ipa-client-3.0.0-51.el6.centos>t  DH_pX Fz"c]8FK1k}^<~CDΔ%!x C\Kf\I^~S} $3ΆUp Fҋ`g77Q[37C.kq{ڗHs+PD*nB%B;~r}}gF{jA47@uJENNBn S +p\yfQx c^ῌt BCad_1i䌼ZC櫶m7of*}L¯xܪhJFyfh#|8_>aUz|m9E F8̖o:RZ̽Ӛ)E3>k_vg(-_S% -c:w4|{df6Yo1FJp|}2 VK䥠rҍ8)00=a&,W8i֝,\(q6gaQt%扊̦PMq 3t*yòWvɓ#g5qv߇&غ`_)Hڪ܅I,))a7d7316a9429d7a8fc73dd2ecf6f9ab32cab9cddZhX FǟQ+pzkf*ůaqI-GAxe* g:ot:6a@^-Rt*MFc!(EM&z Xl\p߇Bj6a#`S=%)nnEؗ́ugWlaT`` F>j>xCdX2._MI2 \ d&ϹяJ8rdAs7 E8%psGhT!yVGw$>7?d  ! G .4;"P" " " `"  "  ","""(H222(w89x:<]>B'GH"H"IX"X|YZ[\"]P"^1 b:deflCipa-client3.0.051.el6.centosIPA authentication for use on clientsIPA is an integrated solution to provide centrally managed Identity (machine, user, virtual machines, groups, authentication credentials), Policy (configuration settings, access control information) and Audit (events, logs, analysis thereof). If your network uses IPA for authentication, this package should be installed on every client machine.Xhc1bm.rdu2.centos.orgCentOSGPLv3+CentOS BuildSystem System Environment/Basehttp://www.freeipa.org/linuxx86_64if [ $1 -gt 1 ] ; then # Has the client been configured? restore=0 test -f '/var/lib/ipa-client/sysrestore/sysrestore.index' && restore=$(wc -l '/var/lib/ipa-client/sysrestore/sysrestore.index' | awk '{print $1}') if [ -f '/etc/sssd/sssd.conf' -a $restore -ge 2 ]; then if ! egrep -q '/var/lib/sss/pubconf/krb5.include.d/' /etc/krb5.conf 2>/dev/null ; then echo "includedir /var/lib/sss/pubconf/krb5.include.d/" > /etc/krb5.conf.ipanew cat /etc/krb5.conf >> /etc/krb5.conf.ipanew mv -Z /etc/krb5.conf.ipanew /etc/krb5.conf /sbin/restorecon /etc/krb5.conf fi fi fi,H77I533GEln0+x8K!^ sA큤A큤AA큤AAXXXXXXXXXXXXXXXXXXXEPx#Px#Px#XXXXXXXXXXXX53c32f2a54177b1dc5ac0eb923104df528c1c194eb4bd42ce03c48a1417a1b212601d0792dee1ad0d0556b70219cae1720fe4583cdb6de2fb5cc8ba3e9dcd1852601d0792dee1ad0d0556b70219cae1720fe4583cdb6de2fb5cc8ba3e9dcd18529f937508a89718ba6cabb5479a56c360adc85feec8fd47e0351bef88324c2d49e1a56fe37fdf71bad1e1b93934b848e2097d5ed442c97626e864f46b77e2e039e1a56fe37fdf71bad1e1b93934b848e2097d5ed442c97626e864f46b77e2e03c8db0446ca00a1ba1801e184ebede3604f53fab83c52c3df148f065be479aa8f2a3d8501307a5dd6a0ef441679346fb9ad3b7c03af279293b86391b80d28d8622a3d8501307a5dd6a0ef441679346fb9ad3b7c03af279293b86391b80d28d8626ba1933e045ab24fcde2f32fbed310de486222447b3a46c176be1c073ddd19d4ab6767c179bd34aa4ff225cdd03f388672e11d9219e2cb342af307182e9aaa8fab6767c179bd34aa4ff225cdd03f388672e11d9219e2cb342af307182e9aaa8fbdad3cc3d875f94eb152736c133e6bcca16d178216a78c7ce6c1e747dbaf805cc10df4c0b0a7bc17b29ebbc80e8c6c6f5a9da11f1903e8cceb2567879ca8b514b1f2c2d38a0a42c14f72af80647150b4a05df6bb1a3bc3d0ef717702834416186866a471848fb0b513fc890b98be2fa0b36b04ccc025da214a76e4f76f68cf36cf354d8d9cf24b59fb82864283888f7627168d82154fb3648a8adc0f7885381a8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9038b3fa5a8ac636291c60ae3897cfd6e6be58104bf79788633feb81a13623e944a2378ae5f9d2bc73370af9c30cb96b70f5bf81e70f6a14ad259c22de2a1524a932f97e3e96810ba138d0930b42fb50505332ef42e918498567519dc30de119c1a787e1673160d1fd857404a93888915284067e7ea463160ec42a7c06e8b9a8e3c226ac7db51b406f7edf39c15194a18974e21de9d68d693de8f87c70602e789db0db0b5e0ae7d1d0781f9631c2d5676dac24161743fee5c9cf26a4d75272282c274fdb7c2a0b5a2a1b2a5c6e286d02a7156f1ea42ccbbdb28ebed7d24447bc73669e3a8e1a554e232005bfdfb521560361bc2c14fe7a65736c7a737223d35df0178429ac0705fbd23d714de234358fc70bab3d036efcfd60d0d7a55a1ebdd52070539b8a0b6a9af6f4c5b5aaf646e23524062a16d963854df1147613996a1f394rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootipa-3.0.0-51.el6.centos.src.rpmipa-clientipa-client(x86-64)      @@@@@@@@@@@@@@@@@@@@@@@@ ipa-pythonpython-ldapcyrus-sasl-gssapi(x86-64)ntpkrb5-workstationauthconfigpam_krb5wgetxmlrpc-csssdcertmongernss-toolsbind-utilsoddjob-mkhomedirpython-krbVlibsss_autofsautofsnfs-utilspolicycoreutilsrpmlib(VersionedDependencies)/bin/shrpmlib(PartialHardlinkSets)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libcom_err.so.2()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcurl.so.4()(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libsasl2.so.2()(64bit)libxmlrpc_client.so.3()(64bit)libxmlrpc.so.3()(64bit)libxmlrpc_util.so.3()(64bit)python(abi)rtld(GNU_HASH)/usr/bin/env/usr/bin/pythonrpmlib(PayloadIsXz)3.0.0-51.el6.centos1.16.24-1200.1840.el6_1.41.11.60.61-33.0.3-14.0.4-14.6.0-14.0-13.0.4-12.65.2-14.8.0XX lWu@W@W @VS@Vy;@VD@USA@O>A@N@N@NN@NNN^Nj@NNNNx@Nx@Ns:@N_sNI @M@M@MMy@MM@M@Mx@MMTM~@Mx@MfH@MdMU$MOMOMGMA^@M=iM6@M4/@M.@M.@M-M-M M@L!LfLNLdLLLzLe3La?@LD>@L#HL#HL@K/KՀ@KK@KKs@Kie@K`*KK@K @JJ@J@J@JJB@J{IIIm@I1Iq@IKIFFI9I1.Ih@IIP@H@HXHO@H-w@H HHH@G߮GGgGs@G@G@G@G}G}G}GG@GC@GkGDG<4G)G(n@G3G@GJF@FS@FFuF@Johnny Hughes - 3.0.0-51.el6Jan Cholasta - 3.0.0-51.el6Jan Cholasta - 3.0.0-50.el6.3Jan Cholasta - 3.0.0-50.el6.2Alexander Bokovoy - 3.0.0-50.el6.1Jan Cholasta - 3.0.0-50.el6Martin Basti - 3.0.0-49.el6Jan Cholasta - 3.0.0-48.el6Petr Vobornik - 3.0.0-47.el6Petr Vobornik - 3.0.0-46.el6Petr Vobornik - 3.0.0-45.el6Petr Vobornik - 3.0.0-44.el6Petr Vobornik - 3.0.0-43.el6Martin Kosek - 3.0.0-42.el6Martin Kosek - 3.0.0-41.el6Martin Kosek - 3.0.0-40.el6Martin Kosek - 3.0.0-39.el6Martin Kosek - 3.0.0-38.el6Martin Kosek - 3.0.0-37.el6Martin Kosek - 3.0.0-36.el6Martin Kosek - 3.0.0-35.el6Martin Kosek - 3.0.0-34.el6Martin Kosek - 3.0.0-33.el6Martin Kosek - 3.0.0-32.el6Martin Kosek - 3.0.0-31.el6Martin Kosek - 3.0.0-30.el6Martin Kosek - 3.0.0-29.el6Martin Kosek - 3.0.0-28.el6Martin Kosek - 3.0.0-27.el6Rob Crittenden - 3.0.0-26.el6Rob Crittenden - 3.0.0-25.el6Rob Crittenden - 3.0.0-24.el6Rob Crittenden - 3.0.0-23.el6Martin Kosek - 3.0.0-22.el6Rob Crittenden - 3.0.0-21.el6Rob Crittenden - 3.0.0-20.el6Martin Kosek - 3.0.0-19.el6Martin Kosek - 3.0.0-18.el6Martin Kosek - 3.0.0-17.el6Martin Kosek - 3.0.0-16.el6Rob Crittenden - 3.0.0-15.el6Rob Crittenden - 3.0.0-14.el6Rob Crittenden - 3.0.0-13.el6Rob Crittenden - 3.0.0-12.el6Rob Crittenden - 3.0.0-11.el6Rob Crittenden - 3.0.0-10.el6Rob Crittenden - 3.0.0-9.el6Rob Crittenden - 3.0.0-8.el6Rob Crittenden - 3.0.0-7.el6Rob Crittenden - 3.0.0-6.el6Rob Crittenden - 3.0.0-5.el6Alexander Bokovoy - 3.0.0-4.el6Rob Crittenden - 3.0.0-3.el6Rob Crittenden - 3.0.0-2.el6Rob Crittenden - 3.0.0-1.el6Rob Crittenden - 2.2.0-16.el6Rob Crittenden - 2.2.0-15.el6Rob Crittenden - 2.2.0-14.el6Rob Crittenden - 2.2.0-13.el6Rob Crittenden - 2.2.0-12.el6Rob Crittenden - 2.2.0-11.el6Rob Crittenden - 2.2.0-10.el6Rob Crittenden - 2.2.0-9.el6Rob Crittenden - 2.2.0-8.el6Rob Crittenden - 2.2.0-7.el6Rob Crittenden - 2.2.0-6.el6Rob Crittenden - 2.2.0-5.el6Rob Crittenden - 2.2.0-4.el6Rob Crittenden - 2.2.0-3.el6Rob Crittenden - 2.2.0-2.el6Rob Crittenden - 2.2.0-1.el6Rob Crittenden - 2.1.3-9.el6Rob Crittenden - 2.1.3-8.el6Rob Crittenden - 2.1.3-7.el6Rob Crittenden - 2.1.3-6.el6Rob Crittenden - 2.1.3-5.el6Rob Crittenden - 2.1.3-4.el6Rob Crittenden - 2.1.3-3.el6Rob Crittenden - 2.1.3-2.el6Rob Crittenden - 2.1.3-1.el6Rob Crittenden - 2.1.2-2.el6Rob Crittenden - 2.1.2-1.el6Rob Crittenden - 2.1.1-4.el6Rob Crittenden - 2.1.1-3.el6Rob Crittenden - 2.1.1-2.el6Rob Crittenden - 2.1.1-1.el6John Dennis - 2.1.0-1.el6Rob Crittenden - 2.0.0-25Rob Crittenden - 2.0.0-24Rob Crittenden - 2.0.0-23Stephen Gallagher - 2.0.0-22Rob Crittenden - 2.0.0-21Rob Crittenden - 2.0.0-20Rob Crittenden - 2.0.0-19Rob Crittenden - 2.0.0-18Rob Crittenden - 2.0.0-17Rob Crittenden - 2.0.0-16Rob Crittenden - 2.0.0-15Rob Crittenden - 2.0.0-14Rob Crittenden - 2.0.0-13Rob Crittenden - 2.0.0-12Rob Crittenden - 2.0.0-11Rob Crittenden - 2.0.0-10Rob Crittenden - 2.0.0-9Rob Crittenden - 2.0.0-8Rob Crittenden - 2.0.0-7Rob Crittenden - 2.0.0-6Rob Crittenden - 2.0.0-5Rob Crittenden - 2.0.0-4Rob Crittenden - 2.0.0-3Rob Crittenden - 2.0.0-2Rob Crittenden - 2.0.0-1Rob Crittenden - 1.99-36Rob Crittenden - 1.99-35Jr Aquino - 1.99-34Simo Sorce - 1.99-33Rob Crittenden - 1.99-32Rob Crittenden - 1.99-31Rob Crittenden - 1.99-30Rob Crittenden - 1.99-29Rob Crittenden - 1.99-28Rob Crittenden - 1.99-27Rob Crittenden - 1.99-26Rob Crittenden - 1.99-25Adam Young - 1.99-24Rob Crittenden - 1.99-23Rob Crittenden - 1.99-22Rob Crittenden - 1.99-21Rob Crittenden - 1.99-20Rob Crittenden - 1.99-19Jason Gerard DeRose - 1.99-18Jason Gerard DeRose - 1.99-17Jason Gerard DeRose - 1.99-16Rob Crittenden - 1.99-15Jason Gerard DeRose - 1.99-14Rob Crittenden - 1.99-13Rob Crittenden - 1.99-12Rob Crittenden - 1.99-11Rob Crittenden - 1.99-10Rob Crittenden - 1.99-9Jason Gerard DeRose - 1.99-8Rob Crittenden - 1.99-7Rob Crittenden - 1.99-6Rob Crittenden - 1.99-5Rob Crittenden - 1.99-4Rob Crittenden - 1.99-3Rob Crittenden - 1.99-2Rob Crittenden - 1.99-1Tomas Mraz - 1.2.1-3Dan Walsh - 1.2.1-2Simo Sorce - 1.2.1-1Simo Sorce - 1.2.1-0Ignacio Vazquez-Abrams - 1.2.0-4Simo Sorce - 1.2.0-3Simo Sorce - 1.2.0-2Rob Crittenden - 1.2.0-1Simo Sorce - 1.1.0-3Rob Crittenden - 1.1.0-2Rob Crittenden - 1.1.0-1Rob Crittenden - 1.0.0-5Rob Crittenden - 1.0.0-4Rob Crittenden - 1.0.0-3Rob Crittenden - 1.0.0-2Rob Crittenden - 1.0.0-1Rob Crittenden 0.99-12Rob Crittenden 0.99-11Rob Crittenden 0.99-10Rob Crittenden 0.99-9Rob Crittenden 0.99-8Rob Crittenden 0.99-7Rob Crittenden 0.99-6Rob Crittenden 0.99-5Rob Crittenden 0.99-4Rob Crittenden 0.99-3Rob Crittenden 0.99-2Rob Crittenden 0.99-1Rob Crittenden - 0.6.0-2Karl MacMillan - 0.6.0-1Karl MacMillan - 0.5.0-1Rob Crittenden - 0.4.1-2Karl MacMillan - 0.4.1-1Karl MacMillan - 0.4.0-6Rob Crittenden - 0.4.0-5Rob Crittenden - 0.4.0-4Karl MacMillan - 0.4.0-3Karl MacMillan - 0.4.0-2Karl MacMillan - 0.2.0-1Rob Crittenden - 0.1.0-3Rob Crittenden - 0.1.0-2Karl MacMillan - 0.1.0-1- Roll in CentOS Branding- Resolves: #1321138 Missing dependency package "python-sss-murmur" in ipa-server-3.0.0-50.el6.x86_64 - SPEC: Require python2 version of sssd bindings - Resolves: #1367026 Document and test procedure for running IdM Server in TLS 1.2+ environment - Require 389-ds-base with TLS 1.0 disable switch- Resolves: #1322059 IPA Replica-Install from RHEL6 to RHEL7 Fails - Modififed NSSConnection not to shutdown existing database. - Do not erroneously reinit NSS in Dogtag interface - Make sure replication works after DM password is changed- Resolves: #1351593 CVE-2016-5404 ipa: Insufficient privileges check in certificate revocation - cert-revoke: fix permission check bypass (CVE-2016-5404)- Update IPA code to support Samba 4.2 - Related: #1322689- Resolves: #1225868 display browser config options that apply to the browser - Chrome - Remove ico files from Makefile - Resolves: #1232843 ipa-client-install errors out if client and server time are not in sync or unreachable - Skip time sync during client install when using --no-ntp - Resolves: #1288495 Add userCertificate index used in Smart Card authentication - add DS index for userCertificate attribute - Resolves: #1293588 JavaScript error in ssbrowser.html - TypeError: Cannot read property 'mozilla' of undefined - webui: fix browser detection in browserconfig.html and ssbrowser.html - Resolves: #1296124 Adjust Firefox configuration to new extension signing policy - webui: use manual Firefox configuration for Firefox >= 40 - Remove binary patching from patch 0140- Resolves: #1127211 ipa-server-install --uninstall produces avc - sysrestore: copy files instead of moving them to avoind SELinux issues - Use 'mv -Z' in specfile to restore SELinux context - Resolves: #1222999 ipa aci plugin is not parsing aci's correctly. - ACI plugin: correctly parse bind rules enclosed in parentheses - Resolves: #1225868 display browser config options that apply to the browser - Chrome - webui: add Kerberos configuration instructions for Chrome - Remove ico files from Makefile - WebUI: fix ipa_error.css - Resolves: #1232468 The Domain option is not correctly set in idmapd.conf when ipa-client-automount is executed. - Simplify adding options in ipachangeconf - ipachangeconf: Add ability to preserve section case - ipa-client-automount: Leverage IPAChangeConf to configure the domain for idmapd - Resolves: #1232899 ipa-client-install does not respect --realm option - Allow user to force Kerberos realm during installation. - Resolves: #1276358 Remove /usr/share/ipa/updates/50-lockout-policy.update file from IPA 3.0 releases - Remove 50-lockout-policy.update file- Resolves: #1263703 ipa-server-install with externally signed CA fails with NSS error (SEC_ERROR_BUSY) - Free NSS objects in --external-ca scenario - Resolves: #1263262 Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Do not lookup up the domain too early if only the SID is known - Do not store SID string in a local buffer - Allow ID-to-SID mappings in the extdom plugin- Resolves: #1220788 - Some IPA schema files are not RFC 4512 compliant- Use tls version range in NSSHTTPS initialization - Resolves: #1154687 - POODLE: force using safe ciphers (non-SSLv3) in IPA client and server - Resolves: #1012224 - host certificate not issued to client during ipa-client-install- Resolves: #1205660 - ipa-client rpm should require keyutils- Release 3.0.0-44 - Resolves: #1201454 - ipa breaks sshd config- Release 3.0.0-43 - Resolves: #1191040 - ipa-client-automount: failing with error LDAP server returned UNWILLING_TO_PERFORM. This likely means that minssf is enabled. - Resolves: #1185207 - ipa-client dont end new line character in /etc/nsswitch.conf - Resolves: #1166241 - CVE-2010-5312 CVE-2012-6662 ipa: various flaws - Resolves: #1161722 - IDM client registration failure in a high load environment - Resolves: #1154687 - POODLE: force using safe ciphers (non-SSLv3) in IPA client and server - Resolves: #1146870 - ipa-client-install fails with "KerbTransport instance has no attribute '__conn'" traceback - Resolves: #1132261 - ipa-client-install failing produces a traceback instead of useful error message - Resolves: #1131571 - Do not allow IdM server/replica/client installation in a FIPS-140 mode - Resolves: #1198160 - /usr/sbin/ipa-server-install --uninstall does not clean /var/lib/ipa/pki-ca - Resolves: #1198339 - ipa-client-install adds extra sss to sudoers in nsswitch.conf - Require: 389-ds-base >= 1.2.11.15-51 - Require: mod_nss >= 1.0.10 - Require: pki-ca >= 9.0.3-40 - Require: python-nss >= 0.16- Require 389-ds-base >= 1.2.11.15-38 to fix roken dereference control with the FreeIPA 4.0 ACIs (#1112698)- ipasam does not support deleting multiple child trusted domains due to LDAP delete operation (#1110664) - Excessive LDAP calls by ipa-sam during file operations to samba file share on freeipa master cause high CPU and slow performance (#1074314)- Explicitly specify auth mechanism when calling ldapmodify in the installers (#1108661) - Add support for DNS classless reverse domains (#1095250) - Multiple nsDS5ReplicaId attributes created in cn=replication,cn=etc (#1109050) - ipa-client-install should configure sudo automatically (#1111121)- Rebuild package to fix a brew tag- ipa-server-install intermittently crashed with "Unable to find preop.pin" (#905064) - Disabled sudo rules were still active in the sudoers tree (#1022199) - Replica installation fails if forward zone is not present (#1034478) - Administrative password change did not respect user password policy (#1029921) - Re-initializing a winsync connection exits with "Can't contact LDAP server" (#1016042) - Server checked for unknown attributes before "ipa" tool version check (#1015481) - CA subsystem certificate renewal was broken on CA clones (#1040009) - Lockout plugin worked inconsistently compared to KDC lockout mechanism. Also, default user policy may not have been applied if krbPwdPolicyReference was missing (#1088772) - ipa-client-automount was not backwards compatible (#1082590) - Increase service timeout from 120s to 300s as some services are known to start for more than 120s (#1060639) - Proxy calls to /ca/ee/ca/profileSubmit to PKI to enable installation of replicas with Dogtag 10 PKI (#1083878)- group-add-member command reported wrong error on duplicates (#970541) - ipa-client installation succeeding in ipa server instance (#1011044)- ipa-join failed when doing a forced host re-enrollment (#924009)- ipa-replica-manage del always exits with error (#1005448)- Host and Hostgroup commands were broken after upgrade (#1001810)- Fix coverity issue in AD 2012 stabilization patch fixing memleaks (#980409)- Fix coverity issue in AD 2012 support patch and add 2 related stabilization patches (#980409)- Require 389-ds-base >= 1.2.11.15-14 to pick up fix for CVE-2013-1897 (#928162) - Password policy lockout plugin does not work as expected (#907881 - Remove deprecated support of the HBAC source host (#924542) - ipa-client-install may not obtain CA certificate (#924004) - Allow client to re-enroll without first unenrolling (#924009) - Enrolling a host into may take two attempts (#950014) - Add userClass attribute for host objects (#955698) - Inconsistent replies from FreeIPA to Netlogon ping queries (#967870) - Performance improvement for IPA CLI and UI user and group related plugins (#970541) - Do not create /var/lib/ipa/pki-ca/publish, retain reference as ghost (#975431) - Add support for AD 2012 trusted domains (#980409) - XML-RPC server may return a wrong Content-Type (#976716) - Add missing openssh-clients Requires to ipa-server package (#983463) - Add an option to edit "Gecos" field from Web UI (#986211)- LDAP upload CA cert sometimes double-encodes the value (#948928) - wrong trust argument assigned to renewed certs in ipa cert automatic renew (#952241)- ipa-client-install fails to autodiscover on LDAP servers with disabled anonymous access (#922843)- ipa-adtrust-install and ipa-replica-conncheck may not parse krb5.conf correctly and crash (#916209)- Missing LDAP schema attributeType and objectClass after upgrade (#915745)- Significant decrease in migration performance. (#904119) - ipa-client-install failed to fall over to replica with master down (#905626) - During Migration - If Schema is unavailable migration fails (#906846)- Filter generated winbind dependencies so the right version of samba can be installed. (#905594)- Add certmonger condrestart to server post scriptlet (#903758) - Make certmonger a (pre) Requires (#903758) - Add selinux-policy to Requires(pre) to avoid post scriptlet AVCs (#903758) - Set minimum version of pki-ca to 9.0.3-30 and add to Requires(pre) to pick up certmonger upgrade fix (#902474) - Update anonymous access ACI to protect secret attributes (#902481)- Installer should not connect to 127.0.0.1. (#895561) - Don't initialize NSS if we don't have to. (#878220)- Set minimum version of bind-dyndb-ldap to 2.3-2 to pick up missing DNS zone SOA serial fix (#894131) - Stopped named service crashed ipa-upgradeconfig program (#895298) - ipa-replica-prepare crashed when manipulating DNS zone without SOA serial (#894143) - Use new certmonger locking to prevent NSS database corruption during CA subsystem renewal (#883484) - Set minimum selinux-policy to 3.7.19-193 to allow certmonger to talk to dbus in an rpm scriptlet. (related #883484) - Set minimum vresion of certmonger to 0.61-3 for new locking scheme (related #883484)- Properly handle migrated uniqueMember attributes (#894090) - ipa permission-find using valid targetgroup throws internal error (#893827) - Fix migration of CRLs to new directory location (#893722) - Installing IPA with a single realm component sometimes fails (#893187)- Set maxbersize to a large value to accomondate large CRLs during replica installation. (#888956) - Set minimum version of pki-ca, pki-slient and pki-setup to 9.0.3-29 to pick up default CA validity period of 20 years. (#891980)- Client installation crashes when Kerberos SRV record is not found (#889583) - Fix typo in patch 0048 for CVE-2012-5484 (#878220)- Cookie Expires date should be locale insensitive to avoid CLI errors (#888915)- ipa delegation-find --group option returns internal error (#888524) - Add missing Requires for python-crypto replacement (#878969)- sssd is not enabled on client/server install (#888124)- ipa-server-install --uninstall doesn't clear certmonger dirs, which leads to install failing (#817080)- Compliant client side session cookie behavior. CVE-2012-5631. (#886371)- Use secure method to retrieve IPA CA during client enrollment. CVE-2012-5484 (#878220) - Reformat patch 0044 so it works with git-am- Include /var/lib/sss/pubconf/krb5.include.d/ for domain-realm mappings in krb5.conf (#883166) - Set minimum selinux-policy >= 3.7.19-184 to allow domains that can read sssd_public_t files to also list the directory (#881413) - Remove dist label from changelog entries. - Fix timestamp on patched files to avoid multilib warnings- Set Requires on httpd 2.2.15-24, mod_nss to 1.0.8-18 and patch to check for existing mod_ssl configuration. These versions allow mod_proxy to simultaneously support SSL servers using mod_ssl and mod_proxy (#761574) - IPA WebUI login for AD Trusted User fails (#875261) - Add 'disable_last_success' and 'disable_lockout' to the ipa_lockout plugin (#824488)- Make default group type POSIX in ui (#880655) - Write replacement for python-crypto (#878969) - ipa trust-add prints misleading information about required DNS setting (#878485) - Lookup user SIDs in external groups (#878480) - Special case NFS related ticket to avoid attaching MS-PACs (#878462) - IPA users are not available after ipa-server-install because sssd not running (#878288) - Incorrect error message when time difference between AD and IPA is too great (#877434) - Missing option to add SSH Public Key in Web UI after upgrade (#877324)- Update minimum BR and Requires of sssd to 1.9.2-25 (related #870278, related #871160, related #878262) - Replication agreement tools report errors with new single instance CA database (#878491) - If time is moved back on the IPA server, ipasam does not invalidate the existing ticket (#866576)- Server installation fails to find A/AAAA record for IPA hostname (#874935) - Out of range error when listing RUV on host with no agreements (#873726) - Tighten dependency on krb5-server to limit to 1.10 (#872707) - Default SELinuxusermaporder needs to mapped with default selinux users list (#870053) - Clarify trust-add help regarding multiple runs against the same domain (#869741) - Improve reliabilityof RA renewal script (#869663) - Add option to disable DNS forwarding by zone (#869658) - Update minimum version of bind-dyndb-ldap to 2.3-1 (#869658) - Improve information on passsync user in man page, command help (#869656) - Resolve external members from trusted domain via Global Catalog (#869616) - Process relative nameserver DNS record correctly (#868956) - ipa-adtrust-install does not reset all information when re-run (#867447) - Fix potential memory leak in KDB backend (#811989)- Fix type conversion of integers when doing modifications (#870446) - Set SECURE_NFS to lowercase yes rather than uppercase (#869654) - Add autofs service to sssd.conf before enabling it (#869649) - Add strict Requires for policycoreutils to avoid user removing them during package lifetime (#869281) - Make internal rename_s() call compatible with python-ldap-2.3.10 (#867902) - Update minimum version of bind-dyndb-ldap to 2.2-1.el6 (related #871583) - Restart httpd after running ipa-adtrust-install (#866966)- Add patch to override xmlrpc request method for session (#786199) - Bad link to Web UI config page after session is expired (#869279) - extdom plugin does not handle Posix UID and GID request (#867676) - ipa-server-install --setup-dns always installs reverse zone (#866978) - Inform user when ipa-upgradeconfig reports errors (#866977) - Certificate request fails when CSR has subjectAltnames (#866955) - ipa-adtrust-install checks for /usr/bin/smbpasswd, which is not required (#866572) - Instructions to uninstall are unclear (#856294) - Inconsistent service naming in ipa-server-install (#856292) - Improve instructions to generate certificate in Web UI (#856282) - /etc/ipa/default.conf is out of date (#855855) - Time synchronization is disabled in ipa-client-install (#854325) - ipa-replica-install httpd restart sometimes fails (#845405) - Improve error messages during ipa-replica-manage del (#835632) - Always log errors from dogtag (#813401)- Update to upstream 3.0.0 GA release (#827602) - Add zip dependency, needed for creating unsigned Firefox extensions - Filter generated winbind dependencies so the right version of samba can be installed. - Remove patch to support python-ldap 2.3.10. Fixed upstream. - Add directory /var/lib/ipa/pki-ca/publish for CRL published by pki-ca (#864533) - Add zip dependency, needed for creating unsigned Firefox extensions- Make sure server-trust-ad subpackage alternates winbind_krb5_locator.so plugin to /dev/null since they cannot be used when trusts are configured (related #864889) - Update BR and Requires of samba4 to 4.0.0-31 to pick up winbind_krb5_locator alternatives change. (related #864889)- Update to upstream 3.0.0.rc2 release (#827602) - Provide new Firefox extension. - Own /etc/ipa/ca.crt- Remove Requires on krb5-pkinit-openssl as part of disabling pkinit code. - Add missing subdirectories in site-packages/ipaserver discovered by rpmdiff. (#827602)- Update to upstream 3.0.0.rc1 release (#827602) - Update BR and Requires of 389-ds-base to 1.2.11.14 - Update BR and Requires of krb5 to 1.10 - Update BR and Requires of samba4 to 4.0.0-24 - Update BR and Requires of sssd to 1.9.0 - Update Requires on policycoreutils to 2.0.83-19.24 - Update Requires on httpd to httpd-2.2.15-17 to pick up #787247 - Update minimum version of bind-dyndb-ldap to 1.1.0-0.9.b1.el6_3.1 - Update minimum version of bind to 9.8.2-0.10.rc1.el6_3.2 - Sync upstream spec file Requires - Add patch to support python-ldap 2.3.10- SSH Tech Preview feature enabled by default (#825321)- Test for locked users before incrementing failed login counter (#822429)- Fix host page to display all data when DNS is not configured (#818868)- Make ipa 2.2 client capable of joining an older server (#817867)- Remove patch 0042 and add revert patch for handling which attributes are allowed in a permission. (#783502) - ipa-client-install sets "KerberosAuthenticate yes" in sshd.conf, breaking SSSD auth (#817030) - pwpolicy_find does not sort by priority in UI (#815799) - Improve zonemgr validation (#745705)- Make new DNS permission mixed-case (#807361) - hbactest returns failure when hostgroups are chained (#801769) - Man Page : Document client IP addressing / FQDN requirements (#768257) - Login failed attempts counter or locked out status are not displayed (#759501) - Wrong title and icon in login and logout pages (#814752)- Don't interactively prompt for dnsrecord options provided on the command-line options (#790295) - Validate external hosts added to netgroups (#797256) - Handle invalid RDN for container in migration (#804807) - Unable to use permission-mod to rename permission object (#805478) - Migration: don't append basedn to container if it is included (#807371) - Raise correct exception when LDAP limits are exceeded (#808042) - Notify user that password needs to be reset in forms-based login (#811296) - DNS Resource records: add & delete A & AAAA record does not work in root (#811744) - user-mod --rename with an empty string fails (#811748) - DNS CNAME record: delete sometimes does not work (#811758) - Delegation UI does not allow to specify permission (#812110) - IPA uninstall after upgrade returns some sysrestore.state errors (#812391) - Improve migration plugin error when 2 groups have identical GID (#813389)- Fix password policy history enforcement (#810900) - Privilege page should not have choice to list permissions by "indirect membership" (#810350) - ipa-server-install fails when domain name is not resolvable (#809190) - Identity->DNS->Settings:Forward policy: change check box to radio buttons (#808620) - When adding permissions for a type, attributes that are not allowed are listed (#807755) - user-mod --rename is successful for more than max login characters (#807417) - Can't specify netgroup host, user category to all in Web UI (#807366) - Permission names cannot contains '<' or '>' (#807304) - ipa-server-install --uninstall errors out when trying to start dirsrv. (#801376) - Should not be allowed to run host-disable on an IPA Server or service-disable on an IPA Server service (#800119) - permission with filter or subtree does not allow attr to be specified (#783536) - Netgroups compat plugin not reporting users correctly (#767372) - certmonger renews server certificates ok but those services need a restart (related #766167) - Set minimum vresion of certmonger to 0.56 (related #766167) - Set minimum version of slapi-nis to 0.40 (#767372) - Unable to disable or enable hbacrule with --setattr (#810948) - When adding a user with --noprivate option gidNumber should be required (#805546) - Fix error when no value is given in --revocation-reason optional argument with "ipa cert-revoke" (#808099) - Set minimum version of bind-dyndb-ldap to 1.1.0-0.5.b1 (related #805814)- Fix ambiguous error msg in automount indirect map creation (#790131) - Invalid error message attempting to delete config attributes (#791373) - Enforce single-value attributes (#794746) - config-mod allowed to add additional certificate subjects bases (#794750) - Embedded carriage returns in a CSV not handled (#797569) - WebUI displays "Insufficient access: invalid credentials" when a password doesn't meet policy requirements (#802786) - Tech Preview: SELinux User Mapping (#803821) - Tech Preview: Add support for central management of the SSH keys (#803822) - Password Policy Failure Interval Reset is not working. (#804096) - Set SELinux booleans properly (#806330) - DNS records in LDAP are publicly accessible (#807361) - Upgrading replication agreements without nsDS5ReplicatedAttributeList fails (#808201) - IPA Upgrade Web UI failure with internal server error (#809262) - Do not create private groups for migrated users (#809560)- Remove version requirement from BuildRequires on sssd. (related #736865)- Set minimum version of 389-ds-base to 1.2.10.2-4 (related #803930) - Only split CSV on client (#797565) - Search allowed attributes in superior objectclasses (#783502) - Fix precallback validators in DNS plugin (#804562) - Fix memleak in KDB backend (#800363) - Harden raw record processing in DNS plugin (#804572) - Fix attributes that contain DNs when migrating (#804609) - Wait for child process to terminate after receiving SIGINT (#754635) - Avoid deleting DNS zone when a context is reused (#801380) - Fix default SOA serial format (#805427) - Set nsslapd-minssf-exclude-rootdse to on so the DSE is always available. (#803836) - Amend permissions for new DNS attributes (related #766073) - Improve user awareness about dnsconfig (#802864) - Fix uses of O=REALM instead of the configured certificate subject base. (#802912) - Fix dnsrecord-del interactive mode (#807230) - Add requires on python-krbV to client subpackage (#807362) - Tolerate UDP port failures in conncheck (#802860) - Netgroup nisdomain and hosts validation (#797256) - Remove Conflicts on mod_ssl (#804605) - Set minimum version of pki-ca, pki-slient and pki-setup to 9.0.3-24. Change location of TOMCAT_LOG to match tomcat6 changes (related #802396) - Add python-lxml, python-pyasn1 and sssd to BuildRequires - Set minimum selinux-policy >= 3.7.19-142 to pick up certmonger_t type (related #790967) - netgroup-add and netgroup-mod --nisdomain should not allow commas (#797237)- Set minimum version of pki-ca, pki-silent and pki-setup to 9.0.3-23. Either we shell escape or dogtag does, we can't both do it. (#802832) - Set dbdir in request context after a connection is created (#804128) - Don't overwrite content by an error message (#803050) - Don't allow IPA master hosts/services to be disabled (#800119) - Don't error out on empty option (#798792) - Populate gidnumber in entries added via winsync (#798352) - Set subjectKeyIdentifier in SSL certs that IPA issues (#797274) - Fix escaping and comma-separated value handling (#769491) - Display certificate serial numbers in both hex and deciaml (#746060) - Use attribute name/option name when returning errors (#718015) - DNS forwarder's value can consist of IP address and part (#766073) - Store DNS global options in LDAP (#766073) - Move extension.js to subdirectory to suppress rpm warning- Allow removing sudo commands with special characters (#800537) - Ignore case in yes/no prompts when deleting DNS records (#800483) - Refresh resolvers after DNS server configuration (#799335) - Fix nsslapd-anonlimitsdn in cn=config (#798361) - Handle more exceptions gracefully in ipa-client-install (#797567) - Fixed checkbox value in table without pkey (#791324) - Fix exception when removing all values from configuration (#782974) - Set httpd_manage_ipa SELinux boolean - Fix mask validator in network validator (#802848) - Don't shell escape arguments sent to pkisilent (#802832) - Reorder patches so those that disable unsupported features are applied last - Rebase disable persistent search patch- Rebase to upstream 2.1.90.rc1 release (#736865) - Remove dependency on krb5-server-ldap, we use our own backend now (#797564) - Set minimum mod_auth_kerb to 5.4-8 for S4U2Proxy support (related #767741) - Set minimum selinux-policy >= 3.7.19-137 to pick up ipa_memcache boolean - Set minimum python-memcached >= 1.43-6 to pick up status check fix - Set minimum version of 389-ds-base to 1.2.10.1-1 - Set minimum version of krb5-server to 1.9-27 - Set minimum version of sssd to 1.8.0-11 (#766068) - Add Requires: oddjob-mkhomedir to ipa-client (#786223) - Remove Requires on krb5-server-ldap (#797564) - Add Conflicts on mod_ssl (#761574) - Remove BuildRequires on python-rhsm - Renumber all patches - Don't remove dirsrv user on uninstall (#797566) - Don't allow host-del on active replicas (#797563) - Fix invalid hostnames when hostname contains trailing dot (#797562) - encode Bool attributes used in setattr/addattr/delattr (#797561) - Migration plugin raises Internal Server Error (#796401) - man page for ipa-replica-manage has typos in examples (#796347) - Can not add new user objectclass to ipa configuration (#794474) - Don't require SELinux to be enabled on client (#790513) - dnsrecord-add does not validate the record names with space in between (#790318) - Prompt for missing DNS options (#790295) - Resource Record type options should be more descriptive (#790017) - Correction in error message while deleting a invalid record (#789987) - Adding some of the RR type from the "allowed values" results in an error message (#789980) - IP address with just 3 octets are accepted as valid addresses (#789919) - Errors not reported correctly when logging into WebUI (#789459) - Need option for ipa-client-install to not call authconfig (#789413) - IPA nested netgroups not seen from ypcat (#788625) - gid number: 0 and negative number accepted (#786240) - Allow basedn to be passed into migrate-ds (#786185) - permission with filter or subtree does not allow attr to be specified (#783536) - ipa permission-add does not fail if using invalid attribute (#783502) - When migrating warn user if compat is enabled (#783270) - Make ipausers a non-posix group on new installs (#773488) - Need tool to update exclusive list in replication agreements (#772359) - Reverse DNS rec not created upon creation of fwd DNS rec (#772301) - Adding a netgroup with a "+" causes ns-slapd to crash (#772043) - Man Page : Document client IP addressing / FQDN requirements (#768257) - GSS-TSIG DNS updates should update reverse entries as well (#767725) - UI for SELinux user mapping (tech preview) - Allow forms based kerberos authentication (#766070) - Add support for central management of the SSH keys (tech preview) - Login failed attempts counter or locked out status are not displayed (#759501) - Better message for error diagnosis while adding an existing winsync agreement (#755450) - "force-sync, re-initialize and del" options for ipa-replica-manage fail against AD (#754973) - Connect after del using ipa-replica-manage fails (#754539) - Unable to delete migrated groups containing spaces (#753966) - support bind forward zones, aka DNS conditional forwarding (#753483) - IPA needs a check to ensure hostnames 'underscore' is not allowed when installing a replica (#752874) - Unable to select dns zone when only one exists in UI (#751529) - ipa-replica-conncheck does does not properly check UDP ports (#751063) - Adding loc records to a ipa-dns server breaks name resolution for some other records (#750947) - Allow specifying query and transfer policy settings for a zone (#701677)- Add missing changelog information caught by rpmdiff.- Update to upstream 2.1.90.pre2 release (#736865)- Add current password prompt when changing own password in web UI (#751179) - Remove extraneous trailing ' from netgroup patch (#749352)- Updated patch for CVE-2011-3636 to include CR in the HTTP headers. xmlrpc-c in RHEL-6 doesn't suppose the dont_advertise option so that is not set any more. Another fake header, X-Original-User_Agent, is added so there is no more trailing junk after the Referer header. (#749870)- Require an HTTP Referer header to address CSRF attackes. CVE-2011-3636. (#749870)- Users not showing up in nis netgroup triple (#749352)- Add update file to remove entitlement roles, privileges and permissions (#739060)- Quote worker option in krb5kdc (#748754)- hbactest fails while you have svcgroup in hbacrule (#746227) - Add Kerberos domain mapping for system hostname (#747443) - Format certificates as PEM in browser (#701325)- ipa-client-install hangs if the discovered server is unresponsive (#745392) - Fix minor problems in help system (#747028) - Remove help fix from Disable automember patch (#746717) - Update minimum version of sssd to 1.5.1-60 to pick up SELinux fix (#746265)- Update to upstream 2.1.3 release (#736170) - Additional branding (#742264) - Disable automember cli (#746717) - ipa-client-install sometimes fails to start sssd properly (#736954) - ipa-client-install adds duplicate information to krb5.conf (#714597) - ipa-client-install should configure hostname (#714919) - inconsistency in enabling "delete" buttons (#730751) - hbactest does not resolve canonical names during simulation (#740850) - Default DNS Administration Role - Permissions missing (#742327) - named fails to start after installing ipa server when short (#742875) - Duplicate hostgroup and netgroup should not be allowed (#743253) - named fails to start (#743680) - Global password policy should not be able to be deleted (#744074) - Client install fails when anonymous bind is disabled (#744101) - Internal Server Error adding invalid reverse DNS zone (#744234) - ipa hbactest does not evaluate indirect members from groups. (#744410) - Leaks KDC password and master password via command line arguments (#744422) - Traceback when upgrading from ipa-server-2.1.1-1 (#744798) - IPA User's Primary GID is not being set to their UPG's GID (#745552) - --forwarder option of ipa-dns-install allows invalid IP addr (#745698) - UI does not grant access based on roles (#745957) - Unable to add external user for RunAs User for Sudo (#746056) - Typo in error message while adding invalid ptr record. (#746199) - Don't use python 2.7-only syntax (#746229) - Error when using ipa-client-install with --no-sssd option (#746276) - Installation fails if sssd.conf exists and is already config (#746298) - External hosts are not removed properly from sudorule (#709665) - Competely remove entitlement support (#739060) - Add winsync section to ipa-replica-manage man page (#744306)- Remove python-rhsm as a Requires (#739060)- Update to upstream 2.1.2 release (#736170) - More completely disable entitlement support (#739060) - Drop patch to ignore return value from restorecon (upstreamed) - Set min version of 389-ds-base to 1.2.9.12-2 - Set min version of dogtag to 9.0.3-20 - Rebased hide-pkinit, ipa-RHEL-index and remove-persistent-search patches (#700586)- Update RHEL patch (#740094)- Ignore return value from restorecon (#739604) - Disable entitlement support (#739060, #739061)- Update minimum xmlrpc-c version (#736787) - Fix package installation order causing SELinux problems (#737516)- Update to upstream 2.1.1 release (#732803)- Resolves: rhbz#708388 - Update to upstream 2.1.0 release- Remove client debug logging patch (#705800)- Wait for 389-ds tasks to complete (#698421) - Set replica to restart ipa on boot (#705794) - Improve client debug logging (#705800) - Managed Entries not configured on replicas (#703869) - Don't create bogus aRecord when creating new zone (#704012)- Update ipa-Fix-traceback-in-nis-manage.patch to fix python error (#697583)- Resolves: rhbz#697583 - Can not enable ipa-nis-manage plugin- Default groups are missing ipaUniqueID attribute (#696508)- Set min version of 389-ds-base to 1.2.8.0-1 for fix in BZ 693466. - Fix some problems in IPA schema (#692978) - postalCode should be a string not an integer (#692945)- Port 7390 is managed by selinux-policy-3.7.19-80. Update ipa-repl_selinux.patch to not manage it any more. (#691883) - Patch to fix setting gidnumber when a user is created. (#692168)- Fix uninitialized variable in password plugin (#690595)- Wait for Directory Service ports to open (#688934) - Mixed case hostname can cause issues and confusion (#688622) - Wrong timeout parameter in ipapython (#684273) - Run ipa-ldap-updater on upgrades (#688931) - Internal Error and trace back when adding DNS AAAA record (#689452)- Use realm provided by installer in LDAP Updater (#684744) - Use args for domain and server when doing DNS discovery in client (#684780) - Fix 2 SELinux issues in dogtag replication (#684269)- Add Obsoletes so upgrade from ipa-client package is possible (#684931)- Update to upstream 2.0.0rc3 (#680993) - Set minimum version of sssd to 1.5.1-12 - Remove SuitespotGroup patch - Rebase remove-pkinit patch- Set the SuitespotGroup directive in the 389-ds installation template. This ensures group read/write to /var/run/dirsrv. (#680201) - Make single line out of python sitelib/sitearch code.- Update to upstream 2.0.0rc2 (#675282) - Set minimum version of sssd to 1.5.1-10 - Set minimum version of python-nss to 0.11 - Set minimum version of 389-ds to 1.2.8 - Add bind-utils as Requires in client subpackage - Remove unused BuildRequires e2fsprogs-devel and libcap-devel - Add branding patch - Add default.conf man page - Upstream moved some utilites from the admintools subpackage, reflect that here as well.- Add pyOpenSSL to BuildRequires. (#670954)- ExcludeArch doesn't do per-package exclusions, use ifarch to force ONLY_CLIENT on non-supported architectures. (#670954) - Manually install ipa-admintools since the upstream client-install target doesn't. - Move a lot of the BuildRequires out of the ! ONLY_CLIENT conditional because the API validator in the upstream code requires them.- Exclude building server and server-selinux on ppc, ppc64, s390 and s390x platforms. (#670954) - Add date variable to the release to make daily builds easier.- Merge in changes from FreeIPA beta 2 (#670954) - Add patches to disable pkinit- Set minimum version of dogtag to 9.0.0 and add Requires for the theme we need. (#658275) - Remove unnecessary moving of v1 CA serial number file in post script - Move some man pages into admintools subpackage- Drop specific Requires on libcurl and krb5-libs (#658275)- Consistent usage of buildroot vs RPM_BUILD_ROOT (#658275)- Drop Requires on nss-ldap (#658275)- Temporarily disable building on s390- Drop optional radius package, the underlying code isn't there - Re-arrange the doc lines so that defattr is first (#658275)- Initial 2.0.0 build (#658275) - This is IPA v2.0.0 beta 1 plus all patches through git commit 4da9228fb2ac34adab8eb1884ae414236adb84fa - Removed some Fedora conditionals- Drop BuildRequires on mozldap-devel- Add Requires on krb5-pkinit-openssl- Add ipa-host-net-manage script- Add ipa init script- Set minimum level of 389-ds-base to 1.2.7 for enhanced memberof plugin- remove ipa-fix-CVE-2008-3274- Remove duplicate %files entries on share/ipa/static - Add python default encoding shared library- Drop requires on python-configobj (not used any more) - Drop ipa-ldap-updater message, upgrades are done differently now- Drop conflicts on mod_nss - Require nss-pam-ldapd on F-14 or higher instead of nss_ldap (#606847) - Drop a slew of conditionals on older Fedora releases (< 12) - Add a few conditionals against RHEL 6 - Add Requires of nss-tools on ipa-client- Set minimum version of certmonger to 0.26 (to pck up #621670) - Set minimum version of pki-silent to 1.3.4 (adds -key_algorithm) - Set minimum version of pki-ca to 1.3.6 - Set minimum version of sssd to 1.2.1- Add BuildRequires for authconfig- Bump up minimum version of python-nss to pick up nss_is_initialize() API- Removed python-asset based webui- Change Requires from fedora-ds-base to 389-ds-base - Set minimum level of 389-ds-base to 1.2.6 for the replication version plugin.- Drop Requires of python-krbV on ipa-client- Load ipa_dogtag.pp in post install- Set minimum level of sssd to 1.1.1 to pull in required hbac fixes.- No need to create /var/log/ipa_error.log since we aren't using TurboGears any more.- Fixed share/ipa/wsgi.py so .pyc, .pyo files are included- Added Require mod_wsgi, added share/ipa/wsgi.py- Require python-wehjit >= 0.2.2- Add sssd and certmonger as a Requires on ipa-client- Require python-wehjit >= 0.2.0- Add ipa-rmkeytab tool- Set minimum of python-pyasn1 to 0.0.9a so we have support for the ASN.1 Any type- Remove v1-style /etc/ipa/ipa.conf, replacing with /etc/ipa/default.conf- Add bash completion script and own /etc/bash_completion.d in case it doesn't already exist- Remove ipa_webgui, its functions rolled into ipa_httpd- Removed python-cherrypy from BuildRequires and Requires - Added Requires python-assets, python-wehjit- Added httpd SELinux policy so CRLs can be read- Move ipalib to ipa-python subpackage - Bump minimum version of slapi-nis to 0.15- Set 0.14 as minimum version for slapi-nis- Add Requires: python-nss to ipa-python sub-package- Remove the IPA DNA plugin, use the DS one- Build radius separately - Fix a few minor issues- Replace TurboGears requirement with python-cherrypy- rebuild with new openssl- Fix SELinux code- Fix breakage caused by python-kerberos update to 1.1- New upstream release 1.2.1- Rebuild for Python 2.6- Respin after the tarball has been re-released upstream New hash is 506c9c92dcaf9f227cba5030e999f177- Conditionally restart also dirsrv and httpd when upgrading- Update to upstream version 1.2.0 - Set fedora-ds-base minimum version to 1.1.3 for winsync header - Set the minimum version for SELinux policy - Remove references to Fedora 7- Fix for CVE-2008-3274 - Fix segfault in ipa-kpasswd in case getifaddrs returns a NULL interface - Add fix for bug #453185 - Rebuild against openldap libraries, mozldap ones do not work properly - TurboGears is currently broken in rawhide. Added patch to not build the UI locales and removed them from the ipa-server files section.- Add call to /usr/sbin/upgradeconfig to post install- Update to upstream version 1.1.0 - Patch for indexing memberof attribute - Patch for indexing uidnumber and gidnumber - Patch to change DNA default values for replicas - Patch to fix uninitialized variable in ipa-getkeytab- Set fedora-ds-base minimum version to 1.1.0.1-4 and mod_nss minimum version to 1.0.7-4 so we pick up the NSS fixes. - Add selinux-policy-base(post) to Requires (446496)- Add missing entry for /var/cache/ipa/kpasswd (444624) - Added patch to fix permissions problems with the Apache NSS database. - Added patch to fix problem with DNS querying where the query could be returned as the answer. - Fix spec error where patch1 was in the wrong section- Added patch to fix problem reported by ldapmodify- Fix Requires for krb5-server that was missing for Fedora versions > 9 - Remove quotes around test for fedora version to package egg-info- Update to upstream version 1.0.0- Pull upstream changelog 722 - Add Conflicts mod_ssl (435360)- Pull upstream changelog 698 - Fix ownership of /var/log/ipa_error.log during install (435119) - Add pwpolicy command and man page- Pull upstream changelog 678 - Add new subpackage, ipa-server-selinux - Add Requires: authconfig to ipa-python (bz #433747) - Package i18n files- Pull upstream changelog 641 - Require minimum version of krb5-server on F-7 and F-8 - Package some new files- Marked with wrong license. IPA is GPLv2.- Ensure that /etc/ipa exists before moving user-modifiable html files there - Put html files into /etc/ipa/html instead of /etc/ipa- Pull upstream changelog 608 which renamed several files- package the sessions dir /var/cache/ipa/sessions - Pull upstream changelog 597- Updated upstream pull (596) to fix bug in ipa_webgui that was causing the UI to not start.- Included LICENSE and README in all packages for documentation - Move user-modifiable content to /etc/ipa and linked back to /usr/share/ipa/html - Changed some references to /usr to the {_usr} macro and /etc to {_sysconfdir} - Added popt-devel to BuildRequires for Fedora 8 and higher and popt for Fedora 7 - Package the egg-info for Fedora 9 and higher for ipa-python- Added auto* BuildRequires- Unified spec file- Fixed License in specfile - Include files from /usr/lib/python*/site-packages/ipaserver- Version bump for release- Preverse mode on ipa-keytab-util - Version bump for relase and rpm name change- Broke invididual Requires and BuildRequires onto separate lines and reordered them - Added python-tgexpandingformwidget as a dependency - Require at least fedora-ds-base 1.1- Version bump for release- Add dep for freeipa-admintools and acl- Add dependency for python-krbV- Require mod_nss-1.0.7-2 for mod_proxy fixes- Convert to autotools-based build* Fri Sep 7 2007 Karl MacMillan - 0.3.0-1 - Added support for libipa-dna-plugin- Added support for ipa_kpasswd and ipa_pwd_extop- Abstracted client class to work directly or over RPC- Add mod_auth_kerb and cyrus-sasl-gssapi to Requires - Remove references to admin server in ipa-server-setupssl - Generate a client certificate for the XML-RPC server to connect to LDAP with - Create a keytab for Apache - Create an ldif with a test user - Provide a certmap.conf for doing SSL client authentication- Initial rpm version/bin/shipa-clientipa-client-debuginfo  !"3.0.0-51.el6.centos3.0.0-51.el6.centos 2.0-9.el62.0-9.el6 ipaclient__init__.py__init__.pyc__init__.pyoipachangeconf.pyipachangeconf.pycipachangeconf.pyoipadiscovery.pyipadiscovery.pycipadiscovery.pyontpconf.pyntpconf.pycntpconf.pyoipa-client-automountipa-client-installipa-getkeytabipa-joinipa-rmkeytabipa-client-3.0.0COPYINGContributors.txtREADMEipaipaclientipa.cfgipa.jsipa-client-automount.1.gzipa-client-install.1.gzipa-getkeytab.1.gzipa-join.1.gzipa-rmkeytab.1.gzdefault.conf.5.gzipa-clientsysrestore/usr/lib/python2.6/site-packages//usr/lib/python2.6/site-packages/ipaclient//usr/sbin//usr/share/doc//usr/share/doc/ipa-client-3.0.0//usr/share//usr/share/ipa//usr/share/ipa/ipaclient//usr/share/man/man1//usr/share/man/man5//var/lib//var/lib/ipa-client/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu?7zXZ !PH6㽾] b2u jӫ`(iP +%;g]YPu>4șWEMyY Q`v*nF Au/Ydf),d,NAj6ئ ߘ'͝kxEfHwid5yWP4 Aŷ8#q )DU8GԽJھkUKs$B:?.+F'aJl7T LpW-xq7v3ɶ nw9 KGV  |]qǀʬ>D>@ `؃Ñ:VReJ]:߆nbU&.z;sHX1D5 G=Y=vlj0ZhmMr{`Z*+y.U<2@\K\(nT /$١5r>DfKd;q(|SBFnGު+ܽb4u?R.U |u^l!T4!GЎ $ ʑ`m_h| Cm>41niE=p `gE-g(bX>856;ED*.H٢ZIKБftp@'Z`ԧ[1?j+ 9dU&A!IRTd _f,pz\UxH>q=\9n1i+Cw:wV KS9`=nj 7"vXnz x8%h/Y<\d[k <;&Í2v O!f@m4ouaH(Z@kX PQ TJq=dkZB2(Ds}VVah=tӹcF o=vwTjolC*äﻗ?-q 5} J|^QܬLr\GwcS}|܂їiarsK2{ =>PT܆pԉ0vSeӺQfa`0*cg6sW OS\WLB8جty0,n|~DH[e?`8ebJ )B}_IFYNwZxaj2ʐwCTؿ&%Ul`F0ORGNK I'5Ca0ZwSzr6kVnX5 e7e({(+:2oO@~1@Jު2HjhT$nк5I_U"yi9)V;ۂ)@Txth29vzp(kȼoR}b8Z&iN0N̹P:^ % бN'G! )hab9lHPV 5x(/Kڗ Y$ (YI0L΂G9?%?9qM3rGW{6@Cť^Ыݢ^@!;8؏D 6#65>(*ŞCѷ]pHpu4IҠӔq؂@ حkxs-H=bXeNl[pIk1bMԾ Gr!.O;&!U/bx,^Bz,]z$"5-eܙס85BoF,ZT )'iQӖtJ\ 1R yrா |~b@3ȫȆiY~Im}nВC/~ثv;tE:CjâOC"K; .9Or60p 6`6hq+`i6H JGz,".y^뺿N#koxY.Z t܍Pm8 ̓sj&~ɫ/}!%lXt(}E:򛳂?RZ q:+kZ6 >٭[cW N=!P1=Ա=$jD4S~9bK|vL5)*Y7 'o1݄ nnjڎ7^opvbXN3s ,]'5I:iA~=MBM NyQ@.G(#;+)ȉ"&׆\;10㴕tYO1l5-/68}&c쓴мP-ѷFeWE$N?_}4dt?䚗^핳IP# Dx?b`jT(H;:^ FL/phx/]f7S;Y[T8y-s{\8-ڹ *H7 ,O|v1fýսj{ v6 k5UY"~J%#RaF$z=y=*߆HU9|\M/o neg,_-#M;dUXnN,Y?{ v,tIkv2a·c2GѸg^]Jl9wj=Ͽ QBв0V 5TDy k |BhN a7`ư6]"@V]_I V Es%௮1]l}=L^:#>cIvSO|ۉ[!"0flX0"ϗ?jb)ʊ4Y-[{/k"N i|qUڱ|NO$ڞc?DȒEhl)N? IY+R/od:S#9V#HIGƅ߭4mςtM62+'ØN֒czw&3`׹(Hn QZŒJ21bw/biiu T{M<k)|?ݨ);S1s/,>߻NtWA0vi02v#u$8I=`p|]b2>~[NW!K2Z"o\S6D'n~zf8"{APKdΦbV4ıY=|=,iG\'|72XX0aDs-6hEv[`"D&T:/Y ai TmcdǛaAZ1v#6~}]o\ +5[tsu*ef, Ѻ44M۱dyy'T2)ւ&O3H?3C&\f$ N\3YoиJR)}oOeVFRt(k]$}5ɡ7\pm{ЪYq $;W]SO(Znopݪ3f}6M^4&]򘪻"M Sc 'G?'-E]lkV=z{<9 "#Q4)~؆#/5?U/cc[Tx SE{̜4ߺ@EߑxrH̼ \ydPvb$usV >S$}4kߓi ^94 M%㝋+}ݰ!O&1f/a:} MtH4]Kb䥉NHնֳmwߺBu]%i΋jˈU󾗣)/ȑoۣ*It"7Q/qNJ2{!w;B_&kv̟T$ÆAq0w {3BGl@@_E Э@FM_I ./L<u) v di+h@vko \Y9>Ք0ܾ3BR}=K&aEpd~%Z>JIZ,{P{?A"f[W\ܿ.'뙽0&U[ .́~-?;_(2hP@ZU~/w|ssPFiYC%xkiu<֝#lθ>%۬KkV!x)3ͩ3gR5̐Plw)n,f`5-{yn>]ZFm^inEVK)'ݘѭZLM{b_DAlrhTJǁP&_tn ԶEEt$2,˫nyw#cNNjS 欅0ৄ;|9P\[V}#ݍTglhm뷈|_m5d)Ss\˸5"YStBLjx.^룙*h:8>9_zd%nY# C?rI&~pIM5K;IN| $<<<1kH}VzJP3lЅ͉q$Q8dU9|yhNWba2\?6ԻayQ з&+l%k;yn?j)^;3z96FUjN9[A*F'bRcZkړ1+|na9Wq?bK2*֚du# v&]:jSKK0d|VΡl;Du u!;w }x1厓9-[quی^U$|E9ʼqCF"V:SYIIɑL2 H%P%Zf̦r6>82B8B+ ^ FyjX@+D25[_w/ׇbq'lNM"%w!SH,I+1^YԊI=uLun6ZALRD)hu@ !-;cl%CLݻvg|g ,Q`C|MZ+Vi/6=QAI|p qaZ (@ƚ.c\Yj{ϴ%꧀m;#(k.aBVQؖmI_eǫf2믋̨^3VSKy<㬎u_Lk.(;,8:Bv.(:V*<2хjJkB౦pї~\If$vxڍ/G5Җw޾$|lJ~@J[M"p8qnԉފI[gJtHNu0HLL=m;6ŧ h〛 ۋ޻ݛUзdX2U3A= MРST\@0ᒬbE[)p q WL۩rW _e bPv:E ߝ3IlkDš*OB|HQu٩/4GZ|/]7~WU/a7gk+xMY 8?Dj\T;Y2@_jBy%%ߦ&ĺݼ?iI֥Tkd e}8M'2J8efMĀϾЩz ZE6}dPT?2 d~jjmU4m/5 ig-[3d7i z\^bn\$ IDR[YTb# / ]G. zBbS :60$ >(N:@IUc-lTuKr'4n,4B' * `D%MޘD^L"3~yz1Qúלs4A ϤujboD-3pE[qBrS@tLآ;C~h+7dLq_sEaѭt~da#DǬ$ՙ\(k/y#eWWo?Qg)?b# _:UzÓ3z?6Q`yWDq15 ny* boOӌ@^*H͐|T9HJ/vT":=0'8qjvj_:ad %ޡS.]}]"zβbJG/x@=exFiA7iYِ֣970YTPWvK^61mt,]>A$u=\!ae gl9=Ow +qP@qyØ:&t.<;x⯐*Q/q欎J-e@ݡ1-%NHX3 #]8ShLN*{vuBJ Z}\U;Gvaʍ/9K1"%f)EoFêaF:u!.c FD .^Fj\viZOAo5Tv4rh𳋢P響FӐ=.,1MjڦWz[#=ߡI$j1LS _[YA4`w'xhWMlgOa9c DPq8vn\^JPԚ#Eg{_0Spn7bAMJ)+D5g68&X)nU͋(&m;ƪ !8R&Ckq_3Y9,kiA=Z-zgPe9:^,ˑNCtwH۶JZ3 79qΠz9cJ3/BA.xH$:$vd_#K$$Ad-E{o{{!&): r7YѵHQ,;\+#UMrߪ( lM]EDiPM&mH!G Gj0 e$PU>) y?X't3}2ekc"F%Ad'C5dCj'hO sPЮ y$ק=;Q)_ 3JW0㟊-2!gƯ0fpg[B-$/_I*F{;b0)1y0e*w8arv+RY#AjJ! _0՘_}$wjA1K1ܿ8ʛ_iN ?*TP>#M`,~#f5I[W>>kRAԗcu"z[g6+[x6rNeNEx3MYΫ:tetrMRG"ʾfRe^_}Spc7_F_+v"crp̌&p9"=Kk(_؍|w@/_-maNɳj^e^{MeȲ)*|*<Ҍ>=-ycd߿Q`ILX e5*VP#˝Qm'w [ ov R#w@g3bLbdRelI^'=J8ހ[&w:*"|I'TCP @H/+ mѴL6_N; ' JtB9=gɞ)hG@RhёWߡ=<i <"f@E8F2ʋ<5ᢊ{BV:qT:TA> vPwaZ/V@~mtөSÛBX8̻g@e;,j8`gJt}93s5Sd7 ~Ȫ^6FsԢِa*lrYEx45ԷыgK5ݾBA91V]4hͭwMGf դ %%X~N?P5R!;)Q@wx aֽ$S0w@ʳ%Ɍ- WwH`A&ICw0y4g$t #`b}dn3o_+'hBmY$fiX~sǪϧeES ݫFpH81pkȚM8 ?d"4s7ǢY ae{&<"{R2Wf ŹG*F(n1Eq0~Z|U}?Esog/!$_{] "'U_ÎTIbg bҹN4$Iʤ`#څxߗӃS0)y9;x|!3|2h2l:؟?Л-p XaMb]YOs\~Ҙ剦s)Ejy[ܹYߏkP DiRFw(x6m0P%D~E&_.#?ޘ χoo|k쏕t5I. `M*8_mگsnѹX 5!ʛt;[.*POI`QԶ0(L&USTU+NtR.`4)>ƢC!1qS1~#dn'_}>ޑ賠qK/cX]%z8 "W](8"W@0Nc0ͭ4:t`{1\3ޝz..4{QwϊE<oBŚ.AVe1`.ҨyU}o!\?#[]OBAWDM)O!gy@ a%((p4uqH o @˻hvO[^`a:df,čTW%܎a4ӣ$S8,3b|]gLT"Ti)\kZBHD[N l>QEȦ *0-""x|دi[wi_4rgX,qL⸋a%7xwU~&W@,2re6p$gh /ŽRiDy,NWdH׈&W^=}OϤ6GnzҫQv~fc3%rKi: oS(*0pU0*:x%ƁT `!7^&!ɒ1EqdQIZ Ǯ_ɹGfݟ^k/jo@sum,BleUB"f,'(G1'% %kT^Az q~>5!p,M`"Xn?jzGOۓ.( MϳPm kW-w_-7.}C {Z\6_s㕰mJ8#=)vF\ۭ 4ĄG"Hͦs?%q=17 ɌWM֑[r ~!G@5V0<ȨAÌ0:J51? }!?j?;H@MVŌ;< :1ժP)M?"m| { +zKS:Aϊö?snT|Za٣/ y<bu. A5~gVZ)`4P4'r`*Ș@,3M>Qth.-h6HnTOƮrݖ= ( ROzF\8 6p;)Ր$V*% ߟ<6!7SL}JdI? / fG>Lz \sM`DRlFyRCkht,ZGN@\#ATfUlȜjףF -!n,P@Ε@9>c2ؠԶ@xǹm%]Ώo==8'dx v_ [Hj7Z9RFe4UX+^p{>O6s@3(O 0(cimCĹB~MM7ʂL::C6-U3 T(&sH9wϚۏCB>TBf4b +=^TY-dl_V)prTEL_%/`wTHpzuN5"OxV%c/A85,n3& YJr@w}1~( ڿj{(G@Z2UDhNsyܮU4d5eX ^p3MsڟY@(_ Q ZNǫAäv4FHplzq?uJC+fQ`nγhe<DK hp}ҔR mfp4]uMN$qwt~9Y%ݗ *Mt6 y%Nz5 ԬlqāG'eqwrLy-.J ձ0FਊC04EFLBhLߥ_+U媀).QwvNE%kA;)\ 3[xA=df0y K*E |bO_Eq%dP`J} l?OPNhz^Y_c{ﮟj5QӀM2}~WsyBVApe Q7ih-k b-x$XJ+aQV],eA  ;rmaJvo٪+ '_oM9NпOhq‘]֕Y4.im4-ŝnwFGmAO1)ud=ǔ}GzHN$%5zh+cMe؃nRr>H(&4(@7$p.x{{)FOz:rE*ƒ˞:%'G:N~-lyt[΁zDQګlb#$eFׁƥscFe̹. {1#Ɩh7o, >s"hgRF9uȟڂ"'QB7/kSuCCP'64)I)Y!_,*] F =~ Gud)%B9šwV\0 ϗ(,U۔cPmʸU ?2@]":cP"d}2@L{raޭ𧓇$J.j'?Uf._m oL!pt"y嬶r޺E*yG V`RE XN: *' }$)bzHrCkFV_/'FV} b .ᏲLcB[-āco򍉷DUO:#Zˁ&U*{y[>7Zm7R_~H<hT1'_<l|eVeSvΖ[p.M(ء&Sl)rCKyW{P&P4%L}a2fbS#F&MC=:K3= '03JʆU 3xΟNukأFM&@\_^񬳗ՔqHm. aH+b ZYpavۗV>/<;h 7.}U3*Mfۭ&j=ݚ b|e>VsTl 㬼O[o$*bm9LGLm'?"QX?,Ȟܖ e'| ` 2mI ig&"Rg*C(Bﭮ.C(49?) 룼 0 Qt,JKU#>P^t>˱gߠYih-ה^/OB^zixWx! oZKVbYӥJއF*"; i%'OK}-!6{%ł'ȏ=.x;=='llT1, Mq}uPVAq̟F{+?!)OqFz(M]Hu@foJibsi/(BT (# JJ"~"Y[ ip/JOkvW#,&*Y!uQ/4@i'} &ɀ9JDGQ4Feymڦ|Ho0*X֊ >+;:nfLzQr %B͟UP9T Iz]Ƹc^7 O/yzS _Y,/S_Gk&ׇ\ qb `fiiS8|,> ~[|ªx=өn([VT.M.!)hFn-.`gS*a NH`pm7 ^g,.hgDP$/* W3 R *Muhf)^U1g|_Ѝ7{%k# KWu)A"^MZD:)ju! #4{QZo. ,+bp8SGW:BP4C'hG$ %K1`0VJ ǞG֞bm$>vÓ=d!l&@t9^-zԴkC0 g'!/>1˰ \?ad91$$|ЮWf*ݚօ-'eF#͵u|o+}z} @Y@˪(TB&lD-GiW} eKi7,U}jN/,TL,,b; x=?MDѹq`ŵ^xe if;G6A*lIQM-IRgKГL̉qg6:3[*4L6:vv _2#W#5`B5X"~C*Al ɟ" [?)aN:"8/4ܘU#{*9c; `'~RS 1bq X|] QZu#Hbjp>zMԿqhPB͇gBݒ'-D[_R9 CSTX[v#AleB>pUp%ODG~u)6VXҌTIWq?!nmvʓ> b|X}S_rfٽ`Ƥ`w ۝!FR}$ |-чcf=o%!i-fkQ)&w-'G8¡1EMN'rE|IFI광e}̬+{ ^//k:aټFKdc>ZX#E3t0&-D+ *;Gf*+S\!mfw}?<$X1Y65Z a}^ӏy`16}'CL'uu- X|YhYNs=߮FgcJfM~Q5떝$aPdU *Ԋ(^rWО-lp vTpO}vnrە W9[ QI0\:˔RE،| ݳ_Nj;j-$B%S_-_x<&+;J[pwQ=|VQkCeqg)ZK+?YSf.ʒ%cԊ 2fH"PGMxRq(O B^jC˵GQQ\s9kKJvIVX?J̑aЀuf^GocHYZs`+2ͷ5d13 Dvט_ԫ@ $8۞ 0{Y"ꋘZ={LӦa Lb"R ?lp&~$MGdeU[\ت]잇JIܾ քKfDZ:4!kv2xN ^P\wARD ;˭a,)Nb܋P' kN_ZM*;<⣡;,x-԰8%j}KsyPk;|SfV P[ #lɋ2,A|_apk$'g/ |}H$뭧g,%н IPG0tNYNcICt}ґƟ W3y|Z[ꙺf9; ;M(\>JV2qE:ݍ^JΙs T)Mmt*A }}PcU 1ʞ0,.h{>l`r"TA4ͪK׿:FA'?\eRs4^qQ9 ^_\cGhrOBuˣoDI4˛sEҐBL.lSv1DcֻdL~)l|/O|#ѨK"?s#qKcdȄpeosYyjOWVΎ[e;G5LEzO}kI'1{1ҊA= vYvl**86hߺ;xCpb.1hP{UWt܆F $~dy>Lv̮3cj&yK&ٷ+kc[:*tPYhj";VdHa%g [F?$IUˎg1x^ ?M|!Pi݋L?W׎hOS pcS%: @xث NwABo(\ ib;V+(D ƆQx/]cIᐉO|Βn|g"/*!a̚M75XbG펲3*A d5=u|4XhqLy[lcs;&uڊ5x/+@$v:XNVb!p=Pj@dJJ97`\]˲@ށ}Cl;>PlXj-F05B5Yaq"H]ì,-FQ$ǘgȀ|v: ثo#EjhUQ[9Sv3R9hٕh `68̬FrjJCT{]Әp6YxfvFy$>_U`EwH~ǐrBOwwf_ +;>{DžI/5onи-L |벒 YW8X%kS+c3 !Ǔm-7x@g/^טE0c1+Ո2hh'jf݄krlX \{j." KH+=y(]nRW^7kcϞk'3xUzdrDl\{Yx%ǀ?'%x$4Ө^\ч-;K&e1-DFNʉ!1j+!nRQ;ߘkDFՈC`1܌LAF?IMV Օ82QVR1mlAm;%Ώs^) E1/1z_\D)zXAr8 ,՛3rh !S7Q,3y@dQCnԌ $Kmg.ZK] /%=po}˯9N(QG|{T Pnvl[욒EB;q,靊Ѱ6Qy0 [O>|6RwrbׅAr^rgD͆ yߓy@R4$}JʹqkCF-$8_D2WBF]dg`nc[bQ>z"e|]kM[%ֈSHG AKO^|D:H*E8崓$8YdĎ[gM3h=8") $o0mEO>?K:}}Y٠LX U,u}ƹIJQC踵0H^͈k~) G@83Kfҝ :|nrdjյW<cQQ3(jv?U3 Py=@MŜNJH7!]?3se=/9zRy}bV/ml% 8hM6\]@@oG0fjN`B"I5+$@P&'D kyi?PcO6模=3 `•k (`1-RBPd?~ ZOh2 2kЧH*+N`or<W$1U/R1#|3gP4yXKՠ}0;WPq@΅Њ2Nwֵi/7gɐO1Z,D` @PGq6o>PdLSao5]1`Ble4B2%),h睍X&}sD65'9֊aU/?J.gcz~KדI(uI{nx(Itl$FiCl$ BMd+BE>L@sS"c~aڈ+#뛾g3aARv*&QI{і2^(z٠O@jD n- ֋ l"/Cxo6r؇_Z"&q̌&2bEY76MlJi/#c% ~R`Y ymL&U>8£УmfY=\퉮ė{:k1rqpBK>=& {Ho; S\[\~^DÙ%T"3棶aC33.碆tvjo )M<\MW,5Qk3J!0~#` |^C2Rԍ)e )hMV XLmQAE=t:sC]JSex&*ARÅWԊ^KE+J9eO( ;qR{,d Rr(s?9:-Tk$[rjaR9c )[I]b nkuT2'-lm1cʺbBJFy_ 9PF>u'y>K) Q6NK?g}[avx2)u'UNZ㆟CHӗ5b't7;p2,[aM xlrOI>`(y"=̇HȯD=uI:FV{txNSO7D)xCqq oF %^XJ)0 @+Eq6g1.#!w˕C;uDko5\mf$ kVHCOdWY㲸 (Û9 /:?ћmڴhJaI;a, _~o^u2ֳDF{Hy~E6*$`1ϴc {i4NG&+z,h+2V;.i:%w `&nQxx.m<묔2ՀI`ɗ_Sv=]brđvH`~XS,t}jw F'00 fp}KeBoM ]e?l (`ir_)m_ȧ|+:Hq~e2֧}۬N#/xߍEŗCbs =BU۲!Qp* (hHui_vEAWEdN*+>N;AH=MDtXd'y%9s pJ88 dp`P%'Od#!3@u<CI<;]24߉,'3aUAn 0?#J5ewS.p[U㒔Z4c iPm#UV OvpADXĆUʾ:!{Ma*k6&d 0ݴGn!H[k`"HV9kz'ݞ-zUPe_$fv$*z ƨ@&b隽٥ w*e6v\3~& lBPI^cmnT㚵bfVgCũ.xF7\EMa?]68Z =1[) ǐ<'$$$ʆTK q,5~)R~1h#VPȮlo"G`k$No*ZWEz(pIAxXN-w{us,B!( 6_S`ltzNeW/WV`M`"v#'#g3,XV&{W 7Si-S*; UO *\R<XPɁF!B{94F{# WD%#2Ӱ 7WyO24H[y )OeGT\51805z);$mF/o2o=I d+Y%#wG8N{ @'Il=2=EI7/DƸ UK[$yB/slarrHºHꮎ4 -H.Ԫ:{t$P GJz\Uɱn :rlKcV}Nr N=P$QrP,j:dί oImSdƥ ("[s-sUs< }(jA\uܯײzӌHs&1dž-L,U{ &+n˺#,!o>"<\6"}/Z5e=*7~S9B3A4'R] ҷ= xyVQ &BA1Y0WqmVˈ3lPFE&w Fw#6C0nRxNc)Wk@ܻ $I=eLRf-Ј>4#-`~4c~^tƙhutuq*E&Jm lyvy6hɽW˴PIH㤘Qf_9+0X'"8' _CʾAT}$tލ)呇Z*N4 ꌌV4}Diy 8]p@χ"xnJD>~ b'F f쭵ѥdO#IbY=LDJT2(l5"%2n"fCY]hRCсNO4{2ĐAonK4'l4kMSB\#@>{jom$=r$.d9sS,x)%˱iMP7WjԔ#tF J^Wx؛MA `GN6̘ʹ"h. x.pe8SЕXB7څB9^2Ta/eS*o:`<ʿÍd*vw}rѢ zQlj>.Gc wVOzYD^6T= :|M %RdЏl>o*Lz:T 3ކ) H0 bw~v&<1)b^]SBH SJAb?T9Y3ʦ9Pf4o]Z^ق -5@B \zԈטD$(7DHXLj' ^ I 2 |6u<#}IN%π&Qy̕Far,^o_}bkW|q3eA\eHtX k糂ê.i{=Z?23wu8g/C jsyg؍bB5^uNU?Ƽ$)LXNI%.<^~mFFi՚Rp<}>" :$Š*DD+ yZM\44Iwv_wfݤzqc#]"u^sFLR?ݢ>KQQ]{zϫuypg~wW˿dU;@sn<уmTyDx hX G{AaQq"wI"ESYv@?8La$!7WTD[W 6: %;ѻ gYu(AGج$$jާX1u[5;Yˊ p1H髩Wz` R.*RhSܭS4Z^@ xn/3@O:R^el鼢MٝzOhV7@vى{=j9nGf:o^(k8f+E ozQ5"@:@lt1 >^\QrAdW9Ev5N!jսPI )i  '(a@yoZ"!G-捠#0R(kW), aX=RYqYLi({Z[KMvf*#ne Q߄h s+,( uL.U  ^9Vc4DT AH"M>C+ [.+4h(eOEߘ &lA|nFziG-/gQƱxņ>8u wrGfvPU N}ZgzMaMaj¶'w5ymכ7tQ|[#>8/vpj0C&ջ^PgBg{omF|L E'eq<| zM~]X0d~B'+wj\$,LK^[[HhyܭYqΛ 'lJ[2veQtaD0CLj1?[m}f: 4r)w9\FRoXZcPIۙ+i$l|4%Pq7Q}C$Vo181x,t+ @W[UFz$:r{_t_B S1-a 04҆Ϗp/cD0,nL!=BUWj < ݎԉ}aޡ)%]蚌QfOku?eY<-|I-š`[W(05 %m rGW߈qv]M$(#) 78{");ȧu|msn[ fI }:>J'|LH|J͖lb(G ni+Bҵ]i[TEhaug#Am7|?Ռ@-}CܰD3ֱ\Ȕ~اMbF 8vo{X/k,@HM#8k5 "ڸ7hprٳUQ>!_Iyy9>1W~ yJ)]uhj?>/ 86|Ih|DOhЫ|@4K7o&r:Ld)h22jVJ#SA&(!Qd,r <=g@o:!5kb~3K@ߕ&{aU5w|1b1xlT5Ѯ3\d Gd]!|7'`b-p-BUаߊfL|Ep^PK',Ç#ܗfCpu|Hmt90lz>wbțj(#/ 4"feLkz`lBIױ 6z tM[ 7 B1g방 eS=tO/ZxMA">_ UR_4m G,rŐv{t%#SZT#ۯ MJߺ (^dW4POLǩm=ŸgJ+T1_x}!|Aw C]eۤ>QhMǫX%wƊ`%k;?lUѿpMf["  _DIGp9=V UY(\gk׈m|CUg`m:Q(+LtOR[2~G3UɯF}foi蒚Y1 !O MUu ofʼTv[%b?(m^dJS !"_Pr FSx﭂#ݗ/yA#X8,14IlPWO1u.sPHK} C{vw.V;Ϳ JV1WLsk!=◚f>Olˌz%^SuJ3VD8SZHz<9V<>}FkGSk\cɱi!C`qF+l+*(-Z1u2 &ǼĹ _q&dC5GşMݟ i{ N?stgTw}ɜĢ8]In2^u JBk{-b(tV\wUccFA?ʒ~K@QJ"xBovsy'@gM93zi `_Ѡo0+ þS7ZĪ^-|HX|>$C.Gprj6`Q^`x=.5z尀܍Ҙ݈3-GC5쭢(DNs(e-3|$LÉw@PXSe?ݕ]8=T5䂂ݒQ7r$.@; }q-؅'s&qjd'4~y)sWBi޶xY*X. %~9hy7Ӈr2RrsRs"HkVYGږ !S'J_g@1S^)f*IM כ)M1,ԅ}\ SRs^#wbe+<+,VrmTRJ?½5$6h웩>jNOw4 .~Xh. X&NMwAv`%UJ 4gѱ@88~F9YoIo{B}Y?ܱCDrKf'zz-J\3Lr 2B"84;$ʑ-BnYc[V"YVq,6ސ$}%]-=5+k6!!qmqKR\_N$):- kFh=m eV\Rq(Ao EqDݖ ԋ{ 'tj"*e̳pVT L@ZJ0Q}kgfbRxpu*qgQFl4uP]n oM$ ;  aYh<ҥsZ&9IdZhj vѓW ^6mmjm ܝeГ) A GR'j}ޒ^y D^NӋ 35 ىҗ0 c!Z prڣ<ZfHj9h:7 @w˫3t5 p'ay-sHuv 宁ԯ rV =V/DlNb(*ɉ7nv0b&S6D]%r?̍T&\rd)fYpv- 8@ >)yx޹)>a8RW:MP.%/r!խ|E7$ڍ5Wp>#Ą;( dRej'6@"%p/LߔZq^fRLH!WK!xgKo VʎP6R> ^Na<;{۲'ĸR1m niTY-)<@}, GP+R6K R/ E Xal"+Rs ր~x49\LHh8% ceO-Q'Y?).*pKnmD1c!x\rXe^ ΌC+ Mt9΅!Q+"۾}}@/O]][V.40UЯ4i9*,)6I vfML&Dt(#oHuK|0Ge&%qõN9݃θZ31xkim Ҽh )fc5ôヌ?K-̨9 0J'=Qu˥h@aTGP_1 !8U쐫(QwF20& #іbBPMA4JnX7QGFyjT ;v%-&涶r+Tk'k;:W\='S 4hOcN$ƛsU`aI) ?^\dC~QbS{u7>`a<0jS s.6Hf_;v>.h.$ }Iz\V:SM'xrDY1^IUϥlQ]8#Q>q5Fsl6VyT(~Vtx?RDT 1\ڌ%Up}X gq@.= nIZ/LNyLlYj}"D:,yqC&ņ2EƟ3!m GXqm&,k@ aMh[8]?d>gG@qX i3JWD^,K C*z3_ ƿV+xdcd9DŽ ל*"g6D"~!97^ɟDZUXR+L gMU |UDPU44a{R/Gގv&Fs7a} HtxcIsX!p Zz0eMVIWxUCP}t[cKަME9w>",=*FyeDe mK6׭ֺVwDǿ΄`R@[,b GdB-yBc^`X~=CI:LcNu+d _C)J>Qd.̟= >067f s>Vw~dfD< 1 M4`GIB:z*岍S$5v"46xur`EZg&D$#x}\bzm{(~uJVg נik_)S97f%c/{V< GWǼ:)hc<%In` ͘_ HV`ɘ(akή5ky0]WU("T"Y"e^.!RKbM_iܜ7.-G[,Hʄ[kw 7bx4 Dn"FD;"X^tDo(wj>"oGG@[lL&{-OR".[("ٴW Uyn ._6و ''ov+Jܣ2 OPE'MIn-IBn ;x,jB&fLm\:w:bgڿMԴ'c[u]z].~T0* L_(;_ut{ŗ84K GU:|Н*$*&]MV 8x@5Liljy\UVE5NAztuJlV1A4YO3zZUS V*G%~P.qFlNFP@EZe:yqLK]%6VYJDisS1 vDlN#_8mo4cG̗ 3%Mo7Sӑ޽/ ΊNhL("<=_;D*Eqe s:Hn=P93i/?o^\.G@A;} V#h;v 4i,U=j/mE[d$|Lm t,pY^஌T "c-Z@ lMKfX|A:&ŕr.s f003и/yؠCͷ0F+޼k8CIkbID0;8jˡdnkQ~L_rI}qa[1vK(dֽM6í2 =Rr;BKFW84Jv+_4M,}(@!ʸѠXvjp2H{Z=D%H #O*;B3381َ BK=OOO[],g2U?/7`q%ہ.TQq9t&| P2 d4WSs`fgf@%gl)gMm;I:go.t~ bvG1xqˠ0d>pb%[nOPJZ8j.leKᦓWy|x_  xj^}3vSB>.@]k??Xea` rIi&euu[D 項U|uIInkvk+O >4'B [Qң-όN<+.:iĒT[UT' 4+/ ;Y{zgͱXfþڼ|>:ה!AfP#(_~B 7=D9@Xx E_ɧӵ5)<h"ZNGqSxLH܌ӊ{IYt|\jL5OY%ˤsx"u7߉)lkf.+W, M \JN\E:p7|PxJ"DZB.xҮ^қ[%u=LRp'P{GμO,|hf1 HVLz޴JWgfI}Ĕ' DsCB$aNn5s>=EDL:'F LnïN^: %\$NJG-BZLn| lۗײ1C v4~9 |g!cJd@x„K'4X9 ~gާ{nh:2sBv?"ux%%U[=,`Yߛotf,R~SGe63)ҀK5 By=Z {@xPc>0d8"0댶 DBK7m&67t!87#P#3ꆻgv[cb4 G@MF%{ oBkw0#_ ŻuNvQX B@lOHS~ MH׭|-lUљ-*W N ]1ќ{@?bOCUb[o7]B*eަx7AnPSXUT ?k;oC[k6j1mvtɼWq>tskF+α@3e5>BlR'2] PMq o#K90NM͑zuT O޸#Kj52tOfX\^~ҙ6$9(g fM7kvZŷ@V=ǴcC_{$;" =`BAIR|TZrcww&P҃ږ&pnxޠŤHc9UŗL7w2n]dxp<K6 ͅ@KX{;q#/HM*o9`j0N M;B n a0ʅpYR7h$F$lhxC#]R6 +Y4 Qb;ݛ}HqX)s&ְTtIow/A5CB$:+{.U_! w4޸H୰ 啟(RՉ}g֚ ]uaјORIF0i;H={,` m)#Pkc'Րso,SvI)v:& ƁN455Wi۞C2adx[V~YX] ׄ(╦\?Gi}\]oU/ Wxs:GRC&5D=c٭ o*(B.bAnc\sNK/NU';Oh}{:jͥ*2WZߩsMJEOa`|vDu\)Y7_bMyΝ'hhu8w`/p(5 wa[h~es#:7a'MyjD"m(Ŵ)6 p& qu@}%P-3IyDAO'@U;g!W‡nJR%5V︩+tHI v=G`jBvNg+O=ig t K0)@ t5bܮ"s2QRϒ|~+d?c$x fdkH#Ev$'"OҢv^1NyF߆w0N _SP&UM:2'EmM#Wx2al;N*~7 /.*{¬}7ʙ>P-k?@vݯ\uwO%׳S5F9(hx#ti7$9gM=]({x8% O8`1a#8-|k+^iL eMV*~i+~!΃)_oˢvRd nvy\#btӰI9.Xp{FHK~] @t:9VFL ~kZ*+ ձчֿ:nwB[iϺNᇗ$PuE@K1If`d*?Uuò]n:2Q Lǰ^}ihޙ`216O4H5)?fA9oΕE=?>L2}T+%OJ_=i$'s6&UuS:iy=,e#Ǡ7U/kMJ4Փj!db&}cGa_)2y]ʴ`a!| LPЇCt:ӟqx_ .^h]f+0ᣏΪ'ͦ )puި4pVa3r~YM5:@5鉅3ʹ)hbV 5&HG-@TϮ{ FH%B d UTت%O%ISbrk Iz,F0>?xY9й#L|e 4o83đVL i+Ϋ$v,i\8Vװf^$jND"|M ]L]`.ci az")%Ύ# 14tN0.Dȷ9Uu8[oW6`F+Gs9`ԡIO(B,{cK%&%$yrogj4v.rSJg~L <'*Ocpjq~|ߛ NLn/;܊޼&B(t35]aL v n?G+с:-T{}yN6(9Ķ#sy_9׷ y$>q7 I8.y2Ĺn2HK"LTsyZL?<@4(:=JFWujV2wI0MI!npN3~FSF NڢVŶz ˲.Z iF5 k˨ Kuk?W\ѿ|^WWgRa-\DK{pakLB}vELIE9'Mx5:ke&" ĬSe'2iܶB;%تPz[;YF_rwAY6'yZMz5ȉHA]MŅ#最Q9=*F gys2(#hD@]9Rvf_b\Ck ̺5[ęl9nNTwfӖ:K%$;kaF`!PYG_BzUA1{1 Ԑl@9#n!3P>Sp9?ccjbIG>,E5_HY(ELF6W=\m/uVh^7ejtBe}E6kHd|\#:"ꏙk:"c6"~JGxw,E |y #Oګz%äjhzDX eږm_ r1i/oþ2efG& @ȷNS 7O R PeáG + ҏ#m AT2IydL6Y*dh "!)Cws*-ׯىl j ,}PC@䘳R /FCTҖ.5MO]=4ū\v3 -:Nx{zBv͘DbHHb)8zzoNV[f09yoο$)H2?TVuu;ھPNYdO_bJTzPj700_=h)*-VoQ,iuosPi&Q7ύc|zspB??ӗLnW·lx`j5xzMj4_p?Xݠƀs|ʺ5QjRGAGf^"='ɩXY]m10eY{SHFT5m&2 <$3)UnR7sa4UIRNдn,8ne{.~ %9~Z;p݇$6yτtX=8L⟤ =PNת۴i طmhvŬ/gbM_OpCHt5`IH| [OmuI0| ,T^kfCG|/člI{m̪F9VL^ } Y[@]QPXIX To|sE +@,651 Ω H%X//ɸU:qrlg}^Z\.;.֪>tY(d2+Zi [Bc n39GѾMvJ422ۤ<= _)Ԁ r$ IxyK44zt*9H\WLۗ恧05`-Z0eNI6vnӥdY(/dɽDÎP(?G?p#= i)83[Qahb4ff5yd4# K 2d;y c^\\H @u z'sJYU6?z#R@.m8+p)B[nQ- iTk7-I8$:_(i+CjoHNƾ{Sa3Go/5 _[ۃ,e2B?~kOC5fH1oc1Cxx*ʯztİX'mp=MxwU9.gJ+ԍf^E!5!#ٗ5Otz7OQw eE[*qs[HS );7LblӆGp3.;gHLq I-93\5XqEw/;9tj߬l49y}u#J,Rȝd!S kP={)+a+[aR>-u s 6a>qHGX2XZ(iu= "p >|`tC guHd|8O05,L9g8蓡;#eZXfQB6(f 2L(#4R) W 0/I IQB1Ssiz[֟:L-RO3W*z+iO榼(eQRZ߽ Rf2r܌OsHjB`*/^YCB=nLhPn@'!F0 nU=}X )amH]U#ޞM} d:JU*Gv BJRP a-Ε}YXS Ot05۪Lg1³ &7w%L*p(t<`|AG)a'!~3+(a衡m۵5A=3bRGr!0{쇔oPdAW-HLČӤxdlSGL3NJ[K6ֆz2Lu~QާJTSQpeHcCC}\ d؈9#o߽\×okuml@CYh40(Я>쑡jfҨ#T+`Rt-uvԭ>6 rClƶj[ǫ/f\|b`Ԃ {|t&&LLKQ)~|iJQÅ?)Ė'Rҕϟ Y04OJ.XH~cR_ Bsp%3=4st+y-7wjrPil.Z`h xU$!gf<4;u# 2EZc?E췲2ͧw*UNmAEF[Ⅼ2\<-}iq!-%3/eɞg΂;DPxsOq&m.i{Ь%7W~ө˓ߑ"N8w`K04)P{)a$IcdeO;iHe]"6ݦN߳Hȹv4FoCS@:iJz؁hSWfhozw|'"5-Ķb?>!YrK>H}Lʕ龕LD^Zo:-P<_}Qo:7޾X)k\0}> <)혽E0vdE׳ɜdT^QnD[ǎZ۸WIPgW?3D kz:Q6QSLgnWtu~ ӕӜ趴xWb*lH~ɞ~Tmgg{BLne^}|DC- ǝzZ)L.pBh^(uMP_aGS^j5bˈuvN:]|7%y;%?' v !ɨ;+?j\^`q*4nd$MxDGk"aJ́2@(\&78` &2ɑCoQWolX~^5I:;!:+~u'ɕݸ_РjE eQ΄M̺t)%"oLw\ζK`2L F]/{D:]4xthHI lE[(QDa;~٪#JHb}9 4;Jӌ U9J*/lӭ W\++N0øEXfdmo$wH;\{q䓭Umq!H/>to'`dQE:T^n5A38`tcHސS9N@^{p'u6z=A1ZDQhK2$V|~u2(/8n36FmI^TeK:JF ,N&M@&ӆMFq;`l 2.2G-slYmcv/IG{kQm&01ϘQx5X$ѵ ~휨m [p4=Ũu\5!tJ̍m{Yqo~mNPM7IVrU VEI̍6!7[ٷkEy}y=߇TuBK=L|qBMx Zgy$\*cr -2(ˊj\VC\#&(7\B@0Nlkͤ2 TB@%At~4{qئ0B *ۄwo ffh\@;s1uU}lci;c_%.;:9;DKb@pv ~cP| cE gzʒj?T)+AE<sAilsi2WQԎ[3gj9gT|3Mj:d0up5gxpr 7*q>64i[%d!nfPE!]e }n3xYW{() ]a$bd풹_oBȆƯ*Y&m)YjrZYl9r N}R'{^v.ڜ3۪Jb%6^Z]__o>,+(R K1ӿ 뽩ZFA{1n=초Ts,xfgq#o}kRNS춚700A:$FZa4J8^S SeW\C`߰&+CfKʅߧ:njH]aکtlb>eʷKY2R.拦؀G %2b:A4,؁φ̘L*&<=?, i>'DhXRS~2O1X/=-]Ȗ?6ڬPV :mN20iJ{-aYiDLC}ӆνQ<ƜY7v7ajwHuFg%->]$0MIoycY[u8[ N#R3985X>84k!8?<\#P?aXEf Yz%(sk0N@)0;A  9wW-TѾ՘أ.FFO5`g4MW]TbN\G /!p2LTwg1(h.XdW9لPM4Uz#ch < (Thco s!dew4[[CoXaǐ5, Voi ^54Sg-^Lm3y9j UknKsF}(nfu2Xy,DvUEM3QHi u$Pl#gfC)ݝr.moq03M{£.UTш||*wxT~0w /KdEXo7z[Ħ5v$ꯊuNXG 0>f~Uo.aN%3 <{. *4,X/5?ui)Ȣ~]R[ɛR`#^c^j(:S="~u`(LD_im)Z1o>i+cBB{cnS|Ga>-RWv,h&WjG!)LL<9\kQNhbaL2NF?TckdB*|0Fo!Zd,xwh@|{ {LVVGT_MBkEUM[a Rc<3IK\u>\ߏI8?qTTqi V[˨m6.\ZYS`ߙc-dlOir#=KU<<ʜ)Tn36݀S=SGqjl vYc`zr`Ok`\f<$F*uZMs,e* @[(HQu5L3DkQ"kȤbVcӤXKps/.eȂ[ec G֝SQsix> 1t|um7axAo]Շ Ys ui̓+ %i-A! >^ȝ@^Z#?qZ{@KW^Xh528Sږz5RZDR,>}WR Tdj:xhy-U2-@2]eĸ|W}Gαo=Iʜ0bQ8'),~Lf0Ew}<-zdSbfqy.0 N686mRд942x8 Kއ5_4]D'oz}1fou:m8?zu&H9 ْ_)2"Ǧ9l$&ΉUZȡ!gqmo]D4^HC硚z|LjsAunv?yXhNcVQ:zf!nuՒDbV;|+[\NkYYlԤFؗ͆36|ꚅ 8J戢Roc<΍]SX5Fעyҵ%›f~*J7h}(H6WΠ;S֯Ŋ\2bE[ x92VMֺ"vk&y =AěB!F@Gai3RJ/mstt TWwNBĈ½N#,N=Td3<5 +B5\/pÓ?34b . #՟mqA]BiߞQx--m6dr}302sRz8[;eŒCY|/Q7#MjL.+7G9*kK* BxB/Z m—*nϢ.B8x,f|ʛtJc0g 6l0-m~t0u,tI{Cѐ`pE{k"ZG%zPbULaD"921Z_aM*)as/;3iW1\"v*;uMk,+i'+/^t4d^Bn>[{O $¥fU)Vf{!SW:6]nEgZɅ ԳɿpL^t9i)8j*;W%IrVnPnDl37' ! }@%!nuȯVdWp{Pۗ"Sٜ 6BPObbhv_59TUҡ]Na󈗱5Ea:} Ԝeb5!cHCusPʫCnW5ƋǸǡ;Eeãv䀢PVz- bZVQ.]a%3:U_  _/sù~֛`ᅛ!JZʧ{(WI#uL[گ(y8VxU)- Eap`]E7lΑ:BO~\QjOo+ZƹLQyX1O{R<`{xmCAq,B0FNf$[CNc\΂ij5 sPP][3ٲ)(_:dabJC_dX,sgݍ*K/\9:3mpXn7˛!/71I( !(YޗV-!qH j̤rY5<,v,W(^2eQ wa8F@kT-ilH7/ JY@ gR^_R!s- N:^YWjcItMj0U(-o/rHLy Bs(a(gJ~E~ tnRG0x>csT{, u$I H([Sr4*b /upڸXڵ6ǭV2 >k>Xm(h^ufW~u^s^ypݑj AĐ\-.:.>!+QD/zb$V 9y$Ҩ/Ųg]ũ.*gLʓS-oa7* c9.؉c4ŤyWY@R)+ʩljHp).#"mَJђ;eki ?R:_O's0%pfn*0D큟sKm6>]wYt!/IOoE*@v=ײPܓXl@`p^ zN-g|+ tUR1u8%}C Hj r&Z=-tΔV"PH8(7GgxlpyT-Ǿꆦsޔ;'wX?ePzOKxMsFԙkڋ6"FSg:Voe4>M]&,Cÿ>;wf>$,jKxFrxnDv>XJG? ZA,;yM'(`-|К\)8NYL1ʪ&qo:Ʃ;q/1W9pG<0ko I[/w Pz(4>a[kD' J[j΅fUy ~VԒ*oOgN״vjBU)kC3.!B[=n\+rDut r`"خYeqɄHVɋ8t4Wa(/F#^iD⟪*8s}X 6g.`R`z떛穛K3l̿#1uP8_ҫ&}v1WڴVŜCu+vsv#7IV$+fL|5}v4b84[vZGFXTA:Y*m/. < OE+4 gH+YE@|iynYH!$g_&lG7CN,5yn_ހ>64ga2ܻ0R`Jrw_!$IտM{ќ=GO7.t+2XN6xY ᮭ&UN,j@cz&Q;%íE=9 gCS#Gud!pEa70.L-R$?P*Z6gM`=W~074}CѢ& e:dץK߾Fj y`?K,Ouׯ&Eˌc{{fkL)\Lq%s@Ff2=f/n6rsզ8bUAzHT&?[~|t;dܺ"Z*fa-Aɢ zJ/#[cI+v`C61g,,ub݆h=Wk3/ >)p R&•km!OBp?I3~ڽpnW'-}yA:![J&v0arDH G+D/Te(eB;d乴uL 8t/W﫳L(tp^U5h=6 jmX|9ӹ.b.βt(~&) qxKհd Lj Osf-?LQ6>x%f 機(I:9 jכWWs@DhTߡ MW镫k Y*m,1}`6b#J&j?I4v_bPi#k|yI7`z|Չ^@`Ͽʂ뚢 LMt5>eB8@]OǦ.*0-? - N0~Zȕg3Xqӽga/DБ6v+|>!7BtpsdS< |?7DD}]Sh1.$41ng}w}& @](Ξj ithV{t5Ki̷%#P2w|.M{6խ5{3ǟ  c Oܖ!1:MRppt^S]Yxd.Sou7QexCXǮáFD6c)m-oD9-)qo~[L}-b;f@jם1R8zc6t&}9bQSB1κ>#j/+SۣB%-m&$S mI|2sy;ƈ 'kn?[^B\f{Ν#KH=ЦEYwUgjѕ[\ń)(2N /B~G"vDh4M4In>l iG63UhFziګKMּz IJ},gH1R@"sɄz^ɷQ `&ㄿ4Dܸ`W۩V!`B*t#tg"C?z* pRG/$Oih)S2ZE}& +!)]UjP5 .pԖ˷ț&xc9ۂcon[d=ߨ7t[l%,l> ?uS1YrAe0b=M==mս0Ŵ\A/G)W PuZ'#<9nNu:V(T"T6[7?OI%^Q27;4O.XQaO@UgGMdx9~$K;PBfpBfu%VG9/sRZ1~jjVԋ8x鮅/|srI7]E}\xU쿷Lyy^.B2%%/WaɊ5"gtrec<5-pl(.]s["O(k'{t6{ b:@]X$%G =կVMv,Tx*<]$ϩrVvu B WnohjE@#w`QR]mOyؓzV7$U ]b@sCH@iܚإPgam VAQ6%4x$%W#*iUh],b]fM@41oEA!uaY.k3LjlB~xK*eF=\dF}JɜbnN?~9(*> \ej`p(K̵舞4Ek&$v9\&q,̯xxxpV.R$ܠR=3\zxxc=*%?J*ц$ ē? fj+H\ɣVm0W,;VLKIj,UT 1mhN'ljDSx47TCN|SheY>YΧj]MHNE ƕH9+=d3ȅĿԅn:tG ׌'^w{bPr>/ڼXi '++13Mkp{F'..$i:(N 0\^˂}IUӹ?UGD~ٱ11D%aVkxZ, dB*bvA=LLu TT}[YnWNHh8 UlI!צf^4_Z<\gWO5Vsh09_GdY-z-l9/.j~ /UO5Z6 ^fgFߔ`:Qvc#xiycNXڟ9T}q~vmk|{9ST3 w'։Y7='^e۬VxG5wB $9UKmaTՍׯ`QF(MZ#TC0FA8w4BKRLQagY3Y@`1[E<['_wXyCV^3m=ք(@C֯֨R-T&L)9ޜ˥¬|7䌵OefEE`U!.[Sm Ta,I)Ιv:fKh^y]2te ,tij[S8B޽_dW|Ea|[S9U\퀓I+a|U` ] y{ wl gZL',zyɣn'"] rTYc0?ꆝ]6s??u}Q!{NP,*6򪑤0^ISP@ 6A8~NgC ='nT_bIDJzZ(1!kWk ͉'Eig2/6dVYrMoܖ}?0 cUdrxY oLe_sn')w1ˡ:oyy\B٢Ng %K&WF2m:g]+*85C,z7<~HϼMcй=tȹ93\0 /|e=Z\btfI`f9= kxI̪ӣ:^r`x: w~/š"$Ml'x76!}/W'L}&޺np-8-\rB?IY!W3+{'-`t. ?g>rGh:TPȨ$]'%"8|լ~ۓdljrx*ΉMrȭf >1xA:QWLȉ|9 N94[4@RPR<}78 *ٱ`V rDTY .qŒ|jy>G+i!Ri2 ?,>]Gg\^ #QAUt|渤"M<6|)V9٪$:0aC|ʤaeq:LvC%sť֥#,C-uj I Haւi+RQ}4 0[:hg & 6"Q.zk(ު印 {?Ĉ؜3C?EU\2X%xSuQ>:}DcH&yV=yR;Bc2>}Vhk\~lS|.3F\|y2p[O\(( Of ý(VPp\~Yb>Dp6T9H'ܓ^UOja"/5s/U Z5uldJneMͩvp` Ęي0|D*W!>L,34U0C" \fo8X p4~JeV*=P/p M4E*ʁtYV7"H_;n*Oz[b~a;N T:<kD >FS8GC8UQ.Іx9""S?cMEqޣrW=C jC(M,Eu4 ń 7#{sK;O3;=6H9G%:T?cRFCE_ʐ/R\M7Z;RҰ˰=}RU= %!hP('萤WȉX7B|I'rE+nu5a`5 ع&wzIzo d|?ڼ?< 5d+0%0p$k%qZخ)G/mY.M2EC;ySP4_bw N\zEqCcuaz/ZAtD<4ECC\M~؄~m{<*i4ius(neaqP}.2z1'D1z^rM ܧ:](p^W6L4{z}܄;I0y3P p /<iSY(l32&]QI7ԩtT `VS>"Tl>IE|݄'HeY>xnI_n>0_at}Xȟp;&ъ_'SE@%Q~"bT*[/VFD2n*m;3'_T#O{@DCRR##:Dž2m5Q ,`[̶UXR$אk+]m"|v;fn X>úsĄ;%|{B>Kfᦉ,h5KIoLΙpᏒԏz;Dq }\U *焒_FqP$V-5zc J5@SO1WfI]")KzFpk5$JV)a*\#`-6p(lT;_,.k%GZbįg߃b򪻤2/~ǁ۽ԝ's4+z ak,+%i%q^TՙYyl*s)s.ѐOџ睝PrS&4ϬD@t e;9OB=6l 9k͒=w]Y.dҐăHqp"Т0H-x ** x=XȊV=._g9$l`/Jި?*!*4k3[>VR,I0Z!SB8CϤ"wV` ~!F+jc+[[L-WYs7bQcS !`)3G5^`q76 ]dݒ@AFy+H}4(,Nf\_ZOQi3σl(da==\"]V&xm)1YYv:%(rB|;JV;Ĕ\/VHT;v e]M: 3 px^z)yVgxX*P{fRm^%++֢$m23mثkYKT+p[F0ߗG`,::e8XzIX[Ҫs_@zq?Xi3)ShmF?p-IOH2 ^ع+KA;]ۅ$3p5S)3/ɭ|_K9!)u(ZQ1 :\mZlh?E1|v|y)qVryT]4H9TxV;$k1 cеZxAӺI$H> T1w_xXQ@~Κƕ|guZD]2I*]|8!._'P$"Ju,)-*RPF(O##NTI֪d咈} JTHI3:&!픪0N"9exߗք{piJ&v|z'U9k;I_X} )\ђlH a0>IEP(x|)O8z?=rϡU}%No@K Ֆxq `22RT65` k2 ܟ`I"uA%SQEU>e>dF-4? IxiٴP#&h* `yB~%Wts#2'TU`yъyLTDqf۵1 >%tu)^\BA3mIR1qa;"@Q etn1ZboH2QgNcRM{ЛgRRYpػ(sj%yk]~8ǻ~):+xd>4X&gOg]" K!h)ZY.&ު>X;yv i{)/@ 5,v_(fڔ&|%O&:Vعw2Zֱ7De?kᶶzO*ـ*8 Z{, бLK.y=K!S~Bb{S#:s)Jo)C"G',hKMmM㱬ʢ-LM/';^SS(ENi&Snz`cmYֺnsellg{61<%`:"/k3zN4ܬM""Gb+5qT'[ Cqw HLd $;"ޮX6:]>s ,mOnR~wp[_vo꺖zvZ:?4=1)j<޷*8}O#H|5;ԕWX}?twIesw8\rn((ZW/`eh9ÂUlSePdƁ.>ۼjr)*XzWKbg Q~Ts?_Eǐ6]NE J Z\ݕM*zL)xfȞwBD$*Ry܇M3m hv+ TZuZxLXˆrMw+ޠ>W-cM\1ՅlrYɨQZArCĮeJ؞r/bl9x*V-IsΘRϰ=g1"OO82߇O:$e*F:f ;>Dȩ!;l&KtO|\LV3uZEut2 T̫:,[#Fd@bje7f.d2r=p7 "Hc [ D  gSPn.B=s/o]? >GB5T(w]38«|.Se7pf6[|ڿ!t-Žm{% >d:+R+c%)75 cue%3zzQKp~QT/E w BMlTd3z(?j㩄z+nMr制f4F1OR@!_Ѻ+BT_9TօJNyr_~ 4T;E]"xi2ejZzmX|Ӧ}mb*3b,snjZ&\+$azn4;a> (Z3DZ=^PkR܃T_u+kĨ+)O%1p%vgoRo~%!Ľ;<;G<@wZxȓ<5/\O$ ~<6 ;X/yw,a[m_9nsjD<Ļ OuT0%9 ,G~A[W"F&ㅿzꎇ6Ì4nL.uV3UE I%a"$m{ Ffna./RN&1i ڶdeз: B+vX×Sdi  II-fu(p83 LE%*-D4Ɋku4dп_kNalMaĝiNӧ s1Zt)}C#edI‘?KxNgKplF>`>m &۹Ȋqf0#ڥ} @f:Pufwe? i>ep .,wz^-] n+vqAB-~pS4zbmLˮ 3^&ةz@σimרᮭ#UNzNz([Ɋ7\` sjn`+Iy 9fmIP179ܢoΘ@~c`}ʈ0F'ϡ:1zz "?l<rCww c1oX܅9i.[bIu%Q*QjqBQgV_ yaՌ2-P`фD]z9.b)ؠ0Wpܩ6v_ly9K盥]@FtF3rl|H5p7b-Mp">ذ_ǨR1Ls`͋$ONЎP1f5unjd2 ;۰Ԩ7 N]s%CIzNJv1Z'"M6]Qm/D'Im.bM20T%oVvXKEէi/2||7MS;s7gvLSYG$ тeVu>qVX9c(&pgi'ϗŤ[r)4{2ʦt;^/ Zj, d10nے&="U%_ 6XQF]K+(jQ]z=pZ]uБmG)ϩd3M*+"?(\z2w{V̷Km2?7K޷Xic x~I08o饓#U]:w g ^_^"2PcXoS9lf 4S;G"gPMy ;${[>1ѢՒIo' j,iLݝїMnpd ,<v"FMk WG&t{o5dW EÜ``L ]*J8]85FL塛dbR?#Z;RIVZ}Lj~1oáڷ,_St (Cv{bUobN+кc(Co.^%:6whΧl}4r3$!aOK I\1ݫ@|{%Qn ,$TLGm؋\oS-g 权He:'DZoe`-.V.&Lp,'HX?4&S2<4i (w@@Is< @I)?μ{=ox.uY}*ԡ]0Oe:$$9d$2UgxW;w35$&+gO~R*9)ۿu^%W;5XǔUQyfʶU*_(rMkU_?)f{j0ZNo'0:];.D!388$3d;n3xx,7"u2&1WK F^"hW| cMn#`LA}P .ڞY䎢Ӝf%C^X6*:]䵬I$0ߎyi3`H )RXL!tν𠪠g;M3Ki WRy4NQCpaOE=Sz/b'7rXْ<(?˜UjE8} KHG}ں*J.R |ē*9""\IPB̢&:H-6##EOx&ŃӤ4ꘆAoA,hzDT*iSd TdZ۟]󍲤7^7%) Ev)rRM*!Yxy/@ Da- 5CR*ڵ_/sԊ)c'0g垦Km5↎h\Wq~^=aX9%D,>ya$"o+`.4w|EM-\WЯN'1]1Mcd.l>5f{d/^ ~Osh)ه ,Ili*j-C"$官ic(a50!njdA, +9z'tƫXSv\ЄkI093=Y* whb*_p񆙂 Ww %M/8[9.'ΓųT6Jz_tdAo(5AҕUYn Ȧ56£oWL/lrɮoqP%MA4~R2q9T[WM;ʗ#kSϫM0xؠFiw뭴Cw4zG唿 %3ꇥ RQ ~q }KRr6&FD6*=n6Mviy uD^׀@i@p5q6f^/Te]}V؃G250)ۭ ҝ$ 21U|sҵcNvآd(LHR=sbnHt}Nv _?K37\ o^>\yiY*ڃݴ.ׄ79nU0Er9l 1lʞ<=\EW5@)J:=LjJD%*UiU3/biG[zr]k i<rpW~r6t޹[~mewR 2v8jMU>Tr }[4eKOOtz *23cȵŃl '0{܀ۣ~TA(w^I0^W$yFoNvD)Re3oqvLlOX^9X0h &Lǘ2Q=&$h^ϖ8S^d&m^1 2 ;%V&!^UZY3QX8$3.DXʴC>#od1#l=:EcP" < 5B=$E+-I$j߿)d#> lY\R (O]J4.%\넩"(my[ziΚQ1j nLay)#VwHr7]+I@CH2@x ]0J% EFqkL;h~+l~ HeO0k6e'DbPxcw>q.2᫾c +RLFp,xKszbI3NR,#yja#1,UE>KJO> F1|('"ep 7U29lBc L lO΂X0FǤ`Y!j؛>S\c's7-(>$Yp.cYd2 ʣpwR"5 P@)C$\08,U1@G~1B$3\yWUdaG}5hɁGB>WĴVw$ ] Cv^Ftp&$s$뒭FqNȂi*-V ~w6>-܍fqJe06u(ng @?:RŅi*={xXb#YY9ȝd:c0VMKO]0!|"gTT sZ16w-30j~yŲ~Zk`|*vk¬$JvS;U|9vmmsڅ^c#K95d}ynAȇYǠ;iʡNݵ "<ɐ̋dU7'F&~YX엋BN`q׆/}ײ|d (EH |mV񙶜-D6m&14{^xXWi1rmeTӵ"i:vʵ 709]pnpbڃNݵAy탐;6ڧRWGO'=v*ň S(ߍ`iq5˹Tj5T[: 4if&F8oMyt Ї0N.|<'t[.8voY  96K)8߰&( %W%s1^I?:ecy} tzl f wcaD4Z8/kk!վcի BBh|LhO/ͰLhUEw%`*0iF?Zqu.mj;mI/[^ F_+2 HG*U-1ZUigI^e`N8(~0gR "WCMFxi!&l>J c!V>C#Eɦ?/ (!TimhMMhҮ6+p:rjuW'9"~%RہoX@,)Zdn'Ʊǡkz/]sQ#!:"W=F׮'GB 3572LVR?/Ch2SAx3qWXerl a6p)KYv 5EA7BD9s<{; G$-nC|_:ͼPuN>w ge#[`xgQ*T  Qn74 A d5n\Eh_ NF|c7vjŴeM.{xibWp\z3ӯ/ =cGn8f*N|CVL;BڥHMsut)~Gpu?k IeÂSd6a5fpD6l Gdf\G`p.w7)yQv¾FṘtrZ"gjF5&xTy m"AnͅHLa5O1Ô\+?66O2tҠ; )Հ|i~U.sRw_<7mX+k4b^M QzExCLif#/@)0p7-f|课oG!bٯ)x{Ty/_7+$@H !D]Kd^7N1H+m]nl KjЅNĤxۧAܼbLJsg"xًk.kUf|G:ï\6yVe7~\ q mM1k ,G#bM//ļ NH11-<T!M%K<}lhMr@heb`Ahcz(($p`_Bnja, #4w:.Nꛧ|dC]>1l <My ]d )ją2\ Յ+j}2TOy }TԻϔ>.4MSm/ygnI2U_e[~Fxv&A&",;a M!VY䘴 k&V[i,_\:,R^FYEIlPЩt2q x{6%ozyk&sOɑ?B$;D \ jVENS )Nv!L=%*֪@čyZrO#U2ؙAyrq%nˆt_&V,I3D㖧WqwyDOh9 _jumFQBڥcPxYjXjrPz^kFAg\ȋ7wk{Gz^eIQ9&(A]x?\x''GQ:gᏙEݯӮ}T:9HzrI H,/&;lჶ$" 'T0e:q끕'ݮϙt!wrq?Aiƣ?i$|ྒྷz_->J3TqxĐK]@y@iQI%<񰍦$+I3hX+t `W\c(H* .r[A[fp6 @Dʔ1T uzХو|g{'d;OSF#S ]tI)wܩ"ճ5ȽG(/C k'<ÎdO-yRHwgy΍%T ,\J ~ԍbw}QĆ>XMmuYȩV;kyt ތ_p{{VYV_ D7`[Ze甝lj8r@$[ ta=\?}đMJk9ɖهQ Rόk^+a9BYK~YoPHo}*"v`SϘw6Nj=NLAEl"3iX b3idKUfU8$^L \ܥ+c]76_<R K p;X!G\+fdC%=@ >S;u?i*6g'ɋ&ED,G_֍f,{ahەg2o.4S)!UL/JFWn?}ʃ@oZdq P/S&&bs9ƾȲSvt81"2>fNr9unDIDǽ bQgBEl5KNrBU{tkr/B 3Vߛ KxR4Mc25׼Jd!+mOaK9 ռ鼠$+w;ۃX:`';÷>[菋ox0* iƆ8^+Z}=7LoYZu"YAv۽ 4 y# ӪHL8!xI[nQG< KT4J5GٿF f}ƮA$ .bdc//{IL&=IvYQ5Ԙ/ TwXlz2lFQ$eB9O̚0_ y3ylqs?+- "Wˋ v4;Y9g*~Cۺt8W^3- gܹ4\3^Yܚ$-ǗRP#PfldFIPnר3SDv&+-h ,DfKil}芯C:$~:rpӲ!~eYGT[4^y|A;X1\(;RV'uj^$lZ)PSj$xu7㺑數 ϕWE߫=}^A/0EBYIyHCxA՟"<K|q|r^PpF=fuo#+"UEBcps LzKnNE[1`)fOLbUc˫0#_7,$hwi2j$#Giuީ?RB dCj؃!k4~7ƚ .~7}V#኎?K9ɿJ,O9T(|}/(wAy1WŌŰ5DK4yژ$Ӆ _:$th$X쨋Lǻbor sz J3ta=+Ӆ '1fWHq蘆Z-2^J+Q"׻X3"N먡+Q]4 Rh01ܥձ0-2ǖF ɍ|F-wz<*xǬ5'G%N\T[1S4"c ]":?bF᲋ |`M5 _EGAÝH7ެus%+Q/z59  ! `,M7~A") `)Xm[P"GYΤ[xG;0?ւ[*.T2~$^FhY_ܒ'ۏޥ|sk`@h"(?sf.E-hݛ$&;ؽis9E&7FϞtZr'`KJVd͈1tPjϑ~RKƨ rBhxs  =|.CMN*$~h6e rχE}bEͻ81J}P'[FYSaP~U:Lq9+/ۮȔ3;|z 5l'8[E5.[eGL*:/Is`I5y÷⍼,QPbջ*deh\%/,A gvж( ļcDh)@ͤB&U*+ޑsԊ4g4.~ǒ%i"nP| D*k p쑽)?7]gl'p]"X3?Ga>6G}q[)5uT_tҐ^LR5v5]#EM&M`phqSo^z)&d|ԘoH> d'HПxAEkomLNG#0P@ai͏i2dbh.f^&0<Ls!{0,1IݿQlBl1慽ˇY٘!Be;6]ĀMai(AD >}IMfKn1,iHj8*Ki!gdڨ -0 =C5pzႠ@06aqB2 g1ȢVS8b Tb0@[BFl/q:f  vTJծK#a{o6KW e)O OY%dmh*c_~T`P-:9X^:}:p`F꧊02F̷j0Ka z`{BPV軄ZE:EhNE:ȶKBֲd@./Rͷ> ǭR о +@ӕ{Z`N;Ӄ6@Pq=pO0;9A'ES!}fP@~ V;qv N ױv#nSκE+kIU?nBs~$D.F +Jzx r_dķ ( 9ԋ|࿓@+')-W8zKT!ƞh$WJ=^+7ijs$iHXL8 ukdأz%_~Ypz vfPRjk-̴ MlyB7"]{hFnD[n;@ 7 3L,nZJu1KAm$l* z@ur6H{p$myФ,GL z_>0-spYwh5Z`^i;B-zxU Pe*Q5EWDMe}!v3i#rfs< P*G!QFP31xn,W ]=A!sB=_ֱ&Uwe_R[_xbK YxؐPR> x+(qoG+a|c#lgJ銮&$b #sIdD4cДI||ɻFĪr)? ݿ $ZGV6̊41z2 3zRY<#Nk[#'[UQe.%o#£è`)k V#vG|.)9g11M<ĤW4O³t˳D= K^>Y#y|}k3e r\`Ba"`K8{fYh>xWApYW)kE:,OP\{\ʾ֟4)'k㖮Ypg]#.D!q]ޏGMI^mX9bQnF ix`4<<32L }9tUŜt:H(qbyt-GYwB%ik Ԇ;&'y v76.e$=Bdz/ ~6&h} ɔNRDQ)݆^g vV ڨuoKy@<@R? t&(Xble㔀oI WLbZ,&c\eyWLe6ECV['èYV:MMP` %˹b YxC1ք3*/ hpuW+:Y$A0y1=Lo&^ɺӾT7tm3|B+ wg\fǜ?#cuNXߤ_r=;e: =WZagB"vǺqXnk]6!F~4HsoitpxwXN(SQ d]R3("hbj R-F0KVTy|hYcԉ0bouUzy+9j@zOyi{G#+fW!blF++vȠ EnNY;5 q|ѝ P`RAVAl `6o% [1wGrZMTc?uDMKMr3n׸Pv +t;r',wƏj/QDjX$T.6)V:ѭ)^tsqdU/; Y 8vfn"}kB !14Yk)#lRC35HqU~Ŵ/~ނOaaen<6uyc'ȷ G[x1<9a^5p 4. G63,0z?2+q:}ځ,ADۧM"ȾA{+Bܦ aUQb2'6c.ت?FL!Pw,+W<]OTL:M{YrWJ4ђ%< ђB2kM[KPgg黋h>7Jh5̄M>pjJ( xzZl@KIV,5eQ>nl+t&e8.a2!z lj8wh~A5,>(8~5лghb!NYUD?ɚTCvOk|pa("~7A*֐z([, :)vegsjd&Βb dUr5J')҈RNF73=HE&I O h4d9m*8|LOtUAQhOt23|r_Ir"1.|ؒy@7*Zd4P6v6GK"4O%E+а3w1EbHTgD3JzPgxCOۂN 73!dNy$ʈS'GNBIV1HqPezCόjR˜CŠJ%g+l=ǴFw#[K-G e[*`rhHKnIUOީ_;n0Ai 'ZZdFz)Ag4P)LMPoѣ:H; H`-VXv{t:Iшˌ &@E@*ҺaR6,@<3g*2CIT/yx@n`,Ӟ;cș3f"V$MnR,aeYދ)3:et;Ry*|^N~$CyKlԙU~,>5AТu(_tÀy[!KCeO=b8q7עM6Q8,˃EP鋩SB [& t5Fq: H,3ɆR`C.o"?Ѥ'X:QP<|$%R Z(q;/ -r#KՉdrl`FQL}1@mmu!_pA( ̘rK)\~!2̲i1K$xzQېH8ZYC/F{MmISǵO*'ywwD+ o-8SVM#F(O)JK Z|\2:'oFўޝzDcHz[Q?hd#{y8acjQ;u#) Φ*Sb>m4|C!f]isʐ`㭖y=&<(HY}ţ17jK&r98Z-)^ޒYÊXh9KǪ090GDNjx]N㘈76Ȥj]`> CaJv g=3yP؛<h^YRjǬv*X]–mdm+sU{Tw yJc0vD0̜/)@m_\"^\AʟlUʂR P|K^c-F~Ѽ!RrðFTty(Y4*У4W5YЍ -x,K l-_I8HeEJM7%&S+3Ig_~y:b! _i2{2gmeP}w}wA{i2=9lAػgOZ@KzT\U7y) 5ͷF^o:fz?OKR o^8A8ΏjIP^af%Z$ΙK=!;+@B|坠836.dB~ѫWۻSQS!7HiW}OhyII#? J5yms+"˅P< [kH3-1S<\yɵ^4|POr۞⚹VxEeQM1( Cn *.=H2PNvh9#~t9.N,@eN!^JeN XtoO܉nvzgMeSPK%ke$$ڟT&? g7BANJ|lS60mȋ"2P9uZw ñ@ ݃XBs7F3¦lo(Rs_}B^ߒR27Yn*bL@Ή}Ko3LN]fQȁR(zPtSPsAc,:LyiMbB/`zqN\Iϓ9E]V&\U-pZ'{5=An8m.s⟑ e_Mf$| TPxH~'P%+m^{<}ykmuw?kTRYOGXR0~蚻!9Ϋݮy=<Ұ=MI#YEwn Ԙ/|Dlof{[nh8wmՎ9Oc6Ƨ0FWՐ̓lBbS3Ng$L##k!'x=cB. K; u7ؒr-z!=[@I%nχ3\;E67ԘI6[-F*b3 ǗF} pQǻgTZm~jK+! gGjs3Hd-palhhwsBҢZ@?A@_6 1B ,RIIDn/jVsm3.A+\« U 6O_\]?3Iv񿐓~c' r?t΂K9b, ]T B`KejDWi^ʈ"/v$.8CSsW+0(f*~F pڻe$V'bJK-.ݔ5E)4BB2S+]:'pGKJhzQD*лT y;Rì$qhK~ ŁÎX CnizrPI;5zo13g[QC6%xFr %KoV$ᩬ0; =52b %'پJ6҂LObjhhSL!+`9 D1> /`GN8@$[~3yg%)-ۑGZFSGkT|}T[b#ut=pIɛ Kx Ãp))!4.per!7}KcLT b]5ޭESJr8,Hոfj#wxxt-wU$Ng 7pK!fc}ޅ@!l)%_]q=M֨%]; Os/aM ԝ,#E 2vNg7b!ݜ]:ӈC-ѴCHCvsӼh2fĶVi;wثL0MV9q`P1sG棬9~;9ZδUU* P};ϻvaرJxں%H!چXS (^?) o ux ;%XV+i쒴Įmx<)gAZP[[Zv>5Ө#Uzt*ȆkC`9I4; JLrb!Nc(y())xL֋r@EBXѝ ^G%RAZNʉRTSǩM3NeWq40}l jG!gS^PiFZ/*h*iXIO[StO^Ea. \;M~[H1)j{<2ꁞn/Ow~CF}ׂGuF-T H?[#My{T<Nc:v\ׄ UpY7aR9 D@tFgφiێ>,Tv[2+f0JWpV_`Bfϕl,S;&@SēT%TuI]Tqio6,b2ow9kFNCxMni,<NX0pN8 Z;ATՕAAމ;秚LysqÇ?n Jgq#%{cTd|3'aX'^Z$.-%2=rzXr:E( 1s9IiMsܭ;ۄ ׎//PFUܾ#76 E;'I49, |f pR.  e9% g QL .T˔Čd{>G%!#87.>X/B?˚8 ѶxDGK8I:S8lQ^&t5.LqUŤgD@! LUɠ:iĘ: ?9duǨ;dɖpP:lK`I_!>+2+q `/o͎&t}ZqR$D$ѕ -=|DUV/). &T:%Z_@h#a {T"OT|!evnjX+r> J)WC艅,s ' ֣/⬾Q=3` kp{ӯCvLR聆;*T.C#LފՕ6bzk:jFQ(WD>OL`ֈfӶ3%ׁ/6U=1?#51]o&k={+COo0+E-/v3=|D6sod\PE֊6*MTr˼mKk~mR|2$!ٰ-ɱ uٞX":Iєj)¨MEID~&r@{,dxs*kMNaz˃ck~t{~I$ܑf3S'"0@8R2 '"=]yК$O[Hk9@3KL>(m|#HXz p6T/i~mO[]D)-K}]w~0ctR )\C3Jb M X"9A͈kԄަkOKM0$0w_IwWtbz<ܶM.d~y1.r%` ;5-F+xL%<{,l_SPI!0 sb~Q|tI?%~F+nK W` *5EU;^wS6u9]|< SƢ樌,U@\^=k}nbpqr5Rv*NV LPʍLt}3 -j2*{楐^۝y $TO_H!kA󌲿=råܦdZBM {C1+r oM9$+"N:2Əo謶 YZ