sssd-ipa-1.16.0-19.el7_5.8>t  DH`p[$ƨt|ۉ2CD@$1O8ļiT ;4媇ViL ws8j5 t$p̫U 3j2($4hyl7;j'x~_\}KHŨ2tce#:A`D\JAߔ43P^ 9V*&M5^B@. "[jx@W (Vi Ga^qح%q=)섣6Jyݛڴ " }DY:LP6u ˻۠dԟiQ1ۂ%VG߁Ήv<ɠ|~4\~xN@I_Eձ4 ~Uc@1 K##Al\FǁE5 p1da09By=1vZ. [TED !;޾|C rpvHU[66S\XC5;AF=GWL.߹h=aN4_D39qb~ 'yo#-5WYgw)E UϤ^pW]q=ߗa >vٜGҎ G8SU(EITlO#__6ƝJ)B4$z%FҔF9%՗-jy^''j= JH>=?ݸd   : "?EL    4 { $XQQ Q(89:t=,G4HPIlXxYׄ\׬]^ bعd~eكfنlوt٠uټvwx8yTXݴCsssd-ipa1.16.019.el7_5.8The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.[םx86-01.bsys.centos.org ECentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdKV#[A큤A[׃[׃[ךY [_[_[h146047d44588cf05db234d261c1da0eb78a9a1c7c38afb4c0340d7b29b3c39abc5373c27ec48270e64891b802d82b506268ac6728e0ff09153618b905f83f7898ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90309649d6a5472164fcb720b44b731dce4c7d23615543c04ac52f4d509e2fafb656471cbd8f5e77cdede3b07bfeab88d67206a0129bc7b2d9ecedab129c42c4d18rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.16.0-19.el7_5.8.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.0-19.el7_5.83.0.4-14.6.0-14.0-11.16.0-19.el7_5.81.16.0-19.el7_5.81.16.0-19.el7_5.85.2-1sssd1.10.0-8.beta24.11.3[Y[W[Q[[Z@Z@ZZ_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.16.0-19.8Jakub Hrozek - 1.16.0-19.7Jakub Hrozek - 1.16.0-19.6Fabiano Fidêncio - 1.16.0-19.5Fabiano Fidêncio - 1.16.0-19.4Fabiano Fidêncio - 1.16.0-19.3Fabiano Fidêncio - 1.16.0-19.2Fabiano Fidêncio - 1.16.0-19.1Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1601360 - SSSD bails out saving desktop profiles in case an invalid profile is found [rhel-7.5.z]- Resolves: rhbz#1596292 - home dir disappear in sssd cache on the IPA master for AD users [rhel-7.5.z]- Resolves: rhbz#1594178 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 [rhel-7.5.z]- Resolves: rhbz#1583746 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process [rhel-7.5.z]- Resolves: rhbz#1580281 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION [rhel-7.5.z]- Resolves: rhbz#1579780 - After updating to RHEL 7.5 failing to clear the sssd cache [rhel-7.5.z]- Resolves: rhbz#1579703 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000] [rhel-7.5.z]- Resolves: rhbz#1570527 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash [rhel-7.5.z]- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.16.0-19.el7_5.81.16.0-19.el7_5.8libsss_ipa.soselinux_childsssd-ipa-1.16.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bdb3efce6bce11efa4c2fb9f5d9b063eb953a7a2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=5b75ab342ae4029f0862699994798d065cd5accd, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)EEPR!RRRR$R R RRRRRRRGRRDR.R=R RR"R#R1R?RAR0R+RR R(RRR/R RRR2RER9RFR7R:R8R6R5R&R'R*R)R%R-R>RRRRR RRR -Ӥ>v% Ih2aHrk"w4L9)lxu|t[uH#K4raF?t8jgW.С]Z_؄P 8Vg  47?h'K 5{"} Y߿Z[\=`u]K|<@\p_@{Hʼn`4["]kSXSó$ݝmg)@7Q!Y:èl!c6TƞQuv~WYJE{6TT@Ł?pOૺ@&99,2z!?F>bacg%6G#l,%@'2;26cɼF2V g9HtE12 m8ƿ[k塄׷BRK>J7Q\8c*t) &z<-~WLfOwC>, ϡF:o\=<~[W7ߧftfyKS>0SJg~(&w|#7X%=`8*~ZB8x[FvN)w$SK &b ymRg5a`@053Kۏm6.wsqF%Lj .Ȝ7#)t>ed!Σ*rh&a:(}s@5D~le 8mQkdȢQYA\G>rcQg }8Yzz3:8B"VEf! 4ed,d!krJgZ EY?JAPD&95|6*-֏b"t=YMm(ucX!xH)-_gSb[g!)lӊYlJp(6<^?mu7Xn`Uʖ\MH)pZr!CRE;7hڭ(*R\|EMBdŒe%JQ"|:2a 2kzx`͎Dn4k 8@J$9 Y$֯$:.ۄ#0'SQ`C0}ae^ס.w2nȍ#jި ߗE2Y=88q`~KOeiMt(_w-ݍoIZa_2jyFؓ6u)އ>"]ojaz om/Ӧ|ۦ/^CM{nڛ5E1.YQ 7?e {Y `Wʤ\¤7!{imma4ѩMbHONnHTBtCDs B8xC#džLh|ہD{GP"'S[o}FE )2KbtSj;bV{ UմhJƷ)ktxvv'+[5roy^=Xnns_kԦٶU({4 3y7k v,1Jj*\eSHT,'_}^JByܕ hNT,n#d T PAect Q>%Rd<2\{b:vECaE+pC^dgPhC]QqĠDyZ*,` W#QU]i4! VɎ'DҢ]Ii%**Hg}EO>@&լBz_.(1*]|@O'IRMT#OSÒ\!{0FWF>ZJ9uֵ9ؗޚ?T 5i Ӛx`Q΍Sgpnd>e[+7+,}Ȫ$cp!tnSʬ;6M^8HZ8N)p?KxkkМxoHQ ['V;aɖV8J% ȝHeۃ(,IhI!$oy5M ?6E!gE5&T%`H`OcQ`3&.~U/ba+{qAt+=_  ː\*AxUNOLN/hX9ݔ3,S5s>-ymQp.%-U韴H !uM8qXXٿ?QUH=X_#E@U/ b;`? r?\plӬR, tV#hv ,}낯%hVmgRBlk g^tXuǓ"e rxˊE}QcT7FEI+JϨ%v8әQ1¼l$`W4|+Wb|9:gNKz~3w3 exEu>:UN(v+Y[UUG(;Uʋjk~3eT ڨ%Wt׵+CҌ N*+- JM">U?H1Y,osCa3AlUT9N@_rLhC΢%3h&CH$DÐ̆,wK 6cjK8ژ$aby ({.ёlvK$_&iMlCs{KowGE|`]A3/0/\u<ɲLu}.۝uIFX*#Ĝ0쓧5 S6@` ZQW>Ɲ; EX;c>UCw_ d0SΚHHMSLPԣz'~rx|{+:+46jDs&DK' vN?l0d{+eOpM\J&[z4VR#6Թ3^,%PG-ӨYWH5f[o^?ĚD|RW^zͷ/yQ\d5}\5pcu*dśyfmc^L*{xg"2( Ci ;:JQQFyIvu"`7.S2q z>eMF0X=ӘӰXo1A8zd/Oٗӵ#V>->O ű2ީo3ICwϱz;K_J9eb#8!&K\T,&ǂub\(Y K/+O%gΑew^댻`R-V~N6SQadAT4 L0DQ\DmdYA ˶3cc~E+@ "&TW_JPiEV%4 Ml *иkv]rvԈ#lv0ܟ#˜Qb-r>G@(-UZgCmj\duؖJU&@yBH䈟QNͰ7V'[v ^ P=bq'&+.evS+3@i$;5m9jqӬ/rFoap{eAV.df47dڟ u>H]K%}0umJ1^t'8f Q`mȯ0ldEj!%0a? $yoOS W/Wf4\Fj[_*@1m@>ȓNN!/x?nLiWRX",]˹.R~_"m\.SF#`vj'%duJ< _ 嘲;V !7;Ym'C>0 .l Ijm7E cx,FxFЂxݞSF( 3ObKbj#a0p ;!:zz 0OJrׁv51`EIx˪َ/9B |ZN{!J3 9Í7x-[oa+ƶk}5؁1e}nEUe!rOZƸ7:z\,P} KN+Տ~+w)S =fƨDzcH|\ٓ` FNYk\2A:o#|^FTvQ[ڎN&DTEd&NLfRѩrzH+m)DfҕO3vWE6, :E6U/]a"pVە<񫂔Bиٿ6QM҉?P?eЈ 6x/ A6j6lQ/b;V*W%"k %.ʶ&ů7m svJ+0m?-;b)^BF^BXK|x*j_^uTcY-:;a?(0ՌOQi+{w '2 $-^Ƅm{A~)܇88֝!1%ouP4+=V{[L"K*&"*#^O〞坫BruaKL!oTGXJPy2Zȴvӹ(wk|p/j}qry5/!`M#x $%(2ܪ+m8#I ӊ([p~~:>~ZtFPu7x:7rT*{GoVl3-uV}TV4۾J/[,{-S.lDn;ʀw#B(2QXM`\+Zu b#ٌ\u@dBo}TN?n0Dw/W듰(܀Y!/k̝:C|4!=7i=)²wK_%0Aė TO!}M&eS>K$aN-.r8>pF0^#ȮxEY/0ԫj Le`1+Uج 1i͎i\!7Y}܍,\ŪJ\ un-MO3I:@TO `@ Wh#2Q2}2n~I(3nXѺIZ: g}SUC9$Q)!S dvvzA]+ػ7Tx`ȽHV7|eaF(+rE[^Ir wa9ssCXɃ7T^C:y堝AkV\L8:k$lU2aB{X2\qѩ\Y9;ԋ8uWυ½hm~Nl:Mut*[T,;Hj*p'/nju͘Ϫ۽BˡԎ<RI](wť`l?IK{Aa5Sln⟬W}9 =pd0|{G^S,6^F.])7TF 5iAqqU&Uؽ7i}'6N9sp61I~Kuͷ& P@0W7w-m?trwh#<=:& "8z)Ï`/Y'X?z=vށ|pfe/`"2a>T7]2(Kz&iz 9 10վ0d4Dz]P<)?U}UCrI׉v@dRZTGB\WwvmY }(ii Mˌex"gK5&P4x˜ڧ/ږϟPRà5!wO)h* 3 %k.TF?sKP(ж 3 Tڰf~K7kho򓐦3F{E?)7QJ^.΄qg3թ`U/8kj `$ނʒx`4Jc3pj:Ρ $aK=@K?@Zl ͉],ۼj@i- G۶yn.úiG&S .Ԇ|>{^J{~aNg/AI(_*ksDu kjS|uKIQqDi -MF䋥5%'۠,3.Zλbp|Fi y 32FCoiZ "Ec;.}mfּ,&D>߈򏪪بд rN8ܠ;?aV.cOߎ:1CV f8Qܪ߄9'dShN1w4!<+X FPYXg=Mgq)0͹5zsPl& hB TLZX'}D1Tm\<&ca8NG3`Qr,rqZݺ1Yn96 P܂ sbN^*oӺxsaqbpald"hEj^n t1n|p#qF׍a=d0iPpH 3@ eYU? 3꾀jrW>'ޯl[𔲪+qRTK%ŀ>&pZj87զR#ޥrvƶ?h$K :cH*Cq1:RbMBU4}G;Qݏ)=[J*D)ݰl҆5=pRz@;>1ȚS+0K8/5 57 9I]0F7K*cif rC5wA)(~ٷ~'{~8ĂUBH#7FDdOSQ~eK}\"QjVⲽiϳuoY ?zqCRFE8vyPթsS,xɲV}xwfqfj=WU|!r^iDp!ݼ6Vq/>/m)/4 ,]7Ñ679ho3Tl٩`pL&i7קR h\=R(]yJ%O"+?>g0PJ=Џ7%ȋ3D$vMG}Ь7bgXH3piIy/ cTJ7]ZvؾrN)}Yh[fF9oG!BP >b5\p(v"+Z($FR56}v~4 n(ͪowdt'ua5Q ~)_]kxĸɪg'j6,6-EdQ}HsOQꑂyƄAgΫ ᰄ5B+^'1\' ^bW.YΗ)hhY`s\E5 6Q7 1p|Hc=y7FDʿ$5AZR+PXfӫn#nF~E3UJ d8V!6{"` f/%k,6BI4O?Y.0&)6f[#Ga)>59dKeJ_\|( H^mt*me+3pTRpGTۘb+x7]7mkVF(Sۑl &޼3 RUl[`Vj}F!sq>7wc4C\U^G%fu#]1Q]6Iߨ5si?:3:C)SdZ'yՁمl',ۃ9jCo$4'=H x^B6HAEo/j!:&']1|xt"&j#Ẇcπ䤾YKx>l0 K 5DaҮ'A@"CK?z}XJd%`w߻F!?aԯ՞ƑZr <_y8ῖL/~8@0䉸yLZO>+{8WH>Ego/@ 3OILKO)Yky'h Y SXyQLS}w o(P9r>h#|nhk-@vh,`A/aƀ)^Gq_rqAŒ;<Ҟ֋3Nw.]Gw.5E$;_L 罧gx뿚*̯7m˓j[ͷ&ũvR\{H7JȷNQ*}˕X4c>¹  q]ktzG]?.M4 ̦i"X\P+ lȷIoEQVؐsi`G͍q}h[ZA?ݨB_Pe`hBd9Kkcw :Jn pN+f?KjԤ-CJVh$7AssS-x[3cj!gT; Ӯ0^f-e6,SI;|8 R{l^s[ */T-zXK YI&LS/34Ev0T,6T.`$a(@u[`F/8wdF {iv2?Ͽ% 82\률[?xay֖m+&՛C AjƣUŲd6AϓޚV%^g* Q  ?Wc&{22d/HHc^،N [Rp+k([`0L&b(A|@$P>X"d# 3u&eL&E\+0s"YX$`9{c16v9WJ#S2tQrY|i&5W^K{ H2>^]z*(+(7J;%vrX0an-4`Epv١ ɼ#/wYV#Q;Ty '|ap7ڱlm$Ϸr(_37JM$ρO4 ֈmn; %ǡ(QU-xIㅗS>%yU& bc-&yONBE;91R}Vx"^W(fukX37gGPK(`悕-#Y [#dX?|9qㇽeֽ/B&롦9NRts jZ< R=c{@wSr =UE0ʂ-zshΆH/]>ND[>ٔa8{XRHw3#H>aƣYY=tfZM4~c!ZSY(379>)?JإVKHN.EuYoaC QrIK%5 VEļ1꩸YΑsHɣ*p lܚP|âncv/S4Q;gɵ6xd~\0rܝQkS>m4 Yqrrq "6}(P,/7l3][H2{S$6{>oQ2$@@ҍL.|g" M&y[fE`s,E@mX1Tݖ'*42N;MȡA fAWhK(Xf;c^,v,g.d&յZPFwIӲʤN'χa1:pBva5$77C uVUQh!f!4uH{ֳϯӀcD墣; hue5S8`y^*_Ǡ 4ū8PaR'PH %WA&;i {s?8t>jAփX&|"blkhQ2'p.9`CmАYlCTiPqg'4 !5R"S!dpĪN/6O&_@/\LHj'_GGlŧY >>snJRޖbG.ONw7SH,V4X9IX>Vcx/f  jxFZ 4^7 DW6EM$E3}gn\utZo?hO9NB_"yHNJr6YnHc Ը!ad3zUwئ5==rAŚ56+iX;Ѽo.$!tCa'Y]z˨Vۯ<䃶EXyv]:(\|dTJ2N#ʮڑkYBރTlj LJѬ~[TUc ~ !! @44XAyhB6SNd{!K\AQ(CaǨo8o )˩f9={vG EmR9 ~wb;| O27/A() 0Y= 2)**右ˈ,lD0:LA(U0D@~CX[?+__(H=rl.U kF68$njߎz\HދXp.gm޾ kd)YVd;M N6xܧ.pyWDd@3~_ jq%%_!FK|桾cknh. j~͂$U]<{{ZZ9}᠏>DEeуshW_4?t)g_SDP2 AR88! ^q5D'㏆^sdx]JAJ37P^Ќ.EL%1P2|E23TXhYe"ceppX5ځt=KR}~uǮ4*#ȡd;(ş14mL"=ֆnA.-$푳 h5'ylqGNzIyӈL|]DnKy ‘]? ip?X&5wE40 n=KTAgXvXn6':;MmS òڛv"^-rNNf\ڍ͞8}ի) %wY\#R/6+)?u Jvd:v߼U2(v 5;7ܒU4FTDJj&)_vˁO426 te2Ye2+/xi iU9PtX)F#Y^i,wդF-`[L)11ׯ5'=ɂ j;Axl&TNלxH 7}enC2Sk: s- :9!)e< *>^پqq *_l#Kݒ`C4&@('h~DC.[/ThLjC: f W~h\q+9﫨&RLwCQS^v-zܘ۽_*,ltEXyn95CG}ReG"ZBg)oeARCİ '-9T{4PS|>pq 6 ? l;҈Sx eh#Gnj&i2W30[/ R2{|{*'wtq^75Qci.PRqz ~7k&| Ǥ/%rst/W46G8.gk/Kj6I] >B$ɦu-آ6U)ۤ@+1$Ks RM[]*ςTXL} '|W|-J$HloW6E1ZC.E|P#'Bȱ_5v$9Abތ~"Ҟeb\ +S^͝V]\ x.;\jЅ} KMif /9Ͼ*#y^;|0pq 8h"qlƣWB߰kpmNu$ql.$Hձ\bDoi/ x<*$ivu $i8Yߒ7at%GU T*Q F_F b'^^(مFDJPc~z ީ[\ʧQShw mg\6&LS迤Jȕ:ACN{MrmA:CcbHb;5F8yP%/]1X ٘yrmǑA9zmI4;)zyhM=]ZE)%FXr\e??hY|2 76_)2W/|T N$D{V"*vOwawHivPGq$|yY@GP7S󭻐Y)RT8)fLR!:N큂$[b⪛ǪCe>ն}$QkȼX^v Ь$m$8B]Pbn ȀAli@&9& ;~oUψJeKS:GW[(3ZO!)k K'24Xse^Ta5?Ԥ/OUGgcsן*˶>ȏ;ЪƈsXuL~g;ϯC:A7=턱FZ0 8J #Zg%4KT]<+WzQ7섁I6mi}{}9*Z8K^HQ@@&psXm1X=Zِ4V#qURJpZ 7j j<0SH{=݇yJ4?F? =Ҧy#0 fMI_cW1TqT07~ST#€0Mgn& #_$y8MH#nm $>ԣ2COZH{`rJ nAzϛ>q#C2z82%}\8ijkaRpr8YdgM/WCM_Wԓ 韹n7StTTCX!3)O*M#xtCuJSiq\Y6?IvAnE2[<# iw\{`-_PHNɝv➨'oiH gk׃~O&X#jp5hL'F @Xs3OZiegEPQ0!HkqXDЁ[܁ >2?~9{P/n-SI`|zUL@VsBl~!GcXeny\D暰.벥I:|%<fQ7]< {؝lr& h {3wHQH/`z@v8g VN l>\Dբy`ϑqe \ Āe'DnM3vp㑻SY(F%f;^S~.mN{?dP3Լg.]z@U ag?M$ir I Z0uiXl+P6vheGxl<@? /?bMwzU[qd`Ҹ̞1 z?&{/ D\'H-A18Ck*ЇQ*7_\|~)ɪdP%S{9]Ȋ f&č1Uxa*5_5Mn8:4)](73)v7pZ/⭒mR4}F6mϻ?pnhv|9[D@tc5hǁB1;·^9:C "wYĸ-+Uvp>yKSF*]<!'d%/4EKvcX? _r䆣pBt"=}r!N$BA+f$Ȋ/bp%tL,Z"|B5%5^ ೲ|/gLb~< Y N1_g Ns_8Ix(wX`_$|BS#z\H%X9ZYruil-f.CحP_5)] _8>7F&ًh`ߠJSJcD:2oM7pB7Y5;H=e5|st EHE.c̛I(ɛahjv/B qPq,Piot@yQzQy_$r %BENuJ< c\5-lǠiȒQCeZS\9Uwr XVQT@EкO rhtfo %o@S lʌ[gtwcG9!`e퀒O3x쀮];ES~%P_\%=o:sĵG, x:\2 l:I:0XՈ˷fO{W3 * $'9 ,BՒUK?ʁ+B1ωO[ȯp_/ޒԃk:ҊYo&D*(0@<_v#tQ/_Zԅ#s|59>2dd\cUuL֮W`+QS9 4)XY(Tۻ:nlB)GI'=mÄ#3-2F<^]hqä-?eaҥK,|j$6}ŏUy52!Ie{"l&lZJ>B_V#/jʐ9=~ 3Nv_kYJ^N sc>ջphQה A*X&NYs\"v6G!A Np0/&Q TZh>IVbϼLJNPnk9%D۲*"HaOXꥅg MKtH4*ʲ짻ܴq +=9v+5x{5 Vk`([1i0WZL[|0҉CDŽLZqT&9 |V'ʂ]/Sy IL8{AAY;;&]lJn 8|fb :LYR\lE*X7^ˡvyEl(緢s2$#TvKlbU@? gtx'T$0C߾!z:7$M7őJ#9o`?]ڽ[BL-< A>@H2'@PE8&&Mz.uoN/ V+㩶- !\ 6f ti"*'y΋{$h#Ű8|'Z_A6O2yի0th*x,M[}*km4vFuM}'m`e| \0@%ԏfH,#]ݾNsY[FP:*]NJ2{1L8Jΰ nW+Uj`r=`KJ*K?jJ@`u,Z}}!|9KbH ` q B Қ68ښ$fwTB3)1 ڵ1 'MBc$4h^0oLԀ&eXw(s6"NOj+}!dk3tkYw !YY)KcRM% v&R1켟OBu&}f4PuR!-@3,?H~LSH7\+8^4&YVMʵ56,B{5 i@&I j&%D^@}y#TD1-%2Ax cJYe Tg>d ,$CR;,;e>QWL ܞW]00I+Ԍ\>@SZiʕ^]Ͻiwz{YKUQ9?%D\J^1'o]ݗ+sC@ݞֈv ;\;ƧzƖ3Uz3b'E{ Õ㼼>`y/!^ʝ]YQ9 G12*!X= c~tGye޾7_A dB0"A& 3ϟ>b[id#$eNyT=fJ5b{, \nt8Zf1GP"iȿ5ºV^@a)[zxUY8yJ5 Wky %j+-6QfrAtG>_/Pq}Yh*bV25xi0tH/XZ@1XxF(ZGo&r >f0y.HH]ItN= >w O* 7{!$a`%D˥!9S UY7KĬBnW]"/*MreVCdƇ,F.+?> "e4e⟬M"J 2 Jh13q-Dpxl;7Mx])?:E'$#XՍա,tƘ˸@yfDP " yNL[k!,0&.RԘ c">3N5"xOk]>X~Y EddTo;ȲDZ gIc2™nء?1 3q+ݘA݈R -&k+ކȗq,-WvjtoBhg2NGse}궏q9{ރX%2 ?. GZ)Z!=Q?k.OCs+0_\P`ԝ;tGr㒓PD9Z,ŭR5Tsn gOG+Q5kI`-}wDzPػTuȂYŬ ;]+fY/;!ª(W ^ۭ7RpN&U(Oks@lV{ 7F"_%qqB;f̙xJٿt9O3S<~z(=>YvU GM` !Ki6Tɭ^xD?g/(! $ UeOO1sks/.=140-Bo{9I(ܚFv&2Q!#Л1sF-6(08Q<:cIYkzgCub/C3ZCiS4n8H'k6n< %_@+gvx~tsn[\9KiU3Ø+H6NQ?6#j'c#zf+'GWONWXK:͋T}C>0'8OVOψITv0!5D6/Ĵe4 -=≼6{v ):5y5\灋/I+BcG9vc=%K;@B2]o[P0I|x*!cOPT׼q3ZK紾3MJ/Z jդQPvaom {]`HիTbsGB|8 %BB(jhk-щFp"GzTkKsb<"Lm{dndc6cty/8^mZY^&9ưғEEM-K\!h_?FK'BE͑$)]8Cg6s/YF:Ӻ2{"኷B̦DGx' N1i.@cyv -6eSWa`$C+'CE !َ<_ U\6()C*| vwQFoX,ݴl}U@a rr$?ZSaGl%Kఌ㪀sQA371Eս7ʏ}-'- rș@"j?g x7|;/?m^﷢I ^OՎk E3xuwa[O5walF]㞸_픪+?*((bL1]4cTHIH<0 0Ii apaH/(+FĽZpwB_PWRn}}i#t2e9W:{z=ކnPݠu3FЬ$H ym ]iܳu6bvCETh!ng}FyJ{Wm*G)Z/ fQ>}.e@Oˤ]SiE| bdQa!>ܢͮ$[V'HF^n'恳^(JD1&WgӚ8cL>ܗ2X;H#܆DPXaWy|*(ƋEiVsQk%v6G= R\R 8lҧ͛y0k47nWh*C v2hdx]6 XJ9;`rǺl$:P( Z+%Ú/fIGJKl>4+F'} ˳&4WAOg2ɗGڸ8 p웹i^&t?G3}^8*|*lDþd\ueh_<-tRۆӧIWqʩ=bc%1" dV0at$ciDjχѫk6>`)i?%%0ӏҺTld0|gUHsK>> pŊZ`nJ4J%~՘d:7d,Ǧ(4~ #%DeەtsрtC;+z,Pmz .uE~GqKpqtqxa)$ {} ^/,!eW0T󨦢jzͅ]և 3U1H*,fC>~ GqVKl|7M$_FD )F5X_Xq1J)z0THջJiboQʳ ee~E֬ĉ"tM'C"(ק V6D~뱕}' pͲ zfp,`ؑ%#c2\J*vpX.2jH!Vj5i ى/E;\=?$ӮA Px&TIw؎<=JR LZ.sKa?K'~  nUY?F9eT!?54$9jSiat_͑zYArF:^g}+{VAN9_Im>%֝XJ(mXc+6 )췇P!JJG¤\ ge,8UaCm13IHYha.F+wp"/RZSζ`F'QF‚[^ 1ӑq8Bы8lfJk~c$!}ԩ-偖( HҮ"uοp5o}ڨ;%،Ƅb:F:% /Aqǡ:r坈pqISqעlP}*G1VvvE}d*,~H;|PZ>'(t;Wqe>wܷKݑOڷ"% kZpOr'JrߎNDUGH&k!}nT{+I;]Jsd%X$%Pa f)LR>R:OLL_U/ H5԰S_B B߬ $۱س-:ypzYyX$m#5GBMFǖS9XeQލCDss0łTv,}&U* ZŭV]FegA@4lYuTGI[!qR(h/48SQ!7#T8pyEnsH=Ey`giQx~d}pzF6@bD!ih,x'/ںD7 /BD ,䛚rdm%{^jNZ"9]K3U]~|/=c4=^*,{B&- KZ"3>B^ } o tSf '+Kb<"%`gĊa )m.L|>Zr,9gHdA*/b[ g+70k"WD8;uێVM9Yy/κ{:۲|zEfXʊ<}S2jWD6;LY<45D6t E~s)h p4TǏK32ao`!,uuO.yr%fu$JYm)4ulG,IT~̩bDL0s+Ẋ +M}/Be(^~lj-9=7'U rʿD :eafT"5o/Az/& 4g" +0`Kaݲ O3w /Eޏhp!F8XҐ^ŢwOPUCm`*`F#"A䏔4ʹ27'F''-KS!g/AA1v0( ر] )Iۜ3j- glcEd D#SSp;RRȄpmIM ϾE&lOnw$>)Ȗo*ЍzݿliaIe2KRnNJNVSh \i-9iI,o !B䩌`M'BcǭywNdt^Ni6q t9v4ffĻqΣ[&W51 -# i0%I*ѐ.)7gvgq;TdGK8`cٗ/Ͷ3h3 &'梉5B-wҼ{ј}d#>LO [C^T^qTkR_X0ݢ8E[W}ÎP?^xOV2進'ޔHue52_k'c{n(A0La!Mb^n\:WREh+a^t1oTJ$换v3p#f;jv|VoF<̵;D(|1W8h_fV/ i^6Լ<4|"z~ϳg*˺)ykV,^2h9iX `#:'k%&s cةwǕe$1k֮J0)TLYTE{oaY" gcPհ6,? RJq4kp1=˵R^Rci,8I\:7,d#,Eai%~,t`lF}ɗI| +ºPj;hJ4. B/ U LT:U^2`)Fӛ[ %Ё]v{Ldu@x֎`Z5A~E$38kf~E%8w)Hb>)(Y Q-ĺUx?25 o!=+,)LQ)2G׃;o|CU;l w%wWOS`~Ws=1t-e֥eFιLNPx*t dOTˎcG{A@L#N+/ Z{ty窎6BKO],Ц9]rLmӹgU]>hfͫvO&rW&/|@Ҋ~f (_T4];Sv(Vr Y6֡Wv M LWHw~{fb_y4[fji{MsVe1x2}J( Q-.QVavO2W;9f2z$Xq ~uHj~YoI("*.y)G\&t7pQ)DhzE֐"rM]tybSj<pފ6D|-.\[ )Uƈѱ^j@eTEꍋʝhcDQA3$vS/~&MϧS!V?;X?I;VC6*݇ xvD'Uw=VA<BwZ1cܞJӏL*b):/L7Ü{3֡:\z!ge$_6G0+ک=vmsD9>#w:f wm jl?wB$Rƹ2CNc`ú9+wP?3].~˕7cQ^mItH1guX"ߔ%zs🾔GJk&4aU"=6!>_ ߟ!AWw?8Q #8tOσ#:#K&ӓ)= x{un(b#mm l_WK!o{tk ^?eẆ 69jQRj|_Ѽ".uScJ!fugu+9  ɤ1љ'nk܁w =J ;x :%+撝 ~9=[}<\ TڑE%Ћ z NuF^<@hqƕOd` q)^ w΂Sx78J CSzJ@–KL8t*}5.#cns}ZxG%@d7hANvN򬮝v^m6hDj(l֍RIĮ']O R.KzZ]y!~Rm ҎGYҤX4\gV$½97^ă4!Omw׸.r@9t5AU,-iP8 ^ٰ'|? Fc'-: Z;j"BŒ)d햡GSqwz4]OJHxzREPecmVAi*b^Ό<ͽCA>+te相j2(B8pa  y>Ig y7EZx=cx46 ]C1L&d14)}X0Ks;Vdj.U&ćDa60ܒÉB^8++AtEZe'jS8%GK^#_tvz6vQLgGS(Πj ( I {l=,Ֆ~5QʚY>au2eb4K4*XZTzWȮmA1M{,+g%ƙJA 'WD)iG]EW-u083nI,3 x<}nԵΫCk@?p򩙜θ?tT@[$Gưv$ekO5u =O[621fj0!zn!'1{ vFUuϕ3@C?d"U*^tu ]I0j=V*zQߡ(*qU_3!٤P-/ ՘) QtfO+sujv2' }InԿʻU+Ζ%'ES& LD"Oc*efnϡܾ!/f/Lc~N|s!6 ɅH~UIku,qg|%@U@saU^0FgT73Xb&O:M@rͧsJfddg ;aWyffl^^8mhYou„b #BBFp '4a@M6ĖE]M{t8itƻks'2o4룠3gC˗s``0qAZű: (_3T!͗m[~ D@a}tI P]hkXD[2ȷ^cd/Fo^&S2,Ol*o  sRUxu\ou`vb(ւ51^*K'H}8Lh&/dƞ15֞%Ѡ&xN5P)糒 93ieumo^['`_0ݎ1M &OuA;/ɼ؄$Z'/i!#,e [2o[C[8>]h)b h8&້_ 0<\dLt+xO P)ڵFb{;~3+@Gتo(4 6a؋whՕS6^B V5vx΍LM/ޙ_ Β%y/^X̓5۔V]hZR=:_NrW]y@fWZKK FAkV6{\ :vљab%Q?6ыƚe'a,7BpX&JOJv{;eD$Y1:PAʶJdm58U``GDNcrA%pL}Ly.慟 5$szDF:WC-yr} Izt?\99a`r(ri!28JhyO9Ϫ>ncU딾rRfj 9QrFR* mn njNE`g@ |y[0bـ4^f⠭sf.褎AzKOҎƑ[cZO5[+|;@,m: LJu!S.shWǒf0a9kM疥#x1T&p"{lA1ssZ@d:DzyaIҹ:ع"KhQ[rP_!92k桤yɖ\'% jzA?^j@mκᖗ2,`X1/8_o㉗rQWrYkRm8؆JxR70LXA6m8h]0Oafxae ?# Ǎ8ষ_Y1A"͐NpMKˉdfs5[ggaG}J"aJh$i?5gD^%b)2MG ruӿkkb79UC3 LJ97#ߦQ̯GsE0mM0uEǀgbbHd&ҐwYB| Є'2+ 'ӎ"ik4\~A$T{A | ,˹!gkC xv_TFaFO^i*U C}~3%w:*s! rT%YjN;x!fLHfC(|@6!pT#Ma3x:sG3l {(XS,鏿QZle`&BdULE"7ʉ{*K!'Jسw9=\h~ʰ"1sA+ 6@2 x ,>~,ܪR:vC4QAeB'K)%Ms9Nrx%V+L>?wFQSc}7fӍ*˹UQ>o{ #T9NDgsvӑ'Ө~Z1ט'9]-eU\{ pc5-8u3O~ZC#M0zw@@/`'FtB:2E\)]+?5z{&јk*p:fuS!"{m}LuOOOL;kXZb hv|?g ?0ç_zJL=NUh'ȇӀF3;}^6ޖkʹ(woƫRBL>لfYh4_],JeGuaiSDk=!*,`g%pe,JԜyћV{-g{q3G&_)t*Xo#3*8ƙRkE5C-=j'(M| g/xݞ"kCC+AO\;uP# h|ppmwxȚb-1 }V{+LѤ0#TSS K 9G =f^vlXRϗBm#Mq#e<`Zֺyc#VCSUqX7MH|&: , XfڿG6,çg^YhVm`}7oہ_`EN^߆dʠE G*% 4q*XK(Z"ڜ;0ttFaqPU]*BWzaΗELgqWkBӱs{M/NA1οeaSo^E^@[Imp>M!ys (l@ZHl)nYh\SM Rb}bcg^>!5L \Cv,2Fw @y6.%3&A/FiuGRugVۍѭ1&֣/+@g6kPI6yߐv'ߟrg29c_ "V@9ň˙>hG?OeoCY2|F` ޢ )Ύ_k]&OҏezMޠjDI W{'Q H<"T/zŵ Xx Gq &ݵٕ0çC_hWg}Te;Wf0*wϠ,^y|%rbo))\Kf3KM#k|q6^4"d@& hR.NE3ȏ'sAK~z6!DzKm@cբs`qY_.ʑNkȦy7RBر#p#1ԳȃɊdqP26!7eHnSރ~NcqL)κy;.`dN*ҨaK1X.EcӠr gv "tie!2;nv e|> zp0͋iVIH{QKh^xyBm~"117͟:TtvT`eN@Gx7EvL ?A-.9+BK B!}8~% aIFզ#cF&+dFj4O]a94naD,אF9fɤI2VvV;e&v >4<}TkL"2¦8Q1ū9V-؋YF3EU?ii{ +-|]l%R#4C_nt2e*}62< ‘OpceweY{;.'i; xT9IyX(WR0kֵO~NSl~\jk? bf\|Lݿ6#(D]Y3;C4µxHϼ\tSRTX9¸'^ŗ١n&oTӃ=TR.we5}!b+! v.q)<4q͞qLNqĻD2a'Aϡqe\Ҕ)Qx} Pl;hwYPG: ^$Ac7=ůjlI͊@TTU=(d@=g'k-E\X/\6 G|bvXz8qCg7pTުgm~L_TCtWqeg{v<Bڭ8m_=Qf66W! vXZ_LJp&kU3+-&4Qʜ%oih f+n)qBqkce_t'"csc.DY Km_ }").iN ᲒcrM I l8:u_wg2P5b(d9j*͞^|5UXτCB @D# JlD6n3`v|6K_O1WH-2#Ad:%( 5FX''51 S-އY:"40ZZw^挎B;>M4V? dIJ5v_\=D+@qǹ5J`ʬ/]XpQI/1:$LȦZ.ް5-5yd~;]P"9oLl[r8_aq5iCm \\HƗUu+1cU_m< NzV$fr`u"Y1|_tfuT0 j*Sx0ڹ"463+Y&фir]'y.bzBk5m{Qv3N ES5:⺞=hxEDgu$+Zl)gQ/->ذy=(A'Hܚl#_,x@fMRL-HL&Gy,~1"uu G *V9x2kj ^yEp\8 1jW=|x[Ѷ`$cVFALU_]jӲW= #Tv)pahaxE ;4{;;7C7FG 쉾ӨC`}ٗsX}4GDn%Ly#|$>IE82B!f˅=#~`fFGU=ЁZg?;c"͝?ij -Mv,z)V ݮ2?2ܶ9b{$>J!˹Xe+pXکGK$DLG3yM |\B;9GBboӛGZ!Gko.ƭu)j:e8|6|DWfzR#J{bKt |4kth,l8 HJFU6? l^$đ\^̶2y>;Su9UFҬ-\q@emپ 2(wcu ڱcW#F`%hA۠v&U蹮aJG]rs0I`n*걘%o< vvbX<8(?>MZ< vz.} Z6j"#OyI8&H\~5Gp (D>¡?bstk>nP s&N9VOdРώBUz4ea7Jsמa7m`[.i>R58faTF6@p?Nt:J:>ď aˁA|UymcƵ|{AmrZ]玕|CrRB C| uzn^/)73MN`ͬ{q9*\y~s͖ R k%mӊIh.$IRGi&~vhKDmLcRޕM:#~qJA#؝d#@SJuhT ;Գ,`aV;ZVDMd5RQu8'&Eh4 ÄAŷ~Uwm7P[Ykz[.FG2+~ rUUatj&p=k ,(]Ҹ5p˕T+?_q!ey_ġcWd`` Tr3PrNAW Ka}DgILâ!$'o .S`pT8 E. a#~/ D|BMG"Q$' bD _ 6g1C L`/oZ=[>}t#Ą&od84VrfobU @s$Ľ.l!ngB`u1dHWV\wi&Q$5Va3@Cbҳz;teZ]c"'fߊf'[< 45;#TM@8Wl°Qk; JcĪ L%68*si ,wX?!2$("eP ,6U"I\8VCb'0aC7 QS0h/g*0׊.162~=Tk1;SȀF+lH`٦Q&ӤYY9xrubap0BqRiсcZUMr "e&nS Ln\0‹ pAfUoR5M B.Ϻ^ĪOf:bHmJD_֯1I+s˃;9O-e4n[#1+@/ ?g^ֵ2}(N9K{E]%PM9Lj}\L*4?h DO@GJSbaIA#pD(%t,MhKd[B @msHS<_~s]Z ӭ&{_eVVI\L@`iD2ܾ4g+vƒ)"jj+`ak9ͧBi,ʲvy3V)b<lۏNR]˓h.`T^m0BXԧuҾqh=e1C)͇kԆiL'V5kEke UM.:OܨXtN:§%9"Al{i&CdU>X)/j97Qϻ'jcޏїVEdL\KOJ䡾ɷxIf=¨}gC +%Ψ <~" PNT8~Uf iDQVDOlylHx >-Xr%p{j/ZRm  ]k)*/᭨G](cD|%K/IiWlqR`ӑ `"VT V͙ik!~!M)&QQZvhCN3?Lݭ'Kwg$F ǀ~A&P4{#&\A+*l'+:Ib4Š,f4Qrnb:V~{8gZa}Q3 ҩ*jLP|1&Sq rvI䆡s1Js 6ՙCJ#zHr{:$Өlc[1[Q-rO=^GY_j dDrKoP؆4evN[^'B<"em3,*!1BY_ 1$t&,F!֤4ڜܐj*,(㲫u a׷c6ɽ @&g#!)!l=@k~@ue!t;;Uzưa^#rN˷S# zciJLx? xIL%:deO3-SR 4 b/(V#pM 8C_>bAK,-]'nK7l+eˮ*lh˴;i+y4>H>l Y~䐂솚yp눋UqW t5kc)%*hҤX^ע+ ; qE'Hh&1 nb񋪋b<"JE!/ؓO Q]rT_j# ݐR:tjHO?Y{Prޟ}6=vyySd6!o[,I(OrRHdHw;W:Ƃ"3!~:llGeSDžE` #)?_ K~39ZR\պ욐mEg}Q61#sH⋬҈g܋pVUF ݲ1:A{r dܛ^I;#L8D#SHzS$P{sܛ].Q .7Ե{S~ew-2]Sk«JdET=4B*$x6$ȋ])ad4[M4aRwk}ÙRaL܍vOcJ0y&52vŘ{B' ިa?4[M68BjO+֨ψb^!iWÇO`X͑ضy2|$f+-xz <88[3Z r>Z g2w'#;}{Qu}*PܹWL&,l5mGg`zfŬci7M6ɰ4wb~h/ @$Mh/o<ū8}4CYbjUcR|Sh#:!k.ZC@WDKl72ϔRQHQ-oڽlz^"nimW"Ι`@RIܚal~Z@XҌI20nI`*o.:Fw7,'Lِ.fk~]ph5[ح\D@d],jAUVDPXMO*mq#^΂=Ċԛe[~ MT%z˦zJ9`/+f=_sq3K &+a1mtsAЁPO!nq:IiZ]rdV0sُ@h~4 &cl'U@M5g.Ŭ.՜u޳H.H6 atWԠE>44Gnj.Z8sH#)5);*Uڙ[,N~bCi7Ym! 7deUG7XfL=cɼӝm-,̖)hEÀ+jŸ>O WkhhXV;):Ȭ lp^ 5RIt@7-kÔ 4-Ms^/eFyw_i'Yo12쩓Nቭdk>OMah ǖhohJܳg`3gk̵'.* .(.hJJD._Ppn6EW}4~ WW&?|~SpAˉ5,&[~ՙov'-rq 4eքvTFlpR2Z'fN}Dl> ]jcFrew}[I$ em||ktG)̼nZA{oAU(3J`Nh|ˌ\R7 <0OZPbۇ,(YۘDM,q ׍kSGeRb5 "'^,M6F~D6y΢*3TZvWG\5!V—I47/*uݾ6ٖ~wt4C)mNUYMV<5z[D3,hI#xݵa ѸR$u=R.7.r f@ʳ⦃qw'$q+r9@>xĀ=)IP"zDFAd.us,UizPEH:̏M ̎f,Dո_U!$T yI?E7]33a%$X2C<.00Q,w (}ڨ{:'w{ig >l^R*A{L6}b%zPsT>yY&m?/q[~ pK>J8uMT@x1&5j .hR.\ސ/^1sӃ`o!){9IW̜Զr/&'~-+~?1g~gB?iK,K6u c;kf?29jx ty|!=j\W3V|14RjB_`M[2mSu:O@mdLfs7(0>1o;Swek ~K;,YO@Ry><:|&&BE{(r4jyDeLnw7=2(dvi1'0"Nwx6'QcK衸dFm?'xS1s]p[XR,t6g ;!"p [@L#OBHkfu3l)7RYbMfK}mm/f>a NrNT* PT莣7Ї;^.WqxGzBU7j{x-8*)+ D) P@ ~|~|123!ź?q[⥘|sq~)f1|=iJ.Du_Qn6,dœ_WM*ڀZ8HhX&}Yo:6kr8Tju'J*7Ղ]IoIx}.gQio`4+ÙPldm ێ)qIhED`TZ$խMa<,CVHhjZNa>I&18fjI.s raaڸX3L([ߑrO]% @8GuǜbӋ.`EpAmCCÚ3D6=TzV쭈9-\ 5 ޹PS'!B~+%ř=0k0eӽ{uk6J̍D[!InM3b!SENSg3whvwRE+"ٲ x<^98 nIWL W ۖLdD*Z1Q!w&amr,DELfcB#0 Oآax;>rLKvmrNIW村M#ĢÆ5%`Dc9H@î^?涟x&B +~ +4A#Rj"\1i?Ď*z+I.ָ !- ѳM M>2**|PdNl%J? }8zTIKYA9+(H|2d-1L:Jz+I? WA]p&^69P%p I.^Vmz2͛wǃ,4Z%,-SjYd9b.]BO^#Ӆ^Ǣ&LfE(U賂)I&~DgD;}2m5$%2v$Ԛ mY- M+g( "# )CZޕr밤c~&U 9ì`֋d:lŤdHGh≆Q]ڤc]ァ8ZO^6ׄ+YȁOKj34,|;i؍3_T6RY8NÌjTqv~lms&G\.ӄn`EnSsCfzq#k~NZe!j@=kYwM3ãd1pojbal ~ J7F"$%'=Zh M_ca#*iOfsN^cA/*<0# Č󊗒0^Iw蜆k.7hދtk25ah.TD9v_kASV=O1k~s{Jpwqb\ ml=$Bތ4^R&qa1peF(NcXRv4/TM//C:BK23Z͊HV橡(ѷ=$ˬu`E"bue$åg^dgIqp FS{6(~[-}jK&J44R<\g?%$CДNՀt?BE9 +Nl̙@q|"NSEhzӛBk'uIuևX |oPpy.Lf+q),zJc$۾)6,5|{'&ų[{[.tm"4rl>c3 9&]B6 }1!1y&T+)! O{9p4ah6e#1 ͗T$V{={wV4fBR·u4% .u$7ݾЅ=a@'<7\Sr! 0ĊT/#RuIRR1|N[8Kϼ )Xm3h۔< c1n!gw jnGRñg`tnoV`}ƂSJ#R+]3??t61$BH:Ϡ o$7[w/Wi~6/I:= +W_`f`(oإ`zJT.^ \a^vpr}raǦ۩7W./[0924t` AHv#a I' :6~;4N02C~!yV`D3u8SMf"ig8GB0YQ r$qKX!h9xCW/\&<;6Q+ْjZqKSo2$T/S:aSƠzs ]Ho{vY :V}ӫ|s\ @եoQ썦/"c/w〳vkdb':n5GpioZQo&9p* 0ŝ@8{sUJyj`6@<Ŭ{myҠUK8#Iyu.9P}8``q<|ZUI5dR©)^$VuBJ_sWcD&0n"{2)$+*Ԉ}ܹyhmp 3sG# 渌6Mzo' oQ3evZDQ^ǫ*`GAsлË3jh3ܽL>u?GDglPz$i\ 58jI~bZ4>yuLl9.hze{0߻]IeZsAS`%G>zn%K捎qSӢcfPջ^2J=bLďbBNT.["ݯ@)([k:dҟ;pg?[> !K0w{{} bIV3K`hnܻG0&Hj(qLk9\ᰠRn4*`9N:Mё 2 D){cZIο>i`i j?|u0I#O~rױ|f1Bk)1 (xCVXcV_JXnӅnvMcaMa[gx\ӵVxVQcj!LxnL6IGJZfz1˽9sB$墸AE2 [t㱥_>jz! OI`]@v8Y)m{uR $h/֚DסV.W}@NZΣ |H4w ) ȮmK P,N\ҭ6b߁NЌEg@ : 8H,!w)[7G~ H+^Zezh.܇iS>$ Z`K0rۇ6|8m=!dJQ352@S+cfCFuXe$P01kw ch#,xmBnqYԣ=G(+#?9jl2d(nCȐ a)jIj4whov;J94C o3'y?C,H&\8)kK뮅' ȽL ]֏\zT'^9 p0ߛ7] ^c /HGGpl;+Dһ̤1M&އwΐ 缶WDìgIS;~!j:m*}9?ha"0#~K`]Nv m2H% TqDM.9ww*&D}Pѻnq9B˄Y]Y⎅IH?Mh@ukZQq D0EB7 9-i{|KVe5Qhˊ+մCrfQɱ'? (>jǴo66RSP#`+{F!As}W3gM$W(dJj Gz;w[/-JVR^Cѵ }GԝJ֦(t`}rEν 7(j 3U(?6nj(yi[f<ÔX$F }6[a=|ua "L~L=>SuYe ]qLʥ~}o2[pZj b +͢ϻXO1V.w54;RvIKBڼ޼t}&sqZYFQmFC1.M!?B `η)sdlC ݼ-afݤ^FwaƜuB&N( =Y0)骟g2YhE% ߵL^NJ6g"U!&g,mb,ZLLJI)Xwn؂O.ĸiByx~2Mz[9H]vvyH>Ž XnF"#![n ~zn.m[Sk^c[I^ s)7upNFd`SRTm9NO^Aؠm$db)&rlޔ hyH+B}Q=+hQmo}"%mi(Mrya@Ã&ONbn.h-dV":dۺ7@nE[ ]݋^p-8OE7ot|2Osm>A ~bGjPN L5ΰQQ*Fw?ls:V|2pA9L# ¤ȮvݯP#VZ1vp_͗ZrlKS`Jle%->ok:n-Л}ٝ>a~pݞVg~It.`Dҗ5$-.Ы,覧C{2dcy'YSn*Bv6$~k' lCG5K8~AEV [\[F\:jDNuΣ:x{>]ۥ|P6yft/بIGR|P1P4ձߣ`,C^DjVlkd6Ө/5@TyNT3, ꩴS&=(4G dCbjiZT͆Ma{_X' cL|ۗޙe^4)E?{Uh('tDfJJ4^mYv9ǣsQ!&=>'QFq>~Y6s07/vw_mQ/Cn8IucvZQOw b8  >\FcR{=J/8jBgs=}ͭn|lz&]7718Dx]"x B6Lz,|smoaP4}*!awCrUY[fvĀW1Bwq/$>h`?nɲd i3ryL[n\3z ǺS2^ wdf4qN\v9\*[¯ƨ!xHhBJ&I"1[ݪ%-+m<-}> IجM~ԑ.]:hUx  ѳi= :&7 N&oDt(Ysb 7] ɖŷ^d8QZY4q$fBLVqDc ʥtIXHiGle#)/b~)xh_&KዡCL]g'$DX {5wOr}CWXdY@KjN,vq)kKq,ɨc"TTH_V,yvϼ?̢<0:B7sJrT@¦ ī xx\ŵv6( V?xS/QiPTɾ.KeD-OO3[[2/U廂XՃ#b{&cz2W.uQ`3^)?(K(DԼu Sd?Q&3RI4@0 7m٘{x n?θƵ[zeFN)2+b:f:F2ƿW7@8@9zC q7ΪM6i=03 L?R)c468,LP{7w `n}L j4 JOɞV>x5s¹}TKRnlJ]t }lJo!}s$x! KOŻd| *xoJ.z_E7vSJ!t%ލ>_v=@hQeK S,:"őzi@uy V9#;Vf{QGG47_~aMpgEkW+^wφȰ dlBy@g_D^F-PYUWQ9q֠7y,`Sj]meo`bu9Ё= E z{o"eEA qL OhC ,+ȤB>sDxw$Gwte.[iCxEBS+SٹCtֻ5ߣ n][07-h367Pۅf-"!B<>#@[!ZۓŻ5%6ަw劥 44H{r/2xizfK-jh7fOkB^my:pp{d,qK7)?"#Tf#07nRiq<ħdY.yB? mV|8d+X=x=n\oI80* PZH+Czb-)5\F,"Jk0R7(i %l;,[,#:N\*-kj.Gqھ%Ė,}ğP&w:~0Q#(}IS`Ћ`Lo83Ǖ'O:xS2;uªYVq(OKCr9qJcK$#iqp+Y %HeאE{8aO1;|.쭸p<9+nں%;PBĊU*AI]1p+ɸ 1)N> WF\zzgm.8E5P <4Xiݪ),u2EQvQo nB!?$˶Rl8cHF&d3'{d֩#ģOh7Ipl`Au_{ "q/ N Щړ6\|JK mй ƞyw< ^ oYD`_;L 2}YiVIm=[%z7oT遜PB*Χ+ujԘ+% #ܮa1Wis X$iDN=43WiP2E).8$I]s*xlf&&qfAt*{ʑdh _DfBd'hfk j]Gd>,&{=}JN[& B3hNu7WL=m ղ`˒6Tk$BM!AzqjRs>_Vm$>ve- r]t~1i?%9>EI+үfȜKsZ: ;RMy9t3#RIzmүZF 7GճK.G>NF\NSN328Ms5<m'DaY CC0isuW?7C6 > R!x@~Iw' r ̼W-ZY!9 pSti{泐N+>3d ^TO),4nY_vzj _M6#\-HfT*OvVK0 _Zdc`h<a~6D~yiGOczAגKK!]wHV^VrBfdWaz`S6[wpЏ 4?ݢIX`wDBl=H ޛp<'"ʮ(bqb%7 ~(" Kމg&PBO 4gĆ̢ZK@V:&7t*j?Ws8Bcl2谍dwL# Ibv3v(ƕ1#YڸԢqyOWV jv)'_d%GxevQr fBZ_d䎼m>Ivz&؎ČCb 'ð#E=.9ȥ*X4.490)OM"+\fL&W}؝e'5 B9":d8)mm>o@=pT _[$hL0p~SHH 'id185Gg=7 t~o,Ćla- NNC }^L>cy۳.SBoNG Ц]7A$4DdE[|GxQi˘R!_dQeuBLcב0jW.!<|0x/ㄔ:og?P}:(}::Ї'jJ&9@X8nƣړJGRgH6&HDlo I !vR_)@w=Truz:MSIS%|>M,ٓ@P^:bs5J<@scL7dt HSRxW$@TIKr_դ{Gqoec(U?f'0wT* R%¼^i0{}8Əd<5IzsB%].>>~ j Bwpi9A-<Z7+ C:yv1ҋfD]펍/Z0O?AoA[C:4.{x؃Ĝ^ǭt+1JE>U6Iz[KhUqg7olL'UNKH xV r'Y#r/GHLq-t)Eºu=`C-o9l].l0R:IYZ3Vlr{j7R7YNΦ;{T4ԬhK:b|i>~P*gFh•;}ßM0{c7|7:v â掜Sf9zf vfoIFCs,JPZ.k{XAcxL;F!TyIzv 4Ū0#36\,Fe:-C4|"'bqJku豓$ЎqZSL&YW+Wmpq]ܚ*"\.F6k5d5F4-ÍX6}fa%Y[De3az=QV ey"xQJkP`xퟪTe{C>92a^Lt;xEհeENFnYVLrz1Q#!G5Vлa;H@JltXۥ@~8 3ܸ7mkA^t)44, $l "b`-}'cf$$4pm{zY-=̤zمic _݋8rpqHڱ{|֙> y%sGj ڌ j.&@mt>nn`: w~8gGiy X`d?jz s8R@w5|u߿tBM>똂;E1\f$Y9Gcu;ƈl=ߑ5.k} SY5%55%=}S4$ߡ),'&[Yrce'Ua0V2%͝U*40SogBK$镐D`-` >@x"&U*vgQ>-Xfk-C]fXO`_c/^޾x+=ٮ(6)ew8=gގ]"ˋ[$øP`0.WD&mD:KSOH(0UPb^Lù!j3iL!9}KdZr9(oXp$4Txo䥶Ϡ^Wa@R!AЪ_2~sDW0֞Na{P|=", 2`8ϝIP=-ڔQj`1θap܋O3aVr/+IR%R*'6E?\H.Жg`@~aֽ{8O7$@RER1JBr]׌iywa* =bs Xۡ#"ء8s("nmAt'Sgp56u(a4NgM|,6`ޱ .CR98jBSWwKc0k; .ܧh؁JyT?^Ls\ݝїq#3BcZE;Vf5ހhJhѿ:ɿC!' /o@w%iY9!EUq6zÒ "86;XnY+OE谬 p||l¨O{XjpOqj,OiFz.d]Ƈg|`5`WHUeqsz{{ﻅΔC|!AzVrBS}\aLܥQ[++a~\$)r߁1Z@i6Rk wAKcǐ{5xգ3"BR)Ք sD gӒcG3對&a$L|(aonFQxs3)C0ʩTǴБ1o~oZ_3 cY6Ab+Jn}/+Y-Y’:8#rc_$LׅET E~63h*L樫V2y ~Jn8ે0m{;6>~c3~0towEj=/ Mfx]#<-fg~TJRuK i}3P2 4ެio_gu˪O1 (ML'.Dem^A C夣P,XTڋ qdtjBZjiU .3i9;Cv̲qj,NGX%abm24t2mѾmWid @o@z3]u$S{%tU6w{4O怌XNk=yt֛S>:^?ǧԝ S2'l?3mVͣ N.u% o$EP-xո #{-@BޏͲQFbP:in|6?,|@nAYT1-ō GiEgC9P >~sq9TK> M+LD&د;])~:oK ='%C-n) M.E݂VӚCwCVm(EzsSh?l!>)koR$lkU5Ve;b<m=O2iM1݂m a+ :B-L'>"ι2|ؼ_6G 7yaLjWx$+Q(Y F6}s[daOPO D]֨p_ q5un<$ΪU!c%Xw6X6Ȇ*MsQn "TZ`lm"t6@ZI[Nx;i)L4GKN6c̥A&hA1[s}8W:CB6c9#~J**/AGghHCڵCHnO|GJgX!=$BB;J5xT9t:q"vt? &r#J6ZK"l ȸ2JzLaƯ7#ǨbQ HCo5 |=[ZP7߱NoAxT?!8ޑy,>ƏmQAd -?+:Y~xq:"r)mً^j=Zc;"sU0ccW_ AX^[@B"Xo=F-;t堉V!P Av]YݽeˊR2̜E ..&q -ekҸc[7QMX.oU+(J;ړ~ꛥ9'a+}g>m)@dz|1S\2Gȸu2j3zOd@jo3s}m۠5&Šg.SOnILak21Sn̺qJw˚L>:SaL7?EVC3%Z!hqrLC8 C2=uv(WluZ>] P@28>k!GV{$kѷYT`_ϴZ >eCI}QRBbA0);d7U;ShYt͑t(%\gQxIs|u%vM(O(fZ5OE?8Ymƚur= is: FΙ+饞pۂAN~$O]-k,}B4z LӖ~F8ӾRaE93[_bv~` cɶ5H봊]rbK0ۯ4,CZ n/]wARnPB M)\ׅb}OUu mـ/+3ha0uqS|W߉|@h_L?C;Nw IMI/޻nZmstN F5Y^8_@])KHxx(11Ҭ6&6dc P%hA!,KtNTSo($o" .*(gp'Ldc"4nl1mQq6d.Q@/2&t> Ef t#? ˦@,/]Y-b&1SH Qe6LhWyxs C57 p%~AX=ڑ6uzğVxG4Pjj~C n88MQxCVhe*(\d&Df:qo% R7 rPPZ)rXԊ9>L %0ت|D$[{ԣ͈A}aMCJ"SϙIG+D25:Iɽ>ETxh/"(/M#b84!,:?ۏ*-!J3{idq>.R7B]݃eKDv]u`b`Rc- Ygk;Il@g8{iWm.dzlթTN|btpT2h1zu`lcEJաOm@%調N\̭0FARt(́~@b_+戢IHwb|W^nF1>PqlE>ZFDHhg޳дB#sLvA)6:mIu Úf!d'BLD>|ncjBny-v]ɥǜhFd^!b"G^J-(-XK!$e5 BIE8xH1ܣ?y\/<[e9 $v^Y|i6P9k>fMylS.# B2T4UX2\ϧ|?Y2l2Sj,A,4mgȗ D^#He@|n22v,X|;i[8E&,Ns @H'pM0E̠ 寢1p*b62}B<$dウ8k21AP鎙1ӔB!LzX5Ծ'ԣOebw6{e ~BHJĊC!ͅ>}0jfp'\aEV;EfeI15j͠>E)hswM)֛d+gT\w`F>Ap?kD)p??~oeieEdepZBArj@YQ,B ?S Ju:eL@pAP:cx \8/3g*>b}&""sEwJOZRye^%nȓp"$(7tw]a{'hŽ [woDpX" ab~WPe? %  9?@PYXPx:;'VL^}-)dϨҤ 1fK7 STyGuy=Фl0vHX z4$m32>{?M : %|rn ^&Z/ql[`Qw' i| gMg.;t;;E_sY[NrZhpQu2.%"mhS|=9PrU x`#lQBk7c`}*8NET?ѣ ٧Z { }詶/gX_x]z H>qge t/@Sl $R狅i`>fRۤ54z% Q$u^a5`@o&7"1-T[K&XMc^ࠏj`sh zv2.!dI#Q@VNyk)"QL|Q!F$2y@`)+̫bͬ1}Kop"l|u~`|2;hp:sD-'<{UR9vtqI.p}]@ ^ u6^ H` |dqy}lU魮|_{vKb1x Yq =93 >6`CNQ\*ֿd\y3ȍ- !|i/w 6x&8źL?%_jn$|.C8,rF /4kO*f4-s6RKs 3`)A94s-E&%{S: @ѳ~jGxpF(4qth=C ŵnDvWӶ ϐ`')\/<2%~gYȾ} Վ߹% @_3U5:%}%PdAb͹I8^$acwr̮|I WOf,e H0;yt!jxnKKUoƔcu҉+u+U d@qI=*4Q-^|0tL3::T,a "\xrʖ)gK`eϧ pUېeɷ39PŔTvFoev⒉B0[r!1 ltgțJTYRlGE[cd o_Jؙ.`h6v8RRi{|&ܺ"ߪ3W.n!=$W- U'sğKDԢObc!ᑃ!GY'$5,;y`an[ Ğtj@|wp97eBQ(J{p6{WJ}Q17ykU( <#&]L=HRE|UHN/VKtc M?P2aa7+nӽoyf&X6hQ*׵O`]χ Uq2hbbx(}þWFKn "u8[-eeEv(Pf~V˄TILmsƬJڢǩ/ MaLV}Lݭ0j<ݭ΅AV 9zTveْaw6GF&G(Grj];p u S1˯h?6$4FY⸐n> 5RKVveH$`…W>q)[o߶ Fq~ *c ñqT .?J RǨ&;:s[gu%' 7\/l(7f~sts̀gَ~PcJ jz*i"כHZo7ݹ۫)z4%ʸ/zb _/B+]'T3MxR |ϊڛlZF)@w+lfV hj)Pk8%X Ho9 Uܾ3[̯ImnZd)whި#OU/?.MIy MCڟ Gj1E(aa-Ndϔ~(SFN9Яӟv(ۃD dsݬFq]@UXJ ~['h^PN#3'(Pٮ/(2 cĹ1vU+o$[pq U/)v. ((e$M@3CZvqFע̋)KsdS"W!NL3;oO0vKu!FUf n678>CYX[uFc7kC6N~@+t|b7 Z͊`4o%JMQ)S~|2\Ix--JqH_͟x+gC p^5%DSk1G##h :G=Q_9B߷S;|l#L+o^GbL}PZ̦v lقXi<<.QXƭ޼x'^:N:34/Zv;P˳S撺 4y~xxm: }?D aP%6ڕXF~Ic45qR65 _t&u 0+̡X#? I?öYt:7 r=1x|"S;i$hiv|PNVFÆ1| Y2|6,jbyMgݑu,A2'_&`S؜Màpc73{/dIȣ@-܊w%vR9ыCi55~U!oP2i=` 7 e|4cvH]/ϧvDk1~bP{χ4?1ICljYaAtsVR<87#s<.A}鹁+t*AJGŻ%KZ) /Y1 9P\Dy7O}w[kE5%f+a.44i깞ӋGZ\7qfIݵI^K >wyw#Cp)2 `i'aOdF=?}+'-RB7eٴ:'Gr6J~"E 7ΗbR$y#d.$^.A|Y h$<˰DRIxXޢi) uggۗd:9. VfB#w";̄CDp Ecs(yeZ-]Ņםڮvn&{pVn Kyl bMjs Z^_\Vo-d cS|F?aB I }@rkP%sm +@<2!WaF4ep*(݀h> s #UPSjt_Q3|TZy@M4{fׁ7C35HrO}l6pZE1{FQXp9,[[Д0^#U`TAcH3WSu#7JGۑOb_Df;xOUJ= HLNѸ@XS'B5ɞJv (¼!TRR9IX`\6L7雘I~ "<:kzKb ]l1I0o^-t]S(=<܌YD 0ꫝx|AŧZ45~W=swViI 5hFYNF'MT0fPumͲ}q>+:h1 lh7b ZIi'zk, !Siؼjdw:$4ė/_ +[}ֱ!`p]o"?H?2a=tf~nY=XZrI<75}ea[ڪ$].1'PKsf4|ߺ[nIi3'+A7 ȵͺw:pUE*j>ׄyZ(Z\f)@zǕ /!?am1.ڰH?I6/·VWče sgܳ$LZ5C5xRz|'tس庸umJ!;o~30D- J@Yܞ < 慎uXsW|De46 kuL%݆"`"ͮʼ r}@0S2"Ct/%}Ma>b<6S#AAL'ND+w;xHpѡۗ XyX-S` !N04`IGZX[b?*ZPT(kxCJs/sޙ] `#wH0鸅Xy*˳8"P@dT؝{5-YK~CC4&rw yU: jsd;rhoTU -d'$3C7ntN<$ӿj|C0cG5޹hIm -EXNW|P&P B%hUx^d Z˺{+X?hBn f'V{v=Ohkw2!po9w e-E"E_Q ݴq̖Wj&"B91x.g=.{W$p ?\p0f!U9Za-\Z}P+֏ ec%? ,Ɔ -{D@ipX7L̀v9rzuA^[F%):'.I{VD\&kI@,8 1?F nE18"aq/q(_tk"UNT_*Wr^&"sO,2xe\w_!H7UA ֯؀b+fX,f&z *BLtHwߵQHd;NB ninOZ7oS:(%X7p0 8XvY`?&2OId,u 峾b3 1ITw8u!kqtuH %EVJB)F0 q]haz9m',ٰ4Ň Cm5fغ` lrc< G{iHA.(]]Dݖ>J50<#la+Dž^B_J/U9;X^m3\hRnmh Cs ƃ*xz砙NZ,ǽZ9`騀Փ%H1.P-x$2CF+uV>{p`͉k>}gO [ae"# 6@qexO_=;9F`e[~aHGAwLeWD7t%ɵ QB֯F|/Ph4jQۭ.˯s6s(`)1.z ,޹R9-d?o&/;f3b Rg kTqN74n {keHLl4+:ReyXG2k#hPP![&-ԉǐoSDxl5w>uV)%4;bS:(fZt{!Չ5\b/v?(!ţ晿Ez2 a|r\L$E'pZlutӻH6g[TvDjKpRՂկHSCՃU-bl8~ O;M0>lvaWnOI/ne@ܲ*dt)Ǒ ^w/4D'>vUK4ɫwW_|\!emL)2eH Ae%D'&D3#荲= j*D@L:5^,#%xŖf%K)I;GTBc  7:5Rh<XvL>5K p傸t05r}邂Wڇt43j<;^-VD $ɎzJ2xu{H(]\.}zIڦ Mį҄gM{M}e;D-wbI9%3GU;fqqS<&ܯ?IOި7] = P34c`OSEwp2u!b;m/vmfi9f!JrztD'g4akIP$Bw# |0)ry|u*M@ɩgQRY}7- !1qGp~D @!.)GNƧG8/U8GL.`@$/^/5[>Y'_\DiI`<;PbE_Lm^F;\JJʮdOXNQGCs@U8/%XV}DTz|Io_{{" ӓ0T8O=$(drqV.MnMsI5bHB<ŹV`4 r̅{); a:ɤy͖!!!n,sxϼ.&qGb8 z WaXEϝ$ZM}A{QecMޓ^0o# \n[5Ԫ C+V\t|Y/qt*»,_+4Ep/dB-3Dn&2>Z%ԝ%]~|N^o)DZl- tZG;XRԸhٌ>ΖSk72T7)L*Yr8>Ti')\N7-#<,nLKk0%tsK5s %h"bqO^@=.E#a27um΅Imq3ə8{Sn+_uO󯶏'NB(ar겙  /O܁-0I] AKV!rxv.\ϵLdÔ%7{o2ì>_u}j1zODe^npKRG'g~ (!ez6*@[ÆTR Nc41u2ՔR׃P{(g y;9v z7r6ŘO?5TT2|k 2`U4ev@оG HBGb뒔.'jYTɬIr1K0?aYɱw_|bt][c+DU*%oI:ap ː2FPb@L RwtoyPsyl=0  #Sjd.0T @K&w'XXg^N9ggSaIۗf+p\ѕi*1PKE yn^ ǃ"5{7__|YLn!?TA#f6K! whL뙭B̺Ȟ 6c2"WGt֡Λ'C d`–[ Z׬r62(^dm0?ay AW;oJ 3U-A<7ːa݌(SR᝚*(ay8\ÚtrM(L;ʔXC!q&]L!\ tBGDs.8Pgv@iPn(q qk㞄l.LՅ5/%XO0:PF2$MHFgu!6s^o /mP{9*( #)f X\ .GrY \̙Sny^yB|OZ^智[ 02Vz] ^k'Xgh%7J=|WB ?"CmE5ngdN9êQ0#o P@j*yW*P! 髿_ }PCXF ;:ICyA=^Q 7x #pvf͸uRJӛOdm<UݲM&RS|ݙ%mlfAަَ{-:E e\eNrWM?۲86!KG X ]C9$@PВ꧰/`~h%,IL;qٍVYˏm-van޻3׼Sfhl*0?V[_ޘOprbA-tcnxYj A%LLO(:qHluqqlVK Rw>_ֿvWCr0ϓDB f7T 8T#v#[79wnqbi G3 \U@Xph,7ySf2%{ U5<>wE21!$[b8$K%%t-~JV:K_x4$=VhZV:v>D 4|;$ /fͺ`'ʐH,i^Pثk˃H,`վZNGhS+NcZA Tՠ&瘛jˡVmyTbjNw>FKySB[!BhFIpCDx9%.of'..8!$Xеg@ڧS 7W{ 4J| A!)6jc[5>++$J|p'A{ZV8goFӢu)q\sјW|o|ˇQǾ]f6r#N{8L@ =d+.Iv@׽1ppVQ.7Xm_]t-) o!Y'QHirv[m=Ԯbs"Pا̊BZڈo :>\EK%O!7!6e7j#6 rmhA0I`19oqhОCM,#*ټejEy|<qRVu9e* 3[//RD}?!YBȚU5r}QN3az`$sW,K8ڌ-7D_`tks>%39shOo+eXPC20FػQkprXc hsxWUBw.yj5$զ?k#ڢ[e\[C#/-qb;>jQ3Rϝs1eR9'g1Bp?b҇#|{Z (DȘқf|WoS2=# (Ä__Hb܄N5E 1w^52rl9.܈L8Ա\^YqRZkCY?垥 oB" __!`Ranb܅hv Q{FNdeMT.\m%oP>IV_FlN$k3 \n׷!#" $#|\1͛gxu! ͂9L!A]*ʥzm7&!1T3<Ox %U"Y3ab=y:S&=%u3l 2]73~;4K@:aᯇd!t3L@QV;KD"5|%tpH}abyf m ;.X7Y7LL{K(?|-荥<\D ?jl_ |L9 Wa B=ٴ|w5/f[Sq*{O{/`v~}=w&=A sP#8Ak}SF`FhI خ`~ǽ?nH2Ee' rNL|LrXLu;@o<c`5ݏ'-k Lt4VE G,D#%#HNMYU١Z&Jk8,O첤t0IpՆ7ap"xrV~hbu/b+.WY9&6 x<<\{QDeru Dw8ySԍDmtip6}( ׇM EBpQ[ H⇗g0o{n}ϸ0 &L!vz2Q#|鞋x8")e&dѐ2 "Zy b&pKcK&IzEui@u@Ϟُʵ-Gl^NԺ$*#AZ'Jخ,5χeBU#^M ]ۡs$r%t1 6qG?82fB#ͥN4YeoNcB lTkHt4X2SWHU4Serc`'Z,Dޗp#AӯEne}aYkoK=(6<3W||j0?5#< }zP)m9`7|uJJYih=\!4]%,7[&A5-΍,]IS b~55kՄYkUFHl sL$5)ӟk:_iQVLEWjsYƓB c|`WiQ*_ǍLwǦZ#C!g?+3~*YU֎(3*OEں]ɩ#O)*Xb8h\?ɹXz99ɒ#$;@ ,Oߺ*|79v_'4ؤic)C6 &Eei/$[AQ3*P2)S#R DN7FMJfNSca`ȱEi `De Lpit~dR٘i8(F{<7e 4"[FrRr{oPdC}T^ԊwTrx'hmê2$MC[ :|.i*VkhPŖ|^;7YglY24&A #Se]>YMQľI{QH6fHe+FVOF" U q+H|T*0su<+;yMMo $EQb9A;_;!|⢡<Χ@u1HKDưD4$Kȇ/ʠ}]M0?ʤh!T[h E%k=\7#kaB %Oޚ+Ą>R%mnyqR4`yrԕA 453/6:}wl=&" ExVl`wSN4E :o"lڦ v^Ŏ(X׃>SӤSTъeJ^_xz(o:UJQ"sZXU2=|c,2sYĴ;);tpƨςI`Lӽ#]#![`ĹqQrL$9?4u뺳sAl$|羄TPk0[5J˔i&zNQ7 nR>5u,O|*Bm3=350f?^&!Nr⧥ jiwmڥd}gjg;!PHdbWAQ/HIZxVd f ?G"λuߘw8s> >H$䩸6, H @ x|'_(o#BkU̺ڃ՚^=xEe 6΍;d7/Cq=o.:BnЗ=Dmuؐ0(adSh# -"%? ͂86G>Yi'eƻ sYqYN\ALа`!q9(4=d!&f؎ŀ5y9X{i:4_M]gn:DXKЬX5v& 2g˓?eFEǡ ʊsJ1E{t,0X}\&f1.SnQ =᥅lewkT;{nRЧT+n;1 TΈ[A Wf#"[ 0h9QJ:Ә;ኰDv9_9vMs b=;dzz1b-%zhwF436"tUr?Q/TK7YwizU b,W3.w< ֪: 1VaPow":54K{[FFzD0 `ley|',VMK-7flF <_]썍qn& 6o#bJü%9h 귭϶ Xl#" 0K 7I%"&~D.ָՆbN|_oC*NSǡWyZ9oꑎ,dRsHFyb0ݐ;y5ٱV?ޒ*10k'BokQs%o-0ܳEۢFɉg-5o %JaIA>w횤ԫo0w!ɢSF\0xBoB?R!d3bjƐ$J=;&hk!JVYPWhtykHC8,GN/3}+J!jv1`aJղwf<E [ Ư?L1?Wk_L@n2n""$Z*:>LjVj5k}Z~Po]8/ؓ (in;@S߯&F ~T]JE Kiǵ͂tr+tɯRV{3^%+]ci*p)Ԑ'?F{;YOxH?tB6A8-r\>h)hskRA*y{3L\n͊'hMc61,OjWXWZqW( us50Vd瘥Șd[c`=~`>zyaGZ$:xTR>87ĥ(vjE%^~W㢘D$K8A7':k1Ђr7 4{tD>qQAc6U@E<ߵpJ03_A&D]CM>@Ԟ{%/FQRd '/ޤ~zA3nX$݈VJa/E q[7 O'=@E(ExpSذsM՜N"bp12 n6|lqkˮG0Iΐ҂B l9!W9-ps@5 JU2is*y+Piʹ|Aݢ_c?7c1+;|HEv){XQ jdM4§i׈ nx!e:٢ijnЀ2 b|5Χ)S٭@vc$^uKpY 14ȅ О"Yy& g(M>),׻N sѧKve1y8_We{g:4'C5T dJ=JJqkG,VONEwo-?#CK8b= ;6L}NT= )7<#>B9LGV>͘0LNE6h5@O݅<"J7M-EJޏbqަOnsI87n sC3C\2`C+TL_|8qtuJ8c:X-GU#:-0pZ1 fW.VBS-+e |މ 7~д I90%ouǯfɗxЅW)( V)D|JEN]af]0Vad3UR#%۞y],ɓuf Oaޘ3I<Ŀb U6݋xu/td`[NXM1)QWa%1ciX$w8L< wԙzʄ1&9H!Y) 2YkKSMQcF%\~\NS,Oә7mS.BT[L$k[ЧQKJjr5A|FoMsJ!Z_1^Uwkr#h&SM]"7*)~ w-H1% )`K3+|p9W2߲F:r?0tN\/{ڗo]GvZ{YϥB4>bH@)g8>Sq'J,fNH4cĨQ ϰin?͹*sMA 0GȲR O3*τcOlDU^YUwEl_t, jNGA$b7(ipHLGP:Xk,v{\Ǫ#~z150H"'+77îΦ;1i|fbi3yy2 ~( +Y-d\PyTFi o<>F+>llLD( g?ivbc!qmE_NLll#|D{pK }4yՠ4d2@~]C e約hLo6g7p>eXx?@ fA'6)Vr:)g40= TT7}z|g5Zr.E TDRL3/gn3=T?"7xcb\ĹMcC"@^& g rdHbfn[o0˷b~5,[CdAؙ}Pw2s5Ap+wMQSdǔiܥ(%Zqa2Y3XfgP|0TW8YJp?cTA3yAfYX6jȨ&h e2}m] r#wKA1\e-FODӻ;F![%Q _@Y’w33Ea>2BNJ|Q򛪻F*eg6M4'$m1'Ң[ huN +?us_0{sm^c& `D#Y4aUP3b)+"+ eE]BugnLRH_Ql8\ F|Gg,Slv@D7]^VL"#wEiڶ (^U[M^mAG\!Zb96a-ҿNoiNXPB\/Ha)J{C@:-AQW9ꈓ nuǔ#[3r%S,;ִAQD8G'&9E^dʵZDS v.@ _ -gN$r jMVfiЅ* zўH`K͂gm΁=dp`s`2,A90~n8pd ֒ܣG:Q~!9ctNy[}EpK4l [(]&of>/elM6,[)Pq<Ȭg<57ElXS6LvǛ^ 9jYR՞E<`odڶ%k5.$뮨=fc" j׃t;F=6I3ymAL:ز]f,2?vk-GߛEu5)̙,tA>w`Aq;O!%YD|*KRby$N21冨;y٥h3) dEȓs+5gvuklQ70Tku9 &Jx3$QR-KT(e>_V%N9TB<*nm͓|%2q2KmLycwtrO KxnJ",JX&%Xk[_Ioh$G6 =a˾屣UěVD|1Kk H:F@OҀOi,Q)RPO\?[ʶ,E-+;LDՔjؒ˵R%"Y\*~-<@Ö1Yl*w{0tw]0{=1ۑR؞L(۲y0( ^Ru vSž7qՌ|K+l-ʎͲ+O)I+u_R7f~1ԗ\7f[3Eیu|T"9MH\ɐK{zb=u;$(~ϐ",, yԴGGmn}]NfB rA&{tqF4`)Y⛭…B\ s "%x&Xw νzOkOT=hŰ"_-Yb +Q=d%ibF3p'%6*LN8 ~xdHOV}Eܷ&55r$aFe_y}[ɫK9MTB Y[GhijjJp 5{ &(vy.p{evhM{B=aJdž omMpXW5YR*^%(q/[p*eev|?K# K[ CƉ nuroqVW]Dn|Խ!ɺ[~tiȄrI_L9LF(0h+>;93ܬk\iI[a:GHrUHWi!`X_A ~VzR7E!Map53.vN ^!1!EX򧍱xbvWJ>D;76]3>6ϝd|zRe ֨?mfgO0 s<'ȫ} ?͉]amGeO=Y ^7W՗c WWVl ':!Zrg\ja_.OT)ϛFZ~"֔wWOVZ],#ksNzk½Lr}uFmI~abnE0 t*mSHˍ2|a3LJ i>:p!&8ݯ!v6"aVhO7н:Cq]1'M)tkhaZCZ\q~DK(ZD'l]X'ѥC-<~>TNF~UPb,#OET)-4>M^#G$Kh8 {ܯ5MnTMe gҊzwWBkK.k{ Wa.N/^}LŗFe*JzQrS8l /u;ĥa^D90Lϫ0ޓ{||eqZ 9݈|Xb4M=;͑uSf1$Z,d_Wl씎qy[sm8G&k?FH :&7x#V|]Bj(ƥ>KRA>BXꮝn F:Ҥ3{hK$m?eμOc*yv.cŖy#I{ؾ8IbYg'^1 JVFؐ4_Ga۰vWg2>Y}V!l)CӋcw&F Z7X,aW^A; !34xyL=M&tִsEamy:"T AM#a&X=~Z$FKɊz"~ (J&zC`uА/{`]m9ԚdILCkO 8Rvh*]J\Y}Xl1LX348<|3& 6`4Tmӟ?&"?'}%[F⽍BY4#cqR]C j :M X uQ-m"fyexg3WxNpj,V6T1T8rvAq> T]Y]ctsmX)9C@ yx{ B@tV<+Q*̀CzT{(A&4Sa}AQ,)\3>؅5 E5KܰFd@ֆxkvKG\R U%q,L,IUUA3a[# S'&ͪE[/rFdޤcWJ=QcX_~QܖaGt3A&\:k7t̮&'8R5_ʙ0EW h}Vf0BAei\GG.s PJmKyH =bE%fgiL%nd?7𔊤$? ǔtxwl1mOLx8wʯ̞(e@GjðdN@fF7MA{h NMmVZ5uMLl zDWҠb<.p$EKïw:B$Zwz f;e2::/B026KwbnxP2)66v[j(D,aIl3zig u}5Oq)(5<#9-\'BWfȦ53o]oVhA{ wIcu:V<1B(QFb%W9b+ղa:մh|a:c; k`|ˮ!Tc[ق`U뎿ڮ;>V^q6z8dqZD\YTeI!V39n*&ajBۏOdz2=/ &7H}I;}X PCW{:38! tP%G}][6 д&|ȡGت}O(&/7s %,:_EvL3e^мML uþy׻rʜPϽW=޾;S{.\gѕMOBAAƎz SKMv3c?80*jA&?߰@Bhi|AmSZl\'\vZ{]ۇ׈eQJV|vN@%aFς]@5/K9=`E{kO'5}aRZc8K^}XA#UgxfVPZjk2#:MFY& k *|K L޳WpͻֽߦHkaY7 &+ְVIuM>8*?&>ݚScvLTƩ0 קg#+jU@k”> 4rjsE<6(6% +':_/m//&gS5GN`wbRte?{ /nB A!–rFwN;2]U 8x!m9dÓRTF1V'˥YWI< /$RӥDy1R~ 4dQߠpK;i6P?'KGnVWT$:(R҉Ƨ1LG+h×Ct.$5KMYV5h'TlI86J]P8KN#(>'TOq>Rmyd2WǃW$Á0+Ezo}sW7}qU_gB2'40>V> rvW2%}?<^`=S2RJĊdޝ Ř+ }gGD7qz25h{s)xJ:9Pd/j1_}-Hw/x Ɩ}q."/{Ɨc[e^,3 SK"/ dՙ\Q4~ߨ*vW-i5Hh5R}k"E~ cSV8K]F02\\ ْfNzH(0N>0[6 }O0zxbl[Ε` lg NM)ٳ\Ur4u?/ : H l*c7MD4$4G-)$ߕR=DͫR&Ia^.չQXS/Վ_Sl { %2,s׃ M3^ˍ\0i~=6!_vZ WQo!QڊXW$TED-gڝ^ֿ@jp/fbnckw:dt?`+\>vnzލtUKætL'FCN&yxd-Z(F,hԓG,w#r#h͎mL|+OtAc֪N1@4Ui9(zhkEh ?~+B EDμKpNj3,̻a_dcȐ7y|~wʎl/((\@ݻ_G{Sm]D ~NJj󂒾>Iu:/֭?ުVZKVN&DewqЮ:$\| sGҏ~ ||{CJCpMny0b໻{gM /- La :(~uUܺفX^ztFT{x)mHx4WzL)oƊu;[uK5*X'ndTALxutYQ\´k(72 AJ1  B{"bs` \r=E,Aٖz}!n4 7V5߽!K!&'a*bj eczY3uVw`jP|] G*M.m.K\(p]!85si*N; Ra(=&%AHڢ)IR2rO0V4 a2.0)RfXaW>FA8׎K8˯JxacTjO}f)'=.yÐ r\j7tB{'HBFHDJ0q/lH۾=o;\<Om^}^<`>th@tZN陼Q-CgR{v5Bdנ(쭩W/Խ&)vC+JYd]ƻE~q Õ1"Q+96A*LxTKtx1 U)yqɑ=ǡm7yY)<Ʉ<˃𰍛uuűr@Ҕ+2¦73e9L{h_iOFCa(*}8 SNB<UOE`-5o.8*FgKm]Wy'-ɥ*@|*NmR05az7 r<-\vn?!{Ms:lpMd*=rP=etmt| (`#p#:*mJ|9 > pn,|mݛ~ўN0,*hmE{V뭽"O| +֮0.?@`R5gOtoCDQO|#`TZvx؁VY,TF$v 8l+<1 ~O6*:iB *zu/2E؀ǰYCUe<`=Cd>IbXI? ]C3Ҙ7W/#[_+ hwtl ^7e\tLīz!=s)#oP:Y!1Q=yI&`/L8ү~hZ&i~_ aȍUr O[ZUVm{ΪJk,xTR)Dӷ\'FEr&Z7!7_Y7 bL*!P]Qbd{֏_[Z6_xޤhD{OSS7""XQ<,+(M.Q({0;}`j|omNI$ Ҕ/Pވ>W8607( 7-5ABÄv5Kt"αu9'7uVS`JS,r1, 5 !ؿ$`oN0)I8 NxzVk UOa͖<]!d})zi! Sh3,KY 7 ɀ!YP|4z˲Nv#;[>:6~ErA |D(~:1;&^zmo+C4ߨALm_\t1V0QMAך[X6jD* ^^K"Vl'ʆ3wn@RdI+:Ht`ѡf:&5S@ Ŏ2RءUqM/+J{rrVD^q7iuGDM;`tb9D'[,Zø!v{tޱj? _LW7T0w =4@ʆDZװ_*E +nDS VJnk%ÁN}klR 8־VH"dsBZ;\՞ p5czlceA_W;V'e uyM'`Eʼ> ]ާzDArͭ:T')K>diۦ )ϋ@e\(Խ]]F>O{.8G<xs(:3Έ T7Tf%_ʷ$BzjI }"Tiv3Cpȋ=lX +9`%7=Z[M63Sps%RH b}i c57!IO`|G3Β& J\28MO|~p1톦UYjّXnFEzb9NyXi qղj@P m4FF=OBו쓗7 7yF{=}dX|w%Ń|'3ja)MmT&(?['  k~{IJ&OB )n1Y_ Iv'c[S@ vEY~S#\ʋ0hV0LEC2srW]HR:ѾǽRl]}Cv<3*ٍ +&ʔOSeo; 1X%ۄP뭠]H,WBTyz?UZh4ɋB9k~M _B Q)N}wǐU+Z}odTøm6J7݊m 8>p)7K3Dk:U'\ZFIkA X 2 %i䢧\q o ?KWeu ;tLX\P-=YѦI3sc==6MɻRIII5 ~jN )7Tˋ3"uۣr $sn+@}4I&`~%μhݘӀjNJbOda6^]ʣ$vϞ.M 뫜O|4%:f7󂹽P`V35q)1Bۥ$; =b}((= Ȕ1RK$sUWQ1E1myw!:rOjI-r#dPʄ(=@Z$ߢ] Ti7QF|V=4q=gzyYӡ8G KQ`wқ́ $ 0Qp~_^{Եr3Cjx1Zy_ xZۥA $ֺKS%wUaG9y Vq:F&*(nĆUN]#f,3ݔ>)VP=]p8e7SZ5VW2,9`C %8{Q|dB8( ѹ<+{͍Scݥj,ˍL((n#5]\YB_ie7\c3FWiZ8}W`Q*V>uWa}CD0Zd/-% /e^RB,'tBnC &BI萙]~_iIW@K u,@w`T@C ,<7x4m3x.qzjǼߢY"OVziU *qtEHW 9KYY|f6pv6eHPM{” g*ՓئmAQ1/s\<82TocC_STGWBᣓm\f3k9RHk'zr̳UJB9R^'(ЮG;Ņ̑3 a mAi~~-x3cо[ݿ=+:)m^As͙!m`i /KDr5:ƒK⛼n:gI+)Hg7IuLP:OFWY9*ҕd3 t9N6M7>V5suwf;i[7kĝ|q >6=A.Lls1ӲJ,dQ6>#t=6)L.ei3"-'Ѥ.o'S؎]u Dʅw\>A¡U K1\@NH7lh[}eRθf}OT"s_tRozjHM8+f HK(9mwF̊t*xv5#'uO=ݣqj PC,1WOAgzU3nVAyR5c[Uss'kOMh<$YLp+aQKZ4|%#u '+I GOk M)ł5;vK'ϝsU3}PR+ a5 |[`g ܿ cp㮣NNT# o7c PͩQ[Ff>גjdr\Kx$0pNOY i{̑֐?FEr>dQdznj$4'PD~0 65Qr΁;Wsf^OfLa"=Slj@0[[J6[o/!$`&%G TWQ[H.]Rb#Gcs}D!>H,Y.Aè x2{}7SŊA]#`m[u orhIL>W8KXL 2a$tkjI7Wy )c:fb@JH7c`f7K!ޓr#Q24T@c?B1dJL/*Y- <sQH:v̹NZ&xWjyQgG0Է?vS,3):K4Y[]vG9n :Ц.lL?rJzMÃWf'Od!3D##j/]2%Y͹XU++h!}P838D:a4\ڃHOd$ O/SI!q4Њ1=9ܽ]%b+0GQLcG™g)dMZ"Cl{(/}~ /JVvy_xT%m ^"k1iSl\ Qt􋹐[]hKS zՒ YN e&١Xlmh{ "uv׎f*lS "aai-P64j<ȶ}gyN0bw<]Ka+s]D'-w'F'`DFq]9 eق/+B 6oFn+9ÚtR^ pOE /e4KIEx+II|mdTx%oTjUTuto5bɧpb.AR4a`7FgMf``HMs?U =Fh&3$פ.d@-n^/3c!3LG{.1 >jz,V!H틝I0p3ؚz]\€?EvMDI g-V@A -gKOa~/(A Bp952MEmCEh+BDr{GCjԇI6bŷI"Ӱ?QӖW Xi7}ƕHt_ c`/oZ{3>YWUw"s=gw.նORu{w.B9Oj9n,-C9EK s=ղ1ɋdwF ֙Y}MYm,\ְo@۳'d6Y:H^ e D 4PꂇElaT֬-\i]mU+54,+1*`0 ; #ytϧ_eBGT&qK-bQ&/I%Q&vE% J\X<{ܞFK{?^#n=vZ/1/ZAꯞEe7@} SWQ;ZCת1oK*j'?y!2'N-3ݠ"5I3 # TVvQAВ WӪW۞&h^4 (6 ;>uymK|Qxwz?k?#Xj*w{wm$[ƫ*qnK!oh6R&b[70a/%BdźK~7U L -Kǿz yP]+Jӽ16ʇ9,ZOE`fKD+rTᣩahԽgE80, ZJth=|Jv7[ %CR^ b9k̊NGeYC˸Kc0oe\1|9 ZǛ;.~a( Sz~Y!5g(ls&D1::\ի㣋5?& cQ˪Ffw }$H?{RV:v_ZaC#(P0ـ#-W#qYrk:Z1^R(7Z I6EZ2>-r x1%wBh``!7+6K+œ0e8Ke,l\, K {էT@ѓOr^\d'O+}ҔA | z- ZΕyP;>JzE_[Wjz\,ڃG͓suD/WuTW!azI߯NjhѥJ+:xc˓҃xP Yr=B2 MZ[e$58`FS{{]O.51,y'883-nkDϘTu^&j\Woxuӌړ6 /egz#ʃZ֦mU!5͜1I&X+B0f+!WU^nff}7<*,^MF vm`"@򀹌i%>f ʏ7R6e IIhc^J D< ԆF;mcP?UA@'lǫ*om]" !եZzH3`SA-;o5aC(utwont1ĭ,pe& m@s6y?w4^ eU4+9T,eih'zvޫN_wuEB1(tWcW(Pь Y4o ƪ`ߏڏr%Q3F @cK')H,WB\;ΙvوE`pm&f,#y]irvX:"vj+:)"B, $7R-ИBZo4#GICa}bFըnq٨$(nLG:G[]>2'!xtQY|CXxԹ-䏼jRp/o Ȍ^ N [2pp؄BDر:(1?actgtMZk鱚u`6Qqon,()6񥡿sӓB"|NLjO*>'Ԕ,Pc[s_4Z,EdIT+b8U +{=EZ\l#Ft#%h""fXzST"g\9 \ׁV#%1O1ňbXiO)~{!_ٖhR?T;۽AZtJRMNiv 9kG 0 |KtguL=fD%ݝbJ̓ka CqQd_=-n矿i|WM:ɠ tKl\KƯEPsci,#i6G=ě*2ci9RG} :.q PfE`&5g" [( *;h#߮6Ða5 Ddu(P&ftCN܋6Cn?19/lNyΦβ(Av"{Ri8YʞW!2F0!:-˵Dma#FUcD>!.f 3 塿D!%P0Hū}&'"r?ry-+ KnO*7F%u`-!}bPAA[E_{1(=;6E. 6kv`݊韋ku1^(/.VVE6`*yAvraFSf`9"\H<2ɰfm Zk;.L&:"ȷTs!9PY\&?6!weKZ ŌR.Xi-k8cŕD:B}X! u eBP"}!LWaY5rpSShC.d45uƲ-{|mc zSy`v0Jà#50lIoRsLq?53(2 JE+4WR#]d*&`LvłHCǎsec-oAzv6O9؍%)VWE~OkҍyY% -:p+4}̡A,lElq# )[ l`)=/NRww:c2;Մ?D\v¸po*XE{'i8i(] nzm>_"wtYsSؙвޏ ymř\/ NpAOPx"@rdu>]h.|NdY  9AKyK~+, dCqII6%Y:Xi.ë`ݳ0%}wXA̯IY{ & |i7՛-};K'CV5O~i6_Yex)?o>'?᭴X`8pm )30u+ mB5dW|&*ho/2ynvAEk Q5"pD3d6-!NY͟aAl{Ce/}wxQ>2 FrA ;֒F<(]IvH^YhO%.JYtz?Y$2pTjm} anIN~)r' R@B2$ݤ'U-rW6\-YZ. w;qBqpPΡ!ycsnUh4ڞ ko(.=Q]Y14VٗL`_Sn~p?J&r<fjXؑ|m R$c{ *%9i$,yCw)Uv\3UkOI_wrHkdqTNBVJ$'H! fŔ!YDlεs_} C/4.$Jnn,41 3fOSfR;&xjJ@It[8VÓ^FZ=<%!b Vrk_뼠>A[꺇tc\`FÌٽ|H4N2d-SD*~ ,W{S?+emU (g#5̠_"6D7Ŋd@P3 |ƛߘ F퇲 VV773Ckʍ_ƨ@ĭM9YAjcgKt cC=H0U z&*b Yh- 2GOUlЯ8W{OrAOqχU]S{U7Vo;K <-"(FQ ؐ]7j\XrG̝u9H_tqJC eѾ0]]J1Y&KD#_0xppI_ˎZ$ϚjrK(м羹>`W7.)Ay]C4(btFg%ȓXQ_0:6rEZ6eE=E5:ڡ03*녶f;+!G)T%rNd"OyVI^}w>Ң;]g4_%h}k7$q%\n sS s+5ZG Ox9yhK`N@T}yJ pƲ0kYS@9}6AUL|@ 26T[was0 DBcEC_5lh %Jξ* z.GHIlڤpdU?o;p^JϤ[esO<2 )z9E=U0^LZ%<}%QC_q$`NNS e7 }}jvHZ8Y}|z. 7}SOMSA,+5h3$iEfXYsry4S_9M hEu0S33]QE]I>avOjlù=,;ol篳;O-un~Lfko5j:T07]9T0LEbЂm`ۄ-bZ*eⴊ|UB4{0*[6v+9am-pD]};e1X?q΄\\Ɠ"`2DqQ "â|U+ 6$e#4NPf@E iˀ-Xw$sXACU񸰷VRP484xjtŔXnC g-p`@ZX`m`bkTE1!b&QVnDH+';1} 2P |%›?edsn;_i?C~FJd)tNyˢۢy$:-jkT:e* (,?1<@0̱+sLECߠٱXseeV#̐W|}eY 1w璬f,kf #]QiZ.+U{SЀӥ*0;@qI9Mfa3TPp'gn4{a)1U mYBOi/sy^PWA"54Ր#9YOp8Kx4r4aWcNڑC)!2y-(]/sS'[M{*+U6Iq y ʳ:[1vw :w6G  ׶Ah|"cE>k,_t*P24,6?mlqunMGSo3ɘwҳIžΝP>ߌGEbػy*o]/h YXud]jwqegGlBctZ(OK;!no[24:fxL:xI=IP6)Ԇj}Zm^Ws( V e )f[/H{npʏH@?8/l}V7u:O]ȿ sZF*ܚXN>9{PXq,jZבbC7UN+ڱBo'O%V^[Z~"m-{1RU|v#S†@c6MB"䰃!*C:f#sƂ֨hV` x)ӿs'8H*(ճv{dKXlA_4GV1k'wHhQ:o1$zHewx2VLe@zNqi7:ת&1A{sDsō7q9!),-˩>&w:8*GY!`w@Z` ZOM?"(-?ꏳ}نڬJbFSeKi{PWT}-<#dFޣEb 7>9N"iYA4YcJ&d#-.- S jeaS:2s5⩞./z@~;#^\ 6MniYHi2am^kQW#q$V3Eb :+g+5f?aϡ;1MJKU1G\C5Z2^l0oZάiCR#dt ldI\Ta0T`3(e9]Ηq' $>'c.+ lxGč=TZGUJvPsF>)VM2wCWZ6*El%?Aݭ[|]T,J^])VcJf$P\xK7xH7'z!LF%a珆~Hk2 ߪ `!jAgS{2wytOp=ز{T/d3!Y.8!)3I{b3Lk㈭iSL;+9l6ItDWS@N+ѕxss)K{qJHVE@2g\.eF)XI*NY;R#`tע$Q#jAaxTᬃӴc`n3e Ҽ9jV{=q⤜E]X6ٜȌ2n6]ZfvS\[Hd<"c##]؊NlߡϜYRCډ3U4*>_T$%I/2;WKkzI`?Ah0Llw9lVp4Xyu{! mjBl|o 'ِ$l\gZUm#fM6Cg̵jösbH?IMm%LmByJjXa6 BO2z9Č >gt$`STq&fv"%c3*.Ժ0=\Ͷy,3ШцZwJDHֵҢl!y?,rrΛ^׍T5̭3jw_с.FmwIn?iBWn/oF62aHz㥈'ʱDn{4G!?E ӓy'T~b( +1 daX(eBD.XU.bʤ6n@]]Hzɣ0[i*aHvl<7wjhKփ/!\V1AqZ(]ҳI4J|eEv5ZrHlrK`KGa3nPĻ|%ṋ~!6VF $e0 VR;rlcmN-88/j3q @ǭ:3J~A'ǝy. k >3@ǟfy!V  :0@i:`McamQp?ޱfG] +̘>?7תCzRQBlOesO1k.Ӑ/SSm`1%vddX iC%ҩǕXKeK#J/2} H@ |mi*H,/ٸeU9BH`L$˙x Ζh-"r,~ddIwmjYɗڢ%/ZCU޳Me\0*}-N )qAGW 9{2!=>yzR%?pT"$sl QR//[u/( {š-1@$okﵩRdPH^KؼIdpK,Do1"@]6nХ9Q[p܎=)&q}D5e'nZ] RgZ)?wt){TPz05Z̖XtiW(0obZ*`d4:S0| 5wtKn:Z LIΈiO=}$OZY8HP]?c{c^ wE(.!<ݞ{ΛvgSSf占s/h hǀDv{[HV0W 55RcwK vǯFsB3<MW[`A-Vtv+޺/>]#8vm&p$ D"+%x6-Z{\,8rw 9Xmf-9, :Д|MCΖ7sp3%YǞ%#u2L/:剪ý!+D"'S6#-ãm !Fiy!{O3~*9/6]IjyɕٻT8X o, &RBE =,>06HBmQK~iNf1 ;l$gBJGkjvE8jY+&<6 F.4Iڛ7j56,`2O]~!D巬LC+qIIYu>#,K[U q韸m ;G8/WXUjBw{D\8 6{Wz "݃Z2ӹ4B1{pyZ=lBԅ;zEyO&N466{ I0}IgO`HCH-Pg>ԉEw7[s>,5C7[j*8q\u\ j`1[j}HT+"#in v<^jGq~1IvBVV;1l}H nwb6뭴>V.݋J385;I!Y\biSD]FWѸ^%-3{x%̹#lyU*wy@$ _4ں[TБJw ZI&Q9JC%G$K&|J<dzhtt0I9m cȱ͂4^K:["Ǿq $k&+жb dιyT$?;g/Dg+E^9^M"Z4p! ]<[Ӆ(_(?r|~2AVVH0+`/+1^J@S?@>,h(9`+JŷiWN:=% 7=pݔݻ^r栏E\+YXdY8586cȽ׀E2o? ΣUgt.-e$P(+,{ct.rI'(LBmi?]>|.ƌ^s*'R 6mͣʎɫ/y{6*tR_b%cՍ:r1Sv8VpC e'ɴ),7 *d#}Dž`(w]Bl'8-H3I]>k{佷A*!&b<ӊ)gTo +c)bC$ߵ")c_a6WJs0r 5ꅼx!-( -s:ZjN~IL]98ϋjA+h}F@GpfoEރ!j}k[w ֋k1"k*ejYaKRx(&!.uk!L: .FPY6~@[b ih}hP][)4 . !k3l^C2`5jp=JjF:!7#F*R\RRXC͂_!*71s*""9E%B#Ӂ!Ȭ)P FCRa{ iwׂ#ݘ,2QDUI ebR 1dUVhE6cPJŖ)獕: oKٱSCXH7TNIM<PE- ^l"!ȮgCh*饦;3CQVmupr-*vKP{a_s&W)(%ϗ =y-ۤybe`J۩ cP.- NuQ?""bZ+V)鍉uCiDRm(\;X칽nTt-?-ЙNg^? 0rm)Hbu+pѳR aIxXXS2Gؕǩʴ?]p" b05Ƚ";{(Sʧ3)߂02~UKmwkAs@Oc]G E|Z3J"bMS8Chiߠ]=ijpwVR_iM*=r]=Ś I:6NKi_ %ݸʞ*s z{ۄB+oB%9oP#M2 昚Z$=w=" le22שT.=nf 6"2‡3'mco~zIB2G 'G/'o2~: &#(Dm/8zQ} F۪襳Cfn` RE)SO޹ٶR؛<$ fRmmeoi^t(-?|=\:$ɜEwe&GזQbZFj@%*UM>6TLf~TY4ٿn@ۼ9i+Y[6ɗGHiԄї|ාKU $,-l~:xekbT@r #!gn֠.?T<39흑W sanˣ3gf4ܶuT c2 *u0H wDc @s,vW<:rxɼ)as >/<)~9Ji.v\Oõ#wRW*0gW׽H,>u3UY=X*e9,}y QWj$&/]clN[Q2[2ų9.֓oE3*j(~ȉ5m2Ѷt"1x$}pKR#+'&ڡxtHT83ܦdEV$YxpɦN)Mqط unRG{qrP*6xD3xf4 z.!¥;=ڛcFPiE0fO[sBbi JӍnQrH%n J7YKPvv#PKޝwŊpz͐#juuEH(a8Xms4 "%м2kqz{{Se,z<9@YqmbQ@ \"GSҍ5!`dqѮ/oY EF < /K~'EnВIm1!?mߚB,F(G*7z%Yy*fk U@uc5N&<)c2P*O0u^X_bYwOOb]:8T553 j{~Q;2Sh[pBofv; *,_@ɥg9f. lCic i9nT8VȹH̶Љ+v=y1Ԇ{=n^`rĸXk.6S'_BW| -- ( eJ/!s~YF _SFO@F:D6jC6vSJ?U^PܱJrA1k-)Ig(9a1s%ݴ_3/9n,Xq313;Ě< ,6桃(ʔ ӆ33,kqڷ랜8j`pZ*3,0ng$Fh˔|-7G'j1_b@FLRVjvQ56Öy>^VP>*  TjPAL޸j0/<WqP;-7?ێSy O<6 if'"דenz@bF]X5T5y8ɋY.=>_5DA(oo?PI[9F :<&SN^p-.gDFQ1z?g^Ƞ߶>,m>h.>Z@ؑ"5f7s r! )jkJD*']2ym0a֖l7lqva`GȈ 3"/RT]yA ˡ-^h$ M[P9R4){%{;󠇲V"A˩|I\O:1ZdK`@@cFy@|'@||O85<`f/0¬^D*K'IN&,uo[iItQrbȽM)©:J^ܰ0@s0Z!Y "ڎ/)"drc!L~E}X2 ѷByB'*@I]n-n6C‮ExjFg:v[]4JQŋ~R &`_gHm*3AAf:l=֞0-r>dCxnJ6?,hkE!-{SK38)-ΰSVqhm>bo{vqfC}2Jf;E /}1EU7 YA`iTR4$TtN{>NfdA vj5FHbHY$9JERcO2{lj}VsbiH,6 k郵e +e۫&AB4Ñڂ٦b~Ds; GHE8;E*mؠ}ŒܥJfhfqCN }@s9!CsA bQ>k: ;nK[C,|~`'UwY2i7_qm~>Y;crmw%$eQDiuɾ8Ck c8hYN:{)_ E 87Qq\~eN1懁@ff?雓PRh$xI ZrQvH,~$:ce)u]ԍnoP!Ccdq {ir<_^[Hhy@!:oVȨ ]'srOu*˦w NhߴN&kZS@Ё9V9WUҞ(SPmm (5W7 Ȁ>DoUKE2"LE[IdLb\RtG|8;TiGPPm+߰ߌ\),YL&VH֣X@t/-\Yu,mWOCc-͢x7{O}ɴӏB?Zc,tOXO(2,#ҝo US{@PKR`}77&X`;?f-,|Kw ;{!Yݗ҄ssnIܥu dXCX7}sY3{Dczn7g]4͂W[L[9WleĨx@_fY2#!`F#!߷~]Xn6v)L(3mGHtt$њj3ظ\-ۀ2lŶ0p%"[Xw+0sp2jP4>:AU53L\TIZY5NFI4Љqw饨`P^sR&X3b UPFܐz_Ӫ$!-+ŮRavTpֱ>f%綽 K6O6L%^ρV'GG`Fʀ38V絨@Ru;u,,zʀp/6{=Y+0kAUVB@u FC'vG3}o0椹!&zvm lpрE緙Ń5w<{^D"zES@rL6v\nwqDͪHp,gayIasODT_цF쏫Zf)rD1m!ÿo+zKgzed#khmf0 7=WrCknk~=&6?\{vѰNÜs!o|KEM\^gGp<FlYa&̙>?uD8VKwkˆR48uWbZ_8e UJ7G`O5#9P|UۃҍAjc|^8inTΕB;")tK~e\^@EIFtLmր8.;q] MvӴhiMiKpduQƩ͂Uz}/Kx :qaK/,66,CY?m~͍9fQ6*l07,S8elQuwgT9Ac:D*g1I.aSN8+v8rOMIBit_d-c)1BB{cR P֪b^De7\ ̘{໢<õK+Ҽ͈uvuAG0 .YZc$7"/| L}O8ŽYMzELSoD#ֲ\o?̕+^r䩃02̼gL~D1_]b읝%=⎐䆵 {l2$W2P:G qAZ굦I)q vF׺Qx\ݵ, &#H05k#o}.,ô`sIy.2/X5Ʉ9f`MRNsöm= 1.,\'}3V->p-Ha@vru- :%Xף@('*MBHWOT~5lD9V)of)$5ElX^;s$ԟ~ *3F4T5GG]ՇP'N $~=uv[\ vmr{s<=͚W]Ʈ`N=/ w>BM5q!&!a0&5q4ȳgr'|snSn_D\UeK٤r-&ـʨ}М3&9vyYY.ep %)Q{")`YxZ0MD17 G+YBP@m%e`dYV E+rW+%0ءO6\VPx@a<ߨ Gmd{^Npq"aRq:i`g8 ="}-k%A)z3(}Od;F]{mQNQ1+9"N\R$"`{⿴/ 2Ҥ/ Iߍ7JoFkږkSr( od ɕp@etll!}׹vDܬaF7A,^Eɞ[LD^)@̌%'pӬ kQ|j$%5BnZ'~>L{#c-)|{V~rJyx۔ .މKQ$ߣNԈs]΀\(Ukh kEٝFL^lλ֡Vz?oh=;8^|+m)B͜3']@e{1.plT6 Ry|'B2k%N#tz⊒Qsޜ_ q[ /|?+;$u*pTɃ%x+[%A|--{рxM01v$.F2;!I^ F7ب:jJ̶((=CgؘT9YJCaUeאM6wpVbdC]In:.׌s~= +7yo,F ;X4QdAޞ?W5n%KMLhDۧk%*@jM3&7{~ݼ"QeƞFϨ:}x>k4oa.st@*v '<|"mK62FR[KQ; F) sM%75iM 5rhFf"K2[;bA)J_AjEXyW\ <>2 R9E)ZP8eU-J2KɧS<$_nwN JD.z)/L̶Ȳ@ 7ƭIy3 eyfmx RDiÅZĀfNhNz2Cw[O,#{Gp$;J:|Y@z87+xFyE =9zSƲ)=n*&X~U7h=2yN"!Ki8Z!{#^Cȼ)CmbhdrMoMV bb=7Kt< \*Մ.vlyjgq %Qbd'GXGŽ&̨=.v)reW&'V]b5QP,T+Qdlg֬pW J9ior&\'|& mX~ԐJQ]'mBD!Nd^7G,IR4IcUФ /vnD Eih7!$3)F7h'om_!xvHSrq>Vg!P&,RaT]&" cQHQf E;H[N2=zƱ7&nLn\ˆ|v'ay]e۝~\}Z9Sq68ih~أez_!9 $:ݘ .]˽UE}.GD h3tlՒ]w'^X- wJS744GW 30 ALVZohgM'zX:~q[$1llj8£g(yTȇ_hVqlqeA ~!q&ڣtz|֢B]z}|VX z=J5M~Ybɽ) ׸ [Syac}K!Io^făb9C[m= 0`=QΖ"Y?g ^}5|~}(Sx/*ZT$oȻ,카+z(D!8/+:}nolQخ2K É&O35Ew۬BL,Dbp( KGCqTxP:<r\P)x3P@x&."٫+9BA9 G_O_::}2B(}Z[׿fRZthw_l@49sp-pW#Q ޣ3D.SD40.as :e}~ղ^=E+&~*+2s.o>@j,ߵ{(ZgS  |y4oVb#1iqE z"Cϙ\ĔBՙS; b?b4^-Al-Qv`2` v%R’\AZ3/]GTViD#_ ;@2gRxi9ɉ b͚-XWa]j8_&"v)9>^ZsVS-ӫܲ Yr eDhO]u~ vO<_i4+yQT=-?5ZμP|\{%;>i`/e-fEf߱Nu \L[ (-_db5B=;g%LS¶dߗDY >\g;]b"njJR͓7]p9.5K݆)u: 魽CmpPe `[B;-rW 䔶Q%@V,r $lnArG%:Yw&e_jW/ZA CZyˡ if )+%oR aki\ZuɂvK @]\ %@`*#&. č2NUٳ*7 {sӻٶ8fn,W#7!v4P%! ʨ[D CR`$\ 2S"Fs>c@ҥufnh]*f*F;{ܻkXc£?rXs' Ί낛X0z]f;8L~l3IѦ ^ v/+7+\PI֝=緯b~ p+u 5?}aVwAjr↬ +)P,PQ,z~1#dEnk ܵ`~HFQ5]gnr~MoIQ8H2&jnU}oVP՛ݥR cg95?ĶV:[pb_YfՂ!4 k~*[U7>-I2T.D-[|M)XhK0aK'݋ź> S(E՘bVi'|3:hD ]WI5 yexTLOꤕ}`mae'ong .4 !EAgLMv5jyi4+TdX>"DABu| B[ތbϡWd 'GRx<40@3V뮎 fbvl?mԡa(q]X_gf_;yCG/bblo%Y O#"56()Igwj|r[U!L͆؟ _r\ )+:,Oksd_b樓4\90y ӦCITREB`M,k?*v jpR[MB4fFU *jjkŘW#-^q;@.kjb 6 &$v}wp:ݚۚE2̳@9ۗT?CLz$hRُazZ9#s:.v-F)lC\ZWq$AL`YuAd^]~aM<秕+& wx D~䳅' b󚜱r ft1q#M)ό%Rje"L dаw92[[v0T`<1+uΎ͍G?ǰ  ,O-M}ߘ'zjD;dTؿ$9C+O!(.-m 5>QaKx`Uc0T+ ctɗt@aܸE}`:<ȉJgR"]"7#)։~"oE\"<|B=OOWUI0?ї*TӅtݒҀ6tJYOAӸnƘ-HW[C6I|pwr~=v?ݯ'0fI$}tC+cihjwM}0X*b&Ytͻұ6UJ\RįF<ŗNcyk0 N)-Ծޗ$>)n Xf!KIաj\c 4eg.F36e{ ak4i9hmoH08)\kSɜabt#၇ex)zUӰ+ ]b/R{*p;& M\q=/ '\!܂8ڌؒ謸#ov_ t9Jpon8]: Vh"(41M{e;}}i!$Ǔ셬Kpw K9:0K&g**I{CuqfRf-kRB&t&(ϓ?ďτ^.vz@Id7MPAkP(+a̩EHLKb![t3VrcH/]D+Rx>o5+GK#n˲`̷P!u?NS`ԧy }Z#ǕGG=:Q]CR+OLp)2"3SFQJtz$iNhGS@AIW-'*RaR51λjz:C뵦M%*D @'^DBO;vjM^wOvNFѨI[X#x/e&+Fa }ԃ+gӓK5/Sku=P3'M<{@~yxH?KVOSi? 2{EcTd}b+/ )["B7 ~\ 7AjRJ}KjNd$en ]i& Fgb`.mv=:k%T\ 텩lᴡLZ?4쳔yw.eIvN. );'QW{Pb'욦wk ؠxTq#o]^8 bT-owwX3$%^pR2~e x[9!G_ZRy4?P^)cMΗ8<3~Z *(ӤɊD勿SWLМv+G_jEK G),ХHU'zʣI^ Wd=?ÇmVݫm$Qbͳ) e[(= ,@QK((!tiHAX ՊTs^ʞ+wJ-= vv8Gbb w.x(*p!~=͓NXX\%[N\F:f>٤ Z9TX}pv^'3RT} GS;^w0˰Hsh;׿ԉoVNb?X[#"=aZDŽ!LcE1J?rC- b;+϶ |>8/خ3[$Q&0!xf)CZa'SMb3yG4H ĺ<λڜ@I$Z"[FUxSxz $:QsDZee=K0 O͚N@ a)A1;߁' ;pfޕBV'n|C NR0V#_4=lcd5h%&Qfh L~JܸH ; _ H_؃֨:~pK2AB qW-t%_"Yif`Im#5M,_ל"eCX8bs_!tM$>D-} `]>x*w'N9UKw*Ҫo"Ry Dg|ɲΙ@,dJ.4|6oDždGC0Y9Je +R!$'Tj5~1C>qϫ8,-,6G"V|⿢ 4}kǯ g6f,$6m|iwHلr(Up[? ){X2blQ[AF+?.n,h ѽN3 ~VVFܿx٭>&6<ǰ4*5&tak)>lKe 3~㗜2(ģ9aww9{D9I쭠#olu;0 uʎ6 Ao1]1v{utu^=7ۦb*Ü>˅j0mqzc*-~he[7vZWfm⮒_iuӴ JBf'}1H}?"̸J76 ]pRc'/B_yDMD³rX hPI9q]AMպ*g/~XYSS" ;x}4 wdeLyA{xOb 捭jW SAPɾX :H njpbÁE:An뛆4FќaU5*k@/pvr$?,DkZ9V΁[o\Udx=nI {ޭ2CYc2&{0E"cLLxi"k$(Sn[U%%O&XG:='FR2EZ-쀋^#kdeJjln|(2sVI3u:U̦Wzx=ud̶}889y>-: @ -+l'LmNzt,H24W.g,Rۘq氻oQ" pEFjqBGjS#.^7. uQlCIh!Ʋ׮/#HPt98gha֗S.EʫU<1]r:$47Domg/qP`O[j}rF߆ i";`[)IGpݱV[dƜw]Ok㻜[TJV;U%[s V4Ǜjj\yҭ5!Q)ƹ2~}jץb:;͕Y, ת{1]ٗU L⌞ 5Q ɷBL{"4`Agw3' &"\ CȄnPK2VFJ@91F${7] Y>DJiAAt-V߫$#V~7>*Sb6\NCY}ڲȲ!\Mnk~+8,Ǜ~Exhܼ-30!g T3MfUbOkC!wo^##.mҊ}#Kl?woPj8ay<b\a8 * VOQjByMk4~WҶXD7!,]vl\IYȓoBqiD3KF )?Ō ٍS =%qQ-BbG$M>\>k0%xP̦8@'1ԯt"iYIH{:3\:SGŨdV󪌁dZax V1T?m*b5T0xJ~ZI̱&7>{٬4 wSQ;*'/{p]i}O[]'\@_j/& J`zA"Cxv ŗQ,[P#;v5IIT]Z7W}FQ? r\]kغz9B.ZR`?  9 OV&PI|P¶|QoYE( d&E@8YN&fRA{%vm&I$U99?nlWn.iήƷ+ew e$Z@$>ޞDF>Ev@"wCtr3{%# :S yqŭ>lm)>lwBݪQ#sn̮0>m6Ֆq\}OJ6@l'i$&ܞoE_PwPK9JRCWwR A qF<e0#R8/{"aY&Yʞm-WKܝc_CӃLahQEG&/LG[9eȨ+I}B蕔7Q y_`A v|̣cG7Gj!Ac~iѫNobA+\s*Ҋv',zn,ծ;7yEοa"ivꫝH (He ud2!"9{aY`v(CˆvϮݧ{6wW :0hW Xs-5z-_ʶ \`ʯ+kCeys/2aسݟdKm] !{ dԅhBLk6uۙ/^.շi/ye4C%A*ZrpXKU}4[00SL:^GFQB8۰|XE4ȶG'\HlTB,p9U@Kxf23j'oTo4xt*i\f-H5bәRruG0=ʼnԋGB#[k`s"`K<3|5|ǰ_6!Z`yd8268ꐁcPsz$A\w߼H Y^fj:!4MQ GU53pۨ)jc 4<qYJ] Y&!XӿGʷ̆n3l剷&u12ޛ$o`l&!۞f :$Q~i"r@~EYdzI~pC`{_LhS br:Ć;+{&߫ LH^ 9|H{/h?-? s&~2:E#wꛊzXxʊ f+ Wk tJBN̉K`n( ^-uʓ5,ˉL%tWv;`8xt_J%pVLYhloHzJJ+|RFE02 rZ]N7tEL덤Q.$qMv~9+ǡx'zgdX h5}#p<}S/T/*LCӺU&3{>%?ep:r\U҉o$@7.˲;HZ⠩ p%HTEQ%9Ȕ+gz+Q[=(V=FziBHiDj~v+)}_NQmY*_+i_MS#*ΤS j &io؊!d Yx`?SL4{nJ)sJk( #Nr`YrN23!?-Z}FG0R [yD} m2 AFw'h4(Wυґݚiޅ̽9&q-?\UXew-&2Qke.ԏ;hSK<]F#wA[ONcނMk>T%M"U`)h 6JNL7w;_ l(DnZ+V$&xQk;SXjHop^f-ileHO;^f$hJL1S{,6p ;!$FOk:!.0jWCP2锝`NjL>X17}'_DqJ_R*|؇&_xp~XQ@- @ĕ1=A6| Eb\n@.=S#Ouu|qWxr&?'Tґ-j RU{,o~I)٭ӽ]ṇ43&أ %H[*pf7;¿Jz\u^̓}0Px pB9{l`7zgPe'J> ¥w()M>J4ڞs͡]+a )nZKcƣOūKSDh2}azgۖ H%P1L Y1K@8KMD:2_i b-BT|@VSn,7#i#z{F+۵s[slgk1BOs7[D95{~! }췼vL=Ue8*]Gȅy, :"-8nUO{+1VƘ\q@ O;;=Z6քx zE}a~ݭ̊)Xu'#z{rLL_! M&Wnw~AC! ~2{›;ŖlqSY"W(Gy#&Q{ GG$K)֍&.o:]Dwl/XDG"RĻ%58h{`x;Ce(Fԉ6{2%{fF@?qs1b #똑Thm3 uD45O#/,ˮ"ƍ戋aᐦ*B~Ј$c|*9d{ 7P:W(N4H`m11Q^^84bmǫܤ+ ug5rjh͊~jOO d ?:;fXDf{:R*XN1"~&j<&\{D+GI0%[((H(xBL'Nsk1YsDXi?44?^ǧ@X>c\vp;O-Z0Np@$ <2 &J| / hWշ? X;O~&ul;U>RFvHi ٬lg6BjX$ n]p긌˄H rϚ;oDl9{ vG_K ZZY!E}(GEF-s%>[?hToItH7N=黪]8)y| Nrg|fsۼ8k2p4UZMW*iNOA46Ȑll\pI*j Ps}41Ϣo}'GYVZ s٪ ++5m,['Eٽ쮫O"7 ̮Ѓ&+_lBV ~nŶoOݮۛ}>fSw<(7GM-DooMr&sMNjR{Et^ʱ@ LJN2}ۗ-[Zʸ#ǤMu.+OvZ*-vRq[օVqT>W OBz) %)$>t +\x uT{TNjq³ nBz8+?ZVGLҰS0u? LU WPCۂԆ_499(GΝ9s=9#K=Ӂ1|WG̱ ]a|DJf֩CZASQeqasof+"ӰLn0PGO `u P=]F3J!RbIq4yyVC_Pb..!zR]|DY99MGq%`#H jIyRxF6Z}HV5#tTL_b2Y;ݝXEnf@S-!̄v.-<N}XcpaFعe%W(f?lnǞX(+! wGw"#BzͳΓTKCxk9v۪(Q?*|-E7rs/(abu>З ;JFjArR^ұ Qh-,T3t` A^mp(IjQz:v*(+;@y&5PU!TϫnHLr~P7Qfӎ.rx<[xu1%U\oq=m e說ɔۿ?|OU8:g(zV3%uK_A1hn-<(iu9@Ks.gEH*LL +GCN~Kf>߳& ce[>RHsy V :ܱ6 #51ɽ_7"~ w9')Dw/-NIotߙP,tXo"7)4_E%5]n:uܯ(GP$qVD]\9 ة{O~{1R-mpNY}8Veٽf0h{t얂'hf {+󂢀э &^+7o !j*?'ffʮJ8>֡3ǑA+$!IJ0o{= m+t:m\0\Ձǭ8C/0[e:"g}wf~..UK&*́{ ?Xc7F2_jdm:f ]HdQUƶP^2瀍Б6R9)kʇoKV_9Arl䁡蘴/0B\ǖN tzdv>"Pӏ=9a@~t5P7P vbu g2{*&$QM'|GTɣ}һ0\a 0=dq̏ikntARa;ȘE3- 4Љ8 v {rT$4$b'(ᥟ|RqL@֛e p;oEELkbjB,#7r$ۼf :wނwtڤRfVTkk`V(˫l+TԻ9&ff,%S yW5*@HpX&&Ω?5fx Z*.\;J 9ʡl󧉒5K7@ItoO}eM VMVzQnDB_i~$rTp.lVʂ֪MlH* 3?OZAiXh~ t &©?Nm:tK9>"uaA`T-G#.RmB?qhJn<mqٰFj aK LXb`<$_3k`-́xfs/tWd/(7_Ջ"w⬒EWF^a9{>YŠcs+ڪ.ud?0OItta>YctjIKڠXSm[6o~j_=* N{C99A,طpw{f_ 'fxE\6ږ913_/4i J?J1Z䨴H<{X=]%ؔ,}BEv0*C4ނD9-PוvLjs4ź_GaX;s6F 9V  U=RFLfl98cuP7iy%r^TWQƂ]n4pmoP{Y>JjNC3)9CGIr25䥇cX¿W_V01'`^CJUphS,i/xo|`q eT4qDU N芴 Z+$;<#78 q6 ~R6)QEĚp sS\=ϧmiD+L7sٽ),t>]?> ƽ1 <4Ƈ j;QBXRx,-DvF<g\>Hlhힱ7H-%30#$a:t49p;u R^+=pʍHn*!=%=MU8VP:8L E #z|RK}'QgmjrQ|1vrN݁f3aOr'y:LVCX?\nc9)ҧՌqO05?Aw|J+0#p}(Z0]a_h XV"aӮ1j7;O,K^:F"C< z[bFE%%&i!HGdeVLpH}+zK<3SB0A qO;T I˼ja=hŧ^o}U!۸4"$"3DܰFT&@*4ƈ8LMNqKXF7tHQmgC L m[Y/GDZ^gP+i2 mg hå.ʱRYHrW`lօ.\Œra'N~8abLۉ@Q_]=]_2YL%= 6PJY\X<&3b< [ 9L]o[nfUf;~fYNY(0kDj28NG&-|SkKt^`)\ 3Ds_!=; Na&/ 44m6y;_4V{@@徹ne[غv[| @* 4A~x3Q7%rXsyQ%:T{¢xQvABzL"/pFu9fӴ:52b|,h$*.RVNND [FJi}.tK 8dp״o͖41ЦZ^>2UNƇ>hU*y= 8 TZlҫ\hIL7(xjǽd2W / ҦFF]^ô&,!5zeƬႄ6K=Ye>e.8Rφ][ׅ~XbA9Cz#=XMa;C5R96iv'] ]Lȷp>7[ָq;O&X (qT jtϚL#MIl9 #aSڰȣ:5#;tFʆ}ڛQSQ#ٱ"?-+U=|DYz 76 q sm9nSK *:4f85>orp0Y@hV*2(s.g> TnCF8?q k=(;9F[wK l(1i0v4]̾KC ~q39aSޠL=(ұh(T9ykՃ3 X:"w#Ǎ|@ &uް 1K(jt^V ]4מ,SnexPT J~>ヾfwB}q=|KyT3AsE4@G<.H[ zaL ŎH^I.^[BY͉8Թž#bɡE[izAR)2]?KP󗯾q 9 F{ed,$zY$$!igrfsbXDgsYA^J"= /q?DĊؾ{p$@4vwUW3u,*+T*< JUc.MOVcMvMΟTW49[xBm254̻OcPF/=KOP%UF*NS+@hʙhxm@hM; d)%5Y IFʴk/e>eӘԞJ\|T5~5/l&*6a,K%Moo~_{2FPDA;.ۮm`|3|n ihOmZ~j!aZ.'ܤԇyݥB_b|Aclb*r5o<{nxH!@UPw~#CWKx=igB9P [t l{kk5D5]MFBN\T>J?M1.6Ih{$&Op %~< +myu)4y;q5 ֤UDU W .)b-g03oDDi/-POGNDR>:h(%7f2{CNmt„=HT U^~jhUWHnRtl1g`8'׬gzQv XP}xa% h\KV5Ju"–\(d`;a^A_iTɓ8kL'ù%`ySI vm9Md5AO^غ>UZ` !QD"i5,v&E /P`6U!u'X taԒIh pJm,D!s?kqfKSF] gcşX7Tt(uq.BjjrIx=) $q]]q(.+I{&lT4$gev{wg1&z#_}05c4| Q<ZۖE G)D7T x@y(~ p gQ:i)yN)>@m >0F?F»WOa[%I{la:њ"qm V& >\~<*G}U V'́_fC69uOOsr%6Δz1E}1=+*bJ^B_hk(y- cY3v,[<aGޤXP+ZPŕ(h@40[{Roy#~ o\e^ER<Kh/2>")Z=+Bqw!jkğyaFثMCapI-Ky\F4NJNv^NF0δMVhl6VmAe(\#p/}226/f9&I+.j %yrm@ݳ>۾DH95qڿSHLBYY,t6ɦA0C 4ثܓ/!>#o }ºB' ]ϼث 1/&-Bb簿@q.x&}ߴS?ySO|TWC,'54NT"K Y!U.CiQ hleD"P4]ݡRI6% _=Iv icw}br$wO92ovhI`[#ÆxN>\uʃ bD)<Wݍ#T{߁lw&NAEg%dm, DJ1M3$ ;t2d.!#ֈZ\?Tc3(?W>jiu~.wlr*&9|Wh{]{^$Qu0(hcLVxnA(ǤJZY[>_gƀ. N6~ ?|$!x7bGewM+2k }^A _MνInعP&6Ռ9m0mX)r4VuZ~fAtN7/'k0o˭BnnnBYx<ӊ~Mb}ȨPd'vp)ҙs°G`A>X>/6FsnUq_02YUoJ\ldL׌a+w:C4NdLZwٙȚhQXAʠ]֚w+`BXV'l&W ]+ izm4Y':enNK (|w˗A RPJLL>tG|&M")lyQu ;{! 0Nu1|q.4%pxW.Ds/Cb=gvFJ8:7U Pj ,"=~yb}WDc&S LsYW l鬹r4F^w3uYBϡ {=@0HaodcLQ8l C/Njeay|r\ ;(\6?YYy&iqlqS,%ɛ5@SM :[\JDZ4*uaNްŀĮP =+ms4ԛ@9 RYT< _"K,,$S^"F&xtArCQ>Ԩ)Pw4/'ԟ08-8m-_'`ߴ1d ,ib?m:c}o6P/ \n4ǽ)q4:gÖ83^UK7/*H"Vm-`1a JAZTMwlOm!_s2Դ$ƚGjw4]]xU[Du-U׹DABƆT@Ă"-p07胴M^v2l BlVjo<fCmh6E(z&lzx`Ԣoq|zZxG&"*jॐCcpWW%Ybb+ݥzU>UHlLMgI6&Mds5S-kPk-'ѓ_+إHYV$pK81Eŀ[~ Ott[}'yS)\a+Ȑeds4qft/;N qOU0P*r&߽L={b (NcLۼN5>#*a!of kKh5pbY7>r~^ i1s u ?p9Ьj,njoM+d>iEf?x N jl1Vh*{g̍lJ~޶>R{1ѣb6/PZ0h?sKS/'WR()+,-/"s짰f57^x{ 'tFV.w.ERPitۏ,k-jUUqiV &c9x5Mj԰DYtK~Zon/7E_sֱR."Ly0DB c D !g)W*"Ћv} Ql8e9inEhC3 4`;9tumzyQo.PлU$yn,1QQm48 wPJ6vX@OCC/x=xv>lGybK{3" )=pbd>'xKk CЎ`=yib~dyG8]%~$dO* cs4|ڴf#g>c|蝙* wTnvdLGN5-PcoqA0gmS+y &&s'1z@e9͜ 嘚4Rf.G7ܬ¬ ;?&WvULUʅs-<ГJtI]NvROYGn|H c 33k-+uGS]Ε49O}kO_{_;CFVX`; }u@|̳ LHzipq)RgD @Sn\2(9TkiZq5^ -U!=/eKQ(6Ş$ݓ%ں(w i_وɎhHcW@ ?IÂI̩MgmgiPǍ?pE& rnj^62߷ȖQ 0Ex#R).!6#]7ȋlkUm1cJb=H8SyV}lP*=;(pLi:mco@AK8|J+-6o $;z5[m\Rh)=R ;g2Ty`vU(Z5:|dz^:O/o&$q;i {*SXTPUI kՍBd{t[uN9bl/x[: M2J9>{R31VEorΛ.X_$g1kƔJ{CV3FwE kyW{ +lk,]Ȉ{K-" {NVU;\{XQӣg[ٽeȷӲ> t"i 7هixI"(lN7&Iҹ.ڑ *_ߟ츬c>#+Uch?AVH %=IG9^%i1xJ<[9R8f0HoAknb?G$sA{'S7ƀM=篊;2JoC%dSuթ]?:Pu)j* /\#GQyMTJ,7 煢_gR-şxsyu3k,)l)d ;n:ΩGoxp(ż |W(!B7S |6$e2l38bߖ7#Fm)ˇ10\` ТSm, 2+~P0_,R)s mzN S />+~7gwL1FX+SkfP9{+EvʀLGBTd k)-9B;BE0\Ķ7uD,Xv{-4ϟi 75zA-dC avmQF؀WUk6,W=c.-<ѣY"u$C![6;8@}KQqȵ)SUYowqʼ?H5f8VF=%eⷵV2gsوUAkd]=Q`y'y1ַ} C0EPpS*eK˾DKwS.}Kd|X/%HaASˡZu~Oc740 y]?9TYf賘dݚʑuI\h#3 rNT[,mjg;̣?\cC0(ЎfɺRYzXOj.-%/=LUoFJu"8{UKb i?B;wO0u!.T" +OgJR5|n98F PN]9޺pZ^.@MsրZpSd2#+VH'(KЭ'#ȟ^OGhF>H5!~jv)]K-L,h4yo7;{2.4-i7J4Us\=?vuYĺrQ\9$MۻvH;o۳Pj{qD( fVY(3ڼ 6C[=*KT)ŞZ'nK$ʃ8"˱eM|C˃B]IP,`Oak-`3_>G&ڽH Ŧh`韚mw6@pfK]1^:MԘ J ! x"IGnLNs mC%L YF%Q|68ڣ*ey_Vd_6FP;`P\W$˺Pvo-)OHwS2{~>S\*"Edbu7gȆ"<}0 $-cTmD(ԚNoW'MdVzQby/~+P,Blpi@N/_ͨ0BL6F"|# tnk;RD#1B^Zie̪mܕpbhdrKc4WPG)#խ1ƓJsT"p& pO|&x!}.R]zmdl 'Ϧܑ߱iD_oM8jeP=24f0zDXJ[RVtRN,=Ufoo网ȸ+=!72CFB#2^ DRGprW B=yI[M `;Sq&*=wpBΜ'u!­+*w?g+۩,ڧҔ̈H-<6o=ZX"eiH& fJ44ӸCC0.'.SyR•0mnHq İ{vezAJGCwZ};]4 [#>8>O @hAŻ_cs;0SRobn"vdUMAK ՛1b59^>Rm}Jʠpr4Z69ۀP6L"lժ7Pˤ{Իq!Ux NF^)/.yw|1ƤDB0sJ'^5N'e)ĔcƭHtX: k͗#H@ DEC~2Qgb7X%nɌx=󾑪斷84^wl~g=_zU/v-ނ؄;?z`XJdg\#zp[9lד+$e{XB<Sp[pLeG.'$`Q.ȸm%*Ų گoh.`6.><^+hh|8HkbH8>O2\u:}7DH&!`R El?^ Ga<+s? os ԮPNьAw=|qlp<ME2ΌËK,CZl%ם-\oH$V>B/:̛ Y>J+ (&Dbpxwk*y`#9,lcGj[@-~:X}k=v~.܇ć~-\=Ty7g+Z֕|9zױX*cF(;Y Oeז&yY+q[˒„yɳYR1#ƯxR|mUŪBbqH[aSRu7}/Y{ 8fAĥ܋ȇSp&8N=}J|=ھ wÁbl?]CwҒ0*i˶j{?#,v> Hk^}]z{9Rס=Eh z(%W=n ֍sut)n(F=9 aZ\gJS0wP5o96)'BB-Ȣ/DZ9.SR^fn1Yዼك&^hnuxKlti٠ +L/8<++9U&h~?5B~d携lb=1^fFL&`)HXrWϊUbdW-'0YDEi"14khQ~g##Ԧ&r}h{khk: #i&; "hC=} ZYAMJ TW;\֤<-:ʑ2ZAG^}+uؒy=~kOg݌MA~Cв>5=KcH8hJ!`W :(,kjz<l[j'FUSH;5XodrI˙vrs y*Wd]ϕMy4z~/8j";/Qg̜DŽ2$ȁkÆg` LUyn#e+LwD$[LX-5c1$,6{hvE/͈T,>P%z@{\14DKNyd]rw'ԇ)mAQ6~vJBB2Iƈr5Bm1%Վx$"Z:I,vԲ" x%JѨ qVi h|êC@8s(4vF.nۨǨ9g>ٗڗ)?&w| yK)'FYKn?er%|_T-"ʭ~ ɼ&n;7%fAf?bY]3ca+trgrWm=(mL]zʧz>䉭 }`(- ii Yؤ))ok}'j4iFp>1%ȜK[#UOOPr 585 8lq&{h#R fxH|:Z;ȸ@H`\(# 8ozngcX@\bQ#EfM(9k Pa}. l 3>uHQ*XbEɒn.%ANʱ|Qv?gUYO[&j섟;*L8ES֮yk^o~Yn}alSMy4w11hc~:;8jrYjȰۢ%IfPggܛIcgv.H-W'{Q#Eu7$>0X LO ߷Xhڴ2:! ;T~By`vϳV0rsf3vSp_c]VX$vOΠIS1 :]*>4\2UmamG^Q둳NUr5J58SX™u@5_0L.E@"ʅnj؉R;}#;xh~wx!Wlcc Up0-i2ݐ(ONNFF:xۢ&<j{Bf$e-? UQF&L6E2h?LL=-;V[bTгcҫc 23,)WE5%p^Xj e4 `@Y~mbP^k|tUsj64pAkfrNUwV-,`ԢzQ\̿W5QlP?߰7r)ȞFd@*a *sCJi؊GtJ bFU Yj+&t؏k't7YOu<7ݍH€4l;EeS@2ayLwCg壪fz5ux˟9è\k"1o]<H>=".lՁ}^n!(R8 ?jʼn[Bx̪f,jQZ#c)9qAPl% ;$6 @ẩcUZ͔h{ &z2:C+{M3?\.H,MszǐL}>Q!dCHRrHm3<¬k.P-UH~F|N*3528OͦIK)u[;%=|{:@Zt|LS$l OSKr%3/N^tҥ ձWޕj'XS$I'(oaDp%t791(&VSJt>g0塙-ڗirRU@s[kՌ75uJbEEhHYj0q,AX,2`TF-s,kCX> Zzz2‚pDn 5$o^'3rumVvR!>D3`w$NKgkxa_ ӕ*1xHNFߒЌëYۭH#`Vԩ_t˜VG7Ԯ?{W-EA`=P,LuU T;6DhtaEո|`R4*"%z8황4x;W8mJ " 5[26YSa)cV!7ݪfl* 8J=U, JkP8#%O)+EbZYx OCce51?\ܑZ/U ,r? >yC3`)'RŲ"gv읡q9Aj4S5قrdKP3?Ie'*xV{#$W\B0hUUXv !`N %4+%jHA[?8jvN]4Bnn~  ?Y`&2#-֌4dҳx d>eȻHA$sq=&3nV;6CWU"NƋКBGyF%E]~*:StO$֥\tbܹZł9 ZgJ -)_VGa Xb\΃\ 561D/hkIOTcψIH#QF8U˿*=을!0OexgG@Է^CaQ ѓ?@lO@tfkr^i׿X 94LKZ+Y DNiqe.%TÇ 鉽5dWYk(wVR|"g;|t~XZbD4[^sX(ۏXOX67Vas}Y?=԰ Ȃid^+Obx=UȩĖ$9@tXzwߩT]fʏD&zԀ{U =!bI>0տ}> =b(1k0lM\AϿ7?>B0/ؼ՘}cO@qj|J ]r{2/!@):Kf^t_CMbhk U4HO)c,Eq@OZ]tqJT9{W$٥x  zw(yM7ED`J!ߨQn}^&O2kljmqJ#-ۿ9b[Ri |OH׳RhqOmfM(·\b9b\5Të8^ a*Nj翛_;v,DIy^#?bDox 0vN5%+!X%< efW:/I-EpH]A(g qLj"^ٯcPF;,>IΩ8|VZN|׎2JtJF_72ٵT͹ Ie=(zyNXc 9Ρx?˭uc@GHDY}NqD* 30}Ia퍆R>Ƙ~󝕟i;1OOؼZUI&VCOa:+^psTYc'}~I<ýrKokW=Iؠ{I;._9-mi/uɛفDN^pa:[`:}C7ż&L|7@},„:Po*<_gWa=)}$v3Rq`J/JZ4?a91{gnXZHH_sa~Ÿ$ʭNۗ p2 }!8l YgN H>]`"2'W8ːgidi~CN,ZvƢ&;tt~JN*;jGڳ&_AC jTJL G~DdtKz ' Q8*=w+D%[LR6/<::' AC)+8NnGcwIsF9Q>V*e.$cۡBV|xk3u'SnԫA6½Tf?!K-9j=hAT#c!o2.WY3Cĸ$p kDr.2a"IDlpziKkRpW"K.ʼn}! ċOJy>U(L/Wf,dz 9 -> tmqSVýFu1f`Mp鋃æwë %,+8ϲ*6Xdf2y5Lw8^'|d#|Yz̘i˝Ubz k9 >)5ѓ i fK{ko“dGB Z6+\x qDGUGom蚶5.$}h?B:J^G#ۤ{Ռ$"btQ[E}C=BZqR4'Fٯb9'S y"4#7G%nUf1NqmDnWp.B䚋D"?GO;z,|68aЗdē`W~B\9v`lG8 þ$5 hIlm_Acm\B  %q{f> 8xBi3ԓ O#S m:Ƃč8E?2},ݫ}i1O^壒`ƃNLYz?YGt>œR[sIoz"\5*bƇi',q87X(TX◮'VW?_:^?l94 ttiDhq1Qe( 0&xF9Dq'$e9~)WD mV&dz0hs[r{Y>Ɵ$#XZbA#4I AUiytB@qƵ-Wd#QF-'+V\x `?n1NظQ`WAU.G 1+U R=g۷rR\ezooLeQqSGDTs>3˥Ʌ֘Q 2;a-| +<~N ę;^ޯU|+A=b!OGϒ3Pѡ8g?F1KhTHO+Bt E<Ƌ5SY3?ɼݔP&:mݨXԨ /mt06~nd1M, 3C s A+ XX 0u즃C$)4p1]i8~6@`!nPfF:ԂLC7k]ݹ#i(`UĮdGK=. Bg[tw :wds{{[vgCQdwZLF]?5g'cd w&A"LɗYHAOG4Vaڤcu/L: AaP|c*$\DͧRD.uA$pV3nVSI쨚#>a2k63~Z tܧbEW~Çi[k t[L_{I-08Q.|:Lp,}t /,s$*qAHbõD0DK50-4*ԩ<٭s#hp/ \5ɅD Ȕ dO jF`p:1h|~\ܺS"0$]gB!$L#4hKb '`]x)⹨ъ=P^re퉠G^(RI9>GmIv҇8_N6+׈gWA`3t$A$,9q^c Vۤ!¿!_lw=\oeg[Æq?Ե{7܌]TC~q[b1ȃB%mywTa! %sA,AuJg:ҴX}u=U*Fhg(+N^;׬ TLzodX贵e-{lӆ6I 1CDj?N%ɽI,ႇ}NB>sUh!R&1^Dr~v{HRL0`qBl:#(iqze)]iT0ir^u 8{ROp7&xBpޮn7Cj *M B\ȜCt,>{uS~Yř9|(/2H,>mhiUS )s wb`t#k$%::m>5՟]T ;Y#Ɯz+K/YnW (n꒢,`{,Ye`bէ &6\Xh%);ӝs. i_(K' 0aTk (ce!MZ3Y*N SN|V7|0% DJ5oSd|\G3O@,$)plH]gf7Qg/hn <OEGm eaƍA-,Vdr 0u }Jl~'cY2ڠ̃!IYަwВK zfkcGRbr5e=Ƨ`x $!Jrٻ {bR+Xy<|,ks#L#xDpHTɲ}fn3ánWN!o|$oIb~DYrbhPر~!:>\"m|+6rXv啴<j+~y>p/{ּUOk+דf:q>0IKA/ ;O%YA7tܦ[*?Fw0HK[ktdܼ޾XU:dm".G^Ά׊I>ۡI9굈bƖ)QӌL_Bȷvi 8xmjW=ڱC9 j/6J3M4Ծe7!D/΂ZHp8m*0nRCux& T;p҅; ÞX*uܹHhBbzED2!ZŊB:,d^ȶ vBiߊ/l88P?1Eqp1f榔Y4j~#BFA6ˁoWMաMXh[\e ^r \73\Q8M?|c[EaZ2iCJYA-ʓViT&'߷zt(,4:g70"p ^-P&tuF3 *)-DaPe*aᐜ1YpO[oy#X;D0goUI0]SOۀj0J5;7MlгgdW? >Cz?[jX,6/ب#8owg#eUjכi=c*p S8zm?P;z;,7Z8ge, ^6YT:5CgkP ^i+CǓ"% +؉L>U&mV&3:Q PVԯm9"62n W>SյxÞ7P;(*3.3W1dcfSdmk/aNN 7b O/8-.ݔOcP,u@q$vc|{I}f\kDnm`/jF4 ^쟦eClh^`T4ϱW(ɓK}XF^}ǧrc&8s4䝗g(؃8˲ 3j .Y =#MÍCyl8_tGݤDAaro̵&Uwo8zEٸZ[ =h xY/)mv4)*4*_-򇫻:;?4kw:,E/gM[Yޔaw`"-x?7} TNT61uEFH}KpR91`rj-_{ A @g?Hk=?d,Gc ^'9n"uVҋT6[5E^t]GY9ffM>LhQty4O7K.*n[gfF, "tw۽ib&q*Ow)sЅ]~$o,Wb;:-H63\PЎ ye 3'}dq@uP6j0 k>8 < *'|""Pt{N(%$lZD0?v]<A?} n<.(UH~Ĺ5ل "hba'7w 7(28oaEn^b,Vh>RW 98.h:|aRm1=д7T"dGׂV&oK@JcA2A`[^u]"ȓJ.]5W\Zzj}rY+}2Nj Hjcdx6k5U{DL40D9H &%)ÍQ8= CiyjbZP}q}+ ? ޚ%yEu2-WuxZshu3YNDAp޲ΠX ~F2!iwͰvS67#XPXGoA"XCk%C®x#N*yu MEQ)dh | i#| X]LUD Tm}OVYA$1 }_b&_7?HeCwp |K|'0 cG;ߦ{vnԺ> mH~x4)g~%n|"=iHgkԧ;XXT 9΀ &6a4C=VuNGb^ >.@7_3Ҳ~F s$vL>f̿mĘ 42OɦrlȴQK%HBgBkn3` $/ݕ;R(.JoizhqD:Absq?7Xhո3|0&³*7nfܐJNq%Cǘ^sxBSZuW"km^=8BϋфעMS(`輭{ -r$.O/7Rͱb;MzTd/ 14% .xtw׸$j3ˣ,gUIK$v#8a5'cVNn,7Y[ϔekUab+nN_vVS^`[̫qA {, F\0YhfcR.Pc%zر/vݼ<)YFkQ*T AM%-z0!(LPvsBi @?1ܜ_~Y Rbċ.y 6osUK -UOOS"R&3e>oqd+@%mmۭBYu:6U7:\erȍ/dSQV Rc|Ն85 Qt25F,ޓ1)`V j=x(dU:[| %eN9['s?-p w5jPApEx;rS.9,$OxTޝ$ \$ R:!t3;5Ѡ`:H'{~] QqeUx614q/1ˀ`Na s ҘH<GNWp6|O[e4q+6~~}-]pDgBg7ҝ[ d˶? Ic ۘg.r2-RK_Y΂am FݳG+ɰB܏Ms kPLN T"^Pb!yz` ?|L&)wנY& d G -_f7~/&JK~CTfcK"ӿ *[tG@cѩ]o$QD[G&IK8iJh$WN+ώM-[̹$ Ӗ03o4ٴeaÆ3t楚Rvx( WW,T. TA?0ɍ}}HI`O`6ŁnU`:GymV( YUɓ)7D."GLy 5Z>Z4<T{I v|:D{b2+z2<(3'CUHVc/I6K4nF;wI}e A;`Nfuc5z]!93l>^`{+Mws U D#NXl#®C3+Sa'76HДڋP0{d0uFc_C*ݘ ڃU>Z}Z/כ䡻s- "@mv|HA4FeLOh,qP7 ~cĬ]mrRhꉓ:Zo[^[ɧIT^PfSO< 5 _mţD}Lf(RG̀Mrgt?ZA%AiC5 <#46?cF#yit{>zAeH ;WEcK!R*skAVq#I )o)溾R m3>~? }{bsgiC =.i7m)!Ev0Ԙd,ߠG 0,͕2T"CΞ4~HC,)o;(J?cn#GyV_l;{v2J}ҥhNE9@x5nVN`-bL V ʈ?C#_q4nq t +-DsRƱ"߿=ǿ'kaU LVZ@H@ܕyg'n җ](RAB_ 4m"#> 1wI;m1%5R̳;׫1ܜYKhUTAԩjReb?bj}w;E^E ^r&i{dT4Wv$ W({8j.ҵȰx3MN 5q{=L2?ni-\a*tTz(qI3M IlxaEϷ c2^G餛Ƕ!6!!T.go*sYG[q|gѮV{xX ظͿ™Aa#`O Ur7d#VG ~2(Go#hzpq w#P XJBa.,z-pZ[r"]JS2NxT D!XtÀ$ ؃:jJwcMe\m,VY4;&<[!by44YF'+TWRJdzH^0!Lz"$$Clh aqV`j[9s_Ggܹ*4NEbI#z _yR.A)@@r9n=LBl˥*B]êF>Vz 8PFO3_1-䥣3 q %\U 71 1h^x a2$t#i@n_FOhCbtcS хŊ(nkĕ-R<@cwN0')vj  @bA}p:(|i$s4P!_UG ۆ \'lYVCT UIfDXaM_u5Zn世x}r OI=DG"9'Qb IFak@"P}K">Kn"Yn+1T@xf81Tq+s{1I PhhlA8 JRED鞨 "_[U?mGSQ)1.\;1 tRp<Ȼĸpo 7؂/ImzsDM9NIo[gX g\# e+sߟ<= HZ, 2j5iwg WMw޿}ȉGM.QeJH@i|*9怯[ SOb'ȕD\$'$a`ĀN RktskfoH[!Usux&Y*j[r ; EKF" Owu256A[~K jMC4ψ$Uh=>FS#VʁNHQX0:8)5f\oK2v?aΑ`W4lS0^zaxG!v`xRXQYVU/Uz k>=nint6B}49P+ %YꓩkR IgdOQl G --9h;USECGbJC<7pwM eY6ZOCSY)׹EF8o|=Y E-k*ğ7t*bKKLEJaf"*x8(c+ vCsۗG0ծ84gRP6s$Ϥ.Hlш42REi׹nzLTF5!H̘+Z;JTEe3G >Ih%Jxm ț ?pAǕ:`,iA'XЃ<+fy"H&+OKc:+eg ?Ͱ7M+\0+Yc{㫍,aw߻SAkf1˻7XrVwF) gv:d" +(F% {n Ǚ |8[˪)yyf^ Qx1 Mcr.kV\OM/11#Ԇrjܾwѫ3P8Sl7̰6'"QGpY LeQ$áس8%CKgfl"sqJuT[n[;jY@wo+# #)ʇHW݆\3gc2:}Ji [%,S\8($Ql-'ב܈])uv'9·]uHTTϙͻ8ʷbƒ`a {lc t- ޅP4wua5r>"0$sJ9t3.$_~̰W7,*@:E!kP2׉U "-~`"*^^v5EnGZ.rFBCk6t9Juihp ɦi\2D"'t_Agb.Q lv\'"qEêSMj4 oGSgHzQvi.q\%c2͞$HCvls}п4]a+nOr6ߓXErh_&Wf< UG%T1fg_,=F} bӏv/{2 GITJTspl(S<*a0~i!,DUqo+r\ P櫓+S[,ZP`c3B锿&혱5pSNi&,k0eQ(N ,ɡ :܈Y]YA,a@ﻸk5 5H1i8l( ڼ?|*Tj Ԅ)Y7Pl$U,Ԣdo[&*{Y3h><&`3k,W߫zW|:=<QtߐX¨ޣ/I!#38,Jg7Po0ZRϛti;Pw~f8ߡ#K Q9sF^ܰ(C0gY&ʾ:w+,|sO5q`o!pSP|`:2`z@{9Ydrdy&1Bx)q$Sp&=ƳXݬ*s{u/o3yG ^jar-5/mqDS*Xov+Ēx"1tP px"S1!!C_sX@Vh EN6^g*'B8&8`ştc89LS6tidZ0{\yu>gge0OWRl _pLA6y.EJyd=Zڢ礋N tfԳ(}XTVKk%[^uPK |gH8%]:UWy¢(ԦҮ+|r F 0\d@cJwhZ@H;*ġ$swqd8 |J7DhtrWx2 q12X'D3}Χ{o>3ܣxYዚQK'ŽIT/5a:0\Nf." Цy8?o3BŚdVH R)cgi .rqz߅r}i%g/ܢBF5(ۜzppN_UK"'oWVQ.f'EB=IZ8 j2Q~S5 φL5v[Z, aW ߋM~J^(T%pXc iI\W&&6 øq_͑we/gy:7a `{ <}hQkAum chi,P]:R ѿ„eAZEwHz/8:Or>\r !&}_vpA)|ZC68է][6*g̲ SDv+e SRhM\ͯu5#X J&R hͦ1V}u#-Pr]UmYdra=pڰM^(9?~$~STwY9r&&ލU{o)1 @[n7VLɈq?]Zhpj%l'ő`~d 1EZ?Ol,Ape5 bV^@][PW]e Cj,q S8UzN╪q Jꈶ(Suɹ걾u:`j:qtCmUd؀gdUzFߢNU1CzhX(,b^6JXWg &MeÉ8 >x7Bw_AU{W%T:`ʟ=#k=s`o}.sQN@%e)I6(^y2lӃعƷg svZ9H< G]8xߪr}ށLW)2A=fGMFPW.M K-.mj&1Ԧj"WtwWsGAcb7?u[74~2ܗ;We=52Tۧ΁jX E;:VdgAw/Ǧư wf- &p|mMxz=ak{2ʸn_XPj(`\ѧjcdzUaZ3ֈ8,1N7/ּu,``Ũpy7?_m@UEu#*׹&n+t2q1 @NFk$ԸD6Hw]-!nی"m9)#NcջD".ޟ$mw|}vQZTγãgR ͫښ>3=Q_:X%?\je rbb}%&hF8sف1:og+wGym.CFIamBqoG올[VRn1KBmt<I h=0gi#c8 4=b@Hf/.7$/yvU xa4 f㧊yj)PjV [d; 7I벮@p̭VkgJ>nu}!{V;8m+I2d' y*{x4o;m6rf!|mmyHP!4F7Lz?Jek2SUSϋ5(lrmneD~>jL=r)!ch@ ӷ!e {A-M)vA@tHy\E;Iz'tؒXм.aSss,JkF5?͛ؠJf |@).mWcYh`J]bA'ęk*^\v(,lgMYѬN+L YЃu?]G:ћ`IMÆb_l*73,M`M_~k![ݝi%a!č;EÓ aԲvYqTǏaRU1/ѐeZ`“l۫E_DxwC&%)xBPN_̂K. cy~pǽ.Հ Yy2zxjKRnNWId=)-_O tǮYE<8hXD4.K#.HJUkp9v53W< tK ˩oɫ4ti~l]Ag-?E;>nVdoЙv6`2XWL򗰤Q C8xKƀҷV`^9ϋ2,';m:ѽOzs+Q|8E `yK"txHM;*ZY"Iy97Q\K |dP,-td%&Hp*1M]o OrFp!РYO˅@r~6 : zM1m;1P%t~j]J,<*7eRe~jEv|Zywd'w !qUѣ';COn!{Hq1Eg9ƆNU ,{DnJ `g(tA5Kl3`UB~#(͒\rUMÏ'pi`($eh?@T1ar_֏8ɏЧ6'WtJ9U.'/}|<^b>CUPI9e*dJ ؊FW#^ xQ\n_ C3<?@%"^X 7$SVPaN s]p'G_`sigfb\h*,w%K7dEP})F1a Gz"\Mžw+J/@_Х^Y^4z.aEmꍰjg0n67)}] ?J0&LtYXqƕ#t倫>b-^ 7}ιѩ ܌kgy' ;v(UQs`Qu{|As`h` q`^"" wr}WkfAF`Bc'Q<߿aM܃D.^|g듳 7 {h{w I;7 VDx8MB4F0w*z~ψ /P~e䮹BM)\PRD5{@_yq(CogwI-0"r0zj$-dP㩾,j{b mo96[ĢS2AXb#&5%v8;4+-! i SSpY ʬ~ :C,jkY"3OUςV&>=t23c1Oel a~ <9d#0_oKÅ8=BL6X5[](7|p)Y{Wz~s T ==8K2s]++ 1"@~[wuLհ]ayzWli0ˆef!Xxs\{мaB\d#B|'8E 8RP67`#a7|_Jl.ۂ9`fM`cUU9CG6+cE0H)䖠kV$Qp"s0 YLpQs[bIMNy~QgYqW.D|89,V]40:(" -M{R\^ZԹL`KحSBz`Sp~Qa@8~ORw_[_Bvq,?Z `_,x֠sׯ_GPԫ;xs*ccC*Ǜy:jK.8h՞es5'.z έ{1U\5]0Tqm&5A%\o'^;\b2:LX433@:{V[ۮcjP( $FZNm"p V@MbQ1{ x#z\r/_FJ tиAx;$dmWSؗ˨`G-eszyTr##AJ;_;}Jjٶ$4#wk&Z~@j{q-mUĈYH~1 2L6Z4C0:JJWtkŜ)Yݷ8bC6biR%2#TS󈪑Jl/t]j7A(p(v,~S ѼY_'b]_9]Hb̷QQ-0w'mu}D{Bァ>7hEd|Al/c"? {)_Sg)*3t}C6㹌~f0o-((hH-Pn^7k~*Ívk}qLYZd$Ao(ir=%p ޾h@KGWm pvR+%xOx{H:M*@tK:1X*# ԍwJ6oC&I7?OE7L䯣vCDĵ[Ky}*Bu8m6 mwݙJ ;<48f!{)C@o0aa:r{Vir3źE,Cg8 q|w!Z)0#l-x+%<I>~RU;"D2X ;nْ!e;Poܯ7]2s0C\>~4vI& S,$WI#uI2O7@F{k. @s|&W1/'5.ìY`|q)/]WKmѠuVAg~n6SyqT A4:\s}Xw2eidqmUڊ {j̘%G G~^6BM!WgMf^2wA2:ԊJ:!9 R\Bi- vgo&^0K%MD)] |g[xp<1niS7q'ұ Wt^? PtdWQ. )x!%--LNgby%l` :FN._V⫟؝<^.3Ψ ߍrn0;Ԩ*և~w\{QWJ]Adm@ܙo}u{x R.BzU>K3V|&FN7*"Dl_\Z7wr]eZi֢Q(7v++kEhtxR4\P)}y-;gKuT8k) j%DDT-”-Krl ;)BU3pܬvΰ_P11n`Cr'}h˧F*pg y)*X(J{XBp{/X8R] |d/_>qƔNQ,z&X'^D[D[儜T|b{([Y %*(J I"\dWfC\:_{5I9xMUy d3+ ƒreqa 97\8nUuRpðe8(SDZgϳ+j'I^;B_Hi1g~Uft&\X+-R )M2Xn& Pu%=;u@Jpҹ9piyo-I"Yg'f3aKF퀏W.p][ј u=zz1ww|a7g:)NGmGluK ? 495G z P"W.k ;>}#J"5bNw-Gwy^ @dL>oHN/a`)a auB61M>nl:mx+'{ eU\2SsՆ <>VD_ t{ pZ ;&gUtO{RbWz[0٢J Ww'g0>`'&e"n+˺ԂJA16cz=5Dro叄^z6>kFt:}_0&-GC~ H>Pe:2-%9Vv=} g]'BFaTRڭĵIKēi*ÄݗAqGc{SS7fɡ!S$63> Lro$52O[5{&`dr)x]=bI2C)nemVu߮L%c)o^_P2|kM@uSf'-Y!׸.zc_҅cib&zqיbg6/S ٙ=YV}z0|Q{aUK"'j9%b9&17ADZt1)3S{qv֢[ C<" •@cPI`cG$MXPDg{8$x 03໚`;G-˘TENs(>\,}b;}&HM- 61N(]{zw7,D#O!ksחcϣ0E}V^x%DzgYI@'O(2D)7Όg*]=j {cO|oڍV*/_x=I_Dm` ʶS9 kQ 1dh,oh\TW$ sSi5rm#~6?§DpO,>b¢f%^he f?y&Vnzuq*kGk<)g4^^v1Fd]9`T&z4҃X#EokAuR;R6? mku n,_shcwCz B9mV\/Gme#i=oEo6.@Æspg@-X3Βmhh~rb\~aרxZڒM=@AP݅|L9@WU b8ert!4覶V]yG c;f?ѭ+/v=PG)gNMwp&;yR[UiIzBmL:"%6whd-*{&e(Az6y mgIF}i?@ڜJ9MV6 WlOD^V0YC\JOVcی=r\,.E2+ $bC8ԶOՇ }G N-x5Y%>C8Zr]kLԪs{Eu>MYBd^=bʜ) iL!0VB9q8c%NpvCG!-mp@NnTs!z}!N+Ps}sZR0%[>/k2KL U̒?nnopߢ.*?6-0Uy`A}ȞU +2.82-UqhJiONǬټn;OT@aw6] e44}HzsuƤOXUn &GÁz, )ĝx|mCq:7R9=/:Dj)"kBqJ<b8f{DOa<, E/U쌜6ed@Cr0없;_t[ZBMyfUA>^3؉:(Gc &KECȪZ_3RQI_H Nn` wh tiOg1|p6^74fͽu$B̓ AX8lTZ"r?J^72}kʶm>̴q 7\БBz/(,xS?t[O 1j~j͟-pgPmw ˧[FCO#iه]B^]&(cT0Ṯ`cU.˛1Ͱl%Z)(YUnRSĎhN$$"&`v7SmJbW$:4iƟFvBG(YG׽fpKPas- ز'Ih& jSOAS&s%D ˝rv.kPk%0R(g{A'0,jn>C;РX3] $l+nL[f13$UcOA`87e&܈@u,eC6lXe3ZZ뚑H{I:tAB΢ Rf΢/n\g$tl%#I1e}}x{;ܼ#Nˊ~Zty:VW?xAVڲ\ֹo1e5}gfTy2>58-lM:A JT:,-tJ2.[ȉqoKI,riZkǖB) OYq.n!u!DN~w0G,.COJğZٽZdN5 \s֑4.Ps4%^M'K[0wdW:z[ܟ7x-]9vqTv}R6*X6}N݆7ƅq?l?wӪ.}lt;a-jhDr۠Mg_QOu96@[`Mݫ"uq⟔{ ,S8 Sj%I}erC5=9k0R_ߙ@J +@%(IT$-erFB&Nܗowv ^G**C!Nq DT ZSApF]2,MkLBH )*'#9({>H ]A(.`>y][0:JK$Q?b:- #N]_: wJ+]P4-X,d]źN"Wq[u1o*aF@NE\z9 ,&yFuMb*eZ\3f ,V݌i>E.Jևp̀"YA&iD̢٘ϻ8#Lxbq,Y +tQ?]؆}mlQN !d<+\x!/ӓP={MH@'ݵsA.J>+ B̓TmpfST!-LIvʵkWfګ B$?y @ ]aw8~CԞٶ5a*o\?gAhD" /ωdQߵVvӃ[9oOw͍"ĆU鈟Keƒk5ދ/8|4Mp mV*b#OFŧdfi,d@͌izPE;MgJ\^U7: iCR6쟉;(*\QM&iDh{ש+ )*х0Q k948,݇Ȳ-(e ~tLr_R+子v|IR&Ћ;}.DLݴtt"ĝKx[IW9q1sFHPBQL8aI6}?4  q18zAd(}ZC&CqL1&U3ҫ@-~CN&G>[OPC!5!M[*%s {ֳU wtS~g@Ks 䍖dwSlHVu*1ZWYҞg'A{݌g|UII*?~XWB@,)4{zA_N:X:ꖇ ¯lToFO3M9yʆEEҢ&RO\}P׹͓f͢h럗ެd4בQNFԁ-Aw1Uzo4;s|^,T]H =A&FLT|.ܯ18*Ziĝ[90 baMf}|^`NU`22*\VNJ5ed!Q bU:$w˶ySy ?`ÈVo#~|& ײJ@q'm/qƄjH:4!fC2reI-k5XZVia2icn?5 E!(3Gژ eϥQU{6@W.;z܊Z0+j*"~x\Vg S"QNHe@"^-E1d$5۰XR|#O:q$y~Fyeӈp{q]vP=/T!iFNj?woGDdh9IIi!RRc *<0Ai^ʂLZŬdEx6+-ew֚ /(OF`W^`6oH)%%RX3$BChK`Wdo90F}h}6Mw-=hx~`p'o^/^1Bd/lD hj鏇 ~0Й+Revc"@`;?xQbLg#.ز(!!+k̑Oaxpʻ׋X>b Wn8-Ttg{D*{s.u}>VyhI2B:*l9}DVDn))[<6#d=*]K]02,]}^`Iqm<>4t9St3fpXʌk3 X$vbxͅcZ Бt,`9 c+b:;QMr|s*io$G"opoXuPkLώX֑5z*WdU`RAC!w߁CDCᙼ]/݃|+˻ h5~ V*9Q/5UC-?Q` ±g?c*[58(zv'1@NS6w1KA}Q0}SnR:FPJFQY ]/,%#/7M#w%Dϸ"6:V=vVҶdp!8;D('꧊j1Vs0 :bbl @a*J# AEqh*p5,MLO*KD 'A~W0b*6(LA*@R_[۞L.%nhl Q]CrgKa*,q j:ZˍCԅpSCKĭtz藷/tߍ+-pL;#qyz9FsxӰՏW62_/Y*ݳMx\*'kmq,|Тk#;ˍ+6ёj&fHk/_\+l H:7He|++obX>X =&Vʏz];[7[RQVZZn"&_iɣ_j|.`U1֏m2%e,֜{Qd> 8ʑ.B 䀷 ׿x ::}&/߸ ;%\K`=CZt|Gpg\ IUZf^'Y0!9q1YV& <Ž/|;>!흲4NpIl_5n!)1Z4`x]ǪC,h_R ]E!Ȉq,p$)NJ_8juL ;*'fx~`WdaXsg]N finM3ziq8Ymj؛ pZ7L0jq=D׼`v7iJ _G^ZRQJiU!JY b'fa~_$z4{9PT4 {<2Z!-' U|#굖> Y_ iSXRT4ԙKgRQ%1]P(9'e,W^ $IUޞ-?œbptPOae aq{(*lˑ QOš,\o Iom9\4AEX#G[q{q`xHc( *]E/_h){. ] -^|#1ZFX_~1k)јBn]L6Wߙ怓pkn-n]O BH2Z8X=Q u/ h Ș!˱nzk]}2ꜞ3"]J3\NDԧb6yANjW:9 5~Tb2y9xaƒ D; [w8t/~Xca ",o &8G`6P-@e>@w5O_ 1V_g!uەj*65>yonSݞR~})Rj.3Ȳp_oÊ/p:wjkqBf=* +/7ˍa>ēqVO4,@KZ]f~"GsaqXwV1XV2,s+7E Ȅ+@k/]Sy;`¥S稧 ]%,c6A) N+HF:J;L؝? 2tWpXE2);2l=,yOH~ ׫l(nML`?G]GFv䤭#U`d=8?\G |x+) SZ38Da[b#\;2yp#Mh$&ǺQ* w%`1CWY@geK x&yˬyF}\>R״(<qBT!tVkz?$PCi%G KqQΖ4ĨXG:C:֚/j|+7+ cT$FcDN齮[/z18eNYr5xg*Om?t~n ΤYSjW& A@PL+$i,L٘n To~HL5KGDkƱt|@GIC5B6E%Rgߟ;"n]m+g&HGih҄D M^mm͞WiMbӝHli2 idnrD2Al:j"lA0onڷSBN 4,* Xt=r"vzOm8ZfPcsC)ڸ`mS6´V0[0!44i'!DǸI?R8JGSl@%_V1s/˟7ӟpIZk&dM7ș 8l(Lh2Qj. QВCEkd1M ?k%tKkjD~){n*́4Yj+8E g#Za-e o߀kOLmcXy&\N¼Ms918 d(\p<.S^Sϡ};Ϫ&^R##RHE+ms 0vf LQ)fva^*H  E֮dۮ8P! X;WCOz9S/ƮxbuH}PkűѴʋ4w:8ۂ! i}o7 v#x;A7, QsMA|c/';\^K>_1_czTYno I6u]&^qZMR5F|N*YwtW9t *q_P:LՉK6Ҽ7ߒKtYt: aX7ZYS `n{A.T;{սYPqs̾ y%H`рM8g[߽t{3`"` 'Yۀ[r d3IݦpW:v", み~x;u=n#3jrIL1OmpʄVe<]Q{K6ǒuB 1i(UvtTAd[s%۴#>d#syxyz_M2o{@^3.]RK2= E2D"9V!6sxgioMJKprJVhp79YtW-$ۓ:o"]=~ PISEE}bZ^q67OΊ _N D: ;={LwH`ydtAމdΆ>& BJJg^ڄS|@m!eX+*%0^a.]zHi7$Oa4h0viAv?5!wߙ&&qH:"HorBͿz]Q%uwQLV.(1l^ XB Se]zZ׺vƿQ"x\m:׊lхCJ V&Pv00uRaݗTFpOHYLylP`N dqVνC/j}yZ9]^ECƄøAe!vI&0&f6El bK?W1&㟯LYkK~ ~ʴ> I4Mph?بwe ufGF{)SjC<[n+Cn*gMuZcwLZlB1/0cy{#˓D^/7(YVr+a-!IO~9DZMj.).r'Y:m{Zyᲁ93<1Pxj2zbID$ y^ u`?Y//,Ԭs5SoAӯQb0J6ݮn'Aζ:R̤$} `Ar{E8P2>ۈ;h/rmL ^>4b_]Jk= I_`f8XߠL0K E.< rrVƚpK!Rݺс':kv?ks%(S7<7`x&(# OZkYL86 !H۝ڕAzsƃ'T={ BV z@?\q5Zs :҈X3r]O9c FK)j>@>us?uC,r2(MA.*+4bmrw-*pC 4|Om̈Iyp C  {MvI5 <~J@L:㺱>Vg!/ĥSY6|=wLgBa! m(Bhq*C)YN Q_$Ղ^ N-6gCIgQ.+6JosX'/ݫ\ڇ"OqTx==h-mHA9{yfP7q%|\%ZQk>~n i@|'iyL%-gz`ւ9;w1-D 4Lv(<٭ t[E170%σA-6!59=RZPފeBQ@ |Gn|Qe?b=lFx9ꧪ]S [ wNFGѤ\z^TsgqH/>jL޾>[ m\3@x g9Sd($`| 'O 7}F}?F +gx l*~:Om1S%5=8'o aVZ2 NI|H¡K' SX?m(^V 6KPZch=pc[qiP`IkAeP?+kBx@ =mΙh;}ݛ"2+*Zۥ=jTyځ01 6~Z'o2PTyD' sL$`G{P=={H1%$}BVTxTz"gxEK` /:ыoҲhL^l?A}}SW2]pt $ oD/>&aTV2~ +B=0h 'U FtaaP窞ýgjc?;:& ZDSt~o6dH I"=z c;BYR]*جR'9eiA{mlR l00&݂gq6մ?sMW<5]# iϨ إŕ};͐rXB~.Y9=!K@ c~!h3p+`QߠDh0oE᠃p_~Z7b^Eb6IYI!(7PxV'!aC &DV,߸)MY$~ق)ϊ~!jUUV=cE *< >0 BW, el!_]VډHڅ2=Jڋ\.}uHDjlV 0;.\01།Q+KAq/EAǁzc9XX=>S_V`;Yqxc y+ ;.,"٨p7^kmWbRxn_ٔ?-QG;9OغÁ8L0!Iۘ0 Ig\&RAXOh` #Lތd(K`  դic"nR8v"ꪏ=WbpqY+W )U@hjTdb &m7$K͗jzJn*qZKl[D>s'㒈wFE"Oz$T98-qZ*W0 5r;k?7|L?(>tCkaBl2*׼Ҷs\; p~&W6r[r }>mz yfVFv !?VSV2նvsZoBlKbj8 S:$ALġqRAŖz@[$Pp;oP.E7,_(U`Ҝq=Ho+U}Y]mu?2#ܲm>Tx̅) HV**k@F^Vc5{bL;_hK?fJȢhI۪,¶lsz-TA_J-&ъ\x ֓6NB.4B%ͱ#bjĶxKk .T1q |OB%~<<=E)ˆwNS[{fY v!>Y~j%sf* \*GFu]Rx?pۙ_W,X'moHҪd|pE7`Y'JTW{Q~ŎeCkD%eN=$0fWӑ:Q{|EIR<$¯*(8\MTypM@$Vk_ץ-3G_/hTȪ@,qYs[K,?pɜʲ_&2Q}䭌O~2c@Dħ.Rş=mVx֘l,Q/=tcek3nND , +{#b~)@ 4YHR8,$b<  $xx̒i|#bon{!+s)ItVуrھb,ϙtXŒ]؏"`D5GVr}b7A/-2E5mZ]tKQ S\C3>`p}JU-zr!G ߩ8ո#"QYr8/mqbw) ': Sx7M?"G]yCl>*}z4zm'슼M毃~}I@}[صx'BrWȝp;iLooc4Zp-VʳG}Wӎ*]+^A-<ӌNtm>ਣT}#{ME<; EX& P+[Àdʼn`{ҙ `d? F#/P,W.CQn\ugoj`e IyL5g掲VP Ql uԋK'LӛQj"Dwpn1+a-:6ZfiZ`uVLGW+x)oޑɋqsJܹ}<Ƒk/? ,پ '~UlF^yإr! ld@Qb{X0}vA/<u+v1&ə:d [%ݦVG`pr/"pgH+ $d9`TB~LCMYϴ>sxxl !C] nT 䟣Q{x)&߿qRimsWp*lmYNj]y=zi;Lgp@f܃:& @߼mBRXf\ECi%k/6y* `̳#N*/aז4~maҥϓaA }z:>ԟt[,+ \RNrǤge3HƺZ5yիm̡-♽b `~ҏ[|Da/)O%J k0aY<̏d&nA|Gl_-fDQ+R&8àC';y"$z<2ƭ[!@Q"i2(+ߡ& 晹ll|ۉIh7o2ʊ)|ݦz%%@ǤUa?F+DjPBFq=8#;kְ$ݼ*h{M&bpevo>c<-&w}9u;Νݵi8^|l.`2+"meYi9@G{yGd fp8re6-2<{qgv"j989 OqV+jN “œUpTv>ʙdO<Jmee(:r/("hky(V&|сK_=z|!7 gB~lɾzOu1A|x=2jH1Ojnwdv}/8Iwf? 8jhEU+C/aC/3eb ν ͹ ˒(7ckJ(J{$?] % bW +uO]1:$ϙZADx ]vXWS𜫭 W/wpqj& 2#Dm S!Yx=rão-6vE69.b8z\]SbAgҩOSK \wPc5P^v)񙆪gɋjCY)fLZוd@A/0P!=K3&ψsahxfm\%_IuvvEUFrNB!:^_$ n2*sҴ=P!u ]0d`3ư5Xo,YVlN鴭G]i,hb$#Zt6g xo5qi *^9; AiF0*30 ю^ )%=|CNbAɺ| uj{Ko2ߖ3MX0رSLkZ~C jDz.o3H ]°UFEc6AL_+=OLG}] XoiUE7)\W:g{v/98K &pJ Xx:?U+kH0<#O$S^Eas :},SYycqQ9 1-qn,Rdg 측kǧ~Sfg'mS"Pf=6MD:u:2(g^P$j+ L;|UcorM%BοDё`h4 FI  Of6%"b ON׌֢Iոbi}U9L6nG NV0)Gb #7̛:Y7f55'$T5p]s]D^pӴQ]i{̫=I&E`'<z3ౄ\[Xgw ¶JX.*6X D]/x>´]>شY"4t_c眓:xiI&7`vtAv+=*J'mӵ`L/)W;>Rs+ex9;gOCr@hG3Է&6/:"z؈[Ѳ#]1|R l vX $ZҌhc0!D_)Q͇1˃ m+ABxr,v[%6``u-he5U V=?LVG9vے`>/<{T2;1qhSf3 sF%Dԝؚp4D" Z.3RD.|u`BrprI.ӥ_Z Eہ$D,'7{-·sw(?r?Su뵯F!ϗئ;\ȕor?+잝8_q\b6 5w:'#$9P.J*ܒvMW)D>o OJ/'2868@mBDmqHgo!D>0rNlϚ><.U+svhKx!1:ŷbmL kLYZJM5VZeP#Hk|U+WA N1-sH&/荬rNW/vx&>ƒo\~WQz*{7?Qk4 sI6l5JSG(WLKZ{W_\kЖpgH@ݚco} h)+oݛ`Xn"~ Z> &̭\ NK17=Wy 6l¥Yd>!h? 0!A2H|>djs^~I$`!xѱQ'NO/0x_ggafQ#|cx{g=Oq?7灸pTX5Afm$jˀOro0oe8bʒ8oNhʪ)vh!S01ł%vm9 x rQp -<{,&Dvo;Z"aX(}r&!yʪ E3p\mi8rcKu"% dmJ p[E5|'Y7e wtHխX>hon-pwcJEaMŷ_@ e>RG^MG W!J7Gcc3H5WQ{f[?xt ɒ#*GO,dQ_GEcѓs ՚Atj8 LWΎͶ裗 kl}[p$RfU( .:n7RrpO@yJyuūun_$7IJeT2~ǻH“)\XfZz۱^ 5M_4rRJѕKip0t& C^t,3\Û6x&c{ئ7S?P9k(D!|aXb?bztJԹ /߇q}_c S2FHوE6cI: hSla'u7`7횾[YHg37͆! #~Xsњz3u/ibЃcuT2hb3:23NAlּ/ahcF{TI4H~$ĀVR9Fg;XȬc3eA߮e=?Ih gƑZb(x.aiO?t b̳tovJSTY5:a_ fὓ;QNv!>!W}lg?(IhBWpM rQ,@@כּb7lm+XPؙjc?y;_̫k0ZPAl^~9 AϙH璤l'zLHRW6(v%PsfRDlDx'=С)Ï0ǟ˂-7ğwqfۍaDV%IՖ c% yp)]J4F0M]}nSD%XMC>0!24:x'gC>jj$7Utߎ9Z-"~--Оu`FwA)(.owX14 ą^ğOzib8do pܣ0DhŊ$RVz2yg(a 0Um;:#o/5k+Q!ڸH,h{>^ Aq<,r^3f({+hvg+UQ'gTYNXAJf?x&-~gLō#ZӦA2/-(BhH])Q20