sssd-ipa-1.14.0-43.el7_3.18$>\e nC''7C>=?d   ; "@FM    4 { $XLL 3L   ( 89:g =9GDH`I|XY\]^0bdefltuvw$x@y\RCsssd-ipa1.14.043.el7_3.18The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.YTEpc1bm.rdu2.centos.org 'CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdhKOjA큤AYTE_YTE_YTEoW~YTEMYTELYTEOb81dff727b2c5f2e041d79953f1631a428ba87ab85847b3bdc991af78e8f669694d30cbaba62288876ee7e92f0ba8b5e69aaebca8c190f9060a3670d91a193ba8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90371ce67dead6a25db630c6b71465c06b2ed9bdfad044db73aaabefec0bdd0cd740a17ad4e3be94abb12e67598d0e01f60f4419f9887368b81d29b7d0fb4f3b8d1rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.14.0-43.el7_3.18.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.14.0-43.el7_3.183.0.4-14.6.0-14.0-11.14.0-43.el7_3.181.14.0-43.el7_3.181.14.0-43.el7_3.185.2-1sssd1.10.0-8.beta24.11.3Y(YYtYXBXpXv@XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.18Jakub Hrozek - 1.14.0-43.17Jakub Hrozek - 1.14.0-43.16Jakub Hrozek - 1.14.0-43.15Jakub Hrozek - 1.14.0-43.14Jakub Hrozek - 1.14.0-43.13Jakub Hrozek - 1.14.0-43.12Jakub Hrozek - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1456013 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1450125 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1446085 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1445821 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1422183 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user.- Resolves: rhbz#1418943 - If a long-running task (e.g. enumeration) blocks the sssd_be process, sssd_be can deadlock - Also Require a new-enough version of selinux-policy so that setpgid() by sssd is allowed- Resolves: rhbz#1405584 - SSH: default_domain_suffix is not being used for users' authorized keys- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.14.0-43.el7_3.181.14.0-43.el7_3.18libsss_ipa.soselinux_childsssd-ipa-1.14.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.14.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=21eef38c65d50e5eb1c3f51f72c108a65d626955, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=50c96aca176bd9bc566fd36de8a0511b472b4003, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)@@PRRRRR!RRRRRRRBR R?R+R8RRR R-R:RR6R=R/RRRFR)R R?RRRRRR0R6R=R>R(R R/RRRF?07zXZ !PH6>]"k%w+p}|,p35muذH^WҀe:>Ў /8jm3~jK^) XZ㴿WVpl;>#,6Gǃ;9J|CH1 fȉhJ'c/ 7:tֻ\ލQ& E[TQ}Fy"sGNTۍb;(w-΃,cʁSΚV%ӋX*%7fyl5;B Mun)SUyyhlb`Gɰl}IGIእ%605&|6sWW%[ s k\AK O꽈u|뤊/QVY9+ixw7d+jiT Ƃ/dt X9'\uUՇp #ǚ#?Y |xCUyХ 07؁Kj:yحS|@- ZH&+l?!?&] C2)Y{ $4V wos ( ^?HcJ>lVxjZT VPm^,0B0/Q2O#+nz>\ Zr$^3ƶ'g]XFŸσJ҂Gi tno>,㢯Pj`ʠ >Q~uU3PUO.q[y- Um2O}:SL B3<' J5wO YjA^6A`4Z^ђ1vB 6mr|Ͻ@.AOJ8PvQ*0ۗFaEs O$PVpLdq xaTTL PJ!UTk;?WT$_ 6)O}_ti={ݪ7sՑx62 1F$t 2l 5~&Cf ."k:} u;K(3M[àai.jKD%kg>o_gߦT&*x?= 3%E"V^rp5 ɨ[;{0_W=}uas5 9pď3G8ۤ$upLN%p(R :G@5AUf/%4"VvrE=\a2zik{YK\Uzbe/ bu/ܗ0tEt8>WVNcΚ+!;#:PPZN2*E5UOoZ1ܑLfnvZfg :?5]{K>B|>z+}A.DG{7hyXqDQ<+hH` J;}6:51ʠZAI >N/ߍ]X%n(M~_;9$X73^*e0a!CU <D&l+S Pg l󫛴'y4ҪϰK4 '˸Hw} Ia|HtZt* $l΁I"RtoyZy'$/Ӆ^XgZj0,;9^vkA<ǹ{Tv"w7\/!+xwI.tuhHmc?4\r8x35k'ɶf6'P-UCPzVbi;x5 ZZiC$K@s4ヤ? #h((Y*^X>= Вv)t$x+,ztE2ИTO{gpN Dt/f_">h'Ysc緽|~bA*ܨRG?^;!/ Kg !T.R,er:_ɽ%\WI '7}tm.ϣm ,^z߸ 8' _UQc=Y8GX l $H ]JN^&MiWFfbX dH[,X`eFM^ݧ2׵[`{B8HFNYRIJnm$"`( M &%f# .V)z1B|aϜo4 OV I(K$ MC:Z*C-S}=)6l ,S/kO-8ܱr\ývD$#7})#`?K'd&@h{8Q:N>Fr\# R 4FwLDBJ>TU>;;^0UD 2bF}Dq'iq-t'ėR~`m*mfC Y< ɌM%-%N4yݤ}t8r@iv븂CuR㦩`dy%71kd\'h3uI3`x[7M¶x@#Ayi$J™nOHAQ>S_.<@^σhMt*mDMԳ"[ 鄪B\ĊDd<хۂ@\[:hxm\«PZr-$+W}͠iЕg~ RD2rq;8 V!#4ь]gBZ= G ;qkU'KQMo0]7teI(˜`Ƙ4D%X:Fgǩ} =թ TZ +>13Xʹp . L #,v'na9B԰ }!䨿Bul(+}#|b z,UnBǞDxcD78f>\1oRgNP%3ܰ۠VxY[$r!0#EBh&!J\;\ ԕ{춉؁8I4kX7Pq2p_D5aR7Xtҟ L[>P MY?NY"AlNwS"Xw[V f(ikTWl]O 5CcfL닡a76G."M(`=KԚK_I䝉S`N@F)SCRD;a`$ Q{:gߥy%YK,wcmꁵJ.E&hP,r^84TO<#M6aQQWl@f^YLKy{BjwFc-[3F>a '{ kX+qݍጂŬ=cÉBSXql*$E(c4˜Qc 7OQA d [ojA5)qU /yfc&є1St*53бB'G"ٵ@Ej=0u&T`w:2GKrD}" s@e@8pMy4}@?x.[rN@`'23.!d_0e"qYBQnXU]N,кL7UٳNR+" f+2A?D0BI}9|E]cxB/wdPvv4QeClIbh c~^ R+'AޱrfRg]#E*͇5R(9h_hmIoGMפ<hՊ)4fBb?)Lja?Zd_->U2f̭ j1݌1mLaae+1v>ӆLomoFǃgҋ.XjXݜu+SU!P6K|y%k2b&}F"X4P⽲ QVj)NmEq[s #=vOl$'z HUh4ȕ1ȱ,py 7ڐxLЧl\6`T T ~_$r)ݞnvImG:(/Uqex%pM2\ InujP@Ra6Ϯs}u*2U8Hk?냏rlUM[nU g;n*l iqb_֯Sn%v(DeUr=F|텰ׂQϛ0鯐?7-;;[Xܸ; >Y^0r90rΎb4^)mH&;S Xx8+ޡBQX^*}"+C֛QoqpBU ߏ!wr1ap[V}EMR>tma2|B0?k`DG??h=ש63w,,/mRuV KՀYB>s[}ΘGmu@~5na[ixB/GeQ隠9-h5' WS[f|% ( {HSzuםs)o2򨛉?O߱”:j[SAu=Y{[]Wqmt'SYל. gm/YtMkc {Dg޴1Q@Gm*S @B$*!R J5c _9nڵ&WkZzE.zڨCXkl׿}/7o-bE~ܻUY8:(uX2.>a8VW $LUݰ)^ n~-o~ H!$ӣM i=Cm(`; ~3pU#Y#ѨyȴU_LE*`}i/罭Ah^.xN{Ķ8̪Z߷Zb*]7Nws/oĈ1J ϐ\u0_R,ydbp)6{2iE@jNrDոx0l<ٹuሃr^aġm3NJ#S+Q䄧5iuT&ḳu^.oT5-oQ*\M69[>fQx{,?|qͧD,V39b,aH,d= S*kkc&_ɟ;o&KN I1^EM7yɽ q%(j9^DiiD$f~oRQY+&lxNL+苨7hL T0u١D܅~=+ݳ g/vDC~kJ7g?OmTaЙ7Ұ u{as2:mJAWgBJW( dbڸE&~ybb>0~Znr"~_x >"d^䑘j%b\ג3W]z7a\v,+H PNcꗎ{ iy;m޻\ӎ[~8s:iĦX;c|VhI{I".}tS Hg>a0P<ZcS8΅*vDc뫣$f\ *"Bjr U,-9*K60Q/.pCeu$RV$/^u'TK:xba ixc/Vz:H$=XIX_"m߱0'CYփWB+ZU a;.TZJZ,0qI96 @пǕ@?*-ͮJ2N,kA+.AlHINAL\C{C*TB;3O,*BƋ0QO24cV:v~Lϝv@ek6+qĆL`ںA2֡i 0pil:cRI؏T^ }1j<Ĝ-RLK}7J;R@u>[4EvYypIDf(xg< "IU3ɪ89_D*`j] ,^3nODbCԽ6DΔCVþZ❿ Y_sT>l qŒ; d(3rU4Un\&J4M J3O 9S3D'ܷF%ډ擔gN?-C>u Y*%RMo8TFS!j)U,Y mCғ,F+(jݤwn5ʰ,__(ײƖ"5_O=s2M|qRTAtS%F`3c7 ?诲 HSQýy6Q}~DX K渶%YE6X$Q>BʚIʎB7)yk1:a2XJjI&7NX#tn9x$sѲ2&a,Ǣ>`z BzxЈ^xSM2M~v*%'t(ѹ{r!9ЫM(8 *~\8{m1TW7QI}npo{>(VLjnrxX 75Bj?9gX^2K$r팞wE6 AZ 4!k_Fe1cT?LvM[31bdwջ"kW]O}S+G=2C^+rΆ0JY^eHN &-Mx|)5כUZ? jj/5Itc =fP,WS Dр͕ㅞenA@Кk1k| ?|9t)X@WsJB M.TaGyuVQ0 D"?u8gPHvbaV C T&Ja Mw~QJv|L  3I9>FM#LlQDмU#>8' D$,i oxaL̮Ưn$-*8@/r>UOtñH}79e[!՗$J h`x%Q=^DB2X54xbcgegxIV8i16*v?W]jɏgsT)41ePąLko0a?Yܦ8g{ @4Ɇx֪|6&.:M+JGѽfhheR^By4BV sam`,,bw5v e[M5Oe*DX/LcqmjXqoS"4!m􆝮QFbءŢLlƽ̉)?AȨ-ףg,AcO- 0!8,8G)Z wJէnE}3rf)BK E򝪟SyҦ `-0I|oY']$j" _bM_1}ʚCQ /SK.%UITqbQo!DaZcSֹXLa, N5v9n.8_79P]q &Jnaψ9"74%`30M&"Yy ԛ㙋2զR8ǐSF po6vAIiR$lj`>(tx:Md=hOH$&5٧|/K-+Vt64zV+Þ^ei~m erh]v`kX@Ph34_'] m /J]>C V$eЌS~ >EFKqBa"4q)(]$dʎ9 BNdؒzFCJrſu|\ LsuQM*@6{lk'_Յy2u 94^qÙ`S;-?;*г霵S_1D>(Ic[UgxcݛnۥOy^%ÚǼ#{H}BSb#`LXaA4S4RbDE>~25}kަ5T )I۷m (WK߼<۫k/m8f˩cSZ%j[InkflgNEynP>?=?Rt `}!5Zv^wK޷U_#,IitgYH 'F™Q{?k ,߾tJ_x9-3'1)w9/zPT6bRukGQ`a6f]1Õ^ie?Oҡk!938\dJ݄:fg }y 8CGm3KՋby2ֲrZj$؄!*)_) lv5ӌ>F"Itj2v2ID@NVκx 7T|@Öpi(*d{\ BQsv ?]Y<-s$_ؑJyohvEi{lpSӿ u+gbgk;+!'ޮnlF6q|oʹ\ j:0('x cf 4HS锷`Xbw Sx6rC G=QL@*-+,Uz=_4A"C3T$ ^@%8X|\Mޠ=aRxǶhu[,f6<<6o/.*W"y&EG$6@ey^'4P]l_||2K7DȾ , 7@c7)611?Rgh1:}|O_S|X_R!o|lbc2(GUmr2KM(2f15rcd :Y I_hjl76E},LJU;m4v7Vq@Ȟ$NV:JUHSc>hwe6# G5WW &ۖEn,%T(?oϣ_hۨX׬cĠxLyΓK>mĺCNp|9疄W Y>"r%r3:ٿUmٰ(=MD#݉m2k>1QֿTXMa,LE[4 FR./UI̶Y0fzr (oE״^7QW!: F0t$A5oFmqؚ\+ z\&S$ ~ă}j?n)t^O*SX\3(ImcIPiµ]qyFӾ#@`Azc7,f=/g$nc~f7#HW#6EH)eڟ/+VXZaI)ʵg<ᖻN.IpB=E( y@GeF<Ҥt"_rϑHaDeF]PSO (fKun+&W&QL?;٢{\%Pj&=:-(|~7O##>Ͼ*b+8)ӧ*,0~!-t&\#KeM? 1ĔSc-KvV{2IȆ@o*3ww׹\6&SǮ? `&@q쑓%Mo7)9!BK:ϸUl+H@ &0EۅǩEj(]w OR m",+0^(\ZIZA ژ/Y>_TWjNC6dS%JA*=:UaLY9{$+i6@$tLy0%M'' 4^CzJ@ߥS" *Vtѡk ǺJM4d2i iWs`BR-L=CwBW2g}ǻryl|V* ΃nwqGIoTڎs?$@0zqSo痒)wyƔKkAb(q+ɩAɐcw`߳,nn14l|+=aZЅrUrm`9B2PDE=O/!ʜuU Z[ڃqNxpXKhb̺fE.PHI~b>B yʦi.^.$Ac'LKۻ\K-K3W}:^ A4+%etBfbOT0s I)˥D62$7uM[ Բq i? G1dآtAԶL3-m0>3(q8dݗhqҔ}C(*.ƶQ˜hʛa0M_(s}15X`@:'SnMg_1jMӺݙSa~ 7+dyWPSrW2X%!ͽP"X>ŐtQӜU;i9Teڢp QA(z5W)ҲH e92m>Ӭ~K#/Dh=WWOl 5@tkczAR::br˖H}x5`O=Sː6dN)ot]WB'`9K1 whIIFef 0F?414:6icg}"KWƧN;'=e%Sxl@kK M Ctp1gceϣx1 mL4pʉ\?oG Il6/||73d6@YXw?,7(XEH[_Gs81nKb&DSh虑]Y8z9Q Z - JϝiU7@-Ⱦ($h<~7e\llHᗺ>ᾱV)Td'=RDJ#6 +\ 3#t+|٪XG|ʽB*SȊϐw|G ""fvx=$XNwة:mjdɢi{\ʦy$vA'W )7ZԠ/UZ?[պ{/_EʎD&x+ Ug7D8ηJ~(ޓC_QT7H?3 3 F.HOV~#" e$)׆CȉAձ.%3ZDLuu/SW; Wa=J 3ޜ{rK$0aG~Kd`*0?"OՇhuOFu˧wʄ\gV2e -#cvD3PbԒZ^9g~?a|qzҜXðITgqܻl3t'n2%p9<ǖGp<'t_Ga&!MA@zC?d 1jVV]/֞ZmHI:7|E+!YRsO8M Uk;dC5P8bghEWfr%V|))nv3zV?ww=W9\{vLլQ4<ݮ/)ͅ ^hzk%=MXیBHSxq|heVb@Cc]rM ^ETPZR?]UPCP;I8qRXvi"j!4*{<)gʙ \n~FP[m˩FI*~D;BT7 ͻ0RQoB:|>cZY\jFh]"&6jiX=%tl~Oiv:eu-[fYΆRZͱ>aP";KV$6k0}dx|axTQJZ[0L&5x9،>3iX~ ]y@Yo~[_L@Z=n DCDΛ? X -.PUrh(^ /?bE]<ox= ~iԑD@M?dgtE_Od$8E DAͽ6=.$ 4_Kİ E vHX%u1Ոrq1J.4#DrCc \q ~c$w' ۓg!_/nr=ߢ}@{<#W#Z>;\P-bRdc)Esjz)LfR<;8u](GIܩ~ w<'\{FW\6p}Md_=Tv]~GLۗΘ=h?q5<\:s;PzB&3ALvL'YlQ0DJGaqG9E7NDd0$]y05 Z00눪;Q~g(ro6حזᝐ#Bʤx1^H}EmBZ4g=B[/s2 ]2sصB(wulN/R2!-0(0h߃0)[]!8t`tA*@_7NNeݦC%eaZE*;jNQPDu|>L8 jƗ)ap $l!B3E%Sm׈ +! >,hm.YgMJY-K}ޘAa2[[ӷ5[bgx3Gx][#,_XF8K (`TplÂv3lTw`elzYNz{vJ d7 1{N>Z5?x8O)#7YV* X(z@Lت+^ZcWvcMM؍) Kv-?!i!3neqh7'n:`ײܰ'}JbZqJ+yʡFŇ9껦IIlK5ճ3<:Uw2S4KPN#yC4X. TDn;B,+5 _Dk {ۏgĵa4_ui=%D:>4b'%SWC)_tdObm%<49Xjc9xaj {5qW^,Eعݎ1X}J(%CQDUC\+϶tؘZX$67 +%RqteKET8ò!POtQZi͙d*so]LrSSujs0{)nS51,=װZD;T{_GMom$*\9?. ΰB=|,#qW,j/o\1Y6VT:k`aDŘI,g> c5]oL3Lu5+/s&tGY:Mkx&y&d{POWڇ T@N42Rj<||%Zk,afcΛ񮎕|Uހg.rѓHbբ1̋A `P9zm7r X5t#b%% Z"8~$T51DZZxZ9*80qzGa?T1c[yX,A'"kMT$  rDqiY+D{XHoڄ 3qB>t3ykFlj]e}aYr %oAeLuB.cq4 #K2itG (S : HG"dH0y/JEOQgqhܧ :XSjvH -|@~n, .oa[ }a ~ K.Q<~S|.t !šw]R -ʛ# o{#_hO,:?FGi(pm(udnG,jkiww\~,: +n莹&6b"AW%j:SO Z5yDZb\ i<ݒOi#awϓ.UR[#Srn_m}j;!˧{õķ6UJTkk'钡HuFEX&PPR& OXOoSYh7+n |ZV-&C=\TNخrJi < I"2%%PpOy|wp*P+XjA80@af.TF`鱼^xY/)D~Yorugo.7hj׻?EE. 9crGN+6n/ DG**iEZuFhȯ͙ >ь$eHf[-5^!:Kjnfn%I\l*nX@bH RHɛ~5kLsxJlQdLͅ7us$CyM|O쏇s88\A35kW3:-1'y) *<6Mc))dwp4i/.x Iͼf\1t]?Z = GϡsD4 y3:aK)@JܬDN5UN wv #].TS.tN;U yO,7vG%;L?twyPmӿHA3{;2&VƎ=2afB+q皉y#0]^9qUM;=\LC{iY9],@׫K r_PB{гA1v4|w;xZCEU;feY8ф }gH)2cV.*q"fzczÞY|ΑΧVPDtrݾ(a77lʽ'+t5~4y.|6U $3 |41VaJS>|I$krQT_ީ ȞS?iK0I$/:e'ɣ03u.;c$FDoO-4= d0Ǧ˄y2.OJ\AKH=0pgq8{5[nJ eҰǤv+䇩 82 Kh4zc;TՁ^dz5-R]H"9PFN3yN4ʈI6QxA-`'3&<~>/J >-_Vi:@ OΓr1Ų巀epvq;AT<(0n׭ʁT1Th lyOMa$SIxO>2*w?:|V՞W\}A͇HXnDs1]RBR)q:* _ei-pFJ'!F0q.D5B!7sjsI>fڸ9guL˺t'+D*>ɞYJ޼ ]`O,s0Di+B$"}c9DꖐmgMR8@\0ꄸyԧ>C?J|}rY؝N*n)Fs3BXA!dPFˌRҋM֒[5-xIPns+LfBhV*;v5@% ݅kq*qA| d1R]0>鋮F6-D388EY-@4W{c mAIe]Mi'jbg*Gf''7G/\J9Úng%njMQblqX3G_vѼFaQ&αH_4b%AI0y fh|L ʱ6G #V}HЮ@> %6Ȍm>eaUF+#9s6%[xfy$\;rxz214∖.vΊG`@^o"f"0xw w]'&rV/z䄺zI q+/D~N+@bT\ZAF9!Bmz{F5#XALM|{Vi4({iݞ?UeyK?8$r T|<%WӧO|QoI0\'e},+HI1WX۹$'afnjuL[fy_ $2Fᾭ7I#\zBR'jȺY'dq:ZoV^׶/L#f%gH1F8Gcwo{ Io(ٔ=aGRQKۂ0wi9rc ׋rTbFҡgVQGngkL5 yTiřPz 4#Fg^xv` Y%cvl}*`l9=ՑՋV5;KPY;D='_@|g$k#boӦC W$.o y- {©QR~9d#TgMф5ǹ4 p>*v9+;^l$yzh" X+yg|S{aZ􏯷31h4{#^wA?Nadz2Fzؐ)coӡt!D_Dals7}04|9ay oT 1:44LTYgOKd2&N`Y=`לTJ#W5zR&)`!dλU#+ =g11]Z Éѧ򔿸aO,:DJ/*[@2P0, n@:|Tͨ1h[0&Y-~o|댠yz'e~8rYZM/=绑WK ĸj_y$͈PIOUpRO](4HaVv(mObrڮ6xVTzӐiՖ| Um\#Os07LvVK $?6L}>͎<WkUaf>=a`W-GJb}i7}㫑fwZ :ld;z!_./jk )_G$UĆW2,8 l-g _M ӏ[8hoV,Z3p5Ҫ@MI2}~_k}, ߕc7Af@ߩ~{ce-%IbҫF4gzp3Y,ާ՗oq?DLJ)]\M'sp0,ο6P,+9~Տ>x}5Dv0!!L{Q: FՂY)D ?]0ezCӛaL@ЏZb6|?\.ԵpFSē<Ո9BӂW,A91r89Jg`Bsܸ'.3e"B;W_G04$v'sK󝚷GȶrՋcz&;;ENiQ[^nYz58O;4UM$A)rN\AkexB M/[lYTUw| XZ7& jEF(zɒbNӗ,kŧ5e6(?,3 oS9lW F!jBF:3f#L)F9X|7\ihd(ǭi!&]½?tAraq;7qT '&Ɏ3Kk \-@gCqh.lՑS3B{7]ssҶu[tXXv- OJ]‘.*F'7iRoIl<&oouoﱬZd]`!@0i͸l }S؝}ǎ\+| Wyͮ+ |5=sK-B8j?O.4Atf3|"$ܓA2tz{WsfDy T\}X-F :+??`<_RpLgZF%+98Vozކa ~֨㸊hwz)C<&7@hpUr>7Pr3ɹ|LIa#DBG5?\c~_`$]9!$` lVdnnj.X" {3 &rRY3%Ur5V\ hc}BǭK)畆%rv ƐY +،Z Ƒi+S9 uP1_/Cu3khUL3wTckt}wca&LUP;f\P C:;}ߥW[b3`KE@,&t@dž2a2jLV7gK((N4/9?LOMOkùM5xk*d?1tFQ(6uuvS|T .a:SG8BM~HT&] 6dY[c-U>ku\(2pF兝x: 2V>4Ip:M}.SLAdz bPi+bsWixr#G$$GqZ&Z, (f~뮅J\~w2& _ "WnΎaQ1Iu>gp?=UuWW>lш 1 ;xS;"X 7FO*+GϷ(oaoߺ ٖܘCQ7aeQ+Fp>#C:фӉكPT+5Gu-0Tϡ# ڇtE)QcaT]Nvs&a7~o`U\RꃣaiBC4>偝|yq U+ Ace_.7H&e30`ע敻mnOx?<߻Bu/HU=R(#-Y@$wӆM,Z;C5@kױu@Q4݊T6G?vqƋ$'qkeML߫Wx]n*x"o/8CAϳ 5NWWg z@o %M PPsx|ǟt|w V`0k;4ra*R!6JPTsH|X%HT:6QHh$/wP^\@dݺa`yyL [&oCLeX&ex0ݾ0iɦKf3l6[=K[8qCf UsGhE߾ȍc>0s68(3"ZPH6 )g^ۢK'$ZYdF| iKHe5SY W,A L%{뒻h9~f:b%&D)C9Ɍ)lg΍Fů9X` FDݱ )DPY  x_|xxJh9j `[#9KˡYrG1 7n}g9*Eἷ_| Td.#+ ݬtP՗¤D'3ӎ}dG?A.*!~wbNήesEVUJ~3ԕTeVC4IvhFo1_tɠ۩ 9qR8ʑN7{f\o\sEAE=μ=)eʰA kj)6NwN1(^V٣8.7%NTT Cׂ?s fAn/"Di]OSkXb h N W+ (o91i_+lԍ=x%KE^UT@C}(ۆ{;FgXLmIH *Z%?r=zEWPFb;ĄlQs44/C;kxʶ}=U  3(Mw! bRnྰAbؽ=Ȧ3 -?c7 %hf$M{G[{T{avjT&-afGYDf.E/'997<ƒ@ݪHv-PzICe^Qf'Wxb稪/,8rjʐ0KO027 K=c^`'KcB˺T}+@%,3 0o!OtdɘyJvc{=h!Jַa˝AM6Jk])a'z+@[kgu[0 wyk% ƌ&~JZ] @%> (^HNG2`n$J.4w3Quk.hW~x2&@m1q{ͬ}VWK(ߞKx.""yLzp#()\mUxA8Vdh{^^>8f%'#I;XD側YZ:U$/,PA14`a(155G舜W%Y=Ïŋ~gخC?]|lCYٟ8eK)57ߜ zk_|A5ViQV1Eq"'3E~[BXqAx*BI.4`p`wɥd=;% Kv8~(@l^>n程ˤ"{r//d/?0%&zPn},‘SPʪ22-ӗfr |*WMPd`2_}ouV/TQтX )ۭSy0AZLLvpSW4##"4t1>W遍Es  T]g!Wh>?`jJDynfXG.6SSLmaP~R{aųWo84sR0Eei}sZ.D$Zy CϠeoen{ÞURX$6e.'cQ[Uct-璈U"^8zG]wI&SYL xmiZ}ހ[4!˰=W7` Rmt% ;55ؿyRƔ@T)m҆FCCAbnQZ)a[Ec@XEdRC9Ϸ闷Af?asB0Yz7+ ^dG|G#^zP P{ٜt$i&XK^ 8L?@/vp\mNFwe3`>+B |T%l:EB0y񾟦>/u3$~KD[7GdV @U-x 3ΡrtdAа{\M\j >'.>δ)SOp&vq!v]%qM)n*#yѧF]% yob,j}Dsc-(^$9}j*?>K]Lf^xQf֗D,Dhg;nh89^7*vYr$O.?. B/F\u2/ϚY1L lI~]j*RH-ޱtd`}QrjUw]9)d5ս%sY6_o{)eJp7Jdv.I:_?H2z1E`-6j[2!~0Njeؖ_vy (}H%/OzFa86s ׇkI:05jUB+!' 3ʁ48IwZ  .` +!cZr_f.j-4$Z6@??'*eΟFB2 k$=#7MC6C ִ2lՊm#k䈣!J㖳M<ܳP!*~͗I0 Gy*$Bjmo^Dt,}@Tx8rk5N:6F-Z^r qaCJOէETxPk;vj܈*nj[tCW|J:Z; [VUX巧>4q_"pۡu8a)>4#W܍ @NfE#!cJF#RA/it-(\̮tv(lIZXOT#a^c4ySNų'v kyDJyKd)7pcp#粜Ɵb67Sփk Z#z]1lO5 KM}؍t`sҡ?`p)p1)dB}nrQXpj'^Z昉$ݥKg+r$[MrR`8b*o#h&=l~V|3L^ \,E5މR)8ۋA:0ĽʵQ 6R.cVpl࡫Y܎ds={h3v,=# bTPOM1%+|~ш_&ȟڤK=Zm-ز:A)goˀj&b9p;e2ck|m6Ѱ/mFB0R HC+Iy1;&BE/VKʚZ:6 3A/+mXv\(]P=%Q Wn$ɍ O/SG.vS@ GW,U@C}D驀 `KFrBltf]aTV:tgWidާ\fQg'(cx,'71L;t562bW5/sҒ~z%Wύ1by@CBC#߆m5<&4؁v i;)7KYڶhICiƼw7*VJp٬к}2t^7,c+,q>V2 dANPPVog ,?]:s ."e]JHCA[EE DZ5-ߪvqI5Wh5hK^;*^o9[>UV(MXɥc_\ ]CѫG TU' ˧ W&?'] ,0;2(Nm$ujOX-6Kv2#Ϸ@3$ﮣׅt3B.̸Jt߈ ?`uLOFRDZF,g7sheԾ_$2q?Q] 7n-{i9bA0Ǘ6BR<`d&vӠS׍1LhU[T_YVt 505Fޛ`Ɩ/? p` mVʐ=vJ\AO}:_ 7YCe_VW+RϳPa xs Quh:j2I/+qX׭ n7sKrL=Vl:unQLg偡CY]j8IJZ)Ö - ǀgޯW`@@3i˽1^rrձڗ&Gy'i+̏uÏ$Ɠ_FS>plWR<;Q߇ n& :G"$zEr nFR+f&`t" 红#g*AQۨٝl*Z eZ 0Q\ԇn:4H=FhVl"g"ϑʢ7q9#nx34՞ˢ78t ʪo'}pǢ+Pq"%Fjφ¡ lbu:0h/p’"[XkY E4랡UQ96ݡ՟P ]|tp|M\Q}+'Y |3u zLx'`fcjbI0L.~][;ehnjJ` t=>ow }i2eh'wֵ,ќl9e)зT'dF_)[;[u$u;>I}N510KmfV<$ҚwA|{m]xv\M"n L#5̨i`|E Kݮ\tmc~g*{KgEwtljXbT_>_(~R-%XI|ɜgMߦЙygyd1H78擄(EL ƍ4db2~% RsRze0Agrtld!G{1+xdbH@mӮeV<۲Be@%avEl=^DӘ@j[#iA/. \Adyuf8_su4O%JM&3#՝PKFYdA5ѤL=R3mvk) P 7\wB)ʰezӦ;\I l:Km(ӱOL ]&=ƌzqVӇ3?Y| Afso-SPgic'sެ5)IV raUAWԧbU9ݮo%!Ruta@jFt\åmmn\'/W8o:3aCa:ՖюF32 ޷9P5p"6DK uAfsaߗLvpΘ; Zn{gء+#Hcq{AmߢB<)u;~Տjd_莊O vwt>T@e,:"ׅ6} "-YS.Yo^9F/:T^KZqq Ď>b?.Jb{ZbGHAWr|i7dFn="DʎBϰ3/j>3ح#xv8D4I  ?Y@l%Lx7/uwk$o՘0_P5#RB WcmeU@(yq;X 9+XU5@\DyZ a}ʐNX_z̾m<@=0h8g=TNf'2xa< fX#[~ |Ѓ=3Y2;a -cfn4_O%zlOLގ8{;݈ҙ@ˎǿkEFlq&sgG1Lt ^X@+8,^ij.aѻ#Mpz[nɑ8 ܱV*屵o:+˜P2R K)01"Ub9d뀿k%5o sE$B6{OlcVR "l /\'Az7p#ٙ0R"`pXb0z6v|3vşs9v{NbࡑT$w)ׯD~B)m<3LOs9!DYaNH6a@+ozwƨ(:Ee@)B^XN[W6\ݯJk 7*p,LϬLVy]εգ?NP`XMBLI7CFTgbP(^@3iaR7H,wjbQ~ΓYჹOt37W/7FMi޴25ZتdfXXU2,e戋5TJg{#u6//JAY,1O_nljzcۜx6+a-InV53\Ptp%*{p1bʂ]uU[W=);uVW˿b~#]AHUP~R/\x\9Lr&=)Jdo%m-V*ʽCN~M8~dLmuf ݦ5/snyodkGLcKvɀS0PJx$󸃲R ^%6fL+YD~؀Lf8L[&-<>E6h n'A a`˥ +绋D=xEM,d N:}(H^ oaӥ@ɏj b*vX? S .@'1 1{IRU~I6hY#'ٗs9_)@' krZ%Ԍ#1&_DT❜Ir ,./tor!݀'e?Q֧g42i7nKWN\NY귢?x Q YO y }+>O%%ˤ_JBRdU;Pg^i>\2rOl&EI9Xª- TFTilI O;%=08Vҟ4eU9ro?xU)8z*\wAT]vƫR /MP)z*؈=& ?&fЁTtTͳ::f$g%3J#*_n&\}Z~am2wӮP<7z<+ K /=;I1#qOd BH%!wX)sv8εȇFLaPTe/zRI[3*Kuђ#9D8괄GILJi7u]v˘"F[ ۖҤXⲶwFtA1V3ی q1ІLؿ1gm&7.lZ}\OQzꅎAA,t Y ԕmǿ7C]Mo!h6XL!7M,US<_z}6DžByŽ Bܓβ9]`d̀k`XqW;"0:h&A쮞/ǔԢLF/B],jQ0@5yHmXezJ>ui y#LjaE4(^# <[uT&}`'G [j`Y c~y;Gԑ;o JHd!:/B3z .`]^Z&Nn-;qBFMr( }Sz'ˡoeF0Dgw~s+l ?.NJҫMy,t5);b}#z+D A&V#i-nq!aIpZ,zuV\Wq0;(W+i4̀x۟h<G$ D#d{TIRHr]˟қK :v7(7`s[B=Jb&>Y嗏%,x1~`j浘BrqI {^ǂOom^%L2ݐ<4nd" E0[\Y[>lNތ$Z9wPXA=Zdm:] ~r?↰Tjd{ -O=@X?dA}vs׫ ˹^٤95ORf9ܟ+r^ДI5A_n t㎟)%V/|Q?*}B1*oX'.pYVfس/) ZBcm*:np'ݨ޺Ƴ'oP2"O[IFeDd,'O ~ټ"vfܤƵ^$η9 > HNl$#Qg_d<3 QS,O(;ќ5k\۩ӡNDJ=VrCK!)J-KvÖ}Sj@oc )B߆i0RT͒29 /YO \⢠V8+Y5A&/ym{,{ pes|^z[ls65tO?.'7C.mKC.ԍQ e(aیξԐw:3aC8ڮd G1ܓ gpv35 7-8AI(2{:5g@N/ePvc}_UKjpj1 "O8nZ߽$B֛X,|'ߤuEW8nj=7k״5K3*QSɑ{ˌ͇땇AhC8ot)vz`NC`rlIs."L.ES?tBmC;ӹ:qXUBK[ECZ5H?9I/~…C_ n<,SEFK\'lΗ8O=5*عYkŝh7/Pڡį("őe4hx'ǘ-Xު4UyA.5Ax3u8ڈ)Zֳ+ӡ f&P0fbl-@חʭ%8Z|>VjܫL=Cv=Qpۉ!o,`†UP. t yET(vL+יYWct^΋Ew<2 \ݣ⺵x kd^alĚN/ª!1YMEI8(wTo  nq!>+g7t FZkfNG ZRGogAԡ(3a<xbNi\/sk!&e 1m9s"X DnC)V.fF11yϓÇqlN/ +Nz@2$l`s Id*:aFJ3cfC!%vj糚2a=@E[MwrDmKش`jV]sgw)ArՒ%*{z{eyEɁd#٠c A:=jEhю`Dܙ")n(\:&z y0s0:""ӌFAȀ睵BQe=)KSOVC⟈>LY z$~ɍ M3B$U]ѓ^Ա~qvg yw(d$'4|D\Y|!c{B<oPZo쓘GTB .Ih1mJ!yPVxFcRoKԞHE2 E.=j$p2A )nn"WA@-pG<ʊ\L/Y{q/a"{z6!Hݵ@.Ðzo5PcR,XAYޟ6~H | ʪ`E{oU o |E JS6]i>-ΩyX'lλoHB^J# 0v`ۉY3N ‚y aE=Zۅ6{Ĕ/5s9s1^imNYfaR#0f,s.wh^`n9>O(g5~$m)tQB]p ht_r "~MPdkKc jk Gr9ͯLMu*H[kNDV./f &BIؑd(nf_T6!EzJ~ +o~ xlbnOd;x1)nU{ʾ^6Xe Ir vСA=Ol!Pg!*:OJ̎BT}Q k߬zt!JZ=&օu Jނ}mrglF|ҝlɑA=DQ*/a֌Sȋ uh{. ^9RMD▸Nj#ښ@i`IH@;>+\mQ3Ozz{g `iIL 8*nū& ++hhq3_L(c(z~3$V\63{3~+9%%fG+ C âwg mK ?y T,{a?Sbz߆*P Gѵ5rഉ%µ Nm!Kԗh<.!FU5tH%OPh%0|;?>{A;Q\8V#M;b߇5&sL8&`m8pn5 |o!w,%ـM8 +c}9@8%s+cЩĭ;ۊm@amG>fT]Tv>vL@oa;J8\F_wk>4QB2{*.j)[?ϭ"UK (k)|={I3hXC F7սL@w`1qjUW~/8jk#f27ܥx. id*yU_Z@Wjǧ} *-#A)?s[ !Y\i`( և(Rir{Bw4J`ϑyB 2(pG D7JcSFDiz=@diV)'p}Z$5 6 ׼:YiC ~ ҵ '~H꡼(\h#&`@qGo^ 1S'hရr9w`][.ޓG B?-'#P9'\IYp\N>g2$2{t[1"Q]t볦^2i(%Xe m a\^p!'k/|@ϲjrGOCc2du^S 46%J8x|fgܜ`3dl Ȕz|62;RBuE_Se Z >t`XPb .mwb mH`ppgz}+{d;1#YP"~gEK|5aUEk\<<9✆r@X̻ $+fƒy0:w+AՐPϞv L?IFrB4:Ym~7@/U唟J΀w_{91d&BQsMf_ | /OF$ N힞}b;z r/W.9z/t{5UN O/=}}q1W鿡 UE)y p;12w^TP>ΈOq:X0Y>݀KL>koo""I'E*ÌGh r6]e#hyG9C=?xR; 3,볰Ks7]MU?#S"j,`Lg y.suj7WT(Xl&i )~i<8]`SQ ~n5#oGZ=MHQ┪ ?T3^DE>1x%X\NM❭gPYyrn'i(OTd]b-*K%APX cq]Z] lЋ1xXo6P1qqеEy&8AQ^qe8GA٢_p]b|왤Ar'bBAEn_\@,A-9 Sfkx5D޷++ǫ,e;u!^%p|?0v,YD7 ]s`S 7^3Pi{&]VD_/ޯ._fZQTftwٛQ^:M$d_*C#?MgYm?\{1?W-aiO_El }6ЧK c9݈C ŭێ`uSUZX G֯*nb_W҉d]:1إ'?`"!'ŮDP ɒj)Gg*1ez--Z!CgMoƶFɆQ</`HQy&0ۛ-al3ro%L1:-*f7wE/|j'47x$vSw[/ŷzI/rt"TM)"rM0x"˴i/I4eoCU6S҃ZBz۞5nrtR&i4܊r1Zןe StJ!kf睞< ֤^tLu{"AX̬^Iн 8:k E;=&fgEʮH}XQ7#(TݧxՔ ERr4uSZm c]gK,%Ȋ,;qPvNgoL:z %4'cͿݩRI2eT6;T Bmg qӎi ůګ.|#w,'n%y]u6$dLy FY.^u55݅cT#{Ek-s=}R:#Dx K6sVCcP~(2 Q,"uO#ŋS'M}[c>yI"BmQ3+Qm#-j Nz.JcMU6!5>G_(00,z6UU_;#Dg=ָ!j״HKĶ1cTMOnui9KusGl@HKY8/Z\8fu }T5g /!LG4GPrܭmeQUxw*kk6^0< gDʀF-c,%^\K9$>~[kri 5!nC%#eul.?"cWA+gAGי\2Āza>FL ¬񂳨 ѠDT3h HMEԱ3| 5h?fchxX5Miyc#stVnkͅSFD梨 %P)HƜղr31sgy(k t"b,n0#aL?@pW-PZ٠l7&Ni;4["= ^iy}8~0Ĉ`srz֎*u+|Y)%qw'˿h5B$D"{1Dcu'eQ6'碌2RL2YܣB&ɦ$fvǴQCs7K"'8UI bDCncGSq#H\dSy;pRs1…@,KB!?KovDi$2NfEb[G쓟hoxf@gqan8Bȑ:_TGRo a4iN/kf] ҩRڥd\:aL}<8ب$*趥^B4͂!VS'V_}=.YVɯ W1 o@WhCb:rdݐd" Zr306 1i=$!:ZW>:z=(k^6;`}⟰HBWΘ,)> H7ܱM&(Y3V.^|w VKqmTސˎaԤ}}e+ʹi/~sn /è9!}h_ftKKLBiîЪzz`&|$`nlf@Ž@jHQ7x4*cg9v5a *6"4~RXN%zG~DЗkS׍Ē1 . njp~ З^:¶,WN+r.Ĥ#-vb;d?`+NSvlZ61Iu1Omb^1jwـE6pуYVɇL ;ZsHN$,?m9 o+3J;kq9 <M8[bg5\ц̃ d]#^dIE]m&3}ujn"蝒 (>Pp6Hy)[}>wr("-`ɧ4RrYO n5T:Q2c>k8 f)qCjK:B9x"."lÏoL"]uAڣ$<Y?P#3x)gqv@xPyF-4۞zCVݪ߁XԹsrd 6D USEGa/T`;pM1'q yS r p_;8m\n:$?ąa# 1P ze{uPԣud!ZP>G8fչɯTpHĞwi VJO dA_z: O/p<<E~ ѽuH3W_h( nVk_ϲ3Hf6LuZ;^S{hoh m.+f殬/J-Bl:4ioq7M ~Qj X-yrP XQ8FP P/ܠ"N i7 o>!bV='ME[Jċ89 {Ţ\vtk)H*DhZ:yQYc -T`VGv`O{t>M)RiOi0t^PִXHZvϠLX/e?qX4>,-[Kj{{:p@/qmvp(O}xDRg]v.t6 tcJ_EBx }.*g4S, `!UKs7 Ha) nkxI{J}郂+:YzS#nţU]Pqqh'"`OJ*0#g4ѪX"jVC$zm@=C܏eԑP5;@u WOc>K@^2 >Cy, H diU;5!`лpPEmhg7 {xklj mBw>&p`Uw* ēݥSHիuϵY-vJּ Y!4{22>Kj/ƇV)3@*}YHXBd~-lAYh Vi'yE$d^I3{V@nD=*=c!gZVT6K@,D c.?/`RA5jiEz23㰍ofvnWE,eX@aAxn4QB8 / c=7[Y[ _~K4^kV}tRwq1$}:My&|=-J!r6dupB|hꩅvPNqo1qQ4V]nbD&OYU/@\c;O^ْᯞ/p(咺j:E=H\ͨ6?;ywQs:F:T^oCvľ$ix.b{/] ԗ  <> M<#+%n'_Z - /I&)L7N6[z>SmV {[RG^"CpLa(@5a :{rI[oSXzyW95d ibi tDq}e:!bT1:MD#`~qFȎ4L:/5 qY+Z =/sx$# |4(fPVSC~{YQL6&z9?I\"aWK&zrΣt~ߗ1VL4t2JU[F$ĺ`EGXMwC*\tG; ϛLc n 2A'tU^LyݮXRb #e./ Q]EJ<Ś"78g t| EC>uvr yB F[\ɸRmgp {)D"q;-aopGQ yK w֮:g s91\[5 IŃ3UO7fGJs@NJ-Z_b}/w%&-+Wل+7j0J2IE\> {;S?/|S xm)1=AfsIQ|K)cqiosq]!hR 3yeƵB)I Dǖe *Drv8NL/a  *Qfcº/ G ׏̡߫2l~g8fsl>R>0  0{*;a2HHѪYGYȠ|6&y{RO8U; N\:|0rmճ;/U 퀚/ |ZRwdk^ :uǦ--lJOd@1l.!>Ļ!^9 uyKU֢d՝giېwLUƚQi~1ۅ'ieX+n/Ә=OH?!E^rVG̋C? BAQ|hSV-64YƖF)?i?ZEd[(9Ҟή ^#z>F=R{鞄]Wɥ$UUXD;bXafCdÑ(Ha>~@t備1cY (śҠׇh=([O]UfOKh^I6;]ꮜ[h7Ur0*MZ>j $Po%C8QZv-_`I,r;ʝ`8m9OC;F_\v> ;MY GH,`t>WYa$;̑ٶĩ?:cۧltI{"?\ W9tKPiU#11;JJgtaP ei"PG?/dHN$!lP&]yf`'ɉ}8q+ȹ\f<"eTfI:BA4ITf㲋Z* pl~ ^Qu]䀎 >G_s9[@Dn9TAbd"r|Q KŎp\뗻f$|nݒI\qճ1EFj $Wvql}pՐ A[k@(ppwO-5 CR;] #l!(0bq|Jdk·cPO{ F cxF饂-vԁ!N&^ں!ޞB'0P%g/H;˄֦'hٛCxŔǬ n&^pS) i%y+}r:"1 SEl2Y b D˜iъ3`ݨy6 EkWgn;ϔsT}R۶3RЮb2)x o2@1wJ)Gߦ"3EOԗO)di xGmvfa}.b  ׀ʋ+^Ѩ4޳»~KO@s L: Xی-MNfmYvɆ$i:1c(# ǁvyu#p8z"k8)?#%e tI'>7Gה"3DЪ+wmI$ʍ 3{)6{{.'n% R#!,E;0Դc#77@vB>%VAL#זo]7'-W##/|Vo8@S!kK 41@/f5},N ܔB%!\~Ff-YyW/b+YX\/ Ep4i+,61Hp }Y%Jba*wR1q0(Hq9`ˢ^)S6l,iz&< a>@"Xf<3Xb}ii8l 0K9؈ |(swljwr?m{:Nnm*g9sA5>/4[v Q`~+t˚gd7&tq fت5s2NVb$0C{~Mx+&ܓp`f(f (nVB/~ˣWgl"zI3OǠA/"`-B]}z? oc!!+Z4@7"0~XG9JOնY-U6X bb3l-!t>~{ ʽG6ɾ}14{U[kVWgY@^_Nan_* TݡĢBJIF=Ke ':g{EF$+=Kb q nY_#,WjՄS3\4Z} 1&)>8%N>Lڤ~*Ca(@,$1m 6N:@`>u:Q24lÅVEZԈZV:4AUȾWZOulNb V5UnZӨD }5es)Z D&/Y Ӹ-%ffMZh.9IIE5C5 0~oe%A-9q?OKU sdrEt R6cآۈ6_f[|)^ȼQSt٫Z- ikϽуųsD8{{>rbAy23ʀ"QK}AO%wlqǰp͖xc%w_IF#]P7HfNCje%I? ͝5ZۺO#6 R<%:,G)M%-lwkaƜIzmBM1 қ)Tk&6j<ܲ'"B,$c3F=?:};D셙h3`q*_8}'`5?՘aA[)H93-}|͒E"뤴1 bk/jkJ iw:.@G^mA#~dtvF%ŔFO'xDo]kvTht{ wԘe&QQZF~mZtEnUxL86{й<3ŝ Y%{\?Rd|&kK˚zy=Ml[,X~jC1QT456~$Spa%x@(Zxʁ *[`n; v-[{S&"jSrZwε%* FڥK@.!ú.$֕_Xtn(Iʰ- +䊫Xs . 6^)v;v:f ?Q SGqPS,[% 7T2N HD~q0rnINj+P߾`\{K3Awh>dEtnv\DiWM=3-q5_'T )*UI=RCixE$|\o5^GhE[7EQؘ~A[prK?"uR"r;t0ִ~ 0ݱK WFiS/4B!ێ?KIj r]+yv< ڢwW|jɡGw~mlB:v T3r %.W"bͣ5HIӬ*tA)@hv#;U"w5a~DXƗW,dۏJ7>< nv:kH֛cJf CBf+NNGLC|ѭO]PJe`s_ g&lo!Feh%ƚ @a, h+ mi=r3hebapYj6Pb>6`B?0dubk,*b +us)@^ld hY0UT a"An0Ǡi.f2F:j /bSa% k<e"~ g 9V]`r8iQUX_CL:bw2-,I2OKofF@$%ls& `/w܋ AU)7C+\D#1L١BV͌ ;I :a>Y͑pCFI@8.*q/Og)n %~W #IFԜVD؁C~~;B*g5YvI#<(> p+u^sY2&Lv4ux vc#WR2".(Ruq(^"2Ϫ_itWMѰQ H벴=gݥ9] cUhu{l:pΜ]FlQm\'`,kX|~6Y%KɎW^QnG+ެw :i!ys:Qx~I[}Ѻ9?iC-+\ A+@ (^j`é Kb<'YxR.lQV(̞v d=DL(Ad V|Q6Q)9sT.[|I ǧOSE+QC%PYEDVGrӠOϤ)y}(-fNrP挒 N8,7&' ~w֫N!0̌ʁz_ }jKc:b4WL j:0"Mh}+q㡕kRЕoAQ-3`5Yz1` R\ Y$۽$KpyGhI]M#Uf66$6.XxW:R d|Wi&^t1Ѡ<&+8 mEFET-(Okl $x&˷pF6|* e֧Rs| E  8C_?Y#Q i* We Oc[9Q9`0zZ-Ѕ{وگN~C p wCh6YA A3\~qa 0`d@̌Ԕ*xni>˯;IO4*U#L~?(D]y\sϜIJ8/…e"c28)f D?4Qvjey2um4Α"A]i)$ҒŶMad&gsDN!YY۫۾_MOTTSb,id0x [#.=YXr(h244цז&ӘݦrڒЭrsbfyÏ:"JtbTW%'d5L1ivw%H#a7gXrNInB M})ctb&s~S,;3C}-F 1Xyag/i 5O#oAI8xC4Re Aa8#+.qlGN K e; S"YփOTߠ;lhFғwޖ dsBD3'^g1RpcND*r8`fl&.o.-4FNFSC^ >vc`Cw8~UMS& NYzo!.ejf;79LB!KKYC0|87ɣKL0>pN 1E8(~(F5ݐ?BotYAm)sʼ^ *:p"hv9⏍eƘA<[0CBrQ?= `?QN5R[j¶d+;!hհgbxJÚ?R: m&T=EF{w9ŭ!U ,_4:08$;b{౤Au](Lߏ)ŶAj5Me`yG~X7"ۻ2x\cITAq yUlG~ȶ"bc#~N ]@/nX"OPe_B xڥ܎"yu7T @;?^lj57xblcYV Ĕ\4?bNh #˵1/O)ce4qc}8C'yv25v5:-v|NAMv:KEgмcX $l*&Ǐۑb>e& 9j@Me;2;5|x]y=%-}у7bf-²Mp YՂ(#ÙgCiq}CbkiU0f|f4hbo!07~u6kyg~23N<ݥb[Aq ܙ_A78'G b؍Jd*Ivx i+.Nlꩳ ,ob,_yPe{wN*'c]8%Tc`,b[FZ^0i +e,udSՖ߱h ar7#)A_K?!N*` $٠-ÀQ[. }>n$r j8 Ǐ=;krabyCܘt* V4  7-[m<]JjRzL dǮQ06LQ/R|RRG{Z6 MQe6SJw 3*^E'B%,kd:`XxJ4 YV;]kfހ?}aB'}q%x-ɫ'MkXcńN}B>̨ӆԧ0 P>_%|F. yG>xYg" [}6@$|*U  +꼎eT(uxDG)ȩi AUz9O PH oC[(KssN9VJѕ}\Xh,'E=1h#E_!!<#{P|XNvR&gQZFQl8PK]B:YloGfS'!*UL7jߒ#"*8#F *6j9g=[fQ@4f?MTCr->Ke@:Ϭu~٠o\$K?[gQHd N>8Cz\|v[i+J6Qu"h[y]o K{yaF2+)&n9~%WL q_b+l \<"ر3Jl#r5ѱL^P|@z b08Ĵ67v QѢߓ5@VFMdxyթU=LTyav,v_HKEɰBōپ3ўFRI]J#?;@W,R=>ED  n̓uXl*W쀅GY¯0#ҾuS-$>fMGW;H[>VE#uɉ3Gkv9hdxyqH[4("jv :r pNJ+H?6]IՉ0Tfǝ%5K4~N:vE1->m`R}87t<>7!=a3Da)Jj'J[+OKݦIFZ#HNTrQ^L%$-6%xS>|_l^<#UErġ VTYәE8{V 㷟. dA5kvs[jԎ4V|2DHlh ^ >mU}/N< 0zB"{*Bf.}9EeemTB q4+'v 5vcSGstʲ.Wڬ8rO dP+,aaH˧xc_I1F寠>HH/l=̉ho.~Ѽ6&mm/&#r6B.03[s]Ns r(5?Mp#QDk*Tq` Å "x|V,aau:ertilYJT{Ab}e&"C~{qb4ObR]Xf 6zB.t;abϛ/@gz왖[CoZ;M/c ؟ rA 4Wؗ!;;_J,IJ\y{:w1㦺5_& ^TՎ~c8beOS*6M>.32uj8',B d1rJ0`[km+<:rP򀫟{`A' %U9Ij %Lxel_v j%0Es{ L uV!2L(h״m,;z/LN'񠑾;꺟xp1nRb4QJԛ 5^ķ\UEP%dbC?rBMn:U+G]4^_=)R| Gvi{R' wryz{,;;fD3crqbj20bu.>Tlـ/)LiuoN8P,^6^aQYZ+8i3أ3R]-:9ZςX?X*'^_ nv 1N-,bֿhP&2 K "-x<9w;w &ztcuNNYu`0J&TvAmX^L;L L@:h?FKԚU"G7ì{J}H>8@gI+VU}؛)gw2P:oMA-p62\FD דr[Ì7y7m645*K^8ehDh-}`}~(5?M0+faQPU=7#g[䉞 ^ w,;19jH .MVsj/CVЫ/@'P eCf+akIASm)G5HdIZr_!J{DB n< Fی3 3 Ћay"xf߰n{g(J=z885ACYu6I$fp(374oM F'$d?rEy\Ԥ?x\K6&% /K5SjQZ{3ND]y Ǟ-vxx0S:)O؊FƓDfl%Z@6f ΀(SI83b/!M+B HPhI=$Q#= cOi=oa==ۃ@?0 243Z(`>i/5LӜNFm/E POE133z-Mk`Þ`{B#1 sMܡCَ]؃/vsLI K 8 \!6Ys,/Db2(Ʊ2oջ,&'pyx*܃ 9 R!\rЮn֚QrlCI=>^3:6 fD0B_[:N,[UMup Atma*(.T5! qYI@O)l:קS3CտX$Ɂ]V{P!Fԥh[ff׺o_Ǵw0ԫ1Aca~#}!=;K=|9Lk#GV6"Iv­Fg7ؤ[` ]D:msfS`v> ܓ?e ޥʝDhڬ~fDSKR -5O{+z=w,FYQ)}/(!TglC:RIAo+{!m >M'/4lکBMM̙*R64 請(DR~y %ՅWfsR}M72K}AܘkЊ% :5M=D O󱿒&2ώlpG N}iw␈sGL0 *`s=Z}HcW`+AndGVJ0v.ܽl$ Hl)ybbAfY )I@k&~A_iɄ5~<~;\XF5ak(| !fRu: jG١jZ]BɿP{0B̔Ұ.diC.f.fP׌OqX#z'-*x$,?f6qA /(TؑߛZcxDi|qlN|5<_3R/]ߤGH{0 ͠7mw'sxU$y}ø 6딛W׿Ep`]t%b`!%2~_%ƉSUpu>i]fc Lq zW;vZWI bӗk\s#s(դspH3Jߐgu¬ %>R>Y僝nQ#9hc5E`}LAp3>TuW 45S#8`sY_#azפ%wp0 (6DDHUBkKUocRΰ| KLHjг ž-F"frb6"̕Qs-YfiWA.hy#|ᠥ5FP D͵i%r3+ Q7*$HΘ @P> T=j6P%mXe#W).NU26Ҋ]DQqD! 0H?KLY*x6%guÈla]XYYrO\Pg#G< YkȲ?g(~!p$%cLں @rVoH|XR{P͒GR̖wV_ƌ(F2Ç.?KikfvWf XvZiybWxEQ\ 1FjlCƒ10eB8AIn7;P퐹U]|_B 'Yz| oI #9g&4D rpMȧ"T8Q` Z5~ڇ/E;E'NJB޴&$*Oq^~Gu$ 2jܧq *{#LxM 0A |'v{̪HA3 wFV!(e g16˺&6 yb+ZS|r}8`̦9Є_Jz;L=_nR,:jeH=|,^A]td _Yy,Jʍ Ncyߩq}9Vf dr?c(\NΘ k8:dw$^,SټDy ck8cyE2[fߍkmc}lTvl?\|2Q̇v!yl[ݛ3!~)@7))ْW0=~zR/Mat8ItP,č/1M|T9[a7<>.%"|74xFn(2~<Z` ͍KD S/r0G r9+]b 4՟#I.Q6pónH͔cznm=mp_Qdax_BUiiiW;4di2c<FR29 .ryvJ̈6ײO!q?)_]*wY M&"ߢn[Dqm$3YHv /϶9?Qj7B; ̝Oiynυ@q/6O BBլgOU潛/ZKr-6M{+ҕ47HU$v_ˡ~p\@&V_1|a@1 e54͒~rUDa|yF-=W#[sMdAlbJ䣢=T_[^=q{YREc ^Jt2R9qΠI(b#pǩ<Bz{UO7 ~\X okxeϓ.,"RG@^hzJUn$ ̎[R5=ZD))lu!)n 6̫2 ׍*p[`; `'yz%n1tpN{Hl u 3i#0mb#7s9ցMj.c0=%[U@14S!Ew !>: Xڄ,Hx *׷k8NtZ v* &6+1W]"hNUX5,fm崔6mtҸqR^ӷI 2y_?"e/TɆ˹21:N3ˠ;VD>.Fybc:d<%IOl2OԨ3eQq5wN}c`^8_˚d$LK$q!rM_\J';<'$J±Im 8cWh9F27AG* $d ?~7eG71C+2r,D͔$1<4`lL_?5j.ж22kC[D]k Q͆Y>CQgXJ5T;~RsG*m ֘; o痤+s|3Z)]5҈W[ޖMne$TP߼ ߥ|?H~AUnş,h.˚SU8$wfу]*{"%o@Lݓz[~JBq$+P'iAW+ .%+U?ð|AF._nu|??ZN^/CoV@OuJE'NW!@}W<#EdeX/9۠?I21Tҏ䕩b">p\jGz.K廊TM ' /җj؞^շs"BPl[)?A;jq [چo;U~.Ui^@4 zqW&(};Y9d=q.Sx&Q I+S+*iŨw\(žP٨).Eb4.{ sho): %)-)Ű$C9«tg׷xjQ*uzŇ!UN8뉌V0VvylsgI# hvhdSُs|JQC}wN`T5u>S97*7Sv>mIwB,Y $qYXO,6Iv\Vjn*ۃɗR2Mmk}/( P&y#~"c/@#b9Ԧqd@{Y~|”d6ޛb*Q+ęS}!Şi[E/d}WrbÍi`G!,]Nf|HT!0;QsUFj%v|6C5d:w}pMYuTtŒmڶΎ(:+sc[F]x0 3Q'vnbHtnR6gWI,"Y|eWTYxbZ$U'6-d0P!9PϾ@" fw>/h);}LlБi#=WhRpP_Ҳ轾v鄗gb]&:"ā8L"IXYҫm%rpɅҟD]fgs: 9E6µTy>sm>t(Z7n,r4"T7EKO7R/t̂j%s݌X&4z?F$mS#0S[`sN.=#elNHEMġ6X9ڲHk` fm"W 0DMlз%D|2w"O)n1ƈ1ڠc.p]x~}Y+'qVr.5 I#hv`dڎR_IR͒!.tϕ26u@ją3=U]kilƞ2a$.҅v`?푟^rg KIo&_} ~gr P,}^Cv L<)UީA _mO[Dे0=ipfG7K܊DmͧM!|+CP ɝ{];W6/w3wtZ7 8y$䰣S\>L2he\=(zb^\@DRbνD^B$eբ."S2K)hX*tÎ`yZ+Sv6$ i|Zރrj7DТ+&tiݞ%:Pw-o&Hk p`հMȘ*wyMhgpT ψ%vkGo&B,[!ܚ|A{<+VR~aҮAlY=ZmdQ:5N)}Wt%k"xiRpYl|Cq5  [:N#}Lv!ÇVLXki߄gPj{c"|ԎN62YS#FNsv š"4u3l'pqԕt 7Hq>E/ycκJWdl9;[#џYNt_n4Nly NʡtB: !Ò݄u[YNVy?1#v&g?x?<ui@ײCr O)-6͜BlvT.@thylTzh=C)s4 sԲX%:bk<1P1-ݽ$_ׄPoӴS!q ײQkgڭQˌ Qm݇wo|f`Ac/<Ȳ0 d7;ʨC.~d㽦 ?}DLCuI2U`!%,Q8.AzE[H7!}Z>:PLW>ym~Xn|S+u\㗇ah uV iw,.f})Xl(LMX-YWirC[7-MPzd ;vDܮR)Ć? {هi37cg#`e.aZ kz(^s4FVDtW_*F+z`H~in8ػQaRj{pk} lV ~j/669Yx *-z5AtoJ1?]2lJ'\qU\ɊۈxT-.\jͭw/F'LgC,LVwwN:~<E|`}&#$< Y`=*Z IeN1j$<לlDj,Ť4n,ㄳ8/MY}FU ŢĕiVz~]02I{eg6[#>;`~Pʏ`wY\>AD2@}2Ĥ[-Ez)/%N7 ~F\s2K?COԚ9$_k^RMH~ \?_35$* \KXv'kES4MRaaf1} /w4ie:0NTMN8@9y=I`ySRC H򁯦clc&'#'vm4}G\\B9*\;-" 5{_UQa0V4=8EfD2"c˾Oia@|'4al=`6+-<Ҭo=Od}m9}>A?{McJL-q{kN(GV$).H-7@ ȷR ,CѸL)?xHܹZ6/JJӗxIj]_9[1*% (/$DuD+>-~8?NSύvoQ۴ށ}deP?h}azIlm` )'ȟhk4¹y93!ݤ.A٭{(fҕkӞ85Wf~SѓA[OeStL>6؍7| %"U$K>&i+ڵrLFq9]ec2Bx)ov0fXx}mbBinbO1@[-?L2a9JϔLZ 63=U : ʆfl?S(>Y:3aX -*4%yi 1C{Xjj<N崾'GMrrqxyYJpcc/Z2 vwFkl.0 &nТru{f[A8=n 0rSGN.BeLE?Zlr)uT|ٴaʞ2#51ޏBH Fj#jgw7NW~'p r՝/x}܊VmC!9`l_Tx -OG-OaN5 l[v`mX3û=e#CC9O G _<߽&Џx/\>oCghi ᠙o2LF񏋦kfkbIVj J@2]Y\̪4gH K_l#9mOv1nMo:VR6 lFe;;DF7jX(R^e@~[1>ÛF( y聓vꨔ % ]xPL)N qgp'M1l}#z47%=d^d+${w0@_'[|޹9f𗙁?ۜ*`RTPVB?E O`Jft"ˀ$Ka{1BM( rbyaqQ _{JE|c=Ƃ ?KFe daK/KO@I:D"!`kp%_L/$U`& X`nĿ:\.>>= JU$/.xᧇI^M¸vثުT]^Q%2v !d%m^UpfQ;H"s ?Pĉ.a cGvP#5'YoA ,Sͦͷ8v?8r4kLOK$ߝɓu4p3$#u72΍-q͛{yim4 f *딷L}\)|Ӓ|56L_@ $9{J Hugd$~BL(/IΠxVbZZܟrS]\p0 UClNcfz:3Wx\bWSbz/#Qe z')!MvtS9 @V 2nrDS$.JFe^!zЀd&ĠhvUc^BU'q %zvo4W5VW(s`"ZAmDZy9/ Lm@׍k %*'׵e6=q% XK!ώh'>6:-^x .?pR̰{S4UDk-7br1:+ydWW(V:_r+`Cw)ŢO 熉8~ rՍ1r$+eix)4?}1&JĬ[=6tq2/Wn,̗˕G[yPszsk %9s#e&@ gш'+ 8aA PXlx3ȗN)[\wV1r.-2^[ĎS# ,E< |br{&ZT=qld v3K`]1\',uA3I ΜL]@i"^ufj>n4QadDaऩkVUa \<ꋛ)P䂓1k#>V^բbzޏ'83V4<3f2yfIV,Go׸wЂgrWE)Y>,Dži7BA*&`.aN.30f6:Q$j,~(x9v{Lb,$%̈0}3pC 1U$ΥJ'Dj*!Y9kgxP8k_@k U(`1%j[kLYtz||BqUs|*ؘ&4$DK+ 삉>sP;ߧVbcԤ3$3Êp/Cvn7\g <.F-)ՊK=>k[1"Z!FY;W g)pcQ?oLdz]ڥ%Diu'ً9;dΦ%bwAhÂߚL;&FƄBkEET[79p}:v;? ݕYZ}y"^W#k V^ij_ av 2RFhSG[#fvXkwEy!\d"<'N{}1j/O:I{*..5Q]cZ*C=3ϤPÏ#Y|"D }i w}-h0 o4&Һ?oe뵷u=_W薻`٢9C5e{W ;VWKa YRg@wb}PCCv#k>;pltop_授zJ0}IV&5,kLt') X9gocn1"TȦEE+[@}=>_ܜ' n^/3vLv H /"P;Nxl=R$H,rBKBe$?4|ٙA M`Ѡ9]:toiso[N~U:(Sku]1ֳk|6m _ၨܒ>u_JV։ #[<|6#HC]zؠ:X+"Iqd{er sÕڈ# )ܓ|^ϝ>js1Զ7ۮ2dnv=LM9AOY TY.ܧlFISƔxxgd,~W%Y"*fYyέv7 >L̀)pb%#ojSa*xb`{[Ucfg/"dЅ8&,`W̦VY*r8z^2LӂSFyKh/ p2J(y,1tL)c{h0Y}=S ^;xbUNvxr*3Dx%˨\4>~֟B_8Au%/ b*} AllEDxI 鈬_<5~?AmYxfʱ_J Qe'[@vtNHEC`-f+'g)9RYR% :I|Zo>֥h 5HbMmvKb]s?JY1jն\ՁM´w!Ke%aP<=3WHA&y"HcCٚX6,x]^C,аQbKVZP۠XPذ4Qtۤx~ڻwAmb`Oq'P_fBXǰGZn@QcQTX hj<=@]v='E6 Qʸ'0%Z3,vHp'^U ? G栚 6B<aG18Kj r툀i:c>aՍTH6C虏wثw 8aB3' _|õ+8=3YwO d{C f $ݴ cᓹ= 7^t*fkQ xЍ }׍'Vy8YL8 4܃O$pۥԃK+8oI?&3W޷@( |#abN(Dm-F Ru4OBIAz<r߲i"pg5};?g"DzݬI+gquªIxeWr^3V:~FĮ$>13ZxS]oENR$l?(*"w+V30:lS.:UMd+-m `[`^hf44rаs:? ' 9wz{6Jw*x`G{?H9r[b`R] 5{{FͰx]loƒf@`'a2~j+u=?u3\`* J:CUmQRG{ B"ivr_#1c09^?j ʳfiBx!UMNkBxRݔ\kqzX7D\2]o 2*4>υi^AUܯ˃khk#~CQL3$mU2i9 <*l݉pAF9K\K  ?gP#AAdf k rfq<#^~nTIL CZu>GVISsKi"zoJ [Ly%Ǵ Cl:~rDB{TF!%{3? %mh/Js̠@q!@`!;&åe6Z 1bn !<`yS5p|Hs[\Km MNM ï44)>~&9QN`2 /wLjܴ]@hJl*R1CQbYD_c!EU^{SAio,|pB%:="RӬ?./@А0D9 e–DacM[  `}f)~_G ' ^Ⲥ^1 YgEG0GM@I1vroW!Έ=zdZcPqim]9hwP0{2aTuSoĎn7-≪&ql@߸5*/rAZ֯)шUX H*5;},X{c 2r'NY q= ?S3$ϞN'{1`T#cuvѺi `-؈Ľ$C89l:ۋCj6 @|u ֮ l*Y+l1^Ghl؆M$POPqY+L@֪ ͕w-(T ~kJn| 3!mP"LXr5؂fXg~My L3gkc<~J*?IFfqw>,$~| FJLfw aAr{]̼Fi *`N{y1 jȞht_M jo/ݧ靉x3M*"]?hW2cU𭤖cF?܉ #+SXE|ݘD2+L0-$ˮqԈ<_SǞ΄}H/{@o>Tzbj] Rr^/Zl|gnl&gBvNF+Fu{('~2}T]`t4Ee Sկ?oE~m'M%K`|J[Nż&+9 X:wV{N9/pik:Tڀa)Àd`oo8+14[GŘ# V~RQUbۃ_F\ %3i^*WAMBxua>c 0oƖГU[\jV+v.2˼!TS9dH?,5{BSG:%ZO6YQ .{նU l:9STtޟ,ꀺKgDE0.WyDh??sMx@dg艜,usF_O9?Ăs&OX,mF6G:L;<& ,' 8VopYqC_mPulؗ&̀l*=azsk :@?3Y_]ge/Z`+v";hL6+)ZrXNBqfd)޻lzj6f8W=W3!2}we`9>_vj7M ?TZC1Vyk,njr҇ OF ҥ芲%dHp?c]Ot/u{윟;D$fMmMW<@6wrFTMy AkV(X(qQ S/@.n NdCHP\ d* ͟φX\?,yV#ߪkd&f/gػcMu2I~mP@=O Ml'+b $!,/xo/^Ec/o+|c8PaUrXm}p0rKB/--erS>엱EAlW{Zd_1UH|bJ?^ dQ:VRuCol^E[j[FvU[}Dц'ϣމVVխ&52(1QɷY4)t=W.Jm|9I_n9Bؼ"EhXI~!PQ|,0V ӛ_ySfr=<[ s_NJ`~;N {瀑|MK#CяASI] ƭo\ᯏ<ߣGFhXخqNmOAk!Uua6H4j֡P^HKjj] q 0pr%쓲@/Mbt1kXl9< >DB: ̊ ~+%ASD"3U wB,2\,3A>L0w#歕f*j]HCUFя؟Uvs@<@0՗s'Gus-CGynY3335&!> f?vRю`-GGZv**p0~ {I=a19 Bu6n *Ko2Fw@yMN'rpڐ;S5D8fKF4 @ <:?lS(4!ъ}l+y[6IEN+tjշ@&0LfH`]$q93&Ta"SIQ#}%7~ of)VEv/be!gtOkuhOy% G~ޓD3qy]/(BB)k@{܇#܇8H3ٛ7` lA{\V Rxui9F˘ڕJ zGިW/>cnN ]1'f'J-ƗpXaIGD!KT%Sz]#ЊlM_%mXGĹ17cke0B"F]iw=u,L1{W1>D[r<\1`x?΁Ź#Zz5?sB.5B>z IEʦlJ|9ޔ~g Fm|Ht6@l:J?EEۜPUT#NS^8Dg-oL\5/@m.?o;̽k@z ycDNV|OHE/EMoY`!f/"dhW(rv1-"Ǩh+\B2ºu]<1{ .% 86?wTw !> Ս>ߤ7]ꄁxCOT`f"d9+Y%r0"о&#x3(PLd$(?lz6~!ql[J`p?PdjbjC[Y/" Ү2+[0[VYyO~Et${ :fv@*L`BZM`>.ȰOܐx=ُSMH_o#lL2сȺ st m[V~n1ko *v)1u `Rr۲ԣLOAp|=Z #O1VtVC;-oؑ#\4>4=iq}0Ԙ22KnmH( 8%;U!ȩ=}XnҹGV~er8y &ܠ% ;VMza '-m\40a_\"fѪ/'i'RO!X5^Y Ľ /`.8 t*^72vл 3'MB׉t~ */ Q+ (ym۬X:`< 6lrކzYZ.Ά1N~R Lo`/kϖDqIY(tf;'G0uYE(fh:dA>ڤMsV|{ؗ9@][+/%w\+HD^S*s! eppϨ*^ Q7"k 0ʨ+yNMY3BE<}^A0sg+[AoUՊb/}B=V5"lcRҧTE[[oĈ9^쾀{{rgoiif:BN6Ivu&>&IEWjxe70 aEw KMu U׷"6*0n(l kq@ݡHܟ52=H{oT(ϱ$g>cg`YdEDG}^yK !ZB}q<3 E3AP!/y9֞+vfTfxb[S7r2wodUe%&kT=xWSiͷ w$oV|U 6n*h:}lJTb'|NGU v[ Ì0#/n[s.ڤ:pIl!t"b4_*<䬎ԋzIؼ[xXY<q} , .Z5?hgc(C[ZsunFǏarIW =%RitjKYFC_75p U&J8+ "}7X_Ec$p B ]y .s':hL%(@*hF >`B׏Q?$ߡ\**Ac-otI4[/}{{|Iny"'h, Yme! [H3 B/k_w&@!E,IWiQ![.-+ Su|fOuymːfn -$b+叙 ӭw˒="MP<QRk=0vȄqOaCT5niqP"w?T=iVxk[ 薊]/$o+@?(9~}PRO[2dR_S'Yd:^qc`:tUsK'Nn.KzÒȈ|4Ϻ`R+pڕ_Yr`V]-`S>T{;SH'[WRP5L!jstOM/ԂUdъg7HjI+lPjm+-CBx=ôb/Yyt$ձ]Ua}C]IeZš l]ЬRGET{~KA8idNЄ2FZ::]4[E$3 5cTpVj&% Mt4]}߸ʚjl)ҋĴ1F&k@ *fzWɨӥMzj^⻱ {>ZAW+#1 8D˭;rӢ.ϲj*S/-u[x0Xp/zv?پYG9n3brZV#c$и9NpLѺJԶYr{6tS|F`f-Lu(u?]}\I`y}d|1-wyV5W!IqzɟO*Ux벁rd D[謡De&&NSu6joJv#lSsg$doJVV& g-QW=&pOwľ^42:K>OozeX*LI<)w()5MlEMa+m?" >{>YxO̶|"|" a_:%?Z6ޯ@,6 95awsy %yYqY 0yj"Q X<9yIi u$dUq!("3¹ޕS WS1XwhqCPy`(Ȏ!)0oVpi&n=?SL(ȗIL!{udG(:}VkR }m,]ӱ#Yܩwtxo#}Z]MAE U:@+K`F/%1"ޤ`XBBL@7v3])3tXi;XHE8H=* Qcq_?p" o9&)(2 NYqm\m5 V֙fhG V=+=bTVw T-ҋTS+P$ݮd9PHX"RѫH{G7_|K='Ks=`&zDϰNJ4j3ܘɍT[9a$>fsk1%Z_+f\ uEy+f2RyyL(M@k*uͭϏХ_ oT׬t LNeFW 8Z|x)q0X*!8³Z)O=iϾ4uQlC^71b8~0Yx7JnGdyn[يމ'*eޝH" 7ªJ>y 2.bFx&&0dFS޷td뷐NNfC5T?RJilQ? 2|V,Z$Ln:C=;5ڱS\13[U (1 !JfP$-ßU湿ۇ5\cN_?h w®N˝դ:Q b k!s~ɻ;6.\eԛQBCEg7a W6ȱ o5kiW@: "aj#}Z ̓$^,I”ӮtS~pV+ۮv0 %VO'ǥ)+}HfD2Koæ]"8$5oHT4 z`tig;tE{!Nm;Ω!% *-"TMX/û b- =(|ʧ4p#ccb9q6GgKT+ٝ)-k|,4@h]KvaKK-8c=ƞrt:AYr$@5߁@ aҠo=DWO47 ~rxw;9{|eN K\{.9I:j|-=l'͇͙䃂YZih~A>d”v{EGa;ؒ^{O3T. d@w-[Ga&JMD)BSpm^ &=Qiz^A6i?N~Go^T !5ۅ<%CNX~ɔ$5 xT{KBhc9uN5wdZ']OQuybm#&O~e[cyY Eت.4ÊB/?^ʾ|aٳd ( r'q mP'e> 7zP 헙B o-JQU.yx+%B aRzHIxҮ|g]Wp6u2K`; )Q).ɧ:v12jų?k0F~'#'3\kCRv2: D ȡ tU\֞Q$^]sYҗxBЃsxri)OCE3%Sq/=gs'#=4|+SH-`$'P]JF<_qOr̿djy#H܅w,:"VԐ=EL+ܥ+,,;کkς}PJ 299 qa@a=m<\wb Ku+ 0d6ݟ&Ai@}n䇧n YI6=<,C;iЁziS7{3QNe]pJfʽ\4CVA%|F/8MHE   g%xw KY{wm# x_F*>0>! a-< 2LD*o<%ЎBńT+ \uz&5O؁C3T\~$ǥz| (8D^  cp…3iN&CVD8ڋ(zxagb+*Lɨt[n2#jƷg?_UJL1! HkS1E_pnI7 AYf}fSvLP4zbn$^#)-m-.;hBY߱x{~3=7m3Oө 5R CS@o ;P}˱E' =c%.Slf{SxAWxv]zb0oJ o7qk r]o+9Ι:HclYX;[: ȮGq2#EYx[OzSj/,qZH( A:eKl9˲nV Ygfxu(${c"zLdBtOFbep"^3@,EYE=MG˕UEe!ZV2HF dž](BL6  jOۡ^<:xĵٌqb=s bQDg ۭ\1[#&qrE!imoqe9LQs!5gA*S{bfբvwrÓ_~,C I r[aeWlpU-xEeJ1>F`Ag\gVŋW故#˸#?w4J/ RCD6遏s >By.6ϫ% $M iki+.YE6 F A[=lNt)2a(~llY+WB5 nS[yTTK!e'=C=]!CtV'LMHc;9; ?VXcqcʚBD5prQ`O>%dWL%nVuNps$A0?ϮgU5;$%gCQvC`>!Nz ;}ឮ 6n:H c_*9g|9eg?DCZΒ`C}Qԙമ&4\; ^3g).aK,)QHxKU/{|vo#"68S2m1FHjc|j)(cme6[YybY[JYDfI3fH\f^k/T'O[EwLdnو (#:aO:`Q#:^XpLRT'sĬSV&=: nq։Ð]J48T?eUP!b{D(t5`tsTz5Gk߳sAP`a3!ȳTSt_-?H׃AhZzG?ѳǿe?8f%+2꫒^\9N;s1V1ݿ6(z)gdhREz( Q) gs>+.ݮ0TxFu᳍h<Ĺ|Gl1}uj*KIVB04WFO9 L$#vp;eQ-L@vbA1\%ړYRD@JlSeb@ĶͽV aze6qP>0c^[.ĈPِЁNܚKuRQe¹7?+G7_yZqD_/bs+q&T[%HM0~_C@?bOoKM|2jz揮~TEG&Iv"T^:Ta_?pq\xPmb5(SJJ/dRLHU\j =W7eifH+FKc ,=7g~OW1{O}6 a[x}e s~ýX hI߃Aʃ%|`t< Hc@.y׃ߌit^ޗCM~a`+O G5AX!y|tKv\)l'U&Cw=!ʰ. Wl߇QؾZ͇QU".ZkmNHEsX޶O_}\zxK2˜m]择&zj3kR~CPq P\ȳ誚k(C)T|^<tHware_X'' @}.aSa]ƷT3?*ۢ+J ;3K0B&>\~a4x -t 5]?(3@88p lho-C0T&]'"1P(mExApu3"L,,Nj_-*WthL3(cZ? G\"L/o칻nb|bý,E{mR7CI 8}PM$w5- G=/)|Ɓ,:RƊV*ZS8=ۈ>_=s]$!k~^ 铓8S+F(^v'k4|+h Ķ}[W80, Q5֔,3^|!4,D:q?)fX+աⅼrF8PUN&$kG،OF!ma&ڙ$J*>PSmb4گlx3vV"ȏb|BѾă*&oJzj[Y}ZKL(&z'ťc?S<`QBLqa=[$ӻu6> |Xk0O$X6;r\N~|bDFfOx` M*4cgpѶQ u(PX\:a Nr,֎Szɍ9%a9rh/+fWdZ UJ^X{*vՙ[k; v4DwNEqΈßV|d(sB2y2cd)6M`Pr;l"BwAAtйd9QÚmϾ5b$axn1HEŨ6aR|r @hJ-y,=aN7Ayñ]WcQ tQ EskN?#v_9+P$mYcZ.'* tl{]5Zhɫ23NS=箒.[Gt1SOC/DF^d~ :]U]a*цk{h_\odvB~m4%M+2]j K˹sq4"V\e6r %gn:-/ hRA1I0pLڬT?v@9%k~)(d`2 J`RSEuj<~!oaD-uלVM{Kd%I7xozx)7rF `0+e#VVwZ m|F}]̅|}. x$Sۤeיa2߾[ )F:*| yaN{՛ ldR`tOC,hUEn7nGsCZ@o|*E1\bdV!-&ć^'Q$“حMn-ĪKjSXYiv7E_*-"G*Wf=qBcrI_Чh%+8LiȆ$.%Tʹڣ:;sb"aQ+4HJcrYLa9Aջ%H#APC]% C٠'!#R;*:*D" 03mVoDB`[I[h2mU5J^MU2'L>ԛw.;p6L L $p˞ J-+C* e^PtVB `ടA\8F0.ÇvX-YdiB&i{H,XA1@S> EܩIҒ HTu5$}ҳ&]ZcFVzH&m8+I{>s&ZVLW"};"y@j 4UQYY#k| v i?"dTd^'m\U(Z9twf0v_XZ Cz 1[3(aorJZ* x{-z|.IlPN@ev@DуCv:Ak(/D9wd6U=r| [2y"% Jh$ >y>s{#P //RCl! ?) ME N 6 7vҲ.YN߫T,Ֆ?N^7xN9&A'q3Ƣۛ bdTOe;5=mK_?%4焏 4nR ^%ZpO1|>p<#+r?,H3<ԇ*n(t&xՄ+(K z) dϑzcŞg*׈gØVFlLtWrhPfaM"ds`Sg8ߊר Tz}p-48|#ʮeI]RT>qQ>3Z =I\ן*3SCr6a*HQ+ݡ?B9GVb_#\zc}<Kz ) 7j~VE]=Wm2K:Fr-Y+Ty}Hڏ! tުxs>:KL()؟hPy˛jXB`1F?Zbq*l1 ٩psJ#gZJ l٫)E+q =W:@Slt 7wkaw_d$x(ט0Ui ӳY|13w|mm/VYf)To%m[*`p3rGt i5ca?:k e/c1uxְ13✺>3Hf>:9i0Ǥ}X!l0Q x>W8+T),T@ 3/\ᣊ=ju S1 9uIH={!ONk1eղ,z4W^C!ۣ=Ptr+74Y$a}6Q~KUI1T6 J}kyvBg'5Mp |b9ԤoLc~9\Re:CRr2[U6D6@0YJp@~; 3MK'_e)+ܰ*sQfƯsw⟈$kqi> %/!Ӧ}Pr~ ь}jq5B@}sN_?KŌ7> &9UC~׿eaE-:tiPZ2c]&/쌡q֐uo|Yvmc Ԥ1"*cNa&K++xb6ǐKKfDyEЭk|q[o/QQ PޥT(a`߯D~JuNXu;8Wb !=ᅦ~SY5eZW=109Z=Qs2m1 ?WdaRB0Lk:!mF I:?vE9R2_!T=75k!veOӑɏ)Bo]MX_+ n{hg/=ճ(ο0uBT»Y%[oxta/r="g7k]h{vI韺ajHH,3eѳEr~YW1G~ho|'6F]ch:.MnLgizY@ ^ jj]f ($rK ܚHr(Z`/Yů~hͣ,TP>'/ٴGrpŖnas >4g2ssG0oCwabفM RL} Q!,2ʎ ޭJl>ic"fIJ=v .xBl61._U,>W䡧tY>'5A mEƛ!uŖh;J})1Bmpàƒb 1rH}ZqڔgiQ9^aܢZf-#v"NURγfO§2% ?x/6Bt>z0]^ I&LKbֿ2h:7l]NZ=;eATwDJhKJLd;D]9UDAo<4S\x/-iӇɚۼ˕AvCE[>-D$' a Uchտyүֶ 3kbՔ<~#FSe_SNNU c1&RSm{ k>ψઙȑ&9:E_\*nl3[XYI~r'@a*lUw)Y-c"Xfߢ.NM,|iNyC1.b߇ ckS'2"ȃ@Sɓ (ԅk"[N5;dx(A 㩁9;J Z'宑8JD,X< XE13TCl";Y3J}2v&%a]i5D5W)JKbzv|g0}XHS'hmnq:y)pqugO6voN9_mz2&:{cRl ] ވMRg]Tض[Fqt+az0ZQbgEޕa+6@fb92&ҞI7FT'Y<:x{}ށ7@J.ͅZ;kyGq2i[CDe#u7~CUتwi_S\5?krvpX QBur':P0.xFrlOJmfu,)na{oIfI_o,XI8<yesr|Wtw]N#=xɦJVbXJy7rR<N&ӌU*?Eo>TvOnpMK\QnS޷RLĨgρ64 S}-UTW?'L&vƨ1">Tj YѺ'EL8f2o ~Iͦ̽*j~ɂsg̠̔>B FDSY=Kžѽj{)'7E$ԉL1_mʗE/)}co{eb96 ZRNg&aN`|SⳔ\2!b0&M8z`2wa-ʤDfjO_!_"W' `rfLD6P;. h$1(O_x%pge`\ۅQ!HӾC`wjbZl /mYE ti~ʹ 99J⟛j1)P9k. ς-fwrf/ ME]" $;iV 8!]5)L4yUYVOd}8eݞ?KY٩2)gO^Ko5bYvsKm iJ[2dэnOMN߃O5o*[m1Dž({~ 1UurwC:IKLTOrW͒\G1ׄ9_%A[2moYԭ~$ k}F!\5qmէFsA!4S/ƩS2;HGTҘƧ5bV31Su[IöF@zs!t"D*BwY8zUS[7:-WI]ܚ?GŅZSq"MDȟyf$j,0ec׆/42Bpg"R7 EFy L9݆4\b,R"ꠌ&-j̀ xqWP%ޕȮH ^d{vƣD&h~~5hjb(ӊBLG-(5;n tQ[; 1 E#iF=EYӴԙCF^O6fb!BoTAD<֒eBP+'Oq $Gwؐ`O =#HꡏT֝XEԒ [ m(Y_.P*J(\vUz(ǏC~ e\$Rz#hXE+w-HA'F\ZRAXƌYF?itYO>#.Ϗ}qxewf.A[Ϩ&x"c.j-K?9}˅ٍ ̔AWP^XXJ.QXKx3kòhקQL,]{0uLۇOڀd"5O@FSffuubD1,&E= H+<oB㼂Q taj)}Ilݻf~1λƞb6ߗEY>t/#U򝱈Ҝ{T&Cx_l Ns9ONtL#9= Qg*>t0X{PgCX1n eO?9]B!B?U:j#T%[y\nm;dbMnXL}$o(O18'e8= ah~*@x_`6o-c`Rob84sli[t{t**g2_Wjvl;%/Xe:;yyLV͚Z BgzO3x%$pRR|Mi%':GdnJ4R ٌh4ݼv'1qJD2$D&Ll+l]b zggo V`@?~[g̋u~LG|y:!Yڜ\& g^&9ɬzcF#i\W@tv$ E4&o7%y7U-= ~.oEdyPl9d yG}T2juٿ=ZWJgU΄ُ=Ke4hWn8\,,]-a(9fT3hkHg?)A˛dwa!7gE6}o= Ct辁ʓ)9A4]ܫ+ǻ T%g ,HENdXo1wp *t;Xn&P8œ$&e4&ŬyŎ6)nBc{ s-_!lѳ(l6 -`* lH69HLK)UDF4M SH$#z{s؂u~`dS34M$ro_ν]eX.|Mƻ(M?59'qÞx 6*IQKZ݈*!ϗ!Xfkߑz,MmkllFӱkmck÷4C^t~#TcDU&=@%B!(գw9邔{e90hͫ+ڔ[2z"JnNKkȚG gbSmϧbH;RwFC!}K4A1-u!nmg{F%-m vY|C{AjO3~`&"m냄wv8ze#zT:@s 9_Fj{G=`<ߚ>0 @1Po+"giKmj6N\DhD(McxjSQ!Mz[wOU#p>@ªEq "Y9@ӧu).,}t]r55.'D#\!xYxuWTQ5ɪ f;M?Pqfq&舛?)"JNւ/Ҫ@Ճ!5/5AM#Y-]˰3툽##*USϓ&м)7ϘrKag%Wp뉘 /ًiI] CAb/F 5>9ˬ,jU5m6>*쬠yܸط@oXxp=P{tv \kd~G&5o۟1%lǸ]v)Üst(T&1koY@]mUBoݕ=҂a4##kz `^HixǯbS1[o !"_?C2%Ҙ +ꋙHϮם;;Bf"Ȱ?ք]{xLg B>TcDS-=DscLW/EPk=H.1lƻL6$ŴJ^]|04áq] ;m ={Y(I*:`Fan|}} HOChv.z^Sb}㘱*ɔ5;EW\URi~N3" b_wFMu1ӕ.a1ùg-&dgꖝu<3HjRM@AŠQ:TRˬ~|a!;B~v7{Bc6?ow/%h{i1hH):aPhӞD;q)7]ST~.nK]L)p7\HܡĻiRW-dlwVL VaV^li:ܬ vhB.Lma&5_( $ Hy,jU! W}_ imK p$U8dQ s7Ff!_y2 ȷ>s'UBUm&7y.9lzB̟ 3X@|gߥ&M,uW/g=hXq67#FGu3|'oGq!XpmDΖ&n{_UJ!ā{ WcJI4}BLY)!iq*T uT/JMFW^P*Cd@ՠ8 .;Dx͝c9KAܖ ,|}Lxӛ^]>/sgՇM{;+ߌl<ƾs͆ɽ(Q;80i.!QFbV0yЉspYP յ^;@/VIWuEJ0 ^YQ-cȂ+a۰ckA2eDm"Q_Fʳ ҏ a 0='lG)޼u_(d Z^'՜P%]zh.ԓ;,D+y6K)}ڗO{AӖxgxzER&: ?%z?OGut{Xi Jއp(W&@f uxZ:midM1jOOLNv=mUwa%Cîx@.K m\{*ƈ.IAL?m@( )FDh.ĥԛ;;L$jȲ >z2;>kWh<6t¹TԔ|N$Dkt˪Ȍ]c"W9O 6s#wˀ:U&5Q9gM9",`:+jR8gWúAruP +ӭR5szƸgcS|,2d t*zIbm{ &ól6`ϥ;edł^(H*UAUkdpoI|L O5Y~[@}dQp?DiD3b/ # <jei֙jmEƢ쓧K/틲_zJ̪,&,zTogMrUhT CTjY[6K_H0@ه"<6 TF6rT=VO]ttN5rNf+%KWjhkK/㴜+W)򾟭acT3_ Y>ct?8(*Y.64vFNTH1^/$S/@,ÑPf͎>bɺӾw*ѫqnBgBx֣w?Wܿ\Զ*K &#猝M65fHJu^Hht..v,3%OFUOCoU^1*FLxy뼀=F/;NzoS:MړYo񄙉ڙ?U-!5~tRd,{ 1F0%;̊hG{\pVEg\=Ѯ }P،:.^02D{<ibd *f$CHeg(2&TXV[$I$:i?y4Pz*Jk~"e.uV#GDrgD5D~S+^`ؖDy3z~ ޿II@ LE]hCBwEn$9<)YE8Y^.r|6Ih EBDX4t) _5K-z`gm 6ƱVE kYԋ-QG,A`s.f-xl2=XoX$ξbQX J^ȏi7tF2SDvLzM)L귢5 !zr"{=5umd7{@(],t`MiޗaQh2Q L-2/Ol8M~&I '8lֈCږbdxpa:J\>>vU>aߧ0`TWkrO[ɗ &KSf{L&TJ;h/O2~%O Q(OgmquZnC~ ĮGm8ݲeR\${hW~ϞsfL>Ɗǁ(-} 4d&uG}߀<^/JlŤ+L A>SF"qs?it|5_1_˪I唊kIߩ"YN|֩'g{m]TJ4@~6lq(8kII,xJV<`D\2;*^RX ~(kM&"'"ba½E\н}`L-٫A=Ȑ DEAp1z|S]=-;ViVMz+ K#ޯ13Z8-RŋŜ(L>: *@=5[i e׸h:j(§6,s81!mzÀ^[aV@F~02S!B2ŝE=1;Oi"bJBCA(}ZL:k5? *CNV% N׀+MN/ci6yeߒEF8O3V ]3:EQ(lUƵd &*b&&G_Ǐ罟inI'&_f'IuνUKq`k]Li{gFe{<v B`#Ʒ *E .fJqCeYhgɄWtZZ๸TD6y/-yqBBQG@B=I\0zy <ʴ|;GRqz]%z^&5g׾T]w{y KJ  eIzJl}T8?2޲Ӆ=aZPmy!/bkL&W_:v j WPd`bJ=oWyQ'<}!n}5HE T;㔅c>{ׯpX|RYF3R!Kϩۉohjf1U8J|bezf{lOEՄss 8)t.a:ؓuFRL*Sjqxuˎ 2aߜ;K(v| v# ?*¨?R&؉0/ԃ6gKGᬶ.ujOzbkH @bYk۰ky>?^J;+eD?3U4,7OXAgvx镌Izor|>$PS)ᎵLi:d,{CמsLJ͚=7Sד׻CL8*#яYj盄\$t'S6)1GA\菠$p3HtGC!|F)ZӜ"W&i6$Ӷ)_?v{#OW#~=aԉp7c@c e#Hں3oHڏ)JH\Av,薓AD8NCEc#:(n9MCƧA <>ǡ&יCݤS-}_쥽jpޏ1\+V Qc?mR4H'f{\FlAp0!j˵AƑydR]mAnDd-]wgwh2-`,!Kq{hD.Q*Y4KUQ:z\M(F4A#W}`C8/e5ma)Vd$zX ~_@ɥ\?L4kOnm&/E9q\=S8ZWFDTg1 JwOop-am.<;͙A#X1>DQcuR$$K{bm$EB{V!vf^_- &3u<qx8 -6 ocJ"(Sga#KT`y |96țXjќY$tcfQe~1*Fr`9! +`ºgS*̑[8 Dew[tP"'DŻ>s|o|F,^Q Tڜ3K.Q'[8<yv i?:tV\"q5ڠ@W_Ix̬)^ʆGo!.J$7{8Ig9d sRN1\_Y?՜yA|euGrZˈ o3/^v5t5.@j0LrW{Tr޼]l3 T6+=խTś[84OPu 9d`j䗥 W(IO(z0MĪK {ܢ=SzeSLA5vcJ,b7X-R+|`̞⹯8flmzUSC^lvw|OyI`.^xY+6:U^?]!;>6&S\/)]H7ջ/HgŮj;ѝ Eum+H Sg *˽j6QntD {| z3k:@,G_oIVq1F6 D,ܥkb76[Fm&OV{;~\}`QG.B,cemyfp$C_+"\BʣjYHjI0eI,//0 =eCm܈2xɄ'N hF&= 6 q3l| WGa?a)3&~tIy~$́}F~%^BBt%70\ `R9>~]2&</M/y@ 'JD#Xp#>9ϯ'ȊVN} s^k[+lDRefd.?,;e6ĸ2lʓu;Us]9R סY4*c=yۨo)n-Խ塧 [A5]zI"kTzDN0"UQY)`NP? UR]`iE%M sQ$qp5rZ>)eLCQB'3NJ÷c>aSp:@?8Lv#G;gbO8us.2a!8"x\?ҘG,x/tXq*[ 䌊п.)Հrg7rL:Ȑ;X%j ?1YynO2 kz솭Z03}Av Oyf,bH*1Pj7x|nVo^ 4d$uUNճ\`)'D?SrJ3#B [wcY^u\' 8wLV!Q"XR_UC[ހ26Ƥ|$uՃPe!%#/ hRlh0%Naog^ѥ̥9<'U$$.Gxs Hb;^`$Eq( "K #bw hyqNVݏIJSڪkY[Ŝ/D^CL$ L$T8 ؿ9]헲Shp7Sp:X/cv hX:5}~ԛ:U M*wssQ8|ʬVy1*XtwDa_T*C1I_if$n4id}U!l+75;- $4T;@\*}d㰺bD7p[EtG=5>_ WC~3uץfʋa*A)4UR3g'(K+ދtp.9WKI4 &!-Z08~-Fq\JiҵHW:9UA9!̑myyGxSĉbOMlZe[sOBX˭bi Ea.Ghe8\k nJumPx^q|.mӵsU`6BD1~Yd2ՍkI;dž@( "c1UX/#8X tÌGw\,zV*N=:b)P^昧ҾE0E͓onpŲeIl{ԘÑg u^҄m{V5W|;0paSGr?AEi죲HEw4D-U=ð,܋b~eDٓskkދu'!r9W$O" TDe]M҇;fsgsّ!ԤH ,JֈOs'*=ruyaBltܛIiƨ0:`0sIt9XQ(R`>L^i Hl y9rsph쉓ykðoiM"Cu<"n2l0d0xRMʎOκyvj`؁.%N=M5Fn @>vK`͹Mjԑ H?)>:ו.2]-43d8Q]M9(^DP c ռDB0` :@ߔ3O^ cU\7SݫK ptSաm$pFËA˰ >(t0W٥r"7w{cX&W;3,c(9/*爐sd3R6{"eDR`䳷iGgʔƐ͍(NY{R*y!F=>E"R|ms[kNG*3QAF?ޒ]A$6w&^$,r?*)@Z OF![ 8)Z\Rݤ,Ag%C(3?`%PKFK{ f߲˫YP1ɀ::6tl201'_۩KG4&n'L/ۧU:J}-99-~ _Ji`n "n0G(iOqúdi4rMm;vSZ*=l \b1["C gb`Ea \b!ic6K YGLT?&wųK.5"X("F|ݫH*z YN숍m9 -`mT!];QIQZ^.r^]8-#᯦ Cc4:T5wgk^n[ ۺiY꿓uX޶,>c%Gm.Lq>Ǻ|>AyY]HP}}f@gI/6qK,DlAxQx,'=fTh4Ʋd+jpd&DeGU5%Ao,FAag%;͋?8#z鵰<ɿI^ nO=&ӷ BӍ$ /3p},)=n852wɂ1)l,/pş}DMeh B hXzޢD91e+"F h<;%"edJ$JGa rnx,ks?4 kIPm6}O= pb )(ؘPoG-3 " n_^sMcZX,IY WCT?.BP(jSf3ʁs&JǪ#GU<aoj(x}:2qvSI rq#D glM# dxwvTi4 xb u}<S_M1Ih38 k{-DU|p~`)P&L)sˀ=LJR_E SD ih:{"aiXӢ()F/zJ4U,9ז~^˙T舍u;-5[n5#r@7v(i[-SB5 L6Q~4UѣG%BeI[MꗖZobg11L|e<[k/#cA~Jᜯ-'#P]Mx!1#_~da":{~-_XBT?ROPܱȈjJ޴FOϭ~,bJTiwF@M=.r;;[FM\EEd\|`sYi0 ý}ɤRH΂)YDHfT Cˬѿc?HǾpQ͞H ܛh:.2-dAx Eu~G88(bhS0)HB(ȟ !eQMs#jKwpY'+Jc 'ԕ8h(F RXUb"^_664 Qh~A!8.'>p&rFt>Qo:#<= ,~~9DV$RNa0l[in׎.w3(S9JBaKlgDAQMz^0r2f(TJNfk_moEy$$EX$ƾ m'xP%s>q+dmN>>e꡼- H1b;>-GY !$qkXJ7 0q}"UDoĠ9l\S #;n"`H0 9V~`bYj87B$L8|Gǜx*zC|V!Rh܋bz4]b c[ l^ާKTzۗBeY4elshiT=uɜ႞Փ-w$fKxb( %pFR3S\)}]`\v GRmyaY8vqz+[ }+\A)p+(&`]r:q]]0h=Gbpd;٨;4Qͅ pG&>(+kuw`bL.7BPp <5]̑FF .?L Y,{IHJ ){6Я.Y32#RNFjtJbrxMlAtTr'65[ǘthԘP7W"#)U9%=kC`a&CwRw=nIϚ2{4Z⿠V,BdњM7fYITʥá0H 7%jvmP5Cym"5iUL:&}"2{R${JKҏ|<(VbVVLPOJ&,y ۹zܡ.8!F: ۉ\4 >19'] R% V)iϭKX?8bMƁ쎋z #goՎo΂3Sy}asU]ZQy, '?ܹ_8wSwH^(F+)jr{th/O*cecPvsNX Cm}Ӕ;6 !yb'܋/bt U8_ƹ"Oc%zdC=Aoq@T`1܃_HӚ6O>g`pbisapJKydsE#q3+g"Ѧ6ѱRRI%J#^Y Tn Q JPZV+Ngʫ2=,G~RrbM5e6xhsࢩ_Y | ۈڬjk`ۉDr$׹<\ncn<*ciй9Q9쁄6Gi䶡_Z'+se]R,Mb)$ i=?qkˬ#zf+0+@|߈ %f1i".;Tt[/} Zݯj4ti\J'˽}|?%$ k%d&khvЈr2G~B@\|ާح␑3$Aîܟd>|N6{>Ma.;f M1 [(Q$nG!ÀUWsd1IWʤ|6tV:~-ӇM=]R1ӽF8k2b9?%/p)%U^%s#ij5ͼmSgZ30+FG_ B5<vM?׌gK8Nڊ=NYGh:#ә]!~$j86c }3s!s7k_)F/Ji2OfGP,wVjJ4N"ٱXZM- neU4p77ؿy¿|RӗW]f{.x*H,zWO"IMyxR(v` ae:}+ZTD glo'-}@fBԊ~"VÔ BembCŴd{/@\l2qm#(9ad&}?ͦT0< ,%5evAEXu9CJϬ0kQc2g9 MЭ*!fI1P&'A.tU=8)lY Dioo'k GL/Nekg/KwX!w viX13+ quFY(&Kn4~- _5N8gc;!k sLUHg_=ekS<Q"Tt?Mn-DwkBQHޗE<{)>j,3n`uG+{s&$ն1oi:jv޷ovdTRy7j$&-z+In F'zރ^^8ϧs# wr(]=ףƢs_*)X`RK>!+%]=eVBVnzL7`S̃N&g\{xvid^ Te^X1k ʱg9X{7s~ǣ9 %t]4%G{?'ň\^[SY䗳E~g5(pEZ Խt\l2*ҋQÃJBm8Fl̯d%wes0M%Cc2xy+f<>%7S5jw`PkCxC6jh6sh7&Em&-y!t6ɡɯϬT-ULth :12B  kđ~,b]ǶsשIģ,鿒o򴧫ocVWC Hh ˥<Ԥks46tzvkj2v2ݐ%fzbi'*'5/(-Hmi,hAW]loחM6E]M||O:'>?LFiV \#'-8ۀr䱚%0K$%aFww@Ntpr9'7DW|iۼmьWbxCBH͒z H\%v&P쁟F'ءU Is-.O[]09Eaɿav;*ΐ-2i*OK*蛵r ȴ2s Ըd@:)Ȑ= 4~HV&|q:$q;^<ϴRE!@@wzy( f0l SJNϯZ3Z|4Z@P6KCZ1C+v!+RTvQJ꾄k;c8k̛;Ggѩc*_43 r)f]:f'ۡDSzOi!?(peV+q ZCGl0-saکT}8]Ѩ^S>91xitwۙ={W4q#I/%u: D?jj>dǎ G|ބݾ۷uAQ +mA@yfż~4]y.E|_;tOMi3>t`/켌 [\*;j> gO sV5ф=o$4WF)qՌ7vt2ͧ"ƙ/j=OX,!&Tb O%1ٕ1b\lߕR+t&#>Q͕2`V!4ǘV|Wsu]#Z+3k{5@G{C" W*Hh$h2Up.T[2ez0)C?$MChERNY.?D4$ BMI,w(($݆T[`sIO?S?a~N&\,:@XGxI2|q(IBQ0ӝb5DXf*8".yo +:ʿD>L2ޛP<Ն9I5ϊ)iv1cC<|FI_D#6*EA-uN_jKrFfarbw'Ǖp+΁PFm`ò"IϕKrIc_dwK?& g؊(#w6%1)@2Qڕ%W|vfVW6716VjL0 -s=-~ %(,wrG1OX|Mŋө$+4GsL7v]+=(GΔVs#Q G&8Rفү}vcdDPdTL'~~|kjLæN2&'2-2(H|#~u:vuz{u$Kzʞ>NY2_=ؿ\FZz =.Qv 0=KmvE9*=V@Y`ijI^>GzF=u"Y^Z$C!9 ,A+o3OZ͙ahⰊ.úCeP) ~΃B W T(@ωUp :F6ERDCPלXVZ}Ն8&+)JoMpa&rpB$Qpq`QɆz흹J6~aҙZo"S( (wR! ŧCxtDҲp!y oveՈQfaq!(wj9i%Asm}JdWmѲ}oE&36e Fs&%q𪻟]ed837WJ|,)e\q_ǾfUT3sgfEo^@`#(, \Q7LJ{2򶄸ȧN_t{j(6!4K5sOc[`5Bw"WE2ԭ0ޞɅugkxW뜿5)$Qޅ7_TQ"l:Zޢƿ BRϘG#c[z &tK :ר.b?qӸ?AӦU,WUpLo@Cs %]InM '^ǩBN[&$.Jz>][T&N'yq fT޲`u#}Ι)tB S$IK[ J]zp9ΨݧH`{z.7U!D._96,J?`O,YN^7?,ZC]bЫmޖti*ۜO 4 _ tDm4YfDr.Jtエ?l#GoB|> »Y LB?/! KHD%)˖}m1EA;9wo<9J)4(̌jPۨL66]@xoWYSƭam7UWw!U.!**$WxA}pl]цJ rQ6}VUԖ(oZdZп?ҙ,VݩmvՖ# @ɾ+,]H)ڸ6;SQ=^j­]!b,Yl(S^$!K٠A&*I0?@⑾Dl|f?8Q-\wKۏp3LDh~!# "E<:yy[sހhmm#@Q'9l -YJ=Zogn6( eXLOnҐ(%8ŁH}~g.܂ˣE)`%{re h+<A eDRp hƐ-ZRZkH\4S0fNrd47!AEpKX} (EC6 }iq o^=k3)Or4Ec4`-8 ]/<̴h1e1PY/Yڅ})p"~ʸAqnj2Dji,8R a tcM]&DW-*//RvInp; üJrsNHHį_g2*ç7G#@"h<}Y%'ϟ\1v!`E <3f'xqA~?F׬STF(Bbl;gH71^yb8YA Gi^"\p5-hvJ?$@Ҝɬ.؂!!;V|Tlt"~}ZWv+4PIfB&'qevfhB3_eº́x*g*&Z XLG1A0JKyE(FU915N+ pq҅?80(ڤ0M6=h% Ocua J)9bmpg>E3x-b)Ladcf|`Ch C d[jc 9y8@F(@o5b,} VE|gv5W?|gfe7uY'ʐ?X2c]% s >QiKxoĤM# `pL,kä AK`se&p.|?i 2 q*ʞv(O2zw3M+x2QV.|rؓhg 2 Na4{~װ.,nm7pgd,K?ƨ8ǹP&L9{Բ^⳴w~ H©-?DBl+gQ[%=1>ҝ/ynǟLM|UD}Q*]*^부k?w6:מ\%&@ ܅aCҸ2~YA.dJP]UG:,6j)YpI $WT 6XlijrٶDWP6s1)e +0fc= ~{Tw?IgE ФCilu*w%3pgfd1@1(w ]e m#-:1 \@;x@Bd'}ԂcaR%҅7*5  /!EA^#P+9ZB.GAa%An24>BaiF4WrQJ?OܢC\z`a@OvF &iěyBHҧȖ=IS\"%E@2!9YrR6;zFM@ynBO|\!|ϒ|{qbat$SkZ:ؼR'9=UvoAظ(=7\?+gP-a,JꗔyMVK2sK2p~n<8sBAqPReM/'UR}]l(?dagǮP6u!hXʴ7'z(/Q ~x\*1Ydf"Yh''d0&P ZL!fXeZb%'L[ ٫fBﲈh!K%g;ܛ @G93 rl ASi"aPF6. dzd- )8wcE6aϙ{TN(Zq<<x΋f⾮%W~ iUFvÛ]vMkv 0/Cς;l|)N+G֬-"måaR+vw12uxF㼕"AB*pܒnw%0W5\o zg$0ahwG,/QvD6A,|sɽ P|n`E1ò<{_|BYqH3k&? +|N8+ӷ>Mzo6R=J} ag´-[}P& -u*+7)7l+Z/FHێ,{uY>u[κސ4E6K4ދizTC`]oڝ[E5bOYKg؊F=p<.Ogƻ;PG2,r>e1{SMz)Z9fL^i79~7{*QN-˝'T5ҶJ[(.jׅ.ުTn q7Ly^VY |#S?˕eZ-;na-j‡ڤ> Э|-,@Jjq)Vٓ"*Pf*ݿ=5GG ;q :$.~72|~̀XOsCrȣF >HG{e蕕Ԧ&k xCdiv]Z}i0nd%J+L B.-aFf;rYoӽ:@qas$j#K~mPE?Sok=ުwł~k{c5)ڴU5-0ojLZ*{)ˣ0Rx~S7^2*![4zӥ+` z$e&j!"xT*^7MBi/-.E{iՑH+ ,i{5\9g@7dNiEu SJ|;*nCx|BP _~ Fݬz"&٢z59W /oE-y:PWBg;_c9iFBo  ܷ~d*g`Vp/|,P"]XBR''̓+ug6+]zOgOF콗60vz]S~>cuMp@abKP1yN[.>a 0^F_l8RYn?'("=mRw6٬uMv.sykl%›6GϽ\kW6 e&lO;7vgX0gjV>I Om侕aR#Q/;pf-HeԏYFvnouq-Ӿ*TP\RzͰ~438J?N{*si+, r(dGe:{dz hT./9ekq2*<6(%t?1 8R,7HU K!2yugiE>h\SnUe~Awdmt-*GecGs]%"@7y o2q,}((tJ{|UgI&RAƶs\DŽbpOwߞ"^Y$(Ѝ҈k'r>6x$Ԋ9(IMíoxdǮ_G-SNĚ Iu?{>Hx,rX||%r??B2%@SdŅ/܊৳LJj9{&ÚU4[^~ %H7eh)+'2Dx4~WAe7M̌2s)̋,]Gdn3D0 3^yT[t+I/JVR+WELK3FGl=Lcp7EF"nte{ԓhFCD\I@A\|CU$O Õj9c]Cx:<3C {23{ad})#8q&|MCvFq]lm5\3 R $N)nPfj!巑c2yv|2cwL•So}ErN5=f >sezXD,|̨%ZmP E&^\R;kWe@gBv˩4N0#b@U0*[B7 fYm[X"%.`%'@V#AHpE@Ԕ _*H0' )n+,i;za2;3u2p XFYo;Y)@>aGϧŔV1F6VyOk 榖:(23]=1KyJ w~md^tad{,gLw#**NU5Bx9Xԕ :Bc auvN$)4 41]\nd]k@\Y|g.xp"hT#LڔR^.UAp4.Gqÿ3>Ba 7ƽI6m̎c-:6yMMɜ!Xy{t,d$uZ.FҤbom^d{xG["閣A粑-:z PH;kv=c9N73{迡^ _,OiTI`|Mȓj}is. J!w#q8 L&tb9$8bI3y,<k8XeR< ir$- FɾaOQj+X c#X|eKY5s1cmbp`\6 2uS )z2+oYp ̬-B]% N/6*dmJx ^,*TJ 9/_w\QhlXVCe,Η˘Ȅbm^u⮗"rӾP3`&4!.)¢9AP$Ð4Co$@}4A0K7{uA2 hJ8*zЪh`b{b3 KtY&,N-lD^x1zc&lH<ԭuy uY ǀ!'4wglWWQe7 `T :<4rƖ$fh$Kbn׽+:!5ݷjB3 O*Klإ fq/3*7xA0Rx J?~~qGD^5" <˵j)ٱܿUqL=+P=(RNcUqe 15`9 -ʟ)*g0 q f vYBb/>1/ֶt!Ffw򑰡vDN=d",,:uV)+ކɑ6KŁtIךOq)%öB\nz*6v-vQcH^@=u3EaQ;C7Fi•9g}޽`v[J)MzͿov|lf ۇeG[<Ь#jɬ"("o &y„Þ(&^!ĴM3/C9%|I d=;g.PoOpqd]!<g˥kaøiX<ʒFȴpЁ}=d/9 (Zfk!|>ztɰ&TD볉mv<d[8CmOthT2\ !:pv3.I6E">%<1ӰgѫߝP)ס̫X PC?Ls?wl3 wK( O #q;}2~k|&]Ǚ\a`V%~:+] _SHd*~sR:/v<^͵vޮE miڞiAj'8 ('$:%0աl8P\bdf`ʧ{zQ[ [&EU:Gaږ Jkܱ`3"EӪ-jpROVFkTؗzLv`_Vo|¤HQQp|0LeV`&ޱ(]VY2d-zfY"eP1k1GEB|\%Ѕ y T!k?)RMȍe3B2!J+ߙzyLCL=<2O3k/$Kh ǫwN ޯz0YT pxyXe)K|jݜ(sI{kH)Tbh9q,!bLq. !:Dl&X!<* ܸ)V).;74$vFy8g_֝鼯's100~@Gs]@4:P 3)Ge+M'?y[} Ym"= Mey' MΫbJ;Mlrg^]7 J#WvLrڂIC %TFd]HVv?$ []fPl%3VRLUԕȍ=~v? w4M6U}1.r|rm9LQ8bBԨ yg>;źb`)*x2bد9DY)o-_%&Ӹuf:ܛ/%";޿sS&WKtg(~+}}Lm+QBqmDAh| Ri9yս ;=Zj6ۿjL$D}^fwLGYf{`G;4#Xd+Sh ~Lr/hEE1=heMŋvcMQו"o@U|YJ)PfA8IF79LwxyZuO֣k]ڌ]J;2ZAKC:+%nf|4#} U W覵J$YDaB/JV}WYy{ZsLJP+P357@Sn>+IJ:G(1:Gǭ޵Nx9)x\t_qwSKkZo~  f)j`V7oK'qoJ\qv@!nEBMi3(B> |0˅3?$4E] q=S}HHn.:h$%B_7">Dw<bSYȕETJul\_\0Q,*d ~xtOsP $KҒQ _QpĄ퉊΀iVOZœƖ}lxZ2 (,0Rg2b㛦r=85ʀMP(1\ pu~wGTI>YtLK_@R)߈o+ #q}3s8K *rFGi|vKee۞ ~F/ (_I{ǞiJh}T,ODuO{:%>`t=#Jw+OmO(~'^Yec&+VEā-Im/z0܈'4 ɞBzJ<$_G/2sp?nH Dscnmvޝ2fW`!%D3ԗ/+ͷJ/yT\R(!T|Pی$WFUW㦕߁g\ojh']q`K\Rج J_j(Ѧ N'ɝmv{7QIM#تcV&Л^,1ζ;eu}F A H.iY >k9Ph(/'eQp7mfm=ȧWWrʹu]%u&W[B1|[Э_X g-.jCo"B$p:Uzn4J_ 4 FH;_ fmH[ոd1Խ&;w pFo3eS@=wyϙ3 2.045D:6+:hhF9#͔\~sE`{NvqBcw :#J9 y& ݱdu}ǽ"hVK5AAv&R4{h|w%_[-VAxG rn,橷4. mƧR(n{so^|2W1HUĈ;5z3]g?T[k[^*KsCquƖ5|)] m1 h c=s|7Eg[VEԹ8u:~{/O\~SQ;Qs,ֳRmm]؊Qvk}IAA;y8#ibMPv.Lq~LV\LP9B+f[6W)H=7 CAqJ>&JWApiVYÏVδ.I;$98ݵxyuxV"DCw;+xiS#Fe 0"|4닼/|C5-g//.;?g#kYPLhMGңp,C+QƃF_KM 6&PZPXol/=I(:٥mlVx?Vape~1dj4_㩷)'U oX{i-gx?PLͣ Wiα;fX_;M^5YUAdžME b@}ӃU!UY'Ρ%F<2@QqbHAb-8 >GvN(`%1̇;=CŔpq/wQRmPmI,?Ұ3#S=ӌ=;㋫b2+v1<͉bQqDpDxz +~`ȣ~6B\qbpهi,/J/n]>^W.26n/NW{#tx|2^1g$ӂܣx#t҉q@Zo ?kznΠk bUwh`<9Puۜօ[0ˡj=׸[D0&Fd,J͋PqQɩY(!k#Tb/Hkwiw Ss O%Ă Z}$]dv{ݑЯ6BT1@oOM+wraٱ/'{LL1[.Rg)ت޽u2`3ũȥ{D!i?&CvS֩GBVa?<sJ>f PjA$RׇdžDOz_cc@(ߪ "-2ؕޅ| .E^k1d#bi8 N+k渒8~X<`1F6um&1#\tee#ss+`c­6LE;~A[BXg-E8EP"/ljW.Dg[FǶ\9;Kw2,2Nl:~:mQ}:E˵o!=x&7@Lm7A;po_<M+gz7EҨ\_$6t~ Kkr)<mp4bjxSA Xb) rJ.N_6ÀRX:" :bL8#Xn~p5[Y<1߇PfHCVY@):2dB ^;ORner[q)JL @ScR\%4g%zL"+Môr p!,. N'";>NÉ,/Ig REhWӂ&"#-.^n*}\lTQY(m$ѦB=;dp=6,cafB2}@ݘ@~i1[X&ETL~p+G: AP6Z2np=&^Y.v8' 7iˑ:N?;8n)$9=waSW@:;zAX>FL?-0Fbr_;K=p] ?4,iY)ZݰyEmH8j q- L%he"vf(.V6@8(~{ER q,wƘά @89o#:P뮲qz~Y`ҩbY!`[]!ZW'1Ʊԓ

} \9%CAC-:52,2 kr΁7SoE,/p ;i QS4|(i-<"ITƵDs%S7u75izklG&]gמ4^71mqK1{7EQU*ijH5Ը@yyŹ)BXyAAY6h(K9I8 .{y`TV/X*GOZu&{;cwC re1isߥC)$ A'϶|¾|($ёVoJD5e/SU[W)@| 2!("n4a%l1i'KDq84$DѥY|͕]T^~GDH.YT{4zҹVAGl?u4diiG)/'f41 ';+,<| ^2Cv|ބ"jQoe4rsǺq)/,^ʧcȊyT yZ*Q.oq(*|`a%RA'hB y)³^~%==ȮyێMolLE.Tq-+e+ SZ81=l]?"Q[Xva9=et7V3$kVq#W~yJ3g67dsJُ` Ɓ*%HlZ3b{;3jHObwئH L~s^x`PEeVG F6hgMg( \P~3>#Tayu=MGZ !$' 4v%‚ߴl1"Ii -=ߑtm RxϺ&0Say5 j=+i[| bMX=WJ%RT|WQNӛ6[4C5aX_ÊX'y06?׀&؀d'{JV5*p8a?kU*wdTF48@Ѻ:}av'q$8 +G3xjY&R3 ʗ,L:CoTGAquZ׺;p8 =5YJþsXͶa~`Jo$B(/1Oe]$U.&"!粨"oǭ7''iRk<*'I ޏG>1twr ^/Y#n; MZ<q ,Ɓ߇43e-oMpuP W sà\\)b0Z!ް6a PF/jA87AoORYGǺI{a7yTR {m|4p*Yt58z!^\G"` ᑨm%1"L,ЎYk!RSQ/`,iɅ 'k<ʙ7z:sZ =wVǰ3惨Q—)EWSi-mCF𹿣=`@ cXОx4釗i<JDd㢪#=Ki\g=gGKOq ZC,I/DVX%U*jOොFY,@^W- !5QCN.~u2`7UolRx;eroCzM ﮓ ^}4=1vҍ]Y^§!TdEn)dpA "/qxxAh.EnBo:kw3&iAѹƪ WA8!DL9{Et.zBPO|Եaޒ\2 Ĥ׽^XЬ8 8mwb,+]7Z " 9{f.HisۅZw]EIi%ν=NLs pIrAZ pVDj-P~y`m2!ZN[j#]K (_xpY|I,MaEoyDP!!m_RMƺǕ݇]vG6O!%nϧB)J1 vDC˛K΍z|Ķk%&Pb475v ݟ8%囚= -e6- B%U9hҕxA1SV1Q( Y`]-Ic,rE,8 -),mNΦQsjy/#{Ar_ q^EC5N2w@\י_(ٚooFz|$)$]oք*tX_r-gܡ3(Hl${Y1{,ylvR9%7.z2z3 Ej/ZB6(ƌiQ4 '؂xS+y&A;ǕZcq)V3@%n70L 0""X5ǚK)#N8Ye:]Ckm1sQc\iD*!;mIMklu0O:_W 6µb6C ΚqTL%D<4O 6þM NFm:~`X:7Y=)P;yY̖TYF}᷊Tu6D޲-{+q+=h0%.LP5/~LC\v\%A- eXNv'|3X|w%3֔vn\7g ؐXyBx7V5/8!ܵ`'"t C74H7aV 9 *w8lh 0 vw lg8j[z5N=zMf>1kߙ@Osr=ьjOD}~m#ag%HYF-A{[0o>̫`sc.(0VVB7(FQK=#xZ.-(klBwzeoRc2bol_0q`2-(׷㣛OW'樳񱴱|m9P*_jҁ@Ikeyi Wx N8I^7G4TQe!Tn(ӿ؁Ղ],>Õ$'A&WU>4yp^A6w\_ߤ287VvopD9h;"%195-lOG\.yo`V#+ё /;NjyV0??zrQ2#X3Ȥ#q&eɣvdК\Fٴ'=);,Vɹf$1fg]#)Goo²χT~A>Ƞ n SI0UJK0/GCX]vu1ܨ(KO@I;*6gtʴ/3D@ wZ`>M*Tt .PĢuޭ¼2.׏UKHkĩjO^#fs JWݺĘcھe,`~X>`FcXvHY(Rbc,z=yI W)a$ָk33԰Lzn ҜŠMHP&r8(%S.2Z[LOb.b܁;yo!X'N}yV)+RC)H&`4||_2 qXt=w>rrnu^JK)?YL7 B|boRW3[X)[%s* Sf:G?麣8uSa /ܓuzw0 ъޖ<Zh)YBHlX-b1Z L! cUr b6md͂dV|طvە˰|d2t'=x_RU*Hʖ|=~=|V.jrMQ0SXw`A%!\m%wZZ'G}*S![; .MWá ȋ.Z*S&6LO 3YE{S4syf&H[)fjr@62\ ܕjeEO-6@N4[1G` oCe"4 l)zؘV6G3W8p;\~L0 |u\u;'LɕPU,x=F '+׹͹C\/Չ nuO|2"6uD xꏮxghΙR9'.&aBQp}l޻(= tq8z5O?JzKyiEseT"8 I my9UC>^ ^[aC"j5)o@~$(K,jnМTYO:}ʫ[rZU{ǩ*%!m[b@nm|6Y⤍zooT&uՈt֜ck)s8lksWP23Dr\OES)ݮJR&YB;e@H3UGj9vFz{:)˻0)L͉I#DCIaxʽ+wN?TE3yy`'KL ,f"H)+>-SUMj4l3$VHEp,]hƫKKN t_hJ.35{$=vhJ^/ V;I,SD H!Zʫp{=fحcpTpcdi/ uu(H6ƻ@H&dæJãZ-Y6Eрc#ll]>~@W6aWF1c-eO15Z'q\`'d]MDŽ]_&)8gzE _ \J{`- *)Vaᱨ]8ش]0cjX*u"+BKɬ +n}JLHYyDX-XY5Оg [&O5!ʴǞ!}c|Lﻞ %%d7tM|bu.q|^w243R6A?=$HƤHtwٳUB튀}]cԘ2<>bSVyvWKOdühVN @i)?˛5+m?cKٸk̲QsNd(Yӳ91tBG@N`j}4'!4=0uN#HD[8CmQ/voV{H ELЋNVue靏eq|O3-iG8=gr:RkXz.?湲ԍ}qWpLB5' [2G1&71PDS,7@+'=; Dۼ`ѼtJn ' D|3= p9e.2h6n^b9wy3YBس&6 g63j=-V! &:(ق~?7;pFwR PDlԩ }3 c8y0G3_" бAg$rb޿'_ ď1xw6qg12 n 7j?vu>1?k۲K>^਻vCQ:{I [h?2}'-* 'CdHÖ3IX0;zs6S|=k~=%ezZH[ۂL>U UuD)9X}} ?1>jQC`262 AH-\ۦܳEVwDL;i J 8I4`걐lG'O} 9*QT{?=9>Bp*"Uj Ѻ%~&;aS#-v 9m2fT # ^Nt?V.}F>fPif5,krd't T.P/ yA:>4wfCĂ2ToԒiݔWGԈJuJgs ;i)*E CV|Qlֽjy=8|v%GIQ8m[8QMQלK(:Z"nxw<":ixKg`u(T3 3Ft.%[CFmhGo:L)V9D8ˍ[:=PNOK%Z\||ք;/(Oq([╻sY ؄#N R|ۯ{&j#iQℭ/F:_e=ڕ㮷S󣝵> o}ue> ^lsޭ|OH8w$MCN= 'ʲ Jw(@RϴsF&EO~9zVbtN_q7 ~wYDϡZLA[Jriߥ#$P[ /޵|Po)4f3v=WL.j \Ӝ Js KnKt#4 bb) 5&[Ěq:UdbW 5 d@\.Y@eMt'#2.,艼zq8ztҲz2?n7r9+BgVZ"anBsk0'b$<Jܢ`:0yo2;\ϲpSx+`U2y17zɂ7l~ I@3jM>|хYm}Ѽ%s;xVFάlvfFb(d!s ee'7år] 7q$@C5 X 6Zwixwq0puT6/ëCR?/ qYk/6p@GПѨGߜ<7 C05?fi%â)o'%(_c)./A)v^VD)ߦս/r,\0yu숸kns}cTדC`?ZjI鮷K|S39&,2]Hq/IZ;&9i05UD@Kh6NC :2$OL%*F f E%!G `RWk`SbO6J&)鴷mL{NSΡwL_a> kvrRNZd6aOs% *ί?&x[ݱ[cAAJd]t^0 ,UI rd6.jhN,FS(Sr"d1+×U sw ]UѶFin,s ۥJ횱wX`{YSB/iMc&b&M q~]Irl.^ظL5Ò,7V Λ@%:}xR&Hs EKru.45(3.J+qbd|>sX4\d-PqKPApMML|O@I}.]V4n B(ӫGtU#` $듓jiGI. O,zwB8V.rӢ_[ A틉JWn:ٰy\?;X+ni2X$ީ]gw;L5_fJzm(خ[f#R7‡=>CaAGiv}cP2Mq0KEt+#fՄQe&vyFHt4z 4-gBQX˫)qՀhh£nEۅ6o뛏0*P 85h!XHb"ꥫ,x㯊0t 2 ۔x ",B=G 16ܝlqlZjLuQhYoE<_4O5?:`Z14 .8:%*2n}+4fސ09p ]Kx3c\tߺd2OIB|EF`/ *VSZ%v/7V̓=`R9)ݿٜw@xYZpejf12UjpV`b|1'԰( .ڷp؏J>+llה ha $Dk0BD@r(!BKnҊ>!_4T0sY 0l- jOMtN3諐7E ݮ_&&(Hi0߶/,Ey}r ;f(8̔Y0z nh7"UEOà{_iz_tM0 v_8ľ2m4rTG?pېrfHjmX/Cv>6ާh}T{E۲}ơ0TSxo7ㅙ,ǽc$џaˏ2ga.?-L|AtEsavVSKDkүiC jz[5~ޜ1b$|?w p bdC?(Rk\3sll!TqDz 1zvco<5=joW|†ӝc!5M;yE-Ӿ֚}lB&OyՊ} Fd Dr $[,K2H38 n 6_FV%GU++]Տ0n`lBo^`[s^=XL<'"ƗhKz8aF^ee\o#-m[iMwzu1cPG}]؁\c_uE.h?J}:Baz&<KP1滘Z`W}ꂌbv7j/V kge]ge]"(ȯCOԿm+ QEv r69rM#iA_1>)]:Evg8{HZ^:l$bDےz$(Ax&guyiFҿga M@aR:ݘʽoӭh.[]pHeAMK8mu7rL +]1@q}^4ײ]fBe/P6yT.)zVd2"*ѹw"d#9ϯLFoZiX2г ػú;5*.J f@gڽը 0_HBXꃹL$CD!^"} wtl~R6'>IyJ:<`ēqK6{ޓ1n92S`A?¶Ѱܱ BZUI.#C[YݘqINNen48|l/ nsSCZEp5׳ZaV ǮWfݒfFE3#ڛf%@EpsU'v ㊇jlqc=,5V/hPL ,*vvu5NS-˫VTy&5"7, g,Dح`v g ^9a) #ƫF1ɏw. 3mu/^ib;ɄpA]x=·;񮚲Bc@4\iQ9؇{* a h'8C@t-z&[Bkgwe'lltt+:I܈oۓ;Og7Y#t ʏ.^m&%Ό^&6-/]@]$fQl#2j,z1!WQz:Ȓ[_yZW‡.}s^@|W^,5wAgXU]}6ni?1& uM/Z`W\wFqLE/ .,Ry8} @ zK>T`5a!Z!Ϩ㑇E\{WDlo]#$XO3]3/`8TC@hmLJ U t]S@;9j2+=~>Ce[P⛍JXSTJv74l:ڻ&Ҩ#áp ,CcQNaǔR㒂佔H!drƣzqyf8Y 4+D7='F)jOFVh^>B|ps¤D=K a)4 I,c;l @:UD` /ۥ,#uqh'"2wRcY3ѳӺ{,`J$xyu! jUZ0R K'Y=/Lw4%@DGʸXjͅ]#q.e3X. 5Kj `cR}$iޠճ{:,D r0D h`pHG]1_uC;y[=9_G2̺r+3#. V~>,Y`'u3{QSQv="JQc(6ѕ L1yr`.ٻpBZk\4s+/GQnnRQ0U˙ ZgD:m hw58q$KCxJx6W0fU k( wnq|Ɨ*jTZoۋ+ ʭΓT]k\yV8&=b9"+ /3GMEe"hY!i dm8n$&x T* ϰvrTNM&dYJYXCߏ p %Rma˳!)It}QGߖa!8Ws/ju/%ioJ'h@7@?#iM,y\.ʞ ydRdH<}HdT:wӶ|*K>fߣNz m.~f-[M]xIŊjdCGK>wW4N"$o3ȦUPUU鈟uM[]@6b]Gq琘~mu*|PS] n^ݷY8c4kkY.PnL:A"CTJʟDSqG~zqq V,p9Q7DI:kBG'odp: lD3c"]VqVumDR(F#6@ڣQ*wQ輪`g֩p¡XbINGf?ѝ+Y&%H7Gcd_B,0%?ra 'c|yBG3/A*f"acӁۣޥ)y*k!ӊ@KxreԒdk]5̾h!DFY;~?abﶽ5?WPp}(uɬ Fq0ƅ1JՇsgR5/NHxvPӰo'G:gGzxm3H JD9~imM5-t p7[IYsŒxq?!Ӳ̖e\ `t6de#^EQSG*Qr:`'pt*wwwL ęADϨ% ޶\ܕLpXՈ]N .Ā>!_hѴp \tw(LKA%DU௃W5RaX766bTdPsSkEWdŻdyqGMpŕ$Ǒ !ͱlPdy)4MX :-qǑ:%SHY?#w('a56F [_,gUX-o$HBXs'˅yk!cu$|4uqfV'΍`N ֌8MK?/Rj\jN~v_Ũ%" Tj