sssd-client-debuginfo-2.9.4-3.el8_10 > 6 6_6 3!pQp)Tξ7]mtZ`f!Ml ]mtZ`cw(~%L&eǗ V?]V jRѲ?Wo܉&w8e>cw}YnG]}ˆ0x\"G Sm[HoKQD-u{6rXvvT7m&Zl%ӁςoY 2gPzԽB_H/YKug+=A6a3;Ѣfan"+9/j4+xJo>yH Qb ሢuע#;Jڏæ]4(~ L2jPWx^'q;i1m%,e˺sTŭ>@x"illy.6ӻOjP )#ጆpox Q !h|^TPfoJ+%$)Bsnκݞh. ]7 k$1%5j}jf*dtگxU&)0 \4FG!E&?kUТI^&`Q˜in$<]ӑzB;(cGi-PN(.D*̷o1JO1̎?ؼ# S8-99ܼogt!>ǵC 6Tf10|vZGk@dJo"MJ˖vV˻QTҍ^J190S/`!.M0f_]MT@'W‘HG=ob> 䭝JkQR<9>p>`?P % O48=CK i{,X, , , , ,  , , , ` |,, (89:j:G,H0,I,X Y4 \,]L,^b[deflt,u\,v wP,x,y Lsssd-client-debuginfo2.9.43.el8_10Debug information for package sssd-clientThis package provides debug information for package sssd-client. Debug information is useful when developing applications that use this package or when debugging this package.f!<ord1-prod-a64build002.svc.aws.rockylinux.orgKojiRockyLGPLv3+infrastructure@rockylinux.orgDevelopment/Debughttps://github.com/SSSD/sssdlinuxaarch64<l<S<S<t<`<W<n<[s([HK@10h(AAAAAAAAAAAAA큤AAA큤A큤A큤AA큤f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;9a2cd4aadfdd7c5e060a4eb63e5031225e26a076dd8c2bcb7f7996a67d9ffc4a4c4842c1a3cb14fda452a14987505f3da8da05ca5582ab68a5bd14d8a45707633e3ee2c9cb312402662e13180eceb538b98fc14b0058ece4b00e61f1c859da7ce93880618efaa91ba7269a4532112d36698be3259ccdcc27f67f3e80b8d7c122fdce539f2f62dbe2f0dbd900677b8766eb47dc8af7eb4739464aee50e3e0390474a2772f86834bd82b3dfb195ac6b7a2e474b6d4bc644e92760adfc7dccc122e0a1bb614afc8d6e64a6cda120373b77ecb443cb97354c6a76791a0461d2e6b3325625c8180d99532c62c05336d529febfa9344039acfffcf175b96f7dab1e790../../../.build-id/20/fe1e1e22f7cfe0721ef1b538b702f8b1e7b3f6../../../../../usr/lib/debug/usr/lib64/krb5/plugins/authdata/sssd_pac_plugin.so-2.9.4-3.el8_10.aarch64.debug../../../.build-id/22/6e62c6364a17a7d33b5d33ac39d46944fb2e98../../../../../usr/lib/debug/usr/lib64/libnss_sss.so.2-2.9.4-3.el8_10.aarch64.debug../../../.build-id/26/4c678169dff1d6ab66e9519e7f54862f4d078c../../../../../usr/lib/debug/usr/lib64/libsubid_sss.so-2.9.4-3.el8_10.aarch64.debug../../../.build-id/29/ac8eabbcd64f9edd2510294ab9e0d090219045../../../../../usr/lib/debug/usr/lib64/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so-2.9.4-3.el8_10.aarch64.debug../../../.build-id/47/e33ff4d7ae58f43edb1654991e3019655f459a../../../../../usr/lib/debug/usr/lib64/cifs-utils/cifs_idmap_sss.so-2.9.4-3.el8_10.aarch64.debug../../../.build-id/d6/35b0960fe9edd879c8449578fec5a84cc6225d../../../../../usr/lib/debug/usr/lib64/security/pam_sss.so-2.9.4-3.el8_10.aarch64.debug../../../.build-id/ee/f0785b8eed36e39416dda3bae774ac09ceddd8../../../../../usr/lib/debug/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so-2.9.4-3.el8_10.aarch64.debug../../../.build-id/ef/da7f8c83d42e24472ccce3302a4dc1b83de716../../../../../usr/lib/debug/usr/lib64/security/pam_sss_gss.so-2.9.4-3.el8_10.aarch64.debugrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-3.el8_10.src.rpmdebuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)sssd-client-debuginfosssd-client-debuginfo(aarch-64)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sssd-debuginfo(aarch-64)3.0.4-14.6.0-14.0-15.2-12.9.4-3.el8_104.14.3f! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,20fe1e1e22f7cfe0721ef1b538b702f8b1e7b3f6226e62c6364a17a7d33b5d33ac39d46944fb2e98264c678169dff1d6ab66e9519e7f54862f4d078c29ac8eabbcd64f9edd2510294ab9e0d09021904547e33ff4d7ae58f43edb1654991e3019655f459ad635b0960fe9edd879c8449578fec5a84cc6225deef0785b8eed36e39416dda3bae774ac09ceddd8efda7f8c83d42e24472ccce3302a4dc1b83de7162.9.4-3.el8_102.9.4-3.el8_10     debug.build-id20fe1e1e22f7cfe0721ef1b538b702f8b1e7b3f6fe1e1e22f7cfe0721ef1b538b702f8b1e7b3f6.debug226e62c6364a17a7d33b5d33ac39d46944fb2e986e62c6364a17a7d33b5d33ac39d46944fb2e98.debug264c678169dff1d6ab66e9519e7f54862f4d078c4c678169dff1d6ab66e9519e7f54862f4d078c.debug29ac8eabbcd64f9edd2510294ab9e0d090219045ac8eabbcd64f9edd2510294ab9e0d090219045.debug47e33ff4d7ae58f43edb1654991e3019655f459ae33ff4d7ae58f43edb1654991e3019655f459a.debugd635b0960fe9edd879c8449578fec5a84cc6225d35b0960fe9edd879c8449578fec5a84cc6225d.debugeef0785b8eed36e39416dda3bae774ac09ceddd8f0785b8eed36e39416dda3bae774ac09ceddd8.debugefda7f8c83d42e24472ccce3302a4dc1b83de716da7f8c83d42e24472ccce3302a4dc1b83de716.debugusrlib64cifs-utilscifs_idmap_sss.so-2.9.4-3.el8_10.aarch64.debugkrb5pluginsauthdatasssd_pac_plugin.so-2.9.4-3.el8_10.aarch64.debuglibkrb5sssd_krb5_locator_plugin.so-2.9.4-3.el8_10.aarch64.debuglibnss_sss.so.2-2.9.4-3.el8_10.aarch64.debuglibsubid_sss.so-2.9.4-3.el8_10.aarch64.debugsecuritypam_sss.so-2.9.4-3.el8_10.aarch64.debugpam_sss_gss.so-2.9.4-3.el8_10.aarch64.debugsssdmodulessssd_krb5_localauth_plugin.so-2.9.4-3.el8_10.aarch64.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id//usr/lib/debug/.build-id/20//usr/lib/debug/.build-id/22//usr/lib/debug/.build-id/26//usr/lib/debug/.build-id/29//usr/lib/debug/.build-id/47//usr/lib/debug/.build-id/d6//usr/lib/debug/.build-id/ee//usr/lib/debug/.build-id/ef//usr/lib/debug/usr//usr/lib/debug/usr/lib64//usr/lib/debug/usr/lib64/cifs-utils//usr/lib/debug/usr/lib64/krb5//usr/lib/debug/usr/lib64/krb5/plugins//usr/lib/debug/usr/lib64/krb5/plugins/authdata//usr/lib/debug/usr/lib64/krb5/plugins/libkrb5//usr/lib/debug/usr/lib64/security//usr/lib/debug/usr/lib64/sssd//usr/lib/debug/usr/lib64/sssd/modules/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnu directoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=47e33ff4d7ae58f43edb1654991e3019655f459a, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=20fe1e1e22f7cfe0721ef1b538b702f8b1e7b3f6, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=29ac8eabbcd64f9edd2510294ab9e0d090219045, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=226e62c6364a17a7d33b5d33ac39d46944fb2e98, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=264c678169dff1d6ab66e9519e7f54862f4d078c, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d635b0960fe9edd879c8449578fec5a84cc6225d, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=efda7f8c83d42e24472ccce3302a4dc1b83de716, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=eef0785b8eed36e39416dda3bae774ac09ceddd8, with debug_info, not strippedPPPPPPPPsssd-debugsource(aarch-64)2.9.4-3.el8_10utf-83b146f4df6beaac6eaa4552f6453675f620cd6f6d605aa4a48b8774b8ca0c50b? 7zXZ !#,Pj] b2u jӫ`(y0@i:.[T?K뙒Qq`>bƘ`RF< G7I!1  nzJ}2!:Oztӈg3%ꂏw\F83BI%8&JC]9!06ݷ;EL(aeMc=̂ȟ\8ݐޤ 8}C\Pu3$@x +TAg읙ce͟C>MYd5o77C?ZngM"^z o{;FF3ٳ*+ y̸U;$X.*)KRwY#q$/;b¤ފA7zܴ/"?jK2 yϦ#Y=zZ0ԥ g5'Ri|˕o$xKy*l:*p(~# }F.D 1᧑Rm%GR*LBo}j6XGQ4FNvzxZAyQCYήGEc44ڈ c}.9WVrAġ͚]x7#sXA}#4$j!PP{,8F)qW DP/*MB:v8\`o\h j`o1-Kk}V47 \[Éז<#~oyH?3+>Q"f3duWRZaw7r/^SF9gCD~-|(-Ӄ7k^e'vK?zZpĤyZZ-s3B;:ySyr87" c s oq1%窍kMXa]ig^7cVc YTO.,ZPx&JٻSc^i|@D )gɄ(sI.C>mh6HoEgPj'@LQābrpuo3.a - !_g'Ȑw\,om(O-/Ugsi6fD`h]ͰF@ϛivt'/oq7m0B:G"{wT:<1T,l#gy gIal!~tK$frϹ#6oVY1pϹٗ(A5mV폅%9MHd D8qX+kDspDXԆ>Q:JM31.Mwg^=qXYZ^Vf eTx[l~v,0ѵmav!X[O1Zc})7fedf r~)߇TJ' vFނ\J_pWg /I:}uEr6JXV6&yq:c R==}h- s=5V(.G,ٺV4U v̅C?- ݨIOhH.:`x\V}祡ߪ_fY[!.5XI^Qo7{F4J/s1h}{pş_mj5Q,_ GFr˩D@3= tک责X}!jTX=m I~46&~<r>clVf8^u_nj$'k2&͂Ġ7Wk-2ua'TN#j`lzm)=P4 `aFBfg)5fTfgk%%l \vd՗%2>7y9=(!oƁ"5GrbV݁\7 8MO+oL #]GZ.(M@˫N*>.[ Bv;~TRyǟNsT4⭙Lhtف+5bνCD.U ?CsP#ysCİP\N龓I]?cNERCD&]fT-jKnIH4VͯFǀ%թ]9Wnt7KMeT\mp뢨vl e7]|K3GC{^O~%&)C^XLzsȐc@͂=dJfO~$Xߏ1,>o;t^L= V͏HOhHYI(Rg\d㡌GH[<_;xV>8P]*-ж|z崡|~96Q{`y/PA;H 1}4m+9?cFk t!8"Cy]9dv,zmy-WrjEF[riLn Pwʱ*-zHQ{=CIK%S8!\~u>n$9(>.Gʴ^}xN'CƯ8t Z.a:tbdj}7 ͺU^]sLW.sE#ls-"̐3`0W^nQ}vP y*=$ݏQ1v@yzOY8oeie9]Sꄬ`IH.w5ߋy`< 'D@„a1<{& y5jr}d~ov(|Q̢b+)/0.FzI v}=Mp\-:[{̃^5DTKÂY~Kt`jP 7ARVWcv  `a7TC2((ZMฌu;U-bV6}sY>sfNf7 hw^^ ِV@ٳ{k:w-32^k@r<|'OMeb?H@>m!+~Xi9k&(:9.p+'h\;|rP.Bn]O^$yeV;(\!m&ɕ%#Bq1zsgc A##N[.c(T 4|nHGm*-3UCXgDzʰ;IBܥ@=i2a95RcaM Nlp࿭.gJfC O C~?fQ;.vҟT3D{ LtzS8ww_8=+S0رL1%=9N}HM޳$mWVA#@ANuч>W<ąK ftOA~'_LOmR.կ!7Ӫ,I 'p9[lcqb9n.k.Kp}C2W7h$d`$GLC +띟\fTt$-XkM-$n֡HNӱp6CY-եg ¤仄>ñp!9AUb%!n$I˕fń֟:gh[EOW7-6 ‹JRmRub1923[_|FP0DfG&ER Nf[E]wO$Xg0ev]nZav +HکOh,sif G EeuB_'[HoV,bl/C3`f6UÛ֫ۙV:sJ9$gb* 승H"]"1_-Ё΂g{,Ž83OϕǣHdܷcY5ÕLVwJ Ve<$rǕ]چ7l6וu sZʦLk]p&VӜUַ+D̯ZLNzl8 gZW8Z^XܦnVƇNc32PbDBѹuvLej%igxm (įsf$82"p`LLWO6ihpM/NTQ`VF*<'D0O`rށL.G_,"`@H0& o.^ %7=As+4Pdý:d@ "'Zp<ʻ`h9yeIH"PeW}%-܁Tic_B'جehdTG>Dᬣ-Fh6xy{T>nKܛ\׺ j)XG&|8G@p|H[r[66Lj"a,bHP H: UX*>ֈ2֯ᦈ; R`ROp#j=_3k~STk kH+K?Ky ࢜.-DY|Oao j!UrѥΙ1N?2g,8q^ ,z `T HCʢXaxب 6oUg&ֱ iQwҎ(0 |Ӟ}FY73~:u̞/㓟lNFܪY?.1"}D?7jT|4/d/*FsPo(W%맑+M_U40+taI䮶M;s{ح($i.s{T;3yTr*v/>~qV+-uD6C6Im{9p3HrC9#⹃YaJaɴ| )g i>$ !%@wrj&DeD;ꂵ dnwz^i7BlݿFuQMFQ|-Q$GeV ]uh S<8NɊN9MdY>dBX͛ РC!-W7tY/n: H B%Lhɮoft;q|HkPH)#7kc06[B~>4,[ğ*ʸ _6#f>yf[Ӻ. V t6}-L``ur`Iks.`W9fׁWTɏI1?B|3[հir-`v!/"§񽟝lb }+GjG3?S]mZd37_;63 3,~ŸqvB2`kᶈ#̐'?JF%_ǜE@ê|<,TO&XZzC HD v`JgfYo[y/ |^4n;&9 ~! rT:A1n5u2o?S1څvZJϬ _dڭ,4SN Y i y> N|y|b6m|Qt-;-isہ$>HRo93BY0p`>,Q9QCo !WiuMJdaaMFGZ{>+cQSQ'3hV [2sTE^UiXyg!3 P^);|):>,T/ HyМ&?u5joͻ$h.Q+5i \b~Jm7AlBTnX[rBmјb~:(8ƍ0sDt䒿Лq_#_{xgb.-F-? %]-)a0͡aM؋.7P+>Lj?+jk5dpMI̻[M!jF1F֬)6[ A);/Wb__/Xn%\9C!ej'=G?13Kyچwk=+ֵ?7V_lMlMtEsmXZ!#ح_}%o*\խ2#n':ȏVG̃5^q,!@4ؔ"4dO4ʈ @; qu$'Ml-ovgbs2T^~!oUu!FTUN͙ۓ(6>| e¥V$L>Õ)niӟ18t#FR%xO܅^f`w[*- yFk|^t~bQY|9 U;VyD挗C 顲6pK12͇ S׷%嘯jr,sj_s 0Ueͽ._V1=p&c@$tWp"N&"$HoW]Z%7,hFP?_"YBYL>#kV@k=˭Z\ D6 24L+kHkD+ zVֽ"#EC_aP!aN&}X?yVʰ(6 V]\Rx,#;l3 tE;RA]\ TAd/mx1w$33Q˞]B3ۅ9.o0^ %_^/{} q"Qjsh#߹NaQw5U؆a| 1cH'T{QL]_)Ҧ'4`05ǘ S:C[fn&s?baH^f>T+0"U\k2-0>z~dNa^ZZ Y%d/+\޵e M]/MؿWu\eyb7.QH?y̦W‡nй%!+l$CPlt3YQat%70 .!nߒ@}'wnlId]њq;RJncj ĢdDd%jǺ,9T=5fjVR\!'+]ƞ8 u?FC;0*9k߾D?&t4ݑWldBm! K(RgMM(IqJ%jey7>f-ݱT>u,hjƊgn= +oí 5$vķ+ܑiEPߤ- fm#T*M!pW>n(Z.-bT{#k}[Cʆ%HgwUz&(^\} F$Y8I t67@ْ rx#mylw;'q*Lԇ藭 nK A8gZ}B` 7gK4Lo vcVﰺmb .Ch8`ȕ |>@/zd(oJj&SC6xVhdM=]2k,|$K.Q7j?JI>(e&'0djE lzr,o0MH"B .W=?HuwN} Z= vN9~flӥr؟$q 'UX=;rb@A4OL8=sۊ2G1CQ'ֺ&+DX|P1Gv sU v(.= Cx_5HtȫG-7D1mC?[n 2BI`~]4%U g<6/YkA%JFYQ gho&Svneo{\go F Ҋ+ vcM#؆QFR(ukQEKsR= jWw؋ٶNT϶q@h@)^m,`hd{gAcoX|6# [ Ӝğ3)1>i#% ~$u )# eJu&ea&>jc Sh+8_~{)4͗B72[ӏ2s*5l=7"؏0B'U/XׂE9a FqL#YB:7XjiT۪QE&zԒemM0@p[~) ZO5+MI[/^9T1lؿQz#dv@v5(K/G\ VLqeT kodܝ +x~9g5=>: i:N]/_2M Ѣ$*~_GE/>}C7ѹS"]ћ]2:굛 )%5WQ+GNɈu< *U.JI+@"#pJ}>%ZB +99s#B&!~,f$M~\ǻ-bt<:Y ,q pUeF*Dߡ \GX$3}ahݸɖ_^qSt+զdgFs:MNԥno|tMoC1=5se]TvHo +c( 3:а<[ ן!2.@NiFUR97 kÏLT1oəpW(MGp؞;;Fyۜ5,騚q>4B46wBJ /%{ tET7#ma EtB^A"O'>&rYFq>ǾP'd{ +|; RtG2+ F/j^W^V'&bb.B 5j;*ʳ..n'`W ;hb)C Re x f _xFF̟z#׀eЅ`a$U|Z@[;=EOK{gD)r([[3a*#v|؁/Frlwp mk~Γ"Qs&Q0{%ÇiucNūqJEmfA6zn ND@_?ڧg<+_q 1*%R2ݰovPBp^_r59vris% ykX GX17 \Ja()IiB[twvS+&0MZטNͰ쟷q5-nor VqWzd0qLz'C Z ?Nd SroǬ&) ?=_M= ^w.7EA/5Kts<{<#̵-V˓p T+>B-TC%OXqԅ4+01[f}>JtϘ2⚛B*cyaN7$y?'Dpyc-HQO Q%4` ?B&;☖NH)3je1D]qhZo+0;:\~O:Әj^[ Ԏf]0%д$7HN1)<{$׫}Tl_ H|i|#R}H~/(,yk.bO/kkF(ߓ'J@^7 <ʮ/EC_eKNy *?MN}0Uv#6čQ5PZg_d+ʽ}̴BEۖS IfE-[;>b5u:nҸ{J|Bx "S<&R 0 ` < gcG`O&+p~"raeƍd4i!v{WGsႛ6$ Xߗ:J&\Qkud <=aDHa,B蜇?$  < j Jq閪0>  ڻ}QQ覥Jk +Bj NqXZNPՠf6M'O~Z)BZ{n[n'z $d8^kw=q/?, x.pzߗu! 97I4 #QOA!qad@o{KgWZgQq98,gsW7]LO$z0h V&{hE)Qd^Z'4 w-H>![Ÿx@9\MwP崭 4cewÊtV=:S)iVS.,0U=a0$?D$`ǀ؉R@~D,|. >ŦsoXpqPk. prcO\Es_taiyq@[_ʐ4b3xMG||C.kxƺ +d85ި߻ _J AO.C+t.ॶؕCޯ,J)6r%}B!w&q#d&I/MB*Ȇ>PΫ~HHV<~\-{O_I 3?e%FƇAAT眃#/ r,?6K ! Wk;h*tѨéOUҝs%Y1dJT+Kf&v1>B?rDг$^4tIIeWVuo]߷M}T$}W i:,i챫*)`C3x\rf=C ^aܨXG[?zHp;B"m"jnr|PmSx1?y7g yG>H5&TkK2#yD ZֿƘ|N(> Mwl6E -{^UPVw'>*W_<  1q5FAG˻u52ukhџ*IqK`>f0>L2QzVEgRvHacqXgX6(Ce3$pIr΃>-s4dϢE2ڢϿ/gu8Zi͵lApP ( pJ׉şa MexΥS06#>M(<1Eg\"h-F(E*~{KDifq&܄[~t儹b=jR-f5~q yխE {͍%=4 mJxt[paE4uMtbM 00qE}8e9]o:fZhVq? 4*Q #+88}!)kJkA;|,&&zl+~-@wk&(yu]Y_~3O k{1rq^sz |]Ft^\"#B)byQo, םITU[i弽YT; !wILbLii& k{0lqV<0`L `dM 7:ZTh/z~_ :Qrd\>2? Σ\_!՟snl*2=^>u窹Ϲ)52 :$}z"zqv}O#BQ~oݝ+R-ɤ<ЩVcad/@gh#Z`%T%*!J] p8Xղ{8j^؄4 3#rB>Zq煫vw5Oәfj±9ڀ-F%bvM\x *N<:Emgpv 5ie V LuML/%kB-ل/m}ۙl+Go`ڳL\I=+OLI6,GǓE"SwwZyF7JUP]tln%8t֜8-ꩅip>yUj+{wzk‘ė 9&9S b7hnOC<{ŸuD6r~i):a̦ 9g&y5&^k##[rޥsunk(=8܈pЭ-e#v?͖ @(mҔx t%|a \ /zTsZ/#:[V! ;ySYKO#|ŦC-WJdޝCJEue fmk]xk5EȃX)L:gP#(Z=+nb9t3zj$?ќ:ENv]Bzl|ɔ7=-(fl38Cnh #oVHfYKUA5MкS&|`؈ˏx\9aH^#*c&Oی:d!| JIS :RUᕜjmY&scJlXdAyNFmjT&1{1 ƪk odzGܹ+z&pYԅT^ÀM'dQ:j"."!ӫ|}5sIdߖeX ?wrެ_,b-:CC2RO B~XHdxFEaHcco(>RS쩐n"b&*M goT%Bg0Mt.{0+XlN*U]lLΗJ]U 8JAn_&wq]W$_:fi6#FTzC1+Jjv^=}!|pss1(yb{$ndD**rQ&rztqg[YVV+ R^?)^ypnQ"ןQ?ǭaI6H1]j$51M|Ari„A=me=2I*}!9gOz̵3<v;!8&w:_є-_C2Sv;ȇ_> ÌޛVU5D8TB ҟy&ᴕE{lMm}&Nݚ+ŝJo|kmzy&<)ܰiҮmLv?D}YoC΋L`oq 0|ka,w<4(njY>QqU"2O; g9$Z qǾs Ś1wuבAٿp}d1qjTRn*hw)܀Mm)T<! mC suh;J|Az(~UUw@$msVz 7V_^|_!U<>V_GސQe0" wU {VL] O*oɰyXjF:1AJ^425; `bxGvj#mmF g RZ9~LqD A|Y WóB;j<{B*ZI{uk?8 Dbʎ5k#1JS 6?:TKEZy<ş.p|5x ͈˅o #E/%1E)@i&Bu651_h0*GO`!ݭIF_oc HHAk(| sI%i`-=R|xPЭEm#Kޢlm>ſhM޸ހ[j#~@ $p<(E;3jW(?aXUz1׮KBsYxK/hk`CC<-w爃G<Q/)݀QQ9Ǣ^9w)ۛgվ2")p N]y+m^ϯbPj;8ŴWO k=ઉPIl̰deN0&꒺"D'EDRLհC}xVO)6z/߉-\fldZl+][j݉iul9aA?vE C|U5E[05*'*ki02\\ ^2P Jaڧ}K 'f#`)aofD@I;_Fh.(@v&& gY<7.c$ncP/@.0I|dz{;>#4Nd;uS<}eҳp16d~0BW+R~8(1Ng؉|}TY͟+|:Kh«ܧ89yL.oȘ_2k2|ს_sx6ԕnrEWFK úL/y["'Xg]ORzw،8h.ȋAVJ T . aAnf$2Sn@Ge|vcRߢIHYysm!PvJ2N žx~#jh7W_+~>@=Uqu2k#z>@M S'.h? (n8O0Y.6pW\G/.đ`w^F@ra(l5 .-aiFm)_v|v=>E~Q|Y߳N.K$7LT 1 dvmR`}Oe,N~ *5x5C{Rl˗f.^T`V{BR[<ޝNt2lTLWki>P:٬gN"vJܓQht>Aw6iSH#q)9𒲛y<"|__PxLK@*5 @cLm3|՟>jIkvm@9.M̝' l{\$5}Be˔qڠ3x!uŞt\AݳDGrCvrtԃ`5Pdĉ6=Q:/W;/9zI$ 0dҡVw4uGUxtR"BCtNIcY{R>2갧0g]+,1Z|w3`»ﳂ'6ǪgP =`uMC*JNJ:X bHU)w@ɋzץL/st-"K{_kĜC3 ~q5\ ' ]Ed mdx1=Ĵ):i'Yq5 m4 {bO1ϑӉb <); .$K@Ps8 lz3ʤ h+̡zͤlt=먎mT eCtkաlZy@z7[js'4aVW-3NMUEMКwЅ쯨oor%tU>>}G:7/W<`=Ӆ[MT"].\@@J1-b͵{GVq~/gLN驴Z^z d@*Vs;UcBƹ2:hG3<>¡CGNūDJB+Wn _ta@yJH"M)K^=nOˍy$ݜC[#{4QO3X{d{r{E2 Yq.U~$fcK.+tV&ZsaBDL;g4ū\mAuL80O [d|RµIX/RȏW#`W`.q#5!r+Ov1 n2 ٿwܧ@,*8# Wܣ1AY^0,iCsֽ*5i+:9|Aƌ=/jItz {2DTOvM6t*ζ"co;ɤ gsNk~kNqn/xVӂ5ڐQkb6i,귁mבK'rtXp ~kݏDd,=wʢ$O{{T*Ro%vQoVz_\z=a Q\,8P 2^]/^''ȋ1FHRm'[SXaqu3ߖ<&=\G"9>@k2Jꆨ%QpKG=/ᡖK'4I-?~2yO9>SĪ2:2`=rRrߘ_1lA¦j@ԇMy5Gs"#NJ9πii` g˩?'}uԬRi'.l|/4mlYFZRӢjD*QPzu`|%OsrU:_in^Qg<p8e>G#vn@=Ū#1e"ʸp {hY< x5 lD8,p*/ *I5dD͘U #1AA菾UQr60Al ͑ng{J8h9=1&7s|Ɗ -s|TwW1G276-09q\Pm&Yk܊]AvMed~[VMb5#ɈTA5yO-HE%Qj*VQ1sYA/WnnL@6!DR }PP}\A) Y!5#!dNOzR4]P9H ִƪ'F` Ƣ e*QPG 19ݔ U[ݑ&mF?ZEE ly( cְbsH:P2|<.],p .Z $G0n} 5p6o-dύ.k]ee1/GPDM`q̈ ̏yp[1{J_2ڿ~[[Xp[f,uJQ/M0^q~7bES"ŖހN33XALW{uIXp7>;Uy1ZK9X4 L+*Ku׌vn"bU|ͣ Gz7bu.2 _~&rvZ m󷽣 F6vldaH{k TlZ꧎7*bfmp/͌;߰~ǿ 63\Wmka0r7 嘚fQXi+f ɐƩwu5]tRu3J9nyL6jTBtQ2:kidLjZa3AUH$9m;X$@dws- 1s+Ϝ0::ƞYI3' ϞE>y٨hW:fCvIB8U!D| O% H 5 ";5g?TK>]h;w73nY<mF[j^z0p0vM=~FLڶn7{+BY1Phj/ڷDѼDF|88Ԭhۑ2>1W{%>-<XN[,DW)ٝf_̢ÀgX!6fگZIM\}8IȞΠ]"ĸؙMR^ֿie̲|61<f RYL«.4V./h@ }[ӗ:*!C+t̨*̕D\԰l^<yeنZvCap 'wuoüN5^QMpyg!r.%+15*DF$ ]mm+̎3u5@{Grg(-rՀؽGzޢ5s[a̪|Z8aa0AE/%DUy]To|ߞ` D?غFҘ^1TLfhay7R@a)A?.U63~D,8 na|kSH7`wF$`M1pW\9JXVͳY1ueTxl,q#r0ʹi."zri;Rr̓p,ȯW.Jٯ3-hVO94yytpOf :udij5 ]#7m.cVx#ѦщIGFȑeuetާY/F܁ K%>όǜy}h1(j79~*l$?6K9tZ%BuRv2{eeGaބ3 vUC0ǚ4!<*+@znȗg"n0C/x1w@&1%&[Z&RO^Tb tgV.c!T wT p TƫJZzG{ŬvŜ1Z|d0A{dQ)S%-2FWMFb"LyTjLyשD&O'GgL2?%ba@+AYeS1_#@lbouPೡVk+Qv!G;v^fm\u0౨ʓ;ḽ s4Nن /8$:e=5hz*F螛o2CDm TNU [e4=ʓ+4nP?XO?ogS-%3i۫P Ƕc!h]qgÞ*9EѲ~4NԮf|!_^ ]6v VgNAӖe. yX6i &}`X:@tNMm_ɮ!5Qqו13&W,h?ӆcUT26N9d9$?w3am :!/j+J咱7pqXzRSp/Yض1R.QRu&;{»$Z5_W&jSb~^Gk]6CnOk3˃LT١@v몟veU;*a84UCyOF ;o4P3_ĒZCf8ȕ]PZ5H UR1nKD1uUP4O:z}t&t3~HY\̏Klx&O$Ŕߓ<fSEM L85^Ri0-+."O( EZ9>"I%I+^^ڷ4ZJ9T OϘҲ'Ѭ@ k[ĀH |'X`G&ň(y4ԅ2B l/M/rrGB28*yb.&FA;EaN|15! GsD^.l-BJI1!7A^(=V'D{k#=HRqzrԴ ,.W!ZU4VDOeAh%qd,wdzEmm p+e^h$p~^L3 b63Յ~%.Z^zӑʐ4x3:xf"97wsiArΠ 1W1^}Y/+j{gYL@ҌNQ0f`փ9hAE>XS{D0@z$,b*qA 秖[~Үk ,G0o45Ϻ{0{_g^ΣQ|eԥ)s녝6Y3-_qsҏD*!*7y  p3?(C<xIT&Tuu!Qq,j#XAji>pۡ sLV"wr|pI7a#Q.g 4Br S{~ ,OL ɞNQ+񃂩̦PS_2yxh9'8m)H‘#C9޹jCzMY:Hlе!ʒzSۙeW6׾Ha8 TSCL-g)ܛB/~OKO Jnğ^µG#+ ykiQ`z? x1rsliE݂=D~CqV_z NNMՅW9űD0Bp3`}M 7X+"ar,N-2rxAڻ7-CGlY;lBYock DL1|;@GVqm7,i[k3"q4oʽ#}Oۚ~H{K,*k B\x:eXgW:97ׅ3bȉZF@cP5}ZZvu@۰kxP}3%r!},-1=݌ =HK,+:4/t?!p{0- s #Eagt']QQ4Up~/$8&ǂtƢR<\5b epQ-.?0 iAw8&Î+~,.!,h' 5m[ƽA+q0za3~&Rf ؘsU<\3=2[~0۸[LCc%-qT8{~䖤}-S>sB3Ֆۇ3VVk&%;,ΨiSƗR@A EȽǙEFzW]XՊGA|YJlӫ=ᡍ)9PRp"K3΢~) rs1L R7&N00A'CbO^'牺 _==@ov`F+ X"RsUW=^/dV%0¤N΅Kѭ'&[ѣKϾt F4}Kw|ԾڅL;U 4hN'Oq<:Z4Vow}) ΖE@>Wᥦ-#k`úP}Fڷ^wZ0uLN>̴_𰌂'a?L҃{1Lj8XUÏ= # 5 yҙ;;h͖|TqMBG+BC= HKRJQLJ*ѩ{<-ό6AUʊdz%dm˂iܨñp?\pß>;O!yKA T  ;G=TEMժ;& 0`Ϛi;Ip\5_X2Xp387gM%v^& Pf"a7Naw`3Kwfl*ڕ.WAye- +i_s/۝LPgЉ+⇑#mR0ye/i,"u ᥴ'B^>ehМ5|:EA6& A"c-;u U oœ'~"2JA+y$a0DgE6^DK ,{U7% 橇߆A$Sb鋼 ݆?AGdpJ2'D+{`sdBTx!_- =wg}k`D(nG N!&{Cn3ETR>KN5J#ЭOfiuO2r@[O362xWQhdlrP67r–b>RQe`̗RCzQDE2i  V?w'#g&:y*LI_/F2;u_vPqn52Rzz+Op._3/>Q =DY+r# KGV5lv?GZ+L?.7rwjAdȫ2V3B--a ;yD8Thaor@_8R=inmDn: Sn "bHUʵm񘦶py"Q5.9dR#jr+`{>8sq4ߩr]Yf5mpS LF1Ɍy=UlɕSS7|\"8IJ1MtG Ynpt$cqu\wY0wd ,1v |d}N:-h6$5ɳM g)o&} X8s]\<7x$:bg2vjfUz4roٷEs3\Wih/zrEhG,8Mh!BVgC*%c-6n+P"Y1>1@ư%zg\Jk4֬?}D_l9MXehÇDF4$ls uCvvd5+ܮu&Oe%A @轑ٚ- JJEd+iijMV5f>ie!vs YALX.JÒ$=qtBZ1%$;b(CD;+5B|v&>oqqsvuA!& .=ͨĒdip Hսw|yc[c(4Ǻ 1vN2AMG3͸iLi>1[\=]H({>+$@t ss-gm F['KP/xvVlثoF8m=З~oU7y @ߚI9nPdE F˧nIfg n#{ {1⥜VvC} D ܜu憔uǹ 3=A^66T6}D~*W!'V$܀vBl攇onV]RjLv%EKO\1FRi, BEWL/Fp@lתԙqʑmei;IҊ&vPEB.JQӻŎFI G(mbX'DjIeၽ\63+DP/R<⦨4kI#whn&p: S;{?'&Mu"A ;9?S37uFeEj>A9LhLLnHγaоt3n깙Zuהk|1Okq&#Z;)|¦9pwX.(" (:üC0[=HK"aꁓZMT8B[H̵ۛW\rGx63Avxrno ARc9[jFm;``q~O= u̠ oG"=D69zz͆$ug`SwBa]d} aI5^62LTPK%vL27žgQK) 0,? d GTLxO4=S{GIg"$3i[#a(":Q7kz0=X GA Nm)F!rWb Kqrxԍ0DŽ^~Q%ê!x^Jw9] T#ii2 5*f}COEۈojyke G>Ip,;qYM3PGl77y9;Ig@[[j`!?P ̤} 5$UNZnO} 6!9ZƷdG^mj%n}֫4vlxGŵwFgy8;I75j"`rD]H@Le noIݙ.*cEYojَQ' dzpΰ¡m/:_\N%@sV!E6gsuu8O )vvF.Mm:tic%&sRMʺaTB-zBM,xhK'v T2;^ʜ&A2alA2K.Q@PN) O;AHbAҭO.1ťB#N%ɓ39%S ޺Q"-1r lyBcx^Mځ\MܬId \5?&@4b%|Nuq=Hfveo %HJA DK=soUNTYv_ 3 lH@Β坮NjKW@^J~mSA|)m(</ǡ9c /~dmҢs'K1$5A_-Ys/]P|(UVJ= 6d2޿^dtB/h#ZiLɾͲD\N%͖BJ.393{o9o!i8"< Pȫ +&F_fۡuw =Q>ClKƗ0|LQ^50"5*lcPjn ЭQ3>y${:"/d lΛZ3)wOj; t$#4謅^TLP]Kop֔Ba?ܮUn=$M}kIAo)unaU&`$q,Nj y-G #{-_ݩNH_M+F(<Βiȏ,uM"(:E)|7OZ@3_Υ8 )kB$yTx]J7ZsG(-کg[kީzΖ]/CԂqu@UsD5grc_ح&ZLk Džܤ(& 2P|5W 3˛%UMVq9fGOe9) V^нO~vDv)gZlf4mlf1Y%L>GDmO'J(l8&vZ2lEtҋgnw\PKMWܞ~:to>yZV8ʢ;ѩ]8j91e.n0nfY]2FMX2!1O0,C |'r/7 96XFT1x>MFhҔ $e2 Ocv_#jieRV* /zߒ ےУ@db)CrFRX?!{6nu2BЀ"c/cRHɂٴս V_[I YrL QW"v_paYwtj:C! BD-</wʈ_Q!9tw#I{Rba0ς'k="Au2Zn(`gڹ>پe1D%31uRzI`#ӸtK nS^MWEXNz~͉J=ZEg"F[?aPF铒E7Z'kblf$4H4 99~,ݼ3̈&cg[II,Yk[! P]+ p&b]hX*fCUڇ]M&掐LԻFV97Nz!+osK1iJ4#[6+reCYdxg { FN3c $1d[ $}1>*xMl@M![4[9"6`7|1ony3M:a2,æNѐ'GCx#}K3*L~m 1^=N[D7I܄xX 7wQ:\o*xZdh8`)/߫W@kH\hY*}~D|(}+esD?M1@ Czз#842 Q!ܐ!a?5mi׀Ss>W#4qǩbg;U`S7XZ7q0mOntVMZmx 9cFnd߇?-BlRp @: :Em31QRHkeA{/^@Z:}sT$hg)g< }ʠ0/g`8O]2rbD-Pl8*[9\S.hyw& -r&U}fy3Z~Su%8D f0pf :7*GkVRMjO)7$9sh  y!32Mv&"I]%`߁CԟRcQxsk}g/b%m5a&-v:;>+;B^>0 ,Rh+0ZR 'kحPH1N3!qlST ֻSsAlV68iMW*@_L3 9q6wozs}wvI/pݐ JWY:3z8.onӝ=xuvv/4%75YJ/[hQXGs;pamsH~7]3w[˚<2Gf!Zam9HYR{u&6$onݯ9S0U6MѦ6 JyUqg@_]wB)5 #ud#©!g\%MXke>6e'ӳL<^ |1SD˽N[t6Mo#C#7ގ{-ςex}%v~hxݻj<^OT/%fӳl~øM\ֺBkiv)dAIH>vw1܊6@GO I](>bdMsb be(_ӱG\@a'lXU>du$?lO]ciLvC'Fy%1XwmS>DRq&; Ryr8x>i_jǒJl곅ר/$@!GMxA]pY!F[BVH*p ~ǩPDr}+ؤW;޸֞|ɬQ:lL9 ȣLF|%Rbaah{Hv?w) YoC"( <)(i)SD ^,X+9y"«76̡O=eG-YoIĎKSL=p玁(ڂPxOij9Y\L~xmɞa j43H̳k^~F2`f7c)8a~&AD΀ˊ'T9 @-yQ,#CBg[K>ɑ.gOzNPL:1;р9Ѩ]Gj[9a7{]M)~3h?іSL{wHhJqma8}5Y(Q1d-:4"Ҿ7g;?F1 6ծy$*h1ө 9^e<M̿)Q8?{, ҘR).Cz5 yatl,S:1GFfW{A+3#yksYaN|YO]3hlEVJh~F9Vf c;[ &ņȡĆ o` J?];8L$Ё}VغKBp̒QgY(FbbW?*LAPi /lOHg\Uբd7[aÑw2ˌ$i,Yv1rDEF憞ydp˫ G(F_ʱ7XKg٤9/2Y ݧ6ϓ>Rl~[W W vbcn1,w"]ۡyhq|ZD5f\"!gcFި#{Z,QQBF0cj5 L`,x5Yx,[\ZOF_޷6LG03; ޵m]u?qLv< 3MXa粥ΞQ`Xuc #_`YI. N˧Ϭ} xhAMtC_AP0#nJ{< 2˅ض,xV{<b 2E ZP:tj{j {x*e(% #ֲ|ʒhlUK,\.60rK%:!\ZM=-xՎN@ڼ48qqz F]oJw 6jnc}(.JEa߯Y?tϫ~8F_o78i_ VŪx`maOX3m<ǷCKiޕP7Xre'Y`[@AnZFHRtiTgyTg&7&' O9Q-^%e-A$,Ăx:JH#ظ3Cs865N_Θi6ƯqfbdXYֲs$k x')?o]͕c-2'=*ZAǥ D5^Jt^%b %<ˍa`"^ :叏}gp%# %rP=4u<μ&+ŧQ3F]ybԅ}(הF@Z+Σvwx3ae|f:AH"q{"ąGh*Y*Yf"M ĝaLxZ?\VX1]!$s];m>k͊Q޸V<ڵmF&f#a\r@뿓+=+.@.z=N&l.7a]bPΞ_\M4 Ov]p *1Y3VĪi1}{{lzR苌 4 *G pay ͦPv񕛂 4]]_Fd%Ћ.F''GجHkOxDݹoC[2G"e$DhFQG;);';/=M*g*(=Bu?TBSMeEiUr) =_{["@:kON:cGB6{QZ3MT^xZE~/FK҆?S|qڢpf%Dkxzas:kevzi j6ni^RnΣL^1rVm9$Kpqnb7t_jU}3S=nj$6p*#|U[,M87N%')`SRd^omү7R籎1allcAy_s4UxNIȡ[S;?#66#0',wz8/8Ug(q@Wn7lb3h7Ee'ޠ[{<Џ ՄR$[mz,hm$r2TGx.'72bJ3+[!o˱_9H9QAgldoaywS] 5wq魙l*{ȅl|GTr}ύ8#<<C}Ctxehmդ櫓Wԓ.Dh]$Ow dX)U"  0J~wx֌G{#T8`F/(U1VI &v`QRd-aҳ2i(j[F9LQ?,Df ɛ:> 9Q!Xu{$%KFs -40 Y戡[%sbjp8 H5 =Ў4Vڊ'v 4P2Ġ%RE*IeEXxqEOelW`.+,*YAe>ҖבTݸjj=Hkzv׼g8j7 &{'= jC+J]rv^]ҌџecOXjRX:ww#w\Q6R5us+q``Pߓ3`$N:̽ד!J4cH[7L,%l9^QvC<:#oARD$e\8û xZmr[R @Ǎh:PJwm<qm塩ULE戴a[(2ьaѡG)Ւ9zɺ<:A,{HT0֬r$\8/O`$svu%˝irrճLW;#s9+U,$MF/.V'?au.3Ȯ5QUv:R BWQAW^T:5Lפ][ч/'^W-}؞~-AJSd?3b tҜNLj ^S%] 0| &!Nj9t]ʣ0ڼ ^Y?l)MGk<Q 1MMv?dN馔:P7< ; 0:/F|CMDߎ_Dg1ekwݳIf*xecB)4ѿQ*,5>&v \iH+PxTŠk +.t x@ DJh= ˯7'*] &A uV2c<0d$*?J?A~ 0/aH|$g;N=IU+ZI!r0{1zd޾OtTZUdq4 }xU}tScANs6LFnxhQV\Ɲko=zj+dEШyOO,&BatݏD9O 7XDzJϰBDže7?h's)֟# J,4OY ~^"Ϝn6xs49⋦%GrPFddsrVc0O/{B\1N&YLE..XUz&)rr<Ԛ|.VF~_֛e7V@|!(ri>uf< 'کAޘ<װ+亏&m-f<[ aWko7t.p6-ҥ=:F8{?=hym\01Y<'>N$|T(rhf07nT.']M6{}_Y}=U"O.w"XQlm }@Jk>{2.d6Jeʴ-We˓Ch 3)f?Q~ <~t(M:d ~xlڶ_L/tWr^ Ȉ+IB$$hs =}2}]e5{u:1x3}̩ͥ|G,mcCѾK<2̏h0(s7$_T1Zd {p%H0~|;B7ViǼux7EƐfzf$) 6T PKIgw}4nZVg'o]^P=JʖIoxm: Kށ9z1i}sֈyxh>p\ }k s@lw/Z/`[b%O3MuouCqÝ[ |`wEKn ";?t9C]'E=uevOUܰUGzQ0TB)|8`@{'w\ȶП+-}Tguo:inkq6ԘLָBM|oUhK}M5Z UihR{S 4 Ԩ*Ljc('% mm@‘ 4MyKS$?R6pR#KDrc % AO5hc@pםje)W2j9e g[JDWw|C#[O!@ik'>`)Նϝ؏<<,rޑ ,R1q%wK3!u~~P,a*s 7^s/5@Fd bJBh*e{]祈zQ?/v ˺1C::~d+F{RZa `4eLcCFnݻ_݆*ѓ4޴Xf zKҜ闒T:O6dR8ZXUF_@Yځl\c7Ԏe%-Bfq1-'dd6 @6E w# 8s;}]cDR88‑YDNHsrb߀W#ɋ;IPxX;a}X@ͪHPmJ<6"~{'-?^D_Cg-=[07Ǒ}_qk𼿾2N议||-Db4{4\o4vSԇyEq傀EwPth ޠkcaZOȝxDUEDC7]sgImDt x-).V&'E:ˉ3uf?}ui 01 ԏ0*ZzT)]Tl{]*Ft$K+&|L+Em)&`\e#RnwC 0`V޾AT_]ءD4;֫]0 JZ*Sqؼ;=v籥 Us,\ŭa;N|z8NEN]X(L Ʒ"D-%&7Cri-` L8&dW`*Y1nACUlQիl{iJ0o8*f #cLaj8$۪G?HD|̱g z c,CA2&qOʩKc_hFBNcWpb,-m.V'~ʊ4"H1wG5:i}JE喹]rEX?'c~}FɯUq}~_Q) H EsaQeGNzI*ߕUϰ cE.+zC7e"?YZf B231Q'[vn'1_ysQ<;#OSUM|L˱<;?%3_a2T_\u #'cߜlrr6@! #g3}jOyrY&z/C)1/vIGZ糖*4)""ėahUlS?ҿ5JF n1seV'8cre (qNZKZ˖6瞣hB$Եuڐy";|=G7j#y<x|I4dؕ7:PFCw܋aF$͵RMD߾ݸVn\OR=%,($ؙ$-ݥ9&и@Pme'c|u5Ǹ#tyθ[Yg' 9zIx2@\2 )ӴZ67&fnDi"~~S4{$]z8YtSl?A\9ϩ\ kkȪu5bJ/&WS GM]'U^}_ 3;%Ӟf_ժ97>-E"<}kI`HI?+3eXS{X0@s5QH2HqNkujJFaq:h%6[jED'mMLt<*]41!9[(\%T_>_x]Yl>Ǫ3- "RmOA5,#5}_= )yC7b@DŽx\٭L+6L+arP"|*F;엲nl}kӐ8-jL27O M]ř5'tQ/. $@Ij7(2_>i F^;{r]ݟװalL[I]EL\.!{B NjqJ#X'z}T'])g. fBdz>rc&o2+B_A U@WE2@ѿߋzb]|?[.F]w-`7Mx&-ݭsN- ѲB~@r.h7i!t[A[zvZ& Bx[ ۂÂщ]Qi ۏjr?eI|1L^'7OEjM-?5sr5р  I:хE`{vnZ̆  ]4DxWȿuNqƬӲ`8s3oςHg vg|6ykvo{'REM `/R xNP8%aa(T< CuC~:!Ej -f/U#2iBt񨍍cJ 455x0$HR0~dMu` CQ_eg_MϺ_>g']d #wŎj H+㒷X&QTt.SHmUTX4eg^;wUY 1~) 爵Ԃw$:xD^ƨӑr F8u+}Z!piyTm\p 3IwW;ϲ޼盉@%"WBP$k};DCLֺwO߷{{kKv0Ӓjf\?}]ydY۫+B]G[ N ?Y~+nyI;jYՓO 1)W7r8{XZTyWfO"6ǾO10\fC I9ʈ.e<'?*&L%ө 19! `nR%gODZ3R%p VeW8a}Zy穃zXq0;c]40X`R#ӓg3|/3[@5hϏys{%1_{#f-j-J85!^WIJTGeC+avd+)>|zSdT`O)k^/ܻK+CN{g+PS)A>di})1U7p_;d?Pi8;r–oi>8&p{áaͪ(`*-5/ sNd0דݓV6 a+Ud;;SXOlD ݥS sYj#ޤ$HJ aʼne%i_ swJDCbp iʡWqзhu|EŔ Ҟxb9T-pHB %c*8aQ*li-f-is(QȅȽwoӅ+۽.=RM:B%2tr 97i,0ml-q!K^>%-5DR;x2t|78b;:|{\9'׀tU]d`3N],*M&D+^Aܯ&`0R\+Ghϝp i8JMlvuW=f/NU,'sQ e}[J.G)|E֢ÃR~Vfc؇;(\O? +woE,z+KV{k/3ђОO,xx$`yCd|[%,Pdwd\u:mYU&U@.2bܹ1!tZBƏľت.̬lL5` 猫+q^&vp=԰=Mp%ZB}fJ6D);^u0PwZ?kMՏ7VH<9hZP;>ﴱg(`[RRPԅ$-y?F7i0J>ɢ 3\v5v};MQts5Ͻl- V?;1E#$N37pHWn`_@-|wdw.Gk`? ;еCK+aubx ЎigLȢ`Ryv/XJ0Y4h@汲nw/`!I+﷞LU)8qEi U#Dk'.B  `+Q;% 9= cP'_߳L(Yq o~,D?OoY(zZ _\'pmUb룼,aLDivD@G3ɝ7+R'RQծ ZMq/" Q,?_ )G̃}etSNgB၈*JD;?K1CmRTR#, ۏ#QN: vk'NuW2kʶ(&)ʑҔSThJEQiMC/}fzXK&!2wSrNgk^&`N\YC,k:Jn(݇ZƷ px*I+D-ajuof<u !b, )• G]ːeXfBw?f\Y h(JMi=O,aN ?Uk+yN#_=hjrPo XFv۱P]jQΤGK*;9rNa^Y,<,'l3/; *dmjP<߄Ҋ:*bb0$AEas/ 7[<8)Yz|X!\70|_3.?JyfVhAwyQu3vJ{>,m7Mp><W Ub{uyLō|*^s;gT Pp0D@D x ,nϧXg<g/Tf}M%WNTx ~+ Y87 y?#Ŝ )!l9j}'yس.CI4 'Kr;0c*!#<;mʋ`sLCX!s/|Nq- p/vnD* ipRӃQΟĽM_خBPo6c(sG"QdQ</5DL@~>Dm,y^A(7?{U{AuegD8z=B;# *͚.Q?(W W#b,G__8?5NOlVkI$F*q9ܮ׽:CV6Ze}ƁHʁ9+9{En,Ќ7RVpzP8z| QI}17oXS|"`džy&F6!zDF}%mg9s28Up $R5-AD0i=:q.MH*Ĩ ­G(UڢF}**J;cMM$:JuμΟ*nt{I*)|[{%#+D7G.嫂DkPٸ䢧;`|[c @nϐL|#Ƽ_]VGM@ XW׭tw2ACoJeJJ:ԡ o~)|}[d[P[4k.:_,+;ot‚DkwȾTHZҺ.a7T)>ռY-?R+)Fߌh~CK(RotsL KrD.W$ -~V4ec)l~ɪ_- k[Qn.ѫ8Yt\*>a4Tj2gdb])a5EVy4 a r˷ lB[d =ޢsIǔU'8n[͍c zQ :f=l'6;TR^?K2r:ޏ#ésU'\ #N^<&o& )+|Vۗ-hƂʜ'ݰO'} -}"]L\OYMP!1m#1Bۑjk)YhR V`j_Bj0aK3^h*6oGbF)@(w~3F@IQ%_^#cQC]F">kzg V̶Te0LSB};逡͠/nCs'bDQ#BzhR׾@+Q{!O^? x `, 4!궣>G9\wu_AK % pו9?F%(]SNq=m8~\|OБRVGM2۞ [S)M8 2rIɭK :mzcLZIܦ(:gy`H]fBe \O:UUk`(kōIb2cBR_ddPuLuCzd餟{,GqGjȑso7ۯ͝Ad qCz67zҡ#ERRJWG1j9c4LWݠý.aL-ts_u*DĴ|;c -LRM7|)iij~UĊSe+e}Ц If&A+$#(;O %dH| qҡvCez_EV1\gn_7.7Nr˚V՞ }ip :B-2Yy-+X纺1vJt̷\xf;}ԁ[4v")Б%(At5qe* `$Sq_y8 ӷ&7=h?}{֏hÄ9Q$~"|Jb#ݱD[d礱_93& Woj[*TɜGI1*vXC'G,JbLJh֩]\ n ~, 37c( z)kܬ<;cߓ==v[Zc2/ɍBb`_?#TJ11sZ0jb9X#$?S1scc¬JI7pGrOMl--KnhMRCPKN9kj3gI.__а:/߆2joΫa|9xՔ2Jꪐ~ZV\hR 5ȿ*A܀DMKcΗR?J^7v,UڀsKoj)q]b~O@E[s/I*+T^sSL0 @k,x1wNGLJײiibڛGOr`EU nbQ|+6Sa%Z 9uȧ\w{ 3 HM#!>ƮӿL䔔=X(L_MsU#~Itʜ!Bm. mS^cTWe )#c.42_tS>/]K_'qU$l1r/./\`4ZY=j~Ty}o><vk̞S"sTw!a@=u8ὣv },Bjs D @=Pf&wc@D`9!Nea .kyr#`n;cߍf/Ym'k\F] yr2J__mX])9q8!B@ )X ⒝IUTeZķky"HóEs%֙⇊; NyZvms==:ll >)W\h300#v^L#|X-6 ,azdIp.rX`"*!·. 9-KT 㪒XÉ%MjU]ػb:x:J#bY姉T^Z*at_-59@#[ pe؀^x16p.c; K}cK8Lo/3% \T6hl%Xm&Ąy9f ɕ)ϳ]ꐶVLeq#* % IѾJiT[&*_J$*3<=eJUM5^_# ЩHK쩒5' 9rrI'teͥ8% ͫlRO-2E|Uwc6+e7Z*&[9Gz3]NS,PsUvr6iK]m1\HOjEa(+YX`]] ;*2ˁ̛eʰ}tȠ0Sm.}`3nL:Y6j:yȰn[Ѓ{.C\}܉ɇEL"OE>KRКwJ ~=vD9@U.E@B`U4`17gPia̳v M6.;&7aX4OrcIavK5?ca?>or$eB"ڼW+E9+8;g [0Z |6Gy+1p ۴ѭrMȀx(1M"|FeܚS>@f-?/燿uޭe4OQ~r,jw[*gWIkY.7i>l{2s"g O1T9gJ!owQ8+^l˟PmdUJ~QhRy:qwh>\]c&oL*0GQV&m!W=m  |,ΐҖ/+o&:gvD)8u ]ca(lɰ nɒp9[%jÉ;KzDt5EA<'ՖC[878HbM"/,vєJ鿄Â-`HByKYן]!xpmWYy? ,Űz|ŷlڎ]|9 @d;Xa^EBy HS ~?~'gMtϐ[^/|,??c>@q@ b 1?S7{*' YOpW/jt).\-:{r~ܧ.If{d6@2>eª=_4.UC?(ã4ˋP|{4 `xS|;F@rWH#,ްM*@1jTBNJHq-pl!Dg[rRb)g x"Ve)dv"Av²/j2O#~ҳGd ܹp&1ޯwCy 'U{ޏ]T ԰ǎb9syu<'(Q|xy2=uG5'4$Ud4;\S|4Jɿd&nIN Gi{8>/"Qn$|AheJN6e(%՛!0<ohsF8yJ,+Y wS''`A<3d\zjpxa |ϘSU}Qޫ l;V~Bĩl@tҵ{6k |  M(4'ɸ sCIn#D*|M<;9[-rBk1(N~Ͱ&n}sIYwLĐtT\Z^T[6 gL\# 6*{^c䑿W$՞&RZ'PFnx P_$;5tؙ cf7N EۻV'8l;{<07DyvhK{Qk"&wur DH癭hd> U'ګexo?R"N94#UE$lK7G-ѽR$l7D4G`c[(^DE3th.qD4հK@^ D/Q.ĊyNxPls8 Agm|gAfEkL4%GzX0ݦT+ܢ`q30Y+P V^c|U el~_߼u꾍*Qq8N1xjXI\6#ttL )2ʬ fֵA/$Z(&$gWMdḪÆjM>`I;)%5γXYOJyAec^1RmNs1.ܒ%ec/F m%z N̍y8?X%/Oa8$agZʟaGs4)r:RHyr 'HH `81UoY"\5mWa&b)5fզCo^d 9;XzBT!JX ZbQ4Օ4"S'9] 䪇>5}}ǘS.qeB>WX6b9Wf(y.B_jwdn4 sV GWtq8Ÿnr"^MRL ;Ru-_g^e3W4w)xL[;so1Y0~Mcj߿Me-4COl,銓Gj~lb+?$mВ2E+CuN71g.sLB7+!IrKc ?xK8S9VJa}T~})q+diکbzT6륛"`X.v@3,ep,!b'qIVBc& ]f"Ǚf]eio@xĕiOHa MeM%\_sqR!=^(_`+H"G@qtG%C=⫄^"<F0xl63sh$THp#!{*M-$F%M$M0gC|z#o݅xwsngqqթeoW0pLiӼ& fڶZ^[eӻ}l%}+!/.\h.5}@@|& IBJn6^J-# S:>z`rmCđ! UhXPP?a#S@H1# )ꗮ Hn+Aaն!-"7[ۇ=) ^^jd/Yukm$^4.?|:x$]_هF[g9\˒5 J!ѥU @&-qډ|ĝ*@B,6nj(KI$l (Q U&c5^q5C1-ť~Z_VRBk7"ِeWw7:g Wɱw${Sem|}-]cixF;Rn?ͣt^v[S)!Zzc12~Z1oYJ_X':&ED?]1mͮ"WLּCGV\|y.Ò|@Hzb6jΓm9έ821{Ӻ[6V.߳b͹ h> epyx޵?zE /X7]*$ӎo8F>26G= kJZ _xVMC'O^e!ܸY`dW0Rʠ/0x+Aws*KZ8:ۙݡa\2bxZS2,8 r1Hƽr~8bmZ mλʽDvF sFChaڪd{;ef4=c><0@3 N nqWOZ%^?(ŝW}trLmKp[ 7X'<9wºh3դE6V3X9r軒P7?YќQ̀.f$]/cbRX7Ϫb:D*V=S|yݰBʕ{B2[^ΜRLsֵe қ9GN̉a>p76MOoezva"D-NqDLEn('u=*ů~k~g%ZzEW!Mu iBWbMiO}Ҷv&/Io佾uum*X+9Å(/(䝑J 2U{GkE4 %[gjo*1}S1Uyq5Gem9TWIfvH ]uS"F@x96C=~-V!RnY-"s>GKy+~F"4:uHJKkԁ>9' "qDXhU}0uvw$R*Z 0B y$>yUx/31Jplr"6Qw94QaSd+(#{z2nVxQJs2w*݆U*Ğvb@Dnf{KbVr40nQTaHi2"M,0B)x!Dhv'7Xib.2գԡ0eY݂1?@Oҷde췹(K7xV\ybd@Rp9/wCػb^c?`DLwӱ XTaC0~/j8\W;l`/$Se< (9D{::,ryLׄpe$iRj1W KYn xorqyEZ&#!ce,py3IW>燖xܨ[ChW,DZ$8=G9wEdCLH[$/vEXsɬͥF,<2Z!!b\[szC57Tƻcj^%ry8@{lH38@ H{#1R.FF!#>\!~}>dR`A=ޕh?b(*?"8HjvV1?v=@$qƁ::cygnfF8{0p=M0ڏMy뷅Ű3o}`~l*yRA_kkR\5Z4_(0"".q0d3^]*'y9>y!;_-bE5 K3W#I|I.&9)ݔn )Ԃ=L6UlB03# mGyVli97)V8Y |:zCT&w>J5g?1fd/*EalX)pdte>޿mc&صSI:&ɶ߇b.I9U:osh+zUq7[v_O9*j%tFd0mpz2i%Lڈ80ˣ'A"/e= ro*LHN١*xtfُ@Wއc̸R/&%2Q1ƋZB*{M1)CO{K|h!2'ɗEZ?M'&>(P9 VxER#څuѩYbpl fs⊁o3g%9 4]Jw񴌃tڱ=X=o\OiOm>ܭ'Ja2x=ل0-1ي݇TPZx%[2:0y jZ >2i^o=jci *쇯vJF<`ԑHe:Vl}mNLnsF-FƎ(-/a\i=aL@qMLAVfMIkPč#Q?*3vz44\!=9>w4lc…'3⊤3s{[ޅ@7GCܽc`{~#7s.md⹢D:BM R)!3ؖ Ⓠ:NY2K +BĻխ.8d,F &[zN@`|UWdzMNPnϵ*O09~kA/ƛcU IA>iI)8o͸1݉J4jvP涙q0s |VӋӀ>zDBWuS{U@)L嚏j! "7;n+|գ7EIO~zBN7LwY-?Ӿ6j/>g{8)`=a8  XQ| 2 2)̀oXYu^$%p!XEAvzt;Ӱ~іKə-9J2@zൂ ۙک\hG>6)6B?. YN[J.q^6Rr*0fn |}ôpB88s +#;tq:&6A o~3|Ŗqp܀lڒ<5p'|֫*p;/#֫UMʠd`&^ ѹ3; }*Vg}i 1Sຏ8τf7ݵI;蝤u1USUdP!x HA)L0RGe09Z(ǫbȰ$Wj ^?sdK׶OUV?5tE8.qdkVCrYK X89c[SY]1={ Xq}fz+! :Ï;>ʐ@^"n-; r/8 8e/u{6-uYX=BGҕ i1&8S.z(;q.{_-%錭3zXO@CpwkpPP-1L`;Ԍģ*6 r$ 7ح #=Zv 3+ ;]?oWS?8(gm; ptJ^ ׺ԴT{c@tH D ;cen5Gy)Z¸=4rc˻b0>TGh=~H#hN@`+_i1F|kmG!F~VC(s>0z{R,kFBb/_-E'5VĕI ߢOݷ B9Į?b!L6WTK[KIԚCmѓ &mێ79[9lд<ݶ=O];;ź);qUvnT.lB#i\iQ.h<σQ]QH[~͈:O;g:?a#2.qM5I:;Zg6݃ ccczVlņ؋iW[6$ѢV'4[fXn"Ʌ!V^n_o}2w;$ai2vWH!ԑTˠ&h}k8WY#AeV^N2sk.36(]hdm˞+<_d~"D:m\VGOK8Do onlCoPuyoʭ4)W&j]q~JtT: 7+`1^GXη b0xWEza ۴$r畳V xF1ּ F|G̔hAH  a,8̐<3z??3Oq>+;5_֯cT{gaa}Lk >\ka $-kHTFt[S8fߠS;ms KQf=!>m'E(R/֠6P7N/ŗY` %͋,Ӵ6E|L!BHA#Z\) hU@&էU'h@7p=kgO!Td~ 9jx{q=d>9!)ݩ[|4>bDH 3^&k+ĺ9)nֵ,8<,KH˷ps v TFX~lhopNf)&=]R#x.ZPh ˔ҏkeY[dҩɀ n(ni -B)+qS6ǀ5ZY*? +eslgR0E 0gT7s&xz{\xJ"#aB:I)VNR2@Uq%P~CVM+gpڽt#)"elOR?#՝&r:gS tTAY<ɘfhhQ ޿5iu>Іz(0͉Du\&"tyqmE9?<*$k*kG1 ߞxrkG?wlP$!> T ҩ3>YET=тċs͆q\[E1;]j&9s\k[jh!<]C(PxO; + $͜K@eY->ί t@1+]~yyM}[A dt1!Ǧ}ɔ;>]"~nD#+jT%GF8T"0.6gH~yXw/=0t9qJYP.Gce~ Z!G~0D6Ϥy1O8ח0_A )mj ݎWDQ賰xզQ;ɭtSJҵĎnďƢ;])05k>s^Qz) U0"*q&>r_,JRKCJ9P&fE؀> jS uU o"͙jwmg*ywҹXTVddF;)")Z|k%!N2Hm 6RPm0Gb+: WDo|5֎wՌ/h*|Bȵ㌤2# QLڔSu0:5Y]˳M@fFRxT92+[I'-: <١ dK{5ﴆp m5Ngw#*>1~[Y_U6c!0wO24!"RίGL.gD\m[+G=>̝0P -ۯ &0Fb\u뙱*wYIb9}\͂.i”vO931:g4`^Vt,pFʭʢmsi ')rE|+eD|%xB_doXWin_ nwW?ZZfcY] uƑ!c0Q3󞆺0B$ifF'cU&cqe@9nhJ㜨ϸQ#azR q/˳dĂˣaF\.& ӵ ׎n-sKjasP6rh9Cf3kϣ}9dƓ͖O 0~OZCGQ>k>che6PmԎQgÏf$K HL|HGV`m~{W^dD/`6$Xs?,8zJ6n8S8L\QE؅'`)ژ:C5.>*څz}7kc\T_8D~řѤuB8 iޡ<W;Y n3{9ѳ"9 Z 9Hc1[ /~J;rK#o^ -vv(ckk_G5<ʛ{Y6x{niAW hlEh _Dqa)CitJ=~0x"[<046Z_Y0ϑ8p>sR#\nΉjle(/-D*fvo#NoM.JS;":c:":;:ARV%U)S:O>a{ku   (' Q;}ؖIÔ)iº` S\1$[5/ߠgkx SNK8?ڿ^64R9̠ש[*°Qrbuǂ.oAɹ/gNI@y6vZ: C$O9ۖv (E9DgASttr$d 1Nz[CN6Gg&L/dT&GgVL:+zvu)]2SB,Wv]!nuʗ- 'B:bqJ1(̔KwA_J?H556v}JX}t1'z!9Y1 RgVZy ]ņ ai*"J5OO,Xh%R':Rv*iUm+`ͻdƢHM{%AxEpGKgeOmU1B4ٗZZNÕ/OF\-V>b_GrL]sO~6Y^ .Y[`屺v1[7J]ֵp fXz &xn]Ҙ~4J ?#5Q( wIY;4̟0dxJCAgE_ڮ T`1BYSyXtE{"RCCe89^)DL]=cy,?gYÙh](onWU0M -zŗπHk2}Xmj(zIB6O@N3%Zfm!*̉!!=@O.Mna4Y!֦xe/DgY!? Gr[7 K q2{"̶F*Pn{A ц߿s4lK4G«+V͑sh⃝GHF!`=ۇ0TUeؖBZS!v9NMHKd EfLf98 V~!@#f:KbA%uxBƈpԺW@lwPֺIyGC^ $&9;;'ucLjS:-t8L.Ce}OF~s3QxOUݸr}O~I T_=/Oopb_{D脖WFzW8V_3bq?wͩF*.z>EYmp,`7T,`(caF;"e[ Ԡ|oY`K6Ax .?GP(B{ =ƆH{#7ĠМyżdr0cXe}Z1b #dTXLz`!u +q -#:|4Ci6?/ldpՌ?xFW!)`Xj:ɰUun5Ot1q&ِ_gt_0+' 1r^O&Rլ i[*fH_8dq79 t`.#6@jnw-Iiנּ}¤iĦ"ȜæWeAj 7dAKeƛpFb+ ;ͭMfqf٩1l5 t+H:ǵӁ̪(VyQqǁrS<5-v;E`Cw'xcBuPwk;Cn x?m][I?$أ.OZ`.PC6SD$qմwD\Q=yQ/aXxYuZ:|2U)R[IUǓd +%&X*UO)o Ӌ! 8&S*oRaJ΂hCtnJmPz:`3-(8 .zq>hc[-Bh4d/}v!T׷_Qq악}1#&HU6<"V`(Jw%AGđJgΌE,@LxTԸsW F61T3)Ih JYW2om(_y5N/ ʲ|&jͿpF fp}D5e/c%ʬoqA5}\w87N7 9 &^L""hnrP͆ۂ6UPF"0 FTVI`Zl9ND:[tEtJ|TSAI_%SdϘ$WX#Y+m T8buOMz͝=-Z~gu1_:w"lj%pJE g?Ssz] rSAzׂwrN8tEC4^+21GcoאW9(ʯR;tr ⳊL#s Bh#яĻ|n]t-fse@“sP :ioh*B!!(G@|wΟ{fRl!;JCg[s/ݹt[};\-{üZ{iŋ&ɗ=|,إ,K5E -#,y.9_T>N`FW< h[ QP$7b I9dՏRmQz8VT.`r(*yiF&4{YcPkk򰛤6u h]i3Ba;䪚&|5b'M `, 9rՖ+6,ƉN+^4Aj0PnM[Bq2^ӿ,D!/Z*>vLz+ "F-wׁ/H7e!jfj"z6 X,l|p'l[_.fӼN#/tX@_dwOFPňwip~7;,D(̴^:Rh\4.˛$8ޓJMR0Ұ?2W{h;i橤-vr%;=j!"R&+F16@>BVAǻo3 d F$< p1K&IGsKwchE%25iQ(=4ڡκ4mxV, XS8IQ'ϛj5sutr vVdK|g uǚT(g8 i-َ`}PdJ?';YQ|[n{BW % >Kd4 l!=3?#xbFLcbzVq@/e.㑘a)…C7`EZ9`ȇF,&^N|^03")Ь$cK{nvC#~GٯҖ}en:d2mg$3鸏nϥep7Sn;9d뗂ժQiHDQ'#EKb{ELrZoHFrPLa?&hU[xs$I4Y֐ԽҚS,[*jp\+Wu+xA;,LbB5p==SMyc3MaM &jZJv ȸ\HDANY/:נ/ʽObrYQnp K~mrw^ 44Ri504$!C{6P.\^:Ѷ}z+Po[fJW!𵣷TZ.Vbk38YknAF.3E}0̟c+Ų"XYK/uj'֕_c x%rAL|K>D)z* i1b9e(THZN0֓yXxe""Βϧ%cB\Jp]Q@GA{GK߁Wg ^Ee[~C+j3{yzkz˲(gMp5vdN`LОҜ :hH rtLG5ּG=vN5!ܢOqWy\$ZAЁA|nvJI&̭[#Y؉`I}NIDbYQֱm_JW~4nAeo[g|/R9X&<V9H(ח5OCӑ2oiC;vN,D-8KQZ\keA]glԾ|ui-]P"mh<zXG-9t= _H#{!U@O)i©FoGAv(I-2银lJ]<75dJ",I 05 Sv<^YMHgVf2t&uecpǷײQ79n0HKSXsfxЊ"H.Rf#7RC TfERsi}/<Q!UxߊQܵKn&ʌ-@cm 9ve*7etbăL%[(r\Ika._$1ͩ]PpcQ^Ǭ^BY .B=;y hj{iN8!, xC?,XՖBCZݟd+́FF Ʌ4)Οvm@[*\JtIЃi >B0 lѹKXxV+lȾmPs.m/v n _teD<+$KuE Oe*GS?D4LXļTEs7V+! pt [9oK1ÇUADYpn]-mPl{\%۸ҋ&{7xj40eN:kv*MRl;t-ÖW3]ӹ pԓ}& ޞX: Ea jF$Mŏ4~Yu4q00pq޻ڌ& zM;d-qUIf@ X6YkMDg&ILXj/yq B'Ei.V.0@gSx9ò3`- 0X)#xX rֈB>i`ʎ"a/;tMofLDHؕ,Ta|SSˌ00JJ1_H.;qƙǪ>c=̼B(y" /1'+>1PvH4@GT5"T"ݙs?109+ mc e7_ u& }d ƒy݅-ctamܾ6}M&y]wnkBXt]b;-e'^RУh 8Qg<ӽ@[JׇEkīE1ݯξ90NlY F6 OR:fね~ȧgx0(OiKplZn޵oL*e_(F^fÅ\3HأTt:r|p^WwyeA.EvO#$e>`-#~"XmwPq/+ֲo̒5_ľ?')"_H m "d84dtui=.@൙)?Oh*GaX[>,Pvs,BJGH} B(Xb^ɥyH,RW 7LO_aλh%GZd8}iqY=#¨>483-~.S/Ql^Qpo',OHիn8SdSƮjsF#B9rKN6*P R?漧5&^"hc&je;I7fm\rԃ&E[QxXf~ycU;8/XofaޕW2x~-p6J8-Wω#@^ņ2N358%4@octR //*Ha4#:}k@Z՘;e'O&l ƉJ pȘg<%<[{g8JA_zEQrN)#K6wK웜Q bDF2?(E28sEP1bL*ݺGǽb%i􌿕>^]7㰓FEH `M(W`*A2l^k)ʄYز`M+jN),UgV~\ߧޭ({KdpƏl1F\Egk O$@d{<@}xXVɹέ@aV2GݭtϼX~9n7f+4>KrVv2J`}W38:KYD ,]^Qr1MJrK(q 8h^UГn;VIdR'a؆xYW" m' ϯS?[K#uH LIP &[/WQq ԢmW;T @^([ Z>4 E F//Y6Um>So7|3pMnnLNn "%Dg䁳`8B&8xz'/xbbƐ3/_(O 1,!I@<*͞ ӝ|6uLJf̠}3(9fǒřVa&|tcQ:JJsw ܒƃ⎣þN+RMWKe^ G}ěxd&ĺl[Ҩm&Ոݏ*d#p|~k@[DF]؃/쭈(7r4" ҂Nl5cQ:W9ƛ6a{qOW="Oņ }]OaO ظDv4_L@?D-r43 F4T0̩twm#_" #v;A.Q⑒=HSăUl)Ŭ iہm#qfwjuĸMK|֞Wj A܇V'؅tV '*F*|tw'"6X !#]ZPE&m<.p,UZ4}8P|Jw94G#1C+CwWcŅ2=n v^A5H$Ä,D(>2y["XbYgNOsUoVu޷@k0oD]&# Y gm|v&#OuC  @VZɜH_W[dD/( XcՕ^p#oM zaxVQ .oR8*-!X҃hx/Yt+ 7Wl_FN}~d,tnC )XEMX~R%k2,Ye|yO`a[S0 OM!h -ʯn&S'5bbO>du fM L טd2/z{EjjF=6gHK j]Ż\$sM^1C$1ʔauޱa?6Ĵ5AFbb1f_jkj̢햹sJ񦤿o@!\mG {;f}J 3ʹ2{̆:WE8Xǔqf"PRY^tYm+AHUro Pͱd,j94.ʘxOG9/"Mum b$7`uf#%8o$m<_\X1.O*P7Y޺6<_C<3U0] U:qINOt6:ׂY߶$!W Uג#w<DYy=)B*Z><%LެWm$:y$Ʋs~K4CrϿDMKz)mJ D!K<Чql0Z{_ˆVo|;ZHaBV38t]N'bX>-r\;^c(ѻNgk6[fM'J[mr)D0F" ῥ\TJvVS=viQSءF;EzSy@5ҚՆ ?U_w\-z+1 8"6"ypE=|ynі-i V^cJ6]õ( TR VW x7|#F7LY5#ojXm{n;K6WR;;FIb%%uT/+\dOd&jfMQ:_>Њ)jΓ SU1t>{.8K~ Ow]G]&K#>h<]EtMK8ŸAz|{^U"[6Pm_RzjV,63&MpVY<ux 3E@P}-<JM0@40WvHE\b:.Pyqb>C)IwHyj][8&tWy]3 ?cZ֋\-2ѩG*G'I| tEm7[ټuEo2+Wlw0XI&!A΁85m!)P{dUJd''踅vԏR6eǁS΂F&g P$OyC"s fCH7Gv(`'sw3/ ܨ\&x{ 4R43".f3XceC :Vxsh~ "џ\YF=-fy/PqF;6v۟E(kaE̐2uoD\}FhW7d8몴(ҹ[kG6:ANㆀMcG/Gi8cXr̸j[XSO@3g&-ڙϽT&<C G,)HD΍@pd-;lY0~˴gϳbSd#/ѶJN)'M)A͡n3 Σ7sj?UVÐڽ [MC*su5.UJiEn glʣVƐ"fSAVM X@a*Rpy-"oe9ʔCQ\ mm Bp^ʴJ}x=ֲK$^1(RTZpmXGYHc`~xNgn׉h^=Jc\wiwH/<7wWMyLy X pQ4f)~V ^n}]Ni0)h:^ į¥qهܢȁڎ ιs/$\ ۼJJ0B5k+x邋iVE $;.5e=zl x^eTT$Tij~i72( ]}Eg.ݹ(`P!ؖpUa8[2#x^8CjL]@yL+8B|J Eɳi6_g@+8น %W V-.p 8qHD#OhrcwfV(l;D^W `R4c:k3ѻJ *|ny7SOJ>iFzWXap䈽DteU)9 X^T@1m}iK%Nkx|T>%پMpf~>/jCjqh2) h-'\Xn1 ־Q_/ |گ&dH9Jη!5 YAz@mf(|n$%ʥ.jgݤKmX6G5%/m^Փ(,^8ld.cn )EIMB8蘆a!|Ќ-tk4z\ B:d\ogz_b}S *͖1̼aDUhE IE/c {`ż5|e vM(C ~z"iNAVq+9$YJe{ӥGBWM,),Klg-&U"=C 7z>塥_dHxǙ*GmȦ(z6v-骋8>Cpٶ4sݍ ʩWlU׆e`b\y@`@;IkW\JݞJa_=Ҥ }a?i^8+DAOA܀rɱ_$ZŚ`5CIG?*"@T7[ +,%cݽ*`[AW;k3ߨYd}7 ϡ^fEujbׅZz#/RȢ({t9](&dy[ft2z?+|̻%1 qѤxSO˻̫vXuGJj=\3C՗&SsFоYyiA\w¢l/`ݎ GuʙZ\C 5fV }:5E*͸żJ-o`2a-g':Mn1X@\m" d cPM\ RCdBA>Lu֝&_R[ScI4whhxBpa) 3J%pY 0 D2U\oWVt>={. elZ$ Oh,7z(n˴-?5qN& Ho} c̦^@&WR۱8"A_Z*@~1(҂B\%c46©:s tETjv0qkca2Ob(}3*0e؅Mʃ[NþuhzYVKgittDH4@lʠ&:4ݗ hqk-,snA"S#hbu`eo$0|DAt|m%K O _§D֮!p֮'e*2'~CIogի_5IK˥;^ǃ{^s,3(/$ s"QW]&mMJ0MQE\-qN֌C FZ^8=1;# eR&9 RpA2 BfEQsYa&@פtVs%샚V!Oz-u De*gAUe޹M;Ӻpλߊ>4CQ,bWos|l^y2Zؤ}e)MKZ-fg83AMB×Ȥos4Q2LoOa͏#ʌ(Gd?C&Hnm#/] 5)Ku 7Oȡ\5ZOЄt2LDjb65+4_0R'Vl\6uP2;MQ ܍3iSd=⧆+I71JZEܤl;< 5dִc(Ei'W{9h)]RcsA֋MSR@%s`yREZKkf3!Rwq\p̠PҤqxbS,4> pAS-2'^)'U-(HnMg#qm a1e!@QZ<_f]P_bg֎K)+uZlI-FSBhP|VwNIf@Ψw!vm9 vF4 3(t$(7V^a$ZGźYZ`yzSu-0g歑V0g݈{>FҰ&[f ڏŕ \D+YU'pԍˉ) qupOLe7Gb8ZHKrr<.m k*o%IgG#k1x9xЛ7dJ"VT̉<2hu{& y]$?mRnd T\3&X?A%*UB$0|wn;\x t>$&=,Uf/my),skkh?Qe7LKfi?`gn<7+G7kdT5x ͧy^PfRq,D7Mχ X)GGdyRޱ:>gH#KОI)^%΂ vt5h\w /_mND "w|h`&m~ pDg *"U`]}6MH(kB ZOsdn.uF_<^OKA޳Z#/>喬:=.j(W1b$V mT%GZDP4ދG{p'BtlYK>]c}d/+%M!X5Ⰹ]k` ۉzpJ2aMh jsV1%i7*I%ԛ+72S#F}nҪM4 "mm%3&5 ;,>mKSj|C1ɋ41yJPTv?#W\ :nMj>͐͜!Ҝbgp Mmn/"ޞghU L2^|̹PgF xLNܭppڅ440M g3yDIHGvtMZw:*ZԦfǓ٘@qV(ċBOX'|`LqTXІZdbl Y/^O;lxA7_/Yk裧B#,C'8;bR=Xx50&ʊ0Y_Ƴ:%Zvm4#9 3MY} bB\ÍKYkFU mkdv%B|eJͶ2vr1yDʜJ2r;:G?O䍻ul-@,A(-᧯]b+Gx^tylXU; ?~uȌκ7p>f|͉ۯ2xtonDVrAdl&5v{D֋nx{\eC$K@yeXN+47h{+3$>,ؚȗN}eȲQ=ߟo!P䬢ph2/#l~4^AB:## x4+ s!@Jڻ!{ [Ķ+=*-u*dQqY 0 W>RgETX4TV630}KCHF>ސ])3yw21z*iW)6}o"De-\RW)JjN7di M8 T.W7-E?_`bl^{D]`|Pt!Q| )B QNn$LR'aΫ9^90^0Q)ʄ /x_gP 2xyB: ԯ4h b' ΨE &8oY ߣT. ʴȯoEQ?~Q D8Jk`)SU5IP9ef.k K͠M&>,pWE~yޱhzT΄6}W]lbaL)ZfpʍLq] n"^2I{n\TDRi_alGp(ýWσ 'nf8љrFQ7AQ&ERẌ`,6/HP1g ƒ?!S"@@!LBYdUKT( M2=Xw}h<'혴§p5P[W&e4}( CI"+ofa37:XQ T*™6!HgY徴U\91wCA>S!fQiҠ:csTNԡ3qJ\DVlncZN![)JȆ)VϾs׉ΰ!2w w21O_yK&F<;wBgs'${q%Bm 쪄}N>K?mFN*S]x El{6E dth[8q`\Q6Wt^c%$>,_(}]Z1=\;>=_.HWӒ֒'V-LJܼvz. o'[cg&'Vv#Gޙt"T!3e" #S5ӷdr߼m&.-^iعH4=_029݁jw$=%G?&|KHjf2 < ,3,~n4ۇljkG’(`LBq9_vZ=KHϥd/KDD;!B(WC2(%=AqΧ)$+OR2{4̋Z̴LƟl$ncg Jں^'i gO³IoR#/ӑVdbJ^,R&"l pZ9iIt&^xW,`2:!R_ |i#&dh)EMf{1s܉V"E)Y=5 }0h6#ҦJA0'L`ݠ0͛k(" ]8Bu-5騑fZs[\J!z /cMݯ9JCP^1/hq"î'Q[ 3TT|*@6F4'貆,m<ȴl 5Yi7.<\Z ) 6⯶!Mζ('ыRەlU<%!6Cdߘu.Ȁ!Vm{x\_PK '1d=},ԼbrdYi!mEmO[0@E8D9-GKΌ]AHj>v_fApӚ뒀1YաK5֨$xq. y[r(:u67EԞaW2?FT^wm"2DնSkV(jz{RHp}Տ:¤]>v ;t*^';%I o` ~ilQl풿C sLH*AڨvV6)~ߜYH'3ݰV{ AWH~hat1ۥU&'b=|(=.5F ƓxO R ^d3ks4zq6uO HeS +. 4 E_i#>XµZ@CݓyEۯh@WB4]k9@U<Bmq4̞\l(w yˮdY"k~ "@"ɸ|{EskZɴ~PЕ7 ;QSzkW){e:ra%]L~YybJ1MڌWK A4u3JNvvZwKoyy0^ Tΰzzx- 8 h~,Hm`MPky/rE-ٍam tK̎; @A<[1`~.mF+: L7 ^ IjF0L[(W0 PC±b&iTw5^$NL0.4uLU~n MDY.3?9 lHZזzs2G_9//r4CMPd8Ll+fa/36Fpj+@>%?(]/9~m77Gq +j:񀋰@XdkLp9U\4X Xuc 0Diع tC*k fYk>&4EL%:=kW'i@ KH].QȯGe7x&mu*/U#Unm11\[Ad0zV-32r⣇E<sYw cyR)"L /, s"f_x`/yPǐO_ f:-lsLZ7HH -Foڃv1kٝA8H`ܖ7m%֕͝F _Jn+r-14A2bn !p^ B>I|`m(>l:՚npN?9nh" b:1Y$< ocsYy=%$[GNe~81xɒ&21S߭[{$ l>( Ce ]l]ZyUв$m>)N҅"1PMx5 XQ]cZ/M;t)NQih=BMfO[fRc_Kj2V/?%W!/2DFՋՖ+EY^n'!d.ǖ 1- >k`%M=I ]zsy.<}eu8_F P^(la9AdDU⛓XHT2Aqx(hM'lcGѐM4k<.VRSZ)-3%= >MMC ]/cWX-+A_766N^?>InGRv(0!IDǷJN:5Li>es3 5%Eo,&pk̶OzQ sPRIi9,M=L]?.q?bS\!kL3ѻY`O U453;ؼָK^&wޠ pY*8q%ȫJRJW6~Zs b^ B;T k ߃7wYW9Vxx505;nlV$$8#KdEJ>X먦hᜡuDM0#@snQr@%[S}<<~9vGcnJڟvisD!w#Vʢs9^7'+_efU LD3?;IO^C:uY9\ ,3V"$:2ְQG=-틵,5E/l<`]ł+<ͣT#E3wC@n\Zx{wzbKOgxF "TD;b]34]xkm#6N6Y}$1zh~~N{Do:Ģ剒dyjc&<BY#~D0l)/AU7 y>C#lW6Qd02-uo5"c~Q]Iw&#+dS/!!?n{ <ୃ'0RMfAs+sUau=\2V)k7Lab17-݇͒g=D/d /ހ3c)(R.;[U(;K%ֱCS.{ 7%3>X2ۇYuvGx௎ٿ/fXڷbxB`V!"A$UIQ JhЄq5xzYy]ŃyMT.x 4/*8ᙻTLn t@G~]D'4;,v!pH`dfi%C;sY>%;;W"W/vP$3TxnOs{8J,jʒU>|Kd}͊֝.6ϑ~rWhPb2CF'nSԳw`?P쏍}ybf &7 綞?MH7մURp5QHU4f_rʚxV_5NBJ>2 /m%ڝZYbsJ ?,ڡh'y7XAň;Ku88*>|>6Z-mkQ]m2`.lm ş ?&1$"ﺧMdpN#*NX´[{;4S,ȲJ-@.m'!;vU:kvz\}f t+ѿ2G*9h<|hWJQk nC6Sa3L֛F8@9DPzyېHc/E(d33V_"ng_9S.CA%W Q47M{?6VLa 9&t1yj;Eo1$r$.zEOˮ{?7 Ly8Dtq{R3ȘaCj ;Z9,d'FUct3z %93YZxTKb, ]eIZV6m^qubϊ%-Ws&`m Q-;w$f+,gD&lΝ@K9nkg ,6xeS<83˹@ri \m}zk+J=9LCeo?OsSnx>b' /]ƨl3%c \i VmšQxZє'w "s{' PAj{toZ KtsOJnJcr2) 8;ρąu t-.[iۗg_P4(&;)@}Q 9ձLRV$07uP ~ 4Xgl*3vGn%3+ (Dց[73t{- ZVvFj³wa(CL>^^}bz|IOʽʄ=FNb/"%EǪf?Z53ҽX3.m_/oT`Xndk8W*k.2hBM#o7K"~=]_B&xD&2$K , //XO 󌍺c> UI\ ;RŬEfnKˮe=D-z5&WwRa8=(l W^5 [{aW[v *724gn*:LMX2uA$R2 5N_K| e}-Ƈ^_Uђ< XpD*4CgG?6 |1,l I9 ¿ʢ}zzՐeaohРk>p0B;EW"z֬i4 /䈽G0*+qWu 7ҲܹJ~f`(Nd8iE#Q<5 14rlٗ^qň>6cy Wx0T3/+0#%4AcaO.pO5TYD)f58aɱ s`ߥrr* ׳ })ka$6UY|C5aV֑׸V##~#N ڨ(2G2z)7C*"Y"dPW:{y:tͨ,vs# +{K5i@{8#܊?Q4Z#c@%h`Wɤ>kW(Zj-WX^qj)d1ҏSk=߫b,n)UAK۟Wʼ)Y!_ `rL,s>n9z fj*gBxbAI?=$ C*Pssi$a.!Js>x[NIЈWs~k p| _!4mN0f4㉗H% /,WHMQ՗%@ ^UvBԊoG£fA,-W>B6~q?IN{Z@vStRQ*1 ̄JiLq9E rK*<=eNi_uq5} KJ#4{T$s y4baَbM'5rY9|BD,tEdXހ&RD%.? ;/AYXA;֊P9rCА>NT)WJbT=XF1qImh K<{6rPp˄Y\m@ObAĠ۞m~uPHmK_;ck[ $Yu,GBFm@f˯#yNpjƗ{pAt(80^hW4-S4nuk.\\ zPF  &Oׄ]xY4QH(AB.y'_Ěga!&<+^ o1tDJj˩ef;Kb%Ed41[Bt`N'Fj 9XD޼&(u3"9p 0G.M!SvOe0q²'Ð&5eV-Hʸ2w~;z5qk*_n`74#ǃ%s,o4ˍN,W|$o %ƤGJ)77j-dS uH8 Xv{Y3 j{\SiiL ,?Tt:nMlk +S1rҬԩlj85ѓ(rl*MZt*̲P∎8.XZ/H gsuoIj^oD/NO`5%$9T׶Me\{RsUMN{M֨PS[6y[^+5QLȆepnc5)I`pe|GibDet{ ;L^ 3ߊ)A験"7bctө i%p=!:LN8N_2-:C/'pRy[lD?Kḡ|Ҝ*ɿ)}Gw}mUA1abtZ֔ *IF3 F)f,}-8HY/Gvm!Kkqz\y;lR-."ѽ^{Oho$cUt?\B[Gow/#syٓx@ Jpe [d7WAz4%POp Mv1m*D$SAt_]@{[}.׉qMY78FRJɮ__ߩ?gCU|+CD]u"oj)'K98kuSyPB{%J4ފCm)Gڥm(6`mxa2·0ZdE36cv`K]Γ"t(IHY9!I.5.J5>5U0N4i%wڀn<~ _h/71/tdh>MkwwK"ˆ$9'u$ .@nJ6;w%d7e5ت@ށE\ be!nh-l74v004g:YIj#,Re!3U4ОuU\Q\"#ГY.W}I#|}j \T';ZecU80'1ʹؤ?BBY'&[AE v5o=]\fnF|%̄ CB P-F &Ђko]"9 8.䶛Xz~d緒H>+`W3#2Zc>njJoN"9աMx7+sYV{7Z Uj|ha9vXxāC cۈ4uy(!!Hˊ!]pRH}Qe}mspTm~(`!*.Q\02nPonHC6Ret7ꒇz| W&z{U4p :m0?@&фf6srh6|7vp qYb < _@:gj ɀksSFw$tM 1jX!\kt8Np]Wyd,\E싑>2P: vf2"SȐК,:t Vh^yr*L !iGX\TN⡑wCirF-ob{_GP:Nfy?v#aoh MsqEG#MJm89g~2V#k?2Z͹AmRFD俬hu|}Z@_IHrc[muk .G@@MlRI뺯^ &[7@=nj i%)L:1|̤t{>Tyq V~M"[AV+;;1=h}=Q; QƝbtW9GW8&0f{hhx29T ad6!$#1SU\ȦIMv{[rdgzV鸤D)B4%0pRyE1]k\X"Vy(-ftAJLbcVXrmn^BO5ԂߖCMW{',eh#T"GG:U)-J7` k@yF NB]4xFolP< [E| (C"_@O\D#EE]ws:z2R#im=sn @Ť_MB\!J+VLy.V!g[-1{ƁJur[wFyxj<  o4CamMBmV!Y9a3aj]oyaS_n)B9 4Mw2u)e d*ëA>-i:MegRJd2jgP&CBP!5E8P oF,{|XE<]:v.WOh+gDdB劒 @jX챝XD5\`'Hb\ ;s1 'L B4Wlˁ`e0P(R@/?$Wά2 8ӽckv @}X܁gat7LG LNx|+2k&?"8M*يB\}ʲSd A?xGG8@HCu zB|/_IcHoi2m+:y54̤Iu,˸OS&-ҞQ{LJR[zT8Api*F0rL:bw/2x?>{qA։u2a:9I~KLj!c!"n͂j4ŵΒX}'2ݐ aeyCUbduNBUͽn a>6ᒜ\5li Bpr}: ͠8D.Tw:o*)4" aOBBqOWb0ALjGXR:7w$a.;?4;<3\ AZbSYlW .@ O#3.\FD('~q\^ϦʀQj|D1MW xo6 jK d Ő4Q@+5б9-"ԗ24p@`n qMȮqxDWd @k0{po烺OrN.[Κ76Mx7-(yzBC85;l/ ?#(G1 ^_,: 8CkNoG1k m47CۯWm=w2P̎EdU|n_MejjÝ$ocLKB (6M_|?l|/,$tB5%LB:oژsnVD܅gʏM_@DER+$.jC'{M7 φK!|takYVӮ\xtEẞX% lRQk4G!(s1UGYjjfZHmbLd"nںltLZ} I%DۡnD.8a[E>cȇjtQTw`hlAqDqI+_vœț&VFwϞZZ|ؤ2B<ݒr 7hu\ރ~gȱ_ë{+q +vAE^G9N t%rH;*;_PF,7$`{M8$2sjy$_25&D~DOpg#lmG]DbF_hqg*߻!6k2hȹ -bpV\t~ݙlRdl;Uꛒ^"߲%|A'ˇ7Y?(;xd7zhxRX .hK[z 855#Zs8zf.+ փ uLK oU/9"U|R{[G\Ng60uީ〘غ aKA;ϋ$y(x#ѺRXT\r,.Av!;hRIގ7$+'i Nzm{ n·N`dU -|Ff.UC*nJy0ۿ2նB ;SL5AElp 5Xg/B0*}g-un#he&ɧUd:n\ Wʂ8L[;//DYT9Y^3+tܾJ8Pc?˜4@HcLl)y:ۉ*{QF8yRv8:EҠF'̍fAhJ[_HgB)f5VR$ O38"g` [/%Z%][S,UcIacEi`X%o'=57Zσ/ʭ8Zv9sbI˸:YQaaPKDTI+*7w"‰J;'΋ ۟]0˄wnZ֦ww*> IF> ha 8W@ja`A$OqҞ%SU16(jH@^8W*vDGf :wPvY G; à RO1}wNUhbIȺP^z2ppp"jӣ½$]_^U,_DעD\$FVlu jF*4sNq6ED0<&+qcg_Yn .ߕZ|NTOYeDWrڍ)X :]3j}A_y0Ma_^Qцi+i H(!Y#T+0: f]{ة-G4b!4uk-"[ևn4QcWsVVT˂;Øa@iً ip\N<6p䤣(l[U,>L0]qAdE>VQ _2H%ŮSBYClKbA)PJ_79K_DeO}J@LW|fgIŁj8&JLxrxZaY\T^11^LEJ 3/|,:8eᬌ|l>gTa#](8@JLnQZK5ʄd-[7qC"Jm3)I\Y-:E\UZI vR>,44k L9 :W?IDE"ڼ@qu`VEqZ sg{VC1sӸ4ϒvJ}"vUc ߠt݁7EbSk;1a˵#ʸ{ی+B+mxKr%nE@KVϛf#?>(}kqz#I'ѥ+cw}h'd i-/ǝ:?/M48Z$O}[;bq6 (ѽf5cwKK3{ A-"TǸ uCv^KУ*"HۭYJ R؀xC#tԿ!tyڵXZP.#_^2K>L+e0?&?-"#2);(w.*߾]чH Gbdh{$βfM?)竷{$8kEm*XUtnк, qUf'b-\ ԕ )I)$%'=`?F:G0ն+IG 񍰕sN=X ",tӈSY#ɘ0g$ NoZ:v~V7rvw έ-3ڝrRRRy)}z M)<,5Vɣ.^:ɐ<; h~$Ie[=| 6vmyV3dp7hyޚH|[Q~rjB8Lc@4kSC\eX(΍7"-EA"aMO$0`4Q;g `5K 7F"kx_^P/,V\]R&`A{m\Rx&G]ȘT h!ܜvx*"M2\g(&^&ްjsf2Kz9{CL#lAˬw|&wx.wo)Kέ}'pn@&Rs 謷 ɓTK&Cs[z|]F?ohke'g/$5wjW?Q8Z)[ a Ć0r[(=&CQYRFAӈeK/xv:UAj蘇ɞM5p_1)"+@TXȨdXodq-E1_s ;ԅS!B)4 +:[e8 5hv`j׶Y&ΜFb+>, ~c!ٹ#ޥ-WytSը?S[p|M$|d$a ;NTa8cc^ԧQr4@dv8+,T1΢L П@uXIcX÷CT2+" &NIfqXhFh[bz~8O< :\hU_P"MH{F PҐ O`Zj_ !j;G3hpK.l"tU=r]Hyk=}b,I_G`8de\! EeԻ;] s?rPğT온 0QQD.\7+$f:V;hҨ),6]Mh1Wm㺕2\&3Yo9Vge[_P69zV%w+չ[kG6iă#4=cyJ=m oRY! #]AEJnՔ?]u_6X?$ -QxPlN;lAs^{ dh Ɨ *qv}e/԰**KD cڳb0vD~7hzVot$ 5Cwx<7P^7$Emvr͒vd3'鉫7]qpY(w7Q*-i WH^< Ⱦ|C;,Pc,q e隆dW(|cXŮT,uj:"_ .ks^jBrCLÚ=ś=!]Ez޲^&4^K3IGMaeCDyZ(;X-:%~LHxYT1tWe8I(q8't] u;nj!A0<+%p;-6VQa_|7Ϝl''7QI竰u$sb]ZˤZr7RZ˼%Ԍ\M ɶ(cPz.lc8Fzg{Q䑠{woKć,vtyCw727]6T~=r(XJz.jz&C5 ][} Ɵg|z۳fd|l=bPtbU*56 9Dwӵv:UbEM"WTO0AgT[86TŮ,zk; UAYF9ƶ5:HE7QJkb|2 UV;Q6A)9Qz-F{ WJ,]`g\؋ 'f1y\:aQ׏:#@I>Ӧû]Z$Q-^z m kne @"{<9 ug&|;+]罂dd&_ST#KKt]b_`9˅XDպ#՛Sy:QYTGLb} RR3%'sefgZNiw:pr̳(MgcJg-rL܆$ ZS_aG)ю<@fz+kSہF^FǼZAG ^Pܺ܏qiBTFЉG&(vr*᷾Q>y7w-KG^8DJ<\j۱m=l$Z靸wP,ߠvK8\٧:.cZ˜)ZO ,[PX >h2v5ze uh )iP?2C_DN-{8=t45I6 Rł8@uexLhbPw0 cUAFAޣ?B)Վ:k'"jiiszve${"/Vrb%6,F=Pqs3t)cM (k='xe1d>[[yxWdYjv|Y9rgvY"ixVCG<%aɐ'[kT٩p/I ˑ paoDBg`zc_Viks,|dbٟ0vxrw;af"a;S]__d^PvFd}5ޟ5!p6\x^ncss}Mpu{w35 -kxART4=#z|K ؞Ŕ@pTd7W؝&lOHޘ^ "PlgU_ᠶY8|mʭ;61m580!_I]cP H9>̐hkz:뤊yAp:0B1BLJ)r@"+a8uD@3_P@ )/- EKi8=O)G7f3ޞr{a揷~:aV$:o~/4Q*/9@kZLO|@2˥Jع eƔ=o;n8hb@%l3zoX˛ 9?gO,8R̯SX@;*A~ej+zz͊KѦu6顾11k B[|4{FKZK).)d}u+<3i)Wb['ptPan ,SL|D0`||㺔2hN]8R0%) q~%W7_F gH]kcAAH|ɡzyx 1 ]']Hh<ψgX)&X+ c'Z j#pW:"Y6ߊ&k_R9rh #mF=k!If5pPwn76OqR_ hNʹm-o᤹i z^E2x]{B7> Wr|Vɍgì #? jm61 u: l2vp܏_zzI%WB'-BK|;;KOB.$^WlIʔQ`/bb0qS\Au\-S-ƙ6$%31FM4[d>N CB` Zr귽kQ/aa'o]b@P'Я66/j@XmJ%r5:GMz5]̅>~@IyXz~D3ϸ6TB*tf8AUy֦nwu2ȖPbx6])J7H.8(TWd -?#܅J6. )q^C۳'xY0)f3 UeH_,J$а^]Q95^l.z2R{ Klszɂ/`^xUΜIw|;$r⣈p\D+GJLqTߥ i4bZе؉ڥk+1pÙQIؽUON}^i>LoguX^i"BO/ZcHبN{՗S:8@i6 ȺDsn*ϥ!0'}h"u :fl;?4Wr,kfW~mv[%DSa_EsF%V~G4c;/Q"P>D &[CʎWN}_uVPaϗNbT'P'>QÂd56WGo BRRt %0#xWHe~fSOc$w+c!1t刖(eY_!wJ Y4n!~Y4* mQ?OV1GaZhK=m^i!Y){̈@TgJp) 9cF@gz-"n9%ٳE|6B=hE0dB7en PѴ;l7/@ODt<|Tu;M;xeRjiDF꬘j`efD!NDUu) eB\""4 I8EѼ kؑ y71obaƒ5/H_^->J]ntFm{& Ua UxEI|$7 ^d[XRc ?ޙ.?Gx6 bnZ /9i) ي glێƚDi r8 SmHIb*&<m4ډ6N4`(Z_PH:KB_% 4 1.)9C;$wBIɟ)? GJ¢S~މC`| rq`?Uyy[~<R@ r1kz"eCE}s5nk3疍.$ ZT9] |9  9UXcoo4K;א>%٩6/Wq-8,ղFJʁgUջAf(ּ`eV=2.)Hkб<ْۛ)@gN'= ďU"t8'c}H p$:޷>Gw$ºJhO %&$y<4Q[өIJpG}ۜuPyMڒ6x`O*Șq+%؁5wz'b:le)Ae 8Jã!2Dç0SGOa~Ib)*-m z,/fٛeGVfBehxsS,@UWx!^^@Qyw8,%L(#/BaUAg*-3G*e&aZϚ~+|Q D3,5VpkZUWSjq {2 ^Zmbϣi_XME"Xٽ2OǴSDȿ^PRyQ4 : A.ih_1E>XJkep2:;H#$ҷ.X[k%Wc,W] _`9bєRك.SyzrH"?gJB)ͨQKҸn'0(:)١%70|0CW fjx"X2-^ɿy"lTQ) erâ2J7+2)!Oе[\̈ *,}V1?+ilx%DԹRbg ^BZN)Rf9EXл-\EE݆8c)Jڤ;,;Uv~g ݊77@1<*vvP{0P95<DMwBzCod 60q~')`202\x-7ܗ(pvѴ``(FeoĈNʈ MC$# Z#c; V8ց&#C_oύw܆R NvKC(j% #ڐWl9sf=s] k_)my 4{;|ţd# Dhϩ sX]jە!?Խ|AD64E,Y @vIч4]j481g@*׆-5ցn7ly6#>8KMnxD!MMOZ>\L H =8#HiiѰ ǩ x/QYbGVv$TROEzMVq PXJubtfZI;$]?%L}UiVd J=7}b#ބz1Na!v?<_ބ S) &Mlf=ɆD8 /҆&z5ʫˢ/a ^`tfF%fe۸ӿɘÄep貲c(A\YeJpV`GV߬Fo5`Aϑpz!7Ia+Z7c:"dt .v*G#ytn'zvr3+&+}t ' #UZCě; *ͱ`IPUBd]s)P̍JHW ƀs*I aPtVx ?U}HaC2rYhя›L6ϦlQ gb϶vBpR19r13`8o/J[ub>ax$/2V֖n=ЈÔ}tz0b{ ;p D˂PF?dRT$M:z =mWۚJTcW9|RLS k2j\u_@;PԟȟFb("3 e}\lUGZS@8l'PΦ@_z6F"\\+)(Z4܋gl'2m*mHtop 3ΰN,2n zp"K@NGe@`n#ueGeʃ- 3K饿6k}tM[$sCn8f tI%Qae3yI1"R5ۙ+۽cCʶcq:L {s %D8q]m{w)}t5s}5SW) 7#% ao*w;{ ;" oFCsB-Ά㎂E촉U1)b Շ\6LG(UGcV!j6U셿pf@߮#3Vv/1d:5$no8tє[sW.&gP3bVY)gĿR㳼2(_k{-n(J!._x\A(@HP$?~]AD `j;q2L0Nh.Rx۵/%]J͍ݓY|]"ĸ#N"V},pi˰kL+.ːdNe23^ 38gjISS[B {_pk.*G;e.N8W*'O;f8TZ'mIV]ݫ@NƠ/hPrXWcɢ\l|O;-5aSxW#e 4\H$鼄C6c@"N<|IBHDI)tJGPVr]Q{8'Uf 6Ҽɹ-o0>1|DcS>ʪ]U!NqpH1Z6W+W+k't,6.t73~M[DM}!(Oް3  4:rNhЀzNA\uQ#2v:2fLH2ŽJ DRh"=m=vu5Yp!BHe~/NTjrl^xº+N5I-ڞK]I}ISкIiïCA^4@R-sCPm=\;sQ*qlRm^P9"4ݻbIUnIJ $wl';j.#0dȆ_a,6 ڒ<1pm@f<۵7TcpI7U08{a6f/PJrWYDST;O<:Wy{&³@?ȿ,},JE=~wm%+0e- V8b#q.(ksz*jNޔwq@ 8[` fdRH좳&TQ hhn& CCo3)WMneaɁIwejF/q$$۾7~6Wܱ(.w88 .WT~0I*#G:`"Iyiv9Cڄl<1(ÞMk#)Hnd"z4/l$Gݑss;Q%&5[փe{Z^^Y0r@;|@ %XmfP]M ;W)܋Ҵ;J4I{$MwQ԰▌9S ʣl$t^wY)Y+26Il5(,w+ӣ1Vh?ܲ_+pp>C# ,Cp0ےGϣ\d_{zUFmw 4 // | o뾫^($f._…5&]Of+*}8|6P;;UVpdM=<ȔQ {C,b:e_NZA҂J.71b $ 2mU`N`H)OoԱE8aS({`,H))ɜSeTx6\;Xl~9)ʯ,:!iY+~_H^w{|>nv %ڊ({O~!]?Kf׺ּO~KUbCTOInxs!18]yEfƈT*nGŇ46lLr|>KYO$|S9ƒn#i)UkCntzqgB'e&hs"t$}ɠdY&gvgh: 1S@[qN\£{p4o^(%Rϕb&?wM{hpgԚaX)L샠>Hj$Hk" ,áF\v^-1"hjZzl2uY3e?RsIVm.r+2`c/;epF/Q5ênս2o~EЧ|qE'?ULxuS/w+Nk[VoP1#k 7KwK& ]5Ɓ&qxTe%Gpߚ` ^6]9m>:q[oUy$aϭ?pkm>[pCcD{c{6fY"^nO>Jx-fQ-E磋7Gt}|7r5"[ECV0e^2QU3R^k".uqK v<ބlHp9K: ^#),5[3Fe,5i^wwj:Gul beAܷڪ xx<%7poǮc"7u$}P ;oZ='LX<[kȽ9;vhaf'|^j=풩/E/bM0DaEJ~%6&hjK#:)=Ay}=瀎]9C:nb2oM;L-U>~,"āR?(q'f&M#5R!k4Xî~Ibܡ܈7}˩Yk5`(,v5^pFC dҊ& r06S\[e\x`k\R (lYcPl5-8茑9rrcr ]2Czղ&ϏjEfWsojgE]t_ 6DhC t?$DJ(^.>Oq2 ?-tO|鴵_@~?9 %9%2pC 촼Odt4%ܙvw.Yʓ<n*zpTZʬmp}_,ǿ5HaoV>pMAmm =3 vfs oi0?AMhCPh-YqYbyqRPg': qұNuq#>\,sL\Uʿ'%4-XI l7k^} BNNEVM&)vm8:ޫUgZ9 **d bz3U?I 'g,ym [ؚWn ܠ'Z!0Lґ%0Ie6)\`Q]gg2%73Zssr\+\&?O;ED6֗T_5LH({nKK[Q %+GuNظЀ$G8(.pa$N)fyҕTe1U'4=,4eptXN2?XTu`3H_ 7w;c7)iM``}`CsPAEIK>Y/Ϫd2H䘕z5Jm; XxmR.j$,zo@Oo5:‰J?)tFM)lPLv`S=] 3}0š_:IdiY]7H|pf{i{Q-}pOȶ!]Q0WEGl0R+wٳQ@A/ F|s$ ǐ Qӭ23I_g@sg nݝ5{|Q %W'wggm0-0'j7 ƃh=?o e0pbFr{v3^|֍N͏K{K\my{`[q|!*-ΗHxm$}wxW+8 NűU2쿑ы!ΖuB! 0DKzKϢP A8V1L?ԗ8?.Zڿrt#2h?."` dN;ˣZ|j'N5Lsb_؀tV5) ⹻aC)e :mEux[;i??Kc!ٲҐV Wj\ՠ|މ!Jt\sh HyFs N~`OugICXK>;4mԫb;᮱NaE= UͰ"k :$MoChJkmOKS(G{ni'AKw" ZΤ\[IaK܆0 ˡ]Qk}S _G8裝ڰ0-a'9 >%{iZѿ=A ,jbUԘtU&}eOa1* Z[5jLue1P hղoSJE<šs&tQu+2 D #|%slk A[X.+ڸbHN5gZO7Ak9;7*ԁ08@#i"OPu@8 33snM($s\b6ݰþ'sہWOT@5| +ls+5n~A8a(SUG?G ZB>>Uo.+1s9 P_y*]@qչo,#XD~[.)"NCނLdzQelGuOX_ocA4O^ 2^!v, Թ .$_cj3P־-fNjh=k\a)b;@sq[XE>;Q)EЊz3E&ի}0~ K\9یs'Vr~nŭe%ݾWQkG\ZH@-14I*Z c {cIE6b H$[\6n%An/0\K7 ظ&d83dg\ σ7Z<<4%fkN|weUъZ>Ѩh0!:+汍łe̿M5_qT;S~%H#^<sV$m.w `^;? [jt\w=V\0c$g?EQv89O ۣꍕ~ޢIRaq7l|y*`fG\d Ա >ܖ3\Z䛖Jm~SC^ QSMbJr#LxN"Mq Cq FuWv[{×M圩6>3~KB;JƊ_)EJBfp, " Hf{05/Uu\J-]cLhS"P8o,(_9wt9]0OCVa(~"$O#n_s8 0zG;nX)j8$ϫKy5 uiuRI2AIDdvI5T9B@.Tp3$E9Kށ6A׵\Ht CǔlkzrQpC"izE/f1>jXD j4r1 HoaXKj|`-tf]0u f^kF[%f6jDMGK 0/<0y<Jx>2Jh/ƹmF/z| )n;ْL"D%=؏ ;{b9ݺD*-Kk]\r̥ ?r^.IU):@0l_2}IKxNgE{ æL2\+c~ꊖRk:q@J>QtFͤkͨ e:Y-7Ԇ΍QZ ݟ_ynsاjs,47]$p\R,3%k^Vn499ycI^ZdKeWD1eijYs/M3Zr,hDCXee6]j1ñS [uOJeoOBPw)V:xR (&Z`.pWvT ["ȚU;r$qqZjգiwt ĭ5D_ 8H,MSǻwbOj?c鋯Mr,|gb-c@w-3$ⴋۓg5ۆLp{6oJߞۃ,x$ ߀A:$v>f%Ya4.)}e&T!],XL.b_(QUeC =o /|{>tE`<'>^uX20QQ~5F. $Rtz. j0hYW7/E`:+(uQ?哿WMMu읠u0l,\[PTMEPm:N*MR_i\ 㑃GIIkF )\Ht}J/bfy(=]o^YBf>I>0K;zmc#(8V}H} hѨ(>#TUw"R9<1 /4Is1O*=F[s,i=qwk+U f5)v!iiَ,U*lI%.~2j.2i /F*?8Ԛ9Wr#02H@C+(cȍ][{ӻ Z VWFF;v"1[$J{9!O ›֥ꌯ.V޺8u._iGO-hu$z:@oj@ѻKl&ayZÛ7* dzv܁I M/MqXKģM!||?^Rnj6r+>f/\Fd٨.m)6`sǴfGI{4IA0?U6TO) O k+I-1D%Wegʅtf0J6ohJ=8$3vd.ԵG5RZAdx u|V*B)\V7۾CzZ.ax3gA/7:d]"Xx8v/QwUK{ҩl}Yy+I1,le@(6@f4 ʊ{CZ}X&5kSK+M(=I 1̸VAUt3ej=eyo V.Gc\߱l, (فRLHE /;GP+ے" *yosi_A4m Mz y9)-|)׵&@&`,Ony}΅h:XHǮ zo=쏺OI2T⳪0^=ݥd2 `}q$y5ؾQ$SkCԏ.SP0wV\  7" ^MlX,:|#`ȚX>CbmoJ_JV>Je+"9[tC a&T׬Kt~M%'b%E/"(OκS%$ +ubd\BQQvŖ쓂\|gL,IM|۹e tn5m|rۭSVPö k8G@ra@WeY:@rE8DGѡӅ :0;M 8V7..GezDctܶ[!}?p;˂SvI#'o(Y9i2m8}3}ҪOĎwg@i!4gʦ!Fc^;Q["9R\ZDӏی\P<6y@FqCTӄWgF|J>!Zp7ABhtL%T*bh=me?LͩilP?F< obD p`߱^h%צk6/OV)Rm-XҴR1 $~~J-IӥSH kh _ki Bq1߃͕ˁ3n~l8i`Q!dzBv=*4q %栧\/j7JeyFeDVo݂Ko6 -`v" A.(MCa(S<3I9QG܋ѣ*2I}8hDddfEŤ@lk*٧gd6~"ˋ*9ux^kBpijነ-O8Ȍt[xu[[ %0à6EMkoi4#'GR^CbSńWH#AHR}AQ_nY%oՄ>ap aBsdAy%L{)3t˿~;sYzQyF. 8 E0d3hclԌ=lNX\ARoxp <׏eH^ad/q wpa8S%f݂/>;|Vk Qlˮe|SKZbVX\*m#wVȐa֯2z< uШVWiMaPI(TNYxdȈsvsLڷXpqf[[%ăDA! l#7r{q PW8y8yf E`%zqFU4DNRDyq1fYTn`$*c]!e5ғ7vI," 4ߡ421VNۦy^(c< ŎZeilT"A[<&k*'(C`1̏[*-$YqLbme@yA>ś ;:]S !$xDh% 'L>C pB fƴm_ & uZ؋ВP&pY8r>?Jtqk#*#(m29,@}գFXWob l00MZ{7_D?@ubH^C*z$@j+1+dftZA)*(E8Ai1iI4~c5BUdVk{rB&TiĮ$+#@p4%5Ņ3&bq},]q]ɲ2]=4>m3\A7F4MhЌ^`xm4jdJ"]pJD!J зVI~%vh*q9W2GH-PM (5&bŤ=isFӇ+A>-Jz %al \G2̟RLO^{%Nؑng0{2gsj7 ciⷸr[ejL}n5ϲ֊}Xe"8+Gy'x껤)9né6NN>,C*A"(QcK}.,Dیp.>]39$z,Pug!xeR=G[P89stk>7~]g@tt6[] uu2~ǚ"}ǾJC2A{;4)9),uu xiE/ո(Dy9Ҡʼ+QDp5-Mڤ[aLaT9( l3{Fz6Ng)eq.xu@&y Oϭ$Yp<]ϳU25w ?xjQeDu`[=6K)~ @NVKg8v{ KB\V[rd#f̆_T!`3=XH2R^6D^2F eo] }m eHQb~ew7/y/itNd uMh߻$ýԡ}=Ѭ GV%O98᥋qKAӵA+siy2 !ӭM%tTR{~YX~ ԕ<He7# $Һk`]f;ЦB +3fެ/3&"&0"_C˿AڨA%yX$`K@;=ahQ.WCs܄NJwծXWG*LJ^Wc@Mm!$Sv%C|t.1jMsG`%){jyHܪ?h]^m&g[V1T!;g$4qHfP<ɕm nh,1BQ i af/G VhMӶ[oz΋g >n"4W̏a2mm=w޺#&Ę3@}f@pKU wC뻖ar %|p , jms\S澸'ق|òö0 -G&b8&Xtp>Y8y/R';)1"A/;_Ku"wΖBZHE9>:wG_r/{ִ %$+̅;:Uj@ՅDe0 yO`FO[ei"U>qh ;I]R^ s)Ȝ|{λwkؓ}F\6M"A?]4vZJiNk_= v%JW&6 }g)¤%MUX&$7-oJ`#O0h 9~bY(YepsA'9?=FZZtJ%qil4 ˯<pO.q Vnw|ŔkHa: yMl7f^nC]68CM^"c.c]duflaaԥ<#{1`&VA54 gKnPV_ϿA"tUtb M 7bͱ^QX 9OXEY=1I=/ @, Ao'J'& =~@ pTS iG˜)}1ܧ3lD~jr&3yY%ȶܷ/= yiGǕLI66n?GCD!E=/+Hk\mfϵ n4M$]T?:$f{OryM 2ʛK"::}0Q/"{+PDC"@4 >åZvKLyu NB=@:30Oo{;YZ3cQWO]_9fTONO,\Fjog{UGDH(WJ Dhڭf@$+=y̼;qE|b F-Z¾1݉?  "s=_^_73ih넚]&TX۹ʿa١0w]ónz9p<3P>k5ЋqlnPT".Uc Y4ټf @^!hlvQWv>xjlqdMYmml[Ƀ8,~[e,G.7duqq-xDa9e%4q퇫y$lQobw=׃X1xfH)FbdRzhO1(ٗ(lt?QdŔ X p_] q{⛎jЕr^).O@-o(8H<&XL‘@+pŊXidb~u_bōu{In6dW=sjR [^ 4HQQ@NT1Q!2i8cg-gPF֪'"'1eBmDs"L9y>W4֣L55wKYL!GB^#>8>gVm +w7'RÈ)_?\unxH_ ^1:徑|t"&d%lI\8%qW$2P A|hunMD;)00' V P9g O{F4kZ( I*y 4=o.ϥ-JX-X_˟_P,/(bz?q6JwjI:18ou|3j4xHCk 6@{ǯG@hcnZaxzڄ cW8ש},PصЫJc Laٹ'wDJXmD޹]"ԇLR5 cG39fcYWܕ2~c(% n/ p0T<U-Eԍ5\kz W*lY[dkt3r=Kbv;OJ6*{K/5pB}n=tքnlJ5tEK``T9Ǔ\K_#/!|[;P]RYteS9q"o?JDq.9*hHe?㸊 OYw|^LBuޕ}4k.<ݑ.TB}9ޮ0KhZP/LT(Cqۆ2]Y!E N%v魍9b0{yINjyB\9ɨ^7sY 0StH3 6"wMJ jͩGyXx͇GGyy;LdC&RK|N/+$SNvm!JL&D >oBɺs uHb[3/5Ϛ H_wۄUv'(P1.Ӧ,'HxE렾+A{fÍH l=qyk.PxiA)Sb"* yBdB@Z=qQ|!d/kiS)v466Z`쐌\G17&۠eQ_#y Ja`de,-Q (s$?;H( JPb@I탠" \23~l rȨ%_67*n:O1% Ԭ P͞?cŶƝ~t,KQ~m,$)ICOm^? MAJ[Gqāj oMw#``@zlb3Ņ\Aq5ζMڪ:n &[Q" }392h&=Y/DӊPT .C*hK8q8FWT,Yx^v!݊4J B@V]Ŋ_\s X|k4+ܑq1QӇ]3"Ns8beVYsulFhtaK P4[]>*N@k%z6x9kEo(d|ckUJLJr:;Eɯ+EKF 1h1-GZqqhÚgQ--%gЧG~խ9,ޭĔ"_UfTi3sbr11%S ̩]$dv"둫Z ^mTrhBMj#uIFNMܟļ ;ANj<=ZR.)aDS,b;Aݿm$lSՖ|:O',XFǀ|p}Mneb@ NzČճ?&YKPhMjb F{ynsքlAz&f%}hڧ5Fʰ@9 &;6mza#? `2DryOj`B`$͊+ R|UDjx`DQt2K'K]v29Bbh(-Ncۤ_{"&Gc>saslƐ"7e3݉&XWθ {jPTxO&Z"5(kB,$7Lf,@Xv&Pr2e(SVmM'טQ̠ӚHcÑxSفi*K3Fm,.w  >, K#P]Z9K09>BzQg4 aKU7bIuui7~šr?0ؕ/ &TBX)E@$?Z=Uc'dY{=$Y_42$} }<`ʻWEx?yzha(Ghh`ls6ɢ T@ YPjbA}4 rp }z.n*zީ|HY_^%fJBdTmPn=$+Cy~f 98{KHiR.u,sc29`$lؠ8^ ~ b1+B#a8k#dAGQ_n ŨW PkњK2dA1Ny٥svPC!Ë+MBܯz6cѾ09ehc6Uk,Aғ3}M}iJתxzp$mi͔w_uIT4uuP7~XTܻSTG v Vy;8w4Zj*X{oT_vEli-\ux *z`4 ![pU%u5x_Ix$M׻;y9˃L3#M>S)`†6n@k$m.؛bNoeWoP, \p+. g7 B @᡻0*".hۓZW~J4T }7ZTݖ]VMA{ޠ>w9p.;y{q 'BQjp_eD6c`"ѾdqdHn}W&L X`@S-u\"샳錍d!1bi64'p#e-56%)\~'&P3Cf,m)"%P%)'1̅lw(blY`Dz _ G׉uk *YP)'S(ᰕ55rh|wݡ&EfabRȑ OOSaɒ>dM| #B%04157?@M*L9ZTU9 L#Q '3!ll@ڪYs5_elBש\p p\Ԥ/O/;ھwq4`YO ⚧pLsnUcgRj- 8%'7fR5좍a/[&+oQd?#ВrRX%q pK$ʈѱfJ[1bؕNT`h}1Ϯ>ܟ͂sUe[_bTa'o.y\+ NĻNf})TZWI4LC)Oh+$GmgF0*ecWiIȏ&uf-x9h<Ј<0VeGO1\i^НF`]xb-c-6MLr]1Veuʋ"Yii +W9#nw\4Z0*V4?\Ma[b+\g[4GOJ]G#-f<'2i.3 C4BLEP"SF=ʉ5GhPE9lk:m_ɪԎVo 404Yv~Z oJ#C/+I-K=J/ JC~8_1E{AQC4Lr"[BX4~gHJ z]B*T${@+T#N|>|c]Ng|]`k*Tr WblbKR'CL3'eb+D]9Cy)=;kU<:'+K(^M<6jdv+VY X-$8cT K4?}´LF x9d1 V$? f}8`dZЕNX'ݥP^k5q|e/Q"5"Tڹݹ+ʏrc4 MP^b+߆.)" 3CuK)]e͞)FG9[7B* ߵg(#JoB,ۈC6ˁfWf`!0k IvX;~bފ:p Z1+1ȩ¼?_ f2[僚H"La-;u4j"xyIckÞk}^s_IsvЎwrۓ40so20D2R R'.ӈME KoTs+BA@5-=4N'! " KT!v'Α~RߢfK41=ᷢt9I{vXP)I@];ݽnS86.ӁXZULXZPi[txo;m Ec&S ' gG#۵:0q&qNH/&_!yζ=c[ jHGr,2CJ2 c eN:apdžseiֻ̿r|?/.!AsT/ˁAQl,nFq˹#e7L;A䁕~ <}X| Ğ~i"̧r, i_tƤUG9-g5zMPzn?GL}\5{*3O*aK5S@Tq>Nn~Z0=4G) |8"!odeNH:.J^`WOt}k;t(A>i ܌ qs&q#Z){ xxkyZh7cYH)ٞ-zNs: NOn[z\3Y qZũ8 ŲwO[ӷka%B.A(NO73%֟BXvZj\DU3c~*p6>eSFAV_K'*_KwM 8m/`@m[ Ty=TS,b=չVTgWtY(X7I0yTy-bn낋8i6O\u#As5ob/YBS˷"Jن]`Z3ji,R)UpMnxC r^1FEB{Θ&/ ;|];x^B WS4&M!^7b^Hr\:v}|:~l|D~Dn头VɈJ6ݞ='n,Vgj}[tLL74N:CkUbWpT۬7DH$gć5"~箖IEN ncbV6WbqM-am "t7#n ?#JsLi+ROdK _19Gg}ГBdBlFn }*U_Rː&MUӧ, ZLY|t}#Xݦ*1ɐ; JcfS7&뵥O'59h'jgh*e-V-(Cq{(Ѩ#!Vd#@sNq"ifge^ɀQ3ިe >nNM>ȉ zaV %!jGiS^m7{B>jgmr,0FZ6C[Rֲ〼 ɍ( SZJzhy Cu =Tw~v[JN!N* nLfNMYH'%$t}\pfUfud}<%@mdEmRq ʒ:nA)GeZ qu0t8)8rf}- %g+SCZ*YnN+OOym; U MOƔ *-iPL9K'>>%j%쌴`#v~4AO6Tj*|$qElH x7Myӷ'Q@vvaFRJ셢E7zUuNaeF*9<&4X Wx+fBul$+DSV_چo:iD2!mYIB4Q.TWATd1_~)Ao}yE{) k@ګ5 LIˣ) }]PRZL^ʩƪJRMLbӡ$kE8V{3 |^Ic>xy!., :V/c>yb|#"">{z\c/8ӾOag`%YϥK@CYZ cx?lk\ʜiv@9Z.;hRjDӾjJ$]^Unojg^_EODˀtk2ؚܓ3E늏р672OG* nITy#%f;)ݣ年8 Hݭ=EC-:XiyP*tkψ>c g-p,/*APEsQ@|DD p+أueom2+k5%M:i6$"&( ek{kJ#yoa)-RP w*6I(pI%6HrǹPQb=xd>|$Эu:q;߰Zw;e@jv۪xdv#cӳ؁ُuE& <׬@{5D ]e ճ4LiK]%L|e_)%c8 i2AM] ߩ&k0i=â.hsٮak"S\ : *`V2q8~% k6^`'p܊@BT[?*bF4^y7!+8W%h-P(cm( \W[ 4Q:\9.2[4HSSkqSp?5͵G;o>[l~׮bԍ0q!os慭}NHrU4PIՒz'{2ً?zf"䉘#S@ȥ0O/YDzs"oZ۬ۜcO-oz]~h-Pk` T$T_OyI3HydwuNNC&ؕ+˱"8ZYlgk[$b.s:|. r7}}!I`Ÿ% 4|,3FlN17H7.ۙ0>,fQ/\ ڸ5Xs$ID o+XxV_=ʟӜEЭܷqbZ)I&=`(z6'\#"z"#*@iqw/eHrU{C88r3-K!,{vfއ?Z`2b-Um]~Pd\ܩoNNmLMp[ M6tfZt+Ouh` Е#E1%qq&z'2XZܤ,٫iQ?>'Rh 9h0()%9Vae!>{E>/ Oaw^$U.WSSr`\Y1 pZ@ˏ~>~*3HE^<0aH٥b(%^z[FLjCdž"Q^x~'"C;u=W=.Fi͎#nFZn$^bqM@p!-l\H/YtLz25Wd=1gWpC%D*-V-}텓<9bN5*;j1)u{d[J[kX^sbLen{rE{AJ@lB[k5vY^ 6SU`l)UW{r*id;jW}XS4}8k!FbmƦg!VΜ!RqHXmΟws'xg`A0[I\? `ˌ!S}Pe q%GYoINa=:n(h!ʧp:O&m_4P^%0Tϰ[t]WUJM"fWbW2^($R>` /ÿ5 kl䜃%YE#ƳW'I(m:= 5~Y3 ,ECEG¤:'['JU1Rx >$ϊ¸^6xն5 |q1tczLCN7&l[9av.(rL.U_@fϽE rO(`Ra9v0{~SyPV]?@~,e3%gܗQ|ٳ]QMΐbKQ &=k9 bǠ K5e$ MMEݢItŎ ӻ}-# ÁB}4J2T %B"f%bXϯjn uН (oIL$\f>|$Pʴ0àӬ(nYPay.O0VƢI /X0{.(T@ կ׬|Vi‹=er(rW]O z0ąs}%E KD3q_i(>E [BqeY*l` ۱"Ov\Pk\m͉-4 hGUj[n/袴J.tڔ ]Np׾ 1yし04{'Áߕ<O=\wmńh^| NZڬJA*#GT?;VM N:bIҫHBc-s6dbZ74bR]͸I9"t>r4W;+èU`NNtd֥Y=3✝XD"\.AtcgM̛^6a-TfNBYL_ׯgK{Swti),@1+u`{@nt}}FʡY9ߴ?~0;XPȒRYchJ 2s 8ܥbaFQ )S.tFΣQ:O\\mU*'0s$]&]G󒻻9T;_$`E'';ZSDže^Nݷc{yG.2\]~vpκ @l<ܻHADBsJ1ohdj/^[r|܋nrfm4㌓d1844FW{`Ƀ5NsN~RzQ`MXbD2 ASXQ%Vp@f5{Ԣ )oVkZN0~w_yv׌o-uJʪHq|QRq6"~ٷbL7l GY17$!\#!O2`.yPkFD yjl4H}믐C~u&OH;0҂%O'P7/ o$"T? '$+[M ѓ5OIahӁg]bBH5 P3i{PlP?=/q{'5"4L%DCic%.@৔zٔ^S p'[~D;-wIᆕ2٨tWw)׳1~cFq-&=og %(l5*N:#U|(!b𖮌zud}N_QQCy-WG%C4>+Ap+s|ld!ļf;1vFC] *AhCBm%7vf|kGEU+FZd:pD0r `ybbh%hJС>rtMW,K ^BtIB.@y` "Mu@3XG-Q?׊(# %,hz6lƌd_#(l1iBշhE6c bBŻԉ<3" 'VD3*fn\ԑqP:{!͆`UfoԂ`nc!Jte*XjdW7]mV8J#7D֙r^Kt!Zf[aqB@F>E3rD@TgЉPs8p3IЛVA1|dq ur C|/{}3okU O:OyPI ãנ[ccrӍ&ujuE`j(~5EZXy]9}2R OR|E%#4NpVӁnj3? "2 `BJhuT; ׿ofhk`xXJW擐 mȾA//$WbOz^Ҙh57JSkmMuyɿҾ(e-C:O;4,W 3BٍO>:l@#@VT'AQc0Վ j)덜^ s-wp3CRʍF5g 6%3,3 OyIfc {]զP)]X.HF0IǑhI7zSӻt$L'š]aiUϱjcѲ}?H׽p׃ΌGC:QIDR.!Q',Fo)M8t5g[Պ|Yҧcƹ(;l9vsjjA?T̪976_+-Aj/,ȅ_#df!{ʣ\GZQ7(2O_5U0fk0ɃUKnK'l^dx1oaIIw68 *ݣ6>:;v&hU^*%:;vPΌ4æO`dI !/@ER4 Xp앱*GD0ާḄ8k\՗23 [8ʠ ~l-%K~wxGI,drY/*)@82Lvϴ/3M2wW!dFIAɅ3fZ6頌սABLt̫6$IK$ JjߠּCJuN{P]H.zpPv֭]bv,bZ;[q"d):1ѝ$ @?H$/gMDk=HNO>)b ˗7[o9=AA`WzaMxJR!ɓ)ěPi>Y z3 xS:r`H/@_x.g“b?xT3*MHj!ZJaTjv5ʀ̱rŐSi=-&Oc:| Ca},)|3ՅPЃF70-\$ +A˒\W$U|` L|Zŧd1r~\i ψW꣥ Jd 87 a79 k[P 3csؖI-Z.*li[9:م g)&'gim-ӿ'%V% +*X^pm* 7ֆ@89v`x /qHydN6S& 'Z p;|uk텷8!V6-*A?B'[cRnP6ѱ쪫}YD>%,-U8 1܍`]g8y f}Oι>9] AxrW"2j!!/z.?õo͔1tZTnvSfES*%CkP>C}`Y{8}$i:8%E~Tk(9A5Q,Ȧ^kb4^|b ;'oڦF6$&Y<[9qFB{5$eK7J0IZVQu(Wqo!q旆#g3%)5Fאk}JY=y?0;LzIgrQU :K"YG̘4NH 6UIh A !צz0}KUc-|eSdžfB? }IJ{$wG4;#|TKX?ˈ'' Yު(RchMWj?|AtIGc D/-Y92{r`t₉xȇ+7mz>"~fj^ |DIZ/=F ]F]XQ*!YeM!"TA  %;#T٬Z'gkT <3b`pÀ(6o\CǴF8(ԯt RcwHY2 )ti-YQ ' ~Qi$[)Ζ Xn]c; uJWnNI48y1 b@VK 9BL!|#3 LGyvO\%s?? "<\g.W5% ]a'35UMSBD%/\R%}iS hO9>M+6`Fzˆ8P wQ/:>̬ſx ]HBbvfi6BҵFv{5#Oy"@z b>uq_;#p TZv աO5]q|ƞu ӟѬ _]lTH?Ov@CWOyl̖ɾ), .wtf}!a)Snv%D1Ʌ{<lP#- 6&ܧSO.'O5ksZ "sKBEz\ijQ^kҮ!,(c <R(H$ K`Ԭ?Tz&eqқ&f:삤Wko 'G<85Qw>y0} 'o N Jt`m2@R-aAg2#B8*_Vg5)*ճ ?j݀=j ]&E#cwCKY{I:Td h8<%P`!KϮַgZ}(ݦ{`ZXVhaXц4_v\<PA3$Կ+"~3<bM ̭ WMCx.S^)UGzB4V&skfBBc;Dٴs8ξPYh ߹CVi"׭hiW0 ޗliLtd2A']5gg0 (Np\hQ}B{]:a&i,M=d*#V+n$SͳUMH6}#H/Vzq7 J^I]yapЛ uVP3:*p- brL%Nz =TA33Fj8UÁ3G0œ ڢThx,&^?J$ /CGTǛ*2+~z3M s=rjy 72i!f$ '^|e|@41fvS/h*ۛ0Z:+Y/q¡6%yB`̄Z~Ǟo{8¨K΅D+;l!i-"9CI lr{#1褅fR۵jՌOmA~5zk,H"8^L-B|AWF=|$e~{尙C֯)V`#܎JVY!M^!E#6e%Aw6Z:m"l8J:do"^S?k|k{VTM-Wջ[A3m![1/^޷N)wؿ7aA2lҰs&Hf[5D|ZR_FXXaW򹞗u|۾U 9[4H%5*n]IJ4 ojggk),g=X[cK BB$-Z"~ !Dx${$YřZT<0-*Y~@72#hB/iv~Ջ|x ;)0{xO3qx#ͅՉdn~Bz GWQCz].]?uaahssGd8EhPrŷZV܆\/SW&yuZGKl9hIJ ]Z>Qz^o8qw(FӪ9ѥtu- >xۢ;Zi0Pj!8TvϴzS]Z0ZC‰hJ>%0/|% G,3457;b \AgaRNRVYkFH³:|=WWuEFqJ-_4ţ]Ӭ`::9cE%ŅEY]+=4d2gRee@x1j*Г%撍L:7xλZSޟå-hnþ߁\,n!o)OF'Úw.,e{EB"~p/fŢP״T_#SF+̍:OdG!Nc ;Tzfx7Vp51rog@r;(  TCI~^G?RD]DŽ`ǥ|ARpmݐp>DŽQpz(a+e\LZO5Z"`{0TZM>Y_K*([s pe'aK)g7(BZ]R21CwxӉOWN? 1aamG#5Ӧ|p&-znm&RJo׭3#7pa^xH6.r`:U!Sꍒ[,sd\ޠEFhs?E(s21̎ͨH\С'2"۩‘]L;Al @ fR)i^Jv))`eAGo(o\Y:%Lt1>G<0{Ꙋe19DS0b~'n A K۫`w6אo#:;֑uU;xuC")"uMMYcˌms[T N$+Ag@ކ.~ rA E,0 7|E[YjpdWk-(ٖ$!^3'?,;I"" R_ cejx@}A HbNh&J:!dܔ7+ZYJ HEi ĬV! ׋KsSSG ĭDoY+7OYK3:v[vbP~MM~V#l'NRNZMk_B< BS qDaOtb&; pv3Ur_-/O3O!ďهiGCjcm"|}t $\ͥ.h < IF(d=osyeu]iF!uٗ3EM5 q虱?HY"[ȶ3` G!NfȵHĝ7.L/vObO Y.4VGNnWr] .O4;& Kv0}m? ꝌLvMj¥%3bthGQ_0w//Lr~Zw)N}z⵷!0Y2}ndl֛ <>!vwȐpF\-E+mb?j|\ /[ kll7۬`DyV7ݻ # a`s #^e 'jdwۮIkjj4voLi:D+Z㦔"80i:VzkT8[bbZxM9IThYق\= I㮞1A3 .vfLuG%2U8-Imvxh)"KVilx(G$:B]IbB K]61V<1!,7Ix 5 uaB{>abc NJdzf~ !sΗ%!%})\L23P6FMe'L}C΅m$% U3Ϩބe߬V]:^ˉ!l7Y'>B$#H_]kӕKޝD۠~Prs(|aL pl!ޭB 8v b$mJ.c7;㹠T hzǤת]”ٗ}iZ5{n@B=\1ڎJ )6$@O0v|zK8Q|>[7O~A&;Gӆq8?yW^v0^QiU[֪?xE/rʑ ?Vpo MѮS]SQ8fCw4ڙ4!ZVϹxvϣ.i *m KIXYDƠ \vq4:dC0d<ެ0kK<Hc7ڼDSsiL~o$j1U/zWkPvtz^]2HCv?JX;~~}IGuf+kf(gAцwN5v6Q_?r=u<K7J mڳq5˦ֵAեqO3p|y ϺR)\ul};@nŸS5Huf9 ̊Kv揂k[:s5Z] jr3|qtG$i(ץE@!anN^qAS suZF 9N:bׇM4=J~FЭW,^ Q!'i],2Eaą Q?LZq'<]%qehYFfF"=RL23\3XR>kDܰCF3 `cA%3}OP5І㣬3Q%M<5dęJ+m3uaL5kT?oevN)'cy$5d׶vS_V7 [g5|Fߪ6a\;4V\U"!ٴM= Q"lyC`pͨlF1fgȷ2L٤>+D!eמb#q73AC/ޒoisd_2w[pr纰|EzaAoi;LpꕙĻgN`tJ<Դ>s4}l !!emiQdrTS$l\+9YR,\rr,ڇ]<} ɟ-p8@?$řFъ_쇖7܀G>-W@d߶"_EfЄ NhzwUzw&z'GUxm4bM/pAOBB _2(T 95˓ mbJs3XBCGêewtk1f\u_5< R!gH*Wģmi<<: /i1l; Xj&kH}TmۻɑdAyGpuqO fPVYէ*;Ngs+>jTKZMk/ص/>3a2yss}7ԵUuLjU S:A) [u]=]45*1CB$Gw΅;>VF-RH== &,%"br@_1eNHT=QC5 T`Dr*32u-0J9jAF/BJv 750_ۦW'\c!m3'(K =*lP5YJ\f]-6N |cXQqĤ$Rj} PZa/B囩 (1b5R2$|5BNld07 oZOgQ9Lw^X{,3/[򟱧qe}&5fT7MJu)6q]2 /?&0Sh4;4yr8%8ދi, we8B&Wr;oh]ne} k\s: aM*kLf>}A{ +hJ5pDqa%`6]:zn :/zqxXH ^jP+"b_ {g3_kVƕ#e14'IvRAC[xň^E @_)]$Kê[;P!&/s{km9DȪ FSL׸3qK=ya9,5l:BHiu&rLY-:GBU[M:rqS v׵&n"ІbJWPH+92N^5:Y-ÚکV%[f%6P\Wj\q34rYЇ]"ei>E9ƦOi>FݰזHDk K~C1v*./Tj/6{n |v֓@?HA&I qr) N撇R*8s|ՔH%~lJs\ 6z:˫/LK%e:+;409 KZMZ8i) >n 'n2xտ 7;=/8y;(pä@:d@GwnYF7a3xVcOEx7_)Gۺ¿@/y*DBj̡_MNɞ '%+7OY֘SR2 RtֽxJ]ޏܩu H_ɤӚnkp92v ('1i?}Cb8~O||^!^5^*r+Mf3<{5x]+n鄀q4{χN*uuudy+\~4ߋPv~\S1;o)k?[SQ!azuɝo٫k% : YrnEf3@$b Ԫtla͠嘑ždUƝ ]4/wvᱹ]^D>@_^m*SӋ\f`¨)B)uo>&C6 0"V ̓w"uo@ux`Aç/YƗ3p #5 3gMZ Cg*Q&94@m%aWTy{ߞ⹂YMH;;{&"q< o7nLfriEA\22b+w}4u}? +bY,x3t)s߸Ⱥ)k #ZH D7ԣ!YZ V C[WBh8,cfwDE>5x܏7p:Zout@&tso87qbv|QcQ;F1*3S6ƚcql[Ϋ\+ cAt~Yq D_2nC滋fܸM{R2`/j(ut=zR.PY_7!"l| T Twī c]obF\=y=T4S31%$̱Eai^L%m={䦓_+(p,_ϩE#kf6/b?hi3 9^KEXXxzϋo(0X'`7ţn :OtBUh+sW$=ZY#zd}?M]&r|tvf͓qcyyOj{?aƃ{P;_/JXq)g`;߬A(@96FT-QPLYqRwǛT^]A9{"!VnElguk/J>IjY7'm6DF3Ro&Am+к23mWroh{JpU[fkn5s.7I8BS @sjNdZ!4L?t]a6q\[G5-*ͪzEC99ܵqŻV gŨHqD}-Tt 3\?2i0%,kDUVPKRDPխUEv˹&A;/R1Hݑտޔ#ðq}ԩ $VϷM{&n/[)MSmyEm=wC}a[swse](.L3"_UCQڞ}{P}52rP 0t UwM&I/‰[)0=sȓ,8 2F[@|_\9:"Pm1D,j쟮1;df#gƿ>rcAPEh+$f$F܃'JdT=У3/.ZY,lP2X¬NPl,c$'טĜ\VKԓ>i4U5lmឡRt)S8\PJ880UddvTk7 *.|j&ZmJ D[˹9g;ZWǮJ"Y*cG|ju 3K)%*" ~uft OG5-oB|hD[1\U\j݉^N[#"g5k>VmxiڪS,U&zo~V.]XPIrm 3PA5P*+d!ٿP/Vi%ZgU^L$lsn\θ!]S^h*t])15.-rU\E݉¨T$O 0ks}IOƙT;Sxc"ǁҭ(W*̯e9b im[}x"o]g{PG-ҥLaz3` >F!k#fy *7thg%jEU"fnZ?EyQ?dp/^sbοf4#LjO$P9JӫH"FZy= V?4%u S#f_,IYp68e|.~V"{Iփ@/&흊88}п%rJU#hEq bSt0A[)) ^$y_t:]A.`di%*.U9L>OY0C_*f鈪{!1Du^ҼtofqgN!>&Sť!¤,;3o@+$*񠭹zZ2Ygvj j/66`] #)bKkBlߩ$X3{ {8?*Ta!:4#teU|! I<,i)'2vk_ o=L #9fkwn,E]SԐ*,g:ISRu:2т!yS9ZfbG|Zˬ*!2٢@ϻN B54:}4dpXvv g~;jtS{Y'8VI[\nNuG"/=ӳoV0aRBBªK,9h?U"|<͏^f觟?8Mj>RIJܮшh}c_='= 9$*)>x?Ё_E 1|RMg `S-,L:E/$'/{G:lc1~`KaU$ZL,. ~T8d jC2kv.Oec9 !LբEPu-%IdZnu8ˈV 7pg /mP؋ÉRvVݐiృa[CKwD˖48 [@ݓ.bYD*{VOaǏ6l5A [g{]Eڂnz rLd < rBO=O/ &L,Iy]hew?`{Sc>Xa\;(ũ50uVtӏ f =aj&(ѵ:;89ZNrU]k:5XHtv T\mFjbJx{>n_5oA>/.C0~*g *K/Ȑ6&օuJL&Ï9J[6딝$O,K] yWs̨WXÿ`6 ?ݬl0 WXH6*AOYꨦsE;xSBM:a'Oy{U/'M`؅np5m\gҫ֍9Z;8cLծ¥ϺG~N$x>Dk#Tާ9ba'QEW~ìBZ$]%SU2oF uHQٵ YP-3KCLIl$O0n^+O.MĽJ3V7k,v>?G-܃p:Xh׳zoJ$ԏ3zo7rǵexv@9{J%^sE>[:KW25!bvy%MS_GjcZIl;򙱸&΂_ px(Dڴ̕ .S9 yݶۂyy~56}HAb/fMЍ@|gq1jTنRR8HpiW>)(g"t㸒'inEEZ9˱vl,bv>Z9"1!j|Ur:.utj2ROW (Wš6_mFCb uG^Vy϶΅ِd\ q;1QPLH:4 .R+ ,)ﶠ^A(>/aLD)ag _%jdI[Fo)_^He9'XW,9D7jS!u׫Yӭ`4x+A#?\ F&IE!]p5v8 ȡo3?AJ?}'K| 4zԜW*: wZ߸B صm>rɷDN*-x_U}Z9ϕ -/|s GM,bqd d t lmϮQJ _q'tes6 Kx MވEg,RY U@Yú.jv#}|Sf6ٶY9F$]B]FrgH339( 5KdZTT\,MAMaRSDq22ckbzdiI`hc%Rtڭl ER)ltt)BN^ԣ0;n:Sz1 ``Um* Tkb KLb%42{lֱUE6tϗMbN8:B> '46tZ^:T&q19i Ls IIr >1`MwK$#xЀE$}vC#xW='"& v/pww<- u(;؉l)-ѾЎU_RVu>G t6No3ʃ\I5Σ*G^L9M咯 N{cY2-U6mP{ Yk%k<A{ZL{@0!ےw7Z r;͉n.FeXWCC׳掾 RXrX8q9|>k| E ոwG55;WOJ8) nZ3w=ʂ8֬tB(GE M{le9_ucEC 1t!_-ZU3 $cX?6H T$sJ?t~r.H5#cf&<X)nKU`!Fwdu &k  =& t fTPnW智Nagˢ$Lz]t煤Wc dtTOL55WX j"7P'b&G4O%@,p#pMwc,Er8\,Ў%HxRfXoά/-ҵh;9(9A elGY5"$Ia탙44D>MgiO,X3Shy"ˤaŔfRx蚑 @auQSgΗe$?6 *Lzw M ĩG)ٛ-+'nHv3 ֪ϱ篩5.ZR Oz \-^2f)ZbTeYg(Z״ko0a!٢p< C\v0<}fĞenX&)1uٵcNt\I6IPBLRl繲9 L*D~9H- |0J!н+$Pl!lNGzǹn+6tf*9Bo=@J~ 8eJo[POZX<b:ȐjvBGwEti#"L 2,p}mN5EK *TDiEGMgűh|B@ZexfQ#-MY" @|A;DBژ6n)єWDB<t-Q뉵؊f>G P\]O#iCQ ov,sDo {;m%s9 iƷhQ8뮂U6w9~٭9F Zş4d[]oP>B}g0ѩC@E"Xjki/4DvoD5nǺŦR 5Aի':p^3-l_Ψ{^q|rX3 cV{T11a8BKaJk*ɥËK/KT]WC@WӭwSt党INZSA0 lEQ S$5 Kr~oqؿI3:z3"wXDtw,Y?A/$0L}^f&٦hK+glRd)aOȅu(R DގbbXvKJ?2Nno?vei m%rL',ĭשnߴ#[#fk# ΄&{zo?%x)$- 0HwPt,@h34sBӑ=cԾ"W4k7Z9I-^QqIq|Rohڴ)"XyNx#.~L#LMbf/t R=!6ObJwbp5'4RE]FGM6͉w>HI S] XsLl<5j3p_ij*&͐X>l\K?| 5PT ϏwP 6l2߾9c @ >o\YLHt.1TKHK AllöpGA鑔Zyق* 㜍XG׶UXUHGNÔR8za v|tA{Um3̄Cu_ǰ6F!pd}801%r>|JRyVh<+kgyFEMJVۗ͐=N[uϔ-:91x˅tӗ~W˸~Ji<8>ląѯ]2ٶq&eN -' |VgFÊN=%dV0[=Y߸!M%M}ir4Â-eEv鏉*Y Ӿ[ |3B⠽%7I*qpF-v~) ƍnv ]Vf٣*T=7-4%͑8K8uR( S̩s gqpҢל}'\D҅|HЉ\}>_L+INa{G٭ysӸZE\A l :a@N<@,\:/H|V황o\"Đ/b.8aKӂow&arUv^~m}c:ܥ=NbHDT7Tr1LW)V oKhGяس5su,"8/k%n?hҎU4έM#1,6pbN<{?phq̌]51ٖbp_52ZdeP5hspuj`nft= mMק:>*Yݾ>/:5Ui+d☚S2 8?u*h,*{A09ЭC@oq89 J%1K&>!fqV9|2n&DIy>'4ekXBM2ΝN \2}vF2\]a7ς]0B;kH\θtC<;`fE.W,<>FzyPpN:,z<6'f5089F !?Nqfa)Pz'2%يmO5||> SqYn>Ag?a'$c}~wJۙYMPA*o RQUMkj<~Sk:f,Vl Et⾹l*@i{B`t5Tŵ5w~jDoI4)3\@:5xR- Gz^ݢ7&K+*Վ cn7llKq#޷gĄWykB;g8O!3 =ۈY <3>| kzMt\:Yƶwƙ'\bY&">!Kx ]Axȼ䟧{!iNa]h :GB  ސrM&]nƺ^T@:U='&""CF5)m-{VNi?jTz'5ZK;{$7*xAV`T%@jnG/Iuˮl1ƫ V5T kcMMEtj2ؚ){j?ٽ|J=M.=13ڙ^G48\]&"SR %U$x=Vw֌"{4C"~ 1cQ`p1f=څA2Hru:Z6?F6 \,˂kOR=``Nh^ONK0Yt`MKP A}}":W3VL Ͷ;x{E4);Z-==Lo?uMZ1,/$}}\e%FF%Z'۩!lmU$k@ǻc}`=~Vu"z؁Vݐ5&̍n] Ky^9Fe:V2"Q;{2%8$$ Š|tͱo˧-ydюOۼ`8ӻ}kԎ7I.9vԩ<0J_c-[bpc<8L]iYޗ j!2@7rcN`3lziHdQa!U8[=tb osP] 2pXAU|<JDeMh~[G%.D1bLc`<0Hx8-n1Ƣx ;NX .`ƆY'7.M2;|%xՏ.&6{7ȐJA7vnBKߌ9vȈʫN1jqQM6P4_*jqeKѕ;\TY)ZyrĞL.X=pXcC\:> ݎd%VCu5\HK5߿ )NvЌۮ bpހk#Xtlw S&^pAY| 0=E͕M&ʆt(عnz\x HE֨\VK3vh:\Ơa$>^Csi_F&o-Uܓ:hLwC"Ӵo/P&*gwpi=\l}N{ڳ^Y{i=">w,aЕ}v,}:/2S}ga hl"n^:u^@Iݗة.vru DaV+|~DEvj g4sR6Mr(*NoWn@M=@>G.ry:mr_KZ+J(ԧ@X)EGKRV:(j$D׺sOi?bFxYi D[˰CSFf;$DPq&Q)EG 7PO^bQJ٘8iTd^UltbhztK 1N Ab@],BVsB;CUQ pڷ[4c`18w{*!XEX^ Ls` J9p)9[%TAgJ[Q=7Ngdv/V mE`*f/u3r:߰q\!Le(W KoQs@h+Fl%mIk?I3CVӜXwx7HX,lPW B\) G[ 7uьs( ϝ<0C9,$5Ғ 8Id󿵵$ם6aSm *^LQmٲj[|4[^0W mO$=[PC\i=.YċV46ƠBt!5=K},&ώx2~ KX^B| O?Țo_:eh\0f2U>pv^0ij H\ʲճc{,L:{K)z %kyA}O(2|CQ3_!boboS7&a.hbDBSUNQ΂k6%2E")9͝[p`bp۱Z"!/o&'/lM&-mgZ/m(gH\J`T`  .YFj{4!# tإLŴ]h d=K,=l)Avrk" XI'ŸGڶڵzdٳQOPax򝨵;!@SckgT \4kYԸZ}C޴^5s60D3,>gW_@ڟuB28>(^8ZW1+UeIv^C$%DDRw&N<7F1ʨsD_vtm׍Z8+njC>񤩶.v7ElxY^B;.i nt&2hnr} .yBK~A )W4O8Y5@>؄!j<þD\yKc3J0l?pʹT7O_y|JڊJnocr4Һ6! 砘MrP*Tex #= ,K!ߢY =$dTKBُ\fWl(ͭ93`+l 'v,&{#37ll8`C> XX3>8O/<RJ-9.Ƹ]Gc :59i9uy* r)dSkH17ࢋ~Y; ޫ=ڝ.wD9].I$ thst+oh|K@-1#1¬dvʖ=)PKǀ8,6Rj9\)/-> ׸i/n,m,&`P,Rr!JݨoմlJ]Kz+>=,$$UhTu; RL {SiIt+HdUl[q{n[Y)jz[׎\Aх xdrxz]|vZ&>duk <"yU;)^&9۳w&%{>sv<H΍+!Hw\;#K31m nv75Nq?֎׉~rDS1#SE[Z͟t쩜!2X1ڟpD tA)/U ƢR?>M̰f  ΍ѮS*!YS]UW85%a⇿VWrj'뵥 K5ȋE,aUT_ ^!"v\ =,O)^ ⁗P^uG;dR-5 tkCChwJ%$ޖ vvAV"E7דhzwZ9a TU 7P6JЈ/-dbϜŒ+*}S7Aω2+y]nX!IfGqCA`WJb +Pf0gQgYjr|OV(ku8#ZDQ_" ld]..Լ)F.Ńb2ð'R˒2ȍ ٻ;}BHUZq-e&PB>ʨl[]>B3S{FK fs׻zl.GiBtT?GTU'-EQD\ۉp p* :SPs4Jڃm@4"a655zX݇EfUlՑNEā? vْEvFAC%,~ =!S𔶬7MOFvLf *^C~ZBɽH_p6 n9%x"Ġeݑځ-sbj}C.د" \yzW[ڂO)`fK<uf1#Oʃ/ ,kb9|f*O"?7;VF>+&΃_wP0ƫ/ln~I JP[].[ՙFF'w+ȞW&{Pc%g=楃̬ KG7c(i`iz5/b]շ;{ , ,m0B=3ʻ@1d*v 4ScfQr9 %5q;mE+ē '88ʙzUG|MY@EREGH^i>8vVo%̸% k =UXp:^nƁy&uޔKXg#>C*0i56γã՗$|-a93)H)ta_D9n!d{[\-4)W Vb,3`#W\Bktb1MDoٯV 9,5ɧ2,Fl#VK!.cmotCEY+kdxdb\`,Hg4Me*T.h0=oʪ!" HG#jgh#|rVPǴz5vUHX;/P 9ۈzEU;RtNE^Dݐfr˅9MOXknR+GAcM <`n jV{q-vfP1x%\ቩh olAyN?_|d*79A!|@Xt]^|[x'椰q8OI?40DMt.$Lu wb83ה:ŗyR;m\`KY4k%^CO~2CL 9td51EtcFm u{D< r)Tb;]XG P@(^}aix)q`>`pr2?&9,,yyĎZ!?WCV#\R_DhuJŝbۦ{4xS^4 UU xhK;ѷDAi#jnS1mjlO)"Ղ{_ԙt[O{{SSH>mjiGLt9eԗptO;{[JY:&+WX t |Ҡ0_!{?M:B{9ח04nHHW\ûJI;9#C< ⮧*բı=W1 V0ksM1UmXe]G1A!?n(dN<$Kj4mVa8ƴGٔL]4-ܵ J6+1+FYʵ^L*]^ +1%e1I$_Wňy#;m[jlmA2T f#d98Ao:}h#Vh$3!Nw|iqR¢da4GERUR5V(DOuؓڙk+y mc0!a*K"w7ʥ@.& Xד)Gxn}_2Ah`J^\ age[72Y`Z$aYk8ʝׯFw~fh$QN U/Qyп|0珟OM7'˘:`/kzH a}Vq=? 2W-b Җc 4ugv YiF T3Uh,PyDnIRo bi\Nq"8Ɲ,R$u֩DK"ġ_)lLǛCdg1n'D5l+_WAf[$.$Y;~Iל!92mxet86,d#O7\2cjPpuAM@{[\aU6_Gd -XGCI|%0]纮”V e'͎>0-%P0;a-B ަE(̮i@3cn-uDrEGW >#kohleYdU+}ǵmg)&2rxy=.?ڑS̆0>-Jf~oyE*@$|W܍7 *G!w)$a-uE㷴Aޕvͦ*4>kp> p!j>][c\R<.Y9haEwc}S/b'K4-Ks?xEL7;1w7#&zٱOu^rSش={' Y}C7`?H?W3@RC$佸5/:_49.OQ6zS6I\f.;S)5,Ou0 *|ek}~ib86po"Ȟ~~b%[HzFe)ƸU4DWOTDRRioEU`O+K4_x фNBr= ,#!$+Jqe.ENLeU%SsJK\goЎoUuݶɞT81mnߋ!__ $? eN˿Dv[z 2VfqBbJH:L[kE;~Gr , 75Wm1,:N.fNONmhdD?hC_ |bBP?מfcޒL!P3P:(|L?r@\>1j[Fͽp^Ѧ ϠJ$PIXOwTa#=\!I9t콞" I]OgȾ\pzc2%ҹvH Gd̐x7zD'' (y$I6v <,S8yI@m*A6Pղ]e/ j<ϼǙWN[U{Lݵhoe݈(-\, c0P6Qj3{Œ5"P%OoM!a{&WA~p J ,nuI'G2hYrfgAT9N'Om6$&PhϹK񡮗2Ҧ>anu<3XNt M  w5YOs^7Yηc, 挣y]o3T.\Q uy#r\m]l8 i!8S'lo[{iEjw~jub£z䫎شFPVD=ݻ&z9RS2G>G_d?%yMEqm䵣\ljLAzk0An_>vF}6%Cmz3.cLKaJBGnX|Cy-EA-$2p%Бt! =\5.,O9ڑ3(J$xp#zSc]`rel%{ ӲDH_9Z~h8u~(O*-( ill>2; ;so3`Ykbr S$5Y0 #Qɠ1*z'mM-(u]t`c>` 2 <,ꜴְÛb{+X\')Ɔ ̸xG^rJiDmi"F=7<uP4D7ҝͤUbij@)N;%?Qޜ@c&z}n MwI9քK:EEzJօy]b&i8j#pVx;Z-`'.۔;07שڢ99̃1;OB4Wi5ݪ*U:\`Ac5)VY~]>p_&GW -dw/%,z,Sd)dVэB]=vt.:ixA) ." m k5qB!|}/LL)ؑ܁tJй -D^඗N t@ դD&|fɶy<믊/<[ # TjFc wGŚ)(73I \R{ 4c?^n}ߎsZ_ CV-omW&FF^v$? ZBa_=G!J$h#@[*% %,9g[@&iAݍJR5hLN&z|ק.=ԃŴ @FN@L]EL؄P-(ًZu>;FK ^BUyEˌ?!jk{tu)SIja~x~0o*_WF6Nk^R77PV)gEJҸ kvho Q-tw|jjѸXU@Y^6+b}5җx BPYY|3V$PQ Nj Uxyc[Nק曀<}?9{iM5{9o<2rؤ 6k!e(MЋ wZȵ5>}D ſHtT{2£nI_s//4iI<4xh&'^{kTn qI`&җRȃ1N-JƐj1mc?cmA/%?WQF c?T=ds*bf0[̣w` ~1DT=^bR=npD!]aBR[bam(fjw27⃜.;w*j;y.}#VbQω5;"NAGj➤.crf<\{:d v3#BRސgoRidMiOmzuhCl=l,J6wP B=]TesǽIoZNc?8y5F˳WsV1"Ġ?1ӯ=FQ?$AY$Z_oR`1΍T- c4f#ar*t(H ܙ!_ʓt#Fw:OZ "X5}1FDXy[xؗ6+TSswMIA"*4ĸŸɃuOod!DEi=TkЄ޵4d"N^c>GVuBiQҒ(isM[KsZ6Zƈ[K(1SתSEh<̱;f;tI2[`^x 2ڡtwdOxD P ,*z{-wwF,3o 4fJR3nH[0|f x$ϼ.k56ڠ wTa52 OEBc=TÆܔStAvF= )fbdGVMw\jv Ң_`*aw*ۜi]S*wS_D*#9\Y~zOְSUesDlX8ƶ| ISeg gUQ{gûMPc Zf sq$J! 4EZu{KИ_fX3:~­u7PzJbJy,88 P=6C#`=[#3NBt t W̙s QE1LFt\0xa\UW= f|Qv' 䏉  e-~1g nNtP4lŢi\—EίўǧE B#?؇].s'vGF܃Jۆ`jsᣠ6 #^h,C-r<9,_wHxU綷 xxc:m~enCF x3p-gq0\=Y_'ߜZ ^Q).v ʴHgQ ͭ ŧ;8r*EV9qP}Lj5C0Fm+LZK-zP|ș?JLk"8[IpU>TfJnqlĩ;ԑ .Rij%G$P~^ } S:;k߲KlL#l;f+XFE\tLjO]3YJi B?ӧiF΀\#9=eO3JQ8‚l)f2l9wl$U}6Ou\2%L=J@ }TVtC}Y*|Tv@'^Y J25~v#s]q'\UI~DXHsm%Z[&0IPhdx!SR^]3L" δ.l[ K8̗.ooN2/{)>(?/>䎕@ߏ)eA- )bښ/zM%7jjycgDH7RC Y~ɨr(ߪKijU"iS QUepWLY_a?wlg,OP`M/rm[i1y,OK^9\\A|׻S"xqF?Vף~aZ2ԯ{22R' <vt-sN@Ec?F*c0mR^̚Ud?3-$,!9`ݯ `m{2 ;-;" nv8DB Gf0 Y't-En SHJ(w^Xb3O{e劵L]D+ydEJS~ʦ(U⩂ߡ8ק~<'yS=a#u}95;B 7 &OS.Xw>={-xp'rQhP`l1#9: ǣjev yXK+kIu+.BWmP*2@$^M)%H=v#}-i"92YFd`Y(Lxڰ _f`r|4S&׌ stѰ$A]OVKjV+-=wG_)6D:!s=b41uEH_^\YBoGGp |JJMr*zlc9U /c9L,_9C+j en p-֡K9F:uf],)Ӡ3p߬ۨLQ`(!(, 2sZ߻[INp8i]PI :zc;KFș.c̓ـz7 @=\@ ynG3%j)XO,aӁe{B%i+N(銨CL -ȊOׇ^X3w{ɩdȫMΖQ~8O{agC,P)j'Y,mɱ _Zn1E$l H{hF҇۞9W@}ΦbJ΍o~/# S5|̴SgBrW}O/yLĽ$aSg@.qZnՏ5E?3 lvSz,.EM/Da&A̫v|Vd)/O$ SIsG?&a 즺y>>de cxlep_8Xd!)Gdc ϗWG1 2%b,*s6 `7~G&,Yv:;Y|tZIf̻i5)Z,w }f mtkl_C^QpA &SVL.K')N)Ըƿtw !OUlc m~8n?ϻqobHspn8QH?Gs*6s;>V0cM|3kb#I0]?Wa~_\q†:_Q ?@Ծ M1Zyg +Z $3=AR4W=9+Vńa+s `tMTӡ`PJ hpjY0nmx 'znTuvՙWqᇫ~Y s=c)@G ō6f~"f_CߒӅ"nz~1zyEw泫U(!aL6Su"`700"Ҩ!'%]pyrՄF cW ĨkupkwX#2nW"b=*znCw% m9h61mj'!l1W]dV||BX|?LT5*8ʻ7͝vl/3LV5r.AZ~&қd(=t}Xk|ηP)oCʒ5@)ui7bbNj Ȕ( 0D*[̬T8QʆxvMiP{Bh@C?97@f1*超Pɞ7A2[z -8X\c_ \ݙDTq;qXW`Rk>|4sWR{{˨!3 tQ?"+tX|J.0]YHWu{1 ;ٟHq RLӯ;+ ; rA)WHTBgwPx#ᦲF,P5@#;BRN ULBVal^d&eJ" 3<+r]=-п!?¬k^d1w,]/ sFރ`RrL_((k -\4ӽBh+ U/ 4Ux6!y[Ẽ OJ6X-UR;>x=^ Z<&̯b F]zۗbJ[׃̹X@12XZ|TH^u@os3n\ԗAX03cO:mecȓvNQ:։ᤶPTS25ޕE3UR 5($>G[\ʥMΦEֈRgr . +~)1h-{V0xo~o2Ox6+sco{Jͩ3{-[0»Ab |: 1P䫲0UWQ4 g0qJpv.Q{HG1?@mnO ?9xUF׈YIw)?c=Znѿ gr^(ޢ֙rL 5 B.Hv)H|Ja_PlJ,Y is*^cQk$c()O^%v|z>` 'Ņ*w؅[Lq9AQKҙNخ"\p}TK