ipa-client-3.0.0-51.el6.centos>t  DH`pXV F@@H1UDEZMk3&qMr^m ['?rlNh6gYPĆ6Gsr7Wܺ7RԪ.C2lASff%OЄ.D~ud&tMfn4D_lN\(ސ`_ӨnSZ 4=/qmߟlx$(\`Ђ6˵زkB03ԙm01574b4~վޤPד x"І#gEdYإt\_ + Ϊn´ޭ7hf5yS`C"L s%'68`U\َtd;|D(}۬LMdOIҶ +`k8Q$gŻ% ;'k +b~?:f5je <25!NY-5ɏ5q2Mccc9e7819f5a6ad2f4797d9afedaf28215a7b9c0VXV F])])`iv99w %`s7ґ3 pIc0l ˵VUv%ա'ãg $G4+K;)ꏺpCrs-5B( ygOmd^I lP<[Gn3Wdbxd()P3-7I>N0ɔTA.Cv632gC1|bz2"$U?cAR=}xs&x$JFs[!rXKب q[4$yu&A~% `CO݇&o_oxU~/-v[B`bNVVoz7!gackZqnԏF=d[x 77QՒy*k0u'O+Hh8 EVy$EqR1*#" hn7jUfcB'jU},vhmh,ü&M=\bu&~¹~YD=G,դ>7?d  ! G .49"L" " " \"  ~"  "(""|"$D44l4(89:;>ާBޯG"HX"I"XY Z4[<\P"]"^ bd`eefhljCipa-client3.0.051.el6.centosIPA authentication for use on clientsIPA is an integrated solution to provide centrally managed Identity (machine, user, virtual machines, groups, authentication credentials), Policy (configuration settings, access control information) and Audit (events, logs, analysis thereof). If your network uses IPA for authentication, this package should be installed on every client machine.Xc1bm.rdu2.centos.orgCentOSGPLv3+CentOS BuildSystem System Environment/Basehttp://www.freeipa.org/linuxi686if [ $1 -gt 1 ] ; then # Has the client been configured? restore=0 test -f '/var/lib/ipa-client/sysrestore/sysrestore.index' && restore=$(wc -l '/var/lib/ipa-client/sysrestore/sysrestore.index' | awk '{print $1}') if [ -f '/etc/sssd/sssd.conf' -a $restore -ge 2 ]; then if ! egrep -q '/var/lib/sss/pubconf/krb5.include.d/' /etc/krb5.conf 2>/dev/null ; then echo "includedir /var/lib/sss/pubconf/krb5.include.d/" > /etc/krb5.conf.ipanew cat /etc/krb5.conf >> /etc/krb5.conf.ipanew mv -Z /etc/krb5.conf.ipanew /etc/krb5.conf /sbin/restorecon /etc/krb5.conf fi fi fi,H77I533GE`c$8K!^ sA큤A큤AA큤AAXXXXXXXXXXXXXXXXXXXYPx#Px#Px#XXXXXXXXXXXX53c32f2a54177b1dc5ac0eb923104df528c1c194eb4bd42ce03c48a1417a1b21da21bc5f2bcf1028f8e674d09c1923318c6aa1e89a8ca9947306038e4a38b66eda21bc5f2bcf1028f8e674d09c1923318c6aa1e89a8ca9947306038e4a38b66e29f937508a89718ba6cabb5479a56c360adc85feec8fd47e0351bef88324c2d401e194f5cd6aa88e4eb4c8e872d1219c4999a93d53c188ef1fd21147c345cfa501e194f5cd6aa88e4eb4c8e872d1219c4999a93d53c188ef1fd21147c345cfa5c8db0446ca00a1ba1801e184ebede3604f53fab83c52c3df148f065be479aa8f6ace038d520a36ee479ee6c85bc32fd3e90c0fcd37db3cf7af9b2a44fbfeab556ace038d520a36ee479ee6c85bc32fd3e90c0fcd37db3cf7af9b2a44fbfeab556ba1933e045ab24fcde2f32fbed310de486222447b3a46c176be1c073ddd19d4adddb2bbe33d73f490ed0d119bc1413889e535161037f9e6c05d087aa6108350adddb2bbe33d73f490ed0d119bc1413889e535161037f9e6c05d087aa6108350bdad3cc3d875f94eb152736c133e6bcca16d178216a78c7ce6c1e747dbaf805cc10df4c0b0a7bc17b29ebbc80e8c6c6f5a9da11f1903e8cceb2567879ca8b514f259344ae09c1db4eee72454528cafd2b461a1f937c04f19badda42de68ecb33a67797a316abbebd2b7d2cc1127815dbaadad8468d2018f9604d8f03620fbe5ea10cba8f28f76a0d41dc1fc1d4a4a714a14e8364b26637a8c66c6f36d91ef8578ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9038b3fa5a8ac636291c60ae3897cfd6e6be58104bf79788633feb81a13623e944a2378ae5f9d2bc73370af9c30cb96b70f5bf81e70f6a14ad259c22de2a1524a932f97e3e96810ba138d0930b42fb50505332ef42e918498567519dc30de119c1a787e1673160d1fd857404a93888915284067e7ea463160ec42a7c06e8b9a8e3c226ac7db51b406f7edf39c15194a18974e21de9d68d693de8f87c70602e789db0db0b5e0ae7d1d0781f9631c2d5676dac24161743fee5c9cf26a4d75272282c274fdb7c2a0b5a2a1b2a5c6e286d02a7156f1ea42ccbbdb28ebed7d24447bc73669e3a8e1a554e232005bfdfb521560361bc2c14fe7a65736c7a737223d35df0178429ac0705fbd23d714de234358fc70bab3d036efcfd60d0d7a55a1ebdd52070539b8a0b6a9af6f4c5b5aaf646e23524062a16d963854df1147613996a1f394rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootipa-3.0.0-51.el6.centos.src.rpmipa-clientipa-client(x86-32)      @@@@@@@@@@@@@@@@@@@@@@@@@@ ipa-pythonpython-ldapcyrus-sasl-gssapi(x86-32)ntpkrb5-workstationauthconfigpam_krb5wgetxmlrpc-csssdcertmongernss-toolsbind-utilsoddjob-mkhomedirpython-krbVlibsss_autofsautofsnfs-utilspolicycoreutilsrpmlib(VersionedDependencies)/bin/shrpmlib(PartialHardlinkSets)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libcom_err.so.2libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.8)libcurl.so.4libk5crypto.so.3libk5crypto.so.3(k5crypto_3_MIT)libkrb5.so.3libkrb5.so.3(krb5_3_MIT)liblber-2.4.so.2libldap-2.4.so.2libpopt.so.0libpopt.so.0(LIBPOPT_0)libsasl2.so.2libxmlrpc_client.so.3libxmlrpc.so.3libxmlrpc_util.so.3python(abi)rtld(GNU_HASH)/usr/bin/env/usr/bin/pythonrpmlib(PayloadIsXz)3.0.0-51.el6.centos1.16.24-1200.1840.el6_1.41.11.60.61-33.0.3-14.0.4-14.6.0-14.0-13.0.4-12.65.2-14.8.0XX lWu@W@W @VS@Vy;@VD@USA@O>A@N@N@NN@NNN^Nj@NNNNx@Nx@Ns:@N_sNI @M@M@MMy@MM@M@Mx@MMTM~@Mx@MfH@MdMU$MOMOMGMA^@M=iM6@M4/@M.@M.@M-M-M M@L!LfLNLdLLLzLe3La?@LD>@L#HL#HL@K/KՀ@KK@KKs@Kie@K`*KK@K @JJ@J@J@JJB@J{IIIm@I1Iq@IKIFFI9I1.Ih@IIP@H@HXHO@H-w@H HHH@G߮GGgGs@G@G@G@G}G}G}GG@GC@GkGDG<4G)G(n@G3G@GJF@FS@FFuF@Johnny Hughes - 3.0.0-51.el6Jan Cholasta - 3.0.0-51.el6Jan Cholasta - 3.0.0-50.el6.3Jan Cholasta - 3.0.0-50.el6.2Alexander Bokovoy - 3.0.0-50.el6.1Jan Cholasta - 3.0.0-50.el6Martin Basti - 3.0.0-49.el6Jan Cholasta - 3.0.0-48.el6Petr Vobornik - 3.0.0-47.el6Petr Vobornik - 3.0.0-46.el6Petr Vobornik - 3.0.0-45.el6Petr Vobornik - 3.0.0-44.el6Petr Vobornik - 3.0.0-43.el6Martin Kosek - 3.0.0-42.el6Martin Kosek - 3.0.0-41.el6Martin Kosek - 3.0.0-40.el6Martin Kosek - 3.0.0-39.el6Martin Kosek - 3.0.0-38.el6Martin Kosek - 3.0.0-37.el6Martin Kosek - 3.0.0-36.el6Martin Kosek - 3.0.0-35.el6Martin Kosek - 3.0.0-34.el6Martin Kosek - 3.0.0-33.el6Martin Kosek - 3.0.0-32.el6Martin Kosek - 3.0.0-31.el6Martin Kosek - 3.0.0-30.el6Martin Kosek - 3.0.0-29.el6Martin Kosek - 3.0.0-28.el6Martin Kosek - 3.0.0-27.el6Rob Crittenden - 3.0.0-26.el6Rob Crittenden - 3.0.0-25.el6Rob Crittenden - 3.0.0-24.el6Rob Crittenden - 3.0.0-23.el6Martin Kosek - 3.0.0-22.el6Rob Crittenden - 3.0.0-21.el6Rob Crittenden - 3.0.0-20.el6Martin Kosek - 3.0.0-19.el6Martin Kosek - 3.0.0-18.el6Martin Kosek - 3.0.0-17.el6Martin Kosek - 3.0.0-16.el6Rob Crittenden - 3.0.0-15.el6Rob Crittenden - 3.0.0-14.el6Rob Crittenden - 3.0.0-13.el6Rob Crittenden - 3.0.0-12.el6Rob Crittenden - 3.0.0-11.el6Rob Crittenden - 3.0.0-10.el6Rob Crittenden - 3.0.0-9.el6Rob Crittenden - 3.0.0-8.el6Rob Crittenden - 3.0.0-7.el6Rob Crittenden - 3.0.0-6.el6Rob Crittenden - 3.0.0-5.el6Alexander Bokovoy - 3.0.0-4.el6Rob Crittenden - 3.0.0-3.el6Rob Crittenden - 3.0.0-2.el6Rob Crittenden - 3.0.0-1.el6Rob Crittenden - 2.2.0-16.el6Rob Crittenden - 2.2.0-15.el6Rob Crittenden - 2.2.0-14.el6Rob Crittenden - 2.2.0-13.el6Rob Crittenden - 2.2.0-12.el6Rob Crittenden - 2.2.0-11.el6Rob Crittenden - 2.2.0-10.el6Rob Crittenden - 2.2.0-9.el6Rob Crittenden - 2.2.0-8.el6Rob Crittenden - 2.2.0-7.el6Rob Crittenden - 2.2.0-6.el6Rob Crittenden - 2.2.0-5.el6Rob Crittenden - 2.2.0-4.el6Rob Crittenden - 2.2.0-3.el6Rob Crittenden - 2.2.0-2.el6Rob Crittenden - 2.2.0-1.el6Rob Crittenden - 2.1.3-9.el6Rob Crittenden - 2.1.3-8.el6Rob Crittenden - 2.1.3-7.el6Rob Crittenden - 2.1.3-6.el6Rob Crittenden - 2.1.3-5.el6Rob Crittenden - 2.1.3-4.el6Rob Crittenden - 2.1.3-3.el6Rob Crittenden - 2.1.3-2.el6Rob Crittenden - 2.1.3-1.el6Rob Crittenden - 2.1.2-2.el6Rob Crittenden - 2.1.2-1.el6Rob Crittenden - 2.1.1-4.el6Rob Crittenden - 2.1.1-3.el6Rob Crittenden - 2.1.1-2.el6Rob Crittenden - 2.1.1-1.el6John Dennis - 2.1.0-1.el6Rob Crittenden - 2.0.0-25Rob Crittenden - 2.0.0-24Rob Crittenden - 2.0.0-23Stephen Gallagher - 2.0.0-22Rob Crittenden - 2.0.0-21Rob Crittenden - 2.0.0-20Rob Crittenden - 2.0.0-19Rob Crittenden - 2.0.0-18Rob Crittenden - 2.0.0-17Rob Crittenden - 2.0.0-16Rob Crittenden - 2.0.0-15Rob Crittenden - 2.0.0-14Rob Crittenden - 2.0.0-13Rob Crittenden - 2.0.0-12Rob Crittenden - 2.0.0-11Rob Crittenden - 2.0.0-10Rob Crittenden - 2.0.0-9Rob Crittenden - 2.0.0-8Rob Crittenden - 2.0.0-7Rob Crittenden - 2.0.0-6Rob Crittenden - 2.0.0-5Rob Crittenden - 2.0.0-4Rob Crittenden - 2.0.0-3Rob Crittenden - 2.0.0-2Rob Crittenden - 2.0.0-1Rob Crittenden - 1.99-36Rob Crittenden - 1.99-35Jr Aquino - 1.99-34Simo Sorce - 1.99-33Rob Crittenden - 1.99-32Rob Crittenden - 1.99-31Rob Crittenden - 1.99-30Rob Crittenden - 1.99-29Rob Crittenden - 1.99-28Rob Crittenden - 1.99-27Rob Crittenden - 1.99-26Rob Crittenden - 1.99-25Adam Young - 1.99-24Rob Crittenden - 1.99-23Rob Crittenden - 1.99-22Rob Crittenden - 1.99-21Rob Crittenden - 1.99-20Rob Crittenden - 1.99-19Jason Gerard DeRose - 1.99-18Jason Gerard DeRose - 1.99-17Jason Gerard DeRose - 1.99-16Rob Crittenden - 1.99-15Jason Gerard DeRose - 1.99-14Rob Crittenden - 1.99-13Rob Crittenden - 1.99-12Rob Crittenden - 1.99-11Rob Crittenden - 1.99-10Rob Crittenden - 1.99-9Jason Gerard DeRose - 1.99-8Rob Crittenden - 1.99-7Rob Crittenden - 1.99-6Rob Crittenden - 1.99-5Rob Crittenden - 1.99-4Rob Crittenden - 1.99-3Rob Crittenden - 1.99-2Rob Crittenden - 1.99-1Tomas Mraz - 1.2.1-3Dan Walsh - 1.2.1-2Simo Sorce - 1.2.1-1Simo Sorce - 1.2.1-0Ignacio Vazquez-Abrams - 1.2.0-4Simo Sorce - 1.2.0-3Simo Sorce - 1.2.0-2Rob Crittenden - 1.2.0-1Simo Sorce - 1.1.0-3Rob Crittenden - 1.1.0-2Rob Crittenden - 1.1.0-1Rob Crittenden - 1.0.0-5Rob Crittenden - 1.0.0-4Rob Crittenden - 1.0.0-3Rob Crittenden - 1.0.0-2Rob Crittenden - 1.0.0-1Rob Crittenden 0.99-12Rob Crittenden 0.99-11Rob Crittenden 0.99-10Rob Crittenden 0.99-9Rob Crittenden 0.99-8Rob Crittenden 0.99-7Rob Crittenden 0.99-6Rob Crittenden 0.99-5Rob Crittenden 0.99-4Rob Crittenden 0.99-3Rob Crittenden 0.99-2Rob Crittenden 0.99-1Rob Crittenden - 0.6.0-2Karl MacMillan - 0.6.0-1Karl MacMillan - 0.5.0-1Rob Crittenden - 0.4.1-2Karl MacMillan - 0.4.1-1Karl MacMillan - 0.4.0-6Rob Crittenden - 0.4.0-5Rob Crittenden - 0.4.0-4Karl MacMillan - 0.4.0-3Karl MacMillan - 0.4.0-2Karl MacMillan - 0.2.0-1Rob Crittenden - 0.1.0-3Rob Crittenden - 0.1.0-2Karl MacMillan - 0.1.0-1- Roll in CentOS Branding- Resolves: #1321138 Missing dependency package "python-sss-murmur" in ipa-server-3.0.0-50.el6.x86_64 - SPEC: Require python2 version of sssd bindings - Resolves: #1367026 Document and test procedure for running IdM Server in TLS 1.2+ environment - Require 389-ds-base with TLS 1.0 disable switch- Resolves: #1322059 IPA Replica-Install from RHEL6 to RHEL7 Fails - Modififed NSSConnection not to shutdown existing database. - Do not erroneously reinit NSS in Dogtag interface - Make sure replication works after DM password is changed- Resolves: #1351593 CVE-2016-5404 ipa: Insufficient privileges check in certificate revocation - cert-revoke: fix permission check bypass (CVE-2016-5404)- Update IPA code to support Samba 4.2 - Related: #1322689- Resolves: #1225868 display browser config options that apply to the browser - Chrome - Remove ico files from Makefile - Resolves: #1232843 ipa-client-install errors out if client and server time are not in sync or unreachable - Skip time sync during client install when using --no-ntp - Resolves: #1288495 Add userCertificate index used in Smart Card authentication - add DS index for userCertificate attribute - Resolves: #1293588 JavaScript error in ssbrowser.html - TypeError: Cannot read property 'mozilla' of undefined - webui: fix browser detection in browserconfig.html and ssbrowser.html - Resolves: #1296124 Adjust Firefox configuration to new extension signing policy - webui: use manual Firefox configuration for Firefox >= 40 - Remove binary patching from patch 0140- Resolves: #1127211 ipa-server-install --uninstall produces avc - sysrestore: copy files instead of moving them to avoind SELinux issues - Use 'mv -Z' in specfile to restore SELinux context - Resolves: #1222999 ipa aci plugin is not parsing aci's correctly. - ACI plugin: correctly parse bind rules enclosed in parentheses - Resolves: #1225868 display browser config options that apply to the browser - Chrome - webui: add Kerberos configuration instructions for Chrome - Remove ico files from Makefile - WebUI: fix ipa_error.css - Resolves: #1232468 The Domain option is not correctly set in idmapd.conf when ipa-client-automount is executed. - Simplify adding options in ipachangeconf - ipachangeconf: Add ability to preserve section case - ipa-client-automount: Leverage IPAChangeConf to configure the domain for idmapd - Resolves: #1232899 ipa-client-install does not respect --realm option - Allow user to force Kerberos realm during installation. - Resolves: #1276358 Remove /usr/share/ipa/updates/50-lockout-policy.update file from IPA 3.0 releases - Remove 50-lockout-policy.update file- Resolves: #1263703 ipa-server-install with externally signed CA fails with NSS error (SEC_ERROR_BUSY) - Free NSS objects in --external-ca scenario - Resolves: #1263262 Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Do not lookup up the domain too early if only the SID is known - Do not store SID string in a local buffer - Allow ID-to-SID mappings in the extdom plugin- Resolves: #1220788 - Some IPA schema files are not RFC 4512 compliant- Use tls version range in NSSHTTPS initialization - Resolves: #1154687 - POODLE: force using safe ciphers (non-SSLv3) in IPA client and server - Resolves: #1012224 - host certificate not issued to client during ipa-client-install- Resolves: #1205660 - ipa-client rpm should require keyutils- Release 3.0.0-44 - Resolves: #1201454 - ipa breaks sshd config- Release 3.0.0-43 - Resolves: #1191040 - ipa-client-automount: failing with error LDAP server returned UNWILLING_TO_PERFORM. This likely means that minssf is enabled. - Resolves: #1185207 - ipa-client dont end new line character in /etc/nsswitch.conf - Resolves: #1166241 - CVE-2010-5312 CVE-2012-6662 ipa: various flaws - Resolves: #1161722 - IDM client registration failure in a high load environment - Resolves: #1154687 - POODLE: force using safe ciphers (non-SSLv3) in IPA client and server - Resolves: #1146870 - ipa-client-install fails with "KerbTransport instance has no attribute '__conn'" traceback - Resolves: #1132261 - ipa-client-install failing produces a traceback instead of useful error message - Resolves: #1131571 - Do not allow IdM server/replica/client installation in a FIPS-140 mode - Resolves: #1198160 - /usr/sbin/ipa-server-install --uninstall does not clean /var/lib/ipa/pki-ca - Resolves: #1198339 - ipa-client-install adds extra sss to sudoers in nsswitch.conf - Require: 389-ds-base >= 1.2.11.15-51 - Require: mod_nss >= 1.0.10 - Require: pki-ca >= 9.0.3-40 - Require: python-nss >= 0.16- Require 389-ds-base >= 1.2.11.15-38 to fix roken dereference control with the FreeIPA 4.0 ACIs (#1112698)- ipasam does not support deleting multiple child trusted domains due to LDAP delete operation (#1110664) - Excessive LDAP calls by ipa-sam during file operations to samba file share on freeipa master cause high CPU and slow performance (#1074314)- Explicitly specify auth mechanism when calling ldapmodify in the installers (#1108661) - Add support for DNS classless reverse domains (#1095250) - Multiple nsDS5ReplicaId attributes created in cn=replication,cn=etc (#1109050) - ipa-client-install should configure sudo automatically (#1111121)- Rebuild package to fix a brew tag- ipa-server-install intermittently crashed with "Unable to find preop.pin" (#905064) - Disabled sudo rules were still active in the sudoers tree (#1022199) - Replica installation fails if forward zone is not present (#1034478) - Administrative password change did not respect user password policy (#1029921) - Re-initializing a winsync connection exits with "Can't contact LDAP server" (#1016042) - Server checked for unknown attributes before "ipa" tool version check (#1015481) - CA subsystem certificate renewal was broken on CA clones (#1040009) - Lockout plugin worked inconsistently compared to KDC lockout mechanism. Also, default user policy may not have been applied if krbPwdPolicyReference was missing (#1088772) - ipa-client-automount was not backwards compatible (#1082590) - Increase service timeout from 120s to 300s as some services are known to start for more than 120s (#1060639) - Proxy calls to /ca/ee/ca/profileSubmit to PKI to enable installation of replicas with Dogtag 10 PKI (#1083878)- group-add-member command reported wrong error on duplicates (#970541) - ipa-client installation succeeding in ipa server instance (#1011044)- ipa-join failed when doing a forced host re-enrollment (#924009)- ipa-replica-manage del always exits with error (#1005448)- Host and Hostgroup commands were broken after upgrade (#1001810)- Fix coverity issue in AD 2012 stabilization patch fixing memleaks (#980409)- Fix coverity issue in AD 2012 support patch and add 2 related stabilization patches (#980409)- Require 389-ds-base >= 1.2.11.15-14 to pick up fix for CVE-2013-1897 (#928162) - Password policy lockout plugin does not work as expected (#907881 - Remove deprecated support of the HBAC source host (#924542) - ipa-client-install may not obtain CA certificate (#924004) - Allow client to re-enroll without first unenrolling (#924009) - Enrolling a host into may take two attempts (#950014) - Add userClass attribute for host objects (#955698) - Inconsistent replies from FreeIPA to Netlogon ping queries (#967870) - Performance improvement for IPA CLI and UI user and group related plugins (#970541) - Do not create /var/lib/ipa/pki-ca/publish, retain reference as ghost (#975431) - Add support for AD 2012 trusted domains (#980409) - XML-RPC server may return a wrong Content-Type (#976716) - Add missing openssh-clients Requires to ipa-server package (#983463) - Add an option to edit "Gecos" field from Web UI (#986211)- LDAP upload CA cert sometimes double-encodes the value (#948928) - wrong trust argument assigned to renewed certs in ipa cert automatic renew (#952241)- ipa-client-install fails to autodiscover on LDAP servers with disabled anonymous access (#922843)- ipa-adtrust-install and ipa-replica-conncheck may not parse krb5.conf correctly and crash (#916209)- Missing LDAP schema attributeType and objectClass after upgrade (#915745)- Significant decrease in migration performance. (#904119) - ipa-client-install failed to fall over to replica with master down (#905626) - During Migration - If Schema is unavailable migration fails (#906846)- Filter generated winbind dependencies so the right version of samba can be installed. (#905594)- Add certmonger condrestart to server post scriptlet (#903758) - Make certmonger a (pre) Requires (#903758) - Add selinux-policy to Requires(pre) to avoid post scriptlet AVCs (#903758) - Set minimum version of pki-ca to 9.0.3-30 and add to Requires(pre) to pick up certmonger upgrade fix (#902474) - Update anonymous access ACI to protect secret attributes (#902481)- Installer should not connect to 127.0.0.1. (#895561) - Don't initialize NSS if we don't have to. (#878220)- Set minimum version of bind-dyndb-ldap to 2.3-2 to pick up missing DNS zone SOA serial fix (#894131) - Stopped named service crashed ipa-upgradeconfig program (#895298) - ipa-replica-prepare crashed when manipulating DNS zone without SOA serial (#894143) - Use new certmonger locking to prevent NSS database corruption during CA subsystem renewal (#883484) - Set minimum selinux-policy to 3.7.19-193 to allow certmonger to talk to dbus in an rpm scriptlet. (related #883484) - Set minimum vresion of certmonger to 0.61-3 for new locking scheme (related #883484)- Properly handle migrated uniqueMember attributes (#894090) - ipa permission-find using valid targetgroup throws internal error (#893827) - Fix migration of CRLs to new directory location (#893722) - Installing IPA with a single realm component sometimes fails (#893187)- Set maxbersize to a large value to accomondate large CRLs during replica installation. (#888956) - Set minimum version of pki-ca, pki-slient and pki-setup to 9.0.3-29 to pick up default CA validity period of 20 years. (#891980)- Client installation crashes when Kerberos SRV record is not found (#889583) - Fix typo in patch 0048 for CVE-2012-5484 (#878220)- Cookie Expires date should be locale insensitive to avoid CLI errors (#888915)- ipa delegation-find --group option returns internal error (#888524) - Add missing Requires for python-crypto replacement (#878969)- sssd is not enabled on client/server install (#888124)- ipa-server-install --uninstall doesn't clear certmonger dirs, which leads to install failing (#817080)- Compliant client side session cookie behavior. CVE-2012-5631. (#886371)- Use secure method to retrieve IPA CA during client enrollment. CVE-2012-5484 (#878220) - Reformat patch 0044 so it works with git-am- Include /var/lib/sss/pubconf/krb5.include.d/ for domain-realm mappings in krb5.conf (#883166) - Set minimum selinux-policy >= 3.7.19-184 to allow domains that can read sssd_public_t files to also list the directory (#881413) - Remove dist label from changelog entries. - Fix timestamp on patched files to avoid multilib warnings- Set Requires on httpd 2.2.15-24, mod_nss to 1.0.8-18 and patch to check for existing mod_ssl configuration. These versions allow mod_proxy to simultaneously support SSL servers using mod_ssl and mod_proxy (#761574) - IPA WebUI login for AD Trusted User fails (#875261) - Add 'disable_last_success' and 'disable_lockout' to the ipa_lockout plugin (#824488)- Make default group type POSIX in ui (#880655) - Write replacement for python-crypto (#878969) - ipa trust-add prints misleading information about required DNS setting (#878485) - Lookup user SIDs in external groups (#878480) - Special case NFS related ticket to avoid attaching MS-PACs (#878462) - IPA users are not available after ipa-server-install because sssd not running (#878288) - Incorrect error message when time difference between AD and IPA is too great (#877434) - Missing option to add SSH Public Key in Web UI after upgrade (#877324)- Update minimum BR and Requires of sssd to 1.9.2-25 (related #870278, related #871160, related #878262) - Replication agreement tools report errors with new single instance CA database (#878491) - If time is moved back on the IPA server, ipasam does not invalidate the existing ticket (#866576)- Server installation fails to find A/AAAA record for IPA hostname (#874935) - Out of range error when listing RUV on host with no agreements (#873726) - Tighten dependency on krb5-server to limit to 1.10 (#872707) - Default SELinuxusermaporder needs to mapped with default selinux users list (#870053) - Clarify trust-add help regarding multiple runs against the same domain (#869741) - Improve reliabilityof RA renewal script (#869663) - Add option to disable DNS forwarding by zone (#869658) - Update minimum version of bind-dyndb-ldap to 2.3-1 (#869658) - Improve information on passsync user in man page, command help (#869656) - Resolve external members from trusted domain via Global Catalog (#869616) - Process relative nameserver DNS record correctly (#868956) - ipa-adtrust-install does not reset all information when re-run (#867447) - Fix potential memory leak in KDB backend (#811989)- Fix type conversion of integers when doing modifications (#870446) - Set SECURE_NFS to lowercase yes rather than uppercase (#869654) - Add autofs service to sssd.conf before enabling it (#869649) - Add strict Requires for policycoreutils to avoid user removing them during package lifetime (#869281) - Make internal rename_s() call compatible with python-ldap-2.3.10 (#867902) - Update minimum version of bind-dyndb-ldap to 2.2-1.el6 (related #871583) - Restart httpd after running ipa-adtrust-install (#866966)- Add patch to override xmlrpc request method for session (#786199) - Bad link to Web UI config page after session is expired (#869279) - extdom plugin does not handle Posix UID and GID request (#867676) - ipa-server-install --setup-dns always installs reverse zone (#866978) - Inform user when ipa-upgradeconfig reports errors (#866977) - Certificate request fails when CSR has subjectAltnames (#866955) - ipa-adtrust-install checks for /usr/bin/smbpasswd, which is not required (#866572) - Instructions to uninstall are unclear (#856294) - Inconsistent service naming in ipa-server-install (#856292) - Improve instructions to generate certificate in Web UI (#856282) - /etc/ipa/default.conf is out of date (#855855) - Time synchronization is disabled in ipa-client-install (#854325) - ipa-replica-install httpd restart sometimes fails (#845405) - Improve error messages during ipa-replica-manage del (#835632) - Always log errors from dogtag (#813401)- Update to upstream 3.0.0 GA release (#827602) - Add zip dependency, needed for creating unsigned Firefox extensions - Filter generated winbind dependencies so the right version of samba can be installed. - Remove patch to support python-ldap 2.3.10. Fixed upstream. - Add directory /var/lib/ipa/pki-ca/publish for CRL published by pki-ca (#864533) - Add zip dependency, needed for creating unsigned Firefox extensions- Make sure server-trust-ad subpackage alternates winbind_krb5_locator.so plugin to /dev/null since they cannot be used when trusts are configured (related #864889) - Update BR and Requires of samba4 to 4.0.0-31 to pick up winbind_krb5_locator alternatives change. (related #864889)- Update to upstream 3.0.0.rc2 release (#827602) - Provide new Firefox extension. - Own /etc/ipa/ca.crt- Remove Requires on krb5-pkinit-openssl as part of disabling pkinit code. - Add missing subdirectories in site-packages/ipaserver discovered by rpmdiff. (#827602)- Update to upstream 3.0.0.rc1 release (#827602) - Update BR and Requires of 389-ds-base to 1.2.11.14 - Update BR and Requires of krb5 to 1.10 - Update BR and Requires of samba4 to 4.0.0-24 - Update BR and Requires of sssd to 1.9.0 - Update Requires on policycoreutils to 2.0.83-19.24 - Update Requires on httpd to httpd-2.2.15-17 to pick up #787247 - Update minimum version of bind-dyndb-ldap to 1.1.0-0.9.b1.el6_3.1 - Update minimum version of bind to 9.8.2-0.10.rc1.el6_3.2 - Sync upstream spec file Requires - Add patch to support python-ldap 2.3.10- SSH Tech Preview feature enabled by default (#825321)- Test for locked users before incrementing failed login counter (#822429)- Fix host page to display all data when DNS is not configured (#818868)- Make ipa 2.2 client capable of joining an older server (#817867)- Remove patch 0042 and add revert patch for handling which attributes are allowed in a permission. (#783502) - ipa-client-install sets "KerberosAuthenticate yes" in sshd.conf, breaking SSSD auth (#817030) - pwpolicy_find does not sort by priority in UI (#815799) - Improve zonemgr validation (#745705)- Make new DNS permission mixed-case (#807361) - hbactest returns failure when hostgroups are chained (#801769) - Man Page : Document client IP addressing / FQDN requirements (#768257) - Login failed attempts counter or locked out status are not displayed (#759501) - Wrong title and icon in login and logout pages (#814752)- Don't interactively prompt for dnsrecord options provided on the command-line options (#790295) - Validate external hosts added to netgroups (#797256) - Handle invalid RDN for container in migration (#804807) - Unable to use permission-mod to rename permission object (#805478) - Migration: don't append basedn to container if it is included (#807371) - Raise correct exception when LDAP limits are exceeded (#808042) - Notify user that password needs to be reset in forms-based login (#811296) - DNS Resource records: add & delete A & AAAA record does not work in root (#811744) - user-mod --rename with an empty string fails (#811748) - DNS CNAME record: delete sometimes does not work (#811758) - Delegation UI does not allow to specify permission (#812110) - IPA uninstall after upgrade returns some sysrestore.state errors (#812391) - Improve migration plugin error when 2 groups have identical GID (#813389)- Fix password policy history enforcement (#810900) - Privilege page should not have choice to list permissions by "indirect membership" (#810350) - ipa-server-install fails when domain name is not resolvable (#809190) - Identity->DNS->Settings:Forward policy: change check box to radio buttons (#808620) - When adding permissions for a type, attributes that are not allowed are listed (#807755) - user-mod --rename is successful for more than max login characters (#807417) - Can't specify netgroup host, user category to all in Web UI (#807366) - Permission names cannot contains '<' or '>' (#807304) - ipa-server-install --uninstall errors out when trying to start dirsrv. (#801376) - Should not be allowed to run host-disable on an IPA Server or service-disable on an IPA Server service (#800119) - permission with filter or subtree does not allow attr to be specified (#783536) - Netgroups compat plugin not reporting users correctly (#767372) - certmonger renews server certificates ok but those services need a restart (related #766167) - Set minimum vresion of certmonger to 0.56 (related #766167) - Set minimum version of slapi-nis to 0.40 (#767372) - Unable to disable or enable hbacrule with --setattr (#810948) - When adding a user with --noprivate option gidNumber should be required (#805546) - Fix error when no value is given in --revocation-reason optional argument with "ipa cert-revoke" (#808099) - Set minimum version of bind-dyndb-ldap to 1.1.0-0.5.b1 (related #805814)- Fix ambiguous error msg in automount indirect map creation (#790131) - Invalid error message attempting to delete config attributes (#791373) - Enforce single-value attributes (#794746) - config-mod allowed to add additional certificate subjects bases (#794750) - Embedded carriage returns in a CSV not handled (#797569) - WebUI displays "Insufficient access: invalid credentials" when a password doesn't meet policy requirements (#802786) - Tech Preview: SELinux User Mapping (#803821) - Tech Preview: Add support for central management of the SSH keys (#803822) - Password Policy Failure Interval Reset is not working. (#804096) - Set SELinux booleans properly (#806330) - DNS records in LDAP are publicly accessible (#807361) - Upgrading replication agreements without nsDS5ReplicatedAttributeList fails (#808201) - IPA Upgrade Web UI failure with internal server error (#809262) - Do not create private groups for migrated users (#809560)- Remove version requirement from BuildRequires on sssd. (related #736865)- Set minimum version of 389-ds-base to 1.2.10.2-4 (related #803930) - Only split CSV on client (#797565) - Search allowed attributes in superior objectclasses (#783502) - Fix precallback validators in DNS plugin (#804562) - Fix memleak in KDB backend (#800363) - Harden raw record processing in DNS plugin (#804572) - Fix attributes that contain DNs when migrating (#804609) - Wait for child process to terminate after receiving SIGINT (#754635) - Avoid deleting DNS zone when a context is reused (#801380) - Fix default SOA serial format (#805427) - Set nsslapd-minssf-exclude-rootdse to on so the DSE is always available. (#803836) - Amend permissions for new DNS attributes (related #766073) - Improve user awareness about dnsconfig (#802864) - Fix uses of O=REALM instead of the configured certificate subject base. (#802912) - Fix dnsrecord-del interactive mode (#807230) - Add requires on python-krbV to client subpackage (#807362) - Tolerate UDP port failures in conncheck (#802860) - Netgroup nisdomain and hosts validation (#797256) - Remove Conflicts on mod_ssl (#804605) - Set minimum version of pki-ca, pki-slient and pki-setup to 9.0.3-24. Change location of TOMCAT_LOG to match tomcat6 changes (related #802396) - Add python-lxml, python-pyasn1 and sssd to BuildRequires - Set minimum selinux-policy >= 3.7.19-142 to pick up certmonger_t type (related #790967) - netgroup-add and netgroup-mod --nisdomain should not allow commas (#797237)- Set minimum version of pki-ca, pki-silent and pki-setup to 9.0.3-23. Either we shell escape or dogtag does, we can't both do it. (#802832) - Set dbdir in request context after a connection is created (#804128) - Don't overwrite content by an error message (#803050) - Don't allow IPA master hosts/services to be disabled (#800119) - Don't error out on empty option (#798792) - Populate gidnumber in entries added via winsync (#798352) - Set subjectKeyIdentifier in SSL certs that IPA issues (#797274) - Fix escaping and comma-separated value handling (#769491) - Display certificate serial numbers in both hex and deciaml (#746060) - Use attribute name/option name when returning errors (#718015) - DNS forwarder's value can consist of IP address and part (#766073) - Store DNS global options in LDAP (#766073) - Move extension.js to subdirectory to suppress rpm warning- Allow removing sudo commands with special characters (#800537) - Ignore case in yes/no prompts when deleting DNS records (#800483) - Refresh resolvers after DNS server configuration (#799335) - Fix nsslapd-anonlimitsdn in cn=config (#798361) - Handle more exceptions gracefully in ipa-client-install (#797567) - Fixed checkbox value in table without pkey (#791324) - Fix exception when removing all values from configuration (#782974) - Set httpd_manage_ipa SELinux boolean - Fix mask validator in network validator (#802848) - Don't shell escape arguments sent to pkisilent (#802832) - Reorder patches so those that disable unsupported features are applied last - Rebase disable persistent search patch- Rebase to upstream 2.1.90.rc1 release (#736865) - Remove dependency on krb5-server-ldap, we use our own backend now (#797564) - Set minimum mod_auth_kerb to 5.4-8 for S4U2Proxy support (related #767741) - Set minimum selinux-policy >= 3.7.19-137 to pick up ipa_memcache boolean - Set minimum python-memcached >= 1.43-6 to pick up status check fix - Set minimum version of 389-ds-base to 1.2.10.1-1 - Set minimum version of krb5-server to 1.9-27 - Set minimum version of sssd to 1.8.0-11 (#766068) - Add Requires: oddjob-mkhomedir to ipa-client (#786223) - Remove Requires on krb5-server-ldap (#797564) - Add Conflicts on mod_ssl (#761574) - Remove BuildRequires on python-rhsm - Renumber all patches - Don't remove dirsrv user on uninstall (#797566) - Don't allow host-del on active replicas (#797563) - Fix invalid hostnames when hostname contains trailing dot (#797562) - encode Bool attributes used in setattr/addattr/delattr (#797561) - Migration plugin raises Internal Server Error (#796401) - man page for ipa-replica-manage has typos in examples (#796347) - Can not add new user objectclass to ipa configuration (#794474) - Don't require SELinux to be enabled on client (#790513) - dnsrecord-add does not validate the record names with space in between (#790318) - Prompt for missing DNS options (#790295) - Resource Record type options should be more descriptive (#790017) - Correction in error message while deleting a invalid record (#789987) - Adding some of the RR type from the "allowed values" results in an error message (#789980) - IP address with just 3 octets are accepted as valid addresses (#789919) - Errors not reported correctly when logging into WebUI (#789459) - Need option for ipa-client-install to not call authconfig (#789413) - IPA nested netgroups not seen from ypcat (#788625) - gid number: 0 and negative number accepted (#786240) - Allow basedn to be passed into migrate-ds (#786185) - permission with filter or subtree does not allow attr to be specified (#783536) - ipa permission-add does not fail if using invalid attribute (#783502) - When migrating warn user if compat is enabled (#783270) - Make ipausers a non-posix group on new installs (#773488) - Need tool to update exclusive list in replication agreements (#772359) - Reverse DNS rec not created upon creation of fwd DNS rec (#772301) - Adding a netgroup with a "+" causes ns-slapd to crash (#772043) - Man Page : Document client IP addressing / FQDN requirements (#768257) - GSS-TSIG DNS updates should update reverse entries as well (#767725) - UI for SELinux user mapping (tech preview) - Allow forms based kerberos authentication (#766070) - Add support for central management of the SSH keys (tech preview) - Login failed attempts counter or locked out status are not displayed (#759501) - Better message for error diagnosis while adding an existing winsync agreement (#755450) - "force-sync, re-initialize and del" options for ipa-replica-manage fail against AD (#754973) - Connect after del using ipa-replica-manage fails (#754539) - Unable to delete migrated groups containing spaces (#753966) - support bind forward zones, aka DNS conditional forwarding (#753483) - IPA needs a check to ensure hostnames 'underscore' is not allowed when installing a replica (#752874) - Unable to select dns zone when only one exists in UI (#751529) - ipa-replica-conncheck does does not properly check UDP ports (#751063) - Adding loc records to a ipa-dns server breaks name resolution for some other records (#750947) - Allow specifying query and transfer policy settings for a zone (#701677)- Add missing changelog information caught by rpmdiff.- Update to upstream 2.1.90.pre2 release (#736865)- Add current password prompt when changing own password in web UI (#751179) - Remove extraneous trailing ' from netgroup patch (#749352)- Updated patch for CVE-2011-3636 to include CR in the HTTP headers. xmlrpc-c in RHEL-6 doesn't suppose the dont_advertise option so that is not set any more. Another fake header, X-Original-User_Agent, is added so there is no more trailing junk after the Referer header. (#749870)- Require an HTTP Referer header to address CSRF attackes. CVE-2011-3636. (#749870)- Users not showing up in nis netgroup triple (#749352)- Add update file to remove entitlement roles, privileges and permissions (#739060)- Quote worker option in krb5kdc (#748754)- hbactest fails while you have svcgroup in hbacrule (#746227) - Add Kerberos domain mapping for system hostname (#747443) - Format certificates as PEM in browser (#701325)- ipa-client-install hangs if the discovered server is unresponsive (#745392) - Fix minor problems in help system (#747028) - Remove help fix from Disable automember patch (#746717) - Update minimum version of sssd to 1.5.1-60 to pick up SELinux fix (#746265)- Update to upstream 2.1.3 release (#736170) - Additional branding (#742264) - Disable automember cli (#746717) - ipa-client-install sometimes fails to start sssd properly (#736954) - ipa-client-install adds duplicate information to krb5.conf (#714597) - ipa-client-install should configure hostname (#714919) - inconsistency in enabling "delete" buttons (#730751) - hbactest does not resolve canonical names during simulation (#740850) - Default DNS Administration Role - Permissions missing (#742327) - named fails to start after installing ipa server when short (#742875) - Duplicate hostgroup and netgroup should not be allowed (#743253) - named fails to start (#743680) - Global password policy should not be able to be deleted (#744074) - Client install fails when anonymous bind is disabled (#744101) - Internal Server Error adding invalid reverse DNS zone (#744234) - ipa hbactest does not evaluate indirect members from groups. (#744410) - Leaks KDC password and master password via command line arguments (#744422) - Traceback when upgrading from ipa-server-2.1.1-1 (#744798) - IPA User's Primary GID is not being set to their UPG's GID (#745552) - --forwarder option of ipa-dns-install allows invalid IP addr (#745698) - UI does not grant access based on roles (#745957) - Unable to add external user for RunAs User for Sudo (#746056) - Typo in error message while adding invalid ptr record. (#746199) - Don't use python 2.7-only syntax (#746229) - Error when using ipa-client-install with --no-sssd option (#746276) - Installation fails if sssd.conf exists and is already config (#746298) - External hosts are not removed properly from sudorule (#709665) - Competely remove entitlement support (#739060) - Add winsync section to ipa-replica-manage man page (#744306)- Remove python-rhsm as a Requires (#739060)- Update to upstream 2.1.2 release (#736170) - More completely disable entitlement support (#739060) - Drop patch to ignore return value from restorecon (upstreamed) - Set min version of 389-ds-base to 1.2.9.12-2 - Set min version of dogtag to 9.0.3-20 - Rebased hide-pkinit, ipa-RHEL-index and remove-persistent-search patches (#700586)- Update RHEL patch (#740094)- Ignore return value from restorecon (#739604) - Disable entitlement support (#739060, #739061)- Update minimum xmlrpc-c version (#736787) - Fix package installation order causing SELinux problems (#737516)- Update to upstream 2.1.1 release (#732803)- Resolves: rhbz#708388 - Update to upstream 2.1.0 release- Remove client debug logging patch (#705800)- Wait for 389-ds tasks to complete (#698421) - Set replica to restart ipa on boot (#705794) - Improve client debug logging (#705800) - Managed Entries not configured on replicas (#703869) - Don't create bogus aRecord when creating new zone (#704012)- Update ipa-Fix-traceback-in-nis-manage.patch to fix python error (#697583)- Resolves: rhbz#697583 - Can not enable ipa-nis-manage plugin- Default groups are missing ipaUniqueID attribute (#696508)- Set min version of 389-ds-base to 1.2.8.0-1 for fix in BZ 693466. - Fix some problems in IPA schema (#692978) - postalCode should be a string not an integer (#692945)- Port 7390 is managed by selinux-policy-3.7.19-80. Update ipa-repl_selinux.patch to not manage it any more. (#691883) - Patch to fix setting gidnumber when a user is created. (#692168)- Fix uninitialized variable in password plugin (#690595)- Wait for Directory Service ports to open (#688934) - Mixed case hostname can cause issues and confusion (#688622) - Wrong timeout parameter in ipapython (#684273) - Run ipa-ldap-updater on upgrades (#688931) - Internal Error and trace back when adding DNS AAAA record (#689452)- Use realm provided by installer in LDAP Updater (#684744) - Use args for domain and server when doing DNS discovery in client (#684780) - Fix 2 SELinux issues in dogtag replication (#684269)- Add Obsoletes so upgrade from ipa-client package is possible (#684931)- Update to upstream 2.0.0rc3 (#680993) - Set minimum version of sssd to 1.5.1-12 - Remove SuitespotGroup patch - Rebase remove-pkinit patch- Set the SuitespotGroup directive in the 389-ds installation template. This ensures group read/write to /var/run/dirsrv. (#680201) - Make single line out of python sitelib/sitearch code.- Update to upstream 2.0.0rc2 (#675282) - Set minimum version of sssd to 1.5.1-10 - Set minimum version of python-nss to 0.11 - Set minimum version of 389-ds to 1.2.8 - Add bind-utils as Requires in client subpackage - Remove unused BuildRequires e2fsprogs-devel and libcap-devel - Add branding patch - Add default.conf man page - Upstream moved some utilites from the admintools subpackage, reflect that here as well.- Add pyOpenSSL to BuildRequires. (#670954)- ExcludeArch doesn't do per-package exclusions, use ifarch to force ONLY_CLIENT on non-supported architectures. (#670954) - Manually install ipa-admintools since the upstream client-install target doesn't. - Move a lot of the BuildRequires out of the ! ONLY_CLIENT conditional because the API validator in the upstream code requires them.- Exclude building server and server-selinux on ppc, ppc64, s390 and s390x platforms. (#670954) - Add date variable to the release to make daily builds easier.- Merge in changes from FreeIPA beta 2 (#670954) - Add patches to disable pkinit- Set minimum version of dogtag to 9.0.0 and add Requires for the theme we need. (#658275) - Remove unnecessary moving of v1 CA serial number file in post script - Move some man pages into admintools subpackage- Drop specific Requires on libcurl and krb5-libs (#658275)- Consistent usage of buildroot vs RPM_BUILD_ROOT (#658275)- Drop Requires on nss-ldap (#658275)- Temporarily disable building on s390- Drop optional radius package, the underlying code isn't there - Re-arrange the doc lines so that defattr is first (#658275)- Initial 2.0.0 build (#658275) - This is IPA v2.0.0 beta 1 plus all patches through git commit 4da9228fb2ac34adab8eb1884ae414236adb84fa - Removed some Fedora conditionals- Drop BuildRequires on mozldap-devel- Add Requires on krb5-pkinit-openssl- Add ipa-host-net-manage script- Add ipa init script- Set minimum level of 389-ds-base to 1.2.7 for enhanced memberof plugin- remove ipa-fix-CVE-2008-3274- Remove duplicate %files entries on share/ipa/static - Add python default encoding shared library- Drop requires on python-configobj (not used any more) - Drop ipa-ldap-updater message, upgrades are done differently now- Drop conflicts on mod_nss - Require nss-pam-ldapd on F-14 or higher instead of nss_ldap (#606847) - Drop a slew of conditionals on older Fedora releases (< 12) - Add a few conditionals against RHEL 6 - Add Requires of nss-tools on ipa-client- Set minimum version of certmonger to 0.26 (to pck up #621670) - Set minimum version of pki-silent to 1.3.4 (adds -key_algorithm) - Set minimum version of pki-ca to 1.3.6 - Set minimum version of sssd to 1.2.1- Add BuildRequires for authconfig- Bump up minimum version of python-nss to pick up nss_is_initialize() API- Removed python-asset based webui- Change Requires from fedora-ds-base to 389-ds-base - Set minimum level of 389-ds-base to 1.2.6 for the replication version plugin.- Drop Requires of python-krbV on ipa-client- Load ipa_dogtag.pp in post install- Set minimum level of sssd to 1.1.1 to pull in required hbac fixes.- No need to create /var/log/ipa_error.log since we aren't using TurboGears any more.- Fixed share/ipa/wsgi.py so .pyc, .pyo files are included- Added Require mod_wsgi, added share/ipa/wsgi.py- Require python-wehjit >= 0.2.2- Add sssd and certmonger as a Requires on ipa-client- Require python-wehjit >= 0.2.0- Add ipa-rmkeytab tool- Set minimum of python-pyasn1 to 0.0.9a so we have support for the ASN.1 Any type- Remove v1-style /etc/ipa/ipa.conf, replacing with /etc/ipa/default.conf- Add bash completion script and own /etc/bash_completion.d in case it doesn't already exist- Remove ipa_webgui, its functions rolled into ipa_httpd- Removed python-cherrypy from BuildRequires and Requires - Added Requires python-assets, python-wehjit- Added httpd SELinux policy so CRLs can be read- Move ipalib to ipa-python subpackage - Bump minimum version of slapi-nis to 0.15- Set 0.14 as minimum version for slapi-nis- Add Requires: python-nss to ipa-python sub-package- Remove the IPA DNA plugin, use the DS one- Build radius separately - Fix a few minor issues- Replace TurboGears requirement with python-cherrypy- rebuild with new openssl- Fix SELinux code- Fix breakage caused by python-kerberos update to 1.1- New upstream release 1.2.1- Rebuild for Python 2.6- Respin after the tarball has been re-released upstream New hash is 506c9c92dcaf9f227cba5030e999f177- Conditionally restart also dirsrv and httpd when upgrading- Update to upstream version 1.2.0 - Set fedora-ds-base minimum version to 1.1.3 for winsync header - Set the minimum version for SELinux policy - Remove references to Fedora 7- Fix for CVE-2008-3274 - Fix segfault in ipa-kpasswd in case getifaddrs returns a NULL interface - Add fix for bug #453185 - Rebuild against openldap libraries, mozldap ones do not work properly - TurboGears is currently broken in rawhide. Added patch to not build the UI locales and removed them from the ipa-server files section.- Add call to /usr/sbin/upgradeconfig to post install- Update to upstream version 1.1.0 - Patch for indexing memberof attribute - Patch for indexing uidnumber and gidnumber - Patch to change DNA default values for replicas - Patch to fix uninitialized variable in ipa-getkeytab- Set fedora-ds-base minimum version to 1.1.0.1-4 and mod_nss minimum version to 1.0.7-4 so we pick up the NSS fixes. - Add selinux-policy-base(post) to Requires (446496)- Add missing entry for /var/cache/ipa/kpasswd (444624) - Added patch to fix permissions problems with the Apache NSS database. - Added patch to fix problem with DNS querying where the query could be returned as the answer. - Fix spec error where patch1 was in the wrong section- Added patch to fix problem reported by ldapmodify- Fix Requires for krb5-server that was missing for Fedora versions > 9 - Remove quotes around test for fedora version to package egg-info- Update to upstream version 1.0.0- Pull upstream changelog 722 - Add Conflicts mod_ssl (435360)- Pull upstream changelog 698 - Fix ownership of /var/log/ipa_error.log during install (435119) - Add pwpolicy command and man page- Pull upstream changelog 678 - Add new subpackage, ipa-server-selinux - Add Requires: authconfig to ipa-python (bz #433747) - Package i18n files- Pull upstream changelog 641 - Require minimum version of krb5-server on F-7 and F-8 - Package some new files- Marked with wrong license. IPA is GPLv2.- Ensure that /etc/ipa exists before moving user-modifiable html files there - Put html files into /etc/ipa/html instead of /etc/ipa- Pull upstream changelog 608 which renamed several files- package the sessions dir /var/cache/ipa/sessions - Pull upstream changelog 597- Updated upstream pull (596) to fix bug in ipa_webgui that was causing the UI to not start.- Included LICENSE and README in all packages for documentation - Move user-modifiable content to /etc/ipa and linked back to /usr/share/ipa/html - Changed some references to /usr to the {_usr} macro and /etc to {_sysconfdir} - Added popt-devel to BuildRequires for Fedora 8 and higher and popt for Fedora 7 - Package the egg-info for Fedora 9 and higher for ipa-python- Added auto* BuildRequires- Unified spec file- Fixed License in specfile - Include files from /usr/lib/python*/site-packages/ipaserver- Version bump for release- Preverse mode on ipa-keytab-util - Version bump for relase and rpm name change- Broke invididual Requires and BuildRequires onto separate lines and reordered them - Added python-tgexpandingformwidget as a dependency - Require at least fedora-ds-base 1.1- Version bump for release- Add dep for freeipa-admintools and acl- Add dependency for python-krbV- Require mod_nss-1.0.7-2 for mod_proxy fixes- Convert to autotools-based build* Fri Sep 7 2007 Karl MacMillan - 0.3.0-1 - Added support for libipa-dna-plugin- Added support for ipa_kpasswd and ipa_pwd_extop- Abstracted client class to work directly or over RPC- Add mod_auth_kerb and cyrus-sasl-gssapi to Requires - Remove references to admin server in ipa-server-setupssl - Generate a client certificate for the XML-RPC server to connect to LDAP with - Create a keytab for Apache - Create an ldif with a test user - Provide a certmap.conf for doing SSL client authentication- Initial rpm version/bin/shipa-clientipa-client-debuginfo  !"3.0.0-51.el6.centos3.0.0-51.el6.centos 2.0-9.el62.0-9.el6 ipaclient__init__.py__init__.pyc__init__.pyoipachangeconf.pyipachangeconf.pycipachangeconf.pyoipadiscovery.pyipadiscovery.pycipadiscovery.pyontpconf.pyntpconf.pycntpconf.pyoipa-client-automountipa-client-installipa-getkeytabipa-joinipa-rmkeytabipa-client-3.0.0COPYINGContributors.txtREADMEipaipaclientipa.cfgipa.jsipa-client-automount.1.gzipa-client-install.1.gzipa-getkeytab.1.gzipa-join.1.gzipa-rmkeytab.1.gzdefault.conf.5.gzipa-clientsysrestore/usr/lib/python2.6/site-packages//usr/lib/python2.6/site-packages/ipaclient//usr/sbin//usr/share/doc//usr/share/doc/ipa-client-3.0.0//usr/share//usr/share/ipa//usr/share/ipa/ipaclient//usr/share/man/man1//usr/share/man/man5//var/lib//var/lib/ipa-client/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablescpioxz2i686-redhat-linux-gnu?7zXZ !PH6] b2u jӫ`(i*‰A#efqH@Z"?`Go֨vۉ'Ԛ;jMp$-΂*TL8Gk*c~m_Bwh-!^?f{<Si%X}^;[jf ']%fF^piI+e\D>x/栐3L–ϯS4z6aVn޳/q%{2za*"G&8Mm? d?|ќvl@ۼO~8 $.{  %ŋN<x{ s IoedWdYN[o:Ly*NZ?.I͈8%$ҺHT?>ht~ˡJ!EP4Zֺrxa,6AҘmi C)AE q&QLe{uv׃X1&`SD1MR~b9saN?4UBms#7qT8s%gM/DMK:P LޓW5jt(ĹTlF1hiwoKEOOU6ϙ{Y(:/:W28yW,4FB*y 2 =JSA /5hO 9? /Bt&ð8}":鹳DZ ̊#!/y9;v?5FHdldL) FARǥ+@PfȷpJvj% %` %G 49&tQUb:>^On€y<,38AzFߘl"E #†YWt^ΫxT,uD@U{ekW.pNLjLCu\:5T*&=G{;T4!ۀ!5/ Pz 4(wЖʳ3)`֫+щ :?wb P;}"!sݍtfʁI4cΘ]HѶmi"9|V񈽎-xK Uw(i JWl:Ԙٛƅ]SR@ ʧ*YeASGRG1Ěbo+\۞1jm{jd%H1<=D{X]q By^R Y>< {<"-C$5s d\=%Z X=#Z*.}#c|r]՜&2M0S;\C0vz1)w[:H `?fL F4-@v J E(pWI8*t<󤊘|O`8{UZ4; Z :B8ĺI agE^m+mwl C莘g80w`nGi4b_mo0'c`2 SX"Ô'xcW1,( sDBy$(wΛ Rު N+Ae>}&'ǃ7OM;,u؅ gE1 qdEQva鷪f-DCbd[*xH.#\1A N+VW ^&ܰ;Ʃhv")mkrԤk-%oxf{ۼZȗ5]KDzƝ"\s6; J1a v&E~ 1iTt!'bєdEL5tB{e xPcPu\{:J6Ҵ:)9aZExw\V]_6Y;ӪCwl2YqC?A[Xjw ?Khُ.2Usl[ 5a%tnPoNڍwbj0YTUZ?$k(*-)DUJl^L},H~31 #YzeW6d2*Cw{Sm`!]vY&6?ƭ:NfZsHygs!{d$·४s"!ÙUt 3P+b-lCW+mx?̟ZA6dF:(tfP1 ѭR<&U/ [PHl衫a{JyϺcҕ/G6WH]sR8w\m)I:1/K /0i]zz}wXl0#斝*Tߤ誁8 ~Y/amE>^Qg&%+P^MO HoXoL;́х]CZXZ `x e*9Qq‚&‿ֺk]&4,4hNp᠄A.Kw0uw qԅիƕ&Ta&a 3h`)WGBK: Ίe,ȟ.^G jt? 0e^;]`!攖-XMN5RTicμzx׬PJuEڔ ^ z"hK}'4{v-p+Z-1`EVC]>B(n.֐(*R5_z鏬9h5ewɣ6S,+8}yJF3u-X;Pd+xrEk(υ!Z)Xrp ɿ@J#b98-0T.X-2Q |b 3qydx,Q`pfiP/rN7ºs*8Tў.З9kᐋs~}`g XX̵BKGppp?􄌭_2&Wih! J~oAIN󠾚Ƥ!S\SᤑP(Dw ,`ȊR8j1n9]0=5"L)+7iBjn#K^ŭҾ2gP8w]*HH] \H;d\dq4n%Wa Q5} _E`gt=*j0KH:P#w˴bG1JZaRа!Q uz8U1)/j~#F4yEpLf:1}b'c}CQ1}Q̊n[P]y fN~G@UQߘUO6U?ko8d -+Vw7Ď'N+]$Ww x)FE]85Kypuª?w=lHb@nAxH] @ퟩ#opVSWY_fy0Zh-/ 9~:4aQkW7 f'LJA^| 8 h=]3qw-;.mSE5}钧1{Qh|0ZFqLpЪhLX4\G85jfjPxXm8F%o'_*k g˳x?ih.8Bߑ/5eRAdH|GDXVł@T.5/A3f%&))pM–rb#+L/ NG` !%Jw&VĆp:ܧ qG?(9T\/0w"Il;J~,9qS;|ey[QAsy75S @\ I㧽Nmq`Ҋj`2&|ޓz&qNvL,p޴'HApMܘbۉ&<2"%;g6 j݄(LWS}7>)Of3_%jgyNޙ5j'#!tPtjvn! 8 6fS"rQJoL&E b<9+U'#D EB9en@NYȬ 'W7f8YJ5m=RDXEϹ,\_z)ڙ.cYUp7kuka RĝqkP! 6-0ŦxB|VF"hT)m{cBxa+GEp#6YmGݤ80䘨_8ux131F%iL>Zyµ0D撚+zmЕ3-i@\w,#`ܓ4U-a UHQf%f~=:SÃ[4\ F- MQ<ÆY~XpP]I%*lB]gf4O=Ҧ[T7 V RUO!ܥ{:.u1{ʩsKDzӭ]^ڡ*iWW a6^R v׋p4;.d #wt'Md',\ Ai[}N OSxqֺ [Aȡ`b[z%B47 Si# _|^kX]aDhZ-js֫:pmb7-+&hO5 4c#]Jg"aԡfe> 7`4%SOMyBzhsvwcoYK;VmnSH*7rYBWejO'Clդ )LƗg:2e""ZDOJ}_"!h0% ` ~3;W?(N#ey>MX(l`fKe'#9IPTiPEB`HWL"0_ 38H-4KN1ua @ G[EfPx U(Ϟ.[dhzГ:`s!n:+ݬJ%Zy'#q#\dS8ai{%"[SzmlфͪF"lzKD:( 쎫*o= &QzI$vDws|+. v<|?kĚy7;p۲:Z 4Rcʉ;fV L՚I8\{8"p}!nc;_wͯ[GTo*|S,tHg_L "r.No2oZYi ]'E8H~ 340 /.B~Y%E DOtD]H#ސK񍵍puC,1僵0> =ʍ+/ɶZؖܣTef%h.('s3.ύ&q&;?D N&C /NijTj}s. O'xXճY k!st,MLyNqϓe)S7Saܞ[09.L[.rޑ;m;p~6U'|x\g5;MZd_~A+T&BRgG+es.<+![}'!W'| =׌4kvs̮ Ku@?T%_I GA_v$~-HP'H9xU2Pr%$KZ/PpXU8H "CZZY̅qf63J~$Gy9a3VZ7ܖp8(1o Kϛ^Pn*åa*:4y} OdŦ`{eo[w6_ WSu)PI Q0eUH3TiҬ\50J7q Ep1oNãPCUHp ȃqqK` ㇾj; rOj+達G핶[bԣ9VŭrJ}! S/s({7A!mע~t:&}7ƍ}Сt<|I#fc~z0ϖ{bK珜STRZb p y/sNCsш\3{lޝɶ4,j)=,|+`SS~N(z#:W/|l3N H˅ ^Qܦ8[qͽ>㻯2=N3> .t 3=%P98SЪ2&LԾ:~S9~٥`b Q8t'E*H FQڏȗ!ˣ7#@#{58fV @ ۓ Q -m{y E}ʔFf2vJ~#䨠:'"p4JBVh~r7\jfH^ZF͂a5;}lrl2-zP:>dDԓ"ʖ|r;vYx8WؾpC5a>i 0#ǣ%|J b>>/%gZOkW'D`1Y'Gcq| ~?7.ѽ⶛шk{6.|\4sB7J3J#BK+O2 is:֦#lv522"ʖ T?fDD_.WY)z|;`mI#KI /(Ru sDˮHXgUlQ'K=em 9_7RDzl!k9q- 9/=Jol[JB8nVk*ɹyx;'G\` !/k7D=Y=bI ,]$^sXMۃk;cY Z ƶj_@hW6{O ƤTo ҩd<Ҹ貋xtBTf'@yQhTHoߛYymH(cC3n?nF g)FYC + [)XnSgdI*Db\dUiQG)(a:De"-"3Q'7&]No$);I\sQq*b=EDF^L:1~/Ge%R`۶ȤXpӋ3ߎytrcFʡ;\Ag֑PD,>XbYtX!O!)X%G\g3',qݙYHF$Q NrIw)!Ѵ&RZ=vT.Ʉx,b%tO&$Z4MrDZN^AW6D!AygaH"ZZ K&'F4ӄξ{pBjo} KQP4vA5yeegzbݥF%@#=[lB~cBcI"g' *.ŲB E˼GC>Gake˫Fk_ >"pGy #XqS$q XŎk!2sGNfn*!=e+9єFѩ}rGxHwbHց, $CxJI،`g,uJeA:I0%W6~@!z}|`OO#A~kˮ' u{;R+{f?$xI+qVT"q6#x 5 ixƦWV!eK]wHq"B*3ۢ(&̀4ܘ-nOj +C=D=bh;>@Z&\ƃf'xDFp녎 ?8 ʫA 9jyhK; IinW#ۦ;ff-a}bRV>JCnYP(IA =+#NLs q(qH\(ЍQ H7˫yzPѹȾN^jz11YiD˿T1ӱߥxZ=FI;5=$:LSm`uy 8iG8?Svw`jCXVP-͡^ŲĊy.ݸbzh86n1o'#-\=K+2H9d Wzndݤ˹H0- 6V>3^-۴cBMÛsɥ׵ -.P?]нo*OE<{P+.&I3ᭇ?w ZgǖdΞu|1B u%o&)?VѕH#,j*`Ѡ3"ݨ3_x>&d`=sOT $f̬sÆȧF9iI&iŨ0xC\7BbXƟ*ÄFlķ0F U=,о' eʕJY.KcY ?Y rDo}í0=Ɍɜ o6;d@wJw&Ϥ4++Cuw t6 ;B`H1 I/CheGPVo JG[}4hqD":5,gNs f%P  *=FX&pgsh{JAtI/>Xx(@dO( Z7Xй.Gp5ñvDZj<rIPT. < &k'.Gl=\*]%=Eo6uV0bfȪ",o3P.ѧo3-`IaNC5;K<’Eg0F WvVA^WEU:I̾kttHӮM09mgf`'{`ÆSXՂWOU0# hS/2=WU@^/R.ÇDQ¬`*/"vd듢KP:=6&${iM& B'v4~}|cp3\zՑcnjͷ=~ MYi&3tTnD|FD{ _[xde ) d3) 9]Q~+" ~,jnŧA/=l;ٸf07MXKIT9oK#'o:X38f+L3d 2W?}/@\&G[#XT l8fwEwEOR=md}r 18J!py#a& ߘ6| TJQ"o}4h~%rpq#{ ~(rPܕig08jjP9`BVDF2&ps4zZ=k%2I`ӭMD|H}SW#N˷hrD2$M3_9_a_Sh'X)>AuDC}osl<xyHoTX%U g.36DfD2<x@cA.%;8[427 AKx[d;COrı$G*&eɨ{d@p s9ь}BLe{sHW$:} =6%xDz\a݌]Fu,#`]º#Df[)|u'fן9ojP,C.)[kp'6F=iP,}@u]F1..ރzV/o02P{ͯ2wŎ z ,p323pY*XGm.'Jk`rm͵tvSvW]By9P*yBu҄(xmUi陚%^#6cDlOR.%MjRSC0}϶(u6F_wytϿj/ &%[[ig߹!^@reFĒKLAL .JII%_{ 0{rS泅^n#*h~dVPm ޣ2/u|U?e1\12N MJW(/#캶-CHK)پ2K3$b\o3V'؀)+#=UB&NnqD^/H`.*z*k!Sj :š &!+卒dpZ7hs+bFNab0㺨ov!fmMkW5YFL&0Ta9^2hơEKUEph{|F!j)>7 <`dWr߬OJz†j!7V.b/TPz .Mźa0D@6ւsƗRcJVq&'tz_4Yޥ[֡.,}ns;&@xءVA.$K6[ڐ~H'z%L^"pW`+eofEHo^dcJ1c"#R/-8R^7^VߎyPqOB;z1uiVƸ.=#vC1J EYt iH3$\v7"X]!sy'VmSԏ=\/xmxug}V` JzxK`J:ъ/#1{{zpdh!odAC.'Ոk+'q@&xuI_|f?{! g& *"'Єֿ}rהtSAwƀk?b6viReحʜe4dį5S%b/s+q6_D䆲۷_nXP@03 )I4O_XMю|R RRe-u Lu%Di S^ѭR>D1Q&r]QKh̵DoU. 1=0"К0@ {9DAe_<`:N\K ;9Uπo|6tt:1 è(`-.s&9 }-lU1PvnԤ&-JRnc ozZ d==[΍tgVJM` bi+ӍK{1rjN;ג2hAߊP.e{О- RbLk.q?obJlWJr7ؘ&trø鶲u5" tA[ gށ(gdF_Ae;aT;@ȜH ²=L\ 8YׂkRii fF;3# 憄y{U% Pb AYLR&q0:k|E2۫Z26!»"VL:0g7iEjNg6SwxZ[q>p:b9@zHmSnf>{!5aYN1,qY}<&F$G{8Y= 򷚖(;E<$ZNK<[Z~Y]žN!E #?'WA$,{7V,@qS-+Q9J'xm?k fS ʺţ_>2d=C v&})Ł cn1ϻ+D w,wR~mu7|#UH9j8}Q-}",EK5rO(˵=zK Ub`PV"lZ\|׫xar\l#vtn-#O?tJ`1$ᚶ${q2$Cma@sSxl0k cgi]hL(S[;J'ㄫiBFS>;<ᚘ*$$ٕ\E5sGVEF=|(Rvɔ7ST|ħNb}Nn,cX*ZoPTBg~mq>d(dN#TdszMhB,lX4y_8Y vI . JA朙BS'(b~ϛ(JLjW-is2eNhK6^vN{\v*̯[oVlfζ\fEXGp)y™Т~>E旳ؖT= M L/t;- xB0kg4bb/|@|+zrP[)ɬor vr6- M9͈5+Q.r-eF_rޭ$"Zscsb8gqc-ZVEd}E *H3 q^( Uȇ˷^+oCaIp-ec=)bztR0@1f$8#1H4yR wuL<(-2/:J]؂R]y`t҉)K/K(BR:Ie%(ۮtKv^C !Ij0VA!Fxƚ B{TgB]̾NZ ]?zpvނS^Ju,+9TsMV28 !BDJT̥7O*c,Y oum|(.HXz8 ĐHN 6zmDm!dlNחcěj}MicFςK9P3̦=]D~wImi/_"O2챥'Bsէ P_ !kiwu]Θ|Lv~#0)J5̗G; '*:9EcB{ Sf  +iW-d6r}y֖j1cnDm'WAaԤލ'cT.{w40~BGlpF m&$*;| }eF>s  ES Tۛ-`)~ʷQaA&BE̸J.VoO4y.ZSgꤳdoֆ{rTp$R`*Ri2]٧1RM*I@1hvى{~r5UGϏc+> >s1YfP휧XZ"Wt -J/AGÊ:LƋA7@}f15+U >F%A1Aލ rC /^ %?r|^,ˡ00߻A*$Eq6 G ~$=H r`_;Ew_po. P1jH}Y-XX4.WߑSɓ(.B_q祟ۍ-r]+e85Q԰tA~yOz όU㰑JӕdFG?Ч rћO@e2֍yj5Mt|9;~qi/!Zt{ẹ%,Ȋ{ٰ_!_GhFrGqO0bms 4ds}*hhc?uįXsHC=tr=͙k|l_2rrN;%81-v=M[W^V sL%dF uYMΌ!V6 #MBļ2^R/ VCbK@se0#uE +:5c*u)϶ O,H;Jj8EjEI smۡj/5%U}m%_<rQ8A'wBMMq"F&n KR7"vwT^0pqCeB'UǷŗ8vc70eU%@~)r_BG[?aNX[ΠIc"a8/@Q w%,ȿоC{!WCivA!Ff>\֗#xjd>-WAF-Wй0{s}V{mnᰒT0Am) ~^%;|A 髹z磙7wb{a}KH}Z2ݟ8#^h>h#@,>!Hyu!"װY?}ێ@*u<"-8H*齣YQ:m̾mg•=G~?B{:@Ioe;블x7Jnv E<'Ν--|sn&(1|m~qfA96^ ȍs@iavRb %JX@d#c'N-)ϲ 8b.XY;4^ؕ ߣ( xA@ѫz5(7l4{S^8ԍb0R45Dմ!{͍~꟭Can]DݧHLu.ڢPnKw5WmgZ F?3hH !WeR-ݴFZ* n Afx(1%:Ye@O~<`y1d9>urۋ ܘ<o,>^~@E+v ]  J) G8G7j205n,wLPfT'U(>υdg#M!_AYy{ m Vk.*Gڤ[|^ 5)̌UH}fH[91@ږMLտ&[ .\VAiGBhWyX_~cL]GP`7Qb`u+ÓR6#%"'WD(1V%'t{\(D1'g7bɿ ]se $?1uZ28$`4쵲aPǒS.39#b ߈:4)Fɖ{5kw5g{S0nURպXcRt KA*=;e46MR}.wY位ku%?7Eְ)b&T>؁<Q}䩲lUE~GE$s8qxq-xo:H!7g:K@jԵ?+~1~>XFt*/yLHS1˵0W•!Zy1=SX6!f}H-|Je sͥ qMgLdecCF9h\0s:-Z\Bn2w#b;w0!Oz ึ\vgZ-#_LNA7ap~c6>##a5d3%Vht@  ȚFTaVqJ6.' r_;ET/D j Ã|Bfh7BHk&9zǴi8*xW c+.m4 Nۇ*2+`Qr\@q~ǠlmI1ⓥ24F{@*2Pq~TDeҞi'jil f,#]*  sHK疖]7&DBM¬<2aF!=xƒv]8%^`e(F%5 ~)jzŕWh%mg{fh7`H?yh$`%ɠ ``V0IW `&>7gg a =ݐ seֺ|H Htj'- 59}+)2Ʀ z΋3h{#<͓}px 0"U/ʊXl,'٤oQ+Fe1^?ldJQLJvͿF B^Wd YJK MA-^]ɏ}|Ꭱ+δ95- -.hnuj`Bݶ'\dIKPk!g+`{~p5+Zʀrxճ#P|ĊOZ0fˎgV  L>Hv2jz&Q)鲕oz|<^WP߁SN5_-q ?;h f:AO U5^D}.,If%>MUr<TO1r^KqfQnJ` BB:Z'a4*`YvOlOj x(hFl<`;|A ӓaHϡ>G.<0ߜ̼/wS3{U`i/rI&ݺZ=[nKc?,rt= 2vؘPɏ]_gR (Ak)!qǴ#נEs1 H qlcĹ*xJ+y*}]s:hhq@TNɖ!ɿ_dNg3ۘ%&‡߇ !B=N ĎkN)>VDuRW~N*PѦv+a9`?)8(4n}y z-GS,9ZB5.(暟g_uYsA=}n+/hBIm?҄\_',e9M, F=3&w#~Uwh]b~2;_*7><}SӴ!|-ǮcÜaJ;״GzcOsaW(E-PEns,;EVh@] fDe}*b̩.&㮓R([aAAU,7cGgq2*R:I:_ݎ4juԑ>/ `ïj .n0.=CG׬WD!+:7\`)pG X95EU_`?i2:ćwaxS#-;mEo2d=ڽuiɖ5gQn B.DTp7@\xjZS0Ʃ\7(^Բj -ea_ {#0ցvh: 9de$<+&$֚CֿfM_Vj!0g }3}mP0o yZ U(X( 2ѓv0=;P@,zW䐃kj~TH}@a}]Ojij{;Hq? @7> _7T|":3 emDX~wxV5g0²~&kN6,H3WEPpFtAmS9 c8_u{|T0!\>YZMH11 3h0) իL=/1{7Ym,d":t)e#4*&cҺ+Nߒ'"G ļB8C[)'G n?.[} ߠT@cGCl ev ҕr@IfCnR5F:Ҿ) +U7ѿ(a(W{+wfXJZ6ܲW){#g7.ڂ; .%ݮKN=;B5ݺ.M*l2=2/""F"rmw1wto"MإԨEQ;~09EØ{9~y_I@NPijW><0"h=P:=`#V- ? :TT%QH'°PNvn p=[p2 [ڇ0?#}M'4-Ġ~2 !25auo(u=@FqoxWbrWp`RPm Z'p>Keb$_$(oEzI%r46Ccl_sDVPH:˪Q~(`)ݡLk/<5"MK ufdjET{jus^14i?!W4[0e`͠#T$׳%~_ Knӕ<b_i WϋJIM$}Id^A-նAҷC{%]_' ȗ WIS-]$9>NX *si*$ZR2op qqV5¡/cSUk $Z=`yr6qtl\& %iӃKSƚH_M'Dh &,*K_У RS5t431`@y]{K J0G<vLrRI+qH 0&6]iKU[$Ml% jҘFi IJ 4, "Ϻ>0"u11]ZB ^EhE,Q!K;|VZ$HϦ5_p^$ )Mbd D郞8x0HG08"t6r@ Nζe7"\DK;$]ޚ;@[f칂FOCV{ixusV4Qxi~DRǒ~/: sЊ#:IRkf4ҿ.o!iRt8&m-y:}mv0RٵPg.L._+F鲍(߱sT[<Ϡ=;g:]9vWWp]Iڣk?z!e5][ 8GvoCE䪍&0 >Sa{VCҏVL. U%#k|C968b WWY€#֍8{a$eQf6޽Z\na%M&.a 﫽 Us=+ٱ ?f>"~bI/W|kd7IR)~3פ9lTz:;P,wP| څӣdsЬC~ ;袈Me"W$=3_TڈD,|I9SEh\Fs1tıb_ݚD Z"TQP'bIhsyD~ѵpS O_O#Ϳ|lahs'PT0Yn]6?Yp{5vy (#L 6dpp$o1Q@Im^cg&Xf2a;Ղ+DpAal#Po\ TDܗ'$F= Jlna3uߘ}]3qX(_]Uь\o(#glkKj%[/n+-qIN`fTW볝aif=H-,3d:-!6d:c7%W(_nk,Ҥ˼uŨGwgI?ʑɗgޚT*m-> t.گ5[D.6 t15Tp oJgePu t\AC[ ƜCO^VQ1¢$&OXS'/GUgZ E[)E[M-(ƩLm74u-lӍTuE>fT %^ ~0qLU\~ӗ,Ĥb(|Ci. Md\~73JZa<7Y-Mڅk$g}QjO&S&Յyby5$zL"W0cⱷz*S\ʠpN&_i [hþ{ԁybTX#X#Oh :4XE5EQΤBa#AޚttoEG."T4Lͨ6䃝|ro\[V5*TN1OzkHp Ir Rf%Gn@ 5?K.Dy C)10#"QR*}[;ƽ`Y-l0!pL(Pl"@{R%o6S[-+,XfA\7_M^m81&s="^1 >P2)ރeǵF]߅?ZzqzwfoiX7f(Rjf\K>Gxy SM=ب>DWj6@8:Jpd#`4c3Yx(PN 3fZ4R*˭'GK.m6T /Wf2? zc|vd,8\!Ҭqp7YϻQ7#Hcr/gYlΈ&Cg9nGJkYfh?JmJ`Judv0ϼ 90nNr;oQUe]jS5-n"hyFk 8RXBs1.s5#E&ޛ?Ary/esQBvS{LSN\R*Zع(}fj0ЅS~=z,B}?v pM_O~'>L 8>&(ɹfX0.VR7<=Nl6jZ5힌ٯeJ%̀[P?VȾɂ $) IR4 0T^X&NXNs(Pl=m1DJ5Q.\K䜍,V6C!Dė}69VX'G |6Na.o8y/ "_jnr8<'$zmu%B?Eu. d hz̻Zkkn@)!B?Ξi8(& TV;d/3J!Jɕv <*?/ˑp."%`9ɗ]*o#<ɕ Ke$j2̫GR!jDc(Kq脔ߏ\*i1ԿmeYwh9 yo k(zin P% ,(gshB4bBWD]V=T?Ohʡ_?~!Lf~LZ|)M”C+p|%ÁyaK0$u EtM9ܥ>ƵW”ͻ\s|KcȔoFL.WQ%H{PNTO5%0۰ l-AkFú,uy~6Ou͎&aZPVM3ʊc_ds? Id ] ~fUʴ}%IDcZŷ"?>XջmZj\iq٪Œ[MFC?. GkrvH|S 3[7Bc Nt^jf%hbGJv~%Eە=SRV+ayZSc㰻 Bq;\S^c˿B_79qk}\$)q:괣}&GSG~lG`r-:Gy 8E&Lx.b0/[k9`,2N'd,aHn0)ӫiH#FS>ۍu;ݯtIԙ!Z߮9l//'Y@_$ fO~JSB3WǴ;J;֋Qu.`gN-+׮!{%cw\Um=rV)a 0(,)˜֎?Lrˎ~?W]Kǣ_$6?DpFl(9")FvK9>#. ; &sh+Ϳȹ!/䯶E4ǑLnW,.sD҃9O~GyRE`K._FhR3fO|A.6-]K@f@~*Ș, knc5#'] #;%WI/2)3zh6ڶ'nc<Dp %ȕ-#Ok .FaD( D-P$%b V6ol=TEIå%`\:׈vgH9/-Ssΐ`ԸKq:zXKܹp`$/ߑnvTLzLQλ{Nՙoflkl) (=8v׏ |L2;~`g;9[-Mήf _f _tvI@i O a:IV'ՉFNIaʒOC= 03vAv>|qh&[Ӡ٪@+2D}]6$PAmd{QXܢAS4kupY˖T ?n8U {YUMPv{"rm8f#2vhjWuP6Pk 1ZέN0^w>/vφph78P^ir)\Jnɼ!! \QG<y9xb*d=HEN7?U/uÀofy#*^1ȞB:_s^C~Jf}?pDaj#ջ߁{5t-Vn-%Ji~bNB,}|yNj`ηEyM_ʖ>OkJVƫŸ_]L <џh2*$L*19 4SINεPER ̳|l#wWzq){N!.yMtt=B(겶#.ƻ[:Tε9"[6}';o(D>\it:<8L  /YNP= ?f55'=\ͼ55vLfnq/C%|17 bs%J[` }p B@TÕ@ .>]2|4-CG@s&dG,6SK3 ,7 ^\#2* ^tΏ?s,+I-D&KIN9DۅбTaF鄑v_E5eW4m0NJns2D: 7}RbPikQB*GUXݚl ^] t 3 ݙYjgM3Kkje1:g \DU:Y׀ӌˆmUs>ڌ2^nέ՛ 4φRU*XSᇿsC=QcV1g9ȖF}wzߎ|h,{XKÚCN mM;FERj:Ch/#0Cސ辀^hwl5})rpF 0\/-1c\ԗ3Px 3\wKNx vK7tGAde\T+|%~<c$XglS. 7ݧs/ɛL,~HuzTs }9౭[(qS3dXg0FzctBMgc@5+#MA|z`^E XJld| 8.13;`m^YHK}$DP9#94XshitBd8ג7JՉ=OwA8GH duf૏08̠"EƦ,rLc~CtNmGzů"@)Nᰩ(!} ϑA zactgR#k)U 9,,R3J^ ]4v :֙>5Ғ_z(>_3sdncڐIe<;d0Q.:TzCHZnE!%@ `=`3˺AN;i9mﯼ/'Ԩ嫈F-E٩)M\}$ѥ>'cuhwvhHaͷJ:vGo"L;wEps4;1S8w2|Wnf4mc'bwK&bi+,N(Nx gٞ{*J6{-V3dc[X.qQHԚhߩKBv%䢥D. O)g ^b@VO]TqBJ`!e]k;Z6\Vl$%B fZ"[Zܖ ;B+Q=G '- mL@vIzcU `?w\$c%F xkZe*#h)D^hKC܁7@Wwu 4|DE6t"GJ t,˙މ,a0蠓r*E`*.fK| _zP(Fq}%=(9 md<&%=xd'D : %BCB+x #4kF>8g| ?tP*BRQk:M\S]е{9(: nMTn E596p@eg즛pZ3HT%?]g):+; # 4!2 Gx ' (G #ߊo-a+~hz*t,Q?߆st1Ks+$U8oK𩽛OT  WTHR *KY h 'fmj!ĩrݣG&6>2@"r l:UHh1Jri2i*B p{d-v){<"%ٯr[T%q&о{r٫ O/"0PnT2-M|eVK>N~s, @C$']ΧzlӢ@J'E>gXsuHa5v˷@ htWIx%8U.ġgVlN_!~ dh " ]0>\ @Fz4d}̻,X=0AZzmb5`۔][FǷV+vGťݲC|L5!` o̸oe2H?m.R\Rc=q<,ewìǿ07`^[\ xKJrP@iU)HϽ*PK$z.( :QdVȩ,֙x|bI%kxw3|9h<;+so> UkRXW 5u=2+9VGs)V >,V ]H9 exmN?2 HiNf^?Xߧ-חQV;l=$@TՂ9""Ux!]7$/n(U&tM((xz]^-sîW˥?u &iVq :hzڸRY̥"/h͂5v֏w&'#Sw@JNbtUE$!8sx MzzRuȅU6Pp2y.&(PAN(BF h0|cqcEEeC>+vUodRv8Tdǩ4`jm4LɈ9Rͭ[̇]6suz=GDXt\$UzfJTlؑM M/Bڝxmƙ$ijR &1:470n*~~w=K0C܊gYEܷpb{{GY_ړ 2VdQXJxJJl+¤p]G#YU8e扆8cgKf\Ȅ NM,[[y}j.0Ԫ~ \+PA7Zr(Ui>fc[ʸd'A/7_ViwL(U̳2[_ʋQm֭#J9?}XM3v D&=3'-[.| d{5RAHAl7|9B?UC&NM&|Ts@ ՚)^p>ܝHG7byJ?U\/R!m &O-y@]TlgT\tWpz)Ϻ}Dpx~ @,emEWhz*YxJ;%yR- \ "_dM+rQc'|@A,@eow^D2)5".c~Az_2Yo5ŒP#dԇ p5r/bHA|! [ui9!P}xU.z,4.Ooh0xFB4gt"C)yDYқzדZg(_I4Lts9 w)RP*ΐV'SCᓛq{N2h* 29-PTf'$gL.OUEN7sը0 xbǭ«cSe d:E @-N {cajWU G.4(Uk_?G:t]R{ӌ+B!oe̐Zu Xu=6%5˻g 4o]콢UpT7/s8mo~e2}UNqI>ERkKIZZN3D(b.@cDN0I;_" m͑+R*Z&/QjGNi-8 ;G P>/5͡v8kPoQ4cv}ț~uk8y45iIt"4vN nFv" V%LARrթ. &pJq%ш*nw ,ۯj7xZ()TtV( *0mh%"E=A~L"=$U|u+ +TJgWs*<9v[֙"H(z09LTfyoȭJͿuW*5-'xLekqtkmć :q48 m+v4U4OqA#ZmrJY OɔH2hJGP#r`,c{(,]<= HjOE4+%D !),U.7 D8x EnsC s Iۣcg*),i4/Y?UF"l8O" A-KG)xNJ$,?/qƗگ-mU+ ?O{`wX_ Quc6B9-9tt;/3Z3Y3_a>W|* b|Z- ' L{]m67B$ 7(:ёM~O;sBx_Ou:,рM] iQq{= -(- SP[lH㰾߁&;NlʐzBˉ RR ~ՐlvQ D;],6Z 1mGYyxsr"J؉fڜ"dVq6G_='(V'q= =z,)p&/C ܮD+weѯ`b} $L/WjnmK@sW'Zx<4,f bP$N_33>:9!LAu RTi@K$4HӄrapH4nɈC+VrӢ=[RI ٘±V*2:CW)+BaEM; ?hXB)uVf+ ҧ!Ҫ?,$5\R)H{'ec 2>]~tƯ/Șx9jl·᠙ 0<٥}mK^uްuaqxt@?jW]u eXb6dfz5Y&#(;)fn䣍9zUALӼ6ij(>˚k9`d-_E))`#v idCHRnԻn)}A C.%excbt4Mk6oj 9_J <63Vh\!ImcXt"Ŋ}=F1fK'+4T":yyPtMqhZUN6-oJd{b"݋WzrBeyY3|WMrmb'jHZV1폡LiݱIĨ!M d%'q&@YJû|@+w'eF ;ިD{0gG/g*>J{d>qنsIߞEY1LBؠ kgW}ViNqJx¦];~B6#[($ ;z3=P7e*Ghg5Pe%Q@#;0ϘsH5۔8F @Fgz9 3\C Je7 gi^A6_^gPӼh<0A9b BQ`j:EP^cWI A)[Ny}MgڡN3AEMw`*ft1iOm~LuZ^ C^~FZ916Fӄݘ`5j6+.X珂ذSфyt/E CZYTN+MUOwS7ޕ|c6 vKhz] >g[ߙ0fiD~¢ȕL>-7 n6uVӢ7wJ5+l9,Y.:E7zf\'!dZnBЯhUWX`I5Biߨ! I'>X=|^ ⨕FK>栳_ՄVD$U&L35ܮ7)6fW3l8H@tg8lj|J{UߐL}OSxʝ1B #;=Ed,!sE&5A(@ၚpj=n'~[|ڔʻƅznˎKXExsiT}:KMحQ.JIg 1/! Bڶ$Vl#-p\:ߦ:|ץ ;&(P2KIS[T%N~ ~Ĩ)~xzIo =!jMuZw|\JȽ~x1SI+=8ΛzpS&nc':yUS9ɉq"՚s:$`^喨~s''x)8҇QPbjT[OvwI#Ҽ[ٵ%ֵ\d6\ZEÚL[TkA_Iv&N5oϰ-7'`#8(J]>m`7ނv݁Ǵ G|f|ܖ/%_Vr4 !Z;g?^>Dwӏ]Ebl.)"´6m{#6k\Rz[Rt5?!fi JVps@Te}l*P< J1G'|~Bw`MO cA"ycxd Cj;1ڣIyƟAԫGD-=)cr4j՗sΠ YI-h%RYVByueʪ- .ހxWJui J{ܕ}T[[qh3?aB;]q7/+ O 1@M>UiPG _=tE\3$8jvcvO5RlcP `SpHQ(=.>i9HuAbz&?x>mry1Tx#+^ˈN?fK. ieE Z~#Ak']Ū jY?^=pje7<.C@c@ vh$7_ʼ7}.j,|"%ͪP~t~eZ|Ț# iRT|*G>Ƿ:ߋ; }aP1jEu99Sh1a{Ca؍YPNNF{q?_ rTDAUzKPu‚Ib/l"5g[)Ӈȧux{t'VVB]b4$˩y:6<ް?1Ma*ꈵc%×GEK6pm&2;ί]RP|KFs -yNB0Tbf C҅1uJ :t{/[l=@ q!(W￐\RE3xB6_fn|yRdNg(%vڄ K93]W ~.pjd,Dw=?97&B0vii[((qq@ fcqA}Tn4^oQXN1(2DˡiMN8_%$%{0و6߹N*UkhFV)^Z[0LŁe sOd󟏌ih@wH>@Ew3K?f џvTQͶ+S) ztqEPkm yd` !8Xlg i:BMX@J,/Mi B)%̷!+ZVy2bj-$YN_M/-V/s;UJ :vXT7cO3J/4d -ë{ģrf%<3 W}U?B{ Ox\#bL$4nC"CS_D+ !XD2 Agt9c,98= DBR{t$;(y;8]a,eop<%`Z**9S)v4w ksˑK+‡EiѷZo?ҩ$ ӷ 0< y?]"l4dmHr(qELsW~F0߰"G#osH@u!Rs/ NuZP"w0;3W52׶~0 Q ~;x-EW[?/xʯbN9y^4kB`{#ku>;e+::;q؞sKhF7 J3ky27B=,ٜ!${n?u/Yz]-ɨ ?ociT" <:>UT9-4F0[:,9S3anV5Q$/-K ?lR1cIלdzqS]v P1_|a1%t)I_#So6?McCBqcȈ#Œ;~#%WFAD-G.u.2l3MyA"X9B'l'7W 6~3>z~_%+P:u$Tw}Hی176ePpSA͔@|58t)=016NtzafLB)۾1?*SROڽVdޯFeSHr#1(G=4/e5 x {\B&4;Mvf|5E ,*8]_u Y}=4 =s&l_fݢ!^%]fXViW2c,GkͶk*  [°Gg#OOK1L~ .30:N4,PPptg%hZp䛜J#X<H1\V"&dF7J֧fԉeT¸ط\)1zt:1F_4DY!*eP~-zRƄ[. <%vH4LwFQ`伳șCi?$E6w5ä!kQpiqP.5E=R_&ϔ$qB#Rظ|R٤bsױ-ާ0S*1R)֍: }gF&rS[ 'e 0p/n]2#io?Z74^+(A78x8.fɊnB8.S/dl)A?Wo='6/ԥtR?Fv,|Xsva C:iX#cZp{9=9/z<#'U@Z݊מx/ŽpbQՕk8F~#/e4yR\at_qΙz s'?Mۭ3S3o 47Qwڂ(NN+G@1C9Gkzy1Tva4?˹D_#W ROY oq* "xC8G&.gpwe8>7rej PzC4׬Ghg-QUc,^HdEۥK;pR;;"s-÷fYrvbΙJpwC9ӃBS^Kn֏#FV,NdI[&o-&ӊS4#}}WOEPODz3=U>}Z3θN4+2,c(NձJJh^ΛW='T #3=O\Hfvl7:yi@9d,ҿCL!)I^ܹe!=YTg:3bl$9=\h 5OXvdw5> #LLAEg/o|X}\&Лߠ~, 1Y*n51/nfnMljY:^2!]I )wvqIqV•_}b敏?];Ruec4GUwu4mh-% 2bs\qY2w8vTo>pA8g #%*NV!oڍلhPT>=2C1mșQg9|`[x'w_%F}ߚ#$ *clA>K'loV478#;Dq0Ty%C77Aq'.F:% nx0Xqc=~|:['fGui˩8j@Bjˆ͉[CX8v'66ͭu>]7ܬl1~]ވ1ȕ{)O@6iN裂嫜L@T)Q.GHp,w;A8yW@zVT tu`EzE %"(87Ϛ[V7<$'wVa#M|IXv^ :tH`7R0&g In"r#X26<)%Qעu)Z>Mv,<tgS!˹jhs݄x3VT_m5'GI$pYZZBznW0֖/3=x]X $$N@%~FwjYM{U֞p4fx G@@AOq9'L?w{BOd_|>CC%UÈ' n֥FN}`P;JaD9Wn;(ٝ3r{dW1յ>-X# D.wF c.ͳ]u2W1:Cefe)]+VUмz4*j!6uKbBk%=ړϧOuT_+4U/n8.2S4=)ڰxIiV|EbM ' M}EnLcԪnNf re6ub 53H|m#)cF"^ntB6xb},<LfۘuE|pkDF 3&yWiY"؎ShS:-}-|e]zEI!k>m ؏M_@MzX(=i6/6 LH!co`IWl\P/C«hk+z\2o3CT m&y%xHpSFa(+R-@}͙J$U/ Dpp&m>rΩV>.\dA?f G Yzw&q]C*2IrjJDݥn#cS w>V&nhk0rnHs Apr^P1 al#<=H4JMe;ye 3BK(1v1& Fd*he HPx(eoj*J9C{ܪӲ7IV^k9_4<3ToAvG!rQ7Ĵ`Nsrz7~v%rgڶ[ljJ7 n^(;&.0(:ON6A撱ipٕc*D2ό' u:R,4 CRΊ'TxQ//adP _X> <,yojA+﷙`sV\u!n{ " n\v,rs5ޮ2:aʔEZQTz։)RYW'X!?x>scϐQcdIӔ¢Bm;@.>R+hXMTAc$ʜłk\m_9uY#˩5KqRN֊!&RUܻ&)&sM5 uduKK\$ϱ?C|vS :!uW?;\֍dCIC "YՄɸW\:3f3 p($VIn.jroY.N⡏.rBW}ڭG';6L%x-lJ劒A.mKu9.܁\=B=A_T[+?F x irpQ%CÀ:USZӧqn``fpJi{Dfh:;9Z'ȥH ${2lcwj[wo׳D[d!'ۢ &H 979%ש>ʨ4~ dwW2c*E]*-#݋,48?LYNTxAwU,.aږ"#WY^JOeGo1z,B"RAs:qӅq9w \~[ R~)? Yi 3{(N ,;@!ڑ mn-ӛwL0e] Ұ"8Mr'H*gӬ* *:5AuV+^6Q91|(y"Q^Sg`R@?F |j C=V ?@y|/t{?A`0a um$op/)mt:QDc@ʘIfN&1OHR^E_:i72f=1g%*`Ѷ.h,-JK+*3uA c^V`AT)ڼ*up&-p{qV7S{]Ӑb5h)뮞[TY#R61XKG&>Eqoa"̞M`r6GInb"3vx0iTGC{υԚ ꈩ}3 xڣƌVp(d~@Ac6@}60klfMH_+ͭ=JwOC+ 6(\ _dQ❼7,ӧ5Y]#|XCޟFP?!˫X K+F:S!gOP=B'Wb* uLO'b_HҼx/*j&Qc[ l1VB %.6rw6Ӑ[ ɐ;Iosy?##xb;$ ! ԧ~|u^#B @Y/pdX&T]pC#dϣjQ$iS7#ىQjHZ65_ U`MNw$Q= vLқb@rF\*ԵZ@Ϟ{l>;: 氾[1J2&AX&qt- /c3g_}w<rAfZY .mƖZ7¦l@Jf+Zb Wr-׵ ݙ<[#yýaPQ0^Keq,DI8(zFϐ ⤦gTs>fS掄&ZGZq `[wYV_@_ f^%u35&km GH ypw1zUg]f.O Gu% W žc(Nfv{ikH_[3[TY a#梸+wz_L2㷛1]imSW# %^eF@ĥF)9xs' T˜ǧfOw1_Vq;nG?%j9`Z#Ըrxz4N-KI HYVmY$/w HUA>~BM RO%I`O3,hfa*4qM[z*AD+ H[`d,C[VE^00 l+yZ'G@!{Bma#싾/XFPr)nWˤyY|`HW'=pjW&0xK*1W\'%%VCp{`ܢB;S=o{ _>нr`g9lOv6ܹRUC~P E3s:&he=.\n: hw n21rtC 3 =joiR@ 4/}K=\_?]+7\W ^h=hFB‡+n^ eR,͙K'0}&#o u3ێv>-l.MeBQ`LkI"6[$I] E7/\-@6 8jKQջ~A0z^nnJ3ǯ`YAx&tpYB)Qz<@ mC‡m(Z#xr5ZȰ8-~?-p_ .)e+xCDfRl\ oRdVobH$^ c?<ei#d@ֵqGλ4H!$I DpNg,E \QC¤.߫ 9 ?}v7_vq_z-Aހ@_sȟjg"=F~,W{EMP O&mY7>h A'FCE$!xЁy5(.c j@4vooI΃_&e@P+U 8bx(iz)eh񇬏LycRyZ,pߎ蕧_7x>Y tU|l&ƚ^=8_#Y9p[F-Q0N -ndu, ~+t6 z{r7^ HW4i3z ޲ 7v?~prۛ|caN Η R1Dy۞Ş.< L+H̵ zBv&h[J5}@o8>P*V?^ a4}v 6A;_t/uw`5 %H#2sv9's@$`QrSnqfZgw]Rg"7q vP41ڷna-zG ]U=Mt.d%6-rkaB-C&Ջ饸SzCCfQ AEE 9o&3-Oז#l=C}vtt +v؅<]S!m:L @#f2ݱаa|q8z&&~h(D%21t @6` )+[LKaԒl^*r6z9ok`HR'^;¯gI!8XBwsn2+$&rJS8&+&]c7`~7t+oUnё[|{JgϥK`n8l:# j^e> T;E?l SLij7n9 u{C:P4RPsOJ0fH ۽)`_ݫN7=]޶XPi]qx\+ IͲS6+(nW&ۧEn39lg}SH*Bz]KduTìiZzшFb-%p/ta`cs2ρW*Bv?rʢUJS,$%rtbZĭgO`uYFo_%8M[ ^!>__9rdiqS)3 E691jIhCF51Ƥ m [4͔6\1bmlFi .6A2vHAySw`h @+_?!{OtD1YyAB%4Y'1|ԙS\8?7-\uȍoث[#7vC~%1m7Vt;:Tu9]3t!'%N̨cs\\/ɼNEJh2[59s?lZrx-NRئ\b_( 5"*Y^cUC_PrQcVe.y]wNdIIg2'_.Z=q/]1~]͎тxj'aq*` ,c Ȑn#tZѼP!!⍆YZ^ )!ۊ|oZ>`%NRcf_:9 VWD9Csw Phd8'}k Ѡ!łwg&'F3'cy=_q46EN97ݰd;^yd*w?uIKJ5"Ȣ!^}kR*Qރ/VzuVzk#)kS(J8|Hӌ*z3GXNqs*1dC[vq-?$M|WkvΤ'r{g XgϏPBzTr bN’l& l\JτʴtUl뤯j=aO ݅BF-U~=tT$#S(eZAWD`uxĊ{V& TT;@q}YPCM_ lP!e糮Y# s-\PabBeZ HʁV؞)1jІoE9z ;$kS^-n'tmkM޸ie?\[iWʭ!jxjF~˰As$ ^3a۷ jBJ% q}n,7E3AY!s$j|Ct<¹(˗b{0BChhfX&06xߐvui`Uq}Rk1QPqB rp0UzuM(Fq9oݩA*fVG-_r4%4lvhf0м'Nh `a V蔶Dۡ-EYApv;KMr믂shA% p2G Ͽw°`TIz+A|d9"|sLJ[Td[z#B4b61mqfM<t/Y"8;+z~,LBI%FkznrY:_[[s+UW0R ';x*=x$Lӗ"`-pĴ,l//n|sn$L">4qUjkpo/ fyxfwB7-U{pX`7Aޥk䟀1D#qd2l ݻ}3+EO- F7 F(={/p b|.kVo9BLG6*.cw7CK}K䰿EF^[սg wj"}'Y[R0P.|xgXlՂ5}/ջW OQAcC/1$3{Z*"5vX4*[  - |*t[?N9P }>䰄^@c]\dw^vjl$%Je)]~[jK#c}ӞJ̹~Xy.5}0} ¥zXd9KL0;5afe# 8ԙn@q?j>״I=#I$t,p e~4UТ,XJ{xZJh\~R7c0 qG$/ Fȣd\ ldup:wq=W%Լ჻X-GUє>3R+4>ۂs3UAS-}Rbr}iUi4Qv9сTn&v4pWhJ9i@jlt*>w>R]{? xFOvd]PlƇsJ.~n#L*h.3gPT<:rwteTS-˺52OzB!EI|88N*JUZ Eه}]=Õ WDlxjӷcҗ`QeKw5gW.(^8y |oleLXlZ-q8pnNw(`^6᎞ۖZؔn$r"S.i;{& 2Q$̕jTM+>hh͸â k]tf~]bsj'D]b8oCdR`C zUlQެsk&]{mI& wI{,|`nǼ8iA%QR+@"_wwE|O%V?}\ %eF l+N>s0~NAڂ&-:e`a Itv eUAWrxs0L*"9*2HT}BڦAuNM7UE%s'W*ٱ͏d([@i|Qv#6!ۄDKy Ol{ f#LpkJOЦGR j2#Ȧj&2liMcڰpE4$>Y[BуxNDbb.rثtՇ.V-k) sa͋@*ؘYƶ4BdqHT0nAAZʴ901{Xl\Afeh${%c1` ]ҙPh$$z}/6- 3).;[|i/`8O;,J9 pr4@A+C *m<7xTԋmWl 4m=qƋkLΕl8~S+h5(qQxrAV 4,cz1X1c.茉9+LIZA&t"esj}Eȷs.UL=*{ΝZqbX=BY}›OW.b\qqeTbp5)͌4{d*Sї֦C^cZE-5?\ m~uu_ èY Ij#թ(c[|0߅O-٣ = }w;z)+΂С*2I 3Ji]n&`_23#polU5 /z@H= YXYBN=~0%-F$.t&ic2NW&2Z|XċJ`=dkݯͬr2@#eRۏ*r8b}<9|ypЩY-JI%Y' {Z:7! Hodž5C+;v !- n!yﵮ9- @hA>YCCvP-eL^]J5[k DZE-PpBww27MD:Sx4@P"O^%rFr[ KLN&$,i7EjY'4Ot3AS;[ .sKɇVg# ? .{h_[2dq;{}jg_܈YJGתx-l#JJ'j^_VƜAyƂ`:vxLIXD8 Z30OKB B-z$d'BäI*d2Ds2y?m'=`1 jo aoЩ) ~}tWC W5dZOJ9 \VNaG1<~wIRZEԌOEFΦf1 F^51c'L_؜ph‰c)#XR&_ZŜFKϨjZ4)Ow^g!IHfۙ*׬Idٽ4.~Y>mV[u A8F (^[QKTJA,j)@a Ks_h]cLW䜯er]wP_Q\4g]ڭJڗlI|Λ .Qu䝚)Y87ڋ =%&+hHi&"F^Ve%ԊEV, {AӀ00k^uFt?T`E Gde  6kUW v7yO'2V% }jHٔw1I=͒KB]qb_fo5F6=7C6IQ| |ȩ".3zhsE!)p[Dl: #G! oC"Ĕ9MF+,ByW%.3桸6YsOKH#>Hv wXΝ~.mNK r.ǚig</{ͺ )pqRc iG&G<$h|=tɷn9bMi3>y=(ea_r?!'4yI.Yhw:?ے-FU+85jj O5`ϧR&xbߦΧu Ie#J#9*pw"IǨbEFeu&;$ɬZt/bA[ORpd!L%rC^#[IR( _]+t;$腚.|PiC_5 q9th<""ф(ʱBlgjN6xkZ7ׅaxO)5"6Eo3(?J -1b%2)&'ڗ:?tB8x潁B4gx>PNd6-QTAm!`n0sM$R?--,+6ӝGm6*|%Z\x[͉Ĕ 9qp;e0I9F̀U?k-/[:h l5,p1T+wVO<B Kԣآ„Z͑/ 䬈-> nZ@Ɵ'FV+1ZKՊyQ,ą7EOfFD7xvb;iR9KB+e%qZ˅q`tKv<-,rDj ȜpbD7H~q ă݂\`]:iE/Z=%5)W' ݯynV@kn#w&}ܣop1#{|w:%2tLctT0A]qfi%P9Mkp H& Quُ a f-9X&5[8@SΉHB)DB\vvRE<에JݦD<z"SW}LO2fY Pkӗ쓞Xw"D뼏(*σ/)n5]:E,м5{CbSϛ/|]Zg(mJrZ~} x=bD#64٨F.MƇ|\ ]hlbYگ.UM#EO<"^5CI7 YP-U=[Pi?v@laf!hz?d oX$$K:{wrPԕ[ĝ!3>%i%Gͦy=A R<;anp堈`g-vRU=.v)4K(9L=w rJ9:>Yhc%pp:-ͩ3+pٻ!o7IvV-%ԍڶNvLwNvVROv 1M@9sه:;zHwJYQ}%a!V iIRL4rRAzͯ! S ӻmxu}%?UAMM2 KJ?Y'i̻0h;?)i*Pep@)<ކ %#fx=&۶l8"!pExvi.ZwC!Tii ݓ+Bƻz``/MhæZkˮ"͞4''X(ͣ91 ~tA7 3 9+梬r ̌±~\ UjU R͆sz]#F6k;U3z!35W*eleo =2qpK-qt wr$\̙ P4Dl"Q~rPTv)?¶Τ톛e 3jo,1gud?Gg|NY/᪬TJ 3[Wg'fv1l[X)nD@un׳Wcrsj*䖗^**[Ʉ 6(w9(E%(4^8ѳVlŔJ lPXݡ\*'9"?:"1h;90Hz<ʍzm I$JyOԲ8s΅ϡkiqj1,˟3h`˸7ڵpm)3ɤۖ q[~a/csw.HEJ, Hi nlen{\11u0"$ǣIBZ)5~ַՁg/kecbUҾ2Wҏ XDG<1S1.Fk!0V\v~ #D-/(71;T`$}wKN{ގ2}f<; ) xH G9i dG ZNeXLJlEt[/a@pE[Q32{6..njH=O*\=Tcv7KZ]HU4rh9Q 6y ^!V& `3DD&a=h,B_4C[ĝݦ)1o"~-1&6AZy= M .Ǽir uSN |4tw. }?W"*cIn*ht`2~\M"J}lRlnsFjaB`Sb#|Y~h767Bm xh])Ϲ$ R˯ ]x^]6%)[+GEz7O[hLɝ#r[Wkaʁ~+3̩Ќ4U2QqO͙$ć/NKSwݧIzEDQRť4hZTӫ}/v7#O9?"q31&c_Lnv,#8£4s1 _E_(¹hj߉")eiz YҎ}ž.nl,(,hd:/Sed"4%R廉 Y9ڃeU7g;n V9*M:ĺ M#-go \P!Dl) EȒ(+9ce>Rtrz |e[ ՜%V]uxBkr`%8ڄ+x QWU֧^xO%ߝV5ZzT-Aڭd},ۋ_ZjIҡGr Q5 5׃loH+WLvXc+t ݸGBu`vX>`DN[v6kQEz&`oO(,HyvfTx|*Ma6Vׇ|_Ipʦ%zu[誺z}ƦM'Xv72!;0~Swl71ӧwGHƨ={h:/'যg"SǸ\ӴS|$MK)/ƥ#Ϭ_KKȣ<$c\u9ygm5ZL gr}6T#O.Kکr WraC[ϙUxvah{9pЊJ](tLpXqK%'Oy ׸HR6`v 8]J,HݼYBя%j^ʱK9{@P $S^D&aܤK^-` FvwJ8ƀ |I@ |e(n Jz6QuѴB*X|Ι4rA>q-6ǓMGw6p0\dW93]ęIl 7e_)X`3ԅ2ob_غml 12o5,bljmhFO\hBd?b_7)IIn}bxXv]&D% GӥkNq9?TP`V~7;D,06-j][9WepÒhx S$be#xG\yyAd륚R3޻Gr ɩ`3YSJ<ERT{+rTF" 4җLJK2f-81^Kr| ktj~DۺTТe+nqH -`>/b_5"f!"gؿ(r\uD;]k^+[88íʅ0RT_qdhð_H@rc 7:͵س ZTBrBƅ@R]_[uTńD.AD3uhbDXF,B}4?f@˳o@YL/-'?~$<:4501|gk_t[%ߡ<)gX,;8J3?<"aTs{-MT1z W5 ÓHb_g5y3a\vl_15͞lF%6PxfKj1x>ifuj=l^kN:@]RukbKLw-s8 e) )VyNI,|t*]-CaŖex+w!͜WCt?qSa/$u EMbiDO!9( /zU1;vYp- .ޢXw{ihM Yg$TFov6G1|c j;UzaqO,U$,Bt4|; TjT8it[,ZҼodzD+R9d8͑K5"xK׀Q q~ a V\~:@mo&2RxGM4(l[2F;]~du'·X~I[s. G컟WCxCn9p:wAH'$`db pD9gHA@PǙ-:(gq hٛb_,T"PN5e.Mg3-DڃMh2# |3K gA8>MQ5jFylɨr & 9[q, H)3H%덊O!hfa7Z+ӟ=.yEJn9p}yJ,X } *pmC(Wm#~>ӿHe>7{k5Bx` eXqI۞H"Pz ]ȫ4ۗ7 n<2FYJSw]gm%vEd9Ȍ9CI̭Ԇnw4Qdsa{]P!~D}[, QUaˊ  l%pDќ<*R^9il~SrM>ӿkr.]fFqp}.>:xUtkk?u0Ö(1|W_Hpce!vNƕ&FS$OȴPM6AKLj׉ ,N пT Q l7 TO)0.4.eJa培fkwi[1 Pa$z'lO$RM7N?0L;a+j}@fړuђ ":!QbOÎs+aβۣ  Uwb橣p!M*(B 6i+̟\) pW=U}}RJeaIesmm>QLIiJB/ɭ'ex8,:%a!e4PZra.7-bo1x~~G'o1g?LOʋN^2zLꍅ*1SWn^Xr3;} }EGz70/5(sw/-ř#g9[4bk;_?S$Aq~ʔy{*$:;{y!`ֹ=s, (1W*lnV?ØH Wٿۼf$¤i&V$ݯl>]S|k 3K[φL3 v0i$3X)okR+q$K&[fRT Xs2Lr.9ZFkQ>gH 9K/ _Z]qc4'#KTo]z_o|2M-+ ڑi2A70E)w_M%py#Qu\$1tU/4ѤD-A)',?#/#:R {Q %ݥzUDk?8Edn鬰 "czF~UYq4`LKH[W $ć5F3Tԝw؋R"4g9H!ho@µܡpSͽ =(9>*; )}/\O)B`ㅲ1y:*Ώ˥UsD'0X_[ۈZjqlieuoU!&QɑzO-8!qe/̆cԟkRv>D '-v F?$&-/:uc)(#2#m|Pd TIM9LJէ*x2ݫB<PEicVOے Gi@[.A c?(,)x@xɿHY$㢺 Ǭ0hZ>jZh|q5ϱe6DrH#W]kR.ǖJH<:U3\^<¿d0ʯc&Dtl$~xZvړ'c{h-%"~ $ GŒ)茽G{b;x YZ&?z|8^2_ҮtBSAѳE@Y ߠ/uӻLXķVDd ?e';]({'lvƝ>v k2?0;y#E }~lG[)*Q~1@˺WkQ9'%Lo( `ө׹>t1$za>n?"h|t)/VXvk7L4(.ϴ̨N`dpmdviIqZ7 f)qޏ].f!˴N4wNv| W IO G:~iX04|TcViX=[Uж3Ӊ%b7,9ubf)+/} W Ɗf:gwdr kaG+4Lw%o#HQ ÏQ:ǺuyO93~&Nds=DJ{I*S@*u$X1NƄn4/^6U=~vL ++f-nTWşCGyr@psHy4ĈI )Ɏ?^" F%El%En8'Ժ`%7)j?½! It׫R'Z0Ԅl4GѮMrFMVp :DR/7}(UK-x5(@14*טBG>8! ,mAߞ3bY1^0U_b \(U}vw+KwsK^uy7AV4vFS:QSk9HI4*MszH<LY8Z7iPdP=Bs,!mvnQ3ҾpRяG)X~RJ X%sz}UmI<\H=iJy>+;0έ9=V3PM 5lkv7ǭBeYBTe=iA(CkeҁC46g2F%e{uN5n{شJ-v3ɂN" 6v G#B# W+Օ'S<=lBYTxLjZ+'sԙG+i ds4E3ȵEO-䷆f?*:OLQU2nؕdFt7IoAnv3t++@v/2D=Qrm&*ZLuE.P!c]p:84=lq_kXy*픵p |Ei@9^u$kK;!fRvl)o!"0ǵo\[m$aNNOޞr:TKO1Hy6ŵ6gv \"yte).壹3\+A7 xi!PDTVf޻ Aps}Ck>OUGDN~m@Mm/ `75,'D3!"y\kYvJ$Դi6Ѵ-ĸ[}1~ Ezb3˸wYUNr[_#ʨfl'g\> qQ݉ \WjY9k7m Nۣxak<#U]=6A+m( nh$ݼSlӽƤ#wH3sS5eS|M;Ru)\j!);5 .Ca0 wRAVXgrme"!ЧX 8 H0M~;oߗ=~I|Tu{Id`{-D#e@HMxrcs̐|s\o̚DPSiY; .YR 2t="+}U4㨂,DmO=pCz}%/z_0_8ҡe]VcA9* ]Y{$ $cuT2, _ӗ59 $!X9NUko1SŤ9"qiUQTfP\fyKAPVG4Ԫރ7ŢD1 '6TZlzbb_~WPUfF58&)T`'-ܓ|15&IPa-˹QwYiFn*X8?l۝Gc9qIB"1Z3h)*@ݧrdQ~K*kB6Raf` o=/$ r }Ò6l$wkurvD'*Ě6޹_P@X@HIoab9$OjXx? D즿oP[1[o@=637X(0Y< UĺReJ\ZS'/Svut蟮jQhxǴ%腲;Gǽ} 6V90M{]ݺԟ fx#ؗ:V >o@';rjz(;o8WK y Y4EoI07X4'F?aOpi7fL`ꡉمF}aJ| wG'; NC?/F8Nԅ5m$h0'eD]|P>aJdVZ5 7VWRQ>3oG\7}pa-R:&A~rFb2s~)˧ ؑMɵutM5'rSM՟c:fOlgg.@T{>E6M Y=G5f_ͪ!2-#,1p9zrܾ_9HY㜳MsUΞ=KyQq #N0-K8fKehg:Ye1(F 4vIS͚!w2l{ gK2m[05q1T@ҟCjKavyOb'>ʱ~ЎI J]q' 53I@ofێ5fKdTs$MQ^I$Dl6l =#P "SI<A#DM_p5 r=x_K#/~`"(wS-ي*fHp$ i—b]Ĺ5Gtp;jo&;̟ϳ^ P?ExkyPtGy֑vo_FAIVɋaYyJ@[ۇ.`)*w ҁPqZU,92+wi#m7~Caۚ^cױ_[z,d']A':ZKW,+d0ubY&$d'Άc ŴcL#^v1Ǧ0DXZg0VƢz^ga="# '/_q>p:1:AY?YPD5oQda6w;VȐhbݻd]F)ZDȺ5`]bo7,-K>FiݭPw{xKK֏/oQMo8&)VN'/[ ?5]>|E/XVDFIKpO:Ik-ÑV%JSaU65Ր]:#V'a`r+H>߲AGq̨h\)PH9Rn\=<$ϯ}vrͬߊE h .Mi}vz)\ɆIcR1-eqH0 ,e[o͗s!>zGhHh:%´Q"1_ʴZPYG)}ӁE:*7-"zՑUۚ@vCn~[?ވ0ŃOir:M7e.vS5`f\R" ${eR Ӏ4P]ˋ4Ed?j΋%Ea3S SkPutԐ;@dA\bi@pK؄ .ަX3hYsKzH7ʪ_+X\P, ynQm6|l527#CH8Q(tޏ?}_ 5œhTtsTdgr_Zf"-7 ? [̵o?ތiבa җ)6pQ/2 S&oq@?vWō Xij͂'IY͙c~[GtTr|:Ϭ..Dm#*ǺuQΈQ,-&n̦ y̯|BA긿 ux{:mD1wT'-Ƀo-&~ܞ釼qg'?1":V=01!P{Kw7ńP=TҢG82iW= uCOR4=j}e,()pnk1FxgȿӀڦ/xwTk-*XTOe!%Js Iʎh*f$4 )`><|ܕُG;iԑje0% 7 8vzCɟC0.gA (Oa5r24PhĿ\X6AWWAݳ݂:aZʆ܉Uu&~3?&{- Mm (=Q;˙W.g g| asR;5G1qQ;wPY(%9Uds{W lvqecVa^/K̀ Sp{A voRuqC-ei}Zw勲&me=A}NuNrPD H|{ zmvW֛ߛ󶴥쇭*J,d+6CK.X,AĄ0!ֲ]dW1~ wʔBPa*Ur7A(i}0O<]N3Aϴ?2M ڞ;:xŎ {&fxdarwz4& 6ɼ`(S())m@MVԚкK/+g2rlaf}yJNnՄ>BSDOvAmӺQ}]KSr27Vq[)5C۰Z)- Fq(|A=U̷zrv1gxA2PcH|98L4]5@E ᷩx=88k5 Tĥvn-zgHVyh%W>์0gK,?!š.~&fb3gAA #yi.T)ZAڹ֗V ;]ʊT=a+Y+>cEeJR= Fg1,5lXE oR^-9l l m%fҷU\4ׁQK‹ayl?7݊cԄV&|Wr~T$T]­+]cr `˙Erέ Bߓb4$%m.I"x#4=tIc5P^ e8TJlTȉ|!DK$]Xn*WV=RG^8 iUX'LVA@ vHg69" g_88^~! Ù׺: xa{N>8ze$<\&B7rXqW+y;9l^xٜ|{z(Wie~km 6{5hmsU&?7s<1\Qp[#AMu>^vji9[7-~@Oa=flT2+ns%HH{7sda?a>#'|1814`b)"q~I;u\ht}~EyAxMs̨p'F`ȷ!K6_hb6:lo`݅/ZCN75:g<ꆫ ՛lXa]=J> V{(A:K*F mCg.~^uEhadviq' r2XY+zj&f'Gnik,XrC"R >S=v+1Ww٨(B!Q Ħj(4c>o<|H w>>Q{:c& 讵mcpyADDm!/>MGI>(mA1W/5 )Y}fI{&-Լؓ d+GGrڋӻ.soZzVOi&-pf@4FJ!xaӷY?_(oA\5F6G|__ҚgxUԑ~ K\&1qJ^"Lccj>o>ma*΋<1Û?+|9xΙ$b¼Y:-EϤ<v\0cR .WwxsžئSݞ&o$z&nt?<Iȍ.E}M?ab_$KV2uGۇY(@&2r θUa0#9.{L{J)[x\v1f$쬶a["d?< o8)ŢY^1KI#:jLv=,x $LI@{g baз)>]K#B6Ѿtɽl_nXTѷIŮj7f bEo:I6 b9`F^}ȅ. O0jPLF~:4 X,yn&Sb&*5@E J@8O`8 f46 W)JyM-X6~Lkc%!ܐA' |^~*' }"hZ<-ɞWj9AUѹVݭ% ?a'^3;PY@ dH 'm.NsP0[Ons6 yH{\U3F  6!LzOC_H1޸3wAK7ZO#[=Do]R4!d<0Z}$k͞ Khe[H`Qğ2&W0_3NP`Էf4w&o["u!K0R`& Cԗ]w Кx9:R)8roDYc4X Hi~.Jit~eȱIXɚY.-'5j&xhylWYEPd_3b $h&+K(Ʈmr.V5a*^VB* j5M%ibG]Ejf-+1DCb"@sFF{#i2ħn SlfW= Rvqw85y6>zl>Ōns:I`8B\ Tr֑ ;RS["<.W0VQ<e~ƻvŹP+&+V@^,~q; v4wΈ%oT-.2u}+ g8iDcAl8?EUn3)%Oツ5 rTZFܟcADg+v鍷ϝ˞4qwy@,"x<9_Ȣ`BsM Lm~= C閟wh|?tET@au9`kE^qdQKΥ20 !6*tBtV)r!B.@w6=n}˘{qi(D #o{黤6Z?V^|@$ ^wuf<<ڤ9kYP5;1Rvˠ҆7%$ZcJ '8̞hQ]N٪:iiE dC1qon)'N 1_w%>s4o޾aPq^H͡6|w 6GH), z`cWtcx@È:Z>mL2MWh3#5JKxdk_fOV[ֱ; >zwwzI%\fdkOf ՎIO1L]q8-Tuj!a%cv8+@TO sfhIkm^" "Yt"<| O%K愆ڈvz< 6:`V/"ظ͙o埰Gi9-M.#]CaXN|so?nWvLBNQvVc*0p!iDz5of_NLyQَfh]Ԅ t,EkO7qtF@'Vd댭WRݱˣ =;i49HO-=U\猡Y<`p8I&4r!EZjAEFP4鞊ovmѥ )NZ`6z <8M+L'<_u^\%LO"3f๰V=7F7QwaO.](-m?څ@@t$@iR?}+F54Y/'ݛPQΰ-؟YU4, O`=+߶&.xwM瓭o8wf?~c2~i?)yc;I)䝒D[KjR/`zGi ?GE4LR u/o~@Njq6ؔrO^nҊKbƨ SB+lq,|WTǩ5ʰW+tY^HsTR7u q+z樟KYeşJW5pVr QX]_&OvVi"mo0mu|I€½D7[LZBEQRڿ5:U"@:?{M'$~D=37͜%m`U:ItOWy$jYE/}5?/0U ]H(f ;ڤ 3/-DwU~U֖|=a!,XiḄ¼xSud/Kaj!dOK3gϷ^yR;e*WJJϙ!]*[Nd?0enOh"z9lh5~TWn|STU `LId!߉$P@eftÑ1B [YNB8kϨ&/%zN{i7qlf#np Jcぞ伴_ c}Vד+ǀ&obI,4vؒsԪ7$; M2(L.}KCTTapvQ, +-8aRˮ\Jgc`K@5XЁx 1FjiYOڀW8yvm"JΘ ><.*{5-}ǹ)m  e05{n 00lZ|e۵8F)}$kYHNƌ k,HXPEV=&NڭURcbbI㓝[A /u(Q3wwc2(A-ÜqHw6V XRm0-k+2XKLK:*JYedm6., %0u2OZ|sPvk`O_Z'G6*B6$EO+ ty1vJA# +*^ZymCژ$$uT-U2X7J;C,HAk*eP&5П {M{J#wk> "+'/V .NK"xc{T1 4!D?i*W'$oNLpBWA!TZOx&G^tAW\8E:7fnPD4w݉2JxUz3<`nV;Õzosݿ&Q-3V$kPc<4kcIEobsc@ЄS*K'XFMEKT.h'@0"aYJ4e` D*Fj?>)ԎJCU|e՘h{zQvm.J|+'pi^_tY]b2`~UsL }ͪ<ņ4 VrK2 O=} 0} Fk9 ܢj=GVuQ{Tnfv9u{ )&gnJ RSVoj@\e2ϡ QUSq.lˤ6GewU%:`} n+T{P˽g2*=F~Eņ9N8Eи=Ѧ>wj=eU\B+]/ƴЊ<1`#1BZ&{yN81\ݤn󨰂P{HOCiޓUvpG4B!?8xהSC0L ?hw#^^Ilכo~,T0*~\y\?h=#OzOKloR":VbDXuEz==^|#7tE`=S8v]U9h k @#d*@%v&6Cő[j_ G1=ZD4@e|8:. N| v.vRf; :mxɁ_=lx%y%L=$ yGRc`%7 SЪD~t`.cu|}z:T澗7ke3ew;TWeӞsid.+_0soR 2ըH?=P|$ :,7lF<)_]äʠ]>83)[Q#7rV/`<5SY{n.!/Y砩 8Ih%MnGA~FՉ'zn>ǀ%ohDZQb9'0+Aw#{ ƯTBȓ-Te+ [,@.}(*#vd 1;%7S0Ob#Jo Z{xGōR=iXI%T"=\oKmջ^}_`hoFL>~2Y:F+'5R朎R٩IN.N$g-fPeIJ^܇4'wKfh-C`\߫ikSn)< g7V0ppum>ywp{'Ӷz$Ȗ,!6]W3)I @iMLnFQUPۡ_ۣ@q5 HpZ9.mn:۾[0zdDV1W8+ZrGkd`kT:94RF[|/;'\}_-LZv.G$hLE1zaev"H>_WH9,ƏƆB}Im<CO;,,TIc gOs^":IR2Y7,Ug_?БPRL7#2H$W%>!d?Nr|oƽw3u!ͼ١ a n_ڢu6;^WjS5TZR)B<*hSy3UKċDvR_xxDw$3//sKOwJlk\ZF CkD֪Bg2MOWL=(Gr6%({x±Y]e3$FѠB.KM1 TVМs|V R$ ld,S"]Ĭ}P}_~{ raxg([;nf+wu~|E ,O&Fy~kx4!H@Xl=+@ =*H ȓ)5Ы-uYfԺSxWpcxg'U[dK:ŧbg@;Uň@eC[PfoQx)~I$!kC2I'[r%})c7MH֯4c_"HI/\k9K]PU*M0.u~&fHnpyEd'fJHZq T3Ӽu =3ٳ ]>껡'02M9O+DeKw*:4Z\UdP]Nb(5fBtw 쥂F&"ȝE%]ԝ~m:E26di]" =Ty7$m! 76!|Z]џ+i·ܐ2rҐo1(_ y"}S6?+Q^SmЦCߋb2]q kuq!H˅u>q`k~1X眈RX=r`^~/J!~V#޸Kʮ8XЎb/>c6`Vo;d^d+DK4"^']h1=`b30ObղD"ΤTa۲Be;ͽ]Ncp0Ѕփ=k^ʢ %,R +#l/9Tؕ!Mc&h p*I%ee=$,)o}oK,QVuȋI RNJ-K jj 9HIu;]hb Kstwྲྀg^`n:4 Iۂ>mލ]5*bQ lvG{Z\Tao50 Qzt-9n"u 6P&),hHw+<(~hkU ]"(&2le ;ȐW7_Y|ɼI$N񁎹ahmUǟd`QRO2$l Ŕ GQDVwDmbG+/|\w]{OCJlMX 0:=+Cscv/bՈLċE!g?Ɋysb=`qb%<ϗ`(1z [HImכuV fxnP u F?“/Q 5Lؼ^eK"C# (hwIW)l ේKMmd> LvR-:$#9Obnk&=~r"qTMtj* ~zrIe:Ul֋屦qF)x=s6ߞh\#BzNFJPk:&jS}pF{1p[XqRqF,$D&LWZCS%7(rўk[qIuu% O;LAN~/2ܐ̤R -]A;dz)*a= B"#'1-U/aeR]BJ4oW0]ܯK]$`5$1:# Fa]UL<CQHrc^mTNb &^(C(&kn& )֮Wa֚ߤkAybQ waFeni)E+N{(4ѝ85h#}m @KX_HH{kS[U7m'Ԍdyz4 C%qr°-V"=KP%jL#W%|8: pA35?|,bH*`kLцqp_x`(8fU,z@} wũO@`URo$Zv*b`VVys/|S.B]>,D*m4w:u1&4`Yb@a^N?A@n[2 y@N]^w]mۮMyrAt=x'H=(&GvTr 6wRZkLT. Y}XP |7& ey *j ϻu6N|%W /,"m#5c$,4)zؑTs,Zg}Zk>X`] j з<*7G$t4Oyo]9<gi ʧx5d|0ϒm#WA}/Q6@5 Wйt\?, uX'"s@h$̵KC!χ鑷 /jVhE!#t!?V42$Okuա4705ܡ$_<HYK6u;Ya] 4]`fn- ޞBS8ڷ] 5P.?a0$5cUK>. b8C* @9E}tHgYXv>2Zi.cɐ98DaX5mWz Z#J0_o҆ҧ|,sowc]6-CQ$-/hAf%;Xe\荺*Vxa wt-Ā;@}hH}N;dNYryRŶ")ѯn Y`Q>조JU2>Q(9v``7vfL0\5qQ NQRgrm&esD*(Z,İbIJ}@:܎8Jao-Te*o䮖0'eq䍤˳2S:ם#=tG|?""u/t-u 3=3ൃIEd7.5S&AY_t=HzaA=Bo缿aW iA_\!Хk~ױ( lW0vJUzAM9\&-&<5=WvaH1+[ xF7*q{߃ bus/ E%߆>U@*CB2}ʏOi{՗G_ߎ{Jv+[(6QkTUufJBĸGxRńC2< WOlӁo!p֦Lǜb +GR倁6lӧu=Y5mtQϖbF1!bB ,EtnԸ;h¾>&ы-k܅X{>+Aќ__R-2 |aO>eS:VV[@HaZSO-rXJhQdF U{ n^3%0vA|޿numNdb9On=+.u%/Gv@0Zw[j˥Wu>hrZ9SY}$!T 7Fguk;y𠴡9\v̯B&0ߝ v^o_;$S655IOOu4a(nȨ@fl*|XRV,KDʈ_23( LIWp%Y>kY=&GY83wV|%gFE i1wXlZϟޝ|sFUfTOi]S{kOĽ0jz|'g&).i@5YcSϟ76:piqaG?T}'V|R_Kd YZ