sssd-ipa-1.14.0-43.el7_3.14$>s`"9+[C8>=?d   ; "@FM    4 { $XLL 3L   ( 89:f6=|MG|XH|tI|X|Y|\|]|^}Db}d~e~f~l~t~u~v~w8xTypRCsssd-ipa1.14.043.el7_3.14The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.X%c1bm.rdu2.centos.org '{CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKOiA큤AXXX$W~XXX3a27ddde17489327d64e06fadbd99484914f1c3ee242da22c649828f86c73d76f579a29f3640404a41655c0f8f98c17af6c89cd26738b226a11b1ddb00fcaa218ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90390719415649812e8c94ce606489f7ce48c319ebb1dd2d7700afc2ab2cbcd02b71e041758b946c65099aaea0c1b09192a3ba5637df405f17896a2a5673f3bcb0brootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.14.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.143.0.4-14.6.0-14.0-11.14.0-43.el7_3.141.14.0-43.el7_3.141.14.0-43.el7_3.145.2-1sssd1.10.0-8.beta24.11.3XBXpXv@XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.14Jakub Hrozek - 1.14.0-43.13Jakub Hrozek - 1.14.0-43.12Jakub Hrozek - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1422183 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user.- Resolves: rhbz#1418943 - If a long-running task (e.g. enumeration) blocks the sssd_be process, sssd_be can deadlock - Also Require a new-enough version of selinux-policy so that setpgid() by sssd is allowed- Resolves: rhbz#1405584 - SSH: default_domain_suffix is not being used for users' authorized keys- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.141.14.0-43.el7_3.14libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8331f40a84070971d9978cd680a24ba3ac5957aa, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6)g]"k%w+p}|,p35muذH^WҀe:>Ў /8 [?0ФDzot 5ߎ>l3{tTzdCmZ"iMPEҌ50A"DRKo ̌/rλg5Cےú)f?] Dx][jVw$r͛SHzW̺%0͗ +E}0EAW-⮷WЀixL.-Nג?ToEZܤ'B65\gOi *&ǩGD*:b}wx9eNۨC$cVzA]xӟNH]xd@+~B~J4(_Rs[壷kBv1F4\6Y5YF, qYGqa5^^9 8ؖQha..fhT([v%j 6Dn5`ND Q8Qclן8ǔY_RNRN7[x^O%6KX'y5W|?O ~ԏ{tJ?V?>O˼f!oX(3>@M"4ONP'$[lMg ~qt.Zhpi`YxቜM pgX ipNpAvgj'IJ0D7&Q2#|hBCӍȝn-n&4cGO4uu.=Yğ z ,J/GM֩BWfҨd|mʒ_}~ٕ$fV9\9hIS{pSq"X-7P;dO̢]\WaWH"=FKN.CeL&*_(R#wcQtE]1@ULfSG8PM#]_j/Zh`f6>B[ v_K qIm?X6Nf1Oej E]cİ9u=vu蜉WI-7t袌x0l{խY!Aw,tD&x!K=V҃ˆ.m_\qcᲭWsr ?nC+/ro걲BVUTRc=p l湇o:6PB^ `9"%@G\YUl5bΪm$jT: "s ?}@2?&iE_-$02RP[l3) % X6Sv^Eaơ~?]k1hԠ5ԫG; {}RT>b&50s^x\}&m~Tac%[(=/k,I[m? K4}y鹌~GI7%빫V\%i]RPCdžňm##0>Oz?#Ir) ەH^Ja.jw)ā!I\V Ԉ%g̙ 7\00oneZhZٯAHW5Իu:`Gn+ =/mn.Ky-9}XB-cs Kݨ}h9*( r~+MF4.$¼.cB]I?%%u;F[v$%G쩺V:[o$CP"A&tH{!X^k|nY0xÖh@Yolx-UT<`dR՞ k@V=5VCx;'5FeRS\yFA&9̝XFZDATnHkc̶YJYKIsB!w^x7QxGX>wOj/~lu",KYtU/)9.h7>m"M8GL.G{ {-E5:Jԋ8fgVLg˥eYompͬ ":eg*ڧ6Ux N>䠐D b 6e_gw𮂑C:}'ا.8ȻsY:nJϤ5q Vs"Lꂻ D$d:X.+@'SK4JRSȆ]g}2nJvuP/O(smt֙s)RD:Ƶ?*%6^71@I⢬;(ӾHSd54GmS+̌_J S7 I/VJdn~RGp:!_t\+)@J4)/&SC ܱ-2+۹̳O f+OKqgvS޾p'9q98_Ko~~(*@<ꋌA9˚"cKJjQ/$ŜsґaާƞHb/|QmS\\mvۈ'|zb&c ]PM+ӹG*0䠗IT2S ^%ve^Mmj1߭z8i4txغmxUŸ9C;nBw3Fn2~a=2mB|!O@,ح^WsQe,-ޱ lݐ#zD(~y Ma֘=% 3o*Hs#FqQxw[7'Psm@d_tYbnNs,k~=XC3"FLNSc%4%X^s=Ӄ[DRB-Ng[傻ћ_t3'bQU@jG\/] pZ]# n&el,䓳Jh8kv1rŕmH9Pl8nǞ2Z%=.yP=Xq5Y`sDHRrT}y͌46A8+ދ$3 " gmK$k`Xl>+ <7)+:ʞI\HM$ sy 4"%,DRN.*Fς6@+Mhk<]%XfL^u`+i8 ~ihroE]w3 ">u-Mkn:`v`|#FVP_)2&P/hl3m3yd$q;U _n-Y'7bk.=\-eɴuV[t%+iu EԽjM[b|+YcAЂ=bfCVx[V peRNhO'[*ƳK ђh17JhНcaЩ*mghuLd$l=<V>dG 1҈|P.Qufl~MkGNt+ib-಍w܌€g bnmt:b93zy.P"{}\yȣaA^sٝ6te&"գf$3y#0 ~IThYr3 1(L Α|7g`ʸ4Ӽif]0IfJ{w̚|eKRH7D(ۺNa2V>&b!*LCx%ĐE]HfA8 T -4Ԙy04BhHJdM@f޸uRI}*>q;8q 'ռZEG%;ظ0Z]&U[c&^~0HgVעO}aq?+8Ǜa+[8~i Edz!GGU.~^63#|ůla2h{At\>BsQIJ ޥվڐ"_M(3qA d©Qc2P4O`pgȊͺO^G8%!NgD#4u'_g(1hFVt0DϹrv +/'zJ]|UB^x$c̲ͅ%=) 0`~ ܴ3 lj '(C{By7_A9%gUPȥ|^4^ң;fp$,mՄːOM5k_HGI*8ʧkEʲ@32[ON%L%SV$7 aǐd=|V1`FQGI+[^Zfu,_#a%#c؎qPpA `VE͝3@&qR" VwK2H(v6Fݕj2VK҄P3ڿm,_UB=\I='Er$1'N772>Z6V?|qVh9?0ꇪtkG*#^8LGw-zm 轷67߆ןEp^9d T[ONJ6P`F+".brPyH@Gs*UDH6? cvqJ1Ҳ-Ꞡ\?+)i&ߩ‚LRmWFBw<:EPw 5n3f%,+ UBdwde`r;EO8_o<%3jԦ@㾏D*^{Z TϤ~hn^/LHBcrA0CE.']3Vҩ֒niP| G!wS&KJ0ae#3y8utF`!@i龖1ʏhpNxlyYd]ч~hݖ}H-4F&D$4"8^Kg;;^[派>nvS#Tm"e @R?(o)ed76k k@҇jorQRb#wjE`ۦc^\.A>0< :%-5CcW lu9rSn"bK@@o';l% ]jklj}072(n`>*TverLs# 8?_o{Iq!|:%ul*WIJD5ž ^d#+hac^|,Q7l9>ŧUny~ w; ^DG_h}2<*Oz'L#<6,vVݩ}F S,P^֠6 grU79dCe "/{q˗V*xϾ/ 2fG)ԱĶlGbK O܌ʨeJm)Cz؎m;o9w5߅;HJc}cMEw2wSY.Y;Xv[Hsgˢn7{0sPS[蘚$2 j[lPVHwڱFL^vo1>z @l4^Z!-uwG ׾At`u7؈[QSayJh?ݥ(x :9LC Ic l1I*QG Y[7 $$Z\\ 8ͅ)+ Ka5It(>| ʧ]2/(r񢼱e9}ʭx#H䨒*^zxZ8?Xı3TNP^ӸmwU Y^ ?-a!2qP'-_3SA1~C#՚ΤeD{87'__|͗ݴy\vW|9^n* p0݄V\e:0gY* ;\/KzƎw`%^ݦͦ-/ !\}IJRB9*?oR g~- U*IEL8@.^HVkxD7YN0Tן. 0!*B:K?U( fѥ9 hAA'V*{'e۝qq2ryJeT6̋m+-8.⁡MIG-jArqP-cCª e BI'!@dh77$=ǖ&OD3iK0?Z#%?^IX/nBCͅX熩!^G s掆հ@^Uyd2a-!z>f &Spw*W\fD^fcP`ƾCCf=DQ@޽Ua@½ݪ,>q0T1d[eחcL]tr4 &~JG ?8*pjlNFMNl7/TOY^D`QXaH>;$D}t'C8hgPvPsͷH륧+]_3Y7e2 9YňOٚ Rj Е,XTh[EʕVUFѴ9/f#ŷI .P!lh;L:S Jo.kbۊ~jcȼDe)i Ll݇ 캵'r|C+U NI ouB /Vhl۴0:AR`qS#keb4M=B$$@^^΀8aZF9( 1_o<#Ll9Y")Vg*(u,8@[j'6(Cw3;ώڏ>bi$ lc(q t3)!ԔPzEe zd]xo0({%dsvtwzwpWWDI_Z7}TjgsLS|; 2k&}2Ճi[CtŘ|( Fq`#?XDaXBm GAʶ(tD̜xAI (6p[T M_#72![_5(T~( 08҄qPUNyU3nYEa>|ljÜkvRʯL 3K6i n>O[=,J~u7FP* pጾB 1#-F+sɪم6݃!DVY/l7`O.ǟ^Q?&JNP~ ѥkQ w;V/qYĸi\.b ^g9;`S؇Y#aS;%=k8%tRsa f(z n$D9#J>謣NW%lF:Pqc f^dqxרv3`Y41HE7NzF44aZ0sA}P4e3]wP>KIb'pj>6EZP;b٣M( N< hqf3A}[ty=jMAC0.c#@%w{}e %{eRmIQ`L1=j6 K|m@X*gS[m̞bON0LOb@K džl7e7^s1Jojr՛Ʉ6f!5e /9rRVꂸsLP\|=#8٦:]mo:%tU縼@za$=>篨"\CbY6XqF9]|bVL 7̀;]#z?N ]$$Q.8';2׬q̏U- JܟEr}8 YeNGM LaM Og}78*k2$+dFfr j=Roy{l{ye)X< NQl DoVtcbf:y.$NӨČI{rFjJnTl5L= Iy[ o (d u; j+%_ o,_sG.Fط|9 N!7]5M~1:7wKi&C^m_tb:?ʾ5LteC#6O>^e:o/^ Or"̢il=]-sA DdM)O\ijg;.JP|?fYaY}fribm!We4WX|A!:̦-W]W:NG V˚cXʘP=!;Me>NP'^KecK} oRn).d\{KEIDwZeTDP >kACoXyK}T(P3/NT߅ o2td1mD 2S"R*ri Ƅ^xUZ҇"i[WQaq h^g^ sMlL |0v-\f)K'x2i5FF-鉺);MsLmf\,yM Ŝ\է(mnزv#xJ>L' tsy@X.V\5ϸWiP* ]<è7gm^%E7ÿ2' WHJ]ZYj.FOX`y+f_8U<OtTާ23c$c}fp:k1xy-DGPa 7&7[nI q 0'\3^P.Ct~OŒ˛}^ J5x]Qۇ6)(YJkBc2:.hc7Fr8U4^VW'S$*b̰B;:lFn|:lfViXtf/eJ'Dwsrs <"ۭ:x078RPMd=ͬ "~_>JuÎwr pr9@.B@u$da$(l^$͵aAzHkE{D}!h(dHc<\ bO8Su!X|4@'1O᚝Z(ҪjDd̋{A2DA %Qy˫o_cp2!TyW>ƻr)^ -δCi7sl=鸍 px_Qgf>iwKu)cLv;me KXNiK>QlG5_`NmZ2ڊmyRqEJִq>8W!H ]݌By7R0TF]7+. |(֕Ew}"K'>l1 ,(xD(!eImfs@KO4d)m"zB3<o{Sӏ\?Y$sOzZ9KXG(D)-wL9;tvIhGg4{RFg z ǡE=sLNC>_j_#{+52𽢧Q}ʚFxb׺@_I;lGBӖ?9 cFN\Eɩ$u!XO0qռݡYLiߍmpaє1tMEhgK% aXl[iP2 )9o˥?tw*,NGgӄ\ZY(QN\@3UMqzXΌE$@@t1L]VHףqi#P8ӕ :WxmJبbTLjZ ffr+v,^&~m e`Zj9Ѝ$Ш͒9ۥ&M>Ĵ*AIrPAF[ªkA>dB7+CZžbW<2 @涻X#5XŃke3֟U ːsw(3J}E/ŝnt2!=ܬB S/7V6s泍 \\1TIQ;'u%؇nї$1Mk޸6D}(1"H{'-Tm[mhv&I^RzFMqhXlyϓ4͍6y \p;읧eg53s5уH^IAtIo;$wgiɧX9f'q1v7 Z]2L8f!;,}wtNsMK<.Bxg2*=Зʝ^Y/I3JKry`l8 ҵšlK%-hM>ڇd0|<䭊LȿInyOwǣ?U!D&Mkƿ[3M{c'5Ǒ4$ X[BЈ{\*͞I/|kFj DҒzrr!m ̧1n揇5"7BΡ';('Auh?}ϐ,J$5('I \{$H]{?̉Jt'=cE* A{,I%/?f y G ?>VܾY^7g8i|%50seb |{̆B=i$ rN=84׹/BS"_>-jl72qP {bhO]w;"aoqM`t)QT&qϥ&ݥ4\ @|B89 # B9#F%<=_o\(HN[^a=Qͪjs\ xyho{cz ί>Ë4¸7nY56"n氊}j^K4S'=E\ޢԛ*.bЀw6}?g+qooؕ؜-݅b3)0]1=Kt r*u_n)C[Q^ # rFǸf<˓S\b dg딚-O|ECɎP/kEbY-!<L}ڊGŨRw񋵡, OB[WM["ُ#tؤjJ?&Wx"fwp%D׋d"dZ?Fr)qѬԯRWFj"֏Ș^y-sI^M0 Et9e@ˁDgQWkjPAsk P=s=R^~?.Ճ"ŧ;%8]|0Pcc yX3l9H(^ cح+Y7'h 3 p2b%.?J%N=?z8Y@nEr[fmN ;EdgR,gȋWlt/1x++ +Z)?!C nL))fmC{^*kbjtW'.Uvvxب۶uTj&FH[Tu?./+}P 74 Shh8=U,0'q?Sߗ",G)EwApHRwO@Fbmt3 rYAbR5@Aa=-y"$Aٟ<Ѯq9-qnV ][Cոw:qtKuWcQ ,_LtWW4Ii<01<Beriw-N/hc.L@[|BL]Ϝ8 tQ)w(E1/wz D*o]’)W,h77J!&~b(}#`|+ƪ13\da =-FǗ48I^366iWH(_.w VwPOCD. i8ˢ^pڗ$Uf/=뚭kWsu:} AQÀ%7lT P xwt>tO :p4P'GXؘ%Hon ?ڍ5&sFW1 'r='_s7x2h,6WJG.!m* 2_k[dl?P]>~R!<:Wö(!:zƼzpv2: z\Fl0"So&L$5:Kb:"p{°KdjU9](Z"Iάm= dA_wH۬(=(175@֒cq^lTca:D{kƮCQl~*: S'"t/Lcv:J Bkw:]HOR*f,j)p9E*ɠҋ[a>dD"¤ϝ0xEK0-I<`+N:bfi:ؔa '种e*-CĜ1o.[ O'~.=enȱ(,}R=Sȷ(ke.xMlrl %4S1lB =<>BE?8"QB!sR&%z`xpÝQCfRA zΙ6)xQtT\ e]"rէSC/'d^F?&iŘ t6VdMՙIKHMjOiY -?,ר.7S]ʌrA]%^lpU 7NsHf]Ҙ+ky1Pi*sJ~?u"B?pVmCN#+tPԵ?/AY4e CŶmq7:lS32m:01UZ SNIתR\Q|T>'m>m6€* / ܋WOj+jޝ!]fkS_>h07""1S+UwAܻZ8%Rp9'^ bm.EF{A(jЕBWVZA ^ee#aٙfTQbSh< /*eR`oցTnjk۲8 ՠ分1yR 0Ş=ygFpIjjˑQb_e0 @~( oZY>%u&IRP6KC*xcq]L'WYa{vuz˽&l,^' fęOEL 1 n->e]8)/;7mr;j5;,u~á,RZl1HJԊw!p8୓Ϳ{TVY !B)=&خRw J 1L WZU?I䓠@Vɀ>hQ?ʌyQGę # @weٍ ]Ğ/_һYmb<Z"XucG_:D f3}Y L58?4CTaC"!-_TkOyq!P{ۗ`i H;9g^1T$K\C: )T $VSrEǭjXp #yaKwnRWM>|j9TQ!~D] !,i'Z5]1őNS`?}ŇC͢)[ֹ7`Mh;Y~/=oyգAL2zب_סUv٪+[EP3K7jvza7kцVÚ},QݯpKOMAuHдTJ[ `$P0*Y g x2Yk -|:X귩:Y^- yyʿWG(D}Uz^5B2za9G,?mU_x?«Q1q)_.AlZ,Yw`x١!AsѰ0C]Nܖ֡6~ h]fv!W MJ0IOBgʅ1-18k@BNpTOZ.[sRO/jbR${N^HgJ?_wvi#SIn7"4XwfBk?29)N"ە ȓeD*y _S:B=8k.|^!oOaZYL,sR3k@G<3އy}87cnnYHÙzH#i.'q7[7(@$WZ(R.iRjG(;=br r VW %l>X7iut_dց,EYF#|;=T/'8%a2pgaK:o% ڨ);?W~~cLPRt3U5-0p :{#Bt@>9Wn5;S GHԞrwt%m_aϟlF-7=-X8wW<0n<E # saTgbBSl<&i+ L}_* YJeiD( dF3 'bIn"bāi"fDOە$0҆yCty KlP^8Z(CѴ|-0\?+K3}+g>ز&R!֨Εv2 s3+>u2-yuL GYQ*H/]иZ[lzů`]Y)9z.-~H0MV5t,f.4?B1׻ۆI}t^.a$fXSO6舕 FIȳ<Yv-%lo86MPZjh kr:q}E"b*gv㐋H(P> h~ udua-MpXym86w=fp(A~%AliE52['MO$֔<4~vP=|8d wêZVz5s Vi[3qߊ6>{y=Ownm3y{fwmӝ/a?PxlOVBGX2PbB@è'7w}'w} ox=8fg>عnD$ cvn X\w/&Vg ,;R}ZC}6:{ѷ|}h-}ԚK=Gzˋ߂pcVr W;ܴIA@VA}U,+H&l1U_~/_ݫ,$q:.< ہMIK^rBU$o[e2ׯg500^l13tNtfXD 8Wlbg"rӳGflRpu?hKB\;TQBTU(yO@yt+>n&.H9PbWqZ¨mN۱=&46q@ާX'!9NH?2|AQ/"[ yi5rq[ذ]=_I<.`2\U i|%h|f D8('6u.Ȳ BN5jV &%Q%߫Mu8#;zUa1!Ma֭'v$!O+Vݗ1!+bHge H|<۔5szIsXݦy4MMgvF># UޠBE p?n}!5;I9!@rE iS !ƿ#䜒5|D9o]M"xϻۇfv],ൢ]ړ=nOi2 c8ݪ8PYWVVKJ  eDAɎԯiSQ]0B'崃hSgl3x(`ױ?:׵u8bVt=[o+7OTD>9oL2 KOppɚ^; ppY6Ǎ9E/ ]$% [ 륫>eG)㭑!󜞲'8+X'{M5;e;)yvr!Ò$9-6h- wU͈?)r"uwv>T\#EJ]$9OY[ O? C܁- y&Ĩb)\<`N :!]7S`W`曾1^vq=#4׎o#q%%E31ƹVn{=(N64ch͂&4J-V9.'N`.l9 Wof P<ښCL~WC/}]?sv8X02xS4B#"x_ `"DŽM5f)oz2҅? ' ̝2<(υE=?k"%փE v]:jjoqN#$839zjY%tQ;6}Kij l!ۭNv;j};rGJ? W=JR\\4K"3&|oֈ e0K <4q>x 'h--uvN1,N%&7e!jg{\J(} $X?C=XZYcQzFcFs% Ns1f8M1KVW5mwEU׸ի$7m8 0Y>-vL`{S-MNǺ,nM!æ$ӫ&(C|r8J6\8Tmp@d7VJw4?T`q91;* CtReɶY$mjeT&uٱ~ 8$Nҹ~]~x< uC Qd{&F>(ջ}o :MҷB >h[)X554<X "e+AEc`gH}=blL4 vE_$8ZnRZ ` ]|"10A *7dՀ=m$.J5ly'Z 5qEv]vltPXuQ1npE.`x gWqȒ=lf?=zEoS)a2?˱_>\܃d\vdK>gI Jܒ/8L"A=Z9<onT8eqF%?tBx3Z[n`s*iRk5oOI.>TnśC5`=P `3nQ۞@qݣDTn(lotɶĪAr4"O5},`2 dldeTRjș 'I-03o:R4std;F ʩLGjЫKlA*#vI2=DbڹttEȗLR\ZrI-b?σ S #Kawl$\gz1Ƽ:E_"@x+SN5r`LH@F|Cq,6 Og\,B:XC1M&#KtF–fVja #||r Ь+yBf~%3))>?O&\>Y 4@JX>1|_[bvAϞ6x5bO%u}-un]t}F1 %_"EJZtq!~;nga;nkRq $1_A_87:Ք7|j `Vס#>LI/_= 2[RĒwLE;.ѕceľ}QxZRܕT1_\.j{`تCk7 BB" iNzքλ3yG62ɿ ]f,A@<|iO$*0 D[c ISŭ =}SSG.I T]aU,C"Tkϣ8lDYpl4%[9,3u7Wv^o=29 c>!]xChkRYu~DM2'r*V̀&-_1B}%#Oc#U>h4e!HڱzC* 5WbX|Mh/4P6{/ +Q򹠑5z[#6ޗj;H/X 'yE`Z,ޟګr8xv wBwwnbǹl('B9T^Ń+?kCn'=K*10T̤Ȑ`b9jAw[92vx_-3u" xc;6r>Yd8 JjAq[UβۛZ_(yS0 lj+f?jdTpӐ] &vMQ+vZW5>@(Ui|ýU1,-E[ ʕ]ToxSb Lw9%:E<ܛ֋.~Jĵq0Og5ˉij3ncx 6k5 ow+πXn7Ĥoc@ դa2G9 l}44'aݦ'23N^E9#?ިie^;/" q B-DԾe%?Co0BU]@t8dL]!½`L &=[~ Zc,xPpDxD ZF4Q~iJfw1&+4L2qx.2XWgқՑN.;277,ZgGˎKK{>Vt) ׀n;h]WuYww !J6Eh(ڋ$21YkPd9CM@㣺q@a6Pt} [iMYDِqܟnlDVG)V,qϠl7E0Pǃ^DS>w~"@B+MFJYֹ2hV? d㾏Qit1j' VQDT<?YnMذ]CB_ ?QDq{= ¤jAy#j%fJH/xcV_C) m~)=&<)p0ĩ2.[JxcyʎKxAJ(;vj;d˘cs'~edLNXp\Nb7kO%鬹$ֆr$RdqXD9iSGh?305 FB9d{Լ4TpqBSO7< n +Xӯ7 ư$kyaA.xk(Piyhs:% R?YƜL#jit/0'nn=,R/tZ~ ^\?pߝǯel~eHws3x^[jYk3v `ht#GVuzrrqK(exxCL{L]L?J6&y="z9TQup$Ûir hgfRQ#XR(ʙ* To9zk[xWg|d._iU?&}@gMg@${*QM]]lB/n#]$ߚg .z+2[:Iy4CQzAͯuu;wHt̔o MBۯk&jf FFΛzt sO,JkI_n|f;.EnNn'Lu-d-ڦG'vdG}\Q@d#1EBߘImal+aTg:d̉i 7?Rm?Z'/T#a5G^av*7!_4Ӊ鳬Ԯ_g+!OQ65ڦ=h%g;uPГ&1f",:7u6VV޹c9rdݱ2Lg\CEe,1S^O;4^ru8Gvf29)@лhD!p <F,.˦ג-YZ%bF39uMzs<=U?Wo\ڐs}tH5RK^1/`!0X? +TokD÷Ci2"?^9i3WM8[ɡ4VoCN+]?RЂ-%?gd,yY8>̧zOgʅ7h\Ja,qY*-O?emuj"5_N"@ 0? ᤏy%,DOJA4] 0gX~q/a[e 'ĭ!|};Z5b;ddT/pȈ 3OMAvr:Ӈi0G;SkuuaP[leB4';&39<[8ci jXٱVN#(&*qC\UJ6P26@i0 +6{Cb (g񳸢I$rdM{k`˂֞2--W[yF2|Խ*PS 9#FMmWOJ>jZ(kuH$n'y6Jɏ"3{&?ESwwb-LcӳWM47 vv[kc{c.v+.pԨtJ#G[ щ[n $Hx,]ML&_3ʒJ½翄+)('F3ORD\TnsުۭR{TYU>gi_94]jʱhيbH"Ӕ~f$N}LP6$D]MKQ}lY4{gv(BV0"_Apm\ONe8޵bA(!O]Mo9Tog_`mu@qnمR׈AeJg$܈ Kb9e O/b5lsUjCqmkCvϜ] .$xjbhS `$b&uB^mhXрif{Me\MfIѯ&gfmz % Ŷ?FAC x>;v7qm#cᑐJ$4n$kgv A )7zftO6P\YޑZy܎ tk"}2PR@Ae1s ѝ 4rch/&` 40pYBur6vI>ju07_$#urR$S}_G3K]#]8g6ۘ4_*ET| w|6cmmH\QXٿ`71Hl/vyw̛^v97d-y!Y蘲3ǻ@QYdG;sCD6q$w@L%׀؃(2311ξh̉w(d+7Z,f0KU੸ZI jce(ˀ)A^Q,[jl7&w șϝML½cd41:wwi`Q>>(_ cW;s+r3 Ll y\h j2DRQ-uXk8*q:|(d/r>@({cdMEJtll?$?8Ru8$ŭCq lbOnFiXMH[ !z皇HfT/nx<rlfj"%Δ!ܾWPcȉi[MIm*Vq>NGUIBD8>9.7M?tz1fRz2kc|i(61}(?_,,nRbHYD2л4CJuj~+!(SH7g3x+8RB9*3!Μn;g*[wt&Ʊ.koo  dM5=_`!Ee'1}ɵĹk,)ؖNleH!"u ;ձb1G{"uQѹ9DN!ǡWre5\Ϯ]82j i1%ڀ[LZh*Tlᶨ$;aDz`}YGȋL<#a7Cݠc_2pwx9M.6W >&'[ 3U G2 t0J+Jt'RA+G?A'p̖3@ý:gLkѮN`V2et&wu5Ö JXaLewOf7i(ђy`굆2EBLnWz'83IgL90%3SWqi}~6*t]Vhcp !3+MU[0$X"_/<4dWa GJe#”%xv뚸"79e^J 4".zI/Bg %"zhBV he~2qܸCf:{4Bs.ѯ5[9i,Wyk-?<|MIӗyIBa_{StC7m1|0B~EC^묪̕ Sr|<91V#p}.Zqp]ҊKK{Ȩ 6 ]f*\~R셲wfēf?725_2]܊c2q 菘@VMԃ #WBJ [ŨlՉ+~ys6HC6T7 Zvgf#f?Dnuْר=&ZYcPQ |txG?@>k  hpŸ WF`֗o8ڟ$!qƍ]T?4Jo n`rL@SuMɡ_^"-wǸ-v;"eo[1:a/@Z&9177]{TU=yDHIc,ȉ]w!\`q./ )OCMGMHA@ 6Ѳ] Лs#рY;0-˕vNy`5?"PtNkv24}o(U*z&8E C p;'׈H]}82^Xec~[郃f%kI7${He̢HzXyBم8M8餴#(B#k`>O\K XUMC0F%sM*>< Dgvyٖ(njg[1lPozΛIՔ/fFu:'j0Yx8vzl9GE4_,KL &cKw$!|"ʌcfˊ2n2CH4H7L>Dz]7[&.׷&oxiQ"J\w28g XЃi5 d4 9SƆFp`MPxu=fB$Dg<[Z ,1H4ge#ȉG hFׄ@8&3iG(KXE'[;pjǎe>h*H#*HB/ڊ[3wl*ط,8;,;\^բ೗& od > ƿDkYw_rS)(~eK?g𒕌|lU!hI ԟ9o廬SPsa%~ACVcJiKCK:K_PcmqPW2cnM 59dnD:V<43V'Ln>B^SE""A(OobrU4 ÕOqjBGK/59z'Xcʘj%~|C%~֐sH_*XkRX*uf72OJ{'-Ql;X;f+]ɓ p)`? {=Whw$ŠӴ|ox'zO8B}Ô;5~IrkFLdqe&*zS t`t@l[Kf3 p#էq;Y>~aN|]A(k_I~aA'<Y2axLa T\<퀢U[*k\Cs2`k3ڢXh*4+)t '_HB7 |' YN3b?̴{GβC^ajx=ԵxȤM9TA+wi:T^T{8JB%KAMq4LtsyJrs*^T*XfOaF2QAF5.$ 3~}fA.irǓ$> 1{ %|@g@hm(r5 oSEbokRGD)߮SmJU2M^/ޅ1YMˬ)711bnEhaSMG[bs| vhi 䔀{<3WLPGB-gbc‰ f>K#g8'ԳI&Dbj ?x jkXQ8fK3+d`Ru3/ xp\f`ijmc7/;D}mnț5B mERC~wd7Gs4WƀR-`VG|H[7N@9O9]YJqJb| j0;IRE^fn_~CvѷL֤P7TkE Rç15}{tA%b@Ƚ+?mFzYypx",1m ~c(5,1W)ViX 1=ݩaok鿉B@ *M^m_y¤s(Yaˏ?S~F c~RH`Ա@y#'?0 D+^4>ѸX{Wh"*yAlW4 H ^%_KJD";!j 䑨^QTaqjkƓj 'zve ;^.KosWnS*{YeLjʈcٛ!9 `ИfI唗 V-gm۴o6\œ r̅ZH(,~ȫ*C¸eؽ' R}ſdBkNT3Mwg:7?n#|8YMZ8qft¬'x.Sż$0Kɟ$ARq{im,5h@KLb 5}z]gT|K@\r"z08̱Q)KvD"JIT2;xʛD(h ^U I}M}u ?׏ud㉋ JnڰBjJ^cRE^፸gi Tݞ9R<5$pTQk:hCw޿Dޙ=tfV=C/ԹoKC=F\siIj - Rs9am10c4QeĀ͈nE[r DQː}53CSRAByǾ AsZ3f"MfY;*827}ή%"'hla(PFޱrbBE2X`(,(pl:27#}IO)K?`!&g@P4_x:7x0҆B"CoDwbX-s$t)j?i<çD"W}4@yZ-A5&0+sT[@|:Czw!$o4z~Ie7;#&bj6W0LX MMy֑ȼiYQ+$b.2"Fj"\'CR6[YWrEh澃CIf κ{o (fa+$st0W!A(`` % S[U(jIւ~N+e{)w׶yd"ћPLs&Z?DE=1?ܢ%Z qXA[$GԌ|GaraHq"V=fOrTy %:sHOf,.)IwF|Bv)ݿ+Xn[ZH$l 5cU 3?3Ey0z W>~dahvq{* #ȥ\0FϦʜg?3&bӴHG~D #IBL #5 J1CaÀB4S fҦznfPjj6ݚRF'a7yIc[&ɩIIgk yW/F*4Ƨd'aJ(Q=F5wD+detL&c&d 3D)WDB!zDPKsD7d- T)XWA?i*|@dh'C)fޞ`H===#[52t{YUa1R qMgg=p_ ﮴Qd_W+P*.SƍǼΡ oƷ䴻ޞ!B kaM21.n\pݧ\%bԆ=ּV?ꙝzRb֦Zk(ID>s \dGc4^~5MbOx\pt!(@d);qkcKm (`!BțM!~b} Cx^[*8zk څM-)u?72B 8k2TcQȶmQPb-ky$XHHy'cQ[)_0S|g7s 9I *Oi჌?.N:A44dOOIcbdO {o ryk\_ȹv{an=]5*)\.iqMHvA}4!Y9u{}4ڌt2?A߼BBn 8R~0F-mI]HzQ:!%%dQve0/[>n=&|!,&93|$%+ wTڟJ!~!oPسٓ^-f]VB``iSu d[hzPZ.2 )fJbZgWu+K33A8zF.!r 91pĨB*;[`= > &)DRD+Է[3e?exQ@Û 4A͑x:/;&SwַIS^.wUJ_9O?(y$oELbrRwL ˈ"Xr] ۚ [[LW\* [1[@BENtn=y#;/ )o胘0D z$Jy)O4}o=qˑᯜ ŰXrr8('ߑ(HE>hJKjQ+hH}os=Ce lv"u}lo%a[ +SN}9[q=YRWu,K߇gK[a506:Fݼ~,?M^*8>c9W"19I0(g"BbLe䊿b}O0q\W%k5qXx7 @'PGmFG=L?ۇDŽffG8;eg_= eڨ3QijڞÇ"pű0kQ-GutPO n4EpF?5rӒxH5k_Q5~8vgaLVC0LUS8@v.]pax4CoL(p7w-Gcf@I8(vtstt4S^$M}[sujd#rXa|R[ܒm<Ǻ7ʧOw 2 i.zx42]5萌U^MӍخKu(&_ۋk8DNߧmu4ꡬhӐWUWFaR!A;OǙ\,ÍĿcm䏶|LO%\M]<\k` ژV(t!51R3,Mt!㕩d]y0Ds%t {'&~;Ufp5A-Tz.uyQH39?]Q΀(-Imd3 >mdmmH! X7:V3_B)(Co.L mG+>J ӇӳC0h5cce>xJ- ~7' BG {'aH5𷵄~OE^ّ'$G(umSn1|d Â{ܭKnIg*״G)KEH'z+u-Mc(7/IfX * }:H_MM[ r80r wfBb (aVQ ހǿb*d~Q5zs  l䳣M qϫpp?;$TY5ݣZ%0uRl"n$'TE5Cܦ>7cҳc0D`׺xUpcwD^Qwuy $T՗怤Xjoà /I_Ď"{@NQGCTcUq ^.]Ye1nemiѬ0DLUג.';L p>1:pv^bAO!] g^@32wKw#=_rEbNRuYJ9=<Ne8% ,U̵>83fcMBhݡe {~?jT7>Ћi;(o 4ER.̀3xܹ]_ˇmZ]xƻchrR-DhX kԎESs kx6\E}ʕJ;>EFUѠjmYov@+CD{ըQB}Q$2i7Lfa,Ŭǧ7kEvX8ЅmZ]Х'ZBQ_$[=ՍR)^I0LOYɍ@p) ٬kpBo]{lQٕxa400-V[{0DeҔ؄ҧ.M+"C )}P_Ki{BVuL35$b`=ϰ&:,Wz-Ƿ8N:j͉僞THe7c\32^@P$<@Ѐ>ahB2K'7(8fxk<=ĥ"䣃/e7HWt])W!?2{51k"&8(0pهnʌknکzB$cQ.ޗxR5loݹ@?pD؁= 7ut~BxA=֨#ޭRNO W&q=k!WvY \pњIA u^Kg͌% Mz#j'_AmY2SWr@0A(-M&IWܮT$.y9"*ݠ5*@`w![!;;SZ;zݶp2jk%|?f8{R"x`# &\> 2cSȴ005GSM=L%DTMJ=arUEZ]r7/wfhw D֭.ce6ـ84j+'LnACoNl͡ՄQGsTO)\Z\8X.(=&d ȯGD+PzkǍQ͢7C̛#YþXg0+zF}?y#i!n,M?q u|iڨPi] DBlBGH,K~bSf֞Ql0%;"D_:h]0PMM7^Myw4RgOnp> gWmqcĮ"02K&1@Bçg\_m 91'+Fػ[3 rv/hbA09Wj m{ 1D*p5RG?yu, d`93dmjL!c^RiBO3ܭw;9>Auw:qETF.KiPd2`a0GT&ЋeQ-BT)0E1 8%2Fs/ t *"171n9b2V=^/+}bm? Q|.kj}=h$й5 V''WNNKޠmZ1ɨf(k?`nehwt9}_'-)Ed2p@QXܿ ]#MDuG19Hn^;=]ofyb I@.,@&TlYb{䊨_ްK8ώҢZz Ɉ }@z_ >mR>_u<?U(=8lV@Z!h6 %RD=K&[j;{$k k8@zov}#!I8}b$&MƔpjS6Z%?^g OVqEE`LM 08Ap/R=Jm]n߄|bvXf`gGm@<"qvV0`#.Efz٢’wú;GZ<z׮ƃ][g7( 0h=yh;ue_U'2.9O3M !e\%]: }ϙv,gjKx<PAǭ_z^ As.PX FR0.*>,"{NԄDw K/7N31V&]x4pV;xfX0wFL9)? 9WIuуp `F;FnMfۡJCwC0k~gp Y,F?@4ӃG#ى>C(&+|7HX"i?:iAi) V(j/?ֱ#$xtxqSym0)ޛO\hs*ۦwCn%۪GÅZ:FUaL՛6Ms 䜯t6C$g}?TXT:8-yEx8\ɥL]Xq|L|hD2I,GE ٰ+F:ׄb/5Dr~ hIAգgE"2N5BFXt8> +T^FB>x1TagZM\/IF f[7%VǪگr*l 0m.d3Jz gUԠ`+QҶ;1^X`G&>#H.;/B3BOl2]r/FWl]O\"\sHX%Ee5!nN Nsm/2ό $e{?TTX9E TrLqv CTe5-)]{}Br綽'2ŃJLn^S8/>q/sv4o*uKNtLefBM6FDkU=¯xJr9nՎL!hﮈMC}]5 nl|m`,[b~IHVT~6WI8 A!75O?J*0cLn^* xai!n") m'&I_$PS<nԟzQ(سǩ r/G_ 1l@PI9}`X+uD4c Rw\ ߃y@đ'^$mnf C*?(3!uhuGrXR";n-Kgz(B &U~ҏ̃qYkYOex^y#B:Cf7V8U-Fijs:jeֻV8nWfީ2 M,sO ixдA74O>SBa`,U.lZd 8u^![߻H%UݏI =Ujyp`65͙^\th++|ɌH6 she}~˃S|3(; 0yj")B\Hwu@@8ttHvf= %KZP̆a>#;* {t~ں t>4';;7ecq;¯i^w6FԖe EaQv2u>sgNpʘ9%햌)`zJ{ 2 [O@""'F?'JpY'o=,x/-OHg:'~JSÖi4(X$O!cՙ J/ENݝ`M)c^W4/L/q @7۱]Rs)ɫi-O`iO63XXd!͙!giJQT7.B=WGPnzU? czp[xl T.5`gq_Y5#h&l`|Ѱ-! VB9k~vqLxyr Ad?6+P;9t+V܉(]}-R8PL/-|þ#e)+F^70ntۥZ*ʭˌH/m11u&6`/_l Q3F m[o{-^uGyeTd˿wva(YxbҒH^:qf8ۣW-:J v"4SOQ<-JpU? fٴ>yT@4 Dc3Slj%gNt_?HZZ;!p7!߿*. bq9SB>4sН%m1pN}ʗY!uiД,U6B1ZӛSؐ0ЖRNxds--y%V( Tp2ˤ&QrgN KanmkPæM?$qm@ol^o.=!.C(*o:*"u/0']=e ʳErcGB0JA2c_ɕTkIu?1XWyeϮMvf pM ;xZ1k95~7TZ\ L#`՞jP W4ql`†FC=]`{=m_;ƈJz\. K#ˮeSW@آT0 )E)gTnH |,kxWv6Mg҆ ǕEjf+Njl͛Vb:|U;qxڋhln!L&qĤZ^t[,$D=,4ۃ!-#o3E\ꌖ5f$g_ȷ|8!#|^P=0|Pq5f\Ny`ݴr's%R/F(1RX+qZ<,I-;QnQ=rԎfHGqeWMpObٳM]k&ctYg _]1%"s2^{ҏ[c(-2+Pjdc~M#BhbuvSUv^e| pۧxa1B4N7bGvcE^w\*-t콜x-.uY X!L֔P~fdPGT6O_jL$`G uOM-2{G=j_b)N\$ʨ:=CfKgִCj,*œ2 /4d4:$|OJ|P,}%\ |r},RУ3~PΒ#\^SMǹ$jRs 8 "retD]k>۠>"Ջb<@ [+B'*T*ku( /mUUK/sQv+n>­v#褴_e>*p<: orF򨰗\QRktښ枱3EM`a)_1> jxV#|зEFT2`g~-u{LD_^c0`07[rQY8<;%H!ct$O59MG 4QBE?]v{,jj*j~%5 W{NY%8&c%:w߲~Gqm tQfI_&#*=h.Y* @ KU":kx?B_+1a{RP.έv1dU'LSPw$n-O)[#O)]K%ح`tU`| ÏR?3vƱtܗ$ɋJv #@uc`SNPMpDz`׉~YOIw% N7VLn:"G+, ]0&~'! 8hڼkHZP{)ĺ H4.~F©R/q[ݡ0;BSZB*`RtK]o# _gL.e Cn+Wtbu;Ph A]GD5G@zLTnV UX5. wg!Tg2}z<^P=K0KH@Y!Z#fi\R(ЫU4 A>({tN lz(OBYu4 >WKiEm$\fC𨬍E?}PyCbc)] -p~j%_RA+J]p ۈtܬ8ztYB D̳+S~|raDp,UF)\ %~1. AE@ŀܵdWR<x-Vv|OJs?2`ӡ,ܛ-zY>>Ñ ]0Y(RK EE!v*amW=s%Qt9B _+Yqf:W*j(mUe)e Rk)ͳ ѕ/$?s,kF;>dyTml yX2pː_.uPs! ˍCʙix ӭ"ƚ0I3Е̜ňɻJ(0hoqJwB, \Y%;}M $ ȣPGH QS8q|{k7EwvIK<}qP&N>Oftm;3`#VJ٫o:y @+P0?x?|z]*E$C$jGDu<}!hۖ0EɒR+.(W {:` D]i`z1X4*{ ɴh6Te :tʡ$x:-5Pօa42۽@u$HN0SLâDژ2i)O }'@L _K6d+wO,Dot: UD#RGj}R_o\ yR{*alģU9]0'TܥKfǫŕBM>|l8 kc &Y bX9& &1 s?. yӑ} Vyx'vƗ\J\YXݽ$%]u ,ưo?͞.P I֌Cc'_,jMṯΙkZVD{*DC1bN CQ%o]mnϭO to 81,-p?6=VޱDƝM3؀~ZSJicӡ!kddmz@ /*Qb'zeo!qWWƬƒm U;0Yxb#V& [ \ & HDx+elq߰,U=ieAM9=1-pr"zSQ>;$B&5ye@Ȳf8?zyoo0jo $F_^pa]j#L3U;Ty&l\.7'`-/ DqT$B#?+P^&6?D4h[{pmˠ&~%VZurX^/=+5A#d;W,˜\0E!}4tPi}eAETݳDENpøo; L0 sdΙ>43MA!Vzo4J :n)cWx b~17/rޫAPVoj¿da!E csk!q`pp,wǍ`+YPhRwIy;T@NBD 'X,+f7luOa> myhJ's3zP+PAAǡE9_3J"aQSb_1Y0A 2MH4VJ]H{̉CM,.{ | @B޷(ed6X eӟ{O2aضRh3VJ"{ʬ)slO$2@sī2]ҥs/VޅtՅ㹴|@)迦6Rpخ{ 3S&a !/+%M\fǤȀ&Ƭ 7d s(NH8%崜 Za{v%C9ͥ0;ĊO0xF{#2gy%ý@Rrgp5VhƣwHk~1ZAvH'Z[vxR4e)uR%0thqaG,3}J¨mPrkaI n{̉oc,O"@#ƍ8a"ښ)|nn"^?_EF4%{}b_VaYxg4x쬭 ?A\rG*7fW7b5F|S% I3b9}a 𵁗qx]>cDT*f3ڲ&g`3H37x^ .U2/l*t(!z,5 WW~/uӫt̝}=ܢ-ʆ^?=knc^ E,:ŌGIK!eFo ;mX' 4OZӶ^u'rcHO&"H'0h=K|&k!solu M`JFvqDOGX{1>_ uOЩ2έfX.GP n Dn #PhPˮ9҈2hoĸ4[o'w'#  ^⥽{ț$8yB1vs2-/|1'/M)H:|/K {QzٮY6 o;Syl;K듴PPD}VuoR5/_S[b 4{.9q1G8SjLTq"_7,DDa#WӫŰ8zC( G!@[d@(u"@ }Ƈ}+W=_{}^ngR5Pd 8dG0$NsNyf3Wn:P.2Yh°o>#phL.]-G*xɦު{Ϣog ˁqoNL3Qc # 4rLȹ'iBƊ Ju0#҈t(b 9AIk~XYDnK{ B7^nD`>F6ι7GXL-%Ȗcj؋ > ش6TD߰#,ƨ&%ٽ6ACS"d.j@Mل;z)VE(MWlD*НqD .]-)XcGv7hcxf}'kOL!϶R{M)zoeyO- Ղ"߳VwBZߢ{^Z:,㟠הY#IeZܲ5}!Ú[Q!Jno%6>ڱzRZ#Z=uXÅYlw<KpߠY0h40~ѭ+ni[+R0o]3$0`m 2T)o4z4E=Qs%0XJ%9Nm@ $2f $ACn?.D%o؝BO^ HqSY*%]k AA@L%b08GSα T XnNYz Or> 6VO1]?ɩJt 6H{KuK&&X| I/CņjIDO! !68eoP3K yy# :{ >V%ck3 o@OuI3a$G}wr2N@`4\RgUm ZƢwCq[X.vwي΋1}YW 8o ^X6h ;V'TTEկ\]QdN/RmP2:iweԯevќ4g-YվE[(^ާ?$=&OzȣHpS?arL^܆~fhJwl*ELWe!SPwfZPe'#﨟c6+; v_a?a;x&aRcG\sY@#8/g.&-, czVae xna'sQ(BάMQq":+Nsc[5~M&״[7FY9s=w;(`4ם?huJ{v,!5. J%0Q RK[I qZmE=)n/QPE^0)IDYL<ʄ3nKvwyrΆ!oO:6g;i҃ C<[@2RB(r#ec1ܤ^6񲽋eJ}s ~gXSA-.~af^:",d9X)G餆veWo} cيEm V,\u*6Pz@Gfq쪦Py 4rwy[$^B,jEJc4XX n apͷτ?4Hu.50lG:yF!VO`h\Ţ ۮd"GS`w3>: d\z3zIxh$ʅpޟ熺G!]=xY 79.垺OĠ>&L#rMftƃil|LBϖ/f_Pj4_Ȭ92a-!pf@]W rI{gW+-!㮟aM[;V:NZf-k;mR9f9/B"t+ AVm˥(hEWD+zPpAGi5-tzB@ ypw(WtRo5bcC6rnGj5?+ikbaI! pȶק (]sDzSe$6Y A f`W$vqîtxaĄe3Xgh;͇[o% ג ɝĚݜ,x֙ΦHq.75 -爨*n&SG,tƄƭĕ=z >,1 K; A4/AVk'k< h cBuKCZЊYYBLҠI$/pzYHNg<Ǔ_ϰUi/%pg)2x+Gy 1?YO ,*2B3Sdiw N>84!v#3I崰-)&O|-+ ߟP;J1)H*V:{g G d{}!9@;׌j}W@Pz/O_a#)e -CP ~ʳD}@]r2[T$Y_ͪ*V1 ~yTOik?g B^B7F)uz-+UAjXvuT BN2qX,Ҟ%ܤW%Mʹ,ՋlTzl-Ab8'*R5]%2*lUߎ)F:j~I{[f0p`RfidֿeIK$a9ШCLm#^͈4M<^#~ bVTq`"<.?=ω, poC0|:q@4t[k6cc,SCF2|b̂vs+ em-o`)(#؆j,рm}\k3*sz')>-E&.kcd`zӫZmMj>4Q~hOn}8I'&4a&Un橵ƴ[@29P,jkї1`3]kİTx$Ruvh[G (]R͊dn ߧ VΑ?oespQ$ f.ZQz|d2# `ĺ@p %[ M  7;熛T/ko5IµCc }XvY o6y,o_ wŵMZ..0 pVrȷZ' ۆv\kD D@ˢ@M1#K3襑\9_6YrR|hEO$UQcRacJohW=~MyGn$ܰ}Зh&StzsQK4C70܄\'6Փs~'_ǓNڡy>TC> @&‡˄BE*%xfXǃp1;LJphJ&ꎖՎ@V4T V%֭Dy_$}˼fO J6Qg IvX5 I"֪ ta~b` :m\*|f\@sڹt!{ J8]m0NN[s[Ūm.yx (d.Av] ks釭$I.*~ ;Y0ժKW꼣+a%נ 1A[0U% vi˷_"A)}OUa[> ."]F? Vȹ/|]M%aJrf{!WGFaJdg1P-,SD#}X;eО_7rl>x@A)XfIOy60 V:_4ѕLeDf J@1|2}Q`:{'W;~vvȤ;ޱ2X*|Z4 rIʷ/X k>:^ RceepgDlʏ20LT${OC-5q4en5̏prt mQ`I  P5ͭ?$&<PKkw P\ByRb92dVނ̍@4-7h׍V1Ė|#ouYbOA.H/iecͦA`[]<-`!ӞGgZx[f8v9-;>t[ZRJK"uHRQvz;kR_E"iNM&z06i#]tV7޺:G2nJm;~'Z Az)TQ-XcqJ#tf~4tSa9ER=5% k -} Jھ[$sm_Ay㐢 iTbEc$AQ  j`澒n4)!enb 8<,kB6U$QHTYt9}'Ru4EBz4T3487x@ Ϋ,k_6iz*6".rXPqHptJJL $HJDi$ Ü 8"& ddz }0=)uGnlBcJ>}2O?lkqϮJY%~#sv/ǶgT3%,fY `UR6Tl>H.X2ٿoSB6VzQN߲SNaxyVl{Vof;{vqol<;C߳1ESj;3O~$[\4 ?/m1L,0>(XkN@m}-M!81|lˤǹM@쀲! ^E@'\P6Pq# %e8 ؤ;f(_5wCj +<3fR~ UML",$VU nNM01?[✛P@}-n~L9DF'dxc>Julpf|ӭ4{ւD2IPoԌdN,)\a+fnK UCH ݒp Ǜ6ͺg#w{ /Q FA nsY衢 1׹>ǟ{ 0˼ @`O;+x~vK߂-'?(H:dAϔZ`GowTa6IILU =d%5J bcnyFd/U%`*'i3`f )%:vRCj3[D:ូ_CbN7A齪!ZD^[ }9z\ Lj!3 9=S8YOY&*Рy}L9f`VWr%(ccpb`PZF=IV%A~O.q6ٴZ8B"6W8% XlKb21d{-k@$5T# *  Oǃ~sdR;D#urɹ O<ۘRjz N|Sػ훐]9Jd䀫e?0d8*Tz/o >9Rj 3fYBιm.Y& ./LW Y8n-(M@榕;xc͚դWD]Y$Εbyg!Wa,fƹ>O0#:ZZUzm=5D&`XbS*UpBkL ];j9 QOdXm!%l nz8S,z͛8/++I?C3Y"|vdS:!/J G^/{`K-e3'2f*? RZ1'w \]}J-6wrh[r \Cbmoa _xRsF:y(9֕3]<LxhСދH@GO|a*] #eߟ/sF!oi9Wbê"/ 0A<&Mߵ6^ (/M څlҍLqU*4|]zR芹K lNu tDWa\4:;<9EN,gT)|7b&=Sx̩ ^ciNwOI6g[b,,l>OY첰U ec"t/x\_^,~OۇbҩvĔXAŦ 7Ѥ~N=_bҳ8/_kO&I:Ipchx06DkHAim> 3"Tq.guqd&q ;joQ1o@IN$/&0}uT"2.wd%iM<+㢯tE Yu*֓bm/oG8nf*5 (K\P3Y(3'?>74C 3j[;?d92a˵EAy<8{e63ハԻ* w1ncו7~yi/h[wBgP\Xx|||1@z?qbzIyX0X! Āj$(_l2~~= E9Bw}r'CPu7 1-Ԑg_gw^6!l :]5vWsJఖh'.w],RߙhJ!E)ϳkc;r7}x`x'3u^Ĵe~؂I$sD`0[~d47FĘ2GI(dyGBI"VO/VepYр p8|wUB]ǩ`♣My`u CN^]|-x*2l%!X ,w ,Z9OK jD`B"?JւbNAɘ[yݙPRPOpNRO:/wi7:}BIBLzӀ *5 W QؾEyn($ajhNK,%D'|tf`zxMȥIdLڔ\ӬaiļuHBԇ3ÔS޸ cĎH/;>EӴ$3ѩ 1CTЛ'18P.{X㓢W4;cy|! {׷ lD)ш&hJx Vdѫ&"|QO/{gM`zv#k9ֱ%0BI,<LODlL4):w*Wx3Ay[qQ=T*;fo-#qJm2v W/5FD Baa ^‰VJQ yQ=̈́8$,, ,9t9QN~&޼#g2I_<,R e@vǜdvALH@aGC>]=; F!-SAN27 #m0#*I$;L^2.)?ۊ[) ;-=a DϽ< Vs\,Sԉ-@t /kła hHONDxWSlJ5nO;.}_ Ȭ1d_71_9d8G-/C8!Hs{ҔS .DwAv08p/V;W,6(iIoHz/՞`@!k;5%t;V`I ZG%ZgؐF6~ jt5 0HꬨGmvF !PsTVgRe߾^ ${uf(-[[-'c05RELuGrUU۔zJ#q|ĶU/fVS vaUhV<86#EWj>[ ]0mMRƼ WE&GUʔ>E0l!*\ Ӿ$Lu?LLH K?*8DUb[Jג7YdM'c >9?+%TGVLE1F`", Rǣ,gE 97 J`0nHKG#{̹CJ }妙JQz z6ih̄nCV0q<p 0kOwyKE-<w5qM51I>ңa,0kd{8B& w,\~ r+ Wwy" zwR|?Ӄmtg5(F{*PfIRlA>Es~"ซ,MilV m{}QfcXͦiS[ZHvVn6pM\쫘釔@^= yvN|@6]Dd٘O~[Q)V\J+uD]b:lu~cu&m9k܍n)@߇.Q9}/%Z>$YgV㦠3:e!ΡqysY"LPzA$x9/bm/+Ԍ>=;Ft]R='N8?5拽p j-@[3bo0ӟ>K!BvZ7U VY"G6ZMyޡmɓ0+"qqI,{Mso"׸ Ț1e@w<HQ f֕jQݻ>2WЇ.)k1m'NFA^# 3;fwCrY/OW!\*Uă?dSB4ȇ,xjM(2 w\+e+3JNtՂѻ gd#b?N0c+V9hr'biIuBz Pgb]\#N_jv7/=Fm2MOf˦9ƚ3fR󍐐jUV}ZIBL~o4i|$?cKe*J1oZV`"=Ȕ3ٵFkDHSݏƬ0+:E.NeX PdBSHO>m},u{bՑj 6A!6^\ GEtލJpȢ2! PEnހ禑;-IzHzL;]?N`Nɖs6>2SƬLn-%cː)rlg٘]n(cȧW^@ĆL}1C;'ƹ7.lG9WL2LBl7WEnbB@UEywb801Ƶhk#W`V=HBa '+V3ҙsL˖m^g7qD )K1gkCQ~6TiKkfm\Xivj2Z]ƏW_A~C"`?6 KVWk&IK50ˁQ6-wS<\= ;EYr/⮜!|s&4T[ԩNTo;P4kW߄eY +xAm~+Z Sg-՜\ ܾz@zN,F x_sR;NяL*6akBD g\"d byI# J>K \ aQHŸ@GkuPo̻BO3&nx6++9O|Ь1Ӆ!0= X˖t~ R^sOigi=3HZN%V`#%m4t}gC?gQ(i2L39Def˥nLɗ&Dc3Y/MΆ`m5F`ڙ2sՓԼh ,n({RAV^VsSJ*I _5PSD.8z9 9`XF&uyuc~0F]SMU)~ڕ 2;E/.%9ږQ@9zZ3Q]䖡s5 v ?cdy xk Yt XE!kcҡhI2o"K:kUS!DN*M.+vp_]2 /C3hwQ@A`M" 6_0OW?)RtANIʰ_Z[{#E<Sk3 YE`NϚ4Hg w‰d_-_+GP=3{+BYjFƀNk%qwqSKCyu>o'Il8 -VEʩ<[a3,. *m: ~JUIg t:WHb9'gqJĆe6õA_ő-'ڻ<@-ao \-s'mQs#pC!^s &bp|By9ز!S09#xu@G$VBCxaFZ=΄^@-.n}b`?EGSFeAI$00CZ]nǘD$%0dsoAs^\T\J& E;4?[RQ_X$ܪ` {X-ZD1n(0 C|d$:Wxh-:~`V>&2.0 =)91ݬ| + E`݁7UM2 CL]>{hbr*1rt,Fe?>ajIuSE/Cȡ0< s|8ri}aܯ  _jӺ^VW8rhE##vi GTQ829}5,_Zo!NY=}:g5ps,+XQU"57bw }hPoT2nΞ>O sMp@,lHPJM} 6Cw=I$XS:TY56eY  ͣV\PmѸ:O>ٷ?]/ډGD&bw5Υf4:ɫ&u(H<@{ϙ#պT87 ڔ`$p BGJ5@?1ƿM;xber`rX1ppͥv(KMbyP0Vށl*[+ edgyZEm aZ?ijʿoľ+gBY(Qg;q&vCV[$G&45 /p.?6ZDz9zɢDq8r:K/dgaA#ɟH# tx~.fW[tGIӞpQgXf|n ݥGx^t4+duA.8ݎ{^0^ 1l l! *,(t~&d뼋 KD7S-` S9%wm7 kX@eds8X^9| ]B0s Puyꜵ?tD3( *yD·9mj`8 7زA؍s]FFg\G^I VƉ+a̢{LOFu׸+WL:xā^Bhܦ%HN "h^2M?Aejt"3#*^)YRF W𕔾PӋ ܹ5SiqרG<' &s nYEH|5̑kB2Y v#/?жiCgyZAzQ<Xs{T5ԧe4+(i\%9tܣ/9۰<@TrM-%\y:O ]t%bp+qt㠋ڢH|&b( ă4I2s(zS*Qxl?gwg@\=YtWhr{;;[QLϕ2qVlnKˡm"_R@d>6DQHJ yx O,-<58NT(,}e֪oR-ZBR Gf;)a3i¥=Ҥg)Q>3˯(dԬKZyo"k)qxZ*0ҀbMMVV75`v/.4E7\z%oG48~=58}v+q[}.Y M{mA-$s(xxՈ"7pONlKT^l@19@6!+}]qӣB+N;f:  AmU1 `mT| E_?-5M4sc蠤Ҁ%jzyHYvwTyJۑ58Ԣ?[Ys3Cg5 QP׫|Bu9 mL,ݐʐknr JSѡļ ?yp 9]ŭ _?l.DJ MS|8O9s2+ ?u;)k~ #1CuRR3&>n{"Jث+_gٖ>1a #L2 rqB"!iۢ 3bD$Yv0U38C!\. C{f\/3?މ$#xAvh;zɧ6N) ]rٟAVQBfeP3 }5Ay9UNp584sB(/ .=x}{䨧Ex)2=_Q]SjhJl\;(vi'1mApNNB-y jy96fausHC^G:i+܃jYlx5! hk*'rH}p|ksXf@^@oZkQjb\ki0QR.+ A \ಳ &{sX)Y1H{$7;_`թq=E±UMVqvu~.~GE[9*nԯR*QnkЏ_kTqh2wQj/դc;YwFeV$1A)iBB!gzHY^4f8)c;Sa7 =n_SʖR*tY*SQ:E:JC\g4>E;yk;Z{`麠P WM`FG#vҌ@~:v!cdlgK܂;9߬C? ?7~uZ/@|AD vXڼkx}:Jnw-nrU n#L&٦ҢINO~xSPk(J$Eh)'p4a/=,=>~!vE3q,?J?0[@zav|֟T7ۙB 7>c g2H[.Uf$7n}2r( v~/ ՋrWk3/ɈIj^I|'^ X W (p"5ir#qpm5N05iTW432TU>NYSLSQl SJ 8eXɧΫr6~Kn8 t꫑/ACIO _Fp5?օ0b2ӸBc&o4ME8qtbZXG -_4Jb9)o-"~֣*RؽBR]3Ź^PMā!Ufn a򫪨M~tHr[K3ǼT'בT(U7lSbs>6q|2B{3't%-]ltONϞhrP8J~%lt*VB{ }KbGmhRglWj (n]e./!M$# s _-Ψ8$yë[VSoF^?F%#PτX FxeRP>dq'3Iם_>Iib) Ą6%VCu7Th6%)Criyua]|YC#vj{dg`x ?=ZujlW,[:ESpAGq恑NOHr #ʞD͏Mc_6ei yǽu[<3GA.d02; <ndfKdp?$o4u?rג}"1^<9GP z%|MGrw:e`9 &9:m1bӐՖQIĔJ@% UV`1߭Or5;Di|9 Do Y'ƥѱ{Yg`4FO]S`-X(L.&-7Yҟd6U\v?} Yİ?$g~pl(5Ѧ<7fgXR8""Tp?)s>"[&|g[?BfZOMS:y^O2_柜i2*וQE!J~n9]E J%۽R;e_kh윛|';n1]q{!ZOa\+u;ss_%*TJ;8DqDaGYq86a TX*"kΥFB (,uJm`.e;~tQ^7`rn ̝3~f⹮Ic?.sAtZm?ocB `ˮؙa*6-URq#CiG KrFexe :ͷyhǕK0/h,Abu_aQH1U]cEwD_1oT72_aӥEݙ?&z8#aN9'` 'zNg[<`pη_`m?yV4Ec}^Փᆱ`#ׄBF\.eL9@ ~#p0 A5 *vQ[.l%mpdߗ'jaVz3ijoFOI,N jSi[j8CB)^ce !˟îp^& C"^‘y(yIV:{^_Mt~8?39q^tE2Hvn^ÿ+Ʈ*[AMRD?y(9lM˕좯2bO/ml; ),j _X5jbO&^\W@Zєf<(GfXh,̪8Q8 䠥fC(xk䊛Q:P/nەw&VN] 峣jwq" 2oJT*+gOpf vOr-PeYsp.<.Jx(PɊ;yc2U9KOi{݄kKӓgU|hI Fz#u#{ 7RJz='L\\Aʉvq5ņ~ $pIu^37 g 9H8GN$εkHN]H*ElM!??JJI.*/8Q>k`9 _zAݘOV*RCkNncO?78'Eؽ.:A*zsiG6aڙ6?T $OQ [)F?=lgLg*Λߚ7K@8`Ys Y 놰o\46 P5^us-]{; 1ߊB'Pļ=tW\hJAOUFMe]JײͶ"fY%evlodSt_ N\MTu ٩%Si;ںˀ=Up8%KD 0Ka|zMDL[:WaATgw qbZO7 ^{H/4rJp@5Z.@O 57ꖍp2.*B.\z`{z}%5NpZ9XRDw@S|dX Lo*`B<E!:BU\Ԭ@K)+|Pɓ-J[I=\BM.:M"zϕVx[j5إ"C1X˼ؾfX{X}3fV[fvWca q8,x(IOm!IҚ}?Í'f s*v~;iSwHGn=;~heD㭬1Xolb*hY+JP~-ЈPTy+R}p $WWj Xـ9ZqLꎺPvd"8ѯ5]ֻnͼ@k0yt7`PswS\[ttHL,!Q!.w/[:wC&JrLU%Ѿʀ^* 5A+:`hH|2;I'QX^P>-Uz hhA#Lz˵E411?q+~c[|Xp"Yͨ/fOn/J*4>03u{$+qs٣rT* "a0D#w&+E>Pceq셬խD+<8Pd(ܔDmې/&Q@V3`u{y~Oc geC5<@uq#W^afbAC|@KU]<.+^hiSiBszґ&Kh0!AǯA H{["TIhV. ՂcNƤ4K87*/#7rZjjl:;F09uTTsBlIEp p !> "eTfn\:P+(j"Xo1Nހo#nAW(U <ĘGR8R _IR!u QyuhwU Eݻ bc648xO /"ȯ_K"ZaI;hl-G)U3E7FOjdK,AddeVz RX5=ur劌CE5ӭYZ"Ը I}69DX&EkvR}[.LZMAoF[].F +9?yۑ#@#jRG;8PSkt(7/@,UK'jV^^"tJfIxݓ S<,N:c@[_[PP3HD2G-c`wK]ew-2xj :06cpHݘ|` ppm|f{R;7*3[!ıBd-.iu?nՎ}qwQ,̖`#ᱴǶ"ȆQ5lgRYyD!?T[dFD{lA\ 'D9m PB]wbb:,&m˜2fUC֞΃"A N6ZQ  &GЋoOUrE2ٲKO?4$XK}ATM _}7rv}i6xjnWc!|4 pg]aKֱMi0h#Pn^Ϊ/ǚ*rSJ KT0F(>Ϣh{{_S@!" AД6 P9 z]s~H#A;D'KS N'!c`J-Hhm&PSȒ4+8`B Y0L4lʪhǜ s+U=byvЍ% HE7M(!4_, W5;&~MCM:D٦NƋZYF;-lDoi'Ǡ7PӋR#OB"5mM7PTM3#!w $^@, NU@e]6[Bϒ2ظ7NuH_ UoCYb+'a/R`03o fpJ-"#LyrVlM?AkuG~{hƼ0:Y^8j[}0q-lҲhpC~P'wt}cTMn9ʷ$S_S0U< +Vh>Qr!A^7GT2@0ʕw13w1䫗q[e~}J#IM2)ʎ2sptUC̖xlTWtН>xb>o4mE\:Esʀ!Kp$9/~y# [xL4 ohXf~Jt `JL'EtKIWG(aN+ȪY@XVqniI7,j!InɿP$dԛ@q:jK/ZFb^SwH2l a{!;ſy w!]?r٧!'u86|t@Aڂ H]Պht](X"4䙧"^8j!Ok^/_nqO&6xOGF }_{u N9T`a M ا /B1dt[*GdDe uE'6X)pS ޛ3>*ZbZa܀WnG%XU5ꢗpWz#l_^<hCC^0iZ`dwq?lؐyу_Т١ _1h O=GI?QtL4ݥB]R ݌치.l^Ɍ+aÏlykDׇ!fR-3dG*Z30hOcntsu"O?\ x8#0}^>`y:n,7@o '08Ōf.BWaE7#EqDZӱbu?彀lF#s"Ied[`[.-5Pr$&p)@бCi'X(D{me i,@NuZwwM^ModoƑiɏ.E; >#M-BbWJC|[*ͨ˾ȡ)7 gv@k>9XyLJZABSwqb:7 x[a0W32AUc}mo|3Wn}n1E}|)c֩lʸejӗH“9-i&\OvaW"aG#.&22͆{\&Ked*eMK#su1JgְB4nC5"Ʊk +.\^qx gAIS,v|bdw[܁[JN 7o۽bHJrJJ`"[yӪzLN']@ H'N|K 2?,#S*ѴJkPg{Ҍ0hզǶ֋]v` 0 [L54 OPVKr@ 01Td/i)r`,Wy`>bڪniaOᭃ#P?)h#gi4Nl2ы6<1ۯ&m_)ܮ+K< kΓ^,GQ.3ʢ'7(&\х; )xBJ}=$BȘW_,TG3>f\«±@\da7EwDpNG;;B~ABNZ[%qK]~ '()g)bk6|d(jЉܶ3D~/3ɺt8edO8;nf̈́aUDpKiWX ivJ#8U'U0״Ws 9!;YZΪY]AGa Ht 7@j Kd=ŕ' ǚYj!HB%ץC!ےP}?[ #OE^.b&c|P4؊{Ǭ59wr깘yQlS ֦@r5hqR@ 0OLX@9i+SR&jV,yu?EfT(cSA^RSGU6eh3)o{~uQڎE2_Tki {c'&Ex.!Y(|'(4Qڶ3-BM@Y0:bZ0A3L[.CS7y0O'l8Yp[@GI7oUuzcIE >#J)\/j1 $S  VL$l50 \$ED:,: }^0YDZ=+ 9 Z$ގjn9N {C i_!(6&yvA~ B\r_šz3)5r趖cFPqbu@Mwwtϧ;x^ƅcC^P׼%ZY0xdO=,a`}~S2'U)i74j+ڴO!R!ZwWXxN1eQU s?IсPB.P|(M%I|AHrN2Wg EGԕ?n .ku+7lR.Nn'x*3/?ևd4'Are|av"U{>]78YmIJ̲x'DSOAĀllp.NLjՃTfR'%㪖f܃0|^J: hzqk$WiGt5JS@%M@Cqpl :/SĶxWq= U2!D@Mn=o?67ՙ j8OE= ,"RLWz ;|C*kREL#۸5t{aYULƛ [X{ ,&?Hav>ͣ߳7MU3i4<+kؘ&'6Y&@l;^߄y%G^Y͢JswᡕE8y޾ш\l?0F=VryTavTynCq!m#F04(O*6#&sjdn-sf[c~F 2x-vC@6=*"u 0X3Z$,/uU3~δB?ZrY{K NpH2 /w:˫6#%YvV@bFb1}?X)C+@Ax\]J7.Ɇ|:8R75/zàI( Sќ@-h >;V8g&bj?ɖ Y>N=EhF)ѷXYXW.SgsҀfܸꍮb %]TU"s.R̠v'#Phh|FHJ >Rg ɡ6-2cB'YPf@e> @nľ۴|8$9ԇWP6eb.%t] z;IC!{Ʋʃ|@~3{2E8#.YF+"٦krxSh§R F|wU^ ݶgCmbˀtv9"= -$0Ɔ:lTk)yP <iF$ pMEvl84 N<.sȨSXu^uHov\WbR ~+Xy3 w ~TFZ FqN9nZ&B;YKq ͜(9g%'\I\_a` mϔɝO:lE1V\C/B;j.gQDTHrQ+3(wxZE6 !r?sjA^k%HZVtÈw}x>Hw;VܭZ։ 5-jfT$ia-o8%o5: 'OaSJћ'ٔe9]?n֙k5}bOAH/|Iz%p0%x0;:43#ԪN6>qu% fH*\U&]8T'c!"ћeX;eX}٭g˛\j%*>S8h\S-(.B&YUPY] m?k~V{}y>onǔ?עmcye9K$&2*$V 8"hcX?Á"3^X51?7p7A&!>~qʟ(M yu (C٫XW4Zo'3 Y'o)^} n><bmY%tb74pa0fe|{{/flWS@px>M: _Zo3ŶIޘ?qkcjw2k;( >m%I&Ϡ{pn_nc77𻕼 W{vrsJ9g_qˆ2YP2*3(oԎ'y[OT$?Эlzr.:ߓ&f,8VksB uyܜޓ*HaO_St4u |HCt-i3_q!hHܙ9e7T֝ Mߧ.AWl֟֓H[,f,xm(xmhY, z;O.;qr'2\e}U!Bܭ,o]0OH C{ ;gRE ZMxe$;]ā׳r]ƭVLUkO3hTr OM$?ӱTBCT~bH|.afkYyI0r8PLDqbDG#}Ҟ"*k ![(Q D8Y?+ Y0YCH TUA<7wb@ }}LWUݐbd!韥?y,r@m8:×Ŭֆu.>cW܊p)s)DGv֤v Z[=lֿ{{n3g>,+\Fcސ ~71zAoU2YCMU{$m8#~-ŽtKx i\9zU|Jxz;MIKmc8~^Xe.#hmu\~&u֨jleQR@t}"sHrd^M["FEFWV_;@+bΒGQu.q2PhQ~M9>_oxܙvJh"u}3E緙jd@m&-UR ]E7UM \|S@}R} k׺oq빐=0!HIÊ as!ߐxl9Z"$,PP\0FB|ҧخDNp BhVp 3*0*tD@[4HPvF]"W92>2>%똩/OIg`[Ra:3M`nvyb0nr牞Yɥg{ ]8/0B^OI4%|Iq_LP(D]aYT? 95.4|K*_,y9 !>$ԵM9UqI:;iR޻Hng0J1_`{Vo;q@qv)j[PqGA{)1&}f%)8"UGp'g哶w_G`~K2*ٺ?df0hX0Oo T\BD#׻,tʔD`U{y;0 'cu j 2|JaD36C-#>6H?|)z#8!vwe_뚮ɞ!عUhf[5"T~0} VLrɎ_}%AgI6l=FE]򌣇4BĘof"Z"htsB@lHy(bsq b+}D1jSB4m4ُvP ؟հ;Y R6ei3qTAݑ :JNZY7H<z-JjB@8tx[+Yer Q4^,|S7?l~Hv:z eiD"Fu>y0-Zkxq0 +=|$$E׿~c4Z_2A~ |H2Fzù94wSL<ҧ47ܵaB^5_afƕhƦCq"?.#D8BZXg Wn`1=R/R'¡nϧ}M6ĆSiRf/)'=VxrRPJ#bv)nQ |'DЂCr1OC#[I#X]bi@ RJBbv& >5W%lc5GhylT }|JP7+.1:: Ҍoj)x`72E\# f>dY^7IdQcّf>y*򲩎\nu`9*ŎBIͯ3q$4ސYw,[^=}zF` %b:UKJ2>W*^2`?C<?:u5 .!M=rVzIU-7bǓz9u xr${) Ԁ$ɣܻ df~ww@e/qcĥvԽ^\gT|wO$?f!ԋ˜f2[`u̟n3F\gM2* WofTeWd웰SMn)a|/@8M2) dim k7htN*^ol/FI\Fl0 %~+A j0#XO :Mg!Ja}ݒ8S)$2A!?c[uaF3\F5)o|˰F,_q=R\{$u$?FjOX{]"1ڑWk&W}7*OHO9h~a#RT>u/?]ALnڳd{KӸ[Bl۫V!1Nrac bǖ8)TS[6 8|3,sBtcʨ{qi%u&Y O9yjٮ&:biȯ,a':R:.s 8hC +D?4euU]'cb(5tEU,C3`pA*A6cPMy@k6k \؆#EܬhSXӂ0"Lc|@[yjȕ|s2A~?-̣Y2^3r ~; 2SEANcEof"|})޳̃0 k.sxS %d=PPX6 ~ z* !W׉f q_.qĠG$tXT=)jm ) u䈰j‡HV%Oan!yo8N5$>5'7f#mz[Nk<'[$x0CNWAaShM s|B$iي"9ק?Mu9qЗ XrKh4xDkgx?M<L j q<)]{ >Q)[؃Q)hRkVkF%͐ CWd0WJxsJSt&N 6>آvzLD&Z>'/mO1~zGxyqcKpd;f _uB<&dӖbR{tY?MF8* EM{b@Kd|8K0{'b_޵"({Z,.ύ3*p%,kFbWYHR`IQ`2zou{7&z5uFxJ:NR+s{`=.\%J &a-_| [l+*fu{>^^%s l2>Ҡ j3*V%aYD{vi,lvIrRH 3ONgL!ھU\R F*6.Sr`IƞACĶ\MK!nc{ l.eYL#A<jen 7ng4A\"_߭, vۺ6nd5tSw.=.1d:d {6 y}=YJ5 =^]jt&"=u/ O4erO}hN)= [͗$) e} ,̯ ?z'CR oJ@; Ԃ@LKE]oPvPRB*/`zAb]6e f̨w%=*^`-VGyDb/Ѥ?֩Ȍ~\p0Δ/!ߵEŲs-8#}f>Rw!˹ob'WulE#9- #7~Ac9 |(*UyF `A 9ֺr;߄Dnss!J}{N[nM2 S ;\ z4&pc}]4ӥĈZ,3+J*y,G@3 ~DȂsgi[E&9dzBDZ-Ft 2ڸK-JЗe3^չ-YIWK@ $n;hT ?`;:c\Rz G#Sjl{`UY7t2뾒%4G&;/~w ܁$Ps׊;G6@[tI.h3Y6X&cZXc#tHk[¦kd=]ǕK)(_ꆆQ_2VOBrOIiPDݗAR" i(Sߍ/ᄋv"qiOzzdI:rQ ŅwjN!9&s:AK%T2S^1z)UTmxiΤ赾r-lo+Ãrd)rILlqL7tŞ/C'K˶ZAaAKRT,AqB,D~5>/OWpG2UG)]2Q 7;::oxNoM7yQ"N#N61+SΧ催VK,RD` LxU=1$_W$wJV29quN~ocw৯ .>?6sk:´Dl +TO9lBY0G֑"URFT;E@/Fz]VlLs:^8 >8:^i/J]>% t0l~xI% A+ʋ8bUINF]Dcwвk:&5Tal_3oImmRJAUK$-KM]5 /\@bzR?V1IoS$5a' ]_X/FO W}oK=c}e-I LORbA&'L,.7(}r%ro3*oFTb##`0\%% #>xFM2s+ aU1Zc<ɞ:c=##w@lv)<>W%>ȪN{eXhf6 P0}ZаaI^o_;%>UKlS:@q;/lѹ@:}A(?}WK{UlZ}"XBl1V-2Ɲݨ>ңLPV=*c'zx{U~t͛U]T9/M aHԠd.6}~pxRAT̟-ctG">xQ{,!~a`PG#nD`8hu1}H 6 Vj{8nS4srn]*Rg*Y4]V~D={a@yd["l q|>%6 6oJ*8#;dn?l HAa!7*F`p(\UgN \رQ dYs35̹8X¯z.Ø'K+}U+x"}u]K(W]H^ 2Up\ۢ47f0ጥឍSC(΅GNq+G1RT8VUb$΍hMǟECsfr)s@}IKo`]뎠&R›vUb@6ҳҠ1=cF&OGHr&{اB44,,F)M5|ݐJTv3ӆa8VWXw$< ű3N$vY_q>N+"yrB#OE%o1):,dHVԃ ͠eYʴ*Tg"N\q>c+Vmܼ !"!"hv੆$(u%G;`څ1E_!hP1E+,'èo+ PލD~p-ADY|;?1 Gf7ރQM7|Q[!aQ%2qXV.Dx6$@@yd p+vg FG>=x,%f^r9z-fzH¯}a֓]pELI!.]k^,*Bdt{%=QKRn|_BpY7Cv6G%}J fBo/oVtoNaebdRh MS^W:ޯ'coXLndg%~Ʈ u]KoȃNlxK#͌fʟE'A5TB@|p<8rVW^Ǖ[e4Τi,մ+:dvrcmfW1?6w*} 8rzHNj9m,"o}>"p~K?94YrQ24w-;`(z]qIf`bBS.^>ExÛA)=c\ڷNuR`c.? |:bvdGoW{U =_ #5a6Ԭ,N;l:¼‚+!~vfa1taTI%nPa/*<D+t3K0Lb\D0㡅a7\uZqGLR);Jx?TO@d}uAX% ~;ʦZm٢au[.u6=ۛK>Z{3$ ;U*2~w~}= [+w9X[,=`**?e /{ lS dG!u;爚cܨR 05֧dCpO7`9rј ޅ4كfAzcOK|@p2rG$LK1Y<5 C [oTgJ%_Bo3OC\I^$u{Oh^ ֗Ğy"Y\wQѸ4O.NK؍6_ФFv2 %v}JgPHN"Ic&g:%h\{(יB}]JST-Cr.ܥyXk[zH9_"m~g +jB_{-+9K@rv+ر~ Spza}.e+c'D!;z߫&BXpf:e"8`ÚD 1(.IZH2 CRr @?FCiLBF&  otхhL8"nʈ4}*tTϿ1 ֡)d񎒂Ɣ'-nHhq7Tb+|^Jo(VxuWt2 J(u$)<[;wrSk(_$ƜB1M;P,J6V-);U$Y3N|YPA_2DnM@|~u)\gG%>H]~UA;b $:,JC:MfGy;k'ۦ*Ɵ'-}DR#lY\[N ^w# a؏SawdǑq0=IERF偤N&K>yS8SkC08ίns?'V1uIcyT6Y[M\jFR60?~Z>K9AKs}=);seWVa n"1ԠkЌՊ_/E䓃,&ZFf^4 + ;;'<1Vs׼"%4qD0 UY'}G 7@ǫ-Eζa^*GVQ@DLCP Z2f9 m ȱpBjc@Ɯvu<}4H`ݷN 7a f:,>V4"! 7DɰrlN8;Q#[^0OD)joi*LQom[V]!ߑoͲVX%L]T)LBPU2&eڢZ`/9Kɨv6~4KU*95J}xK0ZuM'(xoh6$(Le?&HbuŇٜ Z&*a$wt|NЃݨvvCa԰^)\$$8shzBBB~W N^q!=Gԁ>+3Gj V&X2{Qt `t1ds@]ź n0w7&[W:dʡz~x|6,̉)K1;+TigT XSnHj0[w@v&h4*AugcA`TȓvY H| 9{ Jb]o4቗UL0F򎤌 NM!U9' hv2eYV:Ա^-Ԇ{ bB$$W2⼼PFN}()nUdCME͗IGlt>r8Mzw,s),pU>Mp+3tPtޟ74<Ҫʨe mDz{ 3~Wby`PSILHf{>Px>eLIJ1 ?EFewXG8ݖtqW^NncT(zb:|/*L iAf3ݮy"89P3uKv^z" c,94ɨgR"(1mOcWۘ,S/m~K7u,׃-crbM $' kW!~HO^yDH^OLI$01@mM~ưG>r6!crVv _ >DQ2^cF*üjt̃WSϏf3Au< $ʵX((4${jn!} Ѳ7f3" %j^DKڎ+*Ģ.!}VV`cY$Iɾk1A#X 7eUiDX-uň @F*hFY֣}H;Vi)#Ah.>.X;Gyg1qŒ?G|:݀߾zn%Xb8YY}>Nf)hw$ l뭰v3ijxE9^ha į2;c>s9*HO|v1iecΎg,p6=A#GWHH<бma-WiS;YFcs SwI=HFݾ}4BdҢ&uR/ ];HЀ35 ԭL<ПX+jӄ~Fկ{a|qsnppm2'Gb|-9Ю88{hZs|Ԧӝ7&\4#Op^Qdd_y4R8g\5sTIG^(*(VRPJnMo-XmjPIƫds}Hqu]?R3zr\$rOi6ÜǀLnB'=Vś[$$g*@}0E4ZjrzyQoV0Aa)Ia ]]Z1q&6HBGWѫO/.uRr{St _Ohһl*IهMJpUŠ \= K*9@/RJ8۳͟WH#cx,85|Dp>R3,QPss?Z7NS"~ǟP^WHzU )Z:\E+6kvý"b(UHi:$dgBʕͽ|_5FoKtcA?M7o-"Hߙg~"IPKRl1n.P"U4>SM9k+εQT"2ZJaKoSNkHB*wYRGV@HܻE0LmAgCpO磐e8/Mc \N\EJX d^Hu%-NӾcZk FzzuJR>*LZȰO;K0RB?qAM,1&kv!sb?BmsPYf:ȶfw˗9J84dE geWZ@P[SGlVtNxvXkCEa9: 4D&24 O._M΍ / vܜ2!o%t4rI-^Dr懕+sҞ}ld7o$h7bY,ٲX 1BfizPUSn qO' εh)ewRAj^uYR0X2wOWۄߣY?bs1rѢBKi8 Y6Vw۩+)v(`)bJPsNb,I9f2iZɑuXt#yWӗ }TU=t*u:?tS8Z }|qq3DmZO/&‡_^B97M%KfZK$1Jdlmf,T{jЋ~x(ᅢZ*2F@,T6zO =tGђ?䮣T+{}+"v3H T% }U*:\>?M! ;b&c I nF"ekHNZ$"0?qҧ˜vsϳ'i! /ɓ^' (Sh66$[IuR鬵dTAe̯g@T.׺z>vmkԢ3- 2ש=_E P@ly"Npi>wppz\?rbgTW0T5?[Ϸ[K? T j\ }Rq|j0H.Iaah>%"dCM5dOu3`MML\$,m\V/8o!L[&j]@F,*xscOst~G 6?1>8ht;0s!A@F ^dZ~a*L ń$r|y3/[%QJdRCҝ(͎=xYU.EA e„sr_P6EK2R2^ElΒWy:~}R9;Kt?(gGIsEו_2 h!fKK:+v0M5d WH&:xLjs^^*>l18b6|5r];Q^wV{Dh<:htD# o<$9Y34JHrC{wedEYh(3?Vn`Am;•Nqh'ewRѹ#DŽlG Gɨ'sD[uUmآ'آ( .z쵗&-?|T3TߩHHNXhZ({\҈S ڨ}X `1 /-M2pJ_pMդ#t=O!ASEPwKz O_ÜIH.YՌ9k6f"XyH'{nr ĊYϐ~aG[r ]̔Sڼ47DM0":b=^66Vty~r6f}1.3;u=(R`7wǙF&ʼnRƘ~FYߏr/皊 r(73뇈t?}{9("ũ~41+8\@4pc"H2_RdWɭ *K%@؜V94yv*lsHan|tbTdN2`9YsЫ*/ԶA|"8{5"m5k^{f9%tpSy9d08\0ک[.9rӪy[fî?` #;(U]ʊMκ}N1k1[@WAntm'}e,3 W =uW0i5ܳBX!VǍ+ˬFdNzΛ;ŭ |Ty&tPCj'^C$+bwF"1yaiqV~Mvб[[1nm =k JΟv^d,N/``rNjXިE`D;,ʇ@k.#wc;7z6Xj9M r,`\Dl 9x A}M,ZGD!7ߌ񵽪kBK'WQ_1v{0iѼ\CZeM~ce XV޷_^v:Y}W8nqÍ\ezUKr.Կ~T7ܪ'$nb1dՠk͎6qNE jFi{4%'80ֵ `A>\Zѝq?S:xj?  ԣ *lR`-紧%vkeԃaz땉(Xu01 tQtqa]q%3B,zZ Zot] Ԕ@zMsL5RX#Ú:W_K%aYt#-Xe"I8yg6:`cRplEÜtw*{`icwϝd#1ҮVe97Ua0ʻIcJ.v?;w|(gf%: MuK8 eP iYBZ ߋtN(Qˑ᱕R vew٧ޭL=wiGDɥ/yKdWK%b?C%bء4RuʃadS=׎} HO Hzk䱋\VWRt=)moLյ:U/o!JBzShb k&WNPZk'ys(pZ˳ՐEc~>"Zῤ2o$θVext }e^R5c /Sٰ* ,`7H~ޤ_tU$ԓu{M4m=["~N\Q}B1VW !Je 3Au&E[/w -KT5^R>^6x9 D:mXc [7H0-dŒ? c.<9}(v}h1 xk)ހ:'v7Wa׫&uCz<3qca^h:YeJgxi+j6_1lGH%^ޞ-a]Q@CKH aާeBRP<R@D1зƺr }IyT> ,c=v@'AXl{dw yB>\zO9Jfy`J-za91K'gT{AޣG*umd%:fL_]]HX]-94PoH?ŌG[us)ˠxy`ҜKgfm[l֜~F$>Wlb昆rGpKXbXXih"vlRUKm-"ϔ S҇{/kOg 늤^gҠrmJUs%6_uzC-9 V9B/b͛zG_noeKA. &<*ɕ #ß/l1g}e[4Us: H`G iMAhXvߐ$8{褑 2MA<RޏF"Za T+ڑw9qn/Kb\AIDhV{Y0u+(QVRov&T8V<`FىQ0T8Gu@4SAI >UN`i]iQ>"r3*J;H71[20]hLՕWAq) 1.T@81ɿXT+&GMep*V|+J#p^H|O|@9 g.bj)f8Ɠ^6w}M!%q; l}ّ+[9x< l~n֙|-e;&}*J;WjIm'lU=]n|xVDža -ͽTT0X*ƍZ"9r|X22T<,Z31= 7R@ L}_ q7ଡ6Z7SJ*=XHѡpò׶T@<W2,v\!@;P]yeB-SlPuB7u5?,*]좘\JP[[Qz1[P89mos8eCU.( )]l C d%gUV5#K d!:6[aFdA1R̄ 0#&kP*72jX~wii+"Dh7,45S>(-W1*l6YkPHZ 3lVɊz/GEۂ9l"G1_,1Xxa">rNALk_>hh ٘%"?2֏+ִXGA]'-Z?(![lx#YP ~0kbR7OC-CWs,B$}Mo5?]9!;R$[Iil? $jۉrvְ:([=Q'38OQ%_׻J:*£ǘS{ m ltj`3*yKvO{7&܋> ::5CÜ,|n3xu^^ZMk'9] Hdʞ0I ;48P1" Z [qgvP/a ׭gS5.)nmBA>?R-ϳ[!ۥf!27i-Gw 8Z/٠V{ޱKȎ[7 ےI=VEN;R ',3wdz֣F|h!\,ap} &D#A} (Wn쥛cPe2~5zӭL j0nN݋|GddRg${-߳Luw- %C">h(Á}`I_+ɐ;|u3BÏ.4`RA>* 5,b 83JR;Ol9_*QP`0S(pXUrǹxuFf|~YiIr+*V^{$oC=QB!WZ^VcSkbX [ާOSMS"Ma@8jżs@J1u]BVVݱe6+D]85UY Rѿq /=~ _HGs>9rR/^<`;bBgHSqo/|Oz '݊ a.Zvc(*ٛ-GW\VE9tv2%.MS {J|"%3IT|MUi{/ɹ v9Kh%<n^}]UpB^G/QF^Mc6Un0!9ߎ΂ kJќ&nă:ڣJt-nz5/KV*K.f *ΓFi)TʚZ( gtdS xdU1\>v A,\b[^f!EO Jxf~k[ǒ/"= s S(+:iqP R#K_ԦR"e ^:š1WI~U{%PrfBMS7>pjTؿpWtgZf^L(뮚$ !Teo" g1k*_\GC%V/zV yŞyYӐZh³|B3w9Lt' eqvK읝dH4˾}b>L]jiZ]dlyIZ=!8(!?lO`b1OC½ŎkxdTLs?y^(nC#FOy=7ش Q~:.ĄkEqӥB__GԄyrRFiJ}HgjP<X`*g<&VĒ1,72]L߄3l@/[hQU6{AVC҉Vrgc\G-"SU^`mK(bD.͟LLxYgHi! s;}|C)(a +lhd-)iT?O9gK͂yο2IKn}ȉ[f׳7N7xV^yY뢮7WHk>=}xRv2?=HgcJEJ|#bg^ٹ5rJC6z`QMU i }g6oOQXE#oc(_/ .횲k>@0W}uካʾ6r8V>s!띁F1m* 0ތ2n,2zL")4l:qt4Cax>\%U|.P~k)HOK-VO? gS[_AR$^nPygYUN &|[ԓWɝy 2h9νLՌnpVi^zkckȵ|:x0ϱ~z|v|/y@&dr^y_y0wqUsTN>L ߙik!V}Gټ-T٭ v~ǒnrv@*'u[Yެ!*+'9?f&.R>gz 0RDȽŒu%HN~ZTJPrPl³%/-t)g: #%o5|5XLNY7C!!rLq4EwƵU}eQ^35;.ϊx E+ͤSEF P{cS?QHۈ5fS7|ͅ& Vr9B>]R|D'ҪJM`5!5rcݖͱG%MRs|>rjR Aeg6*B'G|3G6*'iž@#ns ~ݖ;6!+zM+_HA'CC98Y0qk>6U|j1,C* )RE,j a J *qԚɨZҋghI{^NGq(18MՂ.;0 : df[[Mo( |0+Y> }r_1SĜ+yB{9l󫾻DQ29/J{1.]^1҇~ tR^~p$\ (?k]];6{<ç -LX0Uws?ybܘSPX/siU:) "k*&L3.lF4mZ'Gm{( b2> }w5Zz۹+9AY`7e>8muBK͏K`PpTjFsr,b }K{>сyI۳/I/4.hLȚ&Oͨt+T/ݤ^]r3ǐY-&@[cnShʹ$3l_5$ϳ@"_9 @LT'xlM 1c=ݧ_0)l!L^Yn@*[j3I1kBUxy:4_^(*:W\w jQ&Jp(t:iMY 5e )GՀ1 ~RY=wGH *)>(˗;1(haD" ]5lTRf cwOѱfQf(`Rj%7d\YOs~Ͼ-^ɶ;LJzkۉ8t=Ul`A`Zw K_z/$~"~șa 4g86:˹~ AJT!!X&Evߠ+|C,+E+VpwX=0qJDG;_Bwx)btά dh(Q\mkRIe34Tqm1f52nIB#nM,2T-'̥.뒉C_P$ ?<=\CՈLW$~(&:ƾgte#LMq}`u'Q֭yn:4jyIr .Y 鸤 \UN~%Ϊmt(DeKb<"l#eL,%I- "ߩ1bEKFv=fq}T igx&$(~2-)kIBz.::Ȱh}V.nkU_(2 a,V<4o~||m7m PdGpFǬq6<> %uF-]A*ݩIU}NO(?p宓sEy]z˗;2|-N>FO5AjG3xzo ԙyhŗDu=~ "e}>alJ6ww\&YSؿ_U9#ל[E>[3Fin:G'V?>>^1<@!'b{PFޮ\dT+2FcY"c1`wbB2o\% $2(?̲H["'~6bA81]"EE-E{ ?h*BE|0 w߬r}=h4?۬@؋aɮ,D4: ZS.f,*MzcžP9T!zgi _17x Wᷞzş{sua?Z`miB:paʸ<{ό(Oj+>yW?]^7Oubv=5bMk[5%&XJ/#`n$3QLֻ-k5.EsuNYֻcB8r~7:vc狕cR*` GcR?^u@O2 OR0{3sGierPXƺU>K wn&ܙ#p=? Ds%$D\5Nh p,qaFxDok:Ey d̳Fͧ;2Pj C_]Ox^Z\Ǻ~3TC @IN$$&h\G۲2>?pNРSczvmI7ק<: wl4\Y2f Rr}m>'tBdV7CԆ'n2*raNbJ9AOЧy^p.\?"b#0"}[ɱaC#X68 5 _ >JO?#ՂsvT6LCzxf'z:!0~*+aad* ~gTe09+^5ݲ({Ԋby'?ٙ DAGύ^"O|X]8߮dm+r-$/u#i WF^2!#c_p* jS5t2}raFo8h^чҤt~.M㛍&ʃkVh.4'U%=tT8i $ybD-Cx`? {H/5Kw&qi#oR.^dZc%A+Gn(ZX]A᜜[vޖp#i70AAO`tl':tB&yuf;vhwpC{7#be gq2-7ݐE=#cH7LZ䞏[F*/?e,<(48R S;S8BdL;AіTfhjBP$^vk޳PS:-*%/de{ k!TJhT:*pݶϹU2& p3H_DP%3L t"hَ4cjgb%A-6eB\{Z&6;SiR&9fx?SIc/EiQfr^k0[D\`m5צQ镹G T~X./kX%N=rV5t~EL]qn!4f.voTu3ELD:}` ? ӯ1e)6]ǺrΟ9%DB -W G,DηdedI+s)W9`m+ K'XGw0 z#P>ހVU/ E%&Ug.v/ q !܃PCޫp͏!I@č*\D.-Q$ Y c+qD]d׾e` /T/ )xvʥrDB3SVof%"1{`V-EO%Ο#%5y^̖blF}lu{.NSgfsiQy5i8]={/+ۿ(?ɨM pF y Hh~hR@: [Hv\ ZWn/@s.XǮ^,&[p%mjx4~$xO[GN 4kuTb!Hgi; Ip}pq!dc#QXLIZdn%Q9eH<0'O5"ѕ(XyPbUfcgV49`ŘL;B3?Y84iS+m-@k,S/@F|({rkS@rпSPC'#Xk#;肃ui8f1_:iVj)|AOdal5 Dp<"!SQ'Z|5ygjG7+o4vlt OaAPBlp90q{N]a|,z#u`ljMllO2z<;gLX.13&ʟIq}`9#L0rdWlOL =-[žJ]ljxYctil4rXJ"=MmiEbpkN ~G,t'\`SH.OHvV`7Udwad~_ =tX{f6Q&\<c#!(o|5SrS2NU]Qɾ*k55ށ\1y:#̒^ww4U wc8_'KEoc>Eh+Ϫ0X:yʂPV^wA ]/s% ;Cjb! `NΠ{2Z(=ٙ1c$=K-@?Z_?n,5 F,H_j׿]D`j$侹A_ֿ~!a2^{u2^un>4՛"uy%h0Y0>hɃ g'VhN `!i6So5xrPahArUj_JOK$_;Jpt3AuND9JR{79HȆߘÆB.b;z I s\iOņeC "^H]'ՀqasaW^\6#W&vFZwh ^_Q\p\WTnW-?7?^{et.,q MJ 26p`cXnĄa`{˱qUg`qϪlג/x YipУd%;[';.\6G`]/*:hqJ=N,8cZ!`k$SKCCV@T5XVJ56Ut5o8iFA%>Q#:$YaasU~BE78wCPS'ÄozUt<1R:#lKtkMM/g4 WTGN?0_d'EAQQb-o3:lYҏm@7`V@r⑂,,6 '$!&D8Fb. zh Q$BWP|NuTv+XpxC=Ƨ$ /mJ0%@5xu(lEz;Sh^Фt- =Cf{Ӓj !!ߒns YnFV=c%i!w V Ϋi~ޒcl+SrTZ@:bE30ЃݐWJrTͬ}Rp'Y?'1^7щ,W LE crGttC~6GwjWzOW42uee mO#u:2F/{u'p$]g>h֥Hē-Olvs7ȣF/\)ٰ7` `,7d:PTBܐJU ,p 0v~ zhK1;וx.XV#qZoQ:kfKw?9mBM?] q=Y7ʼ6?JƍLD50;*O/c }^ r?b}Cp"; T m"LP Oԯ-B{~SQlG5BObüG8)sT8!l>g~b?|LP7ubKUcQN[>MsI!v46oL ;]pWg&NG mR p(.Go Wb^l1en:w@D 2,: !hLU:E:Njt%EJ͡=k`w7wsi&aTŬslύ{ pKD;‚w.R)<@ ١6/NCL.;#[K=q_nnAxɉrMlXd2ƍ|6EPR4.scю2xrJ%+Y[n".h>r 6%E۾#2f;ڷH&ڐEFE &PCmxZ0!mzV՛ƑGy=JsSW4Vj]Bzl ڂ }dV 8l ʂYKUhk2zx AWGwNSɹ$/~I;bJ=I"MCt:\2v,G쩀ฟA 򔽊m縯5 ъL%ADk 2M:Myq*yӜE<.X5]6-&2s:^c˱׊w"RXG^;`S9srA7es>rB9ە WA+Tq4YOi`wL;&Nz:tpRxR6|.'Kg1c:Y9wW{MJJྀDapl?R։:/V(;%~Ie$# XNJC"TRךsM#:j(Œ0թO:iI m1"k^ Pw&!hQ#jL6)Wvy} O_2Kkϰ~#Xoyj )H a aQdWvF(&N⛍TZξ3o,6MN66r>GJ!l׳.YL/y1՜;Q.?ݳCz褙%O* $վ;?h:UyW{uU4!"݀5҉  S~S1p|[b&Ek`[1K'%=3=Eqd[΢kRbL{R !FB qs{zcRU(]bzQ|n1~3xW'<{8R42͢lf\g6[ ]vc_jGY'?K5]e`LY^y HagwNsQ9P\BV]M_W$HfKNO$}S,&6zޕ.H#QC/F'lyIuDb b;dś˜j6yi,*jq N a]bHT _s5 nĸp'zzj]o0wNYbZV z-_QXŪpAÑAq8ne49,m}qL>I3|.ef~^蛍:ް"X#g.dp\4X9_n%hv0ۚ9@͋IC}:NVH@"#)PQ\s9lO9}0:HD!PC~ڔFMVeخˆ'6Dp#{Z>n6IiC lz$K X~U}.I&6FDIfto%w2ݥK3}J8rW]7,8e;k"s yA_l̽&:8xjeo '䞘CG'eT*(pU€G@ha׭NLi]{IJqe{Q%Ksh5+M贛񕘥 o Ҷm'l=<@oՄHd\.;s|P_``M9g bF l>փ~#U y1Z u$&ee .g)骰B#}Qaܙ[Kk˨,ҧQc2J 5h M />L*C s"UgjU[ "B3:En+@ -]֐[!8{ճb3Μӯ;ܓJF./@|dzlکP I.zU9);fp੒m/%оȟ&.r!+WYphjB(պFic~_8j=^?QKF38rv5:koQU`8Xah"JP'oq\ËezVv*!k*ct#Ҷ_ILی n5>#BWa SJo|޲}o<뷒eل HeNϑ? zX>ǂ"&4$D26+cR?c0zAi>qћpZJ6n9x>Ȳ,!:ӍulW@ߵ41yTDi`8R-x&2QQW_rGeα|jcn%*`{AA3<+eV6c/ }qlhg3(আOcžb_W+CLzZ Pgڏ h˴tl-i7.2ҸTr_seӯ D *^A5rԖhH+iY(wurV/,Pw#kX΍W/|~V]=&:5@ ؎GsXgx#/냅aԧRCRON xq[[X_ه}h}Tnک;^ZܣȐȎʾH=DN͠5Q+R5ZUe ;]-xF2aJCP~(_r)=/ DW4r_( KXmdHg@&+Lo@ܐCN Vp?Qn8if5DAf XIId0*>j1ݗXX CU< xˮ<G&1cF%· ! b#~g-z5ur 710"5АiE*ahn5̜V$չ&-"Ykiɧ,-Xw]Pʠ!ЋXyAaו^? /KK{/#56)p'] jty ˉJ^A +:t<ߡvJ1#tn>ФўU0d_ tJd!x9~ 6?:zu~MFl^j57PÒ[[T C("l} U}U[;{ɹ0_,Zbt +0%Z*z>ĜOG흩_s}~"3*.gK؄ HL Ҵ(EhpgF"Ȓf$D-q {Y1ToM%R9JNB} ȥz"@{VLoVr ZDDÕKsp@R/FC>VYNwmݥੂx|ؔ>c.Bq!*b)&l%=`u|IW>Ӹ?lJe(yS05-"2^;uFFUlDX-&u»P5h5m.<[YvҘ/2Zv#m@iV T4/5`m1T~扜kaΕ./4jC jO8ש {Ubc pa_M#hc%wH?AVV:18$Br -3VE=Oq'8dd܌E0&g4ָVwWVfJ4Y֞jZLVEpD)A·OY%Ѿ}a<0x_( 0# =ӶF3x5a+:WtVVAâA|H‹9$ r;^ō=Tq8س#˺8zDZ2YaC ivYtAnhK _J"gcԢyOGf$<).+Ci4XxS/]eGEN=|)C.EPgc2lɨ~P}1DzOMXc qt> 5|tA"\tJQ"g_k^ m j~;`kW+:oQvsm"գxe{{;sufFw0^: Use{Fw\Lzqu-"GDׁV¾ zD~b|*T8uy !7|? lY².A%raHBpQMuC'b@ aoWƝ َp_wKeњ#ʃЃ4w.6@)1<7;Q8Xi<`ֹ2BMBUZWLWDAЖB9ۑ C #-pibCOCj߉owS$]3Hk+7ROTk߱YXa–g8L;ݪV[l&cƃApM`Hl{!mGt'o1-+&;3']fN*T8elP?=Mb[; 6A4cyɨ~oBS 9Lj RUkϐR'Eq+)Ďss,d U3']sL%$Z:?߿5}%Hzr5*`9Q'c H/OVCHv=[\vt3F 9Mȑݤ*qHݽp _ \[S2;<o7CY^aU O>ޒΨt5|sX#dmHP`\j^5cE<&0ED~&zHROn?le*p\ 6PU+,I»x~?|C6}[h[p ev<`X,-L TH#}(v% _(Ο`5RΊ$ZE6$Q߿}"e+!*@HZ@Az0pv6gx/!#XXU{"Ty*Cg<@j *Cf 1 h,E1Xu"::ga`pH8*t6t TD *Xb,tu$jS 85!12 HvDS>]@f<F/miDU2Ό#n%a=Uuѥ䂱CtD)=kM7YNȞ҇D9s)g1KL-m  aZ%Om*]!ύï&/mqaO'Adboܕ \\|帣tzCoTt'fru5}L +w,Uߔ>݌Vm4ZMǪ;X!8m^LO9|S^޽=ym/цk_Q/HUWM~;w1E@rS _Ꝭ/% d'b7GKD'7%M0etGj%lzL: a|s]Hz-Ñ6H in2!QDJ kDˋ~!kp:]9bXE0XT&Bt2k<  `W$] {616[zĞrO׉姬?u~S7j?FQ\oBTHF.P y%+Q lLh*'k.j覴 6z ǜ0$LjJ2{ui4H$ Q}T;QtceEZ4fQK<!3B-0]yNsJL߱*._KTSĎl k1[W }XR.:fK:L9k7hM_lI&d>-PNVѨW罖Yߪu4ŴPAP)v uWotrEf.J~/?d 5' fcES1hbؓtzSX^D"՗gv§ѩcHD$NǵL:Xʧ3+G7XҒ(F:_!5Lg[)#ч2n|\X{bk~V7(sJv9}<_yC?-عjD<d?C+g? + YYLS^;@i{\x Ȱ]:*'0РqP͘. Dug¯swe (4([xĜ\[]]?rh׏[bHFml!N@?iףaV:)_dLf6vǢZg#aWw{m?=aDBX$Y:&jU*`S1@/lF;|{WIYg4 ҤXk_QKk|_ų(Bb!R# C::&1hO2ӑWۘrnulZ 7(호LCEd VuhHQ$#8}#TEd6T8O3ŨowEC$'?`/;ߜ5r^Q> 5Krd2Rx[Qte"ɞ{SMMȚ[?{ `.{l"+0AQO.4?ơ = 1BG$?AFmW d1ܥō;UbR{/ zeo9'AKM?v~ kr_#\ { ' QhiU{]MuM,KI@>e#6̰#m1hiץf{IQ6g&& ҿ@nIy`_BL 7R6,,rH`a;WNgouϥ{?*$HASnZķ;O6%Zp3gڄqͤ"X̵ n/eia4;nC3oجy(Ոye.8Y L[3h:k*N}[$Ze>V Cȉ"(.F,q9{VX7`bl8٪wm.Q!=xhKUs4j_&`9D>hN]1MgMw{'3 &@#DC;ڪOI7%9ryR܌ԡ3\ȅ5RG’l 1^[/4L}iVA /g K6PF$t8F S8o\K rY#8ͼ|gS;X  /6Di6Y#e*kfÛ Ղ)gF SsY'c@MְL2n}xwI py苛@|xT>Hj8^( Ll/+!_u4UtAiD)) Eޙ [W$/g /`.tK-S&!#K#&3inr {Q,,LG+u2حǥr t@ڣ2>f+^ja.+V7z+G@սྤT9w|Q\pѦuɔ{@p&pn`F<؂J2OO!A5Abd7S\QD=nĹR0S]m+G0xLүY+\x5[wAdZ,ʊPI/K/d ;9j2;TNPs{ki5iS@拾 *b Z ώD L -y&9HLys=x]ÝP Vp[;.7ołͽnWtm+nc)1 4/koʔ;4I1l!j4# BzgYn$U8R:trW#@ .}@a3ĨITol'vb2.MƷ#a&MU}xlt'E #H /+&0 ga6x{?gf-E)_RP!#I 1FpP'$R1e!~kOPmNm^Sv`3HG"hG.x`,WS=GPUR"/L%Ar"UjwCȠ2?Uf|`: Oh[劙=Ngb!7d)אn9_ꚘiaHbna]~a M0xD٥vy~n= K\9# )f& ׹Rl.2K B!. ^4lD+3u6gKrAqC^ cD|-j q^K_()$3-Fڰ49i@u{;iL5-VQVt±U[Ejj9סc, Mԏ7H؁w@ ss8|~a䊭fѧbO>'be֯"SɦP\ hO#`҅_SO{;Q=ќvV47fóE/ ϫIʼ8ad} zXda٭k< ͣk)9{`u!BYCu;B]G6 '{?!>)|.`-WJiÃ&BHX(oϜ=ټ-:Ql-Q̿7Ā*H|eLWL9Qz2GL>iBj\CussfsyIt` \t3|_*nL#svWtZMmBʧJ}ʑ7ء~WQ﬘u6:N2їhk,^VFm9ȮYěB .iKK|'YWh816Ւ͆:_em84h/KUa4mW=3=6(ĸq5Ӎ{uJ@!$,V97AYGH _OCPR+:~!%WoCiӫ^VBt7zPW^rNxj"h;D8?i?4,O>,pLЈE#[%eMxV6JYEQNbڿH蕾^]q:i]u4UiK*@$Wx5ɷ$ ,-0PѲ.G U#S)%MfAF(Y^<@4lPl_^ᶪUi{sO8=g)5lw /D;rbnEvIh`x٬EX{c^^鍌iތEx/ Ym:ϖX/}5;89_df4U-!g*  Hϥ\sCW"bb t@R ]I@S"AZNs cUQeoFizƦ&YK7~BK4{БMoO}#PNkB0ik,J%F{<xɱ < !"C?0g`4zCJnCI@VyG֓COZ :x8asuxdNRb}K,l!2Ga]~;c|R]~yP^11<}9PW R}5RsS&2*1IGO4 [k ?*7b\0 =D;߰v? V:TN{/gqK\KT|J]≇j#suWMDr㕩 ̷,F J|<HU&~.lw_."dгK m ;k!4^a&*Y0Ҁ\BǙnj(AW 1)xJԀ zy"c[4Z|,ĶD,@ȭ:i~ϳ ~4Zx! DH}k(UHkv? !e"Z|B5R:2E~7$#r4Tj ]vaI*V3O$b/Fc\x]0Dfb(5Φm~  :]AkݾJ̘^ꪅI\ݵs4m _vJv$CE(K_hH:8/"#PX.-UDcPJrtzыyܨXJ)ZV%C֤+l7 0MammSPZb1V$\fyCM/Np x]gptBTI >N _Y:Q|bia!S:Aմٴy\9(<^g'uZuН{8Z\=DKB?o=Rւ;!&F$X@\Be.أ9=çfR㕄; 3p|R heE6+U,DSeWK~N$K 2@4Nsd >`-'194+s6YcgFBgJ?Ӵ|ZMU6;/l!޴~';v m"oT7f\g@t|jOْEQ\-61°%|gX2ȗ05" ʉ\d1iMXDžoY}+Fp?enhnexc+ڟ 3kj+G UWBG&^;i dTۗ|aԟwx.\AxivC29RVB䗐ԃde:9kbEnU5-zsK#iTxuuįqOWcd!I6dRB>ۤ3=8vofc}xƢm9k6]UAzD304b16,+(B+8oh=Dtc >CD$*f!(,sAv`EI5}'܀5L=X+ΗJ'ڝaE 9GǐL~cN+pkW0_$0MRp] ^NC$"n2K7=Kk=Kf(d]kÌCׅR [yeyx< Sz7uZbjK#ሶVf.R.p =yv~zXA K[gh*-e^eY;:aJ#rt+Q~}26_~;,"갭HO aَܶus\ f hZͨ;\ "ENCFZ]*$UVu P t9{FVD !#?Hl{[Ou N}-]̋d}$uL?] !<L8i-j؛XäAZt^<C2Ĩ,B =!Ш@ s1a5B3ILsmBKE8lY&Gz !H",< >]~HO?d#'!<g3/LӺZ=/J.e|uN+sSz0S`#M["gkLS?U܉do#{SF>솳U]^^Z@b-IQt PokKܺ4>b,Hȶ23M2&B`h@~Vi9I4ZCBh/8 0!^@2bKn#hM4ݸN^ul3ɂ^cZYNq-;N YbSfJ\Qi<իXg|AA-9}s&r8cd-q$&ۚ2.hj>8VW;GC` )NehTr]Qiy!m!) o$3!/g䱺>@O`ߚ˙a={&M!)0JBs܆J񵑗"Syrix0[)[W[ Z6檞2kRJ-x tmb3 Ջ%-wSv\9@ ȵo~0Âp\^5~kS 51/n$Z.~,:; |Ƕr@LE1E9$kiyX)|Na)-62dfRZ2gvILPxP=z'V|!WyW{^/I~bkC0* ڰ]G8W[3]hJgs":4r+"d .PC 9OLλCȥǎفnu|\ ;k2pK ksd[f6)vrm'^1L}RIoKtKQx1\"?.* g-`Q0ۺ~`wqSU $ʉ N`Qִ)쎹j+-NJOŐtJ@ȧyUi~^  4w{ŁoCzpM)C/?ZtwfN'rY0̐@UFZuWXVv^# Uv{+@.]1_p7 iwMSuCFpj/* aE=u+TơhW+8\fꜶV™9f<C%8.pĺ57U ~ D/AW,ȊC:|̢q̃W_s)P-SCMOKMŨ_W/GRWyHlͣzS ?U1ŏlgBPd4!,e.gĎRşx+O؄A?ڛn şPF 6$jo1h1Ǫe%e MˬPudQ^@-ob>_0S-]'QWbHOVf3u8/X^w'⮁z/*HF3'_!>k\XOXsx5A>hZk.U$Pem#\٤ XkIV'^XH5F%_J#ed0+%-1$QoڍT PU E2W葙 fLls?R8ޡb͛Rf:̫r 0?H7KW]XRufTLg{Ջ%[yTٳu籾;pTCgHHdL.0jg4r'y1bysԱ?֭^H] j{^Zے,ǥV @t3ael7y(h}_%[aٱ*AL⩓ZCDW|a7_g-9/9K3B#JcnW ?fC6GTJnF:)c895 E_ }om魵uk$C5FG{;dFw@CBqID8ýFhBUϵU2Tcj1QҬ3O_Od3s(9qk=Oxh5 D"/9NҶn'F%1(A7nؑ" 7/="͝ 0\4d)pyu/~ a=زԯ70l.6$~ӒsL&ΛqwV~Q.R DL!Mx6Ew` ~{P7 C^Hч53Ɩ9߿VOO2hU8. Jh~&TuuzZT qȚMC^D-69q#m3KxN`Za鳶KY6LCܩ7a\ߑK· br,*mԳ8bb-{kA{KqIxCQKcf˧EK$Z 'lm c^L+_& nAOQ]1p쏃f}8BceD<ܠMZ q ;6( Q꫍*]#cȝhM#,^c+ bMYhzY[FMruuZDİe?|qb٫5A{{`]G/9dnǓt5Q/uOX ~͊/xٹdc"oi&>5_ɀlObuR4%= 4&/OE =(P<0W4a_/:E)%TfA[}ln{N n^@!,i8H:w-E*<֩$Y/E(ȱBVutși5 l䰥$>cνٛ1 g5@sɶ6cb>$o֯"wU=lP]]F oB+wNb29H&løaR_s0'mb l0^wd̅ײ@k50ͤ`sV y0~ߞc)wO |ilۊUHFN_`D7߹;̏ D1M¡1 $ npTA@oS57̣}2+6!ޠ)$K.^sg@hOE8#%KWׇZYt݊w5PƤ@.x3Uن cWQK@?OC|9Yg޵RAnW,YlS娾sR|! Hb0ʂ9|SLj %A^ГD+~Ra *ejL'?%,%`h k&Z,T@MTu)eI:w6~J*rѿT0e %^j ,"Α# *1M8V fċH[6{)ljXO ̙݆Z*NZɦYD{P%lM3vVDr5TT+=-ˀmc_:朂nf6E,K> m2]Hy$`"ꟴt7BNˉ!.d!8{{R0?Op1_NaL$]PaA#$dmWKeùZ90*2P'blRlHX5BשdDlڝ+ۥi[.vj<7ϛȺׄrqKxN7_Z;f5){"] ,j`\qF|!#~:a$:O!iYftG {x٬vLT':;%cqi8o{;zR!lwEpB>G!M5% U4IB>%I2eҹ@.#ǥҌi[:u2^M>Njf }}4wO=^tMe6.os.ўz]1uEX֊'X rUwV@;D4TЩ`4hVGo%Rp¥GY|#0eBn[!dž{:Cck91ȶڑ@vs2jV& c q-[ЄKR C;n"FŔ{sӸkmhl\ܴު]/EczuPpӫuC| SR~0L|H翚ubպuhx¯9P?Ye[hll!߁3v^i+BBal5 3A){Xm 'Ļ+̱uEDzΐpYAne*0*j[L:gQ*ߢWRb/}s o4} G:@3Y֚0aNkZUx5l]ߡ 8lr6{8-3N8E%; Ӫe"ϰ&iftSeB, /.Z^ٗ't0%:0oY9XRbzre8e<BdP[G&JCao!&HT?1sW}gWn kV~ (;.Osߛx̮;c+<E‹ܲb}|WCOWP$ٱT\W Pͮ~B3Nq5]R>`e"(8:,gXO8ʷu{xBl«ccJgJmh;bψ k{1gR$2OmgWF4 W^1',C Hyq9Nar~ 6'JDؒ;C*B)} NhYljStϕj2}iHAȡUB{^:Ta[G^ hsq!7X|Ìd*(g<gu 0@Rs,{\\j|y2ˆS >Uer1cO&J|IΙb@x! Tnm]]TLeXJvMF>[ʴ^0"Ҝ Lh=!gm{-G,m"w,NhS{m]$s«,<\AgJWoZe%6``Ә0|%t~3*pA"_x,sns<5Y"|?Av|};qsoUcBw'gy70nC0:AA) Kv9&;C[o`WiL̀L@"M0ޔ})TE\&8chNS@DLxjb qps]Az[=kF oJn( ' TsK{խVx|jT)n YFiH'Z<ºJ=z3 .FaԘUV:$GJ\ɂ0eRjFbJ\"X_`COy6Z,{R/|BWicNH8 omB{t3!^X Z8c 6^WzFH;s5BItzDw ?(ez9dx |isJ٠g'az=3yf;3 J ^K a({G.-թz(~7_4^ԏmQ퐭M]U5}3LVKF+e<;"}0 #A5r?BcUOm6HJ;}-R pޅ4>n"Iy?WG"Dz|o< 5lyP}C@d!{*_B^/ Oܴ"-5oq :VշYrD~({l4~Z&{!#]E>Z4P9_7*s;6.؇ik1E Ѧ >DEI ׷КZX}̔Vmfٶkq A& PIj×)!#Xi| ,2vij+f.F#Keʌ>layC8j#t52׮Mdۥ}6vjEy3sr1zZù\%֟>6=D} >Z}9 bsD=+ 鼇?mR: ץVbT~hMCvUUTyp.<$`nUCTl=W>5RBbP63GD~2i9m[z;).`ϕ@޾2%}Ia(?WH-^+d3H?i:XT$$ėՠ Q\ @G$Cv+ïclo1.cU,?RB⅜ IFֱlJ[3]5?AgYOK.ſ2qfqAcBg$8l@H [/5YX(Ea9 U^+KFrHνAgȩT=E瓥 H4̄5rťJ9Mm}DzܓÕ7ھyWrE5PԱxg xd[̈́^+6[` Py bei2(kT^+5Gi#raՠv̛ -ȭLoҹ|ɷX̜mFrE╖tW Dc'3T` DJ J!6 ΰ$,{-^ J?2HSg7c'XKumDDЛ}ձc6Sj Q4ŔԹ- Nϖ#*av!FyʔNiϾ_,,5MƄ \n X}Q-j^NJED+6J~ )vޗ&(_FD s:7*#Fy^\T'B2Q=!v^Eϓвˀglw >sW>W\ߡ􎤒)8 'X%MdxX\3B(E4[U{!]-QnS&6/bÛ ^`xÒL q΁Œ |L4]j%lI j[>&c|x֥_:mukrS~QD$S1H:JfCt>6p\֛+{Ovxn"5tJOF5h&RT]; 9ە^\ejfgPIС ̌QR&ƝkQw%L9 sr =Eyԟq<镛jV+o?^ \)3JT?í}iB@\E- Mʶey8sоa.ɫY@ldٯsfrbX T!_㧃қl OKG:+XWgWP'4bqBۣ=ISpʖ/N=a'U [y(Z.)l>~/s Z dgyc[=|N(<UJУ *8h?~T /\? βN-\)Ayy[oA֮q _v]=rpNbufUC\dP^?9lc:ֶ""ދDє`L/>w3ӛqn mG`ܰz^xE4 ' Lx5ܐ0sQPoD2Pi%q\4ӕ:ނ>[ m JFFUqNBfLܮH"࿅XΩu~pRTŶep%M7 i)[t8YC!jxFT&`?~ S 9HAMK"EFpx'ȉGeuq~{֘ b ˢyWim3xh,-r90vyvap⯩#RIH;#gV&BPn T'% ڰC9 D:Mrtsg'%XʈJPGy\*K @μ 10Us5Eu7¼eIvWqG s` Ѩ_Qfh="ץP81#WVoXGDz~7Wag9>+}nlMj}%TOlĚaѽ0% \(U{򪕠p[܃bw䝨a*`Ab1SɞQq.w{<|a4TyR.X8cØy9_dlꍜȑKdAP67k/3ZXν Zz#Uhi_gdJeڑ܆Y1y)Ɍio аB|T ۫;G [ͰqIW7˕1gSc/#X96a .r;O G ywB;|e44&`x?k7%ӓ/ǍgvV:o?ۗ | se_Kq] 0{*mX"N. O." ;*Mv$`8N `D?zrv\2VF* 2[N$+Kh->\SMRπ&NN@<(´g-3&pm{jODݷE:)h=u>NX?qug^%|r^e`.xٮ9V+3wOdD(vn&NRwRlekO'g屇2uyzaZD6Il,Jˊs8_Qw^xMй8c}gb5q|=SP;W伃\Q@pyqyq\2W?KH33aOnu85ޣa`-lIg%)L='uq6Du_^'U4"rlP.G1IT≣4FE= 0e\ oUgi}+s=17ĤR6hI}DxI@aҰo d~^P3T4LqecrnNp<3*ap(M*m͔שd;,u 2Rk,hA;|KS ÆifS9Aղr(q6g%MsmIOt}@yJ*{߾|tV(ƶUNJ ph< i@mnaNaLйlݓ4f6!SF'Xn iPl:F-#kw~FCWE Pr}8ha@wM{ D0p13oaMZ)onO!#ޒ8TkW,_n4'|rVbtGX1BT3"0l15Hʔ2@QH0vEV}^~eČ]In o5kDpM< Hȗi" ]tMC"QEnu9TcC0,O헌S)BZG@vé(ɠf;'', $'37u)_OM!w]tVUx,Nr-Vyt/dzM/c+1Y k=>w:{1ɜx2<\uŗZP[~WJ4S. zc;R1t sX,b/dQ~= ̝y̷Z9[64Fq5۷Qc 6rHQD nLMM(Oul+DӴpDj{Z=9טz+pHpf%8p!+ޔL,J_q V7mPyNiޱ='[x+Ii?U%l<< ZEU?<Ƣi\ x薨zTQ}SvOSCuLԹNX<Fq GrcxZ| S9HHSCW2C UcNÛdIsCfտgx}~`҃VI%DG:ϝ,<%5xU^%U/ #3a'ד-!cC96_,dSO4^ ;#o,Ü`Q@'Ā >IDp-M~/dƎP35UCD5Ƌ ri\⺹|MU@rtFY얫#ƨ}rCq`npb--X0r}EA}m/ LˈM]`h9,M#&4s}>D9[JG|XwM(r-;+M1TqW/Mxr~/R)Dɻa} $%.}/ضIGۧt+KRP3NuӪlclǤQ)0HEsR@T[{&E~pv,H_jp+97=&a7) |&mzC+Te+IJ{gRh>C[?\|rfMm/:p5>A|uVW־ / nU=-jeќ&{0I;4BP29p+]H$^$!\s=n_;\u\[,bA$M+FdVD+EKB @a=EA!0*:wZ\3Q5#KqGKhD^mOA36 !͋ӗ H! q1 鎿8"qq\CD{{1F;"gN~8qj8Oi|*] y8؆g"aWrf4ХGJPbqԕP,3o3#΍2GH2k.pHv?RV =_#[]WV٢,b  g րYs(nN?vq 65IH"6nT|ЯW;ح-c k /6߬ 'DUy.vkdgTeiأ ,gM".IጲhƛTŴΉkЛw@.Du#,> a+K?@RYp ߊZ^d88d L)wj=۽jL@X_7bѰ> N.j:rTx%4.Qۏ8 zwr즺Tv4.,88+ ie,%Szayy_)69dq+\meiZy=qzƻh'8uضZsvqܯ츟WE4+rxh!U# 1dbv6lM#amQPs8OϘ@^jUu} q{=q_]$n=Q-hfDaܘæ/:7^tsI,p",TӦF͏qTY#A$F__`pV_GYi:?91[ DX1hҜ$S!Cњwg Jc =[Թ(RB6BZsdu^QcPr88%ԼeV\b!a~gΡq$`Y٦ &޻QB\ _d_^{U dʐUU z[)񋠕 ? c? Ynu^㟴満}Q~}CR߱D>zЈ6"ڰ Ũ@{L$) kQl8{RnSj%fLZIQ}GY엁ii5X8+ň3`ez'(VԈ?tMRHooc vX?d5GP?*Ӻq<_=v72`Mg$gZyX=&IvD mZ*baZV#qGZy1 L9q,JǞ6Jhu llI3;Z3ԪtusZnܨ7 UP&OfR]Y8I4Ifp0/=ԇ$qiOӭ(UtYr|?}Ayh:3f^<by;2Q !+RE4U]w)]K'ZDUtVBc%ԠB- z7G1Y@l9`V} ^E|hzH$Ɵԫw7K~P0I=/4N)R$Yn2]"ʗDɘ*@5AXZcxnKdE}-~#rIh4Tf4ɽ~ x9dy+#*^~'B!'jGNT͔Q#|gZUcEp/@$중vc>:Etx뛐`)Z/ }(H=׬X$!0FuU0yy>U$BN[)>MьYFx"y[6hUADPJ U(i#11UEa 0/9$԰LYŷYxx-iG,,>*C__[H"GAI눿yff>KL2{4zhR(wIJK|Ag1pG |Zًo ]kl|&x!=]Dߦ2,+w"ȅ4#EvV 䟴<}ka'I H1 N+5+6 s4wIŸCxn,7Sl=ɳs-}P%N<`ӇnmTA|e oRO,=u}\I/VU  l7ħJfG7*3;Iz!.wu_-Ɲi2S+=9c$WىKnhE/`l\ &1˗+nTD *`q)h*b-',oגv?[چ]s8нedc| O3r7nU?"!y,(NLd9)n(n?;h9u~8Q\}t%ȕU6@[NXu;< {cK'k]؈'{r:N8u",?*f&H-TEJ69F;iUByQ$gj SfNԊָBia-y@`MKf\~(bE $1#$ڈ dۘ7Z4l(ON x2Wې_M`H \X^n4ѨL-br s۫VM79Gd^h !t@z Ր+-vF53IO >G_ksHĬ;eO,)G{F@Qm"+E-HEu"Ol|"Al`y!/}v$1=c>Z'<aU{uQGYO+GO04U 2*$+HV)5Œ<ȧi \=]_jc\^e =v[0Anj, lHYR#a*IR)AJXKK2w۵? o@~Xd2l!V?Et:=Gs1׆ 9?F=z(RiP{R "5hVb{ouv2hs7<*GO&x!'.N6LvyOz Vkd]rt#KSblA*&~,,/W'];XֱܔߏAu/R>cCmɬYq~{H`bN=ŰszŒȘeдY=* D}$žc4Y%^JU!6SSڟئ6vtuZ\jZl9ȋ>ßp> })_!2 V6s,zD+K?!SYO,?{i3lSB")}E|iSbvz쨵t5qZ]̕~m⠛hys0uEdDǬ3YA#b7Ac91hgeKWb}̃} P6 {DoGB&qeo!4jpyT[wX*a_pAm JC霟H?H%p8]YW1$,!>' ZS"FPJCc~#jCaP^-iq*/־IckRR4b l!Ӡٿ 3PG=X;E`kϳΎd|4򮋈r<ٶR9ׅ|8t<~2ZYeGlʣ iʛJl*ap>RQsTQ\݆j{4Q&pr za$|)E,DY?`}U^gs97t X LMK|+6[X '[LX.YLy6뀄voł$Bw]iٸ-7s`,]D~"qػO߸zPJRr/bp=*C;Ůl "``Da h\؃{S& { oO隤fq06ѹr3QUf6Xj-&~r7 #vK!%;*WoTBd0FFx%wD=G3,RX|9!W^ nE?JtjwR\ړc,;DYV8XY K#$]]3\'0f{eR8]&c=!#j ,אeS俻ڵmӻ`:Lڴ>z;0z?N\/bȜ:JCҳ jvxQMvۣvq]ԝܥ:2MCjOͥ(ѡʓ*U#i1P<8BId* p~ڒbfU<.Ȱ:*!t۱7bOB+rС' ּ7ۉ:-?3NeI$u#+b|ʷs=cX}4M85B".9 =T Df5;93| o"QWk Fǝr+o@d&W @O/5UNgϖT !4j&f-xe2'SxSa AtRЩ{c*Ԃ_S+Ł>'{WX =|6W7 ʆT"To'4QgR/w8Џn/8@x5/oX} nV0:,|._i}ܶ$^w;GO,p.]65.QՅ{T'*OX869Uμ9gj1^[  *Bpy.X#!o ٍPۓc3aA?ߞMSޠ1|i jzݕ%60{gTEuFQ~h^}#;]h)4 -_C[V/y]B7#7O"hXWeġ*D1CivtڒWzrѣ fhVnM~YQZ3ʣ0qvE+&[q$~ _=no)WpnɞQ怒$0{B^oNrV_5U,s2T^]Mfz8:3Zؙvp^EhG ҭ, jqd.8d--3ܪg聉2` v$ m-qW2e(3E~qmxi8X-#3og?}fT3xD+]վ* -dw,'蒩_eճrn(jS&܊xOCIb˕?JnF|͌A)Wu2!5PϟyUsY^ebRc6`AE҃tKKǰ>f,`yS p Zl,Cih4JWX;H>ZtKԳW8I l9D`R]L3mX+Lڭiy^#.}!+!sWq@`KWQc\|'z^)iŘטxQ8K֜Fyjl_;I_s{7j\z3G "+0-5ƣM=-37˻;oxmXgox]\1;ꍻ^BY^P|ε>WfoVlJITiP~~oL #;fۀ"0=XY1HܨvByW %,WMK[:iha i;q*WAIo^O]FXr@{^U2;…sm%g l*jk#_@m)կ _p Z|5@'tLR2׮Z܈{8u#a(\0\b:jӥGDO6u`ũKhį:Ksg^HAF6FiBHo$ oIoͯ0T;h8OJP#PK[5C)c;BcF~=v^8DbG^Wk'DCIBGuXAE!Y7KEvM%M~Z*Y/"3zXyQ}WxƋtcr8ڊntQT`ppArI9R#;TR9t}+Da+s;'/Z: >=gihaBhW ;8ME*eRՁ>#Nb|aaLf{h##I