sssd-ipa-1.16.0-19.el7_5.5>t  DH`p[;5$ƨ}DAqu^ pԬ?O-MJx4" eEJ`o{q _wV=Z46H \EEp$L!ma,[zHXHnOTK0(3b^Qi?dt'` `x<ZFRpYtO-F o51m_9 YH"DI0orBwlݼf$ʺTv@놢c90}p`&U\a:E ,jJs8"`Zc̤gNvoF fSahUkĥzTׄ̿5e6F XߛK9?TY4iX@? 4u3{]X l'I&U Cۄڞt|*Zi-ŘL3ɡ+Q_-aE9XP?欠fc945c347df73ee0f4e7404cb2ab7f78533dffa5Y[;5$ƨ;.{A(/y3-Rmt;V6-,gc#wWԧ5cgj >ۮ(-<5f;5ėAt$ibnDY$x D|#Ŕ<4(ډdFJ08>=PhU!.!YF'Vwm7ї:{f)u)Kyn -Ld2 /LF ҭ9oc'oT5㭅-4yMT|sA ĒNIBx" n<@ڢj݀J.}:cf('I4U-|WL;mÆϫ*@ ͕oϵ6!vE=8C_n ޝͽeSuG/T!ıb/9-+}`}p?SfNԿ GH^J\t5䒡YPs ȑIBƄ#-UI{>i=v(#E>qh8V)nB mt|.pI J@>=?d   : "?EL    4 { $XQQ Q(89:t'=GGPHlIՈXՔYՠ\]^<bdךeןfעlפt׼uvw8xTypXCsssd-ipa1.16.019.el7_5.5The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.[3x86-01.bsys.centos.org ECentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdKV#[A큤A[3[3[3Y [3[3[3484e8601514017b812fbbf8a71ba3e1ab142fc3b9721ae8a379dd7f48150eb5204bbd3851a2c893cb7b88ad6c65dd94beb79083758c9d007f47410f578390e948ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903c6e7401c72346b41e398ee215483f250001e468620e9866ca53dbb243548f1412a667c8eb08e8bb5bf2673f7f88eb5076ea0e3d40b2d381365b2aef1315fc27arootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.16.0-19.el7_5.5.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.0-19.el7_5.53.0.4-14.6.0-14.0-11.16.0-19.el7_5.51.16.0-19.el7_5.51.16.0-19.el7_5.55.2-1sssd1.10.0-8.beta24.11.3[[Z@Z@ZZ_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.16.0-19.5Fabiano Fidêncio - 1.16.0-19.4Fabiano Fidêncio - 1.16.0-19.3Fabiano Fidêncio - 1.16.0-19.2Fabiano Fidêncio - 1.16.0-19.1Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1583746 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process [rhel-7.5.z]- Resolves: rhbz#1580281 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION [rhel-7.5.z]- Resolves: rhbz#1579780 - After updating to RHEL 7.5 failing to clear the sssd cache [rhel-7.5.z]- Resolves: rhbz#1579703 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000] [rhel-7.5.z]- Resolves: rhbz#1570527 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash [rhel-7.5.z]- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.16.0-19.el7_5.51.16.0-19.el7_5.5libsss_ipa.soselinux_childsssd-ipa-1.16.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=776e55426f1f87ed0aa19d936972db6cfd35c030, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=c1ac03fd5e3a2a023e4c6d676403210e418d324d, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)EEPR!RRRR$R R RRRRRRRGRRDR.R=R RR"R#R1R?RAR0R+RR R(RRR/R RRR2RER9RFR7R:R8R6R5R&R'R*R)R%R-R>RRRRR RRRSq̯pqY .э7y1t:Ejr >ꨈYq3س۷hWiW;qH7 =S\_|YdT$,aO_6K#k麘}%N U;zKlMS7N" $"ۆD&;f8|ihdRms'@.O:B(b{٢_ro4IXkoΦCg#Q[=&%j'<:c"&:`jR0C0 Ԙ(M{yq5SVx^0κu\mWʝ@Y޺-WN(k*K?vPح՘u6aw}zs?-u;9M8`^ٿscE3haz/l)V#JmV'5.^v 1keCsdSԽ8Td8l=> De9Sv++w|0E{3eRn7"h͕Y"0%(ӮGc0uG1JayR-88>$٪<\OF 7eyv>L62æGt5@]U5#7D҆Ϊ7l3؞S'|@}fR~GZ˷#v ]sxV׹+gELDV2^Q˨eN|<v#-) :$LBPAې-epG9+38Vek\<ʨm?9`aGa"0Y 7v .IšU,m6B [PXjgў¢.èΫf<= a4<2sꂬ( wa!xCbTPiQҜ2iG4:$DA $Pܞ}<=5> 8eeo'z( Zdn(D:uixX$ u 6"D~Pz2O'݃;^j*$ڊ=\VeIcx †sTpw2uqD ؒ;b Qm~ N%Jݟ-"`M/bRPxkT@s:iέ~8F ol;  @p4~2,+(i9$'*b*hG.:YbbY.vEZ|~Es=.āeէ.uL#)=<+UkIc<;g5nGvsʝoSjzTx=)_x` b{kz1l ,ϯkP(2Hk'}:Y0c1alkK"LY.v^>u/:I:4I"o6 ϴ3"pQBe;2`{r.Si;/R Dxp{Zcй3 ɧ\-kX b>f"n8ͷru\={VVῚ|[O;&K$I 䒂-C5,1?{)'`mU:x~lR"r4,\}52 rέ{H!y@ƌw~إ;O%2-&MĕDrB+栮YaoxP=rji.MsTw/JN)Z܌זWx4=17^YsgdG|UL3ɤ,usBć%Y J՘o43k,DsALmIm xW-VNjYɋc^dzn-MǛh[L\罵G?1lG\!/1j&*^4}LE`j[h/>TeU˖UB9=h,\DPUFтi8uDF֟`k4mrQQzW6YKwnHb<'J-ۜtJ p}`vu"\ai sXhoFL o!uCcB o&k5٦HeDIn2r)iҊy p(&3FIJhGPOc隬KIPˠ!1kӘIǞ~aTW1HUҍY] .Eg"?5^T"| O5MAh׶8؁9~/0::ԘAc>Bc-Bm ;Z4AMhq>$f 3rk=dizW2Zf^ط7.~dXM݃ D3i˝"0zQ=༳qdjǧؖB/Y/ N KzT|^*8~ 3ͤ*]~5ՇQ7=pW%;zMY:h"E~GiĹssZ/FB9"ר5r_ i N@_AL~V6sH݉dUɌE RQG5S߆PK&pG'csyV ' tz=apj! kv_Y9c1[2@LQ応eAz"/ɥ_qmֿ[1}H,"?HHN/@pN`X\[5$lZZ#@x#Џ$)yni,M_N}x] 4RƝu= 0|"\$ȚWg@1U5a?D Q ^?DI()'kw5C%ND6}1%2KՆ@j7c% xbgN_T3 k>@pkw.a$V.P_2a6`l?iT$~)P:  f!F~ըlʇAe*XK/< 3cU1,&ykEӓN%WQJ3m\VDX7c8r + S5.7=]T=i*BV2)W~Ih0hl9v;ۨsp9;x !>f2v#Ccv4eq٩n0I@`P+q"MŹXˍ>adو:&߯깝l=3~e?밥ԾKV:1]c*0ɬ `5X-t.T{T+ԫ>Yx6pg?e[ ^-(X \h\y6ݐ"MJe# 6|,zb-A@tUR|}&$SrK@ۨ_̪(%w͐e-gʻu}N~R:wwq'c=Ug{1'yAq0P]Eb1S̼&o$9%mX Ȇ6#$tR |f֙uҀe-D[ԷG-.d2`Fm[OYI(|D.ߗNԁ0lC:jR6@NK; 1jo Ƌ;̀[OliuZL ehW "{6Y8/g)P聄ٓkdT?,iSu*{3g=JhDpޔIDab.iA5vOQEi Sl-5ꠝKS*glcZ:"hR Kܔ?K+u"4F8/Lu-Dd)&V.s/Z_ynmw] Kl*-_ ψO=Z wAQ[$"VŰi7:-wфau-,Z>5|^qɁ'];dH}@W3hU ̛hF/4,ܣQ9'KɁoĮm ʲ[`3L`.G:#p5ՅʛjQ7/):@_qRuS(愒Ed۔ uuv&AGgrhqqWjYCwBcnLLfݿ>*bǘTqap'OnmNI /60cx-ӯ)`^;Qu ,{{;GJ?ZnТQY}ڦ}2d$ h#Hڔt˯PԞ'd›r810͘D[u v˿.6 PK8O6r,(0-Ws]4n8N;kO'3M/Ҏָm{gB﬷ٙNYQSb:)po̻m']Ak89x 4Z~`#J\(z#@1VߩbaU^ bfH?b*IJc}tR T/Œ]5O* h[^t  AQ| JS8=zVZFu-?^J:ݾiWw'jߘGd*YDC\Q(8)gޫb+# EGlVtU;Iq 3v)<~X*;X3NH ?ሖZ=L ŜzxB$/m'r1D[lΗ0r@~Ñq7sac f]oLh2UX},V%:lMVpۡmdwxEz^dֽrAߥev7Ρ,?"I8D 2*8 fA GnΈ-!B8-aQcuHEq;3 a#?jhzaZCkz02BD݆/izѮYN }ueּVIH[l~Y%q6oY(No@}-Vϒ؜;'UbfTI3.Y5ɰ$:`5' B rĆ~QӺN;$KT]`ʅ|g4?qy*lDNM-l`)rt44`lO9܌íUa#L?lx d;Ab\'a]r0F ^tW-?us7ŸTWrml\NDO8i⅄];cr.}%5/U[JCv?485.V0;U!( V@_ b UW/u44E؁9AyU vn۬|$ %8-=r7(gИ;n_G2'R8㽳+ <,cW>9f$]l;s'ReprOҹ``%ZUg}Z|j.&灶j}oBx!ۀ!K ] F> rО .kBZЧC &UapB}j(& %x~޼I.I-sQěY\w>ŸF_d[JF^Ty%yc;Y|.ZIiбhcn T ɗsSRꊀB1?F/,' @o!WHZ>Jq%nb_gtۘ J1ם {6,_~#'S+Fta 8۲˱ ?ls_Zђ]0ZWK/ <`Q{Yﰪ ]W <>x0xV%r\tzhPAxʅ hEXg%t~1 2O`soaa;96-Nr.*^-S K+3W %YMfXcǤBf,P-Ԛ]Ԋ3Lk?KFNBqV>ɚXWC5{{:t3IKnMp\v 5sJn))ت^ #K";sxN 'b7`7#GJ(y//rqP7Ļۊ[in!PڹeRQ-"XVsW'(ogK=Tt% ۺ2tδaivbf^[A|!{{ti1=sCv=!eШaԸq׿9.ͧ]GΛPOLGz:טf%c(H*i;$oϸ?nVZ>jg+zӱ K;sB.7ܬ`dZPf~ uRαg ,L.a39CRzYQW{JR{W[Gw24f Dr?1o1~+ oyㄕR! UskLce/[5t=IV.T46eht29Zev,:2#NX vd Ӟ++l:8d+y]ޥ >!ZҺ*(迉ܦ#ht3U9%K~d0U" bXo+EB(W^џLu@/a|/m8}ADOQxFr8W4YJJ .1>p%dHۖ Tx̥zt"*4 5CJ9LHG lp^+ ZHMV$wbksi.5S;B&%lTjyhG9̝W? Z%[g9wLZ)-Gެ.\tr5\Z 5 ד&,|\\t0z69_iD`bԫc2MCpӠTon{$:2QomU5?NAO6㲭r"18~L''{hu_kְյBLn,v)&gw_*h|@ˣݴۀysJ; Gp3Jڅ\$[nv;ϝ!6҂єȃ{ll01Oc™ V8 Q/I cJ9t!HFZ݊҂ MEb[܍Vkk d+ JC 'nnĮJH==vg gCN2^bw: %FV{cg -Rp֋=ߵ>)K\p5ng\3јHӡm6 MR[g:0Cs9u\~N{ :7LR e%|zS6 "hM>}mq 6GkWЇ2jb|Gݺb<8V6{{Z![Ժq +La VDsS#bS= WX쎦xi'B~QkHвiC"X ʆ+Oxcқ`0 b}mi!HJ_fonUFEFHRADzS߱zSCAJХ h3| 6FE ÝPlWM${@>h%,kU@4C38U7c;lZØsM}\ RxА/3#ሽjo0]p8S]7c Й6g*|;dX:-xc>!k65r ^ɪ64B:o RvA&fJZr2֒#.ȋޘIӅNS[O5;Z<} gǣ6)sר3wn8:I׀*Uoe )f IHډ ĸQ80֫; ʓwDdTگmmyď?Ln<ߘXY (I^={B[${,0p37оT '{a7+'\{̰raMXd 28e0G`+=y=tÔeuTqh7i+>z!-fpc*fRvޠVKKN>]o[J(m''OkxՈM*]B5<G`6c+>ZhӁȠ|D ZmV)Ai?frYWM}7#ǖ$< C^E %P8d yr<-iqT˪` 456[.6T(߈MLi5ZK ޴Ig9 r >Z w_xȺ&ؔL/VW9PØΞ癨,,v=|)IR (L!EVI0Vop 8<'Kw7n^|Ua2֬c}1Э%nG .<9&:DՌ2}r^'`t9r%v.l>;R=q.%A"{q0\ŠżUoϛgyx->DBdŜ ,!3"*mzEN+=h9~4I {zݧɤ Idep9 mXgrHe4\piO5zJ+ebøޗr@V}[̕m&DQЙGRmgh=`>+˯RՇFf<᱋8<}>dpp@8z2g! Xl˹0 vY<:RHu>͏d*Og%¼! GuA{) `#¦]5,HcǢ |:,HQYW}I$ɷM|'E`UA!kXqe&[U:hѕ¦_OCnR\:\`aU|iS-gdiզ{Vy3M&]yZ.<r[X\My,|e79ZSo+HBğpsB%Y]`猵x )9U񎬫4Ëp0tQ4.| p^qc=~LJiXO E1aVB?C~.B&>~l@ w4/hw~gO#և&e}iE2._}zṚ}A{Gi2iBs:t܃Pp6drA8qҀl^%Y,>aQ!޸\鈥4v ܒsG^pq]5[oq"JD5STcu,Z[CJ< S0]s֫ Tˌ܏`1`_2yt$1i*_q O¼+W\GKY_CU o%Zc<)?t5 )TS-||Gq˕/Zw$eAҡTF~hW?0\5wj,]B_'B骮)"5Ͻl ༶5T Hj-puaf=;'gzq7e:Eϱtq~d%vΒ. > ! {Gw/>0T}gt"'FNH׋hb>dMi7X"D)k`V.^pYaC$z7hkO ƣ_lƩ,peg)ֿɅ6JHZw$ߜ'WB% L,Ve@do}Q-^kkߍ5MVPHsRvӡq} m,s0b5oU6MMgQ ]l +e+bY`>|)ײ xMA7;#sv<9(3KY!zԡ9iʁwfZ*mJ_L3%&%@tQ)1LBQзCr)hVr3+vwJYd/FQrOeS߹:"QGuq] sJQ/!dTN9HOV1 0v5~9Ueٝo"*jc*k7屲xq;>5ӧ$/egr{K~bCb$z='m] &x-OsGj<5|*kԀ;ҹDIo~N*{Os VT8UIS:X Q9P1fi09JxVX$GŇ7fh7a~$o_YL7d16b^ωqFY4'}Ȉ*i9K^,oMd$渇ν)^`^OH-?!VZ`qm Ca;IbU eN,v7 z"TCox}0UH,]gq=gߨW68RVuhS)X 4Cku @"$f^QΈ$^U~AOI&*iyS4B̍P]4ձ' !K| s_l)^J'0tY)>֦z/Eܼ.NNcflMQ+%R@+)MMK_6!Lc.{¦/Sg1J[J珓5dɹ/&1B/B\ ўc'䒢}i_>"? >`k?IHi9щO!Ws4P`ID0[Dt=; ܳy0=*G&AhJBW-8?J݋l-< V IMBx|,᡺Jk*Ҿ%o.pp+V `"]o˹T'K΁mL)j ss~8ZcR~x0 J0܎*$7ZӵU e~RDn?ȪitLP@f&AXndٚA Ж+xF`3QNuNM5r6BcFݖ6~6pR>gTX&}7+SY Mm{~d'vn:o𯶫dJnk#u {Tcs1aIQIKrΓgnlzH[:/K}Iv {kXC4X,f7]{yobKQ]#>,nc >*OB!-$%Tce:b"KduH Ɇaw$p.J*MH`n[ "UC鲧[p'F X`T-W819Ӷr<zx^vNs- յ y/'id8.Ơ0/[ztme~YԈ>HO[ l#M^KT7Gz=jPYdҜfo~~oT6CGJ^^H$ >\.5V1̀eڸ8 t8T|?CkM{u"SĝzhI͔yX6x!7YIڅ c0P=Y],NkFe k(k?WPVZyF!rq?O+~j`y}"ML*IB"@ ,\B#<3CV \n:l]֔=!*`TP ԃ\jz'Sf9;23 g<̺ ΁Md9:kMtX?)Wdv2 ^;N] 28KDtݒDb!L8=/@=à tl)4.(zQSvZvk:0߇ǹkcK >?GzI0T=Q|O̸ҞMM3Gfwt ᤁIJh]U`3-9 T!\=^zmBy?3*PImzGߵ@mMCi?le )m6h "/38Np=r#W+TMvQ";@kSTyv CJC)@n=e!y"/7~ȁj0t=#C||7ydݭoq @ ovLU3+ӦBvY-*bHs5ۆƇSΐErw$"Ά*񼂕觼#ڹey(؇;ApjXŎm Cdחi.rr"(tYѾ2Uxy}EM4~m&=`I#, -q0s%9eMY(a L '/[ Ͳ* R>k䌺in2V1쉖)t;2FZ*&J0 ެ] ncO;Xʢt,S0MRs`8.NY) r&wm|֚A")|oǪ|Nd hIYl"hk 犄 ̑_DCկu_q+a\]x |WˑR&!scFǟ#^9ifu/3bUhlqAV@ \}$wdC V!huB*n.B$]6פ|,rjd]i˾EVFFa;w$/W ,ySqƲ /gtyo&cB& g+z g_:]#,iֻ5Ȝ=Zi9z(kF% SkKcK#"i z<}%&mq^ nidL۵W=طR1kOM. 9i YC=l=g "|fSfx ?>vw=#;qe }zuUrۙ Kcz=sQQB)S>=˦untoٸݞ9UY^'䎦wΗ dj[4p_18߀]Tۊw]R ڬ =:ؐAQ6:.jn%Y*jvhA^mwI; 쟠|tIKy ݞCmxHf|u_ 2f( /pBZ::rrSKjКz9F{f[ydd\zGD@ M1G&?`D(YQR3} ~g*j`MwXE9MjGL%Mf>–pAkCӭHdp /[Ɇ͑X=M*HYog됈];<4@۸&t1@6StjԌè2īɋe<w6Eokr+3-ۢ"9ХZzUh9}c72E"yR[@pZ'r阃aYN FeKC%XB43AI;p btoB݌K%ڤﵦK Eʛ*}A/O%Sէ ]${Ak106G xi}<.4s0c3Xe[:mY21Z]d;s"|3Z[375y:@Cgy}Hi䦃(r߿vX|#TQP(ttEtgtuZ)4~!X+fl(ב+-3O Q^ܦ5hDVE\^*zlz8F<LNC(ẒsiP^M6S3*ҷݣrً3 V`?6{ZD^x24Ǟűiv#6Jz,w%^wU6ؖ@Zy+ gNr8w]~W>pH*\a76~og&eG UݥTMbN*1g'byK,6&46\87iI9z? :(>anL!E[q$Ԭx=,յbj~&%_t՚"a~wW-Q=@|Wn[[=9WFG PLZdls!%#썟k;֗ݝ(ϋ$ƨkF ے*><$'y@̒,Nf-a,DtD:yq7>1>9 eg72(&@@8%s׎˚ܦ[PX_ +\Z-ُQ4x+QEq/w!!X_Ecr^C،\~QNSro=.$B pK~k zw̨K"D\0"i;p1oof~ב@q7/ae7ҖFafQ%?kU'%(*.DKa&\4p"}iB8Q(Б&]KGx[vt3٩<jT[VsG<=\#``h,J)6hElrC_ͪ?0̇ Q76b2 cCX$J3dՒ b&3^\JIΥ#b2k!޵Pw^Kx˛omA~ WcFbX"˜i-`{n@}\t郐g+ dj6Q繪-ER.N;} KǮQtXXI*Ֆ6,/3G7$ ﬇@Dl3%Xآ\=\--:( /˅=}% N~7*^'Qa#X2B龲>Ai, i'dO9WAU!.i_{ ibـm;6ZHxaIoB|*Y/Eقh$I? ze W55ƙlǖ=MB=Pq+V d1F۬_*~8T4aH\{Q>~6&[6Z(HiuqUr q$Sx7j-cL._f" {\H(oV4*]AhX_@ޱ}0Y$ ͗NFJ TQ ??փ(+Zg.:@mh?f aNb[A~ųT=d:!]{>^@R/x'4dus1X:eD' IB;3aJ'c2F*^ASŏT]R @ȷzMseb,4;^2O /[livH~JK\}Jxt*.H(͕7E%Wx1=Yf6^); /Ԑ+6u0tk@,=X(w.yIJ 0h9DS]2c4N鿌\PW7=HYav$t6!2LluO J4߅쩐_С 8gqvяnPHyHI,~5 !͹L^2<\0 kMݮ[՗Tft]cc,mjFIvvmS V^Pa/n5Q!iT+NJ;ɕFd8<ǏiR! {GTյkH:J~_ O]ȲFd6,QD>65G~vl#7Qe|j<i=n-X 2E-p+yAFq$+HeJJst%lm@$lQ̛Q."99L -CwB(0xtN]s!S]iL'F|J`9ް9c^vκfIYg"6kJ"Cծ|W_եFz'8 (2,igRr !Kbd_ByvZ>n(qX4%=蕹GAC@*HM?D+t= = XtZz$i{per%F%xV |# ָ(7U8ym:g fђ{Afj✿WK/%q1ҥ7; bs {Ꮺ\~NkV//]@V\x#)*>;%̅teOwTN٩^z `x[ O_̈ Ufj!wWUJ΀}aD(.7 @|uP5& 5Iһi`H b'?D:X.L0t#b&3vȂZmb xB R26vnbڃ}pFx tG)%r pVo}^+L}s=Q@.#)ْβI\G<Ɣvëj8`X/l9Vb,]& Yqg֖#ChZ_ -; w@}n΅` o/,yccp! zJfzi>@RΔ ǫXWn3TM\rqT8+UU$Dq{Hf~"p!0Ћ`c.ϵmIR )G x֋ jODL]ܥ?ٝY7X !.z K 9.ʄN1|h٥n!QW~ =jB $2 aMāoc,ݗvPWLq]JBMLb Q^OgEHUK9Ÿ#U#%Tcm)|5ʥWIu\8"YÂ3LHH(E!2\K ތ=4.opqY1"Ԇq}4C\KJᗁ!jZZfx;fz:)䆙6˾PST;b\.Hw9N <#_,.D#ڃd N g9N:B?aC$%` (|. .=dnY)Syouӹ6Zyq] w7BQTdxnD oJH){(sx %[Ijy;"*AKB|?%w {0 O_l׆te%ՕIp[̜&m+riK/<}NejNKt,3$hχO\ KEndJ.qg{(9YNiKch&̇ _c>ݳGweܮvGeOvY!K!dCYJNOEU" \&&MΒH{2v=G0.uJz1;@sCz> $|[&I%qw%J.O?3t>wZcCFXlpN>'_`A7XRZg= δ*'<̘a -  +y% iHGPeyc0K6D$BB̥kV~\wub}gkȤ=vX>fgtQ~"y #z9pB$\ܳQr2$ bP Е1xWe2Vާ<* 1upSZ 1Iv.v 甆<Լc~Z-nM<ۑ(6:T;0MJ>L8h#} j] j0ޗy>ypZ>\HvFJ ࿗Ly86Ҁcvi< .~Iwk*f6cc}pu5_v?J{O 4 ̬gۉ0 euTÔG?Zqoj+Fե:K"85>:)Thv!† #s݃WE.41Vjeߚ[KT-{q 㗢h%{?y;P:_[o_s b,A *ܗ*;8 E5gG2Io̺E>"+B8RRD"z; 11zQI^3K%Yh.x! ~+h1#"0'.jʵy+6(4VNW7,mfw?%|)Ko-la"m-K'?г'}xi<Nh~\ocOq%mtR/0~zIFH:NKF<҈ztsĞB;kMMw-)^ ݵ猣=Þ)IÒDǤԕQi)jF>^1f~~gdZ.]Z[ߨQYi> +PB$8VξVrsƛWoC0[s|;⩈t ˺ڬ=#P]޵!@ncYow' rkZ\R*Y!VY 1t牟J} g`M'\8fDg>o·ut3?qI 5.TS1E#:qr8CLmsH2xx ^¿;ӞP!lfX x4Hl򕣆~4I#;`4LuGibXۯݻgr^)_aOf~W]yڱA⥵{hؐ)9r=EN^NQY#Rٰ z29m>oB;\{s&NDfO1 F*ʯ& "^FRcaLt0/C;j' öu{uJ}D#ꍰ)aK}5 3Pƛm2/g(4Xs& PFb]MӮ{s4WgbEH4,hDd[L`cD #oz񏝩]DGon)V/L>ۓk[b?薭7Q ^>Z!~q,FH^`y&J7$q^pS aE@^v`kXZ*Nc@eLGMĴT_NY2ʶ : j? o4'D8GxFhūCcGW\vҵ(S[$1ZfNG9 ?`tѕUR8v1͇Uo6+nmˡ<!G.: D}ȁVĖbD..M3+Z-̛7 6U^^| vz'VB'$)[9.KDsO,)}0\O )b(fžC^Às:A>Պ&~сT )u¤C=ҧ]~uJ=f>Y$(<u;՞ AK]ҌuW"NOy\VOm j8S/xWw辵!搹45%/7fș$8EP4//og yR.ܚks{D(Py/] e &Nیj53} <XXx]4 >aGOD G~-:MW#5㛴lWfOT&3@l+Qt>S>3$:YY{+a!#+We G,0xj5K;4ē>e`iWrj Vfr9a[T:6al Qzd+QXOZg4#PQ"-j',]?bjrʩ/湚6'.SJ6C>d9娥(,܌gg<89vujt1A#ZkC>Z8(7}GY5$%iCv{jãIXA?}$+v#NI}lUAfwP0@r\F L`qmr::,0r_U}01S̲H(VT'!~kRApZĝٕ NjcX`\k*ٗ[zY35Sb?l&MNr/£8unWV᭔Dx\)דDy6,opo+Xr$lxufGVre9Jpۍ=X>W D(.7f";38ɉ+LMnaHج|^lkn8L|bag:Ef՝>T{ŅZ<*1_$Ok'K?nR "!C|luŽsn/.;>5BWJ8[vR2 ]X1Fg(zy6YiUAnR9d.X 0@IKO4a`ڞzZ2ѝ3d^GָE6@ iR{PeE f+%i$ۍ3؟tjY"XRTd93Pt hxe:,}]o=ΰofj!j<>-!Q1~+Mvr%9k[h0_2{j|8s0eS#5ZvV*8|cp ICӭO]jQ< G=@W i729Jj!͠b>x s1HTj(TP+O#~Cb@N[f9+qNJNGXVd dcwuBldh )NuxKuKLٗ= DTq* ΃O68c6S`lpAi`B6PBڡ$M1bԕsD|Vi` ڃѴl\&Е*^OsM /:..D"Mu; G\Y/5ߖ T^H-m,:튭~He_}+הhYޮ.Xj |x@+bK#k`1E*9nӏeMkfX#HyԖ1\WFL^/X`U{u+`cv(F34O晷`0Us}  ={Do] kW*6"'b|quxvYݰDD{R2fUPղاTY06S4wr 9jj 7_AfPvxjofHIK̩M[<[R6s/_3R(x1BQVnPO.p`cj9LSS.ѥj$'q,؊|!NlW( ?n  dy5Hu8"ۇ2Z?]\:B^q܄Q8O;l[ Zs'eipT=Bv1 p\Iu> \ n_Q[y\+ Ҳ2eG4oT~GCu@@T ՇO@F;s4 vSTqIG98j#g*7esᆣI*bNee iuOdCO%d땹%Q9kM|d( ;O+A'ů@gwzTabTvۄttnB )|-0W4_rS Y,*FR ?\eTحz.xY; :ണbke+y>;I-ĺ6U~fxW{ .|f42Os :s欓-P7rXN8s{  RL`iDp|%[oZbU[fNBF~iQwvy|EU5[x$` a9R(x6jL% i'QmAxbk/uu&uJYW(G C7%D`cJzF᧩뎍ôĨcw~o}(dٮ *7+F257r  ~: C#AշIU7'^i Ц|EGш#oxp3:UZ⏅ ȞV)&Z<~Ս{O\!6 ԩ  g.dtb8PRq=Kz. 䧯Pn6h/#فaڎ8l7W+Mǧd{vnZXIPC`~HnSD1_g͙L].⡻ޓ6ás*v륕qzeW)ĹP[ls$nT>{Լs#lz?t}ЦJ0NF9Ū\@Q~$g$bk8e%? )7^_AꁨWzD:2hw+~ MQ[A~\dkc4_1wx’k\ll8Rx R }4 mZ2nn\RTm$,x^RjTuo>0q s+F#Tzz1{"T]FoVK_vr۞`:.iڦVi@]I[¢V]X8uӟTR@F|h&խ/c}S]<{ |rc󭟕y1S}a9gFN'ٻ tGw%&eơJaS`x.ex:c> xܯnUk܄7R$>V`=6PUl/=*`v'0o9oXK85"$JCu36^k.)\8&p`3 ^Wt53`o>B9lC*!碧˩f*X5u*} d˨nW(K /rUȄ}UG;Z}  `UehmH vz,"l'Șzk EPm +sqBq^u I{z-k߻cmʗ<_XA|:9],=DQ[@%rpEn?M~&(yDMĴm՗04  J|LPXڬP*.D9+'zb9~\:qiJ]FYs"'hXhju>DK:Hs7`_g|dx.~fxQ>v}O;Ć^NBCW) 헅ݔ;b`ɨ)\qD/ݮUVsH%Wse$&R #85 zmPG,o]0!h?a*hy7_9s]Mdަ>p_]R?hXA(oA2R=9G>l;M$p|$U9=ybBCVn?y p3!Ǝ.6o??!Lj>\%ɉS{l/{DؐՑݐE*?K:|F囆) {)3;U@Ӂ)H_%}gVŠ`ۜ~UHc;&}NEIS,0i2+M,{X_Œ @`b(A?,`W@.|bvDGȺ yV'raB9Hb%y?תNiDH< n,c.c?qUu%i TP}#d$]@w@q 2^x|eͱ&"&+˪R43HkZj'nwp<+mʆ%6WsiN$Hr*1:nȱ Đ$i8vInAhl@9c:}ӵ+ʹCjTz͕Q|iW RNɚa¶A lN,x-Q?,W,ʽV[iphW %#Ff2pFd}?1ј'0̌[x.vHbWi @ 鈡|':sP'Yw&96S~x٤GR pLVtk:d^%`lO镍T{5OAVӞad63Ycʰ;5z[p"r<Dah6(zZ)<ыanZ4VV PbDA#T⫂+>xF_i /&J00Q;8m 3Eχ[ɒ +FAF4Mcx&"F~e@\+!qV"8Q/-OB7wl}mzm }Ѝ` [B VR_u Z 2%'/}{ ͉t-3_E(a;],HN*& YT<89FRgӃ$]h{cmthvr.Gn Κ !s,o c̲9D7\ft":zXRM!ߓx<ڒwvno{| _HP<Ҕ|$XptWlD8%V/h ⢹ s=B"__AOyTNaF}y([6,l}y1:SWU=.#σ֙?,63)'*1Wh*>ZP%nY+4EӺF mb6{DfQ>/ن򒸳^$^j~sԜz3-;-#RX5 WHV͑kе{F/jUvdzGD`*J YRg71:(ؽuO'#y/Ǽ_y95/wQ(]:Vccb 'h1+&5V0hDL,6栟z lmN(hZ6tD2 =Ld+)Wxe) BUbs"C%7&C51'CC/2 [tfKM}7iO7x;_=DQݎ%WLעNsHQHz:>?8"ósH+,0i}iCS:ϖͪ҆*7J\%R3>e#q=¾G̑U|H:-?r8 dh\F 9-(K?Rj8>7b4~qՎ1{n@]-pI/8i ƧՕɟ}UDGLTS<8$,K̍CC03@;E?+Y05ZR`o%L 0aY~3gA)swI|WdfSRطpn@(T\U9H6Y)iT*r'xN9zțدʅ>:-s7Ffl.NZx `2 ?: `I0M1|ߛz %lTmӺiN=4R=Ktf.緉wL|*I[!)>#fMѳ)If%r+mozDe䈨Lx#3,6=lcQ^1uV( Ki*%Gc[]+~czd6S)0zc=,WχP'Cpt_<GБR\@ԏwT~ A5>rkX:N k(DhuFjTJcy^0Bb2,][6rO*7k HmO豌ސnxG塆ArwVߗv5gm-vѹ:ن {{,ڀFho48*@z؊R<\ [vM1n6`թBTcҝ1dhDYY6 (bqX:Gwz}Mdn3E$W| ںhAo2xn"2QĀם8 hUXHjfsTmyD֪HTB\=/5m6@1R+7puX*)ױۥFGm#rT7+Ӈ. @d9`ޫ9QhllF$ ZysF}C?+r0-JOS#6uSUl@Rh(uXC4Kpl ]T7$> <3+xiYgEWul>4ZocIFn?}ZBSN2N,cQ+z- gSЂM~hNި&6^ sD %yɎKx2.?Q6(;'+ɈQL ML] ;*֌cahPS-&~U2\T,Dl/,x={f3 7̯$ᅢoFC̢ed75BS!_WIO8t9o")T: U/58 ɐ73\^z(a,H#={ ڇHSmRu 5wza^Eê - _Eu&{b"Ov<|YBߓ`;Bnbúr&EcBKƋ Ј4UܭS`^`Qb qn㵂w7'9MPWP - axFɝ)ѻ5G4%a=L3o% tO1^>YTFaN/xΩq-Ŕwp;B/uLVeatA)1(r1wiBnI6K6F 86[Q EYYK {M$N e}:̃g0}a9/v~!d̲8.U"7x¥L=<9yo9r+,x*8Ȳ!;t\*FsM4*$vήڟ!D9ڳR;?93 5 {=f[u2 AYZHmSaÂ-d3ӑNry٫,`y &u1Cզ+m~灺iq3 J egܘF'ςz4ߗBЊI.rEB~h\xڄŻ)blgQqi"9fd,WفrdR]Љ\2C!>ϵCvnb+;c,;qy<<*&&7T+Q_3s2{/Y8($(c51oPˈe1L&>8d4a>z yf@tڝOVxS Aգ(Ʌ↳QyA0ADc`FѵKD/vSpt)7B98pLR5Sb)CEidt=2`֐G1fne*@.f?`1ɑ_Bg"sz-M3\+2<~`PL[߰XE{B4j-yost!=aoUؿ}W@zBv^!x TaFaTaq#oƐ†_,:Ś=YOZ+H#@s˖b5Z ēk7T&ڿ췩Dynh~]y~2#1G:vYeu]kJx`ߋgAuwkz,{GƯO ˁԫ dHcX ?NNA_eOiWwu|-7Olg:lܗQsW-\)ʸ*Q;}* YpDkPϴO,Qmgto*GOOb")BDUm*[[!OfUl![KYե,ϗ#546~tbVrPWRڊKi*@U+#Q 5ddnb<}V2ehՋreRRҙs'}MA`G9]C@b[-])E݃fBȽAމy%P%xyjJ>:OO%3]^Jv zJЊT$a% ,xe2/o:ØP@n.;u ^v(S Ayw+pD#D¢g`m2UwV+4AɼGP$>籊qu9$;=h"kSĐ6:}\KF׏~qU~`V2s16qpZW6W==PEY煱s4NI7Vi q6 2z7Q>[/hW2*Vac(fwÂ^j<.,=vR`J7ގv~܆H|qP?afEҊkծڵL&eQ\qGWXM?ʡc9!kjfkUZV€:\R.f$\ܜcfwyɇ9&_?`F߮T>^ `Q:[ηUs6-=YfVzo6b)1ǏƵ%i`D?Rԙ;uʐA!US{1Dle_:r%uF @#rr %&CUE8ˑJKhKν8ݪD\{rbirǮ]I}  ^&MX>Hh~ӃwCI>#QtHtoޱSv27@Kf&}YZ{ܐtDV2M7:Rp;c8CHRQIBAnUm1 ܄1@EPe@ e) J/ltw Fh+Xս 4tYWh;CU۴ZzX|r:k{-;\5pCg}_cVS;6L.@n6-> !@dBC35\$R*$R e;Ρxѳ\-v3 ptxkm5ht[J2]? q>"Pr5;.a͹izM=W qhu)q;0tߧSh)8z?,Z0oͨ : BM ZʦGJ{](@ ߁-OG4H(֨dt=%؜&G U \+ݢV18*yD:bJFW+b 2 4%a8l q\S2ףŹ X],cI j%Gq*nm ^/cL `B|a8v]vq-~gѷS-OiN- Vم⹛+1VѪl}N|hbTt0f6dţ#U(4sWے\if VE=ٵ@ayA{&fV,|M.Ua\6C,oTW*>.˥ďpy!0OY,WΗ1-@6czQ+q) ?wmRq]TWBhMrecM>y2oŽ">hq1mj:n)6ic$?7\D0)r5PrڻH97kW-4ز Xu PGciQU=b i/"m~7-},ǚ&\*#YѐmKd>?7pXc[J_Ӄ6]03 wѫ>h{*?ȏ̄Ɂ>2hh%&O2qhrP.n7  ~Wr\2nA5,W(6DȴzPrT|e{oƘav@VHprP0Vr}kEY{] dleFhcistCyInP[JMMq<0_d1D4ﰑeaQUF1]KB^HNjCann3&cOޘMBg 8$j<2XR0GC1='6$ggdrāa!ݚX6/whq`$52RizJ$D=y%ԍ#`hUO3qC;2~ޱEC+8!+wSy 3?ɦ6S flW9q>> &n<uL*g$/ X 6oh+ˢs5PPIvnD _~I/7]5_&z*jmXEk԰>ŦH>C3/2$+zG26Yq#3kv4 q9s),I9 y[1}SB֘rnT9i<\ תtPI)5쿟$tj#tjk!->O$' <+[\D M)鲻hpmlVu:lCџQڲ"]dY`P )=4DRHn%sޤn!)SŌz쩥|sA'`2LQ߬x/S1HK WZƀjV Ums˛gIc0դ}t!9PLaf7|ڎ?i;ltS/ng, ^UE) Q 寉[Ț:@]d`%(6ķ+j`6dKcf걅Zs(6 eiAB>a) ]57;kF5eOyŠ|}#z' j._eIUS{>dD1cshkEȢZ.H(oa3 !Pg.^s}?GBl|P$T@͢:Ub7Z"֌0W+i4c[j*t.r [m:ODx`=JVk@Rt;5]NĠ!M?=a4ϱv",eiJ xa&sPKÉ  u?e Xɠ@ߪQӮϴ:vrxZKW줿kO׃Fjg۸v)B7ɸF/.b-r%\=9?as. TTi1nEN:DɉI?V.i2 d8qʻUE EV0)렂,|*L@M.CZ µFQFՆU0X9۾pX^g/0D,Qb$" `+8 ɰ{ٹv]aaqf;8Zw} jjzü57Nb~k ȰpSu5/'4]CE"J?NvqOlmTޱ(, ȹ2:]ȿiIa0߹_ N6 1L`Cp$IPR™=* oT}~vCH܍B؂x@",IGt!3ͮh96K9;M&ClhZnpm5׾S3[AuOCpux`i"| LE6o wZc{S{P0"_k2WF)Gqs4 d nCf f g{i](8|ƾ {7[86 ]z1Y6'_.|p]wҝ 9$zT c:e>R4iEkP%O,v>+.FQBL$~W`V[· )&jCC"k׷Dvx5&p3 veesi }+J\iu8ute' \Q)ЗxIE=A6=T %>Z{a[ŷ}4`T/<^$vzp~U8ތWgOqtZIV<2=CKH-u\9 _,cm{a( %oF5R?0k/J@j`#. u>>Iv9HtKf j?M e#' e ztr)$ fƈM!'3X%Q,scnҠ/}bn ܞUUU쎫rA9IQ(&NH}%6HH>u$~͠1IvZBr  \ЍAUX=HxZUaq&{ԓ?OյmPdW+9r#)/} M! Z(~:Snj&m՛ y7%(b̯6 Q.JP"9Qk- C n<|ZB#e42E&EdЏD_&Rd"OV>\'w[jZlc*W&KpZ GCדR2DE݈LAŵ;ݯ˵@pL{NOYi_`GXKFZy2}x73^/4Bs&JM9bÛ\>LXdqQKR&b$>Br.4}pK֊Ӛ.#}~Y"FC*H.MΛ:m3cia+ _w8't/RMI'v`َG5m$Ƥ:4`@r}3Jścm[ lcmiqRR//'.Dp9bޣhv @LdʆɅ& X"~"]5 behK=xxMD@s"G;VbXNWNe=(De[_:Mί p,۫edyN+b:f:WCi:tDЋԩkrzSWI2nW:f*dW (A)!R0PkiŴ yoLqXLuH  2: 8#ذY}'Ye)]1.2 mrMrĥ-H'+Ek3E=[R\޹zE`3n@ |k̃&:ح R4jvUl ._:s>z\n&8Bdd@S⸡_G /lErާuM8W\;_ʬ,Py 9!u5IDw[8Ȅw3%RY$ŬbO<[njqUC\FA/|<{U$^B`yqM 4~g=,Zkh.?Qo6Db_~DWwFwl/+Gv7LrryPGd\߽-Qz/XC(c!$[/ZyF{N<9,-al6,52zxawn[g|2Bڊ6XwakwU2\z[ ԵrJԞ*ݛ@Ud[lW|  +ySfJH)ʉKP߿: 6`߻a2*(V?P {N&`}^J1u *;1[FfF7b-/QPVޝ2.b4MYZх=;z7x>|slMEj A=6R 3G[-\av: 5'2m` ~ffÒ|R .[e+CsR?~QheOL pͶ݂Y`l4VB|ϵߊ1ԯ4F Հ_T-@DZ8]cměCiyV/}}fUn'(o!,Xt]%CCDz^bd9~!l$LIcsi`c&#/\QٙnZta9 "  (̼[cN)|(8%*z /X:Wj, Tu4:{  EN$X% M_HO'W#oRB]r=whaA9_or)~HJGE.0!HE02<V%uͶQҫP3rݪ;2ջsvn%oNau [:=W*s )ɃJBLE_7H҃oclnXD)]8jHs* 8I{U^–=:ӭ/ӽw$Xm>^OQT-:٭=.XW懋AB`xnGw6mM?̚n4a=k }u zcw=790QG>/*lZ1HDR LJQY_Yj#c&&1{J7I 85 ? CWUb{A *P[6M[~*Zz*V+jB{C1ARuۤL `o{gHn6WHC"REȂvmE8H18,O}<-XW`%2);lt$krH|[Ժz">R뙲LT~#c_ Z *jמ=\HH;YIJ J:xcMqjG+7b襻=J3ϲJqjYR<~Mq.ߘxvEAh%Y\Or^ش^F>YuԵDw% c WX;3&Ȝ}ei2=ڗZ^lێ΍&G3^-o~βL(&KI$LN˜Fx?:|f!+ZR(szĞ6 2͢[wEB>qf_Aধ*iG*W&F6{T-)T^`]C:0<; + )r?m් Ǵ 1w`y  *ώEP8 >@w$Zi끺 BuF5Z y3߾8PomiَVQ T[F `1r%h0 IbbTU!|,&(Ҥ\r gp'{Ġ}AVe6Q-w J [Ȕ ?8lގ-D$;yC1 @(pn}0_K@VVKlqφu),邰R]3~I;YB?֑XH%GH^*F6f7Z*ck6BJJY݆So>k݊CZ1z ɍRtWT+9̶l5=嫏X\/N4OQ5c^4 3~xtMLu ,l:Y/hikh;Na曠4>0lFɻ֕D5Lj^D|VE!i|z5f0)dnSֲY:&OCn ڊN!K*{z$6;}:p!IA,u!+k@*u j{ $?l"L`Ђ]$-مYȭЄ*֛[HAqlj<d55򍠫cBYs>csDWVw=po:삓n`G̲< &L7 6%aE|k[\XU5*.&7_P/xk#9@ Մ-0fJY% ճ63a1(NNnxNG:Z%xxŁ${HtڼSϗ{bCp< Oc/JMFꂏB0$Ut;`j5SCX9=NpH wQs?/.B~ћ};(Zl;\(Cţ_ )6 D>~m#S4<,nëu s^ gwXa")b^ :܆a(x*bSg-Nsi%pt;׹:$K`.Z߇P+Y%zcO7̗_ ְ|u$]A@ by)ĐqT0 L|ϧAP-[aT8!elVIJ !V0FgA&RP9 N&[\$M]zkGPΎ/UH_vՈ0mO\LvmG.z<᝚|X8f%7ٲ c yPŝN+ʂ4w.x>C^91+صر sCLXr/0z٬5th2H>n"8wYa^6FdĻo'׭v%^fakp!ZuIk%ܓ8:3D_x)~< ``kC,)j, cvҖ m_i>I,OsVB{1 ICR f牻ׁfĤ:F@Xvs@;Mj8 mNAk3t,GLm1fC~*:K<%///N*AHdqVz=u{SV]D1aIO E꟟6" F@}߶Ӓ==/J^IXz9#$N}]&H]_)_e{Z=šʃ7eܔ*JY_p4LFnR??+k\$S5I7+ g=νbZWhs}&}LkmRXɟ:cDFh'MB8L¯8h?̡$pe (`m)&]O Rmws>jZ^6fM T ML4Fl.@В7NhqqֹxnZ H~_WDLT]3*\5Z&y>L{lJ4"Htbpil [Qk_٦6t *HDˌ͍O ao$]p >aAAnbei=D|zYDϫ^UE7rwe*0onB9)T3342;?6΂C.5.W.)`,0uO1yTPJՃÁyC5RKM=5XNlG) j-*/4qGK7釴MKB+Eee݋8;f!?YrK;U(rR=c\\K]@DS,UlEC/y$imC Y;Uz~hnl`ԮT%n~{fVچ%%P'!e=a9r.b< NKm nlj;!F|7JVGet'Cg*ɝuqe%p'@y&'@̑>y N85t} jL{=o˲U \\ ,D geɮeh+ r)9XX&{6(2(ޛG]9"a0ew:CDvX{8Ҷ%!fF3ivo]2#K+\sJr+͸9^Ek|O52F5l3bOCS|z=legGg$Ϋ]$Un%w< ׉3gqK2exL ]ecv$T9K;cZ|\`ȦqR"w# wVxS VE*.Sq3 4B˚]C\_l( 5'rztEW46"JyKS{ J\gX.X*_5ܚߤtnr{eȯ䅛FQ{K|rV=lÓrS/;ñta.|R45 WRAuO/Iƕ^NaE4,rBF? ]N &ϕXJ|Q: e9FOm|&vb [UUr"}nH &\wݧޓr~Pr 7g҉ +fv'Z w7HsU,)m3E9ׄ.Ϩ7X0p{{7JhqA/s~f\nO<;ߋ>`ǁ9Y] *զ ;_XgK˒}n4T"C~}a`94`&kKZr],'d 1%Xs_;6 `بJبR0P~U%vGEc29"># 8(AAw^)-jf\P$؇f&q@U;b.xzߙ3mzsg)# U=[nPVEB=0HvD}J`p"3ѭ {pl*O7Bg39žᯩ{c3%:>q=rh&&DZu@1$4A },dGmq{.=DU5 4y\[6=dzFI5ɌURO+iPKǧ혾.JkF&<Р+޼]E䍔r(b͔MVqSzY$sS.OK5 u2Nm8bH;LfsT븙RÜEI*9Ճ.Η_ D4st2CfffAs]ԡ !"tS}饷1ThNHq}rtKOS,:ќj33ʶE#+^ K?Nlސ. jr<17|CC`h-c q}\DjYAiAT'-V\mę\JIuqڍ8-aw ;K DY"[TU'H@Gx":պ(:B-y.] | LA! ҧj5­#;Ly5MHfx-ת(R{L@'Lv{`~hQ Qc$nejM2!)0`Wpgd!p jO4f `{P|:. ЌR?R\畐ӵΣx;F_Y/ loLWh3J X&;fov=P <In}hq1XJ w;uLe\ zd}F[sZg; b,3~p#o:=hBr*ۇ(_ P˾bod0a+wQ-ȘuЪG⣞?fH'F@G$ `ںe2ֶMYvl컹Mw!Gh]3:4Z*8{vem]sOARSV/ՍV ژ;1J=f~3DѨoy-"xql yk NE>fR]~BH;ViSE&LiU YCv}wAHY4|CNWo=O@,etO F1]TCF 3x$?YneiJmץr?P[:f(S#} U 7q&Ƈ |]wI(+agu1ڃN|UFpEF[;OGxa?o|n,JdO.CjԱe1ծL3B!nb˹`ձ%e]j _m(^#hI&C@W5{͚#8^mr->MWl0)@[RWq|skM L<&?ߢ7cPBJX+%c׿~I{?sV4u滎=Q"6PHO.\! _ r͓v*規)9W!:JY=} zҊL)VTW Ѧɚ7ƴa8wTWjPS#w^!SL^o:|*h5Xiĝv@#†+޸lp*8}2?] ~DW˜d!ME;B ӭL X;2%bŊh10d ,SNE @6Cv2ګċ=% 8X#摗|:&EJn癌R4 e>vԣdlbg06&3.H/_b[~\~xtBaɝ|#QfœuO=&IWsP1~vVfKndZBF_iYڙMf㵵w^'4{ j[ikaEdA3`J$o>_? 6+>"ܺY9%Lt{"/ @~s^l.G?19Tm{s^y&l.&Cډ2]/'m&v qt5#|`Kws2=A9P2q]ZbjAʯê DXҒWK qǠnD?cL}>W3,z403K)D.Q(. "C.ጱPWEhe5WN2&rW/zGcŨ!2ҍv+KE죪}ޫ \rqxX @h|(:H!ٹQ#ՎR]$]W;R6Qnheg$m%ȄHP1ByD08red ྌ;.%f-ng Nr6.?kPKeWB|1(_آl U@vU' t}MDF;!6Jف4}Qs"7ŭWHWV n>vA\8g,CA))0bK=N!^_* u%ߐ;O YrsiWa;&S< @&fMSP\9-H:=D\ 2TJ(sR~#ߞQ6%QB̒[cw o_z集^ ܫyGyb z'uW l= p5#(GA[&cނڞt+Y  #2̇!a[k#I-c~)$_|HZA49B?U^<$gr9gcy3}Ꞑc$TNeS8nWqoO4" >ce?AMzBjQ[^M{^UH{fט|4(A3E ىͩ]Zý-u-̓c\iTslEt$A ihSwdlr=<x-BK\,2(AzG ".ri+蓾#ݘʹ:X/Z蝘D N{E׶@ ̭+*n4 PP]dIFؠL!&_'}v{v.Ät*W#194bQDHzx$}UL v~T>'W(| nY_(.QgI͛HPD b 1U{`&LC=NvS\cx=6t\MeZýDHVDIr_Ϋ1\kN+B^8Nwz3L=τVv|*nKr rqBr9KL(E#i:Z&l8f}m6orF26Mu nݛXXAs̽F"YI-!ˎތf 545xK5},ő{I2rXuxC# <OMVEo|gK-JLj5 ihJ)?Fus<W#989@$ x[ 8Eihج$ɪ·2(HU ?LBJitau8|}Eb[[k-߫aeTAeU$xN Jn%ugʮi &Ϛ$Ys8M] 50~+^X|Ev9^BOhc^>yUDdUXs P&~{X/əikq`]GOcӭ3Ȳes6۲&cʋ?Ix"J)c_pA !<3gUޏ Yz1`x=8m!LNVjw AגtTڞ,DxfBNVSN y OpSo>G|TCȖ*ELFqqDEl&CK2IERg3C AT:`)MvAm$ƮĄGZ.v*󳠐\' Ի1a'dRޫY/ Nf YAbFYYA'.6J$ Uy,͕eX f)`#B{{۸:Žl042G,=/qabDwFHXx5`:ւ)'5;wԞzu;U:ǭYB8V֧Ţ}F(MV-ţܣ]ڦAܘWۨ7|zxJpOូ]eڇ\02hd]gDUxnu&e7/d~h]sTdg]{^eglB(rcqY"jdΕD\ǡP. mʅq`Jd;(-SA֌tW**6mRrX4d]j8_R@}<'#[R+IqK#Tj {uanW1]ܵc,Qh4Yk#.OH~0)ϥRrx~[;lӔLIx\G\Mėĩp]c?;ϧnVb,q m w2ҾL"/SF'Drފ֮# G`o 34>JvsF "}<Д메- rvزI Dޅn|zPK@u7@l+4Q֍^ʟqBhkD;_K/Z8PZ'rډ {-@Dڞ' Uvr՘8.-9^{ %B$:1Hv ѻj1D>>WA:'k"[P&i+Js.xbյI>kP=CN[zoErU!ڭc,R 'RMW7ǴbQfPq*cSxgxQͭש2;ai#+pŬE+.Fv"o˜E=[V'PVKHZw \.2eCk4$6tU9FpyPj9I8P  /M L|j]W2F ؐd˘e  (Qxߒ?Ef7crLb:[_,\U^##ǹY$~=#}29(ŝ0AzrMAOAG_T c6w! ?Ci x/~ŵϾP)OسC¯ i[X:!#ӯp]|=솟q-g9y @)S0YO|NkxIc kl`WwIF0u sM S6Ys3n[VA mJz*VCm5E Ę8F] 6MUT2%mYLyvҕ2L~wWPgM^MWG)7w¢ ZKQKPM*=q+=u~}auw4pGr2(! 9Y&OƝS}C9B nAoK ƕP8n`d v *7L*Bs-!͝.IF, ׬?/irorr`\(9~z}V JO02 Ɣ\_UՐ[ٹ,.#|2E<U4}1OgN?hph1#j̿#wTƂ?9oǽYZ5ŲZϿ~(ٜ'z`7-Q}.|; \3y 幺?|)KZó~kNTaiOs<ᒊ<}#`@(}AIm@P+X3"cUt?)qK5YmA5[a_ " 2͇ߌkۨ`U@1y{@m'oxљF9w*F$,7tGv.`y/1=ZUw;Vxa,"jP)emU4")]lPsg[uZ2Uс)2BҤB:m5Lj6i^Fr@ٝ lJqaTc=_}P =Ek0#Y w(#[. HtbXLo}.T(:-4])/UүFGe:T^STc'>MB4罙ܟ-E)ǣʋtN}ftwQqi (dEQז4 = g:/%X EX<^ͼ%rz_VPr#ˤ!$&B4țї;e8'l s5qǽ~-X6ơݪ6A~b4%>Q4OҧZyf>O"W!!/q=܊W%8 l?ӠwM\kd jkLh]['sܽ5 6ӷ5%VɃEu`:_BfXVkC2Q c;O彗,RjiZhngxW|+-Z.xԮPvUXN@JÉxAU8+_=2҈@V"Cs?͒bZZ"fDADɯwtXC^R a݊QPƪⓠ6畍eDA[^0:i=2lAAw0;al˯PN"׽G;0.(\¾3@!j.#gqgsU?x1 lĚ)yPdǡ/t^}B=Clfz[^LCUдi\{S6ĴIz9=-x3yhse>XpW`^ !2㥧##I&`r|3TDȴL`&K zpS fzlhm2e,Ѵ NxQனӚMJ$xj@,xA^NB P .| ]9amo{2:/澣x^_ Sf0=9/jY_~c 70m UQ\%ϙ< 6㚁#X'n9=:AN'1Ed{:Qq?,Ә~w5&!-s>r)?5}E_yZyeh:؟z~v/!qʫOiž{4ȁn-:z-.h8LgibNlC~~ !ΎR/HՎcf5=L{hX dJyN\JX͉?2Fb )}/IƄv_n׸Ӱ$G+oaPds z:F"ܞ8v?ow>y w4!& #G}d=lWD0#<41t?x2}/-GGw^WQ__~"M ";T)! 8X,S:)In^)7D~)!zJϺ̋<-_٩}O]4OWBYR~NWE)X$vHTvH(*(yGAiap#d=lSn|97F"$HLab#] y+f߱)F0V7hWyYF(x{s,/iIR6S_8Ѡ?<% j]i|!JYYAQAC9rT6sOrhZ:DJj˟? Du!gȇ,D`t(w9 ~ir JZ’EȾ18mvY[w2}Y+ sRrJqV8u=jhx.,ceja%Rvjv;;Km!ɵ-[㤄vMv+^ ؑs3WVwW=QeƱ.5hapҔ6J8Z]b~K˘lFn=Ez"vHH'Qf\T'*Ԑuz1{ ]eQtMUQnqTN=, Ǥ.AAs|߱92ՕM~e&;蝵4P *~t1n?nYh45/ @7`XtgO*6$$ۣΧl27@,{+PqnY-/җoW?OϯZNW6L[AFOշiYi+ {Giu^tP8=73(Zk)NNه*u 5jʕiȑXʣ)0=Iko iͶ|a]hTZE’,AwI֧Vg:k39\BLًm|(:<&4d27';UuNִҰe;5rD/ɑI+ʀRTt5l⏆74BtsԐ{Tf>AyZ aհoרR^!P!?oBnMiy!z UJSj'meOUq2m墑1u)'PVvXèЧwӆs4zªH 0iϸyM7OK`LaPv) A` 0&&pXb.HeՖu~A `r+(/̿15&,`^Z%+(e\*1=ig=9x!$wْF?Xkiev~O)sGqP[l5xrdwؼaMZP\`Ye= Ovq\%;S?l ɬ-F%(ΟHYõ?F%tEkÇ^$*c௷5򍓁Fqo8pU[Iפ(J:n(T]4gTD(逭!%Ϩmmb`[B!*8X +S:zr ĪۣfK3gCjEJ:p"WeZ!Bl-G&>/)Wq@1EbfQej#])ز &뀱fi{t$9&o (A[ t82 0@h쳴O>LB%wU`φf."ge,GV-=Gk¸;Mwg/V&{(t;~xL3>(c8},y#tknA!!fFzmv9)+NѤ)WD\ɠՊ!K`K:ԇ}:&UDU Rcc:W-pӆ ΌĶ$30 ~>MzBv(Glkpsװ>I:Uۘx{ؖ'CA_G7T;byP R@rc@U:l:r tNdc焚QG0JVڷwo9 1*}~P|?xP5Ȑl/ Q2X s#g$MqQt4Gކț \%PK럙~d%?\J0:e Z,l8'#6upC#$lB>lΚ [+qAx;Rӊ$w@\'G_,RhVJnf6mZW6q| ^J1V.!IJ%k~8`_wgGEIphG#z))>:-޵ 120‰s|݀ z?`) 6 yyYInO4Z8%YLcG5Eh%|: D-vobWqLEX؊I˭Ag}˿l/z/5,>ZWcu n,l$HgZj5\Pyt&9U.VaU /"M._ -KP=m XA>G.vV=1j=f3%Kx?p݁}=`!M]hXE`;UQW ?[YȦӘTVX_!FAz|GeDT64"vT$\v0 z#˺ 򖒔Vbm-@tCa'>6R%*mwHӧHFQc0^o <0bml`T}Sc@J-,:"-f}!e (<8Чbo[saŜ-Lq:#abmǠӔi=O\ƲȔYEҎd${]FzGP#rqe_jͿg&23,fYyI%` Eq{tkֆsA܋D[IE#?w?:-Wѷ4&ӚB{`xWv"$̊Ůs#->X؀;nehU\#+1ud`^ll+1=#)&C- {Uyp(i,f*%Uy)fs*XG@ن.5p|Hr83KAMu-kTOgϩQjyL+ۮH}i@S}w"FP T?tQSմ_+#z'vrgGQ +c)HeHʍO|9 %G~pJD:DS2^ 0n}.NNf涬ssܹ ME-5R|LƧgӎο$q>& bܘ O74W huL>7DﷇgԵ9TF\lrn6y90ev*RKN ]hf0ts^E:Jڶ7m .#C<59 4zbvU$+*l.U,Xvc:nj֔rӛwOUZƾ-}zOwSϿ1)y;<>Wy|Hkӏy]hrw0YiI9Ʉ3Fea1et.Y7l@*?]*E?:X$V޿dㄯ3\zV~͂n Pŗlkcfޙlmsބ:65킃Kz.N*s~\ၿOY3IЙ>o}1@jq,@2z} 摓ׅt?L(T 2M_5!L#pjyGlk홖6ϋ|NN jb-`'̓V;}9k?HfsUx *P{ؚ_$~|x~m#d1D\MwY}ӭ-p4ohHCɃUḯ˼r~7Tx_ɩycrf0Qz #ԋV˄>ӏÄ 9~h+Km0$xpk n=zD~9XSX=X%@xdw,H3]dv* uZBB2ϔ hEJȅPg'} 'I0H ]"L9a2O]?7Lg$NA!>\\LFC!Um̀AGL,d< Rq+fՃ(C1"n1׬/6fNJ _ o)tjJ(X0fi\#j7{Bɟ{k! #EH;o Zl-YBW\a=|*1h;F_4c:$]H}UQE"}T"_+jۈw5.+@,.T68;}f"H{UgD=0-J C(:JVDRu~g#sVqI:lLKƂPh$Vce׺f[O& pgji~l!Kr""vco<Su\DCSl@+A%SDij?TP03d(r|AV,UiϩSa},i _/q 2ߠD7CC  `̊M|di)KyG[a*`1ƛ\34L{ld$2Ou*^͍,fyo ;38yL dnHX NvCP 蝃W0J?mYGMڷT~ot!|ZUD0k7NX -̛"Isi4pfϦL7+yWAd@H5,MmZ]L)z/on8Y\w_–̵Ϙng$|=u QgMCD\.E}'?ièfݶx 2nvn,}V>^ >(fڥĜ7YȉB]gEl ڇB,[drp))?h2I}~!ˇ"UFtA)7j eYS'",T2IYM$hKTyH$uq1Q4göU*7Z>+H8o뽽^7|؎$ޓΠtjB^\GW7{ << wڇ̚>$ ][o/1s浾Z,W%?dD)/x3Vk2c.V/?@8A$D'j[jR-9SMl]u %*$ 4Ǐ| g Re25&Z'`4sTAgqI vBo;^&;ɽl0&xј{9Rɮp몹,%Dd]CiN%$@2%qp/ap}m[Gޙ B~ۗ%-'*NV(F(4BH5B8CΥBRKŋυe)hqST„`kР\:puFGO 5@ K]o2"rba-Cu : m96ا5 ï NAU_6Jm;,|jVPK>נ602 ?};EàiBh6#b,ؙ)3'GO˜ᨅ6B,6*Wr=uY4YK22UEA-#jf,.JoSj](TQO􊄼ѹrz9s*0X*tiҎ ӶYI7(d;(cjl'rGZ\4h=1͂n=^~D2ׄC݋ '8[,D@15jHJP+ zgU15*v.8XCF)JiUJVZǩ%`Uch ^E{iȒ<7P= !s VIDkQyzz>n|"7O7ksI= [w": e0c*q3<D/Gv;x׾8mBֳ).K OgVaByp2KZx>\u>%+4[&G%]Ml nA(Mt ZL +0iP]|jVv$  7`C6Bn3y{Jˢ39e k+`]FE|fHxGUrXƵpu&^<̨HAHP`}_P is|E" JcGaF)yqF{TUz~'|  8g'wq8ao[yo2o ,BU*RIX[tMPa6z3: Ga#E]<фt!Or.Tտ [P|i gԝtb?j(gYB^`.2@ s G+BV#Ī0{/i%Sd4`D> P y'67!<5y"M*􀮉PH:S7F)z(9||**[DœsiܧaDZڞlVn󃞍XXp?Z6s.Vsdn#x@) TԳ@rUb߸aSV~8J?RDY2qWٗqzX'g#ȉ8PQѵU"Qz vhs$D/G4;\R Vb3e}U( =N1Op(ƩJT(2uxЌY-us?%z>w *φ"Ұ9[,4IKL: (EVOA5(%|`, J`W\\]ϣ!! !QfI~A2g %CTv%GrZFh cO?*>ǽX,$P|]҉xÌkVWM&*B.~nye2ɲKBdI(r4~2fBE?Nx/T~W3au\QCQwIf ¯]` ~Pmi"|袭"#q MofYq0 `[*KHo@JB8˵| ۚ@>q>Auu07BH]9fz̏iWD$+WZzjzqZסPI&=\k/Яq{wGhm J$jCœK2[YG9ss*DYaNѭgꃿD!u{/o%E"EWM-(j5G6nt?؀of#lj47h!<ᇒ_Wkd#a&̬BDƌ [~~(핹ZEH>))h9K9#WY#dCVu;Χ(Aï-xPN1S4tKٕfF(cg+8 NYPѵhDV %w6pz%>@ڠa6q:j}nےh%/mȢ(i3R=23 Y\,pN_QBI݌o։.h4 葀@- ڔ5*<&=[ٵ &)9QoAmy]swA]U0L(#a\XlFdփW31'uX4{rPώy_>\huα`=}t8SQ),N jlqY<)[O=X~%1HtT$x@2 w)*kdt2EZcB\#ec(6 >3H+8pyr![nQ=)?| x}Ո[VB]V^&Xϰp.ibdZwQr@7Ϧi$E-} I<~`_ČB!.y;2w&I3s"ga>F%"wPİGY7^se ( Ts|zEdqrq~~W+ZD1:Fp,wd1(ǘn.\q~T隚VڣPjƇHdxޝ/Sd 2΋#Ȉ`f!E,Yr:_nˢ.ﳠeDGՂ%27J. t&,6uQ&z| )2bin{iz1%Se9sM[]fBGx<[Ƞo _v>L)}}4ܓ$c _ݴ1>G1Zw@tfV/$ .峌'b9mDnmnZqD}c'yTZԑhxzT%YKrz)h0nzl=㍫.2&c~mFzYXI/ C %Cc`B`ց_h^r_} mRvZ;٬s {j ڼ;g:}-T uߝeb9)P. ȘI]H=!Q=6g^`ӊ n%uNtF) :}Pנ]s?:c*qSݐ`V-]ȤER {OuJKXFhwzo9[0_=ghFJ5'+i#s>vwc +Sҏ=‹ՖXw]Bj7V @PRRs>I93sO0k Ħf 0@VOj>bRgG6hgP3>b1ڵqTa_凁*;daH$J {)Gř=uc }Q1\ 8[m$15kDRaύœF9rc*@Χ Ì")NYO`$Ls5VB1V.F\CRbSni?tO9EjMUd5N,0C)ͭCjUgtH `Eu@j-ҁ u]#$arkC%ҏ֏ gō-6ŝT`6HJjBJy@vV45)MXb.lZ}h|ݿkfߴγx v fi&)Y3aˠ[uZ P…>?7ʳKu(q)Psç'xm0YLvc<\_$o#6ďJvps뱢ۚ1oіWx2XhUJ8'4a_jTx|G PG] a _gc[H~~qG=ӻו, I4XZC|#B mըJ0=_g8+c/ӵ9 un&}2̖G@G]. Hԩ]oi3` W3.zknA{4 AP5ޏS3y{b&I'fE@pvE{/>P H9%RVꤸ&O^[pSlE4{IZ5rX|T]5Y8'>4`l_+U X8)< ֤K7kalMn!Ty$FJm4R%jω͹#Hʄ?kqYƨA#<կv7fw{IוX3c/;G}H^jM\_nbۮ;6Y,ݘ/ :6l(&|'6(ҺNleEs\F"%=70~Q. |-4 K+)Y .$fx_ rNkGe8?1𪃀Β*Ƞ7> yGX&7ɫk'L~wQ蟁БQTdlZF̚[_g)[IX[ȮnӎHQtɉkmS&(;ia5rϔviJ[1崁{rpIB7*cnY], N+RdH̡s&H3>Sڈ͌~:e`4NJu ŀl樚⻆Qwτ $gZ-"ÜFKg!<67/'-IS}}/oTQP32֐;*k'/0<T^]@_~ʤFsϤ"O 1e-9_4.VW<3ya~FA~sG"|^@^d*0TTsz)VLIF7y,O=f)7~C7qEZ8(RkUa|џmN*$8+jcq4sDB! :E7mBu9%[dhH(N\?QoԻ<M{V(E%PXt2;< cä)9fQ/q#2A!ũ=kȰJ#Zg%}rT)t`eO9ACG+LIuRW͕E(An(:^yOG,쭁?QTMrW;+\80' D8\~)qC`L7i?ωɵ Ȍ( xaZ.y,ͥ$Q ,?IFDzRDž>r eތG^<@qiW̓.x(\ǵk#vt\b&ͷ$04 0Ś `t?sB^ @DbI "v//᎟:F]P(rޖ@ ud<6c* S<4LMgcViS~1%J]6ǵ |H Es"Ca8c+벾. ˞>$C 5a^z]2&Q@E1PdۺptoFTLI3b"p0YӤǁ+;x;HP<ҖZ3fһЃgbw.ʱX',eK^ }Tam􌤙qnN r?✪Ώִ%=i!=AeufkD@2w?]#) ήMc- 9}p]K*y'}X"wm8;qqkMH9*~Q$I HMmwz})1S;2%yEU`nQf1؄ɔ[:l;?S3U#p^Z[r;L/R 0SHGD`ɏJ=Fֻq,:x'd@g,/j>22Lf#Q a˺G:T;eKq;:H -1(dke`c4B^Ơe,kLF'*qh;%?zOEmTʬ=@tV0 l ~/qy?19!lW'Y>,^M7X/6]nmAd/;r$7H\t;rq$װguŹph{4>:u'w0ۖKZ ٨:M-t`)Ɂ 0CK5k#zE&^԰Yڔ =I@\{egkkl;vWN!r4>*+D4tKL<уJ DžTtӛGɁ$UV=髃uD(wmK]8=ԩlb@ͧmFw\)YKk-zѫQx^f ӱs~kT4уڴLgEoI/ ^+/Oހ.b \!?Jb*bkv}yoλqj?Pgݟ+~se ߈BKtZU|h 3 CXU$Mr 97\׷ pΚqޙNJ"~Ez,zi6|qgjeAkƼwA{qT}s,|0.$Y832 F-J2s &#q~PC i4 L%)5o|\uP@@e׬u=hK'U}4,@%`j9E#IVzjZptv#?Xq'P~'Dvc}rѻI:gwכ{?fM+x)4[5зh=&,ɕl>?iҁ.A^اy]B|<Z!h-Uʚ-񒟔YE>9}3]EV0H?Ixtd7m?ָ[f$>u,>!okcqk'Nw_n?ksJa": -+f{A  [F!?4 uёr>݀s!0|th+AB_}Fdf \꽀C7)*IL`Do{o*h0zF= lF28U.CI Iҥ=pr{l4q!\`7K8+ȁy٢fP>]Ƌr(n=>y.`G:7 5.+aȘaR/,w os}5ǣ{-C_(muj'_r. ^ZE5 &zuT=zvaMJ[3> yH( Km%Q־mCAO9TBP=|OF۽wmE58Cq;jsf*^u!gC˭x{(7BW L(\`V cR9lLmz``Mo,c?tMaVM.Z8})OPhp|U]j,[;?wrkWc7]PM5K6. +1<L `%&더:+XQ?}!&[ƐmCWsw;g Bb=j[ T9.UO26zpŮ8?zGo*ȩ̮)Vq7EvvwiRkFG[ipUG*7k<ⴠz}~֛_ 7rq"=h0^rE=aSɏMt=4רHM|)u~SϋUg}r=S3( oK 7 x:Е <#3U'}\DTRMRg3U;@ڲ;ǿ6a?b{JjKӦɢ5]%s & 1=1\alyS -%Om2t;j.teӠ6qL*X Њ[Zms62FL0M&[>9ZUfyzeK}cvп~nsﬔG~A1@y5ΐQ2j:[Q<&8X Gm0 Qb~ðY0k$o翵%L><2TY v@cbup ' scX_U!ExS&}2 j5)уj.35l׻t٤ 5"Ş> ,2UDTUiX V?Ę!+S._PPE3Q:r[ݭx\Qdbi)>༯.*y*T"WV4?YMX~nAJӿr麘aěy.(@}B)`dG1n<u-ﮂ8M:\ل7 gy03!w$G=ӽ$.gvaQȇG pҲոkMDC~l MkeH[y~~(Q(0 _Z:p4UG1 +t̍v"}CB&EݪIŞIBV.6=ZWv 2Ï+)}g '=Ɓ{Ȧ]dia[^o{`.ST ȸQbe%,O vCQ+^~|7PزARu-\]yre-LADO$Iu.U<232'eӆ,C bXsD4J{{ QSڹֵTax|Ւ-0 }F|mv7perJhaqHd*T셼DpDWDjѲ^gZThz3XwQ'esW _O6J&eGK)f[;Ҙsd#-w4-quK3@,NZaF~3E[l~7;!Ufd&F {/gM4{꒎2*;l ]$ThnkCɚ*1jyO0puF>*WĔI#"M $u_ =m2;lkdf SaY(`⨺-Mj }BN;#}OI'wʘo"fb-6}e;3•#Y_`;uq_㏼׸uq/C gF{՘VxNKN AngpζD(4P ]&hˀjlpL#BH`U-y\ E|J''A]u߂gU'c5 V:P29Y)صb({G]:aǯ-flQKak"]!BP=ڒ&\":O4fyUR([V}c-4'p;0͚51}kPOk"LVz.Jw^pxJU6j J0b߷z?Qy.ժf_YeyE7SlX;X u[%”fSa|?us`qp緋4wD_tch  f6xٸMPө^Hk.#U*{h4uBz)[7V))؇F\Z"@+!2lHETV"qM4j 2~ohr,\tSWL=ŅGLCto]ͭ}S|VّfSA/%%RX܅Yv_:SW=n ;69) %g[k0Z^XF4DQ:nS'1`3 #+p+1鮜̳X *Kn+qNb 2}Q!okOD_P@UZF3:&N=t72XDqUIEQgOCg3$Sy)paS9o0J-SvB?y 9^ +CdY1 Љ ]Vq\ߟ1Xx3 tu,^&iD'-]<{v嫛<}?f7D=d #>FQ³&_RӉ~:I <3gۄv3jfUR!fum\Ѵ~+W<F[?4ڌI.KLhL?aaˢwatM60}3O*H=C< >3;d#'Qt'YI*ES+#se*!ܔ0ZB&$ЕE ;:oFQl,H@1-PD;F(>>Mےycӯ39)OB> MWٮٝ@'ƛ!C$.O{4i sP؆E"mz.e_k@hS/P;[ iՈUpSz "05V|Ւy1'wX@;NJE~`@2؂W, !u"w߲R'uv9Eg O(T8 q&O$6d3S:x|utGí t5|؉=h29`R#_a^to*/];q7  #zc͙&.zMy!a5{6Ûa(g?6)}}&F2s'r-<$0ٸW\*n/-@7lA{a9"!``ݳp@!@+J:X+*.9ǜs}R.eWe_^ G2+A fU^g "ᬊrxC@l׌dT]= %~ ATճi>-"xd{V1ɹnv7rR *%:$ ΦXTf.|dJ )JX @]7jt:F( l4ʸb,b'J,3a88a=!W=q l'/9t;_!KB4*,DN C }x3dHFhٴ_Y`1_0KʎjI׳~я;=7{a8YKK e$/ g?O`Om6A2s k) uJ9!8r2\+5rt3 { bv#BcHuڭ^8 )F>/ki^&O]P=7 (bҫ.xYV$ƑwLtےcX;cˤ{yڒ ,]"r5=hk?dy.`e="edz&I`[L;pD)%5 z`x`DvF`= gL .sVl!w 11?0͇r$1dHU~n o(|U,Òܿ1ioO~&jÊҩeg^ czb>i+dV^ S)>*eNjpmm $$7/]~U \XDsYo,DS3C&)#A;cJKQd{KiUxL)bA&WG>J{C>WYAC'3nS@G1m/]-e~έo$Y2T APT#iT==JɩR>;f8uQ@'(Q+5w~Sq$@ٳ ;ZF *; Kz6L^Rz]8Ĝt_%E?dd/.:`# ׆tc~ǁqGa\2j0=F#lq٤*Ð :r\$:ѽ@XaosIvܭ7fcOZjfm!iCGdzEV<%p,<^{>3G/C4AuˬE}7PǾ0KItyBW}+]Dú&H=mczOh|.xUZ݆ JT{M a }@R!B|dG6'`wV'7J|DgXV壩҉J97iu"Iu9V!}Xq" z%5/NZI'E0xŅA{$Hi_Zq- ΰ>D!k%H?kSk֪Dsw2L&ݾA!f5 xj85G>fǂ2cqBڣ!ě7i2x%0 Җ[UU.ݬzo&;{>Zdb1JzF_w)B5)Eu`g >拶}r>/]))7PW湭MUEB=?(ª`\Sijđ@z4A T RpIcPS&j̔ʁkoDt T2.E/P)g`} F#%w9J"OW(c d !C7+h B/-=E!@g)3OgMA7c -#2PGغPmU]3ܿJW#󃙏q Cv9O&.EG75ԨٚvϭvR4/T{Pi3v L 7Ȩi#uŬ%Jz3ڝyBd\CbA9]tNmw܈݉fu@,n s:ɉ[$M!znWwƙk X}Ǻ9%&"FRw﷕W(؃L/"SثdD^RyJ,8[%VDb-GW";*ݘ437yrN;Yrft  SSXh<6$TcL={n k3d~W[Q:BiU .0.d%|Qrg)$s2t([tx&pWN_7-,ȡ4f Uar$E>l'Zj!2Id~ѐvX7WN\dCtN]n'e*wHPV gGĺp.e6>fBw}D܎&#`F$!8 +K=g`@mʌթ{چ :K>D0K5sF$aGy8Dg_OGj}ʎy&dVol;Z}l- v=3S GTfp$IFܪ/ ԂTNSRqN23{<ƴ*mza!T~&夋/ҨI)Nh;BGd1ҿ\x`ՌV/w"ۊ5@޲ #ScaE9NN0(Ď=#BQ+#Y(9Md[+Th&/麲+x8N[ݲAJUg@SQHa9(y[ޚdS}Ӎtiv2Lx[W-Xu_)ו;EctG)$Z D%P`__uYZkJ"J 8I,s`-Zs *2/{2 $bKE ( bH<5oh1Kv鶍}$`Q%6^oC]?BHbrD^(8sehUkp6+ح6G*q-omed)5?h;͚#DtBlC4Y'vF|Eഺ݁m쟚5/}eͰg(C7L2x8Ww(tC_t׶x+xaGcMBПLC)N&MCZþ`MXhpmEtyDQ&laYKwKZ6(,ռO\ee c;`iE֦JYUU+2y.7M{]O]~s\<Т23_r)Sޗ+\[#js1*I^t@v vl(+$%hrNmf%%ۡY]v`i4YbWlzej5e ('SķsW*%! Cx>s?@YjrJIݱbcl*uؘHl iH.."Xޓ~X%j gnYD@J_fوQ ~4Vd}=˦/ >xgT>ZM'88{ t64QiYfյloLͳ/X " UV+ -}9-t4֛T K͆aQuj|A"K2ݶpEjDQoil@:}{1yy®fE1}&/oOuYM'|Y $F\&uD촭#4qTKYeǺtZVESčL]|i3PtY@$dF%_'`l<$= J"ѭVm_mD1HîG$ykϺX:ެn%L/F է#VA+iiTPF1H2>_;;}'Jhz?D1/ð,|UF[ǥ9`&N!cD<}/E8G#~JfGYϔ2wAZqM|5a1 fD9cYa2;)^V}- ʨe #sr`GlGg>D`zrsfkגbupf]SaʴF!I{; Ңs;GRDbw%D0_0m3E Pު,/:)IRh]ѫ{gi6i_L=ǯe*ƆDߜ5kViP >Q86oXf&9 ơ+*Lo ]wV>L}.JY(%}.LP[sqgz Gg;Dޱt:~n :W0}JZG 9cׄc=D, |ݢz@;@ ݽ"OdM&O[i*ob|bq9_"[`+ ]y\Aqw B,1nKC)_ҚaAGu/Sy4:k OH"nXtTqGlOh"򯤚-uSͪFq:}ڝ^:ЫнM-%S1̽Ȗ?)pg~vZWL:l&Ohh @wQګѽaimYc.-CN[<6Rxb~ ŲW ]8GqwB_1; ^Ҿ w__<} am`j`nzܘǫF`\RD! AM.Nus7JŞm`a`_aMq#[?%Mx-FtA$V% cS 7\qyMPg`d Q|\Q0W0=R5jS>(^[=!`&!U`k@#rL;"(r^  ѸF.2s'ܦ2@KcB2'o8Zܟ^(L NyHY'ᐂS\AX\Q5JpK g%,[zϣs>z+T+~’o z1P{2֥>̛E yoS#gF\joѓmb[XP1: P4aZ]c-C h ($"81=~_fbJ deS3EA$.Fԧȶf{cQ3 ;U/)ວKZg2pk>2-ެ r_p5Ղ8j{Pg-TQxVi| #m1GveAypuRva {8A|V1NO.~b2ڮE_8.|߄0uV۹QF5|H606Ҫ -]DŽ 9qhˬl*)^ˋ$tP$ޤJtLL2|i gP24 9]`ʴaちX5PiyB -r.^F3D] 6 T>o*ޙk#|?b|B\֐3A?PaTgdGF׈-n)U7|(~8.o8KK,uPbHvN0pt`Ju(ww)0Usb#´Ao)A ƒ. Z&d}P;φqZiܞܼol]=|%w3â3-!"Eqvpy.Op (J?W=l/"STi$e_GҮwxx&m ~nUn|diZ'0pHջ>W,e=aޕL@92 qYD.USn3LdB.RxTeqmS1v`$doą]W5*}#UpO&=sKCGU8=O=)G2(d*}Sa~ _XXS&&h 90Z)5C'h-7~@ǂD>:Tao sň1ˇzm6% V JC u;QޛI EFG=ZHZ ffI=  <$|<8 ߩM(h{ deY&3:˷J <\E^WݢrtZN!@ BY**!'>ض j\OWL !(;ފpN)}ZJ 7چ=V@G8tu K )W͍})`z[uN2N=gc' ihoCB<o:EMb@N'&e4%,\_C Hd5ɲIlK:BXީouˁe[tJb/^c9d 7蹣"yhY/VOn/H`mcZ d72UXҤMU=ȑ.Ig/y5׸1=7ώ?ӛ~Lڲ.q,Pq@rUޫN4-Y?&Qf:rqD$ED<7Ƥ`1j%ҫ,8y "#+%Ib}y!_edgmxoƳHJ`\em#BӛAzȮyW'قL)GJfU6XiLO Ov`_h2GPT}e.T'FGPԉ3WNY O/pzocxw,2#a!̳k1IMvl]"4]6IƆ"b;̣ Cv N预p#Ώl5mg"A L'cȹvzH7o+ hr&UW)OLܥ>,P@0tW bQOy/P+(f`P>!ىIdĵnmCᆏQyDb4>/O:$l!яJY}AbYg|M܃*S@ӃЩ\(D9'M‘^R M}Q"DB;яʯiwq>[}( N-+J=h0UwwoKloٯo\qx혊Ys*7Q><{ hiNY:)wnM5%z%#kT]bGȐ} sah &28]|ץ&F+;x]5Mt#**nt.m>'IM}~bߑ9? SBHk P/&5]8֡NfF $̓9|@P~4ع[8iZu0Ke fB#)9bR,A6ARRU:M;BMKTˮK-j\lTHò+NO7mvs?]&8;d_0}kQ\9bUTu%g}oR'* tqfFA|Si͙[IݽNdgHp_ uKn%II{ ,\V.APw\`_/~>1u=ELs?Me{E$>ϝ=vPQMwrņhMg]^`ըn8"-jH`0Q]Nqc=V"F ! )3u'$> 4qY1ZIm@=+d E:N}(m;#=*f5}uk(֢fr#8D Lkp9;4` x\kyGv72kQCGxYG+J*_d}>J:_;?hOAv=}^綄C҆)Jk=zk2uatϣϫ=Ve`#R $$WžId(-=TB] WW*Y茤⎛ڧqkj/Ϙ'8>xDoNRsdLl8ʛEtәRxme.>&흎F@?$J[̩]HԿ(ʚNAXuA鐶ϽY."!,b5Ã}5=`uOmm)Y/?v5b?J>}6^aك%o"aVbM]c(NqI;QxLW3ֆtK\ @ac^V`wX[oՃיyW|5 ?İN*p_-4%'b)AV,Z0w2wq˯EĭoK1v{j뵏h-@cZz_&*?$״e䚐x9⇮TߕT2g}CE½##@pv#,aך~n` ֜YTDJL KRUGG^ }= [ M3r3p|TgWa5 = 7d(pJen3Ta옕HyjA\gu+8q渟,ϮlPp~[@i(Kuo K pqĉ1dNXg odm6|T뾯곍a1JbSX'W"H!s=:04M8{6ٲ1ivbPG?󧠈.!Y'LSQ-`Imzvl MeV0<1ڣ Y;_L؂d5;qB5ƛz+)W/5ŬX^٪[9|؎w\((qKk)<Ғv+1P1bxSTr&l L>z5)L:,7[_Ғ{MzբP(!F! BfiרriћW5 0&\DžT#-tzc7 \c2igSj[߮ |4N1[1a`ԟ>VI@#ӭx_ FCA^Ɖˣp𩇉T_ʭ_ f7"Qjd*CczNxG!/\F@^{emIP2qAvmv-UÞ&z`<ݛ'J:~@37"9'cGYfIGGY!ۢɿKg1* 5}ImS*xqVaٙb8b[y>ϵ徵S.sI;{Ub\fkU[kcc1Fɜ '(ST Vt$q-<.%44R40O[Ms~eĨ263m+^u[ *k!ѫ 4 w'ҋ-hy!]1(\OB`~jJ7ι-)]NL;VE}I-x3b!y:phXEr51R/gxG8/gj'QKO 0Ww>i`4ǏxЌuW۫29v@N#RwSfJkd޷S 2?ygdIQZ/Xem}*ea4[ݯIl-cmYl | wi =x5!{Ҧd5#N@Kd ?# +hrgDh %R!4݊ˏt0cٝ5 Y<=];X˒5M#AօSeϜHh{fB 7P{a&w_mne XVƩKM\s,p584a'ah|sK5=bdK V Od63q# 0',4H-儭Ams-KZ*ȊǾ.:k Vfjܩy}_2kOREl8ZT.f c0g+ XdAEy})Y~?4~sxǾ*[;yW:x`c+氓j*iwGS߸Wb1sh R/w7dhLi3]N)l|nq2Y ] K0dU Ld{;m ;Eaf1!?EAX1JDkdT4ֺ#,P-mks|vXeVօjpn6A793˻ ʎ[ Ƿô,UQ&ƈi`'2Iw¿ZUzv@/9ՍB2; KLGWADB϶l?efsO b] jP1Έ@$R4t ^=Wf| =EղR]@=ލ}eSXRR0Ȅ8vBRCa1TLfb壘6d4G,6%9*ĎTE ,f]NϪdaN H}3rF߱d~P{{ɳ(5)c<0P!Ź^&ݎOa$.LB@@Kqɑً6^4.AA2OnQԈӳ|Wv5)Y%-tt3Lʹ7}S"Ӄo粀_]W[x{]29{,5">YWue0V~V^{T$G8TUeZRd3zJ? `4X&%$^ĖXBM7| f);컫zݭq H8~%ʨpO,;+fJvB\?"-+s. 5~ԫk[~Rw@ ky1?Sa%gԤRBYЦ,, #'ALTTA@,ZͱCpiaWD2s+u`eIqA2ZG$w9ڢu~IbyʍH;ĽVʬkiݥSjOGojU.*4hm'0c k!83skC^L_IS{oH]]DAe,f' o vyfۭ1mQs0"=59_۬-hj}(/[bN73B[~ dߺ1kTw6n2kO!0D"# +ej+_FۿWǥB~塟T: ziiEh>6K_M&H%2 _G%>D3;ho!OR cRnCR~A:~r`T4==*c:SܜTeִC5Є2ɕثt>/*Q>*^ wMg͜[z%U'uTRQAj KF8l9tJE6cuR{~c>{8T cHlGX<^T<^ A|6vμsTjŠ}g){󜾡ajBUۄ978KLrS%gUGk DX=rᙜ:ۓo?3s>+hzEElmL_fߵk,~b;Nj j\O7ܶqۇ"uӡB{֢*dQiO$0wЯX,ƙQ^"%9^Ey(%0C3P wUlǹIz#\d_*w6Xt`/%gL5֎I{0rQz^u3"S ר t&81?q_oh6 HkGXs^BYR{i}y3X2w5@Vvež}"eU] t P"0mOHcXx09!\U=]n&aM_nq?QV@7TzuK>0­'t:ijEpnZs򞑅 7ޢi<:$WhȏG/RpjV:< ;Op_- xm#@#0iYf%C!}#fY)rFdU(&SS ˒jûFkDGrcY#iu~KG40m6=T=W?/4a@>S`U~tVADXEcLr"2(S~#lOb~=sdޔV/{}H܏ R~Z 1Jo v\6^: <_ew;FEȐm?pb"^4dYH׬`BAT5~ǙzP7='z&}VfW3uG G5`m>I9j_!1g6>tPj^~03(P0rA>md3BL'e>ȋD IEk ^i hஊQ70xb2biN ;PVG+@Sl!.4Ⱥ(8׊/gkSrMF6^ۛm 5WfnņOxaL' :+@2 ٿrOϪWܓt|IhL5Wm+0]3} PMHw?bàZJԸ:ҵ@1$k_EX`^mcJp-Ɲ*1AE&B ݣ-{/Qޏr+M8()DQRf)R|B,GyfmF6Гd!Qп &CbDȟ٤e!.7VZAd\.GɁS4Nw]&ћ+P9pRϒאQ=Īd uceFsͺzʪ}lWK3>%Gb&^pUmLEۗS.wΌ4Ėq\3-|s sVXU?TUjMi>2Ȩ!M;9gz ̘6݉.яoكd_̯j:bM GqHyf#_2&n-֫TnNmf歂4~a~]nnjH(dWὁHS~ ZKϹ Sd`c$4-|؁쀑u|z, ,9Ö?tvԖʊJId%X T[dttP2*lNbbᡆ6цbFʻΐCuLUgEyRIw{Dcs5ѪޥoYrYy NDlm-n}ij#btJrs{`mMǠ LqMXep1B1SoG$')6:DOW ?7J2,Q"Ul9TI >!jʎK`m{#d<Z%53j9Ik3al% ű@@dLWSE,=qPL 3!½N@JQ%˄˻+ů4H[RG.$"OeQ(*O祩bP%/tQk_DQnVs-)J>)\+D#xqbFgӽҶK?W0u-z!z!\y}e}3d1f\ȩh/}oվÔu(f+\b!.#0@EFH[Z(b7/@/?[qǛjp{鹡5 ڭvD@?5V-B{e A@)~B*F@3-3~Ȉ(';:\qR!H:4'7wu)9OO\pVIXe{%;5öK$Cb@{x zN>1< o'O#ޝkk}2>u徭f9[7 ?V9j9N{r?\W{X_f(85i2􎻹_l4!Wd֚̀Di:һݲ6*Ց lf<[4.̄X9';43Bo9 8O ΃ QR0ɴ$M E]0%$xWc:t٧Wov1-z>#g>OBFg +`"A8m˜P~!L2g]> 4+/ KRU)zvX1 ;$ AmJ2)P*vvoMH6AƦ'ޒЀͧ%Tv_HV((H&䳸Qz9 JenYZaJiuW7Y ҇%wt>=Rma`zv>.>*\"z+ )JA=;Vӑ 5 }w TU#<?M(#vQeBdWC6̛3\z.G ߜWpn+P"fUypܷ){-=ޮs"4/O!ŗ |'Jg$E*2;f~4"8'7hz6  Ɗ9RG(VDd*Dy-8"S qW?$ϱpK5"rT맽dIæX}YXM4 +Gf엠-ԭ?.%o[/kݟ8̣'B9ZNƹAY4`Edeޙ\5[JcRTL%qH ?Auos5i݋%D4X8~3ܵ[xT\"@wo>0Ȫ3oKYXO 9.{>~i7 MV$-$`3O(z+J6gqawx8,MZ񛢎*%9ƞMv _Œ3$ K GB)l9Vth [ޟ'SUC}CW(jKVGܬ)fh8qQR:H/]>pxt|mN:57"W}z WXHFx5?@ZY>OW=2Շ̧U= LP˸2k'í;T1 `[cT#>}{/D:dʏ~bt9" ;oDG ʾԌUS7oVfϺT$wT78(YC(D1|SrhSWRJFN-QIq躷sA"ܜO99-$!ֽUuεnr_Rpr y'EE,Χڂn X技|Y#H9joj7 Uh9+:-B=x}rCNзŔBh;͜ʰj S B3J꺗mJ W鰤NGur!sت{MU}-7RRƈծDR).ߩtK_pK]+m|l `lǰ6ĽΜGv}`hjDQr꟩_;o7HRLX*Gc3[v۱s bg ´J, t/Yrq_9Nq7z 'RejAU+^&>ӯ[.8,)w{k4/w2TAOyabQxuyNB34V%#\|dX/o\C+lЋGcBQ(0,N;tD0Tyw~ަƔ#X$Sߘߔ87 b2GZSwǓ6^{W;TQN6i75N;Ϗw]nyAQN?X͖pKGx5+` щg`!d98}=G.vո!:w@AmYu~aY\YMH#كU$KwW1~A+[rHdFC:nf=6hԭTHWW3S/>2Zⓐi! <[xǨXfxQu`r U7 Ȋ&m`RWQo_ bf7X+_@-#ߎ|Q#[A'L& ^0y=""{S+?^X~,xHm3zPA6}?8t$Dg3>|ժ oqE1I(e ^+Ƙ,ߔzCuUc1-Fb}>fq;wgr’ɚ=wg=zo_ZT/X ׆s/mMN`Sݘ/ްA3 mClH!-0N@/Y E5TDo]/*ok ~$D"lD!y6ζ:( &iJ Z[xWrKbOwMtNMC"wBXE@?JޙxR}m7( Otj B{D:l[{o^*Ь/ˋ`}!퀈},S80@UħMm*= CInwi*R kugiԕ3aVNi \cme$5lh-ilƅ&U[8&`TQIܿ{ A&N{o-:9%6Eӹ>^ȝQU +W,g91J\9D9.r^B.|JC }4܍2ۘQ.j$a²(iB7˱$Mu_PcE(RuG lٸRq,18ry<\%2PA{v#k~Kbs uj_eƒSFX:9DڌA Yh#28El%X?W(MϮ5XHOM$Q1߭4lhñ4l=H ӄ Ѹͣ<>v[VwީWMs; gf]oL`|.vIGb}?k#tYpoj{5$ZhDZ߭c{Ej.UV30JޔJ^)0Ya@?xFp3FF_^<[Tax R8\#Ui0͆㪌i>FAFIt/aMz$7 KR5_[t fIlNC T>4rYBɠ GV4GHZ BV&*-+[Eq Z LkRkf# Bi%8?茹ܳzghRk ?Ќ{|BG?'BS(\_J3Zf^\0~va281AďܿJzE ?ö;hZERN>~Q_C4trT >AAT@c3^Yf' d-gA2tZšWNv|qDW| )Fҩ~YDٟN$P-%@lj@"w?T톗e< *%g\5,?ޫ]<¥x#'G[FW F0A*> 1W']kGN;1JF  ^޲Et$ruW>'.䯉29XpkD7\Rf5vy[F h̩ JgU|5(rC64 3O0>M>>u8R] Ӫo{/|m4U *oгI0ItcWC7GiEdYQa]/<>P㈣ Hs]L}1Zk9^Y/=KNk1 Evy|}QǨdMs#j1Oܤe>DEB}wN4qgJX1CAj؃;w(y w[[H72U>y~M*OzJhe#BHJ]o.'u،_?lx7ƃtnH8<ιgp8 uu`bQخ P:>gh #S aXl??mC^H$QTZֶi* Ř̟`5h_zLl t&)P+囏8⤔HVIr#ml2AɆm*р۔dAl~R1OAϐ${WoXer{_}7N\AOKMø hOF @AZI4!T6Oኢ- q >! e;iV;w9) Aaz ӕkR J[' ]rMV3}4wZ9͟4'&}d,/q%[$?)D ?%+ 5N56̡[5O:× 5  pZh}z*TxRhITpBU̮} :yFdwYhҮ jUdR/X4P=C@:F?vJIW!Ϗ(&j{UB':_[OfIC39PH;:O"`atc9(QpcrXQ&zHrpk \NJmt +,*\~uSb}ƈM 3FuJ W,1{~S +hEŗ|ǞHx&McYڣUPUr޴[",0zX.~NiA*.['OP:}#2[4_WÊB_Ђk ߒb! ߙrŨPVN -S#Rl`$(%K3Eik*Q:T}':MY脶f"gPpv¿(.47w5bH(  D^Q[鄞~Np va{3;-GM70qWےKBV#T(`EipV*=a;0s׺F;0bvU Z''ϴ)q3&lyc5չL~#$ OVϐDJʏ;dxGj~ewy ô< sFH`=[@7z#qUԨmw8ڝr;O6r'vrzZw+m6Q[ٜP:0+PG'T,Pl'TA=˫Shq U9~ h[#.ƀo(E0+Ug_~ϔ7zl?}l?8$;8uQ"6 ŽJ {->^7N@m9U4 5i/MX  TD|uyDE 8mq&~BH"rsoL21md7G5SuV/^\I\Ÿru ?;e\{Gh92J=D20i6V&~U/7h% 6jt> VZlQ:;uXl)dmnO"̛5WX"GҊRwaR'V}+e&@CC|z'"zSpO6HM[a_F~[ 6_K{u3hz5-HJ!Abv['LmS  ;UWQsq_wS:xH!gI?>=!%9ҋؼv5V}xJ 6Mk3n8tb.6.HSU2p.\X2܊"Yky?.oXV%!ΐT!+WzAߐ#p'|d7O\((Ȓ'_q{D%ʙB~81#_)xz+ w>I/|ц$GO0wumb;_:P![]T4%n F%F: 'nZÐE^?>۴: ShxAZC}xpX8f`6"4l]mrF\N0؋^{%e7hkMln]vJ"mm)S7hJs^NVGҡڼIq>$Co?]{jUwb  Xpc]1OJ*HlAPc SFQF8\(3t-2[]VMg'怢^ip兖q]IV^PKGtj"Io}$J%#8[Rdt7.]$(B,`|&dht n8V{tA+vNAA*ٰ1.5# 8q[I$e-hq O.>\5$ H* {/,[{Z&eϑiz&>Cۤ\WYb$ƌjuKIb 7JFXBp<`KTuN u]E v joQJāJ/deR:3y3D?t(?Owfl.kX]?B[rT#<8, l %U};.Z*_"/@u./UQxJlBQR }9|O90?]Nc-5$FGF>@76)7vZ@ ;fOygdt>h KrwKbzQKуZw4l-Rh V,?G<2*y`ߣxDT_tB^ n UՀf`":ɻW:U[Ao,%@,U6o9uQ|M~ ДIw }֍›x߇%ܟ&cN+F&C<25ZRj+pa3mNSwlK%8xѳ2}ӾtZ7 Z3w+=AM˙,or4U`7e4dUwź /,XWEHoC% /gy/E)漢5y7Z _ۏ ՜јLzh%,[ShuZN4Q^KKrж w10\?ب+"ON_E?+D+zznADFf;z5iEYJk|;-~g))dv s /?5C ^[ iY;Q`z(>oEPs$X?Љ83!ɍoB,`,V%.qkh|! D~u9y:bMߞDmLO=;7Mʢ>\=#e`.*)zy~*tP@(}T6]rp 9 LKs\UW[}Q?0>B̦V8mȩ}QaZA=aq:(/ږzGۨVrNDƇW}1ta~1_ m8:+_f%ԷOAuю2ͺ,E8ams^t"{f8`홐M|Yb2ytر"h -[}4gbɮL\aŞ,"HGQrRaR _L}iUȵib|G@ agvcX'!5 %!w:e!TL.zZb'-p3abēV&™q!nhnJ:h[*Yr4:X~Pϓ m)[z)#līw+18='5 쁞<ûO]e;" ًyAY zdbBS^<ϔ{̕HY@7_q(sSqR a[_8;as B?|mt_k͔h AWX՚3@l Cz85A7:(uN~<3sWld2Cz|xi 6SY+/^#&C:vA&3iDt O^hrM)a'GѿnNrmn qFie!|)oBhI^{ifADwR-Ҝݪe/K{kRNS٬WϬ:gڟK0Aо b`ge}xc0O Rj";jq;_{_[3XjV%*HD*$ފ%h#Ȯvƛ6Nbs@4lc8GjWjM"|b9_\ %uEtBj~4zXg,S4cEb$)}_"ӄ7`Iti8dw4Qwc'#yʏ" -QgЊDq0Mz@y9DNlOAg!ʇܲ'5 lNM0ak9 ٹxD3Iqu WT31yyVS(4vde3 ]6K8Hԝ_Pִ:O:}{xDi  5( gz8H} R'x0MJnbEAf9 RKx( /XgZvY(51`WDbFV M>~ѻYiyW*y8OP2iqInRM[Rϒ.:-1\0ۅhd):)Fy`Nr m|J¬O1晵۪4 ç_8@j6ݼFAuTDԳ/z@yXbU`駐ց}IVSp0=ʛp.\0*tgB>EZښESSAyIpNo9C,fgK-bVk.;)~{e?9#EN4G u!Z*M pN?ѐEz덙V޼ϚM3$Ka&phܖ ӵnϼl\͖ĽHb)C_=9.&:|ɑ1UD!["J;<5Lq5zVXn &}xs1B k&|ؐG/NĖqec%"% %!Wԡbu /7ܖɕ#䟍D|9Y!ܧ3",)7[bE>Bv"  }mkڙ{&FivG<3yS?C[))ݵobӡ;uR0yFhvv j֑S hP踫LvQ6{VZۭp71KX Xa 0{wբ֕}P;{qaOSG@9RX Eް’N'DҦBC=# -a̯ox-ka uݴN p2gg⠜k.vMNBW̕w ky?Ml-l<$`YÙ{6- gXw[Y~{C}Hχ~^~Bp *CzriNc4dzvyB>+%7r v_'NkW/YY=*vD-Ńy^QEOcuߟrWc`ٹK +n˞\]cU^W(dΤ#? Xe691kt H(۠?lHLy"jPkA)# rVs%@l﬎`$"jjDAep8_*i2K`kk]s|mu_z Dm̖ÍvMǠJCǩ6ԧP>c|5W,MuQHN:ݜ2*ZE K{Vφl[9Uv,[$⯧M Snr=|Ek2o{ߎgSZGR#@  4}\5%у$9JXgXo(q~̊Q2+(6!O:#^ptY T%,h޼`\M'%ËvSۨȇ C8g{| u?\ߵH}9a1]1Ե{LRc+PFz.//G1 -ei < /P3G5ք~),n/bqQE8Z{;]!-fg;|R6tJk?Z`*sHOPR )uƦ7=/a`(0`'ļ_m%;2엀lqt>Pݗ,^8Ч !78XxVL 4l |)>;j=M>D?=:OrW -DkJ{~R8]<܎n=?JNJzeqFt K$JH,cs"ǔjGm0٫wRӨ:5pg C7 +#IU,Ue6Dۚ\_LUhI̴d0 T2r5N:MhjEr:vpJ#~3Uolcsw>[L*H<}~c(s gwM/hBgQީ;OY?L"KS\yt&lHxҸ1E~f]ڤG 8Sz=Vw?맰؝2E`ݭ 0.&j.Of=n_`12^=AuJ'eNq).^vwm#*-i exȬ$A z:lԲTg"q]c& E *{"_>8uAc3;Cd3ſ> $ ӖH"cYdC _-3up3$^m SdGweh/C}ɏ+2E NYN{T @GSHP5[-~G@_vc<] lN/kafXPBd+ʵUGbzŶ\A 1lk(.YBIJ%זy ړ̩0ь_0}IZ|7"ݨ*g> $xNEЎӽo~А0'<-IZ!kXH*R6Ks7r3R9'6hzXwomY(߼`>ږq$I'HY%n5:=u\X> ;p&4l[B ) qf'}dxA1ʸcއ3 tnF(B|GpIxD;'{ֆOPU.~Ϗ%F>O9**:F!:#j5Xu Xb/VkE_r߀Ob@P٦ WؾDb,ikJ渝F/5~m:o4d9i@K =>Y5K>]1tLYQ[Fvrb&/UZHt*m;I LtKd{c^z0͉wD҅0| rAw~bxm)Wޙ."$ MM4 "BW\Yur9pBQBRA̠l/2z7P gWcо:DWQ5s@t,&R)W }G8v*-ahB%gz?͎Q{{[?ִGg#i,oWІWQZQ!lai& .^f!>{|%ҷ]ZLjt)QTT˨Lu\H ;ّlIcg>c#rGqY,o)~Ϣ1\ ܽV[#dZ݇2тhg6W) \E( 2Ky+_vi\_}5"| >\[^/՟(g"{'6&S q@ `25u$/'xbb]GH奎ն jWsbUG~#0/;mhN]$W>ߤݷ!B KTIVwaY_mn4ѳZ&6>Kp zE~8!mx24r9Q!e/WK4(E$M:Pa|c.틂JWDS#gps}Y]z*H)2} 7 Lb]PXfilQx7Ӽj8ol) !$ J@ؙ #tnţaNҥbrV*(a ?QoD&q)afa eOUJ*V 0 jAB'}k|u1o&[ŰNR$ڤ;UdI TT @->2"`Ϸ&¬𼵿XUx ,Ms1pNF\Ίrkz恛֘!;eTDN'phB/*ɄNl0'oiY)Ad' ڶYI2l#6x:?|#$0'A]rRmhkϡ.C}> qMcK߸9a;}#x ^1uFu{ V0*Qn9e|-O;XDL2eRR QsD,bZk^`RyRUom X/Irh 0Z/IY΍*&z`cMyd0oH;BDG ~4k!bF(J*iIyiIt1o*~ZSҤVfj$S8<_0^06HwGŨ~_f/{:H;k3r˂3b9]IjJw 2Kk_}vogrk"pI)zhvĐQ=CT9jR+:"Q3i"XAmUj*WskӊJXQ2gե^h-PY(9ܭ}f)eA7YӾZ Y#uF}7 t@&մPkӆe?G˩JǂL)S'9UZ<5 @Fx^tlݪF8z ͲotH߰QLΖ죔7iy'|i4djU1DdYf[ᛒ7KH>Ҹ A$$K*ԪrC1s}"foUMy:S? oH(>{CSA*6a?66P豘EiK~dm_ 82*bl=: s*X!b Rٝwt@مÀwhVR3pbfHiLO1*K|;j{t`zz _űsĨ%R Pw9\w^^s2w/R}J&ǵMJ(Ux&8QZBKj'T ZP|)% q`wN,(%84]%cNНX5ف>ſc)C/C8=^Y}3|$iJI'gҬ=Zo2010E}7|b*^,8U4ޮ!@vT N6N a먞n=:\\%D0NH^:u 7ƥ֓z~BG69<#|É*gDeM ?y񇒾 5+r:@g$ eV;:J b1`P4TuwHaDs.E@/gτZD:(0ﶨt7~"[ ^9 Fk3rjR~Zkj|7gxgTj">,L6gh)?7H 3ﵦ`fY}}ry;s8F'L߲v)c& ;ߘ[Ct1GͯYdڷr;}`ұ`~O{]bMBEbh0MVصoG=ް[Bۛd枵&~I9V4 N}9W:fdbhtZNXMoݡR8_hP6^O g)kd\e*]E<3iM Qrm'@xo!\QFxN{ho\K5_ fn c] ٧#ˉru֟7o#OԴ~\C\ UsU HUWuU~,A[$Ů>Y5d_7O>3):Mn{u媽e~B.[*mzaԼ:\ACXzMoD*M>WJhMAtbIPm6|GgMp;btA\ݑ ( !E-RW~'@e .F:R9iKE§>nwSOU}2#L`DN<:'R{x2ǐC=^*n侐 7DVe* J"ռT\T's 6W|cٽ:BnE#(+[wX礈OZFj;EɹEXG PO1PwVKl^>`O`wOꩰ֟lYyQ-U'mW` ibs>K6qP#FZ>A*QZM`":.5j2mrARqaGޛ.M)Bh,+PNsf+@py?PḏoP,5+ jfc*}lKVS3<3qC@x\ ܹ)ј ͤ&O&{ Ɣ0?d"}8OwD %%rkW1OKv@Ȱ̊:#G0Dx5a^d^♞;) b^eQI1|yȞTh>".Йjy>-m5kE]״)uNΎxwũ #Ehh#;($ WMZ|b%fX!'ޟ}k2ϔjтo/Q<+HSn4@;%-m^a΋USS^:F۱ڳZedE|6Aw7`Q;@8(I2}ѪɅeB/p$ChHO+1'Ka1DԞ5TԳ{]b\C.V3 % g5Noۍp-ÚwA~}f07=J{T3uCxJvVMZwr1jt۞͹y5`I{x9s`tR.5!A?GTJFwݨi,/qEI?-\VAWxyɻ^-qidMD +{ypY}~oFUa.6b E8 [M"k8ш͚hڰ"4MsWKE9(:ND$5*(P&/u}4O-^|)nWe2(NQhx`1aԱkZ3cb&EN|K+%uC ăsZ 4'Z!V M/0B[cv,"aU2^sea'_f>#GyȖjk^VF= gVG+i0B]ыͥIh# Ìg@l/u6Я:仺JUP"* A/jg!/+b1V׾UB}xCDT i*bi,.uИJӝ@ڟZܪ9kF\A:`f]ɈEGL@>Qo ЬhD&ͅ;*g3wҚrPO,TJ9dPǔUzW:R.b5a@dM Ծ=GE\RB(% ?Lhb1M=KÃ,)4,8Ӥzet.\ kpě֪3ʾJB+K HzlWăNke͚6ElQdks'/U 6é|~8~zYM?kX'E=pZ8׷`r'и&n^h=o+ &ȏ:*dqVؒ-@ʁ=p!znY`Ed*/ȃ@ZiȈag9 {5h+[, Gœw_&f܂¸΀l^p3#l|Ki?612W/ngCC }aMAC bAd,7FV߉38I뮛[ oB"p' JrH2&$u^_ kCsqenAq"Ag# $=Bg~i  &bmu1]F2R% bOl'܊/P5B!cJ  |#ֽJC;ֿym6ȘngsmPMw}?neH{ϵ9MM9vzfdṙl0|K)[bXₜJ(> y`~ maygZ:(ෟz69uS3#?Ѧw]_ @L5B#yZXcqͼ-|aǕs)]s[Pϙ7M&4&aoZߨ%'zS<&l|_@+]ƞ!K86ő G]'At!K;5\S F`'=x`$*_/Re. ]2Mo)f͑N(!giTJ#WM Yya@Cݤџl&Z$/aa6ܫoRc4LP| ܼXI4 gbnܗ빂^&ϮܟhstsG(H= HZn G^=kOaÿJWr?c'0e :i8v"BpCWd {L^ AӐVk!ה1_BRi|!zu._c2;Έ09H6:ٖ롪yry omzz͗*YGZa,Upg"if Ț햽"Mzrb6{EF(ZG3ߨLM~vNh1*D!WvMfCY׍vIZ/ &4ޘMzI}s/CO`BJ qu+ݽL9#k8'_Z\$j_7֦ :\δf ;Y4YsX@n|Ւte\*jOsr|C7kT/pk" v>&/F-%qMF YRiFг5A: cĀץa1ZDpon"x.=Uj YfЖOE = 1NXb{ä?m%T,e> 2]Vtu^;siWVm`L:>Qr\各?5[7MΤh52]Weaj%W+U?=8էvYdo yYA5q;mŠ<{EfKzJI3wXko+mt)&婯xo !e:JL,K79i̩wZv!ƾ9'rR~S!XՒCɍ>OBv·Nٛj3W?&8v_Jj;mZ-N}MxUAC LOYmߡӌr5oK)f~>O[ d, /zd fN9?M>~Q ѪM%.&Ps¸UIKz39&hV l[a5g]Vnj.šy )UȅcV( r=J(X>S{ > _ԇn FP<~;THx?E[:쑅MD=C< WVlXħk(4&Z0,su;MRz@2lC7#Y_q[g7LwؤٛbG?!yor8Y=B^#)XP̮$ˏѸ L: U]"Oz Ƿˑ3yw !-ѷJ z/M:0GSN.8 |Bƞ vB尋ߥlz1.=2(1Sԝ&ufCIu<^f55C۷RWY$Tjb[-]#ƚ T3s#Ѳmky.>n{ DrFjT(w;&e= U/Ϯ;qD'w.Ka;{!/c)+m 1Y!D%?bޢw'UcP6=@Y̎{NҬDu䄹DT^US!ל 9 %ƙヒ[#Q#R% )z큘zI۸iw:)yix[e'KgHlxI>5i&PFaWw$zY}m\drn71!Ac^GH!*MF~QWI}BPhq[Nɺ*ȶWc"vreKp7^]`n%<pkd$8~@llAə1mb~*) IyЬgƄw}sΨw:uj)43cT {C q"z1iyX58%PvܱEY{PM9)*ϪΞ!!XvoM8 hV|U+9YJk Ep7bN׶gs6@ҏJIi46npfYć._5i=,,94{ؑLEd)?Tn8=,Ps qhrdr&n4b V3 vW\yk-61\,>~όhr p;>AĨڮd#oWAV7p*/oZhH|qft"Tz6f$æ5 9br," U.R6s-ŵ&kDYi&N g~ODPІJ,5{<^2JESɷHr)BEaJI:Mǿc kZk8|j Ӳ 0ʮ8c,FApKޏA?IX^+X=RlӱQLc"A +or}6RxX޽.~3" I! Xbk$38Z~XU@!|,|ۢŬ.,QW\풝U?z(}X8"&U3yy`&JV}Ye1^A:^呗+З3 q1S\pfCrƍqCt8Ʉ5,JeoQ{H,yh!zsETc%hcD/FNXX@ܗvcJk0Ms7H'sLjn$,RLLد yrW35F2;2?r/7i!qk{UYSu,h$QФ]}6Ca✓:} haSs v I 9䚢d<{/u "QFi}$,Z[($o)w4^ HE!J40Uur9Hk4ܨwϷf<go&z8q 5rl4Og.J#LMeӆrq蘞=#t$Qj<@ nSush@E4%D}ؾɟ5b{,]^k'VCĈDo`CjH gwՃk\VE(&Ơ](ڰ7 {^/izviVFC1^EK i9_*Wnw¥FאvCJÜ'o( *dNn3S2:"M$Ih|A@4Otqh^WF[q 2Z7Q*yUWco]r@Ti0KŎfP9t}ҾP ] Kxm2507K֗w=g UJpŪfEldw ,s*wJ#1@zcf6,M"1cQWQf "OEZylkE37 j8K:/k[@5j_]Kje˴$l"7nhȋӺaN M 0V84Lp|kCr5vA&g<\;|q]ka275OD<&? Z^j\ef2qOأl|iD51Rf1t 1:=|Hz`!\B"Q\Cp1!Uv@j, 96m4O\N)k#؀"Sl?>ŗ\~:<XkS51{}GZ$㞚 ^Ct# c1ՉuC◊'Q:k9xX5r>Eˇ qC$Vyҫ;b1 a/=7-<"7j0p=LdqÔb>mqܬض!xwl{ߜ&/ɕ&JƘ<)_uƕqN{evӊ0psqR2ۛvͯîp!w'y-,J'u%\0uWt>K "_ LZ',QIsK/XG5J On=CU epNTiʃFVWc-өV"-;!O=+ Ɇn_mC>5Y}}l-˸AY(_a6* yb2xpu~MC;q8!3cBIKD4~23$ lad-"l8$&C?U Ͷ-\Q16*|rL4>{zT|b)WсK:*Ud&]C02b|VqrýDjE٧7QSS|h("7)T|lu a  8U @:xyY |m%ɥh 9^ :XxW3 DcOa?~-w~29]DEyuSIt/濫]1o|w㺌D4{ho#ʛ>dP~=ok2DFm_YYc10.zC z|]Dn:Uja)l1 ^e :鬘(833_r8UZߕtWu~;: \w9x2)wG V]Бs3c3ޣ;t #ણ}ѡݩ扒}><se vX嘆P&Sհgr ~3 rtJ kUb;WHh|26b g*b&zAܵc7i!W<3`S Z\ (EC1'Z^.[iXlo:fJCUcBà @P:\NXvzYM?Xk|6FM˫[Qyv Q{F-!%\\ī{?R:$̽YxҌ2O_˜b>`96$4{nV֧qg젰Kp'!V(~.{%FW,¾V7J۝{X 4ܔc@I$r[wn+$.Ods(6^W/nȖܸNY'Ҏo݂/!qeyRɳzd슕\7?3+~̲`Es 0S}`M}JL\ߙX Jm_sk:zt|GJ: iܢzXmX3"Nh5Z{yKxO-̭Ê9vS4ƣ_2PAuS03ֱdMKXj&@h<.נNo%9Ƨ-,?"¶+glo HiL]"{hhtֆ~f\mVl1O:RTdY,)/ĪX;hVL3B`#Q(Bؔd5c|CY??47+`M [Hz[zWfyF]I0+j;"7T?P eBB?` ֶ`V oZn%DM XYڏkmh1d:f$?kX|z,/aW/C?^>GI6}I4[E<H<-@ Ц<3l栌< 0 R;w !mhc$#7#AQgKHt-XNLot$c5Y?.Pwf(cI;҆9g򟩃uUe7[: ;COys2oH `6L Q0ɤv!(teG#^SIc8%5 uOJ ҟ\ӈ k0͗\CiXt=z;A6Q ~O EL /z-Lg3IhB ZcMEuĆ I;Kѳ1wdC0|5^~2%e̼O($Xb5D~BdR$ <:HĎv[z LXR؁3cSsy?K^ e˳(J7a`~[)oz?+S]b㛝+w3}(t>HPHkzD! W<@,&ĺ}rsws7AmzTp3pS-""aX#B/ 7tfIdf0 0GrzNe9J2G d¦ g-۳̫և22=Vvͤ`1*H_-Y㯇?&PnRݙ#kL{Oo՞eN\ǀ0W$L2K ߫1Ҟ42Ӑ0\T`;doO} :ІW^'f\%}6b3k94RYLTtiꝬ2|.K@82 -Fs}u 'e{̅Y9&=FTrjM|n{ĥɴOl7MlN6umqm1R#A#auҁuHT¾_;YvP pn1ɫRf9b3j<;-|= e7.قȅ 5bt<60v F ,(;$PHn̜䚽G oD-dS5H_ntہGǗ&jXrP "fW]9Z*lvCw<ģ:#<6EȽ̦eH?/ni%ѧtbɔ]vȂ>Ҹ,!GrubyO4D~1;Ijua=bbcg*BT3&z PCetkfhT~+-k/.SQLf[ II\S J7 /e-W ͓ OO [# LxNK{;l AUQ.%xSb ?5H?Qh+vE Y>4"zs.PvuBZ8WMvf;@3@^ i޷R?\پmM~oĘTU1F`_{VL*ýDc g(O V9F|) ɝ*3#i7l~j"I5@9TY1<֣8|5 Tb&iB ^F\?rao4gQˋ|2Ki&|ctgI ɢL'f!{ q]3<~}ѴRGg |dy>,4麕UoпiL^k& ۻzS2O0=eTLKnK</aAR&et!m 򊞮 x0_Jv! dXv&@Vz%(T,C<ɨ ccv$rcQ D(޿o]:(͡BXAUOuN4} ;C b8gaU!%&ۙt˞ַ۫0XӫB(̖Fwg6^SC9΍%H / l9C/c~`0#iu+(2c&1&|xsgZL`.4'"nxKR|v^ oꖁn*h}Gp1B;e)FټDXWܢU;Lr~%_IJe>G9U$٠1e $$>@4̮+mSK%Ab^w8:]Dpz*}Z-7X8[XQ"\8ieIVuX wp92ς .~:/$su^g(8[*=tEii|Ψ`_sUiWwHY]Xj5Ks7ؐhLeSAn{%GuD/x5ʬ ℳuzlHEE'X?(]+&^+ؠ56qqL0r9U m?Wyx7 CQo5;d2954)Ȋ`߭9TY~#婪4LDzYG@50gՓX2j,EjVww^GBĕ]'NP/ M_/ix"/D~?;Dη7 @qzSvZE! \CygZ0;t CEچtxף 0&Vw`p2xͤYhKRۃ&5a~ݿ=8jQR]ZVp[W](ӞwL3pL+_*i?]V쩺Zs~W hϢgݱ8T8DGC GdDf\@WHZ -+^G_:D 2alRiHP@evҕ!~B;IuD_?v GAGhND(z=.hZ~m/w9WIW0ҍKJ$L HFDy߷S*EB!G%&^um]t U`ӻiٯ%v_F)+eo9亙ov͝W!QH+".TȆ}]\aU8`岝1't>Y%*[RNv.RJY:}bq ;jW$s{uf2 (cW4 &x&[1 -;Qux\IUהۼ$ 4ONbv&QfNԺv˰0m >⸚G,hwyʂOb:1SK:=s HNW/Vb8kUj\G2l'1D`%x[‚D+_&?`k^+,'{r؀JKTo:.tdAW2JjSڔ*%s{U3⭆ NhW w-NpI57,A)ɑYlJn K okG5Tsq=I™PaGm{h|U eAކLjiهa9@߄}~a_jgTS6ĩ#@@ah֌ϓX< ӡ*{gC,סՐ{#f h{uAXݭhbչ+ t+ѷEz2p'> %t5E*IaN(!گx)qv[%r:Hl:_ҳ;6]?Vws*uJz0ZVpi$G<]62bU+ʶwdo[@=k('LCONrz47)<mQbHV.N? n\#d7kXEwG uej0Ƽ10% {mOr[QVygzԯC`9 6&C?*y BlֶC?mȡ'y5Na2X5g^E"OeVӼZOj SOԑHT\uծ]'_JzAYL8߰+0b~#/aqн~Lq1Yѻ2r5e; 8*w) %كO{<\W#0b xFca7b 2s`pH[ LtWI{ݳ/SLbH~GNU/C(@Q9a0t1xYHEq55{{K,U`9- <?d Dgd&Õ"ɅPS0g?F^'!ڿ&*8 ipⲘi Wf34cGR[Kk!9bBY-P UfWاTގ3lȟ{Ʒ:I itPq 6~<θ>IR*VI^+jXcv w̆Ͷ֨Ll4S#"43"Qڿo oۂZG˕~A 䨜@NO ccf3[ϵSfڶlijc ]:>};7~%kO;iD1b7/e~WzW5ť84HEeg&lǀPf'␥PM;W!'ɡ&a{ 6K]ȣPlFr5z&{2 fO&\ XNK7nWkpq/+Œ^yWXYIv%BXN%+KXyLv3i%٩ &:>3!nu!kqto#;Gݼ/(9CSRn*%X?p.4qcx2@"r EopJD.N"/yt_m)z/{chFO,18Aʞ1#<$`ZNA9+xdUݠvMB~H(tǶC5w} Xj{If68灰sYꤸgvdXq0oS2Sp> =2S$\.!ܜƂY6g;b,NN;=S:c=&rDG!ZuIEprlЇ3:$l^v.ͶbyQ\% K\P?hcDҠ_ #k>'!#ktІX p`'qz W6^/aI;&^ģ\J}[O!NX%!P}-9/gX2\mD@A.p ƥv גt|$ i"ڸ<< nZCwڃHdHEdJ*<):(5+VX:LbRƋ@`Sk]cV5mWХC4ԛٜ?*KRrsW;L#L>*Jwfn&ĚLٵ;BJF IE=`۹,PoE`OnT06{n$8+ē_ "z ,E+ +#2J*bU1,+/'iKMdsb͠E,QvPZxڬ%CUɏ['q2R%jU>Bȍz!sS-/%ƿ@)f@0k{5Uz*+– Нa7!7]w2S/5U/49CUg-ϰD7C28lU(h<"ܢh W,]b3a++ŷeX;!>Mdo7L](VP{%v_jSߒ b'>h.stHمUr`ƥs4 0>+L4`Pm149hpI F"Opa3݄O'wȉg{s,iN5^@ѻc)>Ij1 \p{GjK#B+7byc,|'楩J .ǯNI|I {[0<۶ïҭ.ͮC$mۆꇫ1^XOiѕ`ٛ?Y詹뻸H_a[V (3:X!VΗ# i|'mV3c&C*cKUxz+Q߻->a^!%*<{WQdY.<g0k,5|2V6)@Ȓj9 DF=ό'9[QpWs ?mr:*I#c8Uo)fV\w5eۻΙRj\^N_PuA7-(BQO}95zrHwݦʥ;4̸ݟzSgTT}Z2 !ɉ,,b7oZptgY{/B9ͺ`w !H2}Ͽew9$[,k7B$')oҒ=܍O-lW% 00L!}:yMhGp"r=XRK@UKآrPz$Coܡ,ƁS?֛f^IA̓x oY|2 -#i4) `)p\3#BF/2= V 5 LX9ݮ8ôү2bܸYlV@oEl͑aEM NUCI9Zsbpx򚪰5ō6L2mgY}]Sg5;#& W=oYxQQpv^.Xgg`Yn~48 %>֔$dgѡ{h$ۈ($M:I޸:ǗqVA+3&2^F kVn׹\4POzZPweV%y>;R 8DELmud'oض䐖wQb`SKev1q֮SZ쮥ZtnVBu g'+;@sD#nEDJeiA]*KԱ{.,sCzXi@r5YÜLKG0!+l ];q)HRn߳? ]bB3; VG<9o蓑),e%kO Vm«3Y$#S08q1s<"a'"+I(g˙'n@?/ YUݝK}1i"dgm9bBbEržG2^@u6.c [ze &=g=οp7\IR<Eo2bɫ{QN j):J >5W>`k NXoO° ^|Z\/Le墓:|2!Cq@&Lhyfr}>!1цdظ0Q+{:0AkO=v5&j Uo`ó1(Acs~ &o/HtbCW/ϋ#Xǭy^L/%maSR9p0<}~vav!^ wK2/@ α8$ qSpwMbk9W(wfZWf`.OP'y ϫaNn}MVuw'b0غ&z%)7۸VTMf;~w0ڲ<Đw߇H;B޾-y %WT+r ^gn)N'Me5AO44~|(0-jAg]#K-Rl0Ʊr^rc|IUb(g6Uw'jH},(kkBUA8-D[k*ҞX%ln6%Ȼo78G%CD -N:ueh(.Cې1tCH\b07B.xB;<;o \b%D (LBr(eլF' ڂ'4N|hpcít% [`o]i. -2I gz%S|k g(@^7O(S.DǤ-STpԾn۝PrOwOsr5Ec+`\W-U!rvyk1CψǒEw ;#vvD˽H# od2v.vʠ-xV0RL{3ƒ^d>VN"P pŬ׽˃S79%rⰼ{1܍Ouv"{B k2mdP.ΏRD;xf5hFnw+fn⃏ۘ`bEaԡ~23%;(r)|ߗaHy^SnR(3!; NƯ9=4ItqSφ ۊL5䥩:"17)(^wzJ J|+*Ӥ /BMÃͰC.f,nc]@Czk֮Rְ%v7HVhɺfFR8;ֿ'#U *wPkuF|1A6k-L@U/|hh45bF@iut/#"-T&1Ԡ7&S!NR[&:TtEh&.-n',K_3B^Z79ApXvo)皠m/QQcRyx׏U+ڎt O $̴O%2N:Pg ZElxq+ˈSPO뒸a7e&4ْxc=rᅖij Ub4v93tXQwz#Y{AqQRVK`f*d_i(N5E/i[R^7M CQR Pk.+88Z G GzXM'zT6dž)Us$|*#"OLF`Rux"r۴DOP!v 7UR4\?1 E%6LW4H MSc!SwKcUl[ = pk{xdS'@0BVFrbKqcDm[/1}Q/|#ڰTtggсg2HV}UEvUoCY }@ WZG#T)f3IxJ^6j A7ڃs16Z8 k18Dk_GX?! D⊶ovZ%~!X歖9zCn: ΂!KҞd]քETgxYmTQKW,ĝ+GЮpyMNI9g3,īP}$lZ&5)/%@,4y"z`{u>!>sK9-_`9󺃤vNtZ$ūQ[ħP]>)g_*1<-_~?o~\PiU @AB3:פ-+7T?~w W; A|PfYRQ!1uG` *Jl|BԵ#VJ 4V/4U~1kb@OpT?z0&Gy2Y-9}$v6,eJH t~ȱ~xTm/;(֐!}jZS8Q6S+m"וֹoTeO' fK+0ޟ.Pi׸nnD70( ]\f=_ +y;e(ÏuVxOeBkl{6XŒnuTV+#a|'!@nzŝz/ M,Fvkr,7ψ=b߰)^!z9:&6KB\R m@"p_F<4䷓Rz@CAE%R&iSlW02V^,;6avp`(0ׯ4:T} v>KYSeV~As`(N[l|=ldAKN0T 5,o[Bmրx=]h1gQO-wUv}E wG!(2voNɜ3f/io.oҁ&onLBZ[Pc[L%Hr'%14dT!&:p6'XzĜ]+x_(F*Cƒf_%]^ډSEX>#U#12ZHgY<"jۮwHdEBQdx~ I۰̷,s:{@;8_»&eb(jϏ{[KςIpq/OK;/"Y Ӌ$PI>$Le(Z+7֝ՋM.GmC97lMR^y7*K>(LJ4W~Wgq%GklS} DRz"}09օ9#,QKDFX44B"^8I;_^|X f_\oZYd T 1.=0_*.z%lw#};cA&+{Qw NҡeHnŘxJ19|ozZSD%Riim}4|  ⧷U +0Y#M-[>?)T)Ѩoީ35mAFMeljc˅&[L V%`´"D|hR V['u3h4B.MA P? ~耉7Ih&G/ױ!0*AwaJ>ЊeDpQr>bIUP?Z?j|@Li)Ex&R KWcl%ۈbuwGR2#Ԅ"U Ϗ EHĩyLDu&[yya^k@?I$cɖت#/]jpC.6j]Pu$<`ꥊGVmeQ&GiOrb}Ni~TLTrXqaꏧ)~|gfcb "}z^I 7su-wWVo9Z<1 }4I8彻Gq9}<72VmMu-KoDN.ӂWocJ62rSº`ȎwKmN +h'W?Iku|ܸu 8ynp^4=VIn8~@AŴߞ.؀)cB J!DP\m>QUdc4Gh .; }~la ΜqK9AgЃ<^T]Kum fb2f)#u%zd 6aX0u5YCmi)uv42`,W9R2u+R$i?ҭ.c4d=S$>+\-( L|CQ E4ojoUzsT=̛̈́TڷL"#<ߒ@N}X7̉U*Ͼ ,87S׉p7l'>TUA{8Y'Q<ጻ.:xvh73W]Q ,؇,/I~ͽBWM%aw_w6>Ntnײ?;Y%S!YHt-|or?M6z|yı> MD;k p^x'*XA c]˸E R [ڋlL5N7SB:oȎ9QNAs2:_%4xud_ ';<{V\m顄|bŭ1R6I^\P%IǗ&&$pe„S+lu8[<uKVc/!#ӃO@AإSdjw1,R LP%HpTtZR˒s,uB02],m)di2[`ATC( U9VcW޷g}+|=͢E2)װ DLf&<~ ]SMȮ%W-!CKgA~eцwNPs (G(F~2h}(;%}cCȻ茪hf ʃc,̵6EqQid" !mFP^l 3},]+qz-=!FxߓF~'"A2%2˅UD*絽$F R]6oh`\Xk !avK厣b1~vHl RΦ:ͬ42y!z٥P{(%4)NxI3 asċ/x]'ߟ=jf+/zN.!#x^kr ws/6:-ϊ=;LD(x:rqh&3?־qgR}" @ ߩqQַ8[|? zMQIWBz۽U}rvD:ִ2$fdaNN[Ùq9Iej*{ V.* ӣGe˜2叙v5VU&cˆb8ԇv@,|nq˚f0ď7MO[*?d,0z\8ֺcwPFi(^}GaqynbIp.B$^C,uUwűA86plmw&RVN Қ}iiLLT]|ϮG&N0l@)Ud! y:zHͧ ,_EfGogP綆%oNm4 "X} Ǵ DU1;TcKⰡr+N !q'ݾEO`kӊgs^͸@H= .>{+9kӲ q{{kipups|U{"SdKhȰM=w\,V5+͆FJt:x&q1,]G&†21̽RsPfP9:E\|Rof9!LKtdvu3)6':YKht+6 O&rJ{h~ p[zK8a `l} 5c&Į$=-oN>Ox8* ߧ CLCA "i}]ChT @NAu5Jycn%o`zw,VO)1:tbٗۃ E]8wK#uRK_^K"rrEӖ/0fY#O=CE'xX@6BW g9 npFt!&H i&˫D\um,pqnwaLtp#u34"}L6svywz4{cCag,D͕Y!BmD,,K c앵 ,3ڃmztWrYAr)h7 ;vI[qpZO{n:WKᢁҥ7;ZX9%UmKm?#[C4C&K!Q`$K{@aI9>5\)r!FFѝ-M9rt@z?uF#(Eh'"X@K>/Aj#iHڧAxk+ U(ކj*~ڦ6Q3f6u~n 7S1՜JP߾"xn*GȐ, ~f"qo 3(sgmi7th,Ao"1[w,HW>Nl%h ەU'e<^;gW =qA졜oME?.6G}hUjvJ%Uc<3l€(@hߗOIiy4Yʂ}kR8 6NK?A!'t#XʼnG6k We[uml\unWTJMg0TQA0GɎs" vN R/3]\!6=a?.; ȈEfĎDA=< = nTB {~ܓ[~o>h@Cd.^ 9R88L Q.y1"ABd6=",A 5[*pX`KY|= we7kw[Qukj<>AIVN3X}()fΦлAAth`fmd(s~^Wl0]ce;(C9kyѼWPi@O&QDB BMN&z/7FUNliJF­3FQĐc#H2Z077yMQ[vNHiƠGA |pRͱ,яx)#X5?ig~>1qtq+b03V gB,_-?mY-5Z*7u]!%oVoHl@'s{ >~UȫŤ4GJU`*up*^VY @$fjG-DF1B0;)1&h;@"D$&6V n\|~p'lSݘ~|'~O٩>R\ټ'`04v\7: nha,z$қ"HvZ:YyP+Ut꺘[-@_Ъi.r^xV3a.S"ݠrnŸݞZroIv^u%g*:Z-1Q|CShYD!Vi*Yt[dz :8>=D5]4عokw <Լk<itk+KGR'YR|? '\t3;p~ɾ@UCˌWz1D.f=)~T k4M.1V3d%m~oGBMՖ Ytz&ts']u>~y(X_|CdJ)9L)-IA2yҔI(IjLR 1;k ypݱDU &XƤsAY,eojޠK_ىhm@/Wx^s?CvpD䲛ɔ7agQ /0Y^+~i}b]wrB.u1H.tٔF4E*eZ&hA>(:ȇ_x٩bg- H M?+NQ95+ѕ#BWaXq &%[FwX"'dsI|c =Qx'|mZcR`j؍ Zl(;2`k{I1Q[:P7-?tR i`MUɏ}2TDR,&r\ ;ٰLf%h' *o!w})V!>1#cI,4`2/S2<ژrhQ_pܘ0){]zGZ;3]˪gI_ptbbG*t{z;S ;D1˄zf^e'dpp(yu sgy<\||武Jc''} bB'ݴL5[y~ c:: l)ՠb;>8e_8 >sܔT$RaJZt pNKh׿fRh7[ 9I@XGS|ʭ`wqf0o>ѥGtJzZLDi@O]98b &j RYVe±6L>_p|Ϣ_jEv| gŪa@I+sH' :̙֊B*桵!F M3SБNx9?aNZPNVX cXrrt0ؽ S9tÐ K"P(yilDձƐ,NkqBN]1-H0ko,a˗H>QLM+p_15pYC9}ߚgI ?$ Zq->SLO[H0A/>۠Z䐇RdNh *TR]QM-!RoS BI9)5bIֻ(NPd46##!͋oO̕PbR*-j`;aHx a*x]B_;lz(MEӢ'RTM\y]XEtqxu 1Z& D*/;ςWu>mQ璏t"$k=M`ռ9F0qPF1ra_ }`G/o}SV{]M?XF嘼d#$A!)f2պf_ k:d|}=HfeRUySM=L5.m!ubsU CS.xS{= Ql"R}|2l7c;lPo+ ea{>r␒FlHq =,i6C|M-e4[Yan \( ዷ5;\gjNs״>s%Օw+]dC*q() k+iA8ÊdfQŬx=TGfprkhu(YF `QX}@oh[͠~ l*%;e2[a!5L#ԑGP<[RBW) UP/ia$.| Ɔ>ݐz(fCIA;nu-/6aupH0 it1pɁJn5gġEV| 0J>pq.,e7+>Ud'BycፋC86/FOI4:ݚT:m&Wm^wroco z-e!Ŕw5( r,AM (ΐ6$C%\8殘z-0}ՊZGHk>ܕkp0P=G҆e8<:.@phZgĝtOt_<}6[l&NρߝPyJ5MLz8JL\/Ӡ8(88Nn\W"4:MD4KovQ8V֗FlNI-n&7sgl tm lo'dwE1gUp/ČEMvy;\/ -9AAs9V;'tDGf?=]@Egft&,ŮA3J5x+e~z:Œ,w˩Ce/uz1j95XE*@- _̧A 1f>A@9ܬ?Nfy~ݜ>(\>fᝑ}byXHNj1SeA*pVWnos@NGkx /{u(!AW_WrjHc4G:;FUVVSB11Տqhl{+ q|Һ_CY~ٜ_!I7̬ņvY:PsMB3'=/.>pl 9^ޱưMZw(tn5&TA@aZkEa|:.@6#[w'}K zk 'esU˦:{;ԷMa/M_?K6(x/Md̮kV@m8B]"6OW9-B7 Hpڜ ¾=pltj6'Ǫ3.[cD8{0-;bYXi /4gsuϞECyZyߵA lƲ\ԣ~eV1Wz֋bǤ2aiifQHd0 οݤy'κo<'ny[5yT_#Fg\/ j$&I80i1Nc3wy(սI2\iYhQĿ7:KBf(}b6 `?Gy51]6BkNp)1'? )% QTo#!ᛆv"T*菵oЬ*%"eUtSPyG4;[EɸYHv!.#ïxJ~jKxb90Ss+Z{h;BGrKAճr #͗hxp+y(YlF?ܑb%oK 9ct,4,L(%DW C ,7?5D$ݞi!,8ezJ} GӨI!Gtߣ9v v VI*Qe3 -e ؅~*btQCi9W]9 ЂtׇXĸ tNt͌;_)͏yOV޶A@U4,BZR(V _3y2B' ˏz~T]քMe'lIڑMqNZ>iU?jX 1 ʨ0 wd9.g(a'ͤ"zaCV8;*>L+EW'4D r]4,[2Q#J ۀԤdBV\\ ',py}MPkrU ''jT7It' "ϟ˰J{oKVIw)OyKyuf'&P-}Cx<'YL:] _dUh)άS%z4 1G.A[k>Mq=;ȨLplu6y_xf?U q8/d\U<-Ӄ})xۧyx_E ‘RPWC.FԟD'NPH]^Sjt;aD(.̽xU~`Uŏa8p.D$:C).0bclWO:l NX`aYB"?[vRzIvn_盹zSWvMߔo[?Tjƽ|V4Sbȶo{[ ͬp=Z:7LkUY] ri͞6x5e[Ux%{=]Vp,ޓakA2),f?[TSC]jR qs~M<B[Et著FQtt*BBW_p# 4>ok^opVS}]ay@ ʫ%mJG\,ۙ|VkٗsAAmаIMu_Ȕ$TVefbS^T J]f&/4JTm4U@d_'".4ʄ RFΉ9(2ؕ&fGT-'omFYGx'5D隥^|.+-NkCASFxM`s#-lD}*0B ?sc ovbe+9oe5LA%FM+E_ܶddRcT#yB :́^D=ž3&ǂ+wmEXrns?%]1y~<6{@(d)GW%N;sU2]Zy.T:/Arڙ|d ")ikdjsHsӡ 5,v2>+ J}hoqFk( e7ED HCroeJ NAyJ+hH#3^$Ք>pPH8j%ME 8fsgzqGӲu$IdO@{׵*"xw^d-¤j]vҥPxȈZHCϲcB 4?ۛt6sr!k2mƊnZ(ڭ% 筶Ѽ%.Ģv ]ȼ=.^ !)"`_?ƭ Ѱ H, Jl=Ȫ"ɆޑD5aK&i!sB%{l@ H4u΅sHz`P|:zK++R7Ccwd>z7y~ %ܰgS%ٯҾ~4-L^Og*p.ϛW*SX|2[6)۔' N.%FI{_ 1"^޽XWY"ѥ&oշSY?:-  * 0Hz b]ўa漟^nhX"^R?},<+ȱIc'fx-x4zQʜв 9gJёzW3;ɧ޲+g I0 s6ݠfV |DA[g<0f0ܨXi30R6G0BQDGn /{.t 5MA\g/ư ׬">G|<=by/=g:=}/4nK[0 .ۥWDӹOoj>ՇDQO35-٤ <\7k{91,&ˑ̀CK6 NAǵKȋskAd93" fTjeaXFP3ItTp Dm-65Ԙ!-NLhSm̈́B22#L1r1kG"!BzjYJ!+w˩P>H:"}Ty#­Sdf)_QOp/RuwXܐLᾏ -pRhu+kMJ7'.62Lf7WCGwwzYyc^r8E[؞Wa?HD N>9ӟ|r7E񘕁<]:v뻿ɋfn7K\!{S/l'r;Awwr bNT]'(R:Vx9&vl9cJGe /mX3 ]n fp{/i w`\ TEZhfUDEƍM Xf@]@|XXf'.7Hs XV-ZPйͷI|RM-p'?gɲ{p׳I,Qgmmd#I7|'Fa:K* _N 6.Lhn/0 *6A=%gzY쇻{k.Ez)v΅h0֠$)q<-x=$^}J<|7u <IPүf Gm M5SvNN!uÚ.^<:"(2if%c[$Т]z AL]33AQO"Qlt.QĜLi w(R*}rl)BK.XRNnTp4 [#z kg8q!uA["/7 X2Hnd=@cbSG|]ri7u.y0xd|^U7ޯ TpxYH_yj6"[CCʿYIoyTd]Թ+g$ٜ:ct:sl׆ت knEL:z`0@>O.= ók 禔J1.5EXʨR.}VJ"%?bv0RLrԬ̏"_Ә3mvW] $=%%q]p8eJ8,dt>9ct {T܄}0 9X HtX >Qudbg(4oȯm ƴJ'T摞dgqiYsHzkwovj0͂b2 pV|]Q/} S}94H'oG>YNoT϶أX?t?CAd̀? y{qΔ5 R3&4OE]DbrT5sY'5sbi) %,/ on 1UԙRlŐzRYi=e 6T**ѷ=Ŀ66~-d8 w_-y%O0 _#4V2R돘^)!ozG.!2-TȊh 7L6*><ul$mT]j?22RzŜ'7o)~\~}Ţ*Q^yj'W- @OJՎP[zB;6b=EĚE*Eʓ3˩&B>l3`ֱ$7B 34zֱ7Eg-؊16=pٲc=Y3 5rsIu\zL$y ˱'M[gW[U/#" CmHj(Rz `q[PB)5ď D=qm}@~G9< G;vJL%I!֞X7'*|O|E=:B0 //hV+*C2҇=N#Y M<=G HipYVXuUtdv,B8a Fs9a9;4ٲԤb# ײ0eכءX|GزxLB_O eݩ:mM߉N̚ӝVFj?fB"=)]m|P`fD&J [:)/_VsǔtO8O[Xe5ToVBlrᄢtWtO;[Λ@3u;PY7jNNmdž,7nQ|Xû1ܠư KǏQ^uG_c? ു$^T \:.3ʟY$T$?*uj=lpb2']UFpMǀȩ: {du П:W?"_Zznm޹1UI--2'ÁF#n{Z\/#K&ʇL!u܈ړ£I  CX:Ti =MmTZNB[%= DMuKn;}B?ySvlb|}ꦜC,1+g'P i khzJ_>.ލ ]Ԑg˦ ,No!!V їݑ8[ )\r Lw|ȹN6i 6Pӡ K*:Ѽv ޛ v,@>Oׅ;h=ܐ"W~.9WP\o%RMas B~Y"p&Rc`a(S(ȊScONx4 .Hs$]4"7^D n$S|^bwwL7%sl,JMWN&l* VXGQ *h) kf)L7X5K u07RS3']"Fix%,uYb\R]8xgs9!MG!Zc7Ey3A'a{q-A1d\6=d:f->Up$]f_Crv]Z(RB1?2J 5F//>K8L)xu0#7+iEy""|ЯA f+tɲ9\cE`њi0xhuvcdWEw6=`*JB>z 鿜J-(H_Xm:g쿁lWl S&^лasMD֬Nc`Ƀ!O4:“ݩY0HV! D6ǿW[=Ɉ`̻gBzkpbe6T;P `Y8ZMvnrv! p7El/#8@"R:w=Yw)>$!v1k5:d&>V糽Y/ 6<9T^?RrKJ kדZG0*ST+ngH# >$[WDEր cAjmL,Ɉ&}I %B{M aK~'d"*3Bz`V?cɸsghK:G- %xh&Tdsy1Պ'2 ސ 7;:g+apc1 w1;k)QҒ $bp=I:ٍw7ٺ!`* D.Ky}r4؟ t,լRG_؂m=t3=Z(/u{:,t4SM0]TBȰCgG#uU;7hD$8x[ʸ qED3x.Gbp"0<\mN}*T6T>=pQllu @@~#T4"JIRgB="WJ(Bt+ ~`gb %>O 4. Sh+XJA E3Ij7>ҝ,yK{_+0,0?V8˩P:ERz6WX8e_HKdMF׹sx8@UT1:}]ﻎ^**R}쪦(1'Ѥ܂NʐڈGW~wԨa)lۡ sZZVW>udOzjVX^ /t2^`20Q ]? H56LTkAJTh"UY-܍wAgDΜNAGLadocB?Dq86Etc# :".;M4M># xGN? 8|xK3J$T H p[ \<^ ⧣/oe>I,=hi(IHkBgx]TӸ:5F,َmoRK+% 볲êZEM^ʌ89{lNF:f[8IM#I^fY'ds#%j٘ZDN"|R< n"က36xd[|iP7ܟCDB>0O`t@/_('ExOU5;Bl|jORㅻ~Ε{-޹!( 7NSRƒ+ɜ{jSTGMqIwFc놓DO)A*CEbq!H !妺`{nA96]6ߵ"C:t@$~S< 1}}6.]&K=S]q|]枪R?\ٙz _wWǞso3/qv@)NUCؗt>V3N\n fdmdp"ap:zOM=m$,}݃jqmTW^Iw xKl[\O0813Pz9DZRe4KQdHO0e"I12Twe/1?BD4&A`OI?`+yJ/e)5"LJ#x5Cx] 9hf=2! *"JeKeix}fLDɷ+a  TxM9i#,tpPW ?t,gk]w)Cʁ6w>0c=ڀ;Yb5pM:UA3͹o/ܡW}/"oۡa;GPGhlʹ nwPAOchAhjz˹`~O. OS6gytB&- ۰Sbh͗j0ԞGZu2[\ 4+(@>Ph%ta"-sj8B 7 d7H״ܪ[tOX)=p^ֺкH',SӃ&~{oukS=OcNh!7a4ŊFS[H0Pw~ӟ볙[;> @/K@P<G"gS'|(8(^ݍbq)sA%O.>0HO]G A `fw+x1@D%׵U_p1`PO6b|yN!"C /|tޡ6$oNĶ?͗[:v~̇>$x88s:?+vs>КWY)3Tp<cRUAnʊ-Mw T>(h:G# d5j@~d?B]lw#\F&Dkɶ"+,EQڮ R g+ڕ;bdݴT'iTta♓OBYW ?iM_הud v!Q6CXG>hs_>#sDf=g ^P3'|J/؛nlU᱕gPM2I͟K )dWrѹ{C%J;,r YXĸ{݊^͚ - ^37$<w0ʺgDeF_ P cyV]8j@O!~- 4/F`h<ퟤyo eCy[~Վn^B|Aߟ7l-7π:_/{# w)BwrUK_4-]9KqηK-Bڢ'b9pkYSIĭN )}PUu}"]B?\0gٞD̡œ"7L5f|u*6G<ga#(ΝS>\*tڥ+dH ܎kœH<{#Ãe٢,4e*i=gp~mU7JvK#Wn|0Jehnz1/dhv:5#6|$Ð.Cfg8rIhJ(J4UF56v#C!n1p{=C^vbvְr;4K1&W͚24vBa_rgYĝV uR(qDcE؈\X*SӚضZB=j ׋%0z(\:y1cGQZW<|1\/!:sX S J&`Qmϛs|*RU,p6 u[T>[i/Qkaɻ!}a㉨M'@B,HN{‚!<s].US$O^UU:LJeMؿQt%ɳv+.;h$~OQ?Fb{ j,7E7B)Lq)W(TzLB If +7|q^S r  bP+,$==vkjÞS!5/ PgsKZ0R'Zj}!u?$ YVoNƛ33)|QVY73Har^(= jzCBcj17\v-Ug6/pBL>gH~e 4;oq?d8n'$mūCNj4e\ +嬲)R](ތ|: @\f0هkH}i&_65zFf093_3Zw!A`{$˥LRK4㵬1FbƃҲ>n\gyLtiJY (qXO?O~׆?+-u݌B=Ya ) $R<-gt寛%˼78+[dOI‱WDhm$DtdAV>4BeuWONफ़3`o+)λN4SPo+&WΙUJM.y!l5>5A{tc_꣍>FSyk3/II@4ήy1aNЙM)Fw}ٴ+o!lErj>ꑘ͉|F-WI1 Xj5p0xnnfBE⌜r`N i-4 @,HB8r¡ X?%@ (ȄR* #\OEËn?}]3[ٳ7:9Yfa 0 EpaHrj֥v xtOQ .XOhL\n2%;wY4oH|xيTRENFxcO؛ ks0WB\1 UByŎ$[j? 9C@h2@ N,AQSyte[ׅFV[Ua{$Z?l(@Bu&S6(mL2Yўh`pTz_7pg7*=| K#{p)#I nt"#MZ-NeH4(9,ZwTDD3 a,YKr\6 65ښ@^b "HQX - u3MSc*po&A#̏Cc H(hnG,m_ ~;M)-<2HPPwcrVB@ ;Py#2T,/(% jɥI wC fW "vP\ ڪCb3yI u:5ٺ&+"HeQTz# `IB|KFݹ<1NH|5,b9F-F`-\4kJSSi/5t6Rje$N}jv>4H#_ZΈ% 2qNwTˏzEW 9AOY؋Oj1SuLOKT #tEnCP{evn規ey{Ѽc{XƜ P8MuK*̎o)T]"h^78^< 3[Sx L̬aŹԩNƁ9';9#.PP{4IŎekmPt.*7Yx@p?)]x%#$1Vt̗VP{Bd=գx;dNء>qnJJha>;;ӈGl P][{#4fBt^5_ˊuWVmZ 8&tgI-Yr/v0hUGTm[4VhdъB$89AY:w9C$o ]6\=ɉjԥ2o++' Bc|35,[]ly櫅  ɍ,pVWR鶈2sȼzt&QyGvtСZss?ܚu] U+vvC_(}S.lj?oAfr fX/((Q3+0˽_R<~ { ' c"p`|W._\VX-Z [8>hny^ Xχq*q6BJ m3%+dFa|#<.'./I8iW&["]3M. GڑXr89YSA1S%^ZKF5AF[XeZGoI*P:Lۜ_N3bwJ7>}J-qP8 q~5>2R52(TEn*1*/ Zle2Y mjfjX;ޯ;/^7JKݱNjaGw)x利6K`?ːePY+4a*v1RyT>:Ls1OMXM0'`+d9C}!K('͠lpjc7]5R[Hpѫt͈]1^\qVԽ;8े5`o0mcDj?5P1[JVV?Q(fx/8~;ط6}=9[gdoԋ'xF܁6@)z{eN=L q 1vJ;ֈᅯ?-9.|;O&ajw2eitc)n Hc6We|]ls}zp~UğkZ*XNy`!5(@!Y$ѼA h KJ3zWdf:Xx`nhH"T0WRgF3eOi^>uĦ^ _KBOM?60Cyqˮn⾧c;Q&$1 d9.LȤ)&-Du2CฃpQިWAmY>#.Wֳ|?'.j8F\ߕ?Nԝ3sV<z~W 5—PBV}ტeeshS,"8B~Ƭ\Fl %eb:"⭊*ڊzɯZ_!Όu bɾ6kˌfD%cz統4B}2pǕCSQ@Nܡ׀*$ <:q¹ r.f>NnCX~6r+ toDٽ07QaN7&&b;W%1Sq#F,P`8 U`FBrt0:S Jނp\!uTۍNa.:h3UW8g-~@_hc\JKv` ?E5hMFgP? (xN"(+LiK;"Tyv\c S7|@SkS/n.>4-jB oJӱp|KXSLYjI AyW|Ӫ1{(>cDZZ qYWITՔ_,+Ea3:uWIVx @}:S!SO"|OJЗ%⺧{sXzn3B?BLB^Å||1Y=@@1b[}8XV2麂՝?HGr* pZ^7WƮj3)!Xv&Lwc~B#Doq,19gָMQܼVf}v{}P.mY8+< ̦*Q!Dz/SϿaIv@mxX9a|Qtә/.9~w&4EiȰw$pqG7<7~Ť\:&gIJuE:$u, }(n/xtI텷Ȭ6Q)3zY3; `Z5^]+ѬN"~ !g+;a<=x /ʅz F̹mdk#g7&1Mn?,L^0zk+ oEܗ{oTZ"Op"N( *yjT7kZmCo,FG `T`vw7X3h-a$e[!@5ħTKL{!-SGG~!J- X*"2^B54MD|;Y1So!D9CmxjjNH-mx/3z# ;넕pǮLF q+ F,?_Kqzw1B{L f|8ot2 O/WHp0-~~LQJy >4m̕bkLn; :|* ddoa+T 8^8@z&mX-0B`VW=@HǮX(ѵ2LwكG\T3z.icIɽƥRSqu1?9]' LQ_',<ˏO^|J5vB`i]{%K@(p-?#)Q=jnsڤ9PktgR3<`(]!e%O1oF` |hZT`,t0^^!ii*-Bo%[sjLQWM@Eaz^@r85^Y3O g8AuO JC޻E`PGSmܨմ&If)wSP<L5bϙ*,4#g!4XyRCr:( 4ֻ3ڵyr[Hv(yȽlUYš'(䳦*plI jkHـ|bPY-Cm}ebZ|n-AkE"ź7@[zמaC9 !m{#wISyW*@9 D*Z\,"~*^E݉% 1]#DYGLި2vNxLj#ʘ ~[xNK MitjjbOk U3Np9ObQ \`k5NA AtpT~: iѾsᲭ ~KOyC tT5T痌 :Y+|Jp e롈}cE0t"j7`Pn$?A9u?楷l+`Bb'ѐ[> wȫF'cI ?0Oeq'k~l-b4ڽxt:H!)cJ(P[;} 옉1OlKfN赊VRe ;"r旑^]Gh%V\`P]ʧW^ex0R/V\Au83UceQn+{O-\&K>"TQΦg&ؕQڝ1%染vU6>r\EBtp#.+{!zǻy8{W\wmC&Q'Xr`w:NIN,"rkS`=싻5;XARbST#Fmh TnP'~&h-H' N*5I*U $PBmH̋8᧦4Zj7I)>ոCJ{%FY! @Rum Y^D;fFnZԜL^'>y邿eyHs$<L|,2KX#4pwM%E]0-[J솥` g& 傦[m"*3vi3_44X4zR݀SEq% U\ůlglR8|eW!.{/Ғ.D` :LYƽ=e h:ye ['Bz|tv,.Bx׵|3++BbUJ-N_>ջMqʺ$߅ "!K(Ù(ޟWXS4@Bf̛k~ pOX8&frGszZOHZS,ٻ~K(ɉH`u#scw^uK&SF/UUsb~׌0N"";%1 ~/[L3c7C{w&o 'S̭g=6k4av-<) dWgT<ɉO:rh3k~8=\<6cclUX;j5`D숢_):=-Y ͿX|2cnOu(Ӈ=H#oY"Oz=YVImuﰞYR">>6na;EǓ)NV:MxuړP_2)iBV00eW Jeq)gxBBW)HQ-wER^ ɴIjX0XwGT<uVn1: ?yQ^*=pE7֢-lAӪ:3_灳!C2/]@۩jBlM L=\*R߻$G%|4[K6 -*}LǯLQrDZӏSd!8K >GzPP"KifrjCmܱH 10#TmLVŀ? &U81i1@#U\/>.3x-if:?zrfQ,(6_&osç{B?-VIښv~1ayHG5LrM۾Fh# v~"kQ/u١!)h(Tӫ4ht:8WɨPZ2&o?M`K~2v^%#B  x/)t]ܱWRZŒ, 9+ 4Z[^ 3~8LBMcw_y`=Cl`]mb1ENvNdt#j>j3BoWX]hXivub3).*Lr Mp.eV^ZB.|q`k2ɨZtw jDbE;5WVu[ c*>-%|2Wi};F܏$Mi~@n@/b>zcCxⲱ՜ztnyqY46|:eRV!CUЈ.,{!!Y I֛1?bzyx̿\Oۖ+nd/?[ k4ن2&D~wW, s$϶uuHG&4 sn'ťIXeHso[az|ۡ\T.B1T.8m]#lp 馝͓av߳;jx&Nz,И21qxP@$/f@A Jig-Ɋ@_|C=g'ܮ>.Nd-L%IW\&^BEM6LHT)H4s;Ȅ~{޺]tw@SƦ |q\!eWIU4M̸XMv>#x+y1o`sz"g guLp7V Y+=~@Y3{"Bf]{`%<ʑԸ'ѶQpm:놮*) }B%1"LgR|#T2/Ufq-?-d !ǀE̿C\EȫͪPR>-W%UfgP4엂:@Ua%serD Ei&2=|@%o!%KپwTN&B)¥7p:(+bϜ0ɢA7[@ɷ\q^myB|98q\WM>_,Fkj~vPbORQ^ K~dD06ǥ<|OB:0f#NJf棅6:Q<4ڇ9D#<Բ ݐPʯ/\&7G R`1dT32󅿯>w:jZ jJ7KqoE+h<['):-Z2]0>ipNEh`&=欀; D)9<0 ӧo[Y0?ޠbѿ~K)e*Lm'&A_%EhDecd7v k3j'; qF]CȠAo NG_.O CЋ @nA(j\Di( qY6Rf=;^z %Ogǃ{^JU $e@-f^5teF< ]g)RᾺȡs%Sb_GQg1s4tCqg9Mt^@onk}$C sK \PFѠ*g{;]nRpmt;YAMeW*OrέB7 i&9X@!XJl냠x7R 4LfѬjU|2qIŕb63j3~(Ps>n/*yŎBhzmͨcؘ)L߲lSZ dS NE@C{DM09( ^ݣK.cHOb9;{KzM\Xktܥj)vSK٠W͛zv*BnwP#f0kkFe4d\ڸv!{+rsXҧ>_4_ ˳ BR""vC`0 !8{{M$^1 N.8 (;yݷߍaO œ|z;YCghbw2z頑 =pyp#2-Q ;\OE9I?S% f僓QR4k6 X X}P-fHr7ވ8Ij= tEVʐ_C9G)"'s\4sXgP1[6S4( )ݍ ƛ$M 1 d7JuwYFs\S"T,Oz _vNAEp2” |U\ASt)K\Z:g#W=5Pqkk l@H6}~TFjvD{[v&mkq{pfqV;Mg#ODL lovtwʍ>4*κv <<`@}DsLħy+'>֜`5QUX+eBJ+ݦ?4!ig6OǏLԏ)R2,b>aOm&:nч2eF.SQ냳Yb朇yA1]rDP=aD5EN:4Twg8b~n?ik+\ *f J4q0-ug/Ms缽51?p gik%Αᐃ>F$ɗHRJ0r)䁻d*_UM 0f_rնT*(ܠȢ=Js}(,+* 1sj }Q|  ]ጌSh ٨V D<̈^1oE NjqN{sHR#F29[Rh[vJQ=7bobF)W)\yfRfG}q?:/?*z``l82a(y4@A'<DZ Fs`") \Nl| , %hy*z jHL#:+U/3㌭7꧒uOʕܝmL_P?JP̯і:۸'ɝ wfis % { ]uBW)dHOurk'`Ԇ+GIg{MQDŽ}&mp*KZX9s>PYƶ-V[;r 1%GK,Yʇkw468rRZcJ3plZayC+I'~i"rUmVElP>0žI,ЮC2 Z!co(Cr [ɈJ.r $k-Y]J9{\i.-n"^l3 yFUJL]_ٓ 7&/Ӈe0+{E"r,RGw3*Qmi"/,"bm7 L5(l*9YHDtl!T$hGD p4$vcco+>4Lv(wHmy{/ i ">d!!iP$8:Z+=iQ/RSP͂qti)6;K>Bkir9zZs:[nߖCa-6؝̗b\/& (mCBڎL"FC|X v߯6Z:HD̓ EOVzrEjTShiM/+JVh[-*X?pm|ˣ<J<5*vVZy`GIR7>3Tt47^jzgY[\?ݦP ?O$%J(Ü Bߢ-!* j[Ǔw('WuQ"xC% #mcW-35eA')c6nkq+PGu ՠCT-z(] 㰂.:&3G(w'<7MZUF?ys,_4UtUG)( cεm؜O;h2.Qu& )v -| [@ٲժdE]^ˀ;.%O`9 +@1_@6VyԈn>&$yI!Hgm05춧,J҃X=Ԏ}JP6HR'WRAĦqLjfRۦi[̏uA7Bw<)m*Et~O+ yWރFQyYEWђ:)s7.ܫL1a(Yf $_ H!޹St w7J710[IdX0 UOYr!bqk _n83(˶3Zc?_ z?eR%L*У/33n"nsΑuꅞ0;:2)&!xHPW.Y7tOTd+2\ϋ tˆ@4zKm~3w9hx[@53, _|4_Ush(P%fAf\^A:d_u=a`\ 6jat@r,xx mg)MR;ܣZ iYb(}x@$3օ3 F{\dMjDc&"3!D;|u@sny%Mȷ'^ q>f=IO7#'`&EcZq!њ.Jq2_+3.= =~7w䟙 smsviYmm]`2K36$|ٱkKїxy2{OY)kD[|/(MR_#Nh{ ?xRQ4$S r*8 ;񭍼F  ; qe Mi3 wK¿(+`l ÙRzU!C{c܈mډ.*A= ]nO 0nq)7jqj2G16ת;‚z}XIJ2p-ˁP_G ge]f`UyĖy3qѬ[UX}x]NkT)EϨ^C} %٤O&= DXs=oUWG "? &|VlڝB3~}/y+z c-|SM5רJY֭(skpI$w!q0 yɥa S1Oa\p6m 9 DϞR} $Wj&?tԜftiGQlKj/&n޴ F,tR׆qfS"ꬷL Ygb})/z8 K8aaNZ/J<),(O#7%Ə7?OUe7p={J ]P FPx˙PSO=2ޏj^Zft ߊ%XO5ie?a*%BT2sĖ jFƤ`FNOmމ/ut?3C> N㍠kH}?<D@ǥX !xld;c]WD#} i؜ 䐎 O5@ʺp_.*}]NYexA*Oݳ&7:l_ 78 ;Ʀn7[!>o]:I:;j0i*Ja `'Xyd`[{u1Xa3 X'λE.Dj <$嘈eW@h#~ℏUL(1ԇ9R'X1dé$LشA'\F`FVEcn I#[m F ]`&.*Aykt#_<„*PꒉeXBͣHGjf V7[c;WX"'WNWi˜ u/ҧޣX$c[iNY7j%aQu>j+j-(b3`ɜڳx2TwG5oXI#?<ػ.1<Ȏ.f}Mv>n&+ ezVw. v 6V!Nױ +~UH+Ę$ &6XS'b$~Mg@ʺӳo;Z;\&d؂5ht+46j{7ڧ i,5NnbӖJPwW&Smݓ鶭W9i`Ʌx>^iVO]zy3YDѧˢfNe#Yf̟ۣ62:jkϷ뎾bPd}~ d5b|so#{S[JP^e 1&+JmUaQO}5:H茩1Xxd: ];rH+cRky,De &x A*9tV{%B+#OswG&gZ#XLmmMc>iXC@RK.SEzQ( vvM`S'X{ \-ڍ{Oy&e*݉[go03Zr`p6-"i>~u ;x U?xYR7u\|ZxQ!M:Q1x%yVv(/FMC=(?R.Ľѯ}WMZr*heyv@82>(0ҁнmP(MN T g PtO yupKshӓyz4"^҄j5y7ꫥY% 4i?Q4WeyԊ#2\M?Y5f@jM:hB@eW-BI! rz./{5i~O8_EawZIkIA* w $ & OTR0d"..( Xb;t!_eLtV}O@"&7 { ֛dATmڽvaXxaΊr0I,hץdDRo;j &KkDŀNgaHZﲘfK痄認T4ÚajvƨTMmIn.f AP̿r^^*:6hlz=X\,|Y':?ίLsz)u7ͦ| XJx0MyUnf09p%PX+ X絭-{h_,Žnai!ɵym^T Ut˘,a"A}ݾy[GT,NS;b _gua+k׷PAmȂNMVOŲbכe ;~;샮zU`~ig;4JISrdJakUSSdI@D c( >Fl&\w+׼D-Ĺn̝F* JT+X!-&huWt,PB3Ţ,xT?bTGgDF8I#g7Zzĭ2aX+ Iv! vZzA4s*+We +iý*㺁WuH>t\ *J-c**hĵ%QJ'VwoT\9lV q8֔"|!E̥z䑝Ly(S5ވnhM|Wa0E- :-q/bƪe0c#X&l$EUj Z]4̧}8b-SGPaCVD'ڿ,pBQok(i*F_!U8(R0C S ;׉m̡K<G>,CY/JZ쒂 _,gWG%' Q!;(cvels7_p><[l+qj'n? (9Xme{>᷵\G1ziАOCSN7k17+\z;?,J6Z`zIU4P_j |1?mZ-'ŋ1CבFBSZY^WA/ O.E 59_( 2̸ݎ͔Ja_M}Krz(5ڛ2H냘 `,B@򵥀0<Ŧu|"CFv/Q٦M< 6NQk_n \GJNq+8yЂ9QU(P#"gZP CЭZyGvK8=x]M||F fynTXPΠ*!D ƤG(tG,#GQ kA9"hĆ=dAW_FGnPO9^"\=ُ7pYZC/:Vp %YhM-lW#.}Ec#&W,sl/_XKJn֑aK\a:a#Sbv6lmI݊-~A,( jfVd7;x|Uyl1YPTx>2z" 5[u߸Ƽnx%!=ry逬"-7rG7߯;mNg҇A~VYP: SA*# `#Fb8#VN"ʫaUbP},vn3|jwJ<Ů" UKRfI&C*7BGTo6uh7JJ1 CO!Vчp'(3Jd#NH =T!g?m*#=pa9VdzvUGЊAx/i g-c1?Ӡo韨C}|Ef)YoM`hSfjͪoIyIC"0ٽрxMJc\V֯kvd/j^{,#5n^,^؍&dAZQ.ߐ?ݤ=\($)Յl[9]bt z@K !%ŸƦ/Yʛ_1 B\; dYR0ƐT- }QŨt4ЖL3Qk,- |6+AN1RO!c=N͍ ><_( `HE5XL:;]\V\яap"=ggt#BZb/Ѣ*J&dK=CxWT2wؼYKN }-EЃfhCA KsND)Jv2'tDȶ@5lטhm{l|PpQ%ĭ0?@9JC8.aX j*5zAN km=s\u)vFH-7(.= 8\x^X=J41FU^90~oY ;DY{bZ,"$}O!&zx@% ."_RS.xZb6vG֑EO=x̀ 'vZbOQe|I~?M?K}ռ@ EDELH?\\xѣ4SQ ֔,zJw>)G!h rb)!ѫwjۣ]oN٣JT]WBݹᲐ$-<& hRr1b}kdb~/9 1 `-f 尛 2I2.ɽ)=gEzuE8Tsٺz*N:a @LJ/9pK\蝙'n<).7Z( GKiΙ*iȎ)1_%|hgB*hΥ=q(9>/U z;(%U(_XHO֕Z{0j0o*`S'Feq|߫RZHEb $Mt04@0(r$k8%c\FsZ7zl\E&]ސSGL? fT}59˽@6l(;k@Z3Zk%9q&{ *@^@FO]aDI #kVPƦfU.SzÈdUO \6&Sih[.6 |Cj<{= wOScBٓL7v~CR^<էK셤+^** [0)mrG6E/=LqӽWgcƒi~*85DΡ桢‹k dӖh\t`DZݐ^6wӺ%n.PY"j?\A5mNN^զf XVFńtʼnW6"xPi;[i{}X"6 ֍/0D*2F;w龥JZY P~B\^"P1HE/.JqrwI&NUò:?guq\-կ/W&oPQI7$5 5\A"|mR%#S+|:jʸ vEP'R3`|8o4b7ӗ;/2^;ʦV=6VP'>ѮF3hK%?VˢPGOc޲1irfGuM )&Ɇ. TJyϔE>CJAg #`{5 !?`A[vobWEvpDnBb\t #R-'4}%hԼvFv F{r)\2O Ȧ@6K-/㟤@W)pHUicFp:ɾR戵9< /Q$kp\J+a2RB zr&}_`<܁٦JK}r/ȍ6ʾT>(K5Y+ 8;V$toUҿ0`#oʹm,uȔlyR8\@:?̪~챼sFHfSf`9|GK"Sw(륳(Be9Lg. %.<5T‹,&쒵MVaw\]ofߺ^LxeD]Vbo=*iG*q}'|5&T_0|1Rf)~ TEÏiz[= ު/z?9uˈ]9E 8X ropn3Lk"G!b!nTU®JaVG3¿-shxpM $R1-/UuHvq@W|7W dۯN=skҿ(AyY|JnxzSnMeM6v6"PFWKʝZ|W͌\9|Gz8]Ḡi{Mm=H)((b'DϞ 5em?#v1HTorZ]#THD] JjCB<ƀk14>_8,"ΫOjo=758 _ !5;f+]`5qY@K'?wD+Qܡ>_tA7Dd7M)x@_GF +_m<ȹ+>Ht&nHG[k)%+gg#FxW[#6߉~e'z ' ] ex'&5W~$reYn$B`6rCrXLM`WӘ_\Y(_d F`04 `u9?uþ H7zYxT`k]ʗ .8b_t')o8oZDAipYq3޷p4 2A^Z4#4W"$V!A h&;ğ{|H^9n9P~Lno%d[Sj%~^n0ܑ 9C{Wje&VHגOʜ=CapΰЁvl 7Ro`FR}Cl`{ٹ}Fi6VMk~+U^;/R<ڴ>0XJP5vA;rUJ^ m˯:a-8c Рg [`b[RX;E|D˖pc+ΖYj:6عK1"JJ_ȥBQn< He #³i'V}Zx, Vwظ'maX1]FKIHT vEY#TIh>'>''G꽋$u"ua_m{S4IOS_Cl-`4-Vg@_N "ZrDw _nƟbr6:;\)oĽ3{v%U _ 6:3S4~fǦӟF2E}sOcjXlMS ZN8XNq6PiM3T ȼ\Z-sY1 fWv}L#s(4!%By%aګkJKl3llІb3M,cuܖkX\Glq~0Lc]?MJ-" ]Oqad(Qt. ?1}L{ړ7<#`1dNPi_>Ez`Y6}1[)=`Hl6B )GK$ Q?mxhZ"0*E]9 .뽛K0;IrmodeԐ Ov6Q1 a-T_SU,wEiC~tfy/T%puiT)e](]#yv_i1w wVM+d8 )z@$wIHZxR-OAP ;*-fqϪװdHfy c*yr8JUg^zʫ-Æ`-o}k͌jVЏ7rCJޖmcϴn4;yWMC:t-3ْ{St;#ȫ|z]2?tƳjY͇ Sܘlt]-Tv3'bpBs%iz1֙ئ% kd6vCsA@4rJL IW["T'?n;ުuY~ӄr[tH#[B`8#)xBE?Cyd)))(nN)BZ aHyYZ Pͻ6dNjRi-[(~_R(JY+f6 ~9cK0U`~il!(-y"ݓdZp띓 PlWU; tA<'ꬌ Rbtrwr@H]OpjGoCO0bͪv4/ikYVMlBC*K Y s62LqN/_]lS z換O&`OP@Tl1}5_"xM/Eo0V5oXޔ cYܦBg[]m멈WJy j{=H^/"R=%ޥ9U1OFBe2{&Џ]FژNlovk7g9)mT'RE$jR#ۜcv* ?u4ITLcG=}rY D~91BD~gj5>패-!pHo~}~J/&qy!J];;ޑS'-1kjIT 9CfPWQ6eXteQZߗ RYd^_ly2/9En05 V5 ^:No "nnb@@UFЁ*_52{ `]o6. yLveK[ &yDܪd&BmSkbݯ,|Mp P$N9K(1ȭdulK[[-|P[&g:s>B~ #sQm 4SK -cI!wde O]WcJE2w)=F;jh*E(*?4_=xJYZJH2_$f/,:jP.Ə A0A;]230@Yh.v&`(3HԔF|wGYPV)G SPm\6)R<6!t _]Ij3n:\f|7Gna"TzF#M& 2sVM% J@Ug-.g(V"yLs3,'&?][m3XEorKD|svb\oa"^1,|uRjA\a~|_vV :W { ZCYE2FIMHȥ!mOW#PFl'9~W?C-i|ո(`ElqdX/f8z@`EmBK:f#H귻m[t.kA )&8r fi̥¤K!=+_0.:|9Й(0u<#k^2n;BHx]vqoܸU((l>$W*&IƳqG'>+~bB'uPA׆> < v9Oi!gkwΠtU- -F|Mԅ<oK`# H,rm0>݀Qn;![wU6< S4ϫ%ATԠ5زܷ[ m@߷ѫ*ARsZlt2F Ñ-HQDFxO4W]IO  &AwcJ`_/̉V o'2P*[>˶s2߸sk耱1bxAS%ϔ6aSTHeew7IwڋONK:)Rwm<_()JiH|>~}"V A]]Rz,fh, $8V;L}lCd(ZMOLoqD>UM(wg[U^< ~rR SߐN#Ctj ' AeN8>!(Y._?X✝5V NeC6ΪM{`VH >X}RsS8itG<"", Ae(Fj!IdlSyqetuQq[uJ%m6ۉhQQXG$u#`R=U 1^mek b1 |]eCb,^>EY K J_sb4&b9aձcnSg33`oWj}I|CXeH SP@8.}!"k֢'R{'yJ%V(.ZתNI֍h%9->K>u\}0+Xl2dS ewWpcؚ%i Bvdxld,.rO<9dž=؞TOjZ?S%%a~aC`6@|{_gy$Deu: V MG-׹ݼ)~S279p:1|goQCꁴt3(RZNn3o!\ZlVsS݌-TzqfW:lYYM9-qoGΥS> msB+jDmcn0nhXjC@p|qg#Z T=}fYI&8fVfUL|fwjEaҹ|sUAI"O$apeȒ>,U5@-R:j9/Ad?ѓ[apaԜ!4I?͉,Ϋfec ~v9%%9r &C5#Ϋľl[_up& i8"zҶuh*v|ݴ|04qs ,}`^;Y{h?~h9 7^'47,oBChv!gLa7ie ~}t:w3/Fpev WPU Qm9RപA+@\d9wdH3U0?GEK:!9)ZVJolY / ZU|@EwBǓH `7=\/ٍ^2t>l#$}6(u?kg,BGlyr8@L)8t{5;)g/(@;c& ҢZ/>J "pLTs_!|yۡ|` |A/5|"/(usRQIE܍B}I5w3fw8{~ܫa>q6hI@5}};XTDIL B.Wiᨪ03:͇#Ţ^F1!yh4j_E7`{6|ų `Q5KBY?6xsOᵯrՂōmߝe )8kuRH-.,cL:eJX݊{|Aק=:.k"F3:qF ITW| 4"arf<#A]),J &S\8Ow::Hj#?yY*Wje`8p gW?76zhrJnせc85[4GX-΂ͳIcdY9[b*NsHnnho9J4?F1'pHjz,) *soP%3o@ΆnP* r5"K3JO *E v4~ES"({aWk׳^V8صfqR6-p}G9V<4 ՜|\Ɛx9t$=iuc'^oqHg;Nľ!ߟ yq$6ǔ~ﰠ:KGG5L\5(@)HB~2(hD2P h|Th- +CtgvyH!q+ar$WJ'hȲ!نAfo;/IXa)6 H GO"T& :|RĹ-C3``Mq!I-Z%N:ƧhoP4rNsm/![(i|/ VՊrIw5qLerO$LGHݦ3j9IX_W+G&@(b?b:< Cj@,㧌=`}zg*jAV}|s1ȸ 0P rBSvXaBFm%~U[*J#*XZN_%㩆pqD = XvҲ>Pcd{R%ghylP=K $#u5qsCcXv%"e}Miѐg]h#FHrI|umhOH~H0*#e>2!9?h ,FЌ""y ]98%%[;.P̿ rA,-ց`ұY̏&Zd̈́W@g;kG~ĖN嫷#V~;tHgE6J1_N aursه5F`Q9vϦ߲ HNK4#$(N$°Hm8Q/0e?)#u$W؂ (O&cCOap=ɐ}V #2/} UQAȇ6K[%Zd{DR#Vbи-9[nۤ dJu1 bCQjTW%a4怰qӎ#Ŧtnf]!GhWBXh7c09!MZ`M^CorzU efK&چx1HD$& ubȋ}J wqCgrO8A*N M!hE4poa^^VDu&>轾>[%Tѻ}JWh(5BkaREׅ!fg" $JR!U؋;%%H *bf:aM+8߀SzHcA3p~zf_BmaH)4TVlrSw+d)dq_v(OBkhMmmF']>`1h^ٙqsK@ ""[rݗ,Ŭܖ>/Y[mQA+uS3?OشԚ+#=yGkv/{QxF&YoQK(I[ 1`CWFGuia]l"Qa^@kO{ ;vRT.էӾZ4!ˋs{QޘƇ7"RfAI`,iHi!8Prssg)㞺+ٟoG<7FNtYӔWg@f542I_y[nXcWE`{wi\SYCAJP;k$h4ybВWF"-# ㇸrNz<#34`D=3w1QMeN{\X +ʿ 4]])I`gFUZtznP*|>]@2ϊIt`7\4f!_2bԨs΅:p~ҥr/*)cl-|Vƃ_ \$)RDIS ZNaQZa8Raa <Hl4&XhT>-jwHۏB'# ĺF6x ͯt{E)6/qsq=<$ t y9psi&~M&dl1.% IǢ@z> c[L3ы\WC=6]1ynGAoܵ n ;@U[լ(IN٨,(eKT('I$oFdWtOмZA }/)|p[YjuHvPg~O"m9e3ܦ}H]ASE$W`?h֧DGi@v ݀xbk`އ6D;;uꩾfvq hȚqQl_>^#,SOy>̊Jw}G}qC ^ӎ(iJ}hfnY%y#D)! =\s`ԗI{_Sz.ݝT-T(IeU) me,IOge?A=6MS5vwArĤՄ%:Lua3vwןK1V;@d$+ C++:Ъ+|4J;.CJ@J~$DGV].C}?ˠMg%mIpu6ܐG dlI뭼89sif=E I&2JU(soR랄V 1 [QvMlia1 L-T"e{9ѧ,`=a5%T1)uvO}A4cYuJ7W'L;Bd'Θ\jK*`G6hgwy@ݞ\53~.멨~L54 Vv)uTmf2^ew2 D&{nRkwQl,ɸ^Ī!`^yW} Bk)|Pw^;+&CFD]M”2c5: P{"~GgaZY CN_e ĵ%IrX9“8 ơZy7dcaCϮB~CP 7E.~< 5{!gcTsJŪrqj7패ڦH)"m 'WkM {blSZ>/| 3e޽3m5zJY@%/x̫ӄ*CpbB"dL{<4߬E쐐Uq4H{N( $e{D=pijwЄ<4g'2D:u&=.t. M`O9D aăhZ=:jJ3$m7x3WvF@ M1ozEOG֜ oQKۈ8C0,frczp|~cV1GPuZ[5ދO`[=D 2#-ȃ}dO4,7l'yP^CK7U]bf6s2L 6D3GpĸdtIA=ZfI֘2wpӋSa'rB/{ń`CQarه{i3Pdddӡk`96l_Q ߵʿ4ne ) <a/ 5u%%L@>W' ^_޳Rz衁N㣽kXm[D& fD PӰfFxQvS{'LW09l*򽬜`yfgWTOGa +[_ua9*SU[tQ\xLCIi_Ś|D^09nb3+ZfQ9sb(]rO \Jr>h*=>1(N~d _ I8ץ#]BA~,hi+}We.xU $r3:݉ U -oaK.& 6,^0 &dqVJ! x?./ 9} 'u lPd#p:47u4xw Me`<ɟ5Dyt#8~m$Fg`6YnŴ[ҮN{mГ-dQt9~y.YG3oՒQ3tcf8A*$ ^bOЭt^IuQeW{T'@2Vr+("^Gtƕ"& \bFx~{UعXgLՅ+ RWqOi3ò 5N] V74iEB]J\妞#qWŵlF$tX%f(~5IBt]| l8%L AZ/kxcx;bN.ޝi:p'.JHcz`WUqBܲ˹FF=1Oq% yht-0SE(lB;Vbn`FX|EY`XFP3`YqdʗQϻ_eGsduHh]n*w\ ްdhFx< E.xe.X3^͗xd? *`8sp%Y1/$ !NS#59avimeÜ4ݜ[/ ' eZ+?U\;V͎-8+?U${gg"2Z,xY~z&mTTӾyq97!Jr׍8.|c1?_ |DC-C`>shT>9oWj qdڵҏ}w͂:4MysFMGTq9=OL#uP|ͭ$Av3 oG?tW3NQe2ʪ?2[+F(9;)Ip画U [\2eV;ݤ#,W+^bM"mOi̝b;DIy6kYVigו"R?4q[w3Db K!sf%X/cF2}# Vv3.|Aϐsچ7Q,HX`%4rSDڦ 7!Qw'JoACX٩ϯo)9$i;F{3P Ψ7| fFM{WB~T}!(jQA? ?ǺWvӦYf1J~Uv^cRȗl,Y ]*c ѻ\qWT_cq ,[Vssa=(*QORAtIg&c7>嗡+ηSӡT9w%m 5yJ"@[viWumc\E [{u$fJBj(u%;k')Gٹc,x4^ j2zCͅSlJ4B.8 [S n :3TsDf8 "ɹ5\k`8#Mfe/ bgGgLmm{B#~F`̞,GunQ =SoUlv˳&]|&>?h0UeD0mI`,qX8 ;N8 kuxϏrG;T9Mw֭{ˡDhSb-SBqW".IZX GX鍦ɕ;-);nJ ЋQŋ#dݜ%1!^f!Cq"7&ʗ">dYnscϴN2MpjP2rV:*`( JeGo v}.r>.I JԢZclQYq 5'w4Yїv 7ļrxϧ=Fg;ЃlR䮉 M<:w@h\N&ljͮMPyFEEOm|% [yMnWU\@|wKWhg n[[%S*?|8|9}yTmCzVrg12`f_izR7ioXһ;v=x;tBY&0dO9nx|o97[.HDO7숑ܗ<]`7f~&'{stƑeMEܸRvߟWZ,H`ui@%5Q-V8 ;Ո6v )*? YZ