sssd-ad-2.9.4-3.el8_10 > 6 6_6 3!pQp)Tξ7]mtZ`f!Mj ]mtZ`g=bBmHzkiSQq9X ^ t`ċǛy[N ƯM*D$jo#A ۙ:{hGwC}gz`D{H䧷lˮ)23V+Y"g`tҽN|[a+"ꔟ3(f\&,SݮL̝. W TXщ"Uɥc\-IkˋV{~EaXD vt!DA>R#hX4h_b2.؂I0CE@d,ND#9\֡{LJl.ڝY@ʍ4*'R  f8K_auNvg 22Ɩ//mhX\#P}ߚb ] @֚!c_%a DzW@V8 Yh-՗3: !(XF >pE?d   5  0Dagp           ( X   LE`E EPTY(h8p9D:hG( HX I XY\ ] ^ bdeflt u, v\w x y O\`qt|Csssd-ad2.9.43.el8_10The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.f!<ord1-prod-a64build002.svc.aws.rockylinux.orgGKojiRockyGPLv3+infrastructure@rockylinux.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxaarch64&'FHK:N>oQAAA큤f!< f!< f!< f!< f!;f!;f!< e+f!;f!;f!;f!;b3378916488d7682b0abfced7c3ae7e8dcd5db6703ee6b7830a3a9aa7975066e4bb8a8ac07f44c20f5ccb9e4b752221af678b18f113d5d47fbcb0e3dc2a811af8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9031eb7f743747b2f6c65866e3c83ac5ca602b86264dd036d6c81e65ec307fd2fe5f6c61f6621f3761c9256bd8d9f98c7e3224749f908b2167348a44ab76a6a014fd7f0662cf41c7b180167978349f9ab1e32af29b88f5617f3aad4df5d6c4313df4b01b3f7a0f77bdcec6727b15787aa846c98676962de08170192b806a47ae98b../../../../usr/libexec/sssd/gpo_child../../../../usr/lib64/sssd/libsss_ad.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-3.el8_10.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.9.4-3.el8_102.9.4-3.el8_103.0.4-14.6.0-14.0-15.2-14.19.4-3.el82.9.4-3.el8_102.9.4-3.el8_102.9.4-3.el8_10sssd1.10.0-8.beta24.14.3f! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.9.4-3.el8_102.9.4-3.el8_10 .build-id5ac10d70835effe93a332f66dec4c6ef7b1110c72f69852b2465c99454c3d1f643b07ac28651cflibsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id/68//usr/lib/.build-id//usr/lib/.build-id/c7//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c72f69852b2465c99454c3d1f643b07ac28651cf, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=685ac10d70835effe93a332f66dec4c6ef7b1110, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)88PRRR9R:RR RRRRR RR6R0R$RRRRR#R2RRR*R1RRRRR3R"RRR R%R7R;RR RR!RR(R,RR+R8R5R R-R4R/RRR?RR R RRR'R6R R-R4RR R RR!RR&R#R8R5RRR?adclibind-utilssssd-winbind-idmap2.9.4-3.el8_10utf-8cd9abc05e172b1d215229323d2f66253fc32b2c10836c7320f5edd93e9024e87?7zXZ !#,] b2u jӫ`(y0@рgoZx@BC 21ǃ)H98C?"F&"TťP|Ek#~Nz?r@YBĔ mk]aBx͚^RT݆وpYgD11P 5|Tј0WA\3rF!M0d^䧚6%YH/K{HzQ`154ȅQӧ_+ygk`1m7Sw@]kazkș6f^͟@mP.aI//l-nhf{ ( |2"$QgK0 Vu'E:A3V+LzZ]9Yڟg(hot..z81C{lL2DgvgTfXpGPe)"hz .=erh 9E8R j nϯg^C6\~B1A^o6q#z9( QM=zg¡YH'sG}A^Y@MlmcQro!mP7Z'\VL(O~ ,S2W'Fniw0!_цCxf;w5tdlrU U}DK Z|T6SQmOTr!M}Fle)4*x!WnOo( QHΣdF,4֊rWJH=4C+ td~6>V%lzT-ˉ' k![z7!86torAV-%3/so s?ƂbC{kƘcEqH On$(>N` ϖc؈% '9^{)ljtEGr.Aj@3%(Kw( Hsdf#=IZХ_9x|5$o -D:}3<` 8}1Scמ[c֑,Հf\U[-.O:YEیjvf^??OCJn:Q>/DN'PgۯҪ4/:![/*-TG{&d6Ho.KYKr,UhWMM&(a./X!/o̠gُ [âJY猯:H37e/-9X֔8@k[ Q4r9@W`Ι<u#Gׯ˄;$:͗ .)h`) Q&S{St}aB\%ڰrLY-,5ǒ_ pū "srI0uu31t%|OH?ayevg9%I>c11mp@u4Zv87 \^xH Ȗ@XoI+e6/jM#0B%yz}e=%rV/=s<T_Q|>HPMjܪCj 779qh fN>7{&D;w)?ov)=t""_%@OA5+ģc5/{y [/I⤒3tHXQS`2h,(*#np]x5z b,4g7 J艇NUb^nƚ;<,Y)kFuHx}9_2pȬbGzaAƼiXS+`w6W62ʑH׷:h2+zՕŋy -U(I Z,eT}݂f{:ly|%b}Ldxn6˟Ph)u&5:j;gBP@a#"'f2qY UEºF엩e&"oqo VXKGT ~ 7#w֛ۧҮ *8b(UQ]PߚK! h<K1Y#.@'MjloM?O>c]즇/rZQU!,W-HOPյ*e*k*.8?>ˊ/n=M2n}%]0lAVtk*aI`f/&V(/Ջb.nFn$“ˋJrJzBM Ok%0X>\fGA:[#puݙN*F^}^H׻7hI}crmk&JWl2_[obMBjY/u+?!R]J"d?oפ5ǰe_MWIo"6` E^^: y=-n$E7RSUU+- m ׻$(^RuYK\HN?Aꓓ%.P`q,KwiP;_+NAd(N7RW S,M-JWOv/m!Ϸ_R2R1od.:ȯ٢].$ew2X<0&?Jm\Gr`GCigP:q'g[}]Bif"AIUJAl610VE0WtB?{F@Fe'Փfc:H4B`O^b!vk։EHB2'Bjdu.8ڝag] .^@Q8 IEZы#L>'& u/u] +:  ƃzx@s:]s&hwRMf &!oؐm\hh7=K e@GQ/¯Pk2; @g< ^!:NB[4E%2hD#o^7.J`l3 LdHi;7 󺢨1~Ɓ9/w駛S!h o2Jۮ?bkئ] E+Tl!S,/+]RW|o(6zEs-V1f9P)+9L՞):2)FbB(\5/d wz[Ǧ gkMp0mU]8/=`n' #otdd(I%R9]w|Q( Rwr:M+CjAg_@1 #17Qya QB͝4eg9_Cgkely|:؝K$7չ]RP'`:#84,ijB+󂺥Jf61ݨBU489lCiLJArNLJ.ӿQ"*{h9M O@O`/ ixd+ˋڷ|nzPL온B/Oզ2 CCb;*Scuyw>PKF7 Efi_ك(AM >Wp~M eO(-HDi[ XVp˾mK V6j2rxK%m xsM2\/+". ٟߡO*{NB)^/[niDo8nANkM&7} }*@m )O|{VQBY" ֛˙e>2>+DfqՀ8 WW/X!/эf 2Ԭ<(G,r^AH7p#π6C4:2]pNw9TUCNNUxzM q9 0u:"Fx+BɊǰq~15cQyȶ /cQ\XƗj $ :#TFf*#,$, F=/VjF^D!2A$W Ok 2ϐ+ّ:1{A2ٞ A7޼?3 ;Zێ(46ZA@t;8 p>3.vJxK}Cǘ" PD6:${8+ɸur8^Z{H 7B-{WClCTZ! HyǏ= }&T_[ cN6ߖleg~9 tAdn2E./"L,,)[xsXa>ڪ)B}cg]-dVR{giVy։=(Y1C [?Lzt/Ao-S0OP/ψM, Y{%>`1쩧pXBٞ~#CxlwOe$s긫tuGԦ`1g1!M{?emM'ޢ ͜X{SK=.&.2F8sDžtu>˜ބ ,34.D9.}^z! Zz/7q]bqZ,Fkgඛi;RWߟvo|qV΀n]w5 &v¾1Sg\'u=~y5I4%vn+!LԮ1QmJXk\a^$wv^P%YcP/ #.6nٹY*5F0 \r-ɽv$;sIp0m%JL J/4ŝ WȌ?nD)Aͼ٥7RGP3rO#b]F gv:@u.p- ufDb>#BB~jLgIe4 =]hF afۺ Y=CbnNNM"lky놷)tonuԂQT.!T~f2[2m6 N3kVZÝ%f32t~Sk.:7DNŽ.EN-F9bcfi DjVs긘(s{*8pɱ7ٴ1h?`\-9_St!$oG X }UX.S(V7h_o"M,^y2ϳQdHD̪/<ّ8iGU3MTM\. ZĂώمӁy-HzV z` XYRNk  &&QҚ`w2NA[P+)XSܵ>[&qBW`t~2 P9IԘhv}B堪{}>mv eܫۜl}0?zXW1RG%]wbhCs*9mXnE߾ֿmY44JwxGQcE h)Ih&X,f9Y?:v"E~ J^L9sF1vs"w^6aϛ ,ivRV{Ca㈦G%!Pמ}_f~@7"JO@B'BYZXEOG$Gr¯&|.TwsL^4Zmi=s\m-mQax9;cͿ_# ;}\eNuEՖͬEb|f߾wąl\RG*P 'IPU"TP#YEQɋ+PP44`YM}]Ӟ`<*'Bi oIBM :j|㰵9,m­":h`3-(mnv۴pOtXPk)h`[\f|Ob/P#Xc !.-Z zg,#}__eE} 'AmlƑL9\]UXJ~r:àssmivv/j { q&I+ B6JUޏcuYu(]4z?Δ 1viGFT}ՈniKD|I~N9e[@Kc5/xXw!7pH~ȍK*iU8w < 4n~3!VgoTH"(Km׵) WNrlNQjC# i2Y!VM9O$9;E j4tX_* Uw_Kn欜–*g L OsӠ;}l@L4ts+4=l"8:,0q||~p88{>]_P<|3ǨlQ|=udaEͼE z,nԗ,`WIIoj+#`PCKǓlJ|( 3g/D`?CY⁩l{"O+f|m %81 %:&bn;N */m+^.CTw -&1!Tٳ!f]=h&\3;&q'9}NkO*9i?̾41;,mǽ30`ܱ*ccMu@|)AW:Kc?n}ӣ#=7:̣.($^`A(e{]Rti?uk8^cKNlfnp')PXr񙠑>/&tҒM`sɐvW5ԾBf/|)xlZ1uS<>e̮cě-WZK6g"$sgl 9`[ݮ^$mrL<5TwomtO֜8TQF/{6>d %_B.j<v%W;NEzJA g0zuBQ8h(J(Kai͆va!bvS"M=:n? BBwdp9ܪ-)]k儂MFAGc&f| BH᠝ q!S(\FՃQm=ó ]H6~Q5{Eй5[@k) ձt2zxoTCK  @г{UbF;GrC0|*\gJvr2;BAJA06qH줱,pv [4=;&+Q;erc6xIǩ=(`,{z9LQ.S̯X^QsLT{q8-.{#AGyC6W"b_qe)'K'mhz32b(hk99gxo_W6,*=t=vOR(WƫaL\M6X%R(Z5RAKs+¹q  zĭ'>'AvگKTϴ*w4n`G@!A6xFpFSVxݬU(["ݛ=2GVHuحzĝZ@4YHcuey* F =-i[tmLkbEJ0EHȐNLuN̴-Ũ$1P耍։ҍ20SI91fAn'EŶzZŀJz~!}W{ԋN$=禂+etT[D=;2,vl6砋;V5}π Os:ڋ՜sҶQ"58wv"4vPkO_ƛ~>%W$6| j)T'j~Ɠ JnOpDĠjۋUKbK فDG,r9`6LKɕDء "I [b[%,:iIoa]zfd+ 4J5jЈC3TF- Mv:u;,P7~(,vMSzg47{5Dc'*BS'ڊOANv1PRyhEɘbFn_K]݉B+YPƪ1 \u>"Si)%*1|dF_xRA r^YҊENE>OkU $97^3 ):! >v2Kix!p<v{wOF kb&4΄d~" I~D} D(Id90 ӻkcoc50̌^;71dklá֊u*N)i9C,kߟMʖmU$YpmMyY⸩ ~>KIt ޞJ9$ o\VE荲4}Cn#>3}Ì<Ygh&; -Ӑp:uCdfoJyֵԇv;,)fHV lo((c6&^]ۖrrOuAth#62uh 2(7z")*0A`D,!vp:)6QI?͗8J76osqdq%eixfQ#sz1!@I4; u?QxMr-<+4A$ GpH ?OjY#rUb [ݵWJe'B冸yR X܁sj RP-n$8BCd)s )) ͜{~,Pt"1E'@8ǎ~=}9AOJ;6ٝ 0"ybI QlCuȺ-M(FGc?fFOX({ 3>&E±)$gF]qˑe O`lTa]=$ԃ3Qi9[ffX%}#%a`3 yBϣo J$a:x׶{U\C,?$Pc 46\B㒢bq۱\ G8* pD,!x*Gv]i-nڼTO*< +;vޞ7#Elx1=`R  o 8劗=  *2]!X8/I\Wi el 0Q73x$+{>v.1Yk`csE/F^68+"A&ƹ隨[srfƻf <}xzǢ _jÁk9jG{4թkAW근D o .6`-q#_*gSj ulKUv|xa,AV}NKxk[}ֈyKL ( jLF{Ԡ,gDRmj?*IOY0;rVsƕ*=-EKq3!=sjimK m!盷/{xll O(e/t!OPt,Nt]İq; dO M(_~Cs.{gR;rIܯ _Z@*8kMs(zH\=`H4 l:>f5mt.meӅȨ.kw=)b5ğ@Z}/tRe24/eÊb@th=vB2#3運sʪhs6G]n)a]"\jBh\ .:. d/$ZeiVװYL ߎyi{GW ,yDAn±G3l[Rd" odnOj n#|hiX*Pg :\%T"B0໠OL oG)_l<\Z^Ux߼B-,[fv!ȁQڄ*4T% W[4XCK0VwGEיzΘ M4qD&$ReC T?^]O}q28rcoRQLwA /ǭߑ{}5̀ I tS67}w_u$4b?gy2rޛ&K@^hR"^KE}^FӶ1[\ E&+!~i-شJ &TmD6fQJuXVпS؛'A!AaGfQ{džgu|FČ[!;^o"ui^U.>Ih^|f'+i`NⰏ # iUOZw99Z5L2D^ $OjPR9v-ygQp;w ;aZ ~i4qgxCIHLWusy/缲0&xS)y*3h$,LMk$Չ }&80V" \^mR̃5]ƕ ɍVC=~߿HinϚgV̓@+rH'e1̑b1֕_Gj BI/qt!5 aYL׉-˧>B 1u')nyNd@̯dvG]K$w(ۨ:lO[uȴzH>G3|b6u(W  K֘ t:QKnGn\"wb`xpMBL@y3?͇F$'+EsEǣ3H\qಸXL2%\'f QB 1tRW $먶EAqE EB~k*ߍE"Jsᘺ YW>"M؇KLSK{1s|wt"%2K2'Jt ۿWꂁ!~~+#TF"o+SqKÊA9гZrL7SX7z>ȖxS,(!X^-_HjeYv(;BYE |0e'ڕC'v<@-,:^j+]lˬAaBO84nzd[̍oߴ/4z94)!4h7Glf|?_e5zoC*o)CLa,\I1$ Ҏ2o .5Ơ]]7=Cd|ǜHi|V$D22y5]P V&q#17JjU)剰DѢB&%({Ǵq|Ju|o oJ0c)NKjк$ KnXo^[ffށVS_/>׎Zϊpl=lm3Xdqe^ ^oω 2eUk#- $&za\y F"Z [$g (i46qpEjG]]>O`Z2g@ @9<e8[,+K9:,X%nJӿ8n1f"ӥ qt+Gq˝~kcQu _ nDv_z El4zd9 M2Y =ˌ7DwNT}h4A5:f؟a|:QkL͍(Q4eQ9c{G&_5ZŊ|,"P|vB. !{i I=>wPΝZ1W$8#^l ]{&-X}A>pwy |#1MZT1B|-`J)#'L% CU5.5t7.Yr_F1ǹŠQR Pw눏2D)^> fVཱྀcj{mY9ƞ~tg8~ְAJԙro%!%7:BmYch`zGwnV )_1Hc=@oH 0}.vsMU*QBf9[:=_<LaUv'9YCJ 1 ^Hp9쏘p,oMyaz:'1${a#G͕PL`!_AFuYr+ &~H v B@\;sߐ{Ҭ^wD8U"c~Ro\G^p,S8\LD1Ʒ[UmMVn~マcN(w?F(7rwj/4kT o>MNh[w7\$opM@>2: |dw CIT+ kxRR]Y{Y2nn=ٜQQl%nmC^(%!c~QWrLNQڼ݊VS, }`kZs#!<+y,Q6CmPa[c"BGW%I5>yMH|:9;`1j#-zYK, 1]FFD6򒌶܊TᬏѵYm-#J_ )x/&d`\hj W:Ob5L:IY8g_ yHf*r[JQ|kF+7Xi46JdIWB PV18cU7p?^I,fDٶx%3)7Avu%s[de9gg~Uy_T"{4aZ4R>`᳼- ?;>1-9[=M hL HDǠS; 'ݎ{cqVuuRnEC0gp?@ [ f?S/7g@NXZU7kxr\ly@[KޤkW^`` a?]pjn8VL$fk\M2 !ҵho@*7pjBWܯKFXSfyΘkϗW̮~Bˣ c EJ;6mD'Փ 5R7AO_~ ɜaPتʙeJȏFN~>0x Yf%c;G]5W)MN@ IXm8o{ t)z @9W'R'n(y^ \IXW.1}o~uW'0.)zR$Ԧnʰ|z2Ĩ eU%3hlNps/ΣǪo#r[޵qǴønt5 p&$})X!QD"3(BsnF?,^gm/Lj2nU!֍Dc+ Bp#̯AZ>Bd\T/oˑ[Ft*X&pi C^g=%NhܸiTݬfTBcږ|Ed=' g>#40x<1/{9r]G9~V=eAss^^1,$3[De/5e4r~r6)0ɾ5L %>:C٩GߥF: B|rc= mN<{X}b+m`F^Ҕ[i"m#s"5k%ΌF5C1*AsT,0+hq)]ẑ ɺ.|>c˷1v㷒| Ӝ xF8|G/k ļy| [aqc[D jlvi@dgǂY X&ѫX7F>i\1]'׆*[O#VQi!ɀ">3Ec[ۄ;t,}Cm: yj1~eH-UGNEeP:')C5&J~w_2dTb{%Z1ge76f@QUefK=HU p($ؗ4Ary7)х`79^qcHp\_xh5EN8uI9b9BmqHH9k} F㠘{߇qYȂ޸u2g?V?sU(~!TkX"O6mzK(")cs6"W7YP *c+7%^ u+XyuPC>*ӓ/d0@*Ls͎0:Jt~܇Yp% WcLw!- \S>1d_sq`_GŜi4TE`%3WI &+ L"2OH|oJ! WNVMM695`D,*e^R+Ɠ?7pDc>+1ZW*38p}OvHr,䠸״ ݭ߹bY=O~}IȇnvHU )ׄU vgWmd!/Qb+Bt^-x`r:ˏ1ývWq:g{^ y:|#-0(GALkIn2ߟ:|j$Tc[P\:Ì GF˘vAyg2MT!-/H>N(r5γXhixn=摃(ṋl{iLkGT#ҟJFMR -\ HL2a!٥ɶ"ݽek`@q J{{ ?rjmes219pJT@ȚDaCxu@Se*<9R^-*ңHr0<@_M\VlLGa'I,AJd|jWvK7u8T1" YR8`cE %)1DZPǢ;Ąݵ۾7ͥƙ[NQ6A 3DF^zf_ofҩ #,:z+)r7ɰ[Y^MOО6>J1w2! k^)nTX{@oܙ ^D9/vX߫ 8Xȷ!J'!e HbQD;ymQFdgHIN.+2&A|ZlryƉQj'A+Gd F$Mz&j0I\LXϤޓѵgV-"p`Uk";XAWo. n&Sψq!EɇlwV5d M pN4nV*Ia)ۮmU  Sq }}VM"Z1g-mr$)z\T\NL|6&+X}ߜ%Wl8;RnZ%n%qz5K$Agw2M\,^<GZ1]ꇺ'S&0bjB6QbEKޛV2>S~7k*%E͒L$xR`TMTVXBCšHLSe:_PblH  M:rXDN㊽m1tx`s/xr!9Ԩ|s3=LO1G3!𶜠2'qd'_Il+e)-Z\fc1C1~9"' >=̷ڸ #+i~^=uf2 ` C 7 #EV{OWP&G }aqK<5/c_3Sߩv 5/qq&_T\*xC) H> !E|V'fs_wȉ .-<%K犒(!5tG_pGp6v)3XOw̞2-+KBr`oJ:tE_0#uwwZ0z`M~JYKkaю֟<Pi-KpGHZH^=*6V^gkI+A5C8tKpp,KLJRXxƮC}MnbwɻlIq(T05[|񼪭xo0 )Ff]JBx+tL6Cu$AY9-45^z88>fG't23IE1Fxd>Kz#k鐏@W&scfA M v0rV֟na@H}lm~OW#nH6hY݉Ht1<9br :G˔`br;,l{ 4L(7Cc3ѭX݋٠R\z#s?orz_rF1_l &l4G~Tjቑ9Y&jIЪ2wi ) `Rp֛t [MRSɗJz"G++=,'X MmAs\G[w Wř8zJM32fP% B= 0ųjӜ \DBsVr)f _:tX0̄+/c~cZ_eYUŶ0!]`vI_Mk$m_8~7[* <#i, 5,ZWoC?PNr J P"c-."FZ<05oy=}0^`%[o_Kވ8/SE+#%|9ґgFg&P"y1AJ*QFnZyQvMFWH~P:ѸIu1uAt0(hVƝcq0XL;(&1P+A16 &dlfRcNEcԗ~ ut%1w#miEo7R M-5W]Tк)E1[ WgPQaŇ/0!ȥr@r޴(kuH,"n?EUçxNo:"FTv}>ou?:QǺHNPȎ+PS^b(%ՙPtcT΀]̘/exfDEێ=x5עpdyHgs:N~?-l1ˎf;ͫFm17d6(4W}-ELh;B!v!I< @Cؗ\EáH1{H*<|@a:zCɘMwD l/\ N5"9&C}xLʆ 7#͐09k]MɭB-/ z>.lwH'Tؔt3|,r[:X= I1yA}-p0wV\0mˊs87w8R]ji}ZHD3+'οdN/І. y9M_7 z58jm1N?"$ej mh~fxBTzRub\ʲ?;͕K؆ΘuiJ{C϶Q;-S jwn/ }y4ؔ=_Mo(T:rI,Z##oTުUj(}wE)#y0xMn沗۫Pg:TL#C@1($[ TZC'vcV| |C)ka؛.`dT*v-qp1x::8?_fcjpGan2S6P dzctYTXK@$ìL+@gД-soq_;.̹qd;uL×gf/ƤB'IpEL.:Pim6Cw)3G2L%I1rp( PL_|' L;&A,q:-jV Cv;[m"ܜL!S+!/W #5!p-UgԓV.AG 2#kFRLސKFyyX,(Ң{n')V&K1i, Ejat;4:~vnH.}R=:ŀ|yq9d%^ڥTG>ޢP8i*ͰTwEYu䀤Gl/ F.,?`6iU-q㷹WT84#U;S5{y&t_Mp9Q}}A9[ywnc lRdb c\T]豌x:R$t#ۇg鞆9S^25 ' bf݇5x5zr_XKڡ[ZC]WIb[#1aԷ, G6ٶ^-\Ql&?{V&oPmR2}k ( 8.._îg_ňrO*S;\kNGU67SuD3.ڜ<ܥ*w܃H:`c[~lJ:Q 4TD8(˄af]%c uP A]}Z7 c'ȗ!c nNP=4vw&& ԕj/d_'}\v)k҈'nyn8QKEV*-pݏ@^{Y"9&$fYOn1S9 bY/\B<FLjHi+⾛Jgw' )[b_vdV4L |SĹ`[V. KW:wCQ~czT[nLb\^ Z\ 2ʄ%x0%~@vE.ās *pwL^~C]3>l\~oP`NDDC * Br45.VWhxW=a8;qP*ÿ5zWֶ`='As&<_d܇A&:vr 9pKZkNk&^bo?ȧE?f](wB?Y7Y 8X^*/ֹtZ1uF%e*8P`x2x $v#Y|23=LmfEeG :DH pADɼw=&f𚙉*$(pC8@]i`}kMD t+^{IrNDO 9θ ۀ2ո|Nqyw,6BIZL~fz_R:2B}qxT[32I$|Bo6q֗C:Jgz)ӻݸdhg=.{tx:KTD "4iz"~5pWo5wNLpnDy!ie$HOY_*חP3: v_ Y#ᙋL4f`ݤ"2ҋD̠=t"7$S@oU |tmmVL1(yf9lC@hEL6dG/r<Ֆ`ȆPZa8TlvrM![zJ[h؟DZΤ~y"k!W󝐻bgrd.MQfxu+|UZmvdFx(๴ԓ0.TcP~<U 9PN}{TbH?맱`wPSh~H,Ev/5,yo`2wqU]M6zad#\ n r1{6ԉ=1b~+Ug'1Y"Ĺg?K,:5Gw+Fh#,4U H85 \Sۘ,t=L)5/ѹBP åݚmUcpuoHj;He ".-Vw@X'_z{2J#c ҏԯ5'"j_gȱrDK]9R}ŷfNeI?.k UZMeFiZڣGM |N}5mnGcE*Ҥ)Pf ٘:oY:et8X TR ;ZBt"ڲayq]V\#Ӥ1 5=6F%E шs SRto6BS홳"hCPM.cA]m<˳'U;Tߥv<}?忊$v]; {2Y%@87P*;oFpz95ߚY">x +P9HɕpgYLpTIR@[xQv>8 ж1lإ|Y3h_\g5K&ԢYlh< =A Tgoi+GNΐ:!|zÃ8MD#'&„xvjϔ4Rm `Չxx4D̒45YxꈩO&2.ƚMX= ۺ|,t|j*̱Q9laWux 9h G/<$pKlqZaQ Ï0u2VkzOuiש:tB)ޗ6Uj{o޺w<9;ĜBOb"W,i+L9ӱ^c{z^'m&^yZ?D}!;ϲ0ЬeJ.쯛zc&Hm p N5m<]ɗ|!o|N7̗ /ЬPK{o,15TC]MM6~N"&PB4P" bn|#:OF4^6?"ӫ<=RU~%Bv_ ֵ"Efz=I>>Jϧf9](?$FXqXkد|3K4]m5q!7l1Ga;6⎸*&0˘]N{(sGDk$ `v:r:ծ Hp^pv:^8 TLӋ[}&")|#L/&WE؄Apfh抉AҼ:X 0LYc${^kM3]y)Cω#=)Lj'm׾%-?,:$sN3UTDa8#"=Y=<`LUT+}#7Ȩ3lcfm\Ƹ2iqO#֎|.}Kōa%EM4H R6;k{/]i)P0bxZ61$d% Xt$/*͍a(|xSב,[4sa=o*0:EaK/u(2 ոj4n]j=zFuF794 S'ʨݓ!fڀ \a;iwO ]h6og_!^pl{ *x$B ޡ%`ˣߤF{k8S4@M rG'cf-woxYf/2Ẩ;#?>J|_J5 ojo"`6@QF*$Nb`?(El4)iqGU=LB)`qu"z )k9rqQ RQ#$sa!eI.(>3ADO wg9κԦ,^ J)k&zD(4of=tY^!/idn{m׀=93q'\R*}1{X/47t\Oуq'<Z_eM?4wo_ȳ"/DZ'U pl:ZPXWp;>.1xT2 lwho"j^İ߷oz"_Kll@Q8b)ҟ)˵9ͬz. Q1ElݹG8fZlBwR0uW6_K/4+ZIi|}o҆#OGY,ЮUMr@YC>Ԓ_};xڣ6+ǚ)`{u!2c  ?˫7yD j轎,_X:uֿ !Vvfmݬ8ԈP|*Z U*1YdkSwc6< q'T.O7CjD>1tGBq=uU.џk˽!qK*(f(Gބ iA ZJ1 ՠ!cd<@`:n,:Z(#$!`$s $=P^MkʤARm79扮lW/(Dኲ=f 4!ب)nhM6F ~}VMeғX#T%#{,ΐ6ɒ'>1-A^H/uDĖޢ]޿a^@eD87o FYZttAm(eLֲmjس-paW$R} / OqO3:%/ծ9譟b.O~.+[ke\evhzU)ӂ|>c٭P"Qa5|-3dn\(V]ZwP"|= j3{V.C6hAy-P(p뭍hwY3-qR0 SS۷mZ&]eԡwRd3Z1t8o]srO^z\t=Z a`d1=ƫΕiBJkzKN̈́h)cWuX>ۚwb/3)7ج72ƝyVB?8^]@%NH ص^OP/D@3ODzA$Ȏl5u)|[ȝ07+{TEaodF6k-XZjVS-6*賰3 x202c` x9Z.Q֤ܺwS!Iy6>*g]~z|lYAVPǼ$Rn.cQbGr2*:Ƥf=8D5]. p^Orᗳ SʹG?7.y˰jt PJntݸ%>z  %;Z֧l=55GT"b'"ɩoXW6|uG:kYUɷDt؀&DIu +vfp-;YJi,ԗp[g^<iXB&hrCGMLy0 -Ţin !ns]`4E |`{5/9^I}ӗ@\QENkVHKV$f Yb3c:Ācm40hlWd .̒r/82 2:۪wb>$G7ړd[׆xgJPOVw 7wBĨKm㰢ojo(Fʡ9VΣj5tQFrmءv #9`8~ѱJԄX*NW2@ mI`1 A;Q= h=Xt(O >b03xPPtohӔze u X) PvrսdYv4Ǫ!Dy.?>]#|1fX'auT񂶤|n[qG70tb̬~AJo9ipOhġS2x'L.,].yԦU&#؍lBJh&jk|a\?!ıؘnew|YSKWAϭO@I$9C9'?q>Þ<+"2Ei#:T6ccOa^P컫?bDLo=lYQ"KkW8lNAɥ$Hu(E\$MmG 7SwHy?S^"1 | >Y?Wv9 1>&o?#rOL~}f}̚ CXD@H((z=Y`}1L[W RUL{m Qt XQC{NdZ[>TwA~0#XSOE jK߯>1pUS4~х#L,WZCEʉ&<}FSȝaFXONHf%to?b:*S걘f`ybuOdrƒ3uJVG|nLD|NMM yC2RvȘL^VDgs,ACW.V4?,K 9o1"3B', x#/r(ttXy]kMzd"Ւ sj0o,.%,{, $z+]3bsL:v>w=9ύvlEES;Kf0 T-laa.˔vA|qi/W% BV2N-2!HBM[cj;h gt-{g#jw(N.e#^m6~ݺ`|q%t!uC}=3ԭ=.=돩T-CG$וm'&ޕ͓Sot8i.!<8.kOJH%8 vhKΛʻF ?;<Ҝ؜,Ε=QoLH#ۖL(iʞ,4  +U'spg<@$t;[c3m0Vyi`oDz/ZI괭ȍ̠BT{y+KUKiwDzE,Z>B2@W_&}k3qVZ;[Oyy[1"ɹXLrWE F|ERydVIGN c7'Jܭ^Bȗ sp 4'k@qT vr3O $se!W։peȲ̦k%O]ۏMUt%U:\8Φ< :j\[BHNl#qBc} xcLJC+}]u19/ڔrʒ)mn8e>򰸘]$h~>J!qDAʸtL,Ǧmx*VnG;0I?*UmI튎@ru"! "ER+ z.3ugtLq~Bq{a1A$iHk_Y|r Hr>y9pϣ,kD%d mdŕ7PH5CSJS:֋4S+l&Z{\2aEJ=Y*F)Xw8W`0L i[!T &2wV6oAd7K"O?Lzs+Wa%ò0΃'/rvZZF~o݌]$7ݴ_xn {\Xz^9r%PΠ'}6#\BSqQ{ˋ_<tkD~ɬ:@KBRv)iH0.TN)8W͌Tchv(sk+ŠU'/{-F!˼sb6=dF Pc 32E˺x#GNaRQ13MXd9yR_8VRbA.H2isҜDMbu 2҉a*[ n/tc&'̃@79xAӀ}gU>*.ؑSE T\w}q黜9Gse[:'.NSyTܴ3/%~7Kf}oFVv*ՇѣjE <-<˽eaҙ>a TYCOVXͲ=T"̜ >puYgY8صz\ak "sF0Zf7aAPϪ5-9Ypbgg31!91(SJ#?;b8ѓxfRٸ~v T%=)tFL~6iTvKnj7;<+H(e#jBڬ^6Z%.h޻j{ tFO n!w1HRL;/WU֯v;rFX7ى`9vi(&y: rhFn`J`No(TU&,R7 %Y6ͭ7T_1J3&5%V)^okK&&tuݚ$+FSH) ћⱬ_lZ Ϣ|?پg'|Ka[_!$)/:3!٪WKٷl#LK؝ݶ*k; *4^gJuI{uO o §`:|o"bo]O#ҁT:V@Coyl@vQHOADiOІiJQIPNؕfbB8_89X=뙁2C9Ȓgd&cjBwnm<6ϧܟOC4А %H}80 *[@FJTIJqH\a}dS描q?_47ۇr2"hc^tN_\ǣ_2^MmH8)dȹ!;qZ\:&"eÊC\:KR̤R WAOCۼCmKCyD]2@=!jh+m5s]ln<|ԏ}hRMNMpv+p/GME&\~iHkQHxq#P-tRƢ q dą sY2يh^D ])ΜuU0bO۸?yGϱ*TRg8^HX_8.<Їki2Z[>`̓F$q} V _CQq^o 7ZoDm>oҵ{uqѸ>q^Zu'cϔdzrB]ts#%7JaÆ^VE ̩Pro@kzq*8Lp#RM:Am.^ #31LU8.#eK`j%5ȳf9PZ4oYϔTD!PA"65_`}gyluH-P#YTR<&QFHhsJהkD `E7s1ՎtL`3{o?b~qDVٝIH~iF:..I(JM+qU)a~b40۷#ފ{=+A8ݹ"k ѱdz15kQ 7KӺ'+Mʜ.xKfQ 'LOl?)%a&ɸ~ )30`96uOL&YF̨Tւ!+!2I7  U@#l]VU9'+hd{sL<$!>ne{.μ|>ヺ&u]*T<\[*i..3oWgZ.hX@+7&]WQWVWF7!;[bs09s΂1(I(Ҽk2ldk(ո܋%\[%S&AAx3 $u}jy 4q.7jprM^pn:V14 K4f]G`@fsfv$>`A] +MKsD h\PۍÍr,n{׀EG5w9H&%%f<-'BG,gD%hRgk _|^zb=-A9C5-UOhr.Q{$n=,I6oQهs^WzIj=/gW=D[N;׆DREmPM}ػ=])w|M9@5XmQ! 6 37t>zLlJmr39sr'fxt)iSLsTꙠ$~OAc/}vsY,Cˤ"OT+zuTz*0AKGY toKNU]aE+ %ٻۺ.:ljMyY-5lȋ|`o;MLTJk=IrH!Ձ;ӹ95BQUmzqr(cJbenAk4[hMY0٠{.L󵽱R඘1@>g03FI^=WWj( ,!(O<yCqn3-*pWBv:B4*Y=R-Qpg9${ cm5-:XM!6l:&$ '*XѸ8ScJ1`вb5_pOTj/)Oͭw#^ހai.zNsǂ8# $7kSM E}X,=/ҘIO UhOXPX4v(F|vj58iR{M+w=*)ev$`eD|`tɮ2kc(GZ6gVXßu:f_K#㪧yg;f4ڳ6',Eٲ~f0fQ3+񞈥} Kc/0%+HD,x4Z:`74{ `H*{fnFJ]U8bQG''NWYWfm je`[JOG1Z}B&*B_R3:;)pƦiJSǫi_[_/Ca2FHg\J}MҲsmZ`L~;ot6,ojFixdfwإDJnI r񹼷M9_~أ{Z%7دpv.¿a7g+hq+z}3e Gܥk0<4>jid6ݝoي#,0^ݏC<Յ +7~5'*bz+p\nɇaFJ?^53*&Xq \) t0~/|L>|L#Nymř(lO%@m+U6l >#nx$oאz9ƏL zBiU':H=sz9AWiO <"Ȃ̪ӫ?9 RaqXͻKiQBg̔x\YKuƬy4HdOYCb$!O3 .%S÷h)]þh(#J;M,4Cl X[pWIS޶&EwB Z@1~JQ+D7mN~(P6brCMS6M欈^VO_伵a1\:!>*,˝)&qY Zڳ+CeVFIRvO9@{#d-#ܒN.Ƴq@-ʵ:P?K01 #Q"$ڍ+Kۓ%bz޳rdˈ yS㹤PL(xq\m_;.$1 L C~o${FwpV'jۍhݕ̼OSg}U:wQCک~k\!QsN"-#LͶYNհ Bݒ$nz^,=hi϶ ].zG1WJȋПc$DF =:1WG$h5b9>Avd\q!_a0d28 ʃK*lA4߬G{$֘?89i{wjk" 2d8o/ٟfY{JC֢pal w4-6{u IIW>8 մu3|5_\deoQi[<H62cS[w@AAD e{>#c&w =ם !Pt[jLBe>⫀? (;kpn$2O|l_E{mx ^1n/q4򅱺O3"|%hrn#L}T )1et $xu7}-U:#x㊚ 'ͪ}8(qgsZIe}%+7g0}*);okT.bR01cN#{2wkַ^{4ڳv*Zmp6wR']DYתGͿO}E^?Y6S@esaJP`Cn 2һ'/g lF[P)k"tMt)衾w\N:#A=vVVJb^n M $b1=ۙ .^pY>DΓǏ/: ^E DSjk} p'8ɕOطXQ?FIsVӀ 'EO,&;X 3\{uc;+މE8Ge|~oHJIuf?-d~:I8~74 >Kny1zo?;ɱ`g֒+W؉tGl^V7@^ڵyX﫹tȚq'8YR 3u8ŒjdEyoVwA?H+#93@;#z^CKDDV6E_X/#Kqm)D['cz*xX(Rnx ^Fy|'dݒ%R¡&Hl唯M_!o3ίp=Nx "h|M-u7R jrfA00/$ iS[scruUX`B\q1tAHO "<Љ}2 Q-8^N2fLC"vת|&}4Щ_,5 ;%vP?P%!$@#k`Q! ziKNJaA.Đkks(}ʆ3:UM 7N4xƹw-q-z@"L2%jBa J>kWZ  Aq]DZɊl`, ʐL9)KTnR:u3~W1*v,. ˮ ٗe$>M2$ 8t[@ aWtY]PL>4!;X(f"<#Y$b3/R!^w{2;^Ԥfڹ_>-RpAQ1\4Q%:B~udTYs`D `;*&l B5RЮ_tq][ɋG1Rj.+ʆ,b*Tlٜr:>[cK&VH5p$Aq`Q?К|9f6t 9œ&85qYK*׋ély0AhbyRagmXO_Żn$utH)%4zZsV ?=렦M8c(5P|@U%j$dOԎgŸrhCYК+ Dy*hڹ掳˾VѮr"#XE yϘgA- X[I O?y 0S)`PgymNK;~bPYaLrHH| RO$Q']Kٳ"SSgDeL~YzOj? ysu'& <%{nЫ  ͑cH֖R. ޸-l.3]=bnǷ{iF P2S ɗK^;wMrJXjrr×;Rb`(ʈ&W2~+.hUTjjqn,;|~T&CDw.I570⻫jo'i!9L:AʼnjeLsb=>Pq2%>ٕ4FE½9ΰ1O"- M+/\ !aojyh :+6<VHፔ)X̕HOԿC}TF5: R/zBl\ۓ.B*$XF 7-mYVbT:xVլ=߂›fӪtNۿBMWy)Z$Pb)_Ȭ 9R']FU * wz%89tR5R=6+>GH6\wg/ 3}[{4bas/GPG\ЍoC˪>wı""r&AjY828V4@_Of ݫ#3̎׭)E)΄]!f v{F{̗׊~R^KŸx~dC`0tvQLpɵN 69>ą8Nb5Ejb ժvf{ 3i;)x9O/檻Aa0~*yS=,IJ1vΈJۉ]hYUQ.P@ǷrۃV+tN':Y+̇.LJ`KM|OƄc6[Jt};@QȻ}lVJ;<ݳQOأs#h(ݟőڣ1a {$ \u ͯL $9Q}\Lo/TE- $A=* ~$ьhvK`l@ĚZ8Ð()gd}ސKHן+cͻq~GNԋ8@ 3Ȑ9qG[ =ƌ'N'FUif[w^)WC-1dv,H1"'SrczAxd'+~rkǶҧmYWtZ9eKrm9(kKk=믐?P0k!Oˆ$K dI+ ^0 PL *hj'D .[oqI'~ךݒL?oVnQhí#4#OTp}b;~ĎX<5.E8ӯUƨYX]=!73ҟPsu\8mgSdhSdR_hL&6g no2.; J"zoDiXü1B&_¨hE7wLi>ugf ֭F˿!rL'7ȵ tj+l7u߈ݤq]C2Dn6X䊌}a+kw(n罒/@$ͭ /ZEKE|`KU15ttPֿn픜"popm|3~@n"JZbLj}_ axʍR)hu`zZomĉݱz^ES˳E{}مfs F~/$y/LN,'QxL!i Q;xA%%7vkjys,;3Y{sŝ9s gshaA=I7ћtdkU~` t?Iv-=)!BIK 6+=Z\sEJB 6BR Zΐgs'lӎX:D,u? oST-Nβ&He0\y1ڷf~W\8n'@,{t*Vב ґig]YE,KS,ѡjSityrvM㟍XjWxR \ Я&cB1f,B~WC$^iꐄ N%X_pSs]w| yW @GeMa";e`l @}m1 1~ Dեs /OVqNr;sq^mL{Y GmtSR&iW3Ӓ= 3{!nbYݣ!ysF7BȜmj}!;"x:;O7@z;Xnp O1Z.Xǘ=Z (U\ȜAxA--#!pK5ܪs(_ЭU7cS:B-ed}m;+R&ֆr,0 UpѿB@ pjzЀka⍤,( xz~Ke88ǐ1xFnms!(SNd-)LxNOߪgPc PVT&}oF)|.%Qr[Cބ & Ƚ?m B0~8e!tk5$Pf+ R Lƭ8BޮYC##K'&︇pĹ;Z&l#F>zkbs P)=Y`r>'9p`:kDU=\)bz@٣R4NJg CA(1 х OW谸LG[4`id2s ^Mx+s#Գ0^fjYm0wed\_os;ޣmL,Gk$2CdGWW~<9n㗩=X sHֵHokxp\1%. Ǣ4`mί_ ]%JAE5BS`?-"#,14z3a!`aRR{5@\8tSzkݚ0~GDFr3]aci_HbQh}FgK-\U橜't^d &T^QYڽjxt. FoHjxrfjє fTtCHiLJЉTTم4*!,ͭL}~=ܡcV F5IA|xYDa@qŀ ح gJm a.o*Sheg!$1pWzړaLEm*t9#e鳗@wtPKqeoV<qIgBHڻm fShQ|cCqxvN5g햱_ɞnj|&Nn cxgQsZǧsԴ./J`PbKNv_ol+9vՅlw[ qC-θz=nT:۰[n ^4JJ'w;8 s<I[2)8nH)(UzEgϋK91wpS-p/0 rY жD9Q.~-|,nnWQT 40l;O\̰ zz ] 2+p}mG:J('aHT ˊy,R%b7XZ[Γ`yu;1[sG >.}#^l%WiGϮt > 5.$( l,9<',B2O 42^-ثa1W2\G!] u*SK][=h$;prxev]~6Fp8GEᤡt!܌Crt*6h5/俭?۔ { 2/!{Dx֦f(oo_s꣯_.8߭jC{R6By[1uX"~-t$00yۖ c?h;y/1>8ĽEKPߺt[cլSW+ݑ !Tu@a}W=U& 0EGpRo8*r8\+@C 0ma=RZ)צּ2#}S&ejK*%uf+6ض D2"R)ga'5#$tUOWAFp:9bgԑIj},_J&QON\(wۂ\Brlk>QӤmsNj@\o+JW'_qy-Ħ\8jCzU=) =B,Zc{ 3򜐙>6kzغ"m}vu޾vr{Y> 3`4V4#VG;PR^2?0ڍX Ahwj\ڜ.6fPp[.]x+a* §(9׊LQ5XzSJ/վ4GDžSA5,'S!f( %FExWJ.y|I< TBjbWNF;~Haͱlf"$V+!K/FZ,ۻ0xjn>T4*O-$ 4_~8lba}ҫ׎0Pʲ2[p/m g! F 8O\ W}!-ff,8,rZD$q450Ux{Qw5㞅D*tbɥG0cZ$oV++n0R_[!u-1rsDD'}D:|y`X~fnI;?F@h[kjaX ˜ꋹ&;|A!ϐPV|#jR!Zv>liTwoJDeGƠD+:GH~\t[զw;Ro" ;ͫΘ5[̙=~̥Z9~@qJa|;jRUIG_`s3ڹf- 46qGkօQpfarH|`m{ᑚ. (YU2r A#5ьi_{/d@((Q){G1F<1 IW"⭇@M@< ft 1Uծ;VǣzdZHuRpMJ.󊅀}נ\F(w_a<]3kii4i@H;G} ч'Q}?7v 8߬0*8UL<w6Bc@֋e0h~lada*صxkbT`ed-?CbdXApoRs'Z#i]l:6uWũ\Zc r)S驓'J 3St1*5q&ާ6 ޮbsS=2wpAA|cc>lއ0o@\}(;5/9,ts1""LOUN*ĩM9wf4Bg;'8,W{oگj5OTF&K!>6?9KO )S9TNTZ?%繏Z;o('MMbT7u/s%_F]%؅|vChaY>6iaа쏪ټAIgȾQڔAqH=xK ih슱?0.\@`lEQF* 8!iJa_n+IV" b|R#W43fr}.#g9&E3;}/$c:R?z m8[|V[4aK"BGJ O )~U1۸*>񒶟'<:=9%zuU|߯)^R@ ) g2TM=zj `dyS.W s$*4z}+ L3WG:d7&dw?FJ3b`amTjڶm<ʄ@ E6 6"k~šH_DT:}H|2BK[GF}/\׏l8cXd[[/؄s3=~1/16~JӔSzm@a0j+T<7 u;zc$K#,"[vN#%-ŒqK&tV;rڅk|(,vy$o}B`ZQPY,"_\fSR! ;pB ؐuȕj?HMJtדic `Οhc~ x)p P)s)>o5١b|St@m dFHEMn?IBwԯxmZp?{E<ٟI h,j\!3vKڹ- eYaL(_puF?:x,SOA$إ(4e --[ Y}$P-g%HXmCb,-hNS6ьjt$T+dYKB/|ro1׋HJ?]L?cUK(e0XXz.:31C^KD]] z̫*EuS޼-8dyžg'Gd:*6S>X}myޒ .89;O/ENib"Hl[U`A-u/̽Ǹqi7ۆ^"%Zo߯50xAԣ.QD$sxP9dC+*N "VO?Anu6`-_ _B_7ʴ +x~4H9'+Ѥ,jXw(UY'^XVECf2, }P_ ސn,TՀyOϓmotGG<8dd]Y 6AޭfZc qI}h:MM/Ac P촀iZc/9ֻ =DZ/8́68a(-qV]B09B=[tWDZ(W15Fv"CsT::wA4_5TUYb,¯ΗFeOg0MB3t(2H' yG_wS`Q=v&Xv+KVUof,"@CFEyJ Yj:vxWo ?^ɐ[U*n5St]0Ru1[cTFB^? WO3e<܅wu'U J`}ƅ]!oFʥ n`{&v 3sv3 E8vJ)f ˑ~x/W{\L{o7!ޖ1&"4s6iAgE$#Uֻb{ $Aʱ0gw~sgLiӶϻ^~O)G/!x\r't'ʬ NZA/+4J\An%2?3z2 ? " ?(6 f>h$<ͫh دFDž (IS%-@Kkq98kԊ >Etɒa4"oTtN)<۝sm9N>P[W^ 63~²DSfV{q5J齈:XWy"/:䥑Z bIP ;_Nf dlcr'& ݁dM޾e%eã\/.84##"e%JL&½i8kt]]|x& T?LɅ[`B)iAXMx^pXދO'Sg/ʚTJn(F]-_>Uw}#]?J)64[؊zvy4 ֑4{d[0lK8 pdBa1 DP=t\G.UptHݞM}r`B\OߞIoi.-Ijs'^sOtd|Qzl }JL&o-b5/m)o V="OLFP<.g]x' 7xHHNM8U۾7g2y&5"dU[3hv%O N%*g+q!yM!^聓B0<{m_H,@Rl5kӃrU>|*XgZxATL"?UiV|:ȗ)WbN'RZ۶lFUH˯??H! d4lp7Yس̚hB7'3,\섾 ~q=ĥ`!_ '=1?,NkcfaB''}rc$n .=VIc_&ECkLSdI0Ni~u @:Xla BR6u:f&n'5P5Q7e0(NX4i<WY6[~.w)̀C473oJP/?~dXp6 S0s\`nU!xx5#d?>:$OQI-[(~&lJ5@f,q}dhJ$aU!-uDE%ŒA\ld;j $ücx+avePxX;[v(=H6so?]kC*w]VأU>Zy7 np=I CzF;F6JlJ4cOU< a6٤G~,=ԭc! mah)Z bΙt`0e@@9`.}Г캔3BMx)6/g*aB,`J$Cn`+N*<)?M#1 +WLLKg2Wş˽?%X0,(*X8!: ̢I>mpq%r_9+A0ZWR_|>O^6c @2g-hBr^K}#ju/d)DZhIUOOUr cL)N{*.?a:_dC^:h"쬍.W̭5 n3mtDz-_l;Y4UׯF:fMOdk@=Nu0VmEރhbtQ" 0Yu\."H`VrάUTIM٘%kgO{OIKQ:8]~m!F$DGӽ \ )}ʘޫt@Er>D!#~m9L&{z'm|23nU5mE#v;;͎UsVsujZ-_<: ~@}?Qf펙:tTT yq&^JaӅك&)o jܱh+,ɭocw!{O(k[Yw.]SBsX ]w)y3Pal.gd}'ok hM 6ȹ.q=7ޜߘ;x:DiH5St["o^zcrڰUǧ'i@reF%13StC?4fIHR,-!e@MhzVzm?8ݽ-@\ m#+tqkv)G09AOjgCb/N%һ % Q«.VxASK-% PTWQ_Cu"$tJeIuj JbalBmZYXneRCG׿oHL /chb5\qr`i)nCzB{wϱ>d7 f{`񌢢Q_mo31̗DRe4My&06 SwGaA~YbP@^qX$CǨpp\Je/Hb)=#Ct0{-Z}^Pʯёb^h-%2r*"d:EЕNR{L*c=\?qon(NJiײ68o€53VBs`攠MJ]@7ŘҩٹMseFVE :dBtBJ\2w&]T"6Gph$mMOϡhV_ٓޠu7(*^/9`te/,+[X6<Ŀ6/G8 ɻ6ުq ;tS*!^}m~?6,;{+\c_ᾠU-X:k#=V8X|[]{ |VdOi&\,>,OkMd}KFi 0vJ}K\W{.9|CһʻDisD#/UF_ 7 ͖il GWfzj_h'/Wk"Rp>P _6 eIt{P=eUOW~5Kf]l08:B exŲ'9Uf jЅ!ܾp۟Cjgxə BNэ@9 bGYK׹[iԑӘ7? =ޏp,/U3h&afɻi Zc0{@.KkaO1IwR"~B!ZfӴJ)oOsϖy6ZB$}✲w%>p,bay6gQb&I+#:X?d{7ԣli+yF@c ,,|$ݛV'cnj0-3D\,P9<eSjxV{Clk>KUip 4%Eܠ Aƒ>ay sٛHkL"[Zb*Ryp4 3"#|Si'*A1% ӻV89:ܮ xtI2qц$6۾i"*EPP["Mkn.Bf?F2/:ywՍ$(BM{ v"]UպP] %I6z@'7էMlL-`3mdi 2n 6c^S˗8 _>Z/H`%Q'PIL"! <}N\{!2 ]AIE QhWLJӤ\M7\axW/%v ^5ўD t0CgJV4!.>g/91=Hd]䮒i.J\7gӇ$W~f7mT|:sqƤ5Ŕ d6q%[k #gO,\rGDT_۱CLh=95UUY>p SŚt< mÒ_UYuw `3ںZ,9ZjzC7`#`Hh+|;nV]A4nSn68aD(ws@/*=v]%I3vPZq;QRHr.bCowb䰎n zݭ4%Ucm-Qa$lat!7ow^Mqf7Oc&m,1ձ>ܯx.L7ǣ=TFĊr4ECq]?b? ZOK(ê֫&rpqz\MYPALײ0Ea¦$q^`z:tULI]!r2Xx,2YӥЯdsLCrf+"1olFK^B -eC+ayBJ:YeT=!JsnUb4=?ۭ< K`ŶR5*5u9MK\(dɎd}Z1Vzc0`âfӱ*w0S)}^?c.#\ޭrd`( K=èH]h3%]5lUNUȾMk:[dZX:ik-YkWyt@ukBi*ab1ev$bj)LA{}θj@WRx,4C=}DIQ 5#QQJZ%6wD e FR<R8hzq{be*-޲nN)ist2E` Хj\[ 4*ak-^r]7x9]5087HoM !{1s](^bo4p8Gځr<8}oMU"?>Do>t j]{j _w1;s;cX&-(HZF\?g)s|d12BZD;NH5ldTɗ)9-.yZÒP9vR j|NX;HI1(ztq)KOm|w {ƞí?Z(XTD3AԽ{D~RMTzbgw֛fXfӗ1'e% G1xC_etKEeAl`%`۷J\j_l1+q|QKCYP |Ñz6Yo܌Y<?j>[?~NL3un0ҫtbCPTDev{$7v`X@?kir>n?q!;TX Tg& b*Z|&nf^؄2IO'g6Z0eFwu8c9Ēgak :øvCȫwa!^ܕzE@闲S,4Ɔ!uN6 J`$Ued!=>B+My~yLXm=+2l\*䵪sh 4~ʾtEld0aIѣg~,ҲԠkGsV\POczg%p7PBK޸PaNxtoᬺ|t>&>VZijSl}" }mJ">,Vobs`MĀ@E`ND6E}h>Ƶ q}V1_榞鴊_Z( a#ڛ&%\%pZij36ɢgN~=H6znh XJ2$_"e9䙜9KKYo~si iC }^`Ls52r"]!9=ϪR]9vA3YFh:p † >E)'úNw:wxR@6d%Ye NƓ'(lS֧zq f#nΉ],ͿnJ2PxXh %ܜꟄϋg.{e[f+[$Kd\ 5gqf;1-Z&36`8 TI> OVۚDCھa3}t*6|Q_dwm8XJ)=1,mFY_3!X 8@.1Vyk3U%VUE~x2x=±oX)ㄊT/Y; Λ]qk*ۭuCsn{!25u4&C$bFoYw޺Tc8љLo|q P[\er_ME2gW؜EH"1 7~ڽeCz$&!&m ga LingNAZ?/~`9[PpkdcimMNDf-'ݚ c#liA0Ԏs! zb-xzH v`aEeI">j8 5?`LD`P'LP ԅy^\Z"XgPS~_cRCxZnOu6pZiڻ}g#aJp&*UohoYGnNy}*) _AEؚRnplB86?֗Dnj-;7k/R|΁jRvhDɃb{R(tpٛS&0sDW 䬉+vu%gUU@)sȉ7QRƗiIJKbD*(OTJo0ҎU<V=И= UN ѯ2s臅KՐQ_pd/d0xI ǬqŵHuqi~K'gD"  {66$^Z]vڞ$ Y6))+^ˬ?Z&`Nc&Oos0O*5J;3ubq.ŭv#"٣Dx"^ A)&~<3~l[l3ʹ1 mʫYǍMupr,G;=r%, [3nkfC+#v]; DͯCZP)o4lgYo ږOg<+4 ,xʨBt0DF+gR9S`(((F\HA$Zv@3^>g  h6$R_.-KISo4^ ʡ$*_Q̓}͑c=k|?m#8ad"+XzE;5c-NU[uX]X]ݕX;3_OΒ;_zoh""&tG$8W,ۚ ~Mط8h9\lljtw$_f]Sn%z֭xXgy@iL &˔둏|19KMC~jR]6r{ ",CdohkFKYy@|m]GobH"ᚩ,9Z(~$nGhgp쀎 ?fab*m0-4V_y6ٝb 㢼O?Cq̲Y$"*@הè 5\ۓYc>Wrxd]b*EU8 ?p FZ#L!xdmW%_5tCf 1Oւoqͼ{%Nا1ޥ3lUvAr&aH_tx,TҺbyZ^ /KhY@*dBzkV,A#)uטn"{*Š&/ÒV[eUzCZ}$5=*TP-fv4Oh[GP3.//I":{>pp* К)\cS:;5DSB >,Փ 1}@:}n2čz/)N]ð5X g% +OIlv !0 (Ld7()$Mclyf/HZIᙩM*cJWeq ?DU ?:LrC9l*"$4.v[Qݙv#ʳUP98kĀe(;Dubb:(2ɒĻtmtX_.BuUe<;+D+HNn;ҸِDt5qtc;g'Dѐ?Pʸi-k6*b PNˏX?P؄[qQR8hgXbe=t?ߙܲCb͏u E7AP:GZS>L#ma;4-^2!%"ydѓqu(MU<.,Y̧iI-X0ǩ`TXMOMaXB X7n1Ma=j)j.N]Ɯz7Y]zJ݀G{j!v7N 'CfYSBˣN쵞OL1zKCas%sCT ~Ё#Y-Lk6iUHjp3Tbo*ph\.Z{ G 6u_%2cYF%#.fy\)t~x$xLބVTk"!dCi+}Z[@$橺RLcN|}θ<[~)C Ganz.#EVK/LT j`%7, bC䉗ZŖ I}C,T5q, | @1D#^ ] 478&S`I=0d"{Қ|Wχ`#Zx(Ap>S &(]_/Z<0&k=cER5eu0Xokzu& ?MlHV| :pxs*(A!R:b4u!crfUXb(>xNHB~sk+7ozr[whr⹼S"pLaו&|b&,z`da: {+ lǗYnlĄ!~N%t G@ 7{#E|1q#+pdOh$WnodltӋ b>mڤ5rsNxqe?ɢ#-2="]=b5/Pz- >ݜ-ش*4˨~&.# ` A)]rCϟIrXK=|Mh"evx_a('8s˾*K 3riս+k vVh ~0Pb,_ !ç6^'S+7 boLXٌW7bMi!x kB-'y,019>nLD&_pcc'-f|0Wx< 4~ܥL hQ~0ëoص(_*ܑI"1C\>J5˚>ܴ kGAYlJY~wI?v|y"搒ҰSd7 1"4s-W^<9, Snjs~[SK-*ȗdDu)V s5 ىˬF& XV?GQz-Mjo{ֽyJ |Äv !9|'"ZTsļ@He9dc ^w#J דQwhLڤFUқӒzA5bWeS i{i'HV^K,调W FKtY"e‰CG$v]>KP7[~Ò+fwMSe|c]?TM8\)v!~ 6D%҉1.e{߬ V;%#&@auU(u࢕C`O6ekB iCw%4os#DsdEn`H:(e>Mg 1ʈM^.NnxG<ŴHͷaW؞}&6UL[1 O8APn,As+C!`?-J9;p.npqjdP!scYs06(h#mޙ׽_oneݦX M_i7"Kce-{##V[QW([=@bh(+Rd ]QT.MQ?Z`3"X^@-ŷ6&([NlGJ~i#&=俉ϧqcf--]2fRǖ q434%A?"Y]HA[I,uOm) Wdƽ6Cŷ)5BJt}""v/?1"?+|<'QJ\w$s@DzVm5Hbe}#>6I9"͍Ѳ5xk5g: '.Izc(phZ"kh5/&D0g~Cz%! G[ _cA99Pä14^p&@a//0fW[t^T< oXvK&q= l͹tΉ۝@6 ް+n2W{!A@-a.MJj o}U$fynqbcU[8SX6M;]7H4/}|)r)&$"iC'v~,fȌF8 w7{̓sy?;ܘT^WE6p ԝ%KB'rS.ƪd!㊑Uz+yĩ7AMyJ =d۪, s(K~)SguuWxKOjXnCx똙em;)C%A>J+*2k˃0'DiGYfofcmCv5CM&<0.HЃ,y~d=r#eސP)nyiϥce+'s2~O媬EzL\@} i[΅nK!yMDSV;S92yINˁ~ E#xr1X$KAZ_x\n{edsXԖ>7k8vv8QSNA"\(Zzv/[_ Enx f +_Z/Ztk/y^1Ws3 3EMH0qzZDZX[r QrP(AHv0A)cƣkYh,\OlteẆBx_?AxǾԟ@0^)Wx]c-0) WޕZT^~ԳV؅FMЯxдiQA&,3@K>'5tdt5L=%/xhbZHpx˅iSlҚ] [} q^4k=#HF1$N6mܧ4L?؋mFg}+iq >6/āV@S6@.p KYCCח''=Q5@43ʰYNq,>Ss)D1qWLx@4&[pْXGE-rq[AW7ϛD`/ ա\=  8Jx3 !BDZu[71N1tfS쓐h^\ 1Η`ui^86.U5|ڍs3<2xz"DwIol3LpM0,IPngo Lէlw\qq HKo.'V/KS3Lӫ7( $ӑ3ƐSޓȃ?1pڟX#`&],VshaαX?եBO yF7RRXt&m pxֹrуTT 8Lt*ǠX?9t}rQTFAcU«QO%Dq;ګQb3/ªج ~,1sy%Ac^ϕP)rG%U)QB7qe=K$*MB^FUհڕZᄦbZW1'vWK F'Icj>aӂr毻kC2̔`/j"51/Q)|' k d+AS֞r f+^a`iQ֨"J頃Lmνˑ3Ro//K$o rY^lȹݟBDO0ހ"v B8( Sda2$ㄢUTA$4ƬAWDc6gdVv{aO7v@t>lKFw%,z;t*7cvdeM>AHa' HK .< JޤTb=*U$Kc]."Q3lZ!OXo[ۛ|ȭN<ǺK#],s??QHW+tUNۨ]ڱFuwRz]39'9(PmF,Fma4JK]td+'&vO۸Gkk A|[ff*y5`1!bc%y1 m/V8f#Ȫz47 j!#U&nrY!/ ޛ?g}~JK`;<c-J0.1RI $R3+e gʒ*Ǝa@-p Co(w. vӎWixWmb^$`m &/N#ʄ|m[m_nYixP#%Hđ#ݞкGhvǯG8Uw-OYu6c{%A2m52mTe02ej%SDKd#03D)F#ٟW=~9B DǸ\lV} / /ڸDKa`M1` #P4"Qĉ 3<*?:9g-F,(h;̞]].ka7|;VF?0G`8|wθƸ2\fRƜ~V}ż;ͻ g^5ڱ콵SKo*,cr{gݲ8Q([%f67%53rw3IFCak:*–S`92 MeT߇O@ IE.p&a40lGuS X2hZ|nnoB=&ak>$I+P䵼SQY NVSvnqC]iD!e^=H( LsWpY/4Þ'^< K S}7\7-mfV@*}`78kl`[K"澔zDO>yAr÷+]niLͬSةl|g&H8M2U&6˄MN6`'8nA~7l;*}q ۞6\Bb^^sj1OowaFe:4Hjf՛zx08jX8H4)fusWUmGS1:Q(|P0_G"X $0NA& Rqlc\֠v{yNJ ]ug-pB,OH gs3KuԾ’1#ƠP>)ֳ_bͥe hKe% Q >4S3,"K(eUlg`̹kSxnd1Y I/QĪV2gLGRCWɷ֐MimoÓŘ4Mp\)۬1 %ǝsA)dXH*6 lb7>*ʐpVSInҧo;;uo: N1ۼo !)<ۧ#JNַ@@ͨ=+)mn-rGw"9"MV1)ިҁHn';rnpp v0D:jY%]-`s cϚ}mM`&m>&F^0:׿qS@*2K'j1Wi7F8_mZvo1> S`vț 1{"U`J X3׋ &=.\V?yt`j^#H¯W(*Y'ycA9wܠIf E>aeyxiS%Yl-{B; 'ڭK<'l1n ܖFbt0/( gALm+,7)zW>:Pk~Pc;+*nUx6}B g|AU*& ==mW/dvR0Qfכ #z\[V7Ӆ3L\lz&ݧb}r75Lwmţyn2*g֏3Pl^+'o6_2-%a0Ou@ eVvKvY2dU󂽹@ n:_myɐB{WOTg\Nu9i487H3-E}EL^e\_] 4 +l/W~I_$<2@:#WCNZQakfXT]6ZHW8 Rt[ts_ɞ{RB){uEw3] **Le߶{-<ƻ-\" )G!%JI>Jn`{k5B.od<Տ]| >V !E%-$)j/9ußy|Mmary#`G df-wM9,OL"CEN=T?~8JhYQzaeWWNw %ۀd*IǟRRG إV Sn*5YOs$~5&9WMBQjZdgW+ #y;>jce;dɃ +$dLCh]׊ۗ.x/'0~heF$ZgudSv aݚO(sL_0,DOi,(m0UC҄sC9veNU+uD`r;6w"8/EM / GL0WzSv/vȒ;+:%s}PUb#UkF, fc͖Sh7ڽf܄~䓿)G܂@Rx ܡנ ' 1klu~82:0 *_R!%$:6{Od-A*zec# %B$P (d[^Q'=l JF%kUBmR F֩9.Y'Kʽw%$vO!Gh\$Lvye{eͰ1BCE%a0tѴn1M@T}G76<,r@V|Z)e{-̜ Ǵwxi3ӥ'A p4Nlr5% ;H]<.ނG0f'H!VvavH1ڜ*tԐGԷ^}}OxTIpZfQ?(EE Gr-\s&(f!=M`O;>a|!EsfSP7,~ 3k/ _DsYC$%6y&GW.UBPҽ=%H;%]"xl?n4-@_C0L _-T;Ĉ:wLQW+.ă :bŒP\bhlte%PX-e lcK[ͨq088I[n*vLᤵ͂ 9QM/.hjO|A(hY^Lri<.E`†S,7o(6g efg_c Z_m_H Dm'Qڄ+1ӅK}׀yF!.c^;o(ʹWMli7"fuЉW$|ȼ՞q4ZVC:[]ZhlF.G͊C8ՆSw VV՜Ӧ;*H|}/k:BHK69"O ݖG TeIoޙZ&)Y׵mOeHO0DkZVP3 ~^4iCm^3pz M(yR?!?_\l!""`Y&-Cu{DƲ{X&{Q%eڲRK#ܸЕ&4HHr`K%0!|"wt;R՞ ($CbGm0@kMs .ߵͪ hEƠ\n2A d mBq֐<#TEcyO@y=IB K*%|̸+GH ?)-9+JIEi*u^S0\zP'w>DC{?7/^&K<$V,ʝu^aѝsPj"LnWw C'pߦ0C;'w1 RO>ib ?ө@cj7芼Bk! d\$kes *X&h =j n3㓿&>VbASϾ&qM%򵥦,݆Ghgt(?.17'X:X_U62X E !w̖xo Ɣ v,D|J$:Ă;-\TPpb \t9LbOPEn錃숩ww}"U"7faV N%a\=YjlHRG5;>UO[ᯠ8cXy$Ȳ߹^q\5O~#~QXKA挟g ѻZYfeaޙY.*ϛK"{ϯS+b'>gEe0d|؜pldqo[Ht桚Odor*tҖIer_n5@(3i8_QuY Eқc\\8gƘF`0 vǑ/0ȃs825ͫ}98A,͍.XwZ@N6dUi(%I &T[2 7W=y:suem[HBUr>5tlxf;I-pf%<*5"#0]_śLS^,EX@f'@Y6Mp!rQbtP] e:?ҏk&K45bKV† RMD_.\XF7)2()N<"+3Q: K6k((-F\!#0tneJ^Ϥ9 3hkeg¦^ tPƄON?gO {q-IԎJ,0bg?{蘭[)V:pC/vX'els 05H1| ktbj!E\j15C&5Zbfi4{ ƥ c7E*?=gZfg dzAq~.˙A=ވ4t &%%vr~ |LP(\A'u[vT0Y#QfzvuDž9 CwEQ(HW^% "Sxԛ!& efNZ #1Jfm@RnV@iGvِn٫n Z #%Y6>,*lѓt'hl_@9gLʢcjޚMѻFHxO^v+vPk,x{r!v"D0؇`O&[9aC/,N12TF-p tJGH9"7ͤh(zP҆ |垻o"׷6M$ӸhF?iy KBEm"gL6TyG!NԞJBUFl~YYJ0>L7ri-b6[%rTbe#;%]K3ՑγyΫP  @i-ִYMtdӇK~Itҳ%ZP&q!6Cnӗ.1BPBcL<8gcͻpnՋ;hQ rZ^o6TT~D{=H/E7F'5qesj:5_:(,uN]ܩcty v ^OZBgNV/\1sErbA dbPyp>>uȥW"UJl!>RO6bzͣ/-Xc߄,ݲ}{&=<^-*h; ˑLˤU51av*hŘV+wu٭XNɉ' ,הSfly%i/U],e+شb)ULrK:c)Epi!rGxe0i Ia d|#Ր2Z' v|3.wwxvY1WWN '}$8Ŋ6?]'{//f6 UP{a  E4h&F\'*~#A0UJ/T GTPpʮcB%;?"‚/'k?꤮rjt]6 hSq~Bx \=$K9%C[kJ1@=A (iPԲ8,"6M٣DmDg7JT_r]H),@OznC46I-a@ 1]1VHkiX?0/Z7(ӈc FFWoR`QһJ1|u8(FC?7 P|^AxIݾ4PT ꙾ JK1 w!#^hތ %"0xoo|a/( %Uj/GlG]|@7U_e|F{@aVTÈ442p߫׏Ex 7l=~yxUA{,P%Frw3 ,3#ߓhmU\v^JhCRKiGk-8~N}z‚<=t脕Y}L5~i'Q86$b,hU vjrO=T?=ddMFs-1+Oד8}g,w`!Ců֤G`^pk0'6G+vkVԶ/ȵ u}nNpI%$_/QMDl R wSe @vG0C,4J=ic],FS'ƣ+t.kXn_s.\v]J 𯘩 _9WwZ[pw;rӗO]:C1ɐa U Rτ۱ U_kA׿+ΜfIRmyqM|Fpx|]1}/%-9_O3~ѫO?lk [b'aX:z%K4E;3?=Y @-KvV[״d)8H*Vc`ٳ;2 !ܨYYN]n(ifP!gx3/ȸe+ް\=Jeom+} uz*ke'ƕ0Pru5d 8nJSY|m_iqs6:{uSRgIP~ e'bȰ2צ&GgS !;J?MlskLƽ}Gv7__=c=P'510as~fei܀ؤB'׹{#!W6x/9l_eY3eV.-*miQ4wģZze,s4p79 ,-wJSU\9,xɕx"LMs~v q?q+. a ЭYZA GU0)(1qZ:h\[U?b_BqCI;A$H3n..9B$b+k^^B;e Tl= y7"aG:n#9߻ǤCF0646E GjPx49^1)i7e6ɂ^o\ + ԀۃGtKx93;,Z =;.)T 1"* 8m/)'of(0-_ܑP zEřÒ.m7sG7gk,LD#_ {T1,MsP̞(E_E-ή_2mŊ<qu*m~zE(h 5pVJqj]<4c, `H?2Pw/KIji&#zZ^!BKTNKcș#s>'ΙI<$5˭x7kA|J| ҩߥ: |4h^;*ֹEBa Xbٍ1WhrgJJܼbâ݈P  rm(?9j}'boO*XLvr{\!•! VḐ`iTCOZ`֋p6T't Qq\U *%6cœxO;.Dġ>kx%W䆋5oW.}#q;\\Elc |yKhUq2 ,Wcmog9@^A.@4*pÄ5kPD>"4) (Cj)H9l߈3k (r|{t3!;cɯ1Eb{ ÃXF0', X" ɿye0n׷Cଙff"C5s2 ˟윈B~LYt[Xt9j5Gs;, Dw6A YJk=)dP4P(FqRK̪F&* +; "6,տLQ3}BfPȥ7Sz6i@;Qj3(fAג]eD1u!|rP4@kZD"S yPeCjeV("ԋr-sSm>pl,|cH s,#&Haݤqi`5Z! WFIܐJ]mn9cr?h(15Atzb2ה(*[4P<:R~!ϊQD9̨+YU倗ڝfរb\9syu8amB=I9J(U @d05qsRWIW*C]DM1B\юXVv } 3FAFE-pwF1-kxmrfCM.ܶO`©TO .t(t{%CfL~"#+\!L挮_O,-g^k cd%_5 KI  kYb5) L4kVMԼ𐥨#tUV#yߠ)%p U pl]2E}^pۉ>)y2mךle6O; Tn*@Pܣ5EÐ=_~!Q0J5,-]j_8H*ՋdPe⚦>X:ŒA8D'!<w #.J]3ɂQYSŎx&5& ]4 E;S34W2;ߡsq fMX0%ެlQzȚ9j]ji$-1uKUA CTݵ@@Y_MNt;V:I(`p)3DtW9<*OݤoF–S"+@Xb;pGi~#wUăI# \8lqr<UuJ)ŪMoB5&[`Ъ$jD2cA*'nw&[]y-QkT0QSXg58h"=!Se;(GF:>:Ҟvہ ZB)R!Xi)mH:BdD `(1:V@_ E)cB.:`0F*cv9Dɕҵ>M8.4%D"VГ_dlC)d419Vb`]rw"pwsDуNH&=9-zpHS]t"}8CG].Z’}`ISt)1V{/N ҜlDB2Yxט1 "vMI%dVvPRyDo+;[xE$)Cu>n׼!f٨$,Ŋ-5K.7e_ȿd!# dKe@2R䠆>;3Q^CzKxvոO%.Z/r0J8#ii⮫8ާDZ*'0 ##5D'c[lm[]aU}Bwlzf=2dB3w,ҟe^ǡ˵F$EP?/A((+p$@ >dcսOjQEc·FPbO w*C>Ē3:Ye-/6DQna<X$Is0aP:zEd 68-P* y.&%f@R-$NIy{g6t"XOD[S&KYW%rLX}%Wk(Mc5Ac\ʐӴZ"ɉ< ڞ:RUEM. de Mg-fQs{-KnfeOpCP+gjk_nF`((FS^j){9ѭՖ(by Z4縁]eɭz'c.%,Тń_bDmd=M_rǮP{^)jX (15pE6(8ӝoH[7`ulCnآ9|JP)stpBAGͅpvCHݛ˕W{x_?,7R†o҆n6E.'e2$ J|>[; +|+Ma`h çrm2_952\б5Y0q\=Z+cAc%'“R@!҇4`Fsd D>^):((ؓaY Ј " K 6pޔ>MadL={k y?ƦčQ^sJꍷh~D }NL 9 ѣKѱ[_}V!pڳɌ{C0V +ڝ ף^ Sr+֍q&=t VDP+Ý LA* L:u6}ӕ%xŷGMiOr>`3O A@R>,5uiM4g:-@/F.C=_|*.W}>>Up4'`q~ ՋL l3PZ+g뒐3y+BDqN $x$\a+Z`jADw$e̺oTua>:4)doO{ mTVhJݺZ32 -D[U UVvq.&ѫeV ]CgdDU.7Be;\ ^2d~ף]Ȏa1ҽ'<ҋI ŽU\G@L;-_;OJf 1mп5l.!<993!D:!=n#uO&*y;1J0'%ӷ5d384\"ʺ>ߟ*ps V{m:}wk :)T2ˠI̦I6G_G'ORhsK Ƃ$>}WXi|xlE$z"gȜy' ӂ ho-{|N`ada7_ $?2d(x{ve@ynK<50Љ˒ZyU{|#E4ʤMn9I#h~3f)&+w\{YZv\U}}0^*1 dh}\rq'?@/b3IbHj<ēߋ.Y3Fe#9"u:1TipȦy6yhE-=}a@w !K<"W2IURrgWUd6(`Юx9f^N; ԊV-eZۑkE 0WվekuJbt! vU4S_k,aggN?%T*hwK[w\|T˪v/[ptȆϜ9DMGT@:095YRFnO({Z=H?WO3= o@<$^_:w[[&Z56HM89kk<Nk23tW^.Lj^P ^ĶQ¾՗(>H,~8KEo{ ya!|+# hfz~6^_K%Q3vuǘk,qm0#j;xTVEjjG` r̨v׍IsFƟ$ڟtc6G ͂ >f=:_sk7ia_WbQlaG1 ɡPƀ70e%-^ S#olGF7Mtr=@/\|\Ibl78P돂ܿgR b!Vğd\b40w./_‹//^\N P K^J˴!}jbKumǿ H; ۑH5BUswFN\QӢ5}Xc&vW,34Xȱ|L(RRP }eh? z}A8u'G;`Udi vLY= MP;g Eި$ rѧ$Y D+%8Ez@5Fz)Ltc?C() tĝB#=ȃY2W͍[m,o2:H_뺸of{=m'j.؄xJTFOʞI\iP ;@=kF٫uuxQ MjS==Ӡ&΄}mźND }$``U,ɗ¡JPI ^|i"*bþ, yRP[*W'Gt^kyfj J(V_=}6א&;?@}"WI hQ9ԧ]аF<{E Ő!{^W4)vFI8}Di|@0bU `6 +v09&rLIIݿFIe}*`ѓI&H ϿQdt XCGmYx?er* 6u4v"#\魺T.W{{%j>xoh ^/?`xl_!}^\XH! jGJ;k}_6 v9I!)`Im?JfkgLIpR;iY1]͕Kf.B CDmBцGл_+牾\B7SKaAw2Q$߰T|E}~(%j)η~i&y=sN]e}-ef r900b}#># )(>~ nhlT> 4s#:]t Qk>^e9\>DV,[2df.9̲lEjpawh;*mɣ횅ls=Ҫ_RsE|Vs{sG[L-@EMkW!f#o4eA*E϶v 55l,aX`q? E*4Etұe(xVb0U߈Kל% ~(Iu􈟤n.sF:%S{<0~\5;e[XL#qUFe Tю`V9L;Em Z-V's. / PLf̥Y@5~}*y‹3PJk>+uT6Yz<4֦K ,FJEZ)ǵf/QUPB!GI6Tԉ.NcQڠC/bzs'pmB6^SixHXgj8 |̂lU"SM9fMV(j:T;S/3h(vDk{| ~uw (Wޜl\T  +iM(tUv*3n5|ys%Kt*^!Vn xV"t@{|e_ݸ.VLa\ťx<5ynҢo5B,e.ũW4"Sa8k)Eg|9UM$r/G1gL8qvfW("4x|u?1Ɵ+"ܸ2pPJH92*f; tuC͈iڶpO n]mmyiTЁ5A{>#qBk+ZmM}6=>d%L p}* @Y/}z?c'Vz&w7@>?0ۥ5 *whmX" RLktkJ5ix/fS P"hg.MJbݟU4_ywV!x(Tc>F$(hȴHzBH,GOٞ2Rh#OT`ʹ hns(߅ŬDʓ_GPلB| M%{<@wglLm> +YSB?;1!pcs4"<IJƀr&RTWC4 WW"MdEV{cIo$ZV<Ͳt;7$|S5jQM=ѭMC29E`2Q!UۺpaWVd9/U* E>hz[~o gFVr7وȩ,fk @A .GɥdZʃ l0;3Ay^@P o9@S.jÕay 'ѕ ޮEg$& UAoƇj@54T2`31TjQXfΚZ2jFv𙷀mkѷ[TME=w-F$׋lUb&)qퟠ9`ϧcAŤ,omi~d bJļf*tT듭K J_b'0P e>%"oڥcNB|K.d_vafU@p׵2T<z)(6!Er OA bhFswGMzJGb1{;;hDw0_ ӫDL180x3ms,N=H23>װx.B5a[tJ>R4#ʲ4mf>t2_fBuɆ5juW./QFUYj3)YPͨlSUDf~vԒ[mMpNO[`#ZӲ* & 8}le P.Rg'NjxН2m!)}0'Acz?#T#аŧ+W iԾL @ J p{k,{{jlg^S_G]+AZXuRd[^jh;$Q7CFV2X)WA,@{XIN1Y]g ap2+:Xj=ebGf7R*slцroUc2?I*$`)cUQGE܍5I[nnLXS"QN{q\A_5Q& ~ f1L cwN**Em ZLj[RE-[cv388gK*ޤmw>LA!wefs/sςl ѐy p r@B & !f'}:bװhʀjWJ*07Ջk V91T?ڍ B:'w?@ՕoLW; \'$E-UEIQ.,bW(ۈnz䯺rV6xķTɑc\* urȹ.|c)Z3\8xBFt:79.tb=}驨-e$ 2P c[B1k 矆IPa' vgV@-E:W5J.TTII MΙbv3 6jk_ <f$yk@u~/qr_ۚa`b&E # /)YEUoaX KK2e [.2NԏW⢧s]բ?bU_`6%~}dR\=D^QaUJDPGqy<;˫{@OG1CW6( + o?wZ4Rr'k*}lt{ґbbRD솄!I uu-Z3ˇ$΢䇼2P!k [zJKXx[J9 A@/G%G/E#tu*0F+sBb]m>0F R#3/Eroę0/ws1DW?nGxPMX-{pǗ};ȪPR$bfrhJx !u'OCSfJEݸMj4 -t>VLBhYNa̙bi=DՠѼz7nfQx>jlIO1f{ (Qe8cFao8cFbc…WK+ztI)XzAg 8B?T;%~,#JG*P+['4'zIH{*z >O1wsJ(7rWzF=+0/,l/IϨPL <'DN+5߶w[qhh\a}j^c8[bV{G;dR-Utըx--&B vN0IRx ;-L ^W&@ iWٔ*\+gbhZzr:*V༡DxDI{=hUfBͼIEhE? U|ؓ8/\B7Lcӭ[)Ȑ@’_*CeJ *82`"0Y֘r:B4D)x)Pȸ~w3^ "\`=/BARBZ% Qʢe ̺F{b.v)HJu;JQMrɥz  ظ~!B6g7MJP!@y0iT'(FvB k9O:1]OP)l*hD"BKnb֮96)ouJe^D3YD* GVS3niC>TDצ, 7I4?Gi0 /:)%7ղ]?Wi,$?In%z Jذ|?ޛGy0GM#k:|V,.F9+EθPՔ>f7kHVS>~= |4+8VϿLtԬ9a~*rDEmN,ӛvOc&Xpޏ}~wG^@NsOdw3\ݐ oMa@ ,h/DPsεOnzC\3%Gh7oa}Ci}wR >bp DaCxe J%vp,&;3L;^MAʎ>P1= T؛鿮U䏮P?;d.kֶZwX":Tpŗz}~+q), 3s^OU\)#JO5zE$|.,,`9L^RWޑv$ |`rw[֏wtК+۫(o@[l@+~C;K]` KP{}]?N&Gk Ifix`cҗvJLT(yפ])'nsD7'&b^ꎲ$U٬6.N4ҝȣ!|g*oWu]_ybX/ O[#i095YExZ-ķNUS@g.7Ɗ&n᭚8~>H3^Dv>p rg,vJ7MlCw.$+CE*,?#[{BSP~;C 1P+s"L8Vm.J^ܚ(Lg!o@ R7grtjϺa?A`vf? f0m< e PqɹHaެ)%;jFE()v4bYvumm^5$wWd!oK7,Vn;>I;i{c0фwgM% pT5dm 2A` d1o oПI:}Ac;Dt]Mt&ibEVwkO ߘQxhzMgzE썑8EY$ W׳)=Xܜٚ덊k%pa<@Lw<‘vs#ap `G^9R+1]%7ZۦǙ qB#Wg{քA¶̿m3,4t&1WD47'HVT J.9]LDֵ =(Ū iCfG6_R2]GO/Kmr9ը0\O nLG$}1>>b?  3]6bA'OU^[J> cc-y9^(2Jbj{$%o[ĥ7Ħ/ZLu>iHq/::lVhK)]YLKs(u3(3N+{j˿wO@BR4^1 5=s3 aԾUm$9k V*$~^zԯR9m@4ȑV-V% j ROwsnDHY37x}t? tZIe ؕA\b³x/gX*jmf,D"A<*]Y[1m %۾/(|b_"#ZB3J4Fs:VDÎӮY-ڊLTǾzg\3YQ;CO|rcu]egtUAJ*N?4?M8VX LV܇6{[ƕJWҷBMjkjrnmJ6.C5x!6Q㑫dvs ! n7aI/LS `yưFܯ=u)VL_R%7K5yA 0 y#MrdYh2nؒ!m˰͎} "P-,lکƨܕ-_ Z!/Q.}8{ua<Vly `6Džm+aCESAᴡ(Y7б gsڿ)nndMh6 A"ơz">hm$Ͳ`~9Eɹ^@%mS,'N]BS$^O삡Fօ164oޯhR$B( B(9YtF"qrmOj,ቖYV6r!bu_$9+~^S>|Zet[E4ٌ4kCصiuaӼDW/%d@t RAϧtK6X:2ANfߒ+C~U؍Se>L0YM WP睮7u=$S0Z"嫝j>/u>Hȃl&+(3O ҫVoͤlnj"('vX)TH)ONL|'H ˨M7RLwEZ>|q́Zd '>wv3tQ Rx^NW12{)_zrYvԉ))Iɿhb[ s+^Z+~G~57[^h_AlZ`>.n+ɼd$~C`."b/e1Ƣ~w ,"M\YAܔЗm#;B̒%bsۺvXٟCǪn2(/{_;ӌj%̻afVa 蠊j]lf[N:ƈ(7$*CKh^n@PLl޽6 oDOHh#j3S'd- ִ_KCI xhtKv?Z(JW#Xz/6LǺmZPőKYxYwЃqv8 ֛ޮ$l_K- i06VW*ejFRnjl"WBwיjJĺxIWXx@xހǘki7dIzado4[+[B =-9(Y5tOb*i<3wU'FDQRbsqB^3Ow.\;3V] "鳿E093$D[D8o_QU)B@7FN\U hjr]e,&+;9a.fL,Fd"sMi WI;F~Cr5 ?"嚐w!ч?]ri$J&RM{iú@`1ieP5|W:i6yꢰ>vY-ǡ8\oõޡ=9 J),2 w}Vy/b!>[Q!pX"zYbeF8[1J ۴?_'jhk)PvR hAy}Q |Y b6"wh1,?ؠ|`YaLN"b3N`Ym=*ug.zdf16n]v<{+8tۋH 2U|>gNnCa0DF&=1[tK-8 5%CK69\nAYr*'MrJ]nۜv!5u5_UҊi}V[Q!b[rL)5 x wքXw)9|Id J@|NJ,o,B=8J O!MJpaU'zCzֿfiP7.]h-M,vy0Ǿ2- i>Hu8!%D~Nt1w@BCxlA)ˠO(΄\Q\jWS"XL'3^xo.8Ey x1,BIUC9x8XK]gM*i@nvpW ͒-^(ز;-f8wTM#{I)xIP\5*>}<ʞ*}|H(+qF1`P\Q#2D3|lw*~[X()Wq2sYػ`d0P__6RChec~\PikhqZDG PtW>D+M̥(܅,P  1Ђʇऔ#ʮTՠhL ,;Q5s:lbnʽL >b7\<=or1N}%k轣 A3AtֵIj# Чee0&Qja 1mtW&"gxһ&Ӓ^ɯUzQN_K٥6_U9Z*2u 9܇ѴfbÿݹPNe4M64E&0BҞ [AdiG_[ټYҾ^#,Ykj䜍5V?6UNB@k:DUX'yi#Bƴ'S6z(rv i/Ji|k߽xIǨ|:i6VP=(KV}M;fĊ_yBJxN'&7X1}FIT td 3:=Dd ]#B0+Z`6E}0#DEcDA +EYө=F*B;"9-u߱+v"^ީPظ=Ij#ZVS^?sߍZN(,W{P VMOVF=9*0F/bӸ'uqGE*X.Lޡ$!`:: ׫K=ɛ}Mu($j26M wlMFRƙVdrka,ÇqKbmRnW؄VΫ,"o{L+ P-验q~k D'|URlzAس]mC=m VcxW΢9{p"E_oH?u_F2<&5Y"Q-6cb &&HdtwJY6yHPTvɜ὞U|-ڠĵ$&Lb[7[T/d%ޓ]=~ߏ2'`LC ui3Df]OEKZ_ l.BL@B~(崉ETBNJPgti=G8ųu݄C4^y &'mP4U/BxvjIwj8.*o2﫧+2jS~4U/7Ofz Q[|ߝ~& >xV[,W5\g,7Lԁ a`$[,]lq7NIRy+/=H[*!J Q[ljl OB x#]]AWXG⟕ gv )$?<Au15Oaz]|ZFZLl5\ 9n{蒅Uqۢ/ fW`oG?wRuZ''pc?҆E``gf&ZO eM|w5JStQ3nE% ]ku ԣ(*|%=fkؕ?Px'\0D3rn2yXKla@Ht#3QcL*8Dp_?l$LM+gcî.%ٟf b7jRᘧ' } ]r7 0.2苈Y:1Fe pAxCBp",ئ$:TȾaZӖ+=_1x[_~nKzdYD=p9A+7uYT貽EЀ0baEe8!Oc$=:CBM:d Ɠe$iہmUC|o-#ϙj,%2+/˕ZUyɋH)_;V`Vt7&mUvKqI\ &Mɵtp=-1-b8Y^1n[l`\!DlT6pkx$4,򈴮ӟXdH}ǽ3Sr旘_@kz\ MOvSN'8Bw˅%l) #V\\{4l2:;/ LJ 5]Iuo~e4Q) /p`#Mdтzd37}Mul?=f%eN,ס}tϡl-D`)\# ]bCg2z%]-@gЋxV<2cڇF7>?XIm8g, ?(-K`$CE@jc9#F, s=J4D s/8Za瘝&EVO&|/627ehă[8WHCe,|jBWOK#kӮU, 9xjlۺ]kR9II2n04اaʞz<[}+dtb4[u8$eH:` 8@=rpi-9YOMi[Y9U%HsۗB-p +SÖ4R+JvbTkWv/e PPkzo̥U"}'dտ!Q ̟ΐ☇HǠS bkE}F5*ݯ+ ===mX ϸo\/Hz6\E'`2<*7WzYn#t܃*.:K& 0O ߼_Ȟp{ aWwLsUaL m=!=~7A{=$Adju8Zd ˑc+yN&QUPIJ>U[`ީR!Jx{kn+sΪPه}j3ACV #)KlPލx0-RϾv*1M7Eദ rV>|=u۝Ml@iItG5ʊmC6-ҹJ7<!q=Ɗ+DS]zHOx*k+&t%#93,m{[di2(BlmkgOč;0N]e:]o+cyĤNPD4.4w4Jf9JOBbGh=OTG!q췑 /A`IG +g^I_0mUcCO`Ӱ44!(̊;Ni}6"#@#F jtr4BŀۨcUB9il1Ik}H_22~;čˣ82؋QEW0.s8/LU_:`Ga .#.efJjEUQ'pݘ]=r3~O#UϊuЪJt9b^K~Ϊ3&OQai=ٕ."72 -:<{XKL{pWzxn&F9`_e6ckv ';.BhCm&5Lh9s 5,ܗ(k Ѡʒm4ˑ!ct %c^(3]jh_h %e8T+R Z,B+/NJc[B.$B XO\~E$U:~뽌7G:DDOt-% Mq^wq O:AeR],Xgs&1r6$D΅I#3;k0&jK{}Abε7G7'dJbw،HG 1L#+t%%˗mF%rQP.FBo5X- KbI˟SlPQɪ{RL{L!ȿ_Yl٨<`716>1-,aϟƛ;qjߴ9#>/]"q֨r'M &IEWWS{ ۯ灜Ds`9Hm2t?xNi%z dBצ$47bROEB?Ÿt*8[6DLy.QTW$F:x2Q`g>ƺG]6xDjXCSkKC0`>KCkQ8l ciL ffVAD*,&yO ԇHNqҳH p N#DVPt\ʔp>'3n!f( Хg_=zAR QJʮnna!W0ZH'iJ_#-CǽgwL0BEBvMk~Kzv}k+TvVbNnft zR|=IPw5hRZw:p֛"*allX=H)f SȼKQb?=G!ީ.ړTt)doGG=T Hœ#aLD(RU, yrb!>b]\ÝȺj&i4W}lؓG.F"8 ᤩДdj0FO,ŚQ9.dZr׽&YÇ{'%ȳ(C,{4::f;'(ŵ97W4Į()|R9"_]m6{ϻ!\b kFRRŌ'uzY.B'廎UQ6xBA|5SkK#2n/b$Y'A* fcxB=t^)U _*]݆elYu(Br>vbSfrLe4?gi(0YY Kۉq$|[TV@\A<\Sd{ ׷hx#rϒ8ԁ/~#\KP%GCnAπ >QP)7kuPu72^'GJ9\ֳ5: B&-G=Yj0#ѝXİ!hT8gaRF"_ܛu5!Pb2eqԸz!?IEwIglIt%J#Gz%Y靑ߒ(ҹHR2N[ 8B]7wF>A0#gAbȯ@WjƨDdgB삆$Х8eGh; 2] eRY?22<ϕ!pHrLgƳąW~A1=V6mclrԴ[XvED6SeNSƓ ZDS7&8(TU0_D iZ/076u|R`8w>[H p^)Q MPU[jyTA6SLb4,>0F_B+9:gPFNQ&ƊMpk-Te^o'13 I?ϾzgzFP#\R}ى?]EB5v폨@lZ5*L6MIjQivlA`wyJJF0YbqVRr!_ͣ8´ƚ MK6hȎQ3DaݤieAker(Ae(;|鐽R.ϓwF(xI#MĞ{taBDFo9S=qfUy ʒ S&GY[ r1pDSFm:9c{X=$^2ˢjUwh0T4Fg.vI)˥̧,ʁgoҘmV^BKKY1pї8D%'͉,~"tt%c(AWlr^9hbo#1ٲ ڬizǯWݙ:K!YQR'EQK~pJ׬gI:/|aV f@N(P2bump7[Q:77e=k/x=_ΏU?6=7>Бj_@OWz }xI[o$+QH+Zr[*-d5g{?C/ jK#$c˙бyH q1j1ضؐah+zRb84|4N6NA3XX5Hh)u_Z`bRup噺7՛琡"0zR5;M# 51u S'dn2XO%|0шSaT^/ n')MsrG6|kcOT}{t'$\Gd50'UL.Tsa@b nǕ=It<9+ZExgv2|1RVAR+RѩJOz":e򲤔F nvbp:)? tx_ QU]WgH!ANECH xw5TPP0 Yr`CvʜaϲͰT s_-C?䮭E|T,"A#j =qAWzp-M*rmcz+jpRʀmƕj.1!"0J{m P!oS4 n_dOzq`JޮPW Ok3jQ[c0c8UͶ$YKԒKe`W|V| eb6=`!QɟȠ^+p6#K.1>fyu++Aa%<5֡~Κ7\.ON*SPS /]Z׊DeH\@!F)b _o2qy\`X g* o]Uw*r䰜1*l ,TWC`&%؎'H1=A0)p~݁bM;adRަX75dwr 2J,`Ұ[ |e6fp )[iE&<ѮVzYvfQ: (W Z&(VM7WfKBӠ}z;^uE<6P!fY*HP0 }xDG֪b_qeIFn%z Տ'ݕxϤY& , 'xFĢ\8w]w0kUҎA|@*qk*B6a.NIe=>CN_#EEh.΋{]Y_W/S%Ry5y :]P8V[/4p$k+88*@N&@'"Ǝ\ӑw 5MpT_@=!7ӼA?H% ,cMMZ~fWFۥAŌzeW%*Kd[r)/;C @z؝͗ۓ'RKAw)6w0-.<Okʌ | m Dhh!Pÿr5kzJ׭z Zj%ZN+՗~LpZ ڱ#1:+/r{bR*J^B9G<ڧ)cN@%0\zC%rtml<=f'pM8yM֩,Eq7+Z}6og:Y.XnwE?&z7Su#'F[!<&P@L? +⧳z{/-LuQTeF?‚3iF;k7Y;s 0[Ρ.lfUSI4yv;A$u]듻4$v Y\3+< ;)bDZo`0R˞#!V(LX`>g"y7<Ȑ@٣<?(%: ߍ`Q4u=y+F9aa5tX@ 0Hz!ŚLSn3(+%묨p bU%rSt(#Qsj fq{vur/xKb1{^P ).Ŗ u{,]| sx.2yvP3-AƲtQǩqz' 4lwםl',}m51:~2FjeʞدҨhnLB'PUodbp5E 0M'\z<`6'wz1"[, f oN.XN+ ­02jNrc:r&z2 !Gyqe6p8%sgbDgR}ƮoNqEgJܗ֘ oY)D@2vSu`ޛ1<-9 څT欕c7t;۞y$c*z_j%)&lG&T:`+L¢L4Vtk0FJƷ@/pފ!fx۽GO޹7(` Fg$4H[ul CQ/YØ8v4ʣpOΊ 5 w;uʓ,}' "!O:tJ9y|H=UY2:Yx'IFtDMY36Y Ug b{mE ގ;{@ȚAR"Z C*GF|cd`ЇRӯ3WA?uaa_Q "BMJD6ߋwwlubjH@٢X0U[;MmRڈ9Uݵ q[mx/a8rڄf7x?I?_0q u&f)!QA OrOZ/eH\'Vi똼A!J+9=3uWm_U\ذ6+ȓ1snrTn׷s[Jlɾ6c:%~?s@iU)UF@@$̢kCMQEAV0or G{a{mBmxLӝz5||׵܍rDXj WOD[Tǥ$|/5#^FfCoo4rswJUM7ϾhB47̭,,O~xhǶ whO ݎqs]➠v]>~}U` ?_^*FPk1.Aӏ/&5Y:V4@>'u˞,r(83z+1WϊrL83eRKҩ3ӌ)F"0hNʬKrV+P  /w#)qS?}F=@z2!riSRr|gbm,>b)wƚ-4[&Y$t0ٰ+qӭ'.RbI GrfZ6!. 3`CUՑ"T}W4X\p(0|+Sy2w*/y,CBn ڎU45+>_JE)~gi,d͟:z& WaxK).Y#9!u!4u̟.C~[ܹ6j|io G@LioxNî">uN,#FF1Xoik2>hOWlɯ.㞝dm]}s)M^]nI])Y1Z"6Z06z胤bL[ۓ1P(]ɘ#+Sv>v;_džza_%A٧`hnRw V!߲}"lNF<8kؐ䶏U->=#ii;檟˷Fk՛|^0jV"+bC۔0~|1_*QmGpm҅CtoWa3pg9w˜LQ i;En.vuLuH^J顅,,B^FE8S:Ԧ{,ӇyFzQ&3JӁMZDm4pc}eRFpphpBgO-T 5Y@,i MBbcRL8A.Mx֯`OFqz0nxZۗsb7q8OzyX"{wK 0Dz0swqmO}T<a8^nd/iiR`19d)Z$MΔ.. “q_ p}k|4Rs݀j`D(9$ZwJF_<:%>up<NQcCh3W] #rFyB̦L_ܢT :ipqM!qu/Ff O\F0]/͞săTg(W"r`ݐBv,(8mSEm8JTW.GbK5E.\vKB_0ňfC8.;bu>^gy*cVhQ) tVP 3Βw^9YƓ k!cVaR x3b ,!yNB[fʩ/bqpȱF! )tIoJ\WُR29SmN@LRgqFeE|<Tp:4 &dSl]ŘB=@%MF?2urfg"ߕ*#׆IJSِ֞+sk0D[B;T0'P%t}-MO(},S5N/MCOt|c,\9K'.b)$NW^?h>o\<&VvT0 n_ qXKʐ7J7!h+z%c#q@tHNF9:yIq3/*E5p|D%ȑOWFMfXNY6u?~O7Cw y\f];-!gU*ҵLsr' :f$Oȁb(Pz8OwneOs4'Z%q+\f ~fgtd}6J;U v0Ǡ*gUnxuw?Ĭݬ R#dlUՙ\Y[I:pA@Ylq.̘튼D1#8JYeCV[*}Ș5 J'(hr01R0xn5Pg ۀ]~k9'kόO|-tܙ*-_¼E5yF92EќP*@@NFzj5{+v>e91kGy T-m-#\)T([-8C1=yOC ʫdv4#䶰X[hcy+6`!!t4'яst6Q4Cjf .^dNr5 C{iQ#jc~AD`@ۀɒףCKe_2V`;-& /bTᝨzp߰z[3\E΅Z"kHV*B'( ,:%!(麰;JP7z 'Tѭr zxa7YJL#qgL= so2C,^2}Ra6K[EJWezGwB"j҆♃~rd2Fzi; \nD8Kh^jl1pX3-ȭ[,xKJdj$,f;QHsE;ld ܜҮ_-e]9EƥvA`(z՘$072GGn\dyq?su' *h^ClD @KV -˟!lvvg휩·hw8.Vr$.F\WoɎgm]Q? ;Gr^csxܵ?* 8`&T;%x;kɊDg(ܜ!AX %yFfyH3^(&DYQ m UxպͧQ[U3ht6ׯ ހjm@գ_O1Ԓ6ғWlP Ii_J `=@O-<-/ +8l`A|+}!cZcݴ(עLPmϨ{`=_PQ/#d./T5 y`7P[4 7'D5A"`NOLM{ 6׽gX6IFk^b̥1}Q$ *TY9DO zMggO^O(>)q|#F4]s LjOA@SkU|0%N Gk4kȵ-2v!#nᎿCj ջ`޷\%a9(q(0UŗLE#gF^ݙ@tKũHLq \`>} @Y= w]|"訝T-/s#2(MEAG&-ĺcx4fɽg& 0 >q$B|ޢCbjԆc^i'ܶf=KswLΛѐ+zd-ڂʤF %c`vp!Kh3GzH dn:O|zuDPj "GܔB[عn2;)C#0۞_@Uq[nC z6'}$KGZGFw'ZM:4EB""}:Oi^;*>+^, C`sOmf3Te 6q%9Ntg]\&G/D0.:})+(M1`Am5ҀGY9M J&t8f?pqU9Lopo|ea7束7t3|| )߃:v};04.-eݿkFC=&18iQ#+}c-VB.Q(vfE,dm'pw/ HS¸a3DY8ҚO-> voRODd y?Z[i`=d-2ۭ 8? l$u=0)4*Kz)@%:g &%:ShVA [0&w7N+NjKVqbs8)1}LK~yfd,h#Êhۍ GmB` dzy4pl[h"*N@=%,<=VO6G=KkڪˀI V=ˈg*/> ;?|WQʖj7DZh#l=)P,X19\\z@ˈtr o9cX@(1M1zZTgM69%:},B=@2D!cmFO9N݋R\PxLJzF(WAk߁a_^`>buf6sɘᾸ v;l'iD @rbFA* G0%VGy"}^o<(}Lw=:?G\K0+hN e;pMTrOØ֛(qc@RrosΆg ȒO<îZk AJ?|e\J61B A8?3JD^aEtatkOhc87D_'X0Ԉ~# lC;mAʚya avɺapGcjbq~: B< gV$liAB]TxcHvQRľf׋2L~ܸ"29g)%w%RMڒB:Wqc^s?8؉sK@@1:YؿəXĥIV}- ɝltͪ+85z1_( .wqBaI TTƮugN•R:M{DEcWL/몕~pU^4vm+&.QQRe@^4}Qϩ ~Q)`t6#=$ZR'&V\Y_0$=Z@ >_|K w:KݣIĎ@#F M 6S}v/@VC wwk!dZ Y^9<_X3MGj \p<kp'ZJusn feyH@@$Gk ;t솜 . ]+u'5)mӝN|HQ 6cek- įʇ40MPy}'Xнoy]{IB*kaF;WaדҲg6*?B|bޟw2ů s{`J\:?8!j'AUF;J&u *#YRd > o lB9,YXfa[yNQQSbAd`o&Ql@KS,CTR슦HwzG6䏤8%3rNV/۹!Rrr2cҷ,>JI,Ĭ>^ jeP7He$ǓwHMvQjg|ֿݕ_\21hjiR-b%2]Us:5 T) WY1y+&C8j\,bԅ̻|s(,cARĪI 0(6933j]b_`0ѿoYd AyuYo{fs/)xͤcýd{Y!b.֢/6҆3YGD!֠@n}z/ĸĠ^|cǤnx+9g4sQ17+UQbxa qK+5(Gdfi~9hPf۟!Ψ5eɶ1ei`2ܮYfCk0Ae( o(W.n:NDp@-3V21#'A~@0WjaV(ki L-* ާ'0UUf<Ϫ)OoMJ{GJYlO<<'$7dA1@eɻTehV/h`[>Wxgaqv kd-gzp$B&O L 6FAѕF aMhcWKׄpR sWs^Z: '+5zdd^ToTW^VpD"G< ^B `z! w7;f<;+a*efz <$m2:.z߆qtHdrs@LSH mͦO[1DǃD#Aيg2n@-֟n?p4$Gy9r$oP~z&aHͳPZ{Bz4pp$=L+P&GrJ6΃rTS\ jm/+'U5OXѼUiWLي>Չ#Y5&oǝu`^=cbwNds4M1\Jj 87_ܺ"@%oD.;7*z?9lSLJq%cbT>MydF\[[Km4HN:ԗhsytpY![- %p2F9Vb¹"}GyqegWW~p\ R4a!AG@R<̝Zzz_5|}V% +F|(*|`B=rJqv,W,H }N_h1ۀ30Ŏ˘-,L@\E >eB1%ɛ6aSEOJ<7o +@0Z$ @WSg oTFʆ~3 ;X~w1pW,w⟎'Whswud6&k ( (-LMr`#Y*D= O||EkֻI?~]if?M 'Ec0] s!gQ橒Q2]8$ $ܳ앟ieecs9ͅ ]SspOrܧQ8>җ .FTMԞ09g- ^_&I/'Ea!;e߻?=)}1I7Z1@*U[l?E& "jZ*[ZC5j}x]0RyJA(OΏ pux`ő|́Lc!,t_En1AP6 *&]dcZSTvwl*nL)ƑW'RIj>p$LU6<=bc=z˓}+D'L(vd6B5_K'M,%:E G뙌Sz= 7Z ai0ᬺBeBAe4hsBzV'ч@0ai~p@ ?cz0 ӣDn"mï+Ü9Yُ V>}nrMGzR B0G tx ?V"N~ܴ DBt@Gg-ɗ$ rJ =bXT7+\ޡ{ZBC$HӃ\,x*ɸ+9v5)=Z msh@sO2'D݅q3U4èmPi e72۠*`&$jgY~rφb2.|ǫ%:c<Q>V;}`,,EKP]:cb\NK7RwoKVҏ!XySӨw(}.R TghoodS((|<u [7*( *PP>4}O㬸){06,TytJ|S 1/5_KƼsu 8<˗E¤C iyrŢSvi4сNLPT?͘=^H$&ҢMF,6TDdfNY*_Iv1W\:OoA%aq)-[тvc]*DX9C.cG@eВ[764U5l@ZPju=^0YW2#8d~۶]ϓLϰi+oqq)bfIPf(@I򉞎Lëh=_>ydDf2foob2:N,+^lsϑJh}䭮rm"yA2̵lȌb%lp?26B("d؛9?Q;(yE$W|R7kLc5&jUCvSp~(_rI?:2¾/,?>m/U͝S^*G5CNPѿ_YwS[a k?Xf~B]]~M*;.DcNZthwdA^cBeo Вm `-zs'cbڤ{<w݌&ZͬMf+fv9c6FX@>0HQf|Nc@o)ۯ6+ &5sp}k[OeQGy>=S܂ȑjZ-6í#,}=-KnܰbE(ՑXr/dh0`nm^M{cӣC4|B|x95y1ygQti]<4IW?&!tFG-!6ziT7 '.8IK\Ah"[RUʭz}>Cjy:VW iAhm!w-ٔMj^ub_жNj ʔOq8H0-UNXfZG{[H]{";NP9)EF7X /_ wp8V1g4=N`{5HVj ;0Vq([rZ80}w-KY6yAjfTRDjsqqOS/ձ"dlbPß$ =MpU?Ysdݐ1FW39bߎ b@HqPHU9> %g% !tn EDAD߿=W s+g<ծ 9CiZK?e2>J)b/D&udSḶ́oC{G;ʓ%w``J"^e6|ȸ|]j~mЂ8Ԙ "_s6kbχNs$D֑Q| (H0؏DDXw|X*snzNVR|iueҖ'q#h"1:QHJy 00щv% 8.SZ1)?AAL;MZr/X|g o%3%{/Z%Wt'hԫq/;h;hP>~uW|pn8]3ibɜe>f1hOP'%"ZaZAuV;[7k1]V;? L&ø&ppϹ>'IsŅʍ4iy9]Sx"tk^g_a YM=U 8ܗ@ 69AD?UEȔ&t vbǕ2k$ƊŚj|s$2z=bt/3 #J3p4S75s';yF*.y-NO$0b a2B Vme5ҟݮj#kР0xY}qnd ';q/SS.!_q?Md'4$@?yS_SWߚi:9PgѢg[l ,!KָoVkQ(|=U8FMp[N+XG ,4Vr_A^vޢ:iRǚS^u4ɕ ?b.UŠ݉wvh{#֧u/v:.52j&ujb`wD EXŧ !mj+Z,Phc0a˖#Pdpz]7.*{ u̴T(c4cY@вݹ!3* ox4?nx%9U>6' p3Vj*tlD- ^'\~!{<]$`ZɜF@BRLTˑ+#C\ %ؙ/c}{gFuX_o-dd, f#\yk녔Y a:%!QS"ޖs- |,)ֽAhxu i.}>쵵z=׃.maPљWڳSI`/|˼"TQ"[ to"U1&3iuJ{aE ־`N\*&]TzW({bBSvU}aV)|%Ӑ{C\Lh'B:>QZ,O ]f6`]F҉Kw,8f!e6s EcZL0(r vp^~sqQ^h^1^sš|w+m)Sa7%mTr nH2?\ J DT1D8`@k:u1TAmd`*\[LvB⸑q=RMޚG~hWȳ2RoD 򄯫K~C_2]^eIe- fިO H_(B왜x}-At{Pm_UbTwr d W=G KlIj<īRprO%X ,%TG[$rq&{UtqCtkq0783cAak;|A447,rf.%D!-i_,a] gp<"ԮS*:b? `[T l.&ۻN-ظA+r*e)*jf@J+A̻Qƶ67IUzcQجE?X>=bJۙ,Rfc>]!/aÆo9V+b =Z&sIї+0ElTRdM7=J熏$ JAU,uH]N(WU)xMyzÄsXH6fP9qh9s#YGRp!%Y?E$k%Yjj%KTd"/FQua;``_nhy]AN;d!5Wh_f{kR,hj٩7Vo51QΧpdI0qYddTJs^|ܷnQ=h#Q@ 'oVa˲m/`օl@K7L9H?D~.;G `OCѝN2 %ruVa_'|ѣ1)Yezv qc6tV4ocn\ou~q“U0 \;#A͗~jWB $F4oWc%S0?˧ (JB`dݸ|t9)K,)s3J;$@Qa!{v*cT rWg*L7:|񨠂5&\MꢞX-nɍ,D%NPs6;Ӥ9[S{LyZ{{r%АCY ̬W|ډsBBg*qK&+H2m]*͕xCp#s^`w 9GgKhCe]W3 dez!"[ I⬍WIг)!TDcB#74,h 9q-??xMz/]4v[1MemSB,\KQ<poHsQ%ݞk$PYPj;%f1Jz=o{ӁwE8VuH`7.2 ߃{Ki)ee)<,Cָ| ܉a Uq{] ӷ!cI vEҰt A'ChfpCxDv<^srx\? LGهlz1ӂdЈwwL<:$k3+2WkX%"}\PS 5Be 40yn1RTP?{?i6TF69E4a|܃҇,1~ɶDb'> Lkoa:6H}@튩aC-ϑp>2DϜ=t$]_lƇkqiH^#Bh6⸾KWyu| rvx j C cdz(I gw3 yǣK`ʻ:yUᙶg%طav @dsJL ק%4xf/,򝀯pcr ;:#fw̺{/q(N7׉^d 9xa댔W/1Yb%N/EѣXM`I#Fcl{98 w%͐K*ǣud.E^\FwU!|@НZU_Z yuR'x@nxɆ> &45.Ʒe FB{͸gr"s7 EJ'x=@Au$]cYYu#S5 ) ޲ʝʞDgRL/vKyh>iCfxJ7*\갳$A^vWr|^Jn%Xt ▸9?I-dn]sSq!Hm^h4/|b|T{R$6U&+90dܓ)l94wضqJ]cAJǡw\ t&&>}ʆo?M~/2)F'-KkNk xX~ELwOSpAц*e1lOE:?X.?xoT(DW!;ӄ-*=ѥ3d1}4$h;2ٔ X^QGozzwTGtơ L`?o46!~aLO_00Wʸ:<Ѳ~ҋ9ZE_Q{vFm5] uמ;^dLj5obZNgnmm5k pL+k8  ސ y1nMaX 3 |q$ ec:@%*bq&z yX3]]J擛u5g'tLɦjK锦Udq0tJ8czߏ>Zd_L%LܠFQVzѶuveX$cd }gq7@|D{X$@Z=pnj hR#"V/פ;]1K>s/QusA/Suc@;)XɈ7Wm)|Fͮ,c,VH/GG %g0v V n{}\+geXl}E䐠up/yZ±֌\ՌqmRDmlA^ ,eL_)iA`hk8OpgUλ*#s̞z˳w|Gn N}7;X 7s)'42 drV8=eF`.N ,tV y IO&Z&.tUn' 1L;|8-p'hOZ?=p 4b͝ BP ݀OBcn 9]3!?Kf絀ʲe질+3S$hC`9qFJyPORzaj-NZO3dgNMkaY9Z0wζ ^Xj!j65nGrFı0d/"G\x4Xq Nw[2/ʼn#$NO /Pͯm6f CYoqg):@ݶ)t4qMiG}93vZVD)Y$@* 򇀀5 %uSt !s6\=po]z2Ju5r@_'OQKPv`UQi(s/?LBUc=7ny4[܅i\5sGr%ۼZYaO¡_;(KDf+h/_2q#L>kݹvnNZXLz3M+tXfo]E]W{t݉ˆPۑ{S3_R]g@5G)z HcQR٦l(r)^sܜ%*+W] |v7!I u$p?y_Oi҇@:*[5YHЎFپSiټtq@yA5 3h(Ƽ4 1jdg`PPFʄ'A~BD˗]Jbq֦2KF ɅI5' L{jLC5}cW1_DNK4]Q&83d4,UZ# Vws}HIG؂ے?o؎*w{F#7y^y`EXQpx^NҝϸP KգKpcim,d%kӣ𡫺/δ[(fY#xD90Ա')՚LXӜdYSgue͂(pްPR@oI4fSЀjd>vY8rZ7}{e1P2UH(a>W}7yv/W~ *+U3r^:QYu愰Ѡxآa"C8:ꝳ KTF.Fˡၢ0s&gLbsƳ֛PZ ПV"˥S\9/ܻ#עf:$u= 3'`UW̞c=RLn0 ņ]SZWrQN!1C.e:ȵo~R/C( s8ϜV74@`˟|!B)D}¯7cѹoz!c+eY #|GOxf@z" Z< b107ji"@D=hkΪAPH"XGUdZL$crCWxJ6 6@im͈h[F.;ާS'rM4m)cq>xL[sd;5ŊS(.9Jj9)l H=5IiڐCnlu(;r ` &0ҬhL0m, ,)rP&gl4*%; ^5ꩥI7,X7}2> ȑ.7mww7tĔMO§Vdȼ,V}4ߏFIdkKs,KXO֊A/xCw(BtZu"@}T9A:բX"ZmWB'V~*8/8arTc"8Z( ДGxϸܬ `S6ՙJ*HJZ {هfuMJQ]紒j`(XITm뺬 ft1yiPh{GЙLƀuX`c Ș,N>DeB}`=WUh/#ʗե4E]Nn.% !?K]k< - Q! *0|9/~Ky7~LJ6V9XX]_ oGN?VjchWiZcm ^XvDƈYVZu=x?M ?q}_p)t@_:=1+%}]cFV!1|zu{e5%wIJuEH@Usgoa5<doށ6oԇeLP>>!M@mH?90kܕA-L%&LOp$C4%l|AjՃ/@G|B\Ɓ m.RMwXIuybb~k2L7Je/'fA.aBFyRy:SY`S^/{tW'rX5]Ǟ/u?qD'~V捹~cD ڊUd',A_̜צ ײܘ~ʼn{:g?='RMs_-t 4bM\1нWx4X^98L,bhr$Ue}DIGh0$kβQ)5U5b%5qf CF_Y)R 2zf!Ő2d?\Ef8~1:ip Ί 0sȱwG}Y ,tW fIov0G_v9݂A$i eqզT^:D\h6Ⱝ7=:VWmTVC3M_c)-f_͎1)Z#psz LL]q][J=L!70lRsLp䭡b#Ϲcbq@E]"᠎iltm"f9!`#|yCY ♱,4lFc`m@Eh9 W˿Gn&b`L`.J f gZT6H;O?yոQF#=^H.Pm ||Qhl^A<D@ԎbNBj\)Q)mD2HlIۧV N(|5P~LHPEM>ۗh]9Iʖ]!C;.t^o2ڨlWh[el8\s gHق#XiwUKq^ʲRF){f5 ʙ(I Ŧ,MQĻSJ,e|a=`C!  v^Pv uV~4I JNuC+Icfd9><^TM7$}<6![[0J^gM\2id@MPj0ij"8#E?sE&i;D2'GE˷[H-UgAwf@MXqP'}꿠?i8>d9ß @{9ƍk] Y1ɀ,ACGw - BX9?ǡB/e2h;DF0dF_8e`D/s hl=_8ncSCrsͣ:e,"L4~f^;4.IPw3Ua(v9X;ڬ_ảY$hpa>hTJ Jm,Ac(m? .q(\LpSx ߭j jلcIL_Ķ4$8"Q?L?HFuaI ĞAvRe9efJA@k^o]*Hɩp"B5Q0 dxȃc &S4G}.5SDlݘY9C)jLw0(7`i;xc+b\%{TG2M -O6ApdQC~,Ōq r1) 7lbfcIDž?]ٽ:ߍj+r W*N!M=V AqYMetM՚;^Jf%O6 ,E>y&kW5/hG8D$b-h ȑ> Bg## KV<'ֱu;+ *9!Ly(Q-LMhl۝63zNZ3Wvmӆ%?ўނlv߫?חf~ N)Zy+ ksQ ӻ4SA6J94-u$b&J]9~Qw)>U\2WCw%3if̂k8sxۺb@!}e97!M5̙T10G,'^+G9;rY9U\Nƭ@E}ߥd1aάNQ@a$k\'Ei+=RȰ0*)#EYr Lc,w>uD.YIAg.Z(Q~%xؔ 77~}s3 pMX"JD9LV>f=괒tAs&PLe=q'JHf<(bg CX&J@V2$\-rYe.eЉQHEٻ=]Ai{_9Hh䅔iaD2$wEN654<չ{얓Ecf>0`46a7=b5#gr6t|g|C:mnC"c 3ݮI+u%MQCBER1 %I0ʤU:̶bžEdmZE[^c=;R! g&"des|Se_٭‚pdԁm[b!4#"l'G' .nJ7A)܉]L;ɥӱkmE* IL񈻳W=+Y↢5N 3';8_<7yj -nąrC.KnlՋvksf#lnp@CJi6'QKU (2 a4!m@4aٮٰjQJ pG'1dUL7&yԸ%ϖK0 *T0,T/D 6S@rU ҌkbkjivԠnkÒ!VҌ2;hU(&OJnVk_t+K7Dy_'Kep*P(䄣OpEYWz@h}QVtjQOjrY>tl{L k Ζ"ͮq6hL-d4HSSJCĄF˴C7k Zn]>-Gg"-  w`(>櫔 Éj)'ɣޗ霞[ᒠ܆u4^UK~6oglg K~j%6W`xtXe_ l5ߛ:UmśIEpm5{1D͵qN{N&;l 2rz ڬ(}Jŕ5$_Ď>Em>Brp47pQDY" ײ{}1V>8a&/v( q؉tR6[\bMyMF).npG-fݭa#Zp6 Җfx8CPn;ɹ:l,'E% ̜[#) xd7?yJzvmGv-A%Cᝐ{ \ypfPPJ,5a鍞 uvĄ6#'rFг[ ܒ[5<&Q_vamOmnECu'PԘPqo%K{؆.B obB$d' mi5)W3 孋ctYGby3`+zӆ:LNDZJM^.{.*V24zn7pdu{kɏjҺt~18D@g'qB-M뎦5-(ݓ '_@68E[5twy%FfWfrHbGGu(>~T#ŵh64~+~VVMeCPdMAC?l."t{5UQ"? Q~E)f);%`;3̲$Kf}{w"gшu^D|8I+--JS W9da sEga\| a]oD:QBd"l15Um|2\zmԌ)YٽnUvLO@S'w&}{{F<~Vm#+l27vH~a VMxYn7e۽%Ѱ`=tM^דD ?uU\MEKt`j?.bYdٴ(R<>VC]B'i)d/]}c>!1ep-[.K,=}*W!k(Sj# ݄L֞D|V}R*P:m1#EZ}cO~UGt7~zջEЮxhKaS/U"ycDf jԹcQ#្Ţ#Dϋ!q^c >rj$*Ӗ{>ݍzZD4RȖLG@QZuzCҘE*R3?n Al?jUO5Ks+J43ry{r {0R(Cqy}o5b_GX y@j Z+ zx/,u2B jzM i,i+rU]{OC >nq]s'c%gƞ@=6 _DTz}s)ȵ*4??$xٹAPb|6XtSYqEvkVI}~ZpA ('u E4wʴۮ9ZcOMvV~~p KHY@?6\G*@z^݇ig> LDY/OSZq A>=&*)Z@EqdTLǟq5Uyx]i;2ɌD;TySTV3?V+c V\\B>,3 jTצXrJ/Ja@`pk|NCt7ȿ#xUh M>9`.C$% 說k-:J׊&97k%ʱAZLC'{r2w0az c0 ؔ aMauІEa8U\nQDr&DPj2_I,Yl]ܞN!͘3J Q_qw@8p\3v|GjHs>JIglNk 1,}'{DeT2jNm2fYx*\'||{ȏ0FZ*0WM*U!.QG1KT5ͧ<?im]5wGUGh소)qҰ?p5Sm峻+A!7f~d_|.Sr2M^kT[.sɞ8hͭ,[^ *U5,WľA_W*x W`nNPyJBJpj2d9V76%)$)nl&'U+ k~:àc&S 4y~P^\c_YDz9J' tY< umd&z+ )UQB-;iN+Hea?sS6ꃦkq82-D%ƣX+G|]8-%2;!hILUh|^UH%AX SG|h+ BT;NUb5%]תHSyZeqA w?wp +(gSAܬ{w!'"Ld  w+%;hhzD6qKU AFJaTXp3;y ClIwP68ٛvO>\NUEFN5%'-B„dluhcèa{TᆓC3:*S'K_]ƌyr|1eʰe8}+vo]!-xW/6|P`n!V?O]ߩNcAS8O}l ͖Q"A3s>EDE&ß%D:Hkgf,~I[^RRҼg$'$PMC[|\jM &ٶvg7AΎCnķj \Tof~ K :iL2s~Ŕ2^nM!8kh7ZΧJQuCkV?<޲W/S\ iyS5E܉KYY`&ș?H őlfˑT\'0AҀ: LuȲ{nz>G̤/%WOP.ƑFBS l%DFy\-ϒuHOV1"'q:%FxB=.$7MopUc'X4?hqNg]fϷ4yTղl i"2|Φ{IS eΖ\e>u 7?N:ZbLUj6B|n3o1*~_m|b:Fl 5@%eƐB &7hhAׯF~G~{DVth{c~u<~Uf.ujZ!H֊u2WWK-)=a/u.=Gܭ_=ˇd=W3X?ܪhǷ}FSޟE1l@(Һw'#PIrN0e9={֡g%/mF GŹ=PL+QQsSqf'hqa_>堀f @ #~R{]a'34"3٭.Hǩg>μ0w^:͸A2h6)P<ye9iTRekx u"^Dgjh9"M|&u#m~X"}& a]?nbf!_tu٢8J;qIqMa+ L2{덎§ $tgh59GiG3B9-%ӎc1>!JM|GAlI^Y|3uc億c+]K ң$CQlzPO^g G%".yc(J 6~%1 %ҍ|p<+A8}5pXNFf'd {*(Rn_^ٖ QD)k Ds @3(\(D<" N&"[%ǔgr# ;z34,S-hz?` |A${2|N{G,E6',c[8^jHqXlm>B "ܝp~zJq~ s>q6O&˽~D}"%8KQ>񄿘ZL苞s7^BV~>S#yѐqz.ߴ76Vk\+Qfź 52Tq%y]vEͮy"Dj9Eo"-Eo6Axx-v3 H;4Mb0-&XՀwXoq3m׋ja%ZaWZXtA#k0ر#"rgΘ>kތ]yPqT=YCZ!FW:P\;*>kA\:%:I/]y}rΝa}껖>O/QZ (VinA:==AɣM\b@wVZeQ NX.hn6%gh|HxA|Pdllo3uw7"n@փ uxL]+6[ reY[ 6Pa4\]pZ-W;[ juŁ$b^13RwdL|B˛Bqh 7??V)ӈw{Rg-#Fw\SK?`a=Q ʡAm+JS;Q[/ ηdyĊ a^"@s^t+ acҨڂQ_–_T@8)}-: KN|{"y 8dkKX`0_7tNFۘ-(zs{D]PeU،S e6j7S_S#dCZnxs$yak.wB՘[6ծ#s_d]8}&,(%Ӄ?sCG2򔕔WB#oViNE Dz۩.]Fu< x*x2$KSSQ16'4HjyL姽i6Gaj_'Qs[;H W<[_3Ng>plf5dG afk8,J!h$iiOVCv#5\uص #WWVdqz=Zpn2AgV@d/3eo?@}o+@|M7ޘP:`8n@v=Fzғ)έs PKWdʟ~?I-3mx[@ybYUxiľקp$]m3v4Z ++` WdtRCƆPrɸ R >л@rυJͨQ0%mC~mxq-BaY:֘`iU3v;|AےPk]aJjў_b魼 d+oND7u=e:֤SF.ᕑ?oqV^tΖ:yB|"l=H32k:RZ}ķ;[rFŰLjF f*:]BEd;GR6, Q-bA!Xa'^;IHFb#B"6uVh =Ղ?]TN{1:_7<3ê4ͱ>:K6smy:d) 2z'#48 g%MIBtrԕ+7n'7pd+S<ħ%Vnd45e#A]Ud= ?/E, r?Fu6xԾ)ye@)?@W{ Yoc<(>+_rn1Io(uaJY| a| o3-I(r *Cp[?oy3Lb'8eE S?eLR y#˼ ĕ͘+whVAޢyUb;v#ThӮcOI`ٯKX7"Ƶnt).wNAޞc_, + 8d'\>~$ N&U &϶w=YK7_< ?EDOBb Ѓc3'9:̱faV^Ά|3G.Xć?ͳL2 y2+rQ&U"O-#><L9m-$} m-0E<:81 Y0'24 >DͨZ֌&cur[k!o>bl BIbU7LX4GKy)liB5dL'yPM#u݀/?2dGT%f gF,}ែBظl^Q²`WEWR_^=9gLg4Ca90(cR º!dDxX bх&'ݱ : ("2IN (JQ A[\9 0 pE_!!#[d*V#95]N48y!Izه-g &^+( "άM3g9 2%,TCX3(O|qX(6E-vf2 }TK^!1rI]ذ`=<G<͚^MeC8>e-d_5I%-.فK݋nv)> oP=-QOg:G7{* OfG쵪6EC `QՏDeA'Ϭ:HBEwAszz <1XG)mom5ҮYUǛVY]tbXT%[_ʕjvS&> Vf38đ~էg&Pe,-'TXT,NYX4R$'S2b#6Ay2}'yYcɺ#f>Xq9nnz3ޘl;^y܉Q<\CWN.m7;"ZD;ܽW6K 7,VJW ^hg>.tO`<yY5>~/CRO>1GDR#BR*÷4@L1,xR.Ҽmg 2YLE*Nŭ啢@_6*Lh YޚC<ƒC=@a=6`d#wJꂛtvGH05]/%#u hݲ+خP)lԻ¡ۻ)g'+7*5:zߧGxf?J_f4Ԣ<я T@A'[ Ny03]SQA ęaxiu\x]\t7IBFzLBԧAd9>&m)dqʚj-6<ޮyb_gK%$j:͚Mjx'FʦK(uGFqݷDO.yA?P.!$(ńVuks 3roy(خ7^Y? >Bxlbu헛.\U!z{yvraD bR+q=aUs Gz+7_[ff(eyϰ1 {j kzRkVFt9aJU27DFh=˂ n\A 35&}S= ^>* lP۰u=7;tWخ7~|mE'gQJV`q/;gdj姶u0ُ_Z&H=Թ$5e4C(fiυc)iK6.  +"\0K\j 3_Xdzw9Ix~g9eM`K{Wk$`E"3= 8~=ڴzͮNX U;g G)X' cg:@x4l斗CG1Gx%ș/~=n8 EDh绛r y7_b2ߤ_LHK [o] iJ֖<źAywc:-5GM u8b8l?,\\5 7&>,XE1R|gҏLT"~8tmWCՖqU7ʂc;4_"1,qM$t/NVL#!+`ly=A@:tyX31t#ŝ܅F}8r y{S;I&@1 X x3)%^Y(XFԵX Msȸ?yLނC>; Í|50DbI/6KnMꞷEv{dG"z-  +˲SkhX"b# zZ BBaڎz48Vc_˦;r?nUtUÉ`FX*˓bY>ʪhՊ09L_f #<^yG%6]#=r>½^ ۟73-f8Rf9D1Y>M7RUv.2ٽ@TffpS=߳aҵ$;ﱔI O3Ζ͛3y0|I@ htgrr)eQ+m.Zҩ:;966ҵӻN?vބA\K0~QJDD; 4ls ~5Lof@N$*o!vݍ?R IlT"]qdAn4k g%N%l(3.޽osf|Sv,#HVR,7m yȸOp!(B'm,M`(R=Eڪ^-r@{o6#NM5N&u8u˴׬0|v'DZGw@= t^wrJy]:gVLv,QL7,t/uƼg0a½ xf/؆*ag9&!6:n4ʾ(}7[6wqћjPػρ}u'ʠryY&~baY7mi\6ǐQ5H sOy{+#٢>l/BcvRP(F5\NvGHĖv?Zb{xkYr5~vKztty값3)li9!kD!ЉRi 5УV4|ʡ*0qуwk[@khgMFdnH|eVmgkk>x5]ĉE J== \H@O'C@J: )fB6iP '5g->Rv콫޽5(lG[`Gp 芰̻RbE,cg?Ma t{ Hu%p*Jʶu:pWeQbJ:HׂuYJm#--P޴M ee j%x4Ir V|>Z L}ћ R)hYO2cAeCeťbB꧘6 !57d+*/T;&JwYU}_? ^~@C X8<'RJR$^LJo33ýh{u*Rm h[^{4 ;{A/ަ P}%hck4>61b־^09n9!D z6 8ЌQLj2xԧZvg1'կgpDU>.F.Yc0ZIzL8e v^׺`aTI5tΝ_6Mh2!}M * /(2>6jG?5q?REYg%OֳyI&Hn߼]gbjaS^;$]^g/sDV}"]ϓd_5%m N26|)Rs]2D25{FF}J&!q)byn+NG0ۚv+8xlꮝ-Ȓls[_I=ՀWOg >,"A+$пӤv 6nv!ͭ- |~N֙!~خ*QL;7Iպ(! ɪm Kq)C@/&%Qc%]Sˎpk֥š}iv&ۦ5䌄ՕT/~EmX^ SGVqOK;Au=V8܊My)î,zxb}_c Dz`QWrGF-͆kOPG V@R@etqc-JrX]@ck+:%h*xy_8?3dѝAy?mxms5X7ns M|~>꫶9&1G$0M WېyZtR/b3Ju2aJbz[ rn1(>p!4?=qVngHBYoci]0a̸tZI78yU&;jױ f ^,"Y}MpphnJ/4U|\Njm:m)BqB Zg'h8`0ٝαPv7IҀrnCH.MPIig7kwRT0ϿDS -WHvL&*0l4O5)JCrHJ5'"kW"~<Sma(+73z}8-o܆6J7o[IgN#hq~\xeO_^** BП 0n/sD D5`g Cਉ1'},^+7ǁ)Ȧ{|1=v)qE6N0EZhG<,G2!_~UuG&q px5盘taHsK|۲Dzwb.::tra2JIZD'Ņ6J(Pl6t{ﳈh'{W`!\:C6 Fd4VȨGcJRUP4s{Kdf2"Hƪ&b8=++DqO"vkxTNrs6%}#U?p6v}rԉ]-:@ ԙ7`<:R #X<tĿtv3z(z6РY4V{*(;@ ['[CfFφ (mն"$>]|-5#S vj̏>c=ah4@tR4J3we-֋C(;}|<{ߎ9]I(K[(&Z!D*ZOζ߼=QwCKP"r؃\hU"ds1V͵s;TS4N" dMh+S;! 6ʏ'(Q]>0 rdT堗C$L;e&w__Y/p{;ѭe a4 UF]>+8ZҙOKsMdW-]O*D\I9mL%ec-LLMVլW%X'EOQ[-N'2ݠPM{66re~}A3/>2n+@~Xh.}@LKRGt=q.havbα.5 }1Y}d6ls(2!5ۂg}P?V6т,VŮŦȧ_i QcT/Rաnud;Q}JxN@S]$K;"ƂdBn +|ܪ2@inn5bCW5,2R@=MWJ` hSXVPI\dIa^, UxlO'5[SCH@hQݐhA>Ms0L k$w$(?=4z6-@ HIİ'`-mg']n*d{VNN}$&GXuz<`齻rG(idWjjTg)(M_ض#8  y}AGxn $(Cí++} VVl!T&Eu:U]~\Z0sغaAB]]"ǙR3p!=Of,D*&t 4dU^w<0* 61lQ >xW Eg 5E4I1S/#vM2#4[;gY^}|,iz@Ao,cxNZZ.NQ[cJFIR1U;SntOĻv#{[ 9:+>A0Ў-(%~:I~G,`38U﯂Ջwmؙi)3[N~'%fܛ%\u !ci!5\I8jf/އJwg9];xo[U\֝ |QH+0r\^U\jlӨַXXZ=6]qE)CMzComwZm *`=Q0zz7#]S*d:{$B$Ģkj2*ES`e+LeVq`8UGKl TJ$)ؚjɾH( 4]Xh"Fwg0_tdoi(d #6dq*XKQM eڊDeYTXfXLBaϙMbE$:o5KJ=-uxi S)$?%)$k7HRMϾ sHNS"I!.[U qt$BWi P.KE@/ ~mz PT}}/ D^'"Z/(6RuJ#cΏ, AGzCxH:LA(v-i˻уbm8N06<[ u_1_ۂ8,׹`]5!|d̓>gmRTu$oL BF}BׁǿXww%KBTQքH>Wasit_}: Ttf34^Zau_c<)F^g|. ^[\1k Ր>v װ_S,F syU MbX ן/:Yv:Tjeۘ_?*V+&_^ls&p a1]`<(:NSTͽor`b4#b.=~O\*JX-":Eѧ>y)ÕMKމV׫~&9M!c]+6[D%VƢ_60'Hu јTz%.Q}"R;K~t׋6{Y}nݾ-ܿ"-YWx YFgsSALsCmVtLww_袓H&N\{P X. g0fvaB4=+x PҒz~c_I4xǸxAy&ZW3' ?@_:*5(G?&]/Lz[$MH *]PCXkZmޯ, -rb+/ʼns;(,mK5e 'U<z[RmC%cg|ۉSv@X>E}(QGR9A> 'Y{U"xh&-17![DD$ ,*g.Oܩd=#Fq=^e[Skɓ 0mf9V@Zt=*76DlƂʺK>ҹ B=-_Ԃ3$5K;½Ag)M,,G|q1>(&;Yjhppvw4d{"Ё6I8!eIѣXM6aT./ &/Z8dc; ~SwҿW*r4wQ߼aʠK<SCrt?g\Z8٘X >Ju {3&Wav0z#5/ljٛ W[XH~EA@ v_:mC,S=Pp"~P`>wFp~ b܈^&J1emzf"Q xP{F/SϡVd\ZW^(=Bo.jIuˎ=ӿZ7FXLD;T by⪌=GxGLx j&`RjZ@E\[Rڙ;7a$]\3 k6$̀JLLCGSpۂlj(/>2QM'4EBq>|Pf8}ȓnP-_%k~n F>j? 0;yơ4cU\Gw,mpEgÝi;N";?NP<:䃚 95]bhd_$ߴm1^j`?g\yf>ѷAU^N{T>!׿k9$b޷aRت8;9ЗX?fbDr_K' * E7?[y0ulqQ/F`\ ji3M 3)4rgTH 0peqV׮iy 毌Ђ\/V!bI' 02a$Vﻻ9(fCJjJ3My%L$Ev^RTQ'W<&[`rcŀpwhC AT#!8rq7(A vsVT ݢLD3 +;xQ'EMe~cVx_!1*\(2giS}ۣںW.BO0VfıJbDHj>bu~K)ہ8JX`%"J0ʍ\2$Jgq=n5ToK(}{vRh&x7.:M7¶Tןw $R/sN5Cd|dRx2\1 !c)OL'[H ZF\|:bZ)H_+F)f Cb˃Xؑ~E;ʊ^ .rMF{Z )*޴~;C\*n't DҲ9ƀzŶ%vR|1y=^ÉLFh7yO BTP_A`3}DŃg? l/$Wг'*!:u8o.:$/ASՓkb$xXXFaQTN9m ~ucVLPh.4Y-#\Ϝ>nKx?l)-۞,f I{Pɣ83Pq7%P?y=xk+'p6uw@E4F_нnsPYuMg$y9Vv eIᱧúZkwG[ W6InG[<[1IeOH"A;'vڦ+V _@׷ ?4~L4B EBFd@ІiAS7'TQ_#},zjWunFuR98ζ~[{ɂ _o̺r5H_6 {y+7PtS#Hl)z%}d Uc[6OlWTF),!MO;DJDc=Ys#@oȌ⯜5Og jE؊Skx9F ae8N ]h [IA7xYΏnj%z$˼=HV[cu4sCX 6 <e2 u{Iv-nK;fnٰDe&(Q> s+ ^Ĺ9~?ۃH8#}/ |no@}oC\v"7jbhpnZj0#u9R0Ü_gv=8mheV7M: ^qoW*+GB^+| t~M6ps75wZ>z^\ K*[,C QBRE=nwKFT@yTwi-k5 3ϳުtN,|֧q$KuugN&?@P_nO|WSL|q m\[(B$h\RQ NQp&pBn*CȵP]2F @7↚ŏsV ى^[~A Ã]YI!Es"j+7Ȏ8BҡTa`^ؚV9`ZL7UQ l쫛pA.MA}x=r]oOs"$6A#=jk) lZ,_F@݄r-Big)iۼtMe$_*Q445`3t> cٸiݭkp3&EbC# 2|!{#w5.諾bIi~qw[dYPR)6=vg+ˑED(bؼl4 :}l/$* zm kN1,2 9d-{Й&DUB >\A*cY [̠oPq}D!ߏ $MegH@"O((Lտuh^$Ǫ2N)u%z*!$@gFr9ݓ0K HCff LO ɨRR'iy VH).ִUHX: W)2 7VVzqI *;MF ?>}>*[eS7?Hs594yL3)q4s#G̠R7Ai,0(Z7J/0KĨJ"M֬Wj2=lpAXO"%)S2'ݟued(/7J(6hOAX =%4 h=0p ;j}b#+ْ $!8Wr _RCIc޻;c42#| *ꗵWYnoI?YׯZ0j+L[RHC"Zh_5ۋs3 .r)B?ZdhF.S(oX?}/mU%q/5C>߶j1Tb_qH؄:C #yvzaQ vg-4uT;GAy-+gHjRwW<4 U)M #dPm^BXv;kWb8 W0mxC"OY`06~/jK o'DJvɀ޿QCW"KH@2]Vɱ(IQ(&P7hBw+A]d3Z0v-T#dBGFʌҪklvOYRǖ"$;X"=$ӼƉ 7%=ᛢ X/Xe'bl&9ՋW#PtY|"kc{ T!A= ][gϻic>R)C63q񭷧fOL\??su S4Dq|iq-z |LV^6\%^*wG&ĕK3oyarr`\}up=uf,jѻiN=4f3P$MF^)Hͥ_hEX=R\cU(`ܺL9(@>6#T>?pV #qU9qUWLѢ Ie OQLsvޜxH2Xa$LQՠ =7LL)x'hoQ>= aYAF'wCҶoocDpqH|3T9b`$#Pwu*6SC}r`D|}XJڋJRٗ S87 =tV u1$Q4G`~澉Q3TCe4*=QSn l?ֺ `5+f8Zפ7ɛkl %021:M=Neez 43\!V~jCyT< "wzz@E`3{?+>V"xQ½(> y3 &Klj&c&6CI :K"¿V!S_s 9Pq({Ҕju L07Zߜ₁ⲕ8TR-2qylU~p G6CtXgb&csך[-8;cH{2I8f"Lj.\A~DG!Ώ:597N<;86T߈(kXppROCS h4ZNI^S/$WY@ex5׀jJt4T F.NҤZ} G]KS1G8;r5y[/ PN?'}$/l@P"|_$2O=ƲQ3vװ] Mmd#=ڍ.͸ѡ zU YEŏ`(HWDزa]:phkuw&]ρM+sw DЎ) N'Tar+eJCm3  @Che7y#:}DlA*Ҥoʢ76XDmEj}P=‰3`0lAkJ\$Ⱦ,XhQ3S{r>"ovvLPlqʕ8X3G.mԚo5' 0$ ibEb"-B$1vϾ -yoT@ymy">ȩxˊt%Q=%8>J'1 Kf= *ʠ+3.,6^ק\.TWM[Yr_Hg(2G.^DP!(! `x'/̓3;,X=Ahh$]{&+Xs!uib+f6Gj o, Z Zj ^$8M8Yqư6!Y {}q^3yȪG]ďaq9fq>.~纡 PPFFqD[%g{N,[7 Vo!At4 p 06n<[.|M2[ѥzs#drաLK4Qd >'8؜(2o),$?~q_ GAR;>c[B-p\4sEr_=F"2h6ܖ b| fTr7[EV%;?Rj9U52B6M}f^U󌠱l]~Ok'`e^(˅<ܒfZw.r:0'G:HbT;}"NO`ki'YM/+j)~PKP3/˿풫e-6zBيy"xW6Yc8^rH¦8qpƌ#=1 Uz#!7v PvUD+Ķ\W{}%yWIdž++=2Zzɪ-aaċ܂~b8֮l%YjJr^iGbhw~s .~ 5#X%uGAzǯe [<1y**˿fq@@~m`?Kw1.ԛ ZΌ.2'2ygN$ i%m q3?p?=J{4cS(GU{(OżiHY'0=(^4o)+f7=WtƨYtMR^S4[oefaܘi-u#5\M["b#ܼ͢m*1Lc'8ק20t?'5WD6ǹ߲-6?SF%Cc:64`r2D4gSĔ 閨>M̋NBZ`;nQt]},½`JbUJˣcϼaZe>}R/9%ajν@e bx<h^X_vWuc=7~)OEt eg0#l*M6!YA3ً+mr>3{,'~??11BRO6'Tjs&d[=Ktu˝Ak7tp ;GMO^ykrrEm?闦'^֕]z0ۋ)‘#BTԽb5pӂ)9ѡ¥{Ykc]Zh:3,8oB:VKߌ=SG!]' [$S7P)DʍҲJ0$98ixm`:7^3 Ƽ <:޹[]@Y6 P۫5tCMlZpS3:L:bnp]s~Kь dxl%*,nK[_v3\hjվVޗQ=%#>}V!۟#4~F}z R_Ϸ[R_z6ߧ&FD5hty WHI玱ݨ`FZcx48ڕQ6hCg}ZebKv4j?z-Wze/ղJc}O}CCؚ n6!kocG[@<0!7~P+(t땫o±Cgv+5;%}ȊЁVg~Dr^ ǘxջ_7pgb;uy{EfPv X׏Yao8()&V3B?a4LƐ*OEDݧ`BkQ8G`A@41T]mT[H hYE+~wDŽ;T OjfJ;T:PʼnWb6,7LN9?H>HD=.X\isy"*t5\oc\# >UPx&]vYkW)U^!&l#7ƛt<-kuU-Ҳ1CB&yalkt}ūmb$tDVX OkҶTϛ@Koj[ڄY 6u"[6S&0V36Z"mjKp6YVDGm*GH?N+uw#Y3]mx>bz,}VW>8׭{ q紃M}Rtn*C]-IJcm#| %kt>:^ |O@BHSWTI:Ց۳ԾT[͹2 o:Fajj+o9=fAjW6v6>ok'FO C]GPqޫ]wWȪTHl;h^6y+);L[ÌpN]v@_<^9 ȁb 1)u,~J)o*SߡH{u3R%/wn`akxSJQx؊ ukٕ/`V"]]cC̯GJA3?g|o's$] |q1CrtNc41$G v Jx7+h6Q/?:;:G.{N> 7X˃Y3rP󶅇CRSN{Ġ~KOELK).} a337ѵy BAʨvEBO0*f4WF+GA zKpG +{!PڙYZ< '{qx^E\oB@vxC#&$2e cJ< D$ wVL3sbqmznb`)nNj 11fϵڸje@ Zi_vōki_0d'i\+ISS=tKu+^^f(ԛWEg+&VPgD4ԓ̴qn$GKr'\C/{0J^ö{Fgܘ1sLtYmMAoC(p=:4h墾.h6[Mz-U%6rs& X"MHM9Y]9QZ^\Jhta (R ~ !lːs$&He >:g3F7:s=X5lM'/IgOi!c{T\&OfwL;:-#߈(' P7 R`mJY6 c+TcyNJʪ9_[`*yMNB>m`C̲ρ '4gx8X-5< 2g<`]j$:'lrvr,Jn HT4TF3\64dm M*6D%gIaum1($W+ҊT[Exr`sgE~ (,,2?[ɞ'Syy3;'H2![Ǐ ]/*e16s3Kaϔˋ?ƹa4z?y[|a}_6[`4wbBQ2 y2ĝ1Ju l˔8Msq ޶)S薰j f)cJ(uyΩߐ 4!`IGj{{l#]^ZbX1k(#mPp(:WYs=5}(ɔԣNJ[6Q&qmAN [(N!f 0F pi/"c|.(X\^ZqRO2E֍>jYư< 'KֿD08nG,g76zA I@,'T X[-LnP#'+`Ȫbg#}S,VY^ FkY%> ax@ DŽy1Ia!^%sζ1=}IE_H}*as/oFč:z^c @>,%cʧa7@C8@oZ]Hc5(Ըθjč}|f* ,-zI1`xBOk'sJkz=䣥z[.|?A~3O3Nߑ/R ]O}eb;_I\El)O(n$>=N|GU6K<G o5ԔcN(/NrfSF?K6zkC*iyMjf^Q]y{H q&OA-4K{/Մ6qa;]}]d~S l=0OƯp1 dq쐌Sm>v!-|4b|he-qs?@Z HV/;yD"n<&$|aAai*f<gt?8O70 i CT5d4hݷ"nl+toOZ^F0Hַs9)CUsH`BaVzj4f1A^,9+c+#T}wjNVWxršxeÐ=$_ωj Y.kǰYIt*ySsMl \djP.E$ ;'n2.yw6 еFA|D#\}i]'EgO2 Hwwğ\-\R:sX8jԡ=$w ALf8JL9(6ݚùܥ]&xݟ|4),?TSl&{ƒ+8 //vMKF|~jM}^ Ga۹^(%РweT4ZyMQ:IJ4W%<`d8dAA6H}L7pt*rFc]%9'E1{7(6//se& gٷB|} 7e Ȫ5{?=A^ȏD\p( a s=Tm(Jsim`{4\a2Fd0kX @FQI is2L;H m>@Bd# U[1zm|{ERlL&D`ar)+9MOW${r[KTӜ|k7[A~L4Tyl?6AjH @t*w1&}y^q4.K*Q.+|agӥ :bϩOɫ! \J )+Q-b#_W*Ntt}RYLQ$cXT>%_MԱK+挵r՚8-{80Z[gs+VbY)GڮH\ L<)L0֜Q$mRG_`X[ZkU㇮-J6)ϝg<$jz>V{e-$[5WTfKG0u0ӫNHĖ9ĎgF;&ۯ\LbZY+ɰ;E>OU+񷹏svAmY7䠹^YBc7fm6.bg䕴.'}5\D[QN©BoP"fR~ Ը2SMKI;T?1i&m0MPm0NM6PqЇ抡Ql@iGH! ][$#k->_~i0jhd;z< Nn~y 0nC+',sAVF^t\DWd!̩TV!! etbfE\fP -[fen`[A!9SUVS ξTq*^ȜB?X-fugS]'놖IXPu_y3V7 +/lWϠ9ΕS?ࣷ#>tT}-[N+Eط| }OQ^`Bdz =\_+pS419jpkJ- YΆ3 t.ɠn(/L2VIk/rTlv`,Qqhs<3=̹X~ @6y+6B6sR1$l FOWƧjZ&TXu*e[VD .2%&`l߂z%q7N4P2;WTχ>cX hvcD;"xd\IȠ@Z N-].WVNE#1rQ\iq({xLM:2dMw8/Ld&?Xr'h%/ gxhߜmmdrdeZ֏KI +-߱ Պgi25y|=ٸ`ɸ(RN&(hH"8 C;jfv"Dn/ ~T!mq%x~۱}" iƍ'B+p~&5,Q=dĻG(I~KchE (>ji-E͹1;gg"SЩOՒp 72iFt޲^Sբv8k,Ѝ +{*7[ȳ5=}N0ʵoMzr"{9߇r[!Nf,d>d-E@gLCREs"+%qעn&̙ Eg\Nva1Y{iDYXf1~wzn[?!~`{tum3LfU,2ࣧEg@[2df#'&-~'s.8=,I 3ٻ-4 &f۳foÄ(=V&u:X记x_87l2#M\7JJ@V ĠZS0hLD9׷R3E_X,WgI3Tuk"iue_= -0*잮T5LŸf!M/)@>  f`_QnD=⷟ϨU} } NH8w$ÆLk"ϚSl9각N`!%m؃[myQWbqTxrˣ  j;י Pd[}3-XDT`SNt:Ýv~kfk8]\#NgIym=pj)~~_H"-@!:$cdf"Z Xq7=X8F6zaP ͛XnS;w@0.d*2̮:9jz7]+K|fCPDa[/30QNBԫG}L`]y簻qW@ Y}+;>V&vUQYQY?%9"G:Hl`t}8Q@aN^?G~\xvCwéƖkd DOc+9ņi,ުiwg5DκBwHw:|C~¸oX8|c- <nJܖτTn,Zv gM2.:r'j5X9N_6 xPçM9 Ν={+g_>{צϾ"w_h֊j]DǰvF1'ԃ v`"S># 6bڳJ&Z2/7:WV0,ҚQptϡ`6thϡvJ߾s9",|6Y~J.r;"'![I˼K_^&.cZH56X_tpy\]TMDbQgKx CΖeJ+Y_|urm3Ň36_bwVvk`J *akhk8ao,Y</ozyܰRT+q[)xu}|+cLIr1y~ƧB3V唻|RƗ; J\:!c!KN[Fdgc%%7,op-s{S 8} |WV&3pܾ3MT:-qS'{:Ne7|cLכmWੈ6,X?ԸmkED W~kxlEY8_gK|;P6;#[NgS!dșIxׯnQE}Oq0avGy0;O=)5CԾ8Ӑ*I] 9,eUUuݚtZe=M'zq~jpejbGe@גÈw/]ߝzũ"2?^t>ƥ+oą+|߆.\+C%_% ƻ/M]l1T{cFϴ%U^ucTv^RkK$yI> b3l9t83͹~O{>g]HNRЧRy+3>  k3KZ&@((_V4^.,řGSתyrv}'z>C2mHK”T yȕ T;QbyxnW΀!,mtZmzoH Ʈ[{M_\PԫV4diqۻ]3#1 wj6n?+עO'I8RoX3;Ƙ?vS$h!2CGqLON6: $L3gG_x ,BI;E APGϔ!ZseqDTp,s+7͒.T\مpFW%→7GKq@00pkqӮ.w9{/5z#tʼ\V\9~)N_%䃤њ[N!罞&o3 ٵ3KzV Ǖ/IZd4HTqyOɃX՗xTE5oݜki'Y$r!MrZd3FV'g20Q. R:62C8SMwG#Ϻ|eLI#QQvH\#q3OFJ: T]05'هs?s;&2T;t=C{ylf5i\M>ێF3gΞ}Sqm$07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!P~_:C1BjMS e)ʶ YZ