Bo-eج Y;C oWz]蚨AP,te /(\9v2>[xq.Z zuk/7dd𥗚=9*rL␬iIf41뛥+f/vʼ*rF\bNoԞb й"ĭM;*߮Hn.;Ӟ4G _o1s*M7]`Bf+@NE'ZL1C1kq_ Qze&kc0 -Np %Te?ܥZ"6)]RP* ;:+eI [U0U+z2_@L| Wk8|dVWX0JJA0cجfnkbe%zu2vϐ==]:f5AMF9̛#+..~)j$VVU+%2@[j mg#+p+(,,f)Gh琖pyn2lv󲄬mt?L96pu3v%O'sy/eL[[(]n~ʣt5GzsE:VP8 ͟8~6qʑ=dэOB;v潺P쀥V`Mi^%Ll} vʂ@Tm2s8ů)ή{XӰ[bS,N? }HeTM/ .<(Z5!*+J0*sXgq$mIi s $0n[l 磻*jKԹ1H_dz{<\>6,H=:|K'gYS.R;;W>ӎ ݭ$ 6p i0%*& `w39O{;=F;cn XcD fIuOξerWȿ'}Av,ԕg/g:KtHbMxqi(/A< U@r|nj \_ʽe7 7pU)CsUo洽Ո }O>r eo;b퍔9zQdL(U] ۏV+!c0C6`c"%ٓ[b4^ PE [svӂ|UL.Mj)NsFӪM=WP+2 }6eAl(Vx׬;56_l%e. lyjGg֠,M%obBd_RHNmMQ֯N=E ®R"5ۡkte]2J صU^xarKTC7WJ,Ph(ns({ 9|)x9b13z_HqGxFZi|*)ݻ k(g#rR Sq'i֗EB u,wuw$.k^]F+a}H}ޅuo)虧l;UwbdſbD9ny\7UBޢ7aB)Qp0;-=P"\{P?W͊/_Mڇ+>*թV;.UHKMQ ?yy:݈}vR eAm= Rsߟ R=Sȿю (7j YZ