sssd-ipa-1.13.3-60.el6>t  DH`p[*= Fa?ك}ito -fx|VJ >{foQ+ǧF,=*YO2p`r*rR :!.3h>DʿH(jDӕ@V'⾑ܼi.8h.|r;?fռ慤ȋj0s;F?Ә u. ձfElP2k2k97|׭Hţ):\.S[iP;[W(,զ5ox<5egE(Lpztؗڟ\-xt ]#K*ӥWh MOm7c'-B.qO؀C;xyGqn! Xn`M+nHW4Fd)| Œ rDCK.~<؎?'R̒kR]MYZ\#{_2P>X^VQ܂ߍeeb072fc13291065d4e40d5ee1da8a4dc26ace60VЉ[*= F cd#9=]+Nh ^[OݽKw1'׀G! K77X;L2V䤖K0C؝CP>T\fXP|F]W>8Tbr Kd%<ȬZV 0oeOi0ǥ(q!oP=%p 9 p^yi2UyeZ׹!{vA@LIO\yI7Zwr qǜ 6 bM d#eщЙȼʪY I`"e_J>INXٌw v,6 2E$9nc[tRh1m뎳Đ%y)ult+sߖ?(P-HfT)+7bxUn)N=ai s#eg+g5TglgA8xyQy2W ȫۚ)B,>N7>i`8ksn{.Byj\:qCtLC>5`?Pd   6  <BHd r    +NlJJ 3J   ( 8 9:eGH8ITX`Yl\]^bd+e0f3l5LCsssd-ipa1.13.360.el6The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.[)'Ox86-01.bsys.centos.org2CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxi686KA큤A[)&[)&[)'9Vpn[)&[)&[)&f92050a11ab67b98e90d3003bfc3c78fcb30bcb1e46d2fffcf2ca29948d5c2f14ae8e6d0250270f21f4a4119e90d3324c5f7970b360eae2aa9fb567992ec55b58ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9032eb2849613fd8f4c5db80671144b186907b06959c120911c2b3e1e6bf80e0a0db353c3eb0238c9a324e92c7c63f270a5e04da55d2f6b326ed3aba9708f35f4a3rootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-60.el6.src.rpmlibsss_ipa.sosssd-ipasssd-ipa(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonsssd-krb5-commonlibipa_hbac(x86-32)bind-utilssssd-common-pacrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0libcollection.so.4libcom_err.so.2libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.8)libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libglib-2.0.so.0libini_config.so.5libipa_hbac.so.0libipa_hbac.so.0(IPA_HBAC_0.0.1)libk5crypto.so.3libkeyutils.so.1libkrb5.so.3liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libndr-nbt.so.0libndr-nbt.so.0(NDR_NBT_0.0.1)libndr.so.0libndr.so.0(NDR_0.0.1)libnspr4.solibnss3.solibnssutil3.solibpcre.so.0libplc4.solibplds4.solibpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.2)libref_array.so.1librt.so.1libsamba-util.so.0libselinux.so.1libsemanage.so.1libsemanage.so.1(LIBSEMANAGE_1.0)libsmime3.solibssl3.solibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_idmap.so.0libsss_idmap.so.0(SSS_IDMAP_0.4)libsss_krb5_common.solibsss_ldap_common.solibsss_semanage.solibsss_util.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0libtevent.so.0(TEVENT_0.9.9)rtld(GNU_HASH)rpmlib(PayloadIsXz)1.13.3-60.el61.13.3-60.el61.13.3-60.el61.13.3-60.el64.6.0-14.0-13.0.4-15.2-1sssd1.10.0-8.beta24.8.0ZH@ZH@Z2gYyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Fabiano Fidêncio - 1.13.3-60Fabiano Fidêncio - 1.13.3-59Fabiano Fidêncio - 1.13.3-58Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Related: rhbz#1442703 - Smart Cards: Certificate in the ID View - Related: rhbz# 1401546 - Please back-port fast failover from sssd 1.14 on RHEL 7 into sssd 1.13 on RHEL 6- Resolves: rhbz#1326007 - Memory cache corruption when rsync and/or tar to copy owner and group info from LDAP - Resolves: rhbz#1442703 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1507435 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-6.10] - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1421057 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results ini failed user logins - Resolves: rhbz#1487944 - ABRT crash - /usr/libexec/sssd/sssd_nss - Resolves: rhbz#1489485 - sssd is not pulling groups in a trusted domain, with the Global scope- Resolves: rhbz#1438360 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)uk1.13.3-60.el61.13.3-60.el6libsss_ipa.soselinux_childsssd-ipa-1.13.3COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.13.3//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablescpioxz2i686-redhat-linux-gnu?7zXZ !PH6] b2u y-iSqay]ZJݚ!R*W2Vn0UsB~"WF *$k |%XB8n▁E)zDrTf.u7!Bt\eRfL; 7yƀZR (oUʺ* I{f,^w"/"AMoPȹEU !9?.6'&8|7V 1 ȭ  F'] pL LZ=8pyA˞VEb Xkdo@A#;gcp) ޵7 kߏ;ZB :>kQwy{)|V^<n"^d29_)+=&q^ cGr#Gk8cFj@!o7@; TP"$nCiʖiFY0 4B@M|gaCԤL\$sW6iQT|Io|\/޴EY ;bT؇Dҏ崼MG U:I9KP6Z}+bPj ܹyr|Hhzyf8_9H;Kh^Y6%(pΓ139[{\YM/۵<+"-5m|XA$ʱ>Ž>ǪY؟`\e(J~)IdcTz$ Cs:<,0+" +&;'z}шbmO{e=zRNaAE-\?U}PTƭZBu\WPz+~wD0 )m.GO5f Ķor̲S6xDNs,!2{|ĉ,9(!$O6P7n$c%5.[|_;Y\< 'M[qM='_P2O߁#aQSA>K>,yP~+SwkV2<QTwMr81M׭\j.r-a.LUy ՉbQphVՌCVxhY7t{CU+dJ1jB [gɅ. Gdܮ4>S݆cB( |#&=0+IktۊQ ._>_gC]n-PV/JL\ݤYɰ Ko,sP.6䐰gWYn[X +l4Vu'& E.+<SZw:w IIyw?]JJTjhBi'`ia >ud:_#DIPtҫԕۈ4&nV7}C&LǧQJ V.%A("'Ԫv2#K-?pŝٯ.Ӎ#a\p/ܤo5. &vMrq!w.dM@- 726][tr =r*b{r){_˪ĒjK 'GgR7ϐ v"-xpB@Mag$gXlkK+QM9 %Ć*xGC=~-?Pu4O;YiPijj7UOX|^3I !/lm7`m8-0!t,gTwo5J?1Z$ut懻r YyO(he$Sw6I#8>ifS\(d9Yº@Jl*}?J+;rCgYY}lǑ#e<9SRanEm6BT'5L) q9[CR~_"oR'cZ@&&s0hp} ]b|c0غ-.݉" ކg5h{r9dĭikNw]ֆ+ydҷ_14i64Ȩ30AnXSoXnQ~$l-̑^];L'w]B-R#: ,o#w5r:OMs:*1ptp/iQ{1apçhh}lHF.!f#,xܿ|z*:B{k }q#JLK5 SnmȊEJӫv >cJ>5䏖b Oqb=J&]ID{?g8lD]N+9Zg)U@dWWE~&pNa͏)J"lr]?$ܳxM,Ue=GQqlwWL W)We%w]?XL9L<߿ ÛSٶUpj1JمPnͺ7?ҀϿ{!19ŦeFARYRwT?Mn tP0z |saǏ6[v#e= ?-JN&;ˍ@j1%SZUp٤ϊ 6)IWWA׮J^H2SϗYqI4#xm"q)co9eIm{%FxqD0_BM<5I(b 5@aEUpbƉ0gY~;?X,fܯpb :yxT@2wG)GW,Zw5m)\:9n}X dţGPS4'o7h_$v{jx=o]_gaVm)=m{|eJR[}[%[1 MnyΟ\?jvPB.:X6eEa$†ثIC+DS-vbW=Ax GӾ" rbqRK>tW, ;u "t4>MյÄfM@iG$&v$C>FH@9~sF}L]+C"/j-`gh_,%;GĞʩ.>EhWeTO~yB%/LpN.PKBHIO+UMٌƯ^)}V:9G!_fKsMMy0ttn]v=aAi6b΢}/#T$9uˆ|M.6/_ۧBvL`U%v}hjYCK0+2LHʝ|A$p\7w쏐>Um2g r78K]%\*Zh0Mq[&P*bEHf~x8I(ݻ&"_ +MKUBÅr'{՝:O D x>=Μl1Ka |Vq`Y\'"xHX6JƦLt}譤Um|@|. I$1Y}9=l[ٷTGOQ6 }dq$07p˲B-ػrSs 5>ùi!`p ~N+%Gav@ _ Z>7sڶIjri v qs`h.|eIp[q)]Ҫ!{;n?#T y !MJ,Uk,! meF,Y?sm룔˃̮s*v@'q尣SA*ά3 lݼwC$Rmdwj {QG_W%_KJi%R{Y@\RLoл]掦v5Jx@'wu|Pm HL=lr@M-%kڿv'UV hL%(hMqX=S/nD<tɗ&<`Hsq6=s\Pv-59e0i3`}V$܌yCFLIXn}F/_MY-B主ms 42.Ӵo! 7v&9+u'.ozAVqchon|EZT5hӎD`b6cʖrtU~~Z5;]FY$iR9a'CA@XYWz;0 )=Hj4"n?}r1kAл~sdHt[ǟ`u+R=̊w_.Hgǿ: jJ5}Hs0x~Jʳ koTfns $]-ܕ<2 "(f;?&xK"p4EhZ{W9DbwP1y2Mh*/ RvcVn=Oz/#X.6G b~9 k(c71oFJJ*۫VVb(HC@7Q/f0EEU.m,1jLeF8f b.#Bbثu;/mbaϼy O›eJ%3l,@OLZ&DU4. &VHRR˳ 5>ig<rVS3}} pS)l)(}hL!+ilՀ+dL e EbY a\<Ŷ YtcJ̏q]6o(sB%΄`WǟI,Nȋa%Zً&jWFK@t(21@_EbF(rl_j'~Hii|u <7fsn;S(3P5f9/@`Zz)? Lm1cK୳lkfЦv]&y$|0MQ ]f,sz[ɷ澢Ӓ8!@^4ݳ_`"}=ˍRxEw\]U`id0[ё$?ηEy)7!µuaj[݊_(Tȕ ˺f7=LJĊ0?8]NQ&]׃Sd*j9ParRu&0]euY7aV4FeDOME*Te\09P 5uz^v+aׂ޲+lfiX@jؚޮw,-ʅi|t*Tk/]M g< ٗJח#&ɭQ l bqu{,_ne8m {jsfZ.W>"{3Ze/L*1<# c9?GByVP/ȡ0,Ah~0|؏^ tWN^QC--JGVSmjaSIUCH=>W@ )/}5'ΚS(m{ 'R`2Pi?Rt‹i:2kG<<\x/滵!0+}?DXaI}RX̀lBբǓ!lum(DZ" vKm',j2 -g'W{l<$Mϙ1fl9P?:~1&ɂk2cWY6X]~AC7<iQ3v~d3\7 s:pi$)s LlNgʛG5AwG.eQ}Q^h:[JNI4?P4v~K:6Ԍj0,E3r^~d<ǹڵ^[ M|xY$m &|XB2!x6Jl~( o$mi](nwWW۝˷ٙa)C|;ר/mCMi MU joϡʊ'iDj\s_ynnzBL&:hOTuGUZ2T"d1m)qTDiڧUldVRki)0LG.9B>f-<hp}DĦe]|޼9.K}wfnGS8*3d})ݞɆ3V/>M)UF/Fej?pDNйZ^mHQ!=5-!'tfZ $ ͈DQ3&7o=6.;Da)dA'J '[6Gi~6Lx8)NqDj4r[UgTX[޹" ]۠ޱYOgm7P/W?iOW*f|G84qZ&E@ Ԧ}ϠGވ:7[AT ٭c`U ԕ& :[lەXGJ; ) p?Z ѳM7aiԠ:CEdAq1@B/A7 g;B;|q!u Lby R-nj6XuU. RW1Rb֚f}|ř:Ͻ26)YqRunxCI?}D7Sj;oz]i,I߿D@J>Mp]cgJ2c[=/%Ie m' [ySn* ZrX6`-RݴRBO8!DM!Kr@zeSBQtU38QC7+l W|R0C?'4ÕE&Mrdgg 3_O Bz=_? tI7 61ejрmkEf A5r(r8爵b Sޞhm =ÞBL፲-LI&isMpOsKn)-<$ٟ7aQl #6qAK@V}I6;(#qQ[.\V'AUIMH퐮['4hQ[5]7sfqV 4SqS.ٖ svuq*_ş( #D5_Snԧ6W&+"*[ kdZm6ԹOnҜCx9:32%T{;=Cz4y ܒYz׬nc"RP%?;Лvh#X@A /2^͵cb1Ƕ'.뵖qEQk=QYl'Oc"WnVLuv!&:F} Vhb| k8tPi"uڐbHʿr_j,D)2HRk;z$nD!_LJGWe;y*޼I w{lʒmUems*Uj8]HztG$Os'1S .`tY-JECRuQQS!MB]_q6OB@|̌e_sWZi9WUCw3ũBBps.!]p Ɉ.1 =SI:{%lQƐr+5I$2}̓e A[%K(MvgrQhGYf-9"#;ϟåPw C/>\=S IAܙ"`W%b?CJW͌@Bp6?;u?iz.Me[HVi7jeP;7t׊DpC ùt#"R@k0P*O1?phIK)2~nԜօA:ԸT>rъA&{Tpi-ξhrLe[Q s8+=>b iHn;}X6~t%s]H`wf)Q)pS{=clݣ܏OCR4a0mu=E _BԝD2ZkϜlf6˿,uVk\K\xYT"T[Zˋ2cr{of:,Cܗ O.WGB#JϧһNSO,w> Mk_V<̻{F <LTry+Ȱ,^j!>-t@\!`2%2[T(3^-h3@ _'=wb+T{9;xt'B |{1ybp5q7)%)Zdky{PQ冞}tY| TsRT׹~yiCeW*D^-a*zpT2_D",mA:Ķ#T#.|nV-d(tvQWs[D٤21<~vUM8{pƞg)*be(Y%@DVM-{a)h1$6cqטtZwo|uK1_o::{چ/w2Us{2_ljJa.r>8ݸ,C+.<JןԷDEa y#X}~ZG"Af![,Wj{M3MLJ*4v/ddzI$.u9U폖iL.dUOSKn=*]S}ɫ< ' \gtr p&,jWzPhnbd~1ߓ厞朗<5Y-UPRA>` οy[sHy@ mHjl vW"6deL%(oo ]t%p$,KV89Y,Yb}_|ɺ&u)*,^*)>Go9c %@agJ ~U !:,W.3mBnݝFh9PvJu+SLbdԽC 3hCʞ% RUzhԉϛTHНVߟ>vpq\\.R Q_;[}B)al 6sTF+Jw`'SתSWs_~yFJYn:1`:K]<4 1hnF=, >F_ @;*󸱓‹pwcH#[j?9.I_YP5^LcNt0Lx;+p=+1YD v` eQ5.h!n[Vf,2?B-y׹ ĥ%u, B싃)wvR$w``ctp4`!5~0O;*&aϿ}Coڋ6\12xk_/2ia#9CUNT8ݱrl+!m]W-e#d$cQLhr)D1M6}';j^{UWC9zu#{%WL-|1!;YWn`ܸj`$NUtb<ӐגB 2yZ> 4y](XetiGXJBEYxq@P/荮V ͙\Kԃ c]W5=K41=u Lr!9iBcN')p z w⏭;X ^BȻy$iXkmHִ|i/N{?Řlug*2IZ‹sD*b? JE}nιw0a< yG`1)DS~[&c,:q+la Vɬ m@"nIs4TvY(E ՆٴM 9'&+73SNx#H ' 5|yr*6w{;m$˚k*DZDkk윂WV6?y$M15΁ρ^c+0`+x$n>r8WTdvpc OrAnl 4Q0asE^@Ԭ{g%a#4_RK(4(b1cN Hnos+f h&fF(QI{ A$?ǠxruoVl_wlKݤJuP=Q|&3lw^ bVr[rpN\ɞYg]]WfPBAt}}C}A RԞ{Cmj#gʼh>(l#xyt965R}Wwhh&!,NSR#i>ăȞU? 2Ov"9- h%K Sky}x̒]HRd5'NZ"QʟZMڊq7P4{7Ϗ4}Esߐ_f^UCn\[ FYS^D!S,;[q;2TxsG`'ifBƁտ(x֠w"|ξL4, 鮢\;p9LScyMpahz$Hk[1:ѿvN O{mktX\K] pǑ`{4q]c+L:^ݹ2/iT<;ȼ\mY,s\a;:ccO6D &Px ɵA& hv"qR'`@.a2>FfXkYVZO*m-&7nu2ܒ/lLoGqQ&څ^92ۦ_*>{;6Vfp c<VڤΞ`ŕ\0݈t^/v eX?e)gw (DT3s>sxN4Q~X$[m +6wGqVB.,SNpWڔi=N-@[x  ˏ+`k-; BאiXİg/b1v`OJ[LT{ W&tUH)H94.X>| tS@ouéY׃.}<4?sW!/G`IҒ-`,mGAR6Ҝ ? !*UԎ imXLŴnk{\j\v7П1im``\xAb0%Ō޳vG& O*XvG45V#z #mad|Q_fΨG84EՖT uVޤV,h]%NԎ\9w V8X^dA#9Ozڂzg,((RJ=IƱftN2=\J5CgSboI YAYaYZnIT~ Q{~XH= ubz*Fi#oE" R ݐ1 *N[ Dv|1&Sh +|Rk_p:mZ#. og TukUm6ШKY2Պ07sbxTא&vKG2T4w0I'DД?迵F;@=+RE _aL׼Ch'VzKA3**5MtgᓼWsU8}K%Pl.A`E̝nYD&HI@IU#"uqOK,C(_BNb=5s8\ҲK]mkZb(a̓a}f }ZzAUyɥB#st75wZĞ˅"w3Gfx O^g{6:H@.899%EDr6x_b$R"= >#y1̾?65?FX<Ȧ$aPZȯ=ˢbЏf~+ECF8w WEԖf*u,IZtl }d@";Nig U֬ ^7)r)`jDyΉ4X_ޅ«/!/,U83r@!w;[{S]:G둒r&٠ 5~0[K\sNdoGZ'1FGZvE+7F ])`lYP qLd&MWJZf!.䧞_Oo"ɮ_K-1:#p )M_ߍiᝓȻhhkZj;ovMRARf`_.dh_@EͧL92RYCuNN' 9~DLlBO߸J3x۸Wǹ)i׶.rۢ޼ITF,%75^e7ۿ Xܫ|ʎ~59%. }#XjvbpiF Lix@{p(8\\OceAAYOQ(HIS.!C–?v7+]D| Lp/bӉ A.n~j{1HpBs<_/FQ׌$D߁DȰEv ]>T `@`?K#e& K"h^ЉhB""`s5~Iס\e:66r`cX6A5O0)J{妫s~ 6IUyhy骟 E8BEֵeS#ַr 5o'OT n3Y>Da3bg^˄`g/%%";a!.n`໨X'k8GV#^}2Y͌Ol4<nYɈykkl <s;v@aB'w.֒lqNהE!~iX/sb} |H-g JˇkQ#l53!}KȮrdu$B1`spBh< ^-9߱h€-,lLc̶4%ܽgB^tCsIII \5IhSq1z_-՞S_j<,L@b:`ЮPBnF&ɦ/i/1E>ҎyNrۑmvDgmi+}K4Bme$/V|~j+u *D2ažd)5;3sMHj=O5KL%Y&8O;d]Czz6 }rP9V)Ԧ< H}0#`LjGT8^[A*ճGo` G* i݂cҦO /ZDE(,Nqm!Q]1ܸIr;A{8CKy}HF,R/ mo`e ,̡|'V~>fx׽KAx)59¨Go/9 ժ!RWcb:S>E#=hXmH{'>kU曾OτY! X=R% i`:hOX-XxBbyp3#Sv}}#!XbE Pqak]^Mu!|!g[r::?# ']5Ne<"#Qg-l9 mdԄbt"hL0ܭӔ:q9^3;Vu%Tc&wþ}EN7c}ׯMed )n^(~.ia|`}n-sp\SxUm:ځ );6ndQ%05RDO/?)_7lfEy<S$my0y:YRc 8˚P܏m\ * 1W"9J!?Y o;PPdʸV{lrޭ p1Xu{T,~; avA&0J빟ǦR @_% ][x39" doOt7MDZb $П5ch6Z *7]>lAS&F%8Oh/:_jeT&wRЖe纜lcW`ޛ2e4n9gӸk{ˤ/V{QQW:.rYMkT#J0Ց08:V(QH9[64md\Gb $I.&lʗA`Z!y}`(3aX:bg1[J z^3-R Cõ9,@D2yN:K (f6]8{NS׈CL NZSp;BޗFSi,y8p#DIϨ^ɢ 8:,TaOyg cMk;1~`)cYkGmvB2'[G.2`9ϮۭESb^.s蛣i;xm^*"002X$WX'ܓo?AnP.NKf?G:RH7澧 tk.xRe7ys\>AJ@I8]9T-YU }b09N0gf.܍ <>ّ;*_$^;bc֩N%"w"24 xN4KLFdV%T(Hl> Dҽ1x~݃&x^(NֻE#܃dF'iBp@{cxVisS`ڪIfU.& ϕI@> %<}Q,{GY&{ƩfCX3g#,™T!?cn'*I+-PPY+56& .X]8EΛP6ȭPVԿ#vGBʻOJab@O)y-r*'WVa6NE0a-.crfsbwt@kipRJv~p]-Dқ)Jd́)с/$%aoiuu ||7H[H9n-+IQ{(Kc*N;.@V*0iC̽M"dU+DkV{IFyBRH2ήHb_nLye.huϟliQb [$t$.W) wF8#;3m` s`QU}LrОDZfԕjoͲW .Ō{c\iH%]I\@N&1DaP#+6dn]IWxb_j(nYu b(qe@V0:j۵HcYʔ~0gEojnmI-(HwivIu9&qi "lJ]ފވue4c3'U ?_ڻ:Kg.X1kVN .|'ǿsijܿmS>(A3! x⍋ݣ"ҋ[9`~HCܢW8]i/,z` rȱMH?4pX^=WelH;{vPN/? JE'TF' >(&,S- m7Q+v H}ry:eQ ~p}XwL7]Fl͐J=ھ`I%uz`N)K8cP?7v;*cS+cӇ+͘bKiJχ!s `H )2}hF"|2jKo?OaluQ49x-/8M߾Ec퍛%nr N`Y"όH}.-sA; i/;ZHLXΠdyp><~^>L\I-`*;SwB?gy!=AО =3 ]2b];-m0R)zD) 1߮F\?c6#dZ"Fy ڒW(zU5\԰k2#,!,K=b6E| - (;nbGE؛eBzI0Kh>/t3As ssL v3XYbdzUPک4&. 7E hp7fq䙪1m:έC!~VV[,K\B 1E#{-0irb@6%- |8O{sd]Kd-X5dYwΉQsZNcQ> t@:"%ZW (*ݏRxP=jL)Zb#Q c=beͭ ;Шq@qS_`|dh_Rt04j,,\@ѱ1gqtf%hmI^,h>wYm,Z0"q4n]-!& (݆IV"'`f%Y W'dmOߺo{<6h+B1@u{қVc9Y}: )40s_c8K_nR'4]8K7GdS{9\j~T@bNt2+ݥpy NI?:JKwTֱHk傇ߟ)Tc1X&mUxV|OΣ^y͔)=X[(-fo)yY =xРqUD `۴SԬs`rMZ$'$PaniZ*hK~soY]%M#ƅءLi`#Pp9*G6<+%ܶ?I_Y<G hbהe vNf5#+OWPk,Int*c,'!p1튌ڞuo`Ȟ/zh5OK=WKڕ N:{W4<#u>C{5_5GT8AQ0pՠ%lEpAj3GU78˜6Jc'n:1bF휺5VN%/Q3pҞExyL e{rr9t|]hpݾ} HyqG *{sV^4La2]Yn;ѓ Eʰ/9!mu`?{>!S{^xY`1;]4 RI,`ʈܺ׬<4DND)1Xޠ ($ǢNqX%ýK9ey<7GR|֞YKNc`X֮ ҩGe=}U9閎n`?f_iRHܕx5|=aM-D`&-ibI[s);hr~Q<{c79 #.lY3yѦhf /](w q@O:_뚠|ݯ }_vWyZPNpPh;NWk38@v =NH,(}>!$ALZ->he9(ir q,9QÎ~ >vVWsx߿sLFf"Ut|((͖E [jE,~MW$&RrH(CxYqE.cHu7y,jÿ`E=YzD1=K}c7 wޒ+pu@ZVn&Ng1_8bT7r7&@1d ֡/€L)a3ATK-A<{Rڻ[:L3kL6Dm^\V:;q s1  aZAlAUP"-: w<_:/'|-" t NjfEAGPӕٳ}T)d?kE2ݙ@ FY]SYpꀡELERǨ<1'9p:jtKgS΀!M'w4>NVJdB]R.{?|f.R7S-#0ց<7b gخi/ !D;nx2/j˦)j.<믋o 0UpVH7'>}R!l^ O(^(i; QlXY{zjUឹO cș IR >0$/ ^$ؚy=#_WFdrs=rCt3v=#DdV6 5݉ߥڀ@bU::KJKǕޜlf2JjW(:7-r\_!>zP@7/nBqdz{t6nsyGŒ,o:51K_ $S}SPKMV6U^}Q &C )78d`Y>EiKv[Vsēqkʒi*/Xq脅?;k`i~bfelm> ^Sp(zWHWӟzYzY87!݀C:dʏLꬃ yøɇuUò0nznP6mvp~σN-}b$l+ЌOR8,.oZv$[;eȑ^O 1Ji 7! W62g2YW̲MU59g:-Ln3'2%>ͳCs"THϏ1lPE0i6cKN_ŝ~ XwLp8CҁljvmdQCm#|:$6X`l 6^Lآإ2Lń2b+n;A kMi|9V?bBT, 8 x1su/d;'rxdi莞%M SQJT˚t|^7vY,b=1nfȵCsoqPHȾ0(7 ya36`gCF(EeS,틚aBS8~Lh 87cwlR )5271F0fF\>J-tHp+|1z#ʽ.<ߧT#KT50l3EH ]B]tZ@M>WY{sFDLB9pV0qO" 刢[(6G TeIԅSLZ9<@?byE|R/$OU#<Ƥ<,n1YU@ygT!+(||N\By@ٓahOİ ׈PÀ+A$iXʮ/Gpqbi g O6Qk(1oR-H@ wzZW x4pEB/VS&jA,90C(q Vo\0dsjpŘQro0*D?'MT \gE*A$;=H]x| C^M@4=]GH( Z8GD*ݿ 2i*⣑xnhn"917+^jx4TWuT9.]XHXŌ!yH|HJd釷%!^bTD moaϓ|3 q~ٛqEģ}M@qT\K uP`MgLw3\U/ irKӞS\6/-6Scj뇴qM=TzA:*v{E] ŝ6Cm?8a\:Rv)ui2_tQLFҁ/\WF0nF+\ d6ttPBLngBE?n|*REF{ o^ݺ F"55rJ/ik I}`fb'p1:'-S-HXI5[H7~zPNPH ]0l9ݴ9~\V g*s%0mD =e:7gm^q"WMc >۶h^6$LA% K: @ɼ8cdֳz/)@ԃ>-u"ƌXW 靔1U|]Q\E,f 4^=;{BIO.eb: G!xgn.`/1".e~x#he+x0?W$?C{; 쮭f'l~vB1tSup;Q?X`xy|PLiʷrh kF]99ho>z.?8c\tI(<{UM;̭ 2Ës2%a%RQ+_Rj_W\o3: K]&JKkC.#tVo}HFսA6ǘ* !uW=$`N(|) =72֊h1yU(XKpu(ov;@ jexiSu8_e(}c5?tF =iݷXY`u;'"ۖ-BGCeA1"f3^W2&t6;NSGSO5PI҂J 麢E 4^pegxd'ؾ64gn;l>줩ſ0y_xF/t^$4Qc4R[>"8[]yl; Sݐ.  R[Oܱ1rmB2"t"Ĕ+ ?; HٷZUE&~nqf2tix?pxΓ;r]Oi1o`gOM;7ϠL&Yw \mǢwto)/+ 3՛k祟 z8O)\hQ_S~k)aiNbdN87 lFDɍR8G,X@ՋԯRt|LSÕ[RAP]@`B!AQc\XsEqZC*s eW6{鯺)X-sS;$߼v:Gm.eh_&]A?m 8nW""VK-aQn[r2 +>[ړҞ2&Q*Gdޗu-ͣV(8b?<>^ܟӑST#kTiЙWBp=&fEu!MXPBd2E{KZYc"k3ʙ;iPDfežev"MɁڬ@NoI<{߂!5>M]\GQT)dF9CVF턃lvcUe-IجcSaSTМte[Ps7oނL@V^=ND{@<90Er.@*lV\bG2P9D{.+VUr n% )HE+1BÖx =zx,#1BH"4X~/]+Lֶ.nÛ8Òyh`KP/-!!M&ոlPAxߎ^F ?3_o&'>PAqm~LܘBhXQgIv6+cq2“pG<6AflzjuCi:H1Y &f^'GFJP NC-\pGE.-AX>n]$f,+Ag.{58y'@MM2jߗpV _&e1flBwK߰߃ޙt&kp Ou!ۈz2eANw>HT`D˩'< OݯEչ"=%n-#~S"R~IQȝX{*)T%W n`\=*Cv !>|C6J7E@݉4{Ő\O}MhlJuC@Vljto2< nZ{Z--.@fQN6 -qvdlC$zmID/jX?K};ei4tz iQM^LH9GsX~933?mdhk˧;;{mf"oVI0MGEu՚\r<*kCL;"!:=t1TK˵9ҙ觉E뗎qWs1$^!=^^V?f}3-`-8=J8H*=C{ TCgEOr^xwf?Ty8xhƑ5Љ )KUZ X밹Q ]\kQk̝Z `56§[B>>apɝugj.5h#6S -VIEdP7uH/?!nN=[RUDpu /AGIꬠU_l h\ FyZK}Z?w_D2|ƲvWL4m dQΚPZ6Zbb}wjw0Se2zR;O]5'8rsr@u?ZЦr6>nOk[ӏ[.}ڧRF:ƽGi*+6qɰNԭ, xԄf'\o#0`MeѦC +?X*0xw4 4~4)ؾYϦ;۴P -Cse6Thq7Kq[&hIG Poh0,Qoxnu!s>֡L;`(}䓟s˥9)&)WX)1Ǚ?{fAY;`3Ŀ+gH;"yv;HX@~Z< X:7!N5E' u'ľ 7A|V\)VH* <ϭ}YlH]p 9Nr)Đ_ycC-eUXS$ 'TIdćy ^ۊDXN7M\+'vւn)RFکyС?ۣ`+DOvK`lDLE#VQ 1SZ u+AQw"lƒI4Y<̨ͯ<%)'FoW~) ye.jluHi\ϒ=84˹*u UI~MxWZ+|¦[vmXRp(DUC٨<7Y8jB+DI!4TyBÓ"| ߗև:i]+hk~j9l5ʕv{$gkBK|R@Z-5Q\r*̯ }n823$s rs/{,ɠru?)qqo;#,$I`M=wÄU7ͣE$&A U b>eje :>[TC" U^w|I0rw7њ?iULr|zpyЂZq'7t6AɻZ*]kUA3;2=^ZQv 4R * E?&?9 !*řz}KN2>EGJ؍{L5Ah0R_g=wh|,,9X 8_㛏dhw_Cr;w73DQ!jwa \?K\k¸ Y(? ,=jB_k%A%2i!܀#3.ɫIs3689~꩝5L4jxY=\t'a=w J^I?@x~6 8/ezU .?+iGpD\N}zDXe[xѳ4~-ׄɑmP5~)|k._"35 72]ֵ =XX[+[K`Fo\kgztwF\,WymxF -?L_5@!D.e?(ĹWvHd$QL*3+ 12 ˫ UKTs]Fc\svH/3ʋysoVj"Vf,X q@7^~Nb HXURLZRXklqv8<< }hoo'ku^yWzc4" 6u'.sbhY pFocr8GL~g?U1;w1E! K5X7,{$+$jwcT!Tǿ&$_4qFM5 >DCsQUv IE֖ɋǪXaxePכUr|. wG}_.{ъ=.q8E^% q~IK70Xuhݻl)ywYY6 m!byz-DcF:rŵHj$30kdw6o~m]QFںfȯ:t=.3!9id5,uAAQzef3NiW.Bh(t{s(h!%νIwgVlMܖ>V𕏋Rɥ鵂8:[>$/]D xfI<.L˪Q#Ǟ4$1nJ%Z>Ԕ-a+~V'*T2K?]ۧؖ ֑8%v>gW]KӿL8*ȭ)#,2~˱->9BIYjuylf4Wq*~T7ϟeQ݅v#jxڤr>E_Xu#s7W(z'#KP!w"#+A *\22(]TB\(NY$ ,xhZ%rayAG2ye23eNԳN%K{mˋ}w~=;Iץ?* dڼhvkϦAܙ苙sֱ҅SP1$_hN_u*kef PjKc mLh X؅A{$I,8KxA5.Ԝψ};|Z1}:|B|X':!яN1-r_T73>y TgýڶmJcznkdᤡf>O{R2)yr9HgW&m{s |IFh]Xm~w dيTl8H9RQ Z4sCL(Ƿ4дeFDmtř!nH3q\'8rk ‰/U9k L-pK|%h̸~4@$|(GSaMU ^`fx~H\Yc`&In)G<7C[59줫z{e%)eKWR7n1& _N_n7/[u6M.`u wqNaE(|nILCu ս'`)F?*zK L!?ے=R#՟3Q=W3 W duo'1g6A¦pg #r$/)qQ,e- E0o#XWB gFcI#`sQ ̚[. +2arN+$Ip7m%h:FxQ|,b-з8Pt]D) W*t6cavl5d9Iّ8x1s"q^ZxG? 4ð1/tR#<'od)tu=q~@#1K>r6>]]>Ʈ5S9xƳi8IsEC"dX*vf8eRozcŴʩPs uvo 0%\Cߦ3lmpf mbBwYhx}scNEt( 6p2-p;*$aZ̚P79 K.qdB nkQ Jf % 'A {8]-v4(PەPKRST"@XQ"|'6)Kʳa6,R1;9WVt~("4Wd E9˲J/D[ ]><u+6bO

/1(6W(|Q1p[}qseb9ޚ''ùZ+Y5ލŋ%Ys֔=l ^Ap0#  $u|`B8|,tX\^+,.,SY=[M Η7̤߸~ #UO\DJߤメT찟%k>yŸ]dhHi昖hpaH֗ r9{gs5eq^rĮ Hϼ0Jvݺ 1T!vt*`.A$<ՙ9ռ9! '`QB8 *ȯsS8l_+lp7vq-SHX9b@,`pvJa+ӫkS$Hu`F5|'`i.z:l2Ƿ:M!YU!a-WCP'P[$ﶊ e(|<~W^-}4%MӤ~C"cii#/|f^NSü%e4 1 ]_!hMZ)8Oi~Ҝm,`r5=(84ZSݺ 0xÌAO) >!~:Ijr`Ži|?ڝݜ|\9W>+bͨ0D.5Jq9Qa o_|nu]%>D2TƜ/5{&%#K91ŭa{BLE:8c{ k;bٝC{c *Av#ltG\m4, Nzۨ!}޷pzd-?ULlA;1!j)2.ڟzq &\,mLshqp7;\_k)Q=~>u.f. Lb \'P(˼z^`In4բG)p 8{賫[I QJeui=Amxr>=24+V܈թξdq m6eM60^^>$^ qug+`9H'B1zԙwOkK̠}B?(&f7ɑDKv-"5vʷy$ 5yPM˂WdK\#G ͦnDaѹb%K;Oc.>YrNg 3.,rlls? oku\%Ju~XXGEBl†Oxm3.2{ EqEV3"VD ԩ`=3)>.A3dF$9"ߩ"/ceaǼFNaӖY*AC;PV3IBV`|7QX6v&9 *Bҵއ2NB{~kb6ىpv54lǚ;j\ڳ6!>ׇvv{*G !: S.;?obێyFƫtBhp!p#p7\f#F}!<baDm~+d\iҐ;~I($ 㞄OTh5VT^!#9 `S:%Ɍww~tte h|"H[ցjLFK\OsAXZ'v}9+}:~dlڴBtzP[6r|}K+%idq{_I-_eϘ 𤎉mP1O.qK8+\K~ǝ,*TxyS^ܞ}-?Pge U4jB;^6R`J|2lM~?l Vy|644ƾlN( Dtl-Ănt)9(u^&AA%ۀ?wf``3I6F, RiAaej̝rIMp #e,Zůg64i 'vRӊ(T[|ϰ`ci:;-E{bͿR)6EVY%6-b 6T y:ϑSui瑗x甌k`kCҶͳNpn`t32 r_<D/Jg͎g U钥~CM o%`=[v۷[lVm0!őVO^OoQ#RYpl$e *hM#!1Z4_Y3hj됫>XfAjSr4E2U=xAj)X{ʙ{`#]aX̯%{m>:Ŏh"qrTԙ ^$g-8w/Y?+<$l#2/h 咄x(r[RQ|]~,L-uWg1]u6莉:PmzNћdPӲ9N6YJI̴G T]S*iobرQfc}pJ1aH2Oߐ@_ULv- u~`0`z.+JhNNSDt/JZr4|Pk>!m:& @尊q˜t)Q2߽WS0bTa51Yk=8VLݑt@TYI uW6UW!^ V \`~ހѦQȌeFW^!YXp64=ى7:%#Ӷ0EUV6_EmO82K9擖0n Ui1D I,?.?u : .RRƞOa?ӵg1cu},SlvT\Q9BLc'&7ރk/.?ËbgOCU;c2k\fN̮{#@xˑ}Wlh@F6u6/2!;+* B8JmΞPEd[w>B3`],5…vVIxjAB+Oͥ@ K,S 9ơI`'Qh1~iSe(iZdӳGHk:/^`A!ur}v$@_Ξ!ud19]O_NmZVktl_J_u[+ [suy3$6f>j`peeb2<Ƶcl6{APo `hC*=F,ajm3|ںX ,6qꄪ!RD|ʲ!1R}+Ӿ 1|ZK0Tf:n}$DgAoW)xRM*f1c]2{Yi"E|&ynEcƛVKoVm@W ߍsC[L>2?NZ!)nqz҆P3ȉZM+32NݟSbu&m$rBvz#'r% $oHQS :XoBYa;Tt@J]mmz>^%"fԸ9nI5NBG_|L0~"_@Iٽ!ͤrӣYI9pXѥ^ zn0` -->Jlq.DCIQ16/e\4RL#ɧ677q3z\)"f,G]KtQ\gJߎ f>hd,|~gѢsSc\mޜB(@ƵgF;(:AYmv 夝ΠP'׃1Ks{`8sP:&n ` Kd8S@Ȏ㹍ߪA# 7 %~Ç9NGv&~ܼ/рB)kuKs\X]12\^TWݐ˰1NgUA93d<ՠMc*`}Lm[D/>/b| {+M+3Au+ܨ賈:$UҸ:~^: cfnF` RTbإ(2PJE3~5ۯ|yLœ_G;/mZx^9UOCM;,fy[` nN3쳺s${0; % 7Eʅq5I<{gth2|=yaA ?-&7otg

    ձO3ZnGi?QߧkDlA oafREŒ+rVZmg4Ielbe︳M@+Ĉ;&X+Aմ`=ҥ-rwJ[?:DF6R?>."KLR/NBhfc)ǪewnoÁ2BUR>b/Ae\@bt[|.<3(9_^Sjs֘6; acYgy"2-td]UhW,o׸Y$]Ȣ4X!ZFaTu| ??߹wA)mu-xj!EğRTi*!g g3JB[^ԨU }*3OuouHkb]VwERF:x'aZ2n6(VȊOR~2n) c#ۃzn&*"ⓒ/sBsy#B4BsȬt(c>^Iµt亳~F+hPwH&*{~A$59y[ÃcqE|9hI".-ʖ+Xd^eژT~0UY&lт#e6t6)3KT.-juz+a.VtBKfLOA ]ɩBIZ3]BltCV ՙ1dyEŔݙ~RY\{?砋zq?w q3q Y{D|)t=Dw8ꌡ!}qT5*.kJMˣcVjbN6";2pWD *Q.$=BNi㸝1<&@p+Qz8\Wud-ڋpxɞ(Wb-WWyiѥ -~j/{d#8t(eȉKvYFUcm;BO w̗d6ɀ*YըeV(1cU.E|;fHStn,9˫ Ij+g ?HH$eEvuD9){Ycs;\_3Y<ƴ{GY1H^UKJ=O(fExP3GH)zJ>A?lcWjSïfoWVlg+3 V9A#IwAL4|#-Ђ=SޠH*; 'pixE<L3&xpTvp Ӝ7v! 9Q~[^4*/̔(8JDpI*:<'a˴]ň Jr[m]F(.kYkC_S;|_w<@K.F%k_`}F)U[1!{Pt0$4KG ' "/WAsV x k˒/<ˊt+SBX{2U3GE\*%XG2[ le~(`x{Ja5j67vYBI.֯:+2nb,w k1g\a'E*"0dC [9vOj~ˡdoNvsmSy|i 2Zfx(TqQ dFTt09`V+͚?Ne|J5Q ᗂA]*}|hNL f 6$o<.uKq: \-\4ok?4*4BsKd/CKA>~".~w!Ɣ=v; ݷţ>8 X=WwM8M,#"`O{X~0zv*+0Z6,q;uwuRO/>{㖵w"W H 6O>4|l|!l ZxNDtV9 J>l-ADj5w^gd |eQhP䪋$@)ׂ-#ŀS`@-JâlSyFXóqA``pI0zNi7r5 gsЏ4 Ȥ⡶`tiā;炇mi2setsgxl։̐c{PH5_\ke(S]|p@H*Z5sz1Ź"08+0FPʯ,Vusׂ*;utڰXҒ佩h!f>ґm4i-]?kI䙕7Lk?{R=.$݋/ܮ.(,@pFCAyWP,d\m6a56'EDNLfn`c`mꄀ'6$t6zc2(fVTptA Yd Gxbyרo$`k?Aݞbjh5X^!67r~*D$]@IHrS["OT! Z%OD*( dN7){Qt&ͤ3^tsZ"T#SO_V1G?ZUoC 'Ub]A|axx;@|Gz4p3L5f0~ء^3բz[ `+ PN/s>riČlDZD$E*Zx҇Sms`tC>XB4BdxŔ** Z% 3즩rCgq#A7'C\>>E9[qXm䥂ZB4:[C򗼞)a "12]У-)}eOa8LR` fZl,=2 omov#ٚAAD{(ؚfYhOl5E Vhc7\mt횷 c|iXBNkRdeX$,ɼyeM "f=_E{&fƍd{Xv"弤l?G* Wپ>QYqL!;ˣ/hÓME5O!&%lo۷̓>mՠ+w^}i/g>!wp>4`~nN /gW1ҍ7GF.E=MK4ڏA.\iMeOآMUh  $!WfaN)8`XԨw)kӶɴ~6B1H!~ᑈ]+ Y7ƻIN|6-[BSs-(h' ⨡~? ]oK1٩Y>"DEJ'GKe(8 _oēqOԣ^ђl*T򒤠}#O9.w >Hz ru`Px6VHOf巟@PGP,RL87c*;Il.K^~![&5XӞÊbetxȝTF;u7)ڭiA* A6?}pg/?Z (g-9%u2'QZg ӆghPdžmv'g˸G/y~Qh3|V{{YR>m*"I ԍ+P_MU˵߲s$40p>vl5Ѭ)z?%kmNGs(,M$%Bg5vq >.FL` ^TܑJQ0x*wǠZa~ȱxs20] K?w۾,W<Ũ4 `cBb$4u%Oceź'3;yg`|><|DM~ABEOQ >YފZ/?o|i'2ḣJɇx12!U讵3,rE(/s  g).p[7f_~l =ga?PU(@zLF%RPk@㠺r< s0"RC['"D1u ,A'^'@{68.['㯿Yl)17R*3S$QɲH+8)) gN0 y`ljAk>dLՑ H~F^wg^I^lzNC̸tn^;c yhelN'xܝk?I"S\bFms% %\Jr^dxM`zjR$v݊  HTcDa6\ I#Xj\!q˫GC1 vϕU9'a ,[PhFqa9@vM^8I$p 8Xzn&WE\bTQ9aLGW*i+qaE˙hBE|\i+`j 4f?<4@͕+Nap'N,9q(O50?r*'iwFXB}1OJPn𰅴幟.T(5w^赵I{8?T +zt\$*Ph 畴$ 7=SyJEkSҪ#"a(dyS(5A_l; cXI%>#[* N=)WFq&>F"0g! br!|Y ƐDQ)h+J2qރ+5 ܒ9rv$Ij3s~l :/iSL#quzsy,\yQ`qW[R z?({nPi7E hG0A7^-]&(LA-JjDnݶvy؋SZZ47 ؉('J2T)3Y~ qQ?T?җMd1ѾzƌC_* @~䄃Yy,(XB_^w:>ƯgU;9qk1Sz1D96AQw i7EB#=9֤# a|%(W k씙$xMXώݭ HKމ~`Y:ZVI<_ҷSzǃ}kKhX`Wr k ͦB3bX@<$楗IŌ7*76A=)f!hrbz#汳'& EI$R\<NܡGP,'e UKW&tvȆ]ƳG4ɾT>`QU&@xZqߑX;f.+>y\n[ TԖŤDWswq3|څ:|h~z4Ht]sIeEM>KBBkh RPߟV-ɒ:x ޮqrc>av>IKH)""VE+cfh#K'‰j]=Rq( OuSåNI@UO 0B(OIu3 E#dŗvCV9oIJc?|sZk8]bb1r]:FO6 b8~L[3S`;)6I[*a :=T{u׶ʀD:k 0w؎OǚUBlf:q貼^fYXA tzBH`iFbİ_®Pf:0W%S+nUBx6E6!js"A:d/m*+3Qܖ_j{E 'w^Iб dšCԱ^/J0yDPs+2NaIY'stGԳad,1?PQPy$@"RG1 qfUx0.l9Gd[O̯둋kF5fe{/:f4+B>^d@l]?VQiL1!"Ҁ͡i;ynڢAo3]n|aiuE,;hZw9KXpX/P6Q?5!܈ 2GBB3}XHhTZM_X˺-W99LupskG83pF`ՇNcP=z Srj̖Å;S)~rgh=$Ik=QSSwK+mN߄o鮩T/V[iݑӜ=ol<5T,_`lta:GsFHFDž{Ͻs3eYFcS.M:WؘAa#^ӁxsTNw̞뵀$*'1Dѣ }](vΌ,<޼& :m`/ç7 Ba03D@T$" ِ'.?%jNy&~=̨8c8ոjs|*2rH~LٺK,PS/*G/E4:w$ cvOl)ZhS(6M5ܒX đRW 21~1I`(vQ4"okvnB83%aGohA9Ӯ1XG ^WHk,C|w3g[~uKHHH @Z]z< *t OcTLBpڧɖ0&(XRoCk@Qij%-ǥ9? 0QSLi8(0}}!VLO/q[Vt=!akCM6D}cbߑ~,tY~F_H2|%VJai'zaC0:' Vpaq5q$\ .t@bܡ̂{sgEiN:_SuwՁqQ_ه}iiGM53: c)%XD "ōڰ|5=w^g$$ =!|;e|)%v@,)< lq*W$cCУxau1,YsCB3Oٕ^؂ ϥp.3% % Efv؏)lB+$ǣ#m9HiG%xa]w Qx$^N`S)qP<)IMT]ȵZ:J4nf,wf`N@bkF$'ޱmT/kBet2;1<O_ ҉ptQZbc.im&*6$oEqov^Rüu9e#b<*X6h"8)TGg1*"vq@q젼֢R5bZ|epn>.?gc H4@.T6 4eie~Je4zjM7mGXalp۾t5{2*-QsV(֑Z/|F1LBhl 8,I: ep}$/}Q :^曯JPkS8S"9/C$sؖ (_a+ZKd IdYT%amr ;D,ׅ1 ([,N嘋qڴDsXG@$k6,ƍ28Yc*0ܲnoej<C疠)7LP~bT_Ͱ vӍS(K T+?gTHR4NF{PңZ zx#rbBz|\LNKlySPrYMV@8ю qH+Qt8q6#fȎCiV"KqB؋C"5$[0_P{eSPrﲽrj2gFt*?,\]{s9pBρZNsB!_~`r|OQ۟6(gY - {&1A-`$_Dw,'$(I6CB,koYso2\'Bʖ0 SG5p= !|rۣ^(;\fG Q]oPEh-TߌgiH,PW^EhA3e$CO.3C{C l`GG~d0[+ ߶o-3qfV?C*OW'| 4XQ|éA(uItZE=mwh]S$/a[<{è}m㍝\ޮ.J?iא oUNE' 6|%!S`cmZ:ES}kx\2'C'\Ч7_uC/!j0Fr,0+Cj pW Ju8SzER`i]FShl1okJ(YF9jƹ5Io]M $({|-3P-P/n&4Z3Y>s(Ε4J\-"zS}BnzNۀȶ+zoe#לloe]m|rx 'D*ʌn\)yʷbۑtIMEPOըZ[6\ZSL "(ku1|o C.-]a針ˆEEgΜ7@09f:z]/u!`._֤%ܥfd=6`*|R2 0ɪ#wɈ UK<:ݨіuɕvs캢8-iRޡ)~N'>0PWwHV\ppGLU<2š7%pϔ"0_HW+T0b+Lhٔ O}q˜ hcMCz?&&#\ _s N~K /pLY]13M'0 ;߅n)So *ٗS;v"oճBs;T+Rq~^)s;qZWR˺z@1'nc׭H*c<(!?fXœvl?;GӽKL;Yf(nʄ J(u`'LN㉾4@RrǞT WڅFQ~I{Ֆد?Ϡ&@M0X&݅Ȗio7-ײF%;#tKXe+:Zjm&c>%Lu6SM^FF%EE0VG li8DyЋnퟹ AߤRY|CUj)\|Qz(\ 3w[)9R|]M 8kܶ~].MJ1P6ʖhLcs%#)e \< x0U+D oXf4u@d:#U}J̓,d0ˈP24`QBv:oҀdlDuI-c_ X5Qo3SV﹜мdcMA2OXa$)aO3^ahԱlrV㹲~)h֫HQ* /6zO5T{X'`:2AfAIZ=.9NHni:iW$dkZon7C>懘lM"ix4 "͂8|]N|Iq :me7Tib, G> Eס8es#!*aKNy>th:<ȂvM܅(ǿXĔ4Lbp㷒([۴Yb+rj"xow^BU0g_wKwPMI,bu:Pږt3(}'{JeW0(I5'"27q>ίlH5.3%f18BIAfR[,T B I:^o4w?y#;'zfypuy n=:Kd߭5\45] lh( *D)KD! LR}q:bLְTut:D]hΧAh ۟=nJiU^qZ֖vY[meZ?Up{i-;)UD1CH; ^l[c3m"~ce9;+N (ܑPwFOPP[ Q%u?]48 %@@0x՟AZ& X(>C8y8e_[=k ,fuI1KE6 DzQ} e0in%lpYhû%-iJqrSBuhz *'sR1>Za! 7Z]#M;΄'č2~ [GsԓzR# /$ҰzW|BT_'× 7S/hl'T"Fy?DŃ?ܝ3L'/`:y0kx Y+⼏{B)^z l\f$&7 39~Btyv~ʮ/osmOdҋ`a3UV3& dQIc{i'yY͈q0 u < o_m,* ՙv]Rq,/Y7x^{&綋#`̏\QaI#rd^}Ec0enzr4QB܊ nwN#DYfh3FN4% 2E;@\Rҵ)PJC?AĚA *pqKx #R,_g:Lgś@ewx1:CSi?0UΩHr䵧^#\EHtC,ʌϿT6QƯmA NOd.)"҃7e4QQ:%GRS_7{Aì ڑb߯hw{4p)g.{T wX[$NElRHG~Ho)(L *=|{g)uFc{%k׊/ϰrqq*?򍋧3e|xRh}J訧U,|1.V71@RJ} B'$/A{1drI1$=vڧ-A.JJ+.& Mh{`xG~Ös4=#yg.aQ'k3a60$ATv khPe320t&|B0&ee| ~]q2|i]aVhÅSfӆޔ*+ ;,a g"527'ܺ^K$#ϰZq[<ÑS%dG$wQ$e.c)hM6"J/G-@%p6nKRI%VZ1ɱ^ >Jpu0H>SL UIJWv{5?Yזӯ#`, +ne^31(@aya`}U%Mz +״ ;p;EG |<_&$fa q212H B. ׫DArt5Dr y3QOϭCeO?A=.1^ w#M53~k f`9+8ꃆ&B \6˓ F6/MzP~/22_Td3Z6Sl=ϸc[ ) /X>T#qru:AccL u- eoXT!b"nOVTDhDJtޝ߭htD=(j V55KXݲӇ)jS.-/K#8SͰ;eBC% 8&,hG" ,Y =pa咞Q//LMiE,I Rj+!*2sj|%}Xl[ޜOZ"CGǀ ɣ*#ڇ&u;[={|bb|{9duP|Ҫ `4ҽ!a  FE!U_Hxy~! ֠UmZBLDtcB-;MkӻV3ݕ1"-֭êNDGv^f;l8vKEG_g'R Hя[(apL*bRķ+"vtOeQc5M|'չ+~G74i~ՌŬ&  G@4w-V(tJNMn pCZD/0%}B?LbeaB#-oRo?\@pFQ\8╞3#E̅8,%tVipݛoui؈cK:d26dGcB_L4IO+IDȱMZ;KStڠ(XInh)gh۝wJ Tz ̪x\&Uׂ&W0!"*jeTQw|e)d*dST*PcnVPΛڥSx9j5 ` ]2g~׶Qyכ4|W%# k!󩶍saU@'\|x@z-A/E֣ ue?Jԩ˘#sNw~{™ |@3.A}(֊dY}/Ӳ* b pv{ٞv z_+NDʘJtלhZ5:0UX>(q]љй;\(*BHU-}֛#7T|~V[<e kbD\ qRviΉ'4 f%(%!OPFQ}NI6#¯ykwEjچD_^kcu@i|Pp?C<JXFʲ)8gOS|FDBP+24cK?R@kϴ!M}G6)zwƲͿ%5.on(烰VoSߐX|)ЏANq.;*DQNXCk>hr*=Ħ! ,Q:)`dvkd0#~dVW+?ѸxopRˊ IyMq XQzD#!!3M%] ;LXza \%:yEWebj!:' >7}Rn3 B h2v5Z4xYEEoO=dX 2+&21*$.HA'E05MtQJFӔqM7/҇ [kruF8 #| IǷk"=DykWبT]!^%zq B`Ӳ5Xf%4Uwc{ԇ؎BF2XS]["s<$M^4/GdH .{;m3a4afX՗~ ̱r pG]X]ޤU$ ' ?M 4``Y{ɖң[ 3c֋m*s=E-1A^ s7]dmM1}L5D޻N|/ҕ_ U(݌Iɒ~$UCLfTO"5rUOιZ?3Xf}Jc;A\&詵\b{p #ACRw2)1iW:۶6'27[VάehV7&$֔ @4Y9*!gkp*Yp Tr5w2 0&_ uפn ЊRM "hc.: ega)5C0\ϋgẌ́7 _ݣ^GM>)gY,L 'eP*~3ǻA\bz[t&iN Gx*.3n~k ZDc෵N?`Zu2] &EN9cF bcbƯĔȍ`\LN5~zp"c>9%$*i ʄә yzb|~~z`Eggʐ^iR:* X!6kfFtB5Uf탵wsN~c8м_n>_l g|W9H+1AC@lS3Vsy;ۋǎCfK&D`qQ gʕxıNLNb2=q LG+lA%;@̯DOFE1om{Nhł$.]h%je^8fuyyKpRh̤"INCwk.m# њ" snQE>ю?}äk[1w!jfdڥ(-2Au*ZM0Y띬+E6@߿Ib{Y =Vu+8^kTkz#mZDSG5DH(Z\# ܩNT=1'@E̡h3"W×1vsA+z#>o\ bP)cˡё)P =|D܅<s"IF=mE{8hDةQ9=s2$sO34t70x͟&Em.{t u?+aP"kOi˘Zqϼ|v>Ȝ$n"I׏(ߒE.w+G{ӥ;=~4eN^ȅgp27Fqr U,ݧ:B;pB $;V6 R̢@N?)RF7NDgo+LT_^}bɝ*w>Z!>يMA>W2Ç4N`Ec¢YSp6Rå12^wW*@Lj7JP&( ʂ)w˛x^bmM˝a#9fcevp6;%: &m}bQu B!/q6d~ӍúFE$8i;`v1Qij>{Z(MU8V1`_^J*- B(vLGtt΋0圴Nzj5%Tj5\z|uUvY:Kp\mW:oj[5bE*F(>V?F1LLy\ }/ggmH>lK3ut>/ ͳyи1PJ#G%i#:pMnۍؒ^D{iZ@ O0|Po4Q6Ѩܨh,3O 62М/PREN53Լ{o W$,ng;tiU!*tL4K?LUQ9L4m#fo[&z`%1`!*n" ᪌3VǑ7 J="nVXyA3|o}2ׅ K,Nԩ~G#V5 %^*H5WHl_Е;V $Ld+:N`sSݥqz7#݉xcG]½/PoӻS\>fk˚XQMGF[*.-M>4=e hYQvW wj<3g޻-TIҦ*k]d{G [uu %CiY\UԒyZDž5m=vr:۩$gn0òNwv1\ +;.ͧu45 Tg!ޔfDQx^Ƨ5݂5hWݯ#) (L4hl(f3tGc;r%ƍq6\ )˳9ɉKaS:ygֹ$+y-= CI*"3hׂ:=f:ތ)b:OOiJ4yUXףUUhԺO6«E߿DbC0KB77q)*`< 1r3<ζ~ѲO g*ֳ,RJKm9( C~fB1jq.<hC,djʖ F2Rrcc{{2Ssd4_ReҖ/6W|ÜQXd4T=2"„JFJ>P[D`]љcuMF2zxRhߴ23X۞w$ ,zآWܢUAsum:d$2.h#};7 4"i์KZA;&xvңES9ꏡ$dY¸8a>l#"巹,@ǝvQb߇8.VTx„f^Va?88T]ld6Zrhj˜p_>iKsAwCɞbit>.B~ fT+U*![1\fӍ&(H_uZ\)K.K*kU%Ύ4[:q~ԄT, ;T䝚rRIlDra$Bq-ƦXT}p;[R#ѬB:/spL_0N mZkޯƠtVU{1MQyώ$ܤ&7SgnD~$ᆱO,kx%J+oEL6Th;Ȝ,??)|bRy$̱['6+IoMiGSu\&G|$R`͘=^WѨ_ٽMӡ nJ 4rS*[9_5举gRG3>h`4ONبf@CŌᗴt\ɂVP6!hO=aӹ d|vU/ C8[ݫXGxPgǢsr?Y\10qȅƁ{ uE14)3 !jf Үwj=)9 ?m-3 tc2#IhPPAHD49aNjṷ꧈b*4}DV؄0B2`!b<27OAdRݗf|J9glQc2LI\&Ԋ,o$ns@$=^T=m@ߘd/XeDZ ECT@{ Ң:gqc1t6dFn?N"'_YًB%ã݂xUN((偱2Wg]Or>ug2 s dGAb̓d~?f^m0pk%S= ++sho$z=3p(B1If?i=Az \8'x>pK8cE8Ұk-Uzm򞦁??GzFư1 6a*%r=Gb3/`tp7cVX>]D@ ,DQ~2~cdX @s%>H}Lt2\hĪeuy{O㑩j69]dI)&kPv(۽f%)~olꇇ&aȋ{ z9ʤ|>2ω]BBP.16irI+^#+{rd͈(~h?_xòսv L46(R^ǂ_2$>K_$W 6jwJ=^H] wKriE <@3籺ϰrcݡjD\3rۃ ԾH6<1nĊLcr' =EԉiAR% nN}̿ݑYGJ■p@jըϐC4&RMU_5t?M*:]D#_ `MqeZHY.u7c^^In# g(˩AV3D^ۼ&le8ZL6OMGYBK.+* 5x1ȩk"AH`^;UP{9LT΃?P$c%lփ舺 aAp:of/ë/WUrݤΟcg"߈z\ɖ г0vǣzl5AYn!fL*O<;v{_oedK'.tO$㧙^%0bUF$'.2'֩ƁgGͧIr# !w$ijZ2RkaKqC $\GeD"d>6s IW-c]YؑúU[]u+ܰCN~bu',[];٣`N\UYHwx ߘ-'/Ң57{'Jŀh5@I>g*\րavpBAçEG^k"4MKL7Aq->cJj2tE;v=%퍨N؎*$Q<~$2|UrFDߕU+۳ )hqIiZåu6z܁`6$ͽ0Fqʓx^b雘42R(^/XFj'2<τzutƖe΍%C׍D%.UnqOI dԫLЏ8y%]]]HoRB CuՆ/]ڤ]|q{kWH, \-|'2K䞶k 4U5q0x7ӈ4 _pGMDC$Sk^)- g}:yc^ ͇?qZͽ0$c}>/hhB.nzm kxy6Zj]s?;o- 6%<.]C0Kw/֝azz9@"92)ZNEZ<tP4_5dse|_]+ k&Ri{A#,BKQi 4xg&fS_b<9ݢoeKu9fSkJE^/A`CL)4n4b\HzɂvÙȶ =˻:mtVk~5CI]NP43aQsIͩ|Z*@͐&lrdZN;*-|-.7ɄN'"\)bu$QQ6h*,02hӥ`S{< "˥>0w1QUhͳƚMD| k=pqEپ7QeDf=h@Fn*?FeQ|ǷR:8jSv^3e<)Y>\2 dJz |dH FKR1;Tȥ~K 56|m'Q$9Z{o>s32N^q^$ͮ2QbO˄,yNV{;{Q4XQ޹_*8np[q lqBb; G))DGy(~mjy1?gEJNoK dkL l̊K6J6*Jt :D:մ䆂 2L09v19;j3ڧU7dwd?r좃/]Ɠ2qeJg/ymʡ\fU`hL_{qsqpr&9o,+O0IWUu4Ӈ˯khD:f64w0Z=nG8B/C0-ڛ1%0DVm2}'cXs*Iޛ_.۶K∁I&6Yvm㙪f&EHf=ĶZv1 Z&N=m) N/|2ni*X(>.X)T Iu+RkjD/2-lj(WtXPNQ@" lK2iAƖށ&l"IpR8p~Z'e Q/tpzzztѭKA Q1bZqL}@ƬBro#5CPo@ 'zE|GJ0k6@ZjB>\MϨ)@ׇ=`Ld@EՃdX/8}Dgʨ@Ȼ!Ut&˂EXɇJ tdLaԑjPhӕTV'=O?>syx:!drsy*ЂǙaZhI-]  b9_uؼMVxH}I<(?^.8Q6wBJzA ntbƂjXuN,~TEE;B5P߅(]oь`_ys2z^VqS19_:hԓQy63vc.~S& s\+T ;=Y]9~Z'ѷ }BqumkǢtXذ`&V$R񦢏ggt*|8_aAhiYZr9*Dka/K34ދcF(+.$F}OB!:GM];{[O5 80LM|."!_ZW.7d'&aGuǺR bdg3*2gp` u"FtEXA-IܤRh>5d>]p~ۺGciu|;cg{k$av-w̡©`NzB ~5 Bm[73c)z?CE(*s,k9*NC2l0XA#u'[ ǤGh+)kȑ [[Lq +"@Lׁ-)O XAȖ&x"s[YPz׺?-]Hω.㼧X4d)/* 4.Rpki8#p:R} ^xk" 8۠ڌg]gF,f|5ʓ4B%<@}/B}fm?3&"x ;ePєj>bIfނ1M,{ M&qNZC)#4yCՆtŃ^-:t΃Q&ON@!,X: ɥ, Rã-xɻk#huqتA>fe<<[@~^5{"qs%=!$fgDZM b*G2j<4`%ٛ ?*YY! #//H >m fau AHGha M-E2 (`4&q @ % 2σfp#ŋje?bLcD;q`-x"Fd?ix;. I _qC#u22X?9ڨF +_Ǵ{=Aa)McOٺ }6O ScBԎ@rr?eC X`߂N 56_$\/G+Q w,D@L˂pZn(q4. 3/0%P;+Mc1ȍ<2&r1-X9g#mBt!xd,Rw%_^qu=paL+\}׿aSmnCq[hsL+[EFeyGcQYJc~ީޛפ>yRAB1P{! se!(WI{Te~8QC+ϟ#6v{Xg n=!>2 b_K1gUci1Benp8: 8cBe'3>7WϱquIQ{\7c LT siCY[0-P'_u& gshgVn!Ay,ZѩpElG[~੾8JP.7{Y M®lZҔ|ntaK@Vqe踰.؈ͽ{r"hV<sHn<kŬxHVsC)|83:\vEN j<}ua>i0ӳyn24#LЃut߹ {¾.3vs(]̟}bPȮCK($'qP"=A_S~' ^seQ[ĒUlI9~ӇaWF.!7dMKZTږ]ST 9'[rͻfqI|r&OJeyƙMΗS֦ ^byptkg6)HT ; #̭3eC7u\e);/PGohbM5/ ZQ"%9괉^Q= xVH}}~*JJx7j[MTk`feOpWtw|(#6?v!K QiMcoVR[?ؠڸ3rzk8Ƽ>@2( KI@DOS9дzenI /=D勇)|'iCȿ~/"7r9T1W01|ތe4 hWj nQ@22'7S W)[J,JQ8zoNv(FS51{D~r[cKe=Hi[ [Nč! ɋ.66 ԥZ$uO%)K .uo~ZJfsԻH;{@F嗜d{jcpoͶΨ[PSsؖEa _y 4v ~Ѡ >՚=(}y$yoޑ(/aX6⚠=,]kr[&WhRbeWii=MpO+^{XNVк-^ؙ8fa(+[* 2{& />ȢU  #8_"c|i/OIAJ6]4(i/ љ4LHئnިi5kt"!_$ce\=GS^Z%Xף1`]nn;Ο_r$&  7(t̃[+"Āh-֝o6-b<m'lk^z-Hжbu2gY[f ƕ(!EܖɣF»w:('E ?ة. X,eÙCLv=8CR<=Z׏RYf!h~7a%Vo͏&|xsU4] N9H:MtAǭc *#bl^Grڇ? %zb (2"2鐦UvʁAw=g|a:G@!Dkpl CQ|`WՖ4Zrܠo<F0MǃRvYlN3E =]9i ωr(يE#Ǐѡ^6NHsWN˔P6^@.q)@j),@x^v& ;\_lyWa!&sԛϏzx \$*,k;a5aQDzH&O!sVssk W㮿ZetZ(\8)̞I._*ƃK^~HsJLb$e-)0?%.Dh7Ҳ̧8#3 \tt/{zZj#&36,'8c=p=gU(Xu=Qe0@Ox[o)|yU ssxHK=>fPȀ&2S?;5(9n?P 9MJv?|񹰋{ц_Ы A1Ԩ G}Ж'gdo HSM"tÖSy(YO,пP,Sm-/[y#*}GL-HXHe@p ~{§v4S.$k=;uf9pGxB/M>0j:˿inciQ8HlP0HL(sVopsT0q6[)y`)1F^5UgiQ>#dCtֿ6;7K')Fsz)OQ`%IC2")*%辟Ae|'o;.xEkQ{y?DEf"93 /f1 Bz⟺8RN2NI3䕵 43DGxix2W&K߷wk {Y4ZM&Ϯ6Qp<I̕ZYSRyԸbK+?Mߠ'*'42IgRct"f{tgKyYj3R$ՃQaW1m?JoU%xIv\ mO>)Z"H zӇ)ī Z-X6vh)*"0y36!jyRaD~JܯȾkdWM6lHp$e$o1I76;~SŀYrQUT M-vav5Xҹڤ:lqev8=^'؟ݦ)EN:/ֱkc(grou6K KYgx椎NogP1Rn~+qoͷp誸w v4/#P~PػK6I兑(Fݯ-b7Yp8?mLjOІo6 ЮlH\x5#v MOIq)8ϨR=p!̓` ###qO&"..ɨ~ cͯ-8*Ԟ‹03RW Cڋ)1f]rHp_I fZ"B0j <잆A RMA[s -}[Ӎg})V1f1s`0|k%kZvЄt-8ԂHd}d|. A( L~Y t} y%'(jt=H,"@莰XݫMU#p ;ȺֲImz >] p︬אf:Q}LJ+yKFe6sL\YMdq-~y Y@T$ZVt 7yR6VB(*xjrX̮4C.6thFxjWIJs!2o bk_t^,ueT0F01H=$?u:hIS%N㷋?k _sϦ8~KJi.Q 5iB1G?tD<6|v\Wai$&h8%֪j[!;ca\."Y=S\ C&&QV=~@sh pŖR+ "| pb(Xfin5FB~/r 2ٹLlcS%-ʒ_+iZzh<:GbuKb4m݁穪8%P-עyS%'^'5VbhJI@R^Fo/C:t Yf1[CvmG۱DMV#^~WpqA?Xtag+:/օ@ NRv BhŠY,˧5nj@$ >{]0hҽ,FY(;Pfi ManHLCbq&(|az;[S H)xO+@S|0wġa3|e ?u¡M=썬}^e5bb7Cfo*^-K~p\޲تo`x/#ic3oÒևh>y=NacOǧ|%׾41=4Ⱦ>m)B$yH:.*;, "ƴA>`3y}sC jw ft fs,mzǼu/DxK=DsJ$\uĎ1E%w>Hys2:6@BfFX}>ѳ}3eĩe`XBrpSX#D]XOLh!+2!TKY2eCR)9 ZIљ1vgO )5L:6ʮx#9PiER>#Ntkd|1khS=zJ'2=Է:BZ/'k0+{[^)7 ?eVk ujQ"6~:[EJ`_&.lMS:&=g_-\P!,}0]OwA݈; ރ=IU%MwCg4$ gX5d\*aS>*kiIlW/$&q^o ~ c ģTxC~=% vcc82ni1_݉HiZᣬs)JJ`8Ju,*%& ڋ- eNs";[Z:ث^ȨUNc(C+Ccp; 9텂$%\C2'r yu: ZS`!^MQw귡VJm|ůu b7#j]E|7\RhW/ ='*QgQ.M0CYuI;O k+Gtw\Q'}xC=oWwl[)` xϛ|@-o,†ʂ%N_v0Zxۥm\2{Ww`ZD#}e8.T!ϡN%x,uҶ6*Y1)\=HJ>֌mm 3w\2@z/X,}jX(Bz~-LSj0,´^_y'!2_R {CrG|~} p56r+CÃs!aYI87Rض?IO!*`=yA'6D /̜wM!Ey&l,d |fR>.`ǁA$jfGg չ?TeT.D. P1Vrx R'쏨hdBT&Ć~.c$1+@7is$d`sqУveFO~8%nFˋJ[`7(w*ǀGe;x)Dޥ˜gmx[ʦBr`N^$ȷ^0Y;'PcdG@R9KvLin…}=kDי Y.k) Jɹ@]Rީڃ2R'$5Fz[6VC8Ui+EsH6Rz{ n-3 n&1QyD0`P_uSw0+Yjn'+جVcbTXtN<Tk~ȠBzv:Yn őU!bmlC%fĞVlZalR@&3|gd'ǤsfKGbiGoD2^+2V~)PD:8[C>̟IuAE2(}R!LMDGm[}]gb( mi9ZMwe5Ͷjnp pŇ$ DrslMR~1~-@&Q^@1XwԣmxѺ$qE5h@8QD;Ç,wԺT_U/C: .rTюXU E0Xl I nnm/h{ǑNb6V}o7΋rN ÄjӕC >b߯OHX,gV匸ym" Ϊ@X&'S|G5taUN7͸Q=^<*5G`[G>"j ܎ BO mOaySw -hMZډBpQ>9Zn=PŹys=m]p6Ӽk-5!jpGidOgЂ [:^WKƚ3R0ug+F~YTh鉩U+0h-첲Y(/[:b?SA=.s%tgٮ.jmבּ_]a9iHE_@퓲u\4=9-q -շO)T u;jN~Xs,:"NDq\["D7T"̅fM _<԰F~Ok|]ogSlVcrjq>:*3pG J搸( TtePK!(Q '?G3N:^M.fp]|Έ WhъJh3a0ifnj+k°ʔx~ie6nt̷2vϡWU*FԾZ6P{DqH4k}hޫ(XB B9fI0 ?+O9zxH;dr#qfd=q \~f|e1Tƣ^B["4fVu;#:lzHzB\n h?*1j&2p&a5A[׽rx"8֦39nvWyoCGCEhؘ?VE0-$9%|Q`274k9m 圪e'OQ7[ylzZ '% @iw(XWPК*yay2 201'u54F[m-SrX!h'kġYk:޳*0URl~cv$O/Nߚ2le_aRsXSƔ.Ms[O.5Zm 44Fҁ"KyD1Va3vkų.ݕw70W*Ur-X\O\tcbҔ >ݍ >;Hiq \M:qe1J:Ic { 4?,E Aȧ8E'J([\iIoޘ/E?Se\W zF~+q28XphwKAJl#&1;= "?7 PdpNnN_Й':ؽnE`GN -9 Z35kR/9p>n<6i9UB+ !_5ն\-r?a9}_Qq^^~Ffrg?2qz5-,"mNEKd[^`pi˜\YBE YG!4yJMlҰ0O>dASt|Maϸ"mpeKDJoz\O4d+rby$ټxIn1A !(Сɡ)0m!.c(-&`|x̭|$~~8=JDݬ e_sp*.CdN{H=RbNvK!](xc8?˥s4vv((.MKמ9hU_g+k%?60=|)&},>Y03<@[;mh3ÞaLˇLn΃e2[C]]( >WiaR<(`FIҗ /Ǥ4k#0rx׬hy %!*O{`ĨCf`wv1 qzp6ǚ!NTr3?PkS-FUoT !",WT)N*vg&vѧ0>s$F{D7`tq{$5W1s-,1B7kyt8>Jul\*Xُʀ6TbW͑#"4;*bNd`YNijfd~0:txh%ɦkx5r5,l+ox!bjM#1Q(.W)=!Xl6lONr#T/s./qzx_ qǓ&h!AgLh*z_W);AVTR$ e;IL]kUX77mV0c9`Gbo+ ț;$W'`ѴJs\;Վs)=(aqȣm,VգhH~'j&67]e2 ,2+Hn荒2ޤ'OQ|>JOz:Xz4rWD#فdEz6+SX20Bma\CʈoH[BnN-q3MIf)ɗ Jq 5eQn)n7>EfJ nsXcP?:yখ9DWM( Cڞ껷h4vЗ{ @A)h)#@>uۨv÷2PƧJp@ ;^ /ۢ]NG@Kmk[EwmΞ)^p6 8] w% #xe k9H^ j(>sn;o2> Op.:語1xC:PLTT+EVzO f"cs2O 7"5UپUP&aAY,G ͺ܂fe ,m@YC}?$t•*ԢXf.TP:9 E82mvaqZC)#AtEk(y{"n2;4)0.vDJ>3zu;gٯ+)+Z3|X0A0.C`wnQE%H,1 _)sᑨ6UYMI$'D|fMbVRCgª., 5zQH6<98w.b?m!Ә7lGUPt&VW ]pQU+pF?j):!7cŞ:SOCK;=#,M?P{IEXNëdЭ4f.#M T8BƯρNLJ=_{FeN0|jٽbSrOÙǫ⬬"g;`q~<{&=/QW-V#zYdWW2ҹ;55y[ӏ@e124ՠ(suMK00y rlOTŻ*UtT+r3an:Χohh&S͚zt9GoՏדoc>T/ Pȷڈ[mN ̓Sx(E3ّ3 4h:&ŠT֏H \%WAyayݙfu`g9ŔugDɹ÷9c.KLF]v]9U䤁BӬNZGח*-3fVPv]OeAo41I w$8i| wJW ~V|*$M;j7 S܍@@y.%q=qZo4C~!{R|;0*H|&0P"yYRbCޡXF(@$Rf1mᏀ6KQԊTx>`7&4uic{)X>s0G8qdeT3b"7hϖj ʵq;sѡǰ=@C9|*ya=k A||r B''GV4AU["CX7 BszϜh2ξz]}%:, kʗuk@7kB?,hEiUu%CXF׫͠?gY(I0| ^au +&Lqzb`i #/V WjupIx0.yS9.yv@$"]kHLc/j  y N^~)aT0-v)^,\.Zɿz3~߫&$DI & qw$Jalpmu- `Cw} A:s r}^ƭ "pS= VS^5B3H 7-8 i/: 6⓷~"eԟt4 =NɄ̽gjcr#^OQhv'R _BG/DE%835 }|0ʐ{Ɋ}([-p?.kق-Ar&mZeq"}wmIY&<S4 W^cd-2\𵯏jU[L`wKLkNJI [l@ Fiq{[46 be+24Xof9! &s^TiCxʙ dձ%= F#2ecLɴ<">f.`[P@S:?/J0(-!:k)wٶ;U#RlT =;wJ`Gz"TքPؑ$ƚbHm)<-]\QFc;\?(ND `#~pF 윝'8Eq_M0.}&`L9/^3ư$C@NRq J*|NAb-zTz9@N'j}G0/Fap)T'D/}1~j' ʕK?^[4wUQ$rz(mGݕP? {MB` KeLMKF{NQex? ,N04 03Ř9 7A,K k 2.;>wq"<ɞ(S’h#:\)x~t?( Bmt #fcrlx:r ݻ_DI3ـ呓aUԙ5ˉL9Hp`%jHbhXaåAt5AuI]~vq36ah@n2{a)-aT jثu)rUM5SuL9Qr_G-W"9rT@pӘHhWn>Vs e:8\r_oÞF2dSxwFA灢 )IWC=)`Mlc_ 2}U4GD3!Õ9N?]&)=5wbDݭyKy CPYE]R,w>jM8UyY8;_I_"2aDo_ȍsF1mwFwjGQӔBh'o^aUC%zlDEՒߜS65+f^˻ImKԼK4DZJBU 4%l2T ө[2T;?F2E;2)*l,p= ~Jv~9ϹWs>k*;XkQ8uBidiwY6pғW;K*#SaϟȍڶZk/G V7fH`ix) T0rYnm}%5?#.!l_OՆXr]b;t`ȹWX% murWPH/''eu2;gjU!,6dT,aUdGq)`$O:0 cKt߬# ;>8k` ^K .64g k>KvmQ>#ʴ՚_D>i`$׊YTV·+su3ؿn;xz6)F!4..fXR" < ;U)Sh # QIwg{ >X-L5(|CvOVVl=vY8 CFW=z*tE 3G)3G%|zI& y߭ˈiEfH,b<ϣ-QNebUTqNS0  Sa p |j0׳NTGCcjDޱB۰$A P72#V樭CimT61jjjXEh 48В"^b:`q|bd$zrvq+$cOpSD :M)P[ˏ7OrEN ="vc/h{fK"aƭ 0?^RހbX3~>Skv^䜂k?News;? f5 QӰ4+PlV|l/~d;U*ƃ+4&jsA1{Ox쬦6KG g/"5_,,0U[ow=o~'וǖ){JAa^>$OWڿʰkU!OU0kP6߃Wp鵤xe< GJrO&mp28Gh N>jHۍ28;n+з8rB[3^/ШvB- &Ե!W2שcFHz Z p S`~NGGٹ+5:P{IМ-N[c}V-SOn},=VZ0Ln1^A7^/";}Tz;KjyɣG &^ʉ}lMW/+o$2}<~:@oAoSbp3Nџ\tж=^l $7RvJ͈`D8.)Kbt$ `XH ?QdBc/H/)}y(wCcM Xe%3Tcg lڞtLaVs򢶌MtsYT:qߦ! ״ thQS6䕼|9$!;^j:Y +opL"EɌiٱ}tkL r4KD5AgFuGb@-NO(= _#0~G(uYke;"ll]RK|&'bt"s}FGa톾P8q'ǰ㝎RF.ŜXNXH؀0a˹_[A"Ie~ _ iNC&KfO4k%8 3ÌF]ۅHtW%M^E10z֝hCVA0^{E8hW[I?SQ-½T֏UXKNgv`՞:!]f(lOt!K 0#̒pNA\0"f0膓V އ<0ʰ"-3)hRAS\JyAtC@Ù NRmxTPX%Wf[+XČJ@? u9F1$^jAk!7wk-5R3:U|dNɤo]m9&k1ZQ8𗱟}<{S,T <%@CNԇl-J|Wk;_R-l 1)'=?a4ڽhJ7G;}';ڝqig)Cݢrɫg? 0t:T*.>3dzg%}"lRiasr<+ܔ=NNv^oJ+>06BTo|ufev:e=D0̴wpg .4pdkuN a#:͑/ՉeQ̼*D w 峳 EUOs;/"N :(15)9j́G޽&6F343ɓ;cD}V)è;xVK:u[("26= YSHS3gщfa{aS:$dy<%:U7*xz7D՛'] wO Mt$%4(uiMRP!`=I@Ė +!\'>O-,XUT#yfm Ƚ>hO<z%o}E]e" W;/;dBm+Eu~1glӾ'o{~e-mME;ˌzgnS&?L+.Di.F ?QS*Ju΂o,迫}H{A,>˫i\WCuen.QmWEyGbN4hd:}":sf98cxh?TWT>X{%"SMjT۷+1y/Og/,6HtXx`Y3!a,ȭ H#d}BiwfEMHh"~j=(ߧy둩IʫXmx9JX_e0]RU*@ՓATTx;z犷vȻ5C)sԤ"J 1 Rtc5^je㝡(x׊O`ĺ$l?;oT |Xkґ2*O@7 n;~M]}=\{7oЅAO½pr0u5(U.Ҧ%P:Gèr_0I,Xk8_2H"땝tW{Z(03%I6zpIO(m(]vVJ%\`+u߉Kiq;_nOW~(niJ_H䀧""J(z`‘_(ʅKщZڏE}͹6s*SCYjQ Dye.KPQ̂H(E 8Fʿ2@Fnxc!4L TX.tt%ɼ/|p*`_Bԃ6WĔ29mޏ˳~~@gVʡw$G eRL:qaaeEt~_[G$X(wm9Q"*kV ?ֵ#)fKNx3˝d(yu9};ğe|#uڎNV7v>2YeMk(n+ 5 ;T}uƝZ7^Cnܲ5tP8Z;S}\ziwr `(w4ŚHkf%WCa*V!>,a[U*1%m:b\R -T B:5;z8}R#9ϔD$Jab]H#"};\,7&8[E%х:I,!<^=I_7_0W|pA__1|߂AJ{fnjByUcXIq(S7kk/RY8+ϙ'Di3ڜξq3ќnl1Y۫WK\jbB]{ LMZ"B<}tl8VLF L>" {OnZ=ɎAb 3 K`}q"S%k'G(gq^k AD@%Mg"eCJHmj =Nr{zU gU)Wzz+\"O0QڸzSa$w~;&ۈ b!`qvW܏1g1wD)yA]Z69%dF6af0cm.!m16g)rXW`}uR|9U%OO"'Zy^ 6J "HrǴa# a6 Cl<8nTng ئ=-4FhC;&}u"C1e*M^վX%k#ep$@a%akErZױ}#{>3 t1ӱl9F*Ҏu,ZlЦv8+@^N#\l~l+0 $T '}X @DP0P+!z-LF۩dl[$Iܲ]5^ V8sdAX-_{Y}^7k)wPUl'ha]4e~fuB`Ρx7 VqTYpUpӭzᨮ<8#cԍêKkm:}"%AxÉ+U\qγTM&CZ]\h'H_CJ'{zT;B3 s&Xďco~wQ߻ π" K{ \( ?7hOmCburP AbD܈FC=%_yz#9im sJ\ow{Ls%U Ɩ9w *V ua>W~QU3M.a~J(;H ٰ@'Sq$Y ^pkCЌ81q+r-H0ZhI {v|M"PK]-X?<kFK+[fPz8f{ !(ϡFZbI7vnjPZ݄u*|LdO/۠MOd[bsu(w'G ]/ W{s'W,a U]D%f2AL#J߬*(bF"B\>\|.@k(7թ#$|[:Pk6'jFrc=Z Ee_xvevvMY`쮲nĘCQLoM9|E gߋy}*tK4&z8aO&888;&~DPMŔ r`q+S@ip߼vډl:Z?q֕BUк*r&}c[Ųt1G$| \œSlyDG¨ʉ{OO)rI9rvA0K3 *Mt ZiI[j;~7139Vom ʮ쮱b'L+=;y {)IPd:U`Lԟ7qS2cl5KokT'K\/Knz7,śQ"[=ೲ1UYݎE@mF"&[v#IZb0!ߑw%Z 1C|ɩנP3S^~,D ܹ+;t#D 0@M>uI"Yt [͠ N4f诀g6Y GjFaE\']a" {#* 9MbfEr Ș4ifk: 9rJbwS S̊emS3~ Tn`|L%$M6y\.Iͮ@̲,xV82&C dBoRYDt}OiRC쭒3lƄp6q#Z*:#-uw^qհQ'c#ܒaOb|dz`Kj^yu[ m$WWBBb-5>)gpLmmV%B$9٧Y\OieĞ]$ج΀G>K8KKڈ6Ov46H86Cv(^rDE|E[DS@tY/!@G_Rx@74$pjGz$!fҁ.F'34ln5< F;}6Y3/0'bCcISFJ|ND+D }.w3ޕW -cs2)[RNے?ğ*la&4&}.-ũa+|3UK$t AܓI[g'5ŒwM\o L˳4WFAn6P1׊[~msU=mQw3zW? z]szPkeLVgUo!dQʼn>hک>dg6 E:_ \ (kE3 .dF Se|<]W~ pr89[ 7$I =' (w_W7G$l[&6P#iM=Y`c/3i.13iP ,5*jvIE `zBžbs{f#Q)DJc*{肍 E"({.G&"PX7%.z 7NcD:|] Tۨ+ty` D-^ փݶDqܨ3H9 *CjȢSą0<]^idB]QMnR\KF\N {F8 G*(Z]ncɼV pݾPL o² TE/au5 랇^ GR#c=C+PiJj K ᯽B3E}q~.>#,kآ~Yzdsۚ}&uO^IZ-9uͳ]ς:Iq`gբ7!j'5'q5U/0rx.9RPկA1yo9O}!*F)a"nDz*l9H?=LROley,J_JOlN S;Bo?1B:I93N6C_HE3Pu3䈃 c>VuZ/xẠ"Nz=g0QсKcbNctCq1O,k3 v0ҼBe?I(X%@3PAxE ӢĀPZxA$1Xj^>}#q5KP'QhQ7 VJ9rT3 LCIF!\ oM?wVYE]H$xg[FXe_,ٺ%=Ѷr##ORܨY,~~>YP2tQbƌʼLy:ʃ*U"Ӿ}у=Q!nxȚ=Ybs?Pv&-U}@]%d{u],؍C[~Q @~ qہ10,sj[[wCs 7{ޒ#$fEgñ0)t;#SySC2P}fFp)Ua|Z?X |}k\LM[Ou3䍥iJPeN(KmۛstNWQIAw1:]9vmrkEXtE|[SJgްce\=Q:v#œ9'N|MV(逬p 9+[KD7#xA=]&*&9͞Vi̍l}Hc{J'`@`pD_Q1e\h79cۼg%7rtBkb4#y#`/ 2> ȹ> ]KuRbEȊΒړvV9:f?<7\݊a}^@;9# VP}&HXqLUOQMv s=q"%H}9L (Dd $ V5U]Ժ?(7³Kԇ'(*;|a,>&aa$3kJ $ué\SJjtY,蟷Evlwr=Y9$CΓr}EC;(!7eg6*֘R],ƒ$Iw*;HC\R!5121K?LVR0hm]"?k 7M>B0X}LVԲu:3f%&]GZ4th u\5;ގe6c\XV#232'\k@).ǟ>;R| c9LH[b?pQ"3J\KK(9! Հ0N>U))i>4dba@+:KE߱e5[UTP#e"E_~yFǜKB)" e0"ԺEyCoSz}|ݹ@REO!4ЉPhwV4KgRx lwù.d0R*ӉR`WDI+Rm\L)P5ݣ՗:'r\ MvHx9J0zd9 Vw/HH!`N* Zjs}\cq ଲ4; V"$=-d9NmQWBlx1PV_|mPɆglY$)aZpq(3b Xܹ)R.i- 7e|W R|"l/(2|f]=*;խ? {ckc\GH~Dx=[lo\ŘVDc+8VBSI9<*ob6Qa+gRʛ-B|y>WJɿ/h{s_uҘx$ͺ׽N˦>ق0%+t?yXG~Й{񓪇2-/唌-KC K3::Gpi܋8E_rlۍz)gHOh0^nvg6{aT4ztؒ"Zie q^>Myw-|m&}kc <E+X:_-bv4)أDݷY46mN0 jGoIu7[no UIX]!u?ll8'Z(Ii#@5H\FEdN1%CwNsoi Ұfh ##qK -ūX'NQ&nm&/%:&ț#{"gѥ(y1m|=v;AH!t"li*jGىS0Tv#x棼6#XoiitʬkQ<vuh5$duxח%WDS.Ob(d|((ka/#B/c$JU̮WxƇCP"_]; ?okH>R8Cf9`4Z.^9dԴ־}>/E2#U+Ba㖯><'6k,| Cf LϤ lu4,ݶyS bW3?pəv!t#_Sv͂ Ȭô"<#fI: I6Fv{O*LK+́f's1s R'9>Y@ z#)Wm>wd6bavB=_] qSfuKHedNa %RADƇ!Q`Y}ܛё+DdŕTL;lkf.C6 Ts';#6Qwx=͘`,02lвƂ|6Cf2O[>ҟ٩ݵ +gC)[!7R'kQiv}*TeHM4x$%1:\h̫jlanWCd2RծܺR4BkCx3qpA]ΫF ]6w|%Xp]% Bl4Y5ndSnh@%]9ݙTr n폌겓&#R'!q 3q4z'~ˆYj80aӬZVڧWK5ٺQss.3vX% Q rUe,}ܷz ?oNڐץ AΉeO% rR40S2C ~=%^J(IRcAr$*I0zN.sܰ"92L~ZMtlUi6R٨m@*lY/xM4LO4Fguلh୩smKEQ{)Qrg] W|H/&z0r+#>Y8osZ PeAD>*aiW3Z  Bcj'1"DY\BYU?^<#Iߖi=5SY$ۂzOp\G◢yfeۄa4tyOʤN\1ϲYIo{햹`)/Ït }>뿚_x&T|ɥ"9͙ZK˃}Ђf/4Bv]bd^Sd]K3%UŌy 1"h^}nQ,ytoSC17*D&pڛPOU2!YDL>b(O_uctni: *놪pg eskL4I+r2H6rY]B ϫ2_DPޯ@])1eokuֆ6mTҪbe 8X0:9e$WԸC Tzk+dDfbC=B E rrlh`=dxl_I1dQu6HM{odWH ШWy sI ?s֮uE~jN[{9E/d6!Uov"c?]"T$wV&3oJ"KK^pt܀CV?N΍@ߊ"&6.x,h@|`.! /Q50P &閤Mn_O`nF "2φ-*iqeSS?gl8O.)cAAEFXŘfCuD+ IS%.`R o,rΤK`tsdB;xd:xR:uˡ{ ~gm(;ܼ5&G|3MՁ?ejtsRoSIhR \oC(@Q=qQ]n%ov2I] ;˅Kn/g7, 4LAty U߿Pn@q},DN>ZeSB'@*|3(2  |+i~o}rߨ5 |Nb+_` v́Uw-+HP5615?Z?Hb3 5/En ۞;3B,O#/ y}{v1eX;D]fobCTѬEBA'k[be5SaKq^Uf0@4bvNIwE¨!aS U'=lVn1)OЬʔQɅc$hٕг0`[Y?!bCqv0w)pbR.¨lE'=LVR3Eج "=>9٥_-Mc7t u.p}yP}!&s|nB~=Eecs&&tХ)^ ) #ok'۠-#0-N$\j6A'I,H'IWyCFAAl0pmd C[NA VDa`-tktAx?۴h`H_mrȋϭ񟎅YdvP{n[y<,?WgugwkT; OF 毮YF~`sS2 ryɟCkjΧ釳@.bG3=}qRLb*)L7 [%rV1#.z>N߂00o Kuqyrcyٹ~%z[Vyˀ't Lez@2 YeS$Zo2,̯3>K:,'G%Ip.:t^v./lL^Z"? A8=h鼿,k-yp 2͋UZٓ&LR_Hܻ⭭k*^D'ӕu,G" aAj? U l֜Zc=J!K½nȉFɶ, #K:1G6՟F*=K0Gch ui`i:'E*+a.CQ1֫c{H!/Z 6r-ȯ>EYn"̌M Y. Xa+ʌjXI])*'mz!f~i;W/ vH`n|@w#7 1ɪrA+ q $JXٓJ*Zs4a#m M l>CV<Ⱦx/)SkھB2H§oHE\Gkt^ , Ts̘eUgRHZ=DUgs?O/%cաq[T+̥Zk2xhv|[D` ІmLuNP=,(&J G߅B7U'?l!F;:V! /bq!E xIZ]\v6^qOY*/9i#Nxt9iwunsͶY{bF13ͱd~[$F&C:G%Yo`j$jku-(eaԖuwDxӂ#1/NRYYIi&1024+S)x]BEnю(.E` wBZ )=* 0wУO6!;`NUEa?Y`bzI}D+lH(S]QUKɮb{l6קfj_AԗKrTzP<}2a?X.V׶Le/SڵZ} 'E{gfmF. T>!6;603}2{|t?AAa ɧw?xc(>&/ <==~D#RKV-u:Rzz=&Y1oNڻ70x:mk5`"gLo0cJh;P&4p*g Q\-HZՉqw@r iRtD)&󒙮g&~n fLDw 9(: vv At+c;r&(51N0GC7U?-:4FPf_#D'9[4ŅGݼqWۜK((}}~Y<Ȓ&T4Y21AMzlzc9VPȖ @Sv`W#O\z}PL=$GHƤ-1Y!gj&Nm6I>~qr'^$Udf'j5 Ep9o8e˹mHp-NH}ʢR nvu++8f6I= BDi YOÝ5}VO$Ȝ\v2P0QCCN4?un8@MOw:PO>lG9vP|joSHs1$H%P&p7vYI`&N'g_a mߝlVeKj6r=^ $m2 Bl\nسJd0#3z2I {"l6.s\4u69gR>iDN>U qɜV1+Q*a6G^`N+TjƳ#K9'2wRRNasϹ (ܠodPf_,Ylw#I=P ?(nPJ<&kz;~ixj1 ?3kNuOAUԅEhN~bΈXX0 xunipLf}O~y:jiKX?\b8re)3`]6t4\pMlhw1K# ŹiQL@Y[:A80YmDmTyAŌ1!__a+Xܢ, Ol E%z3# ?,> %5] ~V< wUU F$MA}ҨWnnkTln**@^ GJ|ELIbb7znu興4O]Ìtlia*XPѦb~H=Aߐַ(ϻ6'ъ`ՉH3t#!X5T3O!n[.֤xgw(}⥁ [VHdA(=IJ]QgLfQ ns5תR\'XAq7Ԧ)PiϢrI[O*Lne2^BIK0'Kƥx2aA]j(Y}9+RYҵ;_ġqmO+g0D"ۏI69'ke*6g#L\G_2\B[BE!ř丱Eo&woOM`_ 3P2މ@[߾/uaSkCz^O6 ^9"'wҍ ZZɩP+ߩB&g+EN> k!Ubo1oBj=|( +YIb6mlu3\nYHA-e3d OHu^}|] ŐCgz! ap\nܿAQr{OHciZܗCgL?Y,Ĩwƃi {m Ω,MC1pP^drM[DloNj7񦼃;Ζ_lCqF:кQ.V2Bja'Q.rG3pd=Tk!~|K~A*eQ@8ŵ | P}1;c zJoRSLfy|>\DD#owr:J[Zm;6p00mQF0HKL-\2$Եb5ð؉ṩ~ۼ $аN.yr/I49^CNwfX$WvaeI=JaJ~kyy㱓;YfZraBIZ6l8k"'_NE峷 o.jqm%8;JB/ &eRK/'͒mWXf"5;#S"Yۆ۴YKƘz z 1n+ֳ!:{;D䎺r,V ' "q:vhk\ E_+=$]NaFnm`uAhXp{("K/n2l;5!:'a4CƝ|HοdzIW%88v$-[N5y< J XEגc<t+u3l'a%Vo_Q9 iD "ED3,"?4zA9`T*su^(霄Ĺ-FJ7hxqI/*~bB6@FvNAǣcoJZ$߯Sz'ɅwYvA T+VxAiOԇT; Y=-,ZH!v*l;秉zCl`5Te }`-l80wΟjb̵}*[;2(0OC b ѩ1ٕt= X'?m31嚝7/+r}y#\-@Y1 t(n=s79O{shII+Ќ=ݛ?F9vJƪ/u*yocSfZuv@9'K{lɗ Xi{ GI&D iӗ;@I>QWZ,r` _fQ\ VBuR*yn|k&z>Z*3#q;*(e 5ɲrnͭon?&H~3!ȿf2$9q5 Ԍρre@(*lsgdَA 3 @scxWI ۴SғB EBmhK)Jx-rۿk\ݍX;yW)'^yaYAһ0q MDzľ5kQ]G:%"DSnڰtqVPXHmnvk἞n55P oH~Z= {(U ȱvg R¶$tmXF}@ނvYvuiʂ/t>7?U(X+C?z& vIZ#Ʀ ֨-eIK*֔XPſ5VHeDqO#Dk9_ˌ QK MH;6U-P*2[,b Iy6wn ΦBES(5yt#òIGd̠sYu%JՈFNiap%V M#BeI cX+ak^ss'{=bl$'nm V@N@Y–EUל*QSxe#e~tҥ*NXf̝6GG2b+\i>_W|h-^\3~5c;\ jG"@P K1K34&sxwF5G9S@V$ @~KHĐ1ӛF5kP INQfI,fԻ$>X?wnqzQlɧR\yiQ̲/$蠠FCd&<$} Bd#)QbtkAf(B8X-\Tt؍z \7 kGs12]aE=,ܟ4z`kScˤ~`F=oa篂>MIn'̚DE+lGy@6snF3>Չe[e{!3!Xƹ/~LΟ1O3@amϬWx:{sE%q9-RF0XA HZn+7[8KW5֤mtD(+`[xG&ss42^y}JĔ{x A5[W?iFJAW(`Ǽ߶̨|ݔSYls#> |gDDK<B˨ݒ mqْ8:a}ֹ6qOߚ;j&tvﷁ#h:73h1ֱ;LԘ8},qv{JaװM̐7}f[MTMg۲ [qba!Mv++4Ą`HP 1_M] fB!xYnesnC],`~HQ+"%*`RZh1,8~xzL9I&\ nؔ{1>Y8pc{B'"CJ< ~3h>>b>eg,B񾌏q2p]C{xo(˛b\ |8?o"M݅:Cq>Wݪcwo h}OtM;?_z8ME747vc͍K(q#*G~t}hXKgQMͿ@C]xgni}M׆xU%VB vF=L:yO}iGl<5&21 ZMd@xL"l56zp_R1̜5."8ի *u& 2l-5K|O^/jcMHgōv *-8:pZyQ&s%r^+1w𘡅ə $ 紇kN \_$m QS5 Khᨷi~=b oUlSC*3wAJػAh0@Q05ySxX|6!~hRo,Bf(Wu|).9w 3c)6:t xDaNLh9nFN耹Wh[˲!6(@K6eW Qf95,Fe"QrmZpqMv< IpYŇyf_PtPM |5ʣd(WxKc"pi6qT^>+SenJc /&-:vԑ"\wVçˀG\@ЮՐ2-&1ӎ "=ҮW ~^nvcGdٖ/=@6 δWb@Yļ=CU )LgWCWwzĒb'[I(}kep4l}]pO)ubmD{ߗ.%.]}wr`rlNwګx8&3DgntU^!ȷ0"Yݖ=&ˌ+.G-NJ[X̑ AnkmƺĪ$)Ёe{(Q@oZAʏrR2ldQiRz๴GcE457CBS !9 GqvX AdZԀi; iP(Y#{xx=$x}XGWGy@LsF^GC_Rѻg;y)V:U:~u u=n \Th,/+OAhQQ8c$vFhȏFC[AX1F!pHג656ft8(%ugN|Tj1IÇ^5^M)wbB' Ksnk5cPnmF%񦷚d0)R2Ƃ*kL$}&k94H>ֺ:,: I\#(ߛ,}:WT]:xKu4F ?,W9%R?N_:}r}o(Lj0 .|@rZ*dy .A/ܿm53d;z9O9 Ɉ~wZiv,Jov2OK2![ c.>m'I`v?VLbٗ"\86ym GWHO֓Hӆo:BM :7A!* JgN6޼UGz@ 9ٲ85@8W*|fR\ ZҞABbN~e| aiaV@HaDQtI.9b[B+igoB}FSI A6 9l7<=6 I-/bq NB21!bNoW8-][~΋:6XIjP5B\|`uc".-ѵn ݕS},s`޻iw:E,ۼUcmv=M\byLHEGq Y)߅`_\+EMpͩmQzH%2}o fx('&ƘV㾍=x4So 1X~-rZ"qJD>FP#PYO!44kI1Aw@dk[@s&R3hJizICV%Ϳ `G(][1{Z`/Opճv_J.3 7{fOf~h;ʒWh/cL(`küTd 0/0gp_OxtyC4*XHAc]XdHw"wpF!MP;g|6G+'qm\5bvΰ=tZ>I_d&'ر)\tØo2B8=<-X/hўAxXNp44R`_0Ed_ꐄZN|o&Tzqa&پDu5Ya0Pu]HM /c躧˵^bU'LDr˷|YQ#d Ĕƥ\>7P-v?'MujloZ75'F#%x9ٸ%>RI~l˥]a I t W(WoDOq` s+v4u$;c_У9(~5،YgJ1{QK~DkP)q⡽m];\g*N?LQ@: ]QvԆiDvy"Ђ): K/''ŏJTpSc}at$~>k>)М6+6)$~ҪW1p@fzuFX349J Ԯ$LD;_8v*9:6f T7AKÎsLIlj6iyVNh@4=`~hDCQ?0}!7׾g6K{ SiEFաK( 3?5Ѓ"L9"+a"j&CrOxui2^, ݂-gL:ӗ=Ϧ#L G٩zvx *;~fc O}v=Ǥ>€&.14&S%E$ 7&=nDK6ߙ,@*'TB[ZѠ#.(f {~^5[QƽgzU[O(3r(:\Qp%kI\Ƕ4G!.sd[ZlXw #&2r?w p⶿9*b`OusLi[,Qp*ݵ5] f,*f`Z@'`&S= :'A5ZxUqc?b:嶷tET ob#: kX8u˘T?;n=9Y:)ϽjiL$KHiX>[YZrͻgwY0½3_kə JlcٝcQ&{+1=Z ݶ`*Wq6te_ y?(ZȆ5R*]df9[HhP3lw߆=d7$0r,X27==#s>ʲ:u~x0pNMA{1ZЮTGo{R/K*AqCt0,k\mk_Ӷ{|-0 A6vyWg KR;pV8F +)9iHamX{Q6y;1+Vlr% |D}ܿzTMg"3 R/HmVJ\f" HOYs899B[F'F;ՠjN5^ J'l1ٴu|hD1e;|#|3Z/$ !-ݼXr(_=5ScOL%`&a/_Bê`x") '愹C>(bӹߡH>oFtinܓ%J ~cnQ8swB*y2Ҭ̓| CB%?yt -Y%~c/I1ywz~8ߋd{X+X,.gOmkLΥ7́RA:d2 q !LH-Ɓ.jBuhCL]sSO }&dUO,f/%39O« ڤ/9pC/cP M)'6jcXOg½.dt>+hv#laR }ϯ b5͍2A0ӲְyȦ/й#89 5P9D!|(K=^w>'G9­)~;:K6 h4+\գ1&i7 P ]v->ne>!NkQ0*O'8gJ&c~2 G^a $Q߿OQ,\iP*b!]yJACׁw]Z:s/[X3r5^ [7[egR$Jq|'a [ ]m!$eL #~)eZT 4Y>[ T֢= n<ѓCD[;Cg N<} ;w i16Ɯ9MSvlڞܸ(`VGm#Wՙ(C,'SHV?\h0].zcIlm`-ԇIHv\@n>͗`z/{$djSdtTSwPf4P4.xFqS ?̼h]O>.-RzV1L?"ݫƉ"deiWZP;P1U0,S.ߴtuL`0Di9D^tRRM>[Z)+&=P~׮\ŠA1oK>dJjTUɻl( RЂ_e1ggjҧDЌw+5qQ$w|06h5A] '+2#.Xn)˵KZƍ 4`ϣWlBgR%]-:!yyMBNtJ@|L91JL5iv %jG4%ϽCrnaF'`eW_ (7i 8LמL}-~ݸ?؈u$(=S޳èW?p#AC-hIMS<ۃ쓏jT[~hcf!5Y2)6wD#c`̋Gŧ#i2Gέ!l]3" ` X@A .a/~׿:l6&5u2]>v3MU5iᨾ2ktt,嫁uMvL @ C³ndjs 䇞ڒy[gߜ?j2g'DU2M7!^g-OΉʁ+)>s܅H$ w Lkэϫ)N3K8W{YFP:v 37_Xsn P\<̓8fmH̓2-=|C~? R9\ @t_S,$U*H4I*XzpN[{gb$G+\nގەᓍZno,E!waj6~\W#]3HKiHV{z;V=ɎN$(>z.}o $]lTX0RZ;%!G;zsnH#cO&w;j28U JО /5'IFU>Ƀ(ZCnfnJs#R[ F#k3avN&Y"6s )o6Ԁ}ַ@1\^/W6>T:~f1K"Vo@zbˤjY` _q1SCidi#~FBecM/W|aT onR}962eگY#CαhSQO\gbnofZWOm-8[KuIӨ|*[6 |ł2YX >K=> ϛBTmm%/W-46h3{ {ȩBdq8_%a^y5X1J$uKֺ?5$x).р '݇G=yRRɫG t՞zF -;{ MYn"%۠Fuƣ,Drlxf5]O p [CUo-_C~6sͧ\\wjs07gNMހ g[:"ϝΧniIȿbULe"Dpz=~sU cgdi^_mHi,e3?~čZ%yJ"Q򙔈Q!sD#V8 VsW}T傶ܣ uv%|_h!(#C!¢vyZ{{r K[蟗B+|21_)c,hWy]}S>1s֚kWߑR~ȁBADZ 7f$ ]EƝTjyH`B)}E :t*]b`r?;W=_jH{I 'e$l#jVy)3>^@fzm I(N9Ca'-%Ϩ])@ޥ%FVܘy|]Qf g(ps?Tڃ W{7ۮ!EN=z9YXccSzt(-ԺL!5xkCbTпUFywBSqj̢D .M(N1_M=x-lD9;|PU^g߶Tbğ8hkXg.%)>)"WX˴Ť 6TWvSVCKF*SnC*!WߑDiJ/_ 2xtSqLFЊX>QfP`]_qsA79}4~c0B̌CxF9=^|noB~Ty^hlL}/UFY8,k,m8L8T톆DѠz iO=} ?x>vФ+{#ܒe (b m>dO#rbTpIGU VbU.4lНqZ_[di~#CHXH|;7'aÉ^j7#nQ{q9Tmyazr;O? LU KFMPW摻E;PF }^n`*_jyȌˌ|j'3 G3ؚ_d9TIh%>Ѭv2z5%=L=7&{pw3f$ cHꓐeIO_ ($׎G;]Zi)yP:59V͌(sfjys5ؾL$C,r>ۮɮk^p ^O@(NR=X8,i <5dAE;Hsu䮙u$uvFWRf9܆e20_lxߣq#,N[Ļ~V1NV\7C~s3|:@GM+Ycu_Fah!_r|'79PIɆ!+^걥WXz/n0%0KJ!nd3#:x3@b=2:H(q9X ! oPrE"[%1eCkOhyi*j-\gq[ts(H x4m$2\]Te1<;38ʳr@Gmc! ]\rO4 <~W߅$w/)ӧaXNˇK^J-[C 筯c Z=9c Ob.|,\Yj ,}$ٓRQ*QpfĿg>a%18YWӤ H)t m l:2o! 2F~WpQ rt4$;Ί1kКQݮgg g 4D:^cO1߆pڝZ(~pFCd5&8B_^G٩Ώ:T[B 0Tm߲N1 ы ǝRҒˉC׵ێHqਫ਼ޚU嗀$ Snj=Ex"!ewH맳׺^.!`}Qpalq"0$%tޡf `WkVU(W sYu. @2[%qxO/5:YX{R?"ݜ]a|*IhΎPD ɇB7BJНW/0d*Tj3Rwl|x Kw p4AT ɦ}gj۫j4FQ6n7vZjώ^8'SS(DڹwU]~A; Ye= =U&k_gv w{#p:ae6[R.DRZxpʸTboѹn̋NUM5^P幣; 3n1b.>oߢY]xp{CX&߾rrTهх?X_[8`y!F>·B +ك;*m-wE)-k?(jztv>E.!V/&y^y̷!MA1-5a^Y a0`b@(1\ĺߨzL5.aFXx18&N;zuHA?'[j)f`,1/ {7Z'tɱ`vɴ%.,&sƔ5θL Dp'3Чu#aR|';:: xӁxjv EoȾ8T2mY(5ޒH*+62z!w $8Exr_2$e] P_ֈx(ԠfQ< n(vԸQj-If;l)$%EC2 ̸So7[|Xqe+i"& (xfZ޶ٙ~ެ|/܂~]7U6-F/0z"Uo}+Gt B2 dS%d<`5áˢ(\O@{s qv*,ndpݎak!=O8 -e / q|ZWVHZ^:|DU-{CH0L_PE%f#)tHEVJ*O $Eh靴[<1%WWW&˧b_̡}ڳ/dx} ܨ\oRʂ݌@;ǂG'Iw$U]{NV$G C`HTEchokhR z4|z]8G D&nӒX$jz3ߎ+J84:qDҿs"8oQ봈\>+7{VT)|Fgܩ*=.^\E߷c8֓Q>`* V@G>J?owQ>MQZЪbqN(Ծ,ܧ;P_RC4p֌Yضӗ]yy4 H֯W:歅ܘRyp-ď'eӍ ]^ `؊M򄹏_>v˳P,,:I`\nrwNd ]H'4mTj򔆜4 bwO>+r̻ʼX5@`vGa:5#@"f>Gn{"Y#-$#i/XN77K8Iq?ey*ЦޭbVFsG|XX. Vgm' , Lf70Qb!e7sFUȎ |ij 8=i3j[؂~ă9~X@nFr8,P_rWP]Uq vAw@FCP GO-?P }+ xEIm`p_\TDc[ ^LB}6f/.Y= Vu6{\e+Sy`民w;,k&RRQl6<kaWPhE-溒lEz  DM:F*ϓ /庻[K -Z TYP!R}Mdt)v D_uhUϾgSSWUvyg"MME6қXPP,4sq};CR&ZKHd a58dkLeMElTbϡB#8ĵ= =I \QU@3y iV1{-*AΒ*16dM<5+d?L{nLR Sy, 7?oGdÂ:);iIj9)xe{1ee+!anOZ^V=IDRٲQOV^~Q衧js$`7p*ҋjLgճyl¦ҡһyMid4Es|r=IHF@ҧ!_}K!ED>l I\5=I-|#/!{L6{5N_$CLbt[Zi6Y6;W2,zz[D ë%3 y/<,WƇU3|v']%l y|9`(3E=ъSi~ ^Iӯ9ӣ$%*b.ط>?x{,ސ2~T7&J{]xuT}3=RFHlOsgf6e&bZ C3g*pVZL3K-3LS>Kj+!O~ݸt7WX֥7t䯥.iBɛ,VclVLtzP bq:Dhivl+NehW?;_[RI9.&aDB!|xV+îszT¤k5`Qq]`1fFU%mU l/yc0cYlгXmJkd rfelE=:< p%3uf!zJWi"CX7tߢRKM\Dx4]?GP!*.ؾ MlޖGuY'fd%3!dPzVo~]̣'m>q$10QTO b0ֵU<@Jvs F@J"䰾h=IĹa-KMh%?#1"lծq4?ƅ{LQ@D,3x+9 l*6^,>-Q3jZx?J5mR_Vc5#L`0l͗+cY*4둟>vxz2pc+LN,f߬Ne!KhZϋK>@hɯVRUS@'zx{_hډ}vE9\| 3P%6]0Swb!E˜ҟ5 !x[W)lGjY8gI[pa#FT)/,wgs="@ۛ(ZsͰog|_p4}p07gQ` a'*^-W.7p ^ ~ q Ku_B7{Vd} .p2shWv% T}oZRJ+})ȟqda>:g$kRu7p)ot(c"<$ϱ`UմUtb&rT8C|vJ<ĉ#8B`aݕ8"-O7?M߹'")Sd .ycNgeuhKcUt)]9N/sz%*ePJlU RE pztԚ1󑦔L',\ Z]یM1Pky6WIn)]!FZJW7+)L/+^lN$730r ݶruxl:4DO>h"8ONo77b:|k{]jd8~(XdѺBO:8 > JeGQ<)1>f<4ټݳ^GՔEm =F.yDaux,=%1O]N-,\A1zBa8q@[PV u)fkU Vq]M"wS=V ҝ Eo5aN#$_VKK?T.1 O$uH&a"yifA&;Tϐz@l Ygdu#ZL|#Y?mZ<-;aTߢFΒf3 9^o eTQ y Oqe5C"QvS] 376ur~g@/=q2:2}ifM螠]M 9+P_L_Ra^meA50!(؀hVLvR] uv(4z\lˌ%oeg O_)HcT-3A&IIiSn/ PvB,68N0ሻě~FذF 3pR#lDtF :-j@P^ wT[ ָʫVh`lI|ʫ ԭ`hx*ᛗm,ȴ*i "S]YrR\~iC=YeoI%!HJ -$už[O P28⪺meY\^-^ן: wC!lᗌJR7Ul-]a\Ϊ~xf);v_['@[wQzԀ{JKKp8gk%t\wgr:}5rg F1a[8\ȝGKATt?$mV2e g /|-A>(.k,T- ^D_K&Doה`; s06ɜ?=W|qgҰvް^*|RI.f%qL\j!I, 5ymjbZaɟ@*\Tߧ-18roO7$ T 788*4i|Ɣ֙T 8@%Q=)tTa3.?t̽ u#)a!9jW:V]p{eƯkT:iK/ɷ&?TKg6+ܡCl@MNᨾrzRExy+f (E[4NZۭ=Azɥ{Ʀ/xIle58 S |ZiE2"E1$fF.ުfm{6fvuקpѲm _AzYd[nsdݪ$Yy[@*l"?S:hnڠ:pV/eф>CYy?a?V5ȓj[SZq2C)~7~e} {RLiJe684}kv(d`H?&)$iɋ u r {Bw"e#68t8J'T}gGk?dfy%g/ל<88TNeGߌV$oR#"V1JA6qL\:aJ; VQm)*UV6GW/~/tG01<.& ).IH~S7NYO%E@E,_iȼ\n^'XB`J0} ˧ߗ>`{df !hd;ݻI7݀*'go0V\SI m -ҟQ9B ;Y8,4ZR 3٦}[5$tl${˲DBɢS5oGQT7OQ嶻!}cٱ;:3'Cg_ gCw@Y44F곇=wM(/YP+FSHv'F>/(?0f* c*w27 X8lגff9gQ5 W8.'H G_ )+֪ZM\eutP)/ۈLOfd 08={?a7c;U|2dQVL- =(P[@ofsHa/G Vf 1v]vCzm +ۺiHa(xΉC Ke4ThVU/~Gxj ;Q +zYS'wwmv7r x>O[ޚyz¹p9? 5=eƬCk|y-΂"/Y~hirA VJJk`3(=<#1JBqzJKOL6"OpJZ0XՆԇ5Ma; i`{eϊ5)d1^VK=>֟IIÉ7O1.Lt>oQ4d>/CuII侅8]i+ENR2.W n4-5lȖ[KiDN7Q$[ d;$| c]G0|*V5Ѱ ΊHa:bTa\ I)$A9yD_'ojtlJsʩ*&EC1w"yZ+?D;TDW /*h)ˢB_qcyDECDž99G H qWV$us_;}藘v%ȿ(Rs4x_@%i NdtsU3@ߌmlhYbr|e@E-1Wz[XS~3en'S#?Dբ[rYANjMQ Ri]Lܠ4JuB0{$@ 6?Sjuӥ'nن::Qo͆EYܽ Im]+.-5PW#3%WNT ,fn'r,a[7}l1ݓ+!43ƘP8p^pq3tfЇ/5 xӢu,(TK o"" ~ߨmꢰ"rK#[]̍Omq%Dd]rӺO=SkT*oĩY ,:c*A*?nk-TYߡݶ@y:'RIh" )Kd3 N} ZSy)r@w0疃^1\mH~>򩧠neW} \ز˿x~gv eCkNsS[DfjB*1 u g"|#:% %|swwW'څt( ܽ92THmVBOGRǰj༼x ÁdMVDhgL=#VՎ,:aSۀs=Bj%br@Qc5K^byw= nRRL2 ~` F^;:Vva;6{yeuqdcUt sFq?TN[:*hcxkejw :4I[]Vkm7\Mhɞ$+GJq(Ѽu4Kc\LG6=Q((fEC`ic he6H;2]UdrV=iRyEX0C'dQV#>Idvq3(tf#iu]~&ϙ =ȳM5E&}*!Qt*m$_.44HUTBXob]Rӻf87J&8plad)Oߛ.UN,zbS/uT8Z3$G`! nE\FCBpl&yȺ >JP>:5||ٮ@MUDDo0r\JK ia߱m.f:D*tMqo^0HbE'_G_Rc>)}OIiq, KKhC8s.2ۂr@6,K|af7p1ɝ-4©?^Q#*$VCd6Yo]y$;Q8I ZŤ/ QWP: 97BX/_FT=ϙTB5#򭱕_3 . ɸv6ҥȅNTkю#皗e`±Eز]ovzAmFW`bp[PUFjh smHJIƟ;e\4Lo%#n=qSwRk~e;uPCs[ ,>񻙹-|TBHz3'QJRݵ# quHP9Hul X/힇Q{vDXWw0/.o}馭`h?%1{%L&#xGRt? ޏWѡ- ր4հ:\Kϵ)f pԖU(| GǫtY rym&P;r%Soߕl2;dbc#S]34t}$>6|@N'WJjy~9ZP9PɎÀ1Q_'Yv O‘`U7(, »Wn?;o]‚c|ѝ,=},7sKF;|:IҴ`i?ęv2.m^Š>/\mg̭A+Nf^u+@, ͿjH|f| '0 KMjOXQHpIVb%\]״zkε*.Y]N ڙb+DrͰ}q'YYMb!zT*ArPq>#-07@NjaaQH&|h5p[4n0Kh^@cC g':WF~T~lPB 9@gc*.X(4@' ZӊȀEXb_BUIExaD{h4:g>#OMѯ) 9S_8Ҵ_KDy/q鍢[.woRY0&ڔ] comV[F)ѭu=Uc!٬O%#S-* [#a%͛`Q gnO<sHDLރV0݀QZ5חQl}pbljWvoI#EhG- 'j fr~JSW'WB[G8ď Τ`E]ZM R6 :svz HܫdN ^ jz8@l \j޶}O71l΃J8UR^RW% wBs֖љf$ 'X$6qn &Itae W*o*o;ќ"e8'P'B'`Ylo.pibF]3%,, Sc݌ qqn3*5;$mh28 J♖Y7Ҧlhm=\⦸<^6LP0SK /P71*N!Z?5\g6 DVY%o~yѐmȌF&N#yq(ÑޕMd{*/t9> Vv7ǂƖJd ϜMgBlve̯qiɤ@Yh`L4FԄB7cF_j , 3`U3C&0qib? f4mCtx&#1޸Ճz9 ZEqM2BmzA'ܩD2' aE.#B>'u6~b|`dJ>|\v@dx;Cgi^ȱd𽼑;lYg^6["#.FPid!h;÷ B5Rs\32lru iߡW Ԭcp@A@_8j@tNPHA2 GF$远[.HQSseGn:1mWՒG-+vևԽݩؘS[U2,^2Ÿ8z`i}SQ.ZjwfՎ}3m,FfJoeQaД\'XNvQƧjۨf`oS ߝ<%/ͱ55+@,%jCVhj' P1DT22,0-C]IY#/rS. JpgqȔLWmԯ(SePSKॕSߝv,(2:e'x:*/$d{G@ETy ee5C?ja/zlגDJΠcdk̓䟪[p(`3TYMLxMTwpl$չlSW!FzEYx=*3EK~OWn=`jc]7^؛MY8ʴ_;B-P\:3(o_[MNW3Iwgw\rkc缯}4Ū/=M^EM^ ?$}q|u~puu+k*2i#d^.>cܕy W<_!Y jC?De5]V X؟r_?-a?KwAmY{O4I|~|9֑߇b}#j%7adFɷ FAe5A/G hb`iKn՛~5ܥO_{ZmWʷv_1^(B =rXrじ P*Kbz:߲%f3v\e0`GMJ5xۓ1jI' 6[睾*BtuهBol,I핦Ǵx{jE=oLݱ9cf:G =%럪,D6`)?BV5^'rݢWvP8M;JcZ vR'蟍@![yGN"d5Ȃ NfL?lGr2?=Q;ZrSF x$bs Q)ܮ.1H_;v%< \|o7`2-ٕ<+‚sr &4PUwA<(H}NSZc[Zȶ7e(e|M7o2&h^.T:Cu:?^2zF$Fm.EP6ZDkw H 7J@s^[DR1(S=>CݎA=.k#*zeE4 ոP:Y CsfO3-f CyV{ntMpGޫͲ[#w朗,ܫ;eQ# {9anO+ISL")9 Cy`bT.3#azйzK̟"<*SssQ0aˎhU;W|@Y3Ve )8zOEZΠêFꍝ$-:+Yf\ɕ\czhό્kJ}g|@`#*dG*×P24t'XPWZ]RLcZ ZU&Y]5:I;'FWol-:j,l T;N_SdmG8y4'PQ_w+w#Gca H40ejZPm/Q"ԹZ\8pQZ[ uY@=4GSro~ đ$>[I^;ޝ<K;⠒hX[)ZuNKD۳9^MႍhD@+1;3vϛħ\۹>k&m#{O _4mRurR[=  -X"ax2?__L|}N rL,;p^&F{]wV(jLVg {"h2&n$hmYI+0`vc@!=4lԎձ-#1Lo"﷊uԧ"",вRO<(taQjQٳmM5nbFߡQB>P OܵI-M3ؓ{w^3({Ԫ a{gSBx?^X+u%2(j P gԛDu#A.,խkԅV{55=́_,0#>nlG^N8.'+SbTzSMU>JUix-Қ 0#U5?Ң:D5Ybe*f`W4YD[$yUT]GkMR'wU'ma/ǬZJVP*޷ ՂkodZzH$T!C8Jɤ d2c8#I伣R=i+x`tkoodzwM5 JkxL1!퇏{xӕmN@T^#Y\s zfWCNQ+1|n%Qs^.>kvx[{ʲ <)ܚʞ^8JW<7L kLTNJ;7QA{N$6o_M?oAy;qPq9SztL p47a`b! gu=k,8щFyxۃv%ROE( LM"aI&-=4.F#ݒ>~l*>S(wgl p_YΉ%Ml8!'\Jm9gʪ F;t/^:'p!pժ" 92LJG Q@ \NpB0!@o'#(&ǫPwj "L"[} ]`g ^3u+l(%n[\lx~~Y+F&qYtw#σ \D7s9f ӲHa`:J=];qs.szQ@;% 8ØTOI쫚ڠc]-<1NT /,nMdҚJМ-; oټta˂m_8p>l릖E C͢mDzM|ȈrzǑcSAgbM%Cip;bAIHtH NX}`?r&;"Y<&FY8}V 8s7uzX~\0WIz}w"xMRZ,K_b5R=BcSUYhLOxz(ͽWG5 >_6dxc'SPsHv:F)R'"C1!Z{}`ۡY蛿v2ձʊ -宽q )Ktz 82` l2u1)Y =?ȝrI1qPMx޳_fRUZx lX]iwsjLsD Uu#Am "[Aσx;lj%锅Jjxk(Qʅ.՞OqZz!i m'-ţ8ojX8G{QVw~Soh!xo!Aއ@x§]P?\(S o,hVp[|:;7mr>6 R[s5n-mZ2Fk|qnS ˣVԽr`]^gX$S!Wp1+_iktD{{/ϳ`(vp9jBDlp|Fxp츆q vP mXT 짬H/t@a{-l|0=)->"J.Qt.#s{;f"TSL:R^/Ѱ¯έCҔ:wcfHVץh } J|9;\TƊ~Liժ̵ov8,@_m3Z21T4yʿ9oD$Ab,7i޸U!khQSʱw#ba$ U0 Q9|6P_3krc7w"~2r1Tmay 9Eשv;?x`7 $dj ,Nks!Nւd#~Nm䒯,l4CnST]LlDf# Xx$͵Lд`Ye?O{X$"U{nѸ ]O٪Jk_vۉ @ڵ k*CT{|E4z-/BOC`L%v%cEZ<$q\Har"eS&jtLGGs 0"QHqVZIu.p86$t91md&sYqy-Nw+D^"֖'9n"hTzB# ϱ~4 ZO>b׍zM Wb]_ q`q =n/Y js":d/Xol fzڣ .(TSVef4p: eVĤ6݉C3EZޤvT[hǂ;1T hnwZ99$,yh#Zv_.ov0P~Gh"]';k=eG;41D3lz_ʠGpb5݀w"PvurZIM;!j#iy(y QRU:37_}*_W dB {Z_!#Хu qdL8αo0L:\yI$apcK5 YI΀|@xcr  gH2VW+m<%l~}\y.~IknIP*1jsDwm'P, ?xO}p>new@ >㜜E@%3{B'F:\:/H`mIqܞ }AOi0~53V;croB#>AMU ND'֚uܿ^Mf{ SisvJ,B9hVAOwkhh* r'ͣyd9q;#?|^$D.C$迋Cj| (o[xYIgU'e?j.ڇŹ~ȝkw€c+U? Ss;D&mߔ'qNb? ߻L+Zuz)Me+, a6ݹwfSЬq`aO.IK9u7 Wtp:WOrAW5ۄ/B$0FavΒ=/tK]m= +j߭.5)աDUӗ5̦1gae\_)B5({}|EXu0P(mB9ۼغ7rd$ѱK"J= s sAۚz0Qk<%(i LQk N*:Ul=z`|jP0*Yakp]5dRK< z;~VT/#[$3#O_9= U19%䜸Fkt(Y# U@}]Ӆ+Bf>NrQ1*Īt-(X*J.FKGQOI)}j< 0.^ruX\PǶN̓"4 ^I]xfoשṴ[sDߕm>37z{~"\H{s^5 =iR+`Ŵ)PU,r<d9y7`~*v)v$4NIc'ѫ,,h_.T g}PPlY<]~?-fjOHg~Ux̪>7aͳmR 4UTӴIB<\^87 _N. J]a{j^V !GB:v.hl#뒲47_,;6kc\^Sk;;(LPrߍtKF.cO^Мq71'̋QVg 4r`h(nbS#5hEw(:SDeCx)* h8I!H3ᢿJr8ΰBMDq~ӨRD'9-l1^1>10rnhL%U{@OnzԼRMΔ,4 T ë.Tc O&xÒhB֫ts63ճ8dc;rmiP؄i6d@fG7vn9Oa[UԓÆԬ L'[X0|=,#68ZRdR8y$dd"545)Р"qlAiاFuЕp5;=Qqw2Շ`pNKStZ4Ĺiy^Mp@;EKHFTALtցF<M"/\{Z<ėIgSpgbd$WXqDԚWߺxmoFͫ)K0W*rK|ıx`M[:C2)fOOfUCiZ&V :s;F#b[:LkÆ mW!bx"C`2ѻ2Hst&b3gQLurCd@,#[t_2βMQ-ΘjsVeR\ÁNB1;wmo= cԕ׽#0o9|gyQp SUfci"hn}*+KSj:hT [#D|i5dH^ʃD9> u>L_tYune#c:iHKS0 cǓ,tЗ`3tov{$1Mہ %Ch -[> _`#tx,jt$ 6!4<(얙D׮ m!WOְpO"ذ/t,*7a?Iguzo?J*^."Z1KS:/g<23'c>ژYK9uB q"kT(: H]'$FfN˜|0H% X ϖFJ 7!dȩ6MMK[-#> ჄEtJ'qM+&*ԧw)>a:{Dfy _w/ފcyQi ,# gjrw)NJw "pcK̑3êkfM6Zhಞ7:X((f2ٺij6%u킶]l+ЪS޸^`rc2FO2cffD? DvͩcUhS ij^[uv (RO6a›~G;aipX]*ژښ5`4] )hQ3/wmp%"yu)#e9^/2=K7kaEG hβPQԌrww1S!!9 ?]&/Ye4yD N{fJe?RKbf(YJ*G e^rSbsJl;SWlu!N<|D =׵XjFyJqPO!7ڱ-`I@7UD]>STwUFp!"诬 k-;*spR N"Y]G}a"l:D~$1ZQM8` Y t*L}=y `AזH荮%ؚ>KxɅ4$ 5&] JR<8pO au>ChO4 E tei13P7)A8&ųa:[ ( rJ( {%H&ɟ#ͼjLDxZ='uU珁R3v M=@t 7-*h=ux`7hZ3+VK He m봥Y7-CLu.;2{Wi4I8C3!y&Zj']R5xf+KW0\3y1)r"uYT"p*;9}-q1%C^4eҚ:sdXoǐx<@cR[d.\3>pu Hm|dh%1.qwVT Ydg.p 8ˇXqL (0{@B)iaѳPUIC5kHLD_Ds-ߝjS*1si{R^*CQʗT&W>X]Njž>1sRn?zdﺋ}4t|V)pj(k^GM>>1UJڀφEԢ1:S uƣMv0D 騷',EL I 턊_~[[K<&oJ .z4)G[C3%Yq?Iߖ8lnP=(O!!Ĭ4KQFwYb7[4Zp' HFtOZ9GS f+=֞,׃E˧۶XHA7Z2/)ȳw tÜJw_^* xms1"RUR O8ULU X6(Gg-ni3>-O@4#:uǭA ❥B/X4TI@[`)[42ɫ#. c6!|72O -??ţ*ȏZ7.vFg> aX'vUZMedz5K%۪m=wL|!Rxe$6?޻l}a -PoòqMHn ;rhZ|uQ9zӆ|cj\>ۨ6Qü$5^兕Ûq5݁t:K4a Ci'ösVܗqPngQacp| !V L d?oK)…KTW<B%!ѫU6.DƫX?nCalm/ |S&Ed CeX..`k \܊}2Yna#N{ P|eop5S=ب*ҵ,Z }"LoǼx8ԫ$*,˒%"ƥrɫr.5i֘Խ7q:r^2b;LFă~8)) ?\,>߿K~N꧹DP Jc}FFb6PNd \%#a>/+;5F"A;v]6 !PH W-rO"]Y rJC :xZ6)}Ԗ] J胠AJFa[g~]!e]4<tViPZ)9(mȯ+|iZ"#^M㱀=4P:D7σmAbtr"2+a8蟙aM1 f,/ʀ\31y9z f'/GXftbDOm%o 熑AZԂ3d D1}#@mVMB=aT5nNˍ'Xrgs;^ioNk61h/I  Qq$4O`NDJi@ọdgJDVZ.<H\a;}R(&HZ)jCB Z-WNWF7r=0geZ4(2Y^-#`?phĊYk;[ ҒNW9зeŃ%Gɖ"eC-_GP+%IPhC労fL,mPC&GsdJ.j&Es}juvT%KUixW/ F Wā({U!-jEduI{?JH]:\Dn7fAJ2D19?fA?/j}Ϧ2x9@IT+ANzt\hp2Zr"vN-:w۠hwA<ڮ7٦zO\[1y\ꋸn* b<%W˝87 IWQiBȇvOcwS;1ˍNCp0sѬ䷖|@1)ʸN.DPGNz=QHgIfGaċs_L4m|$V]mRW!fKUi@<VO!bWyߞxWӲVw7>Ⱦ0NWM,w:7`x. -Gں5B bK d-2;ު;H)!}ňăԙ+ɦ[j[=B.o*#*go 0 LLf8(. G6b>@RWvڤQDK6OMDV,dEp|tdTKKߘqM^A!;,7?Ĩ{ C:KݟYEN6nF6oN̥sSaal:@95U-k8)mC%.k$Fee[{AS"GK$!}\lby.jnyÐbdI]$шR^ z@4.Gπ#ZY 8ߣlbȱ&pV}r9i1 }ʍp_c=l7tb'~h>T2]6czwsmid [b6_>X>L+:#} U^rf7UޑD*@kdz||GzLd<~u 2N7h25[ڻV{-5l_8)K"1kI&h WTO(̦yULkw? j>Q0b3[dGkoHBtdU~V+|[&v FDxEh27t!rR(Yp"ul oB8S[i+D2Gy#4Mr~qm>aXdG}~_µiM.MN\-'F9 ̓Twt n%afdK[vŝc_K0D  ;ũWchzI,n |[TgF$vx{5aViUo?4iY )o$gV ?w!EģLZ h nOf˛z8q{?bU9s984˼m59+E|GH,wGA_0cPmRbq F[{_M E5j 9MpZN qHEp"2>tn^Z2)%P Uqiff oI)#ѣKFK"^U%*Y**Ҭ kA>+eBLЯl*;a7XWC 룚vʲhOc"#-ӄ vMߢ M- n @ZTSV+Z좰Xpuv.ei f>WtN,>(6wf:U6z瑍4 }JcB7ZFg `tG\"Xb#d;d2w% &yF6X岎 "^]@7 꽖s<"ԣ*!أ&.ojHj0x{N!P'bb#lWzϲ~CT ]'Ҹz+%/zk7Ѥ~ Dp[ӏx^K3I|̞Vk)m"\%420ppDW4#G܁ pfČ$Fo wK(Ini~yIyX|qZl-爯U9vPq]!YTwQ̦-)诳8/aĵbJ0<*e@W7?Pg($τ:#b}GDYHtMX&ϫ@:By\C=>LHsa)=P/2=a#}7L RҰL!6Y׏C-‘ p>j.LIO/ 7{ …,MAga05d(F`'gᤀ˺ioՍ*y/GU,+ 5Ajy~x_>̻oBkf>h,ѿMV͢B|sIϗSK>֊{k$,dB,MբHU*n2zj +i]F '% Y7}yAKaLCvgc]92r,J5B 5]P,cFX#R!^pRC|\3rh ~"ԤdQ_&aϵCb fq}*lwGL  bz*yx_?RNd(,KB\^شF˵+B<+n,OdH"uC W֐bO*T#X7[Ԟ~$SХdDѺ̓[aGLm9XqW#IxIş3F"rH]vp{4`kcE4 51\=GwxbAǝX%JP2(s$ WW!(wT1P]4 DbA\q7;0A2ÿ'lם5q:R ydYL0 <\6#[D]eD٣plj3ښ'q[}q,p#rH[)]7bzR:GZn-tAf<C6SKz쑹)}v!\"h/UuLpS|\m;٭B{{%,t$տߡ4|y sּ* N3\ډɿM}+O2Q7 d(IN FӛW.MsY^W56Dc_F:JCH\x0Q`OԟHrmY=ߝfUb QSM34DL%>z<4q!#_l_iרDbur$C؆<66c8辍{4gWpydI+G =THܖD|qӕz ]iDm*}[1>YvN3Bi}*ef:\nٓ@$2\,T>bAg:}".̇AEk95/8*%`n-)%mӅzNHBHv5b%p?ȞZUN[{C4}e[s(S9)ն*:"c_u3uc3^,증,W_ oye @~<`zòL׵גiur;"huF,? (o膦F!VwS1Y?u{R2"Mi@w BG`,_:}O6deJQ#iY\S‹6*kO!?uTd_<4MR$ y2or9S?,FZ{e@6;P#͗?Rq0&``@<ST'z5E׶Q@_ʰ&dilGz~N'DUN/~-43 UdR#twпj5J#W2+A8J?DʭHA]|E7Ue,gv=󼨪hsD%kɟA8x,+MvW_n1>߇"ìK;8f+T*|T'p_Vφ5m@8iA\AR:<+z Յ@Oc 18(w8cus4O3Fc],)J~~CB3fk|X\Y*˫{iU8sE&x yD`X * gm`=$^E/Ά3 8Z۫OJ:p`̈섵9ߗzåAVΡ!2}Gmik^F:;-$/-fhp4jZX.ڵ;x{H@V,{`ۋ?lXvvp V |>1Q|u:j6<}=Dn(Qם"HS8"RzhjL9' t;N\o&$|DXO7昫bg@I^0,6JlVVy SԑD( D!g"}G\|w)MUw5kw9@6j`*ҥ{^3ΛגٴhЙc#d cP4UK4ccINTz&UK wXv {zY~`qMfRZ\G ~ VӛѨ tXϥJ0)nvQ)^JFcXFz@hxW`/y6(*yIQ,xMyЏ(?FxsMFq`-NNKOB),.V AeA > ƚa}Wiz>qrPe.xDsCEWLtn H֑䕞i:~JIkYZ]5J}^Dvt!YQNfbn]p@Ն]h[o$`qlޑca^_W M-.]ڄˆZ+ 5pX3 YCa,AJZXqv#O~D6~\FzHփDL&J9<>K rČ4FU0/Fs<^m."A83 J#  WDȚSl٦P~8g2._Qs:=WMd>CI'491 ?tljP9:n B&YvKMR q[k7pB{޼EEtUpϚI:2ʹ+8GW|S@8徍+,͛>[oh/gT&X]BF:H'#9UB,/[JY'v7KbUHiZQ0`|R. fZKZR57hUh9X7*Aӳ[zB, D4 ~GYvr+~RK8 ZX #LK A+4t<~)ѓ#$oH={5|RX{Y4.,ASM،؀:4^ʚt|Q9laɯt-nɥ~P2 ~bKNwiW c!}>r$GrH<iwRkf\?mH~+2k g0;^%˚G\0 M\Jz8ԨxJo/Ck088uGA^~VY)qp{B,b]1჋ĵaRK!Y^CJ";?< Os%cTD?O ZסM(b*U1MSӣ!u3Ju-[ɉVn6d\6IњRd܉XgniJNrF)fhÆmzmEZ, ?=ƳdJþws)GSl! 벬N5!:8.ic:1ʒ (Wp.H;,cX;P#Nlyk$KkgzA SL8ˀ{,˴+^67`l?D5o"LUBY>}|Ǵӓ삒3/Ш!"!#i2vuH2X$tƂ;sՅ hKtt(YNݿt~Z5z!K3㰵?mKc:Zp9!M*xwZz(T/->T76#Oc:)iK-0#0G@$1蜝VAFO*n5>ǖp^{(= \ܒf}Q؍w))ٞB LW ٪}2j `ɂjB͆0[v'}6+C5eenu;o,Ļn-9] CsZX0s3* 0ƌʠ|d@/yK~СNNZeyGDhP~Y~$)SO N~5*9fNZ,>R;t%FHx6Odzbl3B11_fdwq=]6ʺc3@i͗3\b>v\}63DΉFi?'K ҫQSSܸJvccJRd}@Ĵ]W\X,XKqԒ>;4J=t?Mւ԰ ͝uz Um`y ^ub0t[/Wmp@`kt9E#[At fXxmf4xWilIA1͂Ⱦ&4{wZ9{18\ANj :Y1nGnS~ph 7~j^0orV⤘w`VMBG앬 *w&]MBBt{W0m }(_7oSU>}EhTJ+>fe%jMp>4~bD:Z[I_ /Q (`g5p<ц6֤1}ޜ+ERɠ$$mr9NuV4N՗+8+QB6mc+t͵ k/eo x1l.J|5rj 59Ut+ʪs@U \ ayx6>dސ[nhUlHBɰ%S#L=rH_r{o rYKFQLm֤\p]'GRxBnYEF`06AYB,'FL[ w7-6pRNE_,-r ;e;#,GT36Y"A[[\,EASq-,I^QTH;Яg>9bLu{ E&}ey6Zs`M&mT{_G_Xút.QQeDm\ڭؕc=kF!BbP(h|'fh≓)D}M58^lq`8@1;rz524?e`fid +rk3$Fĩxm Z&5Z#lVv.lW'>bg[ 9G$J{Z(ғ(_9>zJnw[ePYO)w"ȶ Հqr~"&}bN9 {HPJqEͦ?P)ے̃J9] ] 9޻AlhTFIHEkJ╱hzȞAWi`XB\uY╆FGa}F x*3f6[;aoE)GHmSf~<+ٍX~+&M,ڏah$5 Dy=!P ؖ'cv ;ozV~uzr)6tjFb9|n*ϨW:&iiOn'`d`=}1ςUb0LeA ɆWWn BKr!ςgKsoz.? 9}"M/s/,~FIE.7mFymoJ-8UYFh)MCH3L^iCLͨ ?h4'KpdGF(^xsjDkF'SF4# ȟVs,.k ̾cOwt:a‹*+!H:}< ǰR$h>xT2{mgŹ.v] >ێ]Ir3Ѥ/3O3%oIV-}1'C( SouS9 $ WT-&h&K_e@# pﻮ۞@v Yw ż5q_Czu'aFnD=d V %pkc/v5,U6uuFto3u$B%{*`!{.QB:{zTYk w۱ `9RIu̟Y`=xs+մV#c丏tÆqMPL5r~m^qt i -Tj'){|DI yhYU-&l+zwɃ$o1XL[njj@ߞ΢N>'8"I@Y_jn.섢" #3jnUiQcbrN$>͙r4pOkӮ`Qߩf(sN$a{rʱG@ZNφEwe+dPreLxV_\feXI%15[#X1$nxܚ(pXwV Tu4jcL¯hrZRa3=; eʝ#sxv2%cN:sy-;5A+Y~Ołs 6xkN.;[Kzk=ǭS31 R;$$W3֝$q\O|sK ৰb3BdUfmD7z?:SB,4N絨bWsc":y^Ҧ/ANQ '[d'+29xR«r2?:>]R)Swr%Rk?WSKR+j#\Ik3궅 B JXnƜ7Z5T8l1W~Stqィ:%-] 3w>:B=aPP\ՋFe~iuͰ'qYH"_Ef#!f">7p8X|4>脚P q "!β3 ^ g\ZECn]_!8MTQ8: *c6 VR[bH,Z]YJ];}fW] $gRo^XWaˊc 3~\#g%s+P%=|Z6We%Su~|0nT[co+o) B؞\C.Ashۢ Ş `T]~R<ۺ(Y0pc\2k\)1̤7AGDubZ&s \LMT:j_҉yl9*'Qu)\ja!D@DypXK0S%ӃVncK=nNwwHfTͱb7GxPc3~r^;B:\þnmƄRW1O4DZ>/jjlKäE$,G'[ُk ]n 6 @zX}n'o7gFV-nϗc +3Г7'$ӌR횧5&QCp\e5j+RV;CA@u j\P8h9inÿx#y)񣌯/S8ב"|9 0@^I#q9 kW`KDjy5ZaT~a4W|OJҳPa=z`CO9h>.-ƪgy96"jc\FkR:ĺ!b>;>ry6W eOA=ri>ֲIT>Ldo˵zMwAZX(h<,C uzd:>Y@#bw`kyC>UcR"K%f+=?~q$a$C*[v )GȜM|?Ҁ~'M|<{6oUa(p9q[W KPT4<{$ʗ^cN(`]  Мz9{V L4g1avXGࠃGKz+cv=iM伹"6s$ Q8@<Qӕ7֠T=O@੒,>DJMVl {x˶1EQhB6pq"3EToanX8?Gv.k!mϭF;[y\h8߬0-\N=h (n cײ&yp=ļfqW](bWҔ 1hV.i}n]LԲ#6I;b3CMTVG?@&33zY5it,D=:-;ǯRrŭ:yYI&a1f7 f8BVN \g k n{qݪM XRU2GL^ppӦU'p #bGDiӕkflq1#Ukޝ8v1 Xead(@!WL߽mÇ.I9žJ̠:v.(Ӆp[_|RCN ^{X>ܓwӋ N(/b ;%rpG. =Wb]~9LAЈ?Jhha C%Vʘ2\di/nN3]4C.NB{7X*)n?z hPNh%W2 q#uQV~ x?$fAda3QEqZ o`C{E WA/ ~]J [e|2Gl0m|<[M2]EYv-}3ͱ#"a_^^4Z0PAv?#tF«erk#et쩭?"Fm|[Pu½9#u61Kva-@r dJL|Oy Q=|9cݥfޤ!۽K\N6.Ag$Y[@Xn"v[菩A+Um8I(#/'vj|tg C9d F$HB,ǚBwi1ldxwVQAKgp7u$#>PVЋ15 )Hh{ugﮛ%\ 0MsfFw}ȼ\K4W23иk^ iT6rPr1k.*kh-wͩNh8A臈 =Xj)<[6c I=yG3X,sFܳDzn*cK(. RSh/BAG@4 OOp4U3w^XjJguX j/ YZ